Windows 7 DLL File Information - advapi32.dll |
The following DLL report was generated by automatic DLL script that scanned and loaded all DLL files in the system32 directory of Windows 7, extracted the information from them, and then saved it into HTML reports. If you want to view a report of another DLL, go to the main page of this Web site.
General Information
File Description: | Advanced Windows 32 Base API |
File Version: | 6.1.7100.0 (winmain_win7rc.090421-1700) |
Company: | Microsoft Corporation |
Product Name: | Microsoft Windows Operating System |
DLL popularity | Very High - 848 other DLL files in system32 directory are statically linked to this file. |
File Size: | 625 KB |
Total Number of Exported Functions: | 806 |
Total Number of Exported Functions With Names: | 805 |
Section Headers
Name | Virtual Address | Raw Data Size | % of File | Characteristics | Section Contains... |
---|---|---|---|---|---|
.text | 0x00001000 | 465,920 Bytes | 72.8% | Read, Execute | Code |
.data | 0x00073000 | 11,776 Bytes | 1.8% | Write, Read | Initialized Data |
.rsrc | 0x00077000 | 143,872 Bytes | 22.5% | Read | Initialized Data |
.reloc | 0x0009b000 | 16,896 Bytes | 2.6% | Read, Discardable | Initialized Data |
Static Linking
advapi32.dll is statically linked to the following files:msvcrt.dll
ntdll.dll
KERNELBASE.dll
API-MS-WIN-Service-Core-L1-1-0.dll
API-MS-WIN-Service-winsvc-L1-1-0.dll
API-MS-WIN-Service-Management-L1-1-0.dll
API-MS-WIN-Service-Management-L2-1-0.dll
API-MS-Win-Core-LocalRegistry-L1-1-0.dll
API-MS-Win-Core-NamedPipe-L1-1-0.dll
API-MS-Win-Core-ProcessThreads-L1-1-0.dll
API-MS-Win-Security-Base-L1-1-0.dll
KERNEL32.dll
RPCRT4.dll
This means that when advapi32.dll is loaded, the above files are automatically loaded too. If one of these files is corrupted or missing, advapi32.dll won't be loaded.
General Resources Information
Resource Type | Number of Items | Total Size | % of File |
---|---|---|---|
Icons | 0 | 0 Bytes | 0.0% |
Animated Icons | 0 | 0 Bytes | 0.0% |
Cursors | 0 | 0 Bytes | 0.0% |
Animated Cursors | 0 | 0 Bytes | 0.0% |
Bitmaps | 0 | 0 Bytes | 0.0% |
AVI Files | 0 | 0 Bytes | 0.0% |
Dialog-Boxes | 0 | 0 Bytes | 0.0% |
HTML Related Files | 0 | 0 Bytes | 0.0% |
Menus | 0 | 0 Bytes | 0.0% |
Strings | 241 | 40,268 Bytes | 6.3% |
Type Libraries | 0 | 0 Bytes | 0.0% |
Manifest | 0 | 0 Bytes | 0.0% |
All Others | 6 | 432,372 Bytes | 67.6% |
Total | 247 | 472,640 Bytes | 73.8% |
Icons in this file
No icons found in this file
Cursors in this file
No cursors found in this file
Dialog-boxes list (up to 200 dialogs)
No dialog resources in this file.
String resources in this dll (up to 200 strings)
String ID | String Text |
---|---|
1 | Processor Information |
2 | Processor Information |
3 | The Processor Information performance counter set consists of counters that measure aspects of processor activity. The processor is the part of the computer that performs arithmetic and logical computations, initiates operations on peripherals, and runs the threads of processes. A computer can have multiple processors. The Processor Information counter set represents each processor as an instance of the counter set. |
5 | % Processor Time |
6 | % Processor Time |
7 | % Processor Time is the percentage of elapsed time that the processor spends to execute a non-Idle thread. It is calculated by measuring the percentage of time that the processor spends executing the idle thread and then subtracting that value from 100%. (Each processor has an idle thread to which time is accumulated when no other threads are ready to run). This counter is the primary indicator of processor activity, and displays the average percentage of busy time observed during the sample interval. It should be noted that the accounting calculation of whether the processor is idle is performed at an internal sampling interval of the system clock tick. On todays fast processors, % Processor Time can therefore underestimate the processor utilization as the processor may be spending a lot of time servicing threads between the system clock sampling interval. Workload based timer applications are one example of applications which are more likely to be measured inaccurately as timers are signaled just after the sample is taken. |
9 | % User Time |
10 | % User Time |
11 | % User Time is the percentage of elapsed time the processor spends in the user mode. User mode is a restricted processing mode designed for applications, environment subsystems, and integral subsystems. The alternative, privileged mode, is designed for operating system components and allows direct access to hardware and all memory. The operating system switches application threads to privileged mode to access operating system services. This counter displays the average busy time as a percentage of the sample time. |
13 | % Privileged Time |
14 | % Privileged Time |
15 | % Privileged Time is the percentage of elapsed time that the process threads spent executing code in privileged mode. When a Windows system service in called, the service will often run in privileged mode to gain access to system-private data. Such data is protected from access by threads executing in user mode. Calls to the system can be explicit or implicit, such as page faults or interrupts. Unlike some early operating systems, Windows uses process boundaries for subsystem protection in addition to the traditional protection of user and privileged modes. Some work done by Windows on behalf of the application might appear in other subsystem processes in addition to the privileged time in the process. |
17 | Interrupts/sec |
18 | Interrupts/sec |
19 | Interrupts/sec is the average rate, in incidents per second, at which the processor received and serviced hardware interrupts. It does not include deferred procedure calls (DPCs), which are counted separately. This value is an indirect indicator of the activity of devices that generate interrupts, such as the system clock, the mouse, disk drivers, data communication lines, network interface cards, and other peripheral devices. These devices normally interrupt the processor when they have completed a task or require attention. Normal thread execution is suspended. The system clock typically interrupts the processor every 10 milliseconds, creating a background of interrupt activity. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval. |
21 | % DPC Time |
22 | % DPC Time |
