About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>- [" r! n! M3 _4 ?, v
<TBODY>( v5 y" A$ o4 D1 X% M+ K+ s0 K# }
<TR>- F/ m5 l5 @% K
<TD><PRE>Method 01
* ]) @' o. \7 s( \! M=========
/ @  z1 e+ I6 c( {! g
( H5 k  ?0 h% f) f) R9 d7 yThis method of detection of SoftICE (as well as the following one) is& p1 Q; ~% }! K" V- X
used by the majority of packers/encryptors found on Internet.
1 {  Z. C( c( V, {9 SIt seeks the signature of BoundsChecker in SoftICE# R& E$ E- [% z3 l

# e6 A' v$ n4 R  l+ u' x    mov     ebp, 04243484Bh        ; 'BCHK'/ t0 Y8 w  e  g
    mov     ax, 04h
  C) i2 r! i0 M) ~& L1 g9 n    int     3       5 ~) |. r" \' i/ Y' t& S& l
    cmp     al,4
; {" k, e6 E5 c( s' w8 s    jnz     SoftICE_Detected" q& \8 t9 V, p1 m% B) b! O! r( q5 l3 c

3 n0 M4 r# g' W- O" v4 Y. [9 b___________________________________________________________________________
- m, t( k4 J9 q0 }" S5 ]! S: `4 ]( V- T; R6 H
Method 02
2 c; X$ t. h* x0 k  |  P( I, ~% A=========2 [7 [* m5 I; R. H! r  m
8 n( N: O+ y$ N( [5 B& h
Still a method very much used (perhaps the most frequent one).  It is used  t6 {" R1 P; x# A! O3 S- W
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
4 o( C0 Q6 n' A! a6 ror execute SoftICE commands...+ g- n+ E6 y7 H6 ?* ^! a; R  J
It is also used to crash SoftICE and to force it to execute any commands
0 Z7 K$ q8 o4 V/ Z(HBOOT...) :-((  & S3 P8 n" f4 x2 L' a( d6 d2 }

$ Y" E# h2 T) xHere is a quick description:+ ^2 P$ F/ o% `- ^# }) ?/ u
-AX = 0910h   (Display string in SIce windows)
8 Z/ t, O8 l& B) t-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx). z; H6 e- R3 t* D- M+ ?
-AX = 0912h   (Get breakpoint infos)
9 }& p7 o/ P( N+ {- K) e8 E-AX = 0913h   (Set Sice breakpoints)1 }8 y$ ^/ N$ e6 F) z+ N! j, ?7 _
-AX = 0914h   (Remove SIce breakoints)
# h: i( k8 {3 ^3 v/ H& o' R, F: D
Each time you'll meet this trick, you'll see:+ j+ {& J* K( }
-SI = 4647h) c0 P4 C6 s9 A; Y! |& a' C
-DI = 4A4Dh
( ]$ v4 q9 N0 P' x6 C/ F! n0 K7 U2 ~2 sWhich are the 'magic values' used by SoftIce.) H" K2 \3 ^. F8 l
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
4 o9 Z5 J- f$ |
+ l1 |2 `! U% @; nHere is one example from the file "Haspinst.exe" which is the dongle HASP) j$ q$ O+ [1 m& B0 E! i
Envelope utility use to protect DOS applications:8 B8 q1 {: L& X% d( ~" {) C7 F

, k9 C$ l8 ~, w
% X. `' {# X% x+ Z8 f4C19:0095   MOV    AX,0911  ; execute command.
1 d* E) `% h$ p2 k' R! X! Q4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
- n. P- C, h& J! O+ r% ?4C19:009A   MOV    SI,4647  ; 1st magic value.
. C( H/ }8 g5 b7 r4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
( L0 D2 z' ]( x# |6 j  Z8 e, b6 p4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
# h5 y" e3 a' E  K9 h2 k% n4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute: S8 t' r- E, m9 s. d; K
4C19:00A4   INC    CX
* b% \$ J, i( |4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
: \8 Z* Y! ^- L% F( ~& S4C19:00A8   JB     0095     ; 6 different commands.3 y6 [! H$ h9 d3 ~5 y3 F
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.6 V3 {! x. q2 P( P% O
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
. D4 D  h1 j7 \; _3 j- D7 D! E$ q: ]3 h3 w* R6 Z
The program will execute 6 different SIce commands located at ds:dx, which
7 i% W+ {& B+ ~* pare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.6 F! b7 Z3 v/ u/ `7 R* {, e/ _

