<<Click here to return to the search engine

Index


Windows


Found follow exports in KERNEL32.DL
AddAtomA AddAtomW AllocConsole AreFileApisANSI BackupRead BackupSeek BackupWrite Beep BeginUpdateResourceA BeginUpdateResourceW BuildCommDCBA BuildCommDCBAndTimeoutsA BuildCommDCBAndTimeoutsW BuildCommDCBW CallNamedPipeA CallNamedPipeW ClearCommBreak ClearCommError CloseHandle CloseProfileUserMapping CommConfigDialogA CommConfigDialogW CompareFileTime CompareStringA CompareStringW ConnectNamedPipe ContinueDebugEvent ConvertDefaultLocale CopyFileA CopyFileW CreateConsoleScreenBuffer CreateDirectoryA CreateDirectoryExA CreateDirectoryExW CreateDirectoryW CreateEventA CreateEventW CreateFileA CreateFileMappingA CreateFileMappingW CreateFileW CreateIoCompletionPort CreateMailslotA CreateMailslotW CreateMutexA CreateMutexW CreateNamedPipeA CreateNamedPipeW CreatePipe CreateProcessA CreateProcessW CreateRemoteThread CreateSemaphoreA CreateSemaphoreW CreateTapePartition CreateThread DebugActiveProcess DebugBreak DefineDosDeviceA DefineDosDeviceW DeleteAtom DeleteCriticalSection DeleteFileA DeleteFileW DeviceIoControl DisableThreadLibraryCalls DisconnectNamedPipe DosDateTimeToFileTime DuplicateHandle EndUpdateResourceA EndUpdateResourceW EnterCriticalSection EnumCalendarInfoA EnumCalendarInfoW EnumDateFormatsA EnumDateFormatsW EnumResourceLanguagesA EnumResourceLanguagesW EnumResourceNamesA EnumResourceNamesW EnumResourceTypesA EnumResourceTypesW EnumSystemCodePagesA EnumSystemCodePagesW EnumSystemLocalesA EnumSystemLocalesW EnumTimeFormatsA EnumTimeFormatsW EraseTape EscapeCommFunction ExitProcess ExitThread ExpandEnvironmentStringsA ExpandEnvironmentStringsW FatalAppExitA FatalAppExitW FatalExit FileTimeToDosDateTime FileTimeToLocalFileTime FileTimeToSystemTime FillConsoleOutputAttribute FillConsoleOutputCharacterA FillConsoleOutputCharacterW FindAtomA FindAtomW FindClose FindCloseChangeNotification FindFirstChangeNotificationA FindFirstChangeNotificationW FindFirstFileA FindFirstFileW FindNextChangeNotification FindNextFileA FindNextFileW FindResourceA FindResourceExA FindResourceExW FindResourceW FlushConsoleInputBuffer FlushFileBuffers FlushInstructionCache FlushViewOfFile FoldStringA FoldStringW FormatMessageA FormatMessageW FreeConsole FreeEnvironmentStringsA FreeEnvironmentStringsW FreeLibrary FreeLibraryAndExitThread FreeResource GenerateConsoleCtrlEvent GetACP GetAtomNameA GetAtomNameW GetBinaryType GetBinaryTypeA GetBinaryTypeW GetCommandLineA GetCommandLineW GetCommConfig GetCommMask GetCommModemStatus GetCommProperties GetCommState GetCommTimeouts GetCompressedFileSizeA GetCompressedFileSizeW GetComputerNameA GetComputerNameW GetConsoleCP GetConsoleCursorInfo GetConsoleMode GetConsoleOutputCP GetConsoleScreenBufferInfo GetConsoleTitleA GetConsoleTitleW GetCPInfo GetCurrencyFormatA GetCurrencyFormatW GetCurrentDirectoryA GetCurrentDirectoryW GetCurrentProcess GetCurrentProcessId GetCurrentThread GetCurrentThreadId GetDateFormatA GetDateFormatW GetDefaultCommConfigA GetDefaultCommConfigW GetDiskFreeSpaceA GetDiskFreeSpaceExA GetDiskFreeSpaceExW GetDiskFreeSpaceW GetDriveTypeA GetDriveTypeW GetEnvironmentStrings GetEnvironmentStringsA GetEnvironmentStringsW GetEnvironmentVariableA GetEnvironmentVariableW GetExitCodeProcess GetExitCodeThread GetFileAttributesA GetFileAttributesW GetFileInformationByHandle GetFileSize GetFileTime GetFileType GetFullPathNameA GetFullPathNameW GetHandleInformation GetLargestConsoleWindowSize GetLastError GetLocaleInfoA GetLocaleInfoW GetLocalTime GetLogicalDrives GetLogicalDriveStringsA GetLogicalDriveStringsW GetMailslotInfo GetModuleFileNameA GetModuleFileNameW GetModuleHandleA GetModuleHandleW GetNamedPipeHandleStateA GetNamedPipeHandleStateW GetNamedPipeInfo GetNumberFormatA GetNumberFormatW GetNumberOfConsoleInputEvents GetNumberOfConsoleMouseButtons GetOEMCP GetOverlappedResult GetPriorityClass GetPrivateProfileIntA GetPrivateProfileIntW GetPrivateProfileSectionA GetPrivateProfileSectionNamesA GetPrivateProfileSectionNamesW GetPrivateProfileSectionW GetPrivateProfileStringA GetPrivateProfileStringW GetPrivateProfileStructA GetPrivateProfileStructW GetProcAddress GetProcessAffinityMask GetProcessHeap GetProcessHeaps GetProcessShutdownParameters GetProcessTimes GetProcessVersion GetProcessWorkingSetSize GetProfileIntA GetProfileIntW GetProfileSectionA GetProfileSectionW GetProfileStringA GetProfileStringW GetQueuedCompletionStatus GetShortPathNameA GetShortPathNameW GetStartupInfoA GetStartupInfoW GetStdHandle GetStringTypeA GetStringTypeExA GetStringTypeExW GetStringTypeW GetSystemDefaultLangID GetSystemDefaultLCID GetSystemDirectoryA GetSystemDirectoryW GetSystemInfo GetSystemPowerStatus GetSystemTime GetSystemTimeAdjustment GetSystemTimeAsFileTime GetTapeParameters GetTapePosition GetTapeStatus GetTempFileNameA GetTempFileNameW GetTempPathA GetTempPathW GetThreadContext GetThreadLocale GetThreadPriority GetThreadSelectorEntry GetThreadTimes GetTickCount GetTimeFormatA GetTimeFormatW GetTimeZoneInformation GetUserDefaultLangID GetUserDefaultLCID GetVersion GetVersionExA GetVersionExW GetVolumeInformationA GetVolumeInformationW GetWindowsDirectoryA GetWindowsDirectoryW GlobalAddAtomA GlobalAddAtomW GlobalAlloc GlobalCompact GlobalDeleteAtom GlobalFindAtomA GlobalFindAtomW GlobalFix GlobalFlags GlobalFree GlobalGetAtomNameA GlobalGetAtomNameW GlobalHandle GlobalLock GlobalMemoryStatus GlobalReAlloc GlobalSize GlobalUnfix GlobalUnlock GlobalUnWire GlobalWire HeapAlloc HeapCompact HeapCreate HeapDestroy HeapFree HeapLock HeapReAlloc HeapSize HeapUnlock HeapValidate HeapWalk _hread _hwrite InitAtomTable InitializeCriticalSection InterlockedDecrement InterlockedExchange InterlockedIncrement IsBadCodePtr IsBadHugeReadPtr IsBadHugeWritePtr IsBadReadPtr IsBadStringPtrA IsBadStringPtrW IsBadWritePtr IsDBCSLeadByte IsDBCSLeadByteEx IsValidCodePage IsValidLocale _lclose LCMapStringA LCMapStringW _lcreat LeaveCriticalSection _llseek LoadLibraryA LoadLibraryExA LoadLibraryExW LoadLibraryW LoadModule LoadResource LocalAlloc LocalCompact LocalFileTimeToFileTime LocalFlags LocalFree LocalHandle LocalLock LocalReAlloc LocalShrink LocalSize LocalUnlock LockFile LockFileEx LockResource _lopen _lread lstrcat lstrcatA lstrcatW lstrcmp lstrcmpA lstrcmpi lstrcmpiA lstrcmpiW lstrcmpW lstrcpy lstrcpyA lstrcpyn lstrcpynA lstrcpynW lstrcpyW lstrlen lstrlenA lstrlenW _lwrite MapViewOfFile MapViewOfFileEx MoveFileA MoveFileExA MoveFileExW MoveFileW MulDiv MultiByteToWideChar OpenEventA OpenEventW OpenFile OpenFileMappingA OpenFileMappingW OpenMutexA OpenMutexW OpenProcess OpenProfileUserMapping OpenSemaphoreA OpenSemaphoreW OutputDebugStringA OutputDebugStringW PeekConsoleInputA PeekConsoleInputW PeekNamedPipe PostQueuedCompletionStatus PrepareTape PulseEvent PurgeComm QueryDosDeviceA QueryDosDeviceW QueryPerformanceCounter QueryPerformanceFrequency QueueUserAPC RaiseException ReadConsoleA ReadConsoleInputA ReadConsoleInputW ReadConsoleOutputA ReadConsoleOutputAttribute ReadConsoleOutputCharacterA ReadConsoleOutputCharacterW ReadConsoleOutputW ReadConsoleW ReadFile ReadFileEx ReadProcessMemory ReleaseMutex ReleaseSemaphore RemoveDirectoryA RemoveDirectoryW ResetEvent ResumeThread RtlFillMemory RtlMoveMemory RtlUnwind RtlZeroMemory ScrollConsoleScreenBufferA ScrollConsoleScreenBufferW SearchPathA SearchPathW SetCommBreak SetCommConfig SetCommMask SetCommState SetCommTimeouts SetComputerNameA SetComputerNameW SetConsoleActiveScreenBuffer SetConsoleCP SetConsoleCtrlHandler SetConsoleCursorInfo SetConsoleCursorPosition SetConsoleMode SetConsoleOutputCP SetConsoleScreenBufferSize SetConsoleTextAttribute SetConsoleTitleA SetConsoleTitleW SetConsoleWindowInfo SetCurrentDirectoryA SetCurrentDirectoryW SetDefaultCommConfigA SetDefaultCommConfigW SetEndOfFile SetEnvironmentVariableA SetEnvironmentVariableW SetErrorMode SetEvent SetFileApisToANSI SetFileApisToOEM SetFileAttributesA SetFileAttributesW SetFilePointer SetFileTime SetHandleCount SetHandleInformation SetLastError SetLocaleInfoA SetLocaleInfoW SetLocalTime SetMailslotInfo SetNamedPipeHandleState SetPriorityClass SetProcessShutdownParameters SetProcessWorkingSetSize SetStdHandle SetSystemPowerState SetSystemTime SetSystemTimeAdjustment SetTapeParameters SetTapePosition SetThreadAffinityMask SetThreadContext SetThreadLocale SetThreadPriority SetTimeZoneInformation SetUnhandledExceptionFilter SetupComm SetVolumeLabelA SetVolumeLabelW SizeofResource Sleep SleepEx SuspendThread SystemTimeToFileTime SystemTimeToTzSpecificLocalTime TerminateProcess TerminateThread TlsAlloc TlsFree TlsGetValue TlsSetValue TransactNamedPipe TransmitCommChar UnhandledExceptionFilter UnlockFile UnlockFileEx UnmapViewOfFile UpdateResourceA UpdateResourceW VerLanguageNameA VerLanguageNameW VirtualAlloc VirtualFree VirtualLock VirtualProtect VirtualProtectEx VirtualQuery VirtualQueryEx VirtualUnlock WaitCommEvent WaitForDebugEvent WaitForMultipleObjects WaitForMultipleObjectsEx WaitForSingleObject WaitForSingleObjectEx WaitNamedPipeA WaitNamedPipeW WideCharToMultiByte WinExec WriteConsoleA WriteConsoleInputA WriteConsoleInputW WriteConsoleOutputA WriteConsoleOutputAttribute WriteConsoleOutputCharacterA WriteConsoleOutputCharacterW WriteConsoleOutputW WriteConsoleW WriteFile WriteFileEx WritePrivateProfileSectionA WritePrivateProfileSectionW WritePrivateProfileStringA WritePrivateProfileStringW WritePrivateProfileStructA WritePrivateProfileStructW WriteProcessMemory WriteProfileSectionA WriteProfileSectionW WriteProfileStringA WriteProfileStringW WriteTapemark

Found follow exports in NTDLL.DL
DbgBreakPoint DbgPrint DbgPrompt NtCurrentTeb NtQueryPerformanceCounter RtlAllocateHeap RtlAnsiStringToUnicodeString RtlConvertLongToLargeInteger RtlConvertUlongToLargeInteger RtlCreateHeap RtlDestroyHeap RtlEnlargedIntegerMultiply RtlEnlargedUnsignedDivide RtlEnlargedUnsignedMultiply RtlExtendedIntegerMultiply RtlExtendedLargeIntegerDivide RtlExtendedMagicDivide RtlFreeHeap RtlImageNtHeader RtlLargeIntegerAdd RtlLargeIntegerArithmeticShift RtlLargeIntegerDivide RtlLargeIntegerNegate RtlLargeIntegerShiftLeft RtlLargeIntegerShiftRight RtlLargeIntegerSubtract RtlMultiByteToUnicodeN RtlReAllocateHeap RtlSizeHeap RtlUnicodeStringToAnsiString RtlUnicodeToMultiByteN RtlUnwind RtlValidateHeap

Found follow exports in USER32.DL
ActivateKeyboardLayout AdjustWindowRect AdjustWindowRectEx AnyPopup AppendMenuA AppendMenuW ArrangeIconicWindows AttachThreadInput BeginDeferWindowPos BeginPaint BringWindowToTop BroadcastSystemMessage CallMsgFilter CallMsgFilterA CallMsgFilterW CallNextHookEx CallWindowProcA CallWindowProcW CascadeChildWindows CascadeWindows ChangeClipboardChain ChangeDisplaySettingsA ChangeDisplaySettingsW ChangeMenuA ChangeMenuW CharLowerA CharLowerBuffA CharLowerBuffW CharLowerW CharNextA CharNextExA CharNextW CharPrevA CharPrevExA CharPrevW CharToOemA CharToOemBuffA CharToOemBuffW CharToOemW CharUpperA CharUpperBuffA CharUpperBuffW CharUpperW CheckDlgButton CheckMenuItem CheckMenuRadioItem CheckRadioButton ChildWindowFromPoint ChildWindowFromPointEx ClientToScreen ClipCursor CloseClipboard CloseDesktop CloseWindow CloseWindowStation CopyAcceleratorTableA CopyAcceleratorTableW CopyIcon CopyImage CopyRect CountClipboardFormats CreateAcceleratorTableA CreateAcceleratorTableW CreateCaret CreateCursor CreateDesktopA CreateDesktopW CreateDialogIndirectParamA CreateDialogIndirectParamW CreateDialogParamA CreateDialogParamW CreateIcon CreateIconFromResource CreateIconFromResourceEx CreateIconIndirect CreateMDIWindowA CreateMDIWindowW CreateMenu CreatePopupMenu CreateWindowExA CreateWindowExW CreateWindowStationA CreateWindowStationW DdeAbandonTransaction DdeAccessData DdeAddData DdeClientTransaction DdeCmpStringHandles DdeConnect DdeConnectList DdeCreateDataHandle DdeCreateStringHandleA DdeCreateStringHandleW DdeDisconnect DdeDisconnectList DdeEnableCallback DdeFreeDataHandle DdeFreeStringHandle DdeGetData DdeGetLastError DdeImpersonateClient DdeInitializeA DdeInitializeW DdeKeepStringHandle DdeNameService DdePostAdvise DdeQueryConvInfo DdeQueryNextServer DdeQueryStringA DdeQueryStringW DdeReconnect DdeSetQualityOfService DdeSetUserHandle DdeUnaccessData DdeUninitialize DefDlgProcA DefDlgProcW DeferWindowPos DefFrameProcA DefFrameProcW DefMDIChildProcA DefMDIChildProcW DefWindowProcA DefWindowProcW DeleteMenu DestroyAcceleratorTable DestroyCaret DestroyCursor DestroyIcon DestroyMenu DestroyWindow DialogBoxIndirectParamA DialogBoxIndirectParamW DialogBoxParamA DialogBoxParamW DispatchMessageA DispatchMessageW DlgDirListA DlgDirListComboBoxA DlgDirListComboBoxW DlgDirListW DlgDirSelectComboBoxExA DlgDirSelectComboBoxExW DlgDirSelectExA DlgDirSelectExW DragDetect DragObject DrawAnimatedRects DrawCaption DrawCaptionTempA DrawCaptionTempW DrawEdge DrawFocusRect DrawFrame DrawFrameControl DrawIcon DrawIconEx DrawMenuBar DrawStateA DrawStateW DrawTextA DrawTextExA DrawTextExW DrawTextW EditWndProc EmptyClipboard EnableMenuItem EnableScrollBar EnableWindow EndDeferWindowPos EndDialog EndPaint EndTask EnumChildWindows EnumClipboardFormats EnumDesktopsA EnumDesktopsW EnumDesktopWindows EnumDisplaySettingsA EnumDisplaySettingsW EnumPropsA EnumPropsExA EnumPropsExW EnumPropsW EnumThreadWindows EnumWindows EnumWindowStationsA EnumWindowStationsW EqualRect ExcludeUpdateRgn ExitWindowsEx FillRect FindWindowA FindWindowExA FindWindowExW FindWindowW FlashWindow FrameRect FreeDDElParam GetActiveWindow GetAsyncKeyState GetCapture GetCaretBlinkTime GetCaretPos GetClassInfoA GetClassInfoExA GetClassInfoExW GetClassInfoW GetClassLongA GetClassLongW GetClassNameA GetClassNameW GetClassWord GetClientRect GetClipboardData GetClipboardFormatNameA GetClipboardFormatNameW GetClipboardOwner GetClipboardViewer GetClipCursor GetCursor GetCursorPos GetDC GetDCEx GetDesktopWindow GetDialogBaseUnits GetDlgCtrlID GetDlgItem GetDlgItemInt GetDlgItemTextA GetDlgItemTextW GetDoubleClickTime GetFocus GetForegroundWindow GetIconInfo GetInputDesktop GetInputState GetInternalWindowPos GetKBCodePage GetKeyboardLayout GetKeyboardLayoutList GetKeyboardLayoutNameA GetKeyboardLayoutNameW GetKeyboardState GetKeyboardType GetKeyNameTextA GetKeyNameTextW GetKeyState GetLastActivePopup GetMenu GetMenuCheckMarkDimensions GetMenuContextHelpId GetMenuDefaultItem GetMenuItemCount GetMenuItemID GetMenuItemInfoA GetMenuItemInfoW GetMenuItemRect GetMenuState GetMenuStringA GetMenuStringW GetMessageA GetMessageExtraInfo GetMessagePos GetMessageTime GetMessageW GetNextDlgGroupItem GetNextDlgTabItem GetOpenClipboardWindow GetParent GetPriorityClipboardFormat GetProcessWindowStation GetPropA GetPropW GetQueueStatus GetScrollInfo GetScrollPos GetScrollRange GetShellWindow GetSubMenu GetSysColor GetSysColorBrush GetSystemMenu GetSystemMetrics GetTabbedTextExtentA GetTabbedTextExtentW GetThreadDesktop GetTopWindow GetUpdateRect GetUpdateRgn GetUserObjectInformationA GetUserObjectInformationW GetUserObjectSecurity GetWindow GetWindowContextHelpId GetWindowDC GetWindowLongA GetWindowLongW GetWindowPlacement GetWindowRect GetWindowRgn GetWindowTextA GetWindowTextLengthA GetWindowTextLengthW GetWindowTextW GetWindowThreadProcessId GetWindowWord GrayStringA GrayStringW HideCaret HiliteMenuItem ImpersonateDdeClientWindow InflateRect InSendMessage InsertMenuA InsertMenuItemA InsertMenuItemW InsertMenuW InternalGetWindowText IntersectRect InvalidateRect InvalidateRgn InvertRect IsCharAlphaA IsCharAlphaNumericA IsCharAlphaNumericW IsCharAlphaW IsCharLowerA IsCharLowerW IsCharUpperA IsCharUpperW IsChild IsClipboardFormatAvailable IsDialogMessage IsDialogMessageA IsDialogMessageW IsDlgButtonChecked IsIconic IsMenu IsRectEmpty IsWindow IsWindowEnabled IsWindowUnicode IsWindowVisible IsZoomed keybd_event KillTimer LoadAcceleratorsA LoadAcceleratorsW LoadBitmapA LoadBitmapW LoadCursorA LoadCursorFromFileA LoadCursorFromFileW LoadCursorW LoadIconA LoadIconW LoadImageA LoadImageW LoadKeyboardLayoutA LoadKeyboardLayoutW LoadMenuA LoadMenuIndirectA LoadMenuIndirectW LoadMenuW LoadStringA LoadStringW LockWindowStation LockWindowUpdate LookupIconIdFromDirectory LookupIconIdFromDirectoryEx MapDialogRect MapVirtualKeyA MapVirtualKeyExA MapVirtualKeyExW MapVirtualKeyW MapWindowPoints MenuItemFromPoint MessageBeep MessageBoxA MessageBoxExA MessageBoxExW MessageBoxIndirectA MessageBoxIndirectW MessageBoxW ModifyMenuA ModifyMenuW mouse_event MoveWindow MsgWaitForMultipleObjects OemKeyScan OemToCharA OemToCharBuffA OemToCharBuffW OemToCharW OffsetRect OpenClipboard OpenDesktopA OpenDesktopW OpenIcon OpenInputDesktop OpenWindowStationA OpenWindowStationW PackDDElParam PaintDesktop PeekMessageA PeekMessageW PostMessageA PostMessageW PostQuitMessage PostThreadMessageA PostThreadMessageW PtInRect RedrawWindow RegisterClassA RegisterClassExA RegisterClassExW RegisterClassW RegisterClipboardFormatA RegisterClipboardFormatW RegisterHotKey RegisterLogonProcess RegisterSystemThread RegisterTasklist RegisterWindowMessageA RegisterWindowMessageW ReleaseCapture ReleaseDC RemoveMenu RemovePropA RemovePropW ReplyMessage ReuseDDElParam ScreenToClient ScrollDC ScrollWindow ScrollWindowEx SendDlgItemMessageA SendDlgItemMessageW SendMessageA SendMessageCallbackA SendMessageCallbackW SendMessageTimeoutA SendMessageTimeoutW SendMessageW SendNotifyMessageA SendNotifyMessageW SetActiveWindow SetCapture SetCaretBlinkTime SetCaretPos SetClassLongA SetClassLongW SetClassWord SetClipboardData SetClipboardViewer SetCursor SetCursorPos SetDebugErrorLevel SetDeskWallpaper SetDlgItemInt SetDlgItemTextA SetDlgItemTextW SetDoubleClickTime SetFocus SetForegroundWindow SetInternalWindowPos SetKeyboardState SetLastErrorEx SetMenu SetMenuContextHelpId SetMenuDefaultItem SetMenuItemBitmaps SetMenuItemInfoA SetMenuItemInfoW SetMessageExtraInfo SetMessageQueue SetParent SetProcessWindowStation SetPropA SetPropW SetRect SetRectEmpty SetScrollInfo SetScrollPos SetScrollRange SetShellWindow SetSysColors SetSysColorsTemp SetSystemCursor SetThreadDesktop SetTimer SetUserObjectInformationA SetUserObjectInformationW SetUserObjectSecurity SetWindowContextHelpId SetWindowLongA SetWindowLongW SetWindowPlacement SetWindowPos SetWindowRgn SetWindowsHookA SetWindowsHookExA SetWindowsHookExW SetWindowsHookW SetWindowTextA SetWindowTextW SetWindowWord ShowCaret ShowCursor ShowOwnedPopups ShowScrollBar ShowWindow ShowWindowAsync SubtractRect SwapMouseButton SwitchDesktop SwitchToThisWindow SystemParametersInfoA SystemParametersInfoW TabbedTextOutA TabbedTextOutW TileChildWindows TileWindows ToAscii ToAsciiEx ToUnicode TrackPopupMenu TrackPopupMenuEx TranslateAccelerator TranslateAcceleratorA TranslateAcceleratorW TranslateMDISysAccel TranslateMessage UnhookWindowsHook UnhookWindowsHookEx UnionRect UnloadKeyboardLayout UnlockWindowStation UnpackDDElParam UnregisterClassA UnregisterClassW UnregisterHotKey UpdateWindow UserClientDllInitialize ValidateRect ValidateRgn VkKeyScanA VkKeyScanExA VkKeyScanExW VkKeyScanW WaitForInputIdle WaitMessage WindowFromDC WindowFromPoint WinHelpA WinHelpW wsprintfA wsprintfW wvsprintfA wvsprintfW

Found follow exports in GDI32.DL
AbortDoc AbortPath AddFontResourceA AddFontResourceW AngleArc AnimatePalette Arc ArcTo BeginPath BitBlt CancelDC CheckColorsInGamut ChoosePixelFormat Chord CloseEnhMetaFile CloseFigure CloseMetaFile ColorMatchToTarget CombineRgn CombineTransform CopyEnhMetaFileA CopyEnhMetaFileW CopyMetaFileA CopyMetaFileW CreateBitmap CreateBitmapIndirect CreateBrushIndirect CreateColorSpaceA CreateColorSpaceW CreateCompatibleBitmap CreateCompatibleDC CreateDCA CreateDCW CreateDIBitmap CreateDIBPatternBrush CreateDIBPatternBrushPt CreateDIBSection CreateDiscardableBitmap CreateEllipticRgn CreateEllipticRgnIndirect CreateEnhMetaFileA CreateEnhMetaFileW CreateFontA CreateFontIndirectA CreateFontIndirectW CreateFontW CreateHalftonePalette CreateHatchBrush CreateICA CreateICW CreateMetaFileA CreateMetaFileW CreatePalette CreatePatternBrush CreatePen CreatePenIndirect CreatePolygonRgn CreatePolyPolygonRgn CreateRectRgn CreateRectRgnIndirect CreateRoundRectRgn CreateScalableFontResourceA CreateScalableFontResourceW CreateSolidBrush DeleteColorSpace DeleteDC DeleteEnhMetaFile DeleteMetaFile DeleteObject DescribePixelFormat DeviceCapabilitiesExA DeviceCapabilitiesExW DPtoLP DrawEscape Ellipse EndDoc EndPage EndPath EnumEnhMetaFile EnumFontFamiliesA EnumFontFamiliesExA EnumFontFamiliesExW EnumFontFamiliesW EnumFontsA EnumFontsW EnumICMProfilesA EnumICMProfilesW EnumMetaFile EnumObjects EqualRgn Escape ExcludeClipRect ExtCreatePen ExtCreateRegion ExtEscape ExtFloodFill ExtSelectClipRgn ExtTextOutA ExtTextOutW FillPath FillRgn FixBrushOrgEx FlattenPath FloodFill FrameRgn GdiComment GdiFlush GdiGetBatchLimit GdiPlayDCScript GdiPlayJournal GdiPlayScript gdiPlaySpoolStream GdiSetBatchLimit GetArcDirection GetAspectRatioFilterEx GetBitmapBits GetBitmapDimensionEx GetBkColor GetBkMode GetBoundsRect GetBrushOrgEx GetCharABCWidthsA GetCharABCWidthsFloatA GetCharABCWidthsFloatW GetCharABCWidthsW GetCharacterPlacementA GetCharacterPlacementW GetCharWidth32A GetCharWidth32W GetCharWidthA GetCharWidthFloatA GetCharWidthFloatW GetCharWidthW GetClipBox GetClipRgn GetColorAdjustment GetColorSpace GetCurrentObject GetCurrentPositionEx GetDCOrgEx GetDeviceCaps GetDeviceGammaRamp GetDIBColorTable GetDIBits GetEnhMetaFileA GetEnhMetaFileBits GetEnhMetaFileDescriptionA GetEnhMetaFileDescriptionW GetEnhMetaFileHeader GetEnhMetaFilePaletteEntries GetEnhMetaFileW GetFontData GetFontLanguageInfo GetGlyphOutline GetGlyphOutlineA GetGlyphOutlineW GetGraphicsMode GetICMProfileA GetICMProfileW GetKerningPairs GetKerningPairsA GetKerningPairsW GetLogColorSpaceA GetLogColorSpaceW GetMapMode GetMetaFileA GetMetaFileBitsEx GetMetaFileW GetMetaRgn GetMiterLimit GetNearestColor GetNearestPaletteIndex GetObjectA GetObjectType GetObjectW GetOutlineTextMetricsA GetOutlineTextMetricsW GetPaletteEntries GetPath GetPixel GetPixelFormat GetPolyFillMode GetRandomRgn GetRasterizerCaps GetRegionData GetRgnBox GetROP2 GetStockObject GetStretchBltMode GetSystemPaletteEntries GetSystemPaletteUse GetTextAlign GetTextCharacterExtra GetTextCharset GetTextCharsetInfo GetTextColor GetTextExtentExPointA GetTextExtentExPointW GetTextExtentPoint32A GetTextExtentPoint32W GetTextExtentPointA GetTextExtentPointW GetTextFaceA GetTextFaceW GetTextMetricsA GetTextMetricsW GetViewportExtEx GetViewportOrgEx GetWindowExtEx GetWindowOrgEx GetWinMetaFileBits GetWorldTransform IntersectClipRect InvertRgn LineDDA LineTo LPtoDP MaskBlt ModifyWorldTransform MoveToEx OffsetClipRgn OffsetRgn OffsetViewportOrgEx OffsetWindowOrgEx PaintRgn PatBlt PathToRegion Pie PlayEnhMetaFile PlayEnhMetaFileRecord PlayMetaFile PlayMetaFileRecord PlgBlt PolyBezier PolyBezierTo PolyDraw Polygon Polyline PolylineTo PolyPolygon PolyPolyline PolyTextOutA PolyTextOutW PtInRegion PtVisible RealizePalette Rectangle RectInRegion RectVisible RemoveFontResourceA RemoveFontResourceW ResetDCA ResetDCW ResizePalette RestoreDC RoundRect SaveDC ScaleViewportExtEx ScaleWindowExtEx SelectClipPath SelectClipRgn SelectObject SelectPalette SetAbortProc SetArcDirection SetBitmapBits SetBitmapDimensionEx SetBkColor SetBkMode SetBoundsRect SetBrushOrgEx SetColorAdjustment SetColorSpace SetDeviceGammaRamp SetDIBColorTable SetDIBits SetDIBitsToDevice SetEnhMetaFileBits SetFontEnumeration SetGraphicsMode SetICMMode SetICMProfileA SetICMProfileW SetMapMode SetMapperFlags SetMetaFileBitsEx SetMetaRgn SetMiterLimit SetPaletteEntries SetPixel SetPixelFormat SetPixelV SetPolyFillMode SetRectRgn SetROP2 SetStretchBltMode SetSystemPaletteUse SetTextAlign SetTextCharacterExtra SetTextColor SetTextJustification SetViewportExtEx SetViewportOrgEx SetWindowExtEx SetWindowOrgEx SetWinMetaFileBits SetWorldTransform StartDocA StartDocW StartPage StretchBlt StretchDIBits StrokeAndFillPath StrokePath SwapBuffers TextOutA TextOutW TranslateCharsetInfo UnrealizeObject UpdateColors UpdateICMRegKeyA UpdateICMRegKeyW WidenPath

Found follow exports in SHELL32.DL
CheckEscapesW CommandLineToArgvW Control_RunDLL DllGetClassObject DoEnvironmentSubstA DoEnvironmentSubstW DragAcceptFiles DragFinish DragQueryFile DragQueryFileA DragQueryFileAorW DragQueryFileW DragQueryPoint DuplicateIcon ExtractAssociatedIconA ExtractAssociatedIconExA ExtractAssociatedIconExW ExtractAssociatedIconW ExtractIconA ExtractIconEx ExtractIconExA ExtractIconW FindExecutableA FindExecutableW FreeIconList InternalExtractIconListA InternalExtractIconListW OpenAs_RunDLL PrintersGetCommand_RunDLL RealShellExecuteA RealShellExecuteExA RealShellExecuteExW RealShellExecuteW RegenerateUserEnvironment SHAddToRecentDocs SHAppBarMessage SHBrowseForFolder SHBrowseForFolderA SHChangeNotify SheChangeDirA SheChangeDirExW SheGetDirA Shell_NotifyIcon Shell_NotifyIconA ShellAboutA ShellAboutW ShellExecuteA ShellExecuteEx ShellExecuteExA ShellExecuteW SheSetCurDrive SHFileOperation SHFileOperationA SHFormatDrive SHFreeNameMappings SHGetDataFromIDListA SHGetDesktopFolder SHGetFileInfo SHGetFileInfoA SHGetInstanceExplorer SHGetMalloc SHGetPathFromIDList SHGetPathFromIDListA SHGetSpecialFolderLocation SHHelpShortcuts_RunDLL SHLoadInProc

Found follow exports in COMDLG32.DL
ChooseColorA ChooseColorW ChooseFontA ChooseFontW CommDlgExtendedError FindTextA FindTextW GetFileTitleA GetFileTitleW GetOpenFileNameA GetOpenFileNameW GetSaveFileNameA GetSaveFileNameW PageSetupDlgA PageSetupDlgW PrintDlgA PrintDlgW ReplaceTextA ReplaceTextW

Found follow exports in COMCTL32.DL
CreateMappedBitmap CreatePropertySheetPage CreatePropertySheetPageA CreatePropertySheetPageW CreateStatusWindow CreateStatusWindowA CreateStatusWindowW CreateToolbar CreateToolbarEx CreateUpDownControl DestroyPropertySheetPage DllGetVersion DrawInsert DrawStatusText DrawStatusTextA DrawStatusTextW FlatSB_EnableScrollBar FlatSB_GetScrollInfo FlatSB_GetScrollPos FlatSB_GetScrollProp FlatSB_GetScrollRange FlatSB_SetScrollInfo FlatSB_SetScrollPos FlatSB_SetScrollProp FlatSB_SetScrollRange FlatSB_ShowScrollBar GetEffectiveClientRect GetMUILanguage ImageList_Add ImageList_AddIcon ImageList_AddMasked ImageList_BeginDrag ImageList_Copy ImageList_Create ImageList_Destroy ImageList_DragEnter ImageList_DragLeave ImageList_DragMove ImageList_DragShowNolock ImageList_Draw ImageList_DrawEx ImageList_DrawIndirect ImageList_Duplicate ImageList_EndDrag ImageList_GetBkColor ImageList_GetDragImage ImageList_GetIcon ImageList_GetIconSize ImageList_GetImageCount ImageList_GetImageInfo ImageList_GetImageRect ImageList_LoadImage ImageList_LoadImageA ImageList_LoadImageW ImageList_Merge ImageList_Read ImageList_Remove ImageList_Replace ImageList_ReplaceIcon ImageList_SetBkColor ImageList_SetDragCursorImage ImageList_SetFilter ImageList_SetFlags ImageList_SetIconSize ImageList_SetImageCount ImageList_SetOverlayImage ImageList_Write InitCommonControls InitCommonControlsEx InitializeFlatSB InitMUILanguage LBItemFromPt MakeDragList MenuHelp PropertySheet PropertySheetA PropertySheetW ShowHideMenuCtl _TrackMouseEvent UninitializeFlatSB

Found follow exports in ADVAPI32.DL
AbortSystemShutdownA AbortSystemShutdownW AccessCheck AccessCheckAndAuditAlarmA AccessCheckAndAuditAlarmW AddAccessAllowedAce AddAccessDeniedAce AddAce AddAuditAccessAce AdjustTokenGroups AdjustTokenPrivileges AllocateAndInitializeSid AllocateLocallyUniqueId AreAllAccessesGranted AreAnyAccessesGranted BackupEventLogA BackupEventLogW ChangeServiceConfigA ChangeServiceConfigW ClearEventLogA ClearEventLogW CloseEventLog CloseServiceHandle ControlService CopySid CreatePrivateObjectSecurity CreateProcessAsUserA CreateProcessAsUserW CreateServiceA CreateServiceW CryptAcquireContextA CryptCreateHash CryptDecrypt CryptDeriveKey CryptDestroyHash CryptDestroyKey CryptEncrypt CryptExportKey CryptGenKey CryptGenRandom CryptGetHashParam CryptGetKeyParam CryptGetProvParam CryptGetUserKey CryptHashData CryptHashSessionKey CryptImportKey CryptReleaseContext CryptSetHashParam CryptSetKeyParam CryptSetProviderA CryptSetProvParam CryptSignHashA CryptVerifySignatureA DeleteAce DeleteService DeregisterEventSource DestroyPrivateObjectSecurity DuplicateToken EnumDependentServicesA EnumDependentServicesW EnumServicesStatusA EnumServicesStatusW EqualPrefixSid EqualSid FindFirstFreeAce FreeSid GetAce GetAclInformation GetFileSecurityA GetFileSecurityW GetKernelObjectSecurity GetLengthSid GetNumberOfEventLogRecords GetOldestEventLogRecord GetPrivateObjectSecurity GetSecurityDescriptorControl GetSecurityDescriptorDacl GetSecurityDescriptorGroup GetSecurityDescriptorLength GetSecurityDescriptorOwner GetSecurityDescriptorSacl GetServiceDisplayNameA GetServiceDisplayNameW GetServiceKeyNameA GetServiceKeyNameW GetSidIdentifierAuthority GetSidLengthRequired GetSidSubAuthority GetSidSubAuthorityCount GetTokenInformation GetUserNameA GetUserNameW ImpersonateLoggedOnUser ImpersonateNamedPipeClient ImpersonateSelf InitializeAcl InitializeSecurityDescriptor InitializeSid InitiateSystemShutdownA InitiateSystemShutdownW IsTextUnicode IsValidAcl IsValidSecurityDescriptor IsValidSid LockServiceDatabase LogonUserA LogonUserW LookupAccountNameA LookupAccountNameW LookupAccountSidA LookupAccountSidW LookupPrivilegeDisplayNameA LookupPrivilegeDisplayNameW LookupPrivilegeNameA LookupPrivilegeNameW LookupPrivilegeValueA LookupPrivilegeValueW MakeAbsoluteSD MakeSelfRelativeSD MapGenericMask NotifyBootConfigStatus NotifyChangeEventLog ObjectCloseAuditAlarmA ObjectCloseAuditAlarmW ObjectOpenAuditAlarmA ObjectOpenAuditAlarmW ObjectPrivilegeAuditAlarmA ObjectPrivilegeAuditAlarmW OpenBackupEventLogA OpenBackupEventLogW OpenEventLogA OpenEventLogW OpenProcessToken OpenSCManagerA OpenSCManagerW OpenServiceA OpenServiceW OpenThreadToken PrivilegeCheck PrivilegedServiceAuditAlarmA PrivilegedServiceAuditAlarmW QueryServiceConfigA QueryServiceConfigW QueryServiceLockStatusA QueryServiceLockStatusW QueryServiceObjectSecurity QueryServiceStatus ReadEventLogA ReadEventLogW RegCloseKey RegConnectRegistryA RegConnectRegistryW RegCreateKeyA RegCreateKeyExA RegCreateKeyExW RegCreateKeyW RegDeleteKeyA RegDeleteKeyW RegDeleteValueA RegDeleteValueW RegEnumKeyA RegEnumKeyExA RegEnumKeyExW RegEnumKeyW RegEnumValueA RegEnumValueW RegFlushKey RegGetKeySecurity RegisterEventSourceA RegisterEventSourceW RegisterServiceCtrlHandlerA RegisterServiceCtrlHandlerW RegLoadKeyA RegLoadKeyW RegNotifyChangeKeyValue RegOpenKeyA RegOpenKeyExA RegOpenKeyExW RegOpenKeyW RegQueryInfoKeyA RegQueryInfoKeyW RegQueryMultipleValuesA RegQueryMultipleValuesW RegQueryValueA RegQueryValueExA RegQueryValueExW RegQueryValueW RegReplaceKeyA RegReplaceKeyW RegRestoreKeyA RegRestoreKeyW RegSaveKeyA RegSaveKeyW RegSetKeySecurity RegSetValueA RegSetValueExA RegSetValueExW RegSetValueW RegUnLoadKeyA RegUnLoadKeyW ReportEventA ReportEventW RevertToSelf SetAclInformation SetFileSecurityA SetFileSecurityW SetKernelObjectSecurity SetPrivateObjectSecurity SetSecurityDescriptorDacl SetSecurityDescriptorGroup SetSecurityDescriptorOwner SetSecurityDescriptorSacl SetServiceBits SetServiceObjectSecurity SetServiceStatus SetThreadToken SetTokenInformation StartServiceA StartServiceCtrlDispatcherA StartServiceCtrlDispatcherW StartServiceW UnlockServiceDatabase

Found follow exports in WSOCK32.DL
accept bind closesocket connect dn_expand EnumProtocolsA EnumProtocolsW GetAddressByNameA GetAddressByNameW gethostbyaddr gethostbyname gethostname GetNameByTypeA GetNameByTypeW getpeername getprotobyname getprotobynumber getservbyname getservbyport GetServiceA GetServiceW getsockname getsockopt GetTypeByNameA GetTypeByNameW htonl htons inet_addr inet_ntoa ioctlsocket listen NPLoadNameSpaces ntohl ntohs recv recvfrom s_perror select send sendto SetServiceA SetServiceW setsockopt shutdown socket TransmitFile WSAAsyncGetHostByAddr WSAAsyncGetHostByName WSAAsyncGetProtoByName WSAAsyncGetProtoByNumber WSAAsyncGetServByName WSAAsyncGetServByPort WSAAsyncSelect WSACancelAsyncRequest WSACancelBlockingCall WSACleanup __WSAFDIsSet WSAGetLastError WSAIsBlocking WSARecvEx WSASetBlockingHook WSASetLastError WSAStartup WSAUnhookBlockingHook

Found follow exports in WS2_32.DL


Windows 95


Found follow exports in KERNEL32.DL
AllocLSCallback AllocSLCallback Callback12 Callback16 Callback20 Callback24 Callback28 Callback32 Callback36 Callback40 Callback44 Callback48 Callback4 Callback52 Callback56 Callback60 Callback64 Callback8 CloseSystemHandle ConvertToGlobalHandle CreateKernelThread CreateSocketHandle CreateToolhelp32Snapshot FT_Exit0 FT_Exit12 FT_Exit16 FT_Exit20 FT_Exit24 FT_Exit28 FT_Exit32 FT_Exit36 FT_Exit4 FT_Exit40 FT_Exit44 FT_Exit48 FT_Exit52 FT_Exit56 FT_Exit8 FT_Prolog FT_Thunk FreeLSCallback FreeSLCallback GetDaylightFlag GetErrorMode GetHandleContext GetLSCallbackTarget GetLSCallbackTemplate GetProcessFlags GetProductName GetSLCallbackTarget GetSLCallbackTemplate Heap32First Heap32ListFirst Heap32ListNext Heap32Next HeapSetFlags InvalidateNLSCache IsLSCallback IsSLCallback K32Thk1632Epilog K32Thk1632Prolog MakeCriticalSectionGlobal MapHInstLS MapHInstLS_PN MapHInstSL MapHInstSL_PN MapHModuleLS MapHModuleSL MapLS MapSL MapSLFix Module32First Module32Next NotifyNLSUserCache OpenVxDHandle Process32First Process32Next QT_Thunk QueryNumberOfEventLogRecords QueryOldestEventLogRecord RegisterServiceProcess ReinitializeCriticalSection SMapLS SMapLS_IP_EBP_12 SMapLS_IP_EBP_16 SMapLS_IP_EBP_20 SMapLS_IP_EBP_24 SMapLS_IP_EBP_28 SMapLS_IP_EBP_32 SMapLS_IP_EBP_36 SMapLS_IP_EBP_40 SMapLS_IP_EBP_8 SUnMapLS SUnMapLS_IP_EBP_12 SUnMapLS_IP_EBP_16 SUnMapLS_IP_EBP_20 SUnMapLS_IP_EBP_24 SUnMapLS_IP_EBP_28 SUnMapLS_IP_EBP_32 SUnMapLS_IP_EBP_36 SUnMapLS_IP_EBP_40 SUnMapLS_IP_EBP_8 SetDaylightFlag SetHandleContext Thread32First Thread32Next ThunkConnect32 TlsAllocInternal TlsFreeInternal Toolhelp32ReadProcessMemory UTRegister UTUnRegister UnMapLS UnMapSLFixArray UninitializeCriticalSection _DebugOut _DebugPrintf dprintf

Found follow exports in NTDLL.DL
RtlExAllocateHeap RtlExFreeHeap RtlExReAllocateHeap RtlExSizeHeap RtlGetHandleValueHeap RtlGrowHeap RtlSetHandleValueHeap

Found follow exports in USER32.DL
CalcChildScroll CharNextExW CharPrevExW ClientThreadConnect GetNextQueueWindow InitSharedTable InitTask IsHungThread ModifyAccess PlaySoundEvent RegisterNetworkCapabilities SetDesktopBitmap SetLogonNotifyWindow SetWindowFullScreenState SysErrorBox UserSignalProc WNDPROC_CALLBACK WinOldAppHackoMatic YieldTask

Found follow exports in GDI32.DL
ByeByeGDI DeviceCapabilitiesEx GetFontResourceInfo SetObjectOwner UpdateICMRegKey pfnRealizePalette pfnSelectPalette

Found follow exports in SHELL32.DL
CheckEscapesA Control_FillCache_RunDLL ExtractIconResInfoA ExtractIconResInfoW ExtractVersionResource16W SheChangeDirExA SheChangeDirW SheConvertPathW SheFullPathA SheFullPathW SheGetCurDrive SheGetDirExW SheGetDirW SheGetPathOffsetW SheRemoveQuotesA SheRemoveQuotesW SheShortenPathA SheShortenPathW Shl1632_ThunkData32 Shl3216_ThunkData32

Found follow exports in COMDLG32.DL
WEP

Found follow exports in COMCTL32.DL
Cctl1632_ThunkData32 DllInstall

Found follow exports in ADVAPI32.DL
RegRemapPreDefKey

Found follow exports in WSOCK32.DL
WsControl closesockinfo Arecv Asend WSHEnumProtocols inet_network getnetbyname rcmd rexec rresvport sethostname

Found follow exports in WS2_32.DL


Windows 98


Found follow exports in KERNEL32.DL
AllocLSCallback AllocSLCallback Callback12 Callback16 Callback20 Callback24 Callback28 Callback32 Callback36 Callback40 Callback44 Callback48 Callback4 Callback52 Callback56 Callback60 Callback64 Callback8 CancelDeviceWakeupRequest CancelIo CancelWaitableTimer CloseSystemHandle ConvertThreadToFiber ConvertToGlobalHandle CopyFileExA CopyFileExW CreateFiber CreateKernelThread CreateSocketHandle CreateToolhelp32Snapshot CreateWaitableTimerA CreateWaitableTimerW DeleteFiber EnumCalendarInfoExA EnumCalendarInfoExW EnumDateFormatsExA EnumDateFormatsExW FT_Exit0 FT_Exit12 FT_Exit16 FT_Exit20 FT_Exit24 FT_Exit28 FT_Exit32 FT_Exit36 FT_Exit4 FT_Exit40 FT_Exit44 FT_Exit48 FT_Exit52 FT_Exit56 FT_Exit8 FT_Prolog FT_Thunk FindFirstFileExA FindFirstFileExW FreeLSCallback FreeSLCallback GetCPInfoExA GetCPInfoExW GetCalendarInfoA GetCalendarInfoW GetDaylightFlag GetDevicePowerState GetErrorMode GetFileAttributesExA GetFileAttributesExW GetHandleContext GetLSCallbackTarget GetLSCallbackTemplate GetLongPathNameA GetLongPathNameW GetProcessFlags GetProcessPriorityBoost GetProductName GetSLCallbackTarget GetSLCallbackTemplate GetThreadPriorityBoost GetWriteWatch Heap32First Heap32ListFirst Heap32ListNext Heap32Next HeapSetFlags InitializeCriticalSectionAndSpinCount InterlockedCompareExchange InterlockedExchangeAdd InvalidateNLSCache IsDebuggerPresent IsLSCallback IsProcessorFeaturePresent IsSLCallback IsSystemResumeAutomatic K32Thk1632Epilog K32Thk1632Prolog K32_NtCreateFile K32_RtlNtStatusToDosError QT_Thunk MakeCriticalSectionGlobal MapHInstLS MapHInstLS_PN MapHInstSL MapHInstSL_PN MapHModuleLS MapHModuleSL MapLS MapSL MapSLFix Module32First Module32Next NotifyNLSUserCache OpenVxDHandle OpenWaitableTimerA OpenWaitableTimerW Process32First Process32Next QueryNumberOfEventLogRecords QueryOldestEventLogRecord ReadDirectoryChangesW ReadFileScatter RegisterServiceProcess RegisterSysMsgHandler ReinitializeCriticalSection RequestDeviceWakeup RequestWakeupLatency ResetNLSUserInfoCache ResetWriteWatch SMapLS SMapLS_IP_EBP_12 SMapLS_IP_EBP_16 SMapLS_IP_EBP_20 SMapLS_IP_EBP_24 SMapLS_IP_EBP_28 SMapLS_IP_EBP_32 SMapLS_IP_EBP_36 SMapLS_IP_EBP_40 SMapLS_IP_EBP_8 SUnMapLS SUnMapLS_IP_EBP_12 SUnMapLS_IP_EBP_16 SUnMapLS_IP_EBP_20 SUnMapLS_IP_EBP_24 SUnMapLS_IP_EBP_28 SUnMapLS_IP_EBP_32 SUnMapLS_IP_EBP_36 SUnMapLS_IP_EBP_40 SUnMapLS_IP_EBP_8 SetCalendarInfoA SetCalendarInfoW SetCriticalSectionSpinCount SetDaylightFlag SetHandleContext SetMessageWaitingIndicator SetProcessAffinityMask SetProcessPriorityBoost SetThreadExecutionState SetThreadIdealProcessor SetThreadPriorityBoost SetWaitableTimer SignalObjectAndWait SignalSysMsgHandlers SwitchToFiber SwitchToThread Thread32First Thread32Next ThunkConnect32 TlsAllocInternal TlsFreeInternal Toolhelp32ReadProcessMemory TryEnterCriticalSection UTRegister UTUnRegister UnMapLS UnMapSLFixArray UninitializeCriticalSection VirtualAllocEx VirtualFreeEx WriteFileGather _DebugOut _DebugPrintf dprintf

Found follow exports in NTDLL.DL
IoUnregisterDeviceInterface NtCreateFile NtGetDevnodeFromFileHandle NtInitiatePowerAction NtPowerInformation NtRequestWakeupLatency NtSetSystemPowerState RtlExAllocateHeap RtlExFreeHeap RtlExReAllocateHeap RtlExSizeHeap RtlGetHandleValueHeap RtlGrowHeap RtlNtStatusToDosError RtlSetHandleValueHeap

Found follow exports in USER32.DL
AlignRects AnimateWindow BlockInput BroadcastSystemMessageA BroadcastSystemMessageW CalcChildScroll ChangeDisplaySettingsExA ChangeDisplaySettingsExW CharNextExW CharPrevExW ClientThreadConnect DrawMenuBarTemp EndMenu EnumDisplayDevicesA EnumDisplayDevicesW EnumDisplayMonitors EnumDisplaySettingsExA EnumDisplaySettingsExW FlashWindowEx GetAltTabInfo GetAncestor GetClipboardSequenceNumber GetComboBoxInfo GetCursorInfo GetGUIThreadInfo GetGuiResources GetListBoxInfo GetMenuBarInfo GetMenuInfo GetMonitorInfoA GetMonitorInfoW GetMouseMovePoints GetNextQueueWindow GetProcessDefaultLayout GetScrollBarInfo GetTitleBarInfo GetWindowInfo GetWindowModuleFileNameA GetWindowModuleFileNameW HasSystemSleepStarted IMPGetIMEA IMPGetIMEW IMPQueryIMEA IMPQueryIMEW IMPSetIMEA IMPSetIMEW InSendMessageEx InitSharedTable InitTask IsHungThread ModifyAccess MonitorFromPoint MonitorFromRect MonitorFromWindow MsgWaitForMultipleObjectsEx NotifyWinEvent PlaySoundEvent RealChildWindowFromPoint RealGetWindowClass RegisterDeviceNotificationA RegisterDeviceNotificationW RegisterNetworkCapabilities SendIMEMessageExA SendIMEMessageExW SendInput SetDesktopBitmap SetLogonNotifyWindow SetMenuInfo SetProcessDefaultLayout SetWinEventHook SetWindowFullScreenState SysErrorBox ToUnicodeEx TrackMouseEvent UnhookWinEvent UnregisterDeviceNotification UserIsSystemResumeAutomatic UserSetDeviceHoldState UserSignalProc UserTickleTimer WINNLSEnableIME WINNLSGetEnableStatus WINNLSGetIMEHotkey WNDPROC_CALLBACK WinOldAppHackoMatic YieldTask

Found follow exports in GDI32.DL
ByeByeGDI ColorCorrectPalette DeviceCapabilitiesEx EnableEUDC GetFontResourceInfo GetLayout SetLayout SetMagicColors SetObjectOwner pfnRealizePalette pfnSelectPalette

Found follow exports in SHELL32.DL
CheckEscapesA Control_FillCache_RunDLL Control_FillCache_RunDLLA Control_FillCache_RunDLLW Control_RunDLLA Control_RunDLLW DllCanUnloadNow DllGetVersion DllInstall ExtractIconExW ExtractIconResInfoA ExtractIconResInfoW ExtractVersionResource16W FindExeDlgProc OpenAs_RunDLLA OpenAs_RunDLLW PrintersGetCommand_RunDLLA PrintersGetCommand_RunDLLW SHBrowseForFolderW SheChangeDirExA SheChangeDirW SheConvertPathW SheFullPathA SheFullPathW SheGetCurDrive SheGetDirExW SheGetDirW SheGetPathOffsetW Shell_NotifyIconW ShellExecuteExW ShellHookProc SHEmptyRecycleBinA SHEmptyRecycleBinW SheRemoveQuotesA SheRemoveQuotesW SheShortenPathA SheShortenPathW SHExitWindowsEx SHFileOperationW SHGetDataFromIDListW SHGetDiskFreeSpaceA SHGetFileInfoW SHGetNewLinkInfo SHGetPathFromIDListW SHGetSettings SHGetSpecialFolderPathA SHGetSpecialFolderPathW SHHelpShortcuts_RunDLLA SHHelpShortcuts_RunDLLW SHInvokePrinterCommandA SHInvokePrinterCommandW SHQueryRecycleBinA SHQueryRecycleBinW SHUpdateRecycleBinIcon

Found follow exports in COMDLG32.DL
dwLBSubclass dwOKSubclass LoadAlterBitmap WantArrows

Found follow exports in COMCTL32.DL
Cctl1632_ThunkData32 DllInstall ImageList_GetFlags

Found follow exports in ADVAPI32.DL
BuildExplicitAccessWithNameA BuildExplicitAccessWithNameW BuildImpersonateExplicitAccessWithNameA BuildImpersonateExplicitAccessWithNameW BuildImpersonateTrusteeA BuildImpersonateTrusteeW BuildSecurityDescriptorA BuildSecurityDescriptorW BuildTrusteeWithNameA BuildTrusteeWithNameW BuildTrusteeWithSidA BuildTrusteeWithSidW CancelOverlappedAccess ConvertAccessToSecurityDescriptorA ConvertAccessToSecurityDescriptorW ConvertSecurityDescriptorToAccessA ConvertSecurityDescriptorToAccessNamedA ConvertSecurityDescriptorToAccessNamedW ConvertSecurityDescriptorToAccessW CryptAcquireContextW CryptContextAddRef CryptDuplicateHash CryptDuplicateKey CryptEnumProviderTypesA CryptEnumProviderTypesW CryptEnumProvidersA CryptEnumProvidersW CryptGetDefaultProviderA CryptGetDefaultProviderW CryptSetProviderExA CryptSetProviderExW CryptSetProviderW CryptSignHashW CryptVerifySignatureW DuplicateTokenEx GetAccessPermissionsForObjectA GetAccessPermissionsForObjectW GetAuditedPermissionsFromAclA GetAuditedPermissionsFromAclW GetCurrentHwProfileA GetCurrentHwProfileW GetEffectiveRightsFromAclA GetEffectiveRightsFromAclW GetExplicitEntriesFromAclA GetExplicitEntriesFromAclW GetMultipleTrusteeA GetMultipleTrusteeOperationA GetMultipleTrusteeOperationW GetMultipleTrusteeW GetNamedSecurityInfoA GetNamedSecurityInfoExA GetNamedSecurityInfoExW GetNamedSecurityInfoW GetOverlappedAccessResults GetSecurityInfo GetSecurityInfoExA GetSecurityInfoExW GetTrusteeNameA GetTrusteeNameW GetTrusteeTypeA GetTrusteeTypeW LookupSecurityDescriptorPartsA LookupSecurityDescriptorPartsW ObjectDeleteAuditAlarmA ObjectDeleteAuditAlarmW RegRemapPreDefKey SetEntriesInAccessListA SetEntriesInAccessListW SetEntriesInAclA SetEntriesInAclW SetEntriesInAuditListA SetEntriesInAuditListW SetNamedSecurityInfoA SetNamedSecurityInfoExA SetNamedSecurityInfoExW SetNamedSecurityInfoW SetSecurityInfo SetSecurityInfoExA SetSecurityInfoExW TrusteeAccessToObjectA TrusteeAccessToObjectW

Found follow exports in WSOCK32.DL
MigrateWinsockConfiguration WEP WSApSetPostRoutine WsControl closesockinfo Arecv Asend WSHEnumProtocols inet_network getnetbyname rcmd rexec rresvport sethostname NSPStartup AcceptEx GetAcceptExSockaddrs

Found follow exports in WS2_32.DL
accept bind closesocket connect getpeername getsockname getsockopt htonl htons ioctlsocket inet_addr inet_ntoa listen ntohl ntohs recv recvfrom select send sendto setsockopt shutdown socket WSApSetPostRoutine WPUCompleteOverlappedRequest WSAAccept WSAAddressToStringA WSAAddressToStringW WSACloseEvent WSAConnect WSACreateEvent WSADuplicateSocketA WSADuplicateSocketW WSAEnumNameSpaceProvidersA WSAEnumNameSpaceProvidersW WSAEnumNetworkEvents WSAEnumProtocolsA WSAEnumProtocolsW WSAEventSelect WSAGetOverlappedResult WSAGetQOSByName WSAGetServiceClassInfoA WSAGetServiceClassInfoW WSAGetServiceClassNameByClassIdA WSAGetServiceClassNameByClassIdW WSAHtonl WSAHtons WSAInstallServiceClassA WSAInstallServiceClassW WSAIoctl gethostbyaddr gethostbyname getprotobyname getprotobynumber getservbyname getservbyport gethostname WSAJoinLeaf WSALookupServiceBeginA WSALookupServiceBeginW WSALookupServiceEnd WSALookupServiceNextA WSALookupServiceNextW WSANtohl WSANtohs WSAProviderConfigChange WSARecv WSARecvDisconnect WSARecvFrom WSARemoveServiceClass WSAResetEvent WSASend WSASendDisconnect WSASendTo WSASetEvent WSASetServiceA WSASetServiceW WSASocketA WSASocketW WSAStringToAddressA WSAStringToAddressW WSAWaitForMultipleEvents WSCDeinstallProvider WSCEnableNSProvider WSCEnumProtocols WSCGetProviderPath WSCInstallNameSpace WSCInstallProvider WSCUnInstallNameSpace WSAAsyncSelect WSAAsyncGetHostByAddr WSAAsyncGetHostByName WSAAsyncGetProtoByNumber WSAAsyncGetProtoByName WSAAsyncGetServByPort WSAAsyncGetServByName WSACancelAsyncRequest WSASetBlockingHook WSAUnhookBlockingHook WSAGetLastError WSASetLastError WSACancelBlockingCall WSAIsBlocking WSAStartup WSACleanup __WSAFDIsSet WEP

Windows ME


Found follow exports in KERNEL32.DL
AllocLSCallback AllocSLCallback Callback12 Callback16 Callback20 Callback24 Callback28 Callback32 Callback36 Callback40 Callback44 Callback48 Callback4 Callback52 Callback56 Callback60 Callback64 Callback8 CancelDeviceWakeupRequest CancelIo CancelWaitableTimer CloseSystemHandle ConvertThreadToFiber ConvertToGlobalHandle CopyFileExA CopyFileExW CreateFiber CreateKernelThread CreateSocketHandle CreateToolhelp32Snapshot CreateWaitableTimerA CreateWaitableTimerW DeleteFiber EnumCalendarInfoExA EnumCalendarInfoExW EnumDateFormatsExA EnumDateFormatsExW EnumLanguageGroupLocalesA EnumLanguageGroupLocalesW EnumSystemGeoID EnumSystemLanguageGroupsA EnumSystemLanguageGroupsW EnumUILanguagesA EnumUILanguagesW FT_Exit0 FT_Exit12 FT_Exit16 FT_Exit20 FT_Exit24 FT_Exit28 FT_Exit32 FT_Exit36 FT_Exit4 FT_Exit40 FT_Exit44 FT_Exit48 FT_Exit52 FT_Exit56 FT_Exit8 FT_Prolog FT_Thunk FindFirstFileExA FindFirstFileExW FreeLSCallback FreeSLCallback GetCPInfoExA GetCPInfoExW GetCalendarInfoA GetCalendarInfoW GetDaylightFlag GetDevicePowerState GetErrorMode GetFileAttributesExA GetFileAttributesExW GetGeoInfoA GetGeoInfoW GetHandleContext GetLSCallbackTarget GetLSCallbackTemplate GetLongPathNameA GetLongPathNameW GetProcessFlags GetProcessPriorityBoost GetProductName GetSLCallbackTarget GetSLCallbackTemplate GetSystemDefaultUILanguage GetThreadPriorityBoost GetUserDefaultUILanguage GetUserGeoID GetWriteWatch Heap32First Heap32ListFirst Heap32ListNext Heap32Next HeapSetFlags InitializeCriticalSectionAndSpinCount InterlockedCompareExchange InterlockedExchangeAdd InvalidateNLSCache IsDebuggerPresent IsLSCallback IsProcessorFeaturePresent IsSLCallback IsSystemResumeAutomatic IsValidLanguageGroup QT_Thunk K32Thk1632Epilog K32Thk1632Prolog K32_NtCreateFile K32_RtlNtStatusToDosError MakeCriticalSectionGlobal MapHInstLS MapHInstLS_PN MapHInstSL MapHInstSL_PN MapHModuleLS MapHModuleSL MapLS MapSL MapSLFix Module32First Module32Next NotifyNLSUserCache OpenThread OpenVxDHandle OpenWaitableTimerA OpenWaitableTimerW Process32First Process32Next QueryNumberOfEventLogRecords QueryOldestEventLogRecord ReadDirectoryChangesW ReadFileScatter RegisterServiceProcess RegisterSysMsgHandler ReinitializeCriticalSection RequestDeviceWakeup RequestWakeupLatency ResetNLSUserInfoCache ResetWriteWatch SMapLS SMapLS_IP_EBP_12 SMapLS_IP_EBP_16 SMapLS_IP_EBP_20 SMapLS_IP_EBP_24 SMapLS_IP_EBP_28 SMapLS_IP_EBP_32 SMapLS_IP_EBP_36 SMapLS_IP_EBP_40 SMapLS_IP_EBP_8 SUnMapLS SUnMapLS_IP_EBP_12 SUnMapLS_IP_EBP_16 SUnMapLS_IP_EBP_20 SUnMapLS_IP_EBP_24 SUnMapLS_IP_EBP_28 SUnMapLS_IP_EBP_32 SUnMapLS_IP_EBP_36 SUnMapLS_IP_EBP_40 SUnMapLS_IP_EBP_8 SetCalendarInfoA SetCalendarInfoW SetCriticalSectionSpinCount SetDaylightFlag SetHandleContext SetMessageWaitingIndicator SetProcessAffinityMask SetProcessPriorityBoost SetThreadExecutionState SetThreadIdealProcessor SetThreadPriorityBoost SetUserGeoID SetWaitableTimer SignalObjectAndWait SignalSysMsgHandlers SwitchToFiber SwitchToThread Thread32First Thread32Next ThunkConnect32 TlsAllocInternal TlsFreeInternal Toolhelp32ReadProcessMemory TryEnterCriticalSection UTRegister UTUnRegister UnMapLS UnMapSLFixArray UninitializeCriticalSection VirtualAllocEx VirtualFreeEx WriteFileGather _DebugOut _DebugPrintf dprintf

Found follow exports in NTDLL.DL
IoUnregisterDeviceInterface NtCreateFile NtGetDevnodeFromFileHandle NtInitiatePowerAction NtPowerInformation NtRequestWakeupLatency NtSetSystemPowerState RtlExAllocateHeap RtlExFreeHeap RtlExReAllocateHeap RtlExSizeHeap RtlGetHandleValueHeap RtlGrowHeap RtlNtStatusToDosError RtlSetHandleValueHeap

Found follow exports in USER32.DL
AlignRects AllowSetForegroundWindow AnimateWindow BlockInput BroadcastSystemMessageA BroadcastSystemMessageW CalcChildScroll ChangeDisplaySettingsExA ChangeDisplaySettingsExW CharNextExW CharPrevExW ClientThreadConnect DrawMenuBarTemp EndMenu EnumDisplayDevicesA EnumDisplayDevicesW EnumDisplayMonitors EnumDisplaySettingsExA EnumDisplaySettingsExW FlashWindowEx GetAltTabInfo GetAncestor GetClipboardSequenceNumber GetComboBoxInfo GetCursorInfo GetGUIThreadInfo GetGuiResources GetListBoxInfo GetMenuBarInfo GetMenuInfo GetMonitorInfoA GetMonitorInfoW GetMouseMovePoints GetMouseMovePointsEx GetNextQueueWindow GetProcessDefaultLayout GetScrollBarInfo GetTitleBarInfo GetWindowInfo GetWindowModuleFileNameA GetWindowModuleFileNameW HasSystemSleepStarted IMPGetIMEA IMPGetIMEW IMPQueryIMEA IMPQueryIMEW IMPSetIMEA IMPSetIMEW InSendMessageEx InitSharedTable InitTask IsHungThread LockSetForegroundWindow ModifyAccess MonitorFromPoint MonitorFromRect MonitorFromWindow MsgWaitForMultipleObjectsEx NotifyWinEvent PlaySoundEvent RealChildWindowFromPoint RealGetWindowClass RegisterDeviceNotificationA RegisterDeviceNotificationW RegisterNetworkCapabilities SendIMEMessageExA SendIMEMessageExW SendInput SetDesktopBitmap SetLogonNotifyWindow SetMenuInfo SetProcessDefaultLayout SetWinEventHook SetWindowFullScreenState SysErrorBox ToUnicodeEx TrackMouseEvent UnhookWinEvent UnregisterDeviceNotification UserIsSystemResumeAutomatic UserSetDeviceHoldState UserSignalProc UserTickleTimer WINNLSEnableIME WINNLSGetEnableStatus WINNLSGetIMEHotkey WNDPROC_CALLBACK WinOldAppHackoMatic YieldTask _SetProcessDefaultLayout

Found follow exports in GDI32.DL
ByeByeGDI ColorCorrectPalette DeviceCapabilitiesEx EnableEUDC GetFontResourceInfo GetLayout SetLayout SetMagicColors SetObjectOwner pfnRealizePalette pfnSelectPalette

Found follow exports in SHELL32.DL
CheckEscapesA Control_FillCache_RunDLL Control_FillCache_RunDLLA Control_FillCache_RunDLLW Control_RunDLLA Control_RunDLLW DllCanUnloadNow DllGetVersion DllInstall DllRegisterServer DllUnregisterServer ExtractIconExW ExtractIconResInfoA ExtractIconResInfoW ExtractVersionResource16W FindExeDlgProc OpenAs_RunDLLA OpenAs_RunDLLW Options_RunDLL Options_RunDLLA Options_RunDLLW PrintersGetCommand_RunDLLA PrintersGetCommand_RunDLLW SHBindToParent SHBrowseForFolderW SHChangeNotifySuspendResume SHCreateDirectoryExA SHCreateDirectoryExW SHCreateLocalServerRunDll SheChangeDirExA SheChangeDirW SheConvertPathW SheFullPathA SheFullPathW SheGetCurDrive SheGetDirExW SheGetDirW SheGetPathOffsetW Shell_NotifyIconW ShellExec_RunDLL ShellExec_RunDLLA ShellExec_RunDLLW ShellExecuteExW ShellHookProc SHEmptyRecycleBinA SHEmptyRecycleBinW SheRemoveQuotesA SheRemoveQuotesW SheShortenPathA SheShortenPathW SHExitWindowsEx SHExtractIconsW SHFileOperationW SHGetDataFromIDListW SHGetDiskFreeSpaceA SHGetDiskFreeSpaceExA SHGetDiskFreeSpaceExW SHGetFileInfoW SHGetFolderLocation SHGetFolderPathA SHGetFolderPathW SHGetIconOverlayIndexA SHGetIconOverlayIndexW SHGetNewLinkInfo SHGetNewLinkInfoA SHGetNewLinkInfoW SHGetPathFromIDListW SHGetSettings SHGetSpecialFolderPathA SHGetSpecialFolderPathW SHHelpShortcuts_RunDLLA SHHelpShortcuts_RunDLLW SHInvokePrinterCommandA SHInvokePrinterCommandW SHIsFileAvailableOffline SHLoadNonloadedIconOverlayIdentifiers SHOpenFolderAndSelectItems SHPathPrepareForWriteA SHPathPrepareForWriteW SHQueryRecycleBinA SHQueryRecycleBinW SHUpdateRecycleBinIcon

Found follow exports in COMDLG32.DL
dwLBSubclass dwOKSubclass LoadAlterBitmap PrintDlgExA PrintDlgExW WantArrows

Found follow exports in COMCTL32.DL
Cctl1632_ThunkData32 DllInstall ImageList_GetFlags

Found follow exports in ADVAPI32.DL
BuildExplicitAccessWithNameA BuildExplicitAccessWithNameW BuildImpersonateExplicitAccessWithNameA BuildImpersonateExplicitAccessWithNameW BuildImpersonateTrusteeA BuildImpersonateTrusteeW BuildSecurityDescriptorA BuildSecurityDescriptorW BuildTrusteeWithNameA BuildTrusteeWithNameW BuildTrusteeWithSidA BuildTrusteeWithSidW CancelOverlappedAccess ConvertAccessToSecurityDescriptorA ConvertAccessToSecurityDescriptorW ConvertSecurityDescriptorToAccessA ConvertSecurityDescriptorToAccessNamedA ConvertSecurityDescriptorToAccessNamedW ConvertSecurityDescriptorToAccessW CryptAcquireContextW CryptContextAddRef CryptDuplicateHash CryptDuplicateKey CryptEnumProviderTypesA CryptEnumProviderTypesW CryptEnumProvidersA CryptEnumProvidersW CryptGetDefaultProviderA CryptGetDefaultProviderW CryptGetLocalKeyLimits CryptSetProviderExA CryptSetProviderExW CryptSetProviderW CryptSignHashW CryptVerifySignatureW DuplicateTokenEx GetAccessPermissionsForObjectA GetAccessPermissionsForObjectW GetAuditedPermissionsFromAclA GetAuditedPermissionsFromAclW GetCurrentHwProfileA GetCurrentHwProfileW GetEffectiveRightsFromAclA GetEffectiveRightsFromAclW GetExplicitEntriesFromAclA GetExplicitEntriesFromAclW GetMultipleTrusteeA GetMultipleTrusteeOperationA GetMultipleTrusteeOperationW GetMultipleTrusteeW GetNamedSecurityInfoA GetNamedSecurityInfoExA GetNamedSecurityInfoExW GetNamedSecurityInfoW GetOverlappedAccessResults GetSecurityInfo GetSecurityInfoExA GetSecurityInfoExW GetTrusteeNameA GetTrusteeNameW GetTrusteeTypeA GetTrusteeTypeW LookupSecurityDescriptorPartsA LookupSecurityDescriptorPartsW ObjectDeleteAuditAlarmA ObjectDeleteAuditAlarmW RegRemapPreDefKey SetEntriesInAccessListA SetEntriesInAccessListW SetEntriesInAclA SetEntriesInAclW SetEntriesInAuditListA SetEntriesInAuditListW SetNamedSecurityInfoA SetNamedSecurityInfoExA SetNamedSecurityInfoExW SetNamedSecurityInfoW SetSecurityInfo SetSecurityInfoExA SetSecurityInfoExW TrusteeAccessToObjectA TrusteeAccessToObjectW

Found follow exports in WSOCK32.DL
MigrateWinsockConfiguration WEP WSApSetPostRoutine WsControl closesockinfo Arecv Asend WSHEnumProtocols inet_network getnetbyname rcmd rexec rresvport sethostname NSPStartup AcceptEx GetAcceptExSockaddrs

Found follow exports in WS2_32.DL
accept bind closesocket connect getpeername getsockname getsockopt htonl htons ioctlsocket inet_addr inet_ntoa listen ntohl ntohs recv recvfrom select send sendto setsockopt shutdown socket WSApSetPostRoutine WPUCompleteOverlappedRequest WSAAccept WSAAddressToStringA WSAAddressToStringW WSACloseEvent WSAConnect WSACreateEvent WSADuplicateSocketA WSADuplicateSocketW WSAEnumNameSpaceProvidersA WSAEnumNameSpaceProvidersW WSAEnumNetworkEvents WSAEnumProtocolsA WSAEnumProtocolsW WSAEventSelect WSAGetOverlappedResult WSAGetQOSByName WSAGetServiceClassInfoA WSAGetServiceClassInfoW WSAGetServiceClassNameByClassIdA WSAGetServiceClassNameByClassIdW WSAHtonl WSAHtons WSAInstallServiceClassA WSAInstallServiceClassW WSAIoctl gethostbyaddr gethostbyname getprotobyname getprotobynumber getservbyname getservbyport gethostname WSAJoinLeaf WSALookupServiceBeginA WSALookupServiceBeginW WSALookupServiceEnd WSALookupServiceNextA WSALookupServiceNextW WSANtohl WSANtohs WSAProviderConfigChange WSARecv WSARecvDisconnect WSARecvFrom WSARemoveServiceClass WSAResetEvent WSASend WSASendDisconnect WSASendTo WSASetEvent WSASetServiceA WSASetServiceW WSASocketA WSASocketW WSAStringToAddressA WSAStringToAddressW WSAWaitForMultipleEvents WSCDeinstallProvider WSCEnableNSProvider WSCEnumProtocols WSCGetProviderPath WSCInstallNameSpace WSCInstallProvider WSCUnInstallNameSpace WSAAsyncSelect WSAAsyncGetHostByAddr WSAAsyncGetHostByName WSAAsyncGetProtoByNumber WSAAsyncGetProtoByName WSAAsyncGetServByPort WSAAsyncGetServByName WSACancelAsyncRequest WSASetBlockingHook WSAUnhookBlockingHook WSAGetLastError WSASetLastError WSACancelBlockingCall WSAIsBlocking WSAStartup WSACleanup __WSAFDIsSet WEP

Windows NT


Found follow exports in KERNEL32.DL
AddConsoleAliasA AddConsoleAliasW BaseAttachCompleteThunk CancelIo CancelWaitableTimer CloseConsoleHandle CmdBatNotification ConsoleMenuControl ConvertThreadToFiber CopyFileExA CopyFileExW CreateFiber CreateVirtualBuffer CreateWaitableTimerA CreateWaitableTimerW DeleteFiber DuplicateConsoleHandle ExitVDM ExpungeConsoleCommandHistoryA ExpungeConsoleCommandHistoryW ExtendVirtualBuffer FindFirstFileExA FindFirstFileExW FreeVirtualBuffer GetConsoleAliasA GetConsoleAliasExesA GetConsoleAliasExesLengthA GetConsoleAliasExesLengthW GetConsoleAliasExesW GetConsoleAliasW GetConsoleAliasesA GetConsoleAliasesLengthA GetConsoleAliasesLengthW GetConsoleAliasesW GetConsoleCommandHistoryA GetConsoleCommandHistoryLengthA GetConsoleCommandHistoryLengthW GetConsoleCommandHistoryW GetConsoleDisplayMode GetConsoleFontInfo GetConsoleFontSize GetConsoleHardwareState GetConsoleInputExeNameA GetConsoleInputExeNameW GetConsoleInputWaitHandle GetConsoleKeyboardLayoutNameA GetConsoleKeyboardLayoutNameW GetCurrentConsoleFont GetFileAttributesExA GetFileAttributesExW GetNextVDMCommand GetNumberOfConsoleFonts GetProcessPriorityBoost GetThreadPriorityBoost GetVDMCurrentDirectories HeapCreateTagsW HeapExtend HeapQueryTagW HeapSummary HeapUsage InitializeCriticalSectionAndSpinCount InterlockedCompareExchange InterlockedExchangeAdd InvalidateConsoleDIBits IsDebuggerPresent IsProcessorFeaturePresent OpenConsoleW OpenWaitableTimerA OpenWaitableTimerW QueryWin31IniFilesMappedToRegistry ReadConsoleInputExA ReadConsoleInputExW ReadDirectoryChangesW ReadFileScatter RegisterConsoleVDM RegisterWaitForInputIdle RegisterWowBaseHandlers RegisterWowExec SetConsoleCommandHistoryMode SetConsoleCursor SetConsoleDisplayMode SetConsoleFont SetConsoleHardwareState SetConsoleIcon SetConsoleInputExeNameA SetConsoleInputExeNameW SetConsoleKeyShortcuts SetConsoleMaximumWindowSize SetConsoleMenuClose SetConsoleNumberOfCommandsA SetConsoleNumberOfCommandsW SetConsolePalette SetCriticalSectionSpinCount SetLastConsoleEventActive SetProcessAffinityMask SetProcessPriorityBoost SetThreadIdealProcessor SetThreadPriorityBoost SetVDMCurrentDirectories SetWaitableTimer ShowConsoleCursor SignalObjectAndWait SwitchToFiber SwitchToThread TrimVirtualBuffer TryEnterCriticalSection VDMConsoleOperation VDMOperationStarted VerifyConsoleIoHandle VerifyVersionInfoA VerifyVersionInfoW VirtualAllocEx VirtualBufferExceptionHandler VirtualFreeEx WriteConsoleInputVDMA WriteConsoleInputVDMW WriteFileGather

Found follow exports in NTDLL.DL
?Allocate@CBufferAllocator@@UAEPAXK@Z PropertyLengthAsVariant RtlCompareVariants RtlConvertPropertyToVariant RtlConvertVariantToProperty CsrAllocateCaptureBuffer CsrAllocateCapturePointer CsrAllocateMessagePointer CsrCaptureMessageBuffer CsrCaptureMessageString CsrCaptureTimeout CsrClientCallServer CsrClientConnectToServer CsrFreeCaptureBuffer CsrIdentifyAlertableThread CsrNewThread CsrProbeForRead CsrProbeForWrite CsrSetPriorityClass DbgSsHandleKmApiMsg DbgSsInitialize DbgUiConnectToDbg DbgUiContinue DbgUiWaitStateChange DbgUserBreakPoint KiRaiseUserExceptionDispatcher KiUserApcDispatcher KiUserCallbackDispatcher KiUserExceptionDispatcher LdrAccessResource LdrDisableThreadCalloutsForDll LdrEnumResources LdrFindEntryForAddress LdrFindResourceDirectory_U LdrFindResource_U LdrGetDllHandle LdrGetProcedureAddress LdrInitializeThunk LdrLoadDll LdrProcessRelocationBlock LdrQueryImageFileExecutionOptions LdrQueryProcessModuleInformation LdrShutdownProcess LdrShutdownThread LdrUnloadDll LdrVerifyImageMatchesChecksum NPXEMULATORTABLE NlsAnsiCodePage NlsMbCodePageTag NlsMbOemCodePageTag NtAcceptConnectPort NtAccessCheck NtAccessCheckAndAuditAlarm NtAddAtom NtAdjustGroupsToken NtAdjustPrivilegesToken NtAlertResumeThread NtAlertThread NtAllocateLocallyUniqueId NtAllocateUuids NtAllocateVirtualMemory NtCallbackReturn NtCancelIoFile NtCancelTimer NtClearEvent NtClose NtCloseObjectAuditAlarm NtCompleteConnectPort NtConnectPort NtContinue NtCreateChannel NtCreateDirectoryObject NtCreateEvent NtCreateEventPair NtCreateFile NtCreateIoCompletion NtCreateKey NtCreateMailslotFile NtCreateMutant NtCreateNamedPipeFile NtCreatePagingFile NtCreatePort NtCreateProcess NtCreateProfile NtCreateSection NtCreateSemaphore NtCreateSymbolicLinkObject NtCreateThread NtCreateTimer NtCreateToken NtDelayExecution NtDeleteAtom NtDeleteFile NtDeleteKey NtDeleteObjectAuditAlarm NtDeleteValueKey NtDeviceIoControlFile NtDisplayString NtDuplicateObject NtDuplicateToken NtEnumerateKey NtEnumerateValueKey NtExtendSection NtFindAtom NtFlushBuffersFile NtFlushInstructionCache NtFlushKey NtFlushVirtualMemory NtFlushWriteBuffer NtFreeVirtualMemory NtFsControlFile NtGetContextThread NtGetPlugPlayEvent NtGetTickCount NtImpersonateClientOfPort NtImpersonateThread NtInitializeRegistry NtListenChannel NtListenPort NtLoadDriver NtLoadKey2 NtLoadKey NtLockFile NtLockVirtualMemory NtMakeTemporaryObject NtMapViewOfSection NtNotifyChangeDirectoryFile NtNotifyChangeKey NtOpenChannel NtOpenDirectoryObject NtOpenEvent NtOpenEventPair NtOpenFile NtOpenIoCompletion NtOpenKey NtOpenMutant NtOpenObjectAuditAlarm NtOpenProcess NtOpenProcessToken NtOpenSection NtOpenSemaphore NtOpenSymbolicLinkObject NtOpenThread NtOpenThreadToken NtOpenTimer NtPlugPlayControl NtPrivilegeCheck NtPrivilegeObjectAuditAlarm NtPrivilegedServiceAuditAlarm NtProtectVirtualMemory NtPulseEvent NtQueryAttributesFile NtQueryDefaultLocale NtQueryDirectoryFile NtQueryDirectoryObject NtQueryEaFile NtQueryEvent NtQueryFullAttributesFile NtQueryInformationAtom NtQueryInformationFile NtQueryInformationPort NtQueryInformationProcess NtQueryInformationThread NtQueryInformationToken NtQueryIntervalProfile NtQueryIoCompletion NtQueryKey NtQueryMultipleValueKey NtQueryMutant NtQueryObject NtQueryOleDirectoryFile NtQuerySection NtQuerySecurityObject NtQuerySemaphore NtQuerySymbolicLinkObject NtQuerySystemEnvironmentValue NtQuerySystemInformation NtQuerySystemTime NtQueryTimer NtQueryTimerResolution NtQueryValueKey NtQueryVirtualMemory NtQueryVolumeInformationFile NtQueueApcThread NtRaiseException NtRaiseHardError NtReadFile NtReadFileScatter NtReadRequestData NtReadVirtualMemory NtRegisterThreadTerminatePort NtReleaseMutant NtReleaseSemaphore NtRemoveIoCompletion NtReplaceKey NtReplyPort NtReplyWaitReceivePort NtReplyWaitReplyPort NtReplyWaitSendChannel NtRequestPort NtRequestWaitReplyPort NtResetEvent NtRestoreKey NtResumeThread NtSaveKey NtSendWaitReplyChannel NtSetContextChannel NtSetContextThread NtSetDefaultHardErrorPort NtSetDefaultLocale NtSetEaFile NtSetEvent NtSetHighEventPair NtSetHighWaitLowEventPair NtSetHighWaitLowThread NtSetInformationFile NtSetInformationKey NtSetInformationObject NtSetInformationProcess NtSetInformationThread NtSetInformationToken NtSetIntervalProfile NtSetIoCompletion NtSetLdtEntries NtSetLowEventPair NtSetLowWaitHighEventPair NtSetLowWaitHighThread NtSetSecurityObject NtSetSystemEnvironmentValue NtSetSystemInformation NtSetSystemPowerState NtSetSystemTime NtSetTimer NtSetTimerResolution NtSetValueKey NtSetVolumeInformationFile NtShutdownSystem NtSignalAndWaitForSingleObject NtStartProfile NtStopProfile NtSuspendThread NtSystemDebugControl NtTerminateProcess NtTerminateThread NtTestAlert NtUnloadDriver NtUnloadKey NtUnlockFile NtUnlockVirtualMemory NtUnmapViewOfSection NtVdmControl NtWaitForMultipleObjects NtWaitForSingleObject NtWaitHighEventPair NtWaitLowEventPair NtWriteFile NtWriteFileGather NtWriteRequestData NtWriteVirtualMemory NtYieldExecution PfxFindPrefix PfxInitialize PfxInsertPrefix PfxRemovePrefix RestoreEm87Context RtlAbortRXact RtlAbsoluteToSelfRelativeSD RtlAcquirePebLock RtlAcquireResourceExclusive RtlAcquireResourceShared RtlAddAccessAllowedAce RtlAddAccessDeniedAce RtlAddAce RtlAddActionToRXact RtlAddAtomToAtomTable RtlAddAttributeActionToRXact RtlAddAuditAccessAce RtlAddCompoundAce RtlAdjustPrivilege RtlAllocateAndInitializeSid RtlAllocateHandle RtlAnsiCharToUnicodeChar RtlAnsiStringToUnicodeSize RtlAppendAsciizToString RtlAppendStringToString RtlAppendUnicodeStringToString RtlAppendUnicodeToString RtlApplyRXact RtlApplyRXactNoFlush RtlAreAllAccessesGranted RtlAreAnyAccessesGranted RtlAreBitsClear RtlAreBitsSet RtlAssert RtlCaptureStackBackTrace RtlCharToInteger RtlCheckRegistryKey RtlClearAllBits RtlClearBits RtlClosePropertySet RtlCompactHeap RtlCompareMemory RtlCompareMemoryUlong RtlCompareString RtlCompareUnicodeString RtlCompressBuffer RtlConsoleMultiByteToUnicodeN RtlConvertExclusiveToShared RtlConvertSharedToExclusive RtlConvertSidToUnicodeString RtlConvertUiListToApiList RtlCopyLuid RtlCopyLuidAndAttributesArray RtlCopySecurityDescriptor RtlCopySid RtlCopySidAndAttributesArray RtlCopyString RtlCopyUnicodeString RtlCreateAcl RtlCreateAndSetSD RtlCreateAtomTable RtlCreateEnvironment RtlCreateProcessParameters RtlCreatePropertySet RtlCreateQueryDebugBuffer RtlCreateRegistryKey RtlCreateSecurityDescriptor RtlCreateTagHeap RtlCreateUnicodeString RtlCreateUnicodeStringFromAsciiz RtlCreateUserProcess RtlCreateUserSecurityObject RtlCreateUserThread RtlCustomCPToUnicodeN RtlCutoverTimeToSystemTime RtlDeNormalizeProcessParams RtlDecompressBuffer RtlDecompressFragment RtlDelete RtlDeleteAce RtlDeleteAtomFromAtomTable RtlDeleteCriticalSection RtlDeleteElementGenericTable RtlDeleteNoSplay RtlDeleteRegistryValue RtlDeleteResource RtlDeleteSecurityObject RtlDestroyAtomTable RtlDestroyEnvironment RtlDestroyHandleTable RtlDestroyProcessParameters RtlDestroyQueryDebugBuffer RtlDetermineDosPathNameType_U RtlDoesFileExists_U RtlDosPathNameToNtPathName_U RtlDosSearchPath_U RtlDowncaseUnicodeString RtlDumpResource RtlEmptyAtomTable RtlEnterCriticalSection RtlEnumProcessHeaps RtlEnumerateGenericTable RtlEnumerateGenericTableWithoutSplaying RtlEnumerateProperties RtlEqualComputerName RtlEqualDomainName RtlEqualLuid RtlEqualPrefixSid RtlEqualSid RtlEqualString RtlEqualUnicodeString RtlEraseUnicodeString RtlExpandEnvironmentStrings_U RtlExtendHeap RtlFillMemory RtlFillMemoryUlong RtlFindClearBits RtlFindClearBitsAndSet RtlFindLongestRunClear RtlFindLongestRunSet RtlFindMessage RtlFindSetBits RtlFindSetBitsAndClear RtlFirstFreeAce RtlFlushPropertySet RtlFormatCurrentUserKeyPath RtlFormatMessage RtlFreeAnsiString RtlFreeHandle RtlFreeOemString RtlFreeSid RtlFreeUnicodeString RtlFreeUserThreadStack RtlGenerate8dot3Name RtlGetAce RtlGetCallersAddress RtlGetCompressionWorkSpaceSize RtlGetControlSecurityDescriptor RtlGetCurrentDirectory_U RtlGetDaclSecurityDescriptor RtlGetElementGenericTable RtlGetFullPathName_U RtlGetGroupSecurityDescriptor RtlGetLongestNtPathLength RtlGetNtGlobalFlags RtlGetNtProductType RtlGetOwnerSecurityDescriptor RtlGetProcessHeaps RtlGetSaclSecurityDescriptor RtlGetUserInfoHeap RtlGuidToPropertySetName RtlIdentifierAuthoritySid RtlImageDirectoryEntryToData RtlImageRvaToSection RtlImageRvaToVa RtlImpersonateSelf RtlInitAnsiString RtlInitCodePageTable RtlInitNlsTables RtlInitString RtlInitUnicodeString RtlInitializeAtomPackage RtlInitializeBitMap RtlInitializeContext RtlInitializeCriticalSection RtlInitializeCriticalSectionAndSpinCount RtlInitializeGenericTable RtlInitializeHandleTable RtlInitializeRXact RtlInitializeResource RtlInitializeSid RtlInsertElementGenericTable RtlIntegerToChar RtlIntegerToUnicodeString RtlIsDosDeviceName_U RtlIsGenericTableEmpty RtlIsNameLegalDOS8Dot3 RtlIsTextUnicode RtlIsValidHandle RtlIsValidIndexHandle RtlLargeIntegerToChar RtlLeaveCriticalSection RtlLengthRequiredSid RtlLengthSecurityDescriptor RtlLengthSid RtlLocalTimeToSystemTime RtlLockHeap RtlLookupAtomInAtomTable RtlLookupElementGenericTable RtlMakeSelfRelativeSD RtlMapGenericMask RtlMoveMemory RtlMultiByteToUnicodeSize RtlNewInstanceSecurityObject RtlNewSecurityGrantedAccess RtlNewSecurityObject RtlNormalizeProcessParams RtlNtStatusToDosError RtlNumberGenericTableElements RtlNumberOfClearBits RtlNumberOfSetBits RtlOemStringToUnicodeSize RtlOemStringToUnicodeString RtlOemToUnicodeN RtlOnMappedStreamEvent RtlOpenCurrentUser RtlPcToFileHeader RtlPinAtomInAtomTable RtlPrefixString RtlPrefixUnicodeString RtlPropertySetNameToGuid RtlProtectHeap RtlQueryAtomInAtomTable RtlQueryEnvironmentVariable_U RtlQueryInformationAcl RtlQueryProcessBackTraceInformation RtlQueryProcessDebugInformation RtlQueryProcessHeapInformation RtlQueryProcessLockInformation RtlQueryProperties RtlQueryPropertyNames RtlQueryPropertySet RtlQueryRegistryValues RtlQuerySecurityObject RtlQueryTagHeap RtlQueryTimeZoneInformation RtlRaiseException RtlRaiseStatus RtlRandom RtlRealPredecessor RtlRealSuccessor RtlReleasePebLock RtlReleaseResource RtlRemoteCall RtlResetRtlTranslations RtlRunDecodeUnicodeString RtlRunEncodeUnicodeString RtlSecondsSince1970ToTime RtlSecondsSince1980ToTime RtlSelfRelativeToAbsoluteSD RtlSetAllBits RtlSetAttributesSecurityDescriptor RtlSetBits RtlSetCriticalSectionSpinCount RtlSetCurrentDirectory_U RtlSetCurrentEnvironment RtlSetDaclSecurityDescriptor RtlSetEnvironmentVariable RtlSetGroupSecurityDescriptor RtlSetInformationAcl RtlSetOwnerSecurityDescriptor RtlSetProperties RtlSetPropertyNames RtlSetPropertySetClassId RtlSetSaclSecurityDescriptor RtlSetSecurityObject RtlSetTimeZoneInformation RtlSetUnicodeCallouts RtlSetUserFlagsHeap RtlSetUserValueHeap RtlSplay RtlStartRXact RtlSubAuthorityCountSid RtlSubAuthoritySid RtlSubtreePredecessor RtlSubtreeSuccessor RtlSystemTimeToLocalTime RtlTimeFieldsToTime RtlTimeToElapsedTimeFields RtlTimeToSecondsSince1970 RtlTimeToSecondsSince1980 RtlTimeToTimeFields RtlTryEnterCriticalSection RtlUnicodeStringToAnsiSize RtlUnicodeStringToCountedOemString RtlUnicodeStringToInteger RtlUnicodeStringToOemSize RtlUnicodeStringToOemString RtlUnicodeToCustomCPN RtlUnicodeToMultiByteSize RtlUnicodeToOemN RtlUniform RtlUnlockHeap RtlUpcaseUnicodeChar RtlUpcaseUnicodeString RtlUpcaseUnicodeStringToAnsiString RtlUpcaseUnicodeStringToCountedOemString RtlUpcaseUnicodeStringToOemString RtlUpcaseUnicodeToCustomCPN RtlUpcaseUnicodeToMultiByteN RtlUpcaseUnicodeToOemN RtlUpperChar RtlUpperString RtlUsageHeap RtlValidAcl RtlValidSecurityDescriptor RtlValidSid RtlValidateProcessHeaps RtlWalkHeap RtlWriteRegistryValue RtlZeroHeap RtlZeroMemory RtlpNtCreateKey RtlpNtEnumerateSubKey RtlpNtMakeTemporaryKey RtlpNtOpenKey RtlpNtQueryValueKey RtlpNtSetValueKey RtlpUnWaitCriticalSection RtlpWaitForCriticalSection RtlxAnsiStringToUnicodeSize RtlxOemStringToUnicodeSize RtlxUnicodeStringToAnsiSize RtlxUnicodeStringToOemSize SaveEm87Context ZwAcceptConnectPort ZwAccessCheck ZwAccessCheckAndAuditAlarm ZwAddAtom ZwAdjustGroupsToken ZwAdjustPrivilegesToken ZwAlertResumeThread ZwAlertThread ZwAllocateLocallyUniqueId ZwAllocateUuids ZwAllocateVirtualMemory ZwCallbackReturn ZwCancelIoFile ZwCancelTimer ZwClearEvent ZwClose ZwCloseObjectAuditAlarm ZwCompleteConnectPort ZwConnectPort ZwContinue ZwCreateChannel ZwCreateDirectoryObject ZwCreateEvent ZwCreateEventPair ZwCreateFile ZwCreateIoCompletion ZwCreateKey ZwCreateMailslotFile ZwCreateMutant ZwCreateNamedPipeFile ZwCreatePagingFile ZwCreatePort ZwCreateProcess ZwCreateProfile ZwCreateSection ZwCreateSemaphore ZwCreateSymbolicLinkObject ZwCreateThread ZwCreateTimer ZwCreateToken ZwDelayExecution ZwDeleteAtom ZwDeleteFile ZwDeleteKey ZwDeleteObjectAuditAlarm ZwDeleteValueKey ZwDeviceIoControlFile ZwDisplayString ZwDuplicateObject ZwDuplicateToken ZwEnumerateKey ZwEnumerateValueKey ZwExtendSection ZwFindAtom ZwFlushBuffersFile ZwFlushInstructionCache ZwFlushKey ZwFlushVirtualMemory ZwFlushWriteBuffer ZwFreeVirtualMemory ZwFsControlFile ZwGetContextThread ZwGetPlugPlayEvent ZwGetTickCount ZwImpersonateClientOfPort ZwImpersonateThread ZwInitializeRegistry ZwListenChannel ZwListenPort ZwLoadDriver ZwLoadKey2 ZwLoadKey ZwLockFile ZwLockVirtualMemory ZwMakeTemporaryObject ZwMapViewOfSection ZwNotifyChangeDirectoryFile ZwNotifyChangeKey ZwOpenChannel ZwOpenDirectoryObject ZwOpenEvent ZwOpenEventPair ZwOpenFile ZwOpenIoCompletion ZwOpenKey ZwOpenMutant ZwOpenObjectAuditAlarm ZwOpenProcess ZwOpenProcessToken ZwOpenSection ZwOpenSemaphore ZwOpenSymbolicLinkObject ZwOpenThread ZwOpenThreadToken ZwOpenTimer ZwPlugPlayControl ZwPrivilegeCheck ZwPrivilegeObjectAuditAlarm ZwPrivilegedServiceAuditAlarm ZwProtectVirtualMemory ZwPulseEvent ZwQueryAttributesFile ZwQueryDefaultLocale ZwQueryDirectoryFile ZwQueryDirectoryObject ZwQueryEaFile ZwQueryEvent ZwQueryFullAttributesFile ZwQueryInformationAtom ZwQueryInformationFile ZwQueryInformationPort ZwQueryInformationProcess ZwQueryInformationThread ZwQueryInformationToken ZwQueryIntervalProfile ZwQueryIoCompletion ZwQueryKey ZwQueryMultipleValueKey ZwQueryMutant ZwQueryObject ZwQueryOleDirectoryFile ZwQueryPerformanceCounter ZwQuerySection ZwQuerySecurityObject ZwQuerySemaphore ZwQuerySymbolicLinkObject ZwQuerySystemEnvironmentValue ZwQuerySystemInformation ZwQuerySystemTime ZwQueryTimer ZwQueryTimerResolution ZwQueryValueKey ZwQueryVirtualMemory ZwQueryVolumeInformationFile ZwQueueApcThread ZwRaiseException ZwRaiseHardError ZwReadFile ZwReadFileScatter ZwReadRequestData ZwReadVirtualMemory ZwRegisterThreadTerminatePort ZwReleaseMutant ZwReleaseSemaphore ZwRemoveIoCompletion ZwReplaceKey ZwReplyPort ZwReplyWaitReceivePort ZwReplyWaitReplyPort ZwReplyWaitSendChannel ZwRequestPort ZwRequestWaitReplyPort ZwResetEvent ZwRestoreKey ZwResumeThread ZwSaveKey ZwSendWaitReplyChannel ZwSetContextChannel ZwSetContextThread ZwSetDefaultHardErrorPort ZwSetDefaultLocale ZwSetEaFile ZwSetEvent ZwSetHighEventPair ZwSetHighWaitLowEventPair ZwSetHighWaitLowThread ZwSetInformationFile ZwSetInformationKey ZwSetInformationObject ZwSetInformationProcess ZwSetInformationThread ZwSetInformationToken ZwSetIntervalProfile ZwSetIoCompletion ZwSetLdtEntries ZwSetLowEventPair ZwSetLowWaitHighEventPair ZwSetLowWaitHighThread ZwSetSecurityObject ZwSetSystemEnvironmentValue ZwSetSystemInformation ZwSetSystemPowerState ZwSetSystemTime ZwSetTimer ZwSetTimerResolution ZwSetValueKey ZwSetVolumeInformationFile ZwShutdownSystem ZwSignalAndWaitForSingleObject ZwStartProfile ZwStopProfile ZwSuspendThread ZwSystemDebugControl ZwTerminateProcess ZwTerminateThread ZwTestAlert ZwUnloadDriver ZwUnloadKey ZwUnlockFile ZwUnlockVirtualMemory ZwUnmapViewOfSection ZwVdmControl ZwWaitForMultipleObjects ZwWaitForSingleObject ZwWaitHighEventPair ZwWaitLowEventPair ZwWriteFile ZwWriteFileGather ZwWriteRequestData ZwWriteVirtualMemory ZwYieldExecution _CIpow __eCommonExceptions __eEmulatorInit __eF2XM1 __eFABS __eFADD32 __eFADD64 __eFADDPreg __eFADDreg __eFADDtop __eFCHS __eFCOM __eFCOM32 __eFCOM64 __eFCOMP __eFCOMP32 __eFCOMP64 __eFCOMPP __eFCOS __eFDECSTP __eFDIV32 __eFDIV64 __eFDIVPreg __eFDIVR32 __eFDIVR64 __eFDIVRPreg __eFDIVRreg __eFDIVRtop __eFDIVreg __eFDIVtop __eFFREE __eFIADD16 __eFIADD32 __eFICOM16 __eFICOM32 __eFICOMP16 __eFICOMP32 __eFIDIV16 __eFIDIV32 __eFIDIVR16 __eFIDIVR32 __eFILD16 __eFILD32 __eFILD64 __eFIMUL16 __eFIMUL32 __eFINCSTP __eFINIT __eFIST16 __eFIST32 __eFISTP16 __eFISTP32 __eFISTP64 __eFISUB16 __eFISUB32 __eFISUBR16 __eFISUBR32 __eFLD1 __eFLD32 __eFLD64 __eFLD80 __eFLDCW __eFLDENV __eFLDL2E __eFLDLN2 __eFLDPI __eFLDZ __eFMUL32 __eFMUL64 __eFMULPreg __eFMULreg __eFMULtop __eFPATAN __eFPREM __eFPREM1 __eFPTAN __eFRNDINT __eFRSTOR __eFSAVE __eFSCALE __eFSIN __eFSQRT __eFST __eFST32 __eFST64 __eFSTCW __eFSTENV __eFSTP __eFSTP32 __eFSTP64 __eFSTP80 __eFSTSW __eFSUB32 __eFSUB64 __eFSUBPreg __eFSUBR32 __eFSUBR64 __eFSUBRPreg __eFSUBRreg __eFSUBRtop __eFSUBreg __eFSUBtop __eFTST __eFUCOM __eFUCOMP __eFUCOMPP __eFXAM __eFXCH __eFXTRACT __eFYL2X __eFYL2XP1 __eGetStatusWord __isascii __iscsym __iscsymf __toascii _alldiv _allmul _alloca_probe _allrem _allshl _allshr _atoi64 _aulldiv _aullrem _aullshr _chkstk _fltused _ftol _i64toa _i64tow _itoa _itow _ltoa _ltow _memccpy _memicmp _snprintf _snwprintf _splitpath _strcmpi _stricmp _strlwr _strnicmp _strupr _tolower _toupper _ultoa _ultow _vsnprintf _wcsicmp _wcslwr _wcsnicmp _wcsupr _wtoi _wtoi64 _wtol abs atan atoi atol ceil cos fabs floor isalnum isalpha iscntrl isdigit isgraph islower isprint ispunct isspace isupper iswalpha iswctype isxdigit labs log mbstowcs memchr memcmp memcpy memmove memset pow qsort sin sprintf sqrt sscanf strcat strchr strcmp strcpy strcspn strlen strncat strncmp strncpy strpbrk strrchr strspn strstr strtol strtoul swprintf tan tolower toupper towlower towupper vsprintf wcscat wcschr wcscmp wcscpy wcscspn wcslen wcsncat wcsncmp wcsncpy wcspbrk wcsrchr wcsspn wcsstr wcstol wcstombs wcstoul

