About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>% ?: F4 \& M- ^2 q3 {
<TBODY>- R9 R1 ]' T/ T% o: \
<TR>
& t& b7 t1 `; k* g' C<TD><PRE>Method 01 + _2 K' `3 u0 N6 z; n
=========) e, y  X: V6 X
5 a: v( e% N: ]  ^
This method of detection of SoftICE (as well as the following one) is7 h) E2 {, {/ k! Y8 Q: B( a
used by the majority of packers/encryptors found on Internet.; b- P& W# l9 G
It seeks the signature of BoundsChecker in SoftICE
5 J1 K9 E/ H- o, |, i
2 |+ l+ [8 ?: L+ B    mov     ebp, 04243484Bh        ; 'BCHK') d/ v6 b# M6 e- s9 G0 Y
    mov     ax, 04h
' R4 Q* y6 A$ v' Q3 T3 U! S    int     3      
# E4 ^2 P8 B' F    cmp     al,4
3 ~6 A6 M# t! |5 V5 q    jnz     SoftICE_Detected7 @+ N2 b' q8 f* Q$ X

2 |* E, ?) P" ]- W) f. B___________________________________________________________________________
( j' G: l& f7 k3 I2 U8 I2 L, t3 N- U6 M5 D0 v7 ?& S6 C% _
Method 02' t* a6 |: z4 z% S% N. s) H+ c
=========
9 c- Z3 F0 W8 g4 i/ D  M  H: o# U: S
( |* I4 ~" U( [, k8 MStill a method very much used (perhaps the most frequent one).  It is used2 c4 T5 X( ~: W9 c
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,; Y* ]5 L) i% j/ r- m9 R$ R) Z* v8 b
or execute SoftICE commands..." Y9 s# O, N: y2 A5 K0 C. {) b% C/ T2 j
It is also used to crash SoftICE and to force it to execute any commands
- a9 u6 ]) ?3 Y  a7 Q& ](HBOOT...) :-((  ( y0 \# f8 [9 i6 ]

! B) t( X' f- }; ]; a  FHere is a quick description:
8 K" N! B8 X) q' Q( _# Y0 N' W- t-AX = 0910h   (Display string in SIce windows)7 ?2 u" k% n* J- l* B
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
1 B5 U* }! L) {) q$ w: f-AX = 0912h   (Get breakpoint infos)( y7 M4 x) H" b* `, K+ w( e7 |
-AX = 0913h   (Set Sice breakpoints)8 I" q5 g% F) l; u+ d$ K9 j8 [
-AX = 0914h   (Remove SIce breakoints)
4 X/ ^- N8 I9 n# _
4 h, g3 P/ N1 {, T: i* f* U& N6 FEach time you'll meet this trick, you'll see:
. c* j% S/ f! q- @7 M-SI = 4647h
* y7 d, c5 T' [9 B' Z1 j2 T. }-DI = 4A4Dh, m. g, |; s; W7 P! Y1 k
Which are the 'magic values' used by SoftIce.5 [- `* a% U' f  r. x& f6 o% V
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
5 Q- H  n) {( b; o8 ^" K# M7 Y4 d
/ e& Z# b* W0 ^% r0 U- cHere is one example from the file "Haspinst.exe" which is the dongle HASP3 N5 r/ F$ E, j! n! d% _
Envelope utility use to protect DOS applications:
/ V& n5 \6 J& J, S8 O
- O3 E. M) n3 A8 k
# n" L  Q1 k( c- H" g9 J9 g4C19:0095   MOV    AX,0911  ; execute command.& C1 \8 y, X4 b0 g4 X
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
% b: t0 I* w. |( a$ ~0 b7 N4C19:009A   MOV    SI,4647  ; 1st magic value.
. x/ c6 q& _+ b. q4C19:009D   MOV    DI,4A4D  ; 2nd magic value.0 p! M: ^7 Q: m( T& }2 s1 O
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
) B% p" X! C" g5 C  C9 R4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
: H5 Z/ b( l5 q  E4C19:00A4   INC    CX
3 c: o. S0 m9 [4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
! A  v  P1 E3 X# ^4 B4C19:00A8   JB     0095     ; 6 different commands.4 A$ a. Y9 N7 M6 p% s
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
3 _' m7 L: l& C# ^3 o/ u3 [4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
9 g, i& l" b* s0 @9 @& x3 L9 y- O' g  ^3 T, w" {
The program will execute 6 different SIce commands located at ds:dx, which
8 J6 m5 a& I4 P: q* {% {" Care: LDT, IDT, GDT, TSS, RS, and ...HBOOT.5 E7 X' J6 T( o

