About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>$ t( Y% O& f8 T5 V7 r- y
<TBODY>1 t: ]1 K1 O( D/ X
<TR>
) q# O& Z2 \, ?. H1 X" d<TD><PRE>Method 01
7 |  P8 ?( m7 p; v; x/ b. {+ d=========% j. t1 L. i! R% }, Y# c( A

6 U' t/ }$ W% k* v0 _This method of detection of SoftICE (as well as the following one) is- }3 d! h# y9 a9 k; N
used by the majority of packers/encryptors found on Internet.& F5 F! {5 q8 v9 j8 T2 T4 H
It seeks the signature of BoundsChecker in SoftICE
+ N6 [$ f6 r5 l" _
4 f9 @, C, n) B5 o* ^  R    mov     ebp, 04243484Bh        ; 'BCHK') X& ^4 h! ~; W3 g$ s3 |* T
    mov     ax, 04h  U) ?6 W/ u# \* M4 w' |
    int     3       5 d# k  p4 S( s: k- O  J
    cmp     al,4
4 p5 n: x9 u9 O* N0 t1 @5 q3 k  d    jnz     SoftICE_Detected
. p6 B# E' q- d
6 u* N/ _- h" K' N* p" q___________________________________________________________________________  z- |! d7 k8 B

4 {! I) n" N5 b3 z, O7 A$ GMethod 02
. l- @2 W/ E3 h/ i5 m) V=========
2 y* T# g: l5 C  x, z; @
- j2 B# g5 T7 A5 b, o5 YStill a method very much used (perhaps the most frequent one).  It is used  \  X, V( }" C9 j8 K
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,& q" `8 q; v+ o- m' p$ n+ x: f
or execute SoftICE commands...
/ z  p% a; L0 R9 \0 ZIt is also used to crash SoftICE and to force it to execute any commands
! B) S. [, V: X5 @- }(HBOOT...) :-((  " {" P# H* ]0 Q
8 {5 T  B; J8 k5 e; L4 x' v
Here is a quick description:4 H! w1 R- |5 _+ y9 O8 o8 s' H
-AX = 0910h   (Display string in SIce windows): o+ P: V# n2 ]+ j, d+ t  ^
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)  x. c) |: v1 u$ B5 W- A- M
-AX = 0912h   (Get breakpoint infos)6 p$ Z/ J& V8 w7 x
-AX = 0913h   (Set Sice breakpoints)
8 B' y8 ?0 e# }, Y-AX = 0914h   (Remove SIce breakoints)& o* W+ p, V- ]5 I5 P
/ Y8 i' O; e2 n
Each time you'll meet this trick, you'll see:
6 i! M# B7 ~3 M* |/ B& m-SI = 4647h4 |' y  ^* N" q# M; M2 ^. f
-DI = 4A4Dh0 Y2 H' n+ n- z4 K
Which are the 'magic values' used by SoftIce.1 O; `9 J6 W- j: I$ d( Z2 I- a8 }
For more informations, see "Ralf Brown Interrupt list" chapter int 03h." S1 f! s& ~, ~7 a& R$ L
/ z9 N+ _6 J: z
Here is one example from the file "Haspinst.exe" which is the dongle HASP
3 {. S# p* s" e3 pEnvelope utility use to protect DOS applications:1 b  I, Q' S, t& X$ m- Q6 ~

- y7 D  T: \0 p! y
" A+ ~7 c+ G! `" y* g# Z) Q" [) v4C19:0095   MOV    AX,0911  ; execute command.
8 F1 ~2 g3 h& G4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
* ?& F! Y" C; T6 b$ \  s$ f- T* e/ ^4C19:009A   MOV    SI,4647  ; 1st magic value.
/ z$ \% u/ e" T4 Y4C19:009D   MOV    DI,4A4D  ; 2nd magic value.! l: Y$ U" v* }/ a3 I& ?& |
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)2 s& F! m  ?5 v* u, f, a  V
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
$ B+ ^% F" G( b# X" p2 p& `; d4C19:00A4   INC    CX
# |, ^! D5 j# f% ?3 o: ~- Z4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
/ r2 J2 e& V/ @. `2 i/ b$ u4C19:00A8   JB     0095     ; 6 different commands.5 i# W7 a2 c2 L% B6 n- I) j3 f
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
: S9 _  S& R. k5 @; [6 \; N4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
# _& `% u5 @! i! R" ^' p. Z" ^  d
3 E; n& }0 c# SThe program will execute 6 different SIce commands located at ds:dx, which
2 Q# }. A- ?. T; hare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
- b, Z: b8 @0 ]+ v
, \. i8 U0 d- w* D$ A2 K* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
8 }- ^* F1 H, H/ K' o' `___________________________________________________________________________( N" C5 m! R' f3 I
. f7 q. s6 o$ T, q

