About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>8 j( I  `- e+ o9 _1 Y( O7 X
<TBODY>; n# B) L+ O4 Y& H: s( u+ x
<TR>
5 c1 G, x( @5 o8 x' d<TD><PRE>Method 01 3 s% N; l* T- {: m
=========
4 `% @- b: i( A0 d+ E* @. Q3 t& q8 J7 y/ y1 x  k
This method of detection of SoftICE (as well as the following one) is, O3 m4 B) y# \% r; _) I
used by the majority of packers/encryptors found on Internet.
3 E  G! F' @. g6 M" U; [# GIt seeks the signature of BoundsChecker in SoftICE
9 u$ m9 h, `  Z4 C1 O
  E( T6 \0 k) I1 u( r9 p9 }& K    mov     ebp, 04243484Bh        ; 'BCHK'
+ p) a& E+ Z$ R, W    mov     ax, 04h
( g5 [  u4 V! A! d9 j    int     3      
& T( F& t. d2 K1 B5 B7 N: ^$ g8 O0 [    cmp     al,4
* w. ?, C% D" J, F+ F    jnz     SoftICE_Detected
9 ~% a- F+ [, N% ^, ?7 g" d7 _" c: @% Y# C9 p! I# k
___________________________________________________________________________
5 a2 R$ y4 }: q, x* I) U2 O" @$ F  Y5 u- U1 ~1 c
Method 02  j4 X$ n1 z' J8 h4 D
=========
& n' o  `; s0 G/ \; ~! }$ n, H# S- S( P0 V) c
Still a method very much used (perhaps the most frequent one).  It is used
/ s. b7 @  s- `) R# [$ oto get SoftICE 'Back Door commands' which gives infos on Breakpoints,
6 O* ]" I/ B+ ~! dor execute SoftICE commands...
5 g( ]$ T" j5 t9 OIt is also used to crash SoftICE and to force it to execute any commands8 p3 c* O# t& j6 G, C
(HBOOT...) :-((  
. ^2 J( r# R- B# o' ~4 p
6 d( a  r. P) a1 l- B+ c! qHere is a quick description:* I0 d: d% K0 X) C9 I
-AX = 0910h   (Display string in SIce windows)  Z+ ~& {- L3 U) ~
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)9 A7 R" C3 j$ c0 E! H4 ~4 t
-AX = 0912h   (Get breakpoint infos)
  K! ~, U4 O! R8 p* A, i-AX = 0913h   (Set Sice breakpoints)8 l1 ]" v& P; U( m$ P( j
-AX = 0914h   (Remove SIce breakoints)
+ r2 n% \/ J8 T% y" m8 y7 A
6 H# T' X2 \1 bEach time you'll meet this trick, you'll see:
" E' L: J4 F* U5 O-SI = 4647h
6 m( e! ]; J8 U1 _+ n' {-DI = 4A4Dh! d6 f7 e" Z' C( h
Which are the 'magic values' used by SoftIce.
+ R# I( ^1 a6 Z& DFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
/ m+ ^" H7 d1 u9 `% C5 m9 R7 {1 o' ?8 Z" x0 C9 ]) Q
Here is one example from the file "Haspinst.exe" which is the dongle HASP3 C4 C* f# P% a1 e9 R8 @
Envelope utility use to protect DOS applications:1 \) s& _2 J, t: T9 h

( E* ^& e5 N. R; F6 B7 _, Q: J* N# _
4C19:0095   MOV    AX,0911  ; execute command.2 K3 o1 B- N4 d2 ], ^; @; h. @" f7 T
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).8 f4 {' V; U6 y: ^& a
4C19:009A   MOV    SI,4647  ; 1st magic value.  B. _1 K& _1 Q  t5 l
4C19:009D   MOV    DI,4A4D  ; 2nd magic value.( ?5 n' ^7 |# N- R
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
$ \! H( e# ]! s# Y6 l4 f. I6 _) R4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute1 C# X; Y1 S2 ~1 X& m
4C19:00A4   INC    CX
1 Y, ^; u0 O  j/ b* p  u4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute3 l, f: `  M5 Z& n/ u4 w3 x
4C19:00A8   JB     0095     ; 6 different commands.( _% k. C' s+ j2 T) y
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
+ m: u3 w+ I9 t6 o4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
' u7 r9 ]! G5 r% X1 f$ B7 n# z/ L4 ^+ n. D* _# I  A5 A. {7 J
The program will execute 6 different SIce commands located at ds:dx, which; @' Y" f- H0 C
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
- h: Y4 D, K6 ^- p1 b5 W9 i/ N3 v5 T4 L
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.' S2 k# k9 s* o) w# x
___________________________________________________________________________- t/ m. Q( n; `* H' W
' C- t" M* E$ J' T+ ]

( z4 I% @0 Y! g, B* k2 ^Method 03
+ v# ~& u4 @; k2 P% M) c( d; A=========
1 k1 f# N6 i+ `5 @) t7 z: w  p. ^1 F& T
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h/ K3 o6 j) \6 w8 P6 g3 z
(API Get entry point)7 I' j# Y# f; o
        
, O( S: `# X( U" X6 p5 y
, N) j! ]" p  q; Y    xor     di,di
( S! V; A, v/ t3 d0 I1 C7 F. A    mov     es,di2 f; j5 `6 d( |2 X* m2 t
    mov     ax, 1684h         j0 R2 N) U9 u7 F' {, {
    mov     bx, 0202h       ; VxD ID of winice
3 t1 M" m, [+ f. T) x8 B    int     2Fh
) w, L( o) J3 {% ]$ Z    mov     ax, es          ; ES:DI -&gt; VxD API entry point# B; n6 F# B  K( U, l
    add     ax, di
+ Z8 D+ |$ G: H4 i. d7 r+ @4 e    test    ax,ax
6 u( @5 @* E& I( D2 J. g    jnz     SoftICE_Detected
# }4 J$ N. c( a  \
* N' |6 ~2 Y1 a% e4 Y___________________________________________________________________________
  o3 K6 ^- E" @  F& b: n* b% R
7 T, H8 o$ T4 b5 t# DMethod 04
( @3 ]. h5 D1 ?, E( q7 {=========4 l% U( B% l& y) C( W/ f, I
" Q: \0 x0 R. W% f
Method identical to the preceding one except that it seeks the ID of SoftICE; ?+ b% l1 h" ^# A) k
GFX VxD.
0 {* F! ]* s, V& a* ^( _: r! |, O
) Z  ^, H* r' B  ]& ?; Q2 }' K    xor     di,di* D. j/ o3 J) H: A# I
    mov     es,di6 k( H$ p! L- j/ c; G. H
    mov     ax, 1684h       6 l: D6 l* f; `3 I' C5 E& Q
    mov     bx, 7a5Fh       ; VxD ID of SIWVID
1 X: `  H' r& H    int     2fh
5 d' S4 f1 L& q" |- U    mov     ax, es          ; ES:DI -&gt; VxD API entry point% D# u7 b' y; w. ]- U; h
    add     ax, di! Q/ ]" }0 v" a6 H, R+ D9 ?
    test    ax,ax  W' |  L. h! b( o+ w/ F
    jnz     SoftICE_Detected
0 A6 y/ o+ u" ~& `1 a
! t" V1 a( |% p( A' E* J. z__________________________________________________________________________
& g" l( C1 k# q; N. D2 b
% ?+ d  ?# {: b. m
6 c) A9 k* q& [- Q- a4 _Method 05
0 ^7 v2 C' y- ~=========' ~8 v9 _  b9 C* }% M

% |$ Q& D+ q4 M0 t1 Y; H& K/ qMethod seeking the 'magic number' 0F386h returned (in ax) by all system
. t  m+ P8 |0 \" A# t# adebugger. It calls the int 41h, function 4Fh.
- l3 }  H  W0 ~2 E$ ?* xThere are several alternatives.  ( _3 T# g9 Y6 m
( O8 l5 W# A8 r" l- {* a! l
The following one is the simplest:
9 F( V* w8 W" V3 p0 B* \
' Q) J% K% ^5 N- @8 I4 l# w% i    mov     ax,4fh8 r/ ^$ c( j$ K7 I& x. H1 }1 A
    int     41h
- ~; Y; [6 j$ L1 O- x' N/ w) ]" K    cmp     ax, 0F386% Y  B1 J) D3 E" R" X7 v" n4 Q3 C
    jz      SoftICE_detected1 w; i  Q' `' E3 O" Z

