About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>. D* _. `" C) |0 ~9 K# e- ^! M. T- a
<TBODY>
3 K! c3 k: d; n% h7 k<TR>
+ @, |2 B8 L" r. n<TD><PRE>Method 01 & h5 Y. Z5 Y' c
=========
  C( Q! k2 w% E& ?% P# t0 O9 E9 q1 f+ e& ]- Z/ D$ d/ j
This method of detection of SoftICE (as well as the following one) is
! a7 v5 v& x8 G, O- D5 gused by the majority of packers/encryptors found on Internet.
/ }1 ^9 _) _, l3 M, c+ C0 DIt seeks the signature of BoundsChecker in SoftICE
" R. u5 H4 Y+ c5 s) E  m* J# g  V5 S' i& |
    mov     ebp, 04243484Bh        ; 'BCHK'1 m; i5 I% [+ j; i
    mov     ax, 04h
" f: n4 d9 a% ]    int     3      
4 J# t7 H$ y# ^* J& ?    cmp     al,4
2 j' M. F# F- B* {    jnz     SoftICE_Detected
0 a3 A6 N8 P! k  L1 t% f
$ q  H. _! o. C% {( x( o1 i___________________________________________________________________________  ?* a) ]& z8 W) D; T) q3 r- S
5 D  b5 F& C& ^
Method 02- p- `5 t% O% C0 e1 |3 Q% x
=========$ B7 l; H; y* X6 T) x: x
3 L1 r, u6 }0 a) {* C
Still a method very much used (perhaps the most frequent one).  It is used; q8 e( p; v/ a( I3 A
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,+ ~# ?3 H, L: @# b2 {3 A% J
or execute SoftICE commands...
) p! x1 Z& i& e9 E# _4 s! KIt is also used to crash SoftICE and to force it to execute any commands. l# x: D1 h) k# Z- c% b1 [7 `0 R% d
(HBOOT...) :-((  4 J$ ~8 ], B& P7 U
8 g) {! h" [! }  @4 @. ~0 Y+ z. Y
Here is a quick description:
4 K7 G4 u! r+ j# W/ d% O) Z$ Z-AX = 0910h   (Display string in SIce windows)6 f2 f' h' q# ?. B! s. O
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
2 b0 ~1 f) X; X) F-AX = 0912h   (Get breakpoint infos)
( ]0 i4 T1 R* n- V4 J, Y+ J-AX = 0913h   (Set Sice breakpoints)
+ d$ b( V' E6 F-AX = 0914h   (Remove SIce breakoints)
& Q; V9 T* n0 s% q- i) L- D+ ~& Z7 ~1 @4 [
Each time you'll meet this trick, you'll see:( g/ T4 W+ X3 R  z) [$ b/ }
-SI = 4647h
' C/ g2 @2 E& j7 J4 q) ]-DI = 4A4Dh
! Y1 h9 w  E( P$ F9 K: B3 bWhich are the 'magic values' used by SoftIce.3 s$ O" c* [/ {# q8 E# A9 |" |
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
( T& k) k/ u0 F  r/ N4 [6 V
- u% @, l0 ~1 F7 N7 RHere is one example from the file "Haspinst.exe" which is the dongle HASP6 \6 u' O# r8 |+ H
Envelope utility use to protect DOS applications:
- S! U  }8 f9 F% Z- D4 l* R+ p, g" s  [# l9 Q3 J( J& t
* M2 F; [5 R6 i& {+ X- h4 p
4C19:0095   MOV    AX,0911  ; execute command.
# B) _# _2 ~: j7 d/ r8 v4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).* u; @- ~1 _$ W( n) D$ C) W! ?5 D
4C19:009A   MOV    SI,4647  ; 1st magic value.  d7 a8 h% J2 f" q* l' E) Z
4C19:009D   MOV    DI,4A4D  ; 2nd magic value.) b! c* f/ U5 h$ K
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
' l. v% [$ m8 Y* i- t4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
* [2 e' g" M8 c- B0 A  ]4C19:00A4   INC    CX
: x6 n. ~) C/ N- e/ }  F) D4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
; E+ n+ e% ]5 S  G! E4C19:00A8   JB     0095     ; 6 different commands.% G  ~% q6 Y! J/ T' _) ^
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.. F* l, l. J' `; t/ x6 l$ `+ v
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
1 h3 t0 e- d4 J' c  s5 {, v
" C6 E% R* h+ G0 aThe program will execute 6 different SIce commands located at ds:dx, which( {0 s/ W9 W: M/ _7 O: f$ l7 M" c
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.' L, Y" I( \3 P
# v" [! Z% X8 c* U3 n2 l+ Y# J7 U
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
8 K. x+ [' d5 s___________________________________________________________________________
# q+ n; p* E4 R) f$ l
. L4 S! o3 T- s+ u3 }$ _
/ R5 \* v" I% C. _! b- XMethod 03
. _  ~1 U& B+ e3 w) o2 S2 C=========
1 P! i& L% v1 P! W5 h
& A" J6 N9 E4 a! N' OLess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
' H; ~9 T5 k( v# x0 b: X0 A(API Get entry point)
4 U# M9 M% b- H' }* n0 k% s$ r        * \# r; o5 k* b. x2 X6 E2 y5 ?1 @. J
7 b; {+ v" D) U, _2 n
    xor     di,di
, o# m% \: e- B2 }  b    mov     es,di
; O+ G7 l/ u6 Z$ k0 l    mov     ax, 1684h       # r9 X# O$ u8 h% Q4 X3 P+ A
    mov     bx, 0202h       ; VxD ID of winice; I" {, l% O) q6 U0 ]4 X
    int     2Fh* X' m1 k3 _8 _, q
    mov     ax, es          ; ES:DI -&gt; VxD API entry point7 j4 ~  G5 M$ Q% \
    add     ax, di
2 M: \9 u$ Q, ~    test    ax,ax
5 E6 [9 u/ ]9 l5 b! U    jnz     SoftICE_Detected
+ m8 O9 V1 u' z/ I, d: m4 z- b% j9 y' l# A! v: g* P+ D
___________________________________________________________________________; j. C% S% Q$ y) {) x0 u

