tady ten konečnej
GMER 1.0.15.15281 -
http://www.gmer.netRootkit scan 2010-06-18 22:54:30
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Jendus\LOCALS~1\Temp\pftiiaoc.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwAssignProcessToJobObject [0xECDB8610]
SSDT spdg.sys ZwCreateKey [0xF84150E0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwDebugActiveProcess [0xECDB8C10]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwDuplicateObject [0xECDB8730]
SSDT spdg.sys ZwEnumerateKey [0xF8433CA4]
SSDT spdg.sys ZwEnumerateValueKey [0xF8434032]
SSDT spdg.sys ZwOpenKey [0xF84150C0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwOpenProcess [0xECDB84B0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwOpenThread [0xECDB8570]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwProtectVirtualMemory [0xECDB86D0]
SSDT spdg.sys ZwQueryKey [0xF843410A]
SSDT spdg.sys ZwQueryValueKey [0xF8433F8A]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSetContextThread [0xECDB8690]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSetInformationThread [0xECDB8650]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSetSecurityObject [0xECDB87D0]
SSDT spdg.sys ZwSetValueKey [0xF843419C]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSuspendProcess [0xECDB8510]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSuspendThread [0xECDB8590]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwTerminateProcess [0xECDB84D0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwTerminateThread [0xECDB85D0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwWriteVirtualMemory [0xECDB8750]
INT 0x62 ? 823DEBF8
INT 0x63 ? 821E8F00
INT 0x82 ? 823DEBF8
INT 0x83 ? 821E8F00
INT 0x83 ? 821E8F00
INT 0xA4 ? 821E8F00
INT 0xB4 ? 821E8F00
---- Kernel code sections - GMER 1.0.15 ----
? spdg.sys The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload F81048AC 5 Bytes JMP 821E84E0
.text aoi60j5g.SYS F7D2F386 35 Bytes [00, 00, 00, 00, 00, 00, 20, ...]
.text aoi60j5g.SYS F7D2F3AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, ...]
.text aoi60j5g.SYS F7D2F3C4 3 Bytes [00, 70, 02] {ADD [EAX+0x2], DH}
.text aoi60j5g.SYS F7D2F3C9 1 Byte [30]
.text aoi60j5g.SYS F7D2F3C9 11 Bytes [30, 00, 00, 00, 5C, 02, 00, ...] {XOR [EAX], AL; ADD [EAX], AL; POP ESP; ADD AL, [EAX]; ADD [EAX], AL; ADD [EAX], AL}
.text ...
.text win32k.sys!EngSetPointerTag + 8DF8 BF91EE00 36 Bytes CALL BF80ECA7 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngSetPointerTag + 8E1D BF91EE25 4 Bytes [D8, 74, 76, 3B] {FDIV DWORD [ESI+ESI*2+0x3b]}
.text win32k.sys!EngSetPointerTag + 8E22 BF91EE2A 109 Bytes [F8, 0F, 85, B3, 00, 00, 00, ...]
.text win32k.sys!EngSetPointerTag + 8E90 BF91EE98 16 Bytes CALL BF8E59B2 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngSetPointerTag + 8EA1 BF91EEA9 143 Bytes [74, 3C, 8B, 4B, 4C, 8B, 53, ...]
.text ...
.text win32k.sys!XFORMOBJ_iGetFloatObjXform + E BF933494 133 Bytes [C8, FF, EB, 34, 83, 7D, 0C, ...]
.text win32k.sys!FLOATOBJ_GetLong + 2 BF93351A 26 Bytes [55, 8B, EC, 6A, 00, 8D, 45, ...]
.text win32k.sys!FLOATOBJ_AddFloat BF933537 108 Bytes [8B, FF, 55, 8B, EC, 51, 51, ...]
.text win32k.sys!FLOATOBJ_Add + 17 BF9335A4 34 Bytes [90, 90, 90, 90, 90, 8B, FF, ...]
.text win32k.sys!FLOATOBJ_SubFloat + 1E BF9335C7 3 Bytes CALL BF837E98 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!FLOATOBJ_SubFloat + 22 BF9335CB 28 Bytes [C9, C2, 08, 00, 90, 90, 90, ...]
.text win32k.sys!FLOATOBJ_SubLong + 15 BF9335E9 1 Byte [F8]
.text win32k.sys!FLOATOBJ_SubLong + 15 BF9335E9 33 Bytes [F8, 50, FF, 75, 08, FF, 75, ...]
.text win32k.sys!FLOATOBJ_Sub + C BF93360B 6 Bytes [75, 08, E8, 85, 48, F0]
.text win32k.sys!FLOATOBJ_Sub + 13 BF933612 42 Bytes [5D, C2, 08, 00, 90, 90, 90, ...]
.text win32k.sys!FLOATOBJ_MulFloat + 22 BF93363D 47 Bytes [C9, C2, 08, 00, 90, 90, 90, ...]
.text win32k.sys!FLOATOBJ_MulLong + 29 BF93366F 56 Bytes [90, 90, 8B, FF, 55, 8B, EC, ...]
