About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>( I3 A1 q+ J$ C
<TBODY>
$ I7 n3 L- k8 j<TR>3 _2 t$ ~6 Z8 Z1 v, e& D" x5 R
<TD><PRE>Method 01 1 f4 R: z2 V  H8 `( h) g2 [
=========) a$ m9 a+ A! i# \! d

+ H6 v! P4 |. t9 A+ ]This method of detection of SoftICE (as well as the following one) is
2 y9 h1 p, v0 Y# S  I* C9 kused by the majority of packers/encryptors found on Internet.
+ T, b' e/ T( n6 i: X+ `It seeks the signature of BoundsChecker in SoftICE* e6 K/ P" R0 R4 }1 ^# f

  m% H! ?' G. J) q    mov     ebp, 04243484Bh        ; 'BCHK'
% h( ?1 a: Y& ]& z) _" X& v    mov     ax, 04h
: A, T: O- }: [+ |( e( J' L    int     3      
: c' O8 p9 m6 x8 Y    cmp     al,40 J" G% w& e7 u' F# P4 O% |
    jnz     SoftICE_Detected3 c% R2 L. w% p

& X* c1 {7 N. L" g: V% D. d___________________________________________________________________________0 ]. ]+ _) A# ^# q3 P, O9 X
3 a3 B" ]5 h% ^* A3 o/ o
Method 02
! A8 I- h0 i: K$ M0 e4 K=========$ x! @* V6 T' |+ t8 L6 A( m
! M* H0 ^; n6 H4 E
Still a method very much used (perhaps the most frequent one).  It is used
6 n* o' r) T( r5 w0 p& K( \, a) n% _to get SoftICE 'Back Door commands' which gives infos on Breakpoints,; [$ d$ m, Z6 c7 j
or execute SoftICE commands...* k/ w: ?% ^1 c5 b* r9 j/ w  @
It is also used to crash SoftICE and to force it to execute any commands/ P9 o8 x5 y, i1 j' N
(HBOOT...) :-((  ( k, y0 ~) V7 b" e+ d1 F
' t3 A  r( R" F2 \& P
Here is a quick description:
3 q, }- }8 [8 m  i+ ~8 [-AX = 0910h   (Display string in SIce windows)
7 u* U  U* k/ n+ Z3 U! M3 Z-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)! Y+ L, U/ g" O9 U: q3 a
-AX = 0912h   (Get breakpoint infos)9 ~! p) \+ B% U' k$ q" f
-AX = 0913h   (Set Sice breakpoints)
9 I# }/ l" t( ?0 h/ d-AX = 0914h   (Remove SIce breakoints)
' |9 o5 p* ~, l: P3 i' ]6 h! F& @. k7 h5 F+ S* @) j+ c/ ~  m
Each time you'll meet this trick, you'll see:
. t0 V6 i6 I6 K- ?-SI = 4647h
4 T4 K* ~% V8 z* R. I% _-DI = 4A4Dh
5 T8 t& G. H8 b9 DWhich are the 'magic values' used by SoftIce.3 ~" f3 o0 k& ^: ]
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
$ x+ X( _5 Q1 z, F* l. ~
" J7 x7 s/ i) O2 MHere is one example from the file "Haspinst.exe" which is the dongle HASP
/ k, I; G( ~' @  K. C4 z1 LEnvelope utility use to protect DOS applications:
5 h+ h6 L4 y" c* U( [
6 c. K! L' w8 z4 ~$ H; A" T( u
4 q3 G1 F2 y" T: S- B4C19:0095   MOV    AX,0911  ; execute command.
0 ?+ n6 ^# c  A$ h4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
4 p2 K: q3 P: x( h9 o: ~/ U4C19:009A   MOV    SI,4647  ; 1st magic value.
2 x0 ~# P& a! C9 v6 ~% U4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
- I9 x5 G: [7 F4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)9 W# h# M; K. E5 Y8 u4 G, ]
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute/ V! m- G9 n" Z4 _6 j% _8 ]
4C19:00A4   INC    CX4 p9 g5 q, |" Y
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute7 [5 z2 r/ v) x" p; B: V
4C19:00A8   JB     0095     ; 6 different commands.
# P( Y% v1 ]" b' ~4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
+ `5 Z+ q" q% G% M4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
+ `' N5 O) p+ y; B8 F; _1 J6 A' b$ J3 ]8 f3 n( }' F6 O+ c
The program will execute 6 different SIce commands located at ds:dx, which
" j, @# z4 J; F& A. B# O, [% sare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
3 j8 b. }' d7 \' G% ~3 {* U7 E' m1 l$ K, {" l/ ?: }
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
; D1 U. k: x4 A  t; U" W' |$ z___________________________________________________________________________
+ R3 @. G2 @* k4 W, @( e7 [6 j. a* Y* m" w+ Q
# g# p  a" C, s/ q1 a
Method 03  W) c( D1 U+ n$ [/ P3 ?$ I9 j
=========) w6 i# j% Q$ e4 B" h