3 }2 C! |" B7 b+ P$ sMethod 04
* u+ p- E# Z( q, w) z8 j  Q=========. X1 E& X/ v3 t; n2 o
8 \/ `0 g. N3 Q+ J
Method identical to the preceding one except that it seeks the ID of SoftICE
9 o  g7 u4 v) u& Y  L$ P0 _9 nGFX VxD.
, U0 o2 T% \4 M5 C* J- W) ~3 ?( k
    xor     di,di6 m3 u1 ?1 s5 q) H2 G6 G) i
    mov     es,di
9 F2 P/ x$ m2 P. B- N1 P# B    mov     ax, 1684h      
( j/ H4 M' k! o6 m% e0 l# k    mov     bx, 7a5Fh       ; VxD ID of SIWVID
0 D; \( l) K. z" s$ p3 D/ c0 z    int     2fh* ^' ^* _2 g. a* h: \
    mov     ax, es          ; ES:DI -&gt; VxD API entry point0 t5 p1 M4 c$ e* }+ J
    add     ax, di, `4 E. w$ u4 O! d% X
    test    ax,ax- N' Z9 l/ W% U* M6 t8 r6 v. j0 s% h
    jnz     SoftICE_Detected
% H- D) v9 ^) P# N% L
7 Y/ ^' a, f7 R* h9 ~7 D__________________________________________________________________________" e7 |* N" ^0 K8 _1 c) a

! X$ ^) w" g0 M
6 P0 t, ~3 j3 u* Q5 G2 wMethod 055 n' S; Y- h( ^8 n* W2 q+ S
=========
: C9 x7 l! `# o; d
. l; ^, I# n' x! rMethod seeking the 'magic number' 0F386h returned (in ax) by all system- G" X# I7 q8 o3 R  L. R
debugger. It calls the int 41h, function 4Fh.- s! B5 z+ @( g3 `# D
There are several alternatives.  # m8 _6 M; `* E

