About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
/ R/ F" g% `9 W4 P<TBODY>' F3 y6 F* j& r! @8 ]; t5 K* w
<TR>; S$ V2 o9 M( }; J6 u9 U  I8 `
<TD><PRE>Method 01 % _: i( v4 c7 S3 ~  d
=========
5 t4 d" }# j) l! r1 m% a* U" q9 A/ G7 t) `, l6 V
This method of detection of SoftICE (as well as the following one) is
8 e" \  {+ s8 A2 k8 o% `4 t" J0 E6 oused by the majority of packers/encryptors found on Internet.
# P# g  [8 f1 r- r/ p/ VIt seeks the signature of BoundsChecker in SoftICE% p& U! X8 `8 D' k7 O; z
* K1 |+ H2 y  ~
    mov     ebp, 04243484Bh        ; 'BCHK'
. O+ t2 T/ ~  D/ ~5 o6 C2 G    mov     ax, 04h
$ L" p" e( q, ?3 i" S- ^    int     3      
( y# s. d) w' b    cmp     al,4% Z  s, Z$ Y  H& N" K. _" \0 x4 I
    jnz     SoftICE_Detected+ `: ^+ q' C0 \* S5 j5 V

$ S& h! d5 F0 X# W' C, `) G! R___________________________________________________________________________. _6 _: n9 x  T! Z

. J4 L7 \# t6 VMethod 02; @0 S" m/ s5 o! ^; m
=========; F9 D; O# `# e( m9 D
8 }0 O- Z0 [+ T4 Y' j: w5 {5 X
Still a method very much used (perhaps the most frequent one).  It is used
6 e  b+ ?! ^' u8 Lto get SoftICE 'Back Door commands' which gives infos on Breakpoints,
! l0 F! R5 Y5 Nor execute SoftICE commands...
7 M. D+ d) H8 qIt is also used to crash SoftICE and to force it to execute any commands
- N- {$ E( o/ h5 X( {  A6 p(HBOOT...) :-((  $ F* r! Y7 P% H" J/ b$ v

* M$ I, k+ S' U/ Y9 c3 {Here is a quick description:: M; q$ r- y: j  q  N% j
-AX = 0910h   (Display string in SIce windows)7 b- E. {2 }- ^: q' O4 Z
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx); y- T" d7 l+ {8 g
-AX = 0912h   (Get breakpoint infos)
( c8 o' R- j* I: k) _- S-AX = 0913h   (Set Sice breakpoints)# @1 B+ \. g$ E  T
-AX = 0914h   (Remove SIce breakoints)
9 j, p. f( p4 m8 Q0 N. E* a5 V# N* r. s8 w
Each time you'll meet this trick, you'll see:- U0 b2 w1 q" |$ n9 f+ h0 O
-SI = 4647h
) q* [6 R* O: |5 K-DI = 4A4Dh8 c! x# h6 x; E  I: `2 S  a
Which are the 'magic values' used by SoftIce.
5 T+ z6 c# Y2 T0 Z! j! D% B$ \For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
* [  V. x) h6 t/ [8 L; [# j
6 g# t1 M) ~/ \5 L5 jHere is one example from the file "Haspinst.exe" which is the dongle HASP3 H  N& ?0 |0 l
Envelope utility use to protect DOS applications:( t, Y. m) G* U  g4 I# o3 Y8 A: `
* s. q! v1 \, C" g0 X  S% y4 E/ P
) g3 j, z( p% e* \9 \. o
4C19:0095   MOV    AX,0911  ; execute command.
( M) l2 p: y* b2 X4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
9 f$ e- S. \" Q4C19:009A   MOV    SI,4647  ; 1st magic value.% O+ o  ~1 F& y7 E3 m" ~" `, ]+ C0 A4 v
4C19:009D   MOV    DI,4A4D  ; 2nd magic value.- d$ p; {9 i. M4 A, o% v  _
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)6 S" J: m" W! q
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute" N& H- `9 d& \7 r# ~
4C19:00A4   INC    CX' L8 q, [: u$ W! A9 n2 J3 V0 f
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
- A" {* K. |' e2 H4C19:00A8   JB     0095     ; 6 different commands.# K6 B" Y% n0 T* X1 z, G4 Y+ h! L
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
/ w3 P# `( g  F! }4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
& u! z  ~, o8 `! X& P& ?  g6 q7 j  y
The program will execute 6 different SIce commands located at ds:dx, which
6 e' }8 @# m: A/ Rare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.# P) o9 x. W+ n0 H5 ?

