About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
! R3 W# f% p7 I2 o8 W& G$ ^<TBODY>9 x2 o; R% w% X& ?
<TR>6 W2 G2 k* A! D! r  w5 U  H
<TD><PRE>Method 01
) _) i- Y. o7 E8 c# ?/ D& K=========# D4 q& Z. C' I  N2 |4 X0 @
& {/ ?9 J/ R, d
This method of detection of SoftICE (as well as the following one) is! D# R7 d+ M; P& ^3 H3 @
used by the majority of packers/encryptors found on Internet.) h/ H, u" y# F' y# K4 e3 _  p
It seeks the signature of BoundsChecker in SoftICE1 @) {5 y, D7 q2 I& ~; I
. l/ D$ c) Q2 |6 x
    mov     ebp, 04243484Bh        ; 'BCHK'
) O* w! H# G2 }1 j: `& _    mov     ax, 04h
7 E: g9 c( ~* W5 a    int     3       4 N6 i' i1 U# p0 F0 D( O! D" |
    cmp     al,4: N+ D. U5 Y1 X* e2 j0 }8 k! b5 a
    jnz     SoftICE_Detected  a  z# R: p5 Y* I1 ^4 q, I
- [( G4 J9 B. L' G3 d! I$ s' W
___________________________________________________________________________. p% k+ n5 M9 H" h
- z; B7 c6 |0 h# ?; e
Method 02
3 H" `9 q) g3 g, W& d2 S/ E) W=========5 H& q  c' l" x6 u) |/ [0 I. p- P
* u5 T0 s6 W* |
Still a method very much used (perhaps the most frequent one).  It is used
6 A- m+ w& |, f, z* Kto get SoftICE 'Back Door commands' which gives infos on Breakpoints,
, r& Y, U$ B, |! R" sor execute SoftICE commands...2 m5 ]6 n, _/ x2 @+ x% O8 a. ?
It is also used to crash SoftICE and to force it to execute any commands
* b8 S6 E1 T: L( D- M6 U+ E(HBOOT...) :-((  ( R1 c  ], M, W1 J' K: e
4 A7 |7 G% S- B3 w' z1 a4 t2 I
Here is a quick description:
# ^0 z. D; W  j' X; U7 j; Q-AX = 0910h   (Display string in SIce windows)
/ K9 n7 R% H( l0 s9 h0 R- `-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)1 T; \/ G8 J% o! p
-AX = 0912h   (Get breakpoint infos)% R4 ?+ d/ I+ f/ B) W' s% U3 A
-AX = 0913h   (Set Sice breakpoints). N: n# S: Z+ O; S$ ^
-AX = 0914h   (Remove SIce breakoints)
4 g' s# I2 @+ f1 e3 z
/ P0 f! p7 G1 ]Each time you'll meet this trick, you'll see:- \6 K+ u) Z7 ]1 q( X
-SI = 4647h8 i; e. F' d' x, V) _% M
-DI = 4A4Dh( R1 S" ^6 W2 i; O" ^0 r4 V. j
Which are the 'magic values' used by SoftIce.' c+ a+ ?( B5 i" q
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
! ?7 P' U4 i6 S- E" [7 m
* f' H- n+ m  ~$ SHere is one example from the file "Haspinst.exe" which is the dongle HASP
7 Y5 `" N$ z) e8 N) D2 SEnvelope utility use to protect DOS applications:4 J# V% `' f  o, f. C% h
1 |# I- |: K% a- g) M3 J
8 y# \. ~* u& C, [% Y6 J' y8 Q7 @
4C19:0095   MOV    AX,0911  ; execute command.
# u7 n* T9 D1 a% H/ V1 H% j5 S$ h  N  W4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
: r8 R6 T2 B0 Z' H0 Q4C19:009A   MOV    SI,4647  ; 1st magic value.
( [+ f1 ]! b$ f  I4C19:009D   MOV    DI,4A4D  ; 2nd magic value.9 V/ l" [1 Q# N" n, m2 \8 G
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
9 A- {( e6 o1 U# G# B% I! d4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
3 ^. @) {& e& b+ H3 x( w$ z4C19:00A4   INC    CX/ P; Y/ ]& S' P1 h" f
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
" B2 {) P3 l% e. X$ f4C19:00A8   JB     0095     ; 6 different commands.; Z& b6 G9 `0 @1 u8 O. [0 |
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
+ ]7 t# n$ \+ k# b4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
9 d1 I5 a) s* s6 G
" q! \0 b1 y6 t3 V) n. u! oThe program will execute 6 different SIce commands located at ds:dx, which0 B0 `% Q5 G$ j) l2 s  U  X
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
, j2 v2 Y( ]4 D. H# a4 }' L8 G% ~; Q8 y5 u
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
0 e) K" |2 I5 c( G8 s7 y/ h& A___________________________________________________________________________7 r9 U7 q0 g% r; w% @; Q

, e: V. p; N1 s6 C
7 K. Q; I$ d& ~) O% N  N6 wMethod 03
: m4 Y# o8 O; g$ c9 Y7 s=========( n4 ?8 L3 v- J5 J  }$ ?

6 ?& Q; \$ C( eLess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
6 M% j2 T* k; R1 `5 N(API Get entry point)! V8 _$ ^/ F4 t( Y7 a+ b/ v& @
        8 P$ b( k. A& c, b' d8 P' V

; k7 n+ O1 s: R% D( E- `  n    xor     di,di' F6 ?- |# G0 e2 c# R3 j- E. {6 F
    mov     es,di2 E8 |' K- g* a, u( c7 B" n
    mov     ax, 1684h       . z! {/ M! [3 C5 u% K: u
    mov     bx, 0202h       ; VxD ID of winice
4 K, ?; L: g9 S6 n2 a: }' x: p# ]    int     2Fh
: K) Y3 i$ O( E3 m4 P1 ~3 n    mov     ax, es          ; ES:DI -&gt; VxD API entry point: X, E7 N6 Y8 E9 K  p" D+ d" o
    add     ax, di
4 j8 u* ^7 L2 K3 e# a) Q' m    test    ax,ax4 |! r' B6 N, C" x$ ?) l- G  }
    jnz     SoftICE_Detected
$ o! y8 Y$ ^0 q6 |8 Q
% U" a+ G, Y; e! I7 y1 k% T3 E, {___________________________________________________________________________
2 Q" n- p' ?/ Q9 b( L% H4 W- Y7 w2 m& I0 w' m1 _6 G
Method 04$ e8 p& h' A) _6 ^4 i( s
=========
- ?! h) @. n7 p4 v
: I6 e' n7 q. h% z  d+ ?, N$ ]Method identical to the preceding one except that it seeks the ID of SoftICE' ]7 c$ u' b( q; U
GFX VxD./ x' H/ I" {" ^/ ~" N
6 h6 ?4 }/ J4 x& e& e1 E
    xor     di,di
- j# C+ `/ x8 D2 X" [0 v1 P    mov     es,di* ^# f+ J5 V  |
    mov     ax, 1684h      
7 A+ {# E, c; @- V4 z  X    mov     bx, 7a5Fh       ; VxD ID of SIWVID
8 x, o2 ?* Y3 ~" U0 ~2 S3 ?    int     2fh9 |9 b3 S. M( \3 t& C: O4 q- d
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
4 K  f! W" r: v3 }4 e    add     ax, di! O" [( M4 }% i3 N$ L" F
    test    ax,ax
  b' u$ k. e# ]% W9 X, i( x    jnz     SoftICE_Detected8 f3 D1 N; D3 [5 K
& }; ^3 Q; C" Q6 w* M! ~' C% m
__________________________________________________________________________
4 ]0 V; m$ ^; I7 q
- o8 O- J% K: q' u+ u) i- k7 W' C6 a& k( E& l
Method 05( f& e0 E% G6 q& l4 p
=========
2 k* f3 f$ t$ [1 m+ G; U( m+ }' q8 e
Method seeking the 'magic number' 0F386h returned (in ax) by all system, z# J% Q/ Z" K* `+ B" r7 ], _
debugger. It calls the int 41h, function 4Fh.
( ^$ Y, a0 l, U$ I4 {+ t+ c- ~There are several alternatives.    I& r  _4 [- w8 G4 y+ g

