翻老贴了,这个我测过
\->: Software\Microsoft\Windows\CurrentVersion\Policies\WinOldApp
::00406EDA:: B8 01000080 MOV EAX,80000001
\->: Software\Borland\Locales
>>>: ADVAPI32.DLL:RegOpenKeyExA
CallBy:0040D64B, >>>: KERNEL32.DLL:GetACP
::00405F5A:: 8BC0 MOV EAX,EAX
::00405F5C:: FF25 CC824100 JMP [4182CC] \:BYCALL CallBy:0040D699, >>>: KERNEL32.DLL:GetCPInfo
::00405F62:: 8BC0 MOV EAX,EAX
::00405F64:: FF25 C8824100 JMP [4182C8] \:BYCALL CallBy:004073A2, >>>: KERNEL32.DLL:得到现在的进程
::00405F6A:: 8BC0 MOV EAX,EAX
::00405F6C:: FF25 C4824100 JMP [4182C4] >>>: KERNEL32.DLL:GetCurrentProcessId
CallBy:0040D7EC, >>>: KERNEL32.DLL: GetStringTypeExA
::00405FDA:: 8BC0 MOV EAX,EAX
::00405FDC:: FF25 8C824100 JMP [41828C] \:BYCALL CallBy:00406A27, >>>: KERNEL32.DLL: GetSystemDirectoryA
::00405FE2:: 8BC0 MOV EAX,EAX
::00405FE4:: FF25 88824100 JMP [418288] \:BYCALL CallBy:00406A3A, >>>: KERNEL32.DLL: GetTempPathA
::00405FEA:: 8BC0 MOV EAX,EAX