About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>1 T6 y6 b( n- y2 w
<TBODY>$ _& {7 C  c! R1 P
<TR>
0 L6 S0 b; G$ F: @" a$ {<TD><PRE>Method 01 7 U6 B& A4 m1 p- W$ Z
=========& \& a! w; ~9 `+ A2 M* G# p: _) G7 u

3 a) L- n; x- n8 j' EThis method of detection of SoftICE (as well as the following one) is
+ Z4 P3 w+ M) F8 x1 v% W7 |used by the majority of packers/encryptors found on Internet.
3 ~2 J; Z- U+ X: M) K# j2 WIt seeks the signature of BoundsChecker in SoftICE; H. f/ u. v, Z

8 d9 F0 I& q5 h1 u. k    mov     ebp, 04243484Bh        ; 'BCHK'  g& B$ n0 H$ }& V
    mov     ax, 04h
# ]0 G- c$ L& F& N+ O. d  B    int     3      
- w2 ~" _/ l0 U  h9 z1 ?    cmp     al,42 u- h& c: i% \# k) u8 F0 S$ k7 |* I
    jnz     SoftICE_Detected& H% S3 z" H7 ?5 z1 _" K
$ `) p8 Z+ V. s8 }
___________________________________________________________________________6 R3 @2 V0 R; t! d5 i

& b2 I2 D& x5 ?, x) }) WMethod 02
4 K- ?4 ?) j# T8 |+ D" ?# s=========
& D$ J2 w! _6 s3 u- a9 s
0 Q( z) g6 h# z& R( [Still a method very much used (perhaps the most frequent one).  It is used
3 _( W5 C! N7 W5 ^: ^4 a6 T! R$ Ito get SoftICE 'Back Door commands' which gives infos on Breakpoints,
0 H: ?  B: s, e6 Lor execute SoftICE commands...
( D# O  K8 C% H. ?, o3 dIt is also used to crash SoftICE and to force it to execute any commands' I# T& m. j# M9 K4 L
(HBOOT...) :-((  
4 u+ z6 j# p% f: r6 ^
1 B/ l- |4 {& f3 z* k+ oHere is a quick description:5 C$ V- J% n6 B! u
-AX = 0910h   (Display string in SIce windows)
! R/ S" |; A. i-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
# ^% F' {9 J9 L8 S/ E-AX = 0912h   (Get breakpoint infos)
  D2 p" Z2 [8 g5 y! U- \4 c-AX = 0913h   (Set Sice breakpoints)4 K! e; L* z3 v% R/ j
-AX = 0914h   (Remove SIce breakoints)$ n4 Y' N4 r. L

, E" l! f0 x9 m6 S2 y- U" ~; j' DEach time you'll meet this trick, you'll see:9 @' Y* M; ?) _9 |& {5 ]/ y6 E
-SI = 4647h& B1 g1 `! `* c" v2 l; ~
-DI = 4A4Dh
, J( J. _8 ]: Q( b; CWhich are the 'magic values' used by SoftIce.) a: A' i2 b" e3 o
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
6 K$ A( o! Y5 `& W6 j2 F" |6 R) m: y( g# t! D0 h) V" _8 N
Here is one example from the file "Haspinst.exe" which is the dongle HASP  Y( \$ p, s- L2 B( g
Envelope utility use to protect DOS applications:
, h' s" \6 U3 b7 s1 {. b- v. z! Z# C% l
7 p+ |( U- u; Q9 a6 D) `7 r/ w6 |2 Z  _$ N" J& c
4C19:0095   MOV    AX,0911  ; execute command.
0 J8 E# w' h) g' E. N2 Q! m4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
6 Y  c. Q+ F- a$ N4C19:009A   MOV    SI,4647  ; 1st magic value.
4 U3 N+ B! ^4 \; J4C19:009D   MOV    DI,4A4D  ; 2nd magic value.6 ?, ^% K' c7 G6 f$ \
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
$ c; U9 j5 ~7 {  _4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
+ c7 c: j$ ~6 t8 ^: L4 M4C19:00A4   INC    CX. s- B1 w) B1 H6 B8 K
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
* `# y: B& O- Y3 e9 r5 a# a4C19:00A8   JB     0095     ; 6 different commands.5 T' |: r3 ~1 G. k: K4 l
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
: l- F9 F) I& p- z, S: n4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)7 e8 b* X" Y, y7 V& e
0 S& k- ~9 A8 _
The program will execute 6 different SIce commands located at ds:dx, which8 X. C) _. t& Q
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.  g* A# x$ b# Z4 R' l' |' T3 l

