About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
9 K  J- H1 H; _<TBODY>' r2 l; Q9 |, s8 C5 P' H
<TR>
$ v- R7 z, p* u0 o<TD><PRE>Method 01 / N; C5 R+ h0 c
=========8 O! n) [- ~7 }
. R; k( \# B: K5 P0 @
This method of detection of SoftICE (as well as the following one) is
; q: T5 c& e, h3 u: ?used by the majority of packers/encryptors found on Internet.
( L; J( P, l7 s( p* LIt seeks the signature of BoundsChecker in SoftICE
' t. T- }( G  q- P- e( F# T
8 y+ h" t  ^; e" q2 B    mov     ebp, 04243484Bh        ; 'BCHK'0 B7 r/ P9 x& M. ]7 r4 ?- i' \
    mov     ax, 04h
3 q" {& S/ `- M* z    int     3       $ o4 o4 \) w# ~4 x! c  O1 ]. n
    cmp     al,4( D+ d6 a; r' Z# \
    jnz     SoftICE_Detected; ]  M6 I6 K  \/ z

5 }8 y; t# d  ^& |___________________________________________________________________________
* H6 H$ Z0 z! L! n5 |1 t- Q% |/ f) J1 J3 n. ?# h, l8 _* Z
Method 025 _( O* `# u" H/ E- F
=========
$ q/ T2 N0 f$ q! V
  z" y2 B6 B  m2 @Still a method very much used (perhaps the most frequent one).  It is used0 |( @3 J+ {! [4 A( Z: p2 G6 b; W
to get SoftICE 'Back Door commands' which gives infos on Breakpoints," \+ e; S2 G' E
or execute SoftICE commands...2 z& s+ L. m0 y5 y
It is also used to crash SoftICE and to force it to execute any commands
3 m' M3 W& r! f1 l7 ]8 z(HBOOT...) :-((  
; |* i6 _) q$ m6 @+ k* S; Z" t  [# @! R+ G
Here is a quick description:1 m. ]- C$ O9 q% b& U, l1 r
-AX = 0910h   (Display string in SIce windows)
& P, A; G- P' B4 V$ S& l1 K-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
. y9 b- P: Z; A+ m# \9 h-AX = 0912h   (Get breakpoint infos)
. I8 Z2 |  y, E+ E% L& F-AX = 0913h   (Set Sice breakpoints)) ]2 i/ [; r$ X
-AX = 0914h   (Remove SIce breakoints)+ ?" \- N- X- C
( A1 z( n* E7 j, y! V3 Y' h) q1 T* y
Each time you'll meet this trick, you'll see:) V$ x& U% I2 J! i0 \6 ~4 Q1 {5 l
-SI = 4647h2 i7 x+ E/ P* e' j& @
-DI = 4A4Dh$ e% L9 O$ I3 F) ?& `
Which are the 'magic values' used by SoftIce.* _' i* w  O" j) ]) {8 q0 ]
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.5 Y5 I; k# v$ P" g2 l. |: j! S+ o
7 _( `- a+ ^$ f# W& v, o
Here is one example from the file "Haspinst.exe" which is the dongle HASP4 H* V+ _( y. z) ]7 |0 g1 T8 e
Envelope utility use to protect DOS applications:
; V3 y2 U& |- ^1 u9 i2 ?" p7 [, D5 n& u  v& z$ q" c7 i8 z

/ s; f% h) v7 E9 H4C19:0095   MOV    AX,0911  ; execute command.
# n. W* L) u% x' J. D: m9 H4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
5 v+ C8 O% I) ?, Q2 N& F. P3 [4C19:009A   MOV    SI,4647  ; 1st magic value.' R4 ^+ a& D! u, x3 q0 r  j3 K* z1 i
4C19:009D   MOV    DI,4A4D  ; 2nd magic value.0 i" [' l8 Q6 n
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)7 m' p* W9 j6 K# S& J( ^& g  [* p
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute1 @9 C5 c1 b9 A; v" N
4C19:00A4   INC    CX4 ~# n* e& w5 Y: [7 U. }
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute' C6 ~9 V8 ~. e
4C19:00A8   JB     0095     ; 6 different commands.. m5 e) t  y7 C; K8 j' p# @% W
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.  Q# {1 B8 J  o: X0 v
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)! u! {4 i3 W- }9 A: B; v; _) q# \
, j0 m' t" l8 q9 x) V- C
The program will execute 6 different SIce commands located at ds:dx, which8 D" \$ E4 s4 @5 N. u" e  X
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
6 h" v5 C" ?  \8 E( A  A5 |6 u% J4 f( k! t& i
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
2 n0 I: c3 i5 R, O1 K' ?- V___________________________________________________________________________# o# Y1 T6 ?- ^; ?4 M, K

