advapi32.dll

Description: Advanced Windows 32 Base API

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.6328

Architecture: 64-bit

Operating System: Windows NT

SHA256: bde5f0e6f36a706a8a2e0fab1b362eea

File Size: 695.6 KB

Uploaded At: Dec. 1, 2025, 7:21 a.m.

Views: 28

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • (Ordinal: 1000, Address: 0x3ae00)
  • I_ScGetCurrentGroupStateW (Ordinal: 1001, Address: 0x2fee0)
  • A_SHAFinal (Ordinal: 1002, Address: 0x97c9e)
  • A_SHAInit (Ordinal: 1003, Address: 0x97cb9)
  • A_SHAUpdate (Ordinal: 1004, Address: 0x97cd5)
  • AbortSystemShutdownA (Ordinal: 1005, Address: 0x45280)
  • AbortSystemShutdownW (Ordinal: 1006, Address: 0x45320)
  • AccessCheck (Ordinal: 1007, Address: 0x4470)
  • AccessCheckAndAuditAlarmA (Ordinal: 1008, Address: 0x48c60)
  • AccessCheckAndAuditAlarmW (Ordinal: 1009, Address: 0x305b0)
  • AccessCheckByType (Ordinal: 1010, Address: 0x308d0)
  • AccessCheckByTypeAndAuditAlarmA (Ordinal: 1011, Address: 0x48e10)
  • AccessCheckByTypeAndAuditAlarmW (Ordinal: 1012, Address: 0x30630)
  • AccessCheckByTypeResultList (Ordinal: 1013, Address: 0x30850)
  • AccessCheckByTypeResultListAndAuditAlarmA (Ordinal: 1014, Address: 0x48ff0)
  • AccessCheckByTypeResultListAndAuditAlarmByHandleA (Ordinal: 1015, Address: 0x491d0)
  • AccessCheckByTypeResultListAndAuditAlarmByHandleW (Ordinal: 1016, Address: 0x306e0)
  • AccessCheckByTypeResultListAndAuditAlarmW (Ordinal: 1017, Address: 0x307a0)
  • AddAccessAllowedAce (Ordinal: 1018, Address: 0x17110)
  • AddAccessAllowedAceEx (Ordinal: 1019, Address: 0x17920)
  • AddAccessAllowedObjectAce (Ordinal: 1020, Address: 0x30950)
  • AddAccessDeniedAce (Ordinal: 1021, Address: 0x30990)
  • AddAccessDeniedAceEx (Ordinal: 1022, Address: 0x30970)
  • AddAccessDeniedObjectAce (Ordinal: 1023, Address: 0x309b0)
  • AddAce (Ordinal: 1024, Address: 0x1afc0)
  • AddAuditAccessAce (Ordinal: 1025, Address: 0x309f0)
  • AddAuditAccessAceEx (Ordinal: 1026, Address: 0x309d0)
  • AddAuditAccessObjectAce (Ordinal: 1027, Address: 0x30a10)
  • AddConditionalAce (Ordinal: 1028, Address: 0x4ba70)
  • AddMandatoryAce (Ordinal: 1029, Address: 0x97f63)
  • AddUsersToEncryptedFile (Ordinal: 1030, Address: 0x2f730)
  • AddUsersToEncryptedFileEx (Ordinal: 1031, Address: 0x2f7b0)
  • AdjustTokenGroups (Ordinal: 1032, Address: 0x30a30)
  • AdjustTokenPrivileges (Ordinal: 1033, Address: 0x179d0)
  • AllocateAndInitializeSid (Ordinal: 1034, Address: 0x161c0)
  • AllocateLocallyUniqueId (Ordinal: 1035, Address: 0x30a50)
  • AreAllAccessesGranted (Ordinal: 1036, Address: 0x30a70)
  • AreAnyAccessesGranted (Ordinal: 1037, Address: 0x30a90)
  • AuditComputeEffectivePolicyBySid (Ordinal: 1038, Address: 0x30ab0)
  • AuditComputeEffectivePolicyByToken (Ordinal: 1039, Address: 0x33300)
  • AuditEnumerateCategories (Ordinal: 1040, Address: 0x30ad0)
  • AuditEnumeratePerUserPolicy (Ordinal: 1041, Address: 0x30af0)
  • AuditEnumerateSubCategories (Ordinal: 1042, Address: 0x30b10)
  • AuditFree (Ordinal: 1043, Address: 0x1d4c0)
  • AuditLookupCategoryGuidFromCategoryId (Ordinal: 1044, Address: 0x33460)
  • AuditLookupCategoryIdFromCategoryGuid (Ordinal: 1045, Address: 0x334a0)
  • AuditLookupCategoryNameA (Ordinal: 1046, Address: 0x33510)
  • AuditLookupCategoryNameW (Ordinal: 1047, Address: 0x30b30)
  • AuditLookupSubCategoryNameA (Ordinal: 1048, Address: 0x335c0)
  • AuditLookupSubCategoryNameW (Ordinal: 1049, Address: 0x30b50)
  • AuditQueryGlobalSaclA (Ordinal: 1050, Address: 0x33670)
  • AuditQueryGlobalSaclW (Ordinal: 1051, Address: 0x30b70)
  • AuditQueryPerUserPolicy (Ordinal: 1052, Address: 0x1d5b0)
  • AuditQuerySecurity (Ordinal: 1053, Address: 0x30b90)
  • AuditQuerySystemPolicy (Ordinal: 1054, Address: 0x1d4a0)
  • AuditSetGlobalSaclA (Ordinal: 1055, Address: 0x33730)
  • AuditSetGlobalSaclW (Ordinal: 1056, Address: 0x30bb0)
  • AuditSetPerUserPolicy (Ordinal: 1057, Address: 0x30bd0)
  • AuditSetSecurity (Ordinal: 1058, Address: 0x30bf0)
  • AuditSetSystemPolicy (Ordinal: 1059, Address: 0x30c10)
  • BackupEventLogA (Ordinal: 1060, Address: 0x52eb0)
  • BackupEventLogW (Ordinal: 1061, Address: 0x52f50)
  • BaseRegCloseKey (Ordinal: 1062, Address: 0x458a0)
  • BaseRegCreateKey (Ordinal: 1063, Address: 0x458d0)
  • BaseRegDeleteKeyEx (Ordinal: 1064, Address: 0x45940)
  • BaseRegDeleteValue (Ordinal: 1065, Address: 0x45980)
  • BaseRegFlushKey (Ordinal: 1066, Address: 0x459c0)
  • BaseRegGetVersion (Ordinal: 1067, Address: 0x459f0)
  • BaseRegLoadKey (Ordinal: 1068, Address: 0x45a30)
  • BaseRegOpenKey (Ordinal: 1069, Address: 0x45a70)
  • BaseRegRestoreKey (Ordinal: 1070, Address: 0x45ac0)
  • BaseRegSaveKeyEx (Ordinal: 1071, Address: 0x45b00)
  • BaseRegSetKeySecurity (Ordinal: 1072, Address: 0x45b40)
  • BaseRegSetValue (Ordinal: 1073, Address: 0x45b80)
  • BaseRegUnLoadKey (Ordinal: 1074, Address: 0x45bd0)
  • BuildExplicitAccessWithNameA (Ordinal: 1075, Address: 0x1d5d0)
  • BuildExplicitAccessWithNameW (Ordinal: 1076, Address: 0x1d5d0)
  • BuildImpersonateExplicitAccessWithNameA (Ordinal: 1077, Address: 0x3fe70)
  • BuildImpersonateExplicitAccessWithNameW (Ordinal: 1078, Address: 0x3fe70)
  • BuildImpersonateTrusteeA (Ordinal: 1079, Address: 0x40d30)
  • BuildImpersonateTrusteeW (Ordinal: 1080, Address: 0x40d30)
  • BuildSecurityDescriptorA (Ordinal: 1081, Address: 0x3fea0)
  • BuildSecurityDescriptorW (Ordinal: 1082, Address: 0x1cb30)
  • BuildTrusteeWithNameA (Ordinal: 1083, Address: 0x40d50)
  • BuildTrusteeWithNameW (Ordinal: 1084, Address: 0x40d50)
  • BuildTrusteeWithObjectsAndNameA (Ordinal: 1085, Address: 0x40d70)
  • BuildTrusteeWithObjectsAndNameW (Ordinal: 1086, Address: 0x40d70)
  • BuildTrusteeWithObjectsAndSidA (Ordinal: 1087, Address: 0x40dd0)
  • BuildTrusteeWithObjectsAndSidW (Ordinal: 1088, Address: 0x40dd0)
  • BuildTrusteeWithSidA (Ordinal: 1089, Address: 0x17bf0)
  • BuildTrusteeWithSidW (Ordinal: 1090, Address: 0x17bf0)
  • CancelOverlappedAccess (Ordinal: 1091, Address: 0x414e0)
  • ChangeServiceConfig2A (Ordinal: 1092, Address: 0x30c30)
  • ChangeServiceConfig2W (Ordinal: 1093, Address: 0x30c50)
  • ChangeServiceConfigA (Ordinal: 1094, Address: 0x30c70)
  • ChangeServiceConfigW (Ordinal: 1095, Address: 0x1d420)
  • CheckForHiberboot (Ordinal: 1096, Address: 0x1c0e0)
  • CheckTokenMembership (Ordinal: 1097, Address: 0x175d0)
  • ClearEventLogA (Ordinal: 1098, Address: 0x531e0)
  • ClearEventLogW (Ordinal: 1099, Address: 0x53280)
  • CloseCodeAuthzLevel (Ordinal: 1100, Address: 0x16050)
  • CloseEncryptedFileRaw (Ordinal: 1101, Address: 0x2f850)
  • CloseEventLog (Ordinal: 1102, Address: 0x1c610)
  • CloseServiceHandle (Ordinal: 1103, Address: 0x179f0)
  • CloseThreadWaitChainSession (Ordinal: 1104, Address: 0x64300)
  • CloseTrace (Ordinal: 1105, Address: 0x17d80)
  • CommandLineFromMsiDescriptor (Ordinal: 1106, Address: 0x3a70)
  • ComputeAccessTokenFromCodeAuthzLevel (Ordinal: 1107, Address: 0x13bd0)
  • ControlService (Ordinal: 1108, Address: 0x30d30)
  • ControlServiceExA (Ordinal: 1109, Address: 0x30cf0)
  • ControlServiceExW (Ordinal: 1110, Address: 0x30d10)
  • ControlTraceA (Ordinal: 1111, Address: 0x1dea0)
  • ControlTraceW (Ordinal: 1112, Address: 0x44c0)
  • ConvertAccessToSecurityDescriptorA (Ordinal: 1113, Address: 0x41550)
  • ConvertAccessToSecurityDescriptorW (Ordinal: 1114, Address: 0x416d0)
  • ConvertSDToStringSDDomainW (Ordinal: 1115, Address: 0x4c220)
  • ConvertSDToStringSDRootDomainA (Ordinal: 1116, Address: 0x4c2b0)
  • ConvertSDToStringSDRootDomainW (Ordinal: 1117, Address: 0x4c430)
  • ConvertSecurityDescriptorToAccessA (Ordinal: 1118, Address: 0x41760)
  • ConvertSecurityDescriptorToAccessNamedA (Ordinal: 1119, Address: 0x41760)
  • ConvertSecurityDescriptorToAccessNamedW (Ordinal: 1120, Address: 0x417a0)
  • ConvertSecurityDescriptorToAccessW (Ordinal: 1121, Address: 0x417a0)
  • ConvertSecurityDescriptorToStringSecurityDescriptorA (Ordinal: 1122, Address: 0x4c4b0)
  • ConvertSecurityDescriptorToStringSecurityDescriptorW (Ordinal: 1123, Address: 0x4c620)
  • ConvertSidToStringSidA (Ordinal: 1124, Address: 0x1bf30)
  • ConvertSidToStringSidW (Ordinal: 1125, Address: 0x15a20)
  • ConvertStringSDToSDDomainA (Ordinal: 1126, Address: 0x4c6f0)
  • ConvertStringSDToSDDomainW (Ordinal: 1127, Address: 0x1b840)
  • ConvertStringSDToSDRootDomainA (Ordinal: 1128, Address: 0x4c830)
  • ConvertStringSDToSDRootDomainW (Ordinal: 1129, Address: 0x4c900)
  • ConvertStringSecurityDescriptorToSecurityDescriptorA (Ordinal: 1130, Address: 0x4c970)
  • ConvertStringSecurityDescriptorToSecurityDescriptorW (Ordinal: 1131, Address: 0x11f20)
  • ConvertStringSidToSidA (Ordinal: 1132, Address: 0x4ca30)
  • ConvertStringSidToSidW (Ordinal: 1133, Address: 0x11e70)
  • ConvertToAutoInheritPrivateObjectSecurity (Ordinal: 1134, Address: 0x30d50)
  • CopySid (Ordinal: 1135, Address: 0x16c00)
  • CreateCodeAuthzLevel (Ordinal: 1136, Address: 0x393b0)
  • CreatePrivateObjectSecurity (Ordinal: 1137, Address: 0x197a0)
  • CreatePrivateObjectSecurityEx (Ordinal: 1138, Address: 0x30d70)
  • CreatePrivateObjectSecurityWithMultipleInheritance (Ordinal: 1139, Address: 0x30d90)
  • CreateProcessAsUserA (Ordinal: 1140, Address: 0x30db0)
  • CreateProcessAsUserW (Ordinal: 1141, Address: 0x17cc0)
  • CreateProcessWithLogonW (Ordinal: 1142, Address: 0x4b0f0)
  • CreateProcessWithTokenW (Ordinal: 1143, Address: 0x45a0)
  • CreateRestrictedToken (Ordinal: 1144, Address: 0x4500)
  • CreateServiceA (Ordinal: 1145, Address: 0x30e30)
  • CreateServiceEx (Ordinal: 1146, Address: 0x1e040)
  • CreateServiceW (Ordinal: 1147, Address: 0x30ec0)
  • CreateTraceInstanceId (Ordinal: 1148, Address: 0x98b15)
  • CreateWellKnownSid (Ordinal: 1149, Address: 0x17bd0)
  • CredBackupCredentials (Ordinal: 1150, Address: 0x30f50)
  • CredDeleteA (Ordinal: 1151, Address: 0x30f70)
  • CredDeleteW (Ordinal: 1152, Address: 0x30f90)
  • CredEncryptAndMarshalBinaryBlob (Ordinal: 1153, Address: 0x30fb0)
  • CredEnumerateA (Ordinal: 1154, Address: 0x30fd0)
  • CredEnumerateW (Ordinal: 1155, Address: 0x30ff0)
  • CredFindBestCredentialA (Ordinal: 1156, Address: 0x31010)
  • CredFindBestCredentialW (Ordinal: 1157, Address: 0x31030)
  • CredFree (Ordinal: 1158, Address: 0x31050)
  • CredGetSessionTypes (Ordinal: 1159, Address: 0x31070)
