About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
0 G# A$ W& l( w, u& M: i<TBODY>9 d2 G6 s  t. s6 A! l! D
<TR>- b5 D' W) }8 T1 ^+ G3 m8 b) {/ ?0 ~
<TD><PRE>Method 01
, H7 t2 B1 _. {. Y=========
5 Q8 |' p6 j' t- M3 ]$ G# f" w, f/ X5 L
This method of detection of SoftICE (as well as the following one) is% X4 Z+ B% ^5 p  U6 D+ d
used by the majority of packers/encryptors found on Internet.9 U2 j4 A0 H& r- F8 e8 y) l
It seeks the signature of BoundsChecker in SoftICE9 e; C* J3 A' ?- l% y
. w/ T+ ]2 a; z" G6 o; H
    mov     ebp, 04243484Bh        ; 'BCHK'% U' r: q9 @1 P8 I
    mov     ax, 04h) `$ I! X* f$ F6 e, S) c1 k
    int     3      
( V% X, i$ Y' I) @2 @: E. {    cmp     al,4
9 P, T3 U4 s' K* t    jnz     SoftICE_Detected9 w+ y& ?/ Y( H
  o: d1 e: f$ M. `; ~' O+ k
___________________________________________________________________________
3 N6 l" Y4 L* z( j
8 M$ S5 G3 {; l, a  C+ PMethod 02
# O) f! [" i/ X1 U8 s=========. f4 K4 U$ g* y6 k% n
$ s1 p- D5 {3 m/ c) E5 v& m
Still a method very much used (perhaps the most frequent one).  It is used
6 e2 I0 |, U: D( f' c+ j9 Qto get SoftICE 'Back Door commands' which gives infos on Breakpoints,$ X! |0 e2 j1 e3 |1 P
or execute SoftICE commands...
. B4 V/ Q$ H- q; w: aIt is also used to crash SoftICE and to force it to execute any commands4 _8 a0 F6 A1 A; L/ S2 T
(HBOOT...) :-((  4 [  y( ~/ G1 k2 g& m- t
( ^7 C( i. O* b: }$ m9 L3 H0 o
Here is a quick description:
1 v+ W' a! \! `- W! Y$ |1 _-AX = 0910h   (Display string in SIce windows)' ~+ Z% i* }# z2 f! A+ V* E+ L3 S
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)5 i: H+ \2 M8 p) c1 Q
-AX = 0912h   (Get breakpoint infos)
, @! D! t3 V% Q, U-AX = 0913h   (Set Sice breakpoints)# }- B; Z/ L  {. r" J! q6 H
-AX = 0914h   (Remove SIce breakoints)) ?3 C* ~" ]. h1 H6 Z

5 I! T* p1 T* {& LEach time you'll meet this trick, you'll see:8 Q7 U3 y4 X  T* \/ |& t
-SI = 4647h
1 X  t, i$ K, x-DI = 4A4Dh
% n& `2 {" [6 F# o7 c, DWhich are the 'magic values' used by SoftIce.
. S( }! T7 U2 M, zFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.; D: U5 ^$ T# b, T( B

6 f  `/ ]9 W* G% R" oHere is one example from the file "Haspinst.exe" which is the dongle HASP/ F2 F* t2 m" X
Envelope utility use to protect DOS applications:
: _! P( L0 L! r
9 h, z" a) B3 N6 T
0 Q4 b6 z. G& O) Z/ B; M4C19:0095   MOV    AX,0911  ; execute command.1 q8 X5 b) ^7 A! b8 T6 h' g) h6 q
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below)., C' e0 k) ]! I+ S; c9 E
4C19:009A   MOV    SI,4647  ; 1st magic value.
/ Z+ r+ t% M. a5 O+ S/ n4C19:009D   MOV    DI,4A4D  ; 2nd magic value.9 l  n# e$ l- @" P: ^
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)9 D1 g, B0 U2 N. r
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
7 P$ q3 Y7 {$ k: W5 v( t4C19:00A4   INC    CX$ J6 k1 T9 [& n; ^
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute; L% ~% y  z3 u
4C19:00A8   JB     0095     ; 6 different commands.
. u8 m" O; n0 [+ e3 Y4 t, m4C19:00AA   JMP    0002     ; Bad_Guy jmp back.& w3 Q" g2 s8 e9 }5 [! q
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)2 k, I/ L5 G+ T
$ }( R  V0 x/ e# D: d/ a0 k. n
The program will execute 6 different SIce commands located at ds:dx, which
$ ~: P! V7 n, K! [: H/ T& [are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
: o2 j4 N4 g# R& E1 F
& L0 K" r; Z" U) T9 A* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
1 O, S1 m& s: `$ y* b8 V___________________________________________________________________________
, u% S  H& h% Q) I8 l9 b2 \7 T1 Y/ q" v1 L0 b
3 R! V) Q) Z% K4 N$ {3 {& H$ u; o0 {, M
Method 03
' T$ l6 J& |' _2 u=========0 p% _& g. c: O, h- u

