home *** CD-ROM | disk | FTP | other *** search
/ PC World 2005 April / PCWorld_2005-04_cd.bin / software / vyzkuste / vcatch / vcsetup.exe / %SYS% / RulesData.xml < prev    next >
Encoding:
Extensible Markup Language  |  2005-02-04  |  95.7 KB  |  3,796 lines

  1. <?xml version="1.0"?>
  2. <RULES>
  3.     <RULE>
  4.         <NAME>Rule_Fake_Entry_Point  </NAME>
  5.         <TYPE>0</TYPE>
  6.         <ID>0</ID>
  7.         <RULEITEMS>
  8.         </RULEITEMS>
  9.     </RULE>
  10.     <RULE>
  11.         <NAME> Rule_Writable_Sections</NAME>
  12.         <TYPE>1</TYPE>
  13.         <ID>1</ID>
  14.         <RULEITEMS>
  15.         </RULEITEMS>
  16.     </RULE>
  17.     <RULE>
  18.         <NAME> Rule_Executable_Sections</NAME>
  19.         <TYPE>2</TYPE>
  20.         <ID>2</ID>
  21.         <RULEITEMS>
  22.         </RULEITEMS>
  23.     </RULE>
  24.     <RULE>
  25.         <NAME>Rule_Sections_Size  </NAME>
  26.         <TYPE>3</TYPE>
  27.         <ID>3</ID>
  28.         <RULEITEMS>
  29.         </RULEITEMS>
  30.     </RULE>
  31.     <RULE>
  32.         <NAME> Rule_Sections_name</NAME>
  33.         <TYPE>4</TYPE>
  34.         <ID>4</ID>
  35.         <VALUE>0</VALUE>
  36.         <RULEITEMS>
  37.             <RULEITEM><NAME>CODE</NAME>            </RULEITEM>
  38.             <RULEITEM><NAME>DATA</NAME>            </RULEITEM>
  39.             <RULEITEM><NAME>AUTO</NAME>            </RULEITEM>
  40.             <RULEITEM><NAME>BSS</NAME>            </RULEITEM>
  41.             <RULEITEM><NAME>TLS</NAME>            </RULEITEM>
  42.             <RULEITEM><NAME>.bss</NAME></RULEITEM>
  43.             <RULEITEM><NAME>.tls</NAME>            </RULEITEM>
  44.             <RULEITEM><NAME>.CRT</NAME>            </RULEITEM>
  45.             <RULEITEM><NAME>.INIT</NAME>            </RULEITEM>
  46.             <RULEITEM><NAME>.text</NAME>            </RULEITEM>
  47.             <RULEITEM><NAME>.data</NAME>            </RULEITEM>
  48.             <RULEITEM><NAME>TLS</NAME>            </RULEITEM>
  49.             <RULEITEM><NAME>.rsrc</NAME></RULEITEM>
  50.             <RULEITEM><NAME>.reloc</NAME>            </RULEITEM>
  51.             <RULEITEM><NAME>.idata</NAME>            </RULEITEM>
  52.             <RULEITEM><NAME>.sdata</NAME>            </RULEITEM>
  53.             <RULEITEM><NAME>.rdata</NAME></RULEITEM>
  54.             <RULEITEM><NAME>.edata</NAME>            </RULEITEM>
  55.             <RULEITEM><NAME>.debug</NAME></RULEITEM>
  56.             <RULEITEM><NAME>DGROUP</NAME></RULEITEM>
  57.         </RULEITEMS>
  58.     </RULE>
  59.     <RULE>
  60.         <NAME> Rule_Sections_name</NAME>
  61.         <TYPE>4</TYPE>
  62.         <ID>5</ID>
  63.         <RULEITEMS>
  64.             <RULEITEM><NAME>aspack</NAME>
  65.             </RULEITEM>
  66.             <RULEITEM><NAME>UPX0</NAME>
  67.             </RULEITEM>
  68.             <RULEITEM><NAME>UPX1</NAME>
  69.             </RULEITEM>
  70.         </RULEITEMS>
  71.     </RULE>
  72.     <RULE>
  73.         <NAME> Rule_Jump_Non_Code </NAME>
  74.         <TYPE>5</TYPE>
  75.         <ID>6</ID>
  76.         <RULEITEMS>
  77.         </RULEITEMS>
  78.     </RULE>
  79.     <RULE>
  80.         <NAME>Rule_Data_StartUp </NAME>
  81.         <TYPE>6</TYPE>
  82.         <ID>7</ID>
  83.         <RULEITEMS>
  84.             <RULEITEM>
  85.                 <NAME>Software\Microsoft\Windows\CurrentVersion\Run</NAME>
  86.             </RULEITEM>
  87.             <RULEITEM>
  88.                 <NAME>System\CurrentControlSet\Services</NAME>
  89.             </RULEITEM>
  90.             <RULEITEM>
  91.                 <NAME>Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders</NAME>
  92.             </RULEITEM>
  93.             <RULEITEM>
  94.                 <NAME>Software\Microsoft\Windows\CurrentVersion\RunServices</NAME>
  95.             </RULEITEM>
  96.             <RULEITEM>
  97.                 <NAME>Software\Microsoft\Windows\CurrentVersion\RunOnce</NAME>
  98.             </RULEITEM>
  99.             <RULEITEM>
  100.                 <NAME>Software\Microsoft\WindowsNT\CurrentVersion\Winlogon</NAME>
  101.             </RULEITEM>
  102.             <RULEITEM>
  103.                 <NAME>autoexec.bat</NAME></RULEITEM>
  104.             <RULEITEM>
  105.                 <NAME>wininit.ini</NAME></RULEITEM>
  106.             <RULEITEM>
  107.                 <NAME>System.ini</NAME></RULEITEM>
  108.             <RULEITEM>
  109.                 <NAME>Mirc.ini</NAME></RULEITEM>
  110.         </RULEITEMS>
  111.         <RULESEMIITEMS>
  112.             <RULESEMIITEM>
  113.                 <NAME>Software\Microsoft\Windows\CurrentVersion</NAME></RULESEMIITEM>
  114.             <RULESEMIITEM>
  115.                 <NAME>Software\Microsoft\WindowsNT\CurrentVersion\WINDOWS</NAME></RULESEMIITEM>
  116.         </RULESEMIITEMS>
  117.     </RULE>
  118.     <RULE>
  119.         <NAME> Rule_Data_AppName</NAME>
  120.         <TYPE>6</TYPE>
  121.         <ID>8</ID>
  122.         <RULEITEMS>
  123.             <RULEITEM><NAME>Aplica32.exe</NAME>
  124.             </RULEITEM>
  125.             <RULEITEM><NAME>Avconsol.exe</NAME>
  126.             </RULEITEM>
  127.             <RULEITEM><NAME>Avp.exe</NAME>
  128.             </RULEITEM>
  129.             <RULEITEM><NAME>Avp32.exe</NAME>
  130.             </RULEITEM>
  131.             <RULEITEM><NAME>Avpcc.exe</NAME>
  132.             </RULEITEM>
  133.             <RULEITEM><NAME>Avpm.exe</NAME>
  134.             </RULEITEM>
  135.             <RULEITEM><NAME>Cfiadmin.exe</NAME>
  136.             </RULEITEM>
  137.             <RULEITEM><NAME>Cfiaudit.exe</NAME>
  138.             </RULEITEM>
  139.             <RULEITEM><NAME>Cfinet32.exe</NAME>
  140.             </RULEITEM>
  141.             <RULEITEM><NAME>Esafe.exe</NAME>
  142.             </RULEITEM>
  143.             <RULEITEM><NAME>Frw.exe    </NAME>
  144.             </RULEITEM>
  145.             <RULEITEM><NAME>Icload95.exe</NAME>
  146.             </RULEITEM>
  147.             <RULEITEM><NAME>Icloadnt.exe</NAME>
  148.             </RULEITEM>
  149.             <RULEITEM><NAME>Icmon.exe</NAME>
  150.             </RULEITEM>
  151.             <RULEITEM><NAME>Icsupp95.Exe</NAME>
  152.             </RULEITEM>
  153.             <RULEITEM><NAME>Icsuppnt.exe</NAME>
  154.             </RULEITEM>
  155.             <RULEITEM><NAME>Lockdown2000.exe</NAME>
  156.             </RULEITEM>
  157.             <RULEITEM><NAME>Navapw32.exe</NAME>
  158.             </RULEITEM>
  159.             <RULEITEM><NAME>Navw32.exe</NAME>
  160.             </RULEITEM>
  161.             <RULEITEM><NAME>Pcfwallicon.exe</NAME>
  162.             </RULEITEM>
  163.             <RULEITEM><NAME>Safeweb.exe</NAME>
  164.             </RULEITEM>
  165.             <RULEITEM><NAME>Tds2-98.exe</NAME>
  166.             </RULEITEM>
  167.             <RULEITEM><NAME>Tds2-Nt.exe</NAME>
  168.             </RULEITEM>
  169.             <RULEITEM><NAME>Vsecomr.exe</NAME>
  170.             </RULEITEM>
  171.             <RULEITEM><NAME>Vshwin32.exe</NAME>
  172.             </RULEITEM>
  173.             <RULEITEM><NAME>Vsstat.exe</NAME>
  174.             </RULEITEM>
  175.             <RULEITEM><NAME>Webscanx.exe</NAME>
  176.             </RULEITEM>
  177.             <RULEITEM><NAME>Zonealarm.exe</NAME>
  178.             </RULEITEM>
  179.             <RULEITEM><NAME>_Avp32.exe</NAME>
  180.             </RULEITEM>
  181.             <RULEITEM><NAME>_Avpcc.exe</NAME>
  182.             </RULEITEM>
  183.             <RULEITEM><NAME>_Avpm.exe</NAME>
  184.             </RULEITEM>
  185.         </RULEITEMS>
  186.     </RULE>
  187.     <RULE>
  188.         <TYPE>7</TYPE>
  189.         <ID>9</ID>
  190.         <NAME> Rule_Data_Check_Bytes</NAME>
  191.         <RULEITEMS>
  192.             <RULEITEM><DATASIZE>4</DATASIZE><DATA>66ED4D5A</DATA></RULEITEM>
  193.             <RULEITEM><DATASIZE>16</DATASIZE><DATA>01DF020000000000C000000000000046</DATA></RULEITEM>
  194.         </RULEITEMS>
  195.     </RULE>
  196.     <RULE>
  197.         <NAME>Rule_Func_Lib_AntiDebug</NAME>
  198.         <TYPE>8</TYPE>
  199.         <ID>10</ID>
  200.         <RULEITEMS>
  201.             <RULEITEM><NAME>IsDebuggerPresent</NAME></RULEITEM>
  202.             <RULEITEM><NAME>ImageHlp.dll</NAME></RULEITEM>
  203.         </RULEITEMS>
  204.     </RULE>
  205.     <RULE>
  206.         <NAME> Rule_Func_UnRefered</NAME>
  207.         <TYPE>9</TYPE>
  208.         <ID>11</ID>
  209.         <RULEITEMS>
  210.         </RULEITEMS>
  211.     </RULE>
  212.     <RULE>
  213.         <NAME> Rule_Lib_RT</NAME>
  214.         <TYPE>8</TYPE>
  215.         <ID>12</ID>
  216.         <RULEITEMS>
  217.             <RULEITEM><NAME>MSVBVM60.DLL</NAME></RULEITEM>
  218.         </RULEITEMS>
  219.     </RULE>
  220.     <RULE>
  221.         <NAME>Rule_Func_Lib_COM</NAME>
  222.         <TYPE>8</TYPE>
  223.         <ID>13</ID>
  224.         <RULEITEMS>
  225.             <RULEITEM><NAME>CoCreateInstance</NAME></RULEITEM>
  226.         </RULEITEMS>
  227.     </RULE>
  228.     <RULE>
  229.         <NAME>Rule_File_Name_Size Screen Saver</NAME>
  230.         <TYPE>10</TYPE>
  231.         <ID>14</ID>
  232.         <RULEITEMS>
  233.         </RULEITEMS>
  234.         <RULESEMIITEMS>
  235.             <RULESEMIITEM><NAME>.SCR;</NAME></RULESEMIITEM>
  236.         </RULESEMIITEMS>
  237.     </RULE>
  238.     <RULE>
  239.         <NAME>Rule_File_Shell_Open</NAME>
  240.         <TYPE>11</TYPE>
  241.         <ID>15</ID>
  242.         <RULEITEMS>
  243.             <RULEITEM><NAME>wscript.exe</NAME></RULEITEM>
  244.         </RULEITEMS>
  245.     </RULE>
  246.     <RULE>
  247.         <NAME>Rule_File_Company</NAME>
  248.         <TYPE>12</TYPE>
  249.         <ID>16</ID>
  250.         <RULEITEMS>
  251.             <RULEITEM><NAME>CommonSearch</NAME></RULEITEM>
  252.             <RULEITEM><NAME>Microsoft Corporation</NAME></RULEITEM>
  253.         </RULEITEMS>
  254.     </RULE>
  255.     <RULE>
  256.         <NAME>Rule_File_VersionInfo</NAME>
  257.         <TYPE>13</TYPE>
  258.         <ID>17</ID>
  259.         <RULEITEMS>
  260.         </RULEITEMS>
  261.     </RULE>
  262.     <RULE>
  263.         <NAME>Rule_Func_Win32 File I/O - Modify functions</NAME>
  264.         <TYPE>8</TYPE>
  265.         <ID>-19</ID>
  266.         <RULEITEMS>
  267.             <RULEITEM><NAME>_hwrite</NAME></RULEITEM>
  268.             <RULEITEM><NAME>_lwrite</NAME></RULEITEM>
  269.             <RULEITEM><NAME>_lcreat</NAME></RULEITEM>
  270.             <RULEITEM><NAME>CopyFileA</NAME></RULEITEM>
  271.             <RULEITEM><NAME>CopyFileW</NAME></RULEITEM>
  272.             <RULEITEM><NAME>CreateDirectoryA</NAME></RULEITEM>
  273.             <RULEITEM><NAME>CreateDirectoryExA</NAME></RULEITEM>
  274.             <RULEITEM><NAME>CreateDirectoryExW</NAME></RULEITEM>
  275.             <RULEITEM><NAME>CreateDirectoryW</NAME></RULEITEM>
  276.             <RULEITEM><NAME>CreateFileA</NAME></RULEITEM>
  277.             <RULEITEM><NAME>CreateFileW</NAME></RULEITEM>
  278.             <RULEITEM><NAME>DeleteFileA</NAME></RULEITEM>
  279.             <RULEITEM><NAME>DeleteFileW</NAME></RULEITEM>
  280.             <RULEITEM><NAME>MoveFileA</NAME></RULEITEM>
  281.             <RULEITEM><NAME>MoveFileW</NAME></RULEITEM>
  282.             <RULEITEM>
  283.                 <NAME>RemoveDirectoryA</NAME>
  284.             </RULEITEM>
  285.             <RULEITEM>
  286.                 <NAME>RemoveDirectoryW</NAME>
  287.             </RULEITEM>
  288.             <RULEITEM>
  289.                 <NAME>SetFileAttributesA</NAME>
  290.             </RULEITEM>
  291.             <RULEITEM>
  292.                 <NAME>SetFileAttributesW</NAME>
  293.             </RULEITEM>
  294.             <RULEITEM>
  295.                 <NAME>SetVolumeLabelA</NAME>
  296.             </RULEITEM>
  297.             <RULEITEM>
  298.                 <NAME>SetVolumeLabelW</NAME>
  299.             </RULEITEM>
  300.             <RULEITEM>
  301.                 <NAME>WriteFile</NAME>
  302.             </RULEITEM>
  303.             <RULEITEM>
  304.                 <NAME>WriteFileEx</NAME>
  305.             </RULEITEM>
  306.             <RULEITEM>
  307.                 <NAME>DragQueryFileA</NAME>
  308.             </RULEITEM>
  309.             <RULEITEM>
  310.                 <NAME>DragQueryFileW</NAME>
  311.             </RULEITEM>
  312.             <RULEITEM>
  313.                 <NAME>DragQueryPoint</NAME>
  314.             </RULEITEM>
  315.             <RULEITEM>
  316.                 <NAME>DragFinish</NAME>
  317.             </RULEITEM>
  318.             <RULEITEM>
  319.                 <NAME>DragAcceptFiles</NAME>
  320.             </RULEITEM>
  321.             <RULEITEM>
  322.                 <NAME>SHFileOperationA</NAME>
  323.             </RULEITEM>
  324.             <RULEITEM>
  325.                 <NAME>SHFileOperationW</NAME>
  326.             </RULEITEM>
  327.  
  328.             <RULEITEM>
  329.                 <NAME>SHEmptyRecycleBinW</NAME>
  330.             </RULEITEM>
  331.             <RULEITEM>
  332.                 <NAME>SHEmptyRecycleBinA</NAME>
  333.             </RULEITEM>
  334.             <RULEITEM>
  335.                 <NAME>SHAddToRecentDocs</NAME>
  336.             </RULEITEM>
  337.  
  338.         </RULEITEMS>        
  339.     </RULE>        
  340.     <RULE>
  341.  
  342.         <NAME>Rule_Func_Win32 File I/O - read only functions</NAME>
  343.         <TYPE>8</TYPE>
  344.         <ID>19</ID>
  345.         <RULEITEMS>
  346.             <RULEITEM><NAME>_hread</NAME></RULEITEM>
  347.             <RULEITEM><NAME>_lclose</NAME></RULEITEM>
  348.             <RULEITEM><NAME>_llseek</NAME></RULEITEM>
  349.             <RULEITEM><NAME>_lopen</NAME></RULEITEM>
  350.             <RULEITEM><NAME>_lread</NAME></RULEITEM>
  351.             <RULEITEM><NAME>AreFileApisANSI</NAME></RULEITEM>
  352.             <RULEITEM><NAME>CancelIo</NAME></RULEITEM>
  353.             <RULEITEM><NAME>FindClose</NAME></RULEITEM>
  354.             <RULEITEM><NAME>FindCloseChangeNotification</NAME></RULEITEM>
  355.             <RULEITEM><NAME>FindFirstChangeNotificationA</NAME></RULEITEM>
  356.             <RULEITEM><NAME>FindFirstChangeNotificationW</NAME></RULEITEM>
  357.             <RULEITEM><NAME>FindFirstFileA</NAME></RULEITEM>
  358.             <RULEITEM><NAME>FindFirstFileW</NAME></RULEITEM>
  359.             <RULEITEM><NAME>FindNextFileA</NAME></RULEITEM>
  360.             <RULEITEM><NAME>FindNextFileW</NAME></RULEITEM>
  361.             <RULEITEM><NAME>FlushFileBuffers</NAME></RULEITEM>
  362.             <RULEITEM><NAME>GetCurrentDirectoryA</NAME></RULEITEM>
  363.             <RULEITEM><NAME>GetCurrentDirectoryW</NAME></RULEITEM>
  364.             <RULEITEM><NAME>GetDiskFreeSpaceA</NAME></RULEITEM>
  365.             <RULEITEM><NAME>GetDiskFreeSpaceExA</NAME></RULEITEM>
  366.             <RULEITEM><NAME>GetDiskFreeSpaceExW</NAME></RULEITEM>
  367.             <RULEITEM><NAME>GetDiskFreeSpaceW</NAME></RULEITEM>
  368.             <RULEITEM><NAME>GetDriveTypeA</NAME></RULEITEM>
  369.             <RULEITEM><NAME>GetDriveTypeW</NAME></RULEITEM>
  370.             <RULEITEM><NAME>GetFileAttributesA</NAME></RULEITEM>
  371.             <RULEITEM><NAME>GetFileAttributesExA</NAME></RULEITEM>
  372.             <RULEITEM><NAME>GetFileAttributesExW</NAME></RULEITEM>
  373.             <RULEITEM><NAME>GetFileAttributesW</NAME></RULEITEM>
  374.             <RULEITEM><NAME>GetFileInformationByHandle</NAME></RULEITEM>
  375.             <RULEITEM><NAME>GetFileSize</NAME></RULEITEM>
  376.             <RULEITEM><NAME>GetFileType</NAME></RULEITEM>
  377.             <RULEITEM><NAME>GetFullPathNameA</NAME></RULEITEM>
  378.             <RULEITEM><NAME>GetFullPathNameW</NAME></RULEITEM>
  379.             <RULEITEM><NAME>GetLogicalDrives</NAME></RULEITEM>
  380.             <RULEITEM><NAME>GetLogicalDriveStringsA</NAME></RULEITEM>
  381.             <RULEITEM><NAME>GetLogicalDriveStringsW</NAME></RULEITEM>
  382.             <RULEITEM><NAME>GetLongPathNameA</NAME></RULEITEM>
  383.             <RULEITEM><NAME>GetLongPathNameW</NAME></RULEITEM>
  384.             <RULEITEM><NAME>GetShortPathNameA</NAME></RULEITEM>
  385.             <RULEITEM><NAME>GetShortPathNameW</NAME></RULEITEM>
  386.             <RULEITEM><NAME>GetTempFileNameA</NAME></RULEITEM>
  387.             <RULEITEM><NAME>GetTempFileNameW</NAME></RULEITEM>
  388.             <RULEITEM><NAME>GetTempPathA</NAME></RULEITEM>
  389.             <RULEITEM><NAME>GetTempPathW</NAME></RULEITEM>
  390.             <RULEITEM><NAME>LockFile</NAME></RULEITEM>
  391.             <RULEITEM><NAME>MulDiv</NAME></RULEITEM>
  392.             <RULEITEM>
  393.                 <NAME>OpenFile</NAME>
  394.             </RULEITEM>
  395.             <RULEITEM>
  396.                 <NAME>QueryDosDeviceA</NAME>
  397.             </RULEITEM>
  398.             <RULEITEM>
  399.                 <NAME>QueryDosDeviceW</NAME>
  400.             </RULEITEM>
  401.             <RULEITEM>
  402.                 <NAME>ReadFile</NAME>
  403.             </RULEITEM>
  404.             <RULEITEM>
  405.                 <NAME>ReadFileEx</NAME>
  406.             </RULEITEM>
  407.             
  408.             <RULEITEM>
  409.                 <NAME>SearchPathA</NAME>
  410.             </RULEITEM>
  411.             <RULEITEM>
  412.                 <NAME>SearchPathW</NAME>
  413.             </RULEITEM>
  414.             <RULEITEM>
  415.                 <NAME>SetCurrentDirectoryA</NAME>
  416.             </RULEITEM>
  417.             <RULEITEM>
  418.                 <NAME>SetCurrentDirectoryW</NAME>
  419.             </RULEITEM>
  420.             <RULEITEM>
  421.                 <NAME>SetEndOfFile</NAME>
  422.             </RULEITEM>
  423.             <RULEITEM>
  424.                 <NAME>SetFileApisToANSI</NAME>
  425.             </RULEITEM>
  426.             <RULEITEM>
  427.                 <NAME>SetFileApisToOEM</NAME>
  428.             </RULEITEM>
  429.             
  430.             <RULEITEM>
  431.                 <NAME>SetFilePointer</NAME>
  432.             </RULEITEM>
  433.             <RULEITEM>
  434.                 <NAME>SetHandleCount</NAME>
  435.             </RULEITEM>
  436.             
  437.             <RULEITEM>
  438.                 <NAME>UnlockFile</NAME>
  439.             </RULEITEM>
  440.             
