About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>* J2 o" T2 R) r9 P9 H- c- x
<TBODY>
- K2 `7 ]  z& p: L: g& _<TR>, F) ]5 N; z: V4 b' T) D/ o' j* s
<TD><PRE>Method 01
$ m4 }" X: p+ M. f! R* H=========
2 M: s8 J4 B: s( t' b- x: d" \9 O
" y7 }: _+ W1 `; y7 wThis method of detection of SoftICE (as well as the following one) is) Z; C! }. t5 u* f! ?
used by the majority of packers/encryptors found on Internet.
% x( h5 w3 B, h0 V7 P; j/ WIt seeks the signature of BoundsChecker in SoftICE2 _5 D* u) R! c' }7 G0 ]
* L* v% U; [3 n. I9 D0 `7 k
    mov     ebp, 04243484Bh        ; 'BCHK'1 j8 v( w  C$ W
    mov     ax, 04h* Y1 ^, C7 U( `8 l
    int     3       - n' o. L3 T3 _6 k4 |# x
    cmp     al,4( w/ \$ i& F$ A  E5 x8 D
    jnz     SoftICE_Detected
& p# S: R+ y' k) l* U) k2 m- q* X4 _* [+ e7 y; }/ q( d. l
___________________________________________________________________________
$ k1 |# K+ L5 |' b7 j) J$ B  M) B  u3 x, G. }& O: R- U; @
Method 02
( y) I; M  H/ e) z( x8 N9 D=========9 w& p  }8 \9 H8 V
* g0 o7 f1 s. _4 |% r/ E" v
Still a method very much used (perhaps the most frequent one).  It is used8 E9 E8 W: B1 B0 M0 w
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,9 P1 J' |/ U, C  c# ~7 d0 b2 `' B9 R7 Z
or execute SoftICE commands...
. `  b6 e9 x, cIt is also used to crash SoftICE and to force it to execute any commands  q& t6 N/ h/ D0 p3 \# h# t) J
(HBOOT...) :-((  
; G, i& I& C! O% |1 _. K- W3 g$ k- P, v. m' ^& E2 Q% P2 R2 V
Here is a quick description:9 A8 @' l) l0 z/ A( [
-AX = 0910h   (Display string in SIce windows)
  z  S, h% R2 R/ ?! e-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
7 t! M" `* x  @. P% A-AX = 0912h   (Get breakpoint infos)
4 Y6 f) n" Z# A; P0 i" ^-AX = 0913h   (Set Sice breakpoints)0 W  K# J: @0 f! \; e% ]0 h, Z
-AX = 0914h   (Remove SIce breakoints): _  t: f7 g6 p4 i4 l2 I+ e
, Y( Q8 u3 w0 c0 ?5 E2 w' N. `) |  U
Each time you'll meet this trick, you'll see:8 s. h2 l3 P! b
-SI = 4647h
, C4 O. I' |7 `-DI = 4A4Dh% I# N  s' U) D/ B& o
Which are the 'magic values' used by SoftIce.. h1 ~: m* w) V' O: g( y
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
+ D( r9 g" y0 V- G8 w# u% t8 k* b$ L5 g6 t0 ?$ ~$ D2 U
Here is one example from the file "Haspinst.exe" which is the dongle HASP- M, }) w& g8 L1 k7 A
Envelope utility use to protect DOS applications:' F9 O+ f  i! D9 t8 C! `

. Q$ l; Q8 a3 K2 S7 g" V1 h% N. p; ?* K- _7 E  V, e
4C19:0095   MOV    AX,0911  ; execute command.
6 V4 N9 }- |9 ?$ s: A, d4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).  x: m9 [, u5 W7 O1 ^/ w
4C19:009A   MOV    SI,4647  ; 1st magic value." r) t4 N; G* L- W
4C19:009D   MOV    DI,4A4D  ; 2nd magic value.8 g7 a4 Q$ h/ W7 l( }9 t
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)1 ~7 N1 f' z( S$ O- ~; ?
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
) J& I$ O) {# @4C19:00A4   INC    CX
# B) E6 |( o" R4 h* Y- y4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute; ^: I" e/ C1 g: B
4C19:00A8   JB     0095     ; 6 different commands.5 M- b0 Q0 q5 {$ \4 w2 o
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
0 n$ r4 o! U+ s4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
. e* H) j% p, r# q; l# _) O* \
) F  V! v8 H1 N( A. gThe program will execute 6 different SIce commands located at ds:dx, which
, ~! r9 u7 O( I5 Kare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.5 o1 [* c6 _4 s/ t; h
& K6 h# q' G3 H
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.: R$ t0 Z8 d. G% b# W" U
___________________________________________________________________________7 ?( z4 H' ^+ @1 \/ s