- F: S' i- X5 ?1 O* l/ n0 Q6 O6 m
+ o9 S7 I0 Y* k! H' p3 `2 b- L8 }Next method as well as the following one are 2 examples from Stone's
. O8 r! h5 ?( [2 C. d0 t  h"stn-wid.zip" (www.cracking.net):& {1 X2 o: C- e: Z; i
- ~+ {, n# I7 N* `* T: e, g+ u
    mov     bx, cs
2 X, V& W5 m& N& K" s' u    lea     dx, int41handler2
4 G4 P& i8 D2 V. W7 Y5 O8 k3 N    xchg    dx, es:[41h*4]! M, V/ [  t1 n. }$ j; O
    xchg    bx, es:[41h*4+2]
2 k8 v: V& h8 J& y+ t    mov     ax,4fh% Y- a: h' K: P. ~* c
    int     41h1 e- v7 M& s+ n0 d7 t; b+ s
    xchg    dx, es:[41h*4]
& h3 j* m: U# |: C6 G    xchg    bx, es:[41h*4+2]
, b7 U" c  v, Z0 D; g    cmp     ax, 0f386h0 ^, W, K5 I! k0 ^' ?( _
    jz      SoftICE_detected* d4 ^! U0 a. A( l4 {4 b/ I

$ |; a6 @$ Q) jint41handler2 PROC
/ s" B7 s! Q. x. `    iret2 M' ~: {! I& {4 m6 }
int41handler2 ENDP
5 D* ]: D3 {- W6 k7 h* p" F- M6 M9 t( Y: L! [* F& }
( H, m' V5 Q2 \( \# A8 u
_________________________________________________________________________' K$ B5 k. j, Y! D2 c0 N: c( H

( }7 Q; U. u& G5 R% ?( d8 w5 J: u3 a' Q6 d' `$ v
Method 06
* r! a8 g& E* _5 V5 b8 F% i5 ^% B=========
9 x3 G: x8 M  d& O+ K
1 Q3 D% u: h( G
7 }1 I1 V, V% X. `; s2nd method similar to the preceding one but more difficult to detect:% x  x1 o1 y' B9 G, K

+ ~" _) X0 |" c* M! z$ E3 h: A2 R4 K8 j* w2 \
int41handler PROC
# G2 X7 b$ V5 Z# G; I3 }; E    mov     cl,al4 C) {, M6 a" |4 E) g+ l0 B9 |0 U' l
    iret# M$ f( j$ w7 n4 Y4 H
int41handler ENDP
8 v" j; G) k; ^2 Z% C, q% _, Y- W: I0 ]# P* h! x+ W

( g9 v' `9 K3 o3 `    xor     ax,ax
# c7 f4 X& l  L    mov     es,ax
5 W1 o  c4 B" N" a) L( H$ y/ z/ a    mov     bx, cs6 j$ T$ v" Q0 K: P9 E9 {- o
    lea     dx, int41handler
$ _& X4 B' Y/ A3 Q) a    xchg    dx, es:[41h*4]4 Z4 g5 g3 p' e" A1 d* l( q5 K
    xchg    bx, es:[41h*4+2]& F% b' G; U7 N
    in      al, 40h* a. L) z) d9 T$ q6 I
    xor     cx,cx
; J2 T) O# D6 S% G) s4 O& k0 [    int     41h6 ]+ ?0 q; X1 t1 G, s
    xchg    dx, es:[41h*4]
7 x- Z3 d5 E8 \4 {/ k& G. |# o3 E1 P8 ^: P    xchg    bx, es:[41h*4+2]' t/ Q7 ]' Q! q# n
    cmp     cl,al) }3 Z  T8 l# ~% @: X
    jnz     SoftICE_detected6 r; N* D6 I9 m2 O/ J! Y+ U

