About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
* \% w7 H4 K+ Y; w+ N<TBODY>
0 [4 ~1 O% d6 k; T' t<TR>
( R2 s1 s. K) m  [( c% H8 l6 q* H; [<TD><PRE>Method 01 # ^7 D; x* X- P! m) P
=========6 Z' U# F" V2 {  F* j5 i* X
9 p6 y7 ?7 O! }3 x# l
This method of detection of SoftICE (as well as the following one) is$ F$ K9 T; s' r* f" D$ Q, O
used by the majority of packers/encryptors found on Internet.
3 y" o7 H! b- t0 J3 r/ DIt seeks the signature of BoundsChecker in SoftICE; K. T  w! Q+ }: m4 k

+ H, S" h2 ?' y8 g8 t1 K4 X    mov     ebp, 04243484Bh        ; 'BCHK'
5 u; h5 P5 W3 P( r5 f- c    mov     ax, 04h
9 I5 {" J& U7 O    int     3       4 Y3 b% O. r" d/ U, B: r+ @2 q
    cmp     al,44 M6 F& {4 ^1 g2 [
    jnz     SoftICE_Detected  Q5 `1 C5 B4 z. f" _! L/ m4 [; w
1 I9 J1 U! c5 c, w' `
___________________________________________________________________________( `1 l, }4 j  C
; Q% e+ X7 r0 \7 B; k+ w4 C8 G
Method 02
3 }$ a2 T1 x' K/ x- K=========0 k4 |! g' S  ^6 i' D% q1 x; Q
3 F1 ]1 w2 C" S1 z  F) H/ Q$ s0 I0 h: c
Still a method very much used (perhaps the most frequent one).  It is used
# e2 y" u* n5 n" G4 Z' Qto get SoftICE 'Back Door commands' which gives infos on Breakpoints,4 ]* z; }" m; L2 g+ C2 [
or execute SoftICE commands...7 L% U# ~1 |0 r- E' P3 ~1 D
It is also used to crash SoftICE and to force it to execute any commands
6 Y* W* A5 [% c8 \! U(HBOOT...) :-((  
5 u6 X/ ]3 H, X4 _1 q, D) \! w) e: k, D) K
Here is a quick description:$ j  a( A8 I9 B3 c5 Q1 B7 `
-AX = 0910h   (Display string in SIce windows)+ p7 n( u. G$ ^: _* o; q: L1 S
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
  @3 y+ @6 R6 n/ g9 f) S0 s-AX = 0912h   (Get breakpoint infos)) q. z. e! C0 k6 ~- R
-AX = 0913h   (Set Sice breakpoints)
" ~3 h2 g" S2 Q0 {' K-AX = 0914h   (Remove SIce breakoints)
9 V6 c5 e! S' |2 c- l6 n' O1 t  y& L$ j7 D+ g2 @/ J
Each time you'll meet this trick, you'll see:
; b; n) S3 O& N' a7 }8 M+ y-SI = 4647h* N; e6 I1 K# q, @4 D
-DI = 4A4Dh
' T9 P0 l) y  y, L2 tWhich are the 'magic values' used by SoftIce.
2 P$ \- r0 L0 N4 X7 ?1 VFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
. E0 l; a3 P" K( s
' \" ~6 w& |( _6 wHere is one example from the file "Haspinst.exe" which is the dongle HASP, l) X: K6 Q; v# H2 o4 C
Envelope utility use to protect DOS applications:5 K% @0 p, r- b# z8 H" ?9 u
1 s# N  V# L$ W6 g. Y- x& u
$ H5 [9 y* D/ V" m
4C19:0095   MOV    AX,0911  ; execute command.5 X, d: |. r- m" x. t; z
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).! D5 _5 w* J4 f6 B
4C19:009A   MOV    SI,4647  ; 1st magic value.
0 U+ n( w6 ^; A6 J* }4C19:009D   MOV    DI,4A4D  ; 2nd magic value./ a; A4 ?5 D" f( u+ D; Q4 a
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
0 g2 a) C) B7 d/ Z4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute" |; F8 r: n4 S& K  P4 J. h1 C
4C19:00A4   INC    CX1 j  y6 `+ _+ Q8 \- Z  M# P
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute+ e* L" ^( \$ z: t
4C19:00A8   JB     0095     ; 6 different commands.8 d5 x7 i5 }8 U
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
( M, p/ O* l5 v! s; y4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
4 M8 l7 u! e, b' p/ n2 |- R+ h/ a2 E* \  C
The program will execute 6 different SIce commands located at ds:dx, which
- \. P6 X& t( d) F% Y$ _# ~are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
2 K% e: q9 l0 A+ q& ~+ J" ]" b6 g* K. G  t3 H; g1 r4 \( H
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
3 c: X" p( F7 w8 i- M+ \___________________________________________________________________________
3 F/ G+ g& r+ T( K0 @
  v; K  o/ z. m! P1 D5 y8 z$ [  V- m& I( I' a
Method 03
$ O5 q, [0 e, z1 V* T8 m=========+ W- X! v2 G9 {6 D( I  i2 O
' P- _: ^2 M! N0 [2 Q9 c
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h9 {4 b% a8 i; B6 S. l
(API Get entry point)4 n8 U/ N! e% F. I; _
        