Found follow exports in USER32.DL
BlockInput BroadcastSystemMessageA BroadcastSystemMessageW ChangeDisplaySettingsExA ChangeDisplaySettingsExW ClientThreadSetup CreateDialogIndirectParamAorW DdeGetQualityOfService DeregisterShellHookWindow DialogBoxIndirectParamAorW DrawMenuBarTemp EndMenu EnumDisplayDevicesA EnumDisplayDevicesW FullScreenControl GetAccCursorInfo GetAltTabInfo GetAltTabInfoA GetAltTabInfoW GetAncestor GetAppCompatFlags GetComboBoxInfo GetCursorInfo GetGUIThreadInfo GetListBoxInfo GetMenuBarInfo GetProgmanWindow GetScrollBarInfo GetTaskmanWindow GetTitleBarInfo GetWindowInfo GetWindowModuleFileName GetWindowModuleFileNameA GetWindowModuleFileNameW IsHungAppWindow KillSystemTimer LoadKeyboardLayoutEx LoadLocalFonts LoadRemoteFonts MBToWCSEx MB_GetString MenuWindowProcA MenuWindowProcW MsgWaitForMultipleObjectsEx NotifyWinEvent PrivateExtractIconExA PrivateExtractIconExW PrivateExtractIconsA PrivateExtractIconsW PrivateKDBreakPoint QuerySendMessage RealChildWindowFromPoint RealGetWindowClass RealGetWindowClassA RealGetWindowClassW RegisterServicesProcess RegisterShellHookWindow ScrollChildren SendInput SetConsoleReserveKeys SetCursorContents SetLogonNotifyWindow SetProgmanWindow SetShellWindowEx SetSystemMenu SetSystemTimer SetTaskmanWindow SetWinEventHook SetWindowStationUser ShowStartGlass SoftModalMessageBox ToUnicodeEx TrackMouseEvent TranslateMessageEx UnhookWinEvent UpdatePerUserSystemParameters UserRealizePalette UserRegisterWowHandlers WCSToMBEx

Found follow exports in GDI32.DL
AddFontResourceTracking GdiAddFontResourceW GdiAddGlsBounds GdiAddGlsRecord GdiCleanCacheDC GdiConsoleTextOut GdiConvertAndCheckDC GdiConvertBitmap GdiConvertBrush GdiConvertDC GdiConvertEnhMetaFile GdiConvertFont GdiConvertMetaFilePict GdiConvertPalette GdiConvertRegion GdiConvertToDevmodeW GdiCreateLocalEnhMetaFile GdiCreateLocalMetaFilePict GdiDeleteLocalDC GdiDescribePixelFormat GdiDllInitialize GdiEntry10 GdiEntry11 GdiEntry12 GdiEntry13 GdiEntry14 GdiEntry15 GdiEntry1 GdiEntry2 GdiEntry3 GdiEntry4 GdiEntry5 GdiEntry6 GdiEntry7 GdiEntry8 GdiEntry9 GdiFixUpHandle GdiGetCharDimensions GdiGetCodePage GdiGetLocalBrush GdiGetLocalDC GdiGetLocalFont GdiGetSpoolMessage GdiInitSpool GdiIsMetaFileDC GdiIsMetaPrintDC GdiPerf GdiPlayEMF GdiProcessSetup GdiQueryFonts GdiQueryTable GdiReleaseLocalDC GdiSetAttrs GdiSetPixelFormat GdiSetServerAttr GdiSwapBuffers GdiValidateHandle GetCharWidthInfo GetETM GetEnhMetaFilePixelFormat GetFontResourceInfoW GetGlyphOutlineWow GetHFONT GetRelAbs GetTransform NamedEscape PolyPatBlt RemoveFontResourceTracking SelectBrushLocal SelectFontLocal SetMagicColors SetRelAbs SetVirtualResolution UnloadNetworkFonts UpdateICMRegKey bInitSystemAndFontsDirectoriesW bMakePathNameW cGetTTFFromFOT

Found follow exports in SHELL32.DL
CheckEscapesA Control_FillCache_RunDLL Control_FillCache_RunDLLA Control_FillCache_RunDLLW Control_RunDLLA Control_RunDLLW ExtractIconExW ExtractIconResInfoA ExtractIconResInfoW ExtractVersionResource16W FindExeDlgProc OpenAs_RunDLLA OpenAs_RunDLLW PrintersGetCommand_RunDLLA PrintersGetCommand_RunDLLW SHBrowseForFolderW SheChangeDirExA SheChangeDirW SheConvertPathW SheFullPathA SheFullPathW SheGetCurDrive SheGetDirExW SheGetDirW SheGetPathOffsetW Shell_NotifyIconW ShellExecuteExW ShellHookProc SheRemoveQuotesA SheRemoveQuotesW SheShortenPathA SheShortenPathW SHFileOperationW SHGetDataFromIDListW SHGetFileInfoW SHGetNewLinkInfo SHGetPathFromIDListW SHHelpShortcuts_RunDLLA SHHelpShortcuts_RunDLLW SHUpdateRecycleBinIcon StrChrA StrChrIA StrChrIW StrChrW StrCmpNA StrCmpNIA StrCmpNIW StrCmpNW StrCpyNA StrCpyNW StrNCmpA StrNCmpIA StrNCmpIW StrNCmpW StrNCpyA StrNCpyW StrRChrA StrRChrIA StrRChrIW StrRChrW StrRStrA StrRStrIA StrRStrIW StrRStrW StrStrA StrStrIA StrStrIW StrStrW WOWShellExecute

Found follow exports in COMDLG32.DL
dwLBSubclass dwOKSubclass LoadAlterBitmap WantArrows

Found follow exports in COMCTL32.DL
DllInstall

Found follow exports in ADVAPI32.DL
BuildExplicitAccessWithNameA BuildExplicitAccessWithNameW BuildImpersonateExplicitAccessWithNameA BuildImpersonateExplicitAccessWithNameW BuildImpersonateTrusteeA BuildImpersonateTrusteeW BuildSecurityDescriptorA BuildSecurityDescriptorW BuildTrusteeWithNameA BuildTrusteeWithNameW BuildTrusteeWithSidA BuildTrusteeWithSidW CancelOverlappedAccess ConvertAccessToSecurityDescriptorA ConvertAccessToSecurityDescriptorW ConvertSecurityDescriptorToAccessA ConvertSecurityDescriptorToAccessNamedA ConvertSecurityDescriptorToAccessNamedW ConvertSecurityDescriptorToAccessW CryptAcquireContextW CryptSetProviderW CryptSignHashW CryptVerifySignatureW DuplicateTokenEx ElfBackupEventLogFileA ElfBackupEventLogFileW ElfChangeNotify ElfClearEventLogFileA ElfClearEventLogFileW ElfCloseEventLog ElfDeregisterEventSource ElfNumberOfRecords ElfOldestRecord ElfOpenBackupEventLogA ElfOpenBackupEventLogW ElfOpenEventLogA ElfOpenEventLogW ElfReadEventLogA ElfReadEventLogW ElfRegisterEventSourceA ElfRegisterEventSourceW ElfReportEventA ElfReportEventW EnumServiceGroupW EnumServicesStatusExA EnumServicesStatusExW GetAccessPermissionsForObjectA GetAccessPermissionsForObjectW GetAuditedPermissionsFromAclA GetAuditedPermissionsFromAclW GetCurrentHwProfileA GetCurrentHwProfileW GetEffectiveRightsFromAclA GetEffectiveRightsFromAclW GetExplicitEntriesFromAclA GetExplicitEntriesFromAclW GetMultipleTrusteeA GetMultipleTrusteeOperationA GetMultipleTrusteeOperationW GetMultipleTrusteeW GetNamedSecurityInfoA GetNamedSecurityInfoExA GetNamedSecurityInfoExW GetNamedSecurityInfoW GetOverlappedAccessResults GetSecurityInfo GetSecurityInfoExA GetSecurityInfoExW GetTrusteeNameA GetTrusteeNameW GetTrusteeTypeA GetTrusteeTypeW I_ScGetCurrentGroupStateW I_ScSetServiceBitsA I_ScSetServiceBitsW LookupSecurityDescriptorPartsA LookupSecurityDescriptorPartsW LsaAddAccountRights LsaAddPrivilegesToAccount LsaClearAuditLog LsaClose LsaCreateAccount LsaCreateSecret LsaCreateTrustedDomain LsaDelete LsaDeleteTrustedDomain LsaEnumerateAccountRights LsaEnumerateAccounts LsaEnumerateAccountsWithUserRight LsaEnumeratePrivileges LsaEnumeratePrivilegesOfAccount LsaEnumerateTrustedDomains LsaFreeMemory LsaGetQuotasForAccount LsaGetRemoteUserName LsaGetSystemAccessAccount LsaGetUserName LsaICLookupNames LsaICLookupSids LsaLookupNames LsaLookupPrivilegeDisplayName LsaLookupPrivilegeName LsaLookupPrivilegeValue LsaLookupSids LsaNtStatusToWinError LsaOpenAccount LsaOpenPolicy LsaOpenSecret LsaOpenTrustedDomain LsaQueryInfoTrustedDomain LsaQueryInformationPolicy LsaQuerySecret LsaQuerySecurityObject LsaQueryTrustedDomainInfo LsaRemoveAccountRights LsaRemovePrivilegesFromAccount LsaRetrievePrivateData LsaSetInformationPolicy LsaSetInformationTrustedDomain LsaSetQuotasForAccount LsaSetSecret LsaSetSecurityObject LsaSetSystemAccessAccount LsaSetTrustedDomainInformation LsaStorePrivateData ObjectDeleteAuditAlarmA ObjectDeleteAuditAlarmW QueryServiceStatusEx QueryWindows31FilesMigration SetEntriesInAccessListA SetEntriesInAccessListW SetEntriesInAclA SetEntriesInAclW SetEntriesInAuditListA SetEntriesInAuditListW SetNamedSecurityInfoA SetNamedSecurityInfoExA SetNamedSecurityInfoExW SetNamedSecurityInfoW SetSecurityInfo SetSecurityInfoExA SetSecurityInfoExW SynchronizeWindows31FilesAndWindowsNTRegistry SystemFunction001 SystemFunction002 SystemFunction003 SystemFunction004 SystemFunction005 SystemFunction006 SystemFunction007 SystemFunction008 SystemFunction009 SystemFunction010 SystemFunction011 SystemFunction012 SystemFunction013 SystemFunction014 SystemFunction015 SystemFunction016 SystemFunction017 SystemFunction018 SystemFunction019 SystemFunction020 SystemFunction021 SystemFunction022 SystemFunction023 SystemFunction024 SystemFunction025 SystemFunction026 SystemFunction027 SystemFunction028 SystemFunction029 SystemFunction030 SystemFunction031 SystemFunction032 SystemFunction033 TrusteeAccessToObjectA TrusteeAccessToObjectW

Found follow exports in WSOCK32.DL
MigrateWinsockConfiguration WEP WSApSetPostRoutine inet_network getnetbyname rcmd rexec rresvport sethostname AcceptEx GetAcceptExSockaddrs

Found follow exports in WS2_32.DL
accept bind closesocket connect getpeername getsockname getsockopt htonl htons ioctlsocket inet_addr inet_ntoa listen ntohl ntohs recv recvfrom select send sendto setsockopt shutdown socket WSApSetPostRoutine WPUCompleteOverlappedRequest WSAAccept WSAAddressToStringA WSAAddressToStringW WSACloseEvent WSAConnect WSACreateEvent WSADuplicateSocketA WSADuplicateSocketW WSAEnumNameSpaceProvidersA WSAEnumNameSpaceProvidersW WSAEnumNetworkEvents WSAEnumProtocolsA WSAEnumProtocolsW WSAEventSelect WSAGetOverlappedResult WSAGetQOSByName WSAGetServiceClassInfoA WSAGetServiceClassInfoW WSAGetServiceClassNameByClassIdA WSAGetServiceClassNameByClassIdW WSAHtonl WSAHtons WSAInstallServiceClassA WSAInstallServiceClassW WSAIoctl gethostbyaddr gethostbyname getprotobyname getprotobynumber getservbyname getservbyport gethostname WSAJoinLeaf WSALookupServiceBeginA WSALookupServiceBeginW WSALookupServiceEnd WSALookupServiceNextA WSALookupServiceNextW WSANtohl WSANtohs WSAProviderConfigChange WSARecv WSARecvDisconnect WSARecvFrom WSARemoveServiceClass WSAResetEvent WSASend WSASendDisconnect WSASendTo WSASetEvent WSASetServiceA WSASetServiceW WSASocketA WSASocketW WSAStringToAddressA WSAStringToAddressW WSAWaitForMultipleEvents WSCDeinstallProvider WSCEnableNSProvider WSCEnumProtocols WSCGetProviderPath WSCInstallNameSpace WSCInstallProvider WSCUnInstallNameSpace WSAAsyncSelect WSAAsyncGetHostByAddr WSAAsyncGetHostByName WSAAsyncGetProtoByNumber WSAAsyncGetProtoByName WSAAsyncGetServByPort WSAAsyncGetServByName WSACancelAsyncRequest WSASetBlockingHook WSAUnhookBlockingHook WSAGetLastError WSASetLastError WSACancelBlockingCall WSAIsBlocking WSAStartup WSACleanup __WSAFDIsSet WEP

Windows 2000


Found follow exports in KERNEL32.DL
AddConsoleAliasA AddConsoleAliasW AllocateUserPhysicalPages AssignProcessToJobObject BaseAttachCompleteThunk BindIoCompletionCallback CancelDeviceWakeupRequest CancelIo CancelTimerQueueTimer CancelWaitableTimer ChangeTimerQueueTimer CloseConsoleHandle CmdBatNotification ConsoleMenuControl ConvertThreadToFiber CopyFileExA CopyFileExW CreateFiber CreateFiberEx CreateHardLinkA CreateHardLinkW CreateJobObjectA CreateJobObjectW CreateProcessInternalA CreateProcessInternalW CreateProcessInternalWSecure CreateTimerQueue CreateTimerQueueTimer CreateToolhelp32Snapshot CreateVirtualBuffer CreateWaitableTimerA CreateWaitableTimerW DelayLoadFailureHook DeleteFiber DeleteTimerQueue DeleteTimerQueueEx DeleteTimerQueueTimer DeleteVolumeMountPointA DeleteVolumeMountPointW DnsHostnameToComputerNameA DnsHostnameToComputerNameW DosPathToSessionPathA DosPathToSessionPathW DuplicateConsoleHandle EnumCalendarInfoExA EnumCalendarInfoExW EnumDateFormatsExA EnumDateFormatsExW EnumLanguageGroupLocalesA EnumLanguageGroupLocalesW EnumSystemLanguageGroupsA EnumSystemLanguageGroupsW EnumUILanguagesA EnumUILanguagesW ExitVDM ExpungeConsoleCommandHistoryA ExpungeConsoleCommandHistoryW ExtendVirtualBuffer FindFirstFileExA FindFirstFileExW FindFirstVolumeA FindFirstVolumeMountPointA FindFirstVolumeMountPointW FindFirstVolumeW FindNextVolumeA FindNextVolumeMountPointA FindNextVolumeMountPointW FindNextVolumeW FindVolumeClose FindVolumeMountPointClose FreeUserPhysicalPages FreeVirtualBuffer GetCPInfoExA GetCPInfoExW GetCalendarInfoA GetCalendarInfoW GetComputerNameExA GetComputerNameExW GetConsoleAliasA GetConsoleAliasExesA GetConsoleAliasExesLengthA GetConsoleAliasExesLengthW GetConsoleAliasExesW GetConsoleAliasW GetConsoleAliasesA GetConsoleAliasesLengthA GetConsoleAliasesLengthW GetConsoleAliasesW GetConsoleCharType GetConsoleCommandHistoryA GetConsoleCommandHistoryLengthA GetConsoleCommandHistoryLengthW GetConsoleCommandHistoryW GetConsoleCursorMode GetConsoleDisplayMode GetConsoleFontInfo GetConsoleFontSize GetConsoleHardwareState GetConsoleInputExeNameA GetConsoleInputExeNameW GetConsoleInputWaitHandle GetConsoleKeyboardLayoutNameA GetConsoleKeyboardLayoutNameW GetConsoleNlsMode GetConsoleWindow GetCurrentConsoleFont GetDefaultSortkeySize GetDevicePowerState GetFileAttributesExA GetFileAttributesExW GetFileSizeEx GetLinguistLangSize GetLongPathNameA GetLongPathNameW GetNextVDMCommand GetNlsSectionName GetNumberOfConsoleFonts GetProcessIoCounters GetProcessPriorityBoost GetSystemDefaultUILanguage GetSystemWindowsDirectoryA GetSystemWindowsDirectoryW GetThreadPriorityBoost GetUserDefaultUILanguage GetVDMCurrentDirectories GetVolumeNameForVolumeMountPointA GetVolumeNameForVolumeMountPointW GetVolumePathNameA GetVolumePathNameW GetWriteWatch GlobalMemoryStatusEx Heap32First Heap32ListFirst Heap32ListNext Heap32Next HeapCreateTagsW HeapExtend HeapQueryInformation HeapQueryTagW HeapSetInformation HeapSummary HeapUsage InitializeCriticalSectionAndSpinCount InterlockedCompareExchange InterlockedExchangeAdd InvalidateConsoleDIBits IsDebuggerPresent IsProcessorFeaturePresent IsSystemResumeAutomatic IsValidLanguageGroup MapUserPhysicalPages MapUserPhysicalPagesScatter Module32First Module32FirstW Module32Next Module32NextW MoveFileWithProgressA MoveFileWithProgressW NlsConvertIntegerToString NlsGetCacheUpdateCount NlsResetProcessLocale OpenConsoleW OpenDataFile OpenJobObjectA OpenJobObjectW OpenThread OpenWaitableTimerA OpenWaitableTimerW PrivCopyFileExW PrivMoveFileIdentityW Process32First Process32FirstW Process32Next Process32NextW ProcessIdToSessionId QueryInformationJobObject QueryWin31IniFilesMappedToRegistry QueueUserWorkItem ReadConsoleInputExA ReadConsoleInputExW ReadDirectoryChangesW ReadFileScatter RegisterConsoleIME RegisterConsoleOS2 RegisterConsoleVDM RegisterWaitForInputIdle RegisterWaitForSingleObject RegisterWaitForSingleObjectEx RegisterWowBaseHandlers RegisterWowExec ReplaceFile ReplaceFileA ReplaceFileW RequestDeviceWakeup RequestWakeupLatency ResetWriteWatch SetCPGlobal SetCalendarInfoA SetCalendarInfoW SetComputerNameExA SetComputerNameExW SetConsoleCommandHistoryMode SetConsoleCursor SetConsoleCursorMode SetConsoleDisplayMode SetConsoleFont SetConsoleHardwareState SetConsoleIcon SetConsoleInputExeNameA SetConsoleInputExeNameW SetConsoleKeyShortcuts SetConsoleLocalEUDC SetConsoleMaximumWindowSize SetConsoleMenuClose SetConsoleNlsMode SetConsoleNumberOfCommandsA SetConsoleNumberOfCommandsW SetConsoleOS2OemFormat SetConsolePalette SetCriticalSectionSpinCount SetFilePointerEx SetInformationJobObject SetLastConsoleEventActive SetMessageWaitingIndicator SetProcessAffinityMask SetProcessPriorityBoost SetTermsrvAppInstallMode SetThreadExecutionState SetThreadIdealProcessor SetThreadPriorityBoost SetTimerQueueTimer SetVDMCurrentDirectories SetVolumeMountPointA SetVolumeMountPointW SetWaitableTimer ShowConsoleCursor SignalObjectAndWait SwitchToFiber SwitchToThread TerminateJobObject TermsrvAppInstallMode Thread32First Thread32Next Toolhelp32ReadProcessMemory TrimVirtualBuffer TryEnterCriticalSection UTRegister UTUnRegister UnregisterConsoleIME UnregisterWait UnregisterWaitEx VDMConsoleOperation VDMOperationStarted ValidateLCType ValidateLocale VerSetConditionMask VerifyConsoleIoHandle VerifyVersionInfoA VerifyVersionInfoW VirtualAllocEx VirtualBufferExceptionHandler VirtualFreeEx WriteConsoleInputVDMA WriteConsoleInputVDMW WriteFileGather

Found follow exports in NTDLL.DL
PropertyLengthAsVariant RtlConvertPropertyToVariant RtlConvertVariantToProperty RtlUlongByteSwap RtlUlonglongByteSwap RtlUshortByteSwap CsrAllocateCaptureBuffer CsrAllocateMessagePointer CsrCaptureMessageBuffer CsrCaptureMessageString CsrCaptureTimeout CsrClientCallServer CsrClientConnectToServer CsrFreeCaptureBuffer CsrIdentifyAlertableThread CsrNewThread CsrProbeForRead CsrProbeForWrite CsrSetPriorityClass DbgPrintReturnControlC DbgSsHandleKmApiMsg DbgSsInitialize DbgUiConnectToDbg DbgUiContinue DbgUiWaitStateChange DbgUserBreakPoint KiRaiseUserExceptionDispatcher KiUserApcDispatcher KiUserCallbackDispatcher KiUserExceptionDispatcher LdrAccessResource LdrAlternateResourcesEnabled LdrDisableThreadCalloutsForDll LdrEnumResources LdrFindEntryForAddress LdrFindResourceDirectory_U LdrFindResource_U LdrFlushAlternateResourceModules LdrGetDllHandle LdrGetProcedureAddress LdrInitializeThunk LdrLoadAlternateResourceModule LdrLoadDll LdrProcessRelocationBlock LdrQueryImageFileExecutionOptions LdrQueryProcessModuleInformation LdrShutdownProcess LdrShutdownThread LdrUnloadAlternateResourceModule LdrUnloadDll LdrVerifyImageMatchesChecksum NPXEMULATORTABLE NlsAnsiCodePage NlsMbCodePageTag NlsMbOemCodePageTag NtAcceptConnectPort NtAccessCheck NtAccessCheckAndAuditAlarm NtAccessCheckByType NtAccessCheckByTypeAndAuditAlarm NtAccessCheckByTypeResultList NtAccessCheckByTypeResultListAndAuditAlarm NtAccessCheckByTypeResultListAndAuditAlarmByHandle NtAddAtom NtAdjustGroupsToken NtAdjustPrivilegesToken NtAlertResumeThread NtAlertThread NtAllocateLocallyUniqueId NtAllocateUserPhysicalPages NtAllocateUuids NtAllocateVirtualMemory NtAreMappedFilesTheSame NtAssignProcessToJobObject NtCallbackReturn NtCancelDeviceWakeupRequest NtCancelIoFile NtCancelTimer NtClearEvent NtClose NtCloseObjectAuditAlarm NtCompleteConnectPort NtConnectPort NtContinue NtCreateChannel NtCreateDirectoryObject NtCreateEvent NtCreateEventPair NtCreateFile NtCreateIoCompletion NtCreateJobObject NtCreateKey NtCreateMailslotFile NtCreateMutant NtCreateNamedPipeFile NtCreatePagingFile NtCreatePort NtCreateProcess NtCreateProfile NtCreateSection NtCreateSemaphore NtCreateSymbolicLinkObject NtCreateThread NtCreateTimer NtCreateToken NtCreateWaitablePort NtDelayExecution NtDeleteAtom NtDeleteFile NtDeleteKey NtDeleteObjectAuditAlarm NtDeleteValueKey NtDeviceIoControlFile NtDisplayString NtDuplicateObject NtDuplicateToken NtEnumerateKey NtEnumerateValueKey NtExtendSection NtFilterToken NtFindAtom NtFlushBuffersFile NtFlushInstructionCache NtFlushKey NtFlushVirtualMemory NtFlushWriteBuffer NtFreeUserPhysicalPages NtFreeVirtualMemory NtFsControlFile NtGetContextThread NtGetDevicePowerState NtGetPlugPlayEvent NtGetTickCount NtGetWriteWatch NtImpersonateAnonymousToken NtImpersonateClientOfPort NtImpersonateThread NtInitializeRegistry NtInitiatePowerAction NtIsSystemResumeAutomatic NtListenChannel NtListenPort NtLoadDriver NtLoadKey2 NtLoadKey NtLockFile NtLockVirtualMemory NtMakeTemporaryObject NtMapUserPhysicalPages NtMapUserPhysicalPagesScatter NtMapViewOfSection NtNotifyChangeDirectoryFile NtNotifyChangeKey NtNotifyChangeMultipleKeys NtOpenChannel NtOpenDirectoryObject NtOpenEvent NtOpenEventPair NtOpenFile NtOpenIoCompletion NtOpenJobObject NtOpenKey NtOpenMutant NtOpenObjectAuditAlarm NtOpenProcess NtOpenProcessToken NtOpenSection NtOpenSemaphore NtOpenSymbolicLinkObject NtOpenThread NtOpenThreadToken NtOpenTimer NtPlugPlayControl NtPowerInformation NtPrivilegeCheck NtPrivilegeObjectAuditAlarm NtPrivilegedServiceAuditAlarm NtProtectVirtualMemory NtPulseEvent NtQueryAttributesFile NtQueryDefaultLocale NtQueryDefaultUILanguage NtQueryDirectoryFile NtQueryDirectoryObject NtQueryEaFile NtQueryEvent NtQueryFullAttributesFile NtQueryInformationAtom NtQueryInformationFile NtQueryInformationJobObject NtQueryInformationPort NtQueryInformationProcess NtQueryInformationThread NtQueryInformationToken NtQueryInstallUILanguage NtQueryIntervalProfile NtQueryIoCompletion NtQueryKey NtQueryMultipleValueKey NtQueryMutant NtQueryObject NtQueryOpenSubKeys NtQueryQuotaInformationFile NtQuerySection NtQuerySecurityObject NtQuerySemaphore NtQuerySymbolicLinkObject NtQuerySystemEnvironmentValue NtQuerySystemInformation NtQuerySystemTime NtQueryTimer NtQueryTimerResolution NtQueryValueKey NtQueryVirtualMemory NtQueryVolumeInformationFile NtQueueApcThread NtRaiseException NtRaiseHardError NtReadFile NtReadFileScatter NtReadRequestData NtReadVirtualMemory NtRegisterThreadTerminatePort NtReleaseMutant NtReleaseSemaphore NtRemoveIoCompletion NtReplaceKey NtReplyPort NtReplyWaitReceivePort NtReplyWaitReceivePortEx NtReplyWaitReplyPort NtReplyWaitSendChannel NtRequestDeviceWakeup NtRequestPort NtRequestWaitReplyPort NtRequestWakeupLatency NtResetEvent NtResetWriteWatch NtRestoreKey NtResumeThread NtSaveKey NtSaveMergedKeys NtSecureConnectPort NtSendWaitReplyChannel NtSetContextChannel NtSetContextThread NtSetDefaultHardErrorPort NtSetDefaultLocale NtSetDefaultUILanguage NtSetEaFile NtSetEvent NtSetHighEventPair NtSetHighWaitLowEventPair NtSetInformationFile NtSetInformationJobObject NtSetInformationKey NtSetInformationObject NtSetInformationProcess NtSetInformationThread NtSetInformationToken NtSetIntervalProfile NtSetIoCompletion NtSetLdtEntries NtSetLowEventPair NtSetLowWaitHighEventPair NtSetQuotaInformationFile NtSetSecurityObject NtSetSystemEnvironmentValue NtSetSystemInformation NtSetSystemPowerState NtSetSystemTime NtSetThreadExecutionState NtSetTimer NtSetTimerResolution NtSetUuidSeed NtSetValueKey NtSetVolumeInformationFile NtShutdownSystem NtSignalAndWaitForSingleObject NtStartProfile NtStopProfile NtSuspendThread NtSystemDebugControl NtTerminateJobObject NtTerminateProcess NtTerminateThread NtTestAlert NtUnloadDriver NtUnloadKey NtUnlockFile NtUnlockVirtualMemory NtUnmapViewOfSection NtVdmControl NtWaitForMultipleObjects NtWaitForSingleObject NtWaitHighEventPair NtWaitLowEventPair NtWriteFile NtWriteFileGather NtWriteRequestData NtWriteVirtualMemory NtYieldExecution PfxFindPrefix PfxInitialize PfxInsertPrefix PfxRemovePrefix RestoreEm87Context RtlAbortRXact RtlAbsoluteToSelfRelativeSD RtlAcquirePebLock RtlAcquireResourceExclusive RtlAcquireResourceShared RtlAddAccessAllowedAce RtlAddAccessAllowedAceEx RtlAddAccessAllowedObjectAce RtlAddAccessDeniedAce RtlAddAccessDeniedAceEx RtlAddAccessDeniedObjectAce RtlAddAce RtlAddActionToRXact RtlAddAtomToAtomTable RtlAddAttributeActionToRXact RtlAddAuditAccessAce RtlAddAuditAccessAceEx RtlAddAuditAccessObjectAce RtlAddCompoundAce RtlAddRange RtlAdjustPrivilege RtlAllocateAndInitializeSid RtlAllocateHandle RtlAnsiCharToUnicodeChar RtlAnsiStringToUnicodeSize RtlAppendAsciizToString RtlAppendStringToString RtlAppendUnicodeStringToString RtlAppendUnicodeToString RtlApplyRXact RtlApplyRXactNoFlush RtlAreAllAccessesGranted RtlAreAnyAccessesGranted RtlAreBitsClear RtlAreBitsSet RtlAssert RtlCallbackLpcClient RtlCancelTimer RtlCaptureStackBackTrace RtlCharToInteger RtlCheckForOrphanedCriticalSections RtlCheckRegistryKey RtlClearAllBits RtlClearBits RtlCompactHeap RtlCompareMemory RtlCompareMemoryUlong RtlCompareString RtlCompareUnicodeString RtlCompressBuffer RtlConsoleMultiByteToUnicodeN RtlConvertExclusiveToShared RtlConvertSharedToExclusive RtlConvertSidToUnicodeString RtlConvertToAutoInheritSecurityObject RtlConvertUiListToApiList RtlCopyLuid RtlCopyLuidAndAttributesArray RtlCopyRangeList RtlCopySecurityDescriptor RtlCopySid RtlCopySidAndAttributesArray RtlCopyString RtlCopyUnicodeString RtlCreateAcl RtlCreateAndSetSD RtlCreateAtomTable RtlCreateEnvironment RtlCreateLpcServer RtlCreateProcessParameters RtlCreateQueryDebugBuffer RtlCreateRegistryKey RtlCreateSecurityDescriptor RtlCreateTagHeap RtlCreateTimer RtlCreateTimerQueue RtlCreateUnicodeString RtlCreateUnicodeStringFromAsciiz RtlCreateUserProcess RtlCreateUserSecurityObject RtlCreateUserThread RtlCustomCPToUnicodeN RtlCutoverTimeToSystemTime RtlDeNormalizeProcessParams RtlDebugPrintTimes RtlDecompressBuffer RtlDecompressFragment RtlDefaultNpAcl RtlDelete RtlDeleteAce RtlDeleteAtomFromAtomTable RtlDeleteCriticalSection RtlDeleteElementGenericTable RtlDeleteNoSplay RtlDeleteOwnersRanges RtlDeleteRange RtlDeleteRegistryValue RtlDeleteResource RtlDeleteSecurityObject RtlDeleteTimer RtlDeleteTimerQueue RtlDeleteTimerQueueEx RtlDeregisterWait RtlDeregisterWaitEx RtlDestroyAtomTable RtlDestroyEnvironment RtlDestroyHandleTable RtlDestroyProcessParameters RtlDestroyQueryDebugBuffer RtlDetermineDosPathNameType_U RtlDnsHostNameToComputerName RtlDoesFileExists_U RtlDosPathNameToNtPathName_U RtlDosSearchPath_U RtlDowncaseUnicodeString RtlDumpResource RtlEmptyAtomTable RtlEnableEarlyCriticalSectionEventCreation RtlEnterCriticalSection RtlEnumProcessHeaps RtlEnumerateGenericTable RtlEnumerateGenericTableWithoutSplaying RtlEqualComputerName RtlEqualDomainName RtlEqualLuid RtlEqualPrefixSid RtlEqualSid RtlEqualString RtlEqualUnicodeString RtlEraseUnicodeString RtlExpandEnvironmentStrings_U RtlExtendHeap RtlFillMemory RtlFillMemoryUlong RtlFindClearBits RtlFindClearBitsAndSet RtlFindLastBackwardRunClear RtlFindLeastSignificantBit RtlFindLongestRunClear RtlFindMessage RtlFindMostSignificantBit RtlFindNextForwardRunClear RtlFindRange RtlFindSetBits RtlFindSetBitsAndClear RtlFirstFreeAce RtlFormatCurrentUserKeyPath RtlFormatMessage RtlFreeAnsiString RtlFreeHandle RtlFreeOemString RtlFreeRangeList RtlFreeSid RtlFreeUnicodeString RtlFreeUserThreadStack RtlGUIDFromString RtlGenerate8dot3Name RtlGetAce RtlGetCallersAddress RtlGetCompressionWorkSpaceSize RtlGetControlSecurityDescriptor RtlGetCurrentDirectory_U RtlGetDaclSecurityDescriptor RtlGetElementGenericTable RtlGetFirstRange RtlGetFullPathName_U RtlGetGroupSecurityDescriptor RtlGetLongestNtPathLength RtlGetNextRange RtlGetNtGlobalFlags RtlGetNtProductType RtlGetOwnerSecurityDescriptor RtlGetProcessHeaps RtlGetSaclSecurityDescriptor RtlGetSecurityDescriptorRMControl RtlGetUserInfoHeap RtlGetVersion RtlIdentifierAuthoritySid RtlImageDirectoryEntryToData RtlImageRvaToSection RtlImageRvaToVa RtlImpersonateLpcClient RtlImpersonateSelf RtlInitAnsiString RtlInitCodePageTable RtlInitNlsTables RtlInitString RtlInitUnicodeString RtlInitializeAtomPackage RtlInitializeBitMap RtlInitializeContext RtlInitializeCriticalSection RtlInitializeCriticalSectionAndSpinCount RtlInitializeGenericTable RtlInitializeHandleTable RtlInitializeRXact RtlInitializeRangeList RtlInitializeResource RtlInitializeSid RtlInsertElementGenericTable RtlInt64ToUnicodeString RtlIntegerToChar RtlIntegerToUnicodeString RtlInvertRangeList RtlIsDosDeviceName_U RtlIsGenericTableEmpty RtlIsNameLegalDOS8Dot3 RtlIsRangeAvailable RtlIsTextUnicode RtlIsValidHandle RtlIsValidIndexHandle RtlLargeIntegerToChar RtlLeaveCriticalSection RtlLengthRequiredSid RtlLengthSecurityDescriptor RtlLengthSid RtlLocalTimeToSystemTime RtlLockHeap RtlLookupAtomInAtomTable RtlLookupElementGenericTable RtlMakeSelfRelativeSD RtlMapGenericMask RtlMergeRangeLists RtlMoveMemory RtlMultiByteToUnicodeSize RtlNewInstanceSecurityObject RtlNewSecurityGrantedAccess RtlNewSecurityObject RtlNewSecurityObjectEx RtlNormalizeProcessParams RtlNtStatusToDosError RtlNumberGenericTableElements RtlNumberOfClearBits RtlNumberOfSetBits RtlOemStringToUnicodeSize RtlOemStringToUnicodeString RtlOemToUnicodeN RtlOpenCurrentUser RtlPcToFileHeader RtlPinAtomInAtomTable RtlPrefixString RtlPrefixUnicodeString RtlProtectHeap RtlQueryAtomInAtomTable RtlQueryEnvironmentVariable_U RtlQueryHeapInformation RtlQueryInformationAcl RtlQueryProcessBackTraceInformation RtlQueryProcessDebugInformation RtlQueryProcessHeapInformation RtlQueryProcessLockInformation RtlQueryRegistryValues RtlQuerySecurityObject RtlQueryTagHeap RtlQueryTimeZoneInformation RtlQueueWorkItem RtlRaiseException RtlRaiseStatus RtlRandom RtlRealPredecessor RtlRealSuccessor RtlRegisterWait RtlReleasePebLock RtlReleaseResource RtlRemoteCall RtlResetRtlTranslations RtlRunDecodeUnicodeString RtlRunEncodeUnicodeString RtlSecondsSince1970ToTime RtlSecondsSince1980ToTime RtlSelfRelativeToAbsoluteSD2 RtlSelfRelativeToAbsoluteSD RtlSetAllBits RtlSetAttributesSecurityDescriptor RtlSetBits RtlSetControlSecurityDescriptor RtlSetCriticalSectionSpinCount RtlSetCurrentDirectory_U RtlSetCurrentEnvironment RtlSetDaclSecurityDescriptor RtlSetEnvironmentVariable RtlSetGroupSecurityDescriptor RtlSetHeapInformation RtlSetInformationAcl RtlSetIoCompletionCallback RtlSetOwnerSecurityDescriptor RtlSetSaclSecurityDescriptor RtlSetSecurityDescriptorRMControl RtlSetSecurityObject RtlSetSecurityObjectEx RtlSetThreadPoolStartFunc RtlSetTimeZoneInformation RtlSetTimer RtlSetUnicodeCallouts RtlSetUserFlagsHeap RtlSetUserValueHeap RtlShutdownLpcServer RtlSplay RtlStartRXact RtlStringFromGUID RtlSubAuthorityCountSid RtlSubAuthoritySid RtlSubtreePredecessor RtlSubtreeSuccessor RtlSystemTimeToLocalTime RtlTimeFieldsToTime RtlTimeToElapsedTimeFields RtlTimeToSecondsSince1970 RtlTimeToSecondsSince1980 RtlTimeToTimeFields RtlTraceDatabaseAdd RtlTraceDatabaseCreate RtlTraceDatabaseDestroy RtlTraceDatabaseEnumerate RtlTraceDatabaseFind RtlTraceDatabaseLock RtlTraceDatabaseUnlock RtlTraceDatabaseValidate RtlTryEnterCriticalSection RtlUnicodeStringToAnsiSize RtlUnicodeStringToCountedOemString RtlUnicodeStringToInteger RtlUnicodeStringToOemSize RtlUnicodeStringToOemString RtlUnicodeToCustomCPN RtlUnicodeToMultiByteSize RtlUnicodeToOemN RtlUniform RtlUnlockHeap RtlUpcaseUnicodeChar RtlUpcaseUnicodeString RtlUpcaseUnicodeStringToAnsiString RtlUpcaseUnicodeStringToCountedOemString RtlUpcaseUnicodeStringToOemString RtlUpcaseUnicodeToCustomCPN RtlUpcaseUnicodeToMultiByteN RtlUpcaseUnicodeToOemN RtlUpdateTimer RtlUpperChar RtlUpperString RtlUsageHeap RtlValidAcl RtlValidRelativeSecurityDescriptor RtlValidSecurityDescriptor RtlValidSid RtlValidateProcessHeaps RtlVerifyVersionInfo RtlWalkFrameChain RtlWalkHeap RtlWriteRegistryValue RtlZeroHeap RtlZeroMemory RtlpNtCreateKey RtlpNtEnumerateSubKey RtlpNtMakeTemporaryKey RtlpNtOpenKey RtlpNtQueryValueKey RtlpNtSetValueKey RtlpUnWaitCriticalSection RtlpWaitForCriticalSection RtlxAnsiStringToUnicodeSize RtlxOemStringToUnicodeSize RtlxUnicodeStringToAnsiSize RtlxUnicodeStringToOemSize SaveEm87Context VerSetConditionMask ZwAcceptConnectPort ZwAccessCheck ZwAccessCheckAndAuditAlarm ZwAccessCheckByType ZwAccessCheckByTypeAndAuditAlarm ZwAccessCheckByTypeResultList ZwAccessCheckByTypeResultListAndAuditAlarm ZwAccessCheckByTypeResultListAndAuditAlarmByHandle ZwAddAtom ZwAdjustGroupsToken ZwAdjustPrivilegesToken ZwAlertResumeThread ZwAlertThread ZwAllocateLocallyUniqueId ZwAllocateUserPhysicalPages ZwAllocateUuids ZwAllocateVirtualMemory ZwAreMappedFilesTheSame ZwAssignProcessToJobObject ZwCallbackReturn ZwCancelDeviceWakeupRequest ZwCancelIoFile ZwCancelTimer ZwClearEvent ZwClose ZwCloseObjectAuditAlarm ZwCompleteConnectPort ZwConnectPort ZwContinue ZwCreateChannel ZwCreateDirectoryObject ZwCreateEvent ZwCreateEventPair ZwCreateFile ZwCreateIoCompletion ZwCreateJobObject ZwCreateKey ZwCreateMailslotFile ZwCreateMutant ZwCreateNamedPipeFile ZwCreatePagingFile ZwCreatePort ZwCreateProcess ZwCreateProfile ZwCreateSection ZwCreateSemaphore ZwCreateSymbolicLinkObject ZwCreateThread ZwCreateTimer ZwCreateToken ZwCreateWaitablePort ZwDelayExecution ZwDeleteAtom ZwDeleteFile ZwDeleteKey ZwDeleteObjectAuditAlarm ZwDeleteValueKey ZwDeviceIoControlFile ZwDisplayString ZwDuplicateObject ZwDuplicateToken ZwEnumerateKey ZwEnumerateValueKey ZwExtendSection ZwFilterToken ZwFindAtom ZwFlushBuffersFile ZwFlushInstructionCache ZwFlushKey ZwFlushVirtualMemory ZwFlushWriteBuffer ZwFreeUserPhysicalPages ZwFreeVirtualMemory ZwFsControlFile ZwGetContextThread ZwGetDevicePowerState ZwGetPlugPlayEvent ZwGetTickCount ZwGetWriteWatch ZwImpersonateAnonymousToken ZwImpersonateClientOfPort ZwImpersonateThread ZwInitializeRegistry ZwInitiatePowerAction ZwIsSystemResumeAutomatic ZwListenChannel ZwListenPort ZwLoadDriver ZwLoadKey2 ZwLoadKey ZwLockFile ZwLockVirtualMemory ZwMakeTemporaryObject ZwMapUserPhysicalPages ZwMapUserPhysicalPagesScatter ZwMapViewOfSection ZwNotifyChangeDirectoryFile ZwNotifyChangeKey ZwNotifyChangeMultipleKeys ZwOpenChannel ZwOpenDirectoryObject ZwOpenEvent ZwOpenEventPair ZwOpenFile ZwOpenIoCompletion ZwOpenJobObject ZwOpenKey ZwOpenMutant ZwOpenObjectAuditAlarm ZwOpenProcess ZwOpenProcessToken ZwOpenSection ZwOpenSemaphore ZwOpenSymbolicLinkObject ZwOpenThread ZwOpenThreadToken ZwOpenTimer ZwPlugPlayControl ZwPowerInformation ZwPrivilegeCheck ZwPrivilegeObjectAuditAlarm ZwPrivilegedServiceAuditAlarm ZwProtectVirtualMemory ZwPulseEvent ZwQueryAttributesFile ZwQueryDefaultLocale ZwQueryDefaultUILanguage ZwQueryDirectoryFile ZwQueryDirectoryObject ZwQueryEaFile ZwQueryEvent ZwQueryFullAttributesFile ZwQueryInformationAtom ZwQueryInformationFile ZwQueryInformationJobObject ZwQueryInformationPort ZwQueryInformationProcess ZwQueryInformationThread ZwQueryInformationToken ZwQueryInstallUILanguage ZwQueryIntervalProfile ZwQueryIoCompletion ZwQueryKey ZwQueryMultipleValueKey ZwQueryMutant ZwQueryObject ZwQueryOpenSubKeys ZwQueryPerformanceCounter ZwQueryQuotaInformationFile ZwQuerySection ZwQuerySecurityObject ZwQuerySemaphore ZwQuerySymbolicLinkObject ZwQuerySystemEnvironmentValue ZwQuerySystemInformation ZwQuerySystemTime ZwQueryTimer ZwQueryTimerResolution ZwQueryValueKey ZwQueryVirtualMemory ZwQueryVolumeInformationFile ZwQueueApcThread ZwRaiseException ZwRaiseHardError ZwReadFile ZwReadFileScatter ZwReadRequestData ZwReadVirtualMemory ZwRegisterThreadTerminatePort ZwReleaseMutant ZwReleaseSemaphore ZwRemoveIoCompletion ZwReplaceKey ZwReplyPort ZwReplyWaitReceivePort ZwReplyWaitReceivePortEx ZwReplyWaitReplyPort ZwReplyWaitSendChannel ZwRequestDeviceWakeup ZwRequestPort ZwRequestWaitReplyPort ZwRequestWakeupLatency ZwResetEvent ZwResetWriteWatch ZwRestoreKey ZwResumeThread ZwSaveKey ZwSaveMergedKeys ZwSecureConnectPort ZwSendWaitReplyChannel ZwSetContextChannel ZwSetContextThread ZwSetDefaultHardErrorPort ZwSetDefaultLocale ZwSetDefaultUILanguage ZwSetEaFile ZwSetEvent ZwSetHighEventPair ZwSetHighWaitLowEventPair ZwSetInformationFile ZwSetInformationJobObject ZwSetInformationKey ZwSetInformationObject ZwSetInformationProcess ZwSetInformationThread ZwSetInformationToken ZwSetIntervalProfile ZwSetIoCompletion ZwSetLdtEntries ZwSetLowEventPair ZwSetLowWaitHighEventPair ZwSetQuotaInformationFile ZwSetSecurityObject ZwSetSystemEnvironmentValue ZwSetSystemInformation ZwSetSystemPowerState ZwSetSystemTime ZwSetThreadExecutionState ZwSetTimer ZwSetTimerResolution ZwSetUuidSeed ZwSetValueKey ZwSetVolumeInformationFile ZwShutdownSystem ZwSignalAndWaitForSingleObject ZwStartProfile ZwStopProfile ZwSuspendThread ZwSystemDebugControl ZwTerminateJobObject ZwTerminateProcess ZwTerminateThread ZwTestAlert ZwUnloadDriver ZwUnloadKey ZwUnlockFile ZwUnlockVirtualMemory ZwUnmapViewOfSection ZwVdmControl ZwWaitForMultipleObjects ZwWaitForSingleObject ZwWaitHighEventPair ZwWaitLowEventPair ZwWriteFile ZwWriteFileGather ZwWriteRequestData ZwWriteVirtualMemory ZwYieldExecution _CIpow __eCommonExceptions __eEmulatorInit __eF2XM1 __eFABS __eFADD32 __eFADD64 __eFADDPreg __eFADDreg __eFADDtop __eFCHS __eFCOM __eFCOM32 __eFCOM64 __eFCOMP __eFCOMP32 __eFCOMP64 __eFCOMPP __eFCOS __eFDECSTP __eFDIV32 __eFDIV64 __eFDIVPreg __eFDIVR32 __eFDIVR64 __eFDIVRPreg __eFDIVRreg __eFDIVRtop __eFDIVreg __eFDIVtop __eFFREE __eFIADD16 __eFIADD32 __eFICOM16 __eFICOM32 __eFICOMP16 __eFICOMP32 __eFIDIV16 __eFIDIV32 __eFIDIVR16 __eFIDIVR32 __eFILD16 __eFILD32 __eFILD64 __eFIMUL16 __eFIMUL32 __eFINCSTP __eFINIT __eFIST16 __eFIST32 __eFISTP16 __eFISTP32 __eFISTP64 __eFISUB16 __eFISUB32 __eFISUBR16 __eFISUBR32 __eFLD1 __eFLD32 __eFLD64 __eFLD80 __eFLDCW __eFLDENV __eFLDL2E __eFLDLN2 __eFLDPI __eFLDZ __eFMUL32 __eFMUL64 __eFMULPreg __eFMULreg __eFMULtop __eFPATAN __eFPREM __eFPREM1 __eFPTAN __eFRNDINT __eFRSTOR __eFSAVE __eFSCALE __eFSIN __eFSQRT __eFST __eFST32 __eFST64 __eFSTCW __eFSTENV __eFSTP __eFSTP32 __eFSTP64 __eFSTP80 __eFSTSW __eFSUB32 __eFSUB64 __eFSUBPreg __eFSUBR32 __eFSUBR64 __eFSUBRPreg __eFSUBRreg __eFSUBRtop __eFSUBreg __eFSUBtop __eFTST __eFUCOM __eFUCOMP __eFUCOMPP __eFXAM __eFXCH __eFXTRACT __eFYL2X __eFYL2XP1 __eGetStatusWord __isascii __iscsym __iscsymf __toascii _alldiv _allmul _alloca_probe _allrem _allshl _allshr _atoi64 _aulldiv _aullrem _aullshr _chkstk _fltused _ftol _i64toa _i64tow _itoa _itow _ltoa _ltow _memccpy _memicmp _snprintf _snwprintf _splitpath _strcmpi _stricmp _strlwr _strnicmp _strupr _tolower _toupper _ui64toa _ultoa _ultow _vsnprintf _wcsicmp _wcslwr _wcsnicmp _wcsupr _wtoi _wtoi64 _wtol abs atan atoi atol ceil cos fabs floor isalnum isalpha iscntrl isdigit isgraph islower isprint ispunct isspace isupper iswalpha iswctype iswdigit iswlower iswspace iswxdigit isxdigit labs log mbstowcs memchr memcmp memcpy memmove memset pow qsort sin sprintf sqrt sscanf strcat strchr strcmp strcpy strcspn strlen strncat strncmp strncpy strpbrk strrchr strspn strstr strtol strtoul swprintf tan tolower toupper towlower towupper vsprintf wcscat wcschr wcscmp wcscpy wcscspn wcslen wcsncat wcsncmp wcsncpy wcspbrk wcsrchr wcsspn wcsstr wcstol wcstombs wcstoul

