About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
/ f- Y1 T  {6 P8 G4 |& [<TBODY>& i. M' j, M, U5 g3 }
<TR>
" n# k, Q3 r( a" z2 ~<TD><PRE>Method 01
7 _. J4 t& Q% @=========) ~. V) W, g( E0 J! B2 }/ m

6 f5 `- K9 B2 hThis method of detection of SoftICE (as well as the following one) is
4 e" z2 ]( O6 O/ oused by the majority of packers/encryptors found on Internet.. h! S0 [( D8 j" _
It seeks the signature of BoundsChecker in SoftICE
0 I# m% I- Z1 z! |5 q, c2 S, Z5 A+ L7 i0 w$ X
    mov     ebp, 04243484Bh        ; 'BCHK'3 h  `  j" e6 ~) E. G1 [
    mov     ax, 04h2 z# G% _; |" o2 f0 G& z, i1 E
    int     3       , g" {8 ~& }7 ~4 K1 n7 A% }
    cmp     al,4
' C, a; c6 x( ~( W    jnz     SoftICE_Detected
7 j( t& |, M4 `# j; `( T
7 d8 a# @- b9 W1 K% K___________________________________________________________________________
2 g/ o' r" x, z; Y, M' F
- w8 E2 \: D! m  _: E4 eMethod 027 T6 K0 v9 b0 `2 O- g
=========
6 E1 `( B1 l0 T! n4 z2 t3 h! N
7 C4 a4 l( P! ^- M# A+ YStill a method very much used (perhaps the most frequent one).  It is used" w8 P! r8 Y6 S7 Q6 k
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,/ d0 D8 e- C2 g6 H, q
or execute SoftICE commands...
$ n7 j/ _/ ]- N2 [It is also used to crash SoftICE and to force it to execute any commands7 Y6 e1 Q6 H# K
(HBOOT...) :-((  # O8 h6 ^9 R- S
" {- h) L) M8 _3 n
Here is a quick description:
: B6 [) Z5 O1 i* R' d-AX = 0910h   (Display string in SIce windows)
2 E* U( W" e2 X7 W# w. Y! v-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
) S5 j7 P: t, Z) g-AX = 0912h   (Get breakpoint infos)
) K' d- }, E2 }7 g8 ]& o# B7 R-AX = 0913h   (Set Sice breakpoints)
7 \3 k' ?. t8 k4 M-AX = 0914h   (Remove SIce breakoints)4 m, i" J( _9 W' d4 a% A5 K
0 V! V' M- H' N  f. ?9 M) t1 U
Each time you'll meet this trick, you'll see:
+ h6 p/ ~6 N2 G. l-SI = 4647h/ f& ?. Q! U- T' w+ ?/ A
-DI = 4A4Dh$ j6 y% s8 p3 d. H- ~7 Q
Which are the 'magic values' used by SoftIce.$ ?1 y6 T  @  A2 P
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
+ w# P6 @) v" h; u6 X0 L' @4 k; t' D4 L  V
Here is one example from the file "Haspinst.exe" which is the dongle HASP& W6 ?, D, ]  K! |
Envelope utility use to protect DOS applications:& P: |8 Q" E1 |! x

; a0 y  [+ u: I' K$ l
, d5 \" I* Q- t. p5 v1 b, z4C19:0095   MOV    AX,0911  ; execute command.
- D  `4 d) h4 J* C. P4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below)., k6 R; m- |& P/ I
4C19:009A   MOV    SI,4647  ; 1st magic value.
, Z* {' ]7 b; L9 t2 I3 B4 T4C19:009D   MOV    DI,4A4D  ; 2nd magic value.( y4 c3 \6 c" U5 h$ ^) T. x" g
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
. k2 d! i7 {- d! I4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute9 _5 L% y2 k2 s, p* h0 I
4C19:00A4   INC    CX
6 N; w9 {, a0 \4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute! Y+ f$ N! v0 _/ y- y0 F
4C19:00A8   JB     0095     ; 6 different commands.
. Z* E8 W) M7 i- e4C19:00AA   JMP    0002     ; Bad_Guy jmp back.# O" b0 G  b7 I* x/ p  W
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)% n4 ~2 s8 U6 p+ S' ^: B7 Z

