About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>. W; f5 R* c& }3 F9 ~" Z
<TBODY>
" Z, @) _7 h# e5 {. k<TR>, @9 h* Q$ y, A$ K, W$ ]
<TD><PRE>Method 01 5 V& Z+ q- Q% t
=========
# i* S* f+ u2 x" R; h; E0 c! l6 d4 m( y0 J  w
This method of detection of SoftICE (as well as the following one) is# u! m- G! A5 e/ S5 M( G
used by the majority of packers/encryptors found on Internet.6 H* w" u9 `; [9 G' D
It seeks the signature of BoundsChecker in SoftICE
4 ^, G" [) F+ b5 Q, ~
; |& T' X/ F9 x0 K/ \# ]/ n    mov     ebp, 04243484Bh        ; 'BCHK'
! h  S& K& _% A: l4 S  c- j    mov     ax, 04h
8 D, n8 d0 X/ \$ D' N    int     3       8 W$ }" ?) u' m; N' P
    cmp     al,4; I; M1 D/ I9 Z$ _+ F# h
    jnz     SoftICE_Detected
! I2 g- m8 d9 V& w+ g8 k8 k5 {) Y- _. n& y* V
___________________________________________________________________________% _7 h9 E5 a8 N2 ?
* n. N! C+ x. b2 X
Method 02
+ @% t; G1 K. Y; O" Z3 O$ v=========
, a  ?2 H& A' ?4 {
. e$ ?- F& v4 PStill a method very much used (perhaps the most frequent one).  It is used) |7 `6 e, L5 e. Q9 S
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
$ t+ U) g$ g2 v, p2 q' qor execute SoftICE commands...
8 t  K4 I1 |+ }It is also used to crash SoftICE and to force it to execute any commands
$ A* F9 E, ^: W* V* j+ F$ l; z; S(HBOOT...) :-((  
) y/ H' z0 G+ ?  q" |. G2 W( h3 {' \- [  T# U: {! a  ~" C. W
Here is a quick description:
8 r+ E6 z; [9 m" O8 P-AX = 0910h   (Display string in SIce windows)
$ Y9 A& N+ h7 B6 e* [0 _7 f-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
! C) ]4 R) j0 D9 ?, s5 y  ^0 x" U# \; J-AX = 0912h   (Get breakpoint infos)
9 C9 E$ e/ K1 Z5 F-AX = 0913h   (Set Sice breakpoints)8 B2 s" v- o/ y# U, ]* l0 S  S8 F) T
-AX = 0914h   (Remove SIce breakoints)
& \! [/ `  Y$ h3 Z' o( p" l5 H: Z# G: x+ p
Each time you'll meet this trick, you'll see:
. W* K) F1 e8 G: Q-SI = 4647h
+ X. N( m. E1 f9 R3 h- t! ~-DI = 4A4Dh
* {' G6 D3 _1 C4 LWhich are the 'magic values' used by SoftIce.
  q" [* Q% x6 N! x+ yFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
+ ~5 G# e5 k: Z2 A
" V% W7 Z+ o. QHere is one example from the file "Haspinst.exe" which is the dongle HASP5 j* `# d! X" b; v2 Z( y
Envelope utility use to protect DOS applications:* f6 f" T! u: `: L

7 x+ L# w0 A) D3 Z1 P% z  B+ Y9 H! x/ a& A
4C19:0095   MOV    AX,0911  ; execute command.
/ O9 {2 m% r) H2 Y, }) Z+ [4 v4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).' p+ W1 ~1 ]5 y6 n8 A  y; P
4C19:009A   MOV    SI,4647  ; 1st magic value.1 x* \3 |* D6 D9 `. A% }5 x4 c
4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
7 X/ u8 p$ _( t) K/ W. o0 Y4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
6 L; Z: b) c! O- R8 S4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute/ Y" L' l& C) l% p3 _5 {
4C19:00A4   INC    CX8 }4 ]$ X( b, h) i6 ~/ b! [* ~
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute+ a( X8 {" m( I2 [5 h* [
4C19:00A8   JB     0095     ; 6 different commands.
. M! e; U, {: i) n4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
# E$ j- W3 C4 g4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
# d# j. Y8 t: y9 @: J5 A. |" E7 K5 ~9 v+ h: r0 T
The program will execute 6 different SIce commands located at ds:dx, which
. X( C5 g# I; z9 m) ^% Jare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
8 }) U& ]) g% K! b4 k% D0 o& v
1 L, c" E' K; r5 e( a* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
) O3 O2 w% i6 g& E0 L4 W2 R___________________________________________________________________________8 V6 }0 y5 t5 Z6 L2 F

