库 ntoskrnl.exe:
• 0x140027060 - KeAcquireGuardedMutex
• 0x140027068 - KeReleaseGuardedMutex
• 0x140027070 - ObfDereferenceObject
• 0x140027078 - KeStackAttachProcess
• 0x140027080 - KeUnstackDetachProcess
• 0x140027088 - PsLookupProcessByProcessId
• 0x140027090 - PsSetLoadImageNotifyRoutine
• 0x140027098 - PsRemoveLoadImageNotifyRoutine
• 0x1400270a0 - KeSetEvent
• 0x1400270a8 - KeWaitForSingleObject
• 0x1400270b0 - strncpy
• 0x1400270b8 - PsGetCurrentProcessId
• 0x1400270c0 - PsGetCurrentThreadId
• 0x1400270c8 - PsSetCreateProcessNotifyRoutineEx
• 0x1400270d0 - RtlInitUnicodeString
• 0x1400270d8 - KeInitializeEvent
• 0x1400270e0 - KeClearEvent
• 0x1400270e8 - IofCompleteRequest
• 0x1400270f0 - IoCreateDevice
• 0x1400270f8 - IoCreateNotificationEvent
• 0x140027100 - IoCreateSymbolicLink
• 0x140027108 - IoDeleteDevice
• 0x140027110 - IoDeleteSymbolicLink
• 0x140027118 - ZwClose
• 0x140027120 - MmGetSystemRoutineAddress
• 0x140027128 - MmIsAddressValid
• 0x140027130 - wcsncmp
• 0x140027138 - wcsncpy
• 0x140027140 - ExAllocatePool
• 0x140027148 - RtlIntegerToUnicodeString
• 0x140027150 - RtlCompareUnicodeString
• 0x140027158 - RtlAppendUnicodeToString
• 0x140027160 - PsCreateSystemThread
• 0x140027168 - PsTerminateSystemThread
• 0x140027170 - ObReferenceObjectByHandle
• 0x140027178 - SeQuerySessionIdToken
• 0x140027180 - PsReferencePrimaryToken
• 0x140027188 - PsDereferencePrimaryToken
• 0x140027190 - ObQueryNameString
• 0x140027198 - PsGetProcessPeb
• 0x1400271a0 - __C_specific_handler
• 0x1400271a8 - DbgPrint
• 0x1400271b0 - ZwWaitForSingleObject
• 0x1400271b8 - RtlGetVersion
• 0x1400271c0 - KeAcquireSpinLockRaiseToDpc
• 0x1400271c8 - KeReleaseSpinLock
• 0x1400271d0 - KeIpiGenericCall
• 0x1400271d8 - MmGetPhysicalAddress
• 0x1400271e0 - MmGetVirtualForPhysical
• 0x1400271e8 - KeNumberProcessors
• 0x1400271f0 - KeDelayExecutionThread
• 0x1400271f8 - KeQueryTimeIncrement
• 0x140027200 - wcsrchr
• 0x140027208 - RtlCopyUnicodeString
• 0x140027210 - RtlAppendUnicodeStringToString
• 0x140027218 - ZwUnloadDriver
• 0x140027220 - MmBuildMdlForNonPagedPool
• 0x140027228 - MmMapLockedPagesSpecifyCache
• 0x140027230 - MmUnmapLockedPages
• 0x140027238 - IoAllocateMdl
• 0x140027240 - IoFreeMdl
• 0x140027248 - ZwCreateFile
• 0x140027250 - ZwQueryInformationFile
• 0x140027258 - ZwReadFile
• 0x140027260 - ZwWriteFile
• 0x140027268 - ZwCreateSection
• 0x140027270 - ZwMapViewOfSection
• 0x140027278 - ZwUnmapViewOfSection
• 0x140027280 - KeRegisterBugCheckReasonCallback
• 0x140027288 - ProbeForWrite
• 0x140027290 - KeInitializeGuardedMutex
• 0x140027298 - MmProbeAndLockPages
• 0x1400272a0 - MmUnlockPages
• 0x1400272a8 - MmProtectMdlSystemAddress
• 0x1400272b0 - RtlAnsiStringToUnicodeString
• 0x1400272b8 - RtlUnicodeStringToAnsiString
• 0x1400272c0 - PsGetVersion
• 0x1400272c8 - IoGetLowerDeviceObject
• 0x1400272d0 - IoDriverObjectType
• 0x1400272d8 - _wcsnicmp
• 0x1400272e0 - ZwOpenKey
• 0x1400272e8 - ZwQueryValueKey
• 0x1400272f0 - ZwOpenSymbolicLinkObject
• 0x1400272f8 - ZwQuerySymbolicLinkObject
• 0x140027300 - RtlUpcaseUnicodeString
• 0x140027308 - wcsstr
• 0x140027310 - _wcsupr
• 0x140027318 - ExAcquireRundownProtection
• 0x140027320 - ExReleaseRundownProtection
• 0x140027328 - PsInitialSystemProcess
• 0x140027330 - _strnicmp
• 0x140027338 - strncmp
• 0x140027340 - RtlInitAnsiString
• 0x140027348 - ExAcquireFastMutex
• 0x140027350 - ExReleaseFastMutex
• 0x140027358 - RtlInt64ToUnicodeString
• 0x140027360 - RtlFreeUnicodeString
• 0x140027368 - RtlFreeAnsiString
• 0x140027370 - wcsncpy_s
• 0x140027378 - ZwSetInformationFile
• 0x140027380 - CcCoherencyFlushAndPurgeCache
• 0x140027388 - RtlWalkFrameChain
• 0x140027390 - KeEnterCriticalRegion
• 0x140027398 - KeLeaveCriticalRegion
• 0x1400273a0 - ExInitializeResourceLite
• 0x1400273a8 - ExAcquireResourceSharedLite
• 0x1400273b0 - ExAcquireResourceExclusiveLite
• 0x1400273b8 - ExReleaseResourceLite
• 0x1400273c0 - ExDeleteResourceLite
• 0x1400273c8 - RtlInitializeGenericTableAvl
• 0x1400273d0 - RtlInsertElementGenericTableAvl
• 0x1400273d8 - RtlDeleteElementGenericTableAvl
• 0x1400273e0 - RtlLookupElementGenericTableAvl
• 0x1400273e8 - RtlIsGenericTableEmptyAvl
• 0x1400273f0 - IoGetCurrentProcess
• 0x1400273f8 - KeBugCheckEx
• 0x140027400 - ExFreePoolWithTag
• 0x140027408 - KeDeregisterBugCheckReasonCallback
• 0x140027410 - ExAllocatePoolWithTag
• 0x140027418 - ProbeForRead
• 0x140027420 - ZwCreateKey
• 0x140027428 - ZwDeleteKey
• 0x140027430 - ZwEnumerateKey
• 0x140027438 - ZwSetValueKey