) ]; W- p5 ~5 L$ T$ `The following one is the simplest:/ v3 q& `0 i/ s! y. H" `' j6 T
; `! x  B  j4 l: z- U/ g8 w. `6 ^# v
    mov     ax,4fh
; u( R$ ?+ d. I, f  v) m: T8 P2 c& B    int     41h: ?" j6 c2 J( v
    cmp     ax, 0F386
% @4 o0 x# H9 @% P9 I/ B2 h    jz      SoftICE_detected
/ b6 k  M4 a1 D5 d$ d& U, t) Q! B5 m

* p  {$ P" w) G- l, o. eNext method as well as the following one are 2 examples from Stone's
7 g+ V6 M% j: c5 V0 k2 Y"stn-wid.zip" (www.cracking.net):9 b# A8 P: O2 y; ~

7 T/ l. Y4 q2 B0 j" |    mov     bx, cs
6 |/ O. a! [- b    lea     dx, int41handler22 Z- u* [) ^4 Y8 a' a: Z7 p$ V& K% F
    xchg    dx, es:[41h*4]
. j" l1 l) {5 Q8 t1 S    xchg    bx, es:[41h*4+2]* C' Z9 ~  [( O- _
    mov     ax,4fh+ c: Y/ v7 R& u
    int     41h
% p) S2 m* Z: t& ?( l    xchg    dx, es:[41h*4]# O- M7 z2 k- i) K/ Q# i
    xchg    bx, es:[41h*4+2]! u. E' @3 ?( }9 D, m
    cmp     ax, 0f386h
3 p- N" y* H8 c8 }! z/ |    jz      SoftICE_detected$ t3 `8 V- L4 d# B
. y, q0 B, `& ?8 ]! T$ @! M
int41handler2 PROC
6 U9 F- ]( w0 B7 e0 _7 v) @    iret
5 C( S) z" D' `4 ^int41handler2 ENDP( h4 i, @+ W, t# R5 y8 _, s! P
4 w  Q4 `+ E7 E% i

0 S. f8 m1 a1 V. ^+ o6 [6 j_________________________________________________________________________
  i, `" n4 _$ Z4 U% P$ D( U% @% D& Q4 H, O* u+ ?

% t" O2 _8 `7 K& s) u; WMethod 06* y8 n5 R  u$ X5 i  {  _, Y
=========0 i6 V5 {- h0 s5 Q1 }# ]
7 S) i! A7 W; Y$ `  \
+ \- {; ^. L2 r3 t
2nd method similar to the preceding one but more difficult to detect:) q: ]. `' G" x: F1 K, G! ~/ H

- v. q' u* F6 y; W) z+ L0 b* d) V
$ a7 ~5 v. X" W3 Yint41handler PROC  [* [, W5 f3 I8 Y
    mov     cl,al4 {1 b% V( O( n$ P8 F, N4 K
    iret% g4 [' k5 h/ F% G
int41handler ENDP
8 [3 B: s8 x# x. V9 R$ s
  ]1 i4 j+ O) y, y" i) k. S: p
! r8 Y- c6 v) S/ w( h: `9 B    xor     ax,ax
! g& Q8 O' D3 R% U3 A    mov     es,ax
/ h/ {+ ^( n2 A% W" U9 z    mov     bx, cs6 I: D$ u9 N' J# ~1 {2 P8 y# D
    lea     dx, int41handler
7 n+ `( _) a- D; E# L! R; O    xchg    dx, es:[41h*4]
7 y6 t( M. f" \    xchg    bx, es:[41h*4+2]& \, }# Q) r5 n7 D* R+ r
    in      al, 40h' @3 ?! u) x( ]0 d9 f' M3 M$ d, I& q
    xor     cx,cx
- Z/ _1 T& E* M9 u! H0 ?    int     41h9 T8 L' |  E- z
    xchg    dx, es:[41h*4]$ N9 X9 }' p, k/ o& t7 B
    xchg    bx, es:[41h*4+2]! U4 Q" o, m/ U0 G! `
    cmp     cl,al1 \4 d7 t- H6 k5 f8 T/ v. Z$ E
    jnz     SoftICE_detected
# d% T& q7 c' p: D) S" n* W- t1 k1 [* U
_________________________________________________________________________( O5 r2 c3 c5 @6 n
( M" U! F) m' D7 {& i# r! f
Method 07
% L! B2 f6 B3 Y6 C+ C=========
  q* X) k9 x9 C5 o9 t$ n% h0 c% h+ b/ F
6 @8 I0 U9 R9 h9 ^, tMethod of detection of the WinICE handler in the int68h (V86)
4 J; X4 j5 ?- F4 x" ?* V
- H! r4 K$ L% q# N+ r% v    mov     ah,43h) P, c1 p. L" `; i4 A
    int     68h
6 q) @# |! v" M1 p9 {* _    cmp     ax,0F386h
& z( w) d4 b+ b. }$ X    jz      SoftICE_Detected0 F2 {/ n+ m1 n& _$ \
0 p: P: |& d. \: Q  a" V6 v