# y8 s, g1 U9 ~3 {0 A2 }
" \# n9 N8 R  v  S3 _Method 03
6 W; R' A3 w2 l2 d) h- a=========
' F) q, g4 B3 U" }5 M3 ]- R- o6 E5 A. l2 [! S
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h& z$ L1 [; G; Z. n/ m" q; q
(API Get entry point)1 K" k0 [) \3 @8 X
        
, h9 {) n5 T9 K0 m, n: m) n* V& i. H( H, ?! f' w  L3 v
    xor     di,di$ m6 Q( ?) \3 U5 D- d
    mov     es,di
* X( }- l" ]1 _. a" O: S    mov     ax, 1684h      
0 ~$ _; I, Z; @0 [) a9 `9 s    mov     bx, 0202h       ; VxD ID of winice  u- o  M( N, j3 L
    int     2Fh
/ p" a- v* ^/ c9 K' W    mov     ax, es          ; ES:DI -&gt; VxD API entry point
7 o1 k& j( C: C9 h3 m2 O& K    add     ax, di! s6 G8 R, [; D+ V
    test    ax,ax
$ _8 q3 z" K! T" @# Z    jnz     SoftICE_Detected
* t. ^% Q$ t9 G9 q. w6 w
( A# w* y0 N- c* f8 A: L3 w/ [___________________________________________________________________________2 w6 a* i' ~) d  D+ ]2 I

6 \  X& R# V$ A4 T6 A3 kMethod 044 }% j! ]  {  D9 [, Q. r
=========. l% ?  H; l7 @9 R& ^* C
1 r0 {/ ?. z) l6 P7 q" v! y
Method identical to the preceding one except that it seeks the ID of SoftICE
$ C$ d5 h/ T4 C2 M# [, B- X, I2 SGFX VxD.2 X9 p0 M6 J# c7 c. ^# k' ^

$ a( K' Y6 c! q3 K3 o) V5 U! O9 P    xor     di,di" \5 d, y1 |( P7 E- E5 a7 X
    mov     es,di: u& _1 F/ |7 l" U7 h
    mov     ax, 1684h       3 Y: I  z9 h' O, A- d
    mov     bx, 7a5Fh       ; VxD ID of SIWVID2 A4 Y4 e# d* Z2 M
    int     2fh
& C& Q- Z5 Q- N1 ?- _    mov     ax, es          ; ES:DI -&gt; VxD API entry point
7 y) ?( S; m# a    add     ax, di4 k; e9 w" h' f3 `9 o7 e8 F# U
    test    ax,ax9 z, \. |$ N5 I  a
    jnz     SoftICE_Detected
# x& E2 k: z2 l3 ^" ^/ b3 I) `  O$ Z1 u5 O  x- L6 P
__________________________________________________________________________
* b( R  b& n* I; ^$ g
8 b7 _7 E# q% W4 o4 \8 P0 b% O$ W2 `2 i1 ?
Method 05; i: Y& p  u# k4 |; k) D, K* f
=========1 i3 ?: H$ _7 \5 k  ?

