About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>) ]" q; }6 c  d* M" z5 j: [
<TBODY>
6 u0 n* j0 r9 _( g+ O" F<TR>1 _- B" l, `' ]  J7 a- |
<TD><PRE>Method 01 & Y# A' t! K/ s3 U
=========/ }# r) ^8 R5 z: J# W! z# b& R
' f  A" G) P% Y+ [- H( c5 b
This method of detection of SoftICE (as well as the following one) is& t+ D6 m3 N2 W- {6 ^  b0 g3 s9 M
used by the majority of packers/encryptors found on Internet.+ O- c. M" u* L8 d6 w- g, \
It seeks the signature of BoundsChecker in SoftICE! s& D" @9 v7 W" r

  E8 C! }0 u& P! |3 ^    mov     ebp, 04243484Bh        ; 'BCHK'' s! p/ P4 {5 p  f9 `
    mov     ax, 04h
2 `' ]6 U& C% r* G    int     3       ' _5 d; Q$ t# ]' `8 ~
    cmp     al,45 s/ U: `/ ~8 B
    jnz     SoftICE_Detected
( D. X  ~" n. x) J' \
, C0 ^7 ~7 d2 f3 W5 B0 v___________________________________________________________________________
% r) z" i6 X% z, B! [5 k
2 `* N: T9 N6 y/ v, qMethod 02
! S, p6 n4 L/ A5 d2 P=========6 ~  n4 L% a, T

% B* S4 i3 S) L, O0 IStill a method very much used (perhaps the most frequent one).  It is used: }+ }, ?  P( c
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,( H# E( y: N& n/ a
or execute SoftICE commands..." t" E2 t  f2 }) M" I7 z
It is also used to crash SoftICE and to force it to execute any commands
' H( t( |& Q2 C(HBOOT...) :-((  + A; I  A# t# }5 p

) i9 S+ J+ J, _( K2 \, ^8 HHere is a quick description:3 ]* n$ L& Z5 q
-AX = 0910h   (Display string in SIce windows)2 N; N# m* c% V. `+ b; q* m
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)$ X' T4 q, ^* O" h- M
-AX = 0912h   (Get breakpoint infos)" b/ ?7 S  v* q- k1 y9 ?
-AX = 0913h   (Set Sice breakpoints)/ f+ t# C2 I' j  t( D/ C: V& Z
-AX = 0914h   (Remove SIce breakoints)
5 S5 w$ Z, |' S" Z9 |# o' Z
9 m  f; D9 ?- QEach time you'll meet this trick, you'll see:
6 v5 f2 \( i1 v1 i# X' |1 A- o-SI = 4647h% P& H- k  j5 R5 V& t
-DI = 4A4Dh
7 z8 D/ m4 H' Z% G. d1 D: Z: }3 Z8 OWhich are the 'magic values' used by SoftIce.
" I$ f$ @1 ^7 r7 P. {; [6 ^# vFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
, m& B' R* V+ S) ^. r2 S
, ~. b( y' F. }' u* M( a% vHere is one example from the file "Haspinst.exe" which is the dongle HASP
/ _! L0 E( \" g7 a0 m2 CEnvelope utility use to protect DOS applications:6 R9 y3 u; {5 D8 e4 J7 A; i4 {
' H. Y- a+ k) }! l. A( o

+ L5 T, K1 f; S4C19:0095   MOV    AX,0911  ; execute command.
" }/ C* ]: s* W6 Q* h- V! ?5 b4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
4 c2 [1 W: J5 D; Z) @4C19:009A   MOV    SI,4647  ; 1st magic value.
  H' c8 g+ B/ e# b2 W# N( |" \4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
! K$ [+ \8 ~+ w4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
# m* r1 f' o4 K" R$ j7 X8 v7 h% B4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute3 v. o% z! R* S+ W. N# S
4C19:00A4   INC    CX# p5 u$ o, `* \+ B3 A; h3 b
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute' Q: ~9 ^' f/ A0 n2 [; @, j
4C19:00A8   JB     0095     ; 6 different commands.
! P8 \2 L0 ]9 t" [4 K4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
! F: h5 i2 q4 P9 G. X4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)5 K$ s" J- [% n2 f( s! s4 ~