' b+ V' ]& m6 ?8 e) S- ~( D  l( Q_________________________________________________________________________( L& i) E4 m3 @( J: @4 `6 K. e, c

* `+ C2 J8 a7 t3 fMethod 071 R; ]& N' N$ }* g* l
=========
; [! M' n/ o4 F& c  k  N9 G
; W, F1 d/ F2 h* y, uMethod of detection of the WinICE handler in the int68h (V86)
# l2 E8 {6 q! f; U
  K5 C6 ^( j/ r+ ?5 J! _: g    mov     ah,43h
6 }+ T9 X8 n5 O3 J0 h    int     68h0 t& |7 N" O6 B$ `2 Y/ F% \5 ]
    cmp     ax,0F386h* L- n% {+ c+ g' |
    jz      SoftICE_Detected* V' q4 I5 m6 ]# a; L0 C3 J
& C+ ]2 z9 l  F; p" e
- K4 c# ]; _4 b0 ~# r
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
8 c0 m( }- f/ d, C4 g/ X! U   app like this:" S" f3 b* j% }/ @; U5 H0 W9 ]

6 c4 c' C5 @# e& g/ g3 P   BPX exec_int if ax==68
; `: n* a; a: M3 d5 P% t* k" ~   (function called is located at byte ptr [ebp+1Dh] and client eip is
; L' o1 \, I+ j! ?   located at [ebp+48h] for 32Bit apps)" p( b, ^) R2 h# I: C2 U
__________________________________________________________________________
0 u* K9 ~2 s- A9 K" P  Y& ?1 b1 m
" k4 X+ h. }6 O- t' E* z8 z' o+ \$ r' F' x; c1 c
Method 08  ~' ?  f; @- B' X8 u0 N
=========
9 r- b- U$ d# i4 y: ]! n# f" G# F; h" Y/ s5 s/ w
It is not a method of detection of SoftICE but a possibility to crash the# L2 C# A: k% \" Y
system by intercepting int 01h and int 03h and redirecting them to another
2 f& W2 y6 D* P7 n; a$ H* C/ O1 Croutine.. s2 `4 y9 w- D0 E
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points% L- _3 W! d" X/ q& v  C+ d
to the new routine to execute (hangs computer...)1 n/ G- v& U. f( `) P7 h) w

9 }" X. S9 k  `5 c1 s    mov     ah, 25h" U! u! L& d1 E* B3 m8 p
    mov     al, Int_Number (01h or 03h); o( Z- L7 y& g! P& X, k. I* f, K
    mov     dx, offset New_Int_Routine
0 X# S. {7 E2 V2 ^* ^( D    int     21h
" ?4 o6 _4 O4 ]7 E; u% i+ d' M; v
( Q5 w: S% {+ q__________________________________________________________________________& C' P+ I4 S& e! {+ U
0 b: C2 n* F9 i1 d1 g
Method 09
4 s; _9 Y) E5 u=========
" b' E# o9 x7 r6 N. O1 v2 T' x$ q
1 y* n1 x. a' q6 `* J# E0 |This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only8 e8 T: Y" i+ r, {; R! v* M/ z( o
performed in ring0 (VxD or a ring3 app using the VxdCall).. q1 M! k8 x6 N/ E% U, F2 U
The Get_DDB service is used to determine whether or not a VxD is installed  j: Y' ~4 x; Z8 |: h
for the specified device and returns a Device Description Block (in ecx) for: M% ^$ R' T; ?, {
that device if it is installed.$ T5 e, j) m* t

7 C5 q7 y4 F( ~% p& e& H: }- g5 W   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
" f& F/ o2 R/ D$ L( |   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)& [% P7 M0 [( O: N. q* P
   VMMCall Get_DDB
  B3 j, f/ c/ d) [: Q, j   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
- g8 I8 x. _% r: m
6 X: ]# [2 _9 s# j. {3 ], cNote as well that you can easily detect this method with SoftICE:5 V) J2 {5 y8 `
   bpx Get_DDB if ax==0202 || ax==7a5fh
% h* H7 m9 t# R4 V$ }1 S% d( X, j& J# A5 [' W/ _$ b8 S
__________________________________________________________________________
6 ^: @8 j; n" P5 |& a# r$ j9 @( P8 S# e% w; M4 A! Z
Method 10; J9 b8 @; C; P9 j
=========! O) M* F4 J! I# \5 Y
3 @! W! d0 a% p5 q
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
- t2 W* C, V6 ~1 u  SoftICE while the option is enable!!; t0 |& F. Y9 {0 C$ J' F

3 }) a# @/ ?+ c1 E, ]+ kThis trick is very efficient:4 T3 `3 u$ N% z' Z& j6 ?
by checking the Debug Registers, you can detect if SoftICE is loaded0 |9 V/ l. O$ ~2 m4 \0 x5 A
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
: q2 \3 m; m, Vthere are some memory breakpoints set (dr0 to dr3) simply by reading their
5 V  R. ~8 P2 Y  ?6 O) Zvalue (in ring0 only). Values can be manipulated and or changed as well
1 t1 `& N) Z$ I5 h, N! T(clearing BPMs for instance)
: M# m8 i$ y+ @, Q* \( M3 g& e+ W  I5 b. g3 Z/ g# c
__________________________________________________________________________" C5 k6 [( R9 P

. w" l! u! P6 o" \7 z# e8 xMethod 11
: N3 F9 T: f" J: u$ ?1 M=========: p! Q* }7 \0 [0 D  F" n0 ?* k' [# i

/ ]! Z: ^1 P. [: q; HThis method is most known as 'MeltICE' because it has been freely distributed
% H, Y: Y' w2 P' E2 s( {via www.winfiles.com. However it was first used by NuMega people to allow
& N3 f/ k4 K: j/ u( H: MSymbol Loader to check if SoftICE was active or not (the code is located
) N8 H, G/ v& p/ z3 }inside nmtrans.dll).1 M% K' [* e5 g* K# J, Y
' A1 u9 m( s, D5 H( I# ~  f) l
The way it works is very simple:" |! d7 U1 `0 l  f" k/ b
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for; F) X. A5 ^1 c1 E& B( B
WinNT) with the CreateFileA API.3 u- O/ ~# w: ~* [8 S3 R
+ e6 I" W( k( N5 Q4 X6 _
Here is a sample (checking for 'SICE'):
4 o6 ]6 ]" Q& i
6 n! ~7 {# t& [6 W' zBOOL IsSoftIce95Loaded()& C0 x0 [6 ], i
{9 ^7 x, L. @6 s" H9 s- v/ Y1 S
   HANDLE hFile;  
; a! N9 q; f5 ~  E" w" U7 M- L   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
6 v' |# A7 i4 c- @8 ]                      FILE_SHARE_READ | FILE_SHARE_WRITE,
2 T/ Y- ]  a, t                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
/ z& r! l  s8 S; m0 t" A3 o2 c   if( hFile != INVALID_HANDLE_VALUE ). K7 {# e# s' I0 M( @/ j
   {9 j- X2 z8 h9 B. s# H8 M
      CloseHandle(hFile);
3 }9 j1 H/ o/ x: E      return TRUE;
  d. N4 e& e: w6 P* ~! x* c   }
( H8 P4 U; m3 e   return FALSE;1 q  A5 D/ ~% ]1 g
}0 x5 K5 m. b+ S1 Z. o% c
! ^% y1 Y% D3 q9 L  V. O0 J
Although this trick calls the CreateFileA function, don't even expect to be% n# i% T$ L6 z' Q( Q  X5 O! N  X
able to intercept it by installing a IFS hook: it will not work, no way!0 v, Z! s* Y$ u5 U1 S
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
/ h1 e/ ?# w& ?& w) E  \' m8 S( Gservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
1 R0 `( S* g2 N6 {/ ~& R0 Cand then browse the DDB list until it find the VxD and its DDB_Control_Proc# s" [* Y& X9 c( V8 v
field.
" G: x- R6 i# }, R/ F5 j8 {In fact, its purpose is not to load/unload VxDs but only to send a
" A% Y) c0 K$ xW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
  N2 U+ r8 g% q; kto the VxD Control_Dispatch proc (how the hell a shareware soft could try
$ F2 l4 \5 e( Kto load/unload a non-dynamically loadable driver such as SoftICE ;-).6 H2 ?! ^7 M# I% ]$ O
If the VxD is loaded, it will always clear eax and the Carry flag to allow
1 q) }8 s0 ^. }its handle to be opened and then, will be detected.0 p$ y8 e  W5 ]5 Z* c
You can check that simply by hooking Winice.exe control proc entry point) Y+ Q+ G5 T' G3 X* _
while running MeltICE.) e" x9 x' r+ V* [! a

