About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>0 c' e6 u) f! [. \1 f# _1 R2 d/ O0 D
<TBODY>1 S% m: i/ J! r( C( d
<TR>6 {4 u' R* S3 [
<TD><PRE>Method 01
. `7 |. q% _; r2 o=========5 R) n  S8 w$ g, P  l
" U/ |$ n, H0 B6 C& N
This method of detection of SoftICE (as well as the following one) is
5 r" d9 |& Q* @* c8 ^; |; W. Sused by the majority of packers/encryptors found on Internet.5 g7 P' g4 q8 }& |
It seeks the signature of BoundsChecker in SoftICE
1 C4 f# x4 U- b! ~4 _/ B" f6 r/ n& o6 {% _* S& H. n0 d6 I  w' G) k
    mov     ebp, 04243484Bh        ; 'BCHK'
: H  q( x1 e' l- f    mov     ax, 04h
' t1 ?' Q2 P. h5 G( q8 ^" \( w    int     3         `5 W, P1 ^# N% }( [
    cmp     al,4
8 x6 T4 E; F) ^    jnz     SoftICE_Detected
4 t0 r- K0 P7 j# t' \5 v$ B$ {5 k( d$ p  T; r& d
___________________________________________________________________________
6 G* P! _9 F9 A" R& u; C9 b# z  T! o" G: _, t
Method 02
9 E4 O* r/ \  o5 ], i8 h2 R=========* n7 w3 v, R6 v; ~! G% I" g

) v1 W# `3 {# _7 ~- O+ R$ VStill a method very much used (perhaps the most frequent one).  It is used
& E: W' ?9 [* C8 uto get SoftICE 'Back Door commands' which gives infos on Breakpoints,
% `' }- O7 y3 b' a( f3 U8 _6 Zor execute SoftICE commands...
, F5 R9 s; t. Z# R$ MIt is also used to crash SoftICE and to force it to execute any commands7 r; Y3 M  X+ `% A/ m
(HBOOT...) :-((  
2 j  M3 D) H3 U+ s4 {  _  {( [) S, D6 u' a: ~, v2 l
Here is a quick description:
/ h5 R( G5 s. d-AX = 0910h   (Display string in SIce windows). g5 }( I: L. c) n, n; _
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
7 c. q. m6 `3 M. C  i1 a-AX = 0912h   (Get breakpoint infos)
9 |2 x8 H- I6 r4 Q4 I# F" U4 V-AX = 0913h   (Set Sice breakpoints)
3 U. C! A$ I1 C-AX = 0914h   (Remove SIce breakoints)5 \. ]8 T" q. ^& I6 G

6 M+ R% Z2 H% V3 @3 o5 REach time you'll meet this trick, you'll see:( {0 C/ T- X7 A8 y
-SI = 4647h
) t6 g& w9 ~0 h1 e  |-DI = 4A4Dh
5 x3 `! {+ m9 U8 A& ]- JWhich are the 'magic values' used by SoftIce.
; p: ~: J7 i6 ]For more informations, see "Ralf Brown Interrupt list" chapter int 03h.# }, t6 N7 r, w. ~
: u5 Y9 m& N) B! M6 t- C
Here is one example from the file "Haspinst.exe" which is the dongle HASP6 l5 U6 G% W$ J# `4 a( M
Envelope utility use to protect DOS applications:
$ ^6 `! X. S) p! @4 `
/ U, `0 u3 |6 T1 |! J3 G3 z+ h1 q  B: E, e% _. D# g9 W
4C19:0095   MOV    AX,0911  ; execute command.
0 T0 }' E2 L; F, L) B& e3 V& M* B6 v4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
8 ^) e6 f7 v$ e: k/ ~4C19:009A   MOV    SI,4647  ; 1st magic value.* |9 c# W) ?9 Q# q8 [6 x
4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
$ O: k6 B+ j0 O8 [9 u: h4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
" `& H( Y  v  k4 l5 H6 k1 }4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute% B% S# }9 B/ w
4C19:00A4   INC    CX
# S7 X. P" q6 P, e- Z; D" j- Q4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute% f3 j4 d  H4 O/ x
4C19:00A8   JB     0095     ; 6 different commands.8 B% ?# J; ~+ i
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.; M5 H& b2 J6 N2 V+ \% g" i! c
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)3 e& r* }+ w9 n2 T
* c. J% R4 ^( u- c
The program will execute 6 different SIce commands located at ds:dx, which' J$ M( N$ t4 v
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
3 a. D! f; w% m& d; ~& j# g% ~  v* q! f. x; P
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
0 f0 q# Q3 @0 v8 U) l3 q% O6 M___________________________________________________________________________/ U6 u) ^! |! ~  i; p  W
& |* ?' M! ]6 J
1 K5 q) t- Q) G" v: J& U7 g& k
Method 038 V5 E2 A- b  V! z
=========
& Y2 E- f9 u2 Z/ }7 m/ h
, N, [: u) d, a4 i: B# ALess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
6 K% u  d' {5 v(API Get entry point); \7 x6 Z' }4 T& [4 t: B1 ~
        # f* Z1 z* ^: U
4 o1 c# ~$ o7 H9 n2 Q' Z
    xor     di,di
# C# a* Y8 M8 \; ~/ r& s    mov     es,di$ W% B7 N9 n% t7 z
    mov     ax, 1684h      
) U% m; M  |) E- s) v( q    mov     bx, 0202h       ; VxD ID of winice
* G7 {9 _! W# f9 R- h  F    int     2Fh
$ t2 K0 P) m& L    mov     ax, es          ; ES:DI -&gt; VxD API entry point
/ H6 P/ N% `8 i    add     ax, di
2 I  E) K: i$ r2 l0 m! n    test    ax,ax, C" V4 ]* B8 E7 j1 f* D" j+ n9 J
    jnz     SoftICE_Detected
. {! ]( T/ O, o4 s0 D, F( I
; V1 k( D) J: V2 q0 g! R___________________________________________________________________________
/ B+ ]5 I& K. [4 _3 H! w4 j4 J
1 e' V! F  O- u2 }! w0 {Method 04
. Q7 z" ~- ^' g* C2 A" [/ F=========% j8 `8 L7 a: o% V) A. `
+ ^( Q# g+ R  r6 A* F( X6 U- s
Method identical to the preceding one except that it seeks the ID of SoftICE# C+ z7 u3 V$ z& w- G) {
GFX VxD.
. q# I" z3 ?/ T) _1 ?  n; o) I0 z! H. [$ t8 i( y3 L  ?
    xor     di,di6 u: ?; Q/ T3 c, O
    mov     es,di2 y: B3 ^. M* @) ?
    mov     ax, 1684h      
* y; I  j) B$ c7 S# R" J  B  Y    mov     bx, 7a5Fh       ; VxD ID of SIWVID
! i8 r! T+ F9 z3 ^- T7 F    int     2fh8 m" }$ O5 V# F1 N8 c
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
- S0 J+ Q% f: k    add     ax, di
9 q  `: H& a( w' x$ m0 {7 q: ~    test    ax,ax' u1 @5 X+ N/ @9 D- |: T1 z  ^
    jnz     SoftICE_Detected
% B  Q% b3 ^8 T4 @( Z& S% p( R4 ~
0 A' ^8 @7 k9 c- X& M__________________________________________________________________________
* _  E6 e( o$ z, D- @
. j5 h' ]# s7 B8 Y2 I: z/ W( f; J9 T# ]. \, q$ O
Method 05
' i  q6 F% y3 X% c# S$ |=========
+ x  n2 t0 f3 D, B6 u. ~  _3 e5 L: Q
( ~9 l) y" r* `Method seeking the 'magic number' 0F386h returned (in ax) by all system
& z/ B6 ]. d1 X+ x' {debugger. It calls the int 41h, function 4Fh.
: B+ {& s: K3 F2 f, Q% P3 _+ _: {+ DThere are several alternatives.  
$ Y% K+ @  `( g1 Y" @1 Z' z4 w6 W% p$ [
The following one is the simplest:
! ^5 C! Y0 M: Q# r5 \" ^) Q
& p6 b9 d1 J' Z( U+ x    mov     ax,4fh' M5 _) O5 _7 H& Y. s$ \
    int     41h* B: a) e% B" _% E' l
    cmp     ax, 0F386
6 v$ H2 D0 _* z4 D    jz      SoftICE_detected
  Q5 _- ]( [. e5 b) D% j1 V
& T0 i* s! C# e' S* B2 ^/ T
! c8 N- h) Z/ @& a( k% fNext method as well as the following one are 2 examples from Stone's - ^- ~( {5 [3 W: h
"stn-wid.zip" (www.cracking.net):
6 M/ F; `7 F: t3 I( ]4 X0 `4 }$ J6 B# G
    mov     bx, cs) I" z- v+ H2 v" W
    lea     dx, int41handler2/ ^' l8 Z5 D- ]! r
    xchg    dx, es:[41h*4]
7 v1 \7 i. e" h  C    xchg    bx, es:[41h*4+2]
% R! U4 I/ p6 g- R4 b3 J    mov     ax,4fh
% _4 V: F3 c$ D, A0 c* ]& m$ i    int     41h7 l/ r/ j: Q) \, w3 D6 w5 ]# v
    xchg    dx, es:[41h*4]
% o* n: \. o& I' H    xchg    bx, es:[41h*4+2]! H' F7 A8 |5 j+ ~
    cmp     ax, 0f386h% E% x0 G) r3 V- z# n
    jz      SoftICE_detected
0 z2 F; h8 p' o( F/ _' `! }/ q- K7 {, f: c/ B4 C- M/ W
int41handler2 PROC
/ a" Y! o8 e; m( G    iret# K) W- I% i8 ?5 L& R: Y! z
int41handler2 ENDP
" a  Y2 D/ U2 ~, I( H4 v9 v7 `" F* O9 |; l. n$ a
7 S# {2 I# u9 \/ J
_________________________________________________________________________
# W* W* A6 @' G) s" x  m8 t+ o& A" B! ~: N4 X: e
" H# M* N7 w. \2 S
Method 06
5 X, U" b9 ?' H1 l* W=========
2 D, |) \  G$ \( L" h/ s2 `0 H8 V( A* m
# @  s9 r8 l8 m8 O# b- a$ `
2nd method similar to the preceding one but more difficult to detect:
' _4 d5 J; g( j+ J" \& h( H3 L; I: I/ B: q+ ~

; i1 e+ @$ n2 ^) Hint41handler PROC5 i+ v* }' ^) a& I
    mov     cl,al% f: J7 L0 _* c3 G, k
    iret0 B* Q, D4 C. n( F
int41handler ENDP+ C! v) {2 Q# S

' r$ j% e5 z) X' c' {1 A
# @1 I! _2 z5 M+ G+ d    xor     ax,ax
" q0 z  K: a% ?! z9 S7 r    mov     es,ax+ C, z1 q( @4 p7 |/ U# E# D
    mov     bx, cs- Q3 |& W% j1 ~
    lea     dx, int41handler
; E1 h, q: Y0 K- Y: G1 G5 }" S    xchg    dx, es:[41h*4]" e* n4 o0 t% @( l1 F0 c- U
    xchg    bx, es:[41h*4+2]
5 M8 s4 n2 d2 f% }7 ?    in      al, 40h
& Y; t. Z2 i3 K- E  r    xor     cx,cx) K+ A- }+ d, u- v7 E# K
    int     41h
1 G& C) n/ n. Z: ^: N" j    xchg    dx, es:[41h*4]& T+ v1 G( E! P/ M, Q
    xchg    bx, es:[41h*4+2]& X5 J( J# a) t5 Q
    cmp     cl,al% K. ^6 `' Z6 B9 g1 I4 T# d: T
    jnz     SoftICE_detected, Z* p7 v5 u4 N2 B  d1 @
( B/ s! |' `# R4 r+ q( i
_________________________________________________________________________. h  k& G$ ?  W; o6 ~

) J0 }  j) z7 m6 r9 D& h1 NMethod 07
* E' o9 E% {; @' H% S/ R4 ~+ p6 \! E' K=========
" @3 n% Q! G& Q( i3 B
- [8 D! G# C) f" X; m7 {Method of detection of the WinICE handler in the int68h (V86)7 y5 ]; b7 r) F- q& H

' l" \& j$ r, S8 P    mov     ah,43h
$ t# k9 ^/ o9 s' ?+ _/ G    int     68h0 _* ~, {* X& T: O* ~+ [
    cmp     ax,0F386h
5 J) g- M. _* h/ z    jz      SoftICE_Detected
4 Z3 |  ?- t( r- d5 ?  Q& v
6 n0 G" l/ Q6 f+ j) j
" A  L' d% Z2 K* D  |9 b% c4 i=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit4 c" b+ K- T, b( S
   app like this:0 P7 r% D; r& Q$ u
* U, `; U, E  e! m3 Y3 {
   BPX exec_int if ax==681 t, {4 C% g' A
   (function called is located at byte ptr [ebp+1Dh] and client eip is$ A7 K7 q3 G, C
   located at [ebp+48h] for 32Bit apps)& Z; }; ?3 x1 D9 W
__________________________________________________________________________8 q. {8 d0 X7 w3 ]: k
2 b8 a+ z( F& l# C" B% O6 L
$ v  ^) K# v7 u8 E$ m9 Y
Method 08
8 M- i% m1 X1 ]8 Q=========& k) y9 @0 C' i8 a5 b7 u# z

4 _( s( M9 ]4 c9 b3 o" Y9 t9 W) {It is not a method of detection of SoftICE but a possibility to crash the
( v0 J' O# q1 R( z: j  Osystem by intercepting int 01h and int 03h and redirecting them to another
! ]: z1 J' W1 Q! ]. w* broutine.
2 V. x) w! q0 Z& ]It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
, q: \: Q, M$ N/ ]to the new routine to execute (hangs computer...)( [4 J" w5 v( n3 Z

! o; {7 z! T8 H3 o    mov     ah, 25h+ D/ F6 s7 l  u( m
    mov     al, Int_Number (01h or 03h)" h# @; j$ K& n: H
    mov     dx, offset New_Int_Routine
* r; v; w; ~6 ^5 G/ @( `    int     21h
6 i8 R" J. Y8 v, _6 i8 _, L% q. ~  |
* A' a* u8 Z+ J$ D, W__________________________________________________________________________
# h; e' Z3 e8 Y: r6 y* {7 z6 O- w& D* @) _3 P& p
Method 09
: d9 k9 e# R' o8 e. e( ^2 E( ~/ a/ n( m=========% Y5 Y6 z8 }/ n/ g8 u4 m  x1 T
1 d) u: t# C# A9 D) r; G
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only3 Y* }; G: c5 ~+ M8 j4 p, r
performed in ring0 (VxD or a ring3 app using the VxdCall).
" o7 ]% P. u! C( jThe Get_DDB service is used to determine whether or not a VxD is installed2 z. F6 j/ w, @- [2 y: M
for the specified device and returns a Device Description Block (in ecx) for) P! g! w9 g8 w
that device if it is installed.
: U" N" G! o5 _* }, Q* D: ]9 p9 W  y+ n/ B) @& J
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
, o. @# x% ?# B! O- o( Y; W   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)3 K6 X. _& K# `' g0 r3 s
   VMMCall Get_DDB
9 X4 G& B: c; H# Q   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
& ^8 x+ w# I1 i) G8 M' p/ D. b% ^5 J5 m5 Y; z, e5 M
Note as well that you can easily detect this method with SoftICE:
) C4 @4 o6 o3 G. B* l+ h   bpx Get_DDB if ax==0202 || ax==7a5fh
" x( e+ _8 N0 j
: D3 a: }; G5 x7 F__________________________________________________________________________6 K' d; U! `+ b% r
  Z8 P* [) a. Y1 E- r. j' C& s
Method 10
1 D9 i& S4 p4 ?9 F=========0 y+ z3 P5 v& u: v; r# _
  u' a; K  L6 r% j: i' E+ }$ \# d
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
: j+ V2 P% W9 H0 [/ J0 [' E, y  SoftICE while the option is enable!!
1 ~1 w1 |/ {5 h4 B# }) g9 P: Q& @& K6 O
This trick is very efficient:
( R+ J- j0 ?$ e" V9 H# Bby checking the Debug Registers, you can detect if SoftICE is loaded
# ?% ]9 e4 X. p0 f5 }' w(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if) w1 N, m, ?; @$ c/ c3 V
there are some memory breakpoints set (dr0 to dr3) simply by reading their+ U* s  {  M  S- u
value (in ring0 only). Values can be manipulated and or changed as well( h- \0 q) A' \. H1 b. t) \
(clearing BPMs for instance)
: n$ v9 P, L* H. X$ D" x7 {
- |5 C4 C8 W) Q__________________________________________________________________________+ ^: y3 d. G$ M; ]; W5 I

