|
66 | 66 | @ stdcall CommandLineFromMsiDescriptor(wstr ptr ptr)
|
67 | 67 | @ stub ComputeAccessTokenFromCodeAuthzLevel
|
68 | 68 | @ stdcall ControlService(long long ptr)
|
69 |
| -@ stdcall ControlTraceA(double str ptr long) ntdll.EtwControlTraceA |
70 |
| -@ stdcall ControlTraceW(double wstr ptr long) ntdll.EtwControlTraceW |
| 69 | +@ stdcall -version=0x502 ControlTraceA(double str ptr long) ntdll.EtwControlTraceA |
| 70 | +@ stdcall -stub -version=0x600+ ControlTraceA(double str ptr long) |
| 71 | +@ stdcall -version=0x502 ControlTraceW(double wstr ptr long) ntdll.EtwControlTraceW |
| 72 | +@ stdcall -stub -version=0x600+ ControlTraceW(double wstr ptr long) |
71 | 73 | @ stub ConvertAccessToSecurityDescriptorA
|
72 | 74 | @ stub ConvertAccessToSecurityDescriptorW
|
73 | 75 | @ stub ConvertSDToStringSDRootDomainA
|
|
201 | 203 | @ stdcall ElfReportEventA(long long long long ptr long long ptr ptr long ptr ptr)
|
202 | 204 | @ stdcall ElfReportEventAndSourceW(long long ptr long long long ptr ptr long long ptr ptr long ptr ptr)
|
203 | 205 | @ stdcall ElfReportEventW(long long long long ptr long long ptr ptr long ptr ptr)
|
204 |
| -@ stdcall EnableTrace(long long long ptr double) ntdll.EtwEnableTrace |
| 206 | +@ stdcall -version=0x502 EnableTrace(long long long ptr double) ntdll.EtwEnableTrace |
| 207 | +@ stdcall -stub -version=0x600+ EnableTrace(long long long ptr double) |
205 | 208 | @ stdcall EncryptFileA(str)
|
206 | 209 | @ stdcall EncryptFileW(wstr)
|
207 | 210 | @ stub EncryptedFileKeyInfo
|
|
213 | 216 | @ stdcall EnumServicesStatusExA(long long long long ptr long ptr ptr ptr str)
|
214 | 217 | @ stdcall EnumServicesStatusExW(long long long long ptr long ptr ptr ptr wstr)
|
215 | 218 | @ stdcall EnumServicesStatusW(long long long ptr long ptr ptr ptr)
|
216 |
| -@ stdcall EnumerateTraceGuids(ptr long ptr) ntdll.EtwEnumerateTraceGuids |
| 219 | +@ stdcall -version=0x502 EnumerateTraceGuids(ptr long ptr) ntdll.EtwEnumerateTraceGuids |
| 220 | +@ stdcall -stub -version=0x600+ EnumerateTraceGuids(ptr long ptr) |
217 | 221 | @ stdcall EqualDomainSid(ptr ptr ptr)
|
218 | 222 | @ stdcall EqualPrefixSid(ptr ptr)
|
219 | 223 | @ stdcall EqualSid(ptr ptr)
|
220 | 224 | @ stdcall FileEncryptionStatusA(str ptr)
|
221 | 225 | @ stdcall FileEncryptionStatusW(wstr ptr)
|
222 | 226 | @ stdcall FindFirstFreeAce(ptr ptr)
|
223 |
| -@ stdcall FlushTraceA(double str ptr) ntdll.EtwFlushTraceA |
224 |
| -@ stdcall FlushTraceW(double wstr ptr) ntdll.EtwFlushTraceW |
| 227 | +@ stdcall -version=0x502 FlushTraceA(double str ptr) ntdll.EtwFlushTraceA |
| 228 | +@ stdcall -stub -version=0x600+ FlushTraceA(double str ptr) |
| 229 | +@ stdcall -version=0x502 FlushTraceW(double wstr ptr) ntdll.EtwFlushTraceW |
| 230 | +@ stdcall -stub -version=0x600+ FlushTraceW(double wstr ptr) |
225 | 231 | @ stub FreeEncryptedFileKeyInfo
|
226 | 232 | @ stdcall FreeEncryptionCertificateHashList(ptr)
|
227 | 233 | @ stdcall FreeInheritedFromArray(ptr long ptr)
|
|
439 | 445 | @ stdcall PrivilegedServiceAuditAlarmW(wstr wstr long ptr long)
|
440 | 446 | @ stub ProcessIdleTasks
|
441 | 447 | @ stdcall ProcessTrace(ptr long ptr ptr)
|
442 |
| -@ stdcall QueryAllTracesA(ptr long ptr) ntdll.EtwQueryAllTracesA |
443 |
| -@ stdcall QueryAllTracesW(ptr long ptr) ntdll.EtwQueryAllTracesW |
| 448 | +@ stdcall -version=0x502 QueryAllTracesA(ptr long ptr) ntdll.EtwQueryAllTracesA |
| 449 | +@ stdcall -stub -version=0x600+ QueryAllTracesA(ptr long ptr) |
| 450 | +@ stdcall -version=0x502 QueryAllTracesW(ptr long ptr) ntdll.EtwQueryAllTracesW |
| 451 | +@ stdcall -stub -version=0x600+ QueryAllTracesW(ptr long ptr) |
444 | 452 | @ stdcall QueryRecoveryAgentsOnEncryptedFile(wstr ptr)
|
445 | 453 | @ stdcall QueryServiceConfig2A(long long ptr long ptr)
|
446 | 454 | @ stdcall QueryServiceConfig2W(long long ptr long ptr)
|
|
451 | 459 | @ stdcall QueryServiceObjectSecurity(long long ptr long ptr)
|
452 | 460 | @ stdcall QueryServiceStatus(long ptr)
|
453 | 461 | @ stdcall QueryServiceStatusEx(long long ptr long ptr)
|
454 |
| -@ stdcall QueryTraceA(double str ptr) ntdll.EtwQueryTraceA |
455 |
| -@ stdcall QueryTraceW(double str ptr) ntdll.EtwQueryTraceA |
| 462 | +@ stdcall -version=0x502 QueryTraceA(double str ptr) ntdll.EtwQueryTraceA |
| 463 | +@ stdcall -stub -version=0x600+ QueryTraceA(double str ptr) |
| 464 | +@ stdcall -version=0x502 QueryTraceW(double str ptr) ntdll.EtwQueryTraceW |
| 465 | +@ stdcall -stub -version=0x600+ QueryTraceW(double str ptr) |
456 | 466 | @ stdcall QueryUsersOnEncryptedFile(wstr ptr)
|
457 | 467 | @ stdcall ReadEncryptedFileRaw(ptr ptr ptr)
|
458 | 468 | @ stdcall ReadEventLogA(long long long ptr long ptr ptr)
|
|
587 | 597 | @ stdcall StartServiceCtrlDispatcherA(ptr)
|
588 | 598 | @ stdcall StartServiceCtrlDispatcherW(ptr)
|
589 | 599 | @ stdcall StartServiceW(long long ptr)
|
590 |
| -@ stdcall StartTraceA(ptr str ptr) ntdll.EtwStartTraceA |
591 |
| -@ stdcall StartTraceW(ptr wstr ptr) ntdll.EtwStartTraceW |
592 |
| -@ stdcall StopTraceA(double str ptr) ntdll.EtwStopTraceA |
593 |
| -@ stdcall StopTraceW(double wstr ptr) ntdll.EtwStopTraceA |
| 600 | +@ stdcall -version=0x502 StartTraceA(ptr str ptr) ntdll.EtwStartTraceA |
| 601 | +@ stdcall -stub -version=0x600+ StartTraceA(ptr str ptr) |
| 602 | +@ stdcall -version=0x502 StartTraceW(ptr wstr ptr) ntdll.EtwStartTraceW |
| 603 | +@ stdcall -stub -version=0x600+ StartTraceW(ptr wstr ptr) |
| 604 | +@ stdcall -version=0x502 StopTraceA(double str ptr) ntdll.EtwStopTraceA |
| 605 | +@ stdcall -stub -version=0x600+ StopTraceA(double str ptr) |
| 606 | +@ stdcall -version=0x502 StopTraceW(double wstr ptr) ntdll.EtwStopTraceW |
| 607 | +@ stdcall -stub -version=0x600+ StopTraceW(double wstr ptr) |
594 | 608 | @ stdcall SystemFunction001(ptr ptr ptr)
|
595 | 609 | @ stdcall SystemFunction002(ptr ptr ptr)
|
596 | 610 | @ stdcall SystemFunction003(ptr ptr)
|
|
629 | 643 | @ stdcall SystemFunction036(ptr long) # RtlGenRandom
|
630 | 644 | @ stdcall SystemFunction040(ptr long long) # RtlEncryptMemory
|
