<<Click here to return to the search engine

Index


Windows


Found follow exports in KERNEL32.DLL
AddAtomA
AddAtomW
AllocConsole
AreFileApisANSI
BackupRead
BackupSeek
BackupWrite
Beep
BeginUpdateResourceA
BeginUpdateResourceW
BuildCommDCBA
BuildCommDCBAndTimeoutsA
BuildCommDCBAndTimeoutsW
BuildCommDCBW
CallNamedPipeA
CallNamedPipeW
ClearCommBreak
ClearCommError
CloseHandle
CloseProfileUserMapping
CommConfigDialogA
CommConfigDialogW
CompareFileTime
CompareStringA
CompareStringW
ConnectNamedPipe
ContinueDebugEvent
ConvertDefaultLocale
CopyFileA
CopyFileW
CreateConsoleScreenBuffer
CreateDirectoryA
CreateDirectoryExA
CreateDirectoryExW
CreateDirectoryW
CreateEventA
CreateEventW
CreateFileA
CreateFileMappingA
CreateFileMappingW
CreateFileW
CreateIoCompletionPort
CreateMailslotA
CreateMailslotW
CreateMutexA
CreateMutexW
CreateNamedPipeA
CreateNamedPipeW
CreatePipe
CreateProcessA
CreateProcessW
CreateRemoteThread
CreateSemaphoreA
CreateSemaphoreW
CreateTapePartition
CreateThread
DebugActiveProcess
DebugBreak
DefineDosDeviceA
DefineDosDeviceW
DeleteAtom
DeleteCriticalSection
DeleteFileA
DeleteFileW
DeviceIoControl
DisableThreadLibraryCalls
DisconnectNamedPipe
DosDateTimeToFileTime
DuplicateHandle
EndUpdateResourceA
EndUpdateResourceW
EnterCriticalSection
EnumCalendarInfoA
EnumCalendarInfoW
EnumDateFormatsA
EnumDateFormatsW
EnumResourceLanguagesA
EnumResourceLanguagesW
EnumResourceNamesA
EnumResourceNamesW
EnumResourceTypesA
EnumResourceTypesW
EnumSystemCodePagesA
EnumSystemCodePagesW
EnumSystemLocalesA
EnumSystemLocalesW
EnumTimeFormatsA
EnumTimeFormatsW
EraseTape
EscapeCommFunction
ExitProcess
ExitThread
ExpandEnvironmentStringsA
ExpandEnvironmentStringsW
FatalAppExitA
FatalAppExitW
FatalExit
FileTimeToDosDateTime
FileTimeToLocalFileTime
FileTimeToSystemTime
FillConsoleOutputAttribute
FillConsoleOutputCharacterA
FillConsoleOutputCharacterW
FindAtomA
FindAtomW
FindClose
FindCloseChangeNotification
FindFirstChangeNotificationA
FindFirstChangeNotificationW
FindFirstFileA
FindFirstFileW
FindNextChangeNotification
FindNextFileA
FindNextFileW
FindResourceA
FindResourceExA
FindResourceExW
FindResourceW
FlushConsoleInputBuffer
FlushFileBuffers
FlushInstructionCache
FlushViewOfFile
FoldStringA
FoldStringW
FormatMessageA
FormatMessageW
FreeConsole
FreeEnvironmentStringsA
FreeEnvironmentStringsW
FreeLibrary
FreeLibraryAndExitThread
FreeResource
GenerateConsoleCtrlEvent
GetACP
GetAtomNameA
GetAtomNameW
GetBinaryType
GetBinaryTypeA
GetBinaryTypeW
GetCommandLineA
GetCommandLineW
GetCommConfig
GetCommMask
GetCommModemStatus
GetCommProperties
GetCommState
GetCommTimeouts
GetCompressedFileSizeA
GetCompressedFileSizeW
GetComputerNameA
GetComputerNameW
GetConsoleCP
GetConsoleCursorInfo
GetConsoleMode
GetConsoleOutputCP
GetConsoleScreenBufferInfo
GetConsoleTitleA
GetConsoleTitleW
GetCPInfo
GetCurrencyFormatA
GetCurrencyFormatW
GetCurrentDirectoryA
GetCurrentDirectoryW
GetCurrentProcess
GetCurrentProcessId
GetCurrentThread
GetCurrentThreadId
GetDateFormatA
GetDateFormatW
GetDefaultCommConfigA
GetDefaultCommConfigW
GetDiskFreeSpaceA
GetDiskFreeSpaceExA
GetDiskFreeSpaceExW
GetDiskFreeSpaceW
GetDriveTypeA
GetDriveTypeW
GetEnvironmentStrings
GetEnvironmentStringsA
GetEnvironmentStringsW
GetEnvironmentVariableA
GetEnvironmentVariableW
GetExitCodeProcess
GetExitCodeThread
GetFileAttributesA
GetFileAttributesW
GetFileInformationByHandle
GetFileSize
GetFileTime
GetFileType
GetFullPathNameA
GetFullPathNameW
GetHandleInformation
GetLargestConsoleWindowSize
GetLastError
GetLocaleInfoA
GetLocaleInfoW
GetLocalTime
GetLogicalDrives
GetLogicalDriveStringsA
GetLogicalDriveStringsW
GetMailslotInfo
GetModuleFileNameA
GetModuleFileNameW
GetModuleHandleA
GetModuleHandleW
GetNamedPipeHandleStateA
GetNamedPipeHandleStateW
GetNamedPipeInfo
GetNumberFormatA
GetNumberFormatW
GetNumberOfConsoleInputEvents
GetNumberOfConsoleMouseButtons
GetOEMCP
GetOverlappedResult
GetPriorityClass
GetPrivateProfileIntA
GetPrivateProfileIntW
GetPrivateProfileSectionA
GetPrivateProfileSectionNamesA
GetPrivateProfileSectionNamesW
GetPrivateProfileSectionW
GetPrivateProfileStringA
GetPrivateProfileStringW
GetPrivateProfileStructA
GetPrivateProfileStructW
GetProcAddress
GetProcessAffinityMask
GetProcessHeap
GetProcessHeaps
GetProcessShutdownParameters
GetProcessTimes
GetProcessVersion
GetProcessWorkingSetSize
GetProfileIntA
GetProfileIntW
GetProfileSectionA
GetProfileSectionW
GetProfileStringA
GetProfileStringW
GetQueuedCompletionStatus
GetShortPathNameA
GetShortPathNameW
GetStartupInfoA
GetStartupInfoW
GetStdHandle
GetStringTypeA
GetStringTypeExA
GetStringTypeExW
GetStringTypeW
GetSystemDefaultLangID
GetSystemDefaultLCID
GetSystemDirectoryA
GetSystemDirectoryW
GetSystemInfo
GetSystemPowerStatus
GetSystemTime
GetSystemTimeAdjustment
GetSystemTimeAsFileTime
GetTapeParameters
GetTapePosition
GetTapeStatus
GetTempFileNameA
GetTempFileNameW
GetTempPathA
GetTempPathW
GetThreadContext
GetThreadLocale
GetThreadPriority
GetThreadSelectorEntry
GetThreadTimes
GetTickCount
GetTimeFormatA
GetTimeFormatW
GetTimeZoneInformation
GetUserDefaultLangID
GetUserDefaultLCID
GetVersion
GetVersionExA
GetVersionExW
GetVolumeInformationA
GetVolumeInformationW
GetWindowsDirectoryA
GetWindowsDirectoryW
GlobalAddAtomA
GlobalAddAtomW
GlobalAlloc
GlobalCompact
GlobalDeleteAtom
GlobalFindAtomA
GlobalFindAtomW
GlobalFix
GlobalFlags
GlobalFree
GlobalGetAtomNameA
GlobalGetAtomNameW
GlobalHandle
GlobalLock
GlobalMemoryStatus
GlobalReAlloc
GlobalSize
GlobalUnfix
GlobalUnlock
GlobalUnWire
GlobalWire
HeapAlloc
HeapCompact
HeapCreate
HeapDestroy
HeapFree
HeapLock
HeapReAlloc
HeapSize
HeapUnlock
HeapValidate
HeapWalk
_hread
_hwrite
InitAtomTable
InitializeCriticalSection
InterlockedDecrement
InterlockedExchange
InterlockedIncrement
IsBadCodePtr
IsBadHugeReadPtr
IsBadHugeWritePtr
IsBadReadPtr
IsBadStringPtrA
IsBadStringPtrW
IsBadWritePtr
IsDBCSLeadByte
IsDBCSLeadByteEx
IsValidCodePage
IsValidLocale
_lclose
LCMapStringA
LCMapStringW
_lcreat
LeaveCriticalSection
_llseek
LoadLibraryA
LoadLibraryExA
LoadLibraryExW
LoadLibraryW
LoadModule
LoadResource
LocalAlloc
LocalCompact
LocalFileTimeToFileTime
LocalFlags
LocalFree
LocalHandle
LocalLock
LocalReAlloc
LocalShrink
LocalSize
LocalUnlock
LockFile
LockFileEx
LockResource
_lopen
_lread
lstrcat
lstrcatA
lstrcatW
lstrcmp
lstrcmpA
lstrcmpi
lstrcmpiA
lstrcmpiW
lstrcmpW
lstrcpy
lstrcpyA
lstrcpyn
lstrcpynA
lstrcpynW
lstrcpyW
lstrlen
lstrlenA
lstrlenW
_lwrite
MapViewOfFile
MapViewOfFileEx
MoveFileA
MoveFileExA
MoveFileExW
MoveFileW
MulDiv
MultiByteToWideChar
OpenEventA
OpenEventW
OpenFile
OpenFileMappingA
OpenFileMappingW
OpenMutexA
OpenMutexW
OpenProcess
OpenProfileUserMapping
OpenSemaphoreA
OpenSemaphoreW
OutputDebugStringA
OutputDebugStringW
PeekConsoleInputA
PeekConsoleInputW
PeekNamedPipe
PostQueuedCompletionStatus
PrepareTape
PulseEvent
PurgeComm
QueryDosDeviceA
QueryDosDeviceW
QueryPerformanceCounter
QueryPerformanceFrequency
QueueUserAPC
RaiseException
ReadConsoleA
ReadConsoleInputA
ReadConsoleInputW
ReadConsoleOutputA
ReadConsoleOutputAttribute
ReadConsoleOutputCharacterA
ReadConsoleOutputCharacterW
ReadConsoleOutputW
ReadConsoleW
ReadFile
ReadFileEx
ReadProcessMemory
ReleaseMutex
ReleaseSemaphore
RemoveDirectoryA
RemoveDirectoryW
ResetEvent
ResumeThread
RtlFillMemory
RtlMoveMemory
RtlUnwind
RtlZeroMemory
ScrollConsoleScreenBufferA
ScrollConsoleScreenBufferW
SearchPathA
SearchPathW
SetCommBreak
SetCommConfig
SetCommMask
SetCommState
SetCommTimeouts
SetComputerNameA
SetComputerNameW
SetConsoleActiveScreenBuffer
SetConsoleCP
SetConsoleCtrlHandler
SetConsoleCursorInfo
SetConsoleCursorPosition
SetConsoleMode
SetConsoleOutputCP
SetConsoleScreenBufferSize
SetConsoleTextAttribute
SetConsoleTitleA
SetConsoleTitleW
SetConsoleWindowInfo
SetCurrentDirectoryA
SetCurrentDirectoryW
SetDefaultCommConfigA
SetDefaultCommConfigW
SetEndOfFile
SetEnvironmentVariableA
SetEnvironmentVariableW
SetErrorMode
SetEvent
SetFileApisToANSI
SetFileApisToOEM
SetFileAttributesA
SetFileAttributesW
SetFilePointer
SetFileTime
SetHandleCount
SetHandleInformation
SetLastError
SetLocaleInfoA
SetLocaleInfoW
SetLocalTime
SetMailslotInfo
SetNamedPipeHandleState
SetPriorityClass
SetProcessShutdownParameters
SetProcessWorkingSetSize
SetStdHandle
SetSystemPowerState
SetSystemTime
SetSystemTimeAdjustment
SetTapeParameters
SetTapePosition
SetThreadAffinityMask
SetThreadContext
SetThreadLocale
SetThreadPriority
SetTimeZoneInformation
SetUnhandledExceptionFilter
SetupComm
SetVolumeLabelA
SetVolumeLabelW
SizeofResource
Sleep
SleepEx
SuspendThread
SystemTimeToFileTime
SystemTimeToTzSpecificLocalTime
TerminateProcess
TerminateThread
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
TransactNamedPipe
TransmitCommChar
UnhandledExceptionFilter
UnlockFile
UnlockFileEx
UnmapViewOfFile
UpdateResourceA
UpdateResourceW
VerLanguageNameA
VerLanguageNameW
VirtualAlloc
VirtualFree
VirtualLock
VirtualProtect
VirtualProtectEx
VirtualQuery
VirtualQueryEx
VirtualUnlock
WaitCommEvent
WaitForDebugEvent
WaitForMultipleObjects
WaitForMultipleObjectsEx
WaitForSingleObject
WaitForSingleObjectEx
WaitNamedPipeA
WaitNamedPipeW
WideCharToMultiByte
WinExec
WriteConsoleA
WriteConsoleInputA
WriteConsoleInputW
WriteConsoleOutputA
WriteConsoleOutputAttribute
WriteConsoleOutputCharacterA
WriteConsoleOutputCharacterW
WriteConsoleOutputW
WriteConsoleW
WriteFile
WriteFileEx
WritePrivateProfileSectionA
WritePrivateProfileSectionW
WritePrivateProfileStringA
WritePrivateProfileStringW
WritePrivateProfileStructA
WritePrivateProfileStructW
WriteProcessMemory
WriteProfileSectionA
WriteProfileSectionW
WriteProfileStringA
WriteProfileStringW
WriteTapemark


Found follow exports in NTDLL.DLL
DbgBreakPoint
DbgPrint
DbgPrompt
NtCurrentTeb
NtQueryPerformanceCounter
RtlAllocateHeap
RtlAnsiStringToUnicodeString
RtlConvertLongToLargeInteger
RtlConvertUlongToLargeInteger
RtlCreateHeap
RtlDestroyHeap
RtlEnlargedIntegerMultiply
RtlEnlargedUnsignedDivide
RtlEnlargedUnsignedMultiply
RtlExtendedIntegerMultiply
RtlExtendedLargeIntegerDivide
RtlExtendedMagicDivide
RtlFreeHeap
RtlImageNtHeader
RtlLargeIntegerAdd
RtlLargeIntegerArithmeticShift
RtlLargeIntegerDivide
RtlLargeIntegerNegate
RtlLargeIntegerShiftLeft
RtlLargeIntegerShiftRight
RtlLargeIntegerSubtract
RtlMultiByteToUnicodeN
RtlReAllocateHeap
RtlSizeHeap
RtlUnicodeStringToAnsiString
RtlUnicodeToMultiByteN
RtlUnwind
RtlValidateHeap


Found follow exports in USER32.DLL
ActivateKeyboardLayout
AdjustWindowRect
AdjustWindowRectEx
AnyPopup
AppendMenuA
AppendMenuW
ArrangeIconicWindows
AttachThreadInput
BeginDeferWindowPos
BeginPaint
BringWindowToTop
BroadcastSystemMessage
CallMsgFilter
CallMsgFilterA
CallMsgFilterW
CallNextHookEx
CallWindowProcA
CallWindowProcW
CascadeChildWindows
CascadeWindows
ChangeClipboardChain
ChangeDisplaySettingsA
ChangeDisplaySettingsW
ChangeMenuA
ChangeMenuW
CharLowerA
CharLowerBuffA
CharLowerBuffW
CharLowerW
CharNextA
CharNextExA
CharNextW
CharPrevA
CharPrevExA
CharPrevW
CharToOemA
CharToOemBuffA
CharToOemBuffW
CharToOemW
CharUpperA
CharUpperBuffA
CharUpperBuffW
CharUpperW
CheckDlgButton
CheckMenuItem
CheckMenuRadioItem
CheckRadioButton
ChildWindowFromPoint
ChildWindowFromPointEx
ClientToScreen
ClipCursor
CloseClipboard
CloseDesktop
CloseWindow
CloseWindowStation
CopyAcceleratorTableA
CopyAcceleratorTableW
CopyIcon
CopyImage
CopyRect
CountClipboardFormats
CreateAcceleratorTableA
CreateAcceleratorTableW
CreateCaret
CreateCursor
CreateDesktopA
CreateDesktopW
CreateDialogIndirectParamA
CreateDialogIndirectParamW
CreateDialogParamA
CreateDialogParamW
CreateIcon
CreateIconFromResource
CreateIconFromResourceEx
CreateIconIndirect
CreateMDIWindowA
CreateMDIWindowW
CreateMenu
CreatePopupMenu
CreateWindowExA
CreateWindowExW
CreateWindowStationA
CreateWindowStationW
DdeAbandonTransaction
DdeAccessData
DdeAddData
DdeClientTransaction
DdeCmpStringHandles
DdeConnect
DdeConnectList
DdeCreateDataHandle
DdeCreateStringHandleA
DdeCreateStringHandleW
DdeDisconnect
DdeDisconnectList
DdeEnableCallback
DdeFreeDataHandle
DdeFreeStringHandle
DdeGetData
DdeGetLastError
DdeImpersonateClient
DdeInitializeA
DdeInitializeW
DdeKeepStringHandle
DdeNameService
DdePostAdvise
DdeQueryConvInfo
DdeQueryNextServer
DdeQueryStringA
DdeQueryStringW
DdeReconnect
DdeSetQualityOfService
DdeSetUserHandle
DdeUnaccessData
DdeUninitialize
DefDlgProcA
DefDlgProcW
DeferWindowPos
DefFrameProcA
DefFrameProcW
DefMDIChildProcA
DefMDIChildProcW
DefWindowProcA
DefWindowProcW
DeleteMenu
DestroyAcceleratorTable
DestroyCaret
DestroyCursor
DestroyIcon
DestroyMenu
DestroyWindow
DialogBoxIndirectParamA
DialogBoxIndirectParamW
DialogBoxParamA
DialogBoxParamW
DispatchMessageA
DispatchMessageW
DlgDirListA
DlgDirListComboBoxA
DlgDirListComboBoxW
DlgDirListW
DlgDirSelectComboBoxExA
DlgDirSelectComboBoxExW
DlgDirSelectExA
DlgDirSelectExW
DragDetect
DragObject
DrawAnimatedRects
DrawCaption
DrawCaptionTempA
DrawCaptionTempW
DrawEdge
DrawFocusRect
DrawFrame
DrawFrameControl
DrawIcon
DrawIconEx
DrawMenuBar
DrawStateA
DrawStateW
DrawTextA
DrawTextExA
DrawTextExW
DrawTextW
EditWndProc
EmptyClipboard
EnableMenuItem
EnableScrollBar
EnableWindow
EndDeferWindowPos
EndDialog
EndPaint
EndTask
EnumChildWindows
EnumClipboardFormats
EnumDesktopsA
EnumDesktopsW
EnumDesktopWindows
EnumDisplaySettingsA
EnumDisplaySettingsW
EnumPropsA
EnumPropsExA
EnumPropsExW
EnumPropsW
EnumThreadWindows
EnumWindows
EnumWindowStationsA
EnumWindowStationsW
EqualRect
ExcludeUpdateRgn
ExitWindowsEx
FillRect
FindWindowA
FindWindowExA
FindWindowExW
FindWindowW
FlashWindow
FrameRect
FreeDDElParam
GetActiveWindow
GetAsyncKeyState
GetCapture
GetCaretBlinkTime
GetCaretPos
GetClassInfoA
GetClassInfoExA
GetClassInfoExW
GetClassInfoW
GetClassLongA
GetClassLongW
GetClassNameA
GetClassNameW
GetClassWord
GetClientRect
GetClipboardData
GetClipboardFormatNameA
GetClipboardFormatNameW
GetClipboardOwner
GetClipboardViewer
GetClipCursor
GetCursor
GetCursorPos
GetDC
GetDCEx
GetDesktopWindow
GetDialogBaseUnits
GetDlgCtrlID
GetDlgItem
GetDlgItemInt
GetDlgItemTextA
GetDlgItemTextW
GetDoubleClickTime
GetFocus
GetForegroundWindow
GetIconInfo
GetInputDesktop
GetInputState
GetInternalWindowPos
GetKBCodePage
GetKeyboardLayout
GetKeyboardLayoutList
GetKeyboardLayoutNameA
GetKeyboardLayoutNameW
GetKeyboardState
GetKeyboardType
GetKeyNameTextA
GetKeyNameTextW
GetKeyState
GetLastActivePopup
GetMenu
GetMenuCheckMarkDimensions
GetMenuContextHelpId
GetMenuDefaultItem
GetMenuItemCount
GetMenuItemID
GetMenuItemInfoA
GetMenuItemInfoW
GetMenuItemRect
GetMenuState
GetMenuStringA
GetMenuStringW
GetMessageA
GetMessageExtraInfo
GetMessagePos
GetMessageTime
GetMessageW
GetNextDlgGroupItem
GetNextDlgTabItem
GetOpenClipboardWindow
GetParent
GetPriorityClipboardFormat
GetProcessWindowStation
GetPropA
GetPropW
GetQueueStatus
GetScrollInfo
GetScrollPos
GetScrollRange
GetShellWindow
GetSubMenu
GetSysColor
GetSysColorBrush
GetSystemMenu
GetSystemMetrics
GetTabbedTextExtentA
GetTabbedTextExtentW
GetThreadDesktop
GetTopWindow
GetUpdateRect
GetUpdateRgn
GetUserObjectInformationA
GetUserObjectInformationW
GetUserObjectSecurity
GetWindow
GetWindowContextHelpId
GetWindowDC
GetWindowLongA
GetWindowLongW
GetWindowPlacement
GetWindowRect
GetWindowRgn
GetWindowTextA
GetWindowTextLengthA
GetWindowTextLengthW
GetWindowTextW
GetWindowThreadProcessId
GetWindowWord
GrayStringA
GrayStringW
HideCaret
HiliteMenuItem
ImpersonateDdeClientWindow
InflateRect
InSendMessage
InsertMenuA
InsertMenuItemA
InsertMenuItemW
InsertMenuW
InternalGetWindowText
IntersectRect
InvalidateRect
InvalidateRgn
InvertRect
IsCharAlphaA
IsCharAlphaNumericA
IsCharAlphaNumericW
IsCharAlphaW
IsCharLowerA
IsCharLowerW
IsCharUpperA
IsCharUpperW
IsChild
IsClipboardFormatAvailable
IsDialogMessage
IsDialogMessageA
IsDialogMessageW
IsDlgButtonChecked
IsIconic
IsMenu
IsRectEmpty
IsWindow
IsWindowEnabled
IsWindowUnicode
IsWindowVisible
IsZoomed
keybd_event
KillTimer
LoadAcceleratorsA
LoadAcceleratorsW
LoadBitmapA
LoadBitmapW
LoadCursorA
LoadCursorFromFileA
LoadCursorFromFileW
LoadCursorW
LoadIconA
LoadIconW
LoadImageA
LoadImageW
LoadKeyboardLayoutA
LoadKeyboardLayoutW
LoadMenuA
LoadMenuIndirectA
LoadMenuIndirectW
LoadMenuW
LoadStringA
LoadStringW
LockWindowStation
LockWindowUpdate
LookupIconIdFromDirectory
LookupIconIdFromDirectoryEx
MapDialogRect
MapVirtualKeyA
MapVirtualKeyExA
MapVirtualKeyExW
MapVirtualKeyW
MapWindowPoints
MenuItemFromPoint
MessageBeep
MessageBoxA
MessageBoxExA
MessageBoxExW
MessageBoxIndirectA
MessageBoxIndirectW
MessageBoxW
ModifyMenuA
ModifyMenuW
mouse_event
MoveWindow
MsgWaitForMultipleObjects
OemKeyScan
OemToCharA
OemToCharBuffA
OemToCharBuffW
OemToCharW
OffsetRect
OpenClipboard
OpenDesktopA
OpenDesktopW
OpenIcon
OpenInputDesktop
OpenWindowStationA
OpenWindowStationW
PackDDElParam
PaintDesktop
PeekMessageA
PeekMessageW
PostMessageA
PostMessageW
PostQuitMessage
PostThreadMessageA
PostThreadMessageW
PtInRect
RedrawWindow
RegisterClassA
RegisterClassExA
RegisterClassExW
RegisterClassW
RegisterClipboardFormatA
RegisterClipboardFormatW
RegisterHotKey
RegisterLogonProcess
RegisterSystemThread
RegisterTasklist
RegisterWindowMessageA
RegisterWindowMessageW
ReleaseCapture
ReleaseDC
RemoveMenu
RemovePropA
RemovePropW
ReplyMessage
ReuseDDElParam
ScreenToClient
ScrollDC
ScrollWindow
ScrollWindowEx
SendDlgItemMessageA
SendDlgItemMessageW
SendMessageA
SendMessageCallbackA
SendMessageCallbackW
SendMessageTimeoutA
SendMessageTimeoutW
SendMessageW
SendNotifyMessageA
SendNotifyMessageW
SetActiveWindow
SetCapture
SetCaretBlinkTime
SetCaretPos
SetClassLongA
SetClassLongW
SetClassWord
SetClipboardData
SetClipboardViewer
SetCursor
SetCursorPos
SetDebugErrorLevel
SetDeskWallpaper
SetDlgItemInt
SetDlgItemTextA
SetDlgItemTextW
SetDoubleClickTime
SetFocus
SetForegroundWindow
SetInternalWindowPos
SetKeyboardState
SetLastErrorEx
SetMenu
SetMenuContextHelpId
SetMenuDefaultItem
SetMenuItemBitmaps
SetMenuItemInfoA
SetMenuItemInfoW
SetMessageExtraInfo
SetMessageQueue
SetParent
SetProcessWindowStation
SetPropA
SetPropW
SetRect
SetRectEmpty
SetScrollInfo
SetScrollPos
SetScrollRange
SetShellWindow
SetSysColors
SetSysColorsTemp
SetSystemCursor
SetThreadDesktop
SetTimer
SetUserObjectInformationA
SetUserObjectInformationW
SetUserObjectSecurity
SetWindowContextHelpId
SetWindowLongA
SetWindowLongW
SetWindowPlacement
SetWindowPos
SetWindowRgn
SetWindowsHookA
SetWindowsHookExA
SetWindowsHookExW
SetWindowsHookW
SetWindowTextA
SetWindowTextW
SetWindowWord
ShowCaret
ShowCursor
ShowOwnedPopups
ShowScrollBar
ShowWindow
ShowWindowAsync
SubtractRect
SwapMouseButton
SwitchDesktop
SwitchToThisWindow
SystemParametersInfoA
SystemParametersInfoW
TabbedTextOutA
TabbedTextOutW
TileChildWindows
TileWindows
ToAscii
ToAsciiEx
ToUnicode
TrackPopupMenu
TrackPopupMenuEx
TranslateAccelerator
TranslateAcceleratorA
TranslateAcceleratorW
TranslateMDISysAccel
TranslateMessage
UnhookWindowsHook
UnhookWindowsHookEx
UnionRect
UnloadKeyboardLayout
UnlockWindowStation
UnpackDDElParam
UnregisterClassA
UnregisterClassW
UnregisterHotKey
UpdateWindow
UserClientDllInitialize
ValidateRect
ValidateRgn
VkKeyScanA
VkKeyScanExA
VkKeyScanExW
VkKeyScanW
WaitForInputIdle
WaitMessage
WindowFromDC
WindowFromPoint
WinHelpA
WinHelpW
wsprintfA
wsprintfW
wvsprintfA
wvsprintfW


Found follow exports in GDI32.DLL
AbortDoc
AbortPath
AddFontResourceA
AddFontResourceW
AngleArc
AnimatePalette
Arc
ArcTo
BeginPath
BitBlt
CancelDC
CheckColorsInGamut
ChoosePixelFormat
Chord
CloseEnhMetaFile
CloseFigure
CloseMetaFile
ColorMatchToTarget
CombineRgn
CombineTransform
CopyEnhMetaFileA
CopyEnhMetaFileW
CopyMetaFileA
CopyMetaFileW
CreateBitmap
CreateBitmapIndirect
CreateBrushIndirect
CreateColorSpaceA
CreateColorSpaceW
CreateCompatibleBitmap
CreateCompatibleDC
CreateDCA
CreateDCW
CreateDIBitmap
CreateDIBPatternBrush
CreateDIBPatternBrushPt
CreateDIBSection
CreateDiscardableBitmap
CreateEllipticRgn
CreateEllipticRgnIndirect
CreateEnhMetaFileA
CreateEnhMetaFileW
CreateFontA
CreateFontIndirectA
CreateFontIndirectW
CreateFontW
CreateHalftonePalette
CreateHatchBrush
CreateICA
CreateICW
CreateMetaFileA
CreateMetaFileW
CreatePalette
CreatePatternBrush
CreatePen
CreatePenIndirect
CreatePolygonRgn
CreatePolyPolygonRgn
CreateRectRgn
CreateRectRgnIndirect
CreateRoundRectRgn
CreateScalableFontResourceA
CreateScalableFontResourceW
CreateSolidBrush
DeleteColorSpace
DeleteDC
DeleteEnhMetaFile
DeleteMetaFile
DeleteObject
DescribePixelFormat
DeviceCapabilitiesExA
DeviceCapabilitiesExW
DPtoLP
DrawEscape
Ellipse
EndDoc
EndPage
EndPath
EnumEnhMetaFile
EnumFontFamiliesA
EnumFontFamiliesExA
EnumFontFamiliesExW
EnumFontFamiliesW
EnumFontsA
EnumFontsW
EnumICMProfilesA
EnumICMProfilesW
EnumMetaFile
EnumObjects
EqualRgn
Escape
ExcludeClipRect
ExtCreatePen
ExtCreateRegion
ExtEscape
ExtFloodFill
ExtSelectClipRgn
ExtTextOutA
ExtTextOutW
FillPath
FillRgn
FixBrushOrgEx
FlattenPath
FloodFill
FrameRgn
GdiComment
GdiFlush
GdiGetBatchLimit
GdiPlayDCScript
GdiPlayJournal
GdiPlayScript
gdiPlaySpoolStream
GdiSetBatchLimit
GetArcDirection
GetAspectRatioFilterEx
GetBitmapBits
GetBitmapDimensionEx
GetBkColor
GetBkMode
GetBoundsRect
GetBrushOrgEx
GetCharABCWidthsA
GetCharABCWidthsFloatA
GetCharABCWidthsFloatW
GetCharABCWidthsW
GetCharacterPlacementA
GetCharacterPlacementW
GetCharWidth32A
GetCharWidth32W
GetCharWidthA
GetCharWidthFloatA
GetCharWidthFloatW
GetCharWidthW
GetClipBox
GetClipRgn
GetColorAdjustment
GetColorSpace
GetCurrentObject
GetCurrentPositionEx
GetDCOrgEx
GetDeviceCaps
GetDeviceGammaRamp
GetDIBColorTable
GetDIBits
GetEnhMetaFileA
GetEnhMetaFileBits
GetEnhMetaFileDescriptionA
GetEnhMetaFileDescriptionW
GetEnhMetaFileHeader
GetEnhMetaFilePaletteEntries
GetEnhMetaFileW
GetFontData
GetFontLanguageInfo
GetGlyphOutline
GetGlyphOutlineA
GetGlyphOutlineW
GetGraphicsMode
GetICMProfileA
GetICMProfileW
GetKerningPairs
GetKerningPairsA
GetKerningPairsW
GetLogColorSpaceA
GetLogColorSpaceW
GetMapMode
GetMetaFileA
GetMetaFileBitsEx
GetMetaFileW
GetMetaRgn
GetMiterLimit
GetNearestColor
GetNearestPaletteIndex
GetObjectA
GetObjectType
GetObjectW
GetOutlineTextMetricsA
GetOutlineTextMetricsW
GetPaletteEntries
GetPath
GetPixel
GetPixelFormat
GetPolyFillMode
GetRandomRgn
GetRasterizerCaps
GetRegionData
GetRgnBox
GetROP2
GetStockObject
GetStretchBltMode
GetSystemPaletteEntries
GetSystemPaletteUse
GetTextAlign
GetTextCharacterExtra
GetTextCharset
GetTextCharsetInfo
GetTextColor
GetTextExtentExPointA
GetTextExtentExPointW
GetTextExtentPoint32A
GetTextExtentPoint32W
GetTextExtentPointA
GetTextExtentPointW
GetTextFaceA
GetTextFaceW
GetTextMetricsA
GetTextMetricsW
GetViewportExtEx
GetViewportOrgEx
GetWindowExtEx
GetWindowOrgEx
GetWinMetaFileBits
GetWorldTransform
IntersectClipRect
InvertRgn
LineDDA
LineTo
LPtoDP
MaskBlt
ModifyWorldTransform
MoveToEx
OffsetClipRgn
OffsetRgn
OffsetViewportOrgEx
OffsetWindowOrgEx
PaintRgn
PatBlt
PathToRegion
Pie
PlayEnhMetaFile
PlayEnhMetaFileRecord
PlayMetaFile
PlayMetaFileRecord
PlgBlt
PolyBezier
PolyBezierTo
PolyDraw
Polygon
Polyline
PolylineTo
PolyPolygon
PolyPolyline
PolyTextOutA
PolyTextOutW
PtInRegion
PtVisible
RealizePalette
Rectangle
RectInRegion
RectVisible
RemoveFontResourceA
RemoveFontResourceW
ResetDCA
ResetDCW
ResizePalette
RestoreDC
RoundRect
SaveDC
ScaleViewportExtEx
ScaleWindowExtEx
SelectClipPath
SelectClipRgn
SelectObject
SelectPalette
SetAbortProc
SetArcDirection
SetBitmapBits
SetBitmapDimensionEx
SetBkColor
SetBkMode
SetBoundsRect
SetBrushOrgEx
SetColorAdjustment
SetColorSpace
SetDeviceGammaRamp
SetDIBColorTable
SetDIBits
SetDIBitsToDevice
SetEnhMetaFileBits
SetFontEnumeration
SetGraphicsMode
SetICMMode
SetICMProfileA
SetICMProfileW
SetMapMode
SetMapperFlags
SetMetaFileBitsEx
SetMetaRgn
SetMiterLimit
SetPaletteEntries
SetPixel
SetPixelFormat
SetPixelV
SetPolyFillMode
SetRectRgn
SetROP2
SetStretchBltMode
SetSystemPaletteUse
SetTextAlign
SetTextCharacterExtra
SetTextColor
SetTextJustification
SetViewportExtEx
SetViewportOrgEx
SetWindowExtEx
SetWindowOrgEx
SetWinMetaFileBits
SetWorldTransform
StartDocA
StartDocW
StartPage
StretchBlt
StretchDIBits
StrokeAndFillPath
StrokePath
SwapBuffers
TextOutA
TextOutW
TranslateCharsetInfo
UnrealizeObject
UpdateColors
UpdateICMRegKeyA
UpdateICMRegKeyW
WidenPath


Found follow exports in SHELL32.DLL
CheckEscapesW
CommandLineToArgvW
Control_RunDLL
DllGetClassObject
DoEnvironmentSubstA
DoEnvironmentSubstW
DragAcceptFiles
DragFinish
DragQueryFile
DragQueryFileA
DragQueryFileAorW
DragQueryFileW
DragQueryPoint
DuplicateIcon
ExtractAssociatedIconA
ExtractAssociatedIconExA
ExtractAssociatedIconExW
ExtractAssociatedIconW
ExtractIconA
ExtractIconEx
ExtractIconExA
ExtractIconW
FindExecutableA
FindExecutableW
FreeIconList
InternalExtractIconListA
InternalExtractIconListW
OpenAs_RunDLL
PrintersGetCommand_RunDLL
RealShellExecuteA
RealShellExecuteExA
RealShellExecuteExW
RealShellExecuteW
RegenerateUserEnvironment
SHAddToRecentDocs
SHAppBarMessage
SHBrowseForFolder
SHBrowseForFolderA
SHChangeNotify
SheChangeDirA
SheChangeDirExW
SheGetDirA
Shell_NotifyIcon
Shell_NotifyIconA
ShellAboutA
ShellAboutW
ShellExecuteA
ShellExecuteEx
ShellExecuteExA
ShellExecuteW
SheSetCurDrive
SHFileOperation
SHFileOperationA
SHFormatDrive
SHFreeNameMappings
SHGetDataFromIDListA
SHGetDesktopFolder
SHGetFileInfo
SHGetFileInfoA
SHGetInstanceExplorer
SHGetMalloc
SHGetPathFromIDList
SHGetPathFromIDListA
SHGetSpecialFolderLocation
SHHelpShortcuts_RunDLL
SHLoadInProc


Found follow exports in COMDLG32.DLL
ChooseColorA
ChooseColorW
ChooseFontA
ChooseFontW
CommDlgExtendedError
FindTextA
FindTextW
GetFileTitleA
GetFileTitleW
GetOpenFileNameA
GetOpenFileNameW
GetSaveFileNameA
GetSaveFileNameW
PageSetupDlgA
PageSetupDlgW
PrintDlgA
PrintDlgW
ReplaceTextA
ReplaceTextW


Found follow exports in COMCTL32.DLL
CreateMappedBitmap
CreatePropertySheetPage
CreatePropertySheetPageA
CreatePropertySheetPageW
CreateStatusWindow
CreateStatusWindowA
CreateStatusWindowW
CreateToolbar
CreateToolbarEx
CreateUpDownControl
DestroyPropertySheetPage
DllGetVersion
DrawInsert
DrawStatusText
DrawStatusTextA
DrawStatusTextW
FlatSB_EnableScrollBar
FlatSB_GetScrollInfo
FlatSB_GetScrollPos
FlatSB_GetScrollProp
FlatSB_GetScrollRange
FlatSB_SetScrollInfo
FlatSB_SetScrollPos
FlatSB_SetScrollProp
FlatSB_SetScrollRange
FlatSB_ShowScrollBar
GetEffectiveClientRect
GetMUILanguage
ImageList_Add
ImageList_AddIcon
ImageList_AddMasked
ImageList_BeginDrag
ImageList_Copy
ImageList_Create
ImageList_Destroy
ImageList_DragEnter
ImageList_DragLeave
ImageList_DragMove
ImageList_DragShowNolock
ImageList_Draw
ImageList_DrawEx
ImageList_DrawIndirect
ImageList_Duplicate
ImageList_EndDrag
ImageList_GetBkColor
ImageList_GetDragImage
ImageList_GetIcon
ImageList_GetIconSize
ImageList_GetImageCount
ImageList_GetImageInfo
ImageList_GetImageRect
ImageList_LoadImage
ImageList_LoadImageA
ImageList_LoadImageW
ImageList_Merge
ImageList_Read
ImageList_Remove
ImageList_Replace
ImageList_ReplaceIcon
ImageList_SetBkColor
ImageList_SetDragCursorImage
ImageList_SetFilter
ImageList_SetFlags
ImageList_SetIconSize
ImageList_SetImageCount
ImageList_SetOverlayImage
ImageList_Write
InitCommonControls
InitCommonControlsEx
InitializeFlatSB
InitMUILanguage
LBItemFromPt
MakeDragList
MenuHelp
PropertySheet
PropertySheetA
PropertySheetW
ShowHideMenuCtl
_TrackMouseEvent
UninitializeFlatSB


Found follow exports in ADVAPI32.DLL
AbortSystemShutdownA
AbortSystemShutdownW
AccessCheck
AccessCheckAndAuditAlarmA
AccessCheckAndAuditAlarmW
AddAccessAllowedAce
AddAccessDeniedAce
AddAce
AddAuditAccessAce
AdjustTokenGroups
AdjustTokenPrivileges
AllocateAndInitializeSid
AllocateLocallyUniqueId
AreAllAccessesGranted
AreAnyAccessesGranted
BackupEventLogA
BackupEventLogW
ChangeServiceConfigA
ChangeServiceConfigW
ClearEventLogA
ClearEventLogW
CloseEventLog
CloseServiceHandle
ControlService
CopySid
CreatePrivateObjectSecurity
CreateProcessAsUserA
CreateProcessAsUserW
CreateServiceA
CreateServiceW
CryptAcquireContextA
CryptCreateHash
CryptDecrypt
CryptDeriveKey
CryptDestroyHash
CryptDestroyKey
CryptEncrypt
CryptExportKey
CryptGenKey
CryptGenRandom
CryptGetHashParam
CryptGetKeyParam
CryptGetProvParam
CryptGetUserKey
CryptHashData
CryptHashSessionKey
CryptImportKey
CryptReleaseContext
CryptSetHashParam
CryptSetKeyParam
CryptSetProviderA
CryptSetProvParam
CryptSignHashA
CryptVerifySignatureA
DeleteAce
DeleteService
DeregisterEventSource
DestroyPrivateObjectSecurity
DuplicateToken
EnumDependentServicesA
EnumDependentServicesW
EnumServicesStatusA
EnumServicesStatusW
EqualPrefixSid
EqualSid
FindFirstFreeAce
FreeSid
GetAce
GetAclInformation
GetFileSecurityA
GetFileSecurityW
GetKernelObjectSecurity
GetLengthSid
GetNumberOfEventLogRecords
GetOldestEventLogRecord
GetPrivateObjectSecurity
GetSecurityDescriptorControl
GetSecurityDescriptorDacl
GetSecurityDescriptorGroup
GetSecurityDescriptorLength
GetSecurityDescriptorOwner
GetSecurityDescriptorSacl
GetServiceDisplayNameA
GetServiceDisplayNameW
GetServiceKeyNameA
GetServiceKeyNameW
GetSidIdentifierAuthority
GetSidLengthRequired
GetSidSubAuthority
GetSidSubAuthorityCount
GetTokenInformation
GetUserNameA
GetUserNameW
ImpersonateLoggedOnUser
ImpersonateNamedPipeClient
ImpersonateSelf
InitializeAcl
InitializeSecurityDescriptor
InitializeSid
InitiateSystemShutdownA
InitiateSystemShutdownW
IsTextUnicode
IsValidAcl
IsValidSecurityDescriptor
IsValidSid
LockServiceDatabase
LogonUserA
LogonUserW
LookupAccountNameA
LookupAccountNameW
LookupAccountSidA
LookupAccountSidW
LookupPrivilegeDisplayNameA
LookupPrivilegeDisplayNameW
LookupPrivilegeNameA
LookupPrivilegeNameW
LookupPrivilegeValueA
LookupPrivilegeValueW
MakeAbsoluteSD
MakeSelfRelativeSD
MapGenericMask
NotifyBootConfigStatus
NotifyChangeEventLog
ObjectCloseAuditAlarmA
ObjectCloseAuditAlarmW
ObjectOpenAuditAlarmA
ObjectOpenAuditAlarmW
ObjectPrivilegeAuditAlarmA
ObjectPrivilegeAuditAlarmW
OpenBackupEventLogA
OpenBackupEventLogW
OpenEventLogA
OpenEventLogW
OpenProcessToken
OpenSCManagerA
OpenSCManagerW
OpenServiceA
OpenServiceW
OpenThreadToken
PrivilegeCheck
PrivilegedServiceAuditAlarmA
PrivilegedServiceAuditAlarmW
QueryServiceConfigA
QueryServiceConfigW
QueryServiceLockStatusA
QueryServiceLockStatusW
QueryServiceObjectSecurity
QueryServiceStatus
ReadEventLogA
ReadEventLogW
RegCloseKey
RegConnectRegistryA
RegConnectRegistryW
RegCreateKeyA
RegCreateKeyExA
RegCreateKeyExW
RegCreateKeyW
RegDeleteKeyA
RegDeleteKeyW
RegDeleteValueA
RegDeleteValueW
RegEnumKeyA
RegEnumKeyExA
RegEnumKeyExW
RegEnumKeyW
RegEnumValueA
RegEnumValueW
RegFlushKey
RegGetKeySecurity
RegisterEventSourceA
RegisterEventSourceW
RegisterServiceCtrlHandlerA
RegisterServiceCtrlHandlerW
RegLoadKeyA
RegLoadKeyW
RegNotifyChangeKeyValue
RegOpenKeyA
RegOpenKeyExA
RegOpenKeyExW
RegOpenKeyW
RegQueryInfoKeyA
RegQueryInfoKeyW
RegQueryMultipleValuesA
RegQueryMultipleValuesW
RegQueryValueA
RegQueryValueExA
RegQueryValueExW
RegQueryValueW
RegReplaceKeyA
RegReplaceKeyW
RegRestoreKeyA
RegRestoreKeyW
RegSaveKeyA
RegSaveKeyW
RegSetKeySecurity
RegSetValueA
RegSetValueExA
RegSetValueExW
RegSetValueW
RegUnLoadKeyA
RegUnLoadKeyW
ReportEventA
ReportEventW
RevertToSelf
SetAclInformation
SetFileSecurityA
SetFileSecurityW
SetKernelObjectSecurity
SetPrivateObjectSecurity
SetSecurityDescriptorDacl
SetSecurityDescriptorGroup
SetSecurityDescriptorOwner
SetSecurityDescriptorSacl
SetServiceBits
SetServiceObjectSecurity
SetServiceStatus
SetThreadToken
SetTokenInformation
StartServiceA
StartServiceCtrlDispatcherA
StartServiceCtrlDispatcherW
StartServiceW
UnlockServiceDatabase


Found follow exports in WSOCK32.DLL
accept
bind
closesocket
connect
dn_expand
EnumProtocolsA
EnumProtocolsW
GetAddressByNameA
GetAddressByNameW
gethostbyaddr
gethostbyname
gethostname
GetNameByTypeA
GetNameByTypeW
getpeername
getprotobyname
getprotobynumber
getservbyname
getservbyport
GetServiceA
GetServiceW
getsockname
getsockopt
GetTypeByNameA
GetTypeByNameW
htonl
htons
inet_addr
inet_ntoa
ioctlsocket
listen
NPLoadNameSpaces
ntohl
ntohs
recv
recvfrom
s_perror
select
send
sendto
SetServiceA
SetServiceW
setsockopt
shutdown
socket
TransmitFile
WSAAsyncGetHostByAddr
WSAAsyncGetHostByName
WSAAsyncGetProtoByName
WSAAsyncGetProtoByNumber
WSAAsyncGetServByName
WSAAsyncGetServByPort
WSAAsyncSelect
WSACancelAsyncRequest
WSACancelBlockingCall
WSACleanup
__WSAFDIsSet
WSAGetLastError
WSAIsBlocking
WSARecvEx
WSASetBlockingHook
WSASetLastError
WSAStartup
WSAUnhookBlockingHook


Found follow exports in WS2_32.DLL


Windows 95


Found follow exports in KERNEL32.DLL
AllocLSCallback
AllocSLCallback
Callback12
Callback16
Callback20
Callback24
Callback28
Callback32
Callback36
Callback40
Callback44
Callback48
Callback4
Callback52
Callback56
Callback60
Callback64
Callback8
CloseSystemHandle
ConvertToGlobalHandle
CreateKernelThread
CreateSocketHandle
CreateToolhelp32Snapshot
FT_Exit0
FT_Exit12
FT_Exit16
FT_Exit20
FT_Exit24
FT_Exit28
FT_Exit32
FT_Exit36
FT_Exit4
FT_Exit40
FT_Exit44
FT_Exit48
FT_Exit52
FT_Exit56
FT_Exit8
FT_Prolog
FT_Thunk
FreeLSCallback
FreeSLCallback
GetDaylightFlag
GetErrorMode
GetHandleContext
GetLSCallbackTarget
GetLSCallbackTemplate
GetProcessFlags
GetProductName
GetSLCallbackTarget
GetSLCallbackTemplate
Heap32First
Heap32ListFirst
Heap32ListNext
Heap32Next
HeapSetFlags
InvalidateNLSCache
IsLSCallback
IsSLCallback
K32Thk1632Epilog
K32Thk1632Prolog
MakeCriticalSectionGlobal
MapHInstLS
MapHInstLS_PN
MapHInstSL
MapHInstSL_PN
MapHModuleLS
MapHModuleSL
MapLS
MapSL
MapSLFix
Module32First
Module32Next
NotifyNLSUserCache
OpenVxDHandle
Process32First
Process32Next
QT_Thunk
QueryNumberOfEventLogRecords
QueryOldestEventLogRecord
RegisterServiceProcess
ReinitializeCriticalSection
SMapLS
SMapLS_IP_EBP_12
SMapLS_IP_EBP_16
SMapLS_IP_EBP_20
SMapLS_IP_EBP_24
SMapLS_IP_EBP_28
SMapLS_IP_EBP_32
SMapLS_IP_EBP_36
SMapLS_IP_EBP_40
SMapLS_IP_EBP_8
SUnMapLS
SUnMapLS_IP_EBP_12
SUnMapLS_IP_EBP_16
SUnMapLS_IP_EBP_20
SUnMapLS_IP_EBP_24
SUnMapLS_IP_EBP_28
SUnMapLS_IP_EBP_32
SUnMapLS_IP_EBP_36
SUnMapLS_IP_EBP_40
SUnMapLS_IP_EBP_8
SetDaylightFlag
SetHandleContext
Thread32First
Thread32Next
ThunkConnect32
TlsAllocInternal
TlsFreeInternal
Toolhelp32ReadProcessMemory
UTRegister
UTUnRegister
UnMapLS
UnMapSLFixArray
UninitializeCriticalSection
_DebugOut
_DebugPrintf
dprintf

Found follow exports in NTDLL.DLL
RtlExAllocateHeap
RtlExFreeHeap
RtlExReAllocateHeap
RtlExSizeHeap
RtlGetHandleValueHeap
RtlGrowHeap
RtlSetHandleValueHeap

Found follow exports in USER32.DLL
CalcChildScroll
CharNextExW
CharPrevExW
ClientThreadConnect
GetNextQueueWindow
InitSharedTable
InitTask
IsHungThread
ModifyAccess
PlaySoundEvent
RegisterNetworkCapabilities
SetDesktopBitmap
SetLogonNotifyWindow
SetWindowFullScreenState
SysErrorBox
UserSignalProc
WNDPROC_CALLBACK
WinOldAppHackoMatic
YieldTask

Found follow exports in GDI32.DLL
ByeByeGDI
DeviceCapabilitiesEx
GetFontResourceInfo
SetObjectOwner
UpdateICMRegKey
pfnRealizePalette
pfnSelectPalette

Found follow exports in SHELL32.DLL
CheckEscapesA
Control_FillCache_RunDLL
ExtractIconResInfoA
ExtractIconResInfoW
ExtractVersionResource16W
SheChangeDirExA
SheChangeDirW
SheConvertPathW
SheFullPathA
SheFullPathW
SheGetCurDrive
SheGetDirExW
SheGetDirW
SheGetPathOffsetW
SheRemoveQuotesA
SheRemoveQuotesW
SheShortenPathA
SheShortenPathW
Shl1632_ThunkData32
Shl3216_ThunkData32

Found follow exports in COMDLG32.DLL
WEP

Found follow exports in COMCTL32.DLL
Cctl1632_ThunkData32
DllInstall

Found follow exports in ADVAPI32.DLL
RegRemapPreDefKey

Found follow exports in WSOCK32.DLL
WsControl
closesockinfo
Arecv
Asend
WSHEnumProtocols
inet_network
getnetbyname
rcmd
rexec
rresvport
sethostname

Found follow exports in WS2_32.DLL


Windows 98


Found follow exports in KERNEL32.DLL
AllocLSCallback
AllocSLCallback
Callback12
Callback16
Callback20
Callback24
Callback28
Callback32
Callback36
Callback40
Callback44
Callback48
Callback4
Callback52
Callback56
Callback60
Callback64
Callback8
CancelDeviceWakeupRequest
CancelIo
CancelWaitableTimer
CloseSystemHandle
ConvertThreadToFiber
ConvertToGlobalHandle
CopyFileExA
CopyFileExW
CreateFiber
CreateKernelThread
CreateSocketHandle
CreateToolhelp32Snapshot
CreateWaitableTimerA
CreateWaitableTimerW
DeleteFiber
EnumCalendarInfoExA
EnumCalendarInfoExW
EnumDateFormatsExA
EnumDateFormatsExW
FT_Exit0
FT_Exit12
FT_Exit16
FT_Exit20
FT_Exit24
FT_Exit28
FT_Exit32
FT_Exit36
FT_Exit4
FT_Exit40
FT_Exit44
FT_Exit48
FT_Exit52
FT_Exit56
FT_Exit8
FT_Prolog
FT_Thunk
FindFirstFileExA
FindFirstFileExW
FreeLSCallback
FreeSLCallback
GetCPInfoExA
GetCPInfoExW
GetCalendarInfoA
GetCalendarInfoW
GetDaylightFlag
GetDevicePowerState
GetErrorMode
GetFileAttributesExA
GetFileAttributesExW
GetHandleContext
GetLSCallbackTarget
GetLSCallbackTemplate
GetLongPathNameA
GetLongPathNameW
GetProcessFlags
GetProcessPriorityBoost
GetProductName
GetSLCallbackTarget
GetSLCallbackTemplate
GetThreadPriorityBoost
GetWriteWatch
Heap32First
Heap32ListFirst
Heap32ListNext
Heap32Next
HeapSetFlags
InitializeCriticalSectionAndSpinCount
InterlockedCompareExchange
InterlockedExchangeAdd
InvalidateNLSCache
IsDebuggerPresent
IsLSCallback
IsProcessorFeaturePresent
IsSLCallback
IsSystemResumeAutomatic
K32Thk1632Epilog
K32Thk1632Prolog
K32_NtCreateFile
K32_RtlNtStatusToDosError
QT_Thunk
MakeCriticalSectionGlobal
MapHInstLS
MapHInstLS_PN
MapHInstSL
MapHInstSL_PN
MapHModuleLS
MapHModuleSL
MapLS
MapSL
MapSLFix
Module32First
Module32Next
NotifyNLSUserCache
OpenVxDHandle
OpenWaitableTimerA
OpenWaitableTimerW
Process32First
Process32Next
QueryNumberOfEventLogRecords
QueryOldestEventLogRecord
ReadDirectoryChangesW
ReadFileScatter
RegisterServiceProcess
RegisterSysMsgHandler
ReinitializeCriticalSection
RequestDeviceWakeup
RequestWakeupLatency
ResetNLSUserInfoCache
ResetWriteWatch
SMapLS
SMapLS_IP_EBP_12
SMapLS_IP_EBP_16
SMapLS_IP_EBP_20
SMapLS_IP_EBP_24
SMapLS_IP_EBP_28
SMapLS_IP_EBP_32
SMapLS_IP_EBP_36
SMapLS_IP_EBP_40
SMapLS_IP_EBP_8
SUnMapLS
SUnMapLS_IP_EBP_12
SUnMapLS_IP_EBP_16
SUnMapLS_IP_EBP_20
SUnMapLS_IP_EBP_24
SUnMapLS_IP_EBP_28
SUnMapLS_IP_EBP_32
SUnMapLS_IP_EBP_36
SUnMapLS_IP_EBP_40
SUnMapLS_IP_EBP_8
SetCalendarInfoA
SetCalendarInfoW
SetCriticalSectionSpinCount
SetDaylightFlag
SetHandleContext
SetMessageWaitingIndicator
SetProcessAffinityMask
SetProcessPriorityBoost
SetThreadExecutionState
SetThreadIdealProcessor
SetThreadPriorityBoost
SetWaitableTimer
SignalObjectAndWait
SignalSysMsgHandlers
SwitchToFiber
SwitchToThread
Thread32First
Thread32Next
ThunkConnect32
TlsAllocInternal
TlsFreeInternal
Toolhelp32ReadProcessMemory
TryEnterCriticalSection
UTRegister
UTUnRegister
UnMapLS
UnMapSLFixArray
UninitializeCriticalSection
VirtualAllocEx
VirtualFreeEx
WriteFileGather
_DebugOut
_DebugPrintf
dprintf

Found follow exports in NTDLL.DLL
IoUnregisterDeviceInterface
NtCreateFile
NtGetDevnodeFromFileHandle
NtInitiatePowerAction
NtPowerInformation
NtRequestWakeupLatency
NtSetSystemPowerState
RtlExAllocateHeap
RtlExFreeHeap
RtlExReAllocateHeap
RtlExSizeHeap
RtlGetHandleValueHeap
RtlGrowHeap
RtlNtStatusToDosError
RtlSetHandleValueHeap

Found follow exports in USER32.DLL
AlignRects
AnimateWindow
BlockInput
BroadcastSystemMessageA
BroadcastSystemMessageW
CalcChildScroll
ChangeDisplaySettingsExA
ChangeDisplaySettingsExW
CharNextExW
CharPrevExW
ClientThreadConnect
DrawMenuBarTemp
EndMenu
EnumDisplayDevicesA
EnumDisplayDevicesW
EnumDisplayMonitors
EnumDisplaySettingsExA
EnumDisplaySettingsExW
FlashWindowEx
GetAltTabInfo
GetAncestor
GetClipboardSequenceNumber
GetComboBoxInfo
GetCursorInfo
GetGUIThreadInfo
GetGuiResources
GetListBoxInfo
GetMenuBarInfo
GetMenuInfo
GetMonitorInfoA
GetMonitorInfoW
GetMouseMovePoints
GetNextQueueWindow
GetProcessDefaultLayout
GetScrollBarInfo
GetTitleBarInfo
GetWindowInfo
GetWindowModuleFileNameA
GetWindowModuleFileNameW
HasSystemSleepStarted
IMPGetIMEA
IMPGetIMEW
IMPQueryIMEA
IMPQueryIMEW
IMPSetIMEA
IMPSetIMEW
InSendMessageEx
InitSharedTable
InitTask
IsHungThread
ModifyAccess
MonitorFromPoint
MonitorFromRect
MonitorFromWindow
MsgWaitForMultipleObjectsEx
NotifyWinEvent
PlaySoundEvent
RealChildWindowFromPoint
RealGetWindowClass
RegisterDeviceNotificationA
RegisterDeviceNotificationW
RegisterNetworkCapabilities
SendIMEMessageExA
SendIMEMessageExW
SendInput
SetDesktopBitmap
SetLogonNotifyWindow
SetMenuInfo
SetProcessDefaultLayout
SetWinEventHook
SetWindowFullScreenState
SysErrorBox
ToUnicodeEx
TrackMouseEvent
UnhookWinEvent
UnregisterDeviceNotification
UserIsSystemResumeAutomatic
UserSetDeviceHoldState
UserSignalProc
UserTickleTimer
WINNLSEnableIME
WINNLSGetEnableStatus
WINNLSGetIMEHotkey
WNDPROC_CALLBACK
WinOldAppHackoMatic
YieldTask

Found follow exports in GDI32.DLL
ByeByeGDI
ColorCorrectPalette
DeviceCapabilitiesEx
EnableEUDC
GetFontResourceInfo
GetLayout
SetLayout
SetMagicColors
SetObjectOwner
pfnRealizePalette
pfnSelectPalette

Found follow exports in SHELL32.DLL
CheckEscapesA
Control_FillCache_RunDLL
Control_FillCache_RunDLLA
Control_FillCache_RunDLLW
Control_RunDLLA
Control_RunDLLW
DllCanUnloadNow
DllGetVersion
DllInstall
ExtractIconExW
ExtractIconResInfoA
ExtractIconResInfoW
ExtractVersionResource16W
FindExeDlgProc
OpenAs_RunDLLA
OpenAs_RunDLLW
PrintersGetCommand_RunDLLA
PrintersGetCommand_RunDLLW
SHBrowseForFolderW
SheChangeDirExA
SheChangeDirW
SheConvertPathW
SheFullPathA
SheFullPathW
SheGetCurDrive
SheGetDirExW
SheGetDirW
SheGetPathOffsetW
Shell_NotifyIconW
ShellExecuteExW
ShellHookProc
SHEmptyRecycleBinA
SHEmptyRecycleBinW
SheRemoveQuotesA
SheRemoveQuotesW
SheShortenPathA
SheShortenPathW
SHExitWindowsEx
SHFileOperationW
SHGetDataFromIDListW
SHGetDiskFreeSpaceA
SHGetFileInfoW
SHGetNewLinkInfo
SHGetPathFromIDListW
SHGetSettings
SHGetSpecialFolderPathA
SHGetSpecialFolderPathW
SHHelpShortcuts_RunDLLA
SHHelpShortcuts_RunDLLW
SHInvokePrinterCommandA
SHInvokePrinterCommandW
SHQueryRecycleBinA
SHQueryRecycleBinW
SHUpdateRecycleBinIcon

Found follow exports in COMDLG32.DLL
dwLBSubclass
dwOKSubclass
LoadAlterBitmap
WantArrows

Found follow exports in COMCTL32.DLL
Cctl1632_ThunkData32
DllInstall
ImageList_GetFlags

Found follow exports in ADVAPI32.DLL
BuildExplicitAccessWithNameA
BuildExplicitAccessWithNameW
BuildImpersonateExplicitAccessWithNameA
BuildImpersonateExplicitAccessWithNameW
BuildImpersonateTrusteeA
BuildImpersonateTrusteeW
BuildSecurityDescriptorA
BuildSecurityDescriptorW
BuildTrusteeWithNameA
BuildTrusteeWithNameW
BuildTrusteeWithSidA
BuildTrusteeWithSidW
CancelOverlappedAccess
ConvertAccessToSecurityDescriptorA
ConvertAccessToSecurityDescriptorW
ConvertSecurityDescriptorToAccessA
ConvertSecurityDescriptorToAccessNamedA
ConvertSecurityDescriptorToAccessNamedW
ConvertSecurityDescriptorToAccessW
CryptAcquireContextW
CryptContextAddRef
CryptDuplicateHash
CryptDuplicateKey
CryptEnumProviderTypesA
CryptEnumProviderTypesW
CryptEnumProvidersA
CryptEnumProvidersW
CryptGetDefaultProviderA
CryptGetDefaultProviderW
CryptSetProviderExA
CryptSetProviderExW
CryptSetProviderW
CryptSignHashW
CryptVerifySignatureW
DuplicateTokenEx
GetAccessPermissionsForObjectA
GetAccessPermissionsForObjectW
GetAuditedPermissionsFromAclA
GetAuditedPermissionsFromAclW
GetCurrentHwProfileA
GetCurrentHwProfileW
GetEffectiveRightsFromAclA
GetEffectiveRightsFromAclW
GetExplicitEntriesFromAclA
GetExplicitEntriesFromAclW
GetMultipleTrusteeA
GetMultipleTrusteeOperationA
GetMultipleTrusteeOperationW
GetMultipleTrusteeW
GetNamedSecurityInfoA
GetNamedSecurityInfoExA
GetNamedSecurityInfoExW
GetNamedSecurityInfoW
GetOverlappedAccessResults
GetSecurityInfo
GetSecurityInfoExA
GetSecurityInfoExW
GetTrusteeNameA
GetTrusteeNameW
GetTrusteeTypeA
GetTrusteeTypeW
LookupSecurityDescriptorPartsA
LookupSecurityDescriptorPartsW
ObjectDeleteAuditAlarmA
ObjectDeleteAuditAlarmW
RegRemapPreDefKey
SetEntriesInAccessListA
SetEntriesInAccessListW
SetEntriesInAclA
SetEntriesInAclW
SetEntriesInAuditListA
SetEntriesInAuditListW
SetNamedSecurityInfoA
SetNamedSecurityInfoExA
SetNamedSecurityInfoExW
SetNamedSecurityInfoW
SetSecurityInfo
SetSecurityInfoExA
SetSecurityInfoExW
TrusteeAccessToObjectA
TrusteeAccessToObjectW

Found follow exports in WSOCK32.DLL
MigrateWinsockConfiguration
WEP
WSApSetPostRoutine
WsControl
closesockinfo
Arecv
Asend
WSHEnumProtocols
inet_network
getnetbyname
rcmd
rexec
rresvport
sethostname
NSPStartup
AcceptEx
GetAcceptExSockaddrs

Found follow exports in WS2_32.DLL
accept
bind
closesocket
connect
getpeername
getsockname
getsockopt
htonl
htons
ioctlsocket
inet_addr
inet_ntoa
listen
ntohl
ntohs
recv
recvfrom
select
send
sendto
setsockopt
shutdown
socket
WSApSetPostRoutine
WPUCompleteOverlappedRequest
WSAAccept
WSAAddressToStringA
WSAAddressToStringW
WSACloseEvent
WSAConnect
WSACreateEvent
WSADuplicateSocketA
WSADuplicateSocketW
WSAEnumNameSpaceProvidersA
WSAEnumNameSpaceProvidersW
WSAEnumNetworkEvents
WSAEnumProtocolsA
WSAEnumProtocolsW
WSAEventSelect
WSAGetOverlappedResult
WSAGetQOSByName
WSAGetServiceClassInfoA
WSAGetServiceClassInfoW
WSAGetServiceClassNameByClassIdA
WSAGetServiceClassNameByClassIdW
WSAHtonl
WSAHtons
WSAInstallServiceClassA
WSAInstallServiceClassW
WSAIoctl
gethostbyaddr
gethostbyname
getprotobyname
getprotobynumber
getservbyname
getservbyport
gethostname
WSAJoinLeaf
WSALookupServiceBeginA
WSALookupServiceBeginW
WSALookupServiceEnd
WSALookupServiceNextA
WSALookupServiceNextW
WSANtohl
WSANtohs
WSAProviderConfigChange
WSARecv
WSARecvDisconnect
WSARecvFrom
WSARemoveServiceClass
WSAResetEvent
WSASend
WSASendDisconnect
WSASendTo
WSASetEvent
WSASetServiceA
WSASetServiceW
WSASocketA
WSASocketW
WSAStringToAddressA
WSAStringToAddressW
WSAWaitForMultipleEvents
WSCDeinstallProvider
WSCEnableNSProvider
WSCEnumProtocols
WSCGetProviderPath
WSCInstallNameSpace
WSCInstallProvider
WSCUnInstallNameSpace
WSAAsyncSelect
WSAAsyncGetHostByAddr
WSAAsyncGetHostByName
WSAAsyncGetProtoByNumber
WSAAsyncGetProtoByName
WSAAsyncGetServByPort
WSAAsyncGetServByName
WSACancelAsyncRequest
WSASetBlockingHook
WSAUnhookBlockingHook
WSAGetLastError
WSASetLastError
WSACancelBlockingCall
WSAIsBlocking
WSAStartup
WSACleanup
__WSAFDIsSet
WEP

Windows ME


Found follow exports in KERNEL32.DLL
AllocLSCallback
AllocSLCallback
Callback12
Callback16
Callback20
Callback24
Callback28
Callback32
Callback36
Callback40
Callback44
Callback48
Callback4
Callback52
Callback56
Callback60
Callback64
Callback8
CancelDeviceWakeupRequest
CancelIo
CancelWaitableTimer
CloseSystemHandle
ConvertThreadToFiber
ConvertToGlobalHandle
CopyFileExA
CopyFileExW
CreateFiber
CreateKernelThread
CreateSocketHandle
CreateToolhelp32Snapshot
CreateWaitableTimerA
CreateWaitableTimerW
DeleteFiber
EnumCalendarInfoExA
EnumCalendarInfoExW
EnumDateFormatsExA
EnumDateFormatsExW
EnumLanguageGroupLocalesA
EnumLanguageGroupLocalesW
EnumSystemGeoID
EnumSystemLanguageGroupsA
EnumSystemLanguageGroupsW
EnumUILanguagesA
EnumUILanguagesW
FT_Exit0
FT_Exit12
FT_Exit16
FT_Exit20
FT_Exit24
FT_Exit28
FT_Exit32
FT_Exit36
FT_Exit4
FT_Exit40
FT_Exit44
FT_Exit48
FT_Exit52
FT_Exit56
FT_Exit8
FT_Prolog
FT_Thunk
FindFirstFileExA
FindFirstFileExW
FreeLSCallback
FreeSLCallback
GetCPInfoExA
GetCPInfoExW
GetCalendarInfoA
GetCalendarInfoW
GetDaylightFlag
GetDevicePowerState
GetErrorMode
GetFileAttributesExA
GetFileAttributesExW
GetGeoInfoA
GetGeoInfoW
GetHandleContext
GetLSCallbackTarget
GetLSCallbackTemplate
GetLongPathNameA
GetLongPathNameW
GetProcessFlags
GetProcessPriorityBoost
GetProductName
GetSLCallbackTarget
GetSLCallbackTemplate
GetSystemDefaultUILanguage
GetThreadPriorityBoost
GetUserDefaultUILanguage
GetUserGeoID
GetWriteWatch
Heap32First
Heap32ListFirst
Heap32ListNext
Heap32Next
HeapSetFlags
InitializeCriticalSectionAndSpinCount
InterlockedCompareExchange
InterlockedExchangeAdd
InvalidateNLSCache
IsDebuggerPresent
IsLSCallback
IsProcessorFeaturePresent
IsSLCallback
IsSystemResumeAutomatic
IsValidLanguageGroup
QT_Thunk
K32Thk1632Epilog
K32Thk1632Prolog
K32_NtCreateFile
K32_RtlNtStatusToDosError
MakeCriticalSectionGlobal
MapHInstLS
MapHInstLS_PN
MapHInstSL
MapHInstSL_PN
MapHModuleLS
MapHModuleSL
MapLS
MapSL
MapSLFix
Module32First
Module32Next
NotifyNLSUserCache
OpenThread
OpenVxDHandle
OpenWaitableTimerA
OpenWaitableTimerW
Process32First
Process32Next
QueryNumberOfEventLogRecords
QueryOldestEventLogRecord
ReadDirectoryChangesW
ReadFileScatter
RegisterServiceProcess
RegisterSysMsgHandler
ReinitializeCriticalSection
RequestDeviceWakeup
RequestWakeupLatency
ResetNLSUserInfoCache
ResetWriteWatch
SMapLS
SMapLS_IP_EBP_12
SMapLS_IP_EBP_16
SMapLS_IP_EBP_20
SMapLS_IP_EBP_24
SMapLS_IP_EBP_28
SMapLS_IP_EBP_32
SMapLS_IP_EBP_36
SMapLS_IP_EBP_40
SMapLS_IP_EBP_8
SUnMapLS
SUnMapLS_IP_EBP_12
SUnMapLS_IP_EBP_16
SUnMapLS_IP_EBP_20
SUnMapLS_IP_EBP_24
SUnMapLS_IP_EBP_28
SUnMapLS_IP_EBP_32
SUnMapLS_IP_EBP_36
SUnMapLS_IP_EBP_40
SUnMapLS_IP_EBP_8
SetCalendarInfoA
SetCalendarInfoW
SetCriticalSectionSpinCount
SetDaylightFlag
SetHandleContext
SetMessageWaitingIndicator
SetProcessAffinityMask
SetProcessPriorityBoost
SetThreadExecutionState
SetThreadIdealProcessor
SetThreadPriorityBoost
SetUserGeoID
SetWaitableTimer
SignalObjectAndWait
SignalSysMsgHandlers
SwitchToFiber
SwitchToThread
Thread32First
Thread32Next
ThunkConnect32
TlsAllocInternal
TlsFreeInternal
Toolhelp32ReadProcessMemory
TryEnterCriticalSection
UTRegister
UTUnRegister
UnMapLS
UnMapSLFixArray
UninitializeCriticalSection
VirtualAllocEx
VirtualFreeEx
WriteFileGather
_DebugOut
_DebugPrintf
dprintf

Found follow exports in NTDLL.DLL
IoUnregisterDeviceInterface
NtCreateFile
NtGetDevnodeFromFileHandle
NtInitiatePowerAction
NtPowerInformation
NtRequestWakeupLatency
NtSetSystemPowerState
RtlExAllocateHeap
RtlExFreeHeap
RtlExReAllocateHeap
RtlExSizeHeap
RtlGetHandleValueHeap
RtlGrowHeap
RtlNtStatusToDosError
RtlSetHandleValueHeap

Found follow exports in USER32.DLL
AlignRects
AllowSetForegroundWindow
AnimateWindow
BlockInput
BroadcastSystemMessageA
BroadcastSystemMessageW
CalcChildScroll
ChangeDisplaySettingsExA
ChangeDisplaySettingsExW
CharNextExW
CharPrevExW
ClientThreadConnect
DrawMenuBarTemp
EndMenu
EnumDisplayDevicesA
EnumDisplayDevicesW
EnumDisplayMonitors
EnumDisplaySettingsExA
EnumDisplaySettingsExW
FlashWindowEx
GetAltTabInfo
GetAncestor
GetClipboardSequenceNumber
GetComboBoxInfo
GetCursorInfo
GetGUIThreadInfo
GetGuiResources
GetListBoxInfo
GetMenuBarInfo
GetMenuInfo
GetMonitorInfoA
GetMonitorInfoW
GetMouseMovePoints
GetMouseMovePointsEx
GetNextQueueWindow
GetProcessDefaultLayout
GetScrollBarInfo
GetTitleBarInfo
GetWindowInfo
GetWindowModuleFileNameA
GetWindowModuleFileNameW
HasSystemSleepStarted
IMPGetIMEA
IMPGetIMEW
IMPQueryIMEA
IMPQueryIMEW
IMPSetIMEA
IMPSetIMEW
InSendMessageEx
InitSharedTable
InitTask
IsHungThread
LockSetForegroundWindow
ModifyAccess
MonitorFromPoint
MonitorFromRect
MonitorFromWindow
MsgWaitForMultipleObjectsEx
NotifyWinEvent
PlaySoundEvent
RealChildWindowFromPoint
RealGetWindowClass
RegisterDeviceNotificationA
RegisterDeviceNotificationW
RegisterNetworkCapabilities
SendIMEMessageExA
SendIMEMessageExW
SendInput
SetDesktopBitmap
SetLogonNotifyWindow
SetMenuInfo
SetProcessDefaultLayout
SetWinEventHook
SetWindowFullScreenState
SysErrorBox
ToUnicodeEx
TrackMouseEvent
UnhookWinEvent
UnregisterDeviceNotification
UserIsSystemResumeAutomatic
UserSetDeviceHoldState
UserSignalProc
UserTickleTimer
WINNLSEnableIME
WINNLSGetEnableStatus
WINNLSGetIMEHotkey
WNDPROC_CALLBACK
WinOldAppHackoMatic
YieldTask
_SetProcessDefaultLayout

Found follow exports in GDI32.DLL
ByeByeGDI
ColorCorrectPalette
DeviceCapabilitiesEx
EnableEUDC
GetFontResourceInfo
GetLayout
SetLayout
SetMagicColors
SetObjectOwner
pfnRealizePalette
pfnSelectPalette

Found follow exports in SHELL32.DLL
CheckEscapesA
Control_FillCache_RunDLL
Control_FillCache_RunDLLA
Control_FillCache_RunDLLW
Control_RunDLLA
Control_RunDLLW
DllCanUnloadNow
DllGetVersion
DllInstall
DllRegisterServer
DllUnregisterServer
ExtractIconExW
ExtractIconResInfoA
ExtractIconResInfoW
ExtractVersionResource16W
FindExeDlgProc
OpenAs_RunDLLA
OpenAs_RunDLLW
Options_RunDLL
Options_RunDLLA
Options_RunDLLW
PrintersGetCommand_RunDLLA
PrintersGetCommand_RunDLLW
SHBindToParent
SHBrowseForFolderW
SHChangeNotifySuspendResume
SHCreateDirectoryExA
SHCreateDirectoryExW
SHCreateLocalServerRunDll
SheChangeDirExA
SheChangeDirW
SheConvertPathW
SheFullPathA
SheFullPathW
SheGetCurDrive
SheGetDirExW
SheGetDirW
SheGetPathOffsetW
Shell_NotifyIconW
ShellExec_RunDLL
ShellExec_RunDLLA
ShellExec_RunDLLW
ShellExecuteExW
ShellHookProc
SHEmptyRecycleBinA
SHEmptyRecycleBinW
SheRemoveQuotesA
SheRemoveQuotesW
SheShortenPathA
SheShortenPathW
SHExitWindowsEx
SHExtractIconsW
SHFileOperationW
SHGetDataFromIDListW
SHGetDiskFreeSpaceA
SHGetDiskFreeSpaceExA
SHGetDiskFreeSpaceExW
SHGetFileInfoW
SHGetFolderLocation
SHGetFolderPathA
SHGetFolderPathW
SHGetIconOverlayIndexA
SHGetIconOverlayIndexW
SHGetNewLinkInfo
SHGetNewLinkInfoA
SHGetNewLinkInfoW
SHGetPathFromIDListW
SHGetSettings
SHGetSpecialFolderPathA
SHGetSpecialFolderPathW
SHHelpShortcuts_RunDLLA
SHHelpShortcuts_RunDLLW
SHInvokePrinterCommandA
SHInvokePrinterCommandW
SHIsFileAvailableOffline
SHLoadNonloadedIconOverlayIdentifiers
SHOpenFolderAndSelectItems
SHPathPrepareForWriteA
SHPathPrepareForWriteW
SHQueryRecycleBinA
SHQueryRecycleBinW
SHUpdateRecycleBinIcon

Found follow exports in COMDLG32.DLL
dwLBSubclass
dwOKSubclass
LoadAlterBitmap
PrintDlgExA
PrintDlgExW
WantArrows

Found follow exports in COMCTL32.DLL
Cctl1632_ThunkData32
DllInstall
ImageList_GetFlags

Found follow exports in ADVAPI32.DLL
BuildExplicitAccessWithNameA
BuildExplicitAccessWithNameW
BuildImpersonateExplicitAccessWithNameA
BuildImpersonateExplicitAccessWithNameW
BuildImpersonateTrusteeA
BuildImpersonateTrusteeW
BuildSecurityDescriptorA
BuildSecurityDescriptorW
BuildTrusteeWithNameA
BuildTrusteeWithNameW
BuildTrusteeWithSidA
BuildTrusteeWithSidW
CancelOverlappedAccess
ConvertAccessToSecurityDescriptorA
ConvertAccessToSecurityDescriptorW
ConvertSecurityDescriptorToAccessA
ConvertSecurityDescriptorToAccessNamedA
ConvertSecurityDescriptorToAccessNamedW
ConvertSecurityDescriptorToAccessW
CryptAcquireContextW
CryptContextAddRef
CryptDuplicateHash
CryptDuplicateKey
CryptEnumProviderTypesA
CryptEnumProviderTypesW
CryptEnumProvidersA
CryptEnumProvidersW
CryptGetDefaultProviderA
CryptGetDefaultProviderW
CryptGetLocalKeyLimits
CryptSetProviderExA
CryptSetProviderExW
CryptSetProviderW
CryptSignHashW
CryptVerifySignatureW
DuplicateTokenEx
GetAccessPermissionsForObjectA
GetAccessPermissionsForObjectW
GetAuditedPermissionsFromAclA
GetAuditedPermissionsFromAclW
GetCurrentHwProfileA
GetCurrentHwProfileW
GetEffectiveRightsFromAclA
GetEffectiveRightsFromAclW
GetExplicitEntriesFromAclA
GetExplicitEntriesFromAclW
GetMultipleTrusteeA
GetMultipleTrusteeOperationA
GetMultipleTrusteeOperationW
GetMultipleTrusteeW
GetNamedSecurityInfoA
GetNamedSecurityInfoExA
GetNamedSecurityInfoExW
GetNamedSecurityInfoW
GetOverlappedAccessResults
GetSecurityInfo
GetSecurityInfoExA
GetSecurityInfoExW
GetTrusteeNameA
GetTrusteeNameW
GetTrusteeTypeA
GetTrusteeTypeW
LookupSecurityDescriptorPartsA
LookupSecurityDescriptorPartsW
ObjectDeleteAuditAlarmA
ObjectDeleteAuditAlarmW
RegRemapPreDefKey
SetEntriesInAccessListA
SetEntriesInAccessListW
SetEntriesInAclA
SetEntriesInAclW
SetEntriesInAuditListA
SetEntriesInAuditListW
SetNamedSecurityInfoA
SetNamedSecurityInfoExA
SetNamedSecurityInfoExW
SetNamedSecurityInfoW
SetSecurityInfo
SetSecurityInfoExA
SetSecurityInfoExW
TrusteeAccessToObjectA
TrusteeAccessToObjectW

Found follow exports in WSOCK32.DLL
MigrateWinsockConfiguration
WEP
WSApSetPostRoutine
WsControl
closesockinfo
Arecv
Asend
WSHEnumProtocols
inet_network
getnetbyname
rcmd
rexec
rresvport
sethostname
NSPStartup
AcceptEx
GetAcceptExSockaddrs

Found follow exports in WS2_32.DLL
accept
bind
closesocket
connect
getpeername
getsockname
getsockopt
htonl
htons
ioctlsocket
inet_addr
inet_ntoa
listen
ntohl
ntohs
recv
recvfrom
select
send
sendto
setsockopt
shutdown
socket
WSApSetPostRoutine
WPUCompleteOverlappedRequest
WSAAccept
WSAAddressToStringA
WSAAddressToStringW
WSACloseEvent
WSAConnect
WSACreateEvent
WSADuplicateSocketA
WSADuplicateSocketW
WSAEnumNameSpaceProvidersA
WSAEnumNameSpaceProvidersW
WSAEnumNetworkEvents
WSAEnumProtocolsA
WSAEnumProtocolsW
WSAEventSelect
WSAGetOverlappedResult
WSAGetQOSByName
WSAGetServiceClassInfoA
WSAGetServiceClassInfoW
WSAGetServiceClassNameByClassIdA
WSAGetServiceClassNameByClassIdW
WSAHtonl
WSAHtons
WSAInstallServiceClassA
WSAInstallServiceClassW
WSAIoctl
gethostbyaddr
gethostbyname
getprotobyname
getprotobynumber
getservbyname
getservbyport
gethostname
WSAJoinLeaf
WSALookupServiceBeginA
WSALookupServiceBeginW
WSALookupServiceEnd
WSALookupServiceNextA
WSALookupServiceNextW
WSANtohl
WSANtohs
WSAProviderConfigChange
WSARecv
WSARecvDisconnect
WSARecvFrom
WSARemoveServiceClass
WSAResetEvent
WSASend
WSASendDisconnect
WSASendTo
WSASetEvent
WSASetServiceA
WSASetServiceW
WSASocketA
WSASocketW
WSAStringToAddressA
WSAStringToAddressW
WSAWaitForMultipleEvents
WSCDeinstallProvider
WSCEnableNSProvider
WSCEnumProtocols
WSCGetProviderPath
WSCInstallNameSpace
WSCInstallProvider
WSCUnInstallNameSpace
WSAAsyncSelect
WSAAsyncGetHostByAddr
WSAAsyncGetHostByName
WSAAsyncGetProtoByNumber
WSAAsyncGetProtoByName
WSAAsyncGetServByPort
WSAAsyncGetServByName
WSACancelAsyncRequest
WSASetBlockingHook
WSAUnhookBlockingHook
WSAGetLastError
WSASetLastError
WSACancelBlockingCall
WSAIsBlocking
WSAStartup
WSACleanup
__WSAFDIsSet
WEP

Windows NT


Found follow exports in KERNEL32.DLL
AddConsoleAliasA
AddConsoleAliasW
BaseAttachCompleteThunk
CancelIo
CancelWaitableTimer
CloseConsoleHandle
CmdBatNotification
ConsoleMenuControl
ConvertThreadToFiber
CopyFileExA
CopyFileExW
CreateFiber
CreateVirtualBuffer
CreateWaitableTimerA
CreateWaitableTimerW
DeleteFiber
DuplicateConsoleHandle
ExitVDM
ExpungeConsoleCommandHistoryA
ExpungeConsoleCommandHistoryW
ExtendVirtualBuffer
FindFirstFileExA
FindFirstFileExW
FreeVirtualBuffer
GetConsoleAliasA
GetConsoleAliasExesA
GetConsoleAliasExesLengthA
GetConsoleAliasExesLengthW
GetConsoleAliasExesW
GetConsoleAliasW
GetConsoleAliasesA
GetConsoleAliasesLengthA
GetConsoleAliasesLengthW
GetConsoleAliasesW
GetConsoleCommandHistoryA
GetConsoleCommandHistoryLengthA
GetConsoleCommandHistoryLengthW
GetConsoleCommandHistoryW
GetConsoleDisplayMode
GetConsoleFontInfo
GetConsoleFontSize
GetConsoleHardwareState
GetConsoleInputExeNameA
GetConsoleInputExeNameW
GetConsoleInputWaitHandle
GetConsoleKeyboardLayoutNameA
GetConsoleKeyboardLayoutNameW
GetCurrentConsoleFont
GetFileAttributesExA
GetFileAttributesExW
GetNextVDMCommand
GetNumberOfConsoleFonts
GetProcessPriorityBoost
GetThreadPriorityBoost
GetVDMCurrentDirectories
HeapCreateTagsW
HeapExtend
HeapQueryTagW
HeapSummary
HeapUsage
InitializeCriticalSectionAndSpinCount
InterlockedCompareExchange
InterlockedExchangeAdd
InvalidateConsoleDIBits
IsDebuggerPresent
IsProcessorFeaturePresent
OpenConsoleW
OpenWaitableTimerA
OpenWaitableTimerW
QueryWin31IniFilesMappedToRegistry
ReadConsoleInputExA
ReadConsoleInputExW
ReadDirectoryChangesW
ReadFileScatter
RegisterConsoleVDM
RegisterWaitForInputIdle
RegisterWowBaseHandlers
RegisterWowExec
SetConsoleCommandHistoryMode
SetConsoleCursor
SetConsoleDisplayMode
SetConsoleFont
SetConsoleHardwareState
SetConsoleIcon
SetConsoleInputExeNameA
SetConsoleInputExeNameW
SetConsoleKeyShortcuts
SetConsoleMaximumWindowSize
SetConsoleMenuClose
SetConsoleNumberOfCommandsA
SetConsoleNumberOfCommandsW
SetConsolePalette
SetCriticalSectionSpinCount
SetLastConsoleEventActive
SetProcessAffinityMask
SetProcessPriorityBoost
SetThreadIdealProcessor
SetThreadPriorityBoost
SetVDMCurrentDirectories
SetWaitableTimer
ShowConsoleCursor
SignalObjectAndWait
SwitchToFiber
SwitchToThread
TrimVirtualBuffer
TryEnterCriticalSection
VDMConsoleOperation
VDMOperationStarted
VerifyConsoleIoHandle
VerifyVersionInfoA
VerifyVersionInfoW
VirtualAllocEx
VirtualBufferExceptionHandler
VirtualFreeEx
WriteConsoleInputVDMA
WriteConsoleInputVDMW
WriteFileGather

Found follow exports in NTDLL.DLL
?Allocate@CBufferAllocator@@UAEPAXK@Z
PropertyLengthAsVariant
RtlCompareVariants
RtlConvertPropertyToVariant
RtlConvertVariantToProperty
CsrAllocateCaptureBuffer
CsrAllocateCapturePointer
CsrAllocateMessagePointer
CsrCaptureMessageBuffer
CsrCaptureMessageString
CsrCaptureTimeout
CsrClientCallServer
CsrClientConnectToServer
CsrFreeCaptureBuffer
CsrIdentifyAlertableThread
CsrNewThread
CsrProbeForRead
CsrProbeForWrite
CsrSetPriorityClass
DbgSsHandleKmApiMsg
DbgSsInitialize
DbgUiConnectToDbg
DbgUiContinue
DbgUiWaitStateChange
DbgUserBreakPoint
KiRaiseUserExceptionDispatcher
KiUserApcDispatcher
KiUserCallbackDispatcher
KiUserExceptionDispatcher
LdrAccessResource
LdrDisableThreadCalloutsForDll
LdrEnumResources
LdrFindEntryForAddress
LdrFindResourceDirectory_U
LdrFindResource_U
LdrGetDllHandle
LdrGetProcedureAddress
LdrInitializeThunk
LdrLoadDll
LdrProcessRelocationBlock
LdrQueryImageFileExecutionOptions
LdrQueryProcessModuleInformation
LdrShutdownProcess
LdrShutdownThread
LdrUnloadDll
LdrVerifyImageMatchesChecksum
NPXEMULATORTABLE
NlsAnsiCodePage
NlsMbCodePageTag
NlsMbOemCodePageTag
NtAcceptConnectPort
NtAccessCheck
NtAccessCheckAndAuditAlarm
NtAddAtom
NtAdjustGroupsToken
NtAdjustPrivilegesToken
NtAlertResumeThread
NtAlertThread
NtAllocateLocallyUniqueId
NtAllocateUuids
NtAllocateVirtualMemory
NtCallbackReturn
NtCancelIoFile
NtCancelTimer
NtClearEvent
NtClose
NtCloseObjectAuditAlarm
NtCompleteConnectPort
NtConnectPort
NtContinue
NtCreateChannel
NtCreateDirectoryObject
NtCreateEvent
NtCreateEventPair
NtCreateFile
NtCreateIoCompletion
NtCreateKey
NtCreateMailslotFile
NtCreateMutant
NtCreateNamedPipeFile
NtCreatePagingFile
NtCreatePort
NtCreateProcess
NtCreateProfile
NtCreateSection
NtCreateSemaphore
NtCreateSymbolicLinkObject
NtCreateThread
NtCreateTimer
NtCreateToken
NtDelayExecution
NtDeleteAtom
NtDeleteFile
NtDeleteKey
NtDeleteObjectAuditAlarm
NtDeleteValueKey
NtDeviceIoControlFile
NtDisplayString
NtDuplicateObject
NtDuplicateToken
NtEnumerateKey
NtEnumerateValueKey
NtExtendSection
NtFindAtom
NtFlushBuffersFile
NtFlushInstructionCache
NtFlushKey
NtFlushVirtualMemory
NtFlushWriteBuffer
NtFreeVirtualMemory
NtFsControlFile
NtGetContextThread
NtGetPlugPlayEvent
NtGetTickCount
NtImpersonateClientOfPort
NtImpersonateThread
NtInitializeRegistry
NtListenChannel
NtListenPort
NtLoadDriver
NtLoadKey2
NtLoadKey
NtLockFile
NtLockVirtualMemory
NtMakeTemporaryObject
NtMapViewOfSection
NtNotifyChangeDirectoryFile
NtNotifyChangeKey
NtOpenChannel
NtOpenDirectoryObject
NtOpenEvent
NtOpenEventPair
NtOpenFile
NtOpenIoCompletion
NtOpenKey
NtOpenMutant
NtOpenObjectAuditAlarm
NtOpenProcess
NtOpenProcessToken
NtOpenSection
NtOpenSemaphore
NtOpenSymbolicLinkObject
NtOpenThread
NtOpenThreadToken
NtOpenTimer
NtPlugPlayControl
NtPrivilegeCheck
NtPrivilegeObjectAuditAlarm
NtPrivilegedServiceAuditAlarm
NtProtectVirtualMemory
NtPulseEvent
NtQueryAttributesFile
NtQueryDefaultLocale
NtQueryDirectoryFile
NtQueryDirectoryObject
NtQueryEaFile
NtQueryEvent
NtQueryFullAttributesFile
NtQueryInformationAtom
NtQueryInformationFile
NtQueryInformationPort
NtQueryInformationProcess
NtQueryInformationThread
NtQueryInformationToken
NtQueryIntervalProfile
NtQueryIoCompletion
NtQueryKey
NtQueryMultipleValueKey
NtQueryMutant
NtQueryObject
NtQueryOleDirectoryFile
NtQuerySection
NtQuerySecurityObject
NtQuerySemaphore
NtQuerySymbolicLinkObject
NtQuerySystemEnvironmentValue
NtQuerySystemInformation
NtQuerySystemTime
NtQueryTimer
NtQueryTimerResolution
NtQueryValueKey
NtQueryVirtualMemory
NtQueryVolumeInformationFile
NtQueueApcThread
NtRaiseException
NtRaiseHardError
NtReadFile
NtReadFileScatter
NtReadRequestData
NtReadVirtualMemory
NtRegisterThreadTerminatePort
NtReleaseMutant
NtReleaseSemaphore
NtRemoveIoCompletion
NtReplaceKey
NtReplyPort
NtReplyWaitReceivePort
NtReplyWaitReplyPort
NtReplyWaitSendChannel
NtRequestPort
NtRequestWaitReplyPort
NtResetEvent
NtRestoreKey
NtResumeThread
NtSaveKey
NtSendWaitReplyChannel
NtSetContextChannel
NtSetContextThread
NtSetDefaultHardErrorPort
NtSetDefaultLocale
NtSetEaFile
NtSetEvent
NtSetHighEventPair
NtSetHighWaitLowEventPair
NtSetHighWaitLowThread
NtSetInformationFile
NtSetInformationKey
NtSetInformationObject
NtSetInformationProcess
NtSetInformationThread
NtSetInformationToken
NtSetIntervalProfile
NtSetIoCompletion
NtSetLdtEntries
NtSetLowEventPair
NtSetLowWaitHighEventPair
NtSetLowWaitHighThread
NtSetSecurityObject
NtSetSystemEnvironmentValue
NtSetSystemInformation
NtSetSystemPowerState
NtSetSystemTime
NtSetTimer
NtSetTimerResolution
NtSetValueKey
NtSetVolumeInformationFile
NtShutdownSystem
NtSignalAndWaitForSingleObject
NtStartProfile
NtStopProfile
NtSuspendThread
NtSystemDebugControl
NtTerminateProcess
NtTerminateThread
NtTestAlert
NtUnloadDriver
NtUnloadKey
NtUnlockFile
NtUnlockVirtualMemory
NtUnmapViewOfSection
NtVdmControl
NtWaitForMultipleObjects
NtWaitForSingleObject
NtWaitHighEventPair
NtWaitLowEventPair
NtWriteFile
NtWriteFileGather
NtWriteRequestData
NtWriteVirtualMemory
NtYieldExecution
PfxFindPrefix
PfxInitialize
PfxInsertPrefix
PfxRemovePrefix
RestoreEm87Context
RtlAbortRXact
RtlAbsoluteToSelfRelativeSD
RtlAcquirePebLock
RtlAcquireResourceExclusive
RtlAcquireResourceShared
RtlAddAccessAllowedAce
RtlAddAccessDeniedAce
RtlAddAce
RtlAddActionToRXact
RtlAddAtomToAtomTable
RtlAddAttributeActionToRXact
RtlAddAuditAccessAce
RtlAddCompoundAce
RtlAdjustPrivilege
RtlAllocateAndInitializeSid
RtlAllocateHandle
RtlAnsiCharToUnicodeChar
RtlAnsiStringToUnicodeSize
RtlAppendAsciizToString
RtlAppendStringToString
RtlAppendUnicodeStringToString
RtlAppendUnicodeToString
RtlApplyRXact
RtlApplyRXactNoFlush
RtlAreAllAccessesGranted
RtlAreAnyAccessesGranted
RtlAreBitsClear
RtlAreBitsSet
RtlAssert
RtlCaptureStackBackTrace
RtlCharToInteger
RtlCheckRegistryKey
RtlClearAllBits
RtlClearBits
RtlClosePropertySet
RtlCompactHeap
RtlCompareMemory
RtlCompareMemoryUlong
RtlCompareString
RtlCompareUnicodeString
RtlCompressBuffer
RtlConsoleMultiByteToUnicodeN
RtlConvertExclusiveToShared
RtlConvertSharedToExclusive
RtlConvertSidToUnicodeString
RtlConvertUiListToApiList
RtlCopyLuid
RtlCopyLuidAndAttributesArray
RtlCopySecurityDescriptor
RtlCopySid
RtlCopySidAndAttributesArray
RtlCopyString
RtlCopyUnicodeString
RtlCreateAcl
RtlCreateAndSetSD
RtlCreateAtomTable
RtlCreateEnvironment
RtlCreateProcessParameters
RtlCreatePropertySet
RtlCreateQueryDebugBuffer
RtlCreateRegistryKey
RtlCreateSecurityDescriptor
RtlCreateTagHeap
RtlCreateUnicodeString
RtlCreateUnicodeStringFromAsciiz
RtlCreateUserProcess
RtlCreateUserSecurityObject
RtlCreateUserThread
RtlCustomCPToUnicodeN
RtlCutoverTimeToSystemTime
RtlDeNormalizeProcessParams
RtlDecompressBuffer
RtlDecompressFragment
RtlDelete
RtlDeleteAce
RtlDeleteAtomFromAtomTable
RtlDeleteCriticalSection
RtlDeleteElementGenericTable
RtlDeleteNoSplay
RtlDeleteRegistryValue
RtlDeleteResource
RtlDeleteSecurityObject
RtlDestroyAtomTable
RtlDestroyEnvironment
RtlDestroyHandleTable
RtlDestroyProcessParameters
RtlDestroyQueryDebugBuffer
RtlDetermineDosPathNameType_U
RtlDoesFileExists_U
RtlDosPathNameToNtPathName_U
RtlDosSearchPath_U
RtlDowncaseUnicodeString
RtlDumpResource
RtlEmptyAtomTable
RtlEnterCriticalSection
RtlEnumProcessHeaps
RtlEnumerateGenericTable
RtlEnumerateGenericTableWithoutSplaying
RtlEnumerateProperties
RtlEqualComputerName
RtlEqualDomainName
RtlEqualLuid
RtlEqualPrefixSid
RtlEqualSid
RtlEqualString
RtlEqualUnicodeString
RtlEraseUnicodeString
RtlExpandEnvironmentStrings_U
RtlExtendHeap
RtlFillMemory
RtlFillMemoryUlong
RtlFindClearBits
RtlFindClearBitsAndSet
RtlFindLongestRunClear
RtlFindLongestRunSet
RtlFindMessage
RtlFindSetBits
RtlFindSetBitsAndClear
RtlFirstFreeAce
RtlFlushPropertySet
RtlFormatCurrentUserKeyPath
RtlFormatMessage
RtlFreeAnsiString
RtlFreeHandle
RtlFreeOemString
RtlFreeSid
RtlFreeUnicodeString
RtlFreeUserThreadStack
RtlGenerate8dot3Name
RtlGetAce
RtlGetCallersAddress
RtlGetCompressionWorkSpaceSize
RtlGetControlSecurityDescriptor
RtlGetCurrentDirectory_U
RtlGetDaclSecurityDescriptor
RtlGetElementGenericTable
RtlGetFullPathName_U
RtlGetGroupSecurityDescriptor
RtlGetLongestNtPathLength
RtlGetNtGlobalFlags
RtlGetNtProductType
RtlGetOwnerSecurityDescriptor
RtlGetProcessHeaps
RtlGetSaclSecurityDescriptor
RtlGetUserInfoHeap
RtlGuidToPropertySetName
RtlIdentifierAuthoritySid
RtlImageDirectoryEntryToData
RtlImageRvaToSection
RtlImageRvaToVa
RtlImpersonateSelf
RtlInitAnsiString
RtlInitCodePageTable
RtlInitNlsTables
RtlInitString
RtlInitUnicodeString
RtlInitializeAtomPackage
RtlInitializeBitMap
RtlInitializeContext
RtlInitializeCriticalSection
RtlInitializeCriticalSectionAndSpinCount
RtlInitializeGenericTable
RtlInitializeHandleTable
RtlInitializeRXact
RtlInitializeResource
RtlInitializeSid
RtlInsertElementGenericTable
RtlIntegerToChar
RtlIntegerToUnicodeString
RtlIsDosDeviceName_U
RtlIsGenericTableEmpty
RtlIsNameLegalDOS8Dot3
RtlIsTextUnicode
RtlIsValidHandle
RtlIsValidIndexHandle
RtlLargeIntegerToChar
RtlLeaveCriticalSection
RtlLengthRequiredSid
RtlLengthSecurityDescriptor
RtlLengthSid
RtlLocalTimeToSystemTime
RtlLockHeap
RtlLookupAtomInAtomTable
RtlLookupElementGenericTable
RtlMakeSelfRelativeSD
RtlMapGenericMask
RtlMoveMemory
RtlMultiByteToUnicodeSize
RtlNewInstanceSecurityObject
RtlNewSecurityGrantedAccess
RtlNewSecurityObject
RtlNormalizeProcessParams
RtlNtStatusToDosError
RtlNumberGenericTableElements
RtlNumberOfClearBits
RtlNumberOfSetBits
RtlOemStringToUnicodeSize
RtlOemStringToUnicodeString
RtlOemToUnicodeN
RtlOnMappedStreamEvent
RtlOpenCurrentUser
RtlPcToFileHeader
RtlPinAtomInAtomTable
RtlPrefixString
RtlPrefixUnicodeString
RtlPropertySetNameToGuid
RtlProtectHeap
RtlQueryAtomInAtomTable
RtlQueryEnvironmentVariable_U
RtlQueryInformationAcl
RtlQueryProcessBackTraceInformation
RtlQueryProcessDebugInformation
RtlQueryProcessHeapInformation
RtlQueryProcessLockInformation
RtlQueryProperties
RtlQueryPropertyNames
RtlQueryPropertySet
RtlQueryRegistryValues
RtlQuerySecurityObject
RtlQueryTagHeap
RtlQueryTimeZoneInformation
RtlRaiseException
RtlRaiseStatus
RtlRandom
RtlRealPredecessor
RtlRealSuccessor
RtlReleasePebLock
RtlReleaseResource
RtlRemoteCall
RtlResetRtlTranslations
RtlRunDecodeUnicodeString
RtlRunEncodeUnicodeString
RtlSecondsSince1970ToTime
RtlSecondsSince1980ToTime
RtlSelfRelativeToAbsoluteSD
RtlSetAllBits
RtlSetAttributesSecurityDescriptor
RtlSetBits
RtlSetCriticalSectionSpinCount
RtlSetCurrentDirectory_U
RtlSetCurrentEnvironment
RtlSetDaclSecurityDescriptor
RtlSetEnvironmentVariable
RtlSetGroupSecurityDescriptor
RtlSetInformationAcl
RtlSetOwnerSecurityDescriptor
RtlSetProperties
RtlSetPropertyNames
RtlSetPropertySetClassId
RtlSetSaclSecurityDescriptor
RtlSetSecurityObject
RtlSetTimeZoneInformation
RtlSetUnicodeCallouts
RtlSetUserFlagsHeap
RtlSetUserValueHeap
RtlSplay
RtlStartRXact
RtlSubAuthorityCountSid
RtlSubAuthoritySid
RtlSubtreePredecessor
RtlSubtreeSuccessor
RtlSystemTimeToLocalTime
RtlTimeFieldsToTime
RtlTimeToElapsedTimeFields
RtlTimeToSecondsSince1970
RtlTimeToSecondsSince1980
RtlTimeToTimeFields
RtlTryEnterCriticalSection
RtlUnicodeStringToAnsiSize
RtlUnicodeStringToCountedOemString
RtlUnicodeStringToInteger
RtlUnicodeStringToOemSize
RtlUnicodeStringToOemString
RtlUnicodeToCustomCPN
RtlUnicodeToMultiByteSize
RtlUnicodeToOemN
RtlUniform
RtlUnlockHeap
RtlUpcaseUnicodeChar
RtlUpcaseUnicodeString
RtlUpcaseUnicodeStringToAnsiString
RtlUpcaseUnicodeStringToCountedOemString
RtlUpcaseUnicodeStringToOemString
RtlUpcaseUnicodeToCustomCPN
RtlUpcaseUnicodeToMultiByteN
RtlUpcaseUnicodeToOemN
RtlUpperChar
RtlUpperString
RtlUsageHeap
RtlValidAcl
RtlValidSecurityDescriptor
RtlValidSid
RtlValidateProcessHeaps
RtlWalkHeap
RtlWriteRegistryValue
RtlZeroHeap
RtlZeroMemory
RtlpNtCreateKey
RtlpNtEnumerateSubKey
RtlpNtMakeTemporaryKey
RtlpNtOpenKey
RtlpNtQueryValueKey
RtlpNtSetValueKey
RtlpUnWaitCriticalSection
RtlpWaitForCriticalSection
RtlxAnsiStringToUnicodeSize
RtlxOemStringToUnicodeSize
RtlxUnicodeStringToAnsiSize
RtlxUnicodeStringToOemSize
SaveEm87Context
ZwAcceptConnectPort
ZwAccessCheck
ZwAccessCheckAndAuditAlarm
ZwAddAtom
ZwAdjustGroupsToken
ZwAdjustPrivilegesToken
ZwAlertResumeThread
ZwAlertThread
ZwAllocateLocallyUniqueId
ZwAllocateUuids
ZwAllocateVirtualMemory
ZwCallbackReturn
ZwCancelIoFile
ZwCancelTimer
ZwClearEvent
ZwClose
ZwCloseObjectAuditAlarm
ZwCompleteConnectPort
ZwConnectPort
ZwContinue
ZwCreateChannel
ZwCreateDirectoryObject
ZwCreateEvent
ZwCreateEventPair
ZwCreateFile
ZwCreateIoCompletion
ZwCreateKey
ZwCreateMailslotFile
ZwCreateMutant
ZwCreateNamedPipeFile
ZwCreatePagingFile
ZwCreatePort
ZwCreateProcess
ZwCreateProfile
ZwCreateSection
ZwCreateSemaphore
ZwCreateSymbolicLinkObject
ZwCreateThread
ZwCreateTimer
ZwCreateToken
ZwDelayExecution
ZwDeleteAtom
ZwDeleteFile
ZwDeleteKey
ZwDeleteObjectAuditAlarm
ZwDeleteValueKey
ZwDeviceIoControlFile
ZwDisplayString
ZwDuplicateObject
ZwDuplicateToken
ZwEnumerateKey
ZwEnumerateValueKey
ZwExtendSection
ZwFindAtom
ZwFlushBuffersFile
ZwFlushInstructionCache
ZwFlushKey
ZwFlushVirtualMemory
ZwFlushWriteBuffer
ZwFreeVirtualMemory
ZwFsControlFile
ZwGetContextThread
ZwGetPlugPlayEvent
ZwGetTickCount
ZwImpersonateClientOfPort
ZwImpersonateThread
ZwInitializeRegistry
ZwListenChannel
ZwListenPort
ZwLoadDriver
ZwLoadKey2
ZwLoadKey
ZwLockFile
ZwLockVirtualMemory
ZwMakeTemporaryObject
ZwMapViewOfSection
ZwNotifyChangeDirectoryFile
ZwNotifyChangeKey
ZwOpenChannel
ZwOpenDirectoryObject
ZwOpenEvent
ZwOpenEventPair
ZwOpenFile
ZwOpenIoCompletion
ZwOpenKey
ZwOpenMutant
ZwOpenObjectAuditAlarm
ZwOpenProcess
ZwOpenProcessToken
ZwOpenSection
ZwOpenSemaphore
ZwOpenSymbolicLinkObject
ZwOpenThread
ZwOpenThreadToken
ZwOpenTimer
ZwPlugPlayControl
ZwPrivilegeCheck
ZwPrivilegeObjectAuditAlarm
ZwPrivilegedServiceAuditAlarm
ZwProtectVirtualMemory
ZwPulseEvent
ZwQueryAttributesFile
ZwQueryDefaultLocale
ZwQueryDirectoryFile
ZwQueryDirectoryObject
ZwQueryEaFile
ZwQueryEvent
ZwQueryFullAttributesFile
ZwQueryInformationAtom
ZwQueryInformationFile
ZwQueryInformationPort
ZwQueryInformationProcess
ZwQueryInformationThread
ZwQueryInformationToken
ZwQueryIntervalProfile
ZwQueryIoCompletion
ZwQueryKey
ZwQueryMultipleValueKey
ZwQueryMutant
ZwQueryObject
ZwQueryOleDirectoryFile
ZwQueryPerformanceCounter
ZwQuerySection
ZwQuerySecurityObject
ZwQuerySemaphore
ZwQuerySymbolicLinkObject
ZwQuerySystemEnvironmentValue
ZwQuerySystemInformation
ZwQuerySystemTime
ZwQueryTimer
ZwQueryTimerResolution
ZwQueryValueKey
ZwQueryVirtualMemory
ZwQueryVolumeInformationFile
ZwQueueApcThread
ZwRaiseException
ZwRaiseHardError
ZwReadFile
ZwReadFileScatter
ZwReadRequestData
ZwReadVirtualMemory
ZwRegisterThreadTerminatePort
ZwReleaseMutant
ZwReleaseSemaphore
ZwRemoveIoCompletion
ZwReplaceKey
ZwReplyPort
ZwReplyWaitReceivePort
ZwReplyWaitReplyPort
ZwReplyWaitSendChannel
ZwRequestPort
ZwRequestWaitReplyPort
ZwResetEvent
ZwRestoreKey
ZwResumeThread
ZwSaveKey
ZwSendWaitReplyChannel
ZwSetContextChannel
ZwSetContextThread
ZwSetDefaultHardErrorPort
ZwSetDefaultLocale
ZwSetEaFile
ZwSetEvent
ZwSetHighEventPair
ZwSetHighWaitLowEventPair
ZwSetHighWaitLowThread
ZwSetInformationFile
ZwSetInformationKey
ZwSetInformationObject
ZwSetInformationProcess
ZwSetInformationThread
ZwSetInformationToken
ZwSetIntervalProfile
ZwSetIoCompletion
ZwSetLdtEntries
ZwSetLowEventPair
ZwSetLowWaitHighEventPair
ZwSetLowWaitHighThread
ZwSetSecurityObject
ZwSetSystemEnvironmentValue
ZwSetSystemInformation
ZwSetSystemPowerState
ZwSetSystemTime
ZwSetTimer
ZwSetTimerResolution
ZwSetValueKey
ZwSetVolumeInformationFile
ZwShutdownSystem
ZwSignalAndWaitForSingleObject
ZwStartProfile
ZwStopProfile
ZwSuspendThread
ZwSystemDebugControl
ZwTerminateProcess
ZwTerminateThread
ZwTestAlert
ZwUnloadDriver
ZwUnloadKey
ZwUnlockFile
ZwUnlockVirtualMemory
ZwUnmapViewOfSection
ZwVdmControl
ZwWaitForMultipleObjects
ZwWaitForSingleObject
ZwWaitHighEventPair
ZwWaitLowEventPair
ZwWriteFile
ZwWriteFileGather
ZwWriteRequestData
ZwWriteVirtualMemory
ZwYieldExecution
_CIpow
__eCommonExceptions
__eEmulatorInit
__eF2XM1
__eFABS
__eFADD32
__eFADD64
__eFADDPreg
__eFADDreg
__eFADDtop
__eFCHS
__eFCOM
__eFCOM32
__eFCOM64
__eFCOMP
__eFCOMP32
__eFCOMP64
__eFCOMPP
__eFCOS
__eFDECSTP
__eFDIV32
__eFDIV64
__eFDIVPreg
__eFDIVR32
__eFDIVR64
__eFDIVRPreg
__eFDIVRreg
__eFDIVRtop
__eFDIVreg
__eFDIVtop
__eFFREE
__eFIADD16
__eFIADD32
__eFICOM16
__eFICOM32
__eFICOMP16
__eFICOMP32
__eFIDIV16
__eFIDIV32
__eFIDIVR16
__eFIDIVR32
__eFILD16
__eFILD32
__eFILD64
__eFIMUL16
__eFIMUL32
__eFINCSTP
__eFINIT
__eFIST16
__eFIST32
__eFISTP16
__eFISTP32
__eFISTP64
__eFISUB16
__eFISUB32
__eFISUBR16
__eFISUBR32
__eFLD1
__eFLD32
__eFLD64
__eFLD80
__eFLDCW
__eFLDENV
__eFLDL2E
__eFLDLN2
__eFLDPI
__eFLDZ
__eFMUL32
__eFMUL64
__eFMULPreg
__eFMULreg
__eFMULtop
__eFPATAN
__eFPREM
__eFPREM1
__eFPTAN
__eFRNDINT
__eFRSTOR
__eFSAVE
__eFSCALE
__eFSIN
__eFSQRT
__eFST
__eFST32
__eFST64
__eFSTCW
__eFSTENV
__eFSTP
__eFSTP32
__eFSTP64
__eFSTP80
__eFSTSW
__eFSUB32
__eFSUB64
__eFSUBPreg
__eFSUBR32
__eFSUBR64
__eFSUBRPreg
__eFSUBRreg
__eFSUBRtop
__eFSUBreg
__eFSUBtop
__eFTST
__eFUCOM
__eFUCOMP
__eFUCOMPP
__eFXAM
__eFXCH
__eFXTRACT
__eFYL2X
__eFYL2XP1
__eGetStatusWord
__isascii
__iscsym
__iscsymf
__toascii
_alldiv
_allmul
_alloca_probe
_allrem
_allshl
_allshr
_atoi64
_aulldiv
_aullrem
_aullshr
_chkstk
_fltused
_ftol
_i64toa
_i64tow
_itoa
_itow
_ltoa
_ltow
_memccpy
_memicmp
_snprintf
_snwprintf
_splitpath
_strcmpi
_stricmp
_strlwr
_strnicmp
_strupr
_tolower
_toupper
_ultoa
_ultow
_vsnprintf
_wcsicmp
_wcslwr
_wcsnicmp
_wcsupr
_wtoi
_wtoi64
_wtol
abs
atan
atoi
atol
ceil
cos
fabs
floor
isalnum
isalpha
iscntrl
isdigit
isgraph
islower
isprint
ispunct
isspace
isupper
iswalpha
iswctype
isxdigit
labs
log
mbstowcs
memchr
memcmp
memcpy
memmove
memset
pow
qsort
sin
sprintf
sqrt
sscanf
strcat
strchr
strcmp
strcpy
strcspn
strlen
strncat
strncmp
strncpy
strpbrk
strrchr
strspn
strstr
strtol
strtoul
swprintf
tan
tolower
toupper
towlower
towupper
vsprintf
wcscat
wcschr
wcscmp
wcscpy
wcscspn
wcslen
wcsncat
wcsncmp
wcsncpy
wcspbrk
wcsrchr
wcsspn
wcsstr
wcstol
wcstombs
wcstoul

Found follow exports in USER32.DLL
BlockInput
BroadcastSystemMessageA
BroadcastSystemMessageW
ChangeDisplaySettingsExA
ChangeDisplaySettingsExW
ClientThreadSetup
CreateDialogIndirectParamAorW
DdeGetQualityOfService
DeregisterShellHookWindow
DialogBoxIndirectParamAorW
DrawMenuBarTemp
EndMenu
EnumDisplayDevicesA
EnumDisplayDevicesW
FullScreenControl
GetAccCursorInfo
GetAltTabInfo
GetAltTabInfoA
GetAltTabInfoW
GetAncestor
GetAppCompatFlags
GetComboBoxInfo
GetCursorInfo
GetGUIThreadInfo
GetListBoxInfo
GetMenuBarInfo
GetProgmanWindow
GetScrollBarInfo
GetTaskmanWindow
GetTitleBarInfo
GetWindowInfo
GetWindowModuleFileName
GetWindowModuleFileNameA
GetWindowModuleFileNameW
IsHungAppWindow
KillSystemTimer
LoadKeyboardLayoutEx
LoadLocalFonts
LoadRemoteFonts
MBToWCSEx
MB_GetString
MenuWindowProcA
MenuWindowProcW
MsgWaitForMultipleObjectsEx
NotifyWinEvent
PrivateExtractIconExA
PrivateExtractIconExW
PrivateExtractIconsA
PrivateExtractIconsW
PrivateKDBreakPoint
QuerySendMessage
RealChildWindowFromPoint
RealGetWindowClass
RealGetWindowClassA
RealGetWindowClassW
RegisterServicesProcess
RegisterShellHookWindow
ScrollChildren
SendInput
SetConsoleReserveKeys
SetCursorContents
SetLogonNotifyWindow
SetProgmanWindow
SetShellWindowEx
SetSystemMenu
SetSystemTimer
SetTaskmanWindow
SetWinEventHook
SetWindowStationUser
ShowStartGlass
SoftModalMessageBox
ToUnicodeEx
TrackMouseEvent
TranslateMessageEx
UnhookWinEvent
UpdatePerUserSystemParameters
UserRealizePalette
UserRegisterWowHandlers
WCSToMBEx

Found follow exports in GDI32.DLL
AddFontResourceTracking
GdiAddFontResourceW
GdiAddGlsBounds
GdiAddGlsRecord
GdiCleanCacheDC
GdiConsoleTextOut
GdiConvertAndCheckDC
GdiConvertBitmap
GdiConvertBrush
GdiConvertDC
GdiConvertEnhMetaFile
GdiConvertFont
GdiConvertMetaFilePict
GdiConvertPalette
GdiConvertRegion
GdiConvertToDevmodeW
GdiCreateLocalEnhMetaFile
GdiCreateLocalMetaFilePict
GdiDeleteLocalDC
GdiDescribePixelFormat
GdiDllInitialize
GdiEntry10
GdiEntry11
GdiEntry12
GdiEntry13
GdiEntry14
GdiEntry15
GdiEntry1
GdiEntry2
GdiEntry3
GdiEntry4
GdiEntry5
GdiEntry6
GdiEntry7
GdiEntry8
GdiEntry9
GdiFixUpHandle
GdiGetCharDimensions
GdiGetCodePage
GdiGetLocalBrush
GdiGetLocalDC
GdiGetLocalFont
GdiGetSpoolMessage
GdiInitSpool
GdiIsMetaFileDC
GdiIsMetaPrintDC
GdiPerf
GdiPlayEMF
GdiProcessSetup
GdiQueryFonts
GdiQueryTable
GdiReleaseLocalDC
GdiSetAttrs
GdiSetPixelFormat
GdiSetServerAttr
GdiSwapBuffers
GdiValidateHandle
GetCharWidthInfo
GetETM
GetEnhMetaFilePixelFormat
GetFontResourceInfoW
GetGlyphOutlineWow
GetHFONT
GetRelAbs
GetTransform
NamedEscape
PolyPatBlt
RemoveFontResourceTracking
SelectBrushLocal
SelectFontLocal
SetMagicColors
SetRelAbs
SetVirtualResolution
UnloadNetworkFonts
UpdateICMRegKey
bInitSystemAndFontsDirectoriesW
bMakePathNameW
cGetTTFFromFOT

Found follow exports in SHELL32.DLL
CheckEscapesA
Control_FillCache_RunDLL
Control_FillCache_RunDLLA
Control_FillCache_RunDLLW
Control_RunDLLA
Control_RunDLLW
ExtractIconExW
ExtractIconResInfoA
ExtractIconResInfoW
ExtractVersionResource16W
FindExeDlgProc
OpenAs_RunDLLA
OpenAs_RunDLLW
PrintersGetCommand_RunDLLA
PrintersGetCommand_RunDLLW
SHBrowseForFolderW
SheChangeDirExA
SheChangeDirW
SheConvertPathW
SheFullPathA
SheFullPathW
SheGetCurDrive
SheGetDirExW
SheGetDirW
SheGetPathOffsetW
Shell_NotifyIconW
ShellExecuteExW
ShellHookProc
SheRemoveQuotesA
SheRemoveQuotesW
SheShortenPathA
SheShortenPathW
SHFileOperationW
SHGetDataFromIDListW
SHGetFileInfoW
SHGetNewLinkInfo
SHGetPathFromIDListW
SHHelpShortcuts_RunDLLA
SHHelpShortcuts_RunDLLW
SHUpdateRecycleBinIcon
StrChrA
StrChrIA
StrChrIW
StrChrW
StrCmpNA
StrCmpNIA
StrCmpNIW
StrCmpNW
StrCpyNA
StrCpyNW
StrNCmpA
StrNCmpIA
StrNCmpIW
StrNCmpW
StrNCpyA
StrNCpyW
StrRChrA
StrRChrIA
StrRChrIW
StrRChrW
StrRStrA
StrRStrIA
StrRStrIW
StrRStrW
StrStrA
StrStrIA
StrStrIW
StrStrW
WOWShellExecute

Found follow exports in COMDLG32.DLL
dwLBSubclass
dwOKSubclass
LoadAlterBitmap
WantArrows

Found follow exports in COMCTL32.DLL
DllInstall

Found follow exports in ADVAPI32.DLL
BuildExplicitAccessWithNameA
BuildExplicitAccessWithNameW
BuildImpersonateExplicitAccessWithNameA
BuildImpersonateExplicitAccessWithNameW
BuildImpersonateTrusteeA
BuildImpersonateTrusteeW
BuildSecurityDescriptorA
BuildSecurityDescriptorW
BuildTrusteeWithNameA
BuildTrusteeWithNameW
BuildTrusteeWithSidA
BuildTrusteeWithSidW
CancelOverlappedAccess
ConvertAccessToSecurityDescriptorA
ConvertAccessToSecurityDescriptorW
ConvertSecurityDescriptorToAccessA
ConvertSecurityDescriptorToAccessNamedA
ConvertSecurityDescriptorToAccessNamedW
ConvertSecurityDescriptorToAccessW
CryptAcquireContextW
CryptSetProviderW
CryptSignHashW
CryptVerifySignatureW
DuplicateTokenEx
ElfBackupEventLogFileA
ElfBackupEventLogFileW
ElfChangeNotify
ElfClearEventLogFileA
ElfClearEventLogFileW
ElfCloseEventLog
ElfDeregisterEventSource
ElfNumberOfRecords
ElfOldestRecord
ElfOpenBackupEventLogA
ElfOpenBackupEventLogW
ElfOpenEventLogA
ElfOpenEventLogW
ElfReadEventLogA
ElfReadEventLogW
ElfRegisterEventSourceA
ElfRegisterEventSourceW
ElfReportEventA
ElfReportEventW
EnumServiceGroupW
EnumServicesStatusExA
EnumServicesStatusExW
GetAccessPermissionsForObjectA
GetAccessPermissionsForObjectW
GetAuditedPermissionsFromAclA
GetAuditedPermissionsFromAclW
GetCurrentHwProfileA
GetCurrentHwProfileW
GetEffectiveRightsFromAclA
GetEffectiveRightsFromAclW
GetExplicitEntriesFromAclA
GetExplicitEntriesFromAclW
GetMultipleTrusteeA
GetMultipleTrusteeOperationA
GetMultipleTrusteeOperationW
GetMultipleTrusteeW
GetNamedSecurityInfoA
GetNamedSecurityInfoExA
GetNamedSecurityInfoExW
GetNamedSecurityInfoW
GetOverlappedAccessResults
GetSecurityInfo
GetSecurityInfoExA
GetSecurityInfoExW
GetTrusteeNameA
GetTrusteeNameW
GetTrusteeTypeA
GetTrusteeTypeW
I_ScGetCurrentGroupStateW
I_ScSetServiceBitsA
I_ScSetServiceBitsW
LookupSecurityDescriptorPartsA
LookupSecurityDescriptorPartsW
LsaAddAccountRights
LsaAddPrivilegesToAccount
LsaClearAuditLog
LsaClose
LsaCreateAccount
LsaCreateSecret
LsaCreateTrustedDomain
LsaDelete
LsaDeleteTrustedDomain
LsaEnumerateAccountRights
LsaEnumerateAccounts
LsaEnumerateAccountsWithUserRight
LsaEnumeratePrivileges
LsaEnumeratePrivilegesOfAccount
LsaEnumerateTrustedDomains
LsaFreeMemory
LsaGetQuotasForAccount
LsaGetRemoteUserName
LsaGetSystemAccessAccount
LsaGetUserName
LsaICLookupNames
LsaICLookupSids
LsaLookupNames
LsaLookupPrivilegeDisplayName
LsaLookupPrivilegeName
LsaLookupPrivilegeValue
LsaLookupSids
LsaNtStatusToWinError
LsaOpenAccount
LsaOpenPolicy
LsaOpenSecret
LsaOpenTrustedDomain
LsaQueryInfoTrustedDomain
LsaQueryInformationPolicy
LsaQuerySecret
LsaQuerySecurityObject
LsaQueryTrustedDomainInfo
LsaRemoveAccountRights
LsaRemovePrivilegesFromAccount
LsaRetrievePrivateData
LsaSetInformationPolicy
LsaSetInformationTrustedDomain
LsaSetQuotasForAccount
LsaSetSecret
LsaSetSecurityObject
LsaSetSystemAccessAccount
LsaSetTrustedDomainInformation
LsaStorePrivateData
ObjectDeleteAuditAlarmA
ObjectDeleteAuditAlarmW
QueryServiceStatusEx
QueryWindows31FilesMigration
SetEntriesInAccessListA
SetEntriesInAccessListW
SetEntriesInAclA
SetEntriesInAclW
SetEntriesInAuditListA
SetEntriesInAuditListW
SetNamedSecurityInfoA
SetNamedSecurityInfoExA
SetNamedSecurityInfoExW
SetNamedSecurityInfoW
SetSecurityInfo
SetSecurityInfoExA
SetSecurityInfoExW
SynchronizeWindows31FilesAndWindowsNTRegistry
SystemFunction001
SystemFunction002
SystemFunction003
SystemFunction004
SystemFunction005
SystemFunction006
SystemFunction007
SystemFunction008
SystemFunction009
SystemFunction010
SystemFunction011
SystemFunction012
SystemFunction013
SystemFunction014
SystemFunction015
SystemFunction016
SystemFunction017
SystemFunction018
SystemFunction019
SystemFunction020
SystemFunction021
SystemFunction022
SystemFunction023
SystemFunction024
SystemFunction025
SystemFunction026
SystemFunction027
SystemFunction028
SystemFunction029
SystemFunction030
SystemFunction031
SystemFunction032
SystemFunction033
TrusteeAccessToObjectA
TrusteeAccessToObjectW

Found follow exports in WSOCK32.DLL
MigrateWinsockConfiguration
WEP
WSApSetPostRoutine
inet_network
getnetbyname
rcmd
rexec
rresvport
sethostname
AcceptEx
GetAcceptExSockaddrs

Found follow exports in WS2_32.DLL
accept
bind
closesocket
connect
getpeername
getsockname
getsockopt
htonl
htons
ioctlsocket
inet_addr
inet_ntoa
listen
ntohl
ntohs
recv
recvfrom
select
send
sendto
setsockopt
shutdown
socket
WSApSetPostRoutine
WPUCompleteOverlappedRequest
WSAAccept
WSAAddressToStringA
WSAAddressToStringW
WSACloseEvent
WSAConnect
WSACreateEvent
WSADuplicateSocketA
WSADuplicateSocketW
WSAEnumNameSpaceProvidersA
WSAEnumNameSpaceProvidersW
WSAEnumNetworkEvents
WSAEnumProtocolsA
WSAEnumProtocolsW
WSAEventSelect
WSAGetOverlappedResult
WSAGetQOSByName
WSAGetServiceClassInfoA
WSAGetServiceClassInfoW
WSAGetServiceClassNameByClassIdA
WSAGetServiceClassNameByClassIdW
WSAHtonl
WSAHtons
WSAInstallServiceClassA
WSAInstallServiceClassW
WSAIoctl
gethostbyaddr
gethostbyname
getprotobyname
getprotobynumber
getservbyname
getservbyport
gethostname
WSAJoinLeaf
WSALookupServiceBeginA
WSALookupServiceBeginW
WSALookupServiceEnd
WSALookupServiceNextA
WSALookupServiceNextW
WSANtohl
WSANtohs
WSAProviderConfigChange
WSARecv
WSARecvDisconnect
WSARecvFrom
WSARemoveServiceClass
WSAResetEvent
WSASend
WSASendDisconnect
WSASendTo
WSASetEvent
WSASetServiceA
WSASetServiceW
WSASocketA
WSASocketW
WSAStringToAddressA
WSAStringToAddressW
WSAWaitForMultipleEvents
WSCDeinstallProvider
WSCEnableNSProvider
WSCEnumProtocols
WSCGetProviderPath
WSCInstallNameSpace
WSCInstallProvider
WSCUnInstallNameSpace
WSAAsyncSelect
WSAAsyncGetHostByAddr
WSAAsyncGetHostByName
WSAAsyncGetProtoByNumber
WSAAsyncGetProtoByName
WSAAsyncGetServByPort
WSAAsyncGetServByName
WSACancelAsyncRequest
WSASetBlockingHook
WSAUnhookBlockingHook
WSAGetLastError
WSASetLastError
WSACancelBlockingCall
WSAIsBlocking
WSAStartup
WSACleanup
__WSAFDIsSet
WEP

Windows 2000


Found follow exports in KERNEL32.DLL
AddConsoleAliasA
AddConsoleAliasW
AllocateUserPhysicalPages
AssignProcessToJobObject
BaseAttachCompleteThunk
BindIoCompletionCallback
CancelDeviceWakeupRequest
CancelIo
CancelTimerQueueTimer
CancelWaitableTimer
ChangeTimerQueueTimer
CloseConsoleHandle
CmdBatNotification
ConsoleMenuControl
ConvertThreadToFiber
CopyFileExA
CopyFileExW
CreateFiber
CreateFiberEx
CreateHardLinkA
CreateHardLinkW
CreateJobObjectA
CreateJobObjectW
CreateProcessInternalA
CreateProcessInternalW
CreateProcessInternalWSecure
CreateTimerQueue
CreateTimerQueueTimer
CreateToolhelp32Snapshot
CreateVirtualBuffer
CreateWaitableTimerA
CreateWaitableTimerW
DelayLoadFailureHook
DeleteFiber
DeleteTimerQueue
DeleteTimerQueueEx
DeleteTimerQueueTimer
DeleteVolumeMountPointA
DeleteVolumeMountPointW
DnsHostnameToComputerNameA
DnsHostnameToComputerNameW
DosPathToSessionPathA
DosPathToSessionPathW
DuplicateConsoleHandle
EnumCalendarInfoExA
EnumCalendarInfoExW
EnumDateFormatsExA
EnumDateFormatsExW
EnumLanguageGroupLocalesA
EnumLanguageGroupLocalesW
EnumSystemLanguageGroupsA
EnumSystemLanguageGroupsW
EnumUILanguagesA
EnumUILanguagesW
ExitVDM
ExpungeConsoleCommandHistoryA
ExpungeConsoleCommandHistoryW
ExtendVirtualBuffer
FindFirstFileExA
FindFirstFileExW
FindFirstVolumeA
FindFirstVolumeMountPointA
FindFirstVolumeMountPointW
FindFirstVolumeW
FindNextVolumeA
FindNextVolumeMountPointA
FindNextVolumeMountPointW
FindNextVolumeW
FindVolumeClose
FindVolumeMountPointClose
FreeUserPhysicalPages
FreeVirtualBuffer
GetCPInfoExA
GetCPInfoExW
GetCalendarInfoA
GetCalendarInfoW
GetComputerNameExA
GetComputerNameExW
GetConsoleAliasA
GetConsoleAliasExesA
GetConsoleAliasExesLengthA
GetConsoleAliasExesLengthW
GetConsoleAliasExesW
GetConsoleAliasW
GetConsoleAliasesA
GetConsoleAliasesLengthA
GetConsoleAliasesLengthW
GetConsoleAliasesW
GetConsoleCharType
GetConsoleCommandHistoryA
GetConsoleCommandHistoryLengthA
GetConsoleCommandHistoryLengthW
GetConsoleCommandHistoryW
GetConsoleCursorMode
GetConsoleDisplayMode
GetConsoleFontInfo
GetConsoleFontSize
GetConsoleHardwareState
GetConsoleInputExeNameA
GetConsoleInputExeNameW
GetConsoleInputWaitHandle
GetConsoleKeyboardLayoutNameA
GetConsoleKeyboardLayoutNameW
GetConsoleNlsMode
GetConsoleWindow
GetCurrentConsoleFont
GetDefaultSortkeySize
GetDevicePowerState
GetFileAttributesExA
GetFileAttributesExW
GetFileSizeEx
GetLinguistLangSize
GetLongPathNameA
GetLongPathNameW
GetNextVDMCommand
GetNlsSectionName
GetNumberOfConsoleFonts
GetProcessIoCounters
GetProcessPriorityBoost
GetSystemDefaultUILanguage
GetSystemWindowsDirectoryA
GetSystemWindowsDirectoryW
GetThreadPriorityBoost
GetUserDefaultUILanguage
GetVDMCurrentDirectories
GetVolumeNameForVolumeMountPointA
GetVolumeNameForVolumeMountPointW
GetVolumePathNameA
GetVolumePathNameW
GetWriteWatch
GlobalMemoryStatusEx
Heap32First
Heap32ListFirst
Heap32ListNext
Heap32Next
HeapCreateTagsW
HeapExtend
HeapQueryInformation
HeapQueryTagW
HeapSetInformation
HeapSummary
HeapUsage
InitializeCriticalSectionAndSpinCount
InterlockedCompareExchange
InterlockedExchangeAdd
InvalidateConsoleDIBits
IsDebuggerPresent
IsProcessorFeaturePresent
IsSystemResumeAutomatic
IsValidLanguageGroup
MapUserPhysicalPages
MapUserPhysicalPagesScatter
Module32First
Module32FirstW
Module32Next
Module32NextW
MoveFileWithProgressA
MoveFileWithProgressW
NlsConvertIntegerToString
NlsGetCacheUpdateCount
NlsResetProcessLocale
OpenConsoleW
OpenDataFile
OpenJobObjectA
OpenJobObjectW
OpenThread
OpenWaitableTimerA
OpenWaitableTimerW
PrivCopyFileExW
PrivMoveFileIdentityW
Process32First
Process32FirstW
Process32Next
Process32NextW
ProcessIdToSessionId
QueryInformationJobObject
QueryWin31IniFilesMappedToRegistry
QueueUserWorkItem
ReadConsoleInputExA
ReadConsoleInputExW
ReadDirectoryChangesW
ReadFileScatter
RegisterConsoleIME
RegisterConsoleOS2
RegisterConsoleVDM
RegisterWaitForInputIdle
RegisterWaitForSingleObject
RegisterWaitForSingleObjectEx
RegisterWowBaseHandlers
RegisterWowExec
ReplaceFile
ReplaceFileA
ReplaceFileW
RequestDeviceWakeup
RequestWakeupLatency
ResetWriteWatch
SetCPGlobal
SetCalendarInfoA
SetCalendarInfoW
SetComputerNameExA
SetComputerNameExW
SetConsoleCommandHistoryMode
SetConsoleCursor
SetConsoleCursorMode
SetConsoleDisplayMode
SetConsoleFont
SetConsoleHardwareState
SetConsoleIcon
SetConsoleInputExeNameA
SetConsoleInputExeNameW
SetConsoleKeyShortcuts
SetConsoleLocalEUDC
SetConsoleMaximumWindowSize
SetConsoleMenuClose
SetConsoleNlsMode
SetConsoleNumberOfCommandsA
SetConsoleNumberOfCommandsW
SetConsoleOS2OemFormat
SetConsolePalette
SetCriticalSectionSpinCount
SetFilePointerEx
SetInformationJobObject
SetLastConsoleEventActive
SetMessageWaitingIndicator
SetProcessAffinityMask
SetProcessPriorityBoost
SetTermsrvAppInstallMode
SetThreadExecutionState
SetThreadIdealProcessor
SetThreadPriorityBoost
SetTimerQueueTimer
SetVDMCurrentDirectories
SetVolumeMountPointA
SetVolumeMountPointW
SetWaitableTimer
ShowConsoleCursor
SignalObjectAndWait
SwitchToFiber
SwitchToThread
TerminateJobObject
TermsrvAppInstallMode
Thread32First
Thread32Next
Toolhelp32ReadProcessMemory
TrimVirtualBuffer
TryEnterCriticalSection
UTRegister
UTUnRegister
UnregisterConsoleIME
UnregisterWait
UnregisterWaitEx
VDMConsoleOperation
VDMOperationStarted
ValidateLCType
ValidateLocale
VerSetConditionMask
VerifyConsoleIoHandle
VerifyVersionInfoA
VerifyVersionInfoW
VirtualAllocEx
VirtualBufferExceptionHandler
VirtualFreeEx
WriteConsoleInputVDMA
WriteConsoleInputVDMW
WriteFileGather

Found follow exports in NTDLL.DLL
PropertyLengthAsVariant
RtlConvertPropertyToVariant
RtlConvertVariantToProperty
RtlUlongByteSwap
RtlUlonglongByteSwap
RtlUshortByteSwap
CsrAllocateCaptureBuffer
CsrAllocateMessagePointer
CsrCaptureMessageBuffer
CsrCaptureMessageString
CsrCaptureTimeout
CsrClientCallServer
CsrClientConnectToServer
CsrFreeCaptureBuffer
CsrIdentifyAlertableThread
CsrNewThread
CsrProbeForRead
CsrProbeForWrite
CsrSetPriorityClass
DbgPrintReturnControlC
DbgSsHandleKmApiMsg
DbgSsInitialize
DbgUiConnectToDbg
DbgUiContinue
DbgUiWaitStateChange
DbgUserBreakPoint
KiRaiseUserExceptionDispatcher
KiUserApcDispatcher
KiUserCallbackDispatcher
KiUserExceptionDispatcher
LdrAccessResource
LdrAlternateResourcesEnabled
LdrDisableThreadCalloutsForDll
LdrEnumResources
LdrFindEntryForAddress
LdrFindResourceDirectory_U
LdrFindResource_U
LdrFlushAlternateResourceModules
LdrGetDllHandle
LdrGetProcedureAddress
LdrInitializeThunk
LdrLoadAlternateResourceModule
LdrLoadDll
LdrProcessRelocationBlock
LdrQueryImageFileExecutionOptions
LdrQueryProcessModuleInformation
LdrShutdownProcess
LdrShutdownThread
LdrUnloadAlternateResourceModule
LdrUnloadDll
LdrVerifyImageMatchesChecksum
NPXEMULATORTABLE
NlsAnsiCodePage
NlsMbCodePageTag
NlsMbOemCodePageTag
NtAcceptConnectPort
NtAccessCheck
NtAccessCheckAndAuditAlarm
NtAccessCheckByType
NtAccessCheckByTypeAndAuditAlarm
NtAccessCheckByTypeResultList
NtAccessCheckByTypeResultListAndAuditAlarm
NtAccessCheckByTypeResultListAndAuditAlarmByHandle
NtAddAtom
NtAdjustGroupsToken
NtAdjustPrivilegesToken
NtAlertResumeThread
NtAlertThread
NtAllocateLocallyUniqueId
NtAllocateUserPhysicalPages
NtAllocateUuids
NtAllocateVirtualMemory
NtAreMappedFilesTheSame
NtAssignProcessToJobObject
NtCallbackReturn
NtCancelDeviceWakeupRequest
NtCancelIoFile
NtCancelTimer
NtClearEvent
NtClose
NtCloseObjectAuditAlarm
NtCompleteConnectPort
NtConnectPort
NtContinue
NtCreateChannel
NtCreateDirectoryObject
NtCreateEvent
NtCreateEventPair
NtCreateFile
NtCreateIoCompletion
NtCreateJobObject
NtCreateKey
NtCreateMailslotFile
NtCreateMutant
NtCreateNamedPipeFile
NtCreatePagingFile
NtCreatePort
NtCreateProcess
NtCreateProfile
NtCreateSection
NtCreateSemaphore
NtCreateSymbolicLinkObject
NtCreateThread
NtCreateTimer
NtCreateToken
NtCreateWaitablePort
NtDelayExecution
NtDeleteAtom
NtDeleteFile
NtDeleteKey
NtDeleteObjectAuditAlarm
NtDeleteValueKey
NtDeviceIoControlFile
NtDisplayString
NtDuplicateObject
NtDuplicateToken
NtEnumerateKey
NtEnumerateValueKey
NtExtendSection
NtFilterToken
NtFindAtom
NtFlushBuffersFile
NtFlushInstructionCache
NtFlushKey
NtFlushVirtualMemory
NtFlushWriteBuffer
NtFreeUserPhysicalPages
NtFreeVirtualMemory
NtFsControlFile
NtGetContextThread
NtGetDevicePowerState
NtGetPlugPlayEvent
NtGetTickCount
NtGetWriteWatch
NtImpersonateAnonymousToken
NtImpersonateClientOfPort
NtImpersonateThread
NtInitializeRegistry
NtInitiatePowerAction
NtIsSystemResumeAutomatic
NtListenChannel
NtListenPort
NtLoadDriver
NtLoadKey2
NtLoadKey
NtLockFile
NtLockVirtualMemory
NtMakeTemporaryObject
NtMapUserPhysicalPages
NtMapUserPhysicalPagesScatter
NtMapViewOfSection
NtNotifyChangeDirectoryFile
NtNotifyChangeKey
NtNotifyChangeMultipleKeys
NtOpenChannel
NtOpenDirectoryObject
NtOpenEvent
NtOpenEventPair
NtOpenFile
NtOpenIoCompletion
NtOpenJobObject
NtOpenKey
NtOpenMutant
NtOpenObjectAuditAlarm
NtOpenProcess
NtOpenProcessToken
NtOpenSection
NtOpenSemaphore
NtOpenSymbolicLinkObject
NtOpenThread
NtOpenThreadToken
NtOpenTimer
NtPlugPlayControl
NtPowerInformation
NtPrivilegeCheck
NtPrivilegeObjectAuditAlarm
NtPrivilegedServiceAuditAlarm
NtProtectVirtualMemory
NtPulseEvent
NtQueryAttributesFile
NtQueryDefaultLocale
NtQueryDefaultUILanguage
NtQueryDirectoryFile
NtQueryDirectoryObject
NtQueryEaFile
NtQueryEvent
NtQueryFullAttributesFile
NtQueryInformationAtom
NtQueryInformationFile
NtQueryInformationJobObject
NtQueryInformationPort
NtQueryInformationProcess
NtQueryInformationThread
NtQueryInformationToken
NtQueryInstallUILanguage
NtQueryIntervalProfile
NtQueryIoCompletion
NtQueryKey
NtQueryMultipleValueKey
NtQueryMutant
NtQueryObject
NtQueryOpenSubKeys
NtQueryQuotaInformationFile
NtQuerySection
NtQuerySecurityObject
NtQuerySemaphore
NtQuerySymbolicLinkObject
NtQuerySystemEnvironmentValue
NtQuerySystemInformation
NtQuerySystemTime
NtQueryTimer
NtQueryTimerResolution
NtQueryValueKey
NtQueryVirtualMemory
NtQueryVolumeInformationFile
NtQueueApcThread
NtRaiseException
NtRaiseHardError
NtReadFile
NtReadFileScatter
NtReadRequestData
NtReadVirtualMemory
NtRegisterThreadTerminatePort
NtReleaseMutant
NtReleaseSemaphore
NtRemoveIoCompletion
NtReplaceKey
NtReplyPort
NtReplyWaitReceivePort
NtReplyWaitReceivePortEx
NtReplyWaitReplyPort
NtReplyWaitSendChannel
NtRequestDeviceWakeup
NtRequestPort
NtRequestWaitReplyPort
NtRequestWakeupLatency
NtResetEvent
NtResetWriteWatch
NtRestoreKey
NtResumeThread
NtSaveKey
NtSaveMergedKeys
NtSecureConnectPort
NtSendWaitReplyChannel
NtSetContextChannel
NtSetContextThread
NtSetDefaultHardErrorPort
NtSetDefaultLocale
NtSetDefaultUILanguage
NtSetEaFile
NtSetEvent
NtSetHighEventPair
NtSetHighWaitLowEventPair
NtSetInformationFile
NtSetInformationJobObject
NtSetInformationKey
NtSetInformationObject
NtSetInformationProcess
NtSetInformationThread
NtSetInformationToken
NtSetIntervalProfile
NtSetIoCompletion
NtSetLdtEntries
NtSetLowEventPair
NtSetLowWaitHighEventPair
NtSetQuotaInformationFile
NtSetSecurityObject
NtSetSystemEnvironmentValue
NtSetSystemInformation
NtSetSystemPowerState
NtSetSystemTime
NtSetThreadExecutionState
NtSetTimer
NtSetTimerResolution
NtSetUuidSeed
NtSetValueKey
NtSetVolumeInformationFile
NtShutdownSystem
NtSignalAndWaitForSingleObject
NtStartProfile
NtStopProfile
NtSuspendThread
NtSystemDebugControl
NtTerminateJobObject
NtTerminateProcess
NtTerminateThread
NtTestAlert
NtUnloadDriver
NtUnloadKey
NtUnlockFile
NtUnlockVirtualMemory
NtUnmapViewOfSection
NtVdmControl
NtWaitForMultipleObjects
NtWaitForSingleObject
NtWaitHighEventPair
NtWaitLowEventPair
NtWriteFile
NtWriteFileGather
NtWriteRequestData
NtWriteVirtualMemory
NtYieldExecution
PfxFindPrefix
PfxInitialize
PfxInsertPrefix
PfxRemovePrefix
RestoreEm87Context
RtlAbortRXact
RtlAbsoluteToSelfRelativeSD
RtlAcquirePebLock
RtlAcquireResourceExclusive
RtlAcquireResourceShared
RtlAddAccessAllowedAce
RtlAddAccessAllowedAceEx
RtlAddAccessAllowedObjectAce
RtlAddAccessDeniedAce
RtlAddAccessDeniedAceEx
RtlAddAccessDeniedObjectAce
RtlAddAce
RtlAddActionToRXact
RtlAddAtomToAtomTable
RtlAddAttributeActionToRXact
RtlAddAuditAccessAce
RtlAddAuditAccessAceEx
RtlAddAuditAccessObjectAce
RtlAddCompoundAce
RtlAddRange
RtlAdjustPrivilege
RtlAllocateAndInitializeSid
RtlAllocateHandle
RtlAnsiCharToUnicodeChar
RtlAnsiStringToUnicodeSize
RtlAppendAsciizToString
RtlAppendStringToString
RtlAppendUnicodeStringToString
RtlAppendUnicodeToString
RtlApplyRXact
RtlApplyRXactNoFlush
RtlAreAllAccessesGranted
RtlAreAnyAccessesGranted
RtlAreBitsClear
RtlAreBitsSet
RtlAssert
RtlCallbackLpcClient
RtlCancelTimer
RtlCaptureStackBackTrace
RtlCharToInteger
RtlCheckForOrphanedCriticalSections
RtlCheckRegistryKey
RtlClearAllBits
RtlClearBits
RtlCompactHeap
RtlCompareMemory
RtlCompareMemoryUlong
RtlCompareString
RtlCompareUnicodeString
RtlCompressBuffer
RtlConsoleMultiByteToUnicodeN
RtlConvertExclusiveToShared
RtlConvertSharedToExclusive
RtlConvertSidToUnicodeString
RtlConvertToAutoInheritSecurityObject
RtlConvertUiListToApiList
RtlCopyLuid
RtlCopyLuidAndAttributesArray
RtlCopyRangeList
RtlCopySecurityDescriptor
RtlCopySid
RtlCopySidAndAttributesArray
RtlCopyString
RtlCopyUnicodeString
RtlCreateAcl
RtlCreateAndSetSD
RtlCreateAtomTable
RtlCreateEnvironment
RtlCreateLpcServer
RtlCreateProcessParameters
RtlCreateQueryDebugBuffer
RtlCreateRegistryKey
RtlCreateSecurityDescriptor
RtlCreateTagHeap
RtlCreateTimer
RtlCreateTimerQueue
RtlCreateUnicodeString
RtlCreateUnicodeStringFromAsciiz
RtlCreateUserProcess
RtlCreateUserSecurityObject
RtlCreateUserThread
RtlCustomCPToUnicodeN
RtlCutoverTimeToSystemTime
RtlDeNormalizeProcessParams
RtlDebugPrintTimes
RtlDecompressBuffer
RtlDecompressFragment
RtlDefaultNpAcl
RtlDelete
RtlDeleteAce
RtlDeleteAtomFromAtomTable
RtlDeleteCriticalSection
RtlDeleteElementGenericTable
RtlDeleteNoSplay
RtlDeleteOwnersRanges
RtlDeleteRange
RtlDeleteRegistryValue
RtlDeleteResource
RtlDeleteSecurityObject
RtlDeleteTimer
RtlDeleteTimerQueue
RtlDeleteTimerQueueEx
RtlDeregisterWait
RtlDeregisterWaitEx
RtlDestroyAtomTable
RtlDestroyEnvironment
RtlDestroyHandleTable
RtlDestroyProcessParameters
RtlDestroyQueryDebugBuffer
RtlDetermineDosPathNameType_U
RtlDnsHostNameToComputerName
RtlDoesFileExists_U
RtlDosPathNameToNtPathName_U
RtlDosSearchPath_U
RtlDowncaseUnicodeString
RtlDumpResource
RtlEmptyAtomTable
RtlEnableEarlyCriticalSectionEventCreation
RtlEnterCriticalSection
RtlEnumProcessHeaps
RtlEnumerateGenericTable
RtlEnumerateGenericTableWithoutSplaying
RtlEqualComputerName
RtlEqualDomainName
RtlEqualLuid
RtlEqualPrefixSid
RtlEqualSid
RtlEqualString
RtlEqualUnicodeString
RtlEraseUnicodeString
RtlExpandEnvironmentStrings_U
RtlExtendHeap
RtlFillMemory
RtlFillMemoryUlong
RtlFindClearBits
RtlFindClearBitsAndSet
RtlFindLastBackwardRunClear
RtlFindLeastSignificantBit
RtlFindLongestRunClear
RtlFindMessage
RtlFindMostSignificantBit
RtlFindNextForwardRunClear
RtlFindRange
RtlFindSetBits
RtlFindSetBitsAndClear
RtlFirstFreeAce
RtlFormatCurrentUserKeyPath
RtlFormatMessage
RtlFreeAnsiString
RtlFreeHandle
RtlFreeOemString
RtlFreeRangeList
RtlFreeSid
RtlFreeUnicodeString
RtlFreeUserThreadStack
RtlGUIDFromString
RtlGenerate8dot3Name
RtlGetAce
RtlGetCallersAddress
RtlGetCompressionWorkSpaceSize
RtlGetControlSecurityDescriptor
RtlGetCurrentDirectory_U
RtlGetDaclSecurityDescriptor
RtlGetElementGenericTable
RtlGetFirstRange
RtlGetFullPathName_U
RtlGetGroupSecurityDescriptor
RtlGetLongestNtPathLength
RtlGetNextRange
RtlGetNtGlobalFlags
RtlGetNtProductType
RtlGetOwnerSecurityDescriptor
RtlGetProcessHeaps
RtlGetSaclSecurityDescriptor
RtlGetSecurityDescriptorRMControl
RtlGetUserInfoHeap
RtlGetVersion
RtlIdentifierAuthoritySid
RtlImageDirectoryEntryToData
RtlImageRvaToSection
RtlImageRvaToVa
RtlImpersonateLpcClient
RtlImpersonateSelf
RtlInitAnsiString
RtlInitCodePageTable
RtlInitNlsTables
RtlInitString
RtlInitUnicodeString
RtlInitializeAtomPackage
RtlInitializeBitMap
RtlInitializeContext
RtlInitializeCriticalSection
RtlInitializeCriticalSectionAndSpinCount
RtlInitializeGenericTable
RtlInitializeHandleTable
RtlInitializeRXact
RtlInitializeRangeList
RtlInitializeResource
RtlInitializeSid
RtlInsertElementGenericTable
RtlInt64ToUnicodeString
RtlIntegerToChar
RtlIntegerToUnicodeString
RtlInvertRangeList
RtlIsDosDeviceName_U
RtlIsGenericTableEmpty
RtlIsNameLegalDOS8Dot3
RtlIsRangeAvailable
RtlIsTextUnicode
RtlIsValidHandle
RtlIsValidIndexHandle
RtlLargeIntegerToChar
RtlLeaveCriticalSection
RtlLengthRequiredSid
RtlLengthSecurityDescriptor
RtlLengthSid
RtlLocalTimeToSystemTime
RtlLockHeap
RtlLookupAtomInAtomTable
RtlLookupElementGenericTable
RtlMakeSelfRelativeSD
RtlMapGenericMask
RtlMergeRangeLists
RtlMoveMemory
RtlMultiByteToUnicodeSize
RtlNewInstanceSecurityObject
RtlNewSecurityGrantedAccess
RtlNewSecurityObject
RtlNewSecurityObjectEx
RtlNormalizeProcessParams
RtlNtStatusToDosError
RtlNumberGenericTableElements
RtlNumberOfClearBits
RtlNumberOfSetBits
RtlOemStringToUnicodeSize
RtlOemStringToUnicodeString
RtlOemToUnicodeN
RtlOpenCurrentUser
RtlPcToFileHeader
RtlPinAtomInAtomTable
RtlPrefixString
RtlPrefixUnicodeString
RtlProtectHeap
RtlQueryAtomInAtomTable
RtlQueryEnvironmentVariable_U
RtlQueryHeapInformation
RtlQueryInformationAcl
RtlQueryProcessBackTraceInformation
RtlQueryProcessDebugInformation
RtlQueryProcessHeapInformation
RtlQueryProcessLockInformation
RtlQueryRegistryValues
RtlQuerySecurityObject
RtlQueryTagHeap
RtlQueryTimeZoneInformation
RtlQueueWorkItem
RtlRaiseException
RtlRaiseStatus
RtlRandom
RtlRealPredecessor
RtlRealSuccessor
RtlRegisterWait
RtlReleasePebLock
RtlReleaseResource
RtlRemoteCall
RtlResetRtlTranslations
RtlRunDecodeUnicodeString
RtlRunEncodeUnicodeString
RtlSecondsSince1970ToTime
RtlSecondsSince1980ToTime
RtlSelfRelativeToAbsoluteSD2
RtlSelfRelativeToAbsoluteSD
RtlSetAllBits
RtlSetAttributesSecurityDescriptor
RtlSetBits
RtlSetControlSecurityDescriptor
RtlSetCriticalSectionSpinCount
RtlSetCurrentDirectory_U
RtlSetCurrentEnvironment
RtlSetDaclSecurityDescriptor
RtlSetEnvironmentVariable
RtlSetGroupSecurityDescriptor
RtlSetHeapInformation
RtlSetInformationAcl
RtlSetIoCompletionCallback
RtlSetOwnerSecurityDescriptor
RtlSetSaclSecurityDescriptor
RtlSetSecurityDescriptorRMControl
RtlSetSecurityObject
RtlSetSecurityObjectEx
RtlSetThreadPoolStartFunc
RtlSetTimeZoneInformation
RtlSetTimer
RtlSetUnicodeCallouts
RtlSetUserFlagsHeap
RtlSetUserValueHeap
RtlShutdownLpcServer
RtlSplay
RtlStartRXact
RtlStringFromGUID
RtlSubAuthorityCountSid
RtlSubAuthoritySid
RtlSubtreePredecessor
RtlSubtreeSuccessor
RtlSystemTimeToLocalTime
RtlTimeFieldsToTime
RtlTimeToElapsedTimeFields
RtlTimeToSecondsSince1970
RtlTimeToSecondsSince1980
RtlTimeToTimeFields
RtlTraceDatabaseAdd
RtlTraceDatabaseCreate
RtlTraceDatabaseDestroy
RtlTraceDatabaseEnumerate
RtlTraceDatabaseFind
RtlTraceDatabaseLock
RtlTraceDatabaseUnlock
RtlTraceDatabaseValidate
RtlTryEnterCriticalSection
RtlUnicodeStringToAnsiSize
RtlUnicodeStringToCountedOemString
RtlUnicodeStringToInteger
RtlUnicodeStringToOemSize
RtlUnicodeStringToOemString
RtlUnicodeToCustomCPN
RtlUnicodeToMultiByteSize
RtlUnicodeToOemN
RtlUniform
RtlUnlockHeap
RtlUpcaseUnicodeChar
RtlUpcaseUnicodeString
RtlUpcaseUnicodeStringToAnsiString
RtlUpcaseUnicodeStringToCountedOemString
RtlUpcaseUnicodeStringToOemString
RtlUpcaseUnicodeToCustomCPN
RtlUpcaseUnicodeToMultiByteN
RtlUpcaseUnicodeToOemN
RtlUpdateTimer
RtlUpperChar
RtlUpperString
RtlUsageHeap
RtlValidAcl
RtlValidRelativeSecurityDescriptor
RtlValidSecurityDescriptor
RtlValidSid
RtlValidateProcessHeaps
RtlVerifyVersionInfo
RtlWalkFrameChain
RtlWalkHeap
RtlWriteRegistryValue
RtlZeroHeap
RtlZeroMemory
RtlpNtCreateKey
RtlpNtEnumerateSubKey
RtlpNtMakeTemporaryKey
RtlpNtOpenKey
RtlpNtQueryValueKey
RtlpNtSetValueKey
RtlpUnWaitCriticalSection
RtlpWaitForCriticalSection
RtlxAnsiStringToUnicodeSize
RtlxOemStringToUnicodeSize
RtlxUnicodeStringToAnsiSize
RtlxUnicodeStringToOemSize
SaveEm87Context
VerSetConditionMask
ZwAcceptConnectPort
ZwAccessCheck
ZwAccessCheckAndAuditAlarm
ZwAccessCheckByType
ZwAccessCheckByTypeAndAuditAlarm
ZwAccessCheckByTypeResultList
ZwAccessCheckByTypeResultListAndAuditAlarm
ZwAccessCheckByTypeResultListAndAuditAlarmByHandle
ZwAddAtom
ZwAdjustGroupsToken
ZwAdjustPrivilegesToken
ZwAlertResumeThread
ZwAlertThread
ZwAllocateLocallyUniqueId
ZwAllocateUserPhysicalPages
ZwAllocateUuids
ZwAllocateVirtualMemory
ZwAreMappedFilesTheSame
ZwAssignProcessToJobObject
ZwCallbackReturn
ZwCancelDeviceWakeupRequest
ZwCancelIoFile
ZwCancelTimer
ZwClearEvent
ZwClose
ZwCloseObjectAuditAlarm
ZwCompleteConnectPort
ZwConnectPort
ZwContinue
ZwCreateChannel
ZwCreateDirectoryObject
ZwCreateEvent
ZwCreateEventPair
ZwCreateFile
ZwCreateIoCompletion
ZwCreateJobObject
ZwCreateKey
ZwCreateMailslotFile
ZwCreateMutant
ZwCreateNamedPipeFile
ZwCreatePagingFile
ZwCreatePort
ZwCreateProcess
ZwCreateProfile
ZwCreateSection
ZwCreateSemaphore
ZwCreateSymbolicLinkObject
ZwCreateThread
ZwCreateTimer
ZwCreateToken
ZwCreateWaitablePort
ZwDelayExecution
ZwDeleteAtom
ZwDeleteFile
ZwDeleteKey
ZwDeleteObjectAuditAlarm
ZwDeleteValueKey
ZwDeviceIoControlFile
ZwDisplayString
ZwDuplicateObject
ZwDuplicateToken
ZwEnumerateKey
ZwEnumerateValueKey
ZwExtendSection
ZwFilterToken
ZwFindAtom
ZwFlushBuffersFile
ZwFlushInstructionCache
ZwFlushKey
ZwFlushVirtualMemory
ZwFlushWriteBuffer
ZwFreeUserPhysicalPages
ZwFreeVirtualMemory
ZwFsControlFile
ZwGetContextThread
ZwGetDevicePowerState
ZwGetPlugPlayEvent
ZwGetTickCount
ZwGetWriteWatch
ZwImpersonateAnonymousToken
ZwImpersonateClientOfPort
ZwImpersonateThread
ZwInitializeRegistry
ZwInitiatePowerAction
ZwIsSystemResumeAutomatic
ZwListenChannel
ZwListenPort
ZwLoadDriver
ZwLoadKey2
ZwLoadKey
ZwLockFile
ZwLockVirtualMemory
ZwMakeTemporaryObject
ZwMapUserPhysicalPages
ZwMapUserPhysicalPagesScatter
ZwMapViewOfSection
ZwNotifyChangeDirectoryFile
ZwNotifyChangeKey
ZwNotifyChangeMultipleKeys
ZwOpenChannel
ZwOpenDirectoryObject
ZwOpenEvent
ZwOpenEventPair
ZwOpenFile
ZwOpenIoCompletion
ZwOpenJobObject
ZwOpenKey
ZwOpenMutant
ZwOpenObjectAuditAlarm
ZwOpenProcess
ZwOpenProcessToken
ZwOpenSection
ZwOpenSemaphore
ZwOpenSymbolicLinkObject
ZwOpenThread
ZwOpenThreadToken
ZwOpenTimer
ZwPlugPlayControl
ZwPowerInformation
ZwPrivilegeCheck
ZwPrivilegeObjectAuditAlarm
ZwPrivilegedServiceAuditAlarm
ZwProtectVirtualMemory
ZwPulseEvent
ZwQueryAttributesFile
ZwQueryDefaultLocale
ZwQueryDefaultUILanguage
ZwQueryDirectoryFile
ZwQueryDirectoryObject
ZwQueryEaFile
ZwQueryEvent
ZwQueryFullAttributesFile
ZwQueryInformationAtom
ZwQueryInformationFile
ZwQueryInformationJobObject
ZwQueryInformationPort
ZwQueryInformationProcess
ZwQueryInformationThread
ZwQueryInformationToken
ZwQueryInstallUILanguage
ZwQueryIntervalProfile
ZwQueryIoCompletion
ZwQueryKey
ZwQueryMultipleValueKey
ZwQueryMutant
ZwQueryObject
ZwQueryOpenSubKeys
ZwQueryPerformanceCounter
ZwQueryQuotaInformationFile
ZwQuerySection
ZwQuerySecurityObject
ZwQuerySemaphore
ZwQuerySymbolicLinkObject
ZwQuerySystemEnvironmentValue
ZwQuerySystemInformation
ZwQuerySystemTime
ZwQueryTimer
ZwQueryTimerResolution
ZwQueryValueKey
ZwQueryVirtualMemory
ZwQueryVolumeInformationFile
ZwQueueApcThread
ZwRaiseException
ZwRaiseHardError
ZwReadFile
ZwReadFileScatter
ZwReadRequestData
ZwReadVirtualMemory
ZwRegisterThreadTerminatePort
ZwReleaseMutant
ZwReleaseSemaphore
ZwRemoveIoCompletion
ZwReplaceKey
ZwReplyPort
ZwReplyWaitReceivePort
ZwReplyWaitReceivePortEx
ZwReplyWaitReplyPort
ZwReplyWaitSendChannel
ZwRequestDeviceWakeup
ZwRequestPort
ZwRequestWaitReplyPort
ZwRequestWakeupLatency
ZwResetEvent
ZwResetWriteWatch
ZwRestoreKey
ZwResumeThread
ZwSaveKey
ZwSaveMergedKeys
ZwSecureConnectPort
ZwSendWaitReplyChannel
ZwSetContextChannel
ZwSetContextThread
ZwSetDefaultHardErrorPort
ZwSetDefaultLocale
ZwSetDefaultUILanguage
ZwSetEaFile
ZwSetEvent
ZwSetHighEventPair
ZwSetHighWaitLowEventPair
ZwSetInformationFile
ZwSetInformationJobObject
ZwSetInformationKey
ZwSetInformationObject
ZwSetInformationProcess
ZwSetInformationThread
ZwSetInformationToken
ZwSetIntervalProfile
ZwSetIoCompletion
ZwSetLdtEntries
ZwSetLowEventPair
ZwSetLowWaitHighEventPair
ZwSetQuotaInformationFile
ZwSetSecurityObject
ZwSetSystemEnvironmentValue
ZwSetSystemInformation
ZwSetSystemPowerState
ZwSetSystemTime
ZwSetThreadExecutionState
ZwSetTimer
ZwSetTimerResolution
ZwSetUuidSeed
ZwSetValueKey
ZwSetVolumeInformationFile
ZwShutdownSystem
ZwSignalAndWaitForSingleObject
ZwStartProfile
ZwStopProfile
ZwSuspendThread
ZwSystemDebugControl
ZwTerminateJobObject
ZwTerminateProcess
ZwTerminateThread
ZwTestAlert
ZwUnloadDriver
ZwUnloadKey
ZwUnlockFile
ZwUnlockVirtualMemory
ZwUnmapViewOfSection
ZwVdmControl
ZwWaitForMultipleObjects
ZwWaitForSingleObject
ZwWaitHighEventPair
ZwWaitLowEventPair
ZwWriteFile
ZwWriteFileGather
ZwWriteRequestData
ZwWriteVirtualMemory
ZwYieldExecution
_CIpow
__eCommonExceptions
__eEmulatorInit
__eF2XM1
__eFABS
__eFADD32
__eFADD64
__eFADDPreg
__eFADDreg
__eFADDtop
__eFCHS
__eFCOM
__eFCOM32
__eFCOM64
__eFCOMP
__eFCOMP32
__eFCOMP64
__eFCOMPP
__eFCOS
__eFDECSTP
__eFDIV32
__eFDIV64
__eFDIVPreg
__eFDIVR32
__eFDIVR64
__eFDIVRPreg
__eFDIVRreg
__eFDIVRtop
__eFDIVreg
__eFDIVtop
__eFFREE
__eFIADD16
__eFIADD32
__eFICOM16
__eFICOM32
__eFICOMP16
__eFICOMP32
__eFIDIV16
__eFIDIV32
__eFIDIVR16
__eFIDIVR32
__eFILD16
__eFILD32
__eFILD64
__eFIMUL16
__eFIMUL32
__eFINCSTP
__eFINIT
__eFIST16
__eFIST32
__eFISTP16
__eFISTP32
__eFISTP64
__eFISUB16
__eFISUB32
__eFISUBR16
__eFISUBR32
__eFLD1
__eFLD32
__eFLD64
__eFLD80
__eFLDCW
__eFLDENV
__eFLDL2E
__eFLDLN2
__eFLDPI
__eFLDZ
__eFMUL32
__eFMUL64
__eFMULPreg
__eFMULreg
__eFMULtop
__eFPATAN
__eFPREM
__eFPREM1
__eFPTAN
__eFRNDINT
__eFRSTOR
__eFSAVE
__eFSCALE
__eFSIN
__eFSQRT
__eFST
__eFST32
__eFST64
__eFSTCW
__eFSTENV
__eFSTP
__eFSTP32
__eFSTP64
__eFSTP80
__eFSTSW
__eFSUB32
__eFSUB64
__eFSUBPreg
__eFSUBR32
__eFSUBR64
__eFSUBRPreg
__eFSUBRreg
__eFSUBRtop
__eFSUBreg
__eFSUBtop
__eFTST
__eFUCOM
__eFUCOMP
__eFUCOMPP
__eFXAM
__eFXCH
__eFXTRACT
__eFYL2X
__eFYL2XP1
__eGetStatusWord
__isascii
__iscsym
__iscsymf
__toascii
_alldiv
_allmul
_alloca_probe
_allrem
_allshl
_allshr
_atoi64
_aulldiv
_aullrem
_aullshr
_chkstk
_fltused
_ftol
_i64toa
_i64tow
_itoa
_itow
_ltoa
_ltow
_memccpy
_memicmp
_snprintf
_snwprintf
_splitpath
_strcmpi
_stricmp
_strlwr
_strnicmp
_strupr
_tolower
_toupper
_ui64toa
_ultoa
_ultow
_vsnprintf
_wcsicmp
_wcslwr
_wcsnicmp
_wcsupr
_wtoi
_wtoi64
_wtol
abs
atan
atoi
atol
ceil
cos
fabs
floor
isalnum
isalpha
iscntrl
isdigit
isgraph
islower
isprint
ispunct
isspace
isupper
iswalpha
iswctype
iswdigit
iswlower
iswspace
iswxdigit
isxdigit
labs
log
mbstowcs
memchr
memcmp
memcpy
memmove
memset
pow
qsort
sin
sprintf
sqrt
sscanf
strcat
strchr
strcmp
strcpy
strcspn
strlen
strncat
strncmp
strncpy
strpbrk
strrchr
strspn
strstr
strtol
strtoul
swprintf
tan
tolower
toupper
towlower
towupper
vsprintf
wcscat
wcschr
wcscmp
wcscpy
wcscspn
wcslen
wcsncat
wcsncmp
wcsncpy
wcspbrk
wcsrchr
wcsspn
wcsstr
wcstol
wcstombs
wcstoul

Found follow exports in USER32.DLL
AlignRects
AllowSetForegroundWindow
AnimateWindow
BlockInput
BroadcastSystemMessageA
BroadcastSystemMessageW
ChangeDisplaySettingsExA
ChangeDisplaySettingsExW
CliImmSetHotKey
ClientThreadSetup
CreateDialogIndirectParamAorW
CtxInitUser32
DdeGetQualityOfService
DeregisterShellHookWindow
DeviceEventWorker
DialogBoxIndirectParamAorW
DrawMenuBarTemp
EndMenu
EnumDisplayDevicesA
EnumDisplayDevicesW
EnumDisplayMonitors
EnumDisplaySettingsExA
EnumDisplaySettingsExW
FlashWindowEx
GetAltTabInfo
GetAltTabInfoA
GetAltTabInfoW
GetAncestor
GetAppCompatFlags2
GetAppCompatFlags
GetClipboardSequenceNumber
GetComboBoxInfo
GetCursorFrameInfo
GetCursorInfo
GetGUIThreadInfo
GetGuiResources
GetLastInputInfo
GetListBoxInfo
GetMenuBarInfo
GetMenuInfo
GetMonitorInfoA
GetMonitorInfoW
GetMouseMovePointsEx
GetProcessDefaultLayout
GetProgmanWindow
GetScrollBarInfo
GetTaskmanWindow
GetTitleBarInfo
GetWinStationInfo
GetWindowInfo
GetWindowModuleFileName
GetWindowModuleFileNameA
GetWindowModuleFileNameW
IMPGetIMEA
IMPGetIMEW
IMPQueryIMEA
IMPQueryIMEW
IMPSetIMEA
IMPSetIMEW
InSendMessageEx
InitializeLpkHooks
InitializeWin32EntryTable
IsHungAppWindow
KillSystemTimer
LoadKeyboardLayoutEx
LoadLocalFonts
LoadRemoteFonts
LockSetForegroundWindow
LockWorkStation
MBToWCSEx
MB_GetString
MenuWindowProcA
MenuWindowProcW
MonitorFromPoint
MonitorFromRect
MonitorFromWindow
MsgWaitForMultipleObjectsEx
NotifyWinEvent
PrivateExtractIconExA
PrivateExtractIconExW
PrivateExtractIconsA
PrivateExtractIconsW
PrivateSetDbgTag
PrivateSetRipFlags
QuerySendMessage
QueryUserCounters
RealChildWindowFromPoint
RealGetWindowClass
RealGetWindowClassA
RealGetWindowClassW
RegisterDeviceNotificationA
RegisterDeviceNotificationW
RegisterServicesProcess
RegisterShellHookWindow
ResolveDesktopForWOW
ScrollChildren
SendIMEMessageExA
SendIMEMessageExW
SendInput
SetConsoleReserveKeys
SetCursorContents
SetLayeredWindowAttributes
SetLogonNotifyWindow
SetMenuInfo
SetProcessDefaultLayout
SetProgmanWindow
SetShellWindowEx
SetSystemMenu
SetSystemTimer
SetTaskmanWindow
SetWinEventHook
SetWindowStationUser
ShowStartGlass
SoftModalMessageBox
ToUnicodeEx
TrackMouseEvent
TranslateMessageEx
UnhookWinEvent
UnregisterDeviceNotification
UpdateLayeredWindow
UpdatePerUserSystemParameters
User32InitializeImmEntryTable
UserHandleGrantAccess
UserLpkPSMTextOut
UserLpkTabbedTextOut
UserRealizePalette
UserRegisterWowHandlers
VRipOutput
VTagOutput
WCSToMBEx
WINNLSEnableIME
WINNLSGetEnableStatus
WINNLSGetIMEHotkey
Win32PoolAllocationStats

Found follow exports in GDI32.DLL
AddFontMemResourceEx
AddFontResourceExA
AddFontResourceExW
AddFontResourceTracking
AnyLinkedFonts
BRUSHOBJ_hGetColorTransform
BRUSHOBJ_pvAllocRbrush
BRUSHOBJ_pvGetRbrush
BRUSHOBJ_ulGetBrushColor
CLIPOBJ_bEnum
CLIPOBJ_cEnumStart
CLIPOBJ_ppoGetPath
ColorCorrectPalette
CreateFontIndirectExA
CreateFontIndirectExW
EnableEUDC
EndFormPage
EngAcquireSemaphore
EngAlphaBlend
EngAssociateSurface
EngBitBlt
EngCheckAbort
EngComputeGlyphSet
EngCopyBits
EngCreateBitmap
EngCreateClip
EngCreateDeviceBitmap
EngCreateDeviceSurface
EngCreatePalette
EngCreateSemaphore
EngDeleteClip
EngDeletePalette
EngDeletePath
EngDeleteSemaphore
EngDeleteSurface
EngEraseSurface
EngFillPath
EngFindResource
EngFreeModule
EngGetCurrentCodePage
EngGetDriverName
EngGetPrinterDataFileName
EngGradientFill
EngLineTo
EngLoadModule
EngLockSurface
EngMarkBandingSurface
EngMultiByteToUnicodeN
EngMultiByteToWideChar
EngPaint
EngPlgBlt
EngQueryEMFInfo
EngQueryLocalTime
EngReleaseSemaphore
EngStretchBlt
EngStretchBltROP
EngStrokeAndFillPath
EngStrokePath
EngTextOut
EngTransparentBlt
EngUnicodeToMultiByteN
EngUnlockSurface
EngWideCharToMultiByte
EudcLoadLinkW
EudcUnloadLinkW
FONTOBJ_cGetAllGlyphHandles
FONTOBJ_cGetGlyphs
FONTOBJ_pQueryGlyphAttrs
FONTOBJ_pfdg
FONTOBJ_pifi
FONTOBJ_pvTrueTypeFontFile
FONTOBJ_pxoGetXform
FONTOBJ_vGetInfo
FontIsLinked
GdiAddFontResourceW
GdiAddGlsBounds
GdiAddGlsRecord
GdiAlphaBlend
GdiArtificialDecrementDriver
GdiCleanCacheDC
GdiConsoleTextOut
GdiConvertAndCheckDC
GdiConvertBitmap
GdiConvertBitmapV5
GdiConvertBrush
GdiConvertDC
GdiConvertEnhMetaFile
GdiConvertFont
GdiConvertMetaFilePict
GdiConvertPalette
GdiConvertRegion
GdiConvertToDevmodeW
GdiCreateLocalEnhMetaFile
GdiCreateLocalMetaFilePict
GdiDeleteLocalDC
GdiDeleteSpoolFileHandle
GdiDescribePixelFormat
GdiDllInitialize
GdiEndDocEMF
GdiEndPageEMF
GdiEntry10
GdiEntry11
GdiEntry12
GdiEntry13
GdiEntry14
GdiEntry15
GdiEntry16
GdiEntry1
GdiEntry2
GdiEntry3
GdiEntry4
GdiEntry5
GdiEntry6
GdiEntry7
GdiEntry8
GdiEntry9
GdiFixUpHandle
GdiFullscreenControl
GdiGetCharDimensions
GdiGetCodePage
GdiGetDC
GdiGetDevmodeForPage
GdiGetLocalBrush
GdiGetLocalDC
GdiGetLocalFont
GdiGetPageCount
GdiGetPageHandle
GdiGetSpoolFileHandle
GdiGetSpoolMessage
GdiGradientFill
GdiInitSpool
GdiInitializeLanguagePack
GdiIsMetaFileDC
GdiIsMetaPrintDC
GdiIsPlayMetafileDC
GdiPlayEMF
GdiPlayPageEMF
GdiPlayPrivatePageEMF
GdiPrinterThunk
GdiProcessSetup
GdiQueryFonts
GdiQueryTable
GdiRealizationInfo
GdiReleaseDC
GdiReleaseLocalDC
GdiResetDCEMF
GdiSetAttrs
GdiSetLastError
GdiSetPixelFormat
GdiSetServerAttr
GdiStartDocEMF
GdiStartPageEMF
GdiSwapBuffers
GdiTransparentBlt
GdiValidateHandle
GetCharABCWidthsI
GetCharWidthI
GetCharWidthInfo
GetDCBrushColor
GetDCPenColor
GetETM
GetEUDCTimeStamp
GetEUDCTimeStampExW
GetEnhMetaFilePixelFormat
GetFontAssocStatus
GetFontResourceInfoW
GetFontUnicodeRanges
GetGlyphIndicesA
GetGlyphIndicesW
GetGlyphOutlineWow
GetHFONT
GetLayout
GetRelAbs
GetStringBitmapA
GetStringBitmapW
GetTextExtentExPointI
GetTextExtentExPointWPri
GetTextExtentPointI
GetTextFaceAliasW
GetTransform
HT_Get8BPPFormatPalette
HT_Get8BPPMaskPalette
IsValidEnhMetaRecord
IsValidEnhMetaRecordOffExt
MirrorRgn
NamedEscape
PATHOBJ_bEnum
PATHOBJ_bEnumClipLines
PATHOBJ_vEnumStart
PATHOBJ_vEnumStartClipLines
PATHOBJ_vGetBounds
PolyPatBlt
QueryFontAssocStatus
RemoveFontMemResourceEx
RemoveFontResourceExA
RemoveFontResourceExW
RemoveFontResourceTracking
STROBJ_bEnum
STROBJ_bEnumPositionsOnly
STROBJ_bGetAdvanceWidths
STROBJ_dwGetCodePage
STROBJ_vEnumStart
SelectBrushLocal
SelectFontLocal
SetDCBrushColor
SetDCPenColor
SetLayout
SetLayoutWidth
SetMagicColors
SetRelAbs
SetVirtualResolution
StartFormPage
UnloadNetworkFonts
XFORMOBJ_bApplyXform
XFORMOBJ_iGetXform
XLATEOBJ_cGetPalette
XLATEOBJ_hGetColorTransform
XLATEOBJ_iXlate
XLATEOBJ_piVector
bInitSystemAndFontsDirectoriesW
bMakePathNameW
cGetTTFFromFOT

Found follow exports in SHELL32.DLL
CheckEscapesA
Control_FillCache_RunDLL
Control_FillCache_RunDLLA
Control_FillCache_RunDLLW
Control_RunDLLA
Control_RunDLLAsUserW
Control_RunDLLW
DllCanUnloadNow
DllGetVersion
DllInstall
DllRegisterServer
DllUnregisterServer
ExtractIconExW
ExtractIconResInfoA
ExtractIconResInfoW
ExtractVersionResource16W
FindExeDlgProc
FixupOptionalComponents
OCInstall
OpenAs_RunDLLA
OpenAs_RunDLLW
PrintersGetCommand_RunDLLA
PrintersGetCommand_RunDLLW
SHBindToParent
SHBrowseForFolderW
SHChangeNotifySuspendResume
SHCreateDirectoryExA
SHCreateDirectoryExW
SHCreateProcessAsUserW
SheChangeDirExA
SheChangeDirW
SheConvertPathW
SheFullPathA
SheFullPathW
SheGetCurDrive
SheGetDirExW
SheGetDirW
SheGetPathOffsetW
Shell_NotifyIconW
ShellExec_RunDLL
ShellExec_RunDLLA
ShellExec_RunDLLW
ShellExecuteExW
ShellHookProc
SHEmptyRecycleBinA
SHEmptyRecycleBinW
SheRemoveQuotesA
SheRemoveQuotesW
SheShortenPathA
SheShortenPathW
SHExtractIconsW
SHFileOperationW
SHGetDataFromIDListW
SHGetDiskFreeSpaceA
SHGetDiskFreeSpaceExA
SHGetDiskFreeSpaceExW
SHGetFileInfoW
SHGetFolderLocation
SHGetFolderPathA
SHGetFolderPathW
SHGetIconOverlayIndexA
SHGetIconOverlayIndexW
SHGetNewLinkInfo
SHGetNewLinkInfoA
SHGetNewLinkInfoW
SHGetPathFromIDListW
SHGetSettings
SHGetSpecialFolderPathA
SHGetSpecialFolderPathW
SHHelpShortcuts_RunDLLA
SHHelpShortcuts_RunDLLW
SHInvokePrinterCommandA
SHInvokePrinterCommandW
SHIsFileAvailableOffline
SHLoadNonloadedIconOverlayIdentifiers
SHPathPrepareForWriteA
SHPathPrepareForWriteW
SHQueryRecycleBinA
SHQueryRecycleBinW
SHUpdateRecycleBinIcon
StrChrA
StrChrIA
StrChrIW
StrChrW
StrCmpNA
StrCmpNIA
StrCmpNIW
StrCmpNW
StrCpyNA
StrCpyNW
StrNCmpA
StrNCmpIA
StrNCmpIW
StrNCmpW
StrNCpyA
StrNCpyW
StrRChrA
StrRChrIA
StrRChrIW
StrRChrW
StrRStrA
StrRStrIA
StrRStrIW
StrRStrW
StrStrA
StrStrIA
StrStrIW
StrStrW
WOWShellExecute

Found follow exports in COMDLG32.DLL
dwLBSubclass
dwOKSubclass
LoadAlterBitmap
PrintDlgExA
PrintDlgExW
Ssync_ANSI_UNICODE_Struct_For_WOW
WantArrows

Found follow exports in COMCTL32.DLL
DllInstall
ImageList_GetFlags

Found follow exports in ADVAPI32.DLL
I_ScGetCurrentGroupStateW
I_ScIsSecurityProcess
IsInSandbox
AccessCheckByType
AccessCheckByTypeAndAuditAlarmA
AccessCheckByTypeAndAuditAlarmW
AccessCheckByTypeResultList
AccessCheckByTypeResultListAndAuditAlarmA
AccessCheckByTypeResultListAndAuditAlarmByHandleA
AccessCheckByTypeResultListAndAuditAlarmByHandleW
AccessCheckByTypeResultListAndAuditAlarmW
AddAccessAllowedAceEx
AddAccessAllowedObjectAce
AddAccessDeniedAceEx
AddAccessDeniedObjectAce
AddAuditAccessAceEx
AddAuditAccessObjectAce
AddUsersToEncryptedFile
BuildExplicitAccessWithNameA
BuildExplicitAccessWithNameW
BuildImpersonateExplicitAccessWithNameA
BuildImpersonateExplicitAccessWithNameW
BuildImpersonateTrusteeA
BuildImpersonateTrusteeW
BuildSecurityDescriptorA
BuildSecurityDescriptorW
BuildTrusteeWithNameA
BuildTrusteeWithNameW
BuildTrusteeWithObjectsAndNameA
BuildTrusteeWithObjectsAndNameW
BuildTrusteeWithObjectsAndSidA
BuildTrusteeWithObjectsAndSidW
BuildTrusteeWithSidA
BuildTrusteeWithSidW
CancelOverlappedAccess
ChangeServiceConfig2A
ChangeServiceConfig2W
CheckTokenMembership
CloseEncryptedFileRaw
CloseTrace
CommandLineFromMsiDescriptor
ControlTraceA
ControlTraceW
ConvertAccessToSecurityDescriptorA
ConvertAccessToSecurityDescriptorW
ConvertSDToStringSDRootDomainA
ConvertSDToStringSDRootDomainW
ConvertSecurityDescriptorToAccessA
ConvertSecurityDescriptorToAccessNamedA
ConvertSecurityDescriptorToAccessNamedW
ConvertSecurityDescriptorToAccessW
ConvertSecurityDescriptorToStringSecurityDescriptorA
ConvertSecurityDescriptorToStringSecurityDescriptorW
ConvertSidToStringSidA
ConvertSidToStringSidW
ConvertStringSDToSDRootDomainA
ConvertStringSDToSDRootDomainW
ConvertStringSecurityDescriptorToSecurityDescriptorA
ConvertStringSecurityDescriptorToSecurityDescriptorW
ConvertStringSidToSidA
ConvertStringSidToSidW
ConvertToAutoInheritPrivateObjectSecurity
CreatePrivateObjectSecurityEx
CreateProcessAsUserSecure
CreateProcessWithLogonW
CreateRestrictedToken
CreateTraceInstanceId
CreateWellKnownSid
CryptAcquireContextW
CryptContextAddRef
CryptDuplicateHash
CryptDuplicateKey
CryptEnumProviderTypesA
CryptEnumProviderTypesW
CryptEnumProvidersA
CryptEnumProvidersW
CryptGetDefaultProviderA
CryptGetDefaultProviderW
CryptSetProviderExA
CryptSetProviderExW
CryptSetProviderW
CryptSignHashW
CryptVerifySignatureW
DecryptFileA
DecryptFileW
DuplicateEncryptionInfoFile
DuplicateTokenEx
ElfBackupEventLogFileA
ElfBackupEventLogFileW
ElfChangeNotify
ElfClearEventLogFileA
ElfClearEventLogFileW
ElfCloseEventLog
ElfDeregisterEventSource
ElfFlushEventLog
ElfNumberOfRecords
ElfOldestRecord
ElfOpenBackupEventLogA
ElfOpenBackupEventLogW
ElfOpenEventLogA
ElfOpenEventLogW
ElfReadEventLogA
ElfReadEventLogW
ElfRegisterEventSourceA
ElfRegisterEventSourceW
ElfReportEventA
ElfReportEventW
EnableTrace
EncryptFileA
EncryptFileW
EncryptionDisable
EnumServiceGroupW
EnumServicesStatusExA
EnumServicesStatusExW
EqualDomainSid
FileEncryptionStatusA
FileEncryptionStatusW
FreeEncryptionCertificateHashList
GetAccessPermissionsForObjectA
GetAccessPermissionsForObjectW
GetAuditedPermissionsFromAclA
GetAuditedPermissionsFromAclW
GetCurrentHwProfileA
GetCurrentHwProfileW
GetEffectiveRightsFromAclA
GetEffectiveRightsFromAclW
GetEventLogInformation
GetExplicitEntriesFromAclA
GetExplicitEntriesFromAclW
GetLocalManagedApplications
GetManagedApplications
GetMangledSiteSid
GetMultipleTrusteeA
GetMultipleTrusteeOperationA
GetMultipleTrusteeOperationW
GetMultipleTrusteeW
GetNamedSecurityInfoA
GetNamedSecurityInfoExA
GetNamedSecurityInfoExW
GetNamedSecurityInfoW
GetOverlappedAccessResults
GetSecurityDescriptorRMControl
GetSecurityInfo
GetSecurityInfoExA
GetSecurityInfoExW
GetSiteDirectoryA
GetSiteDirectoryW
GetSiteNameFromSid
GetSiteSidFromToken
GetSiteSidFromUrl
GetTraceEnableFlags
GetTraceEnableLevel
GetTraceLoggerHandle
GetTrusteeFormA
GetTrusteeFormW
GetTrusteeNameA
GetTrusteeNameW
GetTrusteeTypeA
GetTrusteeTypeW
GetWindowsAccountDomainSid
I_ScPnPGetServiceName
I_ScSetServiceBitsA
I_ScSetServiceBitsW
ImpersonateAnonymousToken
InitiateSystemShutdownExA
InitiateSystemShutdownExW
InstallApplication
IsProcessRestricted
IsTokenRestricted
IsWellKnownSid
LookupSecurityDescriptorPartsA
LookupSecurityDescriptorPartsW
LsaAddAccountRights
LsaAddPrivilegesToAccount
LsaClearAuditLog
LsaClose
LsaCreateAccount
LsaCreateSecret
LsaCreateTrustedDomain
LsaCreateTrustedDomainEx
LsaDelete
LsaDeleteTrustedDomain
LsaEnumerateAccountRights
LsaEnumerateAccounts
LsaEnumerateAccountsWithUserRight
LsaEnumeratePrivileges
LsaEnumeratePrivilegesOfAccount
LsaEnumerateTrustedDomains
LsaEnumerateTrustedDomainsEx
LsaFreeMemory
LsaGetQuotasForAccount
LsaGetRemoteUserName
LsaGetSystemAccessAccount
LsaGetUserName
LsaICLookupNames
LsaICLookupSids
LsaLookupNames
LsaLookupPrivilegeDisplayName
LsaLookupPrivilegeName
LsaLookupPrivilegeValue
LsaLookupSids
LsaNtStatusToWinError
LsaOpenAccount
LsaOpenPolicy
LsaOpenPolicySce
LsaOpenSecret
LsaOpenTrustedDomain
LsaOpenTrustedDomainByName
LsaQueryDomainInformationPolicy
LsaQueryInfoTrustedDomain
LsaQueryInformationPolicy
LsaQuerySecret
LsaQuerySecurityObject
LsaQueryTrustedDomainInfo
LsaQueryTrustedDomainInfoByName
LsaRemoveAccountRights
LsaRemovePrivilegesFromAccount
LsaRetrievePrivateData
LsaSetDomainInformationPolicy
LsaSetInformationPolicy
LsaSetInformationTrustedDomain
LsaSetQuotasForAccount
LsaSetSecret
LsaSetSecurityObject
LsaSetSystemAccessAccount
LsaSetTrustedDomainInfoByName
LsaSetTrustedDomainInformation
LsaStorePrivateData
MakeAbsoluteSD2
ObjectDeleteAuditAlarmA
ObjectDeleteAuditAlarmW
OpenEncryptedFileRawA
OpenEncryptedFileRawW
OpenTraceA
OpenTraceW
ProcessTrace
QueryAllTracesA
QueryAllTracesW
QueryRecoveryAgentsOnEncryptedFile
QueryServiceConfig2A
QueryServiceConfig2W
QueryServiceStatusEx
QueryUsersOnEncryptedFile
QueryWindows31FilesMigration
ReadEncryptedFileRaw
RegDisablePredefinedCache
RegOpenCurrentUser
RegOpenUserClassesRoot
RegOverridePredefKey
RegisterServiceCtrlHandlerExA
RegisterServiceCtrlHandlerExW
RegisterTraceGuidsA
RegisterTraceGuidsW
RemoveTraceCallback
RemoveUsersFromEncryptedFile
SetEntriesInAccessListA
SetEntriesInAccessListW
SetEntriesInAclA
SetEntriesInAclW
SetEntriesInAuditListA
SetEntriesInAuditListW
SetNamedSecurityInfoA
SetNamedSecurityInfoExA
SetNamedSecurityInfoExW
SetNamedSecurityInfoW
SetPrivateObjectSecurityEx
SetSecurityDescriptorControl
SetSecurityDescriptorRMControl
SetSecurityInfo
SetSecurityInfoExA
SetSecurityInfoExW
SetTraceCallback
SetUserFileEncryptionKey
StartTraceA
StartTraceW
SynchronizeWindows31FilesAndWindowsNTRegistry
SystemFunction001
SystemFunction002
SystemFunction003
SystemFunction004
SystemFunction005
SystemFunction006
SystemFunction007
SystemFunction008
SystemFunction009
SystemFunction010
SystemFunction011
SystemFunction012
SystemFunction013
SystemFunction014
SystemFunction015
SystemFunction016
SystemFunction017
SystemFunction018
SystemFunction019
SystemFunction020
SystemFunction021
SystemFunction022
SystemFunction023
SystemFunction024
SystemFunction025
SystemFunction026
SystemFunction027
SystemFunction028
SystemFunction029
SystemFunction030
SystemFunction031
SystemFunction032
SystemFunction033
SystemFunction034
SystemFunction035
SystemFunction040
SystemFunction041
TraceEvent
TraceEventInstance
TrusteeAccessToObjectA
TrusteeAccessToObjectW
UninstallApplication
UnregisterTraceGuids
WmiCloseBlock
WmiDevInstToInstanceNameA
WmiDevInstToInstanceNameW
WmiEnumerateGuids
WmiExecuteMethodA
WmiExecuteMethodW
WmiFileHandleToInstanceNameA
WmiFileHandleToInstanceNameW
WmiFreeBuffer
WmiMofEnumerateResourcesA
WmiMofEnumerateResourcesW
WmiNotificationRegistrationA
WmiNotificationRegistrationW
WmiOpenBlock
WmiQueryAllDataA
WmiQueryAllDataW
WmiQueryGuidInformation
WmiQuerySingleInstanceA
WmiQuerySingleInstanceW
WmiSetSingleInstanceA
WmiSetSingleInstanceW
WmiSetSingleItemA
WmiSetSingleItemW
WriteEncryptedFileRaw

Found follow exports in WSOCK32.DLL
MigrateWinsockConfiguration
WEP
WSApSetPostRoutine
inet_network
getnetbyname
rcmd
rexec
rresvport
sethostname
AcceptEx
GetAcceptExSockaddrs

Found follow exports in WS2_32.DLL
accept
bind
closesocket
connect
getpeername
getsockname
getsockopt
htonl
htons
ioctlsocket
inet_addr
inet_ntoa
listen
ntohl
ntohs
recv
recvfrom
select
send
sendto
setsockopt
shutdown
socket
WSApSetPostRoutine
WPUCompleteOverlappedRequest
WSAAccept
WSAAddressToStringA
WSAAddressToStringW
WSACloseEvent
WSAConnect
WSACreateEvent
WSADuplicateSocketA
WSADuplicateSocketW
WSAEnumNameSpaceProvidersA
WSAEnumNameSpaceProvidersW
WSAEnumNetworkEvents
WSAEnumProtocolsA
WSAEnumProtocolsW
WSAEventSelect
WSAGetOverlappedResult
WSAGetQOSByName
WSAGetServiceClassInfoA
WSAGetServiceClassInfoW
WSAGetServiceClassNameByClassIdA
WSAGetServiceClassNameByClassIdW
WSAHtonl
WSAHtons
WSAInstallServiceClassA
WSAInstallServiceClassW
WSAIoctl
gethostbyaddr
gethostbyname
getprotobyname
getprotobynumber
getservbyname
getservbyport
gethostname
WSAJoinLeaf
WSALookupServiceBeginA
WSALookupServiceBeginW
WSALookupServiceEnd
WSALookupServiceNextA
WSALookupServiceNextW
WSANtohl
WSANtohs
WSAProviderConfigChange
WSARecv
WSARecvDisconnect
WSARecvFrom
WSARemoveServiceClass
WSAResetEvent
WSASend
WSASendDisconnect
WSASendTo
WSASetEvent
WSASetServiceA
WSASetServiceW
WSASocketA
WSASocketW
WSAStringToAddressA
WSAStringToAddressW
WSAWaitForMultipleEvents
WSCDeinstallProvider
WSCEnableNSProvider
WSCEnumProtocols
WSCGetProviderPath
WSCInstallNameSpace
WSCInstallProvider
WSCUnInstallNameSpace
WSCWriteNameSpaceOrder
WSCWriteProviderOrder
WSAAsyncSelect
WSAAsyncGetHostByAddr
WSAAsyncGetHostByName
WSAAsyncGetProtoByNumber
WSAAsyncGetProtoByName
WSAAsyncGetServByPort
WSAAsyncGetServByName
WSACancelAsyncRequest
WSASetBlockingHook
WSAUnhookBlockingHook
WSAGetLastError
WSASetLastError
WSACancelBlockingCall
WSAIsBlocking
WSAStartup
WSACleanup
__WSAFDIsSet
WEP

Windows XPsp1


Found follow exports in KERNEL32.DLL
ActivateActCtx
AddConsoleAliasA
AddConsoleAliasW
AddLocalAlternateComputerNameA
AddLocalAlternateComputerNameW
AddRefActCtx
AddVectoredExceptionHandler
AllocateUserPhysicalPages
AssignProcessToJobObject
AttachConsole
BaseCheckAppcompatCache
BaseCleanupAppcompatCache
BaseCleanupAppcompatCacheSupport
BaseDumpAppcompatCache
BaseFlushAppcompatCache
BaseInitAppcompatCache
BaseInitAppcompatCacheSupport
BaseProcessInitPostImport
BaseUpdateAppcompatCache
BindIoCompletionCallback
CancelDeviceWakeupRequest
CancelIo
CancelTimerQueueTimer
CancelWaitableTimer
ChangeTimerQueueTimer
CheckNameLegalDOS8Dot3A
CheckNameLegalDOS8Dot3W
CheckRemoteDebuggerPresent
CloseConsoleHandle
CmdBatNotification
ConsoleMenuControl
ConvertFiberToThread
ConvertThreadToFiber
CopyFileExA
CopyFileExW
CopyLZFile
CreateActCtxA
CreateActCtxW
CreateFiber
CreateFiberEx
CreateHardLinkA
CreateHardLinkW
CreateJobObjectA
CreateJobObjectW
CreateJobSet
CreateMemoryResourceNotification
CreateNlsSecurityDescriptor
CreateProcessInternalA
CreateProcessInternalW
CreateSocketHandle
CreateTimerQueue
CreateTimerQueueTimer
CreateToolhelp32Snapshot
CreateVirtualBuffer
CreateWaitableTimerA
CreateWaitableTimerW
DeactivateActCtx
DebugActiveProcessStop
DebugBreakProcess
DebugSetProcessKillOnExit
DelayLoadFailureHook
DeleteFiber
DeleteTimerQueue
DeleteTimerQueueEx
DeleteTimerQueueTimer
DeleteVolumeMountPointA
DeleteVolumeMountPointW
DnsHostnameToComputerNameA
DnsHostnameToComputerNameW
DosPathToSessionPathA
DosPathToSessionPathW
DuplicateConsoleHandle
EnumCalendarInfoExA
EnumCalendarInfoExW
EnumDateFormatsExA
EnumDateFormatsExW
EnumLanguageGroupLocalesA
EnumLanguageGroupLocalesW
EnumSystemGeoID
EnumSystemLanguageGroupsA
EnumSystemLanguageGroupsW
EnumUILanguagesA
EnumUILanguagesW
EnumerateLocalComputerNamesA
EnumerateLocalComputerNamesW
ExitVDM
ExpungeConsoleCommandHistoryA
ExpungeConsoleCommandHistoryW
ExtendVirtualBuffer
FindActCtxSectionGuid
FindActCtxSectionStringA
FindActCtxSectionStringW
FindFirstFileExA
FindFirstFileExW
FindFirstVolumeA
FindFirstVolumeMountPointA
FindFirstVolumeMountPointW
FindFirstVolumeW
FindNextVolumeA
FindNextVolumeMountPointA
FindNextVolumeMountPointW
FindNextVolumeW
FindVolumeClose
FindVolumeMountPointClose
FreeUserPhysicalPages
FreeVirtualBuffer
GetCPFileNameFromRegistry
GetCPInfoExA
GetCPInfoExW
GetCalendarInfoA
GetCalendarInfoW
GetComPlusPackageInstallStatus
GetComputerNameExA
GetComputerNameExW
GetConsoleAliasA
GetConsoleAliasExesA
GetConsoleAliasExesLengthA
GetConsoleAliasExesLengthW
GetConsoleAliasExesW
GetConsoleAliasW
GetConsoleAliasesA
GetConsoleAliasesLengthA
GetConsoleAliasesLengthW
GetConsoleAliasesW
GetConsoleCharType
GetConsoleCommandHistoryA
GetConsoleCommandHistoryLengthA
GetConsoleCommandHistoryLengthW
GetConsoleCommandHistoryW
GetConsoleCursorMode
GetConsoleDisplayMode
GetConsoleFontInfo
GetConsoleFontSize
GetConsoleHardwareState
GetConsoleInputExeNameA
GetConsoleInputExeNameW
GetConsoleInputWaitHandle
GetConsoleKeyboardLayoutNameA
GetConsoleKeyboardLayoutNameW
GetConsoleNlsMode
GetConsoleProcessList
GetConsoleSelectionInfo
GetConsoleWindow
GetCurrentActCtx
GetCurrentConsoleFont
GetDefaultSortkeySize
GetDevicePowerState
GetDllDirectoryA
GetDllDirectoryW
GetExpandedNameA
GetExpandedNameW
GetFileAttributesExA
GetFileAttributesExW
GetFileSizeEx
GetFirmwareEnvironmentVariableA
GetFirmwareEnvironmentVariableW
GetGeoInfoA
GetGeoInfoW
GetHandleContext
GetLinguistLangSize
GetLongPathNameA
GetLongPathNameW
GetModuleHandleExA
GetModuleHandleExW
GetNativeSystemInfo
GetNextVDMCommand
GetNlsSectionName
GetNumaAvailableMemory
GetNumaAvailableMemoryNode
GetNumaHighestNodeNumber
GetNumaNodeProcessorMask
GetNumaProcessorMap
GetNumaProcessorNode
GetNumberOfConsoleFonts
GetProcessHandleCount
GetProcessId
GetProcessIoCounters
GetProcessPriorityBoost
GetSystemDefaultUILanguage
GetSystemRegistryQuota
GetSystemTimes
GetSystemWindowsDirectoryA
GetSystemWindowsDirectoryW
GetSystemWow64DirectoryA
GetSystemWow64DirectoryW
GetThreadIOPendingFlag
GetThreadPriorityBoost
GetUserDefaultUILanguage
GetUserGeoID
GetVDMCurrentDirectories
GetVolumeNameForVolumeMountPointA
GetVolumeNameForVolumeMountPointW
GetVolumePathNameA
GetVolumePathNameW
GetVolumePathNamesForVolumeNameA
GetVolumePathNamesForVolumeNameW
GetWriteWatch
GlobalMemoryStatusEx
Heap32First
Heap32ListFirst
Heap32ListNext
Heap32Next
HeapCreateTagsW
HeapExtend
HeapQueryInformation
HeapQueryTagW
HeapSetInformation
HeapSummary
HeapUsage
InitializeCriticalSectionAndSpinCount
InitializeSListHead
InterlockedCompareExchange
InterlockedExchangeAdd
InterlockedFlushSList
InterlockedPopEntrySList
InterlockedPushEntrySList
InvalidateConsoleDIBits
IsDebuggerPresent
IsProcessInJob
IsProcessorFeaturePresent
IsSystemResumeAutomatic
IsValidLanguageGroup
IsValidUILanguage
IsWow64Process
LZClose
LZCloseFile
LZCopy
LZCreateFileW
LZDone
LZInit
LZOpenFileA
LZOpenFileW
LZRead
LZSeek
LZStart
MapUserPhysicalPages
MapUserPhysicalPagesScatter
Module32First
Module32FirstW
Module32Next
Module32NextW
MoveFileWithProgressA
MoveFileWithProgressW
NlsConvertIntegerToString
NlsGetCacheUpdateCount
NlsResetProcessLocale
NumaVirtualQueryNode
OpenConsoleW
OpenDataFile
OpenJobObjectA
OpenJobObjectW
OpenThread
OpenWaitableTimerA
OpenWaitableTimerW
PrivCopyFileExW
PrivMoveFileIdentityW
Process32First
Process32FirstW
Process32Next
Process32NextW
ProcessIdToSessionId
QueryActCtxW
QueryDepthSList
QueryInformationJobObject
QueryMemoryResourceNotification
QueryWin31IniFilesMappedToRegistry
QueueUserWorkItem
ReadConsoleInputExA
ReadConsoleInputExW
ReadDirectoryChangesW
ReadFileScatter
RegisterConsoleIME
RegisterConsoleOS2
RegisterConsoleVDM
RegisterWaitForInputIdle
RegisterWaitForSingleObject
RegisterWaitForSingleObjectEx
RegisterWowBaseHandlers
RegisterWowExec
ReleaseActCtx
RemoveLocalAlternateComputerNameA
RemoveLocalAlternateComputerNameW
RemoveVectoredExceptionHandler
ReplaceFile
ReplaceFileA
ReplaceFileW
RequestDeviceWakeup
RequestWakeupLatency
ResetWriteWatch
RestoreLastError
RtlCaptureContext
RtlCaptureStackBackTrace
SetCPGlobal
SetCalendarInfoA
SetCalendarInfoW
SetClientTimeZoneInformation
SetComPlusPackageInstallStatus
SetComputerNameExA
SetComputerNameExW
SetConsoleCommandHistoryMode
SetConsoleCursor
SetConsoleCursorMode
SetConsoleDisplayMode
SetConsoleFont
SetConsoleHardwareState
SetConsoleIcon
SetConsoleInputExeNameA
SetConsoleInputExeNameW
SetConsoleKeyShortcuts
SetConsoleLocalEUDC
SetConsoleMaximumWindowSize
SetConsoleMenuClose
SetConsoleNlsMode
SetConsoleNumberOfCommandsA
SetConsoleNumberOfCommandsW
SetConsoleOS2OemFormat
SetConsolePalette
SetCriticalSectionSpinCount
SetDllDirectoryA
SetDllDirectoryW
SetFilePointerEx
SetFileShortNameA
SetFileShortNameW
SetFileValidData
SetFirmwareEnvironmentVariableA
SetFirmwareEnvironmentVariableW
SetHandleContext
SetInformationJobObject
SetLastConsoleEventActive
SetLocalPrimaryComputerNameA
SetLocalPrimaryComputerNameW
SetMessageWaitingIndicator
SetProcessAffinityMask
SetProcessPriorityBoost
SetTermsrvAppInstallMode
SetThreadExecutionState
SetThreadIdealProcessor
SetThreadPriorityBoost
SetThreadUILanguage
SetTimerQueueTimer
SetUserGeoID
SetVDMCurrentDirectories
SetVolumeMountPointA
SetVolumeMountPointW
SetWaitableTimer
ShowConsoleCursor
SignalObjectAndWait
SwitchToFiber
SwitchToThread
TerminateJobObject
TermsrvAppInstallMode
Thread32First
Thread32Next
Toolhelp32ReadProcessMemory
TrimVirtualBuffer
TryEnterCriticalSection
TzSpecificLocalTimeToSystemTime
UTRegister
UTUnRegister
UnregisterConsoleIME
UnregisterWait
UnregisterWaitEx
VDMConsoleOperation
VDMOperationStarted
ValidateLCType
ValidateLocale
VerSetConditionMask
VerifyConsoleIoHandle
VerifyVersionInfoA
VerifyVersionInfoW
VirtualAllocEx
VirtualBufferExceptionHandler
VirtualFreeEx
WTSGetActiveConsoleSessionId
WriteConsoleInputVDMA
WriteConsoleInputVDMW
WriteFileGather
ZombifyActCtx

Found follow exports in NTDLL.DLL
PropertyLengthAsVariant
RtlConvertPropertyToVariant
RtlConvertVariantToProperty
RtlInterlockedPushListSList
RtlUlongByteSwap
RtlUlonglongByteSwap
RtlUshortByteSwap
CsrAllocateCaptureBuffer
CsrAllocateMessagePointer
CsrCaptureMessageBuffer
CsrCaptureMessageMultiUnicodeStringsInPlace
CsrCaptureMessageString
CsrCaptureTimeout
CsrClientCallServer
CsrClientConnectToServer
CsrFreeCaptureBuffer
CsrGetProcessId
CsrIdentifyAlertableThread
CsrNewThread
CsrProbeForRead
CsrProbeForWrite
CsrSetPriorityClass
DbgPrintEx
DbgPrintReturnControlC
DbgQueryDebugFilterState
DbgSetDebugFilterState
DbgUiConnectToDbg
DbgUiContinue
DbgUiConvertStateChangeStructure
DbgUiDebugActiveProcess
DbgUiGetThreadDebugObject
DbgUiIssueRemoteBreakin
DbgUiRemoteBreakin
DbgUiSetThreadDebugObject
DbgUiStopDebugging
DbgUiWaitStateChange
DbgUserBreakPoint
KiRaiseUserExceptionDispatcher
KiUserApcDispatcher
KiUserCallbackDispatcher
KiUserExceptionDispatcher
LdrAccessOutOfProcessResource
LdrAccessResource
LdrAddRefDll
LdrAlternateResourcesEnabled
LdrCreateOutOfProcessImage
LdrDestroyOutOfProcessImage
LdrDisableThreadCalloutsForDll
LdrEnumResources
LdrEnumerateLoadedModules
LdrFindCreateProcessManifest
LdrFindEntryForAddress
LdrFindResourceDirectory_U
LdrFindResourceEx_U
LdrFindResource_U
LdrFlushAlternateResourceModules
LdrGetDllHandle
LdrGetDllHandleEx
LdrGetProcedureAddress
LdrInitShimEngineDynamic
LdrInitializeThunk
LdrLoadAlternateResourceModule
LdrLoadDll
LdrLockLoaderLock
LdrProcessRelocationBlock
LdrQueryImageFileExecutionOptions
LdrQueryProcessModuleInformation
LdrSetAppCompatDllRedirectionCallback
LdrSetDllManifestProber
LdrShutdownProcess
LdrShutdownThread
LdrUnloadAlternateResourceModule
LdrUnloadDll
LdrUnlockLoaderLock
LdrVerifyImageMatchesChecksum
NlsAnsiCodePage
NlsMbCodePageTag
NlsMbOemCodePageTag
NtAcceptConnectPort
NtAccessCheck
NtAccessCheckAndAuditAlarm
NtAccessCheckByType
NtAccessCheckByTypeAndAuditAlarm
NtAccessCheckByTypeResultList
NtAccessCheckByTypeResultListAndAuditAlarm
NtAccessCheckByTypeResultListAndAuditAlarmByHandle
NtAddAtom
NtAddBootEntry
NtAdjustGroupsToken
NtAdjustPrivilegesToken
NtAlertResumeThread
NtAlertThread
NtAllocateLocallyUniqueId
NtAllocateUserPhysicalPages
NtAllocateUuids
NtAllocateVirtualMemory
NtAreMappedFilesTheSame
NtAssignProcessToJobObject
NtCallbackReturn
NtCancelDeviceWakeupRequest
NtCancelIoFile
NtCancelTimer
NtClearEvent
NtClose
NtCloseObjectAuditAlarm
NtCompactKeys
NtCompareTokens
NtCompleteConnectPort
NtCompressKey
NtConnectPort
NtContinue
NtCreateDebugObject
NtCreateDirectoryObject
NtCreateEvent
NtCreateEventPair
NtCreateFile
NtCreateIoCompletion
NtCreateJobObject
NtCreateJobSet
NtCreateKey
NtCreateKeyedEvent
NtCreateMailslotFile
NtCreateMutant
NtCreateNamedPipeFile
NtCreatePagingFile
NtCreatePort
NtCreateProcess
NtCreateProcessEx
NtCreateProfile
NtCreateSection
NtCreateSemaphore
NtCreateSymbolicLinkObject
NtCreateThread
NtCreateTimer
NtCreateToken
NtCreateWaitablePort
NtDebugActiveProcess
NtDebugContinue
NtDelayExecution
NtDeleteAtom
NtDeleteBootEntry
NtDeleteFile
NtDeleteKey
NtDeleteObjectAuditAlarm
NtDeleteValueKey
NtDeviceIoControlFile
NtDisplayString
NtDuplicateObject
NtDuplicateToken
NtEnumerateBootEntries
NtEnumerateKey
NtEnumerateSystemEnvironmentValuesEx
NtEnumerateValueKey
NtExtendSection
NtFilterToken
NtFindAtom
NtFlushBuffersFile
NtFlushInstructionCache
NtFlushKey
NtFlushVirtualMemory
NtFlushWriteBuffer
NtFreeUserPhysicalPages
NtFreeVirtualMemory
NtFsControlFile
NtGetContextThread
NtGetDevicePowerState
NtGetPlugPlayEvent
NtGetWriteWatch
NtImpersonateAnonymousToken
NtImpersonateClientOfPort
NtImpersonateThread
NtInitializeRegistry
NtInitiatePowerAction
NtIsProcessInJob
NtIsSystemResumeAutomatic
NtListenPort
NtLoadDriver
NtLoadKey2
NtLoadKey
NtLockFile
NtLockProductActivationKeys
NtLockRegistryKey
NtLockVirtualMemory
NtMakePermanentObject
NtMakeTemporaryObject
NtMapUserPhysicalPages
NtMapUserPhysicalPagesScatter
NtMapViewOfSection
NtModifyBootEntry
NtNotifyChangeDirectoryFile
NtNotifyChangeKey
NtNotifyChangeMultipleKeys
NtOpenDirectoryObject
NtOpenEvent
NtOpenEventPair
NtOpenFile
NtOpenIoCompletion
NtOpenJobObject
NtOpenKey
NtOpenKeyedEvent
NtOpenMutant
NtOpenObjectAuditAlarm
NtOpenProcess
NtOpenProcessToken
NtOpenProcessTokenEx
NtOpenSection
NtOpenSemaphore
NtOpenSymbolicLinkObject
NtOpenThread
NtOpenThreadToken
NtOpenThreadTokenEx
NtOpenTimer
NtPlugPlayControl
NtPowerInformation
NtPrivilegeCheck
NtPrivilegeObjectAuditAlarm
NtPrivilegedServiceAuditAlarm
NtProtectVirtualMemory
NtPulseEvent
NtQueryAttributesFile
NtQueryBootEntryOrder
NtQueryBootOptions
NtQueryDebugFilterState
NtQueryDefaultLocale
NtQueryDefaultUILanguage
NtQueryDirectoryFile
NtQueryDirectoryObject
NtQueryEaFile
NtQueryEvent
NtQueryFullAttributesFile
NtQueryInformationAtom
NtQueryInformationFile
NtQueryInformationJobObject
NtQueryInformationPort
NtQueryInformationProcess
NtQueryInformationThread
NtQueryInformationToken
NtQueryInstallUILanguage
NtQueryIntervalProfile
NtQueryIoCompletion
NtQueryKey
NtQueryMultipleValueKey
NtQueryMutant
NtQueryObject
NtQueryOpenSubKeys
NtQueryPortInformationProcess
NtQueryQuotaInformationFile
NtQuerySection
NtQuerySecurityObject
NtQuerySemaphore
NtQuerySymbolicLinkObject
NtQuerySystemEnvironmentValue
NtQuerySystemEnvironmentValueEx
NtQuerySystemInformation
NtQuerySystemTime
NtQueryTimer
NtQueryTimerResolution
NtQueryValueKey
NtQueryVirtualMemory
NtQueryVolumeInformationFile
NtQueueApcThread
NtRaiseException
NtRaiseHardError
NtReadFile
NtReadFileScatter
NtReadRequestData
NtReadVirtualMemory
NtRegisterThreadTerminatePort
NtReleaseKeyedEvent
NtReleaseMutant
NtReleaseSemaphore
NtRemoveIoCompletion
NtRemoveProcessDebug
NtRenameKey
NtReplaceKey
NtReplyPort
NtReplyWaitReceivePort
NtReplyWaitReceivePortEx
NtReplyWaitReplyPort
NtRequestDeviceWakeup
NtRequestPort
NtRequestWaitReplyPort
NtRequestWakeupLatency
NtResetEvent
NtResetWriteWatch
NtRestoreKey
NtResumeProcess
NtResumeThread
NtSaveKey
NtSaveKeyEx
NtSaveMergedKeys
NtSecureConnectPort
NtSetBootEntryOrder
NtSetBootOptions
NtSetContextThread
NtSetDebugFilterState
NtSetDefaultHardErrorPort
NtSetDefaultLocale
NtSetDefaultUILanguage
NtSetEaFile
NtSetEvent
NtSetEventBoostPriority
NtSetHighEventPair
NtSetHighWaitLowEventPair
NtSetInformationDebugObject
NtSetInformationFile
NtSetInformationJobObject
NtSetInformationKey
NtSetInformationObject
NtSetInformationProcess
NtSetInformationThread
NtSetInformationToken
NtSetIntervalProfile
NtSetIoCompletion
NtSetLdtEntries
NtSetLowEventPair
NtSetLowWaitHighEventPair
NtSetQuotaInformationFile
NtSetSecurityObject
NtSetSystemEnvironmentValue
NtSetSystemEnvironmentValueEx
NtSetSystemInformation
NtSetSystemPowerState
NtSetSystemTime
NtSetThreadExecutionState
NtSetTimer
NtSetTimerResolution
NtSetUuidSeed
NtSetValueKey
NtSetVolumeInformationFile
NtShutdownSystem
NtSignalAndWaitForSingleObject
NtStartProfile
NtStopProfile
NtSuspendProcess
NtSuspendThread
NtSystemDebugControl
NtTerminateJobObject
NtTerminateProcess
NtTerminateThread
NtTestAlert
NtTraceEvent
NtTranslateFilePath
NtUnloadDriver
NtUnloadKey
NtUnloadKeyEx
NtUnlockFile
NtUnlockVirtualMemory
NtUnmapViewOfSection
NtVdmControl
NtWaitForDebugEvent
NtWaitForKeyedEvent
NtWaitForMultipleObjects
NtWaitForSingleObject
NtWaitHighEventPair
NtWaitLowEventPair
NtWriteFile
NtWriteFileGather
NtWriteRequestData
NtWriteVirtualMemory
NtYieldExecution
PfxFindPrefix
PfxInitialize
PfxInsertPrefix
PfxRemovePrefix
RestoreEm87Context
RtlAbortRXact
RtlAbsoluteToSelfRelativeSD
RtlAcquirePebLock
RtlAcquireResourceExclusive
RtlAcquireResourceShared
RtlActivateActivationContext
RtlActivateActivationContextEx
RtlActivateActivationContextUnsafeFast
RtlAddAccessAllowedAce
RtlAddAccessAllowedAceEx
RtlAddAccessAllowedObjectAce
RtlAddAccessDeniedAce
RtlAddAccessDeniedAceEx
RtlAddAccessDeniedObjectAce
RtlAddAce
RtlAddActionToRXact
RtlAddAtomToAtomTable
RtlAddAttributeActionToRXact
RtlAddAuditAccessAce
RtlAddAuditAccessAceEx
RtlAddAuditAccessObjectAce
RtlAddCompoundAce
RtlAddRange
RtlAddRefActivationContext
RtlAddRefMemoryStream
RtlAddVectoredExceptionHandler
RtlAddressInSectionTable
RtlAdjustPrivilege
RtlAllocateAndInitializeSid
RtlAllocateHandle
RtlAnsiCharToUnicodeChar
RtlAnsiStringToUnicodeSize
RtlAppendAsciizToString
RtlAppendPathElement
RtlAppendStringToString
RtlAppendUnicodeStringToString
RtlAppendUnicodeToString
RtlApplicationVerifierStop
RtlApplyRXact
RtlApplyRXactNoFlush
RtlAreAllAccessesGranted
RtlAreAnyAccessesGranted
RtlAreBitsClear
RtlAreBitsSet
RtlAssert2
RtlAssert
RtlCancelTimer
RtlCaptureContext
RtlCaptureStackBackTrace
RtlCaptureStackContext
RtlCharToInteger
RtlCheckForOrphanedCriticalSections
RtlCheckProcessParameters
RtlCheckRegistryKey
RtlClearAllBits
RtlClearBits
RtlCloneMemoryStream
RtlCommitMemoryStream
RtlCompactHeap
RtlCompareMemory
RtlCompareMemoryUlong
RtlCompareString
RtlCompareUnicodeString
RtlCompressBuffer
RtlComputeCrc32
RtlComputeImportTableHash
RtlComputePrivatizedDllName_U
RtlConsoleMultiByteToUnicodeN
RtlConvertExclusiveToShared
RtlConvertSharedToExclusive
RtlConvertSidToUnicodeString
RtlConvertToAutoInheritSecurityObject
RtlConvertUiListToApiList
RtlCopyLuid
RtlCopyLuidAndAttributesArray
RtlCopyMemoryStreamTo
RtlCopyOutOfProcessMemoryStreamTo
RtlCopyRangeList
RtlCopySecurityDescriptor
RtlCopySid
RtlCopySidAndAttributesArray
RtlCopyString
RtlCopyUnicodeString
RtlCreateAcl
RtlCreateActivationContext
RtlCreateAndSetSD
RtlCreateAtomTable
RtlCreateBootStatusDataFile
RtlCreateEnvironment
RtlCreateProcessParameters
RtlCreateQueryDebugBuffer
RtlCreateRegistryKey
RtlCreateSecurityDescriptor
RtlCreateSystemVolumeInformationFolder
RtlCreateTagHeap
RtlCreateTimer
RtlCreateTimerQueue
RtlCreateUnicodeString
RtlCreateUnicodeStringFromAsciiz
RtlCreateUserProcess
RtlCreateUserSecurityObject
RtlCreateUserThread
RtlCustomCPToUnicodeN
RtlCutoverTimeToSystemTime
RtlDeNormalizeProcessParams
RtlDeactivateActivationContext
RtlDeactivateActivationContextUnsafeFast
RtlDebugPrintTimes
RtlDecompressBuffer
RtlDecompressFragment
RtlDefaultNpAcl
RtlDelete
RtlDeleteAce
RtlDeleteAtomFromAtomTable
RtlDeleteCriticalSection
RtlDeleteElementGenericTable
RtlDeleteElementGenericTableAvl
RtlDeleteNoSplay
RtlDeleteOwnersRanges
RtlDeleteRange
RtlDeleteRegistryValue
RtlDeleteResource
RtlDeleteSecurityObject
RtlDeleteTimer
RtlDeleteTimerQueue
RtlDeleteTimerQueueEx
RtlDeregisterWait
RtlDeregisterWaitEx
RtlDestroyAtomTable
RtlDestroyEnvironment
RtlDestroyHandleTable
RtlDestroyProcessParameters
RtlDestroyQueryDebugBuffer
RtlDetermineDosPathNameType_U
RtlDllShutdownInProgress
RtlDnsHostNameToComputerName
RtlDoesFileExists_U
RtlDosApplyFileIsolationRedirection_Ustr
RtlDosPathNameToNtPathName_U
RtlDosSearchPath_U
RtlDosSearchPath_Ustr
RtlDowncaseUnicodeChar
RtlDowncaseUnicodeString
RtlDumpResource
RtlDuplicateUnicodeString
RtlEmptyAtomTable
RtlEnableEarlyCriticalSectionEventCreation
RtlEnterCriticalSection
RtlEnumProcessHeaps
RtlEnumerateGenericTable
RtlEnumerateGenericTableAvl
RtlEnumerateGenericTableLikeADirectory
RtlEnumerateGenericTableWithoutSplaying
RtlEnumerateGenericTableWithoutSplayingAvl
RtlEqualComputerName
RtlEqualDomainName
RtlEqualLuid
RtlEqualPrefixSid
RtlEqualSid
RtlEqualString
RtlEqualUnicodeString
RtlEraseUnicodeString
RtlExitUserThread
RtlExpandEnvironmentStrings_U
RtlExtendHeap
RtlFillMemory
RtlFillMemoryUlong
RtlFinalReleaseOutOfProcessMemoryStream
RtlFindActivationContextSectionGuid
RtlFindActivationContextSectionString
RtlFindCharInUnicodeString
RtlFindClearBits
RtlFindClearBitsAndSet
RtlFindClearRuns
RtlFindLastBackwardRunClear
RtlFindLeastSignificantBit
RtlFindLongestRunClear
RtlFindMessage
RtlFindMostSignificantBit
RtlFindNextForwardRunClear
RtlFindRange
RtlFindSetBits
RtlFindSetBitsAndClear
RtlFirstEntrySList
RtlFirstFreeAce
RtlFlushSecureMemoryCache
RtlFormatCurrentUserKeyPath
RtlFormatMessage
RtlFreeAnsiString
RtlFreeHandle
RtlFreeOemString
RtlFreeRangeList
RtlFreeSid
RtlFreeThreadActivationContextStack
RtlFreeUnicodeString
RtlFreeUserThreadStack
RtlGUIDFromString
RtlGenerate8dot3Name
RtlGetAce
RtlGetActiveActivationContext
RtlGetCallersAddress
RtlGetCompressionWorkSpaceSize
RtlGetControlSecurityDescriptor
RtlGetCurrentDirectory_U
RtlGetCurrentPeb
RtlGetDaclSecurityDescriptor
RtlGetElementGenericTable
RtlGetElementGenericTableAvl
RtlGetFirstRange
RtlGetFrame
RtlGetFullPathName_U
RtlGetGroupSecurityDescriptor
RtlGetLastNtStatus
RtlGetLastWin32Error
RtlGetLengthWithoutLastFullDosOrNtPathElement
RtlGetLengthWithoutTrailingPathSeperators
RtlGetLongestNtPathLength
RtlGetNativeSystemInformation
RtlGetNextRange
RtlGetNtGlobalFlags
RtlGetNtProductType
RtlGetNtVersionNumbers
RtlGetOwnerSecurityDescriptor
RtlGetProcessHeaps
RtlGetSaclSecurityDescriptor
RtlGetSecurityDescriptorRMControl
RtlGetSetBootStatusData
RtlGetUserInfoHeap
RtlGetVersion
RtlHashUnicodeString
RtlIdentifierAuthoritySid
RtlImageDirectoryEntryToData
RtlImageRvaToSection
RtlImageRvaToVa
RtlImpersonateSelf
RtlInitAnsiString
RtlInitCodePageTable
RtlInitMemoryStream
RtlInitNlsTables
RtlInitOutOfProcessMemoryStream
RtlInitString
RtlInitUnicodeString
RtlInitUnicodeStringEx
RtlInitializeAtomPackage
RtlInitializeBitMap
RtlInitializeContext
RtlInitializeCriticalSection
RtlInitializeCriticalSectionAndSpinCount
RtlInitializeGenericTable
RtlInitializeGenericTableAvl
RtlInitializeHandleTable
RtlInitializeRXact
RtlInitializeRangeList
RtlInitializeResource
RtlInitializeSListHead
RtlInitializeSid
RtlInsertElementGenericTable
RtlInsertElementGenericTableAvl
RtlInt64ToUnicodeString
RtlIntegerToChar
RtlIntegerToUnicodeString
RtlInterlockedFlushSList
RtlInterlockedPopEntrySList
RtlInterlockedPushEntrySList
RtlInvertRangeList
RtlIpv4AddressToStringA
RtlIpv4AddressToStringW
RtlIpv4StringToAddressA
RtlIpv4StringToAddressW
RtlIpv6AddressToStringA
RtlIpv6AddressToStringW
RtlIpv6StringToAddressA
RtlIpv6StringToAddressW
RtlIsActivationContextActive
RtlIsDosDeviceName_U
RtlIsGenericTableEmpty
RtlIsGenericTableEmptyAvl
RtlIsNameLegalDOS8Dot3
RtlIsRangeAvailable
RtlIsTextUnicode
RtlIsThreadWithinLoaderCallout
RtlIsValidHandle
RtlIsValidIndexHandle
RtlLargeIntegerToChar
RtlLeaveCriticalSection
RtlLengthRequiredSid
RtlLengthSecurityDescriptor
RtlLengthSid
RtlLocalTimeToSystemTime
RtlLockBootStatusData
RtlLockHeap
RtlLockMemoryStreamRegion
RtlLogStackBackTrace
RtlLookupAtomInAtomTable
RtlLookupElementGenericTable
RtlLookupElementGenericTableAvl
RtlMakeSelfRelativeSD
RtlMapGenericMask
RtlMapSecurityErrorToNtStatus
RtlMergeRangeLists
RtlMoveMemory
RtlMultiAppendUnicodeStringBuffer
RtlMultiByteToUnicodeSize
RtlNewInstanceSecurityObject
RtlNewSecurityGrantedAccess
RtlNewSecurityObject
RtlNewSecurityObjectEx
RtlNewSecurityObjectWithMultipleInheritance
RtlNormalizeProcessParams
RtlNtPathNameToDosPathName
RtlNtStatusToDosError
RtlNtStatusToDosErrorNoTeb
RtlNumberGenericTableElements
RtlNumberGenericTableElementsAvl
RtlNumberOfClearBits
RtlNumberOfSetBits
RtlOemStringToUnicodeSize
RtlOemStringToUnicodeString
RtlOemToUnicodeN
RtlOpenCurrentUser
RtlPcToFileHeader
RtlPinAtomInAtomTable
RtlPopFrame
RtlPrefixString
RtlPrefixUnicodeString
RtlProtectHeap
RtlPushFrame
RtlQueryAtomInAtomTable
RtlQueryDepthSList
RtlQueryEnvironmentVariable_U
RtlQueryHeapInformation
RtlQueryInformationAcl
RtlQueryInformationActivationContext
RtlQueryInformationActiveActivationContext
RtlQueryInterfaceMemoryStream
RtlQueryProcessBackTraceInformation
RtlQueryProcessDebugInformation
RtlQueryProcessHeapInformation
RtlQueryProcessLockInformation
RtlQueryRegistryValues
RtlQuerySecurityObject
RtlQueryTagHeap
RtlQueryTimeZoneInformation
RtlQueueApcWow64Thread
RtlQueueWorkItem
RtlRaiseException
RtlRaiseStatus
RtlRandom
RtlRandomEx
RtlReadMemoryStream
RtlReadOutOfProcessMemoryStream
RtlRealPredecessor
RtlRealSuccessor
RtlRegisterSecureMemoryCacheCallback
RtlRegisterWait
RtlReleaseActivationContext
RtlReleaseMemoryStream
RtlReleasePebLock
RtlReleaseResource
RtlRemoteCall
RtlRemoveVectoredExceptionHandler
RtlResetRtlTranslations
RtlRestoreLastWin32Error
RtlRevertMemoryStream
RtlRunDecodeUnicodeString
RtlRunEncodeUnicodeString
RtlSecondsSince1970ToTime
RtlSecondsSince1980ToTime
RtlSeekMemoryStream
RtlSelfRelativeToAbsoluteSD2
RtlSelfRelativeToAbsoluteSD
RtlSetAllBits
RtlSetAttributesSecurityDescriptor
RtlSetBits
RtlSetControlSecurityDescriptor
RtlSetCriticalSectionSpinCount
RtlSetCurrentDirectory_U
RtlSetCurrentEnvironment
RtlSetDaclSecurityDescriptor
RtlSetEnvironmentVariable
RtlSetGroupSecurityDescriptor
RtlSetHeapInformation
RtlSetInformationAcl
RtlSetIoCompletionCallback
RtlSetLastWin32Error
RtlSetLastWin32ErrorAndNtStatusFromNtStatus
RtlSetMemoryStreamSize
RtlSetOwnerSecurityDescriptor
RtlSetProcessIsCritical
RtlSetSaclSecurityDescriptor
RtlSetSecurityDescriptorRMControl
RtlSetSecurityObject
RtlSetSecurityObjectEx
RtlSetThreadIsCritical
RtlSetThreadPoolStartFunc
RtlSetTimeZoneInformation
RtlSetTimer
RtlSetUnicodeCallouts
RtlSetUserFlagsHeap
RtlSetUserValueHeap
RtlSplay
RtlStartRXact
RtlStatMemoryStream
RtlStringFromGUID
RtlSubAuthorityCountSid
RtlSubAuthoritySid
RtlSubtreePredecessor
RtlSubtreeSuccessor
RtlSystemTimeToLocalTime
RtlTimeFieldsToTime
RtlTimeToElapsedTimeFields
RtlTimeToSecondsSince1970
RtlTimeToSecondsSince1980
RtlTimeToTimeFields
RtlTraceDatabaseAdd
RtlTraceDatabaseCreate
RtlTraceDatabaseDestroy
RtlTraceDatabaseEnumerate
RtlTraceDatabaseFind
RtlTraceDatabaseLock
RtlTraceDatabaseUnlock
RtlTraceDatabaseValidate
RtlTryEnterCriticalSection
RtlUnhandledExceptionFilter2
RtlUnhandledExceptionFilter
RtlUnicodeStringToAnsiSize
RtlUnicodeStringToCountedOemString
RtlUnicodeStringToInteger
RtlUnicodeStringToOemSize
RtlUnicodeStringToOemString
RtlUnicodeToCustomCPN
RtlUnicodeToMultiByteSize
RtlUnicodeToOemN
RtlUniform
RtlUnlockBootStatusData
RtlUnlockHeap
RtlUnlockMemoryStreamRegion
RtlUpcaseUnicodeChar
RtlUpcaseUnicodeString
RtlUpcaseUnicodeStringToAnsiString
RtlUpcaseUnicodeStringToCountedOemString
RtlUpcaseUnicodeStringToOemString
RtlUpcaseUnicodeToCustomCPN
RtlUpcaseUnicodeToMultiByteN
RtlUpcaseUnicodeToOemN
RtlUpdateTimer
RtlUpperChar
RtlUpperString
RtlUsageHeap
RtlValidAcl
RtlValidRelativeSecurityDescriptor
RtlValidSecurityDescriptor
RtlValidSid
RtlValidateProcessHeaps
RtlValidateUnicodeString
RtlVerifyVersionInfo
RtlWalkFrameChain
RtlWalkHeap
RtlWriteMemoryStream
RtlWriteRegistryValue
RtlZeroHeap
RtlZeroMemory
RtlZombifyActivationContext
RtlpApplyLengthFunction
RtlpEnsureBufferSize
RtlpNotOwnerCriticalSection
RtlpNtCreateKey
RtlpNtEnumerateSubKey
RtlpNtMakeTemporaryKey
RtlpNtOpenKey
RtlpNtQueryValueKey
RtlpNtSetValueKey
RtlpUnWaitCriticalSection
RtlpWaitForCriticalSection
RtlxAnsiStringToUnicodeSize
RtlxOemStringToUnicodeSize
RtlxUnicodeStringToAnsiSize
RtlxUnicodeStringToOemSize
SaveEm87Context
VerSetConditionMask
ZwAcceptConnectPort
ZwAccessCheck
ZwAccessCheckAndAuditAlarm
ZwAccessCheckByType
ZwAccessCheckByTypeAndAuditAlarm
ZwAccessCheckByTypeResultList
ZwAccessCheckByTypeResultListAndAuditAlarm
ZwAccessCheckByTypeResultListAndAuditAlarmByHandle
ZwAddAtom
ZwAddBootEntry
ZwAdjustGroupsToken
ZwAdjustPrivilegesToken
ZwAlertResumeThread
ZwAlertThread
ZwAllocateLocallyUniqueId
ZwAllocateUserPhysicalPages
ZwAllocateUuids
ZwAllocateVirtualMemory
ZwAreMappedFilesTheSame
ZwAssignProcessToJobObject
ZwCallbackReturn
ZwCancelDeviceWakeupRequest
ZwCancelIoFile
ZwCancelTimer
ZwClearEvent
ZwClose
ZwCloseObjectAuditAlarm
ZwCompactKeys
ZwCompareTokens
ZwCompleteConnectPort
ZwCompressKey
ZwConnectPort
ZwContinue
ZwCreateDebugObject
ZwCreateDirectoryObject
ZwCreateEvent
ZwCreateEventPair
ZwCreateFile
ZwCreateIoCompletion
ZwCreateJobObject
ZwCreateJobSet
ZwCreateKey
ZwCreateKeyedEvent
ZwCreateMailslotFile
ZwCreateMutant
ZwCreateNamedPipeFile
ZwCreatePagingFile
ZwCreatePort
ZwCreateProcess
ZwCreateProcessEx
ZwCreateProfile
ZwCreateSection
ZwCreateSemaphore
ZwCreateSymbolicLinkObject
ZwCreateThread
ZwCreateTimer
ZwCreateToken
ZwCreateWaitablePort
ZwDebugActiveProcess
ZwDebugContinue
ZwDelayExecution
ZwDeleteAtom
ZwDeleteBootEntry
ZwDeleteFile
ZwDeleteKey
ZwDeleteObjectAuditAlarm
ZwDeleteValueKey
ZwDeviceIoControlFile
ZwDisplayString
ZwDuplicateObject
ZwDuplicateToken
ZwEnumerateBootEntries
ZwEnumerateKey
ZwEnumerateSystemEnvironmentValuesEx
ZwEnumerateValueKey
ZwExtendSection
ZwFilterToken
ZwFindAtom
ZwFlushBuffersFile
ZwFlushInstructionCache
ZwFlushKey
ZwFlushVirtualMemory
ZwFlushWriteBuffer
ZwFreeUserPhysicalPages
ZwFreeVirtualMemory
ZwFsControlFile
ZwGetContextThread
ZwGetDevicePowerState
ZwGetPlugPlayEvent
ZwGetWriteWatch
ZwImpersonateAnonymousToken
ZwImpersonateClientOfPort
ZwImpersonateThread
ZwInitializeRegistry
ZwInitiatePowerAction
ZwIsProcessInJob
ZwIsSystemResumeAutomatic
ZwListenPort
ZwLoadDriver
ZwLoadKey2
ZwLoadKey
ZwLockFile
ZwLockProductActivationKeys
ZwLockRegistryKey
ZwLockVirtualMemory
ZwMakePermanentObject
ZwMakeTemporaryObject
ZwMapUserPhysicalPages
ZwMapUserPhysicalPagesScatter
ZwMapViewOfSection
ZwModifyBootEntry
ZwNotifyChangeDirectoryFile
ZwNotifyChangeKey
ZwNotifyChangeMultipleKeys
ZwOpenDirectoryObject
ZwOpenEvent
ZwOpenEventPair
ZwOpenFile
ZwOpenIoCompletion
ZwOpenJobObject
ZwOpenKey
ZwOpenKeyedEvent
ZwOpenMutant
ZwOpenObjectAuditAlarm
ZwOpenProcess
ZwOpenProcessToken
ZwOpenProcessTokenEx
ZwOpenSection
ZwOpenSemaphore
ZwOpenSymbolicLinkObject
ZwOpenThread
ZwOpenThreadToken
ZwOpenThreadTokenEx
ZwOpenTimer
ZwPlugPlayControl
ZwPowerInformation
ZwPrivilegeCheck
ZwPrivilegeObjectAuditAlarm
ZwPrivilegedServiceAuditAlarm
ZwProtectVirtualMemory
ZwPulseEvent
ZwQueryAttributesFile
ZwQueryBootEntryOrder
ZwQueryBootOptions
ZwQueryDebugFilterState
ZwQueryDefaultLocale
ZwQueryDefaultUILanguage
ZwQueryDirectoryFile
ZwQueryDirectoryObject
ZwQueryEaFile
ZwQueryEvent
ZwQueryFullAttributesFile
ZwQueryInformationAtom
ZwQueryInformationFile
ZwQueryInformationJobObject
ZwQueryInformationPort
ZwQueryInformationProcess
ZwQueryInformationThread
ZwQueryInformationToken
ZwQueryInstallUILanguage
ZwQueryIntervalProfile
ZwQueryIoCompletion
ZwQueryKey
ZwQueryMultipleValueKey
ZwQueryMutant
ZwQueryObject
ZwQueryOpenSubKeys
ZwQueryPerformanceCounter
ZwQueryPortInformationProcess
ZwQueryQuotaInformationFile
ZwQuerySection
ZwQuerySecurityObject
ZwQuerySemaphore
ZwQuerySymbolicLinkObject
ZwQuerySystemEnvironmentValue
ZwQuerySystemEnvironmentValueEx
ZwQuerySystemInformation
ZwQuerySystemTime
ZwQueryTimer
ZwQueryTimerResolution
ZwQueryValueKey
ZwQueryVirtualMemory
ZwQueryVolumeInformationFile
ZwQueueApcThread
ZwRaiseException
ZwRaiseHardError
ZwReadFile
ZwReadFileScatter
ZwReadRequestData
ZwReadVirtualMemory
ZwRegisterThreadTerminatePort
ZwReleaseKeyedEvent
ZwReleaseMutant
ZwReleaseSemaphore
ZwRemoveIoCompletion
ZwRemoveProcessDebug
ZwRenameKey
ZwReplaceKey
ZwReplyPort
ZwReplyWaitReceivePort
ZwReplyWaitReceivePortEx
ZwReplyWaitReplyPort
ZwRequestDeviceWakeup
ZwRequestPort
ZwRequestWaitReplyPort
ZwRequestWakeupLatency
ZwResetEvent
ZwResetWriteWatch
ZwRestoreKey
ZwResumeProcess
ZwResumeThread
ZwSaveKey
ZwSaveKeyEx
ZwSaveMergedKeys
ZwSecureConnectPort
ZwSetBootEntryOrder
ZwSetBootOptions
ZwSetContextThread
ZwSetDebugFilterState
ZwSetDefaultHardErrorPort
ZwSetDefaultLocale
ZwSetDefaultUILanguage
ZwSetEaFile
ZwSetEvent
ZwSetEventBoostPriority
ZwSetHighEventPair
ZwSetHighWaitLowEventPair
ZwSetInformationDebugObject
ZwSetInformationFile
ZwSetInformationJobObject
ZwSetInformationKey
ZwSetInformationObject
ZwSetInformationProcess
ZwSetInformationThread
ZwSetInformationToken
ZwSetIntervalProfile
ZwSetIoCompletion
ZwSetLdtEntries
ZwSetLowEventPair
ZwSetLowWaitHighEventPair
ZwSetQuotaInformationFile
ZwSetSecurityObject
ZwSetSystemEnvironmentValue
ZwSetSystemEnvironmentValueEx
ZwSetSystemInformation
ZwSetSystemPowerState
ZwSetSystemTime
ZwSetThreadExecutionState
ZwSetTimer
ZwSetTimerResolution
ZwSetUuidSeed
ZwSetValueKey
ZwSetVolumeInformationFile
ZwShutdownSystem
ZwSignalAndWaitForSingleObject
ZwStartProfile
ZwStopProfile
ZwSuspendProcess
ZwSuspendThread
ZwSystemDebugControl
ZwTerminateJobObject
ZwTerminateProcess
ZwTerminateThread
ZwTestAlert
ZwTraceEvent
ZwTranslateFilePath
ZwUnloadDriver
ZwUnloadKey
ZwUnloadKeyEx
ZwUnlockFile
ZwUnlockVirtualMemory
ZwUnmapViewOfSection
ZwVdmControl
ZwWaitForDebugEvent
ZwWaitForKeyedEvent
ZwWaitForMultipleObjects
ZwWaitForSingleObject
ZwWaitHighEventPair
ZwWaitLowEventPair
ZwWriteFile
ZwWriteFileGather
ZwWriteRequestData
ZwWriteVirtualMemory
ZwYieldExecution
_CIcos
_CIlog
_CIpow
_CIsin
_CIsqrt
__eCommonExceptions
__eEmulatorInit
__eF2XM1
__eFABS
__eFADD32
__eFADD64
__eFADDPreg
__eFADDreg
__eFADDtop
__eFCHS
__eFCOM
__eFCOM32
__eFCOM64
__eFCOMP
__eFCOMP32
__eFCOMP64
__eFCOMPP
__eFCOS
__eFDECSTP
__eFDIV32
__eFDIV64
__eFDIVPreg
__eFDIVR32
__eFDIVR64
__eFDIVRPreg
__eFDIVRreg
__eFDIVRtop
__eFDIVreg
__eFDIVtop
__eFFREE
__eFIADD16
__eFIADD32
__eFICOM16
__eFICOM32
__eFICOMP16
__eFICOMP32
__eFIDIV16
__eFIDIV32
__eFIDIVR16
__eFIDIVR32
__eFILD16
__eFILD32
__eFILD64
__eFIMUL16
__eFIMUL32
__eFINCSTP
__eFINIT
__eFIST16
__eFIST32
__eFISTP16
__eFISTP32
__eFISTP64
__eFISUB16
__eFISUB32
__eFISUBR16
__eFISUBR32
__eFLD1
__eFLD32
__eFLD64
__eFLD80
__eFLDCW
__eFLDENV
__eFLDL2E
__eFLDLN2
__eFLDPI
__eFLDZ
__eFMUL32
__eFMUL64
__eFMULPreg
__eFMULreg
__eFMULtop
__eFPATAN
__eFPREM
__eFPREM1
__eFPTAN
__eFRNDINT
__eFRSTOR
__eFSAVE
__eFSCALE
__eFSIN
__eFSQRT
__eFST
__eFST32
__eFST64
__eFSTCW
__eFSTENV
__eFSTP
__eFSTP32
__eFSTP64
__eFSTP80
__eFSTSW
__eFSUB32
__eFSUB64
__eFSUBPreg
__eFSUBR32
__eFSUBR64
__eFSUBRPreg
__eFSUBRreg
__eFSUBRtop
__eFSUBreg
__eFSUBtop
__eFTST
__eFUCOM
__eFUCOMP
__eFUCOMPP
__eFXAM
__eFXCH
__eFXTRACT
__eFYL2X
__eFYL2XP1
__eGetStatusWord
__isascii
__iscsym
__iscsymf
__toascii
_alldiv
_alldvrm
_allmul
_alloca_probe
_allrem
_allshl
_allshr
_atoi64
_aulldiv
_aulldvrm
_aullrem
_aullshr
_chkstk
_fltused
_ftol
_i64toa
_i64tow
_itoa
_itow
_lfind
_ltoa
_ltow
_memccpy
_memicmp
_snprintf
_snwprintf
_splitpath
_strcmpi
_stricmp
_strlwr
_strnicmp
_strupr
_tolower
_toupper
_ui64toa
_ui64tow
_ultoa
_ultow
_vsnprintf
_vsnwprintf
_wcsicmp
_wcslwr
_wcsnicmp
_wcsupr
_wtoi
_wtoi64
_wtol
abs
atan
atoi
atol
bsearch
ceil
cos
fabs
floor
isalnum
isalpha
iscntrl
isdigit
isgraph
islower
isprint
ispunct
isspace
isupper
iswalpha
iswctype
iswdigit
iswlower
iswspace
iswxdigit
isxdigit
labs
log
mbstowcs
memchr
memcmp
memcpy
memmove
memset
pow
qsort
sin
sprintf
sqrt
sscanf
strcat
strchr
strcmp
strcpy
strcspn
strlen
strncat
strncmp
strncpy
strpbrk
strrchr
strspn
strstr
strtol
strtoul
swprintf
tan
tolower
toupper
towlower
towupper
vDbgPrintEx
vDbgPrintExWithPrefix
vsprintf
wcscat
wcschr
wcscmp
wcscpy
wcscspn
wcslen
wcsncat
wcsncmp
wcsncpy
wcspbrk
wcsrchr
wcsspn
wcsstr
wcstol
wcstombs
wcstoul

Found follow exports in USER32.DLL
AlignRects
AllowForegroundActivation
AllowSetForegroundWindow
AnimateWindow
BlockInput
BroadcastSystemMessageA
BroadcastSystemMessageExA
BroadcastSystemMessageExW
BroadcastSystemMessageW
BuildReasonArray
CalcMenuBar
ChangeDisplaySettingsExA
ChangeDisplaySettingsExW
CliImmSetHotKey
ClientThreadSetup
CreateDialogIndirectParamAorW
CreateSystemThreads
CsrBroadcastSystemMessageExW
CtxInitUser32
DdeGetQualityOfService
DefRawInputProc
DeregisterShellHookWindow
DestroyReasons
DeviceEventWorker
DialogBoxIndirectParamAorW
DisableProcessWindowsGhosting
DisplayExitWindowsWarnings
DrawMenuBarTemp
EndMenu
EnterReaderModeHelper
EnumDisplayDevicesA
EnumDisplayDevicesW
EnumDisplayMonitors
EnumDisplaySettingsExA
EnumDisplaySettingsExW
FlashWindowEx
GetAltTabInfo
GetAltTabInfoA
GetAltTabInfoW
GetAncestor
GetAppCompatFlags2
GetAppCompatFlags
GetClipboardSequenceNumber
GetComboBoxInfo
GetCursorFrameInfo
GetCursorInfo
GetGUIThreadInfo
GetGuiResources
GetLastInputInfo
GetLayeredWindowAttributes
GetListBoxInfo
GetMenuBarInfo
GetMenuInfo
GetMonitorInfoA
GetMonitorInfoW
GetMouseMovePointsEx
GetProcessDefaultLayout
GetProgmanWindow
GetRawInputBuffer
GetRawInputData
GetRawInputDeviceInfoA
GetRawInputDeviceInfoW
GetRawInputDeviceList
GetReasonTitleFromReasonCode
GetRegisteredRawInputDevices
GetScrollBarInfo
GetTaskmanWindow
GetTitleBarInfo
GetWinStationInfo
GetWindowInfo
GetWindowModuleFileName
GetWindowModuleFileNameA
GetWindowModuleFileNameW
GetWindowRgnBox
IMPGetIMEA
IMPGetIMEW
IMPQueryIMEA
IMPQueryIMEW
IMPSetIMEA
IMPSetIMEW
InSendMessageEx
InitializeLpkHooks
InitializeWin32EntryTable
IsGUIThread
IsHungAppWindow
IsServerSideWindow
IsWinEventHookInstalled
IsWindowInDestroy
KillSystemTimer
LoadKeyboardLayoutEx
LoadLocalFonts
LoadRemoteFonts
LockSetForegroundWindow
LockWorkStation
MBToWCSEx
MB_GetString
MenuWindowProcA
MenuWindowProcW
MessageBoxTimeoutA
MessageBoxTimeoutW
MonitorFromPoint
MonitorFromRect
MonitorFromWindow
MsgWaitForMultipleObjectsEx
NotifyWinEvent
PaintMenuBar
PrintWindow
PrivateExtractIconExA
PrivateExtractIconExW
PrivateExtractIconsA
PrivateExtractIconsW
PrivateSetDbgTag
PrivateSetRipFlags
QuerySendMessage
QueryUserCounters
RealChildWindowFromPoint
RealGetWindowClass
RealGetWindowClassA
RealGetWindowClassW
ReasonCodeNeedsBugID
ReasonCodeNeedsComment
RecordShutdownReason
RegisterDeviceNotificationA
RegisterDeviceNotificationW
RegisterMessagePumpHook
RegisterRawInputDevices
RegisterServicesProcess
RegisterShellHookWindow
RegisterUserApiHook
ResolveDesktopForWOW
ScrollChildren
SendIMEMessageExA
SendIMEMessageExW
SendInput
SetConsoleReserveKeys
SetCursorContents
SetLayeredWindowAttributes
SetLogonNotifyWindow
SetMenuInfo
SetProcessDefaultLayout
SetProgmanWindow
SetShellWindowEx
SetSystemMenu
SetSystemTimer
SetTaskmanWindow
SetWinEventHook
SetWindowStationUser
ShowStartGlass
SoftModalMessageBox
ToUnicodeEx
TrackMouseEvent
TranslateMessageEx
UnhookWinEvent
UnregisterDeviceNotification
UnregisterMessagePumpHook
UnregisterUserApiHook
UpdateLayeredWindow
UpdatePerUserSystemParameters
User32InitializeImmEntryTable
UserHandleGrantAccess
UserLpkPSMTextOut
UserLpkTabbedTextOut
UserRealizePalette
UserRegisterWowHandlers
VRipOutput
VTagOutput
WCSToMBEx
WINNLSEnableIME
WINNLSGetEnableStatus
WINNLSGetIMEHotkey
Win32PoolAllocationStats

Found follow exports in GDI32.DLL
AddFontMemResourceEx
AddFontResourceExA
AddFontResourceExW
AddFontResourceTracking
AnyLinkedFonts
BRUSHOBJ_hGetColorTransform
BRUSHOBJ_pvAllocRbrush
BRUSHOBJ_pvGetRbrush
BRUSHOBJ_ulGetBrushColor
CLIPOBJ_bEnum
CLIPOBJ_cEnumStart
CLIPOBJ_ppoGetPath
ClearBitmapAttributes
ClearBrushAttributes
ColorCorrectPalette
CreateFontIndirectExA
CreateFontIndirectExW
DdEntry0
DdEntry10
DdEntry11
DdEntry12
DdEntry13
DdEntry14
DdEntry15
DdEntry16
DdEntry17
DdEntry18
DdEntry19
DdEntry1
DdEntry20
DdEntry21
DdEntry22
DdEntry23
DdEntry24
DdEntry25
DdEntry26
DdEntry27
DdEntry28
DdEntry29
DdEntry2
DdEntry30
DdEntry31
DdEntry32
DdEntry33
DdEntry34
DdEntry35
DdEntry36
DdEntry37
DdEntry38
DdEntry39
DdEntry3
DdEntry40
DdEntry41
DdEntry42
DdEntry43
DdEntry44
DdEntry45
DdEntry46
DdEntry47
DdEntry48
DdEntry49
DdEntry4
DdEntry50
DdEntry51
DdEntry52
DdEntry53
DdEntry54
DdEntry55
DdEntry56
DdEntry5
DdEntry6
DdEntry7
DdEntry8
DdEntry9
EnableEUDC
EndFormPage
EngAcquireSemaphore
EngAlphaBlend
EngAssociateSurface
EngBitBlt
EngCheckAbort
EngComputeGlyphSet
EngCopyBits
EngCreateBitmap
EngCreateClip
EngCreateDeviceBitmap
EngCreateDeviceSurface
EngCreatePalette
EngCreateSemaphore
EngDeleteClip
EngDeletePalette
EngDeletePath
EngDeleteSemaphore
EngDeleteSurface
EngEraseSurface
EngFillPath
EngFindResource
EngFreeModule
EngGetCurrentCodePage
EngGetDriverName
EngGetPrinterDataFileName
EngGradientFill
EngLineTo
EngLoadModule
EngLockSurface
EngMarkBandingSurface
EngMultiByteToUnicodeN
EngMultiByteToWideChar
EngPaint
EngPlgBlt
EngQueryEMFInfo
EngQueryLocalTime
EngReleaseSemaphore
EngStretchBlt
EngStretchBltROP
EngStrokeAndFillPath
EngStrokePath
EngTextOut
EngTransparentBlt
EngUnicodeToMultiByteN
EngUnlockSurface
EngWideCharToMultiByte
EudcLoadLinkW
EudcUnloadLinkW
FONTOBJ_cGetAllGlyphHandles
FONTOBJ_cGetGlyphs
FONTOBJ_pQueryGlyphAttrs
FONTOBJ_pfdg
FONTOBJ_pifi
FONTOBJ_pvTrueTypeFontFile
FONTOBJ_pxoGetXform
FONTOBJ_vGetInfo
FontIsLinked
GdiAddFontResourceW
GdiAddGlsBounds
GdiAddGlsRecord
GdiAlphaBlend
GdiArtificialDecrementDriver
GdiCleanCacheDC
GdiConsoleTextOut
GdiConvertAndCheckDC
GdiConvertBitmap
GdiConvertBitmapV5
GdiConvertBrush
GdiConvertDC
GdiConvertEnhMetaFile
GdiConvertFont
GdiConvertMetaFilePict
GdiConvertPalette
GdiConvertRegion
GdiConvertToDevmodeW
GdiCreateLocalEnhMetaFile
GdiCreateLocalMetaFilePict
GdiDeleteLocalDC
GdiDeleteSpoolFileHandle
GdiDescribePixelFormat
GdiDllInitialize
GdiDrawStream
GdiEndDocEMF
GdiEndPageEMF
GdiEntry10
GdiEntry11
GdiEntry12
GdiEntry13
GdiEntry14
GdiEntry15
GdiEntry16
GdiEntry1
GdiEntry2
GdiEntry3
GdiEntry4
GdiEntry5
GdiEntry6
GdiEntry7
GdiEntry8
GdiEntry9
GdiFixUpHandle
GdiFullscreenControl
GdiGetCharDimensions
GdiGetCodePage
GdiGetDC
GdiGetDevmodeForPage
GdiGetLocalBrush
GdiGetLocalDC
GdiGetLocalFont
GdiGetPageCount
GdiGetPageHandle
GdiGetSpoolFileHandle
GdiGetSpoolMessage
GdiGradientFill
GdiInitSpool
GdiInitializeLanguagePack
GdiIsMetaFileDC
GdiIsMetaPrintDC
GdiIsPlayMetafileDC
GdiPlayEMF
GdiPlayPageEMF
GdiPlayPrivatePageEMF
GdiPrinterThunk
GdiProcessSetup
GdiQueryFonts
GdiQueryTable
GdiRealizationInfo
GdiReleaseDC
GdiReleaseLocalDC
GdiResetDCEMF
GdiSetAttrs
GdiSetLastError
GdiSetPixelFormat
GdiSetServerAttr
GdiStartDocEMF
GdiStartPageEMF
GdiSwapBuffers
GdiTransparentBlt
GdiValidateHandle
GetBitmapAttributes
GetBrushAttributes
GetCharABCWidthsI
GetCharWidthI
GetCharWidthInfo
GetDCBrushColor
GetDCPenColor
GetETM
GetEUDCTimeStamp
GetEUDCTimeStampExW
GetEnhMetaFilePixelFormat
GetFontAssocStatus
GetFontResourceInfoW
GetFontUnicodeRanges
GetGlyphIndicesA
GetGlyphIndicesW
GetGlyphOutlineWow
GetHFONT
GetLayout
GetRelAbs
GetStringBitmapA
GetStringBitmapW
GetTextExtentExPointI
GetTextExtentExPointWPri
GetTextExtentPointI
GetTextFaceAliasW
GetTransform
HT_Get8BPPFormatPalette
HT_Get8BPPMaskPalette
MirrorRgn
NamedEscape
PATHOBJ_bEnum
PATHOBJ_bEnumClipLines
PATHOBJ_vEnumStart
PATHOBJ_vEnumStartClipLines
PATHOBJ_vGetBounds
PolyPatBlt
QueryFontAssocStatus
RemoveFontMemResourceEx
RemoveFontResourceExA
RemoveFontResourceExW
RemoveFontResourceTracking
STROBJ_bEnum
STROBJ_bEnumPositionsOnly
STROBJ_bGetAdvanceWidths
STROBJ_dwGetCodePage
STROBJ_vEnumStart
SelectBrushLocal
SelectFontLocal
SetBitmapAttributes
SetBrushAttributes
SetDCBrushColor
SetDCPenColor
SetLayout
SetLayoutWidth
SetMagicColors
SetRelAbs
SetVirtualResolution
StartFormPage
UnloadNetworkFonts
XFORMOBJ_bApplyXform
XFORMOBJ_iGetXform
XLATEOBJ_cGetPalette
XLATEOBJ_hGetColorTransform
XLATEOBJ_iXlate
XLATEOBJ_piVector
bInitSystemAndFontsDirectoriesW
bMakePathNameW
cGetTTFFromFOT

Found follow exports in SHELL32.DLL
Activate_RunDLL
AppCompat_RunDLLW
CallCPLEntry16
CDefFolderMenu_Create
CDefFolderMenu_Create2
CheckEscapesA
Control_FillCache_RunDLL
Control_FillCache_RunDLLA
Control_FillCache_RunDLLW
Control_RunDLLA
Control_RunDLLAsUserW
Control_RunDLLW
DAD_AutoScroll
DAD_DragEnterEx
DAD_DragEnterEx2
DAD_DragLeave
DAD_DragMove
DAD_SetDragImage
DAD_ShowDragImage
DllCanUnloadNow
DllGetVersion
DllInstall
DllRegisterServer
DllUnregisterServer
DriveType
ExtractIconExW
ExtractIconResInfoA
ExtractIconResInfoW
ExtractVersionResource16W
FindExeDlgProc
GetFileNameFromBrowse
ILAppendID
ILClone
ILCloneFirst
ILCombine
ILCreateFromPath
ILCreateFromPathA
ILCreateFromPathW
ILFindChild
ILFindLastID
ILFree
ILGetNext
ILGetSize
ILIsEqual
ILIsParent
ILLoadFromStream
ILRemoveLastID
ILSaveToStream
IsLFNDrive
IsLFNDriveA
IsLFNDriveW
IsNetDrive
IsUserAnAdmin
OpenAs_RunDLLA
OpenAs_RunDLLW
OpenRegStream
Options_RunDLL
Options_RunDLLA
Options_RunDLLW
PathCleanupSpec
PathGetShortPath
PathIsExe
PathIsSlowA
PathIsSlowW
PathMakeUniqueName
PathProcessCommand
PathQualify
PathResolve
PathYetAnotherMakeUniqueName
PickIconDlg
PifMgr_CloseProperties
PifMgr_GetProperties
PifMgr_OpenProperties
PifMgr_SetProperties
PrintersGetCommand_RunDLLA
PrintersGetCommand_RunDLLW
ReadCabinetState
RealDriveType
RestartDialog
RestartDialogEx
SHAddFromPropSheetExtArray
SHAlloc
SHAllocShared
SHBindToParent
SHBrowseForFolderW
SHChangeNotification_Lock
SHChangeNotification_Unlock
SHChangeNotifyDeregister
SHChangeNotifyRegister
SHChangeNotifySuspendResume
SHCloneSpecialIDList
SHCLSIDFromString
SHCoCreateInstance
SHCreateDirectory
SHCreateDirectoryExA
SHCreateDirectoryExW
SHCreateFileExtractIconW
SHCreateLocalServerRunDll
SHCreateProcessAsUserW
SHCreatePropSheetExtArray
SHCreateQueryCancelAutoPlayMoniker
SHCreateShellFolderView
SHCreateShellFolderViewEx
SHCreateShellItem
SHCreateStdEnumFmtEtc
SHDefExtractIconA
SHDefExtractIconW
SHDestroyPropSheetExtArray
SHDoDragDrop
SheChangeDirExA
SheChangeDirW
SheConvertPathW
SheFullPathA
SheFullPathW
SheGetCurDrive
SheGetDirExW
SheGetDirW
SheGetPathOffsetW
Shell_GetCachedImageIndex
Shell_GetImageLists
Shell_MergeMenus
Shell_NotifyIconW
ShellExec_RunDLL
ShellExec_RunDLLA
ShellExec_RunDLLW
ShellExecuteExW
ShellHookProc
ShellMessageBoxA
ShellMessageBoxW
SHEmptyRecycleBinA
SHEmptyRecycleBinW
SHEnableServiceObject
SHEnumerateUnreadMailAccountsW
SheRemoveQuotesA
SheRemoveQuotesW
SheShortenPathA
SheShortenPathW
SHExtractIconsW
SHFileOperationW
SHFind_InitMenuPopup
SHFindFiles
SHFlushClipboard
SHFlushSFCache
SHFree
SHFreeShared
SHGetAttributesFromDataObject
SHGetDataFromIDListW
SHGetDiskFreeSpaceA
SHGetDiskFreeSpaceExA
SHGetDiskFreeSpaceExW
SHGetFileInfoW
SHGetFolderLocation
SHGetFolderPathA
SHGetFolderPathAndSubDirA
SHGetFolderPathAndSubDirW
SHGetFolderPathW
SHGetIconOverlayIndexA
SHGetIconOverlayIndexW
SHGetNewLinkInfo
SHGetNewLinkInfoA
SHGetNewLinkInfoW
SHGetPathFromIDListW
SHGetRealIDL
SHGetSetFolderCustomSettingsW
SHGetSetSettings
SHGetSettings
SHGetShellStyleHInstance
SHGetSpecialFolderPathA
SHGetSpecialFolderPathW
SHGetUnreadMailCountW
SHHandleUpdateImage
SHHelpShortcuts_RunDLLA
SHHelpShortcuts_RunDLLW
SHILCreateFromPath
SHInvokePrinterCommandA
SHInvokePrinterCommandW
SHIsFileAvailableOffline
SHLimitInputEdit
SHLoadNonloadedIconOverlayIdentifiers
SHLoadOLE
SHLockShared
SHMapIDListToImageListIndexAsync
SHMapPIDLToSystemImageListIndex
SHMultiFileProperties
SHObjectProperties
SHOpenFolderAndSelectItems
SHOpenPropSheetW
SHParseDisplayName
SHPathPrepareForWriteA
SHPathPrepareForWriteW
SHPropStgCreate
SHPropStgReadMultiple
SHPropStgWriteMultiple
SHQueryRecycleBinA
SHQueryRecycleBinW
SHReplaceFromPropSheetExtArray
SHRestricted
SHRunControlPanel
SHSetInstanceExplorer
SHSetLocalizedName
SHSetUnreadMailCountW
SHShellFolderView_Message
SHSimpleIDListFromPath
SHStartNetConnectionDialogW
SHTestTokenMembership
SHUnlockShared
SHUpdateImageA
SHUpdateImageW
SHUpdateRecycleBinIcon
SHValidateUNC
SignalFileOpen
StrChrA
StrChrIA
StrChrIW
StrChrW
StrCmpNA
StrCmpNIA
StrCmpNIW
StrCmpNW
StrCpyNA
StrCpyNW
StrNCmpA
StrNCmpIA
StrNCmpIW
StrNCmpW
StrNCpyA
StrNCpyW
StrRChrA
StrRChrIA
StrRChrIW
StrRChrW
StrRStrA
StrRStrIA
StrRStrIW
StrRStrW
StrStrA
StrStrIA
StrStrIW
StrStrW
Win32DeleteFile
WOWShellExecute
WriteCabinetState

Found follow exports in COMDLG32.DLL
dwLBSubclass
dwOKSubclass
LoadAlterBitmap
PrintDlgExA
PrintDlgExW
Ssync_ANSI_UNICODE_Struct_For_WOW
WantArrows

Found follow exports in COMCTL32.DLL
AddMRUStringW
CreateMRUListW
DefSubclassProc
DllInstall
DPA_Create
DPA_DeleteAllPtrs
DPA_DeletePtr
DPA_Destroy
DPA_DestroyCallback
DPA_EnumCallback
DPA_GetPtr
DPA_InsertPtr
DPA_Search
DPA_SetPtr
DPA_Sort
DSA_Create
DSA_DeleteAllItems
DSA_Destroy
DSA_DestroyCallback
DSA_GetItemPtr
DSA_InsertItem
EnumMRUListW
FreeMRUList
ImageList_GetFlags
RemoveWindowSubclass
SetWindowSubclass
Str_SetPtrW

Found follow exports in ADVAPI32.DLL
I_ScGetCurrentGroupStateW
A_SHAFinal
A_SHAInit
A_SHAUpdate
AccessCheckByType
AccessCheckByTypeAndAuditAlarmA
AccessCheckByTypeAndAuditAlarmW
AccessCheckByTypeResultList
AccessCheckByTypeResultListAndAuditAlarmA
AccessCheckByTypeResultListAndAuditAlarmByHandleA
AccessCheckByTypeResultListAndAuditAlarmByHandleW
AccessCheckByTypeResultListAndAuditAlarmW
AddAccessAllowedAceEx
AddAccessAllowedObjectAce
AddAccessDeniedAceEx
AddAccessDeniedObjectAce
AddAuditAccessAceEx
AddAuditAccessObjectAce
AddUsersToEncryptedFile
BuildExplicitAccessWithNameA
BuildExplicitAccessWithNameW
BuildImpersonateExplicitAccessWithNameA
BuildImpersonateExplicitAccessWithNameW
BuildImpersonateTrusteeA
BuildImpersonateTrusteeW
BuildSecurityDescriptorA
BuildSecurityDescriptorW
BuildTrusteeWithNameA
BuildTrusteeWithNameW
BuildTrusteeWithObjectsAndNameA
BuildTrusteeWithObjectsAndNameW
BuildTrusteeWithObjectsAndSidA
BuildTrusteeWithObjectsAndSidW
BuildTrusteeWithSidA
BuildTrusteeWithSidW
CancelOverlappedAccess
ChangeServiceConfig2A
ChangeServiceConfig2W
CheckTokenMembership
CloseCodeAuthzLevel
CloseEncryptedFileRaw
CloseTrace
CommandLineFromMsiDescriptor
ComputeAccessTokenFromCodeAuthzLevel
ControlTraceA
ControlTraceW
ConvertAccessToSecurityDescriptorA
ConvertAccessToSecurityDescriptorW
ConvertSDToStringSDRootDomainA
ConvertSDToStringSDRootDomainW
ConvertSecurityDescriptorToAccessA
ConvertSecurityDescriptorToAccessNamedA
ConvertSecurityDescriptorToAccessNamedW
ConvertSecurityDescriptorToAccessW
ConvertSecurityDescriptorToStringSecurityDescriptorA
ConvertSecurityDescriptorToStringSecurityDescriptorW
ConvertSidToStringSidA
ConvertSidToStringSidW
ConvertStringSDToSDDomainA
ConvertStringSDToSDDomainW
ConvertStringSDToSDRootDomainA
ConvertStringSDToSDRootDomainW
ConvertStringSecurityDescriptorToSecurityDescriptorA
ConvertStringSecurityDescriptorToSecurityDescriptorW
ConvertStringSidToSidA
ConvertStringSidToSidW
ConvertToAutoInheritPrivateObjectSecurity
CreateCodeAuthzLevel
CreatePrivateObjectSecurityEx
CreatePrivateObjectSecurityWithMultipleInheritance
CreateProcessWithLogonW
CreateRestrictedToken
CreateTraceInstanceId
CreateWellKnownSid
CredDeleteA
CredDeleteW
CredEnumerateA
CredEnumerateW
CredFree
CredGetSessionTypes
CredGetTargetInfoA
CredGetTargetInfoW
CredIsMarshaledCredentialA
CredIsMarshaledCredentialW
CredMarshalCredentialA
CredMarshalCredentialW
CredProfileLoaded
CredReadA
CredReadDomainCredentialsA
CredReadDomainCredentialsW
CredReadW
CredRenameA
CredRenameW
CredUnmarshalCredentialA
CredUnmarshalCredentialW
CredWriteA
CredWriteDomainCredentialsA
CredWriteDomainCredentialsW
CredWriteW
CredpConvertCredential
CredpConvertTargetInfo
CredpDecodeCredential
CredpEncodeCredential
CryptAcquireContextW
CryptContextAddRef
CryptDuplicateHash
CryptDuplicateKey
CryptEnumProviderTypesA
CryptEnumProviderTypesW
CryptEnumProvidersA
CryptEnumProvidersW
CryptGetDefaultProviderA
CryptGetDefaultProviderW
CryptSetProviderExA
CryptSetProviderExW
CryptSetProviderW
CryptSignHashW
CryptVerifySignatureW
DecryptFileA
DecryptFileW
DuplicateEncryptionInfoFile
DuplicateTokenEx
ElfBackupEventLogFileA
ElfBackupEventLogFileW
ElfChangeNotify
ElfClearEventLogFileA
ElfClearEventLogFileW
ElfCloseEventLog
ElfDeregisterEventSource
ElfNumberOfRecords
ElfOldestRecord
ElfOpenBackupEventLogA
ElfOpenBackupEventLogW
ElfOpenEventLogA
ElfOpenEventLogW
ElfReadEventLogA
ElfReadEventLogW
ElfRegisterEventSourceA
ElfRegisterEventSourceW
ElfReportEventA
ElfReportEventW
EnableTrace
EncryptFileA
EncryptFileW
EncryptedFileKeyInfo
EncryptionDisable
EnumServiceGroupW
EnumServicesStatusExA
EnumServicesStatusExW
EnumerateTraceGuids
EqualDomainSid
FileEncryptionStatusA
FileEncryptionStatusW
FlushTraceA
FlushTraceW
FreeEncryptedFileKeyInfo
FreeEncryptionCertificateHashList
FreeInheritedFromArray
GetAccessPermissionsForObjectA
GetAccessPermissionsForObjectW
GetAuditedPermissionsFromAclA
GetAuditedPermissionsFromAclW
GetCurrentHwProfileA
GetCurrentHwProfileW
GetEffectiveRightsFromAclA
GetEffectiveRightsFromAclW
GetEventLogInformation
GetExplicitEntriesFromAclA
GetExplicitEntriesFromAclW
GetInformationCodeAuthzLevelW
GetInformationCodeAuthzPolicyW
GetInheritanceSourceA
GetInheritanceSourceW
GetLocalManagedApplicationData
GetLocalManagedApplications
GetManagedApplicationCategories
GetManagedApplications
GetMultipleTrusteeA
GetMultipleTrusteeOperationA
GetMultipleTrusteeOperationW
GetMultipleTrusteeW
GetNamedSecurityInfoA
GetNamedSecurityInfoExA
GetNamedSecurityInfoExW
GetNamedSecurityInfoW
GetOverlappedAccessResults
GetSecurityDescriptorRMControl
GetSecurityInfo
GetSecurityInfoExA
GetSecurityInfoExW
GetTraceEnableFlags
GetTraceEnableLevel
GetTraceLoggerHandle
GetTrusteeFormA
GetTrusteeFormW
GetTrusteeNameA
GetTrusteeNameW
GetTrusteeTypeA
GetTrusteeTypeW
GetWindowsAccountDomainSid
I_ScIsSecurityProcess
I_ScPnPGetServiceName
I_ScSendTSMessage
I_ScSetServiceBitsA
I_ScSetServiceBitsW
IdentifyCodeAuthzLevelW
ImpersonateAnonymousToken
InitiateSystemShutdownExA
InitiateSystemShutdownExW
InstallApplication
IsTokenRestricted
IsTokenUntrusted
IsWellKnownSid
LogonUserExA
LogonUserExW
LookupSecurityDescriptorPartsA
LookupSecurityDescriptorPartsW
LsaAddAccountRights
LsaAddPrivilegesToAccount
LsaClearAuditLog
LsaClose
LsaCreateAccount
LsaCreateSecret
LsaCreateTrustedDomain
LsaCreateTrustedDomainEx
LsaDelete
LsaDeleteTrustedDomain
LsaEnumerateAccountRights
LsaEnumerateAccounts
LsaEnumerateAccountsWithUserRight
LsaEnumeratePrivileges
LsaEnumeratePrivilegesOfAccount
LsaEnumerateTrustedDomains
LsaEnumerateTrustedDomainsEx
LsaFreeMemory
LsaGetQuotasForAccount
LsaGetRemoteUserName
LsaGetSystemAccessAccount
LsaGetUserName
LsaICLookupNames
LsaICLookupNamesWithCreds
LsaICLookupSids
LsaICLookupSidsWithCreds
LsaLookupNames2
LsaLookupNames
LsaLookupPrivilegeDisplayName
LsaLookupPrivilegeName
LsaLookupPrivilegeValue
LsaLookupSids
LsaNtStatusToWinError
LsaOpenAccount
LsaOpenPolicy
LsaOpenPolicySce
LsaOpenSecret
LsaOpenTrustedDomain
LsaOpenTrustedDomainByName
LsaQueryDomainInformationPolicy
LsaQueryForestTrustInformation
LsaQueryInfoTrustedDomain
LsaQueryInformationPolicy
LsaQuerySecret
LsaQuerySecurityObject
LsaQueryTrustedDomainInfo
LsaQueryTrustedDomainInfoByName
LsaRemoveAccountRights
LsaRemovePrivilegesFromAccount
LsaRetrievePrivateData
LsaSetDomainInformationPolicy
LsaSetForestTrustInformation
LsaSetInformationPolicy
LsaSetInformationTrustedDomain
LsaSetQuotasForAccount
LsaSetSecret
LsaSetSecurityObject
LsaSetSystemAccessAccount
LsaSetTrustedDomainInfoByName
LsaSetTrustedDomainInformation
LsaStorePrivateData
MD4Final
MD4Init
MD4Update
MD5Final
MD5Init
MD5Update
MSChapSrvChangePassword2
MSChapSrvChangePassword
MakeAbsoluteSD2
ObjectDeleteAuditAlarmA
ObjectDeleteAuditAlarmW
OpenEncryptedFileRawA
OpenEncryptedFileRawW
OpenTraceA
OpenTraceW
ProcessIdleTasks
ProcessTrace
QueryAllTracesA
QueryAllTracesW
QueryRecoveryAgentsOnEncryptedFile
QueryServiceConfig2A
QueryServiceConfig2W
QueryServiceStatusEx
QueryTraceA
QueryTraceW
QueryUsersOnEncryptedFile
QueryWindows31FilesMigration
ReadEncryptedFileRaw
RegDisablePredefinedCache
RegOpenCurrentUser
RegOpenUserClassesRoot
RegOverridePredefKey
RegSaveKeyExA
RegSaveKeyExW
RegisterIdleTask
RegisterServiceCtrlHandlerExA
RegisterServiceCtrlHandlerExW
RegisterTraceGuidsA
RegisterTraceGuidsW
RemoveTraceCallback
RemoveUsersFromEncryptedFile
SaferCloseLevel
SaferComputeTokenFromLevel
SaferCreateLevel
SaferGetLevelInformation
SaferGetPolicyInformation
SaferIdentifyLevel
SaferRecordEventLogEntry
SaferSetLevelInformation
SaferSetPolicyInformation
SaferiChangeRegistryScope
SaferiCompareTokenLevels
SaferiIsExecutableFileType
SaferiPopulateDefaultsInRegistry
SaferiRecordEventLogEntry
SaferiReplaceProcessThreadTokens
SaferiSearchMatchingHashRules
SetEntriesInAccessListA
SetEntriesInAccessListW
SetEntriesInAclA
SetEntriesInAclW
SetEntriesInAuditListA
SetEntriesInAuditListW
SetInformationCodeAuthzLevelW
SetInformationCodeAuthzPolicyW
SetNamedSecurityInfoA
SetNamedSecurityInfoExA
SetNamedSecurityInfoExW
SetNamedSecurityInfoW
SetPrivateObjectSecurityEx
SetSecurityDescriptorControl
SetSecurityDescriptorRMControl
SetSecurityInfo
SetSecurityInfoExA
SetSecurityInfoExW
SetTraceCallback
SetUserFileEncryptionKey
StartTraceA
StartTraceW
StopTraceA
StopTraceW
SynchronizeWindows31FilesAndWindowsNTRegistry
SystemFunction001
SystemFunction002
SystemFunction003
SystemFunction004
SystemFunction005
SystemFunction006
SystemFunction007
SystemFunction008
SystemFunction009
SystemFunction010
SystemFunction011
SystemFunction012
SystemFunction013
SystemFunction014
SystemFunction015
SystemFunction016
SystemFunction017
SystemFunction018
SystemFunction019
SystemFunction020
SystemFunction021
SystemFunction022
SystemFunction023
SystemFunction024
SystemFunction025
SystemFunction026
SystemFunction027
SystemFunction028
SystemFunction029
SystemFunction030
SystemFunction031
SystemFunction032
SystemFunction033
SystemFunction034
SystemFunction035
SystemFunction036
SystemFunction040
SystemFunction041
TraceEvent
TraceEventInstance
TraceMessage
TraceMessageVa
TreeResetNamedSecurityInfoA
TreeResetNamedSecurityInfoW
TrusteeAccessToObjectA
TrusteeAccessToObjectW
UninstallApplication
UnregisterIdleTask
UnregisterTraceGuids
UpdateTraceA
UpdateTraceW
WdmWmiServiceMain
WmiCloseBlock
WmiCloseTraceWithCursor
WmiConvertTimestamp
WmiDevInstToInstanceNameA
WmiDevInstToInstanceNameW
WmiEnumerateGuids
WmiExecuteMethodA
WmiExecuteMethodW
WmiFileHandleToInstanceNameA
WmiFileHandleToInstanceNameW
WmiFreeBuffer
WmiGetFirstTraceOffset
WmiGetNextEvent
WmiGetTraceHeader
WmiMofEnumerateResourcesA
WmiMofEnumerateResourcesW
WmiNotificationRegistrationA
WmiNotificationRegistrationW
WmiOpenBlock
WmiOpenTraceWithCursor
WmiParseTraceEvent
WmiQueryAllDataA
WmiQueryAllDataMultipleA
WmiQueryAllDataMultipleW
WmiQueryAllDataW
WmiQueryGuidInformation
WmiQuerySingleInstanceA
WmiQuerySingleInstanceMultipleA
WmiQuerySingleInstanceMultipleW
WmiQuerySingleInstanceW
WmiReceiveNotificationsA
WmiReceiveNotificationsW
WmiSetSingleInstanceA
WmiSetSingleInstanceW
WmiSetSingleItemA
WmiSetSingleItemW
Wow64Win32ApiEntry
WriteEncryptedFileRaw

Found follow exports in WSOCK32.DLL
MigrateWinsockConfiguration
WEP
WSApSetPostRoutine
inet_network
getnetbyname
rcmd
rexec
rresvport
sethostname
AcceptEx
GetAcceptExSockaddrs

Found follow exports in WS2_32.DLL
accept
bind
closesocket
connect
getpeername
getsockname
getsockopt
htonl
htons
ioctlsocket
inet_addr
inet_ntoa
listen
ntohl
ntohs
recv
recvfrom
select
send
sendto
setsockopt
shutdown
socket
WSApSetPostRoutine
WPUCompleteOverlappedRequest
WSAAccept
WSAAddressToStringA
WSAAddressToStringW
WSACloseEvent
WSAConnect
WSACreateEvent
WSADuplicateSocketA
WSADuplicateSocketW
WSAEnumNameSpaceProvidersA
WSAEnumNameSpaceProvidersW
WSAEnumNetworkEvents
WSAEnumProtocolsA
WSAEnumProtocolsW
WSAEventSelect
WSAGetOverlappedResult
WSAGetQOSByName
WSAGetServiceClassInfoA
WSAGetServiceClassInfoW
WSAGetServiceClassNameByClassIdA
WSAGetServiceClassNameByClassIdW
WSAHtonl
WSAHtons
WSAInstallServiceClassA
WSAInstallServiceClassW
WSAIoctl
gethostbyaddr
gethostbyname
getprotobyname
getprotobynumber
getservbyname
getservbyport
gethostname
WSAJoinLeaf
WSALookupServiceBeginA
WSALookupServiceBeginW
WSALookupServiceEnd
WSALookupServiceNextA
WSALookupServiceNextW
WSANSPIoctl
WSANtohl
WSANtohs
WSAProviderConfigChange
WSARecv
WSARecvDisconnect
WSARecvFrom
WSARemoveServiceClass
WSAResetEvent
WSASend
WSASendDisconnect
WSASendTo
WSASetEvent
WSASetServiceA
WSASetServiceW
WSASocketA
WSASocketW
WSAStringToAddressA
WSAStringToAddressW
WSAWaitForMultipleEvents
WSCDeinstallProvider
WSCEnableNSProvider
WSCEnumProtocols
WSCGetProviderPath
WSCInstallNameSpace
WSCInstallProvider
WSCUnInstallNameSpace
WSCUpdateProvider
WSCWriteNameSpaceOrder
WSCWriteProviderOrder
freeaddrinfo
getaddrinfo
getnameinfo
WSAAsyncSelect
WSAAsyncGetHostByAddr
WSAAsyncGetHostByName
WSAAsyncGetProtoByNumber
WSAAsyncGetProtoByName
WSAAsyncGetServByPort
WSAAsyncGetServByName
WSACancelAsyncRequest
WSASetBlockingHook
WSAUnhookBlockingHook
WSAGetLastError
WSASetLastError
WSACancelBlockingCall
WSAIsBlocking
WSAStartup
WSACleanup
__WSAFDIsSet
WEP

Windows Vista


Found follow exports in KERNEL32.DLL
AcquireSRWLockExclusive
AcquireSRWLockShared
ActivateActCtx
AddConsoleAliasA
AddConsoleAliasW
AddLocalAlternateComputerNameA
AddLocalAlternateComputerNameW
AddRefActCtx
AddSIDToBoundaryDescriptor
AddVectoredContinueHandler
AddVectoredExceptionHandler
AdjustCalendarDate
AllocateUserPhysicalPages
AllocateUserPhysicalPagesNuma
ApplicationRecoveryFinished
ApplicationRecoveryInProgress
AssignProcessToJobObject
AttachConsole
BaseCheckAppcompatCache
BaseCheckRunApp
BaseCleanupAppcompatCacheSupport
BaseDumpAppcompatCache
BaseFlushAppcompatCache
BaseGenerateAppCompatData
BaseInitAppcompatCacheSupport
BaseIsAppcompatInfrastructureDisabled
BasepCheckBadapp
BasepCheckWinSaferRestrictions
BasepFreeAppCompatData
BaseQueryModuleData
BaseThreadInitThunk
BaseUpdateAppcompatCache
BindIoCompletionCallback
CallbackMayRunLong
CancelDeviceWakeupRequest
CancelIo
CancelIoEx
CancelSynchronousIo
CancelThreadpoolIo
CancelTimerQueueTimer
CancelWaitableTimer
ChangeTimerQueueTimer
CheckElevation
CheckElevationEnabled
CheckForReadOnlyResource
CheckNameLegalDOS8Dot3A
CheckNameLegalDOS8Dot3W
CheckRemoteDebuggerPresent
CloseConsoleHandle
ClosePrivateNamespace
CloseThreadpool
CloseThreadpoolCleanupGroup
CloseThreadpoolCleanupGroupMembers
CloseThreadpoolIo
CloseThreadpoolTimer
CloseThreadpoolWait
CloseThreadpoolWork
CmdBatNotification
CompareCalendarDates
CompareStringEx
CompareStringOrdinal
ConsoleMenuControl
ConvertCalDateTimeToSystemTime
ConvertFiberToThread
ConvertNLSDayOfWeekToWin32DayOfWeek
ConvertSystemTimeToCalDateTime
ConvertThreadToFiber
ConvertThreadToFiberEx
CopyFileExA
CopyFileExW
CopyFileTransactedA
CopyFileTransactedW
CopyLZFile
CreateActCtxA
CreateActCtxW
CreateBoundaryDescriptorA
CreateBoundaryDescriptorW
CreateDirectoryTransactedA
CreateDirectoryTransactedW
CreateEventExA
CreateEventExW
CreateFiber
CreateFiberEx
CreateFileMappingNumaA
CreateFileMappingNumaW
CreateFileTransactedA
CreateFileTransactedW
CreateHardLinkA
CreateHardLinkTransactedA
CreateHardLinkTransactedW
CreateHardLinkW
CreateJobObjectA
CreateJobObjectW
CreateJobSet
CreateMemoryResourceNotification
CreateMutexExA
CreateMutexExW
CreatePrivateNamespaceA
CreatePrivateNamespaceW
CreateProcessInternalA
CreateProcessInternalW
CreateSemaphoreExA
CreateSemaphoreExW
CreateSocketHandle
CreateSymbolicLinkA
CreateSymbolicLinkTransactedA
CreateSymbolicLinkTransactedW
CreateSymbolicLinkW
CreateThreadpool
CreateThreadpoolCleanupGroup
CreateThreadpoolIo
CreateThreadpoolTimer
CreateThreadpoolWait
CreateThreadpoolWork
CreateTimerQueue
CreateTimerQueueTimer
CreateToolhelp32Snapshot
CreateWaitableTimerA
CreateWaitableTimerExA
CreateWaitableTimerExW
CreateWaitableTimerW
DeactivateActCtx
DebugActiveProcessStop
DebugBreakProcess
DebugSetProcessKillOnExit
DecodePointer
DecodeSystemPointer
DelayLoadFailureHook
DeleteBoundaryDescriptor
DeleteFiber
DeleteFileTransactedA
DeleteFileTransactedW
DeleteProcThreadAttributeList
DeleteTimerQueue
DeleteTimerQueueEx
DeleteTimerQueueTimer
DeleteVolumeMountPointA
DeleteVolumeMountPointW
DisassociateCurrentThreadFromCallback
DnsHostnameToComputerNameA
DnsHostnameToComputerNameW
DosPathToSessionPathA
DosPathToSessionPathW
DuplicateConsoleHandle
EncodePointer
EncodeSystemPointer
EnumCalendarInfoExA
EnumCalendarInfoExEx
EnumCalendarInfoExW
EnumDateFormatsExA
EnumDateFormatsExEx
EnumDateFormatsExW
EnumerateLocalComputerNamesA
EnumerateLocalComputerNamesW
EnumLanguageGroupLocalesA
EnumLanguageGroupLocalesW
EnumResourceLanguagesExA
EnumResourceLanguagesExW
EnumResourceNamesExA
EnumResourceNamesExW
EnumResourceTypesExA
EnumResourceTypesExW
EnumSystemFirmwareTables
EnumSystemGeoID
EnumSystemLanguageGroupsA
EnumSystemLanguageGroupsW
EnumSystemLocalesEx
EnumTimeFormatsEx
EnumUILanguagesA
EnumUILanguagesW
ExitVDM
ExpungeConsoleCommandHistoryA
ExpungeConsoleCommandHistoryW
FindActCtxSectionGuid
FindActCtxSectionStringA
FindActCtxSectionStringW
FindFirstFileExA
FindFirstFileExW
FindFirstFileNameTransactedW
FindFirstFileNameW
FindFirstFileTransactedA
FindFirstFileTransactedW
FindFirstStreamTransactedW
FindFirstStreamW
FindFirstVolumeA
FindFirstVolumeMountPointA
FindFirstVolumeMountPointW
FindFirstVolumeW
FindNextFileNameW
FindNextStreamW
FindNextVolumeA
FindNextVolumeMountPointA
FindNextVolumeMountPointW
FindNextVolumeW
FindNLSString
FindNLSStringEx
FindVolumeClose
FindVolumeMountPointClose
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
FlushProcessWriteBuffers
FreeLibraryWhenCallbackReturns
FreeUserPhysicalPages
GetApplicationRecoveryCallback
GetApplicationRestartSettings
GetCalendarDateFormat
GetCalendarDateFormatEx
GetCalendarDaysInMonth
GetCalendarDifferenceInDays
GetCalendarInfoA
GetCalendarInfoEx
GetCalendarInfoW
GetCalendarMonthsInYear
GetCalendarSupportedDateRange
GetCalendarWeekNumber
GetComPlusPackageInstallStatus
GetCompressedFileSizeTransactedA
GetCompressedFileSizeTransactedW
GetComputerNameExA
GetComputerNameExW
GetConsoleAliasA
GetConsoleAliasesA
GetConsoleAliasesLengthA
GetConsoleAliasesLengthW
GetConsoleAliasesW
GetConsoleAliasExesA
GetConsoleAliasExesLengthA
GetConsoleAliasExesLengthW
GetConsoleAliasExesW
GetConsoleAliasW
GetConsoleCharType
GetConsoleCommandHistoryA
GetConsoleCommandHistoryLengthA
GetConsoleCommandHistoryLengthW
GetConsoleCommandHistoryW
GetConsoleCursorMode
GetConsoleDisplayMode
GetConsoleFontInfo
GetConsoleFontSize
GetConsoleHardwareState
GetConsoleHistoryInfo
GetConsoleInputExeNameA
GetConsoleInputExeNameW
GetConsoleInputWaitHandle
GetConsoleKeyboardLayoutNameA
GetConsoleKeyboardLayoutNameW
GetConsoleNlsMode
GetConsoleOriginalTitleA
GetConsoleOriginalTitleW
GetConsoleProcessList
GetConsoleScreenBufferInfoEx
GetConsoleSelectionInfo
GetConsoleWindow
GetCPFileNameFromRegistry
GetCPInfoExA
GetCPInfoExW
GetCurrencyFormatEx
GetCurrentActCtx
GetCurrentConsoleFont
GetCurrentConsoleFontEx
GetCurrentProcessorNumber
GetDateFormatEx
GetDevicePowerState
GetDllDirectoryA
GetDllDirectoryW
GetDurationFormat
GetDurationFormatEx
GetDynamicTimeZoneInformation
GetErrorMode
GetExpandedNameA
GetExpandedNameW
GetFileAttributesExA
GetFileAttributesExW
GetFileAttributesTransactedA
GetFileAttributesTransactedW
GetFileBandwidthReservation
GetFileInformationByHandleEx
GetFileMUIInfo
GetFileMUIPath
GetFileSizeEx
GetFinalPathNameByHandleA
GetFinalPathNameByHandleW
GetFirmwareEnvironmentVariableA
GetFirmwareEnvironmentVariableW
GetFullPathNameTransactedA
GetFullPathNameTransactedW
GetGeoInfoA
GetGeoInfoW
GetHandleContext
GetLargePageMinimum
GetLocaleInfoEx
GetLogicalProcessorInformation
GetLongPathNameA
GetLongPathNameTransactedA
GetLongPathNameTransactedW
GetLongPathNameW
GetModuleHandleExA
GetModuleHandleExW
GetNamedPipeAttribute
GetNamedPipeClientComputerNameA
GetNamedPipeClientComputerNameW
GetNamedPipeClientProcessId
GetNamedPipeClientSessionId
GetNamedPipeServerProcessId
GetNamedPipeServerSessionId
GetNativeSystemInfo
GetNextVDMCommand
GetNLSVersion
GetNLSVersionEx
GetNumaAvailableMemoryNode
GetNumaHighestNodeNumber
GetNumaNodeProcessorMask
GetNumaProcessorNode
GetNumaProximityNode
GetNumberFormatEx
GetNumberOfConsoleFonts
GetProcessHandleCount
GetProcessId
GetProcessIdOfThread
GetProcessIoCounters
GetProcessPriorityBoost
GetProcessWorkingSetSizeEx
GetProductInfo
GetQueuedCompletionStatusEx
GetStringScripts
GetSystemDefaultLocaleName
GetSystemDefaultUILanguage
GetSystemFileCacheSize
GetSystemFirmwareTable
GetSystemPreferredUILanguages
GetSystemRegistryQuota
GetSystemTimes
GetSystemWindowsDirectoryA
GetSystemWindowsDirectoryW
GetSystemWow64DirectoryA
GetSystemWow64DirectoryW
GetThreadId
GetThreadIOPendingFlag
GetThreadPreferredUILanguages
GetThreadPriorityBoost
GetThreadUILanguage
GetTickCount64
GetTimeFormatEx
GetUILanguageInfo
GetUserDefaultLocaleName
GetUserDefaultUILanguage
GetUserGeoID
GetUserPreferredUILanguages
GetVDMCurrentDirectories
GetVolumeInformationByHandleW
GetVolumeNameForVolumeMountPointA
GetVolumeNameForVolumeMountPointW
GetVolumePathNameA
GetVolumePathNamesForVolumeNameA
GetVolumePathNamesForVolumeNameW
GetVolumePathNameW
GetWriteWatch
GlobalMemoryStatusEx
Heap32First
Heap32ListFirst
Heap32ListNext
Heap32Next
HeapQueryInformation
HeapSetInformation
HeapSummary
IdnToAscii
IdnToNameprepUnicode
IdnToUnicode
InitializeConditionVariable
InitializeCriticalSectionAndSpinCount
InitializeCriticalSectionEx
InitializeProcThreadAttributeList
InitializeSListHead
InitializeSRWLock
InitOnceBeginInitialize
InitOnceComplete
InitOnceExecuteOnce
InitOnceInitialize
InterlockedCompareExchange
InterlockedCompareExchange64
InterlockedExchangeAdd
InterlockedFlushSList
InterlockedPopEntrySList
InterlockedPushEntrySList
InterlockedPushListSList
InvalidateConsoleDIBits
IsCalendarLeapDay
IsCalendarLeapMonth
IsCalendarLeapYear
IsDebuggerPresent
IsNLSDefinedString
IsNormalizedString
IsProcessInJob
IsProcessorFeaturePresent
IsSystemResumeAutomatic
IsThreadAFiber
IsThreadpoolTimerSet
IsTimeZoneRedirectionEnabled
IsValidCalDateTime
IsValidLanguageGroup
IsValidLocaleName
IsWow64Process
LCIDToLocaleName
LCMapStringEx
LeaveCriticalSectionWhenCallbackReturns
LoadStringBaseExW
LoadStringBaseW
LocaleNameToLCID
LZClose
LZCloseFile
LZCopy
LZCreateFileW
LZDone
LZInit
LZOpenFileA
LZOpenFileW
LZRead
LZSeek
LZStart
MapUserPhysicalPages
MapUserPhysicalPagesScatter
MapViewOfFileExNuma
Module32First
Module32FirstW
Module32Next
Module32NextW
MoveFileTransactedA
MoveFileTransactedW
MoveFileWithProgressA
MoveFileWithProgressW
NeedCurrentDirectoryForExePathA
NeedCurrentDirectoryForExePathW
NlsCheckPolicy
NlsConvertIntegerToString
NlsEventDataDescCreate
NlsGetCacheUpdateCount
NlsUpdateLocale
NlsUpdateSystemLocale
NlsWriteEtwEvent
NormalizeString
NotifyUILanguageChange
OpenConsoleW
OpenFileById
OpenJobObjectA
OpenJobObjectW
OpenPrivateNamespaceA
OpenPrivateNamespaceW
OpenThread
OpenWaitableTimerA
OpenWaitableTimerW
PrivCopyFileExW
PrivMoveFileIdentityW
Process32First
Process32FirstW
Process32Next
Process32NextW
ProcessIdToSessionId
QueryActCtxSettingsW
QueryActCtxW
QueryDepthSList
QueryFullProcessImageNameA
QueryFullProcessImageNameW
QueryIdleProcessorCycleTime
QueryInformationJobObject
QueryMemoryResourceNotification
QueryProcessCycleTime
QueryThreadCycleTime
QueueUserWorkItem
ReadConsoleInputExA
ReadConsoleInputExW
ReadDirectoryChangesW
ReadFileScatter
RegisterApplicationRecoveryCallback
RegisterApplicationRestart
RegisterConsoleIME
RegisterConsoleOS2
RegisterConsoleVDM
RegisterWaitForInputIdle
RegisterWaitForSingleObject
RegisterWaitForSingleObjectEx
RegisterWowBaseHandlers
RegisterWowExec
ReleaseActCtx
ReleaseMutexWhenCallbackReturns
ReleaseSemaphoreWhenCallbackReturns
ReleaseSRWLockExclusive
ReleaseSRWLockShared
RemoveDirectoryTransactedA
RemoveDirectoryTransactedW
RemoveLocalAlternateComputerNameA
RemoveLocalAlternateComputerNameW
RemoveVectoredContinueHandler
RemoveVectoredExceptionHandler
ReOpenFile
ReplaceFile
ReplaceFileA
ReplaceFileW
RequestDeviceWakeup
RequestWakeupLatency
ResetWriteWatch
RestoreLastError
RtlCaptureContext
RtlCaptureStackBackTrace
SetCalendarInfoA
SetCalendarInfoW
SetClientTimeZoneInformation
SetComPlusPackageInstallStatus
SetComputerNameExA
SetComputerNameExW
SetConsoleCursor
SetConsoleCursorMode
SetConsoleDisplayMode
SetConsoleFont
SetConsoleHardwareState
SetConsoleHistoryInfo
SetConsoleIcon
SetConsoleInputExeNameA
SetConsoleInputExeNameW
SetConsoleKeyShortcuts
SetConsoleLocalEUDC
SetConsoleMaximumWindowSize
SetConsoleMenuClose
SetConsoleNlsMode
SetConsoleNumberOfCommandsA
SetConsoleNumberOfCommandsW
SetConsoleOS2OemFormat
SetConsolePalette
SetConsoleScreenBufferInfoEx
SetCriticalSectionSpinCount
SetCurrentConsoleFontEx
SetDllDirectoryA
SetDllDirectoryW
SetDynamicTimeZoneInformation
SetEnvironmentStringsA
SetEnvironmentStringsW
SetEventWhenCallbackReturns
SetFileAttributesTransactedA
SetFileAttributesTransactedW
SetFileBandwidthReservation
SetFileCompletionNotificationModes
SetFileInformationByHandle
SetFileIoOverlappedRange
SetFilePointerEx
SetFileShortNameA
SetFileShortNameW
SetFileValidData
SetFirmwareEnvironmentVariableA
SetFirmwareEnvironmentVariableW
SetHandleContext
SetInformationJobObject
SetLastConsoleEventActive
SetLocalPrimaryComputerNameA
SetLocalPrimaryComputerNameW
SetMessageWaitingIndicator
SetNamedPipeAttribute
SetProcessAffinityMask
SetProcessPriorityBoost
SetProcessWorkingSetSizeEx
SetStdHandleEx
SetSystemFileCacheSize
SetTermsrvAppInstallMode
SetThreadExecutionState
SetThreadIdealProcessor
SetThreadpoolThreadMaximum
SetThreadpoolThreadMinimum
SetThreadpoolTimer
SetThreadpoolWait
SetThreadPreferredUILanguages
SetThreadPriorityBoost
SetThreadStackGuarantee
SetThreadUILanguage
SetTimerQueueTimer
SetUserGeoID
SetVDMCurrentDirectories
SetVolumeMountPointA
SetVolumeMountPointW
SetWaitableTimer
ShowConsoleCursor
SignalObjectAndWait
SleepConditionVariableCS
SleepConditionVariableSRW
StartThreadpoolIo
SubmitThreadpoolWork
SwitchToFiber
SwitchToThread
TerminateJobObject
TermsrvAppInstallMode
Thread32First
Thread32Next
Toolhelp32ReadProcessMemory
TryEnterCriticalSection
TrySubmitThreadpoolCallback
TzSpecificLocalTimeToSystemTime
UnregisterApplicationRecoveryCallback
UnregisterApplicationRestart
UnregisterConsoleIME
UnregisterWait
UnregisterWaitEx
UpdateCalendarDayOfWeek
UpdateProcThreadAttribute
UTRegister
UTUnRegister
VDMConsoleOperation
VDMOperationStarted
VerifyConsoleIoHandle
VerifyScripts
VerifyVersionInfoA
VerifyVersionInfoW
VerSetConditionMask
VirtualAllocEx
VirtualAllocExNuma
VirtualFreeEx
WaitForThreadpoolIoCallbacks
WaitForThreadpoolTimerCallbacks
WaitForThreadpoolWaitCallbacks
WaitForThreadpoolWorkCallbacks
WakeAllConditionVariable
WakeConditionVariable
WerGetFlags
WerpCleanupMessageMapping
WerpInitiateRemoteRecovery
WerpNotifyLoadStringResource
WerpNotifyLoadStringResourceEx
WerpNotifyUseStringResource
WerpStringLookup
WerRegisterFile
WerRegisterMemoryBlock
WerSetFlags
WerUnregisterFile
WerUnregisterMemoryBlock
Wow64DisableWow64FsRedirection
Wow64EnableWow64FsRedirection
Wow64GetThreadContext
Wow64RevertWow64FsRedirection
Wow64SetThreadContext
Wow64SuspendThread
WriteConsoleInputVDMA
WriteConsoleInputVDMW
WriteFileGather
WTSGetActiveConsoleSessionId
ZombifyActCtx

