About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
, L% F: `) p* |/ C<TBODY>. ~7 `- `% H1 G. U4 Z
<TR>
" r( i- A  n: k; V$ ^<TD><PRE>Method 01 7 r7 l5 j" h# r1 I! _+ h* q
=========& d  \% p4 e( h2 p% E0 m! c* V% M

/ D4 {) O/ S7 |) L( c8 _! _6 Z( WThis method of detection of SoftICE (as well as the following one) is+ N) |! j' n; ?4 M  r3 r3 `: R, ~
used by the majority of packers/encryptors found on Internet.
2 y- a) H; V: I( ]) OIt seeks the signature of BoundsChecker in SoftICE! p# D1 \; ?0 e& f# @! G

( j  g3 o4 I# [# e. A    mov     ebp, 04243484Bh        ; 'BCHK'7 C, F8 L1 ~4 ]" \+ i6 \1 ]
    mov     ax, 04h
8 ~1 K4 y! {. N    int     3      
& w. t% _" j" E- M. S/ X    cmp     al,4
7 P1 k% L6 s1 o9 e    jnz     SoftICE_Detected- C* X) T+ j. |# H- H  S- |

0 G. N) S2 A: {% Y1 I___________________________________________________________________________
: m6 @) p  U0 L* r3 H# F$ u6 j" q0 s5 T& C
Method 02
# e6 K8 u" B/ C* b8 B6 x=========- x2 a& y7 `8 }7 C% s2 c& J) V

" E2 b9 ]% `1 D3 K; E" rStill a method very much used (perhaps the most frequent one).  It is used
4 E' B) Z1 M/ i8 P- Z8 p! [to get SoftICE 'Back Door commands' which gives infos on Breakpoints,  m7 @0 M) c! @, U
or execute SoftICE commands...* w+ `/ u1 E" C; B: o6 g/ ?
It is also used to crash SoftICE and to force it to execute any commands1 {' S& f# x- |# ~% X
(HBOOT...) :-((  ) \2 r6 [# T0 p5 d
3 O# c" y# C# G
Here is a quick description:
, x& Q: L4 y. p  r-AX = 0910h   (Display string in SIce windows)
( U$ N' ^; f2 X-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)" _6 a' X: x* i" d8 H1 |4 Y( Z7 y
-AX = 0912h   (Get breakpoint infos)/ a, o/ b+ w6 t: {7 U
-AX = 0913h   (Set Sice breakpoints)/ N+ H; V; N" W, ?- z
-AX = 0914h   (Remove SIce breakoints)
& r: o" t2 c& c. U4 q/ w- I/ T: ]
3 d: ]3 y. P' BEach time you'll meet this trick, you'll see:- x/ A, X) V- ~& v% f/ r# m7 }
-SI = 4647h
4 H" B0 t# `) R  M8 @# L! e  q-DI = 4A4Dh
/ g9 G. H$ e, O; q- a+ g/ IWhich are the 'magic values' used by SoftIce.
. X/ `  g' M& m% z$ R. TFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
( \9 A8 ^6 h; e* E5 k
) ]+ _. G0 r7 `4 THere is one example from the file "Haspinst.exe" which is the dongle HASP
0 c3 H. W; h( S, X8 B: DEnvelope utility use to protect DOS applications:
- N* c1 ~& H1 z  r+ }& G: w2 K5 ?1 _( X: y; A# L' N# b. f

3 \: m$ V( H) ^4C19:0095   MOV    AX,0911  ; execute command.
- K& R; a5 \' n% x; N7 D4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
1 Y7 m$ g* r2 y9 y, M4C19:009A   MOV    SI,4647  ; 1st magic value.
2 |$ T# f9 h3 T8 J1 A4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
' F; v1 T2 g$ O# K4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)9 Q6 u# V/ O7 r" w* z
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute5 ?7 X% J2 [! V
4C19:00A4   INC    CX# q6 Q9 t0 ~2 y
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute& `  z6 m1 [% E" P3 v* S  J% p
4C19:00A8   JB     0095     ; 6 different commands.
* l0 _# h% O) v2 a+ }# n4C19:00AA   JMP    0002     ; Bad_Guy jmp back.. y" R9 Z, [. l* u  m
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
, L. I& J3 Q* b/ e1 @# K2 J" G* ^
The program will execute 6 different SIce commands located at ds:dx, which4 e9 F5 \. t( w3 d  U9 P, D% L/ H
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
$ G. C) C) K1 ?
% H# ?; ]3 x" R) B  A* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
: i6 D, K/ X3 @' `( H7 U___________________________________________________________________________% g( h2 ?. a8 ^