1 X% @0 g' Z3 t- u- cMethod seeking the 'magic number' 0F386h returned (in ax) by all system
3 i9 a- L; Q8 ]2 Y1 Adebugger. It calls the int 41h, function 4Fh.
* d& G- g$ e8 o8 N0 DThere are several alternatives.  5 _, D3 w$ K2 x, G$ K4 {8 Q
5 h- t4 a- P/ C3 v7 R
The following one is the simplest:
* {! B& I+ l/ s' J- N
! Q5 M% ?* T5 ?, E6 g1 y    mov     ax,4fh
7 o: l; n* s" }: H    int     41h
5 [1 I8 R+ J9 d$ Z6 R' g+ e( L& y    cmp     ax, 0F3866 e% Y: L3 O0 {, m
    jz      SoftICE_detected
6 F+ o0 s$ @( f9 A
( _4 U1 A( j1 s* x! O6 ^- N) j: R4 y2 U: q
Next method as well as the following one are 2 examples from Stone's * {- h9 \+ L- P3 m8 d
"stn-wid.zip" (www.cracking.net):# E& n( H) c. I& v4 r

$ i% _3 z$ i" b  O# ~2 ?    mov     bx, cs
6 ^( T& Y. i  g: L6 a9 A4 [    lea     dx, int41handler2
- _+ e# y( a/ R7 z0 [    xchg    dx, es:[41h*4]6 P# h' ^0 b% E! }( c* Q9 B
    xchg    bx, es:[41h*4+2]9 ^8 [8 A$ R' ]0 h: I
    mov     ax,4fh
6 D" {5 Y5 b' U, K    int     41h/ j* M3 a* a5 d/ _* p) |! f5 U- q) f
    xchg    dx, es:[41h*4]
2 I+ o% Z- w9 A0 s    xchg    bx, es:[41h*4+2]
! w/ U+ f3 M2 c    cmp     ax, 0f386h- O9 C# s+ u" y9 F3 J" u
    jz      SoftICE_detected
, _; V1 w+ N/ T4 N8 q" u9 d2 s/ y/ ~; ~; T2 }
int41handler2 PROC
/ [; Y: ]1 K2 L) x- K+ D    iret
* k# X$ q8 {# E( b. Qint41handler2 ENDP
( a- W' k0 g; @( I( l; D, l6 a# Y: m4 `& d( j& w  j
6 n3 b( |2 t. t8 ?3 f
_________________________________________________________________________( O; r: H1 ~- t6 W; a

( q  V6 b  N0 M7 V; u
; ]1 w; M  g! R+ RMethod 06& `4 w3 a4 `$ a9 G6 ?& G( M
=========5 @# I! D  S2 d
8 V* R% y) k8 K" g

% `2 m* ~" L; o9 I: z2nd method similar to the preceding one but more difficult to detect:' t* i* q/ W) B; ]8 y

$ [9 ^9 K4 _3 u% Y+ ^! O
/ J; Q) }# ~! Z" Hint41handler PROC
8 j) \) J- z+ C! U$ w) u: `0 ]* u    mov     cl,al# b) [' e) ^: \
    iret
( @7 y: W9 f5 ^6 C. M  D5 bint41handler ENDP" M# O  B- W3 l6 c* [
; l! A/ }2 O9 \, S/ T! w

* R4 r7 `. z2 N    xor     ax,ax
! \* e: ]" [8 {/ N" o9 }    mov     es,ax
' N9 D; b* R" V4 C2 Q; u    mov     bx, cs
* a1 [9 z+ v$ F/ S: x    lea     dx, int41handler
; t& K  P( T) e5 F    xchg    dx, es:[41h*4]; K5 m% X, k! {2 }) s; Y' Y
    xchg    bx, es:[41h*4+2]6 I% g# J1 d0 f4 u( q
    in      al, 40h
/ C! r5 D0 F# h6 C7 I- {    xor     cx,cx
! |7 @' y+ d/ P. a, A$ {    int     41h
" {5 @/ @7 b* u5 s' O    xchg    dx, es:[41h*4]
& g/ w/ L" e2 C' X5 s    xchg    bx, es:[41h*4+2]
, C6 z( x9 |2 H8 r4 S' C1 R) d$ H    cmp     cl,al
9 S/ I3 x' G- Q* `& A" F    jnz     SoftICE_detected& I, n- G4 v5 C. q5 l- x
0 f2 v! R& Y4 n/ y9 }! [
_________________________________________________________________________
# @2 R3 X0 a7 N; O) V: p
; T# [4 Z. E2 K! D3 PMethod 07, r$ O& q- [: l( o7 ]
=========
* R4 ?' R+ C) r  _6 d( J
; N, |9 c* X; a0 d! p% yMethod of detection of the WinICE handler in the int68h (V86)3 G) L3 h' f0 i

