Всем привет. Нужно собрать эти таблицы от всех версий(KernelCallbackTable, в User32.dll что юзает KiUserCallbackDispatcher). Можно вручную собирать из модулей, но думаю проще будет взять просто скопировать если есть символы. Указатель на эту таблицу находится в PEB по смещению +0x2C). У кого есть символы сопируйте сюда пожалусто таблицу(можно например под олей выделить и скопировать текст). Есть от XPSP3(сделал как инклуд): Код (Text): fnCOPYDATA equ 0 fnCOPYGLOBALDATA equ 1 fnDWORD equ 2 fnNCDESTROY equ 3 fnDWORDOPTINLPMSG equ 4 fnINOUTDRAG equ 5 fnGETTEXTLENGTHS equ 6 fnINCNTOUTSTRING equ 7 fnOUTSTRING equ 8 fnINLPCOMPAREITEMSTRUCT equ 9 fnINLPCREATESTRUCT equ 10 fnINLPDELETEITEMSTRUCT equ 11 fnINLPDRAWITEMSTRUCT equ 12 fnINLPHELPINFOSTRUCT equ 13 fnPOPTINLPUINT equ 14 fnINLPMDICREATESTRUCT equ 15 fnINOUTLPMEASUREITEMSTRUCT equ 16 fnINLPWINDOWPOS equ 17 fnINOUTLPPOINT5 equ 18 fnINOUTLPWINDOWPOS equ 19 fnINOUTLPRECT equ 20 fnINOUTNCCALCSIZE equ 21 fnINOUTLPWINDOWPOS equ 22 fnINPAINTCLIPBRD equ 23 fnINSIZECLIPBRD equ 24 fnINDESTROYCLIPBRD equ 25 fnINSTRING equ 26 fnINSTRING equ 27 fnINDEVICECHANGE equ 28 fnINOUTNEXTMENU equ 29 fnLOGONNOTIFY equ 30 fnOUTDWORDDWORD equ 31 fnOUTDWORDDWORD equ 32 fnOUTDWORDINDWORD equ 33 fnOUTLPRECT equ 34 fnOUTSTRING equ 35 fnPOPTINLPUINT equ 36 fnOUTSTRING equ 37 fnSENTDDEMSG equ 38 fnINOUTSTYLECHANGE equ 39 fnHkINDWORD equ 40 fnHkINLPCBTACTIVATESTRUCT equ 41 fnHkINLPCBTCREATESTRUCT equ 42 fnHkINLPDEBUGHOOKSTRUCT equ 43 fnHkINLPMOUSEHOOKSTRUCTEX equ 44 fnHkINLPKBDLLHOOKSTRUCT equ 45 fnHkINLPMSLLHOOKSTRUCT equ 46 fnHkINLPMSG equ 47 fnHkINLPRECT equ 48 fnHkOPTINLPEVENTMSG equ 49 ClientCopyDDEIn1 equ 50 ClientCopyDDEIn2 equ 51 ClientCopyDDEOut1 equ 52 ClientCopyDDEOut2 equ 53 ClientCopyImage equ 54 ClientEventCallback equ 55 ClientFindMnemChar equ 56 ClientFontSweep equ 57 ClientFreeDDEHandle equ 58 ClientFreeLibrary equ 59 ClientGetCharsetInfo equ 60 ClientGetDDEFlags equ 61 ClientGetDDEHookData equ 62 ClientGetListboxString equ 63 ClientGetMessageMPH equ 64 ClientLoadImage equ 65 ClientLoadLibrary equ 66 ClientLoadMenu equ 67 ClientLoadLocalT1Fonts equ 68 ClientLoadRemoteT1Fonts equ 69 ClientPSMTextOut equ 70 ClientLpkDrawTextEx equ 71 ClientExtTextOutW equ 72 ClientGetTextExtentPointW equ 73 ClientCharToWchar equ 74 ClientAddFontResourceW equ 75 ClientThreadSetup equ 76 ClientDeliverUserApc equ 77 ClientNoMemoryPopup equ 78 ClientMonitorEnumProc equ 79 ClientCallWinEventProc equ 80 ClientWaitMessageExMPH equ 81 ClientWOWGetProcModule equ 82 ClientWOWTask16SchedNotify equ 83 ClientImmLoadLayout equ 84 ClientImmProcessKey equ 85 fnIMECONTROL equ 86 fnINWPARAMDBCSCHAR equ 87 fnGETTEXTLENGTHS equ 88 fnINLPKDRAWSWITCHWND equ 89 ClientLoadStringW equ 90 ClientLoadOLE equ 91 ClientRegisterDragDrop equ 92 ClientRevokeDragDrop equ 93 fnINOUTMENUGETOBJECT equ 94 ClientPrinterThunk equ 95 fnOUTLPCOMBOBOXINFO equ 96 fnOUTLPSCROLLBARINFO equ 97