Found follow exports in USER32.DL
AlignRects AllowSetForegroundWindow AnimateWindow BlockInput BroadcastSystemMessageA BroadcastSystemMessageW ChangeDisplaySettingsExA ChangeDisplaySettingsExW CliImmSetHotKey ClientThreadSetup CreateDialogIndirectParamAorW CtxInitUser32 DdeGetQualityOfService DeregisterShellHookWindow DeviceEventWorker DialogBoxIndirectParamAorW DrawMenuBarTemp EndMenu EnumDisplayDevicesA EnumDisplayDevicesW EnumDisplayMonitors EnumDisplaySettingsExA EnumDisplaySettingsExW FlashWindowEx GetAltTabInfo GetAltTabInfoA GetAltTabInfoW GetAncestor GetAppCompatFlags2 GetAppCompatFlags GetClipboardSequenceNumber GetComboBoxInfo GetCursorFrameInfo GetCursorInfo GetGUIThreadInfo GetGuiResources GetLastInputInfo GetListBoxInfo GetMenuBarInfo GetMenuInfo GetMonitorInfoA GetMonitorInfoW GetMouseMovePointsEx GetProcessDefaultLayout GetProgmanWindow GetScrollBarInfo GetTaskmanWindow GetTitleBarInfo GetWinStationInfo GetWindowInfo GetWindowModuleFileName GetWindowModuleFileNameA GetWindowModuleFileNameW IMPGetIMEA IMPGetIMEW IMPQueryIMEA IMPQueryIMEW IMPSetIMEA IMPSetIMEW InSendMessageEx InitializeLpkHooks InitializeWin32EntryTable IsHungAppWindow KillSystemTimer LoadKeyboardLayoutEx LoadLocalFonts LoadRemoteFonts LockSetForegroundWindow LockWorkStation MBToWCSEx MB_GetString MenuWindowProcA MenuWindowProcW MonitorFromPoint MonitorFromRect MonitorFromWindow MsgWaitForMultipleObjectsEx NotifyWinEvent PrivateExtractIconExA PrivateExtractIconExW PrivateExtractIconsA PrivateExtractIconsW PrivateSetDbgTag PrivateSetRipFlags QuerySendMessage QueryUserCounters RealChildWindowFromPoint RealGetWindowClass RealGetWindowClassA RealGetWindowClassW RegisterDeviceNotificationA RegisterDeviceNotificationW RegisterServicesProcess RegisterShellHookWindow ResolveDesktopForWOW ScrollChildren SendIMEMessageExA SendIMEMessageExW SendInput SetConsoleReserveKeys SetCursorContents SetLayeredWindowAttributes SetLogonNotifyWindow SetMenuInfo SetProcessDefaultLayout SetProgmanWindow SetShellWindowEx SetSystemMenu SetSystemTimer SetTaskmanWindow SetWinEventHook SetWindowStationUser ShowStartGlass SoftModalMessageBox ToUnicodeEx TrackMouseEvent TranslateMessageEx UnhookWinEvent UnregisterDeviceNotification UpdateLayeredWindow UpdatePerUserSystemParameters User32InitializeImmEntryTable UserHandleGrantAccess UserLpkPSMTextOut UserLpkTabbedTextOut UserRealizePalette UserRegisterWowHandlers VRipOutput VTagOutput WCSToMBEx WINNLSEnableIME WINNLSGetEnableStatus WINNLSGetIMEHotkey Win32PoolAllocationStats

Found follow exports in GDI32.DL
AddFontMemResourceEx AddFontResourceExA AddFontResourceExW AddFontResourceTracking AnyLinkedFonts BRUSHOBJ_hGetColorTransform BRUSHOBJ_pvAllocRbrush BRUSHOBJ_pvGetRbrush BRUSHOBJ_ulGetBrushColor CLIPOBJ_bEnum CLIPOBJ_cEnumStart CLIPOBJ_ppoGetPath ColorCorrectPalette CreateFontIndirectExA CreateFontIndirectExW EnableEUDC EndFormPage EngAcquireSemaphore EngAlphaBlend EngAssociateSurface EngBitBlt EngCheckAbort EngComputeGlyphSet EngCopyBits EngCreateBitmap EngCreateClip EngCreateDeviceBitmap EngCreateDeviceSurface EngCreatePalette EngCreateSemaphore EngDeleteClip EngDeletePalette EngDeletePath EngDeleteSemaphore EngDeleteSurface EngEraseSurface EngFillPath EngFindResource EngFreeModule EngGetCurrentCodePage EngGetDriverName EngGetPrinterDataFileName EngGradientFill EngLineTo EngLoadModule EngLockSurface EngMarkBandingSurface EngMultiByteToUnicodeN EngMultiByteToWideChar EngPaint EngPlgBlt EngQueryEMFInfo EngQueryLocalTime EngReleaseSemaphore EngStretchBlt EngStretchBltROP EngStrokeAndFillPath EngStrokePath EngTextOut EngTransparentBlt EngUnicodeToMultiByteN EngUnlockSurface EngWideCharToMultiByte EudcLoadLinkW EudcUnloadLinkW FONTOBJ_cGetAllGlyphHandles FONTOBJ_cGetGlyphs FONTOBJ_pQueryGlyphAttrs FONTOBJ_pfdg FONTOBJ_pifi FONTOBJ_pvTrueTypeFontFile FONTOBJ_pxoGetXform FONTOBJ_vGetInfo FontIsLinked GdiAddFontResourceW GdiAddGlsBounds GdiAddGlsRecord GdiAlphaBlend GdiArtificialDecrementDriver GdiCleanCacheDC GdiConsoleTextOut GdiConvertAndCheckDC GdiConvertBitmap GdiConvertBitmapV5 GdiConvertBrush GdiConvertDC GdiConvertEnhMetaFile GdiConvertFont GdiConvertMetaFilePict GdiConvertPalette GdiConvertRegion GdiConvertToDevmodeW GdiCreateLocalEnhMetaFile GdiCreateLocalMetaFilePict GdiDeleteLocalDC GdiDeleteSpoolFileHandle GdiDescribePixelFormat GdiDllInitialize GdiEndDocEMF GdiEndPageEMF GdiEntry10 GdiEntry11 GdiEntry12 GdiEntry13 GdiEntry14 GdiEntry15 GdiEntry16 GdiEntry1 GdiEntry2 GdiEntry3 GdiEntry4 GdiEntry5 GdiEntry6 GdiEntry7 GdiEntry8 GdiEntry9 GdiFixUpHandle GdiFullscreenControl GdiGetCharDimensions GdiGetCodePage GdiGetDC GdiGetDevmodeForPage GdiGetLocalBrush GdiGetLocalDC GdiGetLocalFont GdiGetPageCount GdiGetPageHandle GdiGetSpoolFileHandle GdiGetSpoolMessage GdiGradientFill GdiInitSpool GdiInitializeLanguagePack GdiIsMetaFileDC GdiIsMetaPrintDC GdiIsPlayMetafileDC GdiPlayEMF GdiPlayPageEMF GdiPlayPrivatePageEMF GdiPrinterThunk GdiProcessSetup GdiQueryFonts GdiQueryTable GdiRealizationInfo GdiReleaseDC GdiReleaseLocalDC GdiResetDCEMF GdiSetAttrs GdiSetLastError GdiSetPixelFormat GdiSetServerAttr GdiStartDocEMF GdiStartPageEMF GdiSwapBuffers GdiTransparentBlt GdiValidateHandle GetCharABCWidthsI GetCharWidthI GetCharWidthInfo GetDCBrushColor GetDCPenColor GetETM GetEUDCTimeStamp GetEUDCTimeStampExW GetEnhMetaFilePixelFormat GetFontAssocStatus GetFontResourceInfoW GetFontUnicodeRanges GetGlyphIndicesA GetGlyphIndicesW GetGlyphOutlineWow GetHFONT GetLayout GetRelAbs GetStringBitmapA GetStringBitmapW GetTextExtentExPointI GetTextExtentExPointWPri GetTextExtentPointI GetTextFaceAliasW GetTransform HT_Get8BPPFormatPalette HT_Get8BPPMaskPalette IsValidEnhMetaRecord IsValidEnhMetaRecordOffExt MirrorRgn NamedEscape PATHOBJ_bEnum PATHOBJ_bEnumClipLines PATHOBJ_vEnumStart PATHOBJ_vEnumStartClipLines PATHOBJ_vGetBounds PolyPatBlt QueryFontAssocStatus RemoveFontMemResourceEx RemoveFontResourceExA RemoveFontResourceExW RemoveFontResourceTracking STROBJ_bEnum STROBJ_bEnumPositionsOnly STROBJ_bGetAdvanceWidths STROBJ_dwGetCodePage STROBJ_vEnumStart SelectBrushLocal SelectFontLocal SetDCBrushColor SetDCPenColor SetLayout SetLayoutWidth SetMagicColors SetRelAbs SetVirtualResolution StartFormPage UnloadNetworkFonts XFORMOBJ_bApplyXform XFORMOBJ_iGetXform XLATEOBJ_cGetPalette XLATEOBJ_hGetColorTransform XLATEOBJ_iXlate XLATEOBJ_piVector bInitSystemAndFontsDirectoriesW bMakePathNameW cGetTTFFromFOT

Found follow exports in SHELL32.DL
CheckEscapesA Control_FillCache_RunDLL Control_FillCache_RunDLLA Control_FillCache_RunDLLW Control_RunDLLA Control_RunDLLAsUserW Control_RunDLLW DllCanUnloadNow DllGetVersion DllInstall DllRegisterServer DllUnregisterServer ExtractIconExW ExtractIconResInfoA ExtractIconResInfoW ExtractVersionResource16W FindExeDlgProc FixupOptionalComponents OCInstall OpenAs_RunDLLA OpenAs_RunDLLW PrintersGetCommand_RunDLLA PrintersGetCommand_RunDLLW SHBindToParent SHBrowseForFolderW SHChangeNotifySuspendResume SHCreateDirectoryExA SHCreateDirectoryExW SHCreateProcessAsUserW SheChangeDirExA SheChangeDirW SheConvertPathW SheFullPathA SheFullPathW SheGetCurDrive SheGetDirExW SheGetDirW SheGetPathOffsetW Shell_NotifyIconW ShellExec_RunDLL ShellExec_RunDLLA ShellExec_RunDLLW ShellExecuteExW ShellHookProc SHEmptyRecycleBinA SHEmptyRecycleBinW SheRemoveQuotesA SheRemoveQuotesW SheShortenPathA SheShortenPathW SHExtractIconsW SHFileOperationW SHGetDataFromIDListW SHGetDiskFreeSpaceA SHGetDiskFreeSpaceExA SHGetDiskFreeSpaceExW SHGetFileInfoW SHGetFolderLocation SHGetFolderPathA SHGetFolderPathW SHGetIconOverlayIndexA SHGetIconOverlayIndexW SHGetNewLinkInfo SHGetNewLinkInfoA SHGetNewLinkInfoW SHGetPathFromIDListW SHGetSettings SHGetSpecialFolderPathA SHGetSpecialFolderPathW SHHelpShortcuts_RunDLLA SHHelpShortcuts_RunDLLW SHInvokePrinterCommandA SHInvokePrinterCommandW SHIsFileAvailableOffline SHLoadNonloadedIconOverlayIdentifiers SHPathPrepareForWriteA SHPathPrepareForWriteW SHQueryRecycleBinA SHQueryRecycleBinW SHUpdateRecycleBinIcon StrChrA StrChrIA StrChrIW StrChrW StrCmpNA StrCmpNIA StrCmpNIW StrCmpNW StrCpyNA StrCpyNW StrNCmpA StrNCmpIA StrNCmpIW StrNCmpW StrNCpyA StrNCpyW StrRChrA StrRChrIA StrRChrIW StrRChrW StrRStrA StrRStrIA StrRStrIW StrRStrW StrStrA StrStrIA StrStrIW StrStrW WOWShellExecute

Found follow exports in COMDLG32.DL
dwLBSubclass dwOKSubclass LoadAlterBitmap PrintDlgExA PrintDlgExW Ssync_ANSI_UNICODE_Struct_For_WOW WantArrows

Found follow exports in COMCTL32.DL
DllInstall ImageList_GetFlags

Found follow exports in ADVAPI32.DL
I_ScGetCurrentGroupStateW I_ScIsSecurityProcess IsInSandbox AccessCheckByType AccessCheckByTypeAndAuditAlarmA AccessCheckByTypeAndAuditAlarmW AccessCheckByTypeResultList AccessCheckByTypeResultListAndAuditAlarmA AccessCheckByTypeResultListAndAuditAlarmByHandleA AccessCheckByTypeResultListAndAuditAlarmByHandleW AccessCheckByTypeResultListAndAuditAlarmW AddAccessAllowedAceEx AddAccessAllowedObjectAce AddAccessDeniedAceEx AddAccessDeniedObjectAce AddAuditAccessAceEx AddAuditAccessObjectAce AddUsersToEncryptedFile BuildExplicitAccessWithNameA BuildExplicitAccessWithNameW BuildImpersonateExplicitAccessWithNameA BuildImpersonateExplicitAccessWithNameW BuildImpersonateTrusteeA BuildImpersonateTrusteeW BuildSecurityDescriptorA BuildSecurityDescriptorW BuildTrusteeWithNameA BuildTrusteeWithNameW BuildTrusteeWithObjectsAndNameA BuildTrusteeWithObjectsAndNameW BuildTrusteeWithObjectsAndSidA BuildTrusteeWithObjectsAndSidW BuildTrusteeWithSidA BuildTrusteeWithSidW CancelOverlappedAccess ChangeServiceConfig2A ChangeServiceConfig2W CheckTokenMembership CloseEncryptedFileRaw CloseTrace CommandLineFromMsiDescriptor ControlTraceA ControlTraceW ConvertAccessToSecurityDescriptorA ConvertAccessToSecurityDescriptorW ConvertSDToStringSDRootDomainA ConvertSDToStringSDRootDomainW ConvertSecurityDescriptorToAccessA ConvertSecurityDescriptorToAccessNamedA ConvertSecurityDescriptorToAccessNamedW ConvertSecurityDescriptorToAccessW ConvertSecurityDescriptorToStringSecurityDescriptorA ConvertSecurityDescriptorToStringSecurityDescriptorW ConvertSidToStringSidA ConvertSidToStringSidW ConvertStringSDToSDRootDomainA ConvertStringSDToSDRootDomainW ConvertStringSecurityDescriptorToSecurityDescriptorA ConvertStringSecurityDescriptorToSecurityDescriptorW ConvertStringSidToSidA ConvertStringSidToSidW ConvertToAutoInheritPrivateObjectSecurity CreatePrivateObjectSecurityEx CreateProcessAsUserSecure CreateProcessWithLogonW CreateRestrictedToken CreateTraceInstanceId CreateWellKnownSid CryptAcquireContextW CryptContextAddRef CryptDuplicateHash CryptDuplicateKey CryptEnumProviderTypesA CryptEnumProviderTypesW CryptEnumProvidersA CryptEnumProvidersW CryptGetDefaultProviderA CryptGetDefaultProviderW CryptSetProviderExA CryptSetProviderExW CryptSetProviderW CryptSignHashW CryptVerifySignatureW DecryptFileA DecryptFileW DuplicateEncryptionInfoFile DuplicateTokenEx ElfBackupEventLogFileA ElfBackupEventLogFileW ElfChangeNotify ElfClearEventLogFileA ElfClearEventLogFileW ElfCloseEventLog ElfDeregisterEventSource ElfFlushEventLog ElfNumberOfRecords ElfOldestRecord ElfOpenBackupEventLogA ElfOpenBackupEventLogW ElfOpenEventLogA ElfOpenEventLogW ElfReadEventLogA ElfReadEventLogW ElfRegisterEventSourceA ElfRegisterEventSourceW ElfReportEventA ElfReportEventW EnableTrace EncryptFileA EncryptFileW EncryptionDisable EnumServiceGroupW EnumServicesStatusExA EnumServicesStatusExW EqualDomainSid FileEncryptionStatusA FileEncryptionStatusW FreeEncryptionCertificateHashList GetAccessPermissionsForObjectA GetAccessPermissionsForObjectW GetAuditedPermissionsFromAclA GetAuditedPermissionsFromAclW GetCurrentHwProfileA GetCurrentHwProfileW GetEffectiveRightsFromAclA GetEffectiveRightsFromAclW GetEventLogInformation GetExplicitEntriesFromAclA GetExplicitEntriesFromAclW GetLocalManagedApplications GetManagedApplications GetMangledSiteSid GetMultipleTrusteeA GetMultipleTrusteeOperationA GetMultipleTrusteeOperationW GetMultipleTrusteeW GetNamedSecurityInfoA GetNamedSecurityInfoExA GetNamedSecurityInfoExW GetNamedSecurityInfoW GetOverlappedAccessResults GetSecurityDescriptorRMControl GetSecurityInfo GetSecurityInfoExA GetSecurityInfoExW GetSiteDirectoryA GetSiteDirectoryW GetSiteNameFromSid GetSiteSidFromToken GetSiteSidFromUrl GetTraceEnableFlags GetTraceEnableLevel GetTraceLoggerHandle GetTrusteeFormA GetTrusteeFormW GetTrusteeNameA GetTrusteeNameW GetTrusteeTypeA GetTrusteeTypeW GetWindowsAccountDomainSid I_ScPnPGetServiceName I_ScSetServiceBitsA I_ScSetServiceBitsW ImpersonateAnonymousToken InitiateSystemShutdownExA InitiateSystemShutdownExW InstallApplication IsProcessRestricted IsTokenRestricted IsWellKnownSid LookupSecurityDescriptorPartsA LookupSecurityDescriptorPartsW LsaAddAccountRights LsaAddPrivilegesToAccount LsaClearAuditLog LsaClose LsaCreateAccount LsaCreateSecret LsaCreateTrustedDomain LsaCreateTrustedDomainEx LsaDelete LsaDeleteTrustedDomain LsaEnumerateAccountRights LsaEnumerateAccounts LsaEnumerateAccountsWithUserRight LsaEnumeratePrivileges LsaEnumeratePrivilegesOfAccount LsaEnumerateTrustedDomains LsaEnumerateTrustedDomainsEx LsaFreeMemory LsaGetQuotasForAccount LsaGetRemoteUserName LsaGetSystemAccessAccount LsaGetUserName LsaICLookupNames LsaICLookupSids LsaLookupNames LsaLookupPrivilegeDisplayName LsaLookupPrivilegeName LsaLookupPrivilegeValue LsaLookupSids LsaNtStatusToWinError LsaOpenAccount LsaOpenPolicy LsaOpenPolicySce LsaOpenSecret LsaOpenTrustedDomain LsaOpenTrustedDomainByName LsaQueryDomainInformationPolicy LsaQueryInfoTrustedDomain LsaQueryInformationPolicy LsaQuerySecret LsaQuerySecurityObject LsaQueryTrustedDomainInfo LsaQueryTrustedDomainInfoByName LsaRemoveAccountRights LsaRemovePrivilegesFromAccount LsaRetrievePrivateData LsaSetDomainInformationPolicy LsaSetInformationPolicy LsaSetInformationTrustedDomain LsaSetQuotasForAccount LsaSetSecret LsaSetSecurityObject LsaSetSystemAccessAccount LsaSetTrustedDomainInfoByName LsaSetTrustedDomainInformation LsaStorePrivateData MakeAbsoluteSD2 ObjectDeleteAuditAlarmA ObjectDeleteAuditAlarmW OpenEncryptedFileRawA OpenEncryptedFileRawW OpenTraceA OpenTraceW ProcessTrace QueryAllTracesA QueryAllTracesW QueryRecoveryAgentsOnEncryptedFile QueryServiceConfig2A QueryServiceConfig2W QueryServiceStatusEx QueryUsersOnEncryptedFile QueryWindows31FilesMigration ReadEncryptedFileRaw RegDisablePredefinedCache RegOpenCurrentUser RegOpenUserClassesRoot RegOverridePredefKey RegisterServiceCtrlHandlerExA RegisterServiceCtrlHandlerExW RegisterTraceGuidsA RegisterTraceGuidsW RemoveTraceCallback RemoveUsersFromEncryptedFile SetEntriesInAccessListA SetEntriesInAccessListW SetEntriesInAclA SetEntriesInAclW SetEntriesInAuditListA SetEntriesInAuditListW SetNamedSecurityInfoA SetNamedSecurityInfoExA SetNamedSecurityInfoExW SetNamedSecurityInfoW SetPrivateObjectSecurityEx SetSecurityDescriptorControl SetSecurityDescriptorRMControl SetSecurityInfo SetSecurityInfoExA SetSecurityInfoExW SetTraceCallback SetUserFileEncryptionKey StartTraceA StartTraceW SynchronizeWindows31FilesAndWindowsNTRegistry SystemFunction001 SystemFunction002 SystemFunction003 SystemFunction004 SystemFunction005 SystemFunction006 SystemFunction007 SystemFunction008 SystemFunction009 SystemFunction010 SystemFunction011 SystemFunction012 SystemFunction013 SystemFunction014 SystemFunction015 SystemFunction016 SystemFunction017 SystemFunction018 SystemFunction019 SystemFunction020 SystemFunction021 SystemFunction022 SystemFunction023 SystemFunction024 SystemFunction025 SystemFunction026 SystemFunction027 SystemFunction028 SystemFunction029 SystemFunction030 SystemFunction031 SystemFunction032 SystemFunction033 SystemFunction034 SystemFunction035 SystemFunction040 SystemFunction041 TraceEvent TraceEventInstance TrusteeAccessToObjectA TrusteeAccessToObjectW UninstallApplication UnregisterTraceGuids WmiCloseBlock WmiDevInstToInstanceNameA WmiDevInstToInstanceNameW WmiEnumerateGuids WmiExecuteMethodA WmiExecuteMethodW WmiFileHandleToInstanceNameA WmiFileHandleToInstanceNameW WmiFreeBuffer WmiMofEnumerateResourcesA WmiMofEnumerateResourcesW WmiNotificationRegistrationA WmiNotificationRegistrationW WmiOpenBlock WmiQueryAllDataA WmiQueryAllDataW WmiQueryGuidInformation WmiQuerySingleInstanceA WmiQuerySingleInstanceW WmiSetSingleInstanceA WmiSetSingleInstanceW WmiSetSingleItemA WmiSetSingleItemW WriteEncryptedFileRaw

Found follow exports in WSOCK32.DL
MigrateWinsockConfiguration WEP WSApSetPostRoutine inet_network getnetbyname rcmd rexec rresvport sethostname AcceptEx GetAcceptExSockaddrs

Found follow exports in WS2_32.DL
accept bind closesocket connect getpeername getsockname getsockopt htonl htons ioctlsocket inet_addr inet_ntoa listen ntohl ntohs recv recvfrom select send sendto setsockopt shutdown socket WSApSetPostRoutine WPUCompleteOverlappedRequest WSAAccept WSAAddressToStringA WSAAddressToStringW WSACloseEvent WSAConnect WSACreateEvent WSADuplicateSocketA WSADuplicateSocketW WSAEnumNameSpaceProvidersA WSAEnumNameSpaceProvidersW WSAEnumNetworkEvents WSAEnumProtocolsA WSAEnumProtocolsW WSAEventSelect WSAGetOverlappedResult WSAGetQOSByName WSAGetServiceClassInfoA WSAGetServiceClassInfoW WSAGetServiceClassNameByClassIdA WSAGetServiceClassNameByClassIdW WSAHtonl WSAHtons WSAInstallServiceClassA WSAInstallServiceClassW WSAIoctl gethostbyaddr gethostbyname getprotobyname getprotobynumber getservbyname getservbyport gethostname WSAJoinLeaf WSALookupServiceBeginA WSALookupServiceBeginW WSALookupServiceEnd WSALookupServiceNextA WSALookupServiceNextW WSANtohl WSANtohs WSAProviderConfigChange WSARecv WSARecvDisconnect WSARecvFrom WSARemoveServiceClass WSAResetEvent WSASend WSASendDisconnect WSASendTo WSASetEvent WSASetServiceA WSASetServiceW WSASocketA WSASocketW WSAStringToAddressA WSAStringToAddressW WSAWaitForMultipleEvents WSCDeinstallProvider WSCEnableNSProvider WSCEnumProtocols WSCGetProviderPath WSCInstallNameSpace WSCInstallProvider WSCUnInstallNameSpace WSCWriteNameSpaceOrder WSCWriteProviderOrder WSAAsyncSelect WSAAsyncGetHostByAddr WSAAsyncGetHostByName WSAAsyncGetProtoByNumber WSAAsyncGetProtoByName WSAAsyncGetServByPort WSAAsyncGetServByName WSACancelAsyncRequest WSASetBlockingHook WSAUnhookBlockingHook WSAGetLastError WSASetLastError WSACancelBlockingCall WSAIsBlocking WSAStartup WSACleanup __WSAFDIsSet WEP

Windows XPsp1


Found follow exports in KERNEL32.DL
ActivateActCtx AddConsoleAliasA AddConsoleAliasW AddLocalAlternateComputerNameA AddLocalAlternateComputerNameW AddRefActCtx AddVectoredExceptionHandler AllocateUserPhysicalPages AssignProcessToJobObject AttachConsole BaseCheckAppcompatCache BaseCleanupAppcompatCache BaseCleanupAppcompatCacheSupport BaseDumpAppcompatCache BaseFlushAppcompatCache BaseInitAppcompatCache BaseInitAppcompatCacheSupport BaseProcessInitPostImport BaseUpdateAppcompatCache BindIoCompletionCallback CancelDeviceWakeupRequest CancelIo CancelTimerQueueTimer CancelWaitableTimer ChangeTimerQueueTimer CheckNameLegalDOS8Dot3A CheckNameLegalDOS8Dot3W CheckRemoteDebuggerPresent CloseConsoleHandle CmdBatNotification ConsoleMenuControl ConvertFiberToThread ConvertThreadToFiber CopyFileExA CopyFileExW CopyLZFile CreateActCtxA CreateActCtxW CreateFiber CreateFiberEx CreateHardLinkA CreateHardLinkW CreateJobObjectA CreateJobObjectW CreateJobSet CreateMemoryResourceNotification CreateNlsSecurityDescriptor CreateProcessInternalA CreateProcessInternalW CreateSocketHandle CreateTimerQueue CreateTimerQueueTimer CreateToolhelp32Snapshot CreateVirtualBuffer CreateWaitableTimerA CreateWaitableTimerW DeactivateActCtx DebugActiveProcessStop DebugBreakProcess DebugSetProcessKillOnExit DelayLoadFailureHook DeleteFiber DeleteTimerQueue DeleteTimerQueueEx DeleteTimerQueueTimer DeleteVolumeMountPointA DeleteVolumeMountPointW DnsHostnameToComputerNameA DnsHostnameToComputerNameW DosPathToSessionPathA DosPathToSessionPathW DuplicateConsoleHandle EnumCalendarInfoExA EnumCalendarInfoExW EnumDateFormatsExA EnumDateFormatsExW EnumLanguageGroupLocalesA EnumLanguageGroupLocalesW EnumSystemGeoID EnumSystemLanguageGroupsA EnumSystemLanguageGroupsW EnumUILanguagesA EnumUILanguagesW EnumerateLocalComputerNamesA EnumerateLocalComputerNamesW ExitVDM ExpungeConsoleCommandHistoryA ExpungeConsoleCommandHistoryW ExtendVirtualBuffer FindActCtxSectionGuid FindActCtxSectionStringA FindActCtxSectionStringW FindFirstFileExA FindFirstFileExW FindFirstVolumeA FindFirstVolumeMountPointA FindFirstVolumeMountPointW FindFirstVolumeW FindNextVolumeA FindNextVolumeMountPointA FindNextVolumeMountPointW FindNextVolumeW FindVolumeClose FindVolumeMountPointClose FreeUserPhysicalPages FreeVirtualBuffer GetCPFileNameFromRegistry GetCPInfoExA GetCPInfoExW GetCalendarInfoA GetCalendarInfoW GetComPlusPackageInstallStatus GetComputerNameExA GetComputerNameExW GetConsoleAliasA GetConsoleAliasExesA GetConsoleAliasExesLengthA GetConsoleAliasExesLengthW GetConsoleAliasExesW GetConsoleAliasW GetConsoleAliasesA GetConsoleAliasesLengthA GetConsoleAliasesLengthW GetConsoleAliasesW GetConsoleCharType GetConsoleCommandHistoryA GetConsoleCommandHistoryLengthA GetConsoleCommandHistoryLengthW GetConsoleCommandHistoryW GetConsoleCursorMode GetConsoleDisplayMode GetConsoleFontInfo GetConsoleFontSize GetConsoleHardwareState GetConsoleInputExeNameA GetConsoleInputExeNameW GetConsoleInputWaitHandle GetConsoleKeyboardLayoutNameA GetConsoleKeyboardLayoutNameW GetConsoleNlsMode GetConsoleProcessList GetConsoleSelectionInfo GetConsoleWindow GetCurrentActCtx GetCurrentConsoleFont GetDefaultSortkeySize GetDevicePowerState GetDllDirectoryA GetDllDirectoryW GetExpandedNameA GetExpandedNameW GetFileAttributesExA GetFileAttributesExW GetFileSizeEx GetFirmwareEnvironmentVariableA GetFirmwareEnvironmentVariableW GetGeoInfoA GetGeoInfoW GetHandleContext GetLinguistLangSize GetLongPathNameA GetLongPathNameW GetModuleHandleExA GetModuleHandleExW GetNativeSystemInfo GetNextVDMCommand GetNlsSectionName GetNumaAvailableMemory GetNumaAvailableMemoryNode GetNumaHighestNodeNumber GetNumaNodeProcessorMask GetNumaProcessorMap GetNumaProcessorNode GetNumberOfConsoleFonts GetProcessHandleCount GetProcessId GetProcessIoCounters GetProcessPriorityBoost GetSystemDefaultUILanguage GetSystemRegistryQuota GetSystemTimes GetSystemWindowsDirectoryA GetSystemWindowsDirectoryW GetSystemWow64DirectoryA GetSystemWow64DirectoryW GetThreadIOPendingFlag GetThreadPriorityBoost GetUserDefaultUILanguage GetUserGeoID GetVDMCurrentDirectories GetVolumeNameForVolumeMountPointA GetVolumeNameForVolumeMountPointW GetVolumePathNameA GetVolumePathNameW GetVolumePathNamesForVolumeNameA GetVolumePathNamesForVolumeNameW GetWriteWatch GlobalMemoryStatusEx Heap32First Heap32ListFirst Heap32ListNext Heap32Next HeapCreateTagsW HeapExtend HeapQueryInformation HeapQueryTagW HeapSetInformation HeapSummary HeapUsage InitializeCriticalSectionAndSpinCount InitializeSListHead InterlockedCompareExchange InterlockedExchangeAdd InterlockedFlushSList InterlockedPopEntrySList InterlockedPushEntrySList InvalidateConsoleDIBits IsDebuggerPresent IsProcessInJob IsProcessorFeaturePresent IsSystemResumeAutomatic IsValidLanguageGroup IsValidUILanguage IsWow64Process LZClose LZCloseFile LZCopy LZCreateFileW LZDone LZInit LZOpenFileA LZOpenFileW LZRead LZSeek LZStart MapUserPhysicalPages MapUserPhysicalPagesScatter Module32First Module32FirstW Module32Next Module32NextW MoveFileWithProgressA MoveFileWithProgressW NlsConvertIntegerToString NlsGetCacheUpdateCount NlsResetProcessLocale NumaVirtualQueryNode OpenConsoleW OpenDataFile OpenJobObjectA OpenJobObjectW OpenThread OpenWaitableTimerA OpenWaitableTimerW PrivCopyFileExW PrivMoveFileIdentityW Process32First Process32FirstW Process32Next Process32NextW ProcessIdToSessionId QueryActCtxW QueryDepthSList QueryInformationJobObject QueryMemoryResourceNotification QueryWin31IniFilesMappedToRegistry QueueUserWorkItem ReadConsoleInputExA ReadConsoleInputExW ReadDirectoryChangesW ReadFileScatter RegisterConsoleIME RegisterConsoleOS2 RegisterConsoleVDM RegisterWaitForInputIdle RegisterWaitForSingleObject RegisterWaitForSingleObjectEx RegisterWowBaseHandlers RegisterWowExec ReleaseActCtx RemoveLocalAlternateComputerNameA RemoveLocalAlternateComputerNameW RemoveVectoredExceptionHandler ReplaceFile ReplaceFileA ReplaceFileW RequestDeviceWakeup RequestWakeupLatency ResetWriteWatch RestoreLastError RtlCaptureContext RtlCaptureStackBackTrace SetCPGlobal SetCalendarInfoA SetCalendarInfoW SetClientTimeZoneInformation SetComPlusPackageInstallStatus SetComputerNameExA SetComputerNameExW SetConsoleCommandHistoryMode SetConsoleCursor SetConsoleCursorMode SetConsoleDisplayMode SetConsoleFont SetConsoleHardwareState SetConsoleIcon SetConsoleInputExeNameA SetConsoleInputExeNameW SetConsoleKeyShortcuts SetConsoleLocalEUDC SetConsoleMaximumWindowSize SetConsoleMenuClose SetConsoleNlsMode SetConsoleNumberOfCommandsA SetConsoleNumberOfCommandsW SetConsoleOS2OemFormat SetConsolePalette SetCriticalSectionSpinCount SetDllDirectoryA SetDllDirectoryW SetFilePointerEx SetFileShortNameA SetFileShortNameW SetFileValidData SetFirmwareEnvironmentVariableA SetFirmwareEnvironmentVariableW SetHandleContext SetInformationJobObject SetLastConsoleEventActive SetLocalPrimaryComputerNameA SetLocalPrimaryComputerNameW SetMessageWaitingIndicator SetProcessAffinityMask SetProcessPriorityBoost SetTermsrvAppInstallMode SetThreadExecutionState SetThreadIdealProcessor SetThreadPriorityBoost SetThreadUILanguage SetTimerQueueTimer SetUserGeoID SetVDMCurrentDirectories SetVolumeMountPointA SetVolumeMountPointW SetWaitableTimer ShowConsoleCursor SignalObjectAndWait SwitchToFiber SwitchToThread TerminateJobObject TermsrvAppInstallMode Thread32First Thread32Next Toolhelp32ReadProcessMemory TrimVirtualBuffer TryEnterCriticalSection TzSpecificLocalTimeToSystemTime UTRegister UTUnRegister UnregisterConsoleIME UnregisterWait UnregisterWaitEx VDMConsoleOperation VDMOperationStarted ValidateLCType ValidateLocale VerSetConditionMask VerifyConsoleIoHandle VerifyVersionInfoA VerifyVersionInfoW VirtualAllocEx VirtualBufferExceptionHandler VirtualFreeEx WTSGetActiveConsoleSessionId WriteConsoleInputVDMA WriteConsoleInputVDMW WriteFileGather ZombifyActCtx