6 ~9 p. [# j, j% m+ e
; u' E7 y4 F( t% T6 F- O    xor     di,di& a8 G7 d. l: \
    mov     es,di8 @* i& [! _) h! v) W
    mov     ax, 1684h         h" k& G1 k6 X+ R* L0 r8 i' C0 g
    mov     bx, 0202h       ; VxD ID of winice' U2 J% r+ K" Q: ]' D* m
    int     2Fh& z. q' k3 s' M. H5 B0 V7 n
    mov     ax, es          ; ES:DI -&gt; VxD API entry point  u% D" ]1 B' _$ O3 |  y0 v1 U
    add     ax, di0 Y$ B& o: X9 ]2 e& Q
    test    ax,ax
7 E1 u. I: v  x( `9 n" n    jnz     SoftICE_Detected, Q4 z3 E6 |1 i5 P- C
" ?" T$ _5 D& Y/ k+ }# i! W5 H5 _
___________________________________________________________________________5 h5 d7 K9 v% A, w! w0 [
& O" W$ t" {& k: d6 T
Method 04+ M, _, |5 h1 q
=========
+ D3 G- Z; S* ~  u, F( v+ I" a
7 U9 ^3 f  b5 y6 ?) P0 _3 Y: m+ fMethod identical to the preceding one except that it seeks the ID of SoftICE
' c* y/ Q$ q- FGFX VxD.& M" N7 Z2 i" \  J! e* m1 y
! g4 D% \1 W+ k- f7 B
    xor     di,di
- W0 A- f" K8 E+ {) b% i) s    mov     es,di
$ o* q) b" z4 \$ p5 U/ w; e    mov     ax, 1684h       8 r7 R& I  l' \7 k
    mov     bx, 7a5Fh       ; VxD ID of SIWVID
( n/ w6 s; H" _! V    int     2fh6 q% K) Y! Y6 ?2 M8 Y$ ~
    mov     ax, es          ; ES:DI -&gt; VxD API entry point, D: R. q% E# j
    add     ax, di$ w1 q. O( n) k; |. J2 M0 D$ O( A9 f
    test    ax,ax
8 j3 q; H+ l2 r9 R1 q% t! s& c    jnz     SoftICE_Detected3 z( K6 V9 @8 z1 x. H. a
1 u7 J! W7 b5 D) `, @) f8 Z
__________________________________________________________________________- S2 N, p# i4 s( K, M$ ?