, F8 J/ \+ y/ C+ ~: J; y    mov     ah,43h8 s: d9 U5 c/ C3 F" q# B
    int     68h
3 L: x' P3 N# X0 h8 n: r    cmp     ax,0F386h
3 A3 R; }: _4 H$ F; u2 `    jz      SoftICE_Detected
- K2 g3 ~1 n$ z+ T& o
! w' a2 Q$ d: G2 P5 C0 B" ~! H3 c: l0 C$ f  P
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
/ [- U! z& n3 x: Z& Z% y2 V   app like this:
+ Z3 n" ~/ B! J2 ]2 S" `( f7 p; v7 J7 U+ N5 Y% v
   BPX exec_int if ax==68
+ D" k! M# g+ J/ O/ d3 A   (function called is located at byte ptr [ebp+1Dh] and client eip is& R/ b5 p  }4 n" H. S% c, s
   located at [ebp+48h] for 32Bit apps)& O( N; s4 v- l: l8 N
__________________________________________________________________________8 m3 m* y* x( v) ]1 B7 x

+ g2 l. Y. m$ S! }! M0 q
! P, m: |1 H: d* KMethod 08$ U/ A) ^9 U3 ?6 ?& N
=========
+ D6 h. M& b; B! B/ T3 J
4 k2 w  }* `3 Y. gIt is not a method of detection of SoftICE but a possibility to crash the0 Y9 {, P- |8 ^& N
system by intercepting int 01h and int 03h and redirecting them to another; g9 u4 i1 I0 j. \( G: l# V
routine.* F8 E1 k/ ~% J* U! K  Z
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
: R0 u& X% Y, gto the new routine to execute (hangs computer...)9 O4 U0 R. V5 v7 c2 p
( S3 P6 O8 W$ }: H
    mov     ah, 25h
! ^" O8 g5 T6 L, c7 p9 y( i    mov     al, Int_Number (01h or 03h)
2 V% D7 w2 J3 u  b% V    mov     dx, offset New_Int_Routine, Y1 d, r' m4 X' l8 ]4 }/ Y
    int     21h: N; G6 ~" S, R( i) ]( t5 O/ c1 y

- q/ f$ c; |9 o& i  U__________________________________________________________________________7 C  o: Q! s' l6 \) u& J
9 v' M" J8 B( t5 `. d
Method 09, p; K" ]3 E( Y
=========7 @2 a- t4 b3 n( ^
  S$ v( L% M* l4 W, Y# F) }
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only( z2 O; {0 q4 ^" ?. _
performed in ring0 (VxD or a ring3 app using the VxdCall).( a5 q/ i. I7 N' l! Y# T& r. z6 h
The Get_DDB service is used to determine whether or not a VxD is installed* M3 O) V6 J& d( Y3 D4 B
for the specified device and returns a Device Description Block (in ecx) for: R. ]1 {& O6 A& F* g4 i  e; }
that device if it is installed.
2 b6 P; V& R; b8 i0 ]" R4 r
4 p- n9 q& m' W) t. G8 O, L# _9 F! o   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
3 l9 T5 B( x% h& F- ]4 |/ d   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)2 e" J$ v( C% Y* h
   VMMCall Get_DDB9 N& ^9 ~5 j" `$ V7 ^8 G
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed! z* |8 ^& `7 t' B& a: x, H, ^6 K

( _6 s' c4 G' J, jNote as well that you can easily detect this method with SoftICE:
% l, y$ K9 I% l+ _7 D2 U0 ]   bpx Get_DDB if ax==0202 || ax==7a5fh' V4 q5 z8 ?2 ~0 Q3 r* p
3 J: r* a. H  i4 _; D' u8 m2 G
__________________________________________________________________________
/ H) u- P+ ^8 c/ H
0 s3 A; x0 I+ A1 B2 VMethod 10) s2 M3 B" c+ T- V9 f: F! y2 o& S
=========4 B0 v& ^* q& s- F! l

! U' D4 s2 w. N% j% I, G8 W=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
- Q1 z4 ~' |+ k* c* m& b  SoftICE while the option is enable!!& V# q5 J6 [" N8 O1 b+ @7 ^9 z& p

: C- M$ O* i) fThis trick is very efficient:
6 q( e! K6 U+ i1 Qby checking the Debug Registers, you can detect if SoftICE is loaded
% Q, x$ q5 Z% f% V* t(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
2 u9 t7 _. E: K- M  x( q, L7 B* Sthere are some memory breakpoints set (dr0 to dr3) simply by reading their8 \( e3 Z3 R8 }* @( n
value (in ring0 only). Values can be manipulated and or changed as well8 G+ t6 w+ ]. g- G9 i5 T6 b) F
(clearing BPMs for instance)
) V; \0 [% P* R2 u# {  d
3 [% D! n, H0 E( p5 H__________________________________________________________________________4 Z& E5 l' Q  R$ {! u* B) u
$ g  v2 A9 y) i. z
Method 113 V' Z7 @( N( @( w7 f( G5 f
=========
3 L' C7 X8 L9 o$ o9 m$ F2 c7 g0 [& n  T1 `6 t
This method is most known as 'MeltICE' because it has been freely distributed
! E- ~  J' O) ~via www.winfiles.com. However it was first used by NuMega people to allow- D1 e5 [9 @5 Y1 }( I3 ^2 D# @1 j
Symbol Loader to check if SoftICE was active or not (the code is located9 K% t, m; y3 x- e) F7 d. [" J8 E
inside nmtrans.dll).
" z  O: T2 c3 I' }: p6 W
' A+ k6 b6 i) V+ eThe way it works is very simple:
  {( d- ]% f: Q9 S, |7 nIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for$ J! x6 A& o0 [, e8 \
WinNT) with the CreateFileA API.% V' {6 z  r4 b# b( x* L% w

# X. z# m5 `3 h" m# P  |" EHere is a sample (checking for 'SICE'):
) T. \# Y& Y( R+ f3 c) ^5 U; w4 }( x; X
BOOL IsSoftIce95Loaded()
% ]6 v# g' h* m7 {9 u% }6 _) Q{  a$ u% ]4 G# E6 E; L$ b
   HANDLE hFile;  + n- _" C8 ~3 \
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
/ X$ z9 t  l: d3 a4 m                      FILE_SHARE_READ | FILE_SHARE_WRITE,
. ^3 W2 j2 d, u9 w- z                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
4 m5 S; r3 J( \) Z" E! H  t   if( hFile != INVALID_HANDLE_VALUE )
( X6 e$ z9 \0 H& `! g   {
8 s5 B: H) q0 R$ k3 i7 R* b- h' t      CloseHandle(hFile);( B* C, O+ N) r
      return TRUE;
+ e4 s; C8 X4 c' A3 p1 g3 B( n2 ?   }
$ X4 ~1 e" H6 S9 g+ g5 b   return FALSE;9 U. C7 J4 ~" l# Q: `& `/ _/ Z
}
( F1 {' t- g2 @) O: h% _, w5 w* d# P  Y, x# ?; D: `9 E2 X- K% p: I! K3 ]
Although this trick calls the CreateFileA function, don't even expect to be
) f- _/ S; S! ~, Lable to intercept it by installing a IFS hook: it will not work, no way!
; X9 g0 p# ?( y9 m5 p4 u6 eIn fact, after the call to CreateFileA it will get through VWIN32 0x001F
5 v8 A! R0 A- Rservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
2 Z) A4 X" z/ U. h' }" @* a5 Mand then browse the DDB list until it find the VxD and its DDB_Control_Proc
4 P; q; [  u- K4 Z# v) X  x1 Q  u# sfield.
2 y/ i0 N( N. U0 y$ T! ~" f+ P- gIn fact, its purpose is not to load/unload VxDs but only to send a
3 Y( a; m9 O. E6 B& X. \' wW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)4 [$ M. A% v# p0 F* j7 J0 x
to the VxD Control_Dispatch proc (how the hell a shareware soft could try8 i% H- `' d* L8 |1 X* q" {
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
" `9 T& b. w0 Y7 f$ C6 [+ |8 C; PIf the VxD is loaded, it will always clear eax and the Carry flag to allow
9 e- b  {1 |3 j* k, _5 uits handle to be opened and then, will be detected.
+ {# W  B( E% |8 ]# AYou can check that simply by hooking Winice.exe control proc entry point
: N% ~, z! B- |0 z. q& s. @: Twhile running MeltICE.
0 `7 i, g0 w, d, j  c! L6 @
0 ]2 K9 R& {& l* Z1 m) J2 R0 [- m
0 x5 P, p1 q% s* [  00401067:  push      00402025    ; \\.\SICE
1 K, ]& S% D2 @( m: \  0040106C:  call      CreateFileA
# K4 y* G' N$ S3 j- O) |# N  00401071:  cmp       eax,-001, \% b+ y1 a2 D6 P; \
  00401074:  je        00401091
" }( Y& Q/ Q& G7 R2 s! W
, V4 X; [$ x; |) \% l$ ~2 C  @
. }9 k" u$ v2 ^6 AThere could be hundreds of BPX you could use to detect this trick.
$ W. X% B  d9 L/ P, _-The most classical one is:
8 F0 u% ~& k: N, l3 [7 O* R  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||6 r* w4 r2 a7 b+ m: T
    *(esp-&gt;4+4)=='NTIC'+ l8 B; ?. y" k. _4 b

