-----------------------------
.text win32k.sys!XFORMOBJ_bApplyXform + 4C BF8FCC52 142 Bytes CALL BF8DD23D \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!XFORMOBJ_bApplyXform + DB BF8FCCE1 11 Bytes [ 80, 20, 02, 00, 00, 3B, C3, ... ]
.text win32k.sys!XFORMOBJ_bApplyXform + E7 BF8FCCED 13 Bytes CALL BF8DD23C \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!FONTOBJ_vGetInfo + 1C BF8FCE7A 31 Bytes [ 00, 00, 6A, 0C, 8D, 45, D8, ... ]
.text win32k.sys!FONTOBJ_vGetInfo + 3C BF8FCE9A 152 Bytes CALL BF8DD8F7 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!FONTOBJ_vGetInfo + D5 BF8FCF33 117 Bytes [ 12, 00, 00, 85, C0, 74, 41, ... ]
.text win32k.sys!FONTOBJ_vGetInfo + 14B BF8FCFA9 24 Bytes CALL BF80195A \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!FONTOBJ_vGetInfo + 165 BF8FCFC3 65 Bytes [ 00, 8B, 03, 8B, 80, B4, 02, ... ]
.text win32k.sys!FONTOBJ_cGetGlyphs + 34 BF8FD140 39 Bytes [ FF, 55, 8B, EC, 8B, 45, 08, ... ]
.text win32k.sys!FONTOBJ_cGetGlyphs + 5C BF8FD168 67 Bytes [ 89, 48, 08, 74, 20, 8B, 40, ... ]
.text win32k.sys!FONTOBJ_cGetGlyphs + A0 BF8FD1AC 90 Bytes [ 55, 8B, EC, 56, FF, 15, E0, ... ]
.text win32k.sys!STROBJ_bGetAdvanceWidths + 33 BF8FD207 4 Bytes JMP BF8FD2DC \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!STROBJ_bGetAdvanceWidths + 38 BF8FD20C 232 Bytes [ B9, 40, 42, 0F, 00, 3B, F9, ... ]
.text win32k.sys!STROBJ_bGetAdvanceWidths + 121 BF8FD2F5 38 Bytes [ 5A, D7, 32, 00, 7C, 07, B8, ... ]
.text win32k.sys!STROBJ_bGetAdvanceWidths + 148 BF8FD31C 7 Bytes [ FF, FF, 55, 8B, EC, FC, 53 ]
.text win32k.sys!STROBJ_bGetAdvanceWidths + 150 BF8FD324 109 Bytes [ 45, 0C, 99, 8B, DA, 33, C2, ... ]
.text win32k.sys!BRUSHOBJ_hGetColorTransform + 21 BF8FD4B9 19 Bytes [ F4, FF, 75, EC, FF, 75, E8, ... ]
.text win32k.sys!BRUSHOBJ_hGetColorTransform + 35 BF8FD4CD 53 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text win32k.sys!BRUSHOBJ_hGetColorTransform + 6C BF8FD504 8 Bytes [ 57, 8B, 7D, 20, 0F, 85, 6F, ... ]
.text win32k.sys!BRUSHOBJ_hGetColorTransform + 76 BF8FD50E 28 Bytes [ 39, 5D, FC, 0F, 84, F7, 00, ... ]
.text win32k.sys!BRUSHOBJ_hGetColorTransform + 93 BF8FD52B 2 Bytes [ BC, 8B ]
.text win32k.sys!EngAllocUserMem + 34 BF8FDE5A 75 Bytes [ 2B, FB, 8B, 5D, FC, 81, E7, ... ]
.text win32k.sys!EngAllocUserMem + 80 BF8FDEA6 105 Bytes [ 08, 85, C0, 8B, F2, 0F, 84, ... ]
.text win32k.sys!EngAllocUserMem + EB BF8FDF11 51 Bytes [ CA, 8B, F3, F3, A5, 0F, B6, ... ]
.text win32k.sys!EngAllocUserMem + 11F BF8FDF45 11 Bytes [ 75, 1C, 8B, 7D, 14, 8B, 4D, ... ]
.text win32k.sys!EngAllocUserMem + 12B BF8FDF51 146 Bytes [ C3, 20, 3B, 5D, 10, 0F, 83, ... ]
.text win32k.sys!EngMarkBandingSurface + 8 BF8FE3F5 24 Bytes [ 2C, FF, 75, 28, FF, 75, 24, ... ]
