About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
  o# c- ~/ Z" z2 ?, r2 X  e9 o<TBODY>
/ |* b& N. J" h4 M7 y<TR>
$ Q$ \6 P/ O. h% n8 p( |8 c: ~2 {<TD><PRE>Method 01
( F( }& C' [- q% d" \=========3 h9 _5 `# M/ F, d0 B
, w- K7 b+ }# \, L
This method of detection of SoftICE (as well as the following one) is
  A7 H0 g- X1 bused by the majority of packers/encryptors found on Internet.. Y; m5 c+ Y7 h) q6 L9 n/ q
It seeks the signature of BoundsChecker in SoftICE
7 }2 i+ ~" S/ R; N3 L- m& J0 k" l. o5 a& u
    mov     ebp, 04243484Bh        ; 'BCHK'
$ N  d7 }, ~3 V! V4 M    mov     ax, 04h% `" A% h) `+ d7 z
    int     3       1 p3 _9 d3 U& v9 V3 c  [
    cmp     al,4
; ]" X% S" ?" y; k    jnz     SoftICE_Detected9 ?, U9 C% U4 v! U, N
) @& B3 A! f9 F6 x8 e
___________________________________________________________________________' T7 U- |  Z  b! l: u4 Q$ U

- k- ]0 l* }8 D- [; w& |Method 02
0 X$ t" E% v- X=========
0 q9 n& X3 z( r$ p3 B( f1 \/ k) R4 u. O5 d5 q: p' w
Still a method very much used (perhaps the most frequent one).  It is used
& U5 r) L  J; m; V$ k5 X  jto get SoftICE 'Back Door commands' which gives infos on Breakpoints,8 y* F* H1 H  _' a8 f
or execute SoftICE commands...
8 a0 @! v; o. \& k# w/ OIt is also used to crash SoftICE and to force it to execute any commands
* e; N, k, d/ }- t$ d1 g" Y(HBOOT...) :-((  
" S  V% A& J7 C% d3 u
! v) j+ G7 v" X  r/ q: ~( i- QHere is a quick description:8 l4 I! ?7 W- {4 p1 i' V
-AX = 0910h   (Display string in SIce windows)
) ^5 Q: {) Q! k- x  N& [-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
4 ~* F- u( W2 }5 K-AX = 0912h   (Get breakpoint infos)( g4 D. |) o, b5 g/ D7 V7 p
-AX = 0913h   (Set Sice breakpoints)
( Z6 x" g3 p  U& h$ @7 k-AX = 0914h   (Remove SIce breakoints). p2 }, s* f/ m1 M$ w7 m
# R. m# c1 ]$ B: M: P; G  }% t1 W# ~
Each time you'll meet this trick, you'll see:* ]8 N' V1 }* e6 U: m6 f
-SI = 4647h
' J! O0 Z4 P  A. o8 j) {5 s% J-DI = 4A4Dh4 B- T5 r! ?( x% b9 q; ]
Which are the 'magic values' used by SoftIce.  {- q) J0 E8 Q7 z
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.; P9 S3 l, C$ n/ \. Z3 h
5 v  C, J1 ~! R8 @7 [  c) ~; @) h
Here is one example from the file "Haspinst.exe" which is the dongle HASP& Q" P. C  w. w- _* u
Envelope utility use to protect DOS applications:: q9 {; R# y9 j3 ]

1 Y6 O9 v( c9 Q  t- U. e
2 d  p9 q8 r: B( T8 j3 ?  o" D$ d4C19:0095   MOV    AX,0911  ; execute command.
( O. ~' `: k& \/ Q& f7 ~' _4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
' T' U& T" c, e4C19:009A   MOV    SI,4647  ; 1st magic value.
/ R3 W3 B' \, K: r5 I- i4 q4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
1 e8 e7 j% K( A' L5 D3 o9 n/ Q4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
1 V0 ]& K: S+ L' h6 E" B) m% A1 ]7 P4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute  `- F1 x. P) V
4C19:00A4   INC    CX
0 d2 h3 P8 Q" `5 |% c. d4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
/ f& N, i& Z% d4 q: g( j8 T4C19:00A8   JB     0095     ; 6 different commands.; a: a' h4 A% f) z
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.  ?, @# S5 ^( L1 j  P/ L* o  e
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
  T' T5 s6 S+ a5 x- b" U
' }) M$ d$ C1 T9 e0 h6 rThe program will execute 6 different SIce commands located at ds:dx, which* B  I8 f) W4 s0 b- I+ s  O
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.) Z6 M( L* `) [$ l% a# S; s( U$ ^- k