2 Z: T/ E( {& a  TMethod 039 Y) b  O2 a" V  ]8 Q) J2 H. i! t  `
=========1 B  G- i+ g" Y2 n7 w" g1 X

* J; S! A) ]! l4 k3 X/ s3 jLess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
7 S; M4 E6 t4 ]$ A4 Y6 @(API Get entry point)
4 z( ^' M  |" \7 }: V: z        
/ {, a8 ~6 t4 X% h; ]3 S
* r; \( C0 y6 W' @$ ~& n" ^8 s4 m  X" h    xor     di,di
9 V. a6 C$ Z' x) h    mov     es,di
/ z. w4 Q; M& J    mov     ax, 1684h       7 W2 u' Y) c% t2 \8 ?
    mov     bx, 0202h       ; VxD ID of winice& `5 e) f- }; J1 n. Q4 B3 e
    int     2Fh3 |- W9 x' d6 ~# y2 P$ b6 x6 @6 m
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
8 Z! d2 [9 }3 F0 e1 ~    add     ax, di9 {7 c% b! ], ~
    test    ax,ax
  U: K/ _" L' E$ h( L    jnz     SoftICE_Detected4 ~( X) ^: T* H2 b+ Y
1 |) o  _" \# p* s8 |. T
___________________________________________________________________________
( H. ?7 c/ S$ O* Z6 G6 X
  d- a# E) q* e- `% X1 W  gMethod 04
* i2 L  Q2 h9 |# x=========
3 S; T$ X6 J  ^/ T& I# G: B% X0 e, u- p  Y; f
Method identical to the preceding one except that it seeks the ID of SoftICE
4 A; c# ^4 W: z/ O. wGFX VxD.5 @; c  y! ?& e% Z  H+ ~

0 D6 |* r! c$ W1 b9 @8 n    xor     di,di0 t6 J0 R: T! W9 w
    mov     es,di5 d4 z* q/ t+ E1 y
    mov     ax, 1684h       - v% {: E$ i, j& R* s* g) A
    mov     bx, 7a5Fh       ; VxD ID of SIWVID; o; r2 K5 `5 W7 c
    int     2fh
8 }+ G+ ]5 ^# D. b% w: c+ C    mov     ax, es          ; ES:DI -&gt; VxD API entry point( q5 @! p5 S- y+ V5 Q& P
    add     ax, di1 K/ X: ?2 D0 t6 J8 A. D  h$ T
    test    ax,ax
0 B7 d% M' Z- U7 y) H1 x/ r' M    jnz     SoftICE_Detected
3 M8 l* e; x* d
  u' f" F8 q7 x, o__________________________________________________________________________
. O1 Q1 }! `1 n7 _* L2 h1 v: r. n5 o. k  O6 t" [7 Y$ t; G

" K9 Q3 s( H9 o9 GMethod 05
! B% Q* [" l* g8 f4 F( ?$ J=========
0 T1 }3 T) |  V8 R9 ?6 i
: e0 w: K2 Y5 {; g* @Method seeking the 'magic number' 0F386h returned (in ax) by all system* P2 k5 c3 V, c
debugger. It calls the int 41h, function 4Fh., h/ p7 S+ i' b- _2 _  i
There are several alternatives.  ' s# Q6 b( t/ O2 `, _
( R- T- `3 v' B' }
The following one is the simplest:2 }6 ~( r: s0 ~7 {4 w+ K) `

9 V, a* D$ ?& w    mov     ax,4fh
) b, P* z8 {% @, w    int     41h) H( b  D8 k7 `4 I/ p/ s
    cmp     ax, 0F386
- |; d  U" t8 d! G0 m4 L    jz      SoftICE_detected
$ H6 a, W, K7 E' y) H8 H7 Q& \4 N1 l- v6 V, ]  O( i& b
  p4 V) @2 y. z4 t" Z9 \# d
Next method as well as the following one are 2 examples from Stone's
4 U6 R, m# T& {5 n"stn-wid.zip" (www.cracking.net):
- o, \& t8 [+ R( y" `* x% w' G0 D$ s( @* k# H  S# x
    mov     bx, cs
5 h, `; w: ]* |+ n# p1 k  q    lea     dx, int41handler2
+ [3 h" @8 ]* j# e! o    xchg    dx, es:[41h*4]
3 k* c$ [$ o4 w    xchg    bx, es:[41h*4+2]
6 S: j& o4 c1 u1 {* x' }/ L" G    mov     ax,4fh
+ G2 `: Y+ W! v' q- F8 O6 p    int     41h
4 ?  w" b2 e7 q- \. N    xchg    dx, es:[41h*4]
# }0 U. q$ J6 U6 X    xchg    bx, es:[41h*4+2]
7 W3 M# X& |9 F$ o  j5 |    cmp     ax, 0f386h  h" p4 Q6 h" q9 q+ t
    jz      SoftICE_detected; }0 C! }5 O% d- F
" Y. ~9 h7 F- R3 m2 ?$ \, m
int41handler2 PROC7 S- [* l" o( V" l8 A
    iret
) C% u5 }* M5 p0 [  n& C& ?int41handler2 ENDP  F( \; V9 {9 N! v% `6 m

! K+ }+ Z9 L/ B" b5 R# h( M$ X, [: f$ l( |. k
_________________________________________________________________________
4 L( {  s$ ]1 K7 d  f( S  U; S9 ?% E; k( g2 V7 j( g. g# @4 T
' F& q& t# Y5 _( {$ V. J. s
Method 06
& ~- L9 N- {. u) o. O0 q$ b  n. A=========, N! U% w& x  D% k" P: v# _, P

7 a! m, B0 o3 R4 a+ ^
+ {: g! Z& ?4 a8 Y) l2nd method similar to the preceding one but more difficult to detect:
! `; G0 S/ g( s* v4 O$ ~! N! D( `
  f& v$ f  e. |* }8 M+ f0 m1 a% d: e5 M7 a
int41handler PROC9 i7 d% n; S+ D& B% H
    mov     cl,al
3 T8 w  L, h) n2 q    iret* K( G$ y. ]$ G6 x' S1 o7 R
int41handler ENDP8 p0 M5 g9 G# ^6 ^
' W% z9 _6 O8 g; J- A

' r$ Y& T4 V" @+ ~    xor     ax,ax8 n( S1 j/ P+ d4 \8 X6 L
    mov     es,ax
4 B0 U7 I# E# _/ \9 `    mov     bx, cs# ?3 Q7 Z0 H4 U1 P
    lea     dx, int41handler
& d* c1 m1 F4 A- T" N    xchg    dx, es:[41h*4]
# N# U2 d/ p* [) q5 K    xchg    bx, es:[41h*4+2]  w$ K( N+ E: O4 e
    in      al, 40h3 |4 H$ P3 ?! @2 v" Y& m
    xor     cx,cx
+ S7 A8 E3 G+ s. N# S    int     41h1 w+ x5 y, a7 U
    xchg    dx, es:[41h*4]; J8 b" }( _$ }
    xchg    bx, es:[41h*4+2]
* N6 X; F) y/ k- k$ R! B    cmp     cl,al
; U" k0 S1 ]3 M) h$ B  ?- R' M& {    jnz     SoftICE_detected) U2 Z1 B4 m9 h
. _" U# V! p3 r9 a6 @6 N2 A
_________________________________________________________________________* C5 m5 U6 U# a. _& d4 D
/ I7 d" z( ?1 }' o' C) n5 T
Method 073 b0 G) N; W* K- Z3 C5 h3 H
=========1 {; R+ x: K' A: n' M# ~; K9 c