. B3 `9 ?$ s* _1 Z* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
' v0 b" C6 G1 ^9 I9 F5 M0 q___________________________________________________________________________6 n$ J+ e! W% a9 X7 ?
  c7 x  {# d* M$ @$ V1 w
- E( |. V: I3 Y0 [
Method 036 c6 b. z! c% v; Y* r
=========$ K- c$ O0 E- @6 m2 w
+ U! Q1 q0 `! i' p
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
. X( \- g) ~1 Z+ e(API Get entry point)4 l% N; Z: {# J4 ^4 N% T, ]  w6 G
        
* J. {0 L# G/ K4 R8 f$ e- g
) l3 a; T6 V: C. E& f    xor     di,di  A% a5 b* s! B, n! E
    mov     es,di  t& [$ V- L  `
    mov     ax, 1684h      
! C. T) ?9 h" [$ H    mov     bx, 0202h       ; VxD ID of winice, L; Z9 k4 z! H! @( j3 T( i
    int     2Fh4 n6 O* g  }4 ~% e6 F
    mov     ax, es          ; ES:DI -&gt; VxD API entry point+ s! @9 Z' ~) z& @) ~* y, Z
    add     ax, di( D" K, B, m" P/ L6 K, P
    test    ax,ax# W3 l7 x7 [1 J% h3 Y* Y
    jnz     SoftICE_Detected
4 ~- h$ y/ R, Z
  i. l1 |, e& m3 l7 ~& {___________________________________________________________________________
1 O6 ?6 t5 f' A9 z1 c. \8 q# H$ A7 @* c4 i% _
Method 04$ z$ T4 _3 j; l6 t! P9 |
=========
. t/ q$ n( l4 t' W/ M$ D: Q  I" Y) ]9 {3 S7 m$ O
Method identical to the preceding one except that it seeks the ID of SoftICE! h0 T- d) d4 R. E
GFX VxD.
- W0 L' A* F8 j! N6 w. U, ]9 T2 f. Q& j9 u! w& |) Z
    xor     di,di
( |  M, Y, y1 j) d) N: P5 |    mov     es,di
' ~8 r7 a+ W* R    mov     ax, 1684h      
4 F" e9 h1 C  Q# R" S' ]! j% w. D4 B    mov     bx, 7a5Fh       ; VxD ID of SIWVID
/ x2 {- E8 L& g; X. g/ e" i5 e    int     2fh3 d) ^/ R; u' L# P# |, c9 K7 M$ t
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
. j$ ~  Z% s2 z  m' N7 |3 j0 `    add     ax, di, L! w9 Z1 E, l$ C! W
    test    ax,ax
0 h; k& S4 J" @3 `( i    jnz     SoftICE_Detected
  e/ J+ t: M$ \+ m; F: D
+ M! Y% Y& ~( t) ~9 }$ t__________________________________________________________________________
8 N, d( ~+ V) {
  j2 v6 H" Q/ j4 p) N( Q1 `. p
" q% D9 M+ Y. |7 PMethod 05! [: ?# ]% T% U/ w+ K2 Z% j9 M
=========
/ d3 [9 \4 G- a, n) B
) [$ J3 W; I9 Y. b: c) |  GMethod seeking the 'magic number' 0F386h returned (in ax) by all system
9 P$ B) H0 j; U4 Ydebugger. It calls the int 41h, function 4Fh.4 c0 |* g; x5 N" S$ g% d
There are several alternatives.  
+ ?" S- w' x7 I$ N
9 W+ |5 s) Z0 @$ NThe following one is the simplest:  \- F) e- C6 _3 c
2 I* A3 |6 \9 W# G
    mov     ax,4fh9 x2 L& I0 @8 S1 H
    int     41h
# `2 l) G. f1 o8 L* Q" U    cmp     ax, 0F386
; d" v1 V! X1 |4 }    jz      SoftICE_detected& Z, ^  G! ]4 P, a
- F" c5 N' h/ J
- D, X; k/ j: o' W5 O# C8 E
Next method as well as the following one are 2 examples from Stone's ) n+ X+ w+ z5 B( V& t4 A5 @
"stn-wid.zip" (www.cracking.net):9 A5 M, O2 `; ?5 Z
+ a( ]. h4 S8 Y
    mov     bx, cs
" w% j7 G" I+ Q. X- K# z    lea     dx, int41handler27 v  E/ V5 R8 q! M% O9 m' h% U6 g
    xchg    dx, es:[41h*4]3 ~" E, Z: R1 K% a( D+ W9 i
    xchg    bx, es:[41h*4+2]7 H) P( n7 l" K, V! ?( X
    mov     ax,4fh* f: A; S. I$ c  K
    int     41h
9 W1 v$ [( ~9 b3 j. s  o    xchg    dx, es:[41h*4]
1 G' Y0 A/ [' T) `    xchg    bx, es:[41h*4+2]! M6 j; N/ q$ l
    cmp     ax, 0f386h- Z+ a8 Z( U9 v! t! F# s: g
    jz      SoftICE_detected4 h) S: b* S8 s1 c  K6 p2 R5 q
  ^) r0 p3 G  N- u1 h( }
int41handler2 PROC
5 I+ q: Z3 ]! D. ?, I. {    iret
( Z( R3 o$ ]+ G2 B! v( d; ^int41handler2 ENDP4 Y4 i8 M" N4 ~3 N; j+ j/ ?/ e

