About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
8 h9 i0 _( L$ ?<TBODY>8 m7 X7 M% s5 d% L
<TR>3 a8 t2 f4 h( o& [$ ]3 x) w
<TD><PRE>Method 01
7 K, t, A, G1 r7 m7 i+ o=========5 i  y, C: ^7 T, j6 n

0 X1 ]' O2 }3 Y7 B7 U4 \/ pThis method of detection of SoftICE (as well as the following one) is
' q3 @* _9 m, W1 W" Vused by the majority of packers/encryptors found on Internet.
( ?3 T# f$ V2 \- ^9 bIt seeks the signature of BoundsChecker in SoftICE( C8 {4 l8 S6 n) r

2 `, s; ?+ v* P5 m6 K, g5 g    mov     ebp, 04243484Bh        ; 'BCHK'; U4 G5 \% Z8 g! Y4 u1 x
    mov     ax, 04h7 u) \+ R- c% [$ {) S. K
    int     3       % I- R% r- a. d  ]* K  C* p+ h1 {" N
    cmp     al,4
1 R8 a9 n! n* x- U/ J9 {$ W  M    jnz     SoftICE_Detected
; D$ V  t* H) G. W* i5 d6 t
; r5 X# f: y9 A: [3 J___________________________________________________________________________
# V& Z' V' V0 H$ l. }8 d2 _) C, l3 g7 M5 K4 @" p) M
Method 02# M, C3 G! J" o. a% O
=========
: k# q0 B, K; b! o  s8 S$ y* x2 j# U; q/ ~4 p; T
Still a method very much used (perhaps the most frequent one).  It is used) K; r: P, q* V+ c- Y+ R. D5 B# f$ s/ }
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,, s) g) N/ d+ e7 c2 `8 O! ?: R
or execute SoftICE commands...
) k9 ^5 D* \. Q2 C( PIt is also used to crash SoftICE and to force it to execute any commands
$ V: l/ b9 @+ F) r# v(HBOOT...) :-((  ' m, e8 m4 G- F; t% F
. F/ ~$ N+ W5 v, Y4 ^5 N8 k
Here is a quick description:/ M- A! C5 n. n8 f
-AX = 0910h   (Display string in SIce windows)0 _) d& q0 l6 q
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)$ }1 {1 X. B# I1 O, p. H
-AX = 0912h   (Get breakpoint infos)# |9 Y9 U2 s( [9 h& {3 T
-AX = 0913h   (Set Sice breakpoints)( j$ n5 A# I1 }2 l9 f# k
-AX = 0914h   (Remove SIce breakoints)7 @0 [) ?4 E: C" |
& ~; j" w- Q. j# u. B4 V  [
Each time you'll meet this trick, you'll see:6 y" F3 _8 i4 q2 S' Q* J
-SI = 4647h
" V, H# g! h- h5 G" V-DI = 4A4Dh* |- v/ C3 s; U; m
Which are the 'magic values' used by SoftIce.
/ H/ w& p7 ^; Y" LFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
$ C: N0 O( Y  ?. z2 M8 J8 X2 Y
3 r$ w) D# v! Q1 X3 d" ^Here is one example from the file "Haspinst.exe" which is the dongle HASP
% ^6 @2 j1 T( w: `Envelope utility use to protect DOS applications:
+ O. k. L% o' H
; q+ x& s) m+ T' f1 u1 T
9 i0 |. Q' [5 m0 X/ x4C19:0095   MOV    AX,0911  ; execute command.
3 I1 ^' P4 _/ O/ c7 g& |$ U4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).. A- S, N  G- k5 L
4C19:009A   MOV    SI,4647  ; 1st magic value.4 D. f& Z' u! l2 g+ n4 V
4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
  Z1 o3 k- A, t+ y+ Y4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)  ]! F( m2 U  B  h. ?' {
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
3 S; @& _7 H3 W2 s1 |3 [4C19:00A4   INC    CX
4 I3 ^0 B$ Z& |4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute/ s% s  R! y9 V) ?/ _
4C19:00A8   JB     0095     ; 6 different commands.
! s1 V& H: l) C' K( Q; Z4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
% m  f; W9 l8 F3 Q4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
. u* H$ |0 B' N' b" ~
) g+ w1 T% }. PThe program will execute 6 different SIce commands located at ds:dx, which
5 j, F& [1 r1 i; y0 hare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
( F" A3 `) T9 Y) }
+ ~- H  G% S- E0 d" C% e* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded., s$ P, [9 L2 I3 U& I9 b8 z  f
___________________________________________________________________________
2 Y" P( Z: K1 o. Q. E( j# l/ \. }
( [1 E* z3 B% O# @& `# V0 }, z4 k  ~$ T
Method 039 X7 G8 s" p, V
=========2 u  I3 s; o; U5 {$ M4 j( N2 D
5 O- H; ~2 l: p* E) o7 k) r1 @
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h% |2 o. s% t0 Y) e. j
(API Get entry point)
, h  Y: B9 y/ ^+ _4 A9 }. m7 y        
# h4 e3 `4 A# {" a# o& o7 b' ~9 r7 [8 S9 L! w  z
    xor     di,di: |" S: N( U' q% C% `- Z  p/ y
    mov     es,di& z- T" u3 v3 |! u7 N
    mov     ax, 1684h      
& z8 v5 c$ ?( V8 j# n    mov     bx, 0202h       ; VxD ID of winice/ k6 s- H8 v$ u) O" X' a: s
    int     2Fh7 q5 |! I8 e7 N
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
5 s+ e" |3 a+ d4 g, m    add     ax, di
0 N) b! Y7 {! g# F6 v    test    ax,ax
  ]+ d+ `9 s' M5 ?/ E, P8 |$ {" i  n    jnz     SoftICE_Detected
9 ?* Y2 c; [! J9 V/ ?6 H) X1 D! A
) g2 D: A5 U: ^* h4 u) l___________________________________________________________________________
+ Z2 H! }# d' V# i- @! }5 ~0 A/ X' ?# u, T. P: S
Method 04& k* ]1 Z- e& D) ^/ x) ^. K, O
=========, Y: @% h4 Z& y$ Q$ I