8 o. V; g0 h2 L' w, W# m7 w& t=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit+ O" q3 h' Z9 @0 Z, Y
   app like this:1 E7 ]) D" E+ [/ l

! Z- ^  b" i, z% P: R  I3 Y% J; ?" _   BPX exec_int if ax==68
: u* w$ O: q3 _+ @4 B1 E3 _   (function called is located at byte ptr [ebp+1Dh] and client eip is7 r" |' q" H* v5 C
   located at [ebp+48h] for 32Bit apps)
4 e! T' F0 F9 i0 N* I* }__________________________________________________________________________, g9 U, C$ q& @3 t4 }3 i2 d

* Z5 P; v% k0 t9 C2 |
) i& w0 @0 d2 T, m% N, U  D4 ZMethod 08$ H, I( t; f/ P
=========
& S6 _' u, V7 v2 D
4 u3 G+ V' p. NIt is not a method of detection of SoftICE but a possibility to crash the1 g! n8 X7 k' b7 B2 Y+ O9 R
system by intercepting int 01h and int 03h and redirecting them to another3 S: P! ]: `( ^4 x: W& _
routine.
; H! Q! y  d* D; ?It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points. k0 `; w# W& I( R2 Q/ P
to the new routine to execute (hangs computer...)6 R  e. E& |7 |
  w- c% V: ^5 t" R9 v
    mov     ah, 25h
6 Q2 @) v& y" d8 Z9 F1 c    mov     al, Int_Number (01h or 03h)
) b; z' M& C* A; k( ?    mov     dx, offset New_Int_Routine: ~  y& g2 F2 `  B
    int     21h+ ~  E5 W' B. U6 s$ t

, n3 \, t2 T7 f+ t; z. Q5 I__________________________________________________________________________
6 e9 J/ o& f) G$ Y6 {7 x" j7 i% i% ^% g3 g% B1 N& q4 ?# O) a7 t0 g
Method 09/ {" H) \9 p7 n$ b/ m* }! S+ W& q
=========& q! b1 p6 q2 u" L& q

3 p( h1 G# a7 q) TThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
8 Q6 b! \# p9 j' B  nperformed in ring0 (VxD or a ring3 app using the VxdCall).  i1 d5 [. t* N* A6 _4 S; `
The Get_DDB service is used to determine whether or not a VxD is installed( I/ S) T4 L" y+ o, U
for the specified device and returns a Device Description Block (in ecx) for
; F4 S: ~' r( K/ Pthat device if it is installed.
, Q& i2 h/ _8 V* `7 H
$ V1 w5 G! c2 s0 \3 u   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
1 S9 p+ Q% q1 O: K6 p   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
# {, ?. k+ f, {   VMMCall Get_DDB
* G  {8 ~: p) Q, v0 W   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed* S, x/ f6 Q2 p. E5 ^5 D* K

* b8 j5 J. }5 ^/ ~) ?  H4 QNote as well that you can easily detect this method with SoftICE:
7 x" Z1 L6 C/ ^( }2 @3 H   bpx Get_DDB if ax==0202 || ax==7a5fh9 i" s* k  e3 o8 o( J