1 c7 w% V+ f: P& Z% l- n2 E5 M- L- ]7 i) f
Method 03& K* d4 A5 Q) N' E, o
=========
' O4 u, x: ]6 d, U
7 Z6 m5 Z: E+ ILess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
+ W) u' s( O: y, X8 R(API Get entry point)
9 ^. P9 g( @9 T# f3 h        / u+ J. o' X# Q6 X! O  d. u3 {
  s4 N0 L" `- n$ G8 n- _, `# D& q6 }
    xor     di,di
3 ]' O2 Q& O) ]/ f) Z    mov     es,di, r4 V4 T* M6 Z2 K" M; ^; d
    mov     ax, 1684h       . c" I+ n& @) _2 X$ J' L, V% R
    mov     bx, 0202h       ; VxD ID of winice
! s1 e7 A" l" f: p! R9 P$ N    int     2Fh' m! J; w& }$ B2 R* h
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
( J% q. P  a2 _+ X. h) M    add     ax, di0 Y; m8 b* T2 D' `3 m% ?
    test    ax,ax! S; i" y$ }. y  C
    jnz     SoftICE_Detected
+ e" c# {2 l* t5 C$ Y% ]1 _
6 y4 H+ Q8 T! E  p2 M___________________________________________________________________________
# T; a' b# b! W
6 Q& j4 \: f' U8 k/ B# n4 oMethod 04
' n1 G- I$ b7 B" _' T=========
; ?9 U- M5 l7 E& f7 ~
5 n2 W. N& e  g6 j6 `, @7 fMethod identical to the preceding one except that it seeks the ID of SoftICE
# ^- f/ p1 c! g4 t4 g; n- Y  o4 RGFX VxD.2 o: a$ C) G' L4 e% w2 A
+ |( X* X2 K; v
    xor     di,di; V6 d. i& V  N/ X
    mov     es,di
4 y# w5 _$ _1 U    mov     ax, 1684h       4 r" g1 c+ i1 ]- @
    mov     bx, 7a5Fh       ; VxD ID of SIWVID
# m9 g2 b; t# I5 P) }    int     2fh1 d. J# s6 ~  a; K# W4 f7 u
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
, P$ `! f' Y, W( e/ u8 H    add     ax, di
! j; e' |( j* K% N    test    ax,ax+ {) n1 C7 D8 H0 `7 X
    jnz     SoftICE_Detected
' T* V2 ?6 F& N- b" w; _9 h' f3 c7 h  D: b5 V
__________________________________________________________________________7 Z: P, s' K* Q2 ]( k& e. u
% ]; p8 |  z3 E  L3 O; S: B
5 g# x, I+ ?0 ?5 @" g; O
Method 05# x. N: U  T7 p  q+ t, j; M; l" E* Y
=========6 q  m0 v% o8 H! E: A9 Y
7 v0 r2 V- O% S! R3 o1 d$ [. m
Method seeking the 'magic number' 0F386h returned (in ax) by all system
; f/ F. a; n3 odebugger. It calls the int 41h, function 4Fh.( ~" D2 c0 }* L7 N$ ?3 }
There are several alternatives.  
+ M4 v  b6 }9 J% _8 y5 H- Y5 b( \, P
The following one is the simplest:+ u8 G9 v7 m6 F' O* G1 p
( u/ f8 q1 t$ `1 c- _2 k; A& \
    mov     ax,4fh6 [. N4 q3 Q# y/ |* j) L: A  x
    int     41h) N3 ?; G2 j9 W, `" E7 e9 O/ d* Y
    cmp     ax, 0F3867 Q- e' k; b: N6 k- [3 i7 z! j0 W
    jz      SoftICE_detected
  I2 B7 H! i3 l* Y7 L$ T1 b1 m; a/ B9 g; V8 ?
1 S& l1 f7 `2 Z) D  M+ o
Next method as well as the following one are 2 examples from Stone's & ^) A) t) p* W
"stn-wid.zip" (www.cracking.net):
) [- N# Z. @# {2 e
5 k0 h' t; `6 ^9 }    mov     bx, cs; M9 w2 ]& P4 j
    lea     dx, int41handler2( ~! j3 j% [6 i
    xchg    dx, es:[41h*4]
( v6 J' z. g# W) N- R) l* A; A9 [! y    xchg    bx, es:[41h*4+2]2 R/ r' v1 g! l; G' ~/ ^4 r
    mov     ax,4fh
& Y. B1 t' L( J4 j8 r: D    int     41h
! C2 F! B' {2 v& ^0 b" s) a5 i    xchg    dx, es:[41h*4]
' Q$ K! R: M( J( B! B7 f3 y    xchg    bx, es:[41h*4+2]
; ~$ o5 W* ^/ L/ M+ V: a    cmp     ax, 0f386h6 D3 q! w0 J7 N  w$ R
    jz      SoftICE_detected
/ B! ^  x7 f8 h& S
3 i# E* u, s6 }  lint41handler2 PROC
' C6 K" M- W$ r    iret
7 ^$ o7 S5 Q0 `# Nint41handler2 ENDP
/ |' \# F6 G+ o- ?% e2 j+ T3 I$ {' l5 j
; f! H& j* k$ R5 T% {3 ?
_________________________________________________________________________
  y2 Z% v  ~$ n4 F9 L  x& u
2 @# q. X( g9 X3 ?. R6 U4 ?) @1 \: L: I
Method 06: y: V; S% p4 a% {6 |
=========, n" U! h4 D2 V' S5 h+ l
: C, G% a% C% J$ G; A
* k+ z- E, H1 s9 x- Z
2nd method similar to the preceding one but more difficult to detect:
- v3 ~  X7 l/ I' m4 K- D+ L5 q, n/ p) A7 e* x/ p" o1 f0 I
/ C4 x/ Q: b8 Z/ U# `
int41handler PROC5 T* ^# q) k% B* w/ o' B
    mov     cl,al
2 B/ F* E% L& R3 u: u  @    iret4 y3 J- Q( |( K! @) {5 I
int41handler ENDP
* U0 W7 J' G( m2 Z) D# i# Z
, Q7 U7 R* S0 u( t7 j
' T7 J' v1 V' Q; v- K4 @$ T    xor     ax,ax: L6 i  r. J* T
    mov     es,ax$ P8 ]7 G6 D7 O  j& w$ ?
    mov     bx, cs. h7 {+ p! h$ R2 v
    lea     dx, int41handler
( @- {, s" Y2 \( f( L4 [    xchg    dx, es:[41h*4]" Q* U& [4 U2 q1 v& o. `. q3 U6 Z
    xchg    bx, es:[41h*4+2]
, y- Z5 u# c4 k0 o    in      al, 40h- m( P  y1 J; N5 g- h" Y( ~' _
    xor     cx,cx
. \$ n- b/ d, I4 e/ l    int     41h
% h; |$ p2 i0 Q1 k' S    xchg    dx, es:[41h*4]3 m8 _4 ~* q& X9 w" n
    xchg    bx, es:[41h*4+2]
: l# m; G& t( A% _0 I. Z8 Z% v    cmp     cl,al
  v8 q! |* w, ^    jnz     SoftICE_detected0 l- r& ]% {, L% J* r6 }
) V, l) N' }0 ^9 M  d
_________________________________________________________________________3 G7 G7 e- n; u. o4 K  ^
6 w4 d4 Q) h, L5 X& J/ i3 @; N
Method 07- r) k4 F( i* d; \2 V8 r
=========- y, d$ F  u2 n; W! B5 a8 M

