http://msdn.microsoft.com/msdnmag/issues/01/12/XPKernel/default.aspx
---------------------------------------------------
2K 서비스 번호별 API
SDT viewer by DeokYoung ,based SDT recover
KeServiceDescriptorTable 8047F7E0
KeServiceDecriptorTable.ServiceTable 80471128
KeServiceDescriptorTable.ServiceLimit 248
000, ZwAcceptConnectPort
001, ZwAccessCheck
002, ZwAccessCheckAndAuditAlarm
003, ZwAccessCheckByType
004, ZwAccessCheckByTypeAndAuditAlarm
005, ZwAccessCheckByTypeResultList
006, ZwAccessCheckByTypeResultListAndAuditAlarm
007, ZwAccessCheckByTypeResultListAndAuditAlarmByHandle
008, ZwAddAtom
009, ZwAdjustGroupsToken
00A, ZwAdjustPrivilegesToken
00B, ZwAlertResumeThread
00C, ZwAlertThread
00D, ZwAllocateLocallyUniqueId
00E, ZwAllocateUserPhysicalPages
00F, ZwAllocateUuids
010, ZwAllocateVirtualMemory
011, ZwAreMappedFilesTheSame
012, ZwAssignProcessToJobObject
013, ZwCallbackReturn
014, ZwCancelIoFile
015, ZwCancelTimer
016, ZwCancelDeviceWakeupRequest
017, ZwClearEvent
018, ZwClose
019, ZwCloseObjectAuditAlarm
01A, ZwCompleteConnectPort
01B, ZwConnectPort
01C, ZwContinue
01D, ZwCreateDirectoryObject
01E, ZwCreateEvent
01F, ZwCreateEventPair
020, ZwCreateFile
021, ZwCreateIoCompletion
022, ZwCreateJobObject
023, ZwCreateKey
024, ZwCreateMailslotFile
025, ZwCreateMutant
026, ZwCreateNamedPipeFile
027, ZwCreatePagingFile
028, ZwCreatePort
029, ZwCreateProcess
02A, ZwCreateProfile
02B, ZwCreateSection
02C, ZwCreateSemaphore
02D, ZwCreateSymbolicLinkObject
02E, ZwCreateThread
02F, ZwCreateTimer
030, ZwCreateToken
031, ZwCreateWaitablePort
032, ZwDelayExecution
033, ZwDeleteAtom
034, ZwDeleteFile
035, ZwDeleteKey
036, ZwDeleteObjectAuditAlarm
037, ZwDeleteValueKey
038, ZwDeviceIoControlFile
039, ZwDisplayString
03A, ZwDuplicateObject
03B, ZwDuplicateToken
03C, ZwEnumerateKey
03D, ZwEnumerateValueKey
03E, ZwExtendSection
03F, ZwFilterToken
040, ZwFindAtom
041, ZwFlushBuffersFile
042, ZwFlushInstructionCache
043, ZwFlushKey
044, ZwFlushVirtualMemory
045, ZwFlushWriteBuffer
046, ZwFreeUserPhysicalPages
047, ZwFreeVirtualMemory
048, ZwFsControlFile
049, ZwGetContextThread
04A, ZwGetDevicePowerState
04B, ZwGetPlugPlayEvent
04C, ZwGetTickCount
04D, ZwGetWriteWatch
04E, ZwImpersonateAnonymousToken
04F, ZwImpersonateClientOfPort
050, ZwImpersonateThread
051, ZwInitializeRegistry
052, ZwInitiatePowerAction
053, ZwIsSystemResumeAutomatic
054, ZwListenPort
055, ZwLoadDriver
056, ZwLoadKey
057, ZwLoadKey2
058, ZwLockFile
059, ZwLockVirtualMemory
05A, ZwMakeTemporaryObject
05B, ZwMapUserPhysicalPages
05C, ZwMapUserPhysicalPagesScatter
05D, ZwMapViewOfSection
05E, ZwNotifyChangeDirectoryFile
05F, ZwNotifyChangeKey
060, ZwNotifyChangeMultipleKeys
061, ZwOpenDirectoryObject
062, ZwOpenEvent
063, ZwOpenEventPair
064, ZwOpenFile
