About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500># P! B1 e$ G# s# I' j
<TBODY>6 m+ A& t4 }+ g. Q  Q4 g& _
<TR>
9 z' y( t2 X/ ]) U<TD><PRE>Method 01
; ~! ]1 F/ B( [=========" P) w/ [% D- ^  f& c" w

9 e0 |/ n. B3 T/ S1 s- jThis method of detection of SoftICE (as well as the following one) is% l, t) c( o) T, D0 _
used by the majority of packers/encryptors found on Internet.+ g) f% s. K8 y0 Z
It seeks the signature of BoundsChecker in SoftICE. h8 o" {1 |; u% H: y1 l0 S
3 U8 N3 U/ n$ q" g2 X3 l8 m3 N. F& ^
    mov     ebp, 04243484Bh        ; 'BCHK'# w8 t2 u: A. ^
    mov     ax, 04h
* J2 i; d: K. X: G# K' u3 M9 u    int     3       5 N3 A5 @( G; U; I+ B
    cmp     al,4& m- h$ L( w) u0 {
    jnz     SoftICE_Detected9 A9 s, N6 j2 `1 N/ S/ t# F; C
8 K+ L1 F: C& t1 k
___________________________________________________________________________
) T, Q% |/ ]/ D, P5 q5 T
+ `) E( l% v  q: rMethod 023 K+ I# m2 _6 j! O3 x; A* r8 t7 u9 z) C
=========
/ g+ ?5 I3 S% r, k+ y# k: b* x
9 r' i" {, _  A, d. zStill a method very much used (perhaps the most frequent one).  It is used' `' n" r6 `( F; l1 k$ o/ U
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
. y+ v+ Q5 z  T  H7 ]$ ]or execute SoftICE commands...
; Q- _( P4 [- b: t/ \( hIt is also used to crash SoftICE and to force it to execute any commands* X8 A: x5 [6 q/ B
(HBOOT...) :-((  ) M' l+ m+ U% C% G* ~

9 _" s( O( H) N0 n! i; K% wHere is a quick description:- A3 _+ g6 s. V1 I# A4 @# U7 E, x
-AX = 0910h   (Display string in SIce windows)
5 \5 g6 n& f, ?+ \- e' D5 c7 p" G-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
9 H; y+ e) i, q1 k. H/ J: x-AX = 0912h   (Get breakpoint infos)
$ ?( L  Y: }& Q$ _4 P* A-AX = 0913h   (Set Sice breakpoints)
* ~4 q8 f9 D* t4 G3 F-AX = 0914h   (Remove SIce breakoints)
& e* P* x) |  `& E( a
$ R7 w; q, `1 \4 G7 v5 P& @5 ^% CEach time you'll meet this trick, you'll see:  O) N! q5 u* o. `& I, p0 B
-SI = 4647h
+ d$ O4 O2 c! T! k6 P2 E( X-DI = 4A4Dh* F4 a/ D2 h) E
Which are the 'magic values' used by SoftIce.
4 _1 ?: O8 e: I' G; y3 S% {For more informations, see "Ralf Brown Interrupt list" chapter int 03h.+ L+ I/ O" y( v# o  D5 A

+ f; \& ^9 h7 A" a4 N- K, HHere is one example from the file "Haspinst.exe" which is the dongle HASP
. [- g- l+ n4 l: c3 }Envelope utility use to protect DOS applications:0 w; `3 q/ o+ B9 P. l

