About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
6 A% B, ^) u; ]2 H& `4 j<TBODY>, J8 `& H" E% }) |( {
<TR>
( E* h% C  Z" z# _<TD><PRE>Method 01 8 a9 {7 q6 v3 d' @
=========" T1 i+ E8 A7 L; E3 U# m2 F

7 M6 M. n7 K- q  B, fThis method of detection of SoftICE (as well as the following one) is
+ J+ [' E7 D/ X5 S# L# Z4 C' eused by the majority of packers/encryptors found on Internet.7 ~% M& N# f$ D% ~5 K
It seeks the signature of BoundsChecker in SoftICE
9 Q# q. Y# N% ~) K$ @, I1 O2 W8 R2 x; @
: L- a5 |! O( m& T" T    mov     ebp, 04243484Bh        ; 'BCHK'3 d0 ]6 `6 ~5 l5 I) G8 m
    mov     ax, 04h
& o2 j2 j1 B; e# C    int     3      
4 W! b. X& l- A) t9 I$ ^    cmp     al,4
( @* z  {1 ^& e& n1 H    jnz     SoftICE_Detected
$ k4 ]3 G# L5 e/ s' w) M& ^
/ N+ f' f1 d' }___________________________________________________________________________/ U: G# [* U% p9 z

: Z! c0 R/ d) _8 ~Method 02
9 K! D& P( N) T3 ]: O1 R* S' ~=========
8 _& w& v0 z  ]+ F- P$ n
0 C: A$ x, l. A2 [Still a method very much used (perhaps the most frequent one).  It is used
% i! E+ q) q/ i4 Sto get SoftICE 'Back Door commands' which gives infos on Breakpoints,  }  p" H3 L% S+ H! m% S
or execute SoftICE commands...
8 C* Z: F: z8 M, G/ eIt is also used to crash SoftICE and to force it to execute any commands* o" C  Q+ r$ F. d! F8 @
(HBOOT...) :-((  
( r, W% Z; ^6 M& |  v' X/ t! v' ^$ o" ~" y
Here is a quick description:
) c5 T) v4 e! m7 y( U-AX = 0910h   (Display string in SIce windows)
% z/ I/ e5 p0 B+ r$ L. l& r* ~-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
% ^6 t. J& e& Q# r3 H-AX = 0912h   (Get breakpoint infos)9 P4 z  X0 l% q- \" C* g
-AX = 0913h   (Set Sice breakpoints)
4 V! Z1 g2 V4 Y8 K. q9 t+ u-AX = 0914h   (Remove SIce breakoints)
! x: R1 Q) d5 J) R0 ^2 E9 ^, h* b0 n7 p
Each time you'll meet this trick, you'll see:, P2 u- I0 x" F. z) m7 W
-SI = 4647h
- z0 @4 [: x0 }! J  f-DI = 4A4Dh) \; H; s0 ?' o; B* x7 u
Which are the 'magic values' used by SoftIce./ H/ e7 k& q+ Z3 @% z& l
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.& Q9 J1 t1 q1 B* I
, M# a- ~" @' S& m& V
Here is one example from the file "Haspinst.exe" which is the dongle HASP+ T2 }& w- ]" ]1 l6 x# W0 \
Envelope utility use to protect DOS applications:
1 B; {5 Q  M2 J  F, ^
) \* P, U  ]& K( v8 p* e4 z" k  E+ b' R+ l" X+ N( u
4C19:0095   MOV    AX,0911  ; execute command.* B* y& @! {9 P
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
3 p7 e/ q# \$ G. m) M4C19:009A   MOV    SI,4647  ; 1st magic value.. M6 d/ I4 }/ z
4C19:009D   MOV    DI,4A4D  ; 2nd magic value.! U5 _6 I/ k8 q+ R" M
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
3 A& g7 Z" ~% g  Y+ i4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute9 ?8 q3 E$ n; z4 L3 F& j- n
4C19:00A4   INC    CX3 C: ^) N/ W2 ~  |. I
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute  O3 D4 h7 L- u# G$ B& _6 b+ `7 Z
4C19:00A8   JB     0095     ; 6 different commands.8 R: I) N% c+ U2 h/ E, v# w+ }
