About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
$ _" R7 K1 T; U% s& B  t, g<TBODY>
4 Y& K! v7 Y3 i1 j0 j8 P<TR>
; ]2 K% M3 v1 ?& a<TD><PRE>Method 01 ( X' A9 e4 ]1 P6 E8 J! o
=========
9 P! E% d" k3 X6 h0 K9 }- m3 m' ^* @
This method of detection of SoftICE (as well as the following one) is
+ l0 C1 Y: P7 V. S- yused by the majority of packers/encryptors found on Internet.
+ q; A# C; b9 V- `) e' v' L* _) AIt seeks the signature of BoundsChecker in SoftICE6 Z$ q, D% b1 F" {; m" |

- N0 F2 C  q9 l& B6 i% J2 g    mov     ebp, 04243484Bh        ; 'BCHK'# ^3 E) i5 d4 @; u- j+ U( b# H
    mov     ax, 04h( |8 |- F* l2 ~( V6 @" K0 D
    int     3       / \1 U8 d8 o! {
    cmp     al,4# Q2 M$ ~% Y' F8 }8 T6 F$ ]# o/ u
    jnz     SoftICE_Detected
  c& Z* I) N0 L% |5 k
# _4 N3 ]. H6 B, C* O! C___________________________________________________________________________
. i) h5 S- ~8 Z8 ~  H
% I. |2 ^4 _" z6 `, MMethod 02
. I% C( U# q, c- Y; t7 p( v6 ]=========
9 p/ w- i, G8 {$ s
, V$ h4 m6 d2 X- H: {Still a method very much used (perhaps the most frequent one).  It is used* a' E  k( P, W8 ^6 u" H& X1 w
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,0 Z1 W- v: Y. {
or execute SoftICE commands...
& R7 i" C0 K) }6 r  IIt is also used to crash SoftICE and to force it to execute any commands! P9 M6 h6 c  S# Y. ?, C( ?4 e
(HBOOT...) :-((  
3 i9 j! k8 D: M: L# ?
+ `! x/ x0 L8 A' d% G2 X6 {Here is a quick description:
$ `7 X9 E0 t$ n9 X" q! _& i-AX = 0910h   (Display string in SIce windows)1 a+ |- c3 C6 `( [7 r( J
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
2 N; w) [% x9 Q-AX = 0912h   (Get breakpoint infos)
/ ?9 n6 L! [, W1 @; o! o- I-AX = 0913h   (Set Sice breakpoints)
; _6 T* U9 E8 T" q& V/ [, l& S-AX = 0914h   (Remove SIce breakoints)
. N/ o, A5 K4 a0 o  C% k( i) F0 X( {) o# W2 c
Each time you'll meet this trick, you'll see:+ b' l9 H1 o- k! |* t# P7 r
-SI = 4647h7 D: H0 T' A. R& k3 @( U! I, }
-DI = 4A4Dh$ Y( b2 c& Z& W! B. b
Which are the 'magic values' used by SoftIce.
* _, _* v+ u5 MFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.' s7 u- I) P, Z$ Q: O

: E  c% w3 Q# F, N6 eHere is one example from the file "Haspinst.exe" which is the dongle HASP/ q% }) k( ^( j+ q- c( d1 Y0 W
Envelope utility use to protect DOS applications:
$ z4 F  F3 k6 @( [. c- B1 W% ]' g) c3 A* O+ E

- U& S, p  J: ~1 \: \" S& p4C19:0095   MOV    AX,0911  ; execute command.
( I) H+ s' W4 a) z) c4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
/ D; j0 P3 o- N9 E) x$ v' u% s4C19:009A   MOV    SI,4647  ; 1st magic value.- x5 U' r  ^( [+ Y8 j2 ~
4C19:009D   MOV    DI,4A4D  ; 2nd magic value.1 W( A3 ~4 h" d- q
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
8 n  u3 m+ y/ a6 T5 D0 C2 a4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute% R+ D! W% K% h8 g
4C19:00A4   INC    CX3 P0 v( N: m. ~0 v
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
& D  h5 d  E" V' @4C19:00A8   JB     0095     ; 6 different commands.
) T1 h- }$ ~3 d5 Z2 ]4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
) B/ l4 m7 N/ g- f+ r4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
5 ~! P/ M3 W8 j- y4 D* t. A& W6 m" b" L! K  q6 y& i
The program will execute 6 different SIce commands located at ds:dx, which4 @: [" k. }7 M: [$ x! I
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
" @' ?% o4 `, i. H; v6 f4 P; S
; [% F( p5 z* {) v* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
5 m0 P4 t1 o, F# g. d+ E( R' h' D: \0 o$ |___________________________________________________________________________1 K  O+ D3 _. H6 A+ [0 b