1 B9 {% v8 n/ S6 h$ H. Z6 ^. X6 F, y- M2 }4 d5 p$ W% u
4C19:0095   MOV    AX,0911  ; execute command.
7 M' E& A. p; z4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
  W( h; z. q; F: e5 [1 `& V4C19:009A   MOV    SI,4647  ; 1st magic value.
, @( h# n8 R3 N( q0 w4C19:009D   MOV    DI,4A4D  ; 2nd magic value.- I) i- t  @, N% R, |( F
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
/ Z/ l, ]  b. ~& Q4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
- G, j  R7 {3 R) O4C19:00A4   INC    CX
5 [0 b0 Z& D, z9 Z  N" g% Q4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
' g1 e2 ]9 w$ a3 Q1 G* X4C19:00A8   JB     0095     ; 6 different commands.
6 I8 L" c- x/ w9 e( x' |4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
/ ~3 C: I3 ?* {4 L1 S  [% M2 J5 D4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
" D5 S3 |$ [. c0 u! d( R" [2 @3 ~5 D* m
7 v# R6 \' x+ y; s+ tThe program will execute 6 different SIce commands located at ds:dx, which
& J8 t1 Y9 S4 c* R  Q3 Pare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
4 b) C+ T$ s. H! t+ k; q& A; u" L  C- M
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
" E# l2 R: K- @  R___________________________________________________________________________
0 B% M$ H1 W8 ^; x) d, k  j+ ^, x- F
) P5 b- \7 G% `6 j' u# J
Method 03
( m$ g8 u. L4 z6 W$ f=========
' ~( R/ O0 B8 j3 _9 {! D2 u( H" \% D1 n# b
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
( |, ?! W' r& d  y; T7 Q& x(API Get entry point)
3 c* G" e3 o2 F, D' D: x# P        
! u  u- L4 X! h, B1 s; Q" Y8 {! W( w' X
    xor     di,di
* `1 X  r) i) S$ n7 ^8 v) j: z    mov     es,di# y5 z+ r7 H- l
    mov     ax, 1684h      
, n2 H4 D0 \/ z, M( `" m! S    mov     bx, 0202h       ; VxD ID of winice( M' S( c9 H* n' U& P
    int     2Fh
6 P( _# u$ D& o# F2 G% H    mov     ax, es          ; ES:DI -&gt; VxD API entry point
! ]$ Y' @$ X" E/ d( h$ y% Q" c9 @    add     ax, di3 x2 M  G& R; `
    test    ax,ax, l, e% U- H# f- X' q
    jnz     SoftICE_Detected
. G' A7 J9 w4 t3 C; w9 S# p3 e; f" Q( J  {/ S
___________________________________________________________________________+ d- m1 f7 }# W( d# h

+ Z! m' X6 V. P3 J3 uMethod 04
# b* I3 W( _( N: C) `- M=========
$ w$ \! ?+ e7 _$ e- A5 d0 ?& }, Z  F. O3 F0 Z  h
Method identical to the preceding one except that it seeks the ID of SoftICE
3 Q7 ?7 {/ `- f  c7 L; G2 g" W& YGFX VxD.
, H0 V3 P* X  u: a3 d
- ^0 y2 k* _  g* W3 z: |" @- y    xor     di,di
0 _6 p. E. @$ X: S) g' S    mov     es,di5 y) G; p$ y: u( |* O: N# {+ U, Q
    mov     ax, 1684h      
, s4 ~; I% d+ o$ O    mov     bx, 7a5Fh       ; VxD ID of SIWVID" |0 n3 J8 l; K" n: H  O
    int     2fh
) S, K$ Q6 Q0 T; X5 c    mov     ax, es          ; ES:DI -&gt; VxD API entry point0 T; W3 F9 T) k3 X( g2 j3 F
    add     ax, di" @" W& a" j+ q+ u
    test    ax,ax
: Q4 X  h" k, i8 R8 ?6 t    jnz     SoftICE_Detected! E1 c0 }2 ^8 [% O7 k
7 E* b1 _+ k% m+ C1 h1 e" W
__________________________________________________________________________
# D- t  g$ c9 d% R7 e% p$ A3 [( w, q5 O
# M+ Q3 _6 K' {& e4 G) U: a/ x' f$ V
Method 055 J! L0 E' @7 f( V
=========: f! r% Y2 y) b+ t/ a2 f1 m
3 \  e  ~: T7 x
Method seeking the 'magic number' 0F386h returned (in ax) by all system0 N( J4 n9 z1 T; U* b
debugger. It calls the int 41h, function 4Fh.
5 Z: D. H: Q; ]3 vThere are several alternatives.  
7 ~( K$ P* u; }+ n2 p) @* b) f
/ P7 A  c; a5 E. VThe following one is the simplest:. B7 T  t2 d- E) [" @7 |