5 n9 }, F* Z9 ^The following one is the simplest:2 j6 C# d3 ?: N4 z! w% i  Z0 ^

& U8 V1 d, h, D* }    mov     ax,4fh8 `, F% r2 {; x# n
    int     41h
+ |2 Q3 T- S& K3 D! h3 T3 l8 v    cmp     ax, 0F386
4 B- |2 e# }% n7 p    jz      SoftICE_detected1 ~1 K$ z2 K1 Z: y4 I! P; P
; B) X$ `/ o" q4 @; V

, w, R/ y0 d# ?  H8 {8 VNext method as well as the following one are 2 examples from Stone's
) T% D1 f% A: F# B  }1 [- K"stn-wid.zip" (www.cracking.net):" A0 B- S: d  _1 l3 O' N
; d7 R" `" M6 s& E) ?! \. n2 o* J) `
    mov     bx, cs- Q5 C5 K* S1 {8 k
    lea     dx, int41handler2
1 E8 M% {  K5 j  S3 d* q    xchg    dx, es:[41h*4]
5 i8 ]' c0 \! @7 ]1 r5 b5 A    xchg    bx, es:[41h*4+2]( z. z$ Z$ d" C% L/ d- @
    mov     ax,4fh
: _& p. ]0 m! `% s+ x, i    int     41h' J+ e) w6 J4 o* ]2 v: @' Y; Z
    xchg    dx, es:[41h*4]
& b! n3 h9 r, I( r2 i3 d    xchg    bx, es:[41h*4+2]: L- B2 Z5 h2 b) q2 f) o8 o, j; n
    cmp     ax, 0f386h
4 Z  w7 {! _1 N# u( X    jz      SoftICE_detected2 n+ U8 C# J, y; v4 V4 D

3 ], y; X% {) Hint41handler2 PROC' Z7 M6 X8 p6 v3 Q
    iret4 U- O6 w: K6 ]
int41handler2 ENDP9 Q- M. k  j9 ]) @- i. G! t

6 v" L. C: i0 L; s8 a2 L5 J
8 R  u' p/ p$ o- f4 O+ j. P  P% ?: M0 x_________________________________________________________________________4 E( W* L8 s: H' h$ @
- G2 U, U' l% s" H, N1 Y; ]' ~& S9 y

! m. j( t# W8 N& Z$ lMethod 068 s* _; x* M4 l
=========) [3 J  q2 ?/ J0 N
' ~" W$ @7 O/ p2 ~. [
# @1 z2 Z1 t& K0 A5 a5 P
2nd method similar to the preceding one but more difficult to detect:! X2 }) `) }& c1 n. S1 d  k
' v7 w4 x. e) z

2 q$ b# g) Y3 L9 ?3 C6 N5 Kint41handler PROC
1 }/ F+ W# ?# ^# |, c    mov     cl,al. {# N$ ~2 l+ s6 M/ E. [" h" U
    iret% @! n! k- t5 @& ^! Y
int41handler ENDP
2 t- f# N0 N' _* Q+ H4 E
% T6 B( t# N( |
; P7 U) e& T  _# w) ]    xor     ax,ax4 r! ]6 o( ]  ^; U- [
    mov     es,ax
  m$ Q- B! _' l9 Z    mov     bx, cs
8 _: I9 i; A8 d) @* c    lea     dx, int41handler
1 M: B$ T& U) {- `& w0 S    xchg    dx, es:[41h*4]) Z7 T' o! m1 p7 f5 D
    xchg    bx, es:[41h*4+2]" I1 |+ l# A3 l2 D$ T1 V; A1 {
    in      al, 40h
3 L+ |5 j5 P$ s    xor     cx,cx4 d3 ?9 {; f' I2 ^
    int     41h' O- U7 o! i6 z/ t7 g' Z/ q
    xchg    dx, es:[41h*4]( u* p9 q5 r' I0 x! N3 h3 p
    xchg    bx, es:[41h*4+2]
7 }4 D- o* L3 n/ L9 _$ ~, B3 C    cmp     cl,al
# Q+ D1 B) O' @' j    jnz     SoftICE_detected" C' ^5 g! a1 W
4 Y6 t" v: T2 B
_________________________________________________________________________2 T, C" X2 x; C% z  S