1 X" ~- T8 h* e* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
- A  z: F7 z+ Q5 i___________________________________________________________________________
. r# X5 u. U" N) D# u
- W; ?! [/ _" N6 F# F" T8 D( N% G: R. R5 V
Method 03  ~5 ?/ Q2 ?+ H  _7 _# z: L, ~
=========
1 k3 t$ v& o% i2 S& D& |
3 S  {" W; a4 w2 l# H6 C0 T/ v% K0 wLess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
2 _. b% Q$ \7 D2 [* }( `! A' ^(API Get entry point)
* O- c* z! {3 e9 x        
. B. Q+ ~$ h: g' K
: z7 L7 n- k) d, @( S# A" w$ j! r    xor     di,di
$ U' R- s7 P9 s/ h/ F- u4 K    mov     es,di% j7 p4 V. x! h1 \9 o
    mov     ax, 1684h       ) K1 s) \& N7 R0 z9 l
    mov     bx, 0202h       ; VxD ID of winice8 S$ F( w: u; s$ ?9 W
    int     2Fh
, ]" ]( @5 n% R$ `    mov     ax, es          ; ES:DI -&gt; VxD API entry point$ x1 J' _, q: |
    add     ax, di% ]# v" t4 A1 Q$ a" L
    test    ax,ax9 s6 m, D/ c0 f2 l( R: z
    jnz     SoftICE_Detected
( C/ Z* w4 @) j/ \# z" [! ^* B! n
- p! Y, C, @0 t, k! g___________________________________________________________________________
6 v& B) B' ]- I% E, t
, e# y* D0 Y% i3 kMethod 04. ?, }3 G3 q1 t2 W
=========) g. g9 s" z. f
5 t5 o5 G3 ], V& X
Method identical to the preceding one except that it seeks the ID of SoftICE
, n9 M' D  x' _9 LGFX VxD.
  O: x; s! f1 S1 T& a$ f6 d9 G- }# n7 h/ l
    xor     di,di
* z  I. s, w9 t+ O    mov     es,di
( d. z9 @5 Z! P0 X# v4 Y    mov     ax, 1684h      
  ~, F+ J4 J$ C5 j    mov     bx, 7a5Fh       ; VxD ID of SIWVID$ L; K) d  k7 G8 g% F7 I0 u1 w; e- Q
    int     2fh) F* x: j% I& I; h
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
. Z4 E: \- E) d% E    add     ax, di
2 ]. B0 M$ Y& J  g6 s# Y' K4 k& v0 x    test    ax,ax5 e, |8 k* ^; q+ Y
    jnz     SoftICE_Detected: V5 N$ ^* Y+ b$ i
7 x& ?6 r9 o, y: M
__________________________________________________________________________! Z; L" F$ F$ Y, _3 D+ ?
( w- i5 \2 |8 d  ]

$ i! _8 d" B4 Z$ m6 ^- B& j/ nMethod 056 A6 B/ s: ~/ [3 B# _3 y: H1 T' e
=========
5 K% ]4 a6 }, D% M
+ ~+ _4 w- T! O# t, g! sMethod seeking the 'magic number' 0F386h returned (in ax) by all system
- I( |9 \/ Q4 d  G9 Ndebugger. It calls the int 41h, function 4Fh.- H3 V+ y% l8 c5 u  U& |: r% K
There are several alternatives.  ) U5 r% ?5 F& a2 v
, H8 R: C/ X& u$ }" |* H$ G- N
The following one is the simplest:# [$ r5 x: K6 w! e
$ v, c8 e+ U% Y5 |
    mov     ax,4fh" [5 _# [9 c$ ^$ A& w
    int     41h8 _3 V# y+ @6 B
    cmp     ax, 0F386
9 k8 M/ u. o. E$ }6 z8 J$ j6 G    jz      SoftICE_detected
% K; Q4 P5 ^: Y  L. j1 q% C0 ~- w. d

! h5 {0 i; r* G% A. Z7 eNext method as well as the following one are 2 examples from Stone's 8 g, F  V- M; m/ @
"stn-wid.zip" (www.cracking.net):
; L5 {- r& `2 r* b" A" K. S& J& r8 X, p! l. _* j! i
    mov     bx, cs
5 p; J0 g$ z) u6 j' O3 I    lea     dx, int41handler2
" y" [! ~& u4 g& H2 e) w    xchg    dx, es:[41h*4]
0 M+ @: m0 K5 G; E7 x    xchg    bx, es:[41h*4+2]
- a6 x  w" T5 U- Q4 z0 J8 `    mov     ax,4fh7 r% K+ @2 O, @7 b8 X& ]
    int     41h: P% ^0 h$ f8 h& D/ g
    xchg    dx, es:[41h*4]
) k5 V: |( z' O1 H    xchg    bx, es:[41h*4+2]
% i; `& R+ d* ]& j0 R, N7 C    cmp     ax, 0f386h- t& K8 U# ?6 _. e, [) f
    jz      SoftICE_detected
: O1 X0 R7 V7 N4 {* d0 J& }) n( T# Q( L% c
int41handler2 PROC  j# r9 @" n" `" T/ b# r
    iret2 Q: Z( `, q1 C5 ]1 z
int41handler2 ENDP+ p1 }7 w$ z+ W% i- b

" h) _$ W. a- P/ ?
, b7 {6 r/ J# n6 ]8 x: x( |9 m_________________________________________________________________________$ E# V; ~3 a5 T( ~( `1 K6 O$ N
" s7 F6 a" u+ m

; j( w6 `$ N* b- B, y  T0 }5 rMethod 06
$ C+ N/ n; ?7 z  F=========
" g0 A; ?: u! Z! L, z3 E: f* z" B' G) t

7 p6 Y( M5 c. R* n2 t7 w2nd method similar to the preceding one but more difficult to detect:, [2 y. ]+ D6 y1 u. }  I  H; J
/ t8 T5 `/ p* \) n# D# I
+ {* ~  O  X! ?& o
int41handler PROC
9 v. M* z( O& I" X# [3 d    mov     cl,al
6 X# N# y) `  L7 Z+ M0 @    iret
5 C1 W/ a+ ^# O7 b& c( N2 a9 qint41handler ENDP
" Y0 O7 s4 V' @* Z) E7 f
( s6 b$ \0 u7 V+ g; b7 p( C$ F0 n3 r* L' T% A; m6 f3 d
    xor     ax,ax6 B0 N5 q( E: |8 m  X2 \
    mov     es,ax9 K* G6 u8 z* W  A* W2 Z4 V# L3 `
    mov     bx, cs' {6 V' ?- M' j3 d
    lea     dx, int41handler5 x) V/ ?+ m0 o8 {
    xchg    dx, es:[41h*4]
; C6 ^$ C3 S. [    xchg    bx, es:[41h*4+2]
. _2 B$ l% c& X    in      al, 40h$ z7 I8 ?% p2 z3 q. _  \- c
    xor     cx,cx$ V0 D- m3 S' V2 K
    int     41h
- Y% L) O4 z- m; }; ]& j5 k    xchg    dx, es:[41h*4]
3 l! k: s1 {0 j- \    xchg    bx, es:[41h*4+2]
# t% t+ n8 @; |0 p    cmp     cl,al! F  P3 a" }" v1 S8 S/ r" C
    jnz     SoftICE_detected
- p2 f4 r( X6 W" U( W1 F
3 l* D9 c/ C8 P0 j+ w6 P, A8 |+ q1 w_________________________________________________________________________: Y' |1 h8 U) W! m
' W6 e2 F* j8 u$ ~$ x1 _5 @, N  Y. |
Method 07+ L6 m% Y% S) x) L# D5 |) t
=========
$ M8 t8 Z& U* y5 s8 ?- M
7 F  Z0 K( ]7 ]& s7 RMethod of detection of the WinICE handler in the int68h (V86)
8 e4 }$ e7 j" D. }* x$ C
% I: A# S  E' \9 [+ v/ z8 [    mov     ah,43h: _7 j+ G9 P, A9 L
    int     68h
5 t. s# g: m; P- ^& k    cmp     ax,0F386h0 q7 b% B* {$ M& i* c
    jz      SoftICE_Detected' J  F; D( ^; B0 v2 X. o( W& J
, d8 W6 ^8 F( C, g7 ]
& x4 W, r! ~+ Q9 l! X: O5 ~
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
2 Y+ p, Y+ ^- C   app like this:
8 n1 l$ I( m' U4 E" F) f4 f/ h
   BPX exec_int if ax==68
& k8 X# ?$ \: M/ e- @7 M   (function called is located at byte ptr [ebp+1Dh] and client eip is9 e3 k" N) w. i
   located at [ebp+48h] for 32Bit apps)- F: {9 Z( ^3 h
__________________________________________________________________________
7 ~' A; @! H+ @  ?3 B0 F9 p. n3 r1 ?  j2 ]

% \- l! Z. Q4 I$ DMethod 088 R- c) d9 n3 {6 h
=========9 X$ a8 B/ Z* X% F: d0 \) A7 k

8 {; ^9 {+ ~4 |% F  F2 C6 Z1 D/ C* H6 DIt is not a method of detection of SoftICE but a possibility to crash the
) j& l9 [2 ^; ^7 `) ?5 K# i4 dsystem by intercepting int 01h and int 03h and redirecting them to another
# \: }/ o  a' d4 P4 ]( j* Jroutine.% b* d9 d+ _) j
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
, C5 J1 W7 X# _- w  Y! f9 gto the new routine to execute (hangs computer...)
; }1 G- @6 w0 v  `9 D/ W" v" g" i# D- L, ], x* Q0 H" S! T: }
    mov     ah, 25h% I' }3 c, E$ x7 Y
    mov     al, Int_Number (01h or 03h)( W/ g2 J0 D# G6 [* o4 ~- r6 J
    mov     dx, offset New_Int_Routine
+ \" z8 [! R% p/ \: d    int     21h& G% k" g* J& b. M9 {/ K: d

9 B- B4 H7 C6 ^% s+ i- |% d__________________________________________________________________________
, U: U' A6 L# i4 }2 J# t! N4 D1 L  O5 ]
Method 09- \4 B# |$ p6 ]2 f9 U6 V% U
=========$ n! m; ]" c7 A  v  n9 f
+ E/ j& x0 x; A) |' ?2 J% }$ B. y& j3 J
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only  U$ W6 b' m) K% E- l# b
performed in ring0 (VxD or a ring3 app using the VxdCall).% l" m8 C% m. z
The Get_DDB service is used to determine whether or not a VxD is installed
7 }) e, a: R" F" r7 g& d2 `for the specified device and returns a Device Description Block (in ecx) for
0 u1 `* O- `7 ]$ vthat device if it is installed.6 }! Z4 d6 F' h+ {% O1 V2 @5 B1 X

. S& ~0 g4 P0 i* }  I$ Y$ q   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
1 {( B9 x* U1 q2 i" E; F   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)# `7 s( u3 S' W
   VMMCall Get_DDB
- k) S; D& U: H/ t3 G! [   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed% z6 `6 s( V5 E" K) p- w