.text win32k.sys!EngMarkBandingSurface + 21 BF8FE40E 44 Bytes [ FF, 50, FF, 75, 10, FF, 75, ... ]
.text win32k.sys!EngMarkBandingSurface + 4F BF8FE43C 15 Bytes [ 00, FE, 39, 7D, DC, 74, 08, ... ]
.text win32k.sys!EngMarkBandingSurface + 5F BF8FE44C 154 Bytes CALL BF800C62 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngMarkBandingSurface + FA BF8FE4E7 9 Bytes [ 85, C0, 74, 29, 56, 8D, 45, ... ]
.text win32k.sys!BRUSHOBJ_ulGetBrushColor + 14 BF8FED03 292 Bytes [ 83, C6, 1C, 8D, 7D, EC, A5, ... ]
.text win32k.sys!BRUSHOBJ_ulGetBrushColor + 139 BF8FEE28 20 Bytes JMP BF8FEFD0 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!BRUSHOBJ_ulGetBrushColor + 14E BF8FEE3D 72 Bytes JMP BF8FEF64 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!BRUSHOBJ_ulGetBrushColor + 197 BF8FEE86 13 Bytes [ 5D, D4, 89, 5D, 08, FF, 75, ... ]
.text win32k.sys!BRUSHOBJ_ulGetBrushColor + 1A6 BF8FEE95 6 Bytes [ 89, 45, 0C, FF, 75, 10 ]
.text win32k.sys!EngStrokeAndFillPath + A BF9006ED 13 Bytes [ 89, 5D, FC, A1, E0, B7, 9A, ... ]
.text win32k.sys!EngStrokeAndFillPath + 18 BF9006FB 1 Byte [ 45 ]
.text win32k.sys!EngStrokeAndFillPath + 1A BF9006FD 62 Bytes [ 89, 45, E4, 6A, 06, 59, 8B, ... ]
.text win32k.sys!EngStrokeAndFillPath + 59 BF90073C 6 Bytes [ 0A, 3B, 4D, D8, 7D, 03 ]
.text win32k.sys!EngStrokeAndFillPath + 60 BF900743 2 Bytes [ 4D, D8 ]
.text win32k.sys!STROBJ_bEnum + D BF900BAE 54 Bytes [ 46, 04, 08, 89, 45, 08, 74, ... ]
.text win32k.sys!STROBJ_bEnum + 45 BF900BE6 82 Bytes [ 08, 8B, 09, 89, 4D, F0, 8A, ... ]
.text win32k.sys!STROBJ_bEnum + 98 BF900C39 2 Bytes [ 16, 01 ]
.text win32k.sys!STROBJ_bEnum + 9C BF900C3D 67 Bytes [ 88, 06, 88, 5E, 01, 88, 4E, ... ]
.text win32k.sys!STROBJ_bEnum + E1 BF900C82 60 Bytes [ 88, 46, 15, 88, 5E, 16, 88, ... ]
.text win32k.sys!EngCreateDriverObj + 1D BF908065 17 Bytes CALL 351C3255
.text win32k.sys!EngCreateDriverObj + 2F BF908077 26 Bytes CALL BF828F4E \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngCreateDriverObj + 4A BF908092 52 Bytes [ 43, 04, 89, 45, F8, 56, 8D, ... ]
.text win32k.sys!EngCreateDriverObj + 7F BF9080C7 9 Bytes [ 00, 00, 3B, 75, E0, 0F, 8D, ... ]
.text win32k.sys!EngCreateDriverObj + 89 BF9080D1 82 Bytes [ 00, 8B, 45, FC, 3B, 45, 0C, ... ]
.text win32k.sys!EngLockDriverObj + 21 BF908223 55 Bytes [ 8B, 45, EC, 8B, 00, 8B, 00, ... ]
.text win32k.sys!EngDeleteDriverObj + 34 BF90825B 29 Bytes [ 75, 08, 8B, 06, FF, 30, E8, ... ]
.text win32k.sys!EngDeleteDriverObj + 52 BF908279 56 Bytes [ 00, 75, 18, 89, 55, FC, 56, ... ]
.text win32k.sys!EngDeleteDriverObj + 8C BF9082B3 3 Bytes [ 8B, FF, 55 ]
.text win32k.sys!EngDeleteDriverObj + 90 BF9082B7 10 Bytes [ EC, A1, 18, 4D, 9A, BF, 5D, ... ]
