2bd581a222905fa9d6824eb85e99fdc5

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2102-Jun-06 10:03:34
Detected languages English - United States
Debug artifacts wkernel32.pdb
CompanyName Microsoft Corporation
FileDescription Windows NT BASE API Client DLL
FileVersion 10.0.19041.1706 (WinBuild.160101.0800)
InternalName kernel32
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename kernel32
ProductName Microsoft® Windows® Operating System
ProductVersion 10.0.19041.1706

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: May have dropper capabilities:
  • CurrentControlSet\Services
Contains domain names:
  • http://schemas.microsoft.com
  • http://schemas.microsoft.com/SMI/2005/WindowsSettings
  • http://schemas.microsoft.com/SMI/2011/WindowsSettings
  • http://schemas.microsoft.com/SMI/2013/WindowsSettings
  • http://schemas.microsoft.com/SMI/2014/WindowsSettings
  • http://schemas.microsoft.com/SMI/2016/WindowsSettings
  • http://schemas.microsoft.com/SMI/2017/WindowsSettings
  • http://schemas.microsoft.com/SMI/2019/WindowsSettings
  • http://schemas.microsoft.com/SMI/2020/WindowsSettings
  • microsoft.com
  • schemas.microsoft.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Suspicious The PE is possibly packed. Unusual section name found: .didat
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LdrLoadDll
  • LoadLibraryExA
  • GetProcAddress
  • LoadLibraryExW
  • LoadLibraryA
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • DbgPrint
  • NtQueryInformationProcess
  • NtQuerySystemInformation
  • ZwQuerySystemInformation
  • SwitchToThread
  • CheckRemoteDebuggerPresent
Code injection capabilities:
  • CreateRemoteThreadEx
  • CreateRemoteThread
  • OpenProcess
  • WriteProcessMemory
  • VirtualAllocEx
  • VirtualAlloc
  • VirtualAllocExNuma
Code injection capabilities (process hollowing):
  • ResumeThread
  • SetThreadContext
  • WriteProcessMemory
  • Wow64SetThreadContext
Code injection capabilities (mapping injection):
  • CreateRemoteThreadEx
  • CreateRemoteThread
  • CreateFileMappingNumaW
  • MapViewOfFile
  • MapViewOfFileEx
  • CreateFileMappingW
Can access the registry:
  • RegUnLoadKeyW
  • RegLoadAppKeyW
  • RegDeleteValueW
  • RegEnumKeyExA
  • RegEnumKeyExW
  • RegRestoreKeyW
  • RegEnumValueA
  • RegEnumValueW
  • RegSaveKeyExA
  • RegDeleteKeyExA
  • RegDeleteValueA
  • RegCreateKeyExA
  • RegFlushKey
  • RegGetKeySecurity
  • RegGetValueA
  • RegLoadKeyA
  • RegLoadKeyW
  • RegUnLoadKeyA
  • RegCloseKey
  • RegGetValueW
  • RegSetValueExW
  • RegSetValueExA
  • RegSetKeySecurity
  • RegCreateKeyExW
  • RegOpenKeyExW
  • RegDeleteKeyExW
  • RegNotifyChangeKeyValue
  • RegOpenKeyExA
  • RegQueryInfoKeyA
  • RegQueryInfoKeyW
  • RegQueryValueExA
  • RegQueryValueExW
  • RegRestoreKeyA
  • RegSaveKeyExW
Possibly launches other programs:
  • CreateProcessInternalA
  • CreateProcessInternalW
  • CreateProcessAsUserW
  • CreateProcessAsUserA
  • CreateProcessA
  • CreateProcessW
Uses Windows's Native API:
  • NtTerminateProcess
  • NtMapUserPhysicalPagesScatter
  • NtQueryInstallUILanguage
  • NtQueryLicenseValue
  • NtCreateFile
  • NtWow64ReadVirtualMemory64
  • NtMapViewOfSection
  • NtCreateSection
  • NtUnmapViewOfSection
  • NtQueryEvent
  • NtRaiseHardError
  • NtQueryVolumeInformationFile
  • NtReplacePartitionUnit
  • NtQueryValueKey
  • NtQueryInformationToken
  • NtOpenProcessToken
  • NtSetInformationThread
  • NtOpenThreadToken
  • NtOpenKey
  • NtIsSystemResumeAutomatic
  • NtInitiatePowerAction
  • NtWaitForSingleObject
  • NtCreateEvent
  • NtFsControlFile
  • NtOpenFile
  • NtClose
  • NtQueryInformationFile
  • NtSetInformationFile
  • NtSetInformationDebugObject
  • NtSetSystemInformation
  • NtQueryInformationProcess
  • NtQuerySystemInformation
  • NtEnumerateKey
  • NtDeleteValueKey
  • NtSetValueKey
  • NtFindAtom
  • NtQueryInformationAtom
  • NtAddAtomEx
  • NtDeleteAtom
  • NtFlushKey
  • NtCreateKey
  • NtCreateJobSet
  • NtSetInformationJobObject
  • NtQueryInformationJobObject
  • NtCreateJobObject
  • NtAssignProcessToJobObject
  • NtTerminateJobObject
  • NtOpenJobObject
  • NtSetEaFile
  • NtSetSecurityObject
  • NtQueryEaFile
  • NtQuerySecurityObject
  • NtSetInformationProcess
  • NtQuerySection
  • NtFreeVirtualMemory
  • NtWriteFile
  • NtEnumerateValueKey
  • NtUnlockFile
  • NtReadFile
  • NtLockFile
  • NtAllocateVirtualMemory
  • NtQueryVirtualMemory
  • NtProtectVirtualMemory
  • NtCreateMailslotFile
  • NtQueryDirectoryFile
  • NtQueryWnfStateData
  • NtPowerInformation
  • NtGetDevicePowerState
  • NtSetThreadExecutionState
  • NtSetSystemEnvironmentValueEx
  • NtQuerySystemEnvironmentValueEx
  • NtSetVolumeInformationFile
  • NtDeviceIoControlFile
  • NtQueryInformationThread
  • NtQueryAttributesFile
  • NtQueryFullAttributesFile
  • NtSetTimerResolution
  • NtQueryTimerResolution
  • NtWaitForMultipleObjects
  • NtClearEvent
  • NtApphelpCacheControl
  • ZwClose
  • ZwOpenFile
  • ZwOpenKey
  • ZwEnumerateKey
  • ZwQueryValueKey
  • ZwCreateFile
  • ZwQueryInformationFile
  • ZwCreateSection
  • ZwQueryDirectoryFile
  • ZwQuerySystemInformation
  • ZwUnmapViewOfSection
  • ZwMapViewOfSection
Can create temporary files:
  • CreateFileW
  • CreateFileA
  • GetTempPathW
  • GetTempPathA
Memory manipulation functions often used by packers:
  • VirtualProtectEx
  • VirtualAllocEx
  • VirtualProtect
  • VirtualAlloc
Functions related to the privilege level:
  • OpenProcessToken
  • DuplicateToken
Enumerates local disk drives:
  • GetDriveTypeW
  • GetDriveTypeA
  • GetVolumeInformationW
  • GetVolumeInformationByHandleW
  • GetLogicalDriveStringsW
  • GetVolumeInformationA
Manipulates other processes:
  • OpenProcess
  • ReadProcessMemory
  • WriteProcessMemory
Info The PE is digitally signed. Signer: Microsoft Windows
Issuer: Microsoft Windows Production PCA 2011
Safe VirusTotal score: 0/67 (Scanned on 2022-05-10 18:51:27) All the AVs think this file is safe.

Hashes

MD5 2bd581a222905fa9d6824eb85e99fdc5
SHA1 f0b45ccf1a3eb51793790e7494c1bb4b915f7d45
SHA256 23fe8b1f3e7ed9a1b62d21bfa18f890c50e26b5e9d73352b19fa0d10d954e185
SHA3 db97fe989a6f90f302fd3903f69db102777b29b9bb52c47e4dc121f6755236bd
SSDeep 12288:1ZzAIpUQVSFjM0HK7Slw6hXyBNCal92v+3kM86k4J1B/Sas:1JAyUQVSZ1HK7Sl9XyBNCalEW3Fk4J1u
Imports Hash 144bfde480cb4e18c0e113fb4cc87137

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 6
TimeDateStamp 2102-Jun-06 10:03:34
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 14.0
SizeOfCode 0x65000
SizeOfInitializedData 0x32000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0001F640 (Section: .text)
BaseOfCode 0x10000
BaseOfData 0x80000
ImageBase 0x6b800000
SectionAlignment 0x10000
FileAlignment 0x1000
OperatingSystemVersion A.0
ImageVersion A.0
SubsystemVersion A.0
Win32VersionValue 0
SizeOfImage 0xf0000
SizeOfHeaders 0x1000
Checksum 0xa567c
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x40000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 4a73fe9bad0c22175d030b4d1cee81bd
SHA1 649f8963513a318542ef231c3e43f32dab9728b3
SHA256 c6b5bdcd9042c8d31e30709848802c373add99c80725e685ca90d077814e5083
SHA3 9eb13882aa61da3dca280290d38e8b59a514eb0c959d45d7ae7d940ceb2e1e85
VirtualSize 0x64152
VirtualAddress 0x10000
SizeOfRawData 0x65000
PointerToRawData 0x1000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.52

.rdata

MD5 041a4c2e6af3e0609f7f0b2133bd5785
SHA1 6246f42dce06ca9184c125bcefd20c66893f4ad3
SHA256 11d3bf7b35ecab85e5c20b77482c3c846a941c1d9503137f42336bcd0fc861b3
SHA3 13644236f52748c88915a6f83e4d17dd6d12032b1148965a65c425660696ee89
VirtualSize 0x29fb0
VirtualAddress 0x80000
SizeOfRawData 0x2a000
PointerToRawData 0x66000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.8764

.data

MD5 01c4ea8e52c3dbdcea4d269a188076e2
SHA1 64ed0af5f43431ffd4b35d8b0de4350a5d3fb432
SHA256 65e0f4b1d1c89fb49be68ab50afcb14c1a234e47c70196fbde9ce11881b87260
SHA3 54730adb01556d201bef71188ddc70abe7ac6d8b51fd95b1eb9594e427669d96
VirtualSize 0xc78
VirtualAddress 0xb0000
SizeOfRawData 0x1000
PointerToRawData 0x90000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.09858

.didat

MD5 d3699921ac19539d55631e3b8e6c132f
SHA1 dc61d3bc13ae9f76688a25b8ff48e49a7dd25ede
SHA256 55a0c1ccdead1c624421a16a208e8ba028b6305a04c8219f7a6da1e0dbf9e80e
SHA3 b914c1ab6152ae3b6d822a81e06ca6290e2f6e5f258954819c98a94a376a7725
VirtualSize 0x34
VirtualAddress 0xc0000
SizeOfRawData 0x1000
PointerToRawData 0x91000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.117629

.rsrc

MD5 a3c0fb080ec45df66fcb3ca095fc604c
SHA1 d4179b2faab4274571311df45ff1f6fb2d790de8
SHA256 17cd175a7c5e122f512403758bc4d198bee71a20d1c2b60e338155b1f1b6f127
SHA3 8fd8ceeffd335bc373dc4ff95a08fa2170485f5cdc145f76020b5e5fbcf59a2d
VirtualSize 0x520
VirtualAddress 0xd0000
SizeOfRawData 0x1000
PointerToRawData 0x92000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.3218

.reloc

MD5 198ce4588f510d07cb74a3cb57c0d539
SHA1 e8b7cd2570f62e7127f78dd6aba52e918fd60ac0
SHA256 dfac171d9247d735b2ed5d7b4ccbdc43ddc99ec79c8280654c843033ea919c74
SHA3 b92ad3ed600793880ab61a2bcf335733c2090b3c3347171ef9f98d56dee64308
VirtualSize 0x4824
VirtualAddress 0xe0000
SizeOfRawData 0x5000
PointerToRawData 0x93000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.48004

Imports

api-ms-win-core-rtlsupport-l1-1-0.dll RtlCaptureStackBackTrace
RtlUnwind
RtlCaptureContext
api-ms-win-core-rtlsupport-l1-2-0.dll RtlPcToFileHeader
ntdll.dll DbgPrint
_aullshr
RtlUnhandledExceptionFilter
NtTerminateProcess
wcsncmp
wcsncpy
LdrFindResourceEx_U
RtlReadThreadProfilingData
RtlQueryThreadProfiling
RtlDisableThreadProfiling
RtlNtStatusToDosErrorNoTeb
RtlEnableThreadProfiling
NtMapUserPhysicalPagesScatter
RtlDecodeSystemPointer
bsearch
RtlComputeImportTableHash
RtlFindActivationContextSectionGuid
RtlQueryActivationContextApplicationSettings
RtlSubAuthorityCountSid
LdrResFindResourceDirectory
RtlSizeHeap
RtlpConvertCultureNamesToLCIDs
NtQueryInstallUILanguage
RtlExpandEnvironmentStrings_U
RtlPublishWnfStateData
NtQueryLicenseValue
_wtol
memmove_s
RtlGUIDFromString
memmove
wcsncpy_s
RtlGetDeviceFamilyInfoEnum
NtCreateFile
RtlEncodeSystemPointer
RtlQueryEnvironmentVariable_U
EtwEventEnabled
EtwEventRegister
EtwEventWrite
RtlHashUnicodeString
NtWow64ReadVirtualMemory64
EtwEventUnregister
RtlTimeFieldsToTime
RtlQueryInformationActivationContext
RtlSetThreadPreferredUILanguages
RtlMultiAppendUnicodeStringBuffer
swprintf_s
RtlImageNtHeaderEx
NtMapViewOfSection
NtCreateSection
RtlDosPathNameToNtPathName_U_WithStatus
RtlGetActiveActivationContext
RtlDeactivateActivationContext
RtlActivateActivationContext
RtlZombifyActivationContext
RtlReleaseActivationContext
RtlAddRefActivationContext
RtlCreateActivationContext
RtlGetLengthWithoutLastFullDosOrNtPathElement
RtlpApplyLengthFunction
RtlGetFullPathName_U
RtlDoesFileExists_U
RtlDetermineDosPathNameType_U
RtlpEnsureBufferSize
DbgPrintEx
NtUnmapViewOfSection
RtlQueryPackageClaims
tolower
atol
toupper
isdigit
RtlDestroyEnvironment
RtlCreateEnvironmentEx
RtlCreateEnvironment
NtQueryEvent
RtlCreateUnicodeString
NtRaiseHardError
RtlFreeAnsiString
RtlFreeOemString
RtlTimeToTimeFields
wcsrchr
_wcsnicmp
RtlUnicodeStringToOemString
NtQueryVolumeInformationFile
CsrFreeCaptureBuffer
CsrAllocateMessagePointer
CsrAllocateCaptureBuffer
CsrClientCallServer
RtlEqualUnicodeString
RtlUnicodeStringToAnsiString
RtlExitUserThread
RtlAddIntegrityLabelToBoundaryDescriptor
RtlQueryProtectedPolicy
NtReplacePartitionUnit
RtlCompareUnicodeString
RtlExitUserProcess
RtlInitUnicodeStringEx
RtlQueryPackageIdentity
EtwEventWriteNoRegistration
RtlWow64LogMessageInEventLogger
LdrUnloadDll
LdrGetProcedureAddress
LdrLoadDll
RtlAppendUnicodeToString
RtlAppendUnicodeStringToString
RtlFormatCurrentUserKeyPath
NtQueryValueKey
RtlEqualSid
RtlSubAuthoritySid
RtlInitializeSid
NtQueryInformationToken
NtOpenProcessToken
NtSetInformationThread
NtOpenThreadToken
RtlReleaseSRWLockExclusive
RtlQueryRegistryValuesEx
NtOpenKey
RtlAcquireSRWLockExclusive
RtlAnsiStringToUnicodeString
RtlxAnsiStringToUnicodeSize
RtlInitAnsiStringEx
NtIsSystemResumeAutomatic
NtInitiatePowerAction
RtlIsNameLegalDOS8Dot3
RtlGetCurrentProcessorNumberEx
NtWaitForSingleObject
NtCreateEvent
RtlSetSearchPathMode
LdrGetDllDirectory
RtlUnlockHeap
RtlGetUserInfoHeap
RtlLockHeap
RtlDeregisterSecureMemoryCacheCallback
RtlRegisterSecureMemoryCacheCallback
RtlCompactHeap
NtFsControlFile
NtOpenFile
NtClose
_wcsicmp
LdrAddRefDll
NtQueryInformationFile
NtSetInformationFile
wcscpy_s
RtlGetActiveConsoleId
RtlDeactivateActivationContextUnsafeFast
RtlActivateActivationContextUnsafeFast
RtlNtStatusToDosError
RtlFreeUnicodeString
NtSetInformationDebugObject
DbgUiGetThreadDebugObject
DbgUiIssueRemoteBreakin
NtSetSystemInformation
NtQueryInformationProcess
RtlSetCurrentTransaction
RtlGetCurrentTransaction
RtlSetLastWin32Error
LdrDisableThreadCalloutsForDll
RtlGetSuiteMask
LdrQueryImageFileExecutionOptions
RtlInitUnicodeString
_vsnwprintf
RtlSetUserCallbackExceptionFilter
RtlSetProtectedPolicy
LdrSetDllManifestProber
RtlSetThreadPoolStartFunc
RtlImageNtHeader
NtQuerySystemInformation
RtlFreeHeap
RtlSetDaclSecurityDescriptor
RtlSetGroupSecurityDescriptor
RtlSetOwnerSecurityDescriptor
RtlIntegerToUnicodeString
NtEnumerateKey
RtlpConvertLCIDsToCultureNames
RtlGetUILanguageInfo
_wcslwr
RtlUnicodeStringToInteger
RtlGetCurrentDirectory_U
RtlLCIDToCultureName
TpAllocTimer
TpAllocIoCompletion
TpAllocWork
TpCallbackMayRunLong
TpAllocCleanupGroup
TpSimpleTryPost
TpQueryPoolStackInformation
TpAllocPool
TpSetPoolMinThreads
RtlSetLastWin32ErrorAndNtStatusFromNtStatus
TpSetPoolStackInformation
TpAllocWait
RtlQueryEnvironmentVariable
RtlGetVersion
NtDeleteValueKey
NtSetValueKey
towlower
RtlGetCurrentServiceSessionId
CsrVerifyRegion
RtlCharToInteger
RtlInitAnsiString
RtlUpcaseUnicodeChar
RtlUnicodeToMultiByteSize
RtlDestroyAtomTable
NtFindAtom
NtQueryInformationAtom
RtlAddAtomToAtomTable
NtAddAtomEx
NtDeleteAtom
RtlCreateAtomTable
RtlDeleteAtomFromAtomTable
RtlLookupAtomInAtomTable
RtlQueryAtomInAtomTable
RtlDnsHostNameToComputerName
RtlPrefixString
NtFlushKey
_memicmp
RtlxUnicodeStringToAnsiSize
RtlEnterCriticalSection
wcschr
wcsstr
RtlLeaveCriticalSection
NtCreateKey
RtlCreateUnicodeStringFromAsciiz
wcscspn
NtCreateJobSet
RtlReleasePrivilege
NtSetInformationJobObject
NtQueryInformationJobObject
NtCreateJobObject
RtlAcquirePrivilege
NtAssignProcessToJobObject
NtTerminateJobObject
NtOpenJobObject
RtlLengthSecurityDescriptor
NtSetEaFile
NtSetSecurityObject
NtQueryEaFile
NtQuerySecurityObject
LdrQueryImageFileKeyOption
LdrOpenImageFileOptionsKey
RtlQueryElevationFlags
NtSetInformationProcess
RtlRaiseStatus
NtQuerySection
NtFreeVirtualMemory
NtWriteFile
NtEnumerateValueKey
RtlEqualString
RtlUnicodeToMultiByteN
strncpy_s
NtUnlockFile
RtlDosPathNameToNtPathName_U
NtReadFile
NtLockFile
RtlCopyUnicodeString
RtlIsTextUnicode
NtAllocateVirtualMemory
RtlGetLongestNtPathLength
RtlPrefixUnicodeString
RtlMultiByteToUnicodeN
RtlMultiByteToUnicodeSize
RtlDosPathNameToRelativeNtPathName_U
RtlReleaseRelativeName
RtlSetIoCompletionCallback
RtlDeregisterWait
RtlRegisterWait
RtlImageDirectoryEntryToData
NtQueryVirtualMemory
RtlCreateBoundaryDescriptor
NtProtectVirtualMemory
RtlGetThreadErrorMode
NtCreateMailslotFile
RtlExtendedLargeIntegerDivide
RtlDestroyQueryDebugBuffer
RtlQueryProcessDebugInformation
RtlCreateQueryDebugBuffer
NtQueryDirectoryFile
strcpy_s
RtlFindActivationContextSectionString
LdrSetDllDirectory
LdrFindResource_U
RtlSwitchedVVI
NtQueryWnfStateData
NtPowerInformation
NtGetDevicePowerState
NtSetThreadExecutionState
NtSetSystemEnvironmentValueEx
NtQuerySystemEnvironmentValueEx
RtlInitString
NtSetVolumeInformationFile
NtDeviceIoControlFile
NtQueryInformationThread
RtlIsValidHandle
RtlAllocateHandle
RtlReAllocateHeap
RtlFreeHandle
RtlSetUserValueHeap
RtlUnsubscribeWnfStateChangeNotification
RtlSubscribeWnfStateChangeNotification
RtlQueryWnfStateData
strchr
RtlSetEnvironmentStrings
RtlOemStringToUnicodeString
wcscat_s
RtlAllocateAndInitializeSid
NtQueryAttributesFile
RtlFreeSid
strrchr
NtQueryFullAttributesFile
TpCaptureCaller
RtlWow64EnableFsRedirection
_stricmp
NtSetTimerResolution
NtQueryTimerResolution
RtlGetAppContainerSidType
RtlConvertSidToUnicodeString
RtlSetEnvironmentVariable
RtlGetAppContainerParent
RtlRunOnceExecuteOnce
RtlInitializeCriticalSection
_strnicmp
strncmp
RtlTryAcquirePebLock
RtlReleasePebLock
RtlGetNtSystemRoot
NtWaitForMultipleObjects
NtClearEvent
RtlWerpReportException
RtlGetThreadPreferredUILanguages
LdrResSearchResource
wcsnlen
strcat_s
strnlen
NlsMbCodePageTag
NtApphelpCacheControl
RtlGetFullPathName_UEx
ZwClose
ZwOpenFile
ZwOpenKey
ZwEnumerateKey
ZwQueryValueKey
ZwCreateFile
ZwQueryInformationFile
ZwCreateSection
ZwQueryDirectoryFile
RtlNtPathNameToDosPathName
RtlGetNativeSystemInformation
ZwQuerySystemInformation
ZwUnmapViewOfSection
ZwMapViewOfSection
VerSetConditionMask
RtlVerifyVersionInfo
LdrGetDllHandle
ApiSetQueryApiSetPresence
RtlCreateSecurityDescriptor
RtlAddAccessAllowedAce
RtlCreateAcl
RtlAllocateHeap
RtlGetPersistedStateLocation
_CIcos
_CIsin
_alldiv
_allmul
_allshl
_chkstk
_ftol2_sse
floor
memcmp
memcpy
memset
KERNELBASE.dll GetUserDefaultLocaleName
BaseFormatObjectAttributes
GetVolumeNameForVolumeMountPointW
GetRegistryExtensionFlags
KernelBaseGetGlobalData
GlobalFree
LoadStringBaseExW
AppContainerLookupMoniker
AppContainerFreeMemory
PackageIdFromFullName
GetUnicodeStringToEightBitStringRoutine
GetUnicodeStringToEightBitSizeRoutine
CompareStringA
GetNamedPipeAttribute
AppXPreCreationExtension
AppXPostSuccessExtension
AppXReleaseAppXContext
AreFileApisANSI
CreateProcessInternalA
CreateProcessInternalW
CreateProcessAsUserW
CreateProcessAsUserA
BasepNotifyTrackingService
MoveFileWithProgressTransactedW
BasepAdjustObjectAttributesForPrivateNamespace
GetEightBitStringToUnicodeStringRoutine
GetStringTableEntry
CheckGroupPolicyEnabled
OpenRegKey
InternalLcidToName
NlsIsUserDefaultLocale
GetPtrCalDataArray
GetUserOverrideString
GetPtrCalData
Internal_EnumCalendarInfo
Internal_EnumLanguageGroupLocales
Internal_EnumSystemCodePages
Internal_EnumDateFormats
Internal_EnumUILanguages
Internal_EnumSystemLanguageGroups
NlsValidateLocale
Internal_EnumTimeFormats
GetNamedLocaleHashNode
GetUserOverrideWord
GetLocaleInfoHelper
GetCalendar
GetPackageFullName
GetCurrentPackageFullName
CheckIsMSIXPackage
ClosePackageInfo
AppXGetOSMaxVersionTested
GetPackageTargetPlatformProperty
GetTargetPlatformContext
OpenPackageInfoByFullNameForUser
BaseDllFreeResourceId
BaseDllMapResourceIdW
CheckAllowDecryptedRemoteDestinationPolicy
PrivCopyFileExW
NotifyMountMgr
LCIDToLocaleName
EnumSystemLanguageGroupsW
GetSystemDefaultLocaleName
GetEraNameCountedString
FatalAppExitW
FatalAppExitA
lstrlenW
lstrlenA
lstrcpynW
lstrcpynA
lstrcmpiW
lstrcmpW
Sleep
SetFileApisToOEM
SetFileApisToANSI
PulseEvent
MapViewOfFileExNuma
LocalUnlock
LocalReAlloc
LocalLock
LocalAlloc
HeapSummary
GlobalAlloc
GetUserDefaultUILanguage
GetSystemDefaultUILanguage
GetStringTypeA
GetProcAddressForCaller
BaseGetNamedObjectDirectory
EnumUILanguagesW
EnumSystemLocalesEx
EnumLanguageGroupLocalesW
api-ms-win-core-processthreads-l1-1-0.dll CreateProcessA
CreateProcessW
CreateRemoteThreadEx
GetExitCodeThread
GetPriorityClass
GetProcessIdOfThread
GetProcessId
GetProcessTimes
GetStartupInfoW
GetThreadId
GetThreadPriority
GetExitCodeProcess
OpenThread
OpenProcessToken
QueueUserAPC
ResumeThread
SetPriorityClass
SetProcessShutdownParameters
SetThreadPriority
SetThreadPriorityBoost
SuspendThread
SwitchToThread
TerminateProcess
TerminateThread
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
SetProcessAffinityUpdateMode
QueryProcessAffinityUpdateMode
GetProcessVersion
CreateRemoteThread
SetThreadStackGuarantee
UpdateProcThreadAttribute
DeleteProcThreadAttributeList
GetCurrentProcessId
GetCurrentProcess
ProcessIdToSessionId
GetThreadPriorityBoost
InitializeProcThreadAttributeList
api-ms-win-core-processthreads-l1-1-3.dll GetProcessShutdownParameters
SetProcessInformation
SetThreadIdealProcessor
GetProcessInformation
api-ms-win-core-processthreads-l1-1-2.dll GetThreadIOPendingFlag
SetThreadInformation
GetSystemTimes
SetProcessPriorityBoost
GetProcessPriorityBoost
GetThreadInformation
api-ms-win-core-processthreads-l1-1-1.dll GetThreadTimes
GetThreadIdealProcessorEx
GetThreadContext
SetThreadContext
IsProcessorFeaturePresent
OpenProcess
GetProcessHandleCount
SetThreadIdealProcessorEx
FlushInstructionCache
SetProcessMitigationPolicy
GetProcessMitigationPolicy
api-ms-win-core-registry-l1-1-0.dll RegUnLoadKeyW
RegLoadAppKeyW
RegDeleteValueW
RegDisablePredefinedCacheEx
RegEnumKeyExA
RegEnumKeyExW
RegRestoreKeyW
RegEnumValueA
RegEnumValueW
RegSaveKeyExA
RegDeleteKeyExA
RegDeleteValueA
RegCreateKeyExA
RegFlushKey
RegGetKeySecurity
RegGetValueA
RegCopyTreeW
RegLoadKeyA
RegLoadKeyW
RegUnLoadKeyA
RegCloseKey
RegGetValueW
RegSetValueExW
RegDeleteTreeW
RegLoadMUIStringA
RegLoadMUIStringW
RegDeleteTreeA
RegSetValueExA
RegSetKeySecurity
RegCreateKeyExW
RegOpenKeyExW
RegDeleteKeyExW
RegNotifyChangeKeyValue
RegOpenCurrentUser
RegOpenKeyExA
RegOpenUserClassesRoot
RegQueryInfoKeyA
RegQueryInfoKeyW
RegQueryValueExA
RegQueryValueExW
RegRestoreKeyA
RegSaveKeyExW
api-ms-win-core-heap-l1-1-0.dll HeapSetInformation
HeapReAlloc
HeapWalk
HeapValidate
HeapAlloc
GetProcessHeap
HeapFree
HeapUnlock
HeapCompact
HeapCreate
HeapDestroy
HeapLock
HeapQueryInformation
GetProcessHeaps
api-ms-win-core-heap-l2-1-0.dll LocalFree
api-ms-win-core-memory-l1-1-1.dll CreateFileMappingNumaW
VirtualUnlock
GetWriteWatch
QueryMemoryResourceNotification
ResetWriteWatch
SetSystemFileCacheSize
SetProcessWorkingSetSizeEx
GetProcessWorkingSetSizeEx
GetLargePageMinimum
CreateMemoryResourceNotification
VirtualLock
GetSystemFileCacheSize
api-ms-win-core-memory-l1-1-0.dll ReadProcessMemory
VirtualQueryEx
VirtualQuery
VirtualProtectEx
OpenFileMappingW
MapViewOfFile
VirtualFreeEx
VirtualFree
WriteProcessMemory
VirtualAllocEx
MapViewOfFileEx
UnmapViewOfFile
FlushViewOfFile
CreateFileMappingW
VirtualProtect
VirtualAlloc
api-ms-win-core-memory-l1-1-2.dll FreeUserPhysicalPages
AllocateUserPhysicalPages
RegisterBadMemoryNotification
UnregisterBadMemoryNotification
GetMemoryErrorHandlingCapabilities
MapUserPhysicalPages
AllocateUserPhysicalPagesNuma
VirtualAllocExNuma
api-ms-win-core-handle-l1-1-0.dll GetHandleInformation
DuplicateHandle
SetHandleInformation
CloseHandle
api-ms-win-core-synch-l1-1-0.dll DeleteCriticalSection
EnterCriticalSection
OpenSemaphoreW
OpenWaitableTimerW
ReleaseMutex
ReleaseSemaphore
ResetEvent
OpenMutexW
SetEvent
SetWaitableTimer
SleepEx
WaitForMultipleObjectsEx
WaitForSingleObject
LeaveCriticalSection
WaitForSingleObjectEx
CreateSemaphoreExW
CreateMutexW
CreateMutexExW
CreateWaitableTimerExW
CreateMutexExA
OpenEventW
OpenEventA
InitializeCriticalSection
InitializeCriticalSectionEx
InitializeCriticalSectionAndSpinCount
CreateMutexA
CancelWaitableTimer
CreateEventA
CreateEventExA
CreateEventExW
CreateEventW
api-ms-win-core-synch-l1-2-1.dll WaitForMultipleObjects
CreateSemaphoreW
api-ms-win-core-synch-l1-2-0.dll DeleteSynchronizationBarrier
InitializeSynchronizationBarrier
SignalObjectAndWait
EnterSynchronizationBarrier
InitOnceExecuteOnce
api-ms-win-core-file-l1-1-0.dll LocalFileTimeToFileTime
QueryDosDeviceW
RemoveDirectoryW
ReadFileScatter
RemoveDirectoryA
ReadFile
ReadFileEx
LockFileEx
GetFileSizeEx
GetFileSize
GetFileInformationByHandle
GetFileAttributesW
GetFileAttributesExW
GetFileAttributesExA
GetFileAttributesA
GetDriveTypeW
GetDriveTypeA
GetDiskFreeSpaceW
GetDiskFreeSpaceExW
GetDiskFreeSpaceExA
GetDiskFreeSpaceA
FlushFileBuffers
FindVolumeClose
FindNextVolumeW
FindNextFileW
FindNextFileA
FindNextChangeNotification
FindFirstVolumeW
FindFirstFileW
FindFirstFileExW
FindFirstFileExA
FindFirstFileA
FindFirstChangeNotificationW
FindFirstChangeNotificationA
FindCloseChangeNotification
FindClose
FileTimeToLocalFileTime
DeleteVolumeMountPointW
DeleteFileW
DeleteFileA
DefineDosDeviceW
CreateFileW
CreateFileA
CreateDirectoryW
CreateDirectoryA
CompareFileTime
SetFileAttributesA
SetFileAttributesW
SetFileInformationByHandle
SetFilePointer
SetFilePointerEx
SetFileTime
SetFileValidData
UnlockFile
UnlockFileEx
WriteFile
WriteFileEx
WriteFileGather
GetVolumePathNameW
LockFile
GetVolumeInformationW
GetVolumeInformationByHandleW
GetTempFileNameW
GetLogicalDriveStringsW
GetFullPathNameW
GetFullPathNameA
SetEndOfFile
GetFinalPathNameByHandleW
GetFinalPathNameByHandleA
GetFileTime
GetFileType
api-ms-win-core-file-l1-2-0.dll GetVolumePathNamesForVolumeNameW
CreateFile2
GetTempPathW
api-ms-win-core-file-l1-2-2.dll GetTempFileNameA
FindNextFileNameW
FindFirstFileNameW
GetVolumeInformationA
GetTempPathA
FindFirstStreamW
api-ms-win-core-file-l1-2-1.dll SetFileIoOverlappedRange
GetCompressedFileSizeA
GetCompressedFileSizeW
api-ms-win-core-delayload-l1-1-0.dll DelayLoadFailureHook
api-ms-win-core-io-l1-1-0.dll GetQueuedCompletionStatusEx
GetQueuedCompletionStatus
GetOverlappedResult
CreateIoCompletionPort
DeviceIoControl
PostQueuedCompletionStatus
CancelIoEx
api-ms-win-core-io-l1-1-1.dll CancelSynchronousIo
CancelIo
api-ms-win-core-job-l1-1-0.dll IsProcessInJob
api-ms-win-core-threadpool-legacy-l1-1-0.dll QueueUserWorkItem
UnregisterWaitEx
CreateTimerQueueTimer
DeleteTimerQueueTimer
DeleteTimerQueueEx
ChangeTimerQueueTimer
CreateTimerQueue
api-ms-win-core-threadpool-private-l1-1-0.dll RegisterWaitForSingleObjectEx
api-ms-win-core-libraryloader-l1-2-2.dll EnumResourceNamesW
api-ms-win-core-libraryloader-l1-2-0.dll LoadResource
LoadLibraryExA
GetModuleHandleExW
EnumResourceNamesExW
GetModuleHandleExA
GetModuleHandleW
GetModuleHandleA
LockResource
EnumResourceLanguagesExA
EnumResourceLanguagesExW
EnumResourceNamesExA
EnumResourceTypesExA
EnumResourceTypesExW
FreeLibrary
GetProcAddress
LoadLibraryExW
FindResourceExW
DisableThreadLibraryCalls
FreeLibraryAndExitThread
FindStringOrdinal
SizeofResource
GetModuleFileNameW
GetModuleFileNameA
FreeResource
api-ms-win-core-libraryloader-l1-2-1.dll FindResourceW
LoadLibraryA
LoadLibraryW
api-ms-win-core-libraryloader-l2-1-0.dll LoadPackagedLibrary
api-ms-win-core-namedpipe-l1-2-2.dll CallNamedPipeW
api-ms-win-core-namedpipe-l1-1-0.dll CreateNamedPipeW
CreatePipe
DisconnectNamedPipe
GetNamedPipeClientComputerNameW
PeekNamedPipe
ConnectNamedPipe
SetNamedPipeHandleState
TransactNamedPipe
WaitNamedPipeW
api-ms-win-core-namedpipe-l1-2-1.dll GetNamedPipeHandleStateW
api-ms-win-core-datetime-l1-1-0.dll GetDateFormatA
GetTimeFormatA
GetTimeFormatW
GetDateFormatW
api-ms-win-core-datetime-l1-1-1.dll GetTimeFormatEx
GetDateFormatEx
api-ms-win-core-datetime-l1-1-2.dll GetDurationFormatEx
api-ms-win-core-sysinfo-l1-2-0.dll GetSystemTimePreciseAsFileTime
GetSystemFirmwareTable
GetNativeSystemInfo
GetProductInfo
SetComputerNameExW
SetSystemTime
EnumSystemFirmwareTables
api-ms-win-core-sysinfo-l1-1-0.dll GetComputerNameExW
GetLocalTime
GetSystemInfo
GetSystemTime
GetSystemTimeAdjustment
GetSystemTimeAsFileTime
GetVersion
GetComputerNameExA
GetVersionExW
GetWindowsDirectoryA
GetTickCount
GetWindowsDirectoryW
GlobalMemoryStatusEx
SetLocalTime
GetLogicalProcessorInformation
GetLogicalProcessorInformationEx
GetVersionExA
api-ms-win-core-sysinfo-l1-2-3.dll SetComputerNameA
SetComputerNameExA
SetComputerNameW
api-ms-win-core-sysinfo-l1-2-1.dll SetComputerNameEx2W
DnsHostnameToComputerNameExW
GetPhysicallyInstalledSystemMemory
api-ms-win-core-timezone-l1-1-0.dll GetDynamicTimeZoneInformation
GetTimeZoneInformation
GetTimeZoneInformationForYear
SystemTimeToFileTime
FileTimeToSystemTime
SetDynamicTimeZoneInformation
TzSpecificLocalTimeToSystemTime
SystemTimeToTzSpecificLocalTime
SetTimeZoneInformation
api-ms-win-core-localization-l1-2-0.dll IsValidLanguageGroup
IsValidCodePage
IsValidLocale
SetThreadLocale
IsNLSDefinedString
FindNLSStringEx
GetFileMUIInfo
LCMapStringA
GetFileMUIPath
GetLocaleInfoEx
GetNLSVersionEx
GetSystemPreferredUILanguages
LCMapStringW
SetProcessPreferredUILanguages
GetThreadUILanguage
GetUILanguageInfo
GetUserPreferredUILanguages
IdnToAscii
IdnToUnicode
SetLocaleInfoW
IsValidLocaleName
GetCalendarInfoW
EnumSystemLocalesA
LCMapStringEx
LocaleNameToLCID
ResolveLocaleName
ConvertDefaultLocale
VerLanguageNameA
GetThreadPreferredUILanguages
SetCalendarInfoW
GetCalendarInfoEx
EnumSystemLocalesW
FindNLSString
FormatMessageA
FormatMessageW
GetACP
GetCPInfo
GetCPInfoExW
GetNLSVersion
IsValidNLSVersion
SetThreadPreferredUILanguages
SetThreadUILanguage
GetLocaleInfoA
GetLocaleInfoW
GetOEMCP
GetProcessPreferredUILanguages
VerLanguageNameW
GetSystemDefaultLangID
GetSystemDefaultLCID
GetThreadLocale
GetUserDefaultLangID
GetUserDefaultLCID
IsDBCSLeadByte
IsDBCSLeadByteEx
api-ms-win-core-localization-private-l1-1-0.dll NlsGetCacheUpdateCount
NlsUpdateLocale
NlsCheckPolicy
NlsUpdateSystemLocale
api-ms-win-core-processsnapshot-l1-1-0.dll PssWalkMarkerFree
PssWalkMarkerCreate
PssDuplicateSnapshot
PssWalkSnapshot
PssQuerySnapshot
PssFreeSnapshot
PssCaptureSnapshot
PssWalkMarkerSeekToBeginning
PssWalkMarkerSetPosition
PssWalkMarkerGetPosition
api-ms-win-core-processenvironment-l1-1-0.dll SetCurrentDirectoryA
SearchPathW
SetEnvironmentVariableA
SetEnvironmentVariableW
SetStdHandle
ExpandEnvironmentStringsA
GetStdHandle
GetEnvironmentVariableA
GetEnvironmentStringsW
GetCurrentDirectoryW
GetCurrentDirectoryA
GetCommandLineW
GetCommandLineA
FreeEnvironmentStringsW
FreeEnvironmentStringsA
ExpandEnvironmentStringsW
SetCurrentDirectoryW
GetEnvironmentStrings
GetEnvironmentVariableW
SetEnvironmentStringsW
SetStdHandleEx
api-ms-win-core-processenvironment-l1-2-0.dll NeedCurrentDirectoryForExePathW
NeedCurrentDirectoryForExePathA
SearchPathA
api-ms-win-core-string-l1-1-0.dll CompareStringOrdinal
CompareStringEx
WideCharToMultiByte
MultiByteToWideChar
GetStringTypeW
GetStringTypeExW
FoldStringW
CompareStringW
api-ms-win-core-debug-l1-1-1.dll CheckRemoteDebuggerPresent
ContinueDebugEvent
WaitForDebugEvent
DebugActiveProcess
DebugActiveProcessStop
api-ms-win-core-debug-l1-1-0.dll OutputDebugStringA
IsDebuggerPresent
OutputDebugStringW
DebugBreak
api-ms-win-core-errorhandling-l1-1-0.dll GetLastError
RaiseException
SetLastError
UnhandledExceptionFilter
SetUnhandledExceptionFilter
SetErrorMode
GetErrorMode
api-ms-win-core-errorhandling-l1-1-3.dll SetThreadErrorMode
GetThreadErrorMode
api-ms-win-core-fibers-l1-1-0.dll FlsFree
FlsAlloc
FlsGetValue
FlsSetValue
api-ms-win-core-util-l1-1-0.dll Beep
api-ms-win-core-profile-l1-1-0.dll QueryPerformanceFrequency
QueryPerformanceCounter
api-ms-win-security-base-l1-1-0.dll CreateWellKnownSid
GetTokenInformation
DuplicateToken
FreeSid
EqualSid
AllocateAndInitializeSid
AccessCheck
api-ms-win-security-base-l1-2-0.dll GetAppContainerAce
CheckTokenMembershipEx
CheckTokenCapability
SetCachedSigningLevel
AddResourceAttributeAce
AddScopedPolicyIDAce
GetCachedSigningLevel
api-ms-win-core-comm-l1-1-0.dll ClearCommError
GetCommState
EscapeCommFunction
ClearCommBreak
GetCommMask
GetCommModemStatus
GetCommProperties
GetCommTimeouts
PurgeComm
SetCommBreak
SetCommConfig
SetCommMask
SetCommState
SetCommTimeouts
SetupComm
TransmitCommChar
GetCommConfig
WaitCommEvent
api-ms-win-core-wow64-l1-1-1.dll IsWow64Process2
GetSystemWow64DirectoryW
GetSystemWow64DirectoryA
GetSystemWow64Directory2W
api-ms-win-core-wow64-l1-1-0.dll IsWow64Process
Wow64RevertWow64FsRedirection
Wow64DisableWow64FsRedirection
api-ms-win-core-wow64-l1-1-3.dll Wow64SuspendThread
Wow64SetThreadContext
Wow64GetThreadContext
api-ms-win-core-realtime-l1-1-0.dll QueryIdleProcessorCycleTime
QueryProcessCycleTime
QueryThreadCycleTime
QueryIdleProcessorCycleTimeEx
QueryUnbiasedInterruptTime
api-ms-win-core-systemtopology-l1-1-1.dll GetNumaProximityNodeEx
api-ms-win-core-systemtopology-l1-1-0.dll GetNumaHighestNodeNumber
GetNumaNodeProcessorMaskEx
api-ms-win-core-processtopology-l1-1-0.dll SetThreadGroupAffinity
GetThreadGroupAffinity
GetProcessGroupAffinity
api-ms-win-core-namespace-l1-1-0.dll OpenPrivateNamespaceW
ClosePrivateNamespace
CreatePrivateNamespaceW
CreateBoundaryDescriptorW
AddSIDToBoundaryDescriptor
DeleteBoundaryDescriptor
api-ms-win-core-file-l2-1-2.dll CreateHardLinkA
CopyFileW
api-ms-win-core-file-l2-1-0.dll ReplaceFileW
MoveFileExW
CreateDirectoryExW
CopyFileExW
GetFileInformationByHandleEx
CopyFile2
MoveFileWithProgressW
ReadDirectoryChangesW
ReOpenFile
CreateSymbolicLinkW
CreateHardLinkW
api-ms-win-core-file-l2-1-3.dll ReadDirectoryChangesExW
api-ms-win-core-file-l2-1-1.dll OpenFileById
api-ms-win-core-xstate-l2-1-0.dll GetEnabledXStateFeatures
SetXStateFeaturesMask
InitializeContext
GetXStateFeaturesMask
CopyContext
LocateXStateFeature
api-ms-win-core-xstate-l2-1-1.dll InitializeContext2
api-ms-win-core-localization-l2-1-0.dll EnumDateFormatsExW
EnumTimeFormatsEx
EnumDateFormatsW
EnumDateFormatsExEx
EnumCalendarInfoExEx
EnumSystemCodePagesW
GetCurrencyFormatEx
EnumTimeFormatsW
GetNumberFormatEx
EnumCalendarInfoW
EnumCalendarInfoExW
api-ms-win-core-normalization-l1-1-0.dll NormalizeString
VerifyScripts
IsNormalizedString
GetStringScripts
IdnToNameprepUnicode
api-ms-win-core-fibers-l2-1-0.dll ConvertThreadToFiber
SwitchToFiber
DeleteFiber
CreateFiber
ConvertFiberToThread
api-ms-win-core-fibers-l2-1-1.dll ConvertThreadToFiberEx
CreateFiberEx
api-ms-win-core-sidebyside-l1-1-0.dll GetCurrentActCtx
QueryActCtxSettingsW
ActivateActCtx
FindActCtxSectionStringW
QueryActCtxW
FindActCtxSectionGuid
DeactivateActCtx
CreateActCtxW
ZombifyActCtx
AddRefActCtx
ReleaseActCtx
api-ms-win-core-appcompat-l1-1-0.dll BaseDumpAppcompatCache
BaseCheckAppcompatCacheEx
BaseCleanupAppcompatCacheSupport
BaseUpdateAppcompatCache
BaseFlushAppcompatCache
BaseCheckAppcompatCache
BaseInitAppcompatCacheSupport
api-ms-win-core-appcompat-l1-1-1.dll BaseFreeAppCompatDataForProcess
BaseReadAppCompatDataForProcess
api-ms-win-core-windowserrorreporting-l1-1-0.dll GetApplicationRestartSettings
WerUnregisterRuntimeExceptionModule
WerUnregisterFile
WerUnregisterMemoryBlock
WerRegisterRuntimeExceptionModule
WerRegisterMemoryBlock
WerRegisterFile
GetApplicationRecoveryCallback
api-ms-win-core-windowserrorreporting-l1-1-3.dll RegisterApplicationRestart
UnregisterApplicationRestart
api-ms-win-core-windowserrorreporting-l1-1-1.dll WerUnregisterExcludedMemoryBlock
WerRegisterCustomMetadata
WerUnregisterCustomMetadata
WerRegisterAdditionalProcess
WerRegisterExcludedMemoryBlock
WerUnregisterAdditionalProcess
api-ms-win-core-windowserrorreporting-l1-1-2.dll WerRegisterAppLocalDump
WerUnregisterAppLocalDump
api-ms-win-core-console-l1-1-0.dll SetConsoleCtrlHandler
WriteConsoleW
ReadConsoleW
ReadConsoleInputW
ReadConsoleInputA
ReadConsoleA
WriteConsoleA
AllocConsole
GetNumberOfConsoleInputEvents
GetConsoleOutputCP
GetConsoleMode
GetConsoleCP
SetConsoleMode
api-ms-win-core-console-l1-2-0.dll AttachConsole
PeekConsoleInputA
PeekConsoleInputW
FreeConsole
api-ms-win-core-console-l1-2-1.dll ResizePseudoConsole
CreatePseudoConsole
ClosePseudoConsole
api-ms-win-core-console-l2-1-0.dll FillConsoleOutputCharacterA
FillConsoleOutputCharacterW
FlushConsoleInputBuffer
GenerateConsoleCtrlEvent
FillConsoleOutputAttribute
CreateConsoleScreenBuffer
WriteConsoleInputA
SetConsoleWindowInfo
SetConsoleTextAttribute
SetConsoleScreenBufferSize
SetConsoleScreenBufferInfoEx
SetConsoleOutputCP
SetConsoleCursorPosition
SetConsoleCursorInfo
SetConsoleCP
SetConsoleActiveScreenBuffer
ScrollConsoleScreenBufferW
ScrollConsoleScreenBufferA
ReadConsoleOutputW
ReadConsoleOutputCharacterW
ReadConsoleOutputCharacterA
ReadConsoleOutputAttribute
ReadConsoleOutputA
GetLargestConsoleWindowSize
WriteConsoleInputW
GetConsoleScreenBufferInfoEx
GetConsoleScreenBufferInfo
GetConsoleCursorInfo
WriteConsoleOutputA
WriteConsoleOutputAttribute
WriteConsoleOutputCharacterA
WriteConsoleOutputCharacterW
WriteConsoleOutputW
api-ms-win-core-console-l2-2-0.dll SetConsoleTitleW
GetConsoleTitleA
GetConsoleOriginalTitleW
GetConsoleOriginalTitleA
SetConsoleTitleA
GetConsoleTitleW
api-ms-win-core-console-l3-2-0.dll GetConsoleAliasExesLengthW
GetConsoleAliasExesW
GetConsoleAliasW
GetConsoleAliasesA
GetConsoleAliasExesLengthA
GetConsoleAliasExesA
AddConsoleAliasA
GetConsoleAliasesLengthA
GetConsoleAliasesLengthW
AddConsoleAliasW
ExpungeConsoleCommandHistoryA
GetConsoleCommandHistoryA
GetConsoleCommandHistoryLengthA
GetConsoleCommandHistoryLengthW
GetConsoleCommandHistoryW
GetConsoleDisplayMode
GetConsoleFontSize
GetConsoleHistoryInfo
GetConsoleProcessList
GetConsoleSelectionInfo
GetConsoleWindow
GetCurrentConsoleFont
GetCurrentConsoleFontEx
GetNumberOfConsoleMouseButtons
SetConsoleDisplayMode
SetConsoleHistoryInfo
SetConsoleNumberOfCommandsA
ExpungeConsoleCommandHistoryW
GetConsoleAliasA
SetConsoleNumberOfCommandsW
SetCurrentConsoleFontEx
GetConsoleAliasesW
api-ms-win-core-psapi-l1-1-0.dll QueryFullProcessImageNameW
K32GetPerformanceInfo
K32GetProcessImageFileNameW
K32EnumPageFilesW
K32GetMappedFileNameW
K32GetWsChangesEx
K32GetWsChanges
K32InitializeProcessForWsWatch
K32QueryWorkingSetEx
K32QueryWorkingSet
K32EmptyWorkingSet
K32GetProcessMemoryInfo
K32GetDeviceDriverFileNameW
K32GetDeviceDriverBaseNameW
K32EnumDeviceDrivers
K32GetModuleFileNameExW
K32GetModuleBaseNameW
K32EnumProcesses
K32EnumProcessModules
K32GetModuleInformation
K32EnumProcessModulesEx
api-ms-win-core-psapi-ansi-l1-1-0.dll K32EnumPageFilesA
K32GetProcessImageFileNameA
K32GetDeviceDriverFileNameA
QueryFullProcessImageNameA
K32GetDeviceDriverBaseNameA
K32GetMappedFileNameA
K32GetModuleBaseNameA
K32GetModuleFileNameExA
api-ms-win-security-appcontainer-l1-1-0.dll GetAppContainerNamedObjectPath
api-ms-win-eventing-provider-l1-1-0.dll EventSetInformation
EventWriteTransfer
EventRegister
EventUnregister
api-ms-win-core-delayload-l1-1-1.dll ResolveDelayLoadedAPI
ext-ms-win-oobe-query-l1-1-0.dll (delay-loaded) QueryOOBESupport

