About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
0 i" j% B/ y( I% `) z1 n<TBODY>
. ]: K. g: C4 Q9 _<TR>! K3 b7 s" p7 ^
<TD><PRE>Method 01
% J- `4 o2 }* z: M- K5 d=========
" R0 F( o/ @, T& E
0 ?* a- I, M2 U8 Z8 j+ B. rThis method of detection of SoftICE (as well as the following one) is* \: z& S* k0 X( V
used by the majority of packers/encryptors found on Internet.$ P4 z& @0 [. J; h
It seeks the signature of BoundsChecker in SoftICE
5 T$ R! ]5 }( h+ s' Y  j: q+ K/ f1 k" X! F4 L; d& m
    mov     ebp, 04243484Bh        ; 'BCHK'  w$ m+ H3 L4 l0 M# l1 \0 a1 b5 ^
    mov     ax, 04h# f* F) W4 i7 I9 @3 o  ?* j
    int     3      
% ?( [2 A2 S! e, }    cmp     al,46 N7 Z: d( \: Q
    jnz     SoftICE_Detected# h' ?: e' i' v3 A1 j9 H
# r. b7 m) T3 K& r6 t: T
___________________________________________________________________________
3 v7 @8 T6 Q+ k' E4 k
6 Y) b$ Y1 R" [+ y0 j9 @' G" O3 PMethod 021 x# B' R0 c! d3 T: Q4 J
=========  U, `5 j8 y  s) A3 m

; |6 C5 K3 C+ J1 ?Still a method very much used (perhaps the most frequent one).  It is used
% m; d4 ?& }3 V1 c4 Fto get SoftICE 'Back Door commands' which gives infos on Breakpoints,
% ?+ \1 d: D$ ^6 J3 P, _; Wor execute SoftICE commands...- g! i1 l! d+ g7 N4 C' A) p
It is also used to crash SoftICE and to force it to execute any commands& g$ e# j- O2 R2 k* W5 v. a6 T
(HBOOT...) :-((  % S4 k9 y7 k! S# c
9 Y" R# @+ C: p- m( t
Here is a quick description:
* c( k4 `/ Z' @-AX = 0910h   (Display string in SIce windows)
2 X8 [7 ]+ _5 t) p6 u: ?5 p3 X  W-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
! V/ V2 j& o0 m-AX = 0912h   (Get breakpoint infos)
. E( m$ ]' K. b8 D3 T8 N-AX = 0913h   (Set Sice breakpoints)
4 V2 b! ]  ?# C5 B8 o-AX = 0914h   (Remove SIce breakoints)
: ?, y4 i* D# X$ `, M  c7 l3 _2 ?
+ c. G) P5 E' s1 h5 s8 d6 CEach time you'll meet this trick, you'll see:
5 S( `! w3 [6 r% `+ X-SI = 4647h
4 a0 R, ~- l8 K3 y- |( ^* X' H-DI = 4A4Dh
' N$ x* ?" L3 A0 j2 u6 hWhich are the 'magic values' used by SoftIce.
7 u+ D$ K5 X/ S- ?, @For more informations, see "Ralf Brown Interrupt list" chapter int 03h.+ l' O- b& P" ?- _$ p

- x# j0 b; `) vHere is one example from the file "Haspinst.exe" which is the dongle HASP! B4 `3 s  L( g- }( j5 u6 O9 o
Envelope utility use to protect DOS applications:
$ Q' U9 B* ~3 K3 @
7 f* [* I4 o8 t- b/ H/ F- s5 h% N& O: Q/ E* H7 L% @
4C19:0095   MOV    AX,0911  ; execute command.
1 K  @! Y! M% n/ V0 G. u6 v4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).1 b) n1 X0 Y4 J2 x
4C19:009A   MOV    SI,4647  ; 1st magic value.
" q# R; a6 `* o4C19:009D   MOV    DI,4A4D  ; 2nd magic value.) i$ l% R/ s1 W2 t8 I0 q
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
* H6 s4 q( v5 P' c  p) D4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
+ o: b  q( A: ]1 e# N! h# z4C19:00A4   INC    CX; f* K) v! A1 C1 B$ W1 i4 p7 S. H
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
0 Y: v- O0 ]; D  q4C19:00A8   JB     0095     ; 6 different commands.
( g3 v0 _0 u  d- q4C19:00AA   JMP    0002     ; Bad_Guy jmp back.! J4 v, A' D- n/ _
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)  @; @. }* B- I