  441.             <RULEITEM>
  442.                 <NAME>PathAddBackslashA</NAME>
  443.             </RULEITEM>
  444.             <RULEITEM>
  445.                 <NAME>PathAddBackslashW</NAME>
  446.             </RULEITEM>
  447.             <RULEITEM>
  448.                 <NAME>PathAddExtensionA</NAME>
  449.             </RULEITEM>
  450.             <RULEITEM>
  451.                 <NAME>PathAddExtensionW</NAME>
  452.             </RULEITEM>
  453.             <RULEITEM>
  454.                 <NAME>PathAppendA</NAME>
  455.             </RULEITEM>
  456.             <RULEITEM>
  457.                 <NAME>PathAppendW</NAME>
  458.             </RULEITEM>
  459.             <RULEITEM>
  460.                 <NAME>PathBuildRootA</NAME>
  461.             </RULEITEM>
  462.             <RULEITEM>
  463.                 <NAME>PathBuildRootW</NAME>
  464.             </RULEITEM>
  465.             <RULEITEM>
  466.                 <NAME>PathCanonicalizeA</NAME>
  467.             </RULEITEM>
  468.             <RULEITEM>
  469.                 <NAME>PathCanonicalizeW</NAME>
  470.             </RULEITEM>
  471.             <RULEITEM>
  472.                 <NAME>PathCombineA</NAME>
  473.             </RULEITEM>
  474.             <RULEITEM>
  475.                 <NAME>PathCombineW</NAME>
  476.             </RULEITEM>
  477.             <RULEITEM>
  478.                 <NAME>PathCompactPathA</NAME>
  479.             </RULEITEM>
  480.             <RULEITEM>
  481.                 <NAME>PathCompactPathW</NAME>
  482.             </RULEITEM>
  483.             <RULEITEM>
  484.                 <NAME>PathCompactPathExA</NAME>
  485.             </RULEITEM>
  486.             <RULEITEM>
  487.                 <NAME>PathCompactPathExW</NAME>
  488.             </RULEITEM>
  489.             <RULEITEM>
  490.                 <NAME>PathCommonPrefixA</NAME>
  491.             </RULEITEM>
  492.             <RULEITEM>
  493.                 <NAME>PathCommonPrefixW</NAME>
  494.             </RULEITEM>
  495.             <RULEITEM>
  496.                 <NAME>PathFileExistsA</NAME>
  497.             </RULEITEM>
  498.             <RULEITEM>
  499.                 <NAME>PathFileExistsW</NAME>
  500.             </RULEITEM>
  501.             <RULEITEM>
  502.                 <NAME>PathFindExtensionA</NAME>
  503.             </RULEITEM>
  504.             <RULEITEM>
  505.                 <NAME>PathFindExtensionW</NAME>
  506.             </RULEITEM>
  507.             <RULEITEM>
  508.                 <NAME>PathFindFileNameA</NAME>
  509.             </RULEITEM>
  510.             <RULEITEM>
  511.                 <NAME>PathFindFileNameW</NAME>
  512.             </RULEITEM>
  513.             <RULEITEM>
  514.                 <NAME>PathFindNextComponentA</NAME>
  515.             </RULEITEM>
  516.             <RULEITEM>
  517.                 <NAME>PathFindNextComponentW</NAME>
  518.             </RULEITEM>
  519.             <RULEITEM>
  520.                 <NAME>PathFindOnPathA</NAME>
  521.             </RULEITEM>
  522.             <RULEITEM>
  523.                 <NAME>PathFindOnPathW</NAME>
  524.             </RULEITEM>
  525.             <RULEITEM>
  526.                 <NAME>PathGetArgsA</NAME>
  527.             </RULEITEM>
  528.             <RULEITEM>
  529.                 <NAME>PathGetArgsW</NAME>
  530.             </RULEITEM>
  531.             <RULEITEM>
  532.                 <NAME>PathGetCharTypeA</NAME>
  533.             </RULEITEM>
  534.             <RULEITEM>
  535.                 <NAME>PathGetCharTypeW</NAME>
  536.             </RULEITEM>
  537.             <RULEITEM>
  538.                 <NAME>PathGetDriveNumberA</NAME>
  539.             </RULEITEM>
  540.             <RULEITEM>
  541.                 <NAME>PathGetDriveNumberW</NAME>
  542.             </RULEITEM>
  543.             <RULEITEM>
  544.                 <NAME>PathIsDirectoryA</NAME>
  545.             </RULEITEM>
  546.             <RULEITEM>
  547.                 <NAME>PathIsDirectoryW</NAME>
  548.             </RULEITEM>
  549.             <RULEITEM>
  550.                 <NAME>PathIsFileSpecA</NAME>
  551.             </RULEITEM>
  552.             <RULEITEM>
  553.                 <NAME>PathIsFileSpecW</NAME>
  554.             </RULEITEM>
  555.             <RULEITEM>
  556.                 <NAME>PathIsPrefixA</NAME>
  557.             </RULEITEM>
  558.             <RULEITEM>
  559.                 <NAME>PathIsPrefixW</NAME>
  560.             </RULEITEM>
  561.             <RULEITEM>
  562.                 <NAME>PathIsRelativeA</NAME>
  563.             </RULEITEM>
  564.             <RULEITEM>
  565.                 <NAME>PathIsRelativeW</NAME>
  566.             </RULEITEM>
  567.             <RULEITEM>
  568.                 <NAME>PathIsRootA</NAME>
  569.             </RULEITEM>
  570.             <RULEITEM>
  571.                 <NAME>PathIsRootW</NAME>
  572.             </RULEITEM>
  573.             <RULEITEM>
  574.                 <NAME>PathIsSameRootA</NAME>
  575.             </RULEITEM>
  576.             <RULEITEM>
  577.                 <NAME>PathIsSameRootW</NAME>
  578.             </RULEITEM>
  579.             <RULEITEM>
  580.                 <NAME>PathIsUNCA</NAME>
  581.             </RULEITEM>
  582.             <RULEITEM>
  583.                 <NAME>PathIsUNCW</NAME>
  584.             </RULEITEM>
  585.             <RULEITEM>
  586.                 <NAME>PathIsUNCServerA</NAME>
  587.             </RULEITEM>
  588.             <RULEITEM>
  589.                 <NAME>PathIsUNCServerW</NAME>
  590.             </RULEITEM>
  591.             <RULEITEM>
  592.                 <NAME>PathIsUNCServerShareA</NAME>
  593.             </RULEITEM>
  594.             <RULEITEM>
  595.                 <NAME>PathIsUNCServerShareW</NAME>
  596.             </RULEITEM>
  597.             <RULEITEM>
  598.                 <NAME>PathIsContentTypeA</NAME>
  599.             </RULEITEM>
  600.             <RULEITEM>
  601.                 <NAME>PathIsContentTypeW</NAME>
  602.             </RULEITEM>
  603.             <RULEITEM>
  604.                 <NAME>PathIsURLA</NAME>
  605.             </RULEITEM>
  606.             <RULEITEM>
  607.                 <NAME>PathIsURLW</NAME>
  608.             </RULEITEM>
  609.             <RULEITEM>
  610.                 <NAME>PathMakePrettyA</NAME>
  611.             </RULEITEM>
  612.             <RULEITEM>
  613.                 <NAME>PathMakePrettyW</NAME>
  614.             </RULEITEM>
  615.             <RULEITEM>
  616.                 <NAME>PathMatchSpecA</NAME>
  617.             </RULEITEM>
  618.             <RULEITEM>
  619.                 <NAME>PathMatchSpecW</NAME>
  620.             </RULEITEM>
  621.             <RULEITEM>
  622.                 <NAME>PathParseIconLocationA</NAME>
  623.             </RULEITEM>
  624.             <RULEITEM>
  625.                 <NAME>PathParseIconLocationW</NAME>
  626.             </RULEITEM>
  627.             <RULEITEM>
  628.                 <NAME>PathQuoteSpacesA</NAME>
  629.             </RULEITEM>
  630.             <RULEITEM>
  631.                 <NAME>PathQuoteSpacesW</NAME>
  632.             </RULEITEM>
  633.             <RULEITEM>
  634.                 <NAME>PathRelativePathToA</NAME>
  635.             </RULEITEM>
  636.             <RULEITEM>
  637.                 <NAME>PathRelativePathToW</NAME>
  638.             </RULEITEM>
  639.             <RULEITEM>
  640.                 <NAME>PathRemoveArgsA</NAME>
  641.             </RULEITEM>
  642.             <RULEITEM>
  643.                 <NAME>PathRemoveArgsW</NAME>
  644.             </RULEITEM>
  645.             <RULEITEM>
  646.                 <NAME>PathRemoveBackslashA</NAME>
  647.             </RULEITEM>
  648.             <RULEITEM>
  649.                 <NAME>PathRemoveBackslashW</NAME>
  650.             </RULEITEM>
  651.             <RULEITEM>
  652.                 <NAME>PathRemoveBlanksA</NAME>
  653.             </RULEITEM>
  654.             <RULEITEM>
  655.                 <NAME>PathRemoveBlanksW</NAME>
  656.             </RULEITEM>
  657.             <RULEITEM>
  658.                 <NAME>PathRemoveExtensionA</NAME>
  659.             </RULEITEM>
  660.             <RULEITEM>
  661.                 <NAME>PathRemoveExtensionW</NAME>
  662.             </RULEITEM>
  663.             <RULEITEM>
  664.                 <NAME>PathRemoveFileSpecA</NAME>
  665.             </RULEITEM>
  666.             <RULEITEM>
  667.                 <NAME>PathRemoveFileSpecW</NAME>
  668.             </RULEITEM>
  669.             <RULEITEM>
  670.                 <NAME>PathRenameExtensionA</NAME>
  671.             </RULEITEM>
  672.             <RULEITEM>
  673.                 <NAME>PathRenameExtensionW</NAME>
  674.             </RULEITEM>
  675.             <RULEITEM>
  676.                 <NAME>PathSearchAndQualifyA</NAME>
  677.             </RULEITEM>
  678.             <RULEITEM>
  679.                 <NAME>PathSearchAndQualifyW</NAME>
  680.             </RULEITEM>
  681.             <RULEITEM>
  682.                 <NAME>PathSetDlgItemPathA</NAME>
  683.             </RULEITEM>
  684.             <RULEITEM>
  685.                 <NAME>PathSetDlgItemPathW</NAME>
  686.             </RULEITEM>
  687.             <RULEITEM>
  688.                 <NAME>PathSkipRootA</NAME>
  689.             </RULEITEM>
  690.             <RULEITEM>
  691.                 <NAME>PathSkipRootW</NAME>
  692.             </RULEITEM>
  693.             <RULEITEM>
  694.                 <NAME>PathStripPathA</NAME>
  695.             </RULEITEM>
  696.             <RULEITEM>
  697.                 <NAME>PathStripPathW</NAME>
  698.             </RULEITEM>
  699.             <RULEITEM>
  700.                 <NAME>PathStripToRootA</NAME>
  701.             </RULEITEM>
  702.             <RULEITEM>
  703.                 <NAME>PathStripToRootW</NAME>
  704.             </RULEITEM>
  705.             <RULEITEM>
  706.                 <NAME>PathUnquoteSpacesA</NAME>
  707.             </RULEITEM>
  708.             <RULEITEM>
  709.                 <NAME>PathUnquoteSpacesW</NAME>
  710.             </RULEITEM>
  711.             <RULEITEM>
  712.                 <NAME>PathMakeSystemFolderA</NAME>
  713.             </RULEITEM>
  714.             <RULEITEM>
  715.                 <NAME>PathMakeSystemFolderW</NAME>
  716.             </RULEITEM>
  717.             <RULEITEM>
  718.                 <NAME>PathUnmakeSystemFolderA</NAME>
  719.             </RULEITEM>
  720.             <RULEITEM>
  721.                 <NAME>PathUnmakeSystemFolderW</NAME>
  722.             </RULEITEM>
  723.             <RULEITEM>
  724.                 <NAME>PathIsSystemFolderA</NAME>
  725.             </RULEITEM>
  726.             <RULEITEM>
  727.                 <NAME>PathIsSystemFolderW</NAME>
  728.             </RULEITEM>
  729.             
  730.             <RULEITEM>
  731.                 <NAME>SHFreeNameMappings</NAME>
  732.             </RULEITEM>
  733.             <RULEITEM>
  734.                 <NAME>SHQueryRecycleBinA</NAME>
  735.             </RULEITEM>
  736.             <RULEITEM>
  737.                 <NAME>SHQueryRecycleBinW</NAME>
  738.             </RULEITEM>
  739.             
  740.             <RULEITEM>
  741.                 <NAME>SHGetFileInfoA</NAME>
  742.             </RULEITEM>
  743.             <RULEITEM>
  744.                 <NAME>SHGetFileInfoW</NAME>
  745.             </RULEITEM>
  746.             <RULEITEM>
  747.                 <NAME>SHGetDiskFreeSpaceA</NAME>
  748.             </RULEITEM>
  749.             <RULEITEM>
  750.                 <NAME>SHGetDiskFreeSpaceW</NAME>
  751.             </RULEITEM>
  752.             <RULEITEM>
  753.                 <NAME>SHGetNewLinkInfoA</NAME>
  754.             </RULEITEM>
  755.             <RULEITEM>
  756.                 <NAME>SHGetNewLinkInfoW</NAME>
  757.             </RULEITEM>
  758.             <RULEITEM>
  759.                 <NAME>SHGetSpecialFolderPathA</NAME>
  760.             </RULEITEM>
  761.             <RULEITEM>
  762.                 <NAME>SHGetSpecialFolderPathW</NAME>
  763.             </RULEITEM>
  764.             <RULEITEM>
  765.                 <NAME>SHGetPathFromIDListW</NAME>
  766.             </RULEITEM>
  767.             <RULEITEM>
  768.                 <NAME>SHGetPathFromIDListA</NAME>
  769.             </RULEITEM>
  770.             <RULEITEM>
  771.                 <NAME>SHGetSpecialFolderLocation</NAME>
  772.             </RULEITEM>
  773.             <RULEITEM>
  774.                 <NAME>SHBrowseForFolderA</NAME>
  775.             </RULEITEM>
  776.             <RULEITEM>
  777.                 <NAME>SHBrowseForFolderW</NAME>
  778.             </RULEITEM>
  779.             <RULEITEM>
  780.                 <NAME>SHGetDesktopFolder</NAME>
  781.             </RULEITEM>
  782.             
  783.             <RULEITEM>
  784.                 <NAME>SHGetDataFromIDListA</NAME>
  785.             </RULEITEM>
  786.             <RULEITEM>
  787.                 <NAME>SHGetDataFromIDListW</NAME>
  788.             </RULEITEM>
  789.         </RULEITEMS>
  790.     </RULE>
  791.     <RULE>
  792.         <NAME>Rule_Func_Win32_Process</NAME>
  793.         <TYPE>8</TYPE>
  794.         <ID>18</ID>
  795.         <RULEITEMS>
  796.             <RULEITEM>
  797.                 <NAME>AssignProcessToJobObject</NAME>
  798.             </RULEITEM>
  799.             <RULEITEM>
  800.                 <NAME>CommandLineToArgvW</NAME>
  801.             </RULEITEM>
  802.             <RULEITEM><NAME>ConvertThreadToFiber</NAME>
  803.             </RULEITEM>
  804.             <RULEITEM><NAME>CreateFiber</NAME>
  805.             </RULEITEM>
  806.             <RULEITEM><NAME>CreateJobObjectA</NAME>
  807.             </RULEITEM>
  808.             <RULEITEM><NAME>CreateJobObjectW</NAME>
  809.             </RULEITEM>
  810.             <RULEITEM><NAME>CreateProcessA</NAME>
  811.             </RULEITEM>
  812.             <RULEITEM><NAME>CreateProcessA</NAME>
  813.             </RULEITEM>
  814.             <RULEITEM><NAME>CreateProcessAsUserA</NAME>
  815.             </RULEITEM>
  816.             <RULEITEM><NAME>CreateProcessAsUserW</NAME>
  817.             </RULEITEM>
  818.             <RULEITEM><NAME>CreateProcessW</NAME>
  819.             </RULEITEM>
  820.             <RULEITEM><NAME>CreateProcessW</NAME>
  821.             </RULEITEM>
  822.             <RULEITEM><NAME>CreateRemoteThread</NAME>
  823.             </RULEITEM>
  824.             <RULEITEM><NAME>CreateThread</NAME>
  825.             </RULEITEM>
  826.             <RULEITEM><NAME>DeleteFiber</NAME>
  827.             </RULEITEM>
  828.             <RULEITEM><NAME>ExitProcess</NAME>
  829.             </RULEITEM>
  830.             <RULEITEM><NAME>ExitThread</NAME>
  831.             </RULEITEM>
  832.             <RULEITEM><NAME>FreeEnvironmentStringsA</NAME>
  833.             </RULEITEM>
  834.             <RULEITEM><NAME>FreeEnvironmentStringsW</NAME>
  835.             </RULEITEM>
  836.             <RULEITEM><NAME>GetCommandLineA</NAME>
  837.             </RULEITEM>
  838.             <RULEITEM><NAME>GetCommandLineW</NAME>
  839.             </RULEITEM>
  840.             <RULEITEM><NAME>GetCurrentProcess</NAME>
  841.             </RULEITEM>
  842.             <RULEITEM><NAME>GetCurrentProcessId</NAME>
  843.             </RULEITEM>
  844.             <RULEITEM><NAME>GetCurrentThread</NAME>
  845.             </RULEITEM>
  846.             <RULEITEM><NAME>GetCurrentThreadId</NAME>
  847.             </RULEITEM>
  848.             <RULEITEM><NAME>GetEnvironmentStringsA</NAME>
  849.             </RULEITEM>
  850.             <RULEITEM><NAME>GetEnvironmentStringsW</NAME>
  851.             </RULEITEM>
  852.             <RULEITEM><NAME>GetEnvironmentVariableA</NAME>
  853.             </RULEITEM>
  854.             <RULEITEM><NAME>GetEnvironmentVariableW</NAME>
  855.             </RULEITEM>
  856.             <RULEITEM><NAME>GetExitCodeProcess</NAME>
  857.             </RULEITEM>
  858.             <RULEITEM><NAME>GetExitCodeThread</NAME>
  859.             </RULEITEM>
  860.             <RULEITEM><NAME>GetGuiResources</NAME>
  861.             </RULEITEM>
  862.             <RULEITEM><NAME>GetPriorityClass</NAME>
  863.             </RULEITEM>
  864.             <RULEITEM><NAME>GetProcessAffinityMask</NAME>
  865.             </RULEITEM>
  866.             <RULEITEM><NAME>GetProcessPriorityBoost</NAME>
  867.             </RULEITEM>
  868.             <RULEITEM><NAME>GetProcessShutdownParameters</NAME>
  869.             </RULEITEM>
  870.             <RULEITEM><NAME>GetProcessTimes</NAME>
  871.             </RULEITEM>
  872.             <RULEITEM><NAME>GetProcessVersion</NAME>
  873.             </RULEITEM>
  874.             <RULEITEM><NAME>GetProcessWorkingSetSize</NAME>
  875.             </RULEITEM>
  876.             <RULEITEM><NAME>GetStartupInfoA</NAME>
  877.             </RULEITEM>
  878.             <RULEITEM>
  879.                 <NAME>GetStartupInfoW</NAME>
  880.             </RULEITEM>
  881.             <RULEITEM>
  882.                 <NAME>GetThreadPriority</NAME>
  883.             </RULEITEM>
  884.             <RULEITEM>
  885.                 <NAME>GetThreadPriorityBoost</NAME>
  886.             </RULEITEM>
  887.             <RULEITEM>
  888.                 <NAME>GetThreadTimes</NAME>
  889.             </RULEITEM>
  890.             <RULEITEM>
  891.                 <NAME>OpenJobObjectA</NAME>
  892.             </RULEITEM>
  893.             <RULEITEM>
  894.                 <NAME>OpenJobObjectW</NAME>
  895.             </RULEITEM>
  896.             <RULEITEM>
  897.                 <NAME>OpenProcess</NAME>
  898.             </RULEITEM>
  899.             <RULEITEM>
  900.                 <NAME>QueryInformationJobObject</NAME>
  901.             </RULEITEM>
  902.             <RULEITEM>
  903.                 <NAME>ResumeThread</NAME>
  904.             </RULEITEM>
  905.             <RULEITEM>
  906.                 <NAME>SetEnvironmentVariableA</NAME>
  907.             </RULEITEM>
  908.             <RULEITEM>
  909.                 <NAME>SetEnvironmentVariableW</NAME>
  910.             </RULEITEM>
  911.             <RULEITEM>
  912.                 <NAME>SetInformationJobObject</NAME>
  913.             </RULEITEM>
  914.             <RULEITEM>
  915.                 <NAME>SetPriorityClass</NAME>
  916.             </RULEITEM>
  917.             <RULEITEM>
  918.                 <NAME>SetProcessAffinityMask</NAME>
  919.             </RULEITEM>
  920.             <RULEITEM>
  921.                 <NAME>SetProcessPriorityBoost</NAME>
  922.             </RULEITEM>
  923.             <RULEITEM>
  924.                 <NAME>SetProcessShutdownParameters</NAME>
  925.             </RULEITEM>
  926.             <RULEITEM>
  927.                 <NAME>SetProcessWorkingSetSize</NAME>
  928.             </RULEITEM>
  929.             <RULEITEM>
  930.                 <NAME>SetThreadAffinityMask</NAME>
  931.             </RULEITEM>
  932.             <RULEITEM>
  933.                 <NAME>SetThreadIdealProcessor</NAME>
  934.             </RULEITEM>
  935.             <RULEITEM>
  936.                 <NAME>SetThreadPriority</NAME>
  937.             </RULEITEM>
  938.             <RULEITEM>
  939.                 <NAME>SetThreadPriorityBoost</NAME>
  940.             </RULEITEM>
  941.             <RULEITEM>
  942.                 <NAME>Sleep</NAME>
  943.             </RULEITEM>
  944.             <RULEITEM>
  945.                 <NAME>SleepEx</NAME>
  946.             </RULEITEM>
  947.             <RULEITEM>
  948.                 <NAME>SuspendThread</NAME>
  949.             </RULEITEM>
  950.             <RULEITEM>
  951.                 <NAME>SwitchToFiber</NAME>
  952.             </RULEITEM>
  953.             <RULEITEM>
  954.                 <NAME>SwitchToThread</NAME>
  955.             </RULEITEM>
  956.             <RULEITEM>
  957.                 <NAME>TerminateJobObject</NAME>
  958.             </RULEITEM>
  959.             <RULEITEM>
  960.                 <NAME>TerminateProcess</NAME>
  961.             </RULEITEM>
  962.             <RULEITEM>
  963.                 <NAME>TerminateThread</NAME>
  964.             </RULEITEM>
  965.             <RULEITEM>
  966.                 <NAME>WaitForInputIdle</NAME>
  967.             </RULEITEM>
  968.             <RULEITEM>
  969.                 <NAME>WinExec</NAME>
  970.             </RULEITEM>
  971.             <RULEITEM>
  972.                 <NAME>ShellExecuteA</NAME>
  973.             </RULEITEM>
  974.             <RULEITEM>
  975.                 <NAME>ShellExecuteW</NAME>
  976.             </RULEITEM>
  977.             <RULEITEM>
  978.                 <NAME>FindExecutableA</NAME>
  979.             </RULEITEM>
  980.             <RULEITEM>
  981.                 <NAME>FindExecutableW</NAME>
  982.             </RULEITEM>
  983.             <RULEITEM>
  984.                 <NAME>CommandLineToArgvW</NAME>
  985.             </RULEITEM>
  986.             <RULEITEM>
  987.                 <NAME>DoEnvironmentSubstA</NAME>
  988.             </RULEITEM>
  989.             <RULEITEM>
  990.                 <NAME>DoEnvironmentSubstW</NAME>
  991.             </RULEITEM>
  992.             <RULEITEM>
  993.                 <NAME>FindEnvironmentStringA</NAME>
  994.             </RULEITEM>
  995.             <RULEITEM>
  996.                 <NAME>FindEnvironmentStringW</NAME>
  997.             </RULEITEM>
  998.             <RULEITEM>
  999.                 <NAME>ShellExecuteExA</NAME>
  1000.             </RULEITEM>
  1001.             <RULEITEM>
  1002.                 <NAME>ShellExecuteExW</NAME>
  1003.             </RULEITEM>
  1004.             <RULEITEM>
  1005.                 <NAME>WinExecErrorW</NAME>
  1006.             </RULEITEM>
  1007.             <RULEITEM>
  1008.                 <NAME>WinExecErrorA</NAME>
  1009.             </RULEITEM>
  1010.         </RULEITEMS>
  1011.     </RULE>
  1012.     <RULE>
  1013.         <NAME>Rule_func_Win32 Dynamic-Link Libraries</NAME>
  1014.         <TYPE>8</TYPE>
  1015.         <ID>20</ID>
  1016.         <RULEITEMS>
  1017.             <RULEITEM>
  1018.                 <NAME>GetModuleFileNameA</NAME>
  1019.             </RULEITEM>
  1020.             <RULEITEM>
  1021.                 <NAME>GetModuleFileNameW</NAME>
  1022.             </RULEITEM>
  1023.             <RULEITEM>
  1024.                 <NAME>GetProcAddress</NAME>
  1025.             </RULEITEM>
  1026.             <RULEITEM>
  1027.                 <NAME>LoadLibraryA</NAME>
  1028.             </RULEITEM>
  1029.             <RULEITEM>
  1030.                 <NAME>LoadLibraryExA</NAME>
  1031.             </RULEITEM>
  1032.             <RULEITEM>
  1033.                 <NAME>LoadLibraryExW</NAME>
  1034.             </RULEITEM>
  1035.             <RULEITEM>
  1036.                 <NAME>LoadLibraryW</NAME>
  1037.             </RULEITEM>
  1038.             <RULEITEM>
  1039.                 <NAME>LoadModule</NAME>
  1040.             </RULEITEM>
  1041.             <RULEITEM>
  1042.                 <NAME>GetModuleHandleA</NAME>
  1043.             </RULEITEM>
  1044.             <RULEITEM>
  1045.                 <NAME>GetModuleHandleW</NAME>
  1046.             </RULEITEM>
  1047.         </RULEITEMS>
  1048.     </RULE>
  1049.     <RULE>
  1050.         <NAME>Rule_func Win32 Registry - moodify functions</NAME>
  1051.         <TYPE>8</TYPE>
  1052.         <ID>-21</ID>
  1053.         <RULEITEMS>
  1054.             <RULEITEM>
  1055.                 <NAME>RegCreateKeyA</NAME>
  1056.             </RULEITEM>
  1057.             <RULEITEM>
  1058.                 <NAME>RegCreateKeyExA</NAME>
  1059.             </RULEITEM>
  1060.             <RULEITEM>
  1061.                 <NAME>RegCreateKeyExW</NAME>
  1062.             </RULEITEM>
  1063.             <RULEITEM>
  1064.                 <NAME>RegCreateKeyW</NAME>
  1065.             </RULEITEM>
  1066.             <RULEITEM>
  1067.                 <NAME>RegDeleteKeyA</NAME>
  1068.             </RULEITEM>
  1069.             <RULEITEM>
  1070.                 <NAME>RegDeleteKeyW</NAME>
  1071.             </RULEITEM>
  1072.             <RULEITEM>
  1073.                 <NAME>RegDeleteValueA</NAME>
  1074.             </RULEITEM>
  1075.             <RULEITEM>
  1076.                 <NAME>RegDeleteValueW</NAME>
  1077.             </RULEITEM>
  1078.             <RULEITEM>
  1079.                 <NAME>RegReplaceKeyA</NAME>
  1080.             </RULEITEM>
  1081.             <RULEITEM>
  1082.                 <NAME>RegReplaceKeyW</NAME>
  1083.             </RULEITEM>
  1084.             <RULEITEM>
  1085.                 <NAME>RegRestoreKeyA</NAME>
  1086.             </RULEITEM>
  1087.             <RULEITEM>
  1088.                 <NAME>RegRestoreKeyW</NAME>
  1089.             </RULEITEM>
  1090.             <RULEITEM>
  1091.                 <NAME>RegSaveKeyA</NAME>
  1092.             </RULEITEM>
  1093.             <RULEITEM>
  1094.                 <NAME>RegSaveKeyW</NAME>
  1095.             </RULEITEM>
  1096.             <RULEITEM>
  1097.                 <NAME>RegSetKeySecurity</NAME>
  1098.             </RULEITEM>
  1099.             <RULEITEM>
  1100.                 <NAME>RegSetValueA</NAME>
  1101.             </RULEITEM>
  1102.             <RULEITEM>
  1103.                 <NAME>RegSetValueExA</NAME>
  1104.             </RULEITEM>
  1105.             <RULEITEM>
  1106.                 <NAME>RegSetValueExW</NAME>
  1107.             </RULEITEM>
  1108.             <RULEITEM>
  1109.                 <NAME>RegSetValueW</NAME>
  1110.             </RULEITEM>
  1111.  