; I1 Q* ]$ ~/ i0 M. _+ Q& V( wMethod 07
2 \1 V( r: j) C* Z=========5 r, v- i# q0 f6 Y2 g! o

$ k( h. J, [5 l4 r& Y* jMethod of detection of the WinICE handler in the int68h (V86)
, {4 D7 L7 m* k9 e8 t8 [9 Y8 }+ K! d" ~% P6 r" a
    mov     ah,43h3 u4 t. h3 s( z5 L) E2 w
    int     68h9 M2 f' P1 c$ ~* z$ w! b) a
    cmp     ax,0F386h' s- c/ j6 N- z
    jz      SoftICE_Detected
4 ]0 {" e4 h, S) Y' d+ _! W0 E& z+ o7 n- G. w9 P1 y# e2 j/ Z
" C/ x& Q' e* r3 u- p  l8 ^
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
: l4 ?3 h7 o! |$ S   app like this:
( y5 v8 ?- E" i) n# a9 V: `, \8 @
4 J& }- I2 D/ m% _: Q: z   BPX exec_int if ax==68
9 J/ e; G+ s8 x   (function called is located at byte ptr [ebp+1Dh] and client eip is/ w! {+ e, [* D
   located at [ebp+48h] for 32Bit apps)
# h5 q7 P8 X" b1 f__________________________________________________________________________
3 |8 v; I  ]: `' T+ G3 t$ W& n6 j0 m+ u: q$ z7 U) h
3 s4 O4 u9 {, K3 ?- m# m% {
Method 08
& K/ R9 t+ m2 w' W=========
3 |1 q0 }' L! Q$ Z6 a3 h+ i0 y. k$ Y( u- f8 T: I2 C' I
It is not a method of detection of SoftICE but a possibility to crash the  @  d; |+ O: ]1 L! F
system by intercepting int 01h and int 03h and redirecting them to another
  a0 y* y: ?6 v( a4 V8 m3 xroutine.1 d8 v' W  R/ ^; R
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points9 N  x! ^; I/ I* z
to the new routine to execute (hangs computer...). k# n8 m- o* X( s  y
( |9 r/ j" p+ P" S( l
    mov     ah, 25h
" j2 X! v; w. E4 {" w) h    mov     al, Int_Number (01h or 03h)
' C/ _" X) k1 y; [    mov     dx, offset New_Int_Routine
: o" o$ _; o. w+ F0 L# j    int     21h9 q+ c% t# N7 Q' g$ A

0 j" |* w" r+ S" n+ ^( F2 c" |__________________________________________________________________________
( X! B8 ]' x+ m% L3 n. @9 I3 X) ^( G6 r, K; G8 F
Method 093 k/ U6 i& M" s: |. S- u
=========1 e( V$ f' s! g3 E8 Q3 u& f! d; {
1 z3 X7 @% g" O7 F3 }5 v2 J
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
4 |0 Y- z& r( m4 X; v* yperformed in ring0 (VxD or a ring3 app using the VxdCall).
- |: n' O5 q; ?* w* u3 qThe Get_DDB service is used to determine whether or not a VxD is installed7 P2 v, R4 W" H1 _: P, m
for the specified device and returns a Device Description Block (in ecx) for
3 z# O/ G& d* V' t! ]& Hthat device if it is installed.
' n1 a# [4 Y* }
0 p9 c+ e# P! X1 K" l" ]1 A   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
' D& R* q5 }4 C5 x5 V# ~- H: @; A   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
- H8 j; @; O& L4 n! }* I   VMMCall Get_DDB
8 K4 V) W6 ?* i   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
, p  E0 }  q% d
: j& R; k& R* _% {: y' g0 qNote as well that you can easily detect this method with SoftICE:* ~6 d9 p6 f7 X# Z; p
   bpx Get_DDB if ax==0202 || ax==7a5fh
" X# o! w( L4 T1 w* J* ~1 |% c$ n3 g7 Z7 Z* q6 y
__________________________________________________________________________
4 h0 P0 U  Q  d+ y/ M/ |' U: e# G$ K% Y, g7 u# h" ?$ k# y
Method 10. W8 f5 A# u5 D+ m$ @( J
=========
5 R6 |" B$ S* Z9 k- X; ?& B7 Y& i4 B
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with& x3 K& s, X' K! v5 p  |1 A
  SoftICE while the option is enable!!
& r( v$ h& d, e0 ~9 Y+ m8 ], b' k
" z9 U) u% g: a9 E! \This trick is very efficient:- C$ i" r& F9 Y- h1 P
by checking the Debug Registers, you can detect if SoftICE is loaded, m1 Q- H! T/ @5 O% T2 E! {& K5 {/ R7 W
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if# H6 M% h# W4 r. K4 U3 z2 A
there are some memory breakpoints set (dr0 to dr3) simply by reading their+ G2 Y) Y3 }& l; U- U
value (in ring0 only). Values can be manipulated and or changed as well% f6 k6 r% j; j
(clearing BPMs for instance)% v& y. X9 B1 t& b, m5 |+ q