; d7 ?  P7 O( w# ^Method of detection of the WinICE handler in the int68h (V86)
' p: ~/ O. N6 x" U" R, u1 q1 y" m. u5 _" ]
    mov     ah,43h5 L' z! r# E, N- A: M4 Q
    int     68h8 [) I6 E4 U  L1 T0 {, H
    cmp     ax,0F386h# r( Q5 x+ e2 W7 ~
    jz      SoftICE_Detected
) b* a% A2 {9 s. S' ^2 |% q% E) r8 h( e5 n, V2 J8 C) ^6 F

5 G; Z4 d% A* j5 ?=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
$ I5 Q8 F  D  S) m' m! D  x/ \+ f   app like this:
$ [9 L4 j2 o! O% n7 H/ j
; u/ ?# G& x4 v9 J+ n) c* q: Y   BPX exec_int if ax==68# E9 d5 x( s$ V
   (function called is located at byte ptr [ebp+1Dh] and client eip is
" U- Q/ Z% N; x   located at [ebp+48h] for 32Bit apps)  H" n. l: C1 j9 }2 l
__________________________________________________________________________
7 e, q( Y; g2 z6 l7 r: F+ [' g3 c4 C. t9 z% |6 }

9 c+ i; s% r5 }5 m7 |0 l3 PMethod 08
/ L$ d' I+ z; k4 N' v3 o) L=========
- O$ A% X$ z4 J9 x6 U2 ^4 Q5 R5 ^- V" Y% ?! |
It is not a method of detection of SoftICE but a possibility to crash the
4 R9 k2 d4 x- e* F) \! T- F1 u5 W2 I& fsystem by intercepting int 01h and int 03h and redirecting them to another
+ N3 j) a5 w7 c% |routine.
0 R! P% _, o+ L/ ~5 t/ f5 F7 L& YIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points" M9 ?- s7 U! v2 C
to the new routine to execute (hangs computer...)8 x# W; @8 C. f- H
+ N2 B7 D) Z6 e  M7 u6 P2 R
    mov     ah, 25h
4 }" |& i8 `) r6 j    mov     al, Int_Number (01h or 03h)
. G( C+ V3 A2 q& r# m4 R% W2 m    mov     dx, offset New_Int_Routine
; ]5 ^! E9 ~/ o    int     21h
. M; b7 ]% {2 @5 J6 z' j- M
8 ~' o) q! L4 l' i. }; b__________________________________________________________________________) H3 i. e: t% a
& s3 b" W/ }7 o3 x2 Y1 S
Method 09
( S4 Y) ?' b' H$ {+ f=========
5 H( B/ o* f$ s( R8 e$ A2 r: C: C" M( h2 L" W5 G
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
! Q; N2 r. K3 M7 u6 \5 u% @% jperformed in ring0 (VxD or a ring3 app using the VxdCall).- F2 w$ h1 X4 H* {' R  v
The Get_DDB service is used to determine whether or not a VxD is installed
# |! f' J( k) efor the specified device and returns a Device Description Block (in ecx) for
; K: K' k: a: y* i9 o" Lthat device if it is installed.# W8 g1 U$ G5 e

! s0 w+ v6 }& c+ W0 p   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID& V' a* ]  b# B7 e
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)) m. q2 t# J4 ?) c: T( Q" L# D9 K
   VMMCall Get_DDB
% C3 j" P3 C, e( A, w6 ^2 V   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed+ y; w2 Z/ }! p. D& @) i