' d7 O% |- @4 O% e) k( y* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.! g4 o) o8 T7 O& n, b
___________________________________________________________________________3 c3 b2 ~2 A. F# t

$ X' F) g8 i* \: h6 w9 U" H; s. v7 `  g! z
Method 03. n) R" e: C- l5 b/ G: B5 @3 ]' r
=========
! K7 y0 ^( Z* E2 o2 Q, q. |, z
; B. \" }* o, k8 z7 t1 ~# eLess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h/ z, A* E/ O6 N. v- f
(API Get entry point)% p* c7 M! e" x7 I0 b
        
- p$ L+ v# F5 a8 V: C& g* c, S* s4 Z
    xor     di,di3 ]# g5 g# |" S6 s/ l) T( C  ?
    mov     es,di
& c2 S3 ~3 [9 D, H# s    mov     ax, 1684h       3 |! q" h' I; w, v
    mov     bx, 0202h       ; VxD ID of winice
; p; _, L  R- |    int     2Fh& I/ c6 m- T& k8 k# o& I8 i
    mov     ax, es          ; ES:DI -&gt; VxD API entry point8 F) n% d, ]6 U3 h
    add     ax, di( ]" X' o& g  o4 p7 K
    test    ax,ax
' w- Z7 O# q0 j; C5 V) K, S    jnz     SoftICE_Detected1 l& _) D' ?' A8 i+ Q) I* f

# p2 J! f8 c8 ?8 \5 S1 I8 ^% h9 F___________________________________________________________________________4 Z* _0 T2 o" S* H- e/ a
7 q% m, ~& H% c2 S: D
Method 04
8 w8 ^  \' r5 o+ c=========
# t; i/ Q1 ?0 i( o9 P$ U8 F: V' M: @* Q1 B2 q5 y
Method identical to the preceding one except that it seeks the ID of SoftICE
* i3 [5 [& q( XGFX VxD.+ @7 |5 [, d5 l+ O
4 E5 D' g7 f5 H/ t9 `6 J
    xor     di,di
9 N' ?& M' `/ q1 `    mov     es,di) v' ~4 O, S( s, F, p# D
    mov     ax, 1684h      
' ?9 t2 x8 k+ e' `    mov     bx, 7a5Fh       ; VxD ID of SIWVID8 c- y( y% q/ K8 H$ z$ [6 e
    int     2fh0 P: e& P% n# ~* @# X; G
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
3 v3 @+ u* K! {( y    add     ax, di4 ?, F1 C8 M* @) U9 b3 L2 A
    test    ax,ax
/ }' p) T) M- L. V5 W6 r    jnz     SoftICE_Detected
! ~& Q# o. c* \) B$ m2 ]
7 J2 \3 Y) I& ~__________________________________________________________________________# a: v2 {! W- O1 O& W$ y
2 y6 r$ z) e) d# `& @  M6 L2 Q& J
& }, b2 v' a  _5 O5 H
Method 05
/ n7 |# ^7 e9 d: W+ g=========" p  R+ w* M1 G( P3 X
, J; k! j  {; u2 n7 a  i
Method seeking the 'magic number' 0F386h returned (in ax) by all system2 D6 e, o+ r/ _
debugger. It calls the int 41h, function 4Fh.
5 a3 n; r: q5 [  mThere are several alternatives.  
  y$ U# p( a( j. q' N6 Z* x) W& ?- s; S
The following one is the simplest:
# M5 M6 g# t( @2 B5 ]' I% o: @2 F" {+ p  W& r
    mov     ax,4fh
4 w! g; I& L! }: H* v    int     41h
3 Y/ ?1 |  o: p# J# P' g    cmp     ax, 0F386
1 M* v$ F1 I# E5 l+ u) N/ e% F    jz      SoftICE_detected
& H6 g$ y( F; q* k% x4 [2 ?& K
$ N; e; f* d* P9 b8 G' J# X/ B9 c# ~/ M! {0 n* }
Next method as well as the following one are 2 examples from Stone's
# O4 Z# s6 `% r+ x' R"stn-wid.zip" (www.cracking.net):
* X, I: v% ?2 s( V! p3 \/ O
3 s: R" n: c/ e; c* }- H/ b    mov     bx, cs
1 t! x8 D, U* v  f4 ^  x2 c    lea     dx, int41handler2/ M2 V" a1 R1 i9 A# p
    xchg    dx, es:[41h*4]
( V# `9 _* J' o" s: Q0 K. I: k4 o    xchg    bx, es:[41h*4+2]
( Q, Q+ u. n' s0 E. Y$ I    mov     ax,4fh
$ U5 B  ]& d3 g# f! }/ i- `    int     41h
& b% M$ }! z0 }1 m    xchg    dx, es:[41h*4]; K; J2 V$ E7 }% t
    xchg    bx, es:[41h*4+2]
( y" l# T9 M/ G9 v" b    cmp     ax, 0f386h# W" S7 z" T1 K: `& i
    jz      SoftICE_detected% H4 F9 m% D- Z# p. E8 P. L7 q3 _