% J- s, m" I- w/ L/ F. Y    mov     ax,4fh
. f  Q- t+ F2 h7 S+ H1 j    int     41h+ L5 d, U- i& w$ X
    cmp     ax, 0F386* r6 A1 _/ {8 M$ [; S
    jz      SoftICE_detected
. V3 O# x" x9 C  f$ b  Y. d) }) S6 Z0 `

7 j9 Z+ y* r. Z. |/ p  MNext method as well as the following one are 2 examples from Stone's ! A# [6 p" S1 O- ^0 l
"stn-wid.zip" (www.cracking.net):
) s0 R1 c# x+ c1 ]: Q: R* E; M1 X7 l& M+ K$ Y5 {
    mov     bx, cs
# h& |% }7 |' L4 d9 w    lea     dx, int41handler2
7 X- K! Y; A9 G% S    xchg    dx, es:[41h*4]6 ~  w5 X1 K+ X/ f8 v
    xchg    bx, es:[41h*4+2]
8 u0 m. ]* i" O. f; z. J7 Z    mov     ax,4fh
5 r1 ~: @+ `! ^5 L    int     41h
6 o+ A6 K6 r* H  [: o7 C    xchg    dx, es:[41h*4]
' L1 I/ r9 C3 T. g6 K) @' Y: f    xchg    bx, es:[41h*4+2]  ^4 h% D) ~" \4 o* W
    cmp     ax, 0f386h, J7 D. t+ R( m) e6 `1 q
    jz      SoftICE_detected# O* @! _* V' n* n

# y6 {& y5 Q; j' q0 ]. s" ?. hint41handler2 PROC
% C' i" y0 L, ^  {- n    iret
7 K; ^" X- v+ u+ M9 [int41handler2 ENDP
: f4 ^. r" X- K8 J/ v) n% a, V. r* \; [
- ~0 _: M  b8 o5 Q) w
_________________________________________________________________________9 N% N# P% t# t( J% g4 {) N

- t9 e7 g4 L" P* R; Y" `1 W; m$ X( ^7 ~3 I2 d# N2 A  X
Method 06
+ E* }# l2 u# c=========5 B1 v- W  N* R4 k2 W
* a* z) T7 b4 k6 K- H
+ M2 y7 S* k! Y
2nd method similar to the preceding one but more difficult to detect:& A0 o/ n; `  N/ B5 L; X
. P4 y" K% P. _& Z5 [2 K0 l
- d* y/ f) w% m
int41handler PROC0 U2 z# D( m. @6 w: A9 l
    mov     cl,al$ W5 t( {3 F$ ?$ h, O( {5 P. h' b
    iret
. p* H6 Z3 @) s4 b8 _* Lint41handler ENDP  R/ @7 F1 |" _* }8 f: s: R
* ]$ ~3 q: H* t2 I9 F  [
4 a+ O1 N: W0 v# m! b* _
    xor     ax,ax
! w2 g8 V+ S! R6 M    mov     es,ax
' d! @/ x( T- r4 }* b    mov     bx, cs
* w6 l- ?+ Y+ O, [7 P+ Q    lea     dx, int41handler) O- S- B4 g) x
    xchg    dx, es:[41h*4]# E' P& ^7 k5 ]- x* Y& l
    xchg    bx, es:[41h*4+2]
: G( r8 d, \: p    in      al, 40h8 t. Y$ @% V# Q# _8 R
    xor     cx,cx
7 j3 j& q2 n2 {2 Z  Q. s5 A    int     41h# H" D; v/ {- P) x; J4 |
    xchg    dx, es:[41h*4]* z+ c! q1 t$ W1 \, A' a) Z
    xchg    bx, es:[41h*4+2]
. f+ e; j$ k5 Q4 ~    cmp     cl,al$ Z( ^$ E( p9 Y; L7 f5 o
    jnz     SoftICE_detected
" B# I6 X0 s0 Z7 U9 N8 x* w& b' K  a: F5 p+ c' S, D3 X
_________________________________________________________________________* m5 |9 `0 L" I' g+ ^/ z
5 [- C( J3 @( a& K' {+ x! v" e
Method 07( K: t6 v# C0 l8 J/ o1 j! r
=========
7 d: Q$ X( g2 J) U' W) g4 d; U. ]6 f
Method of detection of the WinICE handler in the int68h (V86)" ], h( L5 C- \/ ?/ \, v7 A0 `
: R# c. S8 T% z+ B  o
    mov     ah,43h2 F  v0 l9 }! L6 `& F  w
    int     68h
( W: f' d9 G0 r2 [( Z0 }* A& Y    cmp     ax,0F386h
. d# e" g: M  o) r- w$ l$ Y. c    jz      SoftICE_Detected
& D5 W2 Q! e9 `4 Y4 Y1 m1 E5 a
, d6 G! K# n0 b1 e
& \9 N8 S) Y" m=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit0 B1 X+ {: `# {! ^( C" T" {
   app like this:
" L8 C; z! B9 I; P+ O+ h0 e( Z* Z/ b+ _" g5 l- C6 K- I- G
   BPX exec_int if ax==689 R* O) f$ u$ f; {! m
   (function called is located at byte ptr [ebp+1Dh] and client eip is
, o/ H) y& D9 k5 M! m- `   located at [ebp+48h] for 32Bit apps)
7 T) X3 h3 [5 t5 k) f__________________________________________________________________________9 B- n& ^  K0 r! m9 T
* T5 x; {9 x5 C
3 g5 c! I3 n# c$ Z
Method 088 e/ ^3 c: i. }' m
=========! l3 n/ Z& G( K0 e