# P( V! c/ Q! a2 z+ a& E6 l9 ?( u; |1 f( ]8 w
Method 03
5 ], y7 I0 T+ i$ }6 }=========
& }$ k! @/ |* c0 X! l
6 \6 A& B. m; c) z: KLess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
4 c: `2 c- [) k(API Get entry point)8 U) t: }9 L' W# p% |# ^& P( q7 y
        " o8 i% @' h8 |$ u( f

+ e/ D, }! r' h    xor     di,di4 X4 Q5 w1 z0 c& M7 O
    mov     es,di
+ R; C' f& E# J% M3 x. K    mov     ax, 1684h       - {5 D" d# d9 p9 Y7 Z  p8 P( u4 Y7 x0 m
    mov     bx, 0202h       ; VxD ID of winice
& Z9 k5 V* [1 o4 Z8 L    int     2Fh
: ]# @. e5 x" |9 R; I' R, F5 z    mov     ax, es          ; ES:DI -&gt; VxD API entry point; S  A/ u4 A1 G. w
    add     ax, di+ ^" `0 ?+ C( ?& k( N3 G
    test    ax,ax
$ n" j) p  o9 F& q! _    jnz     SoftICE_Detected
1 e& O6 O& O% |; T
  }  p% q. \+ w* T$ K4 r! W0 ^( u___________________________________________________________________________
; E1 U  i" W0 k! ?" `
. W4 M' M( V' g! V4 p6 XMethod 04
" X9 [6 N: X- @3 r9 v; `=========0 J/ r5 z. N4 P1 C4 C" P

) w$ x- j' v# P) Z* o9 {) K; @Method identical to the preceding one except that it seeks the ID of SoftICE$ s) t: X& F9 q/ u4 x
GFX VxD.7 n( ~/ b# W+ S, _- F2 n# x* |

: o" p; L; [/ X* C$ M! K    xor     di,di
' q& A+ U% F6 Z  |6 ]8 I/ ?) V    mov     es,di
0 Q" G# O( A- |0 A( H) m( f    mov     ax, 1684h       7 h1 q' t9 U5 p, N% o
    mov     bx, 7a5Fh       ; VxD ID of SIWVID
: I% r+ }5 Q4 \# Q    int     2fh! B# v9 p$ T2 \. l% E. [
    mov     ax, es          ; ES:DI -&gt; VxD API entry point, n' q. `& t$ X: \6 V, w* J
    add     ax, di
8 A6 W% Q: b3 ?/ l- X    test    ax,ax- v. ]) q* ]) Y# h9 y
    jnz     SoftICE_Detected
% ~6 m7 ^; x! _0 {9 f% I* q/ F
1 \# O' v( L, N) Y__________________________________________________________________________8 F0 F. b# i6 {$ H" L& o9 }
  k& N4 M& J; c; @

# {8 A# x, t: A* XMethod 05  K6 O+ D" R6 M$ s$ w* ^" g: ]
=========# F9 @. R5 R) I4 P, ^
+ K& D6 z  u2 ?" }
Method seeking the 'magic number' 0F386h returned (in ax) by all system
2 r4 ?" K& m4 U2 C% udebugger. It calls the int 41h, function 4Fh.; p( ^: u, H' `8 W# W' _7 L
There are several alternatives.  , r! q% B/ _6 V