4 X9 c0 F" X. J& N3 p2 u' D9 r4 k5 e* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
/ D* t$ _  {# _2 |( b: w___________________________________________________________________________  w: d8 a6 k. n! V1 C$ M/ F- {

" O7 K4 E+ F" V/ o9 R6 E; e$ |3 C9 J- N. i; z/ s8 O, e5 Z
Method 03( B) m& p- f8 K& }
=========
0 Z  Z/ M( v$ i$ N, T* S/ p& r% V1 g
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h/ l" ~; O; J' _; k" i
(API Get entry point)
5 F( X7 @8 L# T. W7 U0 z% G        
& {' ^. p  z5 ]3 s# a
; T6 Z7 D' y7 y4 @9 c$ p    xor     di,di: U/ i6 d, O7 a: Z( ^% h
    mov     es,di
- V% ]$ L0 {# S# K9 D# ~0 B4 ^    mov     ax, 1684h       - f4 K) M; q# U6 n! s
    mov     bx, 0202h       ; VxD ID of winice
3 T5 n% o, c% {    int     2Fh+ E' O3 u8 g: g" |) J( r7 U
    mov     ax, es          ; ES:DI -&gt; VxD API entry point( t1 s. v% C) d7 |: r! }$ {' |7 ~8 h
    add     ax, di( A& g! b. L; x! C
    test    ax,ax. w  G4 Q8 y" n5 Y: c( w/ \" F5 a
    jnz     SoftICE_Detected6 R4 d' D* {  [. [9 w/ h4 Q7 [

' P( ^& K" c. y0 n: o___________________________________________________________________________- G/ `; d% Z+ Q: S+ J% h" p, f" ]

* ~8 d4 E: ~/ }9 ^. O: eMethod 04
) G6 Q: o; R- l' P. f=========
8 Z, h. f2 L+ E6 |) `7 a% O' A# \# ^- g
Method identical to the preceding one except that it seeks the ID of SoftICE- L* D% {8 o/ V2 t# Z4 |( f
GFX VxD.& o! v- e; n# D) U
6 w$ v% Y* F# c  O* ^
    xor     di,di
/ c+ b' C- ^4 ?/ v) [: Z' o) d8 d/ A    mov     es,di# q7 _: o/ c! ~+ T, r9 `; m' _, h
    mov     ax, 1684h       7 ^9 ^5 m# J8 ^) g5 F% r/ x
    mov     bx, 7a5Fh       ; VxD ID of SIWVID( W# `" l! w1 M. r
    int     2fh8 t1 i: [* U: _% g" ~
    mov     ax, es          ; ES:DI -&gt; VxD API entry point$ k! S$ r1 j9 \* X$ X, z- Q1 d
    add     ax, di
6 O. u, z  r. Y, S6 d1 e2 E    test    ax,ax
' `; f3 z! x5 u( G: H1 g& \2 m    jnz     SoftICE_Detected
' ~4 [" Y, m- g+ O) P; M7 k1 N% \% ]- h1 z' ?
__________________________________________________________________________
6 y0 j9 Y# E+ G* u% x& A, L
- V% ]- B# A7 _3 k$ `9 z0 U' i* O2 c; }  b# ~
Method 053 j. ~4 L3 ~& o7 H9 ?( l+ A
=========
* U' Q6 w- H( T) K) h9 O  Z6 Z; b: V* ^5 R
Method seeking the 'magic number' 0F386h returned (in ax) by all system
( y+ e3 E  K5 j$ d% cdebugger. It calls the int 41h, function 4Fh.
1 z1 q9 E. T4 ~8 _' N2 o1 g2 YThere are several alternatives.  " E( J& |! J1 J$ V