065, ZwOpenIoCompletion
066, ZwOpenJobObject
067, ZwOpenKey
068, ZwOpenMutant
069, ZwOpenObjectAuditAlarm
06A, ZwOpenProcess
06B, ZwOpenProcessToken
06C, ZwOpenSection
06D, ZwOpenSemaphore
06E, ZwOpenSymbolicLinkObject
06F, ZwOpenThread
070, ZwOpenThreadToken
071, ZwOpenTimer
072, ZwPlugPlayControl
073, ZwPowerInformation
074, ZwPrivilegeCheck
075, ZwPrivilegedServiceAuditAlarm
076, ZwPrivilegeObjectAuditAlarm
077, ZwProtectVirtualMemory
078, ZwPulseEvent
079, ZwQueryInformationAtom
07A, ZwQueryAttributesFile
07B, ZwQueryDefaultLocale
07C, ZwQueryDefaultUILanguage
07D, ZwQueryDirectoryFile
07E, ZwQueryDirectoryObject
07F, ZwQueryEaFile
080, ZwQueryEvent
081, ZwQueryFullAttributesFile
082, ZwQueryInformationFile
083, ZwQueryInformationJobObject
084, ZwQueryIoCompletion
085, ZwQueryInformationPort
086, ZwQueryInformationProcess
087, ZwQueryInformationThread
088, ZwQueryInformationToken
089, ZwQueryInstallUILanguage
08A, ZwQueryIntervalProfile
08B, ZwQueryKey
08C, ZwQueryMultipleValueKey
08D, ZwQueryMutant
08E, ZwQueryObject
08F, ZwQueryOpenSubKeys
090, ZwQueryPerformanceCounter
091, ZwQueryQuotaInformationFile
092, ZwQuerySection
093, ZwQuerySecurityObject
094, ZwQuerySemaphore
095, ZwQuerySymbolicLinkObject
096, ZwQuerySystemEnvironmentValue
097, ZwQuerySystemInformation
098, ZwQuerySystemTime
099, ZwQueryTimer
09A, ZwQueryTimerResolution
09B, ZwQueryValueKey
09C, ZwQueryVirtualMemory
09D, ZwQueryVolumeInformationFile
09E, ZwQueueApcThread
09F, ZwRaiseException
0A0, ZwRaiseHardError
0A1, ZwReadFile
0A2, ZwReadFileScatter
0A3, ZwReadRequestData
0A4, ZwReadVirtualMemory
0A5, ZwRegisterThreadTerminatePort
0A6, ZwReleaseMutant
0A7, ZwReleaseSemaphore
0A8, ZwRemoveIoCompletion
0A9, ZwReplaceKey
0AA, ZwReplyPort
0AB, ZwReplyWaitReceivePort
0AC, ZwReplyWaitReceivePortEx
0AD, ZwReplyWaitReplyPort
0AE, ZwRequestDeviceWakeup
0AF, ZwRequestPort
0B0, ZwRequestWaitReplyPort
0B1, ZwRequestWakeupLatency
0B2, ZwResetEvent
0B3, ZwResetWriteWatch
0B4, ZwRestoreKey
0B5, ZwResumeThread
0B6, ZwSaveKey
0B7, ZwSaveMergedKeys
0B8, ZwSecureConnectPort
0B9, ZwSetIoCompletion
0BA, ZwSetContextThread
0BB, ZwSetDefaultHardErrorPort
0BC, ZwSetDefaultLocale
0BD, ZwSetDefaultUILanguage
0BE, ZwSetEaFile
0BF, ZwSetEvent
0C0, ZwSetHighEventPair
0C1, ZwSetHighWaitLowEventPair
0C2, ZwSetInformationFile
0C3, ZwSetInformationJobObject
0C4, ZwSetInformationKey
0C5, ZwSetInformationObject
0C6, ZwSetInformationProcess
0C7, ZwSetInformationThread
0C8, ZwSetInformationToken
0C9, ZwSetIntervalProfile
0CA, ZwSetLdtEntries
0CB, ZwSetLowEventPair
0CC, ZwSetLowWaitHighEventPair
0CD, ZwSetQuotaInformationFile
0CE, ZwSetSecurityObject
0CF, ZwSetSystemEnvironmentValue
0D0, ZwSetSystemInformation
0D1, ZwSetSystemPowerState
0D2, ZwSetSystemTime