  • CredGetTargetInfoA (Ordinal: 1160, Address: 0x31090)
  • CredGetTargetInfoW (Ordinal: 1161, Address: 0x310b0)
  • CredIsMarshaledCredentialA (Ordinal: 1162, Address: 0x33ae0)
  • CredIsMarshaledCredentialW (Ordinal: 1163, Address: 0x310d0)
  • CredIsProtectedA (Ordinal: 1164, Address: 0x310f0)
  • CredIsProtectedW (Ordinal: 1165, Address: 0x31110)
  • CredMarshalCredentialA (Ordinal: 1166, Address: 0x31130)
  • CredMarshalCredentialW (Ordinal: 1167, Address: 0x31150)
  • CredProfileLoaded (Ordinal: 1168, Address: 0x31190)
  • CredProfileLoadedEx (Ordinal: 1169, Address: 0x31170)
  • CredProfileUnloaded (Ordinal: 1170, Address: 0x311b0)
  • CredProtectA (Ordinal: 1171, Address: 0x311d0)
  • CredProtectW (Ordinal: 1172, Address: 0x311f0)
  • CredReadA (Ordinal: 1173, Address: 0x31210)
  • CredReadByTokenHandle (Ordinal: 1174, Address: 0x31230)
  • CredReadDomainCredentialsA (Ordinal: 1175, Address: 0x31250)
  • CredReadDomainCredentialsW (Ordinal: 1176, Address: 0x31270)
  • CredReadW (Ordinal: 1177, Address: 0x31290)
  • CredRenameA (Ordinal: 1178, Address: 0x33b20)
  • CredRenameW (Ordinal: 1179, Address: 0x33b20)
  • CredRestoreCredentials (Ordinal: 1180, Address: 0x312b0)
  • CredUnmarshalCredentialA (Ordinal: 1181, Address: 0x312d0)
  • CredUnmarshalCredentialW (Ordinal: 1182, Address: 0x312f0)
  • CredUnprotectA (Ordinal: 1183, Address: 0x31310)
  • CredUnprotectW (Ordinal: 1184, Address: 0x31330)
  • CredWriteA (Ordinal: 1185, Address: 0x31350)
  • CredWriteDomainCredentialsA (Ordinal: 1186, Address: 0x31370)
  • CredWriteDomainCredentialsW (Ordinal: 1187, Address: 0x31390)
  • CredWriteW (Ordinal: 1188, Address: 0x313b0)
  • CredpConvertCredential (Ordinal: 1189, Address: 0x313d0)
  • CredpConvertOneCredentialSize (Ordinal: 1190, Address: 0x313f0)
  • CredpConvertTargetInfo (Ordinal: 1191, Address: 0x31410)
  • CredpDecodeCredential (Ordinal: 1192, Address: 0x31430)
  • CredpEncodeCredential (Ordinal: 1193, Address: 0x31450)
  • CredpEncodeSecret (Ordinal: 1194, Address: 0x31470)
  • CryptAcquireContextA (Ordinal: 1195, Address: 0x17080)
  • CryptAcquireContextW (Ordinal: 1196, Address: 0x171c0)
  • CryptContextAddRef (Ordinal: 1197, Address: 0x31490)
  • CryptCreateHash (Ordinal: 1198, Address: 0x16900)
  • CryptDecrypt (Ordinal: 1199, Address: 0x314b0)
  • CryptDeriveKey (Ordinal: 1200, Address: 0x314d0)
  • CryptDestroyHash (Ordinal: 1201, Address: 0x16cf0)
  • CryptDestroyKey (Ordinal: 1202, Address: 0x16f30)
  • CryptDuplicateHash (Ordinal: 1203, Address: 0x314f0)
  • CryptDuplicateKey (Ordinal: 1204, Address: 0x31510)
  • CryptEncrypt (Ordinal: 1205, Address: 0x31530)
  • CryptEnumProviderTypesA (Ordinal: 1206, Address: 0x31550)
  • CryptEnumProviderTypesW (Ordinal: 1207, Address: 0x31570)
  • CryptEnumProvidersA (Ordinal: 1208, Address: 0x31590)
  • CryptEnumProvidersW (Ordinal: 1209, Address: 0x315b0)
  • CryptExportKey (Ordinal: 1210, Address: 0x16850)
  • CryptGenKey (Ordinal: 1211, Address: 0x315d0)
  • CryptGenRandom (Ordinal: 1212, Address: 0x17a50)
  • CryptGetDefaultProviderA (Ordinal: 1213, Address: 0x315f0)
  • CryptGetDefaultProviderW (Ordinal: 1214, Address: 0x17590)
  • CryptGetHashParam (Ordinal: 1215, Address: 0x16330)
  • CryptGetKeyParam (Ordinal: 1216, Address: 0x31610)
  • CryptGetProvParam (Ordinal: 1217, Address: 0x31630)
  • CryptGetUserKey (Ordinal: 1218, Address: 0x31650)
  • CryptHashData (Ordinal: 1219, Address: 0x16d10)
  • CryptHashSessionKey (Ordinal: 1220, Address: 0x31670)
  • CryptImportKey (Ordinal: 1221, Address: 0x16830)
  • CryptReleaseContext (Ordinal: 1222, Address: 0x175b0)
  • CryptSetHashParam (Ordinal: 1223, Address: 0x17c80)
  • CryptSetKeyParam (Ordinal: 1224, Address: 0x31690)
  • CryptSetProvParam (Ordinal: 1225, Address: 0x316b0)
  • CryptSetProviderA (Ordinal: 1226, Address: 0x316d0)
  • CryptSetProviderExA (Ordinal: 1227, Address: 0x316f0)
  • CryptSetProviderExW (Ordinal: 1228, Address: 0x31710)
  • CryptSetProviderW (Ordinal: 1229, Address: 0x31730)
  • CryptSignHashA (Ordinal: 1230, Address: 0x31750)
  • CryptSignHashW (Ordinal: 1231, Address: 0x31770)
  • CryptVerifySignatureA (Ordinal: 1232, Address: 0x31790)
  • CryptVerifySignatureW (Ordinal: 1233, Address: 0x17a30)
  • CveEventWrite (Ordinal: 1234, Address: 0x9918a)
  • DecryptFileA (Ordinal: 1235, Address: 0x2f870)
  • DecryptFileW (Ordinal: 1236, Address: 0x2f940)
  • DeleteAce (Ordinal: 1237, Address: 0x175f0)
  • DeleteService (Ordinal: 1238, Address: 0x317b0)
  • DeregisterEventSource (Ordinal: 1239, Address: 0x18910)
  • DestroyPrivateObjectSecurity (Ordinal: 1240, Address: 0x317d0)
  • DuplicateEncryptionInfoFile (Ordinal: 1241, Address: 0x2f9d0)
  • DuplicateToken (Ordinal: 1242, Address: 0x170f0)
  • DuplicateTokenEx (Ordinal: 1243, Address: 0x17980)
  • ElfBackupEventLogFileA (Ordinal: 1244, Address: 0x53c30)
  • ElfBackupEventLogFileW (Ordinal: 1245, Address: 0x53d30)
  • ElfChangeNotify (Ordinal: 1246, Address: 0x53e30)
  • ElfClearEventLogFileA (Ordinal: 1247, Address: 0x53f40)
  • ElfClearEventLogFileW (Ordinal: 1248, Address: 0x54030)
  • ElfCloseEventLog (Ordinal: 1249, Address: 0x1c640)
  • ElfDeregisterEventSource (Ordinal: 1250, Address: 0x18940)
  • ElfFlushEventLog (Ordinal: 1251, Address: 0x54110)
  • ElfNumberOfRecords (Ordinal: 1252, Address: 0x54120)
  • ElfOldestRecord (Ordinal: 1253, Address: 0x54210)
  • ElfOpenBackupEventLogA (Ordinal: 1254, Address: 0x54300)
  • ElfOpenBackupEventLogW (Ordinal: 1255, Address: 0x54470)
  • ElfOpenEventLogA (Ordinal: 1256, Address: 0x545e0)
  • ElfOpenEventLogW (Ordinal: 1257, Address: 0x1c710)
  • ElfReadEventLogA (Ordinal: 1258, Address: 0x54830)
  • ElfReadEventLogW (Ordinal: 1259, Address: 0x549a0)
  • ElfRegisterEventSourceA (Ordinal: 1260, Address: 0x54d60)
  • ElfRegisterEventSourceW (Ordinal: 1261, Address: 0x17f60)
  • ElfReportEventA (Ordinal: 1262, Address: 0x54f00)
  • ElfReportEventAndSourceW (Ordinal: 1263, Address: 0x55360)
  • ElfReportEventW (Ordinal: 1264, Address: 0x184e0)
  • EnableTrace (Ordinal: 1265, Address: 0x1d160)
  • EnableTraceEx (Ordinal: 1266, Address: 0x1d1b0)
  • EnableTraceEx2 (Ordinal: 1267, Address: 0x42b0)
  • EncryptFileA (Ordinal: 1268, Address: 0x2fa70)
  • EncryptFileW (Ordinal: 1269, Address: 0x2fb30)
  • EncryptedFileKeyInfo (Ordinal: 1270, Address: 0x2fbb0)
  • EncryptionDisable (Ordinal: 1271, Address: 0x2fc30)
  • EnumDependentServicesA (Ordinal: 1272, Address: 0x47f40)
  • EnumDependentServicesW (Ordinal: 1273, Address: 0x317f0)
  • EnumDynamicTimeZoneInformation (Ordinal: 1274, Address: 0x31810)
  • EnumServiceGroupW (Ordinal: 1275, Address: 0x480f0)
  • EnumServicesStatusA (Ordinal: 1276, Address: 0x483c0)
  • EnumServicesStatusExA (Ordinal: 1277, Address: 0x18b00)
  • EnumServicesStatusExW (Ordinal: 1278, Address: 0x3a00)
  • EnumServicesStatusW (Ordinal: 1279, Address: 0x48610)
  • EnumerateTraceGuids (Ordinal: 1280, Address: 0x19590)
  • EnumerateTraceGuidsEx (Ordinal: 1281, Address: 0x17d60)
  • EqualDomainSid (Ordinal: 1282, Address: 0x31830)
  • EqualPrefixSid (Ordinal: 1283, Address: 0x31850)
  • EqualSid (Ordinal: 1284, Address: 0x17e00)
  • EventAccessControl (Ordinal: 1285, Address: 0x31870)
  • EventAccessQuery (Ordinal: 1286, Address: 0x31890)
  • EventAccessRemove (Ordinal: 1287, Address: 0x318b0)
  • EventActivityIdControl (Ordinal: 1288, Address: 0x995a2)
  • EventEnabled (Ordinal: 1289, Address: 0x995cf)
  • EventProviderEnabled (Ordinal: 1290, Address: 0x995fa)
  • EventRegister (Ordinal: 1291, Address: 0x99626)
  • EventSetInformation (Ordinal: 1292, Address: 0x99651)
  • EventUnregister (Ordinal: 1293, Address: 0x9967e)
  • EventWrite (Ordinal: 1294, Address: 0x996a2)
  • EventWriteEndScenario (Ordinal: 1295, Address: 0x996cc)
  • EventWriteEx (Ordinal: 1296, Address: 0x996f8)
  • EventWriteStartScenario (Ordinal: 1297, Address: 0x99726)
  • EventWriteString (Ordinal: 1298, Address: 0x99758)
  • EventWriteTransfer (Ordinal: 1299, Address: 0x99785)
  • FileEncryptionStatusA (Ordinal: 1300, Address: 0x2fc80)
  • FileEncryptionStatusW (Ordinal: 1301, Address: 0x2fd50)
  • FindFirstFreeAce (Ordinal: 1302, Address: 0x318d0)
  • FlushEfsCache (Ordinal: 1303, Address: 0x2fdb0)
  • FlushTraceA (Ordinal: 1304, Address: 0x44fd0)
  • FlushTraceW (Ordinal: 1305, Address: 0x44ff0)
  • FreeEncryptedFileKeyInfo (Ordinal: 1306, Address: 0x2fe80)
  • FreeEncryptedFileMetadata (Ordinal: 1307, Address: 0x19580)
  • FreeEncryptionCertificateHashList (Ordinal: 1308, Address: 0x2feb0)
  • FreeInheritedFromArray (Ordinal: 1309, Address: 0x40030)
  • FreeSid (Ordinal: 1310, Address: 0x17130)
  • GetAccessPermissionsForObjectA (Ordinal: 1311, Address: 0x417e0)
  • GetAccessPermissionsForObjectW (Ordinal: 1312, Address: 0x41b40)
  • GetAce (Ordinal: 1313, Address: 0x1afe0)
  • GetAclInformation (Ordinal: 1314, Address: 0x1b370)
  • GetAuditedPermissionsFromAclA (Ordinal: 1315, Address: 0x40080)
  • GetAuditedPermissionsFromAclW (Ordinal: 1316, Address: 0x40100)
  • GetCurrentHwProfileA (Ordinal: 1317, Address: 0x2f4a0)
  • GetCurrentHwProfileW (Ordinal: 1318, Address: 0x171f0)
  • GetDynamicTimeZoneInformationEffectiveYears (Ordinal: 1319, Address: 0x318f0)
  • GetEffectiveRightsFromAclA (Ordinal: 1320, Address: 0x401a0)
  • GetEffectiveRightsFromAclW (Ordinal: 1321, Address: 0x40220)
  • GetEncryptedFileMetadata (Ordinal: 1322, Address: 0x2fee0)
  • GetEventLogInformation (Ordinal: 1323, Address: 0x1c500)
  • GetExplicitEntriesFromAclA (Ordinal: 1324, Address: 0x31910)
  • GetExplicitEntriesFromAclW (Ordinal: 1325, Address: 0x31910)
  • GetFileSecurityA (Ordinal: 1326, Address: 0x493c0)
  • GetFileSecurityW (Ordinal: 1327, Address: 0x44e0)
  • GetInformationCodeAuthzLevelW (Ordinal: 1328, Address: 0x39a80)
  • GetInformationCodeAuthzPolicyW (Ordinal: 1329, Address: 0x5b30)
  • GetInheritanceSourceA (Ordinal: 1330, Address: 0x402c0)
  • GetInheritanceSourceW (Ordinal: 1331, Address: 0x402d0)
  • GetKernelObjectSecurity (Ordinal: 1332, Address: 0x1b3b0)
  • GetLengthSid (Ordinal: 1333, Address: 0x16870)
  • GetLocalManagedApplicationData (Ordinal: 1334, Address: 0x377d0)
  • GetLocalManagedApplications (Ordinal: 1335, Address: 0x37a40)
  • GetManagedApplicationCategories (Ordinal: 1336, Address: 0x37d70)
  • GetManagedApplications (Ordinal: 1337, Address: 0x37de0)