* ], Z: u# T: V5 m# K# L- h" f; d* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.4 z' V2 A. Z# ?( d2 K% s
___________________________________________________________________________8 a  f) }2 T4 h

' j# \% Z& h: N, E# y5 j7 V% j6 T5 l
Method 03' a) {3 R7 X! H' o/ {) H, e3 W) S
=========" \2 ~' M9 m5 [3 Y0 w% P3 l

! w* f$ t! K7 C, mLess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h7 F8 `' y  q; O8 m  `+ J
(API Get entry point)9 j' ~6 Z! g- K% Z; R1 m; [
        
; l0 v& g4 |9 w8 e7 U* F' @* }' C5 N
8 w# o; i; Y% Z0 j    xor     di,di
0 a% q) `  d6 g    mov     es,di# t$ W; m; d  D% U( v% a# e& A
    mov     ax, 1684h      
# s7 b5 I7 H- V0 C3 O$ r+ f9 ?    mov     bx, 0202h       ; VxD ID of winice, ]- Q6 q" ?9 Z( S9 l
    int     2Fh
% _: Q# |4 ?2 f4 m3 s4 X    mov     ax, es          ; ES:DI -&gt; VxD API entry point
1 c) J/ ]8 H& y% n3 s2 J    add     ax, di' w* H) P& d) M
    test    ax,ax& N% }4 c7 l/ R( W+ n
    jnz     SoftICE_Detected
3 ^: N. G3 l2 n: ]: I1 W/ c) }; a) P$ e/ r5 K7 L# t# v
___________________________________________________________________________" a5 _' w, N! m! A" e% F2 ^
" t; c5 [* ^2 @/ _
Method 04! _5 {/ V& Y+ y, H
=========
  _8 ^* O- M* m3 [% t
; G7 p7 z. e" s( }2 @9 hMethod identical to the preceding one except that it seeks the ID of SoftICE% m+ |# D5 x; Y3 x! z
GFX VxD.
+ d; A( U/ s+ T; C/ j
; \8 j% z+ a; I9 x' V. C    xor     di,di* ]6 M- e5 D( a( A! `
    mov     es,di# I/ o' H2 e, L; z: d
    mov     ax, 1684h       0 S4 ]! u; p3 g
    mov     bx, 7a5Fh       ; VxD ID of SIWVID5 I( B; v: h; l
    int     2fh7 M' y6 w( b1 F* a
    mov     ax, es          ; ES:DI -&gt; VxD API entry point" x4 E: o, {& t1 F: N
    add     ax, di6 L4 [4 y$ \2 n4 V: L# V
    test    ax,ax
" e6 p. h  M# h' L' W    jnz     SoftICE_Detected
& C2 C$ w) X  L4 Q6 N: M, ]' I" [; P7 r0 e$ I
__________________________________________________________________________
. k1 U* u0 c+ W- u
" R: a. f( _1 ]# p
5 @& Z& ?& c. H( ~' mMethod 05' d& s9 V+ c/ A# m; L: D& h+ w
=========6 z! Z) S# h" s9 u0 `  E

$ ?. D2 K/ |2 y% H5 l- x6 B+ k% tMethod seeking the 'magic number' 0F386h returned (in ax) by all system2 c! j0 T1 r+ [% G9 B6 s  ?" O8 B
debugger. It calls the int 41h, function 4Fh.$ e6 Z) y! d9 ?9 O
There are several alternatives.  
$ V. I; f+ ?# k/ o- a" y
, I3 d* x. t! h2 X( W" uThe following one is the simplest:
0 W( w' K& ]$ W, J( s' ^
1 P$ l8 B2 Z, ]1 _3 J5 `    mov     ax,4fh
2 D7 H3 P, e' \: M    int     41h
/ j7 s( _1 _( s: C+ m    cmp     ax, 0F386
& q+ a7 j" A, ~' y6 O7 |/ g8 R. W# S  l    jz      SoftICE_detected' |" {* V# W" e3 [1 b# h( n8 G
' @7 g& E' I: a. q

. L' o" s1 ?0 Z. aNext method as well as the following one are 2 examples from Stone's 8 B8 H: Z% s: ]: i1 Y0 A
"stn-wid.zip" (www.cracking.net):* i6 P5 K* y- P8 p  N4 `& }

/ }8 X/ n# l) @' A    mov     bx, cs# e. n- |9 ^0 C! V+ j1 \
    lea     dx, int41handler2
# O) E0 O- {# {/ o9 ]9 ?5 {1 t    xchg    dx, es:[41h*4]+ d- |! I/ t0 V1 J; o# K" E3 d
    xchg    bx, es:[41h*4+2]+ o% `: d9 y1 w3 P1 `
    mov     ax,4fh
" t( F: p) b0 q* P& s5 _2 M    int     41h
. Y) r6 Q3 i* Q2 Z! }    xchg    dx, es:[41h*4]
" g1 |: g' V: x" }0 s# [) v7 |    xchg    bx, es:[41h*4+2]" j( O# w. C$ g3 M
    cmp     ax, 0f386h
1 K1 a) m, b8 P9 L6 A    jz      SoftICE_detected
2 L9 t8 x" \: d. s
1 E8 g$ R5 t0 o: pint41handler2 PROC: f& I# \# w& g7 q0 z2 v
    iret
3 W, \1 ~6 {- w# d9 fint41handler2 ENDP
" L1 R0 [, L6 `! N0 [
; M6 ^1 G$ B/ c8 _
0 [8 f0 a& U% \# q/ V_________________________________________________________________________
$ ?; J; B  ^4 v5 m. \. A) X( _& o2 X- e! V6 N" o7 p0 l( y  N# X

: D4 e! W8 J# e' m( AMethod 06$ D9 ]! u5 Q  }* I# }
=========
' t2 ^3 `0 y2 l' n7 S4 z, q; p  o% _+ [0 X

" H' Y2 p/ q. y+ L2nd method similar to the preceding one but more difficult to detect:$ g8 h* ?) P# k4 s

' H2 ?& i- p; o# u: A$ K/ y+ i% t/ w" ^1 y7 q  T
int41handler PROC8 }0 g9 J7 c: G, ~: a' s
    mov     cl,al
/ o+ ]  T* l( f2 t    iret
9 |* b0 ~8 w5 \; N6 Uint41handler ENDP
& K4 J/ j1 J) n1 C( ~
: x- k4 R* ~1 R% `4 \- ?- p9 N/ G6 _1 d: l" P, e
    xor     ax,ax
' b* ~, d" w% C4 X! a    mov     es,ax1 Y+ l: z/ x8 Z- j% Q" _" J
    mov     bx, cs
# T, l- h/ b1 x    lea     dx, int41handler
! ^6 K4 U' N2 B( C' n5 K0 X    xchg    dx, es:[41h*4]# o* Q- ?+ I6 z# U" J7 G" [
    xchg    bx, es:[41h*4+2]8 s8 C" p- Z4 B1 J1 N
    in      al, 40h1 K/ Q& \8 i. F* ~+ N
    xor     cx,cx2 D, q+ K9 ~1 Z; |4 C1 o
    int     41h* Z, i0 X2 e% |' x3 I8 n
    xchg    dx, es:[41h*4]
, p2 a3 @/ L1 j. F! G! W# d    xchg    bx, es:[41h*4+2]- k2 G/ T  `  |9 _: F2 @7 O
    cmp     cl,al4 G( H) ~, Z: t1 Z" }- ^$ S' [
    jnz     SoftICE_detected% m) Q! i6 ]7 F( H( j

0 \! H( j8 C" y" @* |5 ~( x_________________________________________________________________________- {/ o$ o) m7 {7 e6 n

