About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>9 i, l0 J: T& E1 i
<TBODY>
. o2 D$ T5 m0 z/ X7 b& d<TR>0 [+ X9 _/ }7 R1 g4 ]1 w$ T
<TD><PRE>Method 01 ( E, I0 [( ]; Q1 t" o
=========% o' u+ p' J7 L$ h# m
! i: t. @8 s0 S, h" z
This method of detection of SoftICE (as well as the following one) is7 @( W& }. `" m0 w7 t
used by the majority of packers/encryptors found on Internet.' @1 f, f; d" [" D2 ^% S
It seeks the signature of BoundsChecker in SoftICE+ Y; n1 ~4 Z* ]/ ?8 C3 t
* l3 c$ N" E+ P# o$ \6 F" E
    mov     ebp, 04243484Bh        ; 'BCHK'
) W2 |0 G1 Q% U) \  w! f6 V1 Q    mov     ax, 04h6 W, B. ?- K3 k
    int     3      
% _/ i- p- T' P/ a. y    cmp     al,4
" D4 U: c, a; m    jnz     SoftICE_Detected
2 o! ?- N& K( r# O) A: M
  K2 k% V# L0 }( @: ~4 C___________________________________________________________________________( C/ B6 b$ J4 N: ^8 _6 Z4 `
/ e8 C# G" o7 G0 _- Z
Method 02
) ~. c7 T, M+ h6 w=========
8 o# t  K$ x5 {& C, v& M4 e' D4 u/ H( F  D
Still a method very much used (perhaps the most frequent one).  It is used2 T" m7 o& d+ Y! }- @# V0 I
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
/ `3 |, E+ ~# y6 ^6 M1 h4 j9 R# Jor execute SoftICE commands...# |  q" k3 d+ n
It is also used to crash SoftICE and to force it to execute any commands) E1 l, b  v% z, r* g5 p
(HBOOT...) :-((  
# o0 K5 Y! G. p; c7 }
4 M3 k2 g6 z+ Z$ m  wHere is a quick description:3 |( ]: C4 Q9 _6 D+ R
-AX = 0910h   (Display string in SIce windows)) i3 N# m* u1 j# W  S
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)$ ^  j9 r, D1 {8 ~6 j
-AX = 0912h   (Get breakpoint infos)
- h7 R' a& S0 D1 {% T% e  q" |2 _-AX = 0913h   (Set Sice breakpoints)
3 w! q* D5 r& E4 |( s4 h-AX = 0914h   (Remove SIce breakoints)
6 v' D5 l7 D+ {" Z" [- m
1 C4 d* H. y1 J8 s( C% PEach time you'll meet this trick, you'll see:6 B% u2 k  I  a% i/ e7 A  B/ I
-SI = 4647h) H: U2 M8 M4 Y! a# A) y& E0 x' x
-DI = 4A4Dh
/ @0 x# o, {' H/ hWhich are the 'magic values' used by SoftIce.
" S2 V5 B2 e3 x, V- aFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.5 ]+ ~1 y5 f7 O8 Y4 p3 b& U
& c* t9 X$ w" _+ Q
Here is one example from the file "Haspinst.exe" which is the dongle HASP( \; y/ o  D/ c, @
Envelope utility use to protect DOS applications:# I9 I3 S, F) l/ p

$ {; L/ H8 j# f$ ]3 T
1 n6 b3 e  b2 D* h8 n- l  M0 [4C19:0095   MOV    AX,0911  ; execute command.
7 h8 H( i# Z6 d' C4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
) ]6 J% ]% H$ G  u8 ^4C19:009A   MOV    SI,4647  ; 1st magic value./ p* }7 N9 L+ Q8 J& `
4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
' `; k6 j' K: Q8 P3 G4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
/ \5 }" [0 o  l! {6 R* L" V4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
5 a$ w. N  C3 D2 `4 h! v5 d4C19:00A4   INC    CX, @2 z7 P! k# t4 I6 ^) G
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
  H  J# C8 e( c' j( {4C19:00A8   JB     0095     ; 6 different commands.
. n. `8 P) ~# _" T% i4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
+ _* p) K" `' i4 C4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
! f5 N6 F' \  T: F( M  v; u) ?9 R# m% h5 S
The program will execute 6 different SIce commands located at ds:dx, which4 h2 I. ?7 j: ]
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
5 o. E3 ?; h- M; A4 ^) c. y# b3 B4 m3 c
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.4 S( G# k  w1 f, F2 D9 W
___________________________________________________________________________
8 d* K/ [7 b: I. \1 s' [  C; {. ?. C: W6 d+ b6 S9 P
  [( Y) e9 C; S7 c6 J# v8 S) I( A
Method 03
/ l3 R! t. t% m: b=========4 E* y8 \6 ?* N+ {4 ?- W