# _: g' G4 Z2 h/ T: M" A9 J/ c-The most exotic ones (could be very slooooow :-(
6 d3 c$ D' j. D" m+ I1 R   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
8 S) E) X; L1 ~# m! @* |     ;will break 3 times :-(+ [) h: c4 a% N# E

! {/ I8 y! X. z8 L2 V9 `6 b-or (a bit) faster: 4 W4 G9 y5 J0 K% R" j
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
6 ~! O( {0 C/ {# Y
. q3 u& e5 q) N   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
: ~# v$ d( H2 X: @* c1 s- V     ;will break 3 times :-(, Q5 y  E4 I: V

: u) O/ o. I" \. o/ w1 Z-Much faster:) V% e3 C# N2 q1 b2 U) z. L9 v
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'1 k) R3 A- e1 @# Q6 u( J
8 t) q- P' ?6 u3 Q" _/ @3 V
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen# H1 A3 H, N+ n3 d4 t( [$ ^
function to do the same job:
( z0 B# b0 p0 e" O! ^# r. d& X0 ?
   push    00                        ; OF_READ/ L5 L6 ~; N' N
   mov     eax,[00656634]            ; '\\.\SICE',0
2 |8 P) D0 K: O  c   push    eax: ?, ^; J$ l5 t
   call    KERNEL32!_lopen
3 c) x* c) F! C8 S   inc     eax' V% f8 T7 h( M3 e
   jnz     00650589                  ; detected3 ?$ L( S! t. t" i! K" v; ~5 s4 j
   push    00                        ; OF_READ
% }* t! M' t& ?& u8 ]# }+ z& A   mov     eax,[00656638]            ; '\\.\SICE'( X. X2 L, A: e% f. Y
   push    eax
. H8 a# H" X. l4 a) {# q/ u, `2 S( {   call    KERNEL32!_lopen
; g/ n  s2 L* L  Y: v   inc     eax
  B6 x" f% M7 w/ w   jz      006505ae                  ; not detected1 h% s6 n3 T5 x4 u1 q' V! n4 e

