About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>; w$ ^  g( [# ?& h
<TBODY>
( I: Q& w9 o8 q# _* h1 h<TR>" \8 Q5 D  L, N" i
<TD><PRE>Method 01
2 e5 C. V0 {6 ?, t! S: u=========$ r: V, s9 d9 H0 o8 J7 Y, F
8 s+ j  {5 f5 N7 w
This method of detection of SoftICE (as well as the following one) is' L  b: Z" ]4 g
used by the majority of packers/encryptors found on Internet.
7 @6 d2 U7 D: z, R: F) R+ ?* }7 XIt seeks the signature of BoundsChecker in SoftICE3 H; p5 w! h; M  R4 L
! l+ s/ _; b4 N* @- N& L
    mov     ebp, 04243484Bh        ; 'BCHK'! i7 R+ [; i0 h& P  b6 C
    mov     ax, 04h
, p- E6 c; ^7 l" t4 a3 ~" W) u    int     3      
7 a' o5 D! }) L8 v& i- q    cmp     al,4# {! j  k/ X1 x/ D( h( w
    jnz     SoftICE_Detected
" _  _8 k/ h6 N) Z+ z3 `
# ~  h3 S- g0 ]) j" N6 c___________________________________________________________________________
' H$ Q1 M- ^) [! |$ P4 e/ X7 G; x$ ~$ V6 j
Method 02
& X, |# ?% y- u=========
; Q& H, S5 K+ ]6 o1 o2 k5 w
) \! l+ U. r) wStill a method very much used (perhaps the most frequent one).  It is used
1 a. h- A8 Z$ r1 E. W6 r+ i$ p! Oto get SoftICE 'Back Door commands' which gives infos on Breakpoints,- F' M0 @- K4 \4 z
or execute SoftICE commands.../ Y4 u$ v4 y2 v/ U, y; ^; U, b& @
It is also used to crash SoftICE and to force it to execute any commands
# A2 J! g) i1 i0 T5 b8 [(HBOOT...) :-((  
  F. F/ t& P* b
4 x8 |/ l  {% j7 x7 R$ v1 FHere is a quick description:5 B, m0 y# J; z! M) v* P
-AX = 0910h   (Display string in SIce windows)
- H  L7 ~/ E6 l) x/ v) M% p4 b-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)* g. t* m8 l& r" N3 a9 G
-AX = 0912h   (Get breakpoint infos)# K2 ]1 y+ }, z0 N, L- [8 `
-AX = 0913h   (Set Sice breakpoints). f5 Q0 K6 C0 |8 |
-AX = 0914h   (Remove SIce breakoints)
$ ^9 E) L/ v1 k) w0 H
4 m7 B- g2 c+ e% yEach time you'll meet this trick, you'll see:1 @- |5 k# U. w( R/ r; r
-SI = 4647h9 U6 }" l4 Z( f8 ]4 G1 \. `
-DI = 4A4Dh% a; E; c" W/ p! }8 c5 V- o5 ?
Which are the 'magic values' used by SoftIce.; i) S" U# K' Q( u3 S* `' n
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
* |% v, Q( Y/ j# g
% G4 [2 k2 Y7 UHere is one example from the file "Haspinst.exe" which is the dongle HASP
9 K4 Y% a. j& d; q4 ?Envelope utility use to protect DOS applications:
3 O1 q3 H; @0 O8 R5 A& u+ l4 B  G7 {  s3 b5 o" O3 x$ D
; m( u8 M: ?" ?8 l9 Y
4C19:0095   MOV    AX,0911  ; execute command.
% ~. |( X- F% u' X# a# e1 D5 x4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
) r9 z; b) q; w; z3 {/ u. n# L4C19:009A   MOV    SI,4647  ; 1st magic value.
8 R5 X% J, S' R" O( S4C19:009D   MOV    DI,4A4D  ; 2nd magic value.$ |9 t; u! n, I( n' x& u& j! g
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)9 t$ A* g! Z2 U( A6 e) t
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute( x( ?+ B( V! m- M6 E% f0 A
4C19:00A4   INC    CX( X" Z# t' b9 b3 r7 v: a
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute8 ~: A; I- a. [: C' I
4C19:00A8   JB     0095     ; 6 different commands.
! S; t9 P5 ?) ~4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
) Q; i8 N  P3 L9 v8 H4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
0 ?. |2 Y! @& V4 W. k
' K# o& @+ G0 E$ k" ^The program will execute 6 different SIce commands located at ds:dx, which
/ g. Y! C% Q5 r* V9 mare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
4 U+ ?4 f) E5 c0 \9 g
6 N. r5 l2 |. R* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
& w6 N0 \! U. J" }7 _; p% }  @___________________________________________________________________________
, r" L' b7 q: K* H
3 w2 k- U) r: k( a  H
  G" D; ?4 t" {" g6 z( [& t6 _Method 032 |( h) \4 Y6 z( I$ i
=========& C$ j+ [1 G  h$ \3 U; ^, @
5 a/ Z& S1 b5 }) P2 i; P
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h3 E/ b) c/ U% Z
(API Get entry point)
$ S. B! p4 Q6 |, y' e! A! {1 y# p+ H        
& I: @1 y! `) o! I. z, X6 D! E! W5 k- ]! B) W1 t  _
    xor     di,di1 X4 s" P6 e8 x1 v) w/ y& A
    mov     es,di
2 Z3 v  }# `( j5 Q7 D& d    mov     ax, 1684h       ; S1 b4 l3 o$ C! V/ t8 Y/ x
    mov     bx, 0202h       ; VxD ID of winice2 ~, i; x7 E- \6 E; Z6 g$ P- Y- }3 B
    int     2Fh- L, Q, A; B* y* U( D, k5 @7 h
    mov     ax, es          ; ES:DI -&gt; VxD API entry point0 c" I7 H6 F4 |% Q' p+ D: r
    add     ax, di
0 Z9 r0 o$ T* G4 t    test    ax,ax' }. w- d, I7 k- X$ O7 B' e* R
    jnz     SoftICE_Detected& ~7 d& K0 N5 {4 V9 c* B3 u