8 c& [$ ?. j0 a, T0 c+ ~Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
+ C* u, ?$ i5 C5 E3 q(API Get entry point)9 T& o; i  K1 ^
        
7 F7 G$ w& \7 L
5 T  _6 p) Q0 `    xor     di,di
# K3 A1 U4 s+ T6 e/ a! x- j" o2 x    mov     es,di
0 E' r+ v; P( L. l    mov     ax, 1684h      
2 j0 a; N% j' N% s    mov     bx, 0202h       ; VxD ID of winice
  `/ G5 T. k$ B  d+ p! M1 g) S7 @    int     2Fh4 ]; E& x/ V! f4 b' G0 `
    mov     ax, es          ; ES:DI -&gt; VxD API entry point2 l$ q( n; ^) D" d3 i. P, {$ h5 n
    add     ax, di; y. K# b) H0 ~6 o: S- p4 h* |
    test    ax,ax& A0 ]( g: v- d! y4 k' V
    jnz     SoftICE_Detected& Y0 f( b, _5 U7 h: Q) j* V

" d: k/ E% x4 d- R* q2 {4 x___________________________________________________________________________* g4 U! I* m" o4 ~5 Q$ n  _+ b
7 G0 ]5 I, }6 {; k; S& E% J8 L% k$ m
Method 04
0 o) `) H6 }6 j& N=========; [% J4 f3 G4 p6 u
2 V1 K" _. ~! ~$ g8 \
Method identical to the preceding one except that it seeks the ID of SoftICE$ q* S' t- v5 }1 v9 y
GFX VxD.
. E4 |5 T- b5 i
3 G' W& k/ b$ E  _% ?    xor     di,di
- H! t( y# Q, g0 j7 U5 T) F0 Q; o% v    mov     es,di
- N" f2 V) x3 e/ m8 c, ]  ~    mov     ax, 1684h       4 s5 d, p' f) u; |# m+ D* J
    mov     bx, 7a5Fh       ; VxD ID of SIWVID' N/ ]: m" V5 m) w# c1 b- [
    int     2fh, r3 W) X' o: y" o. C
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
- G+ G) i3 M! l# D& g% H! j. B! @    add     ax, di  ^+ T8 B8 o$ D
    test    ax,ax
7 Q; A( X% }* R4 L    jnz     SoftICE_Detected
, R" x2 x$ }* F# q' G& J3 B8 @% E/ E. ~
__________________________________________________________________________* B% Y" m; k  s" O  Z5 w" n
' P* ]; a5 v  ]0 {: h' I* o5 k0 @
( K7 ~: X% X8 |* I1 y& Y4 v
Method 05. ~+ e$ r5 H1 `/ V9 m2 ~* k
=========
. m  K+ K4 T- h$ S- [# ~* [: K. j& p; ]; R4 z4 B
Method seeking the 'magic number' 0F386h returned (in ax) by all system/ y. ^, o" t) A) Z0 X
debugger. It calls the int 41h, function 4Fh.
! b0 o8 g$ ?$ _% uThere are several alternatives.  5 o1 U' T' {2 b& D3 {
  D4 A: ?4 y7 @5 a9 t
The following one is the simplest:
" i3 s5 V- z- i' g; k; L4 @* L8 `% s
    mov     ax,4fh
9 B( U  {3 r9 f3 R  U2 b6 g    int     41h
! g" s) o; c- k0 H2 w3 @    cmp     ax, 0F386- j) w, k& n  i6 \% J: w
    jz      SoftICE_detected
8 A5 ^9 W) H* k- Y) {. a% c$ M" `/ s
5 x# o  J8 ^! I: k
Next method as well as the following one are 2 examples from Stone's
3 F. T3 b( G! O"stn-wid.zip" (www.cracking.net):
, x0 J) e/ L& F) k, ~5 z8 {4 P9 f% ?( S" d/ D% _1 I, N+ W1 \, i
    mov     bx, cs
/ a' c& k9 m- N/ j    lea     dx, int41handler2% i+ e/ H' M5 ^+ r: u) o
    xchg    dx, es:[41h*4]
3 [' S$ D% C4 q) S) P! h# ^    xchg    bx, es:[41h*4+2]2 P; X' T; ]  z
    mov     ax,4fh
5 g% f5 M" ^/ S. `, R0 \/ `. d* E    int     41h6 N9 v  v7 n' y8 i% ^& S, a! ~
    xchg    dx, es:[41h*4]
! T& v( |* J; @6 [  I  \, }( q    xchg    bx, es:[41h*4+2]
4 o# F0 t8 O$ |    cmp     ax, 0f386h" Y# O$ l4 P' W2 {5 a0 G: w
    jz      SoftICE_detected7 z  z3 e6 J9 d8 `/ j3 z" x2 F

