文章插图
kernel32.dll【kernel32.dll】kernel32.dll是Windows 9x/Me中非常重要的32位动态程式库档案,属于核心级档案 。它控制着系统的记忆体管理、数据的输入输出操作和中断处理,当Windows启动时,kernel32.dll就驻留在记忆体中特定的防写区域,使别的程式无法占用这个记忆体区域 。
基本介绍中文名:kernel32.dll
软体语言:支持多国语言
档案版本:5.1.2600.2180
开 发 商:微软
档案信息软体大小:随作业系统版本不同而不同软体星级:2.5
文章插图
档案描述:Windows NT BASE API Client DLL, Microsoft? Windows? Operating System系统dll档案:是安全等级(0-5):1间谍软体:否广告软体:否木马:否核心档案有时,Windows会弹出“非法页错误”的讯息框,简单地说,这是因为某个或多个程式试图访问kernel32.dll所占用的记忆体保护区域,从而产生冲突而造成的 。该错误一般由某个特定的程式引起,也可能是多个档案或程式 。如果是由某个程式引起,那幺可以尝试重新安装或升级该程式来解决问题,而如果由多个档案和程式引起,那就极有可能是因损坏的硬体设备驱动而引起的 。出错元兇1.Windows自身的临时交换档案被破坏;2.档案分配表(FAT)出现错误;3.用户名和密码列表错误;4.装载了已经被破坏的或者是不正确版本的ker -nel32.dll档案;5.注册表档案被损坏;6.计算机硬体有问题,如CPU过热、超频使用、损坏的电源、地线波动、射频噪音、损坏的磁碟控制器;7.BIOS中等待状态设定出现问题,或者RAM时钟有错误;8.已经损坏或者没有正确、完整地安装软体;9.临时资料夹不存在或者已经损坏;10.损坏的控制台档案(扩展名为cpl);11.不正确或者已经损坏的硬体驱动程式;12.没有正确安装印表机驱动程式;13.Java设备错误;14.已经被破坏的.LOG日誌档案;15.访问历史资料夹错误;16.不合适的或损坏的动态程式库档案;17.机器感染了病毒;18.损坏的或者不正确版本的msinfo32.exe档案;19.磁碟空间不足 。解决方案知道了哪些情况可能引起kernel32.dll档案出问题,那幺就可以採取排除法一一解决 。不过,在大多数情况下,我们建议你优先实施以下解决方案:方法一由于流氓软体篡改的手法多样化,位置也很多,要解决这些问题,最好是採用专业安全软体实际一键清除和修复 。当然,对于计算机底层实现原理相对熟悉的专业人员,也可根据计算机本身的配置信息(注册表等)通过手动方式,或编写批处理档案等方式进行删除 。方法二1.错误的记忆体模组:用“记事本”打开根目录下的config.sys,并在其中插入命令行:DEVICE=C:\WINDOWS\HIMEM.SYS/TESTMEM:ON,然后在电脑重启时观察萤幕所显示的HIMEM has detected unreliable memory at address xxxxxxxxx,这样就可以基本确定记忆体出了问题 。不过,这可能需要重启几次来逐一发现 。当然也可以下载、运行相应的系统诊断软体,特别是记忆体检测软体;2.错误的显示卡驱动程式:最新版本的显示卡驱动程式可以保证显示卡更加稳定、高效地运行,因此你要确保显示卡驱动程式是最新版本;3.超频CPU、汇流排速度:如果想要你的电脑运行得更加稳定、持久,建议不要将CPU和汇流排超频使用,恢复到默认值;4.CPU或者电源风扇转速不正常或落满灰尘:风扇的不稳定可能导致CPU或电源温度过高,从而引起系统不稳定 。CPU风扇可以用小刷子和吹风机处理,电源风扇则需要由专业人员清扫;5.图形加速设定过高:右击“我的电脑”,选择“属性”命令,在“性能”选项卡中选择“图形”按钮,将硬体加速调低一个刻度,然后确定后重启,如果还有问题,再重複以上步骤继续往下调低一个刻度,直到正常为止;6.动画游标、滑鼠轨迹和活动桌面:这些花哨的设定都有可能引起kernel32.dll错误,尝试禁用这些功能,然后再一个一个激活这些功能,直到发现错误为止;7.相当有效的解决方案:实践证明这个方法解决过许多ker- nel32.dll崩溃的问题 。在C糟根目录下,用“记事本”创建或者直接修改系统配置档案config.sys,在其中加入如下3行语句:FILES=65BUFFERS=40STACKS=64,512如果错误仍然存在,可使用“记事本”打开系统资料夹下(如〈C:\Windows\〉)的system.ini档案,然后在[386Enh]节上加入如下两行语句:; Increases default stack pages from 2 to 6MinSPs=6(MinSPs默认值是2,如需要,每次增加2直到解决问题为止,而第一句前面的“;”主要起注释作用 。)修改好后保存退出,重启使之生效 。8.删除临时交换档案:如果错误仍然存在,可以尝试删除 Windows的临时交换档案Win386.swp来解决问题,不过该档案无法在Windows下删除,你需要退到DOS实模式下进行,进入系统目录(如C糟〈Windows〉目录)删除Win386.swp,当系统重启后Windows会重新生成该档案 。9.密码列表损坏:如果系统密码列表档案被损坏也会引起错误,这时需要重建该档案,在“资源管理器”中选择〈Windows〉资料夹,然后按下F3调出查找对话框,在档案名称中键入:*.pwl,然后进行查找,当符合条件的档案列出来后,将它们全部删除掉,接着重启,让系统重建密码列表档案 。10.病毒:如果系统显示的是MSIMN错误导致kernel32.dll产生无效页面错误,那幺你的电脑很有可能被Happy 99蠕虫病毒所侵害,你需要使用防毒软体对你的系统进行一下清除 。11.Kernel32档案损坏:一个完全能够解决问题的方法,需要一定技术:首先下载一个乾净的Kernel32.dll,存放到D糟根目录,在电脑启动时进入DOS,手动删除C糟下的Kernel32.dll,再用COPY将D糟的Kernel32.dll複製过去即可技术信息档案头部Dump of file kernel32.dll PE signature foundFile Type: DLLFILE HEADER VALUES14C machine (i386)4 number of sections49C4F481 time date stamp Sat Mar 21 22:06:57 20090 file pointer to symbol table0 number of symbolsE0 size of optional header210E characteristicsExecutableLine numbers strippedSymbols stripped32 bit word machineDLLOPTIONAL HEADER VALUES10B magic #7.10 linker version83200 size of code95800 size of initialized data0 size of uninitialized dataB64E RVA of entry point1000 base of code80000 base of data7C800000 image base1000 section alignment200 file alignment5.01 operating system version5.01 image version4.00 subsystem version0 Win32 version11E000 size of image400 size of headers11E97E checksum3 subsystem (Windows CUI)0 DLL characteristics40000 size of stack reserve1000 size of stack commit100000 size of heap reserve1000 size of heap commit0 loader flags10 number of directories262C [ 6D19] RVA [size] of Export Directory81898 [ 28] RVA [size] of Import Directory8A000 [ 8D3FC] RVA [size] of Resource Directory0 [ 0] RVA [size] of Exception Directory 0 [ 0] RVA [size] of Certificates Directory118000 [ 5C84] RVA [size] of Base Relocation Directory84188 [ 38] RVA [size] of Debug Directory0 [ 0] RVA [size] of Architecture Directory0 [ 0] RVA [size] of Special Directory0 [ 0] RVA [size] of Thread Storage Directory4E620 [ 40] RVA [size] of Load Configuration Directory0 [ 0] RVA [size] of Bound Import Directory1000 [ 624] RVA [size] of Import Address Table Directory0 [ 0] RVA [size] of Delay Import Directory0 [ 0] RVA [size] of Reserved Directory0 [ 0] RVA [size] of Reserved DirectorySECTION HEADER #1.text name831E9 virtual size1000 virtual address83200 size of raw data400 file pointer to raw data0 file pointer to relocation table0 file pointer to line numbers0 number of relocations0 number of line numbers60000020 flagsCodeExecute ReadDebug DirectoriesType Size RVA Pointer------ -------- -------- --------cv 25 000841C4 835C4 Format: RSDS( A) 4 000841C0 835C0SECTION HEADER #2.data name4460 virtual size85000 virtual address2600 size of raw data83600 file pointer to raw data0 file pointer to relocation table0 file pointer to line numbers0 number of relocations 0 number of line numbersC0000040 flagsInitialized DataRead WriteSECTION HEADER #3.rsrc name8D3FC virtual size8A000 virtual address8D400 size of raw data85C00 file pointer to raw data0 file pointer to relocation table0 file pointer to line numbers0 number of relocations0 number of line numbers40000040 flagsInitialized DataRead OnlySECTION HEADER #4.reloc name5C84 virtual size118000 virtual address5E00 size of raw data113000 file pointer to raw data0 file pointer to relocation table0 file pointer to line numbers0 number of relocations0 number of line numbers42000040 flagsInitialized DataDiscardableRead OnlySummary5000 .data6000 .reloc8E000 .rsrc84000 .text常见问题"提示无法找到kernel32.dll档案" 这是因为被病毒感染相关档案导致,一旦防毒软体删除被感染的档案,就会导致相关档案缺失,导致运行游戏时提示缺少kernel32.dll等.kernel32.dll丢失游戏常用软体运行不起来运行不起来,或者报错修複方法: 方法一: 也是最简单的一种方法,手工替换相关档案可以解决问题 。