About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>1 f3 _" f! b3 }6 V
<TBODY>
9 w: {- M/ l$ t# l# _5 {! U# \<TR>; a' o/ z0 ^6 b- j, p
<TD><PRE>Method 01 $ f" r" `8 E$ J- T7 q" m2 \  L
=========( l! T) A9 b* q" o
+ p5 Y" D% m7 F/ y0 a
This method of detection of SoftICE (as well as the following one) is- T: _, s$ I8 _: J# w; P% ]
used by the majority of packers/encryptors found on Internet.
) e/ @$ q) [. m3 z6 Z$ W6 d% ?2 QIt seeks the signature of BoundsChecker in SoftICE  ~  t/ V% z% ?) R: S

, G0 f  W" ?  \6 s    mov     ebp, 04243484Bh        ; 'BCHK'0 Y3 Z+ R8 M3 J! r/ J5 H
    mov     ax, 04h" S5 ?( Z' a+ s
    int     3       + _3 H/ I$ `" f! c1 @
    cmp     al,4
% B# g& ?, ]. g, i7 m" h. D" @; E    jnz     SoftICE_Detected5 B$ A0 @7 X; {* H* }1 m& @

$ o( x+ V& O8 h# s' \___________________________________________________________________________
; A. {- I( S5 Z  k1 p( ~3 ?9 }3 K& }: \$ }2 k6 L: r
Method 021 P% T* y7 Y7 y
=========
! F2 w5 m! ?0 F% y0 A. q% Y. W8 F& c( K4 L
Still a method very much used (perhaps the most frequent one).  It is used2 z) K, e8 @1 p
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,# D2 e/ f5 t+ x$ S) L. p  D
or execute SoftICE commands...
1 e; Q+ Q" r0 e' L, g8 J$ S3 i4 m8 MIt is also used to crash SoftICE and to force it to execute any commands
9 O& a: O" P. k* `$ S(HBOOT...) :-((  1 `. S0 C/ \. t/ o* H6 @& P! U; H

5 I' ~7 x- _6 Q% G$ nHere is a quick description:
! O! _& {- Q8 ^! h( k" X3 X4 u-AX = 0910h   (Display string in SIce windows)6 y% n9 y+ ~- f4 C
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
) k% e8 [- @. g! ~: K-AX = 0912h   (Get breakpoint infos)) _: C( D! Y8 l4 O* X% |
-AX = 0913h   (Set Sice breakpoints)
) H; G% `0 T& c-AX = 0914h   (Remove SIce breakoints)
1 X& D2 }) [2 @" z, M/ V% ?" r! U' Q$ L% e  j; q6 g
Each time you'll meet this trick, you'll see:, v8 s3 c8 v6 h+ H, c* F
-SI = 4647h
, }/ H% ^: {! ?" }, k# U; l-DI = 4A4Dh$ r$ z: y& b6 S# x6 ?, D3 M: w5 c; t
Which are the 'magic values' used by SoftIce.
. s% N6 f# s/ p) oFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.1 O) e% X' W6 n) C
+ H5 J3 M6 ?  `! o- i& V0 y' l2 p
Here is one example from the file "Haspinst.exe" which is the dongle HASP! @$ m$ N5 L* I) c  E, q" [
Envelope utility use to protect DOS applications:, \2 u) B& P% w1 z

