About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>2 G, t4 r3 Q; |. D  ^7 j5 j, Y
<TBODY>6 J$ v) @8 H6 \4 S' W8 Y
<TR>- I6 R6 x( A, r3 ^" j; l7 k# M
<TD><PRE>Method 01 + d' P  `. I5 ], l- p
=========3 |+ T2 t' s& R

- B1 D. F: Z4 KThis method of detection of SoftICE (as well as the following one) is5 v) u# L9 w( J2 R( O
used by the majority of packers/encryptors found on Internet." b/ k! c! [$ H. Q1 o5 h
It seeks the signature of BoundsChecker in SoftICE0 ]1 g: T% ?, g! v! c! A5 \3 T% c+ ?
! u5 X# k8 `/ ]! @5 H
    mov     ebp, 04243484Bh        ; 'BCHK'# T9 I6 f7 f+ O* G0 N& I
    mov     ax, 04h
# v$ y) N4 L* M+ K% k1 Y8 B- t5 M    int     3       2 @* d  V& J" z% L
    cmp     al,4' Y% \% N: c) g8 B
    jnz     SoftICE_Detected) ]" P  R& M2 M2 F( x: e

0 M* ]9 j0 g4 p3 Z1 c# F3 G# M. o+ h6 ____________________________________________________________________________
- ]# N' o* @, M+ @+ ?
8 K2 K8 n) u5 ]Method 024 y2 |1 o9 R2 j! p3 ^' r- X
=========& `! d+ q/ ]( Z& B2 D3 s4 a" g
/ E  u% w+ Z. E: [. A7 Z
Still a method very much used (perhaps the most frequent one).  It is used
7 D7 U: [  ?) F! M, ^5 a+ xto get SoftICE 'Back Door commands' which gives infos on Breakpoints,* a. C0 C8 c8 z2 n; S
or execute SoftICE commands..." [* g2 k6 L2 L# J9 n+ D1 p
It is also used to crash SoftICE and to force it to execute any commands" r- O4 @% A$ |  n' ^, s
(HBOOT...) :-((  5 y0 B5 i3 Z2 T% V: B/ {
8 U9 Z" g; m1 N
Here is a quick description:
4 A) m8 u- V3 v7 d5 c/ c-AX = 0910h   (Display string in SIce windows)
* ~+ w1 A+ g$ I6 U) F* n-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
$ v" B& l/ C2 \# D-AX = 0912h   (Get breakpoint infos)/ T' H5 g" U9 z3 |8 `
-AX = 0913h   (Set Sice breakpoints)
1 v0 `# b1 q' q1 Y-AX = 0914h   (Remove SIce breakoints)
+ q7 ^' _& Q0 H! a. W. x7 ^$ M4 y/ ?. o
Each time you'll meet this trick, you'll see:! U8 v9 E1 x8 b# o% z
-SI = 4647h7 M! `" g5 C9 c% y
-DI = 4A4Dh1 {3 l( K- r% r/ N) ~
Which are the 'magic values' used by SoftIce.. g1 r3 \0 W& E! X% z
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
" {, R7 e1 E  o3 o3 O% ?' J. x7 i: q; }8 S$ w: O$ W% L
Here is one example from the file "Haspinst.exe" which is the dongle HASP$ a6 e9 n, W, W7 [# b7 A8 m
Envelope utility use to protect DOS applications:5 x$ `1 i/ X0 G3 c+ \5 w  Z
8 T7 P* f' h1 Z' ^3 \- u" z
, ~2 U# }/ m; @4 N1 v2 j0 c
4C19:0095   MOV    AX,0911  ; execute command.
7 _! I3 g; i1 Z4 v- j4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).. S5 i* x5 D% x
4C19:009A   MOV    SI,4647  ; 1st magic value.
" ~/ V& v/ _+ k2 j; f. D6 j4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
* c  p+ J! L! i. x4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
6 R- x# K; o: g0 D7 k" }) \4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute$ q1 F  F3 P$ D
4C19:00A4   INC    CX/ Y/ ?  U+ M' b  }& V7 ^
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
5 c: b# @- J5 j! v4C19:00A8   JB     0095     ; 6 different commands.
1 K) |; L! z  a$ X- k* t5 `4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
+ M* ?  r" x$ G, Q4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
/ k* x) p( X4 y1 P, ]* Z4 t! |$ r7 l3 `9 ^9 B8 I2 S/ m
The program will execute 6 different SIce commands located at ds:dx, which
/ M3 c  }: U& s. V; Vare: LDT, IDT, GDT, TSS, RS, and ...HBOOT./ s- V7 P0 E. r: }4 h* \2 C

- S% e! b" B" Q/ j) x* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.  H% V! K+ ^( ]) ?2 q
___________________________________________________________________________
( F* ~' s6 @0 @
# ]) _& U" l, y' l+ T: x
, }4 N4 }" {# J  d3 `% HMethod 03
- J% t. J" a" O! s=========
. j! M4 D; v3 K) a0 t+ E( c" i% Y1 c
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h) g+ |) ~( o4 o# P2 K
(API Get entry point)5 P6 G  P: N8 ~
        
( W& N0 u, U* F+ S* ]2 S" ^1 l: Q2 Y; W) {" C+ d3 R
    xor     di,di
* ?9 d8 P, |8 i5 J& K( t3 y& z    mov     es,di
+ |2 t! x. g+ j( z2 h    mov     ax, 1684h       ) i9 i8 r* o4 w' k" i% X6 r
    mov     bx, 0202h       ; VxD ID of winice- q% ~, \/ G0 p6 }! A- M" y
    int     2Fh
, {7 ?9 c' q) K. _" X    mov     ax, es          ; ES:DI -&gt; VxD API entry point
8 R* V1 p0 J$ n    add     ax, di9 x, U2 ~: I- a# ]
    test    ax,ax
3 d) o8 g( j' q- _    jnz     SoftICE_Detected& |" M8 N& f# P9 f
: x( u  v3 W# \7 n1 m
___________________________________________________________________________
8 {  M8 o  a- L, P" B  U: E/ t+ _" X* X9 o" v* N
Method 04
3 a# y' [$ s% u& ]=========
5 ^5 ^, F) y& [# n5 A$ m9 E& A! g2 p- u
Method identical to the preceding one except that it seeks the ID of SoftICE
( \! E( m  Q, A9 G( @8 {% y; BGFX VxD.
# K0 |# L: D# `; h  s# I* [' L- ?3 {5 [7 z$ q5 A( f
    xor     di,di
7 k$ E, I- e3 u) B    mov     es,di
% W$ M/ [& J' H! p! M    mov     ax, 1684h      
# v/ M0 y8 }' Z6 B    mov     bx, 7a5Fh       ; VxD ID of SIWVID
$ O: l, ]" m% j9 _/ K; U    int     2fh: j& |. E  r5 J' Y8 @, N
    mov     ax, es          ; ES:DI -&gt; VxD API entry point0 a7 g5 W* Q" Q- k
    add     ax, di
6 P4 p' E- a, s9 U6 H    test    ax,ax! b' M0 T. U/ Y! ?# L  u1 B
    jnz     SoftICE_Detected
5 w: r! V( [9 K" N4 M* x# \
  H% `5 s5 v& {, x__________________________________________________________________________! h# F/ I  X8 o' [" i  O8 G
, W- O4 |2 E8 G6 v* ?' H: ^0 S
/ T; j& Q- F: q
Method 05
1 ?) f; o! {. K  |0 M7 `, _=========
0 d6 l9 Q3 s" ]7 y! L( V, a  }: r$ O$ R. R. J
Method seeking the 'magic number' 0F386h returned (in ax) by all system
2 c) f+ D+ T  o! C! fdebugger. It calls the int 41h, function 4Fh." T8 z9 ~7 ]/ b' s" a! j5 u
There are several alternatives.  
6 `5 a& }# s4 d. o! @7 f
* T5 j$ y9 Y0 AThe following one is the simplest:
* _" Z) s( f' S; B) }: w1 t
  E7 o8 Y. r7 o- Q( W, s+ i    mov     ax,4fh
8 N: m. j  G% L3 \2 Y5 M6 O1 u    int     41h3 o1 n' e* x4 m- A( `
    cmp     ax, 0F386
* n" Q6 w. ]( V% z0 L    jz      SoftICE_detected# n# W$ Z/ b/ M1 p5 q2 `
6 r. C/ Y' g/ N4 p

$ d6 @! V) f2 G- e. iNext method as well as the following one are 2 examples from Stone's
! C/ L+ w3 {+ @0 M" |1 t"stn-wid.zip" (www.cracking.net):
1 k8 C' K! P9 u- G/ |3 u; |' I/ }: s% ~2 l9 _' q* n
    mov     bx, cs" N$ ^, D5 e2 K( v% c' V% k
    lea     dx, int41handler2' Q# G: G( _2 b- h2 ^7 e3 O: L8 W
    xchg    dx, es:[41h*4]
) k( S* p4 {& L9 J7 ?- A9 j9 B    xchg    bx, es:[41h*4+2]
: X' E& N& k; [+ M( P4 Y% Q' r    mov     ax,4fh/ D  \$ N+ r0 f- g' R
    int     41h
( E# K- `. C. x$ N' j, @# J' o    xchg    dx, es:[41h*4]( \8 E! q: Z' W+ U  x3 W
    xchg    bx, es:[41h*4+2]! k0 o; R6 l  P5 e( S
    cmp     ax, 0f386h( K$ N  L  {+ D
    jz      SoftICE_detected8 v" @) j4 N  G. q- Y' W& w
* P1 o, _0 z3 V$ r
int41handler2 PROC
: K# O; F3 `' C, O4 x5 E    iret
' J, i; F- k9 I% D9 k! Qint41handler2 ENDP+ E4 d, j4 t  p' r' S9 x( Z4 I. o
: _. f0 D( |# Q; m. }7 D7 p8 G* x
  Y) R; F5 V! _8 F+ l/ e3 {- _
_________________________________________________________________________9 _5 V  V+ Q* R& ^

# K0 M) ^5 m' U9 m( e1 M. {# S' D9 @& s. I/ o6 X6 S1 l& _
Method 06* O  ~  I" q" a7 i# J8 ?
=========* K! U5 A* }- E; Z. B$ k; d

0 O) Q, \& h% X# r( F. |  l+ U, F: T( \) q4 a7 M" |- u7 d* F4 {/ G
2nd method similar to the preceding one but more difficult to detect:! m4 o" O8 m' K1 e, ^- Y6 _/ [
, e: q( L) E; s0 o4 O! b8 T& J+ z

  Q) f' B$ p' P0 Qint41handler PROC7 e1 z/ ^1 H: v/ z5 ?; ~6 D% S: u6 r+ A
    mov     cl,al; @: A0 ^, [! x/ t
    iret7 p; ^" i5 f% y5 A( W: s
int41handler ENDP
) i4 Y& {7 o9 J0 H  D. ~5 V5 M6 t' H! w/ _: T
2 f) f) l/ Z1 K; P% j! n
    xor     ax,ax
6 `: }. d* }% [/ i' e    mov     es,ax
. K$ q2 J9 x' D9 m- @+ R    mov     bx, cs# F9 i8 A) m4 J- S/ m- b
    lea     dx, int41handler
+ |& c  R+ H* Q- l$ X5 v8 n    xchg    dx, es:[41h*4]
. \9 [# D( e+ q# h5 i    xchg    bx, es:[41h*4+2]$ N5 U  e$ E9 J! U
    in      al, 40h0 L& D( Z: X3 ^9 T  G4 |, s: c. d
    xor     cx,cx5 V& `; f, M; K( Z+ I2 `9 D. V4 o. l
    int     41h
7 r0 \* T8 d' w* i5 S1 r$ a: T    xchg    dx, es:[41h*4]
& ]: k/ p& Q- C9 a, |& Q    xchg    bx, es:[41h*4+2]
1 g3 x- k  m  u0 r, H    cmp     cl,al
# |- F6 N% w7 _+ a8 F! X    jnz     SoftICE_detected
$ z: Q# j/ K/ [' m7 N2 i' d/ s+ t, ^4 f( S& x: n9 b
_________________________________________________________________________, B- \$ j2 R: g0 f8 m8 e

: m0 `2 H* `! ^; v) e) X, {Method 07
: l! I6 x: M/ ~=========
# W& f; T  {3 i( `- E& K$ E1 X
' J( I$ N4 O2 R4 }Method of detection of the WinICE handler in the int68h (V86)
6 [  ?& T3 _2 I7 t" D
  `$ A1 X) r5 Q7 u3 T    mov     ah,43h2 C( ?/ l9 p; @- ?) w
    int     68h$ t2 o1 z3 X8 p: d; u" v/ L
    cmp     ax,0F386h) R' B/ j* V9 ?6 F
    jz      SoftICE_Detected
, u) ^% A, R% s" `9 L/ P- m* t/ b% V4 v( z9 p( B9 f

& Q+ C' c2 ]3 R=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit, m5 \. i# i7 C  v6 q* P
   app like this:
/ m# b# r) I- i. Q) J
3 Q- M8 @, v; R% p# H# s1 `   BPX exec_int if ax==68+ |$ L* A8 \8 r1 H9 Y
   (function called is located at byte ptr [ebp+1Dh] and client eip is) V! m0 d# L8 I$ q# x
   located at [ebp+48h] for 32Bit apps)
" h; S: I% Q( R& u' I$ r__________________________________________________________________________
0 H0 J) O4 D  U0 r# f% m2 _' z0 A
/ @$ \* c9 h" r/ k
# b- x1 g- h' |) x" @Method 08
3 b/ a6 i% H. V9 r=========
" B7 r9 {8 f' o7 b( w; Y$ q' u6 Q  [" ?- v! P& N* x2 O$ Z
It is not a method of detection of SoftICE but a possibility to crash the
# d% ]7 V4 _; V+ I7 jsystem by intercepting int 01h and int 03h and redirecting them to another/ v/ B) M  T4 I. l. e: a
routine.: E3 Q6 r) G7 m! r  u$ d1 e
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
2 v7 }2 p3 F4 T% A* N4 P+ x3 r' cto the new routine to execute (hangs computer...); }" P; o" a5 A- c3 f
5 E9 \. a3 E' |- ]1 `9 t5 ?9 i7 N
    mov     ah, 25h0 {: P0 o3 W" f
    mov     al, Int_Number (01h or 03h)$ l2 D9 z! C. }8 r
    mov     dx, offset New_Int_Routine7 _: O+ \1 H& R: W
    int     21h( I8 ^6 w& a4 i
; e6 f* w. z" w) n) J# `
__________________________________________________________________________7 ^* p, D7 S! u1 |
) x2 e6 E: s6 I) k7 R
Method 09
9 Y# Q; v- [; R7 h- F=========1 [3 }* `6 g) F- Z$ A. g( U% x

, e5 F6 g" [% Q& H5 Z1 Z6 R$ TThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only* y2 r  [3 N5 d& Z  h. e! g$ [4 b
performed in ring0 (VxD or a ring3 app using the VxdCall).( B' S% Q* v; [% B$ O& h
The Get_DDB service is used to determine whether or not a VxD is installed
, C6 u- u. b2 _7 B" T+ i, ffor the specified device and returns a Device Description Block (in ecx) for
4 d( K3 [& F1 M, D! Fthat device if it is installed.
# x" W' Z1 @- }+ p) h0 V2 f, E) _
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
7 d/ `' b' {! |- x# Q9 g   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
1 J7 q6 R8 ^- }/ ~. N   VMMCall Get_DDB% i1 q9 z1 w$ \$ D, o
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed9 a* `, }, R4 g2 j
6 S8 E( t& m+ \& b
Note as well that you can easily detect this method with SoftICE:; `+ Y8 M/ ~. ~9 F; R3 P! q' F  g
   bpx Get_DDB if ax==0202 || ax==7a5fh0 O# u( U' r& O9 N0 n* S' z) }1 h
( P- r; u! v3 ?# D0 {
__________________________________________________________________________! ^! d! L- H( S, u
# r- q' x) W& Y; }8 N3 e) {3 P
Method 104 ]- @& r3 K; b5 H9 Q4 p0 i
=========5 D7 }4 ]0 s6 \- m- U  b
% I) `. b9 d6 H
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with& p- Y' g9 I& U# p5 P1 N
  SoftICE while the option is enable!!- z5 {2 u& q1 U1 @' p( x: i

, ~- B% l0 K$ y$ G: ~This trick is very efficient:& M) U( T5 k* Z! X. m3 x7 S0 u3 L3 J
by checking the Debug Registers, you can detect if SoftICE is loaded
" l( L4 ^9 O3 z- e: h(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if. n" t6 u* l  j# W- O
there are some memory breakpoints set (dr0 to dr3) simply by reading their
$ z% `* I8 y* b% @  Bvalue (in ring0 only). Values can be manipulated and or changed as well- A8 J/ ~. ^: H; K7 M
(clearing BPMs for instance)0 W$ P) C  Q$ S; y3 p! L

8 O! t; n! C/ u) d! Q__________________________________________________________________________
+ v+ i' J/ h9 e, `/ F8 o& ^' Q
% Q; b5 y6 g" B  x9 ]/ F" t# hMethod 11
" R8 B, V# G$ N/ A9 r=========5 x. s/ m" C0 X8 i
1 p  y, M8 r. Y+ ]; ~4 \
This method is most known as 'MeltICE' because it has been freely distributed- v- q! M- y& P! N; V
via www.winfiles.com. However it was first used by NuMega people to allow8 v4 |7 J- D0 y' e3 Y8 V% @% `
Symbol Loader to check if SoftICE was active or not (the code is located
. `$ b) Q" S& M) `inside nmtrans.dll).2 r% i; b! s. O& n

" A  k4 z6 i1 K, F, sThe way it works is very simple:
2 x+ `: h1 @) F3 _It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
3 v/ F. [2 T) r6 W& R" Q7 @WinNT) with the CreateFileA API.% N4 @7 p! q) b8 G8 ]
9 H6 T! p. s+ a: i: P
Here is a sample (checking for 'SICE'):* O( W" ^& R/ i* e" e

5 w5 u0 t# J& x/ ^+ PBOOL IsSoftIce95Loaded()1 R0 P8 ~  t# M7 S% Y. V; h
{
+ p2 k1 l* T; p9 W* F8 V  o/ S   HANDLE hFile;  ) }- Y" I2 g# v; R) G
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
- j8 ?( F( Y- j& o" S* d: h                      FILE_SHARE_READ | FILE_SHARE_WRITE,- y4 a/ r, V5 _$ s
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
2 l- W; `7 t: T& }: \   if( hFile != INVALID_HANDLE_VALUE )
5 B* r6 n' B; X, P0 v6 v  I2 s   {
+ N6 \1 p+ \  S! D; J1 o      CloseHandle(hFile);
) y. ^% }6 T0 a; L  K      return TRUE;
% T( {, E1 r5 Q# E6 t& q  p# y! ~   }- n# ~& e  |9 D
   return FALSE;! L- z& ^& a1 r& p  [/ e
}
) Q8 o' r3 W4 o, F
# S. R0 Q; j6 X* ?, tAlthough this trick calls the CreateFileA function, don't even expect to be
) r& ]2 q2 @1 c" b% [2 K3 @% Pable to intercept it by installing a IFS hook: it will not work, no way!
* r( H. N& i3 Q* ~' tIn fact, after the call to CreateFileA it will get through VWIN32 0x001F
' i" M# j: c1 f+ u+ X9 pservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
; [3 G" t1 g( B/ F5 o, ~and then browse the DDB list until it find the VxD and its DDB_Control_Proc2 B9 B5 m! q( p4 z+ ^3 |
field.
$ t; q3 T! q* k3 I0 D  WIn fact, its purpose is not to load/unload VxDs but only to send a ( H# \9 `- M% k2 ]
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
1 ^* H; |' n6 P8 }+ ?2 g. g6 Lto the VxD Control_Dispatch proc (how the hell a shareware soft could try  N* p* u+ F6 D. O% W- _- Z& {
to load/unload a non-dynamically loadable driver such as SoftICE ;-).3 X' t3 q9 K0 b$ F1 [: A  R6 O5 N
If the VxD is loaded, it will always clear eax and the Carry flag to allow: A  Y& L$ X/ B
its handle to be opened and then, will be detected.% J  u% J8 \2 n, m7 s5 ^8 ?
You can check that simply by hooking Winice.exe control proc entry point7 E$ i  U  d5 s
while running MeltICE.
6 h- D& S8 z: ]: Y5 @8 e- a! G2 a  H9 L2 T  p1 h
' S) R- q6 S/ N& f% y
  00401067:  push      00402025    ; \\.\SICE
7 ^% W1 \% p" g1 Z' C  0040106C:  call      CreateFileA
% g- [6 g; s: f) n: o# L/ ^- l- {  00401071:  cmp       eax,-001
/ b) D6 W. M/ \7 q  u  t  00401074:  je        004010912 b" |! x0 _+ i% ~/ T
, }8 C8 A) k1 `) I6 l7 Q' o

% v; W& s* _0 z, T& _There could be hundreds of BPX you could use to detect this trick.
0 ]$ J, F! T! n) \% b-The most classical one is:/ C" I1 t+ o% j1 v9 c& k  ?
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||: q- g" C" }  U9 t. g0 y' `
    *(esp-&gt;4+4)=='NTIC'5 e# p! V0 N' @7 l1 K7 z, o

/ T$ L" b5 g9 K5 F$ u$ y-The most exotic ones (could be very slooooow :-(
% ~) B: p6 b/ ?! E: a1 @* r! Y$ n, N   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
0 a1 Y" T  |1 x' y& ^     ;will break 3 times :-(! a9 D' K6 ^4 b

4 ?4 X  E: L* Z0 E: E' @, b-or (a bit) faster: 4 c8 ~" L5 G, u) Q- ^- ^2 N2 R3 G8 d
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')3 P7 v( _# k# w/ `( p, f- y

( h2 v3 }( ?$ w$ m" v( a4 r   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
# a3 X; h& X* `5 M     ;will break 3 times :-(
% o  a. c& s  i' M+ X9 N
. r$ `* I1 w; X8 ^6 E, {- V-Much faster:6 w7 n9 w9 I7 B6 g
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
$ c. K" x2 }8 F2 b7 E$ n8 v9 M' b( h  j4 O! s8 ]7 e: V
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen6 N1 k; c) G  E2 G
function to do the same job:
3 H& I; Y# n! k+ @: `8 }: M
: ^" Z/ J; n) `2 R6 e  f   push    00                        ; OF_READ
3 D) i3 z7 Z2 E8 [* q6 {6 ]  w3 M   mov     eax,[00656634]            ; '\\.\SICE',0
! f  \2 e9 b8 }) P   push    eax% ^& T6 C8 H1 Z/ T
   call    KERNEL32!_lopen
$ b: F$ ^6 [0 T+ |   inc     eax# E( N4 K  G+ m' l( L
   jnz     00650589                  ; detected% a" ]" K# d3 P4 ^4 ]9 I4 k1 J% N
   push    00                        ; OF_READ- t) c( A6 j. W
   mov     eax,[00656638]            ; '\\.\SICE'
( O7 B5 |9 G. R3 P   push    eax2 T6 T: [% S0 q; N0 n
   call    KERNEL32!_lopen
# Z$ P( Q) |. R1 v2 s   inc     eax
# a7 x/ f# h7 ^* o, X7 W* d   jz      006505ae                  ; not detected! d% Q4 K& @" b, s  j1 ]; \; ]

. A( U# k; O2 H; u  x# e, \4 h: L: C) _' I0 I
__________________________________________________________________________
* L& \: F) n. D* t% F
6 z2 K7 z: x1 E" J3 EMethod 12
6 i# E/ H/ h3 I=========0 V& t! g0 {( V$ @! T
. h$ p( T2 b" p
This trick is similar to int41h/4fh Debugger installation check (code 05
# V2 h& ~0 n; `1 J. X6 q&amp; 06) but very limited because it's only available for Win95/98 (not NT)
' w  `- Z8 i0 n4 M- a, C1 }7 `0 yas it uses the VxDCall backdoor. This detection was found in Bleem Demo.2 |) L" u: m# v. N, J3 k) `

" `  s+ t, \0 L4 i   push  0000004fh         ; function 4fh+ c: ^9 ]7 \/ ^6 J" l  Y9 U1 |" f
   push  002a002ah         ; high word specifies which VxD (VWIN32)9 m1 N& F2 x4 d4 F. ]  o! h
                           ; low word specifies which service1 r. @6 b9 A( y( X1 `# c+ L9 Y
                             (VWIN32_Int41Dispatch)
. e, Q0 g- J" u4 b7 P' E   call  Kernel32!ORD_001  ; VxdCall* g) m: b; ^/ B9 w) x+ R! {
   cmp   ax, 0f386h        ; magic number returned by system debuggers" @8 H6 s8 ^7 ^6 r# k: p
   jz    SoftICE_detected" Z7 m9 Q: S9 i' V
+ L$ n; x; q. o5 B; _& J3 v
Here again, several ways to detect it:
. |9 B3 |. A- N& @: y% n% J
- r8 k: v) ~; g5 G( Y    BPINT 41 if ax==4f% a9 Y5 A' {' E# O9 y
  h6 ?* [# {8 G* A3 X+ x
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one, H" i& P+ R& H  z/ W3 H

0 b; ?+ K& H. G, N    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
' Y" Z) f0 y% x1 U; o
2 m. F; D! w) H- M( w/ G* D. C    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
. }0 o2 Z+ h% S; X) i/ ~7 O. G
! v: G2 C; z2 W: I5 n3 Y__________________________________________________________________________) T& R; ~- p5 _" S5 v  \1 _; ?
* b+ J/ O; o4 e! H0 o3 q& R
Method 13
" k& C% Q) J  R, z/ h=========
" W( F$ R- ^) _0 i& L, l7 c
' l/ a( E' Q" ^8 s0 TNot a real method of detection, but a good way to know if SoftICE is
( p* A8 B: T  o+ P0 N; l5 K: U, T8 }) `+ ]installed on a computer and to locate its installation directory.9 U8 a8 H* a6 E* }
It is used by few softs which access the following registry keys (usually #2) :) D1 k2 ~1 ~) l: F4 Y' }

& G$ k) v. [# |# \6 p-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
/ s. ]) d& _3 J8 a\Uninstall\SoftICE5 i2 X9 }9 U- y. X
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE9 j1 b0 A& Q+ A: f
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion, _; x, c  A$ e. }4 ?' j$ p
\App Paths\Loader32.Exe3 R$ m: j) F7 r
# ?6 r0 l; H3 W
$ b7 w% L8 h& ^% ~7 O6 O+ F* W
Note that some nasty apps could then erase all files from SoftICE directory
6 k  r4 q9 d. [" Q7 p; ]. M(I faced that once :-(8 n3 o; j8 D5 V3 }2 s0 C

. t  [  K# \8 ~2 J/ Z4 O7 FUseful breakpoint to detect it:
0 @1 ]3 \7 h( {) b& n6 t9 b0 G# s1 c$ m! i1 r& ~
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
( s" d/ r+ P3 U( A4 F
$ v: v. T6 _) o0 H1 F4 q. g3 J* K__________________________________________________________________________' ^- S9 W9 P6 V$ K! D

/ ^' ^4 l! g: A( X* u
0 g$ ^7 _, Z6 s3 D$ s+ B# |! H. HMethod 14 " F! U2 b. k  L* q
=========
* E4 T; e* e3 A2 `
7 Y. ]; t! U7 g# f% z$ i4 O. qA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
/ `& i/ b% ]8 @& Kis to determines whether a debugger is running on your system (ring0 only).2 i( R4 X. ]$ z3 P8 K+ d$ G! _
- w4 }$ H7 u& [7 D8 R4 O! K1 J, y
   VMMCall Test_Debug_Installed
  o% c6 o0 y  S+ \, f   je      not_installed
2 v" q( n+ i+ P7 ]' u& v9 G+ h0 r9 v6 K
This service just checks a flag.5 c$ B  I* T1 x( h, G. c: v
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部