0D3, ZwSetThreadExecutionState
0D4, ZwSetTimer
0D5, ZwSetTimerResolution
0D6, ZwSetUuidSeed
0D7, ZwSetValueKey
0D8, ZwSetVolumeInformationFile
0D9, ZwShutdownSystem
0DA, ZwSignalAndWaitForSingleObject
0DB, ZwStartProfile
0DC, ZwStopProfile
0DD, ZwSuspendThread
0DE, ZwSystemDebugControl
0DF, ZwTerminateJobObject
0E0, ZwTerminateProcess
0E1, ZwTerminateThread
0E2, ZwTestAlert
0E3, ZwUnloadDriver
0E4, ZwUnloadKey
0E5, ZwUnlockFile
0E6, ZwUnlockVirtualMemory
0E7, ZwUnmapViewOfSection
0E8, ZwVdmControl
0E9, ZwWaitForMultipleObjects
0EA, ZwWaitForSingleObject
0EB, ZwWaitHighEventPair
0EC, ZwWaitLowEventPair
0ED, ZwWriteFile
0EE, ZwWriteFileGather
0EF, ZwWriteRequestData
0F0, ZwWriteVirtualMemory
0F1, ZwCreateChannel
0F2, ZwListenChannel
0F3, ZwOpenChannel
0F4, ZwReplyWaitSendChannel
0F5, ZwSendWaitReplyChannel
0F6, ZwSetContextChannel
0F7, ZwYieldExecution
----------------------------------------------------------
XP 서비스 번호별 API
SDT viewer by DeokYoung ,based SDT recover
KeServiceDescriptorTable 8054D8C0
KeServiceDecriptorTable.ServiceTable 804E05F8
KeServiceDescriptorTable.ServiceLimit 284
000, ZwAcceptConnectPort
001, ZwAccessCheck
002, ZwAccessCheckAndAuditAlarm
003, ZwAccessCheckByType
004, ZwAccessCheckByTypeAndAuditAlarm
005, ZwAccessCheckByTypeResultList
006, ZwAccessCheckByTypeResultListAndAuditAlarm
007, ZwAccessCheckByTypeResultListAndAuditAlarmByHandle
008, ZwAddAtom
009, ZwAddBootEntry
00A, ZwAdjustGroupsToken
00B, ZwAdjustPrivilegesToken
00C, ZwAlertResumeThread
00D, ZwAlertThread
00E, ZwAllocateLocallyUniqueId
00F, ZwAllocateUserPhysicalPages
010, ZwAllocateUuids
011, ZwAllocateVirtualMemory
012, ZwAreMappedFilesTheSame
013, ZwAssignProcessToJobObject
014, ZwCallbackReturn
015, ZwCancelDeviceWakeupRequest
016, ZwCancelIoFile
017, ZwCancelTimer
018, ZwClearEvent
019, ZwClose
01A, ZwCloseObjectAuditAlarm
01B, ZwCompactKeys
01C, ZwCompareTokens
01D, ZwCompleteConnectPort
01E, ZwCompressKey
01F, ZwConnectPort
020, ZwContinue
021, ZwCreateDebugObject
022, ZwCreateDirectoryObject
023, ZwCreateEvent
024, ZwCreateEventPair
025, ZwCreateFile
026, ZwCreateIoCompletion
027, ZwCreateJobObject
028, ZwCreateJobSet
029, ZwCreateKey
02A, ZwCreateMailslotFile
02B, ZwCreateMutant
02C, ZwCreateNamedPipeFile
02D, ZwCreatePagingFile
02E, ZwCreatePort
02F, ZwCreateProcess
030, ZwCreateProcessEx
031, ZwCreateProfile
032, ZwCreateSection
033, ZwCreateSemaphore
034, ZwCreateSymbolicLinkObject
035, ZwCreateThread
036, ZwCreateTimer
037, ZwCreateToken
038, ZwCreateWaitablePort
039, ZwDebugActiveProcess
03A, ZwDebugContinue
03B, ZwDelayExecution
03C, ZwDeleteAtom
03D, ZwDeleteBootEntry
03E, ZwDeleteFile
03F, ZwDeleteKey
040, ZwDeleteObjectAuditAlarm
041, ZwDeleteValueKey
042, ZwDeviceIoControlFile
043, ZwDisplayString
