About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>$ k7 ^# Z& G* }! m! l; ?4 D
<TBODY>8 m1 w; Q0 c/ [6 ]
<TR>' z; t- s. W9 j! n
<TD><PRE>Method 01 : e% r8 m, |& b( Y9 b
=========
% T$ T" c# D9 k$ A4 k
0 H5 N5 M( y9 G/ s, S% IThis method of detection of SoftICE (as well as the following one) is
9 q  `# z1 a% n3 d" h/ N& dused by the majority of packers/encryptors found on Internet.
: u2 B  h0 e0 O1 \* oIt seeks the signature of BoundsChecker in SoftICE# a  _$ d1 Q  v) c9 e
' q9 V( K" @* N
    mov     ebp, 04243484Bh        ; 'BCHK'
+ h! M, x) N% F8 e9 |' V    mov     ax, 04h7 z+ ?. d4 M) d$ X6 F' W, W% f
    int     3      
8 E' Y3 |' _* c- {    cmp     al,4
0 l; ^# F3 ?7 P: A5 n    jnz     SoftICE_Detected/ K) R% U5 y/ f4 n
; d( z& B  |: t! U8 f2 Z
___________________________________________________________________________
; L8 B, @7 L* [5 G/ d0 t) x# Q4 {! Y& x  J) y0 Y/ k  j2 t
Method 02
) U+ p& w) }4 o8 I7 q4 Y4 T=========
6 e3 F4 `, V5 O" b1 k/ P
: \5 T& m% c$ q' a( {Still a method very much used (perhaps the most frequent one).  It is used
& [2 ?6 G: e# m6 c  B! g4 v+ m; p6 Yto get SoftICE 'Back Door commands' which gives infos on Breakpoints,
3 z3 ]: E6 B7 F& q3 xor execute SoftICE commands...: c; R7 _! Q# J
It is also used to crash SoftICE and to force it to execute any commands
) o6 a: J, M- O1 w(HBOOT...) :-((  7 b& p8 ]4 `( H" Q, r1 p' q( q
: n9 G9 F; y; w# \, R. J
Here is a quick description:
2 C6 S6 P- o9 w0 q-AX = 0910h   (Display string in SIce windows), b7 a. H$ C# K' L8 U$ m4 E
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)" D$ {! e, ]) M0 u  e. o
-AX = 0912h   (Get breakpoint infos)% N8 u- O1 J( @" D" t# ]1 n8 y
-AX = 0913h   (Set Sice breakpoints)
) o7 |( L* Z1 |6 b2 ?# |-AX = 0914h   (Remove SIce breakoints)4 [! {5 [6 a) t  k$ |* T
. {  _; v8 [4 c
Each time you'll meet this trick, you'll see:
+ A, @# G. U1 E! T3 ?, W-SI = 4647h0 R( u/ l3 `# e5 g
-DI = 4A4Dh% _( ~! v2 C& |) Q0 k! v- x
Which are the 'magic values' used by SoftIce., v9 q' K4 p8 |& \. H
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.: j) x  ?1 |) x; H1 w. b+ a
* n, D) P8 i( x' \
Here is one example from the file "Haspinst.exe" which is the dongle HASP6 ~- @; \8 r- _* h! z  Q
Envelope utility use to protect DOS applications:
8 ^" U1 E! S# A8 c! n* ^" k
, ~' i5 e: v7 X& D. _, S+ M5 ?4 o3 @( r3 |8 {$ j5 E1 q+ V
4C19:0095   MOV    AX,0911  ; execute command.1 x1 l" J% S/ m! |3 {
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
3 R! V+ n# l+ ?5 _4C19:009A   MOV    SI,4647  ; 1st magic value.
$ m, }% c, m& r9 m  _$ _  r4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
$ j% N8 `/ k# u  _4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
/ Z$ D# t4 [+ M0 r' d8 W( B4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
+ ]* P0 a3 m% ?% a4 v4 c2 y/ }4C19:00A4   INC    CX3 ~. ?/ f& v" }# Y; s
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
: |9 v& U) X" N- t# U4C19:00A8   JB     0095     ; 6 different commands.6 _' v& L% Y( y
4C19:00AA   JMP    0002     ; Bad_Guy jmp back., s; l" P/ Z, P# r* x/ O2 L; R9 M+ Z
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)) w. B( S2 j* c3 Q6 z4 a

