Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- //http://waleedassar.blogspot.com - (@waleedassar)
- #pragma once
- //windows XP SP2/XP SP3 - Not finished yet.
- char* Names[0x10000]=
- {
- /*0x0*/ "ZwAcceptConnectPort",
- /*0x1*/ "ZwAccessCheck",
- /*0x2*/ "ZwAccessCheckAndAuditAlarm",
- /*0x3*/ "ZwAccessCheckByType",
- /*0x4*/ "ZwAccessCheckByTypeAndAuditAlarm",
- /*0x5*/ "ZwAccessCheckByTypeResultList",
- /*0x6*/ "ZwAccessCheckByTypeResultListAndAuditAlarm",
- /*0x7*/ "ZwAccessCheckByTypeResultListAndAuditAlarmByHandle",
- /*0x8*/ "ZwAddAtom",
- /*0x9*/ "ZwAddBootEntry",
- /*0xA*/ "ZwAdjustGroupsToken",
- /*0xB*/ "ZwAdjustPrivilegesToken",
- /*0xC*/ "ZwAlertResumeThread",
- /*0xD*/ "ZwAlertThread",
- /*0xE*/ "ZwAllocateLocallyUniqueId",
- /*0xF*/ "ZwAllocateUserPhysicalPages",
- /*0x10*/ "ZwAllocateUuids",
- /*0x11*/ "ZwAllocateVirtualMemory",
- /*0x12*/ "ZwAreMappedFilesTheSame",
- /*0x13*/ "ZwAssignProcessToJobObject",
- /*0x14*/ "ZwCallbackReturn",
- /*0x15*/ "ZwCancelDeviceWakeupRequest",
- /*0x16*/ "ZwCancelIoFile",
- /*0x17*/ "ZwCancelTimer",
- /*0x18*/ "ZwClearEvent",
- /*0x19*/ "ZwClose",
- /*0x1A*/ "ZwCloseObjectAuditAlarm",
- /*0x1B*/ "ZwCompactKeys",
- /*0x1C*/ "ZwCompareTokens",
- /*0x1D*/ "ZwCompleteConnectPort",
- /*0x1E*/ "ZwCompressKey",
- /*0x1F*/ "ZwConnectPort",
- /*0x20*/ "ZwContinue",
- /*0x21*/ "ZwCreateDebugObject",
- /*0x22*/ "ZwCreateDirectoryObject",
- /*0x23*/ "ZwCreateEvent",
- /*0x24*/ "ZwCreateEventPair",
- /*0x25*/ "ZwCreateFile",
- /*0x26*/ "ZwCreateIoCompletion",
- /*0x27*/ "ZwCreateJobObject",
- /*0x28*/ "ZwCreateJobSet",
- /*0x29*/ "ZwCreateKey",
- /*0x2a*/ "ZwCreateMailslotFile",
- /*0x2B*/ "ZwCreateMutant",
- /*0x2C*/ "ZwCreateNamedPipeFile",
- /*0x2D*/ "ZwCreatePagingFile",
- /*0x2E*/ "ZwCreatePort",
- /*0x2f*/ "ZwCreateProcess",
- /*0x30*/ "ZwCreateProcessEx",
- /*0x31*/ "ZwCreateProfile",
- /*0x32*/ "ZwCreateSection",
- /*0x33*/ "ZwCreateSemaphore",
- /*0x34*/ "ZwCreateSymbolicLinkObject",
- /*0x35*/ "ZwCreateThread",
- /*0x36*/ "ZwCreateTimer",
- /*0x37*/ "ZwCreateToken",
- /*0x38*/ "ZwCreateWaitablePort",
- /*0x39*/ "ZwDebugActiveProcess",
- /*0x3a*/ "ZwDebugContinue",
- /*0x3b*/ "ZwDelayExecution",
- /*0x3c*/ "ZwDeleteAtom",
- /*0x3d*/ "ZwDeleteBootEntry",
- /*0x3e*/ "ZwDeleteFile",
- /*0x3f*/ "ZwDeleteKey",
- /*0x40*/ "ZwDeleteObjectAuditAlarm",
- /*0x41*/ "ZwDeleteValueKey",
- /*0x42*/ "ZwDeviceIoControlFile",
- /*0x43*/ "ZwDisplayString",