  1112.             <RULEITEM>
  1113.                 <NAME>SHSetValueW</NAME>
  1114.             </RULEITEM>
  1115.  
  1116.             <RULEITEM>
  1117.                 <NAME>WritePrivateProfileSectionA</NAME>
  1118.             </RULEITEM>
  1119.             <RULEITEM>
  1120.                 <NAME>WritePrivateProfileSectionW</NAME>
  1121.             </RULEITEM>
  1122.             <RULEITEM>
  1123.                 <NAME>WritePrivateProfileStringA</NAME>
  1124.             </RULEITEM>
  1125.             <RULEITEM>
  1126.                 <NAME>WritePrivateProfileStringW</NAME>
  1127.             </RULEITEM>
  1128.             <RULEITEM>
  1129.                 <NAME>WritePrivateProfileStructA</NAME>
  1130.             </RULEITEM>
  1131.             <RULEITEM>
  1132.                 <NAME>WritePrivateProfileStructW</NAME>
  1133.             </RULEITEM>
  1134.             <RULEITEM>
  1135.                 <NAME>WriteProfileSectionA</NAME>
  1136.             </RULEITEM>
  1137.             <RULEITEM>
  1138.                 <NAME>WriteProfileSectionW</NAME>
  1139.             </RULEITEM>
  1140.             <RULEITEM>
  1141.                 <NAME>WriteProfileStringA</NAME>
  1142.             </RULEITEM>
  1143.             <RULEITEM>
  1144.                 <NAME>WriteProfileStringW</NAME>
  1145.             </RULEITEM>
  1146.             <RULEITEM>
  1147.                 <NAME>SHDeleteEmptyKeyW</NAME>
  1148.             </RULEITEM>
  1149.             <RULEITEM>
  1150.                 <NAME>SHDeleteKeyW</NAME>
  1151.             </RULEITEM>
  1152.             <RULEITEM>
  1153.                 <NAME>SHDeleteValueW</NAME>
  1154.             </RULEITEM>
  1155.             <RULEITEM>
  1156.                 <NAME>SHDeleteEmptyKeyA</NAME>
  1157.             </RULEITEM>
  1158.             <RULEITEM>
  1159.                 <NAME>SHDeleteKeyA</NAME>
  1160.             </RULEITEM>
  1161.             <RULEITEM>
  1162.                 <NAME>SHDeleteValueA</NAME>
  1163.             </RULEITEM>
  1164.  
  1165.             <RULEITEM>
  1166.                 <NAME>SHSetValueA</NAME>
  1167.             </RULEITEM>
  1168.             <RULEITEM>
  1169.                 <NAME>SHRegCreateUSKeyW</NAME>
  1170.             </RULEITEM>
  1171.             <RULEITEM>
  1172.                 <NAME>SHRegWriteUSValueW</NAME>
  1173.             </RULEITEM>
  1174.             <RULEITEM>
  1175.                 <NAME>SHRegDeleteUSValueW</NAME>
  1176.             </RULEITEM>
  1177.             <RULEITEM>
  1178.                 <NAME>SHRegDeleteEmptyUSKeyW</NAME>
  1179.             </RULEITEM>
  1180.             <RULEITEM>
  1181.                 <NAME>SHRegSetUSValueW</NAME>
  1182.             </RULEITEM>
  1183.             <RULEITEM>
  1184.                 <NAME>SHRegCreateUSKeyA</NAME>
  1185.             </RULEITEM>
  1186.             <RULEITEM>
  1187.                 <NAME>SHRegDeleteUSValueA</NAME>
  1188.             </RULEITEM>
  1189.             <RULEITEM>
  1190.                 <NAME>SHRegDeleteEmptyUSKeyA</NAME>
  1191.             </RULEITEM>
  1192.             <RULEITEM>
  1193.                 <NAME>SHRegSetUSValueA</NAME>
  1194.             </RULEITEM>
  1195.             <RULEITEM>
  1196.                 <NAME>SHRegWriteUSValueA</NAME>
  1197.             </RULEITEM>
  1198.             <RULEITEM>
  1199.                 <NAME>RegFlushKey</NAME>
  1200.             </RULEITEM>
  1201.         </RULEITEMS>
  1202.     </RULE>
  1203.     <RULE>
  1204.         <NAME>Rule_func Win32 Registry - read only functions</NAME>
  1205.         <TYPE>8</TYPE>
  1206.         <ID>21</ID>
  1207.         <RULEITEMS>
  1208.             <RULEITEM>
  1209.                 <NAME>GetPrivateProfileIntA</NAME>
  1210.             </RULEITEM>
  1211.             <RULEITEM>
  1212.                 <NAME>GetPrivateProfileIntW</NAME>
  1213.             </RULEITEM>
  1214.             <RULEITEM>
  1215.                 <NAME>GetPrivateProfileSectionA</NAME>
  1216.             </RULEITEM>
  1217.             <RULEITEM>
  1218.                 <NAME>GetPrivateProfileSectionNamesA</NAME>
  1219.             </RULEITEM>
  1220.             <RULEITEM>
  1221.                 <NAME>GetPrivateProfileSectionNamesW</NAME>
  1222.             </RULEITEM>
  1223.             <RULEITEM>
  1224.                 <NAME>GetPrivateProfileSectionW</NAME>
  1225.             </RULEITEM>
  1226.             <RULEITEM>
  1227.                 <NAME>GetPrivateProfileStringA</NAME>
  1228.             </RULEITEM>
  1229.             <RULEITEM>
  1230.                 <NAME>GetPrivateProfileStringW</NAME>
  1231.             </RULEITEM>
  1232.             <RULEITEM>
  1233.                 <NAME>GetPrivateProfileStructA</NAME>
  1234.             </RULEITEM>
  1235.             <RULEITEM>
  1236.                 <NAME>GetPrivateProfileStructW</NAME>
  1237.             </RULEITEM>
  1238.             <RULEITEM>
  1239.                 <NAME>GetProfileIntA</NAME>
  1240.             </RULEITEM>
  1241.             <RULEITEM>
  1242.                 <NAME>GetProfileIntW</NAME>
  1243.             </RULEITEM>
  1244.             <RULEITEM>
  1245.                 <NAME>GetProfileSectionA</NAME>
  1246.             </RULEITEM>
  1247.             <RULEITEM>
  1248.                 <NAME>GetProfileSectionW</NAME>
  1249.             </RULEITEM>
  1250.             <RULEITEM>
  1251.                 <NAME>GetProfileStringA</NAME>
  1252.             </RULEITEM>
  1253.             <RULEITEM>
  1254.                 <NAME>GetProfileStringW</NAME>
  1255.             </RULEITEM>
  1256.             <RULEITEM>
  1257.                 <NAME>RegCloseKey</NAME>
  1258.             </RULEITEM>
  1259.             <RULEITEM>
  1260.                 <NAME>RegConnectRegistryA</NAME>
  1261.             </RULEITEM>
  1262.             <RULEITEM>
  1263.                 <NAME>RegConnectRegistryW</NAME>
  1264.             </RULEITEM>
  1265.             
  1266.             <RULEITEM>
  1267.                 <NAME>RegEnumKeyA</NAME>
  1268.             </RULEITEM>
  1269.             <RULEITEM>
  1270.                 <NAME>RegEnumKeyExA</NAME>
  1271.             </RULEITEM>
  1272.             <RULEITEM>
  1273.                 <NAME>RegEnumKeyExW</NAME>
  1274.             </RULEITEM>
  1275.             <RULEITEM>
  1276.                 <NAME>RegEnumKeyW</NAME>
  1277.             </RULEITEM>
  1278.             <RULEITEM>
  1279.                 <NAME>RegEnumValueA</NAME>
  1280.             </RULEITEM>
  1281.             <RULEITEM>
  1282.                 <NAME>RegEnumValueW</NAME>
  1283.             </RULEITEM>
  1284.             
  1285.             <RULEITEM>
  1286.                 <NAME>RegGetKeySecurity</NAME>
  1287.             </RULEITEM>
  1288.             <RULEITEM>
  1289.                 <NAME>RegLoadKeyA</NAME>
  1290.             </RULEITEM>
  1291.             <RULEITEM>
  1292.                 <NAME>RegLoadKeyW</NAME>
  1293.             </RULEITEM>
  1294.             <RULEITEM>
  1295.                 <NAME>RegNotifyChangeKeyValue</NAME>
  1296.             </RULEITEM>
  1297.             <RULEITEM>
  1298.                 <NAME>RegOpenKeyA</NAME>
  1299.             </RULEITEM>
  1300.             <RULEITEM>
  1301.                 <NAME>RegOpenKeyExA</NAME>
  1302.             </RULEITEM>
  1303.             <RULEITEM>
  1304.                 <NAME>RegOpenKeyExW</NAME>
  1305.             </RULEITEM>
  1306.             <RULEITEM>
  1307.                 <NAME>RegOpenKeyW</NAME>
  1308.             </RULEITEM>
  1309.             <RULEITEM>
  1310.                 <NAME>RegOverridePredefKey</NAME>
  1311.             </RULEITEM>
  1312.             <RULEITEM>
  1313.                 <NAME>RegQueryInfoKeyA</NAME>
  1314.             </RULEITEM>
  1315.             <RULEITEM>
  1316.                 <NAME>RegQueryInfoKeyW</NAME>
  1317.             </RULEITEM>
  1318.             <RULEITEM>
  1319.                 <NAME>RegQueryMultipleValuesA</NAME>
  1320.             </RULEITEM>
  1321.             <RULEITEM>
  1322.                 <NAME>RegQueryMultipleValuesW</NAME>
  1323.             </RULEITEM>
  1324.             <RULEITEM>
  1325.                 <NAME>RegQueryValueA</NAME>
  1326.             </RULEITEM>
  1327.             <RULEITEM>
  1328.                 <NAME>RegQueryValueExA</NAME>
  1329.             </RULEITEM>
  1330.             <RULEITEM>
  1331.                 <NAME>RegQueryValueExW</NAME>
  1332.             </RULEITEM>
  1333.             <RULEITEM>
  1334.                 <NAME>RegQueryValueW</NAME>
  1335.             </RULEITEM>
  1336.             
  1337.             <RULEITEM>
  1338.                 <NAME>RegUnLoadKeyA</NAME>
  1339.             </RULEITEM>
  1340.             <RULEITEM>
  1341.                 <NAME>RegUnLoadKeyW</NAME>
  1342.             </RULEITEM>
  1343.             
  1344.             <RULEITEM>
  1345.                 <NAME>SHGetValueW</NAME>
  1346.             </RULEITEM>
  1347.             
  1348.             <RULEITEM>
  1349.                 <NAME>SHQueryValueExW</NAME>
  1350.             </RULEITEM>
  1351.             <RULEITEM>
  1352.                 <NAME>SHEnumKeyExW</NAME>
  1353.             </RULEITEM>
  1354.             <RULEITEM>
  1355.                 <NAME>SHEnumValueW</NAME>
  1356.             </RULEITEM>
  1357.             <RULEITEM>
  1358.                 <NAME>SHQueryInfoKeyW</NAME>
  1359.             </RULEITEM>
  1360.             
  1361.             <RULEITEM>
  1362.                 <NAME>SHGetValueA</NAME>
  1363.             </RULEITEM>
  1364.             
  1365.             <RULEITEM>
  1366.                 <NAME>SHQueryValueExA</NAME>
  1367.             </RULEITEM>
  1368.             <RULEITEM>
  1369.                 <NAME>SHEnumKeyExA</NAME>
  1370.             </RULEITEM>
  1371.             <RULEITEM>
  1372.                 <NAME>SHEnumValueA</NAME>
  1373.             </RULEITEM>
  1374.             <RULEITEM>
  1375.                 <NAME>SHQueryInfoKeyA</NAME>
  1376.             </RULEITEM>
  1377.             <RULEITEM>
  1378.                 <NAME>SHRegOpenUSKeyW</NAME>
  1379.             </RULEITEM>
  1380.             <RULEITEM>
  1381.                 <NAME>SHRegQueryUSValueW</NAME>
  1382.             </RULEITEM>
  1383.             
  1384.             <RULEITEM>
  1385.                 <NAME>SHRegEnumUSKeyW</NAME>
  1386.             </RULEITEM>
  1387.             <RULEITEM>
  1388.                 <NAME>SHRegEnumUSValueW</NAME>
  1389.             </RULEITEM>
  1390.             <RULEITEM>
  1391.                 <NAME>SHRegQueryInfoUSKeyW</NAME>
  1392.             </RULEITEM>
  1393.             <RULEITEM>
  1394.                 <NAME>SHRegGetUSValueW</NAME>
  1395.             </RULEITEM>
  1396.             
  1397.             <RULEITEM>
  1398.                 <NAME>SHRegOpenUSKeyA</NAME>
  1399.             </RULEITEM>
  1400.             <RULEITEM>
  1401.                 <NAME>SHRegQueryUSValueA</NAME>
  1402.             </RULEITEM>
  1403.             
  1404.             
