About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>2 H9 @: ]- w  o' [# j( r
<TBODY>
* Z# q4 D, l& n, q' [- ~<TR>- w( ]  W8 ?" G5 m8 }8 t
<TD><PRE>Method 01 8 t+ x" C7 E* E& m6 w
=========
  o1 S' f0 t+ U+ `" n
- v5 P1 M5 b2 p. Q4 N8 V/ s" [2 dThis method of detection of SoftICE (as well as the following one) is
( Q2 ?# F8 H! sused by the majority of packers/encryptors found on Internet.
4 O% B% b  j3 Y, aIt seeks the signature of BoundsChecker in SoftICE
& s0 c' p1 @7 n$ Y* @$ }5 i  `8 Q- ~/ n" G# h- l& ]/ U! Q! [
    mov     ebp, 04243484Bh        ; 'BCHK'6 s- z7 p3 v& ]/ c, O9 P- C
    mov     ax, 04h
) x+ h# `+ p! u/ t; Y* M    int     3      
* Y4 F; x( q  }$ M( y% w, k+ r    cmp     al,4. D# m* z* ~# P# U, G
    jnz     SoftICE_Detected
) N: R+ c! z3 \2 s- @( I3 F
2 @! e+ x6 `" N  X___________________________________________________________________________
/ S, t: r. e& y, P" X  u$ }' t: T/ w. b$ J' c/ w
Method 02  M  s. E4 ]) [  J: P2 [
=========9 D* y( r1 b- P- q$ p
. L, @' I+ I: a2 c" a
Still a method very much used (perhaps the most frequent one).  It is used
7 m% I, X+ C. C. |8 Vto get SoftICE 'Back Door commands' which gives infos on Breakpoints,
: ~9 }: d( n) ?& Uor execute SoftICE commands...; \( n0 Q# k8 H2 T
It is also used to crash SoftICE and to force it to execute any commands
' S5 J% S$ S( m1 B) P6 F, x  @0 G(HBOOT...) :-((  
' g# A  e7 g7 W0 P) j# H9 ]* B1 a7 Z; w
Here is a quick description:+ V" P+ K9 d( h8 D2 b. }- l
-AX = 0910h   (Display string in SIce windows)% b, q# j" N$ H, E# V. T+ r
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
7 Y/ _' @  M. _/ ]" q9 q-AX = 0912h   (Get breakpoint infos)0 E0 ~6 ^. v! }3 b: G$ W
-AX = 0913h   (Set Sice breakpoints)9 u9 C8 K7 F. p$ I$ i% ]
-AX = 0914h   (Remove SIce breakoints)# ?# B0 m) R: @; T6 i4 [

: E$ @* o0 R- Y) r% wEach time you'll meet this trick, you'll see:' l6 I5 }1 Z, D
-SI = 4647h( K- n, W( Z4 Y( {: i' W. W6 n
-DI = 4A4Dh) ^* R2 z1 V# ?1 T
Which are the 'magic values' used by SoftIce.( B& U8 W! e( B% c* E3 P5 T
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
  k7 s9 `' @7 _  [" p0 c' r4 J; ^, L; ]) J7 A. }8 X2 k. Y
Here is one example from the file "Haspinst.exe" which is the dongle HASP) e9 Y& G8 o) s! ?! K
Envelope utility use to protect DOS applications:
( v" Q. p: ~* D$ w, X. ?2 u5 O1 `9 q$ S4 Y* ]/ K8 d