( e+ [% S7 s  g: aThe program will execute 6 different SIce commands located at ds:dx, which
0 o# E, n+ z  \are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.$ T. R8 F  c' [, J+ e
; I; m- [, V# \' Z) ~8 n9 V
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
+ j6 D# M2 s( Q9 q! `* i( G___________________________________________________________________________
* g! U; t2 Q5 J8 F7 V- Z% i* I6 M# \) F

$ ]  s" M6 `( u$ `/ @Method 03
2 s( @5 O6 `4 g=========
4 Y' {/ N7 ~& ]$ A! ^
$ q' y. [0 z- @- q! g5 @( @% @Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h3 r4 M7 Y) w, N8 x" E
(API Get entry point)! Q! H  t. L1 r0 Q- E( [! m0 K* n
        
9 E; ~' G- j5 z) g! @& s, p
3 w. G' z3 q# Z3 R8 u' b    xor     di,di/ Z8 Y8 U. r1 P  ~
    mov     es,di
% T2 @) g2 Q: |6 N! C: e3 M% H9 x    mov     ax, 1684h       " h. s) B3 y) \8 X. w3 }. X
    mov     bx, 0202h       ; VxD ID of winice
# g; J9 k: }+ P5 [7 j    int     2Fh
* ~# ?9 H& j6 y' R, r2 s    mov     ax, es          ; ES:DI -&gt; VxD API entry point; \& }/ u4 _2 e1 S1 B
    add     ax, di
1 V. }' u* Z) g6 \8 L    test    ax,ax
- z+ \1 `# Q$ I7 P( N9 h    jnz     SoftICE_Detected
" A3 O9 B2 H5 T; c2 z( R4 t0 V5 }& Y% ~5 {8 J3 `! K
___________________________________________________________________________8 x% E# Q7 n; h3 A* y5 e' ^

1 t- Y% Z0 T: l: h- VMethod 04
+ n& E9 i: Q0 a0 {=========
# ?, \2 a7 p0 p. H+ i1 b' l6 n
& E2 A7 `8 z! z- x3 JMethod identical to the preceding one except that it seeks the ID of SoftICE7 B$ J1 A: p5 u/ H' h
GFX VxD.5 |* g; j9 J2 ^+ y" p" b  C' P0 r
' Z0 U" Q7 ]4 R8 p  T
    xor     di,di6 s% f& L0 X, v  `
    mov     es,di
, e0 x, m% A) l1 q8 T; Z    mov     ax, 1684h      
3 v. p1 h6 D9 H, m3 _& N: C6 Z# H    mov     bx, 7a5Fh       ; VxD ID of SIWVID: e0 B: d0 c5 ^1 d# Y3 ]* t
    int     2fh9 w" `8 x0 p! \1 S! j
    mov     ax, es          ; ES:DI -&gt; VxD API entry point  r7 S' F3 Y* q
    add     ax, di
1 ^, F: {+ o+ u$ V: o& z( z* T, @/ I    test    ax,ax
' k, A. A/ G: C, ~: W1 J; d    jnz     SoftICE_Detected' x$ C# g* n; n7 s# V( J

; b+ m9 O& y2 J6 @6 h__________________________________________________________________________
5 L5 a4 E6 B$ \; E4 P  N; S, a$ {
3 f+ D6 U% m" d3 I4 i7 Q- {3 Z3 h8 h
Method 05; {% L, `: c# X+ K" {
=========! V  Y# P. e1 L, Z: g6 u# [; ^

; m& b) V: o2 Y. mMethod seeking the 'magic number' 0F386h returned (in ax) by all system
, I5 v& f: q& tdebugger. It calls the int 41h, function 4Fh.
+ A' I" a5 i) @# l: h+ tThere are several alternatives.  
3 x- Q( h" A) N( {8 i+ j! e4 N) t0 d! E; ~
The following one is the simplest:
, |& `8 R- ?: G0 e5 j, I
3 H, U, q- o! }" ?: E! @0 G6 m    mov     ax,4fh
: E# w. A) M, w$ _" {    int     41h" o% ?' @( D- G
    cmp     ax, 0F386
# m( o- t( L; n& f, b    jz      SoftICE_detected: Q- L# q! @" N! I3 X8 o3 N