23 | % DPC Time is the percentage of time that the processor spent receiving and servicing deferred procedure calls (DPCs) during the sample interval. DPCs are interrupts that run at a lower priority than standard interrupts. % DPC Time is a component of % Privileged Time because DPCs are executed in privileged mode. They are counted separately and are not a component of the interrupt counters. This counter displays the average busy time as a percentage of the sample time. |
25 | % Interrupt Time |
26 | % Interrupt Time |
27 | % Interrupt Time is the time the processor spends receiving and servicing hardware interrupts during sample intervals. This value is an indirect indicator of the activity of devices that generate interrupts, such as the system clock, the mouse, disk drivers, data communication lines, network interface cards and other peripheral devices. These devices normally interrupt the processor when they have completed a task or require attention. Normal thread execution is suspended during interrupts. Most system clocks interrupt the processor every 10 milliseconds, creating a background of interrupt activity. suspends normal thread execution during interrupts. This counter displays the average busy time as a percentage of the sample time. |
29 | DPCs Queued/sec |
30 | DPCs Queued/sec |
31 | DPCs Queued/sec is the average rate, in incidents per second, at which deferred procedure calls (DPCs) were added to the processor's DPC queue. DPCs are interrupts that run at a lower priority than standard interrupts. Each processor has its own DPC queue. This counter measures the rate that DPCs are added to the queue, not the number of DPCs in the queue. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval. |
33 | DPC Rate |
34 | DPC Rate |
35 | DPC Rate is the rate at which deferred procedure calls (DPCs) were added to the processors DPC queues between the timer ticks of the processor clock. DPCs are interrupts that run at alower priority than standard interrupts. Each processor has its own DPC queue. This counter measures the rate that DPCs were added to the queue, not the number of DPCs in the queue. This counter displays the last observed value only; it is not an average. |
37 | % Idle Time |
38 | % Idle Time |
39 | % Idle Time is the percentage of time the processor is idle during the sample interval |
41 | % C1 Time |
42 | % C1 Time |
43 | % C1 Time is the percentage of time the processor spends in the C1 low-power idle state. % C1 Time is a subset of the total processor idle time. C1 low-power idle state enables the processor to maintain its entire context and quickly return to the running state. Not all systems support the % C1 state. |
45 | % C2 Time |
46 | % C2 Time |
47 | % C2 Time is the percentage of time the processor spends in the C2 low-power idle state. % C2 Time is a subset of the total processor idle time. C2 low-power idle state enables the processor to maintain the context of the system caches. The C2 power state is a lower power and higher exit latency state than C1. Not all systems support the C2 state. |
49 | % C3 Time |
50 | % C3 Time |
51 | % C3 Time is the percentage of time the processor spends in the C3 low-power idle state. % C3 Time is a subset of the total processor idle time. When the processor is in the C3 low-power idle state it is unable to maintain the coherency of its caches. The C3 power state is a lower power and higher exit latency state than C2. Not all systems support the C3 state. |
53 | C1 Transitions/sec |
54 | C1 Transitions/sec |
55 | C1 Transitions/sec is the rate that the CPU enters the C1 low-power idle state. The CPU enters the C1 state when it is sufficiently idle and exits this state on any interrupt. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval. |
57 | C2 Transitions/sec |
58 | C2 Transitions/sec |
59 | C2 Transitions/sec is the rate that the CPU enters the C2 low-power idle state. The CPU enters the C2 state when it is sufficiently idle and exits this state on any interrupt. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval. |
61 | C3 Transitions/sec |
62 | C3 Transitions/sec |
63 | C3 Transitions/sec is the rate that the CPU enters the C3 low-power idle state. The CPU enters the C3 state when it is sufficiently idle and exits this state on any interrupt. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval. |
65 | % Priority Time |
66 | % Priority Time |
67 | % Priority Time is the percentage of elapsed time that the processor spends executing threads that are not low priority. It is calculated by measuring the percentage of time that the processor spends executing low priority threads or the idle thread and then subtracting that value from 100%. (Each processor has an idle thread to which time is accumulated when no other threads are ready to run). This counter displays the average percentage of busy time observed during the sample interval excluding low priority background work. It should be noted that the accounting calculation of whether the processor is idle is performed at an internal sampling interval of the system clock tick. % Priority Time can therefore underestimate the processor utilization as the processor may be spending a lot of time servicing threads between the system clock sampling interval. Workload based timer applications are one example of applications which are more likely to be measured inaccurately as timers are signaled just after the sample is taken. |
69 | Parking Status |
70 | Parking Status |
71 | Parking Status represents whether a processor is parked or not. |
73 | Processor Frequency |
74 | Processor Frequency |
75 | Processor Frequency is the frequency of the current processor in megahertz. |
77 | % of Maximum Frequency |
78 | % of Maximum Frequency |
79 | % of Maximum Frequency is the percentage of the current processor's maximum frequency. |
81 | Processor State Flags |
82 | Processor State Flags |
83 | Processor State Flags |
85 | Synchronization |
86 | Synchronization |
87 | The Synchronization performance object consists of counters for kernel synchronization. The synchronization object represents each processor as an instance of the object. |
89 | Spinlock Acquires/sec |
90 | Spinlock Acquires/sec |
91 | Spinlock acquires/sec is the rate of spinlock acquisitions. It includes the basic spinlocks, queued spinlocks, in-stack queued spinlocks, and shared spinlocks acquisitions. |
93 | Spinlock Contentions/sec |
94 | Spinlock Contentions/sec |
95 | Spinlock contentions/sec is the rate of spinlock contentions. It includes the basic spinlocks, queued spinlocks, in-stack queued spinlocks, and shared spinlocks contentions. |
97 | Spinlock Spins/sec |
98 | Spinlock Spins/sec |
99 | Spinlock spins/sec is the rate of spinlock spins. It includes the spins to acquire basic spinlocks, queued spinlocks, in-stack queued spinlocks, and shared spinlocks. |
101 | IPI Send Broadcast Requests/sec |
102 | IPI Send Broadcast Requests/sec |
103 | IPI Send Broadcast Requests/sec is the rate of IPI broadcast requests. |
105 | IPI Send Routine Requests/sec |
106 | IPI Send Routine Requests/sec |
107 | IPI Send Routine Requests/sec is the rate of IPI routine requests. |
109 | IPI Send Software Interrupts/sec |
110 | IPI Send Software Interrupts/sec |
111 | IPI Send Software Interrrupts/sec is the rate of software interrupts. |
113 | Exec. Resource Total Initialize/sec |
114 | Exec. Resource Total Initialize/sec |
115 | Frequency of initialization operations on Executive Resources. |
117 | Exec. Resource Total Re-Initialize/sec |
118 | Exec. Resource Total Re-Initialize/sec |
119 | Frequency of re-initialization operations on Executive Resources. |
121 | Exec. Resource Total Delete/sec |
122 | Exec. Resource Total Delete/sec |
123 | Frequency of delete operations on Executive Resources. |
125 | Exec. Resource Total Acquires/sec |
126 | Exec. Resource Total Acquires/sec |
127 | Frequency of acquire operations on Executive Resources. |
129 | Exec. Resource Total Contentions/sec |
130 | Exec. Resource Total Contentions/sec |
131 | Contention rate on Executive Resources. |
133 | Exec. Resource Total Exclusive Releases/sec |
134 | Exec. Resource Total Exclusive Releases/sec |
135 | Frequency of Exclusive releases on Executive Resources. |
137 | Exec. Resource Total Shared Releases/sec |
138 | Exec. Resource Total Shared Releases/sec |
139 | Frequency of Shared releases on Executive Resources. |
141 | Exec. Resource Total Conv. Exclusive To Shared/sec |
142 | Exec. Resource Total Conv. Exclusive To Shared/sec |
143 | Frequency of convert to shared operations on Executive Resources. |
145 | Exec. Resource Attempts AcqExclLite/sec |
146 | Exec. Resource Attempts AcqExclLite/sec |
147 | Frequency of acquire exclusive attempts on Executive Resources from ExAcquireResourceExclusiveLite. |
149 | Exec. Resource Acquires AcqExclLite/sec |
150 | Exec. Resource Acquires AcqExclLite/sec |
151 | Frequency of first exclusive acquires from ExAcquireResourceExclusiveLite. |
153 | Exec. Resource Recursive Excl. Acquires AcqExclLite/sec |
154 | Exec. Resource Recursive Excl. Acquires AcqExclLite/sec |
155 | Frequency of recursive exclusive acquires from ExAcquireResourceExclusiveLite. |
157 | Exec. Resource Contention AcqExclLite/sec |
158 | Exec. Resource Contention AcqExclLite/sec |
159 | Frequency of waits during exclusive acquire attempts from ExAcquireResourceExclusiveLite. |
161 | Exec. Resource no-Waits AcqExclLite/sec |
162 | Exec. Resource no-Waits AcqExclLite/sec |
163 | Frequency of no-waits during exclusive acquire attempts from ExAcquireResourceExclusiveLite. |
165 | Exec. Resource Attempts AcqShrdLite/sec |
166 | Exec. Resource Attempts AcqShrdLite/sec |
167 | Frequency of acquire shared attempts on Executive Resources from ExAcquireResourceSharedLite. |
169 | Exec. Resource Recursive Excl. Acquires AcqShrdLite/sec |
170 | Exec. Resource Recursive Excl. Acquires AcqShrdLite/sec |
171 | Frequency of recursive exclusive acquires from ExAcquireResourceSharedLite. |
173 | Exec. Resource Acquires AcqShrdLite/sec |
174 | Exec. Resource Acquires AcqShrdLite/sec |
175 | Frequency of first shared acquires from ExAcquireResourceSharedLite. |
177 | Exec. Resource Recursive Sh. Acquires AcqShrdLite/sec |
178 | Exec. Resource Recursive Sh. Acquires AcqShrdLite/sec |
179 | Frequency of recursive shared acquires from ExAcquireResourceSharedLite. |
181 | Exec. Resource Contention AcqShrdLite/sec |
182 | Exec. Resource Contention AcqShrdLite/sec |
183 | Frequency of waits during acquire attempts from ExAcquireResourceSharedLite. |
185 | Exec. Resource no-Waits AcqShrdLite/sec |
186 | Exec. Resource no-Waits AcqShrdLite/sec |
187 | Frequency of no-waits during acquire attempts from ExAcquireResourceSharedLite. |
189 | Exec. Resource Attempts AcqShrdStarveExcl/sec |
190 | Exec. Resource Attempts AcqShrdStarveExcl/sec |
191 | Frequency of acquire shared attempts on Executive Resources from ExAcquireSharedStarveExclusive. |
193 | Exec. Resource Recursive Excl. Acquires AcqShrdStarveExcl/sec |
194 | Exec. Resource Recursive Excl. Acquires AcqShrdStarveExcl/sec |
195 | Frequency of recursive exclusive acquires from ExAcquireSharedStarveExclusive. |
197 | Exec. Resource Acquires AcqShrdStarveExcl/sec |
198 | Exec. Resource Acquires AcqShrdStarveExcl/sec |
199 | Frequency of first shared acquires from ExAcquireSharedStarveExclusive. |
201 | Exec. Resource Recursive Sh. Acquires AcqShrdStarveExcl/sec |
202 | Exec. Resource Recursive Sh. Acquires AcqShrdStarveExcl/sec |
203 | Frequency of recursive shared acquires from ExAcquireSharedStarveExclusive. |
205 | Exec. Resource Contention AcqShrdStarveExcl/sec |
206 | Exec. Resource Contention AcqShrdStarveExcl/sec |
207 | Frequency of waits during shared acquire attempts from ExAcquireSharedStarveExclusive. |
209 | Exec. Resource no-Waits AcqShrdStarveExcl/sec |
210 | Exec. Resource no-Waits AcqShrdStarveExcl/sec |
211 | Frequency of no-waits during shared acquire attempts from ExAcquireSharedStarveExclusive. |
213 | Exec. Resource Attempts AcqShrdWaitForExcl/sec |
214 | Exec. Resource Attempts AcqShrdWaitForExcl/sec |
215 | Frequency of acquire shared attempts on Executive Resources from ExAcquireSharedWaitForExclusive. |
217 | Exec. Resource Recursive Excl. Acquires AcqShrdWaitForExcl/sec |
218 | Exec. Resource Recursive Excl. Acquires AcqShrdWaitForExcl/sec |
219 | Frequency of recursive exclusive acquires from ExAcquireSharedWaitForExclusive. |
221 | Exec. Resource Acquires AcqShrdWaitForExcl/sec |
222 | Exec. Resource Acquires AcqShrdWaitForExcl/sec |
223 | Frequency of first shared acquires from ExAcquireSharedWaitForExclusive. |
225 | Exec. Resource Recursive Sh. Acquires AcqShrdWaitForExcl/sec |
226 | Exec. Resource Recursive Sh. Acquires AcqShrdWaitForExcl/sec |
227 | Frequency of recursive shared acquires from ExAcquireSharedWaitForExclusive. |
229 | Exec. Resource Contention AcqShrdWaitForExcl/sec |
230 | Exec. Resource Contention AcqShrdWaitForExcl/sec |
231 | Frequency of waits during shared acquire attempts from ExAcquireSharedWaitForExclusive. |
233 | Exec. Resource no-Waits AcqShrdWaitForExcl/sec |
234 | Exec. Resource no-Waits AcqShrdWaitForExcl/sec |
235 | Frequency of no-waits during exclusive acquire attempts from ExAcquireSharedWaitForExclusive. |
237 | Exec. Resource Set Owner Pointer Exclusive/sec |
238 | Exec. Resource Set Owner Pointer Exclusive/sec |
239 | Frequency of ExSetResourceOwnerPointer to an exclusive owner. |
241 | Exec. Resource Set Owner Pointer Shared (New Owner)/sec |