- /*0x44*/ "ZwDuplicateObject",
- /*0x45*/ "ZwDuplicateToken",
- /*0x46*/ "ZwEnumerateBootEntries",
- /*0x47*/ "ZwEnumerateKey",
- /*0x48*/ "ZwEnumerateSystemEnvironmentValuesEx",
- /*0x49*/ "ZwEnumerateValueKey",
- /*0x4a*/ "ZwExtendSection",
- /*0x4b*/ "ZwFilterToken",
- /*0x4c*/ "ZwFindAtom",
- /*0x4d*/ "ZwFlushBuffersFile",
- /*0x4e*/ "ZwFlushInstructionCache",
- /*0x4f*/ "ZwFlushKey",
- /*0x50*/ "ZwFlushVirtualMemory",
- /*0x51*/ "ZwFlushWriteBuffer",
- /*0x52*/ "ZwFreeUserPhysicalPages",
- /*0x53*/ "ZwFreeVirtualMemory",
- /*0x54*/ "ZwFsControlFile",
- /*0x55*/ "ZwGetContextThread",
- /*0x56*/ "ZwGetDevicePowerState",
- /*0x57*/ "ZwGetPlugPlayEvent",
- /*0x58*/ "ZwGetWriteWatch",
- /*0x59*/ "ZwImpersonateAnonymousToken",
- /*0x5a*/ "ZwImpersonateClientOfPort",
- /*0x5b*/ "ZwImpersonateThread",
- /*0x5c*/ "ZwInitializeRegistry",
- /*0x5d*/ "ZwInitiatePowerAction",
- /*0x5e*/ "ZwIsProcessInJob",
- /*0x5f*/ "ZwIsSystemResumeAutomatic",
- /*0x60*/ "ZwListenPort",
- /*0x61*/ "ZwLoadDriver",
- /*0x62*/ "ZwLoadKey",
- /*0x63*/ "ZwLoadKey2",
- /*0x64*/ "ZwLockFile",
- /*0x65*/ "ZwLockProductActivationKeys",
- /*0x66*/ "ZwLockRegistryKey",
- /*0x67*/ "ZwLockVirtualMemory",
- /*0x68*/ "ZwMakePermanentObject",
- /*0x69*/ "ZwMakeTemporaryObject",
- /*0x6a*/ "ZwMapUserPhysicalPages",
- /*0x6b*/ "ZwMapUserPhysicalPagesScatter",
- /*0x6c*/ "ZwMapViewOfSection",
- /*0x6d*/ "ZwModifyBootEntry",
- /*0x6e*/ "ZwNotifyChangeDirectoryFile",
- /*0x6f*/ "ZwNotifyChangeKey",
- /*0x70*/ "ZwNotifyChangeMultipleKeys",
- /*0x71*/ "ZwOpenDirectoryObject",
- /*0x72*/ "ZwOpenEvent",
- /*0x73*/ "ZwOpenEventPair",
- /*0x74*/ "ZwOpenFile",
- /*0x75*/ "ZwOpenIoCompletion",
- /*0x76*/ "ZwOpenJobObject",
- /*0x77*/ "ZwOpenKey",
- /*0x78*/ "ZwOpenMutant",
- /*0x79*/ "ZwOpenObjectAuditAlarm",
- /*0x7a*/ "ZwOpenProcess",
- /*0x7b*/ "ZwOpenProcessToken",
- /*0x7c*/ "ZwOpenProcessTokenEx",
- /*0x7d*/ "ZwOpenSection",
- /*0x7e*/ "ZwOpenSemaphore",
- /*0x7f*/ "ZwOpenSymbolicLinkObject",
- /*0x80*/ "ZwOpenThread",
- /*0x81*/ "ZwOpenThreadToken",
- /*0x82*/ "ZwOpenThreadTokenEx",
- /*0x83*/ "ZwOpenTimer",
- /*0x84*/ "ZwPlugPlayControl",
- /*0x85*/ "ZwPowerInformation",
- /*0x86*/ "ZwPrivilegeCheck",
- /*0x87*/ "ZwPrivilegeObjectAuditAlarm",
- /*0x88*/ "ZwPrivilegedServiceAuditAlarm",
- /*0x89*/ "ZwProtectVirtualMemory",
- /*0x8a*/ "ZwPulseEvent",
- /*0x8b*/ "ZwQueryAttributesFile",
- /*0x8C*/ "ZwQueryBootEntryOrder",
- /*0x8D*/ "ZwQueryBootOptions",
- /*0x8e*/ "ZwQueryDebugFilterState",
- /*0x8f*/ "ZwQueryDefaultLocale",
- /*0x90*/ "ZwQueryDefaultUILanguage",
- /*0x91*/ "ZwQueryDirectoryFile",
- /*0x92*/ "ZwQueryDirectoryObject",
- /*0x93*/ "ZwQueryEaFile",
- /*0x94*/ "ZwQueryEvent",
- /*0x95*/ "ZwQueryFullAttributesFile",
- /*0x96*/ "ZwQueryInformationAtom",
- /*0x97*/ "ZwQueryInformationFile",
- /*0x98*/ "ZwQueryInformationJobObject",
- /*0x99*/ "ZwQueryInformationPort",
- /*0x9a*/ "ZwQueryInformationProcess",
- /*0x9b*/ "ZwQueryInformationThread",
- /*0x9c*/ "ZwQueryInformationToken",
- /*0x9d*/ "ZwQueryInstallUILanguage",
- /*0x9e*/ "ZwQueryIntervalProfile",
- /*0x9f*/ "ZwQueryIoCompletion",
- /*0xa0*/ "ZwQueryKey",
- /*0xa1*/ "ZwQueryMultipleValueKey",
- /*0xa2*/ "ZwQueryMutant",
- /*0xa3*/ "ZwQueryObject",
- /*0xa4*/ "ZwQueryOpenSubKeys",
- /*0xa5*/ "ZwQueryPerformanceCounter",
- /*0xa6*/ "ZwQueryQuotaInformationFile",
- /*0xa7*/ "ZwQuerySection",
- /*0xa8*/ "ZwQuerySecurityObject",
- /*0xa9*/ "ZwQuerySemaphore",
- /*0xaa*/ "ZwQuerySymbolicLinkObject",
- /*0xab*/ "ZwQuerySystemEnvironmentValue",
- /*0xac*/ "ZwQuerySystemEnvironmentValueEx",
- /*0xad*/ "ZwQuerySystemInformation",
- /*0xae*/ "ZwQuerySystemTime",
- /*0xaf*/ "ZwQueryTimer",
- /*0xb0*/ "ZwQueryTimerResolution",
- /*0xb1*/ "ZwQueryValueKey",
- /*0xb2*/ "ZwQueryVirtualMemory",
- /*0xb3*/ "ZwQueryVolumeInformationFile",
- /*0xb4*/ "ZwQueueApcThread",
- /*0xb5*/ "ZwRaiseException",
- /*0xb6*/ "ZwRaiseHardError",
- /*0xb7*/ "ZwReadFile",
- /*0xb8*/ "ZwReadFileScatter",
- /*0xb9*/ "ZwReadRequestData",
- /*0xba*/ "ZwReadVirtualMemory",
- /*0xbb*/ "ZwRegisterThreadTerminatePort",
- /*0xbc*/ "ZwReleaseMutant",
- /*0xbd*/ "ZwReleaseSemaphore",
- /*0xbe*/ "ZwRemoveIoCompletion",
- /*0xbf*/ "ZwRemoveProcessDebug",
- /*0xc0*/ "ZwRenameKey",
- /*0xc1*/ "ZwReplaceKey",
- /*0xc2*/ "ZwReplyPort",
- /*0xc3*/ "ZwReplyWaitReceivePort",
- /*0xc4*/ "ZwReplyWaitReceivePortEx",
- /*0xc5*/ "ZwReplyWaitReplyPort",
- /*0xc6*/ "ZwRequestDeviceWakeup",
- /*0xc7*/ "ZwRequestPort",
- /*0xc8*/ "ZwRequestWaitReplyPort",
- /*0xc9*/ "ZwRequestWakeupLatency",
- /*0xca*/ "ZwResetEvent",
- /*0xcb*/ "ZwResetWriteWatch",
- /*0xcc*/ "ZwRestoreKey",
- /*0xcd*/ "ZwResumeProcess",
- /*0xce*/ "ZwResumeThread",
- /*0xcf*/ "ZwSaveKey",
- /*0xd0*/ "ZwSaveKeyEx",
- /*0xd1*/ "ZwSaveMergedKeys",
- /*0xd2*/ "ZwSecureConnectPort",
- /*0xd3*/ "ZwSetBootEntryOrder",
- /*0xd4*/ "ZwSetBootOptions",
- /*0xd5*/ "ZwSetContextThread",
- /*0xd6*/ "ZwSetDebugFilterState",
- /*0xd7*/ "ZwSetDefaultHardErrorPort",
- /*0xd8*/ "ZwSetDefaultLocale",
- /*0xd9*/ "ZwSetDefaultUILanguage",
- /*0xda*/ "ZwSetEaFile",
- /*0xdb*/ "ZwSetEvent",
- /*0xdc*/ "ZwSetEventBoostPriority",
- /*0xdd*/ "ZwSetHighEventPair",
- /*0xde*/ "ZwSetHighWaitLowEventPair",
- /*0xdf*/ "ZwSetInformationDebugObject",
- /*0xe0*/ "ZwSetInformationFile",
- /*0xe1*/ "ZwSetInformationJobObject",
- /*0xe2*/ "ZwSetInformationKey",
- /*0xe3*/ "ZwSetInformationObject",
- /*0xe4*/ "ZwSetInformationProcess",
- /*0xe5*/ "ZwSetInformationThread",
- /*0xe6*/ "ZwSetInformationToken",
- /*0xe7*/ "ZwSetIntervalProfile",
- /*0xe8*/ "ZwSetIoCompletion",
- /*0xe9*/ "ZwSetLdtEntries",
- /*0xea*/ "ZwSetLowEventPair",
- /*0xeb*/ "ZwSetLowWaitHighEventPair",
- /*0xec*/ "ZwSetQuotaInformationFile",
- /*0xed*/ "ZwSetSecurityObject",
- /*0xee*/ "ZwSetSystemEnvironmentValue",
- /*0xef*/ "ZwSetSystemEnvironmentValueEx",
- /*0xf0*/ "ZwSetSystemInformation",
- /*0xf1*/ "ZwSetSystemPowerState",
- /*0xf2*/ "ZwSetSystemTime",
- /*0xf3*/ "ZwSetThreadExecutionState",
- /*0xf4*/ "ZwSetTimer",
- /*0xf5*/ "ZwSetTimerResolution",
- /*0xf6*/ "ZwSetUuidSeed",
- /*0xf7*/ "ZwSetValueKey",
- /*0xf8*/ "ZwSetVolumeInformationFile",
- /*0xf9*/ "ZwShutdownSystem",
- /*0xfa*/ "ZwSignalAndWaitForSingleObject",
- /*0xfb*/ "ZwStartProfile",
- /*0xfc*/ "ZwStopProfile",
- /*0xfd*/ "ZwSuspendProcess",
- /*0xfe*/ "ZwSuspendThread",
- /*0xff*/ "ZwSystemDebugControl",
- /*0x100*/ "ZwTerminateJobObject",
- /*0x101*/ "ZwTerminateProcess",
- /*0x102*/ "ZwTerminateThread",
- /*0x103*/ "ZwTestAlert",
- /*0x104*/ "ZwTraceEvent",
- /*0x105*/ "ZwTranslateFilePath",
- /*0x106*/ "ZwUnloadDriver",
- /*0x107*/ "ZwUnloadKey",
- /*0x108*/ "ZwUnloadKeyEx",
- /*0x109*/ "ZwUnlockFile",
- /*0x10a*/ "ZwUnlockVirtualMemory",
- /*0x10b*/ "ZwUnmapViewOfSection",
- /*0x10c*/ "ZwVdmControl",
- /*0x10d*/ "ZwWaitForDebugEvent",
- /*0x10e*/ "ZwWaitForMultipleObjects",
- /*0x10f*/ "ZwWaitForSingleObject",
- /*0x110*/ "ZwWaitHighEventPair",
- /*0x111*/ "ZwWaitLowEventPair",
- /*0x112*/ "ZwWriteFile",
- /*0x113*/ "ZwWriteFileGather",
- /*0x114*/ "ZwWriteRequestData",
- /*0x115*/ "ZwWriteVirtualMemory",
- /*0x116*/ "ZwYieldExecution",
- /*0x117*/ "ZwCreateKeyedEvent",
- /*0x118*/"ZwOpenKeyedEvent",
- /*0x119*/"ZwReleaseKeyedEvent",
- /*0x11a*/ "ZwWaitForKeyedEvent",
- /*0x11b*/ "ZwQueryPortInformationProcess",
- /*0x11c*/ "UNKNOWN"
- };
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement