About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>! L- J; ~2 R! Z! J1 G1 n( h/ t9 I; H
<TBODY>- V8 a) k: w) H  J
<TR>
: X8 a3 E( ^8 U  r8 j# D<TD><PRE>Method 01
0 G! ]* i& y) s0 I! S) T$ m$ U4 A=========8 I. {, S+ n/ W: `" [

' ]9 s- p# \/ k$ }8 c3 \5 PThis method of detection of SoftICE (as well as the following one) is) q" a! w  P( Q3 p2 q
used by the majority of packers/encryptors found on Internet.0 M. s0 m/ L6 P  I4 O" M) y  d8 N% }2 r4 z
It seeks the signature of BoundsChecker in SoftICE7 t; O  \5 g: G- |

/ R6 z+ E  e- T7 O    mov     ebp, 04243484Bh        ; 'BCHK'7 P2 ]' u' R* g* p7 p
    mov     ax, 04h% _6 A, Y! u- h" D* ^
    int     3      
, q0 {. q9 q1 W( y8 h" ]0 F    cmp     al,4' W6 r! r1 t4 ^" V9 P, H0 h
    jnz     SoftICE_Detected
) g% g5 ~3 D2 s9 a
+ E) t3 [/ ?. b" C___________________________________________________________________________2 t) s. N4 D5 ?

9 g7 ?, C- u" d3 w0 cMethod 02# F# R9 O1 W4 U( ~4 n, D
=========$ h" d! Q+ o- u7 g. f3 v) {% D4 R

- ?# U, k6 E5 v5 N2 v1 aStill a method very much used (perhaps the most frequent one).  It is used
+ ^+ C( V4 R$ h3 H9 ^' ^5 _$ Yto get SoftICE 'Back Door commands' which gives infos on Breakpoints,
! L7 v6 y: G$ X5 Vor execute SoftICE commands...
" u: s3 j: H" ZIt is also used to crash SoftICE and to force it to execute any commands
0 K0 t9 w' |2 v( y5 c' G8 t: l(HBOOT...) :-((  
' v2 V$ R3 P# p5 b& @
8 F* ^! \% r0 Q% J) LHere is a quick description:
- R0 j: e( _; H; O3 }-AX = 0910h   (Display string in SIce windows)
( R9 Y8 W9 V0 F8 O-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx): A1 y9 {! H4 l3 V! Y& x$ y9 m
-AX = 0912h   (Get breakpoint infos)
  R  H' W* A+ w" W-AX = 0913h   (Set Sice breakpoints)0 e' O' A" m! g2 W+ H! i4 I4 o4 N$ X- E
-AX = 0914h   (Remove SIce breakoints)0 o2 R, \1 I7 M/ g2 [$ I

; C$ j# O: B+ h3 p4 J6 Q0 [5 BEach time you'll meet this trick, you'll see:5 c* L# t$ ^4 W( w- F$ X6 A+ @
-SI = 4647h( s  J5 }3 t+ K8 p0 x) l, o
-DI = 4A4Dh; I) @0 g8 z2 t& H1 G7 g
Which are the 'magic values' used by SoftIce.
4 @. p6 E6 d# VFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
) b) r; u& F7 o1 z; F
1 p: k8 ^2 |2 V5 ]Here is one example from the file "Haspinst.exe" which is the dongle HASP+ F2 [$ s7 h& ^9 d
Envelope utility use to protect DOS applications:
7 o/ w0 p0 `: m+ b* X# c6 {9 D. J; {# F. x
! e4 ?; c8 u% ]  c$ Y; [
4C19:0095   MOV    AX,0911  ; execute command.
  A2 L' o' |: T9 S4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below)., k8 ]8 v# M& i) X$ K/ b
4C19:009A   MOV    SI,4647  ; 1st magic value.) ]" Y. I7 r. |7 @
4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
7 h" \5 }9 v6 K3 n- R( T4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*), H9 @( T7 v6 z. E
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
3 t2 U  k% G5 R# G5 w7 n3 w4C19:00A4   INC    CX7 \! D2 R$ J6 C
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute  o% ^$ s4 o6 v" N2 @+ Q
4C19:00A8   JB     0095     ; 6 different commands.
9 x, O7 {2 t6 s3 r# a, @$ V4C19:00AA   JMP    0002     ; Bad_Guy jmp back.% D% ]# O  d& U: g% g0 L+ f+ Z
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
# K  n' O* k8 I6 m
) ]8 a; ]  ^# CThe program will execute 6 different SIce commands located at ds:dx, which
  m: h# d$ z5 m5 h5 Gare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
1 I! w- P0 y) N! h& |
, ~- S' c) T2 Y1 }3 E: O( h4 g* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.+ J9 L' m  {: e" W* d. J$ T
___________________________________________________________________________
0 X5 G' ]1 m0 y$ U  s
* P) o& @' j$ ~7 [
# @( H% f" k- {Method 03) ?' U$ y9 g( u6 w+ J0 b5 G/ |7 E
=========
0 ?! @2 U& l  ]( s" d
! S$ n. ?3 L9 j9 QLess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h0 c- C; E" O& N' g
(API Get entry point)# m- y# m* v* f" \# z3 P- p$ q1 e
        
