About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>1 N% B/ ]. g; N- C) z( c- e
<TBODY>8 @) @8 H% H! c
<TR># _6 e/ a6 F7 A- C  C; v+ |  _  c' D  n
<TD><PRE>Method 01 1 F- `9 M. s  E2 v
=========
8 J- O9 z7 B. m$ |1 t( N
+ k" ^" i" S9 F, EThis method of detection of SoftICE (as well as the following one) is
* b, C! Y( l$ x2 E/ Tused by the majority of packers/encryptors found on Internet.! @% L; D! g. H2 Y- [7 c, U
It seeks the signature of BoundsChecker in SoftICE3 \% p) r9 }+ _! v

  B4 ^" R! f) h& _% h9 i    mov     ebp, 04243484Bh        ; 'BCHK'5 \; k% e4 o/ b+ ~! J9 S; n' c
    mov     ax, 04h
  N  t7 }1 P; Y/ Q2 ?5 H, {8 r# ?    int     3      
8 m7 A7 P3 l" ]3 _    cmp     al,4) Q7 K2 B% q& O. W' _
    jnz     SoftICE_Detected
9 z6 R9 u" B: b2 A) f7 g0 z" ~9 {. D
, t, `! ^  R- s5 {* w0 U___________________________________________________________________________# L* J+ ?( [' K6 y' b7 ^
7 T6 @+ H& P# T9 d% a) r
Method 02) I; @$ b( I# ?' V) {- q, {
=========
& |1 K4 R+ S7 e9 N# H) y/ ^- y+ y: E; V. ~" ~8 o6 _) K  S  m
Still a method very much used (perhaps the most frequent one).  It is used
; U7 O0 _; S) Sto get SoftICE 'Back Door commands' which gives infos on Breakpoints,5 b" z1 b, L3 ?
or execute SoftICE commands...0 C$ f$ ?9 `& |1 E. ?  q
It is also used to crash SoftICE and to force it to execute any commands
3 b; L' J; K1 Q0 c  L: h2 g/ l(HBOOT...) :-((  
7 m! o( U$ J: t2 j" l
2 @( U3 i6 R( R' ~0 `4 y( bHere is a quick description:
3 X9 Q2 K1 n9 k% l: ?-AX = 0910h   (Display string in SIce windows)
( Y9 I1 X& Y6 X  S& F3 ^: ?-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)" q7 u' j1 z9 S  A  K2 Y
-AX = 0912h   (Get breakpoint infos)" v/ Z% q7 L# @% \
-AX = 0913h   (Set Sice breakpoints)! E7 d8 \. c" O2 D, _  f
-AX = 0914h   (Remove SIce breakoints)
/ n: ?- i% H& W6 }6 t6 Z  p7 b, H; y3 y
Each time you'll meet this trick, you'll see:
" X! f- {. P, |+ @- @- a0 Z6 m* x-SI = 4647h  c( U" t: x# \6 i0 a  G
-DI = 4A4Dh
2 ^* l- v, v$ A! y. |Which are the 'magic values' used by SoftIce.# p  p2 D2 q  l5 w& d
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
" I5 @7 z3 P4 P" ?* U3 q, E
& V3 \* F( E3 cHere is one example from the file "Haspinst.exe" which is the dongle HASP$ _- [, L: L9 l0 J% W) {) }$ f2 X
Envelope utility use to protect DOS applications:, J3 ]4 E1 a! T  \1 Q
( b& m, s( Q1 S/ n