  1405.             <RULEITEM>
  1406.                 <NAME>SHRegEnumUSKeyA</NAME>
  1407.             </RULEITEM>
  1408.             <RULEITEM>
  1409.                 <NAME>SHRegEnumUSValueA</NAME>
  1410.             </RULEITEM>
  1411.             <RULEITEM>
  1412.                 <NAME>SHRegQueryInfoUSKeyA</NAME>
  1413.             </RULEITEM>
  1414.             <RULEITEM>
  1415.                 <NAME>SHRegGetUSValueA</NAME>
  1416.             </RULEITEM>
  1417.             <RULEITEM>
  1418.                 <NAME>SHRegGetBoolUSValueA</NAME>
  1419.             </RULEITEM>
  1420.             <RULEITEM>
  1421.                 <NAME>SHRegGetBoolUSValueW</NAME>
  1422.             </RULEITEM>
  1423.             <RULEITEM>
  1424.                 <NAME>SHOpenRegStreamA</NAME>
  1425.             </RULEITEM>
  1426.             <RULEITEM>
  1427.                 <NAME>SHOpenRegStreamW</NAME>
  1428.             </RULEITEM>
  1429.         </RULEITEMS>
  1430.     </RULE>
  1431.     <RULE>
  1432.         <NAME>Rule_func Win32 Windows NT Security</NAME>
  1433.         <TYPE>8</TYPE>
  1434.         <ID>22</ID>
  1435.         <RULEITEMS>
  1436.             <RULEITEM>
  1437.                 <NAME>AccessCheck</NAME>
  1438.             </RULEITEM>
  1439.             <RULEITEM>
  1440.                 <NAME>AccessCheckAndAuditAlarmA</NAME>
  1441.             </RULEITEM>
  1442.             <RULEITEM>
  1443.                 <NAME>AccessCheckAndAuditAlarmW</NAME>
  1444.             </RULEITEM>
  1445.             <RULEITEM>
  1446.                 <NAME>AccessCheckByType</NAME>
  1447.             </RULEITEM>
  1448.             <RULEITEM>
  1449.                 <NAME>AccessCheckByTypeAndAuditAlarmA</NAME>
  1450.             </RULEITEM>
  1451.             <RULEITEM>
  1452.                 <NAME>AccessCheckByTypeAndAuditAlarmW</NAME>
  1453.             </RULEITEM>
  1454.             <RULEITEM>
  1455.                 <NAME>AccessCheckByTypeResultList</NAME>
  1456.             </RULEITEM>
  1457.             <RULEITEM>
  1458.                 <NAME>AccessCheckByTypeResultListAndAuditAlarmA</NAME>
  1459.             </RULEITEM>
  1460.             <RULEITEM>
  1461.                 <NAME>AccessCheckByTypeResultListAndAuditAlarmW</NAME>
  1462.             </RULEITEM>
  1463.             <RULEITEM>
  1464.                 <NAME>AddAccessAllowedAce</NAME>
  1465.             </RULEITEM>
  1466.             <RULEITEM>
  1467.                 <NAME>AddAccessAllowedAceEx</NAME>
  1468.             </RULEITEM>
  1469.             <RULEITEM>
  1470.                 <NAME>AddAccessAllowedObjectAce</NAME>
  1471.             </RULEITEM>
  1472.             <RULEITEM>
  1473.                 <NAME>AddAccessDeniedAce</NAME>
  1474.             </RULEITEM>
  1475.             <RULEITEM>
  1476.                 <NAME>AddAccessDeniedAceEx</NAME>
  1477.             </RULEITEM>
  1478.             <RULEITEM>
  1479.                 <NAME>AddAccessDeniedObjectAce</NAME>
  1480.             </RULEITEM>
  1481.             <RULEITEM>
  1482.                 <NAME>AddAce</NAME>
  1483.             </RULEITEM>
  1484.             <RULEITEM>
  1485.                 <NAME>AddAuditAccessAce</NAME>
  1486.             </RULEITEM>
  1487.             <RULEITEM>
  1488.                 <NAME>AddAuditAccessAceEx</NAME>
  1489.             </RULEITEM>
  1490.             <RULEITEM>
  1491.                 <NAME>AddAuditAccessObjectAce</NAME>
  1492.             </RULEITEM>
  1493.             <RULEITEM>
  1494.                 <NAME>AdjustTokenGroups</NAME>
  1495.             </RULEITEM>
  1496.             <RULEITEM>
  1497.                 <NAME>AdjustTokenPrivileges</NAME>
  1498.             </RULEITEM>
  1499.             <RULEITEM>
  1500.                 <NAME>AllocateAndInitializeSid</NAME>
  1501.             </RULEITEM>
  1502.             <RULEITEM>
  1503.                 <NAME>AllocateLocallyUniqueId</NAME>
  1504.             </RULEITEM>
  1505.             <RULEITEM>
  1506.                 <NAME>AreAllAccessesGranted</NAME>
  1507.             </RULEITEM>
  1508.             <RULEITEM>
  1509.                 <NAME>AreAnyAccessesGranted</NAME>
  1510.             </RULEITEM>
  1511.             <RULEITEM>
  1512.                 <NAME>BuildExplicitAccessWithNameA</NAME>
  1513.             </RULEITEM>
  1514.             <RULEITEM>
  1515.                 <NAME>BuildExplicitAccessWithNameW</NAME>
  1516.             </RULEITEM>
  1517.             <RULEITEM>
  1518.                 <NAME>BuildImpersonateExplicitAccessWithNameA</NAME>
  1519.             </RULEITEM>
  1520.             <RULEITEM>
  1521.                 <NAME>BuildImpersonateExplicitAccessWithNameW</NAME>
  1522.             </RULEITEM>
  1523.             <RULEITEM>
  1524.                 <NAME>BuildImpersonateTrusteeA</NAME>
  1525.             </RULEITEM>
  1526.             <RULEITEM>
  1527.                 <NAME>BuildImpersonateTrusteeW</NAME>
  1528.             </RULEITEM>
  1529.             <RULEITEM>
  1530.                 <NAME>BuildSecurityDescriptorA</NAME>
  1531.             </RULEITEM>
  1532.             <RULEITEM>
  1533.                 <NAME>BuildSecurityDescriptorW</NAME>
  1534.             </RULEITEM>
  1535.             <RULEITEM>
  1536.                 <NAME>BuildTrusteeWithNameA</NAME>
  1537.             </RULEITEM>
  1538.             <RULEITEM>
  1539.                 <NAME>BuildTrusteeWithNameW</NAME>
  1540.             </RULEITEM>
  1541.             <RULEITEM>
  1542.                 <NAME>BuildTrusteeWithSidA</NAME>
  1543.             </RULEITEM>
  1544.             <RULEITEM>
  1545.                 <NAME>BuildTrusteeWithSidW</NAME>
  1546.             </RULEITEM>
  1547.             <RULEITEM>
  1548.                 <NAME>ConvertToAutoInheritPrivateObjectSecurity</NAME>
  1549.             </RULEITEM>
  1550.             <RULEITEM>
  1551.                 <NAME>CopySid</NAME>
  1552.             </RULEITEM>
  1553.             <RULEITEM>
  1554.                 <NAME>CreatePrivateObjectSecurity</NAME>
  1555.             </RULEITEM>
  1556.             <RULEITEM>
  1557.                 <NAME>CreatePrivateObjectSecurityEx</NAME>
  1558.             </RULEITEM>
  1559.             <RULEITEM>
  1560.                 <NAME>CreateRestrictedToken</NAME>
  1561.             </RULEITEM>
  1562.             <RULEITEM>
  1563.                 <NAME>DeleteAce</NAME>
  1564.             </RULEITEM>
  1565.             <RULEITEM>
  1566.                 <NAME>DestroyPrivateObjectSecurity</NAME>
  1567.             </RULEITEM>
  1568.             <RULEITEM>
  1569.                 <NAME>DuplicateToken</NAME>
  1570.             </RULEITEM>
  1571.             <RULEITEM>
  1572.                 <NAME>DuplicateTokenEx</NAME>
  1573.             </RULEITEM>
  1574.             <RULEITEM>
  1575.                 <NAME>EqualPrefixSid</NAME>
  1576.             </RULEITEM>
  1577.             <RULEITEM>
  1578.                 <NAME>EqualSid</NAME>
  1579.             </RULEITEM>
  1580.             <RULEITEM>
  1581.                 <NAME>FindFirstFreeAce</NAME>
  1582.             </RULEITEM>
  1583.             <RULEITEM>
  1584.                 <NAME>FreeSid</NAME>
  1585.             </RULEITEM>
  1586.             <RULEITEM>
  1587.                 <NAME>GetAce</NAME>
  1588.             </RULEITEM>
  1589.             <RULEITEM>
  1590.                 <NAME>GetAclInformation</NAME>
  1591.             </RULEITEM>
  1592.             <RULEITEM>
  1593.                 <NAME>GetAuditedPermissionsFromAclA</NAME>
  1594.             </RULEITEM>
  1595.             <RULEITEM>
  1596.                 <NAME>GetAuditedPermissionsFromAclW</NAME>
  1597.             </RULEITEM>
  1598.             <RULEITEM>
  1599.                 <NAME>GetEffectiveRightsFromAclA</NAME>
  1600.             </RULEITEM>
  1601.             <RULEITEM>
  1602.                 <NAME>GetEffectiveRightsFromAclW</NAME>
  1603.             </RULEITEM>
  1604.             <RULEITEM>
  1605.                 <NAME>GetExplicitEntriesFromAclA</NAME>
  1606.             </RULEITEM>
  1607.             <RULEITEM>
  1608.                 <NAME>GetExplicitEntriesFromAclW</NAME>
  1609.             </RULEITEM>
  1610.             <RULEITEM>
  1611.                 <NAME>GetFileSecurityA</NAME>
  1612.             </RULEITEM>
  1613.             <RULEITEM>
  1614.                 <NAME>GetFileSecurityW</NAME>
  1615.             </RULEITEM>
  1616.             <RULEITEM>
  1617.                 <NAME>GetKernelObjectSecurity</NAME>
  1618.             </RULEITEM>
  1619.             <RULEITEM>
  1620.                 <NAME>GetLengthSid</NAME>
  1621.             </RULEITEM>
  1622.             <RULEITEM>
  1623.                 <NAME>GetMultipleTrusteeA</NAME>
  1624.             </RULEITEM>
  1625.             <RULEITEM>
  1626.                 <NAME>GetMultipleTrusteeOperationA</NAME>
  1627.             </RULEITEM>
  1628.             <RULEITEM>
  1629.                 <NAME>GetMultipleTrusteeOperationW</NAME>
  1630.             </RULEITEM>
  1631.             <RULEITEM>
  1632.                 <NAME>GetMultipleTrusteeW</NAME>
  1633.             </RULEITEM>
  1634.             <RULEITEM>
  1635.                 <NAME>GetNamedSecurityInfoA</NAME>
  1636.             </RULEITEM>
  1637.             <RULEITEM>
  1638.                 <NAME>GetNamedSecurityInfoW</NAME>
  1639.             </RULEITEM>
  1640.             <RULEITEM>
  1641.                 <NAME>GetPrivateObjectSecurity</NAME>
  1642.             </RULEITEM>
  1643.             <RULEITEM>
  1644.                 <NAME>GetSecurityDescriptorControl</NAME>
  1645.             </RULEITEM>
  1646.             <RULEITEM>
  1647.                 <NAME>GetSecurityDescriptorDacl</NAME>
  1648.             </RULEITEM>
  1649.             <RULEITEM>
  1650.                 <NAME>GetSecurityDescriptorGroup</NAME>
  1651.             </RULEITEM>
  1652.             <RULEITEM>
  1653.                 <NAME>GetSecurityDescriptorLength</NAME>
  1654.             </RULEITEM>
  1655.             <RULEITEM>
  1656.                 <NAME>GetSecurityDescriptorOwner</NAME>
  1657.             </RULEITEM>
  1658.             <RULEITEM>
  1659.                 <NAME>GetSecurityDescriptorSacl</NAME>
  1660.             </RULEITEM>
  1661.             <RULEITEM>
  1662.                 <NAME>GetSecurityInfo</NAME>
  1663.             </RULEITEM>
  1664.             <RULEITEM>
  1665.                 <NAME>GetSidIdentifierAuthority</NAME>
  1666.             </RULEITEM>
  1667.             <RULEITEM>
  1668.                 <NAME>GetSidLengthRequired</NAME>
  1669.             </RULEITEM>
  1670.             <RULEITEM>
  1671.                 <NAME>GetSidSubAuthority</NAME>
  1672.             </RULEITEM>
  1673.             <RULEITEM>
  1674.                 <NAME>GetSidSubAuthorityCount</NAME>
  1675.             </RULEITEM>
  1676.             <RULEITEM>
  1677.                 <NAME>GetTokenInformation</NAME>
  1678.             </RULEITEM>
  1679.             <RULEITEM>
  1680.                 <NAME>GetTrusteeFormA</NAME>
  1681.             </RULEITEM>
  1682.             <RULEITEM>
  1683.                 <NAME>GetTrusteeFormW</NAME>
  1684.             </RULEITEM>
  1685.             <RULEITEM>
  1686.                 <NAME>GetTrusteeNameA</NAME>
  1687.             </RULEITEM>
  1688.             <RULEITEM>
  1689.                 <NAME>GetTrusteeNameW</NAME>
  1690.             </RULEITEM>
  1691.             <RULEITEM>
  1692.                 <NAME>GetTrusteeTypeA</NAME>
  1693.             </RULEITEM>
  1694.             <RULEITEM>
  1695.                 <NAME>GetTrusteeTypeW</NAME>
  1696.             </RULEITEM>
  1697.             <RULEITEM>
  1698.                 <NAME>GetUserObjectSecurity</NAME>
  1699.             </RULEITEM>
  1700.             <RULEITEM>
  1701.                 <NAME>ImpersonateLoggedOnUser</NAME>
  1702.             </RULEITEM>
  1703.             <RULEITEM>
  1704.                 <NAME>ImpersonateNamedPipeClient</NAME>
  1705.             </RULEITEM>
  1706.             <RULEITEM>
  1707.                 <NAME>ImpersonateSelf</NAME>
  1708.             </RULEITEM>
  1709.             <RULEITEM>
  1710.                 <NAME>InitializeAcl</NAME>
  1711.             </RULEITEM>
  1712.             <RULEITEM>
  1713.                 <NAME>InitializeSecurityDescriptor</NAME>
  1714.             </RULEITEM>
  1715.             <RULEITEM>
  1716.                 <NAME>InitializeSid</NAME>
  1717.             </RULEITEM>
  1718.             <RULEITEM>
  1719.                 <NAME>IsTokenRestricted</NAME>
  1720.             </RULEITEM>
  1721.             <RULEITEM>
  1722.                 <NAME>IsValidAcl</NAME>
  1723.             </RULEITEM>
  1724.             <RULEITEM>
  1725.                 <NAME>IsValidSecurityDescriptor</NAME>
  1726.             </RULEITEM>
  1727.             <RULEITEM>
  1728.                 <NAME>IsValidSid</NAME>
  1729.             </RULEITEM>
  1730.             <RULEITEM>
  1731.                 <NAME>LogonUserA</NAME>
  1732.             </RULEITEM>
  1733.             <RULEITEM>
  1734.                 <NAME>LogonUserW</NAME>
  1735.             </RULEITEM>
  1736.             <RULEITEM>
  1737.                 <NAME>LookupAccountNameA</NAME>
  1738.             </RULEITEM>
  1739.             <RULEITEM>
  1740.                 <NAME>LookupAccountNameW</NAME>
  1741.             </RULEITEM>
  1742.             <RULEITEM>
  1743.                 <NAME>LookupAccountSidA</NAME>
  1744.             </RULEITEM>
  1745.             <RULEITEM>
  1746.                 <NAME>LookupAccountSidW</NAME>
  1747.             </RULEITEM>
  1748.             <RULEITEM>
  1749.                 <NAME>LookupPrivilegeDisplayNameA</NAME>
  1750.             </RULEITEM>
  1751.             <RULEITEM>
  1752.                 <NAME>LookupPrivilegeDisplayNameW</NAME>
  1753.             </RULEITEM>
  1754.             <RULEITEM>
  1755.                 <NAME>LookupPrivilegeNameA</NAME>
  1756.             </RULEITEM>
  1757.             <RULEITEM>
  1758.                 <NAME>LookupPrivilegeNameW</NAME>
  1759.             </RULEITEM>
  1760.             <RULEITEM>
  1761.                 <NAME>LookupPrivilegeValueA</NAME>
  1762.             </RULEITEM>
  1763.             <RULEITEM>
  1764.                 <NAME>LookupPrivilegeValueW</NAME>
  1765.             </RULEITEM>
  1766.             <RULEITEM>
  1767.                 <NAME>LookupSecurityDescriptorPartsA</NAME>
  1768.             </RULEITEM>
  1769.             <RULEITEM>
  1770.                 <NAME>LookupSecurityDescriptorPartsW</NAME>
  1771.             </RULEITEM>
  1772.             <RULEITEM>
  1773.                 <NAME>MakeAbsoluteSD</NAME>
  1774.             </RULEITEM>
  1775.             <RULEITEM>
  1776.                 <NAME>MakeSelfRelativeSD</NAME>
  1777.             </RULEITEM>
  1778.             <RULEITEM>
  1779.                 <NAME>MapGenericMask</NAME>
  1780.             </RULEITEM>
  1781.             <RULEITEM>
  1782.                 <NAME>ObjectCloseAuditAlarmA</NAME>
  1783.             </RULEITEM>
  1784.             <RULEITEM>
  1785.                 <NAME>ObjectCloseAuditAlarmW</NAME>
  1786.             </RULEITEM>
  1787.             <RULEITEM>
  1788.                 <NAME>ObjectDeleteAuditAlarmA</NAME>
  1789.             </RULEITEM>
  1790.             <RULEITEM>
  1791.                 <NAME>ObjectDeleteAuditAlarmW</NAME>
  1792.             </RULEITEM>
  1793.             <RULEITEM>
  1794.                 <NAME>ObjectOpenAuditAlarmA</NAME>
  1795.             </RULEITEM>
  1796.             <RULEITEM>
  1797.                 <NAME>ObjectOpenAuditAlarmW</NAME>
  1798.             </RULEITEM>
  1799.             <RULEITEM>
  1800.                 <NAME>ObjectPrivilegeAuditAlarmA</NAME>
  1801.             </RULEITEM>
  1802.             <RULEITEM>
  1803.                 <NAME>ObjectPrivilegeAuditAlarmW</NAME>
  1804.             </RULEITEM>
  1805.             <RULEITEM>
  1806.                 <NAME>OpenProcessToken</NAME>
  1807.             </RULEITEM>
  1808.             <RULEITEM>
  1809.                 <NAME>OpenThreadToken</NAME>
  1810.             </RULEITEM>
  1811.             <RULEITEM>
  1812.                 <NAME>PrivilegeCheck</NAME>
  1813.             </RULEITEM>
  1814.             <RULEITEM>
  1815.                 <NAME>PrivilegedServiceAuditAlarmA</NAME>
  1816.             </RULEITEM>
  1817.             <RULEITEM>
  1818.                 <NAME>PrivilegedServiceAuditAlarmW</NAME>
  1819.             </RULEITEM>
  1820.             <RULEITEM>
  1821.                 <NAME>RevertToSelf</NAME>
  1822.             </RULEITEM>
  1823.             <RULEITEM>
  1824.                 <NAME>SetAclInformation</NAME>
  1825.             </RULEITEM>
  1826.             <RULEITEM>
  1827.                 <NAME>SetEntriesInAclA</NAME>
  1828.             </RULEITEM>
  1829.             <RULEITEM>
  1830.                 <NAME>SetEntriesInAclW</NAME>
  1831.             </RULEITEM>
  1832.             <RULEITEM>
  1833.                 <NAME>SetFileSecurityA</NAME>
  1834.             </RULEITEM>
  1835.             <RULEITEM>
  1836.                 <NAME>SetFileSecurityW</NAME>
  1837.             </RULEITEM>
  1838.             <RULEITEM>
  1839.                 <NAME>SetKernelObjectSecurity</NAME>
  1840.             </RULEITEM>
  1841.             <RULEITEM>
  1842.                 <NAME>SetNamedSecurityInfoA</NAME>
  1843.             </RULEITEM>
  1844.             <RULEITEM>
  1845.                 <NAME>SetNamedSecurityInfoW</NAME>
  1846.             </RULEITEM>
  1847.             <RULEITEM>
  1848.                 <NAME>SetPrivateObjectSecurity</NAME>
  1849.             </RULEITEM>
  1850.             <RULEITEM>
  1851.                 <NAME>SetPrivateObjectSecurityEx</NAME>
  1852.             </RULEITEM>
  1853.             <RULEITEM>
  1854.                 <NAME>SetSecurityDescriptorControl</NAME>
  1855.             </RULEITEM>
  1856.             <RULEITEM>
  1857.                 <NAME>SetSecurityDescriptorDacl</NAME>
  1858.             </RULEITEM>
  1859.             <RULEITEM>
  1860.                 <NAME>SetSecurityDescriptorGroup</NAME>
  1861.             </RULEITEM>
  1862.             <RULEITEM>
  1863.                 <NAME>SetSecurityDescriptorOwner</NAME>
  1864.             </RULEITEM>
  1865.             <RULEITEM>
  1866.                 <NAME>SetSecurityDescriptorSacl</NAME>
  1867.             </RULEITEM>
  1868.             <RULEITEM>
  1869.                 <NAME>SetSecurityInfo</NAME>
  1870.             </RULEITEM>
  1871.             <RULEITEM>
  1872.                 <NAME>SetThreadToken</NAME>
  1873.             </RULEITEM>
  1874.             <RULEITEM>
  1875.                 <NAME>SetTokenInformation</NAME>
  1876.             </RULEITEM>
  1877.             <RULEITEM>
  1878.                 <NAME>SetUserObjectSecurity</NAME>
  1879.             </RULEITEM>
  1880.         </RULEITEMS>
  1881.     </RULE>
  1882.     <RULE>
  1883.         <NAME>Rule_func Win32 Windows NT Services</NAME>
  1884.         <TYPE>8</TYPE>
  1885.         <ID>23</ID>
  1886.         <RULEITEMS>
  1887.             <RULEITEM>
  1888.                 <NAME>ChangeServiceConfig2A</NAME>
  1889.             </RULEITEM>
  1890.             <RULEITEM>
  1891.                 <NAME>ChangeServiceConfig2W</NAME>
  1892.             </RULEITEM>
  1893.             <RULEITEM>
  1894.                 <NAME>ChangeServiceConfigA</NAME>
  1895.             </RULEITEM>
  1896.             <RULEITEM>
  1897.                 <NAME>ChangeServiceConfigW</NAME>
  1898.             </RULEITEM>
  1899.             <RULEITEM>
  1900.                 <NAME>CloseServiceHandle</NAME>
  1901.             </RULEITEM>
  1902.             <RULEITEM>
  1903.                 <NAME>ControlService</NAME>
  1904.             </RULEITEM>
  1905.             <RULEITEM>
  1906.                 <NAME>CreateServiceA</NAME>
  1907.             </RULEITEM>
  1908.             <RULEITEM>
  1909.                 <NAME>CreateServiceW</NAME>
  1910.             </RULEITEM>
  1911.             <RULEITEM>
  1912.                 <NAME>DeleteService</NAME>
  1913.             </RULEITEM>
  1914.             <RULEITEM>
  1915.                 <NAME>EnumDependentServicesA</NAME>
  1916.             </RULEITEM>
  1917.             <RULEITEM>
  1918.                 <NAME>EnumDependentServicesW</NAME>
  1919.             </RULEITEM>
  1920.             <RULEITEM>
  1921.                 <NAME>EnumServicesStatusA</NAME>
  1922.             </RULEITEM>
  1923.             <RULEITEM>
  1924.                 <NAME>EnumServicesStatusW</NAME>
  1925.             </RULEITEM>
  1926.             <RULEITEM>
  1927.                 <NAME>GetServiceDisplayNameA</NAME>
  1928.             </RULEITEM>
  1929.             <RULEITEM>
  1930.                 <NAME>GetServiceDisplayNameW</NAME>
  1931.             </RULEITEM>
  1932.             <RULEITEM>
  1933.                 <NAME>GetServiceKeyNameA</NAME>
  1934.             </RULEITEM>
  1935.             <RULEITEM>
  1936.                 <NAME>GetServiceKeyNameW</NAME>
  1937.             </RULEITEM>
  1938.             <RULEITEM>