- x4 `3 V. N$ r# B! W* E8 S# RNote as well that you can easily detect this method with SoftICE:' o' w0 e  e! d# V
   bpx Get_DDB if ax==0202 || ax==7a5fh
8 z4 u5 w' ~" n7 r4 ?6 f6 ^( B0 ?+ ^9 O4 B- E
__________________________________________________________________________
! I' U8 y+ I  A& P$ V( e, c% X
8 n- q, d7 u- `4 h* rMethod 10
5 v( w7 |! G& ^7 ]7 u% R1 ]=========
; p! J* V6 U5 `# j: \
) {) o9 M2 H  C, b  l2 V- b=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
, f/ d$ q9 m  [* m: w* x9 F* _  SoftICE while the option is enable!!9 S6 _1 @- \( |7 [8 B0 b9 P& l0 L
0 q$ [4 o4 i1 ?& r" L+ r' j0 ?" r4 C
This trick is very efficient:3 K  @0 @" Y3 g4 A" \  z' L0 L) T
by checking the Debug Registers, you can detect if SoftICE is loaded( O1 P: B( ~2 m  N
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if5 I+ U4 q8 l1 a- m8 l& m
there are some memory breakpoints set (dr0 to dr3) simply by reading their( X5 w" d3 ]9 Z# X+ a- y1 O6 j
value (in ring0 only). Values can be manipulated and or changed as well
3 U: i9 |4 b6 h+ S3 Q  u3 R(clearing BPMs for instance)5 o1 U; D* A% |$ B+ I1 F# D
3 A+ B; }/ t, s, B
__________________________________________________________________________
, l! Z; }2 X, m* [: {9 x+ F) ~' J+ f
, N9 |' U! p: C2 q6 Y1 p/ EMethod 11% y: @8 v& y! K9 |  Z0 X3 {- y9 u
=========
0 t) j! r3 R- s: {: ?% u  Y6 C9 L3 @$ w/ z5 {2 ?) j6 I7 N. B
This method is most known as 'MeltICE' because it has been freely distributed
2 t0 v( F" e! tvia www.winfiles.com. However it was first used by NuMega people to allow# i) j  {' P3 J" X- n# b9 L6 ~
Symbol Loader to check if SoftICE was active or not (the code is located9 ?3 v( f+ H7 E7 P2 R, Y1 i! M
inside nmtrans.dll).' w4 z- w2 n+ }7 I8 e0 X$ Z" t6 l
* R+ Y! f3 B% j0 x
The way it works is very simple:
: _$ I; W. a" }% GIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for4 B( k' Q7 X, I: k# q+ B
WinNT) with the CreateFileA API.
1 r( D7 i' D  X6 m2 ?7 [9 ?
! f/ k8 `* x0 i8 WHere is a sample (checking for 'SICE'):
3 I  q2 V( A, [# b. T% r! y
, ]: t% `- L+ hBOOL IsSoftIce95Loaded()
; z/ S$ S( T6 W! U5 }' z{
1 c5 w9 ~& ]; ]7 S5 I   HANDLE hFile;  $ {2 Z* _, x1 q5 [5 b7 b. [( H: u9 x- x
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
2 n. E: H! \; N7 [) T9 Y! B                      FILE_SHARE_READ | FILE_SHARE_WRITE,
( n- l9 w0 j( `0 G1 A; M6 W                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);5 |* W" @# m! ~  |  K- Z% R6 y5 Q
   if( hFile != INVALID_HANDLE_VALUE )! }$ a* I+ `0 e+ P6 q9 Z
   {
4 N2 E) R4 T; p3 A5 o+ k      CloseHandle(hFile);
' j7 _. s7 K5 }) y- S! D5 N      return TRUE;$ ~; A. p3 t" m' S: a* i
   }0 m" ]7 x% l! N" Q3 d) W
   return FALSE;2 P& W$ \$ {1 ^$ d; B( q+ f' h( I
}
1 G' r: o8 E, t8 D+ v3 W. f
5 G+ U: B2 c  C* u6 a% e6 KAlthough this trick calls the CreateFileA function, don't even expect to be
; u, h% H! Y+ N. B( Q  O7 H7 Qable to intercept it by installing a IFS hook: it will not work, no way!
" ?+ ~9 A2 ?' h4 w- B5 pIn fact, after the call to CreateFileA it will get through VWIN32 0x001F3 H2 M7 u& `& U
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
+ C) Q* \1 d% I$ d' Qand then browse the DDB list until it find the VxD and its DDB_Control_Proc
; s. U6 f9 S- w  afield.3 U- q6 N0 p: D5 ]7 g
In fact, its purpose is not to load/unload VxDs but only to send a
7 M) `# C4 h. t! A- \3 TW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
" v  [3 A  l6 m( e  ^2 sto the VxD Control_Dispatch proc (how the hell a shareware soft could try
1 m1 p" l8 |6 x* D% r9 x4 l7 a% Q6 B5 Nto load/unload a non-dynamically loadable driver such as SoftICE ;-).
  {; N8 E' @* e' g7 K) EIf the VxD is loaded, it will always clear eax and the Carry flag to allow
' W' p! G  K* v. s" s5 Lits handle to be opened and then, will be detected.
" t) H; D5 V' {) G0 @You can check that simply by hooking Winice.exe control proc entry point, z5 v- L- e& G+ p2 K% J/ O
while running MeltICE.
: p6 i6 |# e& d
) j& d7 D% m, U! _$ x/ \4 A- r+ ?- m: c+ f* G4 S- p
  00401067:  push      00402025    ; \\.\SICE; ^6 t( i7 u0 O2 W. ~  _+ r
  0040106C:  call      CreateFileA. k) ^! p8 T# j$ z
  00401071:  cmp       eax,-001
- a# L  N. v6 a  00401074:  je        004010913 s( o; M. ~/ s2 H; U* S, F

