About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
/ j4 N3 r6 \& n, Z6 M<TBODY>
8 Q' Y2 [9 q2 e# [6 H<TR>3 L+ {8 j# S+ d$ D. N0 G
<TD><PRE>Method 01 1 {% j* I. L: m0 S
=========
9 ]! `+ E! F# n! v, q& D2 k* A% ~3 T/ f
This method of detection of SoftICE (as well as the following one) is
8 k: ]; ^' }, C* H/ p' Vused by the majority of packers/encryptors found on Internet.
+ b8 Q5 y6 Q* p( HIt seeks the signature of BoundsChecker in SoftICE  A) A6 v! M* \6 v/ j/ }

6 p" P! g: b' _6 ]    mov     ebp, 04243484Bh        ; 'BCHK'" `9 I/ h2 g3 F; ?. h8 ]- o
    mov     ax, 04h* k0 |+ o& w# [5 B& G3 n
    int     3       4 c4 Z( j* O3 F
    cmp     al,4
5 m. ~2 F5 _* g- [    jnz     SoftICE_Detected
5 w5 y( ]: n8 y, d9 Q! G, ~$ r7 @
7 X3 ]( J* h& n/ n% q___________________________________________________________________________
: i$ o8 ?; c( [" p% p8 v& ~
& N! B+ r% |* U: F1 L0 d/ K1 Y* WMethod 02
+ J' c" |+ P- T9 v=========" f# a4 P9 H& b. G% c

" W+ a: d8 I0 q5 VStill a method very much used (perhaps the most frequent one).  It is used
9 j  A$ _4 M. `. w1 z" _, ?! rto get SoftICE 'Back Door commands' which gives infos on Breakpoints,/ S9 A8 \, N; G) n+ F
or execute SoftICE commands...9 O7 \8 y7 s4 ]; a
It is also used to crash SoftICE and to force it to execute any commands
/ ?( I: T6 o& h  T9 ^(HBOOT...) :-((  ( W7 \+ {2 C5 ~2 _1 h4 u

( |- l$ q2 Y$ r( V  d" d5 OHere is a quick description:
6 f( g! {$ F: U7 s+ v/ ]-AX = 0910h   (Display string in SIce windows)9 l; h+ E- v* X7 u3 T
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
9 F$ B3 n+ k: W2 V-AX = 0912h   (Get breakpoint infos)( j4 Z9 l( o# o. O- h
-AX = 0913h   (Set Sice breakpoints)
4 f  r* O# D6 ]-AX = 0914h   (Remove SIce breakoints)' u0 b$ _# O7 V2 S

0 t# `) u1 @: _" m. W# LEach time you'll meet this trick, you'll see:) D6 l0 J: ^4 E) T5 ~: i% C
-SI = 4647h: L7 M/ ?% q2 ]/ r
-DI = 4A4Dh
% U9 ^) S4 L- g8 t% X0 T. V1 G* WWhich are the 'magic values' used by SoftIce.
# n$ _" ~" c$ \0 r  _2 xFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
( @% I! p0 @# d  `% ?
* V' O2 \0 b. Q/ o2 oHere is one example from the file "Haspinst.exe" which is the dongle HASP7 V+ X" E' a+ e. ~3 T" x; B) [+ i
Envelope utility use to protect DOS applications:
+ z' _$ m' f. ]& Z2 H
/ q' k3 g. u: }7 v# U" q& ~; ^4 Z9 [" t/ u0 L* H. r
4C19:0095   MOV    AX,0911  ; execute command.
6 D6 Z* x1 D' `3 ^& W; v% I4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
* Z/ d  ]8 y/ l/ ~4C19:009A   MOV    SI,4647  ; 1st magic value.0 Y, q2 a+ H# ]
4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
. D7 `. X# u, P& `9 {: V4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
9 t$ e/ n- v" m& h* d4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
" o! J; @& U$ O# A3 o1 K% l. K/ z4C19:00A4   INC    CX) x' K  f0 s9 D( F
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
, `) E" @. a: ]. Q4C19:00A8   JB     0095     ; 6 different commands.
' s# W: B, v0 {9 F9 ]8 {- o4C19:00AA   JMP    0002     ; Bad_Guy jmp back.- u; U! `$ B: c& o
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
2 h8 X4 E' V9 E$ ?, J7 V7 _: x' P. X2 |- N: }5 g
The program will execute 6 different SIce commands located at ds:dx, which, o1 E0 d4 U( Q* ]; r. P9 I8 }
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.7 {& U* r& ]! e
) J. p: n4 U! W( |4 p/ a9 }
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
  |5 n/ H8 q4 O. s! D0 R  b___________________________________________________________________________  M; V3 l* G" S) S' m- K

