Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- kd> uf win32k!NtUserSetProp
- win32k!NtUserSetProp:
- bf8282f4 8bff mov edi,edi
- bf8282f6 55 push ebp
- bf8282f7 8bec mov ebp,esp
- bf8282f9 56 push esi
- bf8282fa e85b88fdff call win32k!EnterCrit (bf800b5a)
- bf8282ff 8b4d08 mov ecx,[ebp+0x8]
- bf828302 e80993fdff call win32k!ValidateHwnd (bf801610)
- bf828307 8bf0 mov esi,eax
- bf828309 85f6 test esi,esi
- bf82830b 7471 jz win32k!NtUserSetProp+0x95 (bf82837e)
- win32k!NtUserSetProp+0x19:
- bf82830d a118ae9abf mov eax,[win32k!gptiCurrent (bf9aae18)]
- bf828312 8b403c mov eax,[eax+0x3c]
- bf828315 8b4004 mov eax,[eax+0x4]
- bf828318 397008 cmp [eax+0x8],esi
- bf82831b 53 push ebx
- bf82831c 57 push edi
- bf82831d 743e jz win32k!NtUserSetProp+0x74 (bf82835d)
- win32k!NtUserSetProp+0x2b:
- bf82831f 8b3d68cb98bf mov edi,[win32k!_imp__PsGetCurrentProcess (bf98cb68)]
- bf828325 ffd7 call edi
- bf828327 8b1d1ccb98bf mov ebx,[win32k!_imp__PsGetProcessWin32Process (bf98cb1c)]
- bf82832d 50 push eax
- bf82832e ffd3 call ebx
- bf828330 8b4e08 mov ecx,[esi+0x8]
- bf828333 8b492c mov ecx,[ecx+0x2c]
- bf828336 8b8060010000 mov eax,[eax+0x160]
- bf82833c 3b8160010000 cmp eax,[ecx+0x160]
- bf828342 7546 jnz win32k!NtUserSetProp+0x69 (bf82838a)
- win32k!NtUserSetProp+0x50:
- bf828344 ffd7 call edi
- bf828346 50 push eax
- bf828347 ffd3 call ebx
- bf828349 8b4e08 mov ecx,[esi+0x8]
- bf82834c 8b492c mov ecx,[ecx+0x2c]
- bf82834f 8b8064010000 mov eax,[eax+0x164]
- bf828355 3b8164010000 cmp eax,[ecx+0x164]
- bf82835b 752d jnz win32k!NtUserSetProp+0x69 (bf82838a)
- win32k!NtUserSetProp+0x69:
- bf82838a 6a05 push 0x5
- bf82838c 33f6 xor esi,esi
- bf82838e e878b4fdff call win32k!UserSetLastError (bf80380b)
- bf828393 ebe7 jmp win32k!NtUserSetProp+0x93 (bf82837c)
- win32k!NtUserSetProp+0x74:
- bf82835d 8b450c mov eax,[ebp+0xc]
- bf828360 c1e810 shr eax,0x10
- bf828363 66f7d8 neg ax
- bf828366 1bc0 sbb eax,eax
- bf828368 83e002 and eax,0x2
- bf82836b 50 push eax
- bf82836c ff7510 push dword ptr [ebp+0x10]
- bf82836f 0fb7450c movzx eax,word ptr [ebp+0xc]
- bf828373 50 push eax
- bf828374 56 push esi
- bf828375 e820000000 call win32k!InternalSetProp (bf82839a)
- bf82837a 8bf0 mov esi,eax
- win32k!NtUserSetProp+0x93:
- bf82837c 5f pop edi
- bf82837d 5b pop ebx
- win32k!NtUserSetProp+0x95:
- bf82837e e80388fdff call win32k!LeaveCrit (bf800b86)
- bf828383 8bc6 mov eax,esi
- bf828385 5e pop esi
- bf828386 5d pop ebp
- bf828387 c20c00 ret 0xc
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement