About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
0 L2 l, t# y6 N<TBODY>% C3 i5 y- R& W* |
<TR>
1 M1 t1 n7 K% O. D0 d<TD><PRE>Method 01
$ N  j& W) S- o. i$ F$ {8 K=========
6 h: N, k/ _) ^$ R% V9 T
6 o; Z! c4 E; R* `- C0 uThis method of detection of SoftICE (as well as the following one) is
3 d$ b- c" P* f! I: K* Zused by the majority of packers/encryptors found on Internet.5 }$ T& H9 H1 X
It seeks the signature of BoundsChecker in SoftICE% v* u. k& ?- |

* C: D7 C" X+ L4 |: H    mov     ebp, 04243484Bh        ; 'BCHK'* U' X2 a& T  I& t$ i
    mov     ax, 04h' T' T) G  J; `. H
    int     3      
" e; N  P# n# d7 {# J' Z    cmp     al,4
: i: @) x$ f$ W+ n5 }5 _    jnz     SoftICE_Detected
( S1 ?$ Y* ?# e! v! n) S4 m# t0 d. h: A; Q, L
___________________________________________________________________________- S) o, C. J* P5 M+ I4 j

0 S. c' s- a* m1 }0 x' zMethod 023 Z) j+ A* ^) L. e+ b" m
=========& C% ?1 V! n; I9 J: x
0 T. g/ ]9 D& @) I
Still a method very much used (perhaps the most frequent one).  It is used
; @# F* ]5 ^) Lto get SoftICE 'Back Door commands' which gives infos on Breakpoints,
) w: ]2 @6 j# a6 [% Q+ Z2 V% yor execute SoftICE commands.../ b: k0 G2 v- P) V# J
It is also used to crash SoftICE and to force it to execute any commands( h% @0 Q) y$ h( b# X/ B
(HBOOT...) :-((  ( v( B* [0 L3 `3 M+ U

0 T& {! _+ x  p: m9 A1 nHere is a quick description:
/ K4 @) T) [6 v1 G' o, ~' U3 a  I-AX = 0910h   (Display string in SIce windows)
! ^- x& H; C% u-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)  Z0 G$ T3 ~3 t0 Z; \2 n+ F
-AX = 0912h   (Get breakpoint infos)
6 U0 o% P# }) k: x-AX = 0913h   (Set Sice breakpoints)
% E% _# h; _/ ~* U-AX = 0914h   (Remove SIce breakoints)
" H: z. y/ Y8 u  p/ K
3 t( \( E# z6 q( c! @* ]Each time you'll meet this trick, you'll see:! _- b( l( W) |! e; b* W. k: R# j
-SI = 4647h) o* f! X1 M' Q# d7 k
-DI = 4A4Dh
; h3 L  ^( A6 r$ `Which are the 'magic values' used by SoftIce.
3 {. _+ i# U/ P8 D3 ^! a% f+ C5 AFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.; k& l. ^+ l3 f

8 e4 \+ i3 \9 J0 x/ e4 U! E# sHere is one example from the file "Haspinst.exe" which is the dongle HASP3 L2 _& t- N6 k3 f$ g& b
Envelope utility use to protect DOS applications:
3 K: i" v" U0 C4 p& X# L, w5 r2 }9 t# l  G- I# \) S9 R/ l
& f- U/ Z2 _+ V- p. u1 q# H
4C19:0095   MOV    AX,0911  ; execute command.
' o. x. h: o& K. O4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
" _/ _: f* Q2 H: v* D4 }4C19:009A   MOV    SI,4647  ; 1st magic value.5 g4 O9 \! E0 S+ w/ K
4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
4 h9 N6 Z$ ?" {4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)8 |1 W, C" U- Z* x8 M
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
1 J; B& D% I( G8 ]4C19:00A4   INC    CX
- e  G% s. P8 v" x4 @4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
  ~5 ~9 w% b- ~/ o# s4C19:00A8   JB     0095     ; 6 different commands.( ]( J0 F0 f7 z. W- p2 b
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.* H8 A5 q* {, e; _- I
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)/ E- p; X7 V# @) n' Y6 g- A
# O. v$ @7 A5 I5 a
The program will execute 6 different SIce commands located at ds:dx, which
' }+ q0 e( C* E: P2 bare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
1 h, F* f- S$ z0 k/ w6 g7 ^; L! Q, J* _2 B- m0 m+ w& d
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
; ^$ i" ]0 ]8 u- `( T! k3 E0 R/ ?; r___________________________________________________________________________. L& \7 X/ W1 R% c  T9 i& f

