About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>- i. ~! ~1 v1 j5 v
<TBODY>/ _% ~) H4 M& F( I* k1 S
<TR>% P1 k+ X' y  R8 T/ G
<TD><PRE>Method 01
9 D- X/ \. L8 J: m  c8 _) V! g=========6 i6 z1 n9 ]6 {" }0 i2 x; b/ A9 m
7 J- D7 ~+ B; H# M7 t
This method of detection of SoftICE (as well as the following one) is
% u9 Y! W4 ~# a+ t: lused by the majority of packers/encryptors found on Internet.* ]7 ]! s. E. H. t# l
It seeks the signature of BoundsChecker in SoftICE: F3 M3 l/ C/ e% Q9 @9 m. i

' [- N+ L2 s/ o4 Y" S/ A    mov     ebp, 04243484Bh        ; 'BCHK'- J/ M0 O3 i  H) X8 T" m
    mov     ax, 04h
: Z/ ]! x% T' K' v2 P4 S1 }    int     3       9 O# U+ G0 b! v7 [7 e7 e1 ?
    cmp     al,4. \8 n0 _: n- q
    jnz     SoftICE_Detected
/ J  f1 m( n% g% Y, E0 `, ]' I. ^5 K& w6 z
___________________________________________________________________________
& C1 {/ {+ l3 v7 g, P
( @+ O3 {, Y+ S( jMethod 02
0 M5 A$ Y$ P& o" J6 \$ `=========: p& M: l* b& p1 C% O' k
) J# l, ~) V4 h/ X, O) I% j, W
Still a method very much used (perhaps the most frequent one).  It is used" {5 R2 C+ S/ [! n7 j
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
) S: v7 q6 ]8 d- L: [* J; \or execute SoftICE commands...4 E  i1 y, E* t. V
It is also used to crash SoftICE and to force it to execute any commands
% M8 R9 W1 V/ f6 B1 |& _(HBOOT...) :-((  
3 m( Z  z( h) d$ f: |+ P1 A2 q
! `. i- v$ }' P7 Q' vHere is a quick description:
5 q( @; P6 [/ J1 D3 x-AX = 0910h   (Display string in SIce windows)7 q, Q+ j, k5 i8 L7 c$ b1 v$ r: }
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
% j0 P) w( _$ |; R3 e, `-AX = 0912h   (Get breakpoint infos)/ ?7 v% t3 n5 f- J
-AX = 0913h   (Set Sice breakpoints)
4 q6 r2 Y' Y# ~8 O-AX = 0914h   (Remove SIce breakoints)
  d6 u* J( r+ v) A5 x7 j6 K5 s. u/ \" A) `8 W/ K
Each time you'll meet this trick, you'll see:( `4 ]! C7 d7 V  Y& ]- P2 `% m) e
-SI = 4647h
; y* \- N- R% h-DI = 4A4Dh
+ ~: K- d: g& @2 S( k7 H% |. JWhich are the 'magic values' used by SoftIce.. H) |1 X3 v& ~  o  y# G7 G9 X
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.  A- E  h  |4 b6 O' P2 z