' q; a- L  U5 y0 w9 V: QThe program will execute 6 different SIce commands located at ds:dx, which. t# s) O, T+ Y6 |) v
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.7 P% A, f. G& ]; |1 d
0 v9 Y: h6 f, C( L6 H4 v( p; S+ X0 p
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.1 c& t4 D3 L8 n' _0 J
___________________________________________________________________________
8 c8 e5 J- V8 b7 O6 u2 v4 `" ~3 k. x6 [. `8 U0 C
1 ?! Y. e8 m; p. @! ]
Method 03# }/ ~+ T5 ?5 {/ _& R9 p
=========% x- V3 ~% h6 }( H7 ~/ J6 X3 W5 I
& d; ^& C4 R  C& {* m4 U; _& [
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
6 P2 K. S5 U. j. O(API Get entry point)5 s6 G2 V0 v9 T: M6 O# |$ T
        
% K5 S' y% k1 p# d0 h2 z$ D
, f; C% ]; ^; u    xor     di,di6 S, t3 V) t' x" a2 ]" P3 f: c
    mov     es,di9 {: ~% C' q5 L3 q* @
    mov     ax, 1684h       - v4 j; ]5 ~( o! c- `% z4 `7 W
    mov     bx, 0202h       ; VxD ID of winice
# Q$ i6 J' B5 D3 o+ s    int     2Fh: @  T* |* _; u6 g( m. ^
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
; a# k& G/ h! h3 f    add     ax, di
' t! F' D6 l$ W: \7 y    test    ax,ax; ~6 b. g/ U, m
    jnz     SoftICE_Detected# S$ ]- |) R( t* I7 \3 b9 q

- V4 y$ p0 ]2 t2 V, s9 C4 R___________________________________________________________________________
$ f$ d; W; A( a5 H. e( _& \% {1 m
: c+ p- J( S, G0 a% mMethod 042 I* F) I& ~& B+ r
=========" h5 ^7 q2 t  W  l/ P! V
! V2 a/ A1 m7 p6 Z8 n" ?5 Q
Method identical to the preceding one except that it seeks the ID of SoftICE; k3 Z! @/ Q, C8 I
GFX VxD.& ?7 p- Z9 }6 \7 d( m
5 i( v0 s% c! W. l6 j  V
    xor     di,di0 q: S8 J! J' n7 ~: o( s9 i  a& [# S
    mov     es,di2 k  x: y+ J8 R
    mov     ax, 1684h       / B( e' D8 _% V+ l- h
    mov     bx, 7a5Fh       ; VxD ID of SIWVID! h. y6 j# w  r/ ^8 M8 ~
    int     2fh
  O1 j: S! k! I  T$ ~$ ?! b; L$ F    mov     ax, es          ; ES:DI -&gt; VxD API entry point
5 ?* V/ X; G/ D; \+ J. ], P    add     ax, di
8 t. V% g! ^, G% K, P, E. \) \    test    ax,ax# g- t8 u2 T- a& ?: O1 @& V7 |# S0 A( ~
    jnz     SoftICE_Detected+ I) u! W/ d1 a
! n  U+ R% U5 k4 r3 P- D: K- L
__________________________________________________________________________& h* }3 j6 V, P2 w& z" a

3 M2 r8 {* _  ]5 s# J
1 n. H% n, W* C5 l5 Y* fMethod 055 o' B: C: X2 P$ R+ d0 w, N* `
=========) |9 n/ B! ?# _7 E

: K% Z7 Q) W" G2 [7 Q* y7 i! zMethod seeking the 'magic number' 0F386h returned (in ax) by all system  g. ?5 l* i4 U* l+ F
debugger. It calls the int 41h, function 4Fh.  l2 W! n, r) T* n! ?
There are several alternatives.  3 x3 S4 Z7 z/ t) }

