About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
+ I" S0 ?1 i( W" q% b- ~- M' y<TBODY>
& n: z' H, d! k* `0 {( W<TR>6 V  {6 H* a' d3 e( f  _* ?) W' X
<TD><PRE>Method 01
: c* E4 Y0 H( Q. K, h1 j=========
; j3 y& ^- i* r8 l; h% v" z$ u; c0 n8 a1 L3 k$ e
This method of detection of SoftICE (as well as the following one) is
& Z5 b: P6 g7 ]1 xused by the majority of packers/encryptors found on Internet.
. {- `# s! \: U. TIt seeks the signature of BoundsChecker in SoftICE
0 Y2 ?* G& V4 s6 O, R) P7 S0 P. g4 `; ^0 p' z+ u" I
    mov     ebp, 04243484Bh        ; 'BCHK'
! ~+ T5 k, `2 i" H1 l    mov     ax, 04h
4 x& H6 b1 E, F. D    int     3         R* x. H. @( b2 C, A
    cmp     al,4* V. [% N# j' ^: N/ z7 r$ @0 o
    jnz     SoftICE_Detected6 l* U2 J9 d- [5 r
3 c2 Q1 A6 w) Z6 f* F
___________________________________________________________________________
( B" A9 |+ t* [( H: C+ I5 R2 ^$ j- K- v' V
Method 02. N; n& y! ?7 s+ l
=========
8 p5 z6 F& s. q! z7 m7 R# R/ S0 E
7 {5 K. p9 e; F6 PStill a method very much used (perhaps the most frequent one).  It is used1 b# x3 d0 q3 g( f" t* T6 T" e
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,! M- p% ^" \# U2 b: n3 K" o' |
or execute SoftICE commands...
, M, Z2 b3 O6 q& k; l+ l( sIt is also used to crash SoftICE and to force it to execute any commands
$ W$ F' k" u: o" f: ^! h* v(HBOOT...) :-((  
# d. e& [0 `. d/ Q. g) P% {3 Q- A9 s' Q. J5 g( |/ p/ h. |
Here is a quick description:5 r: G- A4 @- ]" M
-AX = 0910h   (Display string in SIce windows)
- ~5 \6 b9 n( @( f& _-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)+ t4 k% \2 v4 S( f
-AX = 0912h   (Get breakpoint infos)# Q7 `8 I+ q' a( n1 Y
-AX = 0913h   (Set Sice breakpoints)
# r' \/ ^$ C+ X- X0 w-AX = 0914h   (Remove SIce breakoints)
4 y* x& j) N$ [3 B9 D  R2 v. {% B. L% t4 [3 h
Each time you'll meet this trick, you'll see:+ p. e% a% \, p& }8 j: h
-SI = 4647h
7 `# c& C  x) J( v8 h7 G) U7 ]" U-DI = 4A4Dh' P1 s0 r- m, `; i+ z
Which are the 'magic values' used by SoftIce.7 k! I+ C: B+ M  R
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
# A- n2 w; J& E
1 c# i4 b! q7 e/ Y1 l* |# wHere is one example from the file "Haspinst.exe" which is the dongle HASP2 E7 N+ Y7 z, V3 e% ^' i; w
Envelope utility use to protect DOS applications:2 g& b# [. }/ A3 d9 o& k7 w6 y& W" ~

, x9 V- \: R" r- M7 `2 a% e7 A+ u' Y) `& n1 j0 ?# b2 {0 n" ]0 N
4C19:0095   MOV    AX,0911  ; execute command.  k: v- s" U) X: ^  E
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).2 t- M* m* `, D; B" m8 w
4C19:009A   MOV    SI,4647  ; 1st magic value.$ \8 S* \5 _; p8 D
4C19:009D   MOV    DI,4A4D  ; 2nd magic value.  d9 z2 _/ H% ]% f
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)3 N: c4 U, R# |* K: p
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute* b: l, x0 a) Z$ Y: G0 ?/ q6 X* g
4C19:00A4   INC    CX
( l6 x9 n0 e& ?' O4 m5 N  A3 A4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute3 i$ {1 Y+ C6 @- x
4C19:00A8   JB     0095     ; 6 different commands.2 n3 R- ^# y2 I1 C9 W
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.7 Y5 r# X  v1 c" I" k3 ]
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)2 _+ N( D( E; ]: R, B

: v5 o! Y* P$ h" e7 WThe program will execute 6 different SIce commands located at ds:dx, which
2 e  ]( H8 h2 {6 M- r3 G% O3 f4 Hare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.  c9 J9 k  U; L" y5 ]: O8 x

$ Q. j0 p$ G4 n% J* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
; }" h( k# X9 M7 B/ q! Z___________________________________________________________________________
1 j/ J- _$ ^$ a, m; e5 d$ O
, r! \- ?& y! S& Q5 V& c6 Y) s$ D. c8 M/ K% H) |  N5 m
Method 03
% ?0 g$ n1 c$ ]$ @# u=========" P3 a: R# b6 N, B

, ]! u( ?; E( L! KLess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
8 U3 u# A2 m- I4 A(API Get entry point)
9 y3 x0 h7 [1 ?3 u        # l& ]" b9 b( x2 v% {; ~

9 b+ M$ e- Y$ i. h8 O    xor     di,di  y% ~0 ^. L, q: b( w9 h9 _. m
    mov     es,di- E% j% H' T1 D# @
    mov     ax, 1684h       , ?& C! L* x3 z, t8 Q  M! k! c* b
    mov     bx, 0202h       ; VxD ID of winice* ?4 }$ K" X: U
    int     2Fh
: u. \& i7 M. r1 J. \    mov     ax, es          ; ES:DI -&gt; VxD API entry point
  ]; x% Q: h$ |4 G    add     ax, di% e: X4 b- x/ n3 v
    test    ax,ax
" r5 c, k: I  T# z# V9 Q    jnz     SoftICE_Detected
( T; M6 H( B! `1 \5 q& z0 S; V2 n' C$ W3 d9 l, d6 ~# T4 e
___________________________________________________________________________* E/ {' y) g* S, q& H

) U7 \+ d0 l4 T6 sMethod 04( a; w* h" b5 P# h6 C2 _
=========" T- ?5 C: p# J0 _, G' o
( S5 ?/ d2 V8 C7 f% k
Method identical to the preceding one except that it seeks the ID of SoftICE
6 x6 ?+ A0 ]2 ^3 i9 NGFX VxD.
' M' W: ~: P) k8 x! |3 ~
4 u  F$ d! w' X  I: a    xor     di,di8 S* y5 z- `/ z) l0 }2 M
    mov     es,di9 y: P* |* |2 v; ^" M
    mov     ax, 1684h       + C, p. W- j1 H, |7 L
    mov     bx, 7a5Fh       ; VxD ID of SIWVID
% o/ P7 E2 R1 p2 P: v; X, Q5 l    int     2fh
: i' P/ |! ^8 e9 f8 |# q    mov     ax, es          ; ES:DI -&gt; VxD API entry point
* D# i, P( e/ O! o( Q' u    add     ax, di; H" w/ W1 W7 R, y
    test    ax,ax, E5 u: i& [' }/ ]1 `$ C4 [9 Z
    jnz     SoftICE_Detected
; q  s* m! b/ [1 [: o! f* q
& G8 m1 a/ J" D( I__________________________________________________________________________
; _) B  D* A" ~) y( ~
. P; f% K, a, C! [. t' H; e3 {% U% J! `/ }$ L
Method 051 v' W- p' R) Y
=========
: l' ]; `5 M0 _6 o* @/ q: V, X9 I8 k+ g' p: b  c! G5 j+ p4 B5 b
Method seeking the 'magic number' 0F386h returned (in ax) by all system/ B5 k6 U5 _9 L/ c# ~% g# D6 b
debugger. It calls the int 41h, function 4Fh.8 G" M: }2 ^: A9 o2 T. ^
There are several alternatives.  3 M& x7 C+ s; b1 C5 P8 C
9 t8 H" h) {2 N, m* s+ O& p
The following one is the simplest:
& l- w' C% b/ F3 t
5 y: T/ C0 K3 O3 X    mov     ax,4fh
" L& {: X4 w! b    int     41h, B0 g5 [' V$ V5 U2 [. E  n
    cmp     ax, 0F386
0 V1 Q2 a" u3 p    jz      SoftICE_detected+ h9 q3 |- i3 `! Z$ g, g
- q$ G' |* O4 H+ A6 A3 z; l
& j/ z: c# u9 u+ N2 [
Next method as well as the following one are 2 examples from Stone's
* N9 ?8 ~$ L7 n+ k! E$ Z, B"stn-wid.zip" (www.cracking.net):
5 P; r- e4 |1 P$ h. w1 O; j4 K# ^2 f& \+ |( B
    mov     bx, cs5 \5 h' I( W9 B1 U7 y" f; y8 C
    lea     dx, int41handler2
9 Y) u2 V2 T/ T    xchg    dx, es:[41h*4]( O. [7 O+ U. X7 O) y' r' F; J
    xchg    bx, es:[41h*4+2]( J, N  j7 T, _" e$ r9 `& y# b
    mov     ax,4fh
4 J4 ?+ }( d+ M) M2 J: g    int     41h
- {2 }7 ?$ t0 A& K( |    xchg    dx, es:[41h*4]
3 z$ E2 f, F% g: ~/ k* X    xchg    bx, es:[41h*4+2]
6 J$ X% s- w0 ~" g9 K    cmp     ax, 0f386h
* x4 Q1 _& G; Y/ `/ [! `7 D7 P    jz      SoftICE_detected$ N# ~9 r! l0 I0 M1 z( a
" Z- M/ q: A  _1 `  [+ b
int41handler2 PROC
6 D, k& y/ l/ Q8 ^/ e  @    iret
: |3 l7 K* a- ~7 _: p( U/ kint41handler2 ENDP% f+ g4 C3 G: m7 @; ^& f2 k

