About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
4 n+ R! }6 ]0 Z* Z8 D<TBODY>: W) ]7 V) E. \8 }, e
<TR>5 a7 e& A2 Y7 ?
<TD><PRE>Method 01
$ s' n: W' P' u4 f. J=========5 J+ ?  I- z6 x) n8 B4 e1 l
- @. ^6 `# J0 K& O' w
This method of detection of SoftICE (as well as the following one) is$ p1 K) j: Y; [& Z0 k+ E: Q
used by the majority of packers/encryptors found on Internet.
! \) G( q' |! _2 M6 [1 M3 ~5 k8 M8 P) HIt seeks the signature of BoundsChecker in SoftICE
7 B6 Z' [6 J$ f4 U' K* ^+ o) f  G  p9 q9 Q& m- M$ R4 p5 N2 I
    mov     ebp, 04243484Bh        ; 'BCHK'
" O& _% \8 Z# A/ ?    mov     ax, 04h  a' `& i2 W" A/ H9 f  h4 Y
    int     3       . l/ s' c! I$ y' I8 g
    cmp     al,4# D5 t: w6 ?" o7 p6 j8 K3 X+ e  |5 r
    jnz     SoftICE_Detected3 I: K& \5 Q  h6 I
" M$ k) g3 k3 y- A. N- ?0 D& e6 Q
___________________________________________________________________________
: E6 z" T  g$ d7 G' P- U# F. `) a. e9 W, L( G/ q
Method 02
7 ]& r( o+ V2 C* W. \=========& Z/ k) }8 _" M1 Y9 N* p& b2 f8 d

8 v2 G2 j, C- [; LStill a method very much used (perhaps the most frequent one).  It is used
6 _0 u) ]+ G5 ]to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
5 I2 G. u+ x" ~2 Tor execute SoftICE commands...6 y# I, A9 ~$ C8 Q6 ~6 I
It is also used to crash SoftICE and to force it to execute any commands
. U0 h' U9 W) @+ ?, {+ i1 t(HBOOT...) :-((  
$ r, {5 Y+ V+ \4 ]' R; B+ u; q
$ T. W7 b! R! B* t$ mHere is a quick description:4 `5 h+ v' o6 T' ^
-AX = 0910h   (Display string in SIce windows)* V( v6 w: e% K; Y* _) b
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)9 I5 k$ P, d& t( w
-AX = 0912h   (Get breakpoint infos)
0 w; Z/ B9 Y) X-AX = 0913h   (Set Sice breakpoints)% @: a. F* n9 B6 f' y% Q$ ]+ r
-AX = 0914h   (Remove SIce breakoints)
4 ~+ o& k( w# E: X3 ~/ C. \
* N9 X0 [( y! ^1 [Each time you'll meet this trick, you'll see:
9 a$ s$ P, _: I" n-SI = 4647h
) V$ @2 q' V' e-DI = 4A4Dh
6 u1 v; {+ p4 y( A, z2 f1 ~Which are the 'magic values' used by SoftIce.
, k8 A+ |' P  r3 `/ V  j) fFor more informations, see "Ralf Brown Interrupt list" chapter int 03h./ L/ |# W* h/ }! I

4 J2 Q# b3 P6 J& J" H1 p! eHere is one example from the file "Haspinst.exe" which is the dongle HASP
; d' l. G; X% c! AEnvelope utility use to protect DOS applications:
: O0 F$ X: C/ X" [# k; D' n  k" |* ]6 n  I! A; x

