About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
( J/ S# ?7 G" ~* p1 W<TBODY>* I5 l& |0 f; B1 N( z, D  Z7 W* f
<TR>; m* w1 c# z2 O! Q0 g
<TD><PRE>Method 01
1 }# J  t+ b0 V3 ^; j=========+ Y3 P8 |; V, {

6 G! d0 |: C% `3 e9 FThis method of detection of SoftICE (as well as the following one) is
5 w  n- |$ V) f; jused by the majority of packers/encryptors found on Internet." v* l1 G( m. I) X7 n6 C
It seeks the signature of BoundsChecker in SoftICE4 D4 p1 R. y/ u$ u; y( {. h" o

: [/ ~' R$ _( @# y    mov     ebp, 04243484Bh        ; 'BCHK'9 c6 h; r$ i* t! H/ l; E, I
    mov     ax, 04h
# C; F! V* O: e0 E    int     3      
  v9 ]  k5 u/ p6 O) z    cmp     al,4
' U% h! }2 D/ }1 _, f6 U    jnz     SoftICE_Detected5 E" |, K% A8 w2 X
) s$ l8 d8 w$ J, J4 R
___________________________________________________________________________# K! N- S3 H" ^  W4 p

) z& {* F2 G* t$ tMethod 02
7 a- ?3 [, h3 P=========
$ k) @$ L( Y; Q( j' U
% ~  A5 n% ]7 W  k. E0 YStill a method very much used (perhaps the most frequent one).  It is used
4 k, o/ G# }. ~to get SoftICE 'Back Door commands' which gives infos on Breakpoints,4 C6 m- }3 m" a0 p0 z" @
or execute SoftICE commands...- H2 b8 V2 C! ?+ z) Z
It is also used to crash SoftICE and to force it to execute any commands# I) U$ f7 _6 N! M% O: t0 j
(HBOOT...) :-((  
! c+ A! h2 ]5 v9 u7 l- f) ~3 S  m( ^; |) k* J
Here is a quick description:, B1 X" Q5 W, c0 j  M9 c8 w
-AX = 0910h   (Display string in SIce windows)/ Z" H, @( c( I8 A3 ?+ C; {6 P1 L
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)' d* f  `; P- P; k/ q, S2 y
-AX = 0912h   (Get breakpoint infos)% [: B* Q" @2 F9 {5 @. _. P
-AX = 0913h   (Set Sice breakpoints)) Q* p4 H2 ~' B# d: V
-AX = 0914h   (Remove SIce breakoints)9 N+ y" h5 [5 {

$ w9 w4 {" S9 R6 wEach time you'll meet this trick, you'll see:$ X- u% i' D" M. U
-SI = 4647h6 R" t, c, _& h( C. [* |2 q# {/ Q! r
-DI = 4A4Dh
  q( ~) l1 u. c, CWhich are the 'magic values' used by SoftIce.. ]# w8 Z6 Y$ [4 c" ^
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
* U; ?. C/ w$ t! f7 H' e3 e" u) A$ T/ R5 c  V9 S
Here is one example from the file "Haspinst.exe" which is the dongle HASP9 Z- _1 w+ L: A- Z$ h1 m9 C
Envelope utility use to protect DOS applications:1 F& z! H$ L9 \4 j3 Q4 K! c
' }- ]) x+ ^* p/ T

9 z% v* |9 G( c/ f! L# M% [' G4C19:0095   MOV    AX,0911  ; execute command.
* m: ^3 F4 G1 U. R% ]4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
0 f0 @$ {# O. u3 V0 U4 B4C19:009A   MOV    SI,4647  ; 1st magic value.: \$ l2 m4 T8 i
4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
* E7 r' v9 {) [7 [6 F4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)6 W& g& W3 r8 f& w7 Y$ G
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
! D$ O0 ~8 G* \9 M" y7 R* k4C19:00A4   INC    CX- B2 i# S0 o2 ]) r
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
8 Q. c7 O) Y. ~# I' p4C19:00A8   JB     0095     ; 6 different commands.) w: o3 S3 X' e9 u9 L- l0 K5 X
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.: f. F8 o9 F/ F
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :): x2 N5 l- C0 |$ B( ]8 D1 m% J' A+ y2 z
9 V( R0 _8 K; N) Z" C
The program will execute 6 different SIce commands located at ds:dx, which
1 ^: e; Q/ m7 K7 q5 S5 \are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.8 S* L, ?( W& ]8 C  g& P
% i  f8 i2 z& r
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.* G  W0 Z4 [5 r" l* i: U; K
___________________________________________________________________________& {% B- \; l5 k/ p1 ~% a! r
1 m& ~+ C+ X% Z- f! n  S/ V
7 u% d* y! Y( E8 b4 O3 y& F- `2 G
Method 03/ Y4 ^( _. }, U0 p: n4 C( {
=========/ ~1 R$ K8 f  c" A" i