% f% w( y* b% i' ZMethod 07
" ?- ?# Y7 r; Q3 o* R=========  o5 N, j1 H. j% m
6 k: |2 L+ O( ~+ Y
Method of detection of the WinICE handler in the int68h (V86)
4 _0 x8 B% l3 o2 [% \8 w# t. M  h3 U- b3 i% L& J
    mov     ah,43h+ p/ z# |: |6 r0 R% i3 j) ~- A
    int     68h9 }( `( Q0 e2 V3 `
    cmp     ax,0F386h5 z0 o# H5 O7 e2 M! @  K7 N1 a* x
    jz      SoftICE_Detected
; [5 n1 V0 l1 t7 R3 a! n  f( Q2 B( V7 o/ d1 H% h4 Z$ `0 v
# h/ i7 H- u3 F% u
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit; ~! y' c' t) [' p- v! X! O; Y! z
   app like this:5 C$ _& f& ^" F5 w' G, D' W! @

5 f& K' r9 a& E2 Z  X   BPX exec_int if ax==68
( w* A1 h7 u" P7 `$ p   (function called is located at byte ptr [ebp+1Dh] and client eip is# T4 Q$ V6 M: {3 n- R/ k% R) Q3 l
   located at [ebp+48h] for 32Bit apps). g( F2 v9 R# d* u+ y% f0 P
__________________________________________________________________________
% y( F6 \. r; W4 n# ~0 r/ W4 Y+ X) S9 r; B4 V" ]* U
) K) ], p1 D( K2 {: c  r; X
Method 08! }( J# s3 z0 l6 R$ d% D
=========) a; u8 o4 S/ E* u; _1 G3 i
6 t* k3 Q4 j  Y8 H$ R
It is not a method of detection of SoftICE but a possibility to crash the
# h- X" }" M! F( Q5 q/ L  Psystem by intercepting int 01h and int 03h and redirecting them to another3 ^; F4 o) {" j2 o
routine.
' f/ ]$ c: X2 {1 o0 h" Q) v- BIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points# _2 I2 Z" X4 o& W( `' n2 Z) D
to the new routine to execute (hangs computer...). B0 u  n/ ]& {

, n+ ^* q2 f1 l" i    mov     ah, 25h
9 k* k/ ^. t  ?+ T6 U0 ]( M    mov     al, Int_Number (01h or 03h)
5 R0 z! t- _2 L) f) [# L8 _6 i    mov     dx, offset New_Int_Routine
3 A0 q- c  c! k2 ^' d; |# C    int     21h9 e$ z& H5 w6 r; p* n, w5 v
) @7 L" W0 o6 a' R4 A
__________________________________________________________________________
' L. l9 {; E+ _" y2 h" t" H( Q' t# k' g
Method 09) M0 d* T6 r7 ?* e: s4 X
=========% S  Z( p3 a& [1 i' l3 U

; f/ A# i; z0 mThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only& R7 J' O; l2 Y7 m% j, U
performed in ring0 (VxD or a ring3 app using the VxdCall).
' O- r$ S1 w9 a7 p( O& B  vThe Get_DDB service is used to determine whether or not a VxD is installed
( R, w  }6 B6 r; U- [4 ]) J/ ~: y6 Nfor the specified device and returns a Device Description Block (in ecx) for( d* ]* X  B5 E: E0 h, A# T
that device if it is installed.
  j( o, J( B* |) R6 k
2 e2 X3 B& ?2 m0 b% v& }   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
2 q8 `! _5 S6 ]/ b. M   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
2 c9 L% B( \; a; Q9 k   VMMCall Get_DDB1 c0 a! f9 C$ O
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
. v3 q9 ~9 E% O+ c0 @' v  y3 I& y! o( U- F0 V
Note as well that you can easily detect this method with SoftICE:# M% k7 C+ @4 J
   bpx Get_DDB if ax==0202 || ax==7a5fh5 s1 W4 }/ _* M8 a
9 B# q1 n) w) g! [" q$ p
__________________________________________________________________________; f. J* G; n: d! i: ~
- W5 o( v0 ], e: _$ S8 q
Method 105 `" `2 l0 B( ?9 S/ O; P% L9 C& I
=========% J  ^5 Q" X+ W0 A; j
9 I; H. q, C. F  U" |* |6 d
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
7 U4 V. t; _3 b  SoftICE while the option is enable!!; y) K" D9 Z; W2 s; n( z

