Summary:
NtAddAtom(>) | 1 | NtGdiCreateSolidBrush(>) | 2 | NtOpenSymbolicLinkObject(>) | 6 | NtQueryInformationFile(>) | 30 |
NtAllocateLocallyUniqueId(>) | 1 | NtGdiHfontCreate(>) | 2 | NtQuerySymbolicLinkObject(>) | 6 | NtEnumerateKey(>) | 31 |
NtAreMappedFilesTheSame(>) | 1 | NtOpenDirectoryObject(>) | 2 | NtCreateSemaphore(>) | 7 | NtCreateEvent(>) | 32 |
NtCallbackReturn(>) | 1 | NtQueryInformationJobObject(>) | 2 | NtUserCallNoParam(>) | 7 | NtOpenThreadToken(>) | 33 |
NtClearEvent(>) | 1 | NtQueryInstallUILanguage(>) | 2 | NtQueryVirtualMemory(>) | 8 | NtReleaseMutant(>) | 38 |
NtConnectPort(>) | 1 | NtRegisterThreadTerminatePort(>) | 2 | NtWriteVirtualMemory(>) | 8 | NtUnmapViewOfSection(>) | 40 |
NtDelayExecution(>) | 1 | NtSetEvent(>) | 2 | NtQueryDefaultUILanguage(>) | 10 | NtQueryInformationProcess(>) | 41 |
NtDuplicateToken(>) | 1 | NtTestAlert(>) | 2 | NtUserGetWindowDC(>) | 10 | NtQueryDefaultLocale(>) | 42 |
NtGdiCreateBitmap(>) | 1 | NtUserCloseDesktop(>) | 2 | NtWriteFile(>) | 10 | NtProtectVirtualMemory(>) | 46 |
NtGdiCreateHalftonePalette(>) | 1 | NtUserCreateWindowEx(>) | 2 | NtSetValueKey(>) | 11 | NtUserUnregisterClass(>) | 47 |
NtGdiCreatePaletteInternal(>) | 1 | NtUserDestroyWindow(>) | 2 | NtUserCallOneParam(>) | 11 | NtUserFindExistingCursorIcon(>) | 49 |
NtGdiCreatePatternBrushInternal(>) | 1 | NtUserFindWindowEx(>) | 2 | NtUserSystemParametersInfo(>) | 11 | NtCreateSection(>) | 58 |
NtGdiDoPalette(>) | 1 | NtUserGetObjectInformation(>) | 2 | NtOpenProcessToken(>) | 14 | NtUserRegisterClassExWOW(>) | 65 |
NtGdiInit(>) | 1 | NtUserMessageCall(>) | 2 | NtRequestWaitReplyPort(>) | 14 | NtWaitForSingleObject(>) | 66 |
NtGdiQueryFontAssocInfo(>) | 1 | NtCreateThread(>) | 3 | NtNotifyChangeKey(>) | 15 | NtOpenSection(>) | 74 |
NtGdiSelectBitmap(>) | 1 | NtDuplicateObject(>) | 3 | NtQueryVolumeInformationFile(>) | 15 | NtReadFile(>) | 77 |
NtOpenKeyedEvent(>) | 1 | NtOpenMutant(>) | 3 | NtCreateKey(>) | 17 | NtMapViewOfSection(>) | 82 |
NtQueryFullAttributesFile(>) | 1 | NtOpenProcess(>) | 3 | NtDeviceIoControlFile(>) | 17 | NtOpenFile(>) | 89 |
NtQueryInformationThread(>) | 1 | NtResumeThread(>) | 3 | NtFsControlFile(>) | 17 | NtQuerySystemInformation(>) | 89 |
NtQueryObject(>) | 1 | NtTerminateProcess(>) | 3 | NtFlushInstructionCache(>) | 19 | NtAllocateVirtualMemory(>) | 90 |
NtQueryPerformanceCounter(>) | 1 | NtUserOpenDesktop(>) | 3 | NtUserRegisterWindowMessage(>) | 19 | NtUserGetClassInfo(>) | 91 |
NtQuerySystemTime(>) | 1 | NtUserRemoveProp(>) | 3 | NtQueryDirectoryFile(>) | 20 | NtOpenProcessTokenEx(>) | 110 |
NtSecureConnectPort(>) | 1 | NtWaitForMultipleObjects(>) | 3 | NtFreeVirtualMemory(>) | 22 | NtOpenThreadTokenEx(>) | 110 |
NtUserBuildNameList(>) | 1 | NtCreateMutant(>) | 4 | NtEnumerateValueKey(>) | 23 | NtQueryInformationToken(>) | 126 |
NtUserGetAtomName(>) | 1 | NtGdiCreateCompatibleDC(>) | 4 | NtSetInformationProcess(>) | 23 | NtQueryKey(>) | 129 |