3 }3 L" D$ H9 Q9 Lint41handler2 PROC# p. ~' _  v1 u* E. P
    iret8 w3 i4 I4 x/ C9 \8 E! o/ d
int41handler2 ENDP
( [* _4 n7 L* y) a* }4 w$ Q/ ]/ j' [9 L0 k
& k9 U6 |, I. Y6 v: O; P3 ]
_________________________________________________________________________- \% H' D6 ^+ @6 h4 p, ~

. H8 c* e: W% [" `- @0 \0 f  c; u) c2 {6 I2 }. L
Method 061 I4 R+ I1 w" d
=========
+ D5 ]! U+ T" _) X! I7 Z
7 }! E5 Q% b8 J; ^" T) O
2 f6 b1 w" `3 J* n' B. r. H& L2nd method similar to the preceding one but more difficult to detect:" O5 n) P$ {1 Y7 L9 Y

5 \: P, q! v# [9 m0 z- M) Q0 ?$ A: K" o3 R& t! R* `
int41handler PROC
0 x% G6 I: g: G2 @1 i    mov     cl,al- F! G$ f+ H/ u# S3 _! I* X
    iret6 _; s- J* \; o& a1 A
int41handler ENDP# ^' E/ ]$ B) y( M( w: K

  o; b! I+ a3 D  v- ~( [' O# h! D# ^; }
    xor     ax,ax; l/ a: L2 x% W' G  B2 K
    mov     es,ax
! q6 x2 c5 h$ \. Q( W" d    mov     bx, cs
; D' v! x& i" K. t    lea     dx, int41handler) ~: Z* T- k% R- ^9 x% p- |
    xchg    dx, es:[41h*4]
. t  q! e& x4 a' F$ X% u    xchg    bx, es:[41h*4+2]
+ t; K" |; \( Y* ^0 ^    in      al, 40h( z+ w" ?  J1 \0 b3 n% W3 ~
    xor     cx,cx+ E0 T' t( T& I$ E- ?( v  X
    int     41h
  P( q/ {4 H  l$ C! Y    xchg    dx, es:[41h*4]- }* z; S* r8 x5 d, T
    xchg    bx, es:[41h*4+2]: N6 [3 F3 ^' F( R
    cmp     cl,al- W" l5 p/ [; r5 T6 e2 F$ t+ s( |" i) a
    jnz     SoftICE_detected. k2 a6 f. N+ e6 m

! G0 H# |3 D! d( f_________________________________________________________________________% L, C. w* U, K/ p