) Z! i& r2 a. `
, |' e1 y6 _* h1 {# tNext method as well as the following one are 2 examples from Stone's # ~3 J! V) z$ P. R; L6 h& k
"stn-wid.zip" (www.cracking.net):
: g# n0 s' @' f
. _; Y. n3 N0 O- I    mov     bx, cs
0 L& M4 ?" v, w4 x3 e4 ^- G7 M    lea     dx, int41handler2+ v, {/ f, V. x( c
    xchg    dx, es:[41h*4]
! ~* |/ F7 k# H4 ^0 F  v    xchg    bx, es:[41h*4+2]4 c$ ]9 m7 m( V
    mov     ax,4fh' ]4 }" m8 h/ B% O# ]
    int     41h0 X5 Z. b: S$ T4 A7 J; t. n
    xchg    dx, es:[41h*4]
0 c6 i( r3 T: F/ e6 z% c    xchg    bx, es:[41h*4+2]% n+ r7 J# J4 M/ |! z2 S/ F) J3 N
    cmp     ax, 0f386h4 l8 S$ d7 U& t
    jz      SoftICE_detected
9 u* C6 E3 K# ]2 P! o9 }; t1 H5 B, ^
int41handler2 PROC
% E- u/ p# r# {+ M* r    iret% Y9 m& _! j0 G# s8 \, M
int41handler2 ENDP
2 H- b4 j, Y: B, L2 D# @, j8 [* ?. U

& Y, b6 e& X& z0 z& `% ~7 L_________________________________________________________________________2 y' d9 w( I9 y; S, e7 i

: c$ ]1 j3 s8 G' I0 k
$ c/ L, ^5 [; M! r" Q# r& a, s" KMethod 06
1 Y% Q1 x; P5 Y=========& ^8 w- n0 L' C; q& ^7 t
. _0 F- D: r! p3 [0 L" l

: e- A! z% W( j: H4 \. [% k4 A1 X2nd method similar to the preceding one but more difficult to detect:9 O+ K) b1 {# u, i1 d# W

$ b6 Q, T% Z& b" T+ u) D5 \* c& ^8 @$ r* ]- H7 J
int41handler PROC2 i6 v' L! o( [0 q
    mov     cl,al5 |% I8 Q& s* _9 y! L% X
    iret
2 n5 M& A  _! s$ w; G7 Yint41handler ENDP( R% V* O# O# {% o+ Z3 i5 ~4 i

7 Y* S, O$ t$ V
/ E9 p5 i6 A5 C" c% {    xor     ax,ax2 U0 f* S; [2 D6 K; F6 y$ \
    mov     es,ax
# ^$ _7 m0 @0 V    mov     bx, cs" [5 g0 |4 Z- a; g& w3 e2 m
    lea     dx, int41handler: E: N  A9 R- W) S/ }  T
    xchg    dx, es:[41h*4]5 t8 Q/ @4 m$ y, F* Q1 j
    xchg    bx, es:[41h*4+2]5 W7 U2 C1 b1 }5 d/ [) y; A
    in      al, 40h: ~) l; X1 U" g8 j; `% m0 P
    xor     cx,cx
" ~$ ]+ J! @( U1 q' Q# Z    int     41h
9 z" X" C# N" y- [, Q" t! o% L0 _    xchg    dx, es:[41h*4]5 V( A% E( q2 Y; S0 }9 ?' Z. r
    xchg    bx, es:[41h*4+2]
* [4 \- I+ [# ~# V    cmp     cl,al5 E/ t' L. L3 s1 H( R6 f. r
    jnz     SoftICE_detected3 K+ d: |8 {6 K
$ S0 T/ i+ a8 ~1 O4 s( {  K
_________________________________________________________________________% i4 i0 U. a+ H2 _4 G2 b* f5 N1 _

