CC326262 = WriteEncryptedFileRaw EE5F8AA9 = WmiSetSingleItemW EE5F8ABF = WmiSetSingleItemA F30952B6 = WmiSetSingleInstanceW F30952A0 = WmiSetSingleInstanceA C7666583 = WmiReceiveNotificationsW C7666595 = WmiReceiveNotificationsA B775AF30 = WmiQuerySingleInstanceW B447F4DE = WmiQuerySingleInstanceMultipleW B447F4C8 = WmiQuerySingleInstanceMultipleA B775AF26 = WmiQuerySingleInstanceA FB4547D4 = WmiQueryGuidInformation 78A0957D = WmiQueryAllDataW F98821E4 = WmiQueryAllDataMultipleW F98821F2 = WmiQueryAllDataMultipleA 78A0956B = WmiQueryAllDataA E2709DEB = WmiOpenBlock 1330F5FE = WmiNotificationRegistrationW 1330F5E8 = WmiNotificationRegistrationA 0E9B2F8C = WmiMofEnumerateResourcesW 0E9B2F9A = WmiMofEnumerateResourcesA 2B6F9E86 = WmiFreeBuffer 0B4FA0B0 = WmiFileHandleToInstanceNameW 0B4FA0A6 = WmiFileHandleToInstanceNameA 960BA624 = WmiExecuteMethodW 960BA632 = WmiExecuteMethodA A2C0C18B = WmiEnumerateGuids 202EC15B = WmiDevInstToInstanceNameW 202EC14D = WmiDevInstToInstanceNameA C43984A6 = WmiCloseBlock F32E5D1E = UsePinForEncryptedFilesW F32E5D08 = UsePinForEncryptedFilesA 4DDBD842 = UpdateTraceW 4DDBD854 = UpdateTraceA 2A5084E9 = UnregisterTraceGuids BC7B7228 = UnregisterIdleTask E119AEA6 = UnlockServiceDatabase D460ADE0 = UninstallApplication 9E999C03 = TrusteeAccessToObjectW 9E999C15 = TrusteeAccessToObjectA FA7A6F2E = TreeSetNamedSecurityInfoW FA7A6F38 = TreeSetNamedSecurityInfoA 33415E00 = TreeResetNamedSecurityInfoW 33415E16 = TreeResetNamedSecurityInfoA DF7AE974 = TraceSetInformation 761E9C0F = TraceMessageVa DDB9D87A = TraceMessage 3E841082 = TraceEventInstance 2C1AF872 = TraceEvent B5058B0A = SystemFunction041 B5058B0B = SystemFunction040 B505888D = SystemFunction036 B505888E = SystemFunction035 B505888F = SystemFunction034 B5058888 = SystemFunction033 B5058889 = SystemFunction032 B505888A = SystemFunction031 B505888B = SystemFunction030 B5058802 = SystemFunction029 B5058803 = SystemFunction028 B505880C = SystemFunction027 B505880D = SystemFunction026 B505880E = SystemFunction025 B505880F = SystemFunction024 B5058808 = SystemFunction023 B5058809 = SystemFunction022 B505880A = SystemFunction021 B505880B = SystemFunction020 B5058982 = SystemFunction019 B5058983 = SystemFunction018 B505898C = SystemFunction017 B505898D = SystemFunction016 B505898E = SystemFunction015 B505898F = SystemFunction014 B5058988 = SystemFunction013 B5058989 = SystemFunction012 B505898A = SystemFunction011 B505898B = SystemFunction010 B5058902 = SystemFunction009 B5058903 = SystemFunction008 B505890C = SystemFunction007 B505890D = SystemFunction006 B505890E = SystemFunction005 B505890F = SystemFunction004 B5058908 = SystemFunction003 B5058909 = SystemFunction002 B505890A = SystemFunction001 D8E73059 = StopTraceW D8E7304F = StopTraceA 4DDD348A = StartTraceW 4DDD349C = StartTraceA 1CA1FD39 = StartServiceW 1B529B72 = StartServiceCtrlDispatcherW 1B529B64 = StartServiceCtrlDispatcherA 1CA1FD2F = StartServiceA 5D08F35B = SetUserFileEncryptionKeyEx 468D7423 = SetUserFileEncryptionKey 8C91096B = SetTraceCallback D4ECC75C = SetTokenInformation A16FE0FD = SetThreadToken 80C6B740 = SetServiceStatus F81C4F9A = SetServiceObjectSecurity 34E9499D = SetServiceBits 9ED90EDA = SetSecurityInfoExW 9ED90ECC = SetSecurityInfoExA 43946CF6 = SetSecurityInfo CE303C3A = SetSecurityDescriptorSacl 9E45D624 = SetSecurityDescriptorRMControl DADD5994 = SetSecurityDescriptorOwner 5A7D1196 = SetSecurityDescriptorGroup CCD03C3A = SetSecurityDescriptorDacl 5445319B = SetSecurityDescriptorControl 65018B7E = SetSecurityAccessMask 14DF2CFD = SetPrivateObjectSecurityEx 3814537C = SetPrivateObjectSecurity 6D523BCB = SetNamedSecurityInfoW 8EF66703 = SetNamedSecurityInfoExW 8EF66715 = SetNamedSecurityInfoExA 6D523BDD = SetNamedSecurityInfoA E29136DD = SetKernelObjectSecurity AD60E377 = SetInformationCodeAuthzPolicyW E219C688 = SetInformationCodeAuthzLevelW 5A9B2FDD = SetFileSecurityW 5A9B2FCB = SetFileSecurityA 6226DD65 = SetEntriesInAuditListW 6226DD73 = SetEntriesInAuditListA 25AE42B7 = SetEntriesInAclW 25AE42A1 = SetEntriesInAclA 47377E97 = SetEntriesInAccessListW 47377E81 = SetEntriesInAccessListA 39968B1D = SetEncryptedFileMetadata 762BE525 = SetAclInformation 7A24EC61 = SaferiSearchMatchingHashRules 24D6FE0E = SaferiRecordEventLogEntry 96FAB802 = SaferiPopulateDefaultsInRegistry E51854CB = SaferiIsExecutableFileType 1E5C04F7 = SaferiIsDllAllowed 5CE7FC1C = SaferiCompareTokenLevels 8DF02930 = SaferiChangeRegistryScope D70528FE = SaferSetPolicyInformation BBDAE993 = SaferSetLevelInformation 38CFDE0A = SaferRecordEventLogEntry 05137DC0 = SaferIdentifyLevel D7052A7E = SaferGetPolicyInformation BBDAE996 = SaferGetLevelInformation 9F2096BE = SaferCreateLevel C36D4157 = SaferComputeTokenFromLevel 2E0EC02E = SaferCloseLevel 9F96FDBB = RevertToSelf 03543100 = ReportEventW 03543116 = ReportEventA 2B794B56 = RemoveUsersFromEncryptedFile B67C7133 = RemoveTraceCallback F1EA62DC = RegisterWaitChainCOMCallback 2847290A = RegisterTraceGuidsW 2847291C = RegisterTraceGuidsA 16B6D738 = RegisterServiceCtrlHandlerW B5CAB9FA = RegisterServiceCtrlHandlerExW B5CAB9EC = RegisterServiceCtrlHandlerExA 16B6D72E = RegisterServiceCtrlHandlerA 96953228 = RegisterIdleTask EC70ED90 = RegisterEventSourceW EC70ED86 = RegisterEventSourceA A2CC7A33 = RegUnLoadKeyW A2CC7A25 = RegUnLoadKeyA CE5CF912 = RegSetValueW 3E400FC0 = RegSetValueExW 3E400FD6 = RegSetValueExA CE5CF904 = RegSetValueA 782CEC50 = RegSetKeyValueW 782CEC46 = RegSetKeyValueA 39F1B40A = RegSetKeySecurity BEDEEFD3 = RegSaveKeyW BBF053E0 = RegSaveKeyExW BBF053F6 = RegSaveKeyExA BEDEEFC5 = RegSaveKeyA 3CCC37F1 = RegRestoreKeyW 3CCC37E7 = RegRestoreKeyA 3FFC0F79 = RegReplaceKeyW 3FFC0F6F = RegReplaceKeyA 0E731084 = RegRenameKey 6E246019 = RegQueryValueW 1802E7DE = RegQueryValueExW 1802E7C8 = RegQueryValueExA 6E24600F = RegQueryValueA BDC97F73 = RegQueryReflectionKey 356031AA = RegQueryMultipleValuesW 356031BC = RegQueryMultipleValuesA BDF4DB0F = RegQueryInfoKeyW BDF4DB19 = RegQueryInfoKeyA 68D5BB23 = RegOverridePredefKey 3F11E989 = RegOpenUserClassesRoot 0EE6AB4B = RegOpenKeyW E6EE6F63 = RegOpenKeyTransactedW E6EE6F75 = RegOpenKeyTransactedA AAD67FEE = RegOpenKeyExW AAD67FF8 = RegOpenKeyExA 0EE6AB5D = RegOpenKeyA 17617A40 = RegOpenCurrentUser 266722A7 = RegNotifyChangeKeyValue 9E060EC8 = RegLoadMUIStringW 9E060EDE = RegLoadMUIStringA AEE0D76B = RegLoadKeyW AEE0D77D = RegLoadKeyA 7EEC8865 = RegLoadAppKeyW 7EEC8873 = RegLoadAppKeyA DA5CF912 = RegGetValueW DA5CF904 = RegGetValueA 