Generated by JEB on 2019/08/01

PE: C:\Windows\System32\wininit.exe Base=0x140000000 SHA-256=13AD43EE6D19DFC9709C3106D796BC3F21791A564E443D042A5AA117F2680649
PDB: wininit.pdb GUID={3C444E7F-C68E-E141-2024936273C6F9B7} Age=1

2050 located named symbols:
0x140045E10: "__cdecl _imp_RtlInitUnicodeStringEx" __imp_RtlInitUnicodeStringEx
0x140048A50: "NtQuerySystemInformation" ??_C@_0BJ@NDLOPGCH@NtQuerySystemInformation?$AA@
0x14003E078: BiAddBootEntryToNvramDisplayOrder
0x14003AE2C: BiIsVolumePartitionInformationRetained
0x140045F78: "__cdecl _imp_ZwAllocateUuids" __imp_ZwAllocateUuids
0x140045EE0: "__cdecl _imp_ZwOpenMutant" __imp_ZwOpenMutant
0x140048168: "Start" ??_C@_1M@IOJLKPKK@?$AAS?$AAt?$AAa?$AAr?$AAt?$AA?$AA@
0x1400456E8: "__cdecl _imp_LockResource" __imp_LockResource
0x1400503B8: "Store %s is the system store" ??_C@_1DK@IKFOIEDK@?$AAS?$AAt?$AAo?$AAr?$AAe?$AA?5?$AA?$CF?$AAs?$AA?5?$AAi?$AAs?$AA?5?$AAt?$AAh?$AAe?$AA?5?$AAs?$AAy?$AAs?$AAt?$AAe?$AAm?$AA?5?$AAs?$AAt?$AAo?$AAr?$AAe?$AA?$AA@
0x140051160: "Boot entry exists for DontSync w" ??_C@_1FI@CIOMJCGH@?$AAB?$AAo?$AAo?$AAt?$AA?5?$AAe?$AAn?$AAt?$AAr?$AAy?$AA?5?$AAe?$AAx?$AAi?$AAs?$AAt?$AAs?$AA?5?$AAf?$AAo?$AAr?$AA?5?$AAD?$AAo?$AAn?$AAt?$AAS?$AAy?$AAn?$AAc?$AA?5?$AAw@
0x1400505A0: GUID_CURRENT_BOOT_ENTRY
0x1400034C8: "__cdecl _raise_securityfailure" __raise_securityfailure
0x14000859C: "unsigned long __cdecl ExecSystemProcesses(void)" ?ExecSystemProcesses@@YAKXZ
0x140045B50: "__cdecl _imp_ImpersonateLoggedOnUser" __imp_ImpersonateLoggedOnUser
0x14004A89C: "FALSE" ??_C@_05MAJJAKPI@FALSE?$AA@
0x1400455D8: api-ms-win-core-file-l1-1-0_NULL_THUNK_DATA
0x140045B78: "__cdecl _imp_GetSecurityDescriptorOwner" __imp_GetSecurityDescriptorOwner
0x140051060: "BiExportStoreAlterationsToEfi fa" ??_C@_1FA@COMALIMP@?$AAB?$AAi?$AAE?$AAx?$AAp?$AAo?$AAr?$AAt?$AAS?$AAt?$AAo?$AAr?$AAe?$AAA?$AAl?$AAt?$AAe?$AAr?$AAa?$AAt?$AAi?$AAo?$AAn?$AAs?$AAT?$AAo?$AAE?$AAf?$AAi?$AA?5?$AAf?$AAa@
0x1400475E0: "CE163B38-1AEC-47AF-854D-FC90ABD6" ??_C@_1EK@EGPAKBOC@?$AAC?$AAE?$AA1?$AA6?$AA3?$AAB?$AA3?$AA8?$AA?9?$AA1?$AAA?$AAE?$AAC?$AA?9?$AA4?$AA7?$AAA?$AAF?$AA?9?$AA8?$AA5?$AA4?$AAD?$AA?9?$AAF?$AAC?$AA9?$AA0?$AAA?$AAB?$AAD?$AA6@
0x140045DC0: "__cdecl _imp_ZwLoadDriver" __imp_ZwLoadDriver
0x140045B28: "__cdecl _imp_EventRegister" __imp_EventRegister
0x14004FCC0: "KeyName" ??_C@_1BA@PCNMLPEP@?$AAK?$AAe?$AAy?$AAN?$AAa?$AAm?$AAe?$AA?$AA@
0x140003A34: "void __cdecl __scrt_initialize_type_info(void)" ?__scrt_initialize_type_info@@YAXXZ
0x140034BD4: KsrpGetTempDirectory
0x140045670: api-ms-win-core-heap-obsolete-l1-1-0_NULL_THUNK_DATA
0x14004F990: "Failed to open system store. Sta" ??_C@_1FA@PPLIENGI@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAo?$AAp?$AAe?$AAn?$AA?5?$AAs?$AAy?$AAs?$AAt?$AAe?$AAm?$AA?5?$AAs?$AAt?$AAo?$AAr?$AAe?$AA?4?$AA?5?$AAS?$AAt?$AAa@
0x140045E50: "__cdecl _imp_EtwUnregisterTraceGuids" __imp_EtwUnregisterTraceGuids
0x1400421C8: SiGetEfiBootEntryById
0x14002F0A8: WmsgPostNotifyMessage
0x140048AF0: PARTITION_SYSTEM_GUID
0x140004C00: IsDwmpNotifyUserLogonPresent
0x140002A60: I_WMsgSendMessage
0x14004F720: "Failed to get the size needed fo" ??_C@_1IA@HAELFFNK@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAg?$AAe?$AAt?$AA?5?$AAt?$AAh?$AAe?$AA?5?$AAs?$AAi?$AAz?$AAe?$AA?5?$AAn?$AAe?$AAe?$AAd?$AAe?$AAd?$AA?5?$AAf?$AAo@
0x140045E60: "__cdecl _imp_RtlCreateEnvironment" __imp_RtlCreateEnvironment
0x14000501E: "__cdecl _imp_load_NotifyBootConfigStatus" __imp_load_NotifyBootConfigStatus
0x1400353B0: "__cdecl TlgCreateSz" _TlgCreateSz
0x140033638: KsrpGetDriversPath
0x1400463C0: "__cdecl _sz_api_ms_win_eventlog_legacy_l1_1_0_dll" __sz_api_ms_win_eventlog_legacy_l1_1_0_dll
0x14002C664: "unsigned long __cdecl ExecuteSetup(void * __ptr64)" ?ExecuteSetup@@YAKPEAX@Z
0x140034D9C: "public: unsigned short * __ptr64 __cdecl SP<unsigned short,class SP_MEM<unsigned short> >::GetPtrAs<unsigned short>(void)const __ptr64" ??$GetPtrAs@G@?$SP@GV?$SP_MEM@G@@@@QEBAPEAGXZ
0x140050378: "Found loaded store at key %s" ??_C@_1DK@GIOPDOOG@?$AAF?$AAo?$AAu?$AAn?$AAd?$AA?5?$AAl?$AAo?$AAa?$AAd?$AAe?$AAd?$AA?5?$AAs?$AAt?$AAo?$AAr?$AAe?$AA?5?$AAa?$AAt?$AA?5?$AAk?$AAe?$AAy?$AA?5?$AA?$CF?$AAs?$AA?$AA@
0x140025B44: "long __cdecl StringCchCatW(unsigned short * __ptr64,unsigned __int64,unsigned short const * __ptr64)" ?StringCchCatW@@YAJPEAG_KPEBG@Z
0x14004F8B0: "BcdOpenStore: Failed to acquire " ??_C@_1KE@DMKAGBMK@?$AAB?$AAc?$AAd?$AAO?$AAp?$AAe?$AAn?$AAS?$AAt?$AAo?$AAr?$AAe?$AA?3?$AA?5?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAa?$AAc?$AAq?$AAu?$AAi?$AAr?$AAe?$AA?5@
0x14005C040: "__cdecl _imp_CapabilityCheck" __imp_CapabilityCheck
0x140042DD0: SiIsWinPeHardDiskZeroUfdBoot
0x1400030C0: "__cdecl _delayLoadHelper2" __delayLoadHelper2
0x140045D68: "__cdecl _imp_RtlFreeUnicodeString" __imp_RtlFreeUnicodeString
0x14004CBE0: "DEVICE: [Unknown]" ??_C@_1CE@OGNCANCM@?$AAD?$AAE?$AAV?$AAI?$AAC?$AAE?$AA?3?$AA?5?$AA?$FL?$AAU?$AAn?$AAk?$AAn?$AAo?$AAw?$AAn?$AA?$FN?$AA?$AA@
0x140045858: "__cdecl _imp_CompareStringOrdinal" __imp_CompareStringOrdinal
0x14005492C: "__cdecl _IMPORT_DESCRIPTOR_ntdll" __IMPORT_DESCRIPTOR_ntdll
0x14004CC88: "DEVICE: [Locate '%ws']" ??_C@_1CO@CENIIIML@?$AAD?$AAE?$AAV?$AAI?$AAC?$AAE?$AA?3?$AA?5?$AA?$FL?$AAL?$AAo?$AAc?$AAa?$AAt?$AAe?$AA?5?$AA?8?$AA?$CF?$AAw?$AAs?$AA?8?$AA?$FN?$AA?$AA@
0x1400022F0: WmsgpPostNotifyMessage
0x140045FF8: "__cdecl _imp_NtQueryDirectoryObject" __imp_NtQueryDirectoryObject
0x14004CFC0: "Failed to register driver, %#08l" ??_C@_1EE@NPEIHIMN@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAr?$AAe?$AAg?$AAi?$AAs?$AAt?$AAe?$AAr?$AA?5?$AAd?$AAr?$AAi?$AAv?$AAe?$AAr?$AA?0?$AA?5?$AA?$CF?$AA?$CD?$AA0?$AA8?$AAl@
0x14004CD18: NULL_GUID
0x140003160: "__cdecl get_startup_commit_mode" _get_startup_commit_mode
0x14004D0B8: "WIMSetTemporaryPath" ??_C@_0BE@FNFLKKCP@WIMSetTemporaryPath?$AA@
0x14002A0B0: "long __cdecl ShutdownServerSecurityCallback(void * __ptr64,void * __ptr64)" ?ShutdownServerSecurityCallback@@YAJPEAX0@Z
0x140054918: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-crt-private-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-crt-private-l1-1-0
0x140054B48: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-kernel32-legacy-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-kernel32-legacy-l1-1-0
0x14004A880: "%d" ??_C@_15KNBIKKIN@?$AA?$CF?$AAd?$AA?$AA@
0x1400593D4: "unsigned long s_WppControlLevel" ?s_WppControlLevel@@3KA
0x14003B818: BiCloseKey
0x140058678: "struct _GUID s_WppWinInitGuid" ?s_WppWinInitGuid@@3U_GUID@@A
0x140058C74: "__cdecl _scrt_current_native_startup_state" __scrt_current_native_startup_state
0x140046030: "__cdecl _imp_DestroyEnvBlock" __imp_DestroyEnvBlock
0x140058408: "__cdecl _security_cookie_complement" __security_cookie_complement
0x14002EDB8: WluiStartup
0x1400513B8: "ZwDeleteBootEntry" ??_C@_0BC@FOJPBJKO@ZwDeleteBootEntry?$AA@
0x140034D9C: "public: unsigned long * __ptr64 __cdecl SP<unsigned char,class SP_HLOCAL<unsigned char> >::GetPtrAs<unsigned long>(void)const __ptr64" ??$GetPtrAs@K@?$SP@EV?$SP_HLOCAL@E@@@@QEBAPEAKXZ
0x140059210: "int g_bProceedAfterSetup" ?g_bProceedAfterSetup@@3HA
0x14005C0F0: "__cdecl _imp_DwmpNotifyUserLogon" __imp_DwmpNotifyUserLogon
0x140027990: WPP_SF_ll
0x140027990: WPP_SF_LL
0x14002C610: WPP_SF_Ll
0x140049150: "Failed to query boot entry order" ??_C@_1FK@GDCDCJIK@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAq?$AAu?$AAe?$AAr?$AAy?$AA?5?$AAb?$AAo?$AAo?$AAt?$AA?5?$AAe?$AAn?$AAt?$AAr?$AAy?$AA?5?$AAo?$AAr?$AAd?$AAe?$AAr@
0x140058CF8: "__cdecl _hmod__api_ms_win_rtcore_ntuser_private_l1_1_2_dll" __hmod__api_ms_win_rtcore_ntuser_private_l1_1_2_dll
0x140004006: "__cdecl o__configthreadlocale" _o__configthreadlocale
0x140045DF0: "__cdecl _imp_RtlSetThreadIsCritical" __imp_RtlSetThreadIsCritical
0x140045610: "__cdecl _imp_HeapDestroy" __imp_HeapDestroy
0x14000464B: "__cdecl _tailMerge_ext_ms_win_ntuser_keyboard_l1_1_0_dll" __tailMerge_ext_ms_win_ntuser_keyboard_l1_1_0_dll
0x1400462D8: "ncalrpc" ??_C@_1BA@EONDGCCM@?$AAn?$AAc?$AAa?$AAl?$AAr?$AAp?$AAc?$AA?$AA@
0x140048F00: "ZwSetSystemEnvironmentValueEx" ??_C@_0BO@INFEBAAK@ZwSetSystemEnvironmentValueEx?$AA@
0x140048AD8: "Description" ??_C@_1BI@DLMANABL@?$AAD?$AAe?$AAs?$AAc?$AAr?$AAi?$AAp?$AAt?$AAi?$AAo?$AAn?$AA?$AA@
0x140031FA0: "void __cdecl PrepareSetupExecution(unsigned short * __ptr64,unsigned long,unsigned long * __ptr64)" ?PrepareSetupExecution@@YAXPEAGKPEAK@Z
0x14002A38C: "void __cdecl WLEventWriteStartStopScenario(bool,struct _EVENT_DESCRIPTOR const & __ptr64,struct _GUID const & __ptr64,unsigned long)" ?WLEventWriteStartStopScenario@@YAX_NAEBU_EVENT_DESCRIPTOR@@AEBU_GUID@@K@Z
0x140003AA0: "__cdecl _scrt_get_dyn_tls_dtor_callback" __scrt_get_dyn_tls_dtor_callback
0x140040B68: BiTranslateBootEntryId
0x14004AD10: "127.0.0.1" ??_C@_1BE@KGBJBGOH@?$AA1?$AA2?$AA7?$AA?4?$AA0?$AA?4?$AA0?$AA?4?$AA1?$AA?$AA@
0x14004FC00: "Exporting alterations to firmwar" ??_C@_1EG@OHPMMJHC@?$AAE?$AAx?$AAp?$AAo?$AAr?$AAt?$AAi?$AAn?$AAg?$AA?5?$AAa?$AAl?$AAt?$AAe?$AAr?$AAa?$AAt?$AAi?$AAo?$AAn?$AAs?$AA?5?$AAt?$AAo?$AA?5?$AAf?$AAi?$AAr?$AAm?$AAw?$AAa?$AAr@
0x14004C068: "RespecializeCmdLine" ??_C@_1CI@HHPKFPMA@?$AAR?$AAe?$AAs?$AAp?$AAe?$AAc?$AAi?$AAa?$AAl?$AAi?$AAz?$AAe?$AAC?$AAm?$AAd?$AAL?$AAi?$AAn?$AAe?$AA?$AA@
0x14005C0E0: "__cdecl _imp_DwmpCreateSessionProcess" __imp_DwmpCreateSessionProcess
0x140045760: "__cdecl _imp_GetCurrentThreadId" __imp_GetCurrentThreadId
0x1400453C8: "__cdecl _imp_NdrServerCallAll" __imp_NdrServerCallAll
0x140004012: "__cdecl configure_narrow_argv" _configure_narrow_argv
0x140045450: "__cdecl _imp_RpcAsyncCompleteCall" __imp_RpcAsyncCompleteCall
0x140027D80: WinMain
0x140045DB0: "__cdecl _imp_RtlWriteRegistryValue" __imp_RtlWriteRegistryValue
0x14004C3E0: "Unexpected parent device type %d" ??_C@_1GO@MOLGDENP@?$AAU?$AAn?$AAe?$AAx?$AAp?$AAe?$AAc?$AAt?$AAe?$AAd?$AA?5?$AAp?$AAa?$AAr?$AAe?$AAn?$AAt?$AA?5?$AAd?$AAe?$AAv?$AAi?$AAc?$AAe?$AA?5?$AAt?$AAy?$AAp?$AAe?$AA?5?$AA?$CF?$AAd@
0x140003F8E: "__cdecl c_exit" _c_exit
0x1400453B0: "__cdecl _imp_RpcServerRegisterIfEx" __imp_RpcServerRegisterIfEx
0x14000431F: "__cdecl _imp_load_I_ScSendTSMessage" __imp_load_I_ScSendTSMessage
0x140027954: WPP_SF_l
0x140027954: WPP_SF_L
0x1400371F8: BiResolveLocateDevice
0x140031DF4: "int __cdecl IsSetupAvailable(void)" ?IsSetupAvailable@@YAHXZ
0x140045CF8: "__cdecl _imp_RtlInitUnicodeString" __imp_RtlInitUnicodeString
0x140049580: "LsaCfgFlagsDefault" ??_C@_1CG@KBBGNCDL@?$AAL?$AAs?$AAa?$AAC?$AAf?$AAg?$AAF?$AAl?$AAa?$AAg?$AAs?$AAD?$AAe?$AAf?$AAa?$AAu?$AAl?$AAt?$AA?$AA@
0x140048BD8: "System partition: %s" ??_C@_1CK@MLEGHHGO@?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AA?5?$AAp?$AAa?$AAr?$AAt?$AAi?$AAt?$AAi?$AAo?$AAn?$AA?3?$AA?5?$AA?$CF?$AAs?$AA?$AA@
0x1400299B8: "unsigned long __cdecl InitializeShutdownModule(void)" ?InitializeShutdownModule@@YAKXZ
0x140029110: WppControlCallback
0x140039BA4: BiCreateFileDeviceElement
0x1400049D1: "__cdecl _imp_load_WTSEnumerateSessionsW" __imp_load_WTSEnumerateSessionsW
0x140005C10: "__cdecl guard_dispatch_icall_nop" _guard_dispatch_icall_nop
0x1400043B6: "__cdecl _tailMerge_api_ms_win_security_capability_l1_1_0_dll" __tailMerge_api_ms_win_security_capability_l1_1_0_dll
0x1400051D1: "__cdecl _imp_load_StartServiceW" __imp_load_StartServiceW
0x140045460: "__cdecl _imp_RpcEpUnregister" __imp_RpcEpUnregister
0x140045480: "__cdecl _imp_RpcServerRegisterAuthInfoW" __imp_RpcServerRegisterAuthInfoW
0x140045A10: "__cdecl _imp__o_wcstoul" __imp__o_wcstoul
0x14003DB28: BiGenerateObjectGuid
0x14004B9A0: "Software\Microsoft\Windows\Curre" ??_C@_1JK@GHFOBNCJ@?$AAS?$AAo?$AAf?$AAt?$AAw?$AAa?$AAr?$AAe?$AA?2?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAW?$AAi?$AAn?$AAd?$AAo?$AAw?$AAs?$AA?2?$AAC?$AAu?$AAr?$AAr?$AAe@
0x1400459C8: "__cdecl _imp__wcslwr" __imp__wcslwr
0x14002A734: "unsigned long __cdecl WsdpStartRemoteShutdown(void)" ?WsdpStartRemoteShutdown@@YAKXZ
0x1400455B8: "__cdecl _imp_CreateFileW" __imp_CreateFileW
0x140004AE9: "__cdecl _imp_load_WaitForWinstationShutdown" __imp_load_WaitForWinstationShutdown
0x14004BDC8: "C:\Debuggers\ntsd.exe" ??_C@_1CM@GCJMEMEJ@?$AAC?$AA?3?$AA?2?$AAD?$AAe?$AAb?$AAu?$AAg?$AAg?$AAe?$AAr?$AAs?$AA?2?$AAn?$AAt?$AAs?$AAd?$AA?4?$AAe?$AAx?$AAe?$AA?$AA@
0x1400473A0: "SOFTWARE\Microsoft\Windows\Curre" ??_C@_1GM@LIMNIEEL@?$AAS?$AAO?$AAF?$AAT?$AAW?$AAA?$AAR?$AAE?$AA?2?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAW?$AAi?$AAn?$AAd?$AAo?$AAw?$AAs?$AA?2?$AAC?$AAu?$AAr?$AAr?$AAe@
0x14005C088: "__cdecl _imp_StartServiceW" __imp_StartServiceW
0x140050640: "Failed to open key for all objec" ??_C@_1FO@EBMPPDOE@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAo?$AAp?$AAe?$AAn?$AA?5?$AAk?$AAe?$AAy?$AA?5?$AAf?$AAo?$AAr?$AA?5?$AAa?$AAl?$AAl?$AA?5?$AAo?$AAb?$AAj?$AAe?$AAc@
0x140032A5C: KsrGetDefaultBootEntry
0x140040758: BiQueryBootEntryOrder
0x14004C0C8: "RespecializeOptional" ??_C@_1CK@MCOFADHC@?$AAR?$AAe?$AAs?$AAp?$AAe?$AAc?$AAi?$AAa?$AAl?$AAi?$AAz?$AAe?$AAO?$AAp?$AAt?$AAi?$AAo?$AAn?$AAa?$AAl?$AA?$AA@
0x1400455C8: "__cdecl _imp_FindNextVolumeW" __imp_FindNextVolumeW
0x140045C00: "__cdecl _imp_RtlUnsubscribeWnfNotificationWaitForCompletion" __imp_RtlUnsubscribeWnfNotificationWaitForCompletion
0x14004B088: "TempDirPath" ??_C@_1BI@OOCLGJBN@?$AAT?$AAe?$AAm?$AAp?$AAD?$AAi?$AAr?$AAP?$AAa?$AAt?$AAh?$AA?$AA@
0x1400025A0: "unsigned long __cdecl GetClientNetAddr(void * __ptr64,unsigned short * __ptr64 * __ptr64)" ?GetClientNetAddr@@YAKPEAXPEAPEAG@Z
0x1400429E8: SiIsValidDiskDevice
0x140045ED8: "__cdecl _imp_ZwReleaseMutant" __imp_ZwReleaseMutant
0x14002FCBC: UmsHlprInit
0x140054218: api-ms-win-eventlog-legacy-l1-1-0_NULL_THUNK_DATA_DLN
0x14004C6A0: "Failed to mount '%wZ', %#08lx" ??_C@_1DM@OFDLIEMK@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAm?$AAo?$AAu?$AAn?$AAt?$AA?5?$AA?8?$AA?$CF?$AAw?$AAZ?$AA?8?$AA?0?$AA?5?$AA?$CF?$AA?$CD?$AA0?$AA8?$AAl?$AAx?$AA?$AA@
0x140004180: "__cdecl vsnwprintf" _vsnwprintf
0x140045410: "__cdecl _imp_RpcServerTestCancel" __imp_RpcServerTestCancel
0x140049EE8: "__cdecl TraceLoggingMetadata" _TraceLoggingMetadata
0x1400040D2: exit
0x140005146: "__cdecl _imp_load_QueryServiceStatus" __imp_load_QueryServiceStatus
0x1400510B0: "\EFI\Microsoft\Boot\BCD" ??_C@_1DA@FADLAHEF@?$AA?2?$AAE?$AAF?$AAI?$AA?2?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAB?$AAo?$AAo?$AAt?$AA?2?$AAB?$AAC?$AAD?$AA?$AA@
0x14004BFC8: "SetupShutdownRequired" ??_C@_1CM@BBLNDNNG@?$AAS?$AAe?$AAt?$AAu?$AAp?$AAS?$AAh?$AAu?$AAt?$AAd?$AAo?$AAw?$AAn?$AAR?$AAe?$AAq?$AAu?$AAi?$AAr?$AAe?$AAd?$AA?$AA@
0x140045F70: "__cdecl _imp_ZwOpenProcess" __imp_ZwOpenProcess
0x140054318: ext-ms-win-ntuser-keyboard-l1-1-0_NULL_THUNK_DATA_DLN
0x14004A498: WIEvt_ShutdownSystemRestore_Start
0x140037BC8: BiIsSystemStore
0x14004F7A0: "Failed to enumerate subelements." ??_C@_1FI@GOPEHANC@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAe?$AAn?$AAu?$AAm?$AAe?$AAr?$AAa?$AAt?$AAe?$AA?5?$AAs?$AAu?$AAb?$AAe?$AAl?$AAe?$AAm?$AAe?$AAn?$AAt?$AAs?$AA?4@
0x140001010: s_WsdrInitiateShutdown
0x14005C038: api-ms-win-rtcore-ntuser-private-l1-1-2_NULL_THUNK_DATA_DLA
0x1400547F0: ext-ms-win-session-wininit-l1-1-0_NULL_THUNK_DATA_DLB