! B( f. W; @) W, l' xLess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
' U7 W0 a! q, c) E1 r$ I(API Get entry point)9 V, S+ i% R6 k/ V' B4 q4 i
        6 e# ]- i, @; @" c! t

( M! K. N/ a8 ~8 M    xor     di,di
. |8 H" A3 F$ i/ |9 r$ a. r    mov     es,di
) L% x) [1 t6 [$ R( D0 Q    mov     ax, 1684h      
& c0 s) o( w/ j' {6 O+ ^! w6 u. V    mov     bx, 0202h       ; VxD ID of winice( W8 d. B% ~0 P$ J4 @
    int     2Fh; B( D: d1 L# k! |( f. G
    mov     ax, es          ; ES:DI -&gt; VxD API entry point6 b) h  U) I" U! X( J
    add     ax, di
% V) Q. p6 h8 p# e0 H    test    ax,ax1 b$ T$ U7 m, ]
    jnz     SoftICE_Detected3 e. t5 ?/ d! E& @3 I
: D" m7 Q5 x* N4 x! V
___________________________________________________________________________
+ H/ E) [# O7 d& b2 O* `: `$ S) ^. K# }7 @( v
Method 04& ?8 [  {! S3 H# B
=========
/ L  j/ |* t$ b2 U, p, k2 a) R4 M) b) u
Method identical to the preceding one except that it seeks the ID of SoftICE6 P$ U2 H" B. {) P
GFX VxD./ e7 O* N- q7 U8 r, j: x7 P
. m5 M$ D& q0 f/ z4 G8 n
    xor     di,di
2 o) q7 |4 J* e: v3 j1 d1 g  c    mov     es,di4 j$ g# t% ^7 ]# K! }; f
    mov     ax, 1684h       % D* _/ D9 z& c. O! k7 m6 q, f
    mov     bx, 7a5Fh       ; VxD ID of SIWVID
, r8 a7 r: v" s. N9 V    int     2fh
' C: E5 y# W" P% m& |    mov     ax, es          ; ES:DI -&gt; VxD API entry point1 p+ L: r! W; Y- Q) c, G
    add     ax, di
7 o3 L$ S% Y' I    test    ax,ax
$ u7 o) b8 d+ ?" ]1 `, X0 p    jnz     SoftICE_Detected
7 r1 w) F5 k$ m! H# C; Z4 U3 _# W8 n
__________________________________________________________________________; Y" T8 Q# f- Z! u

5 N2 Q; I" H6 g2 A3 X9 D1 A
6 F9 x- B, d  q( {& c0 }# O6 lMethod 05
5 S2 i3 H7 h' l2 `% @0 ~=========  |- b8 n( L+ `. c9 O4 k( J2 u

- W1 u9 b: r# K, O2 D, A- D  KMethod seeking the 'magic number' 0F386h returned (in ax) by all system1 \3 q% f& O# |# z5 o( y
debugger. It calls the int 41h, function 4Fh.( W5 x* _& d; i/ W
There are several alternatives.  
  U, R0 w+ N% u; O* y- w( S8 ^" L: m9 j  S& V) a
The following one is the simplest:
: B4 x' T7 v: z, a0 F$ H+ \/ U  J; P; x6 T. R0 u6 ~
    mov     ax,4fh$ O: a; g; w% w$ s5 o
    int     41h
7 X* O* B% X* ]* L    cmp     ax, 0F386+ [# P8 f$ z2 ]4 \- M2 A. N
    jz      SoftICE_detected
: b9 W5 w8 Q( P1 @* t! A$ y) t6 D' e* e% I4 D) u2 |