9 ]. g# N) {' q* k% \Method 078 D" F; _: M3 e
=========
: a* n- Y- H2 Y" g/ X& l( i
- [3 k# ]4 \: r+ S% B% ~4 NMethod of detection of the WinICE handler in the int68h (V86)
5 S/ _/ r+ q# z1 z! E  }
. h7 G8 b7 b: b0 o$ W/ e- ~    mov     ah,43h
1 j  o$ b! r$ I/ J' M& h$ [: S    int     68h
0 f+ N7 J+ f2 f6 Z) e    cmp     ax,0F386h
9 E# H6 K+ _, p  r: o    jz      SoftICE_Detected
1 B" T( D+ O# A0 a, g! |. \" X3 i0 U- P0 s( m
+ v! n& o/ Z8 O/ N1 B( j. a
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit& T. P" \3 U  I! P; |1 u
   app like this:9 z' V' b, E& M& `1 V
$ v! R+ L, C) ]: O& g8 A+ i
   BPX exec_int if ax==68; X! G! u' H5 ]% _, m8 h
   (function called is located at byte ptr [ebp+1Dh] and client eip is% }# a8 I! A" t% X& s/ Z( G
   located at [ebp+48h] for 32Bit apps)
6 G0 J' }! {* \4 a# Y__________________________________________________________________________- |0 K2 p/ r4 K; ^2 _

$ D4 Y3 R0 V8 b5 G9 A  E; V% E: i
Method 08: U2 v8 Z& v7 I+ l
=========
8 B7 ]) x' c+ ]( \$ v% e$ I2 r, |' G* x% {% c! y
It is not a method of detection of SoftICE but a possibility to crash the
9 d) G$ t  l# r1 Y, ^4 _- ]4 ?system by intercepting int 01h and int 03h and redirecting them to another
! ?9 \, w. J3 \routine.
+ \/ n! y/ W; [5 K% D6 \$ zIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points0 V  G0 H4 U5 t  V" g
to the new routine to execute (hangs computer...)$ P) l/ u$ S. [: k
3 J4 g' k3 `! H8 B" n3 k
    mov     ah, 25h2 s& ?# h. F6 ]! T  e- ~- X
    mov     al, Int_Number (01h or 03h)/ J( ~3 q4 K8 l9 h3 {, M  X: x- {
    mov     dx, offset New_Int_Routine
( z8 h3 y+ w  W- e0 y    int     21h6 b& Y! ^3 t. c/ p# y" k

0 Y2 K% ~; |# P6 [) x% E! ]( Z; l__________________________________________________________________________1 p1 B3 C# l$ L0 Y

- `( J7 H1 Z% X! XMethod 09# d* `1 O8 a1 j6 z+ B2 |
=========& S1 Z4 l8 L7 A# ?+ X: v  u3 i
$ x0 x9 u$ ?3 g+ [6 @
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only: Y4 x; l+ A) ]1 U1 ^0 z, W
performed in ring0 (VxD or a ring3 app using the VxdCall).% u' J# h! u% H. J
The Get_DDB service is used to determine whether or not a VxD is installed$ j4 h- O% a8 P4 Y+ f. E5 ?. S
for the specified device and returns a Device Description Block (in ecx) for6 {0 x9 y0 I9 d9 |: w8 x% b8 y
that device if it is installed.
5 H7 ]0 V+ X* A: _* ~
2 D7 o; O2 G5 p4 @, J2 a$ P" _   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
1 q8 Z- ^6 C- R* y% `7 m   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
$ b* p0 g  P- X# }. x4 n5 z   VMMCall Get_DDB
# H8 p4 U8 [" Q$ z' O   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed* e/ F8 V" |& T0 D3 E

# f3 S$ v4 U+ |: u9 z# B! C% u0 MNote as well that you can easily detect this method with SoftICE:( @' ?, z* `4 J! b5 _
   bpx Get_DDB if ax==0202 || ax==7a5fh# H8 Y7 {1 i/ U4 K+ `) h0 r: f' ^
3 h5 d0 k2 D. T1 V7 |
__________________________________________________________________________) u7 Y# h# \# U5 `2 h