' g. K9 C: w, ]/ iMethod identical to the preceding one except that it seeks the ID of SoftICE
+ @+ u! o2 s* _3 K4 NGFX VxD.  n0 @8 G) K7 Z0 O8 X
' _) ?3 ^! T% a. v5 v
    xor     di,di/ `' d3 b" B$ \4 }8 x( E9 t
    mov     es,di0 T' B/ K5 D! a+ s; y! O1 G
    mov     ax, 1684h      
: l! M  R  L4 l9 s# F$ G/ E3 u3 ]    mov     bx, 7a5Fh       ; VxD ID of SIWVID
6 B+ e# D8 P7 [6 a8 m7 j+ X: F    int     2fh" j  ]7 P. D3 t: Z
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
7 n  V& N7 R* o: p" |! j0 a    add     ax, di- ^$ ?7 H0 Y( o& X+ y0 l
    test    ax,ax
/ t/ e& e3 H5 j, Z    jnz     SoftICE_Detected
1 R' I! \6 Q% m' f% l2 g
/ w: ~  b* _$ E1 x  i( G__________________________________________________________________________
$ m& l( Z. {: A' G
0 X  n% G2 s2 ^2 E) F/ z. {! F0 w' U( o; ~
Method 05
* D9 o' _% l- t  i3 v/ ^=========8 i( G: C4 n7 X9 J5 ~3 R5 A
/ }' R0 h$ b! R) J+ H
Method seeking the 'magic number' 0F386h returned (in ax) by all system8 T3 |, p2 y; G5 l& S; w
debugger. It calls the int 41h, function 4Fh.+ ?1 C' t& F3 E9 y6 O% i
There are several alternatives.  5 v  ]# N' I# y0 g( F
- M) z0 K) f  H' y+ D3 ^2 r% F
The following one is the simplest:( h$ `4 p% b! E5 f. b1 z
9 n. T7 p. F8 P3 G
    mov     ax,4fh7 Z1 b- I" N  @. Q4 G
    int     41h
- W7 i* E3 H; y$ h: x# P$ t    cmp     ax, 0F386
+ R$ G) |0 ?8 _    jz      SoftICE_detected* [+ V% m& L9 U1 W
4 ]% T/ t1 a0 Z9 @