.text win32k.sys!FLOATOBJ_DivFloat + 1B BF9336A8 36 Bytes CALL BF80F3A4 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!FLOATOBJ_DivLong + 15 BF9336CD 20 Bytes [F8, 50, FF, 75, 08, FF, 75, ...]
.text win32k.sys!FLOATOBJ_Div BF9336E3 23 Bytes [8B, FF, 55, 8B, EC, FF, 75, ...]
.text win32k.sys!FLOATOBJ_Neg BF9336FF 157 Bytes [8B, FF, 55, 8B, EC, 8B, 4D, ...]
.text win32k.sys!FLOATOBJ_GreaterThanLong + 45 BF93379E 29 Bytes [90, 90, 90, 8B, FF, 55, 8B, ...]
.text win32k.sys!FLOATOBJ_LessThanLong + 1B BF9337BC 35 Bytes [F8, 50, FF, 75, 0C, E8, 38, ...]
.text win32k.sys!FLOATOBJ_Equal + 6 BF9337E0 9 Bytes [75, 0C, 8B, 4D, 08, E8, E5, ...]
.text win32k.sys!FLOATOBJ_Equal + 10 BF9337EA 28 Bytes [5D, C2, 08, 00, 90, 90, 90, ...]
.text win32k.sys!FLOATOBJ_GreaterThan + 14 BF933807 28 Bytes [90, 90, 90, 90, 90, 8B, FF, ...]
.text win32k.sys!FLOATOBJ_LessThan + 19 BF933825 29 Bytes [8B, FF, 55, 8B, EC, 56, 8B, ...]
.text win32k.sys!FLOATOBJ_LessThan + 39 BF933845 180 Bytes [8B, FF, 55, 8B, EC, 56, 57, ...]
.text win32k.sys!FLOATOBJ_LessThan + EE BF9338FA 110 Bytes [55, 8B, EC, 8B, 41, 44, 57, ...]
.text win32k.sys!FLOATOBJ_LessThan + 15D BF933969 98 Bytes [89, 46, 08, 5E, 5D, C2, 04, ...]
.text win32k.sys!FLOATOBJ_LessThan + 1C0 BF9339CC 135 Bytes CALL BF84BEF0 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text ...
.text win32k.sys!CLIPOBJ_ppoGetPath + 2 BF933B1F 3 Bytes [55, 8B, EC] {PUSH EBP; MOV EBP, ESP}
.text win32k.sys!CLIPOBJ_ppoGetPath + 6 BF933B23 5 Bytes [4D, 08, E8, 4C, FE]
.text win32k.sys!CLIPOBJ_ppoGetPath + C BF933B29 104 Bytes [FF, 5D, C2, 04, 00, 90, 90, ...]
.text win32k.sys!EngIsSemaphoreOwnedByCurrentThread + B BF933B92 6 Bytes [90, 90, 90, 90, 90, 8B]
.text win32k.sys!EngDebugPrint + 2 BF933B99 13 Bytes [55, 8B, EC, 81, EC, 04, 01, ...]
.text win32k.sys!EngDebugPrint + 10 BF933BA7 3 Bytes [56, 8B, 75]
.text win32k.sys!EngDebugPrint + 14 BF933BAB 54 Bytes [89, 45, FC, 8B, 45, 08, 57, ...]
.text win32k.sys!EngDebugPrint + 4B BF933BE2 10 Bytes [C9, C2, 0C, 00, 90, 90, 90, ...]
.text win32k.sys!EngDebugPrint + 56 BF933BED 30 Bytes [55, 8B, EC, FF, 75, 18, FF, ...]
.text win32k.sys!EngProbeForRead + 2 BF933C0C 4 Bytes [55, 8B, EC, 57] {PUSH EBP; MOV EBP, ESP; PUSH EDI}
.text win32k.sys!EngProbeForRead + 7 BF933C11 10 Bytes [7D, 0C, 85, FF, 74, 28, 8B, ...] {JGE 0xe; TEST EDI, EDI; JZ 0x2e; MOV EAX, [EBP+0x10]; PUSH ESI}
.text win32k.sys!EngProbeForRead + 12 BF933C1C 100 Bytes [75, 08, 48, 85, C6, 74, 06, ...]
.text win32k.sys!EngAllocSectionMem + 38 BF933C81 6 Bytes [15, 1C, CC, 98, BF, 85]
.text win32k.sys!EngAllocSectionMem + 3F BF933C88 55 Bytes [7D, 04, 33, C0, EB, 48, 8D, ...]
.text win32k.sys!EngAllocSectionMem + 77 BF933CC0 73 Bytes [8B, 7D, 10, 8B, D1, C1, E9, ...]
.text win32k.sys!EngMapSection BF933D0B 142 Bytes [8B, FF, 55, 8B, EC, 83, EC, ...]
.text win32k.sys!EngMapSection + 90 BF933D9B 46 Bytes [90, 90, 90, 8B, FF, 55, 8B, ...]
.text win32k.sys!EngInitializeSafeSemaphore + 1B BF933DCA 183 Bytes [85, C0, 89, 06, 75, 04, 33, ...]
.text win32k.sys!EngDeleteSafeSemaphore + 97 BF933E82 26 Bytes [FF, 55, 8B, EC, 5D, E9, 7F, ...]