3 f5 x! j/ V8 \) K% R! G, ?
- ^1 i' F- ^8 }9 ^2 W9 j9 dMethod 053 @( `% u# B- e0 Z4 k" i+ f+ W7 u
=========
% ]+ S2 k9 w( F* b  i  Z6 v- J) E! Z- Z
Method seeking the 'magic number' 0F386h returned (in ax) by all system
) E& }8 s2 z9 p8 p, Y9 mdebugger. It calls the int 41h, function 4Fh.# z) {. z& I  ]- [/ k% v
There are several alternatives.  0 s6 f6 S9 q% h, {* v" h
; r, p2 L# ]# r
The following one is the simplest:2 r% O1 w- A: I$ w) X/ t
( R: I: w3 T' e7 Y% ]
    mov     ax,4fh4 V# I4 L9 {  m# L- [% d* n+ e" r( I
    int     41h
; u* K8 |( _1 g( ^    cmp     ax, 0F386
5 O$ X7 ^( q- U, @- m    jz      SoftICE_detected4 Y/ p& i( b: \
; s) @5 Q5 h6 q6 r/ I
# f$ {3 f5 c" X3 ^; `) J
Next method as well as the following one are 2 examples from Stone's
# c! |+ v+ [8 m# H  [9 ^' T"stn-wid.zip" (www.cracking.net):( E" l9 X' X3 }$ g* C' y4 Z$ v

7 |$ W/ ?# T7 u0 S1 F7 q    mov     bx, cs( S8 a5 y2 Q$ `& f+ m: \
    lea     dx, int41handler2
( @% M! l# z4 g. o% `- w1 W( X    xchg    dx, es:[41h*4]
0 Z/ a' ?1 W! N    xchg    bx, es:[41h*4+2]0 D1 M2 N; \/ ?. S+ X9 j
    mov     ax,4fh
# e- x, [! Q# _! T1 M2 u6 `    int     41h
6 l; ?  ]2 j% ^- F    xchg    dx, es:[41h*4]8 n! o: ^# d: N$ i+ `- ]
    xchg    bx, es:[41h*4+2]% B: C$ L; x* t1 P* M% ~
    cmp     ax, 0f386h
) b8 P2 P5 E7 ]; K    jz      SoftICE_detected
6 O8 p5 N, Y* \: u' i0 C1 N7 A& H
int41handler2 PROC; V- D0 k/ d$ L1 N2 p
    iret' Q" \2 a9 N) U
int41handler2 ENDP/ N: ]; Q7 |- k) S6 B/ S
1 V  N* T/ y# {/ L/ F7 z

0 W  Z' x" ^& _' r  A) {, K_________________________________________________________________________
9 @; ?: U5 ^% x8 C. @  y5 c9 d2 |; D

5 [3 t* h7 D2 L6 FMethod 06
0 P3 {4 ~* ?7 e+ C! M( F=========
) E* p  P5 ^% v- Z  y+ {
3 A3 A% A% `6 L* ^7 N& u$ {) I- _8 x' T) j
2nd method similar to the preceding one but more difficult to detect:
- q7 L8 q7 r; _6 d4 ^6 W/ I$ H1 |: r! T- [( Y
  ]" _  S6 {! W2 E6 o; Z* u0 I
int41handler PROC
" b0 p% F# {! h# H' z1 a) n    mov     cl,al4 M7 u. C& @/ u3 Z  X- q4 K6 @% K
    iret) M5 M7 S& T. K. H( [& Y; x
int41handler ENDP/ g9 X% e3 ?  y. t& n
( d/ w: M/ P  X. |7 q9 `* J: W

; d) g! q# B- S6 C+ n3 S: w& M' O    xor     ax,ax. m) |9 H. U( p' Y. |, |# g+ v4 p
    mov     es,ax
1 n& n, m0 C6 s& I* o    mov     bx, cs% K0 U7 W- r& b' V
    lea     dx, int41handler- ~1 V( ~9 ^6 f5 J& U3 N
    xchg    dx, es:[41h*4]( P$ [. Y2 |% S
    xchg    bx, es:[41h*4+2]
: g; X5 q, Y1 }) `6 O6 M    in      al, 40h4 _# B8 }: R; X8 y' x# w
    xor     cx,cx3 c; {( Y$ v* F: z  N. f9 h
    int     41h- c# F3 t; v% O" C
    xchg    dx, es:[41h*4]$ i: n7 L, Q$ \. a' b1 a
    xchg    bx, es:[41h*4+2]
$ h6 q. a9 j- E6 c  c! _    cmp     cl,al
  k+ `, n4 U4 N8 L/ X9 l6 C4 E' [    jnz     SoftICE_detected
. k" z, f' }1 l/ h0 D/ K" G0 O# t8 A6 B
_________________________________________________________________________8 g: @# ]) {- G6 H, D) s# a
% e( b" F8 t" U7 ?) b
Method 07
3 T4 e8 j0 Q2 @/ v: [" Z7 f/ w=========
. d% s: t# ~# G: K5 r! v7 V. ~  t: H5 r; r% V$ `' q2 F* L. c
Method of detection of the WinICE handler in the int68h (V86)% X/ }( L, K% J5 G, |
+ i" J8 D1 [% @" |: a' H
    mov     ah,43h" f: _! m) j0 i$ E8 D$ f2 c  n
    int     68h
& L- d# r8 `7 g5 i$ D    cmp     ax,0F386h" e; Q& ^( d/ [" E, S
    jz      SoftICE_Detected
' x, e5 V# }' R& r4 E$ n
& M0 q" I2 _2 E. u$ n: }. ~4 S" B% Y, d2 A% _4 ^& C- O/ }
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit- ?. j/ `! ]! @4 V. A
   app like this:) l+ g# d& V' |. J. `* I1 \

