About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
# A! n1 ]3 W# H# e6 n<TBODY>
" ?1 y& q3 G6 z  L% E' ~9 k<TR>
* e+ `0 R. ]& ?8 d: `, V2 A<TD><PRE>Method 01
# R7 @! n* Y) b" p- j=========
8 C2 L* ]+ `1 e% A- o! Z( d' f1 }* _* \' G9 g
This method of detection of SoftICE (as well as the following one) is
4 a; E; \" O1 {. O8 u. }# L/ aused by the majority of packers/encryptors found on Internet.
9 X8 g6 |$ I1 b5 b& `It seeks the signature of BoundsChecker in SoftICE! R. d! g4 u7 Z% q7 n9 n5 l

- P0 Y( h) Q' T$ v    mov     ebp, 04243484Bh        ; 'BCHK'
5 i/ L# u# j# ?8 R" P    mov     ax, 04h
* x! ~4 P7 \$ N+ h    int     3      
, q, P& n0 f, G2 U    cmp     al,47 D4 x. ^% d4 w6 ~5 F
    jnz     SoftICE_Detected# ~" W5 A, D  O2 d% S% b4 E: l

7 o9 R  e( Q- E. `4 ^; |___________________________________________________________________________
+ z. R( f; }2 V; |  f) k1 [- n7 R2 y3 q( c* k( M: Z3 q
Method 02: C6 h) ]( B% Y% v. ~1 J. P
=========  N5 G2 k. Z( U  {2 V
: Z; p$ H& z. p
Still a method very much used (perhaps the most frequent one).  It is used
' \& U( o. @  d3 |to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
$ l# H  e8 _2 T, V1 ]or execute SoftICE commands...
& X/ P) I( L; c* k/ @It is also used to crash SoftICE and to force it to execute any commands+ U9 h3 G; r, t; y! m
(HBOOT...) :-((  . [3 |: w5 e9 `$ y: |7 o

1 ]  X- T: `' ]$ V0 ~# U6 J4 h) fHere is a quick description:
6 Y# k8 T3 N% Y/ w-AX = 0910h   (Display string in SIce windows)3 H6 t% ?- T, V1 l, m
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)0 J/ b6 }" J% T; k1 d: w/ S$ ]
-AX = 0912h   (Get breakpoint infos)
' y' N' M: |! m6 T-AX = 0913h   (Set Sice breakpoints)) e5 k/ k% z4 O: n7 O0 @7 p
-AX = 0914h   (Remove SIce breakoints)
' X7 ~% v' M( u4 o% _, E: w9 D' p( N, K# Q4 ^( }4 i* F6 v
Each time you'll meet this trick, you'll see:
, d+ m* x! {+ i; d" h7 o; m% r) i# S4 z-SI = 4647h; W0 d  M5 v* j; Z. k  o2 H# l( W& e
-DI = 4A4Dh8 o# Y6 u, J4 F" v* b# T7 x
Which are the 'magic values' used by SoftIce.
$ A: ^- P1 `& U0 s3 F: z* gFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
) U5 }3 ^( {% ~9 R
5 i3 Z9 x. R8 N- R  i: X# A# _+ NHere is one example from the file "Haspinst.exe" which is the dongle HASP4 }- |. H/ s1 W  b  u! v
Envelope utility use to protect DOS applications:
3 c* K/ N- ?6 J
7 _3 {$ {5 p2 B: }
8 A2 m2 D7 v: A9 p- \7 W- R, G1 f4C19:0095   MOV    AX,0911  ; execute command.
0 B" Y; Q3 f8 I; m4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
' @. s! H& _- n* L: O4C19:009A   MOV    SI,4647  ; 1st magic value.; W! M2 K' X( ^& j
4C19:009D   MOV    DI,4A4D  ; 2nd magic value./ j, h, M9 s* W2 A+ S* R3 R  f( e+ r
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
! D! D; [5 x& V0 }, N4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute9 E' l- ^/ J4 [$ ?
4C19:00A4   INC    CX5 h4 a/ Y2 B2 ^3 x# N& F% K, T; ^& c+ [
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
3 i. c  r/ B- U4C19:00A8   JB     0095     ; 6 different commands.$ K' @7 X+ u+ g% H2 a, H" {: U
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
& P! t5 P4 K0 m4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
: c# {$ z3 S8 N3 z
3 k* n1 R: i6 ?The program will execute 6 different SIce commands located at ds:dx, which
) p" H  ]$ ^% [9 t2 tare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.8 L* m3 |& J4 U2 l. ]' ?

! ?+ P/ b5 a" h) H* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.9 I% i, P' v2 G; `: w& w; J- |
___________________________________________________________________________
8 f4 T$ {4 U% L. [1 d' x, _4 _3 m2 y+ Y/ N0 `7 L

& Q9 p8 G- @: }$ H* N* MMethod 03
# v" h6 d* K4 j9 N* n=========1 _/ V/ |6 `8 e: e4 z
5 E6 u, M/ q3 L' }
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h1 Q3 R( i) g/ k3 F/ r; d) i
(API Get entry point)# a  E% l3 h7 R
        
/ r( N& }2 t6 |4 U! j, e, K& i# t- W  \
    xor     di,di
+ E  E" |& R. ]+ \8 K7 b2 c, x    mov     es,di
6 T0 @7 y% T4 E( q0 T    mov     ax, 1684h      
! `. D6 ~0 v* {    mov     bx, 0202h       ; VxD ID of winice4 B8 Y2 N7 V& O9 R& s( O; R% F
    int     2Fh) {6 C( Y! S6 f# n1 s: Z
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
0 o+ U4 e6 @1 a( U+ G- A6 F6 X    add     ax, di: B1 ~+ u8 _( b+ c$ X2 m3 e  o
    test    ax,ax
; c" ]  [: m6 m! f; R    jnz     SoftICE_Detected+ ^$ Y8 f! B% i) G

1 _( E! X% _. K0 z$ T$ C___________________________________________________________________________
6 W- L" M# z' n: ]( p/ _0 x- _* {) J2 o8 G5 y9 y' H/ n
Method 04
5 _; {$ U6 H) r3 I6 N7 C=========
& B; U2 Z, `. t6 S6 i5 z! R
& L; F/ l9 e4 k: X& |! d  K" \Method identical to the preceding one except that it seeks the ID of SoftICE
1 {. W( r3 Y0 Z6 ?GFX VxD.1 [) g0 E0 }, b- n
. ]% d# B  A4 `, K, u- l* g7 r+ u
    xor     di,di7 W% Q+ o+ q) j) r$ G9 ^
    mov     es,di
6 B4 z( y# K5 a    mov     ax, 1684h       9 \$ o8 ]/ t! |' \3 K
    mov     bx, 7a5Fh       ; VxD ID of SIWVID% i: y* a8 Q! g% d7 u
    int     2fh
( O0 Q7 O8 E  u- ]9 s    mov     ax, es          ; ES:DI -&gt; VxD API entry point
$ V2 c, s. A8 D0 v8 e    add     ax, di1 [% a/ O; C7 R
    test    ax,ax: c/ @& P. r( m& C+ A+ C* W
    jnz     SoftICE_Detected
2 {4 V) Q& f5 y6 V$ ?, [
8 d9 E# b: L4 P6 @# X7 g6 k__________________________________________________________________________7 j. l; N+ ^5 _7 j, \
! d1 P2 v" ]5 q, |

- g2 U- n5 L# ?! _' a: b3 ?Method 05
) @$ n( L6 J6 }6 o5 j$ G=========, @6 W1 i7 D; b, D  v
5 e4 H9 Q; g# B7 N) L3 L
Method seeking the 'magic number' 0F386h returned (in ax) by all system, V, Q# `' M2 N
debugger. It calls the int 41h, function 4Fh.$ {% i  |6 C* N8 P
There are several alternatives.  
6 T% Z1 y* C. k
: y0 H" q; Q$ V& X7 Y8 ~The following one is the simplest:! v& V* O0 l1 {

: D  X: l. D$ M6 A    mov     ax,4fh
0 m. Q+ g1 ^; d6 y% [8 @/ C3 T    int     41h' e6 {! m% X+ }$ e5 u# E
    cmp     ax, 0F386
8 P2 S) |8 M" W7 B1 J+ \% x    jz      SoftICE_detected$ o) ?4 Y$ A# r' l% z+ z5 S
$ [+ e% b6 V/ o1 b: D
& i; `3 c9 K) f% X" C3 t0 S& t* h& V
Next method as well as the following one are 2 examples from Stone's , I  ]) J7 Q9 a; b
"stn-wid.zip" (www.cracking.net):  y/ h% @. t9 T: ^+ h8 }. |7 Y
1 u, G. G3 T" u; d3 R
    mov     bx, cs
7 K2 ~! V& ^  v% V2 z    lea     dx, int41handler2
2 b8 X* a0 r: n- n. q9 w    xchg    dx, es:[41h*4]
0 k9 t( p- w6 j+ ~5 v5 t    xchg    bx, es:[41h*4+2]# F  V; S1 k1 ~, }4 ~' e  X4 A  `/ Y+ w
    mov     ax,4fh/ g/ m, ]. ]; M5 x5 K+ Z" S
    int     41h
1 d4 w/ \- x! d" p' U    xchg    dx, es:[41h*4]
) p0 u, P" V" Q+ J    xchg    bx, es:[41h*4+2]
9 S7 X9 `7 z% ^3 p! b: d    cmp     ax, 0f386h
# O, a7 {: d* M1 Z& c: V, D    jz      SoftICE_detected
8 u/ P4 @: C6 w# r+ u0 l2 \) T5 Z7 L; W9 \2 w
int41handler2 PROC9 `7 T  d8 L& Y2 x6 @' Q  j  [
    iret
* `, L/ ?& m: v# I8 wint41handler2 ENDP
( n& b. d& f, T) J0 s* i
+ C+ u. U3 S9 g- p$ O  n. c: V( E* d
_________________________________________________________________________( j- R' o4 u# M
! W3 A1 a: Z! J- J9 O, \
; q2 c' `6 q4 M/ `. c" `/ E, m# H
Method 06# G2 Z- ^  U" d# j, \7 |
=========. i6 ~- |! M- L& v3 v
" N* _3 w9 B0 A4 B, s, n
# B  r4 M6 _3 T8 w
2nd method similar to the preceding one but more difficult to detect:
1 k, Z; c+ K5 {% D% \
; c: F2 j# n5 h1 a) p, G
# T8 W4 p+ T* B' F& B8 Iint41handler PROC- B2 n  f9 r" J9 r0 W
    mov     cl,al6 p0 J! D1 |- A8 I) B# h' H/ I5 B
    iret
, t1 j: C% N( C) tint41handler ENDP1 @6 f% R! Z5 W- }" O) O# X3 q
* i0 ]% N: E, N* C  U& R
$ T( Q- q% x  @5 J5 T% ]; }
    xor     ax,ax! ?: r3 M) d- d7 A% [  S! X8 I
    mov     es,ax$ F# d4 x2 ^* V7 S! R9 y; a
    mov     bx, cs" A: s9 i' ?% A) z
    lea     dx, int41handler
9 h: ]! M% i7 n: Z! f. }6 p9 ]- _    xchg    dx, es:[41h*4]5 b' X. A7 w( F
    xchg    bx, es:[41h*4+2]( _2 Z4 X# r6 {2 L6 G% c2 u+ E
    in      al, 40h
1 Q+ M1 A1 r4 D% C    xor     cx,cx  f" L. E) I$ _
    int     41h7 \9 w% ]" ~! h7 v2 H
    xchg    dx, es:[41h*4]5 I$ K* c+ V$ O0 X
    xchg    bx, es:[41h*4+2]
' _1 c4 ^# R7 D3 {    cmp     cl,al
& l9 b; Y: A& R( a& M) G( n    jnz     SoftICE_detected  M' t3 [: R9 ~/ q+ P/ W
) r+ z! q3 Q% B+ F, q* C
_________________________________________________________________________" ~$ G- n# b# E4 ]

. q2 C6 L. H0 b$ P& e4 m5 S1 `! y& `Method 079 |+ x4 X# i! _: Z
=========
" u! j* P$ z0 ]2 \& s/ n, `. ?2 i/ Z
, F6 y5 b# U; K) r3 S, OMethod of detection of the WinICE handler in the int68h (V86)( o$ Y$ c' S/ n5 M& r% c& G$ j

( l: [8 T1 \& w8 J( E! ?$ N    mov     ah,43h
/ N" s0 X4 J7 g: b    int     68h
: s, l. t4 j2 {- s1 {( z    cmp     ax,0F386h: l% i* g' n0 {! d7 I
    jz      SoftICE_Detected
+ ~/ \( n2 w* R  c  S; Y: J
' e2 U9 `' N0 {4 C! ~5 f# @8 ]1 S; ~" W$ _1 ^
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
9 N( Y1 U4 w: S+ \) F   app like this:
) R# E1 Y( j4 p3 F! a: d/ F$ _
  d, H% m6 N! t) w" O   BPX exec_int if ax==68" @, z, y: ~% z
   (function called is located at byte ptr [ebp+1Dh] and client eip is4 T1 x* P6 v  ?0 @6 A# v" ~: s
   located at [ebp+48h] for 32Bit apps)4 p' m# N; k$ x- e/ z
__________________________________________________________________________' |8 I8 \5 y! x9 x' p% _& \
0 X. I' ]; C2 r) F

) z5 I/ u; I; |; EMethod 080 f7 g0 F. J  }1 _" [
=========
  ^4 a1 [0 ?6 y; ]4 K+ u0 `$ q0 W7 H( L8 y9 f9 q) p) O
It is not a method of detection of SoftICE but a possibility to crash the0 _* u, H2 f( j2 D1 Q7 I- F
system by intercepting int 01h and int 03h and redirecting them to another  `' j% u3 [3 ~) [* r9 ^7 j* G
routine.
6 X5 m4 K- ]" |0 |  mIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points9 Q  c- S( h& x/ `
to the new routine to execute (hangs computer...)
3 X3 i" n) r& _0 N; @% x! K$ a# a7 s2 I$ v) b/ z, m, N3 m
    mov     ah, 25h% Y( b8 x, E/ f: {
    mov     al, Int_Number (01h or 03h)
4 y) ?4 q  K1 Y& ^    mov     dx, offset New_Int_Routine
% o" \- D- y5 {$ y& z    int     21h
2 E: {* W# h$ [, u+ s' ^6 X, d8 t
__________________________________________________________________________0 m3 o* c; I* g" m6 j% T1 Y

" }3 e1 K1 R" D2 ?Method 09
( Z$ x* X9 W) C. \=========& c' i; k/ s) k! c

5 B' g/ W. L) ^- nThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
. ~$ d" Y/ l' w) Tperformed in ring0 (VxD or a ring3 app using the VxdCall).
3 y- ^  h: Q  |2 {+ f1 G: ~' yThe Get_DDB service is used to determine whether or not a VxD is installed* z4 N/ t/ V( m2 u
for the specified device and returns a Device Description Block (in ecx) for
8 i/ B4 T' x9 U$ hthat device if it is installed.6 z4 c1 U; q) p# A
/ ?0 V, T+ g, }- M
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID# b6 F! K' |8 u  p
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)* g1 _* E4 G- P& q2 N+ \' f( O
   VMMCall Get_DDB
7 c- i( C) I5 i- k3 k5 \$ G9 }- ]2 A   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed  E0 `' a, _: d9 g5 s) v6 ^/ k1 c& \
. s( L! i1 u+ h) Z' S
Note as well that you can easily detect this method with SoftICE:
" w" ?7 g( ^* D; ~3 I   bpx Get_DDB if ax==0202 || ax==7a5fh
" |8 d+ o. f) F
" h) \( {6 \) y1 K* f: m__________________________________________________________________________- H2 M6 C$ h) t6 Q5 a# Q, h