3 h( z- o& o* l/ IHere is one example from the file "Haspinst.exe" which is the dongle HASP" R( \- R& E% ^( l7 r$ D
Envelope utility use to protect DOS applications:
$ G! h; s( C7 O) w. p6 W! y. ?/ u4 z9 D2 |5 X
4 N3 w2 Y; E7 ?% N
4C19:0095   MOV    AX,0911  ; execute command.; ?0 V( O4 u* C
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).; X/ ~; U9 i, u1 c
4C19:009A   MOV    SI,4647  ; 1st magic value.! h1 a0 R% X% b! V' z
4C19:009D   MOV    DI,4A4D  ; 2nd magic value./ V8 Q* V2 l9 P# R/ j* D9 U; c, S
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)# n- l7 b# J3 t% ]" P
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute  n  g0 O1 M1 k% Z
4C19:00A4   INC    CX) _  G) i' E- ~
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute: p4 S/ g. @1 i
4C19:00A8   JB     0095     ; 6 different commands.
$ O# @  Z4 o+ U! Q  q4 ~0 U; e4 q2 L& ~4C19:00AA   JMP    0002     ; Bad_Guy jmp back.( S+ g1 v; ^% t# c" K
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
+ ?6 }4 ?. n: z
& A8 {# i" H) q) s# v- eThe program will execute 6 different SIce commands located at ds:dx, which
  p; j4 j$ e, Xare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
, ]; J% @3 V9 k8 E/ W/ J, J
4 p8 m% b$ O  Z/ B1 z. m, R* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
; K5 v% Q" E. r% W6 D___________________________________________________________________________
7 ]4 l' ], m: t8 E$ \( V' A: t' I) k- `9 z8 j
$ J6 Z7 B1 c" T9 Z- v
Method 03
) r; g5 G8 m1 v" e' h=========
; Y1 u% i& z" E& o' v( c7 L" H+ Q$ o, E" s$ j( s0 I! I# C9 j6 C- N4 Y
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
& t# y; O+ x3 T; |; K9 X5 n(API Get entry point)
6 C0 W  b0 t9 f( p        - D- ]" s, W) E& E. A1 J2 S
5 H7 o- v0 v! q3 S* h9 O
    xor     di,di
7 T& n2 {( _( @, _    mov     es,di' T" x* M9 ?/ U4 u
    mov     ax, 1684h       , s7 ]2 _" K3 Z" h4 R
    mov     bx, 0202h       ; VxD ID of winice
( }+ u# b3 ]  @# _/ C1 m3 t9 X    int     2Fh$ d+ W7 p* q9 f* s. ?7 F1 d. ?
    mov     ax, es          ; ES:DI -&gt; VxD API entry point1 M" q' y3 p7 H6 M/ u
    add     ax, di9 Y2 N1 v* w6 E, \3 T& W. U7 a
    test    ax,ax
: O6 d& ~5 o& s& d    jnz     SoftICE_Detected
; j* j3 Y* u  p
/ s6 T+ v5 G0 A  K4 I/ E___________________________________________________________________________1 e5 a4 @4 `6 e: h4 r4 V; V3 P, q' r
6 W8 I% q5 \" C6 J9 _
Method 04$ c, Y; T/ b' b! I* g! v
=========
/ f$ _2 v2 r! s" X& y8 e5 `3 f' s6 _  i; Z" }
Method identical to the preceding one except that it seeks the ID of SoftICE+ [! d/ J. P. U! k( r" a: Z: ~
GFX VxD.$ i# s! N1 o0 n( H/ m

1 ]+ [  N0 C' t& @# n0 e    xor     di,di
0 R: l$ D- ~  U4 L8 d- o: U    mov     es,di
) \4 S; W) c) C6 I    mov     ax, 1684h      
6 X9 h: \* h& L' @    mov     bx, 7a5Fh       ; VxD ID of SIWVID
  n! h9 p3 ^5 P( E$ u6 t3 Y    int     2fh
1 {0 M& ]( d* [' O' s    mov     ax, es          ; ES:DI -&gt; VxD API entry point
) F$ T7 p& I- t- \& y    add     ax, di
' C1 J! O' G+ p) \' \" }    test    ax,ax6 L4 S% T, c1 ^. {+ o' m- E
    jnz     SoftICE_Detected
' ^: X' O7 q/ W) ^. Y1 _  i/ _! e
7 s) c' ?: r3 B* w3 G! y__________________________________________________________________________. I+ i" Q! w& n& B0 e+ @* [# @
6 ~" i0 g+ N- D' P/ }
0 l5 Z/ S$ R+ A( q6 p7 ~
Method 05
& N/ }$ s4 d# C* A! j  q! p0 o' K8 O9 ^=========: |" \7 |6 b4 S$ S

6 P* K# v- K& X6 c1 }$ IMethod seeking the 'magic number' 0F386h returned (in ax) by all system9 R& L6 u2 L" U# s
debugger. It calls the int 41h, function 4Fh.
* c" Y3 r% B  Y2 k9 R2 i+ CThere are several alternatives.  
* B! r3 R. @9 B6 ]4 X* c- x, k  F' I& M3 T
The following one is the simplest:
0 ?* K2 l" W6 W2 ?# T$ f# n4 Y$ h! l! |: E8 N; }3 B. x! ]) b7 z
    mov     ax,4fh
! _2 W0 \% v2 E5 z8 f0 ~  j    int     41h
2 p  X2 p! W5 D# }    cmp     ax, 0F386# T* B) p* L' y* J0 i, l
    jz      SoftICE_detected7 A8 J+ o; R) ?/ e, @" c( A
9 G9 J1 S4 X1 U8 \* z6 j
2 c" H* i" ^* }; E2 b0 i) c& m
Next method as well as the following one are 2 examples from Stone's / s- y) `' h( q
"stn-wid.zip" (www.cracking.net):- V  Q% a5 h! z4 v* x8 J
8 B, j& F! V* i, t
    mov     bx, cs( `( ?6 ^) y* y7 O2 Q
    lea     dx, int41handler2( y! M( C* i! }: ?1 C3 U/ I- H: E
    xchg    dx, es:[41h*4]4 A+ \$ o+ S# Z  E/ F. B5 X0 t
    xchg    bx, es:[41h*4+2]0 W+ ~2 l$ m/ e. c
    mov     ax,4fh
" p/ h; }6 v2 @0 ]    int     41h
$ x; p  s' j  t- C' s6 n    xchg    dx, es:[41h*4]
  W# u" J$ {. [+ q6 n: N  m    xchg    bx, es:[41h*4+2]3 B8 t- f# }* J+ U- F  G
    cmp     ax, 0f386h
  J1 V/ @# g9 ~. V# K    jz      SoftICE_detected
" `( V# D' u: P9 C, O( G
9 j+ g! S6 w: u9 _2 j; Xint41handler2 PROC4 ]* \  l) `/ u; b% o8 V% Z+ c. [. w
    iret; b8 H6 T2 t( q
int41handler2 ENDP& m1 K9 r2 i! j* T

. U$ e, p4 n/ s  m- a+ [/ E" q
. J4 }2 b3 M9 l! o- o6 w7 G6 E_________________________________________________________________________* z3 P" i- b( t/ m( h$ c4 e
3 L1 A" a2 e: N& ?2 \1 }
. Z7 N1 u1 g! P$ h# O
Method 06
" i9 d9 Q0 y* ?3 ]=========4 g5 [: y! G" A8 i& W6 @. u
& s3 b+ w" W4 |1 w

3 R8 W, A( I) @9 Y1 r+ _; [2nd method similar to the preceding one but more difficult to detect:5 a6 T# [( ^6 w5 y5 z- l

0 Q% D7 d0 ?6 U$ u: P" z& E3 I
" u' u! ~3 R$ ]0 E5 N- Tint41handler PROC
( ?8 e# }' A" D0 V5 v    mov     cl,al# C7 B9 ]! a1 m( X2 c  I
    iret! m' J% G0 {) R  R  ^# n5 g* B
int41handler ENDP
" s# s! J: E/ n1 ~8 Q
6 J9 R0 ]2 |1 e* @
4 I- Q  i; J5 {' T! D- h' p) F    xor     ax,ax
! {+ S  }# g" G8 V    mov     es,ax( f$ M& o& X% p+ M  ~! U4 G
    mov     bx, cs
2 V' B* n4 m/ C' ?    lea     dx, int41handler! S" o$ N. f+ A/ I6 A! E
    xchg    dx, es:[41h*4]+ M9 ~; V; C9 D* o, N9 {" C# [
    xchg    bx, es:[41h*4+2]
: Z4 M) \! |) s' a. c" p2 s9 M    in      al, 40h
" t% K+ w+ e, b% W    xor     cx,cx: g# l0 f6 Q7 s' J$ C1 c5 W9 N
    int     41h1 h* n. W7 g( R. M
    xchg    dx, es:[41h*4]
" V# ^, O% S3 ^4 Y9 w' L7 J    xchg    bx, es:[41h*4+2]/ A6 g, m, @5 ~. o' C4 L4 U
    cmp     cl,al$ {+ S% X0 w+ z7 T% h' ]3 o* O; M( ^
    jnz     SoftICE_detected
% Z" }" d( K) ?. ]  p# j2 h- }; K1 i; D7 k- ^
_________________________________________________________________________+ p. J) A- W6 D" E0 q
5 y. c! s' i: w/ S
Method 071 e/ Q9 Q: |# R: n
=========" r9 s% ]8 a) Y
, \8 v2 t8 X( `. ]
Method of detection of the WinICE handler in the int68h (V86)
2 M: y! ]& C) t1 [; v  u/ W$ _( a* k6 S
    mov     ah,43h
1 d# {5 J3 C; f4 L3 ?8 ~" M    int     68h* C8 D4 o4 x0 Q$ l
    cmp     ax,0F386h# g, t, Q+ n- a. P7 o% I
    jz      SoftICE_Detected- ~9 l% [! C9 K( F) Z) ~# L

6 w( A# m# c0 m4 I6 S3 C7 m- d" R0 x* C) w
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit& x* c& g: w. A6 G- [9 w
   app like this:9 b# g# v7 b9 G

+ i0 t0 p  O0 t* I2 u1 h# y   BPX exec_int if ax==68
+ h2 A+ e7 V7 Y& w: u5 E   (function called is located at byte ptr [ebp+1Dh] and client eip is" Z# Q* p% Y/ G, m4 V3 Q! o; O
   located at [ebp+48h] for 32Bit apps)
) B" _7 U/ Q% C__________________________________________________________________________
/ J0 A# f# P; C1 j0 y+ w! V( S5 n
4 `" p! b( E( l; F
Method 08
# R! P" o5 \/ L5 i/ r. Y  z=========0 w: C4 h3 i; w
7 c- G0 P, ^. F* C/ P: Q
It is not a method of detection of SoftICE but a possibility to crash the
8 O- _- T0 |; _9 i# u0 `3 jsystem by intercepting int 01h and int 03h and redirecting them to another8 O1 r; O  n# u
routine.
2 w& i. v* \1 |It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points( l: T' k3 L! A% N. e& z
to the new routine to execute (hangs computer...)
- l- }) t1 U* V- c+ F( k7 j, T6 A' x6 o
    mov     ah, 25h7 t- Q3 w/ Z! W6 a. m8 |
    mov     al, Int_Number (01h or 03h)# m3 U) b6 I7 z1 d3 K
    mov     dx, offset New_Int_Routine
4 ~7 y: q! R8 v; E3 e2 u    int     21h
/ a+ V4 b# g3 S, H$ B% y8 Z. f1 }  ^9 r7 K$ @9 Z
__________________________________________________________________________
" P& Q  \0 s$ {9 W- Y3 y) z
! e8 x/ I7 m7 RMethod 09/ g% z* k2 B" k, W0 h- Q+ x0 N7 M
=========
& |, g+ v' o. P: z' |& b+ P- _& \# i" j2 K( H- f. F7 J; i- p
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
& @' _' u5 p8 Y$ R3 z- w9 u3 P+ Rperformed in ring0 (VxD or a ring3 app using the VxdCall).
; C# v9 @/ B+ U2 w% WThe Get_DDB service is used to determine whether or not a VxD is installed
  J7 r6 g6 K  b# Z, g; \for the specified device and returns a Device Description Block (in ecx) for3 n, S4 [, e  @; S6 W
that device if it is installed.
* u# q, t8 `: Z7 g1 h# [
8 M: h7 Y: {0 U, m. T  ?) h   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID1 [, ?+ I6 m$ t7 l* I" r
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
, D2 f- @' g8 @4 p/ u% u   VMMCall Get_DDB
5 t8 }3 E. m+ f$ ?   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
8 ]( Q. t7 g1 k5 F
( a* z9 `( t' SNote as well that you can easily detect this method with SoftICE:0 k' Y1 h* t4 H" D. T
   bpx Get_DDB if ax==0202 || ax==7a5fh# f" l+ v; W: E. Q
- w/ u2 a1 l" [  e9 W
__________________________________________________________________________
. A0 b6 E. k3 v5 q1 `# x4 ?, Q; p( I% U+ ]. A
Method 10- {) D: n. f* @" p  `
=========
9 E, R2 `# ~, ?3 @0 B- F8 L0 s% S# I
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with9 L8 P. N( O& N) z: G7 E
  SoftICE while the option is enable!!2 L% W6 b. q# B+ r; {
$ [+ W* \) ?) H! b7 x
This trick is very efficient:
" Z6 P' t9 T9 z; ?1 B+ A$ y3 Hby checking the Debug Registers, you can detect if SoftICE is loaded# }% O5 a7 i8 F  |! X
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
, A1 ^5 x$ n% L2 Athere are some memory breakpoints set (dr0 to dr3) simply by reading their
8 R0 y# r9 J8 T% O% G. {  mvalue (in ring0 only). Values can be manipulated and or changed as well
4 [' j, x4 N9 V+ v& J  s(clearing BPMs for instance)' R& j* i3 t. A/ ~( Q: p8 @& m