! y* z7 ]6 i' p% J# n4 t+ ?) e" I1 ]7 c! h* i
_________________________________________________________________________! l) D: Y5 k, t' y6 D% l

" z5 W- z5 Z3 D9 m6 E" h8 Z$ {$ r5 |6 |8 u
Method 06
' _& g/ v  z# w7 r. _/ F4 q, _8 |=========
  D4 b# W3 H) t( _: I; v$ @+ k6 I1 T+ {& B8 {3 p/ i

; o( W% N/ k: t# E$ S7 }2nd method similar to the preceding one but more difficult to detect:
/ s) k! Q6 j4 T! L: i3 x! T4 L/ v, N0 n5 ~

4 q! M. {9 P4 k, j7 _; c& g/ {( wint41handler PROC2 i9 e6 ~9 f& v$ b0 q3 S
    mov     cl,al
! R5 h+ \1 a' w. I3 b    iret( m% y( a( P+ F
int41handler ENDP
9 v) c1 v' {9 Y5 {$ e" E. A& D* }: X& H+ h

8 ~4 [7 }; t3 B$ J" [    xor     ax,ax! h0 w7 A+ S2 H( w5 V) i, g( t
    mov     es,ax
! G+ j* g, C, e    mov     bx, cs
  h. Y5 k/ t; Z2 t. M' C! p    lea     dx, int41handler4 C, a) Z8 v6 Z4 @8 c
    xchg    dx, es:[41h*4]% f' h7 k3 [. b" |) [
    xchg    bx, es:[41h*4+2]
$ M5 @9 b9 R: P% p    in      al, 40h
' ?7 i0 T1 L8 K# O    xor     cx,cx/ r" J; F/ H# ~6 |, i3 ]% M
    int     41h4 @* k) t% B8 w5 Q
    xchg    dx, es:[41h*4]
5 z- Q1 }5 }. n& Q6 p# m4 r# j9 |4 ?    xchg    bx, es:[41h*4+2]% }; ~- Q$ ]+ Z9 u: r" C5 k3 a' u
    cmp     cl,al. \: v5 l3 ?. S; X3 h
    jnz     SoftICE_detected" O- ~/ j, }- N
3 m4 s5 P; r1 X5 H& T) \, B3 C
_________________________________________________________________________$ C/ z9 `) y/ D' c# f

