VISTA64 SP1 SystemServiceTable
NTDLL 에서 추출한,
Vista x64 SP1 의 SystemServiceTable
Windows Server 2008 Kernel Version 6001 (Service Pack 1) MP (2 procs) Free x64 Product: WinNt, suite: TerminalServer SingleUserTS Built by: 6001.18304.amd64fre.vistasp1_gdr.090805-0102 0 ZwMapUserPhysicalPagesScatter 1 ZwWaitForSingleObject 2 ZwCallbackReturn 3 ZwReadFile 4 NtDeviceIoControlFile 5 ZwWriteFile 6 NtRemoveIoCompletion 7 NtReleaseSemaphore 8 NtReplyWaitReceivePort 9 NtReplyPort 0Ah NtSetInformationThread 0Bh ZwSetEvent 0Ch ZwClose 0Dh NtQueryObject 0Eh ZwQueryInformationFile 0Fh ZwOpenKey 10h ZwEnumerateValueKey 11h ZwFindAtom 12h ZwQueryDefaultLocale 13h NtQueryKey 14h NtQueryValueKey 15h NtAllocateVirtualMemory 16h NtQueryInformationProcess 17h ZwWaitForMultipleObjects32 18h NtWriteFileGather 19h ZwSetInformationProcess 1Ah NtCreateKey 1Bh ZwFreeVirtualMemory 1Ch ZwImpersonateClientOfPort 1Dh ZwReleaseMutant 1Eh ZwQueryInformationToken 1Fh ZwRequestWaitReplyPort 20h ZwQueryVirtualMemory 21h ZwOpenThreadToken 22h NtQueryInformationThread 23h ZwOpenProcess 24h NtSetInformationFile 25h ZwMapViewOfSection 26h ZwAccessCheckAndAuditAlarm 27h NtUnmapViewOfSection 28h ZwReplyWaitReceivePortEx 29h ZwTerminateProcess 2Ah NtSetEventBoostPriority 2Bh NtReadFileScatter 2Ch ZwOpenThreadTokenEx 2Dh ZwOpenProcessTokenEx 2Eh ZwQueryPerformanceCounter 2Fh ZwEnumerateKey 30h NtOpenFile 31h ZwDelayExecution 32h NtQueryDirectoryFile 33h ZwQuerySystemInformation 34h NtOpenSection 35h ZwQueryTimer 36h ZwFsControlFile 37h NtWriteVirtualMemory 38h ZwCloseObjectAuditAlarm 39h ZwDuplicateObject 3Ah NtQueryAttributesFile 3Bh NtClearEvent 3Ch ZwReadVirtualMemory 3Dh ZwOpenEvent 3Eh NtAdjustPrivilegesToken 3Fh ZwDuplicateToken 40h NtContinue 41h NtQueryDefaultUILanguage 42h ZwQueueApcThread 43h NtYieldExecution 44h NtAddAtom 45h NtCreateEvent 46h ZwQueryVolumeInformationFile 47h ZwCreateSection 48h ZwFlushBuffersFile 49h ZwApphelpCacheControl 4Ah NtCreateProcessEx 4Bh ZwCreateThread 4Ch ZwIsProcessInJob 4Dh ZwProtectVirtualMemory 4Eh ZwQuerySection 4Fh NtResumeThread 50h NtTerminateThread 51h NtReadRequestData 52h NtCreateFile 53h NtQueryEvent 54h ZwWriteRequestData 55h ZwOpenDirectoryObject 56h ZwAccessCheckByTypeAndAuditAlarm 57h NtQuerySystemTime 58h ZwWaitForMultipleObjects 59h ZwSetInformationObject 5Ah NtCancelIoFile 5Bh ZwTraceEvent 5Ch NtPowerInformation 5Dh NtSetValueKey 5Eh ZwCancelTimer 5Fh NtSetTimer 60h ZwAcceptConnectPort 61h NtAccessCheck 62h ZwAccessCheckByType 63h NtAccessCheckByTypeResultList 64h ZwAccessCheckByTypeResultListAndAuditAlarm 65h NtAccessCheckByTypeResultListAndAuditAlarmByHandle 66h NtAcquireCMFViewOwnership 67h ZwAddBootEntry 68h ZwAddDriverEntry 69h NtAdjustGroupsToken 6Ah ZwAlertResumeThread 6Bh NtAlertThread 6Ch NtAllocateLocallyUniqueId 6Dh NtAllocateUserPhysicalPages 6Eh ZwAllocateUuids 6Fh ZwAlpcAcceptConnectPort 70h ZwAlpcCancelMessage 71h ZwAlpcConnectPort 72h ZwAlpcCreatePort 73h NtAlpcCreatePortSection 74h NtAlpcCreateResourceReserve 75h ZwAlpcCreateSectionView 76h NtAlpcCreateSecurityContext 77h ZwAlpcDeletePortSection 78h ZwAlpcDeleteResourceReserve 79h ZwAlpcDeleteSectionView 7Ah ZwAlpcDeleteSecurityContext 7Bh ZwAlpcDisconnectPort 7Ch ZwAlpcImpersonateClientOfPort 7Dh ZwAlpcOpenSenderProcess 7Eh ZwAlpcOpenSenderThread 7Fh ZwAlpcQueryInformation 80h ZwAlpcQueryInformationMessage 81h ZwAlpcRevokeSecurityContext 82h NtAlpcSendWaitReceivePort 83h ZwAlpcSetInformation 84h ZwAreMappedFilesTheSame 85h ZwAssignProcessToJobObject 86h NtCancelDeviceWakeupRequest 87h ZwCancelIoFileEx 88h ZwCancelSynchronousIoFile 89h NtCommitComplete 8Ah ZwCommitEnlistment 8Bh ZwCommitTransaction 8Ch NtCompactKeys 8Dh ZwCompareTokens 8Eh NtCompleteConnectPort 8Fh ZwCompressKey 90h ZwConnectPort 91h NtCreateDebugObject 92h ZwCreateDirectoryObject 93h NtCreateEnlistment 94h NtCreateEventPair 95h ZwCreateIoCompletion 96h ZwCreateJobObject 97h ZwCreateJobSet 98h ZwCreateKeyTransacted 99h ZwCreateKeyedEvent 9Ah NtCreateMailslotFile 9Bh ZwCreateMutant 9Ch NtCreateNamedPipeFile 9Dh NtCreatePagingFile 9Eh NtCreatePort 9Fh NtCreatePrivateNamespace 0A0h NtCreateProcess 0A1h ZwCreateProfile 0A2h ZwCreateResourceManager 0A3h ZwCreateSemaphore 0A4h ZwCreateSymbolicLinkObject 0A5h NtCreateThreadEx 0A6h ZwCreateTimer 0A7h NtCreateToken 0A8h ZwCreateTransaction 0A9h NtCreateTransactionManager 0AAh NtCreateUserProcess 0ABh ZwCreateWaitablePort 0ACh NtCreateWorkerFactory 0ADh NtDebugActiveProcess 0AEh NtDebugContinue 0AFh ZwDeleteAtom 0B0h ZwDeleteBootEntry 0B1h NtDeleteDriverEntry 0B2h ZwDeleteFile 0B3h NtDeleteKey 0B4h NtDeleteObjectAuditAlarm 0B5h NtDeletePrivateNamespace 0B6h NtDeleteValueKey 0B7h ZwDisplayString 0B8h ZwEnumerateBootEntries 0B9h ZwEnumerateDriverEntries 0BAh NtEnumerateSystemEnvironmentValuesEx 0BBh ZwEnumerateTransactionObject 0BCh ZwExtendSection 0BDh NtFilterToken 0BEh ZwFlushInstallUILanguage 0BFh NtFlushInstructionCache 0C0h NtFlushKey 0C1h ZwFlushProcessWriteBuffers 0C2h ZwFlushVirtualMemory 0C3h NtFlushWriteBuffer 0C4h NtFreeUserPhysicalPages 0C5h ZwFreezeRegistry 0C6h ZwFreezeTransactions 0C7h ZwGetContextThread 0C8h NtGetCurrentProcessorNumber 0C9h NtGetDevicePowerState 0CAh ZwGetMUIRegistryInfo 0CBh ZwGetNextProcess 0CCh NtGetNextThread 0CDh ZwGetNlsSectionPtr 0CEh NtGetNotificationResourceManager 0CFh NtGetPlugPlayEvent 0D0h NtGetWriteWatch 0D1h ZwImpersonateAnonymousToken 0D2h ZwImpersonateThread 0D3h NtInitializeNlsFiles 0D4h ZwInitializeRegistry 0D5h NtInitiatePowerAction 0D6h ZwIsSystemResumeAutomatic 0D7h NtIsUILanguageComitted 0D8h ZwListenPort 0D9h ZwLoadDriver 0DAh ZwLoadKey 0DBh NtLoadKey2 0DCh ZwLoadKeyEx 0DDh NtLockFile 0DEh NtLockProductActivationKeys 0DFh NtLockRegistryKey 0E0h NtLockVirtualMemory 0E1h ZwMakePermanentObject 0E2h NtMakeTemporaryObject 0E3h ZwMapCMFModule 0E4h ZwMapUserPhysicalPages 0E5h ZwModifyBootEntry 0E6h NtModifyDriverEntry 0E7h NtNotifyChangeDirectoryFile 0E8h NtNotifyChangeKey 0E9h ZwNotifyChangeMultipleKeys 0EAh NtOpenEnlistment 0EBh NtOpenEventPair 0ECh ZwOpenIoCompletion 0EDh ZwOpenJobObject 0EEh NtOpenKeyTransacted 0EFh ZwOpenKeyedEvent 0F0h ZwOpenMutant 0F1h ZwOpenObjectAuditAlarm 0F2h ZwOpenPrivateNamespace 0F3h NtOpenProcessToken 0F4h ZwOpenResourceManager 0F5h NtOpenSemaphore 0F6h NtOpenSession 0F7h NtOpenSymbolicLinkObject 0F8h NtOpenThread 0F9h NtOpenTimer 0FAh ZwOpenTransaction 0FBh NtOpenTransactionManager 0FCh NtPlugPlayControl 0FDh NtPrePrepareComplete 0FEh ZwPrePrepareEnlistment 0FFh NtPrepareComplete 100h ZwPrepareEnlistment 101h ZwPrivilegeCheck 102h ZwPrivilegeObjectAuditAlarm 103h ZwPrivilegedServiceAuditAlarm 104h ZwPropagationComplete 105h ZwPropagationFailed 106h ZwPulseEvent 107h NtQueryBootEntryOrder 108h ZwQueryBootOptions 109h NtQueryDebugFilterState 10Ah NtQueryDirectoryObject 10Bh ZwQueryDriverEntryOrder 10Ch ZwQueryEaFile 10Dh NtQueryFullAttributesFile 10Eh NtQueryInformationAtom 10Fh NtQueryInformationEnlistment 110h NtQueryInformationJobObject 111h NtQueryInformationPort 112h NtQueryInformationResourceManager 113h NtQueryInformationTransaction 114h NtQueryInformationTransactionManager 115h NtQueryInformationWorkerFactory 116h ZwQueryInstallUILanguage 117h ZwQueryIntervalProfile 118h NtQueryIoCompletion 119h ZwQueryLicenseValue 11Ah NtQueryMultipleValueKey 11Bh NtQueryMutant 11Ch ZwQueryOpenSubKeys 11Dh ZwQueryOpenSubKeysEx 11Eh ZwQueryPortInformationProcess 11Fh ZwQueryQuotaInformationFile 120h ZwQuerySecurityObject 121h ZwQuerySemaphore 122h NtQuerySymbolicLinkObject 123h ZwQuerySystemEnvironmentValue 124h ZwQuerySystemEnvironmentValueEx 125h NtQueryTimerResolution 126h ZwRaiseException 127h NtRaiseHardError 128h ZwReadOnlyEnlistment 129h ZwRecoverEnlistment 12Ah ZwRecoverResourceManager 12Bh ZwRecoverTransactionManager 12Ch ZwRegisterProtocolAddressInformation 12Dh NtRegisterThreadTerminatePort 12Eh NtReleaseCMFViewOwnership 12Fh NtReleaseKeyedEvent 130h NtReleaseWorkerFactoryWorker 131h NtRemoveIoCompletionEx 132h NtRemoveProcessDebug 133h ZwRenameKey 134h ZwRenameTransactionManager 135h ZwReplaceKey 136h ZwReplacePartitionUnit 137h NtReplyWaitReplyPort 138h ZwRequestDeviceWakeup 139h ZwRequestPort 13Ah NtRequestWakeupLatency 13Bh ZwResetEvent 13Ch NtResetWriteWatch 13Dh NtRestoreKey 13Eh NtResumeProcess 13Fh ZwRollbackComplete 140h NtRollbackEnlistment 141h ZwRollbackTransaction 142h NtRollforwardTransactionManager 143h NtSaveKey 144h ZwSaveKeyEx 145h NtSaveMergedKeys 146h ZwSecureConnectPort 147h NtSetBootEntryOrder 148h ZwSetBootOptions 149h NtSetContextThread 14Ah NtSetDebugFilterState 14Bh NtSetDefaultHardErrorPort 14Ch NtSetDefaultLocale 14Dh ZwSetDefaultUILanguage 14Eh NtSetDriverEntryOrder 14Fh NtSetEaFile 150h ZwSetHighEventPair 151h ZwSetHighWaitLowEventPair 152h ZwSetInformationDebugObject 153h ZwSetInformationEnlistment 154h NtSetInformationJobObject 155h ZwSetInformationKey 156h NtSetInformationResourceManager 157h NtSetInformationToken 158h NtSetInformationTransaction 159h ZwSetInformationTransactionManager 15Ah ZwSetInformationWorkerFactory 15Bh NtSetIntervalProfile 15Ch ZwSetIoCompletion 15Dh ZwSetLdtEntries 15Eh NtSetLowEventPair 15Fh NtSetLowWaitHighEventPair 160h NtSetQuotaInformationFile 161h NtSetSecurityObject 162h ZwSetSystemEnvironmentValue 163h NtSetSystemEnvironmentValueEx 164h ZwSetSystemInformation 165h NtSetSystemPowerState 166h NtSetSystemTime 167h ZwSetThreadExecutionState 168h ZwSetTimerResolution 169h ZwSetUuidSeed 16Ah ZwSetVolumeInformationFile 16Bh ZwShutdownSystem 16Ch ZwShutdownWorkerFactory 16Dh NtSignalAndWaitForSingleObject 16Eh NtSinglePhaseReject 16Fh ZwStartProfile 170h ZwStopProfile 171h NtSuspendProcess 172h ZwSuspendThread 173h NtSystemDebugControl 174h NtTerminateJobObject 175h NtTestAlert 176h NtThawRegistry 177h NtThawTransactions 178h ZwTraceControl 179h ZwTranslateFilePath 17Ah ZwUnloadDriver 17Bh NtUnloadKey 17Ch NtUnloadKey2 17Dh NtUnloadKeyEx 17Eh ZwUnlockFile 17Fh NtUnlockVirtualMemory 180h NtVdmControl 181h NtWaitForDebugEvent 182h ZwWaitForKeyedEvent 183h ZwWaitForWorkViaWorkerFactory 184h ZwWaitHighEventPair 185h NtWaitLowEventPair 186h ZwWorkerFactoryWorkerReady |