; [& N+ M6 |1 wMethod 07" I! J0 ^/ b7 l) H, u
=========
' u. Q* X9 u" U, ?/ F; O/ ^) n3 T. t/ u
Method of detection of the WinICE handler in the int68h (V86)2 e+ L1 ?+ C4 N# S" Q0 K
' l, }1 N2 ?5 Y2 [" ?. [" R
    mov     ah,43h& F* D+ E; G2 p9 c) t' i' e8 ^
    int     68h3 E' s) \& i' \9 h% L6 d7 \
    cmp     ax,0F386h
0 R& a" W5 a0 F- Y% g2 z+ f    jz      SoftICE_Detected
2 `8 y( b+ E( m" t* R; P9 C* {7 i
+ h( O) x# G$ F3 h2 t: U9 a0 |: o$ j/ O. [! w% |
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit5 c. Z+ [$ ]8 H$ Q( ~! H! V4 i
   app like this:; i: _% L/ Q+ h/ B' [7 e
( T; r4 l6 Y5 D. U  F" S
   BPX exec_int if ax==68
" O% B7 I( I: v' V4 o0 C   (function called is located at byte ptr [ebp+1Dh] and client eip is  D9 F3 t8 Z# s$ G9 [# M" T. v; W0 B
   located at [ebp+48h] for 32Bit apps)
" W7 C4 W& W1 Q- Y. y( @7 e__________________________________________________________________________* w& ~  B1 j) L4 A6 H5 h! f" ]. g. w- |
& m9 E6 y7 ]! P6 N6 _7 f$ t6 R

3 J' N, n4 e7 S, PMethod 08
( C0 C6 l5 I  v" Z, ?4 E=========# t* _6 U) W7 ?
* w9 S! M0 q5 F. B4 B- _
It is not a method of detection of SoftICE but a possibility to crash the6 l+ Q4 @- h3 O, q$ M5 f
system by intercepting int 01h and int 03h and redirecting them to another% w5 S  ~# W- e5 Z- X& c. K/ J
routine.2 m8 N; S4 k5 {2 |5 N; G
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points2 G$ @  ]  o# E- S
to the new routine to execute (hangs computer...)
2 k; g0 \; O+ f" G- v9 n% w* p9 A; t) k( k: v' \( Y
    mov     ah, 25h2 J% x/ V  S7 `' v% r
    mov     al, Int_Number (01h or 03h)
* g' C4 k: N* p7 n% E    mov     dx, offset New_Int_Routine
7 c7 @! ^) _: V/ ^$ m, f    int     21h" l: S; Z! _9 j. O% B' w" M

4 H5 Q( z! D! E3 C* v__________________________________________________________________________& ]8 Q0 G3 P$ P+ ~! L

4 \1 O/ ?2 B. s$ e9 l. v) }0 A6 pMethod 09
2 j' e1 G9 h3 O1 E=========" q- ?" J, j; P4 K3 {5 `; N
9 h' ?3 \6 Y* w& E
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
1 O' ?& c" n& D+ m, tperformed in ring0 (VxD or a ring3 app using the VxdCall).
" f& u2 u$ i0 i' x+ M# m$ HThe Get_DDB service is used to determine whether or not a VxD is installed: t+ i9 ~, I. @" a, L- C
for the specified device and returns a Device Description Block (in ecx) for: l/ M4 C9 L4 m; ^
that device if it is installed., x! f8 a6 I, S# i  O2 ~6 {) A

1 ~3 o. Y! B5 N8 t5 g+ a; i   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
+ P# V8 K# ^2 [+ X' F   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
& n3 D6 R- U7 o   VMMCall Get_DDB
; \/ `- L7 C) E; a   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed/ e, f! g  e# p1 q6 H
' Z5 |. J6 L4 Y8 O
Note as well that you can easily detect this method with SoftICE:
9 X! b7 O, [' N0 b% r! j( H$ u3 H   bpx Get_DDB if ax==0202 || ax==7a5fh
* f/ s# ?2 I3 H( a0 j: C, y, `, @% w! I
__________________________________________________________________________$ J5 E6 z1 @1 ?( T- G$ B3 ^
  O0 w2 U4 ^! s& S9 R0 `
Method 10
  x- S, L! K8 w8 D  ?=========& u! y3 ^8 V! y  b) v