% t4 ~8 C- O; o! @* y
* h7 X3 l9 Z7 @+ w9 k    xor     di,di
3 C: L% S! X4 P3 {2 k    mov     es,di  ]/ o! l& a" n- h/ V+ O  D
    mov     ax, 1684h      
' l8 `" e, i% \8 x# p# a5 e    mov     bx, 0202h       ; VxD ID of winice
2 ~, h7 Y/ [' H9 U. P    int     2Fh
/ Z' E) T) l; n2 C. O    mov     ax, es          ; ES:DI -&gt; VxD API entry point) q# @2 |) n% n5 R3 D: U
    add     ax, di
4 b2 I' {; s- I4 T* s  z$ S    test    ax,ax4 C+ {0 O, c, E* ]" D- ]% }/ V& U
    jnz     SoftICE_Detected
0 f% P( ~2 T, s) C: \. [' K
$ [) f, @$ B* ^$ `___________________________________________________________________________. `, v- {  M% Q! M8 y- n

" T: Z4 A5 n) R1 e4 C3 `( o. A- m4 yMethod 04% c% E  K, x; i6 n1 d/ x) s6 P
=========
9 F6 G$ R. r7 F: i7 F
" j* N3 I8 E  YMethod identical to the preceding one except that it seeks the ID of SoftICE& |5 e* e& A% S. [5 o1 k! e7 a
GFX VxD.
; N/ |( a# Z5 u' Y) C+ K  [
% v( \1 d" K/ ^' S  ^7 S    xor     di,di
! t" B+ p1 z! ^! H+ C( k8 J" W2 B    mov     es,di2 O! p4 c  r+ x4 d8 _
    mov     ax, 1684h       1 ]# ~; ?8 x0 l* Y( c
    mov     bx, 7a5Fh       ; VxD ID of SIWVID
# \$ S* F9 t( y' ~& b& b4 d! j8 K    int     2fh' w( n* e7 O; ]' o
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
) \+ |$ ?& w* \" Y$ {( j    add     ax, di$ b8 K" s) s% F- _1 n( Z
    test    ax,ax
/ P8 k! m; F) L    jnz     SoftICE_Detected: R: t* W, N& b4 }* L

) x5 t0 {6 L% A5 b  i! f( h__________________________________________________________________________
6 q0 `+ f3 ~5 ?0 t, w& {. k- R% S# q2 A( {7 I% [

' |1 {4 Y7 x, w9 j9 v1 G' ~Method 05
8 T* W+ d7 k- C6 B( L0 S, v=========; b1 \9 ]% X/ y" |

/ H% N0 m7 [1 c# B+ xMethod seeking the 'magic number' 0F386h returned (in ax) by all system
5 D3 x& F! u7 p& a3 j4 Mdebugger. It calls the int 41h, function 4Fh.5 n/ i% t  x! M' c7 x
There are several alternatives.  & S+ `5 k: a+ h8 Q& k: T  j7 |6 m- Q/ M
# h/ U# f* k" Y( w% c. u7 X
The following one is the simplest:# r' B* d- ]1 w! W% E. L' k
% G+ D7 j9 p( {2 J
    mov     ax,4fh
3 x) q+ j8 e# l    int     41h: O' o" j% ]# O5 @
    cmp     ax, 0F386
1 O1 W1 s/ A: A$ ?& A    jz      SoftICE_detected0 w# ~0 T7 _" ~$ k) G; o7 t
9 S* D; v! `; ?5 q4 I( [. s

9 ^$ N; [! e0 Z, c  a2 hNext method as well as the following one are 2 examples from Stone's
: ?4 y5 J% X/ P# q+ |" U"stn-wid.zip" (www.cracking.net):: C% U1 z" \4 ^6 }9 V9 X

9 u) `7 T1 y; N. Z8 k, C7 P    mov     bx, cs  X0 f. p  ^  U! V4 ^
    lea     dx, int41handler2
. t9 C# {4 N# U& n5 i/ H    xchg    dx, es:[41h*4]
6 W5 D* x) F* E" L    xchg    bx, es:[41h*4+2]
% S; c: L: G0 ]- Q: V$ X    mov     ax,4fh
# Y# [7 m! H* e    int     41h
4 U& X8 c& ?( i9 z; g5 t    xchg    dx, es:[41h*4]. \4 f8 I- L: n- n' S
    xchg    bx, es:[41h*4+2]) ?' D! o* N. V1 J: z! P: ^
    cmp     ax, 0f386h
0 h1 Z9 D( C6 k) m% o8 \    jz      SoftICE_detected1 n" s" S: \# t5 k2 i7 t
( q" @- J0 K% B+ W" M- q
int41handler2 PROC
; X# r/ |3 J( b0 R! m+ Q    iret
6 A$ \7 u) e; Dint41handler2 ENDP
& F. m5 Y/ _' |1 L8 |6 G: Y4 L6 x- S8 M5 T9 J! m

$ U: g5 ]( S# w/ P' \_________________________________________________________________________9 o% ^" G# G- d& ^2 X0 b# l" z

- c$ |  n+ B7 u1 _$ K1 q) D
7 Q! W* D* C5 u7 G  H9 ^) W% LMethod 06. G, G, ?% E" r- _. t
=========
( e: V8 ^, H$ i3 q+ b) \  P- O" b% U6 ]; t( K& e6 E- y) o4 F) l0 F

5 c7 e( F9 z$ u2nd method similar to the preceding one but more difficult to detect:
9 g0 l- |7 M, a& p$ b3 b
- s  Y; N; b1 H0 w8 w5 F  b0 W; A6 a$ R( y: a; I( N3 @
int41handler PROC( `. I6 [: o# w2 k) b" e
    mov     cl,al
2 E5 Q4 F4 N6 N    iret# P- k6 V; Q3 c0 a) Y
int41handler ENDP& T+ R8 q) F# _. n9 h8 r
( J9 A8 [2 q$ x2 w+ Z
, u2 M1 F+ g, x7 }* @6 o
    xor     ax,ax
  X* l, g& y& H$ v1 ?' q% v6 g    mov     es,ax5 e; a2 V5 u+ r3 d& z$ k& X
    mov     bx, cs8 j8 b3 U7 N) P/ Z3 j; S& n( T! j
    lea     dx, int41handler5 ^2 t: K$ w: p% t* U
    xchg    dx, es:[41h*4]
, D0 s4 W6 E& I; F' i    xchg    bx, es:[41h*4+2]
" j3 a( d* f! P7 r/ L    in      al, 40h
4 d  P" x* J6 \" r' d( Y    xor     cx,cx3 N1 I7 J! z$ ?# p2 ?& p( D
    int     41h" l* s7 ^" w! k# q5 {
    xchg    dx, es:[41h*4]- J( T) v3 O9 p" |" {: Q# @& m
    xchg    bx, es:[41h*4+2]+ ~: X( v1 Y; Z' z; c
    cmp     cl,al
: s  v8 `6 D, z" ]    jnz     SoftICE_detected
5 u) n# D: Y) J
! O' M0 G6 i0 q, F  v6 e9 Q! v_________________________________________________________________________5 T, j) n. L$ }6 L! ?. |) R0 S