2 b; P' r* x2 C0 T6 ^9 t; QMethod 079 s( H1 _; i5 g4 x4 `
=========3 {3 V8 V8 [& Y# M6 F- o1 B
8 D) R: |  i& ]$ v0 {7 a
Method of detection of the WinICE handler in the int68h (V86)/ A; P$ A' u" i7 ?- s8 U1 J$ [: _
0 y3 j8 L9 E4 r9 B( Q+ p
    mov     ah,43h5 ~8 q! B( m; o" }2 N4 w) D  O
    int     68h
7 b* a/ l" T/ T3 c0 s1 P2 z8 x    cmp     ax,0F386h
* Z( _% a. J; @1 W0 N  t, `    jz      SoftICE_Detected
" I0 A! z3 i) m9 E1 p& N5 x: \9 M# n  `  \2 V( T0 M( ^7 h: b3 c& J" g' Q

4 J6 V  H) D+ k3 X) B" ?=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
. }* F$ \# ~7 p7 ]   app like this:5 v# p  }. m  s4 x) y
* X5 g+ c% _5 A: B! y" B" w7 d* l7 U
   BPX exec_int if ax==68
4 k$ y3 |  u, t+ q6 m   (function called is located at byte ptr [ebp+1Dh] and client eip is
  r% C# E" o3 E" Z   located at [ebp+48h] for 32Bit apps)
" c* j) Y, l! \) X5 [8 b! q5 B__________________________________________________________________________- T$ N* ?9 _, g$ @' [/ e% ~

! I1 W) \0 M) [
9 F$ g9 e& W3 e6 ]/ B6 ?, R; SMethod 08
4 L* ?! C. i+ U8 T# Y=========
" R& Q+ c5 q8 c) q3 D, j" |* [6 @0 J6 A
It is not a method of detection of SoftICE but a possibility to crash the
% O' K& H5 W4 e3 b3 Isystem by intercepting int 01h and int 03h and redirecting them to another# D2 t1 G* X& k$ I1 t
routine.
% ?& l8 K  z6 V, NIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points" F( c& p  Y' v. [2 i
to the new routine to execute (hangs computer...)
# [& k. }4 Q% `( v! m
  E! |/ u! ~% o    mov     ah, 25h
3 |4 B( X- l6 l7 |. Y. Z    mov     al, Int_Number (01h or 03h); Y  W2 x* G  c" L* N% K
    mov     dx, offset New_Int_Routine
% w3 }% M$ p; ~    int     21h; T% u4 g2 v! M0 W2 v' L

1 D( o* A' D3 B+ w( p__________________________________________________________________________- F9 _3 X. w0 V! n# A

' E% j, E* u- L/ TMethod 09& |+ y2 g0 z- s9 Q# f4 [1 T" M  L
=========
5 E$ a% O8 ]7 Q+ A' ~* p# g9 @# X9 ^4 e) E: Q+ |1 e  k
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only5 v/ c- a5 w/ |8 r# a* c; h
performed in ring0 (VxD or a ring3 app using the VxdCall).
. \" }: g1 D7 s+ n2 pThe Get_DDB service is used to determine whether or not a VxD is installed
$ ?6 J) }8 g3 @" V1 Bfor the specified device and returns a Device Description Block (in ecx) for
- l2 v" }" O- U" }$ x" ythat device if it is installed.
8 r0 e7 }+ C% K9 X/ P2 s7 p5 j1 T, u- ]9 }
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
' U# h7 Q# }: g' g5 P: O" m   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)7 u* I/ k: \( R6 F  n1 r" S& k
   VMMCall Get_DDB. A  |; W) [9 t& _0 @0 S+ Y
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed% s/ c- |- c1 w; |

& F6 k' o4 V) {3 n* E- Q9 [1 s2 ^Note as well that you can easily detect this method with SoftICE:
! ?7 T; V9 [+ u   bpx Get_DDB if ax==0202 || ax==7a5fh" e' W/ N' T; [0 K7 N
4 p5 \  F7 F) U# w. E
__________________________________________________________________________* f" c, F; D9 b+ i/ Y9 R+ ^

