Skip to content

Instantly share code, notes, and snippets.

@spnow
spnow / RDTSC.cpp
Created August 1, 2017 23:10 — forked from evernick/RDTSC.cpp
#include <windows.h>
#include <stdio.h>
#include <intrin.h>
BOOL anti_debug(unsigned __int64 cnt1)
{
unsigned __int64 cnt2;
cnt2 = __rdtsc();
if ((cnt2-cnt1) > 0xFF) {
return 1;
}
#include <windows.h>
#include <stdio.h>
BOOL anti_debug(LARGE_INTEGER cnt1)
{
LARGE_INTEGER cnt2;
QueryPerformanceCounter (&cnt2);
if ((cnt2.QuadPart-cnt1.QuadPart) > 0xFF) {
return 1;
}
#include <windows.h>
#include <stdio.h>
#pragma comment(lib, "winmm.lib")
BOOL anti_debug(DWORD count1)
{
DWORD count2;
count2 = GetTickCount();
if ((count2-count1) > 0x10) {
return 1;
}
#include <windows.h>
#include <stdio.h>
#pragma comment(lib, "winmm.lib")
BOOL anti_debug(DWORD time1)
{
DWORD time2;
time2 = timeGetTime();
if ((time2-time1) > 0x10) {
return 1;
#include <windows.h>
#include <stdio.h>
BOOL anti_debug(SYSTEMTIME s_time1, FILETIME f_time1)
{
SYSTEMTIME s_time2;
FILETIME f_time2;
GetSystemTime(&s_time2);
SystemTimeToFileTime(&s_time2, &f_time2);
if ((f_time2.dwLowDateTime - f_time1.dwLowDateTime)/10000 > 1000) {
#define _WIN32_WINNT 0x0501
#include <windows.h>
#include <stdio.h>
#include <Winternl.h>
typedef DWORD (WINAPI *PFZWQUERYINFORMATIONPROCESS) (
HANDLE ProcessHandle,
DWORD ProcessInformationClass, // Origianl : _PROCESS_INFORMATION_CLASS
PVOID ProcessInformation,
ULONG ProcessInformationLength,
#include <windows.h>
#include <stdio.h>
int main(int argc, char **argv)
{
unsigned long *p;
__asm
{
mov eax, fs:[0x30]
#include <windows.h>
#include <stdio.h>
DWORD anti_debug()
{
__asm
{
mov eax, fs:[0x30] // PEB 접근
movzx eax, byte ptr [eax+2] // PEB.BeingDebugged 멤버 접근
}
#include <windows.h>
#include <stdio.h>
DWORD anti_debug()
{
__asm
{
mov eax, fs:[0x30]
movzx eax, dword ptr [eax+0x68]
}
#include <windows.h>
#include <stdio.h>
BOOL anti_debug()
{
BOOL result = FALSE;
void *pHeap;
DWORD Flags, ForceFlags;
__asm