Continued GMER scan...........
---------------------------------
.text win32k.sys!EngUnicodeToMultiByteN + A7 BF85A916 26 Bytes [ 45, F0, 8B, 55, F4, 8D, 4C, ... ]
.text win32k.sys!EngUnicodeToMultiByteN + C2 BF85A931 27 Bytes [ EB, 04, 48, C6, 45, 13, 00, ... ]
.text win32k.sys!EngUnicodeToMultiByteN + DE BF85A94D 5 Bytes [ 45, CC, 8D, 44, 17 ]
.text win32k.sys!EngUnicodeToMultiByteN + E4 BF85A953 2 Bytes [ D1, F8 ]
.text win32k.sys!EngAllocMem + 1 BF85B876 2 Bytes [ 1E, 57 ]
.text win32k.sys!EngAllocMem + 4 BF85B879 18 Bytes [ F9, 8B, C8, 2B, CB, C1, F9, ... ]
.text win32k.sys!EngAllocMem + 17 BF85B88C 5 Bytes [ FF, 83, E8, 04, A3 ]
.text win32k.sys!EngAllocMem + 1D BF85B892 48 Bytes [ 8A, 9A, BF, 8B, 00, 8B, C8, ... ]
.text win32k.sys!EngAllocMem + 4E BF85B8C3 4 Bytes [ 00, 5B, C3, 90 ]
.text win32k.sys!EngFreeMem + 3E BF85B90A 145 Bytes [ 9A, BF, 5F, C7, 05, 14, 8B, ... ]
.text win32k.sys!EngFreeMem + D0 BF85B99C 84 Bytes [ 8E, 60, 01, 00, 00, 2B, CA, ... ]
.text win32k.sys!EngFreeMem + 125 BF85B9F1 2 Bytes [ 72, 16 ]
.text win32k.sys!EngFreeMem + 128 BF85B9F4 170 Bytes [ 71, F8, 8D, 51, FC, 8B, 0A, ... ]
.text win32k.sys!EngFreeMem + 1D3 BF85BA9F 129 Bytes [ 7E, D8, A1, 18, 8B, 9A, BF, ... ]
.text win32k.sys!FONTOBJ_pxoGetXform + 1 BF86A902 2 Bytes [ 40, 04 ]
.text win32k.sys!FONTOBJ_pxoGetXform + 4 BF86A905 88 Bytes [ 40, 08, 8B, 4B, 28, 8B, 40, ... ]
.text win32k.sys!FONTOBJ_pxoGetXform + 5D BF86A95E 181 Bytes [ F0, 85, F6, 74, 32, 8B, 43, ... ]
.text win32k.sys!FONTOBJ_pxoGetXform + 113 BF86AA14 12 Bytes JMP BF86ACF9 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!FONTOBJ_pxoGetXform + 121 BF86AA22 12 Bytes JMP BF86AC59 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!STROBJ_vEnumStart + 1 BF86FC39 37 Bytes [ 77, 04, 85, F6, 0F, 84, C5, ... ]
.text win32k.sys!STROBJ_vEnumStart + 27 BF86FC5F 47 Bytes [ 0F, B7, CB, C1, E0, 10, 0B, ... ]
.text win32k.sys!STROBJ_vEnumStart + 57 BF86FC8F 25 Bytes [ 75, 0D, 0F, B7, 47, 08, 50, ... ]
.text win32k.sys!STROBJ_vEnumStart + 71 BF86FCA9 99 Bytes [ 30, F1, 00, 00, 74, 1D, EB, ... ]
.text win32k.sys!STROBJ_vEnumStart + D5 BF86FD0D 148 Bytes [ FF, 83, FE, 1B, 74, C7, 83, ... ]
.text win32k.sys!EngTextOut + 5D BF8703CC 16 Bytes [ FF, A1, EC, B6, 9A, BF, 85, ... ]
.text win32k.sys!EngTextOut + 6E BF8703DD 13 Bytes [ 35, E0, B6, 9A, BF, E8, 89, ... ]
.text win32k.sys!EngTextOut + 7D BF8703EC 74 Bytes [ 3B, 45, EC, 74, E5, E9, 9B, ... ]
.text win32k.sys!EngTextOut + C8 BF870437 24 Bytes [ 89, 3D, CC, B2, 9A, BF, E9, ... ]
.text win32k.sys!EngTextOut + E1 BF870450 2 Bytes [ FE, FF ]
.text win32k.sys!XLATEOBJ_iXlate + 7 BF87174C 37 Bytes [ 48, 0C, 8B, 89, 08, 02, 00, ... ]