) Q+ t" z, u5 n! e+ T+ L4C19:0095   MOV    AX,0911  ; execute command.
% Z% u" C# z4 y4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).2 m0 {" v# Q  d. ?
4C19:009A   MOV    SI,4647  ; 1st magic value.
+ w/ T6 H4 U7 w& ?2 l+ c4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
! i/ |; j# C5 P1 ~- e9 J+ ~- Z4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)* W7 [4 a, {2 [* W6 {. k
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute, Z% L% m, L9 a- W& u
4C19:00A4   INC    CX9 i3 |( V# ^' {6 s$ W
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute% R% b( B8 T5 D! v* ^
4C19:00A8   JB     0095     ; 6 different commands.
8 f2 \8 ~% q. W7 c) M- V0 F. |4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
; l* |3 G$ Z" Y. A0 R( e7 g4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)+ l  w+ L' Z, }- z# D
1 P& g0 F+ j% q6 m
The program will execute 6 different SIce commands located at ds:dx, which
8 R9 f5 B+ F7 C% Care: LDT, IDT, GDT, TSS, RS, and ...HBOOT.6 o3 E& Y/ H/ Y' T" S
2 o0 z8 S7 d, Q  b! O
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.6 @7 l  S  K) x+ ~( T& s
___________________________________________________________________________
9 ~8 e% ?: i: e+ t' Z
  {) I# D$ U( P
; _7 B2 p# A+ }2 p: J; DMethod 03
2 @' o+ k6 k" C; Z  r3 N=========  J' L& }$ O) U! s$ q( ~% u+ _

: j5 G- H: R4 D$ J8 @Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
$ {8 D3 K( f4 b7 K; P1 C(API Get entry point)' e, j! x( N1 v/ b$ y- d4 }, Y
        
6 A7 a0 ~  M, e; }2 I  p% C  n0 K3 Q$ [0 T5 t
    xor     di,di: \9 K' v: S* z4 \" C5 S
    mov     es,di: N5 @/ g! `0 e  v8 ?
    mov     ax, 1684h      
, }3 g* l0 ?! J% k( ~! J" e7 e( D1 t    mov     bx, 0202h       ; VxD ID of winice
, e2 v2 `, y( s    int     2Fh( {7 P* F3 q' k9 H
    mov     ax, es          ; ES:DI -&gt; VxD API entry point; _0 a. {8 T# {
    add     ax, di( Y! `6 j- J  ~# W1 [
    test    ax,ax! |1 U9 x* k2 L
    jnz     SoftICE_Detected. p* Z$ Q( h# _9 ~- x, y

6 U+ s  W1 ~$ x+ O8 H' l___________________________________________________________________________
5 G0 B, O( Q3 K  C) \- `; I# w/ N6 I% G' N% S( s( [/ P, W5 q
Method 04: K+ o6 W2 t7 ^
=========
1 N5 p+ t$ F0 k6 U! x  L# ?
0 D/ U# O( T9 @' zMethod identical to the preceding one except that it seeks the ID of SoftICE) u& N6 ~4 r5 D/ K5 T
GFX VxD./ ~- N* v% E0 [$ A, _8 @

, E* F- ?; x5 X: g    xor     di,di3 |* y' `& [3 u& m: b: I5 \
    mov     es,di
7 Y6 v) y. _+ j  [$ Z) Q    mov     ax, 1684h       * R, l9 J- S6 F6 z3 {; Z
    mov     bx, 7a5Fh       ; VxD ID of SIWVID
9 r# [$ x$ Z" Y% ]! |    int     2fh
* l  S; g# U: C+ a* `* R    mov     ax, es          ; ES:DI -&gt; VxD API entry point4 H. q. D" U* j% ~2 I. n- P
    add     ax, di% S* |8 C, F: g) ^% J8 c0 `
    test    ax,ax9 E6 \; T  _0 _; a
    jnz     SoftICE_Detected& D/ b' n1 a  O

