文件名称:Anti-Loader
介绍说明--下载内容均来自于网络,请自行研究使用
Anti-Loader... ...Anti-Loader示例
├──PEB................利用TEB检测
├──FindWindow.........查找句柄检测
├──IsDebuggerPresent..利用IsDebuggerPresent检测
├──Parent.............检查父进程
└──STARTUPINFO........检查STARTUPINFO结构-Anti-Loader ... ... Anti-Loader example ├ ─ ─ PEB ................ use TEB detection ├ ─ ─ FindWindow ......... Find Detection handle ├ ─ ─ IsDebuggerPresent .. use IsDebuggerPresent detection ├ ─ ─ Parent ............. parent process checks └ ─ ─ STARTUPINFO ........ check STARTUPINFO structure
├──PEB................利用TEB检测
├──FindWindow.........查找句柄检测
├──IsDebuggerPresent..利用IsDebuggerPresent检测
├──Parent.............检查父进程
└──STARTUPINFO........检查STARTUPINFO结构-Anti-Loader ... ... Anti-Loader example ├ ─ ─ PEB ................ use TEB detection ├ ─ ─ FindWindow ......... Find Detection handle ├ ─ ─ IsDebuggerPresent .. use IsDebuggerPresent detection ├ ─ ─ Parent ............. parent process checks └ ─ ─ STARTUPINFO ........ check STARTUPINFO structure
(系统自动生成,下载前可以参看下载内容)
下载文件列表
Anti-Loader
...........\FindWindow
...........\..........\FindWindowMain.dcu
...........\..........\FindWindowMain.ddp
...........\..........\FindWindowMain.dfm
...........\..........\FindWindowMain.pas
...........\..........\FindWindowMain.~ddp
...........\..........\FindWindowMain.~dfm
...........\..........\FindWindowMain.~pas
...........\..........\FindWindowProject.cfg
...........\..........\FindWindowProject.dof
...........\..........\FindWindowProject.dpr
...........\..........\FindWindowProject.exe
...........\..........\FindWindowProject.res
...........\IsDebuggerPresent
...........\.................\IsDebuggerMain.dcu
...........\.................\IsDebuggerMain.ddp
...........\.................\IsDebuggerMain.dfm
...........\.................\IsDebuggerMain.pas
...........\.................\IsDebuggerMain.~ddp
...........\.................\IsDebuggerMain.~dfm
...........\.................\IsDebuggerMain.~pas
...........\.................\IsDebuggerPro.cfg
...........\.................\IsDebuggerPro.dof
...........\.................\IsDebuggerPro.dpr
...........\.................\IsDebuggerPro.exe
...........\.................\IsDebuggerPro.res
...........\Parent
...........\......\ParentMain.dcu
...........\......\ParentMain.ddp
...........\......\ParentMain.dfm
...........\......\ParentMain.pas
...........\......\ParentMain.~ddp
...........\......\ParentMain.~dfm
...........\......\ParentMain.~pas
...........\......\ParentPro.cfg
...........\......\ParentPro.dof
...........\......\ParentPro.dpr
...........\......\ParentPro.exe
...........\......\ParentPro.res
...........\PEB
...........\...\PEBMain.dcu
...........\...\PEBMain.ddp
...........\...\PEBMain.dfm
...........\...\PEBMain.pas
...........\...\PEBMain.~ddp
...........\...\PEBMain.~dfm
...........\...\PEBMain.~pas
...........\...\PEBProject.cfg
...........\...\PEBProject.dof
...........\...\PEBProject.dpr
...........\...\PEBProject.exe
...........\...\PEBProject.res
...........\STARTUPINFO
...........\...........\STARTUPINFOMain.dcu
...........\...........\STARTUPINFOMain.ddp
...........\...........\STARTUPINFOMain.dfm
...........\...........\STARTUPINFOMain.pas
...........\...........\STARTUPINFOMain.~ddp
...........\...........\STARTUPINFOMain.~dfm
...........\...........\STARTUPINFOMain.~pas
...........\...........\STARTUPINFOPro.cfg
...........\...........\STARTUPINFOPro.dof
...........\...........\STARTUPINFOPro.dpr
...........\...........\STARTUPINFOPro.exe
...........\...........\STARTUPINFOPro.res
...........\...........\STARTUPINFOPro.~dpr
...........\FindWindow
...........\..........\FindWindowMain.dcu
...........\..........\FindWindowMain.ddp
...........\..........\FindWindowMain.dfm
...........\..........\FindWindowMain.pas
...........\..........\FindWindowMain.~ddp
...........\..........\FindWindowMain.~dfm
...........\..........\FindWindowMain.~pas
...........\..........\FindWindowProject.cfg
...........\..........\FindWindowProject.dof
...........\..........\FindWindowProject.dpr
...........\..........\FindWindowProject.exe
...........\..........\FindWindowProject.res
...........\IsDebuggerPresent
...........\.................\IsDebuggerMain.dcu
...........\.................\IsDebuggerMain.ddp
...........\.................\IsDebuggerMain.dfm
...........\.................\IsDebuggerMain.pas
...........\.................\IsDebuggerMain.~ddp
...........\.................\IsDebuggerMain.~dfm
...........\.................\IsDebuggerMain.~pas
...........\.................\IsDebuggerPro.cfg
...........\.................\IsDebuggerPro.dof
...........\.................\IsDebuggerPro.dpr
...........\.................\IsDebuggerPro.exe
...........\.................\IsDebuggerPro.res
...........\Parent
...........\......\ParentMain.dcu
...........\......\ParentMain.ddp
...........\......\ParentMain.dfm
...........\......\ParentMain.pas
...........\......\ParentMain.~ddp
...........\......\ParentMain.~dfm
...........\......\ParentMain.~pas
...........\......\ParentPro.cfg
...........\......\ParentPro.dof
...........\......\ParentPro.dpr
...........\......\ParentPro.exe
...........\......\ParentPro.res
...........\PEB
...........\...\PEBMain.dcu
...........\...\PEBMain.ddp
...........\...\PEBMain.dfm
...........\...\PEBMain.pas
...........\...\PEBMain.~ddp
...........\...\PEBMain.~dfm
...........\...\PEBMain.~pas
...........\...\PEBProject.cfg
...........\...\PEBProject.dof
...........\...\PEBProject.dpr
...........\...\PEBProject.exe
...........\...\PEBProject.res
...........\STARTUPINFO
...........\...........\STARTUPINFOMain.dcu
...........\...........\STARTUPINFOMain.ddp
...........\...........\STARTUPINFOMain.dfm
...........\...........\STARTUPINFOMain.pas
...........\...........\STARTUPINFOMain.~ddp
...........\...........\STARTUPINFOMain.~dfm
...........\...........\STARTUPINFOMain.~pas
...........\...........\STARTUPINFOPro.cfg
...........\...........\STARTUPINFOPro.dof
...........\...........\STARTUPINFOPro.dpr
...........\...........\STARTUPINFOPro.exe
...........\...........\STARTUPINFOPro.res
...........\...........\STARTUPINFOPro.~dpr