) E' m! `2 Y0 e" J( ~8 b; M) z0 ]  TNext method as well as the following one are 2 examples from Stone's
  ?6 x: d2 J6 Q  }) X2 |8 F"stn-wid.zip" (www.cracking.net):
/ V$ o' e; R5 U2 Y0 R) H
( `) U6 ?: b8 h6 g# [6 f' s- H    mov     bx, cs- z7 c+ v8 {6 Y4 e" M
    lea     dx, int41handler21 ~; S# A6 q$ M
    xchg    dx, es:[41h*4]
8 e7 I6 E6 u, Z  ?  }; o. J9 s    xchg    bx, es:[41h*4+2]2 A0 p6 y+ Q! B% S' E$ R" k: W
    mov     ax,4fh& w& a/ S5 y  E' `
    int     41h$ W1 T" R0 @( W/ a3 R8 ?
    xchg    dx, es:[41h*4]% r3 F& {. P' i& z2 V- P! H
    xchg    bx, es:[41h*4+2]+ f! D* s# v/ F2 l7 J: U1 i( u" s
    cmp     ax, 0f386h
8 H1 V% Q; {- U    jz      SoftICE_detected
- i( ^8 s( e6 D/ u  O: r, A# g- Q& \1 V7 v7 Q
int41handler2 PROC8 y5 M9 ~3 t) N8 w! p' {
    iret
% T9 N2 q( g* w! @, `, z0 p4 q: f9 hint41handler2 ENDP* \; @7 F0 m) [- l9 P8 s
2 C" G$ L$ _0 _2 w8 O  M

2 ~& P) Y7 m7 m5 P9 s3 d3 @_________________________________________________________________________
2 U- v7 a( @3 \3 F8 Q- w
" Y* P% F2 X/ D( \8 R- E
5 `. x6 A/ [1 A/ R7 O& hMethod 06* _1 j& [" F" v; l& f; E* b
=========
) j+ K; R* M% A0 C5 b0 }/ r+ b; l$ W
0 A* M) w* T6 Z6 H0 C0 Y! L0 a, u1 g( _8 E2 Q+ D
2nd method similar to the preceding one but more difficult to detect:
, Q& [9 S$ C5 a4 t
* d# R8 R, a- _# F( q$ [) }* D) t
, B9 }% z0 t# d, n+ x% Xint41handler PROC
, a2 e6 j  a9 @2 M8 w+ d7 d5 V" s9 W' F" u    mov     cl,al* S8 C' v0 P& z( R; a: a
    iret) _: ?, n  n) t& m/ v( P5 Y  G
int41handler ENDP# B, H: m" e. r8 E

1 B% _: E! j# S. O2 i  K( S" q: w- j- R) V+ L# ^/ \
    xor     ax,ax
: D! v& I* R: x* b6 Z- c    mov     es,ax
8 Y+ Q1 M! m; e. N/ S3 t+ K& T    mov     bx, cs+ Y$ h+ [0 e1 S# X, E6 a/ M
    lea     dx, int41handler: s6 m5 ]: [% C" C1 t  n
    xchg    dx, es:[41h*4]
, r, E, B2 L" m' H    xchg    bx, es:[41h*4+2]( r: ?! L  Z" X  }4 i% r
    in      al, 40h( ]# p* u$ n( B! m/ w! v( h/ ^
    xor     cx,cx
% f2 d- J3 m1 H) `    int     41h$ k" g- Q1 H4 ]* C3 w$ o7 b# z
    xchg    dx, es:[41h*4]( w- |3 S4 M# M4 T1 ]
    xchg    bx, es:[41h*4+2]
$ g. y; T/ ?; e. r1 D! C0 S    cmp     cl,al+ M# ]& K* Z4 h) Z6 c
    jnz     SoftICE_detected. I* ]+ o% P6 _. I