4 Q% u6 X+ o; ^; A1 m# ?4 y5 P" C2 j8 U1 c
Method 03! Y1 f3 j  a0 p. c7 b5 P% k
=========0 i! X6 @. X7 d0 I; u7 W) O
9 t- t- [# `' T1 ?
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h) ~6 i) Z; d3 ?8 Z0 Q1 l8 V2 P
(API Get entry point)
) H3 m: R" Y; h  C" G$ u! K        3 d1 m3 K, I* f
+ u/ S: Z  ^9 L
    xor     di,di& f7 k3 `. c: R6 O' G
    mov     es,di, A9 H2 {! h: Y3 \5 w
    mov     ax, 1684h       # k. t! F' M$ `, U
    mov     bx, 0202h       ; VxD ID of winice) ?: o. R8 k( K7 b
    int     2Fh& K) M* a8 T. |/ ?  \
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
9 _" l+ _; s; V% Y, O1 Z, D    add     ax, di
) V& O: o8 k) l    test    ax,ax
" G* b8 N6 o* y4 O8 H. ~0 N; Y    jnz     SoftICE_Detected7 S" U/ q+ ?+ E  }! e
: \) N6 Y7 p/ k+ o1 x0 m
___________________________________________________________________________
( H: G% l2 `* F2 n0 j3 z3 a
. w: n2 g. P+ J8 X* wMethod 04! Z2 j' u6 a  j+ B1 u# }2 D
=========
! a; V: D6 J( j" t  `# e% M! L3 B: l  v- l
Method identical to the preceding one except that it seeks the ID of SoftICE3 d3 T. G" |& c; T! Z$ w, B6 n/ o
GFX VxD.
! n9 O% E' O) A7 G1 {. L2 c+ ~; M0 Z
! C3 g% u6 p& H- B1 j    xor     di,di) m+ {. d6 G2 Y  _5 {9 {5 S
    mov     es,di; }* A9 m) D1 {
    mov     ax, 1684h       % f' P6 W3 q7 H
    mov     bx, 7a5Fh       ; VxD ID of SIWVID$ T! i6 D$ _6 F: ?
    int     2fh
$ l, s  A  v, |    mov     ax, es          ; ES:DI -&gt; VxD API entry point: e+ N+ E5 V' y/ p" ]
    add     ax, di
+ |  C! m0 g0 S6 g& Q( L6 S$ J4 q+ X    test    ax,ax" ^3 ~1 G5 u( e3 p1 N2 p: g
    jnz     SoftICE_Detected
, x9 ~0 }4 s0 c! X/ J% W3 n3 [# Z& q$ Q4 c: h4 A3 ^
__________________________________________________________________________) Q! p5 [" W5 u- u7 l

, {0 E/ Y) P1 R, f5 E2 [, x6 Z6 W5 ]5 r2 @& j  S3 h/ a
Method 05
! R$ [  B1 `5 F# c# P: N=========, h0 l1 _! }; P

( S5 u- d7 D2 |8 `* aMethod seeking the 'magic number' 0F386h returned (in ax) by all system$ n* i5 @& I2 r* E: V
debugger. It calls the int 41h, function 4Fh.- D# ?$ y  z& A3 I
There are several alternatives.  : Z- F9 P5 G- p3 b) d( p

- a% ^: i$ y' ^& ]3 d& P! tThe following one is the simplest:* d4 u* H; O' S9 V; K
. V; p) X/ p* a- U! `
    mov     ax,4fh
( `0 ^& t7 l. S3 ]6 A& k7 c$ C    int     41h
; v* a) O% `, l    cmp     ax, 0F3862 Z2 c- Q4 S. W# J: @' J" b" K
    jz      SoftICE_detected
4 q# K% C' v- O! t( r4 Q: Q2 D$ K! S6 B& @5 K

$ E- v# V  q( b' `Next method as well as the following one are 2 examples from Stone's
1 z# d  q8 G0 _: v"stn-wid.zip" (www.cracking.net):/ P- B% L2 S6 d0 `  s, y5 j
. O7 I9 P' n/ s3 e5 I
    mov     bx, cs
5 n/ s7 c8 m- d" H9 f% W    lea     dx, int41handler20 [  e( A( E* a0 d
    xchg    dx, es:[41h*4]
: F7 h4 a6 Y; I6 x6 `, v" G5 g    xchg    bx, es:[41h*4+2]3 J' D1 T( t% b1 z9 E; q8 z
    mov     ax,4fh2 }! v( E. y# u
    int     41h- b( t% f) `6 t1 u# W
    xchg    dx, es:[41h*4]! I3 v5 W, n) y1 O  I( ?
    xchg    bx, es:[41h*4+2]# B8 V5 A! }% }- t- U) S
    cmp     ax, 0f386h
$ B6 T' ^( _6 d1 m    jz      SoftICE_detected
" D; l. F# A) m7 h+ U1 S! A5 b3 p+ X& e/ C/ D4 s" C; J
int41handler2 PROC
. @) n" ], P, K& f5 v% t- P    iret( v4 H2 x' C  C2 q3 J# R
int41handler2 ENDP
- E* x' p1 h. w6 K' d
9 ^8 {( g% G5 \, a5 M% `
# u4 z( x* P, T3 H_________________________________________________________________________' U. ?6 B( }# D& M& v- e" v
6 m) V2 O' F3 C/ t+ P9 l
" J( c$ a7 r7 i; r6 b8 C
Method 06
3 [6 w9 K1 [, U# A/ p% {=========: \+ g, U* |/ s7 z

0 K5 J& a/ ]: T8 k8 B0 `2 R
, \' R% C' X/ }' d2nd method similar to the preceding one but more difficult to detect:
1 u9 o# Q. C' p% z2 `: `; T+ |9 b( {  A6 y0 S  l; B
; a: u4 ]! }! H7 F& }
int41handler PROC
7 T* C' X3 @, n( y    mov     cl,al
  B2 x. r# ~' q    iret
* m% h1 b3 Y5 Q) r$ vint41handler ENDP
. g, q8 M9 a4 m" w: l7 _! Q. d6 O
. E) R/ M9 t- n* ]: M$ }' T1 o& ?  t/ K, C5 c( ?
    xor     ax,ax
7 u; K. h  ]6 W) F: S# v% _    mov     es,ax/ r+ ^  P* b/ {, s! a: A* H% P* p
    mov     bx, cs4 P- {5 N5 L: ~+ {, b
    lea     dx, int41handler7 q7 a) Z5 E* P1 q
    xchg    dx, es:[41h*4]
; x, G* `- h' ?% }" L" y, t1 g  H    xchg    bx, es:[41h*4+2]
) u! ]" p( p: C9 ]    in      al, 40h
1 |4 ?: `8 L8 k" i    xor     cx,cx) I+ i  b; T* U, \
    int     41h
% {" @. r- @& m8 Y; l0 ?' A    xchg    dx, es:[41h*4]1 ~) h, i$ K, {& l1 t
    xchg    bx, es:[41h*4+2]9 t3 R! V" f8 w  b, r
    cmp     cl,al
; X$ Y$ r" I: Q% c4 X6 J( P# U    jnz     SoftICE_detected
+ R( T" j  M9 N" }+ h! n& {" G6 A9 b  ~7 v
_________________________________________________________________________: ~. j; H3 \- o* G. }2 e) g8 l/ t! S
4 h: @  U) |' U9 w2 m
Method 07$ u( }, v6 ^3 P! t! u& M8 f
=========
4 [# m' h; M0 B7 M# X0 r
' J9 h. j9 W4 n/ w2 p: _! [. zMethod of detection of the WinICE handler in the int68h (V86)
  X( `1 c( T4 m6 u  n* Y, Q" U5 f' R+ L/ V: T* S4 x" B( M0 Y
    mov     ah,43h$ w: ]8 A, j6 {+ _# p
    int     68h
$ D. S" e& o" c( K' ]; }' J8 y    cmp     ax,0F386h4 l2 E% c+ B- Q$ P# M* y
    jz      SoftICE_Detected4 h  y4 i- A7 i: K1 [# y/ {
- M: D8 A( ~1 A0 N2 f

