About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
; u* I6 Z$ C/ s7 f% K+ C/ P$ G. e4 ?' P<TBODY>
7 ?) g# A# p$ P<TR>  A: d- c& a  v" x" e8 a
<TD><PRE>Method 01 . k; w7 Y* P) _  c
=========
' u4 d. C% h% O" a: Q
& K/ T1 r! ^* p) x" Z5 PThis method of detection of SoftICE (as well as the following one) is
/ ~- s, H( _  T1 l5 V) Q- Bused by the majority of packers/encryptors found on Internet.
$ [" P& E# G7 m1 z* q  @It seeks the signature of BoundsChecker in SoftICE$ j+ e6 c1 H& Z5 R$ G

/ R4 N5 {# y: p1 j" q( f! B0 I    mov     ebp, 04243484Bh        ; 'BCHK'
: l: D- m8 h/ Z4 [) E1 p/ d    mov     ax, 04h
; ~. b( B7 R  X' Z1 k    int     3       8 F& I8 O7 J4 u; B" b( ^2 N
    cmp     al,4% b- ~3 B* l! c) T. T
    jnz     SoftICE_Detected
0 q7 ?* y0 }% q$ k5 j+ }% E1 C' L7 u0 Y: t* A) ?
___________________________________________________________________________3 F: H, J! w% O7 J, k5 P

% U7 i9 S6 j6 x! z: d" jMethod 02
" e5 ^0 r: J" D# f- J% }2 \7 u4 N" ?=========6 j' @0 W/ N) G6 T

) X+ N0 @8 j" c+ B; FStill a method very much used (perhaps the most frequent one).  It is used
7 I, N: k8 t+ |1 q- C+ qto get SoftICE 'Back Door commands' which gives infos on Breakpoints,
8 U/ f  \) e5 Z; z* d; }or execute SoftICE commands...
* s9 l  X+ z" u( _It is also used to crash SoftICE and to force it to execute any commands
, m. ^  s6 A5 _# P% M2 P' \(HBOOT...) :-((  
* j! {2 D5 K: [9 Y  p
- n* ~  d+ s" I' E+ |, GHere is a quick description:2 z$ e( F. u5 j  P
-AX = 0910h   (Display string in SIce windows)) e/ a+ R$ o( P% s2 x
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
+ y3 j; Y* j! j  J& }8 c% i-AX = 0912h   (Get breakpoint infos)" y3 ]1 p+ F8 |0 Z) {9 l
-AX = 0913h   (Set Sice breakpoints)! `) J* k. D0 [8 L- g
-AX = 0914h   (Remove SIce breakoints)
7 P8 \9 ?7 c0 W9 S$ L* [6 t% x5 _: Q. h6 t! m# t& H
Each time you'll meet this trick, you'll see:! G& Z* t0 h! a0 G5 \! A
-SI = 4647h1 k0 w- m/ h& L) Y$ D
-DI = 4A4Dh
2 k$ x9 R. H  g% k+ ?0 RWhich are the 'magic values' used by SoftIce.# [) l. X$ }# d1 w" @0 T2 H8 ^
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
' ]& c. |, V  f2 W( Y+ w0 l" w+ N  `
Here is one example from the file "Haspinst.exe" which is the dongle HASP
: d0 w6 D) @! z- m, K3 NEnvelope utility use to protect DOS applications:7 m4 ^' }1 o( B% Y
" a! ?' Q3 W% E. |4 C
; P9 C" ^) a0 F* p& D6 K9 `
4C19:0095   MOV    AX,0911  ; execute command.
9 g* F3 c. ?( n/ g4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).. q3 j2 R6 x, ?9 c/ g; n! {
4C19:009A   MOV    SI,4647  ; 1st magic value.
8 y8 [: v8 O% s6 D0 s4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
1 b& P2 v5 w" C# G! ^) W6 M4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
  j: e! k, c) p* L2 Y0 F4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
8 }3 k2 P6 G) ^- N6 [% m4C19:00A4   INC    CX
8 j# G- `& e6 k+ T( u! Y4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute5 W! W0 j1 z% k8 Z
4C19:00A8   JB     0095     ; 6 different commands.
4 Y5 Z8 }/ }& S1 e5 \! H" j4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
7 [- h- b. h4 J; D9 \4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)7 z: O" y  ~! ^- }! a