- B' Z. Q& w( K__________________________________________________________________________
% \) h% s7 p& y( U& T$ N, y( E, T" f" }) \* D( l
Method 10
! c5 ~$ Z. A( ~9 x=========
1 K/ c2 @; C) M8 z4 @, i' q& s/ q% _
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with+ c+ K" f2 @, y
  SoftICE while the option is enable!!( k  ^5 r! U9 ]# g7 x" U5 }
! i) |, I& I7 f/ i
This trick is very efficient:4 [3 k6 r4 p! O! `# A
by checking the Debug Registers, you can detect if SoftICE is loaded
! O, d; r) N- x  B; \  i(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
6 z! T* r; a7 |2 i4 B, Ethere are some memory breakpoints set (dr0 to dr3) simply by reading their( z' z# B; C" I% L! @' }7 n7 k
value (in ring0 only). Values can be manipulated and or changed as well6 w3 U' L6 V+ h) G
(clearing BPMs for instance)6 [# }' H- ]- K3 b+ M

& n: @' B& I3 a# |! Y__________________________________________________________________________
. [2 y* J8 H& O5 E% p+ r7 z; q+ \+ }% a3 P7 ~" i
Method 113 U. x$ d0 a1 w5 k- a! d
=========% v6 ~. x6 k3 J: z: T) `
8 ]0 K" T+ v  {
This method is most known as 'MeltICE' because it has been freely distributed( K7 O- S) Z. }+ e
via www.winfiles.com. However it was first used by NuMega people to allow
: H( [7 T% M+ F/ b1 mSymbol Loader to check if SoftICE was active or not (the code is located9 c9 H& V. J) B+ R0 K- E7 `7 B* v
inside nmtrans.dll).
  }) b+ q& h$ j) h/ a5 `1 H. S% E! \6 [
The way it works is very simple:# s/ ^7 z0 w9 Q( d* @. y
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for# f" Z' @& Q5 E
WinNT) with the CreateFileA API.
) z/ @$ {- z: p* v8 O. t; X1 S6 a* D! Z. y
Here is a sample (checking for 'SICE'):& i  @. u3 q8 }8 M% N( y
  E/ F/ v5 t' ~* t; w
BOOL IsSoftIce95Loaded()7 C, M* [7 ]  v1 w
{5 C8 [2 f6 c9 T7 r3 q
   HANDLE hFile;  : h- P0 h& ?( q
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,+ R9 ~2 I0 k# T+ ~$ u0 z
                      FILE_SHARE_READ | FILE_SHARE_WRITE,
7 \+ a! M2 ~5 T3 Z3 V6 G: u                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);1 g2 ?, {& Z3 v1 w/ a! O7 c
   if( hFile != INVALID_HANDLE_VALUE )
! d. H- X* B' X( `0 e8 s/ V3 s   {
! e7 T# j9 N1 e$ D* ?6 o      CloseHandle(hFile);% @5 C+ j1 U, |' ]0 `1 _
      return TRUE;$ c, w; e; t$ {+ J+ H
   }
$ F  r5 s' u0 |5 }   return FALSE;. ~3 n4 b) R" v3 O
}
9 M, h- Q( d' N  s/ S9 z
1 ]; i. }! d( I& TAlthough this trick calls the CreateFileA function, don't even expect to be
) P# [" a4 F, u+ n2 y/ t0 N- ?able to intercept it by installing a IFS hook: it will not work, no way!; Q. T8 z2 Q* G9 ?0 f8 d
In fact, after the call to CreateFileA it will get through VWIN32 0x001F$ x3 n4 l; A  }( o+ @8 S
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
: |: ]! _7 Q$ C( X! C: Y6 f! {, oand then browse the DDB list until it find the VxD and its DDB_Control_Proc
; M1 R1 D; P7 r' Wfield.
( @8 G& z3 d' a9 Z! a) b1 \4 MIn fact, its purpose is not to load/unload VxDs but only to send a & z& Z; E0 g4 f
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)! y7 j& q9 x) ~! x# t/ a
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
4 G* l% m1 [6 t# W2 S* zto load/unload a non-dynamically loadable driver such as SoftICE ;-).! \5 i. u+ K$ j! a  z1 j; C
If the VxD is loaded, it will always clear eax and the Carry flag to allow. B0 u' w5 g* F$ h+ B
its handle to be opened and then, will be detected.
% N/ i7 j$ A* x" i: ]You can check that simply by hooking Winice.exe control proc entry point
' I& }1 d9 X7 l4 lwhile running MeltICE.1 t0 V$ R: ]1 x0 ~5 L$ [, Z1 @