  [2 j/ E2 f; |+ V) h& N* i/ t$ {=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with9 ^6 V6 H2 ~! P# _; t- v: S
  SoftICE while the option is enable!!
# u& R2 \2 r9 n
$ T& \3 D8 K6 d0 MThis trick is very efficient:
4 f# ]7 r2 B5 p+ \* \# Mby checking the Debug Registers, you can detect if SoftICE is loaded
; }. P$ K6 ]+ a* X( v; E(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if. A8 P" T7 Q# g2 p/ m: _
there are some memory breakpoints set (dr0 to dr3) simply by reading their4 i- S. V% T- ]0 I2 T5 e
value (in ring0 only). Values can be manipulated and or changed as well
& A8 F4 G$ j1 e  d3 l2 B9 G) h(clearing BPMs for instance)6 B) Q  r5 E1 E- l! n

: Z: t, F3 ]8 Y+ e8 @__________________________________________________________________________
$ ]9 j; u+ T% ?7 N( R8 D8 A4 A, r4 m! k/ d8 p) `/ ]- t5 c
Method 11! W  B: r. X* V8 u  b. D
=========
% S$ a1 z& N2 A5 Y! j4 z& R( Y6 r& L# \
This method is most known as 'MeltICE' because it has been freely distributed
" ]- q% M. a! _; W3 G4 W, h, nvia www.winfiles.com. However it was first used by NuMega people to allow) u8 S, M" U- u" \1 k1 w! s
Symbol Loader to check if SoftICE was active or not (the code is located  e3 N$ Y) l+ L- k; J
inside nmtrans.dll)., s1 b) y- V( S9 L8 [3 f
) x0 ], X  @! M/ D' E- q) X# Q7 U# o
The way it works is very simple:
: C2 K- T! A- |5 d- F1 X/ P+ o0 OIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for! `$ \% o$ k( m, {0 g9 X0 q
WinNT) with the CreateFileA API.7 s  m; x5 Y1 \& F* g' f  r+ w

. W% \  r; p3 m7 [" y7 L: L& h( a8 VHere is a sample (checking for 'SICE'):$ Q2 j/ k) S# D) R! }, ?

6 }& O6 b5 c& Q3 ABOOL IsSoftIce95Loaded()9 M/ G$ l2 |+ g! G) E
{
; q' k+ P8 E& B   HANDLE hFile;  # r" f% s! ], q0 R. u
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,8 U, I' u, J9 x. |! e% x
                      FILE_SHARE_READ | FILE_SHARE_WRITE,' r$ u* q9 }2 D4 G2 U# o$ \
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);! B; i1 \& S$ ^6 K8 c
   if( hFile != INVALID_HANDLE_VALUE )
6 h, y7 m9 M! X" Z! Z6 O   {! |  B1 c. q$ H  v. u9 a: S- j/ O
      CloseHandle(hFile);
1 M  B1 A1 R% O( j5 r8 R# ]      return TRUE;3 O8 Q  w1 i5 s* n# Q. E
   }. {/ N: O: K9 z. Y  |4 j9 }3 W1 P" Q
   return FALSE;
! F3 q8 O4 u9 m. t}1 u- H( k4 ~2 R- h
  V& h* S! p6 w7 {0 u
Although this trick calls the CreateFileA function, don't even expect to be/ Z, ~  f/ ]( F8 l  r2 e  s
able to intercept it by installing a IFS hook: it will not work, no way!
) c6 f) d5 Q0 M; t+ ?3 S9 r9 V! u2 l) VIn fact, after the call to CreateFileA it will get through VWIN32 0x001F
+ P. f% W# O7 \) P' q9 s: hservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)1 M: u$ S& _/ ~% t7 J1 f0 P
and then browse the DDB list until it find the VxD and its DDB_Control_Proc+ Z' y+ p+ P1 u7 c
field.
& v9 b" _" w  X/ f7 b3 TIn fact, its purpose is not to load/unload VxDs but only to send a - z9 m/ j4 L9 h
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)7 X' T. R0 Z1 d6 `3 ~# A, @3 \
to the VxD Control_Dispatch proc (how the hell a shareware soft could try# m! k% c/ B1 ]* n3 e: Z
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
, B5 Y# B. {2 M3 AIf the VxD is loaded, it will always clear eax and the Carry flag to allow
0 E6 y% L! q/ W% jits handle to be opened and then, will be detected.# x7 a8 u% B3 e" ], N$ j
You can check that simply by hooking Winice.exe control proc entry point
, B) ], ~) |: v9 Owhile running MeltICE.+ O, y% V) `2 o# Z, _5 Z& v

