| Код | .386 .model flat, stdcall option casemap :none ; case sensitive
include \masm32\include\windows.inc include \masm32\include\user32.inc include \masm32\include\kernel32.inc include \masm32\include\advapi32.inc includelib \masm32\lib\user32.lib includelib \masm32\lib\kernel32.lib includelib \masm32\lib\advapi32.lib
.data SubKey db "Software\Betrayed programming\Registry\",0 szBetrayed db "Betrayed",0 szCaption db "Reg Adder",0 szNoRun db "It seems you have never run this program before!",13,10 db "I will now add a item to the registry since you have ran this program",0 szHasRun db "Thank you for running this program more then once.",0 szRan db "Ran",0
.data? hKey dd ? hValue dd ? szBuffer db 4 dup (?)
.code
start: invoke RegOpenKeyEx,HKEY_LOCAL_MACHINE,ADDR SubKey,NULL,KEY_QUERY_VALUE,ADDR hKey ;open our key .if !eax ;if it is there we more then likley wrote it invoke RegQueryInfoKey, hKey,0,0,0,0,0,0,0,0,ADDR hValue,0,0 ;get the size of the entry invoke RegQueryValueEx, hKey, ADDR szBetrayed,0,0,ADDR szBuffer,ADDR hValue ;get the value and keep it in the buffer invoke lstrcmp,ADDR szBuffer,ADDR szRan ;compare it our ran string .if !eax ;if they are the same it means the user has not modified it invoke MessageBox,NULL,ADDR szHasRun,ADDR szCaption,MB_OK+MB_ICONINFORMATION ;alert them .endif .else invoke MessageBox,NULL,ADDR szNoRun,ADDR szCaption,MB_OK+MB_ICONINFORMATION ;Alert the fact we have never been ran on this machine invoke RegCreateKey,HKEY_LOCAL_MACHINE, ADDR SubKey,ADDR hKey ;create the key .if !eax ;make sure it does not fail invoke RegSetValueEx,hKey,ADDR szBetrayed,0,REG_SZ,ADDR szRan,4 ;set the szRan string in the registry .endif .endif invoke RegCloseKey , hKey ;close the registry key invoke ExitProcess,NULL ret end start
|
|