About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
  [5 f& \5 Q: S" m<TBODY>7 |/ W" l6 v. X, ]5 k; c
<TR>
5 w4 H9 A& O3 h" |<TD><PRE>Method 01 & D: a/ z: Y! H3 C
=========
9 B  t! `& S0 r! I! N8 A, u: B; f1 |( z7 Q
This method of detection of SoftICE (as well as the following one) is0 a, M! s9 i7 t) O7 J  H
used by the majority of packers/encryptors found on Internet.
4 P6 @9 z0 a; c+ w: A8 k8 y# vIt seeks the signature of BoundsChecker in SoftICE
# \6 h4 i- S9 W6 W6 v$ c" O, E4 \( s0 H7 t3 x) \3 y8 m/ ~! H) m
    mov     ebp, 04243484Bh        ; 'BCHK'$ P2 M+ V( x$ _* R- ~3 \8 [: c3 C8 \
    mov     ax, 04h
" o/ K% y$ ]9 Q( ~    int     3      
4 @& x" b9 A# q# S; w) e. G  w    cmp     al,4
- s" ]# c+ b4 _7 T0 }    jnz     SoftICE_Detected
% L- d& T: T3 |) N
' {, q# p* `- z___________________________________________________________________________
2 D2 H0 D& I) z0 C$ F* T! t  u% ?) ?& {
Method 027 j* q! q& |: j+ o  `
=========$ K; m6 |7 B& h3 E) v8 A; Z3 j