Delayed Imports

Attributes 0x1
Name ext-ms-win-oobe-query-l1-1-0.dll
ModuleHandle 0xb06bc
DelayImportAddressTable 0xc002c
DelayImportNameTable 0x92b28
BoundDelayImportTable 0x92c38
UnloadDelayImportTable 0
TimeStamp 1970-Jan-01 00:00:00

BaseThreadInitThunk

Ordinal 1
Address 0x1fa10

InterlockedPushListSList

Ordinal 2
Address 0x96b98
ForwardName NTDLL.RtlInterlockedPushListSList

Wow64Transition

Ordinal 3
Address 0x82034

AcquireSRWLockExclusive

Ordinal 4
Address 0x96be2
ForwardName NTDLL.RtlAcquireSRWLockExclusive

AcquireSRWLockShared

Ordinal 5
Address 0x96c18
ForwardName NTDLL.RtlAcquireSRWLockShared

ActivateActCtx

Ordinal 6
Address 0x20ac0

ActivateActCtxWorker

Ordinal 7
Address 0x20400

AddAtomA

Ordinal 8
Address 0x195a0

AddAtomW

Ordinal 9
Address 0x1b8d0

AddConsoleAliasA

Ordinal 10
Address 0x23c10

AddConsoleAliasW

Ordinal 11
Address 0x23c20

AddDllDirectory

Ordinal 12
Address 0x96c9e
ForwardName api-ms-win-core-libraryloader-l1-1-0.AddDllDirectory

AddIntegrityLabelToBoundaryDescriptor

Ordinal 13
Address 0x352a0

AddLocalAlternateComputerNameA

Ordinal 14
Address 0x520e0

AddLocalAlternateComputerNameW

Ordinal 15
Address 0x52140

AddRefActCtx

Ordinal 16
Address 0x329f0

AddRefActCtxWorker

Ordinal 17
Address 0x20f40

AddResourceAttributeAce

Ordinal 18
Address 0x32a00

AddSIDToBoundaryDescriptor

Ordinal 19
Address 0x19830

AddScopedPolicyIDAce

Ordinal 20
Address 0x32a20

AddSecureMemoryCacheCallback

Ordinal 21
Address 0x312c0

AddVectoredContinueHandler

Ordinal 22
Address 0x96dd7
ForwardName NTDLL.RtlAddVectoredContinueHandler

AddVectoredExceptionHandler

Ordinal 23
Address 0x96e17
ForwardName NTDLL.RtlAddVectoredExceptionHandler

AdjustCalendarDate

Ordinal 24
Address 0x42370

AllocConsole

Ordinal 25
Address 0x23860

AllocateUserPhysicalPages

Ordinal 26
Address 0x32a60

AllocateUserPhysicalPagesNuma

Ordinal 27
Address 0x32a40

AppPolicyGetClrCompat

Ordinal 28
Address 0x96eaa
ForwardName kernelbase.AppPolicyGetClrCompat

AppPolicyGetCreateFileAccess

Ordinal 29
Address 0x96ee8
ForwardName kernelbase.AppPolicyGetCreateFileAccess

AppPolicyGetLifecycleManagement

Ordinal 30
Address 0x96f30
ForwardName kernelbase.AppPolicyGetLifecycleManagement

AppPolicyGetMediaFoundationCodecLoading

Ordinal 31
Address 0x96f83
ForwardName kernelbase.AppPolicyGetMediaFoundationCodecLoading

AppPolicyGetProcessTerminationMethod

Ordinal 32
Address 0x96fdb
ForwardName kernelbase.AppPolicyGetProcessTerminationMethod

AppPolicyGetShowDeveloperDiagnostic

Ordinal 33
Address 0x9702f
ForwardName kernelbase.AppPolicyGetShowDeveloperDiagnostic

AppPolicyGetThreadInitializationType

Ordinal 34
Address 0x97083
ForwardName kernelbase.AppPolicyGetThreadInitializationType

AppPolicyGetWindowingModel

Ordinal 35
Address 0x970ce
ForwardName kernelbase.AppPolicyGetWindowingModel

AppXGetOSMaxVersionTested

Ordinal 36
Address 0x9710e
ForwardName kernelbase.AppXGetOSMaxVersionTested

ApplicationRecoveryFinished

Ordinal 37
Address 0x3ac00

ApplicationRecoveryInProgress

Ordinal 38
Address 0x3ac20

AreFileApisANSI

Ordinal 39
Address 0x21d80

AssignProcessToJobObject

Ordinal 40
Address 0x535e0

AttachConsole

Ordinal 41
Address 0x23870

BackupRead

Ordinal 42
Address 0x54570

BackupSeek

Ordinal 43
Address 0x55430

BackupWrite

Ordinal 44
Address 0x55690

BaseCheckAppcompatCache

Ordinal 45
Address 0x32aa0

BaseCheckAppcompatCacheEx

Ordinal 46
Address 0x32a80

BaseCheckAppcompatCacheExWorker

Ordinal 47
Address 0x40d00

BaseCheckAppcompatCacheWorker

Ordinal 48
Address 0x40d10

BaseCheckElevation

Ordinal 49
Address 0x13090

BaseCleanupAppcompatCacheSupport

Ordinal 50
Address 0x32ac0

BaseCleanupAppcompatCacheSupportWorker

Ordinal 51
Address 0x40d20

BaseDestroyVDMEnvironment

Ordinal 52
Address 0x37d30

BaseDllReadWriteIniFile

Ordinal 53
Address 0x1c110

BaseDumpAppcompatCache

Ordinal 54
Address 0x32ae0

BaseDumpAppcompatCacheWorker

Ordinal 55
Address 0x22760

BaseElevationPostProcessing

Ordinal 56
Address 0x18d70

BaseFlushAppcompatCache

Ordinal 57
Address 0x32af0

BaseFlushAppcompatCacheWorker

Ordinal 58
Address 0x40d30

BaseFormatObjectAttributes

Ordinal 59
Address 0x22e60

BaseFormatTimeOut

Ordinal 60
Address 0x51860

BaseFreeAppCompatDataForProcessWorker

Ordinal 61
Address 0x197e0

BaseGenerateAppCompatData

Ordinal 62
Address 0x158d0

BaseGetNamedObjectDirectory

Ordinal 63
Address 0x32b00

BaseInitAppcompatCacheSupport

Ordinal 64
Address 0x32b20

BaseInitAppcompatCacheSupportWorker

Ordinal 65
Address 0x221f0

BaseIsAppcompatInfrastructureDisabled

Ordinal 66
Address 0x22180

BaseIsAppcompatInfrastructureDisabledWorker

Ordinal 67
Address 0x22180

BaseIsDosApplication

Ordinal 68
Address 0x57c60

BaseQueryModuleData

Ordinal 69
Address 0x415d0

BaseReadAppCompatDataForProcessWorker

Ordinal 70
Address 0x40d90

BaseSetLastNTError

Ordinal 71
Address 0x1bd20

BaseUpdateAppcompatCache

Ordinal 72
Address 0x32b30

BaseUpdateAppcompatCacheWorker

Ordinal 73
Address 0x41040

BaseUpdateVDMEntry

Ordinal 74
Address 0x37f90

BaseVerifyUnicodeString

Ordinal 75
Address 0x51ab0

BaseWriteErrorElevationRequiredEvent

Ordinal 76
Address 0x56760

Basep8BitStringToDynamicUnicodeString

Ordinal 77
Address 0x1f470

BasepAllocateActivationContextActivationBlock

Ordinal 78
Address 0x51b10

BasepAnsiStringToDynamicUnicodeString

Ordinal 79
Address 0x51a50

BasepAppContainerEnvironmentExtension

Ordinal 80
Address 0x31cb0

BasepAppXExtension

Ordinal 81
Address 0x31cd0

BasepCheckAppCompat

Ordinal 82
Address 0x13000

BasepCheckWebBladeHashes

Ordinal 83
Address 0x18950

BasepCheckWinSaferRestrictions

Ordinal 84
Address 0x17540

BasepConstructSxsCreateProcessMessage

Ordinal 85
Address 0x17160

BasepCopyEncryption

Ordinal 86
Address 0x30f10

BasepFinishPackageActivationForSxS

Ordinal 87
Address 0x3a630

BasepFreeActivationContextActivationBlock

Ordinal 88
Address 0x51c10

BasepFreeAppCompatData

Ordinal 89
Address 0x18510

BasepGetAppCompatData

Ordinal 90
Address 0x15130

BasepGetComputerNameFromNtPath

Ordinal 91
Address 0x21220

BasepGetExeArchType

Ordinal 92
Address 0x14b90

BasepGetPackageActivationTokenForSxS

Ordinal 93
Address 0x3a660

BasepInitAppCompatData

Ordinal 94
Address 0x413d0

BasepIsProcessAllowed

Ordinal 95
Address 0x17ee0

BasepMapModuleHandle

Ordinal 96
Address 0x51c50

BasepNotifyLoadStringResource

Ordinal 97
Address 0x208f0

BasepPostSuccessAppXExtension

Ordinal 98
Address 0x31d20

BasepProcessInvalidImage

Ordinal 99
Address 0x31d40

BasepQueryAppCompat

Ordinal 100
Address 0x133c0

BasepQueryModuleChpeSettings

Ordinal 101
Address 0x41440

BasepReleaseAppXContext

Ordinal 102
Address 0x32350

BasepReleaseSxsCreateProcessUtilityStruct

Ordinal 103
Address 0x18430

BasepReportFault

Ordinal 104
Address 0x3af00

BasepSetFileEncryptionCompression

Ordinal 105
Address 0x21980

Beep

Ordinal 106
Address 0x30650

BeginUpdateResourceA

Ordinal 107
Address 0x40580

BeginUpdateResourceW

Ordinal 108
Address 0x405d0

BindIoCompletionCallback

Ordinal 109
Address 0x58060

BuildCommDCBA

Ordinal 110
Address 0x39510

BuildCommDCBAndTimeoutsA

Ordinal 111
Address 0x39560

BuildCommDCBAndTimeoutsW

Ordinal 112
Address 0x39590

BuildCommDCBW

Ordinal 113
Address 0x39600

CallNamedPipeA

Ordinal 114
Address 0x58090

CallNamedPipeW

Ordinal 115
Address 0x23600

CallbackMayRunLong

Ordinal 116
Address 0x32b50

CancelDeviceWakeupRequest

Ordinal 117
Address 0x31c10

CancelIo

Ordinal 118
Address 0x32b80

CancelIoEx

Ordinal 119
Address 0x21ce0

CancelSynchronousIo

Ordinal 120
Address 0x32ba0

CancelThreadpoolIo

Ordinal 121
Address 0x979b4
ForwardName NTDLL.TpCancelAsyncIoOperation

CancelTimerQueueTimer

Ordinal 122
Address 0x3ae60

CancelWaitableTimer

Ordinal 123
Address 0x22f20

CeipIsOptedIn

Ordinal 124
Address 0x97a0b
ForwardName kernelbase.CeipIsOptedIn

ChangeTimerQueueTimer

Ordinal 125
Address 0x32bc0

CheckAllowDecryptedRemoteDestinationPolicy

Ordinal 126
Address 0x32be0

CheckElevation

Ordinal 127
Address 0x12f10

CheckElevationEnabled

Ordinal 128
Address 0x18d30

CheckForReadOnlyResource

Ordinal 129
Address 0x58390

CheckForReadOnlyResourceFilter

Ordinal 130
Address 0x352d0

CheckIsMSIXPackage

Ordinal 131
Address 0x97ad5
ForwardName kernelbase.CheckIsMSIXPackage

CheckNameLegalDOS8Dot3A

Ordinal 132
Address 0x31ab0

CheckNameLegalDOS8Dot3W

Ordinal 133
Address 0x31b20

CheckRemoteDebuggerPresent

Ordinal 134
Address 0x32bf0

CheckTokenCapability

Ordinal 135
Address 0x32c10

CheckTokenMembershipEx

Ordinal 136
Address 0x32c30

ClearCommBreak

Ordinal 137
Address 0x236a0

ClearCommError

Ordinal 138
Address 0x236b0

CloseConsoleHandle

Ordinal 139
Address 0x602d0

CloseHandle

Ordinal 140
Address 0x22ee0

ClosePackageInfo

Ordinal 141
Address 0x97bb8
ForwardName kernelbase.ClosePackageInfo

ClosePrivateNamespace

Ordinal 142
Address 0x199f0

CloseProfileUserMapping

Ordinal 143
Address 0x221f0

ClosePseudoConsole

Ordinal 144
Address 0x23880

CloseState

Ordinal 145
Address 0x97c20
ForwardName kernelbase.CloseState

CloseThreadpool

Ordinal 146
Address 0x97c46
ForwardName NTDLL.TpReleasePool

CloseThreadpoolCleanupGroup

Ordinal 147
Address 0x97c76
ForwardName NTDLL.TpReleaseCleanupGroup

CloseThreadpoolCleanupGroupMembers

Ordinal 148
Address 0x97cb5
ForwardName NTDLL.TpReleaseCleanupGroupMembers

CloseThreadpoolIo

Ordinal 149
Address 0x97cea
ForwardName NTDLL.TpReleaseIoCompletion

CloseThreadpoolTimer

Ordinal 150
Address 0x97d1b
ForwardName NTDLL.TpReleaseTimer

CloseThreadpoolWait

Ordinal 151
Address 0x97d44
ForwardName NTDLL.TpReleaseWait

CloseThreadpoolWork

Ordinal 152
Address 0x97d6c
ForwardName NTDLL.TpReleaseWork

CmdBatNotification

Ordinal 153
Address 0x317d0

CommConfigDialogA

Ordinal 154
Address 0x35cc0

CommConfigDialogW

Ordinal 155
Address 0x35d50

CompareCalendarDates

Ordinal 156
Address 0x42650

CompareFileTime

Ordinal 157
Address 0x230f0

CompareStringA

Ordinal 158
Address 0x17d40

CompareStringEx

Ordinal 159
Address 0x195e0

CompareStringOrdinal

Ordinal 160
Address 0x16210

CompareStringW

Ordinal 161
Address 0x1dfd0

ConnectNamedPipe

Ordinal 162
Address 0x22390

ConsoleMenuControl

Ordinal 163
Address 0x60390

ContinueDebugEvent

Ordinal 164
Address 0x32c50

ConvertCalDateTimeToSystemTime

Ordinal 165
Address 0x426e0

ConvertDefaultLocale

Ordinal 166
Address 0x32c70

ConvertFiberToThread

Ordinal 167
Address 0x237f0

ConvertNLSDayOfWeekToWin32DayOfWeek

Ordinal 168
Address 0x427a0

ConvertSystemTimeToCalDateTime

Ordinal 169
Address 0x427d0

ConvertThreadToFiber

Ordinal 170
Address 0x23800

ConvertThreadToFiberEx

Ordinal 171
Address 0x23810

CopyContext

Ordinal 172
Address 0x32c90

CopyFile2

Ordinal 173
Address 0x32cb0

CopyFileA

Ordinal 174
Address 0x18b60

CopyFileExA

Ordinal 175
Address 0x58640

CopyFileExW

Ordinal 176
Address 0x19730

CopyFileTransactedA

Ordinal 177
Address 0x586b0

CopyFileTransactedW

Ordinal 178
Address 0x58750

CopyFileW

Ordinal 179
Address 0x237e0

CopyLZFile

Ordinal 180
Address 0x30750

CreateActCtxA

Ordinal 181
Address 0x58dc0

CreateActCtxW

Ordinal 182
Address 0x21f40

CreateActCtxWWorker

Ordinal 183
Address 0x19a30

CreateBoundaryDescriptorA

Ordinal 184
Address 0x58500

CreateBoundaryDescriptorW

Ordinal 185
Address 0x19710

CreateConsoleScreenBuffer

Ordinal 186
Address 0x239a0

CreateDirectoryA

Ordinal 187
Address 0x23100

CreateDirectoryExA

Ordinal 188
Address 0x59100

CreateDirectoryExW

Ordinal 189
Address 0x32cd0

CreateDirectoryTransactedA

Ordinal 190
Address 0x309a0

CreateDirectoryTransactedW

Ordinal 191
Address 0x59160

CreateDirectoryW

Ordinal 192
Address 0x23110

CreateEnclave

Ordinal 193
Address 0x9808d
ForwardName api-ms-win-core-enclave-l1-1-0.CreateEnclave

CreateEventA

Ordinal 194
Address 0x22f30

CreateEventExA

Ordinal 195
Address 0x22f40

CreateEventExW

Ordinal 196
Address 0x22f50

CreateEventW

Ordinal 197
Address 0x22f60

CreateFiber

Ordinal 198
Address 0x23820

CreateFiberEx

Ordinal 199
Address 0x23830

CreateFile2

Ordinal 200
Address 0x23120

CreateFileA

Ordinal 201
Address 0x23130

CreateFileMappingA

Ordinal 202
Address 0x116b0

CreateFileMappingFromApp

Ordinal 203
Address 0x98150
ForwardName api-ms-win-core-memory-l1-1-1.CreateFileMappingFromApp

CreateFileMappingNumaA

Ordinal 204
Address 0x59290

CreateFileMappingNumaW

Ordinal 205
Address 0x32cf0

CreateFileMappingW

Ordinal 206
Address 0x204a0

CreateFileTransactedA

Ordinal 207
Address 0x587f0

CreateFileTransactedW

Ordinal 208
Address 0x58850

CreateFileW

Ordinal 209
Address 0x23140

CreateHardLinkA

Ordinal 210
Address 0x32d10

CreateHardLinkTransactedA

Ordinal 211
Address 0x3a4d0

CreateHardLinkTransactedW

Ordinal 212
Address 0x592f0

CreateHardLinkW

Ordinal 213
Address 0x32d30

CreateIoCompletionPort

Ordinal 214
Address 0x222a0

CreateJobObjectA

Ordinal 215
Address 0x539a0

CreateJobObjectW

Ordinal 216
Address 0x539f0

CreateJobSet

Ordinal 217
Address 0x53a70

CreateMailslotA

Ordinal 218
Address 0x59380

CreateMailslotW

Ordinal 219
Address 0x593d0

CreateMemoryResourceNotification

Ordinal 220
Address 0x19950

CreateMutexA

Ordinal 221
Address 0x22f70

CreateMutexExA

Ordinal 222
Address 0x22f80

CreateMutexExW

Ordinal 223
Address 0x22f90

CreateMutexW

Ordinal 224
Address 0x22fa0

CreateNamedPipeA

Ordinal 225
Address 0x222c0

CreateNamedPipeW

Ordinal 226
Address 0x32d50

CreatePipe

Ordinal 227
Address 0x32d70

CreatePrivateNamespaceA

Ordinal 228
Address 0x58560

CreatePrivateNamespaceW

Ordinal 229
Address 0x195c0

CreateProcessA

Ordinal 230
Address 0x32d90

CreateProcessAsUserA

Ordinal 231
Address 0x32db0

CreateProcessAsUserW

Ordinal 232
Address 0x32dd0

CreateProcessInternalA

Ordinal 233
Address 0x32df0

CreateProcessInternalW

Ordinal 234
Address 0x32e10

CreateProcessW

Ordinal 235
Address 0x188e0

CreatePseudoConsole

Ordinal 236
Address 0x23890

CreateRemoteThread

Ordinal 237
Address 0x32e30

CreateRemoteThreadEx

Ordinal 238
Address 0x98422
ForwardName api-ms-win-core-processthreads-l1-1-0.CreateRemoteThreadEx

