About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
# ^' Z8 r# s  U$ W<TBODY>
+ c. S0 O' w( @, Q<TR>
: o! N- z4 C( \2 A  K) m& ?<TD><PRE>Method 01
( E4 ^; V& d8 v  {6 E=========' _5 K8 i) a' l4 }% i( o5 K

% U$ S9 V3 ]1 A/ PThis method of detection of SoftICE (as well as the following one) is8 b5 k& _2 Z0 j7 a8 H2 t; c
used by the majority of packers/encryptors found on Internet.! _8 R( R. L: M7 ]
It seeks the signature of BoundsChecker in SoftICE
' `; d, ]. M% ?" b
$ d4 \, B( E/ B" q1 J6 G' a' U    mov     ebp, 04243484Bh        ; 'BCHK'8 }. K1 ^2 [$ }2 U
    mov     ax, 04h2 [+ E. V6 J* @/ q! Z+ A4 ?
    int     3       - s! c  k! T* P! L8 g* ]4 c
    cmp     al,4" `- u5 ~% |6 h
    jnz     SoftICE_Detected
' C$ z4 k/ f, y- a+ J' B. f- O( k) Z& n
___________________________________________________________________________3 K/ |% _% n' U: k" `
! X' t4 t9 N) L7 o8 Q  z- e3 L
Method 02- m4 w! u, O+ M# x  w' h
=========( t( K8 U) u) _1 H! E3 Z

# g( F9 C8 S" C2 a' {Still a method very much used (perhaps the most frequent one).  It is used
8 J" k! l+ x$ d/ |5 q: [to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
6 u! k% i) j6 }or execute SoftICE commands...
" A) X# S% I/ m1 s. B- ?It is also used to crash SoftICE and to force it to execute any commands6 {; H3 f" K! ^' ~$ m6 w* d
(HBOOT...) :-((  
4 p$ }# D2 A5 t7 j/ q6 U! t" A0 V2 ~' g
Here is a quick description:/ N8 a1 M5 G3 C5 b  p
-AX = 0910h   (Display string in SIce windows)
9 A' C, h0 w: W' K; c' w0 ]-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)3 A( }1 q7 D; A2 E5 A8 U
-AX = 0912h   (Get breakpoint infos)
1 X' X" K1 e" N$ l-AX = 0913h   (Set Sice breakpoints)
. X+ n) ?( ^1 v2 X5 b, @-AX = 0914h   (Remove SIce breakoints)
$ q: C/ E4 O: p( `3 \3 l7 y$ J5 g! l
Each time you'll meet this trick, you'll see:0 \8 @! `+ a$ Q! H
-SI = 4647h
$ D; ^' i' ^- i* W' X-DI = 4A4Dh3 z# D, F" w& H/ H  |3 `
Which are the 'magic values' used by SoftIce.0 I! x8 K- Q' z
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
* Q& I, P! g+ K. u! m& [% o0 c; [, p& T
Here is one example from the file "Haspinst.exe" which is the dongle HASP  U* n- O& E" I8 b5 E
Envelope utility use to protect DOS applications:
5 R: h2 `5 `3 v( U/ h
9 p- ]! t$ T- K2 p% h/ U1 x
8 f- Y( ^' X) @6 H9 ]# ~4C19:0095   MOV    AX,0911  ; execute command.
2 B/ {9 M' T- U3 D0 g9 |4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
  b- _* r" e3 @4C19:009A   MOV    SI,4647  ; 1st magic value.
9 m/ l5 i5 @2 Z# F5 M4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
7 _1 S- n! W3 t4 K8 P7 k, z4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
% f  |- }% R$ s$ @3 p6 H4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute- w4 v/ Y% c9 `/ d% F
4C19:00A4   INC    CX
9 z5 D' t1 G) W0 |6 c+ f  j- U4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
. X/ `* _" K) L/ \5 B) k; q4C19:00A8   JB     0095     ; 6 different commands.
1 Y5 i' J5 N. e4C19:00AA   JMP    0002     ; Bad_Guy jmp back.. c9 ]5 `4 x7 y( h4 c9 }# i" Z# L
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
' n7 d- y2 j1 _  t( o6 D5 w
; e8 h4 Q& o1 ^5 f& ~6 GThe program will execute 6 different SIce commands located at ds:dx, which
4 V8 h7 D! j& \0 I1 g5 V6 W: L% care: LDT, IDT, GDT, TSS, RS, and ...HBOOT.$ g$ e- [. D6 @9 ?3 Z
: R+ O9 m/ Q; U" S% z
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.- Y" a; F6 s: l' x' b: m: ^2 [
___________________________________________________________________________
. [0 |- J  |& F( e6 e, i4 P: \5 y+ u' F
  F) k: G) {4 t* d* g+ _5 L0 r
Method 03: G% B1 r/ z4 r) ?/ u
=========
  @' b8 V) K' G! i+ o0 w4 B2 |- ~, G1 j
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h% Z- L4 \' p0 s6 N/ g! E6 [
(API Get entry point). _5 ?3 Q3 U9 ~4 V( T) B
        