.text win32k.sys!EngDeleteDriverObj + 9C BF9082C3 22 Bytes [ 00, 90, 90, 90, 90, 90, 8B, ... ]
.text win32k.sys!EngGetCurrentProcessId + 5 BF908882 98 Bytes [ 75, 11, 03, 7D, D8, 03, 75, ... ]
.text win32k.sys!EngGetCurrentProcessId + 68 BF9088E5 92 Bytes [ 00, D3, FA, 6A, 08, 59, 2B, ... ]
.text win32k.sys!EngGetCurrentProcessId + C7 BF908944 28 Bytes CALL 48BCD7D4
.text win32k.sys!EngGetCurrentProcessId + E4 BF908961 94 Bytes [ FF, FF, 39, 55, 08, 74, 27, ... ]
.text win32k.sys!EngGetCurrentProcessId + 143 BF9089C0 123 Bytes [ 55, 8B, EC, A1, 18, 4D, 9A, ... ]
.text win32k.sys!PATHOBJ_bEnumClipLines + 6 BF90C61A 5 Bytes [ 89, 85, EC, FC, FF ]
.text win32k.sys!PATHOBJ_bEnumClipLines + C BF90C620 10 Bytes [ 8D, 9D, E4, FC, FF, FF, 89, ... ]
.text win32k.sys!PATHOBJ_bEnumClipLines + 17 BF90C62B 48 Bytes [ FF, 8D, 85, E4, FC, FF, FF, ... ]
.text win32k.sys!PATHOBJ_bEnumClipLines + 48 BF90C65C 17 Bytes [ 45, 08, 89, 43, 1C, 8B, 45, ... ]
.text win32k.sys!PATHOBJ_bEnumClipLines + 5A BF90C66E 15 Bytes [ 85, CC, FD, FF, FF, 8B, 30, ... ]
.text win32k.sys!EngMapFontFile + 4F BF90CFE6 91 Bytes [ 14, FF, 46, 04, FF, 75, 10, ... ]
.text win32k.sys!EngMapFontFile + AB BF90D042 77 Bytes [ 33, C9, 3B, F0, 0F, 94, C1, ... ]
.text win32k.sys!EngMapFontFile + F9 BF90D090 87 Bytes [ 75, 08, 83, C8, FF, E9, 7D, ... ]
.text win32k.sys!EngMapFontFile + 151 BF90D0E8 10 Bytes [ 18, 8B, 5D, 10, 89, 45, FC, ... ]
.text win32k.sys!EngMapFontFile + 15C BF90D0F3 50 Bytes [ 00, 3B, DF, 76, 27, 83, FB, ... ]
.text win32k.sys!EngUnmapFontFile + 8C BF90DE03 167 Bytes [ 4D, 08, 53, 56, 8B, 70, 78, ... ]
.text win32k.sys!EngUnmapFontFile + 134 BF90DEAB 1 Byte [ 0A ]
.text win32k.sys!EngUnmapFontFile + 136 BF90DEAD 51 Bytes [ C8, 8B, 00, 3B, C3, 74, 12, ... ]
.text win32k.sys!EngUnmapFontFile + 16A BF90DEE1 98 Bytes [ 17, 39, 58, 04, 7F, 19, 8B, ... ]
.text win32k.sys!EngUnmapFontFile + 1CD BF90DF44 56 Bytes [ 80, F8, 00, 00, 00, 89, 46, ... ]
.text win32k.sys!PALOBJ_cGetColors + 7 BF90E191 81 Bytes [ 85, E0, FD, FF, FF, 3B, C7, ... ]
.text win32k.sys!PALOBJ_cGetColors + 5A BF90E1E4 16 Bytes [ 8D, 8D, C4, FD, FF, FF, 51, ... ]
.text win32k.sys!PALOBJ_cGetColors + 6B BF90E1F5 11 Bytes [ 50, 8D, 8D, E4, FD, FF, FF, ... ]
.text win32k.sys!PALOBJ_cGetColors + 77 BF90E201 115 Bytes [ 8B, F8, EB, 42, 8B, 48, 58, ... ]
.text win32k.sys!PALOBJ_cGetColors + EB BF90E275 6 Bytes [ FF, 75, 18, FF, 75, 14 ]
.text win32k.sys!EngCreateClip + 1A BF910D00 55 Bytes CALL BF910A89 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngCreateClip + 52 BF910D38 156 Bytes [ 3B, C1, 74, 43, 3D, F7, 00, ... ]
.text win32k.sys!EngCreateClip + EF BF910DD5 130 Bytes CALL BF804613 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngCreateClip + 172 BF910E58 27 Bytes [ FF, 55, 8B, EC, 51, 89, 4D, ... ]
.text win32k.sys!EngCreateClip + 18E BF910E74 63 Bytes [ 00, 00, FF, 15, E4, C3, 98, ... ]
.text win32k.sys!EngSetPointerTag + 5 BF916075 41 Bytes [ 00, 00, EB, 1E, 90, 90, 90, ... ]
.text win32k.sys!EngSetPointerTag + 2F BF91609F 9 Bytes [ C2, 04, 00, 90, 90, 90, 90, ... ]
.text win32k.sys!EngSetPointerTag + 39 BF9160A9 60 Bytes [ 55, 8B, EC, 56, 8B, 75, 08, ... ]
.text win32k.sys!EngSetPointerTag + 76 BF9160E6 10 Bytes [ 55, 8B, EC, FF, 15, E8, C3, ... ]
.text win32k.sys!EngSetPointerTag + 81 BF9160F1 78 Bytes [ 15, 9C, C3, 98, BF, B9, 00, ... ]
.text win32k.sys!XFORMOBJ_iGetFloatObjXform + 23 BF933501 66 Bytes JMP B3536808
.text win32k.sys!FLOATOBJ_SetLong BF933547 166 Bytes [ 90, 8B, FF, 55, 8B, EC, 83, ... ]
.text win32k.sys!FLOATOBJ_Add + 9 BF9335EE 45 Bytes CALL BF804B28 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!FLOATOBJ_SubFloat + 1B BF93361C 11 Bytes [ 8B, C6, 5E, 5D, C2, 04, 00, ... ]
.text win32k.sys!FLOATOBJ_SubFloat + 27 BF933628 30 Bytes [ 8B, FF, 55, 8B, EC, 56, E8, ... ]
.text win32k.sys!FLOATOBJ_SubLong + 1B BF933647 2 Bytes [ 4E, 04 ]
.text win32k.sys!FLOATOBJ_SubLong + 1E BF93364A 3 Bytes [ EE, 14, ED ]
.text win32k.sys!FLOATOBJ_SubLong + 22 BF93364E 5 Bytes [ 5E, 5D, C2, 04, 00 ]
.text win32k.sys!FLOATOBJ_Sub BF933657 66 Bytes [ 90, 8B, FF, 56, 33, F6, 39, ... ]
.text win32k.sys!FLOATOBJ_MulFloat + 29 BF93369C 35 Bytes [ A1, D0, 02, DF, FF, C1, E8, ... ]
.text win32k.sys!FLOATOBJ_MulLong + 22 BF9336C0 63 Bytes JMP BF94B018 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!FLOATOBJ_DivFloat + 1B BF933700 42 Bytes [ 55, 8B, EC, 6A, 00, FF, 75, ... ]
.text win32k.sys!FLOATOBJ_DivLong + 1B BF93372B 39 Bytes [ FF, 75, 0C, 8D, 45, FC, 50, ... ]
.text win32k.sys!FLOATOBJ_Div + 1A BF933755 38 Bytes [ 8B, FF, 55, 8B, EC, A1, 18, ... ]
.text win32k.sys!FLOATOBJ_EqualLong + F BF93377C 123 Bytes [ FF, 55, 8B, EC, A1, 18, 4D, ... ]
.text win32k.sys!FLOATOBJ_LessThanLong BF9337F9 3 Bytes [ 90, 90, 90 ]
.text win32k.sys!FLOATOBJ_LessThanLong + 4 BF9337FD 32 Bytes [ FF, 55, 8B, EC, A1, 18, 4D, ... ]
.text win32k.sys!FLOATOBJ_LessThanLong + 25 BF93381E 21 Bytes [ A0, 8C, 01, 00, 00, 90, 90, ... ]
.text win32k.sys!FLOATOBJ_Equal + 2 BF933834 64 Bytes [ A0, 44, 01, 00, 00, 90, 90, ... ]
.text win32k.sys!FLOATOBJ_LessThan + 11 BF933875 3 Bytes [ FF, 60, 6C ]
.text win32k.sys!FLOATOBJ_LessThan + 1E BF933882 28 Bytes [ A1, 18, 4D, 9A, BF, 5D, FF, ... ]
.text win32k.sys!FLOATOBJ_LessThan + 3B BF93389F 83 Bytes [ 60, 0C, 90, 90, 90, 90, 90, ... ]