$ |% `" c2 w$ j: S- q* wThe program will execute 6 different SIce commands located at ds:dx, which0 C' s9 d  E, E* a* J% r8 b
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
8 H+ l; ^5 \2 |; |
% `2 M$ @5 A! ^' P& d* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
* [, c9 l+ W  V___________________________________________________________________________
/ o! n( _0 J% }
* K1 |/ a3 {/ P  p7 y7 U/ i
( l1 G. x; l+ S5 n8 a1 yMethod 03
( H( [/ F% d8 K( F7 U=========
4 _' R3 x7 g) G. |$ j0 X% H4 u- K- e
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h  @5 B4 c' H0 e) ?+ E  b
(API Get entry point)+ f% G2 c+ S- s2 z
        & X  {3 i+ E( r4 P; ]

; O1 v! x4 L. `* q    xor     di,di
) e2 n( s$ Q' k    mov     es,di, E  e1 f" k7 T: u) o, `
    mov     ax, 1684h      
( K3 y8 I1 \; D% C* i    mov     bx, 0202h       ; VxD ID of winice- {0 x) C3 t7 G+ z
    int     2Fh
& G" w7 W* ^: t( [! q# S- J    mov     ax, es          ; ES:DI -&gt; VxD API entry point" d# N5 A: w) M8 c/ ^+ t
    add     ax, di
2 G8 w' Q  D1 e1 H# L: e    test    ax,ax
0 p2 s8 _% M/ \) U$ ^- ?' d    jnz     SoftICE_Detected
! C# x/ Z+ f. D5 o
: t4 q  E. v, w2 q___________________________________________________________________________9 f5 F! p& g' D- {6 _$ h

! F6 X. \6 f: w; P4 O( R. JMethod 04) d  o0 k: t% s! J5 y
=========
  F+ h$ W! v" r" C9 Q
9 @* c' H0 Y2 L! P9 ]Method identical to the preceding one except that it seeks the ID of SoftICE1 g8 D3 ~( e) K$ B
GFX VxD.
8 A/ ~* {) T$ ~7 T7 H6 z) J
- Q: R2 O0 l! ^: }0 T& Z( v    xor     di,di% j2 {% }6 `$ L9 u, P# `5 c2 p1 T
    mov     es,di
/ }8 v* J6 |( _+ U) |    mov     ax, 1684h      
$ }) C. y8 Z; l5 T! p) [8 `    mov     bx, 7a5Fh       ; VxD ID of SIWVID& e' v- e+ `/ B, @
    int     2fh# H9 M. b" p, x" U; e. g4 w; w+ x
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
, N6 v1 f; u5 O/ f5 b3 y5 H" l    add     ax, di- `4 V" g2 u9 _8 y
    test    ax,ax
4 P# G4 o% R  j8 s' `    jnz     SoftICE_Detected9 [4 c+ r1 J" M; @) }

( n$ \2 [! P* Q1 j( h& j; o__________________________________________________________________________
# _) k. N( @5 e# _  X* t2 s& Q3 |" }, X- S- S4 }0 |4 A2 D

: `# y1 i$ H. wMethod 05
3 A( z* M+ z( z: t- q& p=========
6 m2 T, H+ e& M8 `* ~
/ S1 u6 r( C7 |- q& t2 ?" e& YMethod seeking the 'magic number' 0F386h returned (in ax) by all system
3 |+ V/ Q: G5 J+ w  A' t4 t7 Z4 X: Adebugger. It calls the int 41h, function 4Fh./ v2 s2 [2 W; X! b6 h0 D; G
There are several alternatives.  * l! j& n+ c1 |+ {( x, N+ x9 M

