About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
; C+ g  i  Q# H4 g3 y) P& i7 Y& h<TBODY>; t6 W6 F  f0 N+ W! m% Z. O: _% J
<TR>
3 j# e) z2 K4 Y; i: W% V<TD><PRE>Method 01
5 B/ K+ a( \: p' e% Z) ~: T1 s=========
6 [7 {& g) ^, i$ v; H+ f
. j; Z- i% h( y0 a  B5 f) t" c( fThis method of detection of SoftICE (as well as the following one) is
, Z& N0 N/ x3 sused by the majority of packers/encryptors found on Internet.% \) M+ C6 }+ r1 N) m3 u' O
It seeks the signature of BoundsChecker in SoftICE, n6 n1 Z/ w" r5 s8 R& i* U
% S) ]% y8 {% o6 D" f7 Y
    mov     ebp, 04243484Bh        ; 'BCHK'$ v7 _5 E; t1 H
    mov     ax, 04h
# N/ S5 a. a0 X6 ^    int     3      
. ?' }: [! p$ X. _% q- y' w( J: F/ Z    cmp     al,4
7 ?7 A# l2 w9 c) U1 F    jnz     SoftICE_Detected
9 Q5 t' V/ v0 l8 d( P
9 i3 p7 k# P3 J9 j% i3 C___________________________________________________________________________6 n8 C  N3 r6 `/ v
/ E+ s! l" p% ~# i. R
Method 020 g% z  Q; b& c4 D$ M9 m: O
=========5 T# w8 g2 ^/ ~8 v, V

/ n! \+ E  G: x0 \& r. ]3 f7 \0 c7 k. @Still a method very much used (perhaps the most frequent one).  It is used
' N1 w8 b# z- J3 Bto get SoftICE 'Back Door commands' which gives infos on Breakpoints,& f( k2 v0 W5 `4 D7 @8 ?
or execute SoftICE commands...4 t3 ]- A5 e- i# [) }
It is also used to crash SoftICE and to force it to execute any commands5 H3 g% _* F6 W4 b0 p0 U! r
(HBOOT...) :-((  . C+ a+ G7 O4 s

* ^5 Y# c( E1 e! V$ G9 v- cHere is a quick description:
7 M# S( T) M; b! U% F2 d2 z, Y! N-AX = 0910h   (Display string in SIce windows)* ?; K8 U5 `5 @
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
; x6 N  Q2 o1 O  x! ]-AX = 0912h   (Get breakpoint infos)0 _/ _* w9 {$ O' L# ~3 g
-AX = 0913h   (Set Sice breakpoints)
8 \2 x2 H: m5 w7 \-AX = 0914h   (Remove SIce breakoints)
0 `4 T7 o% g% P7 v0 _, |0 C( q' w1 p
Each time you'll meet this trick, you'll see:
9 R. ^# Y' B: C# P1 e2 O-SI = 4647h0 e# |* {1 Q; q: d$ f
-DI = 4A4Dh: l4 x; u) K6 ~) Y2 ^& o
Which are the 'magic values' used by SoftIce.
: Y; o) b1 u4 l, U1 KFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.) g0 [) w9 V8 ?, I& d
& _4 [0 q; d& }: e$ D
Here is one example from the file "Haspinst.exe" which is the dongle HASP. J/ q9 @5 Y. \- }4 f( J
Envelope utility use to protect DOS applications:
& [) Q8 D( B& X" ?% P
  b4 b5 S- w. |' H# j5 h. |5 {' \/ v8 O) A- \) \" G& A
4C19:0095   MOV    AX,0911  ; execute command.: D8 r; x4 _2 c/ g! q
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
* m, o  F* Q" }# X1 \4C19:009A   MOV    SI,4647  ; 1st magic value.0 S! w! g* D6 w+ t8 T- r1 B& C
4C19:009D   MOV    DI,4A4D  ; 2nd magic value., y6 @& _& n) \$ }# q* b4 x$ h! f6 G
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
) c( q- B3 T" ?# m4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute) Z/ J- i( u! |  m2 O! V/ y: V
4C19:00A4   INC    CX$ P$ D- F( j6 P0 R
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
3 V: |' C! K+ W8 J6 Y4C19:00A8   JB     0095     ; 6 different commands.' X3 y- Z8 a6 d; _3 B3 g0 {7 T# M
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.8 ^4 a; o# a3 |7 t
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)+ q# q. C) u6 k$ Z
: p6 N+ a9 Y6 ]( Q1 c5 j2 l
The program will execute 6 different SIce commands located at ds:dx, which
; r/ k# z5 ~& Oare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.; U: h: v/ Z6 Z% {# }+ p" C

