这里要用到一个 Windbg 命令:x user32!*
X [模块名] ![函数名/*]
解释:
X :表示查询的意识
x user32!MessageBXA 表示在User32 中查询函数MessageBoxA
x user32!* 表示查询所有语句 和SQL 中 * 的意思一样的
如果一个函数名称不记得全部了 你也可以,用部分匹配的方式去查找,如:
x user32!Message*
结果为以Message开始的函数都会列出来!
0:000> x user32!*
76b7729c USER32!GetClassInfoExA =
76b87bc9 USER32!NtUserInvalidateRect =
76b9776d USER32!_ClientCopyDDEIn2 =
76bd112d USER32!SvSpontUnadvise =
76b93a04 USER32!ImeWndProcA =
76bbc20b USER32!ShowStartGlass =
76bd9e1c USER32!pfnWowGetProcModule =
76ba6c53 USER32!NtUserMapVirtualKeyEx =
76b7109c USER32!_imp___allmul =
76ba572b USER32!__fnOUTLPRECT =
76bc0c7c USER32!TabbedTextOutA =
76b713b4 USER32!_imp__GlobalHandle =
76bd573b USER32!MirrorWindowRect =
76bc1529 USER32!UT_PrevGroupItem =
76b71380 USER32!_imp__FindResourceExA =
76b72676 USER32!NtUserSetInformationThread =
76b9990f USER32!ECGetControlBrush =
76b71344 USER32!_imp__InterlockedIncrement =
76b83a4d USER32!InitUserApiHook =
76b9d989 USER32!LBSetCItemFullMax =
76bd653a USER32!_imp_load__PowerGetActiveScheme =
76b751a4 USER32!__ClientLoadImage =
76bd9004 USER32!_imp__ReportEventW =
76b7268a USER32!NtUserLockWindowStation =
76ba29b4 USER32!ArrangeIconicWindows =
76b712c4 USER32!_imp__SetLayoutWidth =
76b8fc4a USER32!_DllMainCRTStartupForGS2 =
76b71004 USER32!_imp__RtlSetLastWin32Error =
76b71010 USER32!_imp___wtoi =
76bc7a38 USER32!szEXECHELP =
76bb40d0 USER32!szEMISeverity =
76b7389d USER32!NtUserUpdatePerUserSystemParameters =
76b714c0 USER32!_imp__GlobalUnlock =
76b714ac USER32!_imp__RegSetValueExW =
76b820f6 USER32!NtUserSetWindowsHookEx =
76b75678 USER32!ScaleProc =
76bd2e57 USER32!AbandonTransaction =
76b87a64 USER32!SetPropW =
76bd4d71 USER32!NtUserMNDragLeave =
76b98683 USER32!__fnHkINLPCBTACTIVATESTRUCT =
76bd98e0 USER32!DialogLookaside =
76b714dc USER32!_imp__FreeLibrary =
76ba49e6 USER32!NtUserGetCaretPos =
76bd4bb9 USER32!NtUserGetImeHotKey =
76bc2cf4 USER32!ECUpdateFormat =
76bbc19f USER32!RegisterUserHungAppHandlers =
76b90b81 USER32!UninitializeTouchInfoList =
76ba5e25 USER32!IsAnyGestureMessage =
76b933b1 USER32!MLReplaceSel =
76b79111 USER32!ResetMessagePumpHook =
76bc8217 USER32!LBPrintCallback =
76ba3e3d USER32!SetPropA =
76bd4e5f USER32!NtUserResolveDesktopForWOW =
76b7807c USER32!InitializeIcs =
76bc521c USER32!SLGetBlkEnd =
76b7a6db USER32!__fnINSTRING =
76b810e1 USER32!InitClsMenuNameW =
76b86d34 USER32!NtUserSBGetParms =
76b892b9 USER32!NtUserValidateTimerCallback =
76bd4dfb USER32!NtUserRealChildWindowFromPoint =
76ba055a USER32!IsVisible =
76b7d16a USER32!__fnINOUTNEXTMENU =
76b7e58f USER32!GetCurrentThreadDesktopWindow =
76ba4870 USER32!MapDialogRect =
76b82e8a USER32!GetClassInfoW =
76bca8a5 USER32!LBSetTabStops =
76b86d80 USER32!IsDPIAbsoluteSysMet =
76b7e4a3 USER32!InitClsMenuNameA =
76bbd29c USER32!DialogBoxIndirectParamA =
76bd9a00 USER32!fFontAssocStatus =
76bcc0bd USER32!LoadOLEOnce =
76bd9098 USER32!gcxGray =
76bb1e8c USER32!szMS_POPUPHELP =
76b7a4d0 USER32!CopyImage =
76bbe261 USER32!DlgDirListComboBoxW =
76ba0327 USER32!xxxLBoxDeleteItem =