2 Z8 P3 {' d) H5 L4 a1 o* A0 @Still a method very much used (perhaps the most frequent one).  It is used9 V9 J* j5 ?# _7 a; ]5 w, M- A
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,0 P( }3 j9 Y$ }' o6 L; c5 }8 K3 ~
or execute SoftICE commands...
9 {; n' Z9 o8 K. t! UIt is also used to crash SoftICE and to force it to execute any commands/ D6 _( f3 V1 A/ s6 u. H
(HBOOT...) :-((  
6 T# [2 f8 N1 n. p( T5 Q
0 f* [0 {+ B& [  i$ Y9 J6 mHere is a quick description:, C, V& ~. d/ g) X9 z5 H
-AX = 0910h   (Display string in SIce windows)
# v% J$ Z$ I9 P& m3 H/ x! @-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
. w( t- D4 B. o-AX = 0912h   (Get breakpoint infos)& J. Y0 x- V' h
-AX = 0913h   (Set Sice breakpoints)
* n% n# X& T: k+ |( c8 U0 F( r; R  t-AX = 0914h   (Remove SIce breakoints)
- d' M5 p0 D, y- y# m6 L
( Q1 G2 j$ a" ]' XEach time you'll meet this trick, you'll see:( `8 ^# {: ]6 w, J% n
-SI = 4647h
2 m2 v/ q/ }4 H8 n$ G, M3 y$ F5 U-DI = 4A4Dh0 V- x$ q  ~7 Y
Which are the 'magic values' used by SoftIce.
0 D# E4 j' F7 M+ m- }" F& F# pFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
9 E" q5 H. X4 ?' [( u+ y1 P- U8 v1 Y4 b
Here is one example from the file "Haspinst.exe" which is the dongle HASP
. u" s; n/ ?  CEnvelope utility use to protect DOS applications:
9 n" _+ r5 U' @4 X
* q! Q  t- {8 G  {1 m5 S4 Y3 P1 a
4C19:0095   MOV    AX,0911  ; execute command.
$ z1 ?2 n2 h3 D7 p! c, S2 I# F4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).3 w/ F. Y2 v3 y1 x
4C19:009A   MOV    SI,4647  ; 1st magic value.% l+ B( C$ x& ?/ B
4C19:009D   MOV    DI,4A4D  ; 2nd magic value.' P! Q/ ?# K. W8 Y, X+ }6 p2 F
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
# O# H! R/ v0 m4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
- \0 t' d7 M2 |' O4 v9 c. M4C19:00A4   INC    CX
' X& e4 b1 p7 H# K% s8 T4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute5 j! V' Y( h, m) ]1 l
4C19:00A8   JB     0095     ; 6 different commands.* n' L6 \* I) M. J0 {4 I* j
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
& r! s% i( V6 V6 d& A- \' m" V4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)% b5 C, u( h) [% y- Q1 [9 \' ?
- [/ z/ Y' _' o
The program will execute 6 different SIce commands located at ds:dx, which. d0 A' ]5 [/ d! C1 Z3 V
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
1 S  c5 R6 }+ N' }. H# n# O* o" v# F- |' U
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
8 ~& G3 d6 c" `: _; X___________________________________________________________________________
2 ^3 h$ t/ C4 t3 o0 N+ i7 d
, f% {. V! m/ `0 ~0 m3 N; k/ v; Z- c4 j: w. S9 F
Method 03! ^2 q: e2 d4 Z( |! i& j
=========" e8 E7 c0 \" l( l6 M
, s! B3 O) Y) `2 v1 l
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h( q* d; L/ O% }) J: U
(API Get entry point)
# ?( R. x6 i6 A8 v5 I! j. T        
& t0 c5 g& _) R6 P/ C1 j8 l) p2 K
    xor     di,di7 |& p, N6 f; \7 y! r
    mov     es,di. `; N2 a6 r% @
    mov     ax, 1684h      
! `0 R7 `; p" U! Y    mov     bx, 0202h       ; VxD ID of winice- \4 f4 O4 c# W, ?' x+ Y
    int     2Fh) P" \9 R/ L! U. b. k" M/ X
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
5 F, e- k9 p4 N7 @$ _. `/ R9 n8 A    add     ax, di: r/ x# ?$ U9 @2 S
    test    ax,ax. ]' R  i8 Q6 K. @. H0 Z8 K, @
    jnz     SoftICE_Detected% \$ b5 i8 P# J" P5 W: E5 s
( x% P% z2 N( Q3 W: ]) p4 u' \  a
___________________________________________________________________________
8 {2 X% B/ d+ ~' `# Q- Q/ K) N* J1 G& l: E
Method 04: |4 D, x2 z6 t" i
=========8 \, D0 e2 P; h! `9 u7 d3 v* O2 m
. U2 i0 w* @/ q6 p  c/ d& m3 ?) z
Method identical to the preceding one except that it seeks the ID of SoftICE  O7 h3 \# U' z* P. M1 q! k
GFX VxD.- D$ H" ]: W- y2 }
* d  A1 M. e1 P4 A: ~/ B
    xor     di,di
5 W9 ^* ~- y) `8 H  o    mov     es,di5 m3 ?4 g8 N' G  v! z% p9 L9 j+ p3 k( Y
    mov     ax, 1684h         a8 ^1 C, x7 o- @# v. _" L* n5 ]0 A
    mov     bx, 7a5Fh       ; VxD ID of SIWVID5 e+ J0 E: ~! h' y( Y' E( @' ~; T
    int     2fh" I/ h  _1 l5 U# v# [
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
( ?6 y: S% y) R# k    add     ax, di
6 ?2 ?* F  F1 a/ S    test    ax,ax
: d5 |( s& y8 S# T    jnz     SoftICE_Detected8 }8 j: A( t) s% {/ `

" ]8 T! H0 p+ \+ ~__________________________________________________________________________1 w; \4 L3 O3 [" F  h' w  G6 Z
& n: O2 d6 p3 p- I) J
& q! @2 h2 T: x
Method 057 A2 N' ?# S$ e3 x
=========6 P; c/ `/ x, [- T

* ]  Y! k4 x; }9 l  _! @' qMethod seeking the 'magic number' 0F386h returned (in ax) by all system
! I/ i4 Q: w+ y; c& w+ Xdebugger. It calls the int 41h, function 4Fh.8 d9 C  e, o7 W# p
There are several alternatives.  . `, g4 W" y5 L/ f
; V. G8 C) Q$ H( u3 @
The following one is the simplest:" [  j' ?4 Y( |( w1 @. g9 c' I