, G: Q- O9 I1 ^( o* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
! g7 Y6 y$ J) a8 m9 l___________________________________________________________________________' u, r1 O/ }  E  k( O1 A4 R
, F" X- w# {+ D

5 f+ C: t' ^# W1 Z* J0 ]Method 03
) C2 i& n% t9 v=========/ k+ V- W- L" H# R7 V- Q, }& G

  [9 N) W# D5 i( A% T( n. G& WLess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h* P+ {. F& M' w6 H: z3 _! g( K& T" M0 l
(API Get entry point)2 L3 D- m' e3 W9 ~5 Y! E/ S5 h
        
9 L$ y- K+ @  U3 ?7 a
7 E0 R. d" i  n! J! U- q( ?# t    xor     di,di
6 }9 u/ ^" p2 R0 t, u# N    mov     es,di( Z: A( i3 [6 p
    mov     ax, 1684h       7 M* @7 Y, F5 m" U5 o
    mov     bx, 0202h       ; VxD ID of winice
! v3 J% ?, E5 f) b3 w    int     2Fh
- ~6 g  G: G* c8 @' I    mov     ax, es          ; ES:DI -&gt; VxD API entry point0 Y1 H2 G/ L' D; U$ T& ^; F6 N0 ?
    add     ax, di
. |& X6 P3 t' v# V5 A4 i9 k    test    ax,ax. M  Q# y3 T  ?. G
    jnz     SoftICE_Detected5 m" a5 n# o0 e. s+ l
8 c9 c  E; j5 {5 K
___________________________________________________________________________
6 \/ r$ `* C7 Y( G" g4 C+ @0 _0 A$ W5 l1 W0 a2 _
Method 04
1 Z) b1 o9 K/ E4 T=========1 ~8 b: N8 z/ g+ {% |

5 k* h& s) l  XMethod identical to the preceding one except that it seeks the ID of SoftICE
6 A1 a2 U; E  M: s) W& CGFX VxD.
5 K$ c+ s! ~% w- O* w9 R
: S2 q7 {4 Y  H% b6 D( ~! X5 q    xor     di,di
$ Z; g! u& `& a    mov     es,di
+ y1 @# U  j6 w1 ~3 ~9 O    mov     ax, 1684h      
0 y8 G7 \& }2 F- m! I* u    mov     bx, 7a5Fh       ; VxD ID of SIWVID! d" j. p7 e2 c8 e1 }) H
    int     2fh( L9 g; u# C) {* [; l5 j1 s' M
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
! B! k# ?/ z. s" ~( ~    add     ax, di
! g" F# X) S) c/ @! B    test    ax,ax) L4 x5 ?7 D( D
    jnz     SoftICE_Detected
6 i8 |- e1 S$ K/ f% o0 ^5 o, s) z. ]8 \  Q
__________________________________________________________________________5 i" k& ^6 R6 `: C* P

- I& R; w% s3 s  W
% ]3 |% \+ U, K2 [Method 05" P4 O& V3 ]% s0 S6 Q
=========: g) f+ O9 L( @

3 |9 p5 L6 p; ]5 pMethod seeking the 'magic number' 0F386h returned (in ax) by all system
+ y9 \7 B; U1 e( b/ H& }debugger. It calls the int 41h, function 4Fh.
. V! U1 b7 y6 Y" U+ u. U5 }& rThere are several alternatives.  # S6 ]2 z: B, p8 q
, {2 _1 a4 e8 Q( \/ ?* @
The following one is the simplest:
1 N6 v" V( [5 C& f/ h9 x9 L% E* ^6 ~, P
    mov     ax,4fh' o( \. t& W* g  v- J0 @" n
    int     41h. ^  b' ^" a$ P* ^2 K
    cmp     ax, 0F386
+ g. T' O  c5 w. \* t    jz      SoftICE_detected" o1 I7 }3 v& M8 `