044, ZwDuplicateObject
045, ZwDuplicateToken
046, ZwEnumerateBootEntries
047, ZwEnumerateKey
048, ZwEnumerateSystemEnvironmentValuesEx
049, ZwEnumerateValueKey
04A, ZwExtendSection
04B, ZwFilterToken
04C, ZwFindAtom
04D, ZwFlushBuffersFile
04E, ZwFlushInstructionCache
04F, ZwFlushKey
050, ZwFlushVirtualMemory
051, ZwFlushWriteBuffer
052, ZwFreeUserPhysicalPages
053, ZwFreeVirtualMemory
054, ZwFsControlFile
055, ZwGetContextThread
056, ZwGetDevicePowerState
057, ZwGetPlugPlayEvent
058, ZwGetWriteWatch
059, ZwImpersonateAnonymousToken
05A, ZwImpersonateClientOfPort
05B, ZwImpersonateThread
05C, ZwInitializeRegistry
05D, ZwInitiatePowerAction
05E, ZwIsProcessInJob
05F, ZwIsSystemResumeAutomatic
060, ZwListenPort
061, ZwLoadDriver
062, ZwLoadKey
063, ZwLoadKey2
064, ZwLockFile
065, ZwLockProductActivationKeys
066, ZwLockRegistryKey
067, ZwLockVirtualMemory
068, ZwMakePermanentObject
069, ZwMakeTemporaryObject
06A, ZwMapUserPhysicalPages
06B, ZwMapUserPhysicalPagesScatter
06C, ZwMapViewOfSection
06D, ZwModifyBootEntry
06E, ZwNotifyChangeDirectoryFile
06F, ZwNotifyChangeKey
070, ZwNotifyChangeMultipleKeys
071, ZwOpenDirectoryObject
072, ZwOpenEvent
073, ZwOpenEventPair
074, ZwOpenFile
075, ZwOpenIoCompletion
076, ZwOpenJobObject
077, ZwOpenKey
078, ZwOpenMutant
079, ZwOpenObjectAuditAlarm
07A, ZwOpenProcess
07B, ZwOpenProcessToken
07C, ZwOpenProcessTokenEx
07D, ZwOpenSection
07E, ZwOpenSemaphore
07F, ZwOpenSymbolicLinkObject
080, ZwOpenThread
081, ZwOpenThreadToken
082, ZwOpenThreadTokenEx
083, ZwOpenTimer
084, ZwPlugPlayControl
085, ZwPowerInformation
086, ZwPrivilegeCheck
087, ZwPrivilegeObjectAuditAlarm
088, ZwPrivilegedServiceAuditAlarm
089, ZwProtectVirtualMemory
08A, ZwPulseEvent
08B, ZwQueryAttributesFile
08C, ZwQueryBootEntryOrder
08D, ZwQueryBootOptions
08E, ZwQueryDebugFilterState
08F, ZwQueryDefaultLocale
090, ZwQueryDefaultUILanguage
091, ZwQueryDirectoryFile
092, ZwQueryDirectoryObject
093, ZwQueryEaFile
094, ZwQueryEvent
095, ZwQueryFullAttributesFile
096, ZwQueryInformationAtom
097, ZwQueryInformationFile
098, ZwQueryInformationJobObject
099, ZwQueryInformationPort
09A, ZwQueryInformationProcess
09B, ZwQueryInformationThread
09C, ZwQueryInformationToken
09D, ZwQueryInstallUILanguage
09E, ZwQueryIntervalProfile
09F, ZwQueryIoCompletion
0A0, ZwQueryKey
0A1, ZwQueryMultipleValueKey
0A2, ZwQueryMutant
0A3, ZwQueryObject
0A4, ZwQueryOpenSubKeys
0A5, ZwQueryPerformanceCounter
0A6, ZwQueryQuotaInformationFile
0A7, ZwQuerySection
0A8, ZwQuerySecurityObject
0A9, ZwQuerySemaphore
0AA, ZwQuerySymbolicLinkObject
0AB, ZwQuerySystemEnvironmentValue
0AC, ZwQuerySystemEnvironmentValueEx
0AD, ZwQuerySystemInformation
0AE, ZwQuerySystemTime
0AF, ZwQueryTimer
0B0, ZwQueryTimerResolution