+ e8 D9 a5 [6 U( d3 a6 |( x) z- Q- `+ W1 e3 n& \: A
Method 03! D! W2 b0 ~' o$ }
=========
9 q; z/ e; @3 q' w" l  J: U1 @0 }( e% l. g8 S! I5 M
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
" r7 I9 @: @1 p7 Y/ e(API Get entry point)
% `, V( d" {( z        9 w! k6 O4 L0 K0 f. d- @6 j
0 P8 {  D" z4 d& s! k+ h' }' \% D
    xor     di,di, B! @8 @9 o5 w
    mov     es,di1 W3 s6 P' I- z0 L
    mov     ax, 1684h       % y5 Z; |* V- d( l
    mov     bx, 0202h       ; VxD ID of winice
2 `9 N  ]8 R" U    int     2Fh* ~, T* R! N: Y: K: W
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
. k& ~! J4 b/ i2 R$ G    add     ax, di& w0 A' L: ?, s: ]  X( l
    test    ax,ax
! N9 E: q0 I. F7 A5 w    jnz     SoftICE_Detected
1 K9 W3 f% r- l0 Y3 `/ L- J+ H5 I" c+ N& D4 R  b" A4 Y3 }) Z
___________________________________________________________________________
# g  Q% i  O1 \, w/ D
+ V6 R+ M) D' n: X# ]" n% dMethod 04* P2 l( F5 B. p2 D+ a1 F
=========
  N5 G, g* J+ e2 s
- E1 |  o" h5 i9 RMethod identical to the preceding one except that it seeks the ID of SoftICE* w. C. j8 q+ |1 P# y' S# c- H% d
GFX VxD.. I& T& z& T, n+ Q$ S- b6 w
9 k. P3 N- ]/ H" T& y; ^! i
    xor     di,di
* K; O2 i: N( [- y: O: e    mov     es,di
1 ]7 i" M4 d! a0 ~* n3 Z6 K5 d    mov     ax, 1684h      
. `2 S/ t  z) V    mov     bx, 7a5Fh       ; VxD ID of SIWVID
1 ~  h+ D; v( o( v# ^) O+ w    int     2fh
! j2 B! T) i5 r1 `0 Z5 n  ^    mov     ax, es          ; ES:DI -&gt; VxD API entry point
& m- ?$ T. P3 ~6 Z* f; f3 s6 j    add     ax, di
/ {4 M% h* h; N) N    test    ax,ax; T8 c' W+ ~: S) a
    jnz     SoftICE_Detected
2 Z4 a: x0 d/ s; G) z( T6 ^( k. y- f7 m/ A
__________________________________________________________________________
5 e3 v2 ?( K* t+ T2 M' y+ B! E. ~" y5 x" H: U7 j- V0 G4 A/ s
: U( v4 o5 {( y; m+ B1 V
Method 05
0 S7 R, i) m; S  b9 ~=========- ]. _+ Z* @! g
5 X' A3 i. i5 z# i
Method seeking the 'magic number' 0F386h returned (in ax) by all system
0 q5 T+ Z) A8 p$ U- Y5 {- h. x9 Ddebugger. It calls the int 41h, function 4Fh.& L# t4 }$ O$ V, y, s
There are several alternatives.  7 j. L7 ?' x4 H8 }7 K' w9 p* X0 G8 v
6 x# y+ P1 l7 h' ]  E5 s
The following one is the simplest:7 Q) G8 `( V5 D( h2 s- U. a( H
# T& i8 [! o/ `6 j- P8 F
    mov     ax,4fh
& \' V# T* X7 R6 m( a6 e    int     41h! C" [; m% w8 d: x
    cmp     ax, 0F386
4 q) W* F! K, o( r: C    jz      SoftICE_detected1 g9 X; g3 C0 y& R% u
4 Y1 |) \7 T5 F. W+ K$ D
; u" l3 ?/ u' _: N4 H
Next method as well as the following one are 2 examples from Stone's
( P% B$ l9 q2 I! l' l"stn-wid.zip" (www.cracking.net):
# u- Q! ]1 ]5 ~  x! J$ `! v* d# ?" f
    mov     bx, cs2 I# z% t: P! V2 a
    lea     dx, int41handler2
/ R* \1 f; n6 \$ C  E" @$ t% w- v( r    xchg    dx, es:[41h*4]1 R% Z. ?  M0 {$ F3 z
    xchg    bx, es:[41h*4+2]
$ t! R; q2 u9 `6 o    mov     ax,4fh
7 K) e6 x/ l1 c    int     41h
& q. E' y" r; z# Z    xchg    dx, es:[41h*4]
; q, }. A2 ~) n% z4 ^- {2 n' M9 q! T    xchg    bx, es:[41h*4+2]
" c9 {" Q8 q8 \3 u- X    cmp     ax, 0f386h
2 T& f: J( L! N. p6 d# B    jz      SoftICE_detected
; {& D, Q4 e6 y& Y$ w- y/ x# Q$ ?( N$ u  H
int41handler2 PROC
. f9 f( P, d  e    iret
( C. t' f' K0 V( j1 Rint41handler2 ENDP
$ T9 d& x4 W1 n% f  p
  u; ?2 |2 o+ @4 _3 K  q* K5 ~" ^& j3 y, D
_________________________________________________________________________
$ L1 G7 K/ e0 s# \& A
4 G5 e. K6 W/ D0 e  P* k
8 }# u. E, C- }/ {' d. n" |Method 06, m- J0 I6 o$ h5 X; u0 P2 l' q
=========/ ], L+ K' \; V$ c, P" Q$ Q
3 K9 K8 W* }. S7 j2 x

  e- b/ Q' w! D# u2nd method similar to the preceding one but more difficult to detect:$ Z# k  e% B% x$ J6 r
2 n  S/ A& q9 D9 Y0 K6 a$ S) D

, H: }# q: Y* y, ]" Y4 a; A/ {int41handler PROC: V1 [; W/ @' r. m/ s* A
    mov     cl,al
' N, y; X4 h3 i2 q    iret1 z0 w& ?$ E  r/ n% e: I
int41handler ENDP0 V% e) E8 a4 X, A

$ z1 s. V, d' `: \- x, d4 D; @2 Z: E/ _  c) L
    xor     ax,ax
6 k( d& e: u& e! ~+ a1 d" N    mov     es,ax
& `& ^7 p5 S/ R* X: d2 b    mov     bx, cs6 ~3 F- f2 c& k4 |9 _3 X3 C( u
    lea     dx, int41handler
; V* l( ^4 P* A3 {9 ]    xchg    dx, es:[41h*4]
8 _2 w* G: L$ D! Z    xchg    bx, es:[41h*4+2]
5 x- Y' R" H5 T! s# ]7 T, W    in      al, 40h
# I2 G6 l9 e( g/ }$ j9 G: U' B    xor     cx,cx* x" }9 R1 }. v+ l; Y
    int     41h) m6 w  b7 h; O3 {' F' \
    xchg    dx, es:[41h*4]% M2 g3 H1 U6 F: w% W# ~
    xchg    bx, es:[41h*4+2]
6 W' O, u3 B! B/ P) {# }5 b. |- V- W4 L    cmp     cl,al
) `9 d: Z2 T" v9 @    jnz     SoftICE_detected$ x) ~" D' Z3 S9 E- j
: |% f0 L" ^$ D0 i& \* |; }8 d: l: ^
_________________________________________________________________________
' t% y& Y; v! x! T) h* [
, e* m* z. _. f& G8 w) pMethod 079 ?% M) K( i% t; ?
=========
7 c. [- B- I! j4 V/ m
" }% @# F; A) F8 |8 XMethod of detection of the WinICE handler in the int68h (V86)
( u! ?& K( W/ L5 t8 X& o( ^
" {( r7 V8 B, {( P- q$ d# B    mov     ah,43h7 L7 ^( h; z: }' B
    int     68h
; T* k* \) g. ]) G    cmp     ax,0F386h
% \5 g7 p4 A4 Z! f    jz      SoftICE_Detected
! B- ]6 ?/ p; n) v" C  ^2 E2 {: F# D  G
2 Z! ]- c1 h* z; u- S; b; H* h. Q
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
% J& [. E( q; l$ y6 n) c- U   app like this:
  \) W. V, @0 p* D) P2 l* o
* C* |: y. G/ ]% X: L" ~9 @4 b   BPX exec_int if ax==68
4 [6 [- {, k+ M. a$ s* y3 s   (function called is located at byte ptr [ebp+1Dh] and client eip is* ~9 H6 D, F" Q3 |7 m+ ~5 m
   located at [ebp+48h] for 32Bit apps)
1 T; _" c  A4 ]6 z, `3 G& |2 Z% C__________________________________________________________________________3 G/ `+ ~* F# V8 U
) O, e# C3 j& @$ F& x) W

