• Anti Sandboxie[MASM]

 #481629  por top10
 10 Dic 2015, 05:12
.386
.model flat,stdcall
option casemap:none

include \masm32\include\windows.inc
include \masm32\include\kernel32.inc
include \masm32\include\user32.inc
includelib \masm32\lib\user32.lib
includelib \masm32\lib\kernel32.lib

.data
SbieDll         db "SbieDll.dll",0
MsgDetected       db "Detected",0
MsgNotDetected    db "Not Detected",0

    .code

start:
   

invoke GetModuleHandle, addr SbieDll
jz NotDetected ; if is 0 jump to NotDetected
jnz Detected ; if is not 0 jump to Detected

NotDetected:
invoke MessageBox,NULL,addr MsgNotDetected,addr MsgNotDetected,MB_OK
jmp Exit


Detected:
invoke MessageBox,NULL,addr MsgDetected,addr MsgDetected,MB_OK
jmp Exit

Exit:
invoke ExitProcess,0

    ret


end start