Сделал от седьмой(6.1.7100.19): Код (Text): fnCOPYDATA equ 0 fnCOPYGLOBALDATA equ 1 fnDWORD equ 2 fnNCDESTROY equ 3 fnDWORDOPTINLPMSG equ 4 fnINOUTDRAG equ 5 fnGETTEXTLENGTHS equ 6 fnINCNTOUTSTRING equ 7 fnOUTSTRING equ 8 fnINLPCOMPAREITEMSTRUCT equ 9 fnINLPCREATESTRUCT equ 10 fnINLPDELETEITEMSTRUCT equ 11 fnINLPDRAWITEMSTRUCT equ 12 fnINLPHELPINFOSTRUCT equ 13 fnPOPTINLPUINT equ 14 fnINLPMDICREATESTRUCT equ 15 fnINOUTLPMEASUREITEMSTRUCT equ 16 fnINLPWINDOWPOS equ 17 fnINOUTLPPOINT5 equ 18 fnINOUTLPWINDOWPOS equ 19 fnINOUTLPRECT equ 20 fnINOUTNCCALCSIZE equ 21 fnINOUTLPWINDOWPOS equ 22 fnINPAINTCLIPBRD equ 23 fnINSIZECLIPBRD equ 24 fnINDESTROYCLIPBRD equ 25 fnINSTRING equ 26 fnINSTRING equ 27 fnINDEVICECHANGE equ 28 fnPOWERBROADCAST equ 29 fnINOUTNEXTMENU equ 30 fnOUTDWORDDWORD equ 31 fnOUTDWORDDWORD equ 32 fnOUTDWORDINDWORD equ 33 fnOUTLPRECT equ 34 fnOUTSTRING equ 35 fnINLPHELPINFOSTRUCT equ 36 fnOUTSTRING equ 37 fnSENTDDEMSG equ 38 fnINOUTSTYLECHANGE equ 39 fnHkINDWORD equ 40 fnHkINLPCBTACTIVATESTRUCT equ 41 fnHkINLPCBTCREATESTRUCT equ 42 fnHkINLPDEBUGHOOKSTRUCT equ 43 fnHkINLPMOUSEHOOKSTRUCTEX equ 44 fnHkINLPKBDLLHOOKSTRUCT equ 45 fnHkINLPMSLLHOOKSTRUCT equ 46 fnHkINLPMSG equ 47 fnHkINLPRECT equ 48 fnHkOPTINLPEVENTMSG equ 49 ClientCopyDDEIn1 equ 50 ClientCopyDDEIn2 equ 51 ClientCopyDDEOut1 equ 52 ClientCopyDDEOut2 equ 53 ClientCopyImage equ 54 ClientEventCallback equ 55 ClientFindMnemChar equ 56 ClientFreeDDEHandle equ 57 ClientFreeLibrary equ 58 ClientGetCharsetInfo equ 59 ClientGetDDEFlags equ 60 ClientGetDDEHookData equ 61 ClientGetListboxString equ 62 ClientGetMessageMPH equ 63 ClientLoadImage equ 64 ClientLoadLibrary equ 65 ClientLoadMenu equ 66 ClientLoadLocalT1Fonts equ 67 ClientPSMTextOut equ 68 ClientLpkDrawTextEx equ 69 ClientExtTextOutW equ 70 ClientGetTextExtentPointW equ 71 ClientCharToWchar equ 72 ClientAddFontResourceW equ 73 ClientThreadSetup equ 74 ClientDeliverUserApc equ 75 ClientNoMemoryPopup equ 76 ClientMonitorEnumProc equ 77 ClientCallWinEventProc equ 78 ClientWaitMessageExMPH equ 79 ClientWOWGetProcModule equ 80 ClientWOWTask16SchedNotify equ 81 ClientImmLoadLayout equ 82 ClientImmProcessKey equ 83 fnIMECONTROL equ 84 fnINWPARAMDBCSCHAR equ 85 fnGETTEXTLENGTHS equ 86 fnINLPKDRAWSWITCHWND equ 87 ClientLoadStringW equ 88 ClientLoadOLE equ 89 ClientRegisterDragDrop equ 90 ClientRevokeDragDrop equ 91 fnINOUTMENUGETOBJECT equ 92 ClientPrinterThunk equ 93 fnOUTLPCOMBOBOXINFO equ 94 fnOUTLPSCROLLBARINFO equ 95 fnINOUTNEXTMENU equ 96 fnINLPUAHDRAWMENUITEM equ 97 fnINLPUAHINITMENU equ 98 fnINOUTLPUAHMEASUREMENUITEM equ 99 fnINLPUAHNCPAINTMENUPOPUP equ 100 fnOUTLPTITLEBARINFOEX equ 101 fnTOUCH equ 102 fnGESTURE equ 103 fnINPGESTURENOTIFYSTRUCT equ 104 Нужно от висты есчо.