9 Q) U9 l% H( B& q* J0 @) L$ P: x4 JThis trick is very efficient:3 f7 ?7 C) l, ~3 E$ D
by checking the Debug Registers, you can detect if SoftICE is loaded
0 U7 ~$ N. c, r9 n# d2 R; h(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
2 U- {# G& y4 z$ \6 T( ~0 othere are some memory breakpoints set (dr0 to dr3) simply by reading their) \& e9 ?0 a! ~4 L' R4 Z* V4 P
value (in ring0 only). Values can be manipulated and or changed as well' l  @+ h, X+ w
(clearing BPMs for instance)% d9 _; I7 }5 Y, F& C

9 e' ~4 j$ R: P( b$ I: t0 D, m8 F__________________________________________________________________________- |% `/ Q8 {9 Z3 Y6 X8 T
5 ~8 [3 r8 v4 S
Method 11
5 V4 h0 M6 c7 Z  n) u2 k  J( d( z4 m=========9 @( R0 o2 a, p# w7 p* u

1 d) D& [4 X9 r$ gThis method is most known as 'MeltICE' because it has been freely distributed. R" z0 q0 S7 @* ^& ]
via www.winfiles.com. However it was first used by NuMega people to allow  p# O9 C0 U' ]2 I* A
Symbol Loader to check if SoftICE was active or not (the code is located
$ ?" t4 W; C9 ?! y2 t* o. Kinside nmtrans.dll).3 q' N& Z3 A; C6 v8 w

8 _. Q. z& w% L& SThe way it works is very simple:
# f# o0 {+ s3 h, G/ N. I# @, @1 RIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
" B6 ]* p5 J/ aWinNT) with the CreateFileA API.
9 {; n, N. Y/ r% [0 T, f" r5 d9 i, p( O4 A0 a; E
Here is a sample (checking for 'SICE'):0 n5 r  F# C0 J& Y

! P; x* x$ t0 h- J. UBOOL IsSoftIce95Loaded()
0 d5 \% X' B% y# g8 ^{
$ s5 X) l6 |, W! N, D/ s5 O   HANDLE hFile;  5 ]+ W3 u  x- r
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
% _" k' L* K- z" \1 G: T                      FILE_SHARE_READ | FILE_SHARE_WRITE,5 S% H+ H/ o) i7 s  `. F
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
+ ^5 ^! f( v* n$ |/ K. U0 x   if( hFile != INVALID_HANDLE_VALUE )1 M; b5 L3 I! J; k- V) z, p
   {+ y+ R# \! A% w- [* x/ B5 W
      CloseHandle(hFile);4 Y) `0 F( H9 U4 L+ v
      return TRUE;$ w+ b* l' `2 z3 ^
   }  }% [( @6 b! E0 n+ N9 l5 @" f
   return FALSE;
# a/ L7 F" W& [: @, W}
7 P8 f0 z+ W3 }0 K
. \! w; G" ?/ k+ h. BAlthough this trick calls the CreateFileA function, don't even expect to be
4 I8 B. i/ @. }  S% Eable to intercept it by installing a IFS hook: it will not work, no way!/ H0 F# J- w4 X8 [& b8 Q1 ^2 ]
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
9 y9 F3 q; ?  l4 i  n: tservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
: \" y  g' E& d( H& nand then browse the DDB list until it find the VxD and its DDB_Control_Proc
# v! [3 ~/ q  ^. \field.
2 Z6 c$ y2 G* U. r6 m1 pIn fact, its purpose is not to load/unload VxDs but only to send a & }' ?- n, E0 H" u% O( ~
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE): a+ \5 j* l' B  u
to the VxD Control_Dispatch proc (how the hell a shareware soft could try( B8 ^  |& q; U" s7 `
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
& a$ g! t$ p. b7 y1 vIf the VxD is loaded, it will always clear eax and the Carry flag to allow1 g$ O7 {* |) v; T5 Q, _) i1 W
its handle to be opened and then, will be detected.
1 h, F+ }7 B: E2 r7 Z) j+ N9 bYou can check that simply by hooking Winice.exe control proc entry point/ }- R' K' w% }
while running MeltICE.
" p/ W3 w. x5 a2 A0 s, ]- n) d" c. F2 ?( ~, q
. R2 ^) k( N! K6 o
  00401067:  push      00402025    ; \\.\SICE
  E  p7 c; n! K# u7 O7 m  0040106C:  call      CreateFileA
5 i9 w* q2 _! S0 Y/ o  00401071:  cmp       eax,-001! T0 f0 S4 `9 `" T
  00401074:  je        00401091
7 }9 D4 Q7 B5 y9 w5 g9 W& K! D$ Z3 V" D7 y2 X! C( F/ x

! E2 S0 l2 Z; }$ A' x! nThere could be hundreds of BPX you could use to detect this trick., V) D5 o+ W4 |# y$ y3 ~* F" ?
-The most classical one is:
) v8 w5 [$ w2 Y" ^: L  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
  J) m" _  D$ t' d! k* k& U    *(esp-&gt;4+4)=='NTIC'+ f( ]9 Y  G. ]$ Q* H
" V5 x8 O2 _8 r. v) y
-The most exotic ones (could be very slooooow :-(
5 X4 @  t5 d# s8 e, X  [: Y1 X   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  ! Q; [; L4 V7 @2 n5 {. S. s( K
     ;will break 3 times :-(  Y: H7 F) _& C
+ r% o  T. ?, W: R& _1 w: Y
-or (a bit) faster:
8 S7 n4 C! c3 F% ]   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
' E2 G* n' s  X2 w  ^- x) O: I/ k( J' c$ H
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  8 j0 {2 P/ f( s- ?. y0 G2 M
     ;will break 3 times :-(; E! v& R& w( V, H/ k' h; w/ E& F1 d
' ?) [; \1 I$ N/ H
-Much faster:2 \  _( [1 m* b. D! m
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'. i+ ]9 R( X9 z

: a, V1 Z6 z1 ~Note also that some programs (like AZPR3.00) use de old 16-bit _lopen1 A9 `( H1 E* m% q  ?
function to do the same job:7 n6 c" B( c" U1 V

; ~2 t* R& _( S) P   push    00                        ; OF_READ
7 m# n6 e  L0 z" _5 Z   mov     eax,[00656634]            ; '\\.\SICE',0
/ {1 [; \' V& K" c$ }! D! \   push    eax: V0 I4 c% B( ]# W4 m$ H
   call    KERNEL32!_lopen
2 I7 h9 R1 t5 u+ |, ]' b6 r& ^   inc     eax
& B, A! c# @4 S* W& J   jnz     00650589                  ; detected
/ J/ ~& y$ o" F  a   push    00                        ; OF_READ8 v& z- ^* R$ D' y2 e. U; I
   mov     eax,[00656638]            ; '\\.\SICE'# o$ r  b* V4 n; T
   push    eax
& V4 r& @) M& n2 `+ Y9 [* [7 L   call    KERNEL32!_lopen
" p- T- ~+ j) {/ Y$ ]* O3 W. Y   inc     eax+ s; U' o  p/ T
   jz      006505ae                  ; not detected
  [. x8 f* G6 N2 M1 W* D, Y  M: `7 g) l# }% n. u& e+ I
/ |! Q, Z  p& ?; J7 w
__________________________________________________________________________( m! _) p4 k* \; M* \, l