, z% `1 O" F4 I& R) v5 HMethod 105 C( u4 v8 Y6 t8 v7 m  M6 h
=========
. \( ^! C+ G0 J
" l! z# k- W8 S' m+ Q# T  N=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with- t9 p9 A6 ~3 \* y8 y
  SoftICE while the option is enable!!* w+ n! _# M6 |% n1 J  n8 E6 C
' I" g* v$ k/ S% B* h  Z4 x
This trick is very efficient:' X2 F# C  z) E9 @) U  K: I# `
by checking the Debug Registers, you can detect if SoftICE is loaded
; x' a" I* R. u! K/ P" G, R4 z(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if+ p+ t: M2 r" Z3 u- n0 S
there are some memory breakpoints set (dr0 to dr3) simply by reading their1 [# e. j* Q/ S9 |
value (in ring0 only). Values can be manipulated and or changed as well- D5 E" p- Y6 ^% @4 [3 Z- q
(clearing BPMs for instance)
" Z6 b. @7 l4 v) v* p4 }+ e8 G8 [' Y% ]
__________________________________________________________________________
2 a* W9 Z; X$ V1 t' s$ d  ~3 f& _( J9 L1 U5 v3 J
Method 11: O( F- h" b# z$ @* v
=========/ W; K' \" h4 x3 @3 X/ t- Y
: t; V- s; I1 O5 N
This method is most known as 'MeltICE' because it has been freely distributed1 z9 @, d2 U$ u$ Q$ Y$ S. t
via www.winfiles.com. However it was first used by NuMega people to allow
  ]5 ~8 l7 Y' G0 ?% USymbol Loader to check if SoftICE was active or not (the code is located
+ T8 R$ B; U3 q. Kinside nmtrans.dll).$ v- x. [; y8 n- U
9 U/ X. \' g! A/ m0 v1 O3 Q
The way it works is very simple:+ }4 L8 `* _" l& y
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for! K' Q1 q/ y% a: t9 h
WinNT) with the CreateFileA API.; ?4 E5 `. ?, S8 M6 M

8 R5 z- v1 R# L& l( {# lHere is a sample (checking for 'SICE'):( M; ]' `" A- {" X. s3 o- ~; N& f3 T
1 b# P$ O3 @0 \" `/ M. {0 [
BOOL IsSoftIce95Loaded()
7 ], w1 f, A, f/ X{
5 ?  r6 j8 A1 e. N# t# n9 ~   HANDLE hFile;  8 G) o- V" d! c4 U& G6 U1 T
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,/ Q! ^5 \( l# b, k3 f- `
                      FILE_SHARE_READ | FILE_SHARE_WRITE,
$ t! h( `) Q' ?  N8 p& W$ P/ f9 H* \                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);: y* d& M" d6 C: g
   if( hFile != INVALID_HANDLE_VALUE ): ]: E6 M6 p# R+ y* K; s
   {! f" p* h1 C/ O
      CloseHandle(hFile);
: v- I4 z/ b3 i, B" P' r      return TRUE;
; ~( |6 Y1 V7 C; x, b. C   }9 U+ d0 e9 v* o6 c( v, x2 F: F* d
   return FALSE;
5 a4 H0 T0 n- ^  y}
: ?4 e/ J+ I) w" Z  u, u9 \3 l$ l1 `- W* e" T% h, ^& f
Although this trick calls the CreateFileA function, don't even expect to be, Y6 Q$ i4 e1 ~1 H: M, G0 M
able to intercept it by installing a IFS hook: it will not work, no way!
3 [/ _8 p" k$ q$ Q$ Q' SIn fact, after the call to CreateFileA it will get through VWIN32 0x001F) Z! b! z# {& s3 f' [: y
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)( l! N( a& e  ~% W; p' l
and then browse the DDB list until it find the VxD and its DDB_Control_Proc  e% |- c. |' T1 v" W" e8 U
field.
$ v) X8 \/ u+ T% i" y4 [In fact, its purpose is not to load/unload VxDs but only to send a
* X) P& r1 \$ _" ]( QW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE), r6 [: u- @4 }$ E3 X9 V
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
% V* Y; |$ ~1 P3 E1 Tto load/unload a non-dynamically loadable driver such as SoftICE ;-).
# \5 Q! z! x3 P. {  cIf the VxD is loaded, it will always clear eax and the Carry flag to allow
( j8 F, B+ i/ q2 zits handle to be opened and then, will be detected.) z# N3 C% `/ K$ }
You can check that simply by hooking Winice.exe control proc entry point
4 d2 \) f' [0 k9 H* w/ Qwhile running MeltICE.
2 r9 p2 ], G6 f1 U
1 L$ ^8 U6 i+ v) p7 R1 g1 z/ G! J9 N$ R  q: [" [7 I$ ]
  00401067:  push      00402025    ; \\.\SICE
* y3 n4 w  F8 _; N& {  0040106C:  call      CreateFileA  G! ^/ g1 q$ M$ J! X& f3 y% [5 f
  00401071:  cmp       eax,-001
; _7 L$ M: d# U' K3 \0 f  00401074:  je        00401091
4 E+ w) ~4 _7 S% |( C) G5 ?6 Z
' k0 y1 {# ~) Q! j7 R; [2 N0 b" \9 I+ h2 E% a, Z2 L4 N
There could be hundreds of BPX you could use to detect this trick.2 i- n0 m3 Z/ ?) \
-The most classical one is:. @7 K* Y0 c6 s5 E6 e
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||% D, A; X* V) c5 B7 t
    *(esp-&gt;4+4)=='NTIC'8 {3 ]9 v) t9 n4 \% d