4 J. }: g8 Z  }( a" k7 @! |0 h: e_________________________________________________________________________
8 p# X7 D% k2 h( D2 P! k7 @7 [+ O! i) U
Method 07. J0 e' n8 {* O, I0 s" q; L
=========
4 f8 p0 u7 u; T2 z. Z: E. ^
- j: q* L* d1 B) q# ^Method of detection of the WinICE handler in the int68h (V86), p# z+ @8 c5 Z$ B- P
9 j7 C2 z, _- d: V& w0 `" R' F) ]
    mov     ah,43h
2 _1 i% C# i" H  H4 i+ m$ T    int     68h) n% M) I0 V! ^6 w/ o/ H; p
    cmp     ax,0F386h
1 a3 h$ h( z# M+ d4 y    jz      SoftICE_Detected2 U- {: X  Q! w& i

9 C: P/ X0 }6 c; r
4 W! Y' p9 U- x: w' l' ]" g' X4 t$ H=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit9 ], @6 b" \! }( L2 @
   app like this:
4 Y3 O& Y8 I+ e0 f7 T8 S( f3 _1 k5 [0 b
   BPX exec_int if ax==689 g& X7 q7 c5 _% a' V/ {
   (function called is located at byte ptr [ebp+1Dh] and client eip is1 K" W+ Q% F/ Q# t  u
   located at [ebp+48h] for 32Bit apps); A& [, h( _; e. M+ l
__________________________________________________________________________& F) H9 I. P# w7 _0 \

% e( ]/ l$ N4 Q1 ]& x. s
0 l2 w1 P, _$ R- C, xMethod 08: f1 Y8 I6 \/ }+ o
=========  H" q, I. g' Y

$ d( P) _8 G3 G9 Z! y' F7 F" MIt is not a method of detection of SoftICE but a possibility to crash the
5 p4 ~/ M# J0 h2 v1 K3 s" v+ usystem by intercepting int 01h and int 03h and redirecting them to another( T. F: m1 R6 q: f
routine.
# N- `, D) H# Q. K2 M% XIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
. L  b$ V4 r! O4 y, D& fto the new routine to execute (hangs computer...). v9 \9 y# W+ K% E

5 R. Z0 n: S7 _9 P" I9 X    mov     ah, 25h5 J0 q* ]; Y5 T2 I7 U3 a4 ?- s
    mov     al, Int_Number (01h or 03h)
0 E7 x/ ~5 h; ]6 A) L4 ]% O    mov     dx, offset New_Int_Routine! \# ~/ L$ m4 ?
    int     21h
$ p  z( s1 D" Z6 O3 x) F6 d5 l3 P# b2 u# R
__________________________________________________________________________
8 `/ D8 G( S2 c# a. I2 h/ [& M. w* G0 o& H& H: {
Method 09
/ N; p6 `6 K0 ?- [" |* v7 E=========- @' [9 t- i# M: r& t+ f

* {' G, a% g0 H3 Z, M5 z6 iThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
: b2 }# I2 C1 fperformed in ring0 (VxD or a ring3 app using the VxdCall).& M1 t1 a- ]; D
The Get_DDB service is used to determine whether or not a VxD is installed% P) T6 Q$ [5 M5 m/ z
for the specified device and returns a Device Description Block (in ecx) for
- @* ~+ Y% u; C( @$ |that device if it is installed.% s: K8 L5 b5 F3 {9 k& E* Y1 E( {, b
! K9 q( ?. Y" c& O; U3 a6 K- w
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID& K, ^; ]. x, @1 P/ o
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)1 E- C: ~1 [; {0 }' T
   VMMCall Get_DDB) }& c& u: v$ e# `  |
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed6 {# `! {' c7 u

: ]4 k3 i" F5 qNote as well that you can easily detect this method with SoftICE:8 d7 W/ C, h" H) V9 s+ U
   bpx Get_DDB if ax==0202 || ax==7a5fh
8 Q0 k; P' E1 R& H
1 ^8 J% a" R, `/ O! ?__________________________________________________________________________+ x1 L$ G0 ?& v6 @0 j1 o, t
5 o2 I: ?) i) @
Method 102 p1 e& T9 l; N# z7 K5 N
=========; l8 W) j8 @! X% ?
- k" w% \2 d' v, T+ b- I' a! {0 t
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
: T) V* q: T- I9 O$ x: D- U  SoftICE while the option is enable!!! p  [* Q" U5 d  u; x* o

