About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>) c9 N$ v3 Y$ K; V
<TBODY>
* Y* v( N* e& @* P# Y" [( u3 T<TR>7 q1 W! G) e* W, X; _4 L
<TD><PRE>Method 01
$ Y3 {8 e( }) ]1 C: S=========+ k0 e& r' p. [9 R/ @2 {7 {6 P% M8 Y
5 }" _+ a) U- ?
This method of detection of SoftICE (as well as the following one) is
. j$ @4 m% g1 N3 {4 f+ Wused by the majority of packers/encryptors found on Internet.
0 O  G6 h7 {3 }. E) U3 X: {It seeks the signature of BoundsChecker in SoftICE& _' |" B. z( i# `! ]8 p

/ i" a! M/ j  e    mov     ebp, 04243484Bh        ; 'BCHK'5 T! i4 v6 _/ o9 V9 q
    mov     ax, 04h
* r  c4 n  q, f    int     3      
) x- p& i$ Q% O+ \: s    cmp     al,4
% M: a* Y* m7 _' N" t( l    jnz     SoftICE_Detected" c% Y- D& f$ E

' \, f$ i% D, S8 B1 ^, B8 G___________________________________________________________________________
; a* E5 f0 W3 w* @: w- }( v3 I! ]. U8 r8 \/ A
Method 02/ a4 W1 @1 l1 F7 ?
=========
8 J, s. T9 L- O4 @$ V! T6 `' D* \* h; R6 C7 r2 L9 b+ n
Still a method very much used (perhaps the most frequent one).  It is used
/ @- C9 l1 b8 D5 f- f7 N/ Pto get SoftICE 'Back Door commands' which gives infos on Breakpoints,9 M. @9 p! o3 r
or execute SoftICE commands...
5 {2 ~& t* S; Q2 ~$ `/ W8 GIt is also used to crash SoftICE and to force it to execute any commands
; K$ q  }$ L. u; H1 H% T(HBOOT...) :-((  1 C( f9 E  w0 @, @. R
' N, H8 I, I1 g
Here is a quick description:* a% @0 I8 H: V! f" W8 V. b
-AX = 0910h   (Display string in SIce windows)1 o* j/ _+ G0 |
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)3 W+ q6 q/ _6 A7 B) q2 ^% n
-AX = 0912h   (Get breakpoint infos)
/ C5 l- X1 |( g/ i-AX = 0913h   (Set Sice breakpoints)$ C1 V3 n- s3 N* i! j5 A; K
-AX = 0914h   (Remove SIce breakoints)
- }! x& @/ W2 H9 {2 B, ?. A- g& [5 w( v2 V- t0 F9 I  z9 ?# y
Each time you'll meet this trick, you'll see:
$ |( A' [9 H2 i* F7 [$ ~: _2 N-SI = 4647h
' V" @5 }- V0 `$ j8 }-DI = 4A4Dh
7 Q9 W' n2 p: _& S" x; f7 uWhich are the 'magic values' used by SoftIce.0 ^5 {% Q6 m1 _: w$ a
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
4 O+ |; @3 u$ h- B/ @9 o; c( R8 a  `! J; H3 @8 q& J) M
Here is one example from the file "Haspinst.exe" which is the dongle HASP) t8 R  `- w8 l- a$ i" R: }2 c
Envelope utility use to protect DOS applications:3 v0 b/ \' K4 ^
3 |8 j7 ]3 h9 J
+ F: l/ c. ]& s
4C19:0095   MOV    AX,0911  ; execute command.
. J* b8 @8 C' o# L1 M7 c- i4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).; y$ l7 y0 A$ e1 @8 S# u' R
4C19:009A   MOV    SI,4647  ; 1st magic value.! k* q8 I: Y0 P
4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
% V5 d  e% I' s! p$ Q4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
$ i# y1 ~6 F4 T  p/ I" _4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
& I/ M, q( ]! d, a/ L- J& a4C19:00A4   INC    CX/ V8 F! y3 m6 _" }. Z1 Y2 N
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute: U- r, R% x. E- w* e3 U
4C19:00A8   JB     0095     ; 6 different commands.
0 B0 {* _$ V  w5 |# R4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
/ h! T7 j7 G  u6 U- D4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :); L: m8 b1 _' O9 m: u1 c! P& M7 B