) M% P/ X: \* Y& K3 ~2 |8 H" Y1 r2 r- V! A# _* ]1 L4 z
Next method as well as the following one are 2 examples from Stone's
2 S7 ~9 S6 `7 U# N1 d" K% u"stn-wid.zip" (www.cracking.net):
, D- F6 B$ n+ y8 p  j
' c7 t: _  h5 A( ~2 R" k    mov     bx, cs  c* ~# h* S% g" j( [. c$ n  J1 z
    lea     dx, int41handler2
2 Y* l3 X1 q; ]7 _& {4 L2 q: s    xchg    dx, es:[41h*4]
; P  Q3 F1 g- ]    xchg    bx, es:[41h*4+2]% L% s( y! s5 d! M
    mov     ax,4fh, G; k- @8 E3 _0 @2 ?( |
    int     41h$ n0 `1 [; l) H
    xchg    dx, es:[41h*4]
, @: a$ V! I, s    xchg    bx, es:[41h*4+2]
8 i0 T6 z0 h& n7 e    cmp     ax, 0f386h
# p( [& U& R0 o2 S% ~# E5 \2 U    jz      SoftICE_detected
2 b( i( X$ x% j/ W5 K: J- C) _" z' h9 e7 H- k; O
int41handler2 PROC
( {% g( A  D& M( v4 g0 F    iret
/ u9 h. Z8 e9 Mint41handler2 ENDP: g6 U) x/ M  J& w) n: s
$ O! |) Q: e5 Y. ~2 b. z' I4 g  [0 n" y
/ j6 `8 V1 x& v8 _! L2 |7 `+ x
_________________________________________________________________________
$ ?2 P2 I$ x/ a$ P' `
  _! m* k5 y/ H/ S: S  Y  `% J% C) x: |8 h" v2 ~4 G
Method 06
6 }( s& B2 ]; B8 J- g=========1 m0 z7 `7 q# R- h3 B
9 ~) z  d5 u7 s3 p
' z. L) \, P3 p6 ]7 }; E
2nd method similar to the preceding one but more difficult to detect:
. d$ t5 f# W4 }+ M
& k$ u$ G* |0 h/ [% H) M6 F# P4 M
# n4 k! h1 m; R, p% q& [6 Tint41handler PROC
+ V. G- R- Y/ z    mov     cl,al% d% B9 u4 ]6 a( v& o/ m
    iret
8 z' U1 n4 S' N2 ], h+ Wint41handler ENDP& S: v6 Q% y+ {