242 | Exec. Resource Set Owner Pointer Shared (New Owner)/sec |
243 | Frequency of ExSetResourceOwnerPointer to a new shared owner. |
245 | Exec. Resource Set Owner Pointer Shared (Existing Owner)/sec |
246 | Exec. Resource Set Owner Pointer Shared (Existing Owner)/sec |
247 | Frequency of ExSetResourceOwnerPointer to an existing shared owner. |
249 | Exec. Resource Boost Excl. Owner/sec |
250 | Exec. Resource Boost Excl. Owner/sec |
251 | Frequency of boosting exclusive ownwer when waiting for this Executive Resource. |
253 | Exec. Resource Boost Shared Owners/sec |
254 | Exec. Resource Boost Shared Owners/sec |
255 | Frequency of boosting shared ownwer(s) when waiting for this Executive Resource. |
257 | Event Tracing for Windows |
258 | Event Tracing for Windows |
259 | The counters in this collection refer to system-wide metrics about the performance of the Event Tracing for Windows subsystem. |
261 | Total Number of Distinct Enabled Providers |
262 | Total Number of Distinct Enabled Providers |
263 | Number of distinct event providers that are enabled to ETW sessions; multiple instances of a provider are counted only once. |
265 | Total Number of Distinct Pre-Enabled Providers |
266 | Total Number of Distinct Pre-Enabled Providers |
COM Classes/Interfaces
There is no type library in this file with COM classes/interfaces information
Exported Functions List
The following functions are exported by this dll:A_SHAFinal | A_SHAInit |
A_SHAUpdate | AbortSystemShutdownA |
AbortSystemShutdownW | AccessCheck |
AccessCheckAndAuditAlarmA | AccessCheckAndAuditAlarmW |
AccessCheckByType | AccessCheckByTypeAndAuditAlarmA |
AccessCheckByTypeAndAuditAlarmW | AccessCheckByTypeResultList |
AccessCheckByTypeResultListAndAuditAlarmA | AccessCheckByTypeResultListAndAuditAlarmByHandleA |
AccessCheckByTypeResultListAndAuditAlarmByHandleW | AccessCheckByTypeResultListAndAuditAlarmW |
AddAccessAllowedAce | AddAccessAllowedAceEx |
AddAccessAllowedObjectAce | AddAccessDeniedAce |
AddAccessDeniedAceEx | AddAccessDeniedObjectAce |
AddAce | AddAuditAccessAce |
AddAuditAccessAceEx | AddAuditAccessObjectAce |
AddConditionalAce | AddMandatoryAce |
AddUsersToEncryptedFile | AddUsersToEncryptedFileEx |
AdjustTokenGroups | AdjustTokenPrivileges |
AllocateAndInitializeSid | AllocateLocallyUniqueId |
AreAllAccessesGranted | AreAnyAccessesGranted |
AuditComputeEffectivePolicyBySid | AuditComputeEffectivePolicyByToken |
AuditEnumerateCategories | AuditEnumeratePerUserPolicy |
AuditEnumerateSubCategories | AuditFree |
AuditLookupCategoryGuidFromCategoryId | AuditLookupCategoryIdFromCategoryGuid |
AuditLookupCategoryNameA | AuditLookupCategoryNameW |
AuditLookupSubCategoryNameA | AuditLookupSubCategoryNameW |
AuditQueryGlobalSaclA | AuditQueryGlobalSaclW |
AuditQueryPerUserPolicy | AuditQuerySecurity |
AuditQuerySystemPolicy | AuditSetGlobalSaclA |
AuditSetGlobalSaclW | AuditSetPerUserPolicy |
AuditSetSecurity | AuditSetSystemPolicy |
BackupEventLogA | BackupEventLogW |
BuildExplicitAccessWithNameA | BuildExplicitAccessWithNameW |
BuildImpersonateExplicitAccessWithNameA | BuildImpersonateExplicitAccessWithNameW |
BuildImpersonateTrusteeA | BuildImpersonateTrusteeW |
BuildSecurityDescriptorA | BuildSecurityDescriptorW |
BuildTrusteeWithNameA | BuildTrusteeWithNameW |
BuildTrusteeWithObjectsAndNameA | BuildTrusteeWithObjectsAndNameW |
BuildTrusteeWithObjectsAndSidA | BuildTrusteeWithObjectsAndSidW |
BuildTrusteeWithSidA | BuildTrusteeWithSidW |
CancelOverlappedAccess | ChangeServiceConfig2A |
ChangeServiceConfig2W | ChangeServiceConfigA |
ChangeServiceConfigW | CheckTokenMembership |
ClearEventLogA | ClearEventLogW |
CloseCodeAuthzLevel | CloseEncryptedFileRaw |
CloseEventLog | CloseServiceHandle |
CloseThreadWaitChainSession | CloseTrace |
CommandLineFromMsiDescriptor | ComputeAccessTokenFromCodeAuthzLevel |
ControlService | ControlServiceExA |
ControlServiceExW | ControlTraceA |
ControlTraceW | ConvertAccessToSecurityDescriptorA |
ConvertAccessToSecurityDescriptorW | ConvertSDToStringSDRootDomainA |
ConvertSDToStringSDRootDomainW | ConvertSecurityDescriptorToAccessA |
ConvertSecurityDescriptorToAccessNamedA | ConvertSecurityDescriptorToAccessNamedW |
ConvertSecurityDescriptorToAccessW | ConvertSecurityDescriptorToStringSecurityDescriptorA |
ConvertSecurityDescriptorToStringSecurityDescriptorW | ConvertSidToStringSidA |
ConvertSidToStringSidW | ConvertStringSDToSDDomainA |
ConvertStringSDToSDDomainW | ConvertStringSDToSDRootDomainA |
ConvertStringSDToSDRootDomainW | ConvertStringSecurityDescriptorToSecurityDescriptorA |
ConvertStringSecurityDescriptorToSecurityDescriptorW | ConvertStringSidToSidA |
ConvertStringSidToSidW | ConvertToAutoInheritPrivateObjectSecurity |
CopySid | CreateCodeAuthzLevel |
CreatePrivateObjectSecurity | CreatePrivateObjectSecurityEx |
CreatePrivateObjectSecurityWithMultipleInheritance | CreateProcessAsUserA |
CreateProcessAsUserW | CreateProcessWithLogonW |
CreateProcessWithTokenW | CreateRestrictedToken |
CreateServiceA | CreateServiceW |
CreateTraceInstanceId | CreateWellKnownSid |
CredBackupCredentials | CredDeleteA |
CredDeleteW | CredEncryptAndMarshalBinaryBlob |
CredEnumerateA | CredEnumerateW |
CredFindBestCredentialA | CredFindBestCredentialW |
CredFree | CredGetSessionTypes |
CredGetTargetInfoA | CredGetTargetInfoW |
CredIsMarshaledCredentialA | CredIsMarshaledCredentialW |
CredIsProtectedA | CredIsProtectedW |
CredMarshalCredentialA | CredMarshalCredentialW |
CredProfileLoaded | CredProfileUnloaded |
CredProtectA | CredProtectW |
CredReadA | CredReadByTokenHandle |
CredReadDomainCredentialsA | CredReadDomainCredentialsW |
CredReadW | CredRenameA |
CredRenameW | CredRestoreCredentials |
CredUnmarshalCredentialA | CredUnmarshalCredentialW |
CredUnprotectA | CredUnprotectW |
CredWriteA | CredWriteDomainCredentialsA |
CredWriteDomainCredentialsW | CredWriteW |
CredpConvertCredential | CredpConvertOneCredentialSize |
CredpConvertTargetInfo | CredpDecodeCredential |
CredpEncodeCredential | CredpEncodeSecret |
CryptAcquireContextA | CryptAcquireContextW |
CryptContextAddRef | CryptCreateHash |
CryptDecrypt | CryptDeriveKey |
CryptDestroyHash | CryptDestroyKey |
CryptDuplicateHash | CryptDuplicateKey |
CryptEncrypt | CryptEnumProviderTypesA |
CryptEnumProviderTypesW | CryptEnumProvidersA |
CryptEnumProvidersW | CryptExportKey |
CryptGenKey | CryptGenRandom |
CryptGetDefaultProviderA | CryptGetDefaultProviderW |
CryptGetHashParam | CryptGetKeyParam |
CryptGetProvParam | CryptGetUserKey |
CryptHashData | CryptHashSessionKey |
CryptImportKey | CryptReleaseContext |
CryptSetHashParam | CryptSetKeyParam |
CryptSetProvParam | CryptSetProviderA |
CryptSetProviderExA | CryptSetProviderExW |
CryptSetProviderW | CryptSignHashA |
CryptSignHashW | CryptVerifySignatureA |
CryptVerifySignatureW | DecryptFileA |
DecryptFileW | DeleteAce |
DeleteService | DeregisterEventSource |
DestroyPrivateObjectSecurity | DuplicateEncryptionInfoFile |
DuplicateToken | DuplicateTokenEx |
ElfBackupEventLogFileA | ElfBackupEventLogFileW |
ElfChangeNotify | ElfClearEventLogFileA |
ElfClearEventLogFileW | ElfCloseEventLog |
ElfDeregisterEventSource | ElfFlushEventLog |
ElfNumberOfRecords | ElfOldestRecord |
ElfOpenBackupEventLogA | ElfOpenBackupEventLogW |
ElfOpenEventLogA | ElfOpenEventLogW |
ElfReadEventLogA | ElfReadEventLogW |
ElfRegisterEventSourceA | ElfRegisterEventSourceW |
ElfReportEventA | ElfReportEventAndSourceW |
ElfReportEventW | EnableTrace |
EnableTraceEx | EnableTraceEx2 |
EncryptFileA | EncryptFileW |
EncryptedFileKeyInfo | EncryptionDisable |
EnumDependentServicesA | EnumDependentServicesW |
EnumServiceGroupW | EnumServicesStatusA |
EnumServicesStatusExA | EnumServicesStatusExW |
EnumServicesStatusW | EnumerateTraceGuids |
EnumerateTraceGuidsEx | EqualDomainSid |
EqualPrefixSid | EqualSid |
EventAccessControl | EventAccessQuery |
EventAccessRemove | EventActivityIdControl |
EventEnabled | EventProviderEnabled |
EventRegister | EventUnregister |
EventWrite | EventWriteEndScenario |
EventWriteEx | EventWriteStartScenario |
EventWriteString | EventWriteTransfer |
FileEncryptionStatusA | FileEncryptionStatusW |
FindFirstFreeAce | FlushEfsCache |
FlushTraceA | FlushTraceW |
FreeEncryptedFileKeyInfo | FreeEncryptedFileMetadata |
FreeEncryptionCertificateHashList | FreeInheritedFromArray |
FreeSid | GetAccessPermissionsForObjectA |
GetAccessPermissionsForObjectW | GetAce |
GetAclInformation | GetAuditedPermissionsFromAclA |
GetAuditedPermissionsFromAclW | GetCurrentHwProfileA |
GetCurrentHwProfileW | GetEffectiveRightsFromAclA |
GetEffectiveRightsFromAclW | GetEncryptedFileMetadata |
GetEventLogInformation | GetExplicitEntriesFromAclA |
GetExplicitEntriesFromAclW | GetFileSecurityA |
GetFileSecurityW | GetInformationCodeAuthzLevelW |
GetInformationCodeAuthzPolicyW | GetInheritanceSourceA |
GetInheritanceSourceW | GetKernelObjectSecurity |
GetLengthSid | GetLocalManagedApplicationData |
GetLocalManagedApplications | GetManagedApplicationCategories |
GetManagedApplications | GetMultipleTrusteeA |
GetMultipleTrusteeOperationA | GetMultipleTrusteeOperationW |
GetMultipleTrusteeW | GetNamedSecurityInfoA |
GetNamedSecurityInfoExA | GetNamedSecurityInfoExW |
GetNamedSecurityInfoW | GetNumberOfEventLogRecords |
GetOldestEventLogRecord | GetOverlappedAccessResults |
GetPrivateObjectSecurity | GetSecurityDescriptorControl |
GetSecurityDescriptorDacl | GetSecurityDescriptorGroup |
GetSecurityDescriptorLength | GetSecurityDescriptorOwner |
GetSecurityDescriptorRMControl | GetSecurityDescriptorSacl |
GetSecurityInfo | GetSecurityInfoExA |
GetSecurityInfoExW | GetServiceDisplayNameA |
GetServiceDisplayNameW | GetServiceKeyNameA |
GetServiceKeyNameW | GetSidIdentifierAuthority |
GetSidLengthRequired | GetSidSubAuthority |
GetSidSubAuthorityCount | GetThreadWaitChain |
GetTokenInformation | GetTraceEnableFlags |
GetTraceEnableLevel | GetTraceLoggerHandle |
GetTrusteeFormA | GetTrusteeFormW |
GetTrusteeNameA | GetTrusteeNameW |
GetTrusteeTypeA | GetTrusteeTypeW |
GetUserNameA | GetUserNameW |
GetWindowsAccountDomainSid | I_QueryTagInformation |
I_ScGetCurrentGroupStateW | I_ScIsSecurityProcess |
I_ScPnPGetServiceName | I_ScQueryServiceConfig |
I_ScSendPnPMessage | I_ScSendTSMessage |
I_ScSetServiceBitsA | I_ScSetServiceBitsW |
I_ScValidatePnPService | IdentifyCodeAuthzLevelW |
ImpersonateAnonymousToken | ImpersonateLoggedOnUser |
ImpersonateNamedPipeClient | ImpersonateSelf |
InitializeAcl | InitializeSecurityDescriptor |
InitializeSid | InitiateShutdownA |
InitiateShutdownW | InitiateSystemShutdownA |
InitiateSystemShutdownExA | InitiateSystemShutdownExW |
InitiateSystemShutdownW | InstallApplication |
IsTextUnicode | IsTokenRestricted |
IsTokenUntrusted | IsValidAcl |
IsValidRelativeSecurityDescriptor | IsValidSecurityDescriptor |
IsValidSid | IsWellKnownSid |
LockServiceDatabase | LogonUserA |
LogonUserExA | LogonUserExExW |
LogonUserExW | LogonUserW |
LookupAccountNameA | LookupAccountNameW |
LookupAccountSidA | LookupAccountSidW |
LookupPrivilegeDisplayNameA | LookupPrivilegeDisplayNameW |
LookupPrivilegeNameA | LookupPrivilegeNameW |
LookupPrivilegeValueA | LookupPrivilegeValueW |
LookupSecurityDescriptorPartsA | LookupSecurityDescriptorPartsW |
LsaAddAccountRights | LsaAddPrivilegesToAccount |
LsaClearAuditLog | LsaClose |
LsaCreateAccount | LsaCreateSecret |
LsaCreateTrustedDomain | LsaCreateTrustedDomainEx |
LsaDelete | LsaDeleteTrustedDomain |
LsaEnumerateAccountRights | LsaEnumerateAccounts |
LsaEnumerateAccountsWithUserRight | LsaEnumeratePrivileges |
LsaEnumeratePrivilegesOfAccount | LsaEnumerateTrustedDomains |
LsaEnumerateTrustedDomainsEx | LsaFreeMemory |
LsaGetQuotasForAccount | LsaGetRemoteUserName |
LsaGetSystemAccessAccount | LsaGetUserName |
LsaICLookupNames | LsaICLookupNamesWithCreds |
LsaICLookupSids | LsaICLookupSidsWithCreds |
LsaLookupNames | LsaLookupNames2 |
LsaLookupPrivilegeDisplayName | LsaLookupPrivilegeName |
LsaLookupPrivilegeValue | LsaLookupSids |
LsaManageSidNameMapping | LsaNtStatusToWinError |
LsaOpenAccount | LsaOpenPolicy |
LsaOpenPolicySce | LsaOpenSecret |
LsaOpenTrustedDomain | LsaOpenTrustedDomainByName |
LsaQueryDomainInformationPolicy | LsaQueryForestTrustInformation |
LsaQueryInfoTrustedDomain | LsaQueryInformationPolicy |
LsaQuerySecret | LsaQuerySecurityObject |
LsaQueryTrustedDomainInfo | LsaQueryTrustedDomainInfoByName |
LsaRemoveAccountRights | LsaRemovePrivilegesFromAccount |
LsaRetrievePrivateData | LsaSetDomainInformationPolicy |
LsaSetForestTrustInformation | LsaSetInformationPolicy |
LsaSetInformationTrustedDomain | LsaSetQuotasForAccount |
LsaSetSecret | LsaSetSecurityObject |
LsaSetSystemAccessAccount | LsaSetTrustedDomainInfoByName |
LsaSetTrustedDomainInformation | LsaStorePrivateData |
MD4Final | MD4Init |
MD4Update | MD5Final |
MD5Init | MD5Update |
MSChapSrvChangePassword | MSChapSrvChangePassword2 |
MakeAbsoluteSD | MakeAbsoluteSD2 |
MakeSelfRelativeSD | MapGenericMask |
NotifyBootConfigStatus | NotifyChangeEventLog |
NotifyServiceStatusChange | NotifyServiceStatusChangeA |
NotifyServiceStatusChangeW | ObjectCloseAuditAlarmA |
ObjectCloseAuditAlarmW | ObjectDeleteAuditAlarmA |
ObjectDeleteAuditAlarmW | ObjectOpenAuditAlarmA |
ObjectOpenAuditAlarmW | ObjectPrivilegeAuditAlarmA |
ObjectPrivilegeAuditAlarmW | OpenBackupEventLogA |
OpenBackupEventLogW | OpenEncryptedFileRawA |
OpenEncryptedFileRawW | OpenEventLogA |
OpenEventLogW | OpenProcessToken |
OpenSCManagerA | OpenSCManagerW |
OpenServiceA | OpenServiceW |
OpenThreadToken | OpenThreadWaitChainSession |
OpenTraceA | OpenTraceW |
PerfAddCounters | PerfCloseQueryHandle |
PerfCreateInstance | PerfDecrementULongCounterValue |
PerfDecrementULongLongCounterValue | PerfDeleteCounters |
PerfDeleteInstance | PerfEnumerateCounterSet |
PerfEnumerateCounterSetInstances | PerfIncrementULongCounterValue |
PerfIncrementULongLongCounterValue | PerfOpenQueryHandle |
PerfQueryCounterData | PerfQueryCounterInfo |
PerfQueryCounterSetRegistrationInfo | PerfQueryInstance |
PerfSetCounterRefValue | PerfSetCounterSetInfo |
PerfSetULongCounterValue | PerfSetULongLongCounterValue |
PerfStartProvider | PerfStartProviderEx |
PerfStopProvider | PrivilegeCheck |
PrivilegedServiceAuditAlarmA | PrivilegedServiceAuditAlarmW |
ProcessIdleTasks | ProcessIdleTasksW |
ProcessTrace | QueryAllTracesA |
QueryAllTracesW | QueryRecoveryAgentsOnEncryptedFile |
QuerySecurityAccessMask | QueryServiceConfig2A |
QueryServiceConfig2W | QueryServiceConfigA |
QueryServiceConfigW | QueryServiceLockStatusA |
QueryServiceLockStatusW | QueryServiceObjectSecurity |
QueryServiceStatus | QueryServiceStatusEx |
QueryTraceA | QueryTraceW |
QueryUsersOnEncryptedFile | ReadEncryptedFileRaw |
ReadEventLogA | ReadEventLogW |
RegCloseKey | RegConnectRegistryA |
RegConnectRegistryExA | RegConnectRegistryExW |
RegConnectRegistryW | RegCopyTreeA |
RegCopyTreeW | RegCreateKeyA |
RegCreateKeyExA | RegCreateKeyExW |
RegCreateKeyTransactedA | RegCreateKeyTransactedW |
RegCreateKeyW | RegDeleteKeyA |
RegDeleteKeyExA | RegDeleteKeyExW |
RegDeleteKeyTransactedA | RegDeleteKeyTransactedW |
RegDeleteKeyValueA | RegDeleteKeyValueW |
RegDeleteKeyW | RegDeleteTreeA |
RegDeleteTreeW | RegDeleteValueA |
RegDeleteValueW | RegDisablePredefinedCache |
RegDisablePredefinedCacheEx | RegDisableReflectionKey |
RegEnableReflectionKey | RegEnumKeyA |
RegEnumKeyExA | RegEnumKeyExW |
RegEnumKeyW | RegEnumValueA |
RegEnumValueW | RegFlushKey |
RegGetKeySecurity | RegGetValueA |
RegGetValueW | RegLoadAppKeyA |
RegLoadAppKeyW | RegLoadKeyA |
RegLoadKeyW | RegLoadMUIStringA |
RegLoadMUIStringW | RegNotifyChangeKeyValue |
RegOpenCurrentUser | RegOpenKeyA |
RegOpenKeyExA | RegOpenKeyExW |
RegOpenKeyTransactedA | RegOpenKeyTransactedW |
RegOpenKeyW | RegOpenUserClassesRoot |
RegOverridePredefKey | RegQueryInfoKeyA |
RegQueryInfoKeyW | RegQueryMultipleValuesA |
RegQueryMultipleValuesW | RegQueryReflectionKey |
RegQueryValueA | RegQueryValueExA |
RegQueryValueExW | RegQueryValueW |
RegRenameKey | RegReplaceKeyA |
RegReplaceKeyW | RegRestoreKeyA |
RegRestoreKeyW | RegSaveKeyA |
RegSaveKeyExA | RegSaveKeyExW |
RegSaveKeyW | RegSetKeySecurity |
RegSetKeyValueA | RegSetKeyValueW |
RegSetValueA | RegSetValueExA |
RegSetValueExW | RegSetValueW |
RegUnLoadKeyA | RegUnLoadKeyW |
RegisterEventSourceA | RegisterEventSourceW |
RegisterIdleTask | RegisterServiceCtrlHandlerA |
RegisterServiceCtrlHandlerExA | RegisterServiceCtrlHandlerExW |
RegisterServiceCtrlHandlerW | RegisterTraceGuidsA |
RegisterTraceGuidsW | RegisterWaitChainCOMCallback |
RemoveTraceCallback | RemoveUsersFromEncryptedFile |
ReportEventA | ReportEventW |
RevertToSelf | SaferCloseLevel |
SaferComputeTokenFromLevel | SaferCreateLevel |
SaferGetLevelInformation | SaferGetPolicyInformation |
SaferIdentifyLevel | SaferRecordEventLogEntry |
SaferSetLevelInformation | SaferSetPolicyInformation |
SaferiChangeRegistryScope | SaferiCompareTokenLevels |
SaferiIsDllAllowed | SaferiIsExecutableFileType |
SaferiPopulateDefaultsInRegistry | SaferiRecordEventLogEntry |
SaferiSearchMatchingHashRules | SetAclInformation |
SetEncryptedFileMetadata | SetEntriesInAccessListA |
SetEntriesInAccessListW | SetEntriesInAclA |
SetEntriesInAclW | SetEntriesInAuditListA |
SetEntriesInAuditListW | SetFileSecurityA |
SetFileSecurityW | SetInformationCodeAuthzLevelW |
SetInformationCodeAuthzPolicyW | SetKernelObjectSecurity |
SetNamedSecurityInfoA | SetNamedSecurityInfoExA |
SetNamedSecurityInfoExW | SetNamedSecurityInfoW |
SetPrivateObjectSecurity | SetPrivateObjectSecurityEx |
SetSecurityAccessMask | SetSecurityDescriptorControl |
SetSecurityDescriptorDacl | SetSecurityDescriptorGroup |
SetSecurityDescriptorOwner | SetSecurityDescriptorRMControl |
SetSecurityDescriptorSacl | SetSecurityInfo |
SetSecurityInfoExA | SetSecurityInfoExW |
SetServiceBits | SetServiceObjectSecurity |
SetServiceStatus | SetThreadToken |
SetTokenInformation | SetTraceCallback |
SetUserFileEncryptionKey | SetUserFileEncryptionKeyEx |
StartServiceA | StartServiceCtrlDispatcherA |
StartServiceCtrlDispatcherW | StartServiceW |
StartTraceA | StartTraceW |
StopTraceA | StopTraceW |
SystemFunction001 | SystemFunction002 |
SystemFunction003 | SystemFunction004 |
SystemFunction005 | SystemFunction006 |
SystemFunction007 | SystemFunction008 |
SystemFunction009 | SystemFunction010 |
SystemFunction011 | SystemFunction012 |
SystemFunction013 | SystemFunction014 |
SystemFunction015 | SystemFunction016 |
SystemFunction017 | SystemFunction018 |
SystemFunction019 | SystemFunction020 |
SystemFunction021 | SystemFunction022 |
SystemFunction023 | SystemFunction024 |
SystemFunction025 | SystemFunction026 |
SystemFunction027 | SystemFunction028 |
SystemFunction029 | SystemFunction030 |
SystemFunction031 | SystemFunction032 |
SystemFunction033 | SystemFunction034 |
SystemFunction035 | SystemFunction036 |
SystemFunction040 | SystemFunction041 |
TraceEvent | TraceEventInstance |
TraceMessage | TraceMessageVa |
TraceSetInformation | TreeResetNamedSecurityInfoA |
TreeResetNamedSecurityInfoW | TreeSetNamedSecurityInfoA |
TreeSetNamedSecurityInfoW | TrusteeAccessToObjectA |
TrusteeAccessToObjectW | UninstallApplication |
UnlockServiceDatabase | UnregisterIdleTask |
UnregisterTraceGuids | UpdateTraceA |
UpdateTraceW | UsePinForEncryptedFilesA |
UsePinForEncryptedFilesW | WmiCloseBlock |
WmiDevInstToInstanceNameA | WmiDevInstToInstanceNameW |
WmiEnumerateGuids | WmiExecuteMethodA |
WmiExecuteMethodW | WmiFileHandleToInstanceNameA |
WmiFileHandleToInstanceNameW | WmiFreeBuffer |
WmiMofEnumerateResourcesA | WmiMofEnumerateResourcesW |
WmiNotificationRegistrationA | WmiNotificationRegistrationW |
WmiOpenBlock | WmiQueryAllDataA |
WmiQueryAllDataMultipleA | WmiQueryAllDataMultipleW |
WmiQueryAllDataW | WmiQueryGuidInformation |
WmiQuerySingleInstanceA | WmiQuerySingleInstanceMultipleA |
WmiQuerySingleInstanceMultipleW | WmiQuerySingleInstanceW |
WmiReceiveNotificationsA | WmiReceiveNotificationsW |
WmiSetSingleInstanceA | WmiSetSingleInstanceW |