  • GetMultipleTrusteeA (Ordinal: 1338, Address: 0x40e50)
  • GetMultipleTrusteeOperationA (Ordinal: 1339, Address: 0x40e70)
  • GetMultipleTrusteeOperationW (Ordinal: 1340, Address: 0x40e70)
  • GetMultipleTrusteeW (Ordinal: 1341, Address: 0x40e50)
  • GetNamedSecurityInfoA (Ordinal: 1342, Address: 0x40390)
  • GetNamedSecurityInfoExA (Ordinal: 1343, Address: 0x41c80)
  • GetNamedSecurityInfoExW (Ordinal: 1344, Address: 0x41f30)
  • GetNamedSecurityInfoW (Ordinal: 1345, Address: 0x31930)
  • GetNumberOfEventLogRecords (Ordinal: 1346, Address: 0x53350)
  • GetOldestEventLogRecord (Ordinal: 1347, Address: 0x533a0)
  • GetOverlappedAccessResults (Ordinal: 1348, Address: 0x42260)
  • GetPrivateObjectSecurity (Ordinal: 1349, Address: 0x31980)
  • GetSecurityDescriptorControl (Ordinal: 1350, Address: 0x1bdf0)
  • GetSecurityDescriptorDacl (Ordinal: 1351, Address: 0x17900)
  • GetSecurityDescriptorGroup (Ordinal: 1352, Address: 0x1bf10)
  • GetSecurityDescriptorLength (Ordinal: 1353, Address: 0x1be40)
  • GetSecurityDescriptorOwner (Ordinal: 1354, Address: 0x1d400)
  • GetSecurityDescriptorRMControl (Ordinal: 1355, Address: 0x319a0)
  • GetSecurityDescriptorSacl (Ordinal: 1356, Address: 0x1bef0)
  • GetSecurityInfo (Ordinal: 1357, Address: 0x17150)
  • GetSecurityInfoExA (Ordinal: 1358, Address: 0x42390)
  • GetSecurityInfoExW (Ordinal: 1359, Address: 0x42600)
  • GetServiceDisplayNameA (Ordinal: 1360, Address: 0x48660)
  • GetServiceDisplayNameW (Ordinal: 1361, Address: 0x319c0)
  • GetServiceKeyNameA (Ordinal: 1362, Address: 0x48710)
  • GetServiceKeyNameW (Ordinal: 1363, Address: 0x319e0)
  • GetSidIdentifierAuthority (Ordinal: 1364, Address: 0x1bbf0)
  • GetSidLengthRequired (Ordinal: 1365, Address: 0x1b000)
  • GetSidSubAuthority (Ordinal: 1366, Address: 0x16fc0)
  • GetSidSubAuthorityCount (Ordinal: 1367, Address: 0x16f50)
  • GetStringConditionFromBinary (Ordinal: 1368, Address: 0x4bd40)
  • GetThreadWaitChain (Ordinal: 1369, Address: 0x64390)
  • GetTokenInformation (Ordinal: 1370, Address: 0x16180)
  • GetTraceEnableFlags (Ordinal: 1371, Address: 0x99e42)
  • GetTraceEnableLevel (Ordinal: 1372, Address: 0x99e73)
  • GetTraceLoggerHandle (Ordinal: 1373, Address: 0x99ea5)
  • GetTrusteeFormA (Ordinal: 1374, Address: 0x40e90)
  • GetTrusteeFormW (Ordinal: 1375, Address: 0x40e90)
  • GetTrusteeNameA (Ordinal: 1376, Address: 0x40eb0)
  • GetTrusteeNameW (Ordinal: 1377, Address: 0x40eb0)
  • GetTrusteeTypeA (Ordinal: 1378, Address: 0x40ec0)
  • GetTrusteeTypeW (Ordinal: 1379, Address: 0x40ec0)
  • GetUserNameA (Ordinal: 1380, Address: 0x4b170)
  • GetUserNameW (Ordinal: 1381, Address: 0x16640)
  • GetWindowsAccountDomainSid (Ordinal: 1382, Address: 0x31a00)
  • I_QueryTagInformation (Ordinal: 1383, Address: 0x99f6e)
  • I_ScIsSecurityProcess (Ordinal: 1384, Address: 0x99fbc)
  • I_ScPnPGetServiceName (Ordinal: 1385, Address: 0x9a00a)
  • I_ScQueryServiceConfig (Ordinal: 1386, Address: 0x9a059)
  • I_ScRegisterPreshutdownRestart (Ordinal: 1387, Address: 0x9a0b1)
  • I_ScReparseServiceDatabase (Ordinal: 1388, Address: 0x1e050)
  • I_ScSendPnPMessage (Ordinal: 1389, Address: 0x9a120)
  • I_ScSendTSMessage (Ordinal: 1390, Address: 0x9a167)
  • I_ScSetServiceBitsA (Ordinal: 1391, Address: 0x31a20)
  • I_ScSetServiceBitsW (Ordinal: 1392, Address: 0x31a40)
  • I_ScValidatePnPService (Ordinal: 1393, Address: 0x9a1da)
  • IdentifyCodeAuthzLevelW (Ordinal: 1394, Address: 0xb8b0)
  • ImpersonateAnonymousToken (Ordinal: 1395, Address: 0x31a60)
  • ImpersonateLoggedOnUser (Ordinal: 1396, Address: 0x17b30)
  • ImpersonateNamedPipeClient (Ordinal: 1397, Address: 0x31a80)
  • ImpersonateSelf (Ordinal: 1398, Address: 0x17e80)
  • InitializeAcl (Ordinal: 1399, Address: 0x171a0)
  • InitializeSecurityDescriptor (Ordinal: 1400, Address: 0x17570)
  • InitializeSid (Ordinal: 1401, Address: 0x1b020)
  • InitiateShutdownA (Ordinal: 1402, Address: 0x453a0)
  • InitiateShutdownW (Ordinal: 1403, Address: 0x19800)
  • InitiateSystemShutdownA (Ordinal: 1404, Address: 0x454e0)
  • InitiateSystemShutdownExA (Ordinal: 1405, Address: 0x45630)
  • InitiateSystemShutdownExW (Ordinal: 1406, Address: 0x47ac0)
  • InitiateSystemShutdownW (Ordinal: 1407, Address: 0x45780)
  • InstallApplication (Ordinal: 1408, Address: 0x37df0)
  • IsTextUnicode (Ordinal: 1409, Address: 0x161e0)
  • IsTokenRestricted (Ordinal: 1410, Address: 0x31aa0)
  • IsTokenUntrusted (Ordinal: 1411, Address: 0x397a0)
  • IsValidAcl (Ordinal: 1412, Address: 0x31ac0)
  • IsValidRelativeSecurityDescriptor (Ordinal: 1413, Address: 0x9a3ba)
  • IsValidSecurityDescriptor (Ordinal: 1414, Address: 0x31ae0)
  • IsValidSid (Ordinal: 1415, Address: 0x16d30)
  • IsWellKnownSid (Ordinal: 1416, Address: 0x1c080)
  • LockServiceDatabase (Ordinal: 1417, Address: 0x487c0)
  • LogonUserA (Ordinal: 1418, Address: 0x4b650)
  • LogonUserExA (Ordinal: 1419, Address: 0x4b840)
  • LogonUserExExW (Ordinal: 1420, Address: 0x31b00)
  • LogonUserExW (Ordinal: 1421, Address: 0x4b8a0)
  • LogonUserW (Ordinal: 1422, Address: 0x1b920)
  • LookupAccountNameA (Ordinal: 1423, Address: 0x494a0)
  • LookupAccountNameW (Ordinal: 1424, Address: 0x16670)
  • LookupAccountSidA (Ordinal: 1425, Address: 0x499f0)
  • LookupAccountSidW (Ordinal: 1426, Address: 0x166f0)
  • LookupPrivilegeDisplayNameA (Ordinal: 1427, Address: 0x4a0f0)
  • LookupPrivilegeDisplayNameW (Ordinal: 1428, Address: 0x4a300)
  • LookupPrivilegeNameA (Ordinal: 1429, Address: 0x4a4a0)
  • LookupPrivilegeNameW (Ordinal: 1430, Address: 0x4a650)
  • LookupPrivilegeValueA (Ordinal: 1431, Address: 0x12b10)
  • LookupPrivilegeValueW (Ordinal: 1432, Address: 0xfac0)
  • LookupSecurityDescriptorPartsA (Ordinal: 1433, Address: 0x40440)
  • LookupSecurityDescriptorPartsW (Ordinal: 1434, Address: 0x40710)
  • LsaAddAccountRights (Ordinal: 1435, Address: 0x31b80)
  • LsaAddPrivilegesToAccount (Ordinal: 1436, Address: 0x33b50)
  • LsaClearAuditLog (Ordinal: 1437, Address: 0x33be0)
  • LsaClose (Ordinal: 1438, Address: 0x1be10)
  • LsaCreateAccount (Ordinal: 1439, Address: 0x33c70)
  • LsaCreateSecret (Ordinal: 1440, Address: 0x31b90)
  • LsaCreateTrustedDomain (Ordinal: 1441, Address: 0x33d80)
  • LsaCreateTrustedDomainEx (Ordinal: 1442, Address: 0x35b40)
  • LsaDelete (Ordinal: 1443, Address: 0x31ba0)
  • LsaDeleteTrustedDomain (Ordinal: 1444, Address: 0x35d20)
  • LsaEnumerateAccountRights (Ordinal: 1445, Address: 0x31bb0)
  • LsaEnumerateAccounts (Ordinal: 1446, Address: 0x33e90)
  • LsaEnumerateAccountsWithUserRight (Ordinal: 1447, Address: 0x31bc0)
  • LsaEnumeratePrivileges (Ordinal: 1448, Address: 0x33f70)
  • LsaEnumeratePrivilegesOfAccount (Ordinal: 1449, Address: 0x34050)
  • LsaEnumerateTrustedDomains (Ordinal: 1450, Address: 0x340e0)
  • LsaEnumerateTrustedDomainsEx (Ordinal: 1451, Address: 0x35db0)
  • LsaFreeMemory (Ordinal: 1452, Address: 0x1bc40)
  • LsaGetAppliedCAPIDs (Ordinal: 1453, Address: 0x341d0)
  • LsaGetQuotasForAccount (Ordinal: 1454, Address: 0x34350)
  • LsaGetRemoteUserName (Ordinal: 1455, Address: 0x343e0)
  • LsaGetSystemAccessAccount (Ordinal: 1456, Address: 0x345e0)
  • LsaGetUserName (Ordinal: 1457, Address: 0x11d80)
  • LsaICLookupNames (Ordinal: 1458, Address: 0x31bd0)
  • LsaICLookupNamesWithCreds (Ordinal: 1459, Address: 0x31c30)
  • LsaICLookupSids (Ordinal: 1460, Address: 0x31cb0)
  • LsaICLookupSidsWithCreds (Ordinal: 1461, Address: 0x31cc0)
  • LsaInvokeTrustScanner (Ordinal: 1462, Address: 0x1eaf0)
  • LsaLookupNames (Ordinal: 1463, Address: 0x34670)
  • LsaLookupNames2 (Ordinal: 1464, Address: 0x31d40)
  • LsaLookupPrivilegeDisplayName (Ordinal: 1465, Address: 0x34800)
  • LsaLookupPrivilegeName (Ordinal: 1466, Address: 0x34b10)
  • LsaLookupPrivilegeValue (Ordinal: 1467, Address: 0xfbd0)
  • LsaLookupSids (Ordinal: 1468, Address: 0x1bc10)
  • LsaLookupSids2 (Ordinal: 1469, Address: 0x31d50)
  • LsaManageSidNameMapping (Ordinal: 1470, Address: 0x35ea0)
  • LsaNtStatusToWinError (Ordinal: 1471, Address: 0x161a0)
  • LsaOpenAccount (Ordinal: 1472, Address: 0x34bd0)
  • LsaOpenPolicy (Ordinal: 1473, Address: 0x1be20)
  • LsaOpenPolicySce (Ordinal: 1474, Address: 0x34ce0)
  • LsaOpenSecret (Ordinal: 1475, Address: 0x31d60)
  • LsaOpenTrustedDomain (Ordinal: 1476, Address: 0x34df0)
  • LsaOpenTrustedDomainByName (Ordinal: 1477, Address: 0x36000)
  • LsaPurgeLocalSystemAccessTable (Ordinal: 1478, Address: 0x1eb80)
  • LsaQueryCAPs (Ordinal: 1479, Address: 0x34f00)
  • LsaQueryDomainInformationPolicy (Ordinal: 1480, Address: 0x36110)
  • LsaQueryForestTrustInformation (Ordinal: 1481, Address: 0x361c0)
  • LsaQueryForestTrustInformation2 (Ordinal: 1482, Address: 0x1eeb0)
  • LsaQueryInfoTrustedDomain (Ordinal: 1483, Address: 0x35080)
  • LsaQueryInformationPolicy (Ordinal: 1484, Address: 0x1be30)
  • LsaQueryLocalSystemAccess (Ordinal: 1485, Address: 0x1ec40)
  • LsaQueryLocalSystemAccessAll (Ordinal: 1486, Address: 0x1ed20)
  • LsaQuerySecret (Ordinal: 1487, Address: 0x31d70)
  • LsaQuerySecurityObject (Ordinal: 1488, Address: 0x35160)
  • LsaQueryTrustedDomainInfo (Ordinal: 1489, Address: 0x36270)
  • LsaQueryTrustedDomainInfoByName (Ordinal: 1490, Address: 0x36370)
  • LsaRemoveAccountRights (Ordinal: 1491, Address: 0x31d80)
  • LsaRemovePrivilegesFromAccount (Ordinal: 1492, Address: 0x35230)
  • LsaRetrievePrivateData (Ordinal: 1493, Address: 0x31d90)
  • LsaSetCAPs (Ordinal: 1494, Address: 0x352d0)
  • LsaSetDomainInformationPolicy (Ordinal: 1495, Address: 0x36420)
  • LsaSetForestTrustInformation (Ordinal: 1496, Address: 0x364c0)
  • LsaSetForestTrustInformation2 (Ordinal: 1497, Address: 0x1ef70)
  • LsaSetInformationPolicy (Ordinal: 1498, Address: 0x31da0)
  • LsaSetInformationTrustedDomain (Ordinal: 1499, Address: 0x35420)
  • LsaSetLocalSystemAccess (Ordinal: 1500, Address: 0x1edf0)
  • LsaSetQuotasForAccount (Ordinal: 1501, Address: 0x357f0)
  • LsaSetSecret (Ordinal: 1502, Address: 0x31db0)
  • LsaSetSecurityObject (Ordinal: 1503, Address: 0x35880)
  • LsaSetSystemAccessAccount (Ordinal: 1504, Address: 0x359e0)
  • LsaSetTrustedDomainInfoByName (Ordinal: 1505, Address: 0x36580)
  • LsaSetTrustedDomainInformation (Ordinal: 1506, Address: 0x36970)
  • LsaStorePrivateData (Ordinal: 1507, Address: 0x31e30)
  • MD4Final (Ordinal: 1508, Address: 0x9ac05)
  • MD4Init (Ordinal: 1509, Address: 0x9ac1c)