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.& A. k4 T" A  M
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)9 n$ }: @! ^8 p
$ `0 s2 _2 I% v" y
The program will execute 6 different SIce commands located at ds:dx, which
' `" P/ V4 ^% ^6 ~; e& x1 Lare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
- l+ n1 H. b! z; z$ t/ b3 F2 [( {& A, V8 M
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
- h6 E: Y5 [# U2 u6 u___________________________________________________________________________
- W( M9 [# y4 }/ S; y2 y. s9 X0 g1 r* F: J( |7 g
, a, u. u2 `3 I! _
Method 032 K5 q7 a2 s# I/ U# Z" C
=========3 h) D: N# N6 l0 k  t. j# B" b$ a
$ W1 ~4 J0 e1 \+ ?" |' `
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
1 V' v% H" k9 ]; }! n3 N(API Get entry point): p& g3 v5 y8 z0 T
        * G7 G% M+ R4 ^5 c
0 a* a8 C# S9 ?* Y, d5 R
    xor     di,di  ?/ \0 p7 e) b. w* r- D
    mov     es,di0 `  v( l/ U+ ?1 t
    mov     ax, 1684h      
5 Q% A1 q. X3 Y# L    mov     bx, 0202h       ; VxD ID of winice- [& L9 q7 l0 H; m
    int     2Fh( D& s) h; T% a
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
+ \  P" C' T; L! M    add     ax, di
. k% ?0 }0 D; W: ^2 M# s! m; a    test    ax,ax. X7 l7 v( Z3 t1 F6 ?3 J* V
    jnz     SoftICE_Detected: [, i# b2 |  d  W7 L( O: V
5 A( |) Y" ~1 J( K$ Z' X1 r9 ^
___________________________________________________________________________
% E% ?& P# J+ i$ [/ w% z) D8 y% P4 ?6 \8 r3 }
Method 04
" d7 ]! a% l- k; h! y4 y=========
3 u% I" {/ a- ]. A' K6 X
8 W% M0 K3 {" B5 u$ Y) LMethod identical to the preceding one except that it seeks the ID of SoftICE
: X9 t  I+ Y& U  L) [GFX VxD." M* r! j: Z8 x$ I. t  d
: \) Q% N( Y' R! o6 z# j5 z
    xor     di,di
& h1 w+ e$ ~% j: F6 e2 D    mov     es,di1 w' g9 o& Z5 R
    mov     ax, 1684h       ' H1 ^4 ~& y& _5 x
    mov     bx, 7a5Fh       ; VxD ID of SIWVID
2 z- n' e1 {9 N! F6 \3 B    int     2fh3 K; i% t* o& b: f- H
    mov     ax, es          ; ES:DI -&gt; VxD API entry point* I; o/ X% }# {4 d, _
    add     ax, di
, Q; _5 R/ L( K% X/ Y    test    ax,ax4 B3 k1 y/ I( f
    jnz     SoftICE_Detected
7 M: b- f, X6 s- c
/ ], }# I) K# W  b1 B5 k__________________________________________________________________________
4 {9 ^  |2 o' R! ?! _! I( s+ O. G
) f! K; {4 F9 n) _' V- U7 T) J& a% n5 @. K6 `, }$ i
Method 057 K! K7 t1 O" h
=========
  l1 f: x) Q/ j& P
, q5 Z9 J1 A5 e( I( gMethod seeking the 'magic number' 0F386h returned (in ax) by all system6 B( M- @2 e  t
debugger. It calls the int 41h, function 4Fh.4 C9 I0 e+ V" H" N/ m
There are several alternatives.  - N9 E( b& u" N0 S
; Q3 [  p# m( o3 E
The following one is the simplest:/ Y7 k4 H# A; P% |/ j/ H0 C
. B% c1 i9 z. i' O3 |8 ~7 L5 ?6 g; Y
    mov     ax,4fh" h3 y; B7 C7 O1 ^# y1 S3 O
    int     41h% e' M7 q# a; ~5 k8 F
    cmp     ax, 0F386; H3 c  S. D! ^% f! C& {. Y
    jz      SoftICE_detected, n& n( w' O+ A- b) B. N% O& R
/ k' g2 [; o. n