0B1, ZwQueryValueKey
0B2, ZwQueryVirtualMemory
0B3, ZwQueryVolumeInformationFile
0B4, ZwQueueApcThread
0B5, ZwRaiseException
0B6, ZwRaiseHardError
0B7, ZwReadFile
0B8, ZwReadFileScatter
0B9, ZwReadRequestData
0BA, ZwReadVirtualMemory
0BB, ZwRegisterThreadTerminatePort
0BC, ZwReleaseMutant
0BD, ZwReleaseSemaphore
0BE, ZwRemoveIoCompletion
0BF, ZwRemoveProcessDebug
0C0, ZwRenameKey
0C1, ZwReplaceKey
0C2, ZwReplyPort
0C3, ZwReplyWaitReceivePort
0C4, ZwReplyWaitReceivePortEx
0C5, ZwReplyWaitReplyPort
0C6, ZwRequestDeviceWakeup
0C7, ZwRequestPort
0C8, ZwRequestWaitReplyPort
0C9, ZwRequestWakeupLatency
0CA, ZwResetEvent
0CB, ZwResetWriteWatch
0CC, ZwRestoreKey
0CD, ZwResumeProcess
0CE, ZwResumeThread
0CF, ZwSaveKey
0D0, ZwSaveKeyEx
0D1, ZwSaveMergedKeys
0D2, ZwSecureConnectPort
0D3, ZwSetBootEntryOrder
0D4, ZwSetBootOptions
0D5, ZwSetContextThread
0D6, ZwSetDebugFilterState
0D7, ZwSetDefaultHardErrorPort
0D8, ZwSetDefaultLocale
0D9, ZwSetDefaultUILanguage
0DA, ZwSetEaFile
0DB, ZwSetEvent
0DC, ZwSetEventBoostPriority
0DD, ZwSetHighEventPair
0DE, ZwSetHighWaitLowEventPair
0DF, ZwSetInformationDebugObject
0E0, ZwSetInformationFile
0E1, ZwSetInformationJobObject
0E2, ZwSetInformationKey
0E3, ZwSetInformationObject
0E4, ZwSetInformationProcess
0E5, ZwSetInformationThread
0E6, ZwSetInformationToken
0E7, ZwSetIntervalProfile
0E8, ZwSetIoCompletion
0E9, ZwSetLdtEntries
0EA, ZwSetLowEventPair
0EB, ZwSetLowWaitHighEventPair
0EC, ZwSetQuotaInformationFile
0ED, ZwSetSecurityObject
0EE, ZwSetSystemEnvironmentValue
0EF, ZwSetSystemEnvironmentValueEx
0F0, ZwSetSystemInformation
0F1, ZwSetSystemPowerState
0F2, ZwSetSystemTime
0F3, ZwSetThreadExecutionState
0F4, ZwSetTimer
0F5, ZwSetTimerResolution
0F6, ZwSetUuidSeed
0F7, ZwSetValueKey
0F8, ZwSetVolumeInformationFile
0F9, ZwShutdownSystem
0FA, ZwSignalAndWaitForSingleObject
0FB, ZwStartProfile
0FC, ZwStopProfile
0FD, ZwSuspendProcess
0FE, ZwSuspendThread
0FF, ZwSystemDebugControl
100, ZwTerminateJobObject
101, ZwTerminateProcess
102, ZwTerminateThread
103, ZwTestAlert
104, ZwTraceEvent
105, ZwTranslateFilePath
106, ZwUnloadDriver
107, ZwUnloadKey
108, ZwUnloadKeyEx
109, ZwUnlockFile
10A, ZwUnlockVirtualMemory
10B, ZwUnmapViewOfSection
10C, ZwVdmControl
10D, ZwWaitForDebugEvent
10E, ZwWaitForMultipleObjects
10F, ZwWaitForSingleObject
110, ZwWaitHighEventPair
111, ZwWaitLowEventPair
112, ZwWriteFile
113, ZwWriteFileGather
114, ZwWriteRequestData
115, ZwWriteVirtualMemory
116, ZwYieldExecution
117, ZwCreateKeyedEvent
118, ZwOpenKeyedEvent
119, ZwReleaseKeyedEvent
11A, ZwWaitForKeyedEvent
11B, ZwQueryPortInformationProcess
----------------------------------------------------------
2003 서비스 번호별 API
SDT viewer by DeokYoung ,based SDT recover
Could not open physical memory device!