3 r9 f7 k; X/ l1 N3 W- jThe program will execute 6 different SIce commands located at ds:dx, which
5 K% Y& u0 e& g( t9 U2 Nare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.! a/ \2 s& [1 D$ F9 z( V, K' A: w
/ g& y+ w: N+ g7 u; d
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.+ L* u( |( F0 d$ _- a. s
___________________________________________________________________________
! y6 ?8 ?- n+ r- b
8 t) C# i: t5 @( H6 H8 R$ |7 y/ N/ a+ F; c
Method 03
- E" C6 }4 P( t* k  L4 T  z8 i7 U=========
6 y5 B( L5 E$ x8 _1 Z7 `5 D
  |8 r( g$ w8 qLess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
5 c8 P0 \7 ]0 n+ f(API Get entry point)4 c9 T: a$ @. F0 n0 Q6 h
        
4 r$ B; R4 J! z' H" A+ q4 g4 w6 v+ G# y5 ^
    xor     di,di7 n% V" i) _, ]* f4 [" M, S
    mov     es,di' ]( f! {; x. h" k5 F' `( G
    mov     ax, 1684h      
. W% r' t/ g. _* ~& V  Q/ [5 @    mov     bx, 0202h       ; VxD ID of winice
. u0 n6 p8 c, E( ]    int     2Fh
( X8 g; s7 n. a; f0 m  M" O    mov     ax, es          ; ES:DI -&gt; VxD API entry point
$ j4 Y; A9 _- r# w9 D* M    add     ax, di% |) [9 C: |: e7 ^4 b$ D2 J5 r
    test    ax,ax6 i# t7 \' V% B% I
    jnz     SoftICE_Detected
+ N; ~# p  r, p4 ]6 M* S7 V
) f; u6 Y6 H) P$ ~___________________________________________________________________________7 E, ]& _3 }# a: }+ E: O

, i. r. T6 d; Q3 ?( M# OMethod 04
# j  M" L3 [! _- R) |0 ]=========
4 Q- k6 U( N6 D, X  P" T' n  V" o. c% d, k) T) ]; @
Method identical to the preceding one except that it seeks the ID of SoftICE
) z7 R" g( u' a% z. H2 P9 {+ k3 I- IGFX VxD.% d8 z' {' k1 v2 n4 N
" t$ w  J/ |4 |! Q4 ]/ Z. \
    xor     di,di" A1 f& o8 E4 n# C1 J/ D
    mov     es,di
' w' G- X3 P- v7 B. O    mov     ax, 1684h      
0 H7 z, G  R( `: |  [1 I% H% u    mov     bx, 7a5Fh       ; VxD ID of SIWVID
6 E3 T$ Q+ j' _% m: g. w    int     2fh
7 t4 c. h$ d* E& j8 t0 D$ O2 R+ \  c    mov     ax, es          ; ES:DI -&gt; VxD API entry point( I( t$ h3 y) S& A6 M0 c8 e7 k
    add     ax, di: ^/ }- ?! w5 S4 e: }
    test    ax,ax" L5 h/ G) b0 b: F1 M5 V
    jnz     SoftICE_Detected
/ |% e& X2 l. ?8 N0 m- [4 K. n2 H7 u) `4 h- n
__________________________________________________________________________& U* }) ]; j+ u+ `, o

5 ~+ I6 W, y& \. F& o
% t8 I  s: y% X6 n) UMethod 05. f: q/ n2 L0 E  J' u
=========. f) G. |) U' N! F

( C# l9 e( d: `3 F& m' RMethod seeking the 'magic number' 0F386h returned (in ax) by all system$ P. o( q" g, u3 R( g" X- S
debugger. It calls the int 41h, function 4Fh.% [) \( G) O* s6 D9 d7 V7 w' g3 u
There are several alternatives.  ( ^* D! Q% s2 X3 o& T0 R
; I& h* n& f' E9 v) g7 ?; Q6 r/ c
The following one is the simplest:
# u9 j, l! \6 c& t, q; h4 V- ^  N4 _# j9 ~. z4 ?* L
    mov     ax,4fh
' J0 _0 _7 d5 E; J. J. S$ O: E* ?- T    int     41h
! f: @8 A2 n& F    cmp     ax, 0F386
: c5 \% M4 H5 y% a. b2 Y' ~    jz      SoftICE_detected- j# F! P9 p8 r2 @