+ U! e4 B% g# A$ T2 k# ?int41handler2 PROC  ?0 _  \% [- p$ v- {
    iret
) V- m9 ^, }1 U+ U  c, c7 u6 |int41handler2 ENDP: n3 p1 y# l2 N: i
2 I& a; P4 m. e" P2 a

% I: L. {6 x" T5 r$ B_________________________________________________________________________
: w. {! d5 M. D' F/ B/ N/ d# h3 D4 B+ w/ ]  p) y
9 v/ ?' F: P7 e! {) c' [
Method 06% N) [4 P+ J7 K8 ?4 M" ]. O) v4 \( ?' v
=========
/ Q# l4 z( s2 P5 d0 y
$ e* Y- ]% P! M3 N3 l% `2 N- f: z% p- D1 j+ o% S* Z8 Y
2nd method similar to the preceding one but more difficult to detect:
! W  F9 G! S' [1 f
5 R6 f) x. y0 v) D2 L, x& l
& B& X; r; y' h5 q+ g2 Fint41handler PROC' T- L# A4 d7 P* s8 Q4 q8 C
    mov     cl,al
; X' d' ^; n9 R- P: R4 C0 H    iret
& D5 w2 d9 z+ A4 l. Mint41handler ENDP7 I* \0 Q" g$ X8 N
( O# r0 d" [. y1 w! i

