About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>0 N, j5 G# v6 i6 X# M
<TBODY>3 c' k* N' q. g) K, K* l9 C! j
<TR>
+ m6 I& b$ z6 l8 `, X<TD><PRE>Method 01 : @" c  A* X' S, Y% h* X+ C+ O
=========1 D/ x; p4 _% R8 e: O; }
3 b$ L" k- ~: o* C
This method of detection of SoftICE (as well as the following one) is
5 R2 I- e: Q# c% i6 rused by the majority of packers/encryptors found on Internet.
: y2 ^, R" J/ IIt seeks the signature of BoundsChecker in SoftICE
) q' B5 S0 N$ I% H& ?- E; N$ R& s( S' E: y3 a% b# f7 @
    mov     ebp, 04243484Bh        ; 'BCHK'
& K. X3 @# V) v0 N( B    mov     ax, 04h
" ]8 N' P: _0 C# o9 {* F" ]    int     3      
3 V# p) i9 i1 ]) ]' B9 q) `    cmp     al,4" G% r5 b) K6 _' U
    jnz     SoftICE_Detected
8 R* q, \3 i) e! b9 Y, n1 ?4 X
& G: A+ u: F7 `! [___________________________________________________________________________- e6 X, A0 i! L$ j5 U- l. |; N( r
* q( u( k: q7 H1 z
Method 02) U% B$ s5 {% z) q6 o+ l7 L
=========
3 S! R! `) _! g4 X4 l, H# X& I$ i$ a5 J  `2 _# Z: n+ q
Still a method very much used (perhaps the most frequent one).  It is used
7 s; P7 I9 Z4 \! Ato get SoftICE 'Back Door commands' which gives infos on Breakpoints,
3 n/ i( G' L" b7 mor execute SoftICE commands...7 [, m) h+ Q; }/ O/ X3 k0 W
It is also used to crash SoftICE and to force it to execute any commands) K: g8 j! S& A" @) ]! X% a+ w
(HBOOT...) :-((  3 b# p5 g0 a3 k/ A, M

; K; X  G- E# THere is a quick description:# v3 ]! N! J) _7 F' R
-AX = 0910h   (Display string in SIce windows)
% D4 @+ u( l- J& R  c-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx): ^: o4 g  P2 g2 i$ y
-AX = 0912h   (Get breakpoint infos)
0 Y' ?# q6 ~: i, j  o-AX = 0913h   (Set Sice breakpoints)7 L1 f( n3 M' v# U1 x! Q0 q
-AX = 0914h   (Remove SIce breakoints)3 v" P0 T' s1 {/ w8 y0 Q
# L( _% t9 P5 j# H- r% d
Each time you'll meet this trick, you'll see:
4 u! G' G1 D$ W$ P8 n9 k& ]4 B  j-SI = 4647h* x, M% q2 R5 M  H1 I" b1 E6 K
-DI = 4A4Dh% w2 D/ L! @, k* h
Which are the 'magic values' used by SoftIce.
- J; r3 D) Z' E: g( uFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.2 V1 N" c; q7 g! v& J" \1 I: b; O
  n4 M0 b, R- @% a( `& z# Q
Here is one example from the file "Haspinst.exe" which is the dongle HASP9 a- A1 E3 h# z' f( @0 R
Envelope utility use to protect DOS applications:; I% H. D) z1 ~3 L( a- \' J

8 @2 g$ D0 }9 r! w: ]5 o
, w2 X2 M' Z# \6 t/ ~* ?4C19:0095   MOV    AX,0911  ; execute command.) ?5 Q. S6 C- V2 L  G' s
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
; k3 o2 y- \- ?5 K4C19:009A   MOV    SI,4647  ; 1st magic value.
9 s8 n6 S5 S8 W8 ]2 d  j/ a4C19:009D   MOV    DI,4A4D  ; 2nd magic value.! g2 o' a, D( b, v, v2 j1 V
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)# ?5 ]2 u8 y1 a% `& ^
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute  I! C! _& }. Z( [" p0 J
4C19:00A4   INC    CX9 ]6 w$ i8 ?/ u
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute* f1 K1 A' |* J" V! [
4C19:00A8   JB     0095     ; 6 different commands.
4 z" Z  `0 W$ Z* ^. V$ h4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
" W+ _/ P# T" N+ L, b/ `4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)" L+ a* y4 r  m9 _