. f# P- n- @5 E$ u. U
6 F* }3 w1 c3 @# c( B  }& c! e; XThere could be hundreds of BPX you could use to detect this trick.3 _$ y0 S; a* q) {4 b' j
-The most classical one is:) h" ^/ e+ r& Z* X' d
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||6 r9 \% k, A% r0 C" P6 q- v4 S
    *(esp-&gt;4+4)=='NTIC'; x# J$ s% h2 i) o( u
# x$ v1 B; o2 j  f# A
-The most exotic ones (could be very slooooow :-(/ {0 J) \5 ~0 S5 I
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  1 p6 |! }( i% d- k6 S
     ;will break 3 times :-(  g& \, \3 o( I; {, `
; U& G$ T( B- {# g$ Z
-or (a bit) faster:
5 X6 N# W" n9 W' I* J   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
1 i% s5 t9 q- s! e  j5 N/ @, F, _8 G) l- g0 S
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
) R+ g% }7 J) x4 d. n* K1 S     ;will break 3 times :-(8 ?. r2 B$ X& H: H8 z+ W

: s1 [/ y: P1 u+ [" n; h-Much faster:1 o( }# t* f/ x2 t* R+ N+ c8 d6 {
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'6 l- |. h- p: A( w& P7 U" J9 s/ D
% t  A% z/ l2 [8 A# }" |
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen# a( }3 R+ ^$ }. B
function to do the same job:4 j8 Y. h7 r3 [" m- Q  p, }# n" I
  Z  x1 Z+ z. E9 c4 w9 T/ M$ |* D
   push    00                        ; OF_READ
# m6 d% j- Q- X; |3 M6 `   mov     eax,[00656634]            ; '\\.\SICE',0
# e. y' H8 j: R$ M   push    eax* h/ ~! q* T, ?! d! `
   call    KERNEL32!_lopen
6 [$ L4 r/ |' A3 f& M   inc     eax
; f0 O4 R& V( w/ u   jnz     00650589                  ; detected
! Q" ]- e* b3 t   push    00                        ; OF_READ
3 c; T; w' F7 @   mov     eax,[00656638]            ; '\\.\SICE'
/ X" m0 Z' B& F& S   push    eax! O$ t9 k) g4 e; L" H4 x& n
   call    KERNEL32!_lopen
3 l( j8 D8 a- Z2 ~5 d# `1 \3 b   inc     eax- G; @9 P" O4 M* e3 x$ ~" w, ~6 L3 J8 h
   jz      006505ae                  ; not detected
8 I. E- t% s  F8 O! F
  ~: P6 T$ ]; ~8 j8 N; G
1 e- A8 p% N' H- j- {__________________________________________________________________________
: \  d* v- P6 K2 ?
( l# b. D8 S3 IMethod 12
6 {- h& w( L! q: H- N=========  \. `8 e) e& Y7 I8 f