8 [0 |7 T2 R, P: j. k
; ?* g3 k# Q2 z# P' M8 P0 ]Method 03
) f0 F9 H; D* h; z=========
1 i8 J0 W9 S, T4 A" \3 {; \% o# r6 [% l- _" ]3 d
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
+ z& L0 V" r: m9 B. U! ~( A(API Get entry point)
' b3 _  L( M! L, O; r2 O        
( y5 X* X9 ~* w7 d: j3 d4 B
& L8 ^. D$ a0 ?4 @' X) I% E) I    xor     di,di
& R( Y) Q9 {! Y& p    mov     es,di( M% a! @( r+ I" L9 [& Q
    mov     ax, 1684h       ' R2 p8 W* O1 l8 H+ C7 b
    mov     bx, 0202h       ; VxD ID of winice* p. H" v8 b) S
    int     2Fh$ |  X7 F) u  J0 L, @
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
; h3 f7 R1 z' n0 \% Q    add     ax, di0 K' I$ z5 w- O1 d1 t
    test    ax,ax+ W  p' S: [  W5 h# Y9 T
    jnz     SoftICE_Detected$ e# _* [% L9 o) p, t
& ?* \# K+ ]. x
___________________________________________________________________________
/ A1 k0 D5 P$ H/ s. P/ J; t+ b2 D0 @5 Q
Method 04
* }$ Q0 E% h' a& c, A=========8 t  \7 ]1 y# T+ Q9 v, _( `6 z
; C4 K6 H" a2 u/ |0 n6 |
Method identical to the preceding one except that it seeks the ID of SoftICE
( l# Z# \* O1 `GFX VxD.5 Y8 s: q2 q+ K6 T  H/ ]
8 y, ?+ S6 j& Q
    xor     di,di  G8 _8 Z0 L5 a) _
    mov     es,di! J/ Z2 v  b0 o; ~8 q: A6 p
    mov     ax, 1684h       6 s/ B) Z  K. {# |% t/ k
    mov     bx, 7a5Fh       ; VxD ID of SIWVID
" k' N( f2 R( f5 `3 [0 J% _$ l3 f    int     2fh
% t  Y8 j1 h* b2 t& D! A- U0 K    mov     ax, es          ; ES:DI -&gt; VxD API entry point' F" \) Z' l/ t7 U) `: `
    add     ax, di
7 M4 M& ~- {& P8 s    test    ax,ax6 v3 \1 m$ ]0 J7 H7 j
    jnz     SoftICE_Detected
6 X$ E( ?& O  p/ s' k, Q
4 C. g! S+ e  g+ `; W8 q* `8 b/ U__________________________________________________________________________# ~. w. `- H9 m! Z) `0 ]
: h1 R  q3 f3 l% D
8 K0 A' y3 u4 X. ]- @
Method 056 ]3 A0 Q) t( x9 I, C
=========; M5 s5 j. Q. g' B0 y" [
, V9 a7 P8 _& I8 @; A+ M/ a
Method seeking the 'magic number' 0F386h returned (in ax) by all system
' @& _; z* ?- p+ Cdebugger. It calls the int 41h, function 4Fh.
( i8 R7 q8 N6 d  Y, A2 x" Y2 FThere are several alternatives.  4 r/ w4 F$ o! l1 u3 X
& J& d* P0 W4 u  o
The following one is the simplest:0 ~. D- f, c0 V8 X3 U
1 {0 ]! W, F1 I7 T, q8 f6 [0 ^
    mov     ax,4fh/ K4 A. Z1 e- Z% A# a9 M
    int     41h
4 N" ^! ?% ^' p/ e( g- p. k    cmp     ax, 0F3863 i' a3 R2 i1 p% N
    jz      SoftICE_detected* r, f) p5 a  j3 ?6 K& I
: I5 M, B6 k" X6 z  y  c
% A1 M5 r0 _! c  n; n9 W
Next method as well as the following one are 2 examples from Stone's
) M" z1 Z( H/ m3 Z" l0 d: W& d"stn-wid.zip" (www.cracking.net):
% d5 `! t3 I! l- G6 Q4 B
4 N  B5 e# e- A" r    mov     bx, cs$ [! b. S( }, |# P- s: Z
    lea     dx, int41handler2
( N+ l9 U' K, r. `- G  L1 c    xchg    dx, es:[41h*4]* G) R5 ~' z  W- y
    xchg    bx, es:[41h*4+2]! _, V: c2 ?/ F: d) U( M
    mov     ax,4fh1 l  _, E+ \* ?
    int     41h
: W9 \) ]& V, o    xchg    dx, es:[41h*4]
0 u5 A1 d+ d. z& q2 s0 x- x    xchg    bx, es:[41h*4+2]
4 K: p- q* z$ B; e# w# `    cmp     ax, 0f386h
, B' q4 V5 b% f; d+ X* j    jz      SoftICE_detected
1 b4 @' w4 @% d5 t
! I) o: ^! `2 x( `9 f6 ~int41handler2 PROC, F" a5 a/ U4 a+ ]# D: j! y
    iret; K3 P6 ?3 t5 l! r# a! }
int41handler2 ENDP4 V9 t" u( C& w. A! m
2 z$ `+ ?2 l5 I, T' I
7 x! }1 l, L; F2 C/ `! D# X" s" Z
_________________________________________________________________________
& S* p8 R1 e/ W& s& D! g) U. a! G9 ~, X
) H0 V* T+ u" u/ l  ^
Method 06
6 |% J% M% `, l5 [, k2 p( @$ P/ w6 e=========: E! @3 K, S4 C& w) U: @
& ?& k$ t* T( C0 }

+ ^4 V1 A; z1 ^% E1 X; T2nd method similar to the preceding one but more difficult to detect:
/ a; t* n; _8 l5 L6 V
' u& @' V) {0 P6 M* K
/ d) n* Y& `) n8 L3 V4 |. d5 Lint41handler PROC
, u2 i6 c9 Z  i    mov     cl,al% r  ?- L: |) c0 j( O% a. t
    iret
9 T) _4 h: [+ w6 Lint41handler ENDP- |9 `3 D# j6 v$ v9 h: ~8 ]* _
* j( ~/ s( m4 _3 K7 i
% R; S2 l( A: g8 e# i
    xor     ax,ax: g* p" ?8 h# K$ W
    mov     es,ax
2 x# ]0 d9 j3 l2 e3 W# U  D    mov     bx, cs* P) g6 {) `  {! W/ A4 T! O
    lea     dx, int41handler+ z. K/ X9 R5 ~
    xchg    dx, es:[41h*4]
9 q0 n3 ~8 F0 t( n    xchg    bx, es:[41h*4+2]: Z6 ?  q2 U) j/ f* L
    in      al, 40h
1 Q4 j5 E, V; K2 [8 Q$ J    xor     cx,cx8 }1 v( m2 i9 {% h6 x( m9 M3 M
    int     41h
. W* n2 Y! c! w2 h. E- q  V. F. z    xchg    dx, es:[41h*4]. a$ v4 u. p* i0 Y" K
    xchg    bx, es:[41h*4+2]
) ?4 N" t+ [& T" V, D9 D    cmp     cl,al
+ e; j' l1 q) x) F7 E* C    jnz     SoftICE_detected
! _3 _2 }4 D& J) x7 M1 w8 u  K% i3 M
9 Q3 r: N, \2 b3 M: G1 v% ]& z_________________________________________________________________________
4 |( F; g5 q' P( R/ M
) d' M) D; J  n& T& hMethod 07
0 |7 Y7 B. I4 _4 _) I=========
  O1 M& p0 Z5 g) S" d' z. l
8 I8 M. C- o) d+ \Method of detection of the WinICE handler in the int68h (V86)
4 H# u0 r( r. K, P/ e. V. |
2 ?0 r7 x3 b+ w* R3 b) e    mov     ah,43h
0 d2 K! B; f' q+ i9 n! c2 ?3 V3 t    int     68h% Q6 N4 A/ W8 X: W3 p
    cmp     ax,0F386h
) z& l5 [' |+ [" y    jz      SoftICE_Detected
+ o, X, X* Z& H" x0 t& n+ }$ @# p: _. Z/ W$ [' ^. _% o5 I