$ c& ]# F+ }' B! p7 J( l7 B5 d" t1 ~' ?2 u9 k3 h& `% ]. ?6 g: y
    xor     di,di3 X5 e- r7 @; [) [- x
    mov     es,di
% {- k' s' Z: u, W    mov     ax, 1684h       ; _9 j( ^, j( v9 J1 X: {
    mov     bx, 0202h       ; VxD ID of winice
2 f' h5 m/ f: N, C" E    int     2Fh
) O" c( M: h  T    mov     ax, es          ; ES:DI -&gt; VxD API entry point
) n$ ]; b" s" s: L9 l8 {! _" ?    add     ax, di
& n: |2 G3 U: n/ L- y7 ^0 F& g    test    ax,ax
& k1 [. l, `6 J/ Z: b0 `& A' u- ^8 v    jnz     SoftICE_Detected9 o; F% T7 r3 T- B& J3 C3 W" P
( l, f* x: }6 S4 c2 a
___________________________________________________________________________- @  C- s4 P) z! R: N$ Z

" {3 t  U8 M# O6 A, }$ fMethod 042 d( D/ z3 X5 n
=========1 Y. X& {5 j1 d/ H5 q& X

1 V+ ?. J' n) H6 cMethod identical to the preceding one except that it seeks the ID of SoftICE1 D- z; [0 c5 ^
GFX VxD.
" w7 Z; R! N$ ]) c: t+ b% j" o: O) ~) m$ c5 T1 B) S; Z
    xor     di,di( l- e( ~$ c8 m! [. b# T- t
    mov     es,di
$ S# L( y# Y0 [8 S3 ]  q2 q    mov     ax, 1684h      
! U8 _/ N& L' L# E$ M    mov     bx, 7a5Fh       ; VxD ID of SIWVID
. D1 F4 v0 X9 v. w    int     2fh- R- f  l6 A' r2 c
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
7 A- K2 O+ Q* ?  @- T/ r0 P    add     ax, di
  C' k2 P+ U( l    test    ax,ax) |+ L) M6 H9 v: e/ w( E
    jnz     SoftICE_Detected( b. w, a& R' t) N
- a* p2 O, H) @' B/ J  e- e
__________________________________________________________________________
! p% o% G' x7 `
1 {& c4 W& w) ^$ |3 l" J/ Q* ?
+ v! H5 U2 _# T; ZMethod 05
. C" Y1 H2 m% s3 T=========! G, o0 i" G) E: L
0 i+ L( }, G9 r) F+ V( Z8 q& S
Method seeking the 'magic number' 0F386h returned (in ax) by all system, U/ I4 G7 l9 r& q) T( S
debugger. It calls the int 41h, function 4Fh.
( b' ~: z0 ^+ Z8 ?3 wThere are several alternatives.  # X4 e5 K  O$ M
1 ]1 X: t3 D1 q6 E: v$ k( a! h
The following one is the simplest:
- r( Z' _) E9 p" r' V
! s9 F' j- ~5 j# h% s3 {( [2 |& q    mov     ax,4fh5 L4 |9 ?5 v% }* l' i1 q. K
    int     41h$ O0 h3 n7 I* [" I! Y
    cmp     ax, 0F386) z' D" d9 |/ R
    jz      SoftICE_detected( ~; O+ t0 n  p3 W6 f, Y7 a
6 w1 _1 Q- r1 S( s& g
8 b! A5 \- L% |' A
Next method as well as the following one are 2 examples from Stone's 3 P* F0 w) V  E4 e8 r7 @! d& K
"stn-wid.zip" (www.cracking.net):. @* ~8 j. ]2 J1 s+ z* i) x) q& P