.text win32k.sys!FLOATOBJ_LessThan + 8F BF9338F3 18 Bytes [ FF, 55, 8B, EC, A1, 18, 4D, ... ]
.text win32k.sys!FLOATOBJ_LessThan + A2 BF933906 61 Bytes [ FF, 55, 8B, EC, A1, 18, 4D, ... ]
.text win32k.sys!EngGetCurrentThreadId + 8 BF933B93 39 Bytes [ 8B, FF, 55, 8B, EC, A1, 18, ... ]
.text win32k.sys!EngIsSemaphoreOwned BF933BBD 5 Bytes [ 90, 90, 8B, FF, 55 ]
.text win32k.sys!EngIsSemaphoreOwned + 6 BF933BC3 15 Bytes [ EC, A1, 18, 4D, 9A, BF, 5D, ... ]
.text win32k.sys!EngIsSemaphoreOwned + 18 BF933BD5 17 Bytes [ 8B, FF, 55, 8B, EC, A1, 18, ... ]
.text win32k.sys!EngDebugPrint BF933BE7 79 Bytes [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text win32k.sys!EngDebugPrint + 53 BF933C3A 6 Bytes [ 8B, FF, 55, 8B, EC, 56 ]
.text win32k.sys!EngDebugPrint + 5B BF933C42 10 Bytes [ 08, 8D, 4D, 08, 33, F6, E8, ... ]
.text win32k.sys!EngDebugPrint + 66 BF933C4D 155 Bytes [ 39, 75, 08, 74, 1A, 8B, 45, ... ]
.text win32k.sys!EngAllocSectionMem + 51 BF933CEA 21 Bytes [ FC, 89, 7D, E4, 8B, 45, E4, ... ]
.text win32k.sys!EngAllocSectionMem + 67 BF933D00 35 Bytes [ 04, 83, C6, 04, 89, 75, DC, ... ]
.text win32k.sys!EngAllocSectionMem + 8B BF933D24 27 Bytes CALL BF8F8AAC \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngFreeSectionMem + F BF933D40 61 Bytes [ 75, 08, 8D, 4D, 08, 33, F6, ... ]
.text win32k.sys!EngMapSection + 23 BF933D7E 54 Bytes [ 90, 90, 90, 8B, FF, 55, 8B, ... ]
.text win32k.sys!EngMapSection + 5A BF933DB5 8 Bytes [ 7D, 08, 8B, DF, F7, DB, 1B, ... ]
.text win32k.sys!EngMapSection + 63 BF933DBE 77 Bytes [ 45, C0, 8D, 47, F0, 23, D8, ... ]
.text win32k.sys!EngInitializeSafeSemaphore + D BF933E0C 5 Bytes [ 30, FF, 75, 2C, FF ]
.text win32k.sys!EngInitializeSafeSemaphore + 13 BF933E12 7 Bytes [ 28, FF, 75, 24, FF, 75, 20 ]
.text win32k.sys!EngInitializeSafeSemaphore + 1B BF933E1A 171 Bytes [ 75, 1C, FF, 75, 18, FF, 75, ... ]
.text win32k.sys!EngDeleteSafeSemaphore + 8B BF933EC6 86 Bytes [ 76, 04, 89, 7D, B8, 89, 75, ... ]
.text win32k.sys!EngDeleteSafeSemaphore + E2 BF933F1D 69 Bytes [ DC, 89, 75, F8, 8B, 7D, F4, ... ]
.text win32k.sys!EngDeleteSafeSemaphore + 128 BF933F63 13 Bytes [ 39, 45, C0, 89, 45, B0, C6, ... ]
.text win32k.sys!EngDeleteSafeSemaphore + 137 BF933F72 100 Bytes [ 0F, 84, A9, 00, 00, 00, 66, ... ]
.text win32k.sys!EngDeleteSafeSemaphore + 19C BF933FD7 89 Bytes [ 5F, 6B, 83, BF, 8B, 45, B0, ... ]
.text win32k.sys!EngAllocPrivateUserMem + 15 BF93438F 4 Bytes [ 00, 00, 77, 0E ]
.text win32k.sys!EngFreePrivateUserMem + 4 BF934394 110 Bytes [ CE, 69, C9, 50, 04, 00, 00, ... ]
.text win32k.sys!EngUnlockDirectDrawSurface + 31 BF934403 104 Bytes [ 6A, 02, FF, 75, F0, FF, 75, ... ]
.text win32k.sys!EngUnlockDirectDrawSurface + 9A BF93446C 131 Bytes [ FF, 45, F0, 8B, 45, F0, 81, ... ]