2 m" G- R1 n; a6 [___________________________________________________________________________8 W* r# a( ~; f
: {: B! u9 n& D4 U
Method 04+ b- Q7 x% c- w+ W2 W0 j& ^
=========
+ ~" ~4 U2 C" E% n0 R  H9 O6 c& D- q: K' n& G' ~: u2 }! {& F
Method identical to the preceding one except that it seeks the ID of SoftICE
& D4 O# J5 }  f. Z# HGFX VxD.' r1 E, ]- n; z# g( O
$ |' w+ Z; a4 y/ R% W( n
    xor     di,di- L6 K& U6 x& p+ D& Z
    mov     es,di8 m2 ^- V( D% H% T% R! }: M8 E
    mov     ax, 1684h      
" Z& K/ v; p6 \1 c% K6 ]    mov     bx, 7a5Fh       ; VxD ID of SIWVID
; K! @8 r* B) Z6 S) C    int     2fh3 l- k9 L( H5 K5 ]4 K  S) U
    mov     ax, es          ; ES:DI -&gt; VxD API entry point8 b, @2 A$ `- V6 q
    add     ax, di: [+ E+ _  R* @
    test    ax,ax& {0 q5 D$ ?& T1 J8 M
    jnz     SoftICE_Detected
7 m' S8 K; T4 ~2 L: |: G" E, q* u
__________________________________________________________________________
/ H# o7 |( u# x7 S& R
/ r3 H( Y7 f5 \) H, n* y7 `+ o6 s# _# `2 m2 U) H- J6 \0 e4 h9 s& V
Method 05* |: ?7 C, {1 g
=========
' ?0 K/ ]1 u* W9 e- X
$ O. }8 y! w- J0 r5 |Method seeking the 'magic number' 0F386h returned (in ax) by all system
* E. ], c* l3 P6 Y( q5 D1 pdebugger. It calls the int 41h, function 4Fh.
1 K; i2 s6 c  b3 D$ c" U  x& ]There are several alternatives.  
2 p. R3 z' P& e' X) z
$ J6 ]9 X" G0 f) S! IThe following one is the simplest:
' ?; L2 \- \0 z2 U8 R- F( |% O2 N. W* x
    mov     ax,4fh
) J  c3 w, x8 F( O& ~# Z0 I/ ]1 R    int     41h: {' r( j+ p, ~' _8 U
    cmp     ax, 0F386: \3 v/ z% U/ M
    jz      SoftICE_detected
9 S3 V; d; l& w  r* u" w2 [
/ a6 L# n: ~) T' m( {/ S9 R
2 X2 _1 _3 O' ?/ G, d* `  UNext method as well as the following one are 2 examples from Stone's ' y+ s3 m% U- p7 D9 g: w
"stn-wid.zip" (www.cracking.net):
2 g3 f6 t0 }" r3 Q$ o% i5 B& t1 }& @. M7 }' |
    mov     bx, cs! X3 O' E* O( W5 F0 k
    lea     dx, int41handler20 a2 C  q1 _. }3 N
    xchg    dx, es:[41h*4]
: p: V# r+ M& [    xchg    bx, es:[41h*4+2]. V7 u/ }3 r3 Y9 s' |
    mov     ax,4fh
3 [2 D/ e, z3 t/ l5 l' S    int     41h/ ]) D) N! [: X5 a0 ~
    xchg    dx, es:[41h*4]4 u% I1 ]# J% g* {' X
    xchg    bx, es:[41h*4+2]
% V- ]4 x$ d; p7 C$ ?9 s    cmp     ax, 0f386h8 v& p- s( l6 b7 k; E+ \% X
    jz      SoftICE_detected/ x7 [/ z+ u% M/ r! X