! X- [9 O5 _2 vThe program will execute 6 different SIce commands located at ds:dx, which7 I, n0 {+ ?) h; u' _
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.' B: |5 q5 y0 k/ b6 c
" p5 z7 t# W0 \( v+ x+ [- h7 f- t
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
0 g; B8 E) ^, c3 M) Y___________________________________________________________________________& w1 ?/ v" ?4 l

. O/ W6 A* v3 v: K; ]* M  G* z: S# h
Method 03
0 g& n  R, Z# }* H+ e! p+ a=========
: ]. v: v! m  |% F5 w* a; n
- a* N7 Q! U7 j. |" I3 X( W: s& PLess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
( B; }5 d1 C2 a; ^! m: q+ ^(API Get entry point)
% t8 c- s8 T, ~0 g$ i3 Y        
# Z- ^' p) @* n
) T& [: g* h6 P, [, G2 M) U7 e    xor     di,di' H7 |; a* F9 |2 k" d# {6 D
    mov     es,di
; S3 F$ o/ j( D1 j- _& Z( A    mov     ax, 1684h       : _, q1 J  V5 [  n$ c) S, N
    mov     bx, 0202h       ; VxD ID of winice% b5 y; h1 D  `2 T
    int     2Fh6 r+ z7 d6 f2 V, i  v/ U
    mov     ax, es          ; ES:DI -&gt; VxD API entry point/ S1 d; u' b) ^+ S
    add     ax, di- [+ u- @/ L2 o6 d7 M) a
    test    ax,ax4 h* ^9 r- ~7 Z. `6 b! g+ Z) B. Y
    jnz     SoftICE_Detected
1 W% b" p. F9 H5 F/ Z, \  p/ @0 i4 V+ s
___________________________________________________________________________
" ]! c$ d" `9 ~9 L- g- X6 v3 d; ?: h4 M8 [/ _. S$ X
Method 04) ?1 A1 |3 f7 H. S5 K
=========
, i) y0 X  D! V; j6 N5 g. E( O- s; q  M
Method identical to the preceding one except that it seeks the ID of SoftICE1 K1 L  h/ I- E$ T3 R' p
GFX VxD.; t5 a1 X8 n7 e
, y% v; v+ g) i0 O. {6 Q
    xor     di,di
8 u  G# I1 W( H! A4 r! g    mov     es,di3 s/ h0 i( E" R2 H8 k/ \
    mov     ax, 1684h       3 u  {5 k  J- B
    mov     bx, 7a5Fh       ; VxD ID of SIWVID
4 K9 z. \; l+ I8 D- o# g: [/ r    int     2fh& z1 |/ K! m( `# w/ I; O6 a  q
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
8 ^  W1 q& ?9 ^! H    add     ax, di
7 v9 ~  {! H: X, e- q# i* y    test    ax,ax3 u* b+ N' z) N- Q; Y" B
    jnz     SoftICE_Detected
3 i4 ~3 y. v5 k8 U7 _
3 E$ J5 ?/ z( B2 ~2 ^__________________________________________________________________________
, _, H3 d) n! N# K! b4 u0 E7 C! E5 C% q$ R

/ [) T; l( H4 x# |Method 050 O; U9 g$ p* r( f8 }1 q' }# [  k
=========- I2 Q/ I2 r+ ^