, C  x! u# {; M- ?0 t( ZThe program will execute 6 different SIce commands located at ds:dx, which
3 R7 \$ K- t# J9 Zare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.  p( S" q  m9 B% n  w6 N, k- W6 b! `
, O/ {* s3 C8 d' x: F; _3 Z
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.* P2 ~3 y7 X: i0 @# K8 J! M) U
___________________________________________________________________________3 Y; h6 G! m+ K

0 j$ V* _: M9 f; ~7 z
) j1 q$ A& G/ [7 h3 GMethod 034 r7 c4 c0 m+ o$ n# y$ T6 U
=========1 Q$ ?1 J9 D+ A+ z% A+ {: i
9 ?  F* D/ g; `* r8 H2 r7 s, j
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
- c# E/ h7 ^. s8 W6 T(API Get entry point)$ C$ t- \0 x7 `; X% R
        
* x- q- c! t  p
; _" d) |4 k* D' @    xor     di,di+ V, H( T4 H  T, j2 G6 a6 o
    mov     es,di
2 E6 ^: m3 z0 _2 T7 X    mov     ax, 1684h      
9 n: O! s( s& ]6 m    mov     bx, 0202h       ; VxD ID of winice
& i% v6 ^: a4 b' m/ I+ v    int     2Fh
, }8 \: A; s8 e: K3 L% u0 T    mov     ax, es          ; ES:DI -&gt; VxD API entry point
; G. ^6 a2 Q* F- T% C* q' f    add     ax, di
- x2 Z4 j) P9 C, o' c* y    test    ax,ax
6 e* ^4 s% ^) _# B    jnz     SoftICE_Detected& ]! a% z7 q" S

% f# w; V% L' ?___________________________________________________________________________& s; C5 R! p8 u6 V5 q8 l
. E1 n4 G8 x* V" k; P
Method 04( ?" q1 V7 u9 d) @% @9 v
=========% x# a) ^% q* H; w9 U" D

# \, ?6 r8 ]0 }4 ~+ UMethod identical to the preceding one except that it seeks the ID of SoftICE5 d& v6 p, z* L4 k3 z
GFX VxD.
0 e" @7 ^  z1 O1 k; z- ^' V% f5 d# u& K" U
    xor     di,di$ H5 Y6 s' Q! \2 G/ U% s
    mov     es,di
1 N* u# [# Q- O    mov     ax, 1684h      
) {& D, a+ u8 L/ _    mov     bx, 7a5Fh       ; VxD ID of SIWVID
$ ^  j- I) S- ?& R+ z& W! T    int     2fh/ o* I% G2 L1 C
    mov     ax, es          ; ES:DI -&gt; VxD API entry point9 K1 i  v4 @3 ~2 [
    add     ax, di  F, m- ^: F) Q3 \1 G! S
    test    ax,ax9 K: U2 w; Y) `, [0 o) M  M+ E
    jnz     SoftICE_Detected! o& K1 R' L: p. s, w

% g" @8 s$ Y) B$ T* X__________________________________________________________________________) y( r+ D, a/ d. ~# Z; }8 \
. w* k6 T, g, w1 n- d, S3 _
' M/ N7 V5 H  ?! A- N& ~
Method 05
# k9 |) o( m" s  B2 m=========8 p) a4 L' }: w; E) V5 w3 Q" i

