advapi32(AbortSystemShutdownA ADVAPI32.dll(AbortSystemShutdownW ADVAPI32.dllۈ AccessCheck ADVAPI32.dll-AccessCheckAndAuditAlarmA ADVAPI32.dll-AccessCheckAndAuditAlarmW ADVAPI32.dll%AccessCheckByType ADVAPI32.dll3AccessCheckByTypeAndAuditAlarmA ADVAPI32.dll03AccessCheckByTypeAndAuditAlarmW ADVAPI32.dll/AccessCheckByTypeResultList ADVAPI32.dllU=)AccessCheckByTypeResultListAndAuditAlarmA ADVAPI32.dllE1AccessCheckByTypeResultListAndAuditAlarmByHandleA ADVAPI32.dllE1AccessCheckByTypeResultListAndAuditAlarmByHandleW ADVAPI32.dllԈ=)AccessCheckByTypeResultListAndAuditAlarmW ADVAPI32.dll'AddAccessAllowedAce ADVAPI32.dll)AddAccessAllowedAceEx ADVAPI32.dll -AddAccessAllowedObjectAce ADVAPI32.dll~&AddAccessDeniedAce ADVAPI32.dllb(AddAccessDeniedAceEx ADVAPI32.dll,AddAccessDeniedObjectAce ADVAPI32.dllAddAce ADVAPI32.dll%AddAuditAccessAce ADVAPI32.dll'AddAuditAccessAceEx ADVAPI32.dll+AddAuditAccessObjectAce ADVAPI32.dllS%AddConditionalAce ADVAPI32.dll#AddMandatoryAce ADVAPI32.dllT+AddUsersToEncryptedFile ADVAPI32.dll-AddUsersToEncryptedFileEx ADVAPI32.dll8%AdjustTokenGroups ADVAPI32.dll%)AdjustTokenPrivileges ADVAPI32.dll,AllocateAndInitializeSid ADVAPI32.dll+AllocateLocallyUniqueId ADVAPI32.dll)AreAllAccessesGranted ADVAPI32.dll)AreAnyAccessesGranted ADVAPI32.dllڈ4 AuditComputeEffectivePolicyBySid ADVAPI32.dllC6"AuditComputeEffectivePolicyByToken ADVAPI32.dll^,AuditEnumerateCategories ADVAPI32.dll`/AuditEnumeratePerUserPolicy ADVAPI32.dll*/AuditEnumerateSubCategories ADVAPI32.dll0 AuditFree ADVAPI32.dll9%AuditLookupCategoryGuidFromCategoryId ADVAPI32.dll29%AuditLookupCategoryIdFromCategoryGuid ADVAPI32.dll2,AuditLookupCategoryNameA ADVAPI32.dll,AuditLookupCategoryNameW ADVAPI32.dll|/AuditLookupSubCategoryNameA ADVAPI32.dllb/AuditLookupSubCategoryNameW ADVAPI32.dllL)AuditQueryGlobalSaclA ADVAPI32.dll)AuditQueryGlobalSaclW ADVAPI32.dllш+AuditQueryPerUserPolicy ADVAPI32.dllˆ&AuditQuerySecurity ADVAPI32.dll*AuditQuerySystemPolicy ADVAPI32.dll'AuditSetGlobalSaclA ADVAPI32.dllՈ'AuditSetGlobalSaclW ADVAPI32.dll)AuditSetPerUserPolicy ADVAPI32.dll$AuditSetSecurity ADVAPI32.dll(AuditSetSystemPolicy ADVAPI32.dll#BackupEventLogA ADVAPI32.dllZ#BackupEventLogW ADVAPI32.dllD#BaseRegCloseKey ADVAPI32.dll]$BaseRegCreateKey ADVAPI32.dll&BaseRegDeleteKeyEx ADVAPI32.dll=&BaseRegDeleteValue ADVAPI32.dll&#BaseRegFlushKey ADVAPI32.dllQ%BaseRegGetVersion ADVAPI32.dllr"BaseRegLoadKey ADVAPI32.dllՈ"BaseRegOpenKey ADVAPI32.dllÈ%BaseRegRestoreKey ADVAPI32.dllk$BaseRegSaveKeyEx ADVAPI32.dll)BaseRegSetKeySecurity ADVAPI32.dllÈ#BaseRegSetValue ADVAPI32.dllS$BaseRegUnLoadKey ADVAPI32.dll0BuildExplicitAccessWithNameA ADVAPI32.dll0BuildExplicitAccessWithNameW ADVAPI32.dll;'BuildImpersonateExplicitAccessWithNameA ADVAPI32.dll|;'BuildImpersonateExplicitAccessWithNameW ADVAPI32.dllf,BuildImpersonateTrusteeA ADVAPI32.dll_,BuildImpersonateTrusteeW ADVAPI32.dllI,BuildSecurityDescriptorA ADVAPI32.dll[,BuildSecurityDescriptorW ADVAPI32.dllE)BuildTrusteeWithNameA ADVAPI32.dllψ)BuildTrusteeWithNameW ADVAPI32.dll3BuildTrusteeWithObjectsAndNameA ADVAPI32.dllވ3BuildTrusteeWithObjectsAndNameW ADVAPI32.dllȈ2BuildTrusteeWithObjectsAndSidA ADVAPI32.dllA2BuildTrusteeWithObjectsAndSidW ADVAPI32.dll+(BuildTrusteeWithSidA ADVAPI32.dll2(BuildTrusteeWithSidW ADVAPI32.dll*CancelOverlappedAccess ADVAPI32.dll])ChangeServiceConfig2A ADVAPI32.dll))ChangeServiceConfig2W