advapi32.dll
Description: Advanced Windows 32 Base API
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.6328
Architecture: 32-bit
Operating System: Windows NT
SHA256: 20e2c93010771a529ae82b8122baf5e1
File Size: 492.4 KB
Uploaded At: Dec. 1, 2025, 7:52 a.m.
Views: 21
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- (Ordinal: 1000, Address: 0x3dde0)
- I_ScGetCurrentGroupStateW (Ordinal: 1001, Address: 0x35640)
- A_SHAFinal (Ordinal: 1002, Address: 0x661de)
- A_SHAInit (Ordinal: 1003, Address: 0x661f9)
- A_SHAUpdate (Ordinal: 1004, Address: 0x66215)
- AbortSystemShutdownA (Ordinal: 1005, Address: 0x45660)
- AbortSystemShutdownW (Ordinal: 1006, Address: 0x456d0)
- AccessCheck (Ordinal: 1007, Address: 0x35bd0)
- AccessCheckAndAuditAlarmA (Ordinal: 1008, Address: 0x47bc0)
- AccessCheckAndAuditAlarmW (Ordinal: 1009, Address: 0x35b10)
- AccessCheckByType (Ordinal: 1010, Address: 0x35bb0)
- AccessCheckByTypeAndAuditAlarmA (Ordinal: 1011, Address: 0x47cd0)
- AccessCheckByTypeAndAuditAlarmW (Ordinal: 1012, Address: 0x35b30)
- AccessCheckByTypeResultList (Ordinal: 1013, Address: 0x35b90)
- AccessCheckByTypeResultListAndAuditAlarmA (Ordinal: 1014, Address: 0x47df0)
- AccessCheckByTypeResultListAndAuditAlarmByHandleA (Ordinal: 1015, Address: 0x47f10)
- AccessCheckByTypeResultListAndAuditAlarmByHandleW (Ordinal: 1016, Address: 0x35b50)
- AccessCheckByTypeResultListAndAuditAlarmW (Ordinal: 1017, Address: 0x35b70)
- AddAccessAllowedAce (Ordinal: 1018, Address: 0x1f6a0)
- AddAccessAllowedAceEx (Ordinal: 1019, Address: 0x201c0)
- AddAccessAllowedObjectAce (Ordinal: 1020, Address: 0x35bf0)
- AddAccessDeniedAce (Ordinal: 1021, Address: 0x35c30)
- AddAccessDeniedAceEx (Ordinal: 1022, Address: 0x35c10)
- AddAccessDeniedObjectAce (Ordinal: 1023, Address: 0x35c50)
- AddAce (Ordinal: 1024, Address: 0x35c70)
- AddAuditAccessAce (Ordinal: 1025, Address: 0x35cb0)
- AddAuditAccessAceEx (Ordinal: 1026, Address: 0x35c90)
- AddAuditAccessObjectAce (Ordinal: 1027, Address: 0x35cd0)
- AddConditionalAce (Ordinal: 1028, Address: 0x4a8f0)
- AddMandatoryAce (Ordinal: 1029, Address: 0x664a3)
- AddUsersToEncryptedFile (Ordinal: 1030, Address: 0x35080)
- AddUsersToEncryptedFileEx (Ordinal: 1031, Address: 0x350e0)
- AdjustTokenGroups (Ordinal: 1032, Address: 0x35cf0)
- AdjustTokenPrivileges (Ordinal: 1033, Address: 0x20370)
- AllocateAndInitializeSid (Ordinal: 1034, Address: 0x1f5c0)
- AllocateLocallyUniqueId (Ordinal: 1035, Address: 0x35d10)
- AreAllAccessesGranted (Ordinal: 1036, Address: 0x35d30)
- AreAnyAccessesGranted (Ordinal: 1037, Address: 0x35d50)
- AuditComputeEffectivePolicyBySid (Ordinal: 1038, Address: 0x35d70)
- AuditComputeEffectivePolicyByToken (Ordinal: 1039, Address: 0x37e30)
- AuditEnumerateCategories (Ordinal: 1040, Address: 0x35d90)
- AuditEnumeratePerUserPolicy (Ordinal: 1041, Address: 0x35db0)
- AuditEnumerateSubCategories (Ordinal: 1042, Address: 0x35dd0)
- AuditFree (Ordinal: 1043, Address: 0x25400)
- AuditLookupCategoryGuidFromCategoryId (Ordinal: 1044, Address: 0x37f20)
- AuditLookupCategoryIdFromCategoryGuid (Ordinal: 1045, Address: 0x37f60)
- AuditLookupCategoryNameA (Ordinal: 1046, Address: 0x37fc0)
- AuditLookupCategoryNameW (Ordinal: 1047, Address: 0x35df0)
- AuditLookupSubCategoryNameA (Ordinal: 1048, Address: 0x38030)
- AuditLookupSubCategoryNameW (Ordinal: 1049, Address: 0x35e10)
- AuditQueryGlobalSaclA (Ordinal: 1050, Address: 0x380a0)
- AuditQueryGlobalSaclW (Ordinal: 1051, Address: 0x35e30)
- AuditQueryPerUserPolicy (Ordinal: 1052, Address: 0x253e0)
- AuditQuerySecurity (Ordinal: 1053, Address: 0x35e50)
- AuditQuerySystemPolicy (Ordinal: 1054, Address: 0x253a0)
- AuditSetGlobalSaclA (Ordinal: 1055, Address: 0x38120)
- AuditSetGlobalSaclW (Ordinal: 1056, Address: 0x35e70)
- AuditSetPerUserPolicy (Ordinal: 1057, Address: 0x35e90)
- AuditSetSecurity (Ordinal: 1058, Address: 0x35eb0)
- AuditSetSystemPolicy (Ordinal: 1059, Address: 0x35ed0)
- BackupEventLogA (Ordinal: 1060, Address: 0x50f10)
- BackupEventLogW (Ordinal: 1061, Address: 0x50f90)
- BaseRegCloseKey (Ordinal: 1062, Address: 0x45ab0)
- BaseRegCreateKey (Ordinal: 1063, Address: 0x45ae0)
- BaseRegDeleteKeyEx (Ordinal: 1064, Address: 0x45b20)
- BaseRegDeleteValue (Ordinal: 1065, Address: 0x45b50)
- BaseRegFlushKey (Ordinal: 1066, Address: 0x45b80)
- BaseRegGetVersion (Ordinal: 1067, Address: 0x26cc0)
- BaseRegLoadKey (Ordinal: 1068, Address: 0x45bb0)
- BaseRegOpenKey (Ordinal: 1069, Address: 0x45be0)
- BaseRegRestoreKey (Ordinal: 1070, Address: 0x45c10)
- BaseRegSaveKeyEx (Ordinal: 1071, Address: 0x45c40)
- BaseRegSetKeySecurity (Ordinal: 1072, Address: 0x45c70)
- BaseRegSetValue (Ordinal: 1073, Address: 0x45ca0)
- BaseRegUnLoadKey (Ordinal: 1074, Address: 0x45cd0)
- BuildExplicitAccessWithNameA (Ordinal: 1075, Address: 0x23f20)
- BuildExplicitAccessWithNameW (Ordinal: 1076, Address: 0x23f20)
- BuildImpersonateExplicitAccessWithNameA (Ordinal: 1077, Address: 0x41a70)
- BuildImpersonateExplicitAccessWithNameW (Ordinal: 1078, Address: 0x41a70)
- BuildImpersonateTrusteeA (Ordinal: 1079, Address: 0x422c0)
- BuildImpersonateTrusteeW (Ordinal: 1080, Address: 0x422c0)
- BuildSecurityDescriptorA (Ordinal: 1081, Address: 0x41ab0)
- BuildSecurityDescriptorW (Ordinal: 1082, Address: 0x23b00)
- BuildTrusteeWithNameA (Ordinal: 1083, Address: 0x422e0)
- BuildTrusteeWithNameW (Ordinal: 1084, Address: 0x422e0)
- BuildTrusteeWithObjectsAndNameA (Ordinal: 1085, Address: 0x42310)
- BuildTrusteeWithObjectsAndNameW (Ordinal: 1086, Address: 0x42310)
- BuildTrusteeWithObjectsAndSidA (Ordinal: 1087, Address: 0x42370)
- BuildTrusteeWithObjectsAndSidW (Ordinal: 1088, Address: 0x42370)
- BuildTrusteeWithSidA (Ordinal: 1089, Address: 0x20b40)
- BuildTrusteeWithSidW (Ordinal: 1090, Address: 0x20b40)
- CancelOverlappedAccess (Ordinal: 1091, Address: 0x428b0)
- ChangeServiceConfig2A (Ordinal: 1092, Address: 0x35ef0)
- ChangeServiceConfig2W (Ordinal: 1093, Address: 0x35f10)
- ChangeServiceConfigA (Ordinal: 1094, Address: 0x35f30)
- ChangeServiceConfigW (Ordinal: 1095, Address: 0x35f50)
- CheckForHiberboot (Ordinal: 1096, Address: 0x1fc20)
- CheckTokenMembership (Ordinal: 1097, Address: 0x1fa70)
- ClearEventLogA (Ordinal: 1098, Address: 0x51190)
- ClearEventLogW (Ordinal: 1099, Address: 0x51210)
- CloseCodeAuthzLevel (Ordinal: 1100, Address: 0x1ef40)
- CloseEncryptedFileRaw (Ordinal: 1101, Address: 0x35140)
- CloseEventLog (Ordinal: 1102, Address: 0x24290)
- CloseServiceHandle (Ordinal: 1103, Address: 0x20990)
- CloseThreadWaitChainSession (Ordinal: 1104, Address: 0x5d450)
- CloseTrace (Ordinal: 1105, Address: 0x20a70)
- CommandLineFromMsiDescriptor (Ordinal: 1106, Address: 0x20390)
- ComputeAccessTokenFromCodeAuthzLevel (Ordinal: 1107, Address: 0x1bbc0)
- ControlService (Ordinal: 1108, Address: 0x35fb0)
- ControlServiceExA (Ordinal: 1109, Address: 0x35f70)
- ControlServiceExW (Ordinal: 1110, Address: 0x35f90)
- ControlTraceA (Ordinal: 1111, Address: 0x25a60)
- ControlTraceW (Ordinal: 1112, Address: 0x23960)
- ConvertAccessToSecurityDescriptorA (Ordinal: 1113, Address: 0x42930)
- ConvertAccessToSecurityDescriptorW (Ordinal: 1114, Address: 0x42a30)
- ConvertSDToStringSDDomainW (Ordinal: 1115, Address: 0x4af50)
- ConvertSDToStringSDRootDomainA (Ordinal: 1116, Address: 0x4afb0)
- ConvertSDToStringSDRootDomainW (Ordinal: 1117, Address: 0x4b0a0)
- ConvertSecurityDescriptorToAccessA (Ordinal: 1118, Address: 0x42a90)
- ConvertSecurityDescriptorToAccessNamedA (Ordinal: 1119, Address: 0x42a90)
- ConvertSecurityDescriptorToAccessNamedW (Ordinal: 1120, Address: 0x42ac0)
- ConvertSecurityDescriptorToAccessW (Ordinal: 1121, Address: 0x42ac0)
- ConvertSecurityDescriptorToStringSecurityDescriptorA (Ordinal: 1122, Address: 0x4b100)
- ConvertSecurityDescriptorToStringSecurityDescriptorW (Ordinal: 1123, Address: 0x4b1d0)
- ConvertSidToStringSidA (Ordinal: 1124, Address: 0x1ece0)
- ConvertSidToStringSidW (Ordinal: 1125, Address: 0x1eaf0)
- ConvertStringSDToSDDomainA (Ordinal: 1126, Address: 0x4b260)
- ConvertStringSDToSDDomainW (Ordinal: 1127, Address: 0x4b320)
- ConvertStringSDToSDRootDomainA (Ordinal: 1128, Address: 0x4b3a0)
- ConvertStringSDToSDRootDomainW (Ordinal: 1129, Address: 0x4b430)
- ConvertStringSecurityDescriptorToSecurityDescriptorA (Ordinal: 1130, Address: 0x24d80)
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Ordinal: 1131, Address: 0x18db0)
- ConvertStringSidToSidA (Ordinal: 1132, Address: 0x4b490)
- ConvertStringSidToSidW (Ordinal: 1133, Address: 0x19fb0)
- ConvertToAutoInheritPrivateObjectSecurity (Ordinal: 1134, Address: 0x35fd0)
- CopySid (Ordinal: 1135, Address: 0x1f280)
- CreateCodeAuthzLevel (Ordinal: 1136, Address: 0x3c850)
- CreatePrivateObjectSecurity (Ordinal: 1137, Address: 0x23aa0)
- CreatePrivateObjectSecurityEx (Ordinal: 1138, Address: 0x35ff0)
- CreatePrivateObjectSecurityWithMultipleInheritance (Ordinal: 1139, Address: 0x36010)
- CreateProcessAsUserA (Ordinal: 1140, Address: 0x36030)
- CreateProcessAsUserW (Ordinal: 1141, Address: 0x20a90)
- CreateProcessWithLogonW (Ordinal: 1142, Address: 0x4a500)
- CreateProcessWithTokenW (Ordinal: 1143, Address: 0x4a540)
- CreateRestrictedToken (Ordinal: 1144, Address: 0x20d70)
- CreateServiceA (Ordinal: 1145, Address: 0x36050)
- CreateServiceEx (Ordinal: 1146, Address: 0x25b00)
- CreateServiceW (Ordinal: 1147, Address: 0x36070)
- CreateTraceInstanceId (Ordinal: 1148, Address: 0x67055)
- CreateWellKnownSid (Ordinal: 1149, Address: 0x20970)
- CredBackupCredentials (Ordinal: 1150, Address: 0x36090)
- CredDeleteA (Ordinal: 1151, Address: 0x360b0)
- CredDeleteW (Ordinal: 1152, Address: 0x360d0)
- CredEncryptAndMarshalBinaryBlob (Ordinal: 1153, Address: 0x360f0)
- CredEnumerateA (Ordinal: 1154, Address: 0x36110)
- CredEnumerateW (Ordinal: 1155, Address: 0x20cb0)
- CredFindBestCredentialA (Ordinal: 1156, Address: 0x36130)