  c  Q$ n* Z8 g$ R2 LLess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h" N2 S) }1 w2 A+ j; _
(API Get entry point)- M8 z$ r, B8 \4 d
        
9 o5 w2 m  h$ A: j2 z1 L  A& i. n9 w  I' w
    xor     di,di3 k9 I% }! ?4 t3 Z
    mov     es,di* O7 x) c$ A4 ]' V$ V$ F- Q
    mov     ax, 1684h      
+ @# [1 p' R/ @* F& O- _; j    mov     bx, 0202h       ; VxD ID of winice
1 c1 j- m4 x4 @% [1 O$ K2 Q& a    int     2Fh* y" x  b  f6 x  ?+ ^8 v5 I7 g! A
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
& g9 ~/ A7 `$ p2 q2 f" z, Z6 T' T    add     ax, di
' I& c* D7 [( Y2 ]# Z/ Z! O4 y    test    ax,ax$ A3 b9 B' |( ?/ N7 ^
    jnz     SoftICE_Detected( M: B, \# d9 D* L9 ?

$ H8 ?2 n" H# I3 \* z" d0 u5 |4 n3 G___________________________________________________________________________- v# j- B. y) u4 G3 _
% D, B5 l# X! G3 O1 Z
Method 04
/ {" H6 ?+ d& c9 h( G3 h" u% G3 I) r=========
$ |# h1 w4 z! X1 P5 n) E9 t0 K# H: n& ?/ y
Method identical to the preceding one except that it seeks the ID of SoftICE( J8 a+ F$ S# ]$ v6 X0 ~
GFX VxD.8 i6 S1 s" p; ^- J

9 _5 Q1 a3 C  S% B+ O+ Y, S1 h. T    xor     di,di  ?0 e  b3 _; Y6 P. g; L! J3 F
    mov     es,di; a4 r6 E% J$ X7 B, w
    mov     ax, 1684h       8 p7 O6 D& K( g( a: n% c3 ]" w
    mov     bx, 7a5Fh       ; VxD ID of SIWVID
) f( X9 M& S3 p2 E    int     2fh
! q! ~7 H7 W9 \0 g- J) ?0 V( C    mov     ax, es          ; ES:DI -&gt; VxD API entry point! u% }- R# E  z! M8 _
    add     ax, di4 k6 a  }' f% g: p; a: {
    test    ax,ax
. Q8 B8 g& u( |7 ~% d    jnz     SoftICE_Detected$ l& h- x% B# A# B6 g6 c

1 h  C, \) G% y1 C, F__________________________________________________________________________) ]) E8 l) a7 x5 F! I! d
2 a2 y5 y! X8 O" s$ [

: a# K. Y% \+ K8 m0 e/ n( C! @+ m  UMethod 05
& x$ p8 p* R% X, D: r9 T4 P=========
9 A/ C. T# R5 X8 p1 i# e! N
3 K# |4 }8 F: v6 z1 oMethod seeking the 'magic number' 0F386h returned (in ax) by all system; n. f. D4 L. @
debugger. It calls the int 41h, function 4Fh.1 V, N& r# x, B* `  H* D8 ~
There are several alternatives.  1 Z; z% z0 [5 A  I, Q3 c
7 W9 ]: w% g9 Q& ]) w; m  z4 Q' y
The following one is the simplest:5 }. l" e0 S  C3 d2 _% P  F" K

6 ]0 [( D" ]0 B: W9 X8 {! p    mov     ax,4fh3 ]4 e) L- k# _; c. p, v
    int     41h' p. I. `" |) N7 W/ Y7 _
    cmp     ax, 0F386
/ Y4 x7 `: N8 K3 M; k    jz      SoftICE_detected
7 d, n$ S. R! q: E# }
# g, f" ?% p0 L) ]% N2 w, t. |7 w% j" z
Next method as well as the following one are 2 examples from Stone's
; `6 _3 W( [7 w9 r4 t"stn-wid.zip" (www.cracking.net):
; `0 a  s0 U! F* a  p1 G
; S. m) l' I; v    mov     bx, cs
% u6 m" [& m2 g3 Z( N( m! U    lea     dx, int41handler2
! [6 d+ r: X/ j6 b4 L( H2 K    xchg    dx, es:[41h*4]
6 f5 r# C- A% A, \/ x( y4 e! |$ v- U9 F    xchg    bx, es:[41h*4+2]
/ J' d& I2 {/ t7 R; [  s2 {    mov     ax,4fh, |# I3 U3 o2 \1 b5 }4 p9 t
    int     41h
4 b) V/ n3 [! I& m( D    xchg    dx, es:[41h*4]
" f+ Z! P8 ?- k4 [, p, W$ }1 P    xchg    bx, es:[41h*4+2], U3 v# F- h7 B' x0 i3 x5 E- i5 P
    cmp     ax, 0f386h1 D/ d* e. L9 l$ E3 Y+ e
    jz      SoftICE_detected
/ c" y6 p9 s/ T1 r+ L+ [+ g1 \! m( p$ ~. T4 q. t+ g
int41handler2 PROC
) X$ G; h4 P# h4 V1 j" r2 C    iret
$ W  W! }( ?4 {3 i* i: Fint41handler2 ENDP
- q9 \. ~& q; [6 R
+ [2 X8 |% T" i) g8 ^9 X8 `# ]9 m: B3 A, }; |: E" c
_________________________________________________________________________
" K# s! D/ |. g% B7 n) m2 U, v' }$ _$ b+ A$ K- n- r( y, a

4 ?$ ^8 B/ q9 ]) l) YMethod 06$ v9 _( `- f0 o% q# e& [# d
=========+ T$ o; [7 x, r' d/ q8 r
, V5 k8 ?! {3 U6 `2 a3 }) ?
; y+ j1 r* X0 k: e- W
2nd method similar to the preceding one but more difficult to detect:
/ |! k4 M* S# h3 k; d! l; R
) v- @7 p1 V  f9 n: V/ @, o8 Y$ v" d0 v
int41handler PROC5 l, u/ _+ r2 n- C3 I1 ]- y
    mov     cl,al
3 t- y+ ~& I6 ~' D1 j* z    iret) m% |9 D# _3 h3 t- C6 j2 l$ e
int41handler ENDP
  Y2 L: T" ?1 }; t
) I' V& o, f  K! I6 C8 |- D, r: J6 ]8 x: k& i
    xor     ax,ax/ v! D' @+ O% C3 R
    mov     es,ax
5 H. s) F4 O0 R; m    mov     bx, cs
  a* s: u, ?& l* k    lea     dx, int41handler
( u$ h. p# _/ o2 }; b    xchg    dx, es:[41h*4]
& h; L# e# B( B, \    xchg    bx, es:[41h*4+2]
3 y( h* j* L/ r    in      al, 40h
0 {( N2 s/ \' \  c    xor     cx,cx
; ]8 T1 J3 t% U, m; I8 ^    int     41h
* t: t  ?$ u0 u7 E& m+ t9 d5 @, R7 _    xchg    dx, es:[41h*4]
9 c4 Z; G6 C# }6 s! V7 ]    xchg    bx, es:[41h*4+2]
9 r7 v# ^9 [( l% g* S$ f/ I7 Y    cmp     cl,al1 F! h* ]' K- |1 d4 m
    jnz     SoftICE_detected1 q7 X+ F7 F- I5 \7 u( K5 Y
0 A- ?3 U8 N+ L) _
_________________________________________________________________________/ \* X, t" |( ?, w  O! m  ]0 `

6 m8 f, p3 g2 \: {$ QMethod 07
- {2 f2 q! i6 f: ]=========
; b1 K# k6 m- b7 }$ U) v! |
; a0 P5 Y: o" Q$ t& a' @Method of detection of the WinICE handler in the int68h (V86)
/ F( ~- Y' [8 {: O( V
$ j+ Y3 M) j* G, y$ [" P* Z* {8 |    mov     ah,43h
4 P# w9 o9 g- \+ k6 Y5 }1 S    int     68h& s" y3 Q! N. R& x4 F* |
    cmp     ax,0F386h
; N* W$ U& ?' b( ?    jz      SoftICE_Detected; G9 p' C7 A3 E2 N6 i" J

$ z1 l7 p7 ~% u$ J5 d! G
, A. [6 M& I( {2 D=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
4 _3 a+ r# |/ h2 w2 f   app like this:2 t( ]' `- s: p

0 u# x# Q4 d( k$ d) G! z/ z/ Y" l   BPX exec_int if ax==68
& g8 U! g7 w2 l- |6 y8 Y2 O, S   (function called is located at byte ptr [ebp+1Dh] and client eip is; d: ?+ N7 R1 m) u4 u& A+ a
   located at [ebp+48h] for 32Bit apps)
6 W# F9 @& q* i__________________________________________________________________________
2 ]0 M5 c/ y; p8 ?* d3 Z  S3 M, C' l& F6 M2 w
& k- `! U$ g" y8 Y6 r, Y  Y
Method 08
7 D  r. N9 ^% @9 _/ K=========1 |+ u4 N" Z+ e0 J: g8 u

+ ?2 ]# j/ m6 V5 n4 W- d8 `: rIt is not a method of detection of SoftICE but a possibility to crash the' M' ~5 K; {  ]% Q3 L! b! y8 ~1 K
system by intercepting int 01h and int 03h and redirecting them to another
4 x% s- m: c) K$ X! xroutine.& H  g7 _+ X0 Z0 g) D% }6 L& G2 T. R
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points3 S  E' {  F- p& k2 y# @% P
to the new routine to execute (hangs computer...). x4 R  x% q1 i( r- Q: n, P

$ |5 v3 z% h: \. p    mov     ah, 25h
) E6 K" A! g; M- M# O& n8 g7 {; U    mov     al, Int_Number (01h or 03h)& f. J% q5 I2 o4 Y9 S  f4 \
    mov     dx, offset New_Int_Routine- u( ^# S. v4 A# v: p% x
    int     21h* U  c, s8 z8 @+ N- G
; K/ I2 A" h3 e6 U9 ^! X# b+ t) P
__________________________________________________________________________
* M, f" r; }" P- O# D4 J; L* I: l# b
Method 09
2 I* k: e) r- N0 j" T=========$ ~8 o! S: k* e" L# l5 n- }2 L
: t8 j6 \% S4 t$ p* `4 |
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only: n" P) B- C  E8 Z$ W5 X, x, G% |
performed in ring0 (VxD or a ring3 app using the VxdCall).
6 g( V; R+ {  u0 h4 rThe Get_DDB service is used to determine whether or not a VxD is installed: Y5 q6 G- d* D" H' [$ T
for the specified device and returns a Device Description Block (in ecx) for
1 g  X( R( S! |5 e: W( tthat device if it is installed.! x8 m( G; ?& I  y- g6 ]

4 {  ?$ L. a9 Y   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID6 J! N" _. h  m& r( ^2 f0 y; x
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)' Z* s) m, @6 E( a9 z
   VMMCall Get_DDB
+ r) Z& I& ^3 ?# \! K+ b, O5 l' D   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
) p/ l) _, b7 t2 c0 n: [+ C; u: N4 L3 x) R7 i# o
Note as well that you can easily detect this method with SoftICE:: q9 F' ~& D. O8 f: V
   bpx Get_DDB if ax==0202 || ax==7a5fh
2 @' w& g' Y( B) ]
/ k' W3 x% [7 V# y' k6 ~( _$ h__________________________________________________________________________' P3 C- s5 Z6 U8 P

8 b* s, {1 z* dMethod 10! K) ~& p2 _& ?5 C9 g6 d
=========
5 _  _! `7 c$ g6 r+ J
* C9 ~) m8 A5 G, @; O=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
' z$ c8 W; p; y! C4 h  SoftICE while the option is enable!!
* Y- o5 F' x! @! T3 N- W, K$ k% ?+ ]' d. B6 G* S" d
This trick is very efficient:2 L* O  Q' d# h4 I' q- q# K! y4 M; B+ }. }
by checking the Debug Registers, you can detect if SoftICE is loaded
! M+ k* Y! U! }% k8 }' u(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
4 Z# M, \! j2 m0 r  T: {  ~there are some memory breakpoints set (dr0 to dr3) simply by reading their1 r) e0 W! c" j& z- Q, U
value (in ring0 only). Values can be manipulated and or changed as well
/ y; r6 ]! f* w! B; o- z(clearing BPMs for instance)
' y) d% J) a. g6 Q1 C5 C# E) i* W: x7 C' d
__________________________________________________________________________' d5 u5 b2 \- [8 M: y; d; v( R
& k7 m% t! I: E; N- g
Method 111 L- I; o8 c' [: P, i
=========
" I$ k% O, `" z. t
  K6 L$ s+ C$ e; j9 BThis method is most known as 'MeltICE' because it has been freely distributed9 C$ |( P4 ^! H5 w9 j
via www.winfiles.com. However it was first used by NuMega people to allow
2 w* c6 W. e3 x1 G4 X+ TSymbol Loader to check if SoftICE was active or not (the code is located* z& u! \! {3 L' H5 m% G
inside nmtrans.dll).
3 v+ B& V) Z4 L' J3 F- v
* a" M* @4 m& y3 [, HThe way it works is very simple:
. A( }9 p$ _# |. eIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for9 b$ |+ N" N! ]2 b# }4 ~1 B+ B
WinNT) with the CreateFileA API.. C5 h0 k9 H9 w' F1 \: R) I# ^! H
# B. _, ~/ Q8 l! l
Here is a sample (checking for 'SICE'):* E) v' x: S( r

# b, ]- ^7 M2 G' zBOOL IsSoftIce95Loaded(). Z  g* P6 M/ d# q
{+ x+ X# l! J8 E, {* q$ |
   HANDLE hFile;  9 g9 _. _5 r0 [5 D+ r
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,$ E2 \) ?2 @( M
                      FILE_SHARE_READ | FILE_SHARE_WRITE,9 B. m, y- H: G  s$ B
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
9 w- n6 v% X9 [4 D- H& X# Q8 b: J- _   if( hFile != INVALID_HANDLE_VALUE )- L7 v, ]6 J; J: W9 D. u) g
   {
1 s& y) R! V* g      CloseHandle(hFile);
4 }/ b+ l" W- F/ R# q' X      return TRUE;
( D% x' M! c, G0 k, p% V& ?   }
9 @, ~$ H4 K, ~$ L8 M9 q( u* W7 h   return FALSE;
8 a; F+ J6 F  ?) C6 h$ v}
  T, T, H- z5 P& Y2 _& }
! X) m3 ^/ F, w6 [2 uAlthough this trick calls the CreateFileA function, don't even expect to be
. D# Q. x  E2 b. wable to intercept it by installing a IFS hook: it will not work, no way!
# [  n. d4 }# ^9 C* bIn fact, after the call to CreateFileA it will get through VWIN32 0x001F- g+ a  L2 k) c" X( _
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)( C+ x& j9 N3 s8 e7 o& m3 n
and then browse the DDB list until it find the VxD and its DDB_Control_Proc! i' `8 X  B: Q; x( V' C9 j
field.- ?$ h" H- B& Q6 j$ x" p! k
In fact, its purpose is not to load/unload VxDs but only to send a # [6 D; B0 y" H6 n* N1 I* [
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)( [' G( P8 r- J
to the VxD Control_Dispatch proc (how the hell a shareware soft could try0 m6 `. J$ g  I. C" H- n
to load/unload a non-dynamically loadable driver such as SoftICE ;-).5 K  E  t; r, Z7 h9 I
If the VxD is loaded, it will always clear eax and the Carry flag to allow, b2 X5 \6 j  G  n& i1 _3 N# F
its handle to be opened and then, will be detected.9 f4 H$ w/ o# @- S
You can check that simply by hooking Winice.exe control proc entry point( \: j) y! r/ ^" r* w+ y) }) {
while running MeltICE." |; P$ [( i9 r0 d% S/ m

7 ?4 ?; P5 n2 a
7 ?" s0 b4 T9 q5 e  00401067:  push      00402025    ; \\.\SICE9 {0 M3 g7 w1 f9 X( p& @
  0040106C:  call      CreateFileA& j3 v" Y% q2 |$ b0 m. u1 e
  00401071:  cmp       eax,-001
- @) _; I! R6 k# G  00401074:  je        004010915 S8 `6 L) S; k+ W' E. n
3 z% b; {4 r! K# E
9 W2 M# W' |3 b2 X
There could be hundreds of BPX you could use to detect this trick.$ K1 }. r7 O8 ?/ t+ w7 S4 e
-The most classical one is:
" g. j4 n0 a1 E4 Z+ m+ M  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||, I4 F) K& R  R9 h6 X. S
    *(esp-&gt;4+4)=='NTIC'" w3 H! B, T) _+ Q5 g
+ t0 g  m; N+ Z% p* `( D( L
-The most exotic ones (could be very slooooow :-(
. i9 u% }" w* a9 S   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  1 e5 q3 b* F' R6 w, x: C
     ;will break 3 times :-(9 p* ^4 K# Q2 M9 Q( z( X1 \

6 a, h4 m7 C& l: r2 n/ e( n-or (a bit) faster: " w  F& A6 p0 M5 ~0 N3 e# k
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
. ?3 K3 X4 Y( t  }1 u/ j# E! `6 }5 _* H
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  : c5 r' i3 C! S& ^0 d: N/ b
     ;will break 3 times :-(
) M2 A. f( i* I# d5 A; X) g5 E/ v. [9 F! V1 d2 ^
-Much faster:% Q* u" o4 x1 J8 ^& ~
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
" m0 V# [3 B! q% X2 m! E" a
0 D# i  k' H' W# O, KNote also that some programs (like AZPR3.00) use de old 16-bit _lopen- p2 P5 I0 t. b; z% w& o) j
function to do the same job:4 |2 T2 r. q& V" `4 f: H2 E' C
$ `: q1 ?, }$ p) h# ]
   push    00                        ; OF_READ
4 Y6 w2 g4 a+ y7 Y   mov     eax,[00656634]            ; '\\.\SICE',00 s6 u! F9 ^* o+ M. C2 l  f/ U1 i! v
   push    eax
' J. R* X8 m* v/ i5 _   call    KERNEL32!_lopen7 [. Z; N/ ^. w
   inc     eax
& l* ^/ v9 L, {% g4 k; k   jnz     00650589                  ; detected8 }( [% Y9 l+ s, n5 c4 x  g
   push    00                        ; OF_READ
1 F3 w4 v8 }+ p, V0 U, i2 T   mov     eax,[00656638]            ; '\\.\SICE'
: F9 I& Y$ @, u   push    eax0 O; B2 L( x# ?. F
   call    KERNEL32!_lopen
& x  l- N7 @4 h3 Q5 ~9 k   inc     eax
1 W8 h  I6 d' h6 t; R0 [( w5 Y   jz      006505ae                  ; not detected
: F1 Y2 @$ k1 B: f1 G
" Y4 }. D# N$ ^: J" R" K
  U- i1 S5 [: F. C__________________________________________________________________________
# k% V. n+ ^3 ?8 m5 _/ `6 r7 ~; }9 `, O- G# l  O
Method 12
9 s- Z! O# w; N. J* y/ L" b, q=========
& ^- x  z) L& s! @, ~/ L9 f( @% B9 f& T
This trick is similar to int41h/4fh Debugger installation check (code 05
0 n4 U% E5 `% X# G5 M&amp; 06) but very limited because it's only available for Win95/98 (not NT)$ ]! Q4 U3 F5 ?* o
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
3 Q& T1 t2 g$ U2 H
6 E2 A  K1 F' W! Z9 ^   push  0000004fh         ; function 4fh
1 L* }: f4 |' i7 G/ k   push  002a002ah         ; high word specifies which VxD (VWIN32)
1 c: U0 N# d1 G  Z; O1 {; `. B. C+ i                           ; low word specifies which service
! z; o* Z/ J  v8 L3 s                             (VWIN32_Int41Dispatch)
, s* i! I- ]' z   call  Kernel32!ORD_001  ; VxdCall: L$ O/ k9 n1 \( v8 K
   cmp   ax, 0f386h        ; magic number returned by system debuggers
. L( z& c. C& P' Y' p   jz    SoftICE_detected
0 K( P, Q: i2 w& ]5 a, }1 Q
1 U, ?5 c% ^" p3 w2 F! C' eHere again, several ways to detect it:
! h6 f1 K  P  J3 @1 f$ Y: O, x
  x% G. ~1 X7 ], P0 p' [' ^5 R    BPINT 41 if ax==4f
, U" w: g4 D. }3 m# \5 ^. F
9 y2 j8 q/ i. x9 o1 ]$ W" ?    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
0 j+ d+ z# n$ U+ b1 E# |: D& k
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
6 F. a9 `) Q8 J0 f4 g; p9 ~* @  K1 O- S* D! P( B' X- x$ S0 P
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!2 y* L% `' f$ O6 f3 Y7 b
& a9 Y; I" T- w+ }8 o
__________________________________________________________________________8 r8 W# `% }3 E; U) L

. z$ t- n: t! h3 R; `' P0 LMethod 13; B" u  Y' Z. X2 X
=========
- O/ [0 o' B. c# v/ Z( S5 R& z9 l
Not a real method of detection, but a good way to know if SoftICE is
  w1 G# ^; m; C1 zinstalled on a computer and to locate its installation directory.: Z5 F0 K; x! h. J5 b
It is used by few softs which access the following registry keys (usually #2) :; d& u3 x) h/ |) Q
$ P9 h- {* {8 v. D
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
# Y- y" Q+ Q- T1 v3 k, M9 _\Uninstall\SoftICE
' B  K- D% D. ^- t- q7 w-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE( t! J9 t: Y' T9 c; W; m
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion: |6 R! v9 |6 Z: a
\App Paths\Loader32.Exe
, w' U% h3 u( Q! i! g2 s+ s; g* {! X8 |

: k2 [; B( u* r4 tNote that some nasty apps could then erase all files from SoftICE directory" x: r  ?) o  ~
(I faced that once :-(
+ |5 i, t+ v; {6 ~% A
! E  I! \" e: \. @- S( CUseful breakpoint to detect it:
1 |+ t  l! K/ Y# r* l; F9 T. P
1 u! z2 Z- A8 N. L     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
8 M, i3 z: z" ^6 k7 \; n: Y3 Z( j1 r" W7 \. e  L, `
__________________________________________________________________________6 }' V: u3 _1 [, U6 g7 q

/ T. H. T. W/ f6 u3 w5 G
; {4 d. q: J4 o" w2 |) tMethod 14 3 h$ r2 c# [' Z; R& g: Q; q
=========$ P7 I2 P$ D( J. D$ m
! Y$ E5 }- I4 E2 ^3 l
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
$ N' y# e5 L: X/ E8 W0 J3 r0 Eis to determines whether a debugger is running on your system (ring0 only).. c8 ?! I$ g. w$ n9 m
- c' l* e3 D: z% [! q& w
   VMMCall Test_Debug_Installed
2 S8 d" R% Y# Z   je      not_installed6 R6 l  i, u- O; Y6 C, h0 z

& ?8 p! z* K& n9 ^- C0 e% qThis service just checks a flag.
$ P( F' r4 e% Z, O# u; u6 J' a. k</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部