0x14000488C: IsSwitchDesktopPresent
0x140045F20: "__cdecl _imp_ZwEnumerateKey" __imp_ZwEnumerateKey
0x140045440: "__cdecl _imp_RpcAsyncCancelCall" __imp_RpcAsyncCancelCall
0x140045998: "__cdecl _imp__seh_filter_exe" __imp__seh_filter_exe
0x140001FE0: "int __cdecl WMsgBroadcastNotifyHandler(unsigned long,unsigned long,unsigned short const * __ptr64,struct _RPC_ASYNC_STATE * __ptr64,long * __ptr64)" ?WMsgBroadcastNotifyHandler@@YAHKKPEBGPEAU_RPC_ASYNC_STATE@@PEAJ@Z
0x1400460A0: "__cdecl _xp_a" __xp_a
0x140048348: "DefaultInstance" ??_C@_1CA@NOADNNEL@?$AAD?$AAe?$AAf?$AAa?$AAu?$AAl?$AAt?$AAI?$AAn?$AAs?$AAt?$AAa?$AAn?$AAc?$AAe?$AA?$AA@
0x140046208: "fmifs.dll" ??_C@_1BE@IHGPAAHL@?$AAf?$AAm?$AAi?$AAf?$AAs?$AA?4?$AAd?$AAl?$AAl?$AA?$AA@
0x14004BF40: WPP_e24da56f9de334935060f76621ccc52a_Traceguids
0x14004AC60: "InitShutdown" ??_C@_1BK@JADBKLGE@?$AAI?$AAn?$AAi?$AAt?$AAS?$AAh?$AAu?$AAt?$AAd?$AAo?$AAw?$AAn?$AA?$AA@
0x140045980: "__cdecl _imp__o__initialize_narrow_environment" __imp__o__initialize_narrow_environment
0x140045F50: "__cdecl _imp_LdrGetDllHandle" __imp_LdrGetDllHandle
0x140034DD4: "public: void __cdecl SP<unsigned short * __ptr64,class SP_MEM<unsigned short * __ptr64> >::Attach(unsigned short * __ptr64 * __ptr64) __ptr64" ?Attach@?$SP@PEAGV?$SP_MEM@PEAG@@@@QEAAXPEAPEAG@Z
0x140029534: "void __cdecl CommitSoftReboot(void)" ?CommitSoftReboot@@YAXXZ
0x140047850: "CoreShellComposer" ??_C@_1CE@CDKGGBOF@?$AAC?$AAo?$AAr?$AAe?$AAS?$AAh?$AAe?$AAl?$AAl?$AAC?$AAo?$AAm?$AAp?$AAo?$AAs?$AAe?$AAr?$AA?$AA@
0x14005C0D8: "__cdecl _imp_DwmpIsInitialSessionInteractive" __imp_DwmpIsInitialSessionInteractive
0x1400505B0: GUID_DEFAULT_BOOT_ENTRY
0x140045A10: "__cdecl _imp_wcstoul" __imp_wcstoul
0x140024C40: "long __cdecl RemoveTokenPrivileges(void)" ?RemoveTokenPrivileges@@YAJXZ
0x140029F70: "void __cdecl PrepareForSoftReboot(void)" ?PrepareForSoftReboot@@YAXXZ
0x140047C50: "Getting option list for BCD entr" ??_C@_1EE@JGGCDMGE@?$AAG?$AAe?$AAt?$AAt?$AAi?$AAn?$AAg?$AA?5?$AAo?$AAp?$AAt?$AAi?$AAo?$AAn?$AA?5?$AAl?$AAi?$AAs?$AAt?$AA?5?$AAf?$AAo?$AAr?$AA?5?$AAB?$AAC?$AAD?$AA?5?$AAe?$AAn?$AAt?$AAr@
0x1400481E0: "Failed to set 'Type' value, %#08" ??_C@_1EG@LFFJHOHP@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAs?$AAe?$AAt?$AA?5?$AA?8?$AAT?$AAy?$AAp?$AAe?$AA?8?$AA?5?$AAv?$AAa?$AAl?$AAu?$AAe?$AA?0?$AA?5?$AA?$CF?$AA?$CD?$AA0?$AA8@
0x140003D10: "__cdecl RTC_Initialize" _RTC_Initialize
0x140035D78: BiConvertElementToRegistryData
0x14002EEF8: WluiiGetSystemAccountSamName
0x140053F50: "__cdecl _DELAY_IMPORT_DESCRIPTOR_api_ms_win_service_private_l1_1_0_dll" __DELAY_IMPORT_DESCRIPTOR_api_ms_win_service_private_l1_1_0_dll
0x14004EEE4: "" ??_C@_00CNPNBAHC@?$AA@
0x140049130: "ZwQueryBootEntryOrder" ??_C@_0BG@NLKCEPDF@ZwQueryBootEntryOrder?$AA@
0x140045A28: "__cdecl _imp__crt_atexit" __imp__crt_atexit
0x140045A60: "__cdecl _imp___stdio_common_vsnwprintf_s" __imp___stdio_common_vsnwprintf_s
0x140046660: "ext-ms-win-ntuser-private-l1-1-1" ??_C@_1EC@MFGGMKFF@?$AAe?$AAx?$AAt?$AA?9?$AAm?$AAs?$AA?9?$AAw?$AAi?$AAn?$AA?9?$AAn?$AAt?$AAu?$AAs?$AAe?$AAr?$AA?9?$AAp?$AAr?$AAi?$AAv?$AAa?$AAt?$AAe?$AA?9?$AAl?$AA1?$AA?9?$AA1?$AA?9?$AA1@
0x14003D7BC: BiFilterObjectIsInSystemStore
0x140045E80: "__cdecl _imp_EtwGetTraceLoggerHandle" __imp_EtwGetTraceLoggerHandle
0x140046CB0: "ext-ms-win-rtcore-ntuser-mininit" ??_C@_1FA@NFGLAPOI@?$AAe?$AAx?$AAt?$AA?9?$AAm?$AAs?$AA?9?$AAw?$AAi?$AAn?$AA?9?$AAr?$AAt?$AAc?$AAo?$AAr?$AAe?$AA?9?$AAn?$AAt?$AAu?$AAs?$AAe?$AAr?$AA?9?$AAm?$AAi?$AAn?$AAi?$AAn?$AAi?$AAt@
0x140045720: "__cdecl _imp_InitializeProcThreadAttributeList" __imp_InitializeProcThreadAttributeList
0x14003AD1C: BiGetVolumeDiskExtentsInformation
0x14004EEF0: "__cdecl _pfnDliFailureHook2" __pfnDliFailureHook2
0x140059474: "__cdecl _@@_PchSym_@00@KxulyqvxgPillgKxunrmrlUhvxfirgbUorxvmhrmtUhkxzooUoryUyfrowPxorvmgPfnUlyquivUznwGEUhgwzucOlyq@spcall_client_um" __@@_PchSym_@00@KxulyqvxgPillgKxunrmrlUhvxfirgbUorxvmhrmtUhkxzooUoryUyfrowPxorvmgPfnUlyquivUznwGEUhgwzucOlyq@spcall_client_um
0x140004B20: IsValidateSystemShutdownPresent
0x14000502A: "__cdecl _tailMerge_api_ms_win_base_bootconfig_l1_1_0_dll" __tailMerge_api_ms_win_base_bootconfig_l1_1_0_dll
0x140045698: "__cdecl _imp_GetModuleFileNameA" __imp_GetModuleFileNameA
0x140048368: "Altitude" ??_C@_1BC@JBOPDCNA@?$AAA?$AAl?$AAt?$AAi?$AAt?$AAu?$AAd?$AAe?$AA?$AA@
0x14000472C: "__cdecl _tailMerge_ext_ms_win_ntuser_misc_l1_1_0_dll" __tailMerge_ext_ms_win_ntuser_misc_l1_1_0_dll
0x1400459F0: "__cdecl _imp_terminate" __imp_terminate
0x14002F174: WmsgpDisconnect
0x140049298: "\Device" ??_C@_1BA@CCLAPIHO@?$AA?2?$AAD?$AAe?$AAv?$AAi?$AAc?$AAe?$AA?$AA@
0x140037A78: BiCloseStore
0x14004BA40: "WMsgKRpc%X%X%X" ??_C@_1BO@DGOFIHDP@?$AAW?$AAM?$AAs?$AAg?$AAK?$AAR?$AAp?$AAc?$AA?$CF?$AAX?$AA?$CF?$AAX?$AA?$CF?$AAX?$AA?$AA@
0x140054030: "__cdecl _DELAY_IMPORT_DESCRIPTOR_ext_ms_win_ntuser_private_l1_1_0_dll" __DELAY_IMPORT_DESCRIPTOR_ext_ms_win_ntuser_private_l1_1_0_dll
0x140049070: "Failed to set boot entry order. " ??_C@_1FG@CEPAPBIN@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAs?$AAe?$AAt?$AA?5?$AAb?$AAo?$AAo?$AAt?$AA?5?$AAe?$AAn?$AAt?$AAr?$AAy?$AA?5?$AAo?$AAr?$AAd?$AAe?$AAr?$AA?4?$AA?5@
0x140059258: g_pSidLocal
0x140054BD4: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-file-l1-2-0" __IMPORT_DESCRIPTOR_api-ms-win-core-file-l1-2-0
0x140051BF8: "__cdecl _rtc_taa" __rtc_taa
0x1400457F8: "__cdecl _imp_RegEnumValueW" __imp_RegEnumValueW
0x140046E80: WLEvt_DwmpTerminateSessionProcess_Start
0x1400549E0: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-file-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-file-l1-1-0
0x14004C780: "BcdEnumerateAndUnpackElements() " ??_C@_1FO@BKKMCJLE@?$AAB?$AAc?$AAd?$AAE?$AAn?$AAu?$AAm?$AAe?$AAr?$AAa?$AAt?$AAe?$AAA?$AAn?$AAd?$AAU?$AAn?$AAp?$AAa?$AAc?$AAk?$AAE?$AAl?$AAe?$AAm?$AAe?$AAn?$AAt?$AAs?$AA?$CI?$AA?$CJ?$AA?5@
0x140003160: "__cdecl get_startup_thread_locale_mode" _get_startup_thread_locale_mode
0x14004AC80: "succeeded" ??_C@_09KNCHHPEA@succeeded?$AA@
0x140054BC0: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-eventing-classicprovider-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-eventing-classicprovider-l1-1-0
0x14004ADC0: "TEMP" ??_C@_19LFDMGLCC@?$AAT?$AAE?$AAM?$AAP?$AA?$AA@
0x14003D168: BiIsLinkedToFirmwareVariable
0x140045CC0: "__cdecl _imp_RtlCreateSecurityDescriptor" __imp_RtlCreateSecurityDescriptor
0x140045AB0: "__cdecl _imp__initterm_e" __imp__initterm_e
0x14003C4F0: BiGetRegistryValue
0x140045660: api-ms-win-core-heap-l2-1-0_NULL_THUNK_DATA
0x140004C00: IsDwmpIsInitialSessionInteractivePresent
0x140054730: api-ms-win-security-sddl-l1-1-0_NULL_THUNK_DATA_DLB
0x140045458: "__cdecl _imp_RpcServerUnregisterIf" __imp_RpcServerUnregisterIf
0x14003711C: BiGetElement
0x1400419F8: SiGetRegistryValue
0x14003D2D0: BiLogFileOwnerProcess
0x1400453E8: "__cdecl _imp_Ndr64AsyncServerCallAll" __imp_Ndr64AsyncServerCallAll
0x140045F88: "__cdecl _imp_NtSetInformationThread" __imp_NtSetInformationThread
0x140045AC0: api-ms-win-crt-runtime-l1-1-0_NULL_THUNK_DATA
0x140003F64: "__cdecl _scrt_is_ucrt_dll_in_use" __scrt_is_ucrt_dll_in_use
0x140045A78: "__cdecl _imp_wcschr" __imp_wcschr
0x1400593F0: "struct _WNF_STATE_NAME _wnfState" ?_wnfState@@3U_WNF_STATE_NAME@@A
0x140003A48: "__cdecl _vcrt_initialize" __vcrt_initialize
0x140045878: "__cdecl _imp_SetEvent" __imp_SetEvent
0x140045988: "__cdecl _imp__initialize_onexit_table" __imp__initialize_onexit_table
0x140004B0D: "__cdecl _imp_load_WinStationSystemShutdownStartedWorker" __imp_load_WinStationSystemShutdownStartedWorker
0x14004F110: "BcdGetElementDataWithFlags: Fail" ??_C@_1LM@EBMDGPOP@?$AAB?$AAc?$AAd?$AAG?$AAe?$AAt?$AAE?$AAl?$AAe?$AAm?$AAe?$AAn?$AAt?$AAD?$AAa?$AAt?$AAa?$AAW?$AAi?$AAt?$AAh?$AAF?$AAl?$AAa?$AAg?$AAs?$AA?3?$AA?5?$AAF?$AAa?$AAi?$AAl@
0x140050EE0: "Failed to query process info. St" ??_C@_1FC@CBHMOBM@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAq?$AAu?$AAe?$AAr?$AAy?$AA?5?$AAp?$AAr?$AAo?$AAc?$AAe?$AAs?$AAs?$AA?5?$AAi?$AAn?$AAf?$AAo?$AA?4?$AA?5?$AAS?$AAt@
0x140025654: "long __cdecl StartTrustletProcess(unsigned short * __ptr64,void * __ptr64,int,unsigned char * __ptr64,struct _PROCESS_INFORMATION * __ptr64)" ?StartTrustletProcess@@YAJPEAGPEAXHPEAEPEAU_PROCESS_INFORMATION@@@Z
0x14003CF5C: BiLogMessage
0x140004066: "__cdecl o__seh_filter_exe" _o__seh_filter_exe
0x140050BA0: "Attempting to determine owner of" ??_C@_1FG@CNICICCJ@?$AAA?$AAt?$AAt?$AAe?$AAm?$AAp?$AAt?$AAi?$AAn?$AAg?$AA?5?$AAt?$AAo?$AA?5?$AAd?$AAe?$AAt?$AAe?$AAr?$AAm?$AAi?$AAn?$AAe?$AA?5?$AAo?$AAw?$AAn?$AAe?$AAr?$AA?5?$AAo?$AAf@
0x1400040C6: "__cdecl o__wcsupr" _o__wcsupr
0x140058D90: "__cdecl _hmod__ext_ms_win_composition_init_l1_1_0_dll" __hmod__ext_ms_win_composition_init_l1_1_0_dll
0x140059470: KsrUseLocalDriver
0x140045620: "__cdecl _imp_HeapSetInformation" __imp_HeapSetInformation
0x140054B84: "__cdecl _IMPORT_DESCRIPTOR_KERNELBASE" __IMPORT_DESCRIPTOR_KERNELBASE
0x140045C18: "__cdecl _imp_RtlEnterCriticalSection" __imp_RtlEnterCriticalSection
0x140029244: "__cdecl TlgWrite" _TlgWrite
0x1400458F0: "__cdecl _imp_GetLocalTime" __imp_GetLocalTime
0x140037634: BiAddStoreFromFile
0x140046050: "__cdecl _guard_dispatch_icall_fptr" __guard_dispatch_icall_fptr
0x14004F670: "Failed to enumerate subkeys. Sta" ??_C@_1FA@LFNAFIHA@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAe?$AAn?$AAu?$AAm?$AAe?$AAr?$AAa?$AAt?$AAe?$AA?5?$AAs?$AAu?$AAb?$AAk?$AAe?$AAy?$AAs?$AA?4?$AA?5?$AAS?$AAt?$AAa@
0x140004F50: NdrServerCall2
0x1400548A0: api-ms-win-service-management-l1-1-0_NULL_THUNK_DATA_DLB
0x14005C0A0: api-ms-win-service-management-l2-1-0_NULL_THUNK_DATA_DLA
0x14005C090: api-ms-win-service-management-l1-1-0_NULL_THUNK_DATA_DLA
0x1400548D0: api-ms-win-service-management-l2-1-0_NULL_THUNK_DATA_DLB
0x140034D9C: "public: void * __ptr64 __cdecl SP<unsigned char,class SP_MEM<unsigned char> >::GetPtrAs<void>(void)const __ptr64" ??$GetPtrAs@X@?$SP@EV?$SP_MEM@E@@@@QEBAPEAXXZ
0x140054AE4: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-file-l2-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-file-l2-1-0
0x140054280: api-ms-win-service-management-l1-1-0_NULL_THUNK_DATA_DLN
0x140054290: api-ms-win-service-management-l2-1-0_NULL_THUNK_DATA_DLN
0x14004FCD0: "TreatAsSystem" ??_C@_1BM@PKHJDDOK@?$AAT?$AAr?$AAe?$AAa?$AAt?$AAA?$AAs?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AA?$AA@
0x140051330: "Translated a DontSync object to " ??_C@_1FA@HPKMDCCM@?$AAT?$AAr?$AAa?$AAn?$AAs?$AAl?$AAa?$AAt?$AAe?$AAd?$AA?5?$AAa?$AA?5?$AAD?$AAo?$AAn?$AAt?$AAS?$AAy?$AAn?$AAc?$AA?5?$AAo?$AAb?$AAj?$AAe?$AAc?$AAt?$AA?5?$AAt?$AAo?$AA?5@
0x14005C160: "__cdecl _imp_ValidateSystemShutdown" __imp_ValidateSystemShutdown
0x1400310A8: UHReportBootGood
0x14003E600: BiBindEfiNamespaceObjects
0x140050900: "Failed open key %ws. Status: %x" ??_C@_1EA@KNEPPFGO@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAo?$AAp?$AAe?$AAn?$AA?5?$AAk?$AAe?$AAy?$AA?5?$AA?$CF?$AAw?$AAs?$AA?4?$AA?5?$AAS?$AAt?$AAa?$AAt?$AAu?$AAs?$AA?3?$AA?5?$AA?$CF?$AAx?$AA?$AA@
0x140003100: DefaultWMsgMessageHandler
0x1400458C8: "__cdecl _imp_InitializeCriticalSection" __imp_InitializeCriticalSection
0x1400515F0: "\ArcName\multi(0)disk(0)rdisk(0)" ??_C@_1EC@PIADGFGJ@?$AA?2?$AAA?$AAr?$AAc?$AAN?$AAa?$AAm?$AAe?$AA?2?$AAm?$AAu?$AAl?$AAt?$AAi?$AA?$CI?$AA0?$AA?$CJ?$AAd?$AAi?$AAs?$AAk?$AA?$CI?$AA0?$AA?$CJ?$AAr?$AAd?$AAi?$AAs?$AAk?$AA?$CI?$AA0?$AA?$CJ@
0x140005464: "void __cdecl TriggerAssertImplementation(void)" ?TriggerAssertImplementation@@YAXXZ
0x1400592B0: g_pSidAnyRestrictedPackage
0x1400454A0: "__cdecl _imp_RpcEpRegisterW" __imp_RpcEpRegisterW
0x1400459D0: "__cdecl _imp__wcsnicmp" __imp__wcsnicmp
0x14002B55C: "void __cdecl CleanupLeftovers(void)" ?CleanupLeftovers@@YAXXZ
0x1400456D8: "__cdecl _imp_GetModuleHandleExW" __imp_GetModuleHandleExW
0x140045B60: "__cdecl _imp_RevertToSelf" __imp_RevertToSelf
0x1400295C4: "void __cdecl DealWithSession0LogoffRequest(unsigned long)" ?DealWithSession0LogoffRequest@@YAXK@Z
0x1400455D0: "__cdecl _imp_GetShortPathNameW" __imp_GetShortPathNameW
0x140034D9C: "public: unsigned short * __ptr64 __cdecl SP<unsigned char,class SP_MEM<unsigned char> >::GetPtrAs<unsigned short>(void)const __ptr64" ??$GetPtrAs@G@?$SP@EV?$SP_MEM@E@@@@QEBAPEAGXZ
0x140047088: "StagedBootCompletionEvent" ??_C@_1DE@MLCHHIDL@?$AAS?$AAt?$AAa?$AAg?$AAe?$AAd?$AAB?$AAo?$AAo?$AAt?$AAC?$AAo?$AAm?$AAp?$AAl?$AAe?$AAt?$AAi?$AAo?$AAn?$AAE?$AAv?$AAe?$AAn?$AAt?$AA?$AA@
0x14004D050: "Failed to unload the driver, %#0" ??_C@_1EI@IFCPBJDB@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAu?$AAn?$AAl?$AAo?$AAa?$AAd?$AA?5?$AAt?$AAh?$AAe?$AA?5?$AAd?$AAr?$AAi?$AAv?$AAe?$AAr?$AA?0?$AA?5?$AA?$CF?$AA?$CD?$AA0@
0x1400040BA: "__cdecl o__wcsnicmp" _o__wcsnicmp
0x14002D734: "unsigned long __cdecl PerformSystemRestore(void (__cdecl*)(unsigned short const * __ptr64))" ?PerformSystemRestore@@YAKP6AXPEBG@Z@Z
0x140046A10: "ext-ms-win-onecore-shutdown-l1-1" ??_C@_1EG@CIGNOFIC@?$AAe?$AAx?$AAt?$AA?9?$AAm?$AAs?$AA?9?$AAw?$AAi?$AAn?$AA?9?$AAo?$AAn?$AAe?$AAc?$AAo?$AAr?$AAe?$AA?9?$AAs?$AAh?$AAu?$AAt?$AAd?$AAo?$AAw?$AAn?$AA?9?$AAl?$AA1?$AA?9?$AA1@
0x140051BE8: "__cdecl _rtc_iaa" __rtc_iaa
0x1400294E8: "long __cdecl CheckShellExperienceComposerAccess(void)" ?CheckShellExperienceComposerAccess@@YAJXZ
0x140004441: "__cdecl _tailMerge_api_ms_win_eventlog_legacy_l1_1_0_dll" __tailMerge_api_ms_win_eventlog_legacy_l1_1_0_dll
0x140058648: "struct _SYSTEM_PROCESS_FLAGS * SystemProcessFlags" ?SystemProcessFlags@@3PAU_SYSTEM_PROCESS_FLAGS@@A
0x140045B18: api-ms-win-eventing-controller-l1-1-0_NULL_THUNK_DATA
0x14004B430: "\VarFileInfo\Translation" ??_C@_1DC@HCLBMGIA@?$AA?2?$AAV?$AAa?$AAr?$AAF?$AAi?$AAl?$AAe?$AAI?$AAn?$AAf?$AAo?$AA?2?$AAT?$AAr?$AAa?$AAn?$AAs?$AAl?$AAa?$AAt?$AAi?$AAo?$AAn?$AA?$AA@
0x1400049BF: "__cdecl _imp_load_WTSDisconnectSession" __imp_load_WTSDisconnectSession
0x140030F30: "void __cdecl NotifyCallback(void * __ptr64)" ?NotifyCallback@@YAXPEAX@Z
0x14005C0B8: "__cdecl _imp_QueryServiceStatus" __imp_QueryServiceStatus
0x140047700: "Software\Microsoft\Windows\Curre" ??_C@_1GG@BNOMMAHN@?$AAS?$AAo?$AAf?$AAt?$AAw?$AAa?$AAr?$AAe?$AA?2?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAW?$AAi?$AAn?$AAd?$AAo?$AAw?$AAs?$AA?2?$AAC?$AAu?$AAr?$AAr?$AAe@
0x140045B70: "__cdecl _imp_GetSecurityDescriptorControl" __imp_GetSecurityDescriptorControl
0x14005C150: "__cdecl _imp_SwitchDesktop" __imp_SwitchDesktop
0x14003F290: BiCreateMergedBootEntry
0x1400260B0: "void __cdecl TraceFullShutdownInfo(void)" ?TraceFullShutdownInfo@@YAXXZ
0x140054778: api-ms-win-rtcore-ntuser-private-l1-1-2_NULL_THUNK_DATA_DLB
0x14005C198: ext-ms-win-session-wininit-l1-1-0_NULL_THUNK_DATA_DLA
0x140054248: api-ms-win-security-lsalookup-l1-1-0_NULL_THUNK_DATA_DLN
0x14005C058: api-ms-win-security-lsalookup-l1-1-0_NULL_THUNK_DATA_DLA
0x140040AD4: BiSetBootOptions
0x140054878: api-ms-win-security-lsalookup-l1-1-0_NULL_THUNK_DATA_DLB
0x140045A58: "__cdecl _imp__o___stdio_common_vswprintf" __imp__o___stdio_common_vswprintf
0x1400482E0: "Failed to create a service insta" ??_C@_1GC@CACLJMLB@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAc?$AAr?$AAe?$AAa?$AAt?$AAe?$AA?5?$AAa?$AA?5?$AAs?$AAe?$AAr?$AAv?$AAi?$AAc?$AAe?$AA?5?$AAi?$AAn?$AAs?$AAt?$AAa@