4 E& H) E# T) X; eNext method as well as the following one are 2 examples from Stone's * P2 p- S& D: b; L2 v3 {, C
"stn-wid.zip" (www.cracking.net):
7 L/ Y+ c) f* I: p: j# _
$ ?; Z! K) ^( q    mov     bx, cs
! w; P% Z1 }/ g9 Z( I& g    lea     dx, int41handler2
1 \7 Y$ ^% d' e1 J4 p( m    xchg    dx, es:[41h*4]( R8 o+ o/ b1 o  p- s# N
    xchg    bx, es:[41h*4+2]3 m% l0 c9 N( p) R5 f! A
    mov     ax,4fh
( q7 G$ Z9 g3 S  L1 T5 t    int     41h
% b! Z& |; u  t2 K    xchg    dx, es:[41h*4]
0 D6 w1 j. p  ?, W, F9 w    xchg    bx, es:[41h*4+2]- Y+ _# P% R: O# ]" g- o2 V( Y+ \6 E
    cmp     ax, 0f386h: D: g& j3 \( y5 l5 r# x
    jz      SoftICE_detected
' G! _. u, ]& i+ A5 Z. e( q
4 q# V. Z' P- `int41handler2 PROC3 c+ {& U! B. |0 p' I$ F5 N
    iret8 h: C! g! \5 U) ?
int41handler2 ENDP% [) |( z. O% `
& o0 v6 u4 ^0 D- r4 n( I

' z9 M0 q; w5 b$ c* J8 z5 q_________________________________________________________________________+ C- j% t" A( L9 _# C

0 m4 ?5 f+ k: G9 J: M9 q. q) }! V$ m  q* T  v6 C; ^" ]% J
Method 065 f" F4 V1 J; {
=========
( i$ I) K! m; b/ V* ^: f
3 _; e5 r' F  E5 B' T  i. s6 g1 g! D) S3 v0 c
2nd method similar to the preceding one but more difficult to detect:
; D5 \  w) h1 O! {# H+ j# q* N* L% R" M% u) P# `
, X# @% j, @# P+ V6 P# A2 @9 m2 z
int41handler PROC
( h. @. d$ A  B5 }2 R8 P4 j    mov     cl,al
; S3 O( N) S, C2 h( B& Q! V    iret% g0 N7 K  K& Y& D3 Y8 |  C( W
int41handler ENDP
3 x' K1 j8 \! Q) T6 s- m, P1 @. ]+ q/ U# F
' F% {6 D! j4 t) `5 O, u% \$ r
    xor     ax,ax" Q- w+ `3 N) z
    mov     es,ax7 M3 h. e. i) p8 g, u4 s2 c3 D
    mov     bx, cs
: ?4 H9 \, P5 Q. R  f* Y- P  C    lea     dx, int41handler: H+ k6 V7 I% s( B4 P! S* h
    xchg    dx, es:[41h*4]8 T2 q/ c( l' S
    xchg    bx, es:[41h*4+2]9 h" {0 W# Y0 v' A: }* U
    in      al, 40h$ l. f0 n" a! d' u4 n: a
    xor     cx,cx
3 N, e) D$ d9 s" p! `5 }    int     41h5 {, U' z- e# I
    xchg    dx, es:[41h*4]! B) P2 n9 J; ]4 z( E( Y) x
    xchg    bx, es:[41h*4+2]/ z& E) }' A* @9 e2 _& Q
    cmp     cl,al! o; q/ k, G6 O. b( t9 {+ C
    jnz     SoftICE_detected+ {8 x6 @5 n( c( m" |" h# q" U6 f0 c
8 b  z0 p$ Z2 f5 s$ @
_________________________________________________________________________9 w+ X9 G1 w+ ]# S! x: p