7 a+ C- D+ u- J% C! h/ A    mov     bx, cs
; M5 v2 g% ]: r    lea     dx, int41handler2. g" f' @1 h) m* A2 J. b
    xchg    dx, es:[41h*4]
' d6 @  l+ B5 W7 S    xchg    bx, es:[41h*4+2]0 P! w( C$ O( @1 z- J' H  i
    mov     ax,4fh
1 k3 Z: W1 H' U1 X    int     41h
- L: p6 T' @! a. w6 D+ r    xchg    dx, es:[41h*4]2 a; F! ]( ^' f' p% b
    xchg    bx, es:[41h*4+2]7 K, g* d" `6 C. r  J* t, v
    cmp     ax, 0f386h' [) e- b& l+ ?* a2 p
    jz      SoftICE_detected4 T; H+ q; i* v" S& G" O( o; K* \
6 F( }7 C+ W  O- `$ e$ I
int41handler2 PROC6 J4 P$ n: T* t
    iret
( G5 ^+ N% ~: R& H  W% D' m* Lint41handler2 ENDP; v/ }! f4 I/ C5 E) q

/ T* Q* E* S9 s6 t1 n9 v+ ^7 H
( Q% c5 B1 S# f/ b, x  n' p_________________________________________________________________________2 q$ i5 p* }1 g$ H6 A$ I' `. y
+ n; h* y. \5 P* }
( Q/ R& J+ r$ J
Method 06
( m" ]$ h; J" G' u+ d=========
5 Z7 n4 e. m1 G( C  i& O# K1 W
% B( V# C- d( \- C% M, `0 C' F  C. ?4 m- l; X
2nd method similar to the preceding one but more difficult to detect:
, x. x, U3 [+ Q3 U8 _- o+ f
' ~1 L- I  e3 ~% g5 Q! D, Q) a  A9 q  J0 t' }
int41handler PROC
+ m9 m. W6 |, N0 ~: I3 R/ w    mov     cl,al
& k/ i5 s5 m; `' J; ?. ?9 R8 x    iret. G  V4 g) O( \1 Y# `5 o
int41handler ENDP/ f  U5 w0 e' N& d/ w. c9 S0 q
8 l* G1 |" v" e6 s, i
1 V9 ~) B; A( L. B/ o6 O
    xor     ax,ax
8 r. x& N7 z9 h2 v    mov     es,ax5 Y$ X7 ?6 a' Y1 U- M
    mov     bx, cs
& l5 M0 T1 @& y) P    lea     dx, int41handler6 |% D+ w6 r% |7 x( P
    xchg    dx, es:[41h*4]" `/ s+ d1 T7 ?. v7 J
    xchg    bx, es:[41h*4+2]
! d0 q- \0 j3 @: S$ U    in      al, 40h
$ E  \' o( {, L& G    xor     cx,cx
  H% f$ Y% I2 k: Z. o    int     41h: Q6 G+ N. o. V4 @
    xchg    dx, es:[41h*4]
  y$ O; s, L2 g2 F    xchg    bx, es:[41h*4+2]
" L0 h0 b% a8 c8 ]5 x6 _    cmp     cl,al$ O2 G7 d- M( R( x
    jnz     SoftICE_detected1 z" N/ U7 U) U' j2 e
* [) s7 ~3 M( w. \
_________________________________________________________________________9 e: j- V. K% e5 X
# ?* r9 Q( e$ }8 V) x
Method 07
( q) G9 J" F: {9 }=========8 M' ^1 n; d% {
# k  D/ p. s0 ]
Method of detection of the WinICE handler in the int68h (V86)
3 t  W: |5 U4 L' G- z
  c( o  u4 s3 @' i; R    mov     ah,43h
) ^1 m6 y" l2 l& s! w. p/ W9 h    int     68h
  n, M& U$ \2 g; c. N    cmp     ax,0F386h/ }1 k; t. d5 u1 x3 C
    jz      SoftICE_Detected  s8 {3 v0 I) s+ I( q

5 q. x$ B9 Z2 I" y9 y7 f
: f2 _1 N$ w. e! P5 ^=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit$ Z4 w' \- J9 L- w4 a  E% v
   app like this:
5 W! k& P/ o( E& |) T6 n3 K* Q! c7 S$ }6 B" r/ `  `4 P& n7 J- `& K+ z
   BPX exec_int if ax==68* X7 D# n* Q# p( W1 A3 x6 F
   (function called is located at byte ptr [ebp+1Dh] and client eip is
4 v: S/ V& w) h1 t$ ?9 B: r   located at [ebp+48h] for 32Bit apps)" V7 H/ T' A7 t' U- x6 G3 i; Y( h3 U
__________________________________________________________________________6 c) _" u! ], s1 E; P" V& }5 G3 ]
" r# t' d3 w: {2 q+ E0 O* H3 ]- r: p# R
; m3 Q0 D  }$ A9 C
Method 086 ^) C# w' V" o: T: A- K* D
=========
1 x5 S/ L* {4 |( ^3 ^" B3 A/ z* ^& F3 V
It is not a method of detection of SoftICE but a possibility to crash the& m8 L& d2 ^( F+ y8 `
system by intercepting int 01h and int 03h and redirecting them to another
+ X6 j7 S" \# d: jroutine.+ w, k* w# M  i9 s* A, `0 c
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points7 @( \8 b7 A! q+ ]' \& [# d% }7 P
to the new routine to execute (hangs computer...)& k  `+ G# Q' V9 C, j
# {% V" k( t3 p9 ~' |4 m, g
    mov     ah, 25h
0 j8 `' o# Y" i' M* C' n' j# ^    mov     al, Int_Number (01h or 03h)
, P+ O1 n5 n$ A. i% Z    mov     dx, offset New_Int_Routine) l0 s/ y5 O$ W  @/ n# ^8 E5 H
    int     21h
# C; B) X, W/ Q- b4 n9 k9 @2 w$ K/ m+ p* U! g2 g6 @' I. v6 \
__________________________________________________________________________
$ w( v, b0 q8 O. v  }% E4 s3 ]6 ^" ~9 \+ V
Method 09
( ~8 H+ O$ W  f, f6 M! N& t$ F=========
/ y. }( x: M9 E9 h9 r! x: {" @' L- }' d: D$ F4 h  c
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only7 y2 u8 E4 n( v- C( j; Q' A6 x
performed in ring0 (VxD or a ring3 app using the VxdCall).
% j4 @# I& [0 ?7 o3 tThe Get_DDB service is used to determine whether or not a VxD is installed
" ^; ~  V( J8 I! wfor the specified device and returns a Device Description Block (in ecx) for
! R: j2 f9 }! @! d2 A9 c9 Fthat device if it is installed.) o3 [- U0 `( V" L5 T5 m. ]

9 g% a7 c$ ?( p, a, ?. c8 f; ?   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
7 Y% {& z3 Q+ r# _" Q7 v   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)7 X- P4 l- T) M# m& B$ Y
   VMMCall Get_DDB2 }3 b8 ^" u0 A: {$ [
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
; S- j2 }) |7 ^( Z
& Z1 U6 Q" J  M- E7 TNote as well that you can easily detect this method with SoftICE:3 W3 C7 `! D0 c; D& ]) o7 l
   bpx Get_DDB if ax==0202 || ax==7a5fh
" X5 w) n  y4 d; l0 u% Y: ]" z0 J2 S1 F3 ^; U1 b
__________________________________________________________________________  [4 i. \0 N4 a5 t; i: N( |
' }! J0 V9 }% P
Method 10/ F# w6 g' D& H6 u; x) ^
=========
% W4 v4 f0 \( f5 m: M% G! F6 g. P" y) E# G( H
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
# W5 K/ B% t  C" I  SoftICE while the option is enable!!6 Q1 l: t4 |; s' X5 Z/ G/ Q

