I haven't written anything for a long time ~~ :
> Ssdt state
Ntclose
Actual address 0xf0389268
Hooked by: C: \ ollydbg \ plugin \ whlsod. sys
Ntcreateprocess
Actual address 0xf03892c8
Hooked by: C: \ ollydbg \ plugin \ whlsod. sys
Ntduplicateobject
Actual address 0xf03891e8
Hooked by: C: \ ollydbg \ plugin \ whlsod. sys
Ntopenprocess
Actual address 0xf0388e18
Hooked by: C: \ ollydbg \ plugin \ whlsod. sys
Ntopenthread
Actual address 0xf0388f28
Hooked by: C: \ ollydbg \ plugin \ whlsod. sys
Ntqueryinformationprocess
Actual address 0xf0389068
Hooked by: C: \ ollydbg \ plugin \ whlsod. sys
Ntqueryobject
Actual address 0xf0388d78
Hooked by: C: \ ollydbg \ plugin \ whlsod. sys
Ntquerysysteminformation
Actual address 0xf0388988
Hooked by: C: \ ollydbg \ plugin \ whlsod. sys
Ntsetinformationthread
Actual address 0xf0389018
Hooked by: C: \ ollydbg \ plugin \ whlsod. sys
Ntyieldexecution
Actual address 0xf0388e08
Hooked by: C: \ ollydbg \ plugin \ whlsod. sys
> Shadow
Ntuserbuildhwndlist
Actual address 0xf0389558
Hooked by: C: \ ollydbg \ plugin \ whlsod. sys
Ntuserfind1_wex
Actual address 0xf0389718
Hooked by: C: \ ollydbg \ plugin \ whlsod. sys
Ntusergetforegroundwindow
Actual address 0xf03897a8
Hooked by: C: \ ollydbg \ plugin \ whlsod. sys
Ntuserpostmessage
Actual address 0xf0389518
Hooked by: C: \ ollydbg \ plugin \ whlsod. sys
Ntuserquerywindow
Actual address 0xf0389478
Hooked by: C: \ ollydbg \ plugin \ whlsod. sys
Ntusersetparent
Actual address 0xf0389838
Hooked by: C: \ ollydbg \ plugin \ whlsod. sys
> Hooks
2017104420.ollydbg.exe --> kernel32.dll --> continuedebugevent, type: IAT modification 0x0050d2b8
[Strongod. dll]
2017104420.ollydbg.exe --> kernel32.dll --> createprocessa, type: IAT modification 0x0050d2c4
[Strongod. dll]
2017104420.ollydbg.exe --> kernel32.dll --> debugactiveprocess, type: IAT modification 0x0050d2c8
[Strongod. dll]
2017104420.ollydbg.exe --> kernel32.dll --> getprocaddress, type: IAT modification 0x0050d344
[Strongod. dll]
2017104420.ollydbg.exe --> kernel32.dll --> multibytetowidechar, type: IAT modification 0x0050d3c8
[Strongod. dll]
2017104420.ollydbg.exe --> kernel32.dll --> waitfordebugevent, type: IAT modification 0x0050d440
[Strongod. dll]
2017104420.ollydbg.exe --> NTDLL. dll --> ntcreateprocess, type: inline-relativejump 0x7c92d754
[Strongod. dll]
2017104420.ollydbg.exe --> NTDLL. dll --> ntcreateprocessex, type: inline-relativejump 0x7c92d769
[Strongod. dll]
2017104420.ollydbg.exe --> user32.dll --> createmdi0000wa, type: IAT modification 0x0050d7f4
[Strongod. dll]
2017104420.ollydbg.exe --> user32.dll --> dialogboxparama, type: IAT modification 0x0050d81c [strongod. dll]
2017104420.ollydbg.exe --> user32.dll --> enumchildwindows, type: IAT modification 0x0050d83c
[Strongod. dll]
2017104420.ollydbg.exe --> user32.dll --> getclasslonga, type: IAT modification 0x0050d858 [strongod. dll]
2017104420.ollydbg.exe --> user32.dll --> getwindowlonga, type: IAT modification 0x0050d8b0 [strongod. dll]
2017104420.ollydbg.exe --> user32.dll --> getwindowtexta, type: inline-relativejump 0x77d3212b
[Unknown_code_page]
2017104420.ollydbg.exe --> user32.dll --> registerclassa, type: IAT modification 0x0050d920 [strongod. dll]
2017104420.ollydbg.exe --> user32.dll --> setwindowtexta, type: IAT modification 0x0050d96c [strongod. dll]
There is also one CreateProcess notfiy