, U* Q$ g, w9 F; j( h. B: v* P4C19:0095   MOV    AX,0911  ; execute command.4 x* b$ r8 h4 `
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).% |6 Y/ t. v0 c& g
4C19:009A   MOV    SI,4647  ; 1st magic value.
: [4 J& Q- t8 b& o( K2 r8 W% v$ ]) }4C19:009D   MOV    DI,4A4D  ; 2nd magic value.0 S- m. T( x4 {1 A/ Y5 ~& Z
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*). V& ?& V+ S. ?# x0 x
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
1 V: h" D7 C' T) L4C19:00A4   INC    CX4 V5 b2 j' Z& X0 z0 Z
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute) N' l$ x( J) [5 h7 s4 _4 [
4C19:00A8   JB     0095     ; 6 different commands.% U0 p8 M" b$ {: u$ K
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.9 K. B6 X. P! |6 x/ g# m6 f
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
7 a8 l" Q  ~4 I6 l, g$ S7 a2 @0 d3 _# N/ \' ^1 y7 @1 h
The program will execute 6 different SIce commands located at ds:dx, which
( N% [7 x8 U8 l/ ]2 H5 g1 qare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.$ |. \2 t6 Y+ M  s9 R0 X$ z
1 E3 u$ `% {: {0 y$ n  ?
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
, q9 Y+ |# a# T___________________________________________________________________________
( K9 p) x5 }( F; B0 G/ t/ i3 i
  i3 V+ w# D& C8 e: Q  a$ I
+ {* r- ]2 e# W3 XMethod 03
0 \) ~. v1 D& E# h- n) r* C( G( a=========
9 v4 L) i- a9 X3 J+ F! K$ b' }9 s8 y& d. I9 T; p# T& v
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
. s3 q1 R! U% z+ X9 C% E7 V2 `(API Get entry point)
4 \8 i. d- J$ }& j- w5 j# |        # D2 ]) ?6 _  D# V1 r* K

/ L- z$ @" A  Y! Z( h    xor     di,di# M9 k7 v# K# u3 J
    mov     es,di
$ L3 w9 R! e9 N8 [    mov     ax, 1684h      
. _$ p  A. e- `5 L- K    mov     bx, 0202h       ; VxD ID of winice
# n- g  Q' b" ?. N+ b    int     2Fh
; m  V# C& d0 K7 [- X2 a    mov     ax, es          ; ES:DI -&gt; VxD API entry point
# D( K/ W, o' \# P. T+ b* f    add     ax, di
2 u' ~1 m7 P" v4 o/ A    test    ax,ax
9 y- o4 u" F* x! N+ ?' a    jnz     SoftICE_Detected) t; e2 A" L6 Y5 W! ]; f- W7 z
8 k" E+ I) R* g. |" A! j; W
___________________________________________________________________________, }9 t, [- D; H( U* v! e

8 G" P) r: Y4 B2 G6 F% sMethod 04
3 |6 p3 k; y5 d$ ]  A=========8 w1 F, B# W* Q3 y  c& i0 p

% I  A) @  G' i6 p0 sMethod identical to the preceding one except that it seeks the ID of SoftICE) Y: v8 G" o6 L) C; I/ E
GFX VxD.
9 L$ A: v) W  l: @
, f7 t0 e2 e% U4 J5 s8 a" h    xor     di,di6 c& V, \5 g% O
    mov     es,di
  m" f2 U4 H- z+ d) v    mov     ax, 1684h      
1 I  c& |7 R  [) B2 y    mov     bx, 7a5Fh       ; VxD ID of SIWVID
, J( p8 h5 a0 U+ v3 \* c    int     2fh
5 R) ^& T% j( |; p% D3 ~2 }    mov     ax, es          ; ES:DI -&gt; VxD API entry point; ~, Q" Q0 o0 }  d$ R/ e
    add     ax, di
. i( f4 i) {* I5 O    test    ax,ax
' \* ^, c  H& e    jnz     SoftICE_Detected$ G( a. A& h4 _. H

3 O# |) \/ A% H__________________________________________________________________________
6 y- P+ [9 f/ k  Q6 M8 z8 A, }, H; I7 H; H: I0 F