Found follow exports in NTDLL.DL
PropertyLengthAsVariant RtlConvertPropertyToVariant RtlConvertVariantToProperty RtlInterlockedPushListSList RtlUlongByteSwap RtlUlonglongByteSwap RtlUshortByteSwap CsrAllocateCaptureBuffer CsrAllocateMessagePointer CsrCaptureMessageBuffer CsrCaptureMessageMultiUnicodeStringsInPlace CsrCaptureMessageString CsrCaptureTimeout CsrClientCallServer CsrClientConnectToServer CsrFreeCaptureBuffer CsrGetProcessId CsrIdentifyAlertableThread CsrNewThread CsrProbeForRead CsrProbeForWrite CsrSetPriorityClass DbgPrintEx DbgPrintReturnControlC DbgQueryDebugFilterState DbgSetDebugFilterState DbgUiConnectToDbg DbgUiContinue DbgUiConvertStateChangeStructure DbgUiDebugActiveProcess DbgUiGetThreadDebugObject DbgUiIssueRemoteBreakin DbgUiRemoteBreakin DbgUiSetThreadDebugObject DbgUiStopDebugging DbgUiWaitStateChange DbgUserBreakPoint KiRaiseUserExceptionDispatcher KiUserApcDispatcher KiUserCallbackDispatcher KiUserExceptionDispatcher LdrAccessOutOfProcessResource LdrAccessResource LdrAddRefDll LdrAlternateResourcesEnabled LdrCreateOutOfProcessImage LdrDestroyOutOfProcessImage LdrDisableThreadCalloutsForDll LdrEnumResources LdrEnumerateLoadedModules LdrFindCreateProcessManifest LdrFindEntryForAddress LdrFindResourceDirectory_U LdrFindResourceEx_U LdrFindResource_U LdrFlushAlternateResourceModules LdrGetDllHandle LdrGetDllHandleEx LdrGetProcedureAddress LdrInitShimEngineDynamic LdrInitializeThunk LdrLoadAlternateResourceModule LdrLoadDll LdrLockLoaderLock LdrProcessRelocationBlock LdrQueryImageFileExecutionOptions LdrQueryProcessModuleInformation LdrSetAppCompatDllRedirectionCallback LdrSetDllManifestProber LdrShutdownProcess LdrShutdownThread LdrUnloadAlternateResourceModule LdrUnloadDll LdrUnlockLoaderLock LdrVerifyImageMatchesChecksum NlsAnsiCodePage NlsMbCodePageTag NlsMbOemCodePageTag NtAcceptConnectPort NtAccessCheck NtAccessCheckAndAuditAlarm NtAccessCheckByType NtAccessCheckByTypeAndAuditAlarm NtAccessCheckByTypeResultList NtAccessCheckByTypeResultListAndAuditAlarm NtAccessCheckByTypeResultListAndAuditAlarmByHandle NtAddAtom NtAddBootEntry NtAdjustGroupsToken NtAdjustPrivilegesToken NtAlertResumeThread NtAlertThread NtAllocateLocallyUniqueId NtAllocateUserPhysicalPages NtAllocateUuids NtAllocateVirtualMemory NtAreMappedFilesTheSame NtAssignProcessToJobObject NtCallbackReturn NtCancelDeviceWakeupRequest NtCancelIoFile NtCancelTimer NtClearEvent NtClose NtCloseObjectAuditAlarm NtCompactKeys NtCompareTokens NtCompleteConnectPort NtCompressKey NtConnectPort NtContinue NtCreateDebugObject NtCreateDirectoryObject NtCreateEvent NtCreateEventPair NtCreateFile NtCreateIoCompletion NtCreateJobObject NtCreateJobSet NtCreateKey NtCreateKeyedEvent NtCreateMailslotFile NtCreateMutant NtCreateNamedPipeFile NtCreatePagingFile NtCreatePort NtCreateProcess NtCreateProcessEx NtCreateProfile NtCreateSection NtCreateSemaphore NtCreateSymbolicLinkObject NtCreateThread NtCreateTimer NtCreateToken NtCreateWaitablePort NtDebugActiveProcess NtDebugContinue NtDelayExecution NtDeleteAtom NtDeleteBootEntry NtDeleteFile NtDeleteKey NtDeleteObjectAuditAlarm NtDeleteValueKey NtDeviceIoControlFile NtDisplayString NtDuplicateObject NtDuplicateToken NtEnumerateBootEntries NtEnumerateKey NtEnumerateSystemEnvironmentValuesEx NtEnumerateValueKey NtExtendSection NtFilterToken NtFindAtom NtFlushBuffersFile NtFlushInstructionCache NtFlushKey NtFlushVirtualMemory NtFlushWriteBuffer NtFreeUserPhysicalPages NtFreeVirtualMemory NtFsControlFile NtGetContextThread NtGetDevicePowerState NtGetPlugPlayEvent NtGetWriteWatch NtImpersonateAnonymousToken NtImpersonateClientOfPort NtImpersonateThread NtInitializeRegistry NtInitiatePowerAction NtIsProcessInJob NtIsSystemResumeAutomatic NtListenPort NtLoadDriver NtLoadKey2 NtLoadKey NtLockFile NtLockProductActivationKeys NtLockRegistryKey NtLockVirtualMemory NtMakePermanentObject NtMakeTemporaryObject NtMapUserPhysicalPages NtMapUserPhysicalPagesScatter NtMapViewOfSection NtModifyBootEntry NtNotifyChangeDirectoryFile NtNotifyChangeKey NtNotifyChangeMultipleKeys NtOpenDirectoryObject NtOpenEvent NtOpenEventPair NtOpenFile NtOpenIoCompletion NtOpenJobObject NtOpenKey NtOpenKeyedEvent NtOpenMutant NtOpenObjectAuditAlarm NtOpenProcess NtOpenProcessToken NtOpenProcessTokenEx NtOpenSection NtOpenSemaphore NtOpenSymbolicLinkObject NtOpenThread NtOpenThreadToken NtOpenThreadTokenEx NtOpenTimer NtPlugPlayControl NtPowerInformation NtPrivilegeCheck NtPrivilegeObjectAuditAlarm NtPrivilegedServiceAuditAlarm NtProtectVirtualMemory NtPulseEvent NtQueryAttributesFile NtQueryBootEntryOrder NtQueryBootOptions NtQueryDebugFilterState NtQueryDefaultLocale NtQueryDefaultUILanguage NtQueryDirectoryFile NtQueryDirectoryObject NtQueryEaFile NtQueryEvent NtQueryFullAttributesFile NtQueryInformationAtom NtQueryInformationFile NtQueryInformationJobObject NtQueryInformationPort NtQueryInformationProcess NtQueryInformationThread NtQueryInformationToken NtQueryInstallUILanguage NtQueryIntervalProfile NtQueryIoCompletion NtQueryKey NtQueryMultipleValueKey NtQueryMutant NtQueryObject NtQueryOpenSubKeys NtQueryPortInformationProcess NtQueryQuotaInformationFile NtQuerySection NtQuerySecurityObject NtQuerySemaphore NtQuerySymbolicLinkObject NtQuerySystemEnvironmentValue NtQuerySystemEnvironmentValueEx NtQuerySystemInformation NtQuerySystemTime NtQueryTimer NtQueryTimerResolution NtQueryValueKey NtQueryVirtualMemory NtQueryVolumeInformationFile NtQueueApcThread NtRaiseException NtRaiseHardError NtReadFile NtReadFileScatter NtReadRequestData NtReadVirtualMemory NtRegisterThreadTerminatePort NtReleaseKeyedEvent NtReleaseMutant NtReleaseSemaphore NtRemoveIoCompletion NtRemoveProcessDebug NtRenameKey NtReplaceKey NtReplyPort NtReplyWaitReceivePort NtReplyWaitReceivePortEx NtReplyWaitReplyPort NtRequestDeviceWakeup NtRequestPort NtRequestWaitReplyPort NtRequestWakeupLatency NtResetEvent NtResetWriteWatch NtRestoreKey NtResumeProcess NtResumeThread NtSaveKey NtSaveKeyEx NtSaveMergedKeys NtSecureConnectPort NtSetBootEntryOrder NtSetBootOptions NtSetContextThread NtSetDebugFilterState NtSetDefaultHardErrorPort NtSetDefaultLocale NtSetDefaultUILanguage NtSetEaFile NtSetEvent NtSetEventBoostPriority NtSetHighEventPair NtSetHighWaitLowEventPair NtSetInformationDebugObject NtSetInformationFile NtSetInformationJobObject NtSetInformationKey NtSetInformationObject NtSetInformationProcess NtSetInformationThread NtSetInformationToken NtSetIntervalProfile NtSetIoCompletion NtSetLdtEntries NtSetLowEventPair NtSetLowWaitHighEventPair NtSetQuotaInformationFile NtSetSecurityObject NtSetSystemEnvironmentValue NtSetSystemEnvironmentValueEx NtSetSystemInformation NtSetSystemPowerState NtSetSystemTime NtSetThreadExecutionState NtSetTimer NtSetTimerResolution NtSetUuidSeed NtSetValueKey NtSetVolumeInformationFile NtShutdownSystem NtSignalAndWaitForSingleObject NtStartProfile NtStopProfile NtSuspendProcess NtSuspendThread NtSystemDebugControl NtTerminateJobObject NtTerminateProcess NtTerminateThread NtTestAlert NtTraceEvent NtTranslateFilePath NtUnloadDriver NtUnloadKey NtUnloadKeyEx NtUnlockFile NtUnlockVirtualMemory NtUnmapViewOfSection NtVdmControl NtWaitForDebugEvent NtWaitForKeyedEvent NtWaitForMultipleObjects NtWaitForSingleObject NtWaitHighEventPair NtWaitLowEventPair NtWriteFile NtWriteFileGather NtWriteRequestData NtWriteVirtualMemory NtYieldExecution PfxFindPrefix PfxInitialize PfxInsertPrefix PfxRemovePrefix RestoreEm87Context RtlAbortRXact RtlAbsoluteToSelfRelativeSD RtlAcquirePebLock RtlAcquireResourceExclusive RtlAcquireResourceShared RtlActivateActivationContext RtlActivateActivationContextEx RtlActivateActivationContextUnsafeFast RtlAddAccessAllowedAce RtlAddAccessAllowedAceEx RtlAddAccessAllowedObjectAce RtlAddAccessDeniedAce RtlAddAccessDeniedAceEx RtlAddAccessDeniedObjectAce RtlAddAce RtlAddActionToRXact RtlAddAtomToAtomTable RtlAddAttributeActionToRXact RtlAddAuditAccessAce RtlAddAuditAccessAceEx RtlAddAuditAccessObjectAce RtlAddCompoundAce RtlAddRange RtlAddRefActivationContext RtlAddRefMemoryStream RtlAddVectoredExceptionHandler RtlAddressInSectionTable RtlAdjustPrivilege RtlAllocateAndInitializeSid RtlAllocateHandle RtlAnsiCharToUnicodeChar RtlAnsiStringToUnicodeSize RtlAppendAsciizToString RtlAppendPathElement RtlAppendStringToString RtlAppendUnicodeStringToString RtlAppendUnicodeToString RtlApplicationVerifierStop RtlApplyRXact RtlApplyRXactNoFlush RtlAreAllAccessesGranted RtlAreAnyAccessesGranted RtlAreBitsClear RtlAreBitsSet RtlAssert2 RtlAssert RtlCancelTimer RtlCaptureContext RtlCaptureStackBackTrace RtlCaptureStackContext RtlCharToInteger RtlCheckForOrphanedCriticalSections RtlCheckProcessParameters RtlCheckRegistryKey RtlClearAllBits RtlClearBits RtlCloneMemoryStream RtlCommitMemoryStream RtlCompactHeap RtlCompareMemory RtlCompareMemoryUlong RtlCompareString RtlCompareUnicodeString RtlCompressBuffer RtlComputeCrc32 RtlComputeImportTableHash RtlComputePrivatizedDllName_U RtlConsoleMultiByteToUnicodeN RtlConvertExclusiveToShared RtlConvertSharedToExclusive RtlConvertSidToUnicodeString RtlConvertToAutoInheritSecurityObject RtlConvertUiListToApiList RtlCopyLuid RtlCopyLuidAndAttributesArray RtlCopyMemoryStreamTo RtlCopyOutOfProcessMemoryStreamTo RtlCopyRangeList RtlCopySecurityDescriptor RtlCopySid RtlCopySidAndAttributesArray RtlCopyString RtlCopyUnicodeString RtlCreateAcl RtlCreateActivationContext RtlCreateAndSetSD RtlCreateAtomTable RtlCreateBootStatusDataFile RtlCreateEnvironment RtlCreateProcessParameters RtlCreateQueryDebugBuffer RtlCreateRegistryKey RtlCreateSecurityDescriptor RtlCreateSystemVolumeInformationFolder RtlCreateTagHeap RtlCreateTimer RtlCreateTimerQueue RtlCreateUnicodeString RtlCreateUnicodeStringFromAsciiz RtlCreateUserProcess RtlCreateUserSecurityObject RtlCreateUserThread RtlCustomCPToUnicodeN RtlCutoverTimeToSystemTime RtlDeNormalizeProcessParams RtlDeactivateActivationContext RtlDeactivateActivationContextUnsafeFast RtlDebugPrintTimes RtlDecompressBuffer RtlDecompressFragment RtlDefaultNpAcl RtlDelete RtlDeleteAce RtlDeleteAtomFromAtomTable RtlDeleteCriticalSection RtlDeleteElementGenericTable RtlDeleteElementGenericTableAvl RtlDeleteNoSplay RtlDeleteOwnersRanges RtlDeleteRange RtlDeleteRegistryValue RtlDeleteResource RtlDeleteSecurityObject RtlDeleteTimer RtlDeleteTimerQueue RtlDeleteTimerQueueEx RtlDeregisterWait RtlDeregisterWaitEx RtlDestroyAtomTable RtlDestroyEnvironment RtlDestroyHandleTable RtlDestroyProcessParameters RtlDestroyQueryDebugBuffer RtlDetermineDosPathNameType_U RtlDllShutdownInProgress RtlDnsHostNameToComputerName RtlDoesFileExists_U RtlDosApplyFileIsolationRedirection_Ustr RtlDosPathNameToNtPathName_U RtlDosSearchPath_U RtlDosSearchPath_Ustr RtlDowncaseUnicodeChar RtlDowncaseUnicodeString RtlDumpResource RtlDuplicateUnicodeString RtlEmptyAtomTable RtlEnableEarlyCriticalSectionEventCreation RtlEnterCriticalSection RtlEnumProcessHeaps RtlEnumerateGenericTable RtlEnumerateGenericTableAvl RtlEnumerateGenericTableLikeADirectory RtlEnumerateGenericTableWithoutSplaying RtlEnumerateGenericTableWithoutSplayingAvl RtlEqualComputerName RtlEqualDomainName RtlEqualLuid RtlEqualPrefixSid RtlEqualSid RtlEqualString RtlEqualUnicodeString RtlEraseUnicodeString RtlExitUserThread RtlExpandEnvironmentStrings_U RtlExtendHeap RtlFillMemory RtlFillMemoryUlong RtlFinalReleaseOutOfProcessMemoryStream RtlFindActivationContextSectionGuid RtlFindActivationContextSectionString RtlFindCharInUnicodeString RtlFindClearBits RtlFindClearBitsAndSet RtlFindClearRuns RtlFindLastBackwardRunClear RtlFindLeastSignificantBit RtlFindLongestRunClear RtlFindMessage RtlFindMostSignificantBit RtlFindNextForwardRunClear RtlFindRange RtlFindSetBits RtlFindSetBitsAndClear RtlFirstEntrySList RtlFirstFreeAce RtlFlushSecureMemoryCache RtlFormatCurrentUserKeyPath RtlFormatMessage RtlFreeAnsiString RtlFreeHandle RtlFreeOemString RtlFreeRangeList RtlFreeSid RtlFreeThreadActivationContextStack RtlFreeUnicodeString RtlFreeUserThreadStack RtlGUIDFromString RtlGenerate8dot3Name RtlGetAce RtlGetActiveActivationContext RtlGetCallersAddress RtlGetCompressionWorkSpaceSize RtlGetControlSecurityDescriptor RtlGetCurrentDirectory_U RtlGetCurrentPeb RtlGetDaclSecurityDescriptor RtlGetElementGenericTable RtlGetElementGenericTableAvl RtlGetFirstRange RtlGetFrame RtlGetFullPathName_U RtlGetGroupSecurityDescriptor RtlGetLastNtStatus RtlGetLastWin32Error RtlGetLengthWithoutLastFullDosOrNtPathElement RtlGetLengthWithoutTrailingPathSeperators RtlGetLongestNtPathLength RtlGetNativeSystemInformation RtlGetNextRange RtlGetNtGlobalFlags RtlGetNtProductType RtlGetNtVersionNumbers RtlGetOwnerSecurityDescriptor RtlGetProcessHeaps RtlGetSaclSecurityDescriptor RtlGetSecurityDescriptorRMControl RtlGetSetBootStatusData RtlGetUserInfoHeap RtlGetVersion RtlHashUnicodeString RtlIdentifierAuthoritySid RtlImageDirectoryEntryToData RtlImageRvaToSection RtlImageRvaToVa RtlImpersonateSelf RtlInitAnsiString RtlInitCodePageTable RtlInitMemoryStream RtlInitNlsTables RtlInitOutOfProcessMemoryStream RtlInitString RtlInitUnicodeString RtlInitUnicodeStringEx RtlInitializeAtomPackage RtlInitializeBitMap RtlInitializeContext RtlInitializeCriticalSection RtlInitializeCriticalSectionAndSpinCount RtlInitializeGenericTable RtlInitializeGenericTableAvl RtlInitializeHandleTable RtlInitializeRXact RtlInitializeRangeList RtlInitializeResource RtlInitializeSListHead RtlInitializeSid RtlInsertElementGenericTable RtlInsertElementGenericTableAvl RtlInt64ToUnicodeString RtlIntegerToChar RtlIntegerToUnicodeString RtlInterlockedFlushSList RtlInterlockedPopEntrySList RtlInterlockedPushEntrySList RtlInvertRangeList RtlIpv4AddressToStringA RtlIpv4AddressToStringW RtlIpv4StringToAddressA RtlIpv4StringToAddressW RtlIpv6AddressToStringA RtlIpv6AddressToStringW RtlIpv6StringToAddressA RtlIpv6StringToAddressW RtlIsActivationContextActive RtlIsDosDeviceName_U RtlIsGenericTableEmpty RtlIsGenericTableEmptyAvl RtlIsNameLegalDOS8Dot3 RtlIsRangeAvailable RtlIsTextUnicode RtlIsThreadWithinLoaderCallout RtlIsValidHandle RtlIsValidIndexHandle RtlLargeIntegerToChar RtlLeaveCriticalSection RtlLengthRequiredSid RtlLengthSecurityDescriptor RtlLengthSid RtlLocalTimeToSystemTime RtlLockBootStatusData RtlLockHeap RtlLockMemoryStreamRegion RtlLogStackBackTrace RtlLookupAtomInAtomTable RtlLookupElementGenericTable RtlLookupElementGenericTableAvl RtlMakeSelfRelativeSD RtlMapGenericMask RtlMapSecurityErrorToNtStatus RtlMergeRangeLists RtlMoveMemory RtlMultiAppendUnicodeStringBuffer RtlMultiByteToUnicodeSize RtlNewInstanceSecurityObject RtlNewSecurityGrantedAccess RtlNewSecurityObject RtlNewSecurityObjectEx RtlNewSecurityObjectWithMultipleInheritance RtlNormalizeProcessParams RtlNtPathNameToDosPathName RtlNtStatusToDosError RtlNtStatusToDosErrorNoTeb RtlNumberGenericTableElements RtlNumberGenericTableElementsAvl RtlNumberOfClearBits RtlNumberOfSetBits RtlOemStringToUnicodeSize RtlOemStringToUnicodeString RtlOemToUnicodeN RtlOpenCurrentUser RtlPcToFileHeader RtlPinAtomInAtomTable RtlPopFrame RtlPrefixString RtlPrefixUnicodeString RtlProtectHeap RtlPushFrame RtlQueryAtomInAtomTable RtlQueryDepthSList RtlQueryEnvironmentVariable_U RtlQueryHeapInformation RtlQueryInformationAcl RtlQueryInformationActivationContext RtlQueryInformationActiveActivationContext RtlQueryInterfaceMemoryStream RtlQueryProcessBackTraceInformation RtlQueryProcessDebugInformation RtlQueryProcessHeapInformation RtlQueryProcessLockInformation RtlQueryRegistryValues RtlQuerySecurityObject RtlQueryTagHeap RtlQueryTimeZoneInformation RtlQueueApcWow64Thread RtlQueueWorkItem RtlRaiseException RtlRaiseStatus RtlRandom RtlRandomEx RtlReadMemoryStream RtlReadOutOfProcessMemoryStream RtlRealPredecessor RtlRealSuccessor RtlRegisterSecureMemoryCacheCallback RtlRegisterWait RtlReleaseActivationContext RtlReleaseMemoryStream RtlReleasePebLock RtlReleaseResource RtlRemoteCall RtlRemoveVectoredExceptionHandler RtlResetRtlTranslations RtlRestoreLastWin32Error RtlRevertMemoryStream RtlRunDecodeUnicodeString RtlRunEncodeUnicodeString RtlSecondsSince1970ToTime RtlSecondsSince1980ToTime RtlSeekMemoryStream RtlSelfRelativeToAbsoluteSD2 RtlSelfRelativeToAbsoluteSD RtlSetAllBits RtlSetAttributesSecurityDescriptor RtlSetBits RtlSetControlSecurityDescriptor RtlSetCriticalSectionSpinCount RtlSetCurrentDirectory_U RtlSetCurrentEnvironment RtlSetDaclSecurityDescriptor RtlSetEnvironmentVariable RtlSetGroupSecurityDescriptor RtlSetHeapInformation RtlSetInformationAcl RtlSetIoCompletionCallback RtlSetLastWin32Error RtlSetLastWin32ErrorAndNtStatusFromNtStatus RtlSetMemoryStreamSize RtlSetOwnerSecurityDescriptor RtlSetProcessIsCritical RtlSetSaclSecurityDescriptor RtlSetSecurityDescriptorRMControl RtlSetSecurityObject RtlSetSecurityObjectEx RtlSetThreadIsCritical RtlSetThreadPoolStartFunc RtlSetTimeZoneInformation RtlSetTimer RtlSetUnicodeCallouts RtlSetUserFlagsHeap RtlSetUserValueHeap RtlSplay RtlStartRXact RtlStatMemoryStream RtlStringFromGUID RtlSubAuthorityCountSid RtlSubAuthoritySid RtlSubtreePredecessor RtlSubtreeSuccessor RtlSystemTimeToLocalTime RtlTimeFieldsToTime RtlTimeToElapsedTimeFields RtlTimeToSecondsSince1970 RtlTimeToSecondsSince1980 RtlTimeToTimeFields RtlTraceDatabaseAdd RtlTraceDatabaseCreate RtlTraceDatabaseDestroy RtlTraceDatabaseEnumerate RtlTraceDatabaseFind RtlTraceDatabaseLock RtlTraceDatabaseUnlock RtlTraceDatabaseValidate RtlTryEnterCriticalSection RtlUnhandledExceptionFilter2 RtlUnhandledExceptionFilter RtlUnicodeStringToAnsiSize RtlUnicodeStringToCountedOemString RtlUnicodeStringToInteger RtlUnicodeStringToOemSize RtlUnicodeStringToOemString RtlUnicodeToCustomCPN RtlUnicodeToMultiByteSize RtlUnicodeToOemN RtlUniform RtlUnlockBootStatusData RtlUnlockHeap RtlUnlockMemoryStreamRegion RtlUpcaseUnicodeChar RtlUpcaseUnicodeString RtlUpcaseUnicodeStringToAnsiString RtlUpcaseUnicodeStringToCountedOemString RtlUpcaseUnicodeStringToOemString RtlUpcaseUnicodeToCustomCPN RtlUpcaseUnicodeToMultiByteN RtlUpcaseUnicodeToOemN RtlUpdateTimer RtlUpperChar RtlUpperString RtlUsageHeap RtlValidAcl RtlValidRelativeSecurityDescriptor RtlValidSecurityDescriptor RtlValidSid RtlValidateProcessHeaps RtlValidateUnicodeString RtlVerifyVersionInfo RtlWalkFrameChain RtlWalkHeap RtlWriteMemoryStream RtlWriteRegistryValue RtlZeroHeap RtlZeroMemory RtlZombifyActivationContext RtlpApplyLengthFunction RtlpEnsureBufferSize RtlpNotOwnerCriticalSection RtlpNtCreateKey RtlpNtEnumerateSubKey RtlpNtMakeTemporaryKey RtlpNtOpenKey RtlpNtQueryValueKey RtlpNtSetValueKey RtlpUnWaitCriticalSection RtlpWaitForCriticalSection RtlxAnsiStringToUnicodeSize RtlxOemStringToUnicodeSize RtlxUnicodeStringToAnsiSize RtlxUnicodeStringToOemSize SaveEm87Context VerSetConditionMask ZwAcceptConnectPort ZwAccessCheck ZwAccessCheckAndAuditAlarm ZwAccessCheckByType ZwAccessCheckByTypeAndAuditAlarm ZwAccessCheckByTypeResultList ZwAccessCheckByTypeResultListAndAuditAlarm ZwAccessCheckByTypeResultListAndAuditAlarmByHandle ZwAddAtom ZwAddBootEntry ZwAdjustGroupsToken ZwAdjustPrivilegesToken ZwAlertResumeThread ZwAlertThread ZwAllocateLocallyUniqueId ZwAllocateUserPhysicalPages ZwAllocateUuids ZwAllocateVirtualMemory ZwAreMappedFilesTheSame ZwAssignProcessToJobObject ZwCallbackReturn ZwCancelDeviceWakeupRequest ZwCancelIoFile ZwCancelTimer ZwClearEvent ZwClose ZwCloseObjectAuditAlarm ZwCompactKeys ZwCompareTokens ZwCompleteConnectPort ZwCompressKey ZwConnectPort ZwContinue ZwCreateDebugObject ZwCreateDirectoryObject ZwCreateEvent ZwCreateEventPair ZwCreateFile ZwCreateIoCompletion ZwCreateJobObject ZwCreateJobSet ZwCreateKey ZwCreateKeyedEvent ZwCreateMailslotFile ZwCreateMutant ZwCreateNamedPipeFile ZwCreatePagingFile ZwCreatePort ZwCreateProcess ZwCreateProcessEx ZwCreateProfile ZwCreateSection ZwCreateSemaphore ZwCreateSymbolicLinkObject ZwCreateThread ZwCreateTimer ZwCreateToken ZwCreateWaitablePort ZwDebugActiveProcess ZwDebugContinue ZwDelayExecution ZwDeleteAtom ZwDeleteBootEntry ZwDeleteFile ZwDeleteKey ZwDeleteObjectAuditAlarm ZwDeleteValueKey ZwDeviceIoControlFile ZwDisplayString ZwDuplicateObject ZwDuplicateToken ZwEnumerateBootEntries ZwEnumerateKey ZwEnumerateSystemEnvironmentValuesEx ZwEnumerateValueKey ZwExtendSection ZwFilterToken ZwFindAtom ZwFlushBuffersFile ZwFlushInstructionCache ZwFlushKey ZwFlushVirtualMemory ZwFlushWriteBuffer ZwFreeUserPhysicalPages ZwFreeVirtualMemory ZwFsControlFile ZwGetContextThread ZwGetDevicePowerState ZwGetPlugPlayEvent ZwGetWriteWatch ZwImpersonateAnonymousToken ZwImpersonateClientOfPort ZwImpersonateThread ZwInitializeRegistry ZwInitiatePowerAction ZwIsProcessInJob ZwIsSystemResumeAutomatic ZwListenPort ZwLoadDriver ZwLoadKey2 ZwLoadKey ZwLockFile ZwLockProductActivationKeys ZwLockRegistryKey ZwLockVirtualMemory ZwMakePermanentObject ZwMakeTemporaryObject ZwMapUserPhysicalPages ZwMapUserPhysicalPagesScatter ZwMapViewOfSection ZwModifyBootEntry ZwNotifyChangeDirectoryFile ZwNotifyChangeKey ZwNotifyChangeMultipleKeys ZwOpenDirectoryObject ZwOpenEvent ZwOpenEventPair ZwOpenFile ZwOpenIoCompletion ZwOpenJobObject ZwOpenKey ZwOpenKeyedEvent ZwOpenMutant ZwOpenObjectAuditAlarm ZwOpenProcess ZwOpenProcessToken ZwOpenProcessTokenEx ZwOpenSection ZwOpenSemaphore ZwOpenSymbolicLinkObject ZwOpenThread ZwOpenThreadToken ZwOpenThreadTokenEx ZwOpenTimer ZwPlugPlayControl ZwPowerInformation ZwPrivilegeCheck ZwPrivilegeObjectAuditAlarm ZwPrivilegedServiceAuditAlarm ZwProtectVirtualMemory ZwPulseEvent ZwQueryAttributesFile ZwQueryBootEntryOrder ZwQueryBootOptions ZwQueryDebugFilterState ZwQueryDefaultLocale ZwQueryDefaultUILanguage ZwQueryDirectoryFile ZwQueryDirectoryObject ZwQueryEaFile ZwQueryEvent ZwQueryFullAttributesFile ZwQueryInformationAtom ZwQueryInformationFile ZwQueryInformationJobObject ZwQueryInformationPort ZwQueryInformationProcess ZwQueryInformationThread ZwQueryInformationToken ZwQueryInstallUILanguage ZwQueryIntervalProfile ZwQueryIoCompletion ZwQueryKey ZwQueryMultipleValueKey ZwQueryMutant ZwQueryObject ZwQueryOpenSubKeys ZwQueryPerformanceCounter ZwQueryPortInformationProcess ZwQueryQuotaInformationFile ZwQuerySection ZwQuerySecurityObject ZwQuerySemaphore ZwQuerySymbolicLinkObject ZwQuerySystemEnvironmentValue ZwQuerySystemEnvironmentValueEx ZwQuerySystemInformation ZwQuerySystemTime ZwQueryTimer ZwQueryTimerResolution ZwQueryValueKey ZwQueryVirtualMemory ZwQueryVolumeInformationFile ZwQueueApcThread ZwRaiseException ZwRaiseHardError ZwReadFile ZwReadFileScatter ZwReadRequestData ZwReadVirtualMemory ZwRegisterThreadTerminatePort ZwReleaseKeyedEvent ZwReleaseMutant ZwReleaseSemaphore ZwRemoveIoCompletion ZwRemoveProcessDebug ZwRenameKey ZwReplaceKey ZwReplyPort ZwReplyWaitReceivePort ZwReplyWaitReceivePortEx ZwReplyWaitReplyPort ZwRequestDeviceWakeup ZwRequestPort ZwRequestWaitReplyPort ZwRequestWakeupLatency ZwResetEvent ZwResetWriteWatch ZwRestoreKey ZwResumeProcess ZwResumeThread ZwSaveKey ZwSaveKeyEx ZwSaveMergedKeys ZwSecureConnectPort ZwSetBootEntryOrder ZwSetBootOptions ZwSetContextThread ZwSetDebugFilterState ZwSetDefaultHardErrorPort ZwSetDefaultLocale ZwSetDefaultUILanguage ZwSetEaFile ZwSetEvent ZwSetEventBoostPriority ZwSetHighEventPair ZwSetHighWaitLowEventPair ZwSetInformationDebugObject ZwSetInformationFile ZwSetInformationJobObject ZwSetInformationKey ZwSetInformationObject ZwSetInformationProcess ZwSetInformationThread ZwSetInformationToken ZwSetIntervalProfile ZwSetIoCompletion ZwSetLdtEntries ZwSetLowEventPair ZwSetLowWaitHighEventPair ZwSetQuotaInformationFile ZwSetSecurityObject ZwSetSystemEnvironmentValue ZwSetSystemEnvironmentValueEx ZwSetSystemInformation ZwSetSystemPowerState ZwSetSystemTime ZwSetThreadExecutionState ZwSetTimer ZwSetTimerResolution ZwSetUuidSeed ZwSetValueKey ZwSetVolumeInformationFile ZwShutdownSystem ZwSignalAndWaitForSingleObject ZwStartProfile ZwStopProfile ZwSuspendProcess ZwSuspendThread ZwSystemDebugControl ZwTerminateJobObject ZwTerminateProcess ZwTerminateThread ZwTestAlert ZwTraceEvent ZwTranslateFilePath ZwUnloadDriver ZwUnloadKey ZwUnloadKeyEx ZwUnlockFile ZwUnlockVirtualMemory ZwUnmapViewOfSection ZwVdmControl ZwWaitForDebugEvent ZwWaitForKeyedEvent ZwWaitForMultipleObjects ZwWaitForSingleObject ZwWaitHighEventPair ZwWaitLowEventPair ZwWriteFile ZwWriteFileGather ZwWriteRequestData ZwWriteVirtualMemory ZwYieldExecution _CIcos _CIlog _CIpow _CIsin _CIsqrt __eCommonExceptions __eEmulatorInit __eF2XM1 __eFABS __eFADD32 __eFADD64 __eFADDPreg __eFADDreg __eFADDtop __eFCHS __eFCOM __eFCOM32 __eFCOM64 __eFCOMP __eFCOMP32 __eFCOMP64 __eFCOMPP __eFCOS __eFDECSTP __eFDIV32 __eFDIV64 __eFDIVPreg __eFDIVR32 __eFDIVR64 __eFDIVRPreg __eFDIVRreg __eFDIVRtop __eFDIVreg __eFDIVtop __eFFREE __eFIADD16 __eFIADD32 __eFICOM16 __eFICOM32 __eFICOMP16 __eFICOMP32 __eFIDIV16 __eFIDIV32 __eFIDIVR16 __eFIDIVR32 __eFILD16 __eFILD32 __eFILD64 __eFIMUL16 __eFIMUL32 __eFINCSTP __eFINIT __eFIST16 __eFIST32 __eFISTP16 __eFISTP32 __eFISTP64 __eFISUB16 __eFISUB32 __eFISUBR16 __eFISUBR32 __eFLD1 __eFLD32 __eFLD64 __eFLD80 __eFLDCW __eFLDENV __eFLDL2E __eFLDLN2 __eFLDPI __eFLDZ __eFMUL32 __eFMUL64 __eFMULPreg __eFMULreg __eFMULtop __eFPATAN __eFPREM __eFPREM1 __eFPTAN __eFRNDINT __eFRSTOR __eFSAVE __eFSCALE __eFSIN __eFSQRT __eFST __eFST32 __eFST64 __eFSTCW __eFSTENV __eFSTP __eFSTP32 __eFSTP64 __eFSTP80 __eFSTSW __eFSUB32 __eFSUB64 __eFSUBPreg __eFSUBR32 __eFSUBR64 __eFSUBRPreg __eFSUBRreg __eFSUBRtop __eFSUBreg __eFSUBtop __eFTST __eFUCOM __eFUCOMP __eFUCOMPP __eFXAM __eFXCH __eFXTRACT __eFYL2X __eFYL2XP1 __eGetStatusWord __isascii __iscsym __iscsymf __toascii _alldiv _alldvrm _allmul _alloca_probe _allrem _allshl _allshr _atoi64 _aulldiv _aulldvrm _aullrem _aullshr _chkstk _fltused _ftol _i64toa _i64tow _itoa _itow _lfind _ltoa _ltow _memccpy _memicmp _snprintf _snwprintf _splitpath _strcmpi _stricmp _strlwr _strnicmp _strupr _tolower _toupper _ui64toa _ui64tow _ultoa _ultow _vsnprintf _vsnwprintf _wcsicmp _wcslwr _wcsnicmp _wcsupr _wtoi _wtoi64 _wtol abs atan atoi atol bsearch ceil cos fabs floor isalnum isalpha iscntrl isdigit isgraph islower isprint ispunct isspace isupper iswalpha iswctype iswdigit iswlower iswspace iswxdigit isxdigit labs log mbstowcs memchr memcmp memcpy memmove memset pow qsort sin sprintf sqrt sscanf strcat strchr strcmp strcpy strcspn strlen strncat strncmp strncpy strpbrk strrchr strspn strstr strtol strtoul swprintf tan tolower toupper towlower towupper vDbgPrintEx vDbgPrintExWithPrefix vsprintf wcscat wcschr wcscmp wcscpy wcscspn wcslen wcsncat wcsncmp wcsncpy wcspbrk wcsrchr wcsspn wcsstr wcstol wcstombs wcstoul

Found follow exports in USER32.DL
AlignRects AllowForegroundActivation AllowSetForegroundWindow AnimateWindow BlockInput BroadcastSystemMessageA BroadcastSystemMessageExA BroadcastSystemMessageExW BroadcastSystemMessageW BuildReasonArray CalcMenuBar ChangeDisplaySettingsExA ChangeDisplaySettingsExW CliImmSetHotKey ClientThreadSetup CreateDialogIndirectParamAorW CreateSystemThreads CsrBroadcastSystemMessageExW CtxInitUser32 DdeGetQualityOfService DefRawInputProc DeregisterShellHookWindow DestroyReasons DeviceEventWorker DialogBoxIndirectParamAorW DisableProcessWindowsGhosting DisplayExitWindowsWarnings DrawMenuBarTemp EndMenu EnterReaderModeHelper EnumDisplayDevicesA EnumDisplayDevicesW EnumDisplayMonitors EnumDisplaySettingsExA EnumDisplaySettingsExW FlashWindowEx GetAltTabInfo GetAltTabInfoA GetAltTabInfoW GetAncestor GetAppCompatFlags2 GetAppCompatFlags GetClipboardSequenceNumber GetComboBoxInfo GetCursorFrameInfo GetCursorInfo GetGUIThreadInfo GetGuiResources GetLastInputInfo GetLayeredWindowAttributes GetListBoxInfo GetMenuBarInfo GetMenuInfo GetMonitorInfoA GetMonitorInfoW GetMouseMovePointsEx GetProcessDefaultLayout GetProgmanWindow GetRawInputBuffer GetRawInputData GetRawInputDeviceInfoA GetRawInputDeviceInfoW GetRawInputDeviceList GetReasonTitleFromReasonCode GetRegisteredRawInputDevices GetScrollBarInfo GetTaskmanWindow GetTitleBarInfo GetWinStationInfo GetWindowInfo GetWindowModuleFileName GetWindowModuleFileNameA GetWindowModuleFileNameW GetWindowRgnBox IMPGetIMEA IMPGetIMEW IMPQueryIMEA IMPQueryIMEW IMPSetIMEA IMPSetIMEW InSendMessageEx InitializeLpkHooks InitializeWin32EntryTable IsGUIThread IsHungAppWindow IsServerSideWindow IsWinEventHookInstalled IsWindowInDestroy KillSystemTimer LoadKeyboardLayoutEx LoadLocalFonts LoadRemoteFonts LockSetForegroundWindow LockWorkStation MBToWCSEx MB_GetString MenuWindowProcA MenuWindowProcW MessageBoxTimeoutA MessageBoxTimeoutW MonitorFromPoint MonitorFromRect MonitorFromWindow MsgWaitForMultipleObjectsEx NotifyWinEvent PaintMenuBar PrintWindow PrivateExtractIconExA PrivateExtractIconExW PrivateExtractIconsA PrivateExtractIconsW PrivateSetDbgTag PrivateSetRipFlags QuerySendMessage QueryUserCounters RealChildWindowFromPoint RealGetWindowClass RealGetWindowClassA RealGetWindowClassW ReasonCodeNeedsBugID ReasonCodeNeedsComment RecordShutdownReason RegisterDeviceNotificationA RegisterDeviceNotificationW RegisterMessagePumpHook RegisterRawInputDevices RegisterServicesProcess RegisterShellHookWindow RegisterUserApiHook ResolveDesktopForWOW ScrollChildren SendIMEMessageExA SendIMEMessageExW SendInput SetConsoleReserveKeys SetCursorContents SetLayeredWindowAttributes SetLogonNotifyWindow SetMenuInfo SetProcessDefaultLayout SetProgmanWindow SetShellWindowEx SetSystemMenu SetSystemTimer SetTaskmanWindow SetWinEventHook SetWindowStationUser ShowStartGlass SoftModalMessageBox ToUnicodeEx TrackMouseEvent TranslateMessageEx UnhookWinEvent UnregisterDeviceNotification UnregisterMessagePumpHook UnregisterUserApiHook UpdateLayeredWindow UpdatePerUserSystemParameters User32InitializeImmEntryTable UserHandleGrantAccess UserLpkPSMTextOut UserLpkTabbedTextOut UserRealizePalette UserRegisterWowHandlers VRipOutput VTagOutput WCSToMBEx WINNLSEnableIME WINNLSGetEnableStatus WINNLSGetIMEHotkey Win32PoolAllocationStats

Found follow exports in GDI32.DL
AddFontMemResourceEx AddFontResourceExA AddFontResourceExW AddFontResourceTracking AnyLinkedFonts BRUSHOBJ_hGetColorTransform BRUSHOBJ_pvAllocRbrush BRUSHOBJ_pvGetRbrush BRUSHOBJ_ulGetBrushColor CLIPOBJ_bEnum CLIPOBJ_cEnumStart CLIPOBJ_ppoGetPath ClearBitmapAttributes ClearBrushAttributes ColorCorrectPalette CreateFontIndirectExA CreateFontIndirectExW DdEntry0 DdEntry10 DdEntry11 DdEntry12 DdEntry13 DdEntry14 DdEntry15 DdEntry16 DdEntry17 DdEntry18 DdEntry19 DdEntry1 DdEntry20 DdEntry21 DdEntry22 DdEntry23 DdEntry24 DdEntry25 DdEntry26 DdEntry27 DdEntry28 DdEntry29 DdEntry2 DdEntry30 DdEntry31 DdEntry32 DdEntry33 DdEntry34 DdEntry35 DdEntry36 DdEntry37 DdEntry38 DdEntry39 DdEntry3 DdEntry40 DdEntry41 DdEntry42 DdEntry43 DdEntry44 DdEntry45 DdEntry46 DdEntry47 DdEntry48 DdEntry49 DdEntry4 DdEntry50 DdEntry51 DdEntry52 DdEntry53 DdEntry54 DdEntry55 DdEntry56 DdEntry5 DdEntry6 DdEntry7 DdEntry8 DdEntry9 EnableEUDC EndFormPage EngAcquireSemaphore EngAlphaBlend EngAssociateSurface EngBitBlt EngCheckAbort EngComputeGlyphSet EngCopyBits EngCreateBitmap EngCreateClip EngCreateDeviceBitmap EngCreateDeviceSurface EngCreatePalette EngCreateSemaphore EngDeleteClip EngDeletePalette EngDeletePath EngDeleteSemaphore EngDeleteSurface EngEraseSurface EngFillPath EngFindResource EngFreeModule EngGetCurrentCodePage EngGetDriverName EngGetPrinterDataFileName EngGradientFill EngLineTo EngLoadModule EngLockSurface EngMarkBandingSurface EngMultiByteToUnicodeN EngMultiByteToWideChar EngPaint EngPlgBlt EngQueryEMFInfo EngQueryLocalTime EngReleaseSemaphore EngStretchBlt EngStretchBltROP EngStrokeAndFillPath EngStrokePath EngTextOut EngTransparentBlt EngUnicodeToMultiByteN EngUnlockSurface EngWideCharToMultiByte EudcLoadLinkW EudcUnloadLinkW FONTOBJ_cGetAllGlyphHandles FONTOBJ_cGetGlyphs FONTOBJ_pQueryGlyphAttrs FONTOBJ_pfdg FONTOBJ_pifi FONTOBJ_pvTrueTypeFontFile FONTOBJ_pxoGetXform FONTOBJ_vGetInfo FontIsLinked GdiAddFontResourceW GdiAddGlsBounds GdiAddGlsRecord GdiAlphaBlend GdiArtificialDecrementDriver GdiCleanCacheDC GdiConsoleTextOut GdiConvertAndCheckDC GdiConvertBitmap GdiConvertBitmapV5 GdiConvertBrush GdiConvertDC GdiConvertEnhMetaFile GdiConvertFont GdiConvertMetaFilePict GdiConvertPalette GdiConvertRegion GdiConvertToDevmodeW GdiCreateLocalEnhMetaFile GdiCreateLocalMetaFilePict GdiDeleteLocalDC GdiDeleteSpoolFileHandle GdiDescribePixelFormat GdiDllInitialize GdiDrawStream GdiEndDocEMF GdiEndPageEMF GdiEntry10 GdiEntry11 GdiEntry12 GdiEntry13 GdiEntry14 GdiEntry15 GdiEntry16 GdiEntry1 GdiEntry2 GdiEntry3 GdiEntry4 GdiEntry5 GdiEntry6 GdiEntry7 GdiEntry8 GdiEntry9 GdiFixUpHandle GdiFullscreenControl GdiGetCharDimensions GdiGetCodePage GdiGetDC GdiGetDevmodeForPage GdiGetLocalBrush GdiGetLocalDC GdiGetLocalFont GdiGetPageCount GdiGetPageHandle GdiGetSpoolFileHandle GdiGetSpoolMessage GdiGradientFill GdiInitSpool GdiInitializeLanguagePack GdiIsMetaFileDC GdiIsMetaPrintDC GdiIsPlayMetafileDC GdiPlayEMF GdiPlayPageEMF GdiPlayPrivatePageEMF GdiPrinterThunk GdiProcessSetup GdiQueryFonts GdiQueryTable GdiRealizationInfo GdiReleaseDC GdiReleaseLocalDC GdiResetDCEMF GdiSetAttrs GdiSetLastError GdiSetPixelFormat GdiSetServerAttr GdiStartDocEMF GdiStartPageEMF GdiSwapBuffers GdiTransparentBlt GdiValidateHandle GetBitmapAttributes GetBrushAttributes GetCharABCWidthsI GetCharWidthI GetCharWidthInfo GetDCBrushColor GetDCPenColor GetETM GetEUDCTimeStamp GetEUDCTimeStampExW GetEnhMetaFilePixelFormat GetFontAssocStatus GetFontResourceInfoW GetFontUnicodeRanges GetGlyphIndicesA GetGlyphIndicesW GetGlyphOutlineWow GetHFONT GetLayout GetRelAbs GetStringBitmapA GetStringBitmapW GetTextExtentExPointI GetTextExtentExPointWPri GetTextExtentPointI GetTextFaceAliasW GetTransform HT_Get8BPPFormatPalette HT_Get8BPPMaskPalette MirrorRgn NamedEscape PATHOBJ_bEnum PATHOBJ_bEnumClipLines PATHOBJ_vEnumStart PATHOBJ_vEnumStartClipLines PATHOBJ_vGetBounds PolyPatBlt QueryFontAssocStatus RemoveFontMemResourceEx RemoveFontResourceExA RemoveFontResourceExW RemoveFontResourceTracking STROBJ_bEnum STROBJ_bEnumPositionsOnly STROBJ_bGetAdvanceWidths STROBJ_dwGetCodePage STROBJ_vEnumStart SelectBrushLocal SelectFontLocal SetBitmapAttributes SetBrushAttributes SetDCBrushColor SetDCPenColor SetLayout SetLayoutWidth SetMagicColors SetRelAbs SetVirtualResolution StartFormPage UnloadNetworkFonts XFORMOBJ_bApplyXform XFORMOBJ_iGetXform XLATEOBJ_cGetPalette XLATEOBJ_hGetColorTransform XLATEOBJ_iXlate XLATEOBJ_piVector bInitSystemAndFontsDirectoriesW bMakePathNameW cGetTTFFromFOT