NtUserGetDC(>) | 1 | NtOpenEvent(>) | 4 | NtQueryDebugFilterState(>) | 24 | NtUserQueryWindow(>) | 134 |
NtUserGetForegroundWindow(>) | 1 | NtQuerySecurityObject(>) | 4 | NtRaiseException(>) | 25 | NtQueryAttributesFile(>) | 150 |
NtUserGetGUIThreadInfo(>) | 1 | NtGdiGetStockObject(>) | 5 | NtSetInformationFile(>) | 25 | NtQueryValueKey(>) | 223 |
NtUserGetThreadDesktop(>) | 1 | NtReadVirtualMemory(>) | 5 | NtSetInformationThread(>) | 27 | NtOpenKey(>) | 475 |
NtUserSetProp(>) | 1 | NtSetInformationObject(>) | 5 | NtQuerySection(>) | 28 | NtClose(>) | 574 |
NtAccessCheck(>) | 2 | NtUserBuildHwndList(>) | 5 | NtReleaseSemaphore(>) | 28 | ||
NtCreateIoCompletion(>) | 2 | NtUserGetProcessWindowStation(>) | 5 | NtCreateFile(>) | 29 | ||
NtCreateProcessEx(>) | 2 |
\4\231C\0\16sq\217V\316\31\350\265\215\252\1\260\276\205l\6|*%'\11H\355\246\226Q\324\314\260\7\211y\2251\31\257\263\211/v%0\256\236\346\343\13\217\247VK\36ME\5\377e\207\266\243\37\267\317\302\37\246\312\361\345\305LC\307\254\7\13\333\2250\1\344-\26@?\3333j\242\232\306\10\313\0v\361\322\363q\337;*\221oR\31d\0[\37I9\326K\205\306\300\357\\321\33\243\11\13\374\275\304\227 \215!\3109\307\200`\20\316\363\342X$4\274\31\13\360*8\224B!x::)x\360_\32"
, ) , ) == 0x0 00937 444 NtDeviceIoControlFile (112, 0, 0x0, 0x0, 0x390008, (112, 0, 0x0, 0x0, 0x390008, "lP!\304\34g\377\27\245\320\14\263\372V\270\316\305\3716\217|\324\275\305\3716\217|\324\275\305\3716\217|\324\275\305\3716\217|}\273\257\313\202\17\334\347\323\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 00938 444 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 00939 444 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 00940 444 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 00941 444 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 00942 444 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 00943 444 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 00944 444 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 00945 444 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482040, 2, ) }, 0, 0x0, 0, ... -2147482040, 2, ) == 0x0 00946 444 NtSetValueKey (-2147482040, (-2147482040, "Seed", 0, 3, "\345\241\235\302\345^\275\17,\314}\307\200\315\260\302\15z\343zW\225\356\245\32;y\231\317\24\3603?\243\255y[\210k\322W\2\256q\37C|K\361\307\243G\332\337Sx\340\212j\304\276Zv$T\11\4\204\233sn\31\361\26\264\221\260\373\374\326", 80, ... ) , 0, 3, (-2147482040, "Seed", 0, 3, "\345\241\235\302\345^\275\17,\314}\307\200\315\260\302\15z\343zW\225\356\245\32;y\231\317\24\3603?\243\255y[\210k\322W\2\256q\37C|K\361\307\243G\332\337Sx\340\212j\304\276Zv$T\11\4\204\233sn\31\361\26\264\221\260\373\374\326", 80, ... ) , 80, ... ) == 0x0 00947 444 NtClose (-2147482040, ... ) == 0x0 00937 444 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "j\240\365U\302\203\73\353\11\351\310\215:\361\251\277\274+\206\205[\323h\342H\363Fv\17\232X\14\260\264\312\353\374l\7\3]7x\31