Found follow exports in NTDLL.DLL
A_SHAFinal
A_SHAInit
A_SHAUpdate
abs
_alldiv
_alldvrm
_allmul
_alloca_probe
_alloca_probe_16
_alloca_probe_8
_allrem
_allshl
_allshr
AlpcAdjustCompletionListConcurrencyCount
AlpcFreeCompletionListMessage
AlpcGetCompletionListLastMessageInformation
AlpcGetCompletionListMessageAttributes
AlpcGetHeaderSize
AlpcGetMessageAttribute
AlpcGetMessageFromCompletionList
AlpcGetOutstandingCompletionListMessageCount
AlpcInitializeMessageAttribute
AlpcMaxAllowedMessageLength
AlpcRegisterCompletionList
AlpcRegisterCompletionListWorkerThread
AlpcUnregisterCompletionList
AlpcUnregisterCompletionListWorkerThread
atan
atoi
_atoi64
atol
_aulldiv
_aulldvrm
_aullrem
_aullshr
bsearch
ceil
_chkstk
_CIcos
_CIlog
_CIpow
_CIsin
_CIsqrt
cos
CsrAllocateCaptureBuffer
CsrAllocateMessagePointer
CsrCaptureMessageBuffer
CsrCaptureMessageMultiUnicodeStringsInPlace
CsrCaptureMessageString
CsrCaptureTimeout
CsrClientCallServer
CsrClientConnectToServer
CsrFreeCaptureBuffer
CsrGetProcessId
CsrIdentifyAlertableThread
CsrNewThread
CsrSetPriorityClass
CsrVerifyRegion
DbgPrintEx
DbgPrintReturnControlC
DbgQueryDebugFilterState
DbgSetDebugFilterState
DbgUiConnectToDbg
DbgUiContinue
DbgUiConvertStateChangeStructure
DbgUiDebugActiveProcess
DbgUiGetThreadDebugObject
DbgUiIssueRemoteBreakin
DbgUiRemoteBreakin
DbgUiSetThreadDebugObject
DbgUiStopDebugging
DbgUiWaitStateChange
DbgUserBreakPoint
EtwCreateTraceInstanceId
EtwDeliverDataBlock
EtwEnumerateProcessRegGuids
EtwEventActivityIdControl
EtwEventEnabled
EtwEventProviderEnabled
EtwEventRegister
EtwEventUnregister
EtwEventWrite
EtwEventWriteEndScenario
EtwEventWriteFull
EtwEventWriteStartScenario
EtwEventWriteString
EtwEventWriteTransfer
EtwGetTraceEnableFlags
EtwGetTraceEnableLevel
EtwGetTraceLoggerHandle
EtwLogTraceEvent
EtwNotificationRegister
EtwNotificationUnregister
EtwpCreateEtwThread
EtwpGetCpuSpeed
EtwpNotificationThread
EtwProcessPrivateLoggerRequest
EtwRegisterSecurityProvider
EtwRegisterTraceGuidsA
EtwRegisterTraceGuidsW
EtwReplyNotification
EtwSendNotification
EtwSetMark
EtwTraceEventInstance
EtwTraceMessage
EtwTraceMessageVa
EtwUnregisterTraceGuids
EtwWriteUMSecurityEvent
ExpInterlockedPopEntrySListEnd
ExpInterlockedPopEntrySListFault
ExpInterlockedPopEntrySListResume
fabs
floor
_fltused
_ftol
_i64toa
_i64tow
isalnum
isalpha
__isascii
iscntrl
__iscsym
__iscsymf
isdigit
isgraph
islower
isprint
ispunct
isspace
isupper
iswalpha
iswctype
iswdigit
iswlower
iswspace
iswxdigit
isxdigit
_itoa
_itow
KiFastSystemCall
KiFastSystemCallRet
KiIntSystemCall
KiRaiseUserExceptionDispatcher
KiUserApcDispatcher
KiUserCallbackDispatcher
KiUserExceptionDispatcher
labs
LdrAccessResource
LdrAddLoadAsDataTable
LdrAddRefDll
LdrDisableThreadCalloutsForDll
LdrEnumerateLoadedModules
LdrEnumResources
LdrFindEntryForAddress
LdrFindResource_U
LdrFindResourceDirectory_U
LdrFindResourceEx_U
LdrFlushAlternateResourceModules
LdrGetDllHandle
LdrGetDllHandleEx
LdrGetFailureData
LdrGetFileNameFromLoadAsDataTable
LdrGetProcedureAddress
LdrGetProcedureAddressEx
LdrHotPatchRoutine
LdrInitializeThunk
LdrInitShimEngineDynamic
LdrLoadAlternateResourceModule
LdrLoadAlternateResourceModuleEx
LdrLoadDll
LdrLockLoaderLock
LdrOpenImageFileOptionsKey
LdrProcessRelocationBlock
LdrQueryImageFileExecutionOptions
LdrQueryImageFileExecutionOptionsEx
LdrQueryImageFileKeyOption
LdrQueryModuleServiceTags
LdrQueryProcessModuleInformation
LdrRegisterDllNotification
LdrRemoveLoadAsDataTable
LdrResFindResource
LdrResFindResourceDirectory
LdrResRelease
LdrResSearchResource
LdrSetAppCompatDllRedirectionCallback
LdrSetDllManifestProber
LdrSetMUICacheType
LdrShutdownProcess
LdrShutdownThread
LdrUnloadAlternateResourceModule
LdrUnloadAlternateResourceModuleEx
LdrUnloadDll
LdrUnlockLoaderLock
LdrUnregisterDllNotification
LdrVerifyImageMatchesChecksum
LdrVerifyImageMatchesChecksumEx
_lfind
log
_ltoa
_ltow
mbstowcs
MD4Final
MD4Init
MD4Update
MD5Final
MD5Init
MD5Update
_memccpy
memchr
memcmp
memcpy
_memicmp
memmove
memset
NlsAnsiCodePage
NlsMbCodePageTag
NlsMbOemCodePageTag
NtAcceptConnectPort
NtAccessCheck
NtAccessCheckAndAuditAlarm
NtAccessCheckByType
NtAccessCheckByTypeAndAuditAlarm
NtAccessCheckByTypeResultList
NtAccessCheckByTypeResultListAndAuditAlarm
NtAccessCheckByTypeResultListAndAuditAlarmByHandle
NtAcquireCMFViewOwnership
NtAddAtom
NtAddBootEntry
NtAddDriverEntry
NtAdjustGroupsToken
NtAdjustPrivilegesToken
NtAlertResumeThread
NtAlertThread
NtAllocateLocallyUniqueId
NtAllocateUserPhysicalPages
NtAllocateUuids
NtAllocateVirtualMemory
NtAlpcAcceptConnectPort
NtAlpcCancelMessage
NtAlpcConnectPort
NtAlpcCreatePort
NtAlpcCreatePortSection
NtAlpcCreateResourceReserve
NtAlpcCreateSectionView
NtAlpcCreateSecurityContext
NtAlpcDeletePortSection
NtAlpcDeleteResourceReserve
NtAlpcDeleteSectionView
NtAlpcDeleteSecurityContext
NtAlpcDisconnectPort
NtAlpcImpersonateClientOfPort
NtAlpcOpenSenderProcess
NtAlpcOpenSenderThread
NtAlpcQueryInformation
NtAlpcQueryInformationMessage
NtAlpcRevokeSecurityContext
NtAlpcSendWaitReceivePort
NtAlpcSetInformation
NtApphelpCacheControl
NtAreMappedFilesTheSame
NtAssignProcessToJobObject
NtCallbackReturn
NtCancelDeviceWakeupRequest
NtCancelIoFile
NtCancelIoFileEx
NtCancelSynchronousIoFile
NtCancelTimer
NtClearAllSavepointsTransaction
NtClearEvent
NtClearSavepointTransaction
NtClose
NtCloseObjectAuditAlarm
NtCommitComplete
NtCommitEnlistment
NtCommitTransaction
NtCompactKeys
NtCompareTokens
NtCompleteConnectPort
NtCompressKey
NtConnectPort
NtContinue
NtCreateDebugObject
NtCreateDirectoryObject
NtCreateEnlistment
NtCreateEvent
NtCreateEventPair
NtCreateFile
NtCreateIoCompletion
NtCreateJobObject
NtCreateJobSet
NtCreateKey
NtCreateKeyedEvent
NtCreateKeyTransacted
NtCreateMailslotFile
NtCreateMutant
NtCreateNamedPipeFile
NtCreatePagingFile
NtCreatePort
NtCreatePrivateNamespace
NtCreateProcess
NtCreateProcessEx
NtCreateProfile
NtCreateResourceManager
NtCreateSection
NtCreateSemaphore
NtCreateSymbolicLinkObject
NtCreateThread
NtCreateThreadEx
NtCreateTimer
NtCreateToken
NtCreateTransaction
NtCreateTransactionManager
NtCreateUserProcess
NtCreateWaitablePort
NtCreateWorkerFactory
NtDebugActiveProcess
NtDebugContinue
NtDelayExecution
NtDeleteAtom
NtDeleteBootEntry
NtDeleteDriverEntry
NtDeleteFile
NtDeleteKey
NtDeleteObjectAuditAlarm
NtDeletePrivateNamespace
NtDeleteValueKey
NtDeviceIoControlFile
NtDisplayString
NtDuplicateObject
NtDuplicateToken
NtEnumerateBootEntries
NtEnumerateDriverEntries
NtEnumerateKey
NtEnumerateSystemEnvironmentValuesEx
NtEnumerateTransactionObject
NtEnumerateValueKey
NtExtendSection
NtFilterToken
NtFindAtom
NtFlushBuffersFile
NtFlushInstallUILanguage
NtFlushInstructionCache
NtFlushKey
NtFlushProcessWriteBuffers
NtFlushVirtualMemory
NtFlushWriteBuffer
NtFreeUserPhysicalPages
NtFreeVirtualMemory
NtFreezeRegistry
NtFreezeTransactions
NtFsControlFile
NtGetContextThread
NtGetCurrentProcessorNumber
NtGetDevicePowerState
NtGetMUIRegistryInfo
NtGetNextProcess
NtGetNextThread
NtGetNlsSectionPtr
NtGetNotificationResourceManager
NtGetPlugPlayEvent
NtGetTickCount
NtGetWriteWatch
NtImpersonateAnonymousToken
NtImpersonateClientOfPort
NtImpersonateThread
NtInitializeNlsFiles
NtInitializeRegistry
NtInitiatePowerAction
NtIsProcessInJob
NtIsSystemResumeAutomatic
NtIsUILanguageComitted
NtListenPort
NtListTransactions
NtLoadDriver
NtLoadKey
NtLoadKey2
NtLoadKeyEx
NtLockFile
NtLockProductActivationKeys
NtLockRegistryKey
NtLockVirtualMemory
NtMakePermanentObject
NtMakeTemporaryObject
NtMapCMFModule
NtMapUserPhysicalPages
NtMapUserPhysicalPagesScatter
NtMapViewOfSection
NtMarshallTransaction
NtModifyBootEntry
NtModifyDriverEntry
NtNotifyChangeDirectoryFile
NtNotifyChangeKey
NtNotifyChangeMultipleKeys
NtOpenDirectoryObject
NtOpenEnlistment
NtOpenEvent
NtOpenEventPair
NtOpenFile
NtOpenIoCompletion
NtOpenJobObject
NtOpenKey
NtOpenKeyedEvent
NtOpenKeyTransacted
NtOpenMutant
NtOpenObjectAuditAlarm
NtOpenPrivateNamespace
NtOpenProcess
NtOpenProcessToken
NtOpenProcessTokenEx
NtOpenResourceManager
NtOpenSection
NtOpenSemaphore
NtOpenSession
NtOpenSymbolicLinkObject
NtOpenThread
NtOpenThreadToken
NtOpenThreadTokenEx
NtOpenTimer
NtOpenTransaction
NtOpenTransactionManager
NtPlugPlayControl
NtPowerInformation
NtPrepareComplete
NtPrepareEnlistment
NtPrePrepareComplete
NtPrePrepareEnlistment
NtPrivilegeCheck
NtPrivilegedServiceAuditAlarm
NtPrivilegeObjectAuditAlarm
NtPropagationComplete
NtPropagationFailed
NtProtectVirtualMemory
NtPullTransaction
NtPulseEvent
NtQueryAttributesFile
NtQueryBootEntryOrder
NtQueryBootOptions
NtQueryDebugFilterState
NtQueryDefaultLocale
NtQueryDefaultUILanguage
NtQueryDirectoryFile
NtQueryDirectoryObject
NtQueryDriverEntryOrder
NtQueryEaFile
NtQueryEvent
NtQueryFullAttributesFile
NtQueryInformationAtom
NtQueryInformationEnlistment
NtQueryInformationFile
NtQueryInformationJobObject
NtQueryInformationPort
NtQueryInformationProcess
NtQueryInformationResourceManager
NtQueryInformationThread
NtQueryInformationToken
NtQueryInformationTransaction
NtQueryInformationTransactionManager
NtQueryInformationWorkerFactory
NtQueryInstallUILanguage
NtQueryIntervalProfile
NtQueryIoCompletion
NtQueryKey
NtQueryLicenseValue
NtQueryMultipleValueKey
NtQueryMutant
NtQueryObject
NtQueryOpenSubKeys
NtQueryOpenSubKeysEx
NtQueryPortInformationProcess
NtQueryQuotaInformationFile
NtQuerySection
NtQuerySecurityObject
NtQuerySemaphore
NtQuerySymbolicLinkObject
NtQuerySystemEnvironmentValue
NtQuerySystemEnvironmentValueEx
NtQuerySystemInformation
NtQuerySystemTime
NtQueryTimer
NtQueryTimerResolution
NtQueryValueKey
NtQueryVirtualMemory
NtQueryVolumeInformationFile
NtQueueApcThread
NtRaiseException
NtRaiseHardError
NtReadFile
NtReadFileScatter
NtReadOnlyEnlistment
NtReadRequestData
NtReadVirtualMemory
NtRecoverEnlistment
NtRecoverResourceManager
NtRecoverTransactionManager
NtRegisterProtocolAddressInformation
NtRegisterThreadTerminatePort
NtReleaseCMFViewOwnership
NtReleaseKeyedEvent
NtReleaseMutant
NtReleaseSemaphore
NtReleaseWorkerFactoryWorker
NtRemoveIoCompletion
NtRemoveIoCompletionEx
NtRemoveProcessDebug
NtRenameKey
NtReplaceKey
NtReplyPort
NtReplyWaitReceivePort
NtReplyWaitReceivePortEx
NtReplyWaitReplyPort
NtRequestDeviceWakeup
NtRequestPort
NtRequestWaitReplyPort
NtRequestWakeupLatency
NtResetEvent
NtResetWriteWatch
NtRestoreKey
NtResumeProcess
NtResumeThread
NtRollbackComplete
NtRollbackEnlistment
NtRollbackSavepointTransaction
NtRollbackTransaction
NtRollforwardTransactionManager
NtSaveKey
NtSaveKeyEx
NtSaveMergedKeys
NtSavepointComplete
NtSavepointTransaction
NtSecureConnectPort
NtSetBootEntryOrder
NtSetBootOptions
NtSetContextThread
NtSetDebugFilterState
NtSetDefaultHardErrorPort
NtSetDefaultLocale
NtSetDefaultUILanguage
NtSetDriverEntryOrder
NtSetEaFile
NtSetEvent
NtSetEventBoostPriority
NtSetHighEventPair
NtSetHighWaitLowEventPair
NtSetInformationDebugObject
NtSetInformationEnlistment
NtSetInformationFile
NtSetInformationJobObject
NtSetInformationKey
NtSetInformationObject
NtSetInformationProcess
NtSetInformationResourceManager
NtSetInformationThread
NtSetInformationToken
NtSetInformationTransaction
NtSetInformationTransactionManager
NtSetInformationWorkerFactory
NtSetIntervalProfile
NtSetIoCompletion
NtSetLdtEntries
NtSetLowEventPair
NtSetLowWaitHighEventPair
NtSetQuotaInformationFile
NtSetSecurityObject
NtSetSystemEnvironmentValue
NtSetSystemEnvironmentValueEx
NtSetSystemInformation
NtSetSystemPowerState
NtSetSystemTime
NtSetThreadExecutionState
NtSetTimer
NtSetTimerResolution
NtSetUuidSeed
NtSetValueKey
NtSetVolumeInformationFile
NtShutdownSystem
NtShutdownWorkerFactory
NtSignalAndWaitForSingleObject
NtSinglePhaseReject
NtStartProfile
NtStartTm
NtStopProfile
NtSuspendProcess
NtSuspendThread
NtSystemDebugControl
NtTerminateJobObject
NtTerminateProcess
NtTerminateThread
NtTestAlert
NtThawRegistry
NtThawTransactions
NtTraceControl
NtTraceEvent
NtTranslateFilePath
NtUnloadDriver
NtUnloadKey
NtUnloadKey2
NtUnloadKeyEx
NtUnlockFile
NtUnlockVirtualMemory
NtUnmapViewOfSection
NtVdmControl
NtWaitForDebugEvent
NtWaitForKeyedEvent
NtWaitForMultipleObjects
NtWaitForMultipleObjects32
NtWaitForSingleObject
NtWaitForWorkViaWorkerFactory
NtWaitHighEventPair
NtWaitLowEventPair
NtWorkerFactoryWorkerReady
NtWriteFile
NtWriteFileGather
NtWriteRequestData
NtWriteVirtualMemory
NtYieldExecution
PfxFindPrefix
PfxInitialize
PfxInsertPrefix
PfxRemovePrefix
pow
qsort
ResCCloseRuntimeView
ResCCompareCacheIDs
ResCCreateCultureMap
ResCCreateDefaultCultureMap
ResCCreateRuntimeView
ResCDirectoryCreateAndPopulate
ResCDirectoryCreateMapping
ResCDirectoryFree
ResCDirectoryGetBaseFolder
ResCDirectoryGetEntry
ResCDirectoryGetEntryCopy
ResCDirectoryGetEntryEx
ResCDirectoryGetEntryExCopy
ResCDirectoryGetEntryIndex
ResCDirectoryGetEntryIndexEx
ResCDirectoryGetFirstEntry
ResCDirectoryGetFirstEntryIndex
ResCDirectoryGetSegmentIndex
ResCDirectoryGetSegmentName
ResCDirectoryLoadFixedSize
ResCDirectoryOpenMapping
ResCFreeCultureMap
ResCGetCacheIndices
ResCGetCultureID
ResCGetCultureIndex
ResCGetCultureName
ResCGetHighestCacheIndex
ResCGetHighestConsecutiveCacheIndex
ResCGetIndexedName
ResCGetName
ResCGetRegistryBaseFolder
ResCGetRegistryConfig
_ResCGetRegistryFlags
ResCGetRegistryLatestIndex
ResCGetRegistryMappingPrefix
ResCGetRegistryStatus
ResCGetSubIndexedName
ResCInitRuntimeView
ResCInitRuntimeViewEx
ResCKeDirectoryOpenMapping
ResCKeGetBaseFolder
ResCKeGetCacheIndices
ResCKeInitRuntimeViewEx
ResCKeSegmentOpenMapping
ResCLoadCultureMap
_ResCMatchFlags
ResCOpenRegistryKey
ResCOpenRuntimeView
ResCReleaseInitMutex
ResCReloadCultureMap
ResCRequestInitMutex
ResCRuntimeGetAnySegmentData
ResCRuntimeGetCultureID
ResCRuntimeGetEntryData
ResCRuntimeGetEntryDataEx
ResCRuntimeGetResourceData
ResCRuntimeGetResourceDataEx
ResCRuntimeGetResourceDataForCulture
ResCRuntimeGetSegmentData
ResCRuntimeGetSegmentDataEx
ResCRuntimeViewLoadCultureMap
ResCSaveRegistryBaseFolder
ResCSaveRegistryConfig
_ResCSaveRegistryFlags
ResCSaveRegistryLatestIndex
ResCSaveRegistryStatus
ResCSegmentCreateAndPopulate
ResCSegmentCreateMapping
ResCSegmentFree
ResCSegmentGetData
ResCSegmentLoadFixedSize
ResCSegmentOpenMapping
ResCSegmentReserveMapping
ResCSetCacheSecurityType
RtlAbortRXact
RtlAbsoluteToSelfRelativeSD
RtlAcquirePebLock
RtlAcquirePrivilege
RtlAcquireResourceExclusive
RtlAcquireResourceShared
RtlAcquireSRWLockExclusive
RtlAcquireSRWLockShared
RtlActivateActivationContext
RtlActivateActivationContextEx
RtlActivateActivationContextUnsafeFast
RtlAddAccessAllowedAce
RtlAddAccessAllowedAceEx
RtlAddAccessAllowedObjectAce
RtlAddAccessDeniedAce
RtlAddAccessDeniedAceEx
RtlAddAccessDeniedObjectAce
RtlAddAce
RtlAddActionToRXact
RtlAddAtomToAtomTable
RtlAddAttributeActionToRXact
RtlAddAuditAccessAce
RtlAddAuditAccessAceEx
RtlAddAuditAccessObjectAce
RtlAddCompoundAce
RtlAddMandatoryAce
RtlAddRefActivationContext
RtlAddRefMemoryStream
RtlAddressInSectionTable
RtlAddSIDToBoundaryDescriptor
RtlAddVectoredContinueHandler
RtlAddVectoredExceptionHandler
RtlAdjustPrivilege
RtlAllocateActivationContextStack
RtlAllocateAndInitializeSid
RtlAllocateHandle
RtlAllocateMemoryBlockLookaside
RtlAllocateMemoryZone
RtlAnsiCharToUnicodeChar
RtlAnsiStringToUnicodeSize
RtlAppendAsciizToString
RtlAppendPathElement
RtlAppendStringToString
RtlAppendUnicodeStringToString
RtlAppendUnicodeToString
RtlApplicationVerifierStop
RtlApplyRXact
RtlApplyRXactNoFlush
RtlAreAllAccessesGranted
RtlAreAnyAccessesGranted
RtlAreBitsClear
RtlAreBitsSet
RtlAssert
RtlBarrier
RtlBarrierForDelete
RtlCancelTimer
RtlCaptureContext
RtlCaptureStackBackTrace
RtlCaptureStackContext
RtlCharToInteger
RtlCheckForOrphanedCriticalSections
RtlCheckRegistryKey
RtlCleanUpTEBLangLists
RtlClearAllBits
RtlClearBits
RtlCloneMemoryStream
RtlCloneUserProcess
RtlCmDecodeMemIoResource
RtlCmEncodeMemIoResource
RtlCommitDebugInfo
RtlCommitMemoryStream
RtlCompactHeap
RtlCompareAltitudes
RtlCompareMemory
RtlCompareMemoryUlong
RtlCompareString
RtlCompareUnicodeString
RtlCompareUnicodeStrings
RtlCompressBuffer
RtlComputeCrc32
RtlComputeImportTableHash
RtlComputePrivatizedDllName_U
RtlConnectToSm
RtlConsoleMultiByteToUnicodeN
RtlConvertExclusiveToShared
RtlConvertLCIDToString
RtlConvertSharedToExclusive
RtlConvertSidToUnicodeString
RtlConvertToAutoInheritSecurityObject
RtlConvertUiListToApiList
RtlCopyLuid
RtlCopyLuidAndAttributesArray
RtlCopyMappedMemory
RtlCopyMemoryStreamTo
RtlCopyOutOfProcessMemoryStreamTo
RtlCopySecurityDescriptor
RtlCopySid
RtlCopySidAndAttributesArray
RtlCopyString
RtlCopyUnicodeString
RtlCreateAcl
RtlCreateActivationContext
RtlCreateAndSetSD
RtlCreateAtomTable
RtlCreateBootStatusDataFile
RtlCreateBoundaryDescriptor
RtlCreateEnvironment
RtlCreateEnvironmentEx
RtlCreateMemoryBlockLookaside
RtlCreateMemoryZone
RtlCreateProcessParameters
RtlCreateProcessParametersEx
RtlCreateQueryDebugBuffer
RtlCreateRegistryKey
RtlCreateSecurityDescriptor
RtlCreateServiceSid
RtlCreateSystemVolumeInformationFolder
RtlCreateTagHeap
RtlCreateTimer
RtlCreateTimerQueue
RtlCreateUnicodeString
RtlCreateUnicodeStringFromAsciiz
RtlCreateUserProcess
RtlCreateUserSecurityObject
RtlCreateUserStack
RtlCreateUserThread
RtlCultureNameToLCID
RtlCustomCPToUnicodeN
RtlCutoverTimeToSystemTime
RtlDeactivateActivationContext
RtlDeactivateActivationContextUnsafeFast
RtlDebugPrintTimes
RtlDecodePointer
RtlDecodeSystemPointer
RtlDeCommitDebugInfo
RtlDecompressBuffer
RtlDecompressFragment
RtlDefaultNpAcl
RtlDelete
RtlDeleteAce
RtlDeleteAtomFromAtomTable
RtlDeleteBarrier
RtlDeleteBoundaryDescriptor
RtlDeleteCriticalSection
RtlDeleteElementGenericTable
RtlDeleteElementGenericTableAvl
RtlDeleteNoSplay
RtlDeleteRegistryValue
RtlDeleteResource
RtlDeleteSecurityObject
RtlDeleteTimer
RtlDeleteTimerQueue
RtlDeleteTimerQueueEx
RtlDeNormalizeProcessParams
RtlDeregisterWait
RtlDeregisterWaitEx
RtlDestroyAtomTable
RtlDestroyEnvironment
RtlDestroyHandleTable
RtlDestroyMemoryBlockLookaside
RtlDestroyMemoryZone
RtlDestroyProcessParameters
RtlDestroyQueryDebugBuffer
RtlDetermineDosPathNameType_U
RtlDllShutdownInProgress
RtlDnsHostNameToComputerName
RtlDoesFileExists_U
RtlDosApplyFileIsolationRedirection_Ustr
RtlDosPathNameToNtPathName_U
RtlDosPathNameToNtPathName_U_WithStatus
RtlDosPathNameToRelativeNtPathName_U
RtlDosPathNameToRelativeNtPathName_U_WithStatus
RtlDosSearchPath_U
RtlDosSearchPath_Ustr
RtlDowncaseUnicodeChar
RtlDowncaseUnicodeString
RtlDumpResource
RtlDuplicateUnicodeString
RtlEmptyAtomTable
RtlEnableEarlyCriticalSectionEventCreation
RtlEncodePointer
RtlEncodeSystemPointer
RtlEnterCriticalSection
RtlEnumerateGenericTable
RtlEnumerateGenericTableAvl
RtlEnumerateGenericTableLikeADirectory
RtlEnumerateGenericTableWithoutSplaying
RtlEnumerateGenericTableWithoutSplayingAvl
RtlEnumProcessHeaps
RtlEqualComputerName
RtlEqualDomainName
RtlEqualLuid
RtlEqualPrefixSid
RtlEqualSid
RtlEqualString
RtlEqualUnicodeString
RtlEraseUnicodeString
RtlExitUserProcess
RtlExitUserThread
RtlExpandEnvironmentStrings
RtlExpandEnvironmentStrings_U
RtlExtendMemoryBlockLookaside
RtlExtendMemoryZone
RtlFillMemory
RtlFillMemoryUlong
RtlFinalReleaseOutOfProcessMemoryStream
RtlFindAceByType
RtlFindActivationContextSectionGuid
RtlFindActivationContextSectionString
RtlFindCharInUnicodeString
RtlFindClearBits
RtlFindClearBitsAndSet
RtlFindClearRuns
RtlFindClosestEncodableLength
RtlFindLastBackwardRunClear
RtlFindLeastSignificantBit
RtlFindLongestRunClear
RtlFindMessage
RtlFindMostSignificantBit
RtlFindNextForwardRunClear
RtlFindSetBits
RtlFindSetBitsAndClear
RtlFirstEntrySList
RtlFirstFreeAce
RtlFlsAlloc
RtlFlsFree
RtlFlushSecureMemoryCache
RtlFormatCurrentUserKeyPath
RtlFormatMessage
RtlFormatMessageEx
RtlFreeActivationContextStack
RtlFreeAnsiString
RtlFreeHandle
RtlFreeMemoryBlockLookaside
RtlFreeOemString
RtlFreeSid
RtlFreeThreadActivationContextStack
RtlFreeUnicodeString
RtlFreeUserStack
RtlGenerate8dot3Name
RtlGetAce
RtlGetActiveActivationContext
RtlGetCallersAddress
RtlGetCompressionWorkSpaceSize
RtlGetControlSecurityDescriptor
RtlGetCriticalSectionRecursionCount
RtlGetCurrentDirectory_U
RtlGetCurrentPeb
RtlGetCurrentProcessorNumber
RtlGetCurrentTransaction
RtlGetDaclSecurityDescriptor
RtlGetElementGenericTable
RtlGetElementGenericTableAvl
RtlGetFileMUIPath
RtlGetFrame
RtlGetFullPathName_U
RtlGetFullPathName_UstrEx
RtlGetGroupSecurityDescriptor
RtlGetIntegerAtom
RtlGetLastNtStatus
RtlGetLastWin32Error
RtlGetLengthWithoutLastFullDosOrNtPathElement
RtlGetLengthWithoutTrailingPathSeperators
RtlGetLongestNtPathLength
RtlGetNativeSystemInformation
RtlGetNtGlobalFlags
RtlGetNtProductType
RtlGetNtVersionNumbers
RtlGetOwnerSecurityDescriptor
RtlGetParentLocaleName
RtlGetProcessHeaps
RtlGetProductInfo
RtlGetSaclSecurityDescriptor
RtlGetSecurityDescriptorRMControl
RtlGetSetBootStatusData
RtlGetSystemPreferredUILanguages
RtlGetThreadErrorMode
RtlGetThreadLangIdByIndex
RtlGetThreadPreferredUILanguages
RtlGetUILanguageInfo
RtlGetUnloadEventTrace
RtlGetUnloadEventTraceEx
RtlGetUserInfoHeap
RtlGetUserPreferredUILanguages
RtlGetVersion
RtlGUIDFromString
RtlHashUnicodeString
RtlHeapTrkInitialize
RtlIdentifierAuthoritySid
RtlIdnToAscii
RtlIdnToNameprepUnicode
RtlIdnToUnicode
RtlImageDirectoryEntryToData
RtlImageNtHeaderEx
RtlImageRvaToSection
RtlImageRvaToVa
RtlImpersonateSelf
RtlImpersonateSelfEx
RtlInitAnsiString
RtlInitAnsiStringEx
RtlInitBarrier
RtlInitCodePageTable
RtlInitializeAtomPackage
RtlInitializeBitMap
RtlInitializeConditionVariable
RtlInitializeContext
RtlInitializeCriticalSection
RtlInitializeCriticalSectionAndSpinCount
RtlInitializeCriticalSectionEx
RtlInitializeGenericTable
RtlInitializeGenericTableAvl
RtlInitializeHandleTable
RtlInitializeNtUserPfn
RtlInitializeResource
RtlInitializeRXact
RtlInitializeSid
RtlInitializeSListHead
RtlInitializeSRWLock
RtlInitMemoryStream
RtlInitNlsTables
RtlInitOutOfProcessMemoryStream
RtlInitString
RtlInitUnicodeString
RtlInitUnicodeStringEx
RtlInsertElementGenericTable
RtlInsertElementGenericTableAvl
RtlInsertElementGenericTableFull
RtlInsertElementGenericTableFullAvl
RtlInt64ToUnicodeString
RtlIntegerToChar
RtlIntegerToUnicodeString
RtlInterlockedCompareExchange64
RtlInterlockedFlushSList
RtlInterlockedPopEntrySList
RtlInterlockedPushEntrySList
RtlInterlockedPushListSList
RtlIoDecodeMemIoResource
RtlIoEncodeMemIoResource
RtlIpv4AddressToStringA
RtlIpv4AddressToStringExA
RtlIpv4AddressToStringExW
RtlIpv4AddressToStringW
RtlIpv4StringToAddressA
RtlIpv4StringToAddressExA
RtlIpv4StringToAddressExW
RtlIpv4StringToAddressW
RtlIpv6AddressToStringA
RtlIpv6AddressToStringExA
RtlIpv6AddressToStringExW
RtlIpv6AddressToStringW
RtlIpv6StringToAddressA
RtlIpv6StringToAddressExA
RtlIpv6StringToAddressExW
RtlIpv6StringToAddressW
RtlIsActivationContextActive
RtlIsCriticalSectionLocked
RtlIsCriticalSectionLockedByThread
RtlIsCurrentThreadAttachExempt
RtlIsDosDeviceName_U
RtlIsGenericTableEmpty
RtlIsGenericTableEmptyAvl
RtlIsNameLegalDOS8Dot3
RtlIsNormalizedString
RtlIsTextUnicode
RtlIsThreadWithinLoaderCallout
RtlIsValidHandle
RtlIsValidIndexHandle
RtlIsValidLocaleName
RtlLargeIntegerToChar
RtlLCIDToCultureName
RtlLcidToLocaleName
RtlLeaveCriticalSection
RtlLengthRequiredSid
RtlLengthSecurityDescriptor
RtlLengthSid
RtlLocaleNameToLcid
RtlLocalTimeToSystemTime
RtlLockBootStatusData
RtlLockCurrentThread
RtlLockHeap
RtlLockMemoryBlockLookaside
RtlLockMemoryStreamRegion
RtlLockMemoryZone
RtlLockModuleSection
RtlLogStackBackTrace
RtlLookupAtomInAtomTable
RtlLookupElementGenericTable
RtlLookupElementGenericTableAvl
RtlLookupElementGenericTableFull
RtlLookupElementGenericTableFullAvl
RtlMakeSelfRelativeSD
RtlMapGenericMask
RtlMapSecurityErrorToNtStatus
RtlMoveMemory
RtlMultiAppendUnicodeStringBuffer
RtlMultiByteToUnicodeSize
RtlMultipleAllocateHeap
RtlMultipleFreeHeap
RtlNewInstanceSecurityObject
RtlNewSecurityGrantedAccess
RtlNewSecurityObject
RtlNewSecurityObjectEx
RtlNewSecurityObjectWithMultipleInheritance
RtlNormalizeProcessParams
RtlNormalizeString
RtlNtPathNameToDosPathName
RtlNtStatusToDosError
RtlNtStatusToDosErrorNoTeb
RtlNumberGenericTableElements
RtlNumberGenericTableElementsAvl
RtlNumberOfClearBits
RtlNumberOfSetBits
RtlOemStringToUnicodeSize
RtlOemStringToUnicodeString
RtlOemToUnicodeN
RtlOpenCurrentUser
RtlOwnerAcesPresent
RtlpApplyLengthFunction
RtlpCleanupRegistryKeys
RtlpConvertCultureNamesToLCIDs
RtlpConvertLCIDsToCultureNames
RtlpCreateProcessRegistryInfo
RtlPcToFileHeader
RtlpEnsureBufferSize
RtlpGetLCIDFromLangInfoNode
RtlpGetNameFromLangInfoNode
RtlpGetSystemDefaultUILanguage
RtlpGetUserOrMachineUILanguage4NLS
RtlPinAtomInAtomTable
RtlpInitializeLangRegistryInfo
RtlpIsQualifiedLanguage
RtlpLoadMachineUIByPolicy
RtlpLoadUserUIByPolicy
RtlpMuiFreeLangRegistryInfo
RtlpMuiRegCreateRegistryInfo
RtlpMuiRegFreeRegistryInfo
RtlpMuiRegLoadRegistryInfo
RtlpNotOwnerCriticalSection
RtlpNtCreateKey
RtlpNtEnumerateSubKey
RtlpNtMakeTemporaryKey
RtlpNtOpenKey
RtlpNtQueryValueKey
RtlpNtSetValueKey
RtlPopFrame
RtlpQueryDefaultUILanguage
RtlPrefixString
RtlPrefixUnicodeString
RtlpRefreshCachedUILanguage
RtlProcessFlsData
RtlProtectHeap
RtlpSetInstallLanguage
RtlpSetPreferredUILanguages
RtlpSetUserPreferredUILanguages
RtlpUnWaitCriticalSection
RtlPushFrame
RtlpVerifyAndCommitUILanguageSettings
RtlpWaitForCriticalSection
RtlQueryActivationContextApplicationSettings
RtlQueryAtomInAtomTable
RtlQueryCriticalSectionOwner
RtlQueryDepthSList
RtlQueryDynamicTimeZoneInformation
RtlQueryElevationFlags
RtlQueryEnvironmentVariable
RtlQueryEnvironmentVariable_U
RtlQueryHeapInformation
RtlQueryInformationAcl
RtlQueryInformationActivationContext
RtlQueryInformationActiveActivationContext
RtlQueryInterfaceMemoryStream
RtlQueryModuleInformation
RtlQueryProcessBackTraceInformation
RtlQueryProcessDebugInformation
RtlQueryProcessHeapInformation
RtlQueryProcessLockInformation
RtlQueryRegistryValues
RtlQuerySecurityObject
RtlQueryTagHeap
RtlQueryTimeZoneInformation
RtlQueueApcWow64Thread
RtlQueueWorkItem
RtlRaiseException
RtlRaiseStatus
RtlRandom
RtlRandomEx
RtlReadMemoryStream
RtlReadOutOfProcessMemoryStream
RtlRealPredecessor
RtlRealSuccessor
RtlRegisterSecureMemoryCacheCallback
RtlRegisterThreadWithCsrss
RtlRegisterWait
RtlReleaseActivationContext
RtlReleaseMemoryStream
RtlReleasePebLock
RtlReleasePrivilege
RtlReleaseRelativeName
RtlReleaseResource
RtlReleaseSRWLockExclusive
RtlReleaseSRWLockShared
RtlRemoteCall
RtlRemovePrivileges
RtlRemoveVectoredContinueHandler
RtlRemoveVectoredExceptionHandler
RtlReportException
RtlResetMemoryBlockLookaside
RtlResetMemoryZone
RtlResetRtlTranslations
RtlRestoreLastWin32Error
RtlRetrieveNtUserPfn
RtlRevertMemoryStream
RtlRunDecodeUnicodeString
RtlRunEncodeUnicodeString
RtlRunOnceBeginInitialize
RtlRunOnceComplete
RtlRunOnceExecuteOnce
RtlRunOnceInitialize
RtlSecondsSince1970ToTime
RtlSecondsSince1980ToTime
RtlSeekMemoryStream
RtlSelfRelativeToAbsoluteSD
RtlSelfRelativeToAbsoluteSD2
RtlSendMsgToSm
RtlSetAllBits
RtlSetAttributesSecurityDescriptor
RtlSetBits
RtlSetControlSecurityDescriptor
RtlSetCriticalSectionSpinCount
RtlSetCurrentDirectory_U
RtlSetCurrentEnvironment
RtlSetCurrentTransaction
RtlSetDaclSecurityDescriptor
RtlSetDynamicTimeZoneInformation
RtlSetEnvironmentStrings
RtlSetEnvironmentVar
RtlSetEnvironmentVariable
RtlSetGroupSecurityDescriptor
RtlSetHeapInformation
RtlSetInformationAcl
RtlSetIoCompletionCallback
RtlSetLastWin32Error
RtlSetLastWin32ErrorAndNtStatusFromNtStatus
RtlSetMemoryStreamSize
RtlSetOwnerSecurityDescriptor
RtlSetProcessDebugInformation
RtlSetProcessIsCritical
RtlSetSaclSecurityDescriptor
RtlSetSecurityDescriptorRMControl
RtlSetSecurityObject
RtlSetSecurityObjectEx
RtlSetThreadErrorMode
RtlSetThreadIsCritical
RtlSetThreadPoolStartFunc
RtlSetThreadPreferredUILanguages
RtlSetTimer
RtlSetTimeZoneInformation
RtlSetUnhandledExceptionFilter
RtlSetUserFlagsHeap
RtlSetUserValueHeap
RtlSidDominates
RtlSidEqualLevel
RtlSidHashInitialize
RtlSidHashLookup
RtlSidIsHigherLevel
RtlSleepConditionVariableCS
RtlSleepConditionVariableSRW
RtlSplay
RtlStartRXact
RtlStatMemoryStream
RtlStringFromGUID
RtlSubAuthorityCountSid
RtlSubAuthoritySid
RtlSubtreePredecessor
RtlSubtreeSuccessor
RtlSystemTimeToLocalTime
RtlTestBit
RtlTimeFieldsToTime
RtlTimeToElapsedTimeFields
RtlTimeToSecondsSince1970
RtlTimeToSecondsSince1980
RtlTimeToTimeFields
RtlTraceDatabaseAdd
RtlTraceDatabaseCreate
RtlTraceDatabaseDestroy
RtlTraceDatabaseEnumerate
RtlTraceDatabaseFind
RtlTraceDatabaseLock
RtlTraceDatabaseUnlock
RtlTraceDatabaseValidate
RtlTryAcquirePebLock
RtlTryEnterCriticalSection
RtlUlongByteSwap
RtlUlonglongByteSwap
RtlUnhandledExceptionFilter
RtlUnhandledExceptionFilter2
RtlUnicodeStringToAnsiSize
RtlUnicodeStringToCountedOemString
RtlUnicodeStringToInteger
RtlUnicodeStringToOemSize
RtlUnicodeStringToOemString
RtlUnicodeToCustomCPN
RtlUnicodeToMultiByteSize
RtlUnicodeToOemN
RtlUniform
RtlUnlockBootStatusData
RtlUnlockCurrentThread
RtlUnlockHeap
RtlUnlockMemoryBlockLookaside
RtlUnlockMemoryStreamRegion
RtlUnlockMemoryZone
RtlUnlockModuleSection
RtlUpcaseUnicodeChar
RtlUpcaseUnicodeString
RtlUpcaseUnicodeStringToAnsiString
RtlUpcaseUnicodeStringToCountedOemString
RtlUpcaseUnicodeStringToOemString
RtlUpcaseUnicodeToCustomCPN
RtlUpcaseUnicodeToMultiByteN
RtlUpcaseUnicodeToOemN
RtlUpdateClonedCriticalSection
RtlUpdateClonedSRWLock
RtlUpdateTimer
RtlUpperChar
RtlUpperString
RtlUserThreadStart
RtlUshortByteSwap
RtlValidAcl
RtlValidateProcessHeaps
RtlValidateUnicodeString
RtlValidRelativeSecurityDescriptor
RtlValidSecurityDescriptor
RtlValidSid
RtlVerifyVersionInfo
RtlWakeAllConditionVariable
RtlWakeConditionVariable
RtlWalkFrameChain
RtlWalkHeap
RtlWerpReportException
RtlWow64CallFunction64
RtlWow64EnableFsRedirection
RtlWow64EnableFsRedirectionEx
RtlWriteMemoryStream
RtlWriteRegistryValue
RtlxAnsiStringToUnicodeSize
RtlxOemStringToUnicodeSize
RtlxUnicodeStringToAnsiSize
RtlxUnicodeStringToOemSize
RtlZeroHeap
RtlZeroMemory
RtlZombifyActivationContext
ShipAssert
ShipAssertGetBufferInfo
ShipAssertMsgA
ShipAssertMsgW
sin
_snprintf
_snwprintf
_splitpath
sprintf
sqrt
sscanf
strcat
strchr
strcmp
_strcmpi
strcpy
strcspn
_stricmp
strlen
_strlwr
strncat
strncmp
strncpy
_strnicmp
strpbrk
strrchr
strspn
strstr
strtol
strtoul
_strupr
_swprintf
swprintf
tan
__toascii
tolower
toupper
towlower
towupper
TpAllocAlpcCompletion
TpAllocCleanupGroup
TpAllocIoCompletion
TpAllocPool
TpAllocTimer
TpAllocWait
TpAllocWork
TpCallbackLeaveCriticalSectionOnCompletion
TpCallbackMayRunLong
TpCallbackReleaseMutexOnCompletion
TpCallbackReleaseSemaphoreOnCompletion
TpCallbackSetEventOnCompletion
TpCallbackUnloadDllOnCompletion
TpCancelAsyncIoOperation
TpCaptureCaller
TpCheckTerminateWorker
TpDbgDumpHeapUsage
TpDbgSetLogRoutine
TpDisassociateCallback
TpIsTimerSet
TpPostWork
TpReleaseAlpcCompletion
TpReleaseCleanupGroup
TpReleaseCleanupGroupMembers
TpReleaseIoCompletion
TpReleasePool
TpReleaseTimer
TpReleaseWait
TpReleaseWork
TpSetPoolMaxThreads
TpSetPoolMinThreads
TpSetTimer
TpSetWait
TpSimpleTryPost
TpStartAsyncIoOperation
TpWaitForAlpcCompletion
TpWaitForIoCompletion
TpWaitForTimer
TpWaitForWait
TpWaitForWork
_ui64toa
_ui64tow
_ultoa
_ultow
vDbgPrintEx
vDbgPrintExWithPrefix
VerSetConditionMask
_vscwprintf
_vsnprintf
_vsnwprintf
vsprintf
_vswprintf
wcscat
wcschr
wcscmp
wcscpy
wcscspn
_wcsicmp
wcslen
_wcslwr
wcsncat
wcsncmp
wcsncpy
_wcsnicmp
wcspbrk
wcsrchr
wcsspn
wcsstr
wcstol
wcstombs
_wcstoui64
wcstoul
_wcsupr
WerCheckEventEscalation
WerReportSQMEvent
WerReportWatsonEvent
WinSqmAddToStream
WinSqmEndSession
WinSqmEventEnabled
WinSqmEventWrite
WinSqmIsOptedIn
WinSqmSetString
WinSqmStartSession
_wtoi
_wtoi64
_wtol
ZwAcceptConnectPort
ZwAccessCheck
ZwAccessCheckAndAuditAlarm
ZwAccessCheckByType
ZwAccessCheckByTypeAndAuditAlarm
ZwAccessCheckByTypeResultList
ZwAccessCheckByTypeResultListAndAuditAlarm
ZwAccessCheckByTypeResultListAndAuditAlarmByHandle
ZwAcquireCMFViewOwnership
ZwAddAtom
ZwAddBootEntry
ZwAddDriverEntry
ZwAdjustGroupsToken
ZwAdjustPrivilegesToken
ZwAlertResumeThread
ZwAlertThread
ZwAllocateLocallyUniqueId
ZwAllocateUserPhysicalPages
ZwAllocateUuids
ZwAllocateVirtualMemory
ZwAlpcAcceptConnectPort
ZwAlpcCancelMessage
ZwAlpcConnectPort
ZwAlpcCreatePort
ZwAlpcCreatePortSection
ZwAlpcCreateResourceReserve
ZwAlpcCreateSectionView
ZwAlpcCreateSecurityContext
ZwAlpcDeletePortSection
ZwAlpcDeleteResourceReserve
ZwAlpcDeleteSectionView
ZwAlpcDeleteSecurityContext
ZwAlpcDisconnectPort
ZwAlpcImpersonateClientOfPort
ZwAlpcOpenSenderProcess
ZwAlpcOpenSenderThread
ZwAlpcQueryInformation
ZwAlpcQueryInformationMessage
ZwAlpcRevokeSecurityContext
ZwAlpcSendWaitReceivePort
ZwAlpcSetInformation
ZwApphelpCacheControl
ZwAreMappedFilesTheSame
ZwAssignProcessToJobObject
ZwCallbackReturn
ZwCancelDeviceWakeupRequest
ZwCancelIoFile
ZwCancelIoFileEx
ZwCancelSynchronousIoFile
ZwCancelTimer
ZwClearAllSavepointsTransaction
ZwClearEvent
ZwClearSavepointTransaction
ZwClose
ZwCloseObjectAuditAlarm
ZwCommitComplete
ZwCommitEnlistment
ZwCommitTransaction
ZwCompactKeys
ZwCompareTokens
ZwCompleteConnectPort
ZwCompressKey
ZwConnectPort
ZwContinue
ZwCreateDebugObject
ZwCreateDirectoryObject
ZwCreateEnlistment
ZwCreateEvent
ZwCreateEventPair
ZwCreateFile
ZwCreateIoCompletion
ZwCreateJobObject
ZwCreateJobSet
ZwCreateKey
ZwCreateKeyedEvent
ZwCreateKeyTransacted
ZwCreateMailslotFile
ZwCreateMutant
ZwCreateNamedPipeFile
ZwCreatePagingFile
ZwCreatePort
ZwCreatePrivateNamespace
ZwCreateProcess
ZwCreateProcessEx
ZwCreateProfile
ZwCreateResourceManager
ZwCreateSection
ZwCreateSemaphore
ZwCreateSymbolicLinkObject
ZwCreateThread
ZwCreateThreadEx
ZwCreateTimer
ZwCreateToken
ZwCreateTransaction
ZwCreateTransactionManager
ZwCreateUserProcess
ZwCreateWaitablePort
ZwCreateWorkerFactory
ZwDebugActiveProcess
ZwDebugContinue
ZwDelayExecution
ZwDeleteAtom
ZwDeleteBootEntry
ZwDeleteDriverEntry
ZwDeleteFile
ZwDeleteKey
ZwDeleteObjectAuditAlarm
ZwDeletePrivateNamespace
ZwDeleteValueKey
ZwDeviceIoControlFile
ZwDisplayString
ZwDuplicateObject
ZwDuplicateToken
ZwEnumerateBootEntries
ZwEnumerateDriverEntries
ZwEnumerateKey
ZwEnumerateSystemEnvironmentValuesEx
ZwEnumerateTransactionObject
ZwEnumerateValueKey
ZwExtendSection
ZwFilterToken
ZwFindAtom
ZwFlushBuffersFile
ZwFlushInstallUILanguage
ZwFlushInstructionCache
ZwFlushKey
ZwFlushProcessWriteBuffers
ZwFlushVirtualMemory
ZwFlushWriteBuffer
ZwFreeUserPhysicalPages
ZwFreeVirtualMemory
ZwFreezeRegistry
ZwFreezeTransactions
ZwFsControlFile
ZwGetContextThread
ZwGetCurrentProcessorNumber
ZwGetDevicePowerState
ZwGetMUIRegistryInfo
ZwGetNextProcess
ZwGetNextThread
ZwGetNlsSectionPtr
ZwGetNotificationResourceManager
ZwGetPlugPlayEvent
ZwGetWriteWatch
ZwImpersonateAnonymousToken
ZwImpersonateClientOfPort
ZwImpersonateThread
ZwInitializeNlsFiles
ZwInitializeRegistry
ZwInitiatePowerAction
ZwIsProcessInJob
ZwIsSystemResumeAutomatic
ZwIsUILanguageComitted
ZwListenPort
ZwListTransactions
ZwLoadDriver
ZwLoadKey
ZwLoadKey2
ZwLoadKeyEx
ZwLockFile
ZwLockProductActivationKeys
ZwLockRegistryKey
ZwLockVirtualMemory
ZwMakePermanentObject
ZwMakeTemporaryObject
ZwMapCMFModule
ZwMapUserPhysicalPages
ZwMapUserPhysicalPagesScatter
ZwMapViewOfSection
ZwMarshallTransaction
ZwModifyBootEntry
ZwModifyDriverEntry
ZwNotifyChangeDirectoryFile
ZwNotifyChangeKey
ZwNotifyChangeMultipleKeys
ZwOpenDirectoryObject
ZwOpenEnlistment
ZwOpenEvent
ZwOpenEventPair
ZwOpenFile
ZwOpenIoCompletion
ZwOpenJobObject
ZwOpenKey
ZwOpenKeyedEvent
ZwOpenKeyTransacted
ZwOpenMutant
ZwOpenObjectAuditAlarm
ZwOpenPrivateNamespace
ZwOpenProcess
ZwOpenProcessToken
ZwOpenProcessTokenEx
ZwOpenResourceManager
ZwOpenSection
ZwOpenSemaphore
ZwOpenSession
ZwOpenSymbolicLinkObject
ZwOpenThread
ZwOpenThreadToken
ZwOpenThreadTokenEx
ZwOpenTimer
ZwOpenTransaction
ZwOpenTransactionManager
ZwPlugPlayControl
ZwPowerInformation
ZwPrepareComplete
ZwPrepareEnlistment
ZwPrePrepareComplete
ZwPrePrepareEnlistment
ZwPrivilegeCheck
ZwPrivilegedServiceAuditAlarm
ZwPrivilegeObjectAuditAlarm
ZwPropagationComplete
ZwPropagationFailed
ZwProtectVirtualMemory
ZwPullTransaction
ZwPulseEvent
ZwQueryAttributesFile
ZwQueryBootEntryOrder
ZwQueryBootOptions
ZwQueryDebugFilterState
ZwQueryDefaultLocale
ZwQueryDefaultUILanguage
ZwQueryDirectoryFile
ZwQueryDirectoryObject
ZwQueryDriverEntryOrder
ZwQueryEaFile
ZwQueryEvent
ZwQueryFullAttributesFile
ZwQueryInformationAtom
ZwQueryInformationEnlistment
ZwQueryInformationFile
ZwQueryInformationJobObject
ZwQueryInformationPort
ZwQueryInformationProcess
ZwQueryInformationResourceManager
ZwQueryInformationThread
ZwQueryInformationToken
ZwQueryInformationTransaction
ZwQueryInformationTransactionManager
ZwQueryInformationWorkerFactory
ZwQueryInstallUILanguage
ZwQueryIntervalProfile
ZwQueryIoCompletion
ZwQueryKey
ZwQueryLicenseValue
ZwQueryMultipleValueKey
ZwQueryMutant
ZwQueryObject
ZwQueryOpenSubKeys
ZwQueryOpenSubKeysEx
ZwQueryPerformanceCounter
ZwQueryPortInformationProcess
ZwQueryQuotaInformationFile
ZwQuerySection
ZwQuerySecurityObject
ZwQuerySemaphore
ZwQuerySymbolicLinkObject
ZwQuerySystemEnvironmentValue
ZwQuerySystemEnvironmentValueEx
ZwQuerySystemInformation
ZwQuerySystemTime
ZwQueryTimer
ZwQueryTimerResolution
ZwQueryValueKey
ZwQueryVirtualMemory
ZwQueryVolumeInformationFile
ZwQueueApcThread
ZwRaiseException
ZwRaiseHardError
ZwReadFile
ZwReadFileScatter
ZwReadOnlyEnlistment
ZwReadRequestData
ZwReadVirtualMemory
ZwRecoverEnlistment
ZwRecoverResourceManager
ZwRecoverTransactionManager
ZwRegisterProtocolAddressInformation
ZwRegisterThreadTerminatePort
ZwReleaseCMFViewOwnership
ZwReleaseKeyedEvent
ZwReleaseMutant
ZwReleaseSemaphore
ZwReleaseWorkerFactoryWorker
ZwRemoveIoCompletion
ZwRemoveIoCompletionEx
ZwRemoveProcessDebug
ZwRenameKey
ZwReplaceKey
ZwReplyPort
ZwReplyWaitReceivePort
ZwReplyWaitReceivePortEx
ZwReplyWaitReplyPort
ZwRequestDeviceWakeup
ZwRequestPort
ZwRequestWaitReplyPort
ZwRequestWakeupLatency
ZwResetEvent
ZwResetWriteWatch
ZwRestoreKey
ZwResumeProcess
ZwResumeThread
ZwRollbackComplete
ZwRollbackEnlistment
ZwRollbackSavepointTransaction
ZwRollbackTransaction
ZwRollforwardTransactionManager
ZwSaveKey
ZwSaveKeyEx
ZwSaveMergedKeys
ZwSavepointComplete
ZwSavepointTransaction
ZwSecureConnectPort
ZwSetBootEntryOrder
ZwSetBootOptions
ZwSetContextThread
ZwSetDebugFilterState
ZwSetDefaultHardErrorPort
ZwSetDefaultLocale
ZwSetDefaultUILanguage
ZwSetDriverEntryOrder
ZwSetEaFile
ZwSetEvent
ZwSetEventBoostPriority
ZwSetHighEventPair
ZwSetHighWaitLowEventPair
ZwSetInformationDebugObject
ZwSetInformationEnlistment
ZwSetInformationFile
ZwSetInformationJobObject
ZwSetInformationKey
ZwSetInformationObject
ZwSetInformationProcess
ZwSetInformationResourceManager
ZwSetInformationThread
ZwSetInformationToken
ZwSetInformationTransaction
ZwSetInformationTransactionManager
ZwSetInformationWorkerFactory
ZwSetIntervalProfile
ZwSetIoCompletion
ZwSetLdtEntries
ZwSetLowEventPair
ZwSetLowWaitHighEventPair
ZwSetQuotaInformationFile
ZwSetSecurityObject
ZwSetSystemEnvironmentValue
ZwSetSystemEnvironmentValueEx
ZwSetSystemInformation
ZwSetSystemPowerState
ZwSetSystemTime
ZwSetThreadExecutionState
ZwSetTimer
ZwSetTimerResolution
ZwSetUuidSeed
ZwSetValueKey
ZwSetVolumeInformationFile
ZwShutdownSystem
ZwShutdownWorkerFactory
ZwSignalAndWaitForSingleObject
ZwSinglePhaseReject
ZwStartProfile
ZwStartTm
ZwStopProfile
ZwSuspendProcess
ZwSuspendThread
ZwSystemDebugControl
ZwTerminateJobObject
ZwTerminateProcess
ZwTerminateThread
ZwTestAlert
ZwThawRegistry
ZwThawTransactions
ZwTraceControl
ZwTraceEvent
ZwTranslateFilePath
ZwUnloadDriver
ZwUnloadKey
ZwUnloadKey2
ZwUnloadKeyEx
ZwUnlockFile
ZwUnlockVirtualMemory
ZwUnmapViewOfSection
ZwVdmControl
ZwWaitForDebugEvent
ZwWaitForKeyedEvent
ZwWaitForMultipleObjects
ZwWaitForMultipleObjects32
ZwWaitForSingleObject
ZwWaitForWorkViaWorkerFactory
ZwWaitHighEventPair
ZwWaitLowEventPair
ZwWorkerFactoryWorkerReady
ZwWriteFile
ZwWriteFileGather
ZwWriteRequestData
ZwWriteVirtualMemory
ZwYieldExecution