( E  \; k& h  P6 k/ s( g+ `Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h9 X- I, o# ]* E) l2 g' E0 V# `4 S8 ^
(API Get entry point)0 O' F; \+ O( A' L
        1 U$ U) M! m3 x% B, g/ e

3 M+ {$ L: P8 R$ h- l# n% s4 V    xor     di,di
) Y, r. w% c5 b0 B    mov     es,di% @% O" @, S$ B- b
    mov     ax, 1684h      
6 c$ k7 j+ ^% t0 R    mov     bx, 0202h       ; VxD ID of winice
0 B+ f* e9 i( f$ V) E    int     2Fh0 I% _; t! B! |) |8 s
    mov     ax, es          ; ES:DI -&gt; VxD API entry point3 L  l3 R# [' ^* v) E* A  [3 E" U
    add     ax, di
7 e5 u6 W6 F: Z8 c" K: S1 |    test    ax,ax
) ^' b' }# t/ ^' i- B# V    jnz     SoftICE_Detected
: @0 \% `: ^% \$ l! Y$ v* _
9 V& ]- B- ~% ~. W___________________________________________________________________________
. w0 \; D8 r9 e" Z' |' |' x: A' F# F$ l% H4 ]/ ?& U
Method 04( g; e; z9 o9 j" S" X' G# \) }& x$ q
=========
. s; B" T+ I4 u3 z4 W6 M
+ J+ B+ A9 z+ [: B% o" {# mMethod identical to the preceding one except that it seeks the ID of SoftICE4 W$ m+ J9 \' E
GFX VxD.) ?( k: Q/ s8 `8 W

; C5 ?' E% M8 {2 l4 M& g% }    xor     di,di
( |. v& q7 ?1 h% \    mov     es,di
) i, l! o/ _. L. |) c    mov     ax, 1684h      
8 D/ P5 \8 w! K    mov     bx, 7a5Fh       ; VxD ID of SIWVID$ L' g& \0 C7 Z- ~
    int     2fh
6 l" u6 M$ M3 i: _2 N; R4 j6 a    mov     ax, es          ; ES:DI -&gt; VxD API entry point% m+ E0 K$ s+ A: c2 F
    add     ax, di  x: K2 {  B5 W2 F8 a
    test    ax,ax7 }; J/ f; O4 y# `0 \& }1 n! B
    jnz     SoftICE_Detected4 \( g$ R  u; `) d" W
5 L0 d( X; L/ N. s
__________________________________________________________________________1 A- F4 h6 w' A0 A- ?- Y0 e* ]

: o) b# p/ q1 r. t. _. ^, G9 M( H1 d9 @. u6 Y- ?
Method 050 ]1 ~0 `3 R/ T# Z- b! l, O
=========
* V' M* Y. }" O8 L/ A- k4 ^! J( [0 ^  |; I& i
Method seeking the 'magic number' 0F386h returned (in ax) by all system
0 N; P" z! Z: bdebugger. It calls the int 41h, function 4Fh.
+ ]4 K! b* `( N5 m4 ~There are several alternatives.  
6 e) n, c+ m/ g- ~1 D: _* s5 S5 l8 N3 E
The following one is the simplest:) k' i; q+ L) g* @* b2 L
0 S9 `7 z# h. v- L8 f
    mov     ax,4fh
( o0 [4 a, G/ f  H& q    int     41h" ~( s1 r9 |7 g' c- i0 X. g) }
    cmp     ax, 0F3861 [, ]% m; h; Y3 V* N5 W7 m9 i
    jz      SoftICE_detected/ O; V9 T  a: }' w

$ t+ [( R& R. R# T
- H& a1 v2 b9 U) ?( k8 G% mNext method as well as the following one are 2 examples from Stone's / K. e4 e/ D1 Y% U5 N/ K# G- X/ F
"stn-wid.zip" (www.cracking.net):2 a3 M: ?" X6 ?! _  Q7 E# Z1 g

4 U. p% v5 S/ |. J    mov     bx, cs( F1 y: t; J/ I9 `
    lea     dx, int41handler2  f" s) w, W& o' V" v, P
    xchg    dx, es:[41h*4]6 w! ^5 L& l. A! M" U$ p, Z
    xchg    bx, es:[41h*4+2]
# p' J. R5 s0 n7 y$ i; p/ X( @    mov     ax,4fh8 R5 F7 L' Y" r9 N9 F. ?+ W1 F
    int     41h: T6 U2 [! ~! B6 J/ [
    xchg    dx, es:[41h*4]# r. C# u1 h) a# ?  z
    xchg    bx, es:[41h*4+2]
# f/ _# f* E' z! J& o% m- z  y    cmp     ax, 0f386h2 q; s2 }# C) l  s0 a& w% g) E
    jz      SoftICE_detected4 K4 `. s$ v8 u; O2 {
( o' N9 x* B$ Z- m+ H! H" v
int41handler2 PROC
8 ?2 v5 A, _% M) K" @    iret  {* C8 u; }" o& Y
int41handler2 ENDP
4 v  \1 _  t  t6 \' s5 b9 ^5 a' `* ?
5 H9 z' f4 T# [5 G6 `& ~: l" |: m3 K2 c# c$ X9 P0 B
_________________________________________________________________________' ?3 V) M: f* s) u3 ]
$ a* {6 Z/ q/ H. d
; w: y) U& y, B5 u* r3 D; [  z
Method 06, f9 j# m; p5 I0 R7 G+ B4 y
=========6 H4 _& v7 I0 P4 U6 c& R3 [

, E4 r* B7 D% l2 e7 K2 K
# H4 U7 `! Y9 K) F2nd method similar to the preceding one but more difficult to detect:
, n8 M: C; Z1 c" V3 X! V9 m7 ]$ z# z7 t$ O8 x, U* K

: n6 l5 @$ r5 }int41handler PROC
. K+ c2 J( L* X3 f' I    mov     cl,al
2 m* l7 h$ D3 z, h% T    iret
1 M9 p  H6 T- f+ Rint41handler ENDP: F- n" G4 H( h& }7 [

6 G3 o( r, Q9 H$ D* m+ v5 I: N4 I- C2 b
    xor     ax,ax
; p  }# F, }2 H: W- g+ ^" R7 G% E    mov     es,ax
. O& m4 Q, \+ F6 Z* I    mov     bx, cs
; O& V- w& Q  \. h2 @4 \* o    lea     dx, int41handler# T5 A2 z+ y% G0 q6 y0 x8 c: l! G
    xchg    dx, es:[41h*4]- F  _9 @5 T" r( H2 B) }: v. ^
    xchg    bx, es:[41h*4+2]
0 Z& }6 D* e( |* c% B& V( l    in      al, 40h
$ Q0 T$ y. t6 R8 _7 s    xor     cx,cx
9 d: q# M! y( r' _- V    int     41h0 E* j! Q% t) m8 C" I5 \6 d
    xchg    dx, es:[41h*4]3 B9 T7 F3 v8 \& _2 L0 [
    xchg    bx, es:[41h*4+2]8 G5 a( J3 |4 ?0 ]
    cmp     cl,al
; h* T) E+ e+ U# B* y' Y/ R0 b4 X+ F    jnz     SoftICE_detected
- c# ]" n* w7 L% H" n
8 q2 o5 a+ x7 p# O. i_________________________________________________________________________
" E. p+ A4 M' S5 D" m  f8 S5 {
& Y3 T6 \7 J" u3 D( ^Method 07! g, h9 }4 L5 Y% }( [
=========
  y" D! ^; C/ E- X6 i9 d: h1 o- c. Q) _! f; P$ [
Method of detection of the WinICE handler in the int68h (V86)( C& l8 ?8 I. f/ `8 g) m% J

* S( j/ A- l5 Z  W7 f8 V3 g0 b* ~    mov     ah,43h
+ g; z9 i) C( ?6 g/ n    int     68h
. Z4 x" R8 B, s) j+ d% ^" O    cmp     ax,0F386h+ m: ^9 V9 m; J
    jz      SoftICE_Detected
1 g* Q+ C) F4 b
/ l" P/ h# ~9 I: O
7 `; \5 \( u9 K0 e. x( x=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit: ^0 C1 z, b, T$ e+ R
   app like this:
( U3 |, w) ~' v7 M  f( Z1 ~! u0 D) a7 Y* O
   BPX exec_int if ax==68. L$ b* Z" V, I- Y7 a8 w
   (function called is located at byte ptr [ebp+1Dh] and client eip is2 f% R1 q+ F1 y- Z
   located at [ebp+48h] for 32Bit apps)
! \- R5 n$ ~# d  C; ~__________________________________________________________________________/ X# j2 v6 r# w; {+ w, I) [% K( o

: `. R8 }, y9 R+ H$ t. e
. U2 \6 ?- G" L- d2 O, ~: R/ lMethod 08
- G: e5 a! C" \5 K$ }4 \7 H=========
" F7 J# x. A. S$ X
# Q, {& Z5 z* P5 e* r7 SIt is not a method of detection of SoftICE but a possibility to crash the9 w. w1 p. h0 E
system by intercepting int 01h and int 03h and redirecting them to another' u8 D4 P3 b" k1 Z: L/ \& J6 B5 \
routine.
2 L& N3 V/ E7 i( v) BIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points/ {) W) Q% O5 Y+ ?! s* r
to the new routine to execute (hangs computer...)
/ l7 M* B9 `) I5 X8 u# x7 X, ?
& ]1 N* E3 N3 {3 w5 n% ~    mov     ah, 25h
3 f2 t9 p6 H1 ~3 w    mov     al, Int_Number (01h or 03h)- D  w% \" O- l! O2 c; F* T% k; u
    mov     dx, offset New_Int_Routine9 Y; I) A' @5 d- ]9 w& {
    int     21h6 ^6 S6 q5 H  x0 a: I, v6 E$ V/ y% ^( c
, |+ G6 N, z! x2 E
__________________________________________________________________________6 B* C% m4 B& w  V7 P1 d1 c7 w: m

, D; H5 G  ?7 o1 ]; m# VMethod 09# r# o  s5 {! {1 n* e, g
=========
( Z7 d6 N" n8 ~' X& J  [0 c+ k* j/ |) r  X  _5 K1 Y# O
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
0 k' w1 s( o7 wperformed in ring0 (VxD or a ring3 app using the VxdCall).+ |: g, ^2 ]$ K, K4 ~
The Get_DDB service is used to determine whether or not a VxD is installed: i  T* @1 i: B
for the specified device and returns a Device Description Block (in ecx) for# B6 I- t& Y& T6 F& g
that device if it is installed.
* q8 u- ?0 j; |) n
3 H7 i; q7 i9 B7 H% s! n   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
$ j9 H3 i# F9 r   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
& h; L9 a  g! {% Q! ?5 }4 j   VMMCall Get_DDB, w/ p; X  J. ]3 k. K# b5 x
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
/ s9 ^2 e! \/ u) j! u
0 g7 w3 _5 M) m' \; F$ S2 PNote as well that you can easily detect this method with SoftICE:
4 C* B5 L% [; O8 T9 z: B   bpx Get_DDB if ax==0202 || ax==7a5fh
! b) F: p/ o2 l3 v4 T' |; @0 X" d. G, f) t# r3 ]' S! K
__________________________________________________________________________
, q  Y8 S2 |( g5 n2 p; H
4 i  M0 I: i- }. S) ?; o; aMethod 10
  r) R- ~8 o9 D7 _  J=========
) _; k, k3 Q' q+ L) U) W4 {
+ F- ?; {# |) U, b/ x2 H& l=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
5 ?$ N, \+ m* R6 B% p# w% D& }  SoftICE while the option is enable!!9 n2 B2 R9 K/ r3 u2 ^3 t

5 S' g' Y+ x6 G2 D# p; @* v( xThis trick is very efficient:
4 L2 M' s4 b+ G( w5 ^by checking the Debug Registers, you can detect if SoftICE is loaded6 L3 H* e0 l% A4 m' x" F# u* z
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if" p8 {" ^. {6 G$ M
there are some memory breakpoints set (dr0 to dr3) simply by reading their
9 e& j3 ~( O6 V9 i  b3 mvalue (in ring0 only). Values can be manipulated and or changed as well$ r; p/ o7 ~) y/ W' g: I
(clearing BPMs for instance): G; @% I1 o: N. ^) S

, T3 g" I+ r+ U' C3 Z1 W- Z__________________________________________________________________________5 f5 @# E9 ?, {# k
' @5 L- @! @0 b! c
Method 11
$ g  G+ @2 i, @& H6 Q: A=========
! f3 Q3 w' U8 m/ u6 u( N0 O0 p: j
; E3 r3 H4 W% D' r4 h9 p# M8 ZThis method is most known as 'MeltICE' because it has been freely distributed- w1 n# s- F! I4 H& }: n/ D# {* W
via www.winfiles.com. However it was first used by NuMega people to allow
2 F6 d  o; R5 r& _5 A' WSymbol Loader to check if SoftICE was active or not (the code is located
) Q" M3 |( o- U% o* d! n- uinside nmtrans.dll).- h% B- S: A3 ~
4 z; b7 r( E, v& C: }: j3 @
The way it works is very simple:0 V+ m" b+ O+ ?0 G
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for. T) w7 r! j; s* J( P
WinNT) with the CreateFileA API.
" d0 F* Y( G2 X
5 o9 h, ~; j5 d' _Here is a sample (checking for 'SICE'):/ C# S( [4 c( l4 Q5 [6 c

, F4 d7 W- R2 f* h/ dBOOL IsSoftIce95Loaded()" l. y! t' U( W+ }3 {+ V
{/ S' T  n) u& x
   HANDLE hFile;  5 d+ O- j0 g9 C: }4 X+ T) B- N  W" d1 g
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
7 H" [1 F- i* O: ^" K* n' H1 f& u                      FILE_SHARE_READ | FILE_SHARE_WRITE,
. v- T( }) G' x1 r' P% i                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);: Y+ Z' i( g' p( i
   if( hFile != INVALID_HANDLE_VALUE )
( o8 t, k! g2 j% C   {
) [- v% Q/ `( l4 Z5 |& m$ w$ H9 @      CloseHandle(hFile);
! l  o1 k9 X7 l5 V7 C5 h9 z, p! |3 n      return TRUE;
# A8 q1 l& {0 I8 X4 X) t   }" k7 M/ y5 F: [) Z9 Z
   return FALSE;
( f, J. y4 C$ J}
3 I6 x6 f* r  S3 }' O2 n! u# S+ [  f0 Y" w
Although this trick calls the CreateFileA function, don't even expect to be
0 u* u& I3 Y4 a8 j4 ~able to intercept it by installing a IFS hook: it will not work, no way!
6 S3 Y2 M8 P1 K- D! |) s; wIn fact, after the call to CreateFileA it will get through VWIN32 0x001F' ~% S# t9 h& d, q/ J4 A( ~
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)0 W" D( p6 L' X: R. o
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
+ y+ y/ e. h0 {& u- kfield.
% h5 j  s3 l. x" V0 }In fact, its purpose is not to load/unload VxDs but only to send a
, a3 U" [4 a5 o! }. }# tW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
# _; R( e; r: ]3 _' B) Hto the VxD Control_Dispatch proc (how the hell a shareware soft could try
5 p/ P' Y7 d/ \/ l% lto load/unload a non-dynamically loadable driver such as SoftICE ;-).
" y' Y! t' P3 j0 c5 l; cIf the VxD is loaded, it will always clear eax and the Carry flag to allow
. A& D* a# E( Xits handle to be opened and then, will be detected.
$ D; j2 r- _' F; d  @) d: P& oYou can check that simply by hooking Winice.exe control proc entry point; y4 l3 G: B' e5 I: r5 o
while running MeltICE.
7 h  I  S( j' e. K% J) Q' _- k6 d! t' d) Y1 a5 X# j, A" ^
6 U: [( u$ U; K, g5 i! u
  00401067:  push      00402025    ; \\.\SICE7 u6 F- s, n7 u8 R- @% |
  0040106C:  call      CreateFileA/ C" k- @) p- `1 u- F3 m7 H( W' g
  00401071:  cmp       eax,-001, m, F$ l6 [( ]- \
  00401074:  je        00401091* A1 T, J! [* ^$ d) a" H& B