.text win32k.sys!EngUnlockDirectDrawSurface + 11E BF9344F0 40 Bytes CALL BF8969A5 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngUnlockDirectDrawSurface + 147 BF934519 51 Bytes CALL BF8969A6 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngUnlockDirectDrawSurface + 17B BF93454D 119 Bytes [ 45, D4, 89, 3C, 88, EB, 0D, ... ]
.text win32k.sys!EngGetType1FontList + 29 BF934F1B 24 Bytes [ EB, 02, 33, C0, 53, 53, FF, ... ]
.text win32k.sys!EngGetType1FontList + 42 BF934F34 63 Bytes [ 53, 57, 8D, 4D, FC, E8, D3, ... ]
.text win32k.sys!EngGetType1FontList + 82 BF934F74 27 Bytes [ F0, 3B, F3, 74, CA, 83, FF, ... ]
.text win32k.sys!EngGetType1FontList + 9E BF934F90 32 Bytes CALL BF837697 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngGetType1FontList + C0 BF934FB2 186 Bytes [ 85, C0, 74, 05, 83, C0, 10, ... ]
.text win32k.sys!EngQueryLocalTime + 49 BF93506D 65 Bytes [ 75, F4, 89, 75, F8, F6, 00, ... ]
.text win32k.sys!EngQueryLocalTime + 8B BF9350AF 76 Bytes [ 8B, 03, 8B, 49, 10, 3B, 88, ... ]
.text win32k.sys!EngQueryLocalTime + D8 BF9350FC 28 Bytes [ 85, C9, 75, 05, 21, 4D, 08, ... ]
.text win32k.sys!EngQueryLocalTime + F5 BF935119 24 Bytes [ FC, 8D, B0, D8, 03, 00, 00, ... ]
.text win32k.sys!EngQueryLocalTime + 10E BF935132 91 Bytes [ 0B, 8B, 89, DC, 01, 00, 00, ... ]
.text win32k.sys!EngCheckAbort + 61 BF935312 10 Bytes [ 90, 90, 90, 90, 8B, FF, 55, ... ]
.text win32k.sys!EngCheckAbort + 6C BF93531D 129 Bytes [ B8, 00, 00, 00, 53, 8B, 5D, ... ]
.text win32k.sys!EngCheckAbort + EE BF93539F 10 Bytes [ 4E, 1C, 50, 83, EC, 10, 81, ... ]
.text win32k.sys!EngCheckAbort + F9 BF9353AA 90 Bytes [ 00, 8B, FC, A5, A5, A5, 51, ... ]
.text win32k.sys!EngCheckAbort + 154 BF935405 97 Bytes [ 14, 6A, 0E, 33, C0, F6, 06, ... ]
.text win32k.sys!EngUnmapEvent + 12 BF936B95 29 Bytes [ 8B, 75, 24, 85, F6, 74, 13, ... ]
.text win32k.sys!EngSetEvent + 2 BF936BB3 53 Bytes [ 75, 28, 56, FF, 75, 20, FF, ... ]
.text win32k.sys!EngReadStateEvent + 2 BF936BE9 6 Bytes [ 75, 10, E8, 0F, 1D, F9 ]
.text win32k.sys!EngReadStateEvent + 9 BF936BF0 37 Bytes [ 8B, D8, 8B, 75, 0C, 8B, 55, ... ]
.text win32k.sys!EngReadStateEvent + 2F BF936C16 114 Bytes [ C3, 5B, C9, C2, 28, 00, 90, ... ]
.text win32k.sys!EngReadStateEvent + A2 BF936C89 22 Bytes [ 8B, F8, 85, FF, 75, 21, FF, ... ]
.text win32k.sys!EngReadStateEvent + BA BF936CA1 123 Bytes [ 1C, FF, 75, 18, 53, FF, 75, ... ]
.text win32k.sys!EngGetFileChangeTime + 2B BF936D1D 34 Bytes [ 8B, 45, 08, 83, C7, 38, A5, ... ]
.text win32k.sys!EngGetFileChangeTime + 4F BF936D41 27 Bytes [ 8D, B3, 9C, 00, 00, 00, A5, ... ]
.text win32k.sys!EngGetFileChangeTime + 6B BF936D5D 63 Bytes [ 08, 8B, 4D, 0C, 89, 48, 68, ... ]