- CredFindBestCredentialW (Ordinal: 1157, Address: 0x36150)
- CredFree (Ordinal: 1158, Address: 0x36170)
- CredGetSessionTypes (Ordinal: 1159, Address: 0x36180)
- CredGetTargetInfoA (Ordinal: 1160, Address: 0x361a0)
- CredGetTargetInfoW (Ordinal: 1161, Address: 0x361c0)
- CredIsMarshaledCredentialA (Ordinal: 1162, Address: 0x38370)
- CredIsMarshaledCredentialW (Ordinal: 1163, Address: 0x361e0)
- CredIsProtectedA (Ordinal: 1164, Address: 0x36200)
- CredIsProtectedW (Ordinal: 1165, Address: 0x36220)
- CredMarshalCredentialA (Ordinal: 1166, Address: 0x36240)
- CredMarshalCredentialW (Ordinal: 1167, Address: 0x36260)
- CredProfileLoaded (Ordinal: 1168, Address: 0x362a0)
- CredProfileLoadedEx (Ordinal: 1169, Address: 0x36280)
- CredProfileUnloaded (Ordinal: 1170, Address: 0x362b0)
- CredProtectA (Ordinal: 1171, Address: 0x362c0)
- CredProtectW (Ordinal: 1172, Address: 0x362e0)
- CredReadA (Ordinal: 1173, Address: 0x36300)
- CredReadByTokenHandle (Ordinal: 1174, Address: 0x36320)
- CredReadDomainCredentialsA (Ordinal: 1175, Address: 0x36340)
- CredReadDomainCredentialsW (Ordinal: 1176, Address: 0x36360)
- CredReadW (Ordinal: 1177, Address: 0x36380)
- CredRenameA (Ordinal: 1178, Address: 0x383b0)
- CredRenameW (Ordinal: 1179, Address: 0x383b0)
- CredRestoreCredentials (Ordinal: 1180, Address: 0x363a0)
- CredUnmarshalCredentialA (Ordinal: 1181, Address: 0x363c0)
- CredUnmarshalCredentialW (Ordinal: 1182, Address: 0x363e0)
- CredUnprotectA (Ordinal: 1183, Address: 0x36400)
- CredUnprotectW (Ordinal: 1184, Address: 0x36420)
- CredWriteA (Ordinal: 1185, Address: 0x36440)
- CredWriteDomainCredentialsA (Ordinal: 1186, Address: 0x36460)
- CredWriteDomainCredentialsW (Ordinal: 1187, Address: 0x36480)
- CredWriteW (Ordinal: 1188, Address: 0x364a0)
- CredpConvertCredential (Ordinal: 1189, Address: 0x364c0)
- CredpConvertOneCredentialSize (Ordinal: 1190, Address: 0x364e0)
- CredpConvertTargetInfo (Ordinal: 1191, Address: 0x36500)
- CredpDecodeCredential (Ordinal: 1192, Address: 0x36520)
- CredpEncodeCredential (Ordinal: 1193, Address: 0x36540)
- CredpEncodeSecret (Ordinal: 1194, Address: 0x36560)
- CryptAcquireContextA (Ordinal: 1195, Address: 0x20160)
- CryptAcquireContextW (Ordinal: 1196, Address: 0x1f990)
- CryptContextAddRef (Ordinal: 1197, Address: 0x36580)
- CryptCreateHash (Ordinal: 1198, Address: 0x1f540)
- CryptDecrypt (Ordinal: 1199, Address: 0x24bb0)
- CryptDeriveKey (Ordinal: 1200, Address: 0x365a0)
- CryptDestroyHash (Ordinal: 1201, Address: 0x1f970)
- CryptDestroyKey (Ordinal: 1202, Address: 0x1f9d0)
- CryptDuplicateHash (Ordinal: 1203, Address: 0x365c0)
- CryptDuplicateKey (Ordinal: 1204, Address: 0x365e0)
- CryptEncrypt (Ordinal: 1205, Address: 0x36600)
- CryptEnumProviderTypesA (Ordinal: 1206, Address: 0x36620)
- CryptEnumProviderTypesW (Ordinal: 1207, Address: 0x36640)
- CryptEnumProvidersA (Ordinal: 1208, Address: 0x36660)
- CryptEnumProvidersW (Ordinal: 1209, Address: 0x36680)
- CryptExportKey (Ordinal: 1210, Address: 0x1f640)
- CryptGenKey (Ordinal: 1211, Address: 0x24c10)
- CryptGenRandom (Ordinal: 1212, Address: 0x20920)
- CryptGetDefaultProviderA (Ordinal: 1213, Address: 0x366a0)
- CryptGetDefaultProviderW (Ordinal: 1214, Address: 0x207a0)
- CryptGetHashParam (Ordinal: 1215, Address: 0x1f2a0)
- CryptGetKeyParam (Ordinal: 1216, Address: 0x366c0)
- CryptGetProvParam (Ordinal: 1217, Address: 0x366e0)
- CryptGetUserKey (Ordinal: 1218, Address: 0x36700)
- CryptHashData (Ordinal: 1219, Address: 0x1f660)
- CryptHashSessionKey (Ordinal: 1220, Address: 0x36720)
- CryptImportKey (Ordinal: 1221, Address: 0x1f620)
- CryptReleaseContext (Ordinal: 1222, Address: 0x1faf0)
- CryptSetHashParam (Ordinal: 1223, Address: 0x1fb30)
- CryptSetKeyParam (Ordinal: 1224, Address: 0x36740)
- CryptSetProvParam (Ordinal: 1225, Address: 0x36760)
- CryptSetProviderA (Ordinal: 1226, Address: 0x36780)
- CryptSetProviderExA (Ordinal: 1227, Address: 0x367a0)
- CryptSetProviderExW (Ordinal: 1228, Address: 0x367c0)
- CryptSetProviderW (Ordinal: 1229, Address: 0x367e0)
- CryptSignHashA (Ordinal: 1230, Address: 0x36800)
- CryptSignHashW (Ordinal: 1231, Address: 0x36820)
- CryptVerifySignatureA (Ordinal: 1232, Address: 0x36840)
- CryptVerifySignatureW (Ordinal: 1233, Address: 0x1f9b0)
- CveEventWrite (Ordinal: 1234, Address: 0x676ca)
- DecryptFileA (Ordinal: 1235, Address: 0x35170)
- DecryptFileW (Ordinal: 1236, Address: 0x35210)
- DeleteAce (Ordinal: 1237, Address: 0x20350)
- DeleteService (Ordinal: 1238, Address: 0x36860)
- DeregisterEventSource (Ordinal: 1239, Address: 0x21250)
- DestroyPrivateObjectSecurity (Ordinal: 1240, Address: 0x23ae0)
- DuplicateEncryptionInfoFile (Ordinal: 1241, Address: 0x35270)
- DuplicateToken (Ordinal: 1242, Address: 0x1f5e0)
- DuplicateTokenEx (Ordinal: 1243, Address: 0x20760)
- ElfBackupEventLogFileA (Ordinal: 1244, Address: 0x51880)
- ElfBackupEventLogFileW (Ordinal: 1245, Address: 0x51930)
- ElfChangeNotify (Ordinal: 1246, Address: 0x519e0)
- ElfClearEventLogFileA (Ordinal: 1247, Address: 0x51aa0)
- ElfClearEventLogFileW (Ordinal: 1248, Address: 0x51b40)
- ElfCloseEventLog (Ordinal: 1249, Address: 0x242c0)
- ElfDeregisterEventSource (Ordinal: 1250, Address: 0x21280)
- ElfFlushEventLog (Ordinal: 1251, Address: 0x51be0)
- ElfNumberOfRecords (Ordinal: 1252, Address: 0x51bf0)
- ElfOldestRecord (Ordinal: 1253, Address: 0x51ca0)
- ElfOpenBackupEventLogA (Ordinal: 1254, Address: 0x51d50)
- ElfOpenBackupEventLogW (Ordinal: 1255, Address: 0x51e60)
- ElfOpenEventLogA (Ordinal: 1256, Address: 0x51f70)
- ElfOpenEventLogW (Ordinal: 1257, Address: 0x24330)
- ElfReadEventLogA (Ordinal: 1258, Address: 0x52100)
- ElfReadEventLogW (Ordinal: 1259, Address: 0x52210)
- ElfRegisterEventSourceA (Ordinal: 1260, Address: 0x23570)
- ElfRegisterEventSourceW (Ordinal: 1261, Address: 0x20fc0)
- ElfReportEventA (Ordinal: 1262, Address: 0x52460)
- ElfReportEventAndSourceW (Ordinal: 1263, Address: 0x52660)
- ElfReportEventW (Ordinal: 1264, Address: 0x214b0)
- EnableTrace (Ordinal: 1265, Address: 0x249e0)
- EnableTraceEx2 (Ordinal: 1266, Address: 0x23920)
- EnableTraceEx (Ordinal: 1267, Address: 0x24a10)
- EncryptFileA (Ordinal: 1268, Address: 0x352e0)
- EncryptFileW (Ordinal: 1269, Address: 0x35380)
- EncryptedFileKeyInfo (Ordinal: 1270, Address: 0x353e0)
- EncryptionDisable (Ordinal: 1271, Address: 0x35440)
- EnumDependentServicesA (Ordinal: 1272, Address: 0x474e0)
- EnumDependentServicesW (Ordinal: 1273, Address: 0x36880)
- EnumDynamicTimeZoneInformation (Ordinal: 1274, Address: 0x368a0)
- EnumServiceGroupW (Ordinal: 1275, Address: 0x475c0)
- EnumServicesStatusA (Ordinal: 1276, Address: 0x476d0)
- EnumServicesStatusExA (Ordinal: 1277, Address: 0x21730)
- EnumServicesStatusExW (Ordinal: 1278, Address: 0x23ee0)
- EnumServicesStatusW (Ordinal: 1279, Address: 0x477b0)
- EnumerateTraceGuids (Ordinal: 1280, Address: 0x228c0)
- EnumerateTraceGuidsEx (Ordinal: 1281, Address: 0x20bf0)
- EqualDomainSid (Ordinal: 1282, Address: 0x368c0)
- EqualPrefixSid (Ordinal: 1283, Address: 0x368e0)
- EqualSid (Ordinal: 1284, Address: 0x20900)
- EventAccessControl (Ordinal: 1285, Address: 0x36900)
- EventAccessQuery (Ordinal: 1286, Address: 0x36920)
- EventAccessRemove (Ordinal: 1287, Address: 0x36940)
- EventActivityIdControl (Ordinal: 1288, Address: 0x67ae2)
- EventEnabled (Ordinal: 1289, Address: 0x67b0f)
- EventProviderEnabled (Ordinal: 1290, Address: 0x67b3a)
- EventRegister (Ordinal: 1291, Address: 0x67b66)
- EventSetInformation (Ordinal: 1292, Address: 0x67b91)
- EventUnregister (Ordinal: 1293, Address: 0x67bbe)
- EventWrite (Ordinal: 1294, Address: 0x67be2)
- EventWriteEndScenario (Ordinal: 1295, Address: 0x67c0c)
- EventWriteEx (Ordinal: 1296, Address: 0x67c38)
- EventWriteStartScenario (Ordinal: 1297, Address: 0x67c66)
- EventWriteString (Ordinal: 1298, Address: 0x67c98)
- EventWriteTransfer (Ordinal: 1299, Address: 0x67cc5)
- FileEncryptionStatusA (Ordinal: 1300, Address: 0x35480)
- FileEncryptionStatusW (Ordinal: 1301, Address: 0x35520)
- FindFirstFreeAce (Ordinal: 1302, Address: 0x36960)
- FlushEfsCache (Ordinal: 1303, Address: 0x35560)
- FlushTraceA (Ordinal: 1304, Address: 0x45410)
- FlushTraceW (Ordinal: 1305, Address: 0x45440)
- FreeEncryptedFileKeyInfo (Ordinal: 1306, Address: 0x355e0)
- FreeEncryptedFileMetadata (Ordinal: 1307, Address: 0x21910)
- FreeEncryptionCertificateHashList (Ordinal: 1308, Address: 0x35610)
- FreeInheritedFromArray (Ordinal: 1309, Address: 0x41bb0)
- FreeSid (Ordinal: 1310, Address: 0x201a0)
- GetAccessPermissionsForObjectA (Ordinal: 1311, Address: 0x42af0)
- GetAccessPermissionsForObjectW (Ordinal: 1312, Address: 0x42d70)
- GetAce (Ordinal: 1313, Address: 0x36980)
- GetAclInformation (Ordinal: 1314, Address: 0x369a0)
- GetAuditedPermissionsFromAclA (Ordinal: 1315, Address: 0x41bf0)
- GetAuditedPermissionsFromAclW (Ordinal: 1316, Address: 0x41c40)
- GetCurrentHwProfileA (Ordinal: 1317, Address: 0x34eb0)
- GetCurrentHwProfileW (Ordinal: 1318, Address: 0x1fe20)
- GetDynamicTimeZoneInformationEffectiveYears (Ordinal: 1319, Address: 0x369c0)
- GetEffectiveRightsFromAclA (Ordinal: 1320, Address: 0x41ca0)
- GetEffectiveRightsFromAclW (Ordinal: 1321, Address: 0x41cf0)
- GetEncryptedFileMetadata (Ordinal: 1322, Address: 0x35640)
- GetEventLogInformation (Ordinal: 1323, Address: 0x241c0)
- GetExplicitEntriesFromAclA (Ordinal: 1324, Address: 0x369e0)
- GetExplicitEntriesFromAclW (Ordinal: 1325, Address: 0x369e0)
- GetFileSecurityA (Ordinal: 1326, Address: 0x48030)
- GetFileSecurityW (Ordinal: 1327, Address: 0x12840)
- GetInformationCodeAuthzLevelW (Ordinal: 1328, Address: 0x3cdd0)
- GetInformationCodeAuthzPolicyW (Ordinal: 1329, Address: 0x1c220)
- GetInheritanceSourceA (Ordinal: 1330, Address: 0x41d60)
- GetInheritanceSourceW (Ordinal: 1331, Address: 0x41d70)
- GetKernelObjectSecurity (Ordinal: 1332, Address: 0x25430)
- GetLengthSid (Ordinal: 1333, Address: 0x1f170)
