#10
Příspěvek
od otulka » 12 zář 2010 10:32
.text ...
.text KernelBase.dll!SetLocalTime + 4F 75590C10 49 Bytes [66, 89, 4D, DE, 66, 8B, 48, ...]
.text KernelBase.dll!SetLocalTime + 81 75590C42 63 Bytes [00, 00, C0, EB, 4A, 8B, 45, ...]
.text KernelBase.dll!SetLocalTime + C1 75590C82 135 Bytes [FF, 75, F8, 8B, F0, FF, 15, ...]
.text KernelBase.dll!BaseInvalidateProcessSearchPathCache + 48 75590D0A 11 Bytes JMP 3025FF5D
.text KernelBase.dll!BaseInvalidateProcessSearchPathCache + 54 75590D16 5 Bytes [8B, 45, 08, 0F, B7]
.text KernelBase.dll!BaseInvalidateProcessSearchPathCache + 5A 75590D1C 2 Bytes [8D, 44]
.text KernelBase.dll!BaseInvalidateProcessSearchPathCache + 5D 75590D1F 4 Bytes [02, 5D, C2, 04]
.text KernelBase.dll!BaseInvalidateProcessSearchPathCache + 62 75590D24 21 Bytes [90, 90, 90, 90, 90, 8B, FF, ...]
.text ...
.text KernelBase.dll!SetFileApisToANSI + 13 75590DCA 142 Bytes [8B, 0D, 00, 10, 56, 75, 89, ...]
.text KernelBase.dll!SetStdHandleEx + 68 75590E59 170 Bytes [48, 10, 8B, 75, 0C, 8B, 41, ...]
.text KernelBase.dll!SetStdHandleEx + 113 75590F04 11 Bytes [C2, 0C, 00, 90, 90, 90, 90, ...] {RET 0xc; NOP ; NOP ; NOP ; NOP ; NOP ; LEA ECX, [EBP-0x40]}
.text KernelBase.dll!SetStdHandleEx + 11F 75590F10 27 Bytes [15, 54, 10, 56, 75, C3, 90, ...]
.text KernelBase.dll!SetStdHandleEx + 13B 75590F2C 120 Bytes [00, 00, 00, 00, 0C, 0F, 59, ...]
.text KernelBase.dll!Wow64RevertWow64FsRedirection + 6C 75590FA5 125 Bytes [3B, CF, 75, F6, 53, 2B, C2, ...]
.text KernelBase.dll!Wow64RevertWow64FsRedirection + EA 75591023 9 Bytes [83, C4, 0C, BE, A0, 02, 00, ...]
.text KernelBase.dll!Wow64RevertWow64FsRedirection + F4 7559102D 21 Bytes [39, 7D, FC, 74, 16, FF, 75, ...]
.text KernelBase.dll!Wow64RevertWow64FsRedirection + 10A 75591043 9 Bytes [15, 14, 10, 56, 75, E8, 9C, ...]
.text KernelBase.dll!Wow64RevertWow64FsRedirection + 114 7559104D 9 Bytes [8B, 40, 2C, 64, 8B, 0D, 18, ...]
.text ...
.text KernelBase.dll!GetFinalPathNameByHandleA + 5F 755912A7 11 Bytes CALL 7557C750 \Windows\System32\KernelBase.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text KernelBase.dll!GetFinalPathNameByHandleA + 6B 755912B3 76 Bytes [0C, 00, 3B, CE, 77, A6, 8B, ...]
.text KernelBase.dll!GetFinalPathNameByHandleA + B8 75591300 2 Bytes [70, 18] {JO 0x1a}
.text KernelBase.dll!GetFinalPathNameByHandleA + BB 75591303 52 Bytes [15, 14, 10, 56, 75, 8B, C6, ...]
.text KernelBase.dll!GetFinalPathNameByHandleA + F0 75591338 11 Bytes [46, 01, 3B, 45, 10, 77, 14, ...] {INC ESI; ADD [EBX], EDI; INC EBP; ADC [EDI+0x14], DH; MOV EBX, [EBP+0xc]; PUSH ESI}
.text ...
.text KernelBase.dll!MapViewOfFileExNuma + 2 7559136A 33 Bytes [55, 8B, EC, 51, 51, 8B, 4D, ...]