6 X: q! q( d% X# VMethod 10* p7 P; c3 B0 J
=========1 I7 j: V6 T7 ]& S

- i8 E5 {9 Y* m7 P. K% {=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
7 y( u, L& Z/ E" L  SoftICE while the option is enable!!  R$ [+ d% j% F8 n: m6 x2 p

# a( D) ?; C8 f' d' n( QThis trick is very efficient:2 x$ |7 C/ e8 h$ C
by checking the Debug Registers, you can detect if SoftICE is loaded0 O/ a9 f4 a! b, l5 s! o
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if: Z2 \5 K1 v2 p$ ]& E/ u
there are some memory breakpoints set (dr0 to dr3) simply by reading their) _1 m) c: J4 N4 |; D/ f  r
value (in ring0 only). Values can be manipulated and or changed as well3 u' M% H# Y9 _8 P( X
(clearing BPMs for instance)
$ T) z1 D8 g: t5 C) L7 Q
. m* N$ M# ^5 K__________________________________________________________________________8 l7 }6 o8 q1 ~1 N3 J0 T
& p# l7 ~. {0 Y, E
Method 11
! Q" ]' K# i8 {; O1 K7 f=========1 y) g( a( q/ i; E

. q0 g% u. D7 W/ @. A8 O. d' VThis method is most known as 'MeltICE' because it has been freely distributed3 _- G8 P. w$ t, ^+ ^2 d, p
via www.winfiles.com. However it was first used by NuMega people to allow! u' P- I, c' b) ]/ j$ U( u
Symbol Loader to check if SoftICE was active or not (the code is located
: [/ A, s: D* _( ginside nmtrans.dll)./ i5 K* L8 I6 ^

* p; U, p) Q2 h4 M4 P+ w( kThe way it works is very simple:
: U# N% W5 f  EIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
% x/ P! N( A" j  E, c1 hWinNT) with the CreateFileA API.0 C! z% v5 f  L* ]* U3 p9 {
% u" x+ N1 [1 m# K7 z
Here is a sample (checking for 'SICE'):4 ^8 r: P* S( \# v

4 j, S) d- G) p- [# T! S+ RBOOL IsSoftIce95Loaded()5 o" A& V5 }& t( l6 w
{7 A4 r# l2 o, t. r
   HANDLE hFile;  
! d4 M& }3 }  J: A! K   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
! ?# X' N! s1 Q8 _& |" E' e                      FILE_SHARE_READ | FILE_SHARE_WRITE," l3 h( t0 L% l, G  a2 i/ b3 t2 K  j
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);) z) L3 v3 E6 o/ j# @
   if( hFile != INVALID_HANDLE_VALUE )$ `# t0 t1 h0 ~7 o$ K
   {! W4 B9 \* W1 N$ n2 y0 s
      CloseHandle(hFile);
! O; C- L+ S, P$ e7 T1 S& I! E8 [      return TRUE;
- B$ f# r' C0 Z% u   }) w5 q: e# h3 Q2 n% u! W: I: h
   return FALSE;" g/ m0 @/ w/ {2 m6 u0 y
}
; J! M2 m2 n  i" R9 U$ Y1 \
4 U, w) l! L, k  [9 {" LAlthough this trick calls the CreateFileA function, don't even expect to be
  v% \! g+ q1 L: Y( j) mable to intercept it by installing a IFS hook: it will not work, no way!
- X+ m, k) t. c- b: |$ ^In fact, after the call to CreateFileA it will get through VWIN32 0x001F, w# l) ?% j+ n6 l$ U! w
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)9 B  a+ A4 @3 h' ]# ?* {" q
and then browse the DDB list until it find the VxD and its DDB_Control_Proc- G+ ^. e- O' j" ]
field.
8 S8 X3 J5 \# V/ x2 {9 M7 |In fact, its purpose is not to load/unload VxDs but only to send a " o# |- }* O) k0 H; J
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
8 j, i3 D! N3 {3 Q& yto the VxD Control_Dispatch proc (how the hell a shareware soft could try1 ^% f  e; w, Z1 {+ g* H
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
% u, P7 b% A# X# TIf the VxD is loaded, it will always clear eax and the Carry flag to allow% B# C8 F* B3 y/ N
its handle to be opened and then, will be detected.4 u8 X( W: S! S6 y' U# b
You can check that simply by hooking Winice.exe control proc entry point
8 z( S( Z8 D, twhile running MeltICE.7 `& c% H+ q  O5 w/ {' ^( b& D
4 n; A) F: X4 R' r: M& y' I