! J  j0 ]  k  t4 n3 v3 CMethod of detection of the WinICE handler in the int68h (V86)
8 N; T* ~$ `! P0 U5 t7 R! q
% U% c% D; g* c/ y$ h) s    mov     ah,43h
& z) U8 t# a1 u9 b% @1 M    int     68h
, U1 \5 d- r8 a3 |: N    cmp     ax,0F386h
: `  o. D" c9 H    jz      SoftICE_Detected9 H# O/ E" X6 l

& M. D4 V( w0 w: M' H( E2 b3 i' u- B+ B) a
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
2 {* g" G- I& z0 [; ~( Q! X   app like this:* H* i. z. m. t8 t: y
6 U. F, n: A+ l  O" o- H
   BPX exec_int if ax==68
, w/ y  B2 s# i6 f, ^7 y% b: B8 {% [   (function called is located at byte ptr [ebp+1Dh] and client eip is
$ x$ ^6 ^& L% g: V   located at [ebp+48h] for 32Bit apps)9 X* q9 v8 D; w5 j8 M8 ?" L3 e
__________________________________________________________________________# \9 g( o! O0 d. p1 ]
, Q3 x# N! j' O% f0 |( C( R

% q# ~( y2 |! f/ UMethod 08
; T9 R3 \/ p/ l=========/ W/ _0 x9 @+ H2 H
9 Y+ g. I3 e; ~& P# w
It is not a method of detection of SoftICE but a possibility to crash the8 t5 r! A0 q# B, r
system by intercepting int 01h and int 03h and redirecting them to another
7 T) Z  n3 s; f8 G; Iroutine.
7 d+ u% R5 u( t% r# HIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points% W0 e! A* r6 [2 t2 _
to the new routine to execute (hangs computer...): C9 w8 O, L: I

% c7 z: M5 o4 b8 A( ~$ @2 z! @: t    mov     ah, 25h  V0 ?# J* j4 r' U
    mov     al, Int_Number (01h or 03h)
! O# N1 S3 K  ?/ K    mov     dx, offset New_Int_Routine
  \/ j% Y( N* H0 r    int     21h
; p' G5 j0 }* ~6 h& V# C. v8 V  `4 K" w
__________________________________________________________________________0 g! b3 t. V" c7 r

: y# ?9 ?1 M- KMethod 09
$ z! W% t: m( o=========
5 U8 d  x* ]2 z4 {
/ {. t% N: }1 s. BThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
9 S3 `: v9 t6 Q8 L" ^4 zperformed in ring0 (VxD or a ring3 app using the VxdCall).
' g1 I8 V0 j' g2 i  x3 E- vThe Get_DDB service is used to determine whether or not a VxD is installed
2 N8 e) X' E1 Ffor the specified device and returns a Device Description Block (in ecx) for
4 ?8 K" b9 I) d5 k( H6 T5 \5 |* }9 [that device if it is installed.
. d, h2 Z5 U0 p! m3 b7 i- c' X: u$ ^/ _
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
5 _3 ?; V% `: u; x& x   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)  L7 P0 f9 u* z0 M5 s- x
   VMMCall Get_DDB" x8 D( p2 Q" `) ^' ]8 F' ~
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed$ r" j( Z- r- |

: g7 X+ T- L0 r) W0 j& P& {8 b/ YNote as well that you can easily detect this method with SoftICE:
5 y& p! N7 w7 Z. ~9 L/ u. U4 k   bpx Get_DDB if ax==0202 || ax==7a5fh
7 R& J8 T; K6 a1 B: `' m/ \
9 F6 _7 h! o4 D9 m# w7 y__________________________________________________________________________1 ^) {" B4 p% ?
6 k: y3 ?$ P" t) E. j" o. H9 }! t
Method 102 X. L" ]3 k. g+ z+ k
=========2 x* a) j$ T9 Y2 }6 i3 v* }' ]4 J

. e2 I1 c/ E8 ]" f/ z+ a+ k0 H=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
( ]0 b/ u1 C$ ?) I+ M! i; v9 e( w  SoftICE while the option is enable!!
; B& H% ~; A: p
9 a3 o- W# T; AThis trick is very efficient:0 F2 r1 m% O8 r, U/ |. z9 T
by checking the Debug Registers, you can detect if SoftICE is loaded
# h. Z: M, W1 p6 A( l# b" v(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if8 O) K: B2 |! ^5 U0 Y
there are some memory breakpoints set (dr0 to dr3) simply by reading their. ]  z' K. {9 o$ q  C# i4 d
value (in ring0 only). Values can be manipulated and or changed as well
# N4 }+ R3 Q1 V* G1 i(clearing BPMs for instance)
+ O- t5 q1 c9 ~' {
* L$ r- Q4 `7 U__________________________________________________________________________
' i5 O" ~/ f9 s5 m/ Q! o7 j; M
" P, J0 K0 ~5 r, c8 q' }6 q0 U3 GMethod 11( Z7 t2 d' [# D# t1 @7 |+ c* p4 u, ?
=========
6 Q& `- ]( K+ `8 G* X- ^, t& a5 ^2 x6 X6 u0 F
This method is most known as 'MeltICE' because it has been freely distributed
3 P$ l6 w3 ?8 Vvia www.winfiles.com. However it was first used by NuMega people to allow
' J1 ]9 H( m+ o+ k1 v4 M/ sSymbol Loader to check if SoftICE was active or not (the code is located& |% y' d/ r9 d/ X
inside nmtrans.dll).
, ^" Z/ m. ^/ K1 d' g
& B$ k$ I, @' r' j- s; \7 SThe way it works is very simple:
& R1 @4 K6 o: f2 ]% o& b9 `It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
: Z0 O( N7 A$ ^  t# v! e4 k4 H/ hWinNT) with the CreateFileA API.6 y* a% L& G* A6 |3 n0 \" h  s7 N; o
5 z& u, ~  T; h: D( p
Here is a sample (checking for 'SICE'):) ^, f- c. D; `* r7 A9 g

& S$ m9 e, C. zBOOL IsSoftIce95Loaded()1 I& O6 y* U+ \# l9 S
{: h( [$ g( V. P7 r2 N
   HANDLE hFile;  
& u! E- Q% M' b5 N   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,  n$ [+ V$ `9 R+ s  R" }# X+ d$ ?
                      FILE_SHARE_READ | FILE_SHARE_WRITE,1 m0 a" O( F1 O  R/ X. ?4 K
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);$ t  o2 H. [) Y- F' w8 y7 Z
   if( hFile != INVALID_HANDLE_VALUE )1 d* L& G" |0 Y8 A
   {
/ Z  A- w5 g" z      CloseHandle(hFile);7 R+ L  s$ `: B0 a
      return TRUE;
3 l" e1 p  I) c  e5 f   }
2 P% z1 ~. u% J: o  c2 d; ~   return FALSE;; Q0 S! \  k& {8 l6 V: _
}
* w1 _+ Q% G. }+ d) w3 J0 z( i4 k3 _% Y0 G% @* r4 s! h8 U
Although this trick calls the CreateFileA function, don't even expect to be
- x0 P! o% \& U0 H8 R3 Cable to intercept it by installing a IFS hook: it will not work, no way!
, X, m# i& [' ^In fact, after the call to CreateFileA it will get through VWIN32 0x001F$ E0 h& M# v* w- b! s3 J, ?
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
1 Q: b+ v( z) D2 }- w0 Tand then browse the DDB list until it find the VxD and its DDB_Control_Proc
; \( E, c0 y! k; Vfield.
- @; j1 }" Z7 x6 A. RIn fact, its purpose is not to load/unload VxDs but only to send a
/ D+ R0 ?' y6 X7 X4 A2 WW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)9 p$ t6 i1 x  `# ^! I2 b1 ]
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
5 R3 T; |4 U9 s7 P  o; S- g! ]* B8 mto load/unload a non-dynamically loadable driver such as SoftICE ;-).
1 M% [' ~4 t! ZIf the VxD is loaded, it will always clear eax and the Carry flag to allow3 T" l$ U9 o5 K  w
its handle to be opened and then, will be detected.
  @0 ]* f- D  L1 X( H$ u" U  y8 \You can check that simply by hooking Winice.exe control proc entry point
2 r' P8 C) h8 p6 u+ dwhile running MeltICE.
. ]# x" ]+ Y+ M; x, {2 a. _- ^5 Y/ }, Z6 z: v: ]

) g/ W1 o7 A) j7 h7 P, k! f  00401067:  push      00402025    ; \\.\SICE9 @8 f. O: m4 c8 E8 _* g1 c
  0040106C:  call      CreateFileA! b5 \* t- \/ ]
  00401071:  cmp       eax,-001
# l/ u, A. A" f- w. L  00401074:  je        00401091
  i) F$ Y* P$ V  Q4 N& @1 f% m  M  X2 Y7 U

* I* A, f0 v" P% q! UThere could be hundreds of BPX you could use to detect this trick.
4 {) w! W  \+ T- c9 ^( F$ b# a( j-The most classical one is:
. x. w" O4 X! {  Q  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
/ P2 }* w( v5 B* V/ C, z  g4 m$ ?9 R    *(esp-&gt;4+4)=='NTIC'
0 }8 ?  y+ A# c; K5 y! A- r7 ?, [# {. q
-The most exotic ones (could be very slooooow :-(! m3 ?6 B- ]6 f' |. e
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
: _2 m2 `# R. c. @7 D1 c3 g     ;will break 3 times :-(
, Z4 p, o! i+ f; ^, V3 h8 M0 K2 @) @" x( N
-or (a bit) faster: 3 k+ i2 v# [, m8 ?/ \# l% O
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
1 y- R0 e9 C7 x9 `2 C1 S  ^9 Q
( _3 V) V/ ]3 j# r8 b   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  ) m4 I( B- V& b, k
     ;will break 3 times :-() F) }" {; `- S3 P8 f( G% x
) Y) Y& c3 O5 N; f3 h  `$ ~9 u
-Much faster:
6 d2 j/ y6 s- T) {   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'& r6 `4 x4 S) Z
( q, w! o; S1 S' j7 W& T
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen+ j, @5 I$ F/ s. g# d, v" w
function to do the same job:: [4 x( [' `+ G0 @

' g$ D# u/ \7 y; J. e. Q5 x   push    00                        ; OF_READ
+ h  G: V0 V1 H+ j2 j3 l   mov     eax,[00656634]            ; '\\.\SICE',0
% N$ i( t! G+ Y+ W( E: ?   push    eax" x6 Q. b1 D3 a; S' i" g
   call    KERNEL32!_lopen
1 g* p4 E; q+ `" R7 G   inc     eax
/ r( g3 G9 c) j+ u% |   jnz     00650589                  ; detected
( G2 }& U% p/ {. |: n4 i   push    00                        ; OF_READ& S3 r' X8 b) ^9 \# ~8 F
   mov     eax,[00656638]            ; '\\.\SICE'
) b0 r1 N4 _: V2 b3 X0 @( S2 x   push    eax& b! a9 p" B  F. e
   call    KERNEL32!_lopen9 x& h% h. R9 d- @, x. m
   inc     eax. g2 K( u2 R( D' H; E
   jz      006505ae                  ; not detected) [/ t* b6 [" w7 z! e

% K+ {, o: c% R/ n2 a- B1 d: R! ~1 l- o$ j" S! e6 C5 Q5 Z
__________________________________________________________________________3 |, v" U- s; X) {& Q

( D; ?) Z. y. Y6 k' P) LMethod 127 ~2 v4 f( _: G' N, Y) ]4 g# z* e
=========& h+ r. \- r% d/ m- n8 ?+ d
6 l' @- J8 z- o+ H  o( a
This trick is similar to int41h/4fh Debugger installation check (code 054 C$ W; s5 L0 N+ w, N) L; N
&amp; 06) but very limited because it's only available for Win95/98 (not NT)
4 p! Y! w+ x6 D2 j( V) i6 H2 q0 Qas it uses the VxDCall backdoor. This detection was found in Bleem Demo." N7 V' C$ r0 y! W

  m( n$ k8 H. k# I8 t! V   push  0000004fh         ; function 4fh- B3 U( X$ [% C' A* M3 w1 s
   push  002a002ah         ; high word specifies which VxD (VWIN32)
( w& I' D. b' c6 C% A/ f                           ; low word specifies which service
1 l% e* l+ A- \4 k- T                             (VWIN32_Int41Dispatch)
/ u1 A! _" J4 S( W( ]; {5 Y$ t   call  Kernel32!ORD_001  ; VxdCall1 ?2 d0 h2 Y0 _: |6 B/ b7 @
   cmp   ax, 0f386h        ; magic number returned by system debuggers  M& Q2 F# t! k( q! }* d
   jz    SoftICE_detected
4 Q* u' D* d! u* a7 V5 |' l6 e5 D1 _4 I3 n
Here again, several ways to detect it:# ]1 X0 A& P. @! `8 S* K/ Y
7 W) h6 @) |& k! i2 F# w
    BPINT 41 if ax==4f
9 h' N3 @1 B2 h- T! @# k4 e7 `4 U. E  ]5 e7 ~! @& ?& C& M
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one% U5 V" S( h7 N% W1 I8 `
# T: R  `. d7 I
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
# O; h  \+ M, S0 D& a7 }+ e3 \" n) @
. d& d' }9 f2 ^0 X# v8 j, {6 _    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
' D1 u1 N* ]% @$ Z- l, F# T- N8 }7 L: g6 ^
__________________________________________________________________________6 ]9 o, Z; y0 h+ ^% m' ?- n
( [; |3 B6 C9 W0 o
Method 13" M* B7 e# v" @7 x4 [7 ?
=========( F) h4 L; I2 h; P( R3 j- w9 C

- z. F  u1 C0 fNot a real method of detection, but a good way to know if SoftICE is
5 v& A$ I7 }9 Vinstalled on a computer and to locate its installation directory.
# ?8 t. J! w& \0 Y5 m  m7 wIt is used by few softs which access the following registry keys (usually #2) :- _5 h% I; E6 Q. }9 n2 V
7 m/ E: |; C! h4 ~6 T! T
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion" ]; K8 U, h$ V
\Uninstall\SoftICE8 W; \4 Z/ q* y+ D: {$ x/ G
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE! I- [: r* o, O' P! A+ c& L
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
8 l& _' E( g1 p5 L, y3 I! G" Z\App Paths\Loader32.Exe
- P" _7 h8 j0 J6 F! @7 ~  N
! Y, N# V: a( o6 u9 _! @) h, V5 a. l$ i; d  b. Y( E/ P4 R
Note that some nasty apps could then erase all files from SoftICE directory( V' t/ p- B  z9 X; O: z
(I faced that once :-(
9 i( m6 n$ @. d3 Q4 I
" y/ n  k  F2 R* O6 j5 lUseful breakpoint to detect it:
8 S  J: }& T# r+ D  n! h, r% H- V( w; x
- q6 R& g4 ]# J, |; n     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
- L2 J% Y$ D4 D& d4 E1 X! v! x
# T* k! c# U- M; c__________________________________________________________________________1 [! y* y9 q2 L8 J. n9 W
9 T+ r% @  s  c6 U

, q! d, T  |3 i1 ^7 Z8 uMethod 14
  A+ G  T, }6 A% B' y; t=========  v0 C  ]4 k( ~. ~3 N. w2 P5 O1 g

$ l# [6 D+ q( m$ ]& pA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose' m% G; |" Y+ k3 n2 {. ]6 `7 w- T
is to determines whether a debugger is running on your system (ring0 only)." M$ H. _. v# n! [# T8 ^

9 w7 T% {1 w! P' b. U! ?* L5 c/ J   VMMCall Test_Debug_Installed
3 t6 t, \* \' _8 a   je      not_installed
8 l# o  v( A  f$ e$ n) f
8 C0 q- e% C! EThis service just checks a flag.9 x4 v2 u6 u" D' o  B6 K, y
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部