1 i% A  q: y" r) y) i+ ?$ Q% b    xor     ax,ax9 h$ B- y6 z8 M  U. F5 [
    mov     es,ax' T$ c3 N$ b0 G0 ~7 k. s$ J0 y# ]
    mov     bx, cs9 f" a$ k/ U6 ?) o- R4 e, v$ j
    lea     dx, int41handler4 @! o8 U2 M/ C  x& |  v
    xchg    dx, es:[41h*4]2 n; p3 Z1 A" [* E) V; G
    xchg    bx, es:[41h*4+2]. L0 g, M0 U0 h
    in      al, 40h5 u/ @: Z- j; r1 P7 g$ M! ?; i( `$ i
    xor     cx,cx
6 ^9 u7 ?! ]: q    int     41h
5 l2 I0 O/ `( L    xchg    dx, es:[41h*4]
4 K" B, v# d* [* ?    xchg    bx, es:[41h*4+2]
- E3 L1 n1 M: p* y    cmp     cl,al0 n2 J( J6 A9 C: Q8 U
    jnz     SoftICE_detected
" w4 }' O# ~/ C6 R' Z0 n" V& e0 m1 E% r
_________________________________________________________________________
1 Q2 i( q$ Q% G3 _
/ u- }, v* G3 oMethod 076 e5 z) r1 ]" \: @, U4 M5 V9 z
=========
6 X7 ?+ ^0 F- `) S: T7 @4 ]  e  ~, d' [' N( D
Method of detection of the WinICE handler in the int68h (V86)
8 ?  a  Y. a7 L- Y
9 T  f! m( `7 H% s0 \    mov     ah,43h4 V+ ?: k' y$ p' v
    int     68h
8 G: B/ N$ |2 f7 N1 w$ b, G' g    cmp     ax,0F386h
4 w& D, ~, Z6 w, L  q    jz      SoftICE_Detected
, f5 i  `& U1 R
# Z+ }# D$ u4 C/ Q$ G- Y
6 _* g4 j* p% |: P, q! T7 Y: R; e+ j=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
$ {  d7 M4 S2 o% W) h7 s   app like this:
: I4 A7 S7 n' X4 v/ m
% `- W' B( K4 S% r( {   BPX exec_int if ax==68
: @! i7 o6 o- l& w' M   (function called is located at byte ptr [ebp+1Dh] and client eip is  v# K& g. i7 L1 I5 O# @! h$ A
   located at [ebp+48h] for 32Bit apps)
0 r; N% v0 S+ {' P/ n* t__________________________________________________________________________4 W; _. g, w5 {1 z3 M$ f% L- }& y
, N# P3 R9 b: [" v; B$ [: |2 M
  F- J% `. ?" ]& j4 Y* H2 u
Method 08) D) w3 t3 |6 A  ?) L
=========+ _: K2 C0 g) Q' c! J/ ~

+ W* E4 q* X+ s! I  ?It is not a method of detection of SoftICE but a possibility to crash the
) U' i$ Z  Z, C; y4 I6 e! p$ @system by intercepting int 01h and int 03h and redirecting them to another
8 d  x6 J  A1 Mroutine.1 K- L+ w# j% @1 X! l
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points* ?! y. C: y1 B& J  d% C
to the new routine to execute (hangs computer...)
9 b2 s  H6 s; H
  t$ \# ?% w6 V$ k. s' D/ S0 {    mov     ah, 25h3 \" }" y  P; f' {* E" G$ ^
    mov     al, Int_Number (01h or 03h)& v9 ^6 C- Y, Z5 Q! O, T) P# X: t
    mov     dx, offset New_Int_Routine
2 K, d+ l3 M3 a" G: k4 f. I    int     21h
) R. }! C. M0 N6 n- Q3 f: I7 m( Y# m
__________________________________________________________________________
; e& c  A7 [8 M4 t# j( E- r# F0 U
Method 09
. v3 l8 y4 R1 V/ S, @: F=========
& ?' Y: Z7 k2 x) F- W$ ]" ]! \# s  c# G* i- }) L) ]
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
7 ]% w; N/ c1 k3 d. f) X0 eperformed in ring0 (VxD or a ring3 app using the VxdCall).
. \, P5 z+ L- c5 _7 Z0 cThe Get_DDB service is used to determine whether or not a VxD is installed, j1 M- D3 B& p- s) S# y/ x1 b
for the specified device and returns a Device Description Block (in ecx) for1 d5 p5 z9 g- R# D- i2 v
that device if it is installed./ f3 s! g) m- F
$ E5 s+ o- m# B7 y+ M2 L6 F
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
, |" L( s* h) m0 c$ ^& i   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)4 _" W* k8 h, j( D
   VMMCall Get_DDB
! F" K- V7 ~7 X5 ]6 Z  E   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
0 r3 b1 ?; n  |, Q2 w2 T# W5 n. `( H
Note as well that you can easily detect this method with SoftICE:
+ r/ \  |. b$ D$ x/ r5 d   bpx Get_DDB if ax==0202 || ax==7a5fh
3 k: y+ r9 C. t( n9 y2 Z  B& `9 W( P& {% D( Y: |
__________________________________________________________________________
+ C$ h" r1 f7 E  i  A$ C+ b  U7 t% T' b; r! g; _
Method 101 _9 L* H. T0 _+ W
=========
# C+ j/ G1 x4 t1 \* ~/ p' l8 {* @9 D4 ~& q
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with* g1 ~; F0 `) l! _  T- R% k
  SoftICE while the option is enable!!/ ~' u) a) A) z& p# k( V2 J