Make sure you are running as Administrator.
KeServiceDescriptorTable 808A83A0
Failed to map physical memory view of length 2000 at 8A83A0!
000, ZwAcceptConnectPort
001, ZwAccessCheck
002, ZwAccessCheckAndAuditAlarm
003, ZwAccessCheckByType
004, ZwAccessCheckByTypeAndAuditAlarm
005, ZwAccessCheckByTypeResultList
006, ZwAccessCheckByTypeResultListAndAuditAlarm
007, ZwAccessCheckByTypeResultListAndAuditAlarmByHandle
008, ZwAddAtom
009, ZwAddBootEntry
00A, ZwAddDriverEntry
00B, ZwAdjustGroupsToken
00C, ZwAdjustPrivilegesToken
00D, ZwAlertResumeThread
00E, ZwAlertThread
00F, ZwAllocateLocallyUniqueId
010, ZwAllocateUserPhysicalPages
011, ZwAllocateUuids
012, ZwAllocateVirtualMemory
013, ZwApphelpCacheControl
014, ZwAreMappedFilesTheSame
015, ZwAssignProcessToJobObject
016, ZwCallbackReturn
017, ZwCancelDeviceWakeupRequest
018, ZwCancelIoFile
019, ZwCancelTimer
01A, ZwClearEvent
01B, ZwClose
01C, ZwCloseObjectAuditAlarm
01D, ZwCompactKeys
01E, ZwCompareTokens
01F, ZwCompleteConnectPort
020, ZwCompressKey
021, ZwConnectPort
022, ZwContinue
023, ZwCreateDebugObject
024, ZwCreateDirectoryObject
025, ZwCreateEvent
026, ZwCreateEventPair
027, ZwCreateFile
028, ZwCreateIoCompletion
029, ZwCreateJobObject
02A, ZwCreateJobSet
02B, ZwCreateKey
02C, ZwCreateMailslotFile
02D, ZwCreateMutant
02E, ZwCreateNamedPipeFile
02F, ZwCreatePagingFile
030, ZwCreatePort
031, ZwCreateProcess
032, ZwCreateProcessEx
033, ZwCreateProfile
034, ZwCreateSection
035, ZwCreateSemaphore
036, ZwCreateSymbolicLinkObject
037, ZwCreateThread
038, ZwCreateTimer
039, ZwCreateToken
03A, ZwCreateWaitablePort
03B, ZwDebugActiveProcess
03C, ZwDebugContinue
03D, ZwDelayExecution
03E, ZwDeleteAtom
03F, ZwDeleteBootEntry
040, ZwDeleteDriverEntry
041, ZwDeleteFile
042, ZwDeleteKey
043, ZwDeleteObjectAuditAlarm
044, ZwDeleteValueKey
045, ZwDeviceIoControlFile
046, ZwDisplayString
047, ZwDuplicateObject
048, ZwDuplicateToken
049, ZwEnumerateBootEntries
04A, ZwEnumerateDriverEntries
04B, ZwEnumerateKey
04C, ZwEnumerateSystemEnvironmentValuesEx
04D, ZwEnumerateValueKey
04E, ZwExtendSection
04F, ZwFilterToken
050, ZwFindAtom
051, ZwFlushBuffersFile
052, ZwFlushInstructionCache
053, ZwFlushKey
054, ZwFlushVirtualMemory
055, ZwFlushWriteBuffer
056, ZwFreeUserPhysicalPages
057, ZwFreeVirtualMemory
058, ZwFsControlFile
059, ZwGetContextThread
05A, ZwGetDevicePowerState
05B, ZwGetPlugPlayEvent
05C, ZwGetWriteWatch
05D, ZwImpersonateAnonymousToken
05E, ZwImpersonateClientOfPort
05F, ZwImpersonateThread
060, ZwInitializeRegistry