$ X0 C% ~0 M9 R; b4 g& G$ M  00401067:  push      00402025    ; \\.\SICE
# V$ {5 }: J- r; @  0040106C:  call      CreateFileA
' }4 q% X( |. \5 \. b! u  00401071:  cmp       eax,-001$ b. w& ^$ X$ F) x3 N& u
  00401074:  je        004010910 l, Q, I# O0 x) l, [2 `

/ N5 t! o) z5 C& f# U
$ d8 P0 a4 }& _8 i2 _There could be hundreds of BPX you could use to detect this trick.( `6 _: \: d& {! ~
-The most classical one is:0 w! T3 h9 @0 t% j# X
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
1 c9 V+ ^# m8 T( D    *(esp-&gt;4+4)=='NTIC'
3 K% G* {+ ~( W* P( n9 B% O$ ~
' N7 ^6 T% R7 ~! a7 ~3 j) D/ s; \) v-The most exotic ones (could be very slooooow :-(9 {3 N* N' @. A4 Y" g
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  ( r) Z: \7 Q1 u6 r) a' [
     ;will break 3 times :-(( |6 L9 ]( [  f9 e0 s) w" w! E3 a8 r

* g: t" d' k' U, v-or (a bit) faster: & ]6 \" w: N- D
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')/ w+ T5 _, w" N0 A  F

$ S2 t4 ~8 V: h   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
: t' c! B1 _  U/ M, J  Y, I     ;will break 3 times :-(! P8 P8 H1 h/ [
; t5 |  N3 o& ]# O7 M
-Much faster:
5 K* o, o+ n) v) c4 T$ k9 P8 c   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
8 k& F' v, I1 M$ n$ q+ ?% [
* y) c+ T7 C) }) [9 S5 ANote also that some programs (like AZPR3.00) use de old 16-bit _lopen
9 {1 X% h' @# P# A" afunction to do the same job:
9 Q8 Y+ X" U: @4 M
$ L0 ^2 u3 v/ Q0 Q3 c' J   push    00                        ; OF_READ% G- E" x% h. H; u& y. g
   mov     eax,[00656634]            ; '\\.\SICE',0. I; h# }6 e9 b8 h7 B# |4 e
   push    eax
- Q6 @5 f0 g: g9 F   call    KERNEL32!_lopen
+ n& N& p0 h6 x. d- t. }+ A   inc     eax
' @9 \# d; P& G% [) Z# x! r7 |   jnz     00650589                  ; detected
  V% f5 e2 u% l/ u   push    00                        ; OF_READ% I7 S3 g' L' P' m
   mov     eax,[00656638]            ; '\\.\SICE'
7 o- `& n4 N5 Z; C4 p$ Z4 _& |   push    eax% _4 D5 K8 O& \3 r, i
   call    KERNEL32!_lopen
& K; @: X6 W, {3 g   inc     eax  I3 p" k( q" s+ y
   jz      006505ae                  ; not detected" c) e/ Z. f  A+ q) _# i3 }' f) k  m$ Y