% w  C& n" b4 z) r% j" ]3 nThe following one is the simplest:
0 e1 N; c% a& U  T, i0 J6 u4 E0 n% w. u
    mov     ax,4fh. Q, \6 j! C2 U
    int     41h
; E% N3 @0 K, s    cmp     ax, 0F386
/ ^+ b( h& m$ a" p& ?0 ^    jz      SoftICE_detected
' O9 U$ P+ u0 [( Q" ?3 Z
/ r( s/ Q. p  w) d. q; y# c, H6 ^) J- O# }) `% R
Next method as well as the following one are 2 examples from Stone's
0 w/ ^* |1 G/ r/ E"stn-wid.zip" (www.cracking.net):
: G0 x) Q% s8 g& A/ B+ M+ Y
( U/ O* i+ u4 s" W- ]    mov     bx, cs
# O7 r( I8 I9 g    lea     dx, int41handler2
0 T0 M0 J8 c7 g    xchg    dx, es:[41h*4]0 d6 X: S1 F2 Y9 w2 ?9 Z" q# z
    xchg    bx, es:[41h*4+2]
& Q: k% O7 B" K6 X5 ~' ^    mov     ax,4fh
/ Z: M8 u" H& ^    int     41h4 B) B# x4 ]( o# D) x9 V
    xchg    dx, es:[41h*4]
- z* b! z( \; q5 z. g    xchg    bx, es:[41h*4+2]+ C! m* ?1 H' r. E5 B$ d/ B! I
    cmp     ax, 0f386h
8 @9 N& g: ~/ D* L    jz      SoftICE_detected
% P0 Q1 Z% h, j" i6 A! t% D7 {* ~  |3 K8 Z( p: o
int41handler2 PROC
5 T  d+ q% \7 o    iret# ?8 s& [7 e. L# d  f+ ]
int41handler2 ENDP
/ x* n! P3 `* ~% m+ g2 P
! W/ y& k7 x6 j& N# P( o5 W9 ?
& \1 x8 l  M; {: l& c_________________________________________________________________________
1 R7 Q% `  w( v  N4 z6 [* {, }2 z& C7 e, I9 B
) L5 A) W6 z, l( V$ Z1 O' j& F3 M# M' N
Method 06
6 H: {8 j7 \/ p* ?, B& }7 X=========. T& s: A7 w  Z2 y

! k' K& L! J2 N
( v. ^5 ^. x, W  {/ b& s2nd method similar to the preceding one but more difficult to detect:" K1 w" u) f3 R% m7 P  U
2 Y2 V% b& |0 P1 |+ A. {
) Y9 U+ u2 O; v! n
int41handler PROC9 A- S# F  c5 Z
    mov     cl,al0 R$ W) D8 i" m  W' \& n
    iret* S! J; M! M" B
int41handler ENDP
5 z- A0 o$ n! v5 h- q  \6 X/ h. O
6 j  d3 Q7 `# z) \  T$ p7 e. B' u* w! g+ ?* _2 f
    xor     ax,ax
/ a' I1 F0 Z$ `9 p+ z* w4 w% ^    mov     es,ax
* e5 o4 I( ^5 u    mov     bx, cs
; O. a  \' Y+ h' A, H; f    lea     dx, int41handler
( s8 b% H+ [; G0 L* z    xchg    dx, es:[41h*4]7 ^3 ^: ^2 i: G. P& [$ M$ c9 N
    xchg    bx, es:[41h*4+2]( q5 Y4 F0 _7 F. |- E
    in      al, 40h
9 t# u) M$ P% F& C3 o+ [! N    xor     cx,cx% v9 W$ l. W0 O8 ]7 R
    int     41h9 U6 F0 L6 j3 \2 v. T- B
    xchg    dx, es:[41h*4]1 ]5 x3 Y% d. V% k5 ~# c
    xchg    bx, es:[41h*4+2]3 `: g( W  Y9 k# _1 S
    cmp     cl,al5 T1 f- m! J3 L% l8 F( b; j
    jnz     SoftICE_detected
. p' C7 t/ k' W% V6 ?/ w* h, w- F% K9 F
_________________________________________________________________________3 w9 m/ F6 [# c; W3 F) ~