% h6 z  ~  F) i4 f. L- W- G5 M1 HThis trick is very efficient:; r* z  L1 l- ^3 s
by checking the Debug Registers, you can detect if SoftICE is loaded2 g' v# }+ J  R/ F- {
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if4 O4 g' J2 ]4 d8 n7 c
there are some memory breakpoints set (dr0 to dr3) simply by reading their. i# \* r: u5 H$ [
value (in ring0 only). Values can be manipulated and or changed as well) @4 W3 o( A7 O7 O; B  }2 f8 d2 u
(clearing BPMs for instance)
0 R8 Z3 \& W$ f+ f/ ~5 d5 b* V- V" D
__________________________________________________________________________
3 o& p2 Y& h4 `- W4 L9 V  R8 B0 i; s6 Y: P2 a* U$ u2 c. k
Method 11
# B& l2 \$ Q3 ?0 L' q, w=========# c* ~' o) Z! b! B* Q  w9 ~
9 D2 \; [& e7 z; J! h
This method is most known as 'MeltICE' because it has been freely distributed
. X" t* `9 [5 Yvia www.winfiles.com. However it was first used by NuMega people to allow
( O$ U2 ~" e+ a: ?& ^Symbol Loader to check if SoftICE was active or not (the code is located: \+ ^1 w& W+ J( h5 s4 k/ f
inside nmtrans.dll).
3 j) F( e) i0 t' ?5 _; M& Z6 m- w) Y6 f# L& X' M$ m' B, l
The way it works is very simple:6 r0 x; ?4 m. O/ p3 x& E& [2 k
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for2 T' F4 e; S, q3 d
WinNT) with the CreateFileA API.. P+ P- y' E9 N! ~
! C% R! y; Q4 q' P/ k5 V( w, q
Here is a sample (checking for 'SICE'):+ V8 y) y, F- z1 W
& F, R9 {8 ^" \( u" ~  T
BOOL IsSoftIce95Loaded()6 \  v0 @* ^% v3 f; w1 b' v
{
2 `. x, r0 C" X9 K) t; s& A4 F   HANDLE hFile;  ) o, h" [! b9 T1 w5 B$ e7 M: a, e& d0 Y
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,# [$ l6 a, N5 u* x  n
                      FILE_SHARE_READ | FILE_SHARE_WRITE,
, [* {$ j) }% _                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
  y, [3 _- |+ ~7 L7 _; U0 y1 V/ h   if( hFile != INVALID_HANDLE_VALUE )
' z2 V0 t, M/ X3 ?6 ]& C2 ^( i   {
* s: f, ^# Z0 X- [      CloseHandle(hFile);
* N! G+ w- X3 t' s+ C4 o9 V& h! @6 i6 H      return TRUE;
9 b' N3 U% h# b6 V* I4 g" W' b   }! M* F# i9 I/ b* Q1 X
   return FALSE;  N- `& L4 l' X2 M/ ?+ f
}
9 F3 T# ^% v( r# }3 }7 R- Z6 V5 S
% I( p  m: e* {, qAlthough this trick calls the CreateFileA function, don't even expect to be* L& _5 g9 \: ~9 Q; X  p6 u
able to intercept it by installing a IFS hook: it will not work, no way!9 K7 \. c" a7 C( [: b* V7 d# M
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
  W( d4 r+ ^/ ^; H" ~, Vservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
3 A% i; C, U2 K& [( m: band then browse the DDB list until it find the VxD and its DDB_Control_Proc
7 J+ \8 m, K# s) tfield.
' y% }# q3 |2 u" z; n& dIn fact, its purpose is not to load/unload VxDs but only to send a
0 g+ z& Z1 [& Q9 ?$ u9 N+ gW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)# K1 k  \; t9 B$ f3 _
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
- B" b" A1 z% R# `% \  c( F" hto load/unload a non-dynamically loadable driver such as SoftICE ;-).
, K4 c0 F7 m& D! T, JIf the VxD is loaded, it will always clear eax and the Carry flag to allow% A5 F" j: U! M
its handle to be opened and then, will be detected.
& O2 \. Z( ?* e: r' C5 GYou can check that simply by hooking Winice.exe control proc entry point7 n- _! F, s! h, y2 m3 o0 C8 Y
while running MeltICE.
+ L( W. d1 V! t
7 _1 A' r$ n; ?4 h0 V0 O) |" w& S
7 ^, W1 ~5 @# h5 h  00401067:  push      00402025    ; \\.\SICE/ ]- L# f, g! {: i: O+ y9 O9 l( [) s
  0040106C:  call      CreateFileA6 N/ c( _1 v4 X$ q  n( H
  00401071:  cmp       eax,-001
& \+ g  }1 F. @! a  00401074:  je        004010919 |" H0 r. `5 s, B; B8 V1 `8 H
: [) e0 ^% l: g6 Q$ n: R