+ e! s4 _. e9 r* s% x# l=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit, a' R9 D2 K6 t: I1 B! ~
   app like this:
) B8 q0 o3 o9 M5 o7 `; S- M
* k* b/ Z# d/ o  l% r, @   BPX exec_int if ax==68
# O2 R9 w6 [+ l. h% `   (function called is located at byte ptr [ebp+1Dh] and client eip is3 _0 N3 H$ x9 w; `& ?" [4 F3 i) a
   located at [ebp+48h] for 32Bit apps)+ V' z& m$ G( {3 R2 _) T
__________________________________________________________________________# l- G% H7 h" h/ ]& ?8 g) v* n7 R' d

( c$ y3 |, m6 h% S1 c
' P+ z* y5 e) [4 e) q8 YMethod 086 L7 Z: }' f& N0 M8 G  ?# r
=========
, r+ y8 e. e9 L6 j. L) B) h: X1 i
) _& B5 p$ w/ P# I: U2 [5 G% fIt is not a method of detection of SoftICE but a possibility to crash the
  [9 d, y: e3 Nsystem by intercepting int 01h and int 03h and redirecting them to another& g, g2 U7 _6 Q+ U& ]% Y
routine.1 V# ]* v3 B  g2 x
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points2 P8 k. @9 N3 F0 ^. o
to the new routine to execute (hangs computer...)1 W- u* y4 c: _9 X
+ Q+ g+ w7 y, E8 D" [6 J
    mov     ah, 25h9 P* ~* L' p3 ^1 Q6 R
    mov     al, Int_Number (01h or 03h)
2 y9 {* B: j6 F- M# `0 L9 H    mov     dx, offset New_Int_Routine
8 `# ~; ~; d2 s" ^" X+ I% z    int     21h
6 J$ N4 y9 }+ C2 k) _+ V5 |6 p2 j" C* l" r8 S
__________________________________________________________________________
: z' I* J: Y4 N4 F9 S$ |( Z* S% k/ @. F6 ^
Method 09
5 ?2 R9 }' |3 M4 j7 y=========$ r3 D) z% k/ @+ U& z/ C

0 i3 k/ M5 ?6 v& F# aThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
  \2 R+ d7 k2 [4 Y/ I  ?2 Xperformed in ring0 (VxD or a ring3 app using the VxdCall).
3 f, @8 ~3 z% k. h% F8 |The Get_DDB service is used to determine whether or not a VxD is installed
% N  Q: K5 D7 y+ Ffor the specified device and returns a Device Description Block (in ecx) for5 H" }  ~: c) b4 ^$ v3 G
that device if it is installed.
& w- x9 H" s0 z9 F" g; X& K/ C8 R: h9 x# c7 [+ g
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
" t& w1 g; ?$ |4 f* q, t/ Q   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
- m6 s4 t  {' w/ M( q. q   VMMCall Get_DDB
( T$ K" Q3 v, m/ Y) r# @% U( ?  ~   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
1 W7 ?+ b+ G4 K  T3 s4 Z7 m
* F: S) i# d7 i+ U( _+ pNote as well that you can easily detect this method with SoftICE:
8 F* V) I5 D+ B   bpx Get_DDB if ax==0202 || ax==7a5fh: f. S/ a; _6 N& j7 ^) I

1 X1 @7 E- l# n0 m6 f__________________________________________________________________________
8 R' Q6 F# q. o! ^0 q6 _3 B- `" }3 K0 P
Method 106 X, i8 p: c' I+ x* K2 ?
=========
; |! G6 G% c7 C8 O. L
7 N9 U. A# S4 P! F=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with6 R$ |4 l- q$ P8 @& d5 G3 ?
  SoftICE while the option is enable!!
/ ^3 ~* }! b- ~6 a0 v3 Z5 c% J* X3 `* _& c! F6 r+ i
This trick is very efficient:' j% S; d% u+ G
by checking the Debug Registers, you can detect if SoftICE is loaded; o/ M; P9 Q9 C" q& g- N1 r
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if9 m% A- R: X; B0 {8 l9 [
there are some memory breakpoints set (dr0 to dr3) simply by reading their0 h+ W5 ]: Q% `% [
value (in ring0 only). Values can be manipulated and or changed as well
$ C4 e" Q5 C' O9 _(clearing BPMs for instance)
5 z. d4 |3 U1 F2 Z
( |( s$ V; }7 |% E; w8 [__________________________________________________________________________) Z0 j% g! C, e& G5 x4 k/ w4 o

2 P$ E% ^& O* {( e4 ~) _Method 11) B4 {+ ^4 @6 ?. z5 u1 R
=========: @! F- y; q$ ^, [* T
1 }- m3 K( Y; M6 o
This method is most known as 'MeltICE' because it has been freely distributed
; x+ h% l! c4 d  D3 e/ L+ bvia www.winfiles.com. However it was first used by NuMega people to allow  m3 [) n4 H( T
Symbol Loader to check if SoftICE was active or not (the code is located* C% Y: i7 [2 Q, \) C7 Y. _
inside nmtrans.dll).
* s( j" j6 N4 @8 D8 A, }' q
/ w8 R% K% A- u' I; w, h5 _$ SThe way it works is very simple:
+ j, \/ H* l. m/ vIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for+ ]+ \4 K% t3 Z4 V+ A
WinNT) with the CreateFileA API., m+ Z) _8 t7 p* S8 P
6 J0 r# ^7 l3 M& i. e* b
Here is a sample (checking for 'SICE'):. U- X0 X2 a. z; ^$ K
% Z" w9 T5 O& b. z$ v" G! k
BOOL IsSoftIce95Loaded()
, ?- a  ?  K- ~5 Q1 M: E$ ]{
! L2 p6 W' ^) X& z, V   HANDLE hFile;  # b8 W9 L2 c) u& t2 v8 `
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
: J' N6 g! a0 l3 |# r" Z                      FILE_SHARE_READ | FILE_SHARE_WRITE,/ H' X  ?7 T8 C
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
  g6 o3 w: [0 t% f9 n' R   if( hFile != INVALID_HANDLE_VALUE )
1 H7 Q( n% u% j# L   {& z& j. B7 N" L  t! R$ v
      CloseHandle(hFile);1 }+ N: ?3 ?5 ~
      return TRUE;
  D) H. L+ L& @* k   }
" l$ i4 ^3 Q- D- t   return FALSE;, m) J$ R" J; q  Y& k) ?' n1 ]1 S
}
. g/ O: e/ s* B! N4 m
- c  ~0 C( F" Q; d# [5 |Although this trick calls the CreateFileA function, don't even expect to be4 B7 ]/ a8 ]2 K4 M2 f' [# P
able to intercept it by installing a IFS hook: it will not work, no way!3 X! J5 N# H& M+ i7 I3 z: N  a
In fact, after the call to CreateFileA it will get through VWIN32 0x001F' ]" A4 Z" V  l2 b$ I& m/ G1 T5 i
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)) V! U% h: G% L2 M/ x5 k8 e
and then browse the DDB list until it find the VxD and its DDB_Control_Proc+ o( l0 p. U/ @% H9 H7 g' m
field.- Y" B7 z  z/ b- v" ]! o
In fact, its purpose is not to load/unload VxDs but only to send a
% R4 G2 ~9 Q# v% o& p- D7 b& f! LW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
5 J% F- m4 C, T9 I* z- Cto the VxD Control_Dispatch proc (how the hell a shareware soft could try6 G; L4 r" x+ ]2 T3 M
to load/unload a non-dynamically loadable driver such as SoftICE ;-)./ t- ~3 @- u# L
If the VxD is loaded, it will always clear eax and the Carry flag to allow
, o0 Y6 [- a/ g$ Z. ~its handle to be opened and then, will be detected.
4 F4 t$ p  X$ R# ]# ?! AYou can check that simply by hooking Winice.exe control proc entry point( C0 A: j9 k% [7 D+ H, U$ f1 D
while running MeltICE., T. C: ?; L4 r) N0 j7 _. h