  • MD4Update (Ordinal: 1510, Address: 0x9ac34)
  • MD5Final (Ordinal: 1511, Address: 0x9ac4d)
  • MD5Init (Ordinal: 1512, Address: 0x9ac64)
  • MD5Update (Ordinal: 1513, Address: 0x9ac7c)
  • MIDL_user_free_Ext (Ordinal: 1514, Address: 0x16ef0)
  • MSChapSrvChangePassword (Ordinal: 1515, Address: 0x32590)
  • MSChapSrvChangePassword2 (Ordinal: 1516, Address: 0x32850)
  • MakeAbsoluteSD (Ordinal: 1517, Address: 0x1d280)
  • MakeAbsoluteSD2 (Ordinal: 1518, Address: 0x31e40)
  • MakeSelfRelativeSD (Ordinal: 1519, Address: 0x31e60)
  • MapGenericMask (Ordinal: 1520, Address: 0x31e80)
  • NotifyBootConfigStatus (Ordinal: 1521, Address: 0x1ca30)
  • NotifyChangeEventLog (Ordinal: 1522, Address: 0x533f0)
  • NotifyServiceStatusChange (Ordinal: 1523, Address: 0x1e030)
  • NotifyServiceStatusChangeA (Ordinal: 1524, Address: 0x31ea0)
  • NotifyServiceStatusChangeW (Ordinal: 1525, Address: 0x1d570)
  • NpGetUserName (Ordinal: 1526, Address: 0x4b900)
  • ObjectCloseAuditAlarmA (Ordinal: 1527, Address: 0x4a7d0)
  • ObjectCloseAuditAlarmW (Ordinal: 1528, Address: 0x31ec0)
  • ObjectDeleteAuditAlarmA (Ordinal: 1529, Address: 0x4a880)
  • ObjectDeleteAuditAlarmW (Ordinal: 1530, Address: 0x31ee0)
  • ObjectOpenAuditAlarmA (Ordinal: 1531, Address: 0x4a930)
  • ObjectOpenAuditAlarmW (Ordinal: 1532, Address: 0x31f00)
  • ObjectPrivilegeAuditAlarmA (Ordinal: 1533, Address: 0x4aaf0)
  • ObjectPrivilegeAuditAlarmW (Ordinal: 1534, Address: 0x31f80)
  • OpenBackupEventLogA (Ordinal: 1535, Address: 0x53430)
  • OpenBackupEventLogW (Ordinal: 1536, Address: 0x53550)
  • OpenEncryptedFileRawA (Ordinal: 1537, Address: 0x30020)
  • OpenEncryptedFileRawW (Ordinal: 1538, Address: 0x300e0)
  • OpenEventLogA (Ordinal: 1539, Address: 0x53630)
  • OpenEventLogW (Ordinal: 1540, Address: 0x1c490)
  • OpenProcessToken (Ordinal: 1541, Address: 0x16a70)
  • OpenSCManagerA (Ordinal: 1542, Address: 0x17ec0)
  • OpenSCManagerW (Ordinal: 1543, Address: 0x17a10)
  • OpenServiceA (Ordinal: 1544, Address: 0x31fa0)
  • OpenServiceW (Ordinal: 1545, Address: 0x17c30)
  • OpenThreadToken (Ordinal: 1546, Address: 0x16a50)
  • OpenThreadWaitChainSession (Ordinal: 1547, Address: 0x64590)
  • OpenTraceA (Ordinal: 1548, Address: 0x45190)
  • OpenTraceW (Ordinal: 1549, Address: 0x17da0)
  • OperationEnd (Ordinal: 1550, Address: 0x32bb0)
  • OperationStart (Ordinal: 1551, Address: 0x32cb0)
  • PerfAddCounters (Ordinal: 1552, Address: 0x11a0)
  • PerfCloseQueryHandle (Ordinal: 1553, Address: 0x1430)
  • PerfCreateInstance (Ordinal: 1554, Address: 0x9afa9)
  • PerfDecrementULongCounterValue (Ordinal: 1555, Address: 0x9afff)
  • PerfDecrementULongLongCounterValue (Ordinal: 1556, Address: 0x9b065)
  • PerfDeleteCounters (Ordinal: 1557, Address: 0x45c50)
  • PerfDeleteInstance (Ordinal: 1558, Address: 0x9b0d2)
  • PerfEnumerateCounterSet (Ordinal: 1559, Address: 0x6050)
  • PerfEnumerateCounterSetInstances (Ordinal: 1560, Address: 0x3640)
  • PerfIncrementULongCounterValue (Ordinal: 1561, Address: 0x9b161)
  • PerfIncrementULongLongCounterValue (Ordinal: 1562, Address: 0x9b1c7)
  • PerfOpenQueryHandle (Ordinal: 1563, Address: 0x4010)
  • PerfQueryCounterData (Ordinal: 1564, Address: 0x1df0)
  • PerfQueryCounterInfo (Ordinal: 1565, Address: 0x1270)
  • PerfQueryCounterSetRegistrationInfo (Ordinal: 1566, Address: 0x5e30)
  • PerfQueryInstance (Ordinal: 1567, Address: 0x9b282)
  • PerfRegCloseKey (Ordinal: 1568, Address: 0x122c0)
  • PerfRegEnumKey (Ordinal: 1569, Address: 0x55760)
  • PerfRegEnumValue (Ordinal: 1570, Address: 0x557c0)
  • PerfRegQueryInfoKey (Ordinal: 1571, Address: 0x1b040)
  • PerfRegQueryValue (Ordinal: 1572, Address: 0x9680)
  • PerfRegSetValue (Ordinal: 1573, Address: 0x55960)
  • PerfSetCounterRefValue (Ordinal: 1574, Address: 0x9b335)
  • PerfSetCounterSetInfo (Ordinal: 1575, Address: 0x9b386)
  • PerfSetULongCounterValue (Ordinal: 1576, Address: 0x9b3d9)
  • PerfSetULongLongCounterValue (Ordinal: 1577, Address: 0x9b433)
  • PerfStartProvider (Ordinal: 1578, Address: 0x9b486)
  • PerfStartProviderEx (Ordinal: 1579, Address: 0x9b4d0)
  • PerfStopProvider (Ordinal: 1580, Address: 0x9b519)
  • PrivilegeCheck (Ordinal: 1581, Address: 0x31fc0)
  • PrivilegedServiceAuditAlarmA (Ordinal: 1582, Address: 0x4abc0)
  • PrivilegedServiceAuditAlarmW (Ordinal: 1583, Address: 0x31fe0)
  • ProcessIdleTasks (Ordinal: 1584, Address: 0x331c0)
  • ProcessIdleTasksW (Ordinal: 1585, Address: 0x33250)
  • ProcessTrace (Ordinal: 1586, Address: 0x17de0)
  • QueryAllTracesA (Ordinal: 1587, Address: 0x1deb0)
  • QueryAllTracesW (Ordinal: 1588, Address: 0x4560)
  • QueryLocalUserServiceName (Ordinal: 1589, Address: 0x1e060)
  • QueryRecoveryAgentsOnEncryptedFile (Ordinal: 1590, Address: 0x30150)
  • QuerySecurityAccessMask (Ordinal: 1591, Address: 0x32000)
  • QueryServiceConfig2A (Ordinal: 1592, Address: 0x32020)
  • QueryServiceConfig2W (Ordinal: 1593, Address: 0x1d4e0)
  • QueryServiceConfigA (Ordinal: 1594, Address: 0x32040)
  • QueryServiceConfigW (Ordinal: 1595, Address: 0x17ca0)
  • QueryServiceDynamicInformation (Ordinal: 1596, Address: 0x32060)
  • QueryServiceLockStatusA (Ordinal: 1597, Address: 0x48850)
  • QueryServiceLockStatusW (Ordinal: 1598, Address: 0x489e0)
  • QueryServiceObjectSecurity (Ordinal: 1599, Address: 0x32080)
  • QueryServiceStatus (Ordinal: 1600, Address: 0x1d530)
  • QueryServiceStatusEx (Ordinal: 1601, Address: 0x17d40)
  • QueryTraceA (Ordinal: 1602, Address: 0x45010)
  • QueryTraceProcessingHandle (Ordinal: 1603, Address: 0x320a0)
  • QueryTraceW (Ordinal: 1604, Address: 0x1d500)
  • QueryUserServiceName (Ordinal: 1605, Address: 0x1e070)
  • QueryUserServiceNameForContext (Ordinal: 1606, Address: 0x1e080)
  • QueryUsersOnEncryptedFile (Ordinal: 1607, Address: 0x301d0)
  • ReadEncryptedFileRaw (Ordinal: 1608, Address: 0x30250)
  • ReadEventLogA (Ordinal: 1609, Address: 0x536c0)
  • ReadEventLogW (Ordinal: 1610, Address: 0x53760)
  • RegCloseKey (Ordinal: 1611, Address: 0x168e0)
  • RegConnectRegistryA (Ordinal: 1612, Address: 0x46110)
  • RegConnectRegistryExA (Ordinal: 1613, Address: 0x46130)
  • RegConnectRegistryExW (Ordinal: 1614, Address: 0x1ba60)
  • RegConnectRegistryW (Ordinal: 1615, Address: 0x1ba40)
  • RegCopyTreeA (Ordinal: 1616, Address: 0x464d0)
  • RegCopyTreeW (Ordinal: 1617, Address: 0x320c0)
  • RegCreateKeyA (Ordinal: 1618, Address: 0x46550)
  • RegCreateKeyExA (Ordinal: 1619, Address: 0x17a70)
  • RegCreateKeyExW (Ordinal: 1620, Address: 0x16d50)
  • RegCreateKeyTransactedA (Ordinal: 1621, Address: 0x465e0)
  • RegCreateKeyTransactedW (Ordinal: 1622, Address: 0x1ca90)
  • RegCreateKeyW (Ordinal: 1623, Address: 0x17020)
  • RegDeleteKeyA (Ordinal: 1624, Address: 0x41e0)
  • RegDeleteKeyExA (Ordinal: 1625, Address: 0x320e0)
  • RegDeleteKeyExW (Ordinal: 1626, Address: 0x32100)
  • RegDeleteKeyTransactedA (Ordinal: 1627, Address: 0x467d0)
  • RegDeleteKeyTransactedW (Ordinal: 1628, Address: 0x47c00)
  • RegDeleteKeyValueA (Ordinal: 1629, Address: 0x32120)
  • RegDeleteKeyValueW (Ordinal: 1630, Address: 0x1d600)
  • RegDeleteKeyW (Ordinal: 1631, Address: 0x16d70)
  • RegDeleteTreeA (Ordinal: 1632, Address: 0x32140)
  • RegDeleteTreeW (Ordinal: 1633, Address: 0x32160)
  • RegDeleteValueA (Ordinal: 1634, Address: 0x4580)
  • RegDeleteValueW (Ordinal: 1635, Address: 0x197e0)
  • RegDisablePredefinedCache (Ordinal: 1636, Address: 0x17c50)
  • RegDisablePredefinedCacheEx (Ordinal: 1637, Address: 0x32180)
  • RegDisableReflectionKey (Ordinal: 1638, Address: 0x19560)
  • RegEnableReflectionKey (Ordinal: 1639, Address: 0x19560)
  • RegEnumKeyA (Ordinal: 1640, Address: 0x1be60)
  • RegEnumKeyExA (Ordinal: 1641, Address: 0x4240)
  • RegEnumKeyExW (Ordinal: 1642, Address: 0x15b40)
  • RegEnumKeyW (Ordinal: 1643, Address: 0x165f0)
  • RegEnumValueA (Ordinal: 1644, Address: 0x321a0)
  • RegEnumValueW (Ordinal: 1645, Address: 0x16890)
  • RegFlushKey (Ordinal: 1646, Address: 0x1b3d0)
  • RegGetKeySecurity (Ordinal: 1647, Address: 0x1d3e0)
  • RegGetValueA (Ordinal: 1648, Address: 0x321f0)
  • RegGetValueW (Ordinal: 1649, Address: 0x1b390)
  • RegLoadAppKeyA (Ordinal: 1650, Address: 0x32210)
  • RegLoadAppKeyW (Ordinal: 1651, Address: 0x32230)
  • RegLoadKeyA (Ordinal: 1652, Address: 0x32250)
  • RegLoadKeyW (Ordinal: 1653, Address: 0x32270)
  • RegLoadMUIStringA (Ordinal: 1654, Address: 0x32290)
  • RegLoadMUIStringW (Ordinal: 1655, Address: 0x322b0)
  • RegNotifyChangeKeyValue (Ordinal: 1656, Address: 0x17bb0)
  • RegOpenCurrentUser (Ordinal: 1657, Address: 0x17dc0)
  • RegOpenKeyA (Ordinal: 1658, Address: 0x19750)
  • RegOpenKeyExA (Ordinal: 1659, Address: 0x16ed0)
  • RegOpenKeyExW (Ordinal: 1660, Address: 0x16130)
  • RegOpenKeyTransactedA (Ordinal: 1661, Address: 0x46680)
  • RegOpenKeyTransactedW (Ordinal: 1662, Address: 0x17940)
  • RegOpenKeyW (Ordinal: 1663, Address: 0x16c40)
  • RegOpenUserClassesRoot (Ordinal: 1664, Address: 0x322d0)
  • RegOverridePredefKey (Ordinal: 1665, Address: 0x466c0)
  • RegQueryInfoKeyA (Ordinal: 1666, Address: 0x43f0)
  • RegQueryInfoKeyW (Ordinal: 1667, Address: 0x16350)
  • RegQueryMultipleValuesA (Ordinal: 1668, Address: 0x322f0)
  • RegQueryMultipleValuesW (Ordinal: 1669, Address: 0x32310)
  • RegQueryReflectionKey (Ordinal: 1670, Address: 0x32ba0)
  • RegQueryValueA (Ordinal: 1671, Address: 0x46bd0)
  • RegQueryValueExA (Ordinal: 1672, Address: 0x17000)
  • RegQueryValueExW (Ordinal: 1673, Address: 0x16110)
  • RegQueryValueW (Ordinal: 1674, Address: 0x16a90)
  • RegRenameKey (Ordinal: 1675, Address: 0x46730)
  • RegReplaceKeyA (Ordinal: 1676, Address: 0x46ef0)
  • RegReplaceKeyW (Ordinal: 1677, Address: 0x47c40)
  • RegRestoreKeyA (Ordinal: 1678, Address: 0x32330)
  • RegRestoreKeyW (Ordinal: 1679, Address: 0x32350)
  • RegSaveKeyA (Ordinal: 1680, Address: 0x47160)
  • RegSaveKeyExA (Ordinal: 1681, Address: 0x32370)
  • RegSaveKeyExW (Ordinal: 1682, Address: 0x32390)
  • RegSaveKeyW (Ordinal: 1683, Address: 0x47340)
  • RegSetKeySecurity (Ordinal: 1684, Address: 0x1beb0)
  • RegSetKeyValueA (Ordinal: 1685, Address: 0x323b0)
  • RegSetKeyValueW (Ordinal: 1686, Address: 0x4520)
  • RegSetValueA (Ordinal: 1687, Address: 0x474e0)
  • RegSetValueExA (Ordinal: 1688, Address: 0x4290)
  • RegSetValueExW (Ordinal: 1689, Address: 0x170d0)
  • RegSetValueW (Ordinal: 1690, Address: 0x47650)