* Z' g  ~2 g9 W# L* j3 h1 z$ ]) F4 H
5 D& S: c" _. p2 G, e  E; g+ l4C19:0095   MOV    AX,0911  ; execute command.
/ ~2 e( y7 @+ q' f0 i1 J4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
, ~# k- S- ^% M4 _# ?+ l" e. @9 m8 m4C19:009A   MOV    SI,4647  ; 1st magic value.
5 F6 ^+ ^% k0 S% Q1 r- X2 L) g( ?4C19:009D   MOV    DI,4A4D  ; 2nd magic value.7 l% u  W4 `/ @( c# n
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
4 ]* i4 {! z) ?4 f! x! g3 u5 T4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute3 O5 O3 [; s2 }; g/ T
4C19:00A4   INC    CX
' y, N2 ~/ _+ a) o4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute# w0 e1 Q3 m% P  X8 o
4C19:00A8   JB     0095     ; 6 different commands.- W9 L  d4 S8 F$ f5 ~
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.5 {, h: m$ D: e
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
7 `8 Q* r* D1 b' G; c  N* U
7 S1 [' ~! I% e) H+ n/ r4 O9 T4 zThe program will execute 6 different SIce commands located at ds:dx, which( G. t3 k# _5 G- M2 n
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
( N* v" Y& u% M$ q1 U0 \
. h' k: D* |3 W7 g" d, ~* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.* D- Y3 O& R; S* Q2 q6 B
___________________________________________________________________________
9 Q& q  ~6 Q+ G" i8 n+ c3 J2 ~6 W* \3 g# Z

1 A( k# l# N$ f1 V, E% A/ AMethod 03
' K8 x  M2 X! |) [0 `=========6 s0 d/ P. g. h6 S- Z2 Q; k% C

5 q6 D# U3 Z7 {5 f0 l5 a, y' N! n7 ?& zLess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h" t/ h# N8 @* x& i. t. x& `5 F
(API Get entry point)
$ S( F5 A/ O2 j( k2 {! P, \, I        
4 ^9 D0 K! V- Q  i' D4 X; P+ I( C: W3 @5 w. [$ B0 x
    xor     di,di
/ i4 g8 O" x) {. p6 ?$ Q    mov     es,di
+ ?  I5 L; ~! |    mov     ax, 1684h       # g- u: _% K* \
    mov     bx, 0202h       ; VxD ID of winice2 C2 L4 t& A# U( X: {% D$ ~
    int     2Fh9 |2 L6 M% ^8 g7 b; Y8 I
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
' Q+ j! q3 d0 i4 w    add     ax, di
% r5 Q. G& ^( @' c8 Q5 `' j% _; J    test    ax,ax0 F( i+ v3 Z2 E7 m; i4 Q! h2 s
    jnz     SoftICE_Detected
! k/ y7 c* P. L( G% z, d1 ~3 f5 K8 I6 ~
___________________________________________________________________________
3 v; P7 ?- g" O5 V; T% J- S% P1 t  K: d; n& g
Method 04
! c( z% ?0 _# }7 _" o2 Y/ g=========5 _3 j/ s2 z# G% ?

4 ?/ Z1 x1 a6 L% g1 g! S" r3 v9 AMethod identical to the preceding one except that it seeks the ID of SoftICE9 I2 K9 j; `- Z, Y' [* V
GFX VxD.
# m: ?3 x0 N3 B$ m8 W$ l- d4 A0 R2 R
    xor     di,di9 E8 r  F$ M- G; Z+ d
    mov     es,di3 H1 M6 ~+ V& M+ a/ f  S
    mov     ax, 1684h       / z( }  c5 O( x0 r5 l; \
    mov     bx, 7a5Fh       ; VxD ID of SIWVID1 K5 F  b9 E3 L0 g" c: w" i3 r3 X
    int     2fh
& f% P5 E$ @- i# f2 z    mov     ax, es          ; ES:DI -&gt; VxD API entry point
: Q. p6 o6 b2 x) ?+ D    add     ax, di; K/ {7 ?; z0 }7 x* {' a
    test    ax,ax- [! U" M# D7 n6 i4 ^0 W0 g
    jnz     SoftICE_Detected
2 q: c$ O. U. U: E, a2 z3 ?- ]+ n
9 L3 p) \% [; c, r, I2 a6 w__________________________________________________________________________
# [3 N) _- a9 M8 U: e" x3 u, P1 n$ l' r" Z4 t! O2 f4 c% R4 z
9 i+ k7 q+ ]1 @& G9 Y. O; C
Method 058 N0 Y! s: |2 L: F9 G
=========$ m( {7 L, D$ X) |

