Status: Hooked by "<unknown>" at address 0x85c61a58
#: 013 Function Name: NtAlertThread
Status: Hooked by "<unknown>" at address 0x85d033a0
#: 017 Function Name: NtAllocateVirtualMemory
Status: Hooked by "<unknown>" at address 0x85dc6b78
#: 031 Function Name: NtConnectPort
Status: Hooked by "<unknown>" at address 0x85e83cd0
#: 041 Function Name: NtCreateKey
Status: Hooked by "C:\WINDOWS\system32\Drivers\SYMEVENT.SYS" at address 0xf1b43020
#: 043 Function Name: NtCreateMutant
Status: Hooked by "<unknown>" at address 0x85dbf308
#: 053 Function Name: NtCreateThread
Status: Hooked by "<unknown>" at address 0x85c36068
#: 057 Function Name: NtDebugActiveProcess
Status: Hooked by "<unknown>" at address 0x85c389c0
#: 063 Function Name: NtDeleteKey
Status: Hooked by "C:\WINDOWS\system32\Drivers\SYMEVENT.SYS" at address 0xf1b432a0
#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "C:\WINDOWS\system32\Drivers\SYMEVENT.SYS" at address 0xf1b43800
#: 083 Function Name: NtFreeVirtualMemory
Status: Hooked by "<unknown>" at address 0x85c598e8
#: 089 Function Name: NtImpersonateAnonymousToken
Status: Hooked by "<unknown>" at address 0x85c96328
#: 091 Function Name: NtImpersonateThread
Status: Hooked by "<unknown>" at address 0x85c39a58
#: 108 Function Name: NtMapViewOfSection
Status: Hooked by "<unknown>" at address 0x85c48fb0
#: 114 Function Name: NtOpenEvent
Status: Hooked by "<unknown>" at address 0x85dc6ab8
#: 123 Function Name: NtOpenProcessToken
Status: Hooked by "<unknown>" at address 0x85c26f08
#: 125 Function Name: NtOpenSection
Status: Hooked by "<unknown>" at address 0x85c38550
#: 129 Function Name: NtOpenThreadToken
Status: Hooked by "<unknown>" at address 0x85c38658
#: 206 Function Name: NtResumeThread
Status: Hooked by "<unknown>" at address 0x85d4b340
#: 213 Function Name: NtSetContextThread
Status: Hooked by "<unknown>" at address 0x85d44630
#: 228 Function Name: NtSetInformationProcess
Status: Hooked by "<unknown>" at address 0x85c48e58
#: 229 Function Name: NtSetInformationThread
Status: Hooked by "<unknown>" at address 0x85c407e0
#: 247 Function Name: NtSetValueKey
Status: Hooked by "C:\WINDOWS\system32\Drivers\SYMEVENT.SYS" at address 0xf1b43a50
#: 253 Function Name: NtSuspendProcess
Status: Hooked by "<unknown>" at address 0x85c59828
#: 254 Function Name: NtSuspendThread
Status: Hooked by "<unknown>" at address 0x85e84158
#: 257 Function Name: NtTerminateProcess
Status: Hooked by "<unknown>" at address 0x85cef308
#: 258 Function Name: NtTerminateThread
Status: Hooked by "<unknown>" at address 0x85d5a550
#: 267 Function Name: NtUnmapViewOfSection
Status: Hooked by "<unknown>" at address 0x85c569c0
#: 277 Function Name: NtWriteVirtualMemory
Status: Hooked by "<unknown>" at address 0x85c599b8
==EOF==
Edited by photoman20, 27 July 2009 - 11:08 PM.