MSDN |
|
1. __SEH_prolog |
|
|
MSDN |
|
2. NtIsProcessInJob |
|
|
MSDN |
|
3. RtlDosPathNameToRelativeNtPathName_U |
|
NTDLL |
MSDN |
|
4. RtlInitUnicodeString |
|
|
MSDN |
|
5. RtlDetermineDosPathNameType_U |
|
|
MSDN |
|
6. NtOpenFile |
|
|
MSDN |
|
7. RtlReleaseRelativeName |
|
NTDLL |
MSDN |
|
8. NtCreateSection |
|
|
MSDN |
|
9. BasepIsProcessAllowed |
|
KERNEL32 |
MSDN |
|
10. BasepFreeAppCompatData |
|
KERNEL32 |
MSDN |
|
11. NtQuerySection |
|
|
MSDN |
|
12. BasepCheckBadapp |
|
KERNEL32 |
MSDN |
|
13. BasepCheckWinSaferRestrictions |
|
KERNEL32 |
MSDN |
|
14. LdrQueryImageFileExecutionOptions |
|
NTDLL |
MSDN |
|
15. BasepIsImageVersionOk |
|
|
MSDN |
|
16. BaseFormatObjectAttributes |
|
KERNEL32 |
MSDN |
|
17. NtCreateProcessEx |
|
|
MSDN |
|
18. RtlAllocateHeap |
|
NTDLL |
MSDN |
|
19. GetModuleHandleA |
|
KERNEL32 |
MSDN |
|
20. RtlImageNtHeader |
|
NTDLL |
MSDN |
|
21. BasepSxsCreateProcessCsrMessage |
|
KERNEL32 |
MSDN |
|
22. GetFullPathNameW |
|
KERNEL32 |
MSDN |
|
23. GetFileAttributesW |
|
KERNEL32 |
MSDN |
|
24. BasePushProcessParameters |
|
KERNEL32 |
MSDN |
|
25. RtlFreeUnicodeString |
|
|
MSDN |
|
26. BaseCreateStack |
|
KERNEL32 |
MSDN |
|
27. BaseInitializeContext |
|
|
MSDN |
|
28. NtCreateThread |
|
|
MSDN |
|
29. CsrClientCallServer |
|
NTDLL |
MSDN |
|
30. NtResumeThread |
|
|
MSDN |
|
31. __SEH_epilog |
|
|
MSDN |
|
32. NtReadVirtualMemory |
|
|
MSDN |
|
33. StuffStdHandle |
|
|
MSDN |
|
34. BaseComputeProcessExePath |
|
KERNEL32 |
MSDN |
|
35. SearchPathW |
|
KERNEL32 |
MSDN |
|
36. RtlFreeHeap |
|
NTDLL |