" E9 `$ O& q! h! l. U" n# \/ A. k7 J- b- \
Method 03* k2 N- [. D4 W7 R" f  }5 V
=========
) V  e+ S) v: p% u9 m) S/ V2 p5 q" H9 L
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
( s% Y% ?4 E0 x8 a5 p$ x(API Get entry point)
* X# Q* s" m% a: w5 t        7 b+ E# ^9 I5 k/ r! ?; h6 d- o  E8 ?/ ?

/ J0 b( b3 y' r+ X* I" _* i    xor     di,di
% f. I7 U8 G' S( H- x/ R    mov     es,di
' W5 m7 |& H+ T9 [    mov     ax, 1684h       ) C3 D! w) O- p6 V5 U  p6 S2 C
    mov     bx, 0202h       ; VxD ID of winice+ o+ f4 T. D; t! a0 `3 }9 q
    int     2Fh6 h, j9 D# s1 w2 i- `
    mov     ax, es          ; ES:DI -&gt; VxD API entry point7 c8 i, N& Q; N0 `$ s; F& \
    add     ax, di( I" g% z$ L9 v- B; G
    test    ax,ax
* i* b8 ]& M6 p% U3 x; {    jnz     SoftICE_Detected7 J& i& S# V8 w. A/ k. |
% m8 u$ s- F  n
___________________________________________________________________________7 S3 @; ~: b: |5 J( j) Q

3 J# k, W0 a  p7 W9 G4 R0 t4 K3 FMethod 048 d5 g6 d1 D1 p; e; F7 V4 ?
=========
% y! \' s& X  v6 P# T: C5 O$ u/ A+ V1 B
Method identical to the preceding one except that it seeks the ID of SoftICE
% n/ e. \" r5 kGFX VxD.7 ~9 D* [2 U! Z* e

; a4 B4 X5 q6 `" X: A) |7 r    xor     di,di5 p' P2 ?* ~: v% P2 Q3 Y
    mov     es,di) `6 c. P& V* n
    mov     ax, 1684h      
5 |' n- S* D& q- u    mov     bx, 7a5Fh       ; VxD ID of SIWVID
/ ]5 E( R5 z6 k: t; i; W- `    int     2fh
, p  E/ o. R9 T  Q    mov     ax, es          ; ES:DI -&gt; VxD API entry point
2 J! I! ~' S: p    add     ax, di0 R5 M% |& |3 Z& c
    test    ax,ax
9 D- y- w: b" ?' ~/ B    jnz     SoftICE_Detected0 a, e0 n6 V7 t% c0 Z) ?
: d0 E8 A  A1 ]$ S2 j# j
__________________________________________________________________________: D  g( M$ A, I4 v3 S; V5 |
1 G/ P7 x6 u; C4 }. t$ v0 n& ?( Q

: P* V4 T! X9 N1 BMethod 05
# `8 ^) H6 z  ~! P=========' Z# d! S+ a  e# H. F
9 r/ ^4 J+ J5 c: }0 M
Method seeking the 'magic number' 0F386h returned (in ax) by all system( p% C- ]0 o" E1 z( k" T1 M2 C" t
debugger. It calls the int 41h, function 4Fh.* U5 S& z8 M/ _% x
There are several alternatives.  ! F) J% b) M# i$ F0 @8 f7 Y
- _) S* c* \. l) S/ C* E
The following one is the simplest:
( Z+ o8 V5 \8 s( T( t0 a$ O+ y7 _8 G9 C& ~6 k( D4 E" Z. O! @9 e
    mov     ax,4fh
' G* N; f: M6 x- l4 p# l( }    int     41h( `: ^) Y# o' Q4 p, X# z
    cmp     ax, 0F386
, W6 g- v& @2 u% [  {! }: @+ E    jz      SoftICE_detected
! G( q/ }: Q8 P: Q  l; V; H& c. i' T8 T' }- K- M