631 | 645 | @ stdcall SystemFunction041(ptr long long) # RtlDecryptMemory
|
632 |
| -@ stdcall TraceEvent(double ptr) ntdll.EtwTraceEvent |
| 646 | +@ stdcall -version=0x502 TraceEvent(double ptr) ntdll.EtwTraceEvent |
| 647 | +@ stdcall -stub -version=0x600+ TraceEvent(double ptr) |
633 | 648 | @ stdcall TraceEventInstance(double ptr ptr ptr) ntdll.EtwTraceEventInstance
|
634 | 649 | @ varargs TraceMessage() ntdll.EtwTraceMessage
|
635 | 650 | @ stdcall TraceMessageVa() ntdll.EtwTraceMessageVa
|
|
641 | 656 | @ stdcall UnlockServiceDatabase(ptr)
|
642 | 657 | @ stub UnregisterIdleTask
|
643 | 658 | @ stdcall UnregisterTraceGuids(double) ntdll.EtwUnregisterTraceGuids
|
644 |
| -@ stdcall UpdateTraceA(double str ptr) ntdll.EtwUpdateTraceA |
645 |
| -@ stdcall UpdateTraceW(double wstr ptr) ntdll.EtwUpdateTraceW |
| 659 | +@ stdcall -version=0x502 UpdateTraceA(double str ptr) ntdll.EtwUpdateTraceA |
| 660 | +@ stdcall -stub -version=0x600+ UpdateTraceA(double str ptr) |
| 661 | +@ stdcall -version=0x502 UpdateTraceW(double wstr ptr) ntdll.EtwUpdateTraceW |
| 662 | +@ stdcall -stub -version=0x600+ UpdateTraceW(double wstr ptr) |
646 | 663 | @ stub WdmWmiServiceMain
|
647 | 664 | @ stub WmiCloseBlock
|
648 | 665 | @ stub WmiCloseTraceWithCursor
|
|
660 | 677 | @ stub WmiGetTraceHeader
|
661 | 678 | @ stub WmiMofEnumerateResourcesA
|
662 | 679 | @ stub WmiMofEnumerateResourcesW
|
663 |
| -@ stdcall WmiNotificationRegistrationA(ptr long ptr long long) ntdll.EtwNotificationRegistrationA |
664 |
| -@ stdcall WmiNotificationRegistrationW(ptr long ptr long long) ntdll.EtwNotificationRegistrationW |
| 680 | +@ stdcall -version=0x502 WmiNotificationRegistrationA(ptr long ptr long long) ntdll.EtwNotificationRegistrationA |
| 681 | +@ stdcall -stub -version=0x600+ WmiNotificationRegistrationA(ptr long ptr long long) |
| 682 | +@ stdcall -version=0x502 WmiNotificationRegistrationW(ptr long ptr long long) ntdll.EtwNotificationRegistrationW |
| 683 | +@ stdcall -stub -version=0x600+ WmiNotificationRegistrationW(ptr long ptr long long) |
665 | 684 | @ stub WmiOpenBlock
|
666 | 685 | @ stub WmiOpenTraceWithCursor
|
667 | 686 | @ stub WmiParseTraceEvent
|
|
674 | 693 | @ stub WmiQuerySingleInstanceMultipleA
|
675 | 694 | @ stub WmiQuerySingleInstanceMultipleW
|
676 | 695 | @ stub WmiQuerySingleInstanceW
|
677 |
| -@ stdcall WmiReceiveNotificationsA(long long long long) ntdll.EtwReceiveNotificationsA |
678 |
| -@ stdcall WmiReceiveNotificationsW(long long long long) ntdll.EtwReceiveNotificationsW |
| 696 | +@ stdcall -version=0x502 WmiReceiveNotificationsA(long long long long) ntdll.EtwReceiveNotificationsA |
| 697 | +@ stdcall -stub -version=0x600+ WmiReceiveNotificationsA(long long long long) |
| 698 | +@ stdcall -version=0x502 WmiReceiveNotificationsW(long long long long) ntdll.EtwReceiveNotificationsW |
| 699 | +@ stdcall -stub -version=0x600+ WmiReceiveNotificationsW(long long long long) |
679 | 700 | @ stub WmiSetSingleInstanceA
|
680 | 701 | @ stub WmiSetSingleInstanceW
|
681 | 702 | @ stub WmiSetSingleItemA
|
|
0 commit comments