  1939.                 <NAME>LockServiceDatabase</NAME>
  1940.             </RULEITEM>
  1941.             <RULEITEM>
  1942.                 <NAME>NotifyBootConfigStatus</NAME>
  1943.             </RULEITEM>
  1944.             <RULEITEM>
  1945.                 <NAME>OpenSCManagerA</NAME>
  1946.             </RULEITEM>
  1947.             <RULEITEM>
  1948.                 <NAME>OpenSCManagerW</NAME>
  1949.             </RULEITEM>
  1950.             <RULEITEM>
  1951.                 <NAME>OpenServiceA</NAME>
  1952.             </RULEITEM>
  1953.             <RULEITEM>
  1954.                 <NAME>OpenServiceW</NAME>
  1955.             </RULEITEM>
  1956.             <RULEITEM>
  1957.                 <NAME>QueryServiceConfig2A</NAME>
  1958.             </RULEITEM>
  1959.             <RULEITEM>
  1960.                 <NAME>QueryServiceConfig2W</NAME>
  1961.             </RULEITEM>
  1962.             <RULEITEM>
  1963.                 <NAME>QueryServiceConfigA</NAME>
  1964.             </RULEITEM>
  1965.             <RULEITEM>
  1966.                 <NAME>QueryServiceConfigW</NAME>
  1967.             </RULEITEM>
  1968.             <RULEITEM>
  1969.                 <NAME>QueryServiceLockStatusA</NAME>
  1970.             </RULEITEM>
  1971.             <RULEITEM>
  1972.                 <NAME>QueryServiceLockStatusW</NAME>
  1973.             </RULEITEM>
  1974.             <RULEITEM>
  1975.                 <NAME>QueryServiceObjectSecurity</NAME>
  1976.             </RULEITEM>
  1977.             <RULEITEM>
  1978.                 <NAME>QueryServiceStatus</NAME>
  1979.             </RULEITEM>
  1980.             <RULEITEM>
  1981.                 <NAME>RegisterServiceCtrlHandlerA</NAME>
  1982.             </RULEITEM>
  1983.             <RULEITEM>
  1984.                 <NAME>RegisterServiceCtrlHandlerW</NAME>
  1985.             </RULEITEM>
  1986.             <RULEITEM>
  1987.                 <NAME>SetServiceObjectSecurity</NAME>
  1988.             </RULEITEM>
  1989.             <RULEITEM>
  1990.                 <NAME>SetServiceStatus</NAME>
  1991.             </RULEITEM>
  1992.             <RULEITEM>
  1993.                 <NAME>StartServiceA</NAME>
  1994.             </RULEITEM>
  1995.             <RULEITEM>
  1996.                 <NAME>StartServiceCtrlDispatcherA</NAME>
  1997.             </RULEITEM>
  1998.             <RULEITEM>
  1999.                 <NAME>StartServiceCtrlDispatcherW</NAME>
  2000.             </RULEITEM>
  2001.             <RULEITEM>
  2002.                 <NAME>StartServiceW</NAME>
  2003.             </RULEITEM>
  2004.             <RULEITEM>
  2005.                 <NAME>UnlockServiceDatabase</NAME>
  2006.             </RULEITEM>
  2007.         </RULEITEMS>
  2008.     </RULE>
  2009.     <RULE>
  2010.         <NAME>Rule_func Win32 Network Management</NAME>
  2011.         <TYPE>8</TYPE>
  2012.         <ID>24</ID>
  2013.         <RULEITEMS>
  2014.             <RULEITEM>
  2015.                 <NAME>MultinetGetConnectionPerformanceA</NAME>
  2016.             </RULEITEM>
  2017.             <RULEITEM>
  2018.                 <NAME>MultinetGetConnectionPerformanceW</NAME>
  2019.             </RULEITEM>
  2020.             <RULEITEM>
  2021.                 <NAME>NetAlertRaise</NAME>
  2022.             </RULEITEM>
  2023.             <RULEITEM>
  2024.                 <NAME>NetAlertRaiseEx</NAME>
  2025.             </RULEITEM>
  2026.             <RULEITEM>
  2027.                 <NAME>NetApiBufferAllocate</NAME>
  2028.             </RULEITEM>
  2029.             <RULEITEM>
  2030.                 <NAME>NetApiBufferFree</NAME>
  2031.             </RULEITEM>
  2032.             <RULEITEM>
  2033.                 <NAME>NetApiBufferReallocate</NAME>
  2034.             </RULEITEM>
  2035.             <RULEITEM>
  2036.                 <NAME>NetApiBufferSize</NAME>
  2037.             </RULEITEM>
  2038.             <RULEITEM>
  2039.                 <NAME>NetConnectionEnum</NAME>
  2040.             </RULEITEM>
  2041.             <RULEITEM>
  2042.                 <NAME>NetFileClose</NAME>
  2043.             </RULEITEM>
  2044.             <RULEITEM>
  2045.                 <NAME>NetFileGetInfo</NAME>
  2046.             </RULEITEM>
  2047.             <RULEITEM>
  2048.                 <NAME>NetGetAnyDCName</NAME>
  2049.             </RULEITEM>
  2050.             <RULEITEM>
  2051.                 <NAME>NetGetDCName</NAME>
  2052.             </RULEITEM>
  2053.             <RULEITEM>
  2054.                 <NAME>NetGetDisplayInformationIndex</NAME>
  2055.             </RULEITEM>
  2056.             <RULEITEM>
  2057.                 <NAME>NetGroupAdd</NAME>
  2058.             </RULEITEM>
  2059.             <RULEITEM>
  2060.                 <NAME>NetGroupAddUser</NAME>
  2061.             </RULEITEM>
  2062.             <RULEITEM>
  2063.                 <NAME>NetGroupDel</NAME>
  2064.             </RULEITEM>
  2065.             <RULEITEM>
  2066.                 <NAME>NetGroupDelUser</NAME>
  2067.             </RULEITEM>
  2068.             <RULEITEM>
  2069.                 <NAME>NetGroupEnum</NAME>
  2070.             </RULEITEM>
  2071.             <RULEITEM>
  2072.                 <NAME>NetGroupGetInfo</NAME>
  2073.             </RULEITEM>
  2074.             <RULEITEM>
  2075.                 <NAME>NetGroupGetUsers</NAME>
  2076.             </RULEITEM>
  2077.             <RULEITEM>
  2078.                 <NAME>NetGroupSetInfo</NAME>
  2079.             </RULEITEM>
  2080.             <RULEITEM>
  2081.                 <NAME>NetGroupSetUsers</NAME>
  2082.             </RULEITEM>
  2083.             <RULEITEM>
  2084.                 <NAME>NetLocalGroupAdd</NAME>
  2085.             </RULEITEM>
  2086.             <RULEITEM>
  2087.                 <NAME>NetLocalGroupAddMember</NAME>
  2088.             </RULEITEM>
  2089.             <RULEITEM>
  2090.                 <NAME>NetLocalGroupAddMembers</NAME>
  2091.             </RULEITEM>
  2092.             <RULEITEM>
  2093.                 <NAME>NetLocalGroupDel</NAME>
  2094.             </RULEITEM>
  2095.             <RULEITEM>
  2096.                 <NAME>NetLocalGroupDelMember</NAME>
  2097.             </RULEITEM>
  2098.             <RULEITEM>
  2099.                 <NAME>NetLocalGroupDelMembers</NAME>
  2100.             </RULEITEM>
  2101.             <RULEITEM>
  2102.                 <NAME>NetLocalGroupEnum</NAME>
  2103.             </RULEITEM>
  2104.             <RULEITEM>
  2105.                 <NAME>NetLocalGroupGetInfo</NAME>
  2106.             </RULEITEM>
  2107.             <RULEITEM>
  2108.                 <NAME>NetLocalGroupGetMembers</NAME>
  2109.             </RULEITEM>
  2110.             <RULEITEM>
  2111.                 <NAME>NetLocalGroupSetInfo</NAME>
  2112.             </RULEITEM>
  2113.             <RULEITEM>
  2114.                 <NAME>NetLocalGroupSetMembers</NAME>
  2115.             </RULEITEM>
  2116.             <RULEITEM>
  2117.                 <NAME>NetMessageBufferSend</NAME>
  2118.             </RULEITEM>
  2119.             <RULEITEM>
  2120.                 <NAME>NetMessageNameAdd</NAME>
  2121.             </RULEITEM>
  2122.             <RULEITEM>
  2123.                 <NAME>NetMessageNameDel</NAME>
  2124.             </RULEITEM>
  2125.             <RULEITEM>
  2126.                 <NAME>NetMessageNameEnum</NAME>
  2127.             </RULEITEM>
  2128.             <RULEITEM>
  2129.                 <NAME>NetMessageNameGetInfo</NAME>
  2130.             </RULEITEM>
  2131.             <RULEITEM>
  2132.                 <NAME>NetQueryDisplayInformation</NAME>
  2133.             </RULEITEM>
  2134.             <RULEITEM>
  2135.                 <NAME>NetRemoteComputerSupports</NAME>
  2136.             </RULEITEM>
  2137.             <RULEITEM>
  2138.                 <NAME>NetRemoteTOd</NAME>
  2139.             </RULEITEM>
  2140.             <RULEITEM>
  2141.                 <NAME>NetReplExportDirAdd</NAME>
  2142.             </RULEITEM>
  2143.             <RULEITEM>
  2144.                 <NAME>NetReplExportDirDel</NAME>
  2145.             </RULEITEM>
  2146.             <RULEITEM>
  2147.                 <NAME>NetReplExportDirEnum</NAME>
  2148.             </RULEITEM>
  2149.             <RULEITEM>
  2150.                 <NAME>NetReplExportDirGetInfo</NAME>
  2151.             </RULEITEM>
  2152.             <RULEITEM>
  2153.                 <NAME>NetReplExportDirLock</NAME>
  2154.             </RULEITEM>
  2155.             <RULEITEM>
  2156.                 <NAME>NetReplExportDirSetInfo</NAME>
  2157.             </RULEITEM>
  2158.             <RULEITEM>
  2159.                 <NAME>NetReplExportDirUnlock</NAME>
  2160.             </RULEITEM>
  2161.             <RULEITEM>
  2162.                 <NAME>NetReplGetInfo</NAME>
  2163.             </RULEITEM>
  2164.             <RULEITEM>
  2165.                 <NAME>NetReplImportDirAdd</NAME>
  2166.             </RULEITEM>
  2167.             <RULEITEM>
  2168.                 <NAME>NetReplImportDirDel</NAME>
  2169.             </RULEITEM>
  2170.             <RULEITEM>
  2171.                 <NAME>NetReplImportDirEnum</NAME>
  2172.             </RULEITEM>
  2173.             <RULEITEM>
  2174.                 <NAME>NetReplImportDirGetInfo</NAME>
  2175.             </RULEITEM>
  2176.             <RULEITEM>
  2177.                 <NAME>NetReplImportDirLock</NAME>
  2178.             </RULEITEM>
  2179.             <RULEITEM>
  2180.                 <NAME>NetReplImportDirUnlock</NAME>
  2181.             </RULEITEM>
  2182.             <RULEITEM>
  2183.                 <NAME>NetReplSetInfo</NAME>
  2184.             </RULEITEM>
  2185.             <RULEITEM>
  2186.                 <NAME>NetScheduleJobAdd</NAME>
  2187.             </RULEITEM>
  2188.             <RULEITEM>
  2189.                 <NAME>NetScheduleJobDel</NAME>
  2190.             </RULEITEM>
  2191.             <RULEITEM>
  2192.                 <NAME>NetScheduleJobEnum</NAME>
  2193.             </RULEITEM>
  2194.             <RULEITEM>
  2195.                 <NAME>NetScheduleJobGetInfo</NAME>
  2196.             </RULEITEM>
  2197.             <RULEITEM>
  2198.                 <NAME>NetServerComputerNameAdd</NAME>
  2199.             </RULEITEM>
  2200.             <RULEITEM>
  2201.                 <NAME>NetServerComputerNameDel</NAME>
  2202.             </RULEITEM>
  2203.             <RULEITEM>
  2204.                 <NAME>NetServerDiskEnum</NAME>
  2205.             </RULEITEM>
  2206.             <RULEITEM>
  2207.                 <NAME>NetServerEnum</NAME>
  2208.             </RULEITEM>
  2209.             <RULEITEM>
  2210.                 <NAME>NetServerEnumEx</NAME>
  2211.             </RULEITEM>
  2212.             <RULEITEM>
  2213.                 <NAME>NetServerGetInfo</NAME>
  2214.             </RULEITEM>
  2215.             <RULEITEM>
  2216.                 <NAME>NetServerSetInfo</NAME>
  2217.             </RULEITEM>
  2218.             <RULEITEM>
  2219.                 <NAME>NetServerTransportAdd</NAME>
  2220.             </RULEITEM>
  2221.             <RULEITEM>
  2222.                 <NAME>NetServerTransportAddEx</NAME>
  2223.             </RULEITEM>
  2224.             <RULEITEM>
  2225.                 <NAME>NetServerTransportDel</NAME>
  2226.             </RULEITEM>
  2227.             <RULEITEM>
  2228.                 <NAME>NetServerTransportEnum</NAME>
  2229.             </RULEITEM>
  2230.             <RULEITEM>
  2231.                 <NAME>NetSessionDel</NAME>
  2232.             </RULEITEM>
  2233.             <RULEITEM>
  2234.                 <NAME>NetSessionEnum</NAME>
  2235.             </RULEITEM>
  2236.             <RULEITEM>
  2237.                 <NAME>NetSessionGetInfo</NAME>
  2238.             </RULEITEM>
  2239.             <RULEITEM>
  2240.                 <NAME>NetShareAdd</NAME>
  2241.             </RULEITEM>
  2242.             <RULEITEM>
  2243.                 <NAME>NetShareCheck</NAME>
  2244.             </RULEITEM>
  2245.             <RULEITEM>
  2246.                 <NAME>NetShareDel</NAME>
  2247.             </RULEITEM>
  2248.             <RULEITEM>
  2249.                 <NAME>NetShareEnum</NAME>
  2250.             </RULEITEM>
  2251.             <RULEITEM>
  2252.                 <NAME>NetShareGetInfo</NAME>
  2253.             </RULEITEM>
  2254.             <RULEITEM>
  2255.                 <NAME>NetShareSetInfo</NAME>
  2256.             </RULEITEM>
  2257.             <RULEITEM>
  2258.                 <NAME>NetStatisticsGet</NAME>
  2259.             </RULEITEM>
  2260.             <RULEITEM>
  2261.                 <NAME>NetUseAdd</NAME>
  2262.             </RULEITEM>
  2263.             <RULEITEM>
  2264.                 <NAME>NetUseDel</NAME>
  2265.             </RULEITEM>
  2266.             <RULEITEM>
  2267.                 <NAME>NetUseEnum</NAME>
  2268.             </RULEITEM>
  2269.             <RULEITEM>
  2270.                 <NAME>NetUseGetInfo</NAME>
  2271.             </RULEITEM>
  2272.             <RULEITEM>
  2273.                 <NAME>NetUserAdd</NAME>
  2274.             </RULEITEM>
  2275.             <RULEITEM>
  2276.                 <NAME>NetUserChangePassword</NAME>
  2277.             </RULEITEM>
  2278.             <RULEITEM>
  2279.                 <NAME>NetUserDel</NAME>
  2280.             </RULEITEM>
  2281.             <RULEITEM>
  2282.                 <NAME>NetUserEnum</NAME>
  2283.             </RULEITEM>
  2284.             <RULEITEM>
  2285.                 <NAME>NetUserGetGroups</NAME>
  2286.             </RULEITEM>
  2287.             <RULEITEM>
  2288.                 <NAME>NetUserGetInfo</NAME>
  2289.             </RULEITEM>
  2290.             <RULEITEM>
  2291.                 <NAME>NetUserGetLocalGroups</NAME>
  2292.             </RULEITEM>
  2293.             <RULEITEM>
  2294.                 <NAME>NetUserModalsGet</NAME>
  2295.             </RULEITEM>
  2296.             <RULEITEM>
  2297.                 <NAME>NetUserModalsSet</NAME>
  2298.             </RULEITEM>
  2299.             <RULEITEM>
  2300.                 <NAME>NetUserSetGroups</NAME>
  2301.             </RULEITEM>
  2302.             <RULEITEM>
  2303.                 <NAME>NetUserSetInfo</NAME>
  2304.             </RULEITEM>
  2305.             <RULEITEM>
  2306.                 <NAME>NetWkstaGetInfo</NAME>
  2307.             </RULEITEM>
  2308.             <RULEITEM>
  2309.                 <NAME>NetWkstaSetInfo</NAME>
  2310.             </RULEITEM>
  2311.             <RULEITEM>
  2312.                 <NAME>NetWkstaTransportAdd</NAME>
  2313.             </RULEITEM>
  2314.             <RULEITEM>
  2315.                 <NAME>NetWkstaTransportDel</NAME>
  2316.             </RULEITEM>
  2317.             <RULEITEM>
  2318.                 <NAME>NetWkstaTransportEnum</NAME>
  2319.             </RULEITEM>
  2320.             <RULEITEM>
  2321.                 <NAME>NetWkstaUserEnum</NAME>
  2322.             </RULEITEM>
  2323.             <RULEITEM>
  2324.                 <NAME>NetWkstaUserGetInfo</NAME>
  2325.             </RULEITEM>
  2326.             <RULEITEM>
  2327.                 <NAME>NetWkstaUserSetInfo</NAME>
  2328.             </RULEITEM>
  2329.             <RULEITEM>
  2330.                 <NAME>WNetAddConnection2A</NAME>
  2331.             </RULEITEM>
  2332.             <RULEITEM>
  2333.                 <NAME>WNetAddConnection2W</NAME>
  2334.             </RULEITEM>
  2335.             <RULEITEM>
  2336.                 <NAME>WNetAddConnection3A</NAME>
  2337.             </RULEITEM>
  2338.             <RULEITEM>
  2339.                 <NAME>WNetAddConnection3W</NAME>
  2340.             </RULEITEM>
  2341.             <RULEITEM>
  2342.                 <NAME>WNetAddConnectionA</NAME>
  2343.             </RULEITEM>
  2344.             <RULEITEM>
  2345.                 <NAME>WNetAddConnectionW</NAME>
  2346.             </RULEITEM>
  2347.             <RULEITEM>
  2348.                 <NAME>WNetCancelConnection2A</NAME>
  2349.             </RULEITEM>
  2350.             <RULEITEM>
  2351.                 <NAME>WNetCancelConnection2W</NAME>
  2352.             </RULEITEM>
  2353.             <RULEITEM>
  2354.                 <NAME>WNetCancelConnectionA</NAME>
  2355.             </RULEITEM>
  2356.             <RULEITEM>
  2357.                 <NAME>WNetCancelConnectionW</NAME>
  2358.             </RULEITEM>
  2359.             <RULEITEM>
  2360.                 <NAME>WNetCloseEnum</NAME>
  2361.             </RULEITEM>
  2362.             <RULEITEM>
  2363.                 <NAME>WNetConnectionDialog</NAME>
  2364.             </RULEITEM>
  2365.             <RULEITEM>
  2366.                 <NAME>WNetConnectionDialog1A</NAME>
  2367.             </RULEITEM>
  2368.             <RULEITEM>
  2369.                 <NAME>WNetConnectionDialog1W</NAME>
  2370.             </RULEITEM>
  2371.             <RULEITEM>
  2372.                 <NAME>WNetDisconnectDialog</NAME>
  2373.             </RULEITEM>
  2374.             <RULEITEM>
  2375.                 <NAME>WNetDisconnectDialog1A</NAME>
  2376.             </RULEITEM>
  2377.             <RULEITEM>
  2378.                 <NAME>WNetDisconnectDialog1W</NAME>
  2379.             </RULEITEM>
  2380.             <RULEITEM>
  2381.                 <NAME>WNetEnumResourceA</NAME>
  2382.             </RULEITEM>
  2383.             <RULEITEM>
  2384.                 <NAME>WNetEnumResourceW</NAME>
  2385.             </RULEITEM>
  2386.             <RULEITEM>
  2387.                 <NAME>WNetGetConnectionA</NAME>
  2388.             </RULEITEM>
  2389.             <RULEITEM>
  2390.                 <NAME>WNetGetConnectionW</NAME>
  2391.             </RULEITEM>
  2392.             <RULEITEM>
  2393.                 <NAME>WNetGetLastErrorA</NAME>
  2394.             </RULEITEM>
  2395.             <RULEITEM>
  2396.                 <NAME>WNetGetLastErrorW</NAME>
  2397.             </RULEITEM>
  2398.             <RULEITEM>
  2399.                 <NAME>WNetGetNetworkInformationA</NAME>
  2400.             </RULEITEM>
  2401.             <RULEITEM>
  2402.                 <NAME>WNetGetNetworkInformationW</NAME>
  2403.             </RULEITEM>
  2404.             <RULEITEM>
  2405.                 <NAME>WNetGetProviderNameA</NAME>
  2406.             </RULEITEM>
  2407.             <RULEITEM>
  2408.                 <NAME>WNetGetProviderNameW</NAME>
  2409.             </RULEITEM>
  2410.             <RULEITEM>
  2411.                 <NAME>WNetGetResourceInformationA</NAME>
  2412.             </RULEITEM>
  2413.             <RULEITEM>
  2414.                 <NAME>WNetGetResourceInformationW</NAME>
  2415.             </RULEITEM>
  2416.             <RULEITEM>
  2417.                 <NAME>WNetGetResourceParentA</NAME>
  2418.             </RULEITEM>
  2419.             <RULEITEM>
  2420.                 <NAME>WNetGetResourceParentW</NAME>
  2421.             </RULEITEM>
  2422.             <RULEITEM>
  2423.                 <NAME>WNetGetUniversalNameA</NAME>
  2424.             </RULEITEM>
  2425.             <RULEITEM>
  2426.                 <NAME>WNetGetUniversalNameW</NAME>
  2427.             </RULEITEM>
  2428.             <RULEITEM>
  2429.                 <NAME>WNetGetUserA</NAME>
  2430.             </RULEITEM>
  2431.             <RULEITEM>
  2432.                 <NAME>WNetGetUserW</NAME>
  2433.             </RULEITEM>
  2434.             <RULEITEM>
  2435.                 <NAME>WNetOpenEnumA</NAME>
  2436.             </RULEITEM>
  2437.             <RULEITEM>
  2438.                 <NAME>WNetOpenEnumW</NAME>
  2439.             </RULEITEM>
  2440.             <RULEITEM>
  2441.                 <NAME>WNetUseConnectionA</NAME>
  2442.             </RULEITEM>
  2443.             <RULEITEM>
  2444.                 <NAME>WnetUseConnectionW</NAME>
  2445.             </RULEITEM>
  2446.         </RULEITEMS>
  2447.     </RULE>
  2448.     <RULE>
  2449.         <NAME>Rule_func Win32 Windows Sockets</NAME>
  2450.         <TYPE>8</TYPE>
  2451.         <ID>25</ID>
  2452.         <RULEITEMS>
  2453.             <RULEITEM>
  2454.                 <NAME>accept</NAME>
  2455.             </RULEITEM>
  2456.             <RULEITEM>
  2457.                 <NAME>bind</NAME>
  2458.             </RULEITEM>
  2459.             <RULEITEM>
  2460.                 <NAME>closesocket</NAME>
  2461.             </RULEITEM>
  2462.             <RULEITEM>
  2463.                 <NAME>connect</NAME>
  2464.             </RULEITEM>
  2465.             <RULEITEM>
  2466.                 <NAME>gethostbyaddr</NAME>
  2467.             </RULEITEM>
  2468.             <RULEITEM>
  2469.                 <NAME>gethostbyname</NAME>
  2470.             </RULEITEM>
  2471.             <RULEITEM>
  2472.                 <NAME>gethostname</NAME>
  2473.             </RULEITEM>
  2474.             <RULEITEM>
  2475.                 <NAME>getpeername</NAME>
  2476.             </RULEITEM>
  2477.             <RULEITEM>
  2478.                 <NAME>getprotobyname</NAME>
  2479.             </RULEITEM>
  2480.             <RULEITEM>
  2481.                 <NAME>getprotobynumber</NAME>
  2482.             </RULEITEM>
  2483.             <RULEITEM>
  2484.                 <NAME>getservbyname</NAME>