.text KernelBase.dll!MapViewOfFileExNuma + 25 7559138D 19 Bytes [14, 89, 45, F8, 8B, 45, 10, ...] {ADC AL, 0x89; INC EBP; CLC ; MOV EAX, [EBP+0x10]; MOV [EBP-0x4], EAX; MOV EAX, [EBP+0x18]; MOV [EBP+0x14], EAX; MOV EAX, [EBP+0x1c]}
.text KernelBase.dll!MapViewOfFileExNuma + 39 755913A1 4 Bytes [45, 20, 8B, 45]
.text KernelBase.dll!MapViewOfFileExNuma + 3E 755913A6 156 Bytes [83, F8, 21, 75, 05, 83, C0, ...]
.text KernelBase.dll!VirtualAllocExNuma + 1A 75591443 81 Bytes [74, 0F, 83, F8, 10, 72, 0A, ...]
.text KernelBase.dll!SetProcessAffinityUpdateMode + 1 75591495 15 Bytes [FF, 55, 8B, EC, F7, 45, 0C, ...]
.text KernelBase.dll!SetProcessAffinityUpdateMode + 12 755914A6 5 Bytes [C0, E8, D2, 55, FD] {SHR AL, 0xd2; PUSH EBP; STD }
.text KernelBase.dll!SetProcessAffinityUpdateMode + 18 755914AC 9 Bytes [33, C0, EB, 29, F6, 45, 0C, ...]
.text KernelBase.dll!SetProcessAffinityUpdateMode + 22 755914B6 222 Bytes [58, 0F, 94, C0, 6A, 04, 40, ...]
.text KernelBase.dll!FatalAppExitW + 4B 75591595 296 Bytes CALL 3ECE6BAB
.text KernelBase.dll!FatalAppExitA + F1 755916BE 11 Bytes [00, C0, 8B, 5D, 0C, 3B, DF, ...]
.text KernelBase.dll!FatalAppExitA + FD 755916CA 7 Bytes [00, 39, 7D, 08, 0F, 84, D9]
.text KernelBase.dll!FatalAppExitA + 105 755916D2 1 Byte [00]
.text KernelBase.dll!FatalAppExitA + 105 755916D2 71 Bytes [00, 00, 89, 7D, FC, 33, C0, ...]
.text KernelBase.dll!FatalAppExitA + 14D 7559171A 1 Byte [00]
.text ...
.text KernelBase.dll!OpenWaitableTimerW + 11 755917F2 75 Bytes CALL 75566A7C \Windows\System32\KernelBase.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text KernelBase.dll!OpenWaitableTimerW + 5D 7559183E 30 Bytes CALL 755667E5 \Windows\System32\KernelBase.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text KernelBase.dll!OpenWaitableTimerW + 7C 7559185D 18 Bytes [FC, 50, FF, 15, 9C, 12, 56, ...]
.text KernelBase.dll!OpenWaitableTimerW + 8F 75591870 39 Bytes [90, 90, 90, 90, 90, 8B, FF, ...]
.text KernelBase.dll!OpenWaitableTimerW + B7 75591898 5 Bytes [00, 8B, 40, 30, 68]
.text ...
.text KernelBase.dll!SetThreadPriorityBoost + 26 75591978 4 Bytes CALL 75566A7E \Windows\System32\KernelBase.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text KernelBase.dll!SetThreadPriorityBoost + 2B 7559197D 54 Bytes [33, C0, EB, 03, 33, C0, 40, ...]
.text KernelBase.dll!GetThreadPriorityBoost + 27 755919B4 8 Bytes [45, 0C, 8B, 4D, 08, 89, 08, ...]
.text KernelBase.dll!GetThreadPriorityBoost + 30 755919BD 25 Bytes [40, 5D, C2, 08, 00, 90, 90, ...]
.text KernelBase.dll!CreateThread + 10 755919D7 6 Bytes [FF, 75, 10, FF, 75, 0C] {PUSH DWORD [EBP+0x10]; PUSH DWORD [EBP+0xc]}
.text KernelBase.dll!CreateThread + 17 755919DE 8 Bytes [75, 08, 6A, FF, E8, 48, A1, ...]
.text KernelBase.dll!CreateThread + 20 755919E7 10 Bytes [5D, C2, 18, 00, 90, 90, 90, ...]