- J0 c  n  M' e3 \
# T; J/ Y2 `, p. m8 b, B  00401067:  push      00402025    ; \\.\SICE* E. p8 x; C# G
  0040106C:  call      CreateFileA/ Q6 k% g8 O2 q2 S& i. T5 x( C
  00401071:  cmp       eax,-0018 j, o( D# N' V' V! a1 j7 k
  00401074:  je        00401091* G! b' _5 E: Y" H

! u2 g$ b& d, P0 b  M1 S- @6 ?0 B
; b" M' m% r- T6 X, n3 BThere could be hundreds of BPX you could use to detect this trick.
2 ]9 K" t$ F( H( k. G( }+ d-The most classical one is:
' j; B% e( E5 ?% }; H! L  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
: p; O& Y( i" W' b8 l* L    *(esp-&gt;4+4)=='NTIC'
7 i; ~& Y* l9 K. o3 B# r# s/ w) H4 X$ J' W8 {6 L. A
-The most exotic ones (could be very slooooow :-(  r3 ]1 J4 T/ F8 z5 }$ `
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')    d1 H! S+ t# {+ b+ x" s$ J
     ;will break 3 times :-(/ I- B3 S  C) V9 a1 o  ?1 }) X3 m
/ b5 D! b( P9 Y, z+ F# C9 ?# P
-or (a bit) faster:
/ D! ]. N1 [# o0 j& U& F   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')( l& m' `1 [; }' u
4 ^4 H- D. _2 o9 }% h+ n
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  % L/ _6 q6 G, D( A7 k% R
     ;will break 3 times :-(
2 ]3 L1 z  [' {9 |( }* Q  N
9 z  e. u2 f; B, D  w( O-Much faster:- I1 J; K1 Y& T  y, k) y: P+ `
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'8 i8 g; z0 p4 r) R3 r- u
7 \. @3 [9 u* L
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
( c5 J( J! W$ s7 j5 }0 r$ `function to do the same job:3 Y' L8 S, e! `" N- E) p

4 }" Y3 y) h0 I' Y1 A- @9 X- G   push    00                        ; OF_READ
6 j; E1 R9 T1 g% m2 _   mov     eax,[00656634]            ; '\\.\SICE',0
% e! y. O& T7 t/ t  P   push    eax5 Q1 c$ [6 G5 N
   call    KERNEL32!_lopen$ @. a) S0 `4 X
   inc     eax- Y$ c- L6 T, ?& H/ |
   jnz     00650589                  ; detected& w/ h  t+ w, B5 B+ [+ |* A5 [! o
   push    00                        ; OF_READ
5 Z1 Q, [! O7 F. K( h$ O   mov     eax,[00656638]            ; '\\.\SICE'
6 Y  U6 n( u& ^; _# d9 ~2 y  n   push    eax
7 I  o: K8 {, G6 a% y  W   call    KERNEL32!_lopen
7 M( T" y% O& ^, h# l2 I; B   inc     eax" j' J4 K; ^5 V$ v
   jz      006505ae                  ; not detected
+ _$ o) L& e6 ?! l8 c3 a! {5 J
% u* y, ?; s/ s. Y% T1 O# s
+ T+ J$ L- b* v5 n__________________________________________________________________________
5 M5 S- a, |# q8 ~) w' ?, B! S* H* N; T0 j0 U8 d* D/ I
Method 12% M: i5 ?( u& ]8 v& i" E
=========
% J1 J6 i, ?9 Y2 ^, A  c6 ^2 k3 J  a6 q- O6 B
This trick is similar to int41h/4fh Debugger installation check (code 05
$ V' Q! ~& @& ?/ L+ c7 w. a&amp; 06) but very limited because it's only available for Win95/98 (not NT)
$ r6 R  B* n" z" h9 ?" s* |as it uses the VxDCall backdoor. This detection was found in Bleem Demo.* }5 J9 w9 Q% a* J1 ]& s

