Loading

Kernel32.dll API

一、参考文档

API介绍链接:https://www.geoffchappell.com/studies/windows/win32/kernel32/api/index.htm

dumpbin的使用方法:https://blog.csdn.net/xiaoQL520/article/details/68928500

二、前言   

    Kernel32.dll包含一些Win32应用程序常用的函数,提供应用程序一些Win32下的基底API,包括存储器管理、输入/输出操作和同步函数。它们大部分函数皆由原生应用程序实现。

三、开始

    要查看kernel32.dll有哪些函数可用,需要使用VS自带的工具dumpbin,在VS的工具选项->外部工具中可以找到。如果没有找到,可以到VS安装路径中去寻找,在 VS/VC/bin 文件夹里可以找到dumpbin.exe 。

    Kernel32.dll的路径一般是 : C:\windows\system32\kernel32.dll

在该路径下运行cmd输入:

dumpbin /exports c:\windows\system32\kernel32.dll

    窗口输出的就是当前系统的Kernel32.dll提供的API(各个系统版本会不一样,文章内容运行环境是Win10 1909 )

输出:

Microsoft Windows [版本 10.0.18363.720]
(c) 2019 Microsoft Corporation。保留所有权利。

E:\VS2015\VC\bin>dumpbin /exports C:\Windows\System32\kernel32.dll
Microsoft (R) COFF/PE Dumper Version 14.00.24215.1
Copyright (C) Microsoft Corporation.  All rights reserved.


Dump of file C:\Windows\System32\kernel32.dll

File Type: DLL

  Section contains the following exports for KERNEL32.dll
characteristics
    D0CECC10 time date stamp
        0.00 version
ordinal base
number of functions
number of names

    ordinal hint RVA      name
   0          AcquireSRWLockExclusive (forwarded to NTDLL.RtlAcquireSRWLockExclusive)
   1          AcquireSRWLockShared (forwarded to NTDLL.RtlAcquireSRWLockShared)
   2 0001E640 ActivateActCtx
   3 0001A950 ActivateActCtxWorker
   4 00021650 AddAtomA
   5 00010840 AddAtomW
   6 00022B70 AddConsoleAliasA
   7 00022B80 AddConsoleAliasW
   8          AddDllDirectory (forwarded to api-ms-win-core-libraryloader-l1-1-0.AddDllDirectory)
   9 00036C80 AddIntegrityLabelToBoundaryDescriptor
   A 00052C10 AddLocalAlternateComputerNameA
   B 00052C70 AddLocalAlternateComputerNameW
   C 0001FE40 AddRefActCtx
   D 0001CF70 AddRefActCtxWorker
   E 00035610 AddResourceAttributeAce
   F 0001ECF0 AddSIDToBoundaryDescriptor
  10 00035620 AddScopedPolicyIDAce
  11 00033CD0 AddSecureMemoryCacheCallback
  12          AddVectoredContinueHandler (forwarded to NTDLL.RtlAddVectoredContinueHandler)
  13          AddVectoredExceptionHandler (forwarded to NTDLL.RtlAddVectoredExceptionHandler)
  14 00003A60 AdjustCalendarDate
  15 000227C0 AllocConsole
  16 00035640 AllocateUserPhysicalPages
  17 00035630 AllocateUserPhysicalPagesNuma
  18          AppPolicyGetClrCompat (forwarded to kernelbase.AppPolicyGetClrCompat)
  19          AppPolicyGetCreateFileAccess (forwarded to kernelbase.AppPolicyGetCreateFileAccess)
  1A          AppPolicyGetLifecycleManagement (forwarded to kernelbase.AppPolicyGetLifecycleManagement)
  1B          AppPolicyGetMediaFoundationCodecLoading (forwarded to kernelbase.AppPolicyGetMediaFoundationCodecLoading)
  1C          AppPolicyGetProcessTerminationMethod (forwarded to kernelbase.AppPolicyGetProcessTerminationMethod)
  1D          AppPolicyGetShowDeveloperDiagnostic (forwarded to kernelbase.AppPolicyGetShowDeveloperDiagnostic)
  1E          AppPolicyGetThreadInitializationType (forwarded to kernelbase.AppPolicyGetThreadInitializationType)
  1F          AppPolicyGetWindowingModel (forwarded to kernelbase.AppPolicyGetWindowingModel)
  20          AppXGetOSMaxVersionTested (forwarded to kernelbase.AppXGetOSMaxVersionTested)
  21 0003D590 ApplicationRecoveryFinished
  22 0003D5A0 ApplicationRecoveryInProgress
  23 0001EFD0 AreFileApisANSI
  24 0001E4A0 AssignProcessToJobObject
  25 000227D0 AttachConsole
  26 000552E0 BackupRead
  27 00056370 BackupSeek
  28 00056640 BackupWrite
  29 000356B0 BaseCheckAppcompatCache
  2A 00035650 BaseCheckAppcompatCacheEx
  2B 0001EEF0 BaseCheckAppcompatCacheExWorker
  2C 0001EEF0 BaseCheckAppcompatCacheWorker
  2D 000025E0 BaseCheckElevation
  2E 000356C0 BaseCleanupAppcompatCacheSupport
  2F 0001F220 BaseCleanupAppcompatCacheSupportWorker
  30 0003A1E0 BaseDestroyVDMEnvironment
  31 00008750 BaseDllReadWriteIniFile
  32 000356D0 BaseDumpAppcompatCache
  33 00022EC0 BaseDumpAppcompatCacheWorker
  34 0001C480 BaseElevationPostProcessing
  35 000356E0 BaseFlushAppcompatCache
  36 000673F0 BaseFlushAppcompatCacheWorker
  37 00021D90 BaseFormatObjectAttributes
  38 00052450 BaseFormatTimeOut
  39 0001E5D0 BaseFreeAppCompatDataForProcessWorker
  3A 00017450 BaseGenerateAppCompatData
  3B 000356F0 BaseGetNamedObjectDirectory
  3C 00035700 BaseInitAppcompatCacheSupport
  3D 0001F220 BaseInitAppcompatCacheSupportWorker
  3E 0001EEF0 BaseIsAppcompatInfrastructureDisabled
  3F 0001EEF0 BaseIsAppcompatInfrastructureDisabledWorker
  40 00058EF0 BaseIsDosApplication
  41 000677F0 BaseQueryModuleData
  42 0001FED0 BaseReadAppCompatDataForProcessWorker
  43 00010F80 BaseSetLastNTError
  44 00017BC0 BaseThreadInitThunk
  45 00035710 BaseUpdateAppcompatCache
  46 00067450 BaseUpdateAppcompatCacheWorker
  47 0003A4F0 BaseUpdateVDMEntry
  48 000524E0 BaseVerifyUnicodeString
  49 00057800 BaseWriteErrorElevationRequiredEvent
  4A 0001AEC0 Basep8BitStringToDynamicUnicodeString
  4B 00052540 BasepAllocateActivationContextActivationBlock
  4C 00052480 BasepAnsiStringToDynamicUnicodeString
  4D 00018960 BasepAppContainerEnvironmentExtension
  4E 0001E8E0 BasepAppXExtension
  4F 000017B0 BasepCheckAppCompat
  50 0001BFA0 BasepCheckWebBladeHashes
  51 0000D230 BasepCheckWinSaferRestrictions
  52 0000A5F0 BasepConstructSxsCreateProcessMessage
  53 00033820 BasepCopyEncryption
  54 000526B0 BasepFreeActivationContextActivationBlock
  55 0001AF20 BasepFreeAppCompatData
  56 00016AE0 BasepGetAppCompatData
  57 0001D7F0 BasepGetComputerNameFromNtPath
  58 00001EA0 BasepGetExeArchType
  59 00067520 BasepInitAppCompatData
  5A 0001B090 BasepIsProcessAllowed
  5B 0000FFF0 BasepMapModuleHandle
  5C 0001A990 BasepNotifyLoadStringResource
  5D 0001EED0 BasepPostSuccessAppXExtension
  5E 00034790 BasepProcessInvalidImage
  5F 00009820 BasepQueryAppCompat
  60 000675B0 BasepQueryModuleChpeSettings
  61 0001EEC0 BasepReleaseAppXContext
  62 0000E770 BasepReleaseSxsCreateProcessUtilityStruct
  63 0003D850 BasepReportFault
  64 0001D210 BasepSetFileEncryptionCompression
  65 00032D10 Beep
  66 000430E0 BeginUpdateResourceA
  67 00043140 BeginUpdateResourceW
  68 000215D0 BindIoCompletionCallback
  69 0003BF10 BuildCommDCBA
  6A 0003BF40 BuildCommDCBAndTimeoutsA
  6B 0003BF70 BuildCommDCBAndTimeoutsW
  6C 0003BFE0 BuildCommDCBW
  6D 00059670 CallNamedPipeA
  6E 00022560 CallNamedPipeW
  6F 00035720 CallbackMayRunLong
  70 000346E0 CancelDeviceWakeupRequest
  71 0001EF30 CancelIo
  72 0001E740 CancelIoEx
  73 00035750 CancelSynchronousIo
  74          CancelThreadpoolIo (forwarded to NTDLL.TpCancelAsyncIoOperation)
  75 0003D7D0 CancelTimerQueueTimer
  76 00021E50 CancelWaitableTimer
  77          CeipIsOptedIn (forwarded to kernelbase.CeipIsOptedIn)
  78 0001F140 ChangeTimerQueueTimer
  79 00035760 CheckAllowDecryptedRemoteDestinationPolicy
  7A 00002070 CheckElevation
  7B 0001EB20 CheckElevationEnabled
  7C 00059B00 CheckForReadOnlyResource
  7D 00036CB0 CheckForReadOnlyResourceFilter
  7E 00034520 CheckNameLegalDOS8Dot3A
  7F 000345C0 CheckNameLegalDOS8Dot3W
  80 00001160 CheckRemoteDebuggerPresent
  81 00035770 CheckTokenCapability
  82 00035780 CheckTokenMembershipEx
  83 000225C0 ClearCommBreak
  84 000225D0 ClearCommError
  85 00060D30 CloseConsoleHandle
  86 00021E10 CloseHandle
  87          ClosePackageInfo (forwarded to kernelbase.ClosePackageInfo)
  88 0001FDF0 ClosePrivateNamespace
  89 0001F220 CloseProfileUserMapping
  8A 000227E0 ClosePseudoConsole
  8B          CloseState (forwarded to kernelbase.CloseState)
  8C          CloseThreadpool (forwarded to NTDLL.TpReleasePool)
  8D          CloseThreadpoolCleanupGroup (forwarded to NTDLL.TpReleaseCleanupGroup)
  8E          CloseThreadpoolCleanupGroupMembers (forwarded to NTDLL.TpReleaseCleanupGroupMembers)
  8F          CloseThreadpoolIo (forwarded to NTDLL.TpReleaseIoCompletion)
  90          CloseThreadpoolTimer (forwarded to NTDLL.TpReleaseTimer)
  91          CloseThreadpoolWait (forwarded to NTDLL.TpReleaseWait)
  92          CloseThreadpoolWork (forwarded to NTDLL.TpReleaseWork)
  93 0001E680 CmdBatNotification
  94 00037A10 CommConfigDialogA
  95 00037AA0 CommConfigDialogW
  96 000439F0 CompareCalendarDates
  97 00022040 CompareFileTime
  98 0001CD10 CompareStringA
  99 00016720 CompareStringEx
  9A 00016A40 CompareStringOrdinal
  9B 0001A790 CompareStringW
  9C 0001EF80 ConnectNamedPipe
  9D 00060E40 ConsoleMenuControl
  9E 00035790 ContinueDebugEvent
  9F 00043AA0 ConvertCalDateTimeToSystemTime
  A0 000357A0 ConvertDefaultLocale
  A1 00022710 ConvertFiberToThread
  A2 00043B90 ConvertNLSDayOfWeekToWin32DayOfWeek
  A3 00003D10 ConvertSystemTimeToCalDateTime
  A4 00022720 ConvertThreadToFiber
  A5 00022730 ConvertThreadToFiberEx
  A6 000357B0 CopyContext
  A7 000357C0 CopyFile2
  A8 00059E10 CopyFileA
  A9 00059EA0 CopyFileExA
  AA 0001EA20 CopyFileExW
  AB 00059F50 CopyFileTransactedA
  AC 0005A020 CopyFileTransactedW
  AD 00022700 CopyFileW
  AE 00032E90 CopyLZFile
  AF 0001F690 CreateActCtxA
  B0 0001F040 CreateActCtxW
  B1 0000E830 CreateActCtxWWorker
  B2 00059CB0 CreateBoundaryDescriptorA
  B3 0001ECB0 CreateBoundaryDescriptorW
  B4 00022900 CreateConsoleScreenBuffer
  B5 00022050 CreateDirectoryA
  B6 0005A960 CreateDirectoryExA
  B7 000357D0 CreateDirectoryExW
  B8 000331B0 CreateDirectoryTransactedA
  B9 0005A9E0 CreateDirectoryTransactedW
  BA 00022060 CreateDirectoryW
  BB          CreateEnclave (forwarded to api-ms-win-core-enclave-l1-1-0.CreateEnclave)
  BC 00021E60 CreateEventA
  BD 00021E70 CreateEventExA
  BE 00021E80 CreateEventExW
  BF 00021E90 CreateEventW
  C0 00022740 CreateFiber
  C1 00022750 CreateFiberEx
  C2 00022070 CreateFile2
  C3 00022080 CreateFileA
  C4 0001AB30 CreateFileMappingA
  C5          CreateFileMappingFromApp (forwarded to api-ms-win-core-memory-l1-1-1.CreateFileMappingFromApp)
  C6 0005AB50 CreateFileMappingNumaA
  C7 000357E0 CreateFileMappingNumaW
  C8 0001C250 CreateFileMappingW
  C9 0005A100 CreateFileTransactedA
  CA 0005A1C0 CreateFileTransactedW
  CB 00022090 CreateFileW
  CC 000357F0 CreateHardLinkA
  CD 0003CFE0 CreateHardLinkTransactedA
  CE 0005AC10 CreateHardLinkTransactedW
  CF 00021550 CreateHardLinkW
  D0 0001CA20 CreateIoCompletionPort
  D1 000548D0 CreateJobObjectA
  D2 0001CC80 CreateJobObjectW
  D3 00054940 CreateJobSet
  D4 0001ACC0 CreateMailslotA
  D5 0001AD30 CreateMailslotW
  D6 0001ED10 CreateMemoryResourceNotification
  D7 00021EA0 CreateMutexA
  D8 00021EB0 CreateMutexExA
  D9 00021EC0 CreateMutexExW
  DA 00021ED0 CreateMutexW
  DB 00059700 CreateNamedPipeA
  DC 0001E910 CreateNamedPipeW
  DD 0001EB10 CreatePipe
  DE 00059D10 CreatePrivateNamespaceA
  DF 0001EC90 CreatePrivateNamespaceW
  E0 0001B660 CreateProcessA
  E1 00035800 CreateProcessAsUserA
  E2 0001C950 CreateProcessAsUserW
  E3 00035870 CreateProcessInternalA
  E4 000358F0 CreateProcessInternalW
  E5 0001BE40 CreateProcessW
  E6 000227F0 CreatePseudoConsole
  E7 00035970 CreateRemoteThread
  E8          CreateRemoteThreadEx (forwarded to api-ms-win-core-processthreads-l1-1-0.CreateRemoteThreadEx)
  E9 0001ABF0 CreateSemaphoreA
  EA 0001AC20 CreateSemaphoreExA
  EB 00021EE0 CreateSemaphoreExW
  EC 00021EF0 CreateSemaphoreW
  ED 0005B180 CreateSymbolicLinkA
  EE 0005B220 CreateSymbolicLinkTransactedA
  EF 0005B2D0 CreateSymbolicLinkTransactedW
  F0 00021640 CreateSymbolicLinkW
  F1 0003CD20 CreateTapePartition
  F2 0001A810 CreateThread
  F3 0001E9C0 CreateThreadpool
  F4 0001EA70 CreateThreadpoolCleanupGroup
  F5 00021670 CreateThreadpoolIo
  F6 0001B710 CreateThreadpoolTimer
  F7 0001EE80 CreateThreadpoolWait
  F8 0001E960 CreateThreadpoolWork
  F9 0001F0D0 CreateTimerQueue
  FA 0001CF50 CreateTimerQueueTimer
  FB 00023120 CreateToolhelp32Snapshot
  FC 0003BB60 CreateUmsCompletionList
  FD 0003BB90 CreateUmsThreadContext
  FE 0005AE30 CreateWaitableTimerA
  FF 0005AE50 CreateWaitableTimerExA
 100 00021F00 CreateWaitableTimerExW
 101 00001090 CreateWaitableTimerW
 102          CtrlRoutine (forwarded to kernelbase.CtrlRoutine)
 103 0001E650 DeactivateActCtx
 104 0001A9A0 DeactivateActCtxWorker
 105 000359D0 DebugActiveProcess
 106 000359C0 DebugActiveProcessStop
 107 000359E0 DebugBreak
 108 000330A0 DebugBreakProcess
 109 000330D0 DebugSetProcessKillOnExit
 10A          DecodePointer (forwarded to NTDLL.RtlDecodePointer)
 10B          DecodeSystemPointer (forwarded to NTDLL.RtlDecodeSystemPointer)
 10C 0005C850 DefineDosDeviceA
 10D 000220A0 DefineDosDeviceW
 10E 00021630 DelayLoadFailureHook
 10F 000107A0 DeleteAtom
 110 0001ECA0 DeleteBoundaryDescriptor
 111          DeleteCriticalSection (forwarded to NTDLL.RtlDeleteCriticalSection)
 112 00022760 DeleteFiber
 113 000220B0 DeleteFileA
 114 0005B380 DeleteFileTransactedA
 115 00021470 DeleteFileTransactedW
 116 000220C0 DeleteFileW
 117          DeleteProcThreadAttributeList (forwarded to api-ms-win-core-processthreads-l1-1-0.DeleteProcThreadAttributeList)
 118 000359F0 DeleteSynchronizationBarrier
 119 0001F0E0 DeleteTimerQueue
 11A 0001F130 DeleteTimerQueueEx
 11B 0001E950 DeleteTimerQueueTimer
 11C 0003BBC0 DeleteUmsCompletionList
 11D 0003BBF0 DeleteUmsThreadContext
 11E 0005CAC0 DeleteVolumeMountPointA
 11F 000220D0 DeleteVolumeMountPointW
 120 0003BC20 DequeueUmsCompletionListItems
 121 00016360 DeviceIoControl
 122 0001E760 DisableThreadLibraryCalls
 123 0003D880 DisableThreadProfiling
 124          DisassociateCurrentThreadFromCallback (forwarded to NTDLL.TpDisassociateCallback)
 125          DiscardVirtualMemory (forwarded to api-ms-win-core-memory-l1-1-2.DiscardVirtualMemory)
 126 00020650 DisconnectNamedPipe
 127 000539B0 DnsHostnameToComputerNameA
 128 00035A00 DnsHostnameToComputerNameExW
 129 0001B1E0 DnsHostnameToComputerNameW
 12A 000109C0 DosDateTimeToFileTime
 12B 0005DC40 DosPathToSessionPathA
 12C 0005DDF0 DosPathToSessionPathW
 12D 00060D40 DuplicateConsoleHandle
 12E 00033B10 DuplicateEncryptionInfoFileExt
 12F 00021E20 DuplicateHandle
 130 0003D8B0 EnableThreadProfiling
 131          EncodePointer (forwarded to NTDLL.RtlEncodePointer)
 132          EncodeSystemPointer (forwarded to NTDLL.RtlEncodeSystemPointer)
 133 00043350 EndUpdateResourceA
 134 00043360 EndUpdateResourceW
 135          EnterCriticalSection (forwarded to NTDLL.RtlEnterCriticalSection)
 136 00035A10 EnterSynchronizationBarrier
 137 0003BC70 EnterUmsSchedulingMode
 138 00044620 EnumCalendarInfoA
 139 000446B0 EnumCalendarInfoExA
 13A 0001BC40 EnumCalendarInfoExEx
 13B 00035A20 EnumCalendarInfoExW
 13C 00035A30 EnumCalendarInfoW
 13D 00044740 EnumDateFormatsA
 13E 000447A0 EnumDateFormatsExA
 13F 00035A40 EnumDateFormatsExEx
 140 00035A50 EnumDateFormatsExW
 141 00035A60 EnumDateFormatsW
 142 00044800 EnumLanguageGroupLocalesA
 143 00035A70 EnumLanguageGroupLocalesW
 144 00033EC0 EnumResourceLanguagesA
 145 00035A80 EnumResourceLanguagesExA
 146 00035AA0 EnumResourceLanguagesExW
 147 00033EF0 EnumResourceLanguagesW
 148 00033F20 EnumResourceNamesA
 149 00035AC0 EnumResourceNamesExA
 14A 00035AE0 EnumResourceNamesExW
 14B 00022540 EnumResourceNamesW
 14C 00033F50 EnumResourceTypesA
 14D 00035B00 EnumResourceTypesExA
 14E 00035B20 EnumResourceTypesExW
 14F 00033F70 EnumResourceTypesW
 150 00044820 EnumSystemCodePagesA
 151 00035B40 EnumSystemCodePagesW
 152 00033D00 EnumSystemFirmwareTables
 153 0004D1F0 EnumSystemGeoID
 154 0004D2D0 EnumSystemGeoNames
 155 00044830 EnumSystemLanguageGroupsA
 156 00035B50 EnumSystemLanguageGroupsW
 157 00035B60 EnumSystemLocalesA
 158 00035B70 EnumSystemLocalesEx
 159 00035B80 EnumSystemLocalesW
 15A 00044840 EnumTimeFormatsA
 15B 0001EA60 EnumTimeFormatsEx
 15C 00035B90 EnumTimeFormatsW
 15D 000448B0 EnumUILanguagesA
 15E 00035BA0 EnumUILanguagesW
 15F 00053A90 EnumerateLocalComputerNamesA
 160 00053BA0 EnumerateLocalComputerNamesW
 161 0003CD80 EraseTape
 162 000225E0 EscapeCommFunction
 163 0003BD10 ExecuteUmsThread
 164 0001CD80 ExitProcess
 165          ExitThread (forwarded to NTDLL.RtlExitUserThread)
 166 0003A760 ExitVDM
 167 00035BB0 ExpandEnvironmentStringsA
 168 0001AB00 ExpandEnvironmentStringsW
 169 00022B90 ExpungeConsoleCommandHistoryA
 16A 00022BA0 ExpungeConsoleCommandHistoryW
 16B 00035BC0 FatalAppExitA
 16C 00035BD0 FatalAppExitW
 16D 0001CD80 FatalExit
 16E 00010C30 FileTimeToDosDateTime
 16F 000220E0 FileTimeToLocalFileTime
 170 00022580 FileTimeToSystemTime
 171 00022910 FillConsoleOutputAttribute
 172 00022920 FillConsoleOutputCharacterA
 173 00022930 FillConsoleOutputCharacterW
 174 0001B2E0 FindActCtxSectionGuid
 175 00010E50 FindActCtxSectionGuidWorker
 176 0005DF60 FindActCtxSectionStringA
 177 0001F030 FindActCtxSectionStringW
 178 000100F0 FindActCtxSectionStringWWorker
 179 00010820 FindAtomA
 17A 00010C10 FindAtomW
 17B 000220F0 FindClose
 17C 00022100 FindCloseChangeNotification
 17D 00022110 FindFirstChangeNotificationA
 17E 00022120 FindFirstChangeNotificationW
 17F 00022130 FindFirstFileA
 180 00022140 FindFirstFileExA
 181 00022150 FindFirstFileExW
 182 000332A0 FindFirstFileNameTransactedW
 183 00022160 FindFirstFileNameW
 184 00033360 FindFirstFileTransactedA
 185 0005E000 FindFirstFileTransactedW
 186 00022170 FindFirstFileW
 187 00033430 FindFirstStreamTransactedW
 188          FindFirstStreamW (forwarded to api-ms-win-core-file-l1-2-2.FindFirstStreamW)
 189 0005CB00 FindFirstVolumeA
 18A 0005CC70 FindFirstVolumeMountPointA
 18B 0005CE20 FindFirstVolumeMountPointW
 18C 00022180 FindFirstVolumeW
 18D 00035BE0 FindNLSString
 18E 000166C0 FindNLSStringEx
 18F 00022190 FindNextChangeNotification
 190 000221A0 FindNextFileA
 191 000221B0 FindNextFileNameW
 192 000221C0 FindNextFileW
 193          FindNextStreamW (forwarded to api-ms-win-core-file-l1-2-2.FindNextStreamW)
 194 0005D050 FindNextVolumeA
 195 0005D1C0 FindNextVolumeMountPointA
 196 0005D7F0 FindNextVolumeMountPointW
 197 000221D0 FindNextVolumeW
 198          FindPackagesByPackageFamily (forwarded to kernelbase.FindPackagesByPackageFamily)
 199 0000FE10 FindResourceA
 19A 0000FE30 FindResourceExA
 19B 0001AA90 FindResourceExW
 19C 0001E7A0 FindResourceW
 19D 00035BF0 FindStringOrdinal
 19E 000221E0 FindVolumeClose
 19F 0005D800 FindVolumeMountPointClose
 1A0 0001E930 FlsAlloc
 1A1 0001EEE0 FlsFree
 1A2 0001A0C0 FlsGetValue
 1A3 0001BCE0 FlsSetValue
 1A4 00022940 FlushConsoleInputBuffer
 1A5 000221F0 FlushFileBuffers
 1A6 0001A780 FlushInstructionCache
 1A7          FlushProcessWriteBuffers (forwarded to NTDLL.NtFlushProcessWriteBuffers)
 1A8 00035C00 FlushViewOfFile
 1A9 000448C0 FoldStringA
 1AA 00035C10 FoldStringW
 1AB          FormatApplicationUserModelId (forwarded to kernelbase.FormatApplicationUserModelId)
 1AC 0001FCD0 FormatMessageA
 1AD 0001BC80 FormatMessageW
 1AE 00022800 FreeConsole
 1AF 0001E490 FreeEnvironmentStringsA
 1B0 0001E470 FreeEnvironmentStringsW
 1B1 0001BD00 FreeLibrary
 1B2 0001EE00 FreeLibraryAndExitThread
 1B3          FreeLibraryWhenCallbackReturns (forwarded to NTDLL.TpCallbackUnloadDllOnCompletion)
 1B4 00054970 FreeMemoryJobObject
 1B5 0001FAD0 FreeResource
 1B6 00035C20 FreeUserPhysicalPages
 1B7 00022950 GenerateConsoleCtrlEvent
 1B8 0001CD70 GetACP
 1B9 0001C800 GetActiveProcessorCount
 1BA 0005E170 GetActiveProcessorGroupCount
 1BB 00035C30 GetAppContainerAce
 1BC 00035C40 GetAppContainerNamedObjectPath
 1BD 00035C50 GetApplicationRecoveryCallback
 1BE 0003D5B0 GetApplicationRecoveryCallbackWorker
 1BF 00035C60 GetApplicationRestartSettings
 1C0 0003D660 GetApplicationRestartSettingsWorker
 1C1          GetApplicationUserModelId (forwarded to kernelbase.GetApplicationUserModelId)
 1C2 00052B70 GetAtomNameA
 1C3 00010590 GetAtomNameW
 1C4 00058FE0 GetBinaryType
 1C5 00058FE0 GetBinaryTypeA
 1C6 00059030 GetBinaryTypeW
 1C7 0001DD50 GetCPInfo
 1C8 00044B20 GetCPInfoExA
 1C9 00035C70 GetCPInfoExW
 1CA 00035C80 GetCachedSigningLevel
 1CB 00043BC0 GetCalendarDateFormat
 1CC 000042D0 GetCalendarDateFormatEx
 1CD 00003C10 GetCalendarDaysInMonth
 1CE 00043E90 GetCalendarDifferenceInDays
 1CF 00044BE0 GetCalendarInfoA
 1D0 00022590 GetCalendarInfoEx
 1D1 000225A0 GetCalendarInfoW
 1D2 00043FE0 GetCalendarMonthsInYear
 1D3 000039A0 GetCalendarSupportedDateRange
 1D4 000440B0 GetCalendarWeekNumber
 1D5 0003D4F0 GetComPlusPackageInstallStatus
 1D6 000225F0 GetCommConfig
 1D7 00022600 GetCommMask
 1D8 00022610 GetCommModemStatus
 1D9 00022620 GetCommProperties
 1DA 00022630 GetCommState
 1DB 00022640 GetCommTimeouts
 1DC 0001E750 GetCommandLineA
 1DD 0001DE80 GetCommandLineW
 1DE 00035C90 GetCompressedFileSizeA
 1DF 0005B3D0 GetCompressedFileSizeTransactedA
 1E0 0005B430 GetCompressedFileSizeTransactedW
 1E1 00035CA0 GetCompressedFileSizeW
 1E2 0000C610 GetComputerNameA
 1E3 00021600 GetComputerNameExA
 1E4 0001E780 GetComputerNameExW
 1E5 0000C760 GetComputerNameW
 1E6 00022BB0 GetConsoleAliasA
 1E7 00022BC0 GetConsoleAliasExesA
 1E8 00022BD0 GetConsoleAliasExesLengthA
 1E9 00022BE0 GetConsoleAliasExesLengthW
 1EA 00022BF0 GetConsoleAliasExesW
 1EB 00022C00 GetConsoleAliasW
 1EC 00022C10 GetConsoleAliasesA
 1ED 00022C20 GetConsoleAliasesLengthA
 1EE 00022C30 GetConsoleAliasesLengthW
 1EF 00022C40 GetConsoleAliasesW
 1F0 00022810 GetConsoleCP
 1F1 000612F0 GetConsoleCharType
 1F2 00022C50 GetConsoleCommandHistoryA
 1F3 00022C60 GetConsoleCommandHistoryLengthA
 1F4 00022C70 GetConsoleCommandHistoryLengthW
 1F5 00022C80 GetConsoleCommandHistoryW
 1F6 00022960 GetConsoleCursorInfo
 1F7 00061350 GetConsoleCursorMode
 1F8 00022C90 GetConsoleDisplayMode
 1F9 00061660 GetConsoleFontInfo
 1FA 00022CA0 GetConsoleFontSize
 1FB 00060EA0 GetConsoleHardwareState
 1FC 00022CB0 GetConsoleHistoryInfo
 1FD          GetConsoleInputExeNameA (forwarded to kernelbase.GetConsoleInputExeNameA)
 1FE          GetConsoleInputExeNameW (forwarded to kernelbase.GetConsoleInputExeNameW)
 1FF 00060DD0 GetConsoleInputWaitHandle
 200 00061700 GetConsoleKeyboardLayoutNameA
 201 00061720 GetConsoleKeyboardLayoutNameW
 202 00022820 GetConsoleMode
 203 000613C0 GetConsoleNlsMode
 204 00022970 GetConsoleOriginalTitleA
 205 00022980 GetConsoleOriginalTitleW
 206 00022830 GetConsoleOutputCP
 207 00022CC0 GetConsoleProcessList
 208 00022990 GetConsoleScreenBufferInfo
