About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>% w. S* `1 }$ @! k8 x
<TBODY>! p  K+ y( V. Z6 M% Y8 F; {
<TR>: \- ?% x4 u9 v8 m2 d1 _9 v1 s5 b
<TD><PRE>Method 01 4 z) L: X% ~. O$ E! w
=========  D6 \9 ?4 u6 v. N" M3 J
1 N. _6 _6 i7 U* K9 J
This method of detection of SoftICE (as well as the following one) is
5 \% A* I, `% W9 f+ iused by the majority of packers/encryptors found on Internet.5 x1 c  i- Y4 H0 o6 e- \. j
It seeks the signature of BoundsChecker in SoftICE( ]; T$ \3 G$ Z( b
) ~5 u( h) `" j
    mov     ebp, 04243484Bh        ; 'BCHK'
, ]9 ?( W( d7 y4 o1 `5 O    mov     ax, 04h+ R) I7 U8 P3 d1 i
    int     3      
4 n. S  _, o- c6 ?5 h    cmp     al,45 R1 l9 H1 V7 E0 V4 `% T
    jnz     SoftICE_Detected
% R( X+ \3 x6 t3 x- O6 U
/ s: X0 v" ]. M___________________________________________________________________________
& j& p+ H9 z- ~. J' ^7 p; w+ n) n7 i
Method 02" L. T: L* \! V2 N. J. p! v8 w- B
=========
+ d; {$ A2 H) z6 A! {$ }) t% o) U) |
Still a method very much used (perhaps the most frequent one).  It is used% W8 ~$ [( i3 W. j3 l
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
8 K, Z) Y7 c1 @: j: a( W# A4 hor execute SoftICE commands...
2 L3 v0 x" W/ f- h2 bIt is also used to crash SoftICE and to force it to execute any commands, A5 m+ U! W( c
(HBOOT...) :-((  - P/ I: E; M) ?3 a- D9 n0 w

" s, V+ T; D% _Here is a quick description:1 r# N+ O& Y5 d- G. I, s6 ^
-AX = 0910h   (Display string in SIce windows)0 X. `" Q" M: }! p
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)) ~9 r$ w' {8 g
-AX = 0912h   (Get breakpoint infos)5 A, [# Q4 V0 B- u2 l4 k  r+ T
-AX = 0913h   (Set Sice breakpoints)* [( q  ^( x) l5 _+ l8 L
-AX = 0914h   (Remove SIce breakoints)3 X; S! I4 F7 {' G" @

: A2 d( S: _2 m# `9 f3 @3 wEach time you'll meet this trick, you'll see:. c7 c; S# m" f* z. ]
-SI = 4647h
! U& {2 t) w6 J/ Q7 U4 S( G7 f-DI = 4A4Dh
$ y( y7 R6 S4 ]) JWhich are the 'magic values' used by SoftIce.
/ ~, }4 X- d4 M5 y/ n2 u& IFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
5 F8 n7 U% O( A8 u% ^3 A9 f% m# p2 B' O' R" C; \& z$ }, v
Here is one example from the file "Haspinst.exe" which is the dongle HASP' c" d5 J) F3 \6 O
Envelope utility use to protect DOS applications:
8 G' s7 p4 V! }2 X/ q
  n6 p- j; X$ r, {
2 Q* E- L( y) Q" q8 Z& H3 ?4C19:0095   MOV    AX,0911  ; execute command.$ y! V& ?& D+ J: i+ m( ~) j
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
) i4 C$ ?& p8 N0 m0 G) [5 t4C19:009A   MOV    SI,4647  ; 1st magic value.7 B/ \+ x( \/ h, j3 w& r1 W
4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
* `: U0 @. o: ]0 k8 B" V9 ]' z4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)5 m" V; r& S$ B# P( ?0 M, s
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
" K/ C, `) {5 ?2 W0 @4C19:00A4   INC    CX
4 H8 H. M! m5 u, u4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute' Y, V8 F; S2 q2 g
4C19:00A8   JB     0095     ; 6 different commands.* v  N- F: ^, }9 r0 e
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.$ ?: ~7 s/ ^  `+ @4 b7 ]
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)7 A/ x7 F9 I7 _' s5 ^