6 B( Y/ h/ R8 l* K) Q& J__________________________________________________________________________! s7 o9 K. N' y+ `

" I8 L1 q6 S& K4 ]8 U, }0 }$ `
6 A* V+ k, l" J& \% @4 uMethod 05
( g' l* V# v/ }* U  K=========
! d% @0 K7 f0 B+ f7 l5 J! c) |; `$ V& E
Method seeking the 'magic number' 0F386h returned (in ax) by all system
. r1 c3 v6 \9 B2 J% A' Hdebugger. It calls the int 41h, function 4Fh.( Y+ t* R; Z* N' e
There are several alternatives.  & w5 Q# W4 T& z9 `4 `
5 `0 J) X' c- `2 t# B9 B
The following one is the simplest:0 L% j  i% H' Q# n
+ l8 J. p; y& Q6 h, l4 m; D0 L
    mov     ax,4fh
; w9 \9 F( H2 _- q5 |2 u3 O    int     41h
$ V. I8 h2 t! [% L! y* l    cmp     ax, 0F386
& `# F( b, s/ S! G) U2 X    jz      SoftICE_detected
6 G; n  s8 r7 v. x6 g- B
% D9 |: d* ~7 j3 }! f
: B5 w# g9 d& B- V( F( j! vNext method as well as the following one are 2 examples from Stone's
0 Q6 t2 q: I; @1 y" _0 i6 G2 u0 E8 f: u"stn-wid.zip" (www.cracking.net):
3 G/ j3 i4 H. {8 R5 \& b5 H( U# y2 N8 ?) D6 J/ a7 j* ^
    mov     bx, cs
; |# ?! E* C/ m    lea     dx, int41handler2
  }1 s# m9 o  e/ u$ J9 I' S) k3 S    xchg    dx, es:[41h*4]
, y( a0 S) U* t% D9 {8 O" r    xchg    bx, es:[41h*4+2]7 l4 b* T1 h  Z( [
    mov     ax,4fh
4 ~3 {6 A3 p8 ?  V1 V    int     41h
! P$ r! g1 d- l( ^3 q+ _    xchg    dx, es:[41h*4]
7 e  C+ F) l. P    xchg    bx, es:[41h*4+2]
' \) V+ ?7 f* Q! @' W+ t7 c3 j    cmp     ax, 0f386h. d2 E3 [7 Y. P+ a% ]
    jz      SoftICE_detected5 W3 z& S' L. m4 g' N2 G* J4 t1 s

7 |5 b) e9 S5 Q+ Nint41handler2 PROC1 v& e. n/ R- n. E  A4 z$ ?8 T# r
    iret
6 ~) @1 M3 z/ g4 vint41handler2 ENDP, w" i3 C8 D# J8 ?( U% q
$ _; U$ [7 @6 l3 t& G, F% @" g

" M/ ?  K" }$ i_________________________________________________________________________; Q) T: _2 ~- K6 M5 z9 e( e6 l2 ^* b
% _; [+ B) O& o# s+ U
( W" j6 `+ F7 t4 D! i8 {: E0 I
Method 06
0 j/ X5 o. Z' G' q2 z=========
* M% @; w( R" q1 M1 |  G, Y  `' a2 e! _
7 v  x# b9 u% [: P/ j1 L
2nd method similar to the preceding one but more difficult to detect:
5 Q+ p5 H! R5 I9 A5 E; T& ~
( s: h- t1 u( N& r0 ?) s
; M& E, s8 W* \! Jint41handler PROC
4 t0 o8 O- {& |4 A# l) z2 k  O; A; x    mov     cl,al
, M) m* E9 {9 Z: b/ a    iret$ I7 N  f2 E" r! j
int41handler ENDP2 b1 H5 y, B8 n6 D; ]
0 a& U9 j1 x& I7 L% ]0 J
* q5 ^( Q! @/ h7 V
    xor     ax,ax
! K& a% p. T) T/ {9 _    mov     es,ax
/ R4 e2 S, Y8 u/ B8 n* O0 K    mov     bx, cs
/ J! z2 V' J. X4 w+ U) v9 k7 X4 J    lea     dx, int41handler( R( i$ P/ _. W* ~% Q0 D. ^" S
    xchg    dx, es:[41h*4]! J( ]; M$ h7 E! }9 G1 i
    xchg    bx, es:[41h*4+2]" J8 h# @2 q  N9 L% B2 w- U5 u% O( _
    in      al, 40h
+ v9 C$ }5 M/ g/ B+ H7 d; [  j    xor     cx,cx
6 k1 y3 S/ t3 h6 _    int     41h: E  l2 W; ^6 T2 Q7 c  Z
    xchg    dx, es:[41h*4]
! D, A7 h* y. h4 Z9 O+ E, T! }1 k" ]    xchg    bx, es:[41h*4+2]
* a0 t* ~( ~# U8 v- i" V    cmp     cl,al
, a% b6 ~! d2 F5 {2 b% Y5 Y    jnz     SoftICE_detected
+ f+ S: k( D% M. P# b2 |' D' y# U3 a" P/ A: g* S2 P
_________________________________________________________________________; w) b7 O/ |( A: r+ T) W: i; J
( Y: k  X. d6 m/ j* V- l- [* ^
Method 07  u4 v: h2 `6 G, m% C
=========* {, A& D6 {  ~

+ [) t; [- j/ z# u# uMethod of detection of the WinICE handler in the int68h (V86)0 s/ ^* s3 {/ s  T" D) A
' v- |& I! q  q, p# E
    mov     ah,43h' W+ f, f+ N8 e2 o2 m) G
    int     68h
5 p0 t% F% F$ Q/ D    cmp     ax,0F386h6 V, \& B) u  B. I  H0 c
    jz      SoftICE_Detected
/ c" Y! u9 x: s- y6 d: I  |1 }2 g4 @, R$ a7 [

! b3 u  i0 o. e. g4 a7 h=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit: X( |8 S9 ^6 V7 z! J/ t5 P( u
   app like this:+ e0 C7 Z$ x* c. J. A8 ?  r

  u3 W! X" t- O% ~5 O; Z: s0 l* J   BPX exec_int if ax==68, k: V$ s6 e2 `% ~* e' ~5 R
   (function called is located at byte ptr [ebp+1Dh] and client eip is
! B8 i+ z, p8 m4 [2 O   located at [ebp+48h] for 32Bit apps)
, b/ c7 e' S: g1 r* L9 i3 P__________________________________________________________________________' a, {$ Y1 V, a/ c

! b3 @6 {; ~7 X6 V% [& ?8 \
+ D: Z, v5 \: ], q8 UMethod 08
: s: J0 E- L6 T% u- G=========
% q5 C& q" s/ _( w; e
% ^/ g! f# Q+ z$ e2 BIt is not a method of detection of SoftICE but a possibility to crash the$ [; B2 H+ g5 V  `" H: J) O
system by intercepting int 01h and int 03h and redirecting them to another# ]6 e2 r. Y4 M* F, ]
routine." o5 ]: n  R$ |2 U% d0 N
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points! r# M- v6 U9 l# }
to the new routine to execute (hangs computer...)4 _! O, b4 d+ L. ^
9 ?$ f, c: m2 V) j
    mov     ah, 25h
9 T% V9 q6 M$ N    mov     al, Int_Number (01h or 03h), u1 I% W8 L7 d; [/ Q6 @- f0 k
    mov     dx, offset New_Int_Routine, w8 _7 }/ E0 e
    int     21h- J; q% ~8 |) n; Q! Z8 q
0 t/ p& W" O% A; j1 C
__________________________________________________________________________
3 Y9 h. b. P9 g7 n) [% {
+ p8 K* T9 ?8 s  G; x8 aMethod 09- Z, p0 E4 U0 G
=========* i% W- G" F. m/ c% C
% ^; z% j7 |% [+ q* [/ ]2 E
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
6 s6 l, w  l1 tperformed in ring0 (VxD or a ring3 app using the VxdCall)./ C& q% z  q; W
The Get_DDB service is used to determine whether or not a VxD is installed
! \$ m+ Q2 `, e  R- i8 J4 J+ w+ v4 wfor the specified device and returns a Device Description Block (in ecx) for. G9 b- a1 }' F0 r8 K. J* Y0 `! d
that device if it is installed.
: `( G' D0 C% v& u
0 ~+ J& e4 s* A+ E% T   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID- Y3 c" I$ D; T7 x  l
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
, v. T& u# V5 e5 w; P' @   VMMCall Get_DDB) r: x4 [  V$ @$ u2 d. b
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
, j. |, ^6 l" U% W! Q  ?6 T5 J
$ V- X+ G9 F7 _$ i7 w3 L- Y6 VNote as well that you can easily detect this method with SoftICE:
# e+ }( |$ X# E   bpx Get_DDB if ax==0202 || ax==7a5fh5 V+ m! z6 C* J, Y- o
: B3 c/ v. v! w8 p
__________________________________________________________________________3 J3 H& r7 J6 B( Q6 \" Y
- O9 n8 \) ?/ R3 [1 }
Method 106 H: X% a5 |. c2 s3 Q1 g
=========
2 v9 \& u  R9 ^6 A
! _- N  j9 S; o- _=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with, [. c) H" z% \" n0 M/ O
  SoftICE while the option is enable!!" n7 W( T/ `  R6 X1 [* w

+ n. c- l) U; f. DThis trick is very efficient:
+ j, u8 @% [6 C7 yby checking the Debug Registers, you can detect if SoftICE is loaded3 ^0 r& n/ I6 N# ^3 ~/ ^4 g
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
  u5 U$ q, f+ ]5 ]& x. y3 qthere are some memory breakpoints set (dr0 to dr3) simply by reading their
# p% I( G' t) e8 G  v6 \3 T& X# |) xvalue (in ring0 only). Values can be manipulated and or changed as well
3 D& ?+ f; _# O0 Z- \( y7 r(clearing BPMs for instance)2 o3 M1 v4 a5 J8 e8 m" E( m

7 {( h0 Z) `! k0 d__________________________________________________________________________
4 i2 T8 ?7 y. L# r
+ ?& \# l: s* q/ DMethod 111 f* P0 i6 f# a
=========* K7 k1 S9 Q  d  ?1 I
: X( D5 D7 f' Z* c: j
This method is most known as 'MeltICE' because it has been freely distributed
- C( J8 |- K/ F" tvia www.winfiles.com. However it was first used by NuMega people to allow- `, X  I, B+ w$ L* t. l4 u6 W# K/ j
Symbol Loader to check if SoftICE was active or not (the code is located+ z7 R  v, A/ E
inside nmtrans.dll).
0 i. Z0 Q8 U" ~2 W7 H5 X3 I- B5 ~9 _, P1 m0 a5 m. D. h
The way it works is very simple:8 {7 j2 h0 v3 J3 d5 Q
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for! r: W6 h' R4 ~* q" g" V6 g
WinNT) with the CreateFileA API.
, |, H/ z; l& }) j; S2 |7 C8 j3 c% b9 D( v
Here is a sample (checking for 'SICE'):# ]; u  N6 K# H9 z! x" d, ]

" X* h- c0 x; aBOOL IsSoftIce95Loaded()3 E) q5 b& B7 D7 i
{' l5 E. u. b  g  L/ ~
   HANDLE hFile;  
! z7 F- }- y) n! c! f   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
6 ^& T2 P9 h4 o- @                      FILE_SHARE_READ | FILE_SHARE_WRITE,
! N3 i. E! z2 m& t2 X# L                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
) v6 R. b2 @) g9 `. i0 `+ U   if( hFile != INVALID_HANDLE_VALUE )
$ \( K+ H( f* K& V: _. H   {
4 R1 {* S0 G2 j7 @0 I  p6 X      CloseHandle(hFile);, D1 ~- W/ o4 l$ C$ B
      return TRUE;3 g2 j! _) l% p" Q
   }+ ~' U) h! x+ |  p' e& t' {* n
   return FALSE;
2 T) J  u1 G* t: t5 k, D}
) ^& p* s9 ^4 D4 D
0 n; T: a' R& J! bAlthough this trick calls the CreateFileA function, don't even expect to be
3 c4 Q5 o4 x: R% i' \* oable to intercept it by installing a IFS hook: it will not work, no way!
8 F0 A/ J0 W# F& K5 H6 sIn fact, after the call to CreateFileA it will get through VWIN32 0x001F
# k1 N6 c8 z) L) t. F3 g1 f' bservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)6 a/ }- L* }4 A
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
' a" B6 W. ^1 j5 y6 _8 y  P; Z4 efield.
1 X) a! t8 u) [6 YIn fact, its purpose is not to load/unload VxDs but only to send a
& \" q; z! q/ H5 f1 V7 jW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
! l! r8 x5 y+ g0 p* V  jto the VxD Control_Dispatch proc (how the hell a shareware soft could try
" E7 N8 d7 m$ x" ]to load/unload a non-dynamically loadable driver such as SoftICE ;-).
4 q1 d3 Z8 A9 D* H: ~$ NIf the VxD is loaded, it will always clear eax and the Carry flag to allow- \, L( d3 k' a1 s% c  i
its handle to be opened and then, will be detected.0 a5 d) |4 I; O+ j/ q+ j
You can check that simply by hooking Winice.exe control proc entry point
1 k, }$ P8 Q# ?" A8 u( Hwhile running MeltICE.7 t% q; d+ q; a

" n! z7 m8 x  u
: x0 W3 I7 B7 H& s6 t4 T2 }  00401067:  push      00402025    ; \\.\SICE
* s0 ^: h4 T7 w  0040106C:  call      CreateFileA% M$ I- z7 K8 K9 W( d$ i; Y
  00401071:  cmp       eax,-001
8 X6 q; g; j  b8 j  00401074:  je        00401091
. Y& G. h6 i; ]
4 Z! A/ a  S' A  m: D  `
4 O3 R3 u. s; U, P8 TThere could be hundreds of BPX you could use to detect this trick.; z, W: L/ c; w, p0 Q7 r" D
-The most classical one is:% t+ W* q  B6 `7 D* G# ?! T# K
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||2 C; }) c- ]/ H# D% d, T$ A6 s
    *(esp-&gt;4+4)=='NTIC'' ^6 z9 ^- y" N0 n

/ v3 j) ]5 p* M1 B  x-The most exotic ones (could be very slooooow :-(
& g; @0 {! y3 a8 A( {   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  7 m) ~7 |8 L1 Q$ D3 C- S
     ;will break 3 times :-(  [" R% l) q. U- P

* n; d8 i. F  R' n-or (a bit) faster:
& v6 u, w7 r6 q   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')4 k+ \0 J1 l- T
3 R6 A) r/ @4 C! B0 ]' A; O5 A
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
) W. j5 L" Z+ e# N     ;will break 3 times :-(
( n" Z6 F* d1 ]8 }5 _2 Y# C$ r
' w8 u- C. P  f8 Y4 d" d-Much faster:/ ^6 e3 I/ y$ J1 v/ _
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'# L& d7 k# M+ G9 a% R, q' `2 r
# ?/ h* z. |4 q$ h  H. G* t) ^9 R
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen* i4 d  E4 N5 x2 A) |) S
function to do the same job:
+ w2 f/ q# L' }6 y0 D- n" ~5 u# _5 r) N, j9 ?( e
   push    00                        ; OF_READ7 h" d4 c: D' H9 o' I- o
   mov     eax,[00656634]            ; '\\.\SICE',08 C4 M/ X3 J0 a2 O, [/ I+ c; R
   push    eax, V# h3 V- _# v9 {. l, E6 o3 k) K1 `/ _
   call    KERNEL32!_lopen. r0 Z0 c( {# w7 I& t* |4 ?" u
   inc     eax
5 }2 m# E- d- }% o7 L   jnz     00650589                  ; detected
; X! p3 r' W& h$ k   push    00                        ; OF_READ/ e5 o# H9 q% k# U
   mov     eax,[00656638]            ; '\\.\SICE'
, A  X" |, x) _; i, J, J1 ?   push    eax4 X! A8 f+ _. j/ Y& P
   call    KERNEL32!_lopen
: x! n0 T9 A6 n  b$ v   inc     eax, \- T5 C2 E  a, N' r
   jz      006505ae                  ; not detected1 C5 X: ]" a4 B) J  {. i& b

" v$ s7 |2 i" w+ w; p6 \. c+ L7 O* x
' J+ e' P/ |6 l__________________________________________________________________________* t$ n! V) ]1 W7 P, ?5 I

  b: v# l* h* n- RMethod 12
) s. g) G/ U2 W* }# a* u* r=========  g8 C. y1 b% [( `) C$ N# L

6 f+ T, ?: `. e3 q4 ?# dThis trick is similar to int41h/4fh Debugger installation check (code 05
+ l$ `9 B  d( v&amp; 06) but very limited because it's only available for Win95/98 (not NT)( v# a, ~& i9 L' I# E6 L" _
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
& H) I5 c# Y; Y! c- `7 }8 N4 C
  ~3 I2 b2 ?' W   push  0000004fh         ; function 4fh* X7 m4 h4 G8 f2 O+ h
   push  002a002ah         ; high word specifies which VxD (VWIN32)
  e! ]2 \* z# A) t9 Q2 R' J# B6 E                           ; low word specifies which service
& K3 ^! X) |% A# k! m* X6 z7 N+ ]                             (VWIN32_Int41Dispatch)0 l5 F" i5 ^8 }& i" Z
   call  Kernel32!ORD_001  ; VxdCall
% V* k- q7 a, N+ j+ N   cmp   ax, 0f386h        ; magic number returned by system debuggers, t8 s% j( k; |2 f' t
   jz    SoftICE_detected8 o3 @7 Y" f4 G" N& X
: @# A2 r: h( e, g$ r" k$ m$ f0 E# K
Here again, several ways to detect it:# @, u1 k0 ^! |6 ?% H. e$ [
, q/ G: X6 i* n+ t
    BPINT 41 if ax==4f  @( p0 S6 P: U* ~
% I& I# z) h) l/ z& ?& M+ K
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one/ c; Y0 w# n9 I8 _+ b7 L- N  G) v

1 ^/ S- f& R6 ]% J2 c; \3 u    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
; z4 N0 O8 q- ~) n6 a3 g0 c* t2 r; ^
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!1 e2 x; c* W) u, j8 j( M- K5 l8 x

: F0 `" F8 T! ?/ C" v__________________________________________________________________________
& }2 E& G- s, Y8 L
" l6 v( S, w/ o3 b; V3 ~Method 13
8 c( A' Q1 ~; P! C=========
2 T4 Y) s: \' o  ]6 d$ d
) ?& _5 H6 a. X' W, TNot a real method of detection, but a good way to know if SoftICE is9 k: w+ ~3 J/ v; W4 W% P0 \7 \$ m; k
installed on a computer and to locate its installation directory.
9 d6 W' Z# C, q& a8 N5 x7 K' I& NIt is used by few softs which access the following registry keys (usually #2) :
0 j* w( A. h+ K& \% d. U* p( j/ x1 W
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
. E0 W, X9 r+ |) M) v\Uninstall\SoftICE
8 L0 l% t: V8 N5 _0 {( L; V-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
9 S2 {1 h& j: B4 \' ]8 A* c-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
9 F( l2 k) i! ~$ p5 B\App Paths\Loader32.Exe% Q- I3 q& |/ P1 |  c; j

0 R: W* t! {! H7 V7 }7 A+ S
$ `) w+ p4 Y$ e0 I2 j$ e& CNote that some nasty apps could then erase all files from SoftICE directory
/ }8 x1 s+ [& _5 w9 y(I faced that once :-(
1 f3 Z% Z/ L$ {- M4 P
6 q! k, I; J5 I) \$ WUseful breakpoint to detect it:
0 y4 [% t- ?0 t. `
5 I7 |; R+ K( F& d; W4 P9 B3 X6 [     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
( n) I9 t3 `4 q/ r" ]9 q" t" H+ Y4 |) k6 _$ a8 p" Q
__________________________________________________________________________
/ I* [! c. `  s  s* S
8 D1 W  v" v4 Z+ p( G' t
7 a2 n+ e7 P* pMethod 14
2 j$ P! D. e" [=========
' `% H# y: Y' S+ g% S9 `$ j
" A% M; w6 I8 ^A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
# s' c/ x3 N5 L" F4 T. L( bis to determines whether a debugger is running on your system (ring0 only).
) [4 I4 F: e. }, P  o  p% {
3 `5 _6 e2 ~6 p3 f) g. g   VMMCall Test_Debug_Installed
1 z9 `+ y) n' Y* j   je      not_installed! g7 J; ^# V% r, c& z8 B/ a9 f' |
# ?- O+ O3 }$ g! m9 z; o. y
This service just checks a flag.
0 x8 O1 s: _8 x7 x0 r; |</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部