061, ZwInitiatePowerAction
062, ZwIsProcessInJob
063, ZwIsSystemResumeAutomatic
064, ZwListenPort
065, ZwLoadDriver
066, ZwLoadKey
067, ZwLoadKey2
068, ZwLoadKeyEx
069, ZwLockFile
06A, ZwLockProductActivationKeys
06B, ZwLockRegistryKey
06C, ZwLockVirtualMemory
06D, ZwMakePermanentObject
06E, ZwMakeTemporaryObject
06F, ZwMapUserPhysicalPages
070, ZwMapUserPhysicalPagesScatter
071, ZwMapViewOfSection
072, ZwModifyBootEntry
073, ZwModifyDriverEntry
074, ZwNotifyChangeDirectoryFile
075, ZwNotifyChangeKey
076, ZwNotifyChangeMultipleKeys
077, ZwOpenDirectoryObject
078, ZwOpenEvent
079, ZwOpenEventPair
07A, ZwOpenFile
07B, ZwOpenIoCompletion
07C, ZwOpenJobObject
07D, ZwOpenKey
07E, ZwOpenMutant
07F, ZwOpenObjectAuditAlarm
080, ZwOpenProcess
081, ZwOpenProcessToken
082, ZwOpenProcessTokenEx
083, ZwOpenSection
084, ZwOpenSemaphore
085, ZwOpenSymbolicLinkObject
086, ZwOpenThread
087, ZwOpenThreadToken
088, ZwOpenThreadTokenEx
089, ZwOpenTimer
08A, ZwPlugPlayControl
08B, ZwPowerInformation
08C, ZwPrivilegeCheck
08D, ZwPrivilegeObjectAuditAlarm
08E, ZwPrivilegedServiceAuditAlarm
08F, ZwProtectVirtualMemory
090, ZwPulseEvent
091, ZwQueryAttributesFile
092, ZwQueryBootEntryOrder
093, ZwQueryBootOptions
094, ZwQueryDebugFilterState
095, ZwQueryDefaultLocale
096, ZwQueryDefaultUILanguage
097, ZwQueryDirectoryFile
098, ZwQueryDirectoryObject
099, ZwQueryDriverEntryOrder
09A, ZwQueryEaFile
09B, ZwQueryEvent
09C, ZwQueryFullAttributesFile
09D, ZwQueryInformationAtom
09E, ZwQueryInformationFile
09F, ZwQueryInformationJobObject
0A0, ZwQueryInformationPort
0A1, ZwQueryInformationProcess
0A2, ZwQueryInformationThread
0A3, ZwQueryInformationToken
0A4, ZwQueryInstallUILanguage
0A5, ZwQueryIntervalProfile
0A6, ZwQueryIoCompletion
0A7, ZwQueryKey
0A8, ZwQueryMultipleValueKey
0A9, ZwQueryMutant
0AA, ZwQueryObject
0AB, ZwQueryOpenSubKeys
0AC, ZwQueryOpenSubKeysEx
0AD, ZwQueryPerformanceCounter
0AE, ZwQueryQuotaInformationFile
0AF, ZwQuerySection
0B0, ZwQuerySecurityObject
0B1, ZwQuerySemaphore
0B2, ZwQuerySymbolicLinkObject
0B3, ZwQuerySystemEnvironmentValue
0B4, ZwQuerySystemEnvironmentValueEx
0B5, ZwQuerySystemInformation
0B6, ZwQuerySystemTime
0B7, ZwQueryTimer
0B8, ZwQueryTimerResolution
0B9, ZwQueryValueKey
0BA, ZwQueryVirtualMemory
0BB, ZwQueryVolumeInformationFile
0BC, ZwQueueApcThread
0BD, ZwRaiseException
0BE, ZwRaiseHardError
0BF, ZwReadFile
0C0, ZwReadFileScatter
0C1, ZwReadRequestData
0C2, ZwReadVirtualMemory
0C3, ZwRegisterThreadTerminatePort
0C4, ZwReleaseMutant
0C5, ZwReleaseSemaphore