# C2 [0 d: S9 x__________________________________________________________________________
" B. k7 S6 U& \/ q  U' a7 g2 {6 L$ f
Method 11
# Q4 d0 @2 M8 m6 U5 G=========
" d0 S1 |6 ^. L: k1 }
3 d+ c( c6 Z- y8 n, W4 lThis method is most known as 'MeltICE' because it has been freely distributed1 d7 i0 z; P& b6 Y$ {5 a( }
via www.winfiles.com. However it was first used by NuMega people to allow
# `  a( m& f* iSymbol Loader to check if SoftICE was active or not (the code is located
4 h0 `+ [% Y% u$ W6 jinside nmtrans.dll).
; D+ b1 ~0 \) O- p  Q6 ?& T% Q' X  Y# g! A' L$ z, c. _/ {
The way it works is very simple:: M" c: N. v; `+ b
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for& |$ _, R! ?3 F5 f
WinNT) with the CreateFileA API.
) g- ?" i# A, c+ g# @4 x8 q; C+ a7 j- U) W
Here is a sample (checking for 'SICE'):) o' b8 A1 f1 v
* ]' ?2 v. ?% _; n
BOOL IsSoftIce95Loaded()
7 s3 _& p8 q4 l1 U* s+ B{
: m, G$ W) F3 s& {& P) V   HANDLE hFile;  
: P; {9 O' ]1 g. ?( e   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
. w1 H8 A- z2 z' ~7 a/ p. w' u: o                      FILE_SHARE_READ | FILE_SHARE_WRITE,
. `2 f3 ^; G5 P6 f                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
7 E- ]$ H! U; p. O: t   if( hFile != INVALID_HANDLE_VALUE ); F1 i9 P8 I9 L
   {
, |( M0 C! L- F3 d1 d      CloseHandle(hFile);
% J$ a  B5 I4 ^" y2 H      return TRUE;
; S" K* ^$ d0 g/ s& C7 m   }* h  U- R7 u& Q
   return FALSE;. n% p" f. p8 v! ?
}) r6 x- G) L% [
% K1 `8 O6 H  W1 T
Although this trick calls the CreateFileA function, don't even expect to be
" w3 q+ B& V, b* d. Q' kable to intercept it by installing a IFS hook: it will not work, no way!
( G( }. B5 a5 [In fact, after the call to CreateFileA it will get through VWIN32 0x001F
0 R/ Z0 ]* l0 G& l: B7 T2 ^service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
/ H( h9 w* @4 t/ r& \; \and then browse the DDB list until it find the VxD and its DDB_Control_Proc
! }" T% t$ A1 B% dfield.( V! @6 x" J( r. q# T
In fact, its purpose is not to load/unload VxDs but only to send a 2 J$ G0 j' j6 i6 q
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
* a) P# A6 @8 K, u2 r+ q& |to the VxD Control_Dispatch proc (how the hell a shareware soft could try
$ p- G0 V* e' v4 t3 l4 Lto load/unload a non-dynamically loadable driver such as SoftICE ;-).: R8 l( A5 N% F
If the VxD is loaded, it will always clear eax and the Carry flag to allow0 k' y$ _0 Q3 h* J8 B
its handle to be opened and then, will be detected.
# L2 d# {! \6 lYou can check that simply by hooking Winice.exe control proc entry point
5 o+ B- o7 c$ N8 }  p  Lwhile running MeltICE.
1 c9 o, R" u0 f/ m' X+ c) Q' `# y! g3 x4 }2 W# n+ ?* }5 s
% S5 @9 S0 q6 N( I2 a& e, v  T
  00401067:  push      00402025    ; \\.\SICE- z5 k: Q: n+ K  ~6 X( Y( z9 w
  0040106C:  call      CreateFileA
0 @/ a3 |# @2 b, ~9 k  00401071:  cmp       eax,-001
6 _2 E; i. ^% G. P( J0 @9 k; c  00401074:  je        004010918 A3 T  B1 u1 Z9 R