ADVAPI32.dll(ChangeServiceConfigA ADVAPI32.dll](ChangeServiceConfigW ADVAPI32.dllG%CheckForHiberboot ADVAPI32.dlln(CheckTokenMembership ADVAPI32.dll "ClearEventLogA ADVAPI32.dllˈ"ClearEventLogW ADVAPI32.dll'CloseCodeAuthzLevel ADVAPI32.dll)CloseEncryptedFileRaw ADVAPI32.dll! CloseEventLog ADVAPI32.dll&CloseServiceHandle ADVAPI32.dll/CloseThreadWaitChainSession ADVAPI32.dllS CloseTrace ADVAPI32.dll:0CommandLineFromMsiDescriptor ADVAPI32.dll؈8$ComputeAccessTokenFromCodeAuthzLevel ADVAPI32.dll"ControlService ADVAPI32.dlle%ControlServiceExA ADVAPI32.dlla%ControlServiceExW ADVAPI32.dllK! ControlTraceA ADVAPI32.dll! ControlTraceW ADVAPI32.dll6"ConvertAccessToSecurityDescriptorA ADVAPI32.dllA6"ConvertAccessToSecurityDescriptorW ADVAPI32.dll+.ConvertSDToStringSDDomainW ADVAPI32.dll2ConvertSDToStringSDRootDomainA ADVAPI32.dllq2ConvertSDToStringSDRootDomainW ADVAPI32.dll[6"ConvertSecurityDescriptorToAccessA ADVAPI32.dllA;'ConvertSecurityDescriptorToAccessNamedA ADVAPI32.dllR;'ConvertSecurityDescriptorToAccessNamedW ADVAPI32.dll<6"ConvertSecurityDescriptorToAccessW ADVAPI32.dll+H4ConvertSecurityDescriptorToStringSecurityDescriptorA ADVAPI32.dllH4ConvertSecurityDescriptorToStringSecurityDescriptorW ADVAPI32.dllk*ConvertSidToStringSidA ADVAPI32.dllk*ConvertSidToStringSidW ADVAPI32.dllU.ConvertStringSDToSDDomainA ADVAPI32.dll.ConvertStringSDToSDDomainW ADVAPI32.dll2ConvertStringSDToSDRootDomainA ADVAPI32.dllq2ConvertStringSDToSDRootDomainW ADVAPI32.dll[H4ConvertStringSecurityDescriptorToSecurityDescriptorA ADVAPI32.dllH4ConvertStringSecurityDescriptorToSecurityDescriptorW ADVAPI32.dllk*ConvertStringSidToSidA ADVAPI32.dllk*ConvertStringSidToSidW ADVAPI32.dllU=)ConvertToAutoInheritPrivateObjectSecurity ADVAPI32.dllGCopySid ADVAPI32.dllj(CreateCodeAuthzLevel ADVAPI32.dll8/CreatePrivateObjectSecurity ADVAPI32.dll1CreatePrivateObjectSecurityEx ADVAPI32.dll^F2CreatePrivateObjectSecurityWithMultipleInheritance ADVAPI32.dll(CreateProcessAsUserA ADVAPI32.dllD(CreateProcessAsUserW ADVAPI32.dll.+CreateProcessWithLogonW ADVAPI32.dll+CreateProcessWithTokenW ADVAPI32.dllވ)CreateRestrictedToken ADVAPI32.dll"CreateServiceA ADVAPI32.dll"CreateServiceW ADVAPI32.dll)CreateTraceInstanceId ADVAPI32.dll&CreateWellKnownSid ADVAPI32.dll CredDeleteA ADVAPI32.dll  CredDeleteW ADVAPI32.dll"CredEnumerateA ADVAPI32.dll"CredEnumerateW ADVAPI32.dll+CredFindBestCredentialA ADVAPI32.dll<+CredFindBestCredentialW ADVAPI32.dll&CredFree ADVAPI32.dll#'CredGetSessionTypes ADVAPI32.dllv&CredGetTargetInfoA ADVAPI32.dll=&CredGetTargetInfoW ADVAPI32.dll'.CredIsMarshaledCredentialA ADVAPI32.dll.CredIsMarshaledCredentialW ADVAPI32.dll$CredIsProtectedA ADVAPI32.dll$CredIsProtectedW ADVAPI32.dll؈*CredMarshalCredentialA ADVAPI32.dll*CredMarshalCredentialW ADVAPI32.dllo  CredProtectA ADVAPI32.dll{  CredProtectW ADVAPI32.dlle CredReadA ADVAPI32.dll.CredReadDomainCredentialsA ADVAPI32.dll.CredReadDomainCredentialsW ADVAPI32.dll CredReadW ADVAPI32.dllЈ CredRenameA ADVAPI32.dll CredRenameW ADVAPI32.dll,CredUnmarshalCredentialA ADVAPI32.dll,CredUnmarshalCredentialW ADVAPI32.dll"CredUnprotectA ADVAPI32.dll"CredUnprotectW ADVAPI32.dll~ CredWriteA ADVAPI32.dllU/CredWriteDomainCredentialsA ADVAPI32.dllm/CredWriteDomainCredentialsW ADVAPI32.dllW CredWriteW ADVAPI32.dll?