在正常工作的相关软体安装目录中,找到这个kernel32.dll档案,複製到出现问题的软体目录下,即可解决问题 。方法二: 重新安装系统(不推荐) 方法三: 从朋友电脑上拷贝或者到网上下载档案,放到C:\WINDOWS\SYSTEM32资料夹下 。另外複製到X盘:\游戏资料夹\,如果还不行可能是档案版本与游戏所支持的版本不一致 。提供的API共954个API:AActivateActCtxAddAtomAAddAtomWAddConsoleAliasAAddConsoleAliasWAddLocalAlternateComputerNameAAddLocalAlternateComputerNameWAddRefActCtxAddVectoredExceptionHandlerAllocConsoleAllocateUserPhysicalPagesAreFileApisANSIAssignProcessToJobObjectAttachConsole BBackupReadBackupSeekBackupWriteBaseCheckAppcompatCacheBaseCleanupAppcompatCacheBaseCleanupAppcompatCacheSupportBaseDumpAppcompatCacheBaseFlushAppcompatCacheBaseInitAppcompatCacheBaseInitAppcompatCacheSupportBaseProcessInitPostImportBaseQueryModuleDataBaseUpdateAppcompatCacheBasepCheckWinSaferRestrictionsBeepBeginUpdateResourceABeginUpdateResourceWBindIoCompletionCallbackBuildCommDCBABuildCommDCBAndTimeoutsABuildCommDCBAndTimeoutsWBuildCommDCBWCCallNamedPipeACallNamedPipeWCancelDeviceWakeupRequestCancelIoCancelTimerQueueTimerCancelWaitableTimerChangeTimerQueueTimerCheckNameLegalDOS8Dot3ACheckNameLegalDOS8Dot3WCheckRemoteDebuggerPresentClearCommBreakClearCommErrorCloseConsoleHandleCloseHandleCloseProfileUserMappingCmdBatNotificationCommConfigDialogACommConfigDialogWCompareFileTimeCompareStringACompareStringWConnectNamedPipeConsoleMenuControlContinueDebugEventConvertDefaultLocaleConvertFiberToThreadConvertThreadToFiberCopyFileACopyFileExACopyFileExWCopyFileWCopyLZFileCreateActCtxACreateActCtxWCreateConsoleScreenBufferCreateDirectoryACreateDirectoryExACreateDirectoryExWCreateDirectoryWCreateEventACreateEventWCreateFiberCreateFiberExCreateFileACreateFileMappingACreateFileMappingWCreateFileWCreateHardLinkACreateHardLinkWCreateIoCompletionPortCreateJobObjectACreateJobObjectWCreateJobSetCreateMailslotACreateMailslotWCreateMemoryResourceNotificationCreateMutexACreateMutexWCreateNamedPipeACreateNamedPipeWCreateNlsSecurityDescriptorCreatePipeCreateProcessACreateProcessInternalACreateProcessInternalWCreateProcessInternalWSecureCreateProcessWCreateRemoteThreadCreateSemaphoreACreateSemaphoreWCreateSocketHandleCreateTapePartitionCreateThreadCreateTimerQueueCreateTimerQueueTimerCreateToolhelp32SnapshotCreateVirtualBufferCreateWaitableTimerACreateWaitableTimerW DDeactivateActCtxDebugActiveProcessDebugActiveProcessStopDebugBreakDebugBreakProcessDebugSetProcessKillOnExitDecodePointerDecodeSystemPointerDefineDosDeviceADefineDosDeviceWDelayLoadFailureHookDeleteAtomDeleteCriticalSectionDeleteFiberDeleteFileADeleteFileWDeleteTimerQueueDeleteTimerQueueExDeleteTimerQueueTimerDeleteVolumeMountPointADeleteVolumeMountPointWDeviceIoControlDisableThreadLibraryCallsDisconnectNamedPipeDnsHostnameToComputerNameADnsHostnameToComputerNameWDosDateTimeToFileTimeDosPathToSessionPathADosPathToSessionPathWDuplicateConsoleHandleDuplicateHandleEEncodePointerEncodeSystemPointerEndUpdateResourceAEndUpdateResourceWEnterCriticalSectionEnumCalendarInfoAEnumCalendarInfoExAEnumCalendarInfoExWEnumCalendarInfoWEnumDateFormatsAEnumDateFormatsExAEnumDateFormatsExWEnumDateFormatsWEnumLanguageGroupLocalesAEnumLanguageGroupLocalesWEnumResourceLanguagesAEnumResourceLanguagesWEnumResourceNamesAEnumResourceNamesWEnumResourceTypesAEnumResourceTypesWEnumSystemCodePagesAEnumSystemCodePagesWEnumSystemGeoIDEnumSystemLanguageGroupsAEnumSystemLanguageGroupsWEnumSystemLocalesAEnumSystemLocalesWEnumTimeFormatsAEnumTimeFormatsWEnumUILanguagesAEnumUILanguagesWEnumerateLocalComputerNamesAEnumerateLocalComputerNamesWEraseTapeEscapeCommFunctionExitProcessExitThreadExitVDMExpandEnvironmentStringsAExpandEnvironmentStringsWExpungeConsoleCommandHistoryAExpungeConsoleCommandHistoryWExtendVirtualBuffer FFatalAppExitAFatalAppExitWFatalExitFileTimeToDosDateTimeFileTimeToLocalFileTimeFileTimeToSystemTimeFillConsoleOutputAttributeFillConsoleOutputCharacterAFillConsoleOutputCharacterWFindActCtxSectionGuidFindActCtxSectionStringAFindActCtxSectionStringWFindAtomAFindAtomWFindCloseFindCloseChangeNotificationFindFirstChangeNotificationAFindFirstChangeNotificationWFindFirstFileAFindFirstFileExAFindFirstFileExWFindFirstFileWFindFirstVolumeAFindFirstVolumeMountPointAFindFirstVolumeMountPointWFindFirstVolumeWFindNextChangeNotificationFindNextFileAFindNextFileWFindNextVolumeAFindNextVolumeMountPointAFindNextVolumeMountPointWFindNextVolumeWFindResourceAFindResourceExAFindResourceExWFindResourceWFindVolumeCloseFindVolumeMountPointCloseFlushConsoleInputBufferFlushFileBuffersFlushInstructionCacheFlushViewOfFileFoldStringAFoldStringWFormatMessageAFormatMessageWFreeConsoleFreeEnvironmentStringsAFreeEnvironmentStringsWFreeLibraryFreeLibraryAndExitThreadFreeResourceFreeUserPhysicalPagesFreeVirtualBufferGGenerateConsoleCtrlEventGetACPGetAtomNameAGetAtomNameWGetBinaryTypeGetBinaryTypeAGetBinaryTypeWGetCPFileNameFromRegistryGetCPInfoGetCPInfoExAGetCPInfoExWGetCalendarInfoAGetCalendarInfoWGetComPlusPackageInstallStatusGetCommConfigGetCommMaskGetCommModemStatusGetCommPropertiesGetCommStateGetCommTimeoutsGetCommandLineAGetCommandLineWGetCompressedFileSizeAGetCompressedFileSizeWGetComputerNameAGetComputerNameExAGetComputerNameExWGetComputerNameWGetConsoleAliasAGetConsoleAliasExesAGetConsoleAliasExesLengthAGetConsoleAliasExesLengthWGetConsoleAliasExesWGetConsoleAliasWGetConsoleAliasesAGetConsoleAliasesLengthAGetConsoleAliasesLengthWGetConsoleAliasesWGetConsoleCPGetConsoleCharTypeGetConsoleCommandHistoryAGetConsoleCommandHistoryLengthAGetConsoleCommandHistoryLengthWGetConsoleCommandHistoryWGetConsoleCursorInfoGetConsoleCursorModeGetConsoleDisplayModeGetConsoleFontInfoGetConsoleFontSizeGetConsoleHardwareStateGetConsoleInputExeNameAGetConsoleInputExeNameWGetConsoleInputWaitHandleGetConsoleKeyboardLayoutNameAGetConsoleKeyboardLayoutNameWGetConsoleModeGetConsoleNlsModeGetConsoleOutputCPGetConsoleProcessListGetConsoleScreenBufferInfoGetConsoleSelectionInfoGetConsoleTitleAGetConsoleTitleWGetConsoleWindowGetCurrencyFormatAGetCurrencyFormatWGetCurrentActCtxGetCurrentConsoleFontGetCurrentDirectoryAGetCurrentDirectoryWGetCurrentProcessGetCurrentProcessIdGetCurrentThreadGetCurrentThreadIdGetDateFormatAGetDateFormatWGetDefaultCommConfigAGetDefaultCommConfigWGetDefaultSortkeySizeGetDevicePowerStateGetDiskFreeSpaceAGetDiskFreeSpaceExAGetDiskFreeSpaceExWGetDiskFreeSpaceWGetDllDirectoryAGetDllDirectoryWGetDriveTypeAGetDriveTypeWGetEnvironmentStringsGetEnvironmentStringsAGetEnvironmentStringsWGetEnvironmentVariableAGetEnvironmentVariableWGetExitCodeProcessGetExitCodeThreadGetExpandedNameAGetExpandedNameWGetFileAttributesAGetFileAttributesExAGetFileAttributesExWGetFileAttributesWGetFileInformationByHandleGetFileSizeGetFileSizeExGetFileTimeGetFileTypeGetFirmwareEnvironmentVariableAGetFirmwareEnvironmentVariableWGetFullPathNameAGetFullPathNameWGetGeoInfoAGetGeoInfoWGetHandleContextGetHandleInformationGetLargestConsoleWindowSizeGetLastErrorGetLinguistLangSizeGetLocalTimeGetLocaleInfoAGetLocaleInfoWGetLogicalDriveStringsAGetLogicalDriveStringsWGetLogicalDrivesGetLogicalProcessorInformationGetLongPathNameAGetLongPathNameWGetMailslotInfoGetModuleFileNameAGetModuleFileNameWGetModuleHandleAGetModuleHandleExAGetModuleHandleExWGetModuleHandleWGetNamedPipeHandleStateAGetNamedPipeHandleStateWGetNamedPipeInfoGetNativeSystemInfoGetNextVDMCommandGetNlsSectionNameGetNumaAvailableMemoryGetNumaAvailableMemoryNodeGetNumaHighestNodeNumberGetNumaNodeProcessorMaskGetNumaProcessorMapGetNumaProcessorNodeGetNumberFormatAGetNumberFormatWGetNumberOfConsoleFontsGetNumberOfConsoleInputEventsGetNumberOfConsoleMouseButtonsGetOEMCPGetOverlappedResultGetPriorityClassGetPrivateProfileIntAGetPrivateProfileIntWGetPrivateProfileSectionAGetPrivateProfileSectionNamesAGetPrivateProfileSectionNamesWGetPrivateProfileSectionWGetPrivateProfileStringAGetPrivateProfileStringWGetPrivateProfileStructAGetPrivateProfileStructWGetProcAddressGetProcessAffinityMaskGetProcessDEPPolicyGetProcessHandleCountGetProcessHeapGetProcessHeapsGetProcessIdGetProcessIoCountersGetProcessPriorityBoostGetProcessShutdownParametersGetProcessTimesGetProcessVersionGetProcessWorkingSetSizeGetProfileIntAGetProfileIntWGetProfileSectionAGetProfileSectionWGetProfileStringAGetProfileStringWGetQueuedCompletionStatusGetShortPathNameAGetShortPathNameWGetStartupInfoAGetStartupInfoWGetStdHandleGetStringTypeAGetStringTypeExAGetStringTypeExWGetStringTypeWGetSystemDEPPolicyGetSystemDefaultLCIDGetSystemDefaultLangIDGetSystemDefaultUILanguageGetSystemDirectoryAGetSystemDirectoryWGetSystemInfoGetSystemPowerStatusGetSystemRegistryQuotaGetSystemTimeGetSystemTimeAdjustmentGetSystemTimeAsFileTimeGetSystemTimesGetSystemWindowsDirectoryAGetSystemWindowsDirectoryWGetSystemWow64DirectoryAGetSystemWow64DirectoryWGetTapeParametersGetTapePositionGetTapeStatusGetTempFileNameAGetTempFileNameWGetTempPathAGetTempPathWGetThreadContextGetThreadIOPendingFlagGetThreadLocaleGetThreadPriorityGetThreadPriorityBoostGetThreadSelectorEntryGetThreadTimesGetTickCountGetTimeFormatAGetTimeFormatWGetTimeZoneInformationGetUserDefaultLCIDGetUserDefaultLangIDGetUserDefaultUILanguageGetUserGeoIDGetVDMCurrentDirectoriesGetVersionGetVersionExAGetVersionExWGetVolumeInformationAGetVolumeInformationWGetVolumeNameForVolumeMountPointAGetVolumeNameForVolumeMountPointWGetVolumePathNameAGetVolumePathNameWGetVolumePathNamesForVolumeNameAGetVolumePathNamesForVolumeNameWGetWindowsDirectoryAGetWindowsDirectoryWGetWriteWatchGlobalAddAtomAGlobalAddAtomWGlobalAllocGlobalCompactGlobalDeleteAtomGlobalFindAtomAGlobalFindAtomWGlobalFixGlobalFlagsGlobalFreeGlobalGetAtomNameAGlobalGetAtomNameWGlobalHandleGlobalLockGlobalMemoryStatusGlobalMemoryStatusExGlobalReAllocGlobalSizeGlobalUnWireGlobalUnfixGlobalUnlockGlobalWire HHeap32FirstHeap32ListFirstHeap32ListNextHeap32NextHeapAllocHeapCompactHeapCreateHeapCreateTagsWHeapDestroyHeapExtendHeapFreeHeapLockHeapQueryInformationHeapQueryTagWHeapReAllocHeapSetInformationHeapSizeHeapSummaryHeapUnlockHeapUsageHeapValidateHeapWalkIInitAtomTableInitializeCriticalSectionInitializeCriticalSectionAndSpinCountInitializeSListHeadInterlockedCompareExchangeInterlockedDecrementInterlockedExchangeInterlockedExchangeAddInterlockedFlushSListInterlockedIncrementInterlockedPopEntrySListInterlockedPushEntrySListInvalidateConsoleDIBitsIsBadCodePtrIsBadHugeReadPtrIsBadHugeWritePtrIsBadReadPtrIsBadStringPtrAIsBadStringPtrWIsBadWritePtrIsDBCSLeadByteIsDBCSLeadByteExIsDebuggerPresentIsProcessInJobIsProcessorFeaturePresentIsSystemResumeAutomaticIsValidCodePageIsValidLanguageGroupIsValidLocaleIsValidUILanguageIsWow64ProcessLLCMapStringALCMapStringWLZCloseLZCloseFileLZCopyLZCreateFileWLZDoneLZInitLZOpenFileALZOpenFileWLZReadLZSeekLZStartLeaveCriticalSectionLoadLibraryALoadLibraryExALoadLibraryExWLoadLibraryWLoadModuleLoadResourceLocalAllocLocalCompactLocalFileTimeToFileTimeLocalFlagsLocalFreeLocalHandleLocalLockLocalReAllocLocalShrinkLocalSizeLocalUnlockLockFileLockFileExLockResource