Jeg analyserer en PE-fil ved hjælp af IDA Pro
, der bruger int 2Dh
-teknik som anti-debugging:
CODE: 00455050 push ebpCODE: 00455051 mov ebp, espCODE: 00455053 push ecxCODE: 00455054 push ebxCODE: 00455055 push esiCODE: 00455056 push ediCODE: 00455057 xor eax, eaxCODE: 00455059 push ebpCODE: 004550: push45 : 00455062 mov fs: [eax], espCODE: 00455065 int 2Dh; Windows NT - debugging services: eax = typeCODE: 00455067 inc eaxCODE: 00455068 mov [ebp + var_1], 1CODE: 0045506C xor eax, eaxCODE: 0045506E pop edxCODE: 0045506F pop ecxCODE: 00455070 pop ecxCODE: 00 edxCODE: 00455074 jmp short loc_455084
Hvordan skal jeg konfigurere IDA Pro til at håndtere denne afbrydelse / undtagelse i dynamisk analyse?
Jeg bruger den lokale win32 debugger