& ^- c: z, A9 i8 n/ KThe following one is the simplest:
1 Z# y. U4 K0 }9 n& b, V; ^5 K  Y( x
    mov     ax,4fh/ B% `& W6 N! N4 Q9 u, ~
    int     41h
) v: _5 t! m: b" N4 @    cmp     ax, 0F386
: L  l, F. }& Q. {! o: D8 S    jz      SoftICE_detected
1 C6 v9 Y" ]2 g$ O5 b7 v# h, ^" ~# ~) Y% e
, G- Z8 o* m" u5 J  ~7 f
Next method as well as the following one are 2 examples from Stone's 4 h! x1 J' r. v# [- p' Z
"stn-wid.zip" (www.cracking.net):
% ]) Z1 v( W2 Z) N/ {) c3 Y
& L' Y! ~/ G% a  Z7 U  c9 [( U: F$ X    mov     bx, cs8 l5 [; u7 ?$ `- ?5 y8 f8 E
    lea     dx, int41handler2" {- t' G: s6 p$ R1 f. N  ]
    xchg    dx, es:[41h*4]0 p3 l7 J7 o: @9 E" M% D
    xchg    bx, es:[41h*4+2]1 i+ R, {6 }3 a2 E8 i* n
    mov     ax,4fh
+ ?; J" g/ v6 R) [* s: }8 O9 n    int     41h* H. U, j1 `- ]* W# I
    xchg    dx, es:[41h*4]
1 h* W1 s( M4 e* ?+ o    xchg    bx, es:[41h*4+2]
+ Q9 s0 g. X4 v' T8 C    cmp     ax, 0f386h
$ q1 V# D6 ~+ ?    jz      SoftICE_detected
9 U( Q! I$ s) B3 Y/ N* a, V
3 k2 t" X' j- ^4 H3 f1 {9 Oint41handler2 PROC, t- _  Z  \' r: R! i- {
    iret) U3 X& M! C% T( F* a0 B# s
int41handler2 ENDP
3 [4 D; H3 k. j  S7 }9 r- u  g3 t" v; c2 O* z* f

7 Y6 H* M6 j8 p6 h_________________________________________________________________________1 t2 l: u0 D3 Q

! V/ Z. ~& d! m9 `* @4 p% n- Z" ^0 X9 u6 k) V# g
Method 067 D' v2 k, h2 o+ ~" ^. u! Q1 j0 J
=========
9 U- c+ U) \2 ?1 n9 h
# c" k8 _  t. H) f. J4 i
, T3 A* M2 n' l$ D2nd method similar to the preceding one but more difficult to detect:
: v) X' T! n9 H* |5 ?+ n
5 _' m! q7 ?1 x7 C) Y7 D# g# R$ A; v, n
int41handler PROC
+ `& Z  @; H5 n* p  M    mov     cl,al
9 f5 R: u+ V- A+ `    iret* Z( O1 v% _* r2 e
int41handler ENDP/ \8 l' U5 y, Y' }% v
5 @" s8 X1 C1 u9 b3 C
) j) `5 N# T' I  J) n3 z8 R1 I, k
    xor     ax,ax# }8 O9 S6 D8 o2 m: ^
    mov     es,ax
/ a. H+ h! C; a7 y0 v    mov     bx, cs5 `7 {1 J4 A( ~& ~
    lea     dx, int41handler
  w/ D5 u  y4 s# M3 M    xchg    dx, es:[41h*4]
9 o  a- o+ M6 R    xchg    bx, es:[41h*4+2]* b1 a+ v7 s9 D. z! b1 Y
    in      al, 40h) B# c6 R. e) T$ \0 |0 @9 @
    xor     cx,cx
' m; G6 e3 \% r  p    int     41h. J! _; ]% y3 g8 H7 v
    xchg    dx, es:[41h*4]
6 J6 K/ f) y1 t! z  O    xchg    bx, es:[41h*4+2]
# b* h6 t/ T  F3 f) Y    cmp     cl,al% V& @" L* V" n" e! a  [: O) e
    jnz     SoftICE_detected, V# k+ ]! w8 \/ l8 ~
$ h' k3 J. }2 I' p
_________________________________________________________________________) `8 v+ Q$ e' w9 d$ Q0 F6 ~, ?9 g