" S! o* v( _0 M0 r) oThe program will execute 6 different SIce commands located at ds:dx, which
6 ~" @2 @& t1 A  C* `+ G. oare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
& K- m7 ~! [1 e* Q- Y5 z
& _3 o* K8 B, i. _- K5 e# `  `+ s; r9 U* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.1 N8 S! b, @3 d# v8 K# O% {2 n
___________________________________________________________________________
% J4 u: ~: X) b* y; X3 [4 T% L/ g# J
6 D, H$ P; D3 Q, Y* k8 d9 N& V' k4 l
Method 038 I, }! y' y) R# B
=========2 R! c/ V  l2 R4 B  o/ Z1 X4 ~
% J  @9 y  x& g
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h) R& X: P0 v! g5 \
(API Get entry point)
4 p9 y: A* G* J3 F        
+ A- ]# t$ }3 }3 O7 K/ g* S# o) U! l; T, k/ c+ ?4 H5 H% U
    xor     di,di
$ h9 [2 E5 J3 i8 ]. z    mov     es,di
0 y  J5 b' N% B    mov     ax, 1684h      
0 u$ a3 E, @( m2 b' ?+ P6 A0 H$ B    mov     bx, 0202h       ; VxD ID of winice# ]' [3 J/ o& A  ]4 r% I
    int     2Fh
8 ^6 R, ^  b! S- m  V, }  s) @8 \" V    mov     ax, es          ; ES:DI -&gt; VxD API entry point
7 ~: ]% G* @0 e: I% i    add     ax, di
8 ]5 _$ K# N# e3 j+ k1 X    test    ax,ax* \& C9 ^$ b$ {# D# Y# H
    jnz     SoftICE_Detected* G; X/ O, D6 k6 h

# `( u7 |& G7 M' h% Z# j+ o___________________________________________________________________________5 j8 p% B& S. r9 w) `0 a- u
( E$ l$ f! p4 Q' Q3 e
Method 04, O' ~# J$ S9 l: @& d1 C
=========
" a/ r4 ?2 b9 \9 r
5 I3 D4 K; n0 CMethod identical to the preceding one except that it seeks the ID of SoftICE
1 Z& q3 S0 d; n' T8 _% I2 A0 G, dGFX VxD.
2 j& N8 P) M0 Z( H& P
8 O" H0 M) O; Y0 D! z7 a    xor     di,di( J4 \. r0 X( n9 G  S* U
    mov     es,di: \. R. }+ W) z% y$ Y/ M
    mov     ax, 1684h       / Q- r8 j, _0 b, r7 ?+ q. q
    mov     bx, 7a5Fh       ; VxD ID of SIWVID. r# D! p- _" R* e: ~" w0 [- N
    int     2fh
' x" e5 F7 @. Y1 Z  A& A* L    mov     ax, es          ; ES:DI -&gt; VxD API entry point# ^& s- @! Y8 d- [3 w
    add     ax, di4 A3 E7 H6 h$ \4 S1 H% {& `
    test    ax,ax9 n# S; s9 D# m' Z5 n) S: y
    jnz     SoftICE_Detected
% p0 Y. @; h; t9 r1 E8 u9 u$ U3 S" c( G4 Y0 o  L3 w/ t& B8 r5 e
__________________________________________________________________________
& n5 d) {3 Z! w1 E0 C% l9 W% b3 K' m/ `) L
$ _+ ?8 u! y  g$ b! h: T
Method 05+ M* l, N/ ^  g& A$ }
=========2 p3 R- l9 {6 p1 B
, n8 A2 n2 h5 z, @" h9 r7 D; f
Method seeking the 'magic number' 0F386h returned (in ax) by all system
' H' _' p9 M4 D8 Z. N/ ^debugger. It calls the int 41h, function 4Fh.
; ^7 _; N5 _$ D& }+ d& E1 gThere are several alternatives.  
$ [& n" S% [8 c. O' W4 t  \
4 T; R& G- f# Y  P: n- _The following one is the simplest:! R& M5 T, k1 x) W
! K5 J( e7 i7 C" _+ L/ M
    mov     ax,4fh. D; \* ^* y; V2 h+ u
    int     41h3 v3 i" x' }  Y& [
    cmp     ax, 0F386! Q! f' c- j2 G: p4 s1 K
    jz      SoftICE_detected, D& w8 c3 B/ v8 m! z5 z
1 V( U# p( |6 }) l