  2485.             </RULEITEM>
  2486.             <RULEITEM>
  2487.                 <NAME>getservbyport</NAME>
  2488.             </RULEITEM>
  2489.             <RULEITEM>
  2490.                 <NAME>getsockname</NAME>
  2491.             </RULEITEM>
  2492.             <RULEITEM>
  2493.                 <NAME>getsockopt</NAME>
  2494.             </RULEITEM>
  2495.             <RULEITEM>
  2496.                 <NAME>htonl</NAME>
  2497.             </RULEITEM>
  2498.             <RULEITEM>
  2499.                 <NAME>htons</NAME>
  2500.             </RULEITEM>
  2501.             <RULEITEM>
  2502.                 <NAME>inet_addr</NAME>
  2503.             </RULEITEM>
  2504.             <RULEITEM>
  2505.                 <NAME>inet_ntoa</NAME>
  2506.             </RULEITEM>
  2507.             <RULEITEM>
  2508.                 <NAME>ioctlsocket</NAME>
  2509.             </RULEITEM>
  2510.             <RULEITEM>
  2511.                 <NAME>listen</NAME>
  2512.             </RULEITEM>
  2513.             <RULEITEM>
  2514.                 <NAME>ntohl</NAME>
  2515.             </RULEITEM>
  2516.             <RULEITEM>
  2517.                 <NAME>ntohs</NAME>
  2518.             </RULEITEM>
  2519.             <RULEITEM>
  2520.                 <NAME>recv</NAME>
  2521.             </RULEITEM>
  2522.             <RULEITEM>
  2523.                 <NAME>recvfrom</NAME>
  2524.             </RULEITEM>
  2525.             <RULEITEM>
  2526.                 <NAME>select</NAME>
  2527.             </RULEITEM>
  2528.             <RULEITEM>
  2529.                 <NAME>send</NAME>
  2530.             </RULEITEM>
  2531.             <RULEITEM>
  2532.                 <NAME>sendto</NAME>
  2533.             </RULEITEM>
  2534.             <RULEITEM>
  2535.                 <NAME>setsockopt</NAME>
  2536.             </RULEITEM>
  2537.             <RULEITEM>
  2538.                 <NAME>shutdown</NAME>
  2539.             </RULEITEM>
  2540.             <RULEITEM>
  2541.                 <NAME>socket</NAME>
  2542.             </RULEITEM>
  2543.             <RULEITEM>
  2544.                 <NAME>WSAAccept</NAME>
  2545.             </RULEITEM>
  2546.             <RULEITEM>
  2547.                 <NAME>WSAAddressToStringA</NAME>
  2548.             </RULEITEM>
  2549.             <RULEITEM>
  2550.                 <NAME>WSAAddressToStringW</NAME>
  2551.             </RULEITEM>
  2552.             <RULEITEM>
  2553.                 <NAME>WSAAsyncGetHostByAddr</NAME>
  2554.             </RULEITEM>
  2555.             <RULEITEM>
  2556.                 <NAME>WSAAsyncGetHostByName</NAME>
  2557.             </RULEITEM>
  2558.             <RULEITEM>
  2559.                 <NAME>WSAAsyncGetProtoByName</NAME>
  2560.             </RULEITEM>
  2561.             <RULEITEM>
  2562.                 <NAME>WSAAsyncGetProtoByNumber</NAME>
  2563.             </RULEITEM>
  2564.             <RULEITEM>
  2565.                 <NAME>WSAAsyncGetServByName</NAME>
  2566.             </RULEITEM>
  2567.             <RULEITEM>
  2568.                 <NAME>WSAAsyncGetServByPort</NAME>
  2569.             </RULEITEM>
  2570.             <RULEITEM>
  2571.                 <NAME>WSAAsyncSelect</NAME>
  2572.             </RULEITEM>
  2573.             <RULEITEM>
  2574.                 <NAME>WSACancelAsyncRequest</NAME>
  2575.             </RULEITEM>
  2576.             <RULEITEM>
  2577.                 <NAME>WSACancelBlockingCall</NAME>
  2578.             </RULEITEM>
  2579.             <RULEITEM>
  2580.                 <NAME>WSACleanup</NAME>
  2581.             </RULEITEM>
  2582.             <RULEITEM>
  2583.                 <NAME>WSACloseEvent</NAME>
  2584.             </RULEITEM>
  2585.             <RULEITEM>
  2586.                 <NAME>WSAConnect</NAME>
  2587.             </RULEITEM>
  2588.             <RULEITEM>
  2589.                 <NAME>WSACreateEvent</NAME>
  2590.             </RULEITEM>
  2591.             <RULEITEM>
  2592.                 <NAME>WSADuplicateSocketA</NAME>
  2593.             </RULEITEM>
  2594.             <RULEITEM>
  2595.                 <NAME>WSADuplicateSocketW</NAME>
  2596.             </RULEITEM>
  2597.             <RULEITEM>
  2598.                 <NAME>WSAEnumNameSpaceProvidersA</NAME>
  2599.             </RULEITEM>
  2600.             <RULEITEM>
  2601.                 <NAME>WSAEnumNameSpaceProvidersW</NAME>
  2602.             </RULEITEM>
  2603.             <RULEITEM>
  2604.                 <NAME>WSAEnumNetworkEvents</NAME>
  2605.             </RULEITEM>
  2606.             <RULEITEM>
  2607.                 <NAME>WSAEnumProtocolsA</NAME>
  2608.             </RULEITEM>
  2609.             <RULEITEM>
  2610.                 <NAME>WSAEnumProtocolsW</NAME>
  2611.             </RULEITEM>
  2612.             <RULEITEM>
  2613.                 <NAME>WSAEventSelect</NAME>
  2614.             </RULEITEM>
  2615.             <RULEITEM>
  2616.                 <NAME>WSAGetLastError</NAME>
  2617.             </RULEITEM>
  2618.             <RULEITEM>
  2619.                 <NAME>WSAGetOverlappedResult</NAME>
  2620.             </RULEITEM>
  2621.             <RULEITEM>
  2622.                 <NAME>WSAGetQOSByName</NAME>
  2623.             </RULEITEM>
  2624.             <RULEITEM>
  2625.                 <NAME>WSAGetServiceClassInfoA</NAME>
  2626.             </RULEITEM>
  2627.             <RULEITEM>
  2628.                 <NAME>WSAGetServiceClassInfoW</NAME>
  2629.             </RULEITEM>
  2630.             <RULEITEM>
  2631.                 <NAME>WSAGetServiceClassNameByClassIdA</NAME>
  2632.             </RULEITEM>
  2633.             <RULEITEM>
  2634.                 <NAME>WSAGetServiceClassNameByClassIdW</NAME>
  2635.             </RULEITEM>
  2636.             <RULEITEM>
  2637.                 <NAME>WSAHtonl</NAME>
  2638.             </RULEITEM>
  2639.             <RULEITEM>
  2640.                 <NAME>WSAHtons</NAME>
  2641.             </RULEITEM>
  2642.             <RULEITEM>
  2643.                 <NAME>WSAInstallServiceClassA</NAME>
  2644.             </RULEITEM>
  2645.             <RULEITEM>
  2646.                 <NAME>WSAInstallServiceClassW</NAME>
  2647.             </RULEITEM>
  2648.             <RULEITEM>
  2649.                 <NAME>WSAIoctl</NAME>
  2650.             </RULEITEM>
  2651.             <RULEITEM>
  2652.                 <NAME>WSAIsBlocking</NAME>
  2653.             </RULEITEM>
  2654.             <RULEITEM>
  2655.                 <NAME>WSAJoinLeaf</NAME>
  2656.             </RULEITEM>
  2657.             <RULEITEM>
  2658.                 <NAME>WSALookupServiceBeginA</NAME>
  2659.             </RULEITEM>
  2660.             <RULEITEM>
  2661.                 <NAME>WSALookupServiceBeginW</NAME>
  2662.             </RULEITEM>
  2663.             <RULEITEM>
  2664.                 <NAME>WSALookupServiceEnd</NAME>
  2665.             </RULEITEM>
  2666.             <RULEITEM>
  2667.                 <NAME>WSALookupServiceNextA</NAME>
  2668.             </RULEITEM>
  2669.             <RULEITEM>
  2670.                 <NAME>WSALookupServiceNextW</NAME>
  2671.             </RULEITEM>
  2672.             <RULEITEM>
  2673.                 <NAME>WSANtohl</NAME>
  2674.             </RULEITEM>
  2675.             <RULEITEM>
  2676.                 <NAME>WSANtohs</NAME>
  2677.             </RULEITEM>
  2678.             <RULEITEM>
  2679.                 <NAME>WSAProviderConfigChange</NAME>
  2680.             </RULEITEM>
  2681.             <RULEITEM>
  2682.                 <NAME>WSARecv</NAME>
  2683.             </RULEITEM>
  2684.             <RULEITEM>
  2685.                 <NAME>WSARecvDisconnect</NAME>
  2686.             </RULEITEM>
  2687.             <RULEITEM>
  2688.                 <NAME>WSARecvFrom</NAME>
  2689.             </RULEITEM>
  2690.             <RULEITEM>
  2691.                 <NAME>WSARemoveServiceClass</NAME>
  2692.             </RULEITEM>
  2693.             <RULEITEM>
  2694.                 <NAME>WSAResetEvent</NAME>
  2695.             </RULEITEM>
  2696.             <RULEITEM>
  2697.                 <NAME>WSASend</NAME>
  2698.             </RULEITEM>
  2699.             <RULEITEM>
  2700.                 <NAME>WSASendDisconnect</NAME>
  2701.             </RULEITEM>
  2702.             <RULEITEM>
  2703.                 <NAME>WSASendTo</NAME>
  2704.             </RULEITEM>
  2705.             <RULEITEM>
  2706.                 <NAME>WSASetBlockingHook</NAME>
  2707.             </RULEITEM>
  2708.             <RULEITEM>
  2709.                 <NAME>WSASetEvent</NAME>
  2710.             </RULEITEM>
  2711.             <RULEITEM>
  2712.                 <NAME>WSASetLastError</NAME>
  2713.             </RULEITEM>
  2714.             <RULEITEM>
  2715.                 <NAME>WSASetServiceA</NAME>
  2716.             </RULEITEM>
  2717.             <RULEITEM>
  2718.                 <NAME>WSASetServiceW</NAME>
  2719.             </RULEITEM>
  2720.             <RULEITEM>
  2721.                 <NAME>WSASocketA</NAME>
  2722.             </RULEITEM>
  2723.             <RULEITEM>
  2724.                 <NAME>WSASocketW</NAME>
  2725.             </RULEITEM>
  2726.             <RULEITEM>
  2727.                 <NAME>WSAStartup</NAME>
  2728.             </RULEITEM>
  2729.             <RULEITEM>
  2730.                 <NAME>WSAStringToAddressA</NAME>
  2731.             </RULEITEM>
  2732.             <RULEITEM>
  2733.                 <NAME>WSAStringToAddressW</NAME>
  2734.             </RULEITEM>
  2735.             <RULEITEM>
  2736.                 <NAME>WSAUnhookBlockingHook</NAME>
  2737.             </RULEITEM>
  2738.             <RULEITEM>
  2739.                 <NAME>WSAWaitForMultipleEvents</NAME>
  2740.             </RULEITEM>
  2741.             <RULEITEM>
  2742.                 <NAME>WSCDeinstallProvider</NAME>
  2743.             </RULEITEM>
  2744.             <RULEITEM>
  2745.                 <NAME>WSCEnableNSProvider</NAME>
  2746.             </RULEITEM>
  2747.             <RULEITEM>
  2748.                 <NAME>WSCEnumProtocols</NAME>
  2749.             </RULEITEM>
  2750.             <RULEITEM>
  2751.                 <NAME>WSCGetProviderPath</NAME>
  2752.             </RULEITEM>
  2753.             <RULEITEM>
  2754.                 <NAME>WSCInstallNameSpace</NAME>
  2755.             </RULEITEM>
  2756.             <RULEITEM>
  2757.                 <NAME>WSCInstallProvider</NAME>
  2758.             </RULEITEM>
  2759.             <RULEITEM>
  2760.                 <NAME>WSCUnInstallNameSpace</NAME>
  2761.             </RULEITEM>
  2762.         </RULEITEMS>
  2763.     </RULE>
  2764.     <RULE>
  2765.         <NAME>Rule_func Win32 Debugging</NAME>
  2766.         <TYPE>8</TYPE>
  2767.         <ID>26</ID>
  2768.         <RULEITEMS>
  2769.             <RULEITEM>
  2770.                 <NAME>ContinueDebugEvent</NAME>
  2771.             </RULEITEM>
  2772.             <RULEITEM>
  2773.                 <NAME>DebugActiveProcess</NAME>
  2774.             </RULEITEM>
  2775.             <RULEITEM>
  2776.                 <NAME>DebugBreak</NAME>
  2777.             </RULEITEM>
  2778.             <RULEITEM>
  2779.                 <NAME>FatalExit</NAME>
  2780.             </RULEITEM>
  2781.             <RULEITEM>
  2782.                 <NAME>FlushInstructionCache</NAME>
  2783.             </RULEITEM>
  2784.             <RULEITEM>
  2785.                 <NAME>GetThreadContext</NAME>
  2786.             </RULEITEM>
  2787.             <RULEITEM>
  2788.                 <NAME>GetThreadSelectorEntry</NAME>
  2789.             </RULEITEM>
  2790.             <RULEITEM>
  2791.                 <NAME>IsDebuggerPresent</NAME>
  2792.             </RULEITEM>
  2793.             <RULEITEM>
  2794.                 <NAME>OutputDebugStringA</NAME>
  2795.             </RULEITEM>
  2796.             <RULEITEM>
  2797.                 <NAME>OutputDebugStringW</NAME>
  2798.             </RULEITEM>
  2799.             <RULEITEM>
  2800.                 <NAME>ReadProcessMemory</NAME>
  2801.             </RULEITEM>
  2802.             <RULEITEM>
  2803.                 <NAME>SetDebugErrorLevel</NAME>
  2804.             </RULEITEM>
  2805.             <RULEITEM>
  2806.                 <NAME>SetThreadContext</NAME>
  2807.             </RULEITEM>
  2808.             <RULEITEM>
  2809.                 <NAME>WaitForDebugEvent</NAME>
  2810.             </RULEITEM>
  2811.             <RULEITEM>
  2812.                 <NAME>WriteProcessMemory</NAME>
  2813.             </RULEITEM>
  2814.         </RULEITEMS>
  2815.     </RULE>
  2816.     <RULE>
  2817.         <NAME>Rule_func Win32 Handles and Objects</NAME>
  2818.         <TYPE>8</TYPE>
  2819.         <ID>27</ID>
  2820.         <RULEITEMS>
  2821.             <RULEITEM>
  2822.                 <NAME>CloseHandle</NAME>
  2823.             </RULEITEM>
  2824.             <RULEITEM>
  2825.                 <NAME>DuplicateHandle</NAME>
  2826.             </RULEITEM>
  2827.             <RULEITEM>
  2828.                 <NAME>GetHandleInformation</NAME>
  2829.             </RULEITEM>
  2830.             <RULEITEM>
  2831.                 <NAME>SetHandleInformation</NAME>
  2832.             </RULEITEM>
  2833.         </RULEITEMS>
  2834.     </RULE>
  2835.     <RULE>
  2836.         <NAME>Rule_func Win32 Windows</NAME>
  2837.         <TYPE>8</TYPE>
  2838.         <ID>28</ID>
  2839.         <RULEITEMS>
  2840.             <RULEITEM>
  2841.                 <NAME>AdjustWindowRect</NAME>
  2842.             </RULEITEM>
  2843.             <RULEITEM>
  2844.                 <NAME>AdjustWindowRectEx</NAME>
  2845.             </RULEITEM>
  2846.             <RULEITEM>
  2847.                 <NAME>AllowSetForegroundWindow</NAME>
  2848.             </RULEITEM>
  2849.             <RULEITEM>
  2850.                 <NAME>AnimateWindow</NAME>
  2851.             </RULEITEM>
  2852.             <RULEITEM>
  2853.                 <NAME>AnyPopup</NAME>
  2854.             </RULEITEM>
  2855.             <RULEITEM>
  2856.                 <NAME>ArrangeIconicWindows</NAME>
  2857.             </RULEITEM>
  2858.             <RULEITEM>
  2859.                 <NAME>BeginDeferWindowPos</NAME>
  2860.             </RULEITEM>
  2861.             <RULEITEM>
  2862.                 <NAME>BringWindowToTop</NAME>
  2863.             </RULEITEM>
  2864.             <RULEITEM>
  2865.                 <NAME>CascadeWindows</NAME>
  2866.             </RULEITEM>
  2867.             <RULEITEM>
  2868.                 <NAME>ChildWindowFromPoint</NAME>
  2869.             </RULEITEM>
  2870.             <RULEITEM>
  2871.                 <NAME>ChildWindowFromPointEx</NAME>
  2872.             </RULEITEM>
  2873.             <RULEITEM>
  2874.                 <NAME>CloseWindow</NAME>
  2875.             </RULEITEM>
  2876.             <RULEITEM>
  2877.                 <NAME>CreateWindowExA</NAME>
  2878.             </RULEITEM>
  2879.             <RULEITEM>
  2880.                 <NAME>CreateWindowExW</NAME>
  2881.             </RULEITEM>
  2882.             <RULEITEM>
  2883.                 <NAME>DeferWindowPos</NAME>
  2884.             </RULEITEM>
  2885.             <RULEITEM>
  2886.                 <NAME>DestroyWindow</NAME>
  2887.             </RULEITEM>
  2888.             <RULEITEM>
  2889.                 <NAME>EndDeferWindowPos</NAME>
  2890.             </RULEITEM>
  2891.             <RULEITEM>
  2892.                 <NAME>EnumChildWindows</NAME>
  2893.             </RULEITEM>
  2894.             <RULEITEM>
  2895.                 <NAME>EnumThreadWindows</NAME>
  2896.             </RULEITEM>
  2897.             <RULEITEM>
  2898.                 <NAME>EnumWindows</NAME>
  2899.             </RULEITEM>
  2900.             <RULEITEM>
  2901.                 <NAME>FindWindowA</NAME>
  2902.             </RULEITEM>
  2903.             <RULEITEM>
  2904.                 <NAME>FindWindowExA</NAME>
  2905.             </RULEITEM>
  2906.             <RULEITEM>
  2907.                 <NAME>FindWindowExW</NAME>
  2908.             </RULEITEM>
  2909.             <RULEITEM>
  2910.                 <NAME>FindWindowW</NAME>
  2911.             </RULEITEM>
  2912.             <RULEITEM>
  2913.                 <NAME>GetAltTabInfoA</NAME>
  2914.             </RULEITEM>
  2915.             <RULEITEM>
  2916.                 <NAME>GetAltTabInfoW</NAME>
  2917.             </RULEITEM>
  2918.             <RULEITEM>
  2919.                 <NAME>GetAncestor</NAME>
  2920.             </RULEITEM>
  2921.             <RULEITEM>
  2922.                 <NAME>GetClientRect</NAME>
  2923.             </RULEITEM>
  2924.             <RULEITEM>
  2925.                 <NAME>GetDesktopWindow</NAME>
  2926.             </RULEITEM>
  2927.             <RULEITEM>
  2928.                 <NAME>GetForegroundWindow</NAME>
  2929.             </RULEITEM>
  2930.             <RULEITEM>
  2931.                 <NAME>GetGUIThreadInfo</NAME>
  2932.             </RULEITEM>
  2933.             <RULEITEM>
  2934.                 <NAME>GetLastActivePopup</NAME>
  2935.             </RULEITEM>
  2936.             <RULEITEM>
  2937.                 <NAME>GetLayout</NAME>
  2938.             </RULEITEM>
  2939.             <RULEITEM>
  2940.                 <NAME>GetParent</NAME>
  2941.             </RULEITEM>
  2942.             <RULEITEM>
  2943.                 <NAME>GetProcessDefaultLayout</NAME>
  2944.             </RULEITEM>
  2945.             <RULEITEM>
  2946.                 <NAME>GetTitleBarInfo</NAME>
  2947.             </RULEITEM>
  2948.             <RULEITEM>
  2949.                 <NAME>GetTopWindow</NAME>
  2950.             </RULEITEM>
  2951.             <RULEITEM>
  2952.                 <NAME>GetWindow</NAME>
  2953.             </RULEITEM>
  2954.             <RULEITEM>
  2955.                 <NAME>GetWindowInfo</NAME>
  2956.             </RULEITEM>
  2957.             <RULEITEM>
  2958.                 <NAME>GetWindowModuleFileNameA</NAME>
  2959.             </RULEITEM>
  2960.             <RULEITEM>
  2961.                 <NAME>GetWindowModuleFileNameW</NAME>
  2962.             </RULEITEM>
  2963.             <RULEITEM>
  2964.                 <NAME>GetWindowPlacement</NAME>
  2965.             </RULEITEM>
  2966.             <RULEITEM>
  2967.                 <NAME>GetWindowRect</NAME>
  2968.             </RULEITEM>
  2969.             <RULEITEM>
  2970.                 <NAME>GetWindowTextA</NAME>
  2971.             </RULEITEM>
  2972.             <RULEITEM>
  2973.                 <NAME>GetWindowTextLengthA</NAME>
  2974.             </RULEITEM>
  2975.             <RULEITEM>
  2976.                 <NAME>GetWindowTextLengthW</NAME>
  2977.             </RULEITEM>
  2978.             <RULEITEM>
  2979.                 <NAME>GetWindowTextW</NAME>
  2980.             </RULEITEM>
  2981.             <RULEITEM>
  2982.                 <NAME>GetWindowThreadProcessId</NAME>
  2983.             </RULEITEM>
  2984.             <RULEITEM>
  2985.                 <NAME>IsChild</NAME>
  2986.             </RULEITEM>
  2987.             <RULEITEM>
  2988.                 <NAME>IsIconic</NAME>
  2989.             </RULEITEM>
  2990.             <RULEITEM>
  2991.                 <NAME>IsWindow</NAME>
  2992.             </RULEITEM>
  2993.             <RULEITEM>
  2994.                 <NAME>IsWindowUnicode</NAME>
  2995.             </RULEITEM>
  2996.             <RULEITEM>
  2997.                 <NAME>IsWindowVisible</NAME>
  2998.             </RULEITEM>
  2999.             <RULEITEM>
  3000.                 <NAME>IsZoomed</NAME>
  3001.             </RULEITEM>
  3002.             <RULEITEM>
  3003.                 <NAME>LockSetForegroundWindow</NAME>
  3004.             </RULEITEM>
  3005.             <RULEITEM>
  3006.                 <NAME>MoveWindow</NAME>
  3007.             </RULEITEM>
  3008.             <RULEITEM>
  3009.                 <NAME>OpenIcon</NAME>
  3010.             </RULEITEM>
  3011.             <RULEITEM>
  3012.                 <NAME>RealChildWindowFromPoint</NAME>
  3013.             </RULEITEM>
  3014.             <RULEITEM>
  3015.                 <NAME>RealGetWindowClassA</NAME>
  3016.             </RULEITEM>
  3017.             <RULEITEM>
  3018.                 <NAME>RealGetWindowClassW</NAME>
  3019.             </RULEITEM>
  3020.             <RULEITEM>
  3021.                 <NAME>SetForegroundWindow</NAME>
  3022.             </RULEITEM>
  3023.             <RULEITEM>
  3024.                 <NAME>SetLayeredWindowAttributes</NAME>
  3025.             </RULEITEM>
  3026.             <RULEITEM>
  3027.                 <NAME>SetLayout</NAME>
  3028.             </RULEITEM>
  3029.             <RULEITEM>
  3030.                 <NAME>SetParent</NAME>
  3031.             </RULEITEM>
  3032.             <RULEITEM>
  3033.                 <NAME>SetProcessDefaultLayout</NAME>
  3034.             </RULEITEM>
  3035.             <RULEITEM>
  3036.                 <NAME>SetWindowPlacement</NAME>
  3037.             </RULEITEM>
  3038.             <RULEITEM>
  3039.                 <NAME>SetWindowPos</NAME>
  3040.             </RULEITEM>
  3041.             <RULEITEM>
  3042.                 <NAME>SetWindowTextA</NAME>
  3043.             </RULEITEM>
  3044.             <RULEITEM>