: N! L0 Q- n4 p" ~1 P2 {1 p" \2 e" i; W6 Q
  00401067:  push      00402025    ; \\.\SICE% o) V( q9 p7 S; v6 N" j
  0040106C:  call      CreateFileA1 |# j- Q' p* ^% _2 L
  00401071:  cmp       eax,-001; y! I* a* Y: Z
  00401074:  je        00401091* S" g3 r- z- \  l1 G! x) Z/ f
( R3 ?+ k. ?/ t* i4 s4 `- n
1 K% \+ M, I; |
There could be hundreds of BPX you could use to detect this trick.
; `7 o0 |$ v, u9 o+ n; p-The most classical one is:
) g6 ]" b) `7 E( _  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
; F5 u# W1 {# X! j- p# H, s; l    *(esp-&gt;4+4)=='NTIC'
5 C; ?& f$ z7 N, ?$ f
, M3 j3 D4 R7 W- [2 p  T7 D-The most exotic ones (could be very slooooow :-(
$ W6 e  D1 [. n+ K   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
3 p; L+ s) Y8 Y. K     ;will break 3 times :-(+ g# u* T  U2 O, {# l+ U0 K' j
" o5 Q, |5 ~2 E" m/ G& B5 }
-or (a bit) faster: + @( ^  l# F' y
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
5 ~1 e- X- z+ Y8 ]1 o/ O/ Z3 E) A2 |& y% b
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  0 K. f" Y. r/ b4 G% U
     ;will break 3 times :-(
! R/ `+ g( i$ @+ u% d& B: I- d2 o$ b3 P8 c  V, e
-Much faster:
3 u# ~. y4 |% |- R+ o$ C   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV', f8 O0 R0 v7 [3 b) W9 A% O3 I

" ?$ }- [9 ?# D1 D, {) A8 cNote also that some programs (like AZPR3.00) use de old 16-bit _lopen+ i9 x7 W1 }5 U# w: C
function to do the same job:/ s9 ?5 N/ h4 I( z

9 |' i" D4 n0 E; m6 m   push    00                        ; OF_READ7 k. D; l6 j4 b/ {. T
   mov     eax,[00656634]            ; '\\.\SICE',0! l3 C6 N" L; K' N7 V* y+ d
   push    eax+ i0 e# X5 O# ]' B0 z+ X
   call    KERNEL32!_lopen
+ u* |3 ^# }, ^: B   inc     eax
- O2 [( o' H) B* V% Q& ]   jnz     00650589                  ; detected
( L: d( P2 b; `" V' U   push    00                        ; OF_READ6 b- R3 R' k  v# M9 R; n/ J' ]
   mov     eax,[00656638]            ; '\\.\SICE': o* F: J9 x; h$ r  K
   push    eax9 }9 Y4 v+ q% ?; [6 ?
   call    KERNEL32!_lopen* V$ A8 o% V6 g9 a; ^, K# |
   inc     eax
- v% {' k1 R( f   jz      006505ae                  ; not detected
! L& J5 J* ?" |" w2 W0 o3 L& p" U

+ F$ l; ~- @- S3 U4 `& b% `5 Q5 c__________________________________________________________________________0 I  {! x& S% N' x  E