" |8 S  N) e4 ?, \& s1 O4C19:0095   MOV    AX,0911  ; execute command.
: M: T! V; p8 ^  Q1 U8 _4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).  ^+ s3 @; O. V% G9 [% z5 q+ B
4C19:009A   MOV    SI,4647  ; 1st magic value.
/ r' f) p+ z0 ~7 Y: K4 m4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
7 R! |" w- e4 s7 ?4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)9 @( X3 B) U5 A) \
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
7 i2 w2 Y" ~+ o- P5 |, E' g4C19:00A4   INC    CX- w9 o$ e( w) Z) |# H+ l$ I5 _: u% ^
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
: h% x$ N4 I. D0 h! l' u$ C" M4C19:00A8   JB     0095     ; 6 different commands.: M! G1 N9 N! M3 p% v
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.; A9 u/ P& g4 w% ]% }9 @0 J6 w& |2 K# \
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)" v& D( j% k! u: n( |3 j' `4 O: E# M4 q
2 v' m) v9 @2 n5 s2 g
The program will execute 6 different SIce commands located at ds:dx, which
7 L( U; K9 a& Sare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
) N. |5 z0 Y' r) v6 {# x8 `9 ?2 x. Z. Y# T$ f
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
' b3 L. B7 ?; G9 b___________________________________________________________________________
/ T+ A; M6 L( B6 o- a& ~$ ?2 S+ j8 g: l( }/ v6 ~

5 x( V- t- f$ ]* m! l. P4 QMethod 03
! x4 b: f% m& U  m=========
  R. T; L) c- l3 z6 Q* T. X
' j( _4 a9 k+ v( zLess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
* J+ b: V1 D3 F0 f/ }(API Get entry point)
, L9 s$ C  z# f- `        9 M: N9 b; m" O0 V$ A5 a3 I% o
% H) x9 z, L) H; {
    xor     di,di
9 X- m* @* o9 [( L    mov     es,di
' u# y: _" X9 y+ V+ o; i1 l    mov     ax, 1684h      
' p- |- B5 `6 ]& I  ~    mov     bx, 0202h       ; VxD ID of winice
* _2 i, I$ w, n% P7 t    int     2Fh" ^0 a9 G2 Y4 F+ d# r1 c. |
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
1 K6 Q1 G$ x# g& H6 x( h2 ]    add     ax, di- W9 B6 H* F  l( {; K
    test    ax,ax( M' g, D2 \( L1 {0 g
    jnz     SoftICE_Detected. K% ^) }$ Q' z* R" p- }

" Z% _6 V5 P: k% k4 }! X) ]___________________________________________________________________________
  m' C( O/ [8 x
& |6 Z' W+ a7 l4 d, S" wMethod 047 l4 Q: O2 S3 R" R, A
=========% I* \, T  A/ R. S6 d# v

5 k+ D3 p0 `9 y( H9 a! p! lMethod identical to the preceding one except that it seeks the ID of SoftICE
# F0 m& M$ {3 eGFX VxD.
, K& s3 ]* F0 |6 _1 r" ?' h5 _+ o* Q% A9 w1 l7 A
    xor     di,di, k8 v8 _; v' o$ t# l7 K0 Y, b
    mov     es,di
: ]( w) E/ e8 C6 `+ I    mov     ax, 1684h       : R) B7 E! l3 W2 Y; P
    mov     bx, 7a5Fh       ; VxD ID of SIWVID
! K/ Q  i; G, @- u9 x- I  X    int     2fh; m9 X9 U; k* M$ b
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
5 Y+ m/ `* D6 ~0 |    add     ax, di% `" o# v1 R6 q0 _+ e  [
    test    ax,ax
5 E8 Q0 M; r% Y    jnz     SoftICE_Detected
5 z" C! I4 G! |- |! i; a% {/ e" S9 ?" V9 F
__________________________________________________________________________" f. n( b# h! u, I
, t! t& [; S6 ^$ U; ]! H1 b

1 y' A* @8 a" LMethod 05
9 G0 ^4 v2 q, C# {- A8 |* q=========2 T$ W4 D1 s* V7 t& T7 F7 J
# Q* M# Z* G1 U( f! m6 g8 }3 _
Method seeking the 'magic number' 0F386h returned (in ax) by all system
9 W( ~) N- o' u1 C- Xdebugger. It calls the int 41h, function 4Fh.
' _* J6 A$ ?& a3 RThere are several alternatives.  
4 R( v/ W' V' `) ^# L( ~. o. Y' }& x* x- Q
The following one is the simplest:  f: q! T2 w* j7 R* k
2 X! k! D0 X8 g; z
    mov     ax,4fh$ Z: }1 ~' Q  X
    int     41h" {4 K. v0 _# n+ t3 X
    cmp     ax, 0F386
, i, D) a2 F, n    jz      SoftICE_detected
% J- J  X: _, {" m, L# G8 R# b% |0 x  z

$ K  h1 ~5 }- a2 m" r# mNext method as well as the following one are 2 examples from Stone's 5 r2 m* A3 W) n6 S; L, f
"stn-wid.zip" (www.cracking.net):( A+ ~0 d3 U6 S; Z# J7 s4 A; [; t

" `/ z) D: i+ w' j: `    mov     bx, cs
2 l' P6 Y5 v9 K( T+ R    lea     dx, int41handler2
+ P; s; ~9 _- a% h1 \# l    xchg    dx, es:[41h*4]8 ]0 `; f0 w7 N) n4 K  u
    xchg    bx, es:[41h*4+2]
  W; A# A$ j3 W% B. G; Q4 f    mov     ax,4fh/ g# ^+ y8 X! i: A3 X
    int     41h
* J0 }: B( O6 K8 z    xchg    dx, es:[41h*4], ]8 X4 P$ c+ W$ Z2 S0 o
    xchg    bx, es:[41h*4+2]* R3 Q& h8 C2 y/ ?3 ^( L, \
    cmp     ax, 0f386h  a$ E7 {3 h7 T5 W4 u0 @$ ^9 c
    jz      SoftICE_detected
6 R$ @9 n3 X# a8 y1 _& s6 @: n% c! V1 o: R
int41handler2 PROC. X* x' q7 W! ~, n) f% p
    iret
* A) ~$ T; A* bint41handler2 ENDP0 j  ^8 A/ u3 [! n
. g3 e' v  x% E) n( F2 R
  y" ^! A, Q5 G. Z2 {- L  g
_________________________________________________________________________
* ?9 k+ U+ i( e2 r* E- x$ E( W9 T- D. \8 w

5 f7 X2 S; o, d& Y. gMethod 06) m; a6 E% n) Y( y6 o( ?  {
=========1 r, v8 v) y; U

! O* j# F8 [" d% v, Z  x1 H* X& d4 |9 e- h0 p- o
2nd method similar to the preceding one but more difficult to detect:
( ^& X! M' k" i, D" p9 S
# G1 |: ~# F4 V& F& P+ ?) m' j# H8 @4 y4 o) Y
int41handler PROC3 ?& _7 u: w4 \1 V! ]7 y! [
    mov     cl,al
+ N8 @7 a5 Y1 P  c3 v6 I    iret
9 i8 Z* C$ s! x% ?6 d: jint41handler ENDP
* x* a7 Z* s" ?, E, A: y- m7 V6 |% L+ H* ^! h8 w) P0 {
% @+ b0 p$ U$ E9 Q, K2 i
    xor     ax,ax8 ]$ I* L' D; q6 k+ |
    mov     es,ax3 f3 B' w/ e! w$ T0 H# I! {
    mov     bx, cs: d8 P! l- o  y/ k8 j) n( J5 T9 i
    lea     dx, int41handler1 I3 `& A- X) N9 t! Q
    xchg    dx, es:[41h*4]$ r" Y( e$ p3 ?; x# M7 g% ]2 B
    xchg    bx, es:[41h*4+2]
4 y% n$ D6 z* }( Q! n    in      al, 40h
1 m# J+ ]- ~) C! g3 u    xor     cx,cx% l" L* \& b5 h+ w2 I4 C# y/ E
    int     41h# d: d3 q( E4 M! ^7 k5 v- \
    xchg    dx, es:[41h*4]2 S" L2 M+ x. L' R" A
    xchg    bx, es:[41h*4+2]" w/ Y# D# [2 B0 R8 `8 P# S
    cmp     cl,al
8 N2 l3 F/ B* j8 A2 f2 m" w" A    jnz     SoftICE_detected: I; j0 _8 b; e5 b% k- ^! N  u# c- }

8 }% d& D. A' F_________________________________________________________________________' ]) u8 N" ~" s' U1 k% ]' X
; g  C9 e$ v3 q- V/ _
Method 07
- i: L4 O3 d& v: y=========
$ i. z9 `! }4 p) V- B2 P1 J! a/ B3 A" b9 F7 C7 p( Z# u+ c: @) _
Method of detection of the WinICE handler in the int68h (V86)
! Q0 Q- P! |& s# I
) V4 |. B8 `: s    mov     ah,43h
, \$ ^+ N) _  ^' k$ X1 j. Q/ }, n" w    int     68h$ L1 l6 u/ d% ~
    cmp     ax,0F386h
* r9 r% G- A  @) K. O    jz      SoftICE_Detected, R& r) w' i. ]+ E+ ~+ W. v4 _
- \* i8 i& V( C# w' e& N

: a9 ^) K& G8 w- D5 p- H=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
6 q0 d! n0 v/ E) ]/ P   app like this:2 H* F! V8 E% F. _( R( ]
4 ~+ ^; J+ T9 D1 m* M+ `* [3 t
   BPX exec_int if ax==68' L# l! G& ^; j! Q2 J1 V
   (function called is located at byte ptr [ebp+1Dh] and client eip is
; I( W- O# D+ y& O  ~5 b) U+ W. j   located at [ebp+48h] for 32Bit apps)
) M) ^/ A9 G7 t__________________________________________________________________________
5 D* ~) Z8 d$ S2 |" y! S# O: C. j, q2 z. J4 W$ W9 U; A
9 A9 w2 r8 Y3 n2 O$ y
Method 08
; i& a4 H. X" d% L=========, H" C1 V" i; _
4 [* \2 W0 r5 i& W1 ?' T
It is not a method of detection of SoftICE but a possibility to crash the
: w% ?* s$ p' u9 J# I7 esystem by intercepting int 01h and int 03h and redirecting them to another1 E4 W  C! C/ X+ V( L2 g% w
routine.6 g) I3 _% E, h' {
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points8 J0 h& F+ A1 Q/ }" G
to the new routine to execute (hangs computer...)
6 T! m0 q( K/ K; C+ @$ W' w
) {0 V8 D" q  }0 G0 s& y    mov     ah, 25h
9 z4 X! k: A/ }  |" J. C    mov     al, Int_Number (01h or 03h)1 N1 k2 C4 ?$ j, S& U& G2 [
    mov     dx, offset New_Int_Routine7 B5 o3 y& X- f1 x2 n! N
    int     21h
6 z' |9 q2 s! L3 e' `4 [7 [7 x- J+ M) \& x1 @
__________________________________________________________________________
$ k) D: ~: O6 T
5 F1 O" g9 Q! i2 hMethod 09
! c4 E7 Q+ x( x, G) W& `# q( v( f=========) [/ Y- F5 L, g
/ D% B) F: Q7 v* L- d5 x
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only7 Z1 ^. l3 A: f
performed in ring0 (VxD or a ring3 app using the VxdCall).
7 ?7 X" i/ R+ {( `9 s+ PThe Get_DDB service is used to determine whether or not a VxD is installed
! `5 k6 s/ `) u* N8 T* hfor the specified device and returns a Device Description Block (in ecx) for
! T$ a2 o& B/ ]# x' P  g& r5 R0 ithat device if it is installed.
$ M  N" U& V$ P$ |7 }0 `0 p% H8 M" [& D. l3 a
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
4 r! A5 O6 ?; H+ {   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)6 X) J% j1 M8 @
   VMMCall Get_DDB) P$ y# g' `; ~8 l3 [! a# o
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed( w& B/ D" M3 p4 j9 F' @

' |: |+ p; @7 U6 \Note as well that you can easily detect this method with SoftICE:
% N4 d; I5 p, \2 [9 ]   bpx Get_DDB if ax==0202 || ax==7a5fh
& B4 o& V4 k  A& U' Z7 W3 a% S
. D- Q: W* ?  i) T9 f/ Q2 L# w__________________________________________________________________________
, k( b$ p" G. N6 K1 u+ D, T9 l' t
Method 10- d% j2 P/ {2 P4 C) u) H6 x
=========: ]% ~% J/ v4 Y4 x! u3 z* e

& b' s; F3 ]2 R# `8 _! o=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
" {2 h* K( v# A+ y* {% {  h- ?$ x  SoftICE while the option is enable!!
7 V+ s- P2 ]3 f& G( N) b5 R, W/ n" k
This trick is very efficient:/ W  N& d& f2 D4 Z" p
by checking the Debug Registers, you can detect if SoftICE is loaded4 [7 S& Q  _* c# S3 t0 w. B$ W
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
+ D! a) `9 q" r4 sthere are some memory breakpoints set (dr0 to dr3) simply by reading their* n  @. S3 V# J$ `% P4 f
value (in ring0 only). Values can be manipulated and or changed as well1 I: d# x( J- @/ m9 G+ B
(clearing BPMs for instance)
* p1 g& W9 g* n& j
& h, h2 @# D( x& o+ u__________________________________________________________________________8 L  @4 m* T8 l  @& u
, I7 s# y! g% x2 H' j. X8 [' @
Method 11  I5 V' A  H% m1 ?5 m# T
=========
9 c7 J6 d0 S8 s& A: V. r3 ^$ |( }/ Z4 D- d
This method is most known as 'MeltICE' because it has been freely distributed
8 g$ ]/ v( g8 ?. I& M9 R: t& `+ jvia www.winfiles.com. However it was first used by NuMega people to allow
; E) N: a5 f$ y! O+ s" J% x! XSymbol Loader to check if SoftICE was active or not (the code is located
6 n9 W3 Y0 b8 {3 |& Binside nmtrans.dll).1 D  h5 i% A! A/ _

( l$ X& B8 @3 J" D5 BThe way it works is very simple:) S0 Q2 E3 `) b% K$ h
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for) t- u' I) N% m1 P6 P0 N9 P1 z5 t
WinNT) with the CreateFileA API.
- n3 F7 g+ y! i6 o4 E8 N2 g0 e, M0 U. n  N
Here is a sample (checking for 'SICE'):
4 H0 c7 Z7 R) ?5 v" o
  I3 P2 U. M& _$ s8 M2 l( xBOOL IsSoftIce95Loaded()" u  `& F2 P' o$ m" j5 ]
{: R( G5 t8 ]% Q
   HANDLE hFile;  
" l7 d' @. K7 A* A) M1 E) b   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,3 Q* ~4 z& u; o- E8 }( e
                      FILE_SHARE_READ | FILE_SHARE_WRITE,
$ Q) s% j, C' a; m0 M                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
3 i$ R& d' A% Y: U- k   if( hFile != INVALID_HANDLE_VALUE )* _# P1 f6 L* N0 t3 E9 f' Y
   {9 j. O0 h, v0 I# b: ^" {
      CloseHandle(hFile);: F" y  ~0 w1 G7 K6 H
      return TRUE;
4 O. Z  U# y4 y$ d; H& Q5 Q- \# M   }
  E2 v4 `& Z7 }4 W   return FALSE;
# t- B% l. ~; I- u  L}+ l' p7 b+ o! C

" J, r* X8 r( ~8 tAlthough this trick calls the CreateFileA function, don't even expect to be
8 K6 [& c8 f  ?& xable to intercept it by installing a IFS hook: it will not work, no way!: L; p- d% {  x6 J
In fact, after the call to CreateFileA it will get through VWIN32 0x001F! A" _! N# ^5 S' }6 |* |
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
# h0 A# |; b6 u- M" M+ U, N2 _+ yand then browse the DDB list until it find the VxD and its DDB_Control_Proc; n1 x" [3 }. t/ Q
field.8 H1 b5 L  U( Y7 v5 H7 ~" T
In fact, its purpose is not to load/unload VxDs but only to send a
' U8 N1 N$ r3 c5 m) e' \+ n1 qW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)& Q5 F6 Z1 u+ Z* }* g  s- u
to the VxD Control_Dispatch proc (how the hell a shareware soft could try+ g) @! o5 t2 S) l3 h
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
$ E2 t- Y) N# S4 S. F( _If the VxD is loaded, it will always clear eax and the Carry flag to allow! {' r. A  o. [# ^0 w' a
its handle to be opened and then, will be detected.: Z$ I. e, x; C7 k( D3 v
You can check that simply by hooking Winice.exe control proc entry point& z8 W- f9 L1 V
while running MeltICE.
! S4 f8 o- W  G) h) H& p* I8 Y9 _- u+ S6 H& q8 f) g
2 o$ D1 Z8 W  D# |8 c5 a
  00401067:  push      00402025    ; \\.\SICE
1 R/ x" `. o7 n  0040106C:  call      CreateFileA
* L& a* ^# \" y1 p  00401071:  cmp       eax,-001
/ c4 C$ F& _1 Z  00401074:  je        00401091$ u* O2 u' K, x4 Y
; D$ N4 E& z# h* d3 t/ D

# y$ ]1 }$ \: X* G" ]There could be hundreds of BPX you could use to detect this trick./ w: d9 o& _' G7 |$ O% O
-The most classical one is:* }5 o3 M9 A' p0 C+ u$ }; ~; D
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
- c9 q) |( Q4 h7 Q5 `4 E* F    *(esp-&gt;4+4)=='NTIC'& S5 K* Y# X7 V+ e4 [5 h( i$ ^' s

1 M/ y1 i" X' v1 T! P8 k1 M1 B. v) f-The most exotic ones (could be very slooooow :-(
% z# p1 o  z& P1 j; w+ _; z   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
' K2 D& r+ |0 r0 {, o     ;will break 3 times :-(7 Y9 h  X: j8 I

0 q0 l# [1 P/ B) `-or (a bit) faster:
+ r0 v/ x; d  Z3 ^2 _   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
* G( R, i0 f& a* R6 z0 R2 z' }9 h1 ^1 A- _+ v9 W1 G& M# l
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
1 u9 z5 j4 G5 {- P- j$ n2 _4 S     ;will break 3 times :-(
. ^7 P+ o( a7 z# \+ u! k; T& G
0 O2 s9 [: f9 Q" z-Much faster:) T5 Y5 _1 W+ _2 J
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'7 m( B* B% A# T

1 d* l' f8 H* q# P: ]Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
7 |4 z+ f% [  _function to do the same job:6 h, |$ }7 `4 @. H
$ f) G  s+ V8 Y0 Y6 c
   push    00                        ; OF_READ
/ r* f) f, l0 `; [4 h7 Q   mov     eax,[00656634]            ; '\\.\SICE',0, @0 D! o6 }/ r4 o7 S
   push    eax
1 w& x# l$ `6 C) [8 u8 A7 f   call    KERNEL32!_lopen
3 O5 Y# Q" h) f0 E3 O0 F6 \' g  x7 m   inc     eax4 o/ ^& I; g  r5 @* G4 D
   jnz     00650589                  ; detected& r5 ~9 \# z" v& v& M7 w
   push    00                        ; OF_READ0 [( R* s) X9 B3 p; t7 X5 S) x
   mov     eax,[00656638]            ; '\\.\SICE'5 ]9 P( E/ Q- ~. f& w: F9 l
   push    eax: ~2 t5 ^  Z+ o- w. h: @
   call    KERNEL32!_lopen
9 a1 ~9 y: u  l2 t, h7 F2 z   inc     eax2 D7 i7 l' ?8 j
   jz      006505ae                  ; not detected
9 y! N: S5 l1 p# ^& z. |0 T
. h4 i* M0 B) {0 M- X% l# _  d$ v. [* n9 N2 F! W
__________________________________________________________________________
& m0 @; w; t9 q! h* i
/ c" _/ G+ J5 @. D, F& }Method 12: O9 p& f9 k! T4 K) o2 R
=========
* c  D: _8 T" n; }5 H3 k3 [- z9 x5 j& _+ \8 [& D3 I$ ]$ T% F" L
This trick is similar to int41h/4fh Debugger installation check (code 05. S9 s4 s' p5 b! c  T
&amp; 06) but very limited because it's only available for Win95/98 (not NT). @7 P+ S. h; P; i9 l
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.1 h4 U. d$ W0 Y0 r, }
; ~0 N' R6 s6 t8 n) h
   push  0000004fh         ; function 4fh
1 d1 ?. g* i' \- _! Z6 E   push  002a002ah         ; high word specifies which VxD (VWIN32)
! A* a* m8 q8 r9 t/ j" L- X                           ; low word specifies which service
; G* s2 P0 N  ~% k7 ~9 N* ~                             (VWIN32_Int41Dispatch)5 |4 L, {: m! C2 n: B( ~
   call  Kernel32!ORD_001  ; VxdCall3 F# l2 ^9 u3 F* S
   cmp   ax, 0f386h        ; magic number returned by system debuggers
2 a* Y& z+ C! B7 }+ ?: a   jz    SoftICE_detected# C6 G' Y1 `9 h- V# S

* f3 y6 ^: d" [* I  y7 S. FHere again, several ways to detect it:
% ?! P- G, u6 |3 @+ i5 k& [, A3 O* n2 W& K7 H4 F$ g% c) M/ d0 T9 }
    BPINT 41 if ax==4f
) e3 e5 W4 E8 p! x& M: o. L: I" s  G- u/ K1 a& J
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one& [9 f  _3 W. i1 Y. N

9 T% c  D" `( H1 Q    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
; m& d$ G4 i1 S4 z+ c, ?' ~3 R; d7 D6 n% F
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
: B  V0 o2 M( P/ ?. i7 W
! j/ N2 `  `2 q! S9 t, h2 \__________________________________________________________________________
+ t1 n* N' a5 V% J$ x
* A$ e; S4 Z% b8 w8 CMethod 13
$ L" L( @, E& `& b5 a* Y=========; r# C  c4 n# [% W3 T2 z" n% p
$ j7 y% @4 U( G. C/ V
Not a real method of detection, but a good way to know if SoftICE is
: X+ w) y) J$ A4 T3 ~8 tinstalled on a computer and to locate its installation directory.
6 R6 H6 ~+ {( @$ Z8 ]/ T5 I' B# FIt is used by few softs which access the following registry keys (usually #2) :% X, v, I  _/ T5 m8 i5 J
% x5 \& i) l: _. z' y
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
1 O: ?; r: A: w\Uninstall\SoftICE" e  [- r$ _! `9 t7 b5 R, K
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
( d% Y5 h0 o2 D8 `" N2 n! ^-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion8 Z' `0 D; o0 b7 O
\App Paths\Loader32.Exe9 }: X* v/ F1 J9 {0 q! `. \! P( _
& |- g: N; j1 z. w
, J* I$ D5 g) n0 a
Note that some nasty apps could then erase all files from SoftICE directory9 z- ^$ m( s9 T" g- y" w$ i7 s8 w
(I faced that once :-(
% @0 G$ j' i5 M3 D+ |8 m6 Q% y2 c! j" |( [
Useful breakpoint to detect it:
) ~- _$ d3 }- G  L
6 P$ G2 g/ G7 p1 a     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
1 x  v1 h5 j8 d1 A: [5 c. a) S' w0 n0 q, h, H+ S' t5 f
__________________________________________________________________________# D: a  C7 {/ q; t' r; o! o7 r
+ }" f; f) J$ G! u- K; W
* K# O* |( B' w# f, U7 g+ h
Method 14 # i( [( i9 D; c% ~1 Z
=========
( \% M4 h% w5 A8 I! T
3 h0 H* z7 [; @, dA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
2 T! e+ F1 }5 w: p, mis to determines whether a debugger is running on your system (ring0 only).! E9 f! R# x: p$ X# x
6 o' [0 p/ ]  Z- K5 C: @$ t5 O7 x- b
   VMMCall Test_Debug_Installed' s$ W0 N2 ~1 p
   je      not_installed
6 [4 T5 Y9 r- O* H# {; O8 C
4 j$ M! l& J5 p4 h# KThis service just checks a flag.; D$ N$ K- L; q5 [! A% i
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部