2 h/ f- o  S$ y: @Method seeking the 'magic number' 0F386h returned (in ax) by all system
( e: M- {- D1 o+ H% edebugger. It calls the int 41h, function 4Fh.1 \* Z; o8 {% s- _$ G
There are several alternatives.    |6 Q% Z2 Y1 B
5 a# m' [: E5 L# }& a
The following one is the simplest:% D, z' H. t. p: Z7 h
0 f2 k+ s- `/ R$ p
    mov     ax,4fh
$ }1 `* J$ B5 C5 T% ?' x: N    int     41h
. {, Q" u$ u% J  \4 ^8 N( _    cmp     ax, 0F386
0 W; @1 l( U6 z, D( `0 d    jz      SoftICE_detected
+ p- w. U9 x4 W! s
  u, p  _) v2 n/ x0 v# G
2 Y* m9 B5 _+ K. U; ?1 C# E" rNext method as well as the following one are 2 examples from Stone's
$ |) O1 X8 r$ v( @& g7 Y"stn-wid.zip" (www.cracking.net):! P( `+ n* e0 m* i- E' O3 F

& Z+ A4 U- Z0 S    mov     bx, cs
4 L# y" M  D, p& c4 g' h2 p    lea     dx, int41handler2
% E5 r0 d8 D. C    xchg    dx, es:[41h*4]7 P5 M# b; C" I' M
    xchg    bx, es:[41h*4+2]/ f# R8 v0 X! ~8 r9 w
    mov     ax,4fh
# t7 ~! y" t% r8 r) S% }    int     41h
/ {2 t. S8 O8 Z7 v: ]    xchg    dx, es:[41h*4]
1 w% c6 [% f7 x( T/ V! a    xchg    bx, es:[41h*4+2]
! [, E' r1 X+ k2 e3 ]) ~% a0 S: o    cmp     ax, 0f386h
  p7 \: T, {( }. _, ^3 w1 E    jz      SoftICE_detected
6 f1 `8 e/ c4 M1 S6 u
$ @# _$ ~- W' n8 [8 O6 Hint41handler2 PROC; {) r: ~% y. A% e" r1 \
    iret
; ?) P' h) N# ?# Gint41handler2 ENDP
+ `: r) @( u4 u; ^2 b
% ^7 r; P, M' B0 k% r3 C
# Z" b3 V& m3 t* X! n_________________________________________________________________________
7 `3 u% P( D" N, v, l; i$ E& {% t) @9 d8 f2 o/ F$ Q

! p. v& u; o$ m, VMethod 06
: \  F+ P: Q0 Z; T=========, \) F1 z' C, I* ~& O
! a0 o' h( V( w, S. k, b, o* Q
2 t$ m# @, [' z0 p
2nd method similar to the preceding one but more difficult to detect:
( D; z9 _* P  t: g( E7 E4 `8 x8 j4 j0 P' x; R- W6 _+ v4 b

8 L/ A* O4 t8 N+ {" Yint41handler PROC# f( x6 V: {$ Z$ J! b
    mov     cl,al6 ^- k5 p: r" a
    iret! }& S. R% V9 j
int41handler ENDP/ w- P5 ]8 F$ o1 T
' l, [9 r. C; R: m  J

1 Q; p% b4 f2 Z/ F    xor     ax,ax8 a0 H8 c5 e  l+ X9 Y
    mov     es,ax
$ n' g" t5 `5 }( G5 X% x" t    mov     bx, cs
* W/ O# s, w/ I2 t    lea     dx, int41handler
6 ?/ n6 F% \( o9 C/ m    xchg    dx, es:[41h*4]' O! m. Q2 G, ~+ v
    xchg    bx, es:[41h*4+2]
: U9 c$ h' m0 t4 T4 }    in      al, 40h% |: y9 j  y$ }0 h9 N
    xor     cx,cx- N3 _5 R# u4 p# d+ v+ [% V& ^4 N
    int     41h
, G" M" o* K: |# N, {    xchg    dx, es:[41h*4]
+ h- X( v' _4 z4 C1 o    xchg    bx, es:[41h*4+2]
5 l6 f7 E! g) X3 f. K    cmp     cl,al
+ m) Y6 z" n8 u2 S6 @7 X. i/ r' L% ~4 ?    jnz     SoftICE_detected% s# y7 O' ^1 K# P
8 {$ d( D! j: F7 g/ f8 F
_________________________________________________________________________
" c2 e9 w" y4 d6 h9 S' _2 z) a! U
Method 077 i( Q( ~8 H! [( |; `2 ~* B( Y
=========
6 ?' ?8 [1 C' G8 ^6 |' e" @# N' K& j$ b) p
Method of detection of the WinICE handler in the int68h (V86)
' G' k) |5 ?: _9 x+ A! i2 k. [! C9 S1 p" n6 N# u0 f# ?  {
    mov     ah,43h9 a$ {- ~3 L- J
    int     68h
: f1 A) p6 q4 h( \" i0 }: B9 L    cmp     ax,0F386h; q) f2 u3 z& i5 V( f) B6 @  u
    jz      SoftICE_Detected* q1 Z5 d# y, t( Y4 n" [2 m
' n9 c; h: c- T3 ?* B7 H
  i* O$ D2 _' a; R7 U; H5 N2 |2 y
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit* L* T$ p# u3 s) h. T8 j
   app like this:
: i# m1 V8 t9 d! m# b3 ?2 u: b3 V: a& d5 A! ?$ ]
   BPX exec_int if ax==685 U/ B5 z/ F% H/ U- b5 f
   (function called is located at byte ptr [ebp+1Dh] and client eip is
, z' k: a0 q$ u! }   located at [ebp+48h] for 32Bit apps)+ i4 m1 Q, }, G9 {$ _( {/ {
__________________________________________________________________________! ^. o7 x: U; U5 l" |% H

- I0 y# b  x4 A1 d. @5 ?' T4 R  D
4 I! u( t: m5 S% v/ cMethod 08: y+ c5 [9 h# ?/ h
=========
. c0 i9 z' h6 i- ^- a, l/ Z9 r4 X  [  g1 k  K5 X; R
It is not a method of detection of SoftICE but a possibility to crash the
! @2 u, M  H" @+ P1 Jsystem by intercepting int 01h and int 03h and redirecting them to another
2 Q- o/ w8 @. [& d% U# d$ J% nroutine.  A; @# B) x2 V* n# K  K7 @+ L
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points! C! y; n8 \7 C5 L+ s
to the new routine to execute (hangs computer...)7 I$ j8 d) M& e, P) K3 w5 l

+ A4 }! ^) M0 o    mov     ah, 25h
5 T/ n5 n9 r- F    mov     al, Int_Number (01h or 03h)4 ~- M: Y# e, v) w
    mov     dx, offset New_Int_Routine! d. j  B+ Q, i  l
    int     21h
! Y4 Y5 T+ Q: d5 t* N+ n
0 L8 m  |- A2 k9 B# N3 }__________________________________________________________________________
) ]8 H  O1 ?+ F. R% ~' r$ T9 W$ ?5 X* B$ A' d0 C
Method 09
8 b* Z" \8 i# {) z% U5 l$ l3 a' v=========, q+ y# K" n3 g) K4 O/ ^

- Y- q3 {6 p( o! M3 T7 L0 vThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
6 i, `9 M2 e" `7 ?$ @0 L- Rperformed in ring0 (VxD or a ring3 app using the VxdCall).
& @9 @! O# @4 _7 Q: {$ d1 hThe Get_DDB service is used to determine whether or not a VxD is installed
, H+ d( T. @6 }" cfor the specified device and returns a Device Description Block (in ecx) for
! Y5 |! I0 g4 l, S. sthat device if it is installed.
3 U0 g' B( x: o: {
, D, |: r& F4 ~5 Z1 W   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID7 {* B3 D9 j, d* z
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)* Q( l7 R9 P& D' d" [7 C' ]
   VMMCall Get_DDB  ]" q2 s# Z7 Y9 G- P  W4 c/ ~
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
. E; y( e" H- w
  h% t# X+ U7 n, ^Note as well that you can easily detect this method with SoftICE:- @8 I, s. V3 T! F* ~6 e$ u( k
   bpx Get_DDB if ax==0202 || ax==7a5fh+ D" k  X8 H5 B$ u1 _) N
8 ~5 I: N6 H5 y+ |& m1 y! M" c9 j
__________________________________________________________________________
4 S. s1 H/ i/ a# a8 b( n
) A8 G; V) }/ ?/ E8 h$ lMethod 10& j; p& O+ e: l8 ]
=========
) U) B6 [+ P. R1 o6 s7 K3 S7 g0 z; g$ o( O8 V
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with. i" ~9 ^7 r9 y' t) ?
  SoftICE while the option is enable!!
8 n2 u* G5 x& S% y. r) Q% @2 D+ S; l( f' r2 I% L8 G
This trick is very efficient:' b2 m+ {, G# Q4 u' S% j, n$ }" V
by checking the Debug Registers, you can detect if SoftICE is loaded
9 Y" i8 i6 T# c9 `  c(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
4 S5 `( r* H# ^- @there are some memory breakpoints set (dr0 to dr3) simply by reading their
2 G' u3 `. q9 m3 zvalue (in ring0 only). Values can be manipulated and or changed as well
  [# h9 c. e: }; R6 d, J(clearing BPMs for instance): b& d# i  _0 S5 z

3 N- @6 W  v- b$ M__________________________________________________________________________
( q* f. R/ n$ [- W& n* q
9 f1 J4 J/ s" p' R/ I3 ^Method 11
4 q' g4 R( n) a) S3 r* L1 y=========
1 p( j$ y  i6 _6 H9 K
" _# m( v/ h( |( F& R2 m* s$ e4 _9 pThis method is most known as 'MeltICE' because it has been freely distributed
6 u8 l9 i! A4 [! U( \via www.winfiles.com. However it was first used by NuMega people to allow# a  a- E7 p; K) Q% w
Symbol Loader to check if SoftICE was active or not (the code is located3 ^2 }% b- `' z  i8 G0 a+ P* W; G
inside nmtrans.dll).
0 k7 ~% g/ @1 x6 }7 i: K& U
) J9 g3 B: o7 ]- K# m/ d: kThe way it works is very simple:
0 o+ T4 B) g8 n9 @It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for: y3 t7 P5 O. [
WinNT) with the CreateFileA API.) I( u$ e" y* b  `# M- {$ {  b* Y
6 l3 g4 p0 d# C  O/ w" @
Here is a sample (checking for 'SICE'):
, t5 g& w2 [: i0 e. e; i& {* R: b% q' m7 G  j, K& P
BOOL IsSoftIce95Loaded()
9 u7 f9 F0 v/ U1 q4 q2 w! b{
. c7 Q/ g, N2 E0 G+ E- K   HANDLE hFile;  % E' B1 B8 z) S/ L5 q7 I; e/ Q3 Y
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
  n  f4 T# O3 c                      FILE_SHARE_READ | FILE_SHARE_WRITE,5 H  X; d. C# J1 W5 V
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
; {* j& X# A/ ?' z   if( hFile != INVALID_HANDLE_VALUE )
3 i* `8 J7 P. }   {
% X: b2 M: I: g+ [" L5 |: t5 o      CloseHandle(hFile);' P# ?) m  v, C) T
      return TRUE;
5 U( C$ D' I9 E! `. S   }
9 f  W8 G: y; @! q& N( v& I. N* {   return FALSE;
+ B% v% z9 L8 j8 Y8 f0 h}2 \- M# ]0 i. g! {+ H

+ b- ?8 \7 ?' \' b$ gAlthough this trick calls the CreateFileA function, don't even expect to be
0 \& m: f! s3 aable to intercept it by installing a IFS hook: it will not work, no way!
9 g9 ^. _% P" s" \In fact, after the call to CreateFileA it will get through VWIN32 0x001F
  n% p6 F, F& ^service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
2 Q- l9 u" l% T1 W9 Q% ]and then browse the DDB list until it find the VxD and its DDB_Control_Proc* Z2 X5 V# w7 U; m
field.8 ?, G. ^$ o  D4 {5 R$ S
In fact, its purpose is not to load/unload VxDs but only to send a 1 u% Y# ]$ I7 |/ Z
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)- ^% I0 ]: z$ ~" h/ v# v
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
5 I) [2 C7 x& g" E7 sto load/unload a non-dynamically loadable driver such as SoftICE ;-).
+ ?# z% _) _  C5 M. [/ Y4 ~8 aIf the VxD is loaded, it will always clear eax and the Carry flag to allow
5 ?0 S# R' _3 J# X( Yits handle to be opened and then, will be detected.5 M# h; A7 B! y. g! R4 c
You can check that simply by hooking Winice.exe control proc entry point3 z$ T, ~6 k% P+ ?1 X" \
while running MeltICE./ H- U. }3 H/ s6 {( z

2 Q$ j) E: x5 `) U0 }5 t
% j  S4 r2 c5 d  00401067:  push      00402025    ; \\.\SICE
9 x: N5 U, a* r5 h  }9 |  0040106C:  call      CreateFileA
% ]. a4 c% r; l) d/ v( V  u& g  00401071:  cmp       eax,-001" r8 @+ l- M4 X8 c" Y1 k$ ~
  00401074:  je        00401091
$ ^5 L' k& ^! ^$ G: J3 b
" ^- J* w2 B, L6 i3 _  r
, C$ j; [: j) Y( PThere could be hundreds of BPX you could use to detect this trick.
( @: f0 ^* M( a# ~8 Z-The most classical one is:3 F1 C+ v. }( E6 ~, {8 ~
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||6 c* r0 l- v& |& W- J
    *(esp-&gt;4+4)=='NTIC'( i6 G: s! q& P$ z; n( ~4 ^
$ R* l' r( U& \+ Q
-The most exotic ones (could be very slooooow :-(
: l' @% i1 J( l: `* K0 J% B   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
4 j( e5 w6 G0 D+ B     ;will break 3 times :-(
5 ]/ B" h( ~4 u& Y7 k2 ~3 \, I! N. B
-or (a bit) faster: , R: h3 `! T$ D  V, n
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
, [* a/ m6 }  U8 a/ O6 Z; L7 Y0 X4 |  L
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
6 G+ E: \7 f6 \; \% ^3 `     ;will break 3 times :-(
% X; }6 W6 J+ q) P
. G7 e4 f5 U( }" p-Much faster:1 E8 Y7 v+ l% m7 d( y, V6 T$ Y/ m+ z
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
, u0 j3 x& }" J% ~) B9 A( z% F2 V5 W4 h  r5 [! O6 W
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
, [' _& U+ ]. u: vfunction to do the same job:
* n( s0 l' p! h3 i6 c5 {* X# v5 ^
9 d2 {4 x/ y; d& w   push    00                        ; OF_READ  p. U; n' K- X! m8 p$ ^
   mov     eax,[00656634]            ; '\\.\SICE',00 _& i9 _' M9 D9 b" X9 \
   push    eax
1 a; }: Y  m6 r   call    KERNEL32!_lopen
+ c/ I2 G/ G9 i( P! M6 r   inc     eax# N7 G/ c: w! K; T3 h! a  H4 r1 _0 s
   jnz     00650589                  ; detected
" B, s; `: J) Q9 C0 T7 D. N   push    00                        ; OF_READ
+ _; e; P0 G! v# x   mov     eax,[00656638]            ; '\\.\SICE'6 P: h, o! f8 n1 T; W5 L
   push    eax
5 l# K# |, X" @7 j6 c3 t; D: H   call    KERNEL32!_lopen4 P, r9 n8 _7 |0 }
   inc     eax- I2 H9 q/ p& V9 |$ X4 Q. W2 A
   jz      006505ae                  ; not detected/ y5 U8 k! x, S; @+ |+ j
' e% F7 s' M+ n' k9 w
) M/ y' |) P# `: g/ |, I
__________________________________________________________________________9 J% O+ z; P4 D
" e6 Q# R( O! z6 S: c
Method 12& K6 ?# u4 N% J* q. ~7 y5 u
=========
: m2 J- J; z4 C
$ }+ G% y+ @2 M4 D. q2 QThis trick is similar to int41h/4fh Debugger installation check (code 052 f, c  ^/ k# r7 }9 E
&amp; 06) but very limited because it's only available for Win95/98 (not NT)& Q# f9 v3 e2 B) D
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.1 u, ~& X% A& m
4 L) O+ X+ b. S! e! v) R! v
   push  0000004fh         ; function 4fh0 H! n* }8 m5 @9 X& i$ {& u
   push  002a002ah         ; high word specifies which VxD (VWIN32)4 w* C- G. E) F% s0 _  Z
                           ; low word specifies which service7 p+ o% x. i3 b5 a3 q( W
                             (VWIN32_Int41Dispatch)
+ Q/ U* M3 g+ k2 X" b   call  Kernel32!ORD_001  ; VxdCall
, P  w  q# N" Y9 e, m6 X  |   cmp   ax, 0f386h        ; magic number returned by system debuggers: {- y" w9 ~1 D0 H+ p
   jz    SoftICE_detected
% E, x8 w) H0 ?# Q- R; t& Y: K  n+ `5 p% H. D) y# H3 m
Here again, several ways to detect it:/ f7 }9 H! E* D" p8 x

8 y& Z; w& {  O2 j    BPINT 41 if ax==4f
( [4 M/ ?4 s( P/ h, H: _7 O5 g* T$ l" {0 d" W0 ]8 l" X. K) X
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
8 |7 ]4 R3 O2 y9 K# t3 J5 Q6 f% s" s0 `- Z# N  Q% W" _, B
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
- y) K3 n/ E6 t: R/ V8 |: t
& U5 B$ y) ]1 Z. Z# Z# s8 w    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!# o# q6 M& M, h. B; Z. s

& k6 r8 O/ r% `__________________________________________________________________________0 t! {9 B# F( E5 k& G, ]
/ i: x0 Z% Y; H0 p1 i# X
Method 13* s" c' \% k3 x  H2 f
=========
3 P, T4 n$ ^: a) M
* g! L& x( i+ n$ j, n, CNot a real method of detection, but a good way to know if SoftICE is: o! {" v4 i2 ?" g5 E) e3 i4 b8 Q0 \2 f
installed on a computer and to locate its installation directory.4 h0 Z  X' {9 l: e
It is used by few softs which access the following registry keys (usually #2) :: }6 a$ R! j0 |& G2 }) }% |8 ]

- N, T+ v2 [7 R( i-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion" L, @* _5 ]  P6 V- w, x6 }
\Uninstall\SoftICE9 B5 R0 g  r" `7 t. G- O! |
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
8 S' f, o( M+ c( _. s# T2 u-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
  x. K- e" N. \# m\App Paths\Loader32.Exe
3 M/ a4 Q) V0 A5 d: F- X6 _
- J- l5 A" L! R+ M- E7 M! [5 Y& s! X3 }& O1 A
Note that some nasty apps could then erase all files from SoftICE directory2 m: A) J; T6 m/ N
(I faced that once :-(2 N' k* i( g) u
6 L6 r# y' C2 S1 I" O$ [0 _: J
Useful breakpoint to detect it:) V0 Q! B4 ^+ Y. e( f" U
4 `' p. Y8 A3 ], {8 I
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
5 D8 U3 g2 o2 Y6 ~; E: {6 v3 C0 E- e. P. g' E  b  d
__________________________________________________________________________8 o7 C' I2 p! ^& h

) X& `* ~$ m; R2 I. R
5 `6 [7 c9 k& S' AMethod 14 * }# q% _1 m( B) Z
=========
4 K: K' [; s* G" L5 F/ [1 M& A% Y; I# T$ V6 N, [
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
4 E* o! y1 z0 v, F1 z- J& r; ]  Yis to determines whether a debugger is running on your system (ring0 only).
; `% Y) t4 |! U: o9 w* k* c  G: I/ u
   VMMCall Test_Debug_Installed
: F9 ]( M& x. Y   je      not_installed
5 r+ [" s3 S3 ?* P) {; c3 x  A8 c* L; C. ]; k
This service just checks a flag.% {& m" Y+ f' j& m8 \
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部