CreateSemaphoreA

Ordinal 239
Address 0x16230

CreateSemaphoreExA

Ordinal 240
Address 0x16260

CreateSemaphoreExW

Ordinal 241
Address 0x22fb0

CreateSemaphoreW

Ordinal 242
Address 0x22fc0

CreateSocketHandle

Ordinal 243
Address 0x3a550

CreateSymbolicLinkA

Ordinal 244
Address 0x59820

CreateSymbolicLinkTransactedA

Ordinal 245
Address 0x598a0

CreateSymbolicLinkTransactedW

Ordinal 246
Address 0x59920

CreateSymbolicLinkW

Ordinal 247
Address 0x32e70

CreateTapePartition

Ordinal 248
Address 0x3a270

CreateThread

Ordinal 249
Address 0x20f10

CreateThreadpool

Ordinal 250
Address 0x32ee0

CreateThreadpoolCleanupGroup

Ordinal 251
Address 0x32e90

CreateThreadpoolIo

Ordinal 252
Address 0x32ec0

CreateThreadpoolTimer

Ordinal 253
Address 0x21d00

CreateThreadpoolWait

Ordinal 254
Address 0x211b0

CreateThreadpoolWork

Ordinal 255
Address 0x218c0

CreateTimerQueue

Ordinal 256
Address 0x32f10

CreateTimerQueueTimer

Ordinal 257
Address 0x32f20

CreateToolhelp32Snapshot

Ordinal 258
Address 0x24120

CreateWaitableTimerA

Ordinal 259
Address 0x17cd0

CreateWaitableTimerExA

Ordinal 260
Address 0x17d00

CreateWaitableTimerExW

Ordinal 261
Address 0x22fd0

CreateWaitableTimerW

Ordinal 262
Address 0x59610

CtrlRoutine

Ordinal 263
Address 0x98662
ForwardName kernelbase.CtrlRoutine

DeactivateActCtx

Ordinal 264
Address 0x20aa0

DeactivateActCtxWorker

Ordinal 265
Address 0x203d0

DebugActiveProcess

Ordinal 266
Address 0x32f60

DebugActiveProcessStop

Ordinal 267
Address 0x32f40

DebugBreak

Ordinal 268
Address 0x32f80

DebugBreakProcess

Ordinal 269
Address 0x30900

DebugSetProcessKillOnExit

Ordinal 270
Address 0x30930

DecodePointer

Ordinal 271
Address 0x98710
ForwardName NTDLL.RtlDecodePointer

DecodeSystemPointer

Ordinal 272
Address 0x9873b
ForwardName NTDLL.RtlDecodeSystemPointer

DefineDosDeviceA

Ordinal 273
Address 0x5ace0

DefineDosDeviceW

Ordinal 274
Address 0x23150

DelayLoadFailureHook

Ordinal 275
Address 0x32f90

DeleteAtom

Ordinal 276
Address 0x12ed0

DeleteBoundaryDescriptor

Ordinal 277
Address 0x197d0

DeleteCriticalSection

Ordinal 278
Address 0x987c9
ForwardName NTDLL.RtlDeleteCriticalSection

DeleteFiber

Ordinal 279
Address 0x23840

DeleteFileA

Ordinal 280
Address 0x23160

DeleteFileTransactedA

Ordinal 281
Address 0x599b0

DeleteFileTransactedW

Ordinal 282
Address 0x599f0

DeleteFileW

Ordinal 283
Address 0x23170

DeleteProcThreadAttributeList

Ordinal 284
Address 0x98856
ForwardName api-ms-win-core-processthreads-l1-1-0.DeleteProcThreadAttributeList

DeleteSynchronizationBarrier

Ordinal 285
Address 0x32fb0

DeleteTimerQueue

Ordinal 286
Address 0x3ae90

DeleteTimerQueueEx

Ordinal 287
Address 0x32fd0

DeleteTimerQueueTimer

Ordinal 288
Address 0x32ff0

DeleteVolumeMountPointA

Ordinal 289
Address 0x5af20

DeleteVolumeMountPointW

Ordinal 290
Address 0x23180

DeviceIoControl

Ordinal 291
Address 0x1f5d0

DisableThreadLibraryCalls

Ordinal 292
Address 0x21930

DisableThreadProfiling

Ordinal 293
Address 0x3af30

DisassociateCurrentThreadFromCallback

Ordinal 294
Address 0x98988
ForwardName NTDLL.TpDisassociateCallback

DiscardVirtualMemory

Ordinal 295
Address 0x989ba
ForwardName api-ms-win-core-memory-l1-1-2.DiscardVirtualMemory

DisconnectNamedPipe

Ordinal 296
Address 0x33010

DnsHostnameToComputerNameA

Ordinal 297
Address 0x52c80

DnsHostnameToComputerNameExW

Ordinal 298
Address 0x33030

DnsHostnameToComputerNameW

Ordinal 299
Address 0x52d40

DosDateTimeToFileTime

Ordinal 300
Address 0x1b3e0

DosPathToSessionPathA

Ordinal 301
Address 0x5c6c0

DosPathToSessionPathW

Ordinal 302
Address 0x5c830

DuplicateConsoleHandle

Ordinal 303
Address 0x602f0

DuplicateEncryptionInfoFileExt

Ordinal 304
Address 0x31180

DuplicateHandle

Ordinal 305
Address 0x22ef0

EnableThreadProfiling

Ordinal 306
Address 0x3af60

EncodePointer

Ordinal 307
Address 0x98b00
ForwardName NTDLL.RtlEncodePointer

EncodeSystemPointer

Ordinal 308
Address 0x98b2b
ForwardName NTDLL.RtlEncodeSystemPointer

EndUpdateResourceA

Ordinal 309
Address 0x40780

EndUpdateResourceW

Ordinal 310
Address 0x40790

EnterCriticalSection

Ordinal 311
Address 0x98b83
ForwardName NTDLL.RtlEnterCriticalSection

EnterSynchronizationBarrier

Ordinal 312
Address 0x33050

EnumCalendarInfoA

Ordinal 313
Address 0x192b0

EnumCalendarInfoExA

Ordinal 314
Address 0x43600

EnumCalendarInfoExEx

Ordinal 315
Address 0x33070

EnumCalendarInfoExW

Ordinal 316
Address 0x19990

EnumCalendarInfoW

Ordinal 317
Address 0x33090

EnumDateFormatsA

Ordinal 318
Address 0x43660

EnumDateFormatsExA

Ordinal 319
Address 0x43690

EnumDateFormatsExEx

Ordinal 320
Address 0x330b0

EnumDateFormatsExW

Ordinal 321
Address 0x330d0

EnumDateFormatsW

Ordinal 322
Address 0x194a0

EnumLanguageGroupLocalesA

Ordinal 323
Address 0x436c0

EnumLanguageGroupLocalesW

Ordinal 324
Address 0x330f0

EnumResourceLanguagesA

Ordinal 325
Address 0x31500

EnumResourceLanguagesExA

Ordinal 326
Address 0x33110

EnumResourceLanguagesExW

Ordinal 327
Address 0x33130

EnumResourceLanguagesW

Ordinal 328
Address 0x31530

EnumResourceNamesA

Ordinal 329
Address 0x31560

EnumResourceNamesExA

Ordinal 330
Address 0x33150

EnumResourceNamesExW

Ordinal 331
Address 0x33170

EnumResourceNamesW

Ordinal 332
Address 0x235e0

EnumResourceTypesA

Ordinal 333
Address 0x31590

EnumResourceTypesExA

Ordinal 334
Address 0x33190

EnumResourceTypesExW

Ordinal 335
Address 0x331b0

EnumResourceTypesW

Ordinal 336
Address 0x315c0

EnumSystemCodePagesA

Ordinal 337
Address 0x436f0

EnumSystemCodePagesW

Ordinal 338
Address 0x331d0

EnumSystemFirmwareTables

Ordinal 339
Address 0x312f0

EnumSystemGeoID

Ordinal 340
Address 0x4b470

EnumSystemGeoNames

Ordinal 341
Address 0x4b520

EnumSystemLanguageGroupsA

Ordinal 342
Address 0x43710

EnumSystemLanguageGroupsW

Ordinal 343
Address 0x331f0

EnumSystemLocalesA

Ordinal 344
Address 0x33210

EnumSystemLocalesEx

Ordinal 345
Address 0x19520

EnumSystemLocalesW

Ordinal 346
Address 0x19680

EnumTimeFormatsA

Ordinal 347
Address 0x43730

EnumTimeFormatsEx

Ordinal 348
Address 0x33230

EnumTimeFormatsW

Ordinal 349
Address 0x196a0

EnumUILanguagesA

Ordinal 350
Address 0x43780

EnumUILanguagesW

Ordinal 351
Address 0x19600

EnumerateLocalComputerNamesA

Ordinal 352
Address 0x52e00

EnumerateLocalComputerNamesW

Ordinal 353
Address 0x52eb0

EraseTape

Ordinal 354
Address 0x3a2c0

EscapeCommFunction

Ordinal 355
Address 0x236c0

ExitProcess

Ordinal 356
Address 0x24100

ExitThread

Ordinal 357
Address 0x98f46
ForwardName NTDLL.RtlExitUserThread

ExitVDM

Ordinal 358
Address 0x381a0

ExpandEnvironmentStringsA

Ordinal 359
Address 0x22370

ExpandEnvironmentStringsW

Ordinal 360
Address 0x20ee0

ExpungeConsoleCommandHistoryA

Ordinal 361
Address 0x23c30

ExpungeConsoleCommandHistoryW

Ordinal 362
Address 0x23c40

FatalAppExitA

Ordinal 363
Address 0x33250

FatalAppExitW

Ordinal 364
Address 0x33260

FatalExit

Ordinal 365
Address 0x32490

FileTimeToDosDateTime

Ordinal 366
Address 0x1bb80

FileTimeToLocalFileTime

Ordinal 367
Address 0x23190

FileTimeToSystemTime

Ordinal 368
Address 0x23620

FillConsoleOutputAttribute

Ordinal 369
Address 0x239b0

FillConsoleOutputCharacterA

Ordinal 370
Address 0x239c0

FillConsoleOutputCharacterW

Ordinal 371
Address 0x239d0

FindActCtxSectionGuid

Ordinal 372
Address 0x1f630

FindActCtxSectionGuidWorker

Ordinal 373
Address 0x1bc50

FindActCtxSectionStringA

Ordinal 374
Address 0x5c980

FindActCtxSectionStringW

Ordinal 375
Address 0x18900

FindActCtxSectionStringWWorker

Ordinal 376
Address 0x162d0

FindAtomA

Ordinal 377
Address 0x187e0

FindAtomW

Ordinal 378
Address 0x1ba00

FindClose

Ordinal 379
Address 0x231a0

FindCloseChangeNotification

Ordinal 380
Address 0x231b0

FindFirstChangeNotificationA

Ordinal 381
Address 0x231c0

FindFirstChangeNotificationW

Ordinal 382
Address 0x231d0

FindFirstFileA

Ordinal 383
Address 0x231e0

FindFirstFileExA

Ordinal 384
Address 0x231f0

FindFirstFileExW

Ordinal 385
Address 0x23200

FindFirstFileNameTransactedW

Ordinal 386
Address 0x30a60

FindFirstFileNameW

Ordinal 387
Address 0x23210

FindFirstFileTransactedA

Ordinal 388
Address 0x30b00

FindFirstFileTransactedW

Ordinal 389
Address 0x5c9e0

FindFirstFileW

Ordinal 390
Address 0x23220

FindFirstStreamTransactedW

Ordinal 391
Address 0x30ba0

FindFirstStreamW

Ordinal 392
Address 0x99257
ForwardName api-ms-win-core-file-l1-2-2.FindFirstStreamW

FindFirstVolumeA

Ordinal 393
Address 0x5af60

FindFirstVolumeMountPointA

Ordinal 394
Address 0x5b080

FindFirstVolumeMountPointW

Ordinal 395
Address 0x5b1c0

FindFirstVolumeW

Ordinal 396
Address 0x23230

FindNLSString

Ordinal 397
Address 0x33270

FindNLSStringEx

Ordinal 398
Address 0x19020

FindNextChangeNotification

Ordinal 399
Address 0x23240

FindNextFileA

Ordinal 400
Address 0x23250

FindNextFileNameW

Ordinal 401
Address 0x23260

FindNextFileW

Ordinal 402
Address 0x23270

FindNextStreamW

Ordinal 403
Address 0x99353
ForwardName api-ms-win-core-file-l1-2-2.FindNextStreamW

FindNextVolumeA

Ordinal 404
Address 0x5b380

FindNextVolumeMountPointA

Ordinal 405
Address 0x5b4a0

FindNextVolumeMountPointW

Ordinal 406
Address 0x5ba00

FindNextVolumeW

Ordinal 407
Address 0x23280

FindPackagesByPackageFamily

Ordinal 408
Address 0x993ef
ForwardName kernelbase.FindPackagesByPackageFamily

FindResourceA

Ordinal 409
Address 0x12eb0

FindResourceExA

Ordinal 410
Address 0x1b210

FindResourceExW

Ordinal 411
Address 0x1fbc0

FindResourceW

Ordinal 412
Address 0x11f60

FindStringOrdinal

Ordinal 413
Address 0x33290

FindVolumeClose

Ordinal 414
Address 0x23290

FindVolumeMountPointClose

Ordinal 415
Address 0x5ba20

FlsAlloc

Ordinal 416
Address 0x21e20

FlsFree

Ordinal 417
Address 0x22050

FlsGetValue

Ordinal 418
Address 0x1e770

FlsSetValue

Ordinal 419
Address 0x211e0

FlushConsoleInputBuffer

Ordinal 420
Address 0x239e0

FlushFileBuffers

Ordinal 421
Address 0x232a0

FlushInstructionCache

Ordinal 422
Address 0x20f50

FlushProcessWriteBuffers

Ordinal 423
Address 0x9950f
ForwardName NTDLL.NtFlushProcessWriteBuffers

FlushViewOfFile

Ordinal 424
Address 0x19a10

FoldStringA

Ordinal 425
Address 0x437a0

FoldStringW

Ordinal 426
Address 0x18c10

FormatApplicationUserModelId

Ordinal 427
Address 0x99575
ForwardName kernelbase.FormatApplicationUserModelId

FormatMessageA

Ordinal 428
Address 0x18c30

FormatMessageW

Ordinal 429
Address 0x21bc0

FreeConsole

Ordinal 430
Address 0x238a0

FreeEnvironmentStringsA

Ordinal 431
Address 0x332b0

FreeEnvironmentStringsW

Ordinal 432
Address 0x21ba0

FreeLibrary

Ordinal 433
Address 0x20ae0

FreeLibraryAndExitThread

Ordinal 434
Address 0x18ac0

FreeLibraryWhenCallbackReturns

Ordinal 435
Address 0x9963b
ForwardName NTDLL.TpCallbackUnloadDllOnCompletion

FreeMemoryJobObject

Ordinal 436
Address 0x30630

FreeResource

Ordinal 437
Address 0x21200

FreeUserPhysicalPages

Ordinal 438
Address 0x332d0

GenerateConsoleCtrlEvent

Ordinal 439
Address 0x239f0

GetACP

Ordinal 440
Address 0x203c0

GetActiveProcessorCount

Ordinal 441
Address 0x21a90

GetActiveProcessorGroupCount

Ordinal 442
Address 0x5cae0

GetAppContainerAce

Ordinal 443
Address 0x332f0

GetAppContainerNamedObjectPath

Ordinal 444
Address 0x33310

GetApplicationRecoveryCallback

Ordinal 445
Address 0x33330

GetApplicationRecoveryCallbackWorker

Ordinal 446
Address 0x3ac40

GetApplicationRestartSettings

Ordinal 447
Address 0x33350

GetApplicationRestartSettingsWorker

Ordinal 448
Address 0x3acc0

GetApplicationUserModelId

Ordinal 449
Address 0x997bf
ForwardName kernelbase.GetApplicationUserModelId

GetAtomNameA

Ordinal 450
Address 0x52020

GetAtomNameW

Ordinal 451
Address 0x17a20

GetBinaryType

Ordinal 452
Address 0x57d20

GetBinaryTypeA

Ordinal 453
Address 0x57d20

GetBinaryTypeW

Ordinal 454
Address 0x57d60

GetCPInfo

Ordinal 455
Address 0x21530

GetCPInfoExA

Ordinal 456
Address 0x43980

GetCPInfoExW

Ordinal 457
Address 0x33370

GetCachedSigningLevel

Ordinal 458
Address 0x33390

GetCalendarDateFormat

Ordinal 459
Address 0x428a0

GetCalendarDateFormatEx

Ordinal 460
Address 0x42910

GetCalendarDaysInMonth

Ordinal 461
Address 0x42c80

GetCalendarDifferenceInDays

Ordinal 462
Address 0x42e10

GetCalendarInfoA

Ordinal 463
Address 0x43a20

GetCalendarInfoEx

Ordinal 464
Address 0x23630

GetCalendarInfoW

Ordinal 465
Address 0x23640

GetCalendarMonthsInYear

Ordinal 466
Address 0x42f00

GetCalendarSupportedDateRange

Ordinal 467
Address 0x42fc0

GetCalendarWeekNumber

Ordinal 468
Address 0x43070

GetComPlusPackageInstallStatus

Ordinal 469
Address 0x3ab60

GetCommConfig

Ordinal 470
Address 0x236d0

GetCommMask

Ordinal 471
Address 0x236e0

GetCommModemStatus

Ordinal 472
Address 0x236f0

GetCommProperties

Ordinal 473
Address 0x23700

GetCommState

Ordinal 474
Address 0x23710

GetCommTimeouts

Ordinal 475
Address 0x23720

GetCommandLineA

Ordinal 476
Address 0x21ee0

GetCommandLineW

Ordinal 477
Address 0x21d70

GetCompressedFileSizeA

Ordinal 478
Address 0x333b0

GetCompressedFileSizeTransactedA

Ordinal 479
Address 0x59a80

GetCompressedFileSizeTransactedW

Ordinal 480
Address 0x59ad0

GetCompressedFileSizeW

Ordinal 481
Address 0x333d0

GetComputerNameA

Ordinal 482
Address 0x19080

GetComputerNameExA

Ordinal 483
Address 0x333f0

GetComputerNameExW

Ordinal 484
Address 0x22090

GetComputerNameW

Ordinal 485
Address 0x213a0

GetConsoleAliasA

Ordinal 486
Address 0x23c50

GetConsoleAliasExesA

Ordinal 487
Address 0x23c60

GetConsoleAliasExesLengthA

Ordinal 488
Address 0x23c70

GetConsoleAliasExesLengthW

Ordinal 489
Address 0x23c80

GetConsoleAliasExesW

Ordinal 490
Address 0x23c90

GetConsoleAliasW

Ordinal 491
Address 0x23ca0

GetConsoleAliasesA

Ordinal 492
Address 0x23cb0

GetConsoleAliasesLengthA

Ordinal 493
Address 0x23cc0

GetConsoleAliasesLengthW

Ordinal 494
Address 0x23cd0

GetConsoleAliasesW

Ordinal 495
Address 0x23ce0

GetConsoleCP

Ordinal 496
Address 0x238b0

GetConsoleCharType

Ordinal 497
Address 0x607e0

GetConsoleCommandHistoryA

Ordinal 498
Address 0x23cf0

GetConsoleCommandHistoryLengthA

Ordinal 499
Address 0x23d00

GetConsoleCommandHistoryLengthW

Ordinal 500
Address 0x23d10

GetConsoleCommandHistoryW

Ordinal 501
Address 0x23d20

GetConsoleCursorInfo

Ordinal 502
Address 0x23a00

GetConsoleCursorMode

Ordinal 503
Address 0x60840

GetConsoleDisplayMode

Ordinal 504
Address 0x23d30

GetConsoleFontInfo

Ordinal 505
Address 0x60ae0

GetConsoleFontSize

Ordinal 506
Address 0x23d40

GetConsoleHardwareState

Ordinal 507
Address 0x603e0

GetConsoleHistoryInfo

Ordinal 508
Address 0x23d50

GetConsoleInputExeNameA

Ordinal 509
Address 0x99cb2
ForwardName kernelbase.GetConsoleInputExeNameA

GetConsoleInputExeNameW

Ordinal 510
Address 0x99ced
ForwardName kernelbase.GetConsoleInputExeNameW

GetConsoleInputWaitHandle

Ordinal 511
Address 0x60330

GetConsoleKeyboardLayoutNameA

Ordinal 512
Address 0x60b70

GetConsoleKeyboardLayoutNameW

Ordinal 513
Address 0x60b90

GetConsoleMode

Ordinal 514
Address 0x238c0

GetConsoleNlsMode

Ordinal 515
Address 0x608a0

GetConsoleOriginalTitleA

Ordinal 516
Address 0x23a10

GetConsoleOriginalTitleW

Ordinal 517
Address 0x23a20

GetConsoleOutputCP

Ordinal 518
Address 0x238d0

GetConsoleProcessList

Ordinal 519
Address 0x23d60

GetConsoleScreenBufferInfo

Ordinal 520
Address 0x23a30

GetConsoleScreenBufferInfoEx

Ordinal 521
Address 0x23a40

GetConsoleSelectionInfo

Ordinal 522
Address 0x23d70

GetConsoleTitleA

Ordinal 523
Address 0x23a50

GetConsoleTitleW

Ordinal 524
Address 0x23a60

GetConsoleWindow

Ordinal 525
Address 0x23d80

GetCurrencyFormatA

Ordinal 526
Address 0x43bf0

GetCurrencyFormatEx

Ordinal 527
Address 0x33410

GetCurrencyFormatW

Ordinal 528
Address 0x33430

GetCurrentActCtx

Ordinal 529
Address 0x33460

GetCurrentActCtxWorker

Ordinal 530
Address 0x20820

GetCurrentApplicationUserModelId

Ordinal 531
Address 0x99ee8
ForwardName kernelbase.GetCurrentApplicationUserModelId

GetCurrentConsoleFont

Ordinal 532
Address 0x23d90

GetCurrentConsoleFontEx

Ordinal 533
Address 0x23da0

GetCurrentDirectoryA

Ordinal 534
Address 0x33480

GetCurrentDirectoryW

Ordinal 535
Address 0x18ae0

GetCurrentPackageFamilyName

Ordinal 536
Address 0x99f88
ForwardName kernelbase.GetCurrentPackageFamilyName

GetCurrentPackageFullName

Ordinal 537
Address 0x99fc9
ForwardName kernelbase.GetCurrentPackageFullName

GetCurrentPackageId

Ordinal 538
Address 0x9a002
ForwardName kernelbase.GetCurrentPackageId

GetCurrentPackageInfo

Ordinal 539
Address 0x9a037
ForwardName kernelbase.GetCurrentPackageInfo

GetCurrentPackagePath

Ordinal 540
Address 0x9a06e
ForwardName kernelbase.GetCurrentPackagePath

GetCurrentProcess

Ordinal 541
Address 0x22e80

GetCurrentProcessId

Ordinal 542
Address 0x22e90

GetCurrentProcessorNumber

Ordinal 543
Address 0x9a0cf
ForwardName NTDLL.RtlGetCurrentProcessorNumber

GetCurrentProcessorNumberEx

Ordinal 544
Address 0x9a10e
ForwardName NTDLL.RtlGetCurrentProcessorNumberEx

GetCurrentThread

Ordinal 545
Address 0x1e7b0

GetCurrentThreadId

Ordinal 546
Address 0x1df10

GetCurrentThreadStackLimits

Ordinal 547
Address 0x9a173
ForwardName api-ms-win-core-processthreads-l1-1-0.GetCurrentThreadStackLimits

GetDateFormatA

Ordinal 548
Address 0x334a0

GetDateFormatAWorker

Ordinal 549
Address 0x43f20

GetDateFormatEx

Ordinal 550
Address 0x334c0

GetDateFormatW

Ordinal 551
Address 0x18bd0

GetDateFormatWWorker

Ordinal 552
Address 0x12070

GetDefaultCommConfigA

Ordinal 553
Address 0x35eb0

GetDefaultCommConfigW

Ordinal 554
Address 0x35f40

GetDevicePowerState

Ordinal 555
Address 0x5d090

GetDiskFreeSpaceA

Ordinal 556
Address 0x232b0

GetDiskFreeSpaceExA

Ordinal 557
Address 0x232c0

GetDiskFreeSpaceExW

Ordinal 558
Address 0x232d0

GetDiskFreeSpaceW

Ordinal 559
Address 0x232e0

GetDiskSpaceInformationA

Ordinal 560
Address 0x9a2b2
ForwardName api-ms-win-core-file-l1-2-3.GetDiskSpaceInformationA

GetDiskSpaceInformationW

Ordinal 561
Address 0x9a300
ForwardName api-ms-win-core-file-l1-2-3.GetDiskSpaceInformationW

GetDllDirectoryA

Ordinal 562
Address 0x315f0

GetDllDirectoryW

Ordinal 563
Address 0x5ca80

GetDriveTypeA

Ordinal 564
Address 0x232f0

GetDriveTypeW

Ordinal 565
Address 0x23300

GetDurationFormat

Ordinal 566
Address 0x44db0

GetDurationFormatEx

Ordinal 567
Address 0x334e0

GetDynamicTimeZoneInformation

Ordinal 568
Address 0x33510

GetEnabledXStateFeatures

Ordinal 569
Address 0x33530

GetEncryptedFileVersionExt

Ordinal 570
Address 0x31210

GetEnvironmentStrings

Ordinal 571
Address 0x33540

GetEnvironmentStringsA

Ordinal 572
Address 0x23690

GetEnvironmentStringsW

Ordinal 573
Address 0x21ef0

GetEnvironmentVariableA

Ordinal 574
Address 0x18990

GetEnvironmentVariableW

Ordinal 575
Address 0x20860

GetEraNameCountedString

Ordinal 576
Address 0x33550

GetErrorMode

Ordinal 577
Address 0x33570

GetExitCodeProcess

Ordinal 578
Address 0x194c0

GetExitCodeThread

Ordinal 579
Address 0x220e0

GetExpandedNameA

Ordinal 580
Address 0x353b0

GetExpandedNameW

Ordinal 581
Address 0x35490

GetFileAttributesA

Ordinal 582
Address 0x23310

GetFileAttributesExA

Ordinal 583
Address 0x23320

GetFileAttributesExW

Ordinal 584
Address 0x23330

GetFileAttributesTransactedA

Ordinal 585
Address 0x59b60

GetFileAttributesTransactedW

Ordinal 586
Address 0x59bb0

GetFileAttributesW

Ordinal 587
Address 0x23340

GetFileBandwidthReservation

Ordinal 588
Address 0x30c40

GetFileInformationByHandle

Ordinal 589
Address 0x23350

GetFileInformationByHandleEx

Ordinal 590
Address 0x22030

GetFileMUIInfo

Ordinal 591
Address 0x33580

GetFileMUIPath

Ordinal 592
Address 0x335a0

GetFileSize

Ordinal 593
Address 0x23360

GetFileSizeEx

Ordinal 594
Address 0x23370

GetFileTime

Ordinal 595
Address 0x23380

GetFileType

Ordinal 596
Address 0x23390

GetFinalPathNameByHandleA

Ordinal 597
Address 0x233a0

GetFinalPathNameByHandleW

Ordinal 598
Address 0x233b0

GetFirmwareEnvironmentVariableA

Ordinal 599
Address 0x5d240

GetFirmwareEnvironmentVariableExA

Ordinal 600
Address 0x5d270

GetFirmwareEnvironmentVariableExW

Ordinal 601
Address 0x5d330

GetFirmwareEnvironmentVariableW

Ordinal 602
Address 0x5d3d0

GetFirmwareType

Ordinal 603
Address 0x5d5c0

GetFullPathNameA

Ordinal 604
Address 0x233c0

GetFullPathNameTransactedA

Ordinal 605
Address 0x30830

GetFullPathNameTransactedW

Ordinal 606
Address 0x5d620

GetFullPathNameW

Ordinal 607
Address 0x233d0

GetGeoInfoA

Ordinal 608
Address 0x440d0

GetGeoInfoEx

Ordinal 609
Address 0x4b5e0

GetGeoInfoW

Ordinal 610
Address 0x4b710

GetHandleContext

Ordinal 611
Address 0x3a560

GetHandleInformation

Ordinal 612
Address 0x22f00

GetLargePageMinimum

Ordinal 613
Address 0x335c0

GetLargestConsoleWindowSize

Ordinal 614
Address 0x23a70

GetLastError

Ordinal 615
Address 0x1e010

GetLocalTime

Ordinal 616
Address 0x20b60

GetLocaleInfoA

Ordinal 617
Address 0x18410

GetLocaleInfoEx

Ordinal 618
Address 0x20c60

GetLocaleInfoW

Ordinal 619
Address 0x206a0

GetLogicalDriveStringsA

Ordinal 620
Address 0x5d6b0

GetLogicalDriveStringsW

Ordinal 621
Address 0x233e0

GetLogicalDrives

Ordinal 622
Address 0x189e0

GetLogicalProcessorInformation

Ordinal 623
Address 0x191c0

GetLogicalProcessorInformationEx

Ordinal 624
Address 0x9a85d
ForwardName api-ms-win-core-sysinfo-l1-1-0.GetLogicalProcessorInformationEx

GetLongPathNameA

Ordinal 625
Address 0x51c80

GetLongPathNameTransactedA

Ordinal 626
Address 0x38260

GetLongPathNameTransactedW

Ordinal 627
Address 0x57fd0

GetLongPathNameW

Ordinal 628
Address 0x1e260

GetMailslotInfo

Ordinal 629
Address 0x594e0

GetMaximumProcessorCount

Ordinal 630
Address 0x5cb20

GetMaximumProcessorGroupCount

Ordinal 631
Address 0x5cbb0

GetMemoryErrorHandlingCapabilities

Ordinal 632
Address 0x335d0

GetModuleFileNameA

Ordinal 633
Address 0x20e30

GetModuleFileNameW

Ordinal 634
Address 0x20900

GetModuleHandleA

Ordinal 635
Address 0x20a60

GetModuleHandleExA

Ordinal 636
Address 0x189b0

GetModuleHandleExW

Ordinal 637
Address 0x21640

GetModuleHandleW

Ordinal 638
Address 0x20e50

GetNLSVersion

Ordinal 639
Address 0x19870

GetNLSVersionEx

Ordinal 640
Address 0x335f0

GetNamedPipeAttribute

Ordinal 641
Address 0x33610

GetNamedPipeClientComputerNameA

Ordinal 642
Address 0x580e0

GetNamedPipeClientComputerNameW

Ordinal 643
Address 0x33630

GetNamedPipeClientProcessId

Ordinal 644
Address 0x581f0

GetNamedPipeClientSessionId

Ordinal 645
Address 0x317e0

GetNamedPipeHandleStateA

Ordinal 646
Address 0x58220

GetNamedPipeHandleStateW

Ordinal 647
Address 0x33650

GetNamedPipeInfo

Ordinal 648
Address 0x9aabc
ForwardName api-ms-win-core-namedpipe-l1-2-1.GetNamedPipeInfo

GetNamedPipeServerProcessId

Ordinal 649
Address 0x58320

GetNamedPipeServerSessionId

Ordinal 650
Address 0x31830

GetNativeSystemInfo

Ordinal 651
Address 0x21eb0

GetNextVDMCommand

Ordinal 652
Address 0x382f0

GetNumaAvailableMemoryNode

Ordinal 653
Address 0x319c0

GetNumaAvailableMemoryNodeEx

Ordinal 654
Address 0x5dae0

GetNumaHighestNodeNumber

Ordinal 655
Address 0x198f0

GetNumaNodeNumberFromHandle

Ordinal 656
Address 0x319e0

GetNumaNodeProcessorMask

Ordinal 657
Address 0x5db50

GetNumaNodeProcessorMaskEx

Ordinal 658
Address 0x33670

GetNumaProcessorNode

Ordinal 659
Address 0x31a30

GetNumaProcessorNodeEx

Ordinal 660
Address 0x5dbc0

GetNumaProximityNode

Ordinal 661
Address 0x31a80

GetNumaProximityNodeEx

Ordinal 662
Address 0x33690

GetNumberFormatA

Ordinal 663
Address 0x44160

GetNumberFormatEx

Ordinal 664
Address 0x336b0

GetNumberFormatW

Ordinal 665
Address 0x18880

GetNumberOfConsoleFonts

Ordinal 666
Address 0x60c20

GetNumberOfConsoleInputEvents

Ordinal 667
Address 0x238e0

GetNumberOfConsoleMouseButtons

Ordinal 668
Address 0x23db0

GetOEMCP

Ordinal 669
Address 0x22190

GetOverlappedResult

Ordinal 670
Address 0x1e790

GetOverlappedResultEx

Ordinal 671
Address 0x9ad01
ForwardName api-ms-win-core-io-l1-1-1.GetOverlappedResultEx

GetPackageApplicationIds

Ordinal 672
Address 0x9ad4a
ForwardName kernelbase.GetPackageApplicationIds

GetPackageFamilyName

Ordinal 673
Address 0x9ad83
ForwardName kernelbase.GetPackageFamilyName

GetPackageFullName

Ordinal 674
Address 0x9adb6
ForwardName kernelbase.GetPackageFullName

GetPackageId

Ordinal 675
Address 0x9ade1
ForwardName kernelbase.GetPackageId

GetPackageInfo

Ordinal 676
Address 0x9ae08
ForwardName kernelbase.GetPackageInfo

GetPackagePath

Ordinal 677
Address 0x9ae31
ForwardName kernelbase.GetPackagePath

GetPackagePathByFullName

Ordinal 678
Address 0x9ae64
ForwardName kernelbase.GetPackagePathByFullName

GetPackagesByPackageFamily

Ordinal 679
Address 0x9aea3
ForwardName kernelbase.GetPackagesByPackageFamily

GetPhysicallyInstalledSystemMemory

Ordinal 680
Address 0x336d0

GetPriorityClass

Ordinal 681
Address 0x336f0

GetPrivateProfileIntA

Ordinal 682
Address 0x1b4b0

GetPrivateProfileIntW

Ordinal 683
Address 0x112c0

GetPrivateProfileSectionA

Ordinal 684
Address 0x574a0

GetPrivateProfileSectionNamesA

Ordinal 685
Address 0x57530

GetPrivateProfileSectionNamesW

Ordinal 686
Address 0x11390

GetPrivateProfileSectionW

Ordinal 687
Address 0x17d60

GetPrivateProfileStringA

Ordinal 688
Address 0x1b530

GetPrivateProfileStringW

Ordinal 689
Address 0x113c0

GetPrivateProfileStructA

Ordinal 690
Address 0x57560

GetPrivateProfileStructW

Ordinal 691
Address 0x576b0

GetProcAddress

Ordinal 692
Address 0x1f550

GetProcessAffinityMask

Ordinal 693
Address 0x21e40

GetProcessDEPPolicy

Ordinal 694
Address 0x324b0

GetProcessDefaultCpuSets

Ordinal 695
Address 0x9b052
ForwardName api-ms-win-core-processthreads-l1-1-3.GetProcessDefaultCpuSets

GetProcessGroupAffinity

Ordinal 696
Address 0x33710

GetProcessHandleCount

Ordinal 697
Address 0x33730

GetProcessHeap

Ordinal 698
Address 0x1f380

GetProcessHeaps

Ordinal 699
Address 0x33750

GetProcessId

Ordinal 700
Address 0x20c20

GetProcessIdOfThread

Ordinal 701
Address 0x21fd0

GetProcessInformation

Ordinal 702
Address 0x22ea0

GetProcessIoCounters

Ordinal 703
Address 0x21670

GetProcessMitigationPolicy

Ordinal 704
Address 0x9b146
ForwardName api-ms-win-core-processthreads-l1-1-1.GetProcessMitigationPolicy

GetProcessPreferredUILanguages

Ordinal 705
Address 0x33770

GetProcessPriorityBoost

Ordinal 706
Address 0x33790

GetProcessShutdownParameters

Ordinal 707
Address 0x337b0

GetProcessTimes

Ordinal 708
Address 0x1f320

GetProcessVersion

Ordinal 709
Address 0x18b00

GetProcessWorkingSetSize

Ordinal 710
Address 0x3ae00

GetProcessWorkingSetSizeEx

Ordinal 711
Address 0x337d0

GetProcessorSystemCycleTime

Ordinal 712
Address 0x9b24d
ForwardName api-ms-win-core-sysinfo-l1-2-2.GetProcessorSystemCycleTime

GetProductInfo

Ordinal 713
Address 0x22070

GetProfileIntA

Ordinal 714
Address 0x1b490

GetProfileIntW

Ordinal 715
Address 0x57830

GetProfileSectionA

Ordinal 716
Address 0x57850

GetProfileSectionW

Ordinal 717
Address 0x57870

GetProfileStringA

Ordinal 718
Address 0x19170

GetProfileStringW

Ordinal 719
Address 0x10490

GetQueuedCompletionStatus

Ordinal 720
Address 0x22280

GetQueuedCompletionStatusEx

Ordinal 721
Address 0x337f0

GetShortPathNameA

Ordinal 722
Address 0x16b60

GetShortPathNameW

Ordinal 723
Address 0x16ce0

GetStagedPackagePathByFullName

Ordinal 724
Address 0x9b378
ForwardName kernelbase.GetStagedPackagePathByFullName

GetStartupInfoA

Ordinal 725
Address 0x20c80

GetStartupInfoW

Ordinal 726
Address 0x21550

GetStateFolder

Ordinal 727
Address 0x9b3d1
ForwardName kernelbase.GetStateFolder

GetStdHandle

Ordinal 728
Address 0x21700

GetStringScripts

Ordinal 729
Address 0x33810

GetStringTypeA

Ordinal 730
Address 0x198d0

GetStringTypeExA

Ordinal 731
Address 0x198d0

GetStringTypeExW

Ordinal 732
Address 0x11f40

GetStringTypeW

Ordinal 733
Address 0x20c40

GetSystemAppDataKey

Ordinal 734
Address 0x9b45d
ForwardName kernelbase.GetSystemAppDataKey

GetSystemCpuSetInformation

Ordinal 735
Address 0x9b497
ForwardName api-ms-win-core-processthreads-l1-1-3.GetSystemCpuSetInformation

GetSystemDEPPolicy

Ordinal 736
Address 0x324f0

GetSystemDefaultLCID

Ordinal 737
Address 0x17cb0

GetSystemDefaultLangID

Ordinal 738
Address 0x15120

GetSystemDefaultLocaleName

Ordinal 739
Address 0x33830

GetSystemDefaultUILanguage

Ordinal 740
Address 0x21920

GetSystemDirectoryA

Ordinal 741
Address 0x18480

GetSystemDirectoryW

Ordinal 742
Address 0x210b0

GetSystemFileCacheSize

Ordinal 743
Address 0x33850

GetSystemFirmwareTable

Ordinal 744
Address 0x31310

GetSystemInfo

Ordinal 745
Address 0x21910

GetSystemPowerStatus

Ordinal 746
Address 0x21440

GetSystemPreferredUILanguages

Ordinal 747
Address 0x33870

GetSystemRegistryQuota

Ordinal 748
Address 0x32530

GetSystemTime

Ordinal 749
Address 0x21660

GetSystemTimeAdjustment

Ordinal 750
Address 0x21ca0

GetSystemTimeAsFileTime

Ordinal 751
Address 0x1f390

GetSystemTimePreciseAsFileTime

Ordinal 752
Address 0x23610

GetSystemTimes

Ordinal 753
Address 0x33890

GetSystemWindowsDirectoryA

Ordinal 754
Address 0x338b0

GetSystemWindowsDirectoryW

Ordinal 755
Address 0x19500

GetSystemWow64DirectoryA

Ordinal 756
Address 0x237c0

GetSystemWow64DirectoryW

Ordinal 757
Address 0x237d0

GetTapeParameters

Ordinal 758
Address 0x5dd00

GetTapePosition

Ordinal 759
Address 0x3a300

GetTapeStatus

Ordinal 760
Address 0x3a370

GetTempFileNameA

Ordinal 761
Address 0x233f0

GetTempFileNameW

Ordinal 762
Address 0x23400

GetTempPathA

Ordinal 763
Address 0x23410

GetTempPathW

Ordinal 764
Address 0x23420

GetThreadContext

Ordinal 765
Address 0x338d0

GetThreadDescription

Ordinal 766
Address 0x9b761
ForwardName api-ms-win-core-processthreads-l1-1-3.GetThreadDescription

GetThreadErrorMode

Ordinal 767
Address 0x338f0

GetThreadGroupAffinity

Ordinal 768
Address 0x33900

GetThreadIOPendingFlag

Ordinal 769
Address 0x33920

GetThreadId

Ordinal 770
Address 0x33940

GetThreadIdealProcessorEx

Ordinal 771
Address 0x33960

GetThreadInformation

Ordinal 772
Address 0x22eb0

GetThreadLocale

Ordinal 773
Address 0x189d0

GetThreadPreferredUILanguages

Ordinal 774
Address 0x20760

GetThreadPriority

Ordinal 775
Address 0x20a80

GetThreadPriorityBoost

Ordinal 776
Address 0x33980

GetThreadSelectedCpuSets

Ordinal 777
Address 0x9b888
ForwardName api-ms-win-core-processthreads-l1-1-3.GetThreadSelectedCpuSets

GetThreadSelectorEntry

Ordinal 778
Address 0x5dd60

GetThreadTimes

Ordinal 779
Address 0x21f70

GetThreadUILanguage

Ordinal 780
Address 0x17530

GetTickCount64

Ordinal 781
Address 0x1c9c0

GetTickCount

Ordinal 782
Address 0x223a0

GetTimeFormatA

Ordinal 783
Address 0x339a0

GetTimeFormatAWorker

Ordinal 784
Address 0x44430

GetTimeFormatEx

Ordinal 785
Address 0x339c0

GetTimeFormatW

Ordinal 786
Address 0x17140

GetTimeFormatWWorker

Ordinal 787
Address 0x126c0

GetTimeZoneInformation

Ordinal 788
Address 0x21cc0

GetTimeZoneInformationForYear

Ordinal 789
Address 0x339e0

GetUILanguageInfo

Ordinal 790
Address 0x33a00

GetUserDefaultGeoName

Ordinal 791
Address 0x4bb40

GetUserDefaultLCID

Ordinal 792
Address 0x1e760

GetUserDefaultLangID

Ordinal 793
Address 0x19490

GetUserDefaultLocaleName

Ordinal 794
Address 0x22160

GetUserDefaultUILanguage

Ordinal 795
Address 0x21f60

GetUserGeoID

Ordinal 796
Address 0x11f80

GetUserPreferredUILanguages

Ordinal 797
Address 0x193e0

GetVDMCurrentDirectories

Ordinal 798
Address 0x38bd0

GetVersion

Ordinal 799
Address 0x21970

GetVersionExA

Ordinal 800
Address 0x21760

GetVersionExW

Ordinal 801
Address 0x218a0

GetVolumeInformationA

Ordinal 802
Address 0x23430

GetVolumeInformationByHandleW

Ordinal 803
Address 0x23440

GetVolumeInformationW

Ordinal 804
Address 0x23450

GetVolumeNameForVolumeMountPointA

Ordinal 805
Address 0x5ba70

GetVolumeNameForVolumeMountPointW

Ordinal 806
Address 0x22e70

GetVolumePathNameA

Ordinal 807
Address 0x5bbb0

GetVolumePathNameW

Ordinal 808
Address 0x23460

GetVolumePathNamesForVolumeNameA

Ordinal 809
Address 0x5bcf0

GetVolumePathNamesForVolumeNameW

Ordinal 810
Address 0x23470

GetWindowsDirectoryA

Ordinal 811
Address 0x21d50

GetWindowsDirectoryW

Ordinal 812
Address 0x19930

GetWriteWatch

Ordinal 813
Address 0x20590

GetXStateFeaturesMask

Ordinal 814
Address 0x33a20

GlobalAddAtomA

Ordinal 815
Address 0x1b510

GlobalAddAtomExA

Ordinal 816
Address 0x52040

GlobalAddAtomExW

Ordinal 817
Address 0x1b610

GlobalAddAtomW

Ordinal 818
Address 0x1b770

GlobalAlloc

Ordinal 819
Address 0x205f0

GlobalCompact

Ordinal 820
Address 0x31330

GlobalDeleteAtom

Ordinal 821
Address 0x20e90

GlobalFindAtomA

Ordinal 822
Address 0x161f0

GlobalFindAtomW

Ordinal 823
Address 0x1b8b0

GlobalFix

Ordinal 824
Address 0x31350

GlobalFlags

Ordinal 825
Address 0x18560

GlobalFree

Ordinal 826
Address 0x1ffc0

GlobalGetAtomNameA

Ordinal 827
Address 0x52060

GlobalGetAtomNameW

Ordinal 828
Address 0x1b630

GlobalHandle

Ordinal 829
Address 0x17de0

GlobalLock

Ordinal 830
Address 0x1e180

GlobalMemoryStatus

Ordinal 831
Address 0x14e90

GlobalMemoryStatusEx

Ordinal 832
Address 0x21de0

GlobalReAlloc

Ordinal 833
Address 0x1f1a0

GlobalSize

Ordinal 834
Address 0x204e0

GlobalUnWire

Ordinal 835
Address 0x31370

GlobalUnfix

Ordinal 836
Address 0x31380

GlobalUnlock

Ordinal 837
Address 0x1e0d0

GlobalWire

Ordinal 838
Address 0x313a0

Heap32First

Ordinal 839
Address 0x5a240

Heap32ListFirst

Ordinal 840
Address 0x5a480

Heap32ListNext

Ordinal 841
Address 0x5a530

Heap32Next

Ordinal 842
Address 0x5a5d0

HeapAlloc

Ordinal 843
Address 0x9bd75
ForwardName NTDLL.RtlAllocateHeap

HeapCompact

Ordinal 844
Address 0x33a40

HeapCreate

Ordinal 845
Address 0x20a40

HeapDestroy

Ordinal 846
Address 0x20bf0

HeapFree

Ordinal 847
Address 0x1df60

HeapLock

Ordinal 848
Address 0x33a60

HeapQueryInformation

Ordinal 849
Address 0x33a80

HeapReAlloc

Ordinal 850
Address 0x9bde1
ForwardName NTDLL.RtlReAllocateHeap

HeapSetInformation

Ordinal 851
Address 0x21780

HeapSize

Ordinal 852
Address 0x9be15
ForwardName NTDLL.RtlSizeHeap

HeapSummary

Ordinal 853
Address 0x33aa0

HeapUnlock

Ordinal 854
Address 0x33ac0

HeapValidate

Ordinal 855
Address 0x15100

HeapWalk

Ordinal 856
Address 0x33ae0

IdnToAscii

Ordinal 857
Address 0x33b00

IdnToNameprepUnicode

Ordinal 858
Address 0x33b20

IdnToUnicode

Ordinal 859
Address 0x33b40

InitAtomTable

Ordinal 860
Address 0x52080

InitOnceBeginInitialize

Ordinal 861
Address 0x9bea7
ForwardName api-ms-win-core-synch-l1-2-0.InitOnceBeginInitialize

InitOnceComplete

Ordinal 862
Address 0x9beed
ForwardName api-ms-win-core-synch-l1-2-0.InitOnceComplete

InitOnceExecuteOnce

Ordinal 863
Address 0x9bf2f
ForwardName api-ms-win-core-synch-l1-2-0.InitOnceExecuteOnce

InitOnceInitialize

Ordinal 864
Address 0x9bf73
ForwardName NTDLL.RtlRunOnceInitialize

InitializeConditionVariable

Ordinal 865
Address 0x9bfaa
ForwardName NTDLL.RtlInitializeConditionVariable

InitializeContext2

Ordinal 866
Address 0x33b60

InitializeContext

Ordinal 867
Address 0x33b90

InitializeCriticalSection

Ordinal 868
Address 0x9c00e
ForwardName NTDLL.RtlInitializeCriticalSection

InitializeCriticalSectionAndSpinCount

Ordinal 869
Address 0x22fe0

InitializeCriticalSectionEx

Ordinal 870
Address 0x22ff0

InitializeEnclave

Ordinal 871
Address 0x9c085
ForwardName api-ms-win-core-enclave-l1-1-0.InitializeEnclave

InitializeProcThreadAttributeList

Ordinal 872
Address 0x9c0d8
ForwardName api-ms-win-core-processthreads-l1-1-0.InitializeProcThreadAttributeList

InitializeSListHead

Ordinal 873
Address 0x9c134
ForwardName NTDLL.RtlInitializeSListHead

InitializeSRWLock

Ordinal 874
Address 0x9c163
ForwardName NTDLL.RtlInitializeSRWLock

InitializeSynchronizationBarrier

Ordinal 875
Address 0x33bb0

InstallELAMCertificateInfo

Ordinal 876
Address 0x9c1ba
ForwardName api-ms-win-core-sysinfo-l1-2-1.InstallELAMCertificateInfo

InterlockedCompareExchange64

Ordinal 877
Address 0x9c211
ForwardName NTDLL.RtlInterlockedCompareExchange64

InterlockedCompareExchange

Ordinal 878
Address 0x14d30

InterlockedDecrement

Ordinal 879
Address 0x1e860

InterlockedExchange

Ordinal 880
Address 0x12e40

InterlockedExchangeAdd

Ordinal 881
Address 0x15bd0

InterlockedFlushSList

Ordinal 882
Address 0x9c2a8
ForwardName NTDLL.RtlInterlockedFlushSList

InterlockedIncrement

Ordinal 883
Address 0x1e7e0

InterlockedPopEntrySList

Ordinal 884
Address 0x9c2f5
ForwardName NTDLL.RtlInterlockedPopEntrySList

InterlockedPushEntrySList

Ordinal 885
Address 0x9c331
ForwardName NTDLL.RtlInterlockedPushEntrySList

InterlockedPushListSListEx

Ordinal 886
Address 0x9c36f
ForwardName NTDLL.RtlInterlockedPushListSListEx

InvalidateConsoleDIBits

Ordinal 887
Address 0x60d10

IsBadCodePtr

Ordinal 888
Address 0x100e0

IsBadHugeReadPtr

Ordinal 889
Address 0x325a0

IsBadHugeWritePtr

Ordinal 890
Address 0x325b0

IsBadReadPtr

Ordinal 891
Address 0x10100

IsBadStringPtrA

Ordinal 892
Address 0x11600

IsBadStringPtrW

Ordinal 893
Address 0x14cd0

IsBadWritePtr

Ordinal 894
Address 0x10010

IsCalendarLeapDay

Ordinal 895
Address 0x43280

IsCalendarLeapMonth

Ordinal 896
Address 0x43350

IsCalendarLeapYear

Ordinal 897
Address 0x43410

IsDBCSLeadByte

Ordinal 898
Address 0x11690

IsDBCSLeadByteEx

Ordinal 899
Address 0x33bd0

IsDebuggerPresent

Ordinal 900
Address 0x220d0

IsEnclaveTypeSupported

Ordinal 901
Address 0x9c498
ForwardName api-ms-win-core-enclave-l1-1-0.IsEnclaveTypeSupported

IsNLSDefinedString

Ordinal 902
Address 0x33bf0

IsNativeVhdBoot

Ordinal 903
Address 0x30690

IsNormalizedString

Ordinal 904
Address 0x33c10

IsProcessCritical

Ordinal 905
Address 0x9c516
ForwardName api-ms-win-core-processthreads-l1-1-2.IsProcessCritical

IsProcessInJob

Ordinal 906
Address 0x197b0

IsProcessorFeaturePresent

Ordinal 907
Address 0x20b70

IsSystemResumeAutomatic

Ordinal 908
Address 0x31c30

IsThreadAFiber

Ordinal 909
Address 0x33c30

IsThreadpoolTimerSet

Ordinal 910
Address 0x9c5b3
ForwardName NTDLL.TpIsTimerSet

IsUserCetAvailableInEnvironment

Ordinal 911
Address 0x9c5e6
ForwardName api-ms-win-core-sysinfo-l1-2-6.IsUserCetAvailableInEnvironment

IsValidCalDateTime

Ordinal 912
Address 0x434b0

IsValidCodePage

Ordinal 913
Address 0x216a0

IsValidLanguageGroup

Ordinal 914
Address 0x33c50

IsValidLocale

Ordinal 915
Address 0x21880

IsValidLocaleName

Ordinal 916
Address 0x33c70

IsValidNLSVersion

Ordinal 917
Address 0x33c90

IsWow64GuestMachineSupported

Ordinal 918
Address 0x9c6ac
ForwardName api-ms-win-core-wow64-l1-1-2.IsWow64GuestMachineSupported

IsWow64Process2

Ordinal 919
Address 0x9c6f6
ForwardName api-ms-win-core-wow64-l1-1-1.IsWow64Process2

IsWow64Process

Ordinal 920
Address 0x206e0

K32EmptyWorkingSet

Ordinal 921
Address 0x33cb0

K32EnumDeviceDrivers

Ordinal 922
Address 0x33cd0

K32EnumPageFilesA

Ordinal 923
Address 0x33cf0

K32EnumPageFilesW

Ordinal 924
Address 0x33d10

K32EnumProcessModules

Ordinal 925
Address 0x33d50

K32EnumProcessModulesEx

Ordinal 926
Address 0x33d30

K32EnumProcesses

Ordinal 927
Address 0x33d70

K32GetDeviceDriverBaseNameA

Ordinal 928
Address 0x33d90

K32GetDeviceDriverBaseNameW

Ordinal 929
Address 0x33db0

K32GetDeviceDriverFileNameA

Ordinal 930
Address 0x33dd0

K32GetDeviceDriverFileNameW

Ordinal 931
Address 0x33df0

K32GetMappedFileNameA

Ordinal 932
Address 0x33e10

K32GetMappedFileNameW

Ordinal 933
Address 0x33e30

K32GetModuleBaseNameA

Ordinal 934
Address 0x33e50

K32GetModuleBaseNameW

Ordinal 935
Address 0x33e70

K32GetModuleFileNameExA

Ordinal 936
Address 0x33e90

K32GetModuleFileNameExW

Ordinal 937
Address 0x33eb0

K32GetModuleInformation

Ordinal 938
Address 0x196f0

K32GetPerformanceInfo

Ordinal 939
Address 0x33ed0

K32GetProcessImageFileNameA

Ordinal 940
Address 0x33ef0

K32GetProcessImageFileNameW

Ordinal 941
Address 0x33f10

K32GetProcessMemoryInfo

Ordinal 942
Address 0x33f30

K32GetWsChanges

Ordinal 943
Address 0x33f70

K32GetWsChangesEx

Ordinal 944
Address 0x33f50

K32InitializeProcessForWsWatch

Ordinal 945
Address 0x33f90

K32QueryWorkingSet

Ordinal 946
Address 0x33fd0

K32QueryWorkingSetEx

Ordinal 947
Address 0x33fb0

LCIDToLocaleName

Ordinal 948
Address 0x21ec0

LCMapStringA

Ordinal 949
Address 0x198b0

LCMapStringEx

Ordinal 950
Address 0x18840

LCMapStringW

Ordinal 951
Address 0x20e70

LZClose

Ordinal 952
Address 0x35580

LZCloseFile

Ordinal 953
Address 0x35580

LZCopy

Ordinal 954
Address 0x30760

LZCreateFileW

Ordinal 955
Address 0x35610

LZDone

Ordinal 956
Address 0x22760

LZInit

Ordinal 957
Address 0x356e0

LZOpenFileA

Ordinal 958
Address 0x35830

LZOpenFileW

Ordinal 959
Address 0x35900

LZRead

Ordinal 960
Address 0x35990

LZSeek

Ordinal 961
Address 0x35bb0

LZStart

Ordinal 962
Address 0x221f0

LeaveCriticalSection

Ordinal 963
Address 0x9ca4f
ForwardName NTDLL.RtlLeaveCriticalSection

LeaveCriticalSectionWhenCallbackReturns

Ordinal 964
Address 0x9ca95
ForwardName NTDLL.TpCallbackLeaveCriticalSectionOnCompletion

LoadAppInitDlls

Ordinal 965
Address 0x1fff0

LoadEnclaveData

Ordinal 966
Address 0x9cae6
ForwardName api-ms-win-core-enclave-l1-1-0.LoadEnclaveData

LoadLibraryA

Ordinal 967
Address 0x20bd0

LoadLibraryExA

Ordinal 968
Address 0x21620

LoadLibraryExW

Ordinal 969
Address 0x1f3a0

LoadLibraryW

Ordinal 970
Address 0x216c0

LoadModule

Ordinal 971
Address 0x5cbf0

LoadPackagedLibrary

Ordinal 972
Address 0x235f0

LoadResource

Ordinal 973
Address 0x1e840

LoadStringBaseExW

Ordinal 974
Address 0x33ff0

LoadStringBaseW

Ordinal 975
Address 0x314d0

LocalAlloc

Ordinal 976
Address 0x20460

LocalCompact

Ordinal 977
Address 0x31330

LocalFileTimeToFileTime

Ordinal 978
Address 0x23480

LocalFileTimeToLocalSystemTime

Ordinal 979
Address 0x9cbea
ForwardName api-ms-win-core-timezone-l1-1-1.LocalFileTimeToLocalSystemTime

LocalFlags

Ordinal 980
Address 0x5ddc0

LocalFree

Ordinal 981
Address 0x1f530

LocalHandle

Ordinal 982
Address 0x313f0

LocalLock

Ordinal 983
Address 0x20700

LocalReAlloc

Ordinal 984
Address 0x18b40

LocalShrink

Ordinal 985
Address 0x314b0

LocalSize

Ordinal 986
Address 0x202d0

LocalSystemTimeToLocalFileTime

Ordinal 987
Address 0x9cc96
ForwardName api-ms-win-core-timezone-l1-1-1.LocalSystemTimeToLocalFileTime

LocalUnlock

Ordinal 988
Address 0x20720

LocaleNameToLCID

Ordinal 989
Address 0x21e00

LocateXStateFeature

Ordinal 990
Address 0x34010

LockFile

Ordinal 991
Address 0x23490

LockFileEx

Ordinal 992
Address 0x234a0

LockResource

Ordinal 993
Address 0x1f340

MapUserPhysicalPages

Ordinal 994
Address 0x34030

MapUserPhysicalPagesScatter

Ordinal 995
Address 0x3ae30

MapViewOfFile

Ordinal 996
Address 0x1f590

MapViewOfFileEx

Ordinal 997
Address 0x21170

MapViewOfFileExNuma

Ordinal 998
Address 0x34050

MapViewOfFileFromApp

Ordinal 999
Address 0x9cd9f
ForwardName api-ms-win-core-memory-l1-1-1.MapViewOfFileFromApp

Module32First

Ordinal 1000
Address 0x5a820

Module32FirstW

Ordinal 1001
Address 0x5a910

Module32Next

Ordinal 1002
Address 0x5a9c0

Module32NextW

Ordinal 1003
Address 0x5aab0

MoveFileA

Ordinal 1004
Address 0x1f3e0

MoveFileExA

Ordinal 1005
Address 0x59c40

MoveFileExW

Ordinal 1006
Address 0x199b0

MoveFileTransactedA

Ordinal 1007
Address 0x59c70

MoveFileTransactedW

Ordinal 1008
Address 0x59d00

MoveFileW

Ordinal 1009
Address 0x220b0

MoveFileWithProgressA

Ordinal 1010
Address 0x59da0

MoveFileWithProgressW

Ordinal 1011
Address 0x34070

MulDiv

Ordinal 1012
Address 0x22d30

MultiByteToWideChar

Ordinal 1013
Address 0x1df80

NeedCurrentDirectoryForExePathA

Ordinal 1014
Address 0x34090

NeedCurrentDirectoryForExePathW

Ordinal 1015
Address 0x340b0

NlsCheckPolicy

Ordinal 1016
Address 0x23650

NlsGetCacheUpdateCount

Ordinal 1017
Address 0x23660

NlsUpdateLocale

Ordinal 1018
Address 0x23670

NlsUpdateSystemLocale

Ordinal 1019
Address 0x23680

NormalizeString

Ordinal 1020
Address 0x340d0

NotifyMountMgr

Ordinal 1021
Address 0x340f0

NotifyUILanguageChange

Ordinal 1022
Address 0x46530

NtVdm64CreateProcessInternalW

Ordinal 1023
Address 0x325c0

OOBEComplete

Ordinal 1024
Address 0x5e0d0

OfferVirtualMemory

Ordinal 1025
Address 0x9cfa5
ForwardName api-ms-win-core-memory-l1-1-2.OfferVirtualMemory

OpenConsoleW

Ordinal 1026
Address 0x60340

OpenConsoleWStub

Ordinal 1027
Address 0x34100

OpenEventA

Ordinal 1028
Address 0x23000

OpenEventW

Ordinal 1029
Address 0x23010

OpenFile

Ordinal 1030
Address 0x58940

OpenFileById

Ordinal 1031
Address 0x34110

OpenFileMappingA

Ordinal 1032
Address 0x18780

OpenFileMappingW

Ordinal 1033
Address 0x21f00

OpenJobObjectA

Ordinal 1034
Address 0x53aa0

OpenJobObjectW

Ordinal 1035
Address 0x53b00

OpenMutexA

Ordinal 1036
Address 0x12e60

OpenMutexW

Ordinal 1037
Address 0x23020

OpenPackageInfoByFullName

Ordinal 1038
Address 0x9d090
ForwardName kernelbase.OpenPackageInfoByFullName

OpenPrivateNamespaceA

Ordinal 1039
Address 0x585c0

OpenPrivateNamespaceW

Ordinal 1040
Address 0x199d0

OpenProcess

Ordinal 1041
Address 0x20630

OpenProcessToken

Ordinal 1042
Address 0x9d0fe
ForwardName api-ms-win-core-processthreads-l1-1-0.OpenProcessToken

OpenProfileUserMapping

Ordinal 1043
Address 0x221f0

OpenSemaphoreA

Ordinal 1044
Address 0x22320

OpenSemaphoreW

Ordinal 1045
Address 0x23030

OpenState

Ordinal 1046
Address 0x9d174
ForwardName kernelbase.OpenState

OpenStateExplicit

Ordinal 1047
Address 0x9d19b
ForwardName kernelbase.OpenStateExplicit

OpenThread

Ordinal 1048
Address 0x1f5b0

OpenThreadToken

Ordinal 1049
Address 0x9d1d3
ForwardName api-ms-win-core-processthreads-l1-1-0.OpenThreadToken

OpenWaitableTimerA

Ordinal 1050
Address 0x59640

OpenWaitableTimerW

Ordinal 1051
Address 0x23040

OutputDebugStringA

Ordinal 1052
Address 0x19350

OutputDebugStringW

Ordinal 1053
Address 0x34130

PackageFamilyNameFromFullName

Ordinal 1054
Address 0x9d273
ForwardName kernelbase.PackageFamilyNameFromFullName

PackageFamilyNameFromId

Ordinal 1055
Address 0x9d2b4
ForwardName kernelbase.PackageFamilyNameFromId

PackageFullNameFromId

Ordinal 1056
Address 0x9d2ed
ForwardName kernelbase.PackageFullNameFromId

PackageIdFromFullName

Ordinal 1057
Address 0x9d324
ForwardName kernelbase.PackageIdFromFullName

PackageNameAndPublisherIdFromFamilyName

Ordinal 1058
Address 0x9d36d
ForwardName kernelbase.PackageNameAndPublisherIdFromFamilyName

ParseApplicationUserModelId

Ordinal 1059
Address 0x9d3bc
ForwardName kernelbase.ParseApplicationUserModelId

PeekConsoleInputA

Ordinal 1060
Address 0x238f0

PeekConsoleInputW

Ordinal 1061
Address 0x23900

PeekNamedPipe

Ordinal 1062
Address 0x34140

PostQueuedCompletionStatus

Ordinal 1063
Address 0x22260

PowerClearRequest

Ordinal 1064
Address 0x5d0e0

PowerCreateRequest

Ordinal 1065
Address 0x5d160

PowerSetRequest

Ordinal 1066
Address 0x5d1c0

PrefetchVirtualMemory

Ordinal 1067
Address 0x9d47b
ForwardName api-ms-win-core-memory-l1-1-1.PrefetchVirtualMemory

PrepareTape

Ordinal 1068
Address 0x3a3a0

PrivCopyFileExW

Ordinal 1069
Address 0x34160

PrivMoveFileIdentityW

Ordinal 1070
Address 0x59dd0

Process32First

Ordinal 1071
Address 0x191e0

Process32FirstW

Ordinal 1072
Address 0x21c00

Process32Next

Ordinal 1073
Address 0x17950

Process32NextW

Ordinal 1074
Address 0x20780

ProcessIdToSessionId

Ordinal 1075
Address 0x20b90

PssCaptureSnapshot

Ordinal 1076
Address 0x34180

PssDuplicateSnapshot

Ordinal 1077
Address 0x341a0

PssFreeSnapshot

Ordinal 1078
Address 0x341c0

PssQuerySnapshot

Ordinal 1079
Address 0x341e0

PssWalkMarkerCreate

Ordinal 1080
Address 0x34200

PssWalkMarkerFree

Ordinal 1081
Address 0x34220

PssWalkMarkerGetPosition

Ordinal 1082
Address 0x34240

PssWalkMarkerRewind

Ordinal 1083
Address 0x34260

PssWalkMarkerSeek

Ordinal 1084
Address 0x34280

PssWalkMarkerSeekToBeginning

Ordinal 1085
Address 0x34260

PssWalkMarkerSetPosition

Ordinal 1086
Address 0x34280

PssWalkMarkerTell

Ordinal 1087
Address 0x34240

PssWalkSnapshot

Ordinal 1088
Address 0x342a0

PulseEvent

Ordinal 1089
Address 0x342c0

PurgeComm

Ordinal 1090
Address 0x23730

QueryActCtxSettingsW

Ordinal 1091
Address 0x342e0

QueryActCtxSettingsWWorker

Ordinal 1092
Address 0x1b790

QueryActCtxW

Ordinal 1093
Address 0x18760

QueryActCtxWWorker

Ordinal 1094
Address 0x17aa0

QueryDepthSList

Ordinal 1095
Address 0x9d6ad
ForwardName NTDLL.RtlQueryDepthSList

QueryDosDeviceA

Ordinal 1096
Address 0x5ad60

QueryDosDeviceW

Ordinal 1097
Address 0x234b0

QueryFullProcessImageNameA

Ordinal 1098
Address 0x34300

QueryFullProcessImageNameW

Ordinal 1099
Address 0x34320

QueryIdleProcessorCycleTime

Ordinal 1100
Address 0x34360

QueryIdleProcessorCycleTimeEx

Ordinal 1101
Address 0x34340

QueryInformationJobObject

Ordinal 1102
Address 0x18c50

QueryIoRateControlInformationJobObject

Ordinal 1103
Address 0x53b90

QueryMemoryResourceNotification

Ordinal 1104
Address 0x34380

QueryPerformanceCounter

Ordinal 1105
Address 0x1df40

QueryPerformanceFrequency

Ordinal 1106
Address 0x216e0

QueryProcessAffinityUpdateMode

Ordinal 1107
Address 0x343a0

QueryProcessCycleTime

Ordinal 1108
Address 0x343c0

QueryProtectedPolicy

Ordinal 1109
Address 0x9d833
ForwardName api-ms-win-core-processthreads-l1-1-2.QueryProtectedPolicy

QueryThreadCycleTime

Ordinal 1110
Address 0x21be0

QueryThreadProfiling

Ordinal 1111
Address 0x3afa0

QueryThreadpoolStackInformation

Ordinal 1112
Address 0x343e0

QueryUnbiasedInterruptTime

Ordinal 1113
Address 0x22120

QueueUserAPC

Ordinal 1114
Address 0x19790

QueueUserWorkItem

Ordinal 1115
Address 0x21d30

QuirkGetData2Worker

Ordinal 1116
Address 0x41c30

QuirkGetDataWorker

Ordinal 1117
Address 0x41ce0

QuirkIsEnabled2Worker

Ordinal 1118
Address 0x41d80

QuirkIsEnabled3Worker

Ordinal 1119
Address 0x17900

QuirkIsEnabledForPackage2Worker

Ordinal 1120
Address 0x41eb0

QuirkIsEnabledForPackage3Worker

Ordinal 1121
Address 0x41ee0

QuirkIsEnabledForPackage4Worker

Ordinal 1122
Address 0x41f20

QuirkIsEnabledForPackageWorker

Ordinal 1123
Address 0x41f90

QuirkIsEnabledForProcessWorker

Ordinal 1124
Address 0x42000

QuirkIsEnabledWorker

Ordinal 1125
Address 0x1fbe0

RaiseException

Ordinal 1126
Address 0x205b0

RaiseFailFastException

Ordinal 1127
Address 0x9da1e
ForwardName kernelbase.RaiseFailFastException

RaiseInvalid16BitExeError

Ordinal 1128
Address 0x32760

ReOpenFile

Ordinal 1129
Address 0x34410

ReadConsoleA

Ordinal 1130
Address 0x23910

ReadConsoleInputA

Ordinal 1131
Address 0x23920

ReadConsoleInputExA

Ordinal 1132
Address 0x9da98
ForwardName kernelbase.ReadConsoleInputExA

ReadConsoleInputExW

Ordinal 1133
Address 0x9dacb
ForwardName kernelbase.ReadConsoleInputExW

ReadConsoleInputW

Ordinal 1134
Address 0x23930

ReadConsoleOutputA

Ordinal 1135
Address 0x23a80

ReadConsoleOutputAttribute

Ordinal 1136
Address 0x23a90

ReadConsoleOutputCharacterA

Ordinal 1137
Address 0x23aa0

ReadConsoleOutputCharacterW

Ordinal 1138
Address 0x23ab0

ReadConsoleOutputW

Ordinal 1139
Address 0x23ac0

ReadConsoleW

Ordinal 1140
Address 0x23940

ReadDirectoryChangesExW

Ordinal 1141
Address 0x34430

ReadDirectoryChangesW

Ordinal 1142
Address 0x34450

ReadFile

Ordinal 1143
Address 0x234c0

ReadFileEx

Ordinal 1144
Address 0x234d0

ReadFileScatter

Ordinal 1145
Address 0x234e0

ReadProcessMemory

Ordinal 1146
Address 0x34470

ReadThreadProfilingData

Ordinal 1147
Address 0x3afd0

ReclaimVirtualMemory

Ordinal 1148
Address 0x9dc13
ForwardName api-ms-win-core-memory-l1-1-2.ReclaimVirtualMemory

RegCloseKey

Ordinal 1149
Address 0x34490

RegCopyTreeW

Ordinal 1150
Address 0x344b0

RegCreateKeyExA

Ordinal 1151
Address 0x344d0

RegCreateKeyExW

Ordinal 1152
Address 0x344f0

RegDeleteKeyExA

Ordinal 1153
Address 0x34510

RegDeleteKeyExW

Ordinal 1154
Address 0x34530

RegDeleteTreeA

Ordinal 1155
Address 0x34550

RegDeleteTreeW

Ordinal 1156
Address 0x34570

RegDeleteValueA

Ordinal 1157
Address 0x34590

RegDeleteValueW

Ordinal 1158
Address 0x345b0

RegDisablePredefinedCacheEx

Ordinal 1159
Address 0x345d0

RegEnumKeyExA

Ordinal 1160
Address 0x345e0

RegEnumKeyExW

Ordinal 1161
Address 0x34600

RegEnumValueA

Ordinal 1162
Address 0x34620

RegEnumValueW

Ordinal 1163
Address 0x34640

RegFlushKey

Ordinal 1164
Address 0x34660

RegGetKeySecurity

Ordinal 1165
Address 0x34680

RegGetValueA

Ordinal 1166
Address 0x346a0

RegGetValueW

Ordinal 1167
Address 0x346c0

RegLoadKeyA

Ordinal 1168
Address 0x346e0

RegLoadKeyW

Ordinal 1169
Address 0x34700

RegLoadMUIStringA

Ordinal 1170
Address 0x34720

RegLoadMUIStringW

Ordinal 1171
Address 0x34740

RegNotifyChangeKeyValue

Ordinal 1172
Address 0x34760

RegOpenCurrentUser

Ordinal 1173
Address 0x34780

RegOpenKeyExA

Ordinal 1174
Address 0x347a0

RegOpenKeyExW

Ordinal 1175
Address 0x19770

RegOpenUserClassesRoot

Ordinal 1176
Address 0x347c0

RegQueryInfoKeyA

Ordinal 1177
Address 0x347e0

RegQueryInfoKeyW

Ordinal 1178
Address 0x34800

RegQueryValueExA

Ordinal 1179
Address 0x34820

RegQueryValueExW

Ordinal 1180
Address 0x34840

RegRestoreKeyA

Ordinal 1181
Address 0x34860

RegRestoreKeyW

Ordinal 1182
Address 0x34880

RegSaveKeyExA

Ordinal 1183
Address 0x348a0

RegSaveKeyExW

Ordinal 1184
Address 0x348c0

RegSetKeySecurity

Ordinal 1185
Address 0x348e0

RegSetValueExA

Ordinal 1186
Address 0x34900

RegSetValueExW

Ordinal 1187
Address 0x34920

RegUnLoadKeyA

Ordinal 1188
Address 0x34940

RegUnLoadKeyW

Ordinal 1189
Address 0x34960

RegisterApplicationRecoveryCallback

Ordinal 1190
Address 0x17f80

RegisterApplicationRestart