( D. @3 P$ Z& L( sMethod 10
/ B) O0 B3 A8 I. B=========9 ]* A- ~* a5 W# p  ]- w  `
# r2 j5 E; ]. g9 w
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
' A) Q0 i* a7 N6 t7 k$ W  SoftICE while the option is enable!!6 m4 ~2 C0 ~! V3 X( s) @0 k& U
- i0 E) B) Z" _& |& _
This trick is very efficient:
& T( a8 l- w; w: T7 r* K8 U# Fby checking the Debug Registers, you can detect if SoftICE is loaded
$ l0 H6 E! d9 V(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if6 M) F; c& T- g. q/ j$ M* v; h# h
there are some memory breakpoints set (dr0 to dr3) simply by reading their
3 G$ Z1 s4 w6 F$ Tvalue (in ring0 only). Values can be manipulated and or changed as well! q6 O# P4 f' `
(clearing BPMs for instance), B: s- m7 }( c2 Q7 C' {& s- J
7 f& |* y# `. d6 Y
__________________________________________________________________________* a- s7 u1 `; n; u5 C/ [. v: ^4 O  A

5 y6 V3 Q+ t+ z2 vMethod 11, S" v# L8 Q4 c2 t/ N) o4 W; v: o7 [
=========/ U2 z& ]( o6 K+ ^. d

9 ?8 |- ]7 B9 aThis method is most known as 'MeltICE' because it has been freely distributed
1 {1 N! _5 o0 W4 `8 m4 Mvia www.winfiles.com. However it was first used by NuMega people to allow
7 H) W* e, G1 Z( p5 n# `0 z4 fSymbol Loader to check if SoftICE was active or not (the code is located0 C8 z* U$ z# F4 v
inside nmtrans.dll).7 `% u0 W4 O5 A' W& s6 e) i& N

* U, V$ w* G0 ]; k# Z/ D! qThe way it works is very simple:( B- J9 g. C# k& S6 `; v
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
8 K0 s$ S! Z  z2 ?WinNT) with the CreateFileA API., E! [" j! X7 R  _. b; M- Y- F
$ _1 ]: y' D# d4 I$ T" N
Here is a sample (checking for 'SICE'):
. w6 e, w; A4 c1 f, [8 G* N3 r/ g* C% v$ O# ~! W5 Z+ P
BOOL IsSoftIce95Loaded()2 K: e/ }6 N5 }) R
{5 M0 Q8 z# D; H4 m
   HANDLE hFile;  
' L6 Y% y- S6 T  |1 H   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,; y# x) J% M5 r+ \% \% Q; j% ~
                      FILE_SHARE_READ | FILE_SHARE_WRITE,* O* j# Q- d. y- u
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
* c3 Z- [. L! E  B0 q4 X5 k   if( hFile != INVALID_HANDLE_VALUE )
) V5 q& \6 v3 @' y( i7 b, r, U   {
% {3 U( W2 s. {5 H' L      CloseHandle(hFile);
1 O0 d9 L& D; H0 J5 N3 x% ^( A      return TRUE;- T* W6 n: e6 V9 K6 w" _
   }5 Z( e2 n4 k! Q: {- g7 W
   return FALSE;
9 |$ k- X+ O) _7 ^8 `0 i}
, h0 c0 I0 Y7 L  @' ?
0 ?0 T$ k- s  QAlthough this trick calls the CreateFileA function, don't even expect to be& ~. o; T: k' {. Y
able to intercept it by installing a IFS hook: it will not work, no way!
6 V" f) X, I  f" \5 Z( DIn fact, after the call to CreateFileA it will get through VWIN32 0x001F% P5 r9 i3 T/ [
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
, E% @7 p' h5 @& @and then browse the DDB list until it find the VxD and its DDB_Control_Proc
- w: P2 x4 s  _4 bfield.
" Y# s6 y0 t$ y: j  u6 F" nIn fact, its purpose is not to load/unload VxDs but only to send a
; [- k/ _- ?( F6 PW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
6 a; J1 |3 ~% m* @& s' eto the VxD Control_Dispatch proc (how the hell a shareware soft could try) @; W4 F* k, F" V9 c5 _
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
/ H: ^" F- o9 _. w; s+ HIf the VxD is loaded, it will always clear eax and the Carry flag to allow/ c, l. O; W$ ?, M) b2 ^% D
its handle to be opened and then, will be detected.
' _. J( B. ~3 B0 Y) R7 w3 s1 aYou can check that simply by hooking Winice.exe control proc entry point; z1 Y2 y( b/ a  U. K
while running MeltICE.7 [9 l- i% N8 \' R

, ?$ r2 F& W* K+ m
# y* |" L8 c: N7 y  00401067:  push      00402025    ; \\.\SICE! ^' ^- T: N" Q/ @4 N6 c  }2 u2 d
  0040106C:  call      CreateFileA1 S. ]4 p2 V# {2 t& j0 n- I
  00401071:  cmp       eax,-001
$ {; c& l0 y5 }7 C* z. k+ p3 c4 a  00401074:  je        00401091
& g+ O5 b1 o( j) V0 z0 b
. {* M8 j" U# @$ O2 Q" B9 W/ b) m- E9 l* k% V8 W5 f4 O
There could be hundreds of BPX you could use to detect this trick.
( r, g, Z( y/ e5 f1 u* O-The most classical one is:" o, t! u$ w' U) M# [' J; M
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||. r, q) {$ |3 G0 W, B6 F
    *(esp-&gt;4+4)=='NTIC'9 Z$ T/ j: ?% c7 f

1 f: Y" s) j2 x6 T' V" n2 k-The most exotic ones (could be very slooooow :-(
0 }! Z& i& C5 M2 p+ u5 p* `   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
3 M" B, Q* |' }; h; C     ;will break 3 times :-(  e  R2 B9 i# l5 B# B) ]
, G) F% j* G7 x3 [' d  u  g
-or (a bit) faster:
) w: I/ t, h# d% _1 l   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
3 x6 r* C. C$ N3 C; {) U  k$ s! z; t$ ^/ T9 `5 }4 u
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
. Q3 `2 q& h& {7 w: d* |% w$ E     ;will break 3 times :-(% W% w/ }( |% O4 h4 E6 @8 H6 P5 F9 ]

, P& N0 k1 i9 D6 F1 j  Z  J1 ]-Much faster:
( ?0 h9 @3 E/ Z9 R/ W: q4 [3 O   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'- i; ]  o/ A1 Y6 a
$ c  w9 j7 d+ }4 F4 n# \/ K
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen4 [9 c' N8 ?" _2 E2 ?
function to do the same job:' L9 O% z+ f! ~! V% Z. S
" Z: k" E$ I! M, W& M, b
   push    00                        ; OF_READ
; D, I" y$ h; z) n) g   mov     eax,[00656634]            ; '\\.\SICE',0
  U1 v7 Q' y$ u- `5 H' W   push    eax( O& e8 i3 i$ i9 N* P$ U
   call    KERNEL32!_lopen
* Q0 A6 D& s" Z0 @& P   inc     eax
5 b* C* _8 `5 n- ]   jnz     00650589                  ; detected
$ K( z+ r7 ~. {. I: R7 [   push    00                        ; OF_READ
! [; a% Y* z( j, G   mov     eax,[00656638]            ; '\\.\SICE'& |# q4 z, b& F
   push    eax
7 R# t9 v" U3 U7 O   call    KERNEL32!_lopen
6 l7 l# t& }; W   inc     eax
4 x# s$ d; \  o. c   jz      006505ae                  ; not detected
$ ]1 d1 l0 p7 f1 l, W, x' @1 h2 _  l4 _- f+ f9 @- M