0 v' a+ @; ~; t. f; _There could be hundreds of BPX you could use to detect this trick.$ h- @+ i: ]6 ^6 e
-The most classical one is:
+ {" C" m- e8 u( c9 h- |, w( g3 T  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||; [- N* f, H  r5 j7 n% i
    *(esp-&gt;4+4)=='NTIC'0 x- R7 k& h+ F; L, P  K6 d/ s
. ~% ?# W2 P1 d/ J% X1 `# y
-The most exotic ones (could be very slooooow :-(
2 ]8 s1 A$ l& }5 o1 w  ?   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  : ]& {0 G' j: ~/ f) S
     ;will break 3 times :-(
  f1 P( H& T% f0 [+ V) e4 y
) c2 T1 l# U( Z  z* K- e-or (a bit) faster: 5 n/ }1 k5 B+ _/ B+ Y; z0 h8 L
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
3 f) P3 l/ a" `. V9 a) w: F
/ O# Q  w9 X7 ]; l3 I+ [; }, e   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  + K% p( t; O6 b( Z" U: b- C4 G
     ;will break 3 times :-(  _1 j+ T+ a" [% P( X, G
- R6 L5 z% A7 R4 w% o0 t
-Much faster:
- b  x( q% [' O$ I: q! O   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
- s3 x5 |' R' {, o
( N3 E6 g8 ~! ?* U% E. o, p4 y  w. O; `Note also that some programs (like AZPR3.00) use de old 16-bit _lopen8 P) f5 i' a& M- U; W$ o
function to do the same job:
9 c7 B/ t# C' e9 ^' m4 }" j+ H% r  ^" w8 ^6 @; ^9 Q6 H3 e- l" N3 F
   push    00                        ; OF_READ
, C. i) p& Y. b& f% t( k   mov     eax,[00656634]            ; '\\.\SICE',0
7 [% r0 V& u; q. R( r; T! v   push    eax; A5 _/ Z" q/ }) R# h7 v5 G
   call    KERNEL32!_lopen
# w% j& C' ^! W   inc     eax& ^- [! e. z$ z% V
   jnz     00650589                  ; detected
% Z1 ^& _# S3 r$ @) h   push    00                        ; OF_READ
4 @7 B/ F5 Z) _. S6 [4 r) G   mov     eax,[00656638]            ; '\\.\SICE'8 |* G/ g, }7 u  e' I& R0 Q
   push    eax( r- y* a& `) c5 M- `
   call    KERNEL32!_lopen* ^! j+ c. j. \$ ]! F
   inc     eax
; Y, o5 _; q# G% `   jz      006505ae                  ; not detected8 j) w2 J( a1 Q; [
! l4 f, w- W& h

