; ; Generated from: :iprtvfs:file(vd,d:\VMs\nt310\nt310.vdi):vfs(dvm):file(open,vol0):vfs(mount):/winnt/system32/ntdll.dll ; Size file: 0x409e4 (264676) ; Format: PE ; Size of image: 0x47000 (290816) ; Architecture: X86 ; Timestamp: 0x2c4f15d7 - 1993-07-22T22:33:59 ; CsrAllocateCaptureBuffer CsrAllocateCapturePointer CsrAllocateMessagePointer CsrCaptureMessageBuffer CsrCaptureMessageString CsrCaptureTimeout CsrClientCallServer CsrClientConnectToServer CsrClientMaxMessage CsrClientSendMessage CsrClientThreadConnect CsrDumpProfile CsrFreeCaptureBuffer CsrIdentifyAlertableThread CsrNewThread CsrProbeForRead CsrProbeForWrite CsrSetPriorityClass CsrStartProfile CsrStopDumpProfile CsrStopProfile CsrpProcessCallbackRequest DbgBreakPoint DbgPrint DbgPrompt DbgSsHandleKmApiMsg DbgSsInitialize DbgUiConnectToDbg DbgUiContinue DbgUiWaitStateChange DbgUserBreakPoint KiUserApcDispatcher KiUserExceptionDispatcher LdrAccessResource LdrFindEntryForAddress LdrFindResourceDirectory_U LdrFindResource_U LdrGetDllHandle LdrGetProcedureAddress LdrInitializeThunk LdrLoadDll LdrProcessRelocationBlock LdrQueryImageFileExecutionOptions LdrQueryProcessModuleInformation LdrShutdownProcess LdrShutdownThread LdrUnloadDll LdrVerifyImageMatchesChecksum NPXEMULATORTABLE NtAcceptConnectPort NtAccessCheck NtAccessCheckAndAuditAlarm NtAdjustGroupsToken NtAdjustPrivilegesToken NtAlertResumeThread NtAlertThread NtAllocateLocallyUniqueId NtAllocateVirtualMemory NtCancelIoFile NtCancelTimer NtClose NtCloseObjectAuditAlarm NtCompleteConnectPort NtConnectPort NtContinue NtCreateDirectoryObject NtCreateEvent NtCreateEventPair NtCreateFile NtCreateKey NtCreateMailslotFile NtCreateMutant NtCreateNamedPipeFile NtCreatePagingFile NtCreatePort NtCreateProcess NtCreateProfile NtCreateSection NtCreateSemaphore NtCreateSymbolicLinkObject NtCreateThread NtCreateTimer NtCreateToken NtCurrentTeb NtDelayExecution NtDeleteKey NtDeleteValueKey NtDeviceIoControlFile NtDisplayString NtDuplicateObject NtDuplicateToken NtEnumerateKey NtEnumerateValueKey NtExtendSection NtFlushBuffersFile NtFlushInstructionCache NtFlushKey NtFlushVirtualMemory NtFlushWriteBuffer NtFreeVirtualMemory NtFsControlFile NtGetContextThread NtGetTickCount NtImpersonateClientOfPort NtImpersonateThread NtInitializeRegistry NtInitializeVDM NtListenPort NtLoadDriver NtLoadKey NtLockFile NtLockVirtualMemory NtMakeTemporaryObject NtMapViewOfSection NtNotifyChangeDirectoryFile NtNotifyChangeKey NtOpenDirectoryObject NtOpenEvent NtOpenEventPair NtOpenFile NtOpenKey NtOpenMutant NtOpenObjectAuditAlarm NtOpenProcess NtOpenProcessToken NtOpenSection NtOpenSemaphore NtOpenSymbolicLinkObject NtOpenThread NtOpenThreadToken NtOpenTimer NtPrivilegeCheck NtPrivilegeObjectAuditAlarm NtPrivilegedServiceAuditAlarm NtProtectVirtualMemory NtPulseEvent NtQueryDefaultLocale NtQueryDirectoryFile NtQueryDirectoryObject NtQueryEaFile NtQueryEvent NtQueryInformationFile NtQueryInformationPort NtQueryInformationProcess NtQueryInformationThread NtQueryInformationToken NtQueryIntervalProfile NtQueryKey NtQueryMutant NtQueryObject NtQueryPerformanceCounter NtQuerySection NtQuerySecurityObject NtQuerySemaphore NtQuerySymbolicLinkObject NtQuerySystemEnvironmentValue NtQuerySystemInformation NtQuerySystemTime NtQueryTimer NtQueryValueKey NtQueryVirtualMemory NtQueryVolumeInformationFile NtRaiseException NtRaiseHardError NtReadFile NtReadRequestData NtReadVirtualMemory NtRegisterThreadTerminatePort NtReleaseMutant NtReleaseProcessMutant NtReleaseSemaphore NtRenameValueKey NtReplaceKey NtReplyPort NtReplyWaitReceivePort NtReplyWaitReplyPort NtRequestPort NtRequestWaitReplyPort NtResetEvent NtRestoreKey NtResumeThread NtSaveKey NtSetContextThread NtSetDefaultHardErrorPort NtSetDefaultLocale NtSetEaFile NtSetEvent NtSetHighEventPair NtSetHighWaitLowEventPair NtSetHighWaitLowThread NtSetInformationFile NtSetInformationKey NtSetInformationProcess NtSetInformationThread NtSetInformationToken NtSetIntervalProfile NtSetLdtEntries NtSetLowEventPair NtSetLowWaitHighEventPair NtSetLowWaitHighThread NtSetSecurityObject NtSetSystemEnvironmentValue NtSetSystemTime NtSetTimer NtSetValueKey NtSetVolumeInformationFile NtShutdownSystem NtStartProfile NtStopProfile NtSuspendThread NtSystemDebugControl NtTerminateProcess NtTerminateThread NtTestAlert NtUnloadDriver NtUnloadKey NtUnlockFile NtUnlockVirtualMemory NtUnmapViewOfSection NtVdmControl NtVdmStartExecution NtWaitForMultipleObjects NtWaitForProcessMutant NtWaitForSingleObject NtWaitHighEventPair NtWaitLowEventPair NtWriteFile NtWriteRequestData NtWriteVirtualMemory PfxFindPrefix PfxInitialize PfxInsertPrefix PfxRemovePrefix RestoreEm87Context RtlAbortRXact RtlAbsoluteToSelfRelativeSD RtlAcquirePebLock RtlAcquireResourceExclusive RtlAcquireResourceShared RtlAddAccessAllowedAce RtlAddAccessDeniedAce RtlAddAce RtlAddActionToRXact RtlAddAttributeActionToRXact RtlAddAuditAccessAce RtlAdjustPrivilege RtlAllocateAndInitializeSid RtlAllocateHeap RtlAnalyzeProfile RtlAnsiCharToUnicodeChar RtlAnsiStringToUnicodeSize RtlAnsiStringToUnicodeString RtlAppendAsciizToString RtlAppendStringToString RtlAppendUnicodeStringToString RtlAppendUnicodeToString RtlApplyRXact RtlApplyRXactNoFlush RtlAreAllAccessesGranted RtlAreAnyAccessesGranted RtlAreBitsClear RtlAreBitsSet RtlAssert RtlCaptureStackBackTrace RtlCharToInteger RtlCheckRegistryKey RtlClearAllBits RtlClearBits RtlCompactHeap RtlCompareMemory RtlCompareMemoryUlong RtlCompareString RtlCompareUnicodeString RtlConsoleMultiByteToUnicodeN RtlConvertExclusiveToShared RtlConvertLongToLargeInteger RtlConvertSharedToExclusive RtlConvertSidToUnicodeString RtlConvertUiListToApiList RtlConvertUlongToLargeInteger RtlCopyLuid RtlCopyLuidAndAttributesArray RtlCopySecurityDescriptor RtlCopySid RtlCopySidAndAttributesArray RtlCopyString RtlCopyUnicodeString RtlCreateAcl RtlCreateAndSetSD RtlCreateEnvironment RtlCreateHeap RtlCreateProcessParameters RtlCreateRegistryKey RtlCreateSecurityDescriptor RtlCreateUnicodeString RtlCreateUnicodeStringFromAsciiz RtlCreateUserProcess RtlCreateUserSecurityObject RtlCreateUserThread RtlCustomCPToUnicodeN RtlDeNormalizeProcessParams RtlDelete RtlDeleteAce RtlDeleteCriticalSection RtlDeleteElementGenericTable RtlDeleteRegistryValue RtlDeleteResource RtlDeleteSecurityObject RtlDestroyEnvironment RtlDestroyHeap RtlDestroyProcessParameters RtlDetermineDosPathNameType_U RtlDoesFileExists_U RtlDosPathNameToNtPathName_U RtlDosSearchPath_U RtlDumpResource RtlEnlargedIntegerMultiply RtlEnlargedUnsignedDivide RtlEnlargedUnsignedMultiply RtlEnterCriticalSection RtlEnumerateGenericTable RtlEnumerateGenericTableWithoutSplaying RtlEqualComputerName RtlEqualDomainName RtlEqualLuid RtlEqualPrefixSid RtlEqualSid RtlEqualString RtlEqualUnicodeString RtlEraseUnicodeString RtlExpandEnvironmentStrings RtlExpandEnvironmentStrings_U RtlExtendedIntegerMultiply RtlExtendedLargeIntegerDivide RtlExtendedMagicDivide RtlFillMemory RtlFillMemoryUlong RtlFindClearBits RtlFindClearBitsAndSet RtlFindLongestRunClear RtlFindLongestRunSet RtlFindMessage RtlFindSetBits RtlFindSetBitsAndClear RtlFirstFreeAce RtlFormatMessage RtlFreeAnsiString RtlFreeHeap RtlFreeOemString RtlFreeSid RtlFreeUnicodeString RtlGenerate8dot3Name RtlGetAce RtlGetCallersAddress RtlGetControlSecurityDescriptor RtlGetCurrentDirectory_U RtlGetDaclSecurityDescriptor RtlGetElementGenericTable RtlGetFullPathName_U RtlGetGroupSecurityDescriptor RtlGetHandleValueHeap RtlGetHeapUserValue RtlGetNtGlobalFlags RtlGetNtProductType RtlGetOwnerSecurityDescriptor RtlGetSaclSecurityDescriptor RtlIdentifierAuthoritySid RtlImageDirectoryEntryToData RtlImageNtHeader RtlImpersonateSelf RtlInitAnsiString RtlInitCodePageTable RtlInitNlsTables RtlInitString RtlInitUnicodeString RtlInitializeBitMap RtlInitializeContext RtlInitializeCriticalSection RtlInitializeGenericTable RtlInitializeProfile RtlInitializeRXact RtlInitializeResource RtlInitializeSid RtlInitializeStackTraceDataBase RtlInsertElementGenericTable RtlIntegerToChar RtlIntegerToUnicodeString RtlIsDosDeviceName_U RtlIsGenericTableEmpty RtlLargeIntegerAdd RtlLargeIntegerArithmeticShift RtlLargeIntegerDivide RtlLargeIntegerNegate RtlLargeIntegerShiftLeft RtlLargeIntegerShiftRight RtlLargeIntegerSubtract RtlLargeIntegerToChar RtlLeaveCriticalSection RtlLengthRequiredSid RtlLengthSecurityDescriptor RtlLengthSid RtlLocalTimeToSystemTime RtlLockHeap RtlLogStackBackTrace RtlLookupElementGenericTable RtlLookupSymbolByAddress RtlLookupSymbolByName RtlMakeSelfRelativeSD RtlMapGenericMask RtlMoveMemory RtlMultiByteToUnicodeN RtlMultiByteToUnicodeSize RtlNewInstanceSecurityObject RtlNewSecurityGrantedAccess RtlNewSecurityObject RtlNormalizeProcessParams RtlNtStatusToDosError RtlNumberGenericTableElements RtlNumberOfClearBits RtlNumberOfSetBits RtlOemStringToUnicodeSize RtlOemStringToUnicodeString RtlOemToUnicodeN RtlOpenCurrentUser RtlPcToFileHeader RtlPrefixString RtlPrefixUnicodeString RtlQueryEnvironmentVariable RtlQueryEnvironmentVariable_U RtlQueryInformationAcl RtlQueryModuleInformation RtlQueryProcessBackTraceInformation RtlQueryProcessHeapInformation RtlQueryProcessLockInformation RtlQueryRegistryValues RtlQuerySecurityObject RtlQueryTimeZoneInformation RtlRaiseException RtlRaiseStatus RtlRandom RtlReAllocateHeap RtlRealPredecessor RtlRealSuccessor