About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
/ y  B/ W0 W0 `0 Q) o<TBODY>
* n$ I' h' o+ |$ k<TR>
  G0 F$ t6 P3 `' R<TD><PRE>Method 01 ! o( G8 D: V1 Z. t
=========7 C6 c0 q$ a2 b3 w* k% c8 U. s
' l7 c3 Z" S7 K+ T
This method of detection of SoftICE (as well as the following one) is
! D3 Q" P- F; j5 ]6 r9 H1 {used by the majority of packers/encryptors found on Internet.$ {. k. e3 k" P! o/ y" |: _! \( Q( [
It seeks the signature of BoundsChecker in SoftICE
' F! ^, w$ X! I" W4 G3 W# L' ^: q2 M. U
    mov     ebp, 04243484Bh        ; 'BCHK'5 T" Z( ?) ^4 i  O2 T' \8 [
    mov     ax, 04h
3 L2 @7 P' Q3 U) Q7 i' p    int     3       : k7 a4 X8 I2 ?% l1 a. S
    cmp     al,4/ t1 x9 t& s( J  h- N- \
    jnz     SoftICE_Detected- z7 E$ R& b4 l3 L6 T0 P

0 }; D/ \2 q, a+ D___________________________________________________________________________. q) j. W) z. F3 A' @
5 b' P0 U$ N4 t5 y% n8 A
Method 023 R$ u* I6 v# Q/ z6 k4 f$ @
=========
. S3 B& p* `5 I/ J
/ {9 w5 Q) v. FStill a method very much used (perhaps the most frequent one).  It is used
: P+ O0 g, x' _2 `* Dto get SoftICE 'Back Door commands' which gives infos on Breakpoints,
  I+ [/ G9 T. |, a6 B; Z; Q, \or execute SoftICE commands...4 S7 H8 `  J$ ^  r: ~
It is also used to crash SoftICE and to force it to execute any commands% E  d" P9 _9 V
(HBOOT...) :-((  . D) H8 b7 c2 I  ]/ |% @

5 T; d0 [# n- r1 p9 j, `Here is a quick description:
: u! Q+ h# d; r: g; a7 F  N-AX = 0910h   (Display string in SIce windows)
" u; I$ C3 q' h: a0 n" L) {% c-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
1 r+ V" [" S  x: t( O-AX = 0912h   (Get breakpoint infos)
% S# U! b: J7 Z( T-AX = 0913h   (Set Sice breakpoints)7 }! f" N; X, F5 l' E: M$ R
-AX = 0914h   (Remove SIce breakoints)% _' _( a5 ~2 m# O( k/ `
) K& W/ s. R3 u
Each time you'll meet this trick, you'll see:
( Z+ L5 S7 ?* ]2 r-SI = 4647h
' b& ^7 y1 C6 u; H/ k2 X-DI = 4A4Dh
4 Y0 E- l+ f- _/ n0 ?- D8 b- T2 \6 eWhich are the 'magic values' used by SoftIce.7 ^3 [4 j; j# P
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
2 e, p, f% ]+ G) \% q1 u/ C+ \: F6 X& ?/ X1 l
Here is one example from the file "Haspinst.exe" which is the dongle HASP- t+ E! Y! @3 }8 v) N; S1 c+ t
Envelope utility use to protect DOS applications:
, a7 b) g1 w: z9 u* ?, W$ w6 `" }# X! `/ H  J. E

+ U! z. B) M2 z- y) d2 v4C19:0095   MOV    AX,0911  ; execute command.
  f/ B1 T, [6 a2 g! S4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).! L/ E) v3 r& \* _0 @; ~
4C19:009A   MOV    SI,4647  ; 1st magic value.# e+ [8 l2 t( h: Z& G- O! {8 y
4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
+ m  R5 V4 Z- y2 e, e; [1 d3 H4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)' Q3 m: @* _& b
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
0 Q8 Z. a* y, [1 _+ e4C19:00A4   INC    CX
+ D* Z! F9 p. |4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
) w9 q( O$ @  C3 |$ k1 T& j; W4C19:00A8   JB     0095     ; 6 different commands.+ B: V, |) b: K+ ]! b
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
" ~4 T3 f2 y- C; c* m2 e, c7 I! n4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)# }  p6 @, N3 `" y0 q% @
" s' u3 A$ i% M/ ?
The program will execute 6 different SIce commands located at ds:dx, which
0 g2 H9 D! H1 U) k% ^! `, H8 r: [are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
" w1 F4 F" Y& F2 ~0 w- X4 L& T5 e1 ]1 I7 \8 q
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.0 ]6 d, m$ _$ j1 W* D
___________________________________________________________________________
9 q& j7 ]5 }8 F4 m, |  C
3 h8 r. |" q% Q8 n1 |! v8 @
2 p% O) N: A8 z2 M( H9 J2 NMethod 039 \) b# y% C( \- e4 X8 ]: c2 l
=========& u3 C* N( t5 ]0 t( Y2 j! F
5 n9 ^; N9 [+ c3 a0 r- j
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
# G$ S% _, t2 H6 L7 {0 |(API Get entry point)9 R6 G' @; y1 }# t
        " Q  m7 Q  Q# s3 P  p/ I
1 |' i  W8 J3 t/ I, \1 l5 r
    xor     di,di
  E* q) F; H; |: D* Z$ w    mov     es,di+ L; r8 w/ `' F- F( j, q
    mov     ax, 1684h      
# `  P' j- I1 |! _0 c    mov     bx, 0202h       ; VxD ID of winice- v9 B6 m7 L& {( H- d" Z- I
    int     2Fh
7 Y" W7 b. {( U* X    mov     ax, es          ; ES:DI -&gt; VxD API entry point8 ?; G1 ~& y% f: Y5 G& f. k5 p
    add     ax, di
* _/ U% f9 O  n7 F1 {    test    ax,ax  l* C: M, L* M* i$ A4 k  C
    jnz     SoftICE_Detected
: n# C% i- l! m! U2 m( @
% M3 n1 C, n; E# q: B6 G___________________________________________________________________________) K, y, \: r1 F3 U
, [. K0 d% x( j/ T% Q0 G
Method 04
$ M, z" N8 r( o. e* S- o5 k: J=========
- d) }4 X6 r- p" Q
; i4 t- Z+ B4 m) W, Y9 E7 gMethod identical to the preceding one except that it seeks the ID of SoftICE
* ^4 j4 `% O. ~, u+ O6 S+ o+ IGFX VxD.& H' [9 q$ y# C# @" ~
' v7 ~2 S) N2 \0 M3 h+ @
    xor     di,di8 B0 K$ ?* L" g( |& e
    mov     es,di
1 a6 n) ?- k" D    mov     ax, 1684h       6 O" \8 ]+ q8 M: H+ u% b3 z
    mov     bx, 7a5Fh       ; VxD ID of SIWVID& e+ z6 J/ V8 [$ D9 y
    int     2fh! |0 q/ D" Y5 t' }+ u8 N
    mov     ax, es          ; ES:DI -&gt; VxD API entry point1 y2 Z, W1 u  ~' C7 U( z1 L1 Z
    add     ax, di" V8 c; [% ]: d, d
    test    ax,ax
- `" J) O* z% E6 _0 \7 y/ ]    jnz     SoftICE_Detected. L0 i: C4 h. l3 ~2 \* |: `8 T
- M9 `) C1 U( z9 m6 R0 D% b' [
__________________________________________________________________________! m! ^2 Z, S7 v, G6 {" \
, O; T1 V6 m# N

  s6 P8 G; E9 c3 O0 N( d: qMethod 05' ?- ]4 X2 g8 L) Z. C4 H
=========
  T1 h- Y* }% N* X* B  e+ T9 s2 c, ]1 ~  n# r' a& I4 u
Method seeking the 'magic number' 0F386h returned (in ax) by all system0 D2 `. H# y4 w6 M: n) T  A
debugger. It calls the int 41h, function 4Fh.1 M' y: i2 ^1 t' O* ?1 _
There are several alternatives.  
9 }1 \) J, C, G+ U* f: Z3 A
7 h' l; m! c" pThe following one is the simplest:0 z/ G/ I2 S3 a. Z

1 g" _" i- G8 N; W6 V0 o4 [    mov     ax,4fh/ [: m5 e7 c. P# K  f$ m
    int     41h
# U9 H6 R8 m. v, F    cmp     ax, 0F386
5 U( Y6 d! `8 ~: C    jz      SoftICE_detected+ l- Q5 \, A; g3 N5 W3 G
& ~( w  R  [+ y9 Y! a! q+ a
& r: e9 C. ~. `! Q5 f8 `" j
Next method as well as the following one are 2 examples from Stone's
5 E: g! G2 p6 R"stn-wid.zip" (www.cracking.net):2 [0 B! B4 e$ a) M) `/ @( ~8 p

& S4 C7 E" z& D9 G) u    mov     bx, cs* ~: Q+ U8 c6 g7 m4 t
    lea     dx, int41handler2' w; |# n/ S* J; r3 n
    xchg    dx, es:[41h*4], F& I9 ^0 w5 d5 r
    xchg    bx, es:[41h*4+2]
" h3 f; }2 }" N0 _* [    mov     ax,4fh
4 n8 c( V) Y  D6 b    int     41h2 u3 f8 n' z$ N3 M0 _) E6 l8 |2 f% U
    xchg    dx, es:[41h*4]% [6 ]8 P+ E9 r- ?
    xchg    bx, es:[41h*4+2]! T4 I1 S, z3 }5 l" T
    cmp     ax, 0f386h
" o$ a( {* [3 `- O; c9 E    jz      SoftICE_detected
" A- L, u% U. E$ t& {& F2 b
% {7 d- Y" a7 [6 Eint41handler2 PROC5 B, q3 d  c* N/ o
    iret  h3 X& X5 U7 f% x% c* j! ?
int41handler2 ENDP+ b6 y% p9 E4 K! l

& P* t! G( c" {: ]  U' s6 q2 r' T1 J# {5 O3 H8 d2 m& i$ s
_________________________________________________________________________
6 j4 O  M8 T1 C. j6 Z& {/ T9 h& y$ A) Z0 I) J0 d3 g( o- H

$ P# h; E% {$ d  q# ]( r& RMethod 06: t# M8 k5 H8 G5 g+ \
=========  c2 C  T: ?$ f1 {% _& Y8 K+ }

0 W( q! m- \1 N3 A4 m3 f! p% T3 [3 Q+ C
2nd method similar to the preceding one but more difficult to detect:5 Y) Q! x% }: F0 h; d

( d+ a% |" @) r) `  V  e  y8 m; v# j  i  B
int41handler PROC+ \7 O( y" U4 X5 g  @1 B
    mov     cl,al
1 r3 J; Y7 s- l$ Q  P* s0 i    iret
& B8 W- ?- u# [, q# m8 aint41handler ENDP0 l9 d8 l; F9 g  S2 ?) O. b( i0 I

; B- s" t3 s" X5 P
7 @; z2 {7 E) [3 W9 r6 A( d- G    xor     ax,ax1 y& Q# l( K' J# x& U  c8 M1 P
    mov     es,ax
. b* m1 |; f( C/ ]! t7 e, W    mov     bx, cs
8 M+ |! I! o+ n0 s6 V    lea     dx, int41handler" B8 w1 w. v% P. q6 H
    xchg    dx, es:[41h*4]
" f6 @; m3 h8 P- t" l6 Y    xchg    bx, es:[41h*4+2]
7 |! x! A- a( J! u% ~    in      al, 40h9 S1 f; |9 I: L" p9 `
    xor     cx,cx
# ], J5 L( O; h$ b    int     41h3 k4 E9 h8 ~) {- n% v
    xchg    dx, es:[41h*4]
* k2 I7 p4 I" u: i    xchg    bx, es:[41h*4+2]+ [) Z4 u- e3 Q: \
    cmp     cl,al
7 @8 E; A  q4 v/ j8 p. k    jnz     SoftICE_detected
% Z6 N! F& n/ z6 x8 e; l4 @; Q4 S
0 A* o- B, m  u* Z_________________________________________________________________________
, Z9 ?2 @2 o% e1 v9 l1 C  |: L$ C! q! f' G
Method 07
' ^$ a  G- R5 D- i2 l=========% k8 @" U1 S% m- `$ D+ d
: Z3 P( l% n* }2 u4 G: P5 F7 u9 W
Method of detection of the WinICE handler in the int68h (V86)" ]3 {! E9 r4 K* `* F

$ T: }, w$ m  y$ T    mov     ah,43h
, ^5 m4 {7 B9 b8 M, [- a    int     68h
* Q! ]# ~4 I1 ~& B/ o- s9 e$ O    cmp     ax,0F386h/ y) m/ A* v9 a8 K& w( m
    jz      SoftICE_Detected& @, i& t3 c" y9 v, n; H; k

, E1 \; u' I! D4 o; A/ l$ Y1 C$ \" Q. [6 r  w" c3 u9 ?! ~4 m- x
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit0 F# }2 f( M* Z) B
   app like this:1 d! _) z7 O1 `8 F1 I
4 H4 I( G5 z  l  C3 H+ Y9 I
   BPX exec_int if ax==68
8 g# D7 b& [6 Z0 h: X   (function called is located at byte ptr [ebp+1Dh] and client eip is
, U8 l* F" C- k- @3 \% [8 Z   located at [ebp+48h] for 32Bit apps)
( }5 P0 y, |/ _$ J1 [5 r__________________________________________________________________________
9 y! P: l* C) E" D+ w* Y6 t7 q4 v" o5 c8 H" V9 A1 s
2 F, p: n5 Y5 ?, c$ U( G  D
Method 08: f% L- j) @; ~% B; A
=========
7 C8 {  X7 S- |4 |* Z3 |; q
7 I5 Z4 `, y3 |It is not a method of detection of SoftICE but a possibility to crash the
0 }: Z  O0 h, z! bsystem by intercepting int 01h and int 03h and redirecting them to another
! g3 h# e7 ]& j3 p7 froutine.
8 D2 W9 e; b" j; n7 l, ^It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points# _% ~; k( R6 U/ e2 v) x
to the new routine to execute (hangs computer...)
; {$ t7 V! h  o4 n: B7 H" ~% ^& Q4 s' b# u+ I
    mov     ah, 25h9 L1 h4 A5 E: i; g
    mov     al, Int_Number (01h or 03h)0 r. p5 E& g% g6 w1 I# r
    mov     dx, offset New_Int_Routine, J  ~8 a; k, D# @
    int     21h
& l2 M3 e+ M. J; T) F
4 W5 v) s# g  P__________________________________________________________________________5 W7 @6 e& M( g6 i. P4 `- M
! y" O, @. m2 I: X' p
Method 09
' p3 D& q$ l& P, {# ?5 d, {=========- V4 b9 P+ s  _2 Y& O5 l
) f* L- b0 T4 d. ^4 [
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only8 _  k/ `# g+ }% k- m' x0 r
performed in ring0 (VxD or a ring3 app using the VxdCall).
1 B1 G1 t: P2 r6 FThe Get_DDB service is used to determine whether or not a VxD is installed
7 `$ e3 @+ b# g  \) I& n3 K5 Efor the specified device and returns a Device Description Block (in ecx) for$ q' d! K& i- n) m/ H- ]+ z
that device if it is installed.
* H! |) u# b/ ?0 w7 B/ W8 {+ H, {2 W/ c
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID6 ^7 O2 R- N: ^2 g+ V
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)( k5 _" U# U3 O1 @' ]6 _! f
   VMMCall Get_DDB
/ K; C( g, u& @8 S: {3 H   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed- K3 V5 B( p% z- ]8 \7 _' ?
9 F+ x9 A2 r6 _& d( B* Z1 W4 j. Q
Note as well that you can easily detect this method with SoftICE:
; y1 h1 w" }% T) a' @3 d   bpx Get_DDB if ax==0202 || ax==7a5fh% l$ j7 d1 ?2 ]6 ]" R1 T- z2 W

