10 ;CcFastReadNotPossible
14 ;CcGetFileObjectFromBcb
15 ;CcGetFileObjectFromSectionPtrs
16 ;CcGetFlushedValidData
17 ;CcGetLsnForFileObject
33 ;CcSetAdditionalCacheAttributes
35 ;CcSetDirtyPageThreshold
38 ;CcSetLogHandleForFile
39 ;CcSetReadAheadGranularity
40 ;CcUninitializeCacheMap
44 ;CcWaitForCurrentLazyWriterActivity
47 CmUnRegisterCallback@4
49 DbgBreakPointWithStatus@4
53 DbgPrintReturnControlC
55 DbgQueryDebugFilterState@8
56 DbgSetDebugFilterState@12
57 @ExAcquireFastMutexUnsafe@4
58 ExAcquireResourceExclusiveLite@8
59 ExAcquireResourceSharedLite@8
60 ;ExAcquireRundownProtection
61 ExAcquireSharedStarveExclusive@8
62 ExAcquireSharedWaitForExclusive@8
63 ExAllocateFromPagedLookasideList@4
65 ExAllocatePoolWithQuota@8
66 ExAllocatePoolWithQuotaTag@12
67 ExAllocatePoolWithTag@12
68 ExAllocatePoolWithTagPriority@16
69 ExConvertExclusiveToSharedLite@4
71 ExDeleteNPagedLookasideList@4
72 ExDeletePagedLookasideList@4
73 ExDeleteResourceLite@4
74 ExDesktopObjectType DATA
75 ;ExDisableResourceBoostLite
77 ExEventObjectType DATA
79 @Exfi386InterlockedDecrementLong@4
80 @Exfi386InterlockedExchangeUlong@8
81 @Exfi386InterlockedIncrementLong@4
82 @ExfInterlockedAddUlong@12
83 @ExfInterlockedInsertHeadList@12
84 @ExfInterlockedInsertTailList@12
85 @ExfInterlockedPopEntryList@8
86 @ExfInterlockedPushEntryList@12
87 @ExfInterlockedRemoveHeadList@8
90 ExFreeToPagedLookasideList@8
91 ;ExGetCurrentProcessorCounts
92 ;ExGetCurrentProcessorCpuUsage
93 ExGetExclusiveWaiterCount@4
95 ExGetSharedWaiterCount@4
96 Exi386InterlockedDecrementLong@4
97 Exi386InterlockedExchangeUlong@8
98 Exi386InterlockedIncrementLong@4
99 ExInitializeNPagedLookasideList@28
100 ExInitializePagedLookasideList@28
101 ExInitializeResourceLite@4
102 ;ExInitializeRundownProtection
104 ExInterlockedAddLargeInteger@12
105 @ExInterlockedAddLargeStatistic@8
106 ExInterlockedAddUlong@12
107 @ExInterlockedCompareExchange64@16
108 ExInterlockedDecrementLong@8
109 ExInterlockedExchangeUlong@12
110 ExInterlockedExtendZone@16
111 @ExInterlockedFlushSList@4
112 @ExInterlockedIncrementLong@8
113 ExInterlockedInsertHeadList@12
114 ExInterlockedInsertTailList@12
115 ExInterlockedPopEntryList@8
116 @ExInterlockedPopEntrySList@8
117 ExInterlockedPushEntryList@12
118 @ExInterlockedPushEntrySList@12
119 ExInterlockedRemoveHeadList@8
120 ExIsProcessorFeaturePresent@4
121 ExIsResourceAcquiredExclusiveLite@4
122 ExIsResourceAcquiredSharedLite@4
123 ExLocalTimeToSystemTime@8
125 ;ExQueryPoolBlockSize
127 ExRaiseAccessViolation@0
128 ExRaiseDatatypeMisalignment@0
132 ;ExReInitializeRundownProtection
133 ExRegisterCallback@12
134 ExReinitializeResourceLite@4
135 @ExReleaseFastMutexUnsafe@4
136 ExReleaseResourceForThreadLite@8
137 @ExReleaseResourceLite@4
138 ;ExReleaseRundownProtection
140 ExSemaphoreObjectType DATA
141 ExSetResourceOwnerPointer@8
142 ExSetTimerResolution@8
143 ;ExSystemExceptionFilter
144 ExSystemTimeToLocalTime@8
145 ExUnregisterCallback@4
148 ;ExWaitForRundownProtectionRelease
149 ExWindowStationObjectType DATA
150 ;FsRtlAcquireFileExclusive
151 ;FsRtlAddLargeMcbEntry
153 ;FsRtlAddToTunnelCache
154 ;FsRtlAllocateFileLock
156 ;FsRtlAllocatePoolWithQuota
157 ;FsRtlAllocatePoolWithQuotaTag
158 ;FsRtlAllocatePoolWithTag
159 ;FsRtlAllocateResource
162 ;FsRtlCheckLockForReadAccess
163 ;FsRtlCheckLockForWriteAccess
167 ;FsRtlCurrentBatchOplock
168 ;FsRtlDeleteKeyFromTunnelCache
169 ;FsRtlDeleteTunnelCache
170 ;FsRtlDeregisterUncProvider
173 ;FsRtlDoesDbcsContainWildCards
174 ;FsRtlDoesNameContainWildCards
175 ;FsRtlFastCheckLockForRead
176 ;FsRtlFastCheckLockForWrite
178 ;FsRtlFastUnlockAllByKey
179 ;FsRtlFastUnlockSingle
180 ;FsRtlFindInTunnelCache
183 ;FsRtlGetNextFileLock
184 ;FsRtlGetNextLargeMcbEntry
185 ;FsRtlGetNextMcbEntry
186 ;FsRtlIncrementCcFastReadNoWait
187 ;FsRtlIncrementCcFastReadNotPossible
188 ;FsRtlIncrementCcFastReadResourceMiss
189 ;FsRtlIncrementCcFastReadWait
190 ;FsRtlInitializeFileLock
191 ;FsRtlInitializeLargeMcb
193 ;FsRtlInitializeOplock
194 ;FsRtlInitializeTunnelCache
195 ;FsRtlInsertPerFileObjectContext
196 ;FsRtlInsertPerStreamContext
197 ;FsRtlIsDbcsInExpression
199 ;FsRtlIsHpfsDbcsLegal
200 ;FsRtlIsNameInExpression
201 ;FsRtlIsNtstatusExpected
203 FsRtlIsTotalDeviceFailure@4
204 ;FsRtlLegalAnsiCharacterArray
205 ;FsRtlLookupLargeMcbEntry
206 ;FsRtlLookupLastLargeMcbEntry
207 ;FsRtlLookupLastLargeMcbEntryAndIndex
208 ;FsRtlLookupLastMcbEntry
210 ;FsRtlLookupPerFileObjectContext
211 ;FsRtlLookupPerStreamContextInternal
213 ;FsRtlMdlReadComplete
214 ;FsRtlMdlReadCompleteDev
216 ;FsRtlMdlWriteComplete
217 ;FsRtlMdlWriteCompleteDev
218 ;FsRtlNormalizeNtstatus
219 ;FsRtlNotifyChangeDirectory
221 ;FsRtlNotifyFilterChangeDirectory
222 ;FsRtlNotifyFilterReportChange
223 ;FsRtlNotifyFullChangeDirectory
224 ;FsRtlNotifyFullReportChange
225 ;FsRtlNotifyInitializeSync
226 ;FsRtlNotifyReportChange
227 ;FsRtlNotifyUninitializeSync
228 ;FsRtlNotifyVolumeEvent
229 ;FsRtlNumberOfRunsInLargeMcb
230 ;FsRtlNumberOfRunsInMcb
232 ;FsRtlOplockIsFastIoPossible
233 ;FsRtlPostPagingFileStackOverflow
234 ;FsRtlPostStackOverflow
235 ;FsRtlPrepareMdlWrite
236 ;FsRtlPrepareMdlWriteDev
238 ;FsRtlProcessFileLock
239 ;FsRtlRegisterFileSystemFilterCallbacks
240 ;FsRtlRegisterUncProvider
242 ;FsRtlRemoveLargeMcbEntry
244 ;FsRtlRemovePerFileObjectContext
245 ;FsRtlRemovePerStreamContext
249 ;FsRtlTeardownPerStreamContexts
250 ;FsRtlTruncateLargeMcb
252 ;FsRtlUninitializeFileLock
253 ;FsRtlUninitializeLargeMcb
254 ;FsRtlUninitializeMcb
255 ;FsRtlUninitializeOplock
256 ;HalDispatchTable DATA
258 ;HalPrivateDispatchTable DATA
260 ;InbvAcquireDisplayOwnership
261 ;InbvCheckDisplayOwnership
263 ;InbvEnableBootDriver
264 ;InbvEnableDisplayString
265 ;InbvInstallDisplayStringFilter
266 ;InbvIsBootDriverInstalled
267 ;InbvNotifyDisplayOwnershipLost
272 ;InitSafeBootMode DATA
273 @InterlockedCompareExchange@12
274 @InterlockedDecrement@4
275 @InterlockedExchange@8
276 @InterlockedExchangeAdd@8
277 @InterlockedIncrement@4
278 @InterlockedPopEntrySList@4
279 @InterlockedPushEntrySList@8
280 IoAcquireCancelSpinLock@4
281 IoAcquireRemoveLockEx@20
282 ;IoAcquireVpbSpinLock
283 IoAdapterObjectType DATA
284 IoAllocateAdapterChannel@20
285 IoAllocateController@16
286 IoAllocateDriverObjectExtension@16
287 IoAllocateErrorLogEntry@8
291 ;IoAssignDriveLetters
294 IoAttachDeviceByPointer@8
295 IoAttachDeviceToDeviceStack@8
296 ;IoAttachDeviceToDeviceStackSafe
297 IoBuildAsynchronousFsdRequest@24
298 IoBuildDeviceIoControlRequest@36
300 IoBuildSynchronousFsdRequest@28
304 ;IoCheckDesiredAccess
305 ;IoCheckEaBufferValidity
306 ;IoCheckFunctionAccess
307 ;IoCheckQuerySetFileInformation
308 ;IoCheckQuerySetVolumeInformation
309 ;IoCheckQuotaBufferValidity
310 IoCheckShareAccess@20
312 IoConnectInterrupt@44
318 ;IoCreateFileSpecifyDeviceObjectHint
319 IoCreateNotificationEvent@8
320 ;IoCreateStreamFileObject
321 ;IoCreateStreamFileObjectEx
322 ;IoCreateStreamFileObjectLite
323 IoCreateSymbolicLink@8
324 IoCreateSynchronizationEvent@8
325 IoCreateUnprotectedSymbolicLink@8
333 IoDeleteSymbolicLink@4
335 IoDeviceHandlerObjectSize DATA
336 IoDeviceHandlerObjectType DATA
337 IoDeviceObjectType DATA
338 IoDisconnectInterrupt@4
339 IoDriverObjectType DATA
341 ;IoEnumerateDeviceObjectList
342 ;IoFastQueryNetworkAttributes
343 IoFileObjectType DATA
344 ;IoForwardAndCatchIrp
345 IoForwardIrpSynchronously@8
347 IoFreeErrorLogEntry@4
351 IoGetAttachedDevice@4
352 IoGetAttachedDeviceReference@4
353 ;IoGetBaseFileSystemDeviceObject
354 IoGetBootDiskInformation@8
355 IoGetConfigurationInformation@0
356 IoGetCurrentProcess@0
357 ;IoGetDeviceAttachmentBaseRef
358 IoGetDeviceInterfaceAlias@12
359 IoGetDeviceInterfaces@16
360 IoGetDeviceObjectPointer@16
361 IoGetDeviceProperty@20
362 IoGetDeviceToVerify@4
363 ;IoGetDiskDeviceObject
365 IoGetDriverObjectExtension@8
366 IoGetFileObjectGenericMapping@0
368 ;IoGetLowerDeviceObject
369 IoGetRelatedDeviceObject@4
370 ;IoGetRequestorProcess
371 ;IoGetRequestorProcessId
372 ;IoGetRequestorSessionId
376 IoInitializeRemoveLockEx@20
378 IoInvalidateDeviceRelations@8
379 IoInvalidateDeviceState@4
380 ;IoIsFileOriginRemote
381 ;IoIsOperationSynchronous
383 ;IoIsValidNameGraftingBuffer
384 IoIsWdmVersionAvailable@8
385 IoMakeAssociatedIrp@8
386 IoOpenDeviceInterfaceRegistryKey@12
387 IoOpenDeviceRegistryKey@16
389 ;IoPnPDeliverServicePowerNotification
390 IoQueryDeviceDescription@32
391 ;IoQueryFileDosDeviceName
392 ;IoQueryFileInformation
393 ;IoQueryVolumeInformation
397 IoRaiseInformationalHardError@12
398 IoReadDiskSignature@12
399 ;IoReadOperationCount DATA
400 @IoReadPartitionTable@16
401 IoReadPartitionTableEx@8
402 ;IoReadTransferCount DATA
403 IoRegisterBootDriverReinitialization@12
404 IoRegisterDeviceInterface@16
405 IoRegisterDriverReinitialization@12
406 ;IoRegisterFileSystem
407 ;IoRegisterFsRegistrationChange
408 ;IoRegisterLastChanceShutdownNotification
409 IoRegisterPlugPlayNotification@28
410 IoRegisterShutdownNotification@4
411 IoReleaseCancelSpinLock@4
412 IoReleaseRemoveLockAndWaitEx@12
413 IoReleaseRemoveLockEx@12
414 ;IoReleaseVpbSpinLock
415 IoRemoveShareAccess@8
416 IoReportDetectedDevice@32
417 ;IoReportHalResourceUsage
418 IoReportResourceForDetection@28
419 IoReportResourceUsage@36
420 IoReportTargetDeviceChange@8
421 IoReportTargetDeviceChangeAsynchronous@16
422 IoRequestDeviceEject@4
424 IoSetCompletionRoutineEx@28
425 IoSetDeviceInterfaceState@8
428 IoSetHardErrorOrVerifyDevice@8
431 @IoSetPartitionInformation@16
432 IoSetPartitionInformationEx@12
434 IoSetStartIoAttributes@12
435 IoSetSystemPartition@4
436 IoSetThreadHardErrorMode@4
439 IoStartNextPacketByKey@12
442 ;IoStatisticsLock DATA
444 ;IoSynchronousInvalidateDeviceRelations
445 ;IoSynchronousPageWrite
447 ;IoUnregisterFileSystem
448 ;IoUnregisterFsRegistrationChange
449 IoUnregisterPlugPlayNotification@4
450 IoUnregisterShutdownNotification@4
451 IoUpdateShareAccess@8
452 IoVerifyPartitionTable@8
454 IoVolumeDeviceToDosName@8
455 IoWMIAllocateInstanceIds@12
456 IoWMIDeviceObjectToInstanceName@12
457 IoWMIExecuteMethod@24
458 IoWMIHandleToInstanceName@12
461 IoWMIQueryAllDataMultiple@16
462 IoWMIQuerySingleInstance@16
463 IoWMIQuerySingleInstanceMultiple@20
464 IoWMIRegistrationControl@8
465 IoWMISetNotificationCallback@12
466 IoWMISetSingleInstance@20
467 IoWMISetSingleItem@24
468 IoWMISuggestInstanceName@16
470 IoWriteErrorLogEntry@4
471 ;IoWriteOperationCount DATA
472 @IoWritePartitionTable@20
473 IoWritePartitionTableEx@8
474 ;IoWriteTransferCount DATA
476 @IofCompleteRequest@8
477 ;KdDebuggerEnabled DATA
478 ;KdDebuggerNotPresent DATA
481 ;KdEnteredDebugger DATA
485 Ke386IoSetAccessProcess@8
486 Ke386QueryIoAccessMap@8
487 Ke386SetIoAccessMap@8
488 @KeAcquireInStackQueuedSpinLockAtDpcLevel@8
489 KeAcquireInterruptSpinLock@4
490 ;KeAcquireSpinLockAtDpcLevel
491 KeAddSystemServiceTable@20
499 ;KeDcacheFlushCount DATA
500 KeDelayExecutionThread@12
501 KeDeregisterBugCheckCallback@4
503 ;KeDisconnectInterrupt
504 KeEnterCriticalRegion@0
505 ;KeEnterKernelDebugger
506 ;KeFindConfigurationEntry
507 ;KeFindConfigurationNextEntry
512 KeGetRecommendedSharedDataAlignment@0
514 ;KeI386AllocateGdtSelectors
515 ;KeI386Call16BitCStyleFunction
516 ;KeI386Call16BitFunction
517 ;KeI386FlatToGdtSelector
519 ;KeI386MachineType DATA
520 ;KeI386ReleaseGdtSelectors
522 ;KeI386SetGdtSelector
523 ;KeIcacheFlushCount DATA
525 KeInitializeDeviceQueue@4
528 ;KeInitializeInterrupt
532 KeInitializeSemaphore@12
533 KeInitializeSpinLock@4
535 KeInitializeTimerEx@8
536 KeInsertByKeyDeviceQueue@12
537 KeInsertDeviceQueue@8
544 KeLeaveCriticalRegion@0
546 KeNumberProcessors DATA
548 ;KeProfileInterruptWithSource
550 KeQueryActiveProcessors@0
551 KeQueryActiveProcessorCount@4
552 KeQueryInterruptTime@0
553 KeQueryPriorityThread@4
554 ;KeQueryRuntimeThread
557 KeQueryTimeIncrement@0
558 ;KeRaiseUserException
563 KeReadStateSemaphore@4
565 KeRegisterBugCheckCallback@20
566 KeReleaseInStackQueuedSpinLockFromDpcLevel@4
567 KeReleaseInterruptSpinLock@8
570 KeReleaseSemaphore@16
571 ;KeReleaseSpinLockFromDpcLevel
572 KeRemoveByKeyDeviceQueue@8
573 ;KeRemoveByKeyDeviceQueueIfBusy
574 KeRemoveDeviceQueue@4
575 KeRemoveEntryDeviceQueue@8
578 ;KeRemoveSystemServiceTable
580 KeRestoreFloatingPointState@4
581 ;KeRevertToUserAffinityThread
583 KeSaveFloatingPointState@4
584 ;KeSaveStateForHibernate
585 ;KeServiceDescriptorTable DATA
587 KeSetBasePriorityThread@8
590 ;KeSetEventBoostPriority
591 ;KeSetIdealProcessorThread
593 ;KeSetKernelStackSwapEnable
594 KeSetPriorityThread@8
596 ;KeSetSystemAffinityThread
597 KeSetTargetProcessorDpc@8
599 @KeSetTimeUpdateNotifyRoutine@4
602 ;KeStackAttachProcess
603 KeSynchronizeExecution@12
606 ;KeUnstackDetachProcess
610 KeWaitForMultipleObjects@32
611 KeWaitForMutexObject@20
612 KeWaitForSingleObject@20
613 @KefAcquireSpinLockAtDpcLevel@4
614 @KefReleaseSpinLockFromDpcLevel@4
621 ;KiEnableTimerWatchdog DATA
624 ;KiUnexpectedInterrupt
625 ;Kii386SpinOnSpinLock
628 ;LdrFindResourceDirectory_U
630 LpcPortObjectType DATA
632 ;LpcRequestWaitReplyPort
633 ;LsaCallAuthenticationPackage
634 ;LsaDeregisterLogonProcess
637 ;LsaLookupAuthenticationPackage
638 ;LsaRegisterLogonProcess
639 ;Mm64BitPhysicalAddress DATA
642 ;MmAdjustWorkingSetSize
644 MmAllocateContiguousMemory@12
645 MmAllocateContiguousMemorySpecifyCache@20
646 MmAllocateMappingAddress@8
647 MmAllocateNonCachedMemory@4
648 MmAllocatePagesForMdl@28
649 MmBuildMdlForNonPagedPool@4
650 ;MmCanFileBeTruncated
653 ;MmDisableModifiedWriteOfSection
654 MmFlushImageSection@8
655 ;MmForceSectionClosed
656 MmFreeContiguousMemory@4
657 MmFreeContiguousMemorySpecifyCache@12
658 MmFreeMappingAddress@8
659 MmFreeNonCachedMemory@8
661 MmGetPhysicalAddress@4
662 MmGetPhysicalMemoryRanges@0
663 MmGetSystemRoutineAddress@4
664 MmGetVirtualForPhysical@4
666 ;MmHighestUserAddress DATA
668 MmIsDriverVerifying@4
669 MmIsNonPagedSystemAddressValid@4
670 ;MmIsRecursiveIoFault
671 MmIsThisAnNtAsSystem@0
672 MmIsVerifierEnabled@4
673 MmLockPagableDataSection@4
674 MmLockPagableImageSection@4
675 MmLockPagableSectionByHandle@4
678 MmMapLockedPagesSpecifyCache@24
679 MmMapLockedPagesWithReservedMapping@16
681 MmMapUserAddressesToPage@12
683 MmMapViewInSessionSpace@12
684 MmMapViewInSystemSpace@12
686 MmMarkPhysicalMemoryAsBad@8
687 MmMarkPhysicalMemoryAsGood@8
690 MmProbeAndLockPages@12
691 MmProbeAndLockProcessPages@16
692 ;MmProbeAndLockSelectedPages
693 MmProtectMdlSystemAddress@8
695 MmRemovePhysicalMemory@8
696 MmResetDriverPaging@4
697 MmSectionObjectType DATA
698 MmSecureVirtualMemory@12
699 ;MmSetAddressRangeModified
702 ;MmSystemRangeStart DATA
703 ;MmTrimAllSystemPagableMemory
704 MmUnlockPagableImageSection@4
708 MmUnmapReservedMapping@12
709 MmUnmapVideoDisplay@8
710 MmUnmapViewInSessionSpace@4
711 MmUnmapViewInSystemSpace@4
712 ;MmUnmapViewOfSection
713 MmUnsecureVirtualMemory@4
714 ;MmUserProbeAddress DATA
715 ;NlsAnsiCodePage DATA
717 ;NlsMbCodePageTag DATA
718 ;NlsMbOemCodePageTag DATA
722 NtAdjustPrivilegesToken@24
723 NtAllocateLocallyUniqueId@4
725 NtAllocateVirtualMemory@24
734 NtDeviceIoControlFile@40
738 NtFreeVirtualMemory@16
742 ;NtMakePermanentObject
743 NtMapViewOfSection@40
744 ;NtNotifyChangeDirectoryFile
747 NtOpenProcessToken@12
748 ;NtOpenProcessTokenEx
752 ;NtQueryDirectoryFile
754 NtQueryInformationAtom@20
755 ;NtQueryInformationFile
756 NtQueryInformationProcess@20
757 NtQueryInformationThread@20
758 NtQueryInformationToken@20
759 ;NtQueryQuotaInformationFile
760 NtQuerySecurityObject@20
761 NtQuerySystemInformation@16
762 ;NtQueryVolumeInformationFile
765 NtRequestWaitReplyPort@12
768 ;NtSetInformationFile
769 NtSetInformationProcess@16
770 NtSetInformationThread@16
771 ;NtSetQuotaInformationFile
772 NtSetSecurityObject@12
773 ;NtSetVolumeInformationFile
778 NtWaitForSingleObject@12
781 ;ObCheckCreateObjectAccess
787 ObDereferenceSecurityDescriptor@8
788 ;ObFindHandleForObject
789 ObGetObjectSecurity@12
791 ObLogSecurityDescriptor@12
792 ObMakeTemporaryObject@4
793 ObOpenObjectByName@28
794 ObOpenObjectByPointer@28
796 ObQueryObjectAuditingByHandle@8
797 ObReferenceObjectByHandle@24
798 ObReferenceObjectByName@32
799 ObReferenceObjectByPointer@16
800 ObReferenceSecurityDescriptor@8
801 ObReleaseObjectSecurity@8
802 ;ObSetHandleAttributes
803 ;ObSetSecurityDescriptorInfo
804 ;ObSetSecurityObjectByPointer
805 @ObfDereferenceObject@4
806 @ObfReferenceObject@4
812 ;PoCancelDeviceNotify
813 ;PoQueueShutdownWorkItem
814 PoRegisterDeviceForIdleDetection@16
815 ;PoRegisterDeviceNotify
816 PoRegisterSystemState@8
818 PoRequestShutdownEvent@4
823 PoStartNextPowerIrp@4
824 PoUnregisterSystemState@4
827 ;PsAssignImpersonationToken
829 ;PsChargeProcessNonPagedPoolQuota
830 ;PsChargeProcessPagedPoolQuota
831 ;PsChargeProcessPoolQuota
832 PsCreateSystemProcess@12
833 PsCreateSystemThread@28
834 ;PsDereferenceImpersonationToken
835 ;PsDereferencePrimaryToken
836 ;PsDisableImpersonation
837 ;PsEstablishWin32Callouts
839 PsGetCurrentProcessId@0
840 ;PsGetCurrentProcessSessionId
842 PsGetCurrentThreadId@0
843 ;PsGetCurrentThreadPreviousMode
844 ;PsGetCurrentThreadStackBase
845 ;PsGetCurrentThreadStackLimit
848 ;PsGetJobUIRestrictionsClass
849 ;PsGetProcessCreateTimeQuadPart
850 ;PsGetProcessDebugPort
851 ;PsGetProcessExitProcessCalled
852 ;PsGetProcessExitStatus
853 ;PsGetProcessExitTime
855 ;PsGetProcessImageFileName
856 ;PsGetProcessInheritedFromUniqueProcessId
859 ;PsGetProcessPriorityClass
860 ;PsGetProcessSectionBaseAddress
861 ;PsGetProcessSecurityPort
862 ;PsGetProcessSessionId
863 ;PsGetProcessWin32Process
864 ;PsGetProcessWin32WindowStation
865 ;PsGetThreadFreezeCount
866 ;PsGetThreadHardErrorsAreDisabled
869 ;PsGetThreadProcessId
870 ;PsGetThreadSessionId
872 ;PsGetThreadWin32Thread
875 ;PsInitialSystemProcess DATA
876 ;PsIsProcessBeingDebugged
878 ;PsIsThreadImpersonating
879 ;PsIsThreadTerminating
881 ;PsLookupProcessByProcessId
882 ;PsLookupProcessThreadByCid
883 ;PsLookupThreadByThreadId
885 ;PsReferenceImpersonationToken
886 ;PsReferencePrimaryToken
887 PsRemoveCreateThreadNotifyRoutine@4
888 PsRemoveLoadImageNotifyRoutine@4
889 ;PsRestoreImpersonation
891 ;PsReturnProcessNonPagedPoolQuota
892 ;PsReturnProcessPagedPoolQuota
893 ;PsRevertThreadToSelf
895 PsSetCreateProcessNotifyRoutine@8
896 PsSetCreateThreadNotifyRoutine@4
897 ;PsSetJobUIRestrictionsClass
898 ;PsSetLegoNotifyRoutine
899 PsSetLoadImageNotifyRoutine@4
900 ;PsSetProcessPriorityByClass
901 ;PsSetProcessPriorityClass
902 ;PsSetProcessSecurityPort
903 ;PsSetProcessWin32Process
904 ;PsSetProcessWindowStation
905 ;PsSetThreadHardErrorsAreDisabled
906 ;PsSetThreadWin32Thread
907 PsTerminateSystemThread@4
909 READ_REGISTER_BUFFER_UCHAR@12
910 READ_REGISTER_BUFFER_ULONG@12
911 READ_REGISTER_BUFFER_USHORT@12
912 READ_REGISTER_UCHAR@4
913 READ_REGISTER_ULONG@4
914 READ_REGISTER_USHORT@4
915 ;RtlAbsoluteToSelfRelativeSD
916 ;RtlAddAccessAllowedAce
918 ;RtlAddAtomToAtomTable
921 ;RtlAnsiCharToUnicodeChar
922 RtlAnsiStringToUnicodeSize@4
923 RtlAnsiStringToUnicodeString@12
924 ;RtlAppendAsciizToString
925 ;RtlAppendStringToString
926 RtlAppendUnicodeStringToString@8
927 RtlAppendUnicodeToString@8
928 ;RtlAreAllAccessesGranted
929 ;RtlAreAnyAccessesGranted
934 ;RtlCaptureStackBackTrace
936 RtlCheckRegistryKey@8
941 ;RtlCompareMemoryUlong
943 RtlCompareUnicodeString@12
946 RtlConvertLongToLargeInteger@4
947 ;RtlConvertSidToUnicodeString
948 RtlConvertUlongToLargeInteger@4
953 RtlCopyUnicodeString@8
957 RtlCreateRegistryKey@8
958 RtlCreateSecurityDescriptor@8
959 ;RtlCreateSystemVolumeInformationFolder
960 ;RtlCreateUnicodeString
961 ;RtlCustomCPToUnicodeN
964 ;RtlDecompressFragment
967 ;RtlDeleteAtomFromAtomTable
968 ;RtlDeleteElementGenericTable
969 ;RtlDeleteElementGenericTableAvl
971 RtlDeleteOwnersRanges@8
973 RtlDeleteRegistryValue@12
977 ;RtlDowncaseUnicodeString
979 RtlEnlargedIntegerMultiply@8
980 RtlEnlargedUnsignedDivide@12
981 RtlEnlargedUnsignedMultiply@8
982 ;RtlEnumerateGenericTable
983 ;RtlEnumerateGenericTableAvl
984 ;RtlEnumerateGenericTableLikeADirectory
985 ;RtlEnumerateGenericTableWithoutSplaying
986 ;RtlEnumerateGenericTableWithoutSplayingAvl
990 RtlEqualUnicodeString@12
991 RtlExtendedIntegerMultiply@8
992 RtlExtendedLargeIntegerDivide@12
993 RtlExtendedMagicDivide@12
997 RtlFindClearBitsAndSet@12
999 RtlFindFirstRunClear@8
1000 RtlFindLastBackwardRunClear@12
1001 RtlFindLeastSignificantBit@4
1002 RtlFindLongestRunClear@8
1004 RtlFindMostSignificantBit@4
1005 RtlFindNextForwardRunClear@12
1008 RtlFindSetBitsAndClear@12
1009 ;RtlFindUnicodePrefix
1010 ;RtlFormatCurrentUserKeyPath
1015 RtlFreeUnicodeString@4
1017 ;RtlGenerate8dot3Name
1019 RtlGetCallersAddress@8
1020 ;RtlGetCompressionWorkSpaceSize
1021 ;RtlGetDaclSecurityDescriptor
1022 ;RtlGetDefaultCodePage
1023 ;RtlGetElementGenericTable
1024 ;RtlGetElementGenericTableAvl
1026 ;RtlGetGroupSecurityDescriptor
1028 ;RtlGetNtGlobalFlags
1029 ;RtlGetOwnerSecurityDescriptor
1030 ;RtlGetSaclSecurityDescriptor
1031 ;RtlGetSetBootStatusData
1033 RtlHashUnicodeString@16
1034 ;RtlImageDirectoryEntryToData
1037 ;RtlInitCodePageTable
1039 RtlInitUnicodeString@8
1040 RtlInitializeBitMap@12
1041 ;RtlInitializeGenericTable
1042 ;RtlInitializeGenericTableAvl
1043 RtlInitializeRangeList@4
1045 ;RtlInitializeUnicodePrefix
1046 ;RtlInsertElementGenericTable
1047 ;RtlInsertElementGenericTableAvl
1048 ;RtlInsertElementGenericTableFull
1049 ;RtlInsertElementGenericTableFullAvl
1050 ;RtlInsertUnicodePrefix
1051 RtlInt64ToUnicodeString@12
1053 ;RtlIntegerToUnicode
1054 RtlIntegerToUnicodeString@12
1055 RtlInvertRangeList@8
1056 ;RtlIpv4AddressToStringA
1057 ;RtlIpv4AddressToStringW
1058 ;RtlIpv4StringToAddressA
1059 ;RtlIpv4StringToAddressW
1060 ;RtlIpv6AddressToStringA
1061 ;RtlIpv6AddressToStringW
1062 ;RtlIpv6StringToAddressA
1063 ;RtlIpv6StringToAddressW
1064 ;RtlIsGenericTableEmpty
1065 ;RtlIsGenericTableEmptyAvl
1066 ;RtlIsNameLegalDOS8Dot3
1067 RtlIsRangeAvailable@32
1068 ;RtlIsValidOemCharacter
1069 RtlLargeIntegerAdd@8
1070 RtlLargeIntegerArithmeticShift@8
1071 RtlLargeIntegerDivide@12
1072 RtlLargeIntegerNegate@4
1073 RtlLargeIntegerShiftLeft@8
1074 RtlLargeIntegerShiftRight@8
1075 RtlLargeIntegerSubtract@8
1076 ;RtlLengthRequiredSid
1077 RtlLengthSecurityDescriptor@4
1079 ;RtlLockBootStatusData
1080 ;RtlLookupAtomInAtomTable
1081 ;RtlLookupElementGenericTable
1082 ;RtlLookupElementGenericTableAvl
1083 ;RtlLookupElementGenericTableFull
1084 ;RtlLookupElementGenericTableFullAvl
1086 ;RtlMapSecurityErrorToNtStatus
1087 RtlMergeRangeLists@16
1089 ;RtlMultiByteToUnicodeN
1090 ;RtlMultiByteToUnicodeSize
1091 ;RtlNextUnicodePrefix
1092 ;RtlNtStatusToDosError
1093 ;RtlNtStatusToDosErrorNoTeb
1094 ;RtlNumberGenericTableElements
1095 ;RtlNumberGenericTableElementsAvl
1096 RtlNumberOfClearBits@4
1097 RtlNumberOfSetBits@4
1098 ;RtlOemStringToCountedUnicodeString
1099 ;RtlOemStringToUnicodeSize
1100 ;RtlOemStringToUnicodeString
1102 ;RtlPinAtomInAtomTable
1103 @RtlPrefetchMemoryNonTemporal@8
1105 RtlPrefixUnicodeString@12
1106 ;RtlQueryAtomInAtomTable
1107 RtlQueryRegistryValues@20
1108 ;RtlQueryTimeZoneInformation
1114 ;RtlRemoveUnicodePrefix
1116 ;RtlSecondsSince1970ToTime
1117 ;RtlSecondsSince1980ToTime
1118 ;RtlSelfRelativeToAbsoluteSD
1119 ;RtlSelfRelativeToAbsoluteSD2
1123 RtlSetDaclSecurityDescriptor@16
1124 ;RtlSetGroupSecurityDescriptor
1125 ;RtlSetOwnerSecurityDescriptor
1126 ;RtlSetSaclSecurityDescriptor
1127 ;RtlSetTimeZoneInformation
1131 ;RtlSubAuthorityCountSid
1133 ;RtlSubtreePredecessor
1134 ;RtlSubtreeSuccessor
1136 RtlTimeFieldsToTime@8
1137 ;RtlTimeToElapsedTimeFields
1138 ;RtlTimeToSecondsSince1970
1139 ;RtlTimeToSecondsSince1980
1140 RtlTimeToTimeFields@8
1141 ;RtlTraceDatabaseAdd
1142 ;RtlTraceDatabaseCreate
1143 ;RtlTraceDatabaseDestroy
1144 ;RtlTraceDatabaseEnumerate
1145 ;RtlTraceDatabaseFind
1146 ;RtlTraceDatabaseLock
1147 ;RtlTraceDatabaseUnlock
1148 ;RtlTraceDatabaseValidate
1150 @RtlUlonglongByteSwap@4
1151 RtlUnicodeStringToAnsiSize@4
1152 RtlUnicodeStringToAnsiString@12
1153 ;RtlUnicodeStringToCountedOemString
1154 RtlUnicodeStringToInteger@12
1155 ;RtlUnicodeStringToOemSize
1156 ;RtlUnicodeStringToOemString
1157 ;RtlUnicodeToCustomCPN
1158 ;RtlUnicodeToMultiByteN
1159 ;RtlUnicodeToMultiByteSize
1161 ;RtlUnlockBootStatusData
1163 RtlUpcaseUnicodeChar@4
1164 RtlUpcaseUnicodeString@12
1165 ;RtlUpcaseUnicodeStringToAnsiString
1166 ;RtlUpcaseUnicodeStringToCountedOemString
1167 ;RtlUpcaseUnicodeStringToOemString
1168 ;RtlUpcaseUnicodeToCustomCPN
1169 ;RtlUpcaseUnicodeToMultiByteN
1170 ;RtlUpcaseUnicodeToOemN
1174 RtlValidRelativeSecurityDescriptor@12
1175 RtlValidSecurityDescriptor@4
1177 RtlVerifyVersionInfo@12
1178 RtlVolumeDeviceToDosName@8
1179 RtlWalkFrameChain@12
1180 RtlWriteRegistryValue@24
1183 ;RtlxAnsiStringToUnicodeSize
1184 ;RtlxOemStringToUnicodeSize
1185 RtlxUnicodeStringToAnsiSize@4
1186 ;RtlxUnicodeStringToOemSize
1190 SeAssignSecurityEx@36
1191 ;SeAuditHardLinkCreation
1192 ;SeAuditingFileEvents
1193 ;SeAuditingFileOrGlobalEvents
1194 ;SeAuditingHardLinkEvents
1195 ;SeCaptureSecurityDescriptor
1196 ;SeCaptureSubjectContext
1197 ;SeCloseObjectAuditAlarm
1198 ;SeCreateAccessState
1199 ;SeCreateClientSecurity
1200 ;SeCreateClientSecurityFromSubjectContext
1201 SeDeassignSecurity@4
1202 ;SeDeleteAccessState
1203 ;SeDeleteObjectAuditAlarm
1207 ;SeImpersonateClient
1208 ;SeImpersonateClientEx
1209 ;SeLockSubjectContext
1210 ;SeMarkLogonSessionForTerminationNotification
1211 ;SeOpenObjectAuditAlarm
1212 ;SeOpenObjectForDeleteAuditAlarm
1214 ;SePrivilegeObjectAuditAlarm
1215 ;SePublicDefaultDacl DATA
1216 ;SeQueryAuthenticationIdToken
1217 ;SeQueryInformationToken
1218 ;SeQuerySecurityDescriptorInfo
1219 ;SeQuerySessionIdToken
1220 ;SeRegisterLogonSessionTerminatedRoutine
1221 ;SeReleaseSecurityDescriptor
1222 ;SeReleaseSubjectContext
1223 ;SeSetAccessStateGenericMapping
1224 ;SeSetSecurityDescriptorInfo
1225 ;SeSetSecurityDescriptorInfoEx
1226 SeSinglePrivilegeCheck@8
1227 ;SeSystemDefaultDacl DATA
1228 ;SeTokenImpersonationLevel
1230 ;SeTokenIsRestricted
1231 SeTokenObjectType DATA
1233 ;SeUnlockSubjectContext
1234 ;SeUnregisterLogonSessionTerminatedRoutine
1235 SeValidSecurityDescriptor@8
1236 VerSetConditionMask@16
1240 ;VfIsVerificationEnabled
1241 WRITE_REGISTER_BUFFER_UCHAR@12
1242 WRITE_REGISTER_BUFFER_ULONG@12
1243 WRITE_REGISTER_BUFFER_USHORT@12
1244 WRITE_REGISTER_UCHAR@8
1245 WRITE_REGISTER_ULONG@8
1246 WRITE_REGISTER_USHORT@8
1250 WmiQueryTraceInformation@20
1257 ZwAccessCheckAndAuditAlarm@44
1259 ZwAdjustPrivilegesToken@24
1261 ZwAllocateVirtualMemory@24
1262 ZwAssignProcessToJobObject@8
1267 ZwCloseObjectAuditAlarm@12
1269 ZwCreateDirectoryObject@12
1272 ZwCreateJobObject@12
1275 ZwCreateSymbolicLinkObject@16
1281 ZwDeviceIoControlFile@40
1283 ZwDuplicateObject@28
1285 ;ZwEnumerateBootEntries
1287 ZwEnumerateValueKey@24
1288 ZwFlushInstructionCache@12
1290 ZwFlushVirtualMemory@16
1291 ZwFreeVirtualMemory@16
1293 ZwInitiatePowerAction@16
1297 ZwMakeTemporaryObject@4
1298 ZwMapViewOfSection@40
1299 ZwNotifyChangeKey@40
1300 ZwOpenDirectoryObject@12
1306 ZwOpenProcessToken@12
1307 ;ZwOpenProcessTokenEx
1309 ZwOpenSymbolicLinkObject@12
1311 ZwOpenThreadToken@16
1312 ;ZwOpenThreadTokenEx
1314 ZwPowerInformation@20
1316 ;ZwQueryBootEntryOrder
1318 ZwQueryDefaultLocale@8
1319 ZwQueryDefaultUILanguage@4
1320 ZwQueryDirectoryFile@44
1321 ZwQueryDirectoryObject@28
1323 ZwQueryFullAttributesFile@8
1324 ZwQueryInformationFile@20
1325 ZwQueryInformationJobObject@20
1326 ZwQueryInformationProcess@20
1327 ZwQueryInformationThread@20
1328 ZwQueryInformationToken@20
1329 ZwQueryInstallUILanguage@4
1333 ZwQuerySecurityObject@20
1334 ZwQuerySymbolicLinkObject@12
1335 ZwQuerySystemInformation@16
1337 ZwQueryVolumeInformationFile@20
1340 ZwRequestWaitReplyPort@12
1345 ;ZwSetBootEntryOrder
1347 ZwSetDefaultLocale@8
1348 ZwSetDefaultUILanguage@4
1351 ZwSetInformationFile@20
1352 ZwSetInformationJobObject@16
1353 ZwSetInformationObject@16
1354 ZwSetInformationProcess@16
1355 ZwSetInformationThread@16
1356 ZwSetSecurityObject@12
1357 ZwSetSystemInformation@12
1361 ;ZwSetVolumeInformationFile
1362 ZwTerminateJobObject@8
1363 ZwTerminateProcess@8
1364 ;ZwTranslateFilePath
1367 ZwUnmapViewOfSection@8
1368 ;ZwWaitForMultipleObjects
1369 ZwWaitForSingleObject@12
1375 ;_abnormal_termination
1446 ;vDbgPrintExWithPrefix