; ^) [/ s0 ?2 F7 P% hMethod 08. C* U) J$ K$ G" \7 F- [
=========: \# S( f. i' ^) W) Y7 Y1 R

0 u! t( e6 y+ R1 mIt is not a method of detection of SoftICE but a possibility to crash the; i/ D& d+ A6 D1 d, _+ K* H
system by intercepting int 01h and int 03h and redirecting them to another
& w4 L- p7 s, Broutine.$ ^8 E- N2 C+ V7 e1 g  f
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
2 _) r. X# Q- G& \to the new routine to execute (hangs computer...)
6 P6 x( m7 D6 C" c5 \1 R! ^
! y- E  F6 ~5 X$ t: h+ q8 ~' n3 `0 w    mov     ah, 25h
$ V: y8 v1 z0 }% X# B    mov     al, Int_Number (01h or 03h)
2 }- h. i# Z) l9 k5 V& J    mov     dx, offset New_Int_Routine0 X* c7 e  n% N9 \: {
    int     21h0 M2 W6 R* \( g4 v* I: G
0 U7 {8 W) Q( N' a0 T- G6 O
__________________________________________________________________________) u6 U8 \% @) a# X5 u
# P5 i% U1 e; ]7 V/ I2 [. O/ u# K
Method 09
7 q& u! i& \. h9 |=========
9 p$ e& Y. e" j) l1 }! \! ?# e1 w# J3 ^5 p; E3 ~
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
" D7 f+ O! @9 A: yperformed in ring0 (VxD or a ring3 app using the VxdCall).. H* o& D6 c; R; z  o1 [1 R
The Get_DDB service is used to determine whether or not a VxD is installed: j7 M. h0 }" e% H! L5 f
for the specified device and returns a Device Description Block (in ecx) for, @: ~, {' I& N: m# n4 Z
that device if it is installed.& }. a- k7 Z0 S( o$ @. R. U; K
4 \# N3 p( M$ y3 l9 X4 N
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID+ h: Z( _4 ~8 [( V5 x- ^
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)3 G; g6 Q7 N+ P9 A* l
   VMMCall Get_DDB
3 {" s+ ~+ h  J+ ?6 J4 p9 S   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
7 b( Y0 j* Y9 m. c" D
) m6 W, ^* q3 ?" \3 |' A! ^. w% [Note as well that you can easily detect this method with SoftICE:* G& U' d7 C# ]
   bpx Get_DDB if ax==0202 || ax==7a5fh0 @% a# {+ }! U7 |
. Q$ g0 s' y0 T6 U5 R
__________________________________________________________________________% z  ^# y; p- @5 M2 A9 _

. f% V2 H  X& E# D+ Z% @9 [. m( }Method 10
0 F2 K" Q# ]& y! ?+ @=========
/ m  a2 L: J1 q0 N7 [6 ?+ O: N7 K% {. F% j' A# S! B4 t
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with" N9 k  }: x5 X* i
  SoftICE while the option is enable!!
2 y; K% m$ o! l- l$ H+ _' J/ _( n9 C$ J7 J* A% A+ j
This trick is very efficient:. I# Y# ]1 s* R* N" x7 A9 e
by checking the Debug Registers, you can detect if SoftICE is loaded
, Y" x' j4 j$ K4 }9 @- F/ U(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
' V8 G3 X, k3 D) J" q0 z- [# q( Nthere are some memory breakpoints set (dr0 to dr3) simply by reading their) j( f$ t8 U- P" H6 W5 c5 e( ?
value (in ring0 only). Values can be manipulated and or changed as well3 X7 ?) U4 f6 y! L- s; |0 g+ u9 k
(clearing BPMs for instance)- @, i0 i- i  L( \

9 v; w* Q/ ?3 A( }__________________________________________________________________________
- [& p0 H* s# J+ N: t- O0 g8 A1 X  m
* x1 M. B4 x2 W; LMethod 11
% l' Q" `% \. o4 G=========/ z! l  g7 s, [+ H: g2 p& G

. b/ ~" n! ~/ M' }" rThis method is most known as 'MeltICE' because it has been freely distributed' w5 a& E% e; |/ H) q
via www.winfiles.com. However it was first used by NuMega people to allow
" y- m/ l1 H# q4 a# hSymbol Loader to check if SoftICE was active or not (the code is located& L& v" a' m! S+ G
inside nmtrans.dll).4 z$ q3 O' r/ \8 e5 Z$ B4 S) H

6 z* r. f$ v2 p2 `, {: mThe way it works is very simple:  ^3 g7 j* m5 B' A" _0 ]( }
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
. g# ]9 ?1 E4 |7 G7 ZWinNT) with the CreateFileA API.
! Y& v% b0 Y) f) j
: J: u: x3 A6 G; H/ sHere is a sample (checking for 'SICE'):9 p5 M( Y8 e1 I1 E% u3 L; q3 e

- v  X  d! e8 W( F2 I( WBOOL IsSoftIce95Loaded()2 U1 k$ b1 y* ~
{
, X* v8 p- {2 t2 I9 n9 P: f   HANDLE hFile;  
! e6 }, E" u% P' w& q   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,- |2 p7 J2 B# \: T$ v7 A8 o
                      FILE_SHARE_READ | FILE_SHARE_WRITE,
9 E5 \( a& y3 e1 ~8 Z" I                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);$ b) x5 B- y, }
   if( hFile != INVALID_HANDLE_VALUE )
. l' _, ?8 Y1 G/ }  B5 Z+ Y   {' G' S/ ~9 ?* C6 H
      CloseHandle(hFile);  T4 ^7 d! i7 J: Z
      return TRUE;
4 h* s/ b* f6 n2 N% N- Q# l   }8 G6 E" }2 y2 w" Y$ Z; _
   return FALSE;
4 l$ u! P( D# C; k' ~6 g/ F; Z- s}
2 m  \1 ~& C1 s& X' n8 l, N
8 Z! E8 Y3 `8 jAlthough this trick calls the CreateFileA function, don't even expect to be
9 _  y' m5 V# i  xable to intercept it by installing a IFS hook: it will not work, no way!
% q- X" h  \7 G) _; `In fact, after the call to CreateFileA it will get through VWIN32 0x001F, z/ s, ?) u% s* u. \2 K  x
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)3 r/ q0 I8 p. I& }: e
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
4 k. ^- V7 Z% f4 ffield.: P& K- p/ W3 I% T) |  b5 V
In fact, its purpose is not to load/unload VxDs but only to send a
' f7 @. I7 o) ^$ mW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)5 V: d# I) [: _7 s: d9 ^0 A
to the VxD Control_Dispatch proc (how the hell a shareware soft could try! u4 @9 u7 n& h' }: T9 p
to load/unload a non-dynamically loadable driver such as SoftICE ;-).$ y! P* |3 }9 F# \* S4 [
If the VxD is loaded, it will always clear eax and the Carry flag to allow; f8 M1 o6 E1 F2 N5 C, f
its handle to be opened and then, will be detected.
, W3 o4 E2 t+ x5 |4 b% d% VYou can check that simply by hooking Winice.exe control proc entry point. o  q& K9 b' ^: `' l, ~
while running MeltICE.
* o* x5 K6 U9 n" x# A( ]2 e
5 u2 z  h3 z. Y( W6 x  e" i$ ]7 m" z' M. y" C& C" Y
  00401067:  push      00402025    ; \\.\SICE8 R& |2 ^/ J2 f& o, m9 X7 K
  0040106C:  call      CreateFileA# Y" F$ j8 ~% {' ]* n
  00401071:  cmp       eax,-001! J' Y4 o8 \! ~* F
  00401074:  je        004010911 u( H! D& t! z2 R* }% b/ \