6 q1 {; f5 u. a1 D: B__________________________________________________________________________5 Q1 c* n- T5 l) `* _  i0 b9 L
" ~: F# i; }3 r: d
Method 10
! ~# D  [; u7 K1 [8 Y=========
5 L5 |; F6 w% y) _  R  Z
1 ^, O: ?; G; N! L+ z! v' u=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
- [2 u+ v6 ~8 D3 P9 [! d  SoftICE while the option is enable!!; m3 t/ u: p3 t) o4 D5 H" l
$ q* ~" D/ |! S' d
This trick is very efficient:  {0 }7 W5 P1 L5 @6 y
by checking the Debug Registers, you can detect if SoftICE is loaded2 z. k6 j4 W8 f1 H# _
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if6 G' J" _$ S6 ?) P- N3 C, v
there are some memory breakpoints set (dr0 to dr3) simply by reading their
' j" e6 |+ {1 q( a0 k$ J+ K  Yvalue (in ring0 only). Values can be manipulated and or changed as well
% \8 m/ f9 U) u2 \(clearing BPMs for instance); N3 K  W) J9 E5 Z

" L; \% I! A& @$ {3 Z+ Z__________________________________________________________________________
: |1 K. i0 |: c* u7 e- `6 W) J& n: P0 Y1 t( Z/ ~2 I4 t
Method 11
* J, |( D0 I) U=========
$ \( Q0 h' n: d* N! P, g' x' X, ]8 Q) ?9 J
This method is most known as 'MeltICE' because it has been freely distributed/ r$ p0 w: A( b1 R$ x4 b
via www.winfiles.com. However it was first used by NuMega people to allow3 O8 ^' T  \2 n9 G% A$ C
Symbol Loader to check if SoftICE was active or not (the code is located
' k  _1 m; G- J# }) Hinside nmtrans.dll).
8 G4 J2 c5 ]) Y2 [3 i$ f: N7 D& p0 K8 d1 N
The way it works is very simple:
2 H8 g* b2 O% }It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for  R, }6 r/ K) K5 T7 L% j
WinNT) with the CreateFileA API.
, h: l, U7 A: A. U; g& M
. o# m3 z' m$ _0 jHere is a sample (checking for 'SICE'):6 ^2 r' o# G5 ~( T# K
: Q5 {9 t! [) q# v
BOOL IsSoftIce95Loaded()
9 e1 y$ a, g7 {) z( W8 p{
  Q. i2 z- u" O. y   HANDLE hFile;  
3 C& K, S- D  i: r/ b) R   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,$ R* p- X# ~& b0 z5 w% O2 B
                      FILE_SHARE_READ | FILE_SHARE_WRITE,  S5 O9 W! V+ T# s$ R
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
; p! m5 N+ Z! g+ a   if( hFile != INVALID_HANDLE_VALUE )0 u5 F3 H% J2 y9 n9 @* c  l" B
   {, j/ H  a$ R4 \3 }" y% K6 W0 t
      CloseHandle(hFile);4 r0 b+ w" [- ^& A8 w; M" S
      return TRUE;' v5 {1 y2 `* ~: ~( J! G7 T
   }) ?# \1 m# J7 f3 T6 w# }
   return FALSE;
: s6 M. ?% {: P4 j+ {}* w! {: f, b  O& Y9 n4 Z9 T
, ~0 |8 Z+ [/ H1 T8 A2 ?9 Z% s+ m
Although this trick calls the CreateFileA function, don't even expect to be
4 `% V+ J+ V3 H3 F' table to intercept it by installing a IFS hook: it will not work, no way!
# X& ~) G% |% Y7 |2 [In fact, after the call to CreateFileA it will get through VWIN32 0x001F
0 s1 Q: j) S0 K6 m0 [% gservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function); G8 r1 |7 G3 d! E
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
: I- y# u# G' Y/ b5 D! yfield.
1 v4 k1 w) w: z  d2 RIn fact, its purpose is not to load/unload VxDs but only to send a
" b& _& Y& V8 ^; k& Y7 v& ^W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
- U# |/ k4 u% V; U0 ^2 Cto the VxD Control_Dispatch proc (how the hell a shareware soft could try
7 x9 a& G8 u+ t3 s) v) qto load/unload a non-dynamically loadable driver such as SoftICE ;-).
! _. b6 a! k/ k! mIf the VxD is loaded, it will always clear eax and the Carry flag to allow
5 ^% ~: S$ ~/ X5 q- a8 \+ Aits handle to be opened and then, will be detected.1 n, ?: z8 _* T4 l$ q
You can check that simply by hooking Winice.exe control proc entry point
4 i# S4 D! D+ W+ cwhile running MeltICE.% a$ f; w, a! W! e6 z% Z: ~
* c8 f2 D9 s( T. [# C$ A  B5 V

