Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Contents of cdr4_2K.sys: 58000 bytes
- Import Table size: 0000003c
- offset 0000d2e0 ntoskrnl.exe
- Hint/Name Table: 0000D32C
- TimeDateStamp: 00000000 (Thu Jan 1 01:00:00 1970)
- ForwarderChain: 00000000
- First thunk RVA: 0000CC90
- Ordn Name
- 58 ExAllocatePoolWithTag d474
- 404 IofCallDriver d48c
- 267 IoBuildDeviceIoControlRequest d49c
- 450 KeInitializeEvent d4bc
- 71 ExFreePool d466
- 293 IoDeleteDevice d4d0
- 265 IoAttachDeviceToDeviceStack d4e2
- 1181 memset d500
- 283 IoCreateDevice d50a
- 560 MmAllocateContiguousMemory d51c
- 487 KeReleaseMutex d53a
- 405 IofCompleteRequest d54c
- 1179 memcpy d562
- 505 KeSetEvent d56c
- 296 IoDetachDevice d57a
- 571 MmFreeContiguousMemory d58c
- 704 PoCallDriver d5a6
- 714 PoStartNextPowerIrp d5b6
- 822 RtlEqualString d5cc
- 698 ObfDereferenceObject d5de
- 317 IoGetDeviceObjectPointer d5f6
- 957 RtlUnicodeStringToAnsiString d612
- 868 RtlInitUnicodeString d632
- 316 IoGetDeviceInterfaces d64a
- 746 PsTerminateSystemThread d41c
- 721 PsCreateSystemThread d44e
- 289 IoCreateSymbolicLink d686
- 453 KeInitializeMutex d69e
- 456 KeInitializeSpinLock d6b2
- 778 RtlCompareMemory d6ca
- 1048 ZwClose d6de
- 1106 ZwQueryValueKey d6e8
- 1081 ZwOpenKey d6fa
- 591 MmMapLockedPagesSpecifyCache d706
- 259 IoAllocateIrp d726
- 306 IoFreeIrp d736
- 387 IoStopTimer d742
- 983 RtlWriteRegistryValue d750
- 781 RtlCompareUnicodeString d768
- 848 RtlFreeUnicodeString d782
- 762 RtlAnsiStringToUnicodeString d79a
- 865 RtlInitAnsiString d7ba
- 1184 sprintf d7ce
- 775 RtlCheckRegistryKey d7d8
- 1065 ZwEnumerateKey d7ee
- 248 InterlockedExchange d800
- 916 RtlQueryRegistryValues d816
- 791 RtlCopyUnicodeString d830
- 266 IoBuildAsynchronousFsdRequest d848
- 1190 strlen d868
- 530 KeWaitForSingleObject d436
- 385 IoStartTimer d662
- 581 MmIsAddressValid d408
- 332 IoInitializeTimer d672
- offset 0000d2f4 HAL.dll
- Hint/Name Table: 0000D31C
- TimeDateStamp: 00000000 (Thu Jan 1 01:00:00 1970)
- ForwarderChain: 00000000
- First thunk RVA: 0000CC80
- Ordn Name
- 68 KeGetCurrentIrql d8a8
- 79 KfAcquireSpinLock d894
- 82 KfReleaseSpinLock d880
- Contents of cdralw2k.sys: 23420 bytes
- Import Table size: 0000003c
- offset 00004520 ntoskrnl.exe
- Hint/Name Table: 00004568
- TimeDateStamp: 00000000 (Thu Jan 1 01:00:00 1970)
- ForwarderChain: 00000000
- First thunk RVA: 000041CC
- Ordn Name
- 81 ExInitializeZone 46c6
- 450 KeInitializeEvent 46f2
- 456 KeInitializeSpinLock 4706
- 80 ExInitializeResourceLite 471e