1 K# Q5 k8 g! p* e+ n. Z2 tMethod 11
4 W; B' O7 K+ M2 K) x=========8 N, ~6 r9 ^3 i+ Q* x! o

5 a7 Q9 j8 ^' L6 q0 OThis method is most known as 'MeltICE' because it has been freely distributed8 \- E3 k, F0 i, y8 W! z
via www.winfiles.com. However it was first used by NuMega people to allow
( y* a; O* Q; b* ASymbol Loader to check if SoftICE was active or not (the code is located) Z) E2 O; u( R7 D2 k* `
inside nmtrans.dll).
) Q0 |6 @3 u+ r6 ^9 }* U3 y7 K2 }6 ]2 w2 b
The way it works is very simple:
5 z3 b/ c/ {3 ^  q$ @: G5 MIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for! f1 j4 q: k0 E; q) h
WinNT) with the CreateFileA API.
9 `9 p' t$ A/ r* U- D6 J
' X) ^' w7 x4 E+ Y5 _Here is a sample (checking for 'SICE'):
' S7 k0 k7 {, S3 {/ a( S2 w% T
: D3 E& r/ b$ G% q8 \: ^BOOL IsSoftIce95Loaded()
/ [& f, F4 B( @( s+ V! _& P3 Z2 L{2 ?0 z: G$ V5 \3 Y9 q& b
   HANDLE hFile;  6 o1 K; x0 }7 O/ c0 K0 _
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
# c0 S) l2 I# b  ?: R/ l& o                      FILE_SHARE_READ | FILE_SHARE_WRITE,
. F9 f, C7 p  ]% Z0 d9 F                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
: s+ t; j2 k& @! e3 I# N+ }: d   if( hFile != INVALID_HANDLE_VALUE )
, d# {- ]+ A+ K   {
8 Q, ?! }6 L7 p% E. u# y2 ~- A% u      CloseHandle(hFile);$ S$ T- ?; {# r8 g1 z! e$ f& X/ m
      return TRUE;1 J- A8 E* Z1 G. l: {5 A" q5 B
   }' _, g+ Q' G6 U% K3 j; u7 b
   return FALSE;5 l9 ^0 A. h$ S- ~3 p- z- h
}& j6 T7 E( C  O  @# ]5 K8 }9 ~