9 ?! K1 E/ ]1 r3 c* F) ^7 w" ]8 h  00401067:  push      00402025    ; \\.\SICE
# x/ K7 k! V9 w. y' g  0040106C:  call      CreateFileA
+ B# K. c5 g/ V( v  00401071:  cmp       eax,-001
& y8 o* F8 x5 x+ q# d2 ^; c- K  00401074:  je        00401091) x7 \6 [! W; F5 U- b& J: W

4 ?- d2 F, \* [5 f: n. V; h' h$ }3 t3 [; F, ~2 c
There could be hundreds of BPX you could use to detect this trick.
6 p2 z7 F0 y: M, D5 A-The most classical one is:
, }5 m2 K! o) F$ \* L0 x  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||$ D: t) C  j( K  M
    *(esp-&gt;4+4)=='NTIC'
1 B1 }. z4 S% H7 `6 n
9 m0 g) @' _' s4 h; l-The most exotic ones (could be very slooooow :-(& L* l0 Q' L) `  J
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  7 Z1 n' i9 ^* \" @. b( l: j
     ;will break 3 times :-(# C! R( z- L9 T2 o
4 k0 t' @$ @( c* v; @  A. X- d& l
-or (a bit) faster: 0 m" U7 ?6 A9 n% c) n
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
  v/ J" y) R, n( A- C* s  F( H
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
+ o/ h5 z) T' ~0 h     ;will break 3 times :-(8 V; ^- U2 S: S8 K

0 G- u3 o8 S& S-Much faster:# F0 Y3 D" S8 |% V) I1 z
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'5 Q4 U0 M' [3 s/ s, J& d

' h+ {( H2 U) F5 T+ U+ ZNote also that some programs (like AZPR3.00) use de old 16-bit _lopen5 X# ]2 g9 ~0 ~7 }. R4 {
function to do the same job:$ N: }* n- r, p( U% Q7 J
' [. }- C5 E; N0 E" u
   push    00                        ; OF_READ4 s* D% |1 Y, S/ r$ L7 T! y* i+ I
   mov     eax,[00656634]            ; '\\.\SICE',0
* `- E4 y5 f7 w! c2 M" q+ K1 q; W   push    eax
4 Z; z' g$ h! B1 Z7 l  F' P# w   call    KERNEL32!_lopen( R. J. A: }# ~( C" B/ Q1 d
   inc     eax0 M) h4 l0 g& i) J
   jnz     00650589                  ; detected
$ j4 l/ s$ H7 ?% n   push    00                        ; OF_READ7 c8 O' k# k' y! v% F0 E3 c7 M
   mov     eax,[00656638]            ; '\\.\SICE'& J6 Y/ T  }( g+ @2 H
   push    eax
* {6 F  {, D, |2 ^' Q$ J' L/ c* P   call    KERNEL32!_lopen( i. m0 N5 A) x! |: @1 g) p1 ^
   inc     eax
  W! X' E  J! m& x2 r   jz      006505ae                  ; not detected8 p( e. j: k' @! b% p1 S: D

: D& x( Z" _1 N# }
! x- m4 {" K" J" s1 b__________________________________________________________________________
( `$ l6 z* R& c: L! L, }( y0 \& W* T3 x0 g' W
Method 12' L# l& K2 r9 S) L2 _
=========
6 F5 r! q; J* E1 B! r& G* Z
" d+ u* A" S5 v! s9 t3 W% g6 }; DThis trick is similar to int41h/4fh Debugger installation check (code 05$ n# m% J: [/ D7 L  N# k2 p3 f
&amp; 06) but very limited because it's only available for Win95/98 (not NT)7 m4 t6 m* u; k' t+ z9 n- ?8 g" f5 y
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
* h6 d' \5 z( E- V6 f: @/ L" L. M* |/ _
   push  0000004fh         ; function 4fh9 f% t$ G/ T9 l/ F3 `. ?
   push  002a002ah         ; high word specifies which VxD (VWIN32)* `$ v0 b0 i8 P) B! @
                           ; low word specifies which service
" W# e3 O$ Z% v7 i                             (VWIN32_Int41Dispatch)9 O  x( N; A* K! V- F/ |/ W- e
   call  Kernel32!ORD_001  ; VxdCall
6 m/ Y* b7 R- P7 J9 Z   cmp   ax, 0f386h        ; magic number returned by system debuggers
( m3 S9 X& r- F: m5 z- p' v) f   jz    SoftICE_detected$ F  `6 w7 K# e2 Y4 T3 {5 s& B% G6 @
& g) g3 N0 m& j0 R3 a0 a
Here again, several ways to detect it:
, B4 {+ L+ i5 u7 P3 U
* p) Y6 d1 b5 ?# I    BPINT 41 if ax==4f/ K/ v3 y2 i; F( ^
2 [+ m% K: u" o3 X! K' C
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one( W( I& F7 N) C* h: ~- w- F0 f

: P9 M* B( ?+ N; I+ W7 C. K4 [    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A6 J8 I( f4 K6 }( v6 [

% c2 W! ]! U9 d- N, {0 k    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
- n: M' P$ K) X9 @4 W" [/ f4 g! M  A) }
__________________________________________________________________________: I1 I; n6 x( ^0 K9 P8 H0 h( N, h

  I+ {) v6 @7 G: eMethod 13! n/ L" B8 ?) D, U7 R
=========/ n. L$ |. O0 R- l
9 j& C) U5 v. w
Not a real method of detection, but a good way to know if SoftICE is
$ n# P- x9 S( B" kinstalled on a computer and to locate its installation directory.
4 [6 a( \! D+ o2 Z& i0 f; GIt is used by few softs which access the following registry keys (usually #2) :$ T+ q- L6 y7 _) p0 m& o8 m

! Z/ n) T; ~% H, D4 B* y. K" n% a' ?-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion* t4 ^4 @+ [; y4 x% Y
\Uninstall\SoftICE
+ ?& c' i' [" |( A6 X-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE  e. w0 ]: h/ U9 s& U* {  t; r  B3 \
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion! Y( Q' m7 Z. e4 O3 \
\App Paths\Loader32.Exe5 M$ u' B& E+ i- j8 Z& `

8 @2 u% ^9 c' D( b( m- m8 W( H, d; r: O
Note that some nasty apps could then erase all files from SoftICE directory
' F9 z  p; F7 c3 M7 G(I faced that once :-(, H  P0 B/ ?6 M/ v

; |0 H, q$ j/ q; d2 v2 ZUseful breakpoint to detect it:
+ E5 I4 S' \; M9 a0 K9 v9 i2 C2 M4 H& V4 z% _. E* |8 `
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'/ m) h3 m8 m) k; d

) ?' ~- g% O' {6 ^__________________________________________________________________________2 R/ l. Q( g! k, }- l- P# S3 ?

: _4 P" J  I6 h/ ?
  [8 C3 q; D9 ^$ ZMethod 14
3 _: b) N1 t3 L4 h=========
  y; j' M' O9 I; I6 d% e) m1 @& `$ F3 `, R. v' ^! r0 [8 W  D
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
! r6 Q6 E& v3 Ris to determines whether a debugger is running on your system (ring0 only).
1 s$ B) Z9 N! R/ u: D4 _( L1 b6 m/ t+ P! e  y% c) J
   VMMCall Test_Debug_Installed+ V' X) a; [- k! s8 K
   je      not_installed
8 [- r0 _" E% w# z" n
' W/ }8 X% K6 H$ F) KThis service just checks a flag.
4 K: p* m: H, r' D, C3 S</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部