(CryptAcquireContextA ADVAPI32.dll (CryptAcquireContextW ADVAPI32.dll&CryptContextAddRef ADVAPI32.dll#CryptCreateHash ADVAPI32.dll+  CryptDecrypt ADVAPI32.dll."CryptDeriveKey ADVAPI32.dll}$CryptDestroyHash ADVAPI32.dll#CryptDestroyKey ADVAPI32.dll&CryptDuplicateHash ADVAPI32.dllވ%CryptDuplicateKey ADVAPI32.dll;  CryptEncrypt ADVAPI32.dll$+CryptEnumProviderTypesA ADVAPI32.dll+CryptEnumProviderTypesW ADVAPI32.dll'CryptEnumProvidersA ADVAPI32.dllg'CryptEnumProvidersW ADVAPI32.dllQ"CryptExportKey ADVAPI32.dllZ CryptGenKey ADVAPI32.dllȈ"CryptGenRandom ADVAPI32.dll,CryptGetDefaultProviderA ADVAPI32.dll,CryptGetDefaultProviderW ADVAPI32.dllj%CryptGetHashParam ADVAPI32.dllj$CryptGetKeyParam ADVAPI32.dllLj%CryptGetProvParam ADVAPI32.dllG#CryptGetUserKey ADVAPI32.dll! CryptHashData ADVAPI32.dll 'CryptHashSessionKey ADVAPI32.dllj"CryptImportKey ADVAPI32.dlla'CryptReleaseContext ADVAPI32.dllU%CryptSetHashParam ADVAPI32.dll^$CryptSetKeyParam ADVAPI32.dll%CryptSetProvParam ADVAPI32.dll;%CryptSetProviderA ADVAPI32.dllG'CryptSetProviderExA ADVAPI32.dll'CryptSetProviderExW ADVAPI32.dllp%CryptSetProviderW ADVAPI32.dll1"CryptSignHashA ADVAPI32.dll"CryptSignHashW ADVAPI32.dll)CryptVerifySignatureA ADVAPI32.dll)CryptVerifySignatureW ADVAPI32.dlly  DecryptFileA ADVAPI32.dll  DecryptFileW ADVAPI32.dlli DeleteAce ADVAPI32.dllň! DeleteService ADVAPI32.dll)DeregisterEventSource ADVAPI32.dll0DestroyPrivateObjectSecurity ADVAPI32.dll/DuplicateEncryptionInfoFile ADVAPI32.dll+"DuplicateToken ADVAPI32.dll{$DuplicateTokenEx ADVAPI32.dll*ElfBackupEventLogFileA ADVAPI32.dll*ElfBackupEventLogFileW ADVAPI32.dll#ElfChangeNotify ADVAPI32.dll?)ElfClearEventLogFileA ADVAPI32.dll&)ElfClearEventLogFileW ADVAPI32.dll$ElfCloseEventLog ADVAPI32.dll,ElfDeregisterEventSource ADVAPI32.dllk$ElfFlushEventLog ADVAPI32.dllֈ&ElfNumberOfRecords ADVAPI32.dll#ElfOldestRecord ADVAPI32.dll4*ElfOpenBackupEventLogA ADVAPI32.dll*ElfOpenBackupEventLogW ADVAPI32.dll$ElfOpenEventLogA ADVAPI32.dll$ElfOpenEventLogW ADVAPI32.dll$ElfReadEventLogA ADVAPI32.dll$ElfReadEventLogW ADVAPI32.dll+ElfRegisterEventSourceA ADVAPI32.dll+ElfRegisterEventSourceW ADVAPI32.dll߈#ElfReportEventA ADVAPI32.dll?,ElfReportEventAndSourceW ADVAPI32.dll#ElfReportEventW ADVAPI32.dll) EnableTrace ADVAPI32.dll"EnableTraceEx2 ADVAPI32.dll! EnableTraceEx ADVAPI32.dll&  EncryptFileA ADVAPI32.dllu  EncryptFileW ADVAPI32.dll_(EncryptedFileKeyInfo ADVAPI32.dll(%EncryptionDisable ADVAPI32.dll2*EnumDependentServicesA ADVAPI32.dllV*EnumDependentServicesW ADVAPI32.dll@2EnumDynamicTimeZoneInformation ADVAPI32.dll%EnumServiceGroupW ADVAPI32.dllG'EnumServicesStatusA ADVAPI32.dllo)EnumServicesStatusExA ADVAPI32.dll)EnumServicesStatusExW ADVAPI32.dll'EnumServicesStatusW ADVAPI32.dllY'EnumerateTraceGuids ADVAPI32.dll|)EnumerateTraceGuidsEx ADVAPI32.dll"EqualDomainSid ADVAPI32.dll"EqualPrefixSid ADVAPI32.dllEqualSid ADVAPI32.dll ,EtwLogSysConfigExtension ADVAPI32.dll_&EventAccessControl ADVAPI32.dllڈ$EventAccessQuery ADVAPI32.dll%EventAccessRemove ADVAPI32.dllO*EventActivityIdControl ADVAPI32.dll*  EventEnabled ADVAPI32.dlln(EventProviderEnabled ADVAPI32.dll! EventRegister ADVAPI32.dll҈'EventSetInformation ADVAPI32.dllY#EventUnregister ADVAPI32.dll EventWrite ADVAPI32.dll)EventWriteEndScenario ADVAPI32.dll  EventWriteEx ADVAPI32.dllQ+EventWriteStartScenario ADVAPI32.dll$EventWriteString ADVAPI32.dll&EventWriteTransfer ADVAPI32.dll)FileEncryptionStatusA ADVAPI32.dll)FileEncryptionStatusW ADVAPI32.dll$FindFirstFreeAce ADVAPI32.dll! FlushEfsCache