.text win32k.sys!EngDeleteSafeSemaphore + B6 BF933EA1 19 Bytes [8B, FF, 55, 8B, EC, 5D, E9, ...] {MOV EDI, EDI; PUSH EBP; MOV EBP, ESP; POP EBP; JMP 0x16cbe; NOP ; NOP ; NOP ; NOP ; NOP ; MOV EDI, EDI; PUSH EBP}
.text win32k.sys!EngDeleteSafeSemaphore + CA BF933EB5 7 Bytes JMP BF80667B \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngDeleteSafeSemaphore + D5 BF933EC0 102 Bytes [90, 8B, FF, 55, 8B, EC, 6A, ...]
.text win32k.sys!EngDeleteSafeSemaphore + 13F BF933F2A 12 Bytes [90, 8B, FF, 55, 8B, EC, A1, ...] {NOP ; MOV EDI, EDI; PUSH EBP; MOV EBP, ESP; MOV EAX, [0xbf9a5480]; POP EBP}
.text ...
.text win32k.sys!HeapVidMemAllocAligned + 14 BF934312 20 Bytes [90, 90, 8B, FF, 55, 8B, EC, ...]
.text win32k.sys!EngAllocPrivateUserMem BF93432A 18 Bytes [8B, FF, 55, 8B, EC, A1, 80, ...] {MOV EDI, EDI; PUSH EBP; MOV EBP, ESP; MOV EAX, [0xbf9a5480]; POP EBP; JMP [EAX+0x2a4]; NOP }
.text win32k.sys!EngFreePrivateUserMem BF934340 16 Bytes [8B, FF, 55, 8B, EC, A1, 80, ...]
.text win32k.sys!EngFreePrivateUserMem + 11 BF934351 44 Bytes [90, 90, 90, 90, 90, 8B, FF, ...]
.text win32k.sys!EngLockDirectDrawSurface + 15 BF934381 130 Bytes [90, 8B, FF, 55, 8B, EC, A1, ...]
.text win32k.sys!EngUnlockDirectDrawSurface + 82 BF934404 239 Bytes [75, 08, 8D, 4D, 08, 33, F6, ...]
.text win32k.sys!EngUnlockDirectDrawSurface + 172 BF9344F4 14 Bytes [C2, 10, 00, 90, 90, 90, 90, ...] {RET 0x10; NOP ; NOP ; NOP ; NOP ; NOP ; MOV EDI, EDI; PUSH EBP; MOV EBP, ESP; PUSH ESI}
.text win32k.sys!EngUnlockDirectDrawSurface + 181 BF934503 24 Bytes [75, 08, 8D, 4D, 08, 33, F6, ...]
.text win32k.sys!EngUnlockDirectDrawSurface + 19A BF93451C 45 Bytes [B0, 08, 03, 00, 00, 8D, 4D, ...]
.text win32k.sys!EngUnlockDirectDrawSurface + 1C8 BF93454A 36 Bytes [4D, 10, 83, 09, FF, 83, 7D, ...]
.text ...
.text win32k.sys!EngGetType1FontList BF934EA2 27 Bytes [8B, FF, 55, 8B, EC, 51, 56, ...]
.text win32k.sys!EngGetType1FontList + 1C BF934EBE 23 Bytes [FF, 89, 86, CC, 02, 00, 00, ...]
.text win32k.sys!EngGetType1FontList + 34 BF934ED6 3 Bytes [84, EB, 00]
.text win32k.sys!EngGetType1FontList + 39 BF934EDB 115 Bytes [8B, 55, 18, 89, 3A, EB, 05, ...]
.text win32k.sys!EngGetType1FontList + AD BF934F4F 11 Bytes [86, CC, 02, 00, 00, 33, D2, ...]
.text ...
.text win32k.sys!EngQueryLocalTime BF934FD4 180 Bytes [8B, FF, 55, 8B, EC, 83, EC, ...]
.text win32k.sys!EngQueryLocalTime + B7 BF93508B 61 Bytes [8B, 01, F6, 40, 28, 08, 74, ...]
.text win32k.sys!EngQueryLocalTime + F5 BF9350C9 4 Bytes [0D, F0, BF, 9A]
.text win32k.sys!EngQueryLocalTime + FA BF9350CE 44 Bytes CALL BF801982 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngQueryLocalTime + 127 BF9350FB 47 Bytes [83, 26, 00, 83, 66, 04, 00, ...]
.text ...
.text win32k.sys!EngCheckAbort + 3 BF935264 236 Bytes [8B, EC, 8B, 45, 08, 8D, 48, ...]
.text win32k.sys!EngCheckAbort + F0 BF935351 9 Bytes CALL BF800C42 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngCheckAbort + FF BF935360 2 Bytes [FF, 55]
.text win32k.sys!EngCheckAbort + 102 BF935363 37 Bytes [EC, 83, EC, 10, 83, 4D, FC, ...]
.text win32k.sys!EngCheckAbort + 128 BF935389 129 Bytes [00, 00, 53, 8B, 5D, 08, 56, ...]
.text ...
.text win32k.sys!EngMapEvent + 1A BF936AA3 60 Bytes [8B, F0, 89, 75, E4, 33, DB, ...]
