ArrowEHSvc Offsets

Posts 1–2 of 2 · Page 1 of 1
EHSvc Offsets
Hey guys today i searched some functions in EHSvc.dll and i found this here:

KeServiceDescriptorTable:
___:10097C70 jb loc_10097EA5
___:10097C81 ja loc_10097EA5
___:10097C87 jmp short loc_10097C8F
mov:
___:10097C89 mov ebx, dword_100D63F0

---------------------------------------------------------

ZwOpenProcess:
___:10097CB4 jz short loc_10097CDB
___:10097CBC jb short loc_10097CDB
___:10097CCD jbe short loc_10097CD3
mov:
___:10097CD3 mov eax, [eax+1]
___:10097CD6 mov dword_100F3B98, eax

---------------------------------------------------------

ZwReadVirtualMemory:
___:10097CF0 jz short loc_10097D17
___:10097CF8 jb short loc_10097D17
___:10097D09 jbe short loc_10097D0F
mov:
___:10097D0F mov eax, [eax+1]
___:10097D12 mov dword_100F3B9C, eax

---------------------------------------------------------

ZwWriteVirtualMemory:
___:10097D2C jz short loc_10097D53
___:10097D34 jb short loc_10097D53
___:10097D45 jbe short loc_10097D4B
mov:
___:10097D4B mov eax, [eax+1]
___:10097D4E mov dword_100F3BA0, eax

---------------------------------------------------------

ZwSuspendThread:
___:10097D68 jz short loc_10097D87
___:10097D70 jb short loc_10097D87
___:10097D81 jbe short loc_10097D87

---------------------------------------------------------

ZwTerminateThread:
___:10097D9C jz short loc_10097DBB
___:10097DA4 jb short loc_10097DBB
___:10097DB5 jbe short loc_10097DB

---------------------------------------------------------

ZwSetContextThread:
___:10097DD0 jz short loc_10097DEF
___:10097DD8 jb short loc_10097DEF
___:10097DE9 jbe short loc_10097DEF

---------------------------------------------------------

ZwGetContextThread:
___:10097E04 jz short loc_10097E2B
___:10097E0C jb short loc_10097E2B
___:10097E1D jbe short loc_10097E23
mov:
___:10097E23 mov eax, [eax+1]
___:10097E26 mov dword_100F3BA8, eax

---------------------------------------------------------

ZwQueryPerformanceCounter:
___:10097E40 jz short loc_10097E5F
___:10097E48 jb short loc_10097E5F
___:10097E59 jbe short loc_10097E5F

---------------------------------------------------------

ZwDeviceIoControlFile:
___:10097E74 jz short loc_10097E83
___:10097E7C jb short loc_10097E83
mov:
___:10097E7E mov dword_100F3BA4, eax

---------------------------------------------------------

Can i this adresses for an bypass?
I'm trying it since one half year. now its time that i get it
What u want to do with it?
Zw* looks like undocumented functions from the ntdll.dll.

u need the custom functions that are crytped..
Posts 1–2 of 2 · Page 1 of 1
This thread is closed for replies.

Similar Threads

Tags for this Thread

None

Need help?