ADVAPI32.dll% FlushTraceA ADVAPI32.dll FlushTraceW ADVAPI32.dllՈ,FreeEncryptedFileKeyInfo ADVAPI32.dll-FreeEncryptedFileMetadata ADVAPI32.dll05!FreeEncryptionCertificateHashList ADVAPI32.dll*FreeInheritedFromArray ADVAPI32.dllVFreeSid ADVAPI32.dll2GetAccessPermissionsForObjectA ADVAPI32.dll*2GetAccessPermissionsForObjectW ADVAPI32.dllGetAce ADVAPI32.dll%GetAclInformation ADVAPI32.dll[1GetAuditedPermissionsFromAclA ADVAPI32.dll1GetAuditedPermissionsFromAclW ADVAPI32.dll(GetCurrentHwProfileA ADVAPI32.dll7(GetCurrentHwProfileW ADVAPI32.dll!?+GetDynamicTimeZoneInformationEffectiveYears ADVAPI32.dll.GetEffectiveRightsFromAclA ADVAPI32.dll.GetEffectiveRightsFromAclW ADVAPI32.dll,GetEncryptedFileMetadata ADVAPI32.dll*GetEventLogInformation ADVAPI32.dll=.GetExplicitEntriesFromAclA ADVAPI32.dllވ.GetExplicitEntriesFromAclW ADVAPI32.dllȈ$GetFileSecurityA ADVAPI32.dllڈ$GetFileSecurityW ADVAPI32.dllĈ1GetInformationCodeAuthzLevelW ADVAPI32.dll}2GetInformationCodeAuthzPolicyW ADVAPI32.dll)GetInheritanceSourceA ADVAPI32.dll͈)GetInheritanceSourceW ADVAPI32.dll+GetKernelObjectSecurity ADVAPI32.dllՈ  GetLengthSid ADVAPI32.dlly2GetLocalManagedApplicationData ADVAPI32.dllQ/GetLocalManagedApplications ADVAPI32.dll^3GetManagedApplicationCategories ADVAPI32.dll*GetManagedApplications ADVAPI32.dllS'GetMultipleTrusteeA ADVAPI32.dllt0GetMultipleTrusteeOperationA ADVAPI32.dll0GetMultipleTrusteeOperationW ADVAPI32.dll'GetMultipleTrusteeW ADVAPI32.dll^)GetNamedSecurityInfoA ADVAPI32.dll߈+GetNamedSecurityInfoExA ADVAPI32.dll+GetNamedSecurityInfoExW ADVAPI32.dll)GetNamedSecurityInfoW ADVAPI32.dllɈ.GetNumberOfEventLogRecords ADVAPI32.dllˈ+GetOldestEventLogRecord ADVAPI32.dll.GetOverlappedAccessResults ADVAPI32.dll,GetPrivateObjectSecurity ADVAPI32.dllY0GetSecurityDescriptorControl ADVAPI32.dll-GetSecurityDescriptorDacl ADVAPI32.dll.GetSecurityDescriptorGroup ADVAPI32.dll[/GetSecurityDescriptorLength ADVAPI32.dll.GetSecurityDescriptorOwner ADVAPI32.dll]2GetSecurityDescriptorRMControl ADVAPI32.dll-GetSecurityDescriptorSacl ADVAPI32.dll#GetSecurityInfo ADVAPI32.dll&GetSecurityInfoExA ADVAPI32.dll &GetSecurityInfoExW ADVAPI32.dll*GetServiceDisplayNameA ADVAPI32.dll~*GetServiceDisplayNameW ADVAPI32.dllh&GetServiceKeyNameA ADVAPI32.dll3&GetServiceKeyNameW ADVAPI32.dll-GetSidIdentifierAuthority ADVAPI32.dll(GetSidLengthRequired ADVAPI32.dll(&GetSidSubAuthority ADVAPI32.dll܈+GetSidSubAuthorityCount ADVAPI32.dllɈ0GetStringConditionFromBinary ADVAPI32.dllĈ&GetThreadWaitChain ADVAPI32.dll'GetTokenInformation ADVAPI32.dllf'GetTraceEnableFlags ADVAPI32.dllʈ'GetTraceEnableLevel ADVAPI32.dll(GetTraceLoggerHandle ADVAPI32.dllP#GetTrusteeFormA ADVAPI32.dll4#GetTrusteeFormW ADVAPI32.dll#GetTrusteeNameA ADVAPI32.dllG#GetTrusteeNameW ADVAPI32.dll1#GetTrusteeTypeA ADVAPI32.dll&#GetTrusteeTypeW ADVAPI32.dll  GetUserNameA ADVAPI32.dll  GetUserNameW ADVAPI32.dll.GetWindowsAccountDomainSid ADVAPI32.dll'I_ScSetServiceBitsA ADVAPI32.dll߈'I_ScSetServiceBitsW ADVAPI32.dllɈ+IdentifyCodeAuthzLevelW ADVAPI32.dll-ImpersonateAnonymousToken ADVAPI32.dll+ImpersonateLoggedOnUser ADVAPI32.dllЈ.ImpersonateNamedPipeClient ADVAPI32.dll#ImpersonateSelf ADVAPI32.dll! InitializeAcl ADVAPI32.dll0InitializeSecurityDescriptor ADVAPI32.dllr! InitializeSid ADVAPI32.dll%InitiateShutdownA ADVAPI32.dll=%InitiateShutdownW ADVAPI32.dll'+InitiateSystemShutdownA ADVAPI32.dll-InitiateSystemShutdownExA ADVAPI32.dll-InitiateSystemShutdownExW ADVAPI32.dllՈ+InitiateSystemShutdownW ADVAPI32.dll&InstallApplication ADVAPI32.dllĈ! IsTextUnicode ADVAPI32.dll%IsTokenRestricted ADVAPI32.dll;$IsTokenUntrusted ADVAPI32.dll IsValidAcl ADVAPI32.dllc5!IsValidRelativeSecurityDescriptor ADVAPI32.dll-IsValidSecurityDescriptor ADVAPI32.dllވ IsValidSid ADVAPI32.dllS"IsWellKnownSid ADVAPI32.dll'LockServiceDatabase ADVAPI32.dll LogonUserA ADVAPI32.dll@  LogonUserExA ADVAPI32.dll"LogonUserExExW ADVAPI32.dll  LogonUserExW ADVAPI32.dlli LogonUserW ADVAPI32.dll*&LookupAccountNameA ADVAPI32.dll&LookupAccountNameW ADVAPI32.dll%LookupAccountSidA ADVAPI32.dlli%LookupAccountSidW ADVAPI32.dllS/LookupPrivilegeDisplayNameA ADVAPI32.dllD/LookupPrivilegeDisplayNameW ADVAPI32.dll.(LookupPrivilegeNameA ADVAPI32.dll((LookupPrivilegeNameW ADVAPI32.dll)LookupPrivilegeValueA ADVAPI32.dll)LookupPrivilegeValueW ADVAPI32.dll2LookupSecurityDescriptorPartsA ADVAPI32.dll2LookupSecurityDescriptorPartsW ADVAPI32.dll'LsaAddAccountRights ADVAPI32.dll-LsaAddPrivilegesToAccount ADVAPI32.dll.$LsaClearAuditLog ADVAPI32.dllLsaClose ADVAPI32.dll $LsaCreateAccount ADVAPI32.dll҈#LsaCreateSecret ADVAPI32.dll;*LsaCreateTrustedDomain ADVAPI32.dllP,LsaCreateTrustedDomainEx ADVAPI32.dll LsaDelete ADVAPI32.dll*LsaDeleteTrustedDomain ADVAPI32.dllQ-LsaEnumerateAccountRights ADVAPI32.dll(LsaEnumerateAccounts ADVAPI32.dll5!LsaEnumerateAccountsWithUserRight ADVAPI32.dll*LsaEnumeratePrivileges ADVAPI32.dll'3LsaEnumeratePrivilegesOfAccount ADVAPI32.dll.LsaEnumerateTrustedDomains ADVAPI32.dll0LsaEnumerateTrustedDomainsEx ADVAPI32.dllˆ! LsaFreeMemory ADVAPI32.dll'LsaGetAppliedCAPIDs ADVAPI32.dll:*LsaGetQuotasForAccount ADVAPI32.dllV(LsaGetRemoteUserName ADVAPI32.dll?-LsaGetSystemAccessAccount ADVAPI32.dll"LsaGetUserName ADVAPI32.dll$LsaICLookupNames ADVAPI32.dll-LsaICLookupNamesWithCreds ADVAPI32.dllZ#LsaICLookupSids ADVAPI32.dll\,LsaICLookupSidsWithCreds ADVAPI32.dll#LsaLookupNames2 ADVAPI32.dllU"LsaLookupNames ADVAPI32.dll1LsaLookupPrivilegeDisplayName ADVAPI32.dlla*LsaLookupPrivilegeName ADVAPI32.dllE+LsaLookupPrivilegeValue ADVAPI32.dllLj"LsaLookupSids2 ADVAPI32.dll! LsaLookupSids ADVAPI32.dll+LsaManageSidNameMapping ADVAPI32.dll/)LsaNtStatusToWinError ADVAPI32.dll"LsaOpenAccount ADVAPI32.dll! LsaOpenPolicy ADVAPI32.dll$LsaOpenPolicySce ADVAPI32.dllֈ! LsaOpenSecret ADVAPI32.dll(LsaOpenTrustedDomain ADVAPI32.dll.LsaOpenTrustedDomainByName ADVAPI32.dllΈ  LsaQueryCAPs ADVAPI32.dll3LsaQueryDomainInformationPolicy ADVAPI32.dllq2LsaQueryForestTrustInformation ADVAPI32.dll-LsaQueryInfoTrustedDomain ADVAPI32.dll-LsaQueryInformationPolicy ADVAPI32.dllՈ"LsaQuerySecret ADVAPI32.dll{*LsaQuerySecurityObject ADVAPI32.dll"-LsaQueryTrustedDomainInfo ADVAPI32.dll3LsaQueryTrustedDomainInfoByName ADVAPI32.dll*LsaRemoveAccountRights ADVAPI32.dll;2LsaRemovePrivilegesFromAccount ADVAPI32.dll*LsaRetrievePrivateData ADVAPI32.dllL LsaSetCAPs ADVAPI32.dll1LsaSetDomainInformationPolicy ADVAPI32.dll_0LsaSetForestTrustInformation ADVAPI32.dll+LsaSetInformationPolicy ADVAPI32.dllÈ2LsaSetInformationTrustedDomain ADVAPI32.dll*LsaSetQuotasForAccount ADVAPI32.dllJ  LsaSetSecret ADVAPI32.dlli(LsaSetSecurityObject ADVAPI32.dll-LsaSetSystemAccessAccount ADVAPI32.dll1LsaSetTrustedDomainInfoByName ADVAPI32.dll2LsaSetTrustedDomainInformation ADVAPI32.dll'LsaStorePrivateData ADVAPI32.dll&MIDL_user_free_Ext ADVAPI32.dll:,MSChapSrvChangePassword2 