.text KernelBase.dll!CreateRemoteThread + 2 755919F2 17 Bytes [55, 8B, EC, FF, 75, 20, 6A, ...] {PUSH EBP; MOV EBP, ESP; PUSH DWORD [EBP+0x20]; PUSH 0x0; PUSH DWORD [EBP+0x1c]; PUSH DWORD [EBP+0x18]; PUSH DWORD [EBP+0x14]}
.text KernelBase.dll!CreateRemoteThread + 14 75591A04 5 Bytes [75, 10, FF, 75, 0C] {JNZ 0x12; PUSH DWORD [EBP+0xc]}
.text KernelBase.dll!CreateRemoteThread + 1A 75591A0A 6 Bytes [75, 08, E8, 1E, A1, FD]
.text KernelBase.dll!CreateRemoteThread + 21 75591A11 146 Bytes [5D, C2, 1C, 00, 90, 90, 90, ...]
.text KernelBase.dll!HeapSummary + 39 75591AA4 27 Bytes [8B, 45, 08, 83, 4D, D4, FF, ...]
.text KernelBase.dll!HeapSummary + 55 75591AC0 24 Bytes [00, 00, C7, 45, E0, 1A, 1A, ...]
.text KernelBase.dll!HeapSummary + 6E 75591AD9 3 Bytes CALL 75566A7F \Windows\System32\KernelBase.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text KernelBase.dll!HeapSummary + 72 75591ADD 23 Bytes [EB, A7, 33, C0, 40, 5E, C9, ...]
.text KernelBase.dll!HeapQueryInformation + 9 75591AF5 56 Bytes [75, 14, FF, 75, 10, FF, 75, ...]
.text KernelBase.dll!FindNextVolumeW + E 75591B2E 11 Bytes [33, F6, 33, DB, 89, 75, FC, ...]
.text KernelBase.dll!FindNextVolumeW + 1A 75591B3A 17 Bytes [04, 02, 00, 00, 8D, 4F, 08, ...]
.text KernelBase.dll!FindNextVolumeW + 2D 75591B4D 61 Bytes [00, 66, 8B, 51, 04, 03, C7, ...]
.text KernelBase.dll!FindNextVolumeW + 6B 75591B8B 113 Bytes [6E, 66, 83, 78, 04, 3F, 75, ...]
.text KernelBase.dll!FindNextVolumeW + DD 75591BFD 18 Bytes [46, 83, C1, 18, 89, 75, FC, ...]
.text ...
.text KernelBase.dll!FindFirstVolumeW + 7A 75591E25 49 Bytes CALL 755683DE \Windows\System32\KernelBase.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text KernelBase.dll!FindFirstVolumeW + AC 75591E57 1 Byte [D3]
.text KernelBase.dll!FindFirstVolumeW + AC 75591E57 5 Bytes [D3, E8, 8C, 49, FD] {SHR EAX, CL; MOV WORD [ECX-0x3], CS}
.text KernelBase.dll!FindFirstVolumeW + B2 75591E5D 5 Bytes [64, 8B, 0D, 18, 00]
.text KernelBase.dll!FindFirstVolumeW + B9 75591E64 13 Bytes [FF, 75, F8, 8B, 40, 2C, 50, ...] {PUSH DWORD [EBP-0x8]; MOV EAX, [EAX+0x2c]; PUSH EAX; MOV EAX, [ECX+0x30]; PUSH DWORD [EAX+0x18]}
.text ...
.text KernelBase.dll!FindVolumeClose + 6 75591EF7 33 Bytes [75, 08, 64, A1, 18, 00, 00, ...]
.text KernelBase.dll!FindVolumeClose + 28 75591F19 71 Bytes [8B, FF, 55, 8B, EC, 81, EC, ...]
.text KernelBase.dll!FindVolumeClose + 70 75591F61 6 Bytes [B7, 85, EC, FD, FF, FF]
.text KernelBase.dll!FindVolumeClose + 77 75591F68 3 Bytes [8D, F0, FD]
.text KernelBase.dll!FindVolumeClose + 7B 75591F6C 27 Bytes CALL 739A63FE
.text ...
.text KernelBase.dll!NotifyMountMgr + 2C 755924B5 55 Bytes [15, 98, 10, 56, 75, B8, FE, ...]
.text KernelBase.dll!NotifyMountMgr + 64 755924ED 24 Bytes [15, 20, 10, 56, 75, 8B, F0, ...]
.text KernelBase.dll!NotifyMountMgr + 7D 75592506 10 Bytes [70, 18, FF, 15, 14, 10, 56, ...]
.text KernelBase.dll!NotifyMountMgr + 89 75592512 49 Bytes [00, 6A, 08, 58, 66, 89, 06, ...]
.text KernelBase.dll!NotifyMountMgr + BB 75592544 75 Bytes [0F, B7, 46, 06, 50, 0F, B7, ...]
.text ...