0 u4 E% E8 z5 ]- v" RMethod seeking the 'magic number' 0F386h returned (in ax) by all system
* U* s5 V9 v" {9 D- k: s# m1 fdebugger. It calls the int 41h, function 4Fh.- A0 a- _3 Q' q6 @
There are several alternatives.  
) ^6 M  ]# ^5 X& N
3 R6 G1 Y+ u& N9 Q3 x$ qThe following one is the simplest:; |9 ]' Z! |8 a3 Q5 [
& F7 ]9 v3 l# i0 B3 W1 ?6 Y
    mov     ax,4fh, }4 H- p, O7 f; T
    int     41h6 H6 [' m) x4 d  F6 U; ]( u3 H- ^
    cmp     ax, 0F3868 [% @7 a: M- f7 r: g. h
    jz      SoftICE_detected
* x7 v1 T* d% _
. M+ ?7 K7 X: m: x3 n6 o2 J" H1 S5 c' x1 k5 D& B
Next method as well as the following one are 2 examples from Stone's * E# I. v  @2 U  M4 b' R  B
"stn-wid.zip" (www.cracking.net):0 i* s3 R3 |) X4 @- Z1 T$ y
/ e* ^$ T; |+ [- y6 a/ u6 @
    mov     bx, cs/ ^/ G! [1 E& t( ~
    lea     dx, int41handler2
2 O5 O5 Y; I( n  m- l" l3 x! W    xchg    dx, es:[41h*4]7 x* }- G& N& \+ j7 z! q, s
    xchg    bx, es:[41h*4+2]
6 a. J! W4 \6 S# }+ b    mov     ax,4fh( k# [) d5 @6 M4 T0 Q
    int     41h
3 f9 b; L' d/ f) S# X    xchg    dx, es:[41h*4]+ E% ], @, [. }/ K8 w
    xchg    bx, es:[41h*4+2]
0 R0 R- V3 j+ N# T* D    cmp     ax, 0f386h% C, `1 V% D5 V* I  \
    jz      SoftICE_detected
7 l/ ?/ u$ ~3 q/ ?
+ E6 t- n$ s' S; |% ?. |int41handler2 PROC/ d7 W: {1 {% @
    iret: Z# H  \/ N+ y% e! R, N' E% O
int41handler2 ENDP
: I  B9 X3 H7 V1 @) S) h( z
: ~5 P3 ~# N# o3 o- e! b- t
) t/ C) \8 f. _; y* m+ K_________________________________________________________________________$ b+ J, o- i* }; n- r: h) w

; F& `  Z. O: B3 v
2 ^4 E& W$ x" f- `6 GMethod 06- j, `3 g1 b4 a  ^
=========
2 X1 A  \( |" C- t' x9 i" m) {% V/ g8 t6 f0 S

9 c) Q0 D& X3 d3 {7 i. Z  I2nd method similar to the preceding one but more difficult to detect:2 m- g0 d, X2 n6 N, f4 E- h

2 S$ ?: c/ a) ^, j# m* z* \0 A
4 D! l9 Y1 a% s/ U6 T3 dint41handler PROC
# T1 [9 O1 k9 Z1 K    mov     cl,al
9 c* X$ G2 J2 |/ X0 _    iret
+ y0 |" C& d$ v3 R2 W/ zint41handler ENDP# p' W8 j2 ~( V* g9 L5 t( i% L# u

" j# J& ^: f1 h% j3 b
0 `; H8 O0 b; G9 A# R/ _    xor     ax,ax5 V% j, c3 U; W$ U, a
    mov     es,ax" ]) |( J- G' [' R% k# d* D1 J* }
    mov     bx, cs1 r% L' J+ g, y& V% S, Y5 a* W: R
    lea     dx, int41handler" }. [) T$ k1 e' V& [# z9 Q
    xchg    dx, es:[41h*4]
+ L2 i; u' ?% u$ _  c    xchg    bx, es:[41h*4+2]" {8 Y, A4 u5 u: _4 g! w0 Q( t
    in      al, 40h
+ M* C6 `3 i; v    xor     cx,cx8 L; O* z9 s4 k* C7 [8 ]
    int     41h! j& [+ j, G9 q
    xchg    dx, es:[41h*4]& b" Y0 `3 I. g
    xchg    bx, es:[41h*4+2]/ ]3 E: a! u4 J# O' ]
    cmp     cl,al0 X8 W5 [& L& Z! [, e! O
    jnz     SoftICE_detected
7 B5 f* P' o  j$ S8 }: N3 U1 o: D  {% @% v
_________________________________________________________________________
& }) _$ w$ Z: `/ V1 X
* Y# c1 C; L( N) qMethod 07; n0 x' @' H! p2 k  |- z
=========* l; ]; Y4 }9 F/ i. \; A1 ^4 |

