库 ntoskrnl.exe:
• 0x1402e5000 - RtlInitUnicodeString
• 0x1402e5008 - RtlUnicodeStringToAnsiString
• 0x1402e5010 - RtlCopyUnicodeString
• 0x1402e5018 - KeQueryTimeIncrement
• 0x1402e5020 - KeInitializeGuardedMutex
• 0x1402e5028 - KeAcquireGuardedMutex
• 0x1402e5030 - KeReleaseGuardedMutex
• 0x1402e5038 - ExAllocatePoolWithTag
• 0x1402e5040 - ExFreePoolWithTag
• 0x1402e5048 - IoGetCurrentProcess
• 0x1402e5050 - ObRegisterCallbacks
• 0x1402e5058 - ObUnRegisterCallbacks
• 0x1402e5060 - PsGetCurrentProcessId
• 0x1402e5068 - PsGetThreadProcessId
• 0x1402e5070 - RtlDowncaseUnicodeString
• 0x1402e5078 - __C_specific_handler
• 0x1402e5080 - PsProcessType
• 0x1402e5088 - PsThreadType
• 0x1402e5090 - ZwCreateFile
• 0x1402e5098 - ZwReadFile
• 0x1402e50a0 - ZwClose
• 0x1402e50a8 - RtlGetVersion
• 0x1402e50b0 - IofCompleteRequest
• 0x1402e50b8 - IoCreateSymbolicLink
• 0x1402e50c0 - IoDeleteDevice
• 0x1402e50c8 - IoDeleteSymbolicLink
• 0x1402e50d0 - KeBugCheck
• 0x1402e50d8 - IoGetRequestorProcessId
• 0x1402e50e0 - IoGetRequestorProcess
• 0x1402e50e8 - SeLocateProcessImageName
• 0x1402e50f0 - MmGetSystemRoutineAddress
• 0x1402e50f8 - IoCreateDevice
• 0x1402e5100 - ObOpenObjectByPointer
• 0x1402e5108 - ZwSetSecurityObject
• 0x1402e5110 - IoDeviceObjectType
• 0x1402e5118 - _snwprintf
• 0x1402e5120 - RtlLengthSecurityDescriptor
• 0x1402e5128 - SeCaptureSecurityDescriptor
• 0x1402e5130 - RtlCreateSecurityDescriptor
• 0x1402e5138 - RtlSetDaclSecurityDescriptor
• 0x1402e5140 - RtlAbsoluteToSelfRelativeSD
• 0x1402e5148 - IoIsWdmVersionAvailable
• 0x1402e5150 - SeExports
• 0x1402e5158 - wcschr
• 0x1402e5160 - _wcsnicmp
• 0x1402e5168 - RtlLengthSid
• 0x1402e5170 - RtlAddAccessAllowedAce
• 0x1402e5178 - RtlGetSaclSecurityDescriptor
• 0x1402e5180 - RtlGetDaclSecurityDescriptor
• 0x1402e5188 - RtlGetGroupSecurityDescriptor
• 0x1402e5190 - RtlGetOwnerSecurityDescriptor
• 0x1402e5198 - ZwOpenKey
• 0x1402e51a0 - ZwCreateKey
• 0x1402e51a8 - ZwQueryValueKey
• 0x1402e51b0 - ZwSetValueKey
• 0x1402e51b8 - RtlFreeUnicodeString
• 0x1402e51c0 - KeBugCheckEx
库 ntoskrnl.exe:
• 0x1402e51d0 - ExAllocatePool
• 0x1402e51d8 - NtQuerySystemInformation
• 0x1402e51e0 - ExFreePoolWithTag
• 0x1402e51e8 - IoAllocateMdl
• 0x1402e51f0 - MmProbeAndLockPages
• 0x1402e51f8 - MmMapLockedPagesSpecifyCache
• 0x1402e5200 - MmUnlockPages
• 0x1402e5208 - IoFreeMdl
• 0x1402e5210 - KeQueryActiveProcessors
• 0x1402e5218 - KeSetSystemAffinityThread
• 0x1402e5220 - KeRevertToUserAffinityThread
• 0x1402e5228 - DbgPrint