Виста SP1 версия user32.dll 6.0.6001.18000 вроде правильно Код (Text): fnCOPYDATA equ 0 fnCOPYGLOBALDATA equ 1 fnDWORD equ 2 fnNCDESTROY equ 3 fnDWORDOPTINLPMSG equ 4 fnINOUTDRAG equ 5 fnGETTEXTLENGTHS equ 6 fnINCNTOUTSTRING equ 7 fnPOUTLPINT equ 8 fnINLPCOMPAREITEMSTRUCT equ 9 fnINLPCREATESTRUCT equ 10 fnINLPDELETEITEMSTRUCT equ 11 fnINLPDRAWITEMSTRUCT equ 12 fnPOPTINLPUINT equ 13 fnPOPTINLPUINT equ 14 fnINLPMDICREATESTRUCT equ 15 fnINOUTLPMEASUREITEMSTRUCT equ 16 fnINLPWINDOWPOS equ 17 fnINOUTLPPOINT5 equ 18 fnINOUTLPWINDOWPOS equ 19 fnINOUTLPRECT equ 20 fnINOUTNCCALCSIZE equ 21 fnINOUTLPWINDOWPOS equ 22 fnINPAINTCLIPBRD equ 23 fnINSIZECLIPBRD equ 24 fnINDESTROYCLIPBRD equ 25 fnINSTRINGNULL equ 26 fnINSTRINGNULL equ 27 fnINDEVICECHANGE equ 28 fnPOWERBROADCAST equ 29 fnINOUTNEXTMENU equ 30 fnOUTDWORDDWORD equ 31 fnOUTDWORDDWORD equ 32 fnOUTDWORDINDWORD equ 33 fnOUTLPRECT equ 34 fnPOUTLPINT equ 35 fnPOPTINLPUINT equ 36 fnPOUTLPINT equ 37 fnSENTDDEMSG equ 38 fnINOUTSTYLECHANGE equ 39 fnHkINDWORD equ 40 fnHkINLPCBTACTIVATESTRUCT equ 41 fnHkINLPCBTCREATESTRUCT equ 42 fnHkINLPDEBUGHOOKSTRUCT equ 43 fnHkINLPMOUSEHOOKSTRUCTEX equ 44 fnHkINLPKBDLLHOOKSTRUCT equ 45 fnHkINLPMSLLHOOKSTRUCT equ 46 fnHkINLPMSG equ 47 fnHkINLPRECT equ 48 fnHkOPTINLPEVENTMSG equ 49 ClientCopyDDEIn1 equ 50 ClientCopyDDEIn2 equ 51 ClientCopyDDEOut1 equ 52 ClientCopyDDEOut2 equ 53 ClientCopyImage equ 54 ClientEventCallback equ 55 ClientFindMnemChar equ 56 ClientFontSweep equ 57 ClientFreeDDEHandle equ 58 ClientFreeLibrary equ 59 ClientGetCharsetInfo equ 60 ClientGetCharsetInfo equ 61 ClientGetDDEHookData equ 62 ClientGetListboxString equ 63 ClientGetMessageMPH equ 64 ClientLoadImage equ 65 ClientLoadLibrary equ 66 ClientLoadMenu equ 67 ClientLoadLocalT1Fonts equ 68 ClientLoadRemoteT1Fonts equ 69 ClientPSMTextOut equ 70 ClientLpkDrawTextEx equ 71 ClientExtTextOutW equ 72 ClientGetTextExtentPointW equ 73 ClientCharToWchar equ 74 ClientAddFontResourceW equ 75 ClientThreadSetup equ 76 ClientDeliverUserApc equ 77 ClientNoMemoryPopup equ 78 ClientMonitorEnumProc equ 79 ClientCallWinEventProc equ 80 ClientWaitMessageExMPH equ 81 ClientWOWGetProcModule equ 82 ClientWOWTask16SchedNotify equ 83 ClientImmLoadLayout equ 84 ClientImmProcessKey equ 85 fnIMECONTROL equ 86 fnINWPARAMDBCSCHAR equ 87 fnGETTEXTLENGTHS equ 88 fnINLPKDRAWSWITCHWND equ 89 ClientLoadStringW equ 90 ClientLoadOLE equ 91 ClientRegisterDragDrop equ 92 ClientRevokeDragDrop equ 93 fnINOUTMENUGETOBJECT equ 94 ClientPrinterThunk equ 95 fnOUTLPCOMBOBOXINFO equ 96 fnOUTLPSCROLLBARINFO equ 97 fnINOUTNEXTMENU equ 98 fnINLPUAHDRAWMENUITEM equ 99 fnINOUTNEXTMENU equ 100 fnINOUTLPUAHMEASUREMENUITEM equ 101 fnINOUTNEXTMENU equ 102 fnOUTLPTITLEBARINFOEX equ 103
Объясните пожалуйста, что такое User32!apfnDispatch и где его искать? А так же - что означает следующая строка: apfnDispatch(PEB.KernelCallbackTable) Где можно найти информацию о структуре KernelCallbackTable?