; B" ], p4 u9 E" O7 V__________________________________________________________________________3 y/ }" o# V6 ?4 x! O7 S# r

" A9 ~( k& n  x$ lMethod 119 Z$ H& m; g% {2 v" h  h4 U
=========7 G2 n* O, W+ S0 h' F- o8 o

2 I4 d3 `  _% u' \6 |This method is most known as 'MeltICE' because it has been freely distributed# K: }! T/ y7 t
via www.winfiles.com. However it was first used by NuMega people to allow
+ h& k2 J: D9 Q. t8 ?9 N4 rSymbol Loader to check if SoftICE was active or not (the code is located
" V( {8 ]. ^$ J' f1 X' r7 Winside nmtrans.dll).6 d8 x7 K5 ?5 n- w

+ b3 T6 ?( y* S+ ^- d; hThe way it works is very simple:
% O% S0 l' ]. p/ F- ^9 k0 \It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for; c- R3 b9 d, R+ r8 e% L
WinNT) with the CreateFileA API.
$ j# S9 W3 \2 \, U* F1 W' F. h7 M8 c" `: }
, D7 K' c; [- h5 p- OHere is a sample (checking for 'SICE'):" W# H) E8 O$ f* {& A/ X2 T) O
7 `2 ~+ W# o! w( X. J2 W, @
BOOL IsSoftIce95Loaded()
) }* A7 M- A$ n1 B2 O! o5 F+ M' e( W{
! \0 a$ t( J, t3 C: Z, F9 q   HANDLE hFile;  
7 d& r% r! N: `# G/ r1 H( x   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
1 P+ r3 n. ~% q                      FILE_SHARE_READ | FILE_SHARE_WRITE,
! D$ Q! C! F% [+ l' @: ~( p                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
0 q7 [: N+ I# f  M6 `2 a. g   if( hFile != INVALID_HANDLE_VALUE )3 k7 r* j! b2 ~$ i( q; C
   {1 ~* `4 x6 \5 t" p( F& d6 F9 F+ v
      CloseHandle(hFile);
9 l1 r. `1 e3 k/ g7 u' C6 H6 @2 o' f  T      return TRUE;
* w. U/ G! p9 ~0 H7 v+ x" n" H, A" u   }
- [: P9 N4 R6 u) M2 ]# p   return FALSE;
1 A! h. K. l) O9 d( s}$ H2 @9 |0 H% U) {0 t* R! \
* h7 i! A% B0 Z% y
Although this trick calls the CreateFileA function, don't even expect to be
/ x2 e6 [- f. ?3 z# Bable to intercept it by installing a IFS hook: it will not work, no way!$ [/ i' i; d+ P' [3 U
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
1 U- S; u7 G& y. W4 oservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
- P0 Y& m6 c4 s7 r, m5 C1 s) ?and then browse the DDB list until it find the VxD and its DDB_Control_Proc' ~. q5 {- h5 k8 g1 M! \& g! N$ ~
field.
5 q% Y0 [. U2 Y* e9 EIn fact, its purpose is not to load/unload VxDs but only to send a 9 p1 H' @& H& v
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)+ `, w4 V8 ]! x  c& g
to the VxD Control_Dispatch proc (how the hell a shareware soft could try4 y" F6 L& [& c
to load/unload a non-dynamically loadable driver such as SoftICE ;-).8 G/ h- |% _" J" ]! Q$ E- }: N& o
If the VxD is loaded, it will always clear eax and the Carry flag to allow
) a  a# D4 O0 j( Lits handle to be opened and then, will be detected.0 V, g/ \) S' q3 j4 \$ \
You can check that simply by hooking Winice.exe control proc entry point
. R" _  s* v- _* C3 Bwhile running MeltICE.
: Z8 x7 x4 X& N4 j. n) ~  q
; a/ o0 ~+ N6 A+ ]7 y8 X/ @- ]+ m3 o* T! ^6 r
  00401067:  push      00402025    ; \\.\SICE
! P2 [9 [$ a  u: w( j  0040106C:  call      CreateFileA
0 F7 |$ Y; }3 i8 W. a" a" m- N  _  00401071:  cmp       eax,-001
* ^! }1 I3 A4 B6 h9 g  00401074:  je        00401091# C5 c  j# a- E0 }

