注册表and 服务改动
004070D4 mov eax, 004072A4 schedule
004070DE mov eax, 004072B8 sharedaccess
004070E8 mov eax, 004072D0 rsccenter
004070F2 mov eax, 004072E4 rsravmon
004070FC mov eax, 004072F0 rsccenter
00407106 mov eax, 004072FC rsravmon
00407110 mov edx, 00407310 software\microsoft\windows\currentversion\run\ravtask
0040711F mov eax, 00407350 kvwsc
00407129 mov eax, 00407360 kvsrvxp
00407133 mov eax, 00407368 kvwsc
0040713D mov eax, 00407370 kvsrvxp
00407147 mov edx, 00407380 software\microsoft\windows\currentversion\run\kvmonxp
00407156 mov eax, 004073C0 kavsvc
00407160 mov eax, 004073D0 avp
0040716A mov eax, 004073D4 avp
00407174 mov eax, 004073D8 kavsvc
0040717E mov edx, 004073E8 software\microsoft\windows\currentversion\run\kav0040718D mov edx, 00407424 software\microsoft\windows\currentversion\run\kavpersonal500040719C mov eax, 00407468 mcafeeframework
004071A6 mov eax, 00407480 mcshield
004071B0 mov eax, 00407494 mctaskmanager
004071BA mov eax, 004074A4 mcafeeframework
004071C4 mov eax, 004074B4 mcshield
004071CE mov eax, 004074C0 mctaskmanager
004071D8 mov edx, 004074D8 software\microsoft\windows\currentversion\run\mcafeeupdaterui
004071E7 mov edx, 00407520 software\microsoft\windows\currentversion\run\network associates error reporting service
004071F6 mov edx, 00407584 software\microsoft\windows\currentversion\run\shstatexe
00407205 mov eax, 004075BC navapsvc
0040720F mov eax, 004075C8 wscsvc
00407219 mov eax, 004075D0 kpfwsvc
00407223 mov eax, 004075D8 sndsrvc
0040722D mov eax, 004075E0 ccproxy
00407237 mov eax, 004075E8 ccevtmgr
00407241 mov eax, 004075F4 ccsetmgr
0040724B mov eax, 00407600 spbbcsvc
00407255 mov eax, 0040760C symantec core lc
0040725F mov eax, 00407620 npfmntor
00407269 mov eax, 0040762C mskservice
00407273 mov eax, 00407638 firesvc
0040727D mov edx, 00407648 software\microsoft\windows\currentversion\run\ylive.exe
0040728C mov edx, 00407688 software\microsoft\windows\currentversion\run\yassistse