' b9 b2 \- Y) a. [* {3 Z- U# i3 v" [1 G, @% W) i) n% y; K- `
There could be hundreds of BPX you could use to detect this trick.+ g& |) [; L$ |$ Y# \8 s# Y
-The most classical one is:8 @6 G1 E) H# L2 f, h) k
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
' b1 c: D; n+ Z( p) C    *(esp-&gt;4+4)=='NTIC'" I7 ?. ?6 J# n7 X) D
" s: R9 N5 o  P5 F( a+ B& U
-The most exotic ones (could be very slooooow :-(
' R3 N: e0 j# n) Q   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  ! k, B0 w- }+ {1 U* e
     ;will break 3 times :-(
' W) O5 R/ ^% C8 A$ n: U& I# c8 B: ?1 m. d2 d2 K6 E, H5 s  b
-or (a bit) faster: * i* u' N6 K+ J
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
  n8 [. |8 f, c0 f  f$ t% ~  ~' e
% ~' ?- q* q. w, g2 g+ t% M   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  ' `! ]7 P% P: K' o1 ], E. W
     ;will break 3 times :-(* ]8 X  C1 q7 }  ^/ K0 ]

& J2 _1 v" [; @3 _! U/ r; \  o-Much faster:0 k4 ]7 ?, A$ o
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'5 v. ^" A9 t; `! J. H
& N# X+ B5 q5 o( p. j% ^
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen. }+ t. L' @4 m; r0 j. N
function to do the same job:  @$ @+ s4 w, c. F: u, q$ u
) I$ y9 X) a& p: V7 I9 ?7 @
   push    00                        ; OF_READ8 E& N& \- m' `+ N) K
   mov     eax,[00656634]            ; '\\.\SICE',0
" [4 b+ C5 P& z4 v   push    eax7 [# m+ h8 P$ P. N
   call    KERNEL32!_lopen2 S% {: c8 D. H
   inc     eax6 p3 f' s% k, D9 ?
   jnz     00650589                  ; detected4 U- c" N8 m2 H
   push    00                        ; OF_READ0 Q2 ?$ ~- ^0 N$ x& D
   mov     eax,[00656638]            ; '\\.\SICE'4 j7 S  L3 D/ g( I" c
   push    eax
/ @) ^9 ^# V1 g! H2 z$ @: h9 C; D   call    KERNEL32!_lopen
8 n4 M( J  d# j2 P. @   inc     eax9 S8 j; l0 [( X- y% q
   jz      006505ae                  ; not detected
2 q, Z' l4 H) b4 c& k" Q5 n$ F
+ Q: [; I$ j8 I  o6 \' k8 p6 f! I6 m6 {! N0 E1 }( d% ^8 B
__________________________________________________________________________
0 M( [% y+ b% R- w& u$ J; }2 V5 z- e* J3 F* @- O* @
Method 12
, G* R: ~! {# x5 g=========  a8 E6 @" W( z8 m8 ~5 Y