$ w. n) m+ @  L5 P! iThe following one is the simplest:
2 l/ x' F9 h; L
; u" {' }7 R% o- n: o* ?2 X$ k    mov     ax,4fh
, x0 f, ?2 |8 l+ I    int     41h
; X4 Q. q0 O0 e% R1 e, V    cmp     ax, 0F386
0 L+ A* S# m7 g    jz      SoftICE_detected8 T$ n  U  d2 Z+ _: b8 l9 R

  {/ B  c" }( |: n; n# t* u0 u6 Q. m. c& D
Next method as well as the following one are 2 examples from Stone's
( C5 z- p% ~) ~* }"stn-wid.zip" (www.cracking.net):
7 z( v2 d! j2 G5 R) J- j8 R7 E% d$ y! a! L' O: X
    mov     bx, cs6 r' y5 E2 Z, p" H6 W
    lea     dx, int41handler27 `" ]- M; P) m6 C$ ?
    xchg    dx, es:[41h*4]3 n: {$ }1 F# `9 R
    xchg    bx, es:[41h*4+2]
+ m4 f7 o, a* M- f/ m" i, i5 j    mov     ax,4fh
3 B- K* t0 M: ^  I    int     41h
4 m6 S1 R+ A* p! E: |    xchg    dx, es:[41h*4]
  p! N3 |& @! p& a7 g    xchg    bx, es:[41h*4+2]
8 _" D$ ~# Y# R% q. m    cmp     ax, 0f386h
1 S2 _, y' S% R/ ^9 M, D    jz      SoftICE_detected1 k: F! k( \' B1 v* f* X0 ?
+ y1 a( s7 Q% Q, P
int41handler2 PROC
- x9 i1 V6 E0 C5 n& h2 X) q    iret
: e- B* H1 U8 t* t( Iint41handler2 ENDP
6 Y6 s$ C. Y  [, ?  J% \0 B. h: [; X2 v( M: I! M  I1 [# s

( I& m) y; p( @9 I) e_________________________________________________________________________7 P) ]4 z# [# w8 i2 C  Y
/ i4 K0 j4 x/ F1 z& ~( M" s

* I! F$ ]' U7 V3 T) _. tMethod 067 M3 B2 S. ?* R* `$ |4 y
=========
1 X, q) F; q" r: }( ], K+ @$ {4 E7 L1 e# l) F

' E- J0 Q# K  T& F2nd method similar to the preceding one but more difficult to detect:5 K) Q4 x' Z" f, O

0 q) q4 ?2 l( o' a; h( V0 t( t# h/ G% C6 S: K) m
int41handler PROC9 A7 _) x. [( ~% f+ G- h
    mov     cl,al" B" J& X3 b& X+ _7 h0 ]
    iret. b0 g+ ]1 ]- l1 z2 L
int41handler ENDP
+ M( I5 E2 Y% [. }* Z" K' Y# z! p3 A0 v: ]
0 L9 d' l5 B- }8 ^3 F; N  _; P
    xor     ax,ax
) t2 K- j. x5 l5 h+ y& V. |    mov     es,ax8 Y) H4 J# B* s
    mov     bx, cs& _3 \+ m' D& q" U" x
    lea     dx, int41handler
3 t8 s1 _  A/ y' ^# W    xchg    dx, es:[41h*4]
$ `5 G$ X$ K5 N    xchg    bx, es:[41h*4+2]/ U0 @" G9 }6 S/ p6 @: Y
    in      al, 40h+ Q& z7 V8 R9 N/ @" N9 W( F' o6 q: P0 O
    xor     cx,cx
+ d$ I7 w$ s  Y) `- P    int     41h; w/ H6 f) }' z
    xchg    dx, es:[41h*4]6 S- n. t6 D! b  D+ c, w& }
    xchg    bx, es:[41h*4+2]
" x3 X1 w5 b! C& r5 t% U6 _    cmp     cl,al
1 ~5 w+ R- E! D: p, k    jnz     SoftICE_detected
+ A% G+ L- k9 U( O/ z: Q. P# Y' v9 e& Q/ |  A
_________________________________________________________________________
: R' ?9 m6 J) W
, @8 J9 ?7 v4 N: Q* ?) q8 Q& eMethod 07
: O9 e- U( V& P- _. |0 u8 Q! ~=========
8 e+ ~* x. W* l4 O- {6 N+ m$ r  g3 k4 X" J+ g- H  e
Method of detection of the WinICE handler in the int68h (V86)8 u+ J6 W* p  a: r7 o9 e* t