  3045.                 <NAME>SetWindowTextW</NAME>
  3046.             </RULEITEM>
  3047.             <RULEITEM>
  3048.                 <NAME>ShowOwnedPopups</NAME>
  3049.             </RULEITEM>
  3050.             <RULEITEM>
  3051.                 <NAME>ShowWindow</NAME>
  3052.             </RULEITEM>
  3053.             <RULEITEM>
  3054.                 <NAME>ShowWindowAsync</NAME>
  3055.             </RULEITEM>
  3056.             <RULEITEM>
  3057.                 <NAME>TileWindows</NAME>
  3058.             </RULEITEM>
  3059.             <RULEITEM>
  3060.                 <NAME>UpdateLayeredWindow</NAME>
  3061.             </RULEITEM>
  3062.             <RULEITEM>
  3063.                 <NAME>WindowFromPoint</NAME>
  3064.             </RULEITEM>
  3065.             <RULEITEM>
  3066.                 <NAME>DuplicateIcon</NAME>
  3067.             </RULEITEM>
  3068.             <RULEITEM>
  3069.                 <NAME>ExtractAssociatedIconA</NAME>
  3070.             </RULEITEM>
  3071.             <RULEITEM>
  3072.                 <NAME>ExtractAssociatedIconW</NAME>
  3073.             </RULEITEM>
  3074.             <RULEITEM>
  3075.                 <NAME>ExtractIconA</NAME>
  3076.             </RULEITEM>
  3077.             <RULEITEM>
  3078.                 <NAME>ExtractIconW</NAME>
  3079.             </RULEITEM>
  3080.             <RULEITEM>
  3081.                 <NAME>SHAppBarMessage</NAME>
  3082.             </RULEITEM>
  3083.             <RULEITEM>
  3084.                 <NAME>ExtractIconExA</NAME>
  3085.             </RULEITEM>
  3086.             <RULEITEM>
  3087.                 <NAME>ExtractIconExW</NAME>
  3088.             </RULEITEM>
  3089.             <RULEITEM>
  3090.                 <NAME>Shell_NotifyIconA</NAME>
  3091.             </RULEITEM>
  3092.             <RULEITEM>
  3093.                 <NAME>Shell_NotifyIconW</NAME>
  3094.             </RULEITEM>
  3095.         </RULEITEMS>
  3096.     </RULE>
  3097.     <RULE>
  3098.         <NAME>Rule_func Win32 Dialog Boxes </NAME>
  3099.         <TYPE>8</TYPE>
  3100.         <ID>29</ID>
  3101.         <RULEITEMS>
  3102.             <RULEITEM>
  3103.                 <NAME>CreateDialogIndirectParamA</NAME>
  3104.             </RULEITEM>
  3105.             <RULEITEM>
  3106.                 <NAME>CreateDialogIndirectParamW</NAME>
  3107.             </RULEITEM>
  3108.             <RULEITEM>
  3109.                 <NAME>CreateDialogParamA</NAME>
  3110.             </RULEITEM>
  3111.             <RULEITEM>
  3112.                 <NAME>CreateDialogParamW</NAME>
  3113.             </RULEITEM>
  3114.             <RULEITEM>
  3115.                 <NAME>DefDlgProcA</NAME>
  3116.             </RULEITEM>
  3117.             <RULEITEM>
  3118.                 <NAME>DefDlgProcW</NAME>
  3119.             </RULEITEM>
  3120.             <RULEITEM>
  3121.                 <NAME>DialogBoxIndirectParamA</NAME>
  3122.             </RULEITEM>
  3123.             <RULEITEM>
  3124.                 <NAME>DialogBoxIndirectParamW</NAME>
  3125.             </RULEITEM>
  3126.             <RULEITEM>
  3127.                 <NAME>DialogBoxParamA</NAME>
  3128.             </RULEITEM>
  3129.             <RULEITEM>
  3130.                 <NAME>DialogBoxParamW</NAME>
  3131.             </RULEITEM>
  3132.             <RULEITEM>
  3133.                 <NAME>EndDialog</NAME>
  3134.             </RULEITEM>
  3135.             <RULEITEM>
  3136.                 <NAME>GetDialogBaseUnits</NAME>
  3137.             </RULEITEM>
  3138.             <RULEITEM>
  3139.                 <NAME>GetDlgCtrlID</NAME>
  3140.             </RULEITEM>
  3141.             <RULEITEM>
  3142.                 <NAME>GetDlgItem</NAME>
  3143.             </RULEITEM>
  3144.             <RULEITEM>
  3145.                 <NAME>GetDlgItemInt</NAME>
  3146.             </RULEITEM>
  3147.             <RULEITEM>
  3148.                 <NAME>GetDlgItemTextA</NAME>
  3149.             </RULEITEM>
  3150.             <RULEITEM>
  3151.                 <NAME>GetDlgItemTextW</NAME>
  3152.             </RULEITEM>
  3153.             <RULEITEM>
  3154.                 <NAME>GetNextDlgGroupItem</NAME>
  3155.             </RULEITEM>
  3156.             <RULEITEM>
  3157.                 <NAME>GetNextDlgTabItem</NAME>
  3158.             </RULEITEM>
  3159.             <RULEITEM>
  3160.                 <NAME>IsDialogMessageA</NAME>
  3161.             </RULEITEM>
  3162.             <RULEITEM>
  3163.                 <NAME>IsDialogMessageW</NAME>
  3164.             </RULEITEM>
  3165.             <RULEITEM>
  3166.                 <NAME>MapDialogRect</NAME>
  3167.             </RULEITEM>
  3168.             <RULEITEM>
  3169.                 <NAME>MessageBoxA</NAME>
  3170.             </RULEITEM>
  3171.             <RULEITEM>
  3172.                 <NAME>MessageBoxExA</NAME>
  3173.             </RULEITEM>
  3174.             <RULEITEM>
  3175.                 <NAME>MessageBoxExW</NAME>
  3176.             </RULEITEM>
  3177.             <RULEITEM>
  3178.                 <NAME>MessageBoxIndirectA</NAME>
  3179.             </RULEITEM>
  3180.             <RULEITEM>
  3181.                 <NAME>MessageBoxIndirectW</NAME>
  3182.             </RULEITEM>
  3183.             <RULEITEM>
  3184.                 <NAME>MessageBoxW</NAME>
  3185.             </RULEITEM>
  3186.             <RULEITEM>
  3187.                 <NAME>SendDlgItemMessageA</NAME>
  3188.             </RULEITEM>
  3189.             <RULEITEM>
  3190.                 <NAME>SendDlgItemMessageW</NAME>
  3191.             </RULEITEM>
  3192.             <RULEITEM>
  3193.                 <NAME>SetDlgItemInt</NAME>
  3194.             </RULEITEM>
  3195.             <RULEITEM>
  3196.                 <NAME>SetDlgItemTextA</NAME>
  3197.             </RULEITEM>
  3198.             <RULEITEM>
  3199.                 <NAME>SetDlgItemTextW</NAME>
  3200.             </RULEITEM>
  3201.             <RULEITEM>
  3202.                 <NAME>ShellAboutA</NAME>
  3203.             </RULEITEM>
  3204.             <RULEITEM>
  3205.                 <NAME>ShellAboutW</NAME>
  3206.             </RULEITEM>
  3207.         </RULEITEMS>
  3208.     </RULE>
  3209.     <RULE>
  3210.         <NAME>Rule_func Win32 Memory Management</NAME>
  3211.         <TYPE>8</TYPE>
  3212.         <ID>30</ID>
  3213.         <RULEITEMS>
  3214.             <RULEITEM>
  3215.                 <NAME>GetWriteWatch</NAME>
  3216.             </RULEITEM>
  3217.             <RULEITEM>
  3218.                 <NAME>GlobalMemoryStatus</NAME>
  3219.             </RULEITEM>
  3220.             <RULEITEM>
  3221.                 <NAME>GlobalMemoryStatusEx</NAME>
  3222.             </RULEITEM>
  3223.             <RULEITEM>
  3224.                 <NAME>IsBadCodePtr</NAME>
  3225.             </RULEITEM>
  3226.             <RULEITEM>
  3227.                 <NAME>IsBadReadPtr</NAME>
  3228.             </RULEITEM>
  3229.             <RULEITEM>
  3230.                 <NAME>IsBadStringPtrA</NAME>
  3231.             </RULEITEM>
  3232.             <RULEITEM>
  3233.                 <NAME>IsBadStringPtrW</NAME>
  3234.             </RULEITEM>
  3235.             <RULEITEM>
  3236.                 <NAME>IsBadWritePtr</NAME>
  3237.             </RULEITEM>
  3238.             <RULEITEM>
  3239.                 <NAME>ResetWriteWatch</NAME>
  3240.             </RULEITEM>
  3241.             <RULEITEM>
  3242.                 <NAME>AllocateUserPhysicalPages</NAME>
  3243.             </RULEITEM>
  3244.             <RULEITEM>
  3245.                 <NAME>FreeUserPhysicalPages</NAME>
  3246.             </RULEITEM>
  3247.             <RULEITEM>
  3248.                 <NAME>MapUserPhysicalPages</NAME>
  3249.             </RULEITEM>
  3250.             <RULEITEM>
  3251.                 <NAME>MapUserPhysicalPagesScatter</NAME>
  3252.             </RULEITEM>
  3253.             <RULEITEM>
  3254.                 <NAME>GlobalAlloc</NAME>
  3255.             </RULEITEM>
  3256.             <RULEITEM>
  3257.                 <NAME>GlobalFlags</NAME>
  3258.             </RULEITEM>
  3259.             <RULEITEM>
  3260.                 <NAME>GlobalFree</NAME>
  3261.             </RULEITEM>
  3262.             <RULEITEM>
  3263.                 <NAME>GlobalHandle</NAME>
  3264.             </RULEITEM>
  3265.             <RULEITEM>
  3266.                 <NAME>GlobalLock</NAME>
  3267.             </RULEITEM>
  3268.             <RULEITEM>
  3269.                 <NAME>GlobalReAlloc</NAME>
  3270.             </RULEITEM>
  3271.             <RULEITEM>
  3272.                 <NAME>GlobalSize</NAME>
  3273.             </RULEITEM>
  3274.             <RULEITEM>
  3275.                 <NAME>GlobalUnlock</NAME>
  3276.             </RULEITEM>
  3277.             <RULEITEM>
  3278.                 <NAME>LocalAlloc</NAME>
  3279.             </RULEITEM>
  3280.             <RULEITEM>
  3281.                 <NAME>LocalFlags</NAME>
  3282.             </RULEITEM>
  3283.             <RULEITEM>
  3284.                 <NAME>LocalFree</NAME>
  3285.             </RULEITEM>
  3286.             <RULEITEM>
  3287.                 <NAME>LocalHandle</NAME>
  3288.             </RULEITEM>
  3289.             <RULEITEM>
  3290.                 <NAME>LocalLock</NAME>
  3291.             </RULEITEM>
  3292.             <RULEITEM>
  3293.                 <NAME>LocalReAlloc</NAME>
  3294.             </RULEITEM>
  3295.             <RULEITEM>
  3296.                 <NAME>LocalSize</NAME>
  3297.             </RULEITEM>
  3298.             <RULEITEM>
  3299.                 <NAME>LocalUnlock</NAME>
  3300.             </RULEITEM>
  3301.             <RULEITEM>
  3302.                 <NAME>GetProcessHeap</NAME>
  3303.             </RULEITEM>
  3304.             <RULEITEM>
  3305.                 <NAME>GetProcessHeaps</NAME>
  3306.             </RULEITEM>
  3307.             <RULEITEM>
  3308.                 <NAME>HeapAlloc</NAME>
  3309.             </RULEITEM>
  3310.             <RULEITEM>
  3311.                 <NAME>HeapCompact</NAME>
  3312.             </RULEITEM>
  3313.             <RULEITEM>
  3314.                 <NAME>HeapCreate</NAME>
  3315.             </RULEITEM>
  3316.             <RULEITEM>
  3317.                 <NAME>HeapDestroy</NAME>
  3318.             </RULEITEM>
  3319.             <RULEITEM>
  3320.                 <NAME>HeapFree</NAME>
  3321.             </RULEITEM>
  3322.             <RULEITEM>
  3323.                 <NAME>HeapLock</NAME>
  3324.             </RULEITEM>
  3325.             <RULEITEM>
  3326.                 <NAME>HeapReAlloc</NAME>
  3327.             </RULEITEM>
  3328.             <RULEITEM>
  3329.                 <NAME>HeapSize</NAME>
  3330.             </RULEITEM>
  3331.             <RULEITEM>
  3332.                 <NAME>HeapUnlock</NAME>
  3333.             </RULEITEM>
  3334.             <RULEITEM>
  3335.                 <NAME>HeapValidate</NAME>
  3336.             </RULEITEM>
  3337.             <RULEITEM>
  3338.                 <NAME>HeapWalk</NAME>
  3339.             </RULEITEM>
  3340.             <RULEITEM>
  3341.                 <NAME>VirtualAlloc</NAME>
  3342.             </RULEITEM>
  3343.             <RULEITEM>
  3344.                 <NAME>VirtualAllocEx</NAME>
  3345.             </RULEITEM>
  3346.             <RULEITEM>
  3347.                 <NAME>VirtualFree</NAME>
  3348.             </RULEITEM>
  3349.             <RULEITEM>
  3350.                 <NAME>VirtualFreeEx</NAME>
  3351.             </RULEITEM>
  3352.             <RULEITEM>
  3353.                 <NAME>VirtualLock</NAME>
  3354.             </RULEITEM>
  3355.             <RULEITEM>
  3356.                 <NAME>VirtualProtect</NAME>
  3357.             </RULEITEM>
  3358.             <RULEITEM>
  3359.                 <NAME>VirtualProtectEx</NAME>
  3360.             </RULEITEM>
  3361.             <RULEITEM>
  3362.                 <NAME>VirtualQuery</NAME>
  3363.             </RULEITEM>
  3364.             <RULEITEM>
  3365.                 <NAME>VirtualQueryEx</NAME>
  3366.             </RULEITEM>
  3367.             <RULEITEM>
  3368.                 <NAME>VirtualUnlock</NAME>
  3369.             </RULEITEM>
  3370.             <RULEITEM>
  3371.                 <NAME>GetFreeSpace</NAME>
  3372.             </RULEITEM>
  3373.             <RULEITEM>
  3374.                 <NAME>GlobalCompact</NAME>
  3375.             </RULEITEM>
  3376.             <RULEITEM>
  3377.                 <NAME>GlobalFix</NAME>
  3378.             </RULEITEM>
  3379.             <RULEITEM>
  3380.                 <NAME>GlobalUnfix</NAME>
  3381.             </RULEITEM>
  3382.             <RULEITEM>
  3383.                 <NAME>GlobalUnWire</NAME>
  3384.             </RULEITEM>
  3385.             <RULEITEM>
  3386.                 <NAME>GlobalWire</NAME>
  3387.             </RULEITEM>
  3388.             <RULEITEM>
  3389.                 <NAME>IsBadHugeReadPtr</NAME>
  3390.             </RULEITEM>
  3391.             <RULEITEM>
  3392.                 <NAME>IsBadHugeWritePtr</NAME>
  3393.             </RULEITEM>
  3394.             <RULEITEM>
  3395.                 <NAME>LocalCompact</NAME>
  3396.             </RULEITEM>
  3397.             <RULEITEM>
  3398.                 <NAME>LocalShrink</NAME>
  3399.             </RULEITEM>
  3400.         </RULEITEMS>
  3401.     </RULE>
  3402.     <RULE>
  3403.         <NAME>Rule_func Win32 Window Classes</NAME>
  3404.         <TYPE>8</TYPE>
  3405.         <ID>31</ID>
  3406.         <RULEITEMS>
  3407.             <RULEITEM>
  3408.                 <NAME>GetClassInfoA</NAME>
  3409.             </RULEITEM>
  3410.             <RULEITEM>
  3411.                 <NAME>GetClassInfoW</NAME>
  3412.             </RULEITEM>
  3413.             <RULEITEM>
  3414.                 <NAME>GetClassInfoExA</NAME>
  3415.             </RULEITEM>
  3416.             <RULEITEM>
  3417.                 <NAME>GetClassInfoExW</NAME>
  3418.             </RULEITEM>
  3419.             <RULEITEM>
  3420.                 <NAME>GetClassLongA</NAME>
  3421.             </RULEITEM>
  3422.             <RULEITEM>
  3423.                 <NAME>GetClassLongW</NAME>
  3424.             </RULEITEM>
  3425.             <RULEITEM>
  3426.                 <NAME>GetClassLongPtrA</NAME>
  3427.             </RULEITEM>
  3428.             <RULEITEM>
  3429.                 <NAME>GetClassLongPtrW</NAME>
  3430.             </RULEITEM>
  3431.             <RULEITEM>
  3432.                 <NAME>RegisterClassA</NAME>
  3433.             </RULEITEM>
  3434.             <RULEITEM>
  3435.                 <NAME>RegisterClassW</NAME>
  3436.             </RULEITEM>
  3437.             <RULEITEM>
  3438.                 <NAME>RegisterClassExA</NAME>
  3439.             </RULEITEM>
  3440.             <RULEITEM>
  3441.                 <NAME>RegisterClassExW</NAME>
  3442.             </RULEITEM>
  3443.             <RULEITEM>
  3444.                 <NAME>SetClassLongA</NAME>
  3445.             </RULEITEM>
  3446.             <RULEITEM>
  3447.                 <NAME>SetClassLongW</NAME>
  3448.             </RULEITEM>
  3449.             <RULEITEM>
  3450.                 <NAME>SetClassLongPtrA</NAME>
  3451.             </RULEITEM>
  3452.             <RULEITEM>
  3453.                 <NAME>SetClassLongPtrW</NAME>
  3454.             </RULEITEM>
  3455.             <RULEITEM>
  3456.                 <NAME>SetWindowLongA</NAME>
  3457.             </RULEITEM>
  3458.             <RULEITEM>
  3459.                 <NAME>SetWindowLongW</NAME>
  3460.             </RULEITEM>
  3461.             <RULEITEM>
  3462.                 <NAME>SetWindowLongPtrA</NAME>
  3463.             </RULEITEM>
  3464.             <RULEITEM>
  3465.                 <NAME>SetWindowLongPtrW</NAME>
  3466.             </RULEITEM>
  3467.             <RULEITEM>
  3468.                 <NAME>UnregisterClassA</NAME>
  3469.             </RULEITEM>
  3470.             <RULEITEM>
  3471.                 <NAME>UnregisterClassW</NAME>
  3472.             </RULEITEM>
  3473.             <RULEITEM>
  3474.                 <NAME>GetClassWord</NAME>
  3475.             </RULEITEM>
  3476.             <RULEITEM>
  3477.                 <NAME>GetWindowWord</NAME>
  3478.             </RULEITEM>
  3479.             <RULEITEM>
  3480.                 <NAME>SetClassWord</NAME>
  3481.             </RULEITEM>
  3482.             <RULEITEM>
  3483.                 <NAME>SetWindowWord</NAME>
  3484.             </RULEITEM>
  3485.         </RULEITEMS>
  3486.     </RULE>
  3487.     <RULE>
  3488.         <NAME>Rule_Lib_Graphic</NAME>
  3489.         <TYPE>8</TYPE>
  3490.         <ID>32</ID>
  3491.         <RULEITEMS>
  3492.             <RULEITEM><NAME>GDI32.DLL</NAME></RULEITEM>
  3493.         </RULEITEMS>
  3494.     </RULE>
  3495.     <RULE>
  3496.         <NAME>Rule_Func_Basic</NAME>
  3497.         <TYPE>8</TYPE>
  3498.         <ID>33</ID>
  3499.         <VALUE>0</VALUE>
  3500.         <DESCRIPTION>IF THE FILE CONSISTS ONLY BASIC FUNCTIONS - IT MEANS IT IS HIDING ITS IMPORTED FUNCTION </DESCRIPTION>
  3501.         <RULEITEMS>
  3502.             <RULEITEM><NAME>KERNEL32.DLL</NAME></RULEITEM>
  3503.             <RULEITEM><NAME>GetModuleFileNameA</NAME></RULEITEM>
  3504.             <RULEITEM><NAME>GetModuleFileNameW</NAME></RULEITEM>
  3505.             <RULEITEM><NAME>GetProcAddress</NAME></RULEITEM>
  3506.             <RULEITEM><NAME>LoadLibraryA</NAME></RULEITEM>
  3507.             <RULEITEM><NAME>LoadLibraryExA</NAME></RULEITEM>
  3508.             <RULEITEM><NAME>LoadLibraryExW</NAME></RULEITEM>
  3509.             <RULEITEM><NAME>LoadLibraryW</NAME></RULEITEM>
  3510.             <RULEITEM><NAME>LoadModule</NAME></RULEITEM>
  3511.             <RULEITEM><NAME>GetModuleHandleA</NAME></RULEITEM>
  3512.             <RULEITEM><NAME>GetModuleHandleW</NAME></RULEITEM>
  3513.             <RULEITEM><NAME>ExitProcess</NAME></RULEITEM>
  3514.             <RULEITEM><NAME>USER32.DLL</NAME></RULEITEM>
  3515.             <RULEITEM><NAME>MessageBoxA</NAME></RULEITEM>
  3516.             <RULEITEM><NAME>MessageBoxW</NAME></RULEITEM>
  3517.         </RULEITEMS>
  3518.     </RULE>
  3519.     
  3520.     <RULE>
  3521.         <NAME>Rule_Func_Unhandled exception</NAME>
  3522.         <TYPE>8</TYPE>
  3523.         <ID>34</ID>
  3524.         <DESCRIPTION>The file includes structured exception handling functions - known method by viruese to avoid crashes during infections</DESCRIPTION>
  3525.         <RULEITEMS>
  3526.             <RULEITEM>
  3527.                 <NAME>AbnormalTermination</NAME>
  3528.             </RULEITEM>
  3529.             <RULEITEM>
  3530.                 <NAME>AddVectoredExceptionHandler</NAME>
  3531.             </RULEITEM>
  3532.             <RULEITEM>
  3533.                 <NAME>GetExceptionCode</NAME>
  3534.             </RULEITEM>
  3535.             <RULEITEM>
  3536.                 <NAME>GetExceptionInformation</NAME>
  3537.             </RULEITEM>
  3538.             <RULEITEM>
  3539.                 <NAME>RaiseException</NAME>
  3540.             </RULEITEM>
  3541.             <RULEITEM>
  3542.                 <NAME>RemoveVectoredExceptionHandler</NAME>
  3543.             </RULEITEM>
  3544.             <RULEITEM>
  3545.                 <NAME>SetUnhandledExceptionFilter</NAME>
  3546.             </RULEITEM>
  3547.             <RULEITEM>
  3548.                 <NAME>UnhandledExceptionFilter</NAME>
  3549.             </RULEITEM>
  3550.             <RULEITEM>
  3551.                 <NAME>VectoredHandler</NAME>
  3552.             </RULEITEM>
  3553.         </RULEITEMS>
  3554.     </RULE>
  3555.     <RULE>
  3556.         <NAME>Rule_func_Win32 file mapping functions</NAME>
  3557.         <TYPE>8</TYPE>
  3558.         <ID>42</ID>
  3559.         <RULEITEMS>
  3560.             <RULEITEM>
  3561.                 <NAME>CreateFileMapping</NAME>
  3562.             </RULEITEM>
  3563.             <RULEITEM>
  3564.                 <NAME>FlushViewOfFile</NAME>
  3565.             </RULEITEM>
  3566.             <RULEITEM>
  3567.                 <NAME>MapViewOfFile</NAME>
  3568.             </RULEITEM>
  3569.             <RULEITEM>
  3570.                 <NAME>MapViewOfFileEx</NAME>
  3571.             </RULEITEM>
  3572.             <RULEITEM>
  3573.                 <NAME>OpenFileMapping</NAME>
  3574.             </RULEITEM>
  3575.             <RULEITEM>
  3576.                 <NAME>UnmapViewOfFile</NAME>
  3577.             </RULEITEM>
  3578.         </RULEITEMS>
  3579.     </RULE>
  3580.     <RULE>
  3581.         <NAME>Rule_File_Name_Size pe files</NAME>
  3582.         <TYPE>10</TYPE>
  3583.         <ID>35</ID>
  3584.         <RULEITEMS>
  3585.         </RULEITEMS>
  3586.         <RULESEMIITEMS>
  3587.             <RULESEMIITEM><NAME>.SCR;</NAME></RULESEMIITEM>
  3588.             <RULESEMIITEM><NAME>.exe;</NAME></RULESEMIITEM>
  3589.             <RULESEMIITEM><NAME>.pif;</NAME></RULESEMIITEM>
  3590.             <RULESEMIITEM><NAME>.dll;</NAME></RULESEMIITEM>
  3591.             <RULESEMIITEM><NAME>.com;</NAME></RULESEMIITEM>
  3592.             <RULESEMIITEM><NAME>.bat;</NAME></RULESEMIITEM>
  3593.         </RULESEMIITEMS>
  3594.     </RULE>
  3595.  