99F1B40A = RegGetKeySecurity DA9F55E4 = RegFlushKey F65A7D83 = RegEnumValueW F65A7D95 = RegEnumValueA 3EF2D3CB = RegEnumKeyW B4F673EB = RegEnumKeyExW B4F673FD = RegEnumKeyExA 3EF2D3DD = RegEnumKeyA C0CE0143 = RegEnableReflectionKey 87F62529 = RegDisableReflectionKey FF70A9C4 = RegDisablePredefinedCacheEx 2CF3FDC2 = RegDisablePredefinedCache 560C7C5C = RegDeleteValueW 560C7C4A = RegDeleteValueA 34CE50CA = RegDeleteTreeW 34CE50DC = RegDeleteTreeA 398C5293 = RegDeleteKeyW D1FFE640 = RegDeleteKeyValueW D1FFE656 = RegDeleteKeyValueA 3C50196E = RegDeleteKeyTransactedW 3C501978 = RegDeleteKeyTransactedA 14A07234 = RegDeleteKeyExW 14A07222 = RegDeleteKeyExA 398C5285 = RegDeleteKeyA AE9E4290 = RegCreateKeyW F8D4198B = RegCreateKeyTransactedW F8D4199D = RegCreateKeyTransactedA 90A097F0 = RegCreateKeyExW 90A097E6 = RegCreateKeyExA AE9E4286 = RegCreateKeyA 8D8CE869 = RegCopyTreeW 8D8CE87F = RegCopyTreeA A85C1CC9 = RegConnectRegistryW 0736D640 = RegConnectRegistryExW 0736D656 = RegConnectRegistryExA A85C1CDF = RegConnectRegistryA DB355534 = RegCloseKey 095ADCD2 = ReadEventLogW 095ADCC4 = ReadEventLogA C6B61661 = ReadEncryptedFileRaw 200351DA = QueryUsersOnEncryptedFile C9DD000A = QueryTraceW C9DD001C = QueryTraceA F6C712F4 = QueryServiceStatusEx C033DB1C = QueryServiceStatus A45CBAF6 = QueryServiceObjectSecurity 9D3D3EC2 = QueryServiceLockStatusW 9D3D3ED4 = QueryServiceLockStatusA EBAAC4EF = QueryServiceConfigW EBAAC4F9 = QueryServiceConfigA D5624522 = QueryServiceConfig2W D5624534 = QueryServiceConfig2A 62AAE99C = QuerySecurityAccessMask 8AE29566 = QueryRecoveryAgentsOnEncryptedFile 5EFE7566 = QueryAllTracesW 5EFE7570 = QueryAllTracesA AD99A2CF = ProcessTrace E4ADF62A = ProcessIdleTasksW FBC95BEC = ProcessIdleTasks E0ACBB18 = PrivilegedServiceAuditAlarmW E0ACBB0E = PrivilegedServiceAuditAlarmA 56FFD371 = PrivilegeCheck 0BF2252D = PerfStopProvider AA8FE9C5 = PerfStartProviderEx 2CF6AA3F = PerfStartProvider 8D117003 = PerfSetULongLongCounterValue 196925ED = PerfSetULongCounterValue 81768094 = PerfSetCounterSetInfo 4AA0C7B4 = PerfSetCounterRefValue 00E678C8 = PerfQueryInstance 6C2CE1AC = PerfQueryCounterSetRegistrationInfo 8AAFF979 = PerfQueryCounterInfo 8B0C3077 = PerfQueryCounterData 4C93C972 = PerfOpenQueryHandle 21409DEC = PerfIncrementULongLongCounterValue DC77FB17 = PerfIncrementULongCounterValue 5DF8AEEF = PerfEnumerateCounterSetInstances 13FB2774 = PerfEnumerateCounterSet 2790769A = PerfDeleteInstance 8526BA3D = PerfDeleteCounters 2140F55C = PerfDecrementULongLongCounterValue DC717017 = PerfDecrementULongCounterValue 1EE1579A = PerfCreateInstance FE66E9F3 = PerfCloseQueryHandle A53217EC = PerfAddCounters DCF34857 = OpenTraceW DCF34841 = OpenTraceA 528A93E4 = OpenThreadWaitChainSession B96CA1C0 = OpenThreadToken 83969972 = OpenServiceW 83969964 = OpenServiceA A06E458A = OpenSCManagerW A06E459C = OpenSCManagerA 80DBBE07 = OpenProcessToken 08887DD7 = OpenEventLogW 08887DC1 = OpenEventLogA 5E0AE215 = OpenEncryptedFileRawW 5E0AE203 = OpenEncryptedFileRawA FA2EC4C0 = OpenBackupEventLogW FA2EC4D6 = OpenBackupEventLogA 255DAFD9 = ObjectPrivilegeAuditAlarmW 255DAFCF = ObjectPrivilegeAuditAlarmA 1C55A1C6 = ObjectOpenAuditAlarmW 1C55A1D0 = ObjectOpenAuditAlarmA C2F1B3A9 = ObjectDeleteAuditAlarmW C2F1B3BF = ObjectDeleteAuditAlarmA 24597E49 = ObjectCloseAuditAlarmW 24597E5F = ObjectCloseAuditAlarmA 9B6643F4 = NotifyServiceStatusChangeW 9B6643E2 = NotifyServiceStatusChangeA 4736CC87 = NotifyServiceStatusChange EFFD1347 = NotifyChangeEventLog 24A9A4BE = NotifyBootConfigStatus B96DA355 = MapGenericMask 43BCA05D = MakeSelfRelativeSD 31D7E0DB = MakeAbsoluteSD2 D263AFC1 = MakeAbsoluteSD 8CCEC5F7 = MSChapSrvChangePassword2 8B199D8B = MSChapSrvChangePassword 4110ACCA = MD5Update 593A82D7 = MD5Init 6DA0A140 = MD5Final 4110A8CA = MD4Update 493A82D7 = MD4Init 6DA0A148 = MD4Final 77B8EE3E = LsaStorePrivateData FBC31C4C = LsaSetTrustedDomainInformation 0012C5B3 = LsaSetTrustedDomainInfoByName D86BF37C = LsaSetSystemAccessAccount 2A3F28BD = LsaSetSecurityObject 8FBEFC9A = LsaSetSecret DDC7D36A = LsaSetQuotasForAccount 830F05FA = LsaSetInformationTrustedDomain A2BFB4E6 = LsaSetInformationPolicy E049AAA7 = LsaSetForestTrustInformation F7369383 = LsaSetDomainInformationPolicy AE8A906D = LsaRetrievePrivateData F88C5CFD = LsaRemovePrivilegesFromAccount F5B173FD = LsaRemoveAccountRights 443A487D = LsaQueryTrustedDomainInfoByName 23F7788F = LsaQueryTrustedDomainInfo A26E3321 = LsaQuerySecurityObject DEA56012 = LsaQuerySecret D12EBEC5 = LsaQueryInformationPolicy 4E7B7671 = LsaQueryInfoTrustedDomain 7CC1FBBC = LsaQueryForestTrustInformation B31E1E4D = LsaQueryDomainInformationPolicy 50969EC1 = LsaOpenTrustedDomainByName 8CF253BA = LsaOpenTrustedDomain A879700D = LsaOpenSecret 6315C213 = LsaOpenPolicySce 099FB318 = LsaOpenPolicy 3F1C4390 = LsaOpenAccount 59CDC5C7 = LsaNtStatusToWinError 39B205F7 = LsaManageSidNameMapping 616BA5BA = LsaLookupSids C3A86A24 = LsaLookupPrivilegeValue 80875044 = LsaLookupPrivilegeName 277AC660 = LsaLookupPrivilegeDisplayName 684B2100 = LsaLookupNames2 64D09642 = LsaLookupNames 9454D733 = LsaICLookupSidsWithCreds FBBCEC09 = LsaICLookupSids EE3086F0 = LsaICLookupNamesWithCreds 0F744F8F = LsaICLookupNames BA4F883A = LsaGetUserName D8CBF37C = LsaGetSystemAccessAccount 2AE9C07E = LsaGetRemoteUserName DDC7D36F = LsaGetQuotasForAccount 2BBE1774 = LsaFreeMemory 47C6FEC3 = LsaEnumerateTrustedDomainsEx 70ED1F1B = LsaEnumerateTrustedDomains DC835BD3 = LsaEnumeratePrivilegesOfAccount 5D665773 = LsaEnumeratePrivileges 9D8E431F = LsaEnumerateAccountsWithUserRight 05A3B95C = LsaEnumerateAccounts B1E7F19D = LsaEnumerateAccountRights 14B64C53 = LsaDeleteTrustedDomain 117EFC43 = LsaDelete D1149537 = LsaCreateTrustedDomainEx DF3F4452 = LsaCreateTrustedDomain 238D59EB = LsaCreateSecret C508B0D5 = LsaCreateAccount 3D0236E9 = LsaClose 602DE07E = LsaClearAuditLog 301964C7 = LsaAddPrivilegesToAccount 74DA1392 = LsaAddAccountRights E322E8BE = LookupSecurityDescriptorPartsW E322E8A8 = LookupSecurityDescriptorPartsA 1B3D12AF = LookupPrivilegeValueW 1B3D12B9 = LookupPrivilegeValueA 70363216 = LookupPrivilegeNameW 70363200 = LookupPrivilegeNameA 9D615778 = LookupPrivilegeDisplayNameW 9D61576E = LookupPrivilegeDisplayNameA F6B76AEE = LookupAccountSidW F6B76AF8 = LookupAccountSidA 8AB72E2D = LookupAccountNameW 8AB72E3B = LookupAccountNameA 31B6C604 = LogonUserW B185B03A = LogonUserExW 6C0A1036 = LogonUserExExW B185B02C = LogonUserExA 31B6C612 = LogonUserA E11CF36E = LockServiceDatabase 5E79B6EF = IsWellKnownSid 6F3973A6 = IsValidSid 1F8F650F = IsValidSecurityDescriptor 5D551455 = IsValidRelativeSecurityDescriptor 6F3DF6AE = IsValidAcl AD5D0BCA = IsTokenUntrusted 876FBD88 = IsTokenRestricted 600CD021 = IsTextUnicode 4460A75B = InstallApplication 0690EC53 = InitiateSystemShutdownW 3B107DF3 = InitiateSystemShutdownExW 3B107DE5 = InitiateSystemShutdownExA 0690EC45 = InitiateSystemShutdownA 38F9C064 = InitiateShutdownW 38F9C072 = InitiateShutdownA C1EA9DD1 = InitializeSid B8538A52 = InitializeSecurityDescriptor C1EE18D9 = InitializeAcl DAA84C5E = ImpersonateSelf 8D434363 = ImpersonateNamedPipeClient 35AE2A45 = ImpersonateLoggedOnUser 9A8650F9 = ImpersonateAnonymousToken C7848298 = IdentifyCodeAuthzLevelW 8F49847D = I_ScValidatePnPService 1B7708DF = I_ScSetServiceBitsW 1B7708C9 = I_ScSetServiceBitsA 77AA4037 = I_ScSendTSMessage EA5B3A6C = I_ScSendPnPMessage B39AAFF1 = I_ScQueryServiceConfig 64BF03BF = I_ScPnPGetServiceName D779FA6A = I_ScIsSecurityProcess 63D1B178 = I_ScGetCurrentGroupStateW A4B830E5 = I_QueryTagInformation 636B72AD = GetWindowsAccountDomainSid B9D41C39 = GetUserNameW B9D41C2F = GetUserNameA 939F385F = GetTrusteeTypeW 939F3849 = GetTrusteeTypeA 3098785E = GetTrusteeNameW 30987848 = GetTrusteeNameA B15FBC5E = GetTrusteeFormW B15FBC48 = GetTrusteeFormA 9E1F8AAE = GetTraceLoggerHandle 51B0196D = GetTraceEnableLevel F095D872 = GetTraceEnableFlags D4ECC759 = GetTokenInformation 0E12826B = GetThreadWaitChain AD0C9F7E = GetSidSubAuthorityCount D21E3D01 = GetSidSubAuthority 299727FA = GetSidLengthRequired 512796CC = GetSidIdentifierAuthority 0567D625 = GetServiceKeyNameW 0567D633 = GetServiceKeyNameA F276DC51 = GetServiceDisplayNameW F276DC47 = GetServiceDisplayNameA 94D90EDA = GetSecurityInfoExW 94D90ECC = GetSecurityInfoExA 43946CA6 = GetSecurityInfo CE30283A = GetSecurityDescriptorSacl 9E457624 = GetSecurityDescriptorRMControl DAD75994 = GetSecurityDescriptorOwner 4BAC491C = GetSecurityDescriptorLength 5A771196 = GetSecurityDescriptorGroup CCD0283A = GetSecurityDescriptorDacl D4453199 = GetSecurityDescriptorControl 38145354 = GetPrivateObjectSecurity E625538B = GetOverlappedAccessResults 12827260 = GetOldestEventLogRecord A6ACD0DC = GetNumberOfEventLogRecords 6D537BCB = GetNamedSecurityInfoW DEF66703 = GetNamedSecurityInfoExW DEF66715 = GetNamedSecurityInfoExA 6D537BDD = GetNamedSecurityInfoA CE891E88 = GetMultipleTrusteeW 5AB4B310 = GetMultipleTrusteeOperationW 5AB4B306 = GetMultipleTrusteeOperationA CE891E9E = GetMultipleTrusteeA 7D70D948 = GetManagedApplications A10B8971 = GetManagedApplicationCategories D1A26ED1 = GetLocalManagedApplications DCC24E2C = GetLocalManagedApplicationData 01D7B6A1 = GetLengthSid B29136DD = GetKernelObjectSecurity 8FE788F5 = GetInheritanceSourceW 8FE788E3 = GetInheritanceSourceA AD604377 = GetInformationCodeAuthzPolicyW E219C7C8 = GetInformationCodeAuthzLevelW 5A9B07DD = GetFileSecurityW 5A9B07CB = GetFileSecurityA 3AF6663F = GetExplicitEntriesFromAclW 3AF66629 = GetExplicitEntriesFromAclA 67E2CDB4 = GetEventLogInformation 39968B35 = GetEncryptedFileMetadata D055A3D4 = GetEffectiveRightsFromAclW D055A3C2 = GetEffectiveRightsFromAclA F684C7BF = GetCurrentHwProfileW F684C7A9 = GetCurrentHwProfileA 1CFC7058 = GetAuditedPermissionsFromAclW 1CFC704E = GetAuditedPermissionsFromAclA 763FE525 = GetAclInformation 5E9073DB = GetAce 64A72F44 = GetAccessPermissionsForObjectW 64A72F52 = GetAccessPermissionsForObjectA 5CB5EF72 = FreeSid A8FE6BC9 = FreeInheritedFromArray C645C79D = FreeEncryptionCertificateHashList 391ECD5F = FreeEncryptedFileMetadata A970A601 = FreeEncryptedFileKeyInfo 59DF41C6 = FlushTraceW 59DF41D0 = FlushTraceA D0DEF280 = FlushEfsCache 59113DAD = FindFirstFreeAce 541F9BF1 = FileEncryptionStatusW 541F9BE7 = FileEncryptionStatusA 0C58E83D = EventWriteTransfer 095DFFDA = EventWriteString 89E12DB7 = EventWriteStartScenario 707880DC = EventWriteEx B0A77BA4 = EventWriteEndScenario 8891C1E2 = EventWrite C6C579F1 = EventUnregister EE867CBB = EventRegister 5DAE1E1E = EventProviderEnabled F2BA9820 = EventEnabled D0562EC6 = EventActivityIdControl CF51E095 = EventAccessRemove D39CAD4E = EventAccessQuery 9B910BDB = EventAccessControl 1D1F334A = EqualSid E0EFDBA6 = EqualPrefixSid F615FB9E = EqualDomainSid AFECD9BC = EnumerateTraceGuidsEx ED12BFB3 = EnumerateTraceGuids A321375E = EnumServicesStatusW 4DD3149F = EnumServicesStatusExW 4DD31489 = EnumServicesStatusExA A3213748 = EnumServicesStatusA 29438F04 = EnumServiceGroupW D9B506F7 = EnumDependentServicesW D9B506E1 = EnumDependentServicesA 443E6591 = EncryptionDisable 625EF68C = EncryptedFileKeyInfo 9FC04AC2 = EncryptFileW 9FC04AD4 = EncryptFileA 77F48F88 = EnableTraceEx2 74EFE91F = EnableTraceEx 2F9DD3BF = EnableTrace 65343017 = ElfReportEventW 820BA5A8 = ElfReportEventAndSourceW 65343001 = ElfReportEventA FB168D91 = ElfRegisterEventSourceW FB168D87 = ElfRegisterEventSourceA 395A5761 = ElfReadEventLogW 395A5777 = ElfReadEventLogA 3888F664 = ElfOpenEventLogW 3888F672 = ElfOpenEventLogA F8000800 = ElfOpenBackupEventLogW F8000816 = ElfOpenBackupEventLogA 5FF5D1D7 = ElfOldestRecord FE016D1F = ElfNumberOfRecords 3275FA03 = ElfFlushEventLog 3CECADF8 = ElfDeregisterEventSource 3F25FC83 = ElfCloseEventLog 2C14C282 = ElfClearEventLogFileW 2C14C294 = ElfClearEventLogFileA 763D9E28 = ElfChangeNotify 2F314F9B = ElfBackupEventLogFileW 2F314F8D = ElfBackupEventLogFileA CEBD40A1 = DuplicateTokenEx 89673AF5 = DuplicateToken 0D8D7EAF = DuplicateEncryptionInfoFile 8905A736 = DestroyPrivateObjectSecurity 8FDCAD73 = DeregisterEventSource DE5D85F8 = DeleteService 087BC2CA = DeleteAce 9FC06802 = DecryptFileW 9FC06814 = DecryptFileA 499F4478 = CryptVerifySignatureW 499F446E = CryptVerifySignatureA C0C0571B = CryptSignHashW C0C0570D = CryptSignHashA 4B755A7C = CryptSetProviderW 569BAE8A = CryptSetProviderExW 569BAE9C = CryptSetProviderExA 4B755A6A = CryptSetProviderA DBD093C5 = CryptSetProvParam 37A53419 = CryptSetKeyParam C3F6E335 = CryptSetHashParam 72760BB8 = CryptReleaseContext 78660DBE = CryptImportKey A752A65C = CryptHashSessionKey F837A387 = CryptHashData 2C25B94B = CryptGetUserKey DBD213C5 = CryptGetProvParam 37A53119 = CryptGetKeyParam C3F46335 = CryptGetHashParam C359FA5A = CryptGetDefaultProviderW C359FA4C = CryptGetDefaultProviderA 453DB143 = CryptGenRandom 2433303E = CryptGenKey 744C0DBE = CryptExportKey E9F43833 = CryptEnumProvidersW E9F43825 = CryptEnumProvidersA D0863B6E = CryptEnumProviderTypesW D0863B78 = CryptEnumProviderTypesA CEBF13BE = CryptEncrypt A76A0569 = CryptDuplicateKey B563B1BB = CryptDuplicateHash 0D4B3D42 = CryptDestroyKey A5FFA46E = CryptDestroyHash 3756058E = CryptDeriveKey CEBF17E6 = CryptDecrypt 3C4DE260 = CryptCreateHash ACAA6891 = CryptContextAddRef 8AD7DE22 = CryptAcquireContextW 8AD7DE34 = CryptAcquireContextA 94FE7A4C = CredpEncodeSecret 70D9CF41 = CredpEncodeCredential 70D9CD6D = CredpDecodeCredential A4DC8268 = CredpConvertTargetInfo 67F5A6CA = CredpConvertOneCredentialSize 90534DE1 = CredpConvertCredential DFF6A049 = CredWriteW 1B18DE14 = CredWriteDomainCredentialsW 1B18DE02 = CredWriteDomainCredentialsA DFF6A05F = CredWriteA BD758800 = CredUnprotectW BD758816 = CredUnprotectA 1323DE2A = CredUnmarshalCredentialW 1323DE3C = CredUnmarshalCredentialA 7CA79A97 = CredRestoreCredentials 89F22900 = CredRenameW 89F22916 = CredRenameA 6F5DE572 = CredReadW 86C08BB6 = CredReadDomainCredentialsW 86C08BA0 = CredReadDomainCredentialsA A06B4CCA = CredReadByTokenHandle 6F5DE564 = CredReadA A8114D9A = CredProtectW A8114D8C = CredProtectA F60B9AA7 = CredProfileUnloaded B0AD1AE6 = CredProfileLoaded 4A12B8AF = CredMarshalCredentialW 4A12B8B9 = CredMarshalCredentialA 620F1A5A = CredIsProtectedW 620F1A4C = CredIsProtectedA A5B06B2D = CredIsMarshaledCredentialW A5B06B3B = CredIsMarshaledCredentialA 70BA7ED1 = CredGetTargetInfoW 70BA7EC7 = CredGetTargetInfoA 6AC03DF0 = CredGetSessionTypes 485B79CB = CredFree BCB7E442 = CredFindBestCredentialW BCB7E454 = CredFindBestCredentialA DDFA3CD8 = CredEnumerateW DDFA3CCE = CredEnumerateA AAB8F51D = CredEncryptAndMarshalBinaryBlob A9743100 = CredDeleteW A9743116 = CredDeleteA 05E90C2B = CredBackupCredentials 96EB7D6A = CreateWellKnownSid E4723B84 = CreateTraceInstanceId 17B3DD38 = CreateServiceW 17B3DD2E = CreateServiceA F1DD0C6D = CreateRestrictedToken 37881099 = CreateProcessWithTokenW 360A9059 = CreateProcessWithLogonW 985267D2 = CreateProcessAsUserW 985267C4 = CreateProcessAsUserA 5F550058 = CreatePrivateObjectSecurityWithMultipleInheritance 4D8639E1 = CreatePrivateObjectSecurityEx 6C653618 = CreatePrivateObjectSecurity 954969B2 = CreateCodeAuthzLevel 0F35FB9B = CopySid ADF5011E = ConvertToAutoInheritPrivateObjectSecurity 3E68CFD0 = ConvertStringSidToSidW 3E68CFC6 = ConvertStringSidToSidA F2F9DE1E = ConvertStringSecurityDescriptorToSecurityDescriptorW F2F9DE08 = ConvertStringSecurityDescriptorToSecurityDescriptorA 6F2FB8E2 = ConvertStringSDToSDRootDomainW 6F2FB8F4 = ConvertStringSDToSDRootDomainA 13F7E3EC = ConvertStringSDToSDDomainW 13F7E3FA = ConvertStringSDToSDDomainA 70395A5A = ConvertSidToStringSidW 70395A4C = ConvertSidToStringSidA E16F2876 = ConvertSecurityDescriptorToStringSecurityDescriptorW E16F2860 = ConvertSecurityDescriptorToStringSecurityDescriptorA 97F800E0 = ConvertSecurityDescriptorToAccessW A279759D = ConvertSecurityDescriptorToAccessNamedW A279758B = ConvertSecurityDescriptorToAccessNamedA 97F800F6 = ConvertSecurityDescriptorToAccessA 670C82C5 = ConvertSDToStringSDRootDomainW 670C82D3 = ConvertSDToStringSDRootDomainA C2C7481F = ConvertAccessToSecurityDescriptorW C2C74809 = ConvertAccessToSecurityDescriptorA 5ADABBCA = ControlTraceW 5ADABBDC = ControlTraceA 7E3A838B = ControlServiceExW 7E3A839D = ControlServiceExA 5FFEE3F1 = ControlService 4CFEC25E = ComputeAccessTokenFromCodeAuthzLevel E5300749 = CommandLineFromMsiDescriptor A287BEE9 = CloseTrace 6E5B0CC8 = CloseThreadWaitChainSession 78CEC357 = CloseServiceHandle 0F257730 = CloseEventLog 4FB321A3 = CloseEncryptedFileRaw D1C76FDE = CloseCodeAuthzLevel 12BADCDB = ClearEventLogW 12BADCCD = ClearEventLogA 87FEDB50 = CheckTokenMembership A1A1E6F1 = ChangeServiceConfigW A1A1E6E7 = ChangeServiceConfigA D0F34A07 = ChangeServiceConfig2W D0F34A11 = ChangeServiceConfig2A 936DF186 = CancelOverlappedAccess 8C6769CD = BuildTrusteeWithSidW 8C6769DB = BuildTrusteeWithSidA 47F6CAF3 = BuildTrusteeWithObjectsAndSidW 47F6CAE5 = BuildTrusteeWithObjectsAndSidA 2A6720F5 = BuildTrusteeWithObjectsAndNameW 2A6720E3 = BuildTrusteeWithObjectsAndNameA E2B6BF90 = BuildTrusteeWithNameW E2B6BF86 = BuildTrusteeWithNameA 97BE24F0 = BuildSecurityDescriptorW 97BE24E6 = BuildSecurityDescriptorA 647366DE = BuildImpersonateTrusteeW 647366C8 = BuildImpersonateTrusteeA C445B542 = BuildImpersonateExplicitAccessWithNameW C445B554 = BuildImpersonateExplicitAccessWithNameA 1E8E1536 = BuildExplicitAccessWithNameW 1E8E1520 = BuildExplicitAccessWithNameA 024B18D3 = BackupEventLogW 024B18C5 = BackupEventLogA 54725874 = AuditSetSystemPolicy 8C63FA43 = AuditSetSecurity 9FADBEFB = AuditSetPerUserPolicy B7473306 = AuditSetGlobalSaclW B7473310 = AuditSetGlobalSaclA E6950E0B = AuditQuerySystemPolicy A2169DB8 = AuditQuerySecurity EC068122 = AuditQueryPerUserPolicy 4822FDAA = AuditQueryGlobalSaclW 4822FDBC = AuditQueryGlobalSaclA 27343AD7 = AuditLookupSubCategoryNameW 27343AC1 = AuditLookupSubCategoryNameA 6F11CDEE = AuditLookupCategoryNameW 6F11CDF8 = AuditLookupCategoryNameA 4B176B3B = AuditLookupCategoryIdFromCategoryGuid E7768ED0 = AuditLookupCategoryGuidFromCategoryId 093721AA = AuditFree 822B94D7 = AuditEnumerateSubCategories 93FBCE6E = AuditEnumeratePerUserPolicy 29FE3929 = AuditEnumerateCategories 56014C34 = AuditComputeEffectivePolicyByToken FB689B0A = AuditComputeEffectivePolicyBySid 86EC7CD5 = AreAnyAccessesGranted 86EE56D5 = AreAllAccessesGranted EEBCE257 = AllocateLocallyUniqueId 28E9E291 = AllocateAndInitializeSid 7A2167DC = AdjustTokenPrivileges 69499ED0 = AdjustTokenGroups B4170CD4 = AddUsersToEncryptedFileEx B8B2D05C = AddUsersToEncryptedFile 6DBA1BEA = AddMandatoryAce F7FFDE35 = AddConditionalAce 9A26C709 = AddAuditAccessObjectAce AB48BED2 = AddAuditAccessAceEx 70AAAD22 = AddAuditAccessAce 4C9073EB = AddAce 3E6F1851 = AddAccessDeniedObjectAce EFD54B58 = AddAccessDeniedAceEx A683BF55 = AddAccessDeniedAce FC56DDBA = AddAccessAllowedObjectAce CC4915E4 = AddAccessAllowedAceEx DC733124 = AddAccessAllowedAce B1944799 = AccessCheckByTypeResultListAndAuditAlarmW 60D9859E = AccessCheckByTypeResultListAndAuditAlarmByHandleW 60D98588 = AccessCheckByTypeResultListAndAuditAlarmByHandleA B194478F = AccessCheckByTypeResultListAndAuditAlarmA 25E5ECCE = AccessCheckByTypeResultList 669A7086 = AccessCheckByTypeAndAuditAlarmW 669A7090 = AccessCheckByTypeAndAuditAlarmA D0266109 = AccessCheckByType 5D494CBA = AccessCheckAndAuditAlarmW 5D494CAC = AccessCheckAndAuditAlarmA DED2AE06 = AccessCheck E6E058F0 = AbortSystemShutdownW E6E058E6 = AbortSystemShutdownA DF096CA5 = A_SHAUpdate 5884FAB0 = A_SHAInit B29C92C0 = A_SHAFinal