" W4 E7 s+ B* k1 I    mov     ax,4fh# ?1 _" Z' u" T$ }" H
    int     41h6 a% @! j" j) e8 G. H  t2 x6 M
    cmp     ax, 0F386) c5 J6 w2 o' A3 S3 t9 m
    jz      SoftICE_detected
" r" w# C& `% Q1 _1 u2 b2 ?
7 c% U1 k1 E! [5 n+ N. H9 d6 o8 g" i5 y& k0 c
Next method as well as the following one are 2 examples from Stone's
- Q  j& ^. \1 d7 l6 o8 v( ^, U; j; d"stn-wid.zip" (www.cracking.net):+ ^! W; v1 J. T3 L) `5 Z+ w
, D- W8 L5 ]3 f, i/ z
    mov     bx, cs$ l# ]' k# g: ]
    lea     dx, int41handler2
2 t6 _( p  m1 P. e6 u3 F    xchg    dx, es:[41h*4]1 |. v% Q; t& R
    xchg    bx, es:[41h*4+2]/ p9 t* m4 L/ U( Z
    mov     ax,4fh
) t6 F4 z$ V0 w9 H1 K3 i9 B9 q    int     41h
8 q8 f1 Q# l9 f% M* H    xchg    dx, es:[41h*4]' N% S" S' G3 o2 a8 y
    xchg    bx, es:[41h*4+2]
9 [$ D3 L- H9 ?/ q; z  O    cmp     ax, 0f386h
, T( B( q' d% a# s7 c5 v# y+ n$ ?    jz      SoftICE_detected! s0 j! P" d3 |% Y8 W. P- s

7 _  P% k1 H7 {: W1 @int41handler2 PROC
' W; B+ P& ?9 y8 K    iret3 O: }$ z( a+ d$ ^' X
int41handler2 ENDP
8 G% X$ e2 ?1 r' Y
0 ]5 P4 k- I- S; x, u" W8 M* T- J: B; T
_________________________________________________________________________
1 t5 D# u0 _. ^1 |+ @7 h% S7 }) E6 B5 p9 R- S! Z  d1 v1 D6 {5 H
2 h  g- _" T4 O3 ]# E
Method 065 W7 I9 C2 q9 C# V2 p# B- G, ?
=========* a$ b9 P, ~1 B! g' q& B) j

! G- h8 g# O( C5 k, ]6 [$ C, `
* ^: w9 X+ w# M4 {5 m4 H0 V2nd method similar to the preceding one but more difficult to detect:$ U, m+ U1 b$ g
' w! p/ u  m& F, _3 a

: O, l1 {3 Z* q8 Xint41handler PROC
, X8 \; y% N1 S" E. T; S( j; O    mov     cl,al
; V: Z8 D7 b' L! v9 Y    iret
0 U# W3 V1 W7 k& {. W" |: Q& wint41handler ENDP
4 Z0 j0 p* I1 H; W( N, s
8 M7 o4 F5 `# u8 t0 n$ J1 _- g" |  h! e5 k! b1 u
    xor     ax,ax
7 X8 d5 t) F4 s3 W' O    mov     es,ax  |+ P, A( r) g
    mov     bx, cs# d3 E* E: V7 o7 V
    lea     dx, int41handler; y' `/ ~  T3 q0 w* A
    xchg    dx, es:[41h*4]
+ S" O; M) N6 y+ S    xchg    bx, es:[41h*4+2]
2 ~, ^* `! P! t8 _' `    in      al, 40h  l! Z+ g0 O& G" Y7 n0 m/ N
    xor     cx,cx- a' u) T6 Y* c" l. K4 F' _
    int     41h
6 s6 S2 `' m5 x& b: f1 Y; ]    xchg    dx, es:[41h*4]1 ?  A& m' u2 x, T$ V) p: W$ p
    xchg    bx, es:[41h*4+2]
. g: A/ I' }6 E) v    cmp     cl,al2 p2 o. d3 x+ }: E, P& O
    jnz     SoftICE_detected
. r$ o+ o( G$ U! ^0 b6 N8 n, g# C7 Z
_________________________________________________________________________
$ f+ D" P' ]" l+ w
* l# |& r; T. Z- k* ^$ {Method 07
# y, O: f% E9 [  Y=========
" T/ q  S$ Y% |3 `
, c: n# q  {( F: J- B, A6 y" ]6 H  I8 TMethod of detection of the WinICE handler in the int68h (V86)
7 J" [- N( I% @/ F8 t
7 ]3 h' E! B4 R) k+ h2 c    mov     ah,43h
, \( s8 ?! L% V    int     68h0 B+ K" [' |& R' {9 G+ {$ b
    cmp     ax,0F386h" n8 r2 S$ ~5 f; E0 y  P
    jz      SoftICE_Detected
( Q, ]7 J( i2 M0 Y, ^: }& M5 ~
7 g6 [; m9 i; B2 m' O
1 S/ Y, _. g5 C& n* `=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
  j! K( _5 J$ f% x4 w8 x   app like this:7 ~5 s9 i7 b# k2 [! S

