Generated by JEB on 2019/08/01

PE: C:\Windows\System32\WppRecorderUM.dll Base=0x180000000 SHA-256=0EA51C68E7418AC6C615F60A56006C922E654F514F38D52F5BB537CE1F835847
PDB: WppRecorderUM.pdb GUID={EF049393-A190-2CC4-3C3C75A656A249CF} Age=1

98 located named symbols:
0x18000192C: "__cdecl _raise_securityfailure" __raise_securityfailure
0x1800022B0: "ForceLogsInMiniDump" ??_C@_1CI@IHDMNONM@?$AAF?$AAo?$AAr?$AAc?$AAe?$AAL?$AAo?$AAg?$AAs?$AAI?$AAn?$AAM?$AAi?$AAn?$AAi?$AAD?$AAu?$AAm?$AAp?$AA?$AA@
0x180002298: "VerboseOn" ??_C@_1BE@GNDHNNGJ@?$AAV?$AAe?$AAr?$AAb?$AAo?$AAs?$AAe?$AAO?$AAn?$AA?$AA@
0x180002764: "__cdecl _IMPORT_DESCRIPTOR_ntdll" __IMPORT_DESCRIPTOR_ntdll
0x180003008: "__cdecl _security_cookie_complement" __security_cookie_complement
0x180002280: "Parameters" ??_C@_1BG@PGIGMDPA@?$AAP?$AAa?$AAr?$AAa?$AAm?$AAe?$AAt?$AAe?$AAr?$AAs?$AA?$AA@
0x180001578: "__cdecl CRT_INIT" _CRT_INIT
0x180002198: "__cdecl _imp_GetCurrentThreadId" __imp_GetCurrentThreadId
0x180001BA0: "__cdecl guard_dispatch_icall_nop" _guard_dispatch_icall_nop
0x180002138: "__cdecl _imp__initterm_e" __imp__initterm_e
0x180002230: "__cdecl _guard_dispatch_icall_fptr" __guard_dispatch_icall_fptr
0x1800021F0: "__cdecl _imp_DecodePointer" __imp_DecodePointer
0x1800022F0: "PerDriverDisableIFR" ??_C@_1CI@ECDDPKME@?$AAP?$AAe?$AAr?$AAD?$AAr?$AAi?$AAv?$AAe?$AAr?$AAD?$AAi?$AAs?$AAa?$AAb?$AAl?$AAe?$AAI?$AAF?$AAR?$AA?$AA@
0x180002238: "__cdecl _xc_a" __xc_a
0x1800013D0: WppAutoLogTrace
0x180002178: api-ms-win-core-heap-l1-1-0_NULL_THUNK_DATA
0x180001B02: memcpy
0x18000190B: "__cdecl initterm" _initterm
0x1800027DC: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-sysinfo-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-sysinfo-l1-1-0
0x180002250: "__cdecl _xi_z" __xi_z
0x180002150: "__cdecl _imp_UnhandledExceptionFilter" __imp_UnhandledExceptionFilter
0x180001AF6: "__cdecl _C_specific_handler" __C_specific_handler
0x180002168: "__cdecl _imp_HeapFree" __imp_HeapFree
0x1800021B8: "__cdecl _imp_RegCloseKey" __imp_RegCloseKey
0x180001B34: "__cdecl _GSHandlerCheckCommon" __GSHandlerCheckCommon
0x180001804: "__cdecl decode_pointer" _decode_pointer
0x1800021D0: api-ms-win-core-registry-l1-1-0_NULL_THUNK_DATA
0x1800027F0: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-util-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-util-l1-1-0
0x180002160: api-ms-win-core-errorhandling-l1-1-0_NULL_THUNK_DATA
0x180002188: "__cdecl _imp_GetCurrentProcess" __imp_GetCurrentProcess
0x180001008: DllMain
0x180002200: api-ms-win-core-util-l1-1-0_NULL_THUNK_DATA
0x180001220: WppAutoLogStart
0x180002120: "__cdecl _imp___C_specific_handler" __imp___C_specific_handler
0x180002218: "__cdecl _imp_RtlCaptureContext" __imp_RtlCaptureContext
0x1800016A4: "__cdecl _DllMainCRTStartup" __DllMainCRTStartup
0x180001B10: "__cdecl _GSHandlerCheck" __GSHandlerCheck
0x180001014: GetWppAutoLogRegistrySettings
0x180002190: "__cdecl _imp_GetCurrentProcessId" __imp_GetCurrentProcessId
0x180002118: "__cdecl _imp_strncpy_s" __imp_strncpy_s
0x180001660: "__cdecl DllMainCRTStartup" _DllMainCRTStartup
0x180002140: "__cdecl _imp__initterm" __imp__initterm
0x180002148: api-ms-win-core-crt-l2-1-0_NULL_THUNK_DATA