RtlReleasePebLock RtlReleaseResource RtlRemoteCall RtlResetRtlTranslations RtlRunDecodeUnicodeString RtlRunEncodeUnicodeString RtlSecondsSince1970ToTime RtlSecondsSince1980ToTime RtlSelfRelativeToAbsoluteSD RtlSetAllBits RtlSetBits RtlSetCurrentDirectory_U RtlSetCurrentEnvironment RtlSetDaclSecurityDescriptor RtlSetEnvironmentVariable RtlSetGroupSecurityDescriptor RtlSetHandleValueHeap RtlSetHeapUserValue RtlSetInformationAcl RtlSetOwnerSecurityDescriptor RtlSetSaclSecurityDescriptor RtlSetSecurityObject RtlSetTimeZoneInformation RtlSizeHeap RtlSnapShotHeap RtlSplay RtlStartProfile RtlStartRXact RtlStopProfile RtlSubAuthorityCountSid RtlSubAuthoritySid RtlSubtreePredecessor RtlSubtreeSuccessor RtlSystemTimeToLocalTime RtlTimeFieldsToTime RtlTimeToElapsedTimeFields RtlTimeToSecondsSince1970 RtlTimeToSecondsSince1980 RtlTimeToTimeFields RtlUnicodeStringToAnsiSize RtlUnicodeStringToAnsiString RtlUnicodeStringToCountedOemString RtlUnicodeStringToInteger RtlUnicodeStringToOemSize RtlUnicodeStringToOemString RtlUnicodeToCustomCPN RtlUnicodeToMultiByteN RtlUnicodeToMultiByteSize RtlUnicodeToOemN RtlUniform RtlUnlockHeap RtlUnwind RtlUpcaseUnicodeChar RtlUpcaseUnicodeString RtlUpcaseUnicodeStringToAnsiString RtlUpcaseUnicodeStringToCountedOemString RtlUpcaseUnicodeStringToOemString RtlUpcaseUnicodeToCustomCPN RtlUpcaseUnicodeToMultiByteN RtlUpcaseUnicodeToOemN RtlUpperChar RtlUpperString RtlValidAcl RtlValidSecurityDescriptor RtlValidSid RtlValidateHeap RtlWriteRegistryValue RtlZeroMemory RtlpInitializeRtl RtlpNtCreateKey RtlpNtEnumerateSubKey RtlpNtMakeTemporaryKey RtlpNtOpenKey RtlpNtQueryValueKey RtlpNtSetValueKey RtlpUnWaitCriticalSection RtlpWaitForCriticalSection SaveEm87Context ZwAcceptConnectPort ZwAccessCheck ZwAccessCheckAndAuditAlarm ZwAdjustGroupsToken ZwAdjustPrivilegesToken ZwAlertResumeThread ZwAlertThread ZwAllocateLocallyUniqueId ZwAllocateVirtualMemory ZwCancelIoFile ZwCancelTimer ZwClose ZwCloseObjectAuditAlarm ZwCompleteConnectPort ZwConnectPort ZwContinue ZwCreateDirectoryObject ZwCreateEvent ZwCreateEventPair ZwCreateFile ZwCreateKey ZwCreateMailslotFile ZwCreateMutant ZwCreateNamedPipeFile ZwCreatePagingFile ZwCreatePort ZwCreateProcess ZwCreateProfile ZwCreateSection ZwCreateSemaphore ZwCreateSymbolicLinkObject ZwCreateThread ZwCreateTimer ZwCreateToken ZwDelayExecution ZwDeleteKey ZwDeleteValueKey ZwDeviceIoControlFile ZwDisplayString ZwDuplicateObject ZwDuplicateToken ZwEnumerateKey ZwEnumerateValueKey ZwExtendSection ZwFlushBuffersFile ZwFlushInstructionCache ZwFlushKey ZwFlushVirtualMemory ZwFlushWriteBuffer ZwFreeVirtualMemory ZwFsControlFile ZwGetContextThread ZwGetTickCount ZwImpersonateClientOfPort ZwImpersonateThread ZwInitializeRegistry ZwInitializeVDM ZwListenPort ZwLoadDriver ZwLoadKey ZwLockFile ZwLockVirtualMemory ZwMakeTemporaryObject ZwMapViewOfSection ZwNotifyChangeDirectoryFile ZwNotifyChangeKey ZwOpenDirectoryObject ZwOpenEvent ZwOpenEventPair ZwOpenFile ZwOpenKey ZwOpenMutant ZwOpenObjectAuditAlarm ZwOpenProcess ZwOpenProcessToken ZwOpenSection ZwOpenSemaphore ZwOpenSymbolicLinkObject ZwOpenThread ZwOpenThreadToken ZwOpenTimer ZwPrivilegeCheck ZwPrivilegeObjectAuditAlarm ZwPrivilegedServiceAuditAlarm ZwProtectVirtualMemory ZwPulseEvent ZwQueryDefaultLocale ZwQueryDirectoryFile ZwQueryDirectoryObject ZwQueryEaFile ZwQueryEvent ZwQueryInformationFile ZwQueryInformationPort ZwQueryInformationProcess ZwQueryInformationThread ZwQueryInformationToken ZwQueryIntervalProfile ZwQueryKey ZwQueryMutant ZwQueryObject ZwQueryPerformanceCounter ZwQuerySection ZwQuerySecurityObject ZwQuerySemaphore ZwQuerySymbolicLinkObject ZwQuerySystemEnvironmentValue ZwQuerySystemInformation ZwQuerySystemTime ZwQueryTimer ZwQueryValueKey ZwQueryVirtualMemory ZwQueryVolumeInformationFile ZwRaiseException ZwRaiseHardError ZwReadFile ZwReadRequestData ZwReadVirtualMemory ZwRegisterThreadTerminatePort ZwReleaseMutant ZwReleaseProcessMutant ZwReleaseSemaphore ZwRenameValueKey ZwReplaceKey ZwReplyPort ZwReplyWaitReceivePort ZwReplyWaitReplyPort ZwRequestPort ZwRequestWaitReplyPort ZwResetEvent ZwRestoreKey ZwResumeThread ZwSaveKey ZwSetContextThread ZwSetDefaultHardErrorPort ZwSetDefaultLocale ZwSetEaFile ZwSetEvent ZwSetHighEventPair ZwSetHighWaitLowEventPair ZwSetHighWaitLowThread ZwSetInformationFile ZwSetInformationKey ZwSetInformationProcess ZwSetInformationThread ZwSetInformationToken ZwSetIntervalProfile ZwSetLdtEntries ZwSetLowEventPair ZwSetLowWaitHighEventPair ZwSetLowWaitHighThread ZwSetSecurityObject ZwSetSystemEnvironmentValue ZwSetSystemTime ZwSetTimer ZwSetValueKey ZwSetVolumeInformationFile ZwShutdownSystem ZwStartProfile ZwStopProfile ZwSuspendThread ZwSystemDebugControl ZwTerminateProcess ZwTerminateThread ZwTestAlert ZwUnloadDriver ZwUnloadKey ZwUnlockFile ZwUnlockVirtualMemory ZwUnmapViewOfSection ZwVdmControl ZwVdmStartExecution ZwWaitForMultipleObjects ZwWaitForProcessMutant ZwWaitForSingleObject ZwWaitHighEventPair ZwWaitLowEventPair ZwWriteFile ZwWriteRequestData ZwWriteVirtualMemory __eCommonExceptions __eEmulatorInit __eF2XM1 __eFABS __eFADD32 __eFADD64 __eFADDPreg __eFADDreg __eFADDtop __eFCHS __eFCOM __eFCOM32 __eFCOM64 __eFCOMP __eFCOMP32 __eFCOMP64 __eFCOMPP __eFCOS __eFDECSTP __eFDIV32 __eFDIV64 __eFDIVPreg __eFDIVR32 __eFDIVR64 __eFDIVRPreg __eFDIVRreg __eFDIVRtop __eFDIVreg __eFDIVtop __eFFREE __eFIADD16 __eFIADD32 __eFICOM16 __eFICOM32 __eFICOMP16 __eFICOMP32 __eFIDIV16 __eFIDIV32 __eFIDIVR16 __eFIDIVR32 __eFILD16 __eFILD32 __eFILD64 __eFIMUL16 __eFIMUL32 __eFINCSTP __eFINIT __eFIST16 __eFIST32 __eFISTP16 __eFISTP32 __eFISTP64 __eFISUB16 __eFISUB32 __eFISUBR16 __eFISUBR32 __eFLD1 __eFLD32 __eFLD64 __eFLD80 __eFLDCW __eFLDENV __eFLDL2E __eFLDLN2 __eFLDPI __eFLDZ __eFMUL32 __eFMUL64 __eFMULPreg __eFMULreg __eFMULtop __eFPATAN __eFPREM __eFPREM1 __eFPTAN __eFRNDINT __eFRSTOR __eFSAVE __eFSCALE __eFSIN __eFSQRT __eFST __eFST32 __eFST64 __eFSTCW __eFSTENV __eFSTP __eFSTP32 __eFSTP64 __eFSTP80 __eFSTSW __eFSUB32 __eFSUB64 __eFSUBPreg __eFSUBR32 __eFSUBR64 __eFSUBRPreg __eFSUBRreg __eFSUBRtop __eFSUBreg __eFSUBtop __eFTST __eFUCOM __eFUCOMP __eFUCOMPP __eFXAM __eFXCH __eFXTRACT __eFYL2X __eFYL2XP1 __eGetStatusWord xRtlDosPathNameToNtPathName