; F+ H, i  M# f* Q( w2 N1 o
0 e3 {) a8 ^+ }" qNext method as well as the following one are 2 examples from Stone's 4 o# e9 x: ~$ }
"stn-wid.zip" (www.cracking.net):
; @# j/ a5 L; {. \' p" t  J* e
. m4 w7 T( ^+ P! s; W- \    mov     bx, cs+ g3 Y& N$ a1 y1 U3 O6 I6 z9 l+ R
    lea     dx, int41handler2
3 N, e3 A# c4 f, V8 j. {    xchg    dx, es:[41h*4]
2 X$ u+ v* Q$ O5 t    xchg    bx, es:[41h*4+2]2 r& Z) X% n: d! e! B; o; {; }
    mov     ax,4fh
! D  h$ P: i6 Z# J  ?    int     41h
: Y# T/ ^2 V( c    xchg    dx, es:[41h*4]4 h5 U. L% a9 f& r
    xchg    bx, es:[41h*4+2]
& L, p* y7 n6 v( V0 O0 b% j. \    cmp     ax, 0f386h2 @" L: M* Y, x2 ]
    jz      SoftICE_detected, P3 v2 g' D. C. b9 u

/ @/ K  U! L4 t/ ]6 Kint41handler2 PROC& W/ b, E) c7 c, @8 J9 a' x' N
    iret
4 p5 d4 B% L  [" x7 Mint41handler2 ENDP
+ ]) N& x% y# o9 Z8 O* k! x1 y* c; K

+ z0 ?9 F7 A1 t/ Z0 j_________________________________________________________________________
1 w+ h) P) D7 u* r, t1 d4 }6 q! U0 M6 q0 {0 F, [9 `
, P, W: [% y) h3 E5 L# F- D& t
Method 068 `1 z: r+ b/ D: M
=========9 Y7 a9 B. N/ v6 |# p
0 H) u* K; F& @- j; x% l- h
9 t: Q! O% X$ A& M
2nd method similar to the preceding one but more difficult to detect:
6 M# o; S- y0 e& `! ]
* z& E  i, F3 g% G7 T$ A& G) ?
, \  b/ |, _! a  \, C$ Fint41handler PROC
# A9 A- W5 T. ^9 |) V5 k. O. K! V: O8 x    mov     cl,al
, r  X  d' _$ J- I" ?    iret
6 t, ]* A# {6 G& a( Fint41handler ENDP
5 R6 ^' e2 I4 ?+ W
4 d: N- i  j2 S& i, q
: [4 p+ \5 y1 h: J5 q  @" _; {8 k    xor     ax,ax
. k5 p2 T" r% K  K( @/ u; |    mov     es,ax
- B1 S7 a2 c/ g" m: j& \( c! d" l    mov     bx, cs
# H- d! l; S9 ?8 m& j$ B8 b7 S! b/ A+ A  O    lea     dx, int41handler
2 `& Q: H/ [# v% d' V( x0 o. h    xchg    dx, es:[41h*4]0 e; T( \* {4 B. ^6 B. q' U, e
    xchg    bx, es:[41h*4+2]
6 W% a# L& x* C& h; ?  I    in      al, 40h
! C$ j8 _: @1 R9 X9 @0 ^    xor     cx,cx
$ G9 E6 M# R* [1 R    int     41h- o/ k: N2 C8 T2 q* N4 B: a
    xchg    dx, es:[41h*4]/ }& S8 t: G6 l* c% Q9 e! R+ n
    xchg    bx, es:[41h*4+2]
; {) Z. V, y- |0 r    cmp     cl,al
* {+ V4 E& r( L" I2 i. z( ]+ d; u6 A. ^    jnz     SoftICE_detected
& W- h* C' w0 X, `6 ]
; D# e$ |9 G$ Q( I# |7 X% J_________________________________________________________________________+ ^/ k0 X/ n- {" N& L0 ~
' p2 M+ C, O. z& x) G: R4 x+ `
Method 07) L+ ?( M  B1 b# F1 p# J0 U0 h; m4 U
=========- n3 p2 \7 T+ D( @9 [$ }) Z
6 j7 E; X; i" `7 F: ]; C- e% |
Method of detection of the WinICE handler in the int68h (V86)  x: F- m* g3 E+ _9 b; A5 C4 c# Y
6 f5 Z: P; O# |; u. |; e3 M
    mov     ah,43h& z% Q- V7 X9 I6 F
    int     68h
# i5 ^, S& u/ N4 D    cmp     ax,0F386h
/ M! e, U1 z* p  @* B. u    jz      SoftICE_Detected
6 }. v0 p8 h  W* I, i, w* |6 e# y( O, K: h" R