.text KernelBase.dll!DeleteVolumeMountPointW + 2A 755927C9 80 Bytes [85, C0, 7D, 08, 50, E8, AB, ...]
.text KernelBase.dll!DeleteVolumeMountPointW + 7B 7559281A 16 Bytes [8B, 45, F4, 66, 83, 78, 02, ...]
.text KernelBase.dll!DeleteVolumeMountPointW + 8C 7559282B 24 Bytes [FF, 57, 68, 80, 00, 00, 00, ...]
.text KernelBase.dll!DeleteVolumeMountPointW + A5 75592844 6 Bytes [A8, 72, FD, FF, 3B, C7]
.text KernelBase.dll!DeleteVolumeMountPointW + AC 7559284B 38 Bytes [84, 59, 02, 00, 00, 50, E8, ...]
.text ...
.text KernelBase.dll!GetVolumePathNameW + 15 75593198 31 Bytes [5D, C2, 0C, 00, 90, 90, 90, ...]
.text KernelBase.dll!GetVolumePathNameW + 35 755931B8 55 Bytes [30, 6A, 00, FF, 70, 18, FF, ...]
.text KernelBase.dll!GetVolumePathNameW + 6D 755931F0 93 Bytes [F8, 8D, 7D, FA, AB, 66, AB, ...]
.text KernelBase.dll!GetVolumePathNameW + CB 7559324E 125 Bytes [FF, 00, 00, 66, 89, 4D, FA, ...]
.text KernelBase.dll!GetComputerNameExA + 2E 755932CC 61 Bytes [FF, FF, 40, 00, 00, 00, 85, ...]
.text KernelBase.dll!GetComputerNameExA + 6C 7559330A 8 Bytes [3B, C7, 0F, 85, 94, 00, 00, ...] {CMP EAX, EDI; JNZ 0x9c}
.text KernelBase.dll!GetComputerNameExA + 75 75593313 3 Bytes CALL 755667EA \Windows\System32\KernelBase.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text KernelBase.dll!GetComputerNameExA + 79 75593317 20 Bytes [64, 8B, 0D, 18, 00, 00, 00, ...]
.text KernelBase.dll!GetComputerNameExA + 8E 7559332C 25 Bytes [41, 30, FF, 70, 18, FF, 15, ...]
.text ...
.text KernelBase.dll!FindFirstChangeNotificationA + F 75593428 3 Bytes CALL 75566CF0 \Windows\System32\KernelBase.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text KernelBase.dll!FindFirstChangeNotificationA + 13 7559342C 16 Bytes [85, C0, 75, 05, 83, C8, FF, ...] {TEST EAX, EAX; JNZ 0x9; OR EAX, -0x1; JMP 0x27; PUSH ESI; PUSH DWORD [EBP+0x10]; PUSH DWORD [EBP+0xc]}
.text KernelBase.dll!FindFirstChangeNotificationA + 24 7559343D 67 Bytes CALL 7557923B \Windows\System32\KernelBase.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text KernelBase.dll!FindFirstFileExA + 27 75593483 35 Bytes CALL 75566CEE \Windows\System32\KernelBase.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text KernelBase.dll!FindFirstFileExA + 4B 755934A7 42 Bytes [B5, 94, FD, FF, FF, E8, 61, ...]
.text KernelBase.dll!FindFirstFileExA + 76 755934D2 54 Bytes [00, 53, 6A, 2C, 8D, 85, AC, ...]
.text KernelBase.dll!FindFirstFileExA + AE 7559350A 1 Byte [66]
.text KernelBase.dll!FindFirstFileExA + AE 7559350A 23 Bytes [66, 89, 85, A2, FD, FF, FF, ...]
.text ...
.text KernelBase.dll!GetShortPathNameW + 41 75593792 5 Bytes [00, 68, 01, 80, 00]
.text KernelBase.dll!GetShortPathNameW + 47 75593798 14 Bytes CALL 755675CD \Windows\System32\KernelBase.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text KernelBase.dll!GetShortPathNameW + 56 755937A7 14 Bytes CALL 7556BFCA \Windows\System32\KernelBase.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text KernelBase.dll!GetShortPathNameW + 65 755937B6 9 Bytes [00, 39, 78, 30, 74, 18, 64, ...]
.text KernelBase.dll!GetShortPathNameW + 6F 755937C0 1 Byte [00]
.text ...
.text KernelBase.dll!GetLongPathNameA + A 75593BAB 44 Bytes CALL 75567B4F \Windows\System32\KernelBase.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text KernelBase.dll!GetLongPathNameA + 37 75593BD8 31 Bytes [9D, C8, FD, FF, FF, 89, 9D, ...]
