MCPcopy Create free account
hub / github.com/BaumFX/cpp-anti-debug / int_2d

Method int_2d

anti_debug.cpp:408–435  ·  view source on GitHub ↗

2d is a kernel interrupt (opcode 0x2D), when it gets executed, windows will use the extended instruction pointer register value as the exception address, after then it increments the extended instruction pointer register value by 1. windows also checks the eax register value to determine how to adjust the exception address if the eax register is 1, 3, or 4 (on all windows version) or 5 on vista an

Source from the content-addressed store, hash-verified

source not stored for this graph (policy: none)

Callers

nothing calls this directly

Calls

no outgoing calls

Tested by

no test coverage detected