# j5 q, I1 q9 j  N: LMethod 05- P9 `& t( t$ K" N  S
=========9 J1 H6 N$ V9 i% g" V
0 J* h0 Z0 t# a8 {) r
Method seeking the 'magic number' 0F386h returned (in ax) by all system
2 b# x& y. G# |! p! D9 Rdebugger. It calls the int 41h, function 4Fh.  q  z# p. c) A: j4 y$ Z
There are several alternatives.  8 m3 U( P4 O; Y9 ?7 O" r% x# O& c
5 x6 U8 \: _- V6 q, {
The following one is the simplest:
) J4 I1 }/ Q5 |: M2 |9 V8 B+ r& a: a# Q% M8 R
    mov     ax,4fh) G" W* A3 R: f% J2 G  p) g+ ~
    int     41h
  u' f  n) R3 @9 B% Q/ Q    cmp     ax, 0F386
" q& }- Z" J. [9 Q$ ]3 U- C2 `    jz      SoftICE_detected  n6 f# {3 g. Y$ [1 y& o! j6 \
; s! K0 S- ]3 O- m; G- F

( W& z- z  D( O' H0 TNext method as well as the following one are 2 examples from Stone's
0 X9 I4 D, p) f$ `, |"stn-wid.zip" (www.cracking.net):
, G; s9 g0 Y* O1 \$ ~
; E) v) H* d# B5 Z3 a; n    mov     bx, cs
) K# X1 m# d# D1 F    lea     dx, int41handler2
2 }( X% X$ B4 o0 o1 E" ~    xchg    dx, es:[41h*4]) I( p5 y1 s0 w# S0 A( M
    xchg    bx, es:[41h*4+2]$ r/ o  j. M' j2 ~3 H( K6 I
    mov     ax,4fh
- k  c+ X: e! ^; s    int     41h* Q: J' k; F8 V- c" k0 I
    xchg    dx, es:[41h*4]/ t! i  R! B3 s
    xchg    bx, es:[41h*4+2]
; i- l3 Z, s* C6 J: m    cmp     ax, 0f386h1 T: G2 y% Q) t* B6 Y
    jz      SoftICE_detected$ \# |$ x  v. l5 j- m
3 r# I% c7 `5 |7 a5 q
int41handler2 PROC
. t# G. O% k) P" V    iret
: d/ [, Z" H9 A  Xint41handler2 ENDP
7 U6 }) Q5 k8 z* y
7 l! u* X% B# v+ P$ [: R: M! \! O+ ~
_________________________________________________________________________
2 M& Y+ u- s/ N
! k. k# Q, ^( K, W% V  {( V; H: b) l0 ]% [$ V
Method 06
; x% s% J7 m: ?$ Y: }: Z6 P=========0 X& o1 e% ?: r
& e* @4 u; L; m& O. J
" a5 G/ B& M' C( o- z
2nd method similar to the preceding one but more difficult to detect:
' c& H3 P/ b1 }" y' g  M( u8 j+ b
* f/ f7 Q5 N; E# b" N
% Y7 i5 ]9 K& Z, ?( v0 Cint41handler PROC
4 M! R7 |& E# k, ?    mov     cl,al6 z: U# t8 P, D; t* u- L
    iret& H% ?; |+ Y8 p1 w' l: r
int41handler ENDP
* v' n6 X$ ]3 d
! m5 Q  ~, S- B. b0 c* [' w
& a* M5 @$ w( i! r) z1 A/ j! U    xor     ax,ax7 L( E9 P. G1 y* h- v( X$ l
    mov     es,ax
  K+ n/ V  G/ r" H    mov     bx, cs* G2 K2 S. X( |9 X
    lea     dx, int41handler
4 H' A& ?4 P! A$ h; m    xchg    dx, es:[41h*4]; ^7 ]. A* z0 v
    xchg    bx, es:[41h*4+2]9 }$ o$ \8 a# _  t1 q3 f
    in      al, 40h3 L* N4 H, p9 L& ?
    xor     cx,cx
, |5 n% Q+ H5 _* x& ^    int     41h& [( r! ~# v6 ~6 m/ O& C) A8 a/ L! t
    xchg    dx, es:[41h*4]
+ \/ b% }! |1 w5 c' v    xchg    bx, es:[41h*4+2]6 s# B9 B# ^0 x% I/ H' e
    cmp     cl,al
; t& j) t( |- Z, F+ G  u3 G4 W    jnz     SoftICE_detected5 L" c" x; \& k