WmiSetSingleItemA | WmiSetSingleItemW |
WriteEncryptedFileRaw |
Imported Functions List
The following functions are imported by this dll:- msvcrt.dll:
_errno _except_handler4_common _ftol2 _strcmpi _ultow _vsnprintf _vsnwprintf _wcsicmp _wcsnicmp _wcstoui64 isalnum isspace iswctype mbstowcs memcpy memmove memset strchr strrchr strstr swprintf_s swscanf_s tolower wcscat_s wcschr wcscpy_s wcsncmp wcsncpy_s wcsrchr wcsstr wcstok wcstombs wcstoul - ntdll.dll:
DbgPrint EtwDeliverDataBlock EtwEnumerateProcessRegGuids EtwEventRegister EtwEventUnregister EtwEventWrite EtwEventWriteEx EtwLogTraceEvent EtwProcessPrivateLoggerRequest EtwSendNotification EtwpGetCpuSpeed LdrGetProcedureAddress LdrLoadDll LdrUnloadDll NlsMbCodePageTag NtAlpcQueryInformation NtCancelIoFile NtClearEvent NtClose NtCompareTokens NtCreateEvent NtCreateFile NtCreateKey NtCreateKeyTransacted NtDelayExecution NtDeleteKey NtDeviceIoControlFile NtDuplicateObject NtDuplicateToken NtEnumerateKey NtLoadKeyEx NtOpenFile NtOpenKey NtOpenKeyEx NtOpenKeyTransacted NtOpenKeyTransactedEx NtOpenProcessToken NtOpenSymbolicLinkObject NtOpenThreadToken NtPowerInformation NtQueryInformationFile NtQueryInformationProcess NtQueryInformationThread NtQueryInformationToken NtQueryKey NtQueryMultipleValueKey NtQueryMutant NtQueryObject NtQueryPerformanceCounter NtQuerySecurityObject NtQuerySymbolicLinkObject NtQuerySystemInformation NtQuerySystemInformation NtQuerySystemTime NtQueryValueKey NtQueryVolumeInformationFile NtReadFile NtRenameKey NtReplaceKey NtSaveKey NtSaveMergedKeys NtSetEvent NtSetInformationThread NtSetInformationToken NtSetSystemInformation NtSetValueKey NtTerminateThread NtTraceControl NtTraceEvent NtWaitForMultipleObjects NtWaitForSingleObject NtWriteFile RtlAbsoluteToSelfRelativeSD RtlAcquireSRWLockExclusive RtlAcquireSRWLockShared RtlAddAccessAllowedAce RtlAddAccessAllowedAceEx RtlAddAccessAllowedObjectAce RtlAddAccessDeniedAceEx RtlAddAccessDeniedObjectAce RtlAddAce RtlAddAuditAccessAceEx RtlAddAuditAccessObjectAce RtlAdjustPrivilege RtlAllocateAndInitializeSid RtlAllocateHandle RtlAllocateHeap RtlAnsiCharToUnicodeChar RtlAnsiStringToUnicodeSize RtlAnsiStringToUnicodeString RtlAppendUnicodeStringToString RtlAppendUnicodeToString RtlCompareMemory RtlCompareUnicodeString RtlConvertSidToUnicodeString RtlCopySid RtlCopyString RtlCopyUnicodeString RtlCreateAcl RtlCreateQueryDebugBuffer RtlCreateSecurityDescriptor RtlCreateUnicodeString RtlCreateUnicodeStringFromAsciiz RtlDeleteCriticalSection RtlDeleteElementGenericTable RtlDestroyHandleTable RtlDestroyQueryDebugBuffer RtlDetermineDosPathNameType_U RtlDllShutdownInProgress RtlDosPathNameToNtPathName_U RtlDosPathNameToRelativeNtPathName_U RtlDuplicateUnicodeString RtlEnterCriticalSection RtlEnumerateGenericTableWithoutSplaying RtlEqualSid RtlEqualUnicodeString RtlExitUserThread RtlExpandEnvironmentStrings_U RtlFirstFreeAce RtlFormatCurrentUserKeyPath RtlFreeAnsiString RtlFreeAnsiString RtlFreeHandle RtlFreeHeap RtlFreeSid RtlGUIDFromString RtlGetControlSecurityDescriptor RtlGetCurrentTransaction RtlGetDaclSecurityDescriptor RtlGetFullPathName_U RtlGetGroupSecurityDescriptor RtlGetLastNtStatus RtlGetNtProductType RtlGetOwnerSecurityDescriptor RtlGetSaclSecurityDescriptor RtlGetThreadPreferredUILanguages RtlGetVersion RtlImageNtHeader RtlImpersonateSelf RtlInitAnsiString RtlInitAnsiStringEx RtlInitUnicodeString RtlInitUnicodeStringEx RtlInitializeBitMap RtlInitializeConditionVariable RtlInitializeCriticalSection RtlInitializeGenericTable RtlInitializeHandleTable RtlInitializeSid RtlInsertElementGenericTable RtlIntegerToUnicodeString RtlInterlockedClearBitRun RtlIpv4AddressToStringW RtlIpv6AddressToStringW RtlIsGenericTableEmpty RtlIsTextUnicode RtlIsValidIndexHandle RtlLeaveCriticalSection RtlLengthSecurityDescriptor RtlLengthSid RtlLookupElementGenericTable RtlMakeSelfRelativeSD RtlMultiByteToUnicodeN RtlNtStatusToDosError RtlNtStatusToDosErrorNoTeb RtlNumberGenericTableElements RtlOemStringToUnicodeString RtlOpenCurrentUser RtlPrefixUnicodeString RtlQueryHeapInformation RtlQueryPerformanceFrequency RtlQueryProcessDebugInformation RtlQueryRegistryValues RtlQueryTimeZoneInformation RtlRandom RtlReAllocateHeap RtlRegisterThreadWithCsrss RtlReleaseRelativeName RtlReleaseSRWLockExclusive RtlReleaseSRWLockShared RtlRestoreLastWin32Error RtlRunOnceBeginInitialize RtlRunOnceExecuteOnce RtlSetDaclSecurityDescriptor RtlSetGroupSecurityDescriptor RtlSetOwnerSecurityDescriptor RtlSetSaclSecurityDescriptor RtlStringFromGUID RtlSubAuthorityCountSid RtlSubAuthoritySid RtlTimeToSecondsSince1970 RtlUnicodeStringToAnsiSize RtlUnicodeStringToAnsiString RtlUnicodeStringToInteger RtlUnicodeToMultiByteN RtlUnicodeToMultiByteSize RtlUpcaseUnicodeChar RtlValidAcl RtlValidRelativeSecurityDescriptor RtlValidSecurityDescriptor RtlValidSid - KERNELBASE.dll:
AreFileApisANSI EnumUILanguagesW GetSystemDefaultUILanguage GetUserDefaultUILanguage - API-MS-WIN-Service-Core-L1-1-0.dll:
sechost!RegisterServiceCtrlHandlerExW sechost!SetServiceStatus sechost!StartServiceCtrlDispatcherW - API-MS-WIN-Service-winsvc-L1-1-0.dll:
sechost!ChangeServiceConfig2A sechost!ChangeServiceConfigA sechost!ControlService sechost!ControlServiceExA sechost!CreateServiceA sechost!I_ScRpcBindA sechost!I_ScRpcBindW sechost!NotifyServiceStatusChangeA sechost!OpenSCManagerA sechost!OpenServiceA sechost!QueryServiceConfig2A sechost!QueryServiceConfigA sechost!QueryServiceStatus sechost!RegisterServiceCtrlHandlerA sechost!RegisterServiceCtrlHandlerExA sechost!RegisterServiceCtrlHandlerW sechost!StartServiceA sechost!StartServiceCtrlDispatcherA - API-MS-WIN-Service-Management-L1-1-0.dll:
sechost!CloseServiceHandle sechost!ControlServiceExW sechost!CreateServiceW sechost!DeleteService sechost!OpenSCManagerW sechost!OpenServiceW sechost!StartServiceW - API-MS-WIN-Service-Management-L2-1-0.dll:
sechost!ChangeServiceConfig2W sechost!ChangeServiceConfigW sechost!NotifyServiceStatusChange sechost!QueryServiceConfig2W sechost!QueryServiceConfigW sechost!QueryServiceObjectSecurity sechost!QueryServiceStatusEx sechost!SetServiceObjectSecurity - API-MS-Win-Core-LocalRegistry-L1-1-0.dll:
kernel32!RegCloseKey kernel32!RegCreateKeyExA kernel32!RegCreateKeyExW kernel32!RegDeleteKeyExA kernel32!RegDeleteKeyExW kernel32!RegDeleteTreeA kernel32!RegDeleteTreeW kernel32!RegDeleteValueA kernel32!RegDeleteValueW kernel32!RegDisablePredefinedCacheEx kernel32!RegEnumKeyExA kernel32!RegEnumKeyExW kernel32!RegEnumValueA kernel32!RegEnumValueW kernel32!RegFlushKey kernel32!RegGetKeySecurity kernel32!RegGetValueA kernel32!RegGetValueW kernel32!RegLoadKeyA kernel32!RegLoadKeyW kernel32!RegLoadMUIStringA kernel32!RegLoadMUIStringW kernel32!RegNotifyChangeKeyValue kernel32!RegOpenCurrentUser kernel32!RegOpenKeyExA kernel32!RegOpenKeyExW kernel32!RegOpenUserClassesRoot kernel32!RegQueryInfoKeyA kernel32!RegQueryInfoKeyW kernel32!RegQueryValueExA kernel32!RegQueryValueExW kernel32!RegRestoreKeyA kernel32!RegRestoreKeyW kernel32!RegSaveKeyExA kernel32!RegSaveKeyExW kernel32!RegSetKeySecurity kernel32!RegSetValueExA kernel32!RegSetValueExW kernel32!RegUnLoadKeyA kernel32!RegUnLoadKeyW - API-MS-Win-Core-NamedPipe-L1-1-0.dll:
KernelBase!ImpersonateNamedPipeClient - API-MS-Win-Core-ProcessThreads-L1-1-0.dll:
KernelBase!OpenProcessToken KernelBase!OpenThreadToken KernelBase!SetThreadToken kernel32!CreateProcessAsUserW kernel32!CreateThread kernel32!GetCurrentProcess kernel32!GetCurrentProcessId kernel32!GetCurrentThread kernel32!GetCurrentThreadId kernel32!GetPriorityClass kernel32!GetProcessId kernel32!OpenThread kernel32!TerminateProcess - API-MS-Win-Security-Base-L1-1-0.dll:
KernelBase!AccessCheck KernelBase!AccessCheckAndAuditAlarmW KernelBase!AccessCheckByType KernelBase!AccessCheckByTypeAndAuditAlarmW KernelBase!AccessCheckByTypeResultList KernelBase!AccessCheckByTypeResultListAndAuditAlarmByHandleW KernelBase!AccessCheckByTypeResultListAndAuditAlarmW KernelBase!AddAccessAllowedAce KernelBase!AddAccessAllowedAceEx KernelBase!AddAccessAllowedObjectAce KernelBase!AddAccessDeniedAce KernelBase!AddAccessDeniedAceEx KernelBase!AddAccessDeniedObjectAce KernelBase!AddAce KernelBase!AddAuditAccessAce KernelBase!AddAuditAccessAceEx KernelBase!AddAuditAccessObjectAce KernelBase!AdjustTokenGroups KernelBase!AdjustTokenPrivileges KernelBase!AllocateAndInitializeSid KernelBase!AllocateLocallyUniqueId KernelBase!AreAllAccessesGranted KernelBase!AreAnyAccessesGranted KernelBase!CheckTokenMembership KernelBase!ConvertToAutoInheritPrivateObjectSecurity KernelBase!CopySid KernelBase!CreatePrivateObjectSecurity KernelBase!CreatePrivateObjectSecurityEx KernelBase!CreatePrivateObjectSecurityWithMultipleInheritance KernelBase!CreateRestrictedToken KernelBase!CreateWellKnownSid KernelBase!DeleteAce KernelBase!DestroyPrivateObjectSecurity KernelBase!DuplicateToken KernelBase!DuplicateTokenEx KernelBase!EqualDomainSid KernelBase!EqualPrefixSid KernelBase!EqualSid KernelBase!FindFirstFreeAce KernelBase!FreeSid KernelBase!GetAce KernelBase!GetAclInformation KernelBase!GetFileSecurityW KernelBase!GetKernelObjectSecurity KernelBase!GetLengthSid KernelBase!GetPrivateObjectSecurity KernelBase!GetSecurityDescriptorControl KernelBase!GetSecurityDescriptorDacl KernelBase!GetSecurityDescriptorGroup KernelBase!GetSecurityDescriptorLength KernelBase!GetSecurityDescriptorOwner KernelBase!GetSecurityDescriptorRMControl KernelBase!GetSecurityDescriptorSacl KernelBase!GetSidIdentifierAuthority KernelBase!GetSidLengthRequired KernelBase!GetSidSubAuthority KernelBase!GetSidSubAuthorityCount KernelBase!GetTokenInformation KernelBase!GetWindowsAccountDomainSid KernelBase!ImpersonateAnonymousToken KernelBase!ImpersonateLoggedOnUser KernelBase!ImpersonateSelf KernelBase!InitializeAcl KernelBase!InitializeSecurityDescriptor KernelBase!InitializeSid KernelBase!IsTokenRestricted KernelBase!IsValidAcl KernelBase!IsValidRelativeSecurityDescriptor KernelBase!IsValidSecurityDescriptor KernelBase!IsValidSid KernelBase!IsWellKnownSid KernelBase!MakeAbsoluteSD KernelBase!MakeAbsoluteSD2 KernelBase!MakeSelfRelativeSD KernelBase!MapGenericMask KernelBase!ObjectCloseAuditAlarmW KernelBase!ObjectDeleteAuditAlarmW KernelBase!ObjectOpenAuditAlarmW KernelBase!ObjectPrivilegeAuditAlarmW KernelBase!PrivilegeCheck KernelBase!PrivilegedServiceAuditAlarmW KernelBase!QuerySecurityAccessMask KernelBase!RevertToSelf KernelBase!SetAclInformation KernelBase!SetFileSecurityW KernelBase!SetKernelObjectSecurity KernelBase!SetPrivateObjectSecurity KernelBase!SetPrivateObjectSecurityEx KernelBase!SetSecurityAccessMask KernelBase!SetSecurityDescriptorControl KernelBase!SetSecurityDescriptorDacl KernelBase!SetSecurityDescriptorGroup KernelBase!SetSecurityDescriptorOwner KernelBase!SetSecurityDescriptorRMControl KernelBase!SetSecurityDescriptorSacl KernelBase!SetTokenInformation - KERNEL32.dll:
CloseHandle CompareFileTime CopyFileW CreateEventW CreateFileMappingW CreateFileW CreateMutexA CreateMutexW CreateProcessInternalA DelayLoadFailureHook DeleteFileW DeviceIoControl DosDateTimeToFileTime DuplicateHandle ExpandEnvironmentStringsA ExpandEnvironmentStringsW FileTimeToDosDateTime FindClose FindFirstFileExW FindNextFileW FindResourceExW FormatMessageW FreeLibrary FreeLibraryAndExitThread GetActiveProcessorCount GetCommandLineW GetComputerNameA GetComputerNameExW GetComputerNameW GetDiskFreeSpaceExW GetDriveTypeW GetFileAttributesExW GetFileAttributesW GetFileMUIPath GetFileSize GetFileSizeEx GetFileTime GetFullPathNameA GetFullPathNameW GetLastError GetLocalTime GetLogicalDriveStringsW GetLongPathNameW GetModuleFileNameW GetModuleHandleExW GetModuleHandleW GetOverlappedResult GetPrivateProfileIntW GetProcAddress GetProcessHeap GetSystemDirectoryW GetSystemInfo GetSystemTime GetSystemTimeAsFileTime GetSystemWindowsDirectoryW GetThreadUILanguage GetTickCount GetVolumeInformationW GetVolumePathNameW GlobalMemoryStatusEx HeapFree InterlockedCompareExchange InterlockedDecrement InterlockedExchange InterlockedIncrement IsWow64Process LoadLibraryA LoadLibraryExA LoadLibraryExW LoadLibraryW LoadResource LocalAlloc LocalFree LocalLock LocalReAlloc LocalUnlock LockResource MapViewOfFile MoveFileW MultiByteToWideChar OpenProcess OutputDebugStringW QueryPerformanceCounter ReadFile ReadProcessMemory RegKrnGetGlobalState RegKrnInitialize ReleaseMutex ResetEvent SearchPathW SetErrorMode SetEvent SetFileInformationByHandle SetFilePointer SetLastError SetUnhandledExceptionFilter SizeofResource Sleep SleepEx UnhandledExceptionFilter UnmapViewOfFile VirtualAllocEx VirtualFree VirtualFreeEx WaitForSingleObject WideCharToMultiByte Wow64DisableWow64FsRedirection Wow64RevertWow64FsRedirection WriteFile lstrcmpW lstrcmpi lstrcmpiW lstrlenW ntdll!RtlAllocateHeap ntdll!RtlDecodePointer ntdll!RtlDeleteCriticalSection ntdll!RtlEncodePointer ntdll!RtlEnterCriticalSection ntdll!RtlInitializeCriticalSection ntdll!RtlLeaveCriticalSection ntdll!RtlReAllocateHeap ntdll!RtlSizeHeap - RPCRT4.dll:
I_RpcExceptionFilter I_RpcMapWin32Status I_RpcSNCHOption NdrClientCall2 RpcBindingBind RpcBindingCreateW RpcBindingFree RpcBindingFromStringBindingW RpcBindingSetAuthInfoA RpcBindingSetAuthInfoExA RpcBindingSetAuthInfoExW RpcBindingSetAuthInfoW RpcEpResolveBinding RpcExceptionFilter RpcRaiseException RpcSsDestroyClientContext RpcStringBindingComposeW RpcStringFreeW UuidCreate UuidFromStringW UuidToStringW