& p$ M8 u: m) }; ]. a" AThis trick is very efficient:
' w' D% q$ S+ \, q$ @' U0 }by checking the Debug Registers, you can detect if SoftICE is loaded5 z% i" D. {. D  `3 X  B& W" `7 M
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
* a# M" [  O, O6 ^" j' Kthere are some memory breakpoints set (dr0 to dr3) simply by reading their- T8 t* A+ U7 L  D
value (in ring0 only). Values can be manipulated and or changed as well
9 v& V9 }  n# q. k(clearing BPMs for instance)
# V" X8 S2 S  L7 R
! b) j& L( P! i# W# B5 v! V__________________________________________________________________________
4 c+ [$ f% ?+ q6 n* M9 S  B4 |- k% S0 \  n% S6 f' n; c
Method 111 z( ~; o3 ~$ c
=========$ _/ m$ m' h/ q: B+ U+ ?" F
  G7 F9 @4 Z+ u- C0 S3 w" C
This method is most known as 'MeltICE' because it has been freely distributed
- R( Y, r0 A5 D9 a: ]& U+ A8 @9 `via www.winfiles.com. However it was first used by NuMega people to allow$ t! n1 C% i( F. X" Y
Symbol Loader to check if SoftICE was active or not (the code is located$ \- S( `. R5 ^: O2 h  q9 v- S
inside nmtrans.dll).4 E6 s, @$ _# `6 a+ B; F
' ?$ P+ |& |. W$ L& V
The way it works is very simple:
9 `& v1 [- Z, i% v2 X  zIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
- k4 @/ o4 Q) u! G6 _7 Z  A# LWinNT) with the CreateFileA API.; E' _' e% N% b# i/ y$ t6 ^

" N6 R2 a( X  I, x/ j0 QHere is a sample (checking for 'SICE'):3 h& l  y6 H4 ]7 M  t

; ]$ I' J0 k! GBOOL IsSoftIce95Loaded()2 D' U, \8 z0 r6 G; f
{
2 [' _; S" K3 f6 q+ z   HANDLE hFile;  4 R1 @) F3 _0 T3 f
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
, F2 ]2 R7 q8 N) L                      FILE_SHARE_READ | FILE_SHARE_WRITE,8 d  a1 N9 O. u# _  Z7 _
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);4 L7 @' F, S0 C9 n* R! A- ~7 c
   if( hFile != INVALID_HANDLE_VALUE )6 \2 Z! `. \% @7 L+ j0 v
   {
& T, `( n) F- E7 S1 H1 f) N" @      CloseHandle(hFile);8 s! D3 `8 s( a; B' G5 @" k3 z
      return TRUE;
; I9 m- j" j2 f8 [+ k   }
  X- Z9 g8 ~2 ^3 f$ T3 s   return FALSE;
9 x3 N; ?; h0 v: }9 y}: Z3 \6 [- R9 e, P: |7 x
: l: u4 `2 [. X  Q" z
Although this trick calls the CreateFileA function, don't even expect to be
" f5 U4 |2 x1 \3 ~2 dable to intercept it by installing a IFS hook: it will not work, no way!
5 q" B% B9 j$ ?: X3 }6 _In fact, after the call to CreateFileA it will get through VWIN32 0x001F4 F- I5 S' x4 R8 ^
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
& o8 O) b; f9 P4 |and then browse the DDB list until it find the VxD and its DDB_Control_Proc- w- @4 t  P9 P1 z, M' h3 B" m
field." ^& D& y1 z' [4 H6 p& I
In fact, its purpose is not to load/unload VxDs but only to send a : t1 w  S" A! C3 d3 h" ]: N
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
, y$ Q* @4 Z$ p6 u8 tto the VxD Control_Dispatch proc (how the hell a shareware soft could try2 j+ p  V4 D8 O, Z6 f
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
/ c# K% s7 O4 z1 }6 ZIf the VxD is loaded, it will always clear eax and the Carry flag to allow% h+ t) y* V' j" E
its handle to be opened and then, will be detected.7 y. y$ Z" x" S* Y; P, j2 |
You can check that simply by hooking Winice.exe control proc entry point
; q$ Q& @4 K# I, w( B9 n3 rwhile running MeltICE.
3 H$ w8 l8 k" X' p$ Q, T# `" N0 P" Y' `: B3 y