7 [$ b, m8 @9 ~7 l7 I   BPX exec_int if ax==68
! t: T6 g; T9 `1 x3 X) o5 O3 {   (function called is located at byte ptr [ebp+1Dh] and client eip is2 k7 l2 f7 G/ y1 w, t$ u) X6 X; R" o
   located at [ebp+48h] for 32Bit apps)9 @- \4 b& N7 j( k* X2 v& c; ]4 f
__________________________________________________________________________1 T" b9 \: ]$ s7 w3 k0 \4 s7 u

% B* A. h) @. I, s1 e& f
" ~  l" J' G7 IMethod 08' X; s  \5 H/ j& S; ]
=========
9 }" M/ r% H4 k2 |) _9 o5 U
6 @* F: v" e* Z8 p& C; I4 cIt is not a method of detection of SoftICE but a possibility to crash the. a$ C; M" {  b; A0 W' F- e  h, f
system by intercepting int 01h and int 03h and redirecting them to another
+ {) F, Y  L* Z, froutine.
- j5 {4 B, s, [5 e7 EIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points& X4 U+ Q1 q' m! ]4 B5 P' W. N9 e
to the new routine to execute (hangs computer...)! f% \' C5 q1 |8 W; _( `8 m; M9 B

+ C0 \* o7 \; K/ Z7 V    mov     ah, 25h
$ Q$ N2 y  G! Q# K    mov     al, Int_Number (01h or 03h)
& _2 O, l3 |, N. t    mov     dx, offset New_Int_Routine+ J# P7 t* v8 @1 i; Q+ w6 }
    int     21h% n. t7 G, @( k0 a, O' b
% d* U" g" m* k: \6 p3 K' v
__________________________________________________________________________2 }3 u4 ?# J, T* Q$ u% Z
5 D" L' ~0 N  I% I' S8 ~
Method 09% ]9 m$ u$ \2 w" x/ j0 f- B* ~, ?
=========
2 l8 s, \6 E7 a
* A' P5 Z) B" ^! G2 j3 z  Y4 v& ~This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
$ a$ t' }1 i( h" s& W* d% mperformed in ring0 (VxD or a ring3 app using the VxdCall).& P* l" D5 h: H+ a
The Get_DDB service is used to determine whether or not a VxD is installed
: y. H6 n3 H0 q2 k5 B8 s6 ^for the specified device and returns a Device Description Block (in ecx) for  u1 g# N4 V+ d& C. H- z, F
that device if it is installed.3 A& _  r0 j6 _
: m2 S2 u' q; i
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
& K- {6 O3 B2 u2 n3 P   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)' @# }% `9 f7 F
   VMMCall Get_DDB( B( h8 c+ G9 t1 y, x( p2 q
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
% P2 Z. E* a( y2 Y
1 \5 c" H3 T! A, y) x) u( O* mNote as well that you can easily detect this method with SoftICE:
! `1 ?- `' I2 V, C* W   bpx Get_DDB if ax==0202 || ax==7a5fh2 O2 Q& \% Q. i- J

+ a  ^3 Q# h; l* `0 \6 r7 a__________________________________________________________________________
( N( R0 i$ X& o7 t0 {9 T( X- m6 R
$ Q% K' g! P' a# _9 H: c# yMethod 106 t7 |% ?; s$ S* R
=========8 u- g2 g% o) ~; E; ^0 q' Y
8 u0 D; h( ?2 M7 z+ m0 `( u# I, @! N
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with9 G; G; b5 N" j: b8 H3 k$ l
  SoftICE while the option is enable!!# x7 O& e& N$ v/ A8 X
2 X/ P& u, m- }& d" S
This trick is very efficient:8 A- K' F7 V. E! H  s; ?( u
by checking the Debug Registers, you can detect if SoftICE is loaded, w$ T6 @( m4 g5 N
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if) X1 J; b( A/ |7 [7 }
there are some memory breakpoints set (dr0 to dr3) simply by reading their
, A) d$ f3 R  a6 k. T  k2 svalue (in ring0 only). Values can be manipulated and or changed as well
: D3 b! [! t. s. y# n7 u2 F* K# k# u(clearing BPMs for instance)
' X1 M9 J$ Z4 A$ M: S, W; d7 x) K- D
__________________________________________________________________________
7 H/ y9 s# R% d4 F" y4 p) c2 P* c) t$ I  K$ x
Method 11, s( ?  D% R! w* a5 F3 t2 e
=========
! e: Q0 k% @& z1 @3 p4 ]/ X( U8 @: u& }: L% \9 O) @
This method is most known as 'MeltICE' because it has been freely distributed
  a* J; x  _- ^! E0 M6 `3 Y. nvia www.winfiles.com. However it was first used by NuMega people to allow# f) g+ g% m& W6 Y: p' U0 D9 U
Symbol Loader to check if SoftICE was active or not (the code is located
" ?$ p" ?( y7 j$ {5 m; S! Yinside nmtrans.dll).) f* }& ?. K9 d1 o& E5 s

# _% j7 Q* G/ P5 q0 a; ]The way it works is very simple:
! W) m/ j+ s3 n  A* a- |& l5 w5 sIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
* T+ t  A' f0 u6 y  i% tWinNT) with the CreateFileA API.
  V; E1 g1 I$ T7 h
/ F9 p" X; C2 }5 y' O" ZHere is a sample (checking for 'SICE'):
% ^* \  }8 l3 h6 l0 D: U( G
! O3 @: B) v" J2 @* IBOOL IsSoftIce95Loaded()
! S# D) `8 k+ V6 [{
  ^. d, F! c+ L5 _   HANDLE hFile;  
4 `, h) A( U5 t" j* I   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
( v# H7 U" o: v                      FILE_SHARE_READ | FILE_SHARE_WRITE,
* S! S: p& E, u                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
: ^+ }7 L3 p7 x8 L, X& g. _   if( hFile != INVALID_HANDLE_VALUE )
# g4 G3 T) c, Y  {   {
  E! x3 L- t: K( k      CloseHandle(hFile);
/ b; F% A' T) L7 E9 q" N& K      return TRUE;0 \& h! e  F6 H# S1 D1 ~& P
   }
9 l0 i" B1 T' `. r1 t, w6 z! P0 R   return FALSE;/ L$ w& U$ I! c! D5 N+ j1 Q
}
2 q8 |" f: v  ]1 m& k+ a* R7 l
- n. {' [& {! X% R6 r9 dAlthough this trick calls the CreateFileA function, don't even expect to be. x7 d+ ~8 ~+ d
able to intercept it by installing a IFS hook: it will not work, no way!
/ K" i' ~) p9 s5 PIn fact, after the call to CreateFileA it will get through VWIN32 0x001F9 Q" G  U2 n7 {0 I, K) {
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
) D, ]# C. d, I( fand then browse the DDB list until it find the VxD and its DDB_Control_Proc$ R9 p. q$ m) T
field.
8 ^' K! d/ D" p6 SIn fact, its purpose is not to load/unload VxDs but only to send a
8 L+ Q3 a4 W( H5 c% r0 f, JW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)' ?+ R8 }( T0 ^  i, W
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
4 B5 t6 E' E9 G1 b* jto load/unload a non-dynamically loadable driver such as SoftICE ;-).0 F( W$ t) r3 o. d; \* x
If the VxD is loaded, it will always clear eax and the Carry flag to allow  M9 i( ?+ f! N) H* a7 p
its handle to be opened and then, will be detected.' s- H% ?: R' ^
You can check that simply by hooking Winice.exe control proc entry point
9 L  B, H+ y. v8 g* t; U8 Zwhile running MeltICE.
( c) `" U. A+ o& ]3 L6 `  f
5 t4 ]* x9 \8 o- [0 c1 R5 p( Q3 F, M) B, Z  ?
  00401067:  push      00402025    ; \\.\SICE
  j2 w4 B: G' E3 Y  0040106C:  call      CreateFileA
7 h% S- _+ H2 m7 u+ t  i* b* [  00401071:  cmp       eax,-001
' A2 F( K" ]& u. e1 A; j  00401074:  je        004010911 S8 s5 \& \/ a# J/ D  a; T# Z/ b( ~

1 i; u" j7 P4 ^( F2 \( t
: C/ o# d# ]; y2 {* }There could be hundreds of BPX you could use to detect this trick.
: [9 e5 ~( m) g6 s6 J-The most classical one is:
; F8 B6 q- G+ J! r& j  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||/ \( ?6 W8 W5 P" k' |' h
    *(esp-&gt;4+4)=='NTIC'
1 \: D4 y$ R" X+ v8 ?8 n  \# Z8 _) }9 `$ k5 {  ^& @+ C
-The most exotic ones (could be very slooooow :-(
$ A( p. A! t- Q' H$ B- s& o7 I   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  ' H+ Z- F5 @& a# W  a
     ;will break 3 times :-(
5 W5 {! B( W5 }* Q+ r5 J9 ]
( C* F* k+ Y) r* u-or (a bit) faster: * w1 r: F8 `: d2 N' K+ P, }& A9 D
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
, }, f% G/ C: m- S) u# o9 F$ M6 p5 C
. B3 e4 A6 K+ X6 J- @3 M   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
; ?, }& X* I( h# J. s* o4 M     ;will break 3 times :-(0 x" ^/ s% H! C* q7 {6 n
6 ^% y; l0 h  q# U
-Much faster:3 n: g1 ?3 o; \2 S% H
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'0 p, J% K0 Y3 k4 x) {- ^
4 |; F& o: b1 A0 k3 {) u
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
$ w( ^( c1 G- Pfunction to do the same job:
! w5 G* w8 r. E- n6 O8 X. G' k. S$ T8 D( s6 i
   push    00                        ; OF_READ  P/ |9 `' E% x) w9 O# O! c
   mov     eax,[00656634]            ; '\\.\SICE',0
, V. `$ }2 z6 T' y0 h% d   push    eax
7 r* |' U8 t- O$ u' s3 D   call    KERNEL32!_lopen5 p9 K/ U' o( C# T2 p
   inc     eax
* }  c5 o; w# \( J   jnz     00650589                  ; detected
$ d: \% y2 H2 c' m9 U1 R! f   push    00                        ; OF_READ
/ }' z  @: E* j) }( y   mov     eax,[00656638]            ; '\\.\SICE'
! _- g6 ]$ [, ~; S* U2 q  ?   push    eax
) s6 y8 L' U+ {- ~$ G, q, z/ }   call    KERNEL32!_lopen
6 D% S. D7 V. F; W$ n% Z8 p   inc     eax
0 _4 [+ X! k. u9 q7 |   jz      006505ae                  ; not detected5 B3 @5 ]  u$ f/ H) F: P$ A) {- K( G

$ O4 b1 F- N/ a) E# c" Q7 G# E0 Y' z% w9 S9 |
__________________________________________________________________________  e% {& T4 J& g  h6 a

; T/ H; i" s. A0 IMethod 12% h( b+ o0 D. D# W9 j+ a- d
=========0 K' p& e+ r. }, ~2 r2 ?8 m
4 }$ W6 {; q& I1 J, @, _7 c9 y
This trick is similar to int41h/4fh Debugger installation check (code 05; ~+ g0 H- V) Q7 ]- f5 m. S5 d
&amp; 06) but very limited because it's only available for Win95/98 (not NT). [9 o( w( ?' Z( K
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
! ^, P  z5 _- v9 K2 G& @9 {# O3 c0 L' q. B5 X; o1 l
   push  0000004fh         ; function 4fh" W( ^2 ]* W' ^/ ?
   push  002a002ah         ; high word specifies which VxD (VWIN32)  U; N' ^) L5 V+ K+ c. @$ C
                           ; low word specifies which service* m$ |8 @2 G9 x! L  B
                             (VWIN32_Int41Dispatch)' R; d; F6 Z6 w& Q- J! b, L0 E
   call  Kernel32!ORD_001  ; VxdCall( `" U; b1 d8 Z% q4 y" ~2 e
   cmp   ax, 0f386h        ; magic number returned by system debuggers
) z2 N% y$ R- ]' {$ Y- T% l   jz    SoftICE_detected! S* k  G! I, r' Q2 J8 C4 g3 q
1 H; u4 M) O( q0 H3 m1 m8 j" ]; v
Here again, several ways to detect it:
& w5 G# ^1 s1 g0 O/ M
6 A. ?6 L2 M4 K  F& z) O    BPINT 41 if ax==4f
0 F. B9 p  N: B, s. ~
* Q, a. a3 l$ p- P3 D    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
, _3 P/ B: z$ W( z. P
& `, P! S, V- n) h& \2 q# A# E    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A8 i. P, b6 O- V. J8 L/ ~. ]! i

& B& ?5 m; _& P$ y    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!2 Y/ E( |: \4 d" g7 V
! Y0 y) }  y% U% z& Z; V
__________________________________________________________________________! `1 y- ?* h) K* H3 L
5 u5 d7 ]6 k" m# q5 [( @
Method 13" {4 m: U$ g' K" T
=========
( e" h4 b- p& T/ W1 ?& ]) B
6 _5 N( A( [; V1 n2 d. WNot a real method of detection, but a good way to know if SoftICE is2 E1 }. T% R9 T* i! Q; z( R
installed on a computer and to locate its installation directory.
9 f  o: M3 t- D' XIt is used by few softs which access the following registry keys (usually #2) :+ {- _) m/ U: l, M
3 n- }. t' J2 r% h! ~- w
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion( }$ T1 T( b1 V8 C: K' B, |1 _
\Uninstall\SoftICE5 q: {7 \# N) K# X2 `) v2 X* U
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE; Y$ Y' D- \# K2 ^
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion3 a  ?( d- ?8 x
\App Paths\Loader32.Exe
1 c4 v% C4 U; i' K: t
/ l: W- T& x1 W8 [' ?$ x. B) g! ?( g' s% X
Note that some nasty apps could then erase all files from SoftICE directory! ]/ {" N% }# j" I6 y  M& R% [8 u
(I faced that once :-(3 x* Q5 J4 G+ ~  W
0 _2 n6 K* I5 ]* T+ g# D. a# C
Useful breakpoint to detect it:/ Q* ]. V3 _% C+ R/ G  G% W7 z4 g2 G

/ G  s/ C+ i' ~9 |) j" I5 g# l     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
) C$ `* p: A; M: a3 z7 r1 `) O( S. m- Y1 k
__________________________________________________________________________
" A' ~0 w( v4 Q9 d  ~9 u
. c: O/ Y' f* R  d+ s" w6 j' Z! ?) _6 C
Method 14 2 t$ b" c, |8 e* o- ?% K* O
=========' Y4 s: `3 k$ {0 ]/ |
5 M% n2 }6 A4 t5 d
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose6 p4 t  k& N8 B3 {4 c
is to determines whether a debugger is running on your system (ring0 only).  D5 _: B% q& R# a' W. P
9 f7 d( v3 i8 P
   VMMCall Test_Debug_Installed
( k  P. ~2 h+ M2 t1 s6 ?   je      not_installed- H" `: h% B) K) x

/ ~& ~5 v, W/ d, V. Y7 U0 `5 ~This service just checks a flag., D5 t0 `% z3 a0 M. L
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部