; p) t- S: b2 YMethod 077 F7 N# ]& l& G9 h3 p
=========
, A; M. [; |8 Y( ^3 G" ]% Q0 K2 ~% m- ]& ?1 R; S
Method of detection of the WinICE handler in the int68h (V86)' u+ }8 N3 j  h! X. w  W  x

2 @1 Z6 [% i  G; C# P    mov     ah,43h
7 y$ _  C+ C* s2 V    int     68h2 |% b$ U1 d( _0 ?# C, x1 k
    cmp     ax,0F386h
7 z2 n; Y# v+ p- f4 ^( ]& ~    jz      SoftICE_Detected
0 h6 g3 j, s( v- @, Q4 w# g: a) y# X' E1 H7 }+ y+ [

: y5 m& j! n! |=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit5 p6 F. Z. L2 _# A/ W9 D
   app like this:
- t5 V4 g3 {& ]4 {1 Q0 K" a  ?4 D# S4 o) j* h  x
   BPX exec_int if ax==68
1 h  i" o9 e' F9 X$ d5 W# J   (function called is located at byte ptr [ebp+1Dh] and client eip is
% k7 F( D3 r# s* T, C: Y' |   located at [ebp+48h] for 32Bit apps)
& _4 Z3 s+ M5 m' h3 m; R' a, R__________________________________________________________________________
" g! j: f/ p3 |5 y
/ R$ R" y. l+ ^" r3 p, q. I2 P) Z  h* }" u( e
Method 08# F$ i+ t5 _9 T( c/ P  r. z- Y
=========
/ Q/ C) ?! B; b) f5 A/ k9 `: |( l: h
- A( Z) `- y6 _4 |' oIt is not a method of detection of SoftICE but a possibility to crash the! L; x3 Y# F: ?/ x6 B- Q& P
system by intercepting int 01h and int 03h and redirecting them to another
8 c4 U; \9 T/ ~routine./ U) r# c( `0 ~
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points) c2 y" K7 ]7 m
to the new routine to execute (hangs computer...)
! z& A+ s4 D. U! W4 A8 a  s/ r9 T( J. H' w$ B
    mov     ah, 25h
/ ^' V- r& i7 b    mov     al, Int_Number (01h or 03h)
# g. R# L6 O$ C: j5 f# Y    mov     dx, offset New_Int_Routine, B, @& O* X4 I/ B' B
    int     21h2 A5 l. y$ g8 D$ ~/ @* b

8 B9 |; c/ Y6 I! W' c2 [% d: l# n$ J- Z__________________________________________________________________________$ t; K3 y8 w( m9 `3 x; Q: R+ \
: b5 q. e8 O) H5 H$ {5 u
Method 09) |- R" K, M- I* w" k, s: o$ l* o
=========
8 N& X9 i  w4 t3 A/ V4 B
5 v2 z; z% t7 \$ h  bThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
) Q; r+ O7 _6 m" L' a1 z$ W0 |) }performed in ring0 (VxD or a ring3 app using the VxdCall).1 t1 H1 ~: R5 _1 y; V( A% A& M4 I
The Get_DDB service is used to determine whether or not a VxD is installed
4 P, F* k8 {$ T/ [for the specified device and returns a Device Description Block (in ecx) for
2 D& g) G1 C7 p6 t# U$ Kthat device if it is installed., K6 ^- _3 r0 n& L
; f) S# ~7 f. G% g" Z! X
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID( z$ M$ r, b/ s  e8 `
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)" V% E5 h5 k8 K8 y
   VMMCall Get_DDB# O+ K+ |) o) G* @
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
' d1 J, m( Q& a- v
/ n0 c4 u4 o& y+ WNote as well that you can easily detect this method with SoftICE:
! X4 U6 Q/ h+ ?5 w, x. S2 s, z. W   bpx Get_DDB if ax==0202 || ax==7a5fh
. i5 ~3 L+ b- o; U) _. {
6 y/ J5 A8 u7 E/ d8 @: Q* F$ Q__________________________________________________________________________
) j: p& X; N* o/ B) ?- p& ^6 U
! r6 M- F2 O1 I- y9 v# n" M2 j3 m& B* {Method 10
4 p9 e; N' U, T/ O& ?=========
% C! K/ B& L7 \( R
% j4 Q+ h. {$ E; x0 s=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with9 G9 x8 l4 _7 x: K
  SoftICE while the option is enable!!
, y0 N5 l  [4 T6 D5 g# I# M$ h6 e& f2 p1 H7 h* `  y
This trick is very efficient:( v8 X7 B7 |* V( d4 f7 |
by checking the Debug Registers, you can detect if SoftICE is loaded
# s+ k  R( @$ f. I(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
7 y* D+ t- ?5 \" ]9 N9 \there are some memory breakpoints set (dr0 to dr3) simply by reading their
* v% y% U0 ~# Ivalue (in ring0 only). Values can be manipulated and or changed as well
0 z% L' o9 l' p& G4 ~(clearing BPMs for instance)
9 F2 U+ f* d; j, [& r0 z/ L$ B5 O9 }, G) i/ W; v9 {0 G# I' f
__________________________________________________________________________! G, C2 q9 d. @/ q
7 R/ M( X# H  n* d6 ~- n
Method 116 F9 Z( z9 Z0 c' z' i
=========( w/ I; x! \3 a' Q0 M; h1 \' f