# x6 }$ C! J, `# `2 e# Z=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
& D: f" `. j8 [: i7 v   app like this:; L/ C: T1 ?0 X
; x) |8 D/ n4 ]3 J+ s# ]
   BPX exec_int if ax==68
7 `) B! b0 b6 F. [; \3 U   (function called is located at byte ptr [ebp+1Dh] and client eip is
" c$ T, y0 i* u! E* f# q9 |7 B   located at [ebp+48h] for 32Bit apps)
. R1 i" d. Q) g: I__________________________________________________________________________. g# y$ _/ _3 O$ O, `2 h2 w
8 P  q( }* v. O+ S6 n3 {, X9 B9 _
8 b# w: ^3 k# ~1 c: T
Method 08  X# b1 K% N! C$ P6 z- s# I
=========6 y- O7 a7 V. w1 \" }3 h- Q
9 c* O0 a' Q: Z) ~
It is not a method of detection of SoftICE but a possibility to crash the( {( E2 m* b4 t; y- r
system by intercepting int 01h and int 03h and redirecting them to another# `6 [# P) G' p
routine.& R0 U1 L3 ]: O: c
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points; Y4 t! ?0 ]  C
to the new routine to execute (hangs computer...)
. p3 k  M* i8 W9 z6 @, U) @5 e. m' h% p# O
    mov     ah, 25h
4 [0 X; y; e7 f3 U9 q, b    mov     al, Int_Number (01h or 03h)
6 Z% c9 v: x, J3 q! q  j* K: [    mov     dx, offset New_Int_Routine
$ k/ J3 [( V2 c. E$ l    int     21h7 k2 ]4 R* g/ @, S9 h2 @: }
3 J0 {9 y0 q1 h6 @/ y4 P/ o8 u
__________________________________________________________________________. W; G7 F2 q( n8 \2 d% Q
; S- ~0 ^, Y% X( U5 ]8 z4 l
Method 09! Z! M" J$ k  x" A. Y/ ~
=========
" F* w: T2 k/ z1 K8 v1 h# f8 D- x) J8 D" ^8 O; X' C' t$ I
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
. h( F" M" C3 k! Y% \5 }performed in ring0 (VxD or a ring3 app using the VxdCall).
3 [- j5 D$ W, g, TThe Get_DDB service is used to determine whether or not a VxD is installed6 P$ R- m+ r: L, T
for the specified device and returns a Device Description Block (in ecx) for
8 x( w, s" Z. Pthat device if it is installed.0 g1 ^4 x: f5 {
, c9 s, {4 ?7 a( r
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID( p, E" f2 n- }
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-): n) f, k- ?1 j0 o0 f
   VMMCall Get_DDB
1 W2 ^5 {3 ?+ o% f; M9 m% |   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
2 y9 p+ h3 i3 ?7 y1 C% b2 i* [
Note as well that you can easily detect this method with SoftICE:/ r! ]" c& l  h% m* z& L9 S* n) d
   bpx Get_DDB if ax==0202 || ax==7a5fh
& z  N4 c7 g8 C5 n) s) p. c1 [5 u& z# Q: e2 K# v) u
__________________________________________________________________________: J1 i% d. b( E. L. B3 }7 c
( q' `# [! |. z( F
Method 100 L) }8 [3 ^0 `) x
=========5 G3 j- I& {# n. y
! k* E, u: Z- p' Q$ F& X. C& [
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with  a. c# B+ n2 q. Y; S
  SoftICE while the option is enable!!' ?4 ^3 C& l" |7 _1 |. Q$ T
1 z8 J3 {4 N  }8 J
This trick is very efficient:( A5 _* S( m3 y+ q; Z8 N' T
by checking the Debug Registers, you can detect if SoftICE is loaded2 W- @9 @9 J+ N& f- ?3 }
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
! I% X% @& F' {! e3 fthere are some memory breakpoints set (dr0 to dr3) simply by reading their8 p& C( m* u. C; d7 [. p7 L
value (in ring0 only). Values can be manipulated and or changed as well
6 X! G4 ?" F1 F, ?# ^(clearing BPMs for instance)
# X9 w* [2 g* ^1 o" R  p+ q  t% W/ V2 N+ t0 j7 b
__________________________________________________________________________' B' M" W2 Y% b

2 T7 T0 A  s! o! h* U9 TMethod 11
+ M6 Y) F- t9 E' z4 r=========8 B& y: l. p8 Z1 |4 f: x1 u3 E
! x% c1 K/ @5 _) T# I6 ~" W
This method is most known as 'MeltICE' because it has been freely distributed; M  ^4 {& v0 c9 |2 i2 ~4 B
via www.winfiles.com. However it was first used by NuMega people to allow0 b# Y- o3 L1 q/ A( P
Symbol Loader to check if SoftICE was active or not (the code is located
4 b1 d" t& d3 K' Ninside nmtrans.dll).
: p! M/ Y9 H: s; c# x0 y" H( p9 C
The way it works is very simple:0 h! b  N' A  U8 G0 r% c4 m  p
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for* ~) d( S* \$ V% r3 g
WinNT) with the CreateFileA API.4 B/ m/ ^6 S' Q5 L" g) S$ m

* W; O3 R( `6 E# t& K* QHere is a sample (checking for 'SICE'):
/ k+ ~+ b6 l9 U' v
; ?3 E3 `! G0 ]# {7 e, b2 @BOOL IsSoftIce95Loaded()
1 D. M/ h$ H, L) V3 I' X{
0 C+ P( E% ?! L   HANDLE hFile;  
3 I0 v1 J' @! J5 u, N   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE," `2 `; r8 T1 s8 j% K+ `9 i
                      FILE_SHARE_READ | FILE_SHARE_WRITE,% I- V  [0 w+ J$ C" u! [
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);( E$ n) ]) R/ _" O9 I8 d$ L
   if( hFile != INVALID_HANDLE_VALUE )
6 S4 z3 q/ d! r4 q. @   {
% ?9 L4 E! {2 @! U9 {      CloseHandle(hFile);$ d2 c0 M' I2 T! Z# W) `
      return TRUE;
7 R: `5 [4 O2 K5 z; Z* b. n   }
! i+ U: M' R8 D9 q" {$ |   return FALSE;! `5 d6 T0 Q9 t, O9 g, e+ w" G! t. K
}0 E1 Y: n' r& a) V8 b6 Q

: V- Z, H# c; [) g/ |- e3 |Although this trick calls the CreateFileA function, don't even expect to be
; C4 ]5 Y# X, f4 ]4 Uable to intercept it by installing a IFS hook: it will not work, no way!
7 g! f. w  S9 M) ~, m7 X" CIn fact, after the call to CreateFileA it will get through VWIN32 0x001F
6 I( f; L- w7 q/ V+ c9 d8 B# [- G3 wservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
$ U  b7 j3 W" s8 G7 k/ Qand then browse the DDB list until it find the VxD and its DDB_Control_Proc$ I5 R5 G, m: Z6 j1 f
field.
$ ^  W- [1 [5 r  \3 E9 x' x& L8 h* v, j; WIn fact, its purpose is not to load/unload VxDs but only to send a ( ?( J0 P4 t8 A* e' s" L: q  g7 z
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)( `3 j, q$ W* ~: R
to the VxD Control_Dispatch proc (how the hell a shareware soft could try# b: q- t4 J: E6 O
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
4 F. X* y5 D1 V  c( G% dIf the VxD is loaded, it will always clear eax and the Carry flag to allow
# B" [# Q. X+ V  f# lits handle to be opened and then, will be detected./ d, u/ G# S0 k+ g
You can check that simply by hooking Winice.exe control proc entry point4 s: [3 V  p( z' N5 J
while running MeltICE.  @( R6 {# V. @+ E  }1 H1 x