7 _& j* ~! m* p: a7 q4 jMethod of detection of the WinICE handler in the int68h (V86)
( v2 J' P* h' D( N" c* u! d
+ z" X% S' `. Y, z' o: D' l! f    mov     ah,43h, A( n2 Z: Q, r- f& a- l5 N) I2 J' j% n* ]
    int     68h# f1 K& L# g( x" F' o) R( V
    cmp     ax,0F386h
% l% j4 u, Y. J; D& }8 Z3 \1 g    jz      SoftICE_Detected
* x' S" v% n( h- E3 w# c+ a: v- _! J9 O

# |) x5 K& R! \, y: _' G7 K=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
% ?7 X7 B( f9 P0 u+ T3 X( b$ s   app like this:0 d0 o2 |' J: D$ n# k
0 Z: n1 J$ N  n! |" b
   BPX exec_int if ax==68
9 n4 m' b5 T. D5 e, n* p8 B8 }   (function called is located at byte ptr [ebp+1Dh] and client eip is6 X' c! ~, }  I# ?/ }
   located at [ebp+48h] for 32Bit apps)4 I% T% [7 q! N  p9 z! T
__________________________________________________________________________2 ~/ Y- s2 p& Y9 Z' j
$ {/ h6 |# K, ?& ?/ R
& Q; K7 b# V: p/ Q2 d
Method 08% `+ Z' E+ q- K# t! g* N
=========
& a! j; y2 p% S0 p5 d1 w) t4 \! N3 d& M8 t% y! A
It is not a method of detection of SoftICE but a possibility to crash the% V( x1 q# r0 k: f. m& t
system by intercepting int 01h and int 03h and redirecting them to another& e5 o8 w) O. _- e: m' m) o$ k
routine.
  v( }! d. j" J0 @* OIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points  k4 M0 o! g& S
to the new routine to execute (hangs computer...)% b5 Z; [9 U% |) B. l
( V5 s7 r2 N1 d" D
    mov     ah, 25h1 V- |/ x) U; z3 d; f0 Z% C3 S
    mov     al, Int_Number (01h or 03h)
8 V8 S: b# ~$ p# R5 X5 R    mov     dx, offset New_Int_Routine
5 }7 N1 N: I2 N* F, z3 p    int     21h8 \: E, B0 @* \

" J# R' T# s* V7 \2 e% I* d% w7 `__________________________________________________________________________
2 i- C) B* k4 B7 K- A+ o  K$ W3 ~& S* H- X( b: g, c7 B
Method 09
6 r# k  a; V# G$ [=========/ I8 @$ v* h& a3 c- y; m, |" p

2 Q3 D) M1 }; z8 hThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
# P4 B7 e7 w" a" [# mperformed in ring0 (VxD or a ring3 app using the VxdCall).: F! L3 f! N9 U( }4 @# }2 o
The Get_DDB service is used to determine whether or not a VxD is installed
) D; o6 h( n7 g  h7 X4 n$ cfor the specified device and returns a Device Description Block (in ecx) for% y& q% J; I9 l# H% m
that device if it is installed.
& a, L+ n( d. H* i2 ]4 S  X4 l( |! m) i2 A$ M
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
3 V" }0 s' @- j/ ~* o) ^- }2 q   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
! i" r! h3 x% \# a   VMMCall Get_DDB
& D' c% g  O9 [& K# g   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
. c1 ~' L3 E- f3 h. N
3 Z! [# A& L$ T( u! g. }* vNote as well that you can easily detect this method with SoftICE:
* S, z0 }$ b8 [/ S, u3 f1 \   bpx Get_DDB if ax==0202 || ax==7a5fh
; w' @5 M# k5 X/ B/ i3 k1 j
; ^, I) \7 w$ D, g4 u4 B__________________________________________________________________________
2 h- @" s. R8 Y/ p
* E* g5 A6 i# F7 [0 ]' BMethod 10
  p1 J% u( X  h; `=========5 B/ T  |5 N. A9 `5 g1 C2 G7 Z