& J9 z& @3 k+ z! Z; `1 h1 _Next method as well as the following one are 2 examples from Stone's
2 @  W# F# P7 o"stn-wid.zip" (www.cracking.net):
' L0 i5 z2 v8 M  X) v4 r. N. s1 ^+ I- v8 a
    mov     bx, cs
/ d2 E6 u$ s+ c0 _( e( m# z    lea     dx, int41handler2" o9 S- F/ x2 `. d
    xchg    dx, es:[41h*4]( E- Y  I0 n; Y
    xchg    bx, es:[41h*4+2]
4 Y& `  a, F  Q4 L, \    mov     ax,4fh
" ~6 Q7 e6 w7 k# B9 ?* _0 t& L" o" X    int     41h2 }; S7 z% d* A! C
    xchg    dx, es:[41h*4]
& |0 y) n! E8 S% S3 x4 K    xchg    bx, es:[41h*4+2]* |" F4 T4 e0 ^3 f& j
    cmp     ax, 0f386h1 [+ |+ ?1 I" K" e
    jz      SoftICE_detected& @" Q6 M, t$ s0 h2 r
# C$ i2 I% T+ A: R9 t7 y- G0 X
int41handler2 PROC) h& v$ k! K" x3 U7 o
    iret- Z- v' H3 ^, s! r7 P9 [
int41handler2 ENDP) H4 ~0 ?& g6 O1 n+ L: y

6 ]$ ~+ h. g  }* G+ }" S5 [8 h. o0 c. [( g; G/ k- U0 k
_________________________________________________________________________0 \; W4 T+ U) T; p; B4 d* h1 _. c) x
' i) l6 ^/ ]+ x1 c' w

( @4 z  ~5 ?2 n  M3 LMethod 06
& F1 |" y2 f+ V! G1 a: u# i0 [=========
- H7 E; M$ V# n: \' H8 |
* K# e" A/ t" _) f" x& U6 i3 s8 d) O  [3 U7 i; |9 k4 ~
2nd method similar to the preceding one but more difficult to detect:+ d4 g$ d9 O9 ?/ T, ~  c) W
0 R6 ?, P3 D& Z, u# r
9 O" O0 P! ?' H. u
int41handler PROC! e* d3 n5 f1 k8 c* Z
    mov     cl,al5 Z" A: P- L5 ]
    iret+ R3 K8 U- _# a, i: h! s& q
int41handler ENDP
: |, e& Q+ w! ~7 X0 e1 W/ G  \) g
0 W( D8 H; {" C6 C+ U* p6 ]+ K" U2 B& M+ H+ n$ ]6 U
    xor     ax,ax3 J. t  K5 V! ?' K
    mov     es,ax- e* y# ?$ U& W& Z
    mov     bx, cs
% }) d& K: U. V1 g  |4 `- J    lea     dx, int41handler0 n. X; x# D- p7 K
    xchg    dx, es:[41h*4]
% _  R8 P- r4 Q5 N    xchg    bx, es:[41h*4+2]
- s, ^$ k' E9 `. I/ @( X    in      al, 40h
- I! M* S3 D4 n    xor     cx,cx7 Z. s1 S4 l/ B) A& y0 Y
    int     41h
) Z( N1 g6 e) J% [* L    xchg    dx, es:[41h*4]
4 r9 t) ?' R0 ]9 \, G5 U. c    xchg    bx, es:[41h*4+2]
6 x  x% R& z2 Z    cmp     cl,al! l. r7 x4 y* \5 Q0 P- k
    jnz     SoftICE_detected
, _# g! F+ @; b8 ?" P  n2 r1 X# i% R" e6 l5 P1 ~- ~
_________________________________________________________________________+ k. Q' L8 g4 K; V' Q
; t  y( s2 _8 u" l2 r+ s
Method 070 ]  ~& k7 L( N" Q1 y* A1 T! x
=========
( t4 @  g) _/ h; c$ K7 L& D6 ~
: F/ l8 ?1 a8 A" p: _. pMethod of detection of the WinICE handler in the int68h (V86)$ P3 y& v* P9 a0 ?, N
/ w2 w# i2 J# [. T! L8 V
    mov     ah,43h
% _  w$ u3 [2 M- {( V- U    int     68h
2 U# a( N2 L( b0 F1 N2 V8 i/ |    cmp     ax,0F386h
& Q+ K3 i% d' s  k$ P3 ?: j    jz      SoftICE_Detected
- E  e) S; M9 `. g# ]  P3 d6 c* x% k4 C2 J
' Y' {5 [. {3 n3 G0 @6 {2 M- D
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
" g3 R4 ~" _, d4 _  f0 L   app like this:
+ c. X5 S, X: n: \, U' \0 |6 t/ {+ g2 J; O1 C1 D4 U& {) d4 e# S! S
   BPX exec_int if ax==689 A8 ^" b' ]" ?; ^. @# ^& h
   (function called is located at byte ptr [ebp+1Dh] and client eip is; e) i4 C+ k1 H* E1 ~1 k% d
   located at [ebp+48h] for 32Bit apps)
/ @  O' Q. V9 h5 q2 M__________________________________________________________________________
1 _) R: Q1 s3 l2 d) K8 \1 I0 M7 U% e8 Y% X+ r- g. m) O