1 _, ]- c* n/ c" J8 k   push  0000004fh         ; function 4fh( L6 x# k6 y( H/ k# ~# M4 u4 S9 A
   push  002a002ah         ; high word specifies which VxD (VWIN32)" R8 L! t, o% k$ N; d, d
                           ; low word specifies which service
2 ~9 |+ I' ^3 G6 |$ U                             (VWIN32_Int41Dispatch)# h+ d# J+ h" B2 J* t; u" Z
   call  Kernel32!ORD_001  ; VxdCall
+ L/ D# D; Z1 z! L4 w   cmp   ax, 0f386h        ; magic number returned by system debuggers* C0 R# U9 N4 O1 G6 l3 ?5 ]
   jz    SoftICE_detected
- P- p: y1 v' [6 J. O! P0 n+ B: [% W5 R8 ]! o1 z
Here again, several ways to detect it:2 Z( }7 v% C; F- U. e- `
. X! g, N3 `8 `1 v0 h
    BPINT 41 if ax==4f
$ z/ T5 K) X0 q% b3 H
( M/ ~: \' i% d4 r* \6 b. d    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one8 z$ G' t* h! s" i5 z. f6 [; B' C! Y
  P7 ?4 n, V$ M3 m8 ~
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
, H, R4 T( h; A8 o; S$ r: N
' ~" t! T  J5 }9 r/ N8 P) p    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
% l# p8 w* E* N- i: P1 E0 X* J, ]  l6 X, v9 U; k
__________________________________________________________________________3 r0 S& B1 ?7 M: E$ t; a5 [
; `- D* K$ Z/ r" f) p, F4 D
Method 13- i$ r7 ]! ~/ L# T
=========
+ |& Y( U( V) J, _! v) \9 ]! h
* M$ ^: V) T& r' PNot a real method of detection, but a good way to know if SoftICE is
+ F7 Z, h4 U, l+ p3 yinstalled on a computer and to locate its installation directory.
8 j, \- R" g; YIt is used by few softs which access the following registry keys (usually #2) :
& {  n9 v: ?" m% d( G) O3 n: x, E' l% M
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion7 e$ R3 A3 k$ E
\Uninstall\SoftICE
. F! Y7 W/ ]  Q5 C  @-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
, F4 |$ ~1 z0 i, N2 O-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
3 d1 i  _4 D, G( f\App Paths\Loader32.Exe" s7 X+ D2 q3 R/ F' c, y
0 `& Z0 [0 \4 w9 ^3 B4 f

$ T) V* w" M. h  R- S$ UNote that some nasty apps could then erase all files from SoftICE directory4 T' O% D, F9 O2 g% M
(I faced that once :-(
' s  s0 t' e" B/ K# K0 t- s( W, S8 N, D5 |* m) [0 L3 m6 d
Useful breakpoint to detect it:/ n  F6 B+ o6 ?

3 A2 t$ d: L  H     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
0 J1 E3 b, N2 Y' t0 i
& A3 t3 ?" a9 ^8 c0 b8 U: R__________________________________________________________________________
% G8 m$ y2 g9 P$ j9 W4 L/ t( D0 b2 `6 y$ I

7 {0 O! d7 }% y! i/ W$ WMethod 14
, `: i0 z$ ]6 B+ P; u=========
- ^8 K4 A! \6 g& ]6 a' _8 I- T: r
3 \6 e  f7 o* i) C6 ]A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
& o  [1 [) Y5 m6 k, e1 [  o# His to determines whether a debugger is running on your system (ring0 only).
- e4 j+ J/ R5 [8 N! E
7 ^1 V5 Q/ M9 d6 j   VMMCall Test_Debug_Installed+ d5 k/ B" e: S$ j
   je      not_installed
# ]+ Y# j' u6 v
' u' w( c9 o" f+ ~This service just checks a flag.
9 i+ E% `1 v6 U+ _</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部