Question: This following code has a malware has anti - debugging technique. After adding a break point at test eax, eax, what should you do to
This following code has a malware has antidebugging technique.
After adding a break point at "test eax, eax",what should you do to overcome the debugger anti debugging technique?
main
push ebp
mov ebp, esp
call DWORD PTR IsDebuggerPresent@
test eax, eax
je SHORT $LN@main
call DWORD PTR GetForegroundWindow@
mov DWORD PTR last$ebp eax
mov ecx, DWORD PTR last$ebp
push ecx
call DWORD PTR DestroyWindow@
test eax, eax
push
call exit
jmp $LN@main
$LN@main:
push swelldone
call printf
$LN@main:
mov esp, ebp
pop ebp
ret
Group of answer choices
change exa value to
change exa value to
change exa value to
change exa value to
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