' G! t9 f. h6 K) oMethod 08
# ?  K: j+ i- ^' o=========; w+ N' y/ o9 B4 B
! s. q3 L7 j) @& x
It is not a method of detection of SoftICE but a possibility to crash the+ ~$ w* r- t* ?# I9 J
system by intercepting int 01h and int 03h and redirecting them to another
5 g* g8 X% N7 C3 B' eroutine.
+ c7 P* @4 h4 o' z" Q) UIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points* Y% [+ l! a3 E5 p
to the new routine to execute (hangs computer...)
% m0 B$ O% t6 D% q# u/ K
% J: d8 {) Z+ p    mov     ah, 25h3 B; g2 K  z9 D; {0 |0 Q
    mov     al, Int_Number (01h or 03h)  E) o& I! E( ]" _* a$ s' O) V
    mov     dx, offset New_Int_Routine
  _, `1 g9 n0 i0 s' V. Z    int     21h
- Y$ f  t) J, i# K# g6 E4 H3 Q% x* O9 ^( n, |/ M# L  c
__________________________________________________________________________6 P1 I8 M/ I* B/ R

* w' _& u% p/ ^- A! eMethod 09
) v: o$ S1 V8 @+ j7 z1 I=========& P$ w) S: I9 i1 u& l
4 p4 h* b4 {, E  U6 m4 R
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
+ Q2 Q7 M& [& \) J8 S9 u( eperformed in ring0 (VxD or a ring3 app using the VxdCall).
* P0 a' H# n! r  _( IThe Get_DDB service is used to determine whether or not a VxD is installed3 l* G4 m2 B- j9 Y  u8 ?: v9 U' T
for the specified device and returns a Device Description Block (in ecx) for
  d- W( @8 e% ~; ?& D! O9 \; Vthat device if it is installed.
2 m2 o: H- S; R8 P8 i/ E, d
6 v8 d  |2 \" s! }  T% i( h   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID! b/ d. \7 F; @  `
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
+ T3 }1 U7 J5 q  J! D1 W   VMMCall Get_DDB
) y: A1 l) {) a   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed' q: A: \0 O" d% z
% ~" n  D' w, o+ w, I" F# ^# e' k3 t
Note as well that you can easily detect this method with SoftICE:) M1 r- c. a+ s0 H# D
   bpx Get_DDB if ax==0202 || ax==7a5fh
+ Y8 d* q6 W" l( s; i" c1 J2 `1 ]- Q% y+ [' i% _4 I
__________________________________________________________________________2 x- {: S- L  U# r9 F

9 X6 O8 l% N. Q; _( K1 L0 D8 `- f1 MMethod 10
" n  r: M8 \/ ~4 N0 C( I( D! [=========1 V+ d1 Q( z) Z- n
% O1 _% h$ h7 ]6 u2 L
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
, E5 A, {' Y1 o, x. ?8 E4 P  SoftICE while the option is enable!!
: ^9 ?0 Q" V+ p% r0 u# Y
, b9 m0 G1 p0 ~$ zThis trick is very efficient:# h- L' b4 J% w/ T+ W
by checking the Debug Registers, you can detect if SoftICE is loaded6 `' ]: {% p; x9 I: o: z+ `2 }
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
% h3 b% F# F. u+ Z  D; gthere are some memory breakpoints set (dr0 to dr3) simply by reading their
9 Q, _/ D5 U9 G& S; Jvalue (in ring0 only). Values can be manipulated and or changed as well
) c1 Z) x2 m# m9 g/ J(clearing BPMs for instance)
( B, k/ Z  w$ G6 h  C
# G; y4 ^# r$ r1 o9 E, O, o& T2 P- L__________________________________________________________________________! X$ u! F6 i2 h4 R. ?( |- ?# O
8 C; ~$ R4 ~! y( J/ w! }- B
Method 11
7 P: J, h4 g. u=========7 w; `3 e. S. T1 \4 Q" {( z- Q2 r
$ y: G7 E/ @) R" N) R& i, g# M
This method is most known as 'MeltICE' because it has been freely distributed3 G5 f! @: j( D  h
via www.winfiles.com. However it was first used by NuMega people to allow
3 q! m  P* P1 R1 a1 `# Y: zSymbol Loader to check if SoftICE was active or not (the code is located
5 o3 ^- t  W, Hinside nmtrans.dll).1 B" F; P3 a7 b2 M2 c
' a& ]' d1 g: Y! c
The way it works is very simple:
& b, A' t. |5 n" |It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for0 _& \, _7 S' q
WinNT) with the CreateFileA API.' j/ V; f  e8 b: J) ~+ L
  R, T- V. W; V( N! J9 z
Here is a sample (checking for 'SICE'):5 y% H; D4 w4 l0 U9 v' [

- u4 n+ }2 @0 n. ]' l- ABOOL IsSoftIce95Loaded(): h3 O7 }- C2 _$ M
{$ n% C! _% c6 T# d% e6 n* ^5 Z" Y- ?
   HANDLE hFile;  - n) Q9 f/ _) G- l8 O
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,* r8 I9 X. x$ b% j4 n" R. r, L
                      FILE_SHARE_READ | FILE_SHARE_WRITE,
6 Q+ U) K/ u6 @/ y4 F8 w4 |0 B/ Q                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);) i+ t, M/ F3 X- ]6 Y
   if( hFile != INVALID_HANDLE_VALUE )
+ z# r/ |0 W$ I( A/ e% I$ ^( o   {* i. W7 @8 B/ N: J# _* w+ @. p7 o) W5 w
      CloseHandle(hFile);
' F/ V% m; h& {" ]4 ^- c0 }7 c      return TRUE;8 O8 c* m) _; u$ i) F  T* O! B
   }
: S( f$ ?1 h7 z6 z   return FALSE;
! \6 W* m- l; w}
0 z8 \% Q( q5 [" o. H' c
/ R: y7 V9 Q* v0 H6 E# mAlthough this trick calls the CreateFileA function, don't even expect to be4 |3 \( x, W4 Y( z" [
able to intercept it by installing a IFS hook: it will not work, no way!/ D( D* |" L+ t
In fact, after the call to CreateFileA it will get through VWIN32 0x001F2 Z! y' ^* R& T; }. j
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
4 n' A. d- p" w2 n% @  l  vand then browse the DDB list until it find the VxD and its DDB_Control_Proc/ v6 E- I+ C( C
field.
6 u, e/ y( H$ @0 b. I) p) aIn fact, its purpose is not to load/unload VxDs but only to send a 7 M, ]' B0 E& A
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE). A9 p. v% r  A4 I
to the VxD Control_Dispatch proc (how the hell a shareware soft could try. W. F6 b$ z" G6 k1 _/ f: L
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
* t5 ?8 V9 @4 K4 S% h9 pIf the VxD is loaded, it will always clear eax and the Carry flag to allow
8 q; g, ?7 a1 ]/ e5 G5 `, N8 j3 |its handle to be opened and then, will be detected.
* z! q1 P: D) ?3 _% gYou can check that simply by hooking Winice.exe control proc entry point- R/ b3 H9 ^" h. I  v1 b
while running MeltICE.% \* d% S: I- u