, O7 v9 i9 H7 k* T" t# JNext method as well as the following one are 2 examples from Stone's
' p, i" I2 ~7 {- O"stn-wid.zip" (www.cracking.net):
* [9 M7 q" S7 Z  T: R0 [0 o% B
1 t; h8 M$ W8 @! l( J    mov     bx, cs6 R% g( G! x! c* n
    lea     dx, int41handler25 w& s. f) a( r+ G9 F
    xchg    dx, es:[41h*4]
+ e; b7 N! z3 m' Z( t* m$ X1 v+ a" ^    xchg    bx, es:[41h*4+2]3 b9 h, a) N. T% B! [2 q9 W; c7 r
    mov     ax,4fh3 Q5 C4 s5 W( o5 ^! l4 j5 |
    int     41h
5 u9 n4 d. H; u/ w; l    xchg    dx, es:[41h*4]
- X$ m' K2 e$ `3 x# z0 u0 ^    xchg    bx, es:[41h*4+2]
0 W7 O' _9 E, x% K: L, S    cmp     ax, 0f386h3 e+ ^& h+ ^8 _' T6 }2 h1 A
    jz      SoftICE_detected
  K, {) x. `+ R+ @. B$ k, _) [) }' D1 l2 H$ k0 S/ t/ g% }
int41handler2 PROC6 @2 g4 k$ T3 Y
    iret
4 V4 p" `- r7 X' l9 E' m3 R- Dint41handler2 ENDP
6 L0 f# ^+ X+ L5 y, n1 X, C
; Y3 p9 T; }3 Q+ n% l9 t" O
+ y8 \# q- @5 b9 m! W_________________________________________________________________________$ O% n0 Y2 r0 z' X" ^
4 i% X8 l" G( g1 ~3 Z/ V# B

" x# w" a& a# ?8 _/ GMethod 06
' N/ q" z& U0 K0 q7 g=========; c, |& f; M% c' S: Y
( l' s" ^# E3 n6 m! X; s

3 F3 _+ u2 s2 G2nd method similar to the preceding one but more difficult to detect:0 `, T' h! p1 c4 c% B

+ g' r7 M4 t) A9 q" d* R4 i4 I7 M, r( D2 ^# }$ Z( B' h( l! W  f* }
int41handler PROC5 |: p$ A. i9 _. p% H
    mov     cl,al
5 X4 s$ H! Y3 x3 T    iret
+ g+ U0 @2 {0 R: H) N3 aint41handler ENDP6 _9 P; q7 S4 Z3 y

; t1 Z9 e2 A' F, C& B* g
  ~, M4 {  a8 ^$ g: Q' \/ N5 k( O    xor     ax,ax
' g2 y2 P+ j+ t$ f    mov     es,ax7 i2 w0 K8 O# U  a2 S- [3 x( k# F+ T' Z
    mov     bx, cs
  c7 Y! p. o! Y. L% v+ g. [    lea     dx, int41handler" Z9 S% T0 M( @  `9 m1 Y# b
    xchg    dx, es:[41h*4]; P8 s* f& e' V% l  ]
    xchg    bx, es:[41h*4+2]" n( o# W  E- I' k4 t: R3 ~4 V
    in      al, 40h
( O" H3 q/ [: {* k    xor     cx,cx' l' c' I9 D% t' n: [2 y; p
    int     41h7 x( g* a8 b/ Z! O# ^+ n
    xchg    dx, es:[41h*4]
2 w1 {; g- V  K9 v- Y/ ~/ H    xchg    bx, es:[41h*4+2]
4 ~! x$ I/ w8 X1 @! P4 ?    cmp     cl,al
8 m4 G' O8 D: X8 ^$ f9 D    jnz     SoftICE_detected9 E7 b1 K1 j2 U% A$ ~7 g
3 q1 m: X. f+ H; {, [7 U
_________________________________________________________________________
8 H; f3 e+ }7 u  R% w7 d, Z4 D$ Z9 p$ g3 Y; [
Method 07
- O0 |9 n1 H5 U! z' |, ?* ^7 {% M=========
% K5 D6 B' Y& R" @0 B: w- u# D+ l. {# s. ~, R/ E" a- W: O8 ]
Method of detection of the WinICE handler in the int68h (V86): S$ R2 ^1 ^7 n: W) @8 H( W# x
2 m6 R. |6 Y. L8 W6 w
    mov     ah,43h
" ~  V2 q  Q" x    int     68h% L  z2 N0 T9 u5 }) `% ]. T9 f
    cmp     ax,0F386h
7 B! ^6 g! P: O0 E- V$ j; Z6 x" t    jz      SoftICE_Detected& c* O1 z8 M7 C5 ^

7 n# a+ F! R, v0 n; A3 h$ p0 ~! ~" x8 D
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
$ v* F3 [4 F1 `, T   app like this:1 z( C0 A& O- M8 m
+ u: Z! W1 n6 t; I( r
   BPX exec_int if ax==68
+ Y! b: V  ^- Y! Z9 W" c: b   (function called is located at byte ptr [ebp+1Dh] and client eip is
) m! d7 R: I  |2 A* l   located at [ebp+48h] for 32Bit apps)
; L3 a  C9 Z: b__________________________________________________________________________
- I$ p8 X  E4 [+ y) a- [1 k4 z! |( X0 [3 r' a( [
9 B7 u$ h' _; x
Method 086 B2 |2 @0 o9 ^% p4 |0 ^
=========8 c' I  O$ H8 K6 B
) L% @8 ~  M. a! D
It is not a method of detection of SoftICE but a possibility to crash the+ o: F5 W' o' x, Z7 O
system by intercepting int 01h and int 03h and redirecting them to another9 k8 w) d; E0 p% l+ ]! _
routine.& N( S6 J# \- q1 P
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points7 J  U& y0 _1 W( m8 |
to the new routine to execute (hangs computer...)
0 e2 b* T$ n  R" b  y# P# K
  P! z5 i" \+ u8 N3 h3 ?% t  h! {    mov     ah, 25h6 j8 v4 Y8 P' f" B$ @' {
    mov     al, Int_Number (01h or 03h)
: m; x1 T& j; t9 H# m    mov     dx, offset New_Int_Routine
$ D9 B* m, j4 e$ L8 s7 _) S1 ?    int     21h: |0 {1 N. K+ `2 m
  ^/ e8 T2 B- W, ]* K9 `
__________________________________________________________________________
" a5 C, e6 s+ G5 U/ f; F9 L
2 W' p5 \3 ^2 U3 }& ^  j9 J8 HMethod 09
. Q2 a4 ~8 i  }  Z) A8 H; m1 u=========
6 T0 S, q5 N& n+ R7 b5 n6 `) A% p
$ C, A- s* h" ]+ d- ]! ZThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only$ _* J* W/ R0 H! X+ v2 @
performed in ring0 (VxD or a ring3 app using the VxdCall).2 h8 }: y! S* n/ S
The Get_DDB service is used to determine whether or not a VxD is installed
+ E2 l& F7 M, `for the specified device and returns a Device Description Block (in ecx) for
/ q- B" c7 R! _7 @that device if it is installed.0 ]; k' X0 o3 N. G

; h% v! J- s; h) g& F+ p; |5 C$ ~( O   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID* k! ~) h5 u4 ?% f3 Y( H1 e
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)) w+ m' e' {# }0 @+ r, }$ X& s
   VMMCall Get_DDB
' L9 F2 K/ V( p* n: A1 C( C) b1 I   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
1 J9 \: G; [# A# s* b4 r0 P( M- F0 q$ ]2 S! Z- s# z
Note as well that you can easily detect this method with SoftICE:
6 i  g, \# V! N* ~6 ?2 r$ L/ R   bpx Get_DDB if ax==0202 || ax==7a5fh
6 [3 x' K; ?+ E: `" i* F! s' R) H7 _+ o1 F
__________________________________________________________________________
/ L$ N" d7 U- m. F' R0 }4 ?- S1 Q, I& [9 ?2 `* x: U$ O
Method 10
9 m  M% F1 n2 g& o" J=========# {8 q% x, G; s: I# [2 ~1 E) u
: ?% v& k' k7 H
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with$ u. r% c( G' X& P+ l
  SoftICE while the option is enable!!4 d% H- V5 `+ |+ O: n
4 e5 e5 Q. A- Q; s# m5 r; k9 q
This trick is very efficient:7 A& F, i( B) U/ R
by checking the Debug Registers, you can detect if SoftICE is loaded# G. Y4 t1 V/ c% }- F7 V( z8 k
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
- ]" U" N+ L9 V! ^0 |1 `! @there are some memory breakpoints set (dr0 to dr3) simply by reading their( h  q# ^3 n  }; S9 e8 J
value (in ring0 only). Values can be manipulated and or changed as well- k$ I! J- R* L3 \1 u3 [
(clearing BPMs for instance)+ O3 e4 x& `( _( K- j7 i
# S9 N5 \0 l+ a) h0 L+ o
__________________________________________________________________________9 d' [" s# F2 u6 A4 b. b
+ Z; e& Z+ ?1 L0 J
Method 11
. {+ W8 ]( Q9 O2 s  j+ H: U1 j7 T% s=========- K2 R. c9 \9 m) ^

: x! {0 R& m& A5 [3 k! |This method is most known as 'MeltICE' because it has been freely distributed2 a0 C3 D% u0 Y: I3 W  l9 I
via www.winfiles.com. However it was first used by NuMega people to allow$ f& Q' b' I5 U6 [- A5 D
Symbol Loader to check if SoftICE was active or not (the code is located) i4 i7 s! f. ?
inside nmtrans.dll).
, r  u, l  b  i  C) M! P5 h6 P% ^% W* i% G8 B7 u$ Z2 j
The way it works is very simple:8 `2 [1 ^, x: z; d5 _5 P
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for4 c' i4 e0 M; S; A2 d
WinNT) with the CreateFileA API.
+ Z1 o9 m& e* [) Z1 p! \& K6 P4 g8 T
Here is a sample (checking for 'SICE'):
  ^- F( }* ~! n4 v) i7 f
/ m7 W# {* ~1 Q8 f! t1 wBOOL IsSoftIce95Loaded()
3 Y8 U) d) x% Y% Z& [{) N' B# U# E& C/ Y% Z. x8 ~
   HANDLE hFile;  3 ]% D( P6 p8 U4 _) V& z3 g
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,# t  P) X" s8 X$ [; }' J
                      FILE_SHARE_READ | FILE_SHARE_WRITE,
5 R) `2 X$ i- `0 {1 r8 J                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
' _8 _9 U$ k+ A% L4 B   if( hFile != INVALID_HANDLE_VALUE )
' E# H! e9 u0 r# M! Q   {. S; \9 e  U" `; u
      CloseHandle(hFile);" P: r+ Q) z8 C' Z' ?  J: O* ]6 ?
      return TRUE;3 [2 `" V- }& j+ L/ f3 Q2 E
   }  c1 O3 L3 l" z/ E
   return FALSE;' n3 y0 d7 Q7 D1 C% y5 t
}6 B6 W$ s4 R+ h' a/ u% }

' ], v4 g4 J  b& RAlthough this trick calls the CreateFileA function, don't even expect to be
6 ~+ `/ G$ f6 H' d0 o+ Mable to intercept it by installing a IFS hook: it will not work, no way!
) N+ G3 G' e+ wIn fact, after the call to CreateFileA it will get through VWIN32 0x001F
, T: [& J3 h" O9 s( E# r6 M% Mservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
- M6 E' N3 d/ O$ s1 B/ V3 xand then browse the DDB list until it find the VxD and its DDB_Control_Proc) x/ G" C, x/ {
field.3 B8 j; ^- R! L/ a9 e% V( L! d
In fact, its purpose is not to load/unload VxDs but only to send a : P- `7 D: K) S$ P
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)( K/ q( ^* X0 K" n
to the VxD Control_Dispatch proc (how the hell a shareware soft could try1 k0 ~3 C( F- W8 P% J/ d0 }
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
7 G! l7 d  P& EIf the VxD is loaded, it will always clear eax and the Carry flag to allow1 H6 |6 S( k) y  B. R' L
its handle to be opened and then, will be detected." X1 O* Y- L2 H% H6 `2 k+ H
You can check that simply by hooking Winice.exe control proc entry point
7 W* h2 C- {3 t+ i. n. U& nwhile running MeltICE.8 I3 B7 B# E- U% D8 K2 C1 t

! Z! \' M9 [+ g. E) A0 I, E
% ~! G( [' G, I* F% i  00401067:  push      00402025    ; \\.\SICE
- E7 P, ^, M8 F% q  0040106C:  call      CreateFileA
* {7 G+ a7 `7 Q4 w- g7 ^: U$ o/ I1 Z  00401071:  cmp       eax,-001. B# X* ]2 V* i+ @
  00401074:  je        00401091
9 t$ u( k3 d; C( y0 B/ R" F' G) A% N9 n' o: |& m  Z! Y/ ~3 a7 L2 v

, Q1 Q- p1 p# C2 q6 yThere could be hundreds of BPX you could use to detect this trick.9 d+ ?# B6 V5 }4 \/ i
-The most classical one is:& u4 t9 _* n* Z+ Y% Z& J5 J" A
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||1 _$ h( y2 K! D. G+ m
    *(esp-&gt;4+4)=='NTIC'
6 b# ]) _# @3 R1 O' x2 O+ z, r9 a0 R) Y( T
-The most exotic ones (could be very slooooow :-(: F6 Q' n' O- x/ k- L( P
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  % n: E. e9 e, \8 ?, D
     ;will break 3 times :-(
' Y8 r' r: w; y
# p. _& n( f! Y-or (a bit) faster:
( c  z7 }% I/ |: h3 X8 _   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
  X' ^; x' B  b4 t
  @! U; P7 c; G( {  j   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  2 I5 _# ?0 M0 v5 V4 j: n8 [* @6 H
     ;will break 3 times :-(
2 ^7 `8 Q, z  z0 F, U: L) w6 U$ u# H- J* d  }
-Much faster:
0 e9 t9 X2 l/ a9 S   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
* z3 ]$ A' Q3 _( y/ F/ R, a8 {" g  _; ]8 f6 I* p0 r! G
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen7 {# E- L9 r% Z6 f4 M: U
function to do the same job:% r, W! C) S1 }
5 C/ [6 B! ^0 D( `+ P
   push    00                        ; OF_READ
9 a+ T) H8 _, n8 T& O' f   mov     eax,[00656634]            ; '\\.\SICE',0
- D1 y+ w3 B- K   push    eax& j5 I, S; {2 \# t* |! J! }
   call    KERNEL32!_lopen8 J2 n$ v4 _4 R$ j" o9 W% T
   inc     eax
0 F3 q3 f$ X/ E: ]$ Q   jnz     00650589                  ; detected
" \0 ?; f0 B8 C' ?2 @+ D! k   push    00                        ; OF_READ" P% d4 V( d+ a; Y) d
   mov     eax,[00656638]            ; '\\.\SICE'
! G6 ~$ E% u. e# k   push    eax
* W% E) U" ]5 ?2 g' b. p# K   call    KERNEL32!_lopen
2 R' p' c6 t/ z) C0 V3 e$ _& t   inc     eax
( J3 K# c3 J2 f' ]+ ?" T3 }5 w   jz      006505ae                  ; not detected
1 d% S1 g4 Q& b+ O! L7 v4 c% e5 i$ o8 W* D5 I# O; e, c

9 s+ R8 L4 ~3 a' M5 b__________________________________________________________________________8 ^/ d/ M0 @3 Z- Q

9 E- b6 Y  u3 Z) Q5 n4 iMethod 12
, x# v" O/ V  t3 H, Q' ]/ C" S=========
, w) R/ d$ `0 {+ D8 {  u
. X" K, y% D# {0 S& h( PThis trick is similar to int41h/4fh Debugger installation check (code 05# B2 b4 e, }. l9 g  O" b
&amp; 06) but very limited because it's only available for Win95/98 (not NT)/ K  b1 |+ V3 r) n' H
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.# b& Q2 h5 G3 Z1 ?
4 I$ f5 U8 z2 ]+ s3 j
   push  0000004fh         ; function 4fh% D0 V. g: L+ A7 y3 T- c
   push  002a002ah         ; high word specifies which VxD (VWIN32)# a0 V% Q' ~/ C: q6 y
                           ; low word specifies which service1 g( c' }' E! }; m+ m- o
                             (VWIN32_Int41Dispatch)
) `3 C1 o% l2 I. u6 \1 E   call  Kernel32!ORD_001  ; VxdCall
9 `) \$ o1 x# @/ p/ N   cmp   ax, 0f386h        ; magic number returned by system debuggers
" Q4 U) E9 p5 \1 x9 J* D4 N! B0 |) d   jz    SoftICE_detected
- @1 [" t# i; e( t% s  s7 ^# S8 V9 S9 p: i% S0 z
Here again, several ways to detect it:
7 L1 S7 N* Y& ?5 |% c) _1 u0 {! g7 u# {3 u
    BPINT 41 if ax==4f
( ~9 s5 @9 U2 t, y5 \; q+ c
0 p: T: G! _3 Y6 N* H    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
/ @" f& A/ q: v6 R& {4 K1 r5 Z' Y$ I
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A& ?' M8 I0 \4 i4 m% q
7 f$ ~0 F: R, s0 o1 N/ d* v
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!# l4 [, D: c) l# J4 y

9 q7 [2 E9 G, w$ N( c__________________________________________________________________________3 T4 F7 ?; l: B2 O& V' Q

  I; q) a. b- B  \8 U- @Method 135 s! k) b" x/ w/ k
=========
9 y( o$ Y' f2 z- A# g& l, s- w/ j$ E' X" s  k
Not a real method of detection, but a good way to know if SoftICE is4 q; j- w) U. D' g
installed on a computer and to locate its installation directory.
; y1 ~; y1 o" H' {It is used by few softs which access the following registry keys (usually #2) :
0 q% ?8 L; P9 g( h/ Q- g! d0 p, X$ ?' B5 t
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
  p" ?# v- ?% C5 C\Uninstall\SoftICE
. C  s( t7 j+ p5 Q$ R; v-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE; q6 q' N4 h4 u! T6 ?& L* \% M% Q
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
$ b8 o$ h9 E- S6 e* n0 w\App Paths\Loader32.Exe
1 [6 r. p/ K6 ~# i' z9 t: u% [$ E! y1 M" z0 ^9 f+ g4 z* S, U5 v
7 O0 @% e  U$ p: T( Q( O
Note that some nasty apps could then erase all files from SoftICE directory
9 M4 x3 |9 o+ d" _( |(I faced that once :-(1 N- l) h( J" t$ U
+ x% F, E9 H/ R8 j1 n' U5 S, X6 n9 _
Useful breakpoint to detect it:
' P0 e' N2 b* E& z5 \  w# x( `
" @# L0 U+ K, e/ p     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
5 p0 @. P  `, Q( P% T3 Y
0 f1 U6 B9 n3 X. Z' S__________________________________________________________________________
& N6 \+ U' }9 l( G3 T2 ~! k+ h+ O( n. @7 T7 V9 ?2 G6 w3 b1 }$ x+ M
( W, _2 }) g# p* d
Method 14
3 ~# T% f3 K8 \5 L* d5 B=========
6 E/ t# J5 _/ R4 q/ V9 u
, S7 w" v! |2 u4 N/ f. hA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose2 X2 u3 e. X9 {5 g
is to determines whether a debugger is running on your system (ring0 only).
9 H! j2 z, A( }4 z& V3 K. Q1 t# S3 e8 o' W: N4 h
   VMMCall Test_Debug_Installed( S* Y9 \6 R8 D
   je      not_installed0 Q8 }. P- D6 V4 @; F

; S  y; ~) X" iThis service just checks a flag.
( F: x' c, Y* a! F& f/ F1 D</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部