IsDebuggerPresent
关于IsDebuggerPresent
BOOL WINAPI IsDebuggerPresent(void);检测代码
call IsDebuggerPresent
test al, al
jne being_debuggedmov eax, fs:[30h] ;Process Environment Block
cmp b [eax+2], 0 ;check BeingDebugged
jne being_debuggedpush 60h
pop rsi
gs:lodsq ;Process Environment Block
cmp b [rax+2], 0 ;check BeingDebugged
jne being_debugged如何绕过
Last updated