AccessCheckAndAuditAlarmA@44
AccessCheckAndAuditAlarmW@44
;AccessCheckByType
-;AccessCheckByTypeAndAuditAlarmA@64
-;AccessCheckByTypeAndAuditAlarmW@64
+AccessCheckByTypeAndAuditAlarmA@64
+AccessCheckByTypeAndAuditAlarmW@64
;AccessCheckByTypeResultList@44
-;AccessCheckByTypeResultListAndAuditAlarmA@64
-;AccessCheckByTypeResultListAndAuditAlarmByHandleA@68
-;AccessCheckByTypeResultListAndAuditAlarmByHandleW@68
-;AccessCheckByTypeResultListAndAuditAlarmW@64
+AccessCheckByTypeResultListAndAuditAlarmA@64
+AccessCheckByTypeResultListAndAuditAlarmByHandleA@68
+AccessCheckByTypeResultListAndAuditAlarmByHandleW@68
+AccessCheckByTypeResultListAndAuditAlarmW@64
AddAccessAllowedAce@16
AddAccessAllowedAceEx@20
-;AddAccessAllowedObjectAce@28
+AddAccessAllowedObjectAce@28
AddAccessDeniedAce@16
AddAccessDeniedAceEx@20
-;AddAccessDeniedObjectAce@28
+AddAccessDeniedObjectAce@28
AddAce@20
AddAuditAccessAce@24
AddAuditAccessAceEx@28
-;AddAuditAccessObjectAce@36
-;AddUsersToEncryptedFile@8
+AddAuditAccessObjectAce@36
+AddUsersToEncryptedFile@8
AdjustTokenGroups@24
AdjustTokenPrivileges@24
AllocateAndInitializeSid@44
BuildImpersonateExplicitAccessWithNameW@24
BuildImpersonateTrusteeA@8
BuildImpersonateTrusteeW@8
-;BuildSecurityDescriptorA@36
-;BuildSecurityDescriptorW@36
+BuildSecurityDescriptorA@36
+BuildSecurityDescriptorW@36
BuildTrusteeWithNameA@8
BuildTrusteeWithNameW@8
BuildTrusteeWithObjectsAndNameA@24
CloseEventLog@4
CloseServiceHandle@4
;CloseTrace@8
-;CommandLineFromMsiDescriptor@12
+CommandLineFromMsiDescriptor@12
;ComputeAccessTokenFromCodeAuthzLevel@20
ControlService@12
+ControlServiceEx@16
;ControlTraceA@12
;ControlTraceW@12
;ConvertAccessToSecurityDescriptorA@20
;ConvertSecurityDescriptorToAccessNamedA=ConvertSecurityDescriptorToAccessA@28
;ConvertSecurityDescriptorToAccessNamedW=ConvertSecurityDescriptorToAccessW@28
;ConvertSecurityDescriptorToAccessW@28
-;ConvertSecurityDescriptorToStringSecurityDescriptorA@20
-;ConvertSecurityDescriptorToStringSecurityDescriptorW@20
+ConvertSecurityDescriptorToStringSecurityDescriptorA@20
+ConvertSecurityDescriptorToStringSecurityDescriptorW@20
ConvertSidToStringSidA@8
ConvertSidToStringSidW@8
;ConvertStringSDToSDDomainA@24
;ConvertStringSDToSDDomainW@24
;ConvertStringSDToSDRootDomainA@20
;ConvertStringSDToSDRootDomainW@20
-;ConvertStringSecurityDescriptorToSecurityDescriptorA@20
-;ConvertStringSecurityDescriptorToSecurityDescriptorW@20
-;ConvertStringSidToSidA@8
-;ConvertStringSidToSidW@8
-;ConvertToAutoInheritPrivateObjectSecurity@24
+ConvertStringSecurityDescriptorToSecurityDescriptorA@16
+ConvertStringSecurityDescriptorToSecurityDescriptorW@16
+ConvertStringSidToSidA@8
+ConvertStringSidToSidW@8
+ConvertToAutoInheritPrivateObjectSecurity@24
CopySid@12
;CreateCodeAuthzLevel@20
-;CreatePrivateObjectSecurity@24
-;CreatePrivateObjectSecurityEx@32
-;CreatePrivateObjectSecurityWithMultipleInheritance@36
+CreatePrivateObjectSecurity@24
+CreatePrivateObjectSecurityEx@32
+CreatePrivateObjectSecurityWithMultipleInheritance@36
CreateProcessAsUserA@44
;CreateProcessAsUserSecure
CreateProcessAsUserW@44
;CreateProcessWithLogonW
-;CreateRestrictedToken@36
+CreateRestrictedToken@36
CreateServiceA@52
CreateServiceW@52
;CreateTraceInstanceId@8
-;CreateWellKnownSid@16
+CreateWellKnownSid@16
;CredDeleteA@12
;CredDeleteW@12
;CredEnumerateA@16
;CryptEnumProviderTypesA@24
;CryptEnumProviderTypesW@24
;CryptEnumProvidersA@24
-;CryptEnumProvidersW@24
+CryptEnumProvidersW@24
CryptExportKey@24
CryptGenKey@16
CryptGenRandom@12
;CryptSetProviderExW@16
CryptSetProviderW@8
CryptSignHashA@24
-;CryptSignHashW@24
+CryptSignHashW@24
CryptVerifySignatureA@24
CryptVerifySignatureW@24
-;DecryptFileA@8
-;DecryptFileW@8
+DecryptFileA@8
+DecryptFileW@8
DeleteAce@8
DeleteService@4
DeregisterEventSource@4
-;DestroyPrivateObjectSecurity@4
+DestroyPrivateObjectSecurity@4
;DuplicateEncryptionInfoFile
DuplicateToken@12
DuplicateTokenEx@24
;ElfReportEventA@48
;ElfReportEventW@48
;EnableTrace
-;EncryptFileA
-;EncryptFileW
+EncryptFileA@4
+EncryptFileW@4
;EncryptedFileKeyInfo
-;EncryptionDisable
+EncryptionDisable@8
EnumDependentServicesA@24
EnumDependentServicesW@24
EnumServiceGroupW@36
EnumServicesStatusA@32
-;EnumServicesStatusExA
-;EnumServicesStatusExW
+EnumServicesStatusExA@40
+EnumServicesStatusExW@40
EnumServicesStatusW@32
;EnumerateTraceGuids
-;EqualDomainSid
+EqualDomainSid@12
EqualPrefixSid@8
EqualSid@8
-;FileEncryptionStatusA
-;FileEncryptionStatusW
+FileEncryptionStatusA@8
+FileEncryptionStatusW@8
FindFirstFreeAce@8
;FlushTraceA
;FlushTraceW
;FreeEncryptedFileKeyInfo
-;FreeEncryptionCertificateHashList
+FreeEncryptionCertificateHashList@4
FreeInheritedFromArray@12
FreeSid@4
;GetAccessPermissionsForObjectA
;GetAccessPermissionsForObjectW
GetAce@12
GetAclInformation@16
-;GetAuditedPermissionsFromAclA@16
-;GetAuditedPermissionsFromAclW@16
+GetAuditedPermissionsFromAclA@16
+GetAuditedPermissionsFromAclW@16
GetCurrentHwProfileA@4
GetCurrentHwProfileW@4
-;GetEffectiveRightsFromAclA@12
-;GetEffectiveRightsFromAclW@12
+GetEffectiveRightsFromAclA@12
+GetEffectiveRightsFromAclW@12
;GetEventLogInformation
-;GetExplicitEntriesFromAclA@12
-;GetExplicitEntriesFromAclW@12
+GetExplicitEntriesFromAclA@12=ADVAPI32.GetExplicitEntriesFromAclW
+GetExplicitEntriesFromAclW@12
GetFileSecurityA@20
GetFileSecurityW@20
;GetInformationCodeAuthzLevelW
GetNumberOfEventLogRecords@8
GetOldestEventLogRecord@8
;GetOverlappedAccessResults
-;GetPrivateObjectSecurity@20
+GetPrivateObjectSecurity@20
GetSecurityDescriptorControl@12
GetSecurityDescriptorDacl@16
GetSecurityDescriptorGroup@12
GetTrusteeTypeW@4
GetUserNameA@8
GetUserNameW@8
-;GetWindowsAccountDomainSid
+GetWindowsAccountDomainSid@12
;I_ScGetCurrentGroupStateW@12
;I_ScIsSecurityProcess
;I_ScPnPGetServiceName
InitializeSid@12
InitiateSystemShutdownA@20
;InitiateSystemShutdownExA@24
-;InitiateSystemShutdownExW@24
+InitiateSystemShutdownExW@24
InitiateSystemShutdownW@20
;InstallApplication
IsTextUnicode@12=NTDLL.RtlIsTextUnicode
-;IsTokenRestricted
+IsTokenRestricted@4
;IsTokenUntrusted
IsValidAcl@4
IsValidSecurityDescriptor@4
IsValidSid@4
-;IsWellKnownSid
+IsWellKnownSid@8
LockServiceDatabase@4
LogonUserA@24
;LogonUserExA
LookupPrivilegeValueW@12
;LookupSecurityDescriptorPartsA@28
;LookupSecurityDescriptorPartsW@28
-;LsaAddAccountRights@16
+LsaAddAccountRights@16
;LsaAddPrivilegesToAccount@8
;LsaClearAuditLog@4
LsaClose@4
;LsaCreateTrustedDomainEx
;LsaDelete@4
;LsaDeleteTrustedDomain@8
-;LsaEnumerateAccountRights@16
+LsaEnumerateAccountRights@16
;LsaEnumerateAccounts@20
-;LsaEnumerateAccountsWithUserRight@16
+LsaEnumerateAccountsWithUserRight@16
;LsaEnumeratePrivileges@20
;LsaEnumeratePrivilegesOfAccount@8
;LsaEnumerateTrustedDomains@20
;LsaLookupPrivilegeDisplayName@16
;LsaLookupPrivilegeName@12
;LsaLookupPrivilegeValue@12
-;LsaLookupSids@20
+LsaLookupSids@20
LsaNtStatusToWinError@4
;LsaOpenAccount@16
LsaOpenPolicy@16
;LsaQuerySecurityObject@12
;LsaQueryTrustedDomainInfo@16
;LsaQueryTrustedDomainInfoByName
-;LsaRemoveAccountRights@20
+LsaRemoveAccountRights@20
;LsaRemovePrivilegesFromAccount@12
LsaRetrievePrivateData@12
-;LsaSetInformationPolicy@12
+LsaSetInformationPolicy@12
;LsaSetForestTrustInformation
;LsaSetInformationPolicy
;LsaSetInformationTrustedDomain@12
;MSChapSrvChangePassword
;MSChapSrvChangePassword2
MakeAbsoluteSD@44
-;MakeAbsoluteSD2
+MakeAbsoluteSD2@8
MakeSelfRelativeSD@12
MapGenericMask@8=NTDLL.RtlMapGenericMask
-;NotifyBootConfigStatus@4
+NotifyBootConfigStatus@4
NotifyChangeEventLog@8
ObjectCloseAuditAlarmA@12
ObjectCloseAuditAlarmW@12
;ProvAccessRightsToNTAccessMask ; ?
;QueryAllTracesA
;QueryAllTracesW
-;QueryRecoveryAgentsOnEncryptedFile
+QueryRecoveryAgentsOnEncryptedFile@8
;QueryServiceConfig2A
;QueryServiceConfig2W
QueryServiceConfigA@16
QueryServiceStatusEx@20
;QueryTraceA
;QueryTraceW
-;QueryUsersOnEncryptedFile
+QueryUsersOnEncryptedFile@8
;QueryWindows31FilesMigration@4
;ReadEncryptedFileRaw
ReadEventLogA@28
RegCloseKey@4
RegConnectRegistryA@12
RegConnectRegistryW@12
+RegCopyTreeA@12
+RegCopyTreeW@12
RegCreateKeyA@12
RegCreateKeyExA@36
RegCreateKeyExW@36
RegCreateKeyW@12
RegDeleteKeyA@8
RegDeleteKeyW@8
+RegDeleteKeyValueA@12
+RegDeleteKeyValueW@12
+RegDeleteTreeA@8
+RegDeleteTreeW@8
RegDeleteValueA@8
RegDeleteValueW@8
;RegDisablePredefinedCache
+RegDisablePredefinedCacheEx@0
RegEnumKeyA@16
RegEnumKeyExA@32
RegEnumKeyExW@32
RegGetKeySecurity@16
RegLoadKeyA@12
RegLoadKeyW@12
+RegLoadMUIStringA@24
+RegLoadMUIStringW@24
RegNotifyChangeKeyValue@20
RegOpenCurrentUser@8
RegOpenKeyA@12
RegOpenKeyExW@20
RegOpenKeyW@12
RegOpenUserClassesRoot@16
-;RegOverridePredefKey
+RegOverridePredefKey@8
RegQueryInfoKeyA@48
RegQueryInfoKeyW@48
RegQueryMultipleValuesA@20
;RegSaveKeyExW
RegSaveKeyW@12
RegSetKeySecurity@12
+RegSetKeyValueA@24
+RegSetKeyValueW@24
RegSetValueA@20
RegSetValueExA@24
RegSetValueExW@24
;RegisterTraceGuidsA
;RegisterTraceGuidsW
;RemoveTraceCallback
-;RemoveUsersFromEncryptedFile
+RemoveUsersFromEncryptedFile@8
ReportEventA@36
ReportEventW@36
RevertToSelf@0
SetAclInformation@16
;SetEntriesInAccessListA
;SetEntriesInAccessListW
-;SetEntriesInAclA@16
-;SetEntriesInAclW@16
+SetEntriesInAclA@16
+SetEntriesInAclW@16
;SetEntriesInAuditListA
;SetEntriesInAuditListW
SetFileSecurityA@12
;SetNamedSecurityInfoExA
;SetNamedSecurityInfoExW
SetNamedSecurityInfoW@28
-;SetPrivateObjectSecurity@20
+SetPrivateObjectSecurity@20
;SetPrivateObjectSecurityEx
SetSecurityDescriptorControl@12
SetSecurityDescriptorDacl@16
;TraceEventInstance
;TraceMessage
;TraceMessageVa
-;TreeResetNamedSecurityInfoA
-;TreeResetNamedSecurityInfoW
+TreeResetNamedSecurityInfoA@44
+TreeResetNamedSecurityInfoW@44
;TrusteeAccessToObjectA
;TrusteeAccessToObjectW
;UninstallApplication