+ @# O! E" S! L5 d3 o3 Q, T: x; NThe following one is the simplest:' q! ^$ C2 _  ~1 P; F& N, D# R9 I
  x2 g* S9 V( @$ i8 p2 r. R' ]
    mov     ax,4fh! ^: p! v  Y" }1 f- S' O) B
    int     41h
/ I) T" S  b. E1 l  {    cmp     ax, 0F386& z) j/ O5 ]3 ~
    jz      SoftICE_detected7 N7 y  ^2 W# l- M! {. Q
. T+ n) e  P& n. ?: H" t8 R
8 d' }/ |0 Z; z- w2 e
Next method as well as the following one are 2 examples from Stone's
: X( p( q/ h  ^4 }( q"stn-wid.zip" (www.cracking.net):9 W3 `9 P  w, `; ?* B/ b5 u

1 d* g$ F0 K: Z7 c  j" i    mov     bx, cs
* i+ }: U6 r6 C& {    lea     dx, int41handler2. E# F" G' L& W+ A8 h" i$ f5 E
    xchg    dx, es:[41h*4]# N) b, ^7 c, C, l/ }8 H
    xchg    bx, es:[41h*4+2]' T7 q6 H$ U3 t" |$ G  D
    mov     ax,4fh8 X$ t1 j! F( o: Y/ C- S) C
    int     41h6 l' b( H  f+ m# ^4 W2 V( W
    xchg    dx, es:[41h*4], O9 E( o: D% n$ N+ f" p( Z/ G3 Z
    xchg    bx, es:[41h*4+2]
# l! O& L+ \, D% F" Z    cmp     ax, 0f386h
, D$ k( }' N& L+ b0 w0 a% B    jz      SoftICE_detected
7 k$ o: J( K9 S
4 Z  e- m/ W4 [" D3 ^% }- \8 z3 iint41handler2 PROC
* E" y( [) a# I$ g    iret
# G& N" ?( \) ]4 yint41handler2 ENDP
8 B7 \7 K6 j; U; T2 v1 U$ T0 X! ?3 X. ^7 k5 `$ _5 d

# u" r0 p& r/ ]3 n_________________________________________________________________________, o, S! Q* l% r/ `. u+ U: h; E7 `
+ x( S5 \, L% s

  T! g, u% N5 k1 V( LMethod 06
( m* j* O4 M' G( G' C" j: e3 b7 p=========
9 N' Q! v" U% R; a3 m5 H9 }% F+ [: o! J& Y
' X, a3 P* {; G3 ]8 r4 D% W0 u! U
2nd method similar to the preceding one but more difficult to detect:2 i$ k0 \  w' P: e- e, G/ g
$ v' F9 C+ M) o
+ J, o- J' M: ?  H9 b
int41handler PROC, m0 C0 }$ D1 N# k" p
    mov     cl,al- W5 ]/ v! }$ `+ o( X# j  C0 }
    iret% k" R9 ?, x4 V3 a
int41handler ENDP3 Y* U8 O" D; R8 ~8 r

* A( }! P/ @1 U+ k+ R5 e/ ~( n" `5 k# N6 o
    xor     ax,ax- ^9 R# `/ D) S$ T* |$ i4 W
    mov     es,ax
/ ~9 N1 j' E, C1 C    mov     bx, cs
) `1 v3 J5 h) Y/ N6 w+ \/ |( _    lea     dx, int41handler/ c9 r1 g. A" n' q' o
    xchg    dx, es:[41h*4]$ p5 ^+ W" _8 v
    xchg    bx, es:[41h*4+2]
( m) Y0 s2 L$ _' |6 g1 u! @7 T9 M! i    in      al, 40h& z3 j2 S1 A; [+ n7 Q* |; w
    xor     cx,cx3 u  V7 b3 v& ]% W: ]9 Q
    int     41h: X9 c! s9 t, c2 W* a
    xchg    dx, es:[41h*4]
: W% a5 s1 T$ |2 i6 t    xchg    bx, es:[41h*4+2], _5 }, ?: v& {7 e
    cmp     cl,al
: O3 `7 l" g- A% K. i+ t4 V    jnz     SoftICE_detected; x( @4 G4 N: u% S3 ~  w4 ]' J
% s8 M9 g, a3 N" @
_________________________________________________________________________7 J* @. W7 y! g% U
9 _" D- b2 d" ]8 d* P  M
Method 077 u8 _: d" r+ p0 y/ f( \- F
=========2 r% O! @; u7 K" k  g4 q' E