.text win32k.sys!XLATEOBJ_iXlate + 2D BF871772 20 Bytes CALL BF86E1E0 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!XLATEOBJ_iXlate + 42 BF871787 14 Bytes CALL BF86E7E6 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!XLATEOBJ_iXlate + 52 BF871797 1 Byte [ 08 ]
.text win32k.sys!XLATEOBJ_iXlate + 54 BF871799 91 Bytes CALL BF86EA99 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngStretchBltROP + 36 BF87407D 80 Bytes [ 8B, 48, 34, 89, 4D, F0, 8B, ... ]
.text win32k.sys!EngStretchBltROP + 87 BF8740CE 97 Bytes [ 24, 0F, 84, 8E, 01, 00, 00, ... ]
.text win32k.sys!EngStretchBltROP + E9 BF874130 26 Bytes [ 89, 45, 10, 83, 7D, 0C, 02, ... ]
.text win32k.sys!EngStretchBltROP + 104 BF87414B 111 Bytes [ 0D, 30, 57, 9A, BF, 89, 4D, ... ]
.text win32k.sys!EngStretchBltROP + 174 BF8741BB 125 Bytes CALL BF873AD6 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngStretchBlt + 2 BF8751E3 1 Byte [ FF ]
.text win32k.sys!EngStretchBlt + 4 BF8751E5 184 Bytes [ 40, 1C, 89, 41, 1C, 8B, 41, ... ]
.text win32k.sys!EngStretchBlt + BE BF87529F 47 Bytes [ 85, C0, 75, 0E, 8B, 4E, 60, ... ]
.text win32k.sys!EngStretchBlt + EE BF8752CF 5 Bytes CALL BF805A0B \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngStretchBlt + F4 BF8752D5 167 Bytes [ C0, A0, FC, F7, 99, BF, 8D, ... ]
.text win32k.sys!EngCreatePalette + 30 BF8794AA 144 Bytes [ 00, 8B, 45, A8, 3B, 45, B0, ... ]
.text win32k.sys!EngCreatePalette + C1 BF87953B 21 Bytes [ FC, A1, 78, B0, 9A, BF, FF, ... ]
.text win32k.sys!EngCreatePalette + D7 BF879551 37 Bytes [ 8D, 45, A8, 50, FF, 75, 20, ... ]
.text win32k.sys!EngCreatePalette + FD BF879577 61 Bytes [ 0F, 84, A6, FC, FF, FF, 8D, ... ]
.text win32k.sys!EngCreatePalette + 13B BF8795B5 42 Bytes JMP BF8793D0 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngCreateSemaphore + A BF87FB43 2 Bytes [ 8D, 55 ]
.text win32k.sys!EngCreateSemaphore + D BF87FB46 132 Bytes [ 89, 51, 28, 89, 45, 94, 0F, ... ]
.text win32k.sys!EngCreateSemaphore + 93 BF87FBCC 77 Bytes [ F6, 43, 19, 02, 0F, 84, 92, ... ]
.text win32k.sys!EngCreateSemaphore + E1 BF87FC1A 32 Bytes [ 39, 7D, E0, 0F, 85, AD, 02, ... ]
.text win32k.sys!EngCreateSemaphore + 102 BF87FC3B 104 Bytes [ C4, 0F, 85, 97, FC, FF, FF, ... ]
.text win32k.sys!EngEraseSurface + 2B BF8830E9 25 Bytes [ 00, 8B, 45, E4, 89, 06, 8B, ... ]
.text win32k.sys!EngEraseSurface + 45 BF883103 228 Bytes [ FF, C2, 10, 00, 89, 39, EB, ... ]
.text win32k.sys!EngEraseSurface + 12A BF8831E8 7 Bytes [ 30, 5F, C9, C2, 08, 00, 56 ]
.text win32k.sys!EngEraseSurface + 132 BF8831F0 12 Bytes CALL BF888FC4 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngEraseSurface + 13F BF8831FD 51 Bytes [ 75, 0C, FF, 76, 04, FF, 36, ... ]