  • RegUnLoadKeyA (Ordinal: 1691, Address: 0x323d0)
  • RegUnLoadKeyW (Ordinal: 1692, Address: 0x323f0)
  • RegisterEventSourceA (Ordinal: 1693, Address: 0x537f0)
  • RegisterEventSourceW (Ordinal: 1694, Address: 0x17ee0)
  • RegisterIdleTask (Ordinal: 1695, Address: 0x33260)
  • RegisterServiceCtrlHandlerA (Ordinal: 1696, Address: 0x1c0c0)
  • RegisterServiceCtrlHandlerExA (Ordinal: 1697, Address: 0x32410)
  • RegisterServiceCtrlHandlerExW (Ordinal: 1698, Address: 0x1b410)
  • RegisterServiceCtrlHandlerW (Ordinal: 1699, Address: 0x17e60)
  • RegisterTraceGuidsA (Ordinal: 1700, Address: 0x9bdf4)
  • RegisterTraceGuidsW (Ordinal: 1701, Address: 0x9be25)
  • RegisterWaitChainCOMCallback (Ordinal: 1702, Address: 0x646b0)
  • RemoteRegEnumKeyWrapper (Ordinal: 1703, Address: 0x46810)
  • RemoteRegEnumValueWrapper (Ordinal: 1704, Address: 0x46980)
  • RemoteRegQueryInfoKeyWrapper (Ordinal: 1705, Address: 0x46ab0)
  • RemoteRegQueryMultipleValues2Wrapper (Ordinal: 1706, Address: 0x477d0)
  • RemoteRegQueryMultipleValuesWrapper (Ordinal: 1707, Address: 0x47950)
  • RemoteRegQueryValueWrapper (Ordinal: 1708, Address: 0x46e50)
  • RemoveTraceCallback (Ordinal: 1709, Address: 0x9bf26)
  • RemoveUsersFromEncryptedFile (Ordinal: 1710, Address: 0x30270)
  • ReportEventA (Ordinal: 1711, Address: 0x53870)
  • ReportEventW (Ordinal: 1712, Address: 0x18270)
  • RevertToSelf (Ordinal: 1713, Address: 0x16c20)
  • SafeBaseRegGetKeySecurity (Ordinal: 1714, Address: 0x45c10)
  • SaferCloseLevel (Ordinal: 1715, Address: 0x16050)
  • SaferComputeTokenFromLevel (Ordinal: 1716, Address: 0x13bd0)
  • SaferCreateLevel (Ordinal: 1717, Address: 0x393b0)
  • SaferGetLevelInformation (Ordinal: 1718, Address: 0x39a80)
  • SaferGetPolicyInformation (Ordinal: 1719, Address: 0x5b30)
  • SaferIdentifyLevel (Ordinal: 1720, Address: 0xb8b0)
  • SaferRecordEventLogEntry (Ordinal: 1721, Address: 0x3b6f0)
  • SaferSetLevelInformation (Ordinal: 1722, Address: 0x3be00)
  • SaferSetPolicyInformation (Ordinal: 1723, Address: 0x3a5c0)
  • SaferiChangeRegistryScope (Ordinal: 1724, Address: 0x3d160)
  • SaferiCompareTokenLevels (Ordinal: 1725, Address: 0x13510)
  • SaferiIsDllAllowed (Ordinal: 1726, Address: 0x3ac80)
  • SaferiIsExecutableFileType (Ordinal: 1727, Address: 0x3d920)
  • SaferiPopulateDefaultsInRegistry (Ordinal: 1728, Address: 0x3d1a0)
  • SaferiRecordEventLogEntry (Ordinal: 1729, Address: 0x3b6f0)
  • SaferiSearchMatchingHashRules (Ordinal: 1730, Address: 0x16e30)
  • SetAclInformation (Ordinal: 1731, Address: 0x32430)
  • SetEncryptedFileMetadata (Ordinal: 1732, Address: 0x2fee0)
  • SetEntriesInAccessListA (Ordinal: 1733, Address: 0x42930)
  • SetEntriesInAccessListW (Ordinal: 1734, Address: 0x42980)
  • SetEntriesInAclA (Ordinal: 1735, Address: 0x409a0)
  • SetEntriesInAclW (Ordinal: 1736, Address: 0x17ea0)
  • SetEntriesInAuditListA (Ordinal: 1737, Address: 0x429d0)
  • SetEntriesInAuditListW (Ordinal: 1738, Address: 0x42a10)
  • SetFileSecurityA (Ordinal: 1739, Address: 0x4acc0)
  • SetFileSecurityW (Ordinal: 1740, Address: 0x1d590)
  • SetInformationCodeAuthzLevelW (Ordinal: 1741, Address: 0x3be00)
  • SetInformationCodeAuthzPolicyW (Ordinal: 1742, Address: 0x3a5c0)
  • SetKernelObjectSecurity (Ordinal: 1743, Address: 0x17e40)
  • SetNamedSecurityInfoA (Ordinal: 1744, Address: 0x1bc60)
  • SetNamedSecurityInfoExA (Ordinal: 1745, Address: 0x42a50)
  • SetNamedSecurityInfoExW (Ordinal: 1746, Address: 0x42ed0)
  • SetNamedSecurityInfoW (Ordinal: 1747, Address: 0x1c060)
  • SetPrivateObjectSecurity (Ordinal: 1748, Address: 0x32470)
  • SetPrivateObjectSecurityEx (Ordinal: 1749, Address: 0x32450)
  • SetSecurityAccessMask (Ordinal: 1750, Address: 0x32490)
  • SetSecurityDescriptorControl (Ordinal: 1751, Address: 0x1bed0)
  • SetSecurityDescriptorDacl (Ordinal: 1752, Address: 0x17520)
  • SetSecurityDescriptorGroup (Ordinal: 1753, Address: 0x1b3f0)
  • SetSecurityDescriptorOwner (Ordinal: 1754, Address: 0x179b0)
  • SetSecurityDescriptorRMControl (Ordinal: 1755, Address: 0x324b0)
  • SetSecurityDescriptorSacl (Ordinal: 1756, Address: 0x197c0)
  • SetSecurityInfo (Ordinal: 1757, Address: 0x16f10)
  • SetSecurityInfoExA (Ordinal: 1758, Address: 0x431d0)
  • SetSecurityInfoExW (Ordinal: 1759, Address: 0x43610)
  • SetServiceBits (Ordinal: 1760, Address: 0x48b90)
  • SetServiceObjectSecurity (Ordinal: 1761, Address: 0x324d0)
  • SetServiceStatus (Ordinal: 1762, Address: 0x17c10)
  • SetThreadToken (Ordinal: 1763, Address: 0x16fe0)
  • SetTokenInformation (Ordinal: 1764, Address: 0x324f0)
  • SetTraceCallback (Ordinal: 1765, Address: 0x9c439)
  • SetUserFileEncryptionKey (Ordinal: 1766, Address: 0x302f0)
  • SetUserFileEncryptionKeyEx (Ordinal: 1767, Address: 0x30350)
  • StartServiceA (Ordinal: 1768, Address: 0x32510)
  • StartServiceCtrlDispatcherA (Ordinal: 1769, Address: 0x1c0a0)
  • StartServiceCtrlDispatcherW (Ordinal: 1770, Address: 0x17e20)
  • StartServiceW (Ordinal: 1771, Address: 0x1d510)
  • StartTraceA (Ordinal: 1772, Address: 0x1dec0)
  • StartTraceW (Ordinal: 1773, Address: 0x4540)
  • StopTraceA (Ordinal: 1774, Address: 0x45030)
  • StopTraceW (Ordinal: 1775, Address: 0x32530)
  • SystemFunction001 (Ordinal: 1776, Address: 0x9c51a)
  • SystemFunction002 (Ordinal: 1777, Address: 0x9c548)
  • SystemFunction003 (Ordinal: 1778, Address: 0x9c576)
  • SystemFunction004 (Ordinal: 1779, Address: 0x9c5a4)
  • SystemFunction005 (Ordinal: 1780, Address: 0x9c5d2)
  • SystemFunction006 (Ordinal: 1781, Address: 0x9c600)
  • SystemFunction007 (Ordinal: 1782, Address: 0x9c62c)
  • SystemFunction008 (Ordinal: 1783, Address: 0x9c658)
  • SystemFunction009 (Ordinal: 1784, Address: 0x9c684)
  • SystemFunction010 (Ordinal: 1785, Address: 0x9c6b0)
  • SystemFunction011 (Ordinal: 1786, Address: 0x9c6dc)
  • SystemFunction012 (Ordinal: 1787, Address: 0x9c708)
  • SystemFunction013 (Ordinal: 1788, Address: 0x9c734)
  • SystemFunction014 (Ordinal: 1789, Address: 0x9c760)
  • SystemFunction015 (Ordinal: 1790, Address: 0x9c78c)
  • SystemFunction016 (Ordinal: 1791, Address: 0x9c7b8)
  • SystemFunction017 (Ordinal: 1792, Address: 0x33290)
  • SystemFunction018 (Ordinal: 1793, Address: 0x9c7f6)
  • SystemFunction019 (Ordinal: 1794, Address: 0x332f0)
  • SystemFunction020 (Ordinal: 1795, Address: 0x9c834)
  • SystemFunction021 (Ordinal: 1796, Address: 0x9c860)
  • SystemFunction022 (Ordinal: 1797, Address: 0x9c88c)
  • SystemFunction023 (Ordinal: 1798, Address: 0x9c8b8)
  • SystemFunction024 (Ordinal: 1799, Address: 0x9c8e4)
  • SystemFunction025 (Ordinal: 1800, Address: 0x9c910)
  • SystemFunction026 (Ordinal: 1801, Address: 0x9c93c)
  • SystemFunction027 (Ordinal: 1802, Address: 0x9c968)
  • SystemFunction028 (Ordinal: 1803, Address: 0x9c994)
  • SystemFunction029 (Ordinal: 1804, Address: 0x9c9c2)
  • SystemFunction030 (Ordinal: 1805, Address: 0x9c9f0)
  • SystemFunction031 (Ordinal: 1806, Address: 0x9ca1c)
  • SystemFunction032 (Ordinal: 1807, Address: 0x9ca48)
  • SystemFunction033 (Ordinal: 1808, Address: 0x9ca74)
  • SystemFunction034 (Ordinal: 1809, Address: 0x9caa0)
  • SystemFunction035 (Ordinal: 1810, Address: 0x9cace)
  • SystemFunction036 (Ordinal: 1811, Address: 0x9cafd)
  • SystemFunction040 (Ordinal: 1812, Address: 0x9cb2b)
  • SystemFunction041 (Ordinal: 1813, Address: 0x9cb59)
  • TraceEvent (Ordinal: 1814, Address: 0x9cb80)
  • TraceEventInstance (Ordinal: 1815, Address: 0x9cbaa)
  • TraceMessage (Ordinal: 1816, Address: 0x9cbd3)
  • TraceMessageVa (Ordinal: 1817, Address: 0x9cbf8)
  • TraceQueryInformation (Ordinal: 1818, Address: 0x9cc26)
  • TraceSetInformation (Ordinal: 1819, Address: 0x32550)
  • TreeResetNamedSecurityInfoA (Ordinal: 1820, Address: 0x402c0)
  • TreeResetNamedSecurityInfoW (Ordinal: 1821, Address: 0x42d0)
  • TreeSetNamedSecurityInfoA (Ordinal: 1822, Address: 0x402c0)
  • TreeSetNamedSecurityInfoW (Ordinal: 1823, Address: 0x40c20)
  • TrusteeAccessToObjectA (Ordinal: 1824, Address: 0x43920)
  • TrusteeAccessToObjectW (Ordinal: 1825, Address: 0x43b80)
  • UninstallApplication (Ordinal: 1826, Address: 0x37e00)
  • UnlockServiceDatabase (Ordinal: 1827, Address: 0x48bd0)
  • UnregisterIdleTask (Ordinal: 1828, Address: 0x33270)
  • UnregisterTraceGuids (Ordinal: 1829, Address: 0x9cd63)
  • UpdateTraceA (Ordinal: 1830, Address: 0x45050)
  • UpdateTraceW (Ordinal: 1831, Address: 0x45070)
  • UsePinForEncryptedFilesA (Ordinal: 1832, Address: 0x30460)
  • UsePinForEncryptedFilesW (Ordinal: 1833, Address: 0x304f0)
  • WaitServiceState (Ordinal: 1834, Address: 0x32570)
  • WmiCloseBlock (Ordinal: 1835, Address: 0x5b760)
  • WmiDevInstToInstanceNameA (Ordinal: 1836, Address: 0x5b7e0)
  • WmiDevInstToInstanceNameW (Ordinal: 1837, Address: 0x5b8d0)
  • WmiEnumerateGuids (Ordinal: 1838, Address: 0x5b9c0)
  • WmiExecuteMethodA (Ordinal: 1839, Address: 0x5bb90)
  • WmiExecuteMethodW (Ordinal: 1840, Address: 0x5bc90)
  • WmiFileHandleToInstanceNameA (Ordinal: 1841, Address: 0x5c010)
  • WmiFileHandleToInstanceNameW (Ordinal: 1842, Address: 0x5c280)
  • WmiFreeBuffer (Ordinal: 1843, Address: 0x5c480)
  • WmiMofEnumerateResourcesA (Ordinal: 1844, Address: 0x5de50)
  • WmiMofEnumerateResourcesW (Ordinal: 1845, Address: 0x5e090)
  • WmiNotificationRegistrationA (Ordinal: 1846, Address: 0x5c4d0)
  • WmiNotificationRegistrationW (Ordinal: 1847, Address: 0x5c560)
  • WmiOpenBlock (Ordinal: 1848, Address: 0x5c5f0)
  • WmiQueryAllDataA (Ordinal: 1849, Address: 0x5c6f0)
  • WmiQueryAllDataMultipleA (Ordinal: 1850, Address: 0x5c760)
  • WmiQueryAllDataMultipleW (Ordinal: 1851, Address: 0x5c7f0)
  • WmiQueryAllDataW (Ordinal: 1852, Address: 0x5ca20)
  • WmiQueryGuidInformation (Ordinal: 1853, Address: 0x5cc90)
  • WmiQuerySingleInstanceA (Ordinal: 1854, Address: 0x5cd50)
  • WmiQuerySingleInstanceMultipleA (Ordinal: 1855, Address: 0x5ce40)
  • WmiQuerySingleInstanceMultipleW (Ordinal: 1856, Address: 0x5cff0)
  • WmiQuerySingleInstanceW (Ordinal: 1857, Address: 0x5d250)
  • WmiReceiveNotificationsA (Ordinal: 1858, Address: 0x5d4e0)
  • WmiReceiveNotificationsW (Ordinal: 1859, Address: 0x5d560)
  • WmiSetSingleInstanceA (Ordinal: 1860, Address: 0x5d5e0)
  • WmiSetSingleInstanceW (Ordinal: 1861, Address: 0x5d6b0)
  • WmiSetSingleItemA (Ordinal: 1862, Address: 0x5d8a0)
  • WmiSetSingleItemW (Ordinal: 1863, Address: 0x5d980)