$ g& Z5 L8 w. u8 z
+ _  p9 d6 H. n! X6 I  00401067:  push      00402025    ; \\.\SICE3 A1 C/ V8 d1 M. V& R! `
  0040106C:  call      CreateFileA
& l  ?4 W8 }" Y8 K$ T  00401071:  cmp       eax,-001
6 w+ |7 f( x7 G; K. C7 A  00401074:  je        00401091
1 Q! U$ y( P+ l( r+ b
- Z# y$ j; y" K  w5 h0 A% T( x6 a+ E7 x5 B$ I5 Z
There could be hundreds of BPX you could use to detect this trick.8 |' [5 y" b8 I2 p9 ?2 Z$ _
-The most classical one is:( V; A  X3 Z( x' \0 F/ n
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
3 C9 n! z5 n- H# G4 i# R    *(esp-&gt;4+4)=='NTIC') q' r4 ?8 T7 B! u0 f) V5 b
& T* z% N+ U4 f* @' I3 D6 R
-The most exotic ones (could be very slooooow :-(# J) Y, U4 Q* h  B* x
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  % x% f, F* ]% Y8 h9 n
     ;will break 3 times :-(
9 n% M7 l: @. d' H! U1 c
4 \; S, N. G5 _( y/ X$ ?-or (a bit) faster: ; A1 B. Y  Z3 ]$ g8 J
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
7 m1 v  \3 a- F6 R$ P; f
2 ]/ D+ O2 e* T( @- T   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  $ n$ W; p4 c: N  r9 B
     ;will break 3 times :-(
! S7 K% N: u; }) z, M. `+ k/ d
0 c5 ?& M3 P" H  o! ]! _-Much faster:. l/ B8 U! g" a, \+ \
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
, @' h9 H9 }6 w+ j% c5 ]! r
# L2 \5 s' n, ^5 d9 TNote also that some programs (like AZPR3.00) use de old 16-bit _lopen6 l2 b" f4 Q) [, x- q9 F) B
function to do the same job:
- h5 l3 i: x1 N0 S7 y9 h/ S) @9 V+ O* O; a( {- [6 v$ A3 O- L
   push    00                        ; OF_READ
- R1 H; \6 e# A5 ]; H! V( J& \   mov     eax,[00656634]            ; '\\.\SICE',0
0 {4 M' [7 I/ W2 I$ w   push    eax$ u/ l0 C7 u; j+ e/ `8 D, c8 U: n
   call    KERNEL32!_lopen5 s, \: U. B% o! f' I, A. m
   inc     eax
4 W  y+ V5 m2 V   jnz     00650589                  ; detected
/ K1 j; G8 Z( g* Q, S- w   push    00                        ; OF_READ
( W; [8 L3 E  C; J3 f   mov     eax,[00656638]            ; '\\.\SICE'1 e8 I: w% G$ i
   push    eax
' b$ ~- h7 h% ^$ f' M   call    KERNEL32!_lopen
& M& M7 w9 ?& E4 Y4 c7 U* C' @! R   inc     eax
) R' W% y" J+ E: A4 {: {0 k   jz      006505ae                  ; not detected8 D' R2 ]+ b1 [0 |! P  N

- N# V' w; {+ H# Q6 \& p7 @
& g0 X) ~7 F7 s/ a% j  S6 m__________________________________________________________________________
7 Z# A7 x, }( z$ e% `7 @
7 X; a1 E* k+ {( g( D! |Method 12
" U' |$ v& g) ]=========
' f, |& u% S" k& R0 A5 T
" H  M" m% ?4 }+ w: B2 }# M3 u" H- wThis trick is similar to int41h/4fh Debugger installation check (code 05
2 B/ @' y  m  Q&amp; 06) but very limited because it's only available for Win95/98 (not NT)) Y- m2 P) Q' M9 L. Y1 l
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.! _: e" |0 |- i# l+ v

$ x( T' @% z2 A+ |* r3 L   push  0000004fh         ; function 4fh7 i! ?$ L+ F$ a& ]/ Q
   push  002a002ah         ; high word specifies which VxD (VWIN32)
5 b' v$ q2 `6 w9 S2 K9 v# D9 c2 m                           ; low word specifies which service6 i; ~/ T, t2 P: u) h
                             (VWIN32_Int41Dispatch)
) j1 I4 G9 J! P   call  Kernel32!ORD_001  ; VxdCall* o; k& ]0 ^1 q) m/ o- f& J
   cmp   ax, 0f386h        ; magic number returned by system debuggers/ X. n5 \/ M0 _/ w* Z! K) p  |
   jz    SoftICE_detected
' J6 D3 _+ d( _; \& I- ^9 N' [4 k( s0 e! p
Here again, several ways to detect it:, E1 o% I6 e: U. w; N0 L

4 h6 S3 b( c( i    BPINT 41 if ax==4f
' X2 N9 O9 @8 ]9 O2 g8 b: O9 c3 W' i0 ?: y' r+ Q2 |; ?8 k/ i
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one$ r) h$ M% H" F  J+ j6 V0 H
9 R. ^5 ~( A- U% Y; J0 N
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A0 _* C) w; a; I: M1 X! ^
" F: C. k$ R( I( O5 q5 t! I
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!, U( n: b! p- f& J3 I0 u# ~' F
/ X5 \7 p+ g3 v( R$ f' ^" f/ X1 g
__________________________________________________________________________9 c) j9 s' {( s% Y4 j

! I$ ~; {/ k6 c9 RMethod 136 }+ H( \4 x9 Q5 M
=========
+ l) p7 m6 W6 {& E9 U* H* k
6 W$ B& B+ q4 C/ CNot a real method of detection, but a good way to know if SoftICE is
' r# q2 b/ r7 r3 h4 K5 D4 p+ ~installed on a computer and to locate its installation directory.
( e+ H8 b0 L* T  U4 E& dIt is used by few softs which access the following registry keys (usually #2) :  M) v6 Q  G( E2 G
" z. Y" M7 \' n$ Z* _
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
7 b, Z, H5 J2 q5 R\Uninstall\SoftICE8 e6 ^; ]$ k( _  o  k! `8 ^
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
, X$ v- V& ?6 H; Y# t  a-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion* ?/ ], a5 R# V* {( O3 ^
\App Paths\Loader32.Exe/ _) Z0 V% G& ]: ~1 q

6 b+ g( l" k- n9 g+ A: K: ?2 B6 }0 e* J! O0 o- C
Note that some nasty apps could then erase all files from SoftICE directory+ N( D( V! ?5 `+ T0 Z
(I faced that once :-(  `5 J8 _% M5 j) b9 s4 `* [( ~0 k+ n
  m2 O% X5 w7 a8 X: y6 E3 i5 Q& {
Useful breakpoint to detect it:' S6 ]* Y8 V1 h" H

1 D1 {: t4 ~0 N( q2 }- l! G4 R     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'3 ?5 M5 N/ \6 @# g
; B3 v1 M  C! \. o/ [- }* X
__________________________________________________________________________8 o% I0 X1 T& {- H: H
4 u* U9 w! A# G! o
, ]3 Y  Q* I! U4 L) |9 N! M
Method 14   i  u% V' r( E
=========& ?1 Q4 g0 l: t: s2 I7 y
# T9 a2 F4 w% E. ]' }3 ?0 u
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose9 g) b5 G8 i0 m7 e0 w
is to determines whether a debugger is running on your system (ring0 only).
, ]6 p" z" _& {6 r6 p$ D$ N5 E* e8 u3 O6 I( \, O
   VMMCall Test_Debug_Installed8 u; A% C  m7 T& i2 v/ G( x
   je      not_installed" a8 {" j) i8 {7 {/ k
5 u" Y0 M' h6 I. O/ J
This service just checks a flag./ Z$ Q$ Z7 D5 [  L5 k
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部