7 T# |$ K* }! [; }% [) U' S- IMethod 12
! ~9 F( I3 ], z=========" z( I7 H2 @& K; J; a8 s3 X

! I6 @( [6 D8 A& r& B; sThis trick is similar to int41h/4fh Debugger installation check (code 05
; P# o  v/ Q9 I0 u: U& s&amp; 06) but very limited because it's only available for Win95/98 (not NT)( d' Q* A) m! p4 F; v) Y
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.* @: C, k# F9 F
( U% c# y' v4 U/ a9 q/ `$ ?: V
   push  0000004fh         ; function 4fh
( G7 v+ ^/ ~, @/ r   push  002a002ah         ; high word specifies which VxD (VWIN32): S# _( i: S1 M7 y$ d; s0 U
                           ; low word specifies which service: d$ A4 E. s2 Q3 i$ ]3 B/ r- j
                             (VWIN32_Int41Dispatch)& s, D- Y) r. I; {/ ?) f8 B
   call  Kernel32!ORD_001  ; VxdCall( N* m+ @7 O. i! R; U/ S; q+ u9 X  `
   cmp   ax, 0f386h        ; magic number returned by system debuggers. N% B5 q2 a3 O# H$ U! _/ Q
   jz    SoftICE_detected6 G: Z: l/ e( q* \' N

8 T- U# `! `7 w  a! `Here again, several ways to detect it:$ ^) G9 n( G) b' D8 }

3 I/ u5 F% E/ W, ?$ o$ @& G    BPINT 41 if ax==4f
$ y0 K" ~, w4 D9 {# h* ~
' @) s/ e3 ]3 A" n7 s7 a3 a+ J9 X# }    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one! X) j4 Q' E/ z

9 ~3 l$ N; o2 }, a    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
- P+ [6 F/ _" m
1 K; U8 v( c( Y$ r9 X    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!2 q2 J9 `5 r) r7 I3 Y- z. G7 t
7 H* Y# f/ q6 l4 k; \0 G& |8 k5 ?
__________________________________________________________________________7 r" [8 i+ X0 l( m5 l  |# v' D9 O% v
9 H5 m# ?" L4 B" x. ^
Method 13
- `/ V" e% y$ `" q* K- N=========% b7 u. L( x/ Z, a  e4 j7 c5 y
: d0 A9 v, c3 |4 [
Not a real method of detection, but a good way to know if SoftICE is3 K  D: v) m1 k7 B. b
installed on a computer and to locate its installation directory.$ S  s9 K" `5 u! {$ v/ Z
It is used by few softs which access the following registry keys (usually #2) :" o! d! W$ N! x# b

1 i5 |, v* {- I- n8 l# L) u-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion* I$ n$ C1 Q: m% m' h/ J
\Uninstall\SoftICE
8 y+ C+ a6 ~: y& x2 O-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE3 N; W$ O/ c0 b: X9 @) t$ \" g% i
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion6 }' `8 W+ M  {( Z5 m
\App Paths\Loader32.Exe0 X+ s6 j; L! b. D; d0 N

! |" c- D6 j5 F& k: x/ u
" Z# f) T1 c( S% U9 M8 ~Note that some nasty apps could then erase all files from SoftICE directory
, f' \3 A* {) W9 f: E' D4 K1 m(I faced that once :-(9 t9 ]/ {1 C6 f0 T3 i
6 W, z  |3 ^$ [  M
Useful breakpoint to detect it:
$ j  U6 U$ E. p/ d' a  v
# F# M8 s. ]0 S     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
1 n* e/ H% s. ^$ j2 Y( Y. }5 j5 w
8 }$ [$ W: s& f7 U! D- K__________________________________________________________________________
/ S# G3 P  r; i; c" J/ W3 D- d. m. Q6 n8 q$ u

0 r; J2 H' n  R% h" ~" `' V* GMethod 14
5 m3 I3 c. K9 x4 O5 w=========$ X! X9 o. s8 s! D, I" r# m
& x; _/ ?( z5 j, T3 e6 }+ o8 T
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose/ C/ x5 a$ q8 w/ l
is to determines whether a debugger is running on your system (ring0 only).5 F- y, v. S. f

  o! E, L  M: F, r   VMMCall Test_Debug_Installed- ^7 H) Y" d- T# l6 m  ?, x
   je      not_installed
8 }' e+ R  R+ A' B+ n
6 d7 L2 V- Z0 _This service just checks a flag.
& }7 D# o& H) D4 p</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部