- GetLocalManagedApplicationData (Ordinal: 1334, Address: 0x3b450)
- GetLocalManagedApplications (Ordinal: 1335, Address: 0x3b670)
- GetManagedApplicationCategories (Ordinal: 1336, Address: 0x3b8b0)
- GetManagedApplications (Ordinal: 1337, Address: 0x3b910)
- GetMultipleTrusteeA (Ordinal: 1338, Address: 0x42400)
- GetMultipleTrusteeOperationA (Ordinal: 1339, Address: 0x42420)
- GetMultipleTrusteeOperationW (Ordinal: 1340, Address: 0x42420)
- GetMultipleTrusteeW (Ordinal: 1341, Address: 0x42400)
- GetNamedSecurityInfoA (Ordinal: 1342, Address: 0x41dd0)
- GetNamedSecurityInfoExA (Ordinal: 1343, Address: 0x42e50)
- GetNamedSecurityInfoExW (Ordinal: 1344, Address: 0x43020)
- GetNamedSecurityInfoW (Ordinal: 1345, Address: 0x23a80)
- GetNumberOfEventLogRecords (Ordinal: 1346, Address: 0x512a0)
- GetOldestEventLogRecord (Ordinal: 1347, Address: 0x512e0)
- GetOverlappedAccessResults (Ordinal: 1348, Address: 0x432e0)
- GetPrivateObjectSecurity (Ordinal: 1349, Address: 0x36a00)
- GetSecurityDescriptorControl (Ordinal: 1350, Address: 0x36a20)
- GetSecurityDescriptorDacl (Ordinal: 1351, Address: 0x1f7e0)
- GetSecurityDescriptorGroup (Ordinal: 1352, Address: 0x36a40)
- GetSecurityDescriptorLength (Ordinal: 1353, Address: 0x23ac0)
- GetSecurityDescriptorOwner (Ordinal: 1354, Address: 0x25470)
- GetSecurityDescriptorRMControl (Ordinal: 1355, Address: 0x36a60)
- GetSecurityDescriptorSacl (Ordinal: 1356, Address: 0x24b50)
- GetSecurityInfo (Ordinal: 1357, Address: 0x1f600)
- GetSecurityInfoExA (Ordinal: 1358, Address: 0x43400)
- GetSecurityInfoExW (Ordinal: 1359, Address: 0x435b0)
- GetServiceDisplayNameA (Ordinal: 1360, Address: 0x477e0)
- GetServiceDisplayNameW (Ordinal: 1361, Address: 0x36a80)
- GetServiceKeyNameA (Ordinal: 1362, Address: 0x47880)
- GetServiceKeyNameW (Ordinal: 1363, Address: 0x36aa0)
- GetSidIdentifierAuthority (Ordinal: 1364, Address: 0x36ac0)
- GetSidLengthRequired (Ordinal: 1365, Address: 0x36ae0)
- GetSidSubAuthority (Ordinal: 1366, Address: 0x1f560)
- GetSidSubAuthorityCount (Ordinal: 1367, Address: 0x1f6c0)
- GetStringConditionFromBinary (Ordinal: 1368, Address: 0x4ab40)
- GetThreadWaitChain (Ordinal: 1369, Address: 0x5d4b0)
- GetTokenInformation (Ordinal: 1370, Address: 0x1ecc0)
- GetTraceEnableFlags (Ordinal: 1371, Address: 0x68382)
- GetTraceEnableLevel (Ordinal: 1372, Address: 0x683b3)
- GetTraceLoggerHandle (Ordinal: 1373, Address: 0x683e5)
- GetTrusteeFormA (Ordinal: 1374, Address: 0x42440)
- GetTrusteeFormW (Ordinal: 1375, Address: 0x42440)
- GetTrusteeNameA (Ordinal: 1376, Address: 0x42460)
- GetTrusteeNameW (Ordinal: 1377, Address: 0x42460)
- GetTrusteeTypeA (Ordinal: 1378, Address: 0x42480)
- GetTrusteeTypeW (Ordinal: 1379, Address: 0x42480)
- GetUserNameA (Ordinal: 1380, Address: 0x239f0)
- GetUserNameW (Ordinal: 1381, Address: 0x1f940)
- GetWindowsAccountDomainSid (Ordinal: 1382, Address: 0x36b00)
- I_QueryTagInformation (Ordinal: 1383, Address: 0x684ae)
- I_ScIsSecurityProcess (Ordinal: 1384, Address: 0x684fc)
- I_ScPnPGetServiceName (Ordinal: 1385, Address: 0x6854a)
- I_ScQueryServiceConfig (Ordinal: 1386, Address: 0x68599)
- I_ScRegisterPreshutdownRestart (Ordinal: 1387, Address: 0x685f1)
- I_ScReparseServiceDatabase (Ordinal: 1388, Address: 0x25b10)
- I_ScSendPnPMessage (Ordinal: 1389, Address: 0x68660)
- I_ScSendTSMessage (Ordinal: 1390, Address: 0x686a7)
- I_ScSetServiceBitsA (Ordinal: 1391, Address: 0x36b20)
- I_ScSetServiceBitsW (Ordinal: 1392, Address: 0x36b40)
- I_ScValidatePnPService (Ordinal: 1393, Address: 0x6871a)
- IdentifyCodeAuthzLevelW (Ordinal: 1394, Address: 0x1c390)
- ImpersonateAnonymousToken (Ordinal: 1395, Address: 0x36b60)
- ImpersonateLoggedOnUser (Ordinal: 1396, Address: 0x20b20)
- ImpersonateNamedPipeClient (Ordinal: 1397, Address: 0x36b80)
- ImpersonateSelf (Ordinal: 1398, Address: 0x20cf0)
- InitializeAcl (Ordinal: 1399, Address: 0x1f800)
- InitializeSecurityDescriptor (Ordinal: 1400, Address: 0x1f920)
- InitializeSid (Ordinal: 1401, Address: 0x36ba0)
- InitiateShutdownA (Ordinal: 1402, Address: 0x45730)
- InitiateShutdownW (Ordinal: 1403, Address: 0x23fa0)
- InitiateSystemShutdownA (Ordinal: 1404, Address: 0x45800)
- InitiateSystemShutdownExA (Ordinal: 1405, Address: 0x458e0)
- InitiateSystemShutdownExW (Ordinal: 1406, Address: 0x47160)
- InitiateSystemShutdownW (Ordinal: 1407, Address: 0x459c0)
- InstallApplication (Ordinal: 1408, Address: 0x3b940)
- IsTextUnicode (Ordinal: 1409, Address: 0x1f030)
- IsTokenRestricted (Ordinal: 1410, Address: 0x36bc0)
- IsTokenUntrusted (Ordinal: 1411, Address: 0x3cc10)
- IsValidAcl (Ordinal: 1412, Address: 0x36be0)
- IsValidRelativeSecurityDescriptor (Ordinal: 1413, Address: 0x688fa)
- IsValidSecurityDescriptor (Ordinal: 1414, Address: 0x36c00)
- IsValidSid (Ordinal: 1415, Address: 0x1f5a0)
- IsWellKnownSid (Ordinal: 1416, Address: 0x36c20)
- LockServiceDatabase (Ordinal: 1417, Address: 0x47920)
- LogonUserA (Ordinal: 1418, Address: 0x4a650)
- LogonUserExA (Ordinal: 1419, Address: 0x4a790)
- LogonUserExExW (Ordinal: 1420, Address: 0x36c40)
- LogonUserExW (Ordinal: 1421, Address: 0x4a7d0)
- LogonUserW (Ordinal: 1422, Address: 0x245b0)
- LookupAccountNameA (Ordinal: 1423, Address: 0x480b0)
- LookupAccountNameW (Ordinal: 1424, Address: 0x1f9f0)
- LookupAccountSidA (Ordinal: 1425, Address: 0x484b0)
- LookupAccountSidW (Ordinal: 1426, Address: 0x1f2c0)
- LookupPrivilegeDisplayNameA (Ordinal: 1427, Address: 0x48a30)
- LookupPrivilegeDisplayNameW (Ordinal: 1428, Address: 0x48bb0)
- LookupPrivilegeNameA (Ordinal: 1429, Address: 0x48d10)
- LookupPrivilegeNameW (Ordinal: 1430, Address: 0x48e40)
- LookupPrivilegeValueA (Ordinal: 1431, Address: 0x24aa0)
- LookupPrivilegeValueW (Ordinal: 1432, Address: 0x1a6e0)
- LookupSecurityDescriptorPartsA (Ordinal: 1433, Address: 0x41e20)
- LookupSecurityDescriptorPartsW (Ordinal: 1434, Address: 0x42040)
- LsaAddAccountRights (Ordinal: 1435, Address: 0x36c60)
- LsaAddPrivilegesToAccount (Ordinal: 1436, Address: 0x383d0)
- LsaClearAuditLog (Ordinal: 1437, Address: 0x38460)
- LsaClose (Ordinal: 1438, Address: 0x36c80)
- LsaCreateAccount (Ordinal: 1439, Address: 0x384e0)
- LsaCreateSecret (Ordinal: 1440, Address: 0x36ca0)
- LsaCreateTrustedDomain (Ordinal: 1441, Address: 0x385a0)
- LsaCreateTrustedDomainEx (Ordinal: 1442, Address: 0x39d40)
- LsaDelete (Ordinal: 1443, Address: 0x36cc0)
- LsaDeleteTrustedDomain (Ordinal: 1444, Address: 0x39e90)
- LsaEnumerateAccountRights (Ordinal: 1445, Address: 0x36ce0)
- LsaEnumerateAccounts (Ordinal: 1446, Address: 0x38660)
- LsaEnumerateAccountsWithUserRight (Ordinal: 1447, Address: 0x36d00)
- LsaEnumeratePrivileges (Ordinal: 1448, Address: 0x38720)
- LsaEnumeratePrivilegesOfAccount (Ordinal: 1449, Address: 0x387e0)
- LsaEnumerateTrustedDomains (Ordinal: 1450, Address: 0x38870)
- LsaEnumerateTrustedDomainsEx (Ordinal: 1451, Address: 0x39f20)
- LsaFreeMemory (Ordinal: 1452, Address: 0x36d20)
- LsaGetAppliedCAPIDs (Ordinal: 1453, Address: 0x38940)
- LsaGetQuotasForAccount (Ordinal: 1454, Address: 0x38a60)
- LsaGetRemoteUserName (Ordinal: 1455, Address: 0x38af0)
- LsaGetSystemAccessAccount (Ordinal: 1456, Address: 0x38c20)
- LsaGetUserName (Ordinal: 1457, Address: 0x1a630)
- LsaICLookupNames (Ordinal: 1458, Address: 0x36d40)
- LsaICLookupNamesWithCreds (Ordinal: 1459, Address: 0x36d80)
- LsaICLookupSids (Ordinal: 1460, Address: 0x36dc0)
- LsaICLookupSidsWithCreds (Ordinal: 1461, Address: 0x36df0)
- LsaInvokeTrustScanner (Ordinal: 1462, Address: 0x26050)
- LsaLookupNames2 (Ordinal: 1463, Address: 0x36e30)
- LsaLookupNames (Ordinal: 1464, Address: 0x38cb0)
- LsaLookupPrivilegeDisplayName (Ordinal: 1465, Address: 0x38dd0)
- LsaLookupPrivilegeName (Ordinal: 1466, Address: 0x39090)
- LsaLookupPrivilegeValue (Ordinal: 1467, Address: 0x1a900)
- LsaLookupSids2 (Ordinal: 1468, Address: 0x36e60)
- LsaLookupSids (Ordinal: 1469, Address: 0x36e90)
- LsaManageSidNameMapping (Ordinal: 1470, Address: 0x39ff0)
- LsaNtStatusToWinError (Ordinal: 1471, Address: 0x1eed0)
- LsaOpenAccount (Ordinal: 1472, Address: 0x39140)
- LsaOpenPolicy (Ordinal: 1473, Address: 0x36ec0)
- LsaOpenPolicySce (Ordinal: 1474, Address: 0x39200)
- LsaOpenSecret (Ordinal: 1475, Address: 0x36ee0)
- LsaOpenTrustedDomain (Ordinal: 1476, Address: 0x392d0)
- LsaOpenTrustedDomainByName (Ordinal: 1477, Address: 0x3a0c0)
- LsaPurgeLocalSystemAccessTable (Ordinal: 1478, Address: 0x260d0)
- LsaQueryCAPs (Ordinal: 1479, Address: 0x39390)
- LsaQueryDomainInformationPolicy (Ordinal: 1480, Address: 0x3a180)
- LsaQueryForestTrustInformation2 (Ordinal: 1481, Address: 0x26360)
- LsaQueryForestTrustInformation (Ordinal: 1482, Address: 0x3a220)
- LsaQueryInfoTrustedDomain (Ordinal: 1483, Address: 0x394a0)
- LsaQueryInformationPolicy (Ordinal: 1484, Address: 0x36f00)
- LsaQueryLocalSystemAccess (Ordinal: 1485, Address: 0x26170)
- LsaQueryLocalSystemAccessAll (Ordinal: 1486, Address: 0x26220)
- LsaQuerySecret (Ordinal: 1487, Address: 0x36f20)
- LsaQuerySecurityObject (Ordinal: 1488, Address: 0x39570)
- LsaQueryTrustedDomainInfo (Ordinal: 1489, Address: 0x3a2c0)
- LsaQueryTrustedDomainInfoByName (Ordinal: 1490, Address: 0x3a390)
- LsaRemoveAccountRights (Ordinal: 1491, Address: 0x36f50)
- LsaRemovePrivilegesFromAccount (Ordinal: 1492, Address: 0x39620)
- LsaRetrievePrivateData (Ordinal: 1493, Address: 0x36f80)
- LsaSetCAPs (Ordinal: 1494, Address: 0x396b0)
- LsaSetDomainInformationPolicy (Ordinal: 1495, Address: 0x3a440)
- LsaSetForestTrustInformation2 (Ordinal: 1496, Address: 0x26400)
- LsaSetForestTrustInformation (Ordinal: 1497, Address: 0x3a4e0)
- LsaSetInformationPolicy (Ordinal: 1498, Address: 0x36fa0)
- LsaSetInformationTrustedDomain (Ordinal: 1499, Address: 0x397a0)
- LsaSetLocalSystemAccess (Ordinal: 1500, Address: 0x262c0)
- LsaSetQuotasForAccount (Ordinal: 1501, Address: 0x39a80)
- LsaSetSecret (Ordinal: 1502, Address: 0x36fc0)