0C6, ZwRemoveIoCompletion
0C7, ZwRemoveProcessDebug
0C8, ZwRenameKey
0C9, ZwReplaceKey
0CA, ZwReplyPort
0CB, ZwReplyWaitReceivePort
0CC, ZwReplyWaitReceivePortEx
0CD, ZwReplyWaitReplyPort
0CE, ZwRequestDeviceWakeup
0CF, ZwRequestPort
0D0, ZwRequestWaitReplyPort
0D1, ZwRequestWakeupLatency
0D2, ZwResetEvent
0D3, ZwResetWriteWatch
0D4, ZwRestoreKey
0D5, ZwResumeProcess
0D6, ZwResumeThread
0D7, ZwSaveKey
0D8, ZwSaveKeyEx
0D9, ZwSaveMergedKeys
0DA, ZwSecureConnectPort
0DB, ZwSetBootEntryOrder
0DC, ZwSetBootOptions
0DD, ZwSetContextThread
0DE, ZwSetDebugFilterState
0DF, ZwSetDefaultHardErrorPort
0E0, ZwSetDefaultLocale
0E1, ZwSetDefaultUILanguage
0E2, ZwSetDriverEntryOrder
0E3, ZwSetEaFile
0E4, ZwSetEvent
0E5, ZwSetEventBoostPriority
0E6, ZwSetHighEventPair
0E7, ZwSetHighWaitLowEventPair
0E8, ZwSetInformationDebugObject
0E9, ZwSetInformationFile
0EA, ZwSetInformationJobObject
0EB, ZwSetInformationKey
0EC, ZwSetInformationObject
0ED, ZwSetInformationProcess
0EE, ZwSetInformationThread
0EF, ZwSetInformationToken
0F0, ZwSetIntervalProfile
0F1, ZwSetIoCompletion
0F2, ZwSetLdtEntries
0F3, ZwSetLowEventPair
0F4, ZwSetLowWaitHighEventPair
0F5, ZwSetQuotaInformationFile
0F6, ZwSetSecurityObject
0F7, ZwSetSystemEnvironmentValue
0F8, ZwSetSystemEnvironmentValueEx
0F9, ZwSetSystemInformation
0FA, ZwSetSystemPowerState
0FB, ZwSetSystemTime
0FC, ZwSetThreadExecutionState
0FD, ZwSetTimer
0FE, ZwSetTimerResolution
0FF, ZwSetUuidSeed
100, ZwSetValueKey
101, ZwSetVolumeInformationFile
102, ZwShutdownSystem
103, ZwSignalAndWaitForSingleObject
104, ZwStartProfile
105, ZwStopProfile
106, ZwSuspendProcess
107, ZwSuspendThread
108, ZwSystemDebugControl
109, ZwTerminateJobObject
10A, ZwTerminateProcess
10B, ZwTerminateThread
10C, ZwTestAlert
10D, ZwTraceEvent
10E, ZwTranslateFilePath
10F, ZwUnloadDriver
110, ZwUnloadKey
111, ZwUnloadKey2
112, ZwUnloadKeyEx
113, ZwUnlockFile
114, ZwUnlockVirtualMemory
115, ZwUnmapViewOfSection
116, ZwVdmControl
117, ZwWaitForDebugEvent
118, ZwWaitForMultipleObjects
119, ZwWaitForSingleObject
11A, ZwWaitHighEventPair
11B, ZwWaitLowEventPair
11C, ZwWriteFile
11D, ZwWriteFileGather
11E, ZwWriteRequestData
11F, ZwWriteVirtualMemory
120, ZwYieldExecution
121, ZwCreateKeyedEvent
122, ZwOpenKeyedEvent
123, ZwReleaseKeyedEvent
124, ZwWaitForKeyedEvent
125, ZwQueryPortInformationProcess
126, ZwGetCurrentProcessorNumber
127, ZwWaitForMultipleObjects32
---------------------------------------------------------
함수의 갯수가 약 40개 씩 증가 하고 있네요 :-)
No hay comentarios:
Publicar un comentario