  M5 t* \/ F7 G+ ?/ q=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with6 r5 n5 P( e' ?8 T0 |! ^" M
  SoftICE while the option is enable!!1 H- N1 M  B4 E! a- R. ~1 o
5 G5 D9 c# J, P' r2 n  \+ J0 n
This trick is very efficient:" {: a* \4 l  S6 {8 C
by checking the Debug Registers, you can detect if SoftICE is loaded
* }( ]$ F$ K/ I) a9 p& B4 e5 e(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if8 A% Z5 A! z3 F6 l
there are some memory breakpoints set (dr0 to dr3) simply by reading their8 C* k% @5 O. j* A$ p
value (in ring0 only). Values can be manipulated and or changed as well
9 `, {. V0 n( q  M5 H(clearing BPMs for instance)
& a% [% c& R) t! M( S
7 Z  F- ~, D' x6 B' O1 r__________________________________________________________________________
  `% {# w1 n9 M; ?# V
5 f- d( ?. b4 zMethod 116 a  l% C8 [# Z8 t5 s. N; s' B
=========+ b! O9 H# a# v

" p; U9 A5 {3 EThis method is most known as 'MeltICE' because it has been freely distributed
( q* }1 B# N: H% h0 Q) Fvia www.winfiles.com. However it was first used by NuMega people to allow
- h3 _6 J% e# j) a$ R  jSymbol Loader to check if SoftICE was active or not (the code is located7 Q1 e- P- R+ L% Q1 t; p. c3 [
inside nmtrans.dll).- }4 ~8 F/ x! Q, B) @6 {

% u4 z4 \  U: l8 D' X' o  A6 EThe way it works is very simple:
3 A$ O) o6 z% S/ Z) y$ r: G( jIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
* O$ ~- M3 K9 V& t3 sWinNT) with the CreateFileA API.! J1 D" J- O: J5 D$ g
8 @. Y) `* z4 a
Here is a sample (checking for 'SICE'):
) l6 \/ T0 T6 {9 b; A: c
% T7 z, g+ ?% _BOOL IsSoftIce95Loaded()
, p, k8 g; o5 M( s0 R" P{" v9 @7 _8 o9 [/ V
   HANDLE hFile;  
+ t6 G5 M& `  J8 O, a   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
$ q; U; U( J# I                      FILE_SHARE_READ | FILE_SHARE_WRITE,8 U' z; n! a; T2 Z2 p# x1 X0 g  V
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
$ E, e6 s$ O/ P4 f   if( hFile != INVALID_HANDLE_VALUE )6 F3 b3 Q2 J8 f; }; e
   {
- U+ K8 J  F& u8 X  h8 `; }      CloseHandle(hFile);; [8 |+ C* Q( D# D4 }0 w% U3 l
      return TRUE;) J, R; }8 k7 Z1 Q6 H
   }1 t8 U4 ~6 z7 j: F
   return FALSE;& d2 N4 D* v& b# w8 R* K+ N! \
}; K' M2 {" ?) M0 B
( H4 R& Y0 Z6 ^& x
Although this trick calls the CreateFileA function, don't even expect to be
  K: C) O5 w# F8 J9 C+ Fable to intercept it by installing a IFS hook: it will not work, no way!
2 _- x; q0 e, DIn fact, after the call to CreateFileA it will get through VWIN32 0x001F
5 m3 y! Z9 A" \' [  q/ [+ qservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)! b6 [5 @& X" l2 i/ K
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
; g5 O" Q8 \. x% Z$ w+ Y/ @. }field.% c% ?' [6 }! y- A' Y
In fact, its purpose is not to load/unload VxDs but only to send a
" H% _* p+ v! O; Q2 U% y1 RW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
6 H- F% ~, t6 x. v  n/ `to the VxD Control_Dispatch proc (how the hell a shareware soft could try) \2 S9 C  W6 c8 G( R3 m5 n
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
4 ?& k( B8 I  ^+ P4 {, [/ VIf the VxD is loaded, it will always clear eax and the Carry flag to allow
4 ^$ H$ h3 ?' g# G- j$ nits handle to be opened and then, will be detected.
+ V& e- W5 d4 |3 R7 tYou can check that simply by hooking Winice.exe control proc entry point
0 ~5 K7 p8 D" x( d9 g, H9 ?while running MeltICE.
' D  k4 @5 m. @8 E
( E& e( c0 T; r/ Q, m8 a1 P3 j8 `7 M' a
  00401067:  push      00402025    ; \\.\SICE( {/ [1 K. O% z+ E" I1 H
  0040106C:  call      CreateFileA1 D4 n2 X* a% Y# s6 C- {$ t
  00401071:  cmp       eax,-001
: J" n8 d6 {) d9 ^9 g% @  00401074:  je        00401091
$ o/ `9 ]) T; T1 u
. Y* A' b2 Q1 h, G9 M
, I! Z  q, ]7 LThere could be hundreds of BPX you could use to detect this trick., N$ r& U, c7 t$ o- a0 e
-The most classical one is:
8 Z- b5 L) k% ]1 w  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||, {0 O) X5 W+ l) I' o- ^; a
    *(esp-&gt;4+4)=='NTIC'. V4 f. |& |: z
, [  o9 i) Y$ [6 {0 ?
-The most exotic ones (could be very slooooow :-(
: c  a  P* ~# S  x6 p- I   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
$ ~) {, o5 G( v2 e     ;will break 3 times :-(
' e! Q* Z5 E% K. R* l/ B; U3 a0 T$ ^" N( M; `$ V+ c
-or (a bit) faster: , I4 f& X) `) V
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')- [* A# U, T' L7 j( V! @