1 G) m3 W: x. D! R; V7 ^$ ZThis trick is very efficient:2 N9 _7 Z) k. G- t
by checking the Debug Registers, you can detect if SoftICE is loaded
) H3 V; O+ W- @& u; p* \(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
$ D9 i1 {1 ^6 y; A  ythere are some memory breakpoints set (dr0 to dr3) simply by reading their
, K9 m4 S+ y# ~  f. Yvalue (in ring0 only). Values can be manipulated and or changed as well5 K( K; C& I4 [: h  e
(clearing BPMs for instance)& x$ p1 X9 z( E* m' Y7 Q

7 @! r: r' G% s* [9 ^. |__________________________________________________________________________2 @' F, W% d/ U+ i

" M3 q, {7 O- xMethod 11
4 T  c1 |" [$ N& E& g: Q' v8 x=========
# [7 B# I' E( e. s) _  x$ V8 ~
- o3 i: |0 P* c: }. ~& D7 UThis method is most known as 'MeltICE' because it has been freely distributed
, |& f- I( i, l: C1 m4 z- pvia www.winfiles.com. However it was first used by NuMega people to allow+ p. i% n0 D+ s3 `* \5 w5 l+ \
Symbol Loader to check if SoftICE was active or not (the code is located
% C# P, f$ s$ _* k# Pinside nmtrans.dll).
3 G0 D# a# E8 l9 Z1 L2 X, M* q
* W6 ]# ?- w+ J* T# r4 ^  PThe way it works is very simple:* Z( c- L* U0 G( ^6 M
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for9 y# F4 E$ g6 C9 V$ F
WinNT) with the CreateFileA API.# n- t$ j) i/ ~4 g$ V2 z; J

' o" s* @9 F8 A' S6 s$ ZHere is a sample (checking for 'SICE'):/ X1 b& q( r! Y; U
( t3 N0 K( Z' E+ ^/ a
BOOL IsSoftIce95Loaded()
  X1 f0 T, h& e0 e{
0 P0 K+ |. i' [( n5 S; U; R   HANDLE hFile;  
, v6 X" I% s: G: ]3 u8 A( b   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
" `6 S- F# W  S. _$ N                      FILE_SHARE_READ | FILE_SHARE_WRITE,
* ~2 @) p8 \, {  A( P                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
+ x2 t: _+ @$ \   if( hFile != INVALID_HANDLE_VALUE ). Q4 ^. z( h# p: R2 b9 T
   {: @2 g1 m& Z  m
      CloseHandle(hFile);9 R- P$ G% ]1 B+ A
      return TRUE;
6 W8 G2 A& Q. b" g   }
" G) G9 B! \% n8 l2 i4 V   return FALSE;- C, ?) p, w' q
}- H+ y( A% P5 F$ Z$ q5 a