7 e5 a- i! i* x& y: ^3 s; ?9 w5 R1 ~+ E
_________________________________________________________________________
- v3 X1 w0 |# V4 j) t7 }! P6 G8 `2 {& z5 J3 A( q- _, |4 [6 ]

* B  h, ^! S. |Method 06+ c( _% o2 j4 |6 j
=========
+ v: q$ z3 Q2 \: M# T2 _  H( Q5 X. w
# h0 Q. S+ n# u  L# j1 n
1 v* @, \3 D  \: S% }2 b6 C2nd method similar to the preceding one but more difficult to detect:
! Z( M2 a/ j9 m% Y% J. ?$ u3 u; L1 g/ W9 J$ [

3 T' a! U, G. A& P9 I/ @# Fint41handler PROC! n. b/ L2 M6 D& f( b
    mov     cl,al- a" j- n; I% Q3 K% C% j
    iret
0 q- k. y. ~0 P  ~$ U; hint41handler ENDP
3 n" m; J# E& k; N+ K, B1 }1 F1 k; ]% S1 K6 u
- v1 \5 M2 b, @' X+ O: }* u" v0 z9 x2 k
    xor     ax,ax3 ?  W- {: |1 g4 `  ]6 a6 k
    mov     es,ax
0 G; D  _7 W2 l* H    mov     bx, cs
+ Q2 _3 m/ R6 K    lea     dx, int41handler9 H- y( U! c/ h: _) D
    xchg    dx, es:[41h*4]; H+ K" N% q, K6 D! d$ }; r
    xchg    bx, es:[41h*4+2]
- n8 }# ?1 {/ [2 T0 f( w    in      al, 40h
) l+ t7 R, Q4 F: I$ W    xor     cx,cx
" z, b" M8 ]$ w9 y( A# Y/ k0 \    int     41h
% x8 S; G0 Y% E1 Q    xchg    dx, es:[41h*4]$ j+ T1 x% t3 D. g
    xchg    bx, es:[41h*4+2]
( c2 S( g! E2 g    cmp     cl,al  }6 N, ]% W9 W) U" u- c( d
    jnz     SoftICE_detected- U  I* C/ E. H: D