2 J9 a+ R4 k7 i4 _; s6 v+ Y
/ n" b# p9 v$ V  \7 X2 MThere could be hundreds of BPX you could use to detect this trick.
% }% u. E# s# V+ i8 f$ R0 t7 z" \-The most classical one is:/ t7 k+ T* b- u
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||; a+ a9 u8 d5 a, {& s* _% |
    *(esp-&gt;4+4)=='NTIC'
3 @/ F, j4 `+ u/ o1 d* X
( b# n' N; ]/ e-The most exotic ones (could be very slooooow :-(
$ c2 K& ^) z* n9 r% [; O   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  2 ]- i" e8 n% Y
     ;will break 3 times :-(
* `# C" c0 N: N$ H0 v& Z7 n2 ^; G- C4 e$ [8 H" J
-or (a bit) faster:
* m* H9 ?+ A6 `7 {4 D   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
# S# w8 M  j+ ~/ m. O. O
8 G! y  d5 N1 }* N2 v2 z' L- W- P   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  0 h. y( C: `  h$ n0 t  t
     ;will break 3 times :-(
3 W% n4 B% v& w; d$ ]' \" A
9 ~2 [  d6 e& W8 w-Much faster:
" S, g, r5 R: g! \0 y   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
& {9 ]+ D3 M: z) Y& q  D' T  j1 g' {) l
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen1 l1 {9 H% m& m7 u! }& ^3 q
function to do the same job:6 _) h" R1 {! ?

1 _/ f9 f* E7 H( R' o   push    00                        ; OF_READ$ R3 ]/ c9 ?2 l! j
   mov     eax,[00656634]            ; '\\.\SICE',01 p0 x6 F1 d' {" K2 e8 ~: A9 R9 o
   push    eax
- `. ]$ D) x+ V: J' B( d   call    KERNEL32!_lopen
  M% k2 L) e1 ^5 u. K# X" @) Z   inc     eax# ?% h' k# M+ Q/ N. t
   jnz     00650589                  ; detected
. l% p+ |3 I' M- A, b   push    00                        ; OF_READ! h- O# s6 U1 q) t, I& ^: J
   mov     eax,[00656638]            ; '\\.\SICE'
3 X& h& a# \; X' m8 P) ~   push    eax3 p0 U7 B3 V& N" O8 Y; P
   call    KERNEL32!_lopen
( l% z: l! O5 k   inc     eax
7 O. O; t2 _8 I  q& U9 l) ~   jz      006505ae                  ; not detected- @' g7 E% V( O& k0 W
) Z& d. m. X4 z1 ]