( Q, ~- h1 k/ L, r( ^/ P' y) k/ h- M+ T0 k$ A8 l
  00401067:  push      00402025    ; \\.\SICE
- U% Z2 B; Z0 g7 J4 \  0040106C:  call      CreateFileA8 g- g, L( M4 m# F4 Q+ E
  00401071:  cmp       eax,-001
0 L1 d; Q& E7 y- C$ U6 B  00401074:  je        00401091( A' C3 D4 k' F& T' P5 ]8 T
  G/ B$ {) O7 g# H
+ ^4 y2 E% a( ^
There could be hundreds of BPX you could use to detect this trick.
+ \9 T' a/ t* C1 |0 f, N2 s-The most classical one is:
: Z+ a1 C6 {9 o: O$ C6 E  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
8 O1 x& C% T( U  r6 H    *(esp-&gt;4+4)=='NTIC'
( v2 ~8 W6 n& t! q- i
: e8 W, Z1 j2 t$ d-The most exotic ones (could be very slooooow :-(" E! D* }, h; m6 _/ L, V- U
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  : n) y7 A5 g+ t8 B+ a
     ;will break 3 times :-(5 z! G0 j) T- D, I( r& h$ q

9 {) S6 _3 m. Y) J5 @5 x) c4 Z! ^9 p-or (a bit) faster: 9 C. i; i: p- F& o0 C
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
8 k* l( k9 B8 u% o% b9 d" u0 W. n  a& w- ?  s9 s- d
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
7 i5 q% l0 ^5 U% b( [  P     ;will break 3 times :-(
6 b* W# t+ Q" A$ P
/ E( g- {4 {) r3 k7 Y-Much faster:9 z8 h# Y, ^- u1 K
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'. x( l! m4 ?$ ]" o# q0 h

7 L3 P2 J2 t! s* S4 }5 nNote also that some programs (like AZPR3.00) use de old 16-bit _lopen
" g% ]  w# R4 i! J/ Yfunction to do the same job:3 D5 I7 I8 k' |- e* \3 O

  Q% Q* G4 ?' D# X   push    00                        ; OF_READ7 T7 A8 [' q$ W% e& z9 l
   mov     eax,[00656634]            ; '\\.\SICE',0
% i/ q/ B. P0 b5 o( I2 B; x3 i   push    eax! [7 I0 O. K2 [# t/ b! t0 {5 p1 t
   call    KERNEL32!_lopen
2 e/ E- {8 Z! S* o1 c   inc     eax0 ?* U4 P+ v0 \, Q, l1 A. Y
   jnz     00650589                  ; detected
: Y7 N' Y  H7 W! k) [4 w) Z  y   push    00                        ; OF_READ
/ t- Z# N: m6 S   mov     eax,[00656638]            ; '\\.\SICE'1 Y. a. V. C" [/ J. i
   push    eax
5 j4 ~) E/ K; @* g" y. R   call    KERNEL32!_lopen
& q4 J6 i( x7 J   inc     eax
. I) U  J6 @/ \4 B/ W   jz      006505ae                  ; not detected. M# l- ^) e- K7 p% S