.text win32k.sys!EngMapEvent + 57 BF936AE0 4 Bytes [15, 54, CE, 98]
.text win32k.sys!EngMapEvent + 5C BF936AE5 9 Bytes [83, 4E, 04, 01, EB, 2C, 56, ...]
.text win32k.sys!EngMapEvent + 66 BF936AEF 1 Byte [EC]
.text win32k.sys!EngMapEvent + 66 BF936AEF 43 Bytes [EC, FF, 33, F6, 89, 75, E4, ...]
.text ...
.text win32k.sys!EngClearEvent + 2 BF936B80 150 Bytes [55, 8B, EC, 8B, 45, 08, FF, ...]
.text win32k.sys!EngReadStateEvent + 80 BF936C17 1 Byte [5D]
.text win32k.sys!EngReadStateEvent + 80 BF936C17 104 Bytes [5D, 08, 8D, 74, 73, DE, EB, ...]
.text win32k.sys!EngGetFilePath + A BF936C80 90 Bytes [70, 20, 85, F6, 74, 0B, 56, ...]
.text win32k.sys!EngGetFileChangeTime + 3A BF936CDC 2 Bytes [80, CB]
.text win32k.sys!EngGetFileChangeTime + 3E BF936CE0 33 Bytes [56, 56, 6A, 10, 6A, 03, 56, ...]
.text win32k.sys!EngGetFileChangeTime + 61 BF936D03 45 Bytes [D4, 18, 00, 00, 00, 89, 75, ...]
.text win32k.sys!EngGetFileChangeTime + 8F BF936D31 18 Bytes [FF, 15, 24, D0, 98, BF, 85, ...] {CALL [0xbf98d024]; TEST EAX, EAX; JL 0x1b; MOV ECX, [EBP-0x44]; MOV EAX, [EBP+0xc]; MOV [EAX], ECX}
.text win32k.sys!EngGetFileChangeTime + A3 BF936D45 50 Bytes [C0, 33, F6, 89, 48, 04, 46, ...]
.text ...
.text win32k.sys!EngDeleteFile + 14 BF936F34 41 Bytes [15, 80, CB, 98, BF, 83, 65, ...]
.text win32k.sys!EngDeleteFile + 3E BF936F5E 169 Bytes [15, 40, D0, 98, BF, 85, C0, ...]
.text win32k.sys!EngDeleteFile + E8 BF937008 179 Bytes [8D, 55, F8, FF, 75, 44, FF, ...]
.text win32k.sys!EngDeleteFile + 19C BF9370BC 82 Bytes [45, F4, 8B, 45, 30, 8B, 18, ...]
.text win32k.sys!EngDeleteFile + 1EF BF93710F 63 Bytes [75, 20, FF, 75, 1C, FF, 75, ...]
.text ...
.text win32k.sys!EngControlSprites + 4 BF9380DC 45 Bytes [EC, 83, EC, 0C, 83, 7D, 0C, ...]
.text win32k.sys!EngControlSprites + 32 BF93810A 9 Bytes [4D, F4, 89, 7D, 08, E8, 8A, ...]
.text win32k.sys!EngControlSprites + 3C BF938114 250 Bytes [8B, 46, 68, 85, C0, 74, 1D, ...]
.text win32k.sys!EngControlSprites + 137 BF93820F 61 Bytes [85, C0, 75, 3A, 53, E8, ED, ...]
.text win32k.sys!EngControlSprites + 175 BF93824D 4 Bytes [8B, 46, 08, 3B]
.text ...
.text win32k.sys!EngMovePointer + 25 BF938A5D 3 Bytes [45, FC, 50] {INC EBP; CLD ; PUSH EAX}
.text win32k.sys!EngMovePointer + 29 BF938A61 53 Bytes CALL BF80CDC9 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngMovePointer + 5F BF938A97 3 Bytes [0F, 82, 86]
.text win32k.sys!EngMovePointer + 63 BF938A9B 23 Bytes [00, 00, 8B, 96, 7C, 01, 00, ...]
.text win32k.sys!EngMovePointer + 7B BF938AB3 13 Bytes [8B, DA, 8B, C1, 8B, 48, 10, ...] {MOV EBX, EDX; MOV EAX, ECX; MOV ECX, [EAX+0x10]; CMP ECX, EBX; JNZ 0x2; XOR EBX, EBX}
.text ...
.text win32k.sys!EngSetPointerShape + 76 BF938C30 44 Bytes [01, 00, 00, 89, 9E, C4, 01, ...]
.text win32k.sys!EngSetPointerShape + A3 BF938C5D 5 Bytes [00, 89, 86, C0, 01]
.text win32k.sys!EngSetPointerShape + AA BF938C64 102 Bytes [39, BE, C4, 01, 00, 00, 72, ...]
.text win32k.sys!EngSetPointerShape + 111 BF938CCB 25 Bytes [7F, 10, 3B, FB, 75, EB, 8D, ...]
.text win32k.sys!EngSetPointerShape + 12B BF938CE5 25 Bytes [75, 14, FF, 75, 10, FF, 75, ...]
.text ...
.text win32k.sys!EngUnlockDriverObj + 6 BF939221 79 Bytes CALL BF8017AA \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngQueryPalette + 1E BF939271 10 Bytes [55, 0C, 83, E0, 0F, 89, 02, ...] {PUSH EBP; OR AL, 0x83; LOOPNZ 0x14; MOV [EDX], EAX; CMP [ECX+0x14], ESI}
.text win32k.sys!EngQueryPalette + 29 BF93927C 9 Bytes [18, 6A, 01, FF, 75, 14, 8D, ...] {SBB [EDX+0x1], CH; PUSH DWORD [EBP+0x14]; LEA ECX, [EBP+0x8]}
.text win32k.sys!EngQueryPalette + 33 BF939286 7 Bytes [75, 10, 56, E8, 33, D0, F7]
.text win32k.sys!EngQueryPalette + 3B BF93928E 96 Bytes [8B, 4D, 08, 8B, F0, EB, 28, ...]
.text win32k.sys!EngQueryPalette + 9C BF9392EF 166 Bytes [EC, 8B, 55, 10, 85, D2, 74, ...]
.text ...
.text win32k.sys!EngCreatePath + 38 BF93959D 3 Bytes CALL BF933958 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngCreatePath + 3C BF9395A1 54 Bytes CALL BF84BEAB \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngDeletePath + 24 BF9395D8 84 Bytes [55, 8B, EC, 83, EC, 14, 53, ...]
.text win32k.sys!EngDeletePath + 79 BF93962D 17 Bytes [4D, F0, 83, 45, F4, 08, EB, ...] {DEC EBP; LOCK ADD DWORD [EBP-0xc], 0x8; JMP 0x1a; PUSH EBX; LEA EAX, [EBP-0x14]; PUSH EAX; PUSH 0x0; MOV ECX, EDI}
.text win32k.sys!EngDeletePath + 8B BF93963F 3 Bytes CALL BF84BC88 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngDeletePath + 8F BF939643 138 Bytes [85, C0, 74, 45, 83, 7D, F0, ...]
.text win32k.sys!WNDOBJ_cEnumStart + 1 BF9396CE 31 Bytes [FF, 55, 8B, EC, FF, 75, 14, ...]
.text win32k.sys!WNDOBJ_vSetConsumer BF9396EE 146 Bytes [8B, FF, 55, 8B, EC, 8B, 45, ...]
.text win32k.sys!WNDOBJ_vSetConsumer + 93 BF939781 27 Bytes [B6, 94, 00, 00, 00, E8, 4C, ...]
.text win32k.sys!WNDOBJ_vSetConsumer + AF BF93979D 7 Bytes [8B, FF, 55, 8B, EC, 56, 57] {MOV EDI, EDI; PUSH EBP; MOV EBP, ESP; PUSH ESI; PUSH EDI}
.text win32k.sys!WNDOBJ_vSetConsumer + B7 BF9397A5 51 Bytes [7D, 08, 8B, F1, 8D, 4F, 04, ...]
.text win32k.sys!WNDOBJ_vSetConsumer + EB BF9397D9 1 Byte [46]
.text ...
.text win32k.sys!EngCreateWnd + 6D BF9398A5 18 Bytes [88, 00, 00, 00, 0F, 84, CE, ...] {MOV [EAX], AL; ADD [EAX], AL; JZ 0x1d8; MOV EAX, [EAX+0x80]; CMP EAX, ESI}
.text win32k.sys!EngCreateWnd + 80 BF9398B8 1 Byte [E7]
.text win32k.sys!EngCreateWnd + 80 BF9398B8 10 Bytes [E7, 8B, 49, 04, 3B, CE, 75, ...] {OUT 0x8b, EAX; DEC ECX; ADD AL, 0x3b; INTO ; JNZ 0xffffffffffffffe3; CMP EBX, ESI}
.text win32k.sys!EngCreateWnd + 8B BF9398C3 41 Bytes [1C, 39, 7B, 10, 75, 08, 8B, ...]
.text win32k.sys!EngCreateWnd + B5 BF9398ED 171 Bytes [D8, 3B, DE, 0F, 84, 2B, 02, ...]
.text ...
.text win32k.sys!EngDeleteWnd + 24 BF939C84 28 Bytes CALL BF939B3E \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngDeleteWnd + 41 BF939CA1 77 Bytes [9A, BF, 8D, 4D, F4, E8, A8, ...]
.text win32k.sys!EngDeleteWnd + 8F BF939CEF 15 Bytes [10, 75, 21, 8B, 7E, 0C, EB, ...]
.text win32k.sys!EngDeleteWnd + 9F BF939CFF 114 Bytes [6A, 00, 8D, 4D, F8, E8, 5E, ...]
.text win32k.sys!EngDeleteWnd + 112 BF939D72 8 Bytes CALL BF80D664 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text ...
.text win32k.sys!EngDitherColor + 29 BF93A9CD 35 Bytes [83, 7D, 0C, 02, 56, 74, 41, ...]
.text win32k.sys!EngDitherColor + 4D BF93A9F1 17 Bytes [C8, 8D, 55, E0, 2B, CA, C1, ...] {ENTER 0x558d, 0xe0; SUB ECX, EDX; SAR ECX, 0x3; CMP ESI, 0x3; PUSH ECX; PUSH EAX; MOV EAX, EDX; PUSH EAX}
.text win32k.sys!EngDitherColor + 5F BF93AA03 78 Bytes CALL BF93A53E \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngDitherColor + AE BF93AA52 163 Bytes [6F, B6, 99, BF, 48, 8D, 0C, ...]
.text win32k.sys!EngDitherColor + 152 BF93AAF6 7 Bytes [5E, 5D, C2, 04, 00, 90, 90] {POP ESI; POP EBP; RET 0x4; NOP ; NOP }
.text ...
.text win32k.sys!EngEnumForms + 2C BF93B264 155 Bytes [4A, 87, ED, FF, 8B, F0, 85, ...]
.text win32k.sys!EngEnumForms + C8 BF93B300 127 Bytes CALL BF802A5D \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngGetPrinter + 5B BF93B383 56 Bytes [FC, 54, BA, 99, BF, 53, 56, ...]
.text win32k.sys!EngGetPrinter + 94 BF93B3BC 3 Bytes CALL BF802AEA \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngGetPrinter + 98 BF93B3C0 11 Bytes [8B, F0, 89, 75, 0C, EB, 07, ...] {MOV ESI, EAX; MOV [EBP+0xc], ESI; JMP 0xe; AND DWORD [EBP+0xc], 0x0}
.text win32k.sys!EngGetPrinter + A4 BF93B3CC 102 Bytes [75, 0C, 85, F6, 74, 59, 6A, ...]
.text win32k.sys!EngGetPrinter + 10B BF93B433 14 Bytes [F8, 5F, 5E, 5B, C9, C2, 14, ...]
.text win32k.sys!EngGetForm + 2 BF93B442 108 Bytes [55, 8B, EC, 51, 56, 33, F6, ...]
.text win32k.sys!EngGetForm + 6F BF93B4AF 157 Bytes [CA, 83, E1, 03, F3, A4, 8D, ...]
.text win32k.sys!EngGetForm + 10D BF93B54D 3 Bytes [EC, 51, 8B]
.text win32k.sys!EngGetForm + 111 BF93B551 56 Bytes [1C, 56, 33, F6, 3B, C6, 89, ...]
.text win32k.sys!EngGetForm + 14A BF93B58A 3 Bytes CALL BF8139B3 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text ...
.text win32k.sys!EngGetPrinterData + 53 BF93B729 50 Bytes [8B, 4D, 18, 89, 38, 89, 48, ...]
.text win32k.sys!EngGetPrinterData + 86 BF93B75C 106 Bytes CALL BF802AE9 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngGetPrinterData + F1 BF93B7C7 3 Bytes CALL BF802A61 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngGetPrinterData + F5 BF93B7CB 16 Bytes CALL BF802A5C \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngGetPrinterData + 106 BF93B7DC 1 Byte [18]
.text win32k.sys!EngSetPrinterData + 5 BF93B7E8 28 Bytes [51, 51, 83, 7D, 0C, 00, 53, ...]
.text win32k.sys!EngSetPrinterData + 22 BF93B805 29 Bytes [02, 59, 89, 7D, FC, EB, 07, ...]
.text win32k.sys!EngSetPrinterData + 40 BF93B823 160 Bytes CALL BF8139AE \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngSetPrinterData + E1 BF93B8C4 60 Bytes [90, 90, 90, 90, 90, 6A, 10, ...]
.text win32k.sys!EngWritePrinter + 38 BF93B901 43 Bytes [FF, 15, 68, CB, 98, BF, 8B, ...]
.text win32k.sys!EngWritePrinter + 66 BF93B92F 68 Bytes [00, C7, 43, 6C, 10, 00, 00, ...]
.text win32k.sys!EngWritePrinter + AB BF93B974 69 Bytes [89, 7D, FC, 8D, 0C, 16, 3B, ...]
.text win32k.sys!EngWritePrinter + F1 BF93B9BA 42 Bytes [83, 67, 08, 00, C7, 43, 70, ...]
.text win32k.sys!EngWritePrinter + 11C BF93B9E5 57 Bytes [89, 7B, 74, C7, 83, 84, 00, ...]
.text ...
.text win32k.sys!EngFileWrite + 1 BF93BB1D 25 Bytes [FF, 55, 8B, EC, 57, 8B, 7D, ...]
.text win32k.sys!EngFileWrite + 1B BF93BB37 46 Bytes [85, C0, 8B, 45, 14, 7D, 05, ...]
.text win32k.sys!EngFileIoControl + 17 BF93BB66 111 Bytes [75, 14, FF, 75, 10, FF, 75, ...]
.text win32k.sys!EngGetTickCount + 4F BF93BBD6 91 Bytes [74, 77, 53, 56, 8B, 75, 08, ...]
.text win32k.sys!EngGetTickCount + AB BF93BC32 7 Bytes [6A, 01, 57, E8, 61, FF, FF]
.text win32k.sys!EngGetTickCount + B3 BF93BC3A 1 Byte [66]
.text win32k.sys!EngGetTickCount + B3 BF93BC3A 74 Bytes [66, 8B, 47, 02, 66, 89, 46, ...]
.text win32k.sys!EngGetTickCount + FE BF93BC85 49 Bytes JMP BF93C82A \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text ...
.text win32k.sys!EngHangNotification + 1B BF93E418 5 Bytes [8B, B7, 74, 05, 00]
.text win32k.sys!EngHangNotification + 21 BF93E41E 6 Bytes [83, FE, FC, 0F, 84, B9]
.text win32k.sys!EngHangNotification + 28 BF93E425 7 Bytes [00, 00, 85, F6, 0F, 84, B1]
.text win32k.sys!EngHangNotification + 30 BF93E42D 44 Bytes [00, 00, 53, 8D, 46, 20, 50, ...]
.text win32k.sys!EngHangNotification + 5D BF93E45A 382 Bytes [8A, CB, 02, C8, 80, C1, 28, ...]
.text ...
.text win32k.sys!EngFntCacheFault + 4 BF93EE93 32 Bytes [EC, 51, A1, 74, 56, 9A, BF, ...]
.text win32k.sys!EngFntCacheFault + 25 BF93EEB4 98 Bytes [76, 27, 83, 7D, 0C, 02, 77, ...]
.text win32k.sys!EngFntCacheFault + 88 BF93EF17 1 Byte [75]
.text win32k.sys!EngFntCacheFault + 88 BF93EF17 89 Bytes [75, 08, 89, 55, FC, 8B, 50, ...]
.text win32k.sys!EngFntCacheFault + E2 BF93EF71 10 Bytes [89, 48, 04, A1, 6C, 56, 9A, ...] {MOV [EAX+0x4], ECX; MOV EAX, [0xbf9a566c]; MOV EAX, [EAX]}
.text ...
.text win32k.sys!EngMapModule + D BF93F0EF 38 Bytes [0C, 89, 0A, 8B, 40, 08, 5D, ...]
.text win32k.sys!EngUnmapFile + 18 BF93F116 83 Bytes [4E, 14, 8B, F8, FF, 15, 3C, ...]
.text win32k.sys!EngUnmapFile + 6C BF93F16A 46 Bytes [F9, 08, 75, 05, 33, C0, 40, ...]
.text win32k.sys!EngUnmapFile + 9B BF93F199 3 Bytes [BE, 00, 00]
.text win32k.sys!EngUnmapFile + 9F BF93F19D 7 Bytes [10, 39, 75, 0C, 0F, 87, AB]
.text win32k.sys!EngUnmapFile + A9 BF93F1A7 48 Bytes [83, 7D, 0C, 0C, 0F, 82, A1, ...]
.text ...
.text win32k.sys!EngMapFile + 6 BF93F82D 34 Bytes [57, 68, 47, 66, 69, 6C, 6A, ...]
.text win32k.sys!EngMapFile + 29 BF93F850 6 Bytes [75, 08, E8, 23, 6E, F6]
.text win32k.sys!EngMapFile + 30 BF93F857 152 Bytes [85, C0, 8B, 45, 10, 74, 07, ...]
.text win32k.sys!EngMapFile + C9 BF93F8F0 86 Bytes [39, 5D, F8, 74, 7E, 39, 5D, ...]
.text win32k.sys!EngMapFile + 120 BF93F947 16 Bytes [75, F8, 8D, 45, D8, 53, 50, ...] {JNZ 0xfffffffffffffffa; LEA EAX, [EBP-0x28]; PUSH EBX; PUSH EAX; PUSH ESI; CALL 0xfffffffffff76b9b; MOV [EBP+0x14], EAX}
.text ...
.text win32k.sys!EngGetPrinterDataFileName + 12 BF93F9B0 15 Bytes [90, 90, 90, 90, 90, 8B, FF, ...]
.text win32k.sys!EngGetDriverName + B BF93F9C0 1 Byte [03]
.text win32k.sys!EngGetDriverName + B BF93F9C0 47 Bytes [03, 00, 00, 8B, 40, 08, 8B, ...]
.text win32k.sys!EngQueryDeviceAttribute + 1E BF93F9F0 19 Bytes [80, 8C, 05, 00, 00, 89, 01, ...] {OR BYTE [EBP+EAX+0x1890000], 0x33; ROL BYTE [EAX+0x5d], 0xc2; SBB [EAX], AL; NOP ; NOP ; NOP ; NOP ; NOP }
.text win32k.sys!EngQueryDeviceAttribute + 32 BF93FA04 108 Bytes [FF, 55, 8B, EC, 83, EC, 10, ...]
.text win32k.sys!EngQueryDeviceAttribute + 9F BF93FA71 24 Bytes [03, 00, 00, 8B, 03, 89, 40, ...]
.text win32k.sys!EngQueryDeviceAttribute + B8 BF93FA8A 30 Bytes [00, 8B, 03, 89, 88, E0, 02, ...]
.text win32k.sys!EngQueryDeviceAttribute + D8 BF93FAAA 62 Bytes CALL 4A93FAB1
.text ...
.text win32k.sys!EngPlgBlt + 2 BF941FC9 117 Bytes [55, 8B, EC, 81, EC, 10, 02, ...]
.text win32k.sys!EngPlgBlt + 79 BF942040 15 Bytes [FA, 08, 0F, 84, AA, 0C, 00, ...]
.text win32k.sys!EngPlgBlt + 89 BF942050 11 Bytes [00, 8B, 4B, 3C, 83, F9, 09, ...]
.text win32k.sys!EngPlgBlt + 95 BF94205C 66 Bytes [00, 83, FA, 0A, 0F, 84, 8C, ...]
.text win32k.sys!EngPlgBlt + D8 BF94209F 12 Bytes [8D, 4D, D4, 89, 45, BC, 89, ...]
.text ...
.text win32k.sys!STROBJ_fxBreakExtra + 22 BF9447E9 22 Bytes [EC, 83, EC, 18, 53, 8B, 5D, ...]
.text win32k.sys!STROBJ_fxBreakExtra + 39 BF944800 123 Bytes CALL 6539EDAA
.text win32k.sys!STROBJ_fxBreakExtra + B5 BF94487C 48 Bytes [4D, EC, 8B, 4D, 0C, 50, 89, ...]
.text win32k.sys!STROBJ_fxBreakExtra + E6 BF9448AD 116 Bytes [10, 10, 74, 3E, FF, 75, 38, ...]
.text win32k.sys!STROBJ_fxBreakExtra + 164 BF94492B 41 Bytes [8B, 55, 10, 4A, 8B, 4D, 08, ...]
.text ...
.text win32k.sys!FONTOBJ_cGetAllGlyphHandles + 2 BF945D75 48 Bytes [55, 8B, EC, 8B, 45, 08, 56, ...]
.text win32k.sys!FONTOBJ_pvTrueTypeFontFile + 2 BF945DA6 29 Bytes [55, 8B, EC, 8B, 4D, 0C, 8B, ...]
.text win32k.sys!FONTOBJ_pvTrueTypeFontFile + 20 BF945DC4 14 Bytes [8B, F0, 83, 65, 0C, 00, 8D, ...] {MOV ESI, EAX; AND DWORD [EBP+0xc], 0x0; LEA ECX, [EBP+0xc]; CALL 0xffffffffffebeb4c}
.text win32k.sys!FONTOBJ_pvTrueTypeFontFile + 2F BF945DD3 5 Bytes [C6, 5E, 5D, C2, 08]
.text win32k.sys!FONTOBJ_pvTrueTypeFontFile + 35 BF945DD9 30 Bytes [90, 90, 90, 90, 90, 8B, FF, ...]
.text win32k.sys!FONTOBJ_pvTrueTypeFontFile + 54 BF945DF8 101 Bytes [74, 0E, 51, 52, 8D, 4D, 10, ...]
.text win32k.sys!FONTOBJ_pwszFontFilePaths + 2 BF945E5E 6 Bytes [55, 8B, EC, 8B, 4D, 0C] {PUSH EBP; MOV EBP, ESP; MOV ECX, [EBP+0xc]}
.text win32k.sys!FONTOBJ_pwszFontFilePaths + 9 BF945E65 140 Bytes [45, 08, 56, 33, F6, 21, 31, ...]
.text win32k.sys!FONTOBJ_pQueryGlyphAttrs + 4F BF945EF2 65 Bytes [FF, 55, 8B, EC, 0F, B6, 4D, ...]
.text win32k.sys!FONTOBJ_pQueryGlyphAttrs + 91 BF945F34 13 Bytes [CA, 25, E0, 03, 00, 00, 81, ...] {RETF 0xe025; ADD EAX, [EAX]; ADD [ECX+0xfc00e1], AL; ADD [EBX], CL}
.text win32k.sys!FONTOBJ_pQueryGlyphAttrs + 9F BF945F42 55 Bytes [81, E2, F8, 00, 00, 00, C1, ...]
.text win32k.sys!FONTOBJ_pQueryGlyphAttrs + D9 BF945F7C 28 Bytes CALL BF8E173C \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!FONTOBJ_pQueryGlyphAttrs + F6 BF945F99 64 Bytes [FF, 55, 8B, EC, 8B, 55, 0C, ...]
.text ...
.text win32k.sys!XLATEOBJ_cGetPalette + 40 BF94746C 132 Bytes [EB, 38, 8B, 49, 24, EB, 03, ...]
.text win32k.sys!XLATEOBJ_hGetColorTransform + 42 BF9474F1 100 Bytes [8B, FF, 55, 8B, EC, 33, C9, ...]
.text win32k.sys!XLATEOBJ_hGetColorTransform + A7 BF947556 5 Bytes [90, 90, 90, 90, 90] {NOP ; NOP ; NOP ; NOP ; NOP }
.text win32k.sys!XLATEOBJ_hGetColorTransform + AD BF94755C 17 Bytes [FF, 55, 8B, EC, 33, C9, 8A, ...]
.text win32k.sys!XLATEOBJ_hGetColorTransform + BF BF94756E 22 Bytes [00, 23, C8, C1, E1, 05, 23, ...]
.text win32k.sys!XLATEOBJ_hGetColorTransform + D6 BF947585 8 Bytes [45, 0C, 8A, 04, 01, 8B, 4D, ...] {INC EBP; OR AL, 0x8a; ADD AL, 0x1; MOV ECX, [EBP+0x8]}
.text ...