7 A* j" u/ K5 J8 |8 \. S4 |This method is most known as 'MeltICE' because it has been freely distributed+ l9 A9 ]: \- q: b
via www.winfiles.com. However it was first used by NuMega people to allow7 M# X, q; C; d* [" Z0 n, v+ F  [
Symbol Loader to check if SoftICE was active or not (the code is located
& ^' W+ H5 a0 K: zinside nmtrans.dll).
1 }$ n1 J* X3 o& z2 @
  d9 K! A: F$ A- AThe way it works is very simple:0 O, @; O% p0 K" I! R4 u
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for% P) L0 U2 z$ l! C0 A: `) K7 R8 C
WinNT) with the CreateFileA API.% M3 J2 v0 `, p2 i
! H+ l7 p" m6 f
Here is a sample (checking for 'SICE'):  b! n3 D% k: R, R$ O& j: C

: J9 H$ Q/ ^. Y& IBOOL IsSoftIce95Loaded()
* ]( a$ e- {, m' K{  c0 Y9 \; v" b6 a+ [! U
   HANDLE hFile;  & ]8 W( \+ @6 a$ m
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
" U! e. x) A$ ]$ }( c" ?                      FILE_SHARE_READ | FILE_SHARE_WRITE,7 o; l5 b* R. b+ y$ O/ y9 E, K4 b
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
3 W* x9 a" Q& y5 E( \5 Y# e   if( hFile != INVALID_HANDLE_VALUE )  ~" c/ a& u3 P9 O% N
   {
. M( z6 p5 C! o; e" n( `      CloseHandle(hFile);
! B) a  c' n& X1 z  [      return TRUE;
9 p2 L. t: `1 J9 K   }
9 X3 {: ~$ V# K6 n$ d( w   return FALSE;
  y: I" N; h/ `4 n6 h( }# j( r}
; _; w% n6 O8 b1 B2 d3 [- M% I6 ]% |9 [( X/ F
Although this trick calls the CreateFileA function, don't even expect to be
# a* L, \( h) V. F7 P7 Xable to intercept it by installing a IFS hook: it will not work, no way!
, T1 A8 w' l- E" b9 RIn fact, after the call to CreateFileA it will get through VWIN32 0x001F
3 i- g9 R3 [' v- yservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
+ T1 O7 h: e/ u6 S! Eand then browse the DDB list until it find the VxD and its DDB_Control_Proc
7 \( r* S, D; x8 E1 ofield.) v% f9 B' |( R! S
In fact, its purpose is not to load/unload VxDs but only to send a
4 z7 Y" _, ^& u0 M* n8 O; k' TW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
9 h' W5 u/ l, Ato the VxD Control_Dispatch proc (how the hell a shareware soft could try
, `3 R8 B$ \& c! p$ S1 pto load/unload a non-dynamically loadable driver such as SoftICE ;-).9 `6 P4 f6 }  A+ O! R' _% M
If the VxD is loaded, it will always clear eax and the Carry flag to allow% [* m9 g9 P5 x8 `4 }8 d
its handle to be opened and then, will be detected.- y/ J  x4 T! O
You can check that simply by hooking Winice.exe control proc entry point; h0 h2 u; T# U) ?7 l, r
while running MeltICE.
% t' i; T. G( f( v% P% o& L2 K$ B  U3 P) E% z