- 283 IoCreateDevice 473a
- 868 RtlInitUnicodeString 474c
- 405 IofCompleteRequest 4764
- 331 IoInitializeRemoveLockEx 477a
- 265 IoAttachDeviceToDeviceStack 4796
- 71 ExFreePool 47b4
- 791 RtlCopyUnicodeString 47c2
- 916 RtlQueryRegistryValues 47da
- 1180 memmove 47f4
- 1144 _aullshr 47fe
- 530 KeWaitForSingleObject 480a
- 404 IofCallDriver 4822
- 267 IoBuildDeviceIoControlRequest 4832
- 957 RtlUnicodeStringToAnsiString 4852
- 1048 ZwClose 4872
- 1106 ZwQueryValueKey 487c
- 848 RtlFreeUnicodeString 488e
- 1081 ZwOpenKey 48a6
- 762 RtlAnsiStringToUnicodeString 48b2
- 865 RtlInitAnsiString 48d2
- 1184 sprintf 48e6
- 361 IoReleaseCancelSpinLock 48f0
- 248 InterlockedExchange 490a
- 251 IoAcquireCancelSpinLock 4920
- 505 KeSetEvent 493a
- 1038 WRITE_REGISTER_UCHAR 4948
- 581 MmIsAddressValid 4960
- 50 ExAcquireResourceExclusiveLite 4974
- 114 ExReleaseResourceForThreadLite 4996
- 434 KeGetCurrentThread 49b8
- 306 IoFreeIrp 49ce
- 289 IoCreateSymbolicLink 46ae
- 58 ExAllocatePoolWithTag 46da
- 266 IoBuildAsynchronousFsdRequest 4a00
- 307 IoFreeMdl 4a20
- 518 KeSetTimer 4a2c
- 564 MmBuildMdlForNonPagedPool 4a3a
- 260 IoAllocateMdl 4a56
- 259 IoAllocateIrp 4a66
- 475 KeQuerySystemTime 4a76
- 571 MmFreeContiguousMemory 4a8a
- 126 ExfInterlockedInsertTailList 4aa4
- 591 MmMapLockedPagesSpecifyCache 4ac4
- 560 MmAllocateContiguousMemory 4ae4
- 295 IoDeleteSymbolicLink 4b02
- 62 ExDeleteNPagedLookasideList 4b1a
- 65 ExDeleteResourceLite 4b38
- 96 ExInterlockedPushEntrySList 4b50
- 127 ExfInterlockedPopEntryList 4b6e
- 128 ExfInterlockedPushEntryList 4b8c
- 1040 WRITE_REGISTER_USHORT 4baa
- 449 KeInitializeDpc 4bc2
- 457 KeInitializeTimer 4bd4
- 599 MmProbeAndLockPages 4be8
- 566 MmCreateMdl 4bfe
- 1146 _except_handler3 4c0c
- 844 RtlFreeAnsiString 4c20
- 1193 strncpy 4c34
- 698 ObfDereferenceObject 4c3e
- 317 IoGetDeviceObjectPointer 4c56
- 316 IoGetDeviceInterfaces 4c72
- 363 IoReleaseRemoveLockEx 4c8a
- 252 IoAcquireRemoveLockEx 4ca2
- 362 IoReleaseRemoveLockAndWaitEx 4cba
- 250 InterlockedIncrement 4cda
- 296 IoDetachDevice 4cf2
- 374 IoSetDeviceInterfaceState 4d04
- 714 PoStartNextPowerIrp 4d20
- 704 PoCallDriver 4d36
- 613 MmUnlockPages 49da
- 293 IoDeleteDevice 469c
- 615 MmUnmapLockedPages 49ea
- offset 00004534 HAL.dll
- Hint/Name Table: 0000455C
- TimeDateStamp: 00000000 (Thu Jan 1 01:00:00 1970)
- ForwarderChain: 00000000
- First thunk RVA: 000041C0
- Ordn Name
- 79 KfAcquireSpinLock 4d68
- 82 KfReleaseSpinLock 4d54
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement