About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
) N. x. o. T3 ~<TBODY>0 g( Z% i& v  b- i5 }5 V  w
<TR>
8 M; \, a8 G8 a2 B<TD><PRE>Method 01
6 N. ~6 _* M0 S* D=========# [3 e5 Y. u8 s

  l* }$ P8 N9 L, {This method of detection of SoftICE (as well as the following one) is7 c1 ~1 Q( m1 f
used by the majority of packers/encryptors found on Internet.# I% @5 H, q! n) v% {: T4 w
It seeks the signature of BoundsChecker in SoftICE
2 J& D* b3 Q# u5 o% I2 o
3 j* B4 ~9 a% Z- ]2 R" i5 r5 X# v    mov     ebp, 04243484Bh        ; 'BCHK'
2 P( j5 s* t" o" r    mov     ax, 04h  V# {* F/ M$ z1 g7 Q0 K8 A
    int     3      
2 R1 V4 x. }& S3 p5 O    cmp     al,4
4 x8 y  z3 e5 R8 L1 Y3 P    jnz     SoftICE_Detected) R1 j" [: O- w+ y8 A+ _* x

7 C5 n# @7 u$ E  J8 g+ w___________________________________________________________________________4 [" p$ N% z/ f& Y$ |
4 M; W+ C% U3 t: D2 g
Method 02: @( |8 q' m3 }$ ?& T
=========
0 I! i" n( A/ W; D
$ P  d5 d: a6 l( m4 jStill a method very much used (perhaps the most frequent one).  It is used3 p7 d7 W% Z1 A- L
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
( d9 F9 M/ q$ p, ~or execute SoftICE commands...
2 Z5 G8 \* P1 D! W7 e- J) wIt is also used to crash SoftICE and to force it to execute any commands
, k) X* w! H% V# s1 m(HBOOT...) :-((  0 S# U$ g5 y, {( G2 \  |. X" O

4 F7 g+ m( a5 ]# J  OHere is a quick description:3 U& T+ ^4 Q9 P; n2 z2 r, V
-AX = 0910h   (Display string in SIce windows)4 {1 Q# B# v0 `) p5 I: s! c' O
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
3 }' q3 @$ E2 k9 U+ L7 x% ]7 O-AX = 0912h   (Get breakpoint infos)" U' ~  F" h) x7 c5 m: W; n$ ]
-AX = 0913h   (Set Sice breakpoints)
9 u; }5 T6 h/ Q-AX = 0914h   (Remove SIce breakoints)4 \+ S9 f2 t/ b2 S7 F+ s7 x
  X4 F  j5 V' I: Y( `6 C
Each time you'll meet this trick, you'll see:2 l% [' H7 v: t0 @3 g
-SI = 4647h/ |. k0 i" ^6 N4 }% U+ s
-DI = 4A4Dh
, v# B! `$ g0 q/ Z5 p9 C& KWhich are the 'magic values' used by SoftIce.6 \1 C( g4 V  e" L- W! A0 d
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.. F1 a0 K/ ?0 J% X7 B; z

3 D& R2 Z8 g9 ~# Z4 d% S; n/ B9 HHere is one example from the file "Haspinst.exe" which is the dongle HASP( f- q7 h6 a1 {) I% u7 M4 j9 D
Envelope utility use to protect DOS applications:# C' {0 T  j) Q$ I: J* x! U
1 G1 f: x9 ~: d+ c
3 ?4 |/ p8 U/ o2 }2 A2 v
4C19:0095   MOV    AX,0911  ; execute command.& r$ ]9 T+ I4 t" P2 u
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).9 o+ m6 s+ `, D' k: G2 s
4C19:009A   MOV    SI,4647  ; 1st magic value., G0 P: n: U& }& d2 H! ~& B
4C19:009D   MOV    DI,4A4D  ; 2nd magic value.! a" }& E6 v9 n; V2 ]0 y% `
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)  ~4 K$ J# m, A' Y* @9 c
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute& {4 d6 H8 U9 M- S) w+ c# M
4C19:00A4   INC    CX
, |- A$ Q9 [% z2 n, j" C2 V. b4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
) b: e- O6 g. U  f4C19:00A8   JB     0095     ; 6 different commands.6 B0 B" C5 e0 c* ]& f- x5 z9 [+ B2 H, u( s
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
3 c! {5 u3 J# ~* M( @( {* Z$ Q4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)$ P) y0 n8 ~  o1 k) V1 p
4 b9 C; Z/ Z, p, E  F
The program will execute 6 different SIce commands located at ds:dx, which
: N( A. K& ?# E( `0 l* rare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.' i. U  H4 P/ T5 s7 E

/ {; C/ \2 G& C2 O* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.- q' E6 T0 c. s- s! k
___________________________________________________________________________
  W$ r0 T& P7 ^8 O  C8 Z1 Y* y) `' I" @0 B; `+ ~+ h1 _$ k7 _' C

6 G7 N7 p3 X- q+ c6 e" AMethod 03+ q1 L, I3 @: L7 R* j2 s! x
=========- B: k1 m! T( |; W

, c7 q2 e/ b: t6 r* f/ JLess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h" v% N: c, Q, h. Y! W2 s3 Z
(API Get entry point)
1 P/ W8 C  R! T8 O$ n0 t* t; H        
! h8 v& w0 y% Q) o3 q- i) l; W- f1 _; d4 |
    xor     di,di
) e- L. \# z# o# f    mov     es,di# Q* Z* J) s4 s5 V; C- E8 h
    mov     ax, 1684h         ]$ ^) g- w6 L1 Z2 ]  w8 m
    mov     bx, 0202h       ; VxD ID of winice
; m4 {. {; y' F6 y/ b6 c    int     2Fh+ K9 m) c! E$ A  t" l$ X6 O* k
    mov     ax, es          ; ES:DI -&gt; VxD API entry point; E4 ]% ?% |) Z9 |- @1 Q6 D
    add     ax, di( a) l4 b4 O% w
    test    ax,ax8 i! Z$ _# F  U) u8 i
    jnz     SoftICE_Detected* T- r  w  {) c
  c+ O  O7 F- R( r# d: f- Z! U. I
___________________________________________________________________________
9 [2 l/ w7 A# R  e
. G( |% l4 [" CMethod 04
6 u3 }2 D4 P; C/ t9 z( {( e8 b=========9 a" W5 S3 W' k, _

4 y* A4 f) p* ~8 eMethod identical to the preceding one except that it seeks the ID of SoftICE: O0 i5 D& ^& M. A1 {
GFX VxD./ x3 p6 j5 U- W+ S+ H' u

* a( V  l! ?: R    xor     di,di
# W- U) e; E9 I  d% g( a    mov     es,di4 _, f- c; e1 G6 E6 a4 Q$ K6 V! [
    mov     ax, 1684h      
) H& Y4 F0 N8 o  Y    mov     bx, 7a5Fh       ; VxD ID of SIWVID/ `8 x% d' p  ]1 [. O
    int     2fh. g/ V( J& t! G- Y0 x4 `+ p* }
    mov     ax, es          ; ES:DI -&gt; VxD API entry point( e7 x& D5 P% _0 R
    add     ax, di
9 Y, D9 |# R7 ~2 E! P1 H4 x    test    ax,ax
6 N% z$ N# U8 Y5 k9 E    jnz     SoftICE_Detected
& C  F8 g0 Y5 Y
/ N9 b+ ]/ S% H( U6 Y' z# V9 s__________________________________________________________________________4 P9 t" ^/ e- F' d

  l' a4 ^$ n3 B1 s% j) g
4 V" P; [3 {& X8 a6 x. OMethod 05
; T6 d) e- {. a=========
/ P0 w6 m" J# g$ U
, ^2 _8 e' g/ n0 xMethod seeking the 'magic number' 0F386h returned (in ax) by all system
7 {# Q1 S+ J% w* J  R2 E  f4 Z! |( |debugger. It calls the int 41h, function 4Fh.( o' n8 C% \1 A; O+ p8 S0 Y7 J
There are several alternatives.  
3 D" ^( ~" Q. w3 Q& z8 U# J7 Q& N9 y, M7 I# i) y( X: Z8 V
The following one is the simplest:$ l3 m* ^6 }8 O* |3 {

& {! b* a  m. ^8 q    mov     ax,4fh( F& ~& }1 C; L9 M7 T# i
    int     41h
9 }# p  g9 X8 }! @$ y& T, k    cmp     ax, 0F386
8 v/ A' [. E* P% {    jz      SoftICE_detected( [+ ?2 T* j9 q2 J3 f& O5 @

+ }; |0 v% g" r6 Q0 |5 f* i$ u3 y( y% {; K3 }" d
Next method as well as the following one are 2 examples from Stone's " T6 J+ [" p+ P
"stn-wid.zip" (www.cracking.net):5 c' N7 c6 `8 B: ?& e

% ]* U: u& m2 w- w# V0 T) B    mov     bx, cs* s0 S' R0 Q- X. I, E3 L) q
    lea     dx, int41handler2
9 P4 R1 \+ H' g' i6 |- n  u    xchg    dx, es:[41h*4]# w' T4 Y* |2 c8 \9 w' E
    xchg    bx, es:[41h*4+2]: C* H4 W/ H) Y. R: j' k
    mov     ax,4fh0 s9 V5 y7 }+ ~! S
    int     41h2 ?5 n3 A+ d3 u6 l, j
    xchg    dx, es:[41h*4]
% d' s3 T. J1 [- z    xchg    bx, es:[41h*4+2]; A: ^' C& F/ S( W
    cmp     ax, 0f386h
) }3 y& `, I( R5 N    jz      SoftICE_detected% S6 i9 Y  x! p1 S) t6 [3 V
" V7 g) w( b5 e: y5 o
int41handler2 PROC
9 t: c# R" G0 R7 p) i    iret
+ ~9 L+ I, t( a6 kint41handler2 ENDP
0 ~, W: r, M$ Z/ ]9 I( x% D9 C( r$ }7 Q! L5 Q

0 {# V+ a& ?/ v; j! O3 k_________________________________________________________________________# o" d0 E3 i/ Q, |* t$ @

. h- H1 b8 |/ k# N; g' q+ c4 x. y# b( \* Y7 q' _* Y
Method 063 v/ K$ v  D. k$ X; I' L% _
=========
1 `5 i; l0 R; E4 J5 F# k0 q- m5 |( c2 b% b2 i% w

$ \3 G, I, j7 E5 u2nd method similar to the preceding one but more difficult to detect:6 H  ^- P- F, T& F3 @, h

% a, s# @3 \' K! j) h" u
  U- d, `- G- r+ F8 aint41handler PROC
9 r. f; _4 ]# j% y% G# T6 Z$ J5 x- c    mov     cl,al
: {. J0 E9 c( F- Z    iret
# ]: x) d0 k* e5 x9 i0 B6 Zint41handler ENDP& n0 @# U% c6 I2 ?; X2 O

) E  D1 @) R/ [1 O: S% L+ V; S# Z& B: e7 f' Q! b+ Q2 O& K
    xor     ax,ax+ g/ j5 E9 N5 J- w+ t% i
    mov     es,ax' h* h5 k) |- \
    mov     bx, cs
0 m: D! X, I1 t. |& h    lea     dx, int41handler* a3 |$ A0 _) ]* \4 `
    xchg    dx, es:[41h*4]
$ B- K- D2 x' h$ A7 |6 A$ [    xchg    bx, es:[41h*4+2]
4 `6 w* ?% Z0 O2 U8 c8 V    in      al, 40h9 y3 r" M- _2 u7 S
    xor     cx,cx
! y1 o0 L( a7 C9 A# l1 u    int     41h. A. R8 Z! j5 t: p# N" i% z! w, P
    xchg    dx, es:[41h*4]9 ~7 X  R! I2 L/ }
    xchg    bx, es:[41h*4+2]" T6 _  j0 @/ o3 i* O
    cmp     cl,al4 s5 H. O. `5 r$ E7 d  a" F# G9 N
    jnz     SoftICE_detected
$ i& g  G; x4 R& A+ Z( D: r2 d, y, [2 f) R0 Z9 Z- S+ O
_________________________________________________________________________
6 {, D+ l* [$ v7 E- R. X
" a  |; o* W( |, {Method 07) J- k, Q( Y4 ^. ?6 ]6 T) K
=========9 u2 k. K3 Q1 u
$ H! @/ n1 a# l4 [0 b2 T  G
Method of detection of the WinICE handler in the int68h (V86)9 @& k3 n' z) d, @2 J

  `, X6 j; K9 q2 v    mov     ah,43h4 J; ?' @1 W: i# |
    int     68h. ~- g2 B2 Q# k+ V: g# I8 N
    cmp     ax,0F386h+ F$ k: O- T3 q- k1 V( Z* p
    jz      SoftICE_Detected+ M3 C0 ]& i1 C; S' V
" ]) W0 _1 m3 j; p, M! O2 s
! F- V" @; A& Y
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
+ E, b$ H9 m5 g9 l   app like this:
  P5 Q' R& u4 h% F; l3 b, ~
. t. o2 m- B" Z, I9 }' y   BPX exec_int if ax==68
) F8 W/ V' M% ~   (function called is located at byte ptr [ebp+1Dh] and client eip is: \5 Y5 L9 G3 Z
   located at [ebp+48h] for 32Bit apps)& D+ @6 w2 v, B2 p
__________________________________________________________________________
* A2 i1 y3 u  ?# o+ |
( P. ?: e- X3 M# U3 H) }" Z; A2 _7 q$ h; P7 h; l( }( j5 v2 J
Method 08' m0 n6 s# ^* c+ C
=========
9 q  M: Q& ^: b- D& r9 c  [( v( b4 G; N, l
It is not a method of detection of SoftICE but a possibility to crash the
* M- _! B, X0 ?; K+ {3 Lsystem by intercepting int 01h and int 03h and redirecting them to another
; ?: w' x& H( O, ^  p, @2 w$ Rroutine.3 K( |3 F6 _  l" E9 L
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points+ g6 K* w4 F% d8 z$ O, q
to the new routine to execute (hangs computer...)- _; v. c# v8 Y! D* {7 N# ?, Y

6 V# g, c8 q' t- w    mov     ah, 25h
( }1 ~8 Q; b* x6 J* s* i    mov     al, Int_Number (01h or 03h)
3 U! h( E- t( e* a    mov     dx, offset New_Int_Routine" P. ?$ G8 o; ?: K  p
    int     21h
7 k3 A, S4 [) ^" D, B+ c6 r! D
0 L, s1 n& L. z. H1 d% n__________________________________________________________________________
; k( [# w) K* y" i* g7 P, \8 q) Q+ D4 `
Method 09. s$ j9 N8 ^0 @
=========, D/ l  J! ?1 y7 V- s  D

, O1 ?0 \, n: ^) q. wThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only$ ~# e" y+ h8 ?% g4 a
performed in ring0 (VxD or a ring3 app using the VxdCall).
3 ]" @6 T7 _- L( O/ [4 H+ cThe Get_DDB service is used to determine whether or not a VxD is installed& J( h0 J8 c- l' L8 M' O/ D4 x/ i
for the specified device and returns a Device Description Block (in ecx) for
" v$ u/ f9 p9 e8 L2 p) Mthat device if it is installed.% K+ ]# M9 j* ?2 y( s: y  e8 V/ A
+ k. J% d$ t7 W% @# C. j; e% I
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID/ z+ L7 N6 S; c/ \0 c! ^
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)9 H# F5 m7 y: T( E* t
   VMMCall Get_DDB
+ x4 v2 Z  x! A. F  ^   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed3 u. F9 w6 B4 f
. ]) R" }+ Y/ I& @( M
Note as well that you can easily detect this method with SoftICE:( t' ~5 x6 f7 b( o* k! H! J
   bpx Get_DDB if ax==0202 || ax==7a5fh
! ~, y8 G$ g: [2 x; M& H2 i2 M
5 A9 k$ N$ r3 S; E/ c: s! G! E__________________________________________________________________________: q5 k. c& h7 S7 R+ j

0 Z* _. S- _' j5 ]) c  }2 Y4 xMethod 10
& q- a7 ~  ~) I: j2 q/ e& o9 E& Z=========+ F0 F; B4 ^* ~1 I; z1 L! Z6 {

; S# f/ P* q* n4 C=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with2 G+ b3 E8 G$ A! x
  SoftICE while the option is enable!!
: H  s4 ]! m9 r: ~& H. n7 |: ?: O& {) d( k3 W0 r
This trick is very efficient:" t/ I& ?2 M2 t
by checking the Debug Registers, you can detect if SoftICE is loaded
$ @/ `4 w. s% b% r; \7 S(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
, H  x1 Z+ S' V, {' W, hthere are some memory breakpoints set (dr0 to dr3) simply by reading their6 }& h; `) k& d) d* \6 r* [
value (in ring0 only). Values can be manipulated and or changed as well
1 t) V* K5 D0 ?) s% `' m(clearing BPMs for instance)
' D+ `& x1 D- v5 ]# k: p
0 S/ N1 [. q- W4 X- k__________________________________________________________________________+ k+ \$ ?2 I) Q8 |% y

& x1 }4 h$ u" A- L$ O0 UMethod 11; V! m) r+ Y9 m5 k* N, p5 n  }. I
=========
. O1 b. U, b* R3 l0 W! w# ?) U7 l- N2 ]) m6 R! v- x  q
This method is most known as 'MeltICE' because it has been freely distributed/ @/ `! H  N: a, @- W
via www.winfiles.com. However it was first used by NuMega people to allow
6 u$ A/ |6 q: v, ?6 A* T& |: CSymbol Loader to check if SoftICE was active or not (the code is located
. q! N+ D' c( b8 q! G7 Ainside nmtrans.dll).
* J$ U' k: J4 s0 D) z
9 t& ]0 I) F- wThe way it works is very simple:: M# \5 Z% T7 k6 S1 ~+ `- N% }$ A
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
  N8 I, q4 W' I" S$ sWinNT) with the CreateFileA API.% k4 j- \( e8 e! I

8 N; ]6 H9 m& m+ _% e. I2 P0 Y! SHere is a sample (checking for 'SICE'):
" x" v9 }2 @9 g" B, u5 ]
, K& G9 C* G1 s3 }1 w6 k, `  GBOOL IsSoftIce95Loaded(). c9 q5 C/ \9 {2 O- A2 j/ J( u
{
: y+ Q' i$ \6 e3 y. v   HANDLE hFile;  
% M( Q0 d# \- _' X  b" x+ ]; u   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
* ^8 s7 \" \! c( B2 G; g+ g* o, c                      FILE_SHARE_READ | FILE_SHARE_WRITE,8 W& T. L& z6 C( F1 `3 ?+ f( P  V
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
  p" Q7 A2 t- a   if( hFile != INVALID_HANDLE_VALUE )
$ M  @' K7 ~# T   {
& ^' ^. Q8 m2 D7 M! w      CloseHandle(hFile);+ I  z% Z: |) S* y( h" }
      return TRUE;
" \. G* Y8 T; ~- N   }
% @# i; F0 F+ O$ m$ p   return FALSE;; B+ d# N6 H7 x1 Q0 O% s
}8 @2 o3 n) H  D/ l7 ?$ y2 _& P; a

3 O, ^3 m7 i: J1 l3 OAlthough this trick calls the CreateFileA function, don't even expect to be2 L# L% x* R" \! {* b7 u
able to intercept it by installing a IFS hook: it will not work, no way!
: z; R- E5 C" cIn fact, after the call to CreateFileA it will get through VWIN32 0x001F6 y& N3 W# M' R" V
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)% k/ V3 _- A# E
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
" s  a. @, q, I" w% l# pfield.! Y  R: t8 b& d; X6 Y4 e
In fact, its purpose is not to load/unload VxDs but only to send a 7 R' U, T7 R- i5 o
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)# G: {  z% l0 d# Y5 X8 h
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
: v3 r+ {9 W) \to load/unload a non-dynamically loadable driver such as SoftICE ;-).
% v5 P* B8 S- |1 u* v' IIf the VxD is loaded, it will always clear eax and the Carry flag to allow/ K2 H! E$ n$ ]9 d) v5 I$ Y
its handle to be opened and then, will be detected.
% n5 w2 c# N* p( S9 ]7 cYou can check that simply by hooking Winice.exe control proc entry point; o4 N3 K. }+ }" n9 r: W/ i# o
while running MeltICE." `8 b$ |# b) S  c0 R& V

& R5 U0 f7 f4 e5 _' s
' v7 U6 _8 ~8 k+ a; K. N  00401067:  push      00402025    ; \\.\SICE$ L6 h6 c8 a% m$ b7 X+ L
  0040106C:  call      CreateFileA4 n7 T) e# B$ H: w- b9 b
  00401071:  cmp       eax,-001
+ X4 D% C# B1 `; T; E/ f& R, c5 a& m  00401074:  je        00401091, C* ]# Q( s2 }0 G" ], C* J2 t) a

0 k( ~  w; F- D) `1 G
0 g9 H. T% C& N7 RThere could be hundreds of BPX you could use to detect this trick.) V$ r0 G4 h  [( P0 c* D
-The most classical one is:3 \0 x5 \5 E6 v0 |
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||; e) r, T8 u1 }
    *(esp-&gt;4+4)=='NTIC'
. ~7 t: v. n9 Y! h
# j1 S3 ^: w3 k1 J-The most exotic ones (could be very slooooow :-(
4 s, ~9 [& r6 D9 d1 F   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
- e/ O2 g" @% z/ a# b, k5 k     ;will break 3 times :-(6 v7 [0 A: ^% c& v

  H6 U/ e# [& i# g6 X, E) x-or (a bit) faster: 1 ?% b$ q4 v; j6 H' n# D" u
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')& }: @7 s& G3 }: R' M9 o
( l) w% y: ?% F& }7 r! C6 a# ]+ u) N
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
* x* X- A- C% I' T% D: _  j     ;will break 3 times :-(
5 s( A* s  J' }9 Q6 u6 j
) `1 u8 v9 Y" a& @& }7 k" H+ C-Much faster:3 l2 l( d1 I* N7 ^9 Z
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
& o6 r* K1 {8 F& p7 Q  u3 V: e) I
7 b% C% D5 z/ ?; }Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
+ ?0 U$ g+ j  H" [$ C/ c7 |function to do the same job:
( [; \4 R  [1 e2 b, a  D
( G! G$ r- g# m' h; K/ K+ Z   push    00                        ; OF_READ) r" {: @2 r" j7 X: x
   mov     eax,[00656634]            ; '\\.\SICE',0& g2 s* T/ ]. _
   push    eax
; v" Q3 Y. n9 |4 A* ~* ~   call    KERNEL32!_lopen
- j& P: x3 m7 q) U- q) e   inc     eax
1 I  ^( X, v$ f( d. _   jnz     00650589                  ; detected
# k2 t7 c) N9 c& E   push    00                        ; OF_READ
& o# u* x/ v$ H$ Z   mov     eax,[00656638]            ; '\\.\SICE'- ~. V5 N) ^7 E  {, a
   push    eax* K9 V4 |3 Z3 |' X& F+ O' y
   call    KERNEL32!_lopen& I! O9 K7 ~2 w* ^3 g0 d6 f9 S+ T
   inc     eax+ z" x' a+ ]. C8 J$ l! U
   jz      006505ae                  ; not detected- z. r  b- Z1 v6 N& C! c6 }5 K- [1 m

- `9 T- a2 d0 }& h! L/ o! r! T
9 R9 A, B( b5 l- O, s__________________________________________________________________________
2 p: N4 H$ ?+ r" D7 J. Z! T( |0 Z7 ^5 q" a! w; E8 x
Method 12) `" c  M+ W( f6 n3 f
=========3 d6 p  D% j2 N, i6 l2 @# E

9 F; Y4 F8 P: x! e  }% YThis trick is similar to int41h/4fh Debugger installation check (code 05
, _4 ]$ a+ F8 ~9 Y) E" ^9 q. H&amp; 06) but very limited because it's only available for Win95/98 (not NT)
# T* B: [) E  U1 }9 J: f2 b' g# u7 H* ^as it uses the VxDCall backdoor. This detection was found in Bleem Demo.9 F5 ~8 N8 a; o& M
6 O+ O7 F6 b  S- R
   push  0000004fh         ; function 4fh# @7 c! u! U" Y" ^8 [" u# e
   push  002a002ah         ; high word specifies which VxD (VWIN32)
. p2 D# ]& ]0 ]" ]9 a                           ; low word specifies which service
7 w5 B& }1 v. S9 E. o$ `: Q                             (VWIN32_Int41Dispatch)
: A  L& q. Y4 s9 S6 x3 ^5 }   call  Kernel32!ORD_001  ; VxdCall
$ P7 f# R; Z) s) s2 w   cmp   ax, 0f386h        ; magic number returned by system debuggers! T4 o. c2 g+ Q/ g1 N; E' p" c% P
   jz    SoftICE_detected8 i* A3 ?2 J8 `( ]
0 E' B3 c! u! }/ e
Here again, several ways to detect it:) [3 ?8 L9 R! t, ^+ L# D
7 z1 D0 L  J, j
    BPINT 41 if ax==4f$ N6 t3 {2 S4 B' z! q
! z8 U2 }7 R" ]3 t5 P" s6 O
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one: z! Z! J7 S# r5 G: L
) ^, U) B7 v& T4 g5 o, a# z2 T
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A# x7 ?# ?( O# e. B0 H- ~# u9 u

" @/ s9 D; N! U/ G9 m' Y    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!% J  |" ]1 S* t1 s
9 s4 J" B4 a& t2 \6 \6 M( A6 I
__________________________________________________________________________
6 I& o/ L3 \9 P/ k/ X+ ?% [6 a8 G8 X' D0 u# Y. c
Method 13( ?# d9 ?( r! k2 |$ z+ u! g
=========0 Y. @5 N! m* R9 q

4 ~, D2 n$ d, V" XNot a real method of detection, but a good way to know if SoftICE is" I: s9 T$ W" P
installed on a computer and to locate its installation directory.2 V+ \& l1 J: O$ [
It is used by few softs which access the following registry keys (usually #2) :
5 N/ _: s- B) d% Y0 g8 @1 J! I4 ^; O
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
; j: ]: M, x4 h\Uninstall\SoftICE/ u$ j8 h5 x  N* M
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
/ B5 V! [  ~% v/ k" Y1 j5 P9 _+ C-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion# c9 M& o) c/ Z0 \
\App Paths\Loader32.Exe: q4 `  G* t9 {7 C; q# J1 W

5 h! z3 _- E* _+ O  A
- t5 [1 i1 L+ o* N# c( uNote that some nasty apps could then erase all files from SoftICE directory/ h5 H/ w; k+ Z9 l. f: M  S
(I faced that once :-(
4 O) W' W) O+ z* x! @
; D4 q6 {( _, u) ]4 l, d% ?5 w+ iUseful breakpoint to detect it:
- z. a! g1 T$ P- v* q: G. l3 E3 h0 O' i* B4 ~0 T1 m
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
! W5 a: x0 Y# V0 o
, w; k# B  |* y1 o__________________________________________________________________________' d2 f7 r" y, D5 P' K! C

7 m3 A# u7 z+ P1 j+ y$ Y: l( n
% `! T5 L% N* `( ^Method 14 ' |5 W- ^2 c9 Q
=========& O$ n' o4 d. s  n* _& g, f

+ y' ?, E3 c, N3 x/ yA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose: u9 o: W; E. A1 b4 }; {
is to determines whether a debugger is running on your system (ring0 only).1 E3 r, ?# t# S- i, X

" d) N5 P& R5 \: Z0 h   VMMCall Test_Debug_Installed4 L* G3 t8 j2 ^7 m
   je      not_installed  b4 e, B% `4 }' I

5 d4 b, R2 {% ^9 D7 H; AThis service just checks a flag.
2 ~# y! C/ S" x2 c1 k% M' Z* ]</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部