- LsaSetSecurityObject (Ordinal: 1503, Address: 0x39b10)
- LsaSetSystemAccessAccount (Ordinal: 1504, Address: 0x39c10)
- LsaSetTrustedDomainInfoByName (Ordinal: 1505, Address: 0x3a580)
- LsaSetTrustedDomainInformation (Ordinal: 1506, Address: 0x3a870)
- LsaStorePrivateData (Ordinal: 1507, Address: 0x36fe0)
- MD4Final (Ordinal: 1508, Address: 0x69145)
- MD4Init (Ordinal: 1509, Address: 0x6915c)
- MD4Update (Ordinal: 1510, Address: 0x69174)
- MD5Final (Ordinal: 1511, Address: 0x6918d)
- MD5Init (Ordinal: 1512, Address: 0x691a4)
- MD5Update (Ordinal: 1513, Address: 0x691bc)
- MIDL_user_free_Ext (Ordinal: 1514, Address: 0x37d30)
- MSChapSrvChangePassword2 (Ordinal: 1515, Address: 0x37700)
- MSChapSrvChangePassword (Ordinal: 1516, Address: 0x37790)
- MakeAbsoluteSD2 (Ordinal: 1517, Address: 0x37000)
- MakeAbsoluteSD (Ordinal: 1518, Address: 0x25410)
- MakeSelfRelativeSD (Ordinal: 1519, Address: 0x37020)
- MapGenericMask (Ordinal: 1520, Address: 0x37040)
- NotifyBootConfigStatus (Ordinal: 1521, Address: 0x24550)
- NotifyChangeEventLog (Ordinal: 1522, Address: 0x51360)
- NotifyServiceStatusChange (Ordinal: 1523, Address: 0x25af0)
- NotifyServiceStatusChangeA (Ordinal: 1524, Address: 0x37050)
- NotifyServiceStatusChangeW (Ordinal: 1525, Address: 0x25510)
- NpGetUserName (Ordinal: 1526, Address: 0x4a810)
- ObjectCloseAuditAlarmA (Ordinal: 1527, Address: 0x48f90)
- ObjectCloseAuditAlarmW (Ordinal: 1528, Address: 0x37070)
- ObjectDeleteAuditAlarmA (Ordinal: 1529, Address: 0x48ff0)
- ObjectDeleteAuditAlarmW (Ordinal: 1530, Address: 0x37090)
- ObjectOpenAuditAlarmA (Ordinal: 1531, Address: 0x49050)
- ObjectOpenAuditAlarmW (Ordinal: 1532, Address: 0x370b0)
- ObjectPrivilegeAuditAlarmA (Ordinal: 1533, Address: 0x49160)
- ObjectPrivilegeAuditAlarmW (Ordinal: 1534, Address: 0x370d0)
- OpenBackupEventLogA (Ordinal: 1535, Address: 0x513a0)
- OpenBackupEventLogW (Ordinal: 1536, Address: 0x51470)
- OpenEncryptedFileRawA (Ordinal: 1537, Address: 0x35710)
- OpenEncryptedFileRawW (Ordinal: 1538, Address: 0x357b0)
- OpenEventLogA (Ordinal: 1539, Address: 0x51520)
- OpenEventLogW (Ordinal: 1540, Address: 0x24160)
- OpenProcessToken (Ordinal: 1541, Address: 0x1f060)
- OpenSCManagerA (Ordinal: 1542, Address: 0x20bd0)
- OpenSCManagerW (Ordinal: 1543, Address: 0x20a30)
- OpenServiceA (Ordinal: 1544, Address: 0x370f0)
- OpenServiceW (Ordinal: 1545, Address: 0x20a50)
- OpenThreadToken (Ordinal: 1546, Address: 0x1eef0)
- OpenThreadWaitChainSession (Ordinal: 1547, Address: 0x5d610)
- OpenTraceA (Ordinal: 1548, Address: 0x455b0)
- OpenTraceW (Ordinal: 1549, Address: 0x20ac0)
- OperationEnd (Ordinal: 1550, Address: 0x37bd0)
- OperationStart (Ordinal: 1551, Address: 0x37c80)
- PerfAddCounters (Ordinal: 1552, Address: 0x10810)
- PerfCloseQueryHandle (Ordinal: 1553, Address: 0x10a30)
- PerfCreateInstance (Ordinal: 1554, Address: 0x694e9)
- PerfDecrementULongCounterValue (Ordinal: 1555, Address: 0x6953f)
- PerfDecrementULongLongCounterValue (Ordinal: 1556, Address: 0x695a5)
- PerfDeleteCounters (Ordinal: 1557, Address: 0x45d30)
- PerfDeleteInstance (Ordinal: 1558, Address: 0x69612)
- PerfEnumerateCounterSet (Ordinal: 1559, Address: 0x18880)
- PerfEnumerateCounterSetInstances (Ordinal: 1560, Address: 0x12120)
- PerfIncrementULongCounterValue (Ordinal: 1561, Address: 0x696a1)
- PerfIncrementULongLongCounterValue (Ordinal: 1562, Address: 0x69707)
- PerfOpenQueryHandle (Ordinal: 1563, Address: 0x123d0)
- PerfQueryCounterData (Ordinal: 1564, Address: 0x111b0)
- PerfQueryCounterInfo (Ordinal: 1565, Address: 0x108b0)
- PerfQueryCounterSetRegistrationInfo (Ordinal: 1566, Address: 0x18930)
- PerfQueryInstance (Ordinal: 1567, Address: 0x697c2)
- PerfRegCloseKey (Ordinal: 1568, Address: 0x23a20)
- PerfRegEnumKey (Ordinal: 1569, Address: 0x52840)
- PerfRegEnumValue (Ordinal: 1570, Address: 0x52890)
- PerfRegQueryInfoKey (Ordinal: 1571, Address: 0x21960)
- PerfRegQueryValue (Ordinal: 1572, Address: 0x13380)
- PerfRegSetValue (Ordinal: 1573, Address: 0x52980)
- PerfSetCounterRefValue (Ordinal: 1574, Address: 0x69875)
- PerfSetCounterSetInfo (Ordinal: 1575, Address: 0x698c6)
- PerfSetULongCounterValue (Ordinal: 1576, Address: 0x69919)
- PerfSetULongLongCounterValue (Ordinal: 1577, Address: 0x69973)
- PerfStartProvider (Ordinal: 1578, Address: 0x699c6)
- PerfStartProviderEx (Ordinal: 1579, Address: 0x69a10)
- PerfStopProvider (Ordinal: 1580, Address: 0x69a59)
- PrivilegeCheck (Ordinal: 1581, Address: 0x37110)
- PrivilegedServiceAuditAlarmA (Ordinal: 1582, Address: 0x491d0)
- PrivilegedServiceAuditAlarmW (Ordinal: 1583, Address: 0x37130)
- ProcessIdleTasks (Ordinal: 1584, Address: 0x37d40)
- ProcessIdleTasksW (Ordinal: 1585, Address: 0x37dd0)
- ProcessTrace (Ordinal: 1586, Address: 0x20950)
- QueryAllTracesA (Ordinal: 1587, Address: 0x25a70)
- QueryAllTracesW (Ordinal: 1588, Address: 0x37150)
- QueryLocalUserServiceName (Ordinal: 1589, Address: 0x25b20)
- QueryRecoveryAgentsOnEncryptedFile (Ordinal: 1590, Address: 0x35800)
- QuerySecurityAccessMask (Ordinal: 1591, Address: 0x37170)
- QueryServiceConfig2A (Ordinal: 1592, Address: 0x37180)
- QueryServiceConfig2W (Ordinal: 1593, Address: 0x254b0)
- QueryServiceConfigA (Ordinal: 1594, Address: 0x371a0)
- QueryServiceConfigW (Ordinal: 1595, Address: 0x23f00)
- QueryServiceDynamicInformation (Ordinal: 1596, Address: 0x371c0)
- QueryServiceLockStatusA (Ordinal: 1597, Address: 0x479b0)
- QueryServiceLockStatusW (Ordinal: 1598, Address: 0x47a50)
- QueryServiceObjectSecurity (Ordinal: 1599, Address: 0x371e0)
- QueryServiceStatus (Ordinal: 1600, Address: 0x23f80)
- QueryServiceStatusEx (Ordinal: 1601, Address: 0x20bb0)
- QueryTraceA (Ordinal: 1602, Address: 0x45470)
- QueryTraceProcessingHandle (Ordinal: 1603, Address: 0x37200)
- QueryTraceW (Ordinal: 1604, Address: 0x12800)
- QueryUserServiceName (Ordinal: 1605, Address: 0x25b30)
- QueryUserServiceNameForContext (Ordinal: 1606, Address: 0x25b40)
- QueryUsersOnEncryptedFile (Ordinal: 1607, Address: 0x35860)
- ReadEncryptedFileRaw (Ordinal: 1608, Address: 0x358c0)
- ReadEventLogA (Ordinal: 1609, Address: 0x51590)
- ReadEventLogW (Ordinal: 1610, Address: 0x515f0)
- RegCloseKey (Ordinal: 1611, Address: 0x1f150)
- RegConnectRegistryA (Ordinal: 1612, Address: 0x460a0)
- RegConnectRegistryExA (Ordinal: 1613, Address: 0x460c0)
- RegConnectRegistryExW (Ordinal: 1614, Address: 0x25250)
- RegConnectRegistryW (Ordinal: 1615, Address: 0x25230)
- RegCopyTreeA (Ordinal: 1616, Address: 0x46350)
- RegCopyTreeW (Ordinal: 1617, Address: 0x37230)
- RegCreateKeyA (Ordinal: 1618, Address: 0x23480)
- RegCreateKeyExA (Ordinal: 1619, Address: 0x1f580)
- RegCreateKeyExW (Ordinal: 1620, Address: 0x1f260)
- RegCreateKeyTransactedA (Ordinal: 1621, Address: 0x463b0)
- RegCreateKeyTransactedW (Ordinal: 1622, Address: 0x23e30)
- RegCreateKeyW (Ordinal: 1623, Address: 0x1fa90)
- RegDeleteKeyA (Ordinal: 1624, Address: 0x1f6e0)
- RegDeleteKeyExA (Ordinal: 1625, Address: 0x37250)
- RegDeleteKeyExW (Ordinal: 1626, Address: 0x22a50)
- RegDeleteKeyTransactedA (Ordinal: 1627, Address: 0x46590)
- RegDeleteKeyTransactedW (Ordinal: 1628, Address: 0x231b0)
- RegDeleteKeyValueA (Ordinal: 1629, Address: 0x37270)
- RegDeleteKeyValueW (Ordinal: 1630, Address: 0x37290)
- RegDeleteKeyW (Ordinal: 1631, Address: 0x1f730)
- RegDeleteTreeA (Ordinal: 1632, Address: 0x372b0)
- RegDeleteTreeW (Ordinal: 1633, Address: 0x24bf0)
- RegDeleteValueA (Ordinal: 1634, Address: 0x20b00)
- RegDeleteValueW (Ordinal: 1635, Address: 0x20870)
- RegDisablePredefinedCache (Ordinal: 1636, Address: 0x20b90)
- RegDisablePredefinedCacheEx (Ordinal: 1637, Address: 0x372d0)
- RegDisableReflectionKey (Ordinal: 1638, Address: 0x21900)
- RegEnableReflectionKey (Ordinal: 1639, Address: 0x21900)
- RegEnumKeyA (Ordinal: 1640, Address: 0x234d0)
- RegEnumKeyExA (Ordinal: 1641, Address: 0x230e0)
- RegEnumKeyExW (Ordinal: 1642, Address: 0x1f100)
- RegEnumKeyW (Ordinal: 1643, Address: 0x1f190)
- RegEnumValueA (Ordinal: 1644, Address: 0x230c0)
- RegEnumValueW (Ordinal: 1645, Address: 0x1f1d0)
- RegFlushKey (Ordinal: 1646, Address: 0x20cd0)
- RegGetKeySecurity (Ordinal: 1647, Address: 0x372e0)
- RegGetValueA (Ordinal: 1648, Address: 0x37300)
- RegGetValueW (Ordinal: 1649, Address: 0x20780)
- RegLoadAppKeyA (Ordinal: 1650, Address: 0x37320)
- RegLoadAppKeyW (Ordinal: 1651, Address: 0x37340)
- RegLoadKeyA (Ordinal: 1652, Address: 0x37360)
- RegLoadKeyW (Ordinal: 1653, Address: 0x37380)
- RegLoadMUIStringA (Ordinal: 1654, Address: 0x373a0)
- RegLoadMUIStringW (Ordinal: 1655, Address: 0x373c0)
- RegNotifyChangeKeyValue (Ordinal: 1656, Address: 0x206b0)
- RegOpenCurrentUser (Ordinal: 1657, Address: 0x20ae0)
- RegOpenKeyA (Ordinal: 1658, Address: 0x20710)
- RegOpenKeyExA (Ordinal: 1659, Address: 0x1f240)
- RegOpenKeyExW (Ordinal: 1660, Address: 0x1efe0)
- RegOpenKeyTransactedA (Ordinal: 1661, Address: 0x46410)
- RegOpenKeyTransactedW (Ordinal: 1662, Address: 0x23e90)
- RegOpenKeyW (Ordinal: 1663, Address: 0x1f360)
- RegOpenUserClassesRoot (Ordinal: 1664, Address: 0x373e0)
- RegOverridePredefKey (Ordinal: 1665, Address: 0x46460)
- RegQueryInfoKeyA (Ordinal: 1666, Address: 0x20120)
- RegQueryInfoKeyW (Ordinal: 1667, Address: 0x1f130)
- RegQueryMultipleValuesA (Ordinal: 1668, Address: 0x37400)
- RegQueryMultipleValuesW (Ordinal: 1669, Address: 0x37420)
- RegQueryReflectionKey (Ordinal: 1670, Address: 0x37bb0)
- RegQueryValueA (Ordinal: 1671, Address: 0x12700)
- RegQueryValueExA (Ordinal: 1672, Address: 0x1f080)
- RegQueryValueExW (Ordinal: 1673, Address: 0x1ef10)
- RegQueryValueW (Ordinal: 1674, Address: 0x1f410)
- RegRenameKey (Ordinal: 1675, Address: 0x46520)
- RegReplaceKeyA (Ordinal: 1676, Address: 0x468b0)
- RegReplaceKeyW (Ordinal: 1677, Address: 0x47260)
- RegRestoreKeyA (Ordinal: 1678, Address: 0x37440)
- RegRestoreKeyW (Ordinal: 1679, Address: 0x37460)
- RegSaveKeyA (Ordinal: 1680, Address: 0x46af0)
- RegSaveKeyExA (Ordinal: 1681, Address: 0x37480)
- RegSaveKeyExW (Ordinal: 1682, Address: 0x374a0)
- RegSaveKeyW (Ordinal: 1683, Address: 0x46c60)
- RegSetKeySecurity (Ordinal: 1684, Address: 0x374c0)
- RegSetKeyValueA (Ordinal: 1685, Address: 0x374e0)
- RegSetKeyValueW (Ordinal: 1686, Address: 0x24b70)
- RegSetValueA (Ordinal: 1687, Address: 0x46da0)
- RegSetValueExA (Ordinal: 1688, Address: 0x206f0)
- RegSetValueExW (Ordinal: 1689, Address: 0x1f220)
- RegSetValueW (Ordinal: 1690, Address: 0x46e90)
- RegUnLoadKeyA (Ordinal: 1691, Address: 0x37500)
- RegUnLoadKeyW (Ordinal: 1692, Address: 0x37520)
- RegisterEventSourceA (Ordinal: 1693, Address: 0x23510)
- RegisterEventSourceW (Ordinal: 1694, Address: 0x20f60)
- RegisterIdleTask (Ordinal: 1695, Address: 0x24f90)
- RegisterServiceCtrlHandlerA (Ordinal: 1696, Address: 0x37540)
- RegisterServiceCtrlHandlerExA (Ordinal: 1697, Address: 0x254f0)
- RegisterServiceCtrlHandlerExW (Ordinal: 1698, Address: 0x24bd0)
- RegisterServiceCtrlHandlerW (Ordinal: 1699, Address: 0x20d30)
- RegisterTraceGuidsA (Ordinal: 1700, Address: 0x6a334)
- RegisterTraceGuidsW (Ordinal: 1701, Address: 0x6a365)
- RegisterWaitChainCOMCallback (Ordinal: 1702, Address: 0x5d6d0)
- RemoteRegEnumKeyWrapper (Ordinal: 1703, Address: 0x465e0)
- RemoteRegEnumValueWrapper (Ordinal: 1704, Address: 0x46700)
- RemoteRegQueryInfoKeyWrapper (Ordinal: 1705, Address: 0x467b0)
- RemoteRegQueryMultipleValues2Wrapper (Ordinal: 1706, Address: 0x46f90)
- RemoteRegQueryMultipleValuesWrapper (Ordinal: 1707, Address: 0x47080)
- RemoteRegQueryValueWrapper (Ordinal: 1708, Address: 0x46860)
- RemoveTraceCallback (Ordinal: 1709, Address: 0x6a466)
- RemoveUsersFromEncryptedFile (Ordinal: 1710, Address: 0x358f0)
- ReportEventA (Ordinal: 1711, Address: 0x51650)
- ReportEventW (Ordinal: 1712, Address: 0x212f0)
- RevertToSelf (Ordinal: 1713, Address: 0x1fe10)
- SafeBaseRegGetKeySecurity (Ordinal: 1714, Address: 0x45d00)
- SaferCloseLevel (Ordinal: 1715, Address: 0x1ef40)
- SaferComputeTokenFromLevel (Ordinal: 1716, Address: 0x1bbc0)
- SaferCreateLevel (Ordinal: 1717, Address: 0x3c850)
- SaferGetLevelInformation (Ordinal: 1718, Address: 0x3cdd0)
- SaferGetPolicyInformation (Ordinal: 1719, Address: 0x1c220)
- SaferIdentifyLevel (Ordinal: 1720, Address: 0x1c390)
- SaferRecordEventLogEntry (Ordinal: 1721, Address: 0x3e3b0)
- SaferSetLevelInformation (Ordinal: 1722, Address: 0x3e9b0)
- SaferSetPolicyInformation (Ordinal: 1723, Address: 0x3d720)
- SaferiChangeRegistryScope (Ordinal: 1724, Address: 0x3f900)
- SaferiCompareTokenLevels (Ordinal: 1725, Address: 0x1b500)
- SaferiIsDllAllowed (Ordinal: 1726, Address: 0x3dca0)
- SaferiIsExecutableFileType (Ordinal: 1727, Address: 0x3fe60)
- SaferiPopulateDefaultsInRegistry (Ordinal: 1728, Address: 0x3f940)
- SaferiRecordEventLogEntry (Ordinal: 1729, Address: 0x3e3b0)
- SaferiSearchMatchingHashRules (Ordinal: 1730, Address: 0x200b0)
- SetAclInformation (Ordinal: 1731, Address: 0x37560)
- SetEncryptedFileMetadata (Ordinal: 1732, Address: 0x35950)
- SetEntriesInAccessListA (Ordinal: 1733, Address: 0x43870)
- SetEntriesInAccessListW (Ordinal: 1734, Address: 0x438b0)
- SetEntriesInAclA (Ordinal: 1735, Address: 0x24e90)
- SetEntriesInAclW (Ordinal: 1736, Address: 0x20b70)
- SetEntriesInAuditListA (Ordinal: 1737, Address: 0x438f0)
- SetEntriesInAuditListW (Ordinal: 1738, Address: 0x43920)
- SetFileSecurityA (Ordinal: 1739, Address: 0x49270)
- SetFileSecurityW (Ordinal: 1740, Address: 0x254d0)
- SetInformationCodeAuthzLevelW (Ordinal: 1741, Address: 0x3e9b0)
- SetInformationCodeAuthzPolicyW (Ordinal: 1742, Address: 0x3d720)
- SetKernelObjectSecurity (Ordinal: 1743, Address: 0x20d50)
- SetNamedSecurityInfoA (Ordinal: 1744, Address: 0x24c60)
- SetNamedSecurityInfoExA (Ordinal: 1745, Address: 0x43950)
- SetNamedSecurityInfoExW (Ordinal: 1746, Address: 0x43c70)
- SetNamedSecurityInfoW (Ordinal: 1747, Address: 0x37580)
- SetPrivateObjectSecurity (Ordinal: 1748, Address: 0x375c0)
- SetPrivateObjectSecurityEx (Ordinal: 1749, Address: 0x375a0)
- SetSecurityAccessMask (Ordinal: 1750, Address: 0x375e0)
- SetSecurityDescriptorControl (Ordinal: 1751, Address: 0x375f0)
- SetSecurityDescriptorDacl (Ordinal: 1752, Address: 0x1f680)
- SetSecurityDescriptorGroup (Ordinal: 1753, Address: 0x24c30)
- SetSecurityDescriptorOwner (Ordinal: 1754, Address: 0x20180)
- SetSecurityDescriptorRMControl (Ordinal: 1755, Address: 0x37610)
- SetSecurityDescriptorSacl (Ordinal: 1756, Address: 0x37630)
- SetSecurityInfo (Ordinal: 1757, Address: 0x206d0)
- SetSecurityInfoExA (Ordinal: 1758, Address: 0x43e90)
- SetSecurityInfoExW (Ordinal: 1759, Address: 0x44180)
- SetServiceBits (Ordinal: 1760, Address: 0x47b00)
- SetServiceObjectSecurity (Ordinal: 1761, Address: 0x37650)
- SetServiceStatus (Ordinal: 1762, Address: 0x20a10)
- SetThreadToken (Ordinal: 1763, Address: 0x1f3f0)
- SetTokenInformation (Ordinal: 1764, Address: 0x24b90)
- SetTraceCallback (Ordinal: 1765, Address: 0x6a979)
- SetUserFileEncryptionKey (Ordinal: 1766, Address: 0x35960)
- SetUserFileEncryptionKeyEx (Ordinal: 1767, Address: 0x359b0)
- StartServiceA (Ordinal: 1768, Address: 0x37670)
- StartServiceCtrlDispatcherA (Ordinal: 1769, Address: 0x25530)
- StartServiceCtrlDispatcherW (Ordinal: 1770, Address: 0x20d10)
- StartServiceW (Ordinal: 1771, Address: 0x25490)
- StartTraceA (Ordinal: 1772, Address: 0x25a80)
- StartTraceW (Ordinal: 1773, Address: 0x23f60)
- StopTraceA (Ordinal: 1774, Address: 0x454a0)
- StopTraceW (Ordinal: 1775, Address: 0x37690)
- SystemFunction001 (Ordinal: 1776, Address: 0x6aa5a)
- SystemFunction002 (Ordinal: 1777, Address: 0x6aa88)
- SystemFunction003 (Ordinal: 1778, Address: 0x6aab6)
- SystemFunction004 (Ordinal: 1779, Address: 0x6aae4)
- SystemFunction005 (Ordinal: 1780, Address: 0x6ab12)
- SystemFunction006 (Ordinal: 1781, Address: 0x6ab40)
- SystemFunction007 (Ordinal: 1782, Address: 0x6ab6c)
- SystemFunction008 (Ordinal: 1783, Address: 0x6ab98)
- SystemFunction009 (Ordinal: 1784, Address: 0x6abc4)
- SystemFunction010 (Ordinal: 1785, Address: 0x6abf0)
- SystemFunction011 (Ordinal: 1786, Address: 0x6ac1c)
- SystemFunction012 (Ordinal: 1787, Address: 0x6ac48)
- SystemFunction013 (Ordinal: 1788, Address: 0x6ac74)
- SystemFunction014 (Ordinal: 1789, Address: 0x6aca0)
- SystemFunction015 (Ordinal: 1790, Address: 0x6accc)
- SystemFunction016 (Ordinal: 1791, Address: 0x6acf8)
- SystemFunction017 (Ordinal: 1792, Address: 0x37de0)
- SystemFunction018 (Ordinal: 1793, Address: 0x6ad36)
- SystemFunction019 (Ordinal: 1794, Address: 0x37e20)
- SystemFunction020 (Ordinal: 1795, Address: 0x6ad74)
- SystemFunction021 (Ordinal: 1796, Address: 0x6ada0)
- SystemFunction022 (Ordinal: 1797, Address: 0x6adcc)
- SystemFunction023 (Ordinal: 1798, Address: 0x6adf8)
- SystemFunction024 (Ordinal: 1799, Address: 0x6ae24)
- SystemFunction025 (Ordinal: 1800, Address: 0x6ae50)
- SystemFunction026 (Ordinal: 1801, Address: 0x6ae7c)
- SystemFunction027 (Ordinal: 1802, Address: 0x6aea8)
- SystemFunction028 (Ordinal: 1803, Address: 0x6aed4)
- SystemFunction029 (Ordinal: 1804, Address: 0x6af02)
- SystemFunction030 (Ordinal: 1805, Address: 0x6af30)
- SystemFunction031 (Ordinal: 1806, Address: 0x6af5c)
- SystemFunction032 (Ordinal: 1807, Address: 0x6af88)
- SystemFunction033 (Ordinal: 1808, Address: 0x6afb4)
- SystemFunction034 (Ordinal: 1809, Address: 0x6afe0)
- SystemFunction035 (Ordinal: 1810, Address: 0x6b00e)
- SystemFunction036 (Ordinal: 1811, Address: 0x6b03d)
- SystemFunction040 (Ordinal: 1812, Address: 0x6b06b)
- SystemFunction041 (Ordinal: 1813, Address: 0x6b099)
- TraceEvent (Ordinal: 1814, Address: 0x6b0c0)
- TraceEventInstance (Ordinal: 1815, Address: 0x6b0ea)
- TraceMessage (Ordinal: 1816, Address: 0x6b113)
- TraceMessageVa (Ordinal: 1817, Address: 0x6b138)
- TraceQueryInformation (Ordinal: 1818, Address: 0x6b166)
- TraceSetInformation (Ordinal: 1819, Address: 0x376b0)
- TreeResetNamedSecurityInfoA (Ordinal: 1820, Address: 0x42220)
- TreeResetNamedSecurityInfoW (Ordinal: 1821, Address: 0x12550)
- TreeSetNamedSecurityInfoA (Ordinal: 1822, Address: 0x42220)
- TreeSetNamedSecurityInfoW (Ordinal: 1823, Address: 0x42230)
- TrusteeAccessToObjectA (Ordinal: 1824, Address: 0x443a0)
- TrusteeAccessToObjectW (Ordinal: 1825, Address: 0x44570)
- UninstallApplication (Ordinal: 1826, Address: 0x3b960)
- UnlockServiceDatabase (Ordinal: 1827, Address: 0x47b40)
- UnregisterIdleTask (Ordinal: 1828, Address: 0x21880)
- UnregisterTraceGuids (Ordinal: 1829, Address: 0x6b2a3)
- UpdateTraceA (Ordinal: 1830, Address: 0x454d0)
- UpdateTraceW (Ordinal: 1831, Address: 0x45500)
- UsePinForEncryptedFilesA (Ordinal: 1832, Address: 0x35a10)
- UsePinForEncryptedFilesW (Ordinal: 1833, Address: 0x35a70)
- WaitServiceState (Ordinal: 1834, Address: 0x376e0)
- WmiCloseBlock (Ordinal: 1835, Address: 0x23990)
- WmiDevInstToInstanceNameA (Ordinal: 1836, Address: 0x573b0)
- WmiDevInstToInstanceNameW (Ordinal: 1837, Address: 0x57470)
- WmiEnumerateGuids (Ordinal: 1838, Address: 0x57540)
- WmiExecuteMethodA (Ordinal: 1839, Address: 0x576e0)
- WmiExecuteMethodW (Ordinal: 1840, Address: 0x57760)
- WmiFileHandleToInstanceNameA (Ordinal: 1841, Address: 0x57a60)
- WmiFileHandleToInstanceNameW (Ordinal: 1842, Address: 0x57c80)
- WmiFreeBuffer (Ordinal: 1843, Address: 0x57e70)
- WmiMofEnumerateResourcesA (Ordinal: 1844, Address: 0x58f40)
- WmiMofEnumerateResourcesW (Ordinal: 1845, Address: 0x59130)
- WmiNotificationRegistrationA (Ordinal: 1846, Address: 0x57eb0)
- WmiNotificationRegistrationW (Ordinal: 1847, Address: 0x57ef0)
- WmiOpenBlock (Ordinal: 1848, Address: 0x22a70)
- WmiQueryAllDataA (Ordinal: 1849, Address: 0x57f30)
- WmiQueryAllDataMultipleA (Ordinal: 1850, Address: 0x57f80)
- WmiQueryAllDataMultipleW (Ordinal: 1851, Address: 0x57fd0)
- WmiQueryAllDataW (Ordinal: 1852, Address: 0x58180)
- WmiQueryGuidInformation (Ordinal: 1853, Address: 0x58370)
- WmiQuerySingleInstanceA (Ordinal: 1854, Address: 0x58420)
- WmiQuerySingleInstanceMultipleA (Ordinal: 1855, Address: 0x584c0)
- WmiQuerySingleInstanceMultipleW (Ordinal: 1856, Address: 0x58620)
- WmiQuerySingleInstanceW (Ordinal: 1857, Address: 0x22ba0)
- WmiReceiveNotificationsA (Ordinal: 1858, Address: 0x58830)
- WmiReceiveNotificationsW (Ordinal: 1859, Address: 0x58870)
- WmiSetSingleInstanceA (Ordinal: 1860, Address: 0x588b0)
- WmiSetSingleInstanceW (Ordinal: 1861, Address: 0x58930)
- WmiSetSingleItemA (Ordinal: 1862, Address: 0x58ad0)
- WmiSetSingleItemW (Ordinal: 1863, Address: 0x58b50)
- WriteEncryptedFileRaw (Ordinal: 1864, Address: 0x35ae0)
Imported DLLs & Functions
api-ms-win-core-apiquery-l1-1-0.dll
- ApiSetQueryApiSetPresence (Address: 0x4c370248)
api-ms-win-core-namedpipe-l1-1-0.dll
- ImpersonateNamedPipeClient (Address: 0x4c370250)
api-ms-win-core-pcw-l1-1-0.dll
- PcwAddQueryItem (Address: 0x4c370260)
- PcwCollectData (Address: 0x4c370278)
- PcwCreateNotifier (Address: 0x4c370270)
- PcwCreateQuery (Address: 0x4c37025c)
- PcwEnumerateInstances (Address: 0x4c370258)
- PcwRemoveQueryItem (Address: 0x4c370264)
- PcwSendNotification (Address: 0x4c370268)
- PcwSendStatelessNotification (Address: 0x4c37026c)
- PcwSetQueryItemUserData (Address: 0x4c370274)
api-ms-win-core-processthreads-l1-1-0.dll
- CreateThread (Address: 0x4c37028c)
- GetCurrentProcess (Address: 0x4c3702a8)
- GetCurrentProcessId (Address: 0x4c3702a0)
- GetCurrentThread (Address: 0x4c370284)
- GetCurrentThreadId (Address: 0x4c370280)
- GetPriorityClass (Address: 0x4c370288)
- GetProcessId (Address: 0x4c37029c)
- OpenProcessToken (Address: 0x4c3702ac)
- OpenThread (Address: 0x4c370298)
- OpenThreadToken (Address: 0x4c370290)
- SetThreadToken (Address: 0x4c370294)
- TerminateProcess (Address: 0x4c3702a4)
api-ms-win-core-processthreads-l1-1-1.dll
- OpenProcess (Address: 0x4c3702b4)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x4c37035c)
- RegCopyTreeW (Address: 0x4c370324)
- RegCreateKeyExA (Address: 0x4c3702ec)
- RegCreateKeyExW (Address: 0x4c3702f4)
- RegDeleteKeyExA (Address: 0x4c370300)
- RegDeleteKeyExW (Address: 0x4c3702d0)
- RegDeleteTreeA (Address: 0x4c3702bc)
- RegDeleteTreeW (Address: 0x4c370310)
- RegDeleteValueA (Address: 0x4c370350)
- RegDeleteValueW (Address: 0x4c370348)
- RegDisablePredefinedCacheEx (Address: 0x4c3702c0)
- RegEnumKeyExA (Address: 0x4c370358)
- RegEnumKeyExW (Address: 0x4c370304)
- RegEnumValueA (Address: 0x4c370344)
- RegEnumValueW (Address: 0x4c370354)
- RegFlushKey (Address: 0x4c3702f0)
- RegGetKeySecurity (Address: 0x4c3702c8)
- RegGetValueA (Address: 0x4c3702dc)
- RegGetValueW (Address: 0x4c37033c)
- RegLoadAppKeyA (Address: 0x4c37031c)
- RegLoadAppKeyW (Address: 0x4c3702cc)
- RegLoadKeyA (Address: 0x4c370328)
- RegLoadKeyW (Address: 0x4c370334)
- RegLoadMUIStringA (Address: 0x4c3702e4)
- RegLoadMUIStringW (Address: 0x4c370314)
- RegNotifyChangeKeyValue (Address: 0x4c3702c4)
- RegOpenCurrentUser (Address: 0x4c3702d4)
- RegOpenKeyExA (Address: 0x4c370338)
- RegOpenKeyExW (Address: 0x4c370360)
- RegOpenUserClassesRoot (Address: 0x4c3702fc)
- RegQueryInfoKeyA (Address: 0x4c370330)
- RegQueryInfoKeyW (Address: 0x4c3702d8)
- RegQueryValueExA (Address: 0x4c3702e8)
- RegQueryValueExW (Address: 0x4c370364)
- RegRestoreKeyA (Address: 0x4c37034c)
- RegRestoreKeyW (Address: 0x4c370340)
- RegSaveKeyExA (Address: 0x4c3702e0)
- RegSaveKeyExW (Address: 0x4c37030c)
- RegSetKeySecurity (Address: 0x4c370308)
- RegSetValueExA (Address: 0x4c370320)
- RegSetValueExW (Address: 0x4c370318)
- RegUnLoadKeyA (Address: 0x4c3702f8)
- RegUnLoadKeyW (Address: 0x4c37032c)
api-ms-win-core-registry-l1-1-1.dll
- RegDeleteKeyValueA (Address: 0x4c370374)
- RegDeleteKeyValueW (Address: 0x4c37036c)
- RegSetKeyValueA (Address: 0x4c370370)
- RegSetKeyValueW (Address: 0x4c370378)
api-ms-win-core-registry-l1-1-2.dll
- RegQueryMultipleValuesA (Address: 0x4c370380)
- RegQueryMultipleValuesW (Address: 0x4c370384)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetComputerNameExA (Address: 0x4c37038c)
- GetComputerNameExW (Address: 0x4c37039c)
- GetLocalTime (Address: 0x4c3703a0)
- GetSystemDirectoryW (Address: 0x4c370398)
- GetSystemTime (Address: 0x4c370390)
- GetSystemTimeAsFileTime (Address: 0x4c3703a8)
- GetSystemWindowsDirectoryW (Address: 0x4c370394)
- GetTickCount (Address: 0x4c3703a4)
api-ms-win-core-timezone-l1-1-0.dll
- EnumDynamicTimeZoneInformation (Address: 0x4c3703b0)
- GetDynamicTimeZoneInformationEffectiveYears (Address: 0x4c3703b4)
api-ms-win-eventing-consumer-l1-1-0.dll
- CloseTrace (Address: 0x4c3703bc)
- OpenTraceW (Address: 0x4c3703c4)
- ProcessTrace (Address: 0x4c3703c0)
api-ms-win-eventing-consumer-l1-1-1.dll
- QueryTraceProcessingHandle (Address: 0x4c3703cc)
api-ms-win-eventing-controller-l1-1-0.dll
- ControlTraceW (Address: 0x4c3703e4)
- EnableTraceEx2 (Address: 0x4c3703e0)
- EnumerateTraceGuidsEx (Address: 0x4c3703f0)
- EventAccessControl (Address: 0x4c3703d8)
- EventAccessQuery (Address: 0x4c3703d4)
- EventAccessRemove (Address: 0x4c3703ec)
- QueryAllTracesW (Address: 0x4c3703dc)
- StartTraceW (Address: 0x4c3703f4)
- StopTraceW (Address: 0x4c3703f8)
- TraceSetInformation (Address: 0x4c3703e8)
api-ms-win-eventing-provider-l1-1-0.dll
- EventRegister (Address: 0x4c370400)
- EventSetInformation (Address: 0x4c370404)
- EventUnregister (Address: 0x4c370408)
- EventWriteTransfer (Address: 0x4c37040c)
api-ms-win-security-audit-l1-1-0.dll
- AuditComputeEffectivePolicyBySid (Address: 0x4c370420)
- AuditFree (Address: 0x4c370414)
- AuditQuerySystemPolicy (Address: 0x4c37041c)
- AuditSetSystemPolicy (Address: 0x4c370418)
api-ms-win-security-audit-l1-1-1.dll
- AuditEnumerateCategories (Address: 0x4c37043c)
- AuditEnumeratePerUserPolicy (Address: 0x4c370440)
- AuditEnumerateSubCategories (Address: 0x4c370434)
- AuditLookupCategoryNameW (Address: 0x4c370444)
- AuditLookupSubCategoryNameW (Address: 0x4c370428)
- AuditQueryGlobalSaclW (Address: 0x4c370438)
- AuditQueryPerUserPolicy (Address: 0x4c370450)
- AuditQuerySecurity (Address: 0x4c37042c)
- AuditSetGlobalSaclW (Address: 0x4c370448)
- AuditSetPerUserPolicy (Address: 0x4c370430)
- AuditSetSecurity (Address: 0x4c37044c)
api-ms-win-security-base-l1-1-0.dll
- AccessCheck (Address: 0x4c370544)
- AccessCheckAndAuditAlarmW (Address: 0x4c3704d0)
- AccessCheckByType (Address: 0x4c37051c)
- AccessCheckByTypeAndAuditAlarmW (Address: 0x4c3705c0)
- AccessCheckByTypeResultList (Address: 0x4c370534)
- AccessCheckByTypeResultListAndAuditAlarmByHandleW (Address: 0x4c370570)
- AccessCheckByTypeResultListAndAuditAlarmW (Address: 0x4c3704b0)
- AddAccessAllowedAce (Address: 0x4c370510)
- AddAccessAllowedAceEx (Address: 0x4c3704f8)
- AddAccessAllowedObjectAce (Address: 0x4c3704e8)
- AddAccessDeniedAce (Address: 0x4c3704bc)
- AddAccessDeniedAceEx (Address: 0x4c37046c)
- AddAccessDeniedObjectAce (Address: 0x4c370514)
- AddAce (Address: 0x4c3704a8)
- AddAuditAccessAce (Address: 0x4c3704ac)
- AddAuditAccessAceEx (Address: 0x4c370520)
- AddAuditAccessObjectAce (Address: 0x4c370558)
- AdjustTokenGroups (Address: 0x4c370548)
- AdjustTokenPrivileges (Address: 0x4c3705b8)
- AllocateAndInitializeSid (Address: 0x4c370574)
- AllocateLocallyUniqueId (Address: 0x4c3705a4)
- AreAllAccessesGranted (Address: 0x4c370588)
- AreAnyAccessesGranted (Address: 0x4c370540)
- CheckTokenMembership (Address: 0x4c3704d4)
- ConvertToAutoInheritPrivateObjectSecurity (Address: 0x4c3705a0)
- CopySid (Address: 0x4c370478)
- CreatePrivateObjectSecurity (Address: 0x4c370468)
- CreatePrivateObjectSecurityEx (Address: 0x4c37054c)
- CreatePrivateObjectSecurityWithMultipleInheritance (Address: 0x4c370590)
- CreateRestrictedToken (Address: 0x4c3704c0)
- CreateWellKnownSid (Address: 0x4c370580)
- DeleteAce (Address: 0x4c370484)
- DestroyPrivateObjectSecurity (Address: 0x4c37058c)
- DuplicateToken (Address: 0x4c3704e0)
- DuplicateTokenEx (Address: 0x4c370504)
- EqualDomainSid (Address: 0x4c3704a0)
- EqualPrefixSid (Address: 0x4c3704c8)
- EqualSid (Address: 0x4c370564)
- FindFirstFreeAce (Address: 0x4c3705c4)
- FreeSid (Address: 0x4c3704c4)
- GetAce (Address: 0x4c370458)
- GetAclInformation (Address: 0x4c370550)
- GetFileSecurityW (Address: 0x4c3704cc)
- GetKernelObjectSecurity (Address: 0x4c3704ec)
- GetLengthSid (Address: 0x4c3704fc)
- GetPrivateObjectSecurity (Address: 0x4c370584)
- GetSecurityDescriptorControl (Address: 0x4c370474)
- GetSecurityDescriptorDacl (Address: 0x4c3705a8)
- GetSecurityDescriptorGroup (Address: 0x4c370578)
- GetSecurityDescriptorLength (Address: 0x4c37050c)
- GetSecurityDescriptorOwner (Address: 0x4c370490)
- GetSecurityDescriptorRMControl (Address: 0x4c37045c)
- GetSecurityDescriptorSacl (Address: 0x4c3705c8)
- GetSidIdentifierAuthority (Address: 0x4c37052c)
- GetSidLengthRequired (Address: 0x4c370594)
- GetSidSubAuthority (Address: 0x4c37057c)
- GetSidSubAuthorityCount (Address: 0x4c370568)
- GetTokenInformation (Address: 0x4c370530)
- GetWindowsAccountDomainSid (Address: 0x4c370598)
- ImpersonateAnonymousToken (Address: 0x4c370494)
- ImpersonateLoggedOnUser (Address: 0x4c37049c)
- ImpersonateSelf (Address: 0x4c370498)
- InitializeAcl (Address: 0x4c3704dc)
- InitializeSecurityDescriptor (Address: 0x4c37059c)
- InitializeSid (Address: 0x4c37048c)
- IsTokenRestricted (Address: 0x4c370464)
- IsValidAcl (Address: 0x4c370508)
- IsValidSecurityDescriptor (Address: 0x4c3704b8)
- IsValidSid (Address: 0x4c3704a4)
- IsWellKnownSid (Address: 0x4c370480)
- MakeAbsoluteSD (Address: 0x4c370524)
- MakeSelfRelativeSD (Address: 0x4c370518)
- MapGenericMask (Address: 0x4c3704f0)
- ObjectCloseAuditAlarmW (Address: 0x4c37053c)
- ObjectDeleteAuditAlarmW (Address: 0x4c37056c)
- ObjectOpenAuditAlarmW (Address: 0x4c370560)
- ObjectPrivilegeAuditAlarmW (Address: 0x4c37047c)
- PrivilegeCheck (Address: 0x4c370538)
- PrivilegedServiceAuditAlarmW (Address: 0x4c370488)
- QuerySecurityAccessMask (Address: 0x4c3705b0)
- RevertToSelf (Address: 0x4c3705ac)
- SetAclInformation (Address: 0x4c3704b4)
- SetFileSecurityW (Address: 0x4c370554)
- SetKernelObjectSecurity (Address: 0x4c3704f4)
- SetPrivateObjectSecurity (Address: 0x4c3705b4)
- SetPrivateObjectSecurityEx (Address: 0x4c3704e4)
- SetSecurityAccessMask (Address: 0x4c370470)
- SetSecurityDescriptorControl (Address: 0x4c370500)
- SetSecurityDescriptorDacl (Address: 0x4c3705bc)
- SetSecurityDescriptorGroup (Address: 0x4c370528)
- SetSecurityDescriptorOwner (Address: 0x4c370460)
- SetSecurityDescriptorRMControl (Address: 0x4c3704d8)
- SetSecurityDescriptorSacl (Address: 0x4c3705cc)
- SetTokenInformation (Address: 0x4c37055c)
api-ms-win-security-base-private-l1-1-0.dll
- MakeAbsoluteSD2 (Address: 0x4c3705d4)
api-ms-win-service-core-l1-1-0.dll
- RegisterServiceCtrlHandlerExW (Address: 0x4c3705e0)
- SetServiceStatus (Address: 0x4c3705dc)
- StartServiceCtrlDispatcherW (Address: 0x4c3705e4)
api-ms-win-service-core-l1-1-1.dll
- EnumDependentServicesW (Address: 0x4c3705ec)
- EnumServicesStatusExW (Address: 0x4c3705f0)
- QueryServiceDynamicInformation (Address: 0x4c3705f4)
api-ms-win-service-core-l1-1-2.dll
- GetServiceDisplayNameW (Address: 0x4c3705fc)
- GetServiceKeyNameW (Address: 0x4c370600)
api-ms-win-service-management-l1-1-0.dll
- CloseServiceHandle (Address: 0x4c370614)
- ControlServiceExW (Address: 0x4c37061c)
- CreateServiceW (Address: 0x4c370608)
- DeleteService (Address: 0x4c370620)
- OpenSCManagerW (Address: 0x4c37060c)
- OpenServiceW (Address: 0x4c370618)
- StartServiceW (Address: 0x4c370610)
api-ms-win-service-management-l2-1-0.dll
- ChangeServiceConfig2W (Address: 0x4c370644)
- ChangeServiceConfigW (Address: 0x4c370634)
- NotifyServiceStatusChangeW (Address: 0x4c370640)
- QueryServiceConfig2W (Address: 0x4c370630)
- QueryServiceConfigW (Address: 0x4c370638)
- QueryServiceObjectSecurity (Address: 0x4c370628)
- QueryServiceStatusEx (Address: 0x4c37062c)
- SetServiceObjectSecurity (Address: 0x4c37063c)
api-ms-win-service-private-l1-1-0.dll
- I_ScRpcBindA (Address: 0x4c37064c)
- I_ScRpcBindW (Address: 0x4c370650)
- I_ScSetServiceBitsA (Address: 0x4c370658)
- I_ScSetServiceBitsW (Address: 0x4c37065c)
- WaitServiceState (Address: 0x4c370654)
api-ms-win-service-private-l1-1-2.dll
- I_ScReparseServiceDatabase (Address: 0x4c370668)
- QueryLocalUserServiceName (Address: 0x4c370664)
- QueryUserServiceName (Address: 0x4c37066c)
api-ms-win-service-private-l1-1-3.dll
- QueryUserServiceNameForContext (Address: 0x4c370674)
api-ms-win-service-private-l1-1-4.dll
- CreateServiceEx (Address: 0x4c37067c)
api-ms-win-service-winsvc-l1-1-0.dll
- ChangeServiceConfig2A (Address: 0x4c370688)
- ChangeServiceConfigA (Address: 0x4c370698)
- ControlService (Address: 0x4c370690)
- ControlServiceExA (Address: 0x4c370684)
- CreateServiceA (Address: 0x4c3706b0)
- NotifyServiceStatusChangeA (Address: 0x4c3706bc)
- OpenSCManagerA (Address: 0x4c37069c)
- OpenServiceA (Address: 0x4c370694)
- QueryServiceConfig2A (Address: 0x4c3706ac)
- QueryServiceConfigA (Address: 0x4c3706a4)
- QueryServiceStatus (Address: 0x4c3706b8)
- RegisterServiceCtrlHandlerA (Address: 0x4c3706a0)
- RegisterServiceCtrlHandlerExA (Address: 0x4c3706c0)
- RegisterServiceCtrlHandlerW (Address: 0x4c3706a8)
- StartServiceA (Address: 0x4c37068c)
- StartServiceCtrlDispatcherA (Address: 0x4c3706b4)
KERNEL32.dll
- AreFileApisANSI (Address: 0x4c3700cc)
- CancelIoEx (Address: 0x4c370144)
- CancelThreadpoolIo (Address: 0x4c370148)
- CloseHandle (Address: 0x4c370040)
- CloseThreadpoolIo (Address: 0x4c370140)
- CompareFileTime (Address: 0x4c370098)
- CompareStringOrdinal (Address: 0x4c3700b4)
- CopyFileExW (Address: 0x4c37016c)
- CreateEventW (Address: 0x4c37003c)
- CreateFileMappingW (Address: 0x4c370088)
- CreateFileW (Address: 0x4c37005c)
- CreateMutexW (Address: 0x4c3700e4)
- CreateThreadpoolIo (Address: 0x4c37014c)
- DecodePointer (Address: 0x4c370128)
- DelayLoadFailureHook (Address: 0x4c370028)
- DeleteCriticalSection (Address: 0x4c3700a8)
- DeleteFileW (Address: 0x4c37006c)
- DeviceIoControl (Address: 0x4c370150)
- DosDateTimeToFileTime (Address: 0x4c370110)
- DuplicateHandle (Address: 0x4c370130)
- EncodePointer (Address: 0x4c370138)
- EnterCriticalSection (Address: 0x4c370010)
- EnumUILanguagesW (Address: 0x4c37015c)
- ExpandEnvironmentStringsA (Address: 0x4c3700c4)
- ExpandEnvironmentStringsW (Address: 0x4c370054)
- FileTimeToDosDateTime (Address: 0x4c37010c)
- FindClose (Address: 0x4c370170)
- FindFirstFileExW (Address: 0x4c370118)
- FindNextFileW (Address: 0x4c370174)
- FindResourceExW (Address: 0x4c37009c)
- FormatMessageW (Address: 0x4c370060)
- FreeLibrary (Address: 0x4c370020)
- FreeLibraryAndExitThread (Address: 0x4c370134)
- FreeLibraryWhenCallbackReturns (Address: 0x4c37013c)
- GetCommandLineW (Address: 0x4c370048)
- GetComputerNameW (Address: 0x4c3700c0)
- GetFileAttributesExW (Address: 0x4c370064)
- GetFileAttributesW (Address: 0x4c370000)
- GetFileMUIPath (Address: 0x4c370158)
- GetFileSize (Address: 0x4c370114)
- GetFileSizeEx (Address: 0x4c370084)
- GetFileTime (Address: 0x4c370108)
- GetFullPathNameW (Address: 0x4c3700d4)
- GetLastError (Address: 0x4c370018)
- GetLongPathNameW (Address: 0x4c370094)
- GetModuleFileNameW (Address: 0x4c3700c8)
- GetModuleHandleExW (Address: 0x4c37004c)
- GetModuleHandleW (Address: 0x4c370074)
- GetProcAddress (Address: 0x4c37001c)
- GetProcessHeap (Address: 0x4c37007c)
- GetThreadUILanguage (Address: 0x4c370044)
- GetVolumePathNameW (Address: 0x4c3700a4)
- HeapAlloc (Address: 0x4c370080)
- HeapFree (Address: 0x4c370078)
- InitializeCriticalSection (Address: 0x4c3700e8)
- InitOnceBeginInitialize (Address: 0x4c3700b0)
- InitOnceComplete (Address: 0x4c3700bc)
- IsWow64Process (Address: 0x4c3700ec)
- LeaveCriticalSection (Address: 0x4c370014)
- LoadLibraryA (Address: 0x4c3700e0)
- LoadLibraryExA (Address: 0x4c3700dc)
- LoadLibraryExW (Address: 0x4c370024)
- LoadLibraryW (Address: 0x4c37012c)
- LoadResource (Address: 0x4c3700a0)
- LocalFree (Address: 0x4c370008)
- LockResource (Address: 0x4c3700f8)
- MapViewOfFile (Address: 0x4c37008c)
- MoveFileW (Address: 0x4c370070)
- MultiByteToWideChar (Address: 0x4c370004)
- OutputDebugStringW (Address: 0x4c370068)
- QueryPerformanceCounter (Address: 0x4c370038)
- RaiseException (Address: 0x4c370164)
- ReadProcessMemory (Address: 0x4c370124)
- ReleaseMutex (Address: 0x4c3700b8)
- ResetEvent (Address: 0x4c370104)
- ResolveDelayLoadedAPI (Address: 0x4c37002c)
- SearchPathW (Address: 0x4c3700d0)
- SetErrorMode (Address: 0x4c370160)
- SetEvent (Address: 0x4c370100)
- SetFileInformationByHandle (Address: 0x4c370168)
- SetFilePointer (Address: 0x4c370058)
- SetLastError (Address: 0x4c370178)
- SetUnhandledExceptionFilter (Address: 0x4c370034)
- SizeofResource (Address: 0x4c3700f4)
- SleepEx (Address: 0x4c3700d8)
- StartThreadpoolIo (Address: 0x4c370154)
- TermsrvDeleteKey (Address: 0x4c37011c)
- TermsrvOpenUserClasses (Address: 0x4c370120)
- UnhandledExceptionFilter (Address: 0x4c370030)
- UnmapViewOfFile (Address: 0x4c370090)
- WaitForSingleObject (Address: 0x4c3700ac)
- WideCharToMultiByte (Address: 0x4c37000c)
- Wow64DisableWow64FsRedirection (Address: 0x4c3700f0)
- Wow64RevertWow64FsRedirection (Address: 0x4c3700fc)
- WriteFile (Address: 0x4c370050)
KERNELBASE.dll
- CLOSE_LOCAL_HANDLE_INTERNAL (Address: 0x4c3701d8)
- CreateProcessAsUserA (Address: 0x4c3701a0)
- CreateProcessAsUserW (Address: 0x4c37019c)
- DisablePredefinedHandleTableInternal (Address: 0x4c3701c4)
- GetStagedPackagePathByFullName (Address: 0x4c3701bc)
- GetSystemDefaultUILanguage (Address: 0x4c3701a4)
- GetUserDefaultUILanguage (Address: 0x4c3701a8)
- LocalAlloc (Address: 0x4c370194)
- LocalReAlloc (Address: 0x4c370198)
- lstrcmpiW (Address: 0x4c3701ac)
- lstrcmpW (Address: 0x4c3701b4)
- lstrlenW (Address: 0x4c370190)
- MapPredefinedHandleInternal (Address: 0x4c3701d4)
- PackageIdFromFullName (Address: 0x4c370180)
- RegCreateKeyExInternalA (Address: 0x4c3701c8)
- RegCreateKeyExInternalW (Address: 0x4c3701e0)
- RegDeleteKeyExInternalA (Address: 0x4c3701d0)
- RegDeleteKeyExInternalW (Address: 0x4c3701b0)
- RegKrnGetClassesEnumTableAddressInternal (Address: 0x4c370188)
- RegKrnGetHKEY_ClassesRootAddress (Address: 0x4c370184)
- RegKrnGetTermsrvRegistryExtensionFlags (Address: 0x4c37018c)
- RegOpenKeyExInternalA (Address: 0x4c3701c0)
- RegOpenKeyExInternalW (Address: 0x4c3701dc)
- RemapPredefinedHandleInternal (Address: 0x4c3701cc)
- Sleep (Address: 0x4c3701b8)
msvcrt.dll
- __CxxFrameHandler3 (Address: 0x4c37071c)
- _errno (Address: 0x4c3706f8)
- _except_handler4_common (Address: 0x4c370744)
- _ftol2 (Address: 0x4c370734)
- _i64tow_s (Address: 0x4c370700)
- _resetstkoflw (Address: 0x4c37070c)
- _stricmp (Address: 0x4c370704)
- _ui64tow_s (Address: 0x4c3706fc)
- _ultow (Address: 0x4c3706f0)
- _ultow_s (Address: 0x4c3706dc)
- _vsnprintf (Address: 0x4c370718)
- _vsnwprintf (Address: 0x4c370750)
- _wcsicmp (Address: 0x4c3706c8)
- _wcsnicmp (Address: 0x4c3706cc)
- _wcstoi64 (Address: 0x4c3706ec)
- _wcstoui64 (Address: 0x4c3706e8)
- iswalpha (Address: 0x4c370710)
- iswctype (Address: 0x4c3706e0)
- memcmp (Address: 0x4c370738)
- memcpy (Address: 0x4c37073c)
- memcpy_s (Address: 0x4c370730)
- memmove (Address: 0x4c370740)
- memset (Address: 0x4c37075c)
- strchr (Address: 0x4c3706d8)
- strstr (Address: 0x4c3706d4)
- swprintf_s (Address: 0x4c370708)
- swscanf_s (Address: 0x4c370754)
- tolower (Address: 0x4c3706d0)
- wcscat_s (Address: 0x4c370758)
- wcschr (Address: 0x4c370748)
- wcscpy_s (Address: 0x4c370720)
- wcsncmp (Address: 0x4c370714)
- wcsncpy_s (Address: 0x4c370728)
- wcsnlen (Address: 0x4c37074c)
- wcsrchr (Address: 0x4c37072c)
- wcsstr (Address: 0x4c370724)
- wcstok_s (Address: 0x4c3706f4)
- wcstoul (Address: 0x4c3706e4)
ntdll.dll
- DbgPrint (Address: 0x4c370a38)
- EtwEventRegister (Address: 0x4c3707d4)
- EtwEventSetInformation (Address: 0x4c3708e0)
- EtwEventUnregister (Address: 0x4c370800)
- EtwEventWrite (Address: 0x4c3707d8)
- EtwEventWriteTransfer (Address: 0x4c3708dc)
- EtwGetTraceEnableFlags (Address: 0x4c370904)
- EtwGetTraceEnableLevel (Address: 0x4c370900)
- EtwGetTraceLoggerHandle (Address: 0x4c3708fc)
- EtwRegisterTraceGuidsW (Address: 0x4c370908)
- EtwTraceMessage (Address: 0x4c3708f8)
- EtwUnregisterTraceGuids (Address: 0x4c37090c)
- LdrLoadDll (Address: 0x4c3707c0)
- LdrUnloadDll (Address: 0x4c3707c8)
- NtAlpcQueryInformation (Address: 0x4c3709b0)
- NtClose (Address: 0x4c3708e4)
- NtCompareTokens (Address: 0x4c370788)
- NtCreateFile (Address: 0x4c370954)
- NtCreateKey (Address: 0x4c3707dc)
- NtCreateMutant (Address: 0x4c370934)
- NtCreatePrivateNamespace (Address: 0x4c37093c)
- NtDeleteKey (Address: 0x4c3707ec)
- NtDeviceIoControlFile (Address: 0x4c3707cc)
- NtDuplicateToken (Address: 0x4c370784)
- NtEnumerateKey (Address: 0x4c370804)
- NtOpenFile (Address: 0x4c3707a8)
- NtOpenKey (Address: 0x4c3709e4)
- NtOpenKeyEx (Address: 0x4c3709cc)
- NtOpenPrivateNamespace (Address: 0x4c370938)
- NtOpenProcessToken (Address: 0x4c370768)
- NtOpenSymbolicLinkObject (Address: 0x4c370834)
- NtOpenThreadToken (Address: 0x4c370764)
- NtQueryInformationFile (Address: 0x4c370844)
- NtQueryInformationProcess (Address: 0x4c3707b0)
- NtQueryInformationThread (Address: 0x4c370918)
- NtQueryInformationToken (Address: 0x4c370a14)
- NtQueryKey (Address: 0x4c3707b8)
- NtQueryMutant (Address: 0x4c3709bc)
- NtQueryObject (Address: 0x4c3709b8)
- NtQueryPerformanceCounter (Address: 0x4c37092c)
- NtQuerySecurityObject (Address: 0x4c37091c)
- NtQuerySymbolicLinkObject (Address: 0x4c370838)
- NtQuerySystemInformation (Address: 0x4c3707d0)
- NtQuerySystemTime (Address: 0x4c3708f0)
- NtQueryValueKey (Address: 0x4c370a58)
- NtQueryVolumeInformationFile (Address: 0x4c370830)
- NtReadFile (Address: 0x4c37095c)
- NtRenameKey (Address: 0x4c370874)
- NtReplaceKey (Address: 0x4c3709c8)
- NtSaveKey (Address: 0x4c3709d0)
- NtSaveMergedKeys (Address: 0x4c3709d4)
- NtSetInformationThread (Address: 0x4c370884)
- NtSetInformationToken (Address: 0x4c370778)
- NtSetSystemInformation (Address: 0x4c370a2c)
- NtSetValueKey (Address: 0x4c3707e0)
- NtTraceControl (Address: 0x4c370860)
- NtWaitForMultipleObjects (Address: 0x4c370948)
- NtWaitForSingleObject (Address: 0x4c370910)
- NtWriteFile (Address: 0x4c370958)
- RtlAbsoluteToSelfRelativeSD (Address: 0x4c3708bc)
- RtlAcquireSRWLockExclusive (Address: 0x4c370970)
- RtlAcquireSRWLockShared (Address: 0x4c37097c)
- RtlAddAccessAllowedAce (Address: 0x4c3709c0)
- RtlAddAccessAllowedAceEx (Address: 0x4c370774)
- RtlAddAccessAllowedObjectAce (Address: 0x4c3708c4)
- RtlAddAccessDeniedAceEx (Address: 0x4c3708c0)
- RtlAddAccessDeniedObjectAce (Address: 0x4c3708c8)
- RtlAddAce (Address: 0x4c370888)
- RtlAddAuditAccessAceEx (Address: 0x4c3708ac)
- RtlAddAuditAccessObjectAce (Address: 0x4c37089c)
- RtlAddSIDToBoundaryDescriptor (Address: 0x4c370940)
- RtlAdjustPrivilege (Address: 0x4c3708e8)
- RtlAllocateAndInitializeSid (Address: 0x4c37078c)
- RtlAllocateHandle (Address: 0x4c3709f0)
- RtlAllocateHeap (Address: 0x4c370a1c)
- RtlAnsiCharToUnicodeChar (Address: 0x4c370858)
- RtlAnsiStringToUnicodeString (Address: 0x4c370a50)
- RtlAppendUnicodeStringToString (Address: 0x4c370810)
- RtlAppendUnicodeToString (Address: 0x4c3707e8)
- RtlConvertSidToUnicodeString (Address: 0x4c3709f8)
- RtlCopySid (Address: 0x4c3707f4)
- RtlCopyString (Address: 0x4c3708ec)
- RtlCopyUnicodeString (Address: 0x4c37079c)
- RtlCreateAcl (Address: 0x4c37094c)
- RtlCreateBoundaryDescriptor (Address: 0x4c370944)
- RtlCreateQueryDebugBuffer (Address: 0x4c3709b4)
- RtlCreateSecurityDescriptor (Address: 0x4c37077c)
- RtlCreateUnicodeString (Address: 0x4c3707ac)
- RtlCreateUnicodeStringFromAsciiz (Address: 0x4c370870)
- RtlDeleteBoundaryDescriptor (Address: 0x4c370930)
- RtlDeleteCriticalSection (Address: 0x4c370a28)
- RtlDeleteElementGenericTable (Address: 0x4c3707e4)
- RtlDeleteElementGenericTableAvl (Address: 0x4c37098c)
- RtlDestroyHandleTable (Address: 0x4c3707fc)
- RtlDestroyQueryDebugBuffer (Address: 0x4c3709a8)
- RtlDetermineDosPathNameType_U (Address: 0x4c370840)
- RtlDllShutdownInProgress (Address: 0x4c37096c)
- RtlDosPathNameToNtPathName_U (Address: 0x4c3708d8)
- RtlDosPathNameToRelativeNtPathName_U (Address: 0x4c370998)
- RtlDuplicateUnicodeString (Address: 0x4c3707a0)
- RtlEnterCriticalSection (Address: 0x4c370a34)
- RtlEnumerateGenericTableAvl (Address: 0x4c370988)
- RtlEnumerateGenericTableWithoutSplaying (Address: 0x4c370798)
- RtlEqualSid (Address: 0x4c37076c)
- RtlEqualUnicodeString (Address: 0x4c3709a4)
- RtlExpandEnvironmentStrings_U (Address: 0x4c3707a4)
- RtlFirstFreeAce (Address: 0x4c3708cc)
- RtlFormatCurrentUserKeyPath (Address: 0x4c370814)
- RtlFreeAnsiString (Address: 0x4c370a54)
- RtlFreeHandle (Address: 0x4c3709e8)
- RtlFreeHeap (Address: 0x4c370a0c)
- RtlFreeSid (Address: 0x4c370790)
- RtlFreeUnicodeString (Address: 0x4c370a18)
- RtlGetAce (Address: 0x4c3708a8)
- RtlGetControlSecurityDescriptor (Address: 0x4c370898)
- RtlGetCurrentTransaction (Address: 0x4c370a48)
- RtlGetDaclSecurityDescriptor (Address: 0x4c3708d4)
- RtlGetFullPathName_U (Address: 0x4c370848)
- RtlGetGroupSecurityDescriptor (Address: 0x4c3708b8)
- RtlGetLastNtStatus (Address: 0x4c3707b4)
- RtlGetNtProductType (Address: 0x4c3709e0)
- RtlGetOwnerSecurityDescriptor (Address: 0x4c3708b4)
- RtlGetSaclSecurityDescriptor (Address: 0x4c3708a4)
- RtlGetThreadPreferredUILanguages (Address: 0x4c370a04)
- RtlGetVersion (Address: 0x4c370914)
- RtlGUIDFromString (Address: 0x4c370828)
- RtlImageNtHeader (Address: 0x4c3707c4)
- RtlImpersonateSelf (Address: 0x4c370a20)
- RtlInitAnsiString (Address: 0x4c370a40)
- RtlInitAnsiStringEx (Address: 0x4c370868)
- RtlInitializeCriticalSection (Address: 0x4c370a24)
- RtlInitializeGenericTable (Address: 0x4c370818)
- RtlInitializeGenericTableAvl (Address: 0x4c370990)
- RtlInitializeHandleTable (Address: 0x4c3707f8)
- RtlInitializeSid (Address: 0x4c370894)
- RtlInitializeSRWLock (Address: 0x4c3709a0)
- RtlInitUnicodeString (Address: 0x4c370a4c)
- RtlInitUnicodeStringEx (Address: 0x4c37086c)
- RtlInsertElementGenericTable (Address: 0x4c3707f0)
- RtlInsertElementGenericTableAvl (Address: 0x4c370974)
- RtlIntegerToUnicodeString (Address: 0x4c370808)
- RtlIsGenericTableEmpty (Address: 0x4c370794)
- RtlIsTextUnicode (Address: 0x4c370880)
- RtlIsValidIndexHandle (Address: 0x4c3709ec)
- RtlLeaveCriticalSection (Address: 0x4c370a30)
- RtlLengthSecurityDescriptor (Address: 0x4c3709d8)
- RtlLengthSid (Address: 0x4c370770)
- RtlLookupElementGenericTable (Address: 0x4c370820)
- RtlLookupElementGenericTableAvl (Address: 0x4c370980)
- RtlMakeSelfRelativeSD (Address: 0x4c370a08)
- RtlMultiByteToUnicodeN (Address: 0x4c37085c)
- RtlNtStatusToDosError (Address: 0x4c370a3c)
- RtlNtStatusToDosErrorNoTeb (Address: 0x4c370850)
- RtlNumberGenericTableElements (Address: 0x4c370824)
- RtlOemStringToUnicodeString (Address: 0x4c37087c)
- RtlOpenCurrentUser (Address: 0x4c3709c4)
- RtlPrefixUnicodeString (Address: 0x4c37083c)
- RtlQueryPackageIdentity (Address: 0x4c370878)
- RtlQueryPerformanceCounter (Address: 0x4c370968)
- RtlQueryProcessDebugInformation (Address: 0x4c3709ac)
- RtlQueryRegistryValuesEx (Address: 0x4c37081c)
- RtlReleaseRelativeName (Address: 0x4c37099c)
- RtlReleaseSRWLockExclusive (Address: 0x4c370978)
- RtlReleaseSRWLockShared (Address: 0x4c370984)
- RtlRunOnceBeginInitialize (Address: 0x4c370924)
- RtlRunOnceExecuteOnce (Address: 0x4c370920)
- RtlRunOnceInitialize (Address: 0x4c370928)
- RtlSetDaclSecurityDescriptor (Address: 0x4c3708a0)
- RtlSetGroupSecurityDescriptor (Address: 0x4c3708d0)
- RtlSetLastWin32Error (Address: 0x4c370864)
- RtlSetOwnerSecurityDescriptor (Address: 0x4c370780)
- RtlSetSaclSecurityDescriptor (Address: 0x4c370890)
- RtlStringFromGUID (Address: 0x4c37080c)
- RtlSubAuthorityCountSid (Address: 0x4c3709fc)
- RtlSubAuthoritySid (Address: 0x4c370a00)
- RtlTimeToSecondsSince1970 (Address: 0x4c3708f4)
- RtlUnicodeStringToAnsiString (Address: 0x4c370a44)
- RtlUnicodeStringToInteger (Address: 0x4c3709f4)
- RtlUnicodeToMultiByteN (Address: 0x4c37084c)
- RtlUnicodeToMultiByteSize (Address: 0x4c370854)
- RtlUpcaseUnicodeChar (Address: 0x4c37082c)
- RtlValidAcl (Address: 0x4c37088c)
- RtlValidRelativeSecurityDescriptor (Address: 0x4c370950)
- RtlValidSecurityDescriptor (Address: 0x4c3709dc)
- RtlValidSid (Address: 0x4c3707bc)
- RtlWaitOnAddress (Address: 0x4c370960)
- RtlWakeAddressAll (Address: 0x4c370964)
- RtlWakeAddressSingle (Address: 0x4c370994)
- RtlxAnsiStringToUnicodeSize (Address: 0x4c3708b0)
- RtlxUnicodeStringToAnsiSize (Address: 0x4c370a10)
RPCRT4.dll
- I_RpcExceptionFilter (Address: 0x4c370228)
- I_RpcMapWin32Status (Address: 0x4c37022c)
- I_RpcSNCHOption (Address: 0x4c370220)
- NdrClientCall4 (Address: 0x4c370200)
- RpcBindingBind (Address: 0x4c3701e8)
- RpcBindingCreateW (Address: 0x4c3701ec)
- RpcBindingFree (Address: 0x4c3701fc)
- RpcBindingFromStringBindingW (Address: 0x4c370214)
- RpcBindingSetAuthInfoA (Address: 0x4c37021c)
- RpcBindingSetAuthInfoExW (Address: 0x4c3701f4)
- RpcBindingSetAuthInfoW (Address: 0x4c370230)
- RpcEpResolveBinding (Address: 0x4c370224)
- RpcExceptionFilter (Address: 0x4c370204)
- RpcRaiseException (Address: 0x4c370210)
- RpcSsDestroyClientContext (Address: 0x4c3701f0)
- RpcStringBindingComposeW (Address: 0x4c370218)
- RpcStringFreeW (Address: 0x4c3701f8)
- UuidFromStringW (Address: 0x4c37020c)
- UuidToStringW (Address: 0x4c370208)
SECHOST.dll
- ControlTraceA (Address: 0x4c37023c)
- QueryAllTracesA (Address: 0x4c370238)
- StartTraceA (Address: 0x4c370240)