0 O. R# n' m3 J* X; T/ y  fNote as well that you can easily detect this method with SoftICE:7 x3 w2 g  p; O. n4 U3 r) u8 u& ~6 y
   bpx Get_DDB if ax==0202 || ax==7a5fh! N" L6 [0 v& i/ B% m) `6 g, F
+ V. n  y* q: W3 g/ ^/ ^: D
__________________________________________________________________________, M1 W1 g! l0 {/ G- l6 p/ r: P
" X1 q) P' p; H
Method 10
$ m" O; \6 o: Q; @0 s1 Z/ }=========
3 ~7 s: z4 e- }0 r* `% b/ G; W0 ?
. s/ Z( e6 U+ Q% L=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
& p  b$ Q/ s1 W+ v  SoftICE while the option is enable!!
/ b, o) O+ _) c3 k, A/ ]% l
$ J% S1 s' L+ z- J7 NThis trick is very efficient:
8 T/ T' S. L) Rby checking the Debug Registers, you can detect if SoftICE is loaded
9 U9 e- a4 d6 l/ B(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
% }( v! m% n2 X$ ?there are some memory breakpoints set (dr0 to dr3) simply by reading their& R& G9 x& f6 O1 c0 C6 s
value (in ring0 only). Values can be manipulated and or changed as well* H, A* m( J  m: u8 \/ r' @
(clearing BPMs for instance)% {4 f3 T" F* m6 w
& S/ u; |9 ]( l. x9 O$ R) e
__________________________________________________________________________
; |+ C- Y1 ^/ v! h% n' C% C3 f, r, _* T
Method 11' w1 A7 g  u. j2 Y5 J2 |9 R
=========3 F6 ^( w0 A- u/ {7 n9 R& S

! q* h: O9 f  l) J1 nThis method is most known as 'MeltICE' because it has been freely distributed6 k! N' W* ]* h$ G: U
via www.winfiles.com. However it was first used by NuMega people to allow3 u! w1 `' \# B/ N* p2 I
Symbol Loader to check if SoftICE was active or not (the code is located
0 v" {) i$ x7 n! v! J. z; |0 kinside nmtrans.dll).
. l# O/ D  j0 K+ x3 ]6 E
, O7 ]: d. V' v, o. nThe way it works is very simple:
- k8 S* k$ y) h& ]0 ]( [$ tIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for, _1 y* q5 M8 G* _1 f0 G% n* r
WinNT) with the CreateFileA API.4 w7 P( \8 Z7 B8 D. @% u

! F9 k- R+ a# p- G  w( A# UHere is a sample (checking for 'SICE'):
, I" g8 Z0 S5 I# G
) f4 @& e3 t% TBOOL IsSoftIce95Loaded()
! P! M) D; k8 A& q{
5 S" l' g) u/ o   HANDLE hFile;  + E+ W4 ]' ]. W
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
3 L( H5 H, |0 `" j9 `                      FILE_SHARE_READ | FILE_SHARE_WRITE,
+ }  g( e# n& Q, K) T                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);( G7 u  O7 G! Z
   if( hFile != INVALID_HANDLE_VALUE )
; V: }! i9 h* I$ |: o6 @- r8 p   {
# f- p7 D0 }" O; W/ f      CloseHandle(hFile);
/ S  M1 x& U0 E0 D! ]2 ~  j      return TRUE;2 ]/ `+ u- q% {4 P, m- F
   }
1 P! o9 W6 W4 v) N+ P9 a   return FALSE;
; u1 X0 g. N+ n8 H}, n3 O  {$ T, {% o+ M, C