2 D2 D, M  U/ R5 `- j+ k+ @   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  . Z7 P* ^) D) c; e) V
     ;will break 3 times :-(' n7 P0 L' ]* u) b' K

1 f  I- v- T# v& i-Much faster:' Y; y1 k1 _! G
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
" A* g1 R2 m0 C' j
1 I0 _7 I3 g) `Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
, E% Q  t! j0 Xfunction to do the same job:1 P) K' |  ?5 E$ V. F& p4 q( `! r, \
. `! X6 X  N! o+ |/ y  P
   push    00                        ; OF_READ1 ^  |) J9 N- @; F; e( d+ X) y
   mov     eax,[00656634]            ; '\\.\SICE',0: V8 o7 X4 W/ y, C
   push    eax
' h% n' E- v% |$ D% T   call    KERNEL32!_lopen9 U5 @% F7 T8 ?  n  ^8 R
   inc     eax. K" i' X7 g8 V2 ?# K) ~
   jnz     00650589                  ; detected
8 Y! h& G. f7 j   push    00                        ; OF_READ& P2 t8 ]. D4 H) b1 B
   mov     eax,[00656638]            ; '\\.\SICE'5 [* i1 H6 Q+ q: X+ Z3 N' w. ~5 n- F
   push    eax5 ]4 B$ u1 ]4 V+ y5 M. @/ y
   call    KERNEL32!_lopen
9 O6 ]4 t2 y1 A, K7 d* {   inc     eax$ g3 `* D- T$ s  W/ ~
   jz      006505ae                  ; not detected9 S5 W, s" D$ V! A+ G* R1 m! ?