2 c; E7 V3 C' N7 h1 ^Method 07" x7 e$ N$ B9 N0 ~8 `
=========8 M5 X& F) l9 d6 t! T1 u

/ ]' P( J7 x. U  v0 _) i2 vMethod of detection of the WinICE handler in the int68h (V86)/ U* a* G$ r3 Z2 a' s% [$ u4 p! z: s

$ H& Q5 j: j2 f) X    mov     ah,43h
; b; z6 i7 B+ k% D    int     68h( @# N1 m1 h  V
    cmp     ax,0F386h
/ l& V: H  Z/ x/ n7 c8 R# y    jz      SoftICE_Detected. D1 ~) v$ A3 e, r

3 d; w+ s  L% y2 g" G( W6 q3 l6 N# e1 h4 P- N& X, K5 G8 L
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit, L1 j$ h% v7 o4 Y# ]
   app like this:) h3 n( z6 f' _' _& a

0 c& o( k! C; u. q   BPX exec_int if ax==68
' b6 ^. p- a1 c   (function called is located at byte ptr [ebp+1Dh] and client eip is2 ~8 Z+ w8 ~% [$ K
   located at [ebp+48h] for 32Bit apps)
1 M  C7 [  M! _$ b__________________________________________________________________________$ I! r& Z% v5 X* t* v, c! M: E
4 T( s% J/ s4 p) N# V+ G( F
4 B- F/ W( @  y- n0 y
Method 088 _7 Z7 \3 `8 }9 q* _" G
=========) j$ n& l0 E7 M  c5 h6 f. @
) N5 S" [0 g4 c% {  A
It is not a method of detection of SoftICE but a possibility to crash the
& ]+ ]5 |+ |1 B" q# t3 u! |/ y3 c+ Ksystem by intercepting int 01h and int 03h and redirecting them to another
% p. H3 ^2 N2 _: Broutine.) H1 K& L( X" j
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
3 Y  e9 K! v9 Lto the new routine to execute (hangs computer...)
1 \) J0 {. o4 w; G) R" T" ~5 u0 E8 O. t
    mov     ah, 25h
3 Y6 T8 U/ p9 F6 N/ D+ B7 j    mov     al, Int_Number (01h or 03h)" Z# O. [% a$ D9 |* `
    mov     dx, offset New_Int_Routine
3 J0 A: e2 B, J; M    int     21h1 e, D( y& T8 ~7 i5 D

& _3 q$ f1 N2 o( m$ {7 K7 T2 ?' J! @! T__________________________________________________________________________
* E9 o- j% ~  |& N
5 D6 h, G# g$ W' X; T# y& dMethod 09, x3 u* c; Q/ k  ?$ v! H* t
=========
+ M# R/ a) i% E6 K7 O- ]' x" X3 K3 o  J* W2 w' E0 z1 ^
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
; x2 w1 ?* ~  C3 gperformed in ring0 (VxD or a ring3 app using the VxdCall).7 L/ r& _1 d0 N
The Get_DDB service is used to determine whether or not a VxD is installed
4 p7 S5 N4 D$ e0 h" y# s7 jfor the specified device and returns a Device Description Block (in ecx) for
/ G$ K$ M2 e) j, j3 ethat device if it is installed.' E- c; V8 {, u

9 Z2 N2 o1 \/ ^' Z/ X; @   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID, s/ j3 b5 x  D+ W8 z8 h+ G
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)9 C/ k" t, X- b
   VMMCall Get_DDB2 f$ v% p& F+ S- i
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
- g# b( ^$ J" ]2 i' Z4 a, U/ G# y6 l9 E* o3 L9 H
Note as well that you can easily detect this method with SoftICE:
5 I3 ]* t, D; W! Z- i6 T   bpx Get_DDB if ax==0202 || ax==7a5fh
- u& w, X; s. ^$ l$ }5 J) B8 r' U7 ^1 X% e7 G$ H
__________________________________________________________________________
5 E# G+ e, k% t9 c7 y4 R
7 Z% ?# [0 e% D- {9 |9 lMethod 10
* v$ H$ U- }% _=========% o6 Q* q0 v. @/ c9 N# i
5 G" D3 i) G. U; X$ m
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with+ D. T9 P+ I* B" K4 j; Y: _
  SoftICE while the option is enable!!# z3 B$ E, n. v3 X3 A. g3 u! w; p