% S& J1 @1 x! b2 P4 y( wNext method as well as the following one are 2 examples from Stone's
& R5 `! I8 R5 b8 W# ~3 y"stn-wid.zip" (www.cracking.net):
) Y& X+ @# U( _- x  {3 A
5 y, m6 x  n4 B- e) p$ v+ a7 |    mov     bx, cs( _" H+ }" {& v
    lea     dx, int41handler2
1 ~! o+ S( s& [6 n! \4 T& O    xchg    dx, es:[41h*4]9 m$ r& {8 b7 }1 A+ m+ x+ ^7 J
    xchg    bx, es:[41h*4+2]) k8 i  S" p/ L4 _- w
    mov     ax,4fh; e+ s* T" S" |7 X( @; c
    int     41h/ `0 P  c% M0 k- |3 O# }  l3 Y0 l0 x/ t
    xchg    dx, es:[41h*4]5 f, D) d) z' r% ~
    xchg    bx, es:[41h*4+2]1 w, @* ]. ]8 A; c2 [' x
    cmp     ax, 0f386h/ C, W, x+ }5 y3 E( @
    jz      SoftICE_detected; T! Z# y- u/ J
: v4 h# A( {2 p6 u$ S
int41handler2 PROC9 b* `+ O8 [) O  p9 d) n
    iret
& F7 H% O" G6 F* _' U$ gint41handler2 ENDP
  d; f; z$ J4 ^( M7 \4 P5 Y" g' ~$ [5 }3 ?# w3 S# f; x
& v- ]7 F6 {! U
_________________________________________________________________________
" k$ m) }2 t8 r+ B, W: @% z$ {, u. [( N9 I3 C! t2 ^2 M
: L" B7 B( e: R0 G4 d
Method 06+ \1 B, f( s( A
=========
  L0 p% e/ t% I5 S! J) {
: k! S! X8 R3 D3 f. c$ s& F' Q. e; }) h9 [
2nd method similar to the preceding one but more difficult to detect:
  z- s" B% p. j  H* [. Q7 r' w' E( D" Z/ J% X

. z0 h$ z8 _: C( mint41handler PROC
2 V% E0 W4 q) _8 _' _6 W4 E# |. c    mov     cl,al
" x+ I' ~2 [1 ?8 a    iret. }0 i, o6 I6 `- ~- C$ Y
int41handler ENDP
) R0 c2 p6 w0 Q  |
: h+ L1 F7 P  r4 z1 v8 ~* R3 Q2 e# A+ K5 }
    xor     ax,ax7 b$ ~$ x2 H4 W- u# \
    mov     es,ax
3 Y+ x3 d' w1 t& j: }    mov     bx, cs) k- V+ h* \6 g; b# G
    lea     dx, int41handler6 d- O, E8 u: I5 \* X/ d
    xchg    dx, es:[41h*4]
1 V. `5 W! B, q& h* a    xchg    bx, es:[41h*4+2]$ M3 y) K. L& F/ y3 n; a) @" [5 ^6 m/ `
    in      al, 40h; z9 Y6 d( J6 h+ i# [! T( |  s3 k
    xor     cx,cx( Q$ f1 ?: |+ K/ e
    int     41h
. A; h: V0 |+ F& b  n    xchg    dx, es:[41h*4]! }+ l2 U& k  j* {
    xchg    bx, es:[41h*4+2]3 ?6 I0 {, V6 j0 V. z% T
    cmp     cl,al
9 I" i$ W6 w# x2 g' W' @5 I& A    jnz     SoftICE_detected
: n3 E/ }. G2 t* V4 q$ m: d2 E
2 P0 B# N( z6 Q$ g, ]8 {* Y: t_________________________________________________________________________
% M% J0 G- X9 e
$ C  G7 L1 Z1 o/ g7 u; x1 AMethod 07
& y5 l+ ?7 Q4 H; G2 x1 u=========$ v" E8 o' I9 {

1 L. E* A' p( P3 V* L7 UMethod of detection of the WinICE handler in the int68h (V86)7 i2 h, a' q# Q* \
. q, o2 |/ s+ b' }8 y, E+ ?" S
    mov     ah,43h- m7 A3 h9 P2 S0 R4 T$ K
    int     68h" `1 G+ H" v+ i* T: y
    cmp     ax,0F386h/ b7 Y+ g) O4 K: m4 G. p" T
    jz      SoftICE_Detected8 Z1 |  |1 r1 e+ h
4 \6 M* O! w0 D0 V! M6 |! |
: H# {, h1 A: {( A0 {7 S9 T
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit1 J; s5 c$ ~1 y# O+ H; y. i
   app like this:0 n' c' V2 J& b

' L8 A5 Q) O- l" }   BPX exec_int if ax==68$ h$ _5 b3 s" ~: c) w7 h, Q
   (function called is located at byte ptr [ebp+1Dh] and client eip is& |" _, N. K" j+ m0 \! {
   located at [ebp+48h] for 32Bit apps)
4 _  s2 g8 T, _$ B& b8 n  ]__________________________________________________________________________
$ o) X8 F, A) H' |, m7 }' [: h! u8 _- p; A! Z! P1 F' H0 N
  ~; b4 Z: U) _
Method 083 ^' Q& T$ I/ ]; I5 V% D! y4 Q
=========
: w0 f8 P4 a/ i' Y0 f3 D2 q6 Q3 V/ E) r* p( w6 v) R
It is not a method of detection of SoftICE but a possibility to crash the$ ~& k7 J/ m0 {3 b! s& ?
system by intercepting int 01h and int 03h and redirecting them to another
4 k9 r% e! m2 Nroutine.) I5 H! _# L5 X; {+ F( C6 I) l
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
5 d' A7 Q1 `5 R# [+ L1 Qto the new routine to execute (hangs computer...)4 }7 k% W  w/ Z5 a, J4 E. s6 X; N4 E
$ q) P7 h: W  D, ~
    mov     ah, 25h
  j8 e8 q" t& p9 o    mov     al, Int_Number (01h or 03h)
7 h, ?, y: X7 O. b& \; O; _8 I    mov     dx, offset New_Int_Routine
1 v2 B- h% C3 _1 G, t    int     21h
- s6 W2 Q0 [6 V1 d1 L2 W* i/ p: l6 N! `$ R* V
__________________________________________________________________________$ e# T4 T' _6 M

) |% r2 n/ f, _( J* ]: C0 NMethod 09
0 F3 }" u! W# J=========( Y! ]0 |. C; k* G& T

' w5 p$ N% z2 M4 KThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only0 H3 V1 }, m3 w2 ]& T
performed in ring0 (VxD or a ring3 app using the VxdCall).
- e4 Y2 e5 p) \5 y# O1 pThe Get_DDB service is used to determine whether or not a VxD is installed
+ r2 a( d" v2 @for the specified device and returns a Device Description Block (in ecx) for6 q& x1 F% V: p' f3 k
that device if it is installed.
# a7 P0 p% j0 F2 X. F3 N
6 z, ^6 o9 K& ?! W4 ^, M   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID. R* |$ n$ g, Q3 }- m9 u$ L
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-). k: [5 s; a; J# L0 j! m& w
   VMMCall Get_DDB
3 f9 a8 g3 Z7 G! w# J. W$ ~1 \   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
- f1 D2 D) W5 n& E" |. S$ z
. w  c4 j; |1 @Note as well that you can easily detect this method with SoftICE:, `* a* ]+ t5 z/ a% ]( d8 ~
   bpx Get_DDB if ax==0202 || ax==7a5fh1 @4 ~: j( p) V1 d" l

; ?7 `$ H% I( t; o8 K__________________________________________________________________________$ }9 n! Z. F2 D9 S* L5 H& R# V

! v6 Q& C; n$ P! d( u( CMethod 10
( r+ W! g' v# [4 g) O=========" ~! Q2 W! V; L5 l( \
; g* @: ]1 x( L$ V  _
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
  R0 B6 O- l! B& m7 C" y' L  SoftICE while the option is enable!!
% s1 Y8 O/ S! f" J4 q  P2 u/ R' R! z; b9 Q3 n
This trick is very efficient:
7 y2 b" V2 k! d; O2 I* _; }by checking the Debug Registers, you can detect if SoftICE is loaded
9 I, {  g2 t8 w8 m(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
! J. ^& ~8 J  _  sthere are some memory breakpoints set (dr0 to dr3) simply by reading their
% O$ f* _0 ]# ]5 ]value (in ring0 only). Values can be manipulated and or changed as well/ l+ W$ W" N1 i4 y! v% O( _8 i
(clearing BPMs for instance)  f- n/ h- ^" s. y( Q0 H

& r8 U6 g+ c6 A. h# _+ p! x/ m__________________________________________________________________________
* g5 b" x2 C/ M. K# A( \3 z& \- Q$ Y4 ~( J
Method 11
# W) y' B4 @) M. o3 I# a4 A=========
! T$ I* c" c# @9 o0 e5 n( o: p# K1 _/ i+ n1 K7 U
This method is most known as 'MeltICE' because it has been freely distributed6 a9 v1 ~! J4 O
via www.winfiles.com. However it was first used by NuMega people to allow# [/ ~3 L3 q" [% U. L
Symbol Loader to check if SoftICE was active or not (the code is located$ `6 `6 t5 R& A" f
inside nmtrans.dll).
: S0 H; n$ x3 u8 p# T( b
. ]  r* }, ^' A$ h+ tThe way it works is very simple:
; ~/ ~7 h, C* K# `! m& \: ?It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for2 H4 k' Z$ E0 o( B
WinNT) with the CreateFileA API.
/ L/ N1 y4 M7 ^( ~& m
# n/ b% {! Z4 U% }+ Y) ?& KHere is a sample (checking for 'SICE'):
4 @* O8 ?& r- n$ }
& k8 d* R& e- O: c/ dBOOL IsSoftIce95Loaded()
2 c1 D& q5 P0 m& x{+ }% @* F6 e7 Y9 ?: \* S: z
   HANDLE hFile;  
" l- B5 \) r) x, F* N  U. J   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,, \+ p; [  `1 g) Q8 C* v
                      FILE_SHARE_READ | FILE_SHARE_WRITE,. v/ H- |  X- {  v
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
4 n  u% p% U9 w   if( hFile != INVALID_HANDLE_VALUE )
: k" \- U) o0 z+ o5 B2 E   {: f/ N& L9 H1 w9 ~: I
      CloseHandle(hFile);
- U1 E: h1 j) K1 Z      return TRUE;
2 a( a( z2 o- o; t1 z   }) w- Z: B5 M" p" O; e% g2 U
   return FALSE;
$ N" p4 ~- o/ W: o' Y}
2 n8 g8 \: U) J/ A7 B! E1 b- H) H1 O
Although this trick calls the CreateFileA function, don't even expect to be
7 Z5 Q" Q; J3 Dable to intercept it by installing a IFS hook: it will not work, no way!
1 S7 j3 i. g5 {" XIn fact, after the call to CreateFileA it will get through VWIN32 0x001F
9 |* |( e. P: w  kservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)1 D" {/ o9 `3 d" p* ^0 Z
and then browse the DDB list until it find the VxD and its DDB_Control_Proc) A# q9 m4 w  x
field.
" V3 Q. W$ ^% \/ l* D- LIn fact, its purpose is not to load/unload VxDs but only to send a 8 ~  J% }% w. J
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
9 N- m3 Y5 u8 x& _9 Hto the VxD Control_Dispatch proc (how the hell a shareware soft could try! z' w3 o" _" h$ N
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
' S+ R7 o( e: C( w9 ZIf the VxD is loaded, it will always clear eax and the Carry flag to allow
5 V/ _+ r" O( i7 xits handle to be opened and then, will be detected.4 G! ^8 \$ K& K8 E$ K, `; [( u7 }
You can check that simply by hooking Winice.exe control proc entry point& N" W! s0 i6 G! U
while running MeltICE.) O' g, M6 D1 N5 _- L' [' O6 T( `+ z