$ B* |! f( w% X: n( u3 I! v  kThe program will execute 6 different SIce commands located at ds:dx, which+ K. k* Q- M9 y. Q
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.( R/ W" Q9 D6 i; A& e4 T

/ |( b2 P6 D9 t4 g8 F+ ^' b* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.( f6 S, v7 ^: m) Y: [
___________________________________________________________________________
( B0 }$ q# K0 M) A1 `
) [! O* Y+ ]) t" \. i3 {% i! B# _+ [7 H, d7 O
Method 03
- b' |- O8 Y  k5 a5 L1 }=========5 v) t6 M- X; e7 W% d

# ~8 f0 C9 t, S4 h  ]' xLess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h; P) j) ?' N/ C% [
(API Get entry point)
% v" x7 X$ f, d4 B3 q" h        
( T/ i$ B, P! D: V) g
' b6 g- L0 w2 h- l    xor     di,di
* L# m7 @& y! s8 V! X/ q7 O/ v1 C    mov     es,di
( |0 H( @% Q6 `3 {! I; G+ ]4 \8 u: w    mov     ax, 1684h      
( z" l: v; T! G$ ?5 ]& t7 Y    mov     bx, 0202h       ; VxD ID of winice
: W! Y: w7 @) A  T1 g    int     2Fh
6 ^2 ]2 T9 u. v/ B    mov     ax, es          ; ES:DI -&gt; VxD API entry point& z& y7 [0 }0 |2 l' i
    add     ax, di5 k  j0 [4 V' L" X* ?8 k! F* _
    test    ax,ax( q8 g/ ^: S  V' S" w; E
    jnz     SoftICE_Detected
, q& o5 A; y' R; J! @2 o1 `: t9 @* ]! _6 q* g9 y' k6 J/ u
___________________________________________________________________________
) r/ o% t8 E. U2 b
2 U8 [+ ^4 o3 qMethod 04
, n0 c; }* m; n, z  O8 ]$ n=========
4 k( i/ u" }' t2 @4 u$ h' ^7 L' Y5 j7 Q% x" T7 u
Method identical to the preceding one except that it seeks the ID of SoftICE
8 G8 D8 n  Z) w% H4 J3 oGFX VxD.! B8 X1 N/ n7 ]7 e( S

" X/ `; ~( `6 q: F( P    xor     di,di* x' H* n) V% z. k) }
    mov     es,di; x! M+ P2 S9 ^9 c5 F
    mov     ax, 1684h       - f: J, _: H  H9 J' T! F
    mov     bx, 7a5Fh       ; VxD ID of SIWVID# A6 e( U$ d2 [/ W( h
    int     2fh1 S: H1 N/ m- G3 L3 U
    mov     ax, es          ; ES:DI -&gt; VxD API entry point2 C; M+ D! l4 J
    add     ax, di
  l0 S5 I! ^* h+ ~9 ^( ^) q3 D    test    ax,ax+ Q" A: Z" B! h5 N) l- V. e8 k
    jnz     SoftICE_Detected2 J+ F- z8 i( G) v
% _( Z; B# O3 A6 P2 f! A
__________________________________________________________________________
6 u" E: m2 E( o% B6 w; l) I
, [. q& D. K- s& Q% {7 E; @4 o, q" G! p% `* _, x+ U, i
Method 05
4 `% d' q5 g9 D, {: i=========
/ U$ a  S0 z* K8 r, E! d+ b$ p9 p
9 E4 |; h& P, i) n7 ]Method seeking the 'magic number' 0F386h returned (in ax) by all system. B1 u9 |- E, r9 M9 \
debugger. It calls the int 41h, function 4Fh.4 ]& c+ D) ]" O6 T$ d  l
There are several alternatives.  
2 Q. X2 @9 H- a, F$ z
1 ~, f3 u3 d3 m* n8 O1 P+ PThe following one is the simplest:
9 I2 D% D4 R8 P% Q' z' P& }" d
5 {& D3 B/ ?# ]) v7 P    mov     ax,4fh$ C( v( {' h  W) ^: f( e4 Z/ {
    int     41h, }. Z) ?! J% n8 h+ u& a& v
    cmp     ax, 0F386
) c6 u  P& O" b    jz      SoftICE_detected5 |% w9 u0 y+ l