; {% N4 M: Z' u& q' d! e9 v: L=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
7 c9 M! m8 ^0 c- Z% A. X3 }  ?/ S; c5 q4 u   app like this:/ Q: n: V+ h3 q8 S; }& ]0 ^
+ J5 X" j+ W, P+ }% T" A. o
   BPX exec_int if ax==68
. ]) ^( L; \$ y/ L( A8 W   (function called is located at byte ptr [ebp+1Dh] and client eip is
4 U. y8 K6 v& C, l5 P/ b   located at [ebp+48h] for 32Bit apps)5 g$ H/ d! w8 y0 n  s
__________________________________________________________________________) W# N1 n7 v3 s. O( @
9 n' L" U  r& w$ R- x- ]

5 n+ l0 X4 n2 v3 j" uMethod 08
3 J4 N  e6 x& J* c6 E; ^, i=========
" ?! e# B  h# R9 J9 ]4 C
) d( {! C0 s0 u. W1 uIt is not a method of detection of SoftICE but a possibility to crash the
& |( h0 P, l5 [1 bsystem by intercepting int 01h and int 03h and redirecting them to another
( r; O: o7 D% @7 h% ]  c) ^routine.# T0 O. L9 _  D7 U. x6 v. |
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
" v, \; H0 c+ P# x0 eto the new routine to execute (hangs computer...). r2 {; ?! |. M0 {: r
% E4 Q4 x+ h, p8 ]' l# v, t4 h6 U
    mov     ah, 25h
* t. _" R; H6 ]3 H    mov     al, Int_Number (01h or 03h)9 _  t8 V) z) e( s4 k
    mov     dx, offset New_Int_Routine- [9 L+ P0 J3 ~0 V3 w  i
    int     21h" M. k3 e% r/ @

$ m% j4 ?/ O( i__________________________________________________________________________6 V+ r) X5 ]  ^

7 Z; }: ?6 H: l' F1 C( R3 jMethod 09
) l& R) B8 C( [6 Q=========, m% t$ T; D+ {" X6 p1 ^

2 Q% v9 d' R2 k. v( M; E) GThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only- V, Y. c' Y4 K0 n6 I2 j( _
performed in ring0 (VxD or a ring3 app using the VxdCall).
. }- k! J& p# ~, M- V8 GThe Get_DDB service is used to determine whether or not a VxD is installed
- g( I  A$ S8 C2 `0 ufor the specified device and returns a Device Description Block (in ecx) for# v/ g+ Z  Q+ m) F+ t
that device if it is installed.
: o/ y* ^) x5 o
: @. H; M# b6 Z   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
& F) P2 b' N  _   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-), x0 P2 M3 H; S" ^. m3 J2 d) z. D1 a! l
   VMMCall Get_DDB4 d4 A" @" K# H, a# x2 l
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed' t9 ^0 T/ X" n0 ]' ~6 s: d& z

0 Z4 k9 R  v" {! CNote as well that you can easily detect this method with SoftICE:
  n! o% Q) C1 Y   bpx Get_DDB if ax==0202 || ax==7a5fh, h0 _- V# A  u