76bbb19b USER32!AllocGestureDataCopy =
76bcee1d USER32!GetClassWOWWords =
76b8325e USER32!DefWindowProcWorker =
76bbc9e0 USER32!GUID_VIDEO_SUBGROUP =
76bd0803 USER32!DwmSetRedirSurfacePresentFlags =
76bd3b03 USER32!AppendMenuA =
76b8f2ca USER32!CategoryMaskFromEvent =
76bcf20c USER32!OemToCharBuffW =
76bd5a88 USER32!aGeneralPunctuation_EndBreak =
76b716fd USER32!CreateDesktopW =
76bccad0 USER32!szEventMsgFile =
76b9a57c USER32!ButtonWndProcWorker =
76bd07cb USER32!DwmGetRedirSurfacePresentFlags =
76bd37b6 USER32!DdeQueryConvInfo =
76b956bc USER32!PaintRect =
76bd645c USER32!RtlUnwind =
76b710a0 USER32!_imp__RtlUnicodeToMultiByteSize =
76bd551d USER32!RemoveGaps =
76b78dfe USER32!wcsncpycch =
76bbcfd6 USER32!GetIconInfoExW =
76ba244f USER32!ListBoxWndProcA =
76b712b0 USER32!_imp__EnableEUDC =
76b8088e USER32!RegisterDefaultClass =
76bcc4b6 USER32!MonitorStringHandle =
76b83e7b USER32!NtUserUpdateInputContext =
76bc13fb USER32!_ClientGetDDEFlags =
76b7612e USER32!CheckMenuItem =
76b95aa9 USER32!NtUserSfmDxOpenSwapChain =
76bd58c6 USER32!UserIsFELineBreakEnd =
76bb955c USER32!xxxBNGetDC =
76b9fee5 USER32!xxxCBSetDroppedSize =
76ba1bd0 USER32!SetScrollPos =
76bccfe2 USER32!MB_UpdateDlgHdr =
76b9dc9a USER32!xxxSetLBScrollParms =
76ba0490 USER32!CopyAcceleratorTableA =
76ba5b2a USER32!__ClientExtTextOutW =
76b9bd74 USER32!xxxLBPaint =
76bd90d0 USER32!hmodUser =
76b9feae USER32!xxxCBPosition =
76b86a30 USER32!SetRect =
76b91d29 USER32!MLSetTabStops =
76bcece0 USER32!fnCOPYGLOBALDATA =
76bce8c9 USER32!MessageBoxIndirectA =
76bd41af USER32!dummyImmGetOpenStatus =
76b717d9 USER32!NtUserCreateDesktopEx =
76bbc9f0 USER32!GUID_VIDEO_POWERDOWN_TIMEOUT =
76ba252b USER32!GetScrollPos =
76b9159f USER32!Scale824 =
76bd9100 USER32!g_pfnImeWndProcW =
76b76e57 USER32!GetProcAddress =
76b7f5e5 USER32!HowManyColors =
76b7be96 USER32!dummyImmSetCompositionFontA =
76bbc1d8 USER32!SetCursorPos =
76b87b9b USER32!NtUserDispatchMessage =
76bbf412 USER32!__fnINCNTOUTSTRING =
76b71090 USER32!_imp__CsrClientCallServer =
76bd9ee0 USER32!szERROR =
76b82280 USER32!EnumDisplaySettingsW =
76b86632 USER32!SetScrollInfo =
76b874b1 USER32!GetClientRect =
76bd9e24 USER32!ghinstOLE =
76b994cd USER32!IsCharUpperW =
76b7d656 USER32!PostMessageA =
76bd9108 USER32!__security_cookie =
76b84a30 USER32!ImeNotifyHandler =
76b91456 USER32!BltColor =
76b76d9a USER32!_tailMerge_CFGMGR32_dll =
76b78b28 USER32!GetSizeDialogTemplate =
76bc88c4 USER32!xxxLBoxCaretBlinker =
76b983a8 USER32!EnumDisplaySettingsA =
76b71174 USER32!_imp__GetMapMode =
76b8f319 USER32!__security_check_cookie =
76bd41af USER32!dummyImmWINNLSGetEnableStatus =
76b93826 USER32!MLDeleteText =
76b73f22 USER32!CliReadRegistryValue =
76b71210 USER32!_imp__GetTextMetricsW =
76bbf35b USER32!__fnINPGESTURENOTIFYSTRUCT =
76ba5a25 USER32!CopyIcon =
76b86225 USER32!PostMessageW =
76bd21b6 USER32!IsCharUpperA =
76b71370 USER32!_imp__SizeofResource =
76b7c921 USER32!IsWindowEnabled =
76b7a774 USER32!InternalFindWindowExA =
76ba386d USER32!EnableScrollBar =
76bd1c16 USER32!SvRespAdviseDataAck =
76b9343d USER32!MLInsertText =
76b7bea0 USER32!SplFreeResource =
76b7d488 USER32!GetQueueStatus =
76b81829 USER32!__fnINLPWINDOWPOS =
76bd41af USER32!dummyImmLockImeDpi =
76b868fe USER32!InternalGetWindowText =
76bbd50b USER32!GetTouchInputInfoWorker =
76b99323 USER32!CreateIcoCurIndirect =
76bd0659 USER32!GetReasonTitleFromReasonCode =
76bd2642 USER32!DeleteLinkCount =
76ba229e USER32!ShowWindowNoRepaint =
76b87c4b USER32!DT_DrawStr =
76b80351 USER32!GetBestImage =
76b88409 USER32!GetSystemMetrics =
76b819c3 USER32!ULongLongToUInt =
76bc0d3c USER32!GetTabbedTextExtentA =
76b95eba USER32!wvsprintfW =
76b7d5ef USER32!NtUserDestroyWindow =
76bc7167 USER32!PrivateExtractIconExA =
76b76c25 USER32!DoCallback =
76b86614 USER32!SetWindowLongW =
76bd9130 USER32!pfnFindResourceExA =
76b9978a USER32!ECGetEditDC =
76bd903c USER32!_imp__PowerWriteDCValueIndex =
76bc0d12 USER32!GetTabbedTextExtentW =
76b7e7a9 USER32!GetCurrentThreadDesktopHwnd =
76b7146c USER32!_imp__QueryPerformanceCounter =
76bbbec3 USER32!TellWOWThehDlg =
76b809ae USER32!RtlGetExpWinVer =
76bd9128 USER32!pfnFindResourceExW =
76b967b4 USER32!SendNotifyMessageA =
76b71110 USER32!_imp__RtlFindActivationContextSectionString =
76b7fde8 USER32!GetAppCompatFlags =
76b7406c USER32!_LoadKeyboardLayoutEx =
76b9b454 USER32!CBNcCreateHandler =
76ba1b58 USER32!NtUserGetUpdateRgn =
76b91c9a USER32!MLSize =
76b74cd1 USER32!Scale424 =
76bbf153 USER32!__fnSENTDDEMSG =
76bc2ca6 USER32!DbcsCombine =
76b7c184 USER32!NtUserIsTopLevelWindow =
76b88650 USER32!_SEH_epilog4 =
76b7e18a USER32!CreateWindowExA =
76b714d0 USER32!_imp__GlobalDeleteAtom =
76b713c8 USER32!_imp__GetCPInfo =
76b7148c USER32!_imp__DelayLoadFailureHook =
76b713bc USER32!_imp__Sleep =
76b87915 USER32!MapWindowPoints =
76b75b6e USER32!EnumDisplayDevicesW =
76bbe5ec USER32!InitiateEnumerationProc =
76bc6055 USER32!SLSetFocus =
76bba9db USER32!Map8 =
76b864f8 USER32!AdjustWindowRectEx =
76bc7927 USER32!LaunchHelp =
76bca18a USER32!DlgDirSelectExW =
76b872e1 USER32!RealDefWindowProcW =
76b7107c USER32!_imp__CsrFreeCaptureBuffer =
76ba0208 USER32!LBGetItemRect =
76bd99fc USER32!gphn =
76bbc132 USER32!SetProgmanWindow =
76bbcf28 USER32!ScrollBarWndProcA =
76b7fc1e USER32!PathIsUNC =
76b7f283 USER32!LoadCursorW =
76b86e81 USER32!IsDPIDWMSysMet =
76ba6189 USER32!PathFindFileName =
76b7241d USER32!IsTestSigningEnabled =
76bd4e37 USER32!NtUserRegisterTasklist =
76b84b56 USER32!NtUserSetImeOwnerWindow =
76b7dfbd USER32!CharPrevA =
76b8335a USER32!CalcWakeMask =
76ba1833 USER32!DrawIcon =
76bd418b USER32!dummyImmNotifyIME =
76b738d7 USER32!GetCursorBitCount =
76bd9eb0 USER32!gatomReaderMode =
76b9d301 USER32!DrawFrameControl =
76bd629a USER32!dummyCtfImmHideToolbarWnd =
76b83ef8 USER32!AllocateFromZone =
76ba3de1 USER32!RemovePropA =
76bcd5cb USER32!MB_AddPushButtons =
76b97a16 USER32!InternalDdeQueryString =
76bd908c USER32!gcyGray =
76b966dc USER32!szMS_WINHELP =
76bc2b5c USER32!ECCopy =
76b93677 USER32!MLSetSelection =