* r" d7 c7 ?. a: a" h* z; [. J    mov     ah,43h
* p+ o. K3 r$ U# F. E: H; n4 Q  C; x6 C    int     68h9 `5 [/ k' Q- _3 v/ c" a! Q5 h
    cmp     ax,0F386h2 P% p* q! C: L1 O) n& t# r& U
    jz      SoftICE_Detected
, q4 d: o( c9 d# f1 M/ h
* C8 l- ]0 s4 k0 R$ p2 ^# C+ k$ c; C4 \  v5 N
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit* W; m; }8 `: T' e
   app like this:
  J/ K9 o5 Z" E% }# ~7 W+ q* h. S1 _. E  x$ _- ^! y
   BPX exec_int if ax==681 @0 f% |2 H( B: M: G1 O3 |& o& }
   (function called is located at byte ptr [ebp+1Dh] and client eip is
/ j# C" q' Q* Q* B4 f   located at [ebp+48h] for 32Bit apps)
: J2 t/ X. t; ?. n6 p9 e__________________________________________________________________________
$ Q' g, u. }  @: Y! i5 m
4 a1 W! A9 ]5 u1 r0 C
: a3 c8 B; P" q( AMethod 08
& x, I: n+ @; G3 d' T: C  @=========
, i0 F! m. z" `
. a6 X2 O; d. K% _8 BIt is not a method of detection of SoftICE but a possibility to crash the
+ i. V$ t3 v6 r8 I8 X0 O+ i* ^; @0 Fsystem by intercepting int 01h and int 03h and redirecting them to another
+ S0 f0 Q6 \8 B% E# [) Iroutine.3 m& |1 {) R8 t0 l) a: `4 E
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points) X# w  n+ s4 J2 p+ v9 K
to the new routine to execute (hangs computer...)
  X% X/ L+ l/ k. S6 R
, i0 O, y7 d% j) I. I$ B- J% ^+ J    mov     ah, 25h
. \. A/ [/ |2 V! a    mov     al, Int_Number (01h or 03h)/ [7 }/ g3 b; \& f# ~
    mov     dx, offset New_Int_Routine
- R! O2 T6 ~6 r    int     21h1 Y% G7 D) v; y% l* S4 h; E

3 c8 L: B7 Y% w5 Q__________________________________________________________________________
- f) Q- l' \8 I* G' J1 c8 x  ]# p0 P' o/ [# f, n% m
Method 09- k  ?' ]! n* Q6 d
=========
; H; A8 S1 J& N/ ?( Q/ n5 `) |, Z, W" _7 G/ v# {
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
& ^8 C8 j/ ^# fperformed in ring0 (VxD or a ring3 app using the VxdCall).5 _% R5 J5 k" j3 B5 N0 _. ~6 `
The Get_DDB service is used to determine whether or not a VxD is installed
! d/ Q2 Z& d! hfor the specified device and returns a Device Description Block (in ecx) for/ ?9 x6 Y5 O8 g# _7 d0 m
that device if it is installed.
2 e" j* V! S$ n7 {1 o1 G0 Q- K# Y3 a& q0 J3 o0 ]  ]0 |; _
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
, R' u1 e+ V3 m   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
5 u7 S) q8 s2 S2 W5 D   VMMCall Get_DDB- ]1 L5 ?$ t0 [2 b
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed. v3 M0 @  L& u& }) J, e

) j6 }' r3 K$ c3 G4 n# f* FNote as well that you can easily detect this method with SoftICE:
" F) a3 m  M2 B( ^   bpx Get_DDB if ax==0202 || ax==7a5fh9 }  P# X* d  q! x. F

8 R% ~* n4 |/ D* y: ?6 \, t__________________________________________________________________________" |$ v9 q2 A9 h$ l. Q8 R: U; d$ t0 a
' x$ o1 F6 k$ R+ E. p2 ?
Method 10% d) x4 E* P+ d( [1 S9 U
=========
9 H8 m' U- |7 I* w. R
) f' U1 j0 ~& n- j) u1 d=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with8 }! S9 z& ~/ R- s3 w# @
  SoftICE while the option is enable!!' s! e! Q$ T6 d9 Z

' b' u$ ]( `6 ?$ sThis trick is very efficient:
  S) ~. m$ n& wby checking the Debug Registers, you can detect if SoftICE is loaded, h6 m/ l( O2 `' x' Y
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if* O) a4 Q- ?+ }, |, e- X
there are some memory breakpoints set (dr0 to dr3) simply by reading their
8 Y) p6 Y% V5 r3 avalue (in ring0 only). Values can be manipulated and or changed as well
6 ]$ d! L5 V% @% g) I(clearing BPMs for instance)
- y$ K! d9 M$ B5 T! F% `
+ d5 M: N; T! ?# Q! A. W7 O__________________________________________________________________________2 N9 K: k( j# @* S3 F4 |5 r

( ^3 N) h- B, A& @2 P; OMethod 11
& |7 V( U7 }* A  F=========, M; c1 |1 I. G( c) R2 \. ?

0 d; ~- x) u, F9 B$ SThis method is most known as 'MeltICE' because it has been freely distributed: a) T: @! a' C+ @$ M: m
via www.winfiles.com. However it was first used by NuMega people to allow' x6 F5 e9 u) D0 |
Symbol Loader to check if SoftICE was active or not (the code is located
! \" p# B! c  jinside nmtrans.dll)., O& z+ U& c  W; M" g2 ?

9 M7 \1 B1 j& S( |  @The way it works is very simple:, K! t) g% j6 K
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for- D6 L( b& I9 w" q4 t: I5 F
WinNT) with the CreateFileA API.
4 @; }4 z: [7 O' @+ q9 ^
% P9 a$ W( r, h; E) [! THere is a sample (checking for 'SICE'):
0 P* N! P7 k& W2 V. V
' l7 m6 x) C- CBOOL IsSoftIce95Loaded()- }+ w7 M- s# c3 k( `  Y
{# I& h$ B6 Y+ ~* |  a5 `
   HANDLE hFile;  
, `0 Q# H( J$ K4 F3 A9 g! g* x% r. _   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
8 q# Z& }* X+ p2 @                      FILE_SHARE_READ | FILE_SHARE_WRITE,
% k% k0 }4 U* b( O3 x8 t. r5 N% L                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);5 g8 ^- M# o+ C6 K5 U5 n
   if( hFile != INVALID_HANDLE_VALUE )
0 s6 {) _, ]( V   {3 o% Z; }- L/ E5 u- u/ L4 U
      CloseHandle(hFile);! c% i+ `& _& ~- j2 X' G7 j1 o- V$ X
      return TRUE;& y& B0 f1 @) |8 h3 s, Q$ g
   }
+ f5 x! N3 T8 b  V( u   return FALSE;. O' S* y8 Q1 e/ K
}
3 S; t5 J, v4 W, F# c" q8 o* e4 u: ?0 ?
Although this trick calls the CreateFileA function, don't even expect to be& H" q7 y- I: R7 c
able to intercept it by installing a IFS hook: it will not work, no way!
: P' Y, c" v9 U/ G8 O  jIn fact, after the call to CreateFileA it will get through VWIN32 0x001F
( p0 B2 M! w9 e* h8 Q9 b6 Gservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
& x0 T! _* E# p4 d& Y( eand then browse the DDB list until it find the VxD and its DDB_Control_Proc/ @8 j3 D! q. T% C1 B9 e# e' u
field.' w6 S+ E2 N, l' p
In fact, its purpose is not to load/unload VxDs but only to send a
' p0 o. e* p, f! W+ D6 VW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)& ~: y+ W# e1 Z% V; q/ F6 O9 H1 E
to the VxD Control_Dispatch proc (how the hell a shareware soft could try. {+ {5 @  b# L0 A/ V3 K! y
to load/unload a non-dynamically loadable driver such as SoftICE ;-).8 V" X& y- L7 O/ C6 \' j
If the VxD is loaded, it will always clear eax and the Carry flag to allow( d; T% w4 W2 I" u, \
its handle to be opened and then, will be detected.
; q( M; p% O4 R8 [+ U% g) N; _You can check that simply by hooking Winice.exe control proc entry point" ^" A( s& Z' i+ t
while running MeltICE.0 d* X. Z9 \2 A$ G
  F/ c. `1 o" e! G# d8 W3 B4 `. Y

6 l4 o& d+ h0 v  00401067:  push      00402025    ; \\.\SICE2 _. V0 Q$ D. r# E3 L7 \+ y
  0040106C:  call      CreateFileA
& ]1 X% Q7 Z# @  00401071:  cmp       eax,-001
' k$ \6 m1 Q/ u# E! r" d% G  00401074:  je        00401091# C: b* V" Q, W7 }+ t
. }8 M& @" U1 c3 ~. [8 D: l* y2 {8 g; j

. N- u4 P+ ^  R1 n2 a7 gThere could be hundreds of BPX you could use to detect this trick.
' M3 ?7 C! C4 p+ K" h-The most classical one is:
* ^) n* j5 h8 @8 @2 @/ h: M/ E# }  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
; z9 R: }. S2 k    *(esp-&gt;4+4)=='NTIC'6 W5 s1 _& F) t6 ^: [3 P2 h7 W

" x' h0 ?/ u: E9 V. x-The most exotic ones (could be very slooooow :-(9 t; n: b0 g4 s. [' D
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  4 k' i: N+ r4 x" G0 S* f
     ;will break 3 times :-(
/ @$ ^% g  W% y8 ?0 s* A- k8 S# e- X9 y5 e
-or (a bit) faster:
0 K! x4 \8 i' Y& Y- ~3 z   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')) X2 k5 D3 ^3 i8 k3 w. W, Q% Q

' E7 Q+ K: N' s3 j! w   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  7 I3 @# R/ C* J9 V7 W. J
     ;will break 3 times :-(# {5 `" O( T. a

8 G2 ]  P& m5 S2 T1 K7 T-Much faster:
) f9 D' T) W& g, j& K4 }   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'6 q0 z, c& \! l" n) q0 Y3 [" a
  {( N  d; }! N; U
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
. C* R( d9 L+ B2 a) M, {- H1 y9 \. bfunction to do the same job:
" \$ g5 u; i6 G* T$ N( D
: F  Y: u: q5 u* }( T2 @   push    00                        ; OF_READ
/ B9 k4 }: r0 I7 g; f   mov     eax,[00656634]            ; '\\.\SICE',0
: r" O) U' @$ F, O+ G1 \   push    eax( N8 X, V9 ?6 [3 r8 x
   call    KERNEL32!_lopen
4 ]7 E6 V/ A3 ^+ i6 W   inc     eax
/ i( b2 r5 r$ o. h   jnz     00650589                  ; detected
. T9 m+ P& ]) h0 }1 N& X7 h   push    00                        ; OF_READ% A! E/ u  ?( S' c6 W( {
   mov     eax,[00656638]            ; '\\.\SICE'
  P& B: Y6 p% d; \0 D! c, Z   push    eax, P  C# x2 u! s% q5 e, k+ d7 z0 l
   call    KERNEL32!_lopen
8 R# E% M/ s+ {$ \/ u$ p   inc     eax
+ c+ a$ F5 s; r0 Y   jz      006505ae                  ; not detected, G3 R4 i# N' A# D

; V; |2 a/ e1 i$ i9 [+ B# B: P
% i2 e* F2 r$ Y, ?/ @__________________________________________________________________________- D  _8 f' m1 Y  y: k: }5 _6 ~
! t( R1 W$ S2 ^- o# ~! d5 R" \
Method 12; n. F6 r" U, c& D
=========  v, n8 s; N& ^1 R; y" P" n- k  G4 `

9 i% P* t- s/ VThis trick is similar to int41h/4fh Debugger installation check (code 05
/ ~' R) o) @7 n&amp; 06) but very limited because it's only available for Win95/98 (not NT)" g7 D+ E3 X8 _1 v
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.9 Q  ?9 }+ v$ O) o8 X

7 M7 g+ Z7 f5 v/ o1 p* n   push  0000004fh         ; function 4fh6 H9 [- k; `) Z0 o
   push  002a002ah         ; high word specifies which VxD (VWIN32)
# I# s  u. V7 F1 I* c8 m                           ; low word specifies which service
" H# M0 a5 R/ a; S; F+ U4 c3 j2 p4 \                             (VWIN32_Int41Dispatch)
& Z, C7 x% {% s5 T! y% a, i   call  Kernel32!ORD_001  ; VxdCall  ]2 S7 s  Q; F1 P
   cmp   ax, 0f386h        ; magic number returned by system debuggers
) s0 T: w: K& Z" z' N   jz    SoftICE_detected4 q! E+ u; f! K4 h; ^$ ^/ u
/ D8 F) A; L+ x' U
Here again, several ways to detect it:9 A* w: S' u5 ~; D3 Y
! |9 @+ L5 }# T; F/ Y
    BPINT 41 if ax==4f
8 R2 `" k5 Z: J5 o+ O4 Y7 L: u' E) L; s% |
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one( G7 J  S4 l3 U

+ u+ M  O' H. f* t; b    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
6 R5 U% b0 ^+ t' b9 g6 G; I
: O/ R3 {& {2 e) @* m' U    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!( G+ H& Z: W: V8 C. r8 Z
! N4 a7 j. i8 L  I" G9 ?1 N2 e
__________________________________________________________________________( C2 ?3 C$ i6 m

( e7 P! Y3 R2 [' KMethod 13" Z- R" ~5 Z# H4 |* e
=========" `! ~( s3 @  y/ |9 z* |" S

* E. L9 q- @# FNot a real method of detection, but a good way to know if SoftICE is! ?7 T6 V: }1 a* g  _
installed on a computer and to locate its installation directory.& b% `/ Z9 G2 s6 r! f1 E0 x
It is used by few softs which access the following registry keys (usually #2) :3 p% V' Z" L- ]# V% s/ i% J2 R" G6 y
7 a4 v: w! t+ n8 d
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
. c$ C$ I" @8 l3 @9 G\Uninstall\SoftICE/ T' k- c3 f1 i: Z4 U5 V3 @
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE7 A( G$ u4 ?9 n' s9 g: }
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
! W8 U' h$ c, G1 S; u' M\App Paths\Loader32.Exe) F5 o/ j, J+ T+ G7 L4 C7 `6 ^

6 C+ f! h) {4 o7 d3 y, R4 o5 [, _
Note that some nasty apps could then erase all files from SoftICE directory. i7 m9 ]2 o! {# Z; o( w# ]
(I faced that once :-(0 Q5 ~- e& F4 L4 {
* Z# P6 ]. ?; L' n: J; K
Useful breakpoint to detect it:
( W& M7 n0 p( G2 E* i, j5 M* D# W# K% D6 E- l; f
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
  R1 c: \+ m% X, C" i+ y( Y0 z2 w7 X& S" j& R. Q* m# Y1 \
__________________________________________________________________________7 P- I. V% z& E
4 [  {  W$ ?  F9 r! }

! ^1 }2 O2 [5 MMethod 14
3 L, q8 P, P5 v3 M# m  l' O=========0 Q$ S$ O9 e- J6 J9 j( H

5 N% o$ ~- O9 w5 Y; w1 L: I! ]! xA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
' O3 b( E' w' Z7 y. G$ s4 Y) [is to determines whether a debugger is running on your system (ring0 only).
9 w( X7 x3 c% M& M7 p4 z" x* \2 B$ q
   VMMCall Test_Debug_Installed
6 C' t7 e% J8 @2 ]6 x+ Z6 X$ x   je      not_installed
; T! \3 k2 D: M  M6 x$ E6 Q3 o  [# Y1 }
This service just checks a flag.) t4 {0 j/ V4 y+ q( M& k# Z
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部