1 O" k0 l" q: \0 h: }4 r9 R! z% SMethod 078 _( e5 x; j. [. Z1 @8 {' k
=========, t2 R9 ]1 _, G$ x8 w1 ~

' C6 B" D0 \6 j' @$ r) ~3 x0 SMethod of detection of the WinICE handler in the int68h (V86)& s' {: ~6 g0 ^" H$ A5 X
6 t# E/ Z" Z# I8 b; j8 X! R
    mov     ah,43h
5 j* `3 B! w# I' e" F$ E) f6 C1 T    int     68h
) T2 g7 `5 H4 z6 p: q- c0 d& n    cmp     ax,0F386h( E/ D/ t- t+ S: l9 H7 @
    jz      SoftICE_Detected! L' z, J' Z) Y2 H
, l+ C; M0 I- n: m3 F" v
; v7 E2 l! F5 d( @* ]
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit/ R* ]: {( |$ g( O* r6 H
   app like this:, X' @- f$ ~( L- d7 Q

6 ?  \8 l3 w- D- X& Z   BPX exec_int if ax==68& [. _+ p& l# f/ q+ _. T# y
   (function called is located at byte ptr [ebp+1Dh] and client eip is0 G: i3 k7 K" V4 j
   located at [ebp+48h] for 32Bit apps)! _: L6 W7 W9 P( ~$ T( B
__________________________________________________________________________5 l( u! G4 k* o1 t) b
  h1 m4 ]; W$ I( o$ X2 L! v

1 X) l$ s5 U/ j; DMethod 082 C& _5 a7 {9 M& v8 R: n) K* D
=========
- W: |7 d2 x' E* a4 o1 Z0 ^" H* Q6 k8 e, ~) a6 E
It is not a method of detection of SoftICE but a possibility to crash the* B( f/ ^4 s5 ?: I- U3 F1 @
system by intercepting int 01h and int 03h and redirecting them to another# R: C% G) U! N  v6 G
routine.8 z3 Y0 [  V" |9 B$ d+ r$ B% f
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
6 F  w3 e. |' k$ Eto the new routine to execute (hangs computer...): K8 ?# {. Q- b+ m, ^. T
3 w6 `8 f$ I% X, p
    mov     ah, 25h
* N7 J8 A5 ~/ C7 u  }6 S    mov     al, Int_Number (01h or 03h)! w4 \; x0 L: A' k
    mov     dx, offset New_Int_Routine" r2 m  ?& }/ r& _
    int     21h
2 K' b7 U. `3 I4 e9 l: o5 c( E% N! T- s. b1 a! G+ Y" p% D2 w+ |
__________________________________________________________________________
; j" d! t6 u# H: G4 a/ S- q( Q4 F
Method 093 D4 d* I+ P2 z% c1 }/ u
=========: p9 f6 N# T' W, Z9 @, A0 H

! O) ~* a1 [  mThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only, t# M! m; X: Q) n. S
performed in ring0 (VxD or a ring3 app using the VxdCall).
% ^0 Z& ^: k$ D! B  |The Get_DDB service is used to determine whether or not a VxD is installed. m; C5 q. N1 ]8 W
for the specified device and returns a Device Description Block (in ecx) for
/ n# h/ E7 e# f+ H3 \* Y1 F! }3 @' `% gthat device if it is installed.
6 P( m9 z! \' x0 V. `- m
, P4 z3 y" s6 P" _( F! E4 ~  k2 |   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID, d( R! l5 j) q1 G7 x1 R& g; s8 f
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)' s! w" x# b7 G, |) O
   VMMCall Get_DDB
' u% F9 F$ j" X, p   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed2 H! E1 t4 Q" y6 K" O

5 u. |! u, W2 y& \' r3 INote as well that you can easily detect this method with SoftICE:' v0 @% B7 j' f- y% f" x
   bpx Get_DDB if ax==0202 || ax==7a5fh. z( P- c# b& r4 h1 }

. y" q! a8 Z$ x0 U/ n; E__________________________________________________________________________* E) `* m+ J' i$ `
$ P1 _! V1 E: r% C
Method 104 r2 S8 \+ i" L  B; F  i. u! [
=========$ y+ f: D; L; m+ H+ s: q  |

# x4 x& B8 o: ?: i( u" A1 O=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
/ i6 {1 v6 |1 [. d0 L9 B  SoftICE while the option is enable!!2 ]2 E+ {1 o# i6 D" \- {2 @/ r; r
$ ?5 o) f4 ~* `2 Z% E
This trick is very efficient:+ h" X" q% ?$ X# n
by checking the Debug Registers, you can detect if SoftICE is loaded. p, Q# e& o2 d" I
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
3 C7 L$ ]4 Z& S7 F4 ethere are some memory breakpoints set (dr0 to dr3) simply by reading their7 L) U- Y5 z8 Z9 l, n) e
value (in ring0 only). Values can be manipulated and or changed as well
; u0 D! }3 Z" W4 d(clearing BPMs for instance)
0 p2 F9 w7 A5 b1 F; N
8 X& s/ Q6 w  ^__________________________________________________________________________
6 d/ _( V9 g* o2 V8 o# V" q2 _- I* H, b, g% `
Method 11
$ N- [' R4 v% ~" W) \=========# p. H$ N+ m0 I/ ?1 m& p0 K
3 s5 L1 C# W$ C+ O( A( v8 i
This method is most known as 'MeltICE' because it has been freely distributed
* ^5 T0 Q  _' S/ j$ Tvia www.winfiles.com. However it was first used by NuMega people to allow8 O8 l7 i% C; W6 D2 G& K
Symbol Loader to check if SoftICE was active or not (the code is located
5 @  B/ o& {8 `6 ?9 Z( A7 I3 finside nmtrans.dll).5 ~2 M" l) z) @! U& H
8 K' U+ {5 }$ ]% A* V% I- W
The way it works is very simple:9 f6 g2 N2 f, [9 N& R/ e
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for  L: \/ d; ]. y
WinNT) with the CreateFileA API.
/ o- c, s7 N" Q6 _0 i6 L- w
% Y8 h9 }0 U/ [Here is a sample (checking for 'SICE'):! [" [4 u; }4 {9 ?
0 s( y3 V1 j1 D$ x7 n) F% r
BOOL IsSoftIce95Loaded()4 |" N' _. `2 e
{! h3 ~# p! {; j
   HANDLE hFile;  
/ b; z9 _( R) a) |- R( L   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
1 q2 D! R9 Z1 q# y! A$ A                      FILE_SHARE_READ | FILE_SHARE_WRITE,, H3 Z5 X4 h$ t! o) v- i6 v# @+ U( E
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);( M1 h# y$ C4 Q6 P  u6 W; d$ H. d
   if( hFile != INVALID_HANDLE_VALUE )4 D" N2 ^: o, _! b5 P9 i3 M
   {
% r5 A: J& J2 o2 }      CloseHandle(hFile);
% [( p, p) ?5 P# t  g+ ^      return TRUE;
. O8 O2 p" V9 C   }
! K9 T$ I. ^+ N  R   return FALSE;. ~2 J5 @5 {: U
}6 K# \$ h& I$ S, [: p( x- b+ e
& O: f& ^2 q/ j  Z6 c
Although this trick calls the CreateFileA function, don't even expect to be
8 m0 h* x% j' {+ g( w$ ~% z2 \3 Hable to intercept it by installing a IFS hook: it will not work, no way!
" ~) O4 X7 ]/ v1 j- C' f5 B9 f% ?In fact, after the call to CreateFileA it will get through VWIN32 0x001F
- p  a2 H; r# I, U* U" |service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
2 I$ d7 R2 ~5 t' Y! [1 L. sand then browse the DDB list until it find the VxD and its DDB_Control_Proc
' M& M3 J$ ?6 @. \6 \+ yfield.
5 Z( k1 B& X# a( b- H! SIn fact, its purpose is not to load/unload VxDs but only to send a
  O" N8 q% M* [( P. JW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)# B  F, l" d" c
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
1 F+ f# P( j; |) qto load/unload a non-dynamically loadable driver such as SoftICE ;-).% ~, w7 e. X( N% H
If the VxD is loaded, it will always clear eax and the Carry flag to allow
$ U( `0 f' }; d" D8 xits handle to be opened and then, will be detected.
/ Y. ^* e9 K0 a) W- p) _You can check that simply by hooking Winice.exe control proc entry point
+ N7 F# P. D) K& D9 U4 Hwhile running MeltICE.
& T" @6 _' J1 D# d
* a! K  A/ O" S: |9 Z9 e7 h4 b. @; a" I
  00401067:  push      00402025    ; \\.\SICE
( @5 K7 T' m" {: e- v2 f/ I  ]  0040106C:  call      CreateFileA
  s& R7 i& L4 s9 ]  00401071:  cmp       eax,-001
7 H; {/ J/ o1 D  00401074:  je        00401091
" s- @1 f& k( l$ d. w. g9 J8 V