6 Z# c  K, b" z- H  00401067:  push      00402025    ; \\.\SICE) \5 `: ~) L+ c5 p0 X0 C
  0040106C:  call      CreateFileA
5 A: g" |; U- D* L  00401071:  cmp       eax,-0018 y2 [# |$ m& k# K% u! o
  00401074:  je        004010917 a6 q3 R4 q3 Q' |, T

7 D+ c5 q( f+ }
  P& `+ ]% t! C% H) DThere could be hundreds of BPX you could use to detect this trick.; m" h! L( ]7 o
-The most classical one is:* p' c  _1 l$ p  \3 F
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
* a0 {% w& t6 A! b1 U  e  `8 \4 [5 P    *(esp-&gt;4+4)=='NTIC'( D9 ~/ O2 L9 d- M4 _& d1 L% V
7 h5 t2 m0 @% |, \8 B
-The most exotic ones (could be very slooooow :-(2 J& p( Q! D- w. u0 w9 Z+ b' \7 M% L
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
& r+ c) n# K0 P0 T$ I2 h2 A1 ?     ;will break 3 times :-(
+ N% c* T- R/ z) Z: e! R$ a0 R7 q9 P8 C4 P5 f; f  h3 Z
-or (a bit) faster:
! W2 }+ [7 ~  V   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')) m* O; w1 _# s  o* u' u: _9 b
. l( n. W+ n  _0 Z  Q7 l! M& z8 ^
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  - U/ Y7 e  Z: K8 U& L
     ;will break 3 times :-(
, e; z( [) l2 K0 b/ O" b* m, u3 n
; X6 G% x- m+ C1 V2 F. B4 V1 e-Much faster:" b% y1 z; M- ]+ @! v4 q
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV', N- g/ C7 L! r' K0 l
$ R2 P' T  d6 l9 k$ Y* u
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
, E5 x+ |) c7 M$ I. f9 J; E7 A) ?function to do the same job:& C. H# r. G8 `9 @
0 c/ @" E, w5 C( ]
   push    00                        ; OF_READ8 g& O% j% @$ \  y
   mov     eax,[00656634]            ; '\\.\SICE',0
' Z) n1 ?- v6 n% k8 n  F. I6 S   push    eax
5 O$ N: _% j# v( e! T/ i* J2 C( {   call    KERNEL32!_lopen
0 W* Z; y" T, l" `, V# F6 Y0 m   inc     eax
" ?! i; k/ U; f   jnz     00650589                  ; detected
. G% L1 U  d, ?/ R5 b8 p9 g0 u   push    00                        ; OF_READ
( s5 R, [9 P8 b% `2 t7 e) N   mov     eax,[00656638]            ; '\\.\SICE'3 w' c* z$ f1 v; k2 P9 }
   push    eax5 k+ T5 n" B- M
   call    KERNEL32!_lopen  M& R4 I8 @8 F5 r* W4 f
   inc     eax* R& Z; C; }- ]/ ?' w* {
   jz      006505ae                  ; not detected
9 `: I. C. b7 g, X( {! P- |# j$ z: j2 R- `* ~% |( M