& P( c; Y6 ^; t' z& r
3 L( ?( u% F2 D. S8 M% L; y  00401067:  push      00402025    ; \\.\SICE  \/ t& ]- g7 i# S% C  w& b
  0040106C:  call      CreateFileA
. p  c) D8 o- e6 `  00401071:  cmp       eax,-001. H6 c0 Q% Y" l* {! s% w/ E% e
  00401074:  je        004010912 ?9 ~0 k" C& i* z

" V6 [5 k  ]- c7 \3 b" R% J3 K& y5 v$ {, v, f
There could be hundreds of BPX you could use to detect this trick.
- ]; Q7 G! Y  }+ |% O-The most classical one is:
4 A, O) X5 C3 S9 x* p  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||/ Y) I( s% w* u) a: z2 ^* _
    *(esp-&gt;4+4)=='NTIC'8 P; H2 G+ l# H
7 Z. k/ [5 I+ |0 l+ }' D
-The most exotic ones (could be very slooooow :-($ v, b0 D  S. U) @
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  - H  t* L5 @2 n+ E4 m. [4 C
     ;will break 3 times :-(8 Y' r9 Y3 g, s) L  c( n3 B6 s

2 W: B6 H9 s" I# Y& A-or (a bit) faster:
3 s, ]3 C0 V% o& v* v9 j   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
' ?; K" g- J5 z; B3 i9 g& W1 C: p8 Q4 B( K9 N; F: @  H& c
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  0 Q1 p8 k2 H! E; G  W& P
     ;will break 3 times :-(3 T$ Z; N9 j3 ?1 _" E2 a& A7 a
, ^5 p* {8 _! G. P; u1 [
-Much faster:8 z. w' k& `3 v
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV', p0 v7 g7 s) N, ^2 n4 |2 ~5 b3 n4 x

4 X7 b+ b: g8 ]1 z. c: mNote also that some programs (like AZPR3.00) use de old 16-bit _lopen
1 K6 J3 s1 p' C0 V. R& Gfunction to do the same job:7 r6 W' ]4 k. h1 B; T

6 l; V# a0 e. d% X1 z) J9 {0 F& z, I   push    00                        ; OF_READ
1 M* n$ v) v: a# y5 c   mov     eax,[00656634]            ; '\\.\SICE',0
: i/ o% d6 |5 N0 h1 X! y& t) Z   push    eax
0 Z3 B+ k  j$ G3 ]   call    KERNEL32!_lopen! I" n2 x: r9 e8 L
   inc     eax" c- r+ b6 A2 N5 B+ E3 g: ^
   jnz     00650589                  ; detected9 c9 D: u9 w) @. w7 w$ M/ ~/ M
   push    00                        ; OF_READ
: f3 m& c) ]' ]. T4 h4 s) x   mov     eax,[00656638]            ; '\\.\SICE'
: u/ U1 D% A( {5 w   push    eax2 M- f! s: r! _
   call    KERNEL32!_lopen
) E& K$ e; Z9 \' p" h   inc     eax
  ]$ U" F% G/ @/ W% F8 z- o   jz      006505ae                  ; not detected
! U: P- H+ ]2 W- V' w* R3 f( y
% @8 y/ g! {' i# c* @( v4 i; J
5 K+ c8 p5 x; c3 u/ g9 f# m" I__________________________________________________________________________
2 P0 Z( l6 M# g6 s! p8 @! V' ?! l" A3 y2 c8 z. P/ [
Method 12, D+ f, l3 r! A7 z8 J4 M; M0 y
=========
- `, y9 u2 G- W3 u) F0 a& |' [& M- ~% K
This trick is similar to int41h/4fh Debugger installation check (code 05
  X) o5 P; g  ~/ Z5 V, N&amp; 06) but very limited because it's only available for Win95/98 (not NT). H+ F8 Q) k) W- q5 L9 m8 B5 t' C
as it uses the VxDCall backdoor. This detection was found in Bleem Demo., y3 E% ^" v$ Z3 r' w2 @- J) {7 a9 k
5 Y- p1 u  y( f) f7 V- k5 H
   push  0000004fh         ; function 4fh
1 G0 b" Y2 p) j; E/ m- E   push  002a002ah         ; high word specifies which VxD (VWIN32)
9 N. z: A9 p; D                           ; low word specifies which service# _) M. m% L9 U
                             (VWIN32_Int41Dispatch)1 `+ O, J" m4 q0 j
   call  Kernel32!ORD_001  ; VxdCall+ E. A; H6 I0 Z$ t  E6 ?  z
   cmp   ax, 0f386h        ; magic number returned by system debuggers
5 E6 J/ S$ }3 T6 |   jz    SoftICE_detected
' {, y, @0 y$ p" q" n1 _: g- J* W& {; L
Here again, several ways to detect it:
5 s9 v+ x2 t6 F
2 ]/ c* G5 n8 v6 Q3 ]3 \  Y( I    BPINT 41 if ax==4f+ j6 Z0 L+ V7 ~$ Q( X% i; t
+ y& j8 U0 f  X8 [: v+ S
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one& U$ j  F/ z8 H6 M0 }0 c- {. E, H

