About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
. W% q7 G0 |; k9 ^: f$ d: v<TBODY>1 F+ e/ ^4 a7 r, v$ I2 d- O
<TR>" I  O* A; A. A8 H3 a+ q7 V
<TD><PRE>Method 01
# W- ~/ P3 F4 }, V$ _5 ?=========
4 k, S( I  s! _! T
5 ?7 }0 s  S" P( UThis method of detection of SoftICE (as well as the following one) is
1 ^, [! `$ N7 f/ L+ u; d+ l) V0 {- M0 Qused by the majority of packers/encryptors found on Internet.& v. M' g2 {3 z
It seeks the signature of BoundsChecker in SoftICE
9 N* Q$ m, O4 w2 v0 c; c2 [- ]' J" o$ T* s
    mov     ebp, 04243484Bh        ; 'BCHK', d# `6 e# r$ O$ g. o) w" K
    mov     ax, 04h; M0 L5 h3 v1 F& v
    int     3      
0 u6 f1 k4 I( l" }; {2 O9 _7 ^1 {1 h    cmp     al,4: o0 Z$ h4 T- _7 u8 h4 T
    jnz     SoftICE_Detected
6 I+ S* B( a+ d$ C* @
' b1 w' w- C. A, y% G___________________________________________________________________________
7 o1 b1 a& S5 ~4 \/ H
$ `9 V- k1 n$ P( H5 EMethod 02
# B! l( h" Q0 j: M# T2 ?=========  z8 L! ]1 l( v& }$ m6 }0 G7 v

/ ]3 I: [2 G5 XStill a method very much used (perhaps the most frequent one).  It is used
. R8 M7 O7 y0 @& c1 vto get SoftICE 'Back Door commands' which gives infos on Breakpoints,
; g3 N$ W: F3 Vor execute SoftICE commands...4 n9 l; ~0 M4 r( U( F& {
It is also used to crash SoftICE and to force it to execute any commands
# }- n( p" Z: u$ c- s& W(HBOOT...) :-((  % Y. m: l+ h& z8 A3 p% v3 V" U

  j8 |) z1 ~/ z1 W' dHere is a quick description:! K5 F7 s& z: @4 y6 d* t
-AX = 0910h   (Display string in SIce windows)
: w9 N/ g  U3 O-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
! r: U8 S5 P# ^$ n-AX = 0912h   (Get breakpoint infos)
8 L% Z7 ^0 W8 u3 g& h-AX = 0913h   (Set Sice breakpoints)8 [0 ^+ S) X) i: _2 }" `5 K( d. T
-AX = 0914h   (Remove SIce breakoints)
/ Q# A5 T" c. n
8 d* D, |; B5 x( kEach time you'll meet this trick, you'll see:: Y' n; e- [; ]+ [, S6 k* ?6 W
-SI = 4647h
. ]9 a( |  o+ s! p% N-DI = 4A4Dh
0 t, q9 t6 w/ \: n) K4 y" [Which are the 'magic values' used by SoftIce.3 B$ h9 f0 e" R2 u7 |. @
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
$ t$ H1 |+ W- J/ J
$ B( M! a2 C+ n' _+ S# G5 C1 l& `* WHere is one example from the file "Haspinst.exe" which is the dongle HASP
% |4 _; U4 I" VEnvelope utility use to protect DOS applications:
4 H4 \2 q# ], a! k: j
) i3 ?( x; J. }. ^3 I: S: D# B& r: [1 {6 \5 f( ]1 g
4C19:0095   MOV    AX,0911  ; execute command.
5 j0 H+ }$ I- {$ a4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).& ~6 K) i% j- r" p4 R
4C19:009A   MOV    SI,4647  ; 1st magic value.
7 ^- p/ G9 d- ^6 y) N) P4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
9 a  e# G- d8 ?1 d9 M4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)7 O8 K; u  I) C9 F, M4 Z
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute1 a5 B2 o3 Q: U
4C19:00A4   INC    CX, U$ y& d) H; A# ~( \; g
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
  |3 l+ d* m# o9 G' A4 a" N' h4C19:00A8   JB     0095     ; 6 different commands.
" C8 e+ H4 w3 n0 v5 u: k- o4C19:00AA   JMP    0002     ; Bad_Guy jmp back.7 A# `; U& ^: o& N4 P; e
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)% F  B+ y) }% P! L( _5 z

9 q" g5 h$ Y- M( L1 `9 S9 g  sThe program will execute 6 different SIce commands located at ds:dx, which
5 F% q+ k" w9 ?+ H: J. a  Y/ |are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.! `# u- K; T, j2 E+ U1 a2 p3 B
, `' c3 g( l3 l, J$ u' P# U7 K
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.) b7 C4 V+ `# D
___________________________________________________________________________
) ]9 V( S7 o. ~# p1 Z* i* J0 U$ V6 a; P: S$ \
" P) J& v2 b) H  r
Method 035 O% T# @4 }8 Q% l' l
=========, u0 I( z8 M' E7 A4 B& z

8 v* H$ j' r# o2 iLess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h7 }4 G9 q' }% u  |5 m" E
(API Get entry point)6 \6 E$ y, x- Z
        ( M7 J$ I' C/ _1 c/ e5 I7 h" m' e

. b8 b7 s& F; Y2 ?: f  e( [6 Z% M    xor     di,di
! j$ j) m4 N; v$ g5 R4 m' V    mov     es,di
% X! B. z; c+ P$ r8 H    mov     ax, 1684h       , H. A+ `6 [/ W  ~/ N  T
    mov     bx, 0202h       ; VxD ID of winice& u" `- I$ n# u: R
    int     2Fh
7 {. o; N6 ^$ A    mov     ax, es          ; ES:DI -&gt; VxD API entry point
# N% Q+ Q* s1 A4 y  B  R9 _    add     ax, di
# E" O& f" a; T5 Q3 O: f    test    ax,ax! f+ X; a0 @, M; B' B! r" B# Q
    jnz     SoftICE_Detected
, I$ p5 y# a+ a: ^1 \8 d2 \4 w
& Q8 u* i9 b7 ?___________________________________________________________________________
- S6 D" u- T! d* A# z# x* E- y, P! j/ W& n3 v
Method 04" O/ c0 X! L% ~0 P6 b
=========
5 J" Y- g+ R% D) \) {6 k# e) a
/ D$ e3 D7 ~0 g; WMethod identical to the preceding one except that it seeks the ID of SoftICE
# x4 g) D8 j: H6 v$ r; H$ u1 zGFX VxD.) u4 W  s7 ^3 l( h

9 b/ B# u! u9 i2 Y! a$ Q    xor     di,di
' a7 S# J1 W  b    mov     es,di
0 x( w1 U, ]  Z    mov     ax, 1684h      
2 q- }# y2 j/ \; h7 z4 v    mov     bx, 7a5Fh       ; VxD ID of SIWVID/ l, E) w: t& u6 A
    int     2fh  \% K; ]/ H2 X/ i  C  f
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
+ l3 z5 @. M2 O" C9 R1 b/ _    add     ax, di
3 y+ j7 T% F2 {! z    test    ax,ax
+ G& A4 `4 R4 y( r8 {* T7 u    jnz     SoftICE_Detected) M1 ?& b1 k* I& B+ s( k

2 `& o+ |  E! C: x2 Y__________________________________________________________________________
9 C+ c- @4 Y: t) j8 p" D' S! V1 j  f4 G2 G; A# x; S
4 f, y0 h3 |( n/ B$ @
Method 057 S9 W! [+ F: V6 W  E6 `
=========
6 ]$ o' X4 P, l9 \
' s" X5 f8 w) |7 r9 h  G9 KMethod seeking the 'magic number' 0F386h returned (in ax) by all system
" P- a0 \+ t* U9 n, |5 z' H5 O! Xdebugger. It calls the int 41h, function 4Fh.
# J0 g  K0 z3 c# CThere are several alternatives.  8 W/ l0 c% f$ E" v0 \
8 t9 L0 K. i: e# T) p
The following one is the simplest:6 c3 R! v/ o' P7 U* R
3 o8 L( R% v. Z7 J; g" G7 E
    mov     ax,4fh
2 D6 n+ i- Y' M% a4 ]0 [    int     41h3 q7 u0 G$ w2 k2 c' C
    cmp     ax, 0F386
" w6 z4 u- a! k3 Q# ]8 j$ P3 [    jz      SoftICE_detected" V/ ~: e; ~! O; z, r

, i- ?; R8 C  Z6 t1 o0 ~/ [6 ~
3 n* B* [; @& m: cNext method as well as the following one are 2 examples from Stone's * x' f* x, F1 X2 |2 s7 T
"stn-wid.zip" (www.cracking.net):0 S$ N5 f% A1 m, o
; l& ~6 C, _' V/ t
    mov     bx, cs. z: i; R4 e, Z+ x% p! X% o+ u
    lea     dx, int41handler2
+ r  f+ e3 `. E# @% `1 P    xchg    dx, es:[41h*4]
$ E0 r" ~$ `# S6 K/ S    xchg    bx, es:[41h*4+2]: l5 m; F2 O6 l1 y% A
    mov     ax,4fh/ D# Y. t9 m; b% _2 z
    int     41h
/ E- v" g% s( z/ F# e( y/ e    xchg    dx, es:[41h*4]
5 N: ]0 M6 z' {9 o! r2 |    xchg    bx, es:[41h*4+2]- c" b0 o- n# X/ N- O
    cmp     ax, 0f386h6 o# A. O  E- n8 s
    jz      SoftICE_detected
" J0 h/ Q' v1 n& u* M8 V4 B- P- o  ^; s$ }! T" Z# m4 h
int41handler2 PROC
! B0 ~% s* Y$ _/ {: P6 h5 b8 U    iret
  I6 g6 p9 ~2 F7 ^% Z1 i9 i6 Cint41handler2 ENDP, b4 D. N( b) Q" B( A
8 P8 L! i) w7 ?; F+ e, R
5 ^! X9 O$ i9 M* B
_________________________________________________________________________
# V/ D6 M% p- j' }
- X* b$ p$ R! a4 ^: v  t% R; y( r! J( p  \8 k& o% D
Method 06
9 W. O; q- H( d=========
+ {5 m& f6 D3 `6 @+ {& }" p- o( z3 y) O6 W; K

8 m  }, q" V4 L% Y4 A3 k4 Z2nd method similar to the preceding one but more difficult to detect:
' c5 Q, h% [) m% S- M+ i1 J
# h. G) r' q9 R6 K- L: m2 H& @; E- x: ^
int41handler PROC
+ g" F0 n+ K. Y1 X; p7 r) `    mov     cl,al
$ S, ^7 j3 j9 Y! F# _2 c    iret/ }( e- w: C) a8 |  H0 ~; c
int41handler ENDP- G4 W/ J: _( H& ?. I1 ]
: s% N7 k6 t; C! F

2 T/ Z* m  n4 [* i( `9 o9 [3 @    xor     ax,ax
; N; Y1 o/ ?" `' S/ O    mov     es,ax
: E" x  [* P0 b* [! {' X3 \    mov     bx, cs
3 C& F- u9 x$ x- j0 R0 G    lea     dx, int41handler
: x7 `  I6 s3 p& y; k    xchg    dx, es:[41h*4]/ w$ e0 a2 I0 F/ k
    xchg    bx, es:[41h*4+2]
) m2 a/ m" \. V6 g% w, a7 g    in      al, 40h& g  y! I$ ^& @
    xor     cx,cx
* ]: [& a  w6 g) J    int     41h' ]4 |& e9 T7 W# I8 ^- ?1 w
    xchg    dx, es:[41h*4]
8 W- u& C- C  ?6 Y1 ~! @    xchg    bx, es:[41h*4+2]% F0 ~/ {  j: [' c0 M
    cmp     cl,al; _, G1 G& A7 s* F  y3 |1 P
    jnz     SoftICE_detected( G, o% w$ R" i% v) i! J
5 F; z( ^' ]& N2 `
_________________________________________________________________________7 F( m- o" j5 H7 J7 D+ ^

" f* H- U2 b0 P; H# p5 x; M* D9 X) o: FMethod 07
/ `2 m( D/ N; {1 J=========
( k3 m2 w$ `, ]: s: U* i: ^. R9 Y7 j& u& c- M1 e( m* S
Method of detection of the WinICE handler in the int68h (V86)6 n) r: C8 j! b5 y# }0 B/ K
3 v, q7 E* K. }6 O
    mov     ah,43h
3 ?! m( y" S, Y" S$ C& r) T% B    int     68h
, z% Z" E' m" P8 Y% |3 c8 B- [; e    cmp     ax,0F386h
1 a4 x2 U. |2 B0 N5 F; ?8 o& Z    jz      SoftICE_Detected
2 ?! W& m3 Y' F' A
- s5 @* y! C- I/ M+ O+ B& V
' ~) W( l5 ]. S- I+ L4 c=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit4 p0 c# L9 R8 ^& a& I
   app like this:1 O% y/ Q' J: d/ K" R9 Y  B1 j
' }- L) s" ?' s6 W
   BPX exec_int if ax==68
# Z* {: N: Q0 L# O# L) \. `# x   (function called is located at byte ptr [ebp+1Dh] and client eip is9 R" z" h( e) j
   located at [ebp+48h] for 32Bit apps)
' W: U7 [& w+ c, w7 `__________________________________________________________________________# k3 c% h3 _" X( p6 A; w2 @  T

4 i4 M. G+ M0 b% w% h% S* w# z8 Z  {! ?8 Q8 I; q4 L
Method 08! K+ P/ X  y- W$ {
=========
2 I- a# n" i! n- t& U4 I& L
9 D( r: {7 Y& }) j! e+ @4 f+ ZIt is not a method of detection of SoftICE but a possibility to crash the) e2 @9 B1 u" G- H1 M
system by intercepting int 01h and int 03h and redirecting them to another
- s8 C* W3 O) ~* n+ X% D1 Groutine.
" ]2 s* [* |- OIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points1 d, J7 |5 B% J0 j
to the new routine to execute (hangs computer...)8 G0 x' j7 o  Z- Q' R" \

3 h, T5 U/ F9 D0 @+ H8 j( D8 _6 f    mov     ah, 25h
4 P2 b. \9 C  i: j% Q    mov     al, Int_Number (01h or 03h)+ Z, S6 ^) A. h4 u
    mov     dx, offset New_Int_Routine
! x' s3 c% d, t% [1 n    int     21h
8 x) C' H) L7 l# D" M# B6 m
! g' o3 k$ i* x" z' A5 W__________________________________________________________________________
) r- U- X3 h" y
5 W2 ?) l3 \, Q' U) }Method 09
0 F3 \4 z' F$ O+ O; \7 j=========+ U& m+ z! q$ x5 V# j$ E
' A" w2 a6 v" l; I5 F
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only4 ]7 W: M+ Z' ?1 J" C
performed in ring0 (VxD or a ring3 app using the VxdCall).
  s% @4 y: z" g& H# T8 B/ e, LThe Get_DDB service is used to determine whether or not a VxD is installed7 t1 I* l. `- X5 E; V
for the specified device and returns a Device Description Block (in ecx) for
( T) O* T- N( K' ~. s: gthat device if it is installed.
. ]& ?7 N& N9 @% |- w2 u" ^4 ]' [2 L3 K" Q( [4 V5 |- u
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID1 C* }0 p( y' \. X
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
& n( k. Y3 Y7 i8 I   VMMCall Get_DDB
- J% y9 O$ v, |& C& H   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
: f. g4 S' V4 u% }* o7 {! a
1 O( J2 ~4 |5 i6 N' {Note as well that you can easily detect this method with SoftICE:9 b% C$ J4 R3 _+ n4 t+ z
   bpx Get_DDB if ax==0202 || ax==7a5fh
% x2 \: k* n! Z: z# l. I5 L
/ f& h2 t; k1 m! W: o  t0 r* F' m__________________________________________________________________________& G' x8 A0 b9 a6 k+ G7 o3 c& c

& t3 L+ Q1 b' nMethod 10! P! `2 f% Z& O
=========) y' x/ O5 m( V$ w1 a! m

5 c1 Q* D( P/ R, U" f& g/ `=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
0 O$ ^$ @! k3 E  s  SoftICE while the option is enable!!
5 \) j) a4 T2 s* g* \! L$ F$ j; q/ L0 [7 p/ z
This trick is very efficient:
; \3 G3 n# i% E* }by checking the Debug Registers, you can detect if SoftICE is loaded" N( `3 K0 Z5 s  J) y
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if3 J( p# d9 ?% e
there are some memory breakpoints set (dr0 to dr3) simply by reading their2 e# `: }  U! D
value (in ring0 only). Values can be manipulated and or changed as well
8 F  p: p& L" [- w8 j$ `. ^; a(clearing BPMs for instance)
, f0 k9 ?) y- {5 W2 J. l' _: C5 k3 K' I7 O5 `
__________________________________________________________________________$ m7 W' \" U( L$ h+ c9 U9 @
* z& ?' |% M4 |: H
Method 11
0 y$ J. }0 K# Y  Z( E: M, E9 |=========
8 z; Y: v$ k0 K1 y. J! r# L+ r! e/ }
This method is most known as 'MeltICE' because it has been freely distributed
- \# R" f+ b$ e9 M8 ]via www.winfiles.com. However it was first used by NuMega people to allow: [8 a; H! g  e: U1 g& M
Symbol Loader to check if SoftICE was active or not (the code is located
3 q$ @3 u/ ^2 Q  Z! H$ Sinside nmtrans.dll).7 C6 J0 ]" S& D' F& q/ h

4 ~% E! a/ ~$ l3 xThe way it works is very simple:
; d5 d/ }' @" ]# ~6 q1 xIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for4 v% h  s9 k2 R) a
WinNT) with the CreateFileA API.
" _) g7 e9 E3 f: U* M" T. b, S6 p" t+ w, ]
Here is a sample (checking for 'SICE'):
  ?- J( ^2 u* p; n* N: o
8 ~4 }, I% g* qBOOL IsSoftIce95Loaded()7 X# P! p% o' A6 @% H" @
{4 ~7 J* K- x# P3 t
   HANDLE hFile;  
; w& l$ h8 w0 B6 ]   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,5 j; r' P* p: B& x3 R( B
                      FILE_SHARE_READ | FILE_SHARE_WRITE,$ j  M7 m3 |$ \
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
9 s; @( R1 n  D  f   if( hFile != INVALID_HANDLE_VALUE )' K9 A* n8 [) x+ T) A  I
   {
. m8 Y7 u9 o% H      CloseHandle(hFile);4 n- \' Q. P; M* _# \
      return TRUE;& t# ?% M/ N  @0 F( ^
   }/ Q( ?. Q* {( C1 f- t2 W
   return FALSE;2 d! K) j6 ?# `, q5 s; i
}5 R: x6 W+ n" x
( N) ]8 `/ d) ^
Although this trick calls the CreateFileA function, don't even expect to be) D. P$ w' I  S; O5 B% l) l9 n# T! |
able to intercept it by installing a IFS hook: it will not work, no way!
+ X! G* j! |2 g8 dIn fact, after the call to CreateFileA it will get through VWIN32 0x001F7 H/ K$ k/ X" s: u, X5 i
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
2 {* ?5 B, r  ]0 q9 B, Kand then browse the DDB list until it find the VxD and its DDB_Control_Proc
5 k2 ?9 t: L! D. i+ e  Y( ]field.
' T/ F- t5 x' g/ `. e7 j! @+ LIn fact, its purpose is not to load/unload VxDs but only to send a
0 K3 i7 P: k' ~7 }! E  LW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)2 r) _* L) C' L( }( q3 ]+ v
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
& N' e, j; {( g4 ?7 B; Uto load/unload a non-dynamically loadable driver such as SoftICE ;-).
/ W* h$ ?3 h  |! \If the VxD is loaded, it will always clear eax and the Carry flag to allow8 G* e: }0 [4 i5 L9 G
its handle to be opened and then, will be detected./ Y( F% e/ \9 A3 }8 W- A7 Y
You can check that simply by hooking Winice.exe control proc entry point
/ x( S: I/ q4 k* [while running MeltICE.. x9 f4 d3 c" ]2 X% }4 n4 w

0 C* @3 u# J3 v/ r0 v( K/ Y8 M$ W2 }9 S) V$ K
  00401067:  push      00402025    ; \\.\SICE3 r$ ?, P5 A8 v( R) ?# D3 `
  0040106C:  call      CreateFileA! I3 o$ m& r$ H
  00401071:  cmp       eax,-001; n. c: a( _* w# ?4 X0 K
  00401074:  je        00401091
/ y/ }! k& F! g7 n7 ~/ {9 Q; G4 v, z
) \- t& ^  @% \; x% e3 V- z
% `! L# c" P" E5 ~& W. g: i. }There could be hundreds of BPX you could use to detect this trick.- B6 `# ^- \  d: h& Y
-The most classical one is:
. K: h( B1 h0 [, H7 ~# e  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
$ x/ c* y; h: H% r* v    *(esp-&gt;4+4)=='NTIC'
5 ]/ Y( e  [" P
: D& m4 V0 w1 n# \-The most exotic ones (could be very slooooow :-(
. c) K- M/ u" _9 `# d; F   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  6 H% i$ @( W6 [- j7 o$ I* ^) M
     ;will break 3 times :-(# i) c! [2 g+ @$ }; ?0 o5 n3 J
! R! V% k, `; Q7 V
-or (a bit) faster:
" T7 X/ r0 U, p6 B+ X9 q4 \0 |   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
/ h0 t0 _, Y" F/ K$ K* d/ d- P" z1 N: T# n9 Y+ }
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  " c1 _; z7 _+ G( @
     ;will break 3 times :-(
7 a0 i5 L- P$ _2 V1 y* r
% K; n* f2 y: [* H# W; U. T-Much faster:
# b3 i0 N& e% u' G' S2 C   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'$ y. I! J$ f# h, d1 F. m5 N
, `% I. m8 s/ }9 p
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
1 S# t9 ~8 v* P* Z/ x2 r3 U6 ~( T( Efunction to do the same job:
5 a+ h" f, p8 q+ m: Y7 _6 y+ x8 W% k, m  M. S9 H
   push    00                        ; OF_READ  f+ F8 O! v: X6 V4 J' H) Y. P- ]
   mov     eax,[00656634]            ; '\\.\SICE',0
1 P  x2 M0 p" C1 h1 a( f$ ]   push    eax' _% \* M6 q) k7 q) h+ ?
   call    KERNEL32!_lopen& y) S* _( T( s. T$ ^# ~8 O
   inc     eax
+ X2 I2 j7 a" ]' v5 N   jnz     00650589                  ; detected
6 C$ [. d/ U8 K4 w   push    00                        ; OF_READ
, ^7 u/ W% q, j* [* f' Z$ G   mov     eax,[00656638]            ; '\\.\SICE'7 M! J% F( K  ?. x& M
   push    eax; p/ d; f( l6 N8 I
   call    KERNEL32!_lopen! n% z! Z( B2 s' @) t) |$ c7 w
   inc     eax
. i, c, W+ W; f* D9 k( y3 {   jz      006505ae                  ; not detected$ ?' w  b: y: e' p- c# ~& a7 g8 T
9 w& [$ ^7 M& f) G, n
2 a( ~; i  z/ z
__________________________________________________________________________
& L- V! z6 C& ?& _7 {3 D2 i1 @* ]0 R5 W6 _5 G
Method 12
3 M! k; Y) X& T4 d=========" e; i# A: P: D! E/ k' o/ s

9 ~2 Q9 k5 T9 f+ J4 GThis trick is similar to int41h/4fh Debugger installation check (code 05. a$ h/ n4 L4 O) q& L% q
&amp; 06) but very limited because it's only available for Win95/98 (not NT)
& n9 Z5 x$ j$ `- k) c& F# Was it uses the VxDCall backdoor. This detection was found in Bleem Demo.3 A( a) F; z: W  G0 Z8 K

  n% Z1 r" r: s! V# s# g% Z   push  0000004fh         ; function 4fh( s8 g% `2 Y# r7 z2 n% t
   push  002a002ah         ; high word specifies which VxD (VWIN32): x* D0 k7 Z( X9 f
                           ; low word specifies which service
  a' w2 O& z( @% }                             (VWIN32_Int41Dispatch): p: `7 p, l6 a+ ~- v& {* l! K
   call  Kernel32!ORD_001  ; VxdCall
9 E, m9 G6 G4 H/ T! T+ ~: J6 n   cmp   ax, 0f386h        ; magic number returned by system debuggers5 {9 P) F7 C+ N' _( \( Z0 m* t) s
   jz    SoftICE_detected* j& ]0 b: ]; ^! y. Z- B

$ z, B) x0 b. q- L3 \* b8 i- BHere again, several ways to detect it:
& z' p* a6 ~# t. ~" w( P: y) o& e
7 x" U- j% e$ f0 J' I' W1 [    BPINT 41 if ax==4f$ V/ X, P, f9 u' ^

3 z* I3 I4 H+ v3 L% `8 n    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
- c+ F1 C% J5 b9 C5 T+ R  K/ k
* S, T4 c1 q' r2 y0 k/ V; `$ m    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
7 u" ~: H* G: {# o3 K+ z+ i- s# Z8 D% ^1 x. l- V$ T
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!( a. o1 {! ?5 l& L
! H3 n+ N1 h1 e% t$ x
__________________________________________________________________________
5 K7 c0 }7 X' a2 Z8 N$ k9 e8 l& \1 {6 z9 X9 Z
Method 13
! |. x% b* W7 O=========
3 J) ~! A" Z& g% |3 C* L9 b! Q* o3 s; c; V" N8 ?+ ~
Not a real method of detection, but a good way to know if SoftICE is
  |2 g: y2 E. ]  e9 Winstalled on a computer and to locate its installation directory.0 _; b  c9 F) z9 Q) W/ e7 [
It is used by few softs which access the following registry keys (usually #2) :
( a4 I7 n0 ]7 ^# W
6 V' i  R; J9 b6 `! _-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
% L' N8 D/ y' i. x0 y\Uninstall\SoftICE: ?! q& x8 c! M3 d' g/ u. \! R
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE* S& x7 A; `" Z. W. N/ I5 \- j
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion% p$ e' W" V) ]# o) f: i3 O
\App Paths\Loader32.Exe
( n3 i+ S  ^# c5 K% q6 [
) ?1 x: b' N, D/ k5 n+ |8 @" h! U
* ~% N- r9 h5 ?- @Note that some nasty apps could then erase all files from SoftICE directory
( w4 f5 @9 n( ^- u/ }(I faced that once :-(: O0 \$ ]8 P8 e7 Y& c
: c4 Y3 H2 j2 Y8 d7 j5 i
Useful breakpoint to detect it:7 L( `+ C0 V1 F7 U

1 y6 Q# g+ A9 t) m. B     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
' Z/ R2 n) K5 ]3 L2 _( n
1 [6 u4 E" h# o3 Z__________________________________________________________________________5 Z# G+ P8 f  B$ B

5 O/ d% d( x7 j" V+ o9 Q, u  V9 D: `: \" V
Method 14
5 O6 G! R$ B% m; L1 T6 O=========
0 m6 g  o- I, i5 o6 h/ m
% }: P$ V4 A. NA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
, i6 i3 a+ w- b& n, K6 `is to determines whether a debugger is running on your system (ring0 only).. O$ `1 T5 h2 Z/ ?

7 w4 X' _# T: }7 P- u) l4 b" U; k   VMMCall Test_Debug_Installed! L/ i/ n) \( w" l) Y" p
   je      not_installed
  ?1 t- P2 I9 r! B0 t
* x7 p( T! R4 w, oThis service just checks a flag.
6 J4 Q2 m. ?2 f/ P/ H</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部