0x1800027C8: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-registry-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-registry-l1-1-0
0x1800013C0: WppAutoLogStop
0x180002228: "__cdecl _guard_check_icall_fptr" __guard_check_icall_fptr
0x180002130: api-ms-win-core-crt-l1-1-0_NULL_THUNK_DATA
0x180002180: "__cdecl _imp_TerminateProcess" __imp_TerminateProcess
0x1800021E8: api-ms-win-core-sysinfo-l1-1-0_NULL_THUNK_DATA
0x180002248: "__cdecl _xi_a" __xi_a
0x1800021D8: "__cdecl _imp_GetTickCount" __imp_GetTickCount
0x1800027A0: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-processthreads-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-processthreads-l1-1-0
0x1800021F8: "__cdecl _imp_EncodePointer" __imp_EncodePointer
0x18000278C: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-heap-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-heap-l1-1-0
0x1800017E0: "__cdecl _security_check_cookie" __security_check_cookie
0x180002240: "__cdecl _xc_z" __xc_z
0x1800021A0: api-ms-win-core-processthreads-l1-1-0_NULL_THUNK_DATA
0x1800021E0: "__cdecl _imp_GetSystemTimeAsFileTime" __imp_GetSystemTimeAsFileTime
0x180002170: "__cdecl _imp_GetProcessHeap" __imp_GetProcessHeap
0x180003018: "__cdecl _dllonexit_data" __dllonexit_data
0x1800021B0: api-ms-win-core-profile-l1-1-0_NULL_THUNK_DATA
0x180002258: "__cdecl _guard_fids_table" __guard_fids_table
0x180002010: "__cdecl load_config_used" _load_config_used
0x180002208: "__cdecl _imp_RtlLookupFunctionEntry" __imp_RtlLookupFunctionEntry
0x1800021A8: "__cdecl _imp_QueryPerformanceCounter" __imp_QueryPerformanceCounter
0x180001814: "__cdecl encoded_null" _encoded_null
0x180002210: "__cdecl _imp_RtlVirtualUnwind" __imp_RtlVirtualUnwind
0x180001920: "__cdecl guard_check_icall_nop" _guard_check_icall_nop
0x1800018FF: "__cdecl initterm_e" _initterm_e
0x180002220: ntdll_NULL_THUNK_DATA
0x180002128: "__cdecl _imp_memcpy" __imp_memcpy
0x180003000: "__cdecl _security_cookie" __security_cookie
0x1800021C0: "__cdecl _imp_RegQueryValueExW" __imp_RegQueryValueExW
0x180002778: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-errorhandling-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-errorhandling-l1-1-0
0x180002750: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-crt-l2-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-crt-l2-1-0
0x180002318: "WudfDriverLog" ??_C@_0O@DCKKIKEI@WudfDriverLog?$AA@
0x180002158: "__cdecl _imp_SetUnhandledExceptionFilter" __imp_SetUnhandledExceptionFilter
0x1800021C8: "__cdecl _imp_RegOpenKeyExW" __imp_RegOpenKeyExW
0x180001824: "__cdecl _security_init_cookie" __security_init_cookie
0x18000273C: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-crt-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-crt-l1-1-0
0x180001970: "__cdecl _report_gsfailure" __report_gsfailure
0x1800027B4: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-profile-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-profile-l1-1-0
0x180001560: WppAutoLogGetDefaultHandle
0x180002804: "__cdecl _NULL_IMPORT_DESCRIPTOR" __NULL_IMPORT_DESCRIPTOR
0x1800022D8: "LogPages" ??_C@_1BC@JJOIPLPH@?$AAL?$AAo?$AAg?$AAP?$AAa?$AAg?$AAe?$AAs?$AA?$AA@

[JEB Decompiler by PNF Software]