只判断这个搜不全吧?
INIT:00103E93 mov dword ptr [esi+7Ch], offset _NtfsFsdLockControl@8 ; NtfsFsdLockControl(x,x)
INIT:00103E9A mov dword ptr [esi+68h], offset _NtfsFsdDirectoryControl@8 ; NtfsFsdDirectoryControl(x,x)
INIT:00103EA1 mov dword ptr [esi+50h], offset _NtfsFsdSetInformation@8 ; NtfsFsdSetInformation(x,x)
INIT:00103EA8 mov dword ptr [esi+38h], offset _NtfsFsdCreate@8 ; NtfsFsdCreate(x,x)
INIT:00103EAF mov dword ptr [esi+40h], offset _NtfsFsdClose@8 ; NtfsFsdClose(x,x)
INIT:00103EB6 mov dword ptr [esi+44h], offset _NtfsFsdRead@8 ; NtfsFsdRead(x,x)
INIT:00103EBD mov dword ptr [esi+48h], offset _NtfsFsdWrite@8 ; NtfsFsdWrite(x,x)
INIT:00103EC4 mov dword ptr [esi+5Ch], offset _NtfsFsdFlushBuffers@8 ; NtfsFsdFlushBuffers(x,x)
INIT:00103ECB mov dword ptr [esi+6Ch], offset _NtfsFsdFileSystemControl@8 ; NtfsFsdFileSystemControl(x,x)
INIT:00103ED2 mov dword ptr [esi+80h], offset _NtfsFsdCleanup@8 ; NtfsFsdCleanup(x,x)
INIT:00103EDC mov dword ptr [esi+78h], offset _NtfsFsdShutdown@8 ; NtfsFsdShutdown(x,x)
INIT:00103EE3 mov dword ptr [esi+0A4h], offset _NtfsFsdPnp@8 ; NtfsFsdPnp(x,x)
INIT:00103EED mov dword ptr [esi+70h], offset _NtfsFsdDeviceControl@8 ; NtfsFsdDeviceControl(x,x)
INIT:00103EF4 mov dword ptr [esi+28h], offset _NtfsFastIoDispatch
INIT:00103EFB mov eax, offset _NtfsFsdDispatchWait@8 ; NtfsFsdDispatchWait(x,x)
INIT:00103F00 mov [esi+4Ch], eax
INIT:00103F03 mov [esi+0A0h], eax
INIT:00103F09 mov [esi+9Ch], eax
INIT:00103F0F mov [esi+58h], eax
INIT:00103F12 mov [esi+54h], eax
INIT:00103F15 mov eax, offset _NtfsFsdDispatch@8 ; NtfsFsdDispatch(x,x)
INIT:00103F1A mov [esi+64h], eax
INIT:00103F1D mov [esi+60h], eax
INIT:00103F20 mov [esi+8Ch], eax
INIT:00103F26 mov [esi+88h], eax
后面还有俩函数呢~~~当然搜到也很容易啦~~xp&vista下反正都没变,win7没看过