.text win32k.sys!EngCreateDeviceSurface + 6 BF888D5D 25 Bytes [ F7, 8B, 45, 18, 0F, B6, 04, ... ]
.text win32k.sys!EngCreateDeviceSurface + 20 BF888D77 19 Bytes [ 8B, F8, 3B, FB, 74, 26, 56, ... ]
.text win32k.sys!EngCreateDeviceSurface + 34 BF888D8B 91 Bytes CALL BF80645B \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngCreateDeviceSurface + 90 BF888DE7 18 Bytes [ 85, D1, 00, 00, 00, 53, 68, ... ]
.text win32k.sys!EngCreateDeviceSurface + A3 BF888DFA 52 Bytes [ F8, 3B, FB, 0F, 84, F9, 00, ... ]
.text win32k.sys!EngGetCurrentCodePage + CD BF88CBF5 53 Bytes CALL BF82126D \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngGetCurrentCodePage + 103 BF88CC2B 56 Bytes JMP BF88CCE5 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngGetCurrentCodePage + 13C BF88CC64 22 Bytes [ 00, 00, F8, 23, F0, 89, 7D, ... ]
.text win32k.sys!EngGetCurrentCodePage + 153 BF88CC7B 18 Bytes [ 8B, 23, F8, 75, 9A, 6A, 01, ... ]
.text win32k.sys!EngGetCurrentCodePage + 166 BF88CC8E 11 Bytes [ 39, 5D, 90, 75, 65, FF, 75, ... ]
.text win32k.sys!EngFntCacheLookUp + E BF89A51D 160 Bytes [ 46, 28, 89, 7D, F8, FF, 47, ... ]
.text win32k.sys!EngFntCacheLookUp + B0 BF89A5BF 96 Bytes CALL BF8B7891 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngFntCacheLookUp + 111 BF89A620 221 Bytes [ 53, 56, 57, 6A, 01, FF, 35, ... ]
.text win32k.sys!EngFntCacheLookUp + 1EF BF89A6FE 37 Bytes CALL BF80D04D \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngFntCacheLookUp + 216 BF89A725 83 Bytes [ 00, 74, 07, 3D, 0F, 03, 00, ... ]
.text win32k.sys!EngFntCacheAlloc + 65 BF89AA3B 2 Bytes [ 45, 0C ]
.text win32k.sys!EngFntCacheAlloc + 68 BF89AA3E 18 Bytes [ 4D, F4, FF, 53, 56, 8B, 75, ... ]
.text win32k.sys!EngFntCacheAlloc + 7B BF89AA51 30 Bytes [ 3E, 33, C9, 39, 08, 8D, 50, ... ]
.text win32k.sys!EngFntCacheAlloc + 9A BF89AA70 66 Bytes [ FF, 85, C0, 74, 2C, 8B, 4D, ... ]
.text win32k.sys!EngFntCacheAlloc + DD BF89AAB3 36 Bytes [ 45, F4, EB, E3, 90, 90, 90, ... ]
.text win32k.sys!EngWideCharToMultiByte + B BF89C079 20 Bytes [ 15, 00, C8, 98, BF, 5F, 5E, ... ]
.text win32k.sys!EngWideCharToMultiByte + 20 BF89C08E 92 Bytes JMP 805BE874 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
.text win32k.sys!EngWideCharToMultiByte + 7D BF89C0EB 61 Bytes [ 00, 00, 8B, 46, 3C, 85, C0, ... ]
.text win32k.sys!EngWideCharToMultiByte + BB BF89C129 11 Bytes [ 00, 00, 00, 85, C0, 74, 07, ... ]
.text win32k.sys!EngWideCharToMultiByte + C7 BF89C135 82 Bytes CALL BF8011C9 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngMultiByteToUnicodeN + 24 BF89E07E 16 Bytes JMP 470DEF95
.text win32k.sys!EngMultiByteToUnicodeN + 36 BF89E090 69 Bytes [ 00, 49, 49, 0F, 84, ED, 00, ... ]
.text win32k.sys!EngMultiByteToUnicodeN + 7D BF89E0D7 95 Bytes JMP BF89E055 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngMultiByteToUnicodeN + DE BF89E138 93 Bytes JMP BF89E054 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngMultiByteToUnicodeN + 13C BF89E196 72 Bytes [ 81, F9, 00, 00, 00, 80, 0F, ... ]
.text win32k.sys!EngFindImageProcAddress + 15 BF8A1CBE 25 Bytes [ 03, 8B, 4B, 08, 56, 2B, C8, ... ]
.text win32k.sys!EngFindImageProcAddress + 2F BF8A1CD8 31 Bytes [ 8B, C1, 2B, 45, 0C, FF, 35, ... ]
.text win32k.sys!EngFindImageProcAddress + 4F BF8A1CF8 11 Bytes [ C7, 2B, 45, 0C, 99, 2B, C2, ... ]
.text win32k.sys!EngFindImageProcAddress + 5B BF8A1D04 65 Bytes [ 7B, 04, 8B, 5D, 08, 53, E8, ... ]
.text win32k.sys!EngFindImageProcAddress + 9D BF8A1D46 75 Bytes [ 0C, 50, 57, 56, 53, E8, E8, ... ]
.text win32k.sys!EngLoadImage + 6 BF8A1E25 60 Bytes [ 81, E0, 07, 00, 00, F6, C6, ... ]
.text win32k.sys!EngLoadImage + 43 BF8A1E62 132 Bytes [ 56, 04, 2B, FA, 3B, C7, 89, ... ]
.text win32k.sys!EngLoadImage + C8 BF8A1EE7 54 Bytes [ 45, 08, 83, 7D, 08, 05, 7C, ... ]
.text win32k.sys!EngLoadImage + 100 BF8A1F1F 22 Bytes [ 00, FF, 75, 0C, 53, E8, 66, ... ]
.text win32k.sys!EngLoadImage + 119 BF8A1F38 17 Bytes [ 8B, FF, 55, 8B, EC, 56, 8B, ... ]
.text win32k.sys!EngQueryPerformanceFrequency + 53 BF8A3D2B 15 Bytes [ A1, F8, A2, 9A, BF, 8B, 0D, ... ]
.text win32k.sys!EngQueryPerformanceFrequency + 63 BF8A3D3B 60 Bytes [ 00, A1, F8, A2, 9A, BF, 8B, ... ]
.text win32k.sys!EngQueryPerformanceFrequency + A0 BF8A3D78 12 Bytes [ 50, F6, FF, FF, 50, E8, 73, ... ]
.text win32k.sys!EngQueryPerformanceFrequency + AD BF8A3D85 68 Bytes [ 19, 8D, 85, 1C, FE, FF, FF, ... ]
.text win32k.sys!EngQueryPerformanceFrequency + F3 BF8A3DCB 21 Bytes CALL BF8385E3 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngCreateEvent + 2A BF8A5DAA 10 Bytes [ 45, E4, 0F, 82, 08, FF, FF, ... ]
.text win32k.sys!EngCreateEvent + 35 BF8A5DB5 7 Bytes [ 7A, 18, 40, 5F, 5E, 5B, C9 ]
.text win32k.sys!EngCreateEvent + 3D BF8A5DBD 1 Byte [ 08 ]
.text win32k.sys!EngCreateEvent + 3F BF8A5DBF 28 Bytes [ F6, 41, 20, 08, 0F, 84, 1E, ... ]
.text win32k.sys!EngQuerySystemAttribute + 18 BF8A5DDC 10 Bytes [ 00, 00, 90, 90, 90, 90, 90, ... ]
.text win32k.sys!EngQuerySystemAttribute + 23 BF8A5DE7 18 Bytes [ EC, 83, 7D, 08, 24, 1B, C0, ... ]
.text win32k.sys!EngQuerySystemAttribute + 36 BF8A5DFA 38 Bytes [ 33, F6, EB, 24, 90, 90, 90, ... ]
.text win32k.sys!EngQuerySystemAttribute + 5D BF8A5E21 27 Bytes CALL BF800BA5 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngQuerySystemAttribute + 79 BF8A5E3D 27 Bytes [ 3B, 05, 0C, A3, 9A, BF, 75, ... ]
.text win32k.sys!EngFindResource + C7 BF8A80A7 30 Bytes [ 88, 03, 00, 00, 85, C0, 0F, ... ]
.text win32k.sys!EngFindResource + E6 BF8A80C6 2 Bytes [ 80, 7D ]
.text win32k.sys!EngFindResource + E9 BF8A80C9 29 Bytes [ 00, 0F, 85, 94, 02, 00, 00, ... ]
.text win32k.sys!EngFindResource + 108 BF8A80E8 77 Bytes [ 66, A3, 94, A5, 99, BF, E9, ... ]
.text win32k.sys!EngFindResource + 156 BF8A8136 7 Bytes CALL BF88E2A0 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngLoadModule + 1B BF8A898A 21 Bytes [ F8, 89, 45, 0C, 76, 16, 6A, ... ]
.text win32k.sys!EngLoadModule + 31 BF8A89A0 203 Bytes [ 3B, F5, FF, FF, 33, FF, 39, ... ]
.text win32k.sys!EngLoadModule + FE BF8A8A6D 58 Bytes [ 0F, B7, 43, 0C, 03, C1, 89, ... ]
.text win32k.sys!EngLoadModule + 139 BF8A8AA8 3 Bytes [ C7, 74, 1B ]
.text win32k.sys!EngLoadModule + 13D BF8A8AAC 43 Bytes [ 43, 10, 80, 38, 00, 74, 13, ... ]
.text win32k.sys!EngFreeModule + C BF8A8AF9 16 Bytes [ 09, 0F, B7, 43, 24, 03, C1, ... ]
.text win32k.sys!EngFreeModule + 1D BF8A8B0A 19 Bytes [ 75, FC, 6A, FF, FF, 15, B8, ... ]
.text win32k.sys!EngFreeModule + 31 BF8A8B1E 30 Bytes [ C3, 5F, 5B, C9, C2, 10, 00, ... ]
.text win32k.sys!EngFreeModule + 50 BF8A8B3D 15 Bytes [ 08, 39, 78, 10, 74, 09, 0F, ... ]
.text win32k.sys!EngFreeModule + 60 BF8A8B4D 51 Bytes [ 4D, 08, 89, 41, 18, EB, B4, ... ]
.text win32k.sys!EngGetLastError + 2 BF8AC88D 51 Bytes [ 39, 41, 08, 75, 0E, 8B, 41, ... ]
.text win32k.sys!EngGetLastError + 36 BF8AC8C1 5 Bytes [ 00, E9, DA, F6, FF ]
.text win32k.sys!EngGetLastError + 3C BF8AC8C7 100 Bytes CALL BF8AC8D9 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngGetLastError + A1 BF8AC92C 97 Bytes CALL BF82704D \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngGetLastError + 103 BF8AC98E 171 Bytes [ F8, 33, D2, F3, A7, 74, 26, ... ]
.text win32k.sys!EngGradientFill + 38 BF8AED86 32 Bytes [ FF, FF, FF, 00, 74, 0B, E9, ... ]
.text win32k.sys!EngGradientFill + 59 BF8AEDA7 17 Bytes [ 33, F6, 33, DB, 39, 72, 0C, ... ]
.text win32k.sys!EngGradientFill + 6B BF8AEDB9 24 Bytes [ 8B, 07, 8B, 88, 74, 05, 00, ... ]
.text win32k.sys!EngGradientFill + 84 BF8AEDD2 55 Bytes [ 00, 75, 02, 8B, DE, 8B, 41, ... ]
.text win32k.sys!EngGradientFill + BC BF8AEE0A 5 Bytes [ 89, 85, 0C, FF, FF ]
.text win32k.sys!EngModifySurface + 17 BF8B95BF 25 Bytes [ 6A, 00, 68, 55, 73, 73, 61, ... ]
.text win32k.sys!EngModifySurface + 31 BF8B95D9 101 Bytes [ 09, 89, 4F, 0C, 8B, 4D, 0C, ... ]
.text win32k.sys!EngModifySurface + 97 BF8B963F 26 Bytes [ FF, 8B, 45, 08, 85, C0, 0F, ... ]
.text win32k.sys!EngModifySurface + B2 BF8B965A 49 Bytes [ 5D, CC, 85, DB, 0F, 84, 30, ... ]
.text win32k.sys!EngModifySurface + E4 BF8B968C 9 Bytes [ 8B, F0, 33, C9, 3B, F1, 0F, ... ]
.text win32k.sys!EngAlphaBlend + 7A BF8BA11B 20 Bytes CALL BF819AEB \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngAlphaBlend + 8F BF8BA130 86 Bytes [ 75, 0C, FF, 75, 08, E8, 16, ... ]
.text win32k.sys!EngAlphaBlend + E6 BF8BA187 11 Bytes JMP BF8BA3BC \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngAlphaBlend + F2 BF8BA193 85 Bytes CALL BF80E8CC \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngAlphaBlend + 149 BF8BA1EA 12 Bytes JMP BF8BA3BC \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!PATHOBJ_vEnumStart + 3B BF8C69E9 35 Bytes CALL BF8E499A \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!PATHOBJ_vEnumStart + 5F BF8C6A0D 34 Bytes [ 75, 20, 8B, 0F, FF, 75, 1C, ... ]
.text win32k.sys!PATHOBJ_vEnumStart + 82 BF8C6A30 14 Bytes [ 33, C0, 40, EB, BC, F6, 45, ... ]
.text win32k.sys!PATHOBJ_vEnumStart + 91 BF8C6A3F 39 Bytes CALL BF84DD02 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!PATHOBJ_vEnumStart + B9 BF8C6A67 39 Bytes [ C3, 90, 90, 90, 90, 90, 8B, ... ]
.text win32k.sys!EngStrokePath + 32 BF8C87FD 49 Bytes [ 8B, 75, 14, F7, DE, E9, 51, ... ]
.text win32k.sys!EngStrokePath + 64 BF8C882F 11 Bytes [ 46, FF, 45, 08, EB, E9, 33, ... ]
.text win32k.sys!EngStrokePath + 70 BF8C883B 14 Bytes [ 0F, 84, 3A, FF, FF, FF, 33, ... ]
.text win32k.sys!EngStrokePath + 7F BF8C884A 49 Bytes [ F6, 45, D8, 04, 89, 75, F4, ... ]
.text win32k.sys!EngStrokePath + B1 BF8C887C 55 Bytes [ 09, 45, 18, 8B, 45, 18, C1, ... ]
.text win32k.sys!EngSort + 22 BF8D2DBE 87 Bytes [ 75, 18, 2B, DE, 0F, AF, 75, ... ]
.text win32k.sys!EngSort + 7A BF8D2E16 111 Bytes [ 55, 20, 89, 55, FC, 83, 7D, ... ]
.text win32k.sys!EngSort + EA BF8D2E86 17 Bytes [ 13, 03, C1, 33, D2, F7, F7, ... ]
.text win32k.sys!EngSort + FC BF8D2E98 8 Bytes [ 45, 0C, 04, FF, 4D, FC, 66, ... ]
.text win32k.sys!EngSort + 105 BF8D2EA1 42 Bytes [ 53, 75, CD, 8B, 5D, F0, FF, ... ]
.text win32k.sys!EngLineTo + 4 BF8D4858 79 Bytes [ 3D, CC, 8A, 9A, BF, 66, 89, ... ]
.text win32k.sys!EngLineTo + 54 BF8D48A8 44 Bytes CALL BF853F3D \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngLineTo + 81 BF8D48D5 3 Bytes [ 64, F6, F7 ]
.text win32k.sys!EngLineTo + 85 BF8D48D9 107 Bytes [ 83, C4, 30, 03, F0, 81, FE, ... ]
.text win32k.sys!EngLineTo + F1 BF8D4945 41 Bytes CALL BF8EBDE1 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngDeleteSemaphore + B BF8DFAF0 32 Bytes [ 55, 8B, EC, 83, EC, 1C, 8D, ... ]
.text win32k.sys!EngDeleteSemaphore + 2C BF8DFB11 1 Byte [ 00 ]