0 v$ J: D, F! E7 ^/ F__________________________________________________________________________
$ n8 T0 N8 a/ J# b( e7 S0 I8 e9 |7 h7 b# e7 H
Method 121 R0 [. f- E- r/ I1 p! B
=========3 m! q1 J3 o2 l; S: C( b& r
5 G' w1 F* r) f* ?& o
This trick is similar to int41h/4fh Debugger installation check (code 055 z" F; w% N! o6 m/ L. R
&amp; 06) but very limited because it's only available for Win95/98 (not NT)
5 ?! h2 ~( @. las it uses the VxDCall backdoor. This detection was found in Bleem Demo.
3 s6 e! h6 E- }( H7 j# @- n+ t6 e8 K/ P* R2 v, C+ r; q
   push  0000004fh         ; function 4fh6 S# y' S- T2 ^- I. ]
   push  002a002ah         ; high word specifies which VxD (VWIN32), H! l- o% D" E* H+ Z2 b4 l0 Q
                           ; low word specifies which service4 N& R% X9 h. c
                             (VWIN32_Int41Dispatch)3 Q( V9 ]9 E" w8 }5 d
   call  Kernel32!ORD_001  ; VxdCall4 D4 G) v; y0 C& Z
   cmp   ax, 0f386h        ; magic number returned by system debuggers
0 Y1 K5 F' ^& ^* l( c' }   jz    SoftICE_detected
  c- [; Y+ W1 o6 z
" o8 f8 O8 m' B9 l0 J' ^7 WHere again, several ways to detect it:
, ~& U! [( o2 a0 p/ c
/ a; I3 m. \, j2 m- w/ X' S( t4 S    BPINT 41 if ax==4f
& s, P8 _4 y/ F# c' w/ O
' |+ c6 A( Y- W1 c6 l* r    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
* D* D. Y/ i* h3 x
+ u; ]5 ]' Z3 O6 {" V* l5 i: \    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A0 T8 }% Y+ i: ~, a( r% U, Z
9 X/ i$ O& i& C9 z8 r
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!" u" g7 [" X# V
  L, o* a* m2 |* e$ j2 \6 q
__________________________________________________________________________2 }* G* L: i: e& [1 M. O
, O8 z5 K6 q# k* W( N  W8 g, @
Method 13& k8 }; Z6 ~' }% T
=========. ]6 F3 F. M" B8 C* c6 k! I
* ^0 W4 o5 s2 L3 e% _
Not a real method of detection, but a good way to know if SoftICE is  q2 E$ g5 p3 @! J. E8 b. d& t  u
installed on a computer and to locate its installation directory.5 w! F% e- s/ k& t" R' K; f# ~
It is used by few softs which access the following registry keys (usually #2) :
6 j. r" Y% b% ~) S' u# `- i& A
. k5 m' c" i) p7 R$ g; w. V-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion/ U6 P6 P/ }0 Q! _" C( F# c
\Uninstall\SoftICE
9 A7 f0 m( H5 R! J, H( ^# @-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
" X3 F! J7 Z$ D, A3 |* q-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
# ^4 V0 I! c) K2 M3 g% }$ x\App Paths\Loader32.Exe
/ }) z8 y9 e( }& s0 Q- L
" X9 }* y% i2 H1 k* U: F# D; n4 F0 I! f! [% \- o, B8 X
Note that some nasty apps could then erase all files from SoftICE directory3 P, m; T- Z' r% K
(I faced that once :-(, m2 F$ n8 t1 \$ X9 }( A

+ H$ Z$ ?( Z- c# f- lUseful breakpoint to detect it:( d; N5 k4 W. m% p
4 G2 {# u- Q# J, J
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'/ n" V! j% Y9 T  c
) I5 g$ L! o) E! x5 s& y) X
__________________________________________________________________________
1 K' M+ {# J) Y1 F
  _4 [- E; U  W1 e% [( g) X  t5 p5 }+ P- b
Method 14 ! ^! J5 d- h3 W4 T
=========
- e  n1 n# w$ R% W% A! U* F0 l) |/ K* m1 v
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
( w0 {% J) P; u4 O+ Xis to determines whether a debugger is running on your system (ring0 only).
+ H5 u7 u" A+ V5 O8 y6 k3 c! @; R4 I4 L4 o5 n0 ?
   VMMCall Test_Debug_Installed
& T% S& }2 S3 b1 v# I% z   je      not_installed) S% T' D( Z! j" Z; M7 D
# u( R& f# \) d1 O* M" o
This service just checks a flag./ ]4 [" F( y# R- w; k8 q
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部