ADVAPI32.dll+MSChapSrvChangePassword ADVAPI32.dll#MakeAbsoluteSD2 ADVAPI32.dll"MakeAbsoluteSD ADVAPI32.dllÈ&MakeSelfRelativeSD ADVAPI32.dll4"MapGenericMask ADVAPI32.dll*NotifyBootConfigStatus ADVAPI32.dll (NotifyChangeEventLog ADVAPI32.dll(-NotifyServiceStatusChange ADVAPI32.dll.NotifyServiceStatusChangeA ADVAPI32.dll.NotifyServiceStatusChangeW ADVAPI32.dll*ObjectCloseAuditAlarmA ADVAPI32.dll*ObjectCloseAuditAlarmW ADVAPI32.dll+ObjectDeleteAuditAlarmA ADVAPI32.dll6+ObjectDeleteAuditAlarmW ADVAPI32.dll )ObjectOpenAuditAlarmA ADVAPI32.dll)ObjectOpenAuditAlarmW ADVAPI32.dll.ObjectPrivilegeAuditAlarmA ADVAPI32.dll܈.ObjectPrivilegeAuditAlarmW ADVAPI32.dllƈ'OpenBackupEventLogA ADVAPI32.dll'OpenBackupEventLogW ADVAPI32.dll)OpenEncryptedFileRawA ADVAPI32.dllވ)OpenEncryptedFileRawW ADVAPI32.dllȈ! OpenEventLogA ADVAPI32.dll"! OpenEventLogW ADVAPI32.dll $OpenProcessToken ADVAPI32.dll"OpenSCManagerA ADVAPI32.dll"OpenSCManagerW ADVAPI32.dll݈  OpenServiceA ADVAPI32.dllw  OpenServiceW ADVAPI32.dlla#OpenThreadToken ADVAPI32.dll*.OpenThreadWaitChainSession ADVAPI32.dll OpenTraceA ADVAPI32.dll] OpenTraceW ADVAPI32.dllG  OperationEnd ADVAPI32.dllS"OperationStart ADVAPI32.dllX#PerfAddCounters ADVAPI32.dll,(PerfCloseQueryHandle ADVAPI32.dll&&PerfCreateInstance ADVAPI32.dll2PerfDecrementULongCounterValue ADVAPI32.dll6"PerfDecrementULongLongCounterValue ADVAPI32.dlly&PerfDeleteCounters ADVAPI32.dll܈&PerfDeleteInstance ADVAPI32.dll+PerfEnumerateCounterSet ADVAPI32.dllƈ4 PerfEnumerateCounterSetInstances ADVAPI32.dll 2PerfIncrementULongCounterValue ADVAPI32.dll6"PerfIncrementULongLongCounterValue ADVAPI32.dllk'PerfOpenQueryHandle ADVAPI32.dll(PerfQueryCounterData ADVAPI32.dll(PerfQueryCounterInfo ADVAPI32.dll7#PerfQueryCounterSetRegistrationInfo ADVAPI32.dll%PerfQueryInstance ADVAPI32.dll9#PerfRegCloseKey ADVAPI32.dllK"PerfRegEnumKey ADVAPI32.dll$PerfRegEnumValue ADVAPI32.dllֈ'PerfRegQueryInfoKey ADVAPI32.dll%PerfRegQueryValue ADVAPI32.dllS#PerfRegSetValue ADVAPI32.dllA*PerfSetCounterRefValue ADVAPI32.dllT)PerfSetCounterSetInfo ADVAPI32.dll,PerfSetULongCounterValue ADVAPI32.dll0PerfSetULongLongCounterValue ADVAPI32.dll%PerfStartProvider ADVAPI32.dll+'PerfStartProviderEx ADVAPI32.dllj$PerfStopProvider ADVAPI32.dll"PrivilegeCheck ADVAPI32.dll0PrivilegedServiceAuditAlarmA ADVAPI32.dll0PrivilegedServiceAuditAlarmW ADVAPI32.dll  ProcessTrace ADVAPI32.dllM#QueryAllTracesA ADVAPI32.dllC#QueryAllTracesW ADVAPI32.dll-6"QueryRecoveryAgentsOnEncryptedFile ADVAPI32.dll=+QuerySecurityAccessMask ADVAPI32.dll(QueryServiceConfig2A ADVAPI32.dll[(QueryServiceConfig2W ADVAPI32.dllE'QueryServiceConfigA ADVAPI32.dll'QueryServiceConfigW ADVAPI32.dlly2QueryServiceDynamicInformation ADVAPI32.dllň+QueryServiceLockStatusA ADVAPI32.dllЈ+QueryServiceLockStatusW ADVAPI32.dll.QueryServiceObjectSecurity ADVAPI32.dlli&QueryServiceStatus ADVAPI32.dll(QueryServiceStatusEx ADVAPI32.dll QueryTraceA ADVAPI32.dll׈ QueryTraceW ADVAPI32.dll-QueryUsersOnEncryptedFile ADVAPI32.dll(ReadEncryptedFileRaw ADVAPI32.dll7! ReadEventLogA ADVAPI32.dll8! ReadEventLogW ADVAPI32.dll" RegCloseKey ADVAPI32.dll'RegConnectRegistryA ADVAPI32.dll)RegConnectRegistryExA ADVAPI32.dllʈ)RegConnectRegistryExW ADVAPI32.dll'RegConnectRegistryW ADVAPI32.dllu  RegCopyTreeA ADVAPI32.dll  RegCopyTreeW ADVAPI32.dll{! RegCreateKeyA ADVAPI32.dll=#RegCreateKeyExA ADVAPI32.dll|#RegCreateKeyExW ADVAPI32.dllf+RegCreateKeyTransactedA ADVAPI32.dll +RegCreateKeyTransactedW ADVAPI32.dll ! RegCreateKeyW ADVAPI32.dll'! RegDeleteKeyA ADVAPI32.dll>#RegDeleteKeyExA ADVAPI32.dll}#RegDeleteKeyExW ADVAPI32.dllg+RegDeleteKeyTransactedA ADVAPI32.dll!