* u+ Q3 ^( ], f& b- Y7 ]   BPX exec_int if ax==68. ~0 o. v9 l# F
   (function called is located at byte ptr [ebp+1Dh] and client eip is, B- o1 P* k7 Y& @9 G/ M+ `
   located at [ebp+48h] for 32Bit apps)+ l2 u% e& s& V, ^7 B" S
__________________________________________________________________________+ ?7 a/ w9 G7 f2 y* k  ~7 M

2 b7 ~8 L1 f, T( j
6 b+ B  x9 ^. o, KMethod 08
& y9 e3 K) q' h=========9 ]: E, _$ ~. ~) e
. B: L. a+ K6 [% c8 z8 Z( T
It is not a method of detection of SoftICE but a possibility to crash the) F: b1 l/ S0 G, }/ t
system by intercepting int 01h and int 03h and redirecting them to another# Y; l1 [9 z0 y- [$ D$ b; f
routine.
' F# q( X' a4 i. T0 B- }It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
; d: e  L; B9 x. |/ a2 D9 G5 \/ eto the new routine to execute (hangs computer...): ]1 {/ v2 ~  C3 z' F3 J: M
% {& |9 X3 k8 Y, b, @" g
    mov     ah, 25h7 }; ^$ `5 H/ d7 o
    mov     al, Int_Number (01h or 03h)- |$ @" B+ H$ \) e
    mov     dx, offset New_Int_Routine6 k& F# ^$ j: N: b/ j5 {- W% \, h
    int     21h) f5 d7 T$ u, h- E
6 E1 ^- g- O+ s4 Z6 O# i# l$ w
__________________________________________________________________________
9 J' v% o$ |* l# s# F2 k* L4 M# O% E0 M5 y- }* c% h2 J3 L2 N- w) |
Method 09
/ t+ X, t' p5 `& d# k=========9 U  E. s9 {# ^$ e

- u% i' w1 R7 R- V- }9 XThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only+ u) e- v$ ?  W
performed in ring0 (VxD or a ring3 app using the VxdCall).* w* n% U$ Q* t  I0 s5 m
The Get_DDB service is used to determine whether or not a VxD is installed( s- X5 N  n1 p( j$ h
for the specified device and returns a Device Description Block (in ecx) for2 [* [# O9 B. k- Q( {5 h, R" r1 ~
that device if it is installed.! i7 q3 t+ i; }* H- ]

8 H! \# t# t2 |" A" K, q4 M   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID9 x2 o( n, P$ a2 n4 y
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-), }% N, V& G' [4 v. T
   VMMCall Get_DDB8 _' ]! }9 m% h1 g. K6 p6 f( M. O
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed. ^1 ?* t& U5 o6 F: {3 D7 D

& s: v7 K  J3 x: oNote as well that you can easily detect this method with SoftICE:1 k" `& Y" k/ |/ z8 {$ ~# F
   bpx Get_DDB if ax==0202 || ax==7a5fh6 E4 A* w  L) `+ R: l# \% F
  d( M' c, {3 N% ^: `( u
__________________________________________________________________________$ R1 ?5 j1 Y" `, S" c; l% X

; `  t5 d& f6 U. u2 mMethod 10' X8 d* D. S8 L3 \
=========/ L9 J+ b* U( I( o9 E5 x7 \0 \
' D4 Q  I6 N% \2 m( e+ K
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with7 |  l: L  Z- O7 u. c) K
  SoftICE while the option is enable!!' E" w% D6 B1 ?

