我正在分析一个IDA Pro
使用int 2Dh
作为反调试技术的 PE 文件:
CODE:00455050 push ebp
CODE:00455051 mov ebp, esp
CODE:00455053 push ecx
CODE:00455054 push ebx
CODE:00455055 push esi
CODE:00455056 push edi
CODE:00455057 xor eax, eax
CODE:00455059 push ebp
CODE:0045505A push offset loc_455076
CODE:0045505F push dword ptr fs:[eax]
CODE:00455062 mov fs:[eax], esp
CODE:00455065 int 2Dh ; Windows NT - debugging services: eax = type
CODE:00455067 inc eax
CODE:00455068 mov [ebp+var_1], 1
CODE:0045506C xor eax, eax
CODE:0045506E pop edx
CODE:0045506F pop ecx
CODE:00455070 pop ecx
CODE:00455071 mov fs:[eax], edx
CODE:00455074 jmp short loc_455084
我应该如何配置 IDA Pro 来处理动态分析中的这个中断/异常?
我正在使用本地 win32 调试器