2 ^0 B  J/ q4 x# p' r- U__________________________________________________________________________
" r, s' \, Q$ }0 J* J* x$ K  X. v0 w6 g1 O7 V  W0 l( h
Method 108 j) y* ]: P! G2 L' x" ?
=========. @  @7 D. i& T) I. a5 r$ L7 Q+ _
. x2 @, t: `4 H; j$ R3 B
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with& \1 m3 Q  g1 K# L7 K& z2 @6 p
  SoftICE while the option is enable!!: u& I% f- c# b( H1 X

% y0 [% Q" n' R* S; _This trick is very efficient:# C0 `' O7 ~& Y% K- q" L( K
by checking the Debug Registers, you can detect if SoftICE is loaded
4 S' Z  }: I2 }& ~$ C; F(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
$ o) W2 W+ q5 s! \there are some memory breakpoints set (dr0 to dr3) simply by reading their, _# J& Q! P& ?% E
value (in ring0 only). Values can be manipulated and or changed as well1 g% f: u  `, k5 y$ ~7 o5 d
(clearing BPMs for instance)
" h* l& H4 W9 w# G* |' a
* `2 h: S- K9 `0 @8 b. T__________________________________________________________________________" M, Y9 K7 P' h8 L
0 ]4 P) d$ V7 b) Q( A3 z
Method 11. `0 G" T- ^5 U. {# B4 r
=========
# t/ ~+ T+ j6 Q
: |6 m8 @% [4 e$ I0 R9 HThis method is most known as 'MeltICE' because it has been freely distributed# D3 q' z0 V; _
via www.winfiles.com. However it was first used by NuMega people to allow
( }. G( a. R6 }7 }; FSymbol Loader to check if SoftICE was active or not (the code is located
2 |5 ~- ~9 \, q8 q& sinside nmtrans.dll).
: m) c4 Z0 F* ?% |! [8 X- H8 @4 p* P: w; |
The way it works is very simple:$ k) B9 }3 S7 ^3 S" b) j
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for+ |- w5 E  ~# B% a' i3 U
WinNT) with the CreateFileA API.9 ~, [- |3 l) w

# u2 P* T$ D. u/ t- AHere is a sample (checking for 'SICE'):- A7 \4 G9 `3 E7 ?9 p5 Z

+ h. |  F0 v6 M1 [. D, ?8 nBOOL IsSoftIce95Loaded()
2 R% U( E: L2 d6 O{
# B9 P1 P# m3 t" K' W4 E* ^   HANDLE hFile;  
# n- W! c, t4 ~$ H* e, j" Y8 a9 [! Z   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,7 {% K! C9 V3 \+ O( T# J
                      FILE_SHARE_READ | FILE_SHARE_WRITE,
& v% r9 ~% V+ k' C                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
. Y& l' n3 _; I* [- O; W! T   if( hFile != INVALID_HANDLE_VALUE )  n. {9 `( n3 V5 I: _- U' Q
   {4 I$ ~- i, |" W- N" v" y! \# ~# q+ p
      CloseHandle(hFile);3 Q& w  p8 C* K+ j8 \& }* O3 S
      return TRUE;
8 X9 [' Y0 K- f3 u3 m6 Z   }
+ }& _+ h, F5 {. D4 p9 `   return FALSE;
: M3 a6 m% n, f2 |( N  p. _' e}# J* g' b, E" {