- H# }) _) J) MMethod 07& e$ f: R" a6 e% s
=========
, x; d0 }. a+ \5 K
1 T, ~% e; ^% V# vMethod of detection of the WinICE handler in the int68h (V86)
2 y2 T; ?8 r9 T! A$ u  a
4 Y+ P+ ~8 Q5 @    mov     ah,43h% K* C2 Y- ^8 R4 `6 A1 \
    int     68h
. m! Z, \3 a, a    cmp     ax,0F386h6 k! i0 C0 W2 S+ V
    jz      SoftICE_Detected
  q5 N6 h" Q% _- p8 Q$ A# G6 R* S  }. t) x" e* N9 x! M
; y/ G  R1 a3 h
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit, ^  `1 S1 D3 Z+ c6 t. b& H; ]/ M
   app like this:0 x+ ]* o+ |2 y( X/ T) u  m9 y

. a) g% i8 K9 x) L# q# f   BPX exec_int if ax==68
5 E$ a% R- p4 K3 r8 b9 J- \   (function called is located at byte ptr [ebp+1Dh] and client eip is& @5 U# H( S- o# E8 J/ h- r' i5 O
   located at [ebp+48h] for 32Bit apps)
1 K$ N4 k8 U* V8 X* P' u  P% E__________________________________________________________________________
. v9 q. x/ z7 l+ G; X5 ]  X" |. K2 N

$ g% z$ k- y' r9 S& kMethod 08- R5 N) V/ t4 m" u3 a  G
=========" w- X$ J( h. w4 ]2 U. R  p! `
3 S: X; e& U4 `7 M2 p
It is not a method of detection of SoftICE but a possibility to crash the5 \& J7 Y- c. g1 j5 G
system by intercepting int 01h and int 03h and redirecting them to another
1 X% W. ]/ ^8 Kroutine.
' p$ G# d0 W' L, E" Y& M. MIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points( C5 r# e1 [9 S8 x
to the new routine to execute (hangs computer...)
5 v" Y9 V" _6 Q$ n' `( J2 H
! O! }/ j6 \6 L6 U3 {9 T' r    mov     ah, 25h- m# x* S; _; b: }" k* V
    mov     al, Int_Number (01h or 03h); m- J4 `0 c4 C: W" ~' w- o
    mov     dx, offset New_Int_Routine
% S* P& H+ ?- J. B- Q& K    int     21h2 V5 |" P2 o% Q2 p2 g. ]8 W

3 ~# T1 g6 ~2 b) f__________________________________________________________________________
. U6 x1 w5 R, o1 p8 n
2 ~- X3 Z3 V5 \, P3 UMethod 09
8 ~8 d9 N4 V+ o=========4 E8 ]8 [3 E* Q/ b* D. F

0 G( y# c5 {7 j+ ?2 q5 U8 `This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
# v7 ~; d1 H1 r4 M1 eperformed in ring0 (VxD or a ring3 app using the VxdCall).
0 p& b( W1 o9 j; G8 e" X7 FThe Get_DDB service is used to determine whether or not a VxD is installed
3 U6 A) I3 c/ M+ [for the specified device and returns a Device Description Block (in ecx) for
- H% W6 |3 W7 i+ u; K. h+ xthat device if it is installed.* \' B8 b2 U, s