2 g/ C) H# |- n8 i( [Although this trick calls the CreateFileA function, don't even expect to be* V- ?: u6 w( v+ s, Y% w! C# l
able to intercept it by installing a IFS hook: it will not work, no way!
& r) b( N. U. F- `" pIn fact, after the call to CreateFileA it will get through VWIN32 0x001F. R# m: o% M9 K( F2 Q
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)' t# J4 D/ a. B$ q) q  B/ f5 u( m) h
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
( b* w9 p- ^7 \2 _# N" `7 kfield.; q) Q/ G$ w/ A) t
In fact, its purpose is not to load/unload VxDs but only to send a 4 l' [5 {4 V9 ~0 s* Q$ Z
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
- C1 A- G; H0 ato the VxD Control_Dispatch proc (how the hell a shareware soft could try6 X6 h2 t- g* t# ]) ^
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
# g% [. G' z8 A! G3 E, V* bIf the VxD is loaded, it will always clear eax and the Carry flag to allow# b" N8 |! B1 f* H- K, f
its handle to be opened and then, will be detected.
4 [: B6 p$ g9 m/ q4 w. u# y( }2 \7 EYou can check that simply by hooking Winice.exe control proc entry point8 w0 D4 j* b7 Q7 [
while running MeltICE.6 e% Y$ w, p7 [$ `6 S7 \# x
1 U+ o! G& N/ O& g+ e
! B, _. E! Z7 r: I; b5 ]
  00401067:  push      00402025    ; \\.\SICE1 ~0 k# g  O: |2 {( K3 e" E! P
  0040106C:  call      CreateFileA
0 U" D, h2 x, C  00401071:  cmp       eax,-001
( B; ~+ {" y# B' G/ g- ~  00401074:  je        004010919 ?% F5 P7 e& s3 l+ Z& r( |
2 c  W  H) P7 v+ ~5 R* T9 s" S
( c5 c. \$ ?7 _% N
There could be hundreds of BPX you could use to detect this trick.5 O( k7 y% D* x0 R% Q' b3 X
-The most classical one is:
/ X# T% @0 Q: K& v  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
% h) T0 l4 a- N+ Y    *(esp-&gt;4+4)=='NTIC'
- K! v4 u! E) E# t6 g9 g, j
6 g2 k5 o" G( I# h. e-The most exotic ones (could be very slooooow :-(
& e, h, z1 u2 m* Q% K   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
, ^1 f0 m* b2 I     ;will break 3 times :-(
1 @" b: p, u# E. [3 a* I' D2 Z7 e, K9 I' O
-or (a bit) faster: - t0 R9 b) J$ s# L: D2 B' e' J6 F
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')  M' R; s2 U' M) o: S, P
4 w8 B5 ~" B% R
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  - [4 l* _, S' \) g/ R  Z( }* T0 T
     ;will break 3 times :-(
; v; I+ d8 u5 D% t( I7 I: V; R3 o
. u* r4 ^8 r$ C* G-Much faster:+ t# j  i9 G$ _4 b' y
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'- r/ b9 c9 V4 A! J/ q+ c' M7 Y

3 N5 o0 l5 a- P8 f( RNote also that some programs (like AZPR3.00) use de old 16-bit _lopen1 k' i4 D1 J3 u4 L0 ]% a% d! O) j
function to do the same job:# J, m$ W4 W' H! S7 F' b0 L

# I* O* ^, a2 }' ~" p. z: H9 E! D   push    00                        ; OF_READ) `, F  k9 u7 j; ]7 d7 S
   mov     eax,[00656634]            ; '\\.\SICE',0
0 V* F8 A4 F6 e2 x5 a# E   push    eax( ?: a. p+ i, ?9 e0 v
   call    KERNEL32!_lopen1 Q6 B) d$ t8 ~
   inc     eax7 q# ~- Z: @) B2 q4 l
   jnz     00650589                  ; detected
/ P$ u4 g/ D5 u9 U9 c% G   push    00                        ; OF_READ
) G0 E' h' Y; K- |* E   mov     eax,[00656638]            ; '\\.\SICE'
2 C: V# M- \& y9 N   push    eax8 t$ V8 m9 t/ _# C0 S" Q: a
   call    KERNEL32!_lopen9 ~  m! E: i' B6 ?5 _* j  x2 Y/ C
   inc     eax# B& @7 I0 F" b  r4 j1 i/ P2 {( n: A
   jz      006505ae                  ; not detected
% A/ H5 X/ I5 R6 W, \) ?/ `& Z. x: Y
# T) m) b- X2 d: _. F  S2 H8 ~" k3 E
__________________________________________________________________________9 p- ~5 c* c6 z4 J/ r( l