# {4 U5 ?, k9 f5 N9 q# u. S__________________________________________________________________________
7 ~' X4 W, M; O6 x! i& ]' K; \* N3 k9 x0 Q
Method 121 Z. Q) S) j1 v) R1 n0 u
=========
. d; M  X! i6 r3 |: k
  W0 V# H: T; e) _& Y7 pThis trick is similar to int41h/4fh Debugger installation check (code 05
  n9 B; I! E9 B' n, s" K5 X&amp; 06) but very limited because it's only available for Win95/98 (not NT)$ N: ]+ |1 Y0 |
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.& i8 _$ v6 b4 \) `6 y
! F$ J" \6 ~, A& k7 q( ^+ K3 ^' ~$ O
   push  0000004fh         ; function 4fh
! O1 F* _; x5 i, S5 U& g* h3 V   push  002a002ah         ; high word specifies which VxD (VWIN32)4 T1 z( p" I* x0 d* @
                           ; low word specifies which service3 J7 s- l6 U2 O: j% [+ F1 g! ?0 x
                             (VWIN32_Int41Dispatch)0 Q( N2 c/ C( C* _) Y
   call  Kernel32!ORD_001  ; VxdCall# s1 T( t, g$ q, t- [7 C0 H
   cmp   ax, 0f386h        ; magic number returned by system debuggers
) r5 \' ?, X. P% Z   jz    SoftICE_detected
; P7 j% H% d$ ]+ h9 G7 \; K- Q8 U% R6 O+ o5 z2 ~" b6 A8 e
Here again, several ways to detect it:: y5 n$ k' m* r

+ H# {  J$ \( u7 s! D    BPINT 41 if ax==4f
( L2 E; W- U  L/ p- o
8 |" E; B! C* _3 {) ~$ k5 i  W    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one: O* ?; [( {! `+ O% Y+ ^
& R2 n5 W( H4 P
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
" U: S2 W" {9 S# J
4 c* t- V: s' \    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
6 Y& _+ J2 W9 N- m. F, f. j; Y2 Q, S1 S: @0 S! @% ^0 m9 s2 t# g' F
__________________________________________________________________________
9 v/ _1 L' H3 V- P
; |% ?$ A" K( H% q+ oMethod 130 r7 e1 b" a+ |- K8 c9 Q8 B; s
=========9 x1 l& \0 v6 B' N# d
) ?% I# z+ w) ]( q
Not a real method of detection, but a good way to know if SoftICE is
4 Y; v" e, f% L! Q; u% _2 Ainstalled on a computer and to locate its installation directory.
8 P/ z6 Y8 t: BIt is used by few softs which access the following registry keys (usually #2) :3 a4 Z# v- ~5 y. z# `7 r, _( J  @

5 e( m  O, ]; n) |( {: c( c4 Q, ]-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
# d' ?1 r" e# Q; h. U/ _\Uninstall\SoftICE
' D" d; ]. F* G% p0 |5 I-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
& N. T2 W2 W8 d  q4 M- y: z-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion( P8 ?: ^( d. ]5 Y! z; B
\App Paths\Loader32.Exe
! n% V7 W5 o4 N; d6 }0 E$ x, Q3 u) r: t  c, Z

/ j2 V2 u  p. u3 ~$ q; YNote that some nasty apps could then erase all files from SoftICE directory
* `' f) D6 r- z+ |+ N, O" q(I faced that once :-(
9 K4 X4 l% A: `* [- ]0 d( a" R; m8 o4 k6 E# o+ O, \' [: z1 p3 d* u
Useful breakpoint to detect it:
5 C2 T1 U9 P1 `0 z/ S8 K0 x4 m+ j8 f/ s% E! G
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'* v" n) g# V4 P- g+ m

% L, B7 E: j8 U' \__________________________________________________________________________7 P/ ?# V7 J/ D* X

, i* Y: L7 ]* c0 K; o8 ?3 @7 ~' j4 N3 Z* Z' h) F# v. z( Z7 t1 Y
Method 14 7 p3 C/ `+ @/ i" N. W0 l
=========' }9 U8 j6 \) \$ k

- ~  A' Z+ x; P0 X2 TA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
# A! ]2 j  h: e4 Y4 h% Qis to determines whether a debugger is running on your system (ring0 only).
/ |* j) \8 ~% w% t  B) l" c  k" |$ {7 I* N2 z+ [! s% |/ ^* s
   VMMCall Test_Debug_Installed  d$ m1 [% w8 J; y- H" G
   je      not_installed
) V7 Q' n; S) X9 Q
* B; r& U8 V" d1 k6 l2 `This service just checks a flag.! ^; P; Q$ `1 W) |* s3 e/ v  n
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部