: s5 j% I; u% V5 K" QIt is not a method of detection of SoftICE but a possibility to crash the- N+ n8 V0 L4 Q4 u  p, i
system by intercepting int 01h and int 03h and redirecting them to another% x$ O( x& F0 N
routine.5 Y# j4 y4 A, g9 A( J# K
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
8 c/ I* h! u" mto the new routine to execute (hangs computer...)
8 v" A% X/ {6 L9 N& @
/ }" O: t$ c3 B! U/ r  `    mov     ah, 25h
' K8 J% U* a3 |2 g' W- [* k& o    mov     al, Int_Number (01h or 03h)
# k" Z: Z: x1 b1 j    mov     dx, offset New_Int_Routine
' s, I- O# @. }1 q    int     21h0 p5 j3 f3 r' h; t# @
" j$ S$ \3 f/ l
__________________________________________________________________________# g7 ?0 n  O& G3 r) b6 e

$ z! G7 k0 l7 F/ K3 T8 v7 o2 p- QMethod 09+ b# z/ f% y; Z- c; p4 d; X
=========
4 u* O0 m1 v! e1 i) B% F$ W8 @2 ]. B( l$ i  F
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only  A, ?% b8 r( L6 ]7 S' b4 b+ m
performed in ring0 (VxD or a ring3 app using the VxdCall).
( k  d2 z, i0 l1 L5 T9 ZThe Get_DDB service is used to determine whether or not a VxD is installed
0 ?  f$ N; z8 J; tfor the specified device and returns a Device Description Block (in ecx) for
( @' T5 l8 F2 |" ~+ s1 \that device if it is installed.  f% Z$ Q( N: M  T. J' x5 E" j

# C- b) u0 D, w2 S# K   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
4 Q! D6 m, i. p0 p' ^2 Y! R4 y   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
+ h/ v; J% i+ T1 O2 L, a   VMMCall Get_DDB; N2 A# ?% m) \: ?% f4 B! C2 _2 ]
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
8 n/ O# l# \2 k, s3 C5 t
* K# I% J7 }+ h+ Z1 |) eNote as well that you can easily detect this method with SoftICE:0 k+ u' V: o! C$ O% E& s
   bpx Get_DDB if ax==0202 || ax==7a5fh
  R* U% F) u+ e- F" p0 w
+ w% k7 v- ?3 @5 L& u__________________________________________________________________________" P' U! @3 Q' _; d8 [
$ T1 _% Y# y4 c
Method 104 V. ^* A' X; S' a, b7 C4 d
=========; n0 h3 z+ @3 l) W  k+ z$ i
( P* J# R0 ?  P) x/ `9 b3 a
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with1 V3 e2 m. y3 f; X
  SoftICE while the option is enable!!4 Q$ ^2 X2 B4 ?/ z

4 h- u. I- c: ?7 CThis trick is very efficient:
$ G1 n$ `6 s$ r0 M8 u7 ?by checking the Debug Registers, you can detect if SoftICE is loaded
. j/ x) r* i( Y& w(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if, v8 ]* R, Y' Z7 c& D  E3 q
there are some memory breakpoints set (dr0 to dr3) simply by reading their8 N8 g! X6 y& x+ t/ M
value (in ring0 only). Values can be manipulated and or changed as well& Q' \$ H! u" z3 A# E
(clearing BPMs for instance)2 u! \2 q8 n4 h, \  ]" c# V
) T5 ]7 x& M9 T3 e/ d
__________________________________________________________________________. N! v) {3 b5 `
5 V  i# J( [, A) J
Method 11
+ P3 ]2 J9 |; F& @0 e  G1 W# o=========( z- h* s2 M3 u8 r

* P( D$ |" _6 C4 SThis method is most known as 'MeltICE' because it has been freely distributed
3 K  b! S8 e- \. |4 h- U* }via www.winfiles.com. However it was first used by NuMega people to allow
, U( I- d; K2 @# w+ ~- qSymbol Loader to check if SoftICE was active or not (the code is located, S  ^+ D+ d  W3 j* Z4 c+ B2 h
inside nmtrans.dll).
7 m9 K" c4 {: I: k; K* ]
# o2 A5 F8 Y; n! C' q6 p8 ]The way it works is very simple:, G8 R0 f6 P7 N7 s* R
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
( [4 y% r& S0 |" k. P& c* [# IWinNT) with the CreateFileA API.
0 H4 ?- F5 o: O$ n! Y- n. M, o+ c2 m7 P9 T0 r& X8 q0 F( H7 ?
Here is a sample (checking for 'SICE'):5 }4 f8 l& B7 e2 g. w

9 M; Z" t5 x# ^9 JBOOL IsSoftIce95Loaded()1 K. u% u/ [1 O2 D7 s, O
{/ R3 W8 C2 j- a4 ^( m) g' w
   HANDLE hFile;  4 L) v4 |- ~$ R: J
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
( H9 k1 e; G( B& R. E% c6 s4 W                      FILE_SHARE_READ | FILE_SHARE_WRITE,  ~8 G+ d4 Q5 ?/ C5 `
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
$ k6 R( ?/ Q! N8 T- Z9 L4 Y* w   if( hFile != INVALID_HANDLE_VALUE )
+ q: s% {5 X9 {! f   {+ ?8 E2 u$ ]' ]% C0 Y6 ^, @
      CloseHandle(hFile);1 M# f7 N6 Z6 L) T( [
      return TRUE;! F3 F+ g. ~" L8 C+ F
   }; R/ r1 W" t  J  G7 X1 k
   return FALSE;
) ^, B2 U7 l: S& }/ o}
( Z/ W# [3 A& a% s
- I6 H3 S8 {6 B6 t6 T# h2 LAlthough this trick calls the CreateFileA function, don't even expect to be% Y# V6 B1 E0 W
able to intercept it by installing a IFS hook: it will not work, no way!% L( _1 `- \) T, _& V, Z5 A
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
  q, @0 p/ Q  mservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)+ f( x* E. Y- g6 ^  }
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
) C6 I. `& g9 w/ ?field.
5 T5 K7 Y% v8 _In fact, its purpose is not to load/unload VxDs but only to send a 8 A& N6 B$ O( s0 _; K. N
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
& ?8 g8 B; g( d' hto the VxD Control_Dispatch proc (how the hell a shareware soft could try
# Y( ?8 x' X. c- B1 D- Cto load/unload a non-dynamically loadable driver such as SoftICE ;-).2 p6 _+ S+ \3 \& [; j# @4 C
If the VxD is loaded, it will always clear eax and the Carry flag to allow
$ Y: X2 p# M3 L$ Hits handle to be opened and then, will be detected.
8 s6 J0 Q* s5 T/ h) fYou can check that simply by hooking Winice.exe control proc entry point" X  |. l$ S- n2 d
while running MeltICE.7 V# }0 p' d3 f3 p2 @
+ }  C" T$ ~  B  [  V  _( h