.text win32k.sys!EngDeleteSemaphore + 2E BF8DFB13 1 Byte [ 8B ]
.text win32k.sys!EngDeleteSemaphore + 30 BF8DFB15 4 Bytes [ 89, 45, F4, 8B ]
.text win32k.sys!EngDeleteSemaphore + 35 BF8DFB1A 85 Bytes [ 08, 89, 45, F8, FF, 15, D4, ... ]
.text win32k.sys!EngFillPath + 7 BF8E4874 66 Bytes [ 3B, DF, 74, 09, 8D, 4B, 08, ... ]
.text win32k.sys!EngFillPath + 4A BF8E48B7 34 Bytes [ 85, F6, 74, 34, A1, B8, A6, ... ]
.text win32k.sys!EngFillPath + 6D BF8E48DA 19 Bytes CALL BF8011CB \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngFillPath + 81 BF8E48EE 77 Bytes [ FF, 5E, 66, 85, DB, EB, 25, ... ]
.text win32k.sys!EngFillPath + CF BF8E493C 23 Bytes JMP BF8E4A99 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!PATHOBJ_vGetBounds + D1 BF8E676E 62 Bytes [ 33, D2, 39, 50, 30, 75, 09, ... ]
.text win32k.sys!PATHOBJ_vGetBounds + 110 BF8E67AD 88 Bytes [ FF, 85, C0, 74, 04, 83, 4E, ... ]
.text win32k.sys!PATHOBJ_vGetBounds + 169 BF8E6806 90 Bytes [ EC, FF, 75, 08, 8D, 4D, 08, ... ]
.text win32k.sys!PATHOBJ_vGetBounds + 1C4 BF8E6861 58 Bytes [ 1C, 50, 03, DA, 8B, 56, 14, ... ]
.text win32k.sys!PATHOBJ_vGetBounds + 1FF BF8E689C 87 Bytes CALL 4790C42B
.text win32k.sys!PATHOBJ_bMoveTo + 4 BF8EBC95 57 Bytes [ 06, 83, B8, 04, 02, 00, 00, ... ]
.text win32k.sys!PATHOBJ_bPolyLineTo + 22 BF8EBCCF 51 Bytes CALL BF8EBCF1 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!PATHOBJ_bPolyLineTo + 56 BF8EBD03 26 Bytes [ 74, DB, FF, 75, 0C, FF, 75, ... ]
.text win32k.sys!PATHOBJ_bPolyLineTo + 71 BF8EBD1E 70 Bytes JMP BF8EC2CD \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!PATHOBJ_bPolyLineTo + B8 BF8EBD65 2 Bytes [ FF, 55 ]
.text win32k.sys!PATHOBJ_bPolyLineTo + BB BF8EBD68 81 Bytes [ EC, 8B, 4D, 0C, 2B, 4D, 14, ... ]
.text win32k.sys!PATHOBJ_bCloseFigure + 27 BF8EC135 53 Bytes [ 85, C0, 0F, 84, BF, 04, 00, ... ]
.text win32k.sys!PATHOBJ_bCloseFigure + 5D BF8EC16B 18 Bytes [ 55, 8B, EC, 81, EC, B4, 00, ... ]
.text win32k.sys!PATHOBJ_bCloseFigure + 70 BF8EC17E 7 Bytes [ FF, 8B, 45, 18, 83, 65, F8 ]
.text win32k.sys!PATHOBJ_bCloseFigure + 78 BF8EC186 25 Bytes [ 85, C0, 0F, 85, 03, FC, FF, ... ]
.text win32k.sys!PATHOBJ_bCloseFigure + 92 BF8EC1A0 44 Bytes [ F0, 0F, 83, 13, FC, FF, FF, ... ]
.text win32k.sys!EngDeletePalette + 16 BF8F9DF7 51 Bytes [ 00, C3, 90, 90, 90, 90, 90, ... ]
.text win32k.sys!EngDeletePalette + 4A BF8F9E2B 62 Bytes [ 59, 59, 85, C0, 0F, 85, B2, ... ]
.text win32k.sys!EngDeletePalette + 89 BF8F9E6A 25 Bytes [ 90, 90, 90, 90, 6A, 44, 68, ... ]
.text win32k.sys!EngDeletePalette + A3 BF8F9E84 22 Bytes CALL BF800B76 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngDeletePalette + BA BF8F9E9B 102 Bytes [ C6, 6A, 06, 59, 8B, F0, 8D, ... ]
.text win32k.sys!FONTOBJ_pifi + 1 BF8FAC19 39 Bytes CALL BF800C62 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!FONTOBJ_pifi + 29 BF8FAC41 1 Byte [ 00 ]
.text win32k.sys!FONTOBJ_pifi + 2B BF8FAC43 73 Bytes [ C3, 03, 74, 06, FF, 15, 0C, ... ]
.text win32k.sys!FONTOBJ_pifi + 75 BF8FAC8D 10 Bytes [ 75, 10, 83, FE, 04, 0F, 87, ... ]
.text win32k.sys!FONTOBJ_pifi + 80 BF8FAC98 22 Bytes [ 8D, 45, BC, 89, 45, E4, 89, ... ]
.text win32k.sys!HT_Get8BPPMaskPalette + 16 BF8FC50D 5 Bytes [ B1, 0C, 04, 00, 00 ]
.text win32k.sys!HT_Get8BPPMaskPalette + 1C BF8FC513 12 Bytes [ C4, 90, F0, FF, 8D, 4D, F4, ... ]
.text win32k.sys!HT_Get8BPPMaskPalette + 29 BF8FC520 6 Bytes [ F0, 8B, 45, 08, 85, C0 ]
.text win32k.sys!HT_Get8BPPMaskPalette + 30 BF8FC527 95 Bytes [ 09, 8D, 48, 08, FF, 15, B0, ... ]
.text win32k.sys!HT_Get8BPPMaskPalette + 90 BF8FC587 4 Bytes JMP BF8FC6C1 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!HT_Get8BPPFormatPalette + 32 BF8FC8E8 13 Bytes [ 00, 89, 7D, F4, 89, 7D, F8, ... ]
.text win32k.sys!HT_Get8BPPFormatPalette + 40 BF8FC8F6 144 Bytes [ F0, 3B, F7, 74, A2, 39, BE, ... ]
.text win32k.sys!HT_Get8BPPFormatPalette + D1 BF8FC987 19 Bytes [ 13, 8B, 75, FC, 8D, 4D, F0, ... ]
.text win32k.sys!HT_Get8BPPFormatPalette + E5 BF8FC99B 17 Bytes [ FF, 75, F8, 8B, CE, FF, 75, ... ]
.text win32k.sys!HT_Get8BPPFormatPalette + F7 BF8FC9AD 3 Bytes [ 7C, 9D, 07 ]
.text win32k.sys!STROBJ_bEnumPositionsOnly + 17 BF8FCB6E 127 Bytes [ 5F, 5E, 5B, C9, C2, 14, 00, ... ]
.text win32k.sys!STROBJ_bEnumPositionsOnly + 97 BF8FCBEE 67 Bytes [ 04, B8, 85, C0, 74, 39, 8B, ... ]
.text win32k.sys!XFORMOBJ_bApplyXform + 2C BF8FCC32 15 Bytes [ F4, FE, FF, FF, EB, AD, 8B, ... ]
.text win32k.sys!XFORMOBJ_bApplyXform + 3C BF8FCC42 14 Bytes JMP C1B04CD2
.text win32k.sys!XFORMOBJ_bApplyXform + 4C BF8FCC52 142 Bytes CALL BF8DD23D \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!XFORMOBJ_bApplyXform + DB BF8FCCE1 11 Bytes [ 80, 20, 02, 00, 00, 3B, C3, ... ]
.text win32k.sys!XFORMOBJ_bApplyXform + E7 BF8FCCED 13 Bytes CALL BF8DD23C \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!FONTOBJ_vGetInfo + 1C BF8FCE7A 31 Bytes [ 00, 00, 6A, 0C, 8D, 45, D8, ... ]
.text win32k.sys!FONTOBJ_vGetInfo + 3C BF8FCE9A 152 Bytes CALL BF8DD8F7 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!FONTOBJ_vGetInfo + D5 BF8FCF33 117 Bytes [ 12, 00, 00, 85, C0, 74, 41, ... ]
.text win32k.sys!FONTOBJ_vGetInfo + 14B BF8FCFA9 24 Bytes CALL BF80195A \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!FONTOBJ_vGetInfo + 165 BF8FCFC3 65 Bytes [ 00, 8B, 03, 8B, 80, B4, 02, ... ]
.text