" {" C  v7 W: q) z( V6 b9 |6 bMethod of detection of the WinICE handler in the int68h (V86)9 K' o8 u4 r1 p) U3 v

5 R; P$ e. ~  E- f    mov     ah,43h
4 k$ `! C7 p. x/ c0 T    int     68h
; ^$ e6 S6 _/ N' C5 A* `9 W    cmp     ax,0F386h
$ E+ L1 M$ u1 m" z    jz      SoftICE_Detected3 w. X! P2 A, n
& k4 L! Y+ }  I6 |
7 `' M$ h3 o) x: [  l
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit( I4 q. T3 v7 m% O7 D, R& V7 z4 v; B
   app like this:
$ f7 J; c" n, O3 C6 F  Z2 K0 x& w* F8 E* B. g! g) Z
   BPX exec_int if ax==68# D6 K3 U! |9 r. O" H/ y
   (function called is located at byte ptr [ebp+1Dh] and client eip is" k* V" i, o4 j0 i5 O2 j" K
   located at [ebp+48h] for 32Bit apps)
1 v- h. B6 T. C2 X4 f( ?5 ^__________________________________________________________________________
; b" w2 b' n* a* p6 D2 l2 H7 u% \: Z- d9 {; k' t' p) W

1 x1 O* [: p# ]' P9 C  a0 }! cMethod 087 [! V& q8 n" G& j
=========
) S$ ^4 a# s7 ?8 o' T  l$ R4 p3 j& e5 d6 p
It is not a method of detection of SoftICE but a possibility to crash the6 F5 u" R) s3 f6 A
system by intercepting int 01h and int 03h and redirecting them to another, V6 X1 I$ w# ?
routine.6 M5 P. ^5 l$ E4 c6 `4 j- b3 {5 c
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points9 S( C' h3 S6 e! o
to the new routine to execute (hangs computer...), [# B. ?3 v5 {0 z% d% }  R, q; M

. b! h+ x2 {6 C; {$ ?8 e    mov     ah, 25h
' m) M: A, h9 [9 u$ v/ r    mov     al, Int_Number (01h or 03h)
& l( d% H# ]. y8 f( J! i    mov     dx, offset New_Int_Routine2 R1 P1 E; V7 b, p2 j
    int     21h
* M8 Q. @' h/ Z/ f! h8 I; u2 Y9 q. W, Z' k" O) W8 Q
__________________________________________________________________________
( k$ L  e0 ]$ h; @9 D) Q9 n+ ?) }/ i; ~7 V/ ?% _
Method 09' b) X. A; D! Q! v1 T+ W2 U
=========  d  g' m( U8 u: d& Z) Q7 X- w1 N/ Q
4 {9 r$ E' d6 B, u: l* K) F
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only& B- v6 R9 G) w. T  o. @7 R6 A
performed in ring0 (VxD or a ring3 app using the VxdCall).
  N6 @. @* }7 ]2 I! C! ?The Get_DDB service is used to determine whether or not a VxD is installed
0 f5 x; B, X! n; J3 sfor the specified device and returns a Device Description Block (in ecx) for1 |) C% ~* e* w) z
that device if it is installed.
9 k/ }9 X' Y- Q2 O1 G* O* I! v3 v( {% z  e7 l$ d
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID* b/ C7 R+ _, v. [
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)' K0 _2 _* f$ ]0 G
   VMMCall Get_DDB) S7 ^% s' a3 C+ F, X2 u
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
1 P  a# C+ l4 w/ H, Y" _. W& B/ l2 v
Note as well that you can easily detect this method with SoftICE:! s# h: X9 Q9 `! d( u6 H$ [
   bpx Get_DDB if ax==0202 || ax==7a5fh
! k. C3 ^' h2 \
% z; `1 t! r# r! b" v4 b__________________________________________________________________________
$ Y* j+ w; t7 j! m: N' t4 P; {! M" `
Method 10% f$ R5 l$ ]  y9 k) N
=========. \# H5 A7 |  c
# t; {# }- C' A. d' ?& Z2 T
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
/ ?* B2 h6 K( a0 N  SoftICE while the option is enable!!. S; c# e+ h# e- z6 U

. ~4 s/ E/ e% f! X6 iThis trick is very efficient:6 |5 n& O1 T" {3 f2 H& i# u% Q
by checking the Debug Registers, you can detect if SoftICE is loaded; d3 [+ E5 j8 I7 L" a* r
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
' c, q+ K& ^- E: x6 s* mthere are some memory breakpoints set (dr0 to dr3) simply by reading their
% v( g8 A! m6 |' T# Svalue (in ring0 only). Values can be manipulated and or changed as well
, {- P3 l6 V, q1 N# B(clearing BPMs for instance)  X/ J, a$ x) c0 H
7 X# Y9 \1 c. e2 o( a5 H
__________________________________________________________________________5 m) V( Y3 f6 N/ P3 t% _( Q
" n& ]- F& I" L& @
Method 116 X" [  ^  |; A" i- i3 z
=========9 B. Q. v6 T. z# H& G4 {

+ z. X; L$ @6 G& BThis method is most known as 'MeltICE' because it has been freely distributed: l! j' x( f3 h& w5 @8 p
via www.winfiles.com. However it was first used by NuMega people to allow% F( _+ k/ _. X/ x
Symbol Loader to check if SoftICE was active or not (the code is located/ o# F4 l9 C3 Y: s# ]1 x
inside nmtrans.dll).. b  t9 w# N0 K& |% e

. m/ q5 {: O* T% r8 J. r6 TThe way it works is very simple:* a: p- w* d2 u; O$ q: [
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
5 F8 }4 F% l0 n7 o: q  T$ kWinNT) with the CreateFileA API.
8 ?! Z9 p' `( }
( w$ K, k- Y4 Q. r) _0 KHere is a sample (checking for 'SICE'):7 r& k& K1 i: u1 n' D
* b$ A" S7 j9 l  J' u9 q" V+ @  `
BOOL IsSoftIce95Loaded()
/ I! \, K4 N! }' F% D- F% \5 w{6 @" ^- @: x# H0 ]8 n6 Y; D
   HANDLE hFile;  
& q* L; ~- s5 \   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,9 \4 J' C3 U) Y6 ~5 z8 n5 C
                      FILE_SHARE_READ | FILE_SHARE_WRITE,' l, s, j7 D3 \1 c9 `8 P7 ~$ t
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
- p* q) X% |- J& O4 ^/ S, r   if( hFile != INVALID_HANDLE_VALUE )
% @# l3 u1 F& d- J3 H   {
) V* l0 q9 Q6 a0 O- o9 ]      CloseHandle(hFile);) i7 U$ X% ^7 A2 f" J
      return TRUE;
$ d4 S+ y9 B1 @. U0 R2 \   }" i& r' F& n* A. J
   return FALSE;3 G! i* H8 a# _5 Z" ?' ~6 R5 B
}
4 K! M; m1 _1 w. V! I+ K0 u) T; T4 t* R5 `& z/ T& E
Although this trick calls the CreateFileA function, don't even expect to be
& Q# K. E2 w9 Q& }  H8 Y% Mable to intercept it by installing a IFS hook: it will not work, no way!8 C4 t7 d6 _; ~# v
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
/ _/ x& q+ }' V) \. Cservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)" K  R# m4 s% H, H8 }" l
and then browse the DDB list until it find the VxD and its DDB_Control_Proc) |% ~# I/ M$ s/ D) G
field.
$ h4 O6 ]3 d" U: O- H5 x6 ?In fact, its purpose is not to load/unload VxDs but only to send a 8 N$ F! J6 b! K; C
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE). d- W( K6 c9 V: ^! P
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
) E& v  n' X9 E/ l: @to load/unload a non-dynamically loadable driver such as SoftICE ;-).- v/ V$ o0 i7 v0 |
If the VxD is loaded, it will always clear eax and the Carry flag to allow2 _" M8 S  l+ u( S) K
its handle to be opened and then, will be detected.+ F1 a  M# E- m. m" u1 H# y) A
You can check that simply by hooking Winice.exe control proc entry point6 I# V, @4 o% t6 _1 n2 A# w
while running MeltICE.7 ~8 M4 }9 ]! |, v- O
( O! u. I: r5 s' X$ I5 J
  Y* s3 A, L, Y& C4 P0 T" U
  00401067:  push      00402025    ; \\.\SICE2 p+ H- F0 L! D& ~- n5 z
  0040106C:  call      CreateFileA
6 W# ]5 _, b  y% K7 Q+ u* [  00401071:  cmp       eax,-001
. b0 W$ x% I8 A. q6 C$ m  00401074:  je        00401091; l: ?- h; @5 G4 G% u
1 W) w  R" |/ V) t: X
5 C% i# n8 A9 |8 \4 `# L" F
There could be hundreds of BPX you could use to detect this trick.
" C& B7 c8 e: e. Y# {$ I-The most classical one is:8 O* u& F. t8 O. L. }4 m
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
4 N- s3 s' i5 ?    *(esp-&gt;4+4)=='NTIC'
+ }- ^1 K. _& C' h# C0 G+ L" z5 f) e
-The most exotic ones (could be very slooooow :-(
8 l3 V' Z, S4 O   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  . E* l, l( i+ j! Z
     ;will break 3 times :-(8 ^4 O9 o/ ]+ X  V
7 h# o  d# U+ y! J; N
-or (a bit) faster:
9 a& l  |. V5 O9 L- i   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
# o+ {$ s8 w, s+ T
" b: `6 D( ^' V8 ?7 [  U9 L   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  ! P* \, E& V3 x9 A" Q2 P
     ;will break 3 times :-(- u$ h% z; u2 g

6 M- c* ~  W* T% Z/ r-Much faster:+ A; c1 _3 {) n- H9 e& \
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'$ H# N6 J7 ]" r$ Z
' A7 Q% T2 M7 F- ?" X
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
! P" x1 {0 K1 w3 l3 a9 [function to do the same job:
( X% u' Z6 X9 h
$ Q0 T8 Z, |# Q2 _+ a) O0 H   push    00                        ; OF_READ
! z* E4 A: z; o- O" Y% N4 x   mov     eax,[00656634]            ; '\\.\SICE',0
4 F  @1 C0 Q  A+ z9 F; H0 c   push    eax+ o6 I  p4 Z# Z
   call    KERNEL32!_lopen
; C9 a2 W5 m7 n- u4 M' G   inc     eax
4 y! ^  |5 m' h& C5 i, N- Q   jnz     00650589                  ; detected* W+ v. l! p& u" y6 J2 J" _
   push    00                        ; OF_READ- J3 L4 Z5 h/ P" X) I% A* S
   mov     eax,[00656638]            ; '\\.\SICE'
0 h# o% i& h6 Q9 ~/ i   push    eax) c1 d0 Y, g# {$ f: d
   call    KERNEL32!_lopen$ ]# e4 i/ f9 ~( P
   inc     eax& s% f3 k. t' A. U" N
   jz      006505ae                  ; not detected6 Z( Q& b2 G; J( y+ t, w! `

) E" ~  g6 @7 C* `( i# k3 N. q, t8 Q
__________________________________________________________________________5 W& H& I) O9 v3 U7 C
9 Y6 y3 p* _% X' ~) m: _
Method 12  Z1 y* a8 V# O1 c. ~% H: q
=========
0 Z: K1 U! X0 e8 I) J) s6 m5 D1 r1 k! T. d# y+ e) B
This trick is similar to int41h/4fh Debugger installation check (code 05( V7 O" d8 b0 L4 Y6 y7 m  N- t
&amp; 06) but very limited because it's only available for Win95/98 (not NT)
' i: s: n% f' V9 j: k$ Vas it uses the VxDCall backdoor. This detection was found in Bleem Demo.
$ l2 A- E8 h' X6 S
1 i  R2 a) ^* `4 R9 V' O   push  0000004fh         ; function 4fh# v% A/ I" R9 e4 C9 I6 z& Q7 |* l( ~$ E
   push  002a002ah         ; high word specifies which VxD (VWIN32)0 E" U, Y) X6 ^$ O
                           ; low word specifies which service
5 w; \4 `7 x% C& {) a                             (VWIN32_Int41Dispatch)
# I$ i" _0 e" R   call  Kernel32!ORD_001  ; VxdCall
7 Z7 e0 i( |+ e. o. H  k& E5 D# @& |   cmp   ax, 0f386h        ; magic number returned by system debuggers
# k* i4 @2 _. k, u' ?  ^   jz    SoftICE_detected2 S1 c  U5 r2 y8 D; G* l
4 n9 y) E! i) z# ~# N' L
Here again, several ways to detect it:
/ Q) m, z. H9 U
. U/ t% w6 V, M* z2 P    BPINT 41 if ax==4f( d# e% L6 W7 o8 I1 `4 @, Z

' y( F9 l$ w- c" K3 V1 n; ^5 G    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one  V# [4 a" q" x3 [: F2 I5 {& ~
1 H9 F% R( N$ j# @  l7 H1 g
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A' ^8 R6 x. ?2 A) W) a# T  X
0 G7 x4 o; q: E
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!" u, u' B! V% O* Y0 t/ J

* A4 `7 q) V' ~: n8 ^  U9 S( p/ K__________________________________________________________________________
" Q% d. C8 D3 C0 z8 c' L, I
1 l5 w+ u! ]; W4 \: w+ HMethod 13
, t5 X1 t* t' u6 V8 w=========
9 D# C5 s, ~6 q: y$ u4 q$ W' @+ i1 {% n8 S
Not a real method of detection, but a good way to know if SoftICE is7 ^  \4 D) P5 B) I6 I# f1 Y% |
installed on a computer and to locate its installation directory.
6 p# j& {  x2 {: J( s8 ~It is used by few softs which access the following registry keys (usually #2) :
' x# X' T% g, W8 U
4 j  j$ p0 e3 u" f- _8 `-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
6 N# I& c5 M, }3 K" C! v% X\Uninstall\SoftICE
  c3 Q( U; E* D3 q' z! k) h9 `-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
* c9 ?8 x# V7 N: C-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion( M' y) [1 I) X1 i5 l
\App Paths\Loader32.Exe
# H0 A0 _! x8 l" C5 c7 g
9 I! a% r7 B+ ?; M2 c6 t( t8 o2 }
" @* I+ G- o& X( I3 t& TNote that some nasty apps could then erase all files from SoftICE directory% k2 Z( r; C& z7 u" p
(I faced that once :-(% Q5 i5 h- j# F. S- A" T# W
4 X- {( N7 i0 }$ N# G8 B2 c. T
Useful breakpoint to detect it:
/ ?3 k9 F1 X. Z; E! u5 ?' N1 U7 ~6 i
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'0 t' ]9 P5 K) C" W" I- X$ o

: H2 I5 I0 i! K2 d" s* D__________________________________________________________________________5 [$ v) [9 Y* g# e& x
* x0 Y4 r2 e$ Y! g8 k

; e' s. }4 _3 _Method 14
/ L) E6 X  H+ I- J( C" N=========# e$ U3 ~. u' U- j' j! K+ S
" _$ S$ I1 L$ y6 c
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
! H, q! l# x  J, |4 J2 D2 v% bis to determines whether a debugger is running on your system (ring0 only).- ?5 e5 W; }* h* l

0 o0 i; j2 _2 `) S; ?! E5 C+ d" `$ A   VMMCall Test_Debug_Installed
5 ~8 d9 j$ o5 w* C: ?( T2 j: W   je      not_installed
# L% t( }* T/ q7 _2 C5 k1 x: u! q* i8 A* A
This service just checks a flag.% Z% A6 [2 T' J- S# z% [) b+ }
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部