7 z8 E/ ]! x. T5 m! s3 @7 n' oMethod 12
" }# b& J% V$ ]9 z=========
; A: @0 o5 `* |3 [( d' V; `4 X/ e, [" ?5 k5 P) m3 V# U
This trick is similar to int41h/4fh Debugger installation check (code 05. E0 u$ _+ ^0 x) G
&amp; 06) but very limited because it's only available for Win95/98 (not NT)
4 E2 A8 I: Q2 d1 i1 q1 o" B9 a# `& j% J' Fas it uses the VxDCall backdoor. This detection was found in Bleem Demo.
  j7 [7 A8 @" q/ S3 ~! }. c
4 A) F: c+ t, P2 `) X' F5 ^2 l   push  0000004fh         ; function 4fh0 u! r" m5 L/ A8 H! g2 H0 V' {
   push  002a002ah         ; high word specifies which VxD (VWIN32)  D0 j4 B  s& ]6 s
                           ; low word specifies which service- M- x; y; u2 f1 @
                             (VWIN32_Int41Dispatch)
5 o2 ^# _: p" j: |   call  Kernel32!ORD_001  ; VxdCall
  {4 o! z1 k% Z6 c1 u1 t. y. M   cmp   ax, 0f386h        ; magic number returned by system debuggers* A0 i* Q: l) ^! U0 K  x
   jz    SoftICE_detected
  n+ Z& r2 x- V1 L+ A! R  b  a- F
0 l; w& T7 d* v5 zHere again, several ways to detect it:( ?0 @& z; T, [6 _0 G8 ]6 R2 ]
3 E% Z7 Q* n. x, t* z3 |
    BPINT 41 if ax==4f
6 M5 U/ b! z- q
( S9 x1 h: K, o! k$ i2 W    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
2 J% m. v3 J+ N5 L. \+ P; R8 T1 L
! B  r! q; s" }+ ~0 B& n6 \. T. e    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
. d/ Y& }. T# ^/ Y% p* O
% U: w. _6 V9 x    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
) {5 `. m: a* ]% i+ O0 a: O  `8 Z* H5 b* b4 x0 R
__________________________________________________________________________
3 i; e& Z6 H5 U7 w3 a3 T9 a% _- L6 D; F! W6 ~
Method 132 J1 Z: E" y& `" z  w0 M9 j7 R+ {! y
=========
$ q  i; W, o6 }" N
2 \* E9 G- n  T& TNot a real method of detection, but a good way to know if SoftICE is* F6 j1 V9 g  z2 u8 \
installed on a computer and to locate its installation directory.
% J$ @$ t' L  n) o. x1 _It is used by few softs which access the following registry keys (usually #2) :& `  U- a" r3 i

# M5 q+ ^0 T$ p: I: w-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion6 U4 a% g6 M' y3 a) Z2 n
\Uninstall\SoftICE0 e/ j$ Z  R& b2 O
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE; W! l5 C+ E- E/ Z6 T# w. h
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion6 Q3 B  G. F2 t. J
\App Paths\Loader32.Exe
5 _8 n% F2 ~% o$ ?
1 E# C# @/ r6 j, ?2 P  c) W2 ]7 \3 s
/ C% X+ k9 ^; ?6 s9 {Note that some nasty apps could then erase all files from SoftICE directory
& @' W4 x' B: c. Q2 w(I faced that once :-(9 f  Z, z: L# u! k& S: L( S

: z7 R/ H/ @0 s7 N# K5 x- sUseful breakpoint to detect it:
0 B* |4 d$ S- M2 H! e0 K* k
1 [- L# u# N1 `     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
  j4 e' ]7 B0 g3 J7 k  r1 _2 U# ^9 @% {6 {; a& j/ X/ h7 L& l
__________________________________________________________________________0 i2 E+ A6 `6 X- p, l2 t
' j. G  Z: r0 u" a! v& ]& e
( N, R( G) x( I& Q0 x1 L0 r- {9 C: w
Method 14
9 D1 ^2 D6 y7 I! ~8 D=========# J$ v% u8 @4 T2 a( F
$ o& x  G& ~: y3 c6 {- r6 }, [' n. R- r
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose/ T, ?- l2 M5 e# ?4 b7 E' C5 o
is to determines whether a debugger is running on your system (ring0 only).
0 ?1 j( K) s5 I# V- R  f1 D0 w) y
   VMMCall Test_Debug_Installed+ [0 T- E2 F# H
   je      not_installed$ o, G$ ?; [! p% v

0 F: q3 T0 n9 s) s! Y: u/ v6 GThis service just checks a flag.
# G- \' ^: E" f% A& q</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部