1 Q* ?- c$ k5 w& c* M- x6 m6 nAlthough this trick calls the CreateFileA function, don't even expect to be
& H2 d: U0 S* r" T2 f$ \/ ~able to intercept it by installing a IFS hook: it will not work, no way!
8 z* _( ^  V# ]" i5 F, c/ S" j7 zIn fact, after the call to CreateFileA it will get through VWIN32 0x001F# ~2 C% K% y# {8 @7 R) H
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
9 I" K. A! b, X+ `9 vand then browse the DDB list until it find the VxD and its DDB_Control_Proc) w, }- ~0 t  R& }7 |
field.' u0 t" X7 m7 X5 ?
In fact, its purpose is not to load/unload VxDs but only to send a
. R  t/ Y1 v, i5 G. D9 y5 aW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
4 l: i# q2 Z6 ]  G7 b6 V  ~to the VxD Control_Dispatch proc (how the hell a shareware soft could try
0 p' A; M" T& O) Q  `to load/unload a non-dynamically loadable driver such as SoftICE ;-).- p% Z7 o3 Q- s1 |5 r  B& d6 N1 t
If the VxD is loaded, it will always clear eax and the Carry flag to allow, l7 }/ ]- }! {
its handle to be opened and then, will be detected.% Y* X0 c1 j5 j1 ?: D/ i
You can check that simply by hooking Winice.exe control proc entry point
4 t+ M! v) Y- S- _# Awhile running MeltICE.
; f" v, y, c( y# V6 N: {) F
; ]5 r- \% _1 Y# l0 ]5 K  j
( P1 P$ l8 }6 r6 p  y/ l) {9 C1 n  00401067:  push      00402025    ; \\.\SICE/ X( ^# o7 e, g0 d
  0040106C:  call      CreateFileA0 O  h: n/ g; u, x
  00401071:  cmp       eax,-001- @1 R8 Q9 k5 j0 l% F" J' a- v  y/ F" f
  00401074:  je        00401091! u+ e% }  c6 X7 ]3 q1 e
& e4 I% r# \7 |  ]
* B* y% {" L  s
There could be hundreds of BPX you could use to detect this trick.
- z+ n7 i# d) M: D-The most classical one is:. G% Y% Z0 N  |8 Q* N9 o9 q7 R0 k
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
! _" ~- m  v/ K) U+ d- w    *(esp-&gt;4+4)=='NTIC'
% q- `* h/ t7 c! P/ d: G4 Y& y8 b1 g
-The most exotic ones (could be very slooooow :-(: d6 k' K9 U! @% y
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  - W( C; H: X4 l1 Y1 f" s8 u
     ;will break 3 times :-(
4 K6 l- B/ c7 i8 u5 {
! k" Y4 ?& K. @-or (a bit) faster: . N4 ^: M, y& N/ g& G
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV'), l3 Q4 @. Q; z! _1 r

/ j% w+ t# r) i/ T  d0 X   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  3 i/ R% ~1 g- F, A/ A9 r
     ;will break 3 times :-(
1 J; u6 s8 }- x5 O# J3 P, p( K: b0 ?; a, t) u6 R. _/ ^
-Much faster:* N( K$ _& T% H( C# W
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
2 c& {4 E/ S8 Z8 I& i7 u( A9 c) K) m# E; h
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen4 v3 z5 r  z8 \1 \8 ]9 ]
function to do the same job:! I1 ~; x: c  ~% r

( G! l. ]( c3 {# K1 I   push    00                        ; OF_READ
  E; ?6 X0 o% n8 o4 j. q   mov     eax,[00656634]            ; '\\.\SICE',0
. P5 j6 M* N" @4 g   push    eax5 g) U- L/ }4 }8 Q8 n0 n+ u
   call    KERNEL32!_lopen
# N0 S" g7 a( m   inc     eax
/ \9 I$ {. H; x+ f9 |- X: o1 b   jnz     00650589                  ; detected1 Z  j. k$ @( J) q$ h
   push    00                        ; OF_READ
8 I8 [1 M# G" f& K: f/ j   mov     eax,[00656638]            ; '\\.\SICE'+ C. q0 G- O' `
   push    eax2 H; o6 L  W. t! l& c- X
   call    KERNEL32!_lopen* D; k- C( _  @9 i# Q" k
   inc     eax" j8 O/ Q- Z; X. N! [, D4 I
   jz      006505ae                  ; not detected
0 R- z# m/ S! G, ?
  W( y6 U) n6 F6 z4 ~. \" \: n, K! O0 K: W% q" ^# t
__________________________________________________________________________9 m8 |1 d7 s; N; }7 H" X
( B0 x1 s# R4 ^* a
Method 12# e+ N) ]/ U5 w$ t
=========- }6 r9 `! W3 p