2 Y" b; r7 y+ e1 v9 G# `2 M   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID, j3 T$ v7 @! R. P  R) H/ |
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
! A! `" j" t9 @& f5 T& v% y3 U  @   VMMCall Get_DDB, D" @' ^0 \! A
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed+ E6 y) T* R. ?" v  }
/ b+ F' E& c% [1 ~5 q# Y1 s
Note as well that you can easily detect this method with SoftICE:; I4 Y7 J+ Z" Z+ A: N2 W& l. V
   bpx Get_DDB if ax==0202 || ax==7a5fh5 x% [: b4 {1 z. `2 A3 I% `
- \3 u) A5 G+ n$ B1 K2 D0 L
__________________________________________________________________________1 u0 ?; M) W: j, d* T- h
8 e* h/ O9 Y: D
Method 10
, Q4 J& Q2 o1 f& [/ ~5 l, n" ?( E. p=========8 `$ G$ |5 z' R+ m, A9 O# x: J
' ~7 O' P$ I4 v
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with: F8 r% ~8 y& b7 b3 @6 l
  SoftICE while the option is enable!!
+ A, w% _4 V1 ^/ D8 I: I* s
, n# ?1 w0 U' [$ t* u' uThis trick is very efficient:
, z0 u6 S  W& Uby checking the Debug Registers, you can detect if SoftICE is loaded
* B- ~9 a) ~% h' E$ }(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
! }: D9 _/ q8 v1 H7 W1 I+ jthere are some memory breakpoints set (dr0 to dr3) simply by reading their
0 o$ H! @8 G: v* G+ `) v6 Tvalue (in ring0 only). Values can be manipulated and or changed as well
5 U5 W( e- A1 ^- Q2 O9 `9 G, N(clearing BPMs for instance)8 b8 T, h, d9 L% E5 z: a  S! p' U

6 S# k$ M5 ^0 }. P__________________________________________________________________________
* Q# V: c5 @2 H: Y8 a$ W1 u1 J7 D0 q% z2 H2 }4 d7 S2 ]
Method 11$ m6 g9 x. m2 `: d: N" ^8 t
=========# k; ]& e1 R! v' \2 J
2 h4 m0 y: b1 n2 z
This method is most known as 'MeltICE' because it has been freely distributed- R9 c1 l& `0 @+ g  x) M+ s8 c
via www.winfiles.com. However it was first used by NuMega people to allow
! W- @; R' a2 @- @( NSymbol Loader to check if SoftICE was active or not (the code is located
9 V4 c; X1 ~/ I& I' t1 G% r  Zinside nmtrans.dll).& M  r  l# ^- B/ m

" U: y6 f/ I; oThe way it works is very simple:
& s7 o( a/ A0 t. ], [/ N6 oIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
; G4 z6 H! @: l( WWinNT) with the CreateFileA API.
* p, S/ Y& R* b% ^) h' Z( P: U. E. a' c: ~) I: S' [  |  z2 g! U; F
Here is a sample (checking for 'SICE'):4 T6 R- a8 s  l7 Q& Z, c; x% Q5 K

