As dbghelp.chm says:
DWORD64 WINAPI SymLoadModuleEx(
__in HANDLE hProcess,
__in HANDLE hFile,
__in PCTSTR ImageName,
__in PCTSTR ModuleName,
__in DWORD64 BaseOfDll,
__in DWORD DllSize,
__in PMODLOAD_DATA Data,
__in DWORD Flags
);
CPU Disasm
Address Hex dump Command
Comments
00401356 |. B9 00000000 MOV ECX,0
0040135B |. 51 PUSH ECX ; /Arg9
=> 0
0040135C |. B9 00000000 MOV ECX,0 ; |
00401361 |. 51 PUSH ECX ; |Arg8
=> 0
00401362 |. 8B8D D4FDFFFF MOV ECX,DWORD PTR SS:[LOCAL.139] ; |
00401368 |. 51 PUSH ECX ; |Arg7
=> [LOCAL.139]
00401369 |. 8985 D0FDFFFF MOV DWORD PTR SS:[LOCAL.140],EAX ; |
0040136F |. 8B8D F0FEFFFF MOV ECX,DWORD PTR SS:[LOCAL.68] ; |
00401375 |. 8B85 F4FEFFFF MOV EAX,DWORD PTR SS:[LOCAL.67] ; |
0040137B |. 50 PUSH EAX ; |Arg6
=> [LOCAL.67]
0040137C |. 51 PUSH ECX ; |Arg5
=> [LOCAL.68]
0040137D |. B8 00000000 MOV EAX,0 ; |
00401382 |. 50 PUSH EAX ; |Arg4
=> 0
00401383 |. 8B85 D0FDFFFF MOV EAX,DWORD PTR SS:[LOCAL.140] ; |
00401389 |. 8B00 MOV EAX,DWORD PTR DS:[EAX] ; |
0040138B |. 50 PUSH EAX ; |Arg3
0040138C |. B8 00000000 MOV EAX,0 ; |
00401391 |. 50 PUSH EAX ; |Arg2
=> 0
00401392 |. 8B45 FC MOV EAX,DWORD PTR SS:[LOCAL.1] ; |
00401395 |. 50 PUSH EAX ; |Arg1
=> [LOCAL.1]
00401396 |. E8 CD020000 CALL <JMP.&dbghelp.SymLoadModuleEx> ;
\dbghelp.SymLoadModuleEx
0040139B |. 8985 E8FEFFFF MOV DWORD PTR SS:[LOCAL.70],EAX
004013A1 |. 8995 ECFEFFFF MOV DWORD PTR SS:[LOCAL.69],EDX
Can any body help?