1 g2 ~, G6 x7 ~2 h9 {
' @+ h* r# w+ t: a7 x  00401067:  push      00402025    ; \\.\SICE; R3 a5 e; _3 J& t# v/ e
  0040106C:  call      CreateFileA
, ]' W5 P: j5 d' Y, X  T" a+ ^9 ]  00401071:  cmp       eax,-001
1 Q! I7 x) l; S& s3 Y  00401074:  je        00401091
- l; V( ?* u$ C" @5 v5 p+ d, o2 x
- m& _+ V. \* S( C" Q1 ?% F6 o: v3 j$ H8 {( l2 W
There could be hundreds of BPX you could use to detect this trick.
' H! |  _+ \# G& N, N! E* t. r* s4 l-The most classical one is:' r- D: {3 @# C8 S4 r2 J- a6 p% L
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
9 ?" U% k1 k& N- f2 I    *(esp-&gt;4+4)=='NTIC'
1 _4 F. c4 Y* P( K) |  j1 `( e3 Z9 G) s2 d9 l& h+ s4 u! n0 H
-The most exotic ones (could be very slooooow :-(* Q& W, o4 p5 `5 Z+ x7 u
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  6 E0 I" v3 }+ F  T% w' w. W* l
     ;will break 3 times :-(6 p' ]8 a. |' W1 v; L/ f6 J" u

% F: ]. u+ T: B  n3 r6 L-or (a bit) faster: 0 Y+ |, {: D/ h1 S* g6 j4 `, V
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
2 i- C+ B0 ?& b$ V. k; w. c+ `* E; X% ^7 u5 N( B
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'    W6 [7 L: x' H* f/ x; T: D
     ;will break 3 times :-(6 Z6 d1 d- t) p1 D# l
: J3 T0 L; k2 X" m& n
-Much faster:
3 H3 S, Y) k# m   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'7 d. f- u( X1 O/ I# _/ L" h7 \4 I

6 Q+ I# ]  t5 V, F( g2 X# ^3 SNote also that some programs (like AZPR3.00) use de old 16-bit _lopen5 A% d1 C9 G5 j7 J) s7 z; f
function to do the same job:
; s7 ?; I1 Z3 B2 g3 R7 ]- ^8 I
: |- c/ n  o$ z7 Y   push    00                        ; OF_READ
+ [7 H$ Y. A/ C% {6 S   mov     eax,[00656634]            ; '\\.\SICE',0
) F5 W* l+ b3 c6 r   push    eax' I6 v9 z/ R" S* h" p, I% j( u3 I
   call    KERNEL32!_lopen
) A9 M$ n2 Z$ p   inc     eax. c- j% V' c. K7 x2 F
   jnz     00650589                  ; detected
; z+ L5 e, Z, z4 K9 H6 j% @+ z   push    00                        ; OF_READ* J. E8 S: ~3 g7 ?/ |0 r6 J
   mov     eax,[00656638]            ; '\\.\SICE'" X! S: c8 x4 C9 f2 s
   push    eax: |* h/ R5 U; G. `# [9 O
   call    KERNEL32!_lopen
/ m* q7 |5 r) I, x& L: h   inc     eax
/ Z" B$ L5 v1 I4 g; ~   jz      006505ae                  ; not detected3 T" L; N' |5 G% z2 C% a3 ]