' X1 W, R% y2 N, p  }' HBOOL IsSoftIce95Loaded()
: o6 }. i- J3 f{+ ~4 {# g8 q% c; L: m
   HANDLE hFile;  # P" C% S: q; x5 ?
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,+ s4 p) v; t" T/ z: c
                      FILE_SHARE_READ | FILE_SHARE_WRITE," h- {+ D6 J, [; }, m
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);4 |3 O5 Q' h2 k) j% Z) i
   if( hFile != INVALID_HANDLE_VALUE )1 C% o0 S7 C! \! n! {$ a2 z
   {8 t$ {: g1 f5 i. j
      CloseHandle(hFile);
# q, U/ \2 y5 [+ R% a' B/ W: P      return TRUE;& D5 |+ Y* K) ]4 ?4 X
   }
. v! z$ g" Y# k$ N8 E2 V" `   return FALSE;  \6 @5 Z% U: v  i2 ?
}' e4 d, ~0 V* j  \- M, C
! w0 V5 m+ o5 T0 A
Although this trick calls the CreateFileA function, don't even expect to be
: a% o5 B6 D& c5 n" oable to intercept it by installing a IFS hook: it will not work, no way!! C& @6 r) l! v$ J- G+ H2 }3 z
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
8 R4 y* u+ L9 Z# Aservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)- p8 q% b9 k5 D4 N) H& r; B
and then browse the DDB list until it find the VxD and its DDB_Control_Proc4 e6 R7 {% X1 Y, x$ ^) ?
field.
4 L0 K: g( E8 H! n1 ]. L+ ^In fact, its purpose is not to load/unload VxDs but only to send a
+ Q- L. H2 t3 z5 ]W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
4 f  ?9 F% u5 E! `+ l; zto the VxD Control_Dispatch proc (how the hell a shareware soft could try: c' C# H# v. `) N  W. I
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
: R# y- W0 ]) p6 V/ r' LIf the VxD is loaded, it will always clear eax and the Carry flag to allow
; X% Z1 [4 _5 ]! P* m* _  Iits handle to be opened and then, will be detected.4 d( @9 |5 R2 B+ Y- Q
You can check that simply by hooking Winice.exe control proc entry point
! S5 L  h: Q7 p6 X$ D/ c5 iwhile running MeltICE.
5 j8 W  z  t4 G6 z& ]+ X3 V& x( O: }6 X- N- o4 A
1 a+ ^, P# j3 N+ `
  00401067:  push      00402025    ; \\.\SICE) e0 e+ f. Q2 K/ d# L
  0040106C:  call      CreateFileA
" b1 G3 ?% m. r4 t. v0 I# K  00401071:  cmp       eax,-001! }9 `8 _2 u9 U9 w2 Z4 e/ a
  00401074:  je        00401091
" V, I0 S" q8 l# E# }! X; c/ `, e# f* X
) Y" c7 o1 K4 h
7 y+ A) T, R& ^There could be hundreds of BPX you could use to detect this trick.
, A5 Q8 m: f6 a- M0 {$ f, u5 y1 i% `-The most classical one is:: q7 P( Z  U8 Q7 L0 l5 ]
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||9 }* Z9 E( w5 R$ j8 k  B
    *(esp-&gt;4+4)=='NTIC': Q' z$ c, |5 X! C# O( r0 p
$ U: p! _2 T: ]
-The most exotic ones (could be very slooooow :-(* {' J0 q; a5 w6 d  b
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  % b* G' a8 D0 Z4 Q+ i- ~' Q
     ;will break 3 times :-(2 ]4 H9 {9 [7 b! @3 C
# |0 {/ V8 `% i
-or (a bit) faster:
3 }' z6 ^8 c$ ^8 W   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')4 g' |% d& E2 E' `& V
# r. Z% R9 Q" X0 u/ ]% o
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
  P9 U7 n! J" w$ n     ;will break 3 times :-(+ C4 _0 B# U9 `4 p% \