+RegDeleteKeyTransactedW ADVAPI32.dll &RegDeleteKeyValueA ADVAPI32.dll7&RegDeleteKeyValueW ADVAPI32.dll!! RegDeleteKeyW ADVAPI32.dll("RegDeleteTreeA ADVAPI32.dllՈ"RegDeleteTreeW ADVAPI32.dll#RegDeleteValueA ADVAPI32.dllf#RegDeleteValueW ADVAPI32.dllP-RegDisablePredefinedCache ADVAPI32.dlle/RegDisablePredefinedCacheEx ADVAPI32.dll+RegDisableReflectionKey ADVAPI32.dll*RegEnableReflectionKey ADVAPI32.dlln RegEnumKeyA ADVAPI32.dll! RegEnumKeyExA ADVAPI32.dll?! RegEnumKeyExW ADVAPI32.dll) RegEnumKeyW ADVAPI32.dll! RegEnumValueA ADVAPI32.dll(! RegEnumValueW ADVAPI32.dll RegFlushKey ADVAPI32.dllԈ%RegGetKeySecurity ADVAPI32.dllR  RegGetValueA ADVAPI32.dll  RegGetValueW ADVAPI32.dll"RegLoadAppKeyA ADVAPI32.dll"RegLoadAppKeyW ADVAPI32.dll؈ RegLoadKeyA ADVAPI32.dll RegLoadKeyW ADVAPI32.dll%RegLoadMUIStringA ADVAPI32.dllЈ%RegLoadMUIStringW ADVAPI32.dll+RegNotifyChangeKeyValue ADVAPI32.dll&RegOpenCurrentUser ADVAPI32.dll݈ RegOpenKeyA ADVAPI32.dll! RegOpenKeyExA ADVAPI32.dllB! RegOpenKeyExW ADVAPI32.dll,)RegOpenKeyTransactedA ADVAPI32.dll)RegOpenKeyTransactedW ADVAPI32.dllЈ RegOpenKeyW ADVAPI32.dll*RegOpenUserClassesRoot ADVAPI32.dllF(RegOverridePredefKey ADVAPI32.dll.$RegQueryInfoKeyA ADVAPI32.dll$RegQueryInfoKeyW ADVAPI32.dllӈ+RegQueryMultipleValuesA ADVAPI32.dllԈ+RegQueryMultipleValuesW ADVAPI32.dll)RegQueryReflectionKey ADVAPI32.dll"RegQueryValueA ADVAPI32.dll$RegQueryValueExA ADVAPI32.dll$RegQueryValueExW ADVAPI32.dllΈ"RegQueryValueW ADVAPI32.dll  RegRenameKey ADVAPI32.dll|"RegReplaceKeyA ADVAPI32.dllӈ"RegReplaceKeyW ADVAPI32.dll"RegRestoreKeyA ADVAPI32.dll"RegRestoreKeyW ADVAPI32.dll RegSaveKeyA ADVAPI32.dll! RegSaveKeyExA ADVAPI32.dllE! RegSaveKeyExW ADVAPI32.dll/ RegSaveKeyW ADVAPI32.dll%RegSetKeySecurity ADVAPI32.dllF#RegSetKeyValueA ADVAPI32.dlld#RegSetKeyValueW ADVAPI32.dllN  RegSetValueA ADVAPI32.dll"RegSetValueExA ADVAPI32.dll҈"RegSetValueExW ADVAPI32.dll  RegSetValueW ADVAPI32.dll}! RegUnLoadKeyA ADVAPI32.dllN! RegUnLoadKeyW ADVAPI32.dll8(RegisterEventSourceA ADVAPI32.dll(RegisterEventSourceW ADVAPI32.dll/RegisterServiceCtrlHandlerA ADVAPI32.dllS1RegisterServiceCtrlHandlerExA ADVAPI32.dll1RegisterServiceCtrlHandlerExW ADVAPI32.dll|/RegisterServiceCtrlHandlerW ADVAPI32.dll='RegisterTraceGuidsA ADVAPI32.dll'RegisterTraceGuidsW ADVAPI32.dll0RegisterWaitChainCOMCallback ADVAPI32.dllR+RemoteRegEnumKeyWrapper ADVAPI32.dll܈-RemoteRegEnumValueWrapper ADVAPI32.dll0RemoteRegQueryInfoKeyWrapper ADVAPI32.dllň.RemoteRegQueryValueWrapper ADVAPI32.dll'RemoveTraceCallback ADVAPI32.dll0RemoveUsersFromEncryptedFile ADVAPI32.dll  ReportEventA ADVAPI32.dll\  ReportEventW ADVAPI32.dllF  RevertToSelf ADVAPI32.dllV-SafeBaseRegGetKeySecurity ADVAPI32.dllH#SaferCloseLevel ADVAPI32.dll6.SaferComputeTokenFromLevel ADVAPI32.dll$SaferCreateLevel ADVAPI32.dllֈ,SaferGetLevelInformation ADVAPI32.dllt-SaferGetPolicyInformation ADVAPI32.dll&SaferIdentifyLevel ADVAPI32.dll,SaferRecordEventLogEntry ADVAPI32.dll},SaferSetLevelInformation ADVAPI32.dllh-SaferSetPolicyInformation ADVAPI32.dll.SaferiIsExecutableFileType ADVAPI32.dllň%SetAclInformation ADVAPI32.dllO,SetEncryptedFileMetadata ADVAPI32.dll+SetEntriesInAccessListA