这是恶意软件清理助手(tommsoft.com)的特征库吧, 里面应该是某种数据库的格式.
前面的数据什么意思不知道, 后面的数据(0x0001b4e2起)大概组织格式是这样的:
{
dword id;
byte flag;
string uri;
string action;
}
其中string是指一个四字节的长度后跟长度个字节组成的字符串. 下面以具体数据为例:
0001b4e0h: 33 30 04 00 00 00 01 12 00 00 00 7B 4D 7D 5C 53 ; 30.........{M}\S
0001b4f0h: 4F 46 54 57 41 52 45 5C 33 36 30 73 6F 06 00 00 ; OFTWARE\360so...
0001b500h: 00 65 78 69 73 74 73 05 00 00 00 01 0B 00 00 00 ; .exists.........
0001b510h: 33 36 30 4D 61 69 6E 2E 65 78 65 04 00 00 00 6B ; 360Main.exe....k
0001b520h: 69 6C 6C 06 00 00 00 01 16 00 00 00 7B 70 72 67 ; ill.........{prg
0001b530h: 7D 33 36 30 73 6F 5C 33 36 30 6D 61 69 6E 2E 64 ; }360so\360main.d
0001b540h: 6C 6C 08 00 00 00 75 6E 72 65 67 73 76 72 06 00 ; ll....unregsvr..
0001b550h: 00 00 01 16 00 00 00 7B 70 72 67 7D 33 36 30 73 ; .......{prg}360s
0001b560h: 6F 5C 61 73 70 61 74 30 31 2E 64 6C 6C 08 00 00 ; o\aspat01.dll...
0001b570h: 00 75 6E 72 65 67 73 76 72 07 00 00 00 01 0A 00 ; .unregsvr.......
0001b580h: 00 00 7B 70 72 67 7D 33 36 30 73 6F 06 00 00 00 ; ..{prg}360so....
0001b590h: 64 65 6C 65 74 65 08 00 00 00 01 12 00 00 00 7B ; delete.........{
0001b5a0h: 52 7D 5C 33 36 30 4D 61 69 6E 2E 55 70 64 61 74 ; R}\360Main.Updat
0x0001b4e2起:
04 00 00 00
01
12 00 00 00 7B 4D 7D 5C 53 4F 46 54 57 41 52 45 5C 33 36 30 73 6F "{M}\SOFTWARE\360so"
06 00 00 00 65 78 69 73 74 73 "exists"
05 00 00 00
01
0B 00 00 00 33 36 30 4D 61 69 6E 2E 65 78 65 "360Main.exe"
04 00 00 00 6B 69 6C 6C "kill"
06 00 00 00
01
16 00 00 00 7B 70 72 67 7D 33 36 30 73 6F 5C 33 36 30 6D 61 69 6E 2E 64 6C 6C "{prg}360so\360main.dll"
08 00 00 00 75 6E 72 65 67 73 76 72 "unregsvr"
后面的你自己类推吧.