( }1 Z* ^/ S. t
/ N* m: X6 |* G1 h% J0 Y" Z+ {. j__________________________________________________________________________1 I# @- P8 T, U
* Z; Q* y& e7 L) s7 P
Method 12
; R- `1 R' g& z) G  _=========8 G: H- G( I, H, z
  A  P0 i9 V, r% o6 ^
This trick is similar to int41h/4fh Debugger installation check (code 052 m) W' ]5 \% I+ w6 ^) @- e" Q
&amp; 06) but very limited because it's only available for Win95/98 (not NT)
& n; p. i& B4 Z' jas it uses the VxDCall backdoor. This detection was found in Bleem Demo.
: k6 p5 X5 b7 N$ ~) }. j5 [( H/ F0 y+ h$ G& W, n
   push  0000004fh         ; function 4fh% {  j$ K0 U/ j, O0 m
   push  002a002ah         ; high word specifies which VxD (VWIN32)6 d( V8 b# u9 q9 i9 s( D
                           ; low word specifies which service
7 w; X& z; o% S; T                             (VWIN32_Int41Dispatch)  R6 ^2 b) n/ a, b
   call  Kernel32!ORD_001  ; VxdCall6 q& H" p7 D' a5 ?' z, ~) U
   cmp   ax, 0f386h        ; magic number returned by system debuggers; Y; D) K  _+ |! y! `
   jz    SoftICE_detected# [9 E2 l. s9 j( V0 S
/ p  B. j) F( W; y8 ^
Here again, several ways to detect it:
+ A2 {, L1 s  }! U: c5 H+ U9 y, v! V6 s* z
    BPINT 41 if ax==4f  ?. _, T7 f8 v

, F  U' `% e1 U    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
2 Z7 w/ s4 F/ W; L7 H  c8 |9 D+ w) F; o; O1 J) q" J" @3 ~
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
' X. r# B7 [4 x& K/ r3 h) ]: }3 `: g9 g; X
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
& W* h6 a8 S) E0 G: e- h8 W+ E1 W/ F8 l. l$ w& g; K
__________________________________________________________________________2 s+ ^: s9 {  Q1 |: N7 s; P
7 v# S2 `; w4 t& \0 `$ {2 ^
Method 135 f: M% f" R4 x9 r; {: h- ^$ r
=========
: b9 E. ^# K) F1 b8 e
  s9 D: B: o1 R6 a/ E0 g$ ^Not a real method of detection, but a good way to know if SoftICE is# v( x  B2 W# L8 d+ p+ x' V  K
installed on a computer and to locate its installation directory.
5 J2 p( y8 {2 b+ NIt is used by few softs which access the following registry keys (usually #2) :
' U- l  I8 e, d9 s
* t' v. w' t, P: X6 f0 a-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion- U# D( M, I4 B) l; d
\Uninstall\SoftICE
) b' T( r* e+ M: D8 L' d-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE$ Z8 k6 [' S1 U6 D
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion5 I& A7 B- H& l$ t) F  V6 K
\App Paths\Loader32.Exe6 k* a. H( A. @' a) X. K
( Y" A0 B( i5 [! O
' x8 x; O  O' ]/ v2 N
Note that some nasty apps could then erase all files from SoftICE directory$ G: q3 h+ p5 D: E( M
(I faced that once :-(; X6 `; f1 |9 I! J' y

0 g- R' w+ m% w( J, sUseful breakpoint to detect it:2 b4 L: p% d' R' S, O. t

6 K: l* z2 r: D! V4 k: w; F     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
9 r, z9 Y) h7 [9 l( d$ }" ]( p7 K
__________________________________________________________________________
7 q% M; \7 n" s' ]% M6 z9 U/ |0 p  y
0 ]4 {% M! s- H- Y6 r( `. R. y- |' @$ y8 E/ y( K% f
Method 14 ' s0 [% b* ^* g" r
=========
8 z, C$ v' G: }7 H) c. J! D7 t, H7 C* ]' a, |& C
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
4 ^% B. ^' r7 E9 His to determines whether a debugger is running on your system (ring0 only).5 @1 Q3 V) M7 i2 Y: I# d, Q

8 Y; d5 Y4 Y% x   VMMCall Test_Debug_Installed! l$ M# m6 g/ l# _
   je      not_installed/ A$ M  B8 {8 |, ^1 g* _# {1 V
, r9 U$ n) X- I! @# b  J
This service just checks a flag.
% |) j% w" F+ e* M2 L( l</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部