7 c5 o+ |) f+ Q. J9 H5 W7 `! c/ i. j' s4 B- T/ c
__________________________________________________________________________
+ {) U6 _, z# Y5 |8 Z- w& q! N8 j' q5 q$ e: W7 @
Method 12
; A$ ?1 R( S8 A/ a: ~=========" @% m9 P' G5 x: M' F) }
  |9 |( f& F8 n9 [3 T
This trick is similar to int41h/4fh Debugger installation check (code 05" E8 }/ t, Z, R+ E0 k; x
&amp; 06) but very limited because it's only available for Win95/98 (not NT)
; k" R- h4 j  [5 g" Fas it uses the VxDCall backdoor. This detection was found in Bleem Demo.
1 h$ d2 X6 p* k0 O/ R# M( l; k$ w3 o  T/ G$ L% z
   push  0000004fh         ; function 4fh: ]0 _- w8 D6 i% W
   push  002a002ah         ; high word specifies which VxD (VWIN32): o7 y& C- Q$ W& T
                           ; low word specifies which service
* x7 [4 P" _/ D                             (VWIN32_Int41Dispatch). P, x1 ?! s  [2 c
   call  Kernel32!ORD_001  ; VxdCall
& [* o8 T" R, s) x0 u& i   cmp   ax, 0f386h        ; magic number returned by system debuggers% q7 w' G' m" G! C& K& M2 k
   jz    SoftICE_detected+ x; B0 H) h( I2 t+ ]

6 ?; H8 @5 B5 v* ~! d# ?Here again, several ways to detect it:
5 n6 S& Z( J2 t% X2 r  G3 q; Y' w9 ^5 I0 l- X. O9 ^
    BPINT 41 if ax==4f# s5 Z+ j/ R! S1 z/ ]1 r: I8 ]
9 z3 B% z3 m) L! B2 f3 S
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one% p) _! V$ W# R3 k7 I

0 w7 Z- R1 o3 P' X8 Q3 G, w( T    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A4 T1 j. p; d2 l$ J+ I6 c2 G' W

- c3 l2 x! @# c5 ^* a7 j; A8 }! h    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
/ k8 X; ]. |0 u- n1 }0 Z% O* w3 S+ z$ D
__________________________________________________________________________! @9 w, P0 {' F& X: t/ x# U

3 K# z. W7 r, r% Y9 y- l8 Y' S/ KMethod 135 ~' N; ?8 a4 ?0 \# x5 l4 K1 c% _" |
=========! E! ]/ r) ^) U0 S5 A
+ ^! V) W$ |: ~$ e. g0 ~
Not a real method of detection, but a good way to know if SoftICE is
' P2 k2 x! p" l! sinstalled on a computer and to locate its installation directory." |/ U3 s4 r/ L/ Z- _9 ]4 d( h" v
It is used by few softs which access the following registry keys (usually #2) :' y4 T4 s8 G0 K% @  P
" s( _2 x# o/ G( `
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion7 t* L1 i; @$ i( @! G: K
\Uninstall\SoftICE
: Q! B3 K$ y* I, N2 h# j-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
- f0 M: B- A2 }6 X$ x( G-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
1 N% t% E' {: S% h\App Paths\Loader32.Exe: F, M9 N: _$ @4 e& e/ r
) G( O. M7 q% \" ]$ `
7 P& H1 w  U8 [1 `
Note that some nasty apps could then erase all files from SoftICE directory; \+ f/ D3 D7 e0 Q$ s: O
(I faced that once :-(
0 y2 l& J0 @3 E0 C6 a* o2 k: P, ?1 v* q3 t( l9 d5 ?, g+ F
Useful breakpoint to detect it:$ d% m+ {8 F  E1 A

0 t# N8 w" U4 A" X     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
' G' q9 C3 D; v/ M6 g$ V* @4 p. L- U- `( F* k
__________________________________________________________________________
! v+ {& R8 H3 v# k6 m8 {% k
$ J6 S0 X1 @) y) E0 m6 P$ v4 j! b; o" z& A- x
Method 14 & Q! I) }& O! u. j2 |
=========8 D  f9 u. e* r
' u* c- E' b6 E2 }* C7 |( K
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose. [" w4 Z) H% N0 G9 z! x7 {
is to determines whether a debugger is running on your system (ring0 only).% r" Y& V& w: {( @
8 s+ L7 x4 N& L
   VMMCall Test_Debug_Installed
  M: |$ F( m( U# u$ j# H& W1 E   je      not_installed3 f- L8 f* z* q2 y. @- x+ f

+ y! m) n; ^# b6 ^7 r7 X+ k" xThis service just checks a flag.
: C1 Q& g( E* y) s) ~</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部