* K) n* Q8 ~, {4 F4 ~/ E# A_________________________________________________________________________
& R2 A; ?# n* A0 E
! U2 U) ?, w: N! u3 KMethod 076 X$ z0 K  f( o* H" L+ `4 @
=========
& K- r- X6 u+ k3 i
9 j( G2 z+ ~8 hMethod of detection of the WinICE handler in the int68h (V86)
% f& G' Q" q3 N, k7 }6 ~' I" g: Z: F3 l# H! I, O
    mov     ah,43h
( O0 Z2 j4 t# e$ ?* d6 N" F& s6 q$ Z9 W; ^    int     68h6 o9 L4 k; G6 k5 ?0 v' u
    cmp     ax,0F386h
& B. I; z; ^  v* N& v8 j! V    jz      SoftICE_Detected7 `: v# e6 l! |2 B8 ?
6 W4 l& ^5 a) r. \

+ a  Y0 V" Y+ U& l=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit, |3 v7 i. d4 H' a! A
   app like this:* C1 `7 o: \& i" M( B& k- t

) w" F4 n# X$ ~8 B6 K' U6 [$ y   BPX exec_int if ax==68% {1 w4 u+ j, D- }3 ~0 Z& J6 }! x
   (function called is located at byte ptr [ebp+1Dh] and client eip is
  }  P7 _# U) a+ |& ~   located at [ebp+48h] for 32Bit apps)
% J2 W7 P9 b3 }. c: R( s! L1 j__________________________________________________________________________
* Z. ]# W$ j) p
1 P: B9 x6 I; l8 Y. d% _' g7 i
1 {- _" R# F- j& N9 U% mMethod 08
0 J8 q; O( {7 E' A7 K* Z2 i=========/ \& T  O$ F4 z' z* f- h8 U& V
( E# S' o2 h! Y+ W% G
It is not a method of detection of SoftICE but a possibility to crash the
! @' f, }/ ?9 ]% Y1 g4 _+ t% osystem by intercepting int 01h and int 03h and redirecting them to another
0 y" C* o( A1 |7 J  A+ t- @6 S" ?routine.
2 m! w! G* B& S; z2 e  OIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points# q. H: L7 b' n) D0 x
to the new routine to execute (hangs computer...)
" @( [- v! a" p6 E9 z
8 O# H' `: b/ |. e( _# `7 q. Z    mov     ah, 25h
/ n2 T+ n$ Y9 P' Q    mov     al, Int_Number (01h or 03h)
$ d1 ~9 `3 B  h$ a! W' u5 l    mov     dx, offset New_Int_Routine
& g* Q) J$ P: y1 u' |* z) a    int     21h
  {; L/ H2 C" H1 g/ X9 {* Q( X( A
__________________________________________________________________________1 T/ z, @0 Z* w$ Y* k$ f/ l
! B- ~% S& ?  t" d0 i/ x. q; y7 q
Method 09
+ _$ `* D* |, u, R! Y# ~* a=========
6 ]5 o  G9 L, `3 e# `$ V6 {4 s
% p0 n: d  G$ ?+ F" FThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only; |) L% s) _2 A7 B- H
performed in ring0 (VxD or a ring3 app using the VxdCall).( M# _) V7 F6 M
The Get_DDB service is used to determine whether or not a VxD is installed5 ]# T( {, J* ]1 U, d2 ?# g: b5 D
for the specified device and returns a Device Description Block (in ecx) for
! S; c3 s# W  K* ithat device if it is installed.
: Q" _! b5 F: H, f
1 _) C1 P$ A+ i& V8 b   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID" e+ w  v( k+ h  |; Z* i
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
  F; M7 G& ^7 V2 k+ b2 n9 Y   VMMCall Get_DDB
( D( M& v6 w2 o, R0 c. V   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
6 n4 c+ e1 ^3 h7 h4 p# i6 N$ B) @7 y) b5 F5 I: G3 \! m! a
Note as well that you can easily detect this method with SoftICE:5 \6 a( }' _1 Y# c
   bpx Get_DDB if ax==0202 || ax==7a5fh0 D0 Y% g, u! Z' U- d: U

. |: W6 A0 {+ n  _9 L) \5 R__________________________________________________________________________$ c9 ?, r+ w2 Z  |! |2 W4 U% {3 `