# R+ U8 s6 Z. d$ h8 r
5 q8 c5 m( `0 x0 W) }Next method as well as the following one are 2 examples from Stone's ! H5 D0 T- P% T1 c7 B
"stn-wid.zip" (www.cracking.net):
3 Y  Z8 ?7 q$ u2 l  ^- r/ R5 |0 D( H3 J" |
    mov     bx, cs
+ x3 j5 u8 s0 ?9 j. H    lea     dx, int41handler2- ?* A& O5 s1 [2 Z$ Y
    xchg    dx, es:[41h*4]* l. Y1 T4 d# a
    xchg    bx, es:[41h*4+2]5 [4 l/ ^! f' U
    mov     ax,4fh# Q8 F) Q+ ]% u7 Y8 p
    int     41h" v5 O5 f& @6 Z8 T
    xchg    dx, es:[41h*4]
9 c% f( P( f4 ?9 u    xchg    bx, es:[41h*4+2]9 ~1 B$ n0 e. V5 L
    cmp     ax, 0f386h
7 @/ k! |2 X" Q9 a& A  G% X4 C# \1 q# {    jz      SoftICE_detected
5 C! x5 U# V/ U, z) K; b
9 s. c) O6 O* N/ t( ?. c8 J* r3 hint41handler2 PROC
" M' c1 d& s1 ]9 u0 p# O    iret
+ T, A5 E9 o; O8 A  ~4 D+ K( W, Z, Dint41handler2 ENDP
" s3 W7 U7 N8 I7 S* _  S4 p+ }, T* c" s6 U7 P! `: C8 [0 A  Y8 I5 }: k
9 u. p  ?; R7 }
_________________________________________________________________________
6 C. G4 ^2 P% X1 i' J$ s" R4 f' Y9 d: n, B6 C/ m( @8 B7 i4 F

. K- A8 `0 K; ?; L( W2 u8 h9 E. cMethod 06
8 y. i4 |6 [. J" r+ Y% `=========$ `& n( T. E) p. n& S

' P: V) J' r- @
) M# F1 a4 v. n; P7 V! C  U2nd method similar to the preceding one but more difficult to detect:8 C4 H4 k8 L' O

6 ]  K+ P; c3 y  C
$ @7 `% l  ?5 q* ~0 _$ Hint41handler PROC( x5 A- A3 ^2 F' N4 k
    mov     cl,al
$ B! U4 U9 a; [% i" Q  _. t    iret
+ C" ]$ G9 i& Sint41handler ENDP
( M: \. g# h1 E0 s1 j$ u, k4 @; B# `. J# Z4 N

5 ?  [4 g; c& I$ V1 w! u    xor     ax,ax
+ Q0 \; l  G/ \: g    mov     es,ax
2 n6 L5 a! n7 |! `5 _    mov     bx, cs
9 N7 e5 G' A: f8 O    lea     dx, int41handler% l! {/ V# I' I
    xchg    dx, es:[41h*4]
0 p% h' N0 b* k' J8 ]    xchg    bx, es:[41h*4+2]# i' o+ ~# `0 y( g, j
    in      al, 40h) z! p* c; D" \. U& l0 a
    xor     cx,cx
' k3 U' n$ i# i7 }- j7 F& |# M! o+ W    int     41h
$ D6 t# |( o( A% M4 P6 w# E- f    xchg    dx, es:[41h*4], {: m! X$ l1 S6 N
    xchg    bx, es:[41h*4+2]# w8 [& z! O) F* b+ a
    cmp     cl,al
  ^+ I# j! t3 k/ p( _& j3 n2 E0 ]8 w    jnz     SoftICE_detected2 w1 G2 S* m0 G, V' Y/ _  S

! ?+ I) b# r4 Y" Z# z_________________________________________________________________________
1 l5 p9 ]6 r: j
( l# \8 @$ u& j* y- c% e) AMethod 07
7 W4 P5 y* P" H+ \=========
8 c  S4 K$ ~: A6 R
8 d7 x8 A: y  W) n- V2 |Method of detection of the WinICE handler in the int68h (V86)- C& G7 R1 z( N* m6 c
. y, B( s! b; g1 X
    mov     ah,43h
  p/ L2 b5 M; |& O9 x: y( \9 s5 ?    int     68h
. \! e( s5 K" `8 g    cmp     ax,0F386h- H) v1 t5 o5 n! h9 C- h' P* c5 d
    jz      SoftICE_Detected
" a2 M+ d) }9 \' Q4 w  Z2 [; w/ V; E: B( x+ r8 H# l( g5 g
: L3 q" U  u" ?: D
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit/ _/ C* C  G/ ?/ |8 N# @6 I' o
   app like this:
( ^% F' [* ~& g0 l5 I" g0 E0 W% v" j$ U; i+ V
   BPX exec_int if ax==68
8 p# E( r' C8 L   (function called is located at byte ptr [ebp+1Dh] and client eip is2 ?3 X4 M; a/ p- ~# H1 X$ X
   located at [ebp+48h] for 32Bit apps)
  u$ |, \/ o/ f! G% V* T& `: W8 j- u4 r0 D__________________________________________________________________________* f1 K0 W1 H! A+ H. C1 v+ x! K

4 _* X( h' p0 _* W% z1 a% R, s* c* K) c* E* D% p
Method 08
: z, {# ~" j: J/ o5 _5 R=========$ h2 N$ _$ ~2 J( n( U( e

/ N) D$ N9 v' j% J5 O( q# rIt is not a method of detection of SoftICE but a possibility to crash the
8 B( W% @, N8 P- _  F0 z; xsystem by intercepting int 01h and int 03h and redirecting them to another
! f" L& g6 i% g! C4 ~2 C9 ]2 V& Iroutine.9 l6 b- @" e& ~) k
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
" N7 ]& H5 x. b! Dto the new routine to execute (hangs computer...)8 r- U" l3 F4 b9 O3 v

5 I5 x3 X% a+ e; `4 M# w5 y0 d    mov     ah, 25h
( S: T- [5 z" A: U! Y    mov     al, Int_Number (01h or 03h)
9 N3 u* Q4 A7 c3 o; u    mov     dx, offset New_Int_Routine
1 H( r5 |1 X. a0 X  B$ E- R    int     21h
  J) W. S) [- O2 W) j" r/ ]* b
+ j% ?# t9 K. k2 W7 M& j__________________________________________________________________________6 |/ J9 i. |+ K% E

4 p' ]/ N) m" }/ FMethod 09& o* A# v3 w& R
=========, y3 R; h$ E3 S0 d
3 K1 G% ?6 I1 t% e# E
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
' \: W! Z! T/ e+ o% nperformed in ring0 (VxD or a ring3 app using the VxdCall).
2 N! F, b0 \9 n, KThe Get_DDB service is used to determine whether or not a VxD is installed- K- d# l; i2 l: P  ~4 t, L- B
for the specified device and returns a Device Description Block (in ecx) for: U( m. U0 m: ^4 z% X" j7 u
that device if it is installed.
3 l# g1 O. y1 l: Y, ?
, ^, w5 B4 X8 q7 w6 }   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
. i% Y# R" l+ P" e  a2 m   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)0 h" R% G% {. a& O3 D4 o/ f$ R$ R
   VMMCall Get_DDB
) k. i# ]# ]6 S; f% r   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed8 u6 ~6 Y4 L: p) ]6 i- |
9 r  H" q0 v, n- v6 g
Note as well that you can easily detect this method with SoftICE:
3 M' \4 q. K5 |4 [3 i& I   bpx Get_DDB if ax==0202 || ax==7a5fh; ^& B' O. a/ P' r9 \/ K7 H* }

& K  E5 I9 o* d( P( ^8 P9 W__________________________________________________________________________" f0 @; T! P' Z6 f
; A* |* F& b  M* u3 L7 p6 w
Method 10( b7 }# x9 b: q1 F' T. |5 n; S/ Y5 w
=========
) ^9 _& c- J8 y6 x: g  ?0 m3 ]' V4 J; N, O
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with& y9 z8 m. G9 ?* {/ K4 \
  SoftICE while the option is enable!!
- N) G$ T, I! P: B4 |1 o4 V
. ~: k9 |5 {+ Q/ g$ S5 ?+ Z9 x) WThis trick is very efficient:
5 g- ]! p. H% ^7 Z; i4 eby checking the Debug Registers, you can detect if SoftICE is loaded' J; f$ A; P& k; h+ ?8 X" h
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
& T! T! {% c1 j/ c" @# `: Tthere are some memory breakpoints set (dr0 to dr3) simply by reading their
' |) |; W) q! E# Dvalue (in ring0 only). Values can be manipulated and or changed as well
& n" C0 u7 m2 G( j(clearing BPMs for instance)& U& p% j" A- ^4 P# U- _
. I& P: U# ~. S0 g2 c5 r
__________________________________________________________________________
1 z2 P: g/ j8 v2 E5 s4 d! Z& t
. s& \2 L, q! cMethod 11, A' Z: G% N. ?- Y
=========/ k1 f" E% o8 n* ]
6 S4 [9 o7 b2 |+ }/ w- o/ p+ l
This method is most known as 'MeltICE' because it has been freely distributed
! g8 S; U" j. D* i1 h6 [& K3 mvia www.winfiles.com. However it was first used by NuMega people to allow
% c; r) k3 c+ d' b- j6 f5 Q% tSymbol Loader to check if SoftICE was active or not (the code is located4 f$ e* i7 T9 X1 K! Z2 C7 v
inside nmtrans.dll).: K5 \$ l9 v8 W5 H
7 i' f% N# _6 F; r* A
The way it works is very simple:2 U- j8 |. A2 h% F0 Y2 J
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
/ u  S  Z! z  N5 i( OWinNT) with the CreateFileA API.' \# p5 v7 l  }, G
8 o  l+ R# F$ M: m8 y' Q
Here is a sample (checking for 'SICE'):8 U/ \" T1 g& K0 s8 v) w7 _1 Q+ i
: `% b, |  l$ c# L% D6 n) V; x
BOOL IsSoftIce95Loaded()
% u& h' R6 N" L0 w, Y/ k$ V{3 }5 V- U( N0 q% v$ O
   HANDLE hFile;  3 N& v$ Y% Z3 O; B
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE," V+ z3 ~' M* i2 L9 ]
                      FILE_SHARE_READ | FILE_SHARE_WRITE,
( c( Z4 v# s4 q4 e: Z# p- c# X                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);9 Q/ N+ _# |0 O8 N: i: M
   if( hFile != INVALID_HANDLE_VALUE )
3 G- f* Q5 c' f* L# U# f   {& g, a" ~# p: C
      CloseHandle(hFile);
7 X7 D- {. G# {4 t6 b$ {- M2 Y      return TRUE;: s$ Y; [! Y3 J5 ^
   }8 n  t( P+ ?- D" I9 j
   return FALSE;6 k* L, \% U6 |1 n4 D
}
9 T* v" P1 W4 N3 Z( B0 m6 g1 E. W
4 M* n, U2 X' U7 H: z0 OAlthough this trick calls the CreateFileA function, don't even expect to be/ z. y1 w- f/ O4 O% C) ?4 u
able to intercept it by installing a IFS hook: it will not work, no way!% |" Z% n7 T) T" c6 J7 ~- u
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
8 n; V% I7 `0 M; D# rservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)4 V& X6 x( W  K& }4 M2 r
and then browse the DDB list until it find the VxD and its DDB_Control_Proc: N5 L! S& [+ o3 k' w
field.: b6 h0 G4 V+ |! k9 J4 D9 T
In fact, its purpose is not to load/unload VxDs but only to send a * E5 n: z, l& H5 B
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE), C6 b: i* {( w1 }( x
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
* P% P5 D' l' @" O  H3 qto load/unload a non-dynamically loadable driver such as SoftICE ;-).
- }+ l4 y" d" ^. @/ ^9 GIf the VxD is loaded, it will always clear eax and the Carry flag to allow/ x4 h! R/ k, e$ d
its handle to be opened and then, will be detected.& t1 t. L, B. q4 I  }9 S
You can check that simply by hooking Winice.exe control proc entry point
5 W, R* j5 r  |while running MeltICE.  ]6 f$ B/ y4 q; u  n" l