Found follow exports in SHELL32.DL
Activate_RunDLL AppCompat_RunDLLW CallCPLEntry16 CDefFolderMenu_Create CDefFolderMenu_Create2 CheckEscapesA Control_FillCache_RunDLL Control_FillCache_RunDLLA Control_FillCache_RunDLLW Control_RunDLLA Control_RunDLLAsUserW Control_RunDLLW DAD_AutoScroll DAD_DragEnterEx DAD_DragEnterEx2 DAD_DragLeave DAD_DragMove DAD_SetDragImage DAD_ShowDragImage DllCanUnloadNow DllGetVersion DllInstall DllRegisterServer DllUnregisterServer DriveType ExtractIconExW ExtractIconResInfoA ExtractIconResInfoW ExtractVersionResource16W FindExeDlgProc GetFileNameFromBrowse ILAppendID ILClone ILCloneFirst ILCombine ILCreateFromPath ILCreateFromPathA ILCreateFromPathW ILFindChild ILFindLastID ILFree ILGetNext ILGetSize ILIsEqual ILIsParent ILLoadFromStream ILRemoveLastID ILSaveToStream IsLFNDrive IsLFNDriveA IsLFNDriveW IsNetDrive IsUserAnAdmin OpenAs_RunDLLA OpenAs_RunDLLW OpenRegStream Options_RunDLL Options_RunDLLA Options_RunDLLW PathCleanupSpec PathGetShortPath PathIsExe PathIsSlowA PathIsSlowW PathMakeUniqueName PathProcessCommand PathQualify PathResolve PathYetAnotherMakeUniqueName PickIconDlg PifMgr_CloseProperties PifMgr_GetProperties PifMgr_OpenProperties PifMgr_SetProperties PrintersGetCommand_RunDLLA PrintersGetCommand_RunDLLW ReadCabinetState RealDriveType RestartDialog RestartDialogEx SHAddFromPropSheetExtArray SHAlloc SHAllocShared SHBindToParent SHBrowseForFolderW SHChangeNotification_Lock SHChangeNotification_Unlock SHChangeNotifyDeregister SHChangeNotifyRegister SHChangeNotifySuspendResume SHCloneSpecialIDList SHCLSIDFromString SHCoCreateInstance SHCreateDirectory SHCreateDirectoryExA SHCreateDirectoryExW SHCreateFileExtractIconW SHCreateLocalServerRunDll SHCreateProcessAsUserW SHCreatePropSheetExtArray SHCreateQueryCancelAutoPlayMoniker SHCreateShellFolderView SHCreateShellFolderViewEx SHCreateShellItem SHCreateStdEnumFmtEtc SHDefExtractIconA SHDefExtractIconW SHDestroyPropSheetExtArray SHDoDragDrop SheChangeDirExA SheChangeDirW SheConvertPathW SheFullPathA SheFullPathW SheGetCurDrive SheGetDirExW SheGetDirW SheGetPathOffsetW Shell_GetCachedImageIndex Shell_GetImageLists Shell_MergeMenus Shell_NotifyIconW ShellExec_RunDLL ShellExec_RunDLLA ShellExec_RunDLLW ShellExecuteExW ShellHookProc ShellMessageBoxA ShellMessageBoxW SHEmptyRecycleBinA SHEmptyRecycleBinW SHEnableServiceObject SHEnumerateUnreadMailAccountsW SheRemoveQuotesA SheRemoveQuotesW SheShortenPathA SheShortenPathW SHExtractIconsW SHFileOperationW SHFind_InitMenuPopup SHFindFiles SHFlushClipboard SHFlushSFCache SHFree SHFreeShared SHGetAttributesFromDataObject SHGetDataFromIDListW SHGetDiskFreeSpaceA SHGetDiskFreeSpaceExA SHGetDiskFreeSpaceExW SHGetFileInfoW SHGetFolderLocation SHGetFolderPathA SHGetFolderPathAndSubDirA SHGetFolderPathAndSubDirW SHGetFolderPathW SHGetIconOverlayIndexA SHGetIconOverlayIndexW SHGetNewLinkInfo SHGetNewLinkInfoA SHGetNewLinkInfoW SHGetPathFromIDListW SHGetRealIDL SHGetSetFolderCustomSettingsW SHGetSetSettings SHGetSettings SHGetShellStyleHInstance SHGetSpecialFolderPathA SHGetSpecialFolderPathW SHGetUnreadMailCountW SHHandleUpdateImage SHHelpShortcuts_RunDLLA SHHelpShortcuts_RunDLLW SHILCreateFromPath SHInvokePrinterCommandA SHInvokePrinterCommandW SHIsFileAvailableOffline SHLimitInputEdit SHLoadNonloadedIconOverlayIdentifiers SHLoadOLE SHLockShared SHMapIDListToImageListIndexAsync SHMapPIDLToSystemImageListIndex SHMultiFileProperties SHObjectProperties SHOpenFolderAndSelectItems SHOpenPropSheetW SHParseDisplayName SHPathPrepareForWriteA SHPathPrepareForWriteW SHPropStgCreate SHPropStgReadMultiple SHPropStgWriteMultiple SHQueryRecycleBinA SHQueryRecycleBinW SHReplaceFromPropSheetExtArray SHRestricted SHRunControlPanel SHSetInstanceExplorer SHSetLocalizedName SHSetUnreadMailCountW SHShellFolderView_Message SHSimpleIDListFromPath SHStartNetConnectionDialogW SHTestTokenMembership SHUnlockShared SHUpdateImageA SHUpdateImageW SHUpdateRecycleBinIcon SHValidateUNC SignalFileOpen StrChrA StrChrIA StrChrIW StrChrW StrCmpNA StrCmpNIA StrCmpNIW StrCmpNW StrCpyNA StrCpyNW StrNCmpA StrNCmpIA StrNCmpIW StrNCmpW StrNCpyA StrNCpyW StrRChrA StrRChrIA StrRChrIW StrRChrW StrRStrA StrRStrIA StrRStrIW StrRStrW StrStrA StrStrIA StrStrIW StrStrW Win32DeleteFile WOWShellExecute WriteCabinetState

Found follow exports in COMDLG32.DL
dwLBSubclass dwOKSubclass LoadAlterBitmap PrintDlgExA PrintDlgExW Ssync_ANSI_UNICODE_Struct_For_WOW WantArrows

Found follow exports in COMCTL32.DL
AddMRUStringW CreateMRUListW DefSubclassProc DllInstall DPA_Create DPA_DeleteAllPtrs DPA_DeletePtr DPA_Destroy DPA_DestroyCallback DPA_EnumCallback DPA_GetPtr DPA_InsertPtr DPA_Search DPA_SetPtr DPA_Sort DSA_Create DSA_DeleteAllItems DSA_Destroy DSA_DestroyCallback DSA_GetItemPtr DSA_InsertItem EnumMRUListW FreeMRUList ImageList_GetFlags RemoveWindowSubclass SetWindowSubclass Str_SetPtrW

Found follow exports in ADVAPI32.DL
I_ScGetCurrentGroupStateW A_SHAFinal A_SHAInit A_SHAUpdate AccessCheckByType AccessCheckByTypeAndAuditAlarmA AccessCheckByTypeAndAuditAlarmW AccessCheckByTypeResultList AccessCheckByTypeResultListAndAuditAlarmA AccessCheckByTypeResultListAndAuditAlarmByHandleA AccessCheckByTypeResultListAndAuditAlarmByHandleW AccessCheckByTypeResultListAndAuditAlarmW AddAccessAllowedAceEx AddAccessAllowedObjectAce AddAccessDeniedAceEx AddAccessDeniedObjectAce AddAuditAccessAceEx AddAuditAccessObjectAce AddUsersToEncryptedFile BuildExplicitAccessWithNameA BuildExplicitAccessWithNameW BuildImpersonateExplicitAccessWithNameA BuildImpersonateExplicitAccessWithNameW BuildImpersonateTrusteeA BuildImpersonateTrusteeW BuildSecurityDescriptorA BuildSecurityDescriptorW BuildTrusteeWithNameA BuildTrusteeWithNameW BuildTrusteeWithObjectsAndNameA BuildTrusteeWithObjectsAndNameW BuildTrusteeWithObjectsAndSidA BuildTrusteeWithObjectsAndSidW BuildTrusteeWithSidA BuildTrusteeWithSidW CancelOverlappedAccess ChangeServiceConfig2A ChangeServiceConfig2W CheckTokenMembership CloseCodeAuthzLevel CloseEncryptedFileRaw CloseTrace CommandLineFromMsiDescriptor ComputeAccessTokenFromCodeAuthzLevel ControlTraceA ControlTraceW ConvertAccessToSecurityDescriptorA ConvertAccessToSecurityDescriptorW ConvertSDToStringSDRootDomainA ConvertSDToStringSDRootDomainW ConvertSecurityDescriptorToAccessA ConvertSecurityDescriptorToAccessNamedA ConvertSecurityDescriptorToAccessNamedW ConvertSecurityDescriptorToAccessW ConvertSecurityDescriptorToStringSecurityDescriptorA ConvertSecurityDescriptorToStringSecurityDescriptorW ConvertSidToStringSidA ConvertSidToStringSidW ConvertStringSDToSDDomainA ConvertStringSDToSDDomainW ConvertStringSDToSDRootDomainA ConvertStringSDToSDRootDomainW ConvertStringSecurityDescriptorToSecurityDescriptorA ConvertStringSecurityDescriptorToSecurityDescriptorW ConvertStringSidToSidA ConvertStringSidToSidW ConvertToAutoInheritPrivateObjectSecurity CreateCodeAuthzLevel CreatePrivateObjectSecurityEx CreatePrivateObjectSecurityWithMultipleInheritance CreateProcessWithLogonW CreateRestrictedToken CreateTraceInstanceId CreateWellKnownSid CredDeleteA CredDeleteW CredEnumerateA CredEnumerateW CredFree CredGetSessionTypes CredGetTargetInfoA CredGetTargetInfoW CredIsMarshaledCredentialA CredIsMarshaledCredentialW CredMarshalCredentialA CredMarshalCredentialW CredProfileLoaded CredReadA CredReadDomainCredentialsA CredReadDomainCredentialsW CredReadW CredRenameA CredRenameW CredUnmarshalCredentialA CredUnmarshalCredentialW CredWriteA CredWriteDomainCredentialsA CredWriteDomainCredentialsW CredWriteW CredpConvertCredential CredpConvertTargetInfo CredpDecodeCredential CredpEncodeCredential CryptAcquireContextW CryptContextAddRef CryptDuplicateHash CryptDuplicateKey CryptEnumProviderTypesA CryptEnumProviderTypesW CryptEnumProvidersA CryptEnumProvidersW CryptGetDefaultProviderA CryptGetDefaultProviderW CryptSetProviderExA CryptSetProviderExW CryptSetProviderW CryptSignHashW CryptVerifySignatureW DecryptFileA DecryptFileW DuplicateEncryptionInfoFile DuplicateTokenEx ElfBackupEventLogFileA ElfBackupEventLogFileW ElfChangeNotify ElfClearEventLogFileA ElfClearEventLogFileW ElfCloseEventLog ElfDeregisterEventSource ElfNumberOfRecords ElfOldestRecord ElfOpenBackupEventLogA ElfOpenBackupEventLogW ElfOpenEventLogA ElfOpenEventLogW ElfReadEventLogA ElfReadEventLogW ElfRegisterEventSourceA ElfRegisterEventSourceW ElfReportEventA ElfReportEventW EnableTrace EncryptFileA EncryptFileW EncryptedFileKeyInfo EncryptionDisable EnumServiceGroupW EnumServicesStatusExA EnumServicesStatusExW EnumerateTraceGuids EqualDomainSid FileEncryptionStatusA FileEncryptionStatusW FlushTraceA FlushTraceW FreeEncryptedFileKeyInfo FreeEncryptionCertificateHashList FreeInheritedFromArray GetAccessPermissionsForObjectA GetAccessPermissionsForObjectW GetAuditedPermissionsFromAclA GetAuditedPermissionsFromAclW GetCurrentHwProfileA GetCurrentHwProfileW GetEffectiveRightsFromAclA GetEffectiveRightsFromAclW GetEventLogInformation GetExplicitEntriesFromAclA GetExplicitEntriesFromAclW GetInformationCodeAuthzLevelW GetInformationCodeAuthzPolicyW GetInheritanceSourceA GetInheritanceSourceW GetLocalManagedApplicationData GetLocalManagedApplications GetManagedApplicationCategories GetManagedApplications GetMultipleTrusteeA GetMultipleTrusteeOperationA GetMultipleTrusteeOperationW GetMultipleTrusteeW GetNamedSecurityInfoA GetNamedSecurityInfoExA GetNamedSecurityInfoExW GetNamedSecurityInfoW GetOverlappedAccessResults GetSecurityDescriptorRMControl GetSecurityInfo GetSecurityInfoExA GetSecurityInfoExW GetTraceEnableFlags GetTraceEnableLevel GetTraceLoggerHandle GetTrusteeFormA GetTrusteeFormW GetTrusteeNameA GetTrusteeNameW GetTrusteeTypeA GetTrusteeTypeW GetWindowsAccountDomainSid I_ScIsSecurityProcess I_ScPnPGetServiceName I_ScSendTSMessage I_ScSetServiceBitsA I_ScSetServiceBitsW IdentifyCodeAuthzLevelW ImpersonateAnonymousToken InitiateSystemShutdownExA InitiateSystemShutdownExW InstallApplication IsTokenRestricted IsTokenUntrusted IsWellKnownSid LogonUserExA LogonUserExW LookupSecurityDescriptorPartsA LookupSecurityDescriptorPartsW LsaAddAccountRights LsaAddPrivilegesToAccount LsaClearAuditLog LsaClose LsaCreateAccount LsaCreateSecret LsaCreateTrustedDomain LsaCreateTrustedDomainEx LsaDelete LsaDeleteTrustedDomain LsaEnumerateAccountRights LsaEnumerateAccounts LsaEnumerateAccountsWithUserRight LsaEnumeratePrivileges LsaEnumeratePrivilegesOfAccount LsaEnumerateTrustedDomains LsaEnumerateTrustedDomainsEx LsaFreeMemory LsaGetQuotasForAccount LsaGetRemoteUserName LsaGetSystemAccessAccount LsaGetUserName LsaICLookupNames LsaICLookupNamesWithCreds LsaICLookupSids LsaICLookupSidsWithCreds LsaLookupNames2 LsaLookupNames LsaLookupPrivilegeDisplayName LsaLookupPrivilegeName LsaLookupPrivilegeValue LsaLookupSids LsaNtStatusToWinError LsaOpenAccount LsaOpenPolicy LsaOpenPolicySce LsaOpenSecret LsaOpenTrustedDomain LsaOpenTrustedDomainByName LsaQueryDomainInformationPolicy LsaQueryForestTrustInformation LsaQueryInfoTrustedDomain LsaQueryInformationPolicy LsaQuerySecret LsaQuerySecurityObject LsaQueryTrustedDomainInfo LsaQueryTrustedDomainInfoByName LsaRemoveAccountRights LsaRemovePrivilegesFromAccount LsaRetrievePrivateData LsaSetDomainInformationPolicy LsaSetForestTrustInformation LsaSetInformationPolicy LsaSetInformationTrustedDomain LsaSetQuotasForAccount LsaSetSecret LsaSetSecurityObject LsaSetSystemAccessAccount LsaSetTrustedDomainInfoByName LsaSetTrustedDomainInformation LsaStorePrivateData MD4Final MD4Init MD4Update MD5Final MD5Init MD5Update MSChapSrvChangePassword2 MSChapSrvChangePassword MakeAbsoluteSD2 ObjectDeleteAuditAlarmA ObjectDeleteAuditAlarmW OpenEncryptedFileRawA OpenEncryptedFileRawW OpenTraceA OpenTraceW ProcessIdleTasks ProcessTrace QueryAllTracesA QueryAllTracesW QueryRecoveryAgentsOnEncryptedFile QueryServiceConfig2A QueryServiceConfig2W QueryServiceStatusEx QueryTraceA QueryTraceW QueryUsersOnEncryptedFile QueryWindows31FilesMigration ReadEncryptedFileRaw RegDisablePredefinedCache RegOpenCurrentUser RegOpenUserClassesRoot RegOverridePredefKey RegSaveKeyExA RegSaveKeyExW RegisterIdleTask RegisterServiceCtrlHandlerExA RegisterServiceCtrlHandlerExW RegisterTraceGuidsA RegisterTraceGuidsW RemoveTraceCallback RemoveUsersFromEncryptedFile SaferCloseLevel SaferComputeTokenFromLevel SaferCreateLevel SaferGetLevelInformation SaferGetPolicyInformation SaferIdentifyLevel SaferRecordEventLogEntry SaferSetLevelInformation SaferSetPolicyInformation SaferiChangeRegistryScope SaferiCompareTokenLevels SaferiIsExecutableFileType SaferiPopulateDefaultsInRegistry SaferiRecordEventLogEntry SaferiReplaceProcessThreadTokens SaferiSearchMatchingHashRules SetEntriesInAccessListA SetEntriesInAccessListW SetEntriesInAclA SetEntriesInAclW SetEntriesInAuditListA SetEntriesInAuditListW SetInformationCodeAuthzLevelW SetInformationCodeAuthzPolicyW SetNamedSecurityInfoA SetNamedSecurityInfoExA SetNamedSecurityInfoExW SetNamedSecurityInfoW SetPrivateObjectSecurityEx SetSecurityDescriptorControl SetSecurityDescriptorRMControl SetSecurityInfo SetSecurityInfoExA SetSecurityInfoExW SetTraceCallback SetUserFileEncryptionKey StartTraceA StartTraceW StopTraceA StopTraceW SynchronizeWindows31FilesAndWindowsNTRegistry SystemFunction001 SystemFunction002 SystemFunction003 SystemFunction004 SystemFunction005 SystemFunction006 SystemFunction007 SystemFunction008 SystemFunction009 SystemFunction010 SystemFunction011 SystemFunction012 SystemFunction013 SystemFunction014 SystemFunction015 SystemFunction016 SystemFunction017 SystemFunction018 SystemFunction019 SystemFunction020 SystemFunction021 SystemFunction022 SystemFunction023 SystemFunction024 SystemFunction025 SystemFunction026 SystemFunction027 SystemFunction028 SystemFunction029 SystemFunction030 SystemFunction031 SystemFunction032 SystemFunction033 SystemFunction034 SystemFunction035 SystemFunction036 SystemFunction040 SystemFunction041 TraceEvent TraceEventInstance TraceMessage TraceMessageVa TreeResetNamedSecurityInfoA TreeResetNamedSecurityInfoW TrusteeAccessToObjectA TrusteeAccessToObjectW UninstallApplication UnregisterIdleTask UnregisterTraceGuids UpdateTraceA UpdateTraceW WdmWmiServiceMain WmiCloseBlock WmiCloseTraceWithCursor WmiConvertTimestamp WmiDevInstToInstanceNameA WmiDevInstToInstanceNameW WmiEnumerateGuids WmiExecuteMethodA WmiExecuteMethodW WmiFileHandleToInstanceNameA WmiFileHandleToInstanceNameW WmiFreeBuffer WmiGetFirstTraceOffset WmiGetNextEvent WmiGetTraceHeader WmiMofEnumerateResourcesA WmiMofEnumerateResourcesW WmiNotificationRegistrationA WmiNotificationRegistrationW WmiOpenBlock WmiOpenTraceWithCursor WmiParseTraceEvent WmiQueryAllDataA WmiQueryAllDataMultipleA WmiQueryAllDataMultipleW WmiQueryAllDataW WmiQueryGuidInformation WmiQuerySingleInstanceA WmiQuerySingleInstanceMultipleA WmiQuerySingleInstanceMultipleW WmiQuerySingleInstanceW WmiReceiveNotificationsA WmiReceiveNotificationsW WmiSetSingleInstanceA WmiSetSingleInstanceW WmiSetSingleItemA WmiSetSingleItemW Wow64Win32ApiEntry WriteEncryptedFileRaw

Found follow exports in WSOCK32.DL
MigrateWinsockConfiguration WEP WSApSetPostRoutine inet_network getnetbyname rcmd rexec rresvport sethostname AcceptEx GetAcceptExSockaddrs

Found follow exports in WS2_32.DL
accept bind closesocket connect getpeername getsockname getsockopt htonl htons ioctlsocket inet_addr inet_ntoa listen ntohl ntohs recv recvfrom select send sendto setsockopt shutdown socket WSApSetPostRoutine WPUCompleteOverlappedRequest WSAAccept WSAAddressToStringA WSAAddressToStringW WSACloseEvent WSAConnect WSACreateEvent WSADuplicateSocketA WSADuplicateSocketW WSAEnumNameSpaceProvidersA WSAEnumNameSpaceProvidersW WSAEnumNetworkEvents WSAEnumProtocolsA WSAEnumProtocolsW WSAEventSelect WSAGetOverlappedResult WSAGetQOSByName WSAGetServiceClassInfoA WSAGetServiceClassInfoW WSAGetServiceClassNameByClassIdA WSAGetServiceClassNameByClassIdW WSAHtonl WSAHtons WSAInstallServiceClassA WSAInstallServiceClassW WSAIoctl gethostbyaddr gethostbyname getprotobyname getprotobynumber getservbyname getservbyport gethostname WSAJoinLeaf WSALookupServiceBeginA WSALookupServiceBeginW WSALookupServiceEnd WSALookupServiceNextA WSALookupServiceNextW WSANSPIoctl WSANtohl WSANtohs WSAProviderConfigChange WSARecv WSARecvDisconnect WSARecvFrom WSARemoveServiceClass WSAResetEvent WSASend WSASendDisconnect WSASendTo WSASetEvent WSASetServiceA WSASetServiceW WSASocketA WSASocketW WSAStringToAddressA WSAStringToAddressW WSAWaitForMultipleEvents WSCDeinstallProvider WSCEnableNSProvider WSCEnumProtocols WSCGetProviderPath WSCInstallNameSpace WSCInstallProvider WSCUnInstallNameSpace WSCUpdateProvider WSCWriteNameSpaceOrder WSCWriteProviderOrder freeaddrinfo getaddrinfo getnameinfo WSAAsyncSelect WSAAsyncGetHostByAddr WSAAsyncGetHostByName WSAAsyncGetProtoByNumber WSAAsyncGetProtoByName WSAAsyncGetServByPort WSAAsyncGetServByName WSACancelAsyncRequest WSASetBlockingHook WSAUnhookBlockingHook WSAGetLastError WSASetLastError WSACancelBlockingCall WSAIsBlocking WSAStartup WSACleanup __WSAFDIsSet WEP

Windows Vista


Found follow exports in KERNEL32.DL
AcquireSRWLockExclusive AcquireSRWLockShared ActivateActCtx AddConsoleAliasA AddConsoleAliasW AddLocalAlternateComputerNameA AddLocalAlternateComputerNameW AddRefActCtx AddSIDToBoundaryDescriptor AddVectoredContinueHandler AddVectoredExceptionHandler AdjustCalendarDate AllocateUserPhysicalPages AllocateUserPhysicalPagesNuma ApplicationRecoveryFinished ApplicationRecoveryInProgress AssignProcessToJobObject AttachConsole BaseCheckAppcompatCache BaseCheckRunApp BaseCleanupAppcompatCacheSupport BaseDumpAppcompatCache BaseFlushAppcompatCache BaseGenerateAppCompatData BaseInitAppcompatCacheSupport BaseIsAppcompatInfrastructureDisabled BasepCheckBadapp BasepCheckWinSaferRestrictions BasepFreeAppCompatData BaseQueryModuleData BaseThreadInitThunk BaseUpdateAppcompatCache BindIoCompletionCallback CallbackMayRunLong CancelDeviceWakeupRequest CancelIo CancelIoEx CancelSynchronousIo CancelThreadpoolIo CancelTimerQueueTimer CancelWaitableTimer ChangeTimerQueueTimer CheckElevation CheckElevationEnabled CheckForReadOnlyResource CheckNameLegalDOS8Dot3A CheckNameLegalDOS8Dot3W CheckRemoteDebuggerPresent CloseConsoleHandle ClosePrivateNamespace CloseThreadpool CloseThreadpoolCleanupGroup CloseThreadpoolCleanupGroupMembers CloseThreadpoolIo CloseThreadpoolTimer CloseThreadpoolWait CloseThreadpoolWork CmdBatNotification CompareCalendarDates CompareStringEx CompareStringOrdinal ConsoleMenuControl ConvertCalDateTimeToSystemTime ConvertFiberToThread ConvertNLSDayOfWeekToWin32DayOfWeek ConvertSystemTimeToCalDateTime ConvertThreadToFiber ConvertThreadToFiberEx CopyFileExA CopyFileExW CopyFileTransactedA CopyFileTransactedW CopyLZFile CreateActCtxA CreateActCtxW CreateBoundaryDescriptorA CreateBoundaryDescriptorW CreateDirectoryTransactedA CreateDirectoryTransactedW CreateEventExA CreateEventExW CreateFiber CreateFiberEx CreateFileMappingNumaA CreateFileMappingNumaW CreateFileTransactedA CreateFileTransactedW CreateHardLinkA CreateHardLinkTransactedA CreateHardLinkTransactedW CreateHardLinkW CreateJobObjectA CreateJobObjectW CreateJobSet CreateMemoryResourceNotification CreateMutexExA CreateMutexExW CreatePrivateNamespaceA CreatePrivateNamespaceW CreateProcessInternalA CreateProcessInternalW CreateSemaphoreExA CreateSemaphoreExW CreateSocketHandle CreateSymbolicLinkA CreateSymbolicLinkTransactedA CreateSymbolicLinkTransactedW CreateSymbolicLinkW CreateThreadpool CreateThreadpoolCleanupGroup CreateThreadpoolIo CreateThreadpoolTimer CreateThreadpoolWait CreateThreadpoolWork CreateTimerQueue CreateTimerQueueTimer CreateToolhelp32Snapshot CreateWaitableTimerA CreateWaitableTimerExA CreateWaitableTimerExW CreateWaitableTimerW DeactivateActCtx DebugActiveProcessStop DebugBreakProcess DebugSetProcessKillOnExit DecodePointer DecodeSystemPointer DelayLoadFailureHook DeleteBoundaryDescriptor DeleteFiber DeleteFileTransactedA DeleteFileTransactedW DeleteProcThreadAttributeList DeleteTimerQueue DeleteTimerQueueEx DeleteTimerQueueTimer DeleteVolumeMountPointA DeleteVolumeMountPointW DisassociateCurrentThreadFromCallback DnsHostnameToComputerNameA DnsHostnameToComputerNameW DosPathToSessionPathA DosPathToSessionPathW DuplicateConsoleHandle EncodePointer EncodeSystemPointer EnumCalendarInfoExA EnumCalendarInfoExEx EnumCalendarInfoExW EnumDateFormatsExA EnumDateFormatsExEx EnumDateFormatsExW EnumerateLocalComputerNamesA EnumerateLocalComputerNamesW EnumLanguageGroupLocalesA EnumLanguageGroupLocalesW EnumResourceLanguagesExA EnumResourceLanguagesExW EnumResourceNamesExA EnumResourceNamesExW EnumResourceTypesExA EnumResourceTypesExW EnumSystemFirmwareTables EnumSystemGeoID EnumSystemLanguageGroupsA EnumSystemLanguageGroupsW EnumSystemLocalesEx EnumTimeFormatsEx EnumUILanguagesA EnumUILanguagesW ExitVDM ExpungeConsoleCommandHistoryA ExpungeConsoleCommandHistoryW FindActCtxSectionGuid FindActCtxSectionStringA FindActCtxSectionStringW FindFirstFileExA FindFirstFileExW FindFirstFileNameTransactedW FindFirstFileNameW FindFirstFileTransactedA FindFirstFileTransactedW FindFirstStreamTransactedW FindFirstStreamW FindFirstVolumeA FindFirstVolumeMountPointA FindFirstVolumeMountPointW FindFirstVolumeW FindNextFileNameW FindNextStreamW FindNextVolumeA FindNextVolumeMountPointA FindNextVolumeMountPointW FindNextVolumeW FindNLSString FindNLSStringEx FindVolumeClose FindVolumeMountPointClose FlsAlloc FlsFree FlsGetValue FlsSetValue FlushProcessWriteBuffers FreeLibraryWhenCallbackReturns FreeUserPhysicalPages GetApplicationRecoveryCallback GetApplicationRestartSettings GetCalendarDateFormat GetCalendarDateFormatEx GetCalendarDaysInMonth GetCalendarDifferenceInDays GetCalendarInfoA GetCalendarInfoEx GetCalendarInfoW GetCalendarMonthsInYear GetCalendarSupportedDateRange GetCalendarWeekNumber GetComPlusPackageInstallStatus GetCompressedFileSizeTransactedA GetCompressedFileSizeTransactedW GetComputerNameExA GetComputerNameExW GetConsoleAliasA GetConsoleAliasesA GetConsoleAliasesLengthA GetConsoleAliasesLengthW GetConsoleAliasesW GetConsoleAliasExesA GetConsoleAliasExesLengthA GetConsoleAliasExesLengthW GetConsoleAliasExesW GetConsoleAliasW GetConsoleCharType GetConsoleCommandHistoryA GetConsoleCommandHistoryLengthA GetConsoleCommandHistoryLengthW GetConsoleCommandHistoryW GetConsoleCursorMode GetConsoleDisplayMode GetConsoleFontInfo GetConsoleFontSize GetConsoleHardwareState GetConsoleHistoryInfo GetConsoleInputExeNameA GetConsoleInputExeNameW GetConsoleInputWaitHandle GetConsoleKeyboardLayoutNameA GetConsoleKeyboardLayoutNameW GetConsoleNlsMode GetConsoleOriginalTitleA GetConsoleOriginalTitleW GetConsoleProcessList GetConsoleScreenBufferInfoEx GetConsoleSelectionInfo GetConsoleWindow GetCPFileNameFromRegistry GetCPInfoExA GetCPInfoExW GetCurrencyFormatEx GetCurrentActCtx GetCurrentConsoleFont GetCurrentConsoleFontEx GetCurrentProcessorNumber GetDateFormatEx GetDevicePowerState GetDllDirectoryA GetDllDirectoryW GetDurationFormat GetDurationFormatEx GetDynamicTimeZoneInformation GetErrorMode GetExpandedNameA GetExpandedNameW GetFileAttributesExA GetFileAttributesExW GetFileAttributesTransactedA GetFileAttributesTransactedW GetFileBandwidthReservation GetFileInformationByHandleEx GetFileMUIInfo GetFileMUIPath GetFileSizeEx GetFinalPathNameByHandleA GetFinalPathNameByHandleW GetFirmwareEnvironmentVariableA GetFirmwareEnvironmentVariableW GetFullPathNameTransactedA GetFullPathNameTransactedW GetGeoInfoA GetGeoInfoW GetHandleContext GetLargePageMinimum GetLocaleInfoEx GetLogicalProcessorInformation GetLongPathNameA GetLongPathNameTransactedA GetLongPathNameTransactedW GetLongPathNameW GetModuleHandleExA GetModuleHandleExW GetNamedPipeAttribute GetNamedPipeClientComputerNameA GetNamedPipeClientComputerNameW GetNamedPipeClientProcessId GetNamedPipeClientSessionId GetNamedPipeServerProcessId GetNamedPipeServerSessionId GetNativeSystemInfo GetNextVDMCommand GetNLSVersion GetNLSVersionEx GetNumaAvailableMemoryNode GetNumaHighestNodeNumber GetNumaNodeProcessorMask GetNumaProcessorNode GetNumaProximityNode GetNumberFormatEx GetNumberOfConsoleFonts GetProcessHandleCount GetProcessId GetProcessIdOfThread GetProcessIoCounters GetProcessPriorityBoost GetProcessWorkingSetSizeEx GetProductInfo GetQueuedCompletionStatusEx GetStringScripts GetSystemDefaultLocaleName GetSystemDefaultUILanguage GetSystemFileCacheSize GetSystemFirmwareTable GetSystemPreferredUILanguages GetSystemRegistryQuota GetSystemTimes GetSystemWindowsDirectoryA GetSystemWindowsDirectoryW GetSystemWow64DirectoryA GetSystemWow64DirectoryW GetThreadId GetThreadIOPendingFlag GetThreadPreferredUILanguages GetThreadPriorityBoost GetThreadUILanguage GetTickCount64 GetTimeFormatEx GetUILanguageInfo GetUserDefaultLocaleName GetUserDefaultUILanguage GetUserGeoID GetUserPreferredUILanguages GetVDMCurrentDirectories GetVolumeInformationByHandleW GetVolumeNameForVolumeMountPointA GetVolumeNameForVolumeMountPointW GetVolumePathNameA GetVolumePathNamesForVolumeNameA GetVolumePathNamesForVolumeNameW GetVolumePathNameW GetWriteWatch GlobalMemoryStatusEx Heap32First Heap32ListFirst Heap32ListNext Heap32Next HeapQueryInformation HeapSetInformation HeapSummary IdnToAscii IdnToNameprepUnicode IdnToUnicode InitializeConditionVariable InitializeCriticalSectionAndSpinCount InitializeCriticalSectionEx InitializeProcThreadAttributeList InitializeSListHead InitializeSRWLock InitOnceBeginInitialize InitOnceComplete InitOnceExecuteOnce InitOnceInitialize InterlockedCompareExchange InterlockedCompareExchange64 InterlockedExchangeAdd InterlockedFlushSList InterlockedPopEntrySList InterlockedPushEntrySList InterlockedPushListSList InvalidateConsoleDIBits IsCalendarLeapDay IsCalendarLeapMonth IsCalendarLeapYear IsDebuggerPresent IsNLSDefinedString IsNormalizedString IsProcessInJob IsProcessorFeaturePresent IsSystemResumeAutomatic IsThreadAFiber IsThreadpoolTimerSet IsTimeZoneRedirectionEnabled IsValidCalDateTime IsValidLanguageGroup IsValidLocaleName IsWow64Process LCIDToLocaleName LCMapStringEx LeaveCriticalSectionWhenCallbackReturns LoadStringBaseExW LoadStringBaseW LocaleNameToLCID LZClose LZCloseFile LZCopy LZCreateFileW LZDone LZInit LZOpenFileA LZOpenFileW LZRead LZSeek LZStart MapUserPhysicalPages MapUserPhysicalPagesScatter MapViewOfFileExNuma Module32First Module32FirstW Module32Next Module32NextW MoveFileTransactedA MoveFileTransactedW MoveFileWithProgressA MoveFileWithProgressW NeedCurrentDirectoryForExePathA NeedCurrentDirectoryForExePathW NlsCheckPolicy NlsConvertIntegerToString NlsEventDataDescCreate NlsGetCacheUpdateCount NlsUpdateLocale NlsUpdateSystemLocale NlsWriteEtwEvent NormalizeString NotifyUILanguageChange OpenConsoleW OpenFileById OpenJobObjectA OpenJobObjectW OpenPrivateNamespaceA OpenPrivateNamespaceW OpenThread OpenWaitableTimerA OpenWaitableTimerW PrivCopyFileExW PrivMoveFileIdentityW Process32First Process32FirstW Process32Next Process32NextW ProcessIdToSessionId QueryActCtxSettingsW QueryActCtxW QueryDepthSList QueryFullProcessImageNameA QueryFullProcessImageNameW QueryIdleProcessorCycleTime QueryInformationJobObject QueryMemoryResourceNotification QueryProcessCycleTime QueryThreadCycleTime QueueUserWorkItem ReadConsoleInputExA ReadConsoleInputExW ReadDirectoryChangesW ReadFileScatter RegisterApplicationRecoveryCallback RegisterApplicationRestart RegisterConsoleIME RegisterConsoleOS2 RegisterConsoleVDM RegisterWaitForInputIdle RegisterWaitForSingleObject RegisterWaitForSingleObjectEx RegisterWowBaseHandlers RegisterWowExec ReleaseActCtx ReleaseMutexWhenCallbackReturns ReleaseSemaphoreWhenCallbackReturns ReleaseSRWLockExclusive ReleaseSRWLockShared RemoveDirectoryTransactedA RemoveDirectoryTransactedW RemoveLocalAlternateComputerNameA RemoveLocalAlternateComputerNameW RemoveVectoredContinueHandler RemoveVectoredExceptionHandler ReOpenFile ReplaceFile ReplaceFileA ReplaceFileW RequestDeviceWakeup RequestWakeupLatency ResetWriteWatch RestoreLastError RtlCaptureContext RtlCaptureStackBackTrace SetCalendarInfoA SetCalendarInfoW SetClientTimeZoneInformation SetComPlusPackageInstallStatus SetComputerNameExA SetComputerNameExW SetConsoleCursor SetConsoleCursorMode SetConsoleDisplayMode SetConsoleFont SetConsoleHardwareState SetConsoleHistoryInfo SetConsoleIcon SetConsoleInputExeNameA SetConsoleInputExeNameW SetConsoleKeyShortcuts SetConsoleLocalEUDC SetConsoleMaximumWindowSize SetConsoleMenuClose SetConsoleNlsMode SetConsoleNumberOfCommandsA SetConsoleNumberOfCommandsW SetConsoleOS2OemFormat SetConsolePalette SetConsoleScreenBufferInfoEx SetCriticalSectionSpinCount SetCurrentConsoleFontEx SetDllDirectoryA SetDllDirectoryW SetDynamicTimeZoneInformation SetEnvironmentStringsA SetEnvironmentStringsW SetEventWhenCallbackReturns SetFileAttributesTransactedA SetFileAttributesTransactedW SetFileBandwidthReservation SetFileCompletionNotificationModes SetFileInformationByHandle SetFileIoOverlappedRange SetFilePointerEx SetFileShortNameA SetFileShortNameW SetFileValidData SetFirmwareEnvironmentVariableA SetFirmwareEnvironmentVariableW SetHandleContext SetInformationJobObject SetLastConsoleEventActive SetLocalPrimaryComputerNameA SetLocalPrimaryComputerNameW SetMessageWaitingIndicator SetNamedPipeAttribute SetProcessAffinityMask SetProcessPriorityBoost SetProcessWorkingSetSizeEx SetStdHandleEx SetSystemFileCacheSize SetTermsrvAppInstallMode SetThreadExecutionState SetThreadIdealProcessor SetThreadpoolThreadMaximum SetThreadpoolThreadMinimum SetThreadpoolTimer SetThreadpoolWait SetThreadPreferredUILanguages SetThreadPriorityBoost SetThreadStackGuarantee SetThreadUILanguage SetTimerQueueTimer SetUserGeoID SetVDMCurrentDirectories SetVolumeMountPointA SetVolumeMountPointW SetWaitableTimer ShowConsoleCursor SignalObjectAndWait SleepConditionVariableCS SleepConditionVariableSRW StartThreadpoolIo SubmitThreadpoolWork SwitchToFiber SwitchToThread TerminateJobObject TermsrvAppInstallMode Thread32First Thread32Next Toolhelp32ReadProcessMemory TryEnterCriticalSection TrySubmitThreadpoolCallback TzSpecificLocalTimeToSystemTime UnregisterApplicationRecoveryCallback UnregisterApplicationRestart UnregisterConsoleIME UnregisterWait UnregisterWaitEx UpdateCalendarDayOfWeek UpdateProcThreadAttribute UTRegister UTUnRegister VDMConsoleOperation VDMOperationStarted VerifyConsoleIoHandle VerifyScripts VerifyVersionInfoA VerifyVersionInfoW VerSetConditionMask VirtualAllocEx VirtualAllocExNuma VirtualFreeEx WaitForThreadpoolIoCallbacks WaitForThreadpoolTimerCallbacks WaitForThreadpoolWaitCallbacks WaitForThreadpoolWorkCallbacks WakeAllConditionVariable WakeConditionVariable WerGetFlags WerpCleanupMessageMapping WerpInitiateRemoteRecovery WerpNotifyLoadStringResource WerpNotifyLoadStringResourceEx WerpNotifyUseStringResource WerpStringLookup WerRegisterFile WerRegisterMemoryBlock WerSetFlags WerUnregisterFile WerUnregisterMemoryBlock Wow64DisableWow64FsRedirection Wow64EnableWow64FsRedirection Wow64GetThreadContext Wow64RevertWow64FsRedirection Wow64SetThreadContext Wow64SuspendThread WriteConsoleInputVDMA WriteConsoleInputVDMW WriteFileGather WTSGetActiveConsoleSessionId ZombifyActCtx

Found follow exports in NTDLL.DL
A_SHAFinal A_SHAInit A_SHAUpdate abs _alldiv _alldvrm _allmul _alloca_probe _alloca_probe_16 _alloca_probe_8 _allrem _allshl _allshr AlpcAdjustCompletionListConcurrencyCount AlpcFreeCompletionListMessage AlpcGetCompletionListLastMessageInformation AlpcGetCompletionListMessageAttributes AlpcGetHeaderSize AlpcGetMessageAttribute AlpcGetMessageFromCompletionList AlpcGetOutstandingCompletionListMessageCount AlpcInitializeMessageAttribute AlpcMaxAllowedMessageLength AlpcRegisterCompletionList AlpcRegisterCompletionListWorkerThread AlpcUnregisterCompletionList AlpcUnregisterCompletionListWorkerThread atan atoi _atoi64 atol _aulldiv _aulldvrm _aullrem _aullshr bsearch ceil _chkstk _CIcos _CIlog _CIpow _CIsin _CIsqrt cos CsrAllocateCaptureBuffer CsrAllocateMessagePointer CsrCaptureMessageBuffer CsrCaptureMessageMultiUnicodeStringsInPlace CsrCaptureMessageString CsrCaptureTimeout CsrClientCallServer CsrClientConnectToServer CsrFreeCaptureBuffer CsrGetProcessId CsrIdentifyAlertableThread CsrNewThread CsrSetPriorityClass CsrVerifyRegion DbgPrintEx DbgPrintReturnControlC DbgQueryDebugFilterState DbgSetDebugFilterState DbgUiConnectToDbg DbgUiContinue DbgUiConvertStateChangeStructure DbgUiDebugActiveProcess DbgUiGetThreadDebugObject DbgUiIssueRemoteBreakin DbgUiRemoteBreakin DbgUiSetThreadDebugObject DbgUiStopDebugging DbgUiWaitStateChange DbgUserBreakPoint EtwCreateTraceInstanceId EtwDeliverDataBlock EtwEnumerateProcessRegGuids EtwEventActivityIdControl EtwEventEnabled EtwEventProviderEnabled EtwEventRegister EtwEventUnregister EtwEventWrite EtwEventWriteEndScenario EtwEventWriteFull EtwEventWriteStartScenario EtwEventWriteString EtwEventWriteTransfer EtwGetTraceEnableFlags EtwGetTraceEnableLevel EtwGetTraceLoggerHandle EtwLogTraceEvent EtwNotificationRegister EtwNotificationUnregister EtwpCreateEtwThread EtwpGetCpuSpeed EtwpNotificationThread EtwProcessPrivateLoggerRequest EtwRegisterSecurityProvider EtwRegisterTraceGuidsA EtwRegisterTraceGuidsW EtwReplyNotification EtwSendNotification EtwSetMark EtwTraceEventInstance EtwTraceMessage EtwTraceMessageVa EtwUnregisterTraceGuids EtwWriteUMSecurityEvent ExpInterlockedPopEntrySListEnd ExpInterlockedPopEntrySListFault ExpInterlockedPopEntrySListResume fabs floor _fltused _ftol _i64toa _i64tow isalnum isalpha __isascii iscntrl __iscsym __iscsymf isdigit isgraph islower isprint ispunct isspace isupper iswalpha iswctype iswdigit iswlower iswspace iswxdigit isxdigit _itoa _itow KiFastSystemCall KiFastSystemCallRet KiIntSystemCall KiRaiseUserExceptionDispatcher KiUserApcDispatcher KiUserCallbackDispatcher KiUserExceptionDispatcher labs LdrAccessResource LdrAddLoadAsDataTable LdrAddRefDll LdrDisableThreadCalloutsForDll LdrEnumerateLoadedModules LdrEnumResources LdrFindEntryForAddress LdrFindResource_U LdrFindResourceDirectory_U LdrFindResourceEx_U LdrFlushAlternateResourceModules LdrGetDllHandle LdrGetDllHandleEx LdrGetFailureData LdrGetFileNameFromLoadAsDataTable LdrGetProcedureAddress LdrGetProcedureAddressEx LdrHotPatchRoutine LdrInitializeThunk LdrInitShimEngineDynamic LdrLoadAlternateResourceModule LdrLoadAlternateResourceModuleEx LdrLoadDll LdrLockLoaderLock LdrOpenImageFileOptionsKey LdrProcessRelocationBlock LdrQueryImageFileExecutionOptions LdrQueryImageFileExecutionOptionsEx LdrQueryImageFileKeyOption LdrQueryModuleServiceTags LdrQueryProcessModuleInformation LdrRegisterDllNotification LdrRemoveLoadAsDataTable LdrResFindResource LdrResFindResourceDirectory LdrResRelease LdrResSearchResource LdrSetAppCompatDllRedirectionCallback LdrSetDllManifestProber LdrSetMUICacheType LdrShutdownProcess LdrShutdownThread LdrUnloadAlternateResourceModule LdrUnloadAlternateResourceModuleEx LdrUnloadDll LdrUnlockLoaderLock LdrUnregisterDllNotification LdrVerifyImageMatchesChecksum LdrVerifyImageMatchesChecksumEx _lfind log _ltoa _ltow mbstowcs MD4Final MD4Init MD4Update MD5Final MD5Init MD5Update _memccpy memchr memcmp memcpy _memicmp memmove memset NlsAnsiCodePage NlsMbCodePageTag NlsMbOemCodePageTag NtAcceptConnectPort NtAccessCheck NtAccessCheckAndAuditAlarm NtAccessCheckByType NtAccessCheckByTypeAndAuditAlarm NtAccessCheckByTypeResultList NtAccessCheckByTypeResultListAndAuditAlarm NtAccessCheckByTypeResultListAndAuditAlarmByHandle NtAcquireCMFViewOwnership NtAddAtom NtAddBootEntry NtAddDriverEntry NtAdjustGroupsToken NtAdjustPrivilegesToken NtAlertResumeThread NtAlertThread NtAllocateLocallyUniqueId NtAllocateUserPhysicalPages NtAllocateUuids NtAllocateVirtualMemory NtAlpcAcceptConnectPort NtAlpcCancelMessage NtAlpcConnectPort NtAlpcCreatePort NtAlpcCreatePortSection NtAlpcCreateResourceReserve NtAlpcCreateSectionView NtAlpcCreateSecurityContext NtAlpcDeletePortSection NtAlpcDeleteResourceReserve NtAlpcDeleteSectionView NtAlpcDeleteSecurityContext NtAlpcDisconnectPort NtAlpcImpersonateClientOfPort NtAlpcOpenSenderProcess NtAlpcOpenSenderThread NtAlpcQueryInformation NtAlpcQueryInformationMessage NtAlpcRevokeSecurityContext NtAlpcSendWaitReceivePort NtAlpcSetInformation NtApphelpCacheControl NtAreMappedFilesTheSame NtAssignProcessToJobObject NtCallbackReturn NtCancelDeviceWakeupRequest NtCancelIoFile NtCancelIoFileEx NtCancelSynchronousIoFile NtCancelTimer NtClearAllSavepointsTransaction NtClearEvent NtClearSavepointTransaction NtClose NtCloseObjectAuditAlarm NtCommitComplete NtCommitEnlistment NtCommitTransaction NtCompactKeys NtCompareTokens NtCompleteConnectPort NtCompressKey NtConnectPort NtContinue NtCreateDebugObject NtCreateDirectoryObject NtCreateEnlistment NtCreateEvent NtCreateEventPair NtCreateFile NtCreateIoCompletion NtCreateJobObject NtCreateJobSet NtCreateKey NtCreateKeyedEvent NtCreateKeyTransacted NtCreateMailslotFile NtCreateMutant NtCreateNamedPipeFile NtCreatePagingFile NtCreatePort NtCreatePrivateNamespace NtCreateProcess NtCreateProcessEx NtCreateProfile NtCreateResourceManager NtCreateSection NtCreateSemaphore NtCreateSymbolicLinkObject NtCreateThread NtCreateThreadEx NtCreateTimer NtCreateToken NtCreateTransaction NtCreateTransactionManager NtCreateUserProcess NtCreateWaitablePort NtCreateWorkerFactory NtDebugActiveProcess NtDebugContinue NtDelayExecution NtDeleteAtom NtDeleteBootEntry NtDeleteDriverEntry NtDeleteFile NtDeleteKey NtDeleteObjectAuditAlarm NtDeletePrivateNamespace NtDeleteValueKey NtDeviceIoControlFile NtDisplayString NtDuplicateObject NtDuplicateToken NtEnumerateBootEntries NtEnumerateDriverEntries NtEnumerateKey NtEnumerateSystemEnvironmentValuesEx NtEnumerateTransactionObject NtEnumerateValueKey NtExtendSection NtFilterToken NtFindAtom NtFlushBuffersFile NtFlushInstallUILanguage NtFlushInstructionCache NtFlushKey NtFlushProcessWriteBuffers NtFlushVirtualMemory NtFlushWriteBuffer NtFreeUserPhysicalPages NtFreeVirtualMemory NtFreezeRegistry NtFreezeTransactions NtFsControlFile NtGetContextThread NtGetCurrentProcessorNumber NtGetDevicePowerState NtGetMUIRegistryInfo NtGetNextProcess NtGetNextThread NtGetNlsSectionPtr NtGetNotificationResourceManager NtGetPlugPlayEvent NtGetTickCount NtGetWriteWatch NtImpersonateAnonymousToken NtImpersonateClientOfPort NtImpersonateThread NtInitializeNlsFiles NtInitializeRegistry NtInitiatePowerAction NtIsProcessInJob NtIsSystemResumeAutomatic NtIsUILanguageComitted NtListenPort NtListTransactions NtLoadDriver NtLoadKey NtLoadKey2 NtLoadKeyEx NtLockFile NtLockProductActivationKeys NtLockRegistryKey NtLockVirtualMemory NtMakePermanentObject NtMakeTemporaryObject NtMapCMFModule NtMapUserPhysicalPages NtMapUserPhysicalPagesScatter NtMapViewOfSection NtMarshallTransaction NtModifyBootEntry NtModifyDriverEntry NtNotifyChangeDirectoryFile NtNotifyChangeKey NtNotifyChangeMultipleKeys NtOpenDirectoryObject NtOpenEnlistment NtOpenEvent NtOpenEventPair NtOpenFile NtOpenIoCompletion NtOpenJobObject NtOpenKey NtOpenKeyedEvent NtOpenKeyTransacted NtOpenMutant NtOpenObjectAuditAlarm NtOpenPrivateNamespace NtOpenProcess NtOpenProcessToken NtOpenProcessTokenEx NtOpenResourceManager NtOpenSection NtOpenSemaphore NtOpenSession NtOpenSymbolicLinkObject NtOpenThread NtOpenThreadToken NtOpenThreadTokenEx NtOpenTimer NtOpenTransaction NtOpenTransactionManager NtPlugPlayControl NtPowerInformation NtPrepareComplete NtPrepareEnlistment NtPrePrepareComplete NtPrePrepareEnlistment NtPrivilegeCheck NtPrivilegedServiceAuditAlarm NtPrivilegeObjectAuditAlarm NtPropagationComplete NtPropagationFailed NtProtectVirtualMemory NtPullTransaction NtPulseEvent NtQueryAttributesFile NtQueryBootEntryOrder NtQueryBootOptions NtQueryDebugFilterState NtQueryDefaultLocale NtQueryDefaultUILanguage NtQueryDirectoryFile NtQueryDirectoryObject NtQueryDriverEntryOrder NtQueryEaFile NtQueryEvent NtQueryFullAttributesFile NtQueryInformationAtom NtQueryInformationEnlistment NtQueryInformationFile NtQueryInformationJobObject NtQueryInformationPort NtQueryInformationProcess NtQueryInformationResourceManager NtQueryInformationThread NtQueryInformationToken NtQueryInformationTransaction NtQueryInformationTransactionManager NtQueryInformationWorkerFactory NtQueryInstallUILanguage NtQueryIntervalProfile NtQueryIoCompletion NtQueryKey NtQueryLicenseValue NtQueryMultipleValueKey NtQueryMutant NtQueryObject NtQueryOpenSubKeys NtQueryOpenSubKeysEx NtQueryPortInformationProcess NtQueryQuotaInformationFile NtQuerySection NtQuerySecurityObject NtQuerySemaphore NtQuerySymbolicLinkObject NtQuerySystemEnvironmentValue NtQuerySystemEnvironmentValueEx NtQuerySystemInformation NtQuerySystemTime NtQueryTimer NtQueryTimerResolution NtQueryValueKey NtQueryVirtualMemory NtQueryVolumeInformationFile NtQueueApcThread NtRaiseException NtRaiseHardError NtReadFile NtReadFileScatter NtReadOnlyEnlistment NtReadRequestData NtReadVirtualMemory NtRecoverEnlistment NtRecoverResourceManager NtRecoverTransactionManager NtRegisterProtocolAddressInformation NtRegisterThreadTerminatePort NtReleaseCMFViewOwnership NtReleaseKeyedEvent NtReleaseMutant NtReleaseSemaphore NtReleaseWorkerFactoryWorker NtRemoveIoCompletion NtRemoveIoCompletionEx NtRemoveProcessDebug NtRenameKey NtReplaceKey NtReplyPort NtReplyWaitReceivePort NtReplyWaitReceivePortEx NtReplyWaitReplyPort NtRequestDeviceWakeup NtRequestPort NtRequestWaitReplyPort NtRequestWakeupLatency NtResetEvent NtResetWriteWatch NtRestoreKey NtResumeProcess NtResumeThread NtRollbackComplete NtRollbackEnlistment NtRollbackSavepointTransaction NtRollbackTransaction NtRollforwardTransactionManager NtSaveKey NtSaveKeyEx NtSaveMergedKeys NtSavepointComplete NtSavepointTransaction NtSecureConnectPort NtSetBootEntryOrder NtSetBootOptions NtSetContextThread NtSetDebugFilterState NtSetDefaultHardErrorPort NtSetDefaultLocale NtSetDefaultUILanguage NtSetDriverEntryOrder NtSetEaFile NtSetEvent NtSetEventBoostPriority NtSetHighEventPair NtSetHighWaitLowEventPair NtSetInformationDebugObject NtSetInformationEnlistment NtSetInformationFile NtSetInformationJobObject NtSetInformationKey NtSetInformationObject NtSetInformationProcess NtSetInformationResourceManager NtSetInformationThread NtSetInformationToken NtSetInformationTransaction NtSetInformationTransactionManager NtSetInformationWorkerFactory NtSetIntervalProfile NtSetIoCompletion NtSetLdtEntries NtSetLowEventPair NtSetLowWaitHighEventPair NtSetQuotaInformationFile NtSetSecurityObject NtSetSystemEnvironmentValue NtSetSystemEnvironmentValueEx NtSetSystemInformation NtSetSystemPowerState NtSetSystemTime NtSetThreadExecutionState NtSetTimer NtSetTimerResolution NtSetUuidSeed NtSetValueKey NtSetVolumeInformationFile NtShutdownSystem NtShutdownWorkerFactory NtSignalAndWaitForSingleObject NtSinglePhaseReject NtStartProfile NtStartTm NtStopProfile NtSuspendProcess NtSuspendThread NtSystemDebugControl NtTerminateJobObject NtTerminateProcess NtTerminateThread NtTestAlert NtThawRegistry NtThawTransactions NtTraceControl NtTraceEvent NtTranslateFilePath NtUnloadDriver NtUnloadKey NtUnloadKey2 NtUnloadKeyEx NtUnlockFile NtUnlockVirtualMemory NtUnmapViewOfSection NtVdmControl NtWaitForDebugEvent NtWaitForKeyedEvent NtWaitForMultipleObjects NtWaitForMultipleObjects32 NtWaitForSingleObject NtWaitForWorkViaWorkerFactory NtWaitHighEventPair NtWaitLowEventPair NtWorkerFactoryWorkerReady NtWriteFile NtWriteFileGather NtWriteRequestData NtWriteVirtualMemory NtYieldExecution PfxFindPrefix PfxInitialize PfxInsertPrefix PfxRemovePrefix pow qsort ResCCloseRuntimeView ResCCompareCacheIDs ResCCreateCultureMap ResCCreateDefaultCultureMap ResCCreateRuntimeView ResCDirectoryCreateAndPopulate ResCDirectoryCreateMapping ResCDirectoryFree ResCDirectoryGetBaseFolder ResCDirectoryGetEntry ResCDirectoryGetEntryCopy ResCDirectoryGetEntryEx ResCDirectoryGetEntryExCopy ResCDirectoryGetEntryIndex ResCDirectoryGetEntryIndexEx ResCDirectoryGetFirstEntry ResCDirectoryGetFirstEntryIndex ResCDirectoryGetSegmentIndex ResCDirectoryGetSegmentName ResCDirectoryLoadFixedSize ResCDirectoryOpenMapping ResCFreeCultureMap ResCGetCacheIndices ResCGetCultureID ResCGetCultureIndex ResCGetCultureName ResCGetHighestCacheIndex ResCGetHighestConsecutiveCacheIndex ResCGetIndexedName ResCGetName ResCGetRegistryBaseFolder ResCGetRegistryConfig _ResCGetRegistryFlags ResCGetRegistryLatestIndex ResCGetRegistryMappingPrefix ResCGetRegistryStatus ResCGetSubIndexedName ResCInitRuntimeView ResCInitRuntimeViewEx ResCKeDirectoryOpenMapping ResCKeGetBaseFolder ResCKeGetCacheIndices ResCKeInitRuntimeViewEx ResCKeSegmentOpenMapping ResCLoadCultureMap _ResCMatchFlags ResCOpenRegistryKey ResCOpenRuntimeView ResCReleaseInitMutex ResCReloadCultureMap ResCRequestInitMutex ResCRuntimeGetAnySegmentData ResCRuntimeGetCultureID ResCRuntimeGetEntryData ResCRuntimeGetEntryDataEx ResCRuntimeGetResourceData ResCRuntimeGetResourceDataEx ResCRuntimeGetResourceDataForCulture ResCRuntimeGetSegmentData ResCRuntimeGetSegmentDataEx ResCRuntimeViewLoadCultureMap ResCSaveRegistryBaseFolder ResCSaveRegistryConfig _ResCSaveRegistryFlags ResCSaveRegistryLatestIndex ResCSaveRegistryStatus ResCSegmentCreateAndPopulate ResCSegmentCreateMapping ResCSegmentFree ResCSegmentGetData ResCSegmentLoadFixedSize ResCSegmentOpenMapping ResCSegmentReserveMapping ResCSetCacheSecurityType RtlAbortRXact RtlAbsoluteToSelfRelativeSD RtlAcquirePebLock RtlAcquirePrivilege RtlAcquireResourceExclusive RtlAcquireResourceShared RtlAcquireSRWLockExclusive RtlAcquireSRWLockShared RtlActivateActivationContext RtlActivateActivationContextEx RtlActivateActivationContextUnsafeFast RtlAddAccessAllowedAce RtlAddAccessAllowedAceEx RtlAddAccessAllowedObjectAce RtlAddAccessDeniedAce RtlAddAccessDeniedAceEx RtlAddAccessDeniedObjectAce RtlAddAce RtlAddActionToRXact RtlAddAtomToAtomTable RtlAddAttributeActionToRXact RtlAddAuditAccessAce RtlAddAuditAccessAceEx RtlAddAuditAccessObjectAce RtlAddCompoundAce RtlAddMandatoryAce RtlAddRefActivationContext RtlAddRefMemoryStream RtlAddressInSectionTable RtlAddSIDToBoundaryDescriptor RtlAddVectoredContinueHandler RtlAddVectoredExceptionHandler RtlAdjustPrivilege RtlAllocateActivationContextStack RtlAllocateAndInitializeSid RtlAllocateHandle RtlAllocateMemoryBlockLookaside RtlAllocateMemoryZone RtlAnsiCharToUnicodeChar RtlAnsiStringToUnicodeSize RtlAppendAsciizToString RtlAppendPathElement RtlAppendStringToString RtlAppendUnicodeStringToString RtlAppendUnicodeToString RtlApplicationVerifierStop RtlApplyRXact RtlApplyRXactNoFlush RtlAreAllAccessesGranted RtlAreAnyAccessesGranted RtlAreBitsClear RtlAreBitsSet RtlAssert RtlBarrier RtlBarrierForDelete RtlCancelTimer RtlCaptureContext RtlCaptureStackBackTrace RtlCaptureStackContext RtlCharToInteger RtlCheckForOrphanedCriticalSections RtlCheckRegistryKey RtlCleanUpTEBLangLists RtlClearAllBits RtlClearBits RtlCloneMemoryStream RtlCloneUserProcess RtlCmDecodeMemIoResource RtlCmEncodeMemIoResource RtlCommitDebugInfo RtlCommitMemoryStream RtlCompactHeap RtlCompareAltitudes RtlCompareMemory RtlCompareMemoryUlong RtlCompareString RtlCompareUnicodeString RtlCompareUnicodeStrings RtlCompressBuffer RtlComputeCrc32 RtlComputeImportTableHash RtlComputePrivatizedDllName_U RtlConnectToSm RtlConsoleMultiByteToUnicodeN RtlConvertExclusiveToShared RtlConvertLCIDToString RtlConvertSharedToExclusive RtlConvertSidToUnicodeString RtlConvertToAutoInheritSecurityObject RtlConvertUiListToApiList RtlCopyLuid RtlCopyLuidAndAttributesArray RtlCopyMappedMemory RtlCopyMemoryStreamTo RtlCopyOutOfProcessMemoryStreamTo RtlCopySecurityDescriptor RtlCopySid RtlCopySidAndAttributesArray RtlCopyString RtlCopyUnicodeString RtlCreateAcl RtlCreateActivationContext RtlCreateAndSetSD RtlCreateAtomTable RtlCreateBootStatusDataFile RtlCreateBoundaryDescriptor RtlCreateEnvironment RtlCreateEnvironmentEx RtlCreateMemoryBlockLookaside RtlCreateMemoryZone RtlCreateProcessParameters RtlCreateProcessParametersEx RtlCreateQueryDebugBuffer RtlCreateRegistryKey RtlCreateSecurityDescriptor RtlCreateServiceSid RtlCreateSystemVolumeInformationFolder RtlCreateTagHeap RtlCreateTimer RtlCreateTimerQueue RtlCreateUnicodeString RtlCreateUnicodeStringFromAsciiz RtlCreateUserProcess RtlCreateUserSecurityObject RtlCreateUserStack RtlCreateUserThread RtlCultureNameToLCID RtlCustomCPToUnicodeN RtlCutoverTimeToSystemTime RtlDeactivateActivationContext RtlDeactivateActivationContextUnsafeFast RtlDebugPrintTimes RtlDecodePointer RtlDecodeSystemPointer RtlDeCommitDebugInfo RtlDecompressBuffer RtlDecompressFragment RtlDefaultNpAcl RtlDelete RtlDeleteAce RtlDeleteAtomFromAtomTable RtlDeleteBarrier RtlDeleteBoundaryDescriptor RtlDeleteCriticalSection RtlDeleteElementGenericTable RtlDeleteElementGenericTableAvl RtlDeleteNoSplay RtlDeleteRegistryValue RtlDeleteResource RtlDeleteSecurityObject RtlDeleteTimer RtlDeleteTimerQueue RtlDeleteTimerQueueEx RtlDeNormalizeProcessParams RtlDeregisterWait RtlDeregisterWaitEx RtlDestroyAtomTable RtlDestroyEnvironment RtlDestroyHandleTable RtlDestroyMemoryBlockLookaside RtlDestroyMemoryZone RtlDestroyProcessParameters RtlDestroyQueryDebugBuffer RtlDetermineDosPathNameType_U RtlDllShutdownInProgress RtlDnsHostNameToComputerName RtlDoesFileExists_U RtlDosApplyFileIsolationRedirection_Ustr RtlDosPathNameToNtPathName_U RtlDosPathNameToNtPathName_U_WithStatus RtlDosPathNameToRelativeNtPathName_U RtlDosPathNameToRelativeNtPathName_U_WithStatus RtlDosSearchPath_U RtlDosSearchPath_Ustr RtlDowncaseUnicodeChar RtlDowncaseUnicodeString RtlDumpResource RtlDuplicateUnicodeString RtlEmptyAtomTable RtlEnableEarlyCriticalSectionEventCreation RtlEncodePointer RtlEncodeSystemPointer RtlEnterCriticalSection RtlEnumerateGenericTable RtlEnumerateGenericTableAvl RtlEnumerateGenericTableLikeADirectory RtlEnumerateGenericTableWithoutSplaying RtlEnumerateGenericTableWithoutSplayingAvl RtlEnumProcessHeaps RtlEqualComputerName RtlEqualDomainName RtlEqualLuid RtlEqualPrefixSid RtlEqualSid RtlEqualString RtlEqualUnicodeString RtlEraseUnicodeString RtlExitUserProcess RtlExitUserThread RtlExpandEnvironmentStrings RtlExpandEnvironmentStrings_U RtlExtendMemoryBlockLookaside RtlExtendMemoryZone RtlFillMemory RtlFillMemoryUlong RtlFinalReleaseOutOfProcessMemoryStream RtlFindAceByType RtlFindActivationContextSectionGuid RtlFindActivationContextSectionString RtlFindCharInUnicodeString RtlFindClearBits RtlFindClearBitsAndSet RtlFindClearRuns RtlFindClosestEncodableLength RtlFindLastBackwardRunClear RtlFindLeastSignificantBit RtlFindLongestRunClear RtlFindMessage RtlFindMostSignificantBit RtlFindNextForwardRunClear RtlFindSetBits RtlFindSetBitsAndClear RtlFirstEntrySList RtlFirstFreeAce RtlFlsAlloc RtlFlsFree RtlFlushSecureMemoryCache RtlFormatCurrentUserKeyPath RtlFormatMessage RtlFormatMessageEx RtlFreeActivationContextStack RtlFreeAnsiString RtlFreeHandle RtlFreeMemoryBlockLookaside RtlFreeOemString RtlFreeSid RtlFreeThreadActivationContextStack RtlFreeUnicodeString RtlFreeUserStack RtlGenerate8dot3Name RtlGetAce RtlGetActiveActivationContext RtlGetCallersAddress RtlGetCompressionWorkSpaceSize RtlGetControlSecurityDescriptor RtlGetCriticalSectionRecursionCount RtlGetCurrentDirectory_U RtlGetCurrentPeb RtlGetCurrentProcessorNumber RtlGetCurrentTransaction RtlGetDaclSecurityDescriptor RtlGetElementGenericTable RtlGetElementGenericTableAvl RtlGetFileMUIPath RtlGetFrame RtlGetFullPathName_U RtlGetFullPathName_UstrEx RtlGetGroupSecurityDescriptor RtlGetIntegerAtom RtlGetLastNtStatus RtlGetLastWin32Error RtlGetLengthWithoutLastFullDosOrNtPathElement RtlGetLengthWithoutTrailingPathSeperators RtlGetLongestNtPathLength RtlGetNativeSystemInformation RtlGetNtGlobalFlags RtlGetNtProductType RtlGetNtVersionNumbers RtlGetOwnerSecurityDescriptor RtlGetParentLocaleName RtlGetProcessHeaps RtlGetProductInfo RtlGetSaclSecurityDescriptor RtlGetSecurityDescriptorRMControl RtlGetSetBootStatusData RtlGetSystemPreferredUILanguages RtlGetThreadErrorMode RtlGetThreadLangIdByIndex RtlGetThreadPreferredUILanguages RtlGetUILanguageInfo RtlGetUnloadEventTrace RtlGetUnloadEventTraceEx RtlGetUserInfoHeap RtlGetUserPreferredUILanguages RtlGetVersion RtlGUIDFromString RtlHashUnicodeString RtlHeapTrkInitialize RtlIdentifierAuthoritySid RtlIdnToAscii RtlIdnToNameprepUnicode RtlIdnToUnicode RtlImageDirectoryEntryToData RtlImageNtHeaderEx RtlImageRvaToSection RtlImageRvaToVa RtlImpersonateSelf RtlImpersonateSelfEx RtlInitAnsiString RtlInitAnsiStringEx RtlInitBarrier RtlInitCodePageTable RtlInitializeAtomPackage RtlInitializeBitMap RtlInitializeConditionVariable RtlInitializeContext RtlInitializeCriticalSection RtlInitializeCriticalSectionAndSpinCount RtlInitializeCriticalSectionEx RtlInitializeGenericTable RtlInitializeGenericTableAvl RtlInitializeHandleTable RtlInitializeNtUserPfn RtlInitializeResource RtlInitializeRXact RtlInitializeSid RtlInitializeSListHead RtlInitializeSRWLock RtlInitMemoryStream RtlInitNlsTables RtlInitOutOfProcessMemoryStream RtlInitString RtlInitUnicodeString RtlInitUnicodeStringEx RtlInsertElementGenericTable RtlInsertElementGenericTableAvl RtlInsertElementGenericTableFull RtlInsertElementGenericTableFullAvl RtlInt64ToUnicodeString RtlIntegerToChar RtlIntegerToUnicodeString RtlInterlockedCompareExchange64 RtlInterlockedFlushSList RtlInterlockedPopEntrySList RtlInterlockedPushEntrySList RtlInterlockedPushListSList RtlIoDecodeMemIoResource RtlIoEncodeMemIoResource RtlIpv4AddressToStringA RtlIpv4AddressToStringExA RtlIpv4AddressToStringExW RtlIpv4AddressToStringW RtlIpv4StringToAddressA RtlIpv4StringToAddressExA RtlIpv4StringToAddressExW RtlIpv4StringToAddressW RtlIpv6AddressToStringA RtlIpv6AddressToStringExA RtlIpv6AddressToStringExW RtlIpv6AddressToStringW RtlIpv6StringToAddressA RtlIpv6StringToAddressExA RtlIpv6StringToAddressExW RtlIpv6StringToAddressW RtlIsActivationContextActive RtlIsCriticalSectionLocked RtlIsCriticalSectionLockedByThread RtlIsCurrentThreadAttachExempt RtlIsDosDeviceName_U RtlIsGenericTableEmpty RtlIsGenericTableEmptyAvl RtlIsNameLegalDOS8Dot3 RtlIsNormalizedString RtlIsTextUnicode RtlIsThreadWithinLoaderCallout RtlIsValidHandle RtlIsValidIndexHandle RtlIsValidLocaleName RtlLargeIntegerToChar RtlLCIDToCultureName RtlLcidToLocaleName RtlLeaveCriticalSection RtlLengthRequiredSid RtlLengthSecurityDescriptor RtlLengthSid RtlLocaleNameToLcid RtlLocalTimeToSystemTime RtlLockBootStatusData RtlLockCurrentThread RtlLockHeap RtlLockMemoryBlockLookaside RtlLockMemoryStreamRegion RtlLockMemoryZone RtlLockModuleSection RtlLogStackBackTrace RtlLookupAtomInAtomTable RtlLookupElementGenericTable RtlLookupElementGenericTableAvl RtlLookupElementGenericTableFull RtlLookupElementGenericTableFullAvl RtlMakeSelfRelativeSD RtlMapGenericMask RtlMapSecurityErrorToNtStatus RtlMoveMemory RtlMultiAppendUnicodeStringBuffer RtlMultiByteToUnicodeSize RtlMultipleAllocateHeap RtlMultipleFreeHeap RtlNewInstanceSecurityObject RtlNewSecurityGrantedAccess RtlNewSecurityObject RtlNewSecurityObjectEx RtlNewSecurityObjectWithMultipleInheritance RtlNormalizeProcessParams RtlNormalizeString RtlNtPathNameToDosPathName RtlNtStatusToDosError RtlNtStatusToDosErrorNoTeb RtlNumberGenericTableElements RtlNumberGenericTableElementsAvl RtlNumberOfClearBits RtlNumberOfSetBits RtlOemStringToUnicodeSize RtlOemStringToUnicodeString RtlOemToUnicodeN RtlOpenCurrentUser RtlOwnerAcesPresent RtlpApplyLengthFunction RtlpCleanupRegistryKeys RtlpConvertCultureNamesToLCIDs RtlpConvertLCIDsToCultureNames RtlpCreateProcessRegistryInfo RtlPcToFileHeader RtlpEnsureBufferSize RtlpGetLCIDFromLangInfoNode RtlpGetNameFromLangInfoNode RtlpGetSystemDefaultUILanguage RtlpGetUserOrMachineUILanguage4NLS RtlPinAtomInAtomTable RtlpInitializeLangRegistryInfo RtlpIsQualifiedLanguage RtlpLoadMachineUIByPolicy RtlpLoadUserUIByPolicy RtlpMuiFreeLangRegistryInfo RtlpMuiRegCreateRegistryInfo RtlpMuiRegFreeRegistryInfo RtlpMuiRegLoadRegistryInfo RtlpNotOwnerCriticalSection RtlpNtCreateKey RtlpNtEnumerateSubKey RtlpNtMakeTemporaryKey RtlpNtOpenKey RtlpNtQueryValueKey RtlpNtSetValueKey RtlPopFrame RtlpQueryDefaultUILanguage RtlPrefixString RtlPrefixUnicodeString RtlpRefreshCachedUILanguage RtlProcessFlsData RtlProtectHeap RtlpSetInstallLanguage RtlpSetPreferredUILanguages RtlpSetUserPreferredUILanguages RtlpUnWaitCriticalSection RtlPushFrame RtlpVerifyAndCommitUILanguageSettings RtlpWaitForCriticalSection RtlQueryActivationContextApplicationSettings RtlQueryAtomInAtomTable RtlQueryCriticalSectionOwner RtlQueryDepthSList RtlQueryDynamicTimeZoneInformation RtlQueryElevationFlags RtlQueryEnvironmentVariable RtlQueryEnvironmentVariable_U RtlQueryHeapInformation RtlQueryInformationAcl RtlQueryInformationActivationContext RtlQueryInformationActiveActivationContext RtlQueryInterfaceMemoryStream RtlQueryModuleInformation RtlQueryProcessBackTraceInformation RtlQueryProcessDebugInformation RtlQueryProcessHeapInformation RtlQueryProcessLockInformation RtlQueryRegistryValues RtlQuerySecurityObject RtlQueryTagHeap RtlQueryTimeZoneInformation RtlQueueApcWow64Thread RtlQueueWorkItem RtlRaiseException RtlRaiseStatus RtlRandom RtlRandomEx RtlReadMemoryStream RtlReadOutOfProcessMemoryStream RtlRealPredecessor RtlRealSuccessor RtlRegisterSecureMemoryCacheCallback RtlRegisterThreadWithCsrss RtlRegisterWait RtlReleaseActivationContext RtlReleaseMemoryStream RtlReleasePebLock RtlReleasePrivilege RtlReleaseRelativeName RtlReleaseResource RtlReleaseSRWLockExclusive RtlReleaseSRWLockShared RtlRemoteCall RtlRemovePrivileges RtlRemoveVectoredContinueHandler RtlRemoveVectoredExceptionHandler RtlReportException RtlResetMemoryBlockLookaside RtlResetMemoryZone RtlResetRtlTranslations RtlRestoreLastWin32Error RtlRetrieveNtUserPfn RtlRevertMemoryStream RtlRunDecodeUnicodeString RtlRunEncodeUnicodeString RtlRunOnceBeginInitialize RtlRunOnceComplete RtlRunOnceExecuteOnce RtlRunOnceInitialize RtlSecondsSince1970ToTime RtlSecondsSince1980ToTime RtlSeekMemoryStream RtlSelfRelativeToAbsoluteSD RtlSelfRelativeToAbsoluteSD2 RtlSendMsgToSm RtlSetAllBits RtlSetAttributesSecurityDescriptor RtlSetBits RtlSetControlSecurityDescriptor RtlSetCriticalSectionSpinCount RtlSetCurrentDirectory_U RtlSetCurrentEnvironment RtlSetCurrentTransaction RtlSetDaclSecurityDescriptor RtlSetDynamicTimeZoneInformation RtlSetEnvironmentStrings RtlSetEnvironmentVar RtlSetEnvironmentVariable RtlSetGroupSecurityDescriptor RtlSetHeapInformation RtlSetInformationAcl RtlSetIoCompletionCallback RtlSetLastWin32Error RtlSetLastWin32ErrorAndNtStatusFromNtStatus RtlSetMemoryStreamSize RtlSetOwnerSecurityDescriptor RtlSetProcessDebugInformation RtlSetProcessIsCritical RtlSetSaclSecurityDescriptor RtlSetSecurityDescriptorRMControl RtlSetSecurityObject RtlSetSecurityObjectEx RtlSetThreadErrorMode RtlSetThreadIsCritical RtlSetThreadPoolStartFunc RtlSetThreadPreferredUILanguages RtlSetTimer RtlSetTimeZoneInformation RtlSetUnhandledExceptionFilter RtlSetUserFlagsHeap RtlSetUserValueHeap RtlSidDominates RtlSidEqualLevel RtlSidHashInitialize RtlSidHashLookup RtlSidIsHigherLevel RtlSleepConditionVariableCS RtlSleepConditionVariableSRW RtlSplay RtlStartRXact RtlStatMemoryStream RtlStringFromGUID RtlSubAuthorityCountSid RtlSubAuthoritySid RtlSubtreePredecessor RtlSubtreeSuccessor RtlSystemTimeToLocalTime RtlTestBit RtlTimeFieldsToTime RtlTimeToElapsedTimeFields RtlTimeToSecondsSince1970 RtlTimeToSecondsSince1980 RtlTimeToTimeFields RtlTraceDatabaseAdd RtlTraceDatabaseCreate RtlTraceDatabaseDestroy RtlTraceDatabaseEnumerate RtlTraceDatabaseFind RtlTraceDatabaseLock RtlTraceDatabaseUnlock RtlTraceDatabaseValidate RtlTryAcquirePebLock RtlTryEnterCriticalSection RtlUlongByteSwap RtlUlonglongByteSwap RtlUnhandledExceptionFilter RtlUnhandledExceptionFilter2 RtlUnicodeStringToAnsiSize RtlUnicodeStringToCountedOemString RtlUnicodeStringToInteger RtlUnicodeStringToOemSize RtlUnicodeStringToOemString RtlUnicodeToCustomCPN RtlUnicodeToMultiByteSize RtlUnicodeToOemN RtlUniform RtlUnlockBootStatusData RtlUnlockCurrentThread RtlUnlockHeap RtlUnlockMemoryBlockLookaside RtlUnlockMemoryStreamRegion RtlUnlockMemoryZone RtlUnlockModuleSection RtlUpcaseUnicodeChar RtlUpcaseUnicodeString RtlUpcaseUnicodeStringToAnsiString RtlUpcaseUnicodeStringToCountedOemString RtlUpcaseUnicodeStringToOemString RtlUpcaseUnicodeToCustomCPN RtlUpcaseUnicodeToMultiByteN RtlUpcaseUnicodeToOemN RtlUpdateClonedCriticalSection RtlUpdateClonedSRWLock RtlUpdateTimer RtlUpperChar RtlUpperString RtlUserThreadStart RtlUshortByteSwap RtlValidAcl RtlValidateProcessHeaps RtlValidateUnicodeString RtlValidRelativeSecurityDescriptor RtlValidSecurityDescriptor RtlValidSid RtlVerifyVersionInfo RtlWakeAllConditionVariable RtlWakeConditionVariable RtlWalkFrameChain RtlWalkHeap RtlWerpReportException RtlWow64CallFunction64 RtlWow64EnableFsRedirection RtlWow64EnableFsRedirectionEx RtlWriteMemoryStream RtlWriteRegistryValue RtlxAnsiStringToUnicodeSize RtlxOemStringToUnicodeSize RtlxUnicodeStringToAnsiSize RtlxUnicodeStringToOemSize RtlZeroHeap RtlZeroMemory RtlZombifyActivationContext ShipAssert ShipAssertGetBufferInfo ShipAssertMsgA ShipAssertMsgW sin _snprintf _snwprintf _splitpath sprintf sqrt sscanf strcat strchr strcmp _strcmpi strcpy strcspn _stricmp strlen _strlwr strncat strncmp strncpy _strnicmp strpbrk strrchr strspn strstr strtol strtoul _strupr _swprintf swprintf tan __toascii tolower toupper towlower towupper TpAllocAlpcCompletion TpAllocCleanupGroup TpAllocIoCompletion TpAllocPool TpAllocTimer TpAllocWait TpAllocWork TpCallbackLeaveCriticalSectionOnCompletion TpCallbackMayRunLong TpCallbackReleaseMutexOnCompletion TpCallbackReleaseSemaphoreOnCompletion TpCallbackSetEventOnCompletion TpCallbackUnloadDllOnCompletion TpCancelAsyncIoOperation TpCaptureCaller TpCheckTerminateWorker TpDbgDumpHeapUsage TpDbgSetLogRoutine TpDisassociateCallback TpIsTimerSet TpPostWork TpReleaseAlpcCompletion TpReleaseCleanupGroup TpReleaseCleanupGroupMembers TpReleaseIoCompletion TpReleasePool TpReleaseTimer TpReleaseWait TpReleaseWork TpSetPoolMaxThreads TpSetPoolMinThreads TpSetTimer TpSetWait TpSimpleTryPost TpStartAsyncIoOperation TpWaitForAlpcCompletion TpWaitForIoCompletion TpWaitForTimer TpWaitForWait TpWaitForWork _ui64toa _ui64tow _ultoa _ultow vDbgPrintEx vDbgPrintExWithPrefix VerSetConditionMask _vscwprintf _vsnprintf _vsnwprintf vsprintf _vswprintf wcscat wcschr wcscmp wcscpy wcscspn _wcsicmp wcslen _wcslwr wcsncat wcsncmp wcsncpy _wcsnicmp wcspbrk wcsrchr wcsspn wcsstr wcstol wcstombs _wcstoui64 wcstoul _wcsupr WerCheckEventEscalation WerReportSQMEvent WerReportWatsonEvent WinSqmAddToStream WinSqmEndSession WinSqmEventEnabled WinSqmEventWrite WinSqmIsOptedIn WinSqmSetString WinSqmStartSession _wtoi _wtoi64 _wtol ZwAcceptConnectPort ZwAccessCheck ZwAccessCheckAndAuditAlarm ZwAccessCheckByType ZwAccessCheckByTypeAndAuditAlarm ZwAccessCheckByTypeResultList ZwAccessCheckByTypeResultListAndAuditAlarm ZwAccessCheckByTypeResultListAndAuditAlarmByHandle ZwAcquireCMFViewOwnership ZwAddAtom ZwAddBootEntry ZwAddDriverEntry ZwAdjustGroupsToken ZwAdjustPrivilegesToken ZwAlertResumeThread ZwAlertThread ZwAllocateLocallyUniqueId ZwAllocateUserPhysicalPages ZwAllocateUuids ZwAllocateVirtualMemory ZwAlpcAcceptConnectPort ZwAlpcCancelMessage ZwAlpcConnectPort ZwAlpcCreatePort ZwAlpcCreatePortSection ZwAlpcCreateResourceReserve ZwAlpcCreateSectionView ZwAlpcCreateSecurityContext ZwAlpcDeletePortSection ZwAlpcDeleteResourceReserve ZwAlpcDeleteSectionView ZwAlpcDeleteSecurityContext ZwAlpcDisconnectPort ZwAlpcImpersonateClientOfPort ZwAlpcOpenSenderProcess ZwAlpcOpenSenderThread ZwAlpcQueryInformation ZwAlpcQueryInformationMessage ZwAlpcRevokeSecurityContext ZwAlpcSendWaitReceivePort ZwAlpcSetInformation ZwApphelpCacheControl ZwAreMappedFilesTheSame ZwAssignProcessToJobObject ZwCallbackReturn ZwCancelDeviceWakeupRequest ZwCancelIoFile ZwCancelIoFileEx ZwCancelSynchronousIoFile ZwCancelTimer ZwClearAllSavepointsTransaction ZwClearEvent ZwClearSavepointTransaction ZwClose ZwCloseObjectAuditAlarm ZwCommitComplete ZwCommitEnlistment ZwCommitTransaction ZwCompactKeys ZwCompareTokens ZwCompleteConnectPort ZwCompressKey ZwConnectPort ZwContinue ZwCreateDebugObject ZwCreateDirectoryObject ZwCreateEnlistment ZwCreateEvent ZwCreateEventPair ZwCreateFile ZwCreateIoCompletion ZwCreateJobObject ZwCreateJobSet ZwCreateKey ZwCreateKeyedEvent ZwCreateKeyTransacted ZwCreateMailslotFile ZwCreateMutant ZwCreateNamedPipeFile ZwCreatePagingFile ZwCreatePort ZwCreatePrivateNamespace ZwCreateProcess ZwCreateProcessEx ZwCreateProfile ZwCreateResourceManager ZwCreateSection ZwCreateSemaphore ZwCreateSymbolicLinkObject ZwCreateThread ZwCreateThreadEx ZwCreateTimer ZwCreateToken ZwCreateTransaction ZwCreateTransactionManager ZwCreateUserProcess ZwCreateWaitablePort ZwCreateWorkerFactory ZwDebugActiveProcess ZwDebugContinue ZwDelayExecution ZwDeleteAtom ZwDeleteBootEntry ZwDeleteDriverEntry ZwDeleteFile ZwDeleteKey ZwDeleteObjectAuditAlarm ZwDeletePrivateNamespace ZwDeleteValueKey ZwDeviceIoControlFile ZwDisplayString ZwDuplicateObject ZwDuplicateToken ZwEnumerateBootEntries ZwEnumerateDriverEntries ZwEnumerateKey ZwEnumerateSystemEnvironmentValuesEx ZwEnumerateTransactionObject ZwEnumerateValueKey ZwExtendSection ZwFilterToken ZwFindAtom ZwFlushBuffersFile ZwFlushInstallUILanguage ZwFlushInstructionCache ZwFlushKey ZwFlushProcessWriteBuffers ZwFlushVirtualMemory ZwFlushWriteBuffer ZwFreeUserPhysicalPages ZwFreeVirtualMemory ZwFreezeRegistry ZwFreezeTransactions ZwFsControlFile ZwGetContextThread ZwGetCurrentProcessorNumber ZwGetDevicePowerState ZwGetMUIRegistryInfo ZwGetNextProcess ZwGetNextThread ZwGetNlsSectionPtr ZwGetNotificationResourceManager ZwGetPlugPlayEvent ZwGetWriteWatch ZwImpersonateAnonymousToken ZwImpersonateClientOfPort ZwImpersonateThread ZwInitializeNlsFiles ZwInitializeRegistry ZwInitiatePowerAction ZwIsProcessInJob ZwIsSystemResumeAutomatic ZwIsUILanguageComitted ZwListenPort ZwListTransactions ZwLoadDriver ZwLoadKey ZwLoadKey2 ZwLoadKeyEx ZwLockFile ZwLockProductActivationKeys ZwLockRegistryKey ZwLockVirtualMemory ZwMakePermanentObject ZwMakeTemporaryObject ZwMapCMFModule ZwMapUserPhysicalPages ZwMapUserPhysicalPagesScatter ZwMapViewOfSection ZwMarshallTransaction ZwModifyBootEntry ZwModifyDriverEntry ZwNotifyChangeDirectoryFile ZwNotifyChangeKey ZwNotifyChangeMultipleKeys ZwOpenDirectoryObject ZwOpenEnlistment ZwOpenEvent ZwOpenEventPair ZwOpenFile ZwOpenIoCompletion ZwOpenJobObject ZwOpenKey ZwOpenKeyedEvent ZwOpenKeyTransacted ZwOpenMutant ZwOpenObjectAuditAlarm ZwOpenPrivateNamespace ZwOpenProcess ZwOpenProcessToken ZwOpenProcessTokenEx ZwOpenResourceManager ZwOpenSection ZwOpenSemaphore ZwOpenSession ZwOpenSymbolicLinkObject ZwOpenThread ZwOpenThreadToken ZwOpenThreadTokenEx ZwOpenTimer ZwOpenTransaction ZwOpenTransactionManager ZwPlugPlayControl ZwPowerInformation ZwPrepareComplete ZwPrepareEnlistment ZwPrePrepareComplete ZwPrePrepareEnlistment ZwPrivilegeCheck ZwPrivilegedServiceAuditAlarm ZwPrivilegeObjectAuditAlarm ZwPropagationComplete ZwPropagationFailed ZwProtectVirtualMemory ZwPullTransaction ZwPulseEvent ZwQueryAttributesFile ZwQueryBootEntryOrder ZwQueryBootOptions ZwQueryDebugFilterState ZwQueryDefaultLocale ZwQueryDefaultUILanguage ZwQueryDirectoryFile ZwQueryDirectoryObject ZwQueryDriverEntryOrder ZwQueryEaFile ZwQueryEvent ZwQueryFullAttributesFile ZwQueryInformationAtom ZwQueryInformationEnlistment ZwQueryInformationFile ZwQueryInformationJobObject ZwQueryInformationPort ZwQueryInformationProcess ZwQueryInformationResourceManager ZwQueryInformationThread ZwQueryInformationToken ZwQueryInformationTransaction ZwQueryInformationTransactionManager ZwQueryInformationWorkerFactory ZwQueryInstallUILanguage ZwQueryIntervalProfile ZwQueryIoCompletion ZwQueryKey ZwQueryLicenseValue ZwQueryMultipleValueKey ZwQueryMutant ZwQueryObject ZwQueryOpenSubKeys ZwQueryOpenSubKeysEx ZwQueryPerformanceCounter ZwQueryPortInformationProcess ZwQueryQuotaInformationFile ZwQuerySection ZwQuerySecurityObject ZwQuerySemaphore ZwQuerySymbolicLinkObject ZwQuerySystemEnvironmentValue ZwQuerySystemEnvironmentValueEx ZwQuerySystemInformation ZwQuerySystemTime ZwQueryTimer ZwQueryTimerResolution ZwQueryValueKey ZwQueryVirtualMemory ZwQueryVolumeInformationFile ZwQueueApcThread ZwRaiseException ZwRaiseHardError ZwReadFile ZwReadFileScatter ZwReadOnlyEnlistment ZwReadRequestData ZwReadVirtualMemory ZwRecoverEnlistment ZwRecoverResourceManager ZwRecoverTransactionManager ZwRegisterProtocolAddressInformation ZwRegisterThreadTerminatePort ZwReleaseCMFViewOwnership ZwReleaseKeyedEvent ZwReleaseMutant ZwReleaseSemaphore ZwReleaseWorkerFactoryWorker ZwRemoveIoCompletion ZwRemoveIoCompletionEx ZwRemoveProcessDebug ZwRenameKey ZwReplaceKey ZwReplyPort ZwReplyWaitReceivePort ZwReplyWaitReceivePortEx ZwReplyWaitReplyPort ZwRequestDeviceWakeup ZwRequestPort ZwRequestWaitReplyPort ZwRequestWakeupLatency ZwResetEvent ZwResetWriteWatch ZwRestoreKey ZwResumeProcess ZwResumeThread ZwRollbackComplete ZwRollbackEnlistment ZwRollbackSavepointTransaction ZwRollbackTransaction ZwRollforwardTransactionManager ZwSaveKey ZwSaveKeyEx ZwSaveMergedKeys ZwSavepointComplete ZwSavepointTransaction ZwSecureConnectPort ZwSetBootEntryOrder ZwSetBootOptions ZwSetContextThread ZwSetDebugFilterState ZwSetDefaultHardErrorPort ZwSetDefaultLocale ZwSetDefaultUILanguage ZwSetDriverEntryOrder ZwSetEaFile ZwSetEvent ZwSetEventBoostPriority ZwSetHighEventPair ZwSetHighWaitLowEventPair ZwSetInformationDebugObject ZwSetInformationEnlistment ZwSetInformationFile ZwSetInformationJobObject ZwSetInformationKey ZwSetInformationObject ZwSetInformationProcess ZwSetInformationResourceManager ZwSetInformationThread ZwSetInformationToken ZwSetInformationTransaction ZwSetInformationTransactionManager ZwSetInformationWorkerFactory ZwSetIntervalProfile ZwSetIoCompletion ZwSetLdtEntries ZwSetLowEventPair ZwSetLowWaitHighEventPair ZwSetQuotaInformationFile ZwSetSecurityObject ZwSetSystemEnvironmentValue ZwSetSystemEnvironmentValueEx ZwSetSystemInformation ZwSetSystemPowerState ZwSetSystemTime ZwSetThreadExecutionState ZwSetTimer ZwSetTimerResolution ZwSetUuidSeed ZwSetValueKey ZwSetVolumeInformationFile ZwShutdownSystem ZwShutdownWorkerFactory ZwSignalAndWaitForSingleObject ZwSinglePhaseReject ZwStartProfile ZwStartTm ZwStopProfile ZwSuspendProcess ZwSuspendThread ZwSystemDebugControl ZwTerminateJobObject ZwTerminateProcess ZwTerminateThread ZwTestAlert ZwThawRegistry ZwThawTransactions ZwTraceControl ZwTraceEvent ZwTranslateFilePath ZwUnloadDriver ZwUnloadKey ZwUnloadKey2 ZwUnloadKeyEx ZwUnlockFile ZwUnlockVirtualMemory ZwUnmapViewOfSection ZwVdmControl ZwWaitForDebugEvent ZwWaitForKeyedEvent ZwWaitForMultipleObjects ZwWaitForMultipleObjects32 ZwWaitForSingleObject ZwWaitForWorkViaWorkerFactory ZwWaitHighEventPair ZwWaitLowEventPair ZwWorkerFactoryWorkerReady ZwWriteFile ZwWriteFileGather ZwWriteRequestData ZwWriteVirtualMemory ZwYieldExecution

Found follow exports in USER32.DL
AddClipboardFormatListener AlignRects AllowForegroundActivation AllowSetForegroundWindow AnimateWindow BlockInput BroadcastSystemMessageA BroadcastSystemMessageExA BroadcastSystemMessageExW BroadcastSystemMessageW BuildReasonArray CalcMenuBar CancelShutdown ChangeDisplaySettingsExA ChangeDisplaySettingsExW ChangeWindowMessageFilter CheckDesktopByThreadId CheckWindowThreadDesktop ClientThreadSetup CliImmSetHotKey CreateDesktopExA CreateDesktopExW CreateDialogIndirectParamAorW CreateSystemThreads CsrBroadcastSystemMessageExW CtxInitUser32 DdeGetQualityOfService DefRawInputProc DeregisterShellHookWindow DestroyReasons DeviceEventWorker DialogBoxIndirectParamAorW DisableProcessWindowsGhosting DisplayExitWindowsWarnings DoSoundConnect DoSoundDisconnect DrawMenuBarTemp DwmGetDxRgn DwmHintDxUpdate DwmStartRedirection DwmStopRedirection EndMenu EnterReaderModeHelper EnumDisplayDevicesA EnumDisplayDevicesW EnumDisplayMonitors EnumDisplaySettingsExA EnumDisplaySettingsExW FlashWindowEx FrostCrashedWindow GetAltTabInfo GetAltTabInfoA GetAltTabInfoW GetAncestor GetAppCompatFlags GetAppCompatFlags2 GetClipboardSequenceNumber GetComboBoxInfo GetCursorFrameInfo GetCursorInfo GetGuiResources GetGUIThreadInfo GetIconInfoExA GetIconInfoExW GetLastInputInfo GetLayeredWindowAttributes GetListBoxInfo GetMenuBarInfo GetMenuInfo GetMonitorInfoA GetMonitorInfoW GetMouseMovePointsEx GetPhysicalCursorPos GetProcessDefaultLayout GetProgmanWindow GetRawInputBuffer GetRawInputData GetRawInputDeviceInfoA GetRawInputDeviceInfoW GetRawInputDeviceList GetReasonTitleFromReasonCode GetRegisteredRawInputDevices GetScrollBarInfo GetSendMessageReceiver GetTaskmanWindow GetTitleBarInfo GetUpdatedClipboardFormats GetWindowInfo GetWindowMinimizeRect GetWindowModuleFileName GetWindowModuleFileNameA GetWindowModuleFileNameW GetWindowRgnBox GetWindowRgnEx GetWinStationInfo GhostWindowFromHungWindow HungWindowFromGhostWindow IMPGetIMEA IMPGetIMEW IMPQueryIMEA IMPQueryIMEW IMPSetIMEA IMPSetIMEW InitializeLpkHooks InSendMessageEx InternalGetWindowIcon IsGUIThread IsHungAppWindow IsProcessDPIAware IsServerSideWindow IsSETEnabled IsThreadDesktopComposited IsWindowInDestroy IsWindowRedirectedForPrint IsWinEventHookInstalled IsWow64Message LoadKeyboardLayoutEx LoadLocalFonts LoadRemoteFonts LockSetForegroundWindow LockWorkStation LogicalToPhysicalPoint MB_GetString MBToWCSEx MenuWindowProcA MenuWindowProcW MessageBoxTimeoutA MessageBoxTimeoutW MonitorFromPoint MonitorFromRect MonitorFromWindow MsgWaitForMultipleObjectsEx NotifyWinEvent OpenThreadDesktop PaintMenuBar PaintMonitor PhysicalToLogicalPoint PrintWindow PrivateExtractIconExA PrivateExtractIconExW PrivateExtractIconsA PrivateExtractIconsW PrivateRegisterICSProc QuerySendMessage RealChildWindowFromPoint RealGetWindowClass RealGetWindowClassA RealGetWindowClassW ReasonCodeNeedsBugID ReasonCodeNeedsComment RecordShutdownReason RegisterDeviceNotificationA RegisterDeviceNotificationW RegisterErrorReportingDialog RegisterFrostWindow RegisterGhostWindow RegisterMessagePumpHook RegisterPowerSettingNotification RegisterRawInputDevices RegisterServicesProcess RegisterSessionPort RegisterShellHookWindow RegisterUserApiHook RemoveClipboardFormatListener ResolveDesktopForWOW ScrollChildren SendIMEMessageExA SendIMEMessageExW SendInput SetConsoleReserveKeys SetCursorContents SetLayeredWindowAttributes SetMenuInfo SetMirrorRendering SetPhysicalCursorPos SetProcessDefaultLayout SetProcessDPIAware SetProgmanWindow SetShellWindowEx SetSystemMenu SetTaskmanWindow SetWindowRgnEx SetWindowStationUser SetWinEventHook ShowStartGlass ShowSystemCursor ShutdownBlockReasonCreate ShutdownBlockReasonDestroy ShutdownBlockReasonQuery SoftModalMessageBox SoundSentry SwitchDesktopWithFade ToUnicodeEx TrackMouseEvent TranslateMessageEx UnhookWinEvent UnregisterDeviceNotification UnregisterMessagePumpHook UnregisterPowerSettingNotification UnregisterSessionPort UnregisterUserApiHook UpdateLayeredWindow UpdateLayeredWindowIndirect UpdatePerUserSystemParameters UpdateWindowTransform User32InitializeImmEntryTable UserHandleGrantAccess UserLpkPSMTextOut UserLpkTabbedTextOut UserRealizePalette UserRegisterWowHandlers _UserTestTokenForInteractive WCSToMBEx Win32PoolAllocationStats WindowFromPhysicalPoint WINNLSEnableIME WINNLSGetEnableStatus WINNLSGetIMEHotkey

Found follow exports in GDI32.DL
AddFontMemResourceEx AddFontResourceExA AddFontResourceExW AddFontResourceTracking AnyLinkedFonts bInitSystemAndFontsDirectoriesW bMakePathNameW BRUSHOBJ_hGetColorTransform BRUSHOBJ_pvAllocRbrush BRUSHOBJ_pvGetRbrush BRUSHOBJ_ulGetBrushColor cGetTTFFromFOT ClearBitmapAttributes ClearBrushAttributes CLIPOBJ_bEnum CLIPOBJ_cEnumStart CLIPOBJ_ppoGetPath ColorCorrectPalette ConfigureOPMProtectedOutput CreateFontIndirectExA CreateFontIndirectExW CreateOPMProtectedOutputs D3DKMTCheckExclusiveOwnership D3DKMTCheckMonitorPowerState D3DKMTCheckOcclusion D3DKMTCloseAdapter D3DKMTCreateAllocation D3DKMTCreateContext D3DKMTCreateDCFromMemory D3DKMTCreateDevice D3DKMTCreateOverlay D3DKMTCreateSynchronizationObject D3DKMTDestroyAllocation D3DKMTDestroyContext D3DKMTDestroyDCFromMemory D3DKMTDestroyDevice D3DKMTDestroyOverlay D3DKMTDestroySynchronizationObject D3DKMTEscape D3DKMTFlipOverlay D3DKMTGetContextSchedulingPriority D3DKMTGetDeviceState D3DKMTGetDisplayModeList D3DKMTGetMultisampleMethodList D3DKMTGetPresentHistory D3DKMTGetProcessSchedulingPriorityClass D3DKMTGetRuntimeData D3DKMTGetScanLine D3DKMTGetSharedPrimaryHandle D3DKMTInvalidateActiveVidPn D3DKMTLock D3DKMTOpenAdapterFromDeviceName D3DKMTOpenAdapterFromGdiDisplayName D3DKMTOpenAdapterFromHdc D3DKMTOpenResource D3DKMTPollDisplayChildren D3DKMTPresent D3DKMTQueryAdapterInfo D3DKMTQueryAllocationResidency D3DKMTQueryResourceInfo D3DKMTQueryStatistics D3DKMTReleaseProcessVidPnSourceOwners D3DKMTRender D3DKMTSetAllocationPriority D3DKMTSetContextSchedulingPriority D3DKMTSetDisplayMode D3DKMTSetDisplayPrivateDriverFormat D3DKMTSetGammaRamp D3DKMTSetProcessSchedulingPriorityClass D3DKMTSetQueuedLimit D3DKMTSetVidPnSourceOwner D3DKMTSharedPrimaryLockNotification D3DKMTSharedPrimaryUnLockNotification D3DKMTSignalSynchronizationObject D3DKMTUnlock D3DKMTUpdateOverlay D3DKMTWaitForIdle D3DKMTWaitForSynchronizationObject D3DKMTWaitForVerticalBlankEvent DDCCIGetCapabilitiesString DDCCIGetCapabilitiesStringLength DDCCIGetTimingReport DDCCIGetVCPFeature DDCCISaveCurrentSettings DDCCISetVCPFeature DdEntry0 DdEntry1 DdEntry10 DdEntry11 DdEntry12 DdEntry13 DdEntry14 DdEntry15 DdEntry16 DdEntry17 DdEntry18 DdEntry19 DdEntry2 DdEntry20 DdEntry21 DdEntry22 DdEntry23 DdEntry24 DdEntry25 DdEntry26 DdEntry27 DdEntry28 DdEntry29 DdEntry3 DdEntry30 DdEntry31 DdEntry32 DdEntry33 DdEntry34 DdEntry35 DdEntry36 DdEntry37 DdEntry38 DdEntry39 DdEntry4 DdEntry40 DdEntry41 DdEntry42 DdEntry43 DdEntry44 DdEntry45 DdEntry46 DdEntry47 DdEntry48 DdEntry49 DdEntry5 DdEntry50 DdEntry51 DdEntry52 DdEntry53 DdEntry54 DdEntry55 DdEntry56 DdEntry6 DdEntry7 DdEntry8 DdEntry9 DestroyOPMProtectedOutput DestroyPhysicalMonitorInternal DwmGetDirtyRgn DwmGetSurfaceData EnableEUDC EndFormPage EngAcquireSemaphore EngAlphaBlend EngAssociateSurface EngBitBlt EngCheckAbort EngComputeGlyphSet EngCopyBits EngCreateBitmap EngCreateClip EngCreateDeviceBitmap EngCreateDeviceSurface EngCreatePalette EngCreateSemaphore EngDeleteClip EngDeletePalette EngDeletePath EngDeleteSemaphore EngDeleteSurface EngEraseSurface EngFillPath EngFindResource EngFreeModule EngGetCurrentCodePage EngGetDriverName EngGetPrinterDataFileName EngGradientFill EngLineTo EngLoadModule EngLockSurface EngMarkBandingSurface EngMultiByteToUnicodeN EngMultiByteToWideChar EngPaint EngPlgBlt EngQueryEMFInfo EngQueryLocalTime EngReleaseSemaphore EngStretchBlt EngStretchBltROP EngStrokeAndFillPath EngStrokePath EngTextOut EngTransparentBlt EngUnicodeToMultiByteN EngUnlockSurface EngWideCharToMultiByte EudcLoadLinkW EudcUnloadLinkW FontIsLinked FONTOBJ_cGetAllGlyphHandles FONTOBJ_cGetGlyphs FONTOBJ_pfdg FONTOBJ_pifi FONTOBJ_pQueryGlyphAttrs FONTOBJ_pvTrueTypeFontFile FONTOBJ_pxoGetXform FONTOBJ_vGetInfo GdiAddFontResourceW GdiAddGlsBounds GdiAddGlsRecord GdiAlphaBlend GdiArtificialDecrementDriver GdiCleanCacheDC GdiConsoleTextOut GdiConvertAndCheckDC GdiConvertBitmap GdiConvertBitmapV5 GdiConvertBrush GdiConvertDC GdiConvertEnhMetaFile GdiConvertFont GdiConvertMetaFilePict GdiConvertPalette GdiConvertRegion GdiConvertToDevmodeW GdiCreateLocalEnhMetaFile GdiCreateLocalMetaFilePict GdiDeleteLocalDC GdiDeleteSpoolFileHandle GdiDescribePixelFormat GdiDllInitialize GdiDrawStream GdiEndDocEMF GdiEndPageEMF GdiEntry1 GdiEntry10 GdiEntry11 GdiEntry12 GdiEntry13 GdiEntry14 GdiEntry15 GdiEntry16 GdiEntry2 GdiEntry3 GdiEntry4 GdiEntry5 GdiEntry6 GdiEntry7 GdiEntry8 GdiEntry9 GdiFixUpHandle GdiFullscreenControl GdiGetBitmapBitsSize GdiGetCharDimensions GdiGetCodePage GdiGetDC GdiGetDevmodeForPage GdiGetLocalBrush GdiGetLocalDC GdiGetLocalFont GdiGetPageCount GdiGetPageHandle GdiGetSpoolFileHandle GdiGetSpoolMessage GdiGradientFill GdiInitializeLanguagePack GdiInitSpool GdiIsMetaFileDC GdiIsMetaPrintDC GdiIsPlayMetafileDC GdiIsScreenDC GdiPlayEMF GdiPlayPageEMF GdiPlayPrivatePageEMF GdiPrinterThunk GdiProcessSetup GdiQueryFonts GdiQueryTable GdiRealizationInfo GdiReleaseDC GdiReleaseLocalDC GdiResetDCEMF GdiSetAttrs GdiSetLastError GdiSetPixelFormat GdiSetServerAttr GdiStartDocEMF GdiStartPageEMF GdiSwapBuffers GdiTransparentBlt GdiValidateHandle GetBitmapAttributes GetBrushAttributes GetCertificate GetCertificateSize GetCharABCWidthsI GetCharWidthI GetCharWidthInfo GetCOPPCompatibleOPMInformation GetDCBrushColor GetDCPenColor GetEnhMetaFilePixelFormat GetETM GetEUDCTimeStamp GetEUDCTimeStampExW GetFontAssocStatus GetFontResourceInfoW GetFontUnicodeRanges GetGlyphIndicesA GetGlyphIndicesW GetGlyphOutlineWow GetHFONT GetLayout GetNumberOfPhysicalMonitors GetOPMInformation GetOPMRandomNumber GetPhysicalMonitorDescription GetPhysicalMonitors GetRelAbs GetStringBitmapA GetStringBitmapW GetSuggestedOPMProtectedOutputArraySize GetTextExtentExPointI GetTextExtentExPointWPri GetTextExtentPointI GetTextFaceAliasW GetTransform HT_Get8BPPFormatPalette HT_Get8BPPMaskPalette IsValidEnhMetaRecord IsValidEnhMetaRecordOffExt MirrorRgn NamedEscape PATHOBJ_bEnum PATHOBJ_bEnumClipLines PATHOBJ_vEnumStart PATHOBJ_vEnumStartClipLines PATHOBJ_vGetBounds PolyPatBlt QueryFontAssocStatus RemoveFontMemResourceEx RemoveFontResourceExA RemoveFontResourceExW RemoveFontResourceTracking SelectBrushLocal SelectFontLocal SetBitmapAttributes SetBrushAttributes SetDCBrushColor SetDCPenColor SetLayout SetLayoutWidth SetMagicColors SetOPMSigningKeyAndSequenceNumbers SetRelAbs SetVirtualResolution StartFormPage STROBJ_bEnum STROBJ_bEnumPositionsOnly STROBJ_bGetAdvanceWidths STROBJ_dwGetCodePage STROBJ_vEnumStart UnloadNetworkFonts XFORMOBJ_bApplyXform XFORMOBJ_iGetXform XLATEOBJ_cGetPalette XLATEOBJ_hGetColorTransform XLATEOBJ_iXlate XLATEOBJ_piVector

Found follow exports in SHELL32.DL
AppCompat_RunDLLW AssocCreateForClasses AssocGetDetailsOfPropKey CDefFolderMenu_Create CDefFolderMenu_Create2 CIDLData_CreateFromIDArray Control_RunDLLA Control_RunDLLAsUserW Control_RunDLLW DAD_AutoScroll DAD_DragEnterEx DAD_DragEnterEx2 DAD_DragLeave DAD_DragMove DAD_SetDragImage DAD_ShowDragImage DllCanUnloadNow DllGetVersion DllInstall DllRegisterServer DllUnregisterServer DriveType ExtractIconExW GetFileNameFromBrowse ILAppendID ILClone ILCloneFirst ILCombine ILCreateFromPath ILCreateFromPathA ILCreateFromPathW ILFindChild ILFindLastID ILFree ILGetNext ILGetSize ILIsEqual ILIsParent ILLoadFromStreamEx ILRemoveLastID ILSaveToStream InitNetworkAddressControl IsLFNDrive IsLFNDriveA IsLFNDriveW IsNetDrive IsUserAnAdmin OpenAs_RunDLLA OpenAs_RunDLLW OpenRegStream Options_RunDLL Options_RunDLLA Options_RunDLLW PathCleanupSpec PathGetShortPath PathIsExe PathIsSlowA PathIsSlowW PathMakeUniqueName PathQualify PathResolve PathYetAnotherMakeUniqueName PickIconDlg PifMgr_CloseProperties PifMgr_GetProperties PifMgr_OpenProperties PifMgr_SetProperties PrepareDiscForBurnRunDllW PrintersGetCommand_RunDLLA PrintersGetCommand_RunDLLW ReadCabinetState RealDriveType RestartDialog RestartDialogEx SHAddDefaultPropertiesByExt SHAddFromPropSheetExtArray SHAlloc SHAssocEnumHandlers SHBindToFolderIDListParent SHBindToFolderIDListParentEx SHBindToObject SHBindToParent SHBrowseForFolderW SHChangeNotification_Lock SHChangeNotification_Unlock SHChangeNotifyDeregister SHChangeNotifyRegister SHChangeNotifyRegisterThread SHChangeNotifySuspendResume SHCloneSpecialIDList SHCLSIDFromString SHCoCreateInstance SHCreateAssociationRegistration SHCreateDataObject SHCreateDefaultContextMenu SHCreateDefaultExtractIcon SHCreateDefaultPropertiesOp SHCreateDirectory SHCreateDirectoryExA SHCreateDirectoryExW SHCreateFileExtractIconW SHCreateItemFromIDList SHCreateItemFromParsingName SHCreateItemFromRelativeName SHCreateItemInKnownFolder SHCreateItemWithParent SHCreateLocalServerRunDll SHCreateProcessAsUserW SHCreatePropSheetExtArray SHCreateQueryCancelAutoPlayMoniker SHCreateShellFolderView SHCreateShellFolderViewEx SHCreateShellItem SHCreateShellItemArray SHCreateShellItemArrayFromDataObject SHCreateShellItemArrayFromIDLists SHCreateShellItemArrayFromShellItem SHCreateStdEnumFmtEtc SHDefExtractIconA SHDefExtractIconW SHDestroyPropSheetExtArray SHDoDragDrop Shell_GetCachedImageIndex Shell_GetCachedImageIndexA Shell_GetCachedImageIndexW Shell_GetImageLists Shell_MergeMenus Shell_NotifyIconW ShellExec_RunDLL ShellExec_RunDLLA ShellExec_RunDLLW ShellExecuteExW ShellHookProc ShellMessageBoxA ShellMessageBoxW SHEmptyRecycleBinA SHEmptyRecycleBinW SHEnableServiceObject SHEnumerateUnreadMailAccountsW SHEvaluateSystemCommandTemplate SHExtractIconsW SHFileOperationW SHFind_InitMenuPopup SHFindFiles SHFlushSFCache SHFree SHGetAttributesFromDataObject SHGetDataFromIDListW SHGetDiskFreeSpaceA SHGetDiskFreeSpaceExA SHGetDiskFreeSpaceExW SHGetDriveMedia SHGetFileInfoW SHGetFolderLocation SHGetFolderPathA SHGetFolderPathAndSubDirA SHGetFolderPathAndSubDirW SHGetFolderPathEx SHGetFolderPathW SHGetIconOverlayIndexA SHGetIconOverlayIndexW SHGetIDListFromObject SHGetImageList SHGetKnownFolderIDList SHGetKnownFolderPath SHGetLocalizedName SHGetNameFromIDList SHGetNewLinkInfo SHGetNewLinkInfoA SHGetNewLinkInfoW SHGetPathFromIDListEx SHGetPathFromIDListW SHGetPropertyStoreFromIDList SHGetPropertyStoreFromParsingName SHGetRealIDL SHGetSetFolderCustomSettings SHGetSetSettings SHGetSettings SHGetSpecialFolderPathA SHGetSpecialFolderPathW SHGetStockIconInfo SHGetTemporaryPropertyForItem SHGetUnreadMailCountW SHHandleUpdateImage SHHelpShortcuts_RunDLLA SHHelpShortcuts_RunDLLW SHILCreateFromPath SHInvokePrinterCommandA SHInvokePrinterCommandW SHIsFileAvailableOffline SHLimitInputEdit SHLoadNonloadedIconOverlayIdentifiers SHMapPIDLToSystemImageListIndex SHMultiFileProperties SHObjectProperties SHOpenFolderAndSelectItems SHOpenPropSheetW SHOpenWithDialog SHParseDisplayName SHPathPrepareForWriteA SHPathPrepareForWriteW SHPropStgCreate SHPropStgReadMultiple SHPropStgWriteMultiple SHQueryRecycleBinA SHQueryRecycleBinW SHQueryUserNotificationState SHRemoveLocalizedName SHReplaceFromPropSheetExtArray SHRestricted SHSetDefaultProperties SHSetFolderPathA SHSetFolderPathW SHSetInstanceExplorer SHSetKnownFolderPath SHSetLocalizedName SHSetTemporaryPropertyForItem SHSetUnreadMailCountW SHShellFolderView_Message SHSimpleIDListFromPath SHStartNetConnectionDialogW SHTestTokenMembership SHUpdateImageA SHUpdateImageW SHUpdateRecycleBinIcon SHValidateUNC SignalFileOpen StrChrA StrChrIA StrChrIW StrChrW StrCmpNA StrCmpNIA StrCmpNIW StrCmpNW StrNCmpA StrNCmpIA StrNCmpIW StrNCmpW StrRChrA StrRChrIA StrRChrIW StrRChrW StrRStrA StrRStrIA StrRStrIW StrRStrW StrStrA StrStrIA StrStrIW StrStrW WaitForExplorerRestartW Win32DeleteFile WOWShellExecute WriteCabinetState

Found follow exports in COMDLG32.DL
DllCanUnloadNow DllGetClassObject dwLBSubclass dwOKSubclass LoadAlterBitmap PrintDlgExA PrintDlgExW Ssync_ANSI_UNICODE_Struct_For_WOW WantArrows

Found follow exports in COMCTL32.DL
AddMRUStringW CreateMRUListW DefSubclassProc DPA_Clone DPA_Create DPA_CreateEx DPA_DeleteAllPtrs DPA_DeletePtr DPA_Destroy DPA_DestroyCallback DPA_EnumCallback DPA_GetPtr DPA_GetPtrIndex DPA_Grow DPA_InsertPtr DPA_LoadStream DPA_Merge DPA_SaveStream DPA_Search DPA_SetPtr DPA_Sort DSA_Create DSA_DeleteAllItems DSA_DeleteItem DSA_Destroy DSA_DestroyCallback DSA_EnumCallback DSA_GetItem DSA_GetItemPtr DSA_InsertItem DSA_SetItem EnumMRUListW FreeMRUList ImageList_GetFlags RegisterClassNameW RemoveWindowSubclass SetWindowSubclass Str_SetPtrW

Found follow exports in ADVAPI32.DL
A_SHAFinal A_SHAInit A_SHAUpdate AccessCheckByType AccessCheckByTypeAndAuditAlarmA AccessCheckByTypeAndAuditAlarmW AccessCheckByTypeResultList AccessCheckByTypeResultListAndAuditAlarmA AccessCheckByTypeResultListAndAuditAlarmByHandleA AccessCheckByTypeResultListAndAuditAlarmByHandleW AccessCheckByTypeResultListAndAuditAlarmW AddAccessAllowedAceEx AddAccessAllowedObjectAce AddAccessDeniedAceEx AddAccessDeniedObjectAce AddAuditAccessAceEx AddAuditAccessObjectAce AddMandatoryAce AddUsersToEncryptedFile AddUsersToEncryptedFileEx AuditComputeEffectivePolicyBySid AuditComputeEffectivePolicyByToken AuditEnumerateCategories AuditEnumeratePerUserPolicy AuditEnumerateSubCategories AuditFree AuditLookupCategoryGuidFromCategoryId AuditLookupCategoryIdFromCategoryGuid AuditLookupCategoryNameA AuditLookupCategoryNameW AuditLookupSubCategoryNameA AuditLookupSubCategoryNameW AuditQueryPerUserPolicy AuditQuerySecurity AuditQuerySystemPolicy AuditSetPerUserPolicy AuditSetSecurity AuditSetSystemPolicy BuildExplicitAccessWithNameA BuildExplicitAccessWithNameW BuildImpersonateExplicitAccessWithNameA BuildImpersonateExplicitAccessWithNameW BuildImpersonateTrusteeA BuildImpersonateTrusteeW BuildSecurityDescriptorA BuildSecurityDescriptorW BuildTrusteeWithNameA BuildTrusteeWithNameW BuildTrusteeWithObjectsAndNameA BuildTrusteeWithObjectsAndNameW BuildTrusteeWithObjectsAndSidA BuildTrusteeWithObjectsAndSidW BuildTrusteeWithSidA BuildTrusteeWithSidW CancelOverlappedAccess ChangeServiceConfig2A ChangeServiceConfig2W CheckAppInitBlockedServiceIdentity CheckTokenMembership CloseCodeAuthzLevel CloseEncryptedFileRaw CloseThreadWaitChainSession CloseTrace CommandLineFromMsiDescriptor ComputeAccessTokenFromCodeAuthzLevel ControlServiceExA ControlServiceExW ControlTraceA ControlTraceW ConvertAccessToSecurityDescriptorA ConvertAccessToSecurityDescriptorW ConvertSDToStringSDRootDomainA ConvertSDToStringSDRootDomainW ConvertSecurityDescriptorToAccessA ConvertSecurityDescriptorToAccessNamedA ConvertSecurityDescriptorToAccessNamedW ConvertSecurityDescriptorToAccessW ConvertSecurityDescriptorToStringSecurityDescriptorA ConvertSecurityDescriptorToStringSecurityDescriptorW ConvertSidToStringSidA ConvertSidToStringSidW ConvertStringSDToSDDomainA ConvertStringSDToSDDomainW ConvertStringSDToSDRootDomainA ConvertStringSDToSDRootDomainW ConvertStringSecurityDescriptorToSecurityDescriptorA ConvertStringSecurityDescriptorToSecurityDescriptorW ConvertStringSidToSidA ConvertStringSidToSidW ConvertToAutoInheritPrivateObjectSecurity CreateCodeAuthzLevel CreatePrivateObjectSecurityEx CreatePrivateObjectSecurityWithMultipleInheritance CreateProcessWithLogonW CreateProcessWithTokenW CreateRestrictedToken CreateTraceInstanceId CreateWellKnownSid CredBackupCredentials CredDeleteA CredDeleteW CredEncryptAndMarshalBinaryBlob CredEnumerateA CredEnumerateW CredFindBestCredentialA CredFindBestCredentialW CredFree CredGetSessionTypes CredGetTargetInfoA CredGetTargetInfoW CredIsMarshaledCredentialA CredIsMarshaledCredentialW CredIsProtectedA CredIsProtectedW CredMarshalCredentialA CredMarshalCredentialW CredpConvertCredential CredpConvertOneCredentialSize CredpConvertTargetInfo CredpDecodeCredential CredpEncodeCredential CredpEncodeSecret CredProfileLoaded CredProfileUnloaded CredProtectA CredProtectW CredReadA CredReadByTokenHandle CredReadDomainCredentialsA CredReadDomainCredentialsW CredReadW CredRenameA CredRenameW CredRestoreCredentials CredUnmarshalCredentialA CredUnmarshalCredentialW CredUnprotectA CredUnprotectW CredWriteA CredWriteDomainCredentialsA CredWriteDomainCredentialsW CredWriteW CryptAcquireContextW CryptContextAddRef CryptDuplicateHash CryptDuplicateKey CryptEnumProvidersA CryptEnumProvidersW CryptEnumProviderTypesA CryptEnumProviderTypesW CryptGetDefaultProviderA CryptGetDefaultProviderW CryptSetProviderExA CryptSetProviderExW CryptSetProviderW CryptSignHashW CryptVerifySignatureW DecryptFileA DecryptFileW DuplicateEncryptionInfoFile DuplicateTokenEx ElfBackupEventLogFileA ElfBackupEventLogFileW ElfChangeNotify ElfClearEventLogFileA ElfClearEventLogFileW ElfCloseEventLog ElfDeregisterEventSource ElfFlushEventLog ElfNumberOfRecords ElfOldestRecord ElfOpenBackupEventLogA ElfOpenBackupEventLogW ElfOpenEventLogA ElfOpenEventLogW ElfReadEventLogA ElfReadEventLogW ElfRegisterEventSourceA ElfRegisterEventSourceW ElfReportEventA ElfReportEventAndSourceW ElfReportEventW EnableTrace EnableTraceEx EncryptedFileKeyInfo EncryptFileA EncryptFileW EncryptionDisable EnumerateTraceGuids EnumerateTraceGuidsEx EnumServiceGroupW EnumServicesStatusExA EnumServicesStatusExW EqualDomainSid EventAccessControl EventAccessQuery EventAccessRemove EventActivityIdControl EventEnabled EventProviderEnabled EventRegister EventUnregister EventWrite EventWriteEndScenario EventWriteStartScenario EventWriteString EventWriteTransfer FileEncryptionStatusA FileEncryptionStatusW FlushEfsCache FlushTraceA FlushTraceW FreeEncryptedFileKeyInfo FreeEncryptedFileMetadata FreeEncryptionCertificateHashList FreeInheritedFromArray GetAccessPermissionsForObjectA GetAccessPermissionsForObjectW GetAuditedPermissionsFromAclA GetAuditedPermissionsFromAclW GetCurrentHwProfileA GetCurrentHwProfileW GetEffectiveRightsFromAclA GetEffectiveRightsFromAclW GetEncryptedFileMetadata GetEventLogInformation GetExplicitEntriesFromAclA GetExplicitEntriesFromAclW GetInformationCodeAuthzLevelW GetInformationCodeAuthzPolicyW GetInheritanceSourceA GetInheritanceSourceW GetLocalManagedApplicationData GetLocalManagedApplications GetManagedApplicationCategories GetManagedApplications GetMultipleTrusteeA GetMultipleTrusteeOperationA GetMultipleTrusteeOperationW GetMultipleTrusteeW GetNamedSecurityInfoA GetNamedSecurityInfoExA GetNamedSecurityInfoExW GetNamedSecurityInfoW GetOverlappedAccessResults GetSecurityDescriptorRMControl GetSecurityInfo GetSecurityInfoExA GetSecurityInfoExW GetThreadWaitChain GetTraceEnableFlags GetTraceEnableLevel GetTraceLoggerHandle GetTrusteeFormA GetTrusteeFormW GetTrusteeNameA GetTrusteeNameW GetTrusteeTypeA GetTrusteeTypeW GetWindowsAccountDomainSid I_QueryTagInformation I_ScGetCurrentGroupStateW I_ScIsSecurityProcess I_ScPnPGetServiceName I_ScQueryServiceConfig I_ScSendPnPMessage I_ScSendTSMessage I_ScSetServiceBitsA I_ScSetServiceBitsW I_ScValidatePnPService IdentifyCodeAuthzLevelW ImpersonateAnonymousToken InitiateShutdownA InitiateShutdownW InitiateSystemShutdownExA InitiateSystemShutdownExW InstallApplication IsTokenRestricted IsTokenUntrusted IsValidRelativeSecurityDescriptor IsWellKnownSid LogonUserExA LogonUserExExW LogonUserExW LookupSecurityDescriptorPartsA LookupSecurityDescriptorPartsW LsaAddAccountRights LsaAddPrivilegesToAccount LsaClearAuditLog LsaClose LsaCreateAccount LsaCreateSecret LsaCreateTrustedDomain LsaCreateTrustedDomainEx LsaDelete LsaDeleteTrustedDomain LsaEnumerateAccountRights LsaEnumerateAccounts LsaEnumerateAccountsWithUserRight LsaEnumeratePrivileges LsaEnumeratePrivilegesOfAccount LsaEnumerateTrustedDomains LsaEnumerateTrustedDomainsEx LsaFreeMemory LsaGetQuotasForAccount LsaGetRemoteUserName LsaGetSystemAccessAccount LsaGetUserName LsaICLookupNames LsaICLookupNamesWithCreds LsaICLookupSids LsaICLookupSidsWithCreds LsaLookupNames LsaLookupNames2 LsaLookupPrivilegeDisplayName LsaLookupPrivilegeName LsaLookupPrivilegeValue LsaLookupSids LsaManageSidNameMapping LsaNtStatusToWinError LsaOpenAccount LsaOpenPolicy LsaOpenPolicySce LsaOpenSecret LsaOpenTrustedDomain LsaOpenTrustedDomainByName LsaQueryDomainInformationPolicy LsaQueryForestTrustInformation LsaQueryInformationPolicy LsaQueryInfoTrustedDomain LsaQuerySecret LsaQuerySecurityObject LsaQueryTrustedDomainInfo LsaQueryTrustedDomainInfoByName LsaRemoveAccountRights LsaRemovePrivilegesFromAccount LsaRetrievePrivateData LsaSetDomainInformationPolicy LsaSetForestTrustInformation LsaSetInformationPolicy LsaSetInformationTrustedDomain LsaSetQuotasForAccount LsaSetSecret LsaSetSecurityObject LsaSetSystemAccessAccount LsaSetTrustedDomainInfoByName LsaSetTrustedDomainInformation LsaStorePrivateData MakeAbsoluteSD2 MD4Final MD4Init MD4Update MD5Final MD5Init MD5Update MSChapSrvChangePassword MSChapSrvChangePassword2 NotifyServiceStatusChange NotifyServiceStatusChangeA NotifyServiceStatusChangeW ObjectDeleteAuditAlarmA ObjectDeleteAuditAlarmW OpenEncryptedFileRawA OpenEncryptedFileRawW OpenThreadWaitChainSession OpenTraceA OpenTraceW PerfAddCounters PerfCloseQueryHandle PerfCreateInstance PerfDecrementULongCounterValue PerfDecrementULongLongCounterValue PerfDeleteCounters PerfDeleteInstance PerfEnumerateCounterSet PerfEnumerateCounterSetInstances PerfIncrementULongCounterValue PerfIncrementULongLongCounterValue PerfOpenQueryHandle PerfQueryCounterData PerfQueryCounterInfo PerfQueryCounterSetRegistrationInfo PerfQueryInstance PerfSetCounterRefValue PerfSetCounterSetInfo PerfSetULongCounterValue PerfSetULongLongCounterValue PerfStartProvider PerfStartProviderEx PerfStopProvider ProcessIdleTasks ProcessIdleTasksW ProcessTrace QueryAllTracesA QueryAllTracesW QueryRecoveryAgentsOnEncryptedFile QuerySecurityAccessMask QueryServiceConfig2A QueryServiceConfig2W QueryServiceStatusEx QueryTraceA QueryTraceW QueryUsersOnEncryptedFile ReadEncryptedFileRaw RegConnectRegistryExA RegConnectRegistryExW RegCopyTreeA RegCopyTreeW RegCreateKeyTransactedA RegCreateKeyTransactedW RegDeleteKeyExA RegDeleteKeyExW RegDeleteKeyTransactedA RegDeleteKeyTransactedW RegDeleteKeyValueA RegDeleteKeyValueW RegDeleteTreeA RegDeleteTreeW RegDisablePredefinedCache RegDisablePredefinedCacheEx RegDisableReflectionKey RegEnableReflectionKey RegGetValueA RegGetValueW RegisterIdleTask RegisterServiceCtrlHandlerExA RegisterServiceCtrlHandlerExW RegisterTraceGuidsA RegisterTraceGuidsW RegisterWaitChainCOMCallback RegLoadAppKeyA RegLoadAppKeyW RegLoadMUIStringA RegLoadMUIStringW RegOpenCurrentUser RegOpenKeyTransactedA RegOpenKeyTransactedW RegOpenUserClassesRoot RegOverridePredefKey RegQueryReflectionKey RegRenameKey RegSaveKeyExA RegSaveKeyExW RegSetKeyValueA RegSetKeyValueW RemoveTraceCallback RemoveUsersFromEncryptedFile SaferCloseLevel SaferComputeTokenFromLevel SaferCreateLevel SaferGetLevelInformation SaferGetPolicyInformation SaferiChangeRegistryScope SaferiCompareTokenLevels SaferIdentifyLevel SaferiIsExecutableFileType SaferiPopulateDefaultsInRegistry SaferiRecordEventLogEntry SaferiReplaceProcessThreadTokens SaferiSearchMatchingHashRules SaferRecordEventLogEntry SaferSetLevelInformation SaferSetPolicyInformation SetEncryptedFileMetadata SetEntriesInAccessListA SetEntriesInAccessListW SetEntriesInAclA SetEntriesInAclW SetEntriesInAuditListA SetEntriesInAuditListW SetInformationCodeAuthzLevelW SetInformationCodeAuthzPolicyW SetNamedSecurityInfoA SetNamedSecurityInfoExA SetNamedSecurityInfoExW SetNamedSecurityInfoW SetPrivateObjectSecurityEx SetSecurityAccessMask SetSecurityDescriptorControl SetSecurityDescriptorRMControl SetSecurityInfo SetSecurityInfoExA SetSecurityInfoExW SetTraceCallback SetUserFileEncryptionKey SetUserFileEncryptionKeyEx StartTraceA StartTraceW StopTraceA StopTraceW SystemFunction001 SystemFunction002 SystemFunction003 SystemFunction004 SystemFunction005 SystemFunction006 SystemFunction007 SystemFunction008 SystemFunction009 SystemFunction010 SystemFunction011 SystemFunction012 SystemFunction013 SystemFunction014 SystemFunction015 SystemFunction016 SystemFunction017 SystemFunction018 SystemFunction019 SystemFunction020 SystemFunction021 SystemFunction022 SystemFunction023 SystemFunction024 SystemFunction025 SystemFunction026 SystemFunction027 SystemFunction028 SystemFunction029 SystemFunction030 SystemFunction031 SystemFunction032 SystemFunction033 SystemFunction034 SystemFunction035 SystemFunction036 SystemFunction040 SystemFunction041 TraceEvent TraceEventInstance TraceMessage TraceMessageVa TreeResetNamedSecurityInfoA TreeResetNamedSecurityInfoW TreeSetNamedSecurityInfoA TreeSetNamedSecurityInfoW TrusteeAccessToObjectA TrusteeAccessToObjectW UninstallApplication UnregisterIdleTask UnregisterTraceGuids UpdateTraceA UpdateTraceW UsePinForEncryptedFilesA UsePinForEncryptedFilesW WmiCloseBlock WmiDevInstToInstanceNameA WmiDevInstToInstanceNameW WmiEnumerateGuids WmiExecuteMethodA WmiExecuteMethodW WmiFileHandleToInstanceNameA WmiFileHandleToInstanceNameW WmiFreeBuffer WmiMofEnumerateResourcesA WmiMofEnumerateResourcesW WmiNotificationRegistrationA WmiNotificationRegistrationW WmiOpenBlock WmiQueryAllDataA WmiQueryAllDataMultipleA WmiQueryAllDataMultipleW WmiQueryAllDataW WmiQueryGuidInformation WmiQuerySingleInstanceA WmiQuerySingleInstanceMultipleA WmiQuerySingleInstanceMultipleW WmiQuerySingleInstanceW WmiReceiveNotificationsA WmiReceiveNotificationsW WmiSetSingleInstanceA WmiSetSingleInstanceW WmiSetSingleItemA WmiSetSingleItemW Wow64Win32ApiEntry WriteEncryptedFileRaw

Found follow exports in WSOCK32.DL
AcceptEx GetAcceptExSockaddrs MigrateWinsockConfiguration WEP WSApSetPostRoutine

Found follow exports in WS2_32.DL
accept bind closesocket connect freeaddrinfo FreeAddrInfoEx FreeAddrInfoExW FreeAddrInfoW getaddrinfo GetAddrInfoExA GetAddrInfoExW GetAddrInfoW gethostbyaddr gethostbyname gethostname getnameinfo GetNameInfoW getpeername getprotobyname getprotobynumber getservbyname getservbyport getsockname getsockopt htonl htons inet_addr inet_ntoa inet_ntop inet_pton InetNtopW InetPtonW ioctlsocket listen ntohl ntohs recv recvfrom select send sendto SetAddrInfoExA SetAddrInfoExW setsockopt shutdown socket WahCloseApcHelper WahCloseHandleHelper WahCloseNotificationHandleHelper WahCloseSocketHandle WahCloseThread WahCompleteRequest WahCreateHandleContextTable WahCreateNotificationHandle WahCreateSocketHandle WahDestroyHandleContextTable WahDisableNonIFSHandleSupport WahEnableNonIFSHandleSupport WahEnumerateHandleContexts WahInsertHandleContext WahNotifyAllProcesses WahOpenApcHelper WahOpenCurrentThread WahOpenHandleHelper WahOpenNotificationHandleHelper WahQueueUserApc WahReferenceContextByHandle WahRemoveHandleContext WahWaitForNotification WahWriteLSPEvent WEP WPUCompleteOverlappedRequest WSAAccept WSAAddressToStringA WSAAddressToStringW WSAAdvertiseProvider WSAAsyncGetHostByAddr WSAAsyncGetHostByName WSAAsyncGetProtoByName WSAAsyncGetProtoByNumber WSAAsyncGetServByName WSAAsyncGetServByPort WSAAsyncSelect WSACancelAsyncRequest WSACancelBlockingCall WSACleanup WSACloseEvent WSAConnect WSAConnectByList WSAConnectByNameA WSAConnectByNameW WSACreateEvent WSADuplicateSocketA WSADuplicateSocketW WSAEnumNameSpaceProvidersA WSAEnumNameSpaceProvidersExA WSAEnumNameSpaceProvidersExW WSAEnumNameSpaceProvidersW WSAEnumNetworkEvents WSAEnumProtocolsA WSAEnumProtocolsW WSAEventSelect __WSAFDIsSet WSAGetLastError WSAGetOverlappedResult WSAGetQOSByName WSAGetServiceClassInfoA WSAGetServiceClassInfoW WSAGetServiceClassNameByClassIdA WSAGetServiceClassNameByClassIdW WSAHtonl WSAHtons WSAInstallServiceClassA WSAInstallServiceClassW WSAIoctl WSAIsBlocking WSAJoinLeaf WSALookupServiceBeginA WSALookupServiceBeginW WSALookupServiceEnd WSALookupServiceNextA WSALookupServiceNextW WSANSPIoctl WSANtohl WSANtohs WSAPoll WSAProviderCompleteAsyncCall WSAProviderConfigChange WSApSetPostRoutine WSARecv WSARecvDisconnect WSARecvFrom WSARemoveServiceClass WSAResetEvent WSASend WSASendDisconnect WSASendMsg WSASendTo WSASetBlockingHook WSASetEvent WSASetLastError WSASetServiceA WSASetServiceW WSASocketA WSASocketW WSAStartup WSAStringToAddressA WSAStringToAddressW WSAUnadvertiseProvider WSAUnhookBlockingHook WSAWaitForMultipleEvents WSCDeinstallProvider WSCEnableNSProvider WSCEnumProtocols WSCGetApplicationCategory WSCGetProviderInfo WSCGetProviderPath WSCInstallNameSpace WSCInstallNameSpaceEx WSCInstallProvider WSCInstallProviderAndChains WSCSetApplicationCategory WSCSetProviderInfo WSCUnInstallNameSpace WSCUpdateProvider WSCWriteNameSpaceOrder WSCWriteProviderOrder


<<Click here to return to the search engine