9 ^4 X, F: m' e6 L" gMethod seeking the 'magic number' 0F386h returned (in ax) by all system/ ~$ F4 S/ c; Q: _2 E" \& C
debugger. It calls the int 41h, function 4Fh.
3 H6 I) C8 S' z! b& }There are several alternatives.  
6 q/ z$ W% s( n& p' L
& n. n  m, i( a# W$ O+ a3 PThe following one is the simplest:
8 ^6 u# Z  g. V. ~
+ ?( S) c8 B- t+ g  ^    mov     ax,4fh
" ?3 _) `2 ^! c, d; `. B+ J6 P9 m    int     41h7 ^7 a9 R6 U  l- m" l& _  m3 ~7 b
    cmp     ax, 0F386. Y4 J! o$ f* @7 j3 a8 B! \
    jz      SoftICE_detected
  d; t- J8 @2 w7 Y" U
6 F! ?0 ^; ^1 L( v" R" j$ o/ p# A7 ]5 ?1 t
Next method as well as the following one are 2 examples from Stone's
1 P7 Z/ r7 ?. |1 q; y. U; Q) o"stn-wid.zip" (www.cracking.net):
" G7 R, k3 ?; |7 s5 T7 y5 m  W9 g
* \+ P/ L' v! E; {- k* M    mov     bx, cs
# r$ i, k) M* r) u: u/ _2 i; o    lea     dx, int41handler2
) W/ K0 n# h% ^* e8 }    xchg    dx, es:[41h*4]7 o7 D+ c2 R: X* x; [% r0 O
    xchg    bx, es:[41h*4+2]
" `1 r4 z" p- J  C    mov     ax,4fh
6 v. U% m& u3 H    int     41h' N# j% a3 r# I, c
    xchg    dx, es:[41h*4]
" Z* S: F, _: z+ B    xchg    bx, es:[41h*4+2]
6 g  |. Q! Y8 m( z0 o" B+ m    cmp     ax, 0f386h
" R$ W: A7 e/ O. \    jz      SoftICE_detected8 c, M  U! ?7 h! F

9 B% c/ Q* p7 d' v/ @/ Aint41handler2 PROC
* a. G- O* }9 F$ P/ I    iret( u3 H' ]+ E: ~. L; e) n; ~7 |
int41handler2 ENDP
! v# C% R4 G  W% ^$ ^: R7 @) x6 M" P1 D6 T1 S

+ c# `9 y* @1 Z5 g8 s_________________________________________________________________________' T6 z; E* n3 X& R% c2 q# u( k
0 v" b% u* V  ]9 E, i- q
# E! F- b/ O. N) S; K! `2 I  I
Method 06/ p9 A" D7 N5 H, H
=========
( @  C3 `) h+ V6 y+ y' Q6 `2 W
  {  v' e2 n: F. ?9 z, U
5 ?3 c' G5 {7 [# j2nd method similar to the preceding one but more difficult to detect:
. q& ^1 y6 ~& A( f7 R& j. {" w5 |9 |0 u! \9 G$ \

2 [0 d( L1 D7 Uint41handler PROC
+ f8 s- Q# H, S9 g    mov     cl,al5 k% e( h; {' k: a6 ~+ i$ _% y# k
    iret5 X* p* W) q: R1 ?
int41handler ENDP% @: a. w) E/ b1 O( h
+ T4 P% n7 [! Y1 E) B0 ~
+ G8 c$ |, p  |, {$ g& O
    xor     ax,ax' ]/ G+ d, e1 e* ^: F: i
    mov     es,ax
4 S/ g0 I, N6 p4 Z, A( v$ @" T* P    mov     bx, cs& q1 m. ]5 C/ G/ M& J# Z' V" m, E
    lea     dx, int41handler* ]2 S3 u2 n  h
    xchg    dx, es:[41h*4], R7 n$ ?( z0 e% z& W2 S3 N# N
    xchg    bx, es:[41h*4+2]
0 v9 H2 ~1 ]4 f+ f, z1 |; Y* [/ T* Q    in      al, 40h4 l+ f  t" t- R0 N: l! C3 @
    xor     cx,cx: X/ g! r. x0 b  Z4 N
    int     41h1 \. y. h6 d* q  C6 q' b. A
    xchg    dx, es:[41h*4]  ]3 q0 D  E0 A/ X+ f, ?
    xchg    bx, es:[41h*4+2]
3 W& N/ Z. W& |1 D) v    cmp     cl,al. M$ N! \0 ~9 n& e
    jnz     SoftICE_detected9 P* \: E  W: T1 S