/ z9 H4 n/ R1 P+ K, m" U0 _0 qThis trick is very efficient:7 ~2 h0 f) H' @6 Y. W" g4 K7 T
by checking the Debug Registers, you can detect if SoftICE is loaded
" K. e& w# w6 r: C& p: n: U0 z7 S; _(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if( w5 j. A. s% u
there are some memory breakpoints set (dr0 to dr3) simply by reading their) u% `. X" A! a
value (in ring0 only). Values can be manipulated and or changed as well3 l% Z4 v0 G: Y- T
(clearing BPMs for instance)
# @" D! H' C) z
4 T- E5 z( a$ `' o__________________________________________________________________________% ?0 P( V  p" u. [9 A3 M: C

( g! F- S0 }3 W% qMethod 118 j, ^! I9 h9 D8 s! i' E
=========
* m8 d# [6 D8 b' p% O9 O* T) ~, C2 @& |/ y6 X) g
This method is most known as 'MeltICE' because it has been freely distributed
" s5 B; T$ \0 F, W4 svia www.winfiles.com. However it was first used by NuMega people to allow
+ A! C, w  d1 h; a, E& q& k% K! b) nSymbol Loader to check if SoftICE was active or not (the code is located4 {( S8 s) L" W3 K8 e  C* h
inside nmtrans.dll).
, N+ o9 K3 h2 x) N
- A; p& Q' m1 N3 ]* AThe way it works is very simple:  ]8 C. d7 p5 o7 i- m
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
2 u2 \+ S' G. F) _1 F, G/ r; LWinNT) with the CreateFileA API.! d; U3 o) O$ D* {# S4 e% q
" n0 K, r" |( h2 m; E
Here is a sample (checking for 'SICE'):
9 I: G8 d: A. r) k; D' V  b1 A1 q3 M, ?
BOOL IsSoftIce95Loaded()7 \7 @3 p6 Q2 n5 ^/ X
{6 E2 j; U5 }& `2 a
   HANDLE hFile;  
6 I; q2 Q) _# Q% j! J, ?   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
8 ~# I! n% Y' e, Q8 V! Q                      FILE_SHARE_READ | FILE_SHARE_WRITE,
: R, y8 I# R5 s, w+ c6 q7 {                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);3 A% W4 i3 H4 {9 v! M
   if( hFile != INVALID_HANDLE_VALUE )( B" k0 }! {+ S7 T. f1 F
   {+ m, e$ \: A$ B; ^) l& z, ]! k
      CloseHandle(hFile);7 |! ?/ x3 E2 G) N( ?
      return TRUE;
" v1 i$ e( n. s/ F2 q   }
8 k% @8 l4 n4 `8 ^5 l0 _& t   return FALSE;& {7 p* ~7 D, `" E) N) d
}- i! v6 w" a* m+ k# `  W
; E* ~8 z$ ^. p* T( y, u
Although this trick calls the CreateFileA function, don't even expect to be2 S5 Q- ?" S8 G( S2 o. y. X: q
able to intercept it by installing a IFS hook: it will not work, no way!- z: ^& O. c+ W0 ]
In fact, after the call to CreateFileA it will get through VWIN32 0x001F/ X% B' L; C4 v/ w( e% s6 T5 i# [
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
; @! T+ D: a* h7 f6 Jand then browse the DDB list until it find the VxD and its DDB_Control_Proc! w/ p# E; A6 y0 S; A& R" _, C
field.
7 |* t' R1 A# [In fact, its purpose is not to load/unload VxDs but only to send a 3 d: j: I8 O1 Y/ J' J- a
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE): S6 {' J' N$ ^3 `; r. c2 x
to the VxD Control_Dispatch proc (how the hell a shareware soft could try5 Q& Y) U# t# z& _+ r
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
2 s$ r0 r+ V" e% p4 T# q$ wIf the VxD is loaded, it will always clear eax and the Carry flag to allow/ N$ l7 u. l0 X% U; [5 J
its handle to be opened and then, will be detected.1 p8 p! {4 d9 @3 m0 H! }
You can check that simply by hooking Winice.exe control proc entry point4 Z& `+ F8 _$ k8 I
while running MeltICE.
, c8 Z4 C* @, A2 j& L% m: g& [" f" ~
# L3 I3 m7 k4 r5 X
  00401067:  push      00402025    ; \\.\SICE. B/ W8 ^5 @- C, S
  0040106C:  call      CreateFileA
$ l$ N5 j" z+ B8 T& D0 C' M  00401071:  cmp       eax,-001
) G( y( a8 ~" Q3 b, E" B# n; D  00401074:  je        004010917 K& s7 v$ E4 C
6 ]$ i7 U" `# e% J4 J+ b4 y