4 n( h8 s3 a4 w4 h: f/ z) T7 a. O6 Z% g  h& u6 U0 R
There could be hundreds of BPX you could use to detect this trick.3 c0 \$ V7 R) @# d" q7 O
-The most classical one is:
! c4 C* ?, K) T+ f# c9 r4 s  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||* x5 v' A3 @5 J8 B; c
    *(esp-&gt;4+4)=='NTIC'
( X/ c/ \% N3 u1 z8 c7 F4 A' o! ^/ b  [; l1 F$ ?
-The most exotic ones (could be very slooooow :-(9 d0 r) W2 R9 q) F% l! o, N
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  $ P$ z' c0 u" i# ?, I/ n% t' c/ ]4 [
     ;will break 3 times :-(
. q9 G) L8 a) @/ F* I8 M
' X; ]+ B7 p' a6 C-or (a bit) faster:
2 t1 l; b6 |2 ~   BPINT 30 if (*edi=='SICE' || *edi=='SIWV'): H3 F! ~" N' ~1 {

: E  ?, l' L8 V   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
2 n! J8 q' a0 B: a* b( O1 L- s" G     ;will break 3 times :-(. P, K- C. u, ^9 j! |

, v. i6 I/ Z+ c-Much faster:/ Z1 |. A% z. s% n' I2 z
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
: h! {7 ~6 |4 Q' A2 N/ D2 e# G
, q; _% w+ v, K* lNote also that some programs (like AZPR3.00) use de old 16-bit _lopen
$ f2 B2 M7 @. B* ]5 K' L! E( D4 L, Ofunction to do the same job:% c9 K3 ^( Y7 `3 S) h, J- ~

* v9 J/ l  l1 c' r$ \   push    00                        ; OF_READ
1 ^* S6 X9 A4 H: x4 @; S, {* @2 ~   mov     eax,[00656634]            ; '\\.\SICE',06 b: O. y9 }- u0 f* Q" r. Z
   push    eax
; d6 N1 F" J% ^; c6 l/ D  @5 t   call    KERNEL32!_lopen
, i6 e8 l0 S- i   inc     eax
2 I+ G  s1 k: v/ c   jnz     00650589                  ; detected* G3 _% \$ l/ F2 Q& m5 I) t
   push    00                        ; OF_READ
2 t' Q1 P+ ?+ n4 i5 R   mov     eax,[00656638]            ; '\\.\SICE'
9 l" l+ s, I2 c  `   push    eax
, }8 ^3 c' H3 ^3 |   call    KERNEL32!_lopen
' y8 M, ^) e6 l   inc     eax
0 b# ~7 Q- W/ U  H( S   jz      006505ae                  ; not detected
: z1 R- i/ Q( j/ |4 G. t% m& S+ C: D2 H3 b  u& w
, W7 b: Z. W+ F. i. u
__________________________________________________________________________* c$ ?3 s) K+ _3 Z: D
& d  q& j' |4 {& F
Method 12
* h. j4 \7 \0 C7 M- g' [. g6 W2 _=========: j/ m- l2 I* H2 b
& d! `: c3 W; z+ B5 i$ _3 d
This trick is similar to int41h/4fh Debugger installation check (code 05$ G: j* q& I4 x# ^
&amp; 06) but very limited because it's only available for Win95/98 (not NT)
# ^% t! L& e4 k; z% h: N& X: Mas it uses the VxDCall backdoor. This detection was found in Bleem Demo.* v  K9 m6 r* _" K