# s9 {; ^& X+ y( S' R! ]# y0 ~
5 S1 n6 D( V9 {! D% b( W% R, uThere could be hundreds of BPX you could use to detect this trick.
0 N1 N2 H$ z/ x3 \3 @1 s: k- Q-The most classical one is:
& h, {  T6 X2 [9 O9 g  Z  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
) r' B7 p9 N$ g0 v6 ?    *(esp-&gt;4+4)=='NTIC'
4 N; b4 K9 x4 Y; t9 H4 [/ U" b( x, b: q
-The most exotic ones (could be very slooooow :-(
; U4 [0 a' M9 u( x6 o8 O( A   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  : V8 W0 T3 r" N% j0 [
     ;will break 3 times :-(1 y7 T/ K8 L  k  y

, {8 e* N0 T+ b; I. t% z-or (a bit) faster:
0 X; T' ?8 g/ }! H" [5 y: D   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
: ~" i6 `5 _, ?3 b5 a- f7 [9 r: `9 w  c
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
; `+ g* e1 l  P1 R; w     ;will break 3 times :-(# d5 v! v. s0 L& |! |6 V3 E9 g" Z

3 }) O& |6 g6 I( R-Much faster:
" g: _" I" e: t/ i/ [" F% @   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
4 E- x+ m: L/ l# t5 Q3 F4 |
- E. Z2 J( o& R: Z9 j; a( vNote also that some programs (like AZPR3.00) use de old 16-bit _lopen* E& r1 x# X5 k* r" ]6 }7 h
function to do the same job:% A/ t! g8 z0 ~
9 D$ g3 m" w/ u) C# H
   push    00                        ; OF_READ
' n. [% H# }' m; ^   mov     eax,[00656634]            ; '\\.\SICE',0
/ ~1 Y) b8 M" [* B% f0 o/ T   push    eax1 n8 h) Y7 K7 ?8 g
   call    KERNEL32!_lopen7 f$ W; k( y, q; b  z7 q
   inc     eax
8 p/ r( |3 ~2 ?; d  n" O   jnz     00650589                  ; detected0 e, g0 U" v9 u
   push    00                        ; OF_READ
6 `; o" [! }) x. C; B. l5 \/ i# v   mov     eax,[00656638]            ; '\\.\SICE'
$ f0 V# v# p: B: m0 U1 E   push    eax
  @( h# V& j( Z$ m8 U" h   call    KERNEL32!_lopen8 ]) C- [/ a  ~0 m* q# D
   inc     eax
; Z  K9 b6 |: `% q" o   jz      006505ae                  ; not detected: K' p6 j0 B3 S% |* ]/ F0 M
% J. C4 E9 R' W- M" u  D

+ Y" M  n9 ~: U  J! U3 Y__________________________________________________________________________
9 b( B" b  K( C9 o
5 H6 d; D9 c; B4 d; m& U* [Method 12
/ D6 \# n* C9 Y1 E9 h=========( {$ G- L$ r8 e# ]" `& p
1 J' c: O. O8 k0 j
This trick is similar to int41h/4fh Debugger installation check (code 05
% l5 z. A% p! x& }&amp; 06) but very limited because it's only available for Win95/98 (not NT)7 q* O2 H& t7 E* A8 L! @/ p- R
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
  j9 e! F/ e6 F0 U, r' b$ @1 d# ]& u: n
   push  0000004fh         ; function 4fh
7 \. Y. k3 O+ h9 o$ Z* H# U8 b/ F   push  002a002ah         ; high word specifies which VxD (VWIN32)
/ @! U8 k. m- |8 d4 @                           ; low word specifies which service
1 ]- ?+ |, Z! O                             (VWIN32_Int41Dispatch)' r' s/ |! h- g/ ^
   call  Kernel32!ORD_001  ; VxdCall
- Y) L- ^& u: Y   cmp   ax, 0f386h        ; magic number returned by system debuggers+ Y7 c2 j8 {+ Z& J4 j- O& ^
   jz    SoftICE_detected
! I& R9 V, K! i
/ p  |9 `5 E/ ]) _. pHere again, several ways to detect it:
  |- b1 q: \! q$ `# R; s! {+ k: L& u' [7 U8 {% G. N, r* m
    BPINT 41 if ax==4f
# F5 {" V7 x- i& x' [" D7 z5 l) V, [
% N- U1 {' P& j    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one: ~. G) w; h, K# n

2 W$ I; M8 W6 W6 `) q  s8 F    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
  c9 w* V" D) ^* L& b; `/ o* k, j. {" \, ~
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
! h# w; r" x4 s' C+ N* O0 A
2 b/ c7 @7 v: ^__________________________________________________________________________! U2 o  i4 s0 W

0 V; V# o: o6 A5 D- z: BMethod 13
; d8 ?) m5 A. e: {9 h=========1 X8 _- Y1 B9 e
3 W- b. x" \% Y: O0 ]/ @
Not a real method of detection, but a good way to know if SoftICE is
( }1 p* v6 L, i. tinstalled on a computer and to locate its installation directory.
* V, T. Z$ k' q+ g' z! X7 _It is used by few softs which access the following registry keys (usually #2) :
- [( ~- N" C: p2 A! k
; Q% U& m7 {" A-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
- p2 Q; f$ j' L  `\Uninstall\SoftICE) y' i$ {  x; q  b) `
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
6 i- j. A8 k8 _9 M/ |( h-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion2 I8 y" \7 g. a: c! V& t, _
\App Paths\Loader32.Exe
2 M  @) e) W! F4 E4 @$ S5 r1 V, F# A7 E

! w2 [% E+ O& Q6 q9 V8 Q/ {Note that some nasty apps could then erase all files from SoftICE directory# f3 p3 N0 `: L9 V$ l1 B
(I faced that once :-(
: {2 Z# f* R9 v  _: z; }& z6 B# z4 N. \- w6 h% o$ m7 \
Useful breakpoint to detect it:
6 ]' U) J! a' C
; `5 Q2 H# K5 O2 [# y. [* e; B     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
2 q* S# W4 ?  K( k9 w
- K0 A! f6 {5 D/ f. l5 v9 i__________________________________________________________________________8 p" t: D) r" h( V

6 T9 ]* M2 u! y1 V$ P9 q) @8 U0 l4 X3 P1 C
Method 14 + E6 O; R% p' L% A: H$ C8 I8 v0 G
=========& J: _$ i- d+ }+ d  I5 n

  i+ x( r% A2 x) X$ cA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
( ]$ T4 V! X) C+ Mis to determines whether a debugger is running on your system (ring0 only).' ]1 ^4 _) e' J

# C! ~2 m0 a8 N! t   VMMCall Test_Debug_Installed1 M) H* @9 Q! @
   je      not_installed
9 p/ c, m+ k) X5 T% ]$ a* e6 M& H, Q
This service just checks a flag.
8 l# k0 e; n+ }8 T4 O</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部