ó
Î )Pc           @   sl  d  Z  d d l Td d l Td Z d Z d Z d Z d Z e e Be Be BZ d e	 f d	 „  ƒ  YZ
 d
 e	 f d „  ƒ  YZ d e	 f d „  ƒ  YZ d e	 f d „  ƒ  YZ d e	 f d „  ƒ  YZ d e	 f d „  ƒ  YZ d e	 f d „  ƒ  YZ d e	 f d „  ƒ  YZ d Z d Z d Z d Z d Z d Z d Z d Z d Z d Z d Z d Z d  Z d! Z d Z  d" Z! d Z" d# Z# d$ Z$ d% Z% d& Z& d' Z' d( Z( d# Z) d Z* d Z+ d) Z, d* Z- d+ Z. d Z/ d* Z0 d, Z1 d- Z2 d, Z3 d. Z4 d/ Z5 d0 Z6 d Z7 d Z8 d Z9 d Z: d& Z; d1 Z< d2 Z= d3 Z> d* Z? d4 Z@ d5 ZA d6 ZB d ZC d ZD d7 ZE d1 ZF d ZG d8 ZH d& ZI d9 ZJ d ZK d: ZL d ZM d ZN d; S(<   s™   
@author:       Pedram Amini
@license:      GNU General Public License 2.0 or later
@contact:      pedram.amini@gmail.com
@organization: www.openrce.org
iÿÿÿÿ(   t   *i   i   i   i   l        t   THREADENTRY32c           B   sM   e  Z d  e f d e f d e f d e f d e f d e f d e f g Z RS(   t   dwSizet   cntUsaget   th32ThreadIDt   th32OwnerProcessIDt	   tpBasePrit
   tpDeltaPrit   dwFlags(   t   __name__t
   __module__t   DWORDt   _fields_(    (    (    s
   defines.pyR   2   s   						t   PROCESSENTRY32c           B   sl   e  Z d  e f d e f d e f d e f d e f d e f d e f d e f d e f d	 e d
 f g
 Z RS(   R   R   t   th32ProcessIDt   th32DefaultHeapIDt   th32ModuleIDt
   cntThreadst   th32ParentProcessIDt   pcPriClassBaseR   t	   szExeFilei  (   R	   R
   R   t   CHARR   (    (    (    s
   defines.pyR   =   s   									t   MODULEENTRY32c           B   sp   e  Z d  e f d e f d e f d e f d e f d e f d e f d e f d e d	 f d
 e d f g
 Z RS(   R   R   R   t   GlblcntUsaget   ProccntUsaget   modBaseAddrt   modBaseSizet   hModulet   szModulei   t	   szExePathi  (   R	   R
   R   R   R   (    (    (    s
   defines.pyR   K   s   								t   _MIB_TCPROW_OWNER_PIDc           B   sD   e  Z d  e f d e f d e f d e f d e f d e f g Z RS(   t   dwStatet   dwLocalAddrt   dwLocalPortt   dwRemoteAddrt   dwRemotePortt   dwOwningPid(   R	   R
   R   R   (    (    (    s
   defines.pyR   Y   s   					t   MIB_TCPTABLE_OWNER_PIDc           B   s$   e  Z d  e f d e d f g Z RS(   t   dwNumEntriest   tablei   (   R	   R
   R   R   R   (    (    (    s
   defines.pyR%   c   s   	t   _MIB_UDPROW_OWNER_PIDc           B   s)   e  Z d  e f d e f d e f g Z RS(   R    R!   R$   (   R	   R
   R   R   (    (    (    s
   defines.pyR(   j   s   		t   MIB_UDPTABLE_OWNER_PIDc           B   s$   e  Z d  e f d e d f g Z RS(   R&   R'   i   (   R	   R
   R   R(   R   (    (    (    s
   defines.pyR)   q   s   	t
   SYSDBG_MSRc           B   s    e  Z d  e f d e f g Z RS(   t   Addresst   Data(   R	   R
   t   c_ulongt   c_ulonglongR   (    (    (    s
   defines.pyR*   |   s   	i   i   i   i   i	   l   ï>[= l       l       l       l       i    i  i  i  i   i  l      i   i   i   i   l   ÿÿ i @  i   i €  i    i@   i€   i   i   iÿ iÿ i 0  i   i   N(O   t   __doc__t	   my_ctypest	   windows_ht   TH32CS_SNAPHEAPLISTt   TH32CS_SNAPPROCESSt   TH32CS_SNAPTHREADt   TH32CS_SNAPMODULEt   TH32CS_INHERITt   TH32CS_SNAPALLt	   StructureR   R   R   R   R%   R(   R)   R*   t   EXCEPTION_DEBUG_EVENTt   CREATE_THREAD_DEBUG_EVENTt   CREATE_PROCESS_DEBUG_EVENTt   EXIT_THREAD_DEBUG_EVENTt   EXIT_PROCESS_DEBUG_EVENTt   LOAD_DLL_DEBUG_EVENTt   UNLOAD_DLL_DEBUG_EVENTt   OUTPUT_DEBUG_STRING_EVENTt	   RIP_EVENTt   USER_CALLBACK_DEBUG_EVENTt   EXCEPTION_ACCESS_VIOLATIONt   EXCEPTION_BREAKPOINTt   EXCEPTION_GUARD_PAGEt   EXCEPTION_SINGLE_STEPt	   HW_ACCESSt
   HW_EXECUTEt   HW_WRITEt   CONTEXT_CONTROLt   CONTEXT_FULLt   CONTEXT_DEBUG_REGISTERSt   CREATE_NEW_CONSOLEt   DBG_CONTINUEt   DBG_EXCEPTION_NOT_HANDLEDt   DBG_EXCEPTION_HANDLEDt   DEBUG_PROCESSt   DEBUG_ONLY_THIS_PROCESSt	   EFLAGS_RFt   EFLAGS_TRAPt   ERROR_NO_MORE_FILESt   FILE_MAP_READt   FORMAT_MESSAGE_ALLOCATE_BUFFERt   FORMAT_MESSAGE_FROM_SYSTEMt   INVALID_HANDLE_VALUEt
   MEM_COMMITt   MEM_DECOMMITt	   MEM_IMAGEt   MEM_RELEASEt   PAGE_NOACCESSt   PAGE_READONLYt   PAGE_READWRITEt   PAGE_WRITECOPYt   PAGE_EXECUTEt   PAGE_EXECUTE_READt   PAGE_EXECUTE_READWRITEt   PAGE_EXECUTE_WRITECOPYt
   PAGE_GUARDt   PAGE_NOCACHEt   PAGE_WRITECOMBINEt   PROCESS_ALL_ACCESSt   SE_PRIVILEGE_ENABLEDt   SW_SHOWt   THREAD_ALL_ACCESSt   TOKEN_ADJUST_PRIVILEGESt   UDP_TABLE_OWNER_PIDt   VIRTUAL_MEMt   SysDbgReadMsrt   SysDbgWriteMsrt   AF_INETt   AF_INET6t   MIB_TCP_STATE_LISTENt   TCP_TABLE_OWNER_PID_ALL(    (    (    s
   defines.pyt   <module>"   sš   