! w7 L+ u, X' n  z/ r( J" \5 q! ?# R& k1 Y4 P4 s6 I4 }3 i& h5 W
__________________________________________________________________________
( |% Y$ X* b4 X9 _. K0 C6 i( W" A4 V
Method 12
! ?& z" r9 I" V=========- G) b  g' I/ g: I5 ^5 w! P7 `0 m
+ h/ w: [$ I: I( X7 S+ X( L
This trick is similar to int41h/4fh Debugger installation check (code 05
, B" b6 m% s  A: ]/ `- {6 X&amp; 06) but very limited because it's only available for Win95/98 (not NT)
  C! J- X1 g7 S- V& W7 \) Cas it uses the VxDCall backdoor. This detection was found in Bleem Demo.
) B& G9 n' v. V- H% ]9 P! e. o, |* K2 x! D$ w! E* [
   push  0000004fh         ; function 4fh! {3 f3 l; o3 O! b3 P* ^8 i
   push  002a002ah         ; high word specifies which VxD (VWIN32)
" s9 F4 U  F) `9 v                           ; low word specifies which service
2 C9 g2 L% m1 U4 {5 @                             (VWIN32_Int41Dispatch)6 [, v+ @: R/ u- M, P9 m
   call  Kernel32!ORD_001  ; VxdCall
6 r$ E. z( m1 i! h' m! ?   cmp   ax, 0f386h        ; magic number returned by system debuggers
: D! {8 w3 Q. p( d! h   jz    SoftICE_detected
6 g2 y" w' N' d
5 ], J* c+ W2 x% u% Q- _: C+ @$ tHere again, several ways to detect it:
0 J1 Z8 E! d! c4 j1 ~( S8 y: Z+ W6 V
    BPINT 41 if ax==4f* e$ E( W; f9 s: n2 A- c' g" U

! n0 k6 Z8 t0 X- z/ T" W    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
9 y2 l* G" y  L% `4 O- }$ y/ n7 f3 n, M! n  w
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
, {2 u6 I  C" Q( d. P- j
1 Z* }: Y' S0 o/ }/ F0 M' C; v    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!. }/ M& V9 J8 P1 V4 u% v

, E0 J/ o8 |% o, z__________________________________________________________________________
: p" [0 ]4 @' p5 g' \. O  Z& G4 j( A! J
Method 137 Q4 e, w# k3 _3 T$ L
=========
2 a4 e, I9 b1 ]% p* c4 C4 [2 [7 E. R) b- p  C: q9 x( W7 _
Not a real method of detection, but a good way to know if SoftICE is
- a0 p2 Y- Y9 a5 b! |+ I: ainstalled on a computer and to locate its installation directory.4 [4 M5 q8 x1 G4 B
It is used by few softs which access the following registry keys (usually #2) :/ v8 W; O+ \. V( X1 U4 I/ T
! {9 _% o7 a0 d+ q$ j1 x0 `
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion5 X: _9 C$ P1 l$ W) n; D
\Uninstall\SoftICE
0 C+ C) q! q/ G( W1 i5 F-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE# N* ^3 P& }# b- r. l- \
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion% z7 y( g" I9 X. z" m& s0 _7 |% n
\App Paths\Loader32.Exe
1 @4 {) z# N  `1 _: [2 M) y/ ^% x& Y2 {

: J6 A, O. S. X7 e) P; {Note that some nasty apps could then erase all files from SoftICE directory
( X% W/ i0 }' _1 t8 I0 o& N(I faced that once :-(* A0 f/ `3 U/ @8 ~

4 o# i2 p8 n3 u) w, u! q, k) p8 I, w* lUseful breakpoint to detect it:
9 U5 P7 F! B5 y8 B* m3 S6 O$ o; U& @8 L+ `4 U: ]" t& u7 n
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'0 \3 b6 j  W* h9 o

+ h' D. C; Q+ {__________________________________________________________________________
% X' @: `: N1 x3 x
: d, m2 w3 d! j4 R; T2 e4 w
2 I! }( r4 O; s3 k/ ~5 RMethod 14
8 `# t& x) Z! _+ o5 g) u=========
1 F+ w8 e" w6 H3 Q( J5 \+ L# ]5 p; w
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
% h8 j. R7 {9 W1 @( N& zis to determines whether a debugger is running on your system (ring0 only).: f4 B% q4 M5 |3 n

2 m6 q  C0 f& w$ Q   VMMCall Test_Debug_Installed
5 r5 C8 b0 q6 R& n. T/ ^6 \   je      not_installed/ Q! P. J7 H6 v. K! C

& t. N8 j* U0 y- |, P. d' NThis service just checks a flag.
5 k8 u8 ]5 Q2 ~. J8 _</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部