1 M3 t6 F8 t2 w- ]3 _" m* tThis trick is very efficient:. F: o9 c( i. I! }: K( S8 {- O3 J
by checking the Debug Registers, you can detect if SoftICE is loaded% a1 z% ?' G2 w
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
2 O7 K2 ?4 \7 U4 f" mthere are some memory breakpoints set (dr0 to dr3) simply by reading their; I7 Q7 s5 A$ u6 V  q
value (in ring0 only). Values can be manipulated and or changed as well+ o. E) t) N% ]+ j: s7 I. _  E2 a2 B
(clearing BPMs for instance)  c/ i, ~5 G9 v! s' l

  ^4 ~7 T3 l. ]$ J$ w" v* |& `__________________________________________________________________________' z1 Y6 w0 i- ]

) v3 Z4 G7 _7 OMethod 111 b% l. m$ P: q5 R' u. _
=========( E2 c- E6 \; M; Z8 h& x
& P, R9 X: A9 ?# W0 O' _7 e7 Z
This method is most known as 'MeltICE' because it has been freely distributed# ~8 [0 ~8 ]8 `! d# |% k3 @
via www.winfiles.com. However it was first used by NuMega people to allow/ T0 |  t1 a- w2 N/ T8 c
Symbol Loader to check if SoftICE was active or not (the code is located+ ~3 M; @: x/ }; ^6 i& O( w  ~; L# ]
inside nmtrans.dll).
& A8 ^. s9 I0 f& N% |' O7 j7 ~( w5 I
The way it works is very simple:2 |" ~' B6 y( W0 t
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for# i9 z( F/ `: U! d1 {: b2 s
WinNT) with the CreateFileA API.
) g, d" X" Z; d1 T( w1 ~" ^. u
* ~# y1 V& o9 _; M7 P0 P9 Y/ T9 G( iHere is a sample (checking for 'SICE'):
3 n- V7 X3 O" t' ~. Z
0 _2 N' m1 M- w% [8 P8 T! V- IBOOL IsSoftIce95Loaded()8 W& h+ J0 i* Y; d7 `4 _( k
{' J: F. ?* w9 g+ s* B/ F! N# F: ?) r9 P
   HANDLE hFile;  
* K5 W$ O9 ?; x- {# u   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
, w! a: M) q+ E2 U$ O% j                      FILE_SHARE_READ | FILE_SHARE_WRITE,  F: t/ z" {% l* s: m) G3 x" I4 m
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
4 I+ P# p' A/ W- l# W" j   if( hFile != INVALID_HANDLE_VALUE )) N7 Z4 B: p% Y& X* [! ?
   {2 w- P9 y( C) M
      CloseHandle(hFile);2 x/ j, a" k/ H" y1 e  P4 o
      return TRUE;
1 c; l6 Y  l! i( t: D$ F   }, T3 @0 P7 ?" J) }& G0 R# V; ]
   return FALSE;" N* L6 b) o4 n  I% I
}
/ s* U" F8 {4 e! a( H
/ S& H% v1 q: ?6 V- GAlthough this trick calls the CreateFileA function, don't even expect to be. S" J0 q8 l; Q- h# E7 u% X
able to intercept it by installing a IFS hook: it will not work, no way!3 R$ g( q8 @1 ]6 a- ^- [
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
6 R6 b0 e  b% M* Sservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)& p. ^9 t% k1 Y6 W
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
4 X2 A+ o- H9 ?field.. q9 l  |, T$ e* Y  @& y5 T/ \
In fact, its purpose is not to load/unload VxDs but only to send a
+ t1 \0 r: X! k; y2 qW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
3 E0 w" U- [! w7 i% E$ q" {to the VxD Control_Dispatch proc (how the hell a shareware soft could try
7 c) \2 L# A2 w& ?, Gto load/unload a non-dynamically loadable driver such as SoftICE ;-).! V5 F; T6 P' t6 |0 ^# O+ T
If the VxD is loaded, it will always clear eax and the Carry flag to allow
- `# p* q0 C! P/ P6 S/ c% Qits handle to be opened and then, will be detected.
2 n* k6 |+ w# R5 ^You can check that simply by hooking Winice.exe control proc entry point
1 \6 j" f: \- p* ^1 z9 e6 _while running MeltICE.9 A* D  S2 c! W8 P( O
; |. Y- ?1 _/ O( Y: r. q
2 J% w& Q6 n: P7 _
  00401067:  push      00402025    ; \\.\SICE
# Q5 j' {* K2 Y  0040106C:  call      CreateFileA8 a3 s/ l: M" {& ~6 H
  00401071:  cmp       eax,-001
  B9 ~4 P8 L8 x  00401074:  je        00401091: f! p7 @0 Y  [' b2 D

- H6 O, G1 T4 F* `; h# o! ]: I) b2 {# k
There could be hundreds of BPX you could use to detect this trick.
3 r4 `/ O2 P$ z* ^-The most classical one is:( `* c' d/ P2 P% ]* X- R
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||8 d) ~1 U  {+ {& C- w
    *(esp-&gt;4+4)=='NTIC'
1 O; K6 R+ r# y
9 w' L* v' ?1 [* `-The most exotic ones (could be very slooooow :-(
7 \0 {% z( k. i6 i7 o5 D   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
) z: a* I# D; H2 e) A     ;will break 3 times :-(! M' c& d+ v5 T" \. |' z

" w5 R, g: f4 U5 M-or (a bit) faster: . p' }, Y- S) L: q
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
) t" a5 ]2 ~) ]5 `3 V$ a+ ^, x. |
$ @" `9 F0 i& R4 y. r   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  7 Z# ]1 G/ h0 _9 @! Z
     ;will break 3 times :-(& o6 Y- B1 [7 b7 W# V- Z

/ v5 s5 G+ |$ V& L) |1 Z( ?/ F1 L-Much faster:4 Q1 J8 x" w# B0 L: h8 t
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
4 q) ~, o1 ~* S) M! d5 j' P
$ g2 t0 b% j+ J; `7 ^Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
2 @; e$ J& s  }7 zfunction to do the same job:
* c  w! J( a2 q, R, R" A6 r/ f
8 a  H0 j6 N' _$ y* C' g5 R   push    00                        ; OF_READ4 u) e4 |" _# G" ]
   mov     eax,[00656634]            ; '\\.\SICE',0
4 b% R3 S+ X0 Q7 P   push    eax
- L! L: K3 e3 Q6 j   call    KERNEL32!_lopen+ x& I; ]) }6 P0 V
   inc     eax
( X7 [- p+ A$ Y5 n2 @   jnz     00650589                  ; detected- k* Q, z( S6 d; z- ?2 U9 o
   push    00                        ; OF_READ
6 ?) J; V( ~& \% S. i   mov     eax,[00656638]            ; '\\.\SICE'9 U6 x1 T0 @2 g& n# D/ N4 z
   push    eax* ?; y0 n  r; O& v& D
   call    KERNEL32!_lopen0 m' R8 e6 y" e" j1 t0 x4 f/ b4 M/ K
   inc     eax
0 P7 T/ A1 k9 F) Z9 G  \& P1 I   jz      006505ae                  ; not detected" y$ r' M* ^/ J* o! Y

. J+ r5 n- x( @& i
9 r7 S* L0 s1 g7 F4 D) K, i__________________________________________________________________________. }+ F1 z4 I/ F& q