" M6 z5 K* M$ \7 R- o' H$ y  00401067:  push      00402025    ; \\.\SICE
' N' z7 H4 i. S  0040106C:  call      CreateFileA
; T$ |3 v5 r" H5 t  00401071:  cmp       eax,-001
- ~4 ^- H, s$ A$ }; f% }( \! B  00401074:  je        00401091+ l9 `. O; N' ~7 @0 W

% B2 G- `/ j1 e' m1 |0 o8 e  V/ D
There could be hundreds of BPX you could use to detect this trick.
+ I: ~+ n  d* `$ O0 t& d-The most classical one is:+ L; d2 e+ m5 a! N; J* i: k8 d
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
* `" l" n# Z$ U- w5 p    *(esp-&gt;4+4)=='NTIC'
5 V1 ~: O/ z- u, j8 T
( n1 t1 x; @, R0 g-The most exotic ones (could be very slooooow :-(' I1 `9 V+ a6 C5 a- Y
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  , n% s, _9 E, T0 M. j1 B+ K: [
     ;will break 3 times :-(6 ?4 |4 I7 Y5 l
3 `8 I3 V0 }8 g" m& F7 p% m1 f
-or (a bit) faster: ( {4 `7 w; H2 b9 ]% V0 i
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')$ f6 k4 B* ^% C

  X4 F8 K( l, {5 |& D% s" ]   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  . y$ C3 |7 e; P4 E* ~$ G% \& N
     ;will break 3 times :-(- X( T/ \( e' \6 R
) X/ Z, G- `. W
-Much faster:, Y  ^. l1 l% ]" u! Y
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
  N" N& A4 p- r3 B8 U* c
( T4 V8 G" q! @' X3 nNote also that some programs (like AZPR3.00) use de old 16-bit _lopen4 }. B0 I* W/ L: n" J+ b
function to do the same job:' M4 ]& K  a& f4 P/ k7 z

, M1 e" M- x  Z2 n9 ?3 _   push    00                        ; OF_READ
4 s! _% v; K! u   mov     eax,[00656634]            ; '\\.\SICE',0
$ C# u6 f8 a: {$ X$ k   push    eax3 _2 ^  P% S, n: v& S) N* I
   call    KERNEL32!_lopen) [  W- a& `' L6 u9 R$ @5 C
   inc     eax
' S4 I% s1 y: [% N+ J% ^" L( ?   jnz     00650589                  ; detected% M6 B" _* n. F" k0 b
   push    00                        ; OF_READ  h( b. f* b( u, i
   mov     eax,[00656638]            ; '\\.\SICE'
& Z6 }; a$ P& k( @& d% h. ]   push    eax
& c1 p. C( S! ~- a1 a3 e' G: V   call    KERNEL32!_lopen
& c1 s% S' @" j7 o3 \0 H   inc     eax
% J: T$ d9 C0 \9 m$ V4 a   jz      006505ae                  ; not detected  T1 H: [- N6 f! t/ i

5 v; S+ N. ^0 ?% j$ z! F! H% @$ v. H$ ^* O
__________________________________________________________________________. S; C& I* L9 y3 a1 F0 N

6 |* B1 J# x4 x4 U* l! GMethod 12% v  l! {/ ^, m
=========- C0 H5 V+ a* n& ?" D" c6 z

, ^' [% Y2 k- D; L3 w, N' PThis trick is similar to int41h/4fh Debugger installation check (code 05$ E8 |, ~' K# R2 n' U( L# m7 ~
&amp; 06) but very limited because it's only available for Win95/98 (not NT)$ X% b$ u4 P& i3 \$ k1 L8 a* F
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
( t' v  `4 q7 S+ m# A. G( x  p" Y+ y; O+ }7 t9 E! c$ N
   push  0000004fh         ; function 4fh
6 r. f( ~4 _: H% Z3 h   push  002a002ah         ; high word specifies which VxD (VWIN32)
1 n: I& [6 E2 l5 E# Z6 o9 v) V                           ; low word specifies which service
- x0 P8 v2 r9 X1 P6 [5 _0 n4 F' a5 f2 t                             (VWIN32_Int41Dispatch)
" H1 M+ E0 |1 W8 N   call  Kernel32!ORD_001  ; VxdCall
% y5 A- W6 \* O: q" y' q   cmp   ax, 0f386h        ; magic number returned by system debuggers. V; V: I! z) L8 o  u4 R9 z1 d' e
   jz    SoftICE_detected% v5 @/ h" T" I& K( ?7 w. K" S) I
9 i0 p; ]$ U6 E  Q
Here again, several ways to detect it:
3 N. t: h: i3 m4 w4 b+ _$ Q+ {% I( Q4 x6 X* U3 V; i
    BPINT 41 if ax==4f. M! m6 z" \, h3 C

; x' j7 e3 u) `2 A) E    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one% @) q- ~  E* o& G9 G4 n
: q6 s; B' p6 S: k% n  l' g7 e
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
* \9 G# R4 _+ S2 S3 F. E. V2 Q9 ?' p6 Q  W5 B: d& |, V/ T! a8 {
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
# A# r5 H( @3 I+ Z1 @0 k/ n) h. S- b7 D- }
__________________________________________________________________________# q; u8 b  u. L

. u" `" {6 M& t, {5 JMethod 13
. c, o9 j  t- U1 ]- @: s0 J=========
! i, f. J. c4 P( C- h" Z
  \# ^! ?1 e5 b0 E, l6 ?Not a real method of detection, but a good way to know if SoftICE is
$ h4 C) m# m0 m; \/ e: Tinstalled on a computer and to locate its installation directory.; L9 H5 I0 C" p# ~! R
It is used by few softs which access the following registry keys (usually #2) :4 M: u' g2 I+ i( x. q0 r. k6 U% @

( y, l  p9 t. U! k0 z-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion3 Z/ n1 l" Q4 @* C  j3 l
\Uninstall\SoftICE# t' {4 y; g7 }" ^1 ^# m
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
9 }( O4 {2 U6 p+ z% v  E-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion& C+ e3 z% u+ ^: N( v# M
\App Paths\Loader32.Exe
! o3 W" @8 f2 A9 C: i, ?8 M/ R: a- i( V

6 t5 d9 P% i2 p+ `# V; KNote that some nasty apps could then erase all files from SoftICE directory
' F% }9 l- q# J5 |( h1 X/ ?: P(I faced that once :-(
8 a1 U9 F* Z/ c4 |  B' E/ p
$ Q3 R  K# ?! x) |* T/ NUseful breakpoint to detect it:) y' q; p' l6 }: w" k1 e

, ~- u3 y& d' S* k- B     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
5 q$ Y! r" \* Z
, J2 j* E$ P2 g7 t: C7 Y9 m, r__________________________________________________________________________  @7 s0 @7 M- B& f+ Y' L
/ r6 @$ o9 t3 P( l* @1 [: P" h
1 D; u5 k; u9 l. Q2 M$ s" @' \
Method 14 $ A$ B3 E5 J$ ^' B
=========
8 m4 Q! T& F: z2 \! m6 U6 `9 n) D
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose+ m& X9 q! v3 y" D
is to determines whether a debugger is running on your system (ring0 only)./ U$ j, g6 t* s+ |
% K; O4 W2 S9 z5 N) d; k, A
   VMMCall Test_Debug_Installed- I$ A2 T/ }" l1 \6 j' v. N
   je      not_installed
. [$ P5 b4 P* v+ u+ K
( D$ V- m" h  D5 @This service just checks a flag.
0 z+ v% J! V! _3 U, [0 \/ a</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部