2 b$ e/ e6 T/ D& X/ \! \Although this trick calls the CreateFileA function, don't even expect to be
1 d! k6 x& M! V. t6 r3 aable to intercept it by installing a IFS hook: it will not work, no way!
* e7 U2 z! I# ~3 D) V( ^In fact, after the call to CreateFileA it will get through VWIN32 0x001F
: i0 `* U% i, H/ iservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)5 ?8 n, P. A2 R0 H
and then browse the DDB list until it find the VxD and its DDB_Control_Proc: L5 L3 I" o- s2 L2 P, ~
field.
/ \" Q1 F0 G/ z9 KIn fact, its purpose is not to load/unload VxDs but only to send a
% T4 r  M* \9 z1 fW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
: ]: y9 }% j! h2 A& ^to the VxD Control_Dispatch proc (how the hell a shareware soft could try. S- ~* P& G9 J" k& A% {6 N
to load/unload a non-dynamically loadable driver such as SoftICE ;-).* J8 a1 }" D/ z
If the VxD is loaded, it will always clear eax and the Carry flag to allow' u0 G0 \+ o3 z$ m1 C+ E
its handle to be opened and then, will be detected.0 @" P" z; B. `$ `
You can check that simply by hooking Winice.exe control proc entry point
8 o3 C4 c+ c, U% \! Z5 kwhile running MeltICE.
5 j/ {" I, c4 j8 C) s. r( P  S8 E8 h$ _7 L- w7 V9 g
  c, I6 G) g6 _  y( `: O' T
  00401067:  push      00402025    ; \\.\SICE
' h7 \0 J# v7 }8 D  0040106C:  call      CreateFileA
. d6 \) r! H' q& i/ ~1 x- d- y  00401071:  cmp       eax,-001
  o' e+ d2 S! m* E, i  00401074:  je        00401091
% y) ]: A0 J- R8 B6 V# u  s1 E  Z% ~8 F3 ?0 F
" c# H1 M$ F/ A8 u
There could be hundreds of BPX you could use to detect this trick.8 \$ T) [. X" y; L& d' g; o
-The most classical one is:7 W+ {  A: v! E  c: R8 H
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
( b/ C( x' K$ m2 L  j& a    *(esp-&gt;4+4)=='NTIC'
2 I2 k* F5 O1 M) P; I$ H4 T
( y& d  k5 z3 `  O6 t' q' D-The most exotic ones (could be very slooooow :-(
) O( _# n, A4 D0 I; \+ h! j   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  $ W$ ?  c8 [# o8 A/ W( Q
     ;will break 3 times :-(8 w$ {4 k# q% q* h) J* U" {2 T
- o4 H  O) _, Z1 h( i
-or (a bit) faster:
7 F' T$ @4 m- ^   BPINT 30 if (*edi=='SICE' || *edi=='SIWV'): q3 _- \  z5 x8 \
( v8 O+ ]- e3 s! V4 b
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  & O' ]  i; F3 a( ?$ r
     ;will break 3 times :-(
' o: n, D/ H. r6 [& R1 U  Y- {& A& f- r
-Much faster:
" _0 U9 h9 L: U' I2 ]   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
5 z5 J9 d" ]/ x
- z* G$ }% a; c" D  VNote also that some programs (like AZPR3.00) use de old 16-bit _lopen# m* I; n  G  w, i9 Q! Y. I$ _
function to do the same job:- A) ~/ R( h2 R) m) A

7 O& O0 A( ~- a- C' o- [" X   push    00                        ; OF_READ7 |5 N$ J  y2 c7 [: |
   mov     eax,[00656634]            ; '\\.\SICE',0" }6 T* M% `$ o% s* E
   push    eax1 Q$ T3 D* l1 o9 E3 x
   call    KERNEL32!_lopen: s! N4 S; f& R& d
   inc     eax
7 F* [( W7 A0 B( \* y6 Z   jnz     00650589                  ; detected
+ J, k0 q7 Y+ P! `7 N   push    00                        ; OF_READ
1 q5 V' p; C" \" F- ~+ c( X   mov     eax,[00656638]            ; '\\.\SICE'& |  I3 i: z; C1 `* _2 q
   push    eax0 S( E& s3 J( t( D/ k
   call    KERNEL32!_lopen1 R' ]' G* d8 ^3 O: `8 G9 a( T
   inc     eax
* V2 H. k6 u5 k0 _   jz      006505ae                  ; not detected
/ e  k7 f3 n8 m5 G* F: x  Q' ]% H% M0 d( b4 p6 ^
6 J. ~$ e# e) K8 [& h
__________________________________________________________________________
4 J9 S* Y( r( S4 ~( |! D; g1 v5 K" Q1 U+ Q8 n
Method 12$ p, P" q6 v0 O* M8 f5 L3 e* ]
=========
6 q" B. d# h+ L1 B+ [
# R7 a% Q5 S; ~8 ?' YThis trick is similar to int41h/4fh Debugger installation check (code 054 t# \9 G, m8 h" {( p8 I! p* L! `
&amp; 06) but very limited because it's only available for Win95/98 (not NT)
# _1 j1 B5 B+ ?% Tas it uses the VxDCall backdoor. This detection was found in Bleem Demo.
  w1 z! b& \; W. K: j0 R6 \5 `" D' V% N' d! l& V2 O/ \& C
   push  0000004fh         ; function 4fh
( c6 s! a! s: V3 b   push  002a002ah         ; high word specifies which VxD (VWIN32)4 N! l& J6 V, H) i
                           ; low word specifies which service6 O- }/ ]& N# q" S( c
                             (VWIN32_Int41Dispatch)
/ e# o2 r( o: R   call  Kernel32!ORD_001  ; VxdCall
/ K( _/ i* U1 F6 I* n. D0 L/ L  K   cmp   ax, 0f386h        ; magic number returned by system debuggers
! _" m. z' \' _$ y7 E# ]; q   jz    SoftICE_detected
8 s+ M3 K/ }; X1 E' X
2 R2 p; U7 @4 G1 M6 D/ sHere again, several ways to detect it:
+ _6 J! q; h9 v
# H5 [/ U- y4 Y2 e, x5 r6 p    BPINT 41 if ax==4f4 \( _8 A# k' t" L

+ K( c4 e$ U0 }  ~4 @9 {    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
' G  X6 w* r& v
" ]8 A- _9 O, s* o$ T) c. \0 y3 M    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
/ ~! d. Q( h, C3 ~2 o) g  t9 B9 ^: q( A8 z) A6 D
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!  ^3 \( N3 E- a+ L  _

" U6 q  g: w/ c/ b__________________________________________________________________________9 m7 i) N  _- A! ^
4 H1 @  {. X' S
Method 13* v* u6 \# f. T$ L1 t1 ~
=========
3 W& F- h% l( z) U, e4 J7 Q
" E) L8 A) @) J9 i. x5 FNot a real method of detection, but a good way to know if SoftICE is
4 S+ a3 r3 U8 N. rinstalled on a computer and to locate its installation directory.
% O0 b8 D2 ~5 @" rIt is used by few softs which access the following registry keys (usually #2) :
# }/ T7 ~/ q# z: m' N
; }" ~$ j; I7 p( N- z9 P5 q-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
; t: U' S; Q0 N) p\Uninstall\SoftICE
) T' v3 C! u( @-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE0 e- l3 v( q0 G8 L6 `' i' M1 {
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion4 x" f0 q5 m4 m9 x/ V) u
\App Paths\Loader32.Exe
" Y9 B& U2 V9 K2 M6 h9 [
2 }: @( {* _: W, e4 |
5 B9 b! X4 S1 VNote that some nasty apps could then erase all files from SoftICE directory0 p2 o6 J3 A6 S6 b0 \- r( Z0 `. \
(I faced that once :-(
, S, c+ K8 }8 c, Z  _% G
  Y2 _+ p  B7 IUseful breakpoint to detect it:
# P( U' a5 c$ ?) v
8 G, L8 h% `$ @+ m     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
% r- c1 v2 A. N0 z  p# ?3 L. T* }1 H- O
__________________________________________________________________________
9 a" s8 f" M# E
: T+ P3 ?0 ?+ N- U+ K" t1 F7 z( y' {4 f
Method 14 7 Q7 S$ \4 V- t( |4 V$ z* @
=========: e$ x. l4 T  T; `) h

0 `+ c) M7 G2 Z  ]3 @A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
0 m: Q$ }9 ]1 [& ?* Wis to determines whether a debugger is running on your system (ring0 only).
; J- s2 u' v: \) j
: S7 a$ Y* x2 U  l, t   VMMCall Test_Debug_Installed6 O; X! r: |- V: `3 t* m6 h
   je      not_installed$ j* Y" h# x* f: s# h! Q
, i; J- R0 J; T0 D# L5 s, |
This service just checks a flag.+ T& K0 g3 O1 C0 a9 t3 K
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部