6 E+ t% G4 \4 `& R5 g1 H* |: ~__________________________________________________________________________
8 {" x* z+ x: C( G  b3 Z; ]* y
0 {2 d) r! R( |' I, R6 nMethod 121 Q2 j" y" P- f, w' [% c- f( U
=========
- g, N1 m7 d: m( w* ~! l- S6 A9 z" u  d. j
This trick is similar to int41h/4fh Debugger installation check (code 058 r5 S5 I& v# k0 n! j+ K- v& p5 h+ L
&amp; 06) but very limited because it's only available for Win95/98 (not NT)
" p" C: A+ E* Las it uses the VxDCall backdoor. This detection was found in Bleem Demo.
- Y# n9 G+ ~  I* f: H
; }6 n' `( j$ B5 g   push  0000004fh         ; function 4fh+ o" A6 M' c. |% Y8 D
   push  002a002ah         ; high word specifies which VxD (VWIN32)
9 r# B* v; M( C7 K; C$ y                           ; low word specifies which service
  Q2 y. R. |/ B4 H                             (VWIN32_Int41Dispatch)' s8 B, [& p8 b4 J; i9 i
   call  Kernel32!ORD_001  ; VxdCall
: _4 o0 U8 {! W& p   cmp   ax, 0f386h        ; magic number returned by system debuggers
* N4 {# r1 Q3 w  P- D   jz    SoftICE_detected! P7 s& j; M) \+ T  q# b
8 J3 ?( F6 X) E6 {+ f3 ]
Here again, several ways to detect it:
, [* R5 j/ U/ x! o+ Z' t$ @4 K7 p3 B( m
    BPINT 41 if ax==4f
& v1 x2 m$ b, G) _6 ^9 ?' r8 J4 D6 D+ @: W2 m
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
/ E# _% F( ^/ B5 H9 W7 r3 x6 o6 t+ S* p1 K  S+ r' D
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A, K- a2 h0 j' P  t! U- j

" u) K3 ~: B) E# g5 @) f1 J' \3 X    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!4 _+ r6 E! _1 S4 E6 J6 x

( m/ v5 s: v" J* Z  J1 S1 |__________________________________________________________________________$ l* \- d- ~8 Q# _# f& A

; B/ w! d) F* D- p3 G' VMethod 13
- G9 c" n% \3 a0 R=========
* Q: [- ?# J0 u. c9 p( }( n6 D  v$ x- h# _! w6 z: I+ ~
Not a real method of detection, but a good way to know if SoftICE is5 s7 ?) s7 j, I
installed on a computer and to locate its installation directory.
0 _; g8 @5 {9 gIt is used by few softs which access the following registry keys (usually #2) :
3 f+ S9 b, _3 i5 A0 s( W1 F- ?& k6 f# ]  w0 M$ b
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion* [" M# p  F  t
\Uninstall\SoftICE8 {5 P. q. \% v' t
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE/ P+ H" H' ~5 _, V# k' B4 Y
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
/ ]5 N- H* f. P( j. {7 J\App Paths\Loader32.Exe! V3 `1 ?% v( [, E) q

' k0 V4 \8 c" b3 _( A- v6 Z3 N; }6 _5 W' G& g4 ?
Note that some nasty apps could then erase all files from SoftICE directory
3 \9 }+ l$ y. ?& Q, d- L  f(I faced that once :-(
3 c+ i7 V) {7 i2 j6 W/ p, {
! p2 S; G$ i" R6 p; H, qUseful breakpoint to detect it:
! p4 y* Y; h; q! n8 g
/ L& P: f9 B$ F8 L1 `' N/ e% f/ c     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'5 j$ r0 i1 j+ K0 w+ Q

  |+ {7 f- n9 n) f' q: M1 D+ u! B8 }__________________________________________________________________________8 Y6 t5 P# t0 b) \' r
3 U; J% f, I& E. M

* f/ v( C. s& u" w6 wMethod 14
: P) M* t8 K1 y0 d  G=========
' k, {0 X3 l2 e* Q8 d4 [  h. r
0 D3 g) @+ t. u. v: W6 Z* aA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose/ D: Y/ Z( x, k, G4 n
is to determines whether a debugger is running on your system (ring0 only)." O8 I1 l! P! s2 F8 Z) {+ r4 p

7 G( }" z7 u  J$ k# I# \4 y   VMMCall Test_Debug_Installed
  c. K% R' O2 a5 f% }   je      not_installed7 _3 B/ T% q' w0 A% F0 n( ^" n# h/ u

& r1 f. T$ k% a$ c7 f8 N2 cThis service just checks a flag.
' d3 ?: G/ U* s) f; |- r; \</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部