5 c- G: ~% {6 C' M3 G
8 G- y( @2 c  Q__________________________________________________________________________8 s) m8 y( o/ R, d- S
, x5 C# z) |! Z4 P% r* S) x
Method 12
  f, m$ b3 l- `3 f- U  L=========& Z# g% O" F+ T- r# h
; I& c  ^. ]3 _2 R5 B6 x  U5 |2 j
This trick is similar to int41h/4fh Debugger installation check (code 05
& X! f" H0 b4 K/ p& X( b7 ?) R&amp; 06) but very limited because it's only available for Win95/98 (not NT)
" T; @& ~+ ]0 a5 S; L. U# u2 Tas it uses the VxDCall backdoor. This detection was found in Bleem Demo.' b0 _' e2 Z$ B  N& o
# D6 q6 t! [9 q8 J7 ~* ]
   push  0000004fh         ; function 4fh
) q& k2 W0 y: M7 j8 w   push  002a002ah         ; high word specifies which VxD (VWIN32)
* u3 Q) \) I/ _! S/ V                           ; low word specifies which service
% Z3 b) _  R* R  b, z                             (VWIN32_Int41Dispatch)' j8 C2 Q) s: m  a1 `9 Z& b
   call  Kernel32!ORD_001  ; VxdCall- d6 y4 _, k3 L/ x& s- Q% ~# `
   cmp   ax, 0f386h        ; magic number returned by system debuggers
8 {! j8 [8 ]8 V   jz    SoftICE_detected
- G. N8 ^0 ~' U/ u' S& o/ f7 L2 ]: @6 V2 j0 P0 [
Here again, several ways to detect it:
/ l$ v8 r' Q; _# q, q# Q  u. n
' [# M3 z: N1 B, c/ ?1 P    BPINT 41 if ax==4f
( X) g4 g3 g) _! n. B; I) i9 D% ]. ^" L
5 a3 k3 r% e3 a/ Y    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one* B- e: w& L2 |! _7 d) z
9 @! z/ x6 n. l4 y% v
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A  P0 ?4 x  y) y
7 ~% x: R; m' e/ h4 V  t
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!% s, l( q) g$ I( t8 \, L

4 j; t* x' A. a0 ^( n4 l3 J% U__________________________________________________________________________) _0 i3 ~& \7 B- ]5 J+ H
4 p( K3 g) W$ O+ t8 v
Method 13
! W3 I7 x% u6 W7 q! W$ o=========! f) r2 b, d& j; @2 T8 x9 i) W1 s' K
7 h( w2 r/ o8 P; F8 x! B
Not a real method of detection, but a good way to know if SoftICE is; h, Y/ X5 u( M+ ]7 V$ _
installed on a computer and to locate its installation directory.
) S9 ^2 t8 v( x. B2 |1 ]& nIt is used by few softs which access the following registry keys (usually #2) :) \' a3 ~3 W! z. X  E( g" {
9 q" n: O" v9 i/ ]/ V0 z
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion" N7 p4 l) ^# S0 @; ^' c4 T5 e
\Uninstall\SoftICE
! N+ c: g# b; R8 J0 L/ R-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
; ~7 z1 A7 }0 q7 m# V4 c1 T-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion8 ?" j4 I& I7 S8 Q5 g. z; P4 _
\App Paths\Loader32.Exe8 \+ Z* _" W! {9 w7 k* R; F0 A! h

" C5 q4 q- o; s  h+ N8 G! {6 h, F" `6 j9 N6 I8 Y; C( @9 _. s7 k
Note that some nasty apps could then erase all files from SoftICE directory1 D% H) d0 V( b$ o- Z' w& n
(I faced that once :-(
1 h' a9 M: ^" R; j
9 N6 _8 b5 M6 I) H! v3 W5 C/ j9 ]Useful breakpoint to detect it:
" C3 Q9 d4 I1 J8 H
8 n8 T8 Z0 E7 l+ W     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
, J9 B8 `! r) p1 z; Q5 i; o2 s" d+ ^- D: r$ X. s- R2 O3 z! \
__________________________________________________________________________
" x5 ]6 H9 G$ E" s7 J2 K
# b! p* l4 E1 [/ L! J
0 ]9 t& N0 O( Z& tMethod 14
5 k: C5 c+ _1 B, V# N, H0 i=========
; G( [  b4 v3 W4 j, K+ E* I
3 w1 L9 @2 H% _+ \# [A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
9 ^5 P# F( D! I, q) Ris to determines whether a debugger is running on your system (ring0 only).
7 l* o4 K+ V% F3 e' o* k& ?+ K; @
5 M  ]( K# l6 D, f8 e4 K8 a' D3 R   VMMCall Test_Debug_Installed
0 C" `# k6 P, ?" n( P8 ^9 _/ e   je      not_installed
/ c# A. t* M2 X# a5 E. |; {# {5 j
. I' o( z0 o+ s( w& h  GThis service just checks a flag.1 w4 H& d8 A0 c4 v
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部