$ q/ I- |" l: `1 w_________________________________________________________________________
3 Y4 N. A( Y4 y5 E5 D: |& f! m$ g  H
Method 07
2 A' n( U$ ^4 [$ r# Z7 `$ L=========
+ c9 N0 n. [+ J" ?6 E# W! y7 @. E5 h- I' `5 X6 i& V
Method of detection of the WinICE handler in the int68h (V86)
+ O$ T/ e! `3 C/ Q
2 E+ u& u0 Y; y8 W8 u; M    mov     ah,43h
0 R+ t  n" G5 y  |  V, F' S    int     68h4 P8 [- X/ Z1 W7 p' q
    cmp     ax,0F386h
0 Z4 u6 j  c/ s3 _$ C    jz      SoftICE_Detected
0 w3 q( W8 [- h; N# k/ [8 `$ k8 k% j" E% P
( g# F$ j7 [: k! y0 Y5 Y4 A
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
: S% X' y, c9 Z2 L  Q8 y   app like this:
* a* o8 a# E- ?$ A
- S* Y/ R* P( D2 n7 J- _   BPX exec_int if ax==68
1 Q& M) H. X+ W   (function called is located at byte ptr [ebp+1Dh] and client eip is3 J( z, ?( x4 ^* h# e' }; b  j' ?
   located at [ebp+48h] for 32Bit apps)9 H5 A8 T2 k1 s0 a% V! P& |
__________________________________________________________________________: I. ]6 R/ u4 W7 ^$ S

9 U6 A9 r( l) f7 E2 I# Q: H7 Z- i' _
Method 08& L6 P# T8 q' [$ P+ h* S% d
=========: O3 J- b) G2 ~/ Z1 y
" h' Z5 w; _+ c0 k) s
It is not a method of detection of SoftICE but a possibility to crash the& ?2 }9 A1 {' D0 v! }6 L
system by intercepting int 01h and int 03h and redirecting them to another
8 \$ v3 T. c! U7 _routine.2 J4 A2 e+ s& R) ^" H6 I
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points0 C( ?+ d+ Q# C, i+ U7 B0 b
to the new routine to execute (hangs computer...)
; m7 z2 r, ?, I3 L- v
* `5 l! y/ M5 _8 S+ J    mov     ah, 25h2 j- \% k+ z/ x3 Y* |4 y* [" i
    mov     al, Int_Number (01h or 03h)  P5 H- Z3 q9 V
    mov     dx, offset New_Int_Routine
& c8 J# B* G5 C/ A5 U  ]* H7 t" V    int     21h
/ |( c+ D  d0 I5 W. _
+ a. H8 `- F& v3 R5 p, Q__________________________________________________________________________7 m$ }( C/ X3 F  |* |# \# v; D) y

- u7 p& }, ]& t) P. V4 [Method 09. H" x8 f' [1 W$ _
=========
3 E/ J  M: l  E/ b: j: a% B  ]$ u: `# v$ D% Y1 T7 j& L
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
# y$ \: w3 @$ Fperformed in ring0 (VxD or a ring3 app using the VxdCall).! x. U( f2 _! R8 W# \% M
The Get_DDB service is used to determine whether or not a VxD is installed/ F% p& S0 F/ s6 V; \. |
for the specified device and returns a Device Description Block (in ecx) for
  H5 B- U  B7 r! @$ a' e9 `that device if it is installed./ R" h4 g- t# x: k
; q9 v. p" C! H) t8 P4 _6 y/ Y3 K
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID! R2 E3 N+ g) b8 W& S
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
+ f. o! ^4 m( B   VMMCall Get_DDB
% O% N! F' r3 b' R& M   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed' C$ j4 f( T9 F& D2 u2 ^' [  h' l