" V- o4 P! e, Q; |* P__________________________________________________________________________6 j. [/ D# V- \6 [, O1 K6 e" W
3 I& W9 Y8 Z5 p! g: I) ^
Method 12( i5 b0 N' z) n% Q* A: y; m# J: p
=========
( {  Q3 z4 x! ]9 m# T! [: I" g9 m: h8 z* L
This trick is similar to int41h/4fh Debugger installation check (code 05
7 A" L, U# h! ^: B2 z&amp; 06) but very limited because it's only available for Win95/98 (not NT)
( M4 }8 e0 ^) O. q  q( @. qas it uses the VxDCall backdoor. This detection was found in Bleem Demo.
. r! d* t2 @4 [) o+ T# q/ R! o- v
# m4 v  i) v, z  q   push  0000004fh         ; function 4fh
: }. e) a( z: F) w! o( n4 ^   push  002a002ah         ; high word specifies which VxD (VWIN32)
, @1 \) C0 b, [( @: ^. L6 p6 R                           ; low word specifies which service, ?6 U" y: R7 c6 @3 u% B( z( T
                             (VWIN32_Int41Dispatch)
: y0 z4 m0 t8 Q. F1 o5 `. m7 F   call  Kernel32!ORD_001  ; VxdCall' w0 T" n2 W6 q3 t1 n/ J0 |
   cmp   ax, 0f386h        ; magic number returned by system debuggers/ E1 p, J! F! Y, i1 c/ |* R0 c
   jz    SoftICE_detected6 z- T1 [. e/ r! b8 h+ Z

: ]3 l' O6 l4 U7 M& tHere again, several ways to detect it:: ]; E! ^9 s, D0 C* {
4 d, C1 r0 q/ g, i5 {* B- e
    BPINT 41 if ax==4f$ S: [+ W1 W' [! @2 ~

8 D* t4 r0 v2 l    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
1 [9 G+ X) l4 w! g% P- S/ P3 w& Q( G6 s5 |/ S
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
$ e4 T% h! Q! G& G6 U  I8 v5 L/ W  ~, I% F
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
# l6 V0 h  @, y. u( t! w& I' j6 t6 a) o4 K0 s" W' R% h. A3 d4 Q1 m! J
__________________________________________________________________________
. k( e9 G1 m$ d3 @
) L$ N" J/ R/ ]) f  o( C" u& @3 uMethod 137 g+ k1 e8 L) s  g
=========
2 W1 B7 a9 ~: P; ~" a
  t) S7 }  i1 e" gNot a real method of detection, but a good way to know if SoftICE is
: u: I+ Z. w* ?, N" f7 Ginstalled on a computer and to locate its installation directory.* r$ ]( a0 m2 V4 w$ q
It is used by few softs which access the following registry keys (usually #2) :/ O5 i0 ]$ r6 g" Z) f; d( z+ a+ A
; K( B7 F. a2 ~9 {
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
3 S+ p* K5 w* f\Uninstall\SoftICE
( k. K+ P8 x; r$ f$ {6 f-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE8 ~# @; ^9 H% {# _5 G9 B
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion" {$ F( i" H- |1 n4 }2 l
\App Paths\Loader32.Exe
& X1 X) y6 {/ u5 d. Y! E1 s3 o
; }* o( o7 i) |% T+ i
0 A5 R4 q9 ?; CNote that some nasty apps could then erase all files from SoftICE directory
9 X- v$ K# f& t/ D0 O2 j9 c4 @(I faced that once :-(
. `# e5 D' P5 y! b( d& `
3 v7 A' x: f% S1 @7 Z2 |0 A& G: kUseful breakpoint to detect it:
2 }8 e5 k, `2 H5 }- J
. p4 v* A' v" I  Y* _     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'  ]9 W9 b0 k7 ~+ v3 B4 S

% I% X9 C( S% U, {5 x__________________________________________________________________________
+ Q6 `. f1 l4 L
; z1 E. W' ^6 g0 z& m& D% C3 D6 L% E! B+ L$ m* ^
Method 14   q! \: D# \  O7 ]
=========4 v( W, t0 f. A0 V2 E7 ?; F7 h
0 M" E) t# \' S. ?
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
, o' M% H  U( f% i/ iis to determines whether a debugger is running on your system (ring0 only).
: \7 R) G+ \" D7 A9 ^6 u5 p$ A$ m' B: s' @4 H" K: s
   VMMCall Test_Debug_Installed9 a- F6 g5 q# h$ j, [! s
   je      not_installed
+ h# C, @: J3 y9 l; y
- c( i+ E) _( N, [  L! G0 s1 {3 A  @This service just checks a flag.3 i9 s! l/ j5 P5 \5 u
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部