* C, A" f8 A& z' `: w/ ]There could be hundreds of BPX you could use to detect this trick.7 Y/ ~5 S3 s- f
-The most classical one is:
0 n2 Q+ l4 R7 b, K  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
! W, e+ @4 Q- T% \    *(esp-&gt;4+4)=='NTIC'
+ X8 d* r+ T. w! P1 b$ t( j  N7 I1 g* `: Z5 a3 E0 ]
-The most exotic ones (could be very slooooow :-(
$ K9 V* T3 I" t' v5 ?" p: V6 w   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
8 M7 c' c  n& l' ]" W; R     ;will break 3 times :-(' u4 R; x) v/ K& ^

# N3 s+ c( }6 u-or (a bit) faster:
' Q1 r! D* c* o   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
+ C# M4 U( K* L. M
' y/ S7 `( J$ v6 s& i   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  6 w# b8 ]8 R' b- F, [4 q; C
     ;will break 3 times :-(( @, N4 N3 ^1 U' N0 h

# D# O( T) ?" J4 D/ U-Much faster:" u  V3 j6 ~% j# @, s
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'  M8 X1 l3 S8 h6 i/ v
/ U' J' R, L; _4 R7 N4 _, |( k
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
4 ]# k6 |* v7 d' ~) ffunction to do the same job:; {  M; _! Y  ^4 r- X- z9 W. c
& c: {8 U7 G; F6 i
   push    00                        ; OF_READ
; C7 R: T) e) G9 Q   mov     eax,[00656634]            ; '\\.\SICE',0
. q0 N6 O- h* `0 l   push    eax6 u$ n3 M+ F& d  O) ^; f9 r
   call    KERNEL32!_lopen
" O, n2 |% V  |# S+ \   inc     eax9 u: `8 I$ }* T8 o
   jnz     00650589                  ; detected9 y/ [" t/ x3 g: Z4 f! f; W
   push    00                        ; OF_READ$ m* k- W* z( H) f
   mov     eax,[00656638]            ; '\\.\SICE'
" }) f' C6 ~0 B/ N7 s' n" g, d   push    eax1 T/ e6 ]& N# F+ ~; L+ {" J) J1 _
   call    KERNEL32!_lopen( [; v: X; m( ^
   inc     eax: z1 _4 C" p9 Y+ B4 \
   jz      006505ae                  ; not detected! _8 _8 r4 X  @) j5 w
5 O9 Z% [9 d( U8 F8 d, v9 j