* `5 b& E, |8 i. w    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
- G# Y- h( F5 {7 v" x- V6 |+ k( w: M7 J7 }" c
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
+ C: o( s7 u5 Z, ?5 z2 E. f# X
& Q; _$ J+ D. X+ f+ r) E1 r5 L__________________________________________________________________________
  y  Q8 k0 f2 o! d( \. T9 H: {# A& B( s* ~3 V, e1 c) }% N
Method 13
" k- [8 E" d3 m) d) m7 O  o1 U- ]=========; g) b! P% C$ @9 j; l( G9 |, s+ q/ {
  J( n. E- k0 \. }+ e
Not a real method of detection, but a good way to know if SoftICE is" Q' v0 `; S' V
installed on a computer and to locate its installation directory.
  F- E" X  `; ]3 p! S0 oIt is used by few softs which access the following registry keys (usually #2) :
; `& x1 m% Z, n' C- j' K" V: ^
" G9 K1 Q+ R+ y! ]) y-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion2 ]: o; V; F0 I! E9 w0 L2 g
\Uninstall\SoftICE
$ q+ V' T. c! \% n-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE8 n( ]8 l( M4 z& V+ D
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
- f7 B) p6 d3 `9 l( S6 E! n0 W\App Paths\Loader32.Exe
6 w7 P8 {3 B: _7 r0 M/ W2 }" Z0 ~4 e$ B' |- M; |6 p- F; H
# j, W! J7 R7 L8 q
Note that some nasty apps could then erase all files from SoftICE directory
  m' Q1 n: a" N$ T8 [4 |(I faced that once :-(
8 Z( s! q+ ~5 _+ L. Q- Y$ r* S/ P$ b6 h4 x) Z6 m
Useful breakpoint to detect it:1 N! \2 M- J, a8 O
% O& G$ V6 c* x8 i
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
  O9 a) ~" e. B) C
/ M9 d  Q4 y9 y: I. A__________________________________________________________________________
( Q0 }: ?) G0 G8 s; E+ D
( |: d# i6 P' O2 k0 Y3 i/ u5 {/ o( a+ O1 V7 M! T
Method 14
: y  ]7 O4 W2 J$ ]; a=========
$ c9 J" t, A0 G# U4 W  J6 a; S) \2 A1 Y. F8 n7 H& R& z
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
  ~4 B, R% Z! N$ O  @0 His to determines whether a debugger is running on your system (ring0 only).
8 g! y4 z$ w7 N2 k0 l( e& l9 R& h: e+ m" ?8 K
   VMMCall Test_Debug_Installed7 @' d8 x2 Q8 Q2 F6 g" d* b
   je      not_installed
& y$ O* c" p5 l- f; v, t; k* q6 S  Q( A' d; Y% N  k* P* ^
This service just checks a flag.
0 W6 v$ Q8 y" B1 B! }</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部