$ U  H* j' p$ ?3 R* zAlthough this trick calls the CreateFileA function, don't even expect to be
6 z3 s& C8 a( fable to intercept it by installing a IFS hook: it will not work, no way!/ O0 n8 {0 W; c2 L6 h. B. O; u
In fact, after the call to CreateFileA it will get through VWIN32 0x001F# k0 p2 i' N6 G, f. n
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function); W& @, q, Q% P
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
0 R! h! V4 ^+ j  H8 wfield.
4 S! z- W, C: s' d+ d- \4 T' UIn fact, its purpose is not to load/unload VxDs but only to send a
9 n7 x  g' j2 XW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
& o9 P+ [  V! A  w* Q7 mto the VxD Control_Dispatch proc (how the hell a shareware soft could try8 _  K8 V3 s5 c7 Q  `# O
to load/unload a non-dynamically loadable driver such as SoftICE ;-).' W# l4 [$ E2 ]% ^/ P
If the VxD is loaded, it will always clear eax and the Carry flag to allow
1 J/ K( X) Y5 U4 |# o. W$ Hits handle to be opened and then, will be detected.
9 N  }$ D/ t( b1 gYou can check that simply by hooking Winice.exe control proc entry point2 S( h: l; C% Q2 \3 P* j9 C
while running MeltICE.
3 ~4 |* q, w& g9 G9 a+ F
- Z8 r0 `# o4 d  X3 [* J9 q2 T
1 D- f4 `5 ^# u0 ~$ b* w" R5 N  d  00401067:  push      00402025    ; \\.\SICE
" L! O( c# m/ ~3 C% T) t4 J; }5 N  0040106C:  call      CreateFileA3 b, p" m8 U7 R, E) m
  00401071:  cmp       eax,-001
; g2 k" e& Y9 V. M3 D, ~  00401074:  je        00401091
  t7 b1 m/ u; m/ ?' }7 f0 Q
7 U9 [$ r6 F6 }+ g; w! J4 O0 Z1 j
4 p  ~% K* \/ HThere could be hundreds of BPX you could use to detect this trick.( x- W* \+ y' Y5 {  E
-The most classical one is:
6 _1 u& E" r6 S+ }7 ^2 p  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||; e- i# ^. y4 [* g2 ?% J
    *(esp-&gt;4+4)=='NTIC'' v0 C* [- z; T/ x/ p
: c$ {8 x  g7 b0 W2 e
-The most exotic ones (could be very slooooow :-(! S$ T& p7 o% q! A% S) u. S6 U
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
; w5 f. W0 d8 o     ;will break 3 times :-(
" x8 t" Q  Z1 P- v2 a9 f0 t
9 N( s) ~6 q4 s! \( b, ^, R* H+ P-or (a bit) faster:
5 M7 W/ I+ i3 j! W+ Y% P3 R   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
( q9 f1 W6 @0 B! v0 H  U  _$ j2 R! O+ |
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
6 P1 ]3 L" h$ A. R  U     ;will break 3 times :-(% d+ E5 f, `. E2 u" C0 c/ W

. ~- p/ b5 t; [1 ?7 f-Much faster:
* h0 G$ \; a6 X/ H   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
; v2 T. e# N" o" u1 ^" b3 s! X7 f" f1 E4 E8 T2 Z# Y
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
/ W  d& I: ^: `* gfunction to do the same job:
# x) y9 F5 E7 T2 t; ]6 R
6 r. s2 }9 N3 x- R/ w7 |6 w9 x   push    00                        ; OF_READ
: e' S& f2 L* \4 g8 L; y& z1 {$ j, W   mov     eax,[00656634]            ; '\\.\SICE',0
/ w( \# @6 G2 P! @0 d   push    eax3 f1 S5 U% p: G. U# K" u
   call    KERNEL32!_lopen
! g0 V: ]& e6 Q  a  U" {5 K9 `   inc     eax
  v) Q$ n( V) ]( g' h   jnz     00650589                  ; detected" M$ K3 L, |4 O) d2 B+ Q
   push    00                        ; OF_READ
5 V8 V8 K' f- Q) k; Z7 R4 n   mov     eax,[00656638]            ; '\\.\SICE'
- B  V+ N+ v& K$ Q, t' h   push    eax
% w4 I$ h- r5 z5 d7 a& E   call    KERNEL32!_lopen% I6 D# X  c. w8 m4 Y/ b( q. `
   inc     eax2 B7 s: `9 n% Q. S7 A; D% w
   jz      006505ae                  ; not detected
1 Q7 N% x5 C& C5 ?& X& n0 E  E+ P6 h. E/ C

! ?+ b9 e4 B  g$ K__________________________________________________________________________
8 O: q+ }8 n+ M7 w
$ v8 @& I& N$ X" a, D$ jMethod 12
2 \. a9 k+ b6 G0 u' R  x, |9 E=========+ G3 U, J5 t3 y. i! R  l- Y
  Y8 H% p/ y/ t8 k% t" s0 n8 d! m
This trick is similar to int41h/4fh Debugger installation check (code 05% |5 T) C1 _- R9 {
&amp; 06) but very limited because it's only available for Win95/98 (not NT)/ A7 \" F* H7 ?9 A* r+ ?
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.( Z8 z. \/ r' K. [

4 H5 V  Z, \8 ?- L- j   push  0000004fh         ; function 4fh) q1 ]' S0 j" O! ]: ]
   push  002a002ah         ; high word specifies which VxD (VWIN32)# n2 K$ ~$ t7 V. u* U7 ~8 V
                           ; low word specifies which service7 _4 `( U: m1 H; R; Y9 Q( C; X
                             (VWIN32_Int41Dispatch)
  g4 z5 F, w  ]& x   call  Kernel32!ORD_001  ; VxdCall
  c% W, o% @9 ?) P) V   cmp   ax, 0f386h        ; magic number returned by system debuggers4 U8 A, L& c/ [6 i" _7 M  @
   jz    SoftICE_detected
1 `9 s: g1 n# B6 E5 Y% ^1 Q; [5 E% h/ O  O2 |3 H
Here again, several ways to detect it:
; Z, y' [+ d9 c
0 m8 i( P! A4 R    BPINT 41 if ax==4f2 {" b9 x; s8 E$ t/ w  x

0 @; s! d$ O% g( ?% Y1 N# p4 Z! n    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
6 u2 D8 Z  G2 l, d7 Y, a4 k+ ?) B0 J0 c7 j! {3 }9 m. S$ H
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A; l! @6 T7 p5 U0 U8 W2 ?
* k$ p# T( q5 ^2 ?  i$ c! \
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!) M  k+ a3 Z- ~- e4 q" n! [
( w9 {. l3 P: Z) T" a, k% b5 R3 u
__________________________________________________________________________2 g& o2 E$ X* w0 W
' C, @' R& a* U* V3 I
Method 138 m; _0 O) p$ p) f
=========
$ Y% G% o' ^# {" h, Q, Q# |/ ~: R% z& Y( B: r" [5 w
Not a real method of detection, but a good way to know if SoftICE is  m1 ]# E# o# C# B7 y7 e
installed on a computer and to locate its installation directory.
! ~: t; K; Y+ X0 |4 IIt is used by few softs which access the following registry keys (usually #2) :
. A8 ], O/ z3 S( i+ O! e- u/ Y
, W$ r# i1 I6 d-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
9 H: v0 V  H% b2 g\Uninstall\SoftICE
* x4 V. m# H" h3 o. v-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
6 A( x3 \5 P/ {6 t/ e. A-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
( E: b! r/ k+ \; v$ D\App Paths\Loader32.Exe
$ A/ f. W0 c: `+ R! L
# Z& `4 m& [% Q: t
! T- u5 {# U$ K- eNote that some nasty apps could then erase all files from SoftICE directory8 l& S. F% b. c: r/ w0 L
(I faced that once :-(5 R" c: ?* x* ]  R$ T$ a. {$ G

4 P9 i$ b: g7 yUseful breakpoint to detect it:
; ]! L! ?, M  M4 y6 Q+ _6 J, F$ Y
# s. ~+ \* d3 e+ _$ d+ t1 L     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'$ |' h; Y: [/ h6 ^8 a9 S4 d0 Q  C

6 E. _& {  x  i% z7 d% I__________________________________________________________________________- ]5 a- x/ f& u

* \9 @1 u: l' R4 ^$ u7 S4 E- }3 O! E7 T' R
Method 14
4 K0 v, A- D* X2 \. m4 i=========( s$ h2 F3 W" D/ \
& [' C- O$ }3 H
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
' p  Q; P" x- C0 e. Bis to determines whether a debugger is running on your system (ring0 only).
! [8 K. o- h  Q: e5 X! F1 k
4 S* B0 I( ?* X! i3 \2 b+ a   VMMCall Test_Debug_Installed% i: R6 }' e7 B6 @! k: E$ w  T
   je      not_installed
; G. k0 e3 Y6 L1 o8 }- K$ w
: Q# c' y& U, `This service just checks a flag." K5 p) k; l( j3 N
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部