! H3 V3 D# ]* r' ^6 {9 J5 wThere could be hundreds of BPX you could use to detect this trick.
9 P+ L; P$ w) g; Y+ i" r! D-The most classical one is:& L3 p8 a4 Z% ]% R4 ~- x/ t8 m$ p
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
6 i# q# R" e. q8 N) S0 i- z0 `5 [    *(esp-&gt;4+4)=='NTIC'
2 K' \" L' c- g: P/ D# n& G: V$ Y3 V' _% J1 ^' A
-The most exotic ones (could be very slooooow :-(! ~! X' q0 l1 ~8 ^/ W8 x
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
6 g! ~# v. `. k2 T  N     ;will break 3 times :-(' Y8 j% j4 l: R, a. w% @2 C+ S
, C, l0 ?/ v4 Y' [
-or (a bit) faster: ! e% ]4 M" j6 r$ ?
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')2 j1 p! u3 g, H) i
7 b+ n  Z7 ?% Y, x5 J
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
& X1 H7 C+ @; L' a) N: X     ;will break 3 times :-(2 o  W% E) e. _) C0 x' |7 e

6 W  k4 W8 q* p* _* V% D  M-Much faster:
* a4 x0 h3 N. N! u' V) y7 l& q   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
  T$ N/ ]; Z" d, u
" `* b, j9 Z% ^% o- W# |Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
) |. \* a; e, Y% O8 }% r- nfunction to do the same job:
' _& J* P  S, {% J* w
5 V& A4 o& N5 y/ V   push    00                        ; OF_READ
8 o$ I0 W0 u( |4 e" w   mov     eax,[00656634]            ; '\\.\SICE',0
# ]( L* S" J% k3 q   push    eax
6 ^' J$ G7 F) s( W% F1 Y   call    KERNEL32!_lopen! m6 g% F' a% A4 L" u0 v/ i% s* ?
   inc     eax  i6 Z7 ]# j7 D: a
   jnz     00650589                  ; detected
9 S. h% ^/ U/ F" ]   push    00                        ; OF_READ, O+ n) v  F5 M
   mov     eax,[00656638]            ; '\\.\SICE'$ S+ ^, j, y: ^0 K. |
   push    eax
7 l) {2 p6 A( {; q   call    KERNEL32!_lopen3 I  p$ r6 s+ s0 R9 G) m/ J* i
   inc     eax
, a( K' C& |1 Z: i2 }   jz      006505ae                  ; not detected1 B- ?" ?. H/ [  S. e" [2 }

/ I+ V( @' F; y* |9 h" W  z8 D7 F( l
__________________________________________________________________________8 B( A' b" v; F  t" A7 n; o