5 R4 p3 e9 w8 w8 b* e6 x( X) _Method 12/ ~0 G& J) N3 F+ y
=========
. W! u. T" y) n2 {; y3 O1 w1 u$ @+ M9 \9 W' l9 @7 l9 a
This trick is similar to int41h/4fh Debugger installation check (code 05
' E& f9 w2 d3 @( C&amp; 06) but very limited because it's only available for Win95/98 (not NT)
: u. N) l' O* Yas it uses the VxDCall backdoor. This detection was found in Bleem Demo.
- Y! S6 ~3 J4 }. i3 G! W- o: ?6 {/ V. `4 s5 @
   push  0000004fh         ; function 4fh( _+ ?( `" p; B6 X% Z8 ~# b& n8 G
   push  002a002ah         ; high word specifies which VxD (VWIN32)
* s- @6 D2 r& V  E- K7 P2 }+ j                           ; low word specifies which service4 O. v* X% e8 m0 G
                             (VWIN32_Int41Dispatch)) F' A& _' V( L9 c/ a3 c
   call  Kernel32!ORD_001  ; VxdCall
) h! o# ^/ U+ y' E& G. @8 {, v   cmp   ax, 0f386h        ; magic number returned by system debuggers# B  Q- @. h+ b% H3 w, H! m) E% g
   jz    SoftICE_detected' e+ @, I0 V! K3 P! r

, U" T& [( \9 H5 m" K3 m0 L) P+ y9 uHere again, several ways to detect it:
! {2 H4 |* H3 B8 t
' G& U) [* r4 x- @    BPINT 41 if ax==4f" f$ U) J" S4 t7 y9 f

7 Z9 T" h" \% ?' o  ?    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one$ s, X) ~  B' j' {! T0 c% `

! k& j8 h/ f6 [8 T- D; c- B    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A1 t1 |/ A6 V# J, k4 |  O
+ N* \' L: ?3 ?- S4 B7 {4 W
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
+ l4 \: x6 A% W; n3 E1 j2 B. x; D8 |1 {" q& P( O1 U# c
__________________________________________________________________________
: \  X8 w2 ~+ m
, p- R* p; a6 J' h( g& EMethod 13/ O0 J6 v6 D: z7 r" y# Z
=========) S2 B7 b* C* k' E: p

: g2 v* y: g% C+ v+ g' I4 c( x$ c. kNot a real method of detection, but a good way to know if SoftICE is
2 ^: \) m, V' }* }installed on a computer and to locate its installation directory.
- e# }: h2 M0 i' x$ B* F+ i, kIt is used by few softs which access the following registry keys (usually #2) :# n, {5 i* f# \  I, B

$ O; v- Z' J/ C& q-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
% c% v9 g) m7 b2 W% j: P/ o" i\Uninstall\SoftICE
6 R) `) z7 @9 M4 ^7 l1 a, I6 r-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
& c* u% c) A) {6 ?( O-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion7 U# I) I) ~+ x
\App Paths\Loader32.Exe
& s: `' ~5 {, W7 @& z% a$ F- w8 W; \( p  ~

3 U& Y$ }" E* `+ t% {Note that some nasty apps could then erase all files from SoftICE directory0 c: r3 n; c: e5 v1 K( s! D
(I faced that once :-(3 d0 p% n' f4 [' P% O9 l( q
- t; F- b! m$ U& T& @1 h. N
Useful breakpoint to detect it:
4 k/ v1 b9 P/ Y
+ _" R% T! A3 A9 }% Y2 v% n+ m9 k     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
3 D2 j3 B1 P- h' U& `# C6 n! N5 H# j1 q7 ]: m) B$ _* D
__________________________________________________________________________$ O- ^' m8 F6 V/ V' W7 D! j
3 L  ]; t4 I7 A2 U
$ B& a; A! b- ?$ V  X- z
Method 14 ' b+ B. s  u' l1 \, w
=========
7 E+ \9 L; L' q! O1 a# X& D( }% ]  f9 V7 C! |9 P* {
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
# L: {4 t9 \6 g$ w7 U" q( E1 nis to determines whether a debugger is running on your system (ring0 only).  W0 F  Y$ V6 @) Q2 D) g/ M! d
3 c3 `4 F& S  I# @
   VMMCall Test_Debug_Installed
7 L: |$ o1 e0 L6 s   je      not_installed
" ?; z( B; d4 |+ ]( t: \
/ r3 q6 |5 W$ ~" ~9 x  r6 QThis service just checks a flag.: {! Q& V/ f! ^! N: N- x
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部