为方便大家研究,直接把源码贴上来。写的比较乱,大家别笑话我。
.386
.model flat,stdcall
option casemap:none
include \masm32\include\windows.inc
include \masm32\include\user32.inc
include \masm32\include\kernel32.inc
include \masm32\include\advapi32.inc
includelib \masm32\lib\advapi32.lib
includelib \masm32\lib\user32.lib
includelib \masm32\lib\kernel32.lib
includelib \MASM32\LIB\oleaut32.lib
include \MASM32\include\oleaut32.inc
.data
var14 dd 0
var10 dd 0
var0c dd 4
var18 dd 0
AppName db "注册程序,(C)电子管 2012.08.05",0
nof_1 db "发现sod!",0
find_1 db "未发现sod!",0
fntdll db "ntdll.dll",0
zwset1 db "ZwSetInformationProcess",0
zwq1 db "ZwQueryInformationProcess",0,0