  B+ s. L* o* E3 ~; EMethod 12  R4 I, v. a  M+ e6 y  a6 w
=========, j  U3 Z, ]4 w6 w( Z- h( V
7 F. V' d  `4 B: q; v, u/ {
This trick is similar to int41h/4fh Debugger installation check (code 05. B7 P* k0 x1 p  @
&amp; 06) but very limited because it's only available for Win95/98 (not NT)
7 M3 x( r+ m- s: M' e9 g7 v1 Cas it uses the VxDCall backdoor. This detection was found in Bleem Demo.3 j  u- i+ t. E( [
& u; u+ i7 i8 C% M$ J" u
   push  0000004fh         ; function 4fh
+ j: r& c/ t% W# M' u' r- h+ c9 a   push  002a002ah         ; high word specifies which VxD (VWIN32)1 k1 a& u6 D7 ^) S2 @4 O, C
                           ; low word specifies which service" e" |, T6 W# e. ~* M" `
                             (VWIN32_Int41Dispatch)4 ~, [/ Z) G' r# _
   call  Kernel32!ORD_001  ; VxdCall2 i) S* o/ K% N; s  F
   cmp   ax, 0f386h        ; magic number returned by system debuggers
- g, W& N- k3 T$ D   jz    SoftICE_detected$ E( _6 {& B9 ]$ }1 T

- S1 a5 a1 t* e5 z+ WHere again, several ways to detect it:
6 ~2 O9 O6 L( N# [2 }  F  B) f
    BPINT 41 if ax==4f/ J/ b2 D7 P/ t8 I$ T6 @
$ h4 R/ r4 d  P( j, Y
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
& P2 A  [4 z1 {4 F* ?. R$ D! @& B0 n# U2 ?/ G4 X6 T6 c
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
' J5 _3 C% E1 `+ N" H$ f
/ R  W/ y1 X* f    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!# R3 g5 n2 E( Y: I4 b0 p( o6 n

' ~8 r1 ?; l2 |0 m- u2 o& e__________________________________________________________________________
# {0 T  M7 S5 @6 j  X- Z; g) b" I, X9 q5 O! [
Method 13& J% i. I- I9 |3 C
=========
  z( H, U( G9 ~' |% a+ r: x. C! p1 F) x9 m8 }! v8 j
Not a real method of detection, but a good way to know if SoftICE is
8 V- a! v1 t4 o2 w# f' P# H& jinstalled on a computer and to locate its installation directory.6 E$ Y. K' S; S* x8 `
It is used by few softs which access the following registry keys (usually #2) :
4 z+ n# L$ A  _1 p" t4 u
" y3 R4 K' z& X8 b-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion* W1 [7 K, x+ j
\Uninstall\SoftICE  `* x6 Z  ]3 l) ~: d
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
, E  E. j% j; p- _9 M4 z9 j-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion2 r( [% r; y; C/ N% N. j: G$ N4 ^
\App Paths\Loader32.Exe/ I3 r0 {4 e- }4 Z5 }5 S8 g
  s4 S# X' G1 }' }
  i% \; O) s7 e( N( [( n
Note that some nasty apps could then erase all files from SoftICE directory
7 h0 o, i0 |* o& p% u+ A5 ]" w(I faced that once :-(
8 {/ q2 s! s/ P4 [9 s
: a0 ?4 z! F* M3 @Useful breakpoint to detect it:
0 {: ^; [# e* G; F% l5 o, ~3 f! h( r6 E( |
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'! [2 `/ }3 k# x8 `
/ |3 z7 q" C' r
__________________________________________________________________________
+ w( C4 ?* S$ l
) |" m' _  j- r+ s+ I
9 J+ w4 u0 F+ Q( f8 Y7 M/ TMethod 14 ; ^* N* J6 E: f
=========
0 E; G, C/ f& o% A, R. A8 q
& r6 A: e) i2 z5 p/ dA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
- \3 c3 H5 m0 e& mis to determines whether a debugger is running on your system (ring0 only).7 o( y) @* Q: Z$ T. h, h

4 W0 t3 a& T5 G' Z. r   VMMCall Test_Debug_Installed+ j, B6 e% U9 c9 t' }! S
   je      not_installed3 W" Z- ]) R# t: d1 {
5 C0 G# @8 r$ V* _
This service just checks a flag.
, b  b  @) _' S) x6 T: M9 f/ J7 e* Z</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部