. e9 `; c8 u6 w( A& e+ f" H' V1 [+ M5 R- v, S$ v+ S7 E
  00401067:  push      00402025    ; \\.\SICE5 {4 B& Z" K7 L2 {2 g
  0040106C:  call      CreateFileA
/ T: z0 B" }( D7 S6 e  U  00401071:  cmp       eax,-001
7 J# V6 J% }: {4 J  H  00401074:  je        00401091
6 Q- Z9 g- l' p( O1 h' s8 ^2 E9 Q
5 l6 J# u* w- S) C/ Q/ ]' x
There could be hundreds of BPX you could use to detect this trick.
$ L6 ?( {/ b4 p, Q2 t8 H. Z-The most classical one is:
; f; [: v! r: \( O1 }7 ~7 N8 ?1 c  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||6 E$ }) L6 K+ `# z) d
    *(esp-&gt;4+4)=='NTIC'
+ L+ s) y) v) a
+ C) Q, B9 \9 d! [3 \- B3 F2 G-The most exotic ones (could be very slooooow :-(* Z0 S( P& p( Z3 V5 b) f
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  8 j+ ?9 F9 G8 r0 h. ^
     ;will break 3 times :-(6 e5 A! \/ n9 k' P

! N5 I5 h# d5 q* @# M-or (a bit) faster:
. C- ~' C- n2 Y& t2 h; X4 I   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')! v1 Y' G0 h' G2 [

1 K0 S5 j% N/ d- f" _6 ^" [   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  - j& ^+ l' A- `6 q4 @' N* G5 H& t
     ;will break 3 times :-() x6 M5 o/ u% w

/ Z0 l- [6 K2 {-Much faster:
1 b5 ?+ R# d, O0 V$ U6 `   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'. P0 E2 c& l6 |( E% \

" V& I% D4 e. r- f) ONote also that some programs (like AZPR3.00) use de old 16-bit _lopen0 k  w$ y9 Y% \. o0 Z) A0 K0 c8 [
function to do the same job:' C9 P" E  O0 c! Y6 j
) K+ P1 V, ^$ g( r: |/ X5 r& U, V
   push    00                        ; OF_READ! O: y: \% P- H$ q5 M8 I1 b. q5 W
   mov     eax,[00656634]            ; '\\.\SICE',0* p# ?) V6 P% D1 t8 T. `
   push    eax2 K  \& i& g1 d7 ^2 y; ~3 h% S
   call    KERNEL32!_lopen4 e# X5 }2 C  R
   inc     eax
! n' l) T7 g: |/ o4 Y8 n" L( h3 J* M; l   jnz     00650589                  ; detected& W0 n  O' G1 N1 y  g) m# Z" S3 v
   push    00                        ; OF_READ9 @$ C8 q+ d1 I, |
   mov     eax,[00656638]            ; '\\.\SICE'
. H5 v$ o6 l, f" V0 J+ X% c   push    eax
4 F  Y0 s3 [& f6 M   call    KERNEL32!_lopen+ B& J* b& V( y. n9 s8 ~. R
   inc     eax
, I: m/ g3 k* ]! F   jz      006505ae                  ; not detected
2 p) @- C* `. {0 x0 v
- N9 r  ]( O: ?7 [
( Z8 I, ~) G1 [6 f__________________________________________________________________________
2 B, I& b8 V1 [5 K5 o  D+ }; B& A5 b6 q3 n
Method 12
0 t  h" C# a( M# g* r+ n, F=========: ~5 I) m  g+ l" s7 {$ E) }

+ z; B) L4 M& b' D& L  |This trick is similar to int41h/4fh Debugger installation check (code 05
2 A* k, l+ ~4 O- @. h$ N&amp; 06) but very limited because it's only available for Win95/98 (not NT)' _: i( [. M2 l# ]6 m, J
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
( d3 F: G+ z) `2 j
/ h8 i+ x  U  y* `: r   push  0000004fh         ; function 4fh
0 }+ K+ O% G0 D& I8 t( o   push  002a002ah         ; high word specifies which VxD (VWIN32)9 w$ r0 A! |* V* I9 Y' T* E
                           ; low word specifies which service0 _7 I( n7 K7 j. V0 C# t
                             (VWIN32_Int41Dispatch)
$ s( ]8 t/ T) s. L" A4 w& Z   call  Kernel32!ORD_001  ; VxdCall) R0 I  ]3 k+ o8 f: T+ q' G
   cmp   ax, 0f386h        ; magic number returned by system debuggers
8 M4 o& `, E& }9 N2 S# n4 D/ V   jz    SoftICE_detected
+ \5 v7 [) N& V- h) N- J6 L, T1 Q6 T7 H2 `& V. Y6 T
Here again, several ways to detect it:, P/ U$ ]6 [, V9 d

: J4 U, _6 \& A! F; O+ R: v6 y    BPINT 41 if ax==4f
2 F* a' L/ v/ R5 p
; `" F! e$ c: k. X  T# r    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one7 T3 p- V1 [& B$ G' E  `

  D- A# z) q; ~( ]3 K. R    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
0 w6 ?! c# I1 A0 I) }- M+ V+ w& q2 T' z3 n3 x. V0 |( M
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!; e& m. `4 V3 ~3 r$ p2 ^
: I* D0 D  V0 \, A' @
__________________________________________________________________________
& O/ v! |. D2 T' B" `0 k+ H) I+ N. a5 _, g4 n
Method 13
6 t8 f) o6 u: M, ]! x- c$ G=========7 n0 g# M* j" T
; h( o) G5 \6 x/ P7 N, k0 ?9 b2 x
Not a real method of detection, but a good way to know if SoftICE is( }- e* q  `1 |. y2 R
installed on a computer and to locate its installation directory.( i  B6 Q+ m) u* j
It is used by few softs which access the following registry keys (usually #2) :
) n7 U( n& J7 K$ W0 }9 I+ C2 s2 l; i
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
$ b+ y9 X3 Y: i4 w/ n) s\Uninstall\SoftICE
; U. s  o- T( N/ r- z-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE' w7 Z) o; Q# r. s
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion. j( z" V  h/ T( `$ ?& y
\App Paths\Loader32.Exe, I# B# V% c/ }, f' r( O& [

# _- Z2 K# J* g, k( w& |& c/ q! w. `# M* w5 Z* U* X2 J; `
Note that some nasty apps could then erase all files from SoftICE directory5 @) Q& f: b. ]+ n8 N2 C
(I faced that once :-(
- \: l; _" ?6 K9 Q( v  H$ v6 E5 l
1 K: @( W5 _5 t* j' |8 X* m: KUseful breakpoint to detect it:. S# e5 x7 r" y3 y9 v

4 J, K  [5 t% g' o     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
6 W4 w7 q% ^; v) i3 |- N, S; @: Y* g2 y
__________________________________________________________________________3 p9 o) h6 e! I

+ k. X. b* P- `6 t0 l0 L' B' v3 j' O/ t# ~/ y, q* v$ R
Method 14   _- J- ^- c5 `
=========# ]  Z. I3 |* l; X

* |* |9 I/ X3 a% E2 `7 ^A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose5 L7 ?% k, m5 l! i# ]) _
is to determines whether a debugger is running on your system (ring0 only).
) O1 }. \$ e. q+ j
- G: q1 {" G3 ]; O   VMMCall Test_Debug_Installed
7 Z" }! Z! C$ r- w0 E8 _   je      not_installed
$ u5 ^0 N' M) U3 K* L4 O9 @  @6 D) X! B8 r2 }, v
This service just checks a flag.4 t5 H: @) T5 _  `7 J; C7 f4 ~
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部