83eb46d688f4e5dfb795ea2f65164e06c2b3162f06fc31a737a771d510a7b281

Summary

Architecture UNKNOWN
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2040-Apr-21 23:38:00
Detected languages English - United States
Debug artifacts kernel32.pdb
CompanyName Microsoft Corporation
FileDescription Windows NT BASE API Client DLL
FileVersion 10.0.22621.5415 (WinBuild.160101.0800)
InternalName kernel32
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename kernel32
ProductName Microsoft® Windows® Operating System
ProductVersion 10.0.22621.5415

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: May have dropper capabilities:
  • CurrentControlSet\Services
Contains domain names:
  • http://schemas.microsoft.com
  • http://schemas.microsoft.com/SMI/2005/WindowsSettings
  • http://schemas.microsoft.com/SMI/2011/WindowsSettings
  • http://schemas.microsoft.com/SMI/2013/WindowsSettings
  • http://schemas.microsoft.com/SMI/2014/WindowsSettings
  • http://schemas.microsoft.com/SMI/2016/WindowsSettings
  • http://schemas.microsoft.com/SMI/2017/WindowsSettings
  • http://schemas.microsoft.com/SMI/2019/WindowsSettings
  • http://schemas.microsoft.com/SMI/2020/WindowsSettings
  • microsoft.com
  • schemas.microsoft.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Suspicious The PE is possibly packed. Unusual section name found: .hexpthk
Unusual section name found: .a64xrm
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LdrLoadDll
  • GetProcAddress
  • LoadLibraryExA
  • LoadLibraryExW
  • LoadLibraryA
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • DbgPrint
  • NtQueryInformationProcess
  • NtQuerySystemInformation
  • ZwQuerySystemInformation
  • SwitchToThread
  • CheckRemoteDebuggerPresent
Code injection capabilities:
  • CreateRemoteThread
  • CreateRemoteThreadEx
  • OpenProcess
  • VirtualAlloc
  • VirtualAllocEx
  • WriteProcessMemory
  • VirtualAllocExNuma
Code injection capabilities (process hollowing):
  • ResumeThread
  • SetThreadContext
  • WriteProcessMemory
  • Wow64SetThreadContext
Code injection capabilities (mapping injection):
  • CreateRemoteThread
  • CreateRemoteThreadEx
  • CreateFileMappingW
  • MapViewOfFile
  • MapViewOfFileEx
  • CreateFileMappingNumaW
Can access the registry:
  • RegCloseKey
  • RegCreateKeyExA
  • RegCreateKeyExW
  • RegDeleteKeyExA
  • RegDeleteKeyExW
  • RegDeleteValueA
  • RegDeleteValueW
  • RegEnumKeyExA
  • RegEnumKeyExW
  • RegEnumValueA
  • RegEnumValueW
  • RegFlushKey
  • RegGetKeySecurity
  • RegGetValueA
  • RegGetValueW
  • RegLoadAppKeyW
  • RegLoadKeyA
  • RegLoadKeyW
  • RegNotifyChangeKeyValue
  • RegOpenKeyExA
  • RegOpenKeyExW
  • RegQueryInfoKeyA
  • RegQueryInfoKeyW
  • RegQueryValueExA
  • RegQueryValueExW
  • RegRestoreKeyA
  • RegRestoreKeyW
  • RegSaveKeyExA
  • RegSaveKeyExW
  • RegSetKeySecurity
  • RegSetValueExA
  • RegSetValueExW
  • RegUnLoadKeyA
  • RegUnLoadKeyW
Possibly launches other programs:
  • CreateProcessAsUserA
  • CreateProcessAsUserW
  • CreateProcessInternalA
  • CreateProcessInternalW
  • CreateProcessA
  • CreateProcessW
Uses Windows's Native API:
  • NtAddAtomEx
  • NtAllocateVirtualMemory
  • NtApphelpCacheControl
  • NtAssignProcessToJobObject
  • NtClearEvent
  • NtClose
  • NtCreateEvent
  • NtCreateJobObject
  • NtCreateJobSet
  • NtCreateKey
  • NtCreateMailslotFile
  • NtDeleteAtom
  • NtDeleteValueKey
  • NtDeviceIoControlFile
  • NtEnumerateKey
  • NtEnumerateValueKey
  • NtFindAtom
  • NtFlushKey
  • NtFreeVirtualMemory
  • NtFsControlFile
  • NtGetDevicePowerState
  • NtInitiatePowerAction
  • NtIsSystemResumeAutomatic
  • NtLockFile
  • NtMapUserPhysicalPagesScatter
  • NtOpenJobObject
  • NtOpenKey
  • NtOpenProcessToken
  • NtOpenThreadToken
  • NtPowerInformation
  • NtProtectVirtualMemory
  • NtQueryDirectoryFile
  • NtQueryEaFile
  • NtQueryEvent
  • NtQueryFullAttributesFile
  • NtQueryInformationAtom
  • NtQueryInformationFile
  • NtQueryInformationJobObject
  • NtQueryInformationProcess
  • NtQueryInformationThread
  • NtQueryInformationToken
  • NtQueryInstallUILanguage
  • NtQueryLicenseValue
  • NtQuerySection
  • NtQuerySecurityObject
  • NtQuerySystemEnvironmentValueEx
  • NtQuerySystemInformation
  • NtQuerySystemInformationEx
  • NtQueryTimerResolution
  • NtQueryValueKey
  • NtQueryVirtualMemory
  • NtQueryVolumeInformationFile
  • NtQueryWnfStateData
  • NtRaiseHardError
  • NtReadVirtualMemory
  • NtReplacePartitionUnit
  • NtSetEaFile
  • NtSetInformationDebugObject
  • NtSetInformationFile
  • NtSetInformationJobObject
  • NtSetInformationProcess
  • NtSetInformationThread
  • NtSetSecurityObject
  • NtSetSystemEnvironmentValueEx
  • NtSetSystemInformation
  • NtSetThreadExecutionState
  • NtSetTimerResolution
  • NtSetValueKey
  • NtSetVolumeInformationFile
  • NtTerminateJobObject
  • NtTerminateProcess
  • NtUnlockFile
  • NtUnmapViewOfSection
  • NtWaitForMultipleObjects
  • NtWaitForSingleObject
  • NtWriteFile
  • ZwClose
  • ZwEnumerateKey
  • ZwEnumerateValueKey
  • ZwOpenKey
  • ZwQueryDirectoryFile
  • ZwQueryInformationFile
  • ZwQuerySystemInformation
  • ZwQueryValueKey
  • ZwUnmapViewOfSection
  • NtCreateFile
  • NtCreateSection
  • NtMapViewOfSection
  • NtOpenFile
  • NtQueryAttributesFile
  • NtReadFile
  • ZwCreateFile
  • ZwCreateSection
  • ZwMapViewOfSection
  • ZwOpenFile
Can create temporary files:
  • CreateFileA
  • CreateFileW
  • GetTempPathA
  • GetTempPathW
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualAllocEx
  • VirtualProtect
  • VirtualProtectEx
Functions related to the privilege level:
  • OpenProcessToken
  • DuplicateToken
Enumerates local disk drives:
  • GetDriveTypeA
  • GetDriveTypeW
  • GetLogicalDriveStringsW
  • GetVolumeInformationByHandleW
  • GetVolumeInformationW
  • GetVolumeInformationA
Manipulates other processes:
  • OpenProcess
  • ReadProcessMemory
  • WriteProcessMemory
Info The PE is digitally signed. Signer: Microsoft Windows
Issuer: Microsoft Windows Production PCA 2011
Safe VirusTotal score: 0/70 (Scanned on 2026-03-04 13:51:58) All the AVs think this file is safe.

Hashes

MD5 e1c3704d8c745c03d6f54b3feca6ae3c
SHA1 14727618d2ee77f30a4f3ea657303a09fb6df17d
SHA256 83eb46d688f4e5dfb795ea2f65164e06c2b3162f06fc31a737a771d510a7b281
SHA3 e604afed2558630764bff0ab088b6fbf285e5e3624be125238ff6b58500947f7
SSDeep 24576:zVkJd24Rrxk+TbgZ+WPcYk1Bq+GxC8zuQ0/Sa8:zVkJV5UwWUJBq+GxC8zuf/Sa8
Imports Hash ba530b0c8b91dfd80d8b1f2eb1146e49

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf0

PE Header

Signature PE
Machine UNKNOWN
NumberofSections 9
TimeDateStamp 2040-Apr-21 23:38:00
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xf1000
SizeOfInitializedData 0x6b800
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000012310 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x180000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion A.0
ImageVersion A.0
SubsystemVersion A.0
Win32VersionValue 0
SizeOfImage 0x163000
SizeOfHeaders 0x400
Checksum 0x16ecdc
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x40000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.hexpthk

MD5 01684053ededfc107c26c8ff7e3ad3c6
SHA1 d543c06b60f963b18646c1e860057e0ebf6b70aa
SHA256 bd7d369d19f470bec025f8622218721467f686fe915db41abb99a3bade0e56b5
SHA3 fa30c11a3c427d6e9ebf4b9daa82ef9c996b3de657f5a04d19d19c360925d643
VirtualSize 0x4ae0
VirtualAddress 0x1000
SizeOfRawData 0x4c00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 4.4907

.text

MD5 314418e7c143bf5ff8fe8069fc76a265
SHA1 de1712d2a8d4fe439a1dfcf6de810fd65dbc89a8
SHA256 15b303a975c636614830c3d0612ad923da9282b1848222f1ebc2f8aedb0ffce3
SHA3 d2fc55b28cf65fb9fad687bc5d530eeced68ee4b9e4d2d967cae03093cce2382
VirtualSize 0xec3a6
VirtualAddress 0x6000
SizeOfRawData 0xec400
PointerToRawData 0x5000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.41636

.rdata

MD5 f5b8ac13d4378a3077fb0fcbd3cfb465
SHA1 96831dccc5ccf4305106d5c91f381e50e2a099bb
SHA256 1c5d424ea4a4281c52e286833ffb9320b6641919f58fa122e53a04df34fa9395
SHA3 3f60f87c4ad5a9d0d89fb22c03e0bb29e8c186483f3645b2d2ab028e2c698d83
VirtualSize 0x5aaf0
VirtualAddress 0xf3000
SizeOfRawData 0x5ac00
PointerToRawData 0xf1400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.50129

.data

MD5 a7b1d9faebc24be1b8b4e79827b529ce
SHA1 0cebc2d006ceeb9c12e359fb12dd073952addf9e
SHA256 12f23ce7176100786e45b92764310fa7423fc1b80e6c32e3d299c72127528155
SHA3 2a1ad9003d3147b5a0f5e0324bcef6351944cc2a3e754a012f7e1463c0bb5e21
VirtualSize 0x20e4
VirtualAddress 0x14e000
SizeOfRawData 0x800
PointerToRawData 0x14c000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.96243

.pdata

MD5 636566f748bcb9bacd26ffc1e248c129
SHA1 28694b1c6e7c388c7db52fa93529f84873db6f34
SHA256 70b8750e49ff98e0d7f8b59aa3f1bcf5ff07afb4e41627b0f9e098f1ce44a890
SHA3 af879cd15c8c94ab255bb7c890c8746e06bbc1fbea1a872c6468af98299887ab
VirtualSize 0x6270
VirtualAddress 0x151000
SizeOfRawData 0x6400
PointerToRawData 0x14c800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.80426

.didat

MD5 cdb6a13cdcf2202e432661f49907348b
SHA1 8fc90f7753feda4dd5a569572bb9428be372192f
SHA256 b2ab1b1030f1bc07d6353947be0d9b0b5213463272da57304bc805d35ab21359
SHA3 4781766469bed9960c0910f242e4f749c39e0d94cd3a072377c6cbef5afa3bf1
VirtualSize 0x1e0
VirtualAddress 0x158000
SizeOfRawData 0x200
PointerToRawData 0x152c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.24354

.a64xrm

MD5 10dd8d396e657d00e13329b22f982d20
SHA1 f3502b02ae8fdde96ebd9b688df8a1cf4fcb57aa
SHA256 e9ddfeb468215cb346aad9b744fa9cb7ddc3ffd9749bbab84f258bae41d23977
SHA3 58481fbfc952227a0f7288c30382c2f603d7d45028ca6bcf9706601abb0eb119
VirtualSize 0x2578
VirtualAddress 0x159000
SizeOfRawData 0x2600
PointerToRawData 0x152e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.73195

.rsrc

MD5 c34f056ca18422b7828b68360d9c7144
SHA1 93f4006961114204d18424070e189c48abe964fd
SHA256 7377b7117a16ff50649f023bc8514fbdbec31e2b5bea193e675fa12eec71fa24
SHA3 c4c3077c3b5dd18a754e35c9318c70f31571d6a5bd27170ac445063d1e8db92f
VirtualSize 0x520
VirtualAddress 0x15c000
SizeOfRawData 0x600
PointerToRawData 0x155400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.99437

.reloc

MD5 76391bdd61dea1bbba3d4e4b19620fd2
SHA1 9c3c86acfe0655b7b5c61cf085815e01e8ee8195
SHA256 be828630bae39dc5c4cc15ea93702fbfab2c33ec32c05a0f3a0efde3b4f96503
SHA3 da35b5adfe745da1f51e324e0df09a5c7dc4155fe30daa69c02949b7899b3da4
VirtualSize 0x56c8
VirtualAddress 0x15d000
SizeOfRawData 0x5800
PointerToRawData 0x155a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.04685

Imports

api-ms-win-core-rtlsupport-l1-1-0.dll RtlAddFunctionTable
RtlCaptureContext
RtlCompareMemory
RtlDeleteFunctionTable
RtlInstallFunctionTableCallback
RtlLookupFunctionEntry
RtlPcToFileHeader
RtlRaiseException
RtlRestoreContext
RtlUnwind
RtlUnwindEx
RtlVirtualUnwind
api-ms-win-core-rtlsupport-l1-2-2.dll RtlVirtualUnwind2
ntdll.dll NlsMbCodePageTag
__chkstk
CsrAllocateCaptureBuffer
CsrAllocateMessagePointer
CsrCaptureMessageMultiUnicodeStringsInPlace
CsrCaptureMessageString
CsrClientCallServer
CsrFreeCaptureBuffer
CsrVerifyRegion
DbgPrint
DbgPrintEx
DbgUiGetThreadDebugObject
DbgUiIssueRemoteBreakin
EtwEventEnabled
EtwEventRegister
EtwEventUnregister
EtwEventWrite
EtwEventWriteNoRegistration
LdrAddRefDll
LdrDisableThreadCalloutsForDll
LdrFindResourceEx_U
LdrFindResource_U
LdrGetDllDirectory
LdrGetProcedureAddress
LdrOpenImageFileOptionsKey
LdrQueryImageFileExecutionOptions
LdrQueryImageFileKeyOption
LdrResFindResourceDirectory
LdrResSearchResource
LdrSetDllDirectory
LdrSetDllManifestProber
LdrUnloadDll
NtAddAtomEx
NtAllocateVirtualMemory
NtApphelpCacheControl
NtAssignProcessToJobObject
NtClearEvent
NtClose
NtCreateEvent
NtCreateJobObject
NtCreateJobSet
NtCreateKey
NtCreateMailslotFile
NtDeleteAtom
NtDeleteValueKey
NtDeviceIoControlFile
NtEnumerateKey
NtEnumerateValueKey
NtFindAtom
NtFlushKey
NtFreeVirtualMemory
NtFsControlFile
NtGetDevicePowerState
NtInitiatePowerAction
NtIsSystemResumeAutomatic
NtLockFile
NtMapUserPhysicalPagesScatter
NtOpenJobObject
NtOpenKey
NtOpenProcessToken
NtOpenThreadToken
NtPowerInformation
NtProtectVirtualMemory
NtQueryDirectoryFile
NtQueryEaFile
NtQueryEvent
NtQueryFullAttributesFile
NtQueryInformationAtom
NtQueryInformationFile
NtQueryInformationJobObject
NtQueryInformationProcess
NtQueryInformationThread
NtQueryInformationToken
NtQueryInstallUILanguage
NtQueryLicenseValue
NtQuerySection
NtQuerySecurityObject
NtQuerySystemEnvironmentValueEx
NtQuerySystemInformation
NtQuerySystemInformationEx
NtQueryTimerResolution
NtQueryValueKey
NtQueryVirtualMemory
NtQueryVolumeInformationFile
NtQueryWnfStateData
NtRaiseHardError
NtReadVirtualMemory
NtReplacePartitionUnit
NtSetEaFile
NtSetInformationDebugObject
NtSetInformationFile
NtSetInformationJobObject
NtSetInformationProcess
NtSetInformationThread
NtSetSecurityObject
NtSetSystemEnvironmentValueEx
NtSetSystemInformation
NtSetThreadExecutionState
NtSetTimerResolution
NtSetValueKey
NtSetVolumeInformationFile
NtTerminateJobObject
NtTerminateProcess
NtUnlockFile
NtUnmapViewOfSection
NtWaitForMultipleObjects
NtWaitForSingleObject
NtWriteFile
RtlAcquirePrivilege
RtlAcquireSRWLockExclusive
RtlActivateActivationContext
RtlActivateActivationContextUnsafeFast
RtlAddAccessAllowedAce
RtlAddAtomToAtomTable
RtlAddIntegrityLabelToBoundaryDescriptor
RtlAddRefActivationContext
RtlAllocateAndInitializeSid
RtlAllocateHeap
RtlAnsiStringToUnicodeString
RtlAppendUnicodeStringToString
RtlAppendUnicodeToString
RtlCharToInteger
RtlCompactHeap
RtlCompareUnicodeString
RtlComputeImportTableHash
RtlConvertSidToUnicodeString
RtlCopyUnicodeString
RtlCreateAcl
RtlCreateActivationContext
RtlCreateAtomTable
RtlCreateBoundaryDescriptor
RtlCreateEnvironment
RtlCreateEnvironmentEx
RtlCreateQueryDebugBuffer
RtlCreateSecurityDescriptor
RtlCreateUnicodeString
RtlCreateUnicodeStringFromAsciiz
RtlDeactivateActivationContext
RtlDeactivateActivationContextUnsafeFast
RtlDecodeSystemPointer
RtlDeleteAtomFromAtomTable
RtlDeregisterSecureMemoryCacheCallback
RtlDeregisterWait
RtlDestroyAtomTable
RtlDestroyEnvironment
RtlDestroyQueryDebugBuffer
RtlDetermineDosPathNameType_U
RtlDisableThreadProfiling
RtlDnsHostNameToComputerName
RtlDoesFileExists_U
RtlDosPathNameToNtPathName_U
RtlDosPathNameToNtPathName_U_WithStatus
RtlDosPathNameToRelativeNtPathName_U
RtlEnableThreadProfiling
RtlEncodeSystemPointer
RtlEnterCriticalSection
RtlEqualSid
RtlEqualString
RtlEqualUnicodeString
RtlExitUserProcess
RtlExitUserThread
RtlFindActivationContextSectionGuid
RtlFindActivationContextSectionString
RtlFormatCurrentUserKeyPath
RtlFreeAnsiString
RtlFreeHeap
RtlFreeOemString
RtlFreeSid
RtlFreeUnicodeString
RtlGUIDFromString
RtlGetActiveActivationContext
RtlGetActiveConsoleId
RtlGetAppContainerParent
RtlGetAppContainerSidType
RtlGetCurrentDirectory_U
RtlGetCurrentProcessorNumberEx
RtlGetCurrentServiceSessionId
RtlGetCurrentTransaction
RtlGetDeviceFamilyInfoEnum
RtlGetFullPathName_U
RtlGetFullPathName_UEx
RtlGetLengthWithoutLastFullDosOrNtPathElement
RtlGetLongestNtPathLength
RtlGetNativeSystemInformation
RtlGetNtSystemRoot
RtlGetPersistedStateLocation
RtlGetSuiteMask
RtlGetThreadErrorMode
RtlGetThreadPreferredUILanguages
RtlGetUILanguageInfo
RtlGetUserInfoHeap
RtlGetVersion
RtlHashUnicodeString
RtlImageDirectoryEntryToData
RtlImageNtHeader
RtlImageNtHeaderEx
RtlInitAnsiString
RtlInitAnsiStringEx
RtlInitString
RtlInitUnicodeString
RtlInitUnicodeStringEx
RtlInitializeCriticalSection
RtlInitializeSid
RtlIntegerToUnicodeString
RtlIsNameLegalDOS8Dot3
RtlIsTextUnicode
RtlLCIDToCultureName
RtlLeaveCriticalSection
RtlLengthSecurityDescriptor
RtlLockHeap
RtlLookupAtomInAtomTable
RtlMultiAppendUnicodeStringBuffer
RtlMultiByteToUnicodeN
RtlMultiByteToUnicodeSize
RtlNotifyFeatureUsage
RtlNtPathNameToDosPathName
RtlNtStatusToDosError
RtlNtStatusToDosErrorNoTeb
RtlOemStringToUnicodeString
RtlPrefixString
RtlPrefixUnicodeString
RtlPublishWnfStateData
RtlQueryActivationContextApplicationSettings
RtlQueryAtomInAtomTable
RtlQueryElevationFlags
RtlQueryEnvironmentVariable
RtlQueryEnvironmentVariable_U
RtlQueryFeatureConfiguration
RtlQueryInformationActivationContext
RtlQueryPackageClaims
RtlQueryPackageIdentity
RtlQueryProcessDebugInformation
RtlQueryRegistryValuesEx
RtlQueryThreadProfiling
RtlQueryWnfStateData
RtlRaiseStatus
RtlReAllocateHeap
RtlReadThreadProfilingData
RtlRegisterSecureMemoryCacheCallback
RtlRegisterWait
RtlReleaseActivationContext
RtlReleasePebLock
RtlReleasePrivilege
RtlReleaseRelativeName
RtlReleaseSRWLockExclusive
RtlRunOnceExecuteOnce
RtlSetCurrentTransaction
RtlSetDaclSecurityDescriptor
RtlSetEnvironmentStrings
RtlSetEnvironmentVariable
RtlSetGroupSecurityDescriptor
RtlSetIoCompletionCallback
RtlSetLastWin32Error
RtlSetLastWin32ErrorAndNtStatusFromNtStatus
RtlSetOwnerSecurityDescriptor
RtlSetSearchPathMode
RtlSetThreadPoolStartFunc
RtlSetThreadPreferredUILanguages
RtlSizeHeap
RtlSubAuthorityCountSid
RtlSubAuthoritySid
RtlSubscribeWnfStateChangeNotification
RtlSwitchedVVI
RtlTimeFieldsToTime
RtlTimeToTimeFields
RtlTryAcquirePebLock
RtlUnhandledExceptionFilter
RtlUnicodeStringToAnsiString
RtlUnicodeStringToInteger
RtlUnicodeStringToOemString
RtlUnicodeToMultiByteN
RtlUnicodeToMultiByteSize
RtlUnlockHeap
RtlUnsubscribeWnfStateChangeNotification
RtlUpcaseUnicodeChar
RtlUpcaseUnicodeString
RtlVerifyVersionInfo
RtlWerpReportException
RtlWow64GetThreadSelectorEntry
RtlWow64LogMessageInEventLogger
RtlZombifyActivationContext
RtlpApplyLengthFunction
RtlpConvertCultureNamesToLCIDs
RtlpConvertLCIDsToCultureNames
RtlpEnsureBufferSize
RtlxAnsiStringToUnicodeSize
RtlxUnicodeStringToAnsiSize
TpAllocCleanupGroup
TpAllocIoCompletion
TpAllocPool
TpAllocTimer
TpAllocWait
TpAllocWork
TpCallbackMayRunLong
TpCaptureCaller
TpQueryPoolStackInformation
TpSetPoolMinThreads
TpSetPoolStackInformation
TpSimpleTryPost
VerSetConditionMask
ZwClose
ZwEnumerateKey
ZwEnumerateValueKey
ZwOpenKey
ZwQueryDirectoryFile
ZwQueryInformationFile
ZwQuerySystemInformation
ZwQueryValueKey
ZwUnmapViewOfSection
__C_specific_handler
_local_unwind
_memicmp
_stricmp
_strnicmp
_vsnwprintf
_wcsicmp
_wcslwr
_wcsnicmp
_wtol
atol
bsearch
cos
isdigit
memcmp
memcpy
memmove
memmove_s
memset
sin
strcat_s
strchr
strcmp
strcpy_s
strncmp
strncpy_s
strnlen
strrchr
swprintf_s
tolower
toupper
towlower
wcscat_s
wcschr
wcscmp
wcscpy_s
wcscspn
wcsncmp
wcsncpy
wcsncpy_s
wcsnlen
wcsrchr
wcsstr
LdrLoadDll
NtCreateFile
NtCreateSection
NtMapViewOfSection
NtOpenFile
NtQueryAttributesFile
NtReadFile
ZwCreateFile
ZwCreateSection
ZwMapViewOfSection
ZwOpenFile
KERNELBASE.dll AppContainerFreeMemory
AppContainerLookupMoniker
AppXGetOSMaxVersionTested
AppXPostSuccessExtension
AppXPreCreationExtension
AppXReleaseAppXContext
AreFileApisANSI
BaseDllFreeResourceId
BaseDllMapResourceIdW
BaseFormatObjectAttributes
BaseGetNamedObjectDirectory
BasepAdjustObjectAttributesForPrivateNamespace
BasepNotifyTrackingService
CheckAllowDecryptedRemoteDestinationPolicy
CheckGroupPolicyEnabled
CheckIsMSIXPackage
ClosePackageInfo
CompareStringA
CreateProcessAsUserA
CreateProcessAsUserW
CreateProcessInternalA
CreateProcessInternalW
EnumLanguageGroupLocalesW
EnumSystemLanguageGroupsW
EnumSystemLocalesEx
EnumUILanguagesW
FatalAppExitA
FatalAppExitW
GetCalendar
GetCurrentPackageFullName
GetEightBitStringToUnicodeStringRoutine
GetEraNameCountedString
GetLocaleInfoHelper
GetNamedLocaleHashNode
GetNamedPipeAttribute
GetPackageFullName
GetPackageTargetPlatformProperty
GetPackagedDataForFile
GetProcAddressForCaller
GetPtrCalData
GetPtrCalDataArray
GetRegistryExtensionFlags
GetStringTableEntry
GetStringTypeA
GetSystemDefaultLocaleName
GetSystemDefaultUILanguage
GetTargetPlatformContext
GetUnicodeStringToEightBitSizeRoutine
GetUnicodeStringToEightBitStringRoutine
GetUserDefaultLocaleName
GetUserDefaultUILanguage
GetUserOverrideString
GetUserOverrideWord
GetVolumeNameForVolumeMountPointW
GlobalAlloc
GlobalFree
HeapSummary
InternalLcidToName
Internal_EnumCalendarInfo
Internal_EnumDateFormats
Internal_EnumLanguageGroupLocales
Internal_EnumSystemCodePages
Internal_EnumSystemLanguageGroups
Internal_EnumTimeFormats
Internal_EnumUILanguages
KernelBaseGetGlobalData
LCIDToLocaleName
LoadStringBaseExW
LocalAlloc
LocalLock
LocalReAlloc
LocalUnlock
MapViewOfFileExNuma
MoveFileWithProgressTransactedW
NlsIsUserDefaultLocale
NlsValidateLocale
NotifyMountMgr
OpenPackageInfoByFullNameForUser
OpenRegKey
PackageIdFromFullName
PrivCopyFileExW
PulseEvent
ReleasePackagedDataForFile
SetFileApisToANSI
SetFileApisToOEM
Sleep
lstrcmpW
lstrcmpiW
lstrcpynA
lstrcpynW
lstrlenA
lstrlenW
api-ms-win-core-processthreads-l1-1-0.dll CreateProcessA
CreateProcessW
CreateRemoteThread
CreateRemoteThreadEx
DeleteProcThreadAttributeList
GetCurrentProcess
GetCurrentProcessId
GetExitCodeProcess
GetExitCodeThread
GetPriorityClass
GetProcessId
GetProcessIdOfThread
GetProcessTimes
GetProcessVersion
GetStartupInfoW
GetThreadId
GetThreadPriority
GetThreadPriorityBoost
InitializeProcThreadAttributeList
OpenProcessToken
OpenThread
ProcessIdToSessionId
QueryProcessAffinityUpdateMode
QueueUserAPC
ResumeThread
SetPriorityClass
SetProcessAffinityUpdateMode
SetProcessShutdownParameters
SetThreadPriority
SetThreadPriorityBoost
SetThreadStackGuarantee
SuspendThread
SwitchToThread
TerminateProcess
TerminateThread
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
UpdateProcThreadAttribute
api-ms-win-core-processthreads-l1-1-1.dll FlushInstructionCache
GetProcessHandleCount
GetProcessMitigationPolicy
GetThreadContext
GetThreadIdealProcessorEx
GetThreadTimes
IsProcessorFeaturePresent
OpenProcess
SetProcessMitigationPolicy
SetThreadContext
SetThreadIdealProcessorEx
api-ms-win-core-processthreads-l1-1-2.dll GetProcessPriorityBoost
GetSystemTimes
GetThreadIOPendingFlag
GetThreadInformation
SetProcessPriorityBoost
SetThreadInformation
api-ms-win-core-processthreads-l1-1-3.dll GetProcessInformation
GetProcessShutdownParameters
SetProcessInformation
SetThreadIdealProcessor
api-ms-win-core-registry-l1-1-0.dll RegCloseKey
RegCopyTreeW
RegCreateKeyExA
RegCreateKeyExW
RegDeleteKeyExA
RegDeleteKeyExW
RegDeleteTreeA
RegDeleteTreeW
RegDeleteValueA
RegDeleteValueW
RegDisablePredefinedCacheEx
RegEnumKeyExA
RegEnumKeyExW
RegEnumValueA
RegEnumValueW
RegFlushKey
RegGetKeySecurity
RegGetValueA
RegGetValueW
RegLoadAppKeyW
RegLoadKeyA
RegLoadKeyW
RegLoadMUIStringA
RegLoadMUIStringW
RegNotifyChangeKeyValue
RegOpenCurrentUser
RegOpenKeyExA
RegOpenKeyExW
RegOpenUserClassesRoot
RegQueryInfoKeyA
RegQueryInfoKeyW
RegQueryValueExA
RegQueryValueExW
RegRestoreKeyA
RegRestoreKeyW
RegSaveKeyExA
RegSaveKeyExW
RegSetKeySecurity
RegSetValueExA
RegSetValueExW
RegUnLoadKeyA
RegUnLoadKeyW
api-ms-win-core-heap-l1-1-0.dll GetProcessHeap
GetProcessHeaps
HeapAlloc
HeapCompact
HeapCreate
HeapDestroy
HeapFree
HeapLock
HeapQueryInformation
HeapReAlloc
HeapSetInformation
HeapUnlock
HeapValidate
HeapWalk
api-ms-win-core-heap-l2-1-0.dll LocalFree
api-ms-win-core-memory-l1-1-0.dll CreateFileMappingW
FlushViewOfFile
MapViewOfFile
MapViewOfFileEx
OpenFileMappingW
ReadProcessMemory
UnmapViewOfFile
VirtualAlloc
VirtualAllocEx
VirtualFree
VirtualFreeEx
VirtualProtect
VirtualProtectEx
VirtualQuery
VirtualQueryEx
WriteProcessMemory
api-ms-win-core-memory-l1-1-2.dll AllocateUserPhysicalPages
AllocateUserPhysicalPagesNuma
FreeUserPhysicalPages
GetMemoryErrorHandlingCapabilities
MapUserPhysicalPages
RegisterBadMemoryNotification
UnregisterBadMemoryNotification
VirtualAllocExNuma
api-ms-win-core-memory-l1-1-1.dll CreateFileMappingNumaW
CreateMemoryResourceNotification
GetLargePageMinimum
GetProcessWorkingSetSize
GetProcessWorkingSetSizeEx
GetSystemFileCacheSize
GetWriteWatch
QueryMemoryResourceNotification
ResetWriteWatch
SetProcessWorkingSetSize
SetProcessWorkingSetSizeEx
SetSystemFileCacheSize
VirtualLock
VirtualUnlock
api-ms-win-core-handle-l1-1-0.dll CloseHandle
DuplicateHandle
GetHandleInformation
SetHandleInformation
api-ms-win-core-synch-l1-2-0.dll DeleteSynchronizationBarrier
EnterSynchronizationBarrier
InitOnceExecuteOnce
InitializeSynchronizationBarrier
SignalObjectAndWait
api-ms-win-core-synch-l1-1-0.dll CancelWaitableTimer
CreateEventA
CreateEventExA
CreateEventExW
CreateEventW
CreateMutexA
CreateMutexExA
CreateMutexExW
CreateMutexW
CreateSemaphoreExW
CreateWaitableTimerExW
DeleteCriticalSection
EnterCriticalSection
InitializeCriticalSection
InitializeCriticalSectionAndSpinCount
InitializeCriticalSectionEx
LeaveCriticalSection
OpenEventA
OpenEventW
OpenMutexW
OpenSemaphoreW
OpenWaitableTimerW
ReleaseMutex
ReleaseSemaphore
ResetEvent
SetEvent
SetWaitableTimer
SleepEx
WaitForMultipleObjectsEx
WaitForSingleObject
WaitForSingleObjectEx
api-ms-win-core-synch-l1-2-1.dll CreateSemaphoreW
WaitForMultipleObjects
api-ms-win-core-file-l1-1-0.dll CompareFileTime
CreateDirectoryA
CreateDirectoryW
CreateFileA
CreateFileW
DefineDosDeviceW
DeleteFileA
DeleteFileW
DeleteVolumeMountPointW
FileTimeToLocalFileTime
FindClose
FindCloseChangeNotification
FindFirstChangeNotificationA
FindFirstChangeNotificationW
FindFirstFileA
FindFirstFileExA
FindFirstFileExW
FindFirstFileW
FindFirstVolumeW
FindNextChangeNotification
FindNextFileA
FindNextFileW
FindNextVolumeW
FindVolumeClose
FlushFileBuffers
GetDiskFreeSpaceA
GetDiskFreeSpaceExA
GetDiskFreeSpaceExW
GetDiskFreeSpaceW
GetDriveTypeA
GetDriveTypeW
GetFileAttributesA
GetFileAttributesExA
GetFileAttributesExW
GetFileAttributesW
GetFileInformationByHandle
GetFileSize
GetFileSizeEx
GetFileTime
GetFileType
GetFinalPathNameByHandleA
GetFinalPathNameByHandleW
GetFullPathNameA
GetFullPathNameW
GetLogicalDriveStringsW
GetTempFileNameW
GetVolumeInformationByHandleW
GetVolumeInformationW
GetVolumePathNameW
LocalFileTimeToFileTime
LockFile
LockFileEx
QueryDosDeviceW
ReadFile
ReadFileEx
ReadFileScatter
RemoveDirectoryA
RemoveDirectoryW
SetEndOfFile
SetFileAttributesA
SetFileAttributesW
SetFileInformationByHandle
SetFilePointer
SetFilePointerEx
SetFileTime
SetFileValidData
UnlockFile
UnlockFileEx
WriteFile
WriteFileEx
WriteFileGather
api-ms-win-core-file-l1-2-2.dll FindFirstFileNameW
FindFirstStreamW
FindNextFileNameW
GetTempFileNameA
GetTempPathA
GetVolumeInformationA
api-ms-win-core-file-l1-2-1.dll GetCompressedFileSizeA
GetCompressedFileSizeW
SetFileIoOverlappedRange
api-ms-win-core-file-l1-2-0.dll CreateFile2
GetTempPathW
GetVolumePathNamesForVolumeNameW
api-ms-win-core-file-l1-2-4.dll GetTempPath2A
GetTempPath2W
api-ms-win-core-delayload-l1-1-0.dll DelayLoadFailureHook
api-ms-win-core-io-l1-1-0.dll CancelIoEx
CreateIoCompletionPort
DeviceIoControl
GetOverlappedResult
GetQueuedCompletionStatus
GetQueuedCompletionStatusEx
PostQueuedCompletionStatus
api-ms-win-core-io-l1-1-1.dll CancelIo
CancelSynchronousIo
api-ms-win-core-job-l1-1-0.dll IsProcessInJob
api-ms-win-core-threadpool-legacy-l1-1-0.dll ChangeTimerQueueTimer
CreateTimerQueue
CreateTimerQueueTimer
DeleteTimerQueue
DeleteTimerQueueEx
DeleteTimerQueueTimer
QueueUserWorkItem
UnregisterWaitEx
api-ms-win-core-threadpool-private-l1-1-0.dll RegisterWaitForSingleObjectEx
api-ms-win-core-largeinteger-l1-1-0.dll MulDiv
api-ms-win-core-libraryloader-l1-2-0.dll DisableThreadLibraryCalls
EnumResourceLanguagesExA
EnumResourceLanguagesExW
EnumResourceNamesExA
EnumResourceNamesExW
EnumResourceTypesExA
EnumResourceTypesExW
FindResourceExW
FindStringOrdinal
FreeLibrary
FreeLibraryAndExitThread
FreeResource
GetModuleFileNameA
GetModuleFileNameW
GetModuleHandleA
GetModuleHandleExA
GetModuleHandleExW
GetModuleHandleW
GetProcAddress
LoadLibraryExA
LoadLibraryExW
LoadResource
LockResource
SizeofResource
api-ms-win-core-libraryloader-l1-2-1.dll FindResourceW
LoadLibraryA
LoadLibraryW
api-ms-win-core-libraryloader-l1-2-2.dll EnumResourceNamesW
api-ms-win-core-libraryloader-l1-2-3.dll EnumResourceNamesA
api-ms-win-core-libraryloader-l2-1-0.dll LoadPackagedLibrary
api-ms-win-core-namedpipe-l1-1-0.dll ConnectNamedPipe
CreateNamedPipeW
CreatePipe
DisconnectNamedPipe
GetNamedPipeClientComputerNameW
PeekNamedPipe
SetNamedPipeHandleState
TransactNamedPipe
WaitNamedPipeW
api-ms-win-core-namedpipe-l1-2-1.dll GetNamedPipeHandleStateW
api-ms-win-core-namedpipe-l1-2-2.dll CallNamedPipeW
api-ms-win-core-datetime-l1-1-0.dll GetDateFormatA
GetDateFormatW
GetTimeFormatA
GetTimeFormatW
api-ms-win-core-datetime-l1-1-2.dll GetDurationFormatEx
api-ms-win-core-datetime-l1-1-1.dll GetDateFormatEx
GetTimeFormatEx
api-ms-win-core-sysinfo-l1-2-0.dll EnumSystemFirmwareTables
GetNativeSystemInfo
GetProductInfo
GetSystemFirmwareTable
GetSystemTimePreciseAsFileTime
SetComputerNameExW
SetSystemTime
api-ms-win-core-sysinfo-l1-1-0.dll GetComputerNameExA
GetComputerNameExW
GetLocalTime
GetLogicalProcessorInformation
GetLogicalProcessorInformationEx
GetSystemInfo
GetSystemTime
GetSystemTimeAdjustment
GetSystemTimeAsFileTime
GetTickCount
GetVersion
GetVersionExA
GetVersionExW
GetWindowsDirectoryA
GetWindowsDirectoryW
GlobalMemoryStatusEx
SetLocalTime
api-ms-win-core-sysinfo-l1-2-3.dll SetComputerNameA
SetComputerNameExA
SetComputerNameW
api-ms-win-core-sysinfo-l1-2-1.dll DnsHostnameToComputerNameExW
GetPhysicallyInstalledSystemMemory
SetComputerNameEx2W
api-ms-win-core-timezone-l1-1-0.dll FileTimeToSystemTime
GetDynamicTimeZoneInformation
GetTimeZoneInformation
GetTimeZoneInformationForYear
SetDynamicTimeZoneInformation
SetTimeZoneInformation
SystemTimeToFileTime
SystemTimeToTzSpecificLocalTime
TzSpecificLocalTimeToSystemTime
api-ms-win-core-localization-l1-2-0.dll ConvertDefaultLocale
EnumSystemLocalesA
EnumSystemLocalesW
FindNLSString
FindNLSStringEx
FormatMessageA
FormatMessageW
GetACP
GetCPInfo
GetCPInfoExW
GetCalendarInfoEx
GetCalendarInfoW
GetFileMUIInfo
GetFileMUIPath
GetLocaleInfoA
GetLocaleInfoEx
GetLocaleInfoW
GetNLSVersion
GetNLSVersionEx
GetOEMCP
GetProcessPreferredUILanguages
GetSystemDefaultLCID
GetSystemDefaultLangID
GetSystemPreferredUILanguages
GetThreadLocale
GetThreadPreferredUILanguages
GetThreadUILanguage
GetUILanguageInfo
GetUserDefaultLCID
GetUserDefaultLangID
GetUserPreferredUILanguages
IdnToAscii
IdnToUnicode
IsDBCSLeadByte
IsDBCSLeadByteEx
IsNLSDefinedString
IsValidCodePage
IsValidLanguageGroup
IsValidLocale
IsValidLocaleName
IsValidNLSVersion
LCMapStringA
LCMapStringEx
LCMapStringW
LocaleNameToLCID
ResolveLocaleName
SetCalendarInfoW
SetLocaleInfoW
SetProcessPreferredUILanguages
SetThreadLocale
SetThreadPreferredUILanguages
SetThreadUILanguage
VerLanguageNameA
VerLanguageNameW
api-ms-win-core-processsnapshot-l1-1-0.dll PssCaptureSnapshot
PssDuplicateSnapshot
PssFreeSnapshot
PssQuerySnapshot
PssWalkMarkerCreate
PssWalkMarkerFree
PssWalkMarkerGetPosition
PssWalkMarkerSeekToBeginning
PssWalkMarkerSetPosition
PssWalkSnapshot
api-ms-win-core-processenvironment-l1-1-0.dll ExpandEnvironmentStringsA
ExpandEnvironmentStringsW
FreeEnvironmentStringsA
FreeEnvironmentStringsW
GetCommandLineA
GetCommandLineW
GetCurrentDirectoryA
GetCurrentDirectoryW
GetEnvironmentStrings
GetEnvironmentStringsW
GetEnvironmentVariableA
GetEnvironmentVariableW
GetStdHandle
SearchPathW
SetCurrentDirectoryA
SetCurrentDirectoryW
SetEnvironmentStringsW
SetEnvironmentVariableA
SetEnvironmentVariableW
SetStdHandle
SetStdHandleEx
api-ms-win-core-processenvironment-l1-2-0.dll NeedCurrentDirectoryForExePathA
NeedCurrentDirectoryForExePathW
SearchPathA
api-ms-win-core-string-l1-1-0.dll CompareStringEx
CompareStringOrdinal
CompareStringW
FoldStringW
GetStringTypeExW
GetStringTypeW
MultiByteToWideChar
WideCharToMultiByte
api-ms-win-core-debug-l1-1-1.dll CheckRemoteDebuggerPresent
ContinueDebugEvent
DebugActiveProcess
DebugActiveProcessStop
WaitForDebugEvent
api-ms-win-core-debug-l1-1-0.dll DebugBreak
IsDebuggerPresent
OutputDebugStringA
OutputDebugStringW
api-ms-win-core-errorhandling-l1-1-0.dll GetErrorMode
GetLastError
RaiseException
SetErrorMode
SetLastError
SetUnhandledExceptionFilter
UnhandledExceptionFilter
api-ms-win-core-errorhandling-l1-1-3.dll GetThreadErrorMode
SetThreadErrorMode
api-ms-win-core-fibers-l1-1-0.dll FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
api-ms-win-core-util-l1-1-0.dll Beep
api-ms-win-core-profile-l1-1-0.dll QueryPerformanceCounter
QueryPerformanceFrequency
api-ms-win-security-base-l1-1-0.dll AccessCheck
AllocateAndInitializeSid
CreateWellKnownSid
DuplicateToken
EqualSid
FreeSid
GetSidSubAuthority
GetSidSubAuthorityCount
GetTokenInformation
InitializeSid
api-ms-win-security-base-l1-2-0.dll AddResourceAttributeAce
AddScopedPolicyIDAce
CheckTokenCapability
CheckTokenMembershipEx
GetAppContainerAce
GetCachedSigningLevel
SetCachedSigningLevel
api-ms-win-security-appcontainer-l1-1-0.dll GetAppContainerNamedObjectPath
api-ms-win-core-comm-l1-1-0.dll ClearCommBreak
ClearCommError
EscapeCommFunction
GetCommConfig
GetCommMask
GetCommModemStatus
GetCommProperties
GetCommState
GetCommTimeouts
PurgeComm
SetCommBreak
SetCommConfig
SetCommMask
SetCommState
SetCommTimeouts
SetupComm
TransmitCommChar
WaitCommEvent
api-ms-win-core-realtime-l1-1-0.dll QueryIdleProcessorCycleTime
QueryIdleProcessorCycleTimeEx
QueryProcessCycleTime
QueryThreadCycleTime
QueryUnbiasedInterruptTime
api-ms-win-core-wow64-l1-1-0.dll IsWow64Process
Wow64DisableWow64FsRedirection
Wow64EnableWow64FsRedirection
Wow64RevertWow64FsRedirection
api-ms-win-core-wow64-l1-1-3.dll Wow64GetThreadContext
Wow64SetThreadContext
Wow64SuspendThread
api-ms-win-core-wow64-l1-1-1.dll GetSystemWow64Directory2W
GetSystemWow64DirectoryA
GetSystemWow64DirectoryW
IsWow64Process2
api-ms-win-core-systemtopology-l1-1-1.dll GetNumaProximityNodeEx
api-ms-win-core-systemtopology-l1-1-0.dll GetNumaHighestNodeNumber
GetNumaNodeProcessorMaskEx
api-ms-win-core-processtopology-l1-1-0.dll GetProcessGroupAffinity
GetThreadGroupAffinity
SetThreadGroupAffinity
api-ms-win-core-namespace-l1-1-0.dll AddSIDToBoundaryDescriptor
ClosePrivateNamespace
CreateBoundaryDescriptorW
CreatePrivateNamespaceW
DeleteBoundaryDescriptor
OpenPrivateNamespaceW
api-ms-win-core-file-l2-1-0.dll CopyFile2
CopyFileExW
CreateDirectoryExW
CreateHardLinkW
CreateSymbolicLinkW
GetFileInformationByHandleEx
MoveFileExW
MoveFileWithProgressW
ReOpenFile
ReadDirectoryChangesW
ReplaceFileW
api-ms-win-core-file-l2-1-3.dll ReadDirectoryChangesExW
api-ms-win-core-file-l2-1-1.dll OpenFileById
api-ms-win-core-file-l2-1-2.dll CopyFileW
CreateHardLinkA
api-ms-win-core-xstate-l2-1-2.dll (EMPTY)
api-ms-win-core-xstate-l2-1-0.dll CopyContext
InitializeContext
api-ms-win-core-xstate-l2-1-1.dll InitializeContext2
api-ms-win-core-localization-l2-1-0.dll EnumCalendarInfoExEx
EnumCalendarInfoExW
EnumCalendarInfoW
EnumDateFormatsExEx
EnumDateFormatsExW
EnumDateFormatsW
EnumSystemCodePagesW
EnumTimeFormatsEx
EnumTimeFormatsW
GetCurrencyFormatEx
GetNumberFormatEx
api-ms-win-core-normalization-l1-1-0.dll GetStringScripts
IdnToNameprepUnicode
IsNormalizedString
NormalizeString
VerifyScripts
api-ms-win-core-heap-obsolete-l1-1-0.dll GlobalFlags
GlobalHandle
GlobalLock
GlobalReAlloc
GlobalSize
GlobalUnlock
LocalFlags
LocalSize
api-ms-win-core-fibers-l2-1-0.dll ConvertFiberToThread
ConvertThreadToFiber
CreateFiber
DeleteFiber
SwitchToFiber
api-ms-win-core-fibers-l2-1-1.dll ConvertThreadToFiberEx
CreateFiberEx
api-ms-win-core-localization-private-l1-1-0.dll NlsCheckPolicy
NlsGetCacheUpdateCount
NlsUpdateLocale
NlsUpdateSystemLocale
api-ms-win-core-sidebyside-l1-1-0.dll ActivateActCtx
AddRefActCtx
CreateActCtxW
DeactivateActCtx
FindActCtxSectionGuid
FindActCtxSectionStringW
GetCurrentActCtx
QueryActCtxSettingsW
QueryActCtxW
ReleaseActCtx
ZombifyActCtx
api-ms-win-core-appcompat-l1-1-0.dll BaseCheckAppcompatCache
BaseCheckAppcompatCacheEx
BaseCleanupAppcompatCacheSupport
BaseDumpAppcompatCache
BaseFlushAppcompatCache
BaseInitAppcompatCacheSupport
BaseUpdateAppcompatCache
api-ms-win-core-windowserrorreporting-l1-1-3.dll RegisterApplicationRestart
UnregisterApplicationRestart
api-ms-win-core-windowserrorreporting-l1-1-0.dll GetApplicationRecoveryCallback
GetApplicationRestartSettings
WerRegisterFile
WerRegisterMemoryBlock
WerRegisterRuntimeExceptionModule
WerUnregisterFile
WerUnregisterMemoryBlock
WerUnregisterRuntimeExceptionModule
api-ms-win-core-windowserrorreporting-l1-1-1.dll WerRegisterAdditionalProcess
WerRegisterCustomMetadata
WerRegisterExcludedMemoryBlock
WerUnregisterAdditionalProcess
WerUnregisterCustomMetadata
WerUnregisterExcludedMemoryBlock
api-ms-win-core-windowserrorreporting-l1-1-2.dll WerRegisterAppLocalDump
WerUnregisterAppLocalDump
api-ms-win-core-console-l1-1-0.dll AllocConsole
GetConsoleCP
GetConsoleMode
GetConsoleOutputCP
GetNumberOfConsoleInputEvents
ReadConsoleA
ReadConsoleInputA
ReadConsoleInputW
ReadConsoleW
SetConsoleCtrlHandler
SetConsoleMode
WriteConsoleA
WriteConsoleW
api-ms-win-core-console-l1-2-0.dll AttachConsole
FreeConsole
PeekConsoleInputA
PeekConsoleInputW
api-ms-win-core-console-l1-2-1.dll ClosePseudoConsole
CreatePseudoConsole
ResizePseudoConsole
api-ms-win-core-console-l2-1-0.dll CreateConsoleScreenBuffer
FillConsoleOutputAttribute
FillConsoleOutputCharacterA
FillConsoleOutputCharacterW
FlushConsoleInputBuffer
GenerateConsoleCtrlEvent
GetConsoleCursorInfo
GetConsoleScreenBufferInfo
GetConsoleScreenBufferInfoEx
GetLargestConsoleWindowSize
ReadConsoleOutputA
ReadConsoleOutputAttribute
ReadConsoleOutputCharacterA
ReadConsoleOutputCharacterW
ReadConsoleOutputW
ScrollConsoleScreenBufferA
ScrollConsoleScreenBufferW
SetConsoleActiveScreenBuffer
SetConsoleCP
SetConsoleCursorInfo
SetConsoleCursorPosition
SetConsoleOutputCP
SetConsoleScreenBufferInfoEx
SetConsoleScreenBufferSize
SetConsoleTextAttribute
SetConsoleWindowInfo
WriteConsoleInputA
WriteConsoleInputW
WriteConsoleOutputA
WriteConsoleOutputAttribute
WriteConsoleOutputCharacterA
WriteConsoleOutputCharacterW
WriteConsoleOutputW
api-ms-win-core-console-l2-2-0.dll GetConsoleOriginalTitleA
GetConsoleOriginalTitleW
GetConsoleTitleA
GetConsoleTitleW
SetConsoleTitleA
SetConsoleTitleW
api-ms-win-core-console-l3-2-0.dll AddConsoleAliasA
AddConsoleAliasW
ExpungeConsoleCommandHistoryA
ExpungeConsoleCommandHistoryW
GetConsoleAliasA
GetConsoleAliasExesA
GetConsoleAliasExesLengthA
GetConsoleAliasExesLengthW
GetConsoleAliasExesW
GetConsoleAliasW
GetConsoleAliasesA
GetConsoleAliasesLengthA
GetConsoleAliasesLengthW
GetConsoleAliasesW
GetConsoleCommandHistoryA
GetConsoleCommandHistoryLengthA
GetConsoleCommandHistoryLengthW
GetConsoleCommandHistoryW
GetConsoleDisplayMode
GetConsoleFontSize
GetConsoleHistoryInfo
GetConsoleProcessList
GetConsoleSelectionInfo
GetConsoleWindow
GetCurrentConsoleFont
GetCurrentConsoleFontEx
GetNumberOfConsoleMouseButtons
SetConsoleDisplayMode
SetConsoleHistoryInfo
SetConsoleNumberOfCommandsA
SetConsoleNumberOfCommandsW
SetCurrentConsoleFontEx
api-ms-win-core-psapi-l1-1-0.dll K32EmptyWorkingSet
K32EnumDeviceDrivers
K32EnumPageFilesW
K32EnumProcessModules
K32EnumProcessModulesEx
K32EnumProcesses
K32GetDeviceDriverBaseNameW
K32GetDeviceDriverFileNameW
K32GetMappedFileNameW
K32GetModuleBaseNameW
K32GetModuleFileNameExW
K32GetModuleInformation
K32GetPerformanceInfo
K32GetProcessImageFileNameW
K32GetProcessMemoryInfo
K32GetWsChanges
K32GetWsChangesEx
K32InitializeProcessForWsWatch
K32QueryWorkingSet
K32QueryWorkingSetEx
QueryFullProcessImageNameW
api-ms-win-core-psapi-ansi-l1-1-0.dll K32EnumPageFilesA
K32GetDeviceDriverBaseNameA
K32GetDeviceDriverFileNameA
K32GetMappedFileNameA
K32GetModuleBaseNameA
K32GetModuleFileNameExA
K32GetProcessImageFileNameA
QueryFullProcessImageNameA
api-ms-win-eventing-provider-l1-1-0.dll EventRegister
EventSetInformation
EventUnregister
EventWriteTransfer
api-ms-win-core-apiquery-l1-1-0.dll ApiSetQueryApiSetPresence
api-ms-win-core-delayload-l1-1-1.dll ResolveDelayLoadedAPI
api-ms-win-core-appcompat-l1-1-1.dll BaseFreeAppCompatDataForProcess
BaseReadAppCompatDataForProcess
ext-ms-win-oobe-query-l1-1-0.dll (delay-loaded) QueryOOBESupport

Delayed Imports

Attributes 0x1
Name ext-ms-win-oobe-query-l1-1-0.dll
ModuleHandle 0x14ebd8
DelayImportAddressTable 0x158130
DelayImportNameTable 0x11bca0
BoundDelayImportTable 0x11c190
UnloadDelayImportTable 0
TimeStamp 1970-Jan-01 00:00:00

AcquireSRWLockExclusive

Ordinal 1
Address 0x13215b
ForwardName NTDLL.RtlAcquireSRWLockExclusive

AcquireSRWLockShared

Ordinal 2
Address 0x132191
ForwardName NTDLL.RtlAcquireSRWLockShared

ActivateActCtx

Ordinal 3
Address 0x84dc0

ActivateActCtxWorker

Ordinal 4
Address 0x17bf0

ActivatePackageVirtualizationContext

Ordinal 5
Address 0x1b3b0

AddAtomA

Ordinal 6
Address 0x4fd30

AddAtomW

Ordinal 7
Address 0x10790

AddConsoleAliasA

Ordinal 8
Address 0x70ea0

AddConsoleAliasW

Ordinal 9
Address 0x70eb0

AddDllDirectory

Ordinal 10
Address 0x13223c
ForwardName api-ms-win-core-libraryloader-l1-1-0.AddDllDirectory

AddIntegrityLabelToBoundaryDescriptor

Ordinal 11
Address 0x87910

AddLocalAlternateComputerNameA

Ordinal 12
Address 0x50080

AddLocalAlternateComputerNameW

Ordinal 13
Address 0x500f0

AddRefActCtx

Ordinal 14
Address 0x84dd0

AddRefActCtxWorker

Ordinal 15
Address 0x8d990

AddResourceAttributeAce

Ordinal 16
Address 0x84de0

AddSIDToBoundaryDescriptor

Ordinal 17
Address 0x84df0

AddScopedPolicyIDAce

Ordinal 18
Address 0x84e00

AddSecureMemoryCacheCallback

Ordinal 19
Address 0x81ba0

AddVectoredContinueHandler

Ordinal 20
Address 0x132375
ForwardName NTDLL.RtlAddVectoredContinueHandler

AddVectoredExceptionHandler

Ordinal 21
Address 0x1323b5
ForwardName NTDLL.RtlAddVectoredExceptionHandler

AdjustCalendarDate

Ordinal 22
Address 0x13270

AllocConsole

Ordinal 23
Address 0x70af0

AllocateUserPhysicalPages

Ordinal 24
Address 0x84e20

AllocateUserPhysicalPagesNuma

Ordinal 25
Address 0x84e10

AppPolicyGetClrCompat

Ordinal 26
Address 0x132448
ForwardName kernelbase.AppPolicyGetClrCompat

AppPolicyGetCreateFileAccess

Ordinal 27
Address 0x132486
ForwardName kernelbase.AppPolicyGetCreateFileAccess

AppPolicyGetLifecycleManagement

Ordinal 28
Address 0x1324ce
ForwardName kernelbase.AppPolicyGetLifecycleManagement

AppPolicyGetMediaFoundationCodecLoading

Ordinal 29
Address 0x132521
ForwardName kernelbase.AppPolicyGetMediaFoundationCodecLoading

AppPolicyGetProcessTerminationMethod

Ordinal 30
Address 0x132579
ForwardName kernelbase.AppPolicyGetProcessTerminationMethod

AppPolicyGetShowDeveloperDiagnostic

Ordinal 31
Address 0x1325cd
ForwardName kernelbase.AppPolicyGetShowDeveloperDiagnostic

AppPolicyGetThreadInitializationType

Ordinal 32
Address 0x132621
ForwardName kernelbase.AppPolicyGetThreadInitializationType

AppPolicyGetWindowingModel

Ordinal 33
Address 0x13266c
ForwardName kernelbase.AppPolicyGetWindowingModel

AppXGetOSMaxVersionTested

Ordinal 34
Address 0x1326ac
ForwardName kernelbase.AppXGetOSMaxVersionTested

ApplicationRecoveryFinished

Ordinal 35
Address 0x36f00

ApplicationRecoveryInProgress

Ordinal 36
Address 0x36f90

AreFileApisANSI

Ordinal 37
Address 0x84e30

AreShortNamesEnabled

Ordinal 38
Address 0x4a300

AssignProcessToJobObject

Ordinal 39
Address 0x12260

AttachConsole

Ordinal 40
Address 0x70b00

BackupRead

Ordinal 41
Address 0x52650

BackupSeek

Ordinal 42
Address 0x52f30

BackupWrite

Ordinal 43
Address 0x530f0

BaseCheckAppcompatCache

Ordinal 44
Address 0x84e80

BaseCheckAppcompatCacheEx

Ordinal 45
Address 0x84e40

BaseCheckAppcompatCacheExWorker

Ordinal 46
Address 0xd8230

BaseCheckAppcompatCacheWorker

Ordinal 47
Address 0x71b60

BaseCheckElevation

Ordinal 48
Address 0xd1e0

BaseCleanupAppcompatCacheSupport

Ordinal 49
Address 0x84e90

BaseCleanupAppcompatCacheSupportWorker

Ordinal 50
Address 0x71ba0

BaseDestroyVDMEnvironment

Ordinal 51
Address 0x8ad90

BaseDllReadWriteIniFile

Ordinal 52
Address 0xfcf0

BaseDumpAppcompatCache

Ordinal 53
Address 0x84ea0

BaseDumpAppcompatCacheWorker

Ordinal 54
Address 0x80560

BaseElevationPostProcessing

Ordinal 55
Address 0x18c80

BaseFlushAppcompatCache

Ordinal 56
Address 0x84eb0

BaseFlushAppcompatCacheWorker

Ordinal 57
Address 0xd8240

BaseFormatObjectAttributes

Ordinal 58
Address 0x6e7b0

BaseFormatTimeOut

Ordinal 59
Address 0xb2e50

BaseFreeAppCompatDataForProcessWorker

Ordinal 60
Address 0xa5860

BaseGenerateAppCompatData

Ordinal 61
Address 0x15e30

BaseGetNamedObjectDirectory

Ordinal 62
Address 0x84ec0

BaseInitAppcompatCacheSupport

Ordinal 63
Address 0x84ed0

BaseInitAppcompatCacheSupportWorker

Ordinal 64
Address 0x71ba0

BaseIsAppcompatInfrastructureDisabled

Ordinal 65
Address 0x71b60

BaseIsAppcompatInfrastructureDisabledWorker

Ordinal 66
Address 0x71b60

BaseIsDosApplication

Ordinal 67
Address 0xb9700

BaseQueryModuleData

Ordinal 68
Address 0x5f4f0

BaseReadAppCompatDataForProcessWorker

Ordinal 69
Address 0x66d0

BaseSetLastNTError

Ordinal 70
Address 0xb2e10

BaseThreadInitThunk

Ordinal 71
Address 0x122a0

BaseUpdateAppcompatCache

Ordinal 72
Address 0x84ee0

BaseUpdateAppcompatCacheWorker

Ordinal 73
Address 0x5f4c0

BaseUpdateVDMEntry

Ordinal 74
Address 0x34db0

BaseVerifyUnicodeString

Ordinal 75
Address 0xb4a60

BaseWriteErrorElevationRequiredEvent

Ordinal 76
Address 0xb8290

Basep8BitStringToDynamicUnicodeString

Ordinal 77
Address 0x6670

BasepAllocateActivationContextActivationBlock

Ordinal 78
Address 0x4a080

BasepAnsiStringToDynamicUnicodeString

Ordinal 79
Address 0xb31b0

BasepAppContainerEnvironmentExtension

Ordinal 80
Address 0x16bd0

BasepAppXExtension

Ordinal 81
Address 0x832b0

BasepCheckAppCompat

Ordinal 82
Address 0x4d650

BasepCheckWebBladeHashes

Ordinal 83
Address 0x18bb0

BasepCheckWinSaferRestrictions

Ordinal 84
Address 0x17700

BasepConstructSxsCreateProcessMessage

Ordinal 85
Address 0xab50

BasepCopyEncryption

Ordinal 86
Address 0x2ffa0

BasepFinishPackageActivation

Ordinal 87
Address 0x30f60

BasepFinishPackageActivationForSxS

Ordinal 88
Address 0x36cc0

BasepFreeActivationContextActivationBlock

Ordinal 89
Address 0xb33b0

BasepFreeAppCompatData

Ordinal 90
Address 0x18180

BasepGetAppCompatData

Ordinal 91
Address 0x15670

BasepGetComputerNameFromNtPath

Ordinal 92
Address 0x6b00

BasepGetExeArchType

Ordinal 93
Address 0xb85a0

BasepGetPackageActivationTokenForFilePath

Ordinal 94
Address 0x30f70

BasepGetPackageActivationTokenForSxS

Ordinal 95
Address 0x1f560

BasepGetPackagedAppInfoForFile

Ordinal 96
Address 0x83b20

BasepInitAppCompatData

Ordinal 97
Address 0xd8d00

BasepIsProcessAllowed

Ordinal 98
Address 0x180a0

BasepMapModuleHandle

Ordinal 99
Address 0xb4c10

BasepNotifyLoadStringResource

Ordinal 100
Address 0x91550

BasepPostSuccessAppXExtension

Ordinal 101
Address 0x83cf0

BasepProcessInvalidImage

Ordinal 102
Address 0x30f80

BasepQueryAppCompat

Ordinal 103
Address 0x15ed0

BasepQueryModuleChpeSettings

Ordinal 104
Address 0x16170

BasepReleaseAppXContext

Ordinal 105
Address 0x843f0

BasepReleasePackagedAppInfo

Ordinal 106
Address 0x84400

BasepReleaseSxsCreateProcessUtilityStruct

Ordinal 107
Address 0xa860

BasepReportFault

Ordinal 108
Address 0x37170

BasepSetFileEncryptionCompression

Ordinal 109
Address 0x6c70

Beep

Ordinal 110
Address 0x2f950

BeginUpdateResourceA

Ordinal 111
Address 0x3cb00

BeginUpdateResourceW

Ordinal 112
Address 0x3cb70

BindIoCompletionCallback

Ordinal 113
Address 0x1ae40

BuildCommDCBA

Ordinal 114
Address 0x36120

BuildCommDCBAndTimeoutsA

Ordinal 115
Address 0x36170

BuildCommDCBAndTimeoutsW

Ordinal 116
Address 0x361b0

BuildCommDCBW

Ordinal 117
Address 0x36240

BuildIoRingCancelRequest

Ordinal 118
Address 0x132f90
ForwardName api-ms-win-core-ioring-l1-1-0.BuildIoRingCancelRequest

BuildIoRingFlushFile

Ordinal 119
Address 0x132fdc
ForwardName api-ms-win-core-ioring-l1-1-1.BuildIoRingFlushFile

BuildIoRingReadFile

Ordinal 120
Address 0x133023
ForwardName api-ms-win-core-ioring-l1-1-0.BuildIoRingReadFile

BuildIoRingRegisterBuffers

Ordinal 121
Address 0x133070
ForwardName api-ms-win-core-ioring-l1-1-0.BuildIoRingRegisterBuffers

BuildIoRingRegisterFileHandles

Ordinal 122
Address 0x1330c8
ForwardName api-ms-win-core-ioring-l1-1-0.BuildIoRingRegisterFileHandles

BuildIoRingWriteFile

Ordinal 123
Address 0x13311a
ForwardName api-ms-win-core-ioring-l1-1-1.BuildIoRingWriteFile

CallNamedPipeA

Ordinal 124
Address 0x56940

CallNamedPipeW

Ordinal 125
Address 0x6fb30

CallbackMayRunLong

Ordinal 126
Address 0x84ef0

CancelDeviceWakeupRequest

Ordinal 127
Address 0x83270

CancelIo

Ordinal 128
Address 0x84f40

CancelIoEx

Ordinal 129
Address 0x84f30

CancelSynchronousIo

Ordinal 130
Address 0x84f50

CancelThreadpoolIo

Ordinal 131
Address 0x1331d3
ForwardName NTDLL.TpCancelAsyncIoOperation

CancelTimerQueueTimer

Ordinal 132
Address 0x915b0

CancelWaitableTimer

Ordinal 133
Address 0x6f100

CeipIsOptedIn

Ordinal 134
Address 0x13322a
ForwardName kernelbase.CeipIsOptedIn

ChangeTimerQueueTimer

Ordinal 135
Address 0x84f60

CheckAllowDecryptedRemoteDestinationPolicy

Ordinal 136
Address 0x84f70

CheckElevation

Ordinal 137
Address 0x4d710

CheckElevationEnabled

Ordinal 138
Address 0xb8870

CheckForReadOnlyResource

Ordinal 139
Address 0xbbfa0

CheckForReadOnlyResourceFilter

Ordinal 140
Address 0x71b60

CheckNameLegalDOS8Dot3A

Ordinal 141
Address 0x30db0

CheckNameLegalDOS8Dot3W

Ordinal 142
Address 0x30e50

CheckRemoteDebuggerPresent

Ordinal 143
Address 0x84f80

CheckTokenCapability

Ordinal 144
Address 0x84f90

CheckTokenMembershipEx

Ordinal 145
Address 0x84fa0

ClearCommBreak

Ordinal 146
Address 0x70410

ClearCommError

Ordinal 147
Address 0x70420

CloseConsoleHandle

Ordinal 148
Address 0xcfb30

CloseHandle

Ordinal 149
Address 0x6f080

CloseIoRing

Ordinal 150
Address 0x1333a1
ForwardName api-ms-win-core-ioring-l1-1-0.CloseIoRing

ClosePackageInfo

Ordinal 151
Address 0x1333dc
ForwardName kernelbase.ClosePackageInfo

ClosePrivateNamespace

Ordinal 152
Address 0x84fb0

CloseProfileUserMapping

Ordinal 153
Address 0x71ba0

ClosePseudoConsole

Ordinal 154
Address 0x70b10

CloseState

Ordinal 155
Address 0x133444
ForwardName kernelbase.CloseState

CloseThreadpool

Ordinal 156
Address 0x13346a
ForwardName NTDLL.TpReleasePool

CloseThreadpoolCleanupGroup

Ordinal 157
Address 0x13349a
ForwardName NTDLL.TpReleaseCleanupGroup

CloseThreadpoolCleanupGroupMembers

Ordinal 158
Address 0x1334d9
ForwardName NTDLL.TpReleaseCleanupGroupMembers

CloseThreadpoolIo

Ordinal 159
Address 0x13350e
ForwardName NTDLL.TpReleaseIoCompletion

CloseThreadpoolTimer

Ordinal 160
Address 0x13353f
ForwardName NTDLL.TpReleaseTimer

CloseThreadpoolWait

Ordinal 161
Address 0x133568
ForwardName NTDLL.TpReleaseWait

CloseThreadpoolWork

Ordinal 162
Address 0x133590
ForwardName NTDLL.TpReleaseWork

CmdBatNotification

Ordinal 163
Address 0x34ea0

CommConfigDialogA

Ordinal 164
Address 0x32670

CommConfigDialogW

Ordinal 165
Address 0x32710

CompareCalendarDates

Ordinal 166
Address 0x3e480

CompareFileTime

Ordinal 167
Address 0x6f3f0

CompareStringA

Ordinal 168
Address 0x84fe0

CompareStringEx

Ordinal 169
Address 0x84ff0

CompareStringOrdinal

Ordinal 170
Address 0x85020

CompareStringW

Ordinal 171
Address 0x85030

ConnectNamedPipe

Ordinal 172
Address 0x85040

ConsoleMenuControl

Ordinal 173
Address 0x58be0

ContinueDebugEvent

Ordinal 174
Address 0x85050

ConvertCalDateTimeToSystemTime

Ordinal 175
Address 0x3e560

ConvertDefaultLocale

Ordinal 176
Address 0x85060

ConvertFiberToThread

Ordinal 177
Address 0x70880

ConvertNLSDayOfWeekToWin32DayOfWeek

Ordinal 178
Address 0x99fc0

ConvertSystemTimeToCalDateTime

Ordinal 179
Address 0x135d0

ConvertThreadToFiber

Ordinal 180
Address 0x70890

ConvertThreadToFiberEx

Ordinal 181
Address 0x708a0

CopyContext

Ordinal 182
Address 0x85070

CopyFile2

Ordinal 183
Address 0x85080

CopyFileA

Ordinal 184
Address 0x4efa0

CopyFileExA

Ordinal 185
Address 0x4f030

CopyFileExW

Ordinal 186
Address 0x85090

CopyFileTransactedA

Ordinal 187
Address 0x4f0e0

CopyFileTransactedW

Ordinal 188
Address 0x4f1d0

CopyFileW

Ordinal 189
Address 0x70730

CopyLZFile

Ordinal 190
Address 0x2f9d0

CreateActCtxA

Ordinal 191
Address 0x4f990

CreateActCtxW

Ordinal 192
Address 0x850a0

CreateActCtxWWorker

Ordinal 193
Address 0x9440

CreateBoundaryDescriptorA

Ordinal 194
Address 0x56be0

CreateBoundaryDescriptorW

Ordinal 195
Address 0x850b0

CreateConsoleScreenBuffer

Ordinal 196
Address 0x70c20

CreateDirectoryA

Ordinal 197
Address 0x6f400

CreateDirectoryExA

Ordinal 198
Address 0x4c220

CreateDirectoryExW

Ordinal 199
Address 0x850c0

CreateDirectoryTransactedA

Ordinal 200
Address 0x2fb80

CreateDirectoryTransactedW

Ordinal 201
Address 0xb6c80

CreateDirectoryW

Ordinal 202
Address 0x6f410

CreateEnclave

Ordinal 203
Address 0x1338b1
ForwardName api-ms-win-core-enclave-l1-1-0.CreateEnclave

CreateEventA

Ordinal 204
Address 0x6f110

CreateEventExA

Ordinal 205
Address 0x6f120

CreateEventExW

Ordinal 206
Address 0x6f130

CreateEventW

Ordinal 207
Address 0x6f140

CreateFiber

Ordinal 208
Address 0x708b0

CreateFiberEx

Ordinal 209
Address 0x708c0

CreateFile2

Ordinal 210
Address 0x6f420

CreateFileA

Ordinal 211
Address 0x6f430

CreateFileMappingA

Ordinal 212
Address 0x18c00

CreateFileMappingFromApp

Ordinal 213
Address 0x133974
ForwardName api-ms-win-core-memory-l1-1-1.CreateFileMappingFromApp

CreateFileMappingNumaA

Ordinal 214
Address 0x56d40

CreateFileMappingNumaW

Ordinal 215
Address 0x850d0

CreateFileMappingW

Ordinal 216
Address 0x850e0

CreateFileTransactedA

Ordinal 217
Address 0x4f2c0

CreateFileTransactedW

Ordinal 218
Address 0x4f370

CreateFileW

Ordinal 219
Address 0x6f360

CreateHardLinkA

Ordinal 220
Address 0x850f0

CreateHardLinkTransactedA

Ordinal 221
Address 0x36c10

CreateHardLinkTransactedW

Ordinal 222
Address 0xbd180

CreateHardLinkW

Ordinal 223
Address 0x85100

CreateIoCompletionPort

Ordinal 224
Address 0x85110

CreateIoRing

Ordinal 225
Address 0x133a9c
ForwardName api-ms-win-core-ioring-l1-1-0.CreateIoRing

CreateJobObjectA

Ordinal 226
Address 0x51f40

CreateJobObjectW

Ordinal 227
Address 0x19380

CreateJobSet

Ordinal 228
Address 0xc1160

CreateMailslotA

Ordinal 229
Address 0x56df0

CreateMailslotW

Ordinal 230
Address 0xca3e0

CreateMemoryResourceNotification

Ordinal 231
Address 0x85120

CreateMutexA

Ordinal 232
Address 0x6f150

CreateMutexExA

Ordinal 233
Address 0x6f160

CreateMutexExW

Ordinal 234
Address 0x6f170

CreateMutexW

Ordinal 235
Address 0x6f180

CreateNamedPipeA

Ordinal 236
Address 0x569d0

CreateNamedPipeW

Ordinal 237
Address 0x85130

CreatePackageVirtualizationContext

Ordinal 238
Address 0x1b440

CreatePipe

Ordinal 239
Address 0x85140

CreatePrivateNamespaceA

Ordinal 240
Address 0x56c50

CreatePrivateNamespaceW

Ordinal 241
Address 0x85150

CreateProcessA

Ordinal 242
Address 0x85160

CreateProcessAsUserA

Ordinal 243
Address 0x85190

CreateProcessAsUserW

Ordinal 244
Address 0x851d0

CreateProcessInternalA

Ordinal 245
Address 0x85210

CreateProcessInternalW

Ordinal 246
Address 0x85250

CreateProcessW

Ordinal 247
Address 0x85290

CreatePseudoConsole

Ordinal 248
Address 0x70b20

CreateRemoteThread

Ordinal 249
Address 0x852c0

CreateRemoteThreadEx

Ordinal 250
Address 0x133ca1
ForwardName api-ms-win-core-processthreads-l1-1-0.CreateRemoteThreadEx

CreateSemaphoreA

Ordinal 251
Address 0x1ab40

CreateSemaphoreExA

Ordinal 252
Address 0x1ab60

CreateSemaphoreExW

Ordinal 253
Address 0x6f190

CreateSemaphoreW

Ordinal 254
Address 0x6f1a0

CreateSymbolicLinkA

Ordinal 255
Address 0x56fe0

CreateSymbolicLinkTransactedA

Ordinal 256
Address 0x57080

CreateSymbolicLinkTransactedW

Ordinal 257
Address 0xcacf0

CreateSymbolicLinkW

Ordinal 258
Address 0x852e0

CreateTapePartition

Ordinal 259
Address 0x36a80

CreateThread

Ordinal 260
Address 0x85310

CreateThreadpool

Ordinal 261
Address 0x1adb0

CreateThreadpoolCleanupGroup

Ordinal 262
Address 0x19a20

CreateThreadpoolIo

Ordinal 263
Address 0x1a910

CreateThreadpoolTimer

Ordinal 264
Address 0x18770

CreateThreadpoolWait

Ordinal 265
Address 0x19060

CreateThreadpoolWork

Ordinal 266
Address 0x18e90

CreateTimerQueue

Ordinal 267
Address 0x854c0

CreateTimerQueueTimer

Ordinal 268
Address 0x854d0

CreateToolhelp32Snapshot

Ordinal 269
Address 0x1e010

CreateUmsCompletionList

Ordinal 270
Address 0x8c620

CreateUmsThreadContext

Ordinal 271
Address 0x8c620

CreateWaitableTimerA

Ordinal 272
Address 0x20a60

CreateWaitableTimerExA

Ordinal 273
Address 0x20a80

CreateWaitableTimerExW

Ordinal 274
Address 0x6f1b0

CreateWaitableTimerW

Ordinal 275
Address 0xca820

CtrlRoutine

Ordinal 276
Address 0x133efd
ForwardName kernelbase.CtrlRoutine

DeactivateActCtx

Ordinal 277
Address 0x854e0

DeactivateActCtxWorker

Ordinal 278
Address 0x17c30

DeactivatePackageVirtualizationContext

Ordinal 279
Address 0x1b460

DebugActiveProcess

Ordinal 280
Address 0x85500

DebugActiveProcessStop

Ordinal 281
Address 0x854f0

DebugBreak

Ordinal 282
Address 0x85510

DebugBreakProcess

Ordinal 283
Address 0x80770

DebugSetProcessKillOnExit

Ordinal 284
Address 0x807b0

DecodePointer

Ordinal 285
Address 0x133fd2
ForwardName NTDLL.RtlDecodePointer

DecodeSystemPointer

Ordinal 286
Address 0x133ffd
ForwardName NTDLL.RtlDecodeSystemPointer

DefineDosDeviceA

Ordinal 287
Address 0x57ca0

DefineDosDeviceW

Ordinal 288
Address 0x6f440

DelayLoadFailureHook

Ordinal 289
Address 0x85520

DeleteAtom

Ordinal 290
Address 0x105b0

DeleteBoundaryDescriptor

Ordinal 291
Address 0x85530

DeleteCriticalSection

Ordinal 292
Address 0x13408b
ForwardName NTDLL.RtlDeleteCriticalSection

DeleteFiber

Ordinal 293
Address 0x708d0

DeleteFileA

Ordinal 294
Address 0x6f450

DeleteFileTransactedA

Ordinal 295
Address 0x57130

DeleteFileTransactedW

Ordinal 296
Address 0xcae10

DeleteFileW

Ordinal 297
Address 0x6f3d0

DeleteProcThreadAttributeList

Ordinal 298
Address 0x134118
ForwardName api-ms-win-core-processthreads-l1-1-0.DeleteProcThreadAttributeList

DeleteSynchronizationBarrier

Ordinal 299
Address 0x85540

DeleteTimerQueue

Ordinal 300
Address 0x6f910

DeleteTimerQueueEx

Ordinal 301
Address 0x85550

DeleteTimerQueueTimer

Ordinal 302
Address 0x85560

DeleteUmsCompletionList

Ordinal 303
Address 0x8c620

DeleteUmsThreadContext

Ordinal 304
Address 0x8c620

DeleteVolumeMountPointA

Ordinal 305
Address 0x4d820

DeleteVolumeMountPointW

Ordinal 306
Address 0x6f460

DequeueUmsCompletionListItems

Ordinal 307
Address 0x8c620

DeviceIoControl

Ordinal 308
Address 0x13180

DisableThreadLibraryCalls

Ordinal 309
Address 0x85570

DisableThreadProfiling

Ordinal 310
Address 0x91680

DisassociateCurrentThreadFromCallback

Ordinal 311
Address 0x134297
ForwardName NTDLL.TpDisassociateCallback

DiscardVirtualMemory

Ordinal 312
Address 0x1342c9
ForwardName api-ms-win-core-memory-l1-1-2.DiscardVirtualMemory

DisconnectNamedPipe

Ordinal 313
Address 0x85580

DnsHostnameToComputerNameA

Ordinal 314
Address 0x50ef0

DnsHostnameToComputerNameExW

Ordinal 315
Address 0x85590

DnsHostnameToComputerNameW

Ordinal 316
Address 0x50fd0

DosDateTimeToFileTime

Ordinal 317
Address 0x10500

DosPathToSessionPathA

Ordinal 318
Address 0x57f00

DosPathToSessionPathW

Ordinal 319
Address 0x580b0

DuplicateConsoleHandle

Ordinal 320
Address 0xcfb40

DuplicateEncryptionInfoFileExt

Ordinal 321
Address 0x302f0

DuplicateHandle

Ordinal 322
Address 0x6f0a0

DuplicatePackageVirtualizationContext

Ordinal 323
Address 0x1b480

EnableThreadProfiling

Ordinal 324
Address 0x916b0

EncodePointer

Ordinal 325
Address 0x134435
ForwardName NTDLL.RtlEncodePointer

EncodeSystemPointer

Ordinal 326
Address 0x134460
ForwardName NTDLL.RtlEncodeSystemPointer

EndUpdateResourceA

Ordinal 327
Address 0x3cd70

EndUpdateResourceW

Ordinal 328
Address 0x3cd80

EnterCriticalSection

Ordinal 329
Address 0x1344b8
ForwardName NTDLL.RtlEnterCriticalSection

EnterSynchronizationBarrier

Ordinal 330
Address 0x855b0

EnterUmsSchedulingMode

Ordinal 331
Address 0x8c620

EnumCalendarInfoA

Ordinal 332
Address 0x984c0

EnumCalendarInfoExA

Ordinal 333
Address 0x98550

EnumCalendarInfoExEx

Ordinal 334
Address 0x855c0

EnumCalendarInfoExW

Ordinal 335
Address 0x855d0

EnumCalendarInfoW

Ordinal 336
Address 0x855e0

EnumDateFormatsA

Ordinal 337
Address 0x985e0

EnumDateFormatsExA

Ordinal 338
Address 0x98640

EnumDateFormatsExEx

Ordinal 339
Address 0x855f0

EnumDateFormatsExW

Ordinal 340
Address 0x85600

EnumDateFormatsW

Ordinal 341
Address 0x85610

EnumLanguageGroupLocalesA

Ordinal 342
Address 0x986a0

EnumLanguageGroupLocalesW

Ordinal 343
Address 0x85620

EnumResourceLanguagesA

Ordinal 344
Address 0x82a50

EnumResourceLanguagesExA

Ordinal 345
Address 0x85630

EnumResourceLanguagesExW

Ordinal 346
Address 0x85640

EnumResourceLanguagesW

Ordinal 347
Address 0x82a60

EnumResourceNamesA

Ordinal 348
Address 0x6fa90

EnumResourceNamesExA

Ordinal 349
Address 0x85650

EnumResourceNamesExW

Ordinal 350
Address 0x85660

EnumResourceNamesW

Ordinal 351
Address 0x6f970

EnumResourceTypesA

Ordinal 352
Address 0x82a70

EnumResourceTypesExA

Ordinal 353
Address 0x85670

EnumResourceTypesExW

Ordinal 354
Address 0x85680

EnumResourceTypesW

Ordinal 355
Address 0x82a80

EnumSystemCodePagesA

Ordinal 356
Address 0x986b0

EnumSystemCodePagesW

Ordinal 357
Address 0x85690

EnumSystemFirmwareTables

Ordinal 358
Address 0x81be0

EnumSystemGeoID

Ordinal 359
Address 0x44ee0

EnumSystemGeoNames

Ordinal 360
Address 0x44fe0

EnumSystemLanguageGroupsA

Ordinal 361
Address 0x986c0

EnumSystemLanguageGroupsW

Ordinal 362
Address 0x856a0

EnumSystemLocalesA

Ordinal 363
Address 0x856b0

EnumSystemLocalesEx

Ordinal 364
Address 0x856c0

EnumSystemLocalesW

Ordinal 365
Address 0x856d0

EnumTimeFormatsA

Ordinal 366
Address 0x986d0

EnumTimeFormatsEx

Ordinal 367
Address 0x856e0

EnumTimeFormatsW

Ordinal 368
Address 0x856f0

EnumUILanguagesA

Ordinal 369
Address 0x98740

EnumUILanguagesW

Ordinal 370
Address 0x85700

EnumerateLocalComputerNamesA

Ordinal 371
Address 0x510a0

EnumerateLocalComputerNamesW

Ordinal 372
Address 0x511a0

EraseTape

Ordinal 373
Address 0x8d660

EscapeCommFunction

Ordinal 374
Address 0x70430

ExecuteUmsThread

Ordinal 375
Address 0x8c650

ExitProcess

Ordinal 376
Address 0x845c0

ExitThread

Ordinal 377
Address 0x1348a3
ForwardName NTDLL.RtlExitUserThread

ExitVDM

Ordinal 378
Address 0x34f10

ExpandEnvironmentStringsA

Ordinal 379
Address 0x85710

ExpandEnvironmentStringsW

Ordinal 380
Address 0x85720

ExpungeConsoleCommandHistoryA

Ordinal 381
Address 0x70ec0

ExpungeConsoleCommandHistoryW

Ordinal 382
Address 0x70ed0

FatalAppExitA

Ordinal 383
Address 0x85730

FatalAppExitW

Ordinal 384
Address 0x85740

FatalExit

Ordinal 385
Address 0x845c0

FileTimeToDosDateTime

Ordinal 386
Address 0x10a60

FileTimeToLocalFileTime

Ordinal 387
Address 0x6f470

FileTimeToSystemTime

Ordinal 388
Address 0x6fd70

FillConsoleOutputAttribute

Ordinal 389
Address 0x70c30

FillConsoleOutputCharacterA

Ordinal 390
Address 0x70c40

FillConsoleOutputCharacterW

Ordinal 391
Address 0x70c50

FindActCtxSectionGuid

Ordinal 392
Address 0x85750

FindActCtxSectionGuidWorker

Ordinal 393
Address 0x10b40

FindActCtxSectionStringA

Ordinal 394
Address 0x4fca0

FindActCtxSectionStringW

Ordinal 395
Address 0x85760

FindActCtxSectionStringWWorker

Ordinal 396
Address 0x102d0

FindAtomA

Ordinal 397
Address 0x4fd60

FindAtomW

Ordinal 398
Address 0x108f0

FindClose

Ordinal 399
Address 0x6f480

FindCloseChangeNotification

Ordinal 400
Address 0x6f490

FindFirstChangeNotificationA

Ordinal 401
Address 0x6f4a0

FindFirstChangeNotificationW

Ordinal 402
Address 0x6f4b0

FindFirstFileA

Ordinal 403
Address 0x6f4c0

FindFirstFileExA

Ordinal 404
Address 0x6f310

FindFirstFileExW

Ordinal 405
Address 0x6f4d0

FindFirstFileNameTransactedW

Ordinal 406
Address 0x809a0

FindFirstFileNameW

Ordinal 407
Address 0x6f300

FindFirstFileTransactedA

Ordinal 408
Address 0x2fc80

FindFirstFileTransactedW

Ordinal 409
Address 0x58250

FindFirstFileW

Ordinal 410
Address 0x6f4e0

FindFirstStreamTransactedW

Ordinal 411
Address 0x80b50

FindFirstStreamW

Ordinal 412
Address 0x134bb4
ForwardName api-ms-win-core-file-l1-2-2.FindFirstStreamW

FindFirstVolumeA

Ordinal 413
Address 0x4d870

FindFirstVolumeMountPointA

Ordinal 414
Address 0x4d9d0

FindFirstVolumeMountPointW

Ordinal 415
Address 0x4db60

FindFirstVolumeW

Ordinal 416
Address 0x6f4f0

FindNLSString

Ordinal 417
Address 0x857a0

FindNLSStringEx

Ordinal 418
Address 0x85770

FindNextChangeNotification

Ordinal 419
Address 0x6f500

FindNextFileA

Ordinal 420
Address 0x6f510

FindNextFileNameW

Ordinal 421
Address 0x6f520

FindNextFileW

Ordinal 422
Address 0x6f530

FindNextStreamW

Ordinal 423
Address 0x134cb0
ForwardName api-ms-win-core-file-l1-2-2.FindNextStreamW

FindNextVolumeA

Ordinal 424
Address 0x4dd40

FindNextVolumeMountPointA

Ordinal 425
Address 0x4deb0

FindNextVolumeMountPointW

Ordinal 426
Address 0x4e500

FindNextVolumeW

Ordinal 427
Address 0x6f540

FindPackagesByPackageFamily

Ordinal 428
Address 0x134d4c
ForwardName kernelbase.FindPackagesByPackageFamily

FindResourceA

Ordinal 429
Address 0x17490

FindResourceExA

Ordinal 430
Address 0x174b0

FindResourceExW

Ordinal 431
Address 0x857b0

FindResourceW

Ordinal 432
Address 0x857c0

FindStringOrdinal

Ordinal 433
Address 0x857d0

FindVolumeClose

Ordinal 434
Address 0x6f550

FindVolumeMountPointClose

Ordinal 435
Address 0xbb0e0

FlsAlloc

Ordinal 436
Address 0x857e0

FlsFree

Ordinal 437
Address 0x857f0

FlsGetValue

Ordinal 438
Address 0x85800

FlsSetValue

Ordinal 439
Address 0x85810

FlushConsoleInputBuffer

Ordinal 440
Address 0x70c60

FlushFileBuffers

Ordinal 441
Address 0x6f560

FlushInstructionCache

Ordinal 442
Address 0x85820

FlushProcessWriteBuffers

Ordinal 443
Address 0x134e6c
ForwardName NTDLL.NtFlushProcessWriteBuffers

FlushViewOfFile

Ordinal 444
Address 0x85830

FoldStringA

Ordinal 445
Address 0x3d320

FoldStringW

Ordinal 446
Address 0x85840

FormatApplicationUserModelId

Ordinal 447
Address 0x134ed2
ForwardName kernelbase.FormatApplicationUserModelId

FormatMessageA

Ordinal 448
Address 0x85850

FormatMessageW

Ordinal 449
Address 0x85860

FreeConsole

Ordinal 450
Address 0x70b30

FreeEnvironmentStringsA

Ordinal 451
Address 0x85870

FreeEnvironmentStringsW

Ordinal 452
Address 0x85880

FreeLibrary

Ordinal 453
Address 0x858a0

FreeLibraryAndExitThread

Ordinal 454
Address 0x85890

FreeLibraryWhenCallbackReturns

Ordinal 455
Address 0x134f98
ForwardName NTDLL.TpCallbackUnloadDllOnCompletion

FreeMemoryJobObject

Ordinal 456
Address 0x7fe30

FreeResource

Ordinal 457
Address 0x858b0

FreeUserPhysicalPages

Ordinal 458
Address 0x858c0

GenerateConsoleCtrlEvent

Ordinal 459
Address 0x70c70

GetACP

Ordinal 460
Address 0x858d0

GetActiveProcessorCount

Ordinal 461
Address 0x18f40

GetActiveProcessorGroupCount

Ordinal 462
Address 0x4c310

GetAppContainerAce

Ordinal 463
Address 0x858e0

GetAppContainerNamedObjectPath

Ordinal 464
Address 0x858f0

GetApplicationRecoveryCallback

Ordinal 465
Address 0x85900

GetApplicationRecoveryCallbackWorker

Ordinal 466
Address 0x36fa0

GetApplicationRestartSettings

Ordinal 467
Address 0x85910

GetApplicationRestartSettingsWorker

Ordinal 468
Address 0x37050

GetApplicationUserModelId

Ordinal 469
Address 0x13511c
ForwardName kernelbase.GetApplicationUserModelId

GetAtomNameA

Ordinal 470
Address 0x4fd90

GetAtomNameW

Ordinal 471
Address 0x10480

GetBinaryType

Ordinal 472
Address 0x4ccc0

GetBinaryTypeA

Ordinal 473
Address 0x4ccc0

GetBinaryTypeW

Ordinal 474
Address 0x4cd20

GetCPInfo

Ordinal 475
Address 0x85930

GetCPInfoExA

Ordinal 476
Address 0x3d530

GetCPInfoExW

Ordinal 477
Address 0x85920

GetCachedSigningLevel

Ordinal 478
Address 0x85940

GetCalendarDateFormat

Ordinal 479
Address 0x3e6b0

GetCalendarDateFormatEx

Ordinal 480
Address 0x13ed0

GetCalendarDaysInMonth

Ordinal 481
Address 0x154c0

GetCalendarDifferenceInDays

Ordinal 482
Address 0x3e980

GetCalendarInfoA

Ordinal 483
Address 0x3d5d0

GetCalendarInfoEx

Ordinal 484
Address 0x6fff0

GetCalendarInfoW

Ordinal 485
Address 0x70000

GetCalendarMonthsInYear

Ordinal 486
Address 0x3eb10

GetCalendarSupportedDateRange

Ordinal 487
Address 0x134d0

GetCalendarWeekNumber

Ordinal 488
Address 0x3ec00

GetComPlusPackageInstallStatus

Ordinal 489
Address 0x911a0

GetCommConfig

Ordinal 490
Address 0x70440

GetCommMask

Ordinal 491
Address 0x70450

GetCommModemStatus

Ordinal 492
Address 0x70460

GetCommProperties

Ordinal 493
Address 0x70470

GetCommState

Ordinal 494
Address 0x70480

GetCommTimeouts

Ordinal 495
Address 0x70490

GetCommandLineA

Ordinal 496
Address 0x85950

GetCommandLineW

Ordinal 497
Address 0x85960

GetCompressedFileSizeA

Ordinal 498
Address 0x85970

GetCompressedFileSizeTransactedA

Ordinal 499
Address 0x57190

GetCompressedFileSizeTransactedW

Ordinal 500
Address 0xcaf30

GetCompressedFileSizeW

Ordinal 501
Address 0x85980

GetComputerNameA

Ordinal 502
Address 0x1ac90

GetComputerNameExA

Ordinal 503
Address 0x85990

GetComputerNameExW

Ordinal 504
Address 0x859a0

GetComputerNameW

Ordinal 505
Address 0x18240

GetConsoleAliasA

Ordinal 506
Address 0x70ee0

GetConsoleAliasExesA

Ordinal 507
Address 0x70ef0

GetConsoleAliasExesLengthA

Ordinal 508
Address 0x70f00

GetConsoleAliasExesLengthW

Ordinal 509
Address 0x70f10

GetConsoleAliasExesW

Ordinal 510
Address 0x70f20

GetConsoleAliasW

Ordinal 511
Address 0x70f30

GetConsoleAliasesA

Ordinal 512
Address 0x70f40

GetConsoleAliasesLengthA

Ordinal 513
Address 0x70f50

GetConsoleAliasesLengthW

Ordinal 514
Address 0x70f60

GetConsoleAliasesW

Ordinal 515
Address 0x70f70

GetConsoleCP

Ordinal 516
Address 0x70ae0

GetConsoleCharType

Ordinal 517
Address 0x59050

GetConsoleCommandHistoryA

Ordinal 518
Address 0x70f80

GetConsoleCommandHistoryLengthA

Ordinal 519
Address 0x70f90

GetConsoleCommandHistoryLengthW

Ordinal 520
Address 0x70fa0

GetConsoleCommandHistoryW

Ordinal 521
Address 0x70fb0

GetConsoleCursorInfo

Ordinal 522
Address 0x70c80

GetConsoleCursorMode

Ordinal 523
Address 0x590b0

GetConsoleDisplayMode

Ordinal 524
Address 0x70e90

GetConsoleFontInfo

Ordinal 525
Address 0x59390

GetConsoleFontSize

Ordinal 526
Address 0x70fc0

GetConsoleHardwareState

Ordinal 527
Address 0x58c30

GetConsoleHistoryInfo

Ordinal 528
Address 0x70fd0

GetConsoleInputExeNameA

Ordinal 529
Address 0x13560f
ForwardName kernelbase.GetConsoleInputExeNameA

GetConsoleInputExeNameW

Ordinal 530
Address 0x13564a
ForwardName kernelbase.GetConsoleInputExeNameW

GetConsoleInputWaitHandle

Ordinal 531
Address 0xcfbc0

GetConsoleKeyboardLayoutNameA

Ordinal 532
Address 0x59410

GetConsoleKeyboardLayoutNameW

Ordinal 533
Address 0x59420

GetConsoleMode

Ordinal 534
Address 0x70b40

GetConsoleNlsMode

Ordinal 535
Address 0x59120

GetConsoleOriginalTitleA

Ordinal 536
Address 0x70c90

GetConsoleOriginalTitleW

Ordinal 537
Address 0x70ca0

GetConsoleOutputCP

Ordinal 538
Address 0x70b50

GetConsoleProcessList

Ordinal 539
Address 0x70fe0

GetConsoleScreenBufferInfo

Ordinal 540
Address 0x70cb0

GetConsoleScreenBufferInfoEx

Ordinal 541
Address 0x70cc0

GetConsoleSelectionInfo

Ordinal 542
Address 0x70ff0

GetConsoleTitleA

Ordinal 543
Address 0x70cd0

GetConsoleTitleW

Ordinal 544
Address 0x70ce0

GetConsoleWindow

Ordinal 545
Address 0x71000

GetCurrencyFormatA

Ordinal 546
Address 0x3d7c0

GetCurrencyFormatEx

Ordinal 547
Address 0x859b0

GetCurrencyFormatW

Ordinal 548
Address 0x859c0

GetCurrentActCtx

Ordinal 549
Address 0x859d0

GetCurrentActCtxWorker

Ordinal 550
Address 0x18060

GetCurrentApplicationUserModelId

Ordinal 551
Address 0x135845
ForwardName kernelbase.GetCurrentApplicationUserModelId

GetCurrentConsoleFont

Ordinal 552
Address 0x71010

GetCurrentConsoleFontEx

Ordinal 553
Address 0x71020

GetCurrentDirectoryA

Ordinal 554
Address 0x859e0

GetCurrentDirectoryW

Ordinal 555
Address 0x859f0

GetCurrentPackageFamilyName

Ordinal 556
Address 0x1358e5
ForwardName kernelbase.GetCurrentPackageFamilyName

GetCurrentPackageFullName

Ordinal 557
Address 0x135926
ForwardName kernelbase.GetCurrentPackageFullName

GetCurrentPackageId

Ordinal 558
Address 0x13595f
ForwardName kernelbase.GetCurrentPackageId

GetCurrentPackageInfo

Ordinal 559
Address 0x135994
ForwardName kernelbase.GetCurrentPackageInfo

GetCurrentPackagePath

Ordinal 560
Address 0x1359cb
ForwardName kernelbase.GetCurrentPackagePath

GetCurrentPackageVirtualizationContext

Ordinal 561
Address 0x1b4a0

GetCurrentProcess

Ordinal 562
Address 0x6e910

GetCurrentProcessId

Ordinal 563
Address 0x6ebb0

GetCurrentProcessorNumber

Ordinal 564
Address 0x135a53
ForwardName NTDLL.RtlGetCurrentProcessorNumber

GetCurrentProcessorNumberEx

Ordinal 565
Address 0x135a92
ForwardName NTDLL.RtlGetCurrentProcessorNumberEx

GetCurrentThread

Ordinal 566
Address 0x7bfb0

GetCurrentThreadId

Ordinal 567
Address 0x7bfc0

GetCurrentThreadStackLimits

Ordinal 568
Address 0x135af7
ForwardName api-ms-win-core-processthreads-l1-1-0.GetCurrentThreadStackLimits

GetCurrentUmsThread

Ordinal 569
Address 0x8c680

GetDateFormatA

Ordinal 570
Address 0x85a00

GetDateFormatAWorker

Ordinal 571
Address 0x3dae0

GetDateFormatEx

Ordinal 572
Address 0x85a10

GetDateFormatW

Ordinal 573
Address 0x85a20

GetDateFormatWWorker

Ordinal 574
Address 0x13770

GetDefaultCommConfigA

Ordinal 575
Address 0x32950

GetDefaultCommConfigW

Ordinal 576
Address 0x329f0

GetDevicePowerState

Ordinal 577
Address 0xcdeb0

GetDiskFreeSpaceA

Ordinal 578
Address 0x6f570

GetDiskFreeSpaceExA

Ordinal 579
Address 0x6f580

GetDiskFreeSpaceExW

Ordinal 580
Address 0x6f590

GetDiskFreeSpaceW

Ordinal 581
Address 0x6f5a0

GetDiskSpaceInformationA

Ordinal 582
Address 0x135c4a
ForwardName api-ms-win-core-file-l1-2-3.GetDiskSpaceInformationA

GetDiskSpaceInformationW

Ordinal 583
Address 0x135c98
ForwardName api-ms-win-core-file-l1-2-3.GetDiskSpaceInformationW

GetDllDirectoryA

Ordinal 584
Address 0x30a30

GetDllDirectoryW

Ordinal 585
Address 0x1ae70

GetDriveTypeA

Ordinal 586
Address 0x6f5b0

GetDriveTypeW

Ordinal 587
Address 0x6f5c0

GetDurationFormat

Ordinal 588
Address 0x983c0

GetDurationFormatEx

Ordinal 589
Address 0x85a30

GetDynamicTimeZoneInformation

Ordinal 590
Address 0x85a40

GetEncryptedFileVersionExt

Ordinal 591
Address 0x303e0

GetEnvironmentStrings

Ordinal 592
Address 0x85a60

GetEnvironmentStringsA

Ordinal 593
Address 0x70180

GetEnvironmentStringsW

Ordinal 594
Address 0x85a70

GetEnvironmentVariableA

Ordinal 595
Address 0x85a80

GetEnvironmentVariableW

Ordinal 596
Address 0x85a90

GetEraNameCountedString

Ordinal 597
Address 0x85aa0

GetErrorMode

Ordinal 598
Address 0x85ab0

GetExitCodeProcess

Ordinal 599
Address 0x190c0

GetExitCodeThread

Ordinal 600
Address 0x85ac0

GetExpandedNameA

Ordinal 601
Address 0x31b90

GetExpandedNameW

Ordinal 602
Address 0x31c80

GetFileAttributesA

Ordinal 603
Address 0x6f5d0

GetFileAttributesExA

Ordinal 604
Address 0x6f5e0

GetFileAttributesExW

Ordinal 605
Address 0x6f5f0

GetFileAttributesTransactedA

Ordinal 606
Address 0x571f0

GetFileAttributesTransactedW

Ordinal 607
Address 0xcb060

GetFileAttributesW

Ordinal 608
Address 0x6f3b0

GetFileBandwidthReservation

Ordinal 609
Address 0x2fd70

GetFileInformationByHandle

Ordinal 610
Address 0x6f600

GetFileInformationByHandleEx

Ordinal 611
Address 0x85ad0

GetFileMUIInfo

Ordinal 612
Address 0x85ae0

GetFileMUIPath

Ordinal 613
Address 0x85af0

GetFileSize

Ordinal 614
Address 0x6f610

GetFileSizeEx

Ordinal 615
Address 0x6f340

GetFileTime

Ordinal 616
Address 0x6f620

GetFileType

Ordinal 617
Address 0x6f630

GetFinalPathNameByHandleA

Ordinal 618
Address 0x6f640

GetFinalPathNameByHandleW

Ordinal 619
Address 0x6f650

GetFirmwareEnvironmentVariableA

Ordinal 620
Address 0x58470

GetFirmwareEnvironmentVariableExA

Ordinal 621
Address 0x58480

GetFirmwareEnvironmentVariableExW

Ordinal 622
Address 0x12160

GetFirmwareEnvironmentVariableW

Ordinal 623
Address 0x1ade0

GetFirmwareType

Ordinal 624
Address 0x58650

GetFullPathNameA

Ordinal 625
Address 0x6f2f0

GetFullPathNameTransactedA

Ordinal 626
Address 0x80570

GetFullPathNameTransactedW

Ordinal 627
Address 0xce730

GetFullPathNameW

Ordinal 628
Address 0x6f3a0

GetGeoInfoA

Ordinal 629
Address 0x3dcd0

GetGeoInfoEx

Ordinal 630
Address 0x45110

GetGeoInfoW

Ordinal 631
Address 0x45180

GetHandleInformation

Ordinal 632
Address 0x6f090

GetIoRingInfo

Ordinal 633
Address 0x1360e0
ForwardName api-ms-win-core-ioring-l1-1-0.GetIoRingInfo

GetLargePageMinimum

Ordinal 634
Address 0x85b00

GetLargestConsoleWindowSize

Ordinal 635
Address 0x70cf0

GetLastError

Ordinal 636
Address 0x85b10

GetLocalTime

Ordinal 637
Address 0x85b20

GetLocaleInfoA

Ordinal 638
Address 0x85b30

GetLocaleInfoEx

Ordinal 639
Address 0x85b40

GetLocaleInfoW

Ordinal 640
Address 0x85b50

GetLogicalDriveStringsA

Ordinal 641
Address 0x586d0

GetLogicalDriveStringsW

Ordinal 642
Address 0x6f660

GetLogicalDrives

Ordinal 643
Address 0x176c0

GetLogicalProcessorInformation

Ordinal 644
Address 0x85b60

GetLogicalProcessorInformationEx

Ordinal 645
Address 0x136205
ForwardName api-ms-win-core-sysinfo-l1-1-0.GetLogicalProcessorInformationEx

GetLongPathNameA

Ordinal 646
Address 0x4a910

GetLongPathNameTransactedA

Ordinal 647
Address 0x35000

GetLongPathNameTransactedW

Ordinal 648
Address 0x4d040

GetLongPathNameW

Ordinal 649
Address 0x19ff0

GetMachineTypeAttributes

Ordinal 650
Address 0x1362b6
ForwardName api-ms-win-core-processthreads-l1-1-7.GetMachineTypeAttributes

GetMailslotInfo

Ordinal 651
Address 0x20980

GetMaximumProcessorCount

Ordinal 652
Address 0x4c370

GetMaximumProcessorGroupCount

Ordinal 653
Address 0x1adf0

GetMemoryErrorHandlingCapabilities

Ordinal 654
Address 0x85b70

GetModuleFileNameA

Ordinal 655
Address 0x85b80

GetModuleFileNameW

Ordinal 656
Address 0x85b90

GetModuleHandleA

Ordinal 657
Address 0x85ba0

GetModuleHandleExA

Ordinal 658
Address 0x85bb0

GetModuleHandleExW

Ordinal 659
Address 0x85bc0

GetModuleHandleW

Ordinal 660
Address 0x85bd0

GetNLSVersion

Ordinal 661
Address 0x85bf0

GetNLSVersionEx

Ordinal 662
Address 0x85be0

GetNamedPipeAttribute

Ordinal 663
Address 0x85c00

GetNamedPipeClientComputerNameA

Ordinal 664
Address 0x56a70

GetNamedPipeClientComputerNameW

Ordinal 665
Address 0x85c10

GetNamedPipeClientProcessId

Ordinal 666
Address 0x63c0

GetNamedPipeClientSessionId

Ordinal 667
Address 0x82d00

GetNamedPipeHandleStateA

Ordinal 668
Address 0xc9f70

GetNamedPipeHandleStateW

Ordinal 669
Address 0x85c20

GetNamedPipeInfo

Ordinal 670
Address 0x1364bc
ForwardName api-ms-win-core-namedpipe-l1-2-1.GetNamedPipeInfo

GetNamedPipeServerProcessId

Ordinal 671
Address 0x7160

GetNamedPipeServerSessionId

Ordinal 672
Address 0x82d60

GetNativeSystemInfo

Ordinal 673
Address 0x85c30

GetNextUmsListItem

Ordinal 674
Address 0x8c680

GetNextVDMCommand

Ordinal 675
Address 0x350c0

GetNumaAvailableMemoryNode

Ordinal 676
Address 0x82f90

GetNumaAvailableMemoryNodeEx

Ordinal 677
Address 0xb6e00

GetNumaHighestNodeNumber

Ordinal 678
Address 0x85c40

GetNumaNodeNumberFromHandle

Ordinal 679
Address 0x82fa0

GetNumaNodeProcessorMask

Ordinal 680
Address 0x4c2a0

GetNumaNodeProcessorMask2

Ordinal 681
Address 0x1365ff
ForwardName api-ms-win-core-systemtopology-l1-1-2.GetNumaNodeProcessorMask2

GetNumaNodeProcessorMaskEx

Ordinal 682
Address 0x85c50

GetNumaProcessorNode

Ordinal 683
Address 0x83000

GetNumaProcessorNodeEx

Ordinal 684
Address 0xb6f00

GetNumaProximityNode

Ordinal 685
Address 0x83070

GetNumaProximityNodeEx

Ordinal 686
Address 0x85c60

GetNumberFormatA

Ordinal 687
Address 0x3dd80

GetNumberFormatEx

Ordinal 688
Address 0x85c70

GetNumberFormatW

Ordinal 689
Address 0x85c80

GetNumberOfConsoleFonts

Ordinal 690
Address 0x594c0

GetNumberOfConsoleInputEvents

Ordinal 691
Address 0x70b60

GetNumberOfConsoleMouseButtons

Ordinal 692
Address 0x71030

GetOEMCP

Ordinal 693
Address 0x85c90

GetOverlappedResult

Ordinal 694
Address 0x85ca0

GetOverlappedResultEx

Ordinal 695
Address 0x13676e
ForwardName api-ms-win-core-io-l1-1-1.GetOverlappedResultEx

GetPackageApplicationIds

Ordinal 696
Address 0x1367b7
ForwardName kernelbase.GetPackageApplicationIds

GetPackageFamilyName

Ordinal 697
Address 0x1367f0
ForwardName kernelbase.GetPackageFamilyName

GetPackageFullName

Ordinal 698
Address 0x136823
ForwardName kernelbase.GetPackageFullName

GetPackageId

Ordinal 699
Address 0x13684e
ForwardName kernelbase.GetPackageId

GetPackageInfo

Ordinal 700
Address 0x136875
ForwardName kernelbase.GetPackageInfo

GetPackagePath

Ordinal 701
Address 0x13689e
ForwardName kernelbase.GetPackagePath

GetPackagePathByFullName

Ordinal 702
Address 0x1368d1
ForwardName kernelbase.GetPackagePathByFullName

GetPackagesByPackageFamily

Ordinal 703
Address 0x136910
ForwardName kernelbase.GetPackagesByPackageFamily

GetPhysicallyInstalledSystemMemory

Ordinal 704
Address 0x85cb0

GetPriorityClass

Ordinal 705
Address 0x85cc0

GetPrivateProfileIntA

Ordinal 706
Address 0x207a0

GetPrivateProfileIntW

Ordinal 707
Address 0xd0e0

GetPrivateProfileSectionA

Ordinal 708
Address 0x55e30

GetPrivateProfileSectionNamesA

Ordinal 709
Address 0x55f00

GetPrivateProfileSectionNamesW

Ordinal 710
Address 0x55f20

GetPrivateProfileSectionW

Ordinal 711
Address 0x20820

GetPrivateProfileStringA

Ordinal 712
Address 0x55f40

GetPrivateProfileStringW

Ordinal 713
Address 0xd910

GetPrivateProfileStructA

Ordinal 714
Address 0x56140

GetPrivateProfileStructW

Ordinal 715
Address 0x562f0

GetProcAddress

Ordinal 716
Address 0x17e00

GetProcessAffinityMask

Ordinal 717
Address 0x199b0

GetProcessDEPPolicy

Ordinal 718
Address 0x84640

GetProcessDefaultCpuSetMasks

Ordinal 719
Address 0x136ac3
ForwardName api-ms-win-core-processthreads-l1-1-6.GetProcessDefaultCpuSetMasks

GetProcessDefaultCpuSets

Ordinal 720
Address 0x136b1f
ForwardName api-ms-win-core-processthreads-l1-1-3.GetProcessDefaultCpuSets

GetProcessGroupAffinity

Ordinal 721
Address 0x85d50

GetProcessHandleCount

Ordinal 722
Address 0x85d60

GetProcessHeap

Ordinal 723
Address 0x85d70

GetProcessHeaps

Ordinal 724
Address 0x85d80

GetProcessId

Ordinal 725
Address 0x85da0

GetProcessIdOfThread

Ordinal 726
Address 0x85d90

GetProcessInformation

Ordinal 727
Address 0x6ebc0

GetProcessIoCounters

Ordinal 728
Address 0x19410

GetProcessMitigationPolicy

Ordinal 729
Address 0x136c13
ForwardName api-ms-win-core-processthreads-l1-1-1.GetProcessMitigationPolicy

GetProcessPreferredUILanguages

Ordinal 730
Address 0x85db0

GetProcessPriorityBoost

Ordinal 731
Address 0x85dc0

GetProcessShutdownParameters

Ordinal 732
Address 0x85dd0

GetProcessTimes

Ordinal 733
Address 0x85de0

GetProcessVersion

Ordinal 734
Address 0x85df0

GetProcessWorkingSetSize

Ordinal 735
Address 0x6f060

GetProcessWorkingSetSizeEx

Ordinal 736
Address 0x85e00

GetProcessesInVirtualizationContext

Ordinal 737
Address 0x1b4c0

GetProcessorSystemCycleTime

Ordinal 738
Address 0x136d3e
ForwardName api-ms-win-core-sysinfo-l1-2-2.GetProcessorSystemCycleTime

GetProductInfo

Ordinal 739
Address 0x85e10

GetProfileIntA

Ordinal 740
Address 0x564b0

GetProfileIntW

Ordinal 741
Address 0xb330

GetProfileSectionA

Ordinal 742
Address 0x564c0

GetProfileSectionW

Ordinal 743
Address 0x208f0

GetProfileStringA

Ordinal 744
Address 0x564d0

GetProfileStringW

Ordinal 745
Address 0x564e0

GetQueuedCompletionStatus

Ordinal 746
Address 0x85e30

GetQueuedCompletionStatusEx

Ordinal 747
Address 0x85e20

GetShortPathNameA

Ordinal 748
Address 0x4d100

GetShortPathNameW

Ordinal 749
Address 0x4ab50

GetStagedPackagePathByFullName

Ordinal 750
Address 0x136e69
ForwardName kernelbase.GetStagedPackagePathByFullName

GetStartupInfoA

Ordinal 751
Address 0x4c430

GetStartupInfoW

Ordinal 752
Address 0x85e40

GetStateFolder

Ordinal 753
Address 0x136ec2
ForwardName kernelbase.GetStateFolder

GetStdHandle

Ordinal 754
Address 0x85e50

GetStringScripts

Ordinal 755
Address 0x85e60

GetStringTypeA

Ordinal 756
Address 0x85e70

GetStringTypeExA

Ordinal 757
Address 0x85e70

GetStringTypeExW

Ordinal 758
Address 0x85e80

GetStringTypeW

Ordinal 759
Address 0x85e90

GetSystemAppDataKey

Ordinal 760
Address 0x136f4e
ForwardName kernelbase.GetSystemAppDataKey

GetSystemCpuSetInformation

Ordinal 761
Address 0x136f88
ForwardName api-ms-win-core-processthreads-l1-1-3.GetSystemCpuSetInformation

GetSystemDEPPolicy

Ordinal 762
Address 0x84690

GetSystemDefaultLCID

Ordinal 763
Address 0x85ea0

GetSystemDefaultLangID

Ordinal 764
Address 0x85eb0

GetSystemDefaultLocaleName

Ordinal 765
Address 0x85ee0

GetSystemDefaultUILanguage

Ordinal 766
Address 0x85ef0

GetSystemDirectoryA

Ordinal 767
Address 0x31a40

GetSystemDirectoryW

Ordinal 768
Address 0x17d70

GetSystemFileCacheSize

Ordinal 769
Address 0x85fe0

GetSystemFirmwareTable

Ordinal 770
Address 0x81bf0

GetSystemInfo

Ordinal 771
Address 0x85ff0

GetSystemPowerStatus

Ordinal 772
Address 0x17ac0

GetSystemPreferredUILanguages

Ordinal 773
Address 0x86000

GetSystemRegistryQuota

Ordinal 774
Address 0x31670

GetSystemTime

Ordinal 775
Address 0x86030

GetSystemTimeAdjustment

Ordinal 776
Address 0x86010

GetSystemTimeAsFileTime

Ordinal 777
Address 0x86020

GetSystemTimePreciseAsFileTime

Ordinal 778
Address 0x6fce0

GetSystemTimes

Ordinal 779
Address 0x86040

GetSystemWindowsDirectoryA

Ordinal 780
Address 0x31ae0

GetSystemWindowsDirectoryW

Ordinal 781
Address 0x1af80

GetSystemWow64DirectoryA

Ordinal 782
Address 0x705b0

GetSystemWow64DirectoryW

Ordinal 783
Address 0x705c0

GetTapeParameters

Ordinal 784
Address 0xbd110

GetTapePosition

Ordinal 785
Address 0x36ad0

GetTapeStatus

Ordinal 786
Address 0x8d730

GetTempFileNameA

Ordinal 787
Address 0x6f670

GetTempFileNameW

Ordinal 788
Address 0x6f3e0

GetTempPath2A

Ordinal 789
Address 0x6f680

GetTempPath2W

Ordinal 790
Address 0x6f690

GetTempPathA

Ordinal 791
Address 0x6f6a0

GetTempPathW

Ordinal 792
Address 0x6f3c0

GetThreadContext

Ordinal 793
Address 0x86070

GetThreadDescription

Ordinal 794
Address 0x13726e
ForwardName api-ms-win-core-processthreads-l1-1-3.GetThreadDescription

GetThreadErrorMode

Ordinal 795
Address 0x86090

GetThreadGroupAffinity

Ordinal 796
Address 0x860a0

GetThreadIOPendingFlag

Ordinal 797
Address 0x860b0

GetThreadId

Ordinal 798
Address 0x860c0

GetThreadIdealProcessorEx

Ordinal 799
Address 0x860d0

GetThreadInformation

Ordinal 800
Address 0x6eb80

GetThreadLocale

Ordinal 801
Address 0x860e0

GetThreadPreferredUILanguages

Ordinal 802
Address 0x860f0

GetThreadPriority

Ordinal 803
Address 0x86110

GetThreadPriorityBoost

Ordinal 804
Address 0x86100

GetThreadSelectedCpuSetMasks

Ordinal 805
Address 0x137399
ForwardName api-ms-win-core-processthreads-l1-1-6.GetThreadSelectedCpuSetMasks

GetThreadSelectedCpuSets

Ordinal 806
Address 0x1373f5
ForwardName api-ms-win-core-processthreads-l1-1-3.GetThreadSelectedCpuSets

GetThreadSelectorEntry

Ordinal 807
Address 0xcec90

GetThreadTimes

Ordinal 808
Address 0x86120

GetThreadUILanguage

Ordinal 809
Address 0x86130

GetTickCount

Ordinal 810
Address 0x806e0

GetTickCount64

Ordinal 811
Address 0x13110

GetTimeFormatA

Ordinal 812
Address 0x86160

GetTimeFormatAWorker

Ordinal 813
Address 0x3e040

GetTimeFormatEx

Ordinal 814
Address 0x86170

GetTimeFormatW

Ordinal 815
Address 0x86180

GetTimeFormatWWorker

Ordinal 816
Address 0x13ae0

GetTimeZoneInformation

Ordinal 817
Address 0x861a0

GetTimeZoneInformationForYear

Ordinal 818
Address 0x86190

GetUILanguageInfo

Ordinal 819
Address 0x861b0

GetUmsCompletionListEvent

Ordinal 820
Address 0x8c620

GetUmsSystemThreadInformation

Ordinal 821
Address 0x8c620

GetUserDefaultGeoName

Ordinal 822
Address 0x45730

GetUserDefaultLCID

Ordinal 823
Address 0x861c0

GetUserDefaultLangID

Ordinal 824
Address 0x861d0

GetUserDefaultLocaleName

Ordinal 825
Address 0x86200

GetUserDefaultUILanguage

Ordinal 826
Address 0x86210

GetUserGeoID

Ordinal 827
Address 0x45820

GetUserPreferredUILanguages

Ordinal 828
Address 0x86240

GetVDMCurrentDirectories

Ordinal 829
Address 0x35860

GetVersion

Ordinal 830
Address 0x86270

GetVersionExA

Ordinal 831
Address 0x86250

GetVersionExW

Ordinal 832
Address 0x86260

GetVolumeInformationA

Ordinal 833
Address 0x6f6b0

GetVolumeInformationByHandleW

Ordinal 834
Address 0x6f6c0

GetVolumeInformationW

Ordinal 835
Address 0x6f6d0

GetVolumeNameForVolumeMountPointA

Ordinal 836
Address 0x4e510

GetVolumeNameForVolumeMountPointW

Ordinal 837
Address 0x6e7c0

GetVolumePathNameA

Ordinal 838
Address 0x6530

GetVolumePathNameW

Ordinal 839
Address 0x6f6e0

GetVolumePathNamesForVolumeNameA

Ordinal 840
Address 0x4e6a0

GetVolumePathNamesForVolumeNameW

Ordinal 841
Address 0x6f6f0

GetWindowsDirectoryA

Ordinal 842
Address 0x86280

GetWindowsDirectoryW

Ordinal 843
Address 0x86290

GetWriteWatch

Ordinal 844
Address 0x862a0

GlobalAddAtomA

Ordinal 845
Address 0x11c40

GlobalAddAtomExA

Ordinal 846
Address 0x4fdb0

GlobalAddAtomExW

Ordinal 847
Address 0x11c10

GlobalAddAtomW

Ordinal 848
Address 0x10600

GlobalAlloc

Ordinal 849
Address 0x862c0

GlobalCompact

Ordinal 850
Address 0x304e0

GlobalDeleteAtom

Ordinal 851
Address 0x18cc0

GlobalFindAtomA

Ordinal 852
Address 0x20190

GlobalFindAtomW

Ordinal 853
Address 0x10920

GlobalFix

Ordinal 854
Address 0x81c20

GlobalFlags

Ordinal 855
Address 0x862d0

GlobalFree

Ordinal 856
Address 0x13140

GlobalGetAtomNameA

Ordinal 857
Address 0x4fde0

GlobalGetAtomNameW

Ordinal 858
Address 0x11b20

GlobalHandle

Ordinal 859
Address 0x862e0

GlobalLock

Ordinal 860
Address 0x81ce0

GlobalMemoryStatus

Ordinal 861
Address 0x19450

GlobalMemoryStatusEx

Ordinal 862
Address 0x862f0

GlobalReAlloc

Ordinal 863
Address 0x86300

GlobalSize

Ordinal 864
Address 0x86310

GlobalUnWire

Ordinal 865
Address 0x81cb0

GlobalUnfix

Ordinal 866
Address 0x81cc0

GlobalUnlock

Ordinal 867
Address 0x81cb0

GlobalWire

Ordinal 868
Address 0x81ce0

Heap32First

Ordinal 869
Address 0x57910

Heap32ListFirst

Ordinal 870
Address 0xcbb90

Heap32ListNext

Ordinal 871
Address 0xcbc80

Heap32Next

Ordinal 872
Address 0xcbd60

HeapAlloc

Ordinal 873
Address 0x137904
ForwardName NTDLL.RtlAllocateHeap

HeapCompact

Ordinal 874
Address 0x86320

HeapCreate

Ordinal 875
Address 0x86330

HeapDestroy

Ordinal 876
Address 0x86340

HeapFree

Ordinal 877
Address 0x86350

HeapLock

Ordinal 878
Address 0x86360

HeapQueryInformation

Ordinal 879
Address 0x86370

HeapReAlloc

Ordinal 880
Address 0x137970
ForwardName NTDLL.RtlReAllocateHeap

HeapSetInformation

Ordinal 881
Address 0x86380

HeapSize

Ordinal 882
Address 0x1379a4
ForwardName NTDLL.RtlSizeHeap

HeapSummary

Ordinal 883
Address 0x86390

HeapUnlock

Ordinal 884
Address 0x863a0

HeapValidate

Ordinal 885
Address 0x863b0

HeapWalk

Ordinal 886
Address 0x863c0

IdnToAscii

Ordinal 887
Address 0x863d0

IdnToNameprepUnicode

Ordinal 888
Address 0x863e0

IdnToUnicode

Ordinal 889
Address 0x863f0

InitAtomTable

Ordinal 890
Address 0x4fe00

InitOnceBeginInitialize

Ordinal 891
Address 0x137a36
ForwardName api-ms-win-core-synch-l1-2-0.InitOnceBeginInitialize

InitOnceComplete

Ordinal 892
Address 0x137a7c
ForwardName api-ms-win-core-synch-l1-2-0.InitOnceComplete

InitOnceExecuteOnce

Ordinal 893
Address 0x137abe
ForwardName api-ms-win-core-synch-l1-2-0.InitOnceExecuteOnce

InitOnceInitialize

Ordinal 894
Address 0x137b02
ForwardName NTDLL.RtlRunOnceInitialize

InitializeConditionVariable

Ordinal 895
Address 0x137b39
ForwardName NTDLL.RtlInitializeConditionVariable

InitializeContext

Ordinal 896
Address 0x86410

InitializeContext2

Ordinal 897
Address 0x86400

InitializeCriticalSection

Ordinal 898
Address 0x137b9d
ForwardName NTDLL.RtlInitializeCriticalSection

InitializeCriticalSectionAndSpinCount

Ordinal 899
Address 0x6f1c0

InitializeCriticalSectionEx

Ordinal 900
Address 0x6f1d0

InitializeEnclave

Ordinal 901
Address 0x137c14
ForwardName api-ms-win-core-enclave-l1-1-0.InitializeEnclave

InitializeProcThreadAttributeList

Ordinal 902
Address 0x137c67
ForwardName api-ms-win-core-processthreads-l1-1-0.InitializeProcThreadAttributeList

InitializeSListHead

Ordinal 903
Address 0x137cc3
ForwardName NTDLL.RtlInitializeSListHead

InitializeSRWLock

Ordinal 904
Address 0x137cf2
ForwardName NTDLL.RtlInitializeSRWLock

InitializeSynchronizationBarrier

Ordinal 905
Address 0x86420

InstallELAMCertificateInfo

Ordinal 906
Address 0x137d49
ForwardName api-ms-win-core-sysinfo-l1-2-1.InstallELAMCertificateInfo

InterlockedFlushSList

Ordinal 907
Address 0x137d99
ForwardName NTDLL.RtlInterlockedFlushSList

InterlockedPopEntrySList

Ordinal 908
Address 0x137dd1
ForwardName NTDLL.RtlInterlockedPopEntrySList

InterlockedPushEntrySList

Ordinal 909
Address 0x137e0d
ForwardName NTDLL.RtlInterlockedPushEntrySList

InterlockedPushListSList

Ordinal 910
Address 0x137e49
ForwardName NTDLL.RtlInterlockedPushListSList

InterlockedPushListSListEx

Ordinal 911
Address 0x137e86
ForwardName NTDLL.RtlInterlockedPushListSListEx

InvalidateConsoleDIBits

Ordinal 912
Address 0x595b0

IsBadCodePtr

Ordinal 913
Address 0x1f550

IsBadHugeReadPtr

Ordinal 914
Address 0x316f0

IsBadHugeWritePtr

Ordinal 915
Address 0x31700

IsBadReadPtr

Ordinal 916
Address 0x20050

IsBadStringPtrA

Ordinal 917
Address 0x847a0

IsBadStringPtrW

Ordinal 918
Address 0x84820

IsBadWritePtr

Ordinal 919
Address 0x200f0

IsCalendarLeapDay

Ordinal 920
Address 0x3f030

IsCalendarLeapMonth

Ordinal 921
Address 0x3f170

IsCalendarLeapYear

Ordinal 922
Address 0x3f270

IsDBCSLeadByte

Ordinal 923
Address 0x86440

IsDBCSLeadByteEx

Ordinal 924
Address 0x86430

IsDebuggerPresent

Ordinal 925
Address 0x86450

IsEnclaveTypeSupported

Ordinal 926
Address 0x137faf
ForwardName api-ms-win-core-enclave-l1-1-0.IsEnclaveTypeSupported

IsIoRingOpSupported

Ordinal 927
Address 0x137ff9
ForwardName api-ms-win-core-ioring-l1-1-0.IsIoRingOpSupported

IsNLSDefinedString

Ordinal 928
Address 0x86460

IsNativeVhdBoot

Ordinal 929
Address 0x80320

IsNormalizedString

Ordinal 930
Address 0x86470

IsProcessCritical

Ordinal 931
Address 0x138073
ForwardName api-ms-win-core-processthreads-l1-1-2.IsProcessCritical

IsProcessInJob

Ordinal 932
Address 0x86480

IsProcessorFeaturePresent

Ordinal 933
Address 0x86490

IsSystemResumeAutomatic

Ordinal 934
Address 0xce0a0

IsThreadAFiber

Ordinal 935
Address 0x864a0

IsThreadpoolTimerSet

Ordinal 936
Address 0x138110
ForwardName NTDLL.TpIsTimerSet

IsUserCetAvailableInEnvironment

Ordinal 937
Address 0x138143
ForwardName api-ms-win-core-sysinfo-l1-2-6.IsUserCetAvailableInEnvironment

IsValidCalDateTime

Ordinal 938
Address 0x14120

IsValidCodePage

Ordinal 939
Address 0x864c0

IsValidLanguageGroup

Ordinal 940
Address 0x864d0

IsValidLocale

Ordinal 941
Address 0x864f0

IsValidLocaleName

Ordinal 942
Address 0x864e0

IsValidNLSVersion

Ordinal 943
Address 0x86500

IsWow64GuestMachineSupported

Ordinal 944
Address 0x138209
ForwardName api-ms-win-core-wow64-l1-1-2.IsWow64GuestMachineSupported

IsWow64Process

Ordinal 945
Address 0x86510

IsWow64Process2

Ordinal 946
Address 0x138262
ForwardName api-ms-win-core-wow64-l1-1-1.IsWow64Process2

K32EmptyWorkingSet

Ordinal 947
Address 0x86520

K32EnumDeviceDrivers

Ordinal 948
Address 0x86530

K32EnumPageFilesA

Ordinal 949
Address 0x86540

K32EnumPageFilesW

Ordinal 950
Address 0x86550

K32EnumProcessModules

Ordinal 951
Address 0x86570

K32EnumProcessModulesEx

Ordinal 952
Address 0x86560

K32EnumProcesses

Ordinal 953
Address 0x86580

K32GetDeviceDriverBaseNameA

Ordinal 954
Address 0x86590

K32GetDeviceDriverBaseNameW

Ordinal 955
Address 0x865a0

K32GetDeviceDriverFileNameA

Ordinal 956
Address 0x865b0

K32GetDeviceDriverFileNameW

Ordinal 957
Address 0x865c0

K32GetMappedFileNameA

Ordinal 958
Address 0x865d0

K32GetMappedFileNameW

Ordinal 959
Address 0x865e0

K32GetModuleBaseNameA

Ordinal 960
Address 0x865f0

K32GetModuleBaseNameW

Ordinal 961
Address 0x86600

K32GetModuleFileNameExA

Ordinal 962
Address 0x86610

K32GetModuleFileNameExW

Ordinal 963
Address 0x86620

K32GetModuleInformation

Ordinal 964
Address 0x86630

K32GetPerformanceInfo

Ordinal 965
Address 0x86640

K32GetProcessImageFileNameA

Ordinal 966
Address 0x86650

K32GetProcessImageFileNameW

Ordinal 967
Address 0x86660

K32GetProcessMemoryInfo

Ordinal 968
Address 0x86670

K32GetWsChanges

Ordinal 969
Address 0x86690

K32GetWsChangesEx

Ordinal 970
Address 0x86680

K32InitializeProcessForWsWatch

Ordinal 971
Address 0x866a0

K32QueryWorkingSet

Ordinal 972
Address 0x866c0

K32QueryWorkingSetEx

Ordinal 973
Address 0x866b0

LCIDToLocaleName

Ordinal 974
Address 0x866d0

LCMapStringA

Ordinal 975
Address 0x866e0

LCMapStringEx

Ordinal 976
Address 0x866f0

LCMapStringW

Ordinal 977
Address 0x86720

LZClose

Ordinal 978
Address 0x31d80

LZCloseFile

Ordinal 979
Address 0x31d80

LZCopy

Ordinal 980
Address 0x2f9e0

LZCreateFileW

Ordinal 981
Address 0x31e30

LZDone

Ordinal 982
Address 0x80560

LZInit

Ordinal 983
Address 0x31f60

LZOpenFileA

Ordinal 984
Address 0x32100

LZOpenFileW

Ordinal 985
Address 0x321f0

LZRead

Ordinal 986
Address 0x32280

LZSeek

Ordinal 987
Address 0x32560

LZStart

Ordinal 988
Address 0x71ba0

LeaveCriticalSection

Ordinal 989
Address 0x1385ac
ForwardName NTDLL.RtlLeaveCriticalSection

LeaveCriticalSectionWhenCallbackReturns

Ordinal 990
Address 0x1385f2
ForwardName NTDLL.TpCallbackLeaveCriticalSectionOnCompletion

LoadAppInitDlls

Ordinal 991
Address 0x16840

LoadEnclaveData

Ordinal 992
Address 0x138643
ForwardName api-ms-win-core-enclave-l1-1-0.LoadEnclaveData

LoadLibraryA

Ordinal 993
Address 0x86730

LoadLibraryExA

Ordinal 994
Address 0x86740

LoadLibraryExW

Ordinal 995
Address 0x86750

LoadLibraryW

Ordinal 996
Address 0x86760

LoadModule

Ordinal 997
Address 0x4c6b0

LoadPackagedLibrary

Ordinal 998
Address 0x6faa0

LoadResource

Ordinal 999
Address 0x86770

LoadStringBaseExW

Ordinal 1000
Address 0x86780

LoadStringBaseW

Ordinal 1001
Address 0x82a40

LocalAlloc

Ordinal 1002
Address 0x86790

LocalCompact

Ordinal 1003
Address 0x304e0

LocalFileTimeToFileTime

Ordinal 1004
Address 0x6f700

LocalFileTimeToLocalSystemTime

Ordinal 1005
Address 0x138747
ForwardName api-ms-win-core-timezone-l1-1-1.LocalFileTimeToLocalSystemTime

LocalFlags

Ordinal 1006
Address 0x867a0

LocalFree

Ordinal 1007
Address 0x867b0

LocalHandle

Ordinal 1008
Address 0x30930

LocalLock

Ordinal 1009
Address 0x867c0

LocalReAlloc

Ordinal 1010
Address 0x867d0

LocalShrink

Ordinal 1011
Address 0x304e0

LocalSize

Ordinal 1012
Address 0x867e0

LocalSystemTimeToLocalFileTime

Ordinal 1013
Address 0x1387f3
ForwardName api-ms-win-core-timezone-l1-1-1.LocalSystemTimeToLocalFileTime

LocalUnlock

Ordinal 1014
Address 0x867f0

LocaleNameToLCID

Ordinal 1015
Address 0x86800

LockFile

Ordinal 1016
Address 0x6f710

LockFileEx

Ordinal 1017
Address 0x6f720

LockResource

Ordinal 1018
Address 0x86820

MapUserPhysicalPages

Ordinal 1019
Address 0x86830

MapUserPhysicalPagesScatter

Ordinal 1020
Address 0x91570

MapViewOfFile

Ordinal 1021
Address 0x86860

MapViewOfFileEx

Ordinal 1022
Address 0x86850

MapViewOfFileExNuma

Ordinal 1023
Address 0x86840

MapViewOfFileFromApp

Ordinal 1024
Address 0x1388e8
ForwardName api-ms-win-core-memory-l1-1-1.MapViewOfFileFromApp

Module32First

Ordinal 1025
Address 0x57bc0

Module32FirstW

Ordinal 1026
Address 0xcc110

Module32Next

Ordinal 1027
Address 0x20b30

Module32NextW

Ordinal 1028
Address 0xcc300

MoveFileA

Ordinal 1029
Address 0x57260

MoveFileExA

Ordinal 1030
Address 0x20b10

MoveFileExW

Ordinal 1031
Address 0x86870

MoveFileTransactedA

Ordinal 1032
Address 0x57280

MoveFileTransactedW

Ordinal 1033
Address 0x57360

MoveFileW

Ordinal 1034
Address 0xcb320

MoveFileWithProgressA

Ordinal 1035
Address 0x57440

MoveFileWithProgressW

Ordinal 1036
Address 0x86880

MulDiv

Ordinal 1037
Address 0x6f930

MultiByteToWideChar

Ordinal 1038
Address 0x86890

NeedCurrentDirectoryForExePathA

Ordinal 1039
Address 0x868a0

NeedCurrentDirectoryForExePathW

Ordinal 1040
Address 0x868b0

NlsCheckPolicy

Ordinal 1041
Address 0x708f0

NlsGetCacheUpdateCount

Ordinal 1042
Address 0x70900

NlsUpdateLocale

Ordinal 1043
Address 0x70910

NlsUpdateSystemLocale

Ordinal 1044
Address 0x70920

NormalizeString

Ordinal 1045
Address 0x868c0

NotifyMountMgr

Ordinal 1046
Address 0x868d0

NotifyUILanguageChange

Ordinal 1047
Address 0x40770

NtVdm64CreateProcessInternalW

Ordinal 1048
Address 0x31710

OOBEComplete

Ordinal 1049
Address 0x18890

OfferVirtualMemory

Ordinal 1050
Address 0x138aee
ForwardName api-ms-win-core-memory-l1-1-2.OfferVirtualMemory

OpenConsoleW

Ordinal 1051
Address 0xcfbd0

OpenConsoleWStub

Ordinal 1052
Address 0x868e0

OpenEventA

Ordinal 1053
Address 0x6f1e0

OpenEventW

Ordinal 1054
Address 0x6f1f0

OpenFile

Ordinal 1055
Address 0x4f4c0

OpenFileById

Ordinal 1056
Address 0x868f0

OpenFileMappingA

Ordinal 1057
Address 0x20900

OpenFileMappingW

Ordinal 1058
Address 0x86900

OpenJobObjectA

Ordinal 1059
Address 0x51fb0

OpenJobObjectW

Ordinal 1060
Address 0xc1230

OpenMutexA

Ordinal 1061
Address 0x56e60

OpenMutexW

Ordinal 1062
Address 0x6f200

OpenPackageInfoByFullName

Ordinal 1063
Address 0x138bd9
ForwardName kernelbase.OpenPackageInfoByFullName

OpenPrivateNamespaceA

Ordinal 1064
Address 0x56cd0

OpenPrivateNamespaceW

Ordinal 1065
Address 0x86910

OpenProcess

Ordinal 1066
Address 0x86920

OpenProcessToken

Ordinal 1067
Address 0x138c47
ForwardName api-ms-win-core-processthreads-l1-1-0.OpenProcessToken

OpenProfileUserMapping

Ordinal 1068
Address 0x71ba0

OpenSemaphoreA

Ordinal 1069
Address 0x56ee0

OpenSemaphoreW

Ordinal 1070
Address 0x6f210

OpenState

Ordinal 1071
Address 0x138cbd
ForwardName kernelbase.OpenState

OpenStateExplicit

Ordinal 1072
Address 0x138ce4
ForwardName kernelbase.OpenStateExplicit

OpenThread

Ordinal 1073
Address 0x86930

OpenThreadToken

Ordinal 1074
Address 0x138d1c
ForwardName api-ms-win-core-processthreads-l1-1-0.OpenThreadToken

OpenWaitableTimerA

Ordinal 1075
Address 0x56f60

OpenWaitableTimerW

Ordinal 1076
Address 0x6f220

OutputDebugStringA

Ordinal 1077
Address 0x86940

OutputDebugStringW

Ordinal 1078
Address 0x86950

PackageFamilyNameFromFullName

Ordinal 1079
Address 0x138dbc
ForwardName kernelbase.PackageFamilyNameFromFullName

PackageFamilyNameFromId

Ordinal 1080
Address 0x138dfd
ForwardName kernelbase.PackageFamilyNameFromId

PackageFullNameFromId

Ordinal 1081
Address 0x138e36
ForwardName kernelbase.PackageFullNameFromId

PackageIdFromFullName

Ordinal 1082
Address 0x138e6d
ForwardName kernelbase.PackageIdFromFullName

PackageNameAndPublisherIdFromFamilyName

Ordinal 1083
Address 0x138eb6
ForwardName kernelbase.PackageNameAndPublisherIdFromFamilyName

ParseApplicationUserModelId

Ordinal 1084
Address 0x138f05
ForwardName kernelbase.ParseApplicationUserModelId

PeekConsoleInputA

Ordinal 1085
Address 0x70b70

PeekConsoleInputW

Ordinal 1086
Address 0x70b80

PeekNamedPipe

Ordinal 1087
Address 0x86960

PopIoRingCompletion

Ordinal 1088
Address 0x138f72
ForwardName api-ms-win-core-ioring-l1-1-0.PopIoRingCompletion

PostQueuedCompletionStatus

Ordinal 1089
Address 0x86970

PowerClearRequest

Ordinal 1090
Address 0xce0d0

PowerCreateRequest

Ordinal 1091
Address 0x19710

PowerSetRequest

Ordinal 1092
Address 0x19940

PrefetchVirtualMemory

Ordinal 1093
Address 0x13900a
ForwardName api-ms-win-core-memory-l1-1-1.PrefetchVirtualMemory

PrepareTape

Ordinal 1094
Address 0x8d750

PrivCopyFileExW

Ordinal 1095
Address 0x86980

PrivMoveFileIdentityW

Ordinal 1096
Address 0x57510

Process32First

Ordinal 1097
Address 0x20c10

Process32FirstW

Ordinal 1098
Address 0x1aa80

Process32Next

Ordinal 1099
Address 0x20ce0

Process32NextW

Ordinal 1100
Address 0x19cc0

ProcessIdToSessionId

Ordinal 1101
Address 0x86990

PssCaptureSnapshot

Ordinal 1102
Address 0x869a0

PssDuplicateSnapshot

Ordinal 1103
Address 0x869b0

PssFreeSnapshot

Ordinal 1104
Address 0x869c0

PssQuerySnapshot

Ordinal 1105
Address 0x869d0

PssWalkMarkerCreate

Ordinal 1106
Address 0x869e0

PssWalkMarkerFree

Ordinal 1107
Address 0x869f0

PssWalkMarkerGetPosition

Ordinal 1108
Address 0x86a00

PssWalkMarkerRewind

Ordinal 1109
Address 0x86a10

PssWalkMarkerSeek

Ordinal 1110
Address 0x86a20

PssWalkMarkerSeekToBeginning

Ordinal 1111
Address 0x86a10

PssWalkMarkerSetPosition

Ordinal 1112
Address 0x86a20

PssWalkMarkerTell

Ordinal 1113
Address 0x86a00

PssWalkSnapshot

Ordinal 1114
Address 0x86a30

PulseEvent

Ordinal 1115
Address 0x86a40

PurgeComm

Ordinal 1116
Address 0x704a0

QueryActCtxSettingsW

Ordinal 1117
Address 0x86a50

QueryActCtxSettingsWWorker

Ordinal 1118
Address 0x10630

QueryActCtxW

Ordinal 1119
Address 0x86a60

QueryActCtxWWorker

Ordinal 1120
Address 0x19280

QueryDepthSList

Ordinal 1121
Address 0x13923c
ForwardName NTDLL.RtlQueryDepthSList

QueryDosDeviceA

Ordinal 1122
Address 0x57d30

QueryDosDeviceW

Ordinal 1123
Address 0x6f730

QueryFullProcessImageNameA

Ordinal 1124
Address 0x86a70

QueryFullProcessImageNameW

Ordinal 1125
Address 0x86a80

QueryIdleProcessorCycleTime

Ordinal 1126
Address 0x86aa0

QueryIdleProcessorCycleTimeEx

Ordinal 1127
Address 0x86a90

QueryInformationJobObject

Ordinal 1128
Address 0x19530

QueryIoRateControlInformationJobObject

Ordinal 1129
Address 0x52030

QueryIoRingCapabilities

Ordinal 1130
Address 0x13933e
ForwardName api-ms-win-core-ioring-l1-1-0.QueryIoRingCapabilities

QueryMemoryResourceNotification

Ordinal 1131
Address 0x86ab0

QueryPerformanceCounter

Ordinal 1132
Address 0x86ac0

QueryPerformanceFrequency

Ordinal 1133
Address 0x86ad0

QueryProcessAffinityUpdateMode

Ordinal 1134
Address 0x86ae0

QueryProcessCycleTime

Ordinal 1135
Address 0x86af0

QueryProtectedPolicy

Ordinal 1136
Address 0x139410
ForwardName api-ms-win-core-processthreads-l1-1-2.QueryProtectedPolicy

QueryThreadCycleTime

Ordinal 1137
Address 0x86b00

QueryThreadProfiling

Ordinal 1138
Address 0x916e0

QueryThreadpoolStackInformation

Ordinal 1139
Address 0x86b10

QueryUmsThreadInformation

Ordinal 1140
Address 0x8c6b0

QueryUnbiasedInterruptTime

Ordinal 1141
Address 0x86b50

QueueUserAPC

Ordinal 1142
Address 0x86b60

QueueUserAPC2

Ordinal 1143
Address 0x1394e5
ForwardName api-ms-win-core-processthreads-l1-1-5.QueueUserAPC2

QueueUserWorkItem

Ordinal 1144
Address 0x86b70

QuirkGetData2Worker

Ordinal 1145
Address 0x5f5d0

QuirkGetDataWorker

Ordinal 1146
Address 0x5f690

QuirkIsEnabled2Worker

Ordinal 1147
Address 0x5f750

QuirkIsEnabled3Worker

Ordinal 1148
Address 0x20e00

QuirkIsEnabledForPackage2Worker

Ordinal 1149
Address 0x20f80

QuirkIsEnabledForPackage3Worker

Ordinal 1150
Address 0xde50

QuirkIsEnabledForPackage4Worker

Ordinal 1151
Address 0xdea0

QuirkIsEnabledForPackageWorker

Ordinal 1152
Address 0xddb0

QuirkIsEnabledForProcessWorker

Ordinal 1153
Address 0x6940

QuirkIsEnabledWorker

Ordinal 1154
Address 0xda70

RaiseException

Ordinal 1155
Address 0x86b80

RaiseFailFastException

Ordinal 1156
Address 0x139657
ForwardName kernelbase.RaiseFailFastException

RaiseInvalid16BitExeError

Ordinal 1157
Address 0x318b0

ReOpenFile

Ordinal 1158
Address 0x86b90

ReadConsoleA

Ordinal 1159
Address 0x70b90

ReadConsoleInputA

Ordinal 1160
Address 0x70ba0

ReadConsoleInputExA

Ordinal 1161
Address 0x1396d1
ForwardName kernelbase.ReadConsoleInputExA

ReadConsoleInputExW

Ordinal 1162
Address 0x139704
ForwardName kernelbase.ReadConsoleInputExW

ReadConsoleInputW

Ordinal 1163
Address 0x70bb0

ReadConsoleOutputA

Ordinal 1164
Address 0x70d00

ReadConsoleOutputAttribute

Ordinal 1165
Address 0x70d10

ReadConsoleOutputCharacterA

Ordinal 1166
Address 0x70d20

ReadConsoleOutputCharacterW

Ordinal 1167
Address 0x70d30

ReadConsoleOutputW

Ordinal 1168
Address 0x70d40

ReadConsoleW

Ordinal 1169
Address 0x70bc0

ReadDirectoryChangesExW

Ordinal 1170
Address 0x86ba0

ReadDirectoryChangesW

Ordinal 1171
Address 0x86bd0

ReadFile

Ordinal 1172
Address 0x6f330

ReadFileEx

Ordinal 1173
Address 0x6f740

ReadFileScatter

Ordinal 1174
Address 0x6f750

ReadProcessMemory

Ordinal 1175
Address 0x86be0

ReadThreadProfilingData

Ordinal 1176
Address 0x91710

ReclaimVirtualMemory

Ordinal 1177
Address 0x13984c
ForwardName api-ms-win-core-memory-l1-1-2.ReclaimVirtualMemory

RegCloseKey

Ordinal 1178
Address 0x86bf0

RegCopyTreeW

Ordinal 1179
Address 0x86c00

RegCreateKeyExA

Ordinal 1180
Address 0x86c10

RegCreateKeyExW

Ordinal 1181
Address 0x86c40

RegDeleteKeyExA

Ordinal 1182
Address 0x86c70

RegDeleteKeyExW

Ordinal 1183
Address 0x86c80

RegDeleteTreeA

Ordinal 1184
Address 0x86c90

RegDeleteTreeW

Ordinal 1185
Address 0x86ca0

RegDeleteValueA

Ordinal 1186
Address 0x86cb0

RegDeleteValueW

Ordinal 1187
Address 0x86cc0

RegDisablePredefinedCacheEx

Ordinal 1188
Address 0x86cd0

RegEnumKeyExA

Ordinal 1189
Address 0x86ce0

RegEnumKeyExW

Ordinal 1190
Address 0x86cf0

RegEnumValueA

Ordinal 1191
Address 0x86d00

RegEnumValueW

Ordinal 1192
Address 0x86d10

RegFlushKey

Ordinal 1193
Address 0x86d20

RegGetKeySecurity

Ordinal 1194
Address 0x86d30

RegGetValueA

Ordinal 1195
Address 0x86d40

RegGetValueW

Ordinal 1196
Address 0x86d50

RegLoadKeyA

Ordinal 1197
Address 0x86d60

RegLoadKeyW

Ordinal 1198
Address 0x86d70

RegLoadMUIStringA

Ordinal 1199
Address 0x86d80

RegLoadMUIStringW

Ordinal 1200
Address 0x86d90

RegNotifyChangeKeyValue

Ordinal 1201
Address 0x86da0

RegOpenCurrentUser

Ordinal 1202
Address 0x86db0

RegOpenKeyExA

Ordinal 1203
Address 0x86dc0

RegOpenKeyExW

Ordinal 1204
Address 0x86dd0

RegOpenUserClassesRoot

Ordinal 1205
Address 0x86de0

RegQueryInfoKeyA

Ordinal 1206
Address 0x86df0

RegQueryInfoKeyW

Ordinal 1207
Address 0x86e30

RegQueryValueExA

Ordinal 1208
Address 0x86e70

RegQueryValueExW

Ordinal 1209
Address 0x86e80

RegRestoreKeyA

Ordinal 1210
Address 0x86e90

RegRestoreKeyW

Ordinal 1211
Address 0x86ea0

RegSaveKeyExA

Ordinal 1212
Address 0x86eb0

RegSaveKeyExW

Ordinal 1213
Address 0x86ec0

RegSetKeySecurity

Ordinal 1214
Address 0x86ed0

RegSetValueExA

Ordinal 1215
Address 0x86ee0

RegSetValueExW

Ordinal 1216
Address 0x86ef0

RegUnLoadKeyA

Ordinal 1217
Address 0x86f00

RegUnLoadKeyW

Ordinal 1218
Address 0x86f10

RegisterApplicationRecoveryCallback

Ordinal 1219
Address 0x37060

RegisterApplicationRestart

Ordinal 1220
Address 0x86f20

RegisterBadMemoryNotification

Ordinal 1221
Address 0x86f30

RegisterConsoleIME

Ordinal 1222
Address 0xd01d0

RegisterConsoleOS2

Ordinal 1223
Address 0x59180

RegisterConsoleVDM

Ordinal 1224
Address 0x58ca0

RegisterWaitForInputIdle

Ordinal 1225
Address 0x19100

RegisterWaitForSingleObject

Ordinal 1226
Address 0x18320

RegisterWaitForSingleObjectEx

Ordinal 1227
Address 0x86f40

RegisterWaitUntilOOBECompleted

Ordinal 1228
Address 0x187e0

RegisterWowBaseHandlers

Ordinal 1229
Address 0x304f0

RegisterWowExec

Ordinal 1230
Address 0x35dd0

ReleaseActCtx

Ordinal 1231
Address 0x86f50

ReleaseActCtxWorker

Ordinal 1232
Address 0x91000

ReleaseMutex

Ordinal 1233
Address 0x6f230

ReleaseMutexWhenCallbackReturns

Ordinal 1234
Address 0x139c85
ForwardName NTDLL.TpCallbackReleaseMutexOnCompletion

ReleasePackageVirtualizationContext

Ordinal 1235
Address 0x1b4e0

ReleaseSRWLockExclusive

Ordinal 1236
Address 0x139cea
ForwardName NTDLL.RtlReleaseSRWLockExclusive

ReleaseSRWLockShared

Ordinal 1237
Address 0x139d20
ForwardName NTDLL.RtlReleaseSRWLockShared

ReleaseSemaphore

Ordinal 1238
Address 0x6f240

ReleaseSemaphoreWhenCallbackReturns

Ordinal 1239
Address 0x139d73
ForwardName NTDLL.TpCallbackReleaseSemaphoreOnCompletion

RemoveDirectoryA

Ordinal 1240
Address 0x6f760

RemoveDirectoryTransactedA

Ordinal 1241
Address 0x2fc20

RemoveDirectoryTransactedW

Ordinal 1242
Address 0xb6d60

RemoveDirectoryW

Ordinal 1243
Address 0x6f770

RemoveDllDirectory

Ordinal 1244
Address 0x139e0b
ForwardName api-ms-win-core-libraryloader-l1-1-0.RemoveDllDirectory

RemoveLocalAlternateComputerNameA

Ordinal 1245
Address 0x51520

RemoveLocalAlternateComputerNameW

Ordinal 1246
Address 0x51590

RemoveSecureMemoryCacheCallback

Ordinal 1247
Address 0x81d00

RemoveVectoredContinueHandler

Ordinal 1248
Address 0x139ec5
ForwardName NTDLL.RtlRemoveVectoredContinueHandler

RemoveVectoredExceptionHandler

Ordinal 1249
Address 0x139f0b
ForwardName NTDLL.RtlRemoveVectoredExceptionHandler

ReplaceFile

Ordinal 1250
Address 0x86f60

ReplaceFileA

Ordinal 1251
Address 0x4f8b0

ReplaceFileW

Ordinal 1252
Address 0x86f60

ReplacePartitionUnit

Ordinal 1253
Address 0x84d50

RequestDeviceWakeup

Ordinal 1254
Address 0x83270

RequestWakeupLatency

Ordinal 1255
Address 0x83270

ResetEvent

Ordinal 1256
Address 0x6f250

ResetWriteWatch

Ordinal 1257
Address 0x86f70

ResizePseudoConsole

Ordinal 1258
Address 0x70bd0

ResolveDelayLoadedAPI

Ordinal 1259
Address 0x139fdc
ForwardName NTDLL.LdrResolveDelayLoadedAPI

ResolveDelayLoadsFromDll

Ordinal 1260
Address 0x13a014
ForwardName NTDLL.LdrResolveDelayLoadsFromDll

ResolveLocaleName

Ordinal 1261
Address 0x86f80

RestoreLastError

Ordinal 1262
Address 0x13a059
ForwardName NTDLL.RtlRestoreLastWin32Error

ResumeThread

Ordinal 1263
Address 0x86f90

RtlAddFunctionTable

Ordinal 1264
Address 0x86fa0

RtlCaptureContext

Ordinal 1265
Address 0x6dbf0

RtlCaptureStackBackTrace

Ordinal 1266
Address 0x13a0c4
ForwardName NTDLL.RtlCaptureStackBackTrace

RtlCompareMemory

Ordinal 1267
Address 0x86fd0

RtlCopyMemory

Ordinal 1268
Address 0x86fe0

RtlDeleteFunctionTable

Ordinal 1269
Address 0x86ff0

RtlFillMemory

Ordinal 1270
Address 0x87020

RtlInstallFunctionTableCallback

Ordinal 1271
Address 0x87040

RtlLookupFunctionEntry

Ordinal 1272
Address 0x87070

RtlMoveMemory

Ordinal 1273
Address 0x13a16c
ForwardName NTDLL.RtlMoveMemory

RtlPcToFileHeader

Ordinal 1274
Address 0x87080

RtlRestoreContext

Ordinal 1275
Address 0x870a0

RtlUnwind

Ordinal 1276
Address 0x870c0

RtlUnwindEx

Ordinal 1277
Address 0x870b0

RtlVirtualUnwind

Ordinal 1278
Address 0x87120

RtlVirtualUnwind2

Ordinal 1279
Address 0x870d0

RtlZeroMemory

Ordinal 1280
Address 0x13a1eb
ForwardName NTDLL.RtlZeroMemory

ScrollConsoleScreenBufferA

Ordinal 1281
Address 0x70d50

ScrollConsoleScreenBufferW

Ordinal 1282
Address 0x70d60

SearchPathA

Ordinal 1283
Address 0x87130

SearchPathW

Ordinal 1284
Address 0x87140

SetCachedSigningLevel

Ordinal 1285
Address 0x87150

SetCalendarInfoA

Ordinal 1286
Address 0x3e2d0

SetCalendarInfoW

Ordinal 1287
Address 0x87160

SetComPlusPackageInstallStatus

Ordinal 1288
Address 0x91200

SetCommBreak

Ordinal 1289
Address 0x704b0

SetCommConfig

Ordinal 1290
Address 0x704c0

SetCommMask

Ordinal 1291
Address 0x704d0

SetCommState

Ordinal 1292
Address 0x704e0

SetCommTimeouts

Ordinal 1293
Address 0x704f0

SetComputerNameA

Ordinal 1294
Address 0x87170

SetComputerNameEx2W

Ordinal 1295
Address 0x87180

SetComputerNameExA

Ordinal 1296
Address 0x87190

SetComputerNameExW

Ordinal 1297
Address 0x871a0

SetComputerNameW

Ordinal 1298
Address 0x871b0

SetConsoleActiveScreenBuffer

Ordinal 1299
Address 0x70d70

SetConsoleCP

Ordinal 1300
Address 0x70d80

SetConsoleCtrlHandler

Ordinal 1301
Address 0x70be0

SetConsoleCursor

Ordinal 1302
Address 0x58d40

SetConsoleCursorInfo

Ordinal 1303
Address 0x70d90

SetConsoleCursorMode

Ordinal 1304
Address 0x591e0

SetConsoleCursorPosition

Ordinal 1305
Address 0x70da0

SetConsoleDisplayMode

Ordinal 1306
Address 0x71040

SetConsoleFont

Ordinal 1307
Address 0x59510

SetConsoleHardwareState

Ordinal 1308
Address 0x58d90

SetConsoleHistoryInfo

Ordinal 1309
Address 0x71050

SetConsoleIcon

Ordinal 1310
Address 0x59560

SetConsoleInputExeNameA

Ordinal 1311
Address 0x13a452
ForwardName kernelbase.SetConsoleInputExeNameA

SetConsoleInputExeNameW

Ordinal 1312
Address 0x13a48d
ForwardName kernelbase.SetConsoleInputExeNameW

SetConsoleKeyShortcuts

Ordinal 1313
Address 0x58de0

SetConsoleLocalEUDC

Ordinal 1314
Address 0x59240

SetConsoleMaximumWindowSize

Ordinal 1315
Address 0x71ba0

SetConsoleMenuClose

Ordinal 1316
Address 0x58e60

SetConsoleMode

Ordinal 1317
Address 0x70bf0

SetConsoleNlsMode

Ordinal 1318
Address 0x592e0

SetConsoleNumberOfCommandsA

Ordinal 1319
Address 0x71060

SetConsoleNumberOfCommandsW

Ordinal 1320
Address 0x71070

SetConsoleOS2OemFormat

Ordinal 1321
Address 0x59330

SetConsoleOutputCP

Ordinal 1322
Address 0x70db0

SetConsolePalette

Ordinal 1323
Address 0x58ec0

SetConsoleScreenBufferInfoEx

Ordinal 1324
Address 0x70dc0

SetConsoleScreenBufferSize

Ordinal 1325
Address 0x70dd0

SetConsoleTextAttribute

Ordinal 1326
Address 0x70de0

SetConsoleTitleA

Ordinal 1327
Address 0x70df0

SetConsoleTitleW

Ordinal 1328
Address 0x70e00

SetConsoleWindowInfo

Ordinal 1329
Address 0x70e10

SetCriticalSectionSpinCount

Ordinal 1330
Address 0x13a643
ForwardName NTDLL.RtlSetCriticalSectionSpinCount

SetCurrentConsoleFontEx

Ordinal 1331
Address 0x71080

SetCurrentDirectoryA

Ordinal 1332
Address 0x871c0

SetCurrentDirectoryW

Ordinal 1333
Address 0x871d0

SetDefaultCommConfigA

Ordinal 1334
Address 0x32fe0

SetDefaultCommConfigW

Ordinal 1335
Address 0x33080

SetDefaultDllDirectories

Ordinal 1336
Address 0x13a6ef
ForwardName api-ms-win-core-libraryloader-l1-1-0.SetDefaultDllDirectories

SetDllDirectoryA

Ordinal 1337
Address 0x58340

SetDllDirectoryW

Ordinal 1338
Address 0x198b0

SetDynamicTimeZoneInformation

Ordinal 1339
Address 0x871e0

SetEndOfFile

Ordinal 1340
Address 0x6f780

SetEnvironmentStringsA

Ordinal 1341
Address 0xcf440

SetEnvironmentStringsW

Ordinal 1342
Address 0x871f0

SetEnvironmentVariableA

Ordinal 1343
Address 0x87200

SetEnvironmentVariableW

Ordinal 1344
Address 0x87210

SetErrorMode

Ordinal 1345
Address 0x87220

SetEvent

Ordinal 1346
Address 0x6f260

SetEventWhenCallbackReturns

Ordinal 1347
Address 0x13a80a
ForwardName NTDLL.TpCallbackSetEventOnCompletion

SetFileApisToANSI

Ordinal 1348
Address 0x87230

SetFileApisToOEM

Ordinal 1349
Address 0x87240

SetFileAttributesA

Ordinal 1350
Address 0x6f790

SetFileAttributesTransactedA

Ordinal 1351
Address 0x578b0

SetFileAttributesTransactedW

Ordinal 1352
Address 0xcb820

SetFileAttributesW

Ordinal 1353
Address 0x6f7a0

SetFileBandwidthReservation

Ordinal 1354
Address 0x2fe20

SetFileCompletionNotificationModes

Ordinal 1355
Address 0x19230

SetFileInformationByHandle

Ordinal 1356
Address 0x6f7b0

SetFileIoOverlappedRange

Ordinal 1357
Address 0x87250

SetFilePointer

Ordinal 1358
Address 0x6f350

SetFilePointerEx

Ordinal 1359
Address 0x6f370

SetFileShortNameA

Ordinal 1360
Address 0x2ff40

SetFileShortNameW

Ordinal 1361
Address 0x80f60

SetFileTime

Ordinal 1362
Address 0x6f7c0

SetFileValidData

Ordinal 1363
Address 0x6f7d0

SetFirmwareEnvironmentVariableA

Ordinal 1364
Address 0x58560

SetFirmwareEnvironmentVariableExA

Ordinal 1365
Address 0x58570

SetFirmwareEnvironmentVariableExW

Ordinal 1366
Address 0x1abf0

SetFirmwareEnvironmentVariableW

Ordinal 1367
Address 0x1abe0

SetHandleCount

Ordinal 1368
Address 0x810a0

SetHandleInformation

Ordinal 1369
Address 0x6f0b0

SetInformationJobObject

Ordinal 1370
Address 0x19170

SetIoRateControlInformationJobObject

Ordinal 1371
Address 0x521e0

SetIoRingCompletionEvent

Ordinal 1372
Address 0x13aa84
ForwardName api-ms-win-core-ioring-l1-1-0.SetIoRingCompletionEvent

SetLastConsoleEventActive

Ordinal 1373
Address 0x13aad5
ForwardName kernelbase.SetLastConsoleEventActive

SetLastError

Ordinal 1374
Address 0x87260

SetLocalPrimaryComputerNameA

Ordinal 1375
Address 0x517b0

SetLocalPrimaryComputerNameW

Ordinal 1376
Address 0x51820

SetLocalTime

Ordinal 1377
Address 0x87270

SetLocaleInfoA

Ordinal 1378
Address 0x3e3a0

SetLocaleInfoW

Ordinal 1379
Address 0x87280

SetMailslotInfo

Ordinal 1380
Address 0xca630

SetMessageWaitingIndicator

Ordinal 1381
Address 0x83270

SetNamedPipeAttribute

Ordinal 1382
Address 0x30bb0

SetNamedPipeHandleState

Ordinal 1383
Address 0x87290

SetPriorityClass

Ordinal 1384
Address 0x872a0

SetProcessAffinityMask

Ordinal 1385
Address 0xb7bb0

SetProcessAffinityUpdateMode

Ordinal 1386
Address 0x872b0

SetProcessDEPPolicy

Ordinal 1387
Address 0x84c90

SetProcessDefaultCpuSetMasks

Ordinal 1388
Address 0x13ac3b
ForwardName api-ms-win-core-processthreads-l1-1-6.SetProcessDefaultCpuSetMasks

SetProcessDefaultCpuSets

Ordinal 1389
Address 0x13ac97
ForwardName api-ms-win-core-processthreads-l1-1-3.SetProcessDefaultCpuSets

SetProcessDynamicEHContinuationTargets

Ordinal 1390
Address 0x13acfd
ForwardName api-ms-win-core-processthreads-l1-1-4.SetProcessDynamicEHContinuationTargets

SetProcessDynamicEnforcedCetCompatibleRanges

Ordinal 1391
Address 0x13ad77
ForwardName api-ms-win-core-processthreads-l1-1-6.SetProcessDynamicEnforcedCetCompatibleRanges

SetProcessInformation

Ordinal 1392
Address 0x6ebd0

SetProcessMitigationPolicy

Ordinal 1393
Address 0x13adfb
ForwardName api-ms-win-core-processthreads-l1-1-1.SetProcessMitigationPolicy

SetProcessPreferredUILanguages

Ordinal 1394
Address 0x872c0

SetProcessPriorityBoost

Ordinal 1395
Address 0x872d0

SetProcessShutdownParameters

Ordinal 1396
Address 0x872e0

SetProcessWorkingSetSize

Ordinal 1397
Address 0x6f070

SetProcessWorkingSetSizeEx

Ordinal 1398
Address 0x872f0

SetProtectedPolicy

Ordinal 1399
Address 0x13aed7
ForwardName api-ms-win-core-processthreads-l1-1-2.SetProtectedPolicy

SetSearchPathMode

Ordinal 1400
Address 0x82c20

SetStdHandle

Ordinal 1401
Address 0x87310

SetStdHandleEx

Ordinal 1402
Address 0x87300

SetSystemFileCacheSize

Ordinal 1403
Address 0x87320

SetSystemPowerState

Ordinal 1404
Address 0xce290

SetSystemTime

Ordinal 1405
Address 0x87330

SetSystemTimeAdjustment

Ordinal 1406
Address 0x80720

SetTapeParameters

Ordinal 1407
Address 0x8d790

SetTapePosition

Ordinal 1408
Address 0x36b60

SetTermsrvAppInstallMode

Ordinal 1409
Address 0x4b5e0

SetThreadAffinityMask

Ordinal 1410
Address 0x1a890

SetThreadContext

Ordinal 1411
Address 0x87340

SetThreadDescription

Ordinal 1412
Address 0x13b006
ForwardName api-ms-win-core-processthreads-l1-1-3.SetThreadDescription

SetThreadErrorMode

Ordinal 1413
Address 0x87350

SetThreadExecutionState

Ordinal 1414
Address 0x19a50

SetThreadGroupAffinity

Ordinal 1415
Address 0x87360

SetThreadIdealProcessor

Ordinal 1416
Address 0x87380

SetThreadIdealProcessorEx

Ordinal 1417
Address 0x87370

SetThreadInformation

Ordinal 1418
Address 0x6e9a0

SetThreadLocale

Ordinal 1419
Address 0x87390

SetThreadPreferredUILanguages

Ordinal 1420
Address 0x873a0

SetThreadPriority

Ordinal 1421
Address 0x873c0

SetThreadPriorityBoost

Ordinal 1422
Address 0x873b0

SetThreadSelectedCpuSetMasks

Ordinal 1423
Address 0x13b13e
ForwardName api-ms-win-core-processthreads-l1-1-6.SetThreadSelectedCpuSetMasks

SetThreadSelectedCpuSets

Ordinal 1424
Address 0x13b19a
ForwardName api-ms-win-core-processthreads-l1-1-3.SetThreadSelectedCpuSets

SetThreadStackGuarantee

Ordinal 1425
Address 0x873d0

SetThreadToken

Ordinal 1426
Address 0x13b200
ForwardName api-ms-win-core-processthreads-l1-1-0.SetThreadToken

SetThreadUILanguage

Ordinal 1427
Address 0x873e0

SetThreadpoolStackInformation

Ordinal 1428
Address 0x87410

SetThreadpoolThreadMaximum

Ordinal 1429
Address 0x13b282
ForwardName NTDLL.TpSetPoolMaxThreads

SetThreadpoolThreadMinimum

Ordinal 1430
Address 0x1af50

SetThreadpoolTimer

Ordinal 1431
Address 0x13b2ca
ForwardName NTDLL.TpSetTimer

SetThreadpoolTimerEx

Ordinal 1432
Address 0x13b2f0
ForwardName NTDLL.TpSetTimerEx

SetThreadpoolWait

Ordinal 1433
Address 0x13b315
ForwardName NTDLL.TpSetWait

SetThreadpoolWaitEx

Ordinal 1434
Address 0x13b339
ForwardName NTDLL.TpSetWaitEx

SetTimeZoneInformation

Ordinal 1435
Address 0x87490

SetTimerQueueTimer

Ordinal 1436
Address 0x915f0

SetUmsThreadInformation

Ordinal 1437
Address 0x8c620

SetUnhandledExceptionFilter

Ordinal 1438
Address 0x874a0

SetUserGeoID

Ordinal 1439
Address 0x45910

SetUserGeoName

Ordinal 1440
Address 0x45930

SetVDMCurrentDirectories

Ordinal 1441
Address 0x35e20

SetVolumeLabelA

Ordinal 1442
Address 0x587a0

SetVolumeLabelW

Ordinal 1443
Address 0x58840

SetVolumeMountPointA

Ordinal 1444
Address 0x4ea40

SetVolumeMountPointW

Ordinal 1445
Address 0x4eac0

SetVolumeMountPointWStub

Ordinal 1446
Address 0x31af0

SetWaitableTimer

Ordinal 1447
Address 0x6f270

SetWaitableTimerEx

Ordinal 1448
Address 0x13b465
ForwardName api-ms-win-core-synch-l1-1-0.SetWaitableTimerEx

SetupComm

Ordinal 1449
Address 0x70500

ShowConsoleCursor

Ordinal 1450
Address 0x58f10

SignalObjectAndWait

Ordinal 1451
Address 0x874d0

SizeofResource

Ordinal 1452
Address 0x874e0

Sleep

Ordinal 1453
Address 0x874f0

SleepConditionVariableCS

Ordinal 1454
Address 0x13b4f3
ForwardName api-ms-win-core-synch-l1-2-0.SleepConditionVariableCS

SleepConditionVariableSRW

Ordinal 1455
Address 0x13b543
ForwardName api-ms-win-core-synch-l1-2-0.SleepConditionVariableSRW

SleepEx

Ordinal 1456
Address 0x6f280

SortCloseHandle

Ordinal 1457
Address 0xa5860

SortGetHandle

Ordinal 1458
Address 0x145a0

StartThreadpoolIo

Ordinal 1459
Address 0x13b5b2
ForwardName NTDLL.TpStartAsyncIoOperation

SubmitIoRing

Ordinal 1460
Address 0x13b5dd
ForwardName api-ms-win-core-ioring-l1-1-0.SubmitIoRing

SubmitThreadpoolWork

Ordinal 1461
Address 0x13b61d
ForwardName NTDLL.TpPostWork

SuspendThread

Ordinal 1462
Address 0x87500

SwitchToFiber

Ordinal 1463
Address 0x708e0

SwitchToThread

Ordinal 1464
Address 0x87510

SystemTimeToFileTime

Ordinal 1465
Address 0x87520

SystemTimeToTzSpecificLocalTime

Ordinal 1466
Address 0x87530

SystemTimeToTzSpecificLocalTimeEx

Ordinal 1467
Address 0x13b6b0
ForwardName api-ms-win-core-timezone-l1-1-0.SystemTimeToTzSpecificLocalTimeEx

TerminateJobObject

Ordinal 1468
Address 0xc1bb0

TerminateProcess

Ordinal 1469
Address 0x87540

TerminateThread

Ordinal 1470
Address 0x87550

TermsrvAppInstallMode

Ordinal 1471
Address 0x4b6d0

TermsrvConvertSysRootToUserDir

Ordinal 1472
Address 0x12130

TermsrvCreateRegEntry

Ordinal 1473
Address 0x16ba0

TermsrvDeleteKey

Ordinal 1474
Address 0x187b0

TermsrvDeleteValue

Ordinal 1475
Address 0x182f0

TermsrvGetPreSetValue

Ordinal 1476
Address 0x16810

TermsrvGetWindowsDirectoryA

Ordinal 1477
Address 0x20010

TermsrvGetWindowsDirectoryW

Ordinal 1478
Address 0xd610

TermsrvOpenRegEntry

Ordinal 1479
Address 0x13240

TermsrvOpenUserClasses

Ordinal 1480
Address 0x18b50

TermsrvRestoreKey

Ordinal 1481
Address 0x4c1e0

TermsrvSetKeySecurity

Ordinal 1482
Address 0x17f70

TermsrvSetValueKey

Ordinal 1483
Address 0x167e0

TermsrvSyncUserIniFileExt

Ordinal 1484
Address 0x11e00

Thread32First

Ordinal 1485
Address 0xccfe0

Thread32Next

Ordinal 1486
Address 0xcd0e0

TlsAlloc

Ordinal 1487
Address 0x87560

TlsFree

Ordinal 1488
Address 0x87570

TlsGetValue

Ordinal 1489
Address 0x87580

TlsSetValue

Ordinal 1490
Address 0x87590

Toolhelp32ReadProcessMemory

Ordinal 1491
Address 0x87a10

TransactNamedPipe

Ordinal 1492
Address 0x875a0

TransmitCommChar

Ordinal 1493
Address 0x70510

TryAcquireSRWLockExclusive

Ordinal 1494
Address 0x13b901
ForwardName NTDLL.RtlTryAcquireSRWLockExclusive

TryAcquireSRWLockShared

Ordinal 1495
Address 0x13b93d
ForwardName NTDLL.RtlTryAcquireSRWLockShared

TryEnterCriticalSection

Ordinal 1496
Address 0x13b976
ForwardName NTDLL.RtlTryEnterCriticalSection

TrySubmitThreadpoolCallback

Ordinal 1497
Address 0x19320

TzSpecificLocalTimeToSystemTime

Ordinal 1498
Address 0x875f0

TzSpecificLocalTimeToSystemTimeEx

Ordinal 1499
Address 0x13b9f5
ForwardName api-ms-win-core-timezone-l1-1-0.TzSpecificLocalTimeToSystemTimeEx

UTRegister

Ordinal 1500
Address 0x82c60

UTUnRegister

Ordinal 1501
Address 0x80560

UmsThreadYield

Ordinal 1502
Address 0x8c650

UnhandledExceptionFilter

Ordinal 1503
Address 0x87600

UnlockFile

Ordinal 1504
Address 0x6f7e0

UnlockFileEx

Ordinal 1505
Address 0x6f7f0

UnmapViewOfFile

Ordinal 1506
Address 0x87610

UnmapViewOfFileEx

Ordinal 1507
Address 0x13bab1
ForwardName api-ms-win-core-memory-l1-1-1.UnmapViewOfFileEx

UnregisterApplicationRecoveryCallback

Ordinal 1508
Address 0x37090

UnregisterApplicationRestart

Ordinal 1509
Address 0x87620

UnregisterBadMemoryNotification

Ordinal 1510
Address 0x87630

UnregisterConsoleIME

Ordinal 1511
Address 0xd01d0

UnregisterWait

Ordinal 1512
Address 0x11ae0

UnregisterWaitEx

Ordinal 1513
Address 0x87640

UnregisterWaitUntilOOBECompleted

Ordinal 1514
Address 0xcf3d0

UpdateCalendarDayOfWeek

Ordinal 1515
Address 0x141b0

UpdateProcThreadAttribute

Ordinal 1516
Address 0x13bbcc
ForwardName api-ms-win-core-processthreads-l1-1-0.UpdateProcThreadAttribute

UpdateResourceA

Ordinal 1517
Address 0x3cf70

UpdateResourceW

Ordinal 1518
Address 0x3d0f0

VDMConsoleOperation

Ordinal 1519
Address 0x59600

VDMOperationStarted

Ordinal 1520
Address 0x360c0

VerLanguageNameA

Ordinal 1521
Address 0x87650

VerLanguageNameW

Ordinal 1522
Address 0x87660

VerSetConditionMask

Ordinal 1523
Address 0x13bc8a
ForwardName NTDLL.VerSetConditionMask

VerifyConsoleIoHandle

Ordinal 1524
Address 0x71b60

VerifyScripts

Ordinal 1525
Address 0x87670

VerifyVersionInfoA

Ordinal 1526
Address 0x583f0

VerifyVersionInfoW

Ordinal 1527
Address 0x181f0

VirtualAlloc

Ordinal 1528
Address 0x876a0

VirtualAllocEx

Ordinal 1529
Address 0x87690

VirtualAllocExNuma

Ordinal 1530
Address 0x87680

VirtualFree

Ordinal 1531
Address 0x876c0

VirtualFreeEx

Ordinal 1532
Address 0x876b0

VirtualLock

Ordinal 1533
Address 0x876d0

VirtualProtect

Ordinal 1534
Address 0x876f0

VirtualProtectEx

Ordinal 1535
Address 0x876e0

VirtualQuery

Ordinal 1536
Address 0x87710

VirtualQueryEx

Ordinal 1537
Address 0x87700

VirtualUnlock

Ordinal 1538
Address 0x87720

WTSGetActiveConsoleSessionId

Ordinal 1539
Address 0xcd970

WaitCommEvent

Ordinal 1540
Address 0x70520

WaitForDebugEvent

Ordinal 1541
Address 0x87730

WaitForDebugEventEx

Ordinal 1542
Address 0x13bdde
ForwardName api-ms-win-core-debug-l1-1-2.WaitForDebugEventEx

WaitForMultipleObjects

Ordinal 1543
Address 0x6f290

WaitForMultipleObjectsEx

Ordinal 1544
Address 0x6f2a0

WaitForSingleObject

Ordinal 1545
Address 0x6f2b0

WaitForSingleObjectEx

Ordinal 1546
Address 0x6f2c0

WaitForThreadpoolIoCallbacks

Ordinal 1547
Address 0x13be86
ForwardName NTDLL.TpWaitForIoCompletion

WaitForThreadpoolTimerCallbacks

Ordinal 1548
Address 0x13bec2
ForwardName NTDLL.TpWaitForTimer

WaitForThreadpoolWaitCallbacks

Ordinal 1549
Address 0x13bef6
ForwardName NTDLL.TpWaitForWait

WaitForThreadpoolWorkCallbacks

Ordinal 1550
Address 0x13bf29
ForwardName NTDLL.TpWaitForWork

WaitNamedPipeA

Ordinal 1551
Address 0x56b80

WaitNamedPipeW

Ordinal 1552
Address 0x87740

WakeAllConditionVariable

Ordinal 1553
Address 0x13bf74
ForwardName NTDLL.RtlWakeAllConditionVariable

WakeConditionVariable

Ordinal 1554
Address 0x13bfac
ForwardName NTDLL.RtlWakeConditionVariable

WerGetFlags

Ordinal 1555
Address 0x1f570

WerGetFlagsWorker

Ordinal 1556
Address 0x1f570

WerRegisterAdditionalProcess

Ordinal 1557
Address 0x87750

WerRegisterAppLocalDump

Ordinal 1558
Address 0x87760

WerRegisterCustomMetadata

Ordinal 1559
Address 0x87770

WerRegisterExcludedMemoryBlock

Ordinal 1560
Address 0x87780

WerRegisterFile

Ordinal 1561
Address 0x87790

WerRegisterFileWorker

Ordinal 1562
Address 0x370b0

WerRegisterMemoryBlock

Ordinal 1563
Address 0x877a0

WerRegisterMemoryBlockWorker

Ordinal 1564
Address 0x370c0

WerRegisterRuntimeExceptionModule

Ordinal 1565
Address 0x877b0

WerRegisterRuntimeExceptionModuleWorker

Ordinal 1566
Address 0x370d0

WerSetFlags

Ordinal 1567
Address 0x18360

WerSetFlagsWorker

Ordinal 1568
Address 0x18360

WerUnregisterAdditionalProcess

Ordinal 1569
Address 0x877c0

WerUnregisterAppLocalDump

Ordinal 1570
Address 0x877d0

WerUnregisterCustomMetadata

Ordinal 1571
Address 0x877e0

WerUnregisterExcludedMemoryBlock

Ordinal 1572
Address 0x877f0

WerUnregisterFile

Ordinal 1573
Address 0x87800

WerUnregisterFileWorker

Ordinal 1574
Address 0x370e0

WerUnregisterMemoryBlock

Ordinal 1575
Address 0x87810

WerUnregisterMemoryBlockWorker

Ordinal 1576
Address 0x370f0

WerUnregisterRuntimeExceptionModule

Ordinal 1577
Address 0x87820

WerUnregisterRuntimeExceptionModuleWorker

Ordinal 1578
Address 0x37100

WerpGetDebugger

Ordinal 1579
Address 0x5ba30

WerpInitiateRemoteRecovery

Ordinal 1580
Address 0x37110

WerpLaunchAeDebug

Ordinal 1581
Address 0x5c440

WerpNotifyLoadStringResourceWorker

Ordinal 1582
Address 0x91550

WerpNotifyUseStringResourceWorker

Ordinal 1583
Address 0x91550

WideCharToMultiByte

Ordinal 1584
Address 0x87830

WinExec

Ordinal 1585
Address 0x4cb10

Wow64DisableWow64FsRedirection

Ordinal 1586
Address 0x87840

Wow64EnableWow64FsRedirection

Ordinal 1587
Address 0x705d0

Wow64GetThreadContext

Ordinal 1588
Address 0x87850

Wow64GetThreadSelectorEntry

Ordinal 1589
Address 0x2fb10

Wow64RevertWow64FsRedirection

Ordinal 1590
Address 0x87860

Wow64SetThreadContext

Ordinal 1591
Address 0x87870

Wow64SuspendThread

Ordinal 1592
Address 0x87880

WriteConsoleA

Ordinal 1593
Address 0x70c00

WriteConsoleInputA

Ordinal 1594
Address 0x70e20

WriteConsoleInputVDMA

Ordinal 1595
Address 0x58f50

WriteConsoleInputVDMW

Ordinal 1596
Address 0x58fd0

WriteConsoleInputW

Ordinal 1597
Address 0x70e30

WriteConsoleOutputA

Ordinal 1598
Address 0x70e40

WriteConsoleOutputAttribute

Ordinal 1599
Address 0x70e50

WriteConsoleOutputCharacterA

Ordinal 1600
Address 0x70e60

WriteConsoleOutputCharacterW

Ordinal 1601
Address 0x70e70

WriteConsoleOutputW

Ordinal 1602
Address 0x70e80

WriteConsoleW

Ordinal 1603
Address 0x70c10

WriteFile

Ordinal 1604
Address 0x6f800

WriteFileEx

Ordinal 1605
Address 0x6f810

WriteFileGather

Ordinal 1606
Address 0x6f820

WritePrivateProfileSectionA

Ordinal 1607
Address 0x564f0

WritePrivateProfileSectionW

Ordinal 1608
Address 0x56560

WritePrivateProfileStringA

Ordinal 1609
Address 0x565d0

WritePrivateProfileStringW

Ordinal 1610
Address 0x12210

WritePrivateProfileStructA

Ordinal 1611
Address 0x56640

WritePrivateProfileStructW

Ordinal 1612
Address 0x567a0

WriteProcessMemory

Ordinal 1613
Address 0x87890

WriteProfileSectionA

Ordinal 1614
Address 0x56900

WriteProfileSectionW

Ordinal 1615
Address 0x56910

WriteProfileStringA

Ordinal 1616
Address 0x56920

WriteProfileStringW

Ordinal 1617
Address 0x56930

WriteTapemark

Ordinal 1618
Address 0x36bc0

ZombifyActCtx

Ordinal 1619
Address 0x878a0

ZombifyActCtxWorker

Ordinal 1620
Address 0x91010

_hread

Ordinal 1621
Address 0xb9fe0

_hwrite

Ordinal 1622
Address 0xba020

_lclose

Ordinal 1623
Address 0xb9e80

_lcreat

Ordinal 1624
Address 0xb9eb0

_llseek

Ordinal 1625
Address 0x17690

_lopen

Ordinal 1626
Address 0xb9f60

_lread

Ordinal 1627
Address 0xb9fe0

_lwrite

Ordinal 1628
Address 0xba020

lstrcat

Ordinal 1629
Address 0xba070

lstrcatA

Ordinal 1630
Address 0xba070

lstrcatW

Ordinal 1631
Address 0xba100

lstrcmp

Ordinal 1632
Address 0x19110

lstrcmpA

Ordinal 1633
Address 0x19110

lstrcmpW

Ordinal 1634
Address 0x7f750

lstrcmpi

Ordinal 1635
Address 0x17c60

lstrcmpiA

Ordinal 1636
Address 0x17c60

lstrcmpiW

Ordinal 1637
Address 0x7f760

lstrcpy

Ordinal 1638
Address 0xba2d0

lstrcpyA

Ordinal 1639
Address 0xba2d0

lstrcpyW

Ordinal 1640
Address 0xba340

lstrcpyn

Ordinal 1641
Address 0x878d0

lstrcpynA

Ordinal 1642
Address 0x878d0

lstrcpynW

Ordinal 1643
Address 0x878e0

lstrlen

Ordinal 1644
Address 0x878f0

lstrlenA

Ordinal 1645
Address 0x878f0

lstrlenW

Ordinal 1646
Address 0x87900

timeBeginPeriod

Ordinal 1647
Address 0x6400

timeEndPeriod

Ordinal 1648
Address 0x62b0

timeGetDevCaps

Ordinal 1649
Address 0x1aee0

timeGetSystemTime

Ordinal 1650
Address 0x20db0

timeGetTime

Ordinal 1651
Address 0x18ed0

uaw_lstrcmpW

Ordinal 1652
Address 0x7f750

uaw_lstrcmpiW

Ordinal 1653
Address 0x7f760

uaw_lstrlenW

Ordinal 1654
Address 0x7f770

uaw_wcschr

Ordinal 1655
Address 0x7f7e0

uaw_wcscpy

Ordinal 1656
Address 0x7f810

uaw_wcsicmp

Ordinal 1657
Address 0x7f830

uaw_wcslen

Ordinal 1658
Address 0x7f840

uaw_wcsrchr

Ordinal 1659
Address 0x7f870

1

Type MUI
Language English - United States
Codepage UNKNOWN
Size 0xc8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.70683
MD5 2fb54c42a4b9c6e6e4850bf3f5fb8199
SHA1 1f052c379a34643e04540a8f152a90eadcaaa3f4
SHA256 7461251a02909765e6ef8dda6304321b6e7f986df9f27e75af8bb214fb0a43b0
SHA3 c00a50f3953c5559b11c1dbc65fca0603dfd31df369d6aa923925df23ee67ef0

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x3a4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.52738
MD5 5494f0555c14807359dc9bea02de50ff
SHA1 919f6a81623c32f3a17b6371de96d712515ac3ab
SHA256 945c7999fdd62d9ef683d114b9d580d6c6d477d890ad88c6b89b5319a2120d68
SHA3 d0688916bbfd4016327518b0c0dbf5bcc95a80a0b1cc886b2848618e623594b3

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 10.0.22621.5415
ProductVersion 10.0.22621.5415
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_DLL
Language English - United States
CompanyName Microsoft Corporation
FileDescription Windows NT BASE API Client DLL
FileVersion (#2) 10.0.22621.5415 (WinBuild.160101.0800)
InternalName kernel32
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename kernel32
ProductName Microsoft® Windows® Operating System
ProductVersion (#2) 10.0.22621.5415
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2040-Apr-21 23:38:00
Version 0.0
SizeofData 37
AddressOfRawData 0x112ad0
PointerToRawData 0x110ed0
Referenced File kernel32.pdb

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2040-Apr-21 23:38:00
Version 0.0
SizeofData 1540
AddressOfRawData 0x112af8
PointerToRawData 0x110ef8

UNKNOWN

Characteristics 0
TimeDateStamp 2040-Apr-21 23:38:00
Version 0.0
SizeofData 36
AddressOfRawData 0x1130fc
PointerToRawData 0x1114fc

TLS Callbacks

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x18014e000
GuardCFCheckFunctionPointer 6443458624
GuardCFDispatchFunctionPointer 0
GuardCFFunctionTable 0
GuardCFFunctionCount 0
GuardFlags (EMPTY)
CodeIntegrity.Flags 0
CodeIntegrity.Catalog 0
CodeIntegrity.CatalogOffset 0
CodeIntegrity.Reserved 0
GuardAddressTakenIatEntryTable 0
GuardAddressTakenIatEntryCount 0
GuardLongJumpTargetTable 0
GuardLongJumpTargetCount 0

RICH Header

XOR Key 0xbfbff040
Unmarked objects 0
Imports (30795) 4
Imports (VS2008 SP1 build 30729) 203
Total imports 2678
C objects (30795) 24
ASM objects (30795) 12
C objects (POGO O) (30795) 416
Exports (30795) 2
Resource objects (30795) 1
Linker (30795) 1

Errors

Leave a comment

No comments yet.