$ J3 T# b$ V- |- q1 A. r/ N  00401067:  push      00402025    ; \\.\SICE# J: n5 X8 H) D$ S$ m
  0040106C:  call      CreateFileA
8 s# G1 `9 K% {8 S8 r. P, l  00401071:  cmp       eax,-001  r" i! g' z! D: _$ L1 o
  00401074:  je        00401091
+ o) G% B! V$ O- h' [$ w$ W  B, S8 V! h# X& t

- h6 H+ F# r. ^There could be hundreds of BPX you could use to detect this trick.  ?9 M0 `& `, e* y  f
-The most classical one is:% z  r/ w6 A' f1 g% Z
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||# L) f' ]7 `, F
    *(esp-&gt;4+4)=='NTIC'+ m% b7 e* ^( d
% X: h" i2 m/ O" i: `2 i( I
-The most exotic ones (could be very slooooow :-(2 j: G+ J1 z4 s( ~
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
! k2 c: I6 ?) S( x. ]- x     ;will break 3 times :-(' n% P" g) ~4 F; \$ y# U, _

" a8 _( h6 s! b* v-or (a bit) faster:
. J6 g' z9 j  ~% m) t& ]   BPINT 30 if (*edi=='SICE' || *edi=='SIWV'); j* y  P) ~! z! x1 n, w
7 _5 H3 z& N8 g, b7 d% p9 @( ^: m# P6 I0 p
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  ) G1 }5 i' `$ ~5 b
     ;will break 3 times :-(; [7 i# Q! r. Y! V& K9 D# E& H) Z

# v" K- D  o" S-Much faster:& Q) M% P& [$ _- Q5 @" O
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
7 l# s8 R/ Y6 I) t+ b' ~( g9 K* h7 @$ j9 P( x/ n
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
+ X4 I1 M1 {  S# q. v+ w) Ifunction to do the same job:
* Z. ]; x$ }# u
. g0 J2 I1 u& S; R   push    00                        ; OF_READ& S' j2 j! x+ {3 }0 D1 H
   mov     eax,[00656634]            ; '\\.\SICE',03 S2 H" I  E- X9 J
   push    eax
! s- B+ m5 Z. j% b, C   call    KERNEL32!_lopen+ v. z, j3 W6 h" R
   inc     eax
& }) `9 N7 }3 W) f% @   jnz     00650589                  ; detected
( q" K" Y5 Q. R  p7 x$ X- E4 R   push    00                        ; OF_READ, c6 |. j0 U  r! w
   mov     eax,[00656638]            ; '\\.\SICE'
1 u+ a& L! ^- r. F1 y  S& p) Z   push    eax: q( i2 Q' u1 V% ]6 {
   call    KERNEL32!_lopen, b! I$ _1 i7 \4 ^
   inc     eax* `! w8 _% M' e4 e
   jz      006505ae                  ; not detected9 N6 g0 V; S/ k# o' o