0 |5 ?4 n. |9 x( m* v-The most exotic ones (could be very slooooow :-(
. z' N0 C+ R6 c* ?" Y- j7 O   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  ! E* I: [9 ~5 T2 v' E- D
     ;will break 3 times :-(0 u3 J# Q+ k" u+ z4 H5 D

: [3 p1 I" q5 \" J# W8 B-or (a bit) faster:
: _$ W# C3 V$ V( m   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
5 \0 P/ {+ U/ a3 S! {# K
! O$ V$ h3 i; ^! V* ~0 p4 S" |' Y/ h   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  + X3 |! Y' y# r- D' z2 c9 U+ w
     ;will break 3 times :-($ b" X$ Z+ n) a2 {6 u  e1 D

$ v) I. Y7 [: v+ w2 k: s-Much faster:
" s" j4 ?# Y  x1 c1 ^   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'7 _. g7 ^5 k4 M! {" A
0 F' A& s1 v* }: Y2 o. V' B/ v
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen* j  P# `) f2 s8 }* X& y  S
function to do the same job:
' E- _8 @( `6 d: S- i- L" I* [% e; m0 i8 l0 X6 G; J
   push    00                        ; OF_READ7 d2 W. _/ w& [
   mov     eax,[00656634]            ; '\\.\SICE',0
6 `3 z) Y. @. t0 J   push    eax
8 e( T  |8 U% d4 @) F   call    KERNEL32!_lopen7 }- u% i, H( M2 N
   inc     eax
! {7 I! v' z1 l* |2 U: T0 o   jnz     00650589                  ; detected3 k; s3 t2 A+ }: m& F
   push    00                        ; OF_READ9 h* N  k+ y& Z8 H) `! g' e: s
   mov     eax,[00656638]            ; '\\.\SICE'
. r7 W; V9 @) `' x5 ?1 H   push    eax
7 j; P5 F/ c8 t  C4 |, J# h   call    KERNEL32!_lopen5 f/ v. H% R4 x
   inc     eax
) i6 j* E+ Y/ x) k   jz      006505ae                  ; not detected
$ ?! o2 r6 w7 i0 ?7 ?; T) [
0 t! W) y- A9 m6 |: Y& D' X0 [+ d" m. A* i3 C4 I  |
__________________________________________________________________________
3 i+ p6 W7 A$ F/ P
9 E9 J& ~# R0 J2 {6 R% g, b9 T3 pMethod 122 f; {: q) j2 B4 p% M0 `
=========
1 x$ F0 J! n% }5 F
! w8 R9 \5 Z5 w, P3 gThis trick is similar to int41h/4fh Debugger installation check (code 05
+ J2 A0 D! q" B3 ~9 W&amp; 06) but very limited because it's only available for Win95/98 (not NT)
- u8 B1 ]" f* ~' kas it uses the VxDCall backdoor. This detection was found in Bleem Demo.& W! c1 O0 e" @5 E
/ |- E% U2 j0 X
   push  0000004fh         ; function 4fh
$ w1 E& S9 n7 t   push  002a002ah         ; high word specifies which VxD (VWIN32)- t' q8 |! Q9 y, S. z
                           ; low word specifies which service
5 \! _. H. d3 Q# a: o                             (VWIN32_Int41Dispatch)
* {% ?5 R) O3 J+ F7 o$ V   call  Kernel32!ORD_001  ; VxdCall
  D% }, K. i2 R* Z   cmp   ax, 0f386h        ; magic number returned by system debuggers
: i  G! C9 M: M8 L! v   jz    SoftICE_detected3 Q, Z  F( ]8 z# y