ADVAPI32.dll+SetEntriesInAccessListW ADVAPI32.dll$SetEntriesInAclA ADVAPI32.dll$SetEntriesInAclW ADVAPI32.dll*SetEntriesInAuditListA ADVAPI32.dllv*SetEntriesInAuditListW ADVAPI32.dll`$SetFileSecurityA ADVAPI32.dllΈ$SetFileSecurityW ADVAPI32.dll1SetInformationCodeAuthzLevelW ADVAPI32.dllq2SetInformationCodeAuthzPolicyW ADVAPI32.dll+SetKernelObjectSecurity ADVAPI32.dllɈ)SetNamedSecurityInfoA ADVAPI32.dllӈ+SetNamedSecurityInfoExA ADVAPI32.dll+SetNamedSecurityInfoExW ADVAPI32.dll)SetNamedSecurityInfoW ADVAPI32.dll,SetPrivateObjectSecurity ADVAPI32.dllM.SetPrivateObjectSecurityEx ADVAPI32.dll)SetSecurityAccessMask ADVAPI32.dll0SetSecurityDescriptorControl ADVAPI32.dllw-SetSecurityDescriptorDacl ADVAPI32.dll.SetSecurityDescriptorGroup ADVAPI32.dllO.SetSecurityDescriptorOwner ADVAPI32.dllQ2SetSecurityDescriptorRMControl ADVAPI32.dllԈ-SetSecurityDescriptorSacl ADVAPI32.dllۈ#SetSecurityInfo ADVAPI32.dll&SetSecurityInfoExA ADVAPI32.dll&SetSecurityInfoExW ADVAPI32.dll"SetServiceBits ADVAPI32.dll,SetServiceObjectSecurity ADVAPI32.dllW$SetServiceStatus ADVAPI32.dll"SetThreadToken ADVAPI32.dll'SetTokenInformation ADVAPI32.dllZ$SetTraceCallback ADVAPI32.dll,SetUserFileEncryptionKey ADVAPI32.dlld.SetUserFileEncryptionKeyEx ADVAPI32.dll! StartServiceA ADVAPI32.dll/StartServiceCtrlDispatcherA ADVAPI32.dllA/StartServiceCtrlDispatcherW ADVAPI32.dll+! StartServiceW ADVAPI32.dll StartTraceA ADVAPI32.dll߈ StartTraceW ADVAPI32.dllɈ StopTraceA ADVAPI32.dllI StopTraceW ADVAPI32.dll3%SystemFunction001 ADVAPI32.dll%SystemFunction002 ADVAPI32.dll%SystemFunction003 ADVAPI32.dll%SystemFunction004 ADVAPI32.dll%SystemFunction005 ADVAPI32.dll%SystemFunction006 ADVAPI32.dll%SystemFunction007 ADVAPI32.dll%SystemFunction008 ADVAPI32.dll%SystemFunction009 ADVAPI32.dll%SystemFunction010 ADVAPI32.dll%SystemFunction011 ADVAPI32.dll%SystemFunction012 ADVAPI32.dll%SystemFunction013 ADVAPI32.dll%SystemFunction014 ADVAPI32.dll%SystemFunction015 ADVAPI32.dll%SystemFunction016 ADVAPI32.dll%SystemFunction017 ADVAPI32.dll%SystemFunction018 ADVAPI32.dll%SystemFunction019 ADVAPI32.dll%SystemFunction020 ADVAPI32.dll%SystemFunction021 ADVAPI32.dll%SystemFunction022 ADVAPI32.dll%SystemFunction023 ADVAPI32.dll%SystemFunction024 ADVAPI32.dll%SystemFunction025 ADVAPI32.dll%SystemFunction026 ADVAPI32.dll%SystemFunction027 ADVAPI32.dll%SystemFunction028 ADVAPI32.dll%SystemFunction029 ADVAPI32.dll%SystemFunction030 ADVAPI32.dll%SystemFunction031 ADVAPI32.dll%SystemFunction032 ADVAPI32.dll%SystemFunction033 ADVAPI32.dll%SystemFunction034 ADVAPI32.dll%SystemFunction036 ADVAPI32.dll%SystemFunction040 ADVAPI32.dll%SystemFunction041 ADVAPI32.dll TraceEvent ADVAPI32.dll.&TraceEventInstance ADVAPI32.dll- _TraceMessage ADVAPI32.dll TraceMessage:"TraceMessageVa ADVAPI32.dll)TraceQueryInformation ADVAPI32.dll~'TraceSetInformation ADVAPI32.dlll/TreeResetNamedSecurityInfoA ADVAPI32.dll`/TreeResetNamedSecurityInfoW ADVAPI32.dllJ-TreeSetNamedSecurityInfoA ADVAPI32.dll;-TreeSetNamedSecurityInfoW ADVAPI32.dll%*TrusteeAccessToObjectA ADVAPI32.dlln*TrusteeAccessToObjectW ADVAPI32.dllX(UninstallApplication ADVAPI32.dll݈)UnlockServiceDatabase ADVAPI32.dll(UnregisterTraceGuids ADVAPI32.dll  UpdateTraceA ADVAPI32.dll  UpdateTraceW ADVAPI32.dllr,UsePinForEncryptedFilesA ADVAPI32.dll,UsePinForEncryptedFilesW ADVAPI32.dll$WaitServiceState ADVAPI32.dll)WriteEncryptedFileRaw ADVAPI32.dll