.text KernelBase.dll!GetLongPathNameA + 58 75593BF9 67 Bytes [85, C0, 0F, 84, 13, 01, 00, ...]
.text KernelBase.dll!GetLongPathNameA + 9D 75593C3E 19 Bytes [00, 8B, B5, B8, FD, FF, FF, ...] {ADD [EBX-0x2474b], CL; DEC DWORD [EBP-0x74aec9f4]; LEA EDI, [EBP+EDI*8-0x3e7e0001]}
.text KernelBase.dll!GetLongPathNameA + B2 75593C53 58 Bytes [20, 00, 51, 8B, 40, 30, FF, ...]
.text ...
.text KernelBase.dll!CreateFileA + 37 75593DE8 184 Bytes [8B, F0, 8D, 45, F8, 50, FF, ...]
.text KernelBase.dll!AccessCheckByTypeAndAuditAlarmW + 33 75593EA1 154 Bytes [45, 08, 50, FF, 75, 3C, 8D, ...]
.text KernelBase.dll!AccessCheckByTypeResultListAndAuditAlarmW + 23 75593F3C 181 Bytes [50, FF, D6, FF, 75, 14, 8D, ...]
.text KernelBase.dll!AccessCheckByTypeResultListAndAuditAlarmByHandleW + 27 75593FF2 46 Bytes [75, 18, 8D, 45, F4, 50, FF, ...]
.text KernelBase.dll!AccessCheckByTypeResultListAndAuditAlarmByHandleW + 57 75594022 91 Bytes [1C, 50, 8D, 45, EC, 50, FF, ...]
.text KernelBase.dll!ObjectPrivilegeAuditAlarmW 75594080 14 Bytes [8B, FF, 55, 8B, EC, 51, 51, ...] {MOV EDI, EDI; PUSH EBP; MOV EBP, ESP; PUSH ECX; PUSH ECX; PUSH DWORD [EBP+0x8]; LEA EAX, [EBP-0x8]; PUSH EAX}
.text KernelBase.dll!ObjectPrivilegeAuditAlarmW + F 7559408F 50 Bytes [15, 98, 10, 56, 75, FF, 75, ...]
.text KernelBase.dll!ObjectPrivilegeAuditAlarmW + 42 755940C2 34 Bytes [90, 90, 90, 90, 90, 8B, FF, ...]
.text KernelBase.dll!ObjectDeleteAuditAlarmW + 1E 755940E5 105 Bytes [FF, 15, 74, 14, 56, 75, 85, ...]
.text KernelBase.dll!SetAclInformation + 2E 75594150 3 Bytes [90, 90, 90] {NOP ; NOP ; NOP }
.text KernelBase.dll!AddAccessDeniedAceEx + 1 75594154 31 Bytes [FF, 55, 8B, EC, FF, 75, 18, ...]
.text KernelBase.dll!AddAccessDeniedAceEx + 21 75594174 22 Bytes [00, C0, 75, 0D, 68, EC, 03, ...]
.text KernelBase.dll!AddAccessDeniedAceEx + 38 7559418B 77 Bytes [33, C0, EB, 03, 33, C0, 40, ...]
.text KernelBase.dll!AddAuditAccessAceEx + 3E 755941D9 36 Bytes [33, C0, EB, 03, 33, C0, 40, ...]
.text KernelBase.dll!AddAccessAllowedObjectAce + 15 755941FE 8 Bytes [75, 0C, FF, 75, 08, FF, 15, ...]
.text KernelBase.dll!AddAccessAllowedObjectAce + 1E 75594207 48 Bytes [56, 75, 85, C0, 7D, 1E, 3D, ...]
.text KernelBase.dll!AddAccessDeniedObjectAce + 1 75594238 133 Bytes [FF, 55, 8B, EC, FF, 75, 20, ...]
.text KernelBase.dll!AddAuditAccessObjectAce + 39 755942BE 28 Bytes [10, 56, 75, EB, 06, 50, E8, ...]
.text KernelBase.dll!FindFirstFreeAce + 2 755942DB 54 Bytes [55, 8B, EC, FF, 75, 0C, FF, ...]