5 z9 s( A( e7 u3 I$ XMethod 102 h: Q. Z; ?* R5 Z- D( t8 {
=========2 a& c' N* y& F5 O) }; O: e, G

: G$ ?, v6 W* m  w( X=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
0 L, |, {: ]/ w4 m4 S/ x1 J  SoftICE while the option is enable!!
7 B5 B* W: }4 X) R+ X; T# r, m$ I0 p+ M5 Q
This trick is very efficient:
: X. n& I- Q: t& W1 t8 dby checking the Debug Registers, you can detect if SoftICE is loaded
/ h: X$ R- B2 o/ S4 X2 R1 o; ~+ M(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
" s" x3 e# }- D, g+ u& r/ m7 D( D+ Athere are some memory breakpoints set (dr0 to dr3) simply by reading their4 W1 h( q3 ~  L' l1 g
value (in ring0 only). Values can be manipulated and or changed as well  W: V* ^, F0 x, i3 |5 C
(clearing BPMs for instance)  [! n" N3 o0 D+ e( W6 ]; |  Q

1 M0 _, b$ M# W% M__________________________________________________________________________
: D  o7 {' m7 J. c3 L
. z! }: Y' D2 }* T" @6 {Method 11. y* `; @) q6 [7 Q) A
=========- W' I- R% v- \+ v

6 |8 B1 X& Z- r* |; J' U, }$ ZThis method is most known as 'MeltICE' because it has been freely distributed
7 N2 F( ]5 _8 `8 ?via www.winfiles.com. However it was first used by NuMega people to allow
0 W# j  G% r! {Symbol Loader to check if SoftICE was active or not (the code is located  q6 e5 _1 D& f& D; u
inside nmtrans.dll).
! H  n$ s  ~0 E9 H" K$ R8 _4 q! `# L7 i
The way it works is very simple:
% S+ d/ O* h; ^$ M) gIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for) K6 Z  z0 N* W+ t, R
WinNT) with the CreateFileA API.
* `; a0 x. l7 |0 ^  ^  t! V/ C2 |8 x6 j) P( {4 F0 m
Here is a sample (checking for 'SICE'):
- Q0 G; q0 c" V/ R3 N
' D# c; `6 q5 D) c0 k8 fBOOL IsSoftIce95Loaded()
* |  ~- Y2 i0 N# p+ Q9 S* C( q{& x% a2 r/ o( I
   HANDLE hFile;  
; b7 s! t. E3 k6 y" p4 w6 G   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
# a8 j5 e5 }" M3 T% y                      FILE_SHARE_READ | FILE_SHARE_WRITE,
8 X+ R+ j$ ]3 _                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);* D* d$ }- h( b, b9 ^3 R
   if( hFile != INVALID_HANDLE_VALUE )
, Z2 _& y( C$ N0 d) r! t" C   {
! p1 h! ^/ C+ p# y0 K' Z      CloseHandle(hFile);
( B- j( w8 u$ _8 ~$ N      return TRUE;: z8 ^" y+ O" P( k' |
   }) n0 {4 E* X0 c
   return FALSE;
! J" k) h2 X: t}0 R; A6 h6 H6 _8 O5 c  {% t2 [