. {6 L3 t2 t+ _Note as well that you can easily detect this method with SoftICE:
; j& c7 i: T9 J. R   bpx Get_DDB if ax==0202 || ax==7a5fh
% i- p. s! s/ K" K6 G) {
0 T& _# B; u7 ~3 ]6 `__________________________________________________________________________; w2 V  R0 z; G, r
% b4 R- f+ M) J6 P! {) \0 E/ u0 b/ ^
Method 10
  R- r6 ?# a- `6 k( ^: n6 t4 P/ n; j=========
: q- t4 Q' G$ Y6 E2 \: l
9 L6 O# ?& k9 ?) m=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
* D  a- M* P3 X5 A+ N. L  SoftICE while the option is enable!!
8 l+ P* i+ I% }+ {
1 `( |/ A) i- [2 x' T7 pThis trick is very efficient:& y" G( v. Z6 e7 M' ?3 x
by checking the Debug Registers, you can detect if SoftICE is loaded
. M+ X; X: Z$ H, S! |2 t(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if6 W! {5 ~4 c. o
there are some memory breakpoints set (dr0 to dr3) simply by reading their$ Y; E4 Q& ]( e; L
value (in ring0 only). Values can be manipulated and or changed as well
" N" @1 q$ n! Z5 X(clearing BPMs for instance)/ r: E: ]" T  w7 }+ C, ^

/ v( |+ m" o* z4 A0 F; l__________________________________________________________________________( y: y/ o, M- X8 b
% `8 m. f" O0 [. i+ y
Method 116 I6 O1 ]! x0 Q: g) `* M* o9 G
=========
8 G9 U  L# m6 `# x# v7 F/ ?/ O  U' k. {1 }! g, P
This method is most known as 'MeltICE' because it has been freely distributed0 q$ u* j9 i  C
via www.winfiles.com. However it was first used by NuMega people to allow: I% Q5 B9 B1 B' H
Symbol Loader to check if SoftICE was active or not (the code is located" v. X8 A# }4 q' J9 l3 h/ ?
inside nmtrans.dll).
8 X5 b3 E4 W9 N. B1 l: p* q- q5 s1 C9 O/ f5 a
The way it works is very simple:
& g9 V! a  B- J, @It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
2 K2 U1 r: K" zWinNT) with the CreateFileA API.% K& k7 V  g/ V' ]- Z

* j4 ?$ T9 {- n( U% o1 p$ j0 zHere is a sample (checking for 'SICE'):" D4 C: y2 @4 w/ e  o- X7 a

  d( Z+ ~% m5 D6 f* t6 M% z6 Y3 W' ABOOL IsSoftIce95Loaded()
- }7 H6 ~# u1 Q* l( i6 `  g1 R{
4 i. d; G6 b) I3 V   HANDLE hFile;  
) i' O8 V3 o* l   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,/ K1 J( ?2 V9 j' L' e
                      FILE_SHARE_READ | FILE_SHARE_WRITE,
/ u& L! `; B/ |$ ?" A% P                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);& N( f" f* a. ^! e* f' ~! c! a
   if( hFile != INVALID_HANDLE_VALUE ); @% V" f0 Y  \2 d& V/ e( |8 J# {
   {' d: l0 ?9 O4 O1 f" r
      CloseHandle(hFile);4 O+ A' c+ ]/ G- e9 Q
      return TRUE;- s; k. }/ Z" w( K! @4 n
   }
) D! {5 l$ g2 T8 V5 Y   return FALSE;, B* U( _; A; L2 i; S) F
}
/ T7 {+ ]! u1 ?2 |- U# e$ w4 M0 F! u2 s9 g' j( A" R( |/ b' E
Although this trick calls the CreateFileA function, don't even expect to be& S/ {& k5 D& q" s
able to intercept it by installing a IFS hook: it will not work, no way!
! z3 u" x3 g! {In fact, after the call to CreateFileA it will get through VWIN32 0x001F" K. F. ]* g3 q# h8 p' l. a
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)* N8 f0 K& p% N# E" Z
and then browse the DDB list until it find the VxD and its DDB_Control_Proc2 b8 R; A; n. K5 o
field.
' {% B7 d& @$ n  ~* ^In fact, its purpose is not to load/unload VxDs but only to send a
' ]8 l% Q7 E/ U+ @, s' hW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
6 H2 C. k% i. ato the VxD Control_Dispatch proc (how the hell a shareware soft could try! `5 {. S- _( e6 \( G; j
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
7 y- ^8 s0 Z- Y2 z8 x( p4 pIf the VxD is loaded, it will always clear eax and the Carry flag to allow
5 T  F0 [" R0 X+ x3 ?9 c4 Kits handle to be opened and then, will be detected.% V- _, q  ^* j" o. v' _* d
You can check that simply by hooking Winice.exe control proc entry point
% u% o/ W8 H1 \; s) uwhile running MeltICE.
4 S  f+ B! Q) U& m
; g, v8 ]5 ~; G3 ]- w5 |3 L/ [9 P  b# A4 ]
  00401067:  push      00402025    ; \\.\SICE1 L# |, q; k9 O" ~% H
  0040106C:  call      CreateFileA
. l; d6 @- ]- g0 L; m5 F2 x  00401071:  cmp       eax,-001% }- S0 G, ?0 N6 n
  00401074:  je        004010915 s1 y% H8 a# h7 v- B4 g7 m% j/ H
6 n% }/ |- [) K) Z: G; S* ]8 v