.text KernelBase.dll!ConvertToAutoInheritPrivateObjectSecurity + 9 75594312 3 Bytes [75, 18, FF]
.text KernelBase.dll!ConvertToAutoInheritPrivateObjectSecurity + D 75594316 16 Bytes [14, FF, 75, 10, FF, 75, 0C, ...] {ADC AL, 0xff; JNZ 0x14; PUSH DWORD [EBP+0xc]; PUSH DWORD [EBP+0x8]; CALL [0x75561518]}
.text KernelBase.dll!ConvertToAutoInheritPrivateObjectSecurity + 1F 75594328 18 Bytes CALL 75566A7B \Windows\System32\KernelBase.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text KernelBase.dll!ConvertToAutoInheritPrivateObjectSecurity + 32 7559433B 19 Bytes [90, 90, 90, 90, 90, 8B, FF, ...] {NOP ; NOP ; NOP ; NOP ; NOP ; MOV EDI, EDI; PUSH EBP; MOV EBP, ESP; PUSH DWORD [EBP+0x28]; PUSH DWORD [EBP+0x24]; PUSH DWORD [EBP+0x20]}
.text KernelBase.dll!CreatePrivateObjectSecurityWithMultipleInheritance + F 7559434F 14 Bytes [75, 1C, FF, 75, 18, FF, 75, ...] {JNZ 0x1e; PUSH DWORD [EBP+0x18]; PUSH DWORD [EBP+0x14]; PUSH DWORD [EBP+0x10]; PUSH DWORD [EBP+0xc]}
.text KernelBase.dll!CreatePrivateObjectSecurityWithMultipleInheritance + 1E 7559435E 10 Bytes [75, 08, FF, 15, 20, 15, 56, ...] {JNZ 0xa; CALL [0x75561520]; TEST EAX, EAX}
.text KernelBase.dll!CreatePrivateObjectSecurityWithMultipleInheritance + 29 75594369 21 Bytes CALL 75566A7C \Windows\System32\KernelBase.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text KernelBase.dll!CreatePrivateObjectSecurityWithMultipleInheritance + 3F 7559437F 21 Bytes [90, 8B, FF, 55, 8B, EC, FF, ...]
.text KernelBase.dll!SetPrivateObjectSecurity + 16 75594396 2 Bytes [24, 15] {AND AL, 0x15}
.text KernelBase.dll!SetPrivateObjectSecurity + 1C 7559439C 39 Bytes CALL 75566A7B \Windows\System32\KernelBase.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text KernelBase.dll!SetPrivateObjectSecurityEx + 10 755943C4 4 Bytes [10, FF, 75, 0C] {ADC BH, BH; JNZ 0x10}
.text KernelBase.dll!SetPrivateObjectSecurityEx + 15 755943C9 34 Bytes [75, 08, FF, 15, 28, 15, 56, ...]
.text KernelBase.dll!GetPrivateObjectSecurity + 1 755943EC 10 Bytes [FF, 55, 8B, EC, FF, 75, 18, ...] {CALL [EBP-0x75]; IN AL, DX ; PUSH DWORD [EBP+0x18]; PUSH DWORD [EBP+0x14]}
.text KernelBase.dll!GetPrivateObjectSecurity + C 755943F7 83 Bytes [75, 10, FF, 75, 0C, FF, 75, ...]
.text KernelBase.dll!GetSecurityDescriptorRMControl + 1 7559444B 52 Bytes [FF, 55, 8B, EC, FF, 75, 0C, ...]
.text KernelBase.dll!SetSecurityDescriptorRMControl + 11 75594480 48 Bytes [33, C0, 5D, C2, 08, 00, 90, ...]
.text KernelBase.dll!SetSecurityDescriptorRMControl + 42 755944B1 205 Bytes [55, 8B, EC, 51, 51, A3, 60, ...]
.text KernelBase.dll!SetSecurityDescriptorRMControl + 110 7559457F 2 Bytes [02, F3] {ADD DH, BL}
.text KernelBase.dll!SetSecurityDescriptorRMControl + 113 75594582 6 Bytes [8B, 0D, 24, 03, FE, 7F] {MOV ECX, [0x7ffe0324]}
.text KernelBase.dll!SetSecurityDescriptorRMControl + 11A 75594589 27 Bytes [15, 20, 03, FE, 7F, A1, 28, ...]
.text ...
.text KernelBase.dll!CheckGroupPolicyEnabled + 23 75595142 11 Bytes [FF, BF, 19, 00, 02, 00, 57, ...]
.text KernelBase.dll!CheckGroupPolicyEnabled + 2F 7559514E 11 Bytes [FF, BE, 68, 07, 59, 75, 56, ...]