/ O4 l% `6 ^: R( I% YThis trick is similar to int41h/4fh Debugger installation check (code 05
! c  E! J: l; |* m- E&amp; 06) but very limited because it's only available for Win95/98 (not NT)
" _$ y' v  E8 L( J. has it uses the VxDCall backdoor. This detection was found in Bleem Demo.
5 ]. j! `* @2 O& N/ o) e1 L5 R3 f0 W! t. d, [' _
   push  0000004fh         ; function 4fh
8 N2 {, z: B1 b2 _   push  002a002ah         ; high word specifies which VxD (VWIN32)4 J8 v1 A4 l* Y7 ~2 ]; l; K( c# y
                           ; low word specifies which service* t5 k6 ]. Q& i2 z1 G7 S7 O
                             (VWIN32_Int41Dispatch)! H7 L+ `  c& w, }4 T" |4 R. H; Z) x
   call  Kernel32!ORD_001  ; VxdCall
% L. J: h( p2 M  A" k( I   cmp   ax, 0f386h        ; magic number returned by system debuggers. U9 Y( {* B0 L, x( Y  E1 Z
   jz    SoftICE_detected
  a  O6 P) @  x+ T, j' H
8 P' e9 |6 `; w9 ^* A% L$ _Here again, several ways to detect it:
' d5 D# E9 K' N8 o2 l! m$ ]
( D( P$ G! w2 |    BPINT 41 if ax==4f$ E4 _4 W. v7 p7 I  ?0 [# L7 A
+ @) K/ y& }" d: B! U
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one' d- M, w" ~2 o$ x; D" W- [

8 Z0 u+ [% O8 [6 C    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A% X3 ]) W* {' T* N4 q8 _* C. a
" w0 H# ]- U1 \9 |, M4 u8 M
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
+ k7 P* L9 p, U8 b0 M4 N( ^- ?8 ]+ {& A& i, \. x6 T/ b
__________________________________________________________________________
9 ?6 D& t- C+ b  y% n+ f8 ]- v, C
Method 13
" l5 b8 o: z! u) s9 m4 o=========
$ i0 Y7 i/ a1 b7 C4 e( v- I3 `3 f$ _' B
Not a real method of detection, but a good way to know if SoftICE is
$ K% @$ K+ V6 M( [$ T6 Sinstalled on a computer and to locate its installation directory.
3 b) a6 z, ]% n# I2 NIt is used by few softs which access the following registry keys (usually #2) :
( v9 z# B3 s2 ~# n, C
. i4 z5 h, R& {4 ~8 h9 |-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
# ^) M( ?  w9 ?! H3 S\Uninstall\SoftICE5 S7 J& @2 Y; t" c8 m8 a2 r% f- R
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
3 `5 |1 `& r  u" ~( Q, l7 |) i- s3 E-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion0 e! k1 d  h3 T$ m
\App Paths\Loader32.Exe
7 j0 \4 i$ B0 a" q+ H. H. o9 e% |. u0 w6 b& w+ I0 x# [

" t. D% e$ Y0 h( e& h% I/ ENote that some nasty apps could then erase all files from SoftICE directory" @' r( f' A5 E, r' c; s( S
(I faced that once :-(* a* x1 R3 _, K8 s
. M7 o6 j! A/ t6 f
Useful breakpoint to detect it:0 w+ k1 D) F3 |6 F! M& |
  D6 A8 R- [1 ~6 X' H& N
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'( y( H' u1 z, r3 g, _8 T
+ R) M# ~" v, v% H, g" \! z; c3 \
__________________________________________________________________________
/ m7 i; f  G2 b. X! L/ \, a3 ^" b$ k2 Q% k' Y  H' E

' n8 F, Y! o+ S4 k5 a& r8 X0 gMethod 14 $ T: d0 K1 k# S: p! T9 t5 G0 T
=========
# |! H' U9 F/ k: g3 f( W' C' I/ o1 F
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
( \- f1 ^2 x0 B; U. pis to determines whether a debugger is running on your system (ring0 only).' u- S$ g# ]! F8 Z9 L6 U0 p, O

8 }, F2 L% _  @" Y* N) d# ?   VMMCall Test_Debug_Installed
$ k" r4 X  n. n   je      not_installed
' H2 Q) b) d, `; `
3 k8 j* h1 |& M! R. b$ @0 z* dThis service just checks a flag.
" d, c9 X4 t- V1 X7 F( i- F2 r</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部