, P  T# [* F8 i; h-Much faster:
# l, n; I3 a* J! A8 V7 U- [   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'* H; B: M2 U7 u, O+ Z# s
  X( z0 g- ~4 d5 a8 g$ b
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
) o  c1 C% ?8 c7 ~/ N3 b; Cfunction to do the same job:& \; p) p& q6 C' Z+ d7 R; l
# Q0 D% ]: o6 H6 ^: Q
   push    00                        ; OF_READ
3 X- M$ ?% N. v7 m) U% o9 u   mov     eax,[00656634]            ; '\\.\SICE',05 Y/ N( J* V! y% w
   push    eax
7 ?' f& `3 q9 N9 B   call    KERNEL32!_lopen4 m2 d# `/ f$ E# e9 y
   inc     eax
0 {: \- Q( v+ y( O6 K   jnz     00650589                  ; detected4 O1 A( e  c7 v2 ~( B/ x! K1 |
   push    00                        ; OF_READ! T: a6 N$ Z- e: C" \
   mov     eax,[00656638]            ; '\\.\SICE'
+ I% r& x2 h3 I3 \$ ^5 D/ [   push    eax
  O% M' ^" ?7 Y   call    KERNEL32!_lopen' B, D, J4 ^4 p- ~( _% x( v0 u
   inc     eax2 m5 A7 ]4 n5 j- [! T& v! O
   jz      006505ae                  ; not detected
! a6 p, ?" R1 y3 p2 o" l* ]: y7 w
- D: z; X0 t4 W$ A
/ H9 K# w: b) s__________________________________________________________________________; y4 R# Z! b- f# M3 @: ]2 z
+ N* F( y' V7 ]4 @) l9 T  t
Method 12% @, Z( [8 t3 F
=========
3 Q2 b) `9 [8 k& X3 N# r5 ?# [/ Q; ?5 [( q
This trick is similar to int41h/4fh Debugger installation check (code 051 D% G$ g9 d( u7 I8 U" \2 q: m
&amp; 06) but very limited because it's only available for Win95/98 (not NT)3 k) N) m6 G8 R6 ^2 v! c# D6 D
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.7 c$ C1 {& ?5 r
* p; g/ H1 w- k- r
   push  0000004fh         ; function 4fh
  M) c  @1 H) D# w! l  H$ E. L6 I" `   push  002a002ah         ; high word specifies which VxD (VWIN32)) d5 }1 H( i* U% T
                           ; low word specifies which service/ S% @' j' x3 \& U, `* Q* Q6 K7 }
                             (VWIN32_Int41Dispatch)
/ F3 A0 _0 [8 m! [6 I   call  Kernel32!ORD_001  ; VxdCall  |* F' ~: B0 X3 G
   cmp   ax, 0f386h        ; magic number returned by system debuggers( m0 T5 [* ]! B1 C
   jz    SoftICE_detected
* W6 M! W3 u! Y' Q8 u$ ?6 V% Q/ ?, Q1 V3 n; f  e6 t- \
Here again, several ways to detect it:
8 f" _0 i8 Q' f) K& R% j
* {* s* s9 m* r    BPINT 41 if ax==4f
0 f. p; W$ O! _* _( K* ]. m$ b8 M% ?2 r$ [
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one- W; k2 d( j; F0 Q3 v' r7 i- _
  F. }# V7 Q( K. I6 E  e- W
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
5 W; I; x! V: R4 ]5 L9 o- ^. l* m( O# @' Z7 v
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!' y% B& @- t* _4 P
; r& M) m7 @% D3 c6 m5 `
__________________________________________________________________________
: W! D2 H" ^# d- d+ c/ y% |
) O' e- D& c; T( A2 rMethod 13
1 w+ H: z: O/ o=========; G* E. o+ |6 c  {
9 D6 o9 {$ A  F& x) s7 y
Not a real method of detection, but a good way to know if SoftICE is. w2 U$ {# Z9 z/ N2 M) R
installed on a computer and to locate its installation directory.
" }5 H) v9 q0 g. ~$ {It is used by few softs which access the following registry keys (usually #2) :0 x( e) t. z& @
& @7 I# R2 d# Z9 W; W3 L2 y
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
4 q8 R! ]2 {! G: l9 D0 t; N\Uninstall\SoftICE. _' {0 B# T5 I* A5 X& u
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
$ H; S7 s! P8 m7 C. X8 ], z: N/ C-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion: D& h- m. B" h% N
\App Paths\Loader32.Exe! o! u& x4 }. {6 J, Z. j* Q
9 }! p8 o: E6 N  l* N4 |- i* O

0 c* ~. o* @% b3 z! bNote that some nasty apps could then erase all files from SoftICE directory5 d8 L+ r7 A0 d( e  f  D5 p
(I faced that once :-(
8 V, O3 d7 U$ ^; o3 D; c
3 Z3 k8 \; Z- n$ G: V- mUseful breakpoint to detect it:$ M' m" w; }5 w- i2 v! \

6 ^' ]4 x2 p2 \7 l  X3 g     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
# g( P9 K8 [/ V9 u* p* z* K: R
5 ?6 W, M" _, d9 c0 k! ~' t- R__________________________________________________________________________
7 P$ i1 z5 S$ f! N9 `! |+ X
- q$ w# `  Q+ C6 D% U7 U/ I+ A
0 p2 N- ~5 z- L; k4 P( N( qMethod 14
3 I$ `' {, u6 F/ O; z4 r$ U8 e=========! l" n# y, Z8 g

2 Z* p0 l1 g- |6 ^8 w6 u; v# d) gA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose8 h# y% Z2 D/ q- X
is to determines whether a debugger is running on your system (ring0 only).
7 J* `# B- v; ?3 d- l& z
+ w1 `+ {5 B9 u4 U# ~! Q2 h   VMMCall Test_Debug_Installed0 I3 q- g/ I, s1 f, a+ o
   je      not_installed
  {% ^3 k( P* m4 x3 S, z; `7 e
3 t( _" G: O, n, Z; W3 i6 Y0 `This service just checks a flag.4 `6 b7 r* r) r1 k; l  I3 x. ]
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部