Min versionXP
Max version10 TH2
x86 offset
offset:bitpos
Field Name
0x0000struct _UNICODE_STRING
DosPath
0x0008void *
Handle