8 l) Q( C# j8 Z5 F3 E2 Q! T
( f4 m5 ]0 L4 t/ d3 L    xor     ax,ax
4 N$ ^% I9 I( N; C& s+ B    mov     es,ax
! V. N2 M4 v0 H- A! b9 D3 g' ~- ~7 Q    mov     bx, cs
6 G+ Z8 ^0 ^* Q/ W9 D    lea     dx, int41handler6 W% G" k: E% _& `, t% s% i- d
    xchg    dx, es:[41h*4]
& g/ M$ X. z4 ?: a9 l    xchg    bx, es:[41h*4+2]
" o/ i7 i2 P1 U6 C    in      al, 40h
0 ?" G* Z/ ?( t* D$ t5 M    xor     cx,cx. C& L0 ~3 D# V# u9 p* F8 r
    int     41h6 @- T, x) P+ O# C
    xchg    dx, es:[41h*4]2 J- ~. u1 U6 n8 W! h# T
    xchg    bx, es:[41h*4+2]; g3 G$ s: M$ }6 \$ F- @3 L- \
    cmp     cl,al
0 R0 ~$ j8 p  T9 _0 G    jnz     SoftICE_detected0 w4 V8 {7 B$ m1 I( J( p  f& K
1 ~9 [, @: o0 k3 F4 f
_________________________________________________________________________
9 z8 o3 D  B' W6 F, r' ^7 ?7 L- G2 U+ |4 K
Method 071 w* h/ s5 R; l' {( {" m
=========$ s  Y+ E3 O- ]. F: L. C
, @' g3 z# @( [" b5 L
Method of detection of the WinICE handler in the int68h (V86)
+ g' A+ l) n) |! L- j3 H" {0 s+ M
    mov     ah,43h
1 a, T, g7 r; R$ E. n6 B" B; L    int     68h
3 ^8 T0 `$ m5 R" F1 g3 A0 I    cmp     ax,0F386h4 x$ K' j7 {; c% E* ?) w; q
    jz      SoftICE_Detected
# N7 @8 a8 v+ D$ h0 D) n- p
5 R- M, T; v( U: O( I. S  x/ ^
# O5 {. K( I& {- z4 i=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit) P! B7 C- {$ {! B5 h
   app like this:. \2 D3 V* C1 S  C
( k/ [9 n+ P) m( Y5 ]; T* z$ h
   BPX exec_int if ax==68; T9 H2 [0 R. m) ~! B0 i
   (function called is located at byte ptr [ebp+1Dh] and client eip is" G" p5 `% E; O8 J; U9 L
   located at [ebp+48h] for 32Bit apps)
) q& U7 a% I' Q  P1 w2 z4 p__________________________________________________________________________
5 v- J5 }- g1 C; A) g, d
4 e$ e$ Z3 o/ B& k' s  D" S1 P0 q, R$ L6 J# x6 z
Method 08
* X2 ~. }1 i& T3 }% l=========
0 Y0 O8 X* s6 ~/ Z2 h, n+ x  ~$ |' `. ?+ Q5 c' }1 _
It is not a method of detection of SoftICE but a possibility to crash the
% p# V) ]1 |9 o6 Dsystem by intercepting int 01h and int 03h and redirecting them to another
* s; h7 X* s( e7 Rroutine.4 e: O9 \2 H0 v  Z
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points. _8 G7 B3 N" ?! D; \
to the new routine to execute (hangs computer...)
8 |* y1 v) n  s" }5 B4 ^8 x3 j. j/ }7 r7 ]" \8 k
    mov     ah, 25h
( E( y/ Y; g* `6 i3 j* p) ?3 C    mov     al, Int_Number (01h or 03h)0 t' B9 m8 U6 H; Z1 \
    mov     dx, offset New_Int_Routine
2 D9 r" I4 L# s* C- D0 K, ?; Z    int     21h
! x3 L' _3 c( T6 ?
1 A" j# R* U8 f" g, t__________________________________________________________________________; _- e5 |7 O4 O+ B
: j& b- q" Z( I3 [
Method 09
6 i; [$ o- F2 V& ~=========
. [$ z1 {' F% ^- i+ H) r& E  ~
: D. W. S7 Y2 rThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only2 K* H2 u! H6 V
performed in ring0 (VxD or a ring3 app using the VxdCall).* n8 O1 S( O, H
The Get_DDB service is used to determine whether or not a VxD is installed
( b& p7 }& [% z& D, Sfor the specified device and returns a Device Description Block (in ecx) for
0 A& ^3 k1 m0 X  r6 d8 C: s5 othat device if it is installed.1 E; Q: ?& i# j

4 g; ^/ e& |, q- e, g$ N) n5 A   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
: {1 b* e' S' Z2 F+ K! }   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
, ]1 U6 c  `+ m2 l6 `  w6 z; c+ M   VMMCall Get_DDB
8 U0 B7 C0 ~) p$ p% {0 F: _   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed' L8 ~" l, \" h7 I) d+ ~1 x

* y5 u3 V5 [# }: ~2 TNote as well that you can easily detect this method with SoftICE:
+ C/ D9 y2 `5 z  Z   bpx Get_DDB if ax==0202 || ax==7a5fh
, y# r& a6 x/ l
3 L" T8 Q( z8 k9 q__________________________________________________________________________/ a/ J" H3 V  e$ B7 E! _
8 E$ T3 `/ l- o3 Z, K3 S' l7 X
Method 10$ z9 Q4 k; Y& W& [* k
=========5 H% V$ o/ V# [0 `  p6 u
7 {0 }: j, F/ k2 a, r- ^$ ], S
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
# L' ]# ~4 E  O* o8 y" \" j  SoftICE while the option is enable!!
8 w9 s* u3 w2 i+ k5 t
+ u9 w& R5 Y  M6 q3 S& @This trick is very efficient:0 k( K6 S/ o2 Y" z+ M) Z) \- Q
by checking the Debug Registers, you can detect if SoftICE is loaded
% ]' w8 l. T0 [9 n" t' n6 A(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if3 m* B' q* w8 w  {! @& z" P
there are some memory breakpoints set (dr0 to dr3) simply by reading their- C2 g5 W" }$ I- Y& {+ O  [
value (in ring0 only). Values can be manipulated and or changed as well, c1 {" B$ x5 i' a9 e
(clearing BPMs for instance)0 }6 N+ C. n! k# g# O  ]

9 c( ~1 S: s8 Y2 X/ `! _& K__________________________________________________________________________2 h* C( o7 @1 e7 A
( c9 X# _, K( _4 F% Y3 A
Method 11
; d! a* w8 S" E6 {2 G=========! ?" L$ O! Y) H+ i* c

% }7 `& R9 i% u/ X. [3 L* bThis method is most known as 'MeltICE' because it has been freely distributed
8 Q$ f% j+ R6 _" I* lvia www.winfiles.com. However it was first used by NuMega people to allow
% v. J0 D: {! u- \2 G. gSymbol Loader to check if SoftICE was active or not (the code is located$ J$ P  a* L  V( L7 H
inside nmtrans.dll).: E! q2 G0 S8 d3 y) k
% P( k$ r7 Q/ ~) H5 t
The way it works is very simple:: ^- X1 r9 e$ B4 K2 k$ {9 w
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
9 S; W) o# G- _( S; Z4 XWinNT) with the CreateFileA API.
2 y) y; x" o0 v( ^5 w1 Y; f
. z7 o6 q: }7 T7 z" I6 T1 xHere is a sample (checking for 'SICE'):
. I5 J- E2 P  T" r. d7 g4 S; l
BOOL IsSoftIce95Loaded()
+ ^% T, ]  @) ]+ Y; i/ X{, P8 g3 C: I/ `9 r0 @7 i
   HANDLE hFile;  
0 ~1 A9 i0 A5 ]+ U8 T   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,5 E0 l! C+ y. `! G7 n* c: h
                      FILE_SHARE_READ | FILE_SHARE_WRITE,9 O0 }, d1 ]- v8 `0 K
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);( A/ A& ^# }) U
   if( hFile != INVALID_HANDLE_VALUE ); R, L/ m: b# H$ h+ y
   {& Z/ R& ~0 \3 q; J4 W" c+ D
      CloseHandle(hFile);
" i1 e* A$ _: }6 l8 @5 I      return TRUE;& q/ A, c/ b% X3 w
   }
( B& X( I3 X5 w1 Q4 e/ H- A8 ^  B   return FALSE;7 a' N' Z8 q4 R; H6 c7 N+ ?
}. Q+ N8 u3 }. {  u+ N' q  T+ F

! i# C$ r0 o. _' v1 ^: t7 E: k" QAlthough this trick calls the CreateFileA function, don't even expect to be6 K9 z/ U) \# o9 c% r0 i9 ]* F
able to intercept it by installing a IFS hook: it will not work, no way!
$ z; l  k6 k! `+ M" V& D7 a# j) d7 {, yIn fact, after the call to CreateFileA it will get through VWIN32 0x001F/ V- u3 j4 r0 Y2 u' _2 {0 J$ f
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
9 b, A* i3 n, d' j  eand then browse the DDB list until it find the VxD and its DDB_Control_Proc
; D2 Y8 w* o3 M5 O) Kfield.
* `9 ~9 O) P2 H. a: mIn fact, its purpose is not to load/unload VxDs but only to send a 1 {4 w* ?) |* K1 x  ^) ~
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
! K0 Y: j! J1 v2 H! Tto the VxD Control_Dispatch proc (how the hell a shareware soft could try6 e; e) S3 [  V. D4 a& x
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
! ~- [9 Z1 D; m  y2 [If the VxD is loaded, it will always clear eax and the Carry flag to allow% X1 G. s/ y( q% @. |1 |
its handle to be opened and then, will be detected.
& v& Q: X' O" t: T& p& g9 wYou can check that simply by hooking Winice.exe control proc entry point- P: R* [; D: w
while running MeltICE.( i9 x4 I9 y; z6 t. k' n1 [  n
% t5 N# p) U! _& K- L

  d0 R. J% j8 }) e2 J0 K  00401067:  push      00402025    ; \\.\SICE
0 K8 R2 H% Q' D  d4 ?  0040106C:  call      CreateFileA- F$ S+ g! u* A- n8 U0 e- g! N0 c3 S
  00401071:  cmp       eax,-001
2 _% r/ ]* [( c" Q) q2 Q4 s  00401074:  je        00401091
; X4 x& l0 q: T2 j! {
' _  p6 K* F* j& t. J& [
$ v: ^8 ^% z; N) ?: W5 O- k; CThere could be hundreds of BPX you could use to detect this trick.* e% K( l+ U# ?+ l
-The most classical one is:: H$ D9 a. p* e2 ~. w2 d) V
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||/ H/ u/ U; |0 M# Y* ~
    *(esp-&gt;4+4)=='NTIC'
9 W; _- \8 [+ l! z4 G
0 i- ^. M" @- P! o-The most exotic ones (could be very slooooow :-(
. F: i" _9 u6 ?3 ?  B   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
3 k/ ]3 N$ b9 ^* N3 q     ;will break 3 times :-(1 [1 l5 m+ X  I, j& M# C
5 J: C& M' ?" K0 v! ?; }
-or (a bit) faster:
/ A; g. L1 J0 o! p, q   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
$ W( E! V$ S' f# y) U1 p5 L) W7 P; [$ _% w. U0 m/ L
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  7 k0 j" G, O5 S8 b. e
     ;will break 3 times :-(- m! D3 K! J- l7 E

3 ^- S! E7 C0 U7 X& h* D. K-Much faster:$ i1 {- t$ z% ]; t  N+ _
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
1 _# I- p( G# G; f# U* f) {+ H
) X: ~" Y! I+ ]: v) ^$ v/ q. QNote also that some programs (like AZPR3.00) use de old 16-bit _lopen
0 o- H/ P6 `9 q; n/ k. rfunction to do the same job:% k% ^0 k7 `4 w5 y' `# N
. F) l% ?2 O/ b- q* O
   push    00                        ; OF_READ- e. L. `! X! p  i5 N. B8 B
   mov     eax,[00656634]            ; '\\.\SICE',0
( n- ]/ d" @' H. ^   push    eax
! U8 f, u& j  C$ _   call    KERNEL32!_lopen: V; \0 |# u# s/ \) L# f$ O7 M- p
   inc     eax
5 }, p- i/ b9 F. M   jnz     00650589                  ; detected
  ]' W$ k: M" h! y- v, R9 q9 b   push    00                        ; OF_READ/ {% a! l& D, P4 J* b
   mov     eax,[00656638]            ; '\\.\SICE'$ l: s8 s5 ?" f5 u/ p  a
   push    eax
6 Z: g) E% J0 r& |+ G" \6 T   call    KERNEL32!_lopen
  ~" |+ R; C+ {9 P# u/ ~; d   inc     eax
5 [- o1 j. n" R" T   jz      006505ae                  ; not detected: v0 r0 |7 W2 B5 e9 k" R) n! ?

$ U6 A# Y! }  n: ~3 e' L' [) H- w0 ^* @0 y
__________________________________________________________________________& v9 ^0 `7 B) ]3 o  D
1 f8 \4 Z% q) ^& a1 [* ^: }
Method 12+ P: k- L  Q4 }" i; W
=========
. q# l5 H1 Z/ |" g/ @. I9 ~& i/ I6 p7 k% g
This trick is similar to int41h/4fh Debugger installation check (code 05
2 I+ E4 {7 l; G; l0 [# K3 J&amp; 06) but very limited because it's only available for Win95/98 (not NT)
+ p" y3 r' ?/ O" ?- H) K5 }2 H! w3 Has it uses the VxDCall backdoor. This detection was found in Bleem Demo.
, F4 K* D% s& b
& j, r. _6 W* P: i   push  0000004fh         ; function 4fh9 |% s  J& U6 a' b; v
   push  002a002ah         ; high word specifies which VxD (VWIN32)
( [4 n$ [( e& i7 M                           ; low word specifies which service% b# e/ G. B+ \9 ?, `: P  ^, e9 R
                             (VWIN32_Int41Dispatch)
- ^# j  D& s$ f7 [8 ?7 Q3 A. j   call  Kernel32!ORD_001  ; VxdCall
7 L/ P0 j5 S; p5 A. `6 f1 Q   cmp   ax, 0f386h        ; magic number returned by system debuggers' J( Y  e( |3 i; R
   jz    SoftICE_detected8 H; o  E6 n$ U5 ?% a

4 \9 `6 D$ p& P% _$ O* lHere again, several ways to detect it:
/ i0 _: ^7 T$ G# a) K
0 N& C# u+ F  m2 N) {5 @    BPINT 41 if ax==4f. a6 e# r0 H8 C7 S
" ?$ l. p1 j: J8 Q4 c  Y, l4 E
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
& M$ t) x0 ]: L3 Y$ H6 v6 [- k8 K, p* u$ ]
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
, }1 T; C. }- O8 B) z# l
' l# I% T5 ~* Q( r$ }    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!7 Y. d& C! c( P/ e+ _

% a( y7 j4 D8 H( A__________________________________________________________________________( D' u6 [; |6 {% Y
5 o' J" l1 s; K) U) u( v
Method 13
! V; ~2 d3 p5 G6 s( W1 e) z=========) l8 @5 t) z1 j' }
, M% u3 U% Y2 C7 l) E1 w, h
Not a real method of detection, but a good way to know if SoftICE is
/ A& ?! x. k# S' ^installed on a computer and to locate its installation directory.
9 V$ A( B  m8 D: A" \7 M; M6 VIt is used by few softs which access the following registry keys (usually #2) :0 Q7 `7 H& O0 G; z. z
3 m- J3 B2 v* P+ S6 M+ T5 `0 R
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion' T/ d- j# ^8 C0 x2 @8 a
\Uninstall\SoftICE' L- \$ u6 r( P  u
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE' \5 t7 ?. b- P! r9 W( h; X
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
" b6 m, o) _( t4 o\App Paths\Loader32.Exe; i/ u& K5 F$ i) Y+ Y+ p

% }, W- n/ O& i- v4 q' F
8 F3 W1 i* w5 I7 `# QNote that some nasty apps could then erase all files from SoftICE directory- t& u% B  L+ C" O
(I faced that once :-(
* _- ?1 J# h. r' P, I# U; ^; w9 r' z. t
Useful breakpoint to detect it:
3 N+ y3 O5 c: O0 C) Q  L  T- o) P4 Z. y7 v/ H9 ]- Z9 J/ `- S! Y
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
5 `% h' m8 d/ n/ K: z3 {
) @$ d0 m4 N6 N  @5 E. c" `__________________________________________________________________________3 F) H" U' L' k7 L1 B! S8 C3 P, g
! j/ t  }  F5 C
1 Q5 D8 J+ H) e
Method 14
3 H0 S' z; P  i( \6 k=========- U. y5 G: S# U2 s% o1 s

7 m; ~) N+ i9 C6 X% T: Y7 rA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
' w, ~) {+ H+ j  ]is to determines whether a debugger is running on your system (ring0 only).* C1 g& Q" ~. S9 O# F! |( e: Y" e' F

, v& t5 T9 ?, d8 U3 z6 H   VMMCall Test_Debug_Installed) b4 ?$ N; G3 K" v# w) N. {
   je      not_installed5 @) X- G; y3 T8 \5 D$ o  G/ H* j

; T0 C( T# m' I% y$ U8 s/ O. K" s6 h2 GThis service just checks a flag.
2 f& V" x0 E+ @+ {' ]</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部