' k% c3 [* T+ e) t' k( c  }
% O+ m% ]% G5 H* n9 y& k7 Y" b8 Q1 r__________________________________________________________________________
  h) h9 O( M. C$ m* p  L% [. o% ~& U
Method 12
$ q0 {5 s' L" Q) `=========
6 w( E- a) d9 I  l
* Z. t* ]3 ~* ^+ g6 IThis trick is similar to int41h/4fh Debugger installation check (code 05
) Z+ L1 ^0 l, Q2 h. s; g&amp; 06) but very limited because it's only available for Win95/98 (not NT). m1 O( J% ?: Q- q, l) o4 _
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
# }( a! p3 R2 U' D& c8 \8 K5 k+ `7 s: M( c" C
   push  0000004fh         ; function 4fh5 j! o+ K3 p7 q2 D$ m: |$ j
   push  002a002ah         ; high word specifies which VxD (VWIN32)
( e4 O) g. K& O                           ; low word specifies which service
) c7 K6 H+ h9 q) R% @, p                             (VWIN32_Int41Dispatch)
0 g, N/ e5 d: D( `% e   call  Kernel32!ORD_001  ; VxdCall
& q; v5 q- G2 F: C8 ~$ q' i0 X8 i! F/ J$ c   cmp   ax, 0f386h        ; magic number returned by system debuggers
$ d. f4 e) n( h3 @   jz    SoftICE_detected* d8 Z! \$ w0 i% u' k$ |' b
/ [+ V( ~9 g; N  ~# w% }" b& }9 U
Here again, several ways to detect it:# A8 w  k! ?4 f: A, K2 I( Q! {% i

* a9 s. V# U4 g    BPINT 41 if ax==4f9 w; w9 @. ~/ ?0 m3 `
$ j" E. a; F# ?4 a* _" }9 a
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one9 ]" }& K% P& p% x* K# C# H  ~7 y" x6 l

  K0 X" ]+ Z+ i$ H! y1 _# m    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
! a4 n0 b/ I  t% L$ a3 W8 w" ~3 X. ^/ y; m/ q
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
5 H! E. c) u  g! [% ^3 D( y! n5 \+ ?6 q; K& W
__________________________________________________________________________
4 G- Y, c0 P: h; T" {* A$ C2 _9 ^' V$ W7 E7 a  Y
Method 137 N" \" w; ?7 A7 Y' @
=========
* }! X5 v6 P' I# \* \- Y$ _0 T% b9 t- ]
Not a real method of detection, but a good way to know if SoftICE is
8 r: V7 K6 i0 L8 \/ I# Cinstalled on a computer and to locate its installation directory.
1 ^5 c0 {% g' lIt is used by few softs which access the following registry keys (usually #2) :7 s5 i: O- d2 I

: N: x; r5 d/ l-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion; X3 T* w( k/ {& X1 L" @
\Uninstall\SoftICE
$ H3 z$ W1 \  w9 z, y. P5 `  h* x-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE5 E7 X6 J) t3 L: g
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion& v" T# K% R. V9 i5 ~" J5 P% i# [
\App Paths\Loader32.Exe: s* C" G/ Z) D' w: {+ p
8 g; H0 A# f/ a3 K+ g4 a# b

4 s5 d# u  w, W' JNote that some nasty apps could then erase all files from SoftICE directory# z# @" P, b- V: h/ {6 g
(I faced that once :-(7 Q; _' X5 t- I
2 q5 o1 @# P9 H1 H, z
Useful breakpoint to detect it:
% u, l5 f- m" o- T, g
4 _, q8 u+ J6 ^5 J' `6 k     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
4 ^) k1 e" W$ q5 I. _8 G
' M: ~: q1 _* `# {# e! x6 q# A__________________________________________________________________________
0 n: t/ u5 a& J$ P, ~$ ~  ]' d' h$ R' M; q- h
  d' f' r$ X% B5 Z' J
Method 14
; O: [1 ^  `8 b* m# z! i=========
' v% J, Z* x' w6 ]& e) g4 q7 c; p/ v
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose2 F6 d7 o5 u; a6 b9 e+ [& _
is to determines whether a debugger is running on your system (ring0 only).
* z, t- V  w( J, }7 e6 x6 r# K$ w! m, K: q- O6 L5 z1 h
   VMMCall Test_Debug_Installed7 M4 y! A5 s5 |% b
   je      not_installed8 Z# I3 p3 d( Q& k( Y0 t# e

. j; w2 c* {* \This service just checks a flag.
% j! {+ Z3 Y( W3 B# R$ N( C  d1 H; |</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部