2 F9 U; S5 `+ {! N. f) f, s4 z( U3 B
__________________________________________________________________________
% E" e3 q6 L3 m" z
  D: k9 g7 \) N3 O# h# gMethod 12
; \, E3 l4 S( @* V0 A=========+ N: t) G; T' P
* e3 b4 w2 X' N$ ^9 E
This trick is similar to int41h/4fh Debugger installation check (code 05/ |8 ]* h7 j3 L. o) C" R
&amp; 06) but very limited because it's only available for Win95/98 (not NT)
5 \) h* e3 G4 K+ fas it uses the VxDCall backdoor. This detection was found in Bleem Demo.
3 D; W! O9 `7 X/ @+ ?
* J; m' p0 O. b8 R- e' p) _- O   push  0000004fh         ; function 4fh
) c' d% o  _4 [2 ?  o7 T8 R4 F   push  002a002ah         ; high word specifies which VxD (VWIN32)- F, K- q+ o7 U& u, k
                           ; low word specifies which service& q  p8 V# V( n' U6 G( A6 w6 L
                             (VWIN32_Int41Dispatch)
! v% G0 h& O( X   call  Kernel32!ORD_001  ; VxdCall9 D7 _. g$ v9 G: r: ]
   cmp   ax, 0f386h        ; magic number returned by system debuggers
* I4 g' \: ~- Q6 |& i/ P( |   jz    SoftICE_detected
' r5 N) ?/ P# x4 z4 B2 [3 _% c1 Y8 {2 e7 ^  K9 ~+ C. U+ I
Here again, several ways to detect it:# i* v& U  ]5 O
/ }5 N2 M+ A6 C/ x( c
    BPINT 41 if ax==4f
! z5 S% l1 _- P
! j+ D! n. L& ?    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
) }& [& f9 F& ~
. L, r0 G1 M7 r, @! o  a3 q    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A* T; u' q3 }. \" W) c3 C2 a3 D1 P  w% o

6 S7 p( \+ D" U    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
& E/ V- X; z5 z5 k* {' n8 v+ ?8 E6 d: B6 \7 b6 J
__________________________________________________________________________$ w2 k' Z0 K' U* E6 m3 U
# v$ k* D$ k( R, Y5 _  i
Method 13
$ f4 J+ M$ [, g  x=========
( S% R/ U3 ^) I) w+ |, ]  v' U1 z4 R' z. D
Not a real method of detection, but a good way to know if SoftICE is
7 G4 q+ o/ m4 W9 k5 Ginstalled on a computer and to locate its installation directory.' n: {$ w) |: `* f2 L* y
It is used by few softs which access the following registry keys (usually #2) :6 i/ P5 _% l) q% g
9 j0 q0 h; k' e- S
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion  k- T; D7 X0 r* E* n
\Uninstall\SoftICE$ V) u- L3 g& H1 k6 P
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
% D$ P6 L; a6 }( \; S/ h-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion# a4 }2 {, |3 J  @
\App Paths\Loader32.Exe
7 J4 D/ O: P" |5 B
  F: I: L8 T% S. l$ z2 U2 |% I4 N6 l' p
Note that some nasty apps could then erase all files from SoftICE directory  }$ u' |, k% w% H7 ]
(I faced that once :-(  v  D& M7 a- {  T" u
  o, I2 F: n$ U1 M4 a, |1 }' G
Useful breakpoint to detect it:
' ~, L* I8 O3 Q& y1 q& Y) B4 m
- C1 z# g1 z9 A2 Y* M5 o! r; L) H     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'3 \# T  X0 o. A4 y
  b, N; ]- L* w: ^; W  B4 H
__________________________________________________________________________5 E, t2 @7 e1 ~2 i" W: ^7 e
" O, U, t4 a! L% w

# i) Y7 ?5 t2 [Method 14 0 |3 x5 Q4 t; }3 L
=========+ K) L! h/ L6 T$ @* h7 h0 Z' _0 O( _
- J( r% n6 y4 N( E
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose8 z) G  ]3 J" N% g& r' }+ i
is to determines whether a debugger is running on your system (ring0 only).& I; D! L6 r. G1 b$ Y) k  v
  E! t, _; |  M
   VMMCall Test_Debug_Installed" c5 O; o0 Y: d) n: Y0 P
   je      not_installed
7 g- j& K4 A, a* E6 A  p: t9 W2 x* L! L" F1 I
This service just checks a flag.. S" o) w( Z7 R& S$ u0 A$ i
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部