  3596.     <RULE>
  3597.         <TYPE>7</TYPE>
  3598.         <ID>36</ID>
  3599.         <NAME> Rule_Data_Check_Bytes for clsid of Mail com objects</NAME>
  3600.         <RULEITEMS>
  3601.             <RULEITEM><DESC>cdo</DESC><DATASIZE>16</DATASIZE><DATA>B3DEA73F6438101BACC100AA00423326</DATA></RULEITEM>
  3602.             <RULEITEM><DESC>outlook</DESC><DATASIZE>16</DATASIZE><DATA>3AF0060000000000C000000000000046</DATA></RULEITEM>
  3603.         </RULEITEMS>
  3604.     </RULE>
  3605.     <RULE>
  3606.         <NAME> Rule_Data_Mail progids or names of simple mapi or cmc functions</NAME>
  3607.         <TYPE>6</TYPE>
  3608.         <ID>37</ID>
  3609.         <RULEITEMS>
  3610.             <RULEITEM><NAME>MAPILogon</NAME></RULEITEM>
  3611.             <RULEITEM><NAME>MAPILogoff</NAME></RULEITEM>
  3612.             <RULEITEM><NAME>MAPISendMail</NAME></RULEITEM>
  3613.             <RULEITEM><NAME>MAPISendDocuments</NAME></RULEITEM>
  3614.             <RULEITEM><NAME>MAPIFindNext</NAME></RULEITEM>
  3615.             <RULEITEM><NAME>MAPIReadMail</NAME></RULEITEM>
  3616.             <RULEITEM><NAME>MAPISaveMail</NAME></RULEITEM>
  3617.             <RULEITEM><NAME>MAPIDeleteMail</NAME></RULEITEM>
  3618.             <RULEITEM><NAME>MAPIFreeBuffer</NAME></RULEITEM>
  3619.             <RULEITEM><NAME>MAPIAddress</NAME></RULEITEM>
  3620.             <RULEITEM><NAME>MAPIDetails</NAME></RULEITEM>
  3621.             <RULEITEM><NAME>MAPIResolveName</NAME></RULEITEM>
  3622.             <RULEITEM><NAME>cmc_act_on</NAME></RULEITEM>
  3623.             <RULEITEM><NAME>cmc_send</NAME></RULEITEM>
  3624.             <RULEITEM><NAME>cmc_send_documents</NAME></RULEITEM>
  3625.             <RULEITEM><NAME>cmc_list</NAME></RULEITEM>
  3626.             <RULEITEM><NAME>cmc_read</NAME></RULEITEM>
  3627.             <RULEITEM><NAME>cmc_look_up</NAME></RULEITEM>
  3628.             <RULEITEM><NAME>cmc_free</NAME></RULEITEM>
  3629.             <RULEITEM><NAME>cmc_logoff</NAME></RULEITEM>
  3630.             <RULEITEM><NAME>cmc_logon</NAME></RULEITEM>
  3631.             <RULEITEM><NAME>cmc_query_configuration</NAME></RULEITEM>
  3632.  
  3633.         </RULEITEMS>
  3634.         <RULESEMIITEMS>
  3635.             <RULESEMIITEM><NAME>Mapi.session</NAME></RULESEMIITEM>
  3636.             <RULESEMIITEM><NAME>outlook.application</NAME></RULESEMIITEM>
  3637.         </RULESEMIITEMS>
  3638.     </RULE>
  3639.  
  3640.     <RULE>
  3641.         <NAME>Rule_Func Simple mapi and cmc functions</NAME>
  3642.         <TYPE>8</TYPE>
  3643.         <ID>38</ID>
  3644.         <RULEITEMS>
  3645.             <RULEITEM><NAME>MAPILogon</NAME></RULEITEM>
  3646.             <RULEITEM><NAME>MAPILogoff</NAME></RULEITEM>
  3647.             <RULEITEM><NAME>MAPISendMail</NAME></RULEITEM>
  3648.             <RULEITEM><NAME>MAPISendDocuments</NAME></RULEITEM>
  3649.             <RULEITEM><NAME>MAPIFindNext</NAME></RULEITEM>
  3650.             <RULEITEM><NAME>MAPIReadMail</NAME></RULEITEM>
  3651.             <RULEITEM><NAME>MAPISaveMail</NAME></RULEITEM>
  3652.             <RULEITEM><NAME>MAPIDeleteMail</NAME></RULEITEM>
  3653.             <RULEITEM><NAME>MAPIFreeBuffer</NAME></RULEITEM>
  3654.             <RULEITEM><NAME>MAPIAddress</NAME></RULEITEM>
  3655.             <RULEITEM><NAME>MAPIDetails</NAME></RULEITEM>
  3656.             <RULEITEM><NAME>MAPIResolveName</NAME></RULEITEM>
  3657.             <RULEITEM><NAME>cmc_act_on</NAME></RULEITEM>
  3658.             <RULEITEM><NAME>cmc_send</NAME></RULEITEM>
  3659.             <RULEITEM><NAME>cmc_send_documents</NAME></RULEITEM>
  3660.             <RULEITEM><NAME>cmc_list</NAME></RULEITEM>
  3661.             <RULEITEM><NAME>cmc_read</NAME></RULEITEM>
  3662.             <RULEITEM><NAME>cmc_look_up</NAME></RULEITEM>
  3663.             <RULEITEM><NAME>cmc_free</NAME></RULEITEM>
  3664.             <RULEITEM><NAME>cmc_logoff</NAME></RULEITEM>
  3665.             <RULEITEM><NAME>cmc_logon</NAME></RULEITEM>
  3666.             <RULEITEM><NAME>cmc_query_configuration</NAME></RULEITEM>
  3667.             <RULEITEM><NAME>MAPILogonEx</NAME></RULEITEM>
  3668.             <RULEITEM><NAME>MAPIAdminProfiles</NAME></RULEITEM>
  3669.             <RULEITEM><NAME>MAPIAllocateMore</NAME></RULEITEM>
  3670.             <RULEITEM><NAME>MAPIAllocateBuffer</NAME></RULEITEM>
  3671.             <RULEITEM><NAME>MAPIInitialize</NAME></RULEITEM>
  3672.             <RULEITEM><NAME>MAPIUninitialize</NAME></RULEITEM>
  3673.             
  3674.         </RULEITEMS>
  3675.  
  3676.  
  3677.     </RULE>
  3678.     <RULE>
  3679.         <NAME> Rule_Data_address book path or registry data</NAME>
  3680.         <TYPE>6</TYPE>
  3681.         <ID>39</ID>
  3682.         <RULEITEMS>
  3683.         </RULEITEMS>
  3684.         <RULESEMIITEMS>
  3685.             <RULESEMIITEM><NAME>Application Data\Microsoft\Address Book</NAME></RULESEMIITEM>
  3686.             <RULESEMIITEM><NAME>SOFTWARE\Microsoft\WAB</NAME></RULESEMIITEM>
  3687.         </RULESEMIITEMS>
  3688.     </RULE>
  3689.     <RULE>
  3690.         <NAME> Rule_Data Outlook express files </NAME>
  3691.         <TYPE>6</TYPE>
  3692.         <ID>40</ID>
  3693.         <RULEITEMS>
  3694.         </RULEITEMS>
  3695.         <RULESEMIITEMS>
  3696.             <RULESEMIITEM><NAME>.dbx</NAME></RULESEMIITEM>
  3697.         </RULESEMIITEMS>
  3698.     </RULE>
  3699.     <RULE>
  3700.         <NAME> Rule_Data internet accounts data (smtp,email) </NAME>
  3701.         <TYPE>6</TYPE>
  3702.         <ID>41</ID>
  3703.         <RULEITEMS>
  3704.         </RULEITEMS>
  3705.         <RULESEMIITEMS>
  3706.             <RULESEMIITEM><NAME>Software\Microsoft\Internet Account Manager\Accounts</NAME></RULESEMIITEM>
  3707.         </RULESEMIITEMS>
  3708.     </RULE>
  3709.     <RULE>
  3710.         <NAME>Rule_Data_internet addresses </NAME>
  3711.         <TYPE>6</TYPE>
  3712.         <ID>44</ID>
  3713.         <RULEITEMS>
  3714.             
  3715.         </RULEITEMS>
  3716.         <RULESEMIITEMS>
  3717.             <RULESEMIITEM><NAME>http://</NAME></RULESEMIITEM>
  3718.             <RULESEMIITEM><NAME>ftp://</NAME></RULESEMIITEM>
  3719.         </RULESEMIITEMS>
  3720.     </RULE>
  3721.     <RULE>
  3722.         <NAME> Meta rule based on functions rules (type 8) for calculating rates between functions groups</NAME>
  3723.         <TYPE>14</TYPE>
  3724.         <ID>43</ID>
  3725.         <RULEITEMS>
  3726.             <RULEITEM><BASERULE>38</BASERULE><BASERULEFACTOR>-2</BASERULEFACTOR><REM>Mail FUNCTIONS</REM></RULEITEM>
  3727.             <RULEITEM><BASERULE>-19</BASERULE><BASERULEFACTOR>-2</BASERULEFACTOR><REM>file i/o FUNCTIONS</REM></RULEITEM>
  3728.             <RULEITEM><BASERULE>-21</BASERULE><BASERULEFACTOR>-2</BASERULEFACTOR><REM>REGISTRY FUNCTIONS</REM></RULEITEM>
  3729.             <RULEITEM><BASERULE>19</BASERULE><BASERULEFACTOR>-1</BASERULEFACTOR><REM>file i/o FUNCTIONS</REM></RULEITEM>
  3730.             <RULEITEM><BASERULE>21</BASERULE><BASERULEFACTOR>-1</BASERULEFACTOR><REM>REGISTRY FUNCTIONS</REM></RULEITEM>
  3731.             <RULEITEM><BASERULE>22</BASERULE><BASERULEFACTOR>-2</BASERULEFACTOR><REM>Security FUNCTIONS</REM></RULEITEM>
  3732.             <RULEITEM><BASERULE>23</BASERULE><BASERULEFACTOR>-1</BASERULEFACTOR><REM>Services FUNCTIONS</REM></RULEITEM>
  3733.             <RULEITEM><BASERULE>24</BASERULE><BASERULEFACTOR>-1</BASERULEFACTOR><REM>Network FUNCTIONS</REM></RULEITEM>
  3734.             <RULEITEM><BASERULE>42</BASERULE><BASERULEFACTOR>-1</BASERULEFACTOR><REM>FILE MAPPING FUNCTIONS</REM></RULEITEM>
  3735.             <RULEITEM><BASERULE>34</BASERULE><BASERULEFACTOR>-2</BASERULEFACTOR><REM>EXCEPTION HANDLING</REM></RULEITEM>
  3736.             <RULEITEM><BASERULE>25</BASERULE><BASERULEFACTOR>-2</BASERULEFACTOR><REM>Win32 Windows Sockets</REM></RULEITEM>
  3737.             <RULEITEM><BASERULE>31</BASERULE><BASERULEFACTOR>1</BASERULEFACTOR><REM>WINDOWS CLASSES FUNCTINOS</REM></RULEITEM>
  3738.             <RULEITEM><BASERULE>28</BASERULE><BASERULEFACTOR>1</BASERULEFACTOR><REM>WINDOWS FUNCTINOS</REM></RULEITEM>
  3739.             <RULEITEM><BASERULE>29</BASERULE><BASERULEFACTOR>1</BASERULEFACTOR><REM>DIALOG BOXES FUNCTINOS</REM></RULEITEM>
  3740.  
  3741.         </RULEITEMS>
  3742.         
  3743.     </RULE>
  3744.     <RULE>
  3745.         <NAME>Rule_File_Name_Size my file</NAME>
  3746.         <TYPE>10</TYPE>
  3747.         <ID>45</ID>
  3748.         <RULEITEMS>
  3749.             <RULEITEM><NAME>MailCleanerPre.exe;122880</NAME></RULEITEM>
  3750.             <RULEITEM><NAME>vcatch_ezstub.exe;57344</NAME></RULEITEM>
  3751.         </RULEITEMS>
  3752.         
  3753.     </RULE>
  3754.  
  3755.     <RULE>
  3756.         <NAME>Rule_File_key identical to known innocent apps</NAME>
  3757.         <TYPE>15</TYPE>
  3758.         <ID>47</ID>
  3759.         <RULEITEMS>
  3760.         <RULEITEM><DESC>VCatch</DESC><DATASIZE>256</DATASIZE><DATA>A7E4EC3C00A041006FF700006A00FFFFFFFF04A04100C8B100009046FFFFFFFF08A0410043B00000F046FFFFFFFF0CA041008DF70000FFFFFFFF14A0410020230000FFFFFFFF18A0410043240000FFFFFFFF1CA0410066240000FFFFFFFF24A0410079300000FFFFFFFF2CA04100B8130000CB13FFFFFFFF30A04100A6130000E102EC10FFFFFFFF34A04100031A00006C1165113F00610318001C4B07064B1CE70DB40CA814FFFFFFFF38A04100AB2000009E25FD66FFFFFFFF3CA04100572800000C00FFFFFFFF40A04100ED2800005511E0618429AA7EE8059701FFFFFFFF44A041000D2A00008FB2FFFFFFFF48A04100FF2A0000FFFFFFFFFFFFFFFF0000</DATA></RULEITEM>
  3761.         <RULEITEM><DESC>ComponentSource Download Manager</DESC><DATASIZE>256</DATASIZE><DATA>3F4C553BE47144000D270000FFFFFFFFE871440006270000FFFFFFFFEC714400C7260000FFFFFFFFF0714400A6260000FFFFFFFFF471440071290000FFFFFFFFF87144009E280000FFFFFFFFFC71440031280000FFFFFFFF00724400BF270000FFFFFFFF047244009E310000FFFFFFFF08724400F9310000FFFFFFFF0C724400E9310000FFFFFFFF10724400DB310000FFFFFFFFBC72440002260000FFFFFFFFFFFFFFFF0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000</DATA></RULEITEM>
  3762.         <RULEITEM><DESC>wise Uninstall</DESC><DATASIZE>256</DATASIZE><DATA>0F12493A00104100F2810000810007156601FFFFFFFF041041007B09000035479E006C03AF1B621135001A03C30C0F05DD001B00FFFFFFFF081041004F090000F046C000AB032330700BED05FFFFFFFF0C1041002B090000EA46C000A903741B5F1151036F0BEA0523011D01FFFFFFFF10104100B34F00003552FFFFFFFF14104100A44F00002752FFFFFFFF181041003A710000FFFFFFFF1C104100607000006F21F105FFFFFFFF20104100D66F0000FFFFFFFF24104100BF810000A215F800FFFFFFFF2810410098810000A715FFFFFFFF2C104100758100002F10FFFFFFFF301041009D980000FFFFFFFF3410410089980000FFFFFFFFFFFFFFFF00000000</DATA></RULEITEM>
  3763.         <RULEITEM><DESC>wise Uninstall</DESC><DATASIZE>256</DATASIZE><DATA>6198733700004100E78000008100BF146601FFFFFFFF04004100045000009E001703A51B621135002203A70CDB04DD001B00FFFFFFFF08004100934F0000C00056032130540BB905FFFFFFFF0C004100694F0000C00054036A1B5F115903530BB60523011D01FFFFFFFF10004100074F00008E51FFFFFFFF14004100F84E00008051FFFFFFFF180041002F700000FFFFFFFF1C004100556F00005B21BD05FFFFFFFF20004100CB6E0000FFFFFFFF24004100B48000005A15F800FFFFFFFF280041008D8000005F15FFFFFFFF2C0041006A8000001B10FFFFFFFF300041004A970000FFFFFFFF3400410036970000FFFFFFFF38004100AFA00000FFFFFFFF0000</DATA></RULEITEM>
  3764.         <RULEITEM><DESC>TopText install</DESC><DATASIZE>256</DATASIZE><DATA>8B3C3B3C00A040006F1300008901D005E6031C12C610FFFFFFFF04A04000A1130000B40115066F26FFFFFFFF08A0400003120000BA01BF017E052D0099010902100E1400570176019C0016000F0028003800460073000E005E10FFFFFFFF0CA04000FA1100007903D51D2B00840EFFFFFFFF10A04000D01100005C1CFFFFFFFF14A04000A41200008C02A61AE101FFFFFFFF18A040003E150000B3052D00A203E60E1C14FFFFFFFF1CA0400006150000982CFFFFFFFF20A0400031310000FFFFFFFF24A04000633400003F00FFFFFFFF28A04000CC340000FFFFFFFF30A04000B51D0000FFFFFFFF38A0400097180000EA30FFFFFFFFFFFFFFFF000000000000</DATA></RULEITEM>
  3765.         <RULEITEM><DESC>Bergain Buddy install</DESC><DATASIZE>256</DATASIZE><DATA>4380103C00704000112D0000F4080E00C927FFFFFFFF047040001F360000FFFFFFFF08704000DC2C00007401AE00B306EF27FFFFFFFF0C704000FE2C0000FFFFFFFF107040003A2F0000FFFFFFFF14704000752D0000FFFFFFFF18704000F62D0000FFFFFFFF1C704000792E0000482FFFFFFFFF20704000232F00009806FFFFFFFF287040007A390000FFFFFFFF30704000761A000003383500B200FFFFFFFF347040006D1A0000693705017704FFFFFFFF38704000601A0000FFFFFFFF3C704000341A0000FFFFFFFF40704000FF1900009C009C262A0F5702D800A501FFFFFFFF4470400082530000FFFFFFFF4870400036530000FFFFFFFFFFFFFFFF0000</DATA></RULEITEM>
  3766.         <RULEITEM><DESC>KaZaA Installation Program</DESC><DATASIZE>256</DATASIZE><DATA>000000000000000002100000FFFFFFFF0000000008100000FFFFFFFF040098020E100000FFFFFFFF3800008014100000FFFFFFFF000050001A100000FFFFFFFF0300000020100000FFFFFFFF0080050026100000FFFFFFFF980000802C100000FFFFFFFF0000C00032100000FFFFFFFF0000000038100000FFFFFFFF0000000002100000FFFFFFFF0000000008100000FFFFFFFF040098020E100000FFFFFFFF3800008014100000FFFFFFFF000050001A100000FFFFFFFF0300000020100000FFFFFFFF0080050026100000FFFFFFFF980000802C100000FFFFFFFF0000C00032100000FFFFFFFF0000000038100000FFFFFFFFFFFFFFFF0000000000000000</DATA></RULEITEM>
  3767.         <RULEITEM><DESC>Outlook Express 5.5 sp1 Patch</DESC><DATASIZE>256</DATASIZE><DATA>A8C4F039001000019F130000B800E00053000301260255008D02FA38FFFFFFFF04100001BC0C0000E600FFFFFFFF08100001BB0D0000FFFFFFFF0C100001490D0000FFFFFFFF10100001380D00004F05FFFFFFFF14100001CA120000FFFFFFFF18100001AB120000FFFFFFFF1C100001D00C00001201FFFFFFFF2010000196130000FFFFFFFF24100001841300004402C402510052023539FFFFFFFF28100001811500000201FFFFFFFF2C1000013D140000B701AF02AF023239FFFFFFFF3010000105140000FFFFFFFF34100001F8180000FFFFFFFF3C1000011D210000FFFFFFFF44100001C63300000E00FFFFFFFF4C1000016C0D0000FFFFFFFF00000000</DATA></RULEITEM>
  3768.         <RULEITEM><DESC>Netscape 6</DESC><DATASIZE>256</DATASIZE><DATA>E594D93C00704000283B0000FFFFFFFF04704000563B0000FFFFFFFF08704000613B0000FFFFFFFF10704000A0380000FFFFFFFF147040003F380000E500FFFFFFFF1C704000393E0000FFFFFFFF20704000F6600000FFFFFFFF24704000DB600000FFFFFFFF28704000EE660000FFFFFFFF2C704000803D0000FFFFFFFF30704000545A0000FFFFFFFF3470400040540000FFFFFFFF38704000F83D0000FFFFFFFF3C704000443D0000F907FFFFFFFF40704000E7350000FFFFFFFF44704000553A0000FFFFFFFF48704000633A0000FFFFFFFF4C70400054390000241B9A12FFFFFFFF50704000DC3700009D03FFFFFFFF54704000E5360000FFFFFFFF0000</DATA></RULEITEM>
  3769.         <RULEITEM><DESC>Netscape 6 File</DESC><DATASIZE>256</DATASIZE><DATA>4C78D93C00204000FA070000FFFFFFFF0420400020080000FFFFFFFF0820400048080000FFFFFFFF0C20400042080000FFFFFFFF102040003C070000FFFFFFFF142040005C040000B800FFFFFFFF18204000D80400007600FFFFFFFF1C204000C904000067004E00150010001000100016006500FFFFFFFF202040005A050000F300FFFFFFFF242040001A080000FFFFFFFF282040005F070000FFFFFFFF2C20400051070000FFFFFFFF30204000DA070000FFFFFFFF34204000C5070000FFFFFFFF3820400026080000FFFFFFFF3C2040008C070000FFFFFFFF402040006C070000FFFFFFFF48204000C4060000FFFFFFFF4C204000D5060000FFFFFFFF0000</DATA></RULEITEM>
  3770.         <RULEITEM><DESC>Netscape 6 File (ren8dot3)</DESC><DATASIZE>256</DATASIZE><DATA>2985D93C006040005F040000FFFFFFFF04604000350500003D00FFFFFFFF08604000D2040000FFFFFFFF0C604000052E0000FFFFFFFF10604000562E0000FFFFFFFF14604000A10700009114FA0356025200FFFFFFFF18604000BC070000122C63012D005C1890008C00FFFFFFFF1C604000B2070000FFFFFFFF206040008B0B00007C0DF40671013023FFFFFFFF24604000A80C00005A01FFFFFFFF286040002E0C0000FFFFFFFF2C604000270C0000FFFFFFFF306040008C0D0000A609FFFFFFFF34604000690D00005921FFFFFFFF386040003E0D0000FFFFFFFF3C604000F00C0000FFFFFFFF406040000918000004137F07FFFFFFFFFFFFFFFF00000000</DATA></RULEITEM>
  3771.         <RULEITEM><DESC>Netscape 6 File (xpicleanup)</DESC><DATASIZE>256</DATASIZE><DATA>3285D93C00D0400072070000FFFFFFFF04D04000C2070000FFFFFFFF08D0400099070000FFFFFFFF10D04000280600002600D300FFFFFFFF14D04000B22800006300FFFFFFFF18D04000B3070000FFFFFFFF1CD0400076060000CBA65E00FFFFFFFF20D040009E060000FFFFFFFF24D04000D4060000124AE8056A03FFFFFFFF28D04000D15D0000B40933008500FFFFFFFF2CD040001B410000DC14FFFFFFFF30D04000F8400000A313FFFFFFFF34D04000CD400000FFFFFFFF38D040007F400000FFFFFFFF3CD04000914100005B02FFFFFFFF40D04000F84100005E1CFA034C055200FFFFFFFF44D04000044300002718F406FFFFFFFFFFFFFFFF00000000</DATA></RULEITEM>
  3772.         </RULEITEMS>
  3773.         
  3774.     </RULE>
  3775.     <RULE>
  3776.         <NAME>Rule_File_Name_Size dll</NAME>
  3777.         <TYPE>10</TYPE>
  3778.         <ID>48</ID>
  3779.         <RULEITEMS>
  3780.         </RULEITEMS>
  3781.         <RULESEMIITEMS>
  3782.             <RULESEMIITEM><NAME>.dll;</NAME></RULESEMIITEM>
  3783.         </RULESEMIITEMS>
  3784.     </RULE>
  3785.     <RULE>
  3786.         <NAME> Rule_Test_Virus_string</NAME>
  3787.         <TYPE>16</TYPE>
  3788.         <ID>49</ID>
  3789.         <RULEITEMS>
  3790.             <RULEITEM><NAME>X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*</NAME></RULEITEM>
  3791.  
  3792.  
  3793.         </RULEITEMS>
  3794.     </RULE>
  3795. </RULES>
  3796.