.text KernelBase.dll!CheckGroupPolicyEnabled + 3B 7559515A 1 Byte [FF]
.text KernelBase.dll!CheckGroupPolicyEnabled + 3B 7559515A 10 Bytes [FF, 68, 40, 07, 59, 75, 8D, ...] {JMP FAR DWORD [EAX+0x40]; POP ES; POP ECX; JNZ 0xffffffffffffff94; TEST ESP, ESP; STD }
.text KernelBase.dll!CheckGroupPolicyEnabled + 47 75595166 11 Bytes [50, 89, 9D, E4, FD, FF, FF, ...]
.text ...
.text KernelBase.dll!FindStringOrdinal + 62 7559535B 27 Bytes [0F, 85, A1, 00, 00, 00, 8B, ...]
.text KernelBase.dll!FindStringOrdinal + 7E 75595377 9 Bytes [75, 0A, 8B, 4D, 0C, E8, 08, ...]
.text KernelBase.dll!FindStringOrdinal + 88 75595381 32 Bytes [8B, F0, 83, FB, FF, 75, 0D, ...]
.text KernelBase.dll!FindStringOrdinal + A9 755953A2 6 Bytes [84, F6, 03, 00, 00, 81]
.text KernelBase.dll!FindStringOrdinal + B0 755953A9 43 Bytes [00, 00, 20, 00, 74, 18, 81, ...]
.text ...
.text KernelBase.dll!NlsCheckPolicy + 17 75595B90 59 Bytes [74, 26, 83, C0, 02, 3B, C8, ...]
.text KernelBase.dll!NlsCheckPolicy + 53 75595BCC 4 Bytes [25, EC, 04, 00]
.text KernelBase.dll!NlsCheckPolicy + 58 75595BD1 8 Bytes [5D, C2, 08, 00, 90, 90, 90, ...] {POP EBP; RET 0x8; NOP ; NOP ; NOP ; NOP }
.text KernelBase.dll!GetFallbackDisplayName 75595BDA 41 Bytes [8B, FF, 55, 8B, EC, E8, 83, ...]
.text KernelBase.dll!GetFallbackDisplayName + 2A 75595C04 114 Bytes [00, 00, 8B, 40, 18, 8D, 04, ...]
.text KernelBase.dll!GetFallbackDisplayName + 9D 75595C77 47 Bytes [89, 90, 00, 00, 00, 8B, 40, ...]
.text KernelBase.dll!IsValidLanguageGroup + 1C 75595CA7 57 Bytes [00, A1, C0, 49, 5A, 75, 33, ...]
.text KernelBase.dll!IsValidLanguageGroup + 56 75595CE1 105 Bytes [FF, 50, 6A, 01, 6A, 10, FF, ...]
.text KernelBase.dll!IsValidLanguageGroup + C1 75595D4C 86 Bytes [74, DD, 33, C0, 8B, 4D, FC, ...]
.text KernelBase.dll!IsValidLanguageGroup + 119 75595DA4 28 Bytes [00, 89, 4D, 0C, 8D, 8E, A0, ...]
.text KernelBase.dll!IsValidLanguageGroup + 136 75595DC1 4 Bytes [83, A1, 01, 00]
.text ...
.text KernelBase.dll!GetPtrCalData + 1 75595FA6 70 Bytes [FF, 55, 8B, EC, 83, 7D, 08, ...]
.text KernelBase.dll!GetEraNameCountedString + 10 75595FEE 17 Bytes [85, C0, 74, 2B, 66, 8B, 08, ...] {TEST EAX, EAX; JZ 0x2f; MOV CX, [EAX]; SUB CX, [EBP+0x10]; INC CX; CMP DWORD [EBP+0x14], 0x0}
.text KernelBase.dll!GetEraNameCountedString + 23 75596001 156 Bytes [C9, 0F, B7, C9, 8B, 04, 88, ...]
.text KernelBase.dll!GetEraNameCountedString + C0 7559609E 58 Bytes [68, 00, 2D, 00, 54, 00, 57, ...]
.text KernelBase.dll!GetEraNameCountedString + FB 755960D9 14 Bytes CALL 75583231 \Windows\System32\KernelBase.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text KernelBase.dll!GetEraNameCountedString + 10A 755960E8 59 Bytes [15, 38, 10, 56, 75, 85, F6, ...]
.text ...
.text KernelBase.dll!SetCalendarInfoW + 2 755963A6 31 Bytes [55, 8B, EC, 81, EC, 80, 02, ...]
.text KernelBase.dll!SetCalendarInfoW + 23 755963C7 3 Bytes CALL 75566E05 \Windows\System32\KernelBase.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text KernelBase.dll!SetCalendarInfoW + 27 755963CB 57 Bytes [89, 85, EC, FD, FF, FF, 3B, ...]
.text KernelBase.dll!SetCalendarInfoW + 61 75596405 23 Bytes [FF, FF, BF, 83, 7D, 10, 30, ...]
.text KernelBase.dll!SetCalendarInfoW + 79 7559641D 34 Bytes [85, F0, FD, FF, FF, 83, F8, ...]
.text ...
.text KernelBase.dll!SetLocaleInfoW 7559657D 10 Bytes [8B, FF, 55, 8B, EC, 81, EC, ...]
.text KernelBase.dll!SetLocaleInfoW + B 75596588 51 Bytes [A1, C0, 49, 5A, 75, 33, C5, ...]
.text KernelBase.dll!SetLocaleInfoW + 3F 755965BC 7 Bytes [00, 3B, DE, 0F, 84, B1, 01]
.text KernelBase.dll!SetLocaleInfoW + 47 755965C4 39 Bytes [00, 6A, 01, 68, B0, 67, 59, ...]
.text KernelBase.dll!SetLocaleInfoW + 6F 755965EC 1 Byte [68]
.text ...
.text KernelBase.dll!NlsUpdateSystemLocale + 1C 75596AD0 99 Bytes [83, 7D, 0C, 01, 74, 07, B8, ...]
.text KernelBase.dll!NlsUpdateSystemLocale + 80 75596B34 52 Bytes [24, FF, 75, 08, 57, FF, 15, ...]
.text KernelBase.dll!NlsUpdateLocale + 2 75596B69 49 Bytes [55, 8B, EC, 81, EC, 68, 02, ...]
.text KernelBase.dll!NlsUpdateLocale + 35 75596B9C 44 Bytes [74, 0A, B8, 58, 05, 00, 00, ...]
.text KernelBase.dll!NlsUpdateLocale + 63 75596BCA 37 Bytes [F6, 45, 0C, 01, 0F, 84, DF, ...]
.text KernelBase.dll!NlsUpdateLocale + 89 75596BF0 50 Bytes [FF, 85, C0, 74, 3D, 53, 89, ...]
.text KernelBase.dll!NlsUpdateLocale + BC 75596C23 14 Bytes CALL 7559EC57 \Windows\System32\KernelBase.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text ...
.text KernelBase.dll!NlsDispatchAnsiEnumProc + 1 75597033 48 Bytes [FF, 55, 8B, EC, 83, EC, 0C, ...]
.text KernelBase.dll!NlsDispatchAnsiEnumProc + 32 75597064 101 Bytes CALL 75596F3E \Windows\System32\KernelBase.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text KernelBase.dll!NlsDispatchAnsiEnumProc + 98 755970CA 15 Bytes [75, F4, 57, FF, 75, 1C, FF, ...] {JNZ 0xfffffffffffffff6; PUSH EDI; PUSH DWORD [EBP+0x1c]; CALL [EBP+0xc]; JMP 0x23; PUSH DWORD [EBP+0x24]; PUSH EDI}
.text KernelBase.dll!NlsDispatchAnsiEnumProc + A8 755970DA 16 Bytes [75, 20, FF, 75, 1C, FF, 55, ...] {JNZ 0x22; PUSH DWORD [EBP+0x1c]; CALL [EBP+0xc]; JMP 0x13; PUSH DWORD [EBP+0x1c]; JMP 0xffffffffffffffe3; PUSH EDI}
.text KernelBase.dll!NlsDispatchAnsiEnumProc + B9 755970EB 29 Bytes [55, 0C, 89, 45, FC, 8B, 35, ...]
.text ...
.text KernelBase.dll!Internal_EnumLanguageGroupLocales + 27 75597157 52 Bytes [86, 02, 00, 00, 6A, 02, 5E, ...]
.text KernelBase.dll!Internal_EnumLanguageGroupLocales + 5C 7559718C 4 Bytes CALL 75574D43 \Windows\System32\KernelBase.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text KernelBase.dll!Internal_EnumLanguageGroupLocales + 61 75597191 72 Bytes [85, C0, 0F, 84, 4F, 02, 00, ...]
.text KernelBase.dll!Internal_EnumLanguageGroupLocales + AA 755971DA 4 Bytes [83, C4, 0C, 8D]
.text KernelBase.dll!Internal_EnumLanguageGroupLocales + AF 755971DF 2 Bytes [B4, FD] {MOV AH, 0xfd}