: m: D$ G) g5 }% jHere again, several ways to detect it:
( Q! s" Z( L" [. b/ H2 T( ~) x# s* Z3 _9 k' q! z6 C
    BPINT 41 if ax==4f$ w  `# g. Q0 q

$ w% U8 m) I& K# q& \4 g    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
- C1 v7 `9 z% I: u* w( k/ ?
! D. ~" u3 P" E% g' U    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
: Y1 m5 ]! m4 P" F5 ?! T8 y, P# p
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
1 g0 i! ?/ w! v2 J" a; f
! z  t$ a2 |2 d0 m__________________________________________________________________________
  q5 I  T3 z2 I  Q
1 w; b; o! |$ e. j, wMethod 13
. s/ V1 c0 j) N4 u5 i  S=========
( C( J2 d; \# i9 M# B/ P0 e( F; ^3 d2 B
Not a real method of detection, but a good way to know if SoftICE is% z: b% \- i3 J& N' r3 C
installed on a computer and to locate its installation directory.
4 D4 ]! [3 i7 H; X, \. |  H/ aIt is used by few softs which access the following registry keys (usually #2) :
8 ]. y$ M' f# X
: n( D9 ^- c3 m- ^- t# |, ?-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion. T0 I! ~2 q% f+ C# o
\Uninstall\SoftICE5 C1 X# }; b( h
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE9 U, ~8 P6 w% \% K, F7 O3 U5 m
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
/ F& ]: _5 O/ N$ z3 k\App Paths\Loader32.Exe
' Q: }) E: K* }) M. {" u
  }% n* l& b/ _+ j5 ^6 K% e
9 L7 t0 y& y" ]/ v# vNote that some nasty apps could then erase all files from SoftICE directory
2 A( H% M, z* _. L  g(I faced that once :-(/ ~: f6 v$ t2 z6 l; l" c' I
2 k6 e2 m1 |! y0 @6 i4 b% U- a: n
Useful breakpoint to detect it:
) G$ b# }& W) L" o' ~, U/ l2 U5 Q. G- A/ l) [, }% r* f. D$ ~
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
; f( A4 O- A3 v/ i2 N: q6 E8 i4 \' X* |7 I- e5 Z( P& \, F4 q
__________________________________________________________________________: i0 h2 f2 c) c1 J1 T2 n
/ W7 w5 t/ B+ x5 C5 c4 Y4 i

: R  K; W. U8 t! ~' OMethod 14 # p5 j" Z5 E+ H' S
=========( l7 @& [1 n" y9 ]0 [8 @7 s7 ~
  i" t# h* w& l
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
/ t; ?+ O9 I1 Q2 ~is to determines whether a debugger is running on your system (ring0 only).: Z. w  ~0 @- K% l+ s
3 @: ~1 H' M& e
   VMMCall Test_Debug_Installed
8 Q$ n% A2 G7 ]" S   je      not_installed; z8 M2 @' q0 v8 Y' R0 O, t5 B
0 @7 v, X. |0 R: E/ v
This service just checks a flag.: E; T/ V9 S/ N
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部