.text win32k.sys!EngGetFileChangeTime + AB BF936D9D 62 Bytes [ 55, 8B, EC, FF, 75, 10, 8B, ... ]
.text win32k.sys!EngGetFileChangeTime + EA BF936DDC 55 Bytes [ 00, 8B, 75, 18, 89, 0E, 8B, ... ]
.text win32k.sys!EngDeleteFile + 7 BF936F77 105 Bytes [ FF, 5F, 8B, C6, 5E, 5B, C9, ... ]
.text win32k.sys!EngDeleteFile + 71 BF936FE1 12 Bytes [ 08, F7, C1, 00, 00, 00, 02, ... ]
.text win32k.sys!EngDeleteFile + 7E BF936FEE 118 Bytes [ FF, FD, 84, C9, 89, 08, 79, ... ]
.text win32k.sys!EngDeleteFile + F5 BF937065 15 Bytes [ 8B, 55, 0C, 8D, 5E, 04, 8B, ... ]
.text win32k.sys!EngDeleteFile + 105 BF937075 35 Bytes [ 0E, 8B, 55, 10, 8B, CB, E8, ... ]
.text win32k.sys!EngControlSprites + 37 BF93815F 25 Bytes [ 85, C0, 0F, 84, BF, 00, 00, ... ]
.text win32k.sys!EngControlSprites + 51 BF938179 98 Bytes [ FF, EB, 05, 83, E1, FD, 89, ... ]
.text win32k.sys!EngControlSprites + B4 BF9381DC 103 Bytes CALL 4503C86C
.text win32k.sys!EngControlSprites + 11C BF938244 134 Bytes [ 55, 8B, EC, 83, EC, 14, 8B, ... ]
.text win32k.sys!EngControlSprites + 1A3 BF9382CB 48 Bytes [ 48, 28, 3B, 4A, 28, 75, 28, ... ]
.text win32k.sys!EngMovePointer + 6 BF938A8E 88 Bytes [ E0, 0F, 89, 02, 39, 71, 14, ... ]
.text win32k.sys!EngMovePointer + 5F BF938AE7 30 Bytes [ 90, 90, 90, 90, 90, 8B, 49, ... ]
.text win32k.sys!EngMovePointer + 7E BF938B06 18 Bytes [ FF, 55, 8B, EC, 8B, 55, 10, ... ]
.text win32k.sys!EngMovePointer + 91 BF938B19 106 Bytes [ 31, 03, 75, 14, 83, C1, 08, ... ]
.text win32k.sys!EngMovePointer + FC BF938B84 2 Bytes [ 85, C0 ]
.text win32k.sys!EngSetPointerShape + 9F BF938CA9 15 Bytes CALL BF802B14 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngSetPointerShape + AF BF938CB9 76 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text win32k.sys!EngSetPointerShape + FC BF938D06 3 Bytes [ 9B, 3D, FC ]
.text win32k.sys!EngSetPointerShape + 100 BF938D0A 30 Bytes [ 89, 45, F8, 33, D2, 8B, 03, ... ]
.text win32k.sys!EngSetPointerShape + 11F BF938D29 25 Bytes [ 75, 20, 8B, 4D, EC, FF, 75, ... ]
.text win32k.sys!EngQueryPalette + 1 BF9392A4 78 Bytes [ 80, 90, 00, 00, 00, 3B, 45, ... ]
.text win32k.sys!EngQueryPalette + 50 BF9392F3 1 Byte [ 0F ]
.text win32k.sys!EngQueryPalette + 52 BF9392F5 70 Bytes [ 0D, 60, 4D, 9A, BF, 89, 4B, ... ]
.text win32k.sys!EngQueryPalette + 99 BF93933C 22 Bytes CALL BF801943 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!EngQueryPalette + B0 BF939353 11 Bytes [ 00, 90, 90, 90, 90, 90, 8B, ... ]
.text win32k.sys!EngCreatePath BF9395B5 3 Bytes [ 90, 90, 90 ]
.text win32k.sys!EngCreatePath + 4 BF9395B9 76 Bytes [ FF, 55, 8B, EC, F6, 45, 08, ... ]
.text win32k.sys!EngDeletePath + 2 BF939606 1 Byte [ FF ]
.text win32k.sys!EngDeletePath + 4 BF939608 4 Bytes [ BF, 80, 00, 00 ]
.text win32k.sys!EngDeletePath + 9 BF93960D 54 Bytes JMP 8504768B
.text win32k.sys!EngDeletePath + 40 BF939644 2 Bytes [ 5D, 08 ]
.text win32k.sys!EngDeletePath + 43 BF939647 83 Bytes CALL BF938F29 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!PATHOBJ_bPolyBezierTo + E BF9396F3 27 Bytes CALL BF805B8B \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!PATHOBJ_bPolyBezierTo + 2B BF939710 143 Bytes [ 83, C0, 1C, 50, 8D, 4D, 08, ... ]
.text win32k.sys!WNDOBJ_vSetConsumer + 62 BF9397A0 3 Bytes [ 4D, 10, E8 ]
.text win32k.sys!WNDOBJ_vSetConsumer + 66 BF9397A4 73 Bytes [ B3, EC, FF, FF, B3, 94, 00, ... ]
.text win32k.sys!WNDOBJ_vSetConsumer + B0 BF9397EE 9 Bytes CALL BF805AB3 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text win32k.sys!WNDOBJ_vSetConsumer + BA BF9397F8 17 Bytes [ FC, FF, 73, 30, 8D, 75, D8, ... ]
.text win32k.sys!WNDOBJ_vSetConsumer + CC BF93980A 61 Bytes [ 8B, 8B, 84, 00, 00, 00, 6A, ... ]
.text win32k.sys!EngCreateWnd + 2 BF93988A 44 Bytes CALL ACE8B777
.text win32k.sys!EngCreateWnd + 2F BF9398B7 57 Bytes [ 45, F8, 8D, 45, F8, 89, 4D, ... ]
.text win32k.sys!EngCreateWnd + 69 BF9398F1 24 Bytes [ FF, 55, 8B, EC, 83, EC, 34, ... ]
.text win32k.sys!EngCreateWnd + 82 BF93990A 23 Bytes [ 35, 60, 4D, 9A, BF, 85, F6, ... ]
.text win32k.sys!EngCreateWnd + 9A BF939922 34 Bytes [ 75, F4, 85, 46, 18, 75, 0C, ... ]
.text win32k.sys!EngDeleteWnd + 1C BF939CCC 223 Bytes [ 85, FF, 74, 0F, 89, 38, 0F, ... ]
.text win32k.sys!EngDeleteWnd + FC BF939DAC 124 Bytes [ 0C, 8D, B0, AF, 99, BF, C7, ... ]
.text win32k.sys!EngDeleteWnd + 179 BF939E29 59 Bytes [ 8B, 19, 88, 14, 18, 8D, 0C, ... ]
.text win32k.sys!EngDeleteWnd + 1B5 BF939E65 20 Bytes [ 45, 0C, 0F, 85, AC, 00, 00, ... ]
.text win32k.sys!EngDeleteWnd + 1CA BF939E7A 89 Bytes [ 40, 0C, 8D, 14, 95, 30, B0, ... ]
.text win32k.sys!EngDitherColor + 1B BF93AA0F 175 Bytes [ 00, 00, 8B, 45, 08, 89, 8F, ... ]
.text win32k.sys!EngDitherColor + CB BF93AABF 1 Byte [ FF ]
.text win32k.sys!EngDitherColor + CD BF93AAC1 2 Bytes [ 4B, 08 ]
.text win32k.sys!EngDitherColor + D0 BF93AAC4 28 Bytes [ 55, 1C, 89, 45, FC, 83, 7D, ... ]
.text win32k.sys!EngDitherColor + ED BF93AAE1 122 Bytes [ 4D, 14, 39, 08, 77, 35, 8B, ... ]
.text win32k.sys!EngEnumForms + 13 BF93B29B 11 Bytes [ 90, 90, 90, 90, 90, 8B, FF, ... ]
.text win32k.sys!EngEnumForms + 20 BF93B2A8 130 Bytes [ 8D, 4D, FC, 33, DB, E8, 4F, ... ]
.text win32k.sys!EngEnumForms + A3 BF93B32B 34 Bytes [ C3, 5B, C9, C2, 08, 00, 90, ... ]
.text win32k.sys!EngEnumForms + C6 BF93B34E 43 Bytes [ 02, 03, 00, 85, C0, 8B, 45, ... ]
.text win32k.sys!EngGetPrinter + 2