 209 000229A0 GetConsoleScreenBufferInfoEx
 20A 00022CD0 GetConsoleSelectionInfo
 20B 000229B0 GetConsoleTitleA
 20C 000229C0 GetConsoleTitleW
 20D 00022CE0 GetConsoleWindow
 20E 00044E10 GetCurrencyFormatA
 20F 00035CB0 GetCurrencyFormatEx
 210 00035CC0 GetCurrencyFormatW
 211 0001FB80 GetCurrentActCtx
 212 0001B380 GetCurrentActCtxWorker
 213          GetCurrentApplicationUserModelId (forwarded to kernelbase.GetCurrentApplicationUserModelId)
 214 00022CF0 GetCurrentConsoleFont
 215 00022D00 GetCurrentConsoleFontEx
 216 0001F110 GetCurrentDirectoryA
 217 0001EA10 GetCurrentDirectoryW
 218          GetCurrentPackageFamilyName (forwarded to kernelbase.GetCurrentPackageFamilyName)
 219          GetCurrentPackageFullName (forwarded to kernelbase.GetCurrentPackageFullName)
 21A          GetCurrentPackageId (forwarded to kernelbase.GetCurrentPackageId)
 21B          GetCurrentPackageInfo (forwarded to kernelbase.GetCurrentPackageInfo)
 21C          GetCurrentPackagePath (forwarded to kernelbase.GetCurrentPackagePath)
 21D 00021DB0 GetCurrentProcess
 21E 00021DC0 GetCurrentProcessId
 21F          GetCurrentProcessorNumber (forwarded to NTDLL.RtlGetCurrentProcessorNumber)
 220          GetCurrentProcessorNumberEx (forwarded to NTDLL.RtlGetCurrentProcessorNumberEx)
 221 00016790 GetCurrentThread
 222 00015E50 GetCurrentThreadId
 223          GetCurrentThreadStackLimits (forwarded to api-ms-win-core-processthreads-l1-1-0.GetCurrentThreadStackLimits)
 224 0003BD40 GetCurrentUmsThread
 225 00035CD0 GetDateFormatA
 226 00020260 GetDateFormatAWorker
 227 00035CE0 GetDateFormatEx
 228 0001E670 GetDateFormatW
 229 00007020 GetDateFormatWWorker
 22A 00037CC0 GetDefaultCommConfigA
 22B 00037D50 GetDefaultCommConfigW
 22C 0005E9B0 GetDevicePowerState
 22D 00022200 GetDiskFreeSpaceA
 22E 00022210 GetDiskFreeSpaceExA
 22F 00022220 GetDiskFreeSpaceExW
 230 00022230 GetDiskFreeSpaceW
 231          GetDiskSpaceInformationA (forwarded to api-ms-win-core-file-l1-2-3.GetDiskSpaceInformationA)
 232          GetDiskSpaceInformationW (forwarded to api-ms-win-core-file-l1-2-3.GetDiskSpaceInformationW)
 233 00033F90 GetDllDirectoryA
 234 0001FB10 GetDllDirectoryW
 235 00022240 GetDriveTypeA
 236 00022250 GetDriveTypeW
 237 00045A30 GetDurationFormat
 238 00035CF0 GetDurationFormatEx
 239 0001EF60 GetDynamicTimeZoneInformation
 23A 00035D00 GetEnabledXStateFeatures
 23B 00033BF0 GetEncryptedFileVersionExt
 23C 0001E480 GetEnvironmentStrings
 23D 000225B0 GetEnvironmentStringsA
 23E 0001E460 GetEnvironmentStringsW
 23F 0001DD20 GetEnvironmentVariableA
 240 0001AAA0 GetEnvironmentVariableW
 241 00035D10 GetEraNameCountedString
 242 0001FE30 GetErrorMode
 243 0001C010 GetExitCodeProcess
 244 0001DDE0 GetExitCodeThread
 245 00036EA0 GetExpandedNameA
 246 00036F90 GetExpandedNameW
 247 00022260 GetFileAttributesA
 248 00022270 GetFileAttributesExA
 249 00022280 GetFileAttributesExW
 24A 0005B4D0 GetFileAttributesTransactedA
 24B 0005B530 GetFileAttributesTransactedW
 24C 00022290 GetFileAttributesW
 24D 000334F0 GetFileBandwidthReservation
 24E 000222A0 GetFileInformationByHandle
 24F 0001B6E0 GetFileInformationByHandleEx
 250 00035D20 GetFileMUIInfo
 251 0001E0D0 GetFileMUIPath
 252 000222B0 GetFileSize
 253 000222C0 GetFileSizeEx
 254 000222D0 GetFileTime
 255 000222E0 GetFileType
 256 000222F0 GetFinalPathNameByHandleA
 257 00022300 GetFinalPathNameByHandleW
 258 0005EA00 GetFirmwareEnvironmentVariableA
View Code

 

 
posted @ 2020-03-17 16:51  毛豆炒肉丝  阅读(1847)  评论(0)    收藏  举报