3 F: f( D# z/ J" R4 X. \) eThere could be hundreds of BPX you could use to detect this trick.
# G+ [9 ^  d3 y" X% a6 H-The most classical one is:
$ M2 A. f' l$ a# c# D  J3 o  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
! s, h) n# l! E! a2 R( U2 _    *(esp-&gt;4+4)=='NTIC'/ x3 K# A# t( g( F
/ Y) j$ e9 `9 D  ^, A# s! U$ Z  P
-The most exotic ones (could be very slooooow :-() }: G5 g, F" ^( j
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
  x  S% X1 u8 h2 I; b1 ~     ;will break 3 times :-(9 M/ m6 T7 ^$ d6 E% c4 d3 A3 y

# m% G; L% K  K2 [. `2 h, }, ~-or (a bit) faster: 9 y1 w7 ~9 i* ]! @$ b1 E
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')$ |6 n/ U/ T# ~1 X
& \8 I8 }: W+ @* s
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
) [' X! w1 F7 f2 t1 B     ;will break 3 times :-(
# K9 |1 a4 Z+ M/ @; G% A2 b9 X( w9 g) S/ L& F& r( b+ B
-Much faster:
) F2 t6 p6 d' b) m8 O4 T   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
# K! T$ a" O4 U- ^
+ s: T; T' {7 v& r( {# {Note also that some programs (like AZPR3.00) use de old 16-bit _lopen: V/ B  J" L8 K# a3 c/ z- ?
function to do the same job:( [; P! |# Q/ c& q. ~9 D

  k" A  @6 O5 L7 r+ c   push    00                        ; OF_READ! L0 o0 \# h1 Y( E
   mov     eax,[00656634]            ; '\\.\SICE',0: N1 i" f1 R' q
   push    eax
/ Z  e( t; U* |$ a   call    KERNEL32!_lopen! T+ P9 D+ `) y; U4 J$ l% q6 W
   inc     eax
! _4 n, e" T  |4 L2 Z& ]   jnz     00650589                  ; detected
7 O4 j/ @$ ~/ Y+ h   push    00                        ; OF_READ$ l# x9 u$ J( G) n% A- e
   mov     eax,[00656638]            ; '\\.\SICE'3 Z1 Y0 z0 a6 @
   push    eax6 _# g  f% s' C, T, H3 t/ n
   call    KERNEL32!_lopen# p$ `& m# ?, m- N
   inc     eax  d& |) d  D; s# S$ ]# A" |
   jz      006505ae                  ; not detected
! L' E9 {/ T0 d$ B$ f& f$ _$ o) Y3 y( E) `

, m: M9 b& a1 N# O9 D5 s; Q__________________________________________________________________________
* x* i* w  k  B  x
5 r+ X! {+ c! xMethod 123 O3 o  V/ i4 m; e$ L
=========9 ^) R. o9 G1 Z+ [+ o; I& O) Y
+ a9 G+ E8 x1 B9 {+ S" A
This trick is similar to int41h/4fh Debugger installation check (code 05
8 c8 Z, Z( j3 Z0 ~, ^3 a$ c0 a&amp; 06) but very limited because it's only available for Win95/98 (not NT)
' X; u0 n4 x4 Das it uses the VxDCall backdoor. This detection was found in Bleem Demo.  L" x5 ^( A% I+ e