5 |/ \! q3 N$ F" c  ^0 \& c& M4 xThis trick is similar to int41h/4fh Debugger installation check (code 05/ Q! s+ A5 V, S1 }  Q1 i8 L
&amp; 06) but very limited because it's only available for Win95/98 (not NT)
) j1 C/ i' U  [" uas it uses the VxDCall backdoor. This detection was found in Bleem Demo.6 H8 R. f- W/ U
) V* N+ o0 r) V" P) z" P- [
   push  0000004fh         ; function 4fh, u4 G. L8 H% @9 L
   push  002a002ah         ; high word specifies which VxD (VWIN32)
- W/ L1 V$ `6 g) z7 f  A                           ; low word specifies which service
7 X2 s' T# ]; V* O4 c; ^                             (VWIN32_Int41Dispatch)8 o' A# [# s& q6 n- Q9 ?
   call  Kernel32!ORD_001  ; VxdCall' {9 I& B$ u7 p; e& m, v, _
   cmp   ax, 0f386h        ; magic number returned by system debuggers; Q) n3 ~& W6 x/ E1 y# }2 M
   jz    SoftICE_detected7 U( D% A: ~2 M6 t7 W9 [& @* z
( n3 C1 P& s# l- ]
Here again, several ways to detect it:
4 L  i9 W1 K7 `( E, n9 E4 f! A$ o) v" }
    BPINT 41 if ax==4f
# z) `+ F/ |' c
: E3 K& u' T8 O0 W% e    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
* K) e% n$ `) l) c8 F5 g
4 d- [# b3 z  g% _" J) ~8 O$ d    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
. @1 e9 Z  ^' Q8 _- y0 B) g% g; n( [* M
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
0 {5 q0 J, C* F1 c1 H
3 k0 o$ [7 ^% k, H& s7 t; B! y" w: s__________________________________________________________________________2 ^8 j- B  L+ Y9 p+ ~
$ H$ F2 l+ o1 R5 t
Method 13
1 A( Y6 [4 U7 g( ]; C/ K# h& D=========
% R- B3 q3 D4 m# ?/ x9 p  s3 ^  g4 d8 {  i/ ?+ X$ j
Not a real method of detection, but a good way to know if SoftICE is( G$ b5 X" J3 y; T1 G* ]
installed on a computer and to locate its installation directory.5 z$ m; m9 y" J5 g9 T% q5 f
It is used by few softs which access the following registry keys (usually #2) :
& {( U5 l( |- e3 E0 V1 K7 I. {: ~' i- `3 S' `
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion/ {% m/ s: b2 a8 ?) |. i6 `  p/ f
\Uninstall\SoftICE
2 u( N7 }& _. L4 P5 t, n1 ^-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
9 Q$ s% o; N( M. h. `9 W, k5 Y5 |( G-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion2 J. H, p  i0 Q% V* y. x
\App Paths\Loader32.Exe
! Z$ T7 X$ A% g: r
+ A% S& G+ \3 Y- {, ?  g
! N! q% W6 }4 ?& f- kNote that some nasty apps could then erase all files from SoftICE directory+ H" D/ O  A! u% F8 S# \7 Q
(I faced that once :-(
; g* E6 [6 K$ Q$ M4 G8 D, |; A7 i( ?" j( M  l# `
Useful breakpoint to detect it:4 y5 ~* ?3 U: l" `) C! G
/ ^! q" b- \" y" f; Z; ?5 a
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE': M1 @* G- y  e, i8 q8 \

, s& z, \) R8 a, V__________________________________________________________________________: g4 C/ Y4 ~0 k
0 x& s; v8 h& n% s0 B: B1 S, p& z  Z% P
& {8 s& Z4 e% z' c% P/ f& Q1 e
Method 14
8 m- R9 q; [) A% \2 x=========) @9 I5 |% K; k  s3 J" v

9 ^0 M( n8 p/ }) W0 J9 ?A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose" r4 B% |: F- ~8 W
is to determines whether a debugger is running on your system (ring0 only).* T3 p9 G5 G$ U3 ]  I" ]  }
8 c, I1 |. s2 g- U$ `
   VMMCall Test_Debug_Installed& v4 _) r. F/ F  Y4 k
   je      not_installed0 L9 d$ X5 M9 L

! O  Z  W, ~* v8 x/ W* ZThis service just checks a flag.0 k2 P* H, r/ e& t1 z. x
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部