$ @" j( G  P; \; \2 Nint41handler2 PROC  F- B4 ~+ y/ n* s/ k- ?* ?
    iret* j) u3 @9 \7 }/ l6 Y* o2 Y6 \2 i7 V
int41handler2 ENDP
( g2 l/ a% u7 o- L5 G. U; d1 P1 x
& j, P# a% O6 w  X) S9 b! A- R' Y6 o1 Y& X& ]5 a4 t% V
_________________________________________________________________________6 g) B- r* ?$ ^" b$ d
; @( L* z( K+ Y, g

/ P- P+ E, F. {% {Method 06
4 O" A* F& Z2 M' A; Y=========8 l9 R0 V7 C( w  ?

/ d- s3 E/ Y5 c. O5 {. k
5 |+ ~  c" u! T  G* L, g0 N8 O2nd method similar to the preceding one but more difficult to detect:( Y7 t, `, S4 `5 N+ A# @6 {8 ^

* p3 F$ G2 o  u; C, o5 M* B; F; M) N( H/ T
int41handler PROC9 s6 d: |' w, A% k  i6 i
    mov     cl,al
( y' v( w5 a+ F  ?- o    iret
! v; E) U! O$ E# u. cint41handler ENDP
. N/ Z, l1 c* P
$ X% c/ D$ w7 y8 g1 X  @( [) d* w% H' q- r* ]1 U
    xor     ax,ax4 E% v! _0 n7 v4 \+ v( M2 _
    mov     es,ax
, P% D4 p5 H* L% k% r% E. g    mov     bx, cs. J, ^8 p- _% W2 ?7 q& B. @- z) f$ a. e
    lea     dx, int41handler0 L- f/ k& u" y- z$ [. t3 I* y' A. U
    xchg    dx, es:[41h*4]
" f$ {$ i( E$ M0 c. O6 l) I    xchg    bx, es:[41h*4+2]
* O, [  K/ u0 T3 S# s9 ]    in      al, 40h
+ ]% H6 `: G" h! a    xor     cx,cx
) Y; b0 U9 O  C, K2 M    int     41h6 Q- B4 m, r( d, @
    xchg    dx, es:[41h*4]0 K5 o1 D+ @! M$ {
    xchg    bx, es:[41h*4+2]
" A- b$ G! S( {7 t    cmp     cl,al4 y9 V6 q: k2 _/ r
    jnz     SoftICE_detected  s9 t6 u1 k, V- ^! @
4 y- X. `- m& ^: F9 F' i
_________________________________________________________________________- q4 ]; I( i; h* s2 f

5 v, n8 }4 r: _# E" h8 M9 hMethod 07/ o3 K; O1 c5 j/ M9 D7 z% m8 @' v1 H" ~
=========0 C+ ]0 @% w2 }) B; J

8 ~0 N& [6 J% O6 O" _Method of detection of the WinICE handler in the int68h (V86). A1 s. u: e& m, Q: A
1 ?' R9 @2 y# e7 G; m7 ~) \! v
    mov     ah,43h* p! o/ h( F" j" N/ O$ g7 @+ P. }
    int     68h
7 D, E8 ]" y7 |, r7 m    cmp     ax,0F386h2 {4 N5 u7 e1 W0 s1 l$ }
    jz      SoftICE_Detected+ i" \& m% s; h1 U$ n
6 t- i) Z& I' R  f- d( O6 r
( d: O- S) Y* o2 z  H
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit/ z, U' G* D' P) Y5 h
   app like this:
3 f  W% v: q% ^! P9 a0 ?1 C3 [* F6 ?" E& m1 M/ V: h
   BPX exec_int if ax==68
# k# l- u1 s* [, G" ]   (function called is located at byte ptr [ebp+1Dh] and client eip is
; V, [% D5 k% s# @7 X. e3 o   located at [ebp+48h] for 32Bit apps)$ W7 v$ ]3 F, {7 i3 }
__________________________________________________________________________9 l8 h- u) i7 l: U% a
9 r+ o5 L) R* P

; ]7 p8 {, T. H7 d  E9 b- WMethod 08+ q* D7 \: h% H% b) p
=========2 ^" a( W4 {8 U7 f6 p8 P5 j
/ }4 k( x7 d/ b' S( `: A/ v
It is not a method of detection of SoftICE but a possibility to crash the
2 {1 J& l- k/ }, }# t! `( asystem by intercepting int 01h and int 03h and redirecting them to another/ `: E& X2 \0 \0 g& V
routine.
1 A* ?6 b( U/ b1 p. Y3 q. YIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
9 E* T( r- E1 F0 `% f7 k1 C3 l; mto the new routine to execute (hangs computer...)
$ \1 ^! X2 _" X9 z. O4 k  Q% I5 o+ }) I( y- @  P2 P
    mov     ah, 25h( J" m* s! v4 H- g" `  O: J
    mov     al, Int_Number (01h or 03h); T7 d7 {* s  c0 G3 G. A, v4 T( w
    mov     dx, offset New_Int_Routine7 H% |  Q; q5 e* U* X, S. \9 i
    int     21h( G! z1 r3 L$ N, R" p* j

0 `; x( _7 D/ p2 M( {__________________________________________________________________________
: ?8 e) x/ B& `  v
; M+ e& J2 O$ {0 @/ t0 ?( f% JMethod 09' D! e6 d) x: p/ }. S
=========
0 s+ e, h9 f- H  a0 e& K. C( b- w" b6 H- L3 O  h
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
" E- |' [* J7 vperformed in ring0 (VxD or a ring3 app using the VxdCall).
5 }4 u- P) ~; c+ s- c4 nThe Get_DDB service is used to determine whether or not a VxD is installed% M6 g' n- |' D; f' ?
for the specified device and returns a Device Description Block (in ecx) for
: `* C+ J0 F2 T8 f/ Uthat device if it is installed.2 N* L. `7 q9 J  Q' M8 Q; e
+ a. P% l& N! {7 `9 _+ Z
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID# r5 N8 _' ]4 f! u4 H7 B
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
1 x( h+ J% N2 X3 r1 i' `# w2 L  G/ z   VMMCall Get_DDB
+ G2 M: R. u1 o+ r   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed( Z" f1 \, \* R% W' F. a0 l0 P# F

4 B. P; M# [+ n! eNote as well that you can easily detect this method with SoftICE:- u$ B" D7 k5 ~* s7 a
   bpx Get_DDB if ax==0202 || ax==7a5fh* i0 y6 J2 G8 |* d5 r$ D2 S

5 l: Y: M7 G. B9 ^( k$ \( v__________________________________________________________________________) G5 [/ T6 J" A1 U
/ D+ V3 \: V1 x  \& ^
Method 10
+ }$ f+ h, v$ \; G2 o$ n2 V=========
9 Z. S4 s2 c( L) [1 A2 e5 ~. S& K( [4 l  o; @" v
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with; B9 F1 L3 p: W
  SoftICE while the option is enable!!
  z$ ~& W  O7 C% @  l3 K$ ?3 U8 F1 f, w, h3 V! l
This trick is very efficient:
  b9 `5 F( S, |7 Mby checking the Debug Registers, you can detect if SoftICE is loaded
2 Y! x: R+ ?! z# l1 V1 I& ^1 k0 f(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
2 `2 S+ {! ^) gthere are some memory breakpoints set (dr0 to dr3) simply by reading their( F) \! c9 j& n6 k" C2 A
value (in ring0 only). Values can be manipulated and or changed as well
# e: D. e6 K# O# t3 ~+ I7 q(clearing BPMs for instance)
, D  r0 a6 q' S( q9 P) N% Y+ P7 r4 c9 B7 p
__________________________________________________________________________9 A% t$ X' b& }, Z- W7 P
. G! _  E$ Q, i
Method 11
" ^% {) ]  r& B& J" \; H=========
" F/ I+ X. G/ j# M* e" j' K, l$ g2 @& B; U- P1 G
This method is most known as 'MeltICE' because it has been freely distributed
+ p  d$ n% u" x3 G" D" q/ rvia www.winfiles.com. However it was first used by NuMega people to allow
5 p0 u  f: p6 T1 N+ [. b3 _9 f$ k' eSymbol Loader to check if SoftICE was active or not (the code is located' ]" I! y/ C# k" r: p# [) Y) g
inside nmtrans.dll).. X, y- E3 @' B2 X
' X% h  |- m' X4 `# [
The way it works is very simple:
) B0 x, I( K7 g" c2 g0 zIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
4 y0 L7 w# q5 C% o  IWinNT) with the CreateFileA API.
. z/ w" b0 O! y; O* k, _! D1 ]$ e0 l
& l) c2 W! n' _7 s% q4 O* p6 K, @2 lHere is a sample (checking for 'SICE'):
& r" I8 c5 I8 ?" h* x
6 M" S: z% i) Z$ H0 @BOOL IsSoftIce95Loaded()& @4 o2 g. k( _. M
{
" V. u1 F. C6 K" z   HANDLE hFile;  
* \* h+ p( X) o" o5 \   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
2 u7 H: s6 A- U1 d                      FILE_SHARE_READ | FILE_SHARE_WRITE,) g5 S& L* g; e
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);6 a# y, S  H4 D) o; T. S9 A
   if( hFile != INVALID_HANDLE_VALUE ). T5 O+ q1 Y; B. w& [5 o; P
   {8 J1 z  s) Z: \1 ]
      CloseHandle(hFile);- g) M2 h# p0 j$ ]' v, ~& ~3 O+ i
      return TRUE;
2 ?/ C& d) k# D4 d1 E9 H   }) W: T2 I# p1 V! V/ G& A# U$ q
   return FALSE;* x' ^) ~( \6 V& b" I6 w4 D
}
7 ~  m, f+ G# p) Z4 h5 E" E, c7 R7 B, K7 a- y6 _
Although this trick calls the CreateFileA function, don't even expect to be. I- Q- Z1 h# ^  h% V9 d* W
able to intercept it by installing a IFS hook: it will not work, no way!
( b0 a! Y8 E; x, ?3 F4 EIn fact, after the call to CreateFileA it will get through VWIN32 0x001F0 l6 s6 Y; s# L& p  N
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)3 j- S6 O" R1 h( K1 L' x/ U& L
and then browse the DDB list until it find the VxD and its DDB_Control_Proc* C+ G4 X# Y( G
field., h) ?' {" {9 Z( e
In fact, its purpose is not to load/unload VxDs but only to send a + S& _8 H0 p, V
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)4 b, r/ q  E; J# i' E4 A
to the VxD Control_Dispatch proc (how the hell a shareware soft could try5 |0 z  K' k# k2 D
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
3 X! A3 s+ t2 b7 s# a0 l( gIf the VxD is loaded, it will always clear eax and the Carry flag to allow
  a" T7 Y+ d% q& g9 L6 n, I4 E$ Qits handle to be opened and then, will be detected.3 g) L* p3 ^) {0 Q5 M. T" \
You can check that simply by hooking Winice.exe control proc entry point
. `2 x4 p# U# \7 zwhile running MeltICE.9 B0 h: w: Z" h

! z1 ?6 p4 R5 d' s/ \" b8 {( b
) b0 E! S$ Y) r* s. I+ M5 u  00401067:  push      00402025    ; \\.\SICE
/ C0 V" K4 X) D! @. U  0040106C:  call      CreateFileA* |& u3 Z# o+ C9 Q
  00401071:  cmp       eax,-001
: }( @; y: P  G& P0 [  00401074:  je        00401091+ K6 |1 W5 e. ~- N4 P$ V7 a
2 I2 h. ^  }  i

7 I8 T, b7 C5 q; h% z* TThere could be hundreds of BPX you could use to detect this trick.
4 l) D5 T$ G5 Q-The most classical one is:" q/ w% q: L9 R8 q1 N8 i, K
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
  C" B4 ]% p/ Q5 m/ J    *(esp-&gt;4+4)=='NTIC'9 y; @+ X* R! Q8 n7 c( J8 c9 g

: ?' ]! ^) E" u+ d) T5 E-The most exotic ones (could be very slooooow :-(
8 V+ V( Z/ ~% X% T- U   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  1 C5 e) D: K# f, J
     ;will break 3 times :-(
9 a" c: F- t" J' R9 Z8 R* ~( _9 `% C1 {: @7 v3 w6 s- K
-or (a bit) faster:
% z, E8 A' C: r& }3 h   BPINT 30 if (*edi=='SICE' || *edi=='SIWV'), u& U2 b' B" q' [9 q6 M4 G1 E+ Q

, Y! f3 M) @6 A  q2 n0 G  U6 B* R   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  - z& e1 u  u8 o
     ;will break 3 times :-(
. z7 ]2 ~' k3 N4 Q7 Q  A2 q0 D' L2 b, Z5 j: J3 m0 h; l
-Much faster:
# I" G" T: f: Q+ U6 V* L1 f   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
1 [# m4 _% q% A% `
2 e1 V) ~* V: [5 p" C! s& V* E1 c9 kNote also that some programs (like AZPR3.00) use de old 16-bit _lopen
5 r. s; a0 z/ @- P, [! C* pfunction to do the same job:
, T: R& e# i* [6 S- ]9 O: f' m0 d" F( ]' z/ S. [
   push    00                        ; OF_READ
# x  D4 N# }$ E! V; R  m   mov     eax,[00656634]            ; '\\.\SICE',0
9 I% b% F% F, t* T8 k- f% Y   push    eax* k% T8 b* W; m5 }* s& k% m4 l8 _
   call    KERNEL32!_lopen
& I5 u2 K: A5 C* N! K% h   inc     eax" m% P. X; S& U6 [
   jnz     00650589                  ; detected
' T: ^/ M7 k! a( T) M' r8 M% o   push    00                        ; OF_READ* _* {* q* h1 }# \
   mov     eax,[00656638]            ; '\\.\SICE'
- m+ l. V0 o0 ]3 _: N   push    eax
( L8 L" ^  d3 e* _   call    KERNEL32!_lopen
8 ?! p3 g8 f' U2 q8 \( _   inc     eax
0 M, ~5 q9 s  G) a7 G# V7 v' d   jz      006505ae                  ; not detected. W) {2 `1 h0 w0 }0 \

  r. h/ f! ?" j. B  b: c0 J2 P  r6 B. ^& E( W
__________________________________________________________________________
0 b) J  B0 k( V1 C0 c
+ m" f3 T& Y, V/ eMethod 127 f' F7 y1 H+ d+ ?6 U2 e9 b5 x3 F
=========" m( P, ^, f# r

9 W6 R# D* u. n* Z; q( MThis trick is similar to int41h/4fh Debugger installation check (code 05# s/ `2 ^8 `) u: B% l7 b
&amp; 06) but very limited because it's only available for Win95/98 (not NT)
) ], d, O: G$ l/ D0 {" X- H, |as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
) n9 V( [$ I- |- J7 a( \* k0 ^. g) u0 o& ~* W' Q4 Z% n; `* x
   push  0000004fh         ; function 4fh7 e: n# F2 g0 l- i! P; y. O' T4 Q
   push  002a002ah         ; high word specifies which VxD (VWIN32)0 A2 N. M8 X7 U7 R
                           ; low word specifies which service
( Q, U' M2 _+ e6 c5 l                             (VWIN32_Int41Dispatch)9 A0 C% P' Q9 g7 T5 c7 n3 U
   call  Kernel32!ORD_001  ; VxdCall$ f* X2 W; d* P: |% n6 l; i. q
   cmp   ax, 0f386h        ; magic number returned by system debuggers
/ r& f2 q, U6 b; @* N) Z   jz    SoftICE_detected
3 i/ {0 n# A' z" v2 @0 ]; g- @1 B% t6 \1 |/ V+ Y) l
Here again, several ways to detect it:( g( {7 W. v4 g5 E. @8 h
; j, B+ R! O9 x9 L. h) K6 d
    BPINT 41 if ax==4f4 z1 C  U$ Q; D5 p: b

) i$ d+ \  v$ ]: x4 _" ^    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one: W- i8 T6 u7 q6 H2 \2 \9 w
! o) W8 t; G. _) S5 _$ }- \  x: I# V. i
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
) ?2 _! e4 @8 K5 ]/ B5 v! w0 o8 P, q) |: ]; f( F- Q- N, l) t, Y
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!) j% R: R$ ?0 ~% H

# ?9 y( S7 c7 I6 K1 F. T( W& @__________________________________________________________________________; @5 s# m3 X: d+ p8 ?5 j0 I$ F" x) |" l
! }& a" L$ f- c/ M$ J
Method 132 I" d, I* @7 {  d* j7 ^
=========
9 ]) v, T+ d0 m6 ]4 R, r
5 |9 |: A9 F" ?0 M) A8 B6 m4 ]5 bNot a real method of detection, but a good way to know if SoftICE is
8 |2 t: N9 U1 P- g2 Z5 cinstalled on a computer and to locate its installation directory.
4 x. p' g! E' \6 X( I) U7 n! gIt is used by few softs which access the following registry keys (usually #2) :
) L3 n  {0 E' C2 `; e6 [
' h) P" s& U/ @-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
: A  \+ b# r6 H# ]" `0 j& L: g\Uninstall\SoftICE' ?$ `* ?. V: ~4 m4 v
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
- E2 R% S% ~* d-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
, n3 c5 @/ e8 }! T\App Paths\Loader32.Exe  ?. C/ d( ]& G8 `" H. z

% o7 g$ N6 ?8 k( F6 k8 X1 e% s2 O+ G0 c  s& T8 @9 f
Note that some nasty apps could then erase all files from SoftICE directory' I6 D, @5 t: b9 O* S- E3 p' G
(I faced that once :-(5 ]. l! b( c: C* j1 p, `! \

  P3 |* V  R6 _' V# x2 lUseful breakpoint to detect it:
1 R4 r9 z$ i# _- F, T: ~
' q! p. }# e! g; m     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'% X- p' D5 Q+ L0 H% P

; }- V7 C" ^4 f7 c3 d! W) R8 [( z__________________________________________________________________________8 Z0 h; b# e8 ^# m' P

5 F# q+ X- z# Z  o
! j. ~" S9 ^* b3 u) c% B% _& T8 ~Method 14 5 n5 e7 f) z7 K/ C/ R
=========
! y: ?" P/ N& @: d4 }! o2 k+ ~6 _9 \* _- h6 m" x5 f
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
9 N) i$ [: T1 i( _* ]7 }is to determines whether a debugger is running on your system (ring0 only).
% |! l3 Q6 i# Y* }9 p$ b1 i8 o, t0 d& s0 m( I0 v" b
   VMMCall Test_Debug_Installed7 h' M1 U: {0 _7 ~- ]/ S- N3 U0 K
   je      not_installed
5 @" W' n' r: w1 n# q/ q4 a: u! N
This service just checks a flag.; t8 g2 {2 V9 P$ d/ T
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部