( Y4 f- ^" f& F7 PAlthough this trick calls the CreateFileA function, don't even expect to be
) e+ }5 V. ^8 uable to intercept it by installing a IFS hook: it will not work, no way!/ p/ W# i2 R; \, }9 S3 O0 g
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
/ B; x" X' u, J$ _8 fservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
8 g/ Q; h- U/ x/ H- Z  Qand then browse the DDB list until it find the VxD and its DDB_Control_Proc
4 k; [: E) {3 r- Nfield.
, T, ~. I7 `+ _0 G' L# K9 Z0 AIn fact, its purpose is not to load/unload VxDs but only to send a
% B" V1 a% f. A: \) B* oW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)! Y  E2 c9 \6 r$ k( @6 R
to the VxD Control_Dispatch proc (how the hell a shareware soft could try# O, u( v; g5 {) r$ \; \2 y- Y
to load/unload a non-dynamically loadable driver such as SoftICE ;-)./ I, y+ g2 o  E
If the VxD is loaded, it will always clear eax and the Carry flag to allow
8 w7 _! i* C' q5 L5 s& S6 d) `its handle to be opened and then, will be detected.5 z( [1 [. L0 i8 B+ M2 B
You can check that simply by hooking Winice.exe control proc entry point% q' \/ k: ~# Q% U- f6 u) V/ h
while running MeltICE.
5 x% G. ]* x& A& G! a
5 E& c+ W/ |- a( I$ `
, R; _8 G9 q; a5 f. K" p7 T/ u  00401067:  push      00402025    ; \\.\SICE
0 B) i' ~" d1 c8 ], Y$ b3 e6 T  0040106C:  call      CreateFileA
3 ?) N+ I& |1 P; v  {; Y  00401071:  cmp       eax,-001% _  X0 C5 }! I5 \4 @
  00401074:  je        00401091& F# D2 A: b" x5 y4 x
6 @: q: X2 s/ L5 q1 J; z
% A: D! l8 V, n$ ^5 [9 l0 p( L$ A
There could be hundreds of BPX you could use to detect this trick.' k  f* s( g- U5 v. S* V2 N
-The most classical one is:% @+ a# a  X9 G
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
! C9 E) w  N( }6 x5 S7 ?    *(esp-&gt;4+4)=='NTIC'
7 X/ y2 J# l8 B- H) c9 o- m# U7 H) y9 p- F- M6 {3 o# r
-The most exotic ones (could be very slooooow :-(- b' J: M; ]# F9 o- _
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  ) y  z, b# ]7 a/ w) z" \
     ;will break 3 times :-(
3 |( w4 w, V. w0 T
* x8 U/ k& Y, ?. g% ]-or (a bit) faster:
2 m5 E6 n# `' a2 n! A2 O4 R   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
0 h' U2 |: t( f& [
8 I) U2 u" m, A: ]   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
- H8 o: L6 ^9 q- G2 X* t* d, m     ;will break 3 times :-(
$ K$ C* u: j- D: M
; w- U( {8 G& c: X7 a. x-Much faster:
9 h; B" m! d( e5 C. f. z) t9 t   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'( Q- ~7 W. @0 K" K* l

5 f; L- _2 u# c8 q9 k* V# aNote also that some programs (like AZPR3.00) use de old 16-bit _lopen$ L1 q9 T6 k$ d( i$ Y
function to do the same job:
  e* i! {, T% F4 O
0 k& O4 {3 ~% J2 g6 t; O( \: j5 ?   push    00                        ; OF_READ
" C: w1 |9 L3 z; ]) h; g$ d2 u   mov     eax,[00656634]            ; '\\.\SICE',0- }  F5 G  t' M* G* J+ w4 M
   push    eax6 H8 s8 D/ {& d
   call    KERNEL32!_lopen5 Z" s1 R# ?* F5 b1 ~1 v
   inc     eax
8 v, B; e( J: r7 h) `  e9 w: Y7 j) }   jnz     00650589                  ; detected+ I3 @: `( w5 p' ?2 t: [
   push    00                        ; OF_READ+ ]7 W$ L9 K2 Z3 b5 s% R, m3 y8 d
   mov     eax,[00656638]            ; '\\.\SICE'
/ u. g1 g: ?' g3 l  f5 J   push    eax
- O# H* z# [& l0 a: V. z. y6 F   call    KERNEL32!_lopen8 x" I+ `5 t9 W% x6 ^9 }
   inc     eax9 e6 c/ Z- _, i5 ~
   jz      006505ae                  ; not detected
9 t1 ]2 M1 C' i  W
& b9 |6 j. |' r- Z2 z& ]: Z8 i; J7 z) C$ I; y4 H( @
__________________________________________________________________________
1 i* }- y3 ]' P# Z0 p' d( }. ?* ^( |
Method 12: P0 |* i( J# x+ C: d
=========% G4 I7 l; y# G9 N" q9 X

# Q  @, S8 n9 a: u2 [This trick is similar to int41h/4fh Debugger installation check (code 05
$ A; K9 e4 L  x  T&amp; 06) but very limited because it's only available for Win95/98 (not NT)
# e5 i, @) L" h( {& c8 oas it uses the VxDCall backdoor. This detection was found in Bleem Demo.
; ~/ X- f) k& R, G# [! U- e, N' ^5 H- i2 L( Z  Y! g, r* h* r
   push  0000004fh         ; function 4fh, V1 O" V5 H; h- Z) x* g
   push  002a002ah         ; high word specifies which VxD (VWIN32)
! W! C/ {" V5 R                           ; low word specifies which service- o( H4 n2 K: ^) o0 V! d6 E+ F
                             (VWIN32_Int41Dispatch)+ o% e3 f( R3 m9 ?* @
   call  Kernel32!ORD_001  ; VxdCall
6 ]0 {) b$ |3 A2 n   cmp   ax, 0f386h        ; magic number returned by system debuggers
8 w3 Y# N% }( w5 f   jz    SoftICE_detected
8 I* S% `% g9 c" m- J# R% g: H2 Z0 {  r! [/ G
Here again, several ways to detect it:
( y* i$ ~4 D) r# ?& H; h0 y8 w/ w8 p# b+ Z0 s4 p, @
    BPINT 41 if ax==4f
7 m$ y6 F/ n: |/ g% @" X1 P6 ~# m% S5 T3 {' K" S, Q
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one3 k! x( S4 K5 v. J- A
; l" D1 f- b) ]
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
; l- s; x* u) M% [5 q3 r
* X3 P' P+ A; M- c; U! U$ t  t) K    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!# ]4 R# h4 p- D' h0 ^

/ i* A1 [0 p; U  {8 ]__________________________________________________________________________# o* z8 K- F& K$ b% i# `8 W
+ |/ M/ F0 A& \1 u3 E8 @
Method 134 P$ ]1 o9 m) J- C; d  {# ?; n, x5 M6 F( k
=========
7 p6 F0 S2 e5 i+ V  M8 b0 ^9 ^! ~
0 h' P7 g3 y5 N1 uNot a real method of detection, but a good way to know if SoftICE is
, e3 M# m) b% q# p9 Ginstalled on a computer and to locate its installation directory.
; t3 }, M8 R& i# E! hIt is used by few softs which access the following registry keys (usually #2) :/ ^4 P. i- y  V/ K# q) F3 V9 Z. [

2 t$ D9 K4 o9 ^0 r4 m( i) o-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion5 m( M" Y) n; W  Y; H; D
\Uninstall\SoftICE6 f) B7 Q/ T1 Z( i& k7 r+ Z
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
4 M8 z2 E5 a# p) y$ Q/ j) B: Y-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion2 S! A( ?$ n" b# }8 v
\App Paths\Loader32.Exe
% G1 U  r7 c$ H" a" Y6 k6 C* ?
* @+ v( t' m! v
. x  p4 Q7 n( {. S+ w  S! C; e9 ]Note that some nasty apps could then erase all files from SoftICE directory
  a# Y  `& e' O* }0 |) U$ I(I faced that once :-(
) J6 Q7 O' H& Y+ |9 z, v. J/ `2 ~
/ W6 S, S$ i; dUseful breakpoint to detect it:5 \( k. F7 {  }
8 B2 E) \* L+ W5 J
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'/ x, K; `: V- w% d

7 h2 `3 @0 L" b5 X, s__________________________________________________________________________
* i9 N6 I% f( E( O8 v0 y: U# C" F  D% k; A6 t+ |" ^
7 x; Q& \+ P7 Q; T' a
Method 14
4 S0 L2 i5 w+ A6 p=========
. }3 ]% X" r6 ]( [- o5 H! s  D4 v& _5 Q" s' W. T) a
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
, v( D6 I4 }% p3 t2 v5 wis to determines whether a debugger is running on your system (ring0 only).3 s$ T: B! |7 E  c
; H3 [/ W0 Q0 ]- ]3 a
   VMMCall Test_Debug_Installed% d  L; o4 Q9 L
   je      not_installed
; C; G! r3 Z( q$ P9 Z+ Q. h/ h) K& w
This service just checks a flag.
' c' F3 n" c, D5 t. W' }6 Y7 o</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部