MMapUserPhysicalPagesMapUserPhysicalPagesScatterMapViewOfFileMapViewOfFileExModule32FirstModule32FirstWModule32NextModule32NextWMoveFileAMoveFileExAMoveFileExWMoveFileWMoveFileWithProgressAMoveFileWithProgressWMulDivMultiByteToWideCharNNlsConvertIntegerToStringNlsGetCacheUpdateCountNlsResetProcessLocaleNumaVirtualQueryNodeOOpenConsoleWOpenDataFileOpenEventAOpenEventWOpenFileOpenFileMappingAOpenFileMappingWOpenJobObjectAOpenJobObjectWOpenMutexAOpenMutexWOpenProcessOpenProfileUserMappingOpenSemaphoreAOpenSemaphoreWOpenThreadOpenWaitableTimerAOpenWaitableTimerWOutputDebugStringAOutputDebugStringWPPeekConsoleInputAPeekConsoleInputWPeekNamedPipePostQueuedCompletionStatusPrepareTapePrivCopyFileExWPrivMoveFileIdentityWProcess32FirstProcess32FirstWProcess32NextProcess32NextWProcessIdToSessionIdPulseEventPurgeCommQQueryActCtxWQueryDepthSListQueryDosDeviceAQueryDosDeviceWQueryInformationJobObjectQueryMemoryResourceNotificationQueryPerformanceCounterQueryPerformanceFrequencyQueryWin31IniFilesMappedToRegistryQueueUserAPCQueueUserWorkItem RRaiseExceptionReadConsoleAReadConsoleInputAReadConsoleInputExAReadConsoleInputExWReadConsoleInputWReadConsoleOutputAReadConsoleOutputAttributeReadConsoleOutputCharacterAReadConsoleOutputCharacterWReadConsoleOutputWReadConsoleWReadDirectoryChangesWReadFileReadFileExReadFileScatterReadProcessMemoryRegisterConsoleIMERegisterConsoleOS2RegisterConsoleVDMRegisterWaitForInputIdleRegisterWaitForSingleObjectRegisterWaitForSingleObjectExRegisterWowBaseHandlersRegisterWowExecReleaseActCtxReleaseMutexReleaseSemaphoreRemoveDirectoryARemoveDirectoryWRemoveLocalAlternateComputerNameARemoveLocalAlternateComputerNameWRemoveVectoredExceptionHandlerReplaceFileReplaceFileAReplaceFileWRequestDeviceWakeupRequestWakeupLatencyResetEventResetWriteWatchRestoreLastErrorResumeThreadRtlCaptureContextRtlCaptureStackBackTraceRtlFillMemoryRtlMoveMemoryRtlUnwindRtlZeroMemorySScrollConsoleScreenBufferAScrollConsoleScreenBufferWSearchPathASearchPathWSetCPGlobalSetCalendarInfoASetCalendarInfoWSetClientTimeZoneInformationSetComPlusPackageInstallStatusSetCommBreakSetCommConfigSetCommMaskSetCommStateSetCommTimeoutsSetComputerNameASetComputerNameExASetComputerNameExWSetComputerNameWSetConsoleActiveScreenBufferSetConsoleCPSetConsoleCommandHistoryModeSetConsoleCtrlHandlerSetConsoleCursorSetConsoleCursorInfoSetConsoleCursorModeSetConsoleCursorPositionSetConsoleDisplayModeSetConsoleFontSetConsoleHardwareStateSetConsoleIconSetConsoleInputExeNameASetConsoleInputExeNameWSetConsoleKeyShortcutsSetConsoleLocalEUDCSetConsoleMaximumWindowSizeSetConsoleMenuCloseSetConsoleModeSetConsoleNlsModeSetConsoleNumberOfCommandsASetConsoleNumberOfCommandsWSetConsoleOS2OemFormatSetConsoleOutputCPSetConsolePaletteSetConsoleScreenBufferSizeSetConsoleTextAttributeSetConsoleTitleASetConsoleTitleWSetConsoleWindowInfoSetCriticalSectionSpinCountSetCurrentDirectoryASetCurrentDirectoryWSetDefaultCommConfigASetDefaultCommConfigWSetDllDirectoryASetDllDirectoryWSetEndOfFileSetEnvironmentVariableASetEnvironmentVariableWSetErrorModeSetEventSetFileApisToANSISetFileApisToOEMSetFileAttributesASetFileAttributesWSetFilePointerSetFilePointerExSetFileShortNameASetFileShortNameWSetFileTimeSetFileValidDataSetFirmwareEnvironmentVariableASetFirmwareEnvironmentVariableWSetHandleContextSetHandleCountSetHandleInformationSetInformationJobObjectSetLastConsoleEventActiveSetLastErrorSetLocalPrimaryComputerNameASetLocalPrimaryComputerNameWSetLocalTimeSetLocaleInfoASetLocaleInfoWSetMailslotInfoSetMessageWaitingIndicatorSetNamedPipeHandleStateSetPriorityClassSetProcessAffinityMaskSetProcessDEPPolicySetProcessPriorityBoostSetProcessShutdownParametersSetProcessWorkingSetSizeSetSearchPathModeSetStdHandleSetSystemPowerStateSetSystemTimeSetSystemTimeAdjustmentSetTapeParametersSetTapePositionSetTermsrvAppInstallModeSetThreadAffinityMaskSetThreadContextSetThreadExecutionStateSetThreadIdealProcessorSetThreadLocaleSetThreadPrioritySetThreadPriorityBoostSetThreadUILanguageSetTimeZoneInformationSetTimerQueueTimerSetUnhandledExceptionFilterSetUserGeoIDSetVDMCurrentDirectoriesSetVolumeLabelASetVolumeLabelWSetVolumeMountPointASetVolumeMountPointWSetWaitableTimerSetupCommShowConsoleCursorSignalObjectAndWaitSizeofResourceSleepSleepExSuspendThreadSwitchToFiberSwitchToThreadSystemTimeToFileTimeSystemTimeToTzSpecificLocalTime TTerminateJobObjectTerminateProcessTerminateThreadTermsrvAppInstallModeThread32FirstThread32NextTlsAllocTlsFreeTlsGetValueTlsSetValueToolhelp32ReadProcessMemoryTransactNamedPipeTransmitCommCharTrimVirtualBufferTryEnterCriticalSectionTzSpecificLocalTimeToSystemTimeUUTRegisterUTUnRegisterUnhandledExceptionFilterUnlockFileUnlockFileExUnmapViewOfFileUnregisterConsoleIMEUnregisterWaitUnregisterWaitExUpdateResourceAUpdateResourceWVVDMConsoleOperationVDMOperationStartedValidateLCTypeValidateLocaleVerLanguageNameAVerLanguageNameWVerSetConditionMaskVerifyConsoleIoHandleVerifyVersionInfoAVerifyVersionInfoWVirtualAllocVirtualAllocExVirtualBufferExceptionHandlerVirtualFreeVirtualFreeExVirtualLockVirtualProtectVirtualProtectExVirtualQueryVirtualQueryExVirtualUnlockWWTSGetActiveConsoleSessionIdWaitCommEventWaitForDebugEventWaitForMultipleObjectsWaitForMultipleObjectsExWaitForSingleObjectWaitForSingleObjectExWaitNamedPipeAWaitNamedPipeWWideCharToMultiByteWinExecWriteConsoleAWriteConsoleInputAWriteConsoleInputVDMAWriteConsoleInputVDMWWriteConsoleInputWWriteConsoleOutputAWriteConsoleOutputAttributeWriteConsoleOutputCharacterAWriteConsoleOutputCharacterWWriteConsoleOutputWWriteConsoleWWriteFileWriteFileExWriteFileGatherWritePrivateProfileSectionAWritePrivateProfileSectionWWritePrivateProfileStringAWritePrivateProfileStringWWritePrivateProfileStructAWritePrivateProfileStructWWriteProcessMemoryWriteProfileSectionAWriteProfileSectionWWriteProfileStringAWriteProfileStringWWriteTapemark ZZombifyActCtx__hread_hwrite_lclose_lcreat_llseek_lopen_lread_lwritellstrcatlstrcatAlstrcatWlstrcmplstrcmpAlstrcmpWlstrcmpilstrcmpiAlstrcmpiWlstrcpylstrcpyAlstrcpyWlstrcpynlstrcpynAlstrcpynWlstrlenlstrlenAlstrlenW