: F/ ]% w" Q) J0 Y. Z: y$ |__________________________________________________________________________
* `* K: N: X7 k# _9 a; ?) Y' r# @
0 D8 E6 o7 V' p! f; o' @4 s4 I' f* f) vMethod 129 D( {" ~5 f: p( |1 M
=========, H& B/ r! Y6 i$ W' R" k
! b- p, T! U' C
This trick is similar to int41h/4fh Debugger installation check (code 05  l5 h$ ^) D% [0 l* Y
&amp; 06) but very limited because it's only available for Win95/98 (not NT)
" l) ?. Q9 h- N3 S8 pas it uses the VxDCall backdoor. This detection was found in Bleem Demo.
5 a. ]3 Q1 I1 z# A; V2 h% Z6 E3 o! r" _; X
   push  0000004fh         ; function 4fh; \7 z, |; t; w7 b) L  b- M5 s4 I
   push  002a002ah         ; high word specifies which VxD (VWIN32)* W5 w5 z  i7 {" n) x
                           ; low word specifies which service6 e$ S, _$ m( h. X- h
                             (VWIN32_Int41Dispatch)
/ C) q3 z1 }" M- J; A2 e2 v0 }   call  Kernel32!ORD_001  ; VxdCall
; u4 m+ Z$ h' t6 C. s- Z! Z- F   cmp   ax, 0f386h        ; magic number returned by system debuggers$ }, a( G5 r$ T# H- j( m
   jz    SoftICE_detected0 p# P0 s* |* J: X2 G

) V! G3 |& B8 Q: c+ SHere again, several ways to detect it:
5 `" p( A$ G% U' W" ^( Y- S& y& ~+ U+ `/ }- j7 @! W! _, ~3 U+ m
    BPINT 41 if ax==4f
3 P# _3 h9 @8 E) l$ G% i8 q2 ^& E! m% r( f
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
, |* F% x+ D! J4 A7 A; f( X$ b! Y5 s' I& r% ~1 D  D1 W
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
5 I: y3 B- t/ m( i# ?
& ^* s' Z" f$ G# i3 t& ^    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
7 {; L* [% g* _1 r! ]: r
4 ?& b9 n6 {$ Y" f! u__________________________________________________________________________
. {+ J% |: P4 r& o" l5 t! {: `/ p7 T
Method 13
/ U' g  B' Q8 v. C" w# K6 j=========
1 S6 ?- l' P$ k& n+ N6 b$ `3 g1 }: f3 O- k, {6 R# b
Not a real method of detection, but a good way to know if SoftICE is" }& j0 ~6 C+ k/ q" E9 l+ o( S! H
installed on a computer and to locate its installation directory.
% {( {2 ], d: [5 ~3 TIt is used by few softs which access the following registry keys (usually #2) :
3 e! y$ S8 [+ L- E6 a  A
# f+ Q- ?& V' U5 S- {' M' \-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
% ~4 M. g3 o1 b$ x1 t1 `; M+ l- M\Uninstall\SoftICE0 v7 ^! h- A- g
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE6 d3 s2 X5 g1 M, _
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
1 n6 o" V( e. ^! M- Z\App Paths\Loader32.Exe
! Y# L0 ~4 R3 H& V/ w$ ?7 {3 o+ P* E+ ^* Y0 C: ?

7 N$ w' v  _3 [' lNote that some nasty apps could then erase all files from SoftICE directory
6 Z. R9 W2 U  [1 d8 g0 ?  d% l# ~(I faced that once :-(
- M# ]$ `+ `+ U7 I/ D: u
! c+ k, }2 m3 P- ~! E2 a( lUseful breakpoint to detect it:. e2 W! ~0 D8 J/ U( n2 |

- G. l; m/ T. ]2 Y' u$ i- {     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'+ o& {7 B" z1 K1 U
: |2 B9 n# w! @: R+ F/ N, N
__________________________________________________________________________
( c1 [; v4 `4 I! ^9 v% R% @8 ^  |& s+ Q

- i8 L1 B( N" RMethod 14 7 u( E2 L9 P- ~+ G. X1 x
=========3 V0 L5 `: x6 Z0 b

2 m4 V" w6 }* }5 {$ j1 ^4 [A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose/ {/ `2 O" j( f+ b; c# B
is to determines whether a debugger is running on your system (ring0 only).
6 Y+ C, g  ]  m; M: c4 c. p
  M, h8 B3 z) y: P/ [7 S1 v% `5 z$ v   VMMCall Test_Debug_Installed
) n, |% ^5 H" Z3 t' F- [   je      not_installed8 M* U9 x* q/ q5 z% S2 E
) i0 \+ p. t$ @4 q4 i
This service just checks a flag.0 e7 _% Q% t+ P/ ]( M
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部