% z% ?  F# f- |$ t2 U; y6 Y   push  0000004fh         ; function 4fh
; c" |& F& I9 _% e0 q4 y   push  002a002ah         ; high word specifies which VxD (VWIN32)4 S6 H9 B. X, g) D/ Y
                           ; low word specifies which service3 I9 e6 w! U! f
                             (VWIN32_Int41Dispatch)
1 K: K% j" k( B' M- B( g! j   call  Kernel32!ORD_001  ; VxdCall
$ t! J5 C, k# O- o   cmp   ax, 0f386h        ; magic number returned by system debuggers" l1 l+ {+ H2 y. Z+ b! c2 I# l7 d
   jz    SoftICE_detected
& H* w$ p3 N  C7 |  J: a2 z1 _- L% E
  [1 s5 G; ^1 m! q& RHere again, several ways to detect it:
& k  b1 Y# y0 k( {; M* B% {) c2 l1 O
    BPINT 41 if ax==4f
! H) m9 [/ A, h9 ^% O  l& C8 T( ^* \% ?9 R. C9 I
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one8 C: z2 R: |" p. i8 ?

8 B! I& H% z6 u4 ?+ H0 t5 j4 P- F9 {    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
2 x7 Q& O& o% s' |& o' s. u$ H. l! d
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!/ @5 q6 ?" B5 X) ?  N
* n/ s" P, L. M# P/ e$ T9 ^
__________________________________________________________________________
9 r9 _1 [5 G9 |& G1 @9 c  E
5 O/ {+ {0 A7 |# mMethod 13% D; E. k$ j; c4 s
=========' u2 i* h" u: D7 {" r

+ r5 u+ E# H: |# {8 r0 Q! m  S( yNot a real method of detection, but a good way to know if SoftICE is: h5 F2 Y9 G& _2 m8 p
installed on a computer and to locate its installation directory.
5 k, e( X  ?# v% Z3 E/ B7 ~2 AIt is used by few softs which access the following registry keys (usually #2) :5 c* Y4 y+ ~' B+ c5 f1 A

" b$ }3 n7 ^7 s+ T-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
( r- {5 l( A9 k! D\Uninstall\SoftICE
. c1 i5 v: \# t$ ^-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
4 ~* n8 {  l. I( Y. }, t) [( V-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
3 U! U( @; {. q\App Paths\Loader32.Exe
2 s& I% }, Q& O* p9 v
& M1 Q3 m  J, p' O; T
+ E# ~0 ^$ h- ^' UNote that some nasty apps could then erase all files from SoftICE directory4 \, z' @' h* f. W; _" \4 I
(I faced that once :-(+ C# ]6 I0 E0 r/ m8 ~! g+ _' I

% Z6 G% G, E: c# ^Useful breakpoint to detect it:
. T- X9 U* d( A& N+ X
+ P' x6 R" B2 i6 N) [     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
% Q, P( d) X: z/ I5 S4 o: {+ j  g8 t# k& ?- J) R( L
__________________________________________________________________________4 V' g7 R7 J; C7 y
/ p- ^3 K) v! |; J& |8 T& W+ n4 ^
0 X5 S6 k. \. a. {
Method 14
. U  ^( H3 b6 n6 F" L1 S: F=========
' f, J* F$ i8 }! ?1 l- d
1 k# S# `$ P. W1 ]$ K2 V) {& e9 v9 MA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose- R  r5 I1 v4 G+ R* s% g& O) L
is to determines whether a debugger is running on your system (ring0 only).% w, C9 K/ j9 o) b! E

+ ^4 b. |) s" z) s' a( o0 N# f. t" Z4 @   VMMCall Test_Debug_Installed1 b  Q5 S# L  |0 @' [0 I
   je      not_installed/ p9 A6 p- H2 l' s" e" U; u4 `6 Y

  w. g$ o- `% m6 ]* x9 l6 z! Q5 XThis service just checks a flag.
1 ~, O0 T7 U* [9 x: c+ l</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部