  • WriteEncryptedFileRaw (Ordinal: 1864, Address: 0x30590)

Imported DLLs & Functions

api-ms-win-core-apiquery-l1-1-0.dll
  • ApiSetQueryApiSetPresence (Address: 0x18007ba10)
api-ms-win-core-namedpipe-l1-1-0.dll
  • ImpersonateNamedPipeClient (Address: 0x18007ba20)
api-ms-win-core-pcw-l1-1-0.dll
  • PcwAddQueryItem (Address: 0x18007ba68)
  • PcwCollectData (Address: 0x18007ba40)
  • PcwCreateNotifier (Address: 0x18007ba60)
  • PcwCreateQuery (Address: 0x18007ba38)
  • PcwEnumerateInstances (Address: 0x18007ba30)
  • PcwRemoveQueryItem (Address: 0x18007ba48)
  • PcwSendNotification (Address: 0x18007ba50)
  • PcwSendStatelessNotification (Address: 0x18007ba58)
  • PcwSetQueryItemUserData (Address: 0x18007ba70)
api-ms-win-core-processthreads-l1-1-0.dll
  • CreateThread (Address: 0x18007ba98)
  • GetCurrentProcess (Address: 0x18007bad0)
  • GetCurrentProcessId (Address: 0x18007bab8)
  • GetCurrentThread (Address: 0x18007baa8)
  • GetCurrentThreadId (Address: 0x18007bab0)
  • GetPriorityClass (Address: 0x18007baa0)
  • GetProcessId (Address: 0x18007ba90)
  • OpenProcessToken (Address: 0x18007bac8)
  • OpenThread (Address: 0x18007ba80)
  • OpenThreadToken (Address: 0x18007ba88)
  • SetThreadToken (Address: 0x18007bac0)
  • TerminateProcess (Address: 0x18007bad8)
api-ms-win-core-processthreads-l1-1-1.dll
  • OpenProcess (Address: 0x18007bae8)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x18007bc38)
  • RegCopyTreeW (Address: 0x18007bbc8)
  • RegCreateKeyExA (Address: 0x18007bb58)
  • RegCreateKeyExW (Address: 0x18007bb68)
  • RegDeleteKeyExA (Address: 0x18007bb80)
  • RegDeleteKeyExW (Address: 0x18007bb20)
  • RegDeleteTreeA (Address: 0x18007baf8)
  • RegDeleteTreeW (Address: 0x18007bba0)
  • RegDeleteValueA (Address: 0x18007bc20)
  • RegDeleteValueW (Address: 0x18007bc10)
  • RegDisablePredefinedCacheEx (Address: 0x18007bb00)
  • RegEnumKeyExA (Address: 0x18007bc30)
  • RegEnumKeyExW (Address: 0x18007bb88)
  • RegEnumValueA (Address: 0x18007bc08)
  • RegEnumValueW (Address: 0x18007bc28)
  • RegFlushKey (Address: 0x18007bb60)
  • RegGetKeySecurity (Address: 0x18007bb10)
  • RegGetValueA (Address: 0x18007bb38)
  • RegGetValueW (Address: 0x18007bbf8)
  • RegLoadAppKeyA (Address: 0x18007bbb8)
  • RegLoadAppKeyW (Address: 0x18007bb18)
  • RegLoadKeyA (Address: 0x18007bbd0)
  • RegLoadKeyW (Address: 0x18007bbe8)
  • RegLoadMUIStringA (Address: 0x18007bb48)
  • RegLoadMUIStringW (Address: 0x18007bba8)
  • RegNotifyChangeKeyValue (Address: 0x18007bb08)
  • RegOpenCurrentUser (Address: 0x18007bb28)
  • RegOpenKeyExA (Address: 0x18007bbf0)
  • RegOpenKeyExW (Address: 0x18007bc40)
  • RegOpenUserClassesRoot (Address: 0x18007bb78)
  • RegQueryInfoKeyA (Address: 0x18007bbe0)
  • RegQueryInfoKeyW (Address: 0x18007bb30)
  • RegQueryValueExA (Address: 0x18007bb50)
  • RegQueryValueExW (Address: 0x18007bc48)
  • RegRestoreKeyA (Address: 0x18007bc18)
  • RegRestoreKeyW (Address: 0x18007bc00)
  • RegSaveKeyExA (Address: 0x18007bb40)
  • RegSaveKeyExW (Address: 0x18007bb98)
  • RegSetKeySecurity (Address: 0x18007bb90)
  • RegSetValueExA (Address: 0x18007bbc0)
  • RegSetValueExW (Address: 0x18007bbb0)
  • RegUnLoadKeyA (Address: 0x18007bb70)
  • RegUnLoadKeyW (Address: 0x18007bbd8)
api-ms-win-core-registry-l1-1-1.dll
  • RegDeleteKeyValueA (Address: 0x18007bc60)
  • RegDeleteKeyValueW (Address: 0x18007bc70)
  • RegSetKeyValueA (Address: 0x18007bc68)
  • RegSetKeyValueW (Address: 0x18007bc58)
api-ms-win-core-registry-l1-1-2.dll
  • RegQueryMultipleValuesA (Address: 0x18007bc88)
  • RegQueryMultipleValuesW (Address: 0x18007bc80)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetComputerNameExA (Address: 0x18007bcb0)
  • GetComputerNameExW (Address: 0x18007bca8)
  • GetLocalTime (Address: 0x18007bc98)
  • GetSystemDirectoryW (Address: 0x18007bca0)
  • GetSystemTime (Address: 0x18007bcc8)
  • GetSystemTimeAsFileTime (Address: 0x18007bcc0)
  • GetSystemWindowsDirectoryW (Address: 0x18007bcd0)
  • GetTickCount (Address: 0x18007bcb8)
api-ms-win-core-timezone-l1-1-0.dll
  • EnumDynamicTimeZoneInformation (Address: 0x18007bce0)
  • GetDynamicTimeZoneInformationEffectiveYears (Address: 0x18007bce8)
api-ms-win-eventing-consumer-l1-1-0.dll
  • CloseTrace (Address: 0x18007bcf8)
  • OpenTraceW (Address: 0x18007bd00)
  • ProcessTrace (Address: 0x18007bd08)
api-ms-win-eventing-consumer-l1-1-1.dll
  • QueryTraceProcessingHandle (Address: 0x18007bd18)
api-ms-win-eventing-controller-l1-1-0.dll
  • ControlTraceW (Address: 0x18007bd70)
  • EnableTraceEx2 (Address: 0x18007bd58)
  • EnumerateTraceGuidsEx (Address: 0x18007bd60)
  • EventAccessControl (Address: 0x18007bd48)
  • EventAccessQuery (Address: 0x18007bd28)
  • EventAccessRemove (Address: 0x18007bd30)
  • QueryAllTracesW (Address: 0x18007bd40)
  • StartTraceW (Address: 0x18007bd68)
  • StopTraceW (Address: 0x18007bd38)
  • TraceSetInformation (Address: 0x18007bd50)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventRegister (Address: 0x18007bd90)
  • EventSetInformation (Address: 0x18007bd98)
  • EventUnregister (Address: 0x18007bd88)
  • EventWriteTransfer (Address: 0x18007bd80)
api-ms-win-security-audit-l1-1-0.dll
  • AuditComputeEffectivePolicyBySid (Address: 0x18007bda8)
  • AuditFree (Address: 0x18007bdb0)
  • AuditQuerySystemPolicy (Address: 0x18007bdb8)
  • AuditSetSystemPolicy (Address: 0x18007bdc0)
api-ms-win-security-audit-l1-1-1.dll
  • AuditEnumerateCategories (Address: 0x18007be00)
  • AuditEnumeratePerUserPolicy (Address: 0x18007bde0)
  • AuditEnumerateSubCategories (Address: 0x18007bdf0)
  • AuditLookupCategoryNameW (Address: 0x18007be10)
  • AuditLookupSubCategoryNameW (Address: 0x18007bdd0)
  • AuditQueryGlobalSaclW (Address: 0x18007bdf8)
  • AuditQueryPerUserPolicy (Address: 0x18007be08)
  • AuditQuerySecurity (Address: 0x18007bdd8)
  • AuditSetGlobalSaclW (Address: 0x18007be18)
  • AuditSetPerUserPolicy (Address: 0x18007bde8)
  • AuditSetSecurity (Address: 0x18007be20)
api-ms-win-security-base-l1-1-0.dll
  • AccessCheck (Address: 0x18007c000)
  • AccessCheckAndAuditAlarmW (Address: 0x18007c090)
  • AccessCheckByType (Address: 0x18007bfb8)
  • AccessCheckByTypeAndAuditAlarmW (Address: 0x18007c110)
  • AccessCheckByTypeResultList (Address: 0x18007bfe8)
  • AccessCheckByTypeResultListAndAuditAlarmByHandleW (Address: 0x18007c010)
  • AccessCheckByTypeResultListAndAuditAlarmW (Address: 0x18007bee0)
  • AddAccessAllowedAce (Address: 0x18007bfa0)
  • AddAccessAllowedAceEx (Address: 0x18007bf70)
  • AddAccessAllowedObjectAce (Address: 0x18007bf50)
  • AddAccessDeniedAce (Address: 0x18007bef8)
  • AddAccessDeniedAceEx (Address: 0x18007c050)
  • AddAccessDeniedObjectAce (Address: 0x18007bfa8)
  • AddAce (Address: 0x18007bed0)
  • AddAuditAccessAce (Address: 0x18007bed8)
  • AddAuditAccessAceEx (Address: 0x18007bfc0)
  • AddAuditAccessObjectAce (Address: 0x18007c0b8)
  • AdjustTokenGroups (Address: 0x18007c098)
  • AdjustTokenPrivileges (Address: 0x18007c0e8)
  • AllocateAndInitializeSid (Address: 0x18007bf20)
  • AllocateLocallyUniqueId (Address: 0x18007c0c0)
  • AreAllAccessesGranted (Address: 0x18007c070)
  • AreAnyAccessesGranted (Address: 0x18007be48)
  • CheckTokenMembership (Address: 0x18007bf28)
  • ConvertToAutoInheritPrivateObjectSecurity (Address: 0x18007c0f0)
  • CopySid (Address: 0x18007c028)
  • CreatePrivateObjectSecurity (Address: 0x18007c058)
  • CreatePrivateObjectSecurityEx (Address: 0x18007c0a0)
  • CreatePrivateObjectSecurityWithMultipleInheritance (Address: 0x18007c078)
  • CreateRestrictedToken (Address: 0x18007bf00)
  • CreateWellKnownSid (Address: 0x18007c060)
  • DeleteAce (Address: 0x18007be88)
  • DestroyPrivateObjectSecurity (Address: 0x18007c038)
  • DuplicateToken (Address: 0x18007bf40)
  • DuplicateTokenEx (Address: 0x18007bf88)
  • EqualDomainSid (Address: 0x18007beb8)
  • EqualPrefixSid (Address: 0x18007bf10)
  • EqualSid (Address: 0x18007be58)
  • FindFirstFreeAce (Address: 0x18007c108)
  • FreeSid (Address: 0x18007bf08)
  • GetAce (Address: 0x18007be60)
  • GetAclInformation (Address: 0x18007c0a8)
  • GetFileSecurityW (Address: 0x18007bf18)
  • GetKernelObjectSecurity (Address: 0x18007bf58)
  • GetLengthSid (Address: 0x18007bf78)
  • GetPrivateObjectSecurity (Address: 0x18007c068)
  • GetSecurityDescriptorControl (Address: 0x18007c030)
  • GetSecurityDescriptorDacl (Address: 0x18007c0c8)
  • GetSecurityDescriptorGroup (Address: 0x18007c008)
  • GetSecurityDescriptorLength (Address: 0x18007bf98)
  • GetSecurityDescriptorOwner (Address: 0x18007bea0)
  • GetSecurityDescriptorRMControl (Address: 0x18007be68)
  • GetSecurityDescriptorSacl (Address: 0x18007c100)
  • GetSidIdentifierAuthority (Address: 0x18007bfd8)
  • GetSidLengthRequired (Address: 0x18007c080)
  • GetSidSubAuthority (Address: 0x18007c018)
  • GetSidSubAuthorityCount (Address: 0x18007be38)
  • GetTokenInformation (Address: 0x18007bfe0)
  • GetWindowsAccountDomainSid (Address: 0x18007c088)
  • ImpersonateAnonymousToken (Address: 0x18007bea8)
  • ImpersonateLoggedOnUser (Address: 0x18007c118)
  • ImpersonateSelf (Address: 0x18007beb0)
  • InitializeAcl (Address: 0x18007bf38)
  • InitializeSecurityDescriptor (Address: 0x18007bf30)
  • InitializeSid (Address: 0x18007be98)
  • IsTokenRestricted (Address: 0x18007be78)
  • IsValidAcl (Address: 0x18007bf90)
  • IsValidSecurityDescriptor (Address: 0x18007bef0)
  • IsValidSid (Address: 0x18007bec8)
  • IsWellKnownSid (Address: 0x18007be80)
  • MakeAbsoluteSD (Address: 0x18007bfc8)
  • MakeSelfRelativeSD (Address: 0x18007bfb0)
  • MapGenericMask (Address: 0x18007bf60)
  • ObjectCloseAuditAlarmW (Address: 0x18007bff8)
  • ObjectDeleteAuditAlarmW (Address: 0x18007be30)
  • ObjectOpenAuditAlarmW (Address: 0x18007c0f8)
  • ObjectPrivilegeAuditAlarmW (Address: 0x18007c020)
  • PrivilegeCheck (Address: 0x18007bff0)
  • PrivilegedServiceAuditAlarmW (Address: 0x18007be90)
  • QuerySecurityAccessMask (Address: 0x18007c0d8)
  • RevertToSelf (Address: 0x18007c0d0)
  • SetAclInformation (Address: 0x18007bee8)
  • SetFileSecurityW (Address: 0x18007c0b0)
  • SetKernelObjectSecurity (Address: 0x18007bf68)
  • SetPrivateObjectSecurity (Address: 0x18007c0e0)
  • SetPrivateObjectSecurityEx (Address: 0x18007bf48)
  • SetSecurityAccessMask (Address: 0x18007c048)
  • SetSecurityDescriptorControl (Address: 0x18007bf80)
  • SetSecurityDescriptorDacl (Address: 0x18007c040)
  • SetSecurityDescriptorGroup (Address: 0x18007bfd0)
  • SetSecurityDescriptorOwner (Address: 0x18007be70)
  • SetSecurityDescriptorRMControl (Address: 0x18007be50)
  • SetSecurityDescriptorSacl (Address: 0x18007bec0)
  • SetTokenInformation (Address: 0x18007be40)
api-ms-win-security-base-private-l1-1-0.dll
  • MakeAbsoluteSD2 (Address: 0x18007c128)
api-ms-win-service-core-l1-1-0.dll
  • RegisterServiceCtrlHandlerExW (Address: 0x18007c148)
  • SetServiceStatus (Address: 0x18007c140)
  • StartServiceCtrlDispatcherW (Address: 0x18007c138)
api-ms-win-service-core-l1-1-1.dll
  • EnumDependentServicesW (Address: 0x18007c168)
  • EnumServicesStatusExW (Address: 0x18007c160)
  • QueryServiceDynamicInformation (Address: 0x18007c158)
api-ms-win-service-core-l1-1-2.dll
  • GetServiceDisplayNameW (Address: 0x18007c180)
  • GetServiceKeyNameW (Address: 0x18007c178)
api-ms-win-service-management-l1-1-0.dll
  • CloseServiceHandle (Address: 0x18007c1c0)
  • ControlServiceExW (Address: 0x18007c1a8)
  • CreateServiceW (Address: 0x18007c190)
  • DeleteService (Address: 0x18007c1b0)
  • OpenSCManagerW (Address: 0x18007c1b8)
  • OpenServiceW (Address: 0x18007c198)
  • StartServiceW (Address: 0x18007c1a0)
api-ms-win-service-management-l2-1-0.dll
  • ChangeServiceConfig2W (Address: 0x18007c1e0)
  • ChangeServiceConfigW (Address: 0x18007c200)
  • NotifyServiceStatusChangeW (Address: 0x18007c1e8)
  • QueryServiceConfig2W (Address: 0x18007c1f8)
  • QueryServiceConfigW (Address: 0x18007c1d0)
  • QueryServiceObjectSecurity (Address: 0x18007c1f0)
  • QueryServiceStatusEx (Address: 0x18007c208)
  • SetServiceObjectSecurity (Address: 0x18007c1d8)
api-ms-win-service-private-l1-1-0.dll
  • I_ScRpcBindA (Address: 0x18007c230)
  • I_ScRpcBindW (Address: 0x18007c238)
  • I_ScSetServiceBitsA (Address: 0x18007c220)
  • I_ScSetServiceBitsW (Address: 0x18007c218)
  • WaitServiceState (Address: 0x18007c228)
api-ms-win-service-private-l1-1-2.dll
  • I_ScReparseServiceDatabase (Address: 0x18007c258)
  • QueryLocalUserServiceName (Address: 0x18007c248)
  • QueryUserServiceName (Address: 0x18007c250)
api-ms-win-service-private-l1-1-3.dll
  • QueryUserServiceNameForContext (Address: 0x18007c268)
api-ms-win-service-private-l1-1-4.dll
  • CreateServiceEx (Address: 0x18007c278)
api-ms-win-service-winsvc-l1-1-0.dll
  • ChangeServiceConfig2A (Address: 0x18007c2e8)
  • ChangeServiceConfigA (Address: 0x18007c298)
  • ControlService (Address: 0x18007c2f8)
  • ControlServiceExA (Address: 0x18007c288)
  • CreateServiceA (Address: 0x18007c2d8)
  • NotifyServiceStatusChangeA (Address: 0x18007c2b8)
  • OpenSCManagerA (Address: 0x18007c2c8)
  • OpenServiceA (Address: 0x18007c2a8)
  • QueryServiceConfig2A (Address: 0x18007c2e0)
  • QueryServiceConfigA (Address: 0x18007c2b0)
  • QueryServiceStatus (Address: 0x18007c2c0)
  • RegisterServiceCtrlHandlerA (Address: 0x18007c2f0)
  • RegisterServiceCtrlHandlerExA (Address: 0x18007c300)
  • RegisterServiceCtrlHandlerW (Address: 0x18007c290)
  • StartServiceA (Address: 0x18007c2a0)
  • StartServiceCtrlDispatcherA (Address: 0x18007c2d0)
KERNEL32.dll
  • AreFileApisANSI (Address: 0x18007b730)
  • CancelIoEx (Address: 0x18007b820)
  • CancelThreadpoolIo (Address: 0x18007b828)
  • CloseHandle (Address: 0x18007b618)
  • CloseThreadpoolIo (Address: 0x18007b818)
  • CompareFileTime (Address: 0x18007b6c8)
  • CompareStringOrdinal (Address: 0x18007b700)
  • CopyFileExW (Address: 0x18007b7c8)
  • CreateEventW (Address: 0x18007b610)
  • CreateFileMappingW (Address: 0x18007b6a8)
  • CreateFileW (Address: 0x18007b650)
  • CreateMutexW (Address: 0x18007b760)
  • CreateThreadpoolIo (Address: 0x18007b830)
  • DecodePointer (Address: 0x18007b7e8)
  • DelayLoadFailureHook (Address: 0x18007b5e8)
  • DeleteCriticalSection (Address: 0x18007b6e8)
  • DeleteFileW (Address: 0x18007b670)
  • DeviceIoControl (Address: 0x18007b838)
  • DosDateTimeToFileTime (Address: 0x18007b7a0)
  • DuplicateHandle (Address: 0x18007b7f8)
  • EncodePointer (Address: 0x18007b808)
  • EnterCriticalSection (Address: 0x18007b5b8)
  • EnumUILanguagesW (Address: 0x18007b850)
  • ExpandEnvironmentStringsA (Address: 0x18007b720)
  • ExpandEnvironmentStringsW (Address: 0x18007b640)
  • FileTimeToDosDateTime (Address: 0x18007b798)
  • FindClose (Address: 0x18007b7c0)
  • FindFirstFileExW (Address: 0x18007b7b0)
  • FindNextFileW (Address: 0x18007b7b8)
  • FindResourceExW (Address: 0x18007b6d0)
  • FormatMessageW (Address: 0x18007b658)
  • FreeLibrary (Address: 0x18007b5d8)
  • FreeLibraryAndExitThread (Address: 0x18007b800)
  • FreeLibraryWhenCallbackReturns (Address: 0x18007b810)
  • GetCommandLineW (Address: 0x18007b628)
  • GetComputerNameW (Address: 0x18007b718)
  • GetFileAttributesExW (Address: 0x18007b660)
  • GetFileAttributesW (Address: 0x18007b740)
  • GetFileMUIPath (Address: 0x18007b848)
  • GetFileSize (Address: 0x18007b7a8)
  • GetFileSizeEx (Address: 0x18007b6a0)
  • GetFileTime (Address: 0x18007b790)
  • GetFullPathNameW (Address: 0x18007b738)
  • GetLastError (Address: 0x18007b5c8)
  • GetLongPathNameW (Address: 0x18007b6c0)
  • GetModuleFileNameW (Address: 0x18007b728)
  • GetModuleHandleExW (Address: 0x18007b630)
  • GetModuleHandleW (Address: 0x18007b680)
  • GetProcAddress (Address: 0x18007b5d0)
  • GetProcessHeap (Address: 0x18007b690)
  • GetThreadUILanguage (Address: 0x18007b620)
  • GetVolumePathNameW (Address: 0x18007b6e0)
  • HeapAlloc (Address: 0x18007b698)
  • HeapFree (Address: 0x18007b688)
  • InitializeCriticalSection (Address: 0x18007b768)
  • InitOnceBeginInitialize (Address: 0x18007b6f8)
  • InitOnceComplete (Address: 0x18007b710)
  • LeaveCriticalSection (Address: 0x18007b5c0)
  • LoadLibraryA (Address: 0x18007b758)
  • LoadLibraryExA (Address: 0x18007b750)
  • LoadLibraryExW (Address: 0x18007b5e0)
  • LoadLibraryW (Address: 0x18007b7f0)
  • LoadResource (Address: 0x18007b6d8)
  • LocalFree (Address: 0x18007b5a8)
  • LockResource (Address: 0x18007b778)
  • MapViewOfFile (Address: 0x18007b6b0)
  • MoveFileW (Address: 0x18007b678)
  • MultiByteToWideChar (Address: 0x18007b5a0)
  • OutputDebugStringW (Address: 0x18007b668)
  • QueryPerformanceCounter (Address: 0x18007b608)
  • RaiseException (Address: 0x18007b860)
  • ReadProcessMemory (Address: 0x18007b7e0)
  • ReleaseMutex (Address: 0x18007b708)
  • ResetEvent (Address: 0x18007b788)
  • ResolveDelayLoadedAPI (Address: 0x18007b5f0)
  • SearchPathW (Address: 0x18007b598)
  • SetErrorMode (Address: 0x18007b858)
  • SetEvent (Address: 0x18007b780)
  • SetFileInformationByHandle (Address: 0x18007b868)
  • SetFilePointer (Address: 0x18007b648)
  • SetLastError (Address: 0x18007b870)
  • SetUnhandledExceptionFilter (Address: 0x18007b600)
  • SizeofResource (Address: 0x18007b770)
  • SleepEx (Address: 0x18007b748)
  • StartThreadpoolIo (Address: 0x18007b840)
  • TermsrvDeleteKey (Address: 0x18007b7d0)
  • TermsrvOpenUserClasses (Address: 0x18007b7d8)
  • UnhandledExceptionFilter (Address: 0x18007b5f8)
  • UnmapViewOfFile (Address: 0x18007b6b8)
  • WaitForSingleObject (Address: 0x18007b6f0)
  • WideCharToMultiByte (Address: 0x18007b5b0)
  • WriteFile (Address: 0x18007b638)
KERNELBASE.dll
  • CLOSE_LOCAL_HANDLE_INTERNAL (Address: 0x18007b8e0)
  • CreateProcessAsUserA (Address: 0x18007b8c0)
  • CreateProcessAsUserW (Address: 0x18007b8b8)
  • DisablePredefinedHandleTableInternal (Address: 0x18007b908)
  • GetStagedPackagePathByFullName (Address: 0x18007b940)
  • GetSystemDefaultUILanguage (Address: 0x18007b918)
  • GetUserDefaultUILanguage (Address: 0x18007b920)
  • LocalAlloc (Address: 0x18007b8a8)
  • LocalReAlloc (Address: 0x18007b8b0)
  • lstrcmpiW (Address: 0x18007b880)
  • lstrcmpW (Address: 0x18007b928)
  • lstrlenW (Address: 0x18007b8a0)
  • MapPredefinedHandleInternal (Address: 0x18007b8e8)
  • PackageIdFromFullName (Address: 0x18007b938)
  • RegCreateKeyExInternalA (Address: 0x18007b900)
  • RegCreateKeyExInternalW (Address: 0x18007b8d0)
  • RegDeleteKeyExInternalA (Address: 0x18007b8f0)
  • RegDeleteKeyExInternalW (Address: 0x18007b8c8)
  • RegKrnGetClassesEnumTableAddressInternal (Address: 0x18007b890)
  • RegKrnGetHKEY_ClassesRootAddress (Address: 0x18007b888)
  • RegKrnGetTermsrvRegistryExtensionFlags (Address: 0x18007b898)
  • RegOpenKeyExInternalA (Address: 0x18007b910)
  • RegOpenKeyExInternalW (Address: 0x18007b8d8)
  • RemapPredefinedHandleInternal (Address: 0x18007b8f8)
  • Sleep (Address: 0x18007b930)
msvcrt.dll
  • __C_specific_handler (Address: 0x18007c428)
  • __CxxFrameHandler3 (Address: 0x18007c3d0)
  • _errno (Address: 0x18007c388)
  • _i64tow_s (Address: 0x18007c398)
  • _resetstkoflw (Address: 0x18007c3b0)
  • _stricmp (Address: 0x18007c3a0)
  • _ui64tow_s (Address: 0x18007c390)
  • _ultow (Address: 0x18007c378)
  • _ultow_s (Address: 0x18007c350)
  • _vsnprintf (Address: 0x18007c3c8)
  • _vsnwprintf (Address: 0x18007c408)
  • _wcsicmp (Address: 0x18007c328)
  • _wcsnicmp (Address: 0x18007c330)
  • _wcstoi64 (Address: 0x18007c3d8)
  • _wcstoui64 (Address: 0x18007c368)
  • iswalpha (Address: 0x18007c3b8)
  • iswctype (Address: 0x18007c358)
  • memcmp (Address: 0x18007c3e8)
  • memcpy (Address: 0x18007c3f0)
  • memcpy_s (Address: 0x18007c3e0)
  • memmove (Address: 0x18007c3f8)
  • memset (Address: 0x18007c400)
  • strchr (Address: 0x18007c348)
  • strstr (Address: 0x18007c340)
  • swprintf_s (Address: 0x18007c320)
  • swscanf_s (Address: 0x18007c420)
  • tolower (Address: 0x18007c338)
  • wcscat_s (Address: 0x18007c318)
  • wcschr (Address: 0x18007c418)
  • wcscmp (Address: 0x18007c438)
  • wcscpy_s (Address: 0x18007c310)
  • wcsncmp (Address: 0x18007c3c0)
  • wcsncpy_s (Address: 0x18007c430)
  • wcsnlen (Address: 0x18007c3a8)
  • wcsrchr (Address: 0x18007c410)
  • wcsstr (Address: 0x18007c370)
  • wcstok_s (Address: 0x18007c380)
  • wcstoul (Address: 0x18007c360)
ntdll.dll
  • DbgPrint (Address: 0x18007ca08)
  • EtwEventRegister (Address: 0x18007c540)
  • EtwEventSetInformation (Address: 0x18007c758)
  • EtwEventUnregister (Address: 0x18007c598)
  • EtwEventWrite (Address: 0x18007c548)
  • EtwEventWriteTransfer (Address: 0x18007c750)
  • EtwGetTraceEnableFlags (Address: 0x18007c7a0)
  • EtwGetTraceEnableLevel (Address: 0x18007c798)
  • EtwGetTraceLoggerHandle (Address: 0x18007c790)
  • EtwRegisterTraceGuidsW (Address: 0x18007c7a8)
  • EtwTraceMessage (Address: 0x18007c788)
  • EtwUnregisterTraceGuids (Address: 0x18007c7b0)
  • LdrGetDllHandle (Address: 0x18007ca48)
  • LdrGetProcedureAddress (Address: 0x18007ca40)
  • LdrLoadDll (Address: 0x18007c518)
  • LdrUnloadDll (Address: 0x18007c528)
  • NtAlpcQueryInformation (Address: 0x18007c8f8)
  • NtClose (Address: 0x18007c458)
  • NtCompareTokens (Address: 0x18007c4a8)
  • NtCreateFile (Address: 0x18007c848)
  • NtCreateKey (Address: 0x18007c550)
  • NtCreateMutant (Address: 0x18007c808)
  • NtCreatePrivateNamespace (Address: 0x18007c818)
  • NtDeleteKey (Address: 0x18007c570)
  • NtDeviceIoControlFile (Address: 0x18007c530)
  • NtDuplicateToken (Address: 0x18007c4a0)
  • NtEnumerateKey (Address: 0x18007c5a0)
  • NtOpenFile (Address: 0x18007c4e8)
  • NtOpenKey (Address: 0x18007c448)
  • NtOpenKeyEx (Address: 0x18007ca30)
  • NtOpenPrivateNamespace (Address: 0x18007c810)
  • NtOpenProcessToken (Address: 0x18007c468)
  • NtOpenSymbolicLinkObject (Address: 0x18007c600)
  • NtOpenThreadToken (Address: 0x18007c460)
  • NtQueryInformationFile (Address: 0x18007c620)
  • NtQueryInformationProcess (Address: 0x18007c4f8)
  • NtQueryInformationThread (Address: 0x18007c7c8)
  • NtQueryInformationToken (Address: 0x18007c9a8)
  • NtQueryKey (Address: 0x18007c508)
  • NtQueryMutant (Address: 0x18007c910)
  • NtQueryObject (Address: 0x18007c908)
  • NtQueryPerformanceCounter (Address: 0x18007c7f8)
  • NtQuerySecurityObject (Address: 0x18007c7d0)
  • NtQuerySymbolicLinkObject (Address: 0x18007c608)
  • NtQuerySystemInformation (Address: 0x18007c538)
  • NtQuerySystemTime (Address: 0x18007c778)
  • NtQueryValueKey (Address: 0x18007c450)
  • NtQueryVolumeInformationFile (Address: 0x18007c5f8)
  • NtReadFile (Address: 0x18007c858)
  • NtRenameKey (Address: 0x18007c680)
  • NtReplaceKey (Address: 0x18007c930)
  • NtSaveKey (Address: 0x18007c938)
  • NtSaveMergedKeys (Address: 0x18007c940)
  • NtSetInformationKey (Address: 0x18007ca38)
  • NtSetInformationThread (Address: 0x18007c6a0)
  • NtSetInformationToken (Address: 0x18007c488)
  • NtSetSystemInformation (Address: 0x18007c9f0)
  • NtSetValueKey (Address: 0x18007c558)
  • NtTraceControl (Address: 0x18007c658)
  • NtWaitForMultipleObjects (Address: 0x18007c830)
  • NtWaitForSingleObject (Address: 0x18007c7b8)
  • NtWriteFile (Address: 0x18007c850)
  • RtlAbsoluteToSelfRelativeSD (Address: 0x18007c710)
  • RtlAcquireSRWLockExclusive (Address: 0x18007c878)
  • RtlAcquireSRWLockShared (Address: 0x18007c890)
  • RtlAddAccessAllowedAce (Address: 0x18007c920)
  • RtlAddAccessAllowedAceEx (Address: 0x18007c480)
  • RtlAddAccessAllowedObjectAce (Address: 0x18007c720)
  • RtlAddAccessDeniedAceEx (Address: 0x18007c718)
  • RtlAddAccessDeniedObjectAce (Address: 0x18007c728)
  • RtlAddAce (Address: 0x18007c6a8)
  • RtlAddAuditAccessAceEx (Address: 0x18007c6f0)
  • RtlAddAuditAccessObjectAce (Address: 0x18007c6d0)
  • RtlAddSIDToBoundaryDescriptor (Address: 0x18007c820)
  • RtlAdjustPrivilege (Address: 0x18007c768)
  • RtlAllocateAndInitializeSid (Address: 0x18007c4b0)
  • RtlAllocateHandle (Address: 0x18007c960)
  • RtlAllocateHeap (Address: 0x18007c9b8)
  • RtlAnsiCharToUnicodeChar (Address: 0x18007c648)
  • RtlAnsiStringToUnicodeString (Address: 0x18007ca58)
  • RtlAppendUnicodeStringToString (Address: 0x18007c5b8)
  • RtlAppendUnicodeToString (Address: 0x18007c568)
  • RtlCaptureContext (Address: 0x18007c9d8)
  • RtlConvertSidToUnicodeString (Address: 0x18007c970)
  • RtlCopySid (Address: 0x18007c580)
  • RtlCopyString (Address: 0x18007c770)
  • RtlCopyUnicodeString (Address: 0x18007c4d0)
  • RtlCreateAcl (Address: 0x18007c838)
  • RtlCreateBoundaryDescriptor (Address: 0x18007c828)
  • RtlCreateQueryDebugBuffer (Address: 0x18007c900)
  • RtlCreateSecurityDescriptor (Address: 0x18007c490)
  • RtlCreateUnicodeString (Address: 0x18007c4f0)
  • RtlCreateUnicodeStringFromAsciiz (Address: 0x18007c678)
  • RtlDeleteBoundaryDescriptor (Address: 0x18007c800)
  • RtlDeleteCriticalSection (Address: 0x18007c9e8)
  • RtlDeleteElementGenericTable (Address: 0x18007c560)
  • RtlDeleteElementGenericTableAvl (Address: 0x18007c8b0)
  • RtlDestroyHandleTable (Address: 0x18007c590)
  • RtlDestroyQueryDebugBuffer (Address: 0x18007c8e8)
  • RtlDetermineDosPathNameType_U (Address: 0x18007c618)
  • RtlDllShutdownInProgress (Address: 0x18007c7e8)
  • RtlDosPathNameToNtPathName_U (Address: 0x18007c748)
  • RtlDosPathNameToRelativeNtPathName_U (Address: 0x18007c8c8)
  • RtlDuplicateUnicodeString (Address: 0x18007c4d8)
  • RtlEnterCriticalSection (Address: 0x18007ca00)
  • RtlEnumerateGenericTableAvl (Address: 0x18007c8a8)
  • RtlEnumerateGenericTableWithoutSplaying (Address: 0x18007c4c8)
  • RtlEqualSid (Address: 0x18007c470)
  • RtlEqualUnicodeString (Address: 0x18007c8e0)
  • RtlExpandEnvironmentStrings_U (Address: 0x18007c4e0)
  • RtlFirstFreeAce (Address: 0x18007c730)
  • RtlFormatCurrentUserKeyPath (Address: 0x18007c5c0)
  • RtlFreeAnsiString (Address: 0x18007ca60)
  • RtlFreeHandle (Address: 0x18007c738)
  • RtlFreeHeap (Address: 0x18007c998)
  • RtlFreeSid (Address: 0x18007c4b8)
  • RtlFreeUnicodeString (Address: 0x18007c9b0)
  • RtlGetAce (Address: 0x18007c6e8)
  • RtlGetControlSecurityDescriptor (Address: 0x18007c6c8)
  • RtlGetCurrentTransaction (Address: 0x18007ca28)
  • RtlGetDaclSecurityDescriptor (Address: 0x18007c740)
  • RtlGetFullPathName_U (Address: 0x18007c628)
  • RtlGetGroupSecurityDescriptor (Address: 0x18007c708)
  • RtlGetLastNtStatus (Address: 0x18007c500)
  • RtlGetNtProductType (Address: 0x18007c958)
  • RtlGetOwnerSecurityDescriptor (Address: 0x18007c700)
  • RtlGetSaclSecurityDescriptor (Address: 0x18007c6e0)
  • RtlGetThreadPreferredUILanguages (Address: 0x18007c988)
  • RtlGetVersion (Address: 0x18007c7c0)
  • RtlGUIDFromString (Address: 0x18007c5e8)
  • RtlImageNtHeader (Address: 0x18007c520)
  • RtlImpersonateSelf (Address: 0x18007c760)
  • RtlInitAnsiString (Address: 0x18007ca18)
  • RtlInitAnsiStringEx (Address: 0x18007c668)
  • RtlInitializeCriticalSection (Address: 0x18007c9e0)
  • RtlInitializeGenericTable (Address: 0x18007c5c8)
  • RtlInitializeGenericTableAvl (Address: 0x18007c8b8)
  • RtlInitializeHandleTable (Address: 0x18007c588)
  • RtlInitializeSid (Address: 0x18007c6c0)
  • RtlInitializeSRWLock (Address: 0x18007c8d8)
  • RtlInitString (Address: 0x18007c918)
  • RtlInitUnicodeString (Address: 0x18007ca50)
  • RtlInitUnicodeStringEx (Address: 0x18007c670)
  • RtlInsertElementGenericTable (Address: 0x18007c578)
  • RtlInsertElementGenericTableAvl (Address: 0x18007c880)
  • RtlIntegerToUnicodeString (Address: 0x18007c5a8)
  • RtlIsGenericTableEmpty (Address: 0x18007c4c0)
  • RtlIsTextUnicode (Address: 0x18007c698)
  • RtlIsValidIndexHandle (Address: 0x18007ca68)
  • RtlLeaveCriticalSection (Address: 0x18007c9f8)
  • RtlLengthSecurityDescriptor (Address: 0x18007c948)
  • RtlLengthSid (Address: 0x18007c478)
  • RtlLookupElementGenericTable (Address: 0x18007c5d8)
  • RtlLookupElementGenericTableAvl (Address: 0x18007c898)
  • RtlLookupFunctionEntry (Address: 0x18007c9d0)
  • RtlMakeSelfRelativeSD (Address: 0x18007c990)
  • RtlMultiByteToUnicodeN (Address: 0x18007c650)
  • RtlNtStatusToDosError (Address: 0x18007ca10)
  • RtlNtStatusToDosErrorNoTeb (Address: 0x18007c638)
  • RtlNumberGenericTableElements (Address: 0x18007c5e0)
  • RtlOemStringToUnicodeString (Address: 0x18007c690)
  • RtlOpenCurrentUser (Address: 0x18007c928)
  • RtlPrefixUnicodeString (Address: 0x18007c610)
  • RtlQueryPackageIdentity (Address: 0x18007c688)
  • RtlQueryPerformanceCounter (Address: 0x18007c870)
  • RtlQueryProcessDebugInformation (Address: 0x18007c8f0)
  • RtlQueryRegistryValuesEx (Address: 0x18007c5d0)
  • RtlReleaseRelativeName (Address: 0x18007c8d0)
  • RtlReleaseSRWLockExclusive (Address: 0x18007c888)
  • RtlReleaseSRWLockShared (Address: 0x18007c8a0)
  • RtlRunOnceBeginInitialize (Address: 0x18007c7e0)
  • RtlRunOnceExecuteOnce (Address: 0x18007c7d8)
  • RtlRunOnceInitialize (Address: 0x18007c7f0)
  • RtlSetDaclSecurityDescriptor (Address: 0x18007c6d8)
  • RtlSetGroupSecurityDescriptor (Address: 0x18007c9c0)
  • RtlSetLastWin32Error (Address: 0x18007c660)
  • RtlSetOwnerSecurityDescriptor (Address: 0x18007c498)
  • RtlSetSaclSecurityDescriptor (Address: 0x18007c6b8)
  • RtlStringFromGUID (Address: 0x18007c5b0)
  • RtlSubAuthorityCountSid (Address: 0x18007c978)
  • RtlSubAuthoritySid (Address: 0x18007c980)
  • RtlTimeToSecondsSince1970 (Address: 0x18007c780)
  • RtlUnicodeStringToAnsiString (Address: 0x18007ca20)
  • RtlUnicodeStringToInteger (Address: 0x18007c968)
  • RtlUnicodeToMultiByteN (Address: 0x18007c630)
  • RtlUnicodeToMultiByteSize (Address: 0x18007c640)
  • RtlUpcaseUnicodeChar (Address: 0x18007c5f0)
  • RtlValidAcl (Address: 0x18007c6b0)
  • RtlValidRelativeSecurityDescriptor (Address: 0x18007c840)
  • RtlValidSecurityDescriptor (Address: 0x18007c950)
  • RtlValidSid (Address: 0x18007c510)
  • RtlVirtualUnwind (Address: 0x18007c9c8)
  • RtlWaitOnAddress (Address: 0x18007c860)
  • RtlWakeAddressAll (Address: 0x18007c868)
  • RtlWakeAddressSingle (Address: 0x18007c8c0)
  • RtlxAnsiStringToUnicodeSize (Address: 0x18007c6f8)
  • RtlxUnicodeStringToAnsiSize (Address: 0x18007c9a0)
RPCRT4.dll
  • I_RpcExceptionFilter (Address: 0x18007b9e0)
  • I_RpcMapWin32Status (Address: 0x18007b9d8)
  • I_RpcSNCHOption (Address: 0x18007b9c0)
  • NdrClientCall2 (Address: 0x18007b9a8)
  • NdrClientCall3 (Address: 0x18007b980)
  • RpcBindingBind (Address: 0x18007b950)
  • RpcBindingCreateW (Address: 0x18007b958)
  • RpcBindingFree (Address: 0x18007b978)
  • RpcBindingFromStringBindingW (Address: 0x18007b9a0)
  • RpcBindingSetAuthInfoA (Address: 0x18007b9b8)
  • RpcBindingSetAuthInfoExW (Address: 0x18007b968)
  • RpcBindingSetAuthInfoW (Address: 0x18007b9d0)
  • RpcEpResolveBinding (Address: 0x18007b9c8)
  • RpcExceptionFilter (Address: 0x18007b988)
  • RpcSsDestroyClientContext (Address: 0x18007b960)
  • RpcStringBindingComposeW (Address: 0x18007b9b0)
  • RpcStringFreeW (Address: 0x18007b970)
  • UuidFromStringW (Address: 0x18007b998)
  • UuidToStringW (Address: 0x18007b990)
SECHOST.dll
  • ControlTraceA (Address: 0x18007b9f8)
  • QueryAllTracesA (Address: 0x18007b9f0)
  • StartTraceA (Address: 0x18007ba00)