1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81
| enum { ZW_CREATE_THREAD = 0, ZW_CREATE_THREAD_EX, ZW_SUSPEND_THREAD, ZW_SUSPEND_PROCESS, ZW_PROTECT_VIRTUAL_MEMORY, ZW_SHUTDOWN_SYSTEM, ZW_TERMINATE_THREAD, ZW_SET_CONTEXT_THREAD, ZW_TERMINATE_JOB_OBJECT, ZW_SYSTEM_DEBUG_CONTROL, ZW_CREATE_USER_PROCESS, ZW_DEBUG_ACTIVE_PROCESS, ZW_SET_SYSTEM_POWER_STATE, ZW_INITIATE_POWER_ACTION, ZW_QUEUE_APC_THREAD, ZW_QUERY_INFORMATION_THREAD, ZW_QUERY_INFORMATION_JOB_OBJECT, ZW_READ_VIRTUAL_MEMORY, ZW_WRITE_VIRTUAL_MEMORY, ZW_TERMINATE_PROCESS, ZW_CREATE_SECTION, ZW_CREATE_PROCESS_EX, ZW_CREATE_PAGING_FILE,
ZW_OPEN_KEY, ZW_CREATE_KEY, ZW_DELETE_KEY, ZW_DELETE_VALUE_KEY, ZW_SET_VALUE_KEY, ZW_QUERY_VALUE_KEY, ZW_ENUMERATE_VALUE_KEY, ZW_ENUMERATE_KEY, ZW_QUERY_KEY, ZW_CLOSE_HANDLE, ZW_OPEN_KEY_EX, ZW_RENAME_KEY, ZW_RESTORE_KEY, ZW_SET_SECURITY_OBJECT,
ZW_WRITE_FILE, ZW_OPEN_SECTION, ZW_LOAD_DRIVER, ZW_SET_SYSTEM_INFORMATION, ZW_REQUEST_WAIT_REPLY_PORT, ZW_SET_SYSTEM_TIME, ZW_DEVICE_IO_CONTROL_FILE, ZW_REPLY_PORT, ZW_UNMAP_VIEWOFSECTION, ZW_FREE_VIRTUAL_MEMORY, ZW_ALPC_SEND_WAIT_RECEIVE_PORT, ZW_RAISE_HARD_ERROR, ZW_FS_CONTROL_FILE,
ZW_TEST_ALERT, ZW_OPEN_PROCESS, ZW_SET_INFORMATION_PROCESS,
ZW_SET_TIMER, ZW_QUERY_VIRTUAL_MEMORY,
ZW_DISPLAY_STRING, NT_DLL_INFOS, };
typedef struct { PVOID ServiceAddress; char* ServiceName; }NTDLL_INFO;
extern NTDLL_INFO __NtdllInfos[NT_DLL_INFOS];
|