; Q  P3 ]2 E" ^8 N! }9 {9 q' u( m# p- H, [4 \) B7 o9 |6 A+ g+ [
  00401067:  push      00402025    ; \\.\SICE" ^5 P0 R" F0 w/ q6 {% G: a6 I
  0040106C:  call      CreateFileA; a- O+ ^2 P" C6 y
  00401071:  cmp       eax,-001
' h5 {5 \' ?! Q. ?  00401074:  je        00401091
# t! z8 j7 n5 q" R% x1 W$ @
$ m+ T/ Z0 u, w$ r7 L, I6 I; {5 U+ `4 h% S6 N7 J  p! l
There could be hundreds of BPX you could use to detect this trick., J- d% S, N3 F+ H6 d
-The most classical one is:
# C! o7 U' p( B! O  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
: U1 t; f' G- X5 z    *(esp-&gt;4+4)=='NTIC'
& H3 O2 F  r2 B0 t, `3 [+ D* K  I) ~+ q
-The most exotic ones (could be very slooooow :-(
; U/ n7 B2 F2 M0 H  G   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  3 g6 S3 K, S. U" D$ H
     ;will break 3 times :-(% l' Y- g' l0 L- j4 \7 k+ N, J1 J
$ H3 c: a6 e; w+ G0 o2 G. p
-or (a bit) faster:
$ t' f  H  o! j; P9 B0 c   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')8 P+ i) Y2 h) f. Z% Z! ?; U$ D2 {+ i
. y# W  F' ]" A$ u& u+ `
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'    C0 ?; l0 \/ B
     ;will break 3 times :-(* J8 X0 K8 f9 R8 E1 }/ z1 {; |% q( w

' }, L4 ]7 j# e: W5 y$ ~, V8 |& g-Much faster:
  P+ C5 J" g' U/ ?9 B: f& a/ p: E( N   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV': O( e" ^. V' V. n! @

- C; j. Y0 Q* lNote also that some programs (like AZPR3.00) use de old 16-bit _lopen' q7 \* q! d% }- z8 Y8 O& v# B; T6 M6 f
function to do the same job:
  e, f1 A+ I9 y9 S0 F& z" `) X" `5 l& h& Q3 H3 P. k
   push    00                        ; OF_READ
9 @- F7 q4 k3 u1 d' r( @   mov     eax,[00656634]            ; '\\.\SICE',02 R/ @6 `# v4 X7 w7 |- E
   push    eax# h3 f$ W% H" t8 s$ b  w: X, w
   call    KERNEL32!_lopen
$ G: z# }& {% w5 I4 p   inc     eax
! Y7 p3 C+ F% K  x5 z   jnz     00650589                  ; detected3 f  p5 @. T' R1 u. F: f
   push    00                        ; OF_READ1 O0 x* ~0 s* x  k
   mov     eax,[00656638]            ; '\\.\SICE'
9 C1 ~- e  T0 L( q   push    eax  |' y$ k  B/ ]- t
   call    KERNEL32!_lopen
! K8 B) b. x! W& f+ O) `/ f: J   inc     eax
+ w  ~  O9 C: ^  Z   jz      006505ae                  ; not detected, F* _; Z! L, d7 U
* I. F. u2 }/ @% d' R% d

3 N' h6 Y) ~0 r0 L* j' q__________________________________________________________________________
! E2 Z; ^) C( Q0 s" g. O. S2 q, a4 ?; q7 s* E9 Y' Z8 _. ?& t
Method 12' k( m3 f: u9 e. q
=========/ d0 h4 T2 n" z9 q; ^
0 {" w. Y& l4 j% b/ o$ U! l2 [2 n
This trick is similar to int41h/4fh Debugger installation check (code 05
) C7 }9 r1 g! C+ K3 f# x&amp; 06) but very limited because it's only available for Win95/98 (not NT)
: k7 @1 d+ a: L! was it uses the VxDCall backdoor. This detection was found in Bleem Demo.
! w' r* x# P# g: ?# m! d8 D! q( h
4 U  s! u* h2 t; E! G   push  0000004fh         ; function 4fh
/ l3 v+ g$ C  `" d1 T4 L   push  002a002ah         ; high word specifies which VxD (VWIN32)
, \. O0 o) X  T+ ~: W                           ; low word specifies which service
; Y8 F& Y# Q+ b. [0 R  J4 z                             (VWIN32_Int41Dispatch)
+ _) A1 [) a  u) N3 w# S( i1 Y0 d   call  Kernel32!ORD_001  ; VxdCall$ [$ l5 M' b- Y3 h& J
   cmp   ax, 0f386h        ; magic number returned by system debuggers
! Z; q+ z: T4 j2 C   jz    SoftICE_detected* r/ m# i/ O  ^/ n$ n: r3 A. `8 l

7 n' H7 y9 X! s  i& e2 ~. @  |Here again, several ways to detect it:& y+ @) i; E. b5 {9 P

6 k) v- x/ d) L( Q! Q' o, M    BPINT 41 if ax==4f% X1 O4 u0 L4 B: N  P5 b$ R8 w

& d4 v3 N; \' w5 \) _    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
5 H3 k5 }4 q+ x4 D8 k8 u4 J7 p! R. `' G3 C6 X
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A) h: A  I; j. ?
& H( z( g8 E! ?0 O; u$ t* X
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!+ W, [" z* V; I- [, y! c

! k% N+ i0 G/ M8 [* m7 Q$ J4 z__________________________________________________________________________
6 J) s# D/ V7 S& V4 Y2 j: J" `1 A# I7 x) D' ?
Method 13
2 |! E: z* J1 [1 ]. K- N- K! a=========  G' b4 @  i! c5 Y, H

& v6 `- R( d5 w( ]Not a real method of detection, but a good way to know if SoftICE is- }5 K" m' C8 ?. a* w3 B
installed on a computer and to locate its installation directory.2 H( s2 b5 v# n9 O6 i- q% @
It is used by few softs which access the following registry keys (usually #2) :
1 |1 [9 M8 m+ o
' K' o9 `" L# h( w-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion2 v( E5 u7 E+ D0 N, _
\Uninstall\SoftICE9 A8 h. c& d  m
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
- S! u6 [0 z8 w) T-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
& O$ E5 l1 q1 c; m3 m) ~! S; {5 v\App Paths\Loader32.Exe: U- S- E) g( X# i: n! E1 r5 D' B4 V

8 I! i. q0 G) A1 b% O- n* [9 c/ h* Q" _0 Z
Note that some nasty apps could then erase all files from SoftICE directory
4 D( w3 p$ E) v4 M5 S& ](I faced that once :-(
5 A$ @; t) B! s+ h2 i# D- x: d4 Z2 R" L
0 \8 ?  e& O# Q* J  m+ G  x7 DUseful breakpoint to detect it:) l1 {) h% h( W3 d% H+ M# s4 k$ {
+ B& _' w& G7 q4 \* A- |
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'2 F' B  A7 U% q* Z! ?# p! i  ]

4 o/ [* j2 q8 b  A__________________________________________________________________________3 Z$ E) j3 e) n/ f  o
' B5 ], ?! D% R* g" m) B9 R8 q

) |8 G) m, T4 e! S2 R2 yMethod 14
  v+ v% u  b% F* k=========
* V" f" v) t) E0 Z. H# H! w' |% E: s$ J. l
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose1 [4 F8 g+ i, ^8 I
is to determines whether a debugger is running on your system (ring0 only).5 F9 X) U9 d8 p8 F" T) U/ F
4 R5 |# ~2 j6 e
   VMMCall Test_Debug_Installed- s  H! _9 t" {: h9 h, M; c9 m
   je      not_installed
; x3 l* c4 _3 X: U/ E4 s+ ]+ O2 b
This service just checks a flag.0 f, w6 `9 o1 b5 T& t/ y
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部