* U1 ~! |1 Y. U% ^4 r) v9 eMethod 12% h+ o. W7 m" ~: K0 h) E$ d+ y
=========
! N9 S4 w  B2 D7 ?; h1 `7 q2 Q0 j) d, q7 K2 M; g5 J9 S" T; ?
This trick is similar to int41h/4fh Debugger installation check (code 05) A6 s" i# k: u; k
&amp; 06) but very limited because it's only available for Win95/98 (not NT)
4 B' f7 {! C; n: K9 R) _) p3 was it uses the VxDCall backdoor. This detection was found in Bleem Demo.
6 a  R& L% P( K1 J. }9 q8 n/ m9 j: A7 U0 G# \
   push  0000004fh         ; function 4fh/ n) j0 z1 Z- H
   push  002a002ah         ; high word specifies which VxD (VWIN32)! f2 A4 A+ z! h, f
                           ; low word specifies which service7 ^5 U5 i7 j" E2 m
                             (VWIN32_Int41Dispatch)
: A( N5 n8 h& M5 v" T$ b3 M0 m   call  Kernel32!ORD_001  ; VxdCall
' C4 m/ A# ~- t$ h   cmp   ax, 0f386h        ; magic number returned by system debuggers
! b) H+ Y# M' m2 U4 M   jz    SoftICE_detected$ H) E# w# p. ]9 P' d$ j  X9 k+ ]0 t

7 u, C# Q; W  q: Z5 c& UHere again, several ways to detect it:
# B* E, E/ B2 X$ p) O* D0 N2 d
8 K' l# ^  x7 ~. }9 b; Q9 o    BPINT 41 if ax==4f
( p& J3 s5 T" W8 i2 b& A4 r; J
$ {0 \# F& p8 A" U# q" d    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one! D' }4 I7 `! C8 d' K

7 e  b2 w* @( r# {    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A; ]1 l3 @3 ~+ N" ?' s

. [: R# d: F+ T2 O% x) q4 K) d    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!6 @! L9 k! P9 }" A4 _  f

4 v2 n5 r/ O6 g4 {' S__________________________________________________________________________4 ]  p6 F7 y0 |, I
0 C1 ]' I1 b: _6 B4 Q- y
Method 13
9 y" |2 p8 A+ r=========
2 A, v, e% _9 ?) f8 ~9 C. F2 S
. t! E0 R9 z* b; e7 R' I# SNot a real method of detection, but a good way to know if SoftICE is* i4 K- W$ l3 V+ v9 ^" q+ C! x9 J& f# [
installed on a computer and to locate its installation directory.4 |5 l  Q! P# r7 q$ A; R& h; O
It is used by few softs which access the following registry keys (usually #2) :% f# k, f) q! F: B
' i$ r" ]% L6 Q% D2 o' \
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion; p4 w; ~- H+ z# w' M
\Uninstall\SoftICE2 m  l& D7 u  [: Z
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
- a" L( S$ ^1 @0 w9 P( M- R-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
1 _: q, u7 i& G2 v; E  V\App Paths\Loader32.Exe
& a& Q! w. g; j- e
8 B0 n8 Z! o; P$ i: ?! g  s7 P$ O$ T# j
Note that some nasty apps could then erase all files from SoftICE directory6 D- U: i5 y/ U4 S* M. @! j8 U0 s3 o
(I faced that once :-(+ R  G+ u% [0 ?: X
0 B3 V2 a2 g2 q
Useful breakpoint to detect it:
9 s! d! i$ U; i( `8 Q
( U5 N$ J/ Y/ L) M. ^     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
4 x! l/ v6 A3 e, F! M9 J
  e- }/ u6 x$ O. n__________________________________________________________________________4 x8 J9 h: S4 }! L
! H6 M: n# i8 X) ?; t# G' |+ Z9 j

+ T7 Z2 I1 L# R/ `5 t; ~Method 14
9 @$ g2 P3 O4 e* `3 H=========
, c1 I7 h" }: C  r! r9 F8 x7 }5 w. x) M' [9 m
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose! e* i9 W" i7 K# w+ t; w. B
is to determines whether a debugger is running on your system (ring0 only).
* K# l7 _! m0 j# a& `9 {7 G- X5 K. k: O- t5 x
   VMMCall Test_Debug_Installed
9 y4 {* L1 A0 A' I3 \- C   je      not_installed
: ^9 X# s  d0 ?% Q% `8 {& l3 O" q. q5 @0 [; L& w
This service just checks a flag.! N/ J3 L3 Y1 C* g2 i
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部