2 p( N  ]( \9 L3 Y4 o4 p5 Z+ R8 ~This trick is similar to int41h/4fh Debugger installation check (code 05. K! G0 E# k- |1 A( [( u. W
&amp; 06) but very limited because it's only available for Win95/98 (not NT)
! U8 w% N, |% |6 Zas it uses the VxDCall backdoor. This detection was found in Bleem Demo.
& m* S6 X0 d- W) i3 G: O1 |: s
8 O4 D1 m. |7 {1 ~, v   push  0000004fh         ; function 4fh
; e4 i5 P3 ]# K/ E* e   push  002a002ah         ; high word specifies which VxD (VWIN32)
8 U7 \+ y  i4 f; w* H                           ; low word specifies which service
( S9 R  x! Z) |8 x                             (VWIN32_Int41Dispatch)1 ~( Q' F# F, w6 S) h0 M
   call  Kernel32!ORD_001  ; VxdCall  ~( Y4 F$ O) z8 s$ Q, L0 j+ W. v
   cmp   ax, 0f386h        ; magic number returned by system debuggers
" h: k& l0 j0 a" F" P$ B   jz    SoftICE_detected
! N5 q( z' |: K" l6 `4 Q$ N5 @5 L
+ r7 ?8 v, D3 u% M* }9 MHere again, several ways to detect it:
, Y  f9 }- K" e6 ^! N7 E% }3 h1 ?8 O. Y
    BPINT 41 if ax==4f- X% ?. i0 i9 E# \5 G" M
1 u3 W+ I) D0 h! J3 _& e
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one- |+ F( Z' R5 o# O

; X+ J" n  ?! @0 e    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
! T' k1 E$ ~: Q' }8 c6 ~+ ~7 K9 w7 ^; |
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!, Z8 C1 M8 K. ^" ^1 d: e  e& Z0 ]( Q

/ }! G+ b7 M1 X__________________________________________________________________________
) k2 o. A, C$ ?# k7 B5 W+ \
$ j, Y2 ]+ O# M# rMethod 135 h. F5 R/ g+ C+ Z1 ~( D  V
=========& j; f( y! e( M+ k5 H& b9 R" ?

( I7 I+ c6 h! _. bNot a real method of detection, but a good way to know if SoftICE is1 e% a( s/ Z& X! |) Q6 f! q! E
installed on a computer and to locate its installation directory.$ _5 T+ d2 r* |
It is used by few softs which access the following registry keys (usually #2) :2 y6 n$ O  Y/ o+ }0 }2 a

+ p, e, G7 [" J: w-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion& `/ ^5 I9 c' s: o+ g% A8 o* p: t
\Uninstall\SoftICE. J2 x. I3 G' L- E0 n$ Q1 D
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE+ r% ]% ?/ J# L' }- R6 m( K
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion, {; ?1 x6 ]3 e6 m+ `& ~
\App Paths\Loader32.Exe
. d& r) y7 I3 S+ h2 ~' [; W. ]2 s$ ]: m' C6 R: A; e

) b3 C+ A8 u, |Note that some nasty apps could then erase all files from SoftICE directory( P. S: A" w8 g4 T% R( S8 X9 ^
(I faced that once :-(* t6 }0 |0 F2 m5 m  a

4 s1 i7 S0 w3 a/ hUseful breakpoint to detect it:4 N+ z- h( u" m9 g$ ]
3 m$ c* s9 m! r3 C1 m. ^4 H& w
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
6 P% W6 O8 _( N$ n% g) D/ M( Q' X1 n( l2 [; P3 G7 J+ p
__________________________________________________________________________% C( _0 H' X+ C: ]' g' p

0 g/ z  s* C* ?4 I
6 y( e/ e1 P) h' G5 |Method 14 " n# b' N! O6 I9 D1 @
=========9 l" E1 M& z' J/ N, l/ V0 k4 h* N
% c8 W1 _0 [2 p4 J/ ~
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose- M( ]. t0 r5 i4 B/ W+ t! p+ q
is to determines whether a debugger is running on your system (ring0 only).8 ^7 z1 T- J6 H0 {# b

1 Y0 `4 i5 u9 w" c, I   VMMCall Test_Debug_Installed8 C, P6 L- B9 b' }* D/ N
   je      not_installed
+ J$ q: G; k9 p' }7 b
& B$ S* t  w( SThis service just checks a flag.- N; v% q3 C, f" C7 j  \6 R0 C
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部