Found follow exports in USER32.DLL
AddClipboardFormatListener
AlignRects
AllowForegroundActivation
AllowSetForegroundWindow
AnimateWindow
BlockInput
BroadcastSystemMessageA
BroadcastSystemMessageExA
BroadcastSystemMessageExW
BroadcastSystemMessageW
BuildReasonArray
CalcMenuBar
CancelShutdown
ChangeDisplaySettingsExA
ChangeDisplaySettingsExW
ChangeWindowMessageFilter
CheckDesktopByThreadId
CheckWindowThreadDesktop
ClientThreadSetup
CliImmSetHotKey
CreateDesktopExA
CreateDesktopExW
CreateDialogIndirectParamAorW
CreateSystemThreads
CsrBroadcastSystemMessageExW
CtxInitUser32
DdeGetQualityOfService
DefRawInputProc
DeregisterShellHookWindow
DestroyReasons
DeviceEventWorker
DialogBoxIndirectParamAorW
DisableProcessWindowsGhosting
DisplayExitWindowsWarnings
DoSoundConnect
DoSoundDisconnect
DrawMenuBarTemp
DwmGetDxRgn
DwmHintDxUpdate
DwmStartRedirection
DwmStopRedirection
EndMenu
EnterReaderModeHelper
EnumDisplayDevicesA
EnumDisplayDevicesW
EnumDisplayMonitors
EnumDisplaySettingsExA
EnumDisplaySettingsExW
FlashWindowEx
FrostCrashedWindow
GetAltTabInfo
GetAltTabInfoA
GetAltTabInfoW
GetAncestor
GetAppCompatFlags
GetAppCompatFlags2
GetClipboardSequenceNumber
GetComboBoxInfo
GetCursorFrameInfo
GetCursorInfo
GetGuiResources
GetGUIThreadInfo
GetIconInfoExA
GetIconInfoExW
GetLastInputInfo
GetLayeredWindowAttributes
GetListBoxInfo
GetMenuBarInfo
GetMenuInfo
GetMonitorInfoA
GetMonitorInfoW
GetMouseMovePointsEx
GetPhysicalCursorPos
GetProcessDefaultLayout
GetProgmanWindow
GetRawInputBuffer
GetRawInputData
GetRawInputDeviceInfoA
GetRawInputDeviceInfoW
GetRawInputDeviceList
GetReasonTitleFromReasonCode
GetRegisteredRawInputDevices
GetScrollBarInfo
GetSendMessageReceiver
GetTaskmanWindow
GetTitleBarInfo
GetUpdatedClipboardFormats
GetWindowInfo
GetWindowMinimizeRect
GetWindowModuleFileName
GetWindowModuleFileNameA
GetWindowModuleFileNameW
GetWindowRgnBox
GetWindowRgnEx
GetWinStationInfo
GhostWindowFromHungWindow
HungWindowFromGhostWindow
IMPGetIMEA
IMPGetIMEW
IMPQueryIMEA
IMPQueryIMEW
IMPSetIMEA
IMPSetIMEW
InitializeLpkHooks
InSendMessageEx
InternalGetWindowIcon
IsGUIThread
IsHungAppWindow
IsProcessDPIAware
IsServerSideWindow
IsSETEnabled
IsThreadDesktopComposited
IsWindowInDestroy
IsWindowRedirectedForPrint
IsWinEventHookInstalled
IsWow64Message
LoadKeyboardLayoutEx
LoadLocalFonts
LoadRemoteFonts
LockSetForegroundWindow
LockWorkStation
LogicalToPhysicalPoint
MB_GetString
MBToWCSEx
MenuWindowProcA
MenuWindowProcW
MessageBoxTimeoutA
MessageBoxTimeoutW
MonitorFromPoint
MonitorFromRect
MonitorFromWindow
MsgWaitForMultipleObjectsEx
NotifyWinEvent
OpenThreadDesktop
PaintMenuBar
PaintMonitor
PhysicalToLogicalPoint
PrintWindow
PrivateExtractIconExA
PrivateExtractIconExW
PrivateExtractIconsA
PrivateExtractIconsW
PrivateRegisterICSProc
QuerySendMessage
RealChildWindowFromPoint
RealGetWindowClass
RealGetWindowClassA
RealGetWindowClassW
ReasonCodeNeedsBugID
ReasonCodeNeedsComment
RecordShutdownReason
RegisterDeviceNotificationA
RegisterDeviceNotificationW
RegisterErrorReportingDialog
RegisterFrostWindow
RegisterGhostWindow
RegisterMessagePumpHook
RegisterPowerSettingNotification
RegisterRawInputDevices
RegisterServicesProcess
RegisterSessionPort
RegisterShellHookWindow
RegisterUserApiHook
RemoveClipboardFormatListener
ResolveDesktopForWOW
ScrollChildren
SendIMEMessageExA
SendIMEMessageExW
SendInput
SetConsoleReserveKeys
SetCursorContents
SetLayeredWindowAttributes
SetMenuInfo
SetMirrorRendering
SetPhysicalCursorPos
SetProcessDefaultLayout
SetProcessDPIAware
SetProgmanWindow
SetShellWindowEx
SetSystemMenu
SetTaskmanWindow
SetWindowRgnEx
SetWindowStationUser
SetWinEventHook
ShowStartGlass
ShowSystemCursor
ShutdownBlockReasonCreate
ShutdownBlockReasonDestroy
ShutdownBlockReasonQuery
SoftModalMessageBox
SoundSentry
SwitchDesktopWithFade
ToUnicodeEx
TrackMouseEvent
TranslateMessageEx
UnhookWinEvent
UnregisterDeviceNotification
UnregisterMessagePumpHook
UnregisterPowerSettingNotification
UnregisterSessionPort
UnregisterUserApiHook
UpdateLayeredWindow
UpdateLayeredWindowIndirect
UpdatePerUserSystemParameters
UpdateWindowTransform
User32InitializeImmEntryTable
UserHandleGrantAccess
UserLpkPSMTextOut
UserLpkTabbedTextOut
UserRealizePalette
UserRegisterWowHandlers
_UserTestTokenForInteractive
WCSToMBEx
Win32PoolAllocationStats
WindowFromPhysicalPoint
WINNLSEnableIME
WINNLSGetEnableStatus
WINNLSGetIMEHotkey

Found follow exports in GDI32.DLL
AddFontMemResourceEx
AddFontResourceExA
AddFontResourceExW
AddFontResourceTracking
AnyLinkedFonts
bInitSystemAndFontsDirectoriesW
bMakePathNameW
BRUSHOBJ_hGetColorTransform
BRUSHOBJ_pvAllocRbrush
BRUSHOBJ_pvGetRbrush
BRUSHOBJ_ulGetBrushColor
cGetTTFFromFOT
ClearBitmapAttributes
ClearBrushAttributes
CLIPOBJ_bEnum
CLIPOBJ_cEnumStart
CLIPOBJ_ppoGetPath
ColorCorrectPalette
ConfigureOPMProtectedOutput
CreateFontIndirectExA
CreateFontIndirectExW
CreateOPMProtectedOutputs
D3DKMTCheckExclusiveOwnership
D3DKMTCheckMonitorPowerState
D3DKMTCheckOcclusion
D3DKMTCloseAdapter
D3DKMTCreateAllocation
D3DKMTCreateContext
D3DKMTCreateDCFromMemory
D3DKMTCreateDevice
D3DKMTCreateOverlay
D3DKMTCreateSynchronizationObject
D3DKMTDestroyAllocation
D3DKMTDestroyContext
D3DKMTDestroyDCFromMemory
D3DKMTDestroyDevice
D3DKMTDestroyOverlay
D3DKMTDestroySynchronizationObject
D3DKMTEscape
D3DKMTFlipOverlay
D3DKMTGetContextSchedulingPriority
D3DKMTGetDeviceState
D3DKMTGetDisplayModeList
D3DKMTGetMultisampleMethodList
D3DKMTGetPresentHistory
D3DKMTGetProcessSchedulingPriorityClass
D3DKMTGetRuntimeData
D3DKMTGetScanLine
D3DKMTGetSharedPrimaryHandle
D3DKMTInvalidateActiveVidPn
D3DKMTLock
D3DKMTOpenAdapterFromDeviceName
D3DKMTOpenAdapterFromGdiDisplayName
D3DKMTOpenAdapterFromHdc
D3DKMTOpenResource
D3DKMTPollDisplayChildren
D3DKMTPresent
D3DKMTQueryAdapterInfo
D3DKMTQueryAllocationResidency
D3DKMTQueryResourceInfo
D3DKMTQueryStatistics
D3DKMTReleaseProcessVidPnSourceOwners
D3DKMTRender
D3DKMTSetAllocationPriority
D3DKMTSetContextSchedulingPriority
D3DKMTSetDisplayMode
D3DKMTSetDisplayPrivateDriverFormat
D3DKMTSetGammaRamp
D3DKMTSetProcessSchedulingPriorityClass
D3DKMTSetQueuedLimit
D3DKMTSetVidPnSourceOwner
D3DKMTSharedPrimaryLockNotification
D3DKMTSharedPrimaryUnLockNotification
D3DKMTSignalSynchronizationObject
D3DKMTUnlock
D3DKMTUpdateOverlay
D3DKMTWaitForIdle
D3DKMTWaitForSynchronizationObject
D3DKMTWaitForVerticalBlankEvent
DDCCIGetCapabilitiesString
DDCCIGetCapabilitiesStringLength
DDCCIGetTimingReport
DDCCIGetVCPFeature
DDCCISaveCurrentSettings
DDCCISetVCPFeature
DdEntry0
DdEntry1
DdEntry10
DdEntry11
DdEntry12
DdEntry13
DdEntry14
DdEntry15
DdEntry16
DdEntry17
DdEntry18
DdEntry19
DdEntry2
DdEntry20
DdEntry21
DdEntry22
DdEntry23
DdEntry24
DdEntry25
DdEntry26
DdEntry27
DdEntry28
DdEntry29
DdEntry3
DdEntry30
DdEntry31
DdEntry32
DdEntry33
DdEntry34
DdEntry35
DdEntry36
DdEntry37
DdEntry38
DdEntry39
DdEntry4
DdEntry40
DdEntry41
DdEntry42
DdEntry43
DdEntry44
DdEntry45
DdEntry46
DdEntry47
DdEntry48
DdEntry49
DdEntry5
DdEntry50
DdEntry51
DdEntry52
DdEntry53
DdEntry54
DdEntry55
DdEntry56
DdEntry6
DdEntry7
DdEntry8
DdEntry9
DestroyOPMProtectedOutput
DestroyPhysicalMonitorInternal
DwmGetDirtyRgn
DwmGetSurfaceData
EnableEUDC
EndFormPage
EngAcquireSemaphore
EngAlphaBlend
EngAssociateSurface
EngBitBlt
EngCheckAbort
EngComputeGlyphSet
EngCopyBits
EngCreateBitmap
EngCreateClip
EngCreateDeviceBitmap
EngCreateDeviceSurface
EngCreatePalette
EngCreateSemaphore
EngDeleteClip
EngDeletePalette
EngDeletePath
EngDeleteSemaphore
EngDeleteSurface
EngEraseSurface
EngFillPath
EngFindResource
EngFreeModule
EngGetCurrentCodePage
EngGetDriverName
EngGetPrinterDataFileName
EngGradientFill
EngLineTo
EngLoadModule
EngLockSurface
EngMarkBandingSurface
EngMultiByteToUnicodeN
EngMultiByteToWideChar
EngPaint
EngPlgBlt
EngQueryEMFInfo
EngQueryLocalTime
EngReleaseSemaphore
EngStretchBlt
EngStretchBltROP
EngStrokeAndFillPath
EngStrokePath
EngTextOut
EngTransparentBlt
EngUnicodeToMultiByteN
EngUnlockSurface
EngWideCharToMultiByte
EudcLoadLinkW
EudcUnloadLinkW
FontIsLinked
FONTOBJ_cGetAllGlyphHandles
FONTOBJ_cGetGlyphs
FONTOBJ_pfdg
FONTOBJ_pifi
FONTOBJ_pQueryGlyphAttrs
FONTOBJ_pvTrueTypeFontFile
FONTOBJ_pxoGetXform
FONTOBJ_vGetInfo
GdiAddFontResourceW
GdiAddGlsBounds
GdiAddGlsRecord
GdiAlphaBlend
GdiArtificialDecrementDriver
GdiCleanCacheDC
GdiConsoleTextOut
GdiConvertAndCheckDC
GdiConvertBitmap
GdiConvertBitmapV5
GdiConvertBrush
GdiConvertDC
GdiConvertEnhMetaFile
GdiConvertFont
GdiConvertMetaFilePict
GdiConvertPalette
GdiConvertRegion
GdiConvertToDevmodeW
GdiCreateLocalEnhMetaFile
GdiCreateLocalMetaFilePict
GdiDeleteLocalDC
GdiDeleteSpoolFileHandle
GdiDescribePixelFormat
GdiDllInitialize
GdiDrawStream
GdiEndDocEMF
GdiEndPageEMF
GdiEntry1
GdiEntry10
GdiEntry11
GdiEntry12
GdiEntry13
GdiEntry14
GdiEntry15
GdiEntry16
GdiEntry2
GdiEntry3
GdiEntry4
GdiEntry5
GdiEntry6
GdiEntry7
GdiEntry8
GdiEntry9
GdiFixUpHandle
GdiFullscreenControl
GdiGetBitmapBitsSize
GdiGetCharDimensions
GdiGetCodePage
GdiGetDC
GdiGetDevmodeForPage
GdiGetLocalBrush
GdiGetLocalDC
GdiGetLocalFont
GdiGetPageCount
GdiGetPageHandle
GdiGetSpoolFileHandle
GdiGetSpoolMessage
GdiGradientFill
GdiInitializeLanguagePack
GdiInitSpool
GdiIsMetaFileDC
GdiIsMetaPrintDC
GdiIsPlayMetafileDC
GdiIsScreenDC
GdiPlayEMF
GdiPlayPageEMF
GdiPlayPrivatePageEMF
GdiPrinterThunk
GdiProcessSetup
GdiQueryFonts
GdiQueryTable
GdiRealizationInfo
GdiReleaseDC
GdiReleaseLocalDC
GdiResetDCEMF
GdiSetAttrs
GdiSetLastError
GdiSetPixelFormat
GdiSetServerAttr
GdiStartDocEMF
GdiStartPageEMF
GdiSwapBuffers
GdiTransparentBlt
GdiValidateHandle
GetBitmapAttributes
GetBrushAttributes
GetCertificate
GetCertificateSize
GetCharABCWidthsI
GetCharWidthI
GetCharWidthInfo
GetCOPPCompatibleOPMInformation
GetDCBrushColor
GetDCPenColor
GetEnhMetaFilePixelFormat
GetETM
GetEUDCTimeStamp
GetEUDCTimeStampExW
GetFontAssocStatus
GetFontResourceInfoW
GetFontUnicodeRanges
GetGlyphIndicesA
GetGlyphIndicesW
GetGlyphOutlineWow
GetHFONT
GetLayout
GetNumberOfPhysicalMonitors
GetOPMInformation
GetOPMRandomNumber
GetPhysicalMonitorDescription
GetPhysicalMonitors
GetRelAbs
GetStringBitmapA
GetStringBitmapW
GetSuggestedOPMProtectedOutputArraySize
GetTextExtentExPointI
GetTextExtentExPointWPri
GetTextExtentPointI
GetTextFaceAliasW
GetTransform
HT_Get8BPPFormatPalette
HT_Get8BPPMaskPalette
IsValidEnhMetaRecord
IsValidEnhMetaRecordOffExt
MirrorRgn
NamedEscape
PATHOBJ_bEnum
PATHOBJ_bEnumClipLines
PATHOBJ_vEnumStart
PATHOBJ_vEnumStartClipLines
PATHOBJ_vGetBounds
PolyPatBlt
QueryFontAssocStatus
RemoveFontMemResourceEx
RemoveFontResourceExA
RemoveFontResourceExW
RemoveFontResourceTracking
SelectBrushLocal
SelectFontLocal
SetBitmapAttributes
SetBrushAttributes
SetDCBrushColor
SetDCPenColor
SetLayout
SetLayoutWidth
SetMagicColors
SetOPMSigningKeyAndSequenceNumbers
SetRelAbs
SetVirtualResolution
StartFormPage
STROBJ_bEnum
STROBJ_bEnumPositionsOnly
STROBJ_bGetAdvanceWidths
STROBJ_dwGetCodePage
STROBJ_vEnumStart
UnloadNetworkFonts
XFORMOBJ_bApplyXform
XFORMOBJ_iGetXform
XLATEOBJ_cGetPalette
XLATEOBJ_hGetColorTransform
XLATEOBJ_iXlate
XLATEOBJ_piVector

Found follow exports in SHELL32.DLL
AppCompat_RunDLLW
AssocCreateForClasses
AssocGetDetailsOfPropKey
CDefFolderMenu_Create
CDefFolderMenu_Create2
CIDLData_CreateFromIDArray
Control_RunDLLA
Control_RunDLLAsUserW
Control_RunDLLW
DAD_AutoScroll
DAD_DragEnterEx
DAD_DragEnterEx2
DAD_DragLeave
DAD_DragMove
DAD_SetDragImage
DAD_ShowDragImage
DllCanUnloadNow
DllGetVersion
DllInstall
DllRegisterServer
DllUnregisterServer
DriveType
ExtractIconExW
GetFileNameFromBrowse
ILAppendID
ILClone
ILCloneFirst
ILCombine
ILCreateFromPath
ILCreateFromPathA
ILCreateFromPathW
ILFindChild
ILFindLastID
ILFree
ILGetNext
ILGetSize
ILIsEqual
ILIsParent
ILLoadFromStreamEx
ILRemoveLastID
ILSaveToStream
InitNetworkAddressControl
IsLFNDrive
IsLFNDriveA
IsLFNDriveW
IsNetDrive
IsUserAnAdmin
OpenAs_RunDLLA
OpenAs_RunDLLW
OpenRegStream
Options_RunDLL
Options_RunDLLA
Options_RunDLLW
PathCleanupSpec
PathGetShortPath
PathIsExe
PathIsSlowA
PathIsSlowW
PathMakeUniqueName
PathQualify
PathResolve
PathYetAnotherMakeUniqueName
PickIconDlg
PifMgr_CloseProperties
PifMgr_GetProperties
PifMgr_OpenProperties
PifMgr_SetProperties
PrepareDiscForBurnRunDllW
PrintersGetCommand_RunDLLA
PrintersGetCommand_RunDLLW
ReadCabinetState
RealDriveType
RestartDialog
RestartDialogEx
SHAddDefaultPropertiesByExt
SHAddFromPropSheetExtArray
SHAlloc
SHAssocEnumHandlers
SHBindToFolderIDListParent
SHBindToFolderIDListParentEx
SHBindToObject
SHBindToParent
SHBrowseForFolderW
SHChangeNotification_Lock
SHChangeNotification_Unlock
SHChangeNotifyDeregister
SHChangeNotifyRegister
SHChangeNotifyRegisterThread
SHChangeNotifySuspendResume
SHCloneSpecialIDList
SHCLSIDFromString
SHCoCreateInstance
SHCreateAssociationRegistration
SHCreateDataObject
SHCreateDefaultContextMenu
SHCreateDefaultExtractIcon
SHCreateDefaultPropertiesOp
SHCreateDirectory
SHCreateDirectoryExA
SHCreateDirectoryExW
SHCreateFileExtractIconW
SHCreateItemFromIDList
SHCreateItemFromParsingName
SHCreateItemFromRelativeName
SHCreateItemInKnownFolder
SHCreateItemWithParent
SHCreateLocalServerRunDll
SHCreateProcessAsUserW
SHCreatePropSheetExtArray
SHCreateQueryCancelAutoPlayMoniker
SHCreateShellFolderView
SHCreateShellFolderViewEx
SHCreateShellItem
SHCreateShellItemArray
SHCreateShellItemArrayFromDataObject
SHCreateShellItemArrayFromIDLists
SHCreateShellItemArrayFromShellItem
SHCreateStdEnumFmtEtc
SHDefExtractIconA
SHDefExtractIconW
SHDestroyPropSheetExtArray
SHDoDragDrop
Shell_GetCachedImageIndex
Shell_GetCachedImageIndexA
Shell_GetCachedImageIndexW
Shell_GetImageLists
Shell_MergeMenus
Shell_NotifyIconW
ShellExec_RunDLL
ShellExec_RunDLLA
ShellExec_RunDLLW
ShellExecuteExW
ShellHookProc
ShellMessageBoxA
ShellMessageBoxW
SHEmptyRecycleBinA
SHEmptyRecycleBinW
SHEnableServiceObject
SHEnumerateUnreadMailAccountsW
SHEvaluateSystemCommandTemplate
SHExtractIconsW
SHFileOperationW
SHFind_InitMenuPopup
SHFindFiles
SHFlushSFCache
SHFree
SHGetAttributesFromDataObject
SHGetDataFromIDListW
SHGetDiskFreeSpaceA
SHGetDiskFreeSpaceExA
SHGetDiskFreeSpaceExW
SHGetDriveMedia
SHGetFileInfoW
SHGetFolderLocation
SHGetFolderPathA
SHGetFolderPathAndSubDirA
SHGetFolderPathAndSubDirW
SHGetFolderPathEx
SHGetFolderPathW
SHGetIconOverlayIndexA
SHGetIconOverlayIndexW
SHGetIDListFromObject
SHGetImageList
SHGetKnownFolderIDList
SHGetKnownFolderPath
SHGetLocalizedName
SHGetNameFromIDList
SHGetNewLinkInfo
SHGetNewLinkInfoA
SHGetNewLinkInfoW
SHGetPathFromIDListEx
SHGetPathFromIDListW
SHGetPropertyStoreFromIDList
SHGetPropertyStoreFromParsingName
SHGetRealIDL
SHGetSetFolderCustomSettings
SHGetSetSettings
SHGetSettings
SHGetSpecialFolderPathA
SHGetSpecialFolderPathW
SHGetStockIconInfo
SHGetTemporaryPropertyForItem
SHGetUnreadMailCountW
SHHandleUpdateImage
SHHelpShortcuts_RunDLLA
SHHelpShortcuts_RunDLLW
SHILCreateFromPath
SHInvokePrinterCommandA
SHInvokePrinterCommandW
SHIsFileAvailableOffline
SHLimitInputEdit
SHLoadNonloadedIconOverlayIdentifiers
SHMapPIDLToSystemImageListIndex
SHMultiFileProperties
SHObjectProperties
SHOpenFolderAndSelectItems
SHOpenPropSheetW
SHOpenWithDialog
SHParseDisplayName
SHPathPrepareForWriteA
SHPathPrepareForWriteW
SHPropStgCreate
SHPropStgReadMultiple
SHPropStgWriteMultiple
SHQueryRecycleBinA
SHQueryRecycleBinW
SHQueryUserNotificationState
SHRemoveLocalizedName
SHReplaceFromPropSheetExtArray
SHRestricted
SHSetDefaultProperties
SHSetFolderPathA
SHSetFolderPathW
SHSetInstanceExplorer
SHSetKnownFolderPath
SHSetLocalizedName
SHSetTemporaryPropertyForItem
SHSetUnreadMailCountW
SHShellFolderView_Message
SHSimpleIDListFromPath
SHStartNetConnectionDialogW
SHTestTokenMembership
SHUpdateImageA
SHUpdateImageW
SHUpdateRecycleBinIcon
SHValidateUNC
SignalFileOpen
StrChrA
StrChrIA
StrChrIW
StrChrW
StrCmpNA
StrCmpNIA
StrCmpNIW
StrCmpNW
StrNCmpA
StrNCmpIA
StrNCmpIW
StrNCmpW
StrRChrA
StrRChrIA
StrRChrIW
StrRChrW
StrRStrA
StrRStrIA
StrRStrIW
StrRStrW
StrStrA
StrStrIA
StrStrIW
StrStrW
WaitForExplorerRestartW
Win32DeleteFile
WOWShellExecute
WriteCabinetState

Found follow exports in COMDLG32.DLL
DllCanUnloadNow
DllGetClassObject
dwLBSubclass
dwOKSubclass
LoadAlterBitmap
PrintDlgExA
PrintDlgExW
Ssync_ANSI_UNICODE_Struct_For_WOW
WantArrows

Found follow exports in COMCTL32.DLL
AddMRUStringW
CreateMRUListW
DefSubclassProc
DPA_Clone
DPA_Create
DPA_CreateEx
DPA_DeleteAllPtrs
DPA_DeletePtr
DPA_Destroy
DPA_DestroyCallback
DPA_EnumCallback
DPA_GetPtr
DPA_GetPtrIndex
DPA_Grow
DPA_InsertPtr
DPA_LoadStream
DPA_Merge
DPA_SaveStream
DPA_Search
DPA_SetPtr
DPA_Sort
DSA_Create
DSA_DeleteAllItems
DSA_DeleteItem
DSA_Destroy
DSA_DestroyCallback
DSA_EnumCallback
DSA_GetItem
DSA_GetItemPtr
DSA_InsertItem
DSA_SetItem
EnumMRUListW
FreeMRUList
ImageList_GetFlags
RegisterClassNameW
RemoveWindowSubclass
SetWindowSubclass
Str_SetPtrW

Found follow exports in ADVAPI32.DLL
A_SHAFinal
A_SHAInit
A_SHAUpdate
AccessCheckByType
AccessCheckByTypeAndAuditAlarmA
AccessCheckByTypeAndAuditAlarmW
AccessCheckByTypeResultList
AccessCheckByTypeResultListAndAuditAlarmA
AccessCheckByTypeResultListAndAuditAlarmByHandleA
AccessCheckByTypeResultListAndAuditAlarmByHandleW
AccessCheckByTypeResultListAndAuditAlarmW
AddAccessAllowedAceEx
AddAccessAllowedObjectAce
AddAccessDeniedAceEx
AddAccessDeniedObjectAce
AddAuditAccessAceEx
AddAuditAccessObjectAce
AddMandatoryAce
AddUsersToEncryptedFile
AddUsersToEncryptedFileEx
AuditComputeEffectivePolicyBySid
AuditComputeEffectivePolicyByToken
AuditEnumerateCategories
AuditEnumeratePerUserPolicy
AuditEnumerateSubCategories
AuditFree
AuditLookupCategoryGuidFromCategoryId
AuditLookupCategoryIdFromCategoryGuid
AuditLookupCategoryNameA
AuditLookupCategoryNameW
AuditLookupSubCategoryNameA
AuditLookupSubCategoryNameW
AuditQueryPerUserPolicy
AuditQuerySecurity
AuditQuerySystemPolicy
AuditSetPerUserPolicy
AuditSetSecurity
AuditSetSystemPolicy
BuildExplicitAccessWithNameA
BuildExplicitAccessWithNameW
BuildImpersonateExplicitAccessWithNameA
BuildImpersonateExplicitAccessWithNameW
BuildImpersonateTrusteeA
BuildImpersonateTrusteeW
BuildSecurityDescriptorA
BuildSecurityDescriptorW
BuildTrusteeWithNameA
BuildTrusteeWithNameW
BuildTrusteeWithObjectsAndNameA
BuildTrusteeWithObjectsAndNameW
BuildTrusteeWithObjectsAndSidA
BuildTrusteeWithObjectsAndSidW
BuildTrusteeWithSidA
BuildTrusteeWithSidW
CancelOverlappedAccess
ChangeServiceConfig2A
ChangeServiceConfig2W
CheckAppInitBlockedServiceIdentity
CheckTokenMembership
CloseCodeAuthzLevel
CloseEncryptedFileRaw
CloseThreadWaitChainSession
CloseTrace
CommandLineFromMsiDescriptor
ComputeAccessTokenFromCodeAuthzLevel
ControlServiceExA
ControlServiceExW
ControlTraceA
ControlTraceW
ConvertAccessToSecurityDescriptorA
ConvertAccessToSecurityDescriptorW
ConvertSDToStringSDRootDomainA
ConvertSDToStringSDRootDomainW
ConvertSecurityDescriptorToAccessA
ConvertSecurityDescriptorToAccessNamedA
ConvertSecurityDescriptorToAccessNamedW
ConvertSecurityDescriptorToAccessW
ConvertSecurityDescriptorToStringSecurityDescriptorA
ConvertSecurityDescriptorToStringSecurityDescriptorW
ConvertSidToStringSidA
ConvertSidToStringSidW
ConvertStringSDToSDDomainA
ConvertStringSDToSDDomainW
ConvertStringSDToSDRootDomainA
ConvertStringSDToSDRootDomainW
ConvertStringSecurityDescriptorToSecurityDescriptorA
ConvertStringSecurityDescriptorToSecurityDescriptorW
ConvertStringSidToSidA
ConvertStringSidToSidW
ConvertToAutoInheritPrivateObjectSecurity
CreateCodeAuthzLevel
CreatePrivateObjectSecurityEx
CreatePrivateObjectSecurityWithMultipleInheritance
CreateProcessWithLogonW
CreateProcessWithTokenW
CreateRestrictedToken
CreateTraceInstanceId
CreateWellKnownSid
CredBackupCredentials
CredDeleteA
CredDeleteW
CredEncryptAndMarshalBinaryBlob
CredEnumerateA
CredEnumerateW
CredFindBestCredentialA
CredFindBestCredentialW
CredFree
CredGetSessionTypes
CredGetTargetInfoA
CredGetTargetInfoW
CredIsMarshaledCredentialA
CredIsMarshaledCredentialW
CredIsProtectedA
CredIsProtectedW
CredMarshalCredentialA
CredMarshalCredentialW
CredpConvertCredential
CredpConvertOneCredentialSize
CredpConvertTargetInfo
CredpDecodeCredential
CredpEncodeCredential
CredpEncodeSecret
CredProfileLoaded
CredProfileUnloaded
CredProtectA
CredProtectW
CredReadA
CredReadByTokenHandle
CredReadDomainCredentialsA
CredReadDomainCredentialsW
CredReadW
CredRenameA
CredRenameW
CredRestoreCredentials
CredUnmarshalCredentialA
CredUnmarshalCredentialW
CredUnprotectA
CredUnprotectW
CredWriteA
CredWriteDomainCredentialsA
CredWriteDomainCredentialsW
CredWriteW
CryptAcquireContextW
CryptContextAddRef
CryptDuplicateHash
CryptDuplicateKey
CryptEnumProvidersA
CryptEnumProvidersW
CryptEnumProviderTypesA
CryptEnumProviderTypesW
CryptGetDefaultProviderA
CryptGetDefaultProviderW
CryptSetProviderExA
CryptSetProviderExW
CryptSetProviderW
CryptSignHashW
CryptVerifySignatureW
DecryptFileA
DecryptFileW
DuplicateEncryptionInfoFile
DuplicateTokenEx
ElfBackupEventLogFileA
ElfBackupEventLogFileW
ElfChangeNotify
ElfClearEventLogFileA
ElfClearEventLogFileW
ElfCloseEventLog
ElfDeregisterEventSource
ElfFlushEventLog
ElfNumberOfRecords
ElfOldestRecord
ElfOpenBackupEventLogA
ElfOpenBackupEventLogW
ElfOpenEventLogA
ElfOpenEventLogW
ElfReadEventLogA
ElfReadEventLogW
ElfRegisterEventSourceA
ElfRegisterEventSourceW
ElfReportEventA
ElfReportEventAndSourceW
ElfReportEventW
EnableTrace
EnableTraceEx
EncryptedFileKeyInfo
EncryptFileA
EncryptFileW
EncryptionDisable
EnumerateTraceGuids
EnumerateTraceGuidsEx
EnumServiceGroupW
EnumServicesStatusExA
EnumServicesStatusExW
EqualDomainSid
EventAccessControl
EventAccessQuery
EventAccessRemove
EventActivityIdControl
EventEnabled
EventProviderEnabled
EventRegister
EventUnregister
EventWrite
EventWriteEndScenario
EventWriteStartScenario
EventWriteString
EventWriteTransfer
FileEncryptionStatusA
FileEncryptionStatusW
FlushEfsCache
FlushTraceA
FlushTraceW
FreeEncryptedFileKeyInfo
FreeEncryptedFileMetadata
FreeEncryptionCertificateHashList
FreeInheritedFromArray
GetAccessPermissionsForObjectA
GetAccessPermissionsForObjectW
GetAuditedPermissionsFromAclA
GetAuditedPermissionsFromAclW
GetCurrentHwProfileA
GetCurrentHwProfileW
GetEffectiveRightsFromAclA
GetEffectiveRightsFromAclW
GetEncryptedFileMetadata
GetEventLogInformation
GetExplicitEntriesFromAclA
GetExplicitEntriesFromAclW
GetInformationCodeAuthzLevelW
GetInformationCodeAuthzPolicyW
GetInheritanceSourceA
GetInheritanceSourceW
GetLocalManagedApplicationData
GetLocalManagedApplications
GetManagedApplicationCategories
GetManagedApplications
GetMultipleTrusteeA
GetMultipleTrusteeOperationA
GetMultipleTrusteeOperationW
GetMultipleTrusteeW
GetNamedSecurityInfoA
GetNamedSecurityInfoExA
GetNamedSecurityInfoExW
GetNamedSecurityInfoW
GetOverlappedAccessResults
GetSecurityDescriptorRMControl
GetSecurityInfo
GetSecurityInfoExA
GetSecurityInfoExW
GetThreadWaitChain
GetTraceEnableFlags
GetTraceEnableLevel
GetTraceLoggerHandle
GetTrusteeFormA
GetTrusteeFormW
GetTrusteeNameA
GetTrusteeNameW
GetTrusteeTypeA
GetTrusteeTypeW
GetWindowsAccountDomainSid
I_QueryTagInformation
I_ScGetCurrentGroupStateW
I_ScIsSecurityProcess
I_ScPnPGetServiceName
I_ScQueryServiceConfig
I_ScSendPnPMessage
I_ScSendTSMessage
I_ScSetServiceBitsA
I_ScSetServiceBitsW
I_ScValidatePnPService
IdentifyCodeAuthzLevelW
ImpersonateAnonymousToken
InitiateShutdownA
InitiateShutdownW
InitiateSystemShutdownExA
InitiateSystemShutdownExW
InstallApplication
IsTokenRestricted
IsTokenUntrusted
IsValidRelativeSecurityDescriptor
IsWellKnownSid
LogonUserExA
LogonUserExExW
LogonUserExW
LookupSecurityDescriptorPartsA
LookupSecurityDescriptorPartsW
LsaAddAccountRights
LsaAddPrivilegesToAccount
LsaClearAuditLog
LsaClose
LsaCreateAccount
LsaCreateSecret
LsaCreateTrustedDomain
LsaCreateTrustedDomainEx
LsaDelete
LsaDeleteTrustedDomain
LsaEnumerateAccountRights
LsaEnumerateAccounts
LsaEnumerateAccountsWithUserRight
LsaEnumeratePrivileges
LsaEnumeratePrivilegesOfAccount
LsaEnumerateTrustedDomains
LsaEnumerateTrustedDomainsEx
LsaFreeMemory
LsaGetQuotasForAccount
LsaGetRemoteUserName
LsaGetSystemAccessAccount
LsaGetUserName
LsaICLookupNames
LsaICLookupNamesWithCreds
LsaICLookupSids
LsaICLookupSidsWithCreds
LsaLookupNames
LsaLookupNames2
LsaLookupPrivilegeDisplayName
LsaLookupPrivilegeName
LsaLookupPrivilegeValue
LsaLookupSids
LsaManageSidNameMapping
LsaNtStatusToWinError
LsaOpenAccount
LsaOpenPolicy
LsaOpenPolicySce
LsaOpenSecret
LsaOpenTrustedDomain
LsaOpenTrustedDomainByName
LsaQueryDomainInformationPolicy
LsaQueryForestTrustInformation
LsaQueryInformationPolicy
LsaQueryInfoTrustedDomain
LsaQuerySecret
LsaQuerySecurityObject
LsaQueryTrustedDomainInfo
LsaQueryTrustedDomainInfoByName
LsaRemoveAccountRights
LsaRemovePrivilegesFromAccount
LsaRetrievePrivateData
LsaSetDomainInformationPolicy
LsaSetForestTrustInformation
LsaSetInformationPolicy
LsaSetInformationTrustedDomain
LsaSetQuotasForAccount
LsaSetSecret
LsaSetSecurityObject
LsaSetSystemAccessAccount
LsaSetTrustedDomainInfoByName
LsaSetTrustedDomainInformation
LsaStorePrivateData
MakeAbsoluteSD2
MD4Final
MD4Init
MD4Update
MD5Final
MD5Init
MD5Update
MSChapSrvChangePassword
MSChapSrvChangePassword2
NotifyServiceStatusChange
NotifyServiceStatusChangeA
NotifyServiceStatusChangeW
ObjectDeleteAuditAlarmA
ObjectDeleteAuditAlarmW
OpenEncryptedFileRawA
OpenEncryptedFileRawW
OpenThreadWaitChainSession
OpenTraceA
OpenTraceW
PerfAddCounters
PerfCloseQueryHandle
PerfCreateInstance
PerfDecrementULongCounterValue
PerfDecrementULongLongCounterValue
PerfDeleteCounters
PerfDeleteInstance
PerfEnumerateCounterSet
PerfEnumerateCounterSetInstances
PerfIncrementULongCounterValue
PerfIncrementULongLongCounterValue
PerfOpenQueryHandle
PerfQueryCounterData
PerfQueryCounterInfo
PerfQueryCounterSetRegistrationInfo
PerfQueryInstance
PerfSetCounterRefValue
PerfSetCounterSetInfo
PerfSetULongCounterValue
PerfSetULongLongCounterValue
PerfStartProvider
PerfStartProviderEx
PerfStopProvider
ProcessIdleTasks
ProcessIdleTasksW
ProcessTrace
QueryAllTracesA
QueryAllTracesW
QueryRecoveryAgentsOnEncryptedFile
QuerySecurityAccessMask
QueryServiceConfig2A
QueryServiceConfig2W
QueryServiceStatusEx
QueryTraceA
QueryTraceW
QueryUsersOnEncryptedFile
ReadEncryptedFileRaw
RegConnectRegistryExA
RegConnectRegistryExW
RegCopyTreeA
RegCopyTreeW
RegCreateKeyTransactedA
RegCreateKeyTransactedW
RegDeleteKeyExA
RegDeleteKeyExW
RegDeleteKeyTransactedA
RegDeleteKeyTransactedW
RegDeleteKeyValueA
RegDeleteKeyValueW
RegDeleteTreeA
RegDeleteTreeW
RegDisablePredefinedCache
RegDisablePredefinedCacheEx
RegDisableReflectionKey
RegEnableReflectionKey
RegGetValueA
RegGetValueW
RegisterIdleTask
RegisterServiceCtrlHandlerExA
RegisterServiceCtrlHandlerExW
RegisterTraceGuidsA
RegisterTraceGuidsW
RegisterWaitChainCOMCallback
RegLoadAppKeyA
RegLoadAppKeyW
RegLoadMUIStringA
RegLoadMUIStringW
RegOpenCurrentUser
RegOpenKeyTransactedA
RegOpenKeyTransactedW
RegOpenUserClassesRoot
RegOverridePredefKey
RegQueryReflectionKey
RegRenameKey
RegSaveKeyExA
RegSaveKeyExW
RegSetKeyValueA
RegSetKeyValueW
RemoveTraceCallback
RemoveUsersFromEncryptedFile
SaferCloseLevel
SaferComputeTokenFromLevel
SaferCreateLevel
SaferGetLevelInformation
SaferGetPolicyInformation
SaferiChangeRegistryScope
SaferiCompareTokenLevels
SaferIdentifyLevel
SaferiIsExecutableFileType
SaferiPopulateDefaultsInRegistry
SaferiRecordEventLogEntry
SaferiReplaceProcessThreadTokens
SaferiSearchMatchingHashRules
SaferRecordEventLogEntry
SaferSetLevelInformation
SaferSetPolicyInformation
SetEncryptedFileMetadata
SetEntriesInAccessListA
SetEntriesInAccessListW
SetEntriesInAclA
SetEntriesInAclW
SetEntriesInAuditListA
SetEntriesInAuditListW
SetInformationCodeAuthzLevelW
SetInformationCodeAuthzPolicyW
SetNamedSecurityInfoA
SetNamedSecurityInfoExA
SetNamedSecurityInfoExW
SetNamedSecurityInfoW
SetPrivateObjectSecurityEx
SetSecurityAccessMask
SetSecurityDescriptorControl
SetSecurityDescriptorRMControl
SetSecurityInfo
SetSecurityInfoExA
SetSecurityInfoExW
SetTraceCallback
SetUserFileEncryptionKey
SetUserFileEncryptionKeyEx
StartTraceA
StartTraceW
StopTraceA
StopTraceW
SystemFunction001
SystemFunction002
SystemFunction003
SystemFunction004
SystemFunction005
SystemFunction006
SystemFunction007
SystemFunction008
SystemFunction009
SystemFunction010
SystemFunction011
SystemFunction012
SystemFunction013
SystemFunction014
SystemFunction015
SystemFunction016
SystemFunction017
SystemFunction018
SystemFunction019
SystemFunction020
SystemFunction021
SystemFunction022
SystemFunction023
SystemFunction024
SystemFunction025
SystemFunction026
SystemFunction027
SystemFunction028
SystemFunction029
SystemFunction030
SystemFunction031
SystemFunction032
SystemFunction033
SystemFunction034
SystemFunction035
SystemFunction036
SystemFunction040
SystemFunction041
TraceEvent
TraceEventInstance
TraceMessage
TraceMessageVa
TreeResetNamedSecurityInfoA
TreeResetNamedSecurityInfoW
TreeSetNamedSecurityInfoA
TreeSetNamedSecurityInfoW
TrusteeAccessToObjectA
TrusteeAccessToObjectW
UninstallApplication
UnregisterIdleTask
UnregisterTraceGuids
UpdateTraceA
UpdateTraceW
UsePinForEncryptedFilesA
UsePinForEncryptedFilesW
WmiCloseBlock
WmiDevInstToInstanceNameA
WmiDevInstToInstanceNameW
WmiEnumerateGuids
WmiExecuteMethodA
WmiExecuteMethodW
WmiFileHandleToInstanceNameA
WmiFileHandleToInstanceNameW
WmiFreeBuffer
WmiMofEnumerateResourcesA
WmiMofEnumerateResourcesW
WmiNotificationRegistrationA
WmiNotificationRegistrationW
WmiOpenBlock
WmiQueryAllDataA
WmiQueryAllDataMultipleA
WmiQueryAllDataMultipleW
WmiQueryAllDataW
WmiQueryGuidInformation
WmiQuerySingleInstanceA
WmiQuerySingleInstanceMultipleA
WmiQuerySingleInstanceMultipleW
WmiQuerySingleInstanceW
WmiReceiveNotificationsA
WmiReceiveNotificationsW
WmiSetSingleInstanceA
WmiSetSingleInstanceW
WmiSetSingleItemA
WmiSetSingleItemW
Wow64Win32ApiEntry
WriteEncryptedFileRaw

Found follow exports in WSOCK32.DLL
AcceptEx
GetAcceptExSockaddrs
MigrateWinsockConfiguration
WEP
WSApSetPostRoutine

Found follow exports in WS2_32.DLL
accept
bind
closesocket
connect
freeaddrinfo
FreeAddrInfoEx
FreeAddrInfoExW
FreeAddrInfoW
getaddrinfo
GetAddrInfoExA
GetAddrInfoExW
GetAddrInfoW
gethostbyaddr
gethostbyname
gethostname
getnameinfo
GetNameInfoW
getpeername
getprotobyname
getprotobynumber
getservbyname
getservbyport
getsockname
getsockopt
htonl
htons
inet_addr
inet_ntoa
inet_ntop
inet_pton
InetNtopW
InetPtonW
ioctlsocket
listen
ntohl
ntohs
recv
recvfrom
select
send
sendto
SetAddrInfoExA
SetAddrInfoExW
setsockopt
shutdown
socket
WahCloseApcHelper
WahCloseHandleHelper
WahCloseNotificationHandleHelper
WahCloseSocketHandle
WahCloseThread
WahCompleteRequest
WahCreateHandleContextTable
WahCreateNotificationHandle
WahCreateSocketHandle
WahDestroyHandleContextTable
WahDisableNonIFSHandleSupport
WahEnableNonIFSHandleSupport
WahEnumerateHandleContexts
WahInsertHandleContext
WahNotifyAllProcesses
WahOpenApcHelper
WahOpenCurrentThread
WahOpenHandleHelper
WahOpenNotificationHandleHelper
WahQueueUserApc
WahReferenceContextByHandle
WahRemoveHandleContext
WahWaitForNotification
WahWriteLSPEvent
WEP
WPUCompleteOverlappedRequest
WSAAccept
WSAAddressToStringA
WSAAddressToStringW
WSAAdvertiseProvider
WSAAsyncGetHostByAddr
WSAAsyncGetHostByName
WSAAsyncGetProtoByName
WSAAsyncGetProtoByNumber
WSAAsyncGetServByName
WSAAsyncGetServByPort
WSAAsyncSelect
WSACancelAsyncRequest
WSACancelBlockingCall
WSACleanup
WSACloseEvent
WSAConnect
WSAConnectByList
WSAConnectByNameA
WSAConnectByNameW
WSACreateEvent
WSADuplicateSocketA
WSADuplicateSocketW
WSAEnumNameSpaceProvidersA
WSAEnumNameSpaceProvidersExA
WSAEnumNameSpaceProvidersExW
WSAEnumNameSpaceProvidersW
WSAEnumNetworkEvents
WSAEnumProtocolsA
WSAEnumProtocolsW
WSAEventSelect
__WSAFDIsSet
WSAGetLastError
WSAGetOverlappedResult
WSAGetQOSByName
WSAGetServiceClassInfoA
WSAGetServiceClassInfoW
WSAGetServiceClassNameByClassIdA
WSAGetServiceClassNameByClassIdW
WSAHtonl
WSAHtons
WSAInstallServiceClassA
WSAInstallServiceClassW
WSAIoctl
WSAIsBlocking
WSAJoinLeaf
WSALookupServiceBeginA
WSALookupServiceBeginW
WSALookupServiceEnd
WSALookupServiceNextA
WSALookupServiceNextW
WSANSPIoctl
WSANtohl
WSANtohs
WSAPoll
WSAProviderCompleteAsyncCall
WSAProviderConfigChange
WSApSetPostRoutine
WSARecv
WSARecvDisconnect
WSARecvFrom
WSARemoveServiceClass
WSAResetEvent
WSASend
WSASendDisconnect
WSASendMsg
WSASendTo
WSASetBlockingHook
WSASetEvent
WSASetLastError
WSASetServiceA
WSASetServiceW
WSASocketA
WSASocketW
WSAStartup
WSAStringToAddressA
WSAStringToAddressW
WSAUnadvertiseProvider
WSAUnhookBlockingHook
WSAWaitForMultipleEvents
WSCDeinstallProvider
WSCEnableNSProvider
WSCEnumProtocols
WSCGetApplicationCategory
WSCGetProviderInfo
WSCGetProviderPath
WSCInstallNameSpace
WSCInstallNameSpaceEx
WSCInstallProvider
WSCInstallProviderAndChains
WSCSetApplicationCategory
WSCSetProviderInfo
WSCUnInstallNameSpace
WSCUpdateProvider
WSCWriteNameSpaceOrder
WSCWriteProviderOrder


<<Click here to return to the search engine