, E! n; ^3 G6 w5 \9 l  G   push  0000004fh         ; function 4fh
4 T/ l* Z5 `) m+ _3 ]0 X   push  002a002ah         ; high word specifies which VxD (VWIN32)
: g5 A0 T6 p  k+ v                           ; low word specifies which service
, w% y1 [* {+ X* s3 x8 V                             (VWIN32_Int41Dispatch)
# X! v, t  ?0 x   call  Kernel32!ORD_001  ; VxdCall+ O3 R2 _! O8 @- ?. g0 a
   cmp   ax, 0f386h        ; magic number returned by system debuggers8 U3 K0 P0 s% Q. x* i
   jz    SoftICE_detected
- s8 R  v8 w. d% n+ E
" ?8 ^: O& U9 U! c' nHere again, several ways to detect it:% i* v" _& ?. K# A9 O- L
" Z" J: ^$ l9 Y& _. \
    BPINT 41 if ax==4f1 c- ?* \% z2 b6 j$ q, v

. `: y/ E. ~* p- k0 R) e    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one0 a2 l* @. ]( \
# r% l+ I7 F% a. s
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
6 A2 ^" V6 F' A3 q2 k0 J4 N5 V* j- _2 z6 o7 R! D" ~
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
7 q- N6 P/ l. Q4 [) Q
$ P5 d3 A' Z1 d* Z__________________________________________________________________________
; m4 q) n! n! r
& Q0 Q# r2 y8 z9 e0 AMethod 13
& d8 l9 |, z6 i- L8 {4 R=========# Y( |& d- _" g5 O) N7 U* [

9 C( O8 Z' t7 V3 z9 @! hNot a real method of detection, but a good way to know if SoftICE is
9 ?9 F% O2 b, T: R2 @  g4 Ninstalled on a computer and to locate its installation directory.3 N: x/ Y$ Q3 x6 m; z  A# ]- s- k/ d
It is used by few softs which access the following registry keys (usually #2) :! M( `; D5 T- V
8 ~' b" R8 W& W
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
6 j5 }. z% t  A9 L% Q# K3 W7 }\Uninstall\SoftICE
; Q+ r- m2 p! F2 V9 b2 }& |-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE/ U6 ], d6 R1 Y. ~! O3 v( Z
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion0 K. y0 Q/ c9 I/ i7 d+ @" E7 f
\App Paths\Loader32.Exe
+ b$ u3 g/ q0 y! L& L3 t4 C* K2 I, V3 j6 U, P/ ?
  F1 k; c1 \$ e
Note that some nasty apps could then erase all files from SoftICE directory
+ V$ J7 u- S% d(I faced that once :-(. [# q- e) ?' d' k7 ]$ a
9 Q- d9 \+ ]$ @! i% u- J6 j
Useful breakpoint to detect it:
' A- R7 C- a9 P' A; w  [/ M) B
" W2 E6 g! }2 d7 Y$ d! v9 @% d     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'4 o+ n1 V+ G) p6 L& ?, X1 z
) a2 l) m- |2 H, m
__________________________________________________________________________
( p. K1 ^/ C* U2 [$ s: F
" O) m- e& Y- \$ \3 ]
( i) v+ G6 O5 W5 v: X$ QMethod 14 % E4 y$ n- A5 Q$ b) [8 Z5 d3 }
=========
, @' a$ L  Y8 j2 R
, [) l# b0 k$ NA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose. l& P8 I( P4 }* H! n' \4 W. p
is to determines whether a debugger is running on your system (ring0 only).7 N7 s8 e2 I1 R& N+ K
7 q$ _" v/ ?0 k4 {$ K3 X
   VMMCall Test_Debug_Installed
4 {3 B% P( {* @- G   je      not_installed
2 x( F+ t; f2 C9 m5 K, C) W, ~; a" A2 J3 m! }4 Q+ w& m
This service just checks a flag.
/ X& k! _9 V: D1 i) g</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部