/ h: J# u2 Z" K_________________________________________________________________________
0 h; e0 u9 e9 A6 c: J' o4 O
0 y, X. \3 Y; [& U4 P' K/ RMethod 07
3 u; }$ b6 _; e. }=========
& }8 X" U. s/ w( z3 h* l" y3 f) Q
" H9 a6 H4 p! |3 \$ LMethod of detection of the WinICE handler in the int68h (V86)
4 Y9 T( d1 j1 K) p" B2 k
- H# m) E$ V! K1 }7 E- {5 x    mov     ah,43h9 ?/ o! j# W" }! \  t# L1 f7 S
    int     68h
5 t0 e" x2 e% ^! J2 i8 c. t% T    cmp     ax,0F386h
/ ]7 u$ A7 ^4 C7 t) l; e    jz      SoftICE_Detected
4 ~1 v' h9 V% Q  u3 m% v. t! U0 c! K' I# _) U; ^  U7 J/ E$ c6 x
+ P( M2 E! W; Y$ o
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
1 S5 s; \6 a0 K9 z   app like this:
' \! u5 q6 g/ j2 m
* K1 G- q; R0 W( Y   BPX exec_int if ax==68+ T) o5 u/ h7 y* D7 C1 L
   (function called is located at byte ptr [ebp+1Dh] and client eip is5 w- ]/ g/ A. N* z3 ]1 p. o! u
   located at [ebp+48h] for 32Bit apps), w# X/ y' C  H& N; v
__________________________________________________________________________
% Y+ b, G1 A  C9 m5 K
+ V& a8 j- Y" H+ `; y$ S7 u6 e) @1 e7 v8 o4 x4 |
Method 08$ r* C% `( C& K; u% T# \# {5 F
=========
0 |2 S2 h& a: T( T) G" a  A5 y
3 h$ \6 z1 w2 w( w% nIt is not a method of detection of SoftICE but a possibility to crash the/ D. ~: s0 `; h
system by intercepting int 01h and int 03h and redirecting them to another+ u% l/ e8 \: b- k3 x' i
routine.& T3 V1 P! f( l. c4 S' M
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
7 D9 i' y' A' |0 Bto the new routine to execute (hangs computer...)
7 @, f9 ^' ?" q# _( S
' w% W) g% k% N+ X9 c, Y' n    mov     ah, 25h
* J3 K" k) y/ s2 ^8 L" o1 F    mov     al, Int_Number (01h or 03h)
# G% r4 a0 M  k    mov     dx, offset New_Int_Routine" P- {* Z2 Q8 c. o
    int     21h
; x8 R3 v5 L. `$ S; z4 \; x! W$ J' Q4 P7 G
__________________________________________________________________________
' r# B/ ]; ]5 w0 N* [. g3 k+ U- h$ _# V) r
Method 09" E( x$ Q/ w' g( q( H0 a( h
=========/ a2 t: b* h# z0 _5 U

1 b, A; `( S1 m# AThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only5 N$ I, F% j6 u+ u! D" z
performed in ring0 (VxD or a ring3 app using the VxdCall).  L# M- n( z! s, Y# M
The Get_DDB service is used to determine whether or not a VxD is installed
; J$ u* G$ H! v2 L* ^  F; O5 Afor the specified device and returns a Device Description Block (in ecx) for
9 o' l  Y+ o- @- J9 Tthat device if it is installed./ `( z. ?( ?* @3 I, s
5 y& m( u% y& F" k1 c
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID9 P0 l3 b$ G5 v& X3 C
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
- Y8 s# s, |( T1 ]( w0 J   VMMCall Get_DDB4 b/ D7 B+ o$ `0 v7 }, ^# F% S
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed& R- r5 K# A8 M$ Q% L, ^7 U
' Q7 T5 S* c! u  h1 `
Note as well that you can easily detect this method with SoftICE:
+ Z# Y" l( j+ L/ Q' o$ |. v: t% ~   bpx Get_DDB if ax==0202 || ax==7a5fh( }  u% e2 ?7 j6 W: y

# {6 D. B1 Q6 r/ F( D: X  ?__________________________________________________________________________& F8 c0 T7 K5 p5 W; @# S8 ~, u; t

- {) Y( o3 O4 a# ?Method 100 u4 d6 O' ?5 f4 n( D  r) r& y5 S
=========" S3 U/ w. H& Y7 a: F
5 T. T# k( j- \
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
! C( a  k* n! M  c! m  SoftICE while the option is enable!!
  U1 m/ ?4 `$ c3 o4 L$ A  Z
( X* B( s/ d9 k+ ZThis trick is very efficient:6 d* ^0 W0 O$ a5 a% B: Y* \
by checking the Debug Registers, you can detect if SoftICE is loaded
% w9 I9 p+ B: H* y' `+ V1 f(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
5 _3 R3 |7 I" vthere are some memory breakpoints set (dr0 to dr3) simply by reading their
6 n4 J( g2 W0 f3 p5 avalue (in ring0 only). Values can be manipulated and or changed as well: e) ^- D" W6 I( b7 B$ H* P! z
(clearing BPMs for instance)$ J! M; r+ ~- ^- X' |3 P( J2 ]/ Q8 d

! z6 `5 R2 n* c1 V* [* s  u__________________________________________________________________________
+ L3 w( q( x% K/ Q/ k  }8 o7 ~* w) l) h$ A1 Y
Method 11
* i' {: w! i6 G1 S=========
& i0 @4 o2 {8 k" V  d0 l" s) u
: ^# }! Z, p- G' d; B- [This method is most known as 'MeltICE' because it has been freely distributed0 t% @% F4 E  ?8 b
via www.winfiles.com. However it was first used by NuMega people to allow
( L' N5 U$ D' H7 QSymbol Loader to check if SoftICE was active or not (the code is located
! Q, `1 r: t9 n3 T% M! Q  rinside nmtrans.dll)., W- s2 F  G+ `% Y

& {; ~  E; E2 A. HThe way it works is very simple:
2 Y) N+ D4 s8 E% PIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for& E+ j, W/ J# \4 z( b+ R
WinNT) with the CreateFileA API.
/ ?& d. R* G' h! h9 X( F0 C/ F8 o: k4 s2 C
Here is a sample (checking for 'SICE'):! R4 [2 c2 U5 q0 b

. O# L  n  p/ s* aBOOL IsSoftIce95Loaded()5 V4 y- C5 t9 c& ?  d3 V% I3 ~
{/ U2 I! V& K; Z3 f! B" T
   HANDLE hFile;  " A# z, @" W. P+ q; @$ E/ S
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,2 b/ G: a5 t" w0 m% g4 v! J+ ?
                      FILE_SHARE_READ | FILE_SHARE_WRITE,! z& ^% Y  K) r/ D
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
1 B, E1 ?/ W2 w. u   if( hFile != INVALID_HANDLE_VALUE )
& p/ \7 f6 v, R! {6 J  V  t# E   {0 A, a9 G- V" R  U* f) Y8 R; ~1 |
      CloseHandle(hFile);$ y2 ]) @' q" U4 Y: \
      return TRUE;
% i. v+ o: B* `1 z   }, ^" \5 h0 H* W
   return FALSE;
) |$ Q  Q# g) t' t}
% e7 s; K+ K9 B, D; G4 M/ N  e% O
2 i/ R8 o8 D" x( \) aAlthough this trick calls the CreateFileA function, don't even expect to be: M) w2 p1 O2 }. S5 ^8 P
able to intercept it by installing a IFS hook: it will not work, no way!+ e! @  P' q# ?1 z) ?; F1 A( Y
In fact, after the call to CreateFileA it will get through VWIN32 0x001F( R7 b4 D1 J: E" w3 i2 v1 B  r( h  A6 ~
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)& j" H4 ]5 z$ F* I" r
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
! I; ^) n! i. c) p* M; ?; yfield.
4 v) m. E0 B! @% MIn fact, its purpose is not to load/unload VxDs but only to send a
; K, K( f/ n3 F  ]1 MW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)! b9 j( z3 f" R6 E
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
+ h+ l. x6 Y) B4 Gto load/unload a non-dynamically loadable driver such as SoftICE ;-).
8 W& C  p' u. ]- L/ C, SIf the VxD is loaded, it will always clear eax and the Carry flag to allow
- _( G& e- f2 U4 f! e  Xits handle to be opened and then, will be detected.
! s' ~6 Y+ s& @7 f6 SYou can check that simply by hooking Winice.exe control proc entry point8 a7 g; V6 D# Y  O
while running MeltICE.- J! M7 H6 v: H* h

6 u& [4 n' q" q% L: k' |1 u, ?: u5 B  q9 n" k
  00401067:  push      00402025    ; \\.\SICE" m  A, C7 E6 q5 x# N# U9 Q9 G
  0040106C:  call      CreateFileA
6 B; n, B6 V- |2 T  00401071:  cmp       eax,-001) w* E: n( @* S' U; k
  00401074:  je        00401091
4 @: g+ b2 T9 f( f; w! A7 }
/ A2 g% d% A# D- \. n1 _! @6 w3 R8 v& n1 _6 n
There could be hundreds of BPX you could use to detect this trick.
& N1 E; K# `1 Z; `8 r( x; V-The most classical one is:
  _. d# Y2 s+ Q  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
; d6 y( H+ T/ n! i5 K    *(esp-&gt;4+4)=='NTIC'
( e. J. R- S! s- b" x$ b
% g8 p0 e1 q1 P8 s0 }-The most exotic ones (could be very slooooow :-(
+ l. M. @7 I  b  n   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
" j: r8 Q$ R) @1 |& L6 v: {     ;will break 3 times :-(
1 G. c" O9 o' ~; e
' J3 ^5 |# \/ Q$ T8 X-or (a bit) faster:
' x3 }9 T) c' G   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
0 S+ `, M7 [# T  B' \
( ?9 O7 p( M2 ], x) q9 s5 k   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
" {7 j7 w* w. H7 ]3 ?6 C3 x% W- N8 P6 }     ;will break 3 times :-(, W) o- d3 G4 V5 t8 Q. n
8 l9 [" W/ M7 b0 s' t  ?
-Much faster:
8 D: `3 _5 Q" v   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
+ ~( }; w% G6 h! d' ~+ Z3 p3 d- h1 U. f
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
7 s, X: ^( |3 Y) afunction to do the same job:
# U+ |7 x0 j5 E. K* K' D3 M! c0 c' T; S$ H0 w# y- h
   push    00                        ; OF_READ. n  H, o9 J3 @8 n: U2 `7 s
   mov     eax,[00656634]            ; '\\.\SICE',0) n' |7 F% t5 M8 v
   push    eax' M! E2 E8 u$ b
   call    KERNEL32!_lopen
+ [! J  E2 k. ^% X  H, W, Y7 A+ V   inc     eax
2 c, T! Z  C% R3 d( ]' N" r   jnz     00650589                  ; detected
) w. X) Y; Q; S   push    00                        ; OF_READ, l0 D, ]( B+ _& t+ d; c! f
   mov     eax,[00656638]            ; '\\.\SICE'* p* O* z0 u0 Q( n! N8 z
   push    eax& |5 {+ w0 S2 ]' z
   call    KERNEL32!_lopen
; `5 h' j3 D  \   inc     eax
( w, s" o# q: A  }' l" x   jz      006505ae                  ; not detected5 i# n% g9 ^/ U4 y
9 U& y' m% B0 K/ S+ D; Q, G* ]. V4 T
$ n6 u( ~9 u! Y5 z) c% l$ G, T8 s5 q, P
__________________________________________________________________________2 ?: B) T' K0 i( T/ x
4 f. T" T7 w: V0 J8 t
Method 12
5 u0 ~) P! o0 W9 b  \=========4 h4 u5 U+ N, K! T+ g1 [/ \
( B- {- U3 h3 q- g# p& _1 `* G; N. g
This trick is similar to int41h/4fh Debugger installation check (code 054 c* A6 `1 k; A5 B9 {$ w
&amp; 06) but very limited because it's only available for Win95/98 (not NT)
# z# Y8 \6 I) J' z+ L" l, d% nas it uses the VxDCall backdoor. This detection was found in Bleem Demo.9 k/ s, M7 w1 }! j

- ~/ [) G; ~1 @9 \. i5 z   push  0000004fh         ; function 4fh3 x+ }% D+ E$ _6 g
   push  002a002ah         ; high word specifies which VxD (VWIN32)& T% ~- B. i4 L) U5 |
                           ; low word specifies which service
0 c' v: K9 X7 o) w4 d7 M                             (VWIN32_Int41Dispatch)7 V2 x, h$ B( f  p' F; h) s' h
   call  Kernel32!ORD_001  ; VxdCall
' U" Y- q0 ?0 m: \: j; Q   cmp   ax, 0f386h        ; magic number returned by system debuggers* y5 B0 }- a" a
   jz    SoftICE_detected5 m  d' E  q6 Z7 v  ~+ Y+ i
0 a7 {9 p, @6 T5 C) a* h
Here again, several ways to detect it:
( T* U) a' `/ {* K$ U( T7 R6 w. I5 \7 e  Y# W9 c) t( ]
    BPINT 41 if ax==4f' r' U. T: o  Y& o
. j1 V- T8 N* `- Y% l; F0 D5 x
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one. K7 E5 l$ L( [
# L! h- b; N4 X/ [. V" B6 x; W6 P6 F$ _% P
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A$ \" R; |% k6 s5 D" L% I! u( ~

9 N+ [5 Z& @, z1 l! k( V    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
/ D2 o- l, V1 `" N9 g: ?3 t1 b
; I7 r: X# i% V9 A4 P  F__________________________________________________________________________
( s- `  K+ }) h6 j- z( G
4 w8 G% ]+ d$ [* D) }Method 13
, i9 V! e, g( n) P1 s$ E=========
" E; x, }2 F3 L& c( {
6 g7 N+ B9 J5 }& F8 f3 E' [5 `Not a real method of detection, but a good way to know if SoftICE is
) ~9 a, M9 K- h4 h% H+ xinstalled on a computer and to locate its installation directory.* u! Y! E6 V; Q" N" ?- s
It is used by few softs which access the following registry keys (usually #2) :
8 Y" s& Q- U5 m$ @" s, w7 i! ^# l  w, n+ g- x7 X( E
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
- o: X' w, [5 x- }2 `7 @\Uninstall\SoftICE
  N' a5 Y0 _2 Z  K( q3 n-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
0 Z3 K! r; ?2 z' u-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
6 Z# |* v2 N' G' D% ~& \\App Paths\Loader32.Exe
' y# X& p! `0 L% ?: ~8 v8 h6 J0 E; g' {# R

2 w% \! Y! f, ?, {( JNote that some nasty apps could then erase all files from SoftICE directory3 O7 k/ \, |& H% H4 D% K0 k
(I faced that once :-(0 R% D: m/ h) n( ?  D0 o

; ^- L, k* o+ b0 w! D) e9 B" OUseful breakpoint to detect it:  W# ]' g2 n4 J" l) n& w
) _; M/ J- I8 p: ]% Q" X- a
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'  f3 [( ?; E9 T
/ v2 R2 {6 }  o" R% w
__________________________________________________________________________
% s8 t3 R+ p7 E+ N  y( Z* x- m# Q

2 e- G: J" E* }; f/ M9 ?Method 14
" ]% {7 a- {# K0 V6 j=========
( l5 F* |: x3 @( I: [( y8 r& w3 ^4 y% V3 I
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
6 q  {$ p3 }# H5 m! Jis to determines whether a debugger is running on your system (ring0 only).
# x! V& E# a6 T8 o: j% _: r) m% D2 c9 I
   VMMCall Test_Debug_Installed: {6 ^  `9 Y4 j
   je      not_installed- P2 H) f. \/ B$ k! L3 z

( u6 u3 Y$ V4 q' w* q  zThis service just checks a flag.$ w5 l6 ?: l0 Y
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部