0x14005C1B8: "__cdecl _imp_WTSQueryUserToken" __imp_WTSQueryUserToken
0x140046058: "__cdecl _xc_a" __xc_a
0x14002B38C: "unsigned short * __ptr64 __cdecl AllocAndGetStringSetting(unsigned short const * __ptr64,unsigned short const * __ptr64)" ?AllocAndGetStringSetting@@YAPEAGPEBG0@Z
0x140045A18: "__cdecl _imp_wcsstr" __imp_wcsstr
0x140034D9C: "public: unsigned char * __ptr64 __cdecl SP<unsigned char,class SP_MEM<unsigned char> >::GetPtrAs<unsigned char>(void)const __ptr64" ??$GetPtrAs@E@?$SP@EV?$SP_MEM@E@@@@QEBAPEAEXZ
0x140045738: "__cdecl _imp_CreateProcessW" __imp_CreateProcessW
0x140050B38: "PortableOperatingSystem" ??_C@_1DA@IFMDNCPF@?$AAP?$AAo?$AAr?$AAt?$AAa?$AAb?$AAl?$AAe?$AAO?$AAp?$AAe?$AAr?$AAa?$AAt?$AAi?$AAn?$AAg?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AA?$AA@
0x14004A3E8: WLEvt_WluiServerStartupFailure
0x140003100: DefaultWMsgPSPHandler
0x1400466B0: "ext-ms-win-ntuser-private-l1-2-0" ??_C@_1EC@PDFFKKND@?$AAe?$AAx?$AAt?$AA?9?$AAm?$AAs?$AA?9?$AAw?$AAi?$AAn?$AA?9?$AAn?$AAt?$AAu?$AAs?$AAe?$AAr?$AA?9?$AAp?$AAr?$AAi?$AAv?$AAa?$AAt?$AAe?$AA?9?$AAl?$AA1?$AA?9?$AA2?$AA?9?$AA0@
0x140051260: "BiExportEfiBootManager failed: %" ??_C@_1EE@FJNEFEPL@?$AAB?$AAi?$AAE?$AAx?$AAp?$AAo?$AAr?$AAt?$AAE?$AAf?$AAi?$AAB?$AAo?$AAo?$AAt?$AAM?$AAa?$AAn?$AAa?$AAg?$AAe?$AAr?$AA?5?$AAf?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?3?$AA?5?$AA?$CF@
0x14002921C: "__cdecl TlgKeywordOn" _TlgKeywordOn
0x14004C9B0: "Unsupported device type (%d) for" ??_C@_1GI@KGKCCHND@?$AAU?$AAn?$AAs?$AAu?$AAp?$AAp?$AAo?$AAr?$AAt?$AAe?$AAd?$AA?5?$AAd?$AAe?$AAv?$AAi?$AAc?$AAe?$AA?5?$AAt?$AAy?$AAp?$AAe?$AA?5?$AA?$CI?$AA?$CF?$AAd?$AA?$CJ?$AA?5?$AAf?$AAo?$AAr@
0x140034D50: StringCbCopyW
0x140049ED8: VmbFsInterfaceTypeGuid
0x140045FE0: "__cdecl _imp_NtQueryBootOptions" __imp_NtQueryBootOptions
0x14004BF20: "ServicesActive" ??_C@_1BO@JHOJBCBI@?$AAS?$AAe?$AAr?$AAv?$AAi?$AAc?$AAe?$AAs?$AAA?$AAc?$AAt?$AAi?$AAv?$AAe?$AA?$AA@
0x140040628: BiIsLinkedToEfiVariable
0x1400049E3: "__cdecl _imp_load_WTSFreeMemory" __imp_load_WTSFreeMemory
0x140047320: "SYSTEM\CurrentControlSet\Control" ??_C@_1HG@POPNHLM@?$AAS?$AAY?$AAS?$AAT?$AAE?$AAM?$AA?2?$AAC?$AAu?$AAr?$AAr?$AAe?$AAn?$AAt?$AAC?$AAo?$AAn?$AAt?$AAr?$AAo?$AAl?$AAS?$AAe?$AAt?$AA?2?$AAC?$AAo?$AAn?$AAt?$AAr?$AAo?$AAl@
0x140034D9C: "public: char * __ptr64 __cdecl SP<unsigned char,class SP_MEM<unsigned char> >::GetPtrAs<char>(void)const __ptr64" ??$GetPtrAs@D@?$SP@EV?$SP_MEM@E@@@@QEBAPEADXZ
0x140045788: "__cdecl _imp_GetStartupInfoW" __imp_GetStartupInfoW
0x140054A58: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-timezone-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-timezone-l1-1-0
0x14004025C: BiGetObjectReferenceFromEfiEntry
0x140047878: "ShutdownStartTimePerfCounter" ??_C@_1DK@DLLNMGDE@?$AAS?$AAh?$AAu?$AAt?$AAd?$AAo?$AAw?$AAn?$AAS?$AAt?$AAa?$AAr?$AAt?$AAT?$AAi?$AAm?$AAe?$AAP?$AAe?$AAr?$AAf?$AAC?$AAo?$AAu?$AAn?$AAt?$AAe?$AAr?$AA?$AA@
0x140051530: "Harddisk" ??_C@_1BC@PEHNMCKA@?$AAH?$AAa?$AAr?$AAd?$AAd?$AAi?$AAs?$AAk?$AA?$AA@
0x14004B200: "bootex.log" ??_C@_1BG@NBJEMHON@?$AAb?$AAo?$AAo?$AAt?$AAe?$AAx?$AA?4?$AAl?$AAo?$AAg?$AA?$AA@
0x1400592A0: g_pSidFontDriverHost
0x140050E70: "Failed to allocate memory for sp" ??_C@_1GM@IKCHKJKN@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAa?$AAl?$AAl?$AAo?$AAc?$AAa?$AAt?$AAe?$AA?5?$AAm?$AAe?$AAm?$AAo?$AAr?$AAy?$AA?5?$AAf?$AAo?$AAr?$AA?5?$AAs?$AAp@
0x140045588: "__cdecl _imp_FindClose" __imp_FindClose
0x1400048E0: IsWTSQueryUserTokenPresent
0x140047960: "ShutdownStopTimePerfCounterBuild" ??_C@_1EI@GHNPDKLI@?$AAS?$AAh?$AAu?$AAt?$AAd?$AAo?$AAw?$AAn?$AAS?$AAt?$AAo?$AAp?$AAT?$AAi?$AAm?$AAe?$AAP?$AAe?$AAr?$AAf?$AAC?$AAo?$AAu?$AAn?$AAt?$AAe?$AAr?$AAB?$AAu?$AAi?$AAl?$AAd@
0x1400040EA: "__cdecl o_wcscat_s" _o_wcscat_s
0x140058E08: BcdMutantHandle
0x1400458F8: "__cdecl _imp_GetComputerNameExW" __imp_GetComputerNameExW
0x140045A30: "__cdecl _imp__o__configure_narrow_argv" __imp__o__configure_narrow_argv
0x140058420: "__cdecl _scrt_ucrt_dll_is_in_use" __scrt_ucrt_dll_is_in_use
0x14002FB58: StopWMsgServer
0x140045DA8: "__cdecl _imp_RtlAppendUnicodeStringToString" __imp_RtlAppendUnicodeStringToString
0x140048E10: "Failed to add boot entry. Status" ??_C@_1EK@DADMEGIB@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAa?$AAd?$AAd?$AA?5?$AAb?$AAo?$AAo?$AAt?$AA?5?$AAe?$AAn?$AAt?$AAr?$AAy?$AA?4?$AA?5?$AAS?$AAt?$AAa?$AAt?$AAu?$AAs@
0x1400040EA: wcscat_s
0x1400040A2: "__cdecl o__wcsicmp" _o__wcsicmp
0x140045C60: "__cdecl _imp_NtAllocateLocallyUniqueId" __imp_NtAllocateLocallyUniqueId
0x14004AC98: "!x-sys-default-locale" ??_C@_1CM@BFAMBNFD@?$AA?$CB?$AAx?$AA?9?$AAs?$AAy?$AAs?$AA?9?$AAd?$AAe?$AAf?$AAa?$AAu?$AAl?$AAt?$AA?9?$AAl?$AAo?$AAc?$AAa?$AAl?$AAe?$AA?$AA@
0x14004A428: WIEvt_ShutdownSystemRestore_Stop
0x140045EC8: "__cdecl _imp_ZwWaitForSingleObject" __imp_ZwWaitForSingleObject
0x14004ADD0: "TMP" ??_C@_17DDHKMLLK@?$AAT?$AAM?$AAP?$AA?$AA@
0x14003850C: BcdOpenObject
0x14004B7E0: "VerboseStatus" ??_C@_1BM@ODFPJGAE@?$AAV?$AAe?$AAr?$AAb?$AAo?$AAs?$AAe?$AAS?$AAt?$AAa?$AAt?$AAu?$AAs?$AA?$AA@
0x14004A3C8: WIEvt_NtShutdownSystem_Info
0x14000480C: "__cdecl _tailMerge_ext_ms_win_ntuser_private_l1_1_0_dll" __tailMerge_ext_ms_win_ntuser_private_l1_1_0_dll
0x140059118: "struct HWINSTA__ * __ptr64 __ptr64 s_hWinsta" ?s_hWinsta@@3PEAUHWINSTA__@@EA
0x140045640: api-ms-win-core-heap-l1-1-0_NULL_THUNK_DATA
0x140003FEE: "__cdecl _stdio_common_vswscanf" __stdio_common_vswscanf
0x140046EB0: WIEvt_Wininit_Lsa_Iso_Launch_Failure
0x14005C068: api-ms-win-security-sddl-l1-1-0_NULL_THUNK_DATA_DLA
0x140034CC4: StringCbCatW
0x140032998: KsrCompletePrepare
0x140048B48: "System store path: %s" ??_C@_1CM@NIKLLOAB@?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AA?5?$AAs?$AAt?$AAo?$AAr?$AAe?$AA?5?$AAp?$AAa?$AAt?$AAh?$AA?3?$AA?5?$AA?$CF?$AAs?$AA?$AA@
0x140047208: "EventFlag" ??_C@_1BE@HLOHNNFD@?$AAE?$AAv?$AAe?$AAn?$AAt?$AAF?$AAl?$AAa?$AAg?$AA?$AA@
0x140045C68: "__cdecl _imp_NtSetValueKey" __imp_NtSetValueKey
0x14004F5B0: "Failed to open object %ws. Statu" ??_C@_1EM@MJGLOODF@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAo?$AAp?$AAe?$AAn?$AA?5?$AAo?$AAb?$AAj?$AAe?$AAc?$AAt?$AA?5?$AA?$CF?$AAw?$AAs?$AA?4?$AA?5?$AAS?$AAt?$AAa?$AAt?$AAu@
0x14000530C: "int __cdecl IsVirtualizationBasedSecurityRunning(void)" ?IsVirtualizationBasedSecurityRunning@@YAHXZ
0x14004BF50: WPP_acf3d487851d35e64a3099cd5564aee8_Traceguids
0x140030F80: "void __cdecl ReportBootGoodThread(void * __ptr64)" ?ReportBootGoodThread@@YAXPEAX@Z
0x1400386DC: BcdQueryObject
0x140034E7C: "public: void __cdecl SP<unsigned long,class SP_MEM<unsigned long> >::Reset(void) __ptr64" ?Reset@?$SP@KV?$SP_MEM@K@@@@QEAAXXZ
0x14004B588: "TracingControlLevel" ??_C@_1CI@PFIOIPBC@?$AAT?$AAr?$AAa?$AAc?$AAi?$AAn?$AAg?$AAC?$AAo?$AAn?$AAt?$AAr?$AAo?$AAl?$AAL?$AAe?$AAv?$AAe?$AAl?$AA?$AA@
0x140046518: "ext-ms-win-ntuser-misc-l1-2-0" ??_C@_1DM@BDNJLNEB@?$AAe?$AAx?$AAt?$AA?9?$AAm?$AAs?$AA?9?$AAw?$AAi?$AAn?$AA?9?$AAn?$AAt?$AAu?$AAs?$AAe?$AAr?$AA?9?$AAm?$AAi?$AAs?$AAc?$AA?9?$AAl?$AA1?$AA?9?$AA2?$AA?9?$AA0?$AA?$AA@
0x140058418: "__cdecl _memcpy_nt_iters" __memcpy_nt_iters
0x1400040A2: "__cdecl wcsicmp" _wcsicmp
0x14004CA18: "\system32\drivers" ??_C@_1CE@JKOAACHF@?$AA?2?$AAs?$AAy?$AAs?$AAt?$AAe?$AAm?$AA3?$AA2?$AA?2?$AAd?$AAr?$AAi?$AAv?$AAe?$AAr?$AAs?$AA?$AA@
0x140004720: "__cdecl _imp_load_ExitWindowsEx" __imp_load_ExitWindowsEx
0x14005C098: "__cdecl _imp_NotifyServiceStatusChangeW" __imp_NotifyServiceStatusChangeW
0x140047440: "ShutdownStateSnapshot" ??_C@_1CM@HENHKCCD@?$AAS?$AAh?$AAu?$AAt?$AAd?$AAo?$AAw?$AAn?$AAS?$AAt?$AAa?$AAt?$AAe?$AAS?$AAn?$AAa?$AAp?$AAs?$AAh?$AAo?$AAt?$AA?$AA@
0x140045580: "__cdecl _imp_DeleteFileW" __imp_DeleteFileW
0x14004086C: BiQueryBootOptions
0x140048FD8: "ZwModifyBootEntry" ??_C@_0BC@JMHOIME@ZwModifyBootEntry?$AA@
0x140050AA8: "ZwLoadKey2" ??_C@_0L@LOHEIM@ZwLoadKey2?$AA@
0x140045AD8: "__cdecl _imp_wcsncmp" __imp_wcsncmp
0x14004A6D8: "NV PrimaryDnsSuffix" ??_C@_1CI@ONFPCBDO@?$AAN?$AAV?$AA?5?$AAP?$AAr?$AAi?$AAm?$AAa?$AAr?$AAy?$AAD?$AAn?$AAs?$AAS?$AAu?$AAf?$AAf?$AAi?$AAx?$AA?$AA@
0x1400461C8: "__cdecl _guard_iat_table" __guard_iat_table
0x140037CA0: BiLoadSystemStore
0x140045708: api-ms-win-core-processenvironment-l1-1-0_NULL_THUNK_DATA
0x140004800: "__cdecl _imp_load_RecordShutdownReason" __imp_load_RecordShutdownReason
0x140005BE3: memcpy
0x14005C140: "__cdecl _imp_RecordShutdownReason" __imp_RecordShutdownReason
0x14004AAD0: "765294BA-60BC-48B8-92E9-89FD7776" ??_C@_1EK@CDBCGHNF@?$AA7?$AA6?$AA5?$AA2?$AA9?$AA4?$AAB?$AAA?$AA?9?$AA6?$AA0?$AAB?$AAC?$AA?9?$AA4?$AA8?$AAB?$AA8?$AA?9?$AA9?$AA2?$AAE?$AA9?$AA?9?$AA8?$AA9?$AAF?$AAD?$AA7?$AA7?$AA7?$AA6@
0x1400456C8: "__cdecl _imp_LoadLibraryExW" __imp_LoadLibraryExW
0x140059108: "struct HDESK__ * __ptr64 __ptr64 s_hdeskApplication" ?s_hdeskApplication@@3PEAUHDESK__@@EA
0x140050330: "Opening system store. Flags: 0x%" ??_C@_1EE@OJEMMLOB@?$AAO?$AAp?$AAe?$AAn?$AAi?$AAn?$AAg?$AA?5?$AAs?$AAy?$AAs?$AAt?$AAe?$AAm?$AA?5?$AAs?$AAt?$AAo?$AAr?$AAe?$AA?4?$AA?5?$AAF?$AAl?$AAa?$AAg?$AAs?$AA?3?$AA?5?$AA0?$AAx?$AA?$CF@
0x140034DA8: "public: void __cdecl SP<unsigned char,class SP_HLOCAL<unsigned char> >::Attach(unsigned char * __ptr64) __ptr64" ?Attach@?$SP@EV?$SP_HLOCAL@E@@@@QEAAXPEAE@Z
0x14004A710: " -winlogon %d" ??_C@_1BM@DIEIKNPK@?$AA?5?$AA?9?$AAw?$AAi?$AAn?$AAl?$AAo?$AAg?$AAo?$AAn?$AA?5?$AA?$CF?$AAd?$AA?$AA@
0x140034E1C: "public: static bool __cdecl SP<unsigned long,class SP_MEM<unsigned long> >::IsNull(unsigned long * __ptr64)" ?IsNull@?$SP@KV?$SP_MEM@K@@@@SA_NPEAK@Z
0x1400059E8: SiGetBootDeviceNameFromRegistry
0x140045AE0: "__cdecl _imp_memset" __imp_memset
0x1400458C0: "__cdecl _imp_WaitForSingleObjectEx" __imp_WaitForSingleObjectEx
0x140045890: "__cdecl _imp_WaitForMultipleObjectsEx" __imp_WaitForMultipleObjectsEx
0x14004B470: "\StringFileInfo\%04x%04x\Company" ??_C@_1EK@ECOKLNNL@?$AA?2?$AAS?$AAt?$AAr?$AAi?$AAn?$AAg?$AAF?$AAi?$AAl?$AAe?$AAI?$AAn?$AAf?$AAo?$AA?2?$AA?$CF?$AA0?$AA4?$AAx?$AA?$CF?$AA0?$AA4?$AAx?$AA?2?$AAC?$AAo?$AAm?$AAp?$AAa?$AAn?$AAy@
0x140003A48: "__cdecl _acrt_initialize" __acrt_initialize
0x14002C2E8: "int __cdecl UpdateUserEnvironment(void * __ptr64 * __ptr64)" ?UpdateUserEnvironment@@YAHPEAPEAX@Z
0x14004FC50: "Failed to export alterations to " ??_C@_1GK@NKBLNBBA@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAe?$AAx?$AAp?$AAo?$AAr?$AAt?$AA?5?$AAa?$AAl?$AAt?$AAe?$AAr?$AAa?$AAt?$AAi?$AAo?$AAn?$AAs?$AA?5?$AAt?$AAo?$AA?5@
0x140045868: "__cdecl _imp_CreateEventW" __imp_CreateEventW
0x1400455E8: api-ms-win-core-file-l1-2-0_NULL_THUNK_DATA
0x1400455F8: api-ms-win-core-file-l2-1-0_NULL_THUNK_DATA
0x140003F76: "__cdecl initterm" _initterm
0x140045AF0: "__cdecl _imp_TraceMessage" __imp_TraceMessage
0x140002AF0: "int __cdecl WMsgMessageHandler(unsigned long,unsigned long,struct _RPC_ASYNC_STATE * __ptr64,long * __ptr64)" ?WMsgMessageHandler@@YAHKKPEAU_RPC_ASYNC_STATE@@PEAJ@Z
0x140045978: "__cdecl _imp__get_narrow_winmain_command_line" __imp__get_narrow_winmain_command_line
0x14004F1D0: "Setting element %08x" ??_C@_1CK@DFMHAPNH@?$AAS?$AAe?$AAt?$AAt?$AAi?$AAn?$AAg?$AA?5?$AAe?$AAl?$AAe?$AAm?$AAe?$AAn?$AAt?$AA?5?$AA?$CF?$AA0?$AA8?$AAx?$AA?$AA@
0x140050C00: "Failed to open file attributes. " ??_C@_1FG@IMCMKLHL@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAo?$AAp?$AAe?$AAn?$AA?5?$AAf?$AAi?$AAl?$AAe?$AA?5?$AAa?$AAt?$AAt?$AAr?$AAi?$AAb?$AAu?$AAt?$AAe?$AAs?$AA?4?$AA?5@
0x140059268: g_pSidAdmin
0x14004F600: "Failed to Enumerate elements fro" ??_C@_1GE@GJPOCJEG@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAE?$AAn?$AAu?$AAm?$AAe?$AAr?$AAa?$AAt?$AAe?$AA?5?$AAe?$AAl?$AAe?$AAm?$AAe?$AAn?$AAt?$AAs?$AA?5?$AAf?$AAr?$AAo@
0x14003CC94: BiSetRegistryValue
0x140045478: "__cdecl _imp_RpcServerInqDefaultPrincNameW" __imp_RpcServerInqDefaultPrincNameW
0x14000404E: "__cdecl o__initialize_onexit_table" _o__initialize_onexit_table
0x1400549CC: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-sysinfo-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-sysinfo-l1-1-0
0x1400373F4: BcdCloseStore
0x140058E00: "__cdecl _dyn_tls_init_callback" __dyn_tls_init_callback
0x140050B68: "SystemStartOptions" ??_C@_1CG@BLIBLCJE@?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AAS?$AAt?$AAa?$AAr?$AAt?$AAO?$AAp?$AAt?$AAi?$AAo?$AAn?$AAs?$AA?$AA@
0x14004AEC0: "CommonProgramFiles" ??_C@_1CG@HMNDLOFD@?$AAC?$AAo?$AAm?$AAm?$AAo?$AAn?$AAP?$AAr?$AAo?$AAg?$AAr?$AAa?$AAm?$AAF?$AAi?$AAl?$AAe?$AAs?$AA?$AA@
0x1400462E8: "shellExperienceComposer" ??_C@_1DA@FFCHBCAK@?$AAs?$AAh?$AAe?$AAl?$AAl?$AAE?$AAx?$AAp?$AAe?$AAr?$AAi?$AAe?$AAn?$AAc?$AAe?$AAC?$AAo?$AAm?$AAp?$AAo?$AAs?$AAe?$AAr?$AA?$AA@
0x140046F40: "Global\FirstWinlogonCheck" ??_C@_1DE@IFFKOIJA@?$AAG?$AAl?$AAo?$AAb?$AAa?$AAl?$AA?2?$AAF?$AAi?$AAr?$AAs?$AAt?$AAW?$AAi?$AAn?$AAl?$AAo?$AAg?$AAo?$AAn?$AAC?$AAh?$AAe?$AAc?$AAk?$AA?$AA@
0x14003A8B8: BiGetPartitionInformation
0x1400458D8: "__cdecl _imp_Sleep" __imp_Sleep
0x14003D248: BiIsWinPEBoot
0x140047670: "ShutdownFlags" ??_C@_1BM@JMKJILKC@?$AAS?$AAh?$AAu?$AAt?$AAd?$AAo?$AAw?$AAn?$AAF?$AAl?$AAa?$AAg?$AAs?$AA?$AA@
0x140050F68: "ZwFilterBootOption" ??_C@_0BD@FBODIBBP@ZwFilterBootOption?$AA@
0x140046098: "__cdecl _xi_z" __xi_z
0x14000402A: "__cdecl exit" _exit
0x14003619C: BiConvertQualifiedPartitionToBootEnvironment
0x140045F40: "__cdecl _imp_ZwSetValueKey" __imp_ZwSetValueKey
0x1400502D0: "File is not system store. File: " ??_C@_1FO@CPLCCCHE@?$AAF?$AAi?$AAl?$AAe?$AA?5?$AAi?$AAs?$AA?5?$AAn?$AAo?$AAt?$AA?5?$AAs?$AAy?$AAs?$AAt?$AAe?$AAm?$AA?5?$AAs?$AAt?$AAo?$AAr?$AAe?$AA?4?$AA?5?$AAF?$AAi?$AAl?$AAe?$AA?3?$AA?5@
0x1400011C0: "unsigned long __cdecl InternalInitiateShutdown(unsigned long,void * __ptr64,int,struct _UNICODE_STRING * __ptr64,unsigned long,unsigned long,unsigned long,unsigned short const * __ptr64,unsigned short const * __ptr64)" ?InternalInitiateShutdown@@YAKKPEAXHPEAU_UNICODE_STRING@@KKKPEBG2@Z
0x140041B70: SiIsWinPEBoot
0x140045560: "__cdecl _imp_UnhandledExceptionFilter" __imp_UnhandledExceptionFilter
0x140004096: "__cdecl ultow_s" _ultow_s
0x140045C20: "__cdecl _imp_NtOpenProcessToken" __imp_NtOpenProcessToken
0x14004BCA0: "Software\Microsoft\Windows NT\Cu" ??_C@_1GK@FDCHPAFD@?$AAS?$AAo?$AAf?$AAt?$AAw?$AAa?$AAr?$AAe?$AA?2?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAW?$AAi?$AAn?$AAd?$AAo?$AAw?$AAs?$AA?5?$AAN?$AAT?$AA?2?$AAC?$AAu@
0x140045E30: "__cdecl _imp_RtlSetEnvironmentVariable" __imp_RtlSetEnvironmentVariable
0x14002A430: "unsigned long __cdecl WsdpInitializeRemoteShutdown(void * __ptr64)" ?WsdpInitializeRemoteShutdown@@YAKPEAX@Z
0x140058300: KsrpServiceDefaultInstanceAltitude
0x140047A90: "wuauserv" ??_C@_1BC@DFGNJLOE@?$AAw?$AAu?$AAa?$AAu?$AAs?$AAe?$AAr?$AAv?$AA?$AA@
0x140045C08: "__cdecl _imp_RtlIsMultiSessionSku" __imp_RtlIsMultiSessionSku
0x140049050: "ZwSetBootEntryOrder" ??_C@_0BE@MMAIHNII@ZwSetBootEntryOrder?$AA@
0x140045E58: "__cdecl _imp_EtwRegisterTraceGuidsW" __imp_EtwRegisterTraceGuidsW
0x140003FB2: "__cdecl _C_specific_handler" __C_specific_handler
0x1400481C8: "Type" ??_C@_19BIEPDBPA@?$AAT?$AAy?$AAp?$AAe?$AA?$AA@
0x14004FCF0: "FirmwareModified" ??_C@_1CC@IOBFIDDP@?$AAF?$AAi?$AAr?$AAm?$AAw?$AAa?$AAr?$AAe?$AAM?$AAo?$AAd?$AAi?$AAf?$AAi?$AAe?$AAd?$AA?$AA@
0x140045688: "__cdecl _imp_WTSGetActiveConsoleSessionId" __imp_WTSGetActiveConsoleSessionId
0x140045C40: "__cdecl _imp_RtlDeregisterWaitEx" __imp_RtlDeregisterWaitEx
0x140045A50: "__cdecl _imp___stdio_common_vswprintf_s" __imp___stdio_common_vswprintf_s
0x1400593D0: "unsigned long s_WppManualOverride" ?s_WppManualOverride@@3KA
0x140002BD0: MIDL_user_free
0x1400458B0: "__cdecl _imp_ReleaseSRWLockExclusive" __imp_ReleaseSRWLockExclusive
0x1400483D0: "Flags" ??_C@_1M@OAJFFPML@?$AAF?$AAl?$AAa?$AAg?$AAs?$AA?$AA@
0x1400040F6: "__cdecl o_wcscpy_s" _o_wcscpy_s
0x140045438: "__cdecl _imp_RpcBindingUnbind" __imp_RpcBindingUnbind
0x14004D0F8: "WIMExtractImagePath" ??_C@_0BE@NOGMIOEH@WIMExtractImagePath?$AA@
0x1400459E8: "__cdecl _imp__o_exit" __imp__o_exit
0x140029670: "unsigned short * __ptr64 __cdecl GetDateTimeString(struct _SYSTEMTIME * __ptr64)" ?GetDateTimeString@@YAPEAGPEAU_SYSTEMTIME@@@Z
0x1400457E0: api-ms-win-core-psapi-l1-1-0_NULL_THUNK_DATA
0x140048E80: "Failed to enumerate boot entries" ??_C@_1FK@FNFPEHCB@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAe?$AAn?$AAu?$AAm?$AAe?$AAr?$AAa?$AAt?$AAe?$AA?5?$AAb?$AAo?$AAo?$AAt?$AA?5?$AAe?$AAn?$AAt?$AAr?$AAi?$AAe?$AAs@
0x14004B508: "RestoreFunction" ??_C@_0BA@OEFJGOLB@RestoreFunction?$AA@
0x140005BEF: memmove
0x14004FD18: "BCD%08d" ??_C@_1BA@MEPDEHOL@?$AAB?$AAC?$AAD?$AA?$CF?$AA0?$AA8?$AAd?$AA?$AA@
0x140045638: "__cdecl _imp_HeapFree" __imp_HeapFree
0x1400495A8: WNF_SYS_SHUTDOWN_IN_PROGRESS
0x1400045B4: "__cdecl _imp_load_InitializeStateSeparation" __imp_load_InitializeStateSeparation
0x1400465E0: "__cdecl _sz_ext_ms_win_ntuser_misc_l1_1_0_dll" __sz_ext_ms_win_ntuser_misc_l1_1_0_dll
0x1400459A8: "__cdecl _imp__set_fmode" __imp__set_fmode
0x14003BF04: BiDoesHiveKeyExist
0x14002D278: WPP_SF_llS
0x1400292E0: "void __cdecl BroadcastPanicShutdownNotification(unsigned short const * __ptr64)" ?BroadcastPanicShutdownNotification@@YAXPEBG@Z
0x140047470: "%SystemRoot%\system32\WerFault.e" ??_C@_1EG@PLEGMAMG@?$AA?$CF?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AAR?$AAo?$AAo?$AAt?$AA?$CF?$AA?2?$AAs?$AAy?$AAs?$AAt?$AAe?$AAm?$AA3?$AA2?$AA?2?$AAW?$AAe?$AAr?$AAF?$AAa?$AAu?$AAl?$AAt?$AA?4?$AAe@
0x140059148: WPP_REGISTRATION_GUIDS
0x140045F48: "__cdecl _imp_LdrGetProcedureAddress" __imp_LdrGetProcedureAddress
0x140058DF0: "__cdecl _hmod__ext_ms_win_ntuser_windowstation_l1_1_0_dll" __hmod__ext_ms_win_ntuser_windowstation_l1_1_0_dll
0x140004294: "__cdecl _imp_load_ConvertStringSecurityDescriptorToSecurityDescriptorW" __imp_load_ConvertStringSecurityDescriptorToSecurityDescriptorW
0x14004EF00: "Elements" ??_C@_1BC@PNOFMOMA@?$AAE?$AAl?$AAe?$AAm?$AAe?$AAn?$AAt?$AAs?$AA?$AA@
0x140046E90: WLEvt_DwmpTerminateSessionProcess_Stop
0x14004C0F8: "RespecializeFailures" ??_C@_1CK@LDDBLPCN@?$AAR?$AAe?$AAs?$AAp?$AAe?$AAc?$AAi?$AAa?$AAl?$AAi?$AAz?$AAe?$AAF?$AAa?$AAi?$AAl?$AAu?$AAr?$AAe?$AAs?$AA?$AA@
0x14002F320: I_WMsgSendPSPMessage
0x14004ACF8: "wininit.exe" ??_C@_1BI@DBNLEFLG@?$AAw?$AAi?$AAn?$AAi?$AAn?$AAi?$AAt?$AA?4?$AAe?$AAx?$AAe?$AA?$AA@
0x140045CC8: "__cdecl _imp_RtlCreateAcl" __imp_RtlCreateAcl
0x1400038BC: "__cdecl _scrt_uninitialize_crt" __scrt_uninitialize_crt
0x140047800: "Software\Microsoft\CoreShell\Com" ??_C@_1EM@JFAHBDJI@?$AAS?$AAo?$AAf?$AAt?$AAw?$AAa?$AAr?$AAe?$AA?2?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAC?$AAo?$AAr?$AAe?$AAS?$AAh?$AAe?$AAl?$AAl?$AA?2?$AAC?$AAo?$AAm@
0x14002C234: "unsigned long __cdecl UIDisplayStatus(unsigned short const * __ptr64,enum _WLUI_STATE,unsigned long)" ?UIDisplayStatus@@YAKPEBGW4_WLUI_STATE@@K@Z
0x14005C078: "__cdecl _imp_OpenServiceW" __imp_OpenServiceW
0x14004BD10: "BpidDebugger" ??_C@_1BK@PIMMPEDB@?$AAB?$AAp?$AAi?$AAd?$AAD?$AAe?$AAb?$AAu?$AAg?$AAg?$AAe?$AAr?$AA?$AA@
0x140051550: "\EFI\Microsoft\Boot\bootmgfw.efi" ??_C@_1EC@LNDFLFLH@?$AA?2?$AAE?$AAF?$AAI?$AA?2?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAB?$AAo?$AAo?$AAt?$AA?2?$AAb?$AAo?$AAo?$AAt?$AAm?$AAg?$AAf?$AAw?$AA?4?$AAe?$AAf?$AAi@
0x140045608: api-ms-win-core-handle-l1-1-0_NULL_THUNK_DATA
0x140047A00: "Enabled" ??_C@_1BA@NPJPKIM@?$AAE?$AAn?$AAa?$AAb?$AAl?$AAe?$AAd?$AA?$AA@
0x14004D0A8: "WIMCreateFile" ??_C@_0O@MHDBFGKK@WIMCreateFile?$AA@
0x140059298: g_pSidWindowManager
0x1400478B8: "LastLogOffEndTimePerfCounter" ??_C@_1DK@JPPMLNFP@?$AAL?$AAa?$AAs?$AAt?$AAL?$AAo?$AAg?$AAO?$AAf?$AAf?$AAE?$AAn?$AAd?$AAT?$AAi?$AAm?$AAe?$AAP?$AAe?$AAr?$AAf?$AAC?$AAo?$AAu?$AAn?$AAt?$AAe?$AAr?$AA?$AA@
0x140003C54: "__cdecl _scrt_initialize_mta" __scrt_initialize_mta
0x140030890: Attach
0x1400464D8: "ext-ms-win-ntuser-misc-l1-1-0" ??_C@_1DM@JNFGLKKC@?$AAe?$AAx?$AAt?$AA?9?$AAm?$AAs?$AA?9?$AAw?$AAi?$AAn?$AA?9?$AAn?$AAt?$AAu?$AAs?$AAe?$AAr?$AA?9?$AAm?$AAi?$AAs?$AAc?$AA?9?$AAl?$AA1?$AA?9?$AA1?$AA?9?$AA0?$AA?$AA@
0x140045810: "__cdecl _imp_RegCloseKey" __imp_RegCloseKey
0x140045BD8: "__cdecl _imp_NtQueryInformationToken" __imp_NtQueryInformationToken
0x140005A84: "__cdecl _GSHandlerCheckCommon" __GSHandlerCheckCommon
0x140045CA8: "__cdecl _imp_NtCreateEvent" __imp_NtCreateEvent
0x1400057D0: SyspartGetFirmwarePartition
0x140058DC8: "__cdecl _hmod__api_ms_win_security_lsalookup_l1_1_0_dll" __hmod__api_ms_win_security_lsalookup_l1_1_0_dll
0x140026FF4: "unsigned long __cdecl WinInitSetup(int * __ptr64,enum _SHUTDOWN_ACTION * __ptr64)" ?WinInitSetup@@YAKPEAHPEAW4_SHUTDOWN_ACTION@@@Z
0x14002EE34: RegOpenSessionDataKey
0x1400037F0: "__cdecl _scrt_is_nonwritable_in_current_image" __scrt_is_nonwritable_in_current_image
0x14004C830: "Failed to allocate option list m" ??_C@_1EM@KNCHKKHC@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAa?$AAl?$AAl?$AAo?$AAc?$AAa?$AAt?$AAe?$AA?5?$AAo?$AAp?$AAt?$AAi?$AAo?$AAn?$AA?5?$AAl?$AAi?$AAs?$AAt?$AA?5?$AAm@
0x140003FFA: "__cdecl cexit" _cexit
0x1400586D0: "unsigned short * s_WppLogSessionName" ?s_WppLogSessionName@@3PAGA
0x140004240: "__cdecl snwscanf_s" _snwscanf_s
0x140045558: "__cdecl _imp_SetErrorMode" __imp_SetErrorMode
0x140038740: BiCreateObject
0x1400036C0: "__cdecl _scrt_initialize_crt" __scrt_initialize_crt
0x14004A9E8: "Winsta0\Winlogon" ??_C@_1CC@DDCBOEJI@?$AAW?$AAi?$AAn?$AAs?$AAt?$AAa?$AA0?$AA?2?$AAW?$AAi?$AAn?$AAl?$AAo?$AAg?$AAo?$AAn?$AA?$AA@
0x14004A448: WLEvt_WluiServerShutdown_Start
0x140045F90: "__cdecl _imp_NtOpenThreadTokenEx" __imp_NtOpenThreadTokenEx
0x140050120: "Failed to set description key va" ??_C@_1JA@LHPLIIFE@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAs?$AAe?$AAt?$AA?5?$AAd?$AAe?$AAs?$AAc?$AAr?$AAi?$AAp?$AAt?$AAi?$AAo?$AAn?$AA?5?$AAk?$AAe?$AAy?$AA?5?$AAv?$AAa@
0x140049560: "LsaCfgFlagsTest" ??_C@_1CA@MJIGMEAJ@?$AAL?$AAs?$AAa?$AAC?$AAf?$AAg?$AAF?$AAl?$AAa?$AAg?$AAs?$AAT?$AAe?$AAs?$AAt?$AA?$AA@
0x140032558: "int __cdecl ShouldSetupExecute(void)" ?ShouldSetupExecute@@YAHXZ
0x14004C028: "SystemSetupInProgress" ??_C@_1CM@DHJDDPJO@?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AAS?$AAe?$AAt?$AAu?$AAp?$AAI?$AAn?$AAP?$AAr?$AAo?$AAg?$AAr?$AAe?$AAs?$AAs?$AA?$AA@
0x140059288: g_pSidInteractive
0x1400353E8: BcdEnumerateAndUnpackElements
0x140003A48: "__cdecl _acrt_uninitialize" __acrt_uninitialize
0x140045AE8: api-ms-win-crt-string-l1-1-0_NULL_THUNK_DATA
0x140002C40: IsRpcCallerLocalSystem
0x14002DEC8: "unsigned long __cdecl WppGrowBuf(void * __ptr64 * __ptr64,unsigned long)" ?WppGrowBuf@@YAKPEAPEAXK@Z
0x1400541B0: "__cdecl _DELAY_IMPORT_DESCRIPTOR_ext_ms_win_ntuser_windowstation_l1_1_0_dll" __DELAY_IMPORT_DESCRIPTOR_ext_ms_win_ntuser_windowstation_l1_1_0_dll
0x140046BB0: "ext-ms-onecore-shellchromeapi-l1" ??_C@_1EK@MHBPMABG@?$AAe?$AAx?$AAt?$AA?9?$AAm?$AAs?$AA?9?$AAo?$AAn?$AAe?$AAc?$AAo?$AAr?$AAe?$AA?9?$AAs?$AAh?$AAe?$AAl?$AAl?$AAc?$AAh?$AAr?$AAo?$AAm?$AAe?$AAa?$AAp?$AAi?$AA?9?$AAl?$AA1@
0x1400040DE: terminate
0x140045D00: "__cdecl _imp_RtlAllocateHeap" __imp_RtlAllocateHeap
0x14003D824: SiGetSystemDeviceName
0x140054ABC: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-psapi-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-psapi-l1-1-0
0x140045860: api-ms-win-core-string-l1-1-0_NULL_THUNK_DATA
0x140059120: WPP_MAIN_CB
0x1400456F8: "__cdecl _imp_SetEnvironmentVariableW" __imp_SetEnvironmentVariableW
0x140058280: "struct _LSAP_STARTUP_CONFIG_PARAMETERS * LsapStartupConfigParams" ?LsapStartupConfigParams@@3PAU_LSAP_STARTUP_CONFIG_PARAMETERS@@A
0x140004D18: IsShell_RequestShutdownPresent
0x140045C30: "__cdecl _imp_NtSetThreadExecutionState" __imp_NtSetThreadExecutionState
0x1400471A0: "SYSTEM\CurrentControlSet\Control" ??_C@_1GE@JLNGECLJ@?$AAS?$AAY?$AAS?$AAT?$AAE?$AAM?$AA?2?$AAC?$AAu?$AAr?$AAr?$AAe?$AAn?$AAt?$AAC?$AAo?$AAn?$AAt?$AAr?$AAo?$AAl?$AAS?$AAe?$AAt?$AA?2?$AAC?$AAo?$AAn?$AAt?$AAr?$AAo?$AAl@
0x14002EFF0: "void * __ptr64 __cdecl MemoryAlloc(unsigned __int64)" ?MemoryAlloc@@YAPEAX_K@Z
0x1400040BA: "__cdecl wcsnicmp" _wcsnicmp
0x140045C38: "__cdecl _imp_CsrClientCallServer" __imp_CsrClientCallServer
0x14003DE8C: BiAddBootEntry
0x140059208: "void * __ptr64 __ptr64 g_hWininitHeap" ?g_hWininitHeap@@3PEAXEA
0x140054A08: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-security-base-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-security-base-l1-1-0
0x14004BF90: "Respecialize" ??_C@_1BK@CGJOHCEH@?$AAR?$AAe?$AAs?$AAp?$AAe?$AAc?$AAi?$AAa?$AAl?$AAi?$AAz?$AAe?$AA?$AA@
0x1400457E8: "__cdecl _imp_RegSetValueExW" __imp_RegSetValueExW
0x140042B04: SiGetBiosSystemDisk
0x140033550: KsrpFindOptionInList
0x14004114C: BiUpdateEfiEntry
0x140025D90: "unsigned long __cdecl SystemProcessDeathWorker(void * __ptr64)" ?SystemProcessDeathWorker@@YAKPEAX@Z
0x1400472F8: "TempDestination" ??_C@_1CA@JNBGKABD@?$AAT?$AAe?$AAm?$AAp?$AAD?$AAe?$AAs?$AAt?$AAi?$AAn?$AAa?$AAt?$AAi?$AAo?$AAn?$AA?$AA@
0x140042A94: SiIsValidWindowsBootEntry
0x1400491D0: "Failed to query boot options. St" ??_C@_1FC@FCIBACCK@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAq?$AAu?$AAe?$AAr?$AAy?$AA?5?$AAb?$AAo?$AAo?$AAt?$AA?5?$AAo?$AAp?$AAt?$AAi?$AAo?$AAn?$AAs?$AA?4?$AA?5?$AAS?$AAt@
0x140004006: "__cdecl configthreadlocale" _configthreadlocale
0x140001C30: "void __cdecl ScheduledShutdownWarningCallback(void * __ptr64,unsigned char)" ?ScheduledShutdownWarningCallback@@YAXPEAXE@Z
0x140003CB8: "__cdecl _scrt_set_unhandled_exception_filter" __scrt_set_unhandled_exception_filter
0x1400304E0: "int __cdecl FoundDebugger(unsigned short * __ptr64,int)" ?FoundDebugger@@YAHPEAGH@Z
0x140047F80: "Failed to query soft reboot flag" ??_C@_1FE@KNJEFHEL@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAq?$AAu?$AAe?$AAr?$AAy?$AA?5?$AAs?$AAo?$AAf?$AAt?$AA?5?$AAr?$AAe?$AAb?$AAo?$AAo?$AAt?$AA?5?$AAf?$AAl?$AAa?$AAg@
0x140034FE4: MicrosoftTelemetryAssertTriggeredNoArgs
0x14002B610: "int __cdecl CreateUserEnvironment(void * __ptr64 * __ptr64)" ?CreateUserEnvironment@@YAHPEAPEAX@Z
0x140004ED8: IsUserMinInitializePresent
0x1400542F8: ext-ms-win-core-stateseparationext-l1-1-0_NULL_THUNK_DATA_DLN
0x14004B4E8: "RestoreModule" ??_C@_1BM@PLHCBBKD@?$AAR?$AAe?$AAs?$AAt?$AAo?$AAr?$AAe?$AAM?$AAo?$AAd?$AAu?$AAl?$AAe?$AA?$AA@
0x14004EEE8: "__cdecl _DefaultResolveDelayLoadedAPIFlags" __DefaultResolveDelayLoadedAPIFlags
0x14003BDE8: BiDeleteRegistryValue
0x140046038: "__cdecl _imp_GetBasicProfileFolderPath" __imp_GetBasicProfileFolderPath
0x140040984: BiRemoveBootEntryFromNvramDisplayOrder
0x14004EEF8: "N/A" ??_C@_17HDJIHIPC@?$AAN?$AA?1?$AAA?$AA?$AA@
0x14003F0A8: BiCreateEfiEntry
0x140054B34: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-threadpool-legacy-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-threadpool-legacy-l1-1-0
0x14002DFC4: "unsigned long __cdecl WppStart(unsigned char,unsigned long)" ?WppStart@@YAKEK@Z
0x140046040: profapi_NULL_THUNK_DATA
0x140045448: "__cdecl _imp_RpcBindingCopy" __imp_RpcBindingCopy
0x140058DD8: "__cdecl _hmod__api_ms_win_service_management_l1_1_0_dll" __hmod__api_ms_win_service_management_l1_1_0_dll
0x14003DCCC: BiAdjustPrivilege
0x140046990: "ext-ms-win-session-wininit-l1-1-" ??_C@_1EE@GBEPNPJC@?$AAe?$AAx?$AAt?$AA?9?$AAm?$AAs?$AA?9?$AAw?$AAi?$AAn?$AA?9?$AAs?$AAe?$AAs?$AAs?$AAi?$AAo?$AAn?$AA?9?$AAw?$AAi?$AAn?$AAi?$AAn?$AAi?$AAt?$AA?9?$AAl?$AA1?$AA?9?$AA1?$AA?9@
0x140058D60: "__cdecl _hmod__ext_ms_win_session_wtsapi32_l1_1_0_dll" __hmod__ext_ms_win_session_wtsapi32_l1_1_0_dll
0x140033DAC: KsrpOpenDriver
0x1400547A8: ext-ms-win-ntuser-misc-l1-1-0_NULL_THUNK_DATA_DLB
0x140048A70: "<unknown>" ??_C@_09EEKGDCPH@?$DMunknown?$DO?$AA@
0x140048EE0: "ZwQuerySystemEnvironmentValueEx" ??_C@_0CA@GPGPKBND@ZwQuerySystemEnvironmentValueEx?$AA@
0x140004036: "__cdecl get_narrow_winmain_command_line" _get_narrow_winmain_command_line
0x14004C170: "Failed to open the system BCD st" ??_C@_1FI@PACOFNLA@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAo?$AAp?$AAe?$AAn?$AA?5?$AAt?$AAh?$AAe?$AA?5?$AAs?$AAy?$AAs?$AAt?$AAe?$AAm?$AA?5?$AAB?$AAC?$AAD?$AA?5?$AAs?$AAt@
0x140038A38: BiGetObjectDescription
0x14003E178: BiBindEfiBootManager
0x1400542C0: ext-ms-onecore-shellchromeapi-l1-1-1_NULL_THUNK_DATA_DLN
0x1400490C8: "ZwSetBootOptions" ??_C@_0BB@COOOOIJN@ZwSetBootOptions?$AA@
0x140047B10: "Failed to complete prepare of th" ??_C@_1HA@LANHFGGM@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAc?$AAo?$AAm?$AAp?$AAl?$AAe?$AAt?$AAe?$AA?5?$AAp?$AAr?$AAe?$AAp?$AAa?$AAr?$AAe?$AA?5?$AAo?$AAf?$AA?5?$AAt?$AAh@
0x140054858: ext-ms-onecore-shellchromeapi-l1-1-1_NULL_THUNK_DATA_DLB
0x14005C0D0: ext-ms-onecore-shellchromeapi-l1-1-1_NULL_THUNK_DATA_DLA
0x140003FBE: "__cdecl o___p__commode" _o___p__commode
0x140058CD8: "__cdecl _hmod__api_ms_win_security_sddl_l1_1_0_dll" __hmod__api_ms_win_security_sddl_l1_1_0_dll
0x14004D120: "\\?\GLOBALROOT" ??_C@_1BO@NLDNEEHD@?$AA?2?$AA?2?$AA?$DP?$AA?2?$AAG?$AAL?$AAO?$AAB?$AAA?$AAL?$AAR?$AAO?$AAO?$AAT?$AA?$AA@
0x14004C090: "\INSTALLATION_SECURITY_HOLD" ??_C@_1DI@BLPBBHKL@?$AA?2?$AAI?$AAN?$AAS?$AAT?$AAA?$AAL?$AAL?$AAA?$AAT?$AAI?$AAO?$AAN?$AA_?$AAS?$AAE?$AAC?$AAU?$AAR?$AAI?$AAT?$AAY?$AA_?$AAH?$AAO?$AAL?$AAD?$AA?$AA@
0x14004C230: "Failed to read the default boot " ??_C@_1FM@IHCDPNND@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAr?$AAe?$AAa?$AAd?$AA?5?$AAt?$AAh?$AAe?$AA?5?$AAd?$AAe?$AAf?$AAa?$AAu?$AAl?$AAt?$AA?5?$AAb?$AAo?$AAo?$AAt?$AA?5@
0x140003A60: "__cdecl initialize_denormal_control" _initialize_denormal_control
0x1400461D0: WIEvt_ReceivedShutdownRequest_Info
0x1400509B0: "Failed load key %ws. Flags: 0x%x" ??_C@_1GK@DIJEAAAL@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAl?$AAo?$AAa?$AAd?$AA?5?$AAk?$AAe?$AAy?$AA?5?$AA?$CF?$AAw?$AAs?$AA?4?$AA?5?$AAF?$AAl?$AAa?$AAg?$AAs?$AA?3?$AA?5?$AA0?$AAx?$AA?$CF?$AAx@
0x1400459E8: "__cdecl _imp_exit" __imp_exit
0x140033D14: KsrpLoadUnloadDriver
0x140047CE8: "\??\" ??_C@_19JHEHLFPM@?$AA?2?$AA?$DP?$AA?$DP?$AA?2?$AA?$AA@
0x1400581E8: KsrpServiceDefaultInstance
0x140024FD0: "int __cdecl SetProcessPriority(void)" ?SetProcessPriority@@YAHXZ
0x140045F68: "__cdecl _imp_ZwQueryInformationFile" __imp_ZwQueryInformationFile
0x140045F18: "__cdecl _imp_ZwDeleteValueKey" __imp_ZwDeleteValueKey
0x1400590C4: "int IgnoreSystemProcessDeath" ?IgnoreSystemProcessDeath@@3HA
0x14004AAA8: "WindowsShutdown" ??_C@_1CA@ENPDKOBA@?$AAW?$AAi?$AAn?$AAd?$AAo?$AAw?$AAs?$AAS?$AAh?$AAu?$AAt?$AAd?$AAo?$AAw?$AAn?$AA?$AA@
0x140003FEE: "__cdecl o___stdio_common_vswscanf" _o___stdio_common_vswscanf
0x140059248: g_pSidSystem
0x1400021D0: WmsgpPostMessage
0x140059320: "int g_fWinPEMode" ?g_fWinPEMode@@3HA
0x140003948: atexit
0x140046A60: "__cdecl _sz_ext_ms_win_onecore_shutdown_l1_1_0_dll" __sz_ext_ms_win_onecore_shutdown_l1_1_0_dll
0x140046B10: "ext-ms-onecore-shellchromeapi-l1" ??_C@_1EK@GNBGAIJN@?$AAe?$AAx?$AAt?$AA?9?$AAm?$AAs?$AA?9?$AAo?$AAn?$AAe?$AAc?$AAo?$AAr?$AAe?$AA?9?$AAs?$AAh?$AAe?$AAl?$AAl?$AAc?$AAh?$AAr?$AAo?$AAm?$AAe?$AAa?$AAp?$AAi?$AA?9?$AAl?$AA1@
0x140045BD0: "__cdecl _imp_RtlInitializeCriticalSection" __imp_RtlInitializeCriticalSection
0x1400463F0: "__cdecl _sz_api_ms_win_rtcore_ntuser_private_l1_1_2_dll" __sz_api_ms_win_rtcore_ntuser_private_l1_1_2_dll
0x1400470E0: "Software\Microsoft\Windows NT\Cu" ??_C@_1GM@NFOGLLJA@?$AAS?$AAo?$AAf?$AAt?$AAw?$AAa?$AAr?$AAe?$AA?2?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAW?$AAi?$AAn?$AAd?$AAo?$AAw?$AAs?$AA?5?$AAN?$AAT?$AA?2?$AAC?$AAu@
0x140046000: "__cdecl _imp_NtEnumerateBootEntries" __imp_NtEnumerateBootEntries
0x140005370: "__cdecl TlgDefineProvider_annotation__Tlgg_hWininitTraceLoggingProviderProv" _TlgDefineProvider_annotation__Tlgg_hWininitTraceLoggingProviderProv
0x140004042: "__cdecl o__initialize_narrow_environment" _o__initialize_narrow_environment
0x14005C0C8: "__cdecl _imp_Shell_RequestShutdown" __imp_Shell_RequestShutdown
0x140046EE0: MS_Wininit_Provider
0x1400456A0: "__cdecl _imp_LoadLibraryExA" __imp_LoadLibraryExA
0x140003F9A: "__cdecl register_thread_local_exe_atexit_callback" _register_thread_local_exe_atexit_callback
0x14004B030: "Software\Microsoft\Windows\Curre" ??_C@_1FE@JJLIONGF@?$AAS?$AAo?$AAf?$AAt?$AAw?$AAa?$AAr?$AAe?$AA?2?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAW?$AAi?$AAn?$AAd?$AAo?$AAw?$AAs?$AA?2?$AAC?$AAu?$AAr?$AAr?$AAe@
0x140046DF0: "__cdecl _sz_ext_ms_win_ntuser_windowstation_l1_1_0_dll" __sz_ext_ms_win_ntuser_windowstation_l1_1_0_dll
0x140045C10: "__cdecl _imp_RtlRemovePrivileges" __imp_RtlRemovePrivileges
0x140027118: "unsigned long __cdecl WinInitShutdown(enum _SHUTDOWN_ACTION,unsigned long)" ?WinInitShutdown@@YAKW4_SHUTDOWN_ACTION@@K@Z
0x1400510E0: "BiBuildIdentifierList failed %x" ??_C@_1EA@PJHIKFCF@?$AAB?$AAi?$AAB?$AAu?$AAi?$AAl?$AAd?$AAI?$AAd?$AAe?$AAn?$AAt?$AAi?$AAf?$AAi?$AAe?$AAr?$AAL?$AAi?$AAs?$AAt?$AA?5?$AAf?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AA?$CF?$AAx?$AA?$AA@
0x1400043AA: "__cdecl _imp_load_CapabilityCheck" __imp_load_CapabilityCheck
0x140059290: g_pSidService
0x140045CE8: "__cdecl _imp_NtAdjustPrivilegesToken" __imp_NtAdjustPrivilegesToken
0x14000537C: KsrpGetScenario
0x14003445C: KsrpConvertWin32ErrorToNtstatus
0x140037B10: BiGetCurrentBcdMutantHandle
0x14003F6C4: BiDeleteEfiVariable
0x140046480: "__cdecl _sz_ext_ms_win_core_stateseparationext_l1_1_0_dll" __sz_ext_ms_win_core_stateseparationext_l1_1_0_dll
0x14004EFC0: "BcdGetElementDataWithFlags: Fail" ??_C@_1JO@HHKLDKGJ@?$AAB?$AAc?$AAd?$AAG?$AAe?$AAt?$AAE?$AAl?$AAe?$AAm?$AAe?$AAn?$AAt?$AAD?$AAa?$AAt?$AAa?$AAW?$AAi?$AAt?$AAh?$AAF?$AAl?$AAa?$AAg?$AAs?$AA?3?$AA?5?$AAF?$AAa?$AAi?$AAl@
0x1400406A4: BiLookupObjectByBootEntry
0x140045870: "__cdecl _imp_EnterCriticalSection" __imp_EnterCriticalSection
0x14004A408: WIEvt_WaitForSystemProcesses_Start
0x14005C1A8: "__cdecl _imp_WTSEnumerateSessionsW" __imp_WTSEnumerateSessionsW
0x140054750: api-ms-win-security-capability-l1-1-0_NULL_THUNK_DATA_DLB
0x140026568: "unsigned long __cdecl UpdateTcpIpParameters(void)" ?UpdateTcpIpParameters@@YAKXZ
0x140045840: api-ms-win-core-registry-l1-1-0_NULL_THUNK_DATA
0x14002F4FC: RegisterWMsgServer
0x140051448: "\Boot\BCD" ??_C@_1BE@FGPPDGFO@?$AA?2?$AAB?$AAo?$AAo?$AAt?$AA?2?$AAB?$AAC?$AAD?$AA?$AA@
0x140003A48: "__cdecl _scrt_stub_for_acrt_initialize" __scrt_stub_for_acrt_initialize
0x1400474B8: "SaveDumpStart" ??_C@_1BM@DPDFFDID@?$AAS?$AAa?$AAv?$AAe?$AAD?$AAu?$AAm?$AAp?$AAS?$AAt?$AAa?$AAr?$AAt?$AA?$AA@
0x140045570: api-ms-win-core-errorhandling-l1-1-0_NULL_THUNK_DATA
0x1400018D0: "void __cdecl StartSystemShutdownCallback(void * __ptr64,unsigned char)" ?StartSystemShutdownCallback@@YAXPEAXE@Z
0x140045690: api-ms-win-core-kernel32-legacy-l1-1-0_NULL_THUNK_DATA
0x14004B0A0: "System\CurrentControlSet\Control" ??_C@_1FC@KHEJADA@?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AA?2?$AAC?$AAu?$AAr?$AAr?$AAe?$AAn?$AAt?$AAC?$AAo?$AAn?$AAt?$AAr?$AAo?$AAl?$AAS?$AAe?$AAt?$AA?2?$AAC?$AAo?$AAn?$AAt?$AAr?$AAo?$AAl@
0x1400459D8: "__cdecl _imp__wcsupr" __imp__wcsupr
0x140040DF0: BiTranslateObjectIdentifier
0x14004BE60: "DbgBreakPoint" ??_C@_0O@ODHAJHCA@DbgBreakPoint?$AA@
0x14004A5F8: "Hostname" ??_C@_1BC@FICMKHCF@?$AAH?$AAo?$AAs?$AAt?$AAn?$AAa?$AAm?$AAe?$AA?$AA@
0x14002BA90: "int __cdecl SetFileSecurityDescriptor(unsigned short const * __ptr64,unsigned short const * __ptr64)" ?SetFileSecurityDescriptor@@YAHPEBG0@Z
0x1400476E8: "Headless" ??_C@_1BC@OLEKLNFL@?$AAH?$AAe?$AAa?$AAd?$AAl?$AAe?$AAs?$AAs?$AA?$AA@
0x1400542B0: api-ms-win-service-winsvc-l1-1-0_NULL_THUNK_DATA_DLN
0x1400460B0: "__cdecl _xt_a" __xt_a
0x140058CD0: "__cdecl _scrt_debugger_hook_flag" __scrt_debugger_hook_flag
0x14004BEC8: "ProgramData" ??_C@_1BI@PCFBINBH@?$AAP?$AAr?$AAo?$AAg?$AAr?$AAa?$AAm?$AAD?$AAa?$AAt?$AAa?$AA?$AA@
0x140045768: "__cdecl _imp_GetCurrentProcess" __imp_GetCurrentProcess
0x1400548B8: api-ms-win-service-winsvc-l1-1-0_NULL_THUNK_DATA_DLB
0x140048F80: "Failed to delete "%ws" variable." ??_C@_1FI@CPKADNBM@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAd?$AAe?$AAl?$AAe?$AAt?$AAe?$AA?5?$AA?$CC?$AA?$CF?$AAw?$AAs?$AA?$CC?$AA?5?$AAv?$AAa?$AAr?$AAi?$AAa?$AAb?$AAl?$AAe?$AA?4@
0x14005C0C0: api-ms-win-service-winsvc-l1-1-0_NULL_THUNK_DATA_DLA
0x14004CD90: "NtDeleteKey(ServiceKey\Enum) fai" ??_C@_1FI@KFMANODH@?$AAN?$AAt?$AAD?$AAe?$AAl?$AAe?$AAt?$AAe?$AAK?$AAe?$AAy?$AA?$CI?$AAS?$AAe?$AAr?$AAv?$AAi?$AAc?$AAe?$AAK?$AAe?$AAy?$AA?2?$AAE?$AAn?$AAu?$AAm?$AA?$CJ?$AA?5?$AAf?$AAa?$AAi@
0x14004C1D0: "Failed to open the BOOTMGR objec" ??_C@_1FE@JHAKBGLH@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAo?$AAp?$AAe?$AAn?$AA?5?$AAt?$AAh?$AAe?$AA?5?$AAB?$AAO?$AAO?$AAT?$AAM?$AAG?$AAR?$AA?5?$AAo?$AAb?$AAj?$AAe?$AAc@
0x140034DD4: "public: void __cdecl SP<unsigned long,class SP_MEM<unsigned long> >::Attach(unsigned long * __ptr64) __ptr64" ?Attach@?$SP@KV?$SP_MEM@K@@@@QEAAXPEAK@Z
0x1400236D0: "unsigned long __cdecl GetLsaConfigurationValue(enum LSAP_STARTUP_CONFIG_INDEX,unsigned long * __ptr64,int * __ptr64,int * __ptr64)" ?GetLsaConfigurationValue@@YAKW4LSAP_STARTUP_CONFIG_INDEX@@PEAKPEAH2@Z
0x140045AD0: "__cdecl _imp_strncmp" __imp_strncmp
0x1400384B0: BcdDeleteObject
0x14002B958: "unsigned long __cdecl ReportWininitEvent(unsigned short,unsigned long,unsigned long,void * __ptr64,unsigned long,...)" ?ReportWininitEvent@@YAKGKKPEAXKZZ
0x140034DD4: "public: void __cdecl SP<unsigned char,class SP_MEM<unsigned char> >::Attach(unsigned char * __ptr64) __ptr64" ?Attach@?$SP@EV?$SP_MEM@E@@@@QEAAXPEAE@Z
0x140004E58: "__cdecl _tailMerge_ext_ms_win_coreui_navshutdown_l1_1_0_dll" __tailMerge_ext_ms_win_coreui_navshutdown_l1_1_0_dll
0x140034DD4: "public: void __cdecl SP<unsigned short,class SP_MEM<unsigned short> >::Attach(unsigned short * __ptr64) __ptr64" ?Attach@?$SP@GV?$SP_MEM@G@@@@QEAAXPEAG@Z
0x140002A10: NotifyPostCompletion
0x14004049C: BiHandleFirmwareDefaultEntry
0x14003FDF4: BiExportStoreAlterationsToEfi
0x1400045C0: "__cdecl _tailMerge_ext_ms_win_core_stateseparationext_l1_1_0_dll" __tailMerge_ext_ms_win_core_stateseparationext_l1_1_0_dll
0x140004B80: "__cdecl _tailMerge_ext_ms_win_onecore_shutdown_l1_1_0_dll" __tailMerge_ext_ms_win_onecore_shutdown_l1_1_0_dll
0x140045CF0: "__cdecl _imp_NtDeleteWnfStateName" __imp_NtDeleteWnfStateName
0x140029DD8: "long __cdecl MyRpcpStartRpcServer(unsigned short const * __ptr64,void * __ptr64)" ?MyRpcpStartRpcServer@@YAJPEBGPEAX@Z
0x14004B7B8: "UIVerbosityLevel" ??_C@_1CC@HLPMLGGJ@?$AAU?$AAI?$AAV?$AAe?$AAr?$AAb?$AAo?$AAs?$AAi?$AAt?$AAy?$AAL?$AAe?$AAv?$AAe?$AAl?$AA?$AA@
0x1400454A8: "__cdecl _imp_RpcExceptionFilter" __imp_RpcExceptionFilter
0x140042F04: SiOpenArcNameObject
0x140045498: "__cdecl _imp_UuidFromStringW" __imp_UuidFromStringW
0x140038328: BiSetFirmwareModifiedFromObject
0x140003D60: "__cdecl RTC_Terminate" _RTC_Terminate
0x14003D680: BiFilterDoOperation
0x140045488: "__cdecl _imp_RpcServerInqBindings" __imp_RpcServerInqBindings
0x140005AE8: "__cdecl _GSHandlerCheck_SEH" __GSHandlerCheck_SEH
0x140054A80: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-string-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-string-l1-1-0
0x1400459C0: "__cdecl _imp__wcsicmp" __imp__wcsicmp
0x140045A00: "__cdecl _imp_wcscat_s" __imp_wcscat_s
0x140046F20: WIEvt_Wininit_Lsa_Iso_Key_Guard
0x140045A70: "__cdecl _imp___C_specific_handler" __imp___C_specific_handler
0x140047900: "SOFTWARE\Microsoft\Windows NT\Cu" ??_C@_1FK@EDIIEKBJ@?$AAS?$AAO?$AAF?$AAT?$AAW?$AAA?$AAR?$AAE?$AA?2?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAW?$AAi?$AAn?$AAd?$AAo?$AAw?$AAs?$AA?5?$AAN?$AAT?$AA?2?$AAC?$AAu@
0x140059234: "int g_fRunSetup" ?g_fRunSetup@@3HA
0x14003B538: BiVerifyBootPartition
0x14004B988: "%s\%s" ??_C@_1M@DFKENGJN@?$AA?$CF?$AAs?$AA?2?$AA?$CF?$AAs?$AA?$AA@
0x1400461E0: "QueryIsDiskCheckScheduledForNext" ??_C@_0CF@DFDEMOPG@QueryIsDiskCheckScheduledForNext@
0x140045790: "__cdecl _imp_ResumeThread" __imp_ResumeThread
0x140045EA8: "__cdecl _imp_RtlCaptureContext" __imp_RtlCaptureContext
0x1400456F0: api-ms-win-core-libraryloader-l1-2-0_NULL_THUNK_DATA
0x14003CDA8: BiUnloadHiveByHandle
0x14004A3D8: WLEvt_WluiServerStartup_Start
0x14004AFC0: "ProgramW6432" ??_C@_1BK@IEDNHAFM@?$AAP?$AAr?$AAo?$AAg?$AAr?$AAa?$AAm?$AAW?$AA6?$AA4?$AA3?$AA2?$AA?$AA@
0x140004036: "__cdecl o__get_narrow_winmain_command_line" _o__get_narrow_winmain_command_line
0x140054BE8: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-eventing-provider-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-eventing-provider-l1-1-0
0x140032B50: KsrpPrepare
0x140045900: "__cdecl _imp_GetWindowsDirectoryW" __imp_GetWindowsDirectoryW
0x140004A58: "__cdecl _tailMerge_ext_ms_win_session_wininit_l1_1_0_dll" __tailMerge_ext_ms_win_session_wininit_l1_1_0_dll
0x140046220: WIEvt_SentLogoffRequest_Info
0x140045E98: "__cdecl _imp_WinSqmAddToStream" __imp_WinSqmAddToStream
0x140048CE0: "Created boot entry 0x%x using ca" ??_C@_1FM@ILDKKABF@?$AAC?$AAr?$AAe?$AAa?$AAt?$AAe?$AAd?$AA?5?$AAb?$AAo?$AAo?$AAt?$AA?5?$AAe?$AAn?$AAt?$AAr?$AAy?$AA?5?$AA0?$AAx?$AA?$CF?$AAx?$AA?5?$AAu?$AAs?$AAi?$AAn?$AAg?$AA?5?$AAc?$AAa@
0x140045568: "__cdecl _imp_GetLastError" __imp_GetLastError
0x140046360: "__cdecl _sz_api_ms_win_service_private_l1_1_0_dll" __sz_api_ms_win_service_private_l1_1_0_dll
0x140002F20: I_WMsgSendNotifyMessage
0x1400586E4: "unsigned long s_VerbosityLevel" ?s_VerbosityLevel@@3KA
0x1400590C8: "void * __ptr64 __ptr64 g_hWinlogonLogOffEvent" ?g_hWinlogonLogOffEvent@@3PEAXEA
0x140045B38: api-ms-win-eventing-provider-l1-1-0_NULL_THUNK_DATA
0x1400048E0: IsWTSDisconnectSessionPresent
0x140030880: "long __cdecl MyUnhandledExceptionFilter(struct _EXCEPTION_POINTERS * __ptr64)" ?MyUnhandledExceptionFilter@@YAJPEAU_EXCEPTION_POINTERS@@@Z
0x140001DF0: "int __cdecl WMsgBroadcastMessageHandler(unsigned long,unsigned long,struct _RPC_ASYNC_STATE * __ptr64,long * __ptr64)" ?WMsgBroadcastMessageHandler@@YAHKKPEAU_RPC_ASYNC_STATE@@PEAJ@Z
0x14004AC20: "DisableShutdownNamedPipe" ??_C@_1DC@JDKKMJKK@?$AAD?$AAi?$AAs?$AAa?$AAb?$AAl?$AAe?$AAS?$AAh?$AAu?$AAt?$AAd?$AAo?$AAw?$AAn?$AAN?$AAa?$AAm?$AAe?$AAd?$AAP?$AAi?$AAp?$AAe?$AA?$AA@
0x140038C58: BiSetObjectDescription
0x140005A60: "__cdecl _GSHandlerCheck" __GSHandlerCheck
0x140034828: KsrpGetDriversPathForWimBoot
0x140030F94: SetProfilesLocation
0x14002D534: "void __cdecl ExtractVersionInfo(unsigned short const * __ptr64,unsigned short * __ptr64,unsigned long)" ?ExtractVersionInfo@@YAXPEBGPEAGK@Z
0x14002AE00: s_BaseInitiateShutdownEx
0x1400056E4: SiQuerySystemInformationString
0x140045F00: "__cdecl _imp_RtlSetOwnerSecurityDescriptor" __imp_RtlSetOwnerSecurityDescriptor
0x1400276CC: "unsigned long __cdecl WinInitStartUp(void)" ?WinInitStartUp@@YAKXZ
0x140046D30: "__cdecl _sz_api_ms_win_base_bootconfig_l1_1_0_dll" __sz_api_ms_win_base_bootconfig_l1_1_0_dll
0x14004FAA0: "BcdForciblyUnloadStore: Failed t" ??_C@_1IM@KDHDNKKJ@?$AAB?$AAc?$AAd?$AAF?$AAo?$AAr?$AAc?$AAi?$AAb?$AAl?$AAy?$AAU?$AAn?$AAl?$AAo?$AAa?$AAd?$AAS?$AAt?$AAo?$AAr?$AAe?$AA?3?$AA?5?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt@
0x140048F20: "Failed to query "%ws" variable. " ??_C@_1FG@DNDJJFMI@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAq?$AAu?$AAe?$AAr?$AAy?$AA?5?$AA?$CC?$AA?$CF?$AAw?$AAs?$AA?$CC?$AA?5?$AAv?$AAa?$AAr?$AAi?$AAa?$AAb?$AAl?$AAe?$AA?4?$AA?5@
0x140005830: SiGetBootDeviceName
0x140045E88: "__cdecl _imp_EtwTraceMessage" __imp_EtwTraceMessage
0x140047BD8: "Preparing for Soft Restart" ??_C@_1DG@PFBMPFEI@?$AAP?$AAr?$AAe?$AAp?$AAa?$AAr?$AAi?$AAn?$AAg?$AA?5?$AAf?$AAo?$AAr?$AA?5?$AAS?$AAo?$AAf?$AAt?$AA?5?$AAR?$AAe?$AAs?$AAt?$AAa?$AAr?$AAt?$AA?$AA@
0x14004B0F8: "%SystemRoot%\temp" ??_C@_1CE@JMFHEBIF@?$AA?$CF?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AAR?$AAo?$AAo?$AAt?$AA?$CF?$AA?2?$AAt?$AAe?$AAm?$AAp?$AA?$AA@
0x140046610: "ext-ms-win-ntuser-private-l1-1-0" ??_C@_1EC@HNNKKNDA@?$AAe?$AAx?$AAt?$AA?9?$AAm?$AAs?$AA?9?$AAw?$AAi?$AAn?$AA?9?$AAn?$AAt?$AAu?$AAs?$AAe?$AAr?$AA?9?$AAp?$AAr?$AAi?$AAv?$AAa?$AAt?$AAe?$AA?9?$AAl?$AA1?$AA?9?$AA1?$AA?9?$AA0@
0x14005C048: api-ms-win-security-capability-l1-1-0_NULL_THUNK_DATA_DLA
0x140004042: "__cdecl initialize_narrow_environment" _initialize_narrow_environment
0x14004D140: "\system32\drivers\winload.sys" ??_C@_1DM@BKHADDEK@?$AA?2?$AAs?$AAy?$AAs?$AAt?$AAe?$AAm?$AA3?$AA2?$AA?2?$AAd?$AAr?$AAi?$AAv?$AAe?$AAr?$AAs?$AA?2?$AAw?$AAi?$AAn?$AAl?$AAo?$AAa?$AAd?$AA?4?$AAs?$AAy?$AAs?$AA?$AA@
0x140045A88: "__cdecl _imp_memcmp" __imp_memcmp
0x14004C450: "The target VHD is expected to be" ??_C@_1IE@OMMJHNFF@?$AAT?$AAh?$AAe?$AA?5?$AAt?$AAa?$AAr?$AAg?$AAe?$AAt?$AA?5?$AAV?$AAH?$AAD?$AA?5?$AAi?$AAs?$AA?5?$AAe?$AAx?$AAp?$AAe?$AAc?$AAt?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAb?$AAe@
0x140003FCA: "__cdecl o___stdio_common_vsnwprintf_s" _o___stdio_common_vsnwprintf_s
0x14004CB50: "DEVICE: Partition: '%ws'" ??_C@_1DC@BIPAFCDL@?$AAD?$AAE?$AAV?$AAI?$AAC?$AAE?$AA?3?$AA?5?$AAP?$AAa?$AAr?$AAt?$AAi?$AAt?$AAi?$AAo?$AAn?$AA?3?$AA?5?$AA?8?$AA?$CF?$AAw?$AAs?$AA?8?$AA?$AA@
0x140005000: Ndr64AsyncServerCallAll
0x140046420: "ext-ms-win-core-stateseparatione" ??_C@_1FE@FHIBAPKJ@?$AAe?$AAx?$AAt?$AA?9?$AAm?$AAs?$AA?9?$AAw?$AAi?$AAn?$AA?9?$AAc?$AAo?$AAr?$AAe?$AA?9?$AAs?$AAt?$AAa?$AAt?$AAe?$AAs?$AAe?$AAp?$AAa?$AAr?$AAa?$AAt?$AAi?$AAo?$AAn?$AAe@
0x1400245F0: "long __cdecl ReadLsaConfigEnvironmentVariable(enum LSAP_STARTUP_CONFIG_INDEX,unsigned long * __ptr64)" ?ReadLsaConfigEnvironmentVariable@@YAJW4LSAP_STARTUP_CONFIG_INDEX@@PEAK@Z
0x14003F80C: BiEnumerateBootEntries
0x1400454B8: "__cdecl _imp_RpcBindingCreateW" __imp_RpcBindingCreateW
0x14004F200: "Failed to open key for object's " ??_C@_1GK@DGBKFFHL@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAo?$AAp?$AAe?$AAn?$AA?5?$AAk?$AAe?$AAy?$AA?5?$AAf?$AAo?$AAr?$AA?5?$AAo?$AAb?$AAj?$AAe?$AAc?$AAt?$AA?8?$AAs?$AA?5@
0x140047AC8: "Failed to allocate the memory" ??_C@_1DM@MMHGDIN@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAa?$AAl?$AAl?$AAo?$AAc?$AAa?$AAt?$AAe?$AA?5?$AAt?$AAh?$AAe?$AA?5?$AAm?$AAe?$AAm?$AAo?$AAr?$AAy?$AA?$AA@
0x140003A28: "__cdecl get_startup_file_mode" _get_startup_file_mode
0x140045FC0: "__cdecl _imp_NtDeviceIoControlFile" __imp_NtDeviceIoControlFile
0x14004A478: WLEvt_WluiServerStartup_Stop
0x140045D98: "__cdecl _imp_ZwCreateFile" __imp_ZwCreateFile
0x1400459D0: "__cdecl _imp__o__wcsnicmp" __imp__o__wcsnicmp
0x1400312F0: WaitForDesiredService
0x140045E70: "__cdecl _imp_RtlAdjustPrivilege" __imp_RtlAdjustPrivilege
0x14004ADE0: "System\CurrentControlSet\Control" ??_C@_1HK@MKBHAIFE@?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AA?2?$AAC?$AAu?$AAr?$AAr?$AAe?$AAn?$AAt?$AAC?$AAo?$AAn?$AAt?$AAr?$AAo?$AAl?$AAS?$AAe?$AAt?$AA?2?$AAC?$AAo?$AAn?$AAt?$AAr?$AAo?$AAl@
0x140046E50: WIEvt_Wininit_Lsa_Ppl
0x14004A4C0: "(null)" ??_C@_1O@CEDCILHN@?$AA?$CI?$AAn?$AAu?$AAl?$AAl?$AA?$CJ?$AA?$AA@
0x140034E1C: "public: static bool __cdecl SP<unsigned short * __ptr64,class SP_MEM<unsigned short * __ptr64> >::IsNull(unsigned short * __ptr64 * __ptr64)" ?IsNull@?$SP@PEAGV?$SP_MEM@PEAG@@@@SA_NPEAPEAG@Z
0x140058414: "__cdecl _isa_enabled" __isa_enabled
0x140045B48: "__cdecl _imp_EqualSid" __imp_EqualSid
0x140004435: "__cdecl _imp_load_RegisterEventSourceW" __imp_load_RegisterEventSourceW
0x14002354C: "unsigned short * __ptr64 __cdecl GetExePathAndOptions(unsigned short const * __ptr64,enum SYSTEM_PROCESS_TYPE,unsigned short const * __ptr64)" ?GetExePathAndOptions@@YAPEAGPEBGW4SYSTEM_PROCESS_TYPE@@0@Z
0x1400494F8: "RunasPPLTest" ??_C@_1BK@BPFJMAEH@?$AAR?$AAu?$AAn?$AAa?$AAs?$AAP?$AAP?$AAL?$AAT?$AAe?$AAs?$AAt?$AA?$AA@
0x14004A4A8: "NULL" ??_C@_19CIJIHAKK@?$AAN?$AAU?$AAL?$AAL?$AA?$AA@
0x140046E60: WIEvt_Wininit_Lsa_Iso_Config
0x140058DE0: "__cdecl _hmod__api_ms_win_service_winsvc_l1_1_0_dll" __hmod__api_ms_win_service_winsvc_l1_1_0_dll
0x14004A3F8: WIEvt_FullShutdown_Info
0x140046EC0: WIEvt_Wininit_Lsa_Iso
0x140059324: "int g_fExecuteSetup" ?g_fExecuteSetup@@3HA
0x140054C10: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-delayload-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-delayload-l1-1-0
0x140045710: "__cdecl _imp_GetCurrentProcessId" __imp_GetCurrentProcessId
0x140058CE0: "__cdecl _hmod__api_ms_win_service_private_l1_1_0_dll" __hmod__api_ms_win_service_private_l1_1_0_dll
0x140045888: "__cdecl _imp_WaitForSingleObject" __imp_WaitForSingleObject
0x14003937C: BiConvertBootEnvironmentDeviceToQualifiedPartition
0x14004CCE0: "DEVICE: UnsupportedType %d" ??_C@_1DG@CPMKLNE@?$AAD?$AAE?$AAV?$AAI?$AAC?$AAE?$AA?3?$AA?5?$AAU?$AAn?$AAs?$AAu?$AAp?$AAp?$AAo?$AAr?$AAt?$AAe?$AAd?$AAT?$AAy?$AAp?$AAe?$AA?5?$AA?$CF?$AAd?$AA?$AA@
0x1400483E0: "Failed to set 'Flags' value, %#0" ??_C@_1EI@HBKOILNC@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAs?$AAe?$AAt?$AA?5?$AA?8?$AAF?$AAl?$AAa?$AAg?$AAs?$AA?8?$AA?5?$AAv?$AAa?$AAl?$AAu?$AAe?$AA?0?$AA?5?$AA?$CF?$AA?$CD?$AA0@
0x14000541C: KsrpSetSoftRebootFlags
0x140054B5C: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-heap-obsolete-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-heap-obsolete-l1-1-0
0x140047240: "\Registry\Machine\System\Current" ??_C@_1JK@IIJAPNAK@?$AA?2?$AAR?$AAe?$AAg?$AAi?$AAs?$AAt?$AAr?$AAy?$AA?2?$AAM?$AAa?$AAc?$AAh?$AAi?$AAn?$AAe?$AA?2?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AA?2?$AAC?$AAu?$AAr?$AAr?$AAe?$AAn?$AAt@
0x140033E70: KsrpRegisterAndLoadDriver
0x140058470: "unsigned short * DontWatchSysProcs" ?DontWatchSysProcs@@3PAGA
0x140049E08: "Instances" ??_C@_1BE@MFOLOKJL@?$AAI?$AAn?$AAs?$AAt?$AAa?$AAn?$AAc?$AAe?$AAs?$AA?$AA@
0x1400581D8: KsrpServiceInstances
0x140035AE4: BiConvertBcdElements
0x140045800: "__cdecl _imp_RegDeleteValueW" __imp_RegDeleteValueW
0x14002B648: "unsigned long __cdecl CreateWindirTemp(void)" ?CreateWindirTemp@@YAKXZ
0x14000404E: "__cdecl initialize_onexit_table" _initialize_onexit_table
0x14004EEE8: "__cdecl _ResolveDelayLoadedAPIFlags" __ResolveDelayLoadedAPIFlags
0x1400459F8: "__cdecl _imp__o_toupper" __imp__o_toupper
0x140003160: "__cdecl _scrt_stub_for_initialize_mta" __scrt_stub_for_initialize_mta
0x140058C78: "__cdecl _scrt_native_startup_lock" __scrt_native_startup_lock
0x140024250: "void __cdecl LogAppInitDllsCallback(void * __ptr64,unsigned char)" ?LogAppInitDllsCallback@@YAXPEAXE@Z
0x14003FE94: BiFreeIdentifierList
0x140030C7C: Breakin
0x140059280: g_pSidRestricted
0x140045FE8: "__cdecl _imp_NtTranslateFilePath" __imp_NtTranslateFilePath
0x140004110: "__cdecl vsnwprintf_s" _vsnwprintf_s
0x140046700: "ext-ms-win-ntuser-private-l1-3-1" ??_C@_1EC@IHEDMNCI@?$AAe?$AAx?$AAt?$AA?9?$AAm?$AAs?$AA?9?$AAw?$AAi?$AAn?$AA?9?$AAn?$AAt?$AAu?$AAs?$AAe?$AAr?$AA?9?$AAp?$AAr?$AAi?$AAv?$AAa?$AAt?$AAe?$AA?9?$AAl?$AA1?$AA?9?$AA3?$AA?9?$AA1@
0x1400454D0: "__cdecl _imp_RpcAsyncAbortCall" __imp_RpcAsyncAbortCall
0x140045D80: "__cdecl _imp_RtlUnlockBootStatusData" __imp_RtlUnlockBootStatusData
0x140045420: "__cdecl _imp_RpcServerRegisterIf3" __imp_RpcServerRegisterIf3
0x140025BD4: "long __cdecl StringCchCopyW(unsigned short * __ptr64,unsigned __int64,unsigned short const * __ptr64)" ?StringCchCopyW@@YAJPEAG_KPEBG@Z
0x1400540B0: "__cdecl _DELAY_IMPORT_DESCRIPTOR_ext_ms_win_composition_init_l1_1_0_dll" __DELAY_IMPORT_DESCRIPTOR_ext_ms_win_composition_init_l1_1_0_dll
0x14002F3B0: I_WMsgSendReconnectionUpdateMessage
0x140054358: ext-ms-win-onecore-shutdown-l1-1-0_NULL_THUNK_DATA_DLN
0x140054820: ext-ms-win-onecore-shutdown-l1-1-0_NULL_THUNK_DATA_DLB
0x14005C168: ext-ms-win-onecore-shutdown-l1-1-0_NULL_THUNK_DATA_DLA
0x1400586B0: "unsigned short * s_WppLogFileName" ?s_WppLogFileName@@3PAGA
0x140045DB8: "__cdecl _imp_ZwUnloadDriver" __imp_ZwUnloadDriver
0x140041310: BiUpdateObjectReferenceInEfiEntry
0x140024694: "long __cdecl ReadShutdownStartInfo(unsigned long * __ptr64,union _LARGE_INTEGER * __ptr64)" ?ReadShutdownStartInfo@@YAJPEAKPEAT_LARGE_INTEGER@@@Z
0x140049518: "Kernel_Lsa_Cfg_Flags" ??_C@_1CK@MBHHJMIP@?$AAK?$AAe?$AAr?$AAn?$AAe?$AAl?$AA_?$AAL?$AAs?$AAa?$AA_?$AAC?$AAf?$AAg?$AA_?$AAF?$AAl?$AAa?$AAg?$AAs?$AA?$AA@
0x140048FF0: "Failed to modify boot entry 0x%x" ??_C@_1FK@CFPAHOIF@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAm?$AAo?$AAd?$AAi?$AAf?$AAy?$AA?5?$AAb?$AAo?$AAo?$AAt?$AA?5?$AAe?$AAn?$AAt?$AAr?$AAy?$AA?5?$AA0?$AAx?$AA?$CF?$AAx@
0x1400459C8: "__cdecl _imp__o__wcslwr" __imp__o__wcslwr
0x140003A48: "__cdecl _vcrt_uninitialize" __vcrt_uninitialize
0x14004CE40: "NtLoadDriver() failed, %#08lx" ??_C@_1DM@JBHAJGLG@?$AAN?$AAt?$AAL?$AAo?$AAa?$AAd?$AAD?$AAr?$AAi?$AAv?$AAe?$AAr?$AA?$CI?$AA?$CJ?$AA?5?$AAf?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?0?$AA?5?$AA?$CF?$AA?$CD?$AA0?$AA8?$AAl?$AAx?$AA?$AA@
0x14003C9E0: BiOpenKey
0x140045D08: "__cdecl _imp_RtlFreeHeap" __imp_RtlFreeHeap
0x140045B88: "__cdecl _imp_DuplicateTokenEx" __imp_DuplicateTokenEx
0x1400542A0: api-ms-win-service-private-l1-1-0_NULL_THUNK_DATA_DLN
0x1400457A8: "__cdecl _imp_IsProcessorFeaturePresent" __imp_IsProcessorFeaturePresent
0x140045508: "__cdecl _imp_GetDateFormatEx" __imp_GetDateFormatEx
0x14004BE50: " -pv" ??_C@_19HECNBBFP@?$AA?5?$AA?9?$AAp?$AAv?$AA?$AA@
0x140046088: "__cdecl _PLEASE_LINK_WITH_legacy_stdio_wide_specifiers.lib" __PLEASE_LINK_WITH_legacy_stdio_wide_specifiers.lib
0x140004FF0: NdrAsyncServerCall
0x14002ADD0: s_BaseInitiateShutdown
0x140054A6C: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-libraryloader-l1-2-0" __IMPORT_DESCRIPTOR_api-ms-win-core-libraryloader-l1-2-0
0x14002A2A8: "long __cdecl StringCbCatW(unsigned short * __ptr64,unsigned __int64,unsigned short const * __ptr64)" ?StringCbCatW@@YAJPEAG_KPEBG@Z
0x14004C5D0: "Failed to open the '%wZ', %#08lx" ??_C@_1EC@DBOBFDPI@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAo?$AAp?$AAe?$AAn?$AA?5?$AAt?$AAh?$AAe?$AA?5?$AA?8?$AA?$CF?$AAw?$AAZ?$AA?8?$AA?0?$AA?5?$AA?$CF?$AA?$CD?$AA0?$AA8?$AAl?$AAx@
0x14004CB30: "DEVICE: [BOOT]" ??_C@_1BO@EGACNLHF@?$AAD?$AAE?$AAV?$AAI?$AAC?$AAE?$AA?3?$AA?5?$AA?$FL?$AAB?$AAO?$AAO?$AAT?$AA?$FN?$AA?$AA@
0x1400383E4: BcdCloseObject
0x14004F958: "Opening store. Flags: 0x%x" ??_C@_1DG@IMJCJDCP@?$AAO?$AAp?$AAe?$AAn?$AAi?$AAn?$AAg?$AA?5?$AAs?$AAt?$AAo?$AAr?$AAe?$AA?4?$AA?5?$AAF?$AAl?$AAa?$AAg?$AAs?$AA?3?$AA?5?$AA0?$AAx?$AA?$CF?$AAx?$AA?$AA@
0x14004FB30: "Exporting forcible unload to fir" ??_C@_1EM@OIPDGHPJ@?$AAE?$AAx?$AAp?$AAo?$AAr?$AAt?$AAi?$AAn?$AAg?$AA?5?$AAf?$AAo?$AAr?$AAc?$AAi?$AAb?$AAl?$AAe?$AA?5?$AAu?$AAn?$AAl?$AAo?$AAa?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAf?$AAi?$AAr@
0x14004BD40: "%SystemRoot%\Debuggers\ntsd.exe" ??_C@_1EA@FFOMHKOG@?$AA?$CF?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AAR?$AAo?$AAo?$AAt?$AA?$CF?$AA?2?$AAD?$AAe?$AAb?$AAu?$AAg?$AAg?$AAe?$AAr?$AAs?$AA?2?$AAn?$AAt?$AAs?$AAd?$AA?4?$AAe?$AAx?$AAe?$AA?$AA@
0x140045EF8: "__cdecl _imp_RtlLengthSecurityDescriptor" __imp_RtlLengthSecurityDescriptor
0x1400048E0: IsWTSEnumerateSessionsWPresent
0x14004A390: "\" ??_C@_13FPGAJAPJ@?$AA?2?$AA?$AA@
0x1400049F8: IsGetLoggedOnUserCountPresent
0x1400490E0: "Failed to set boot options. Stat" ??_C@_1EO@BDPPMOMH@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAs?$AAe?$AAt?$AA?5?$AAb?$AAo?$AAo?$AAt?$AA?5?$AAo?$AAp?$AAt?$AAi?$AAo?$AAn?$AAs?$AA?4?$AA?5?$AAS?$AAt?$AAa?$AAt@
0x140058E90: "void * __ptr64 * hSystemProcesses" ?hSystemProcesses@@3PAPEAXA
0x1400455E0: "__cdecl _imp_GetTempPathW" __imp_GetTempPathW
0x140058DA8: "__cdecl _hmod__ext_ms_onecore_shellchromeapi_l1_1_1_dll" __hmod__ext_ms_onecore_shellchromeapi_l1_1_1_dll
0x140027930: WPP_SF_
0x140047F00: "No" ??_C@_02JINPPBEP@No?$AA@
0x140033B2C: KsrpReadBcdElement
0x140045628: "__cdecl _imp_HeapAlloc" __imp_HeapAlloc
0x1400239E8: "int __cdecl IsHeadlessConfig(void)" ?IsHeadlessConfig@@YAHXZ
0x1400456D0: "__cdecl _imp_FreeLibrary" __imp_FreeLibrary
0x14004A700: " -setup" ??_C@_1BA@CDFPIOA@?$AA?5?$AA?9?$AAs?$AAe?$AAt?$AAu?$AAp?$AA?$AA@
0x140048DE8: "%s%s" ??_C@_19LJDFFCJJ@?$AA?$CF?$AAs?$AA?$CF?$AAs?$AA?$AA@
0x1400458B8: "__cdecl _imp_AcquireSRWLockExclusive" __imp_AcquireSRWLockExclusive
0x1400541D0: "__cdecl _NULL_DELAY_IMPORT_DESCRIPTOR" __NULL_DELAY_IMPORT_DESCRIPTOR
0x140047B80: "Not supported scenario encounter" ??_C@_1FG@IDFAIHIE@?$AAN?$AAo?$AAt?$AA?5?$AAs?$AAu?$AAp?$AAp?$AAo?$AAr?$AAt?$AAe?$AAd?$AA?5?$AAs?$AAc?$AAe?$AAn?$AAa?$AAr?$AAi?$AAo?$AA?5?$AAe?$AAn?$AAc?$AAo?$AAu?$AAn?$AAt?$AAe?$AAr@
0x140045668: "__cdecl _imp_LocalSize" __imp_LocalSize
0x1400457B0: "__cdecl _imp_OpenProcess" __imp_OpenProcess
0x14004B3A0: "winsta0\Default" ??_C@_1CA@CMOLKEPM@?$AAw?$AAi?$AAn?$AAs?$AAt?$AAa?$AA0?$AA?2?$AAD?$AAe?$AAf?$AAa?$AAu?$AAl?$AAt?$AA?$AA@
0x14004F450: "Failed to filter delete element " ??_C@_1GC@BBBNIKMK@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAf?$AAi?$AAl?$AAt?$AAe?$AAr?$AA?5?$AAd?$AAe?$AAl?$AAe?$AAt?$AAe?$AA?5?$AAe?$AAl?$AAe?$AAm?$AAe?$AAn?$AAt?$AA?5@
0x14004AEE8: "ProgramFilesDir (x86)" ??_C@_1CM@LPGAILIM@?$AAP?$AAr?$AAo?$AAg?$AAr?$AAa?$AAm?$AAF?$AAi?$AAl?$AAe?$AAs?$AAD?$AAi?$AAr?$AA?5?$AA?$CI?$AAx?$AA8?$AA6?$AA?$CJ?$AA?$AA@
0x1400453A0: "__cdecl _imp_RpcBindingFree" __imp_RpcBindingFree
0x140045BE8: "__cdecl _imp_NtPrivilegeCheck" __imp_NtPrivilegeCheck
0x140051240: "BootNext" ??_C@_1BC@HGEHGBBD@?$AAB?$AAo?$AAo?$AAt?$AAN?$AAe?$AAx?$AAt?$AA?$AA@
0x140048E60: "ZwEnumerateBootEntries" ??_C@_0BH@ENILHPP@ZwEnumerateBootEntries?$AA@
0x140004F40: NdrServerCallAll
0x14002F480: I_WMsgkSendMessage
0x140045AA8: "__cdecl _imp__initterm" __imp__initterm
0x140045408: "__cdecl _imp_RpcStringBindingComposeW" __imp_RpcStringBindingComposeW
0x140002EB0: "int __cdecl WMsgPSPHandler(unsigned long,struct tagPOWERSTATEPARAMS * __ptr64,struct _RPC_ASYNC_STATE * __ptr64,long * __ptr64)" ?WMsgPSPHandler@@YAHKPEAUtagPOWERSTATEPARAMS@@PEAU_RPC_ASYNC_STATE@@PEAJ@Z
0x140054AF8: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-debug-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-debug-l1-1-0
0x14004BF70: "SYSTEM\Setup" ??_C@_1BK@BHBNHDAL@?$AAS?$AAY?$AAS?$AAT?$AAE?$AAM?$AA?2?$AAS?$AAe?$AAt?$AAu?$AAp?$AA?$AA@
0x1400406D0: BiModifyBootEntry
0x14004B420: WPP_527353cb44743429e11c59f1915a81d9_Traceguids
0x140045598: "__cdecl _imp_FindFirstVolumeW" __imp_FindFirstVolumeW
0x140045428: "__cdecl _imp_RpcImpersonateClient" __imp_RpcImpersonateClient
0x140004D6C: "__cdecl _imp_load_Shell_RequestShutdown" __imp_load_Shell_RequestShutdown
0x14002D160: "unsigned long __cdecl WininitStartWmsgServer(void * __ptr64)" ?WininitStartWmsgServer@@YAKPEAX@Z
0x140045548: "__cdecl _imp_SetLastError" __imp_SetLastError
0x1400491B0: "ZwQueryBootOptions" ??_C@_0BD@KODEDALN@ZwQueryBootOptions?$AA@
0x14004C320: "Failed to get the 'OsDevice' ent" ??_C@_1FG@LOJENFPG@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAg?$AAe?$AAt?$AA?5?$AAt?$AAh?$AAe?$AA?5?$AA?8?$AAO?$AAs?$AAD?$AAe?$AAv?$AAi?$AAc?$AAe?$AA?8?$AA?5?$AAe?$AAn?$AAt@
0x1400541F8: api-ms-win-base-bootconfig-l1-1-0_NULL_THUNK_DATA_DLN
0x14004C618: "Malloc failed" ??_C@_1BM@LINHJDIA@?$AAM?$AAa?$AAl?$AAl?$AAo?$AAc?$AA?5?$AAf?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?$AA@
0x1400459B8: "__cdecl _imp__ultow_s" __imp__ultow_s
0x14004ACC8: "%s %s" ??_C@_1M@MOFLFCEC@?$AA?$CF?$AAs?$AA?5?$AA?$CF?$AAs?$AA?$AA@
0x140040BC8: BiTranslateBootOrder
0x14004A894: "TRUE" ??_C@_04HCDDPBNL@TRUE?$AA@
0x140054BFC: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-delayload-l1-1-1" __IMPORT_DESCRIPTOR_api-ms-win-core-delayload-l1-1-1
0x140038B6C: BiIsObjectAliased
0x1400514F8: "Directory" ??_C@_1BE@DNDHOCGP@?$AAD?$AAi?$AAr?$AAe?$AAc?$AAt?$AAo?$AAr?$AAy?$AA?$AA@
0x140046A90: "ext-ms-win-composition-init-l1-1" ??_C@_1EG@MIHBJCBD@?$AAe?$AAx?$AAt?$AA?9?$AAm?$AAs?$AA?9?$AAw?$AAi?$AAn?$AA?9?$AAc?$AAo?$AAm?$AAp?$AAo?$AAs?$AAi?$AAt?$AAi?$AAo?$AAn?$AA?9?$AAi?$AAn?$AAi?$AAt?$AA?9?$AAl?$AA1?$AA?9?$AA1@
0x14003B798: RtlStringCbPrintfW
0x140050700: "Failed to update object GUID str" ??_C@_1GA@BMFPLOJK@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAu?$AAp?$AAd?$AAa?$AAt?$AAe?$AA?5?$AAo?$AAb?$AAj?$AAe?$AAc?$AAt?$AA?5?$AAG?$AAU?$AAI?$AAD?$AA?5?$AAs?$AAt?$AAr@
0x140047768: "ShutdownPath" ??_C@_1BK@DJDGPBNF@?$AAS?$AAh?$AAu?$AAt?$AAd?$AAo?$AAw?$AAn?$AAP?$AAa?$AAt?$AAh?$AA?$AA@
0x140047220: "\MEMORY.DMP" ??_C@_1BI@JCPJDIDK@?$AA?2?$AAM?$AAE?$AAM?$AAO?$AAR?$AAY?$AA?4?$AAD?$AAM?$AAP?$AA?$AA@
0x1400456E0: "__cdecl _imp_GetModuleFileNameW" __imp_GetModuleFileNameW
0x14004D0D0: "WIMGetAttributes" ??_C@_0BB@OGKMMKDG@WIMGetAttributes?$AA@
0x14004C6F0: GUID_DEVINTERFACE_SURFACE_VIRTUAL_DRIVE
0x140058DE8: "__cdecl _hmod__api_ms_win_service_management_l2_1_0_dll" __hmod__api_ms_win_service_management_l2_1_0_dll
0x14002B154: "unsigned short * __ptr64 __cdecl AllocAndDuplicateString(unsigned short const * __ptr64)" ?AllocAndDuplicateString@@YAPEAGPEBG@Z
0x14005C138: ext-ms-win-ntuser-misc-l1-1-0_NULL_THUNK_DATA_DLA
0x1400458E8: "__cdecl _imp_GetVersionExW" __imp_GetVersionExW
0x14004B2D0: "userinit.exe" ??_C@_1BK@KODGDAJG@?$AAu?$AAs?$AAe?$AAr?$AAi?$AAn?$AAi?$AAt?$AA?4?$AAe?$AAx?$AAe?$AA?$AA@
0x140038004: BiOpenSystemStore
0x14004FB80: "Failed to export unload alterati" ??_C@_1HI@BFAPKPBG@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAe?$AAx?$AAp?$AAo?$AAr?$AAt?$AA?5?$AAu?$AAn?$AAl?$AAo?$AAa?$AAd?$AA?5?$AAa?$AAl?$AAt?$AAe?$AAr?$AAa?$AAt?$AAi@
0x14003AA34: BiGetPartitionVhdFilePathFromUnicodeString
0x140032250: "void __cdecl SetSetupExitCode(unsigned long * __ptr64)" ?SetSetupExitCode@@YAXPEAK@Z
0x140026BCC: "unsigned long __cdecl WinInitBoot(void)" ?WinInitBoot@@YAKXZ
0x14004F270: "Failed to open key for element %" ??_C@_1FM@MCOPBIDM@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAo?$AAp?$AAe?$AAn?$AA?5?$AAk?$AAe?$AAy?$AA?5?$AAf?$AAo?$AAr?$AA?5?$AAe?$AAl?$AAe?$AAm?$AAe?$AAn?$AAt?$AA?5?$AA?$CF@
0x1400540F0: "__cdecl _DELAY_IMPORT_DESCRIPTOR_ext_ms_win_coreui_navshutdown_l1_1_0_dll" __DELAY_IMPORT_DESCRIPTOR_ext_ms_win_coreui_navshutdown_l1_1_0_dll
0x14004F868: "\KernelObjects\BcdSyncMutant" ??_C@_1DK@LKMKBKBC@?$AA?2?$AAK?$AAe?$AAr?$AAn?$AAe?$AAl?$AAO?$AAb?$AAj?$AAe?$AAc?$AAt?$AAs?$AA?2?$AAB?$AAc?$AAd?$AAS?$AAy?$AAn?$AAc?$AAM?$AAu?$AAt?$AAa?$AAn?$AAt?$AA?$AA@
0x140045CB0: "__cdecl _imp_NtCreateWnfStateName" __imp_NtCreateWnfStateName
0x1400549A4: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-registry-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-registry-l1-1-0
0x140050510: "Failed to bind with firmware. Fl" ??_C@_1GK@JIHKALBN@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAb?$AAi?$AAn?$AAd?$AA?5?$AAw?$AAi?$AAt?$AAh?$AA?5?$AAf?$AAi?$AAr?$AAm?$AAw?$AAa?$AAr?$AAe?$AA?4?$AA?5?$AAF?$AAl@
0x1400455F0: "__cdecl _imp_MoveFileExW" __imp_MoveFileExW
0x14003D5F8: BiLookupNtdllProcedureAddress
0x14004F540: "Failed to open element %ws key f" ??_C@_1GM@IPBIONFL@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAo?$AAp?$AAe?$AAn?$AA?5?$AAe?$AAl?$AAe?$AAm?$AAe?$AAn?$AAt?$AA?5?$AA?$CF?$AAw?$AAs?$AA?5?$AAk?$AAe?$AAy?$AA?5?$AAf@
0x140040C54: BiTranslateDisplayOrder
0x14003DA6C: BiCacheGuidValues
0x1400421E8: SiGetEfiSystemDevice
0x140054B98: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-stateseparation-helpers-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-stateseparation-helpers-l1-1-0
0x14004AD38: WPP_64b7c80ecd2f3496dfc519370ccb8824_Traceguids
0x140045A28: "__cdecl _imp__o__crt_atexit" __imp__o__crt_atexit
0x140002520: StringCchPrintfW
0x140004012: "__cdecl o__configure_narrow_argv" _o__configure_narrow_argv
0x14004B280: "Nddeagnt.exe" ??_C@_1BK@NLPBDADF@?$AAN?$AAd?$AAd?$AAe?$AAa?$AAg?$AAn?$AAt?$AA?4?$AAe?$AAx?$AAe?$AA?$AA@
0x1400459B8: "__cdecl _imp__o__ultow_s" __imp__o__ultow_s
0x140047AB8: "Default" ??_C@_1BA@GHOECOCL@?$AAD?$AAe?$AAf?$AAa?$AAu?$AAl?$AAt?$AA?$AA@
0x14002F114: WmsgSendMessage
0x14004F800: "Failed to enumerate subobject el" ??_C@_1GG@GIPNMAPI@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAe?$AAn?$AAu?$AAm?$AAe?$AAr?$AAa?$AAt?$AAe?$AA?5?$AAs?$AAu?$AAb?$AAo?$AAb?$AAj?$AAe?$AAc?$AAt?$AA?5?$AAe?$AAl@
0x140048B80: "Failed to get system partition. " ??_C@_1FG@JFDBELFL@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAg?$AAe?$AAt?$AA?5?$AAs?$AAy?$AAs?$AAt?$AAe?$AAm?$AA?5?$AAp?$AAa?$AAr?$AAt?$AAi?$AAt?$AAi?$AAo?$AAn?$AA?4?$AA?5@
0x140003A6C: "__cdecl _scrt_initialize_default_local_stdio_options" __scrt_initialize_default_local_stdio_options
0x140002E10: I_WMsgkSendPSPMessage
0x140038CE0: BiConvertBootEnvironmentDeviceToNt
0x1400049F8: IsPrimaryTerminalAndHookWorkerPresent
0x140045D90: "__cdecl _imp_ZwDeviceIoControlFile" __imp_ZwDeviceIoControlFile
0x1400512A8: "WINDOWS" ??_C@_07LHJOABLP@WINDOWS?$AA@
0x140049E20: "winload" ??_C@_1BA@GHMPNKPL@?$AAw?$AAi?$AAn?$AAl?$AAo?$AAa?$AAd?$AA?$AA@
0x14004B800: "D:(A;;3;;;AU)" ??_C@_1BM@GLNMBKOF@?$AAD?$AA?3?$AA?$CI?$AAA?$AA?$DL?$AA?$DL?$AA3?$AA?$DL?$AA?$DL?$AA?$DL?$AAA?$AAU?$AA?$CJ?$AA?$AA@
0x140045750: "__cdecl _imp_CreateThread" __imp_CreateThread
0x140045380: "__cdecl _imp_WTSGetServiceSessionId" __imp_WTSGetServiceSessionId
0x140045A20: "__cdecl _imp__exit" __imp__exit
0x14003E504: BiBindEfiEntryToBcdObject
0x140003710: "__cdecl _scrt_initialize_onexit_tables" __scrt_initialize_onexit_tables
0x14002B4A4: "unsigned short * __ptr64 __cdecl AllocAndLoadString(unsigned int)" ?AllocAndLoadString@@YAPEAGI@Z
0x1400269F0: "void __cdecl WLEventWrite(struct _EVENT_DESCRIPTOR const & __ptr64,unsigned long)" ?WLEventWrite@@YAXAEBU_EVENT_DESCRIPTOR@@K@Z
0x140046048: "__cdecl _guard_check_icall_fptr" __guard_check_icall_fptr
0x140046EF0: WIEvt_Wininit_Lsa_Iso_Uefi_Read_Error
0x14002ED1C: WluiSignalShutdown
0x1400592A8: g_pSidAnyPackage
0x1400453A8: "__cdecl _imp_RpcServerUseProtseqEpW" __imp_RpcServerUseProtseqEpW
0x140024F64: "unsigned long __cdecl SetMachineName(void)" ?SetMachineName@@YAKXZ
0x140040CDC: BiTranslateFilePath
0x140048290: "Failed to set 'ImagePath' value," ??_C@_1FA@PIPMLKBO@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAs?$AAe?$AAt?$AA?5?$AA?8?$AAI?$AAm?$AAa?$AAg?$AAe?$AAP?$AAa?$AAt?$AAh?$AA?8?$AA?5?$AAv?$AAa?$AAl?$AAu?$AAe?$AA?0@
0x140045388: KERNELBASE_NULL_THUNK_DATA
0x14003C370: BiGetKeyName
0x14004AA70: "D:(A;;GA;;;AU)(A;;GR;;;AC)" ??_C@_1DG@NKMEEOAN@?$AAD?$AA?3?$AA?$CI?$AAA?$AA?$DL?$AA?$DL?$AAG?$AAA?$AA?$DL?$AA?$DL?$AA?$DL?$AAA?$AAU?$AA?$CJ?$AA?$CI?$AAA?$AA?$DL?$AA?$DL?$AAG?$AAR?$AA?$DL?$AA?$DL?$AA?$DL?$AAA?$AAC?$AA?$CJ?$AA?$AA@
0x14003C324: BiForceUnloadHive
0x1400474F0: "LSA-Policy-EnableCredentialIsola" ??_C@_1EK@JNOPDCMJ@?$AAL?$AAS?$AAA?$AA?9?$AAP?$AAo?$AAl?$AAi?$AAc?$AAy?$AA?9?$AAE?$AAn?$AAa?$AAb?$AAl?$AAe?$AAC?$AAr?$AAe?$AAd?$AAe?$AAn?$AAt?$AAi?$AAa?$AAl?$AAI?$AAs?$AAo?$AAl?$AAa@
0x140041CD8: SiOpenRegistryKey
0x140003AB0: "__cdecl _crt_debugger_hook" __crt_debugger_hook
0x14002DC30: "long __cdecl StringCbPrintfW(unsigned short * __ptr64,unsigned __int64,unsigned short const * __ptr64,...)" ?StringCbPrintfW@@YAJPEAG_KPEBGZZ
0x14004CAE0: "Failed to get the element data, " ??_C@_1EO@LEOMAGLI@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAg?$AAe?$AAt?$AA?5?$AAt?$AAh?$AAe?$AA?5?$AAe?$AAl?$AAe?$AAm?$AAe?$AAn?$AAt?$AA?5?$AAd?$AAa?$AAt?$AAa?$AA?0?$AA?5@
0x1400455A8: "__cdecl _imp_FindFirstFileW" __imp_FindFirstFileW
0x14004A4B4: "NULL" ??_C@_04HIBGFPH@NULL?$AA@
0x140045C88: "__cdecl _imp_NtCreateUserProcess" __imp_NtCreateUserProcess
0x1400367F8: BiEnumerateElements
0x140047410: "ShutdownEventPending" ??_C@_1CK@JPFCBKOB@?$AAS?$AAh?$AAu?$AAt?$AAd?$AAo?$AAw?$AAn?$AAE?$AAv?$AAe?$AAn?$AAt?$AAP?$AAe?$AAn?$AAd?$AAi?$AAn?$AAg?$AA?$AA@
0x140045778: "__cdecl _imp_TerminateProcess" __imp_TerminateProcess
0x140003A48: "__cdecl should_initialize_environment" _should_initialize_environment
0x1400335F8: KsrpGetBootOptionSize
0x140005604: SiGetFirmwareSystemPartition
0x14002F020: WMsg_midl_user_free
0x14004CF70: "NtDeviceIoControlFile() failed, " ??_C@_1EO@GAIDIDOB@?$AAN?$AAt?$AAD?$AAe?$AAv?$AAi?$AAc?$AAe?$AAI?$AAo?$AAC?$AAo?$AAn?$AAt?$AAr?$AAo?$AAl?$AAF?$AAi?$AAl?$AAe?$AA?$CI?$AA?$CJ?$AA?5?$AAf?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?0?$AA?5@
0x14003B3A4: BiTranslateSymbolicLinkFile
0x14002775C: "void __cdecl WinInitWaitForBootShell(void)" ?WinInitWaitForBootShell@@YAXXZ
0x140046010: "__cdecl _imp_RtlAppendUnicodeToString" __imp_RtlAppendUnicodeToString
0x14004C3A8: "Device type is not LOCATE." ??_C@_1DG@GMONFBMK@?$AAD?$AAe?$AAv?$AAi?$AAc?$AAe?$AA?5?$AAt?$AAy?$AAp?$AAe?$AA?5?$AAi?$AAs?$AA?5?$AAn?$AAo?$AAt?$AA?5?$AAL?$AAO?$AAC?$AAA?$AAT?$AAE?$AA?4?$AA?$AA@
0x14003D0BC: BiGetSystemPartition
0x14005C020: "__cdecl _imp_RegisterEventSourceW" __imp_RegisterEventSourceW
0x14002F020: "void __cdecl MemoryFree(void * __ptr64)" ?MemoryFree@@YAXPEAX@Z
0x140045B40: "__cdecl _imp_GetTokenInformation" __imp_GetTokenInformation
0x140045E28: "__cdecl _imp_EtwEventRegister" __imp_EtwEventRegister
0x140034E2C: "public: void __cdecl SH<void * __ptr64,class SH_HANDLE>::Reset(void) __ptr64" ?Reset@?$SH@PEAXVSH_HANDLE@@@@QEAAXXZ
0x140045D20: "__cdecl _imp_RtlNtStatusToDosError" __imp_RtlNtStatusToDosError
0x14000405A: "__cdecl register_onexit_function" _register_onexit_function
0x140003FE2: "__cdecl o___stdio_common_vswprintf_s" _o___stdio_common_vswprintf_s
0x14004B820: "LogonUI.exe" ??_C@_1BI@LFOBLIOF@?$AAL?$AAo?$AAg?$AAo?$AAn?$AAU?$AAI?$AA?4?$AAe?$AAx?$AAe?$AA?$AA@
0x140003160: "__cdecl _scrt_exe_initialize_mta" __scrt_exe_initialize_mta
0x14004FEC0: "Objects" ??_C@_1BA@JMJFMCEO@?$AAO?$AAb?$AAj?$AAe?$AAc?$AAt?$AAs?$AA?$AA@
0x1400501D8: "BCD" ??_C@_17GMNPFCKO@?$AAB?$AAC?$AAD?$AA?$AA@
0x14002B1D8: "unsigned short * __ptr64 __cdecl AllocAndExpandEnvironmentStrings(unsigned short const * __ptr64)" ?AllocAndExpandEnvironmentStrings@@YAPEAGPEBG@Z
0x140054010: "__cdecl _DELAY_IMPORT_DESCRIPTOR_ext_ms_win_ntuser_misc_l1_1_0_dll" __DELAY_IMPORT_DESCRIPTOR_ext_ms_win_ntuser_misc_l1_1_0_dll
0x140045518: "__cdecl _imp_IsDebuggerPresent" __imp_IsDebuggerPresent
0x14004B4C0: "RestoreInProgress" ??_C@_1CE@COMGOJKN@?$AAR?$AAe?$AAs?$AAt?$AAo?$AAr?$AAe?$AAI?$AAn?$AAP?$AAr?$AAo?$AAg?$AAr?$AAe?$AAs?$AAs?$AA?$AA@
0x140035854: BcdSetElementDataWithFlags
0x140045918: api-ms-win-core-sysinfo-l1-1-0_NULL_THUNK_DATA
0x140046070: "__cdecl _xi_a" __xi_a
0x14004A468: WLEvt_DwmpNotifyUserLogon_Stop
0x140046C30: "ext-ms-win-coreui-navshutdown-l1" ??_C@_1EK@IKCELENA@?$AAe?$AAx?$AAt?$AA?9?$AAm?$AAs?$AA?9?$AAw?$AAi?$AAn?$AA?9?$AAc?$AAo?$AAr?$AAe?$AAu?$AAi?$AA?9?$AAn?$AAa?$AAv?$AAs?$AAh?$AAu?$AAt?$AAd?$AAo?$AAw?$AAn?$AA?9?$AAl?$AA1@
0x14002C9D8: "void __cdecl UpdateRegistryItem(struct _REG_CHANGE * __ptr64)" ?UpdateRegistryItem@@YAXPEAU_REG_CHANGE@@@Z
0x140046390: "__cdecl _sz_api_ms_win_security_capability_l1_1_0_dll" __sz_api_ms_win_security_capability_l1_1_0_dll
0x1400457C0: api-ms-win-core-processthreads-l1-1-1_NULL_THUNK_DATA
0x140045908: "__cdecl _imp_GetTickCount" __imp_GetTickCount
0x140045520: api-ms-win-core-debug-l1-1-0_NULL_THUNK_DATA
0x140045538: "__cdecl _imp_ResolveDelayLoadedAPI" __imp_ResolveDelayLoadedAPI
0x14004CA90: "Failed to get the element buffer" ??_C@_1EC@HDNOHGOO@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAg?$AAe?$AAt?$AA?5?$AAt?$AAh?$AAe?$AA?5?$AAe?$AAl?$AAe?$AAm?$AAe?$AAn?$AAt?$AA?5?$AAb?$AAu?$AAf?$AAf?$AAe?$AAr@
0x14005C008: api-ms-win-base-bootconfig-l1-1-0_NULL_THUNK_DATA_DLA
0x140045CB8: "__cdecl _imp_NtQuerySystemEnvironmentValueEx" __imp_NtQuerySystemEnvironmentValueEx
0x140037E6C: BiMarkTreatAsSystemStore
0x140054788: ext-ms-win-core-stateseparationext-l1-1-0_NULL_THUNK_DATA_DLB
0x1400040C6: "__cdecl wcsupr" _wcsupr
0x14005C1C0: ext-ms-win-session-wtsapi32-l1-1-0_NULL_THUNK_DATA_DLA
0x1400547C8: ext-ms-win-session-wtsapi32-l1-1-0_NULL_THUNK_DATA_DLB
0x140033EBC: KsrpRegisterDriver
0x1400543B0: ext-ms-win-session-wtsapi32-l1-1-0_NULL_THUNK_DATA_DLN
0x140003680: "__cdecl _scrt_acquire_startup_lock" __scrt_acquire_startup_lock
0x1400467A0: "ext-ms-win-ntuser-private-l1-3-3" ??_C@_1EC@CNEKAFKD@?$AAe?$AAx?$AAt?$AA?9?$AAm?$AAs?$AA?9?$AAw?$AAi?$AAn?$AA?9?$AAn?$AAt?$AAu?$AAs?$AAe?$AAr?$AA?9?$AAp?$AAr?$AAi?$AAv?$AAa?$AAt?$AAe?$AA?9?$AAl?$AA1?$AA?9?$AA3?$AA?9?$AA3@
0x140045D10: "__cdecl _imp_RtlSubscribeWnfStateChangeNotification" __imp_RtlSubscribeWnfStateChangeNotification
0x140004D78: "__cdecl _tailMerge_ext_ms_onecore_shellchromeapi_l1_1_1_dll" __tailMerge_ext_ms_onecore_shellchromeapi_l1_1_1_dll
0x14004AB20: "DisableRemoteShutdownRPCInterfac" ??_C@_1EE@KNMHNMML@?$AAD?$AAi?$AAs?$AAa?$AAb?$AAl?$AAe?$AAR?$AAe?$AAm?$AAo?$AAt?$AAe?$AAS?$AAh?$AAu?$AAt?$AAd?$AAo?$AAw?$AAn?$AAR?$AAP?$AAC?$AAI?$AAn?$AAt?$AAe?$AAr?$AAf?$AAa?$AAc@
0x140045928: "__cdecl _imp_QueueUserWorkItem" __imp_QueueUserWorkItem
0x140045C58: "__cdecl _imp_RtlGetCurrentServiceSessionId" __imp_RtlGetCurrentServiceSessionId
0x140045BB8: api-ms-win-security-base-l1-1-0_NULL_THUNK_DATA
0x14003A3E8: BiGetNtPartitionPath
0x14000401E: "__cdecl o__crt_atexit" _o__crt_atexit
0x140034EC0: RtlULongLongAdd
0x140054328: ext-ms-win-ntuser-misc-l1-1-0_NULL_THUNK_DATA_DLN
0x140024F50: "void __cdecl SRDisplayMessageCallback(unsigned short const * __ptr64)" ?SRDisplayMessageCallback@@YAXPEBG@Z
0x140003160: "__cdecl get_startup_new_mode" _get_startup_new_mode
0x14005C130: "__cdecl _imp_ExitWindowsEx" __imp_ExitWindowsEx
0x140045BF0: "__cdecl _imp_NtOpenThreadToken" __imp_NtOpenThreadToken
0x140047590: "%SystemRoot%\system32\lsaiso.exe" ??_C@_1EC@GKGJMLBI@?$AA?$CF?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AAR?$AAo?$AAo?$AAt?$AA?$CF?$AA?2?$AAs?$AAy?$AAs?$AAt?$AAe?$AAm?$AA3?$AA2?$AA?2?$AAl?$AAs?$AAa?$AAi?$AAs?$AAo?$AA?4?$AAe?$AAx?$AAe@
0x1400052F9: "__cdecl _imp_load_SwitchDesktop" __imp_load_SwitchDesktop
0x14004B388: "ntsd %s %s" ??_C@_1BG@BGBBKINK@?$AAn?$AAt?$AAs?$AAd?$AA?5?$AA?$CF?$AAs?$AA?5?$AA?$CF?$AAs?$AA?$AA@
0x140003C60: "__cdecl _scrt_is_managed_app" __scrt_is_managed_app
0x140045D70: "__cdecl _imp_RtlGetCurrentDirectory_U" __imp_RtlGetCurrentDirectory_U
0x140004934: "__cdecl _imp_load_WTSQueryUserToken" __imp_load_WTSQueryUserToken
0x1400044C0: "__cdecl _imp_load_DeregisterEventSource" __imp_load_DeregisterEventSource
0x140003CD0: "__cdecl _scrt_unhandled_exception_filter" __scrt_unhandled_exception_filter
0x140003FFA: "__cdecl o__cexit" _o__cexit
0x1400325D4: WPP_SF_dd
0x140045470: "__cdecl _imp_RpcServerUseProtseqW" __imp_RpcServerUseProtseqW
0x140033370: KsrpBootEntryToTransitionEntry
0x14005C070: "__cdecl _imp_CloseServiceHandle" __imp_CloseServiceHandle
0x140059368: "int (__cdecl* __ptr64 g_pfnNamedEscape)(struct HDC__ * __ptr64,unsigned short * __ptr64,int,int,char const * __ptr64,int,char * __ptr64)" ?g_pfnNamedEscape@@3P6AHPEAUHDC__@@PEAGHHPEBDHPEAD@ZEA
0x140027B70: WPP_SF_dS
0x14002CFAC: WPP_SF_DS
0x14004B940: "3BDB59A0-D736-4D44-9074-C1EE%08X" ??_C@_1EC@FOIPJOLI@?$AA3?$AAB?$AAD?$AAB?$AA5?$AA9?$AAA?$AA0?$AA?9?$AAD?$AA7?$AA3?$AA6?$AA?9?$AA4?$AAD?$AA4?$AA4?$AA?9?$AA9?$AA0?$AA7?$AA4?$AA?9?$AAC?$AA1?$AAE?$AAE?$AA?$CF?$AA0?$AA8?$AAX@
0x140059278: g_pSidCreator
0x140045398: "__cdecl _imp_RpcBindingServerFromClient" __imp_RpcBindingServerFromClient
0x140047CF8: "Getting winload.sys path" ??_C@_1DC@JHLGPKIK@?$AAG?$AAe?$AAt?$AAt?$AAi?$AAn?$AAg?$AA?5?$AAw?$AAi?$AAn?$AAl?$AAo?$AAa?$AAd?$AA?4?$AAs?$AAy?$AAs?$AA?5?$AAp?$AAa?$AAt?$AAh?$AA?$AA@
0x14004CE80: "NtUnloadDriver() failed, %#08lx" ??_C@_1EA@EEBFJEHO@?$AAN?$AAt?$AAU?$AAn?$AAl?$AAo?$AAa?$AAd?$AAD?$AAr?$AAi?$AAv?$AAe?$AAr?$AA?$CI?$AA?$CJ?$AA?5?$AAf?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?0?$AA?5?$AA?$CF?$AA?$CD?$AA0?$AA8?$AAl?$AAx?$AA?$AA@
0x14004CC48: "DEVICE: [Locate custom:%08x]" ??_C@_1DK@DAKJMOFL@?$AAD?$AAE?$AAV?$AAI?$AAC?$AAE?$AA?3?$AA?5?$AA?$FL?$AAL?$AAo?$AAc?$AAa?$AAt?$AAe?$AA?5?$AAc?$AAu?$AAs?$AAt?$AAo?$AAm?$AA?3?$AA?$CF?$AA0?$AA8?$AAx?$AA?$FN?$AA?$AA@
0x14004B2B8: "nddeagnt" ??_C@_1BC@JMFKKPEM@?$AAn?$AAd?$AAd?$AAe?$AAa?$AAg?$AAn?$AAt?$AA?$AA@
0x140045AB8: "__cdecl _imp__register_thread_local_exe_atexit_callback" __imp__register_thread_local_exe_atexit_callback
0x14003CE44: BiUnloadHiveByName
0x140058170: WPP_GLOBAL_Control
0x140050080: "Failed to open description key f" ??_C@_1JK@ICGMJJA@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAo?$AAp?$AAe?$AAn?$AA?5?$AAd?$AAe?$AAs?$AAc?$AAr?$AAi?$AAp?$AAt?$AAi?$AAo?$AAn?$AA?5?$AAk?$AAe?$AAy?$AA?5?$AAf@
0x1400040DE: "__cdecl o_terminate" _o_terminate
0x140054050: "__cdecl _DELAY_IMPORT_DESCRIPTOR_ext_ms_win_session_wtsapi32_l1_1_0_dll" __DELAY_IMPORT_DESCRIPTOR_ext_ms_win_session_wtsapi32_l1_1_0_dll
0x140045E40: "__cdecl _imp_RtlGetActiveConsoleId" __imp_RtlGetActiveConsoleId
0x14005C000: "__cdecl _imp_NotifyBootConfigStatus" __imp_NotifyBootConfigStatus
0x140045F28: "__cdecl _imp_ZwQueryValueKey" __imp_ZwQueryValueKey
0x1400593E4: "unsigned long g_BreakinProcessId" ?g_BreakinProcessId@@3KA
0x14004A488: WIDiagEvt_ShutdownDiagnostics_Start
0x1400040AE: "__cdecl o__wcslwr" _o__wcslwr
0x14004621C: "" ??_C@_11LOCGONAA@?$AA?$AA@
0x1400549B8: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-processthreads-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-processthreads-l1-1-0
0x140054A94: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-processthreads-l1-1-1" __IMPORT_DESCRIPTOR_api-ms-win-core-processthreads-l1-1-1
0x140045618: "__cdecl _imp_HeapCreate" __imp_HeapCreate
0x1400291A0: "__cdecl TlgEnableCallback" _TlgEnableCallback
0x140045A68: "__cdecl _imp__o___p__commode" __imp__o___p__commode
0x14002D3E4: "void __cdecl AddSQMDataPoint(struct HINSTANCE__ * __ptr64,unsigned short const * __ptr64)" ?AddSQMDataPoint@@YAXPEAUHINSTANCE__@@PEBG@Z
0x140004B74: "__cdecl _imp_load_ValidateSystemShutdown" __imp_load_ValidateSystemShutdown
0x14003BA94: BiCreateKeySecurityDescriptor
0x140027954: WPP_SF_d
0x140027954: WPP_SF_D
0x140023ED8: "unsigned long __cdecl LaunchBootShell(unsigned long * __ptr64)" ?LaunchBootShell@@YAKPEAK@Z
0x1400456C0: "__cdecl _imp_FindResourceExW" __imp_FindResourceExW
0x140038BC4: BiIsValidObject
0x1400382DC: BiSetFirmwareModified
0x1400593E0: "unsigned long g_AttachProcessId" ?g_AttachProcessId@@3KA
0x140046870: "ext-ms-win-ntuser-windowstation-" ??_C@_1EO@OAMAPFNA@?$AAe?$AAx?$AAt?$AA?9?$AAm?$AAs?$AA?9?$AAw?$AAi?$AAn?$AA?9?$AAn?$AAt?$AAu?$AAs?$AAe?$AAr?$AA?9?$AAw?$AAi?$AAn?$AAd?$AAo?$AAw?$AAs?$AAt?$AAa?$AAt?$AAi?$AAo?$AAn?$AA?9@
0x14004A730: "The system process '%s' terminat" ??_C@_1NK@IBABENEO@?$AAT?$AAh?$AAe?$AA?5?$AAs?$AAy?$AAs?$AAt?$AAe?$AAm?$AA?5?$AAp?$AAr?$AAo?$AAc?$AAe?$AAs?$AAs?$AA?5?$AA?8?$AA?$CF?$AAs?$AA?8?$AA?5?$AAt?$AAe?$AAr?$AAm?$AAi?$AAn?$AAa?$AAt@
0x1400051EF: "__cdecl _tailMerge_api_ms_win_service_management_l2_1_0_dll" __tailMerge_api_ms_win_service_management_l2_1_0_dll
0x140048DF8: "ZwAddBootEntry" ??_C@_0P@NJGBECCE@ZwAddBootEntry?$AA@
0x1400454C0: "__cdecl _imp_I_RpcExceptionFilter" __imp_I_RpcExceptionFilter
0x140046D00: "__cdecl _sz_api_ms_win_security_lsalookup_l1_1_0_dll" __sz_api_ms_win_security_lsalookup_l1_1_0_dll
0x140050CB0: "Failed to query processes. Statu" ??_C@_1EM@PHONPJKB@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAq?$AAu?$AAe?$AAr?$AAy?$AA?5?$AAp?$AAr?$AAo?$AAc?$AAe?$AAs?$AAs?$AAe?$AAs?$AA?4?$AA?5?$AAS?$AAt?$AAa?$AAt?$AAu@
0x14002EFF0: WMsg_midl_user_allocate
0x140045970: api-ms-win-core-version-l1-1-0_NULL_THUNK_DATA
0x140045938: api-ms-win-core-threadpool-legacy-l1-1-0_NULL_THUNK_DATA
0x140045CD0: "__cdecl _imp_RtlFreeSid" __imp_RtlFreeSid
0x1400501E0: "Failed to add system store from " ??_C@_1HG@EJMNDF@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAa?$AAd?$AAd?$AA?5?$AAs?$AAy?$AAs?$AAt?$AAe?$AAm?$AA?5?$AAs?$AAt?$AAo?$AAr?$AAe?$AA?5?$AAf?$AAr?$AAo?$AAm?$AA?5@
0x140045590: "__cdecl _imp_GetDriveTypeW" __imp_GetDriveTypeW
0x14000432B: "__cdecl _tailMerge_api_ms_win_service_private_l1_1_0_dll" __tailMerge_api_ms_win_service_private_l1_1_0_dll
0x140048C98: "FirmwareBootDevice" ??_C@_1CG@EEKKLGPP@?$AAF?$AAi?$AAr?$AAm?$AAw?$AAa?$AAr?$AAe?$AAB?$AAo?$AAo?$AAt?$AAD?$AAe?$AAv?$AAi?$AAc?$AAe?$AA?$AA@
0x14004AF40: "CommonFilesDir (x86)" ??_C@_1CK@FONJNPCI@?$AAC?$AAo?$AAm?$AAm?$AAo?$AAn?$AAF?$AAi?$AAl?$AAe?$AAs?$AAD?$AAi?$AAr?$AA?5?$AA?$CI?$AAx?$AA8?$AA6?$AA?$CJ?$AA?$AA@
0x140003A60: "__cdecl initialize_invalid_parameter_handler" _initialize_invalid_parameter_handler
0x1400318C8: EnablePrivilege
0x140042038: SiBootEntryGetNtFilePath
0x140047E80: "Failed to convert boot entry int" ??_C@_1HO@FPOEFEJC@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAc?$AAo?$AAn?$AAv?$AAe?$AAr?$AAt?$AA?5?$AAb?$AAo?$AAo?$AAt?$AA?5?$AAe?$AAn?$AAt?$AAr?$AAy?$AA?5?$AAi?$AAn?$AAt@
0x140005152: "__cdecl _tailMerge_api_ms_win_service_winsvc_l1_1_0_dll" __tailMerge_api_ms_win_service_winsvc_l1_1_0_dll
0x14004B268: "Userinit" ??_C@_1BC@PNKEHAID@?$AAU?$AAs?$AAe?$AAr?$AAi?$AAn?$AAi?$AAt?$AA?$AA@
0x14004AA50: "ncacn_ip_tcp" ??_C@_1BK@BPGFLIHL@?$AAn?$AAc?$AAa?$AAc?$AAn?$AA_?$AAi?$AAp?$AA_?$AAt?$AAc?$AAp?$AA?$AA@
0x14004B000: "CommonProgramW6432" ??_C@_1CG@NMMNPOME@?$AAC?$AAo?$AAm?$AAm?$AAo?$AAn?$AAP?$AAr?$AAo?$AAg?$AAr?$AAa?$AAm?$AAW?$AA6?$AA4?$AA3?$AA2?$AA?$AA@
0x14004C6E0: VIRTUAL_STORAGE_TYPE_VENDOR_UNKNOWN
0x140046DC0: "__cdecl _sz_api_ms_win_service_management_l2_1_0_dll" __sz_api_ms_win_service_management_l2_1_0_dll
0x140046D60: "__cdecl _sz_api_ms_win_service_management_l1_1_0_dll" __sz_api_ms_win_service_management_l1_1_0_dll
0x140003DA4: "__cdecl _isa_available_init" __isa_available_init
0x14003D000: BiExportStoreAlterationsToFirmware
0x140027860: "void __cdecl WininitHeapFree(void * __ptr64 * __ptr64)" ?WininitHeapFree@@YAXPEAPEAX@Z
0x140054238: api-ms-win-security-capability-l1-1-0_NULL_THUNK_DATA_DLN
0x14004AF18: "ProgramFiles(x86)" ??_C@_1CE@EAPHGJBI@?$AAP?$AAr?$AAo?$AAg?$AAr?$AAa?$AAm?$AAF?$AAi?$AAl?$AAe?$AAs?$AA?$CI?$AAx?$AA8?$AA6?$AA?$CJ?$AA?$AA@
0x140005370: "__cdecl TlgDefineProvider_annotation__Tlgmtaum_hTelemetryAssertProv" _TlgDefineProvider_annotation__Tlgmtaum_hTelemetryAssertProv
0x140045C78: "__cdecl _imp_RtlRegisterWait" __imp_RtlRegisterWait
0x140045DF8: "__cdecl _imp_RtlSetProcessIsCritical" __imp_RtlSetProcessIsCritical
0x140047540: "VsmLKeyProvisioningResult" ??_C@_1DE@FJPMEGFF@?$AAV?$AAs?$AAm?$AAL?$AAK?$AAe?$AAy?$AAP?$AAr?$AAo?$AAv?$AAi?$AAs?$AAi?$AAo?$AAn?$AAi?$AAn?$AAg?$AAR?$AAe?$AAs?$AAu?$AAl?$AAt?$AA?$AA@
0x140003A1C: "__cdecl get_startup_argv_mode" _get_startup_argv_mode
0x14003D1A4: BiIsPortableWorkspaceBoot
0x14004CCB8: "DEVICE: [Locate]" ??_C@_1CC@IJNEGNMF@?$AAD?$AAE?$AAV?$AAI?$AAC?$AAE?$AA?3?$AA?5?$AA?$FL?$AAL?$AAo?$AAc?$AAa?$AAt?$AAe?$AA?$FN?$AA?$AA@
0x140058E30: "int * SystemProcessState" ?SystemProcessState@@3PAHA
0x1400322E0: "void __cdecl SetSetupShutdownAction(int * __ptr64,enum _SHUTDOWN_ACTION * __ptr64)" ?SetSetupShutdownAction@@YAXPEAHPEAW4_SHUTDOWN_ACTION@@@Z
0x140032E7C: KsrpSurfaceVhdFile
0x140045B90: "__cdecl _imp_GetSecurityDescriptorGroup" __imp_GetSecurityDescriptorGroup
0x140045958: "__cdecl _imp_VerQueryValueW" __imp_VerQueryValueW
0x14004A398: WIEvt_ShutdownWindows_Start
0x140045D60: "__cdecl _imp_RtlCompareUnicodeString" __imp_RtlCompareUnicodeString
0x140054940: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-heap-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-heap-l1-1-0
0x140051BF0: "__cdecl _rtc_izz" __rtc_izz
0x1400470C0: "Session0Time" ??_C@_1BK@HCBFHPJE@?$AAS?$AAe?$AAs?$AAs?$AAi?$AAo?$AAn?$AA0?$AAT?$AAi?$AAm?$AAe?$AA?$AA@
0x140045A60: "__cdecl _imp__o___stdio_common_vsnwprintf_s" __imp__o___stdio_common_vsnwprintf_s
0x140045FD0: "__cdecl _imp_NtQueryValueKey" __imp_NtQueryValueKey
0x14004A590: "System\CurrentControlSet\Service" ??_C@_1GG@JJEIMNHF@?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AA?2?$AAC?$AAu?$AAr?$AAr?$AAe?$AAn?$AAt?$AAC?$AAo?$AAn?$AAt?$AAr?$AAo?$AAl?$AAS?$AAe?$AAt?$AA?2?$AAS?$AAe?$AAr?$AAv?$AAi?$AAc?$AAe@
0x140045880: "__cdecl _imp_DeleteCriticalSection" __imp_DeleteCriticalSection
0x14004CC08: "DEVICE: [QualifiedPartition]" ??_C@_1DK@IOFMAAAH@?$AAD?$AAE?$AAV?$AAI?$AAC?$AAE?$AA?3?$AA?5?$AA?$FL?$AAQ?$AAu?$AAa?$AAl?$AAi?$AAf?$AAi?$AAe?$AAd?$AAP?$AAa?$AAr?$AAt?$AAi?$AAt?$AAi?$AAo?$AAn?$AA?$FN?$AA?$AA@
0x14005C180: "__cdecl _imp_WaitForWinstationShutdown" __imp_WaitForWinstationShutdown
0x1400034A0: "__cdecl _security_check_cookie" __security_check_cookie
0x14003E69C: BiBuildIdentifierList
0x140026B08: "int __cdecl WaitForSystemProcesses(void)" ?WaitForSystemProcesses@@YAHXZ
0x14002E558: "void __cdecl WluiiDestroySharedEvents(void)" ?WluiiDestroySharedEvents@@YAXXZ
0x1400051E3: "__cdecl _imp_load_NotifyServiceStatusChangeW" __imp_load_NotifyServiceStatusChangeW
0x140034E54: "public: void __cdecl SP<unsigned char,class SP_HLOCAL<unsigned char> >::Reset(void) __ptr64" ?Reset@?$SP@EV?$SP_HLOCAL@E@@@@QEAAXXZ
0x140046068: "__cdecl _xc_z" __xc_z
0x140048A80: "Failed to get system store path." ??_C@_1FI@JMOEDDGI@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAg?$AAe?$AAt?$AA?5?$AAs?$AAy?$AAs?$AAt?$AAe?$AAm?$AA?5?$AAs?$AAt?$AAo?$AAr?$AAe?$AA?5?$AAp?$AAa?$AAt?$AAh?$AA?4@
0x14002BFD4: "int __cdecl SetupBasicEnvironment(void * __ptr64 * __ptr64)" ?SetupBasicEnvironment@@YAHPEAPEAX@Z
0x140048C30: "\Registry\Machine\SYSTEM\Current" ??_C@_1GG@DILNKBOH@?$AA?2?$AAR?$AAe?$AAg?$AAi?$AAs?$AAt?$AAr?$AAy?$AA?2?$AAM?$AAa?$AAc?$AAh?$AAi?$AAn?$AAe?$AA?2?$AAS?$AAY?$AAS?$AAT?$AAE?$AAM?$AA?2?$AAC?$AAu?$AAr?$AAr?$AAe?$AAn?$AAt@
0x14004FD60: "Failed to load hive into key %ws" ??_C@_1GK@NBGLBMAJ@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAl?$AAo?$AAa?$AAd?$AA?5?$AAh?$AAi?$AAv?$AAe?$AA?5?$AAi?$AAn?$AAt?$AAo?$AA?5?$AAk?$AAe?$AAy?$AA?5?$AA?$CF?$AAw?$AAs@
0x140054A30: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-heap-l2-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-heap-l2-1-0
0x140059200: "struct _RTL_SRWLOCK g_MicrosoftTelemetryAssertLock" ?g_MicrosoftTelemetryAssertLock@@3U_RTL_SRWLOCK@@A
0x1400457A0: api-ms-win-core-processthreads-l1-1-0_NULL_THUNK_DATA
0x14004F060: "BcdGetElementDataWithFlags: Fail" ??_C@_1KA@HLCLNLCE@?$AAB?$AAc?$AAd?$AAG?$AAe?$AAt?$AAE?$AAl?$AAe?$AAm?$AAe?$AAn?$AAt?$AAD?$AAa?$AAt?$AAa?$AAW?$AAi?$AAt?$AAh?$AAF?$AAl?$AAa?$AAg?$AAs?$AA?3?$AA?5?$AAF?$AAa?$AAi?$AAl@
0x1400456B8: "__cdecl _imp_GetProcAddress" __imp_GetProcAddress
0x140045718: "__cdecl _imp_CreateProcessAsUserW" __imp_CreateProcessAsUserW
0x14004B8A0: ""%s" /flags:0x%lx /state0:0x%lx " ??_C@_1JE@CKPFPNDD@?$AA?$CC?$AA?$CF?$AAs?$AA?$CC?$AA?5?$AA?1?$AAf?$AAl?$AAa?$AAg?$AAs?$AA?3?$AA0?$AAx?$AA?$CF?$AAl?$AAx?$AA?5?$AA?1?$AAs?$AAt?$AAa?$AAt?$AAe?$AA0?$AA?3?$AA0?$AAx?$AA?$CF?$AAl?$AAx?$AA?5@
0x140004A4C: "__cdecl _imp_load_PrimaryTerminalAndHookWorker" __imp_load_PrimaryTerminalAndHookWorker
0x14002D31C: WPP_SF_lllll
0x1400425F4: SiGetEspFromFirmware
0x140004096: "__cdecl o__ultow_s" _o__ultow_s
0x1400319E8: "int __cdecl ClaimSetupLaunch(void)" ?ClaimSetupLaunch@@YAHXZ
0x140051380: "Deleting boot entry 0x%x" ??_C@_1DC@NCCLAKLN@?$AAD?$AAe?$AAl?$AAe?$AAt?$AAi?$AAn?$AAg?$AA?5?$AAb?$AAo?$AAo?$AAt?$AA?5?$AAe?$AAn?$AAt?$AAr?$AAy?$AA?5?$AA0?$AAx?$AA?$CF?$AAx?$AA?$AA@
0x140045ED0: "__cdecl _imp_ZwQueryKey" __imp_ZwQueryKey
0x140037F3C: BiOpenStoreKeyFromObject
0x1400049F8: IsWinStationSystemShutdownStartedWorkerPresent
0x1400337E8: KsrpGetOptionList
0x1400049F8: IsWaitForWinstationShutdownPresent
0x1400047AC: IsRecordShutdownReasonPresent
0x14004D0E8: "WIMLoadImage" ??_C@_0N@MPPNAKCM@WIMLoadImage?$AA@
0x140050DF0: "Failed to query process informat" ??_C@_1HC@GNNAHMPH@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAq?$AAu?$AAe?$AAr?$AAy?$AA?5?$AAp?$AAr?$AAo?$AAc?$AAe?$AAs?$AAs?$AA?5?$AAi?$AAn?$AAf?$AAo?$AAr?$AAm?$AAa?$AAt@
0x1400290BC: WppCleanupUm
0x14004BFF8: "\SETUP_LAUNCH_CLAIMED" ??_C@_1CM@PDCEPDCJ@?$AA?2?$AAS?$AAE?$AAT?$AAU?$AAP?$AA_?$AAL?$AAA?$AAU?$AAN?$AAC?$AAH?$AA_?$AAC?$AAL?$AAA?$AAI?$AAM?$AAE?$AAD?$AA?$AA@
0x14004C880: "Failed to get 'SystemRoot', %#08" ??_C@_1EG@DDKAOMGD@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAg?$AAe?$AAt?$AA?5?$AA?8?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AAR?$AAo?$AAo?$AAt?$AA?8?$AA?0?$AA?5?$AA?$CF?$AA?$CD?$AA0?$AA8@
0x140045FD8: "__cdecl _imp_NtQueryBootEntryOrder" __imp_NtQueryBootEntryOrder
0x14002F5B0: ServerWMsg_midl_user_allocate
0x14004AA38: "ncacn_np" ??_C@_1BC@CCHMBIKG@?$AAn?$AAc?$AAa?$AAc?$AAn?$AA_?$AAn?$AAp?$AA?$AA@
0x140048D78: "BiCreateEfiEntry failed %x" ??_C@_1DG@CHHIIJIE@?$AAB?$AAi?$AAC?$AAr?$AAe?$AAa?$AAt?$AAe?$AAE?$AAf?$AAi?$AAE?$AAn?$AAt?$AAr?$AAy?$AA?5?$AAf?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AA?$CF?$AAx?$AA?$AA@
0x140054150: "__cdecl _DELAY_IMPORT_DESCRIPTOR_api_ms_win_service_management_l1_1_0_dll" __DELAY_IMPORT_DESCRIPTOR_api_ms_win_service_management_l1_1_0_dll
0x140050DA0: "Failed to open process. Status: " ??_C@_1EG@GECEKDAJ@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAo?$AAp?$AAe?$AAn?$AA?5?$AAp?$AAr?$AAo?$AAc?$AAe?$AAs?$AAs?$AA?4?$AA?5?$AAS?$AAt?$AAa?$AAt?$AAu?$AAs?$AA?3?$AA?5@
0x14004A383: "__cdecl TraceLoggingMetadataEnd" _TraceLoggingMetadataEnd
0x140004D03: "__cdecl _imp_load_DwmpNotifyUserLogon" __imp_load_DwmpNotifyUserLogon
0x140047030: "system\currentcontrolset\control" ??_C@_1FI@JCMNIPPB@?$AAs?$AAy?$AAs?$AAt?$AAe?$AAm?$AA?2?$AAc?$AAu?$AAr?$AAr?$AAe?$AAn?$AAt?$AAc?$AAo?$AAn?$AAt?$AAr?$AAo?$AAl?$AAs?$AAe?$AAt?$AA?2?$AAc?$AAo?$AAn?$AAt?$AAr?$AAo?$AAl@
0x140045910: "__cdecl _imp_GetSystemTimeAsFileTime" __imp_GetSystemTimeAsFileTime
0x14004A8F8: "BootShell" ??_C@_1BE@EFNIONAO@?$AAB?$AAo?$AAo?$AAt?$AAS?$AAh?$AAe?$AAl?$AAl?$AA?$AA@
0x140040A40: BiSetBootEntryOrder
0x140051010: "Exporting store alterations to e" ??_C@_1EG@HPGNGEP@?$AAE?$AAx?$AAp?$AAo?$AAr?$AAt?$AAi?$AAn?$AAg?$AA?5?$AAs?$AAt?$AAo?$AAr?$AAe?$AA?5?$AAa?$AAl?$AAt?$AAe?$AAr?$AAa?$AAt?$AAi?$AAo?$AAn?$AAs?$AA?5?$AAt?$AAo?$AA?5?$AAe@
0x14004F6C0: "Failed to get registry value. St" ??_C@_1FC@HLAPAKEG@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAg?$AAe?$AAt?$AA?5?$AAr?$AAe?$AAg?$AAi?$AAs?$AAt?$AAr?$AAy?$AA?5?$AAv?$AAa?$AAl?$AAu?$AAe?$AA?4?$AA?5?$AAS?$AAt@
0x14004F3B0: "Deleting element %08x" ??_C@_1CM@NIKMCPNF@?$AAD?$AAe?$AAl?$AAe?$AAt?$AAi?$AAn?$AAg?$AA?5?$AAe?$AAl?$AAe?$AAm?$AAe?$AAn?$AAt?$AA?5?$AA?$CF?$AA0?$AA8?$AAx?$AA?$AA@
0x140048C08: "FirmwareVariable" ??_C@_1CC@MDJGBMLK@?$AAF?$AAi?$AAr?$AAm?$AAw?$AAa?$AAr?$AAe?$AAV?$AAa?$AAr?$AAi?$AAa?$AAb?$AAl?$AAe?$AA?$AA@
0x14004C8D0: "Failed to get 'OsDevice', %#08lx" ??_C@_1EC@LIHCPNNK@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAg?$AAe?$AAt?$AA?5?$AA?8?$AAO?$AAs?$AAD?$AAe?$AAv?$AAi?$AAc?$AAe?$AA?8?$AA?0?$AA?5?$AA?$CF?$AA?$CD?$AA0?$AA8?$AAl?$AAx@
0x140045BF8: "__cdecl _imp_RtlCapabilityCheckForSingleSessionSku" __imp_RtlCapabilityCheckForSingleSessionSku
0x140045650: "__cdecl _imp_LocalAlloc" __imp_LocalAlloc
0x140045E78: "__cdecl _imp_EtwGetTraceEnableLevel" __imp_EtwGetTraceEnableLevel
0x14005C018: "__cdecl _imp_ReportEventW" __imp_ReportEventW
0x14004F340: "Failed to set registry data for " ??_C@_1GO@IGGIJOKF@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAs?$AAe?$AAt?$AA?5?$AAr?$AAe?$AAg?$AAi?$AAs?$AAt?$AAr?$AAy?$AA?5?$AAd?$AAa?$AAt?$AAa?$AA?5?$AAf?$AAo?$AAr?$AA?5@
0x140045528: "__cdecl _imp_DelayLoadFailureHook" __imp_DelayLoadFailureHook
0x14003D730: BiFilterIsPolicyActive
0x140045E90: "__cdecl _imp_WinSqmIsOptedIn" __imp_WinSqmIsOptedIn
0x1400342D4: KsrpUnloadAndUnregisterDriver
0x140050898: "\Device\HarddiskVolume" ??_C@_1CO@JFDIPJLA@?$AA?2?$AAD?$AAe?$AAv?$AAi?$AAc?$AAe?$AA?2?$AAH?$AAa?$AAr?$AAd?$AAd?$AAi?$AAs?$AAk?$AAV?$AAo?$AAl?$AAu?$AAm?$AAe?$AA?$AA@
0x1400472E0: "DumpFile" ??_C@_1BC@LMFNIDDK@?$AAD?$AAu?$AAm?$AAp?$AAF?$AAi?$AAl?$AAe?$AA?$AA@
0x140047F10: "Failed to prepare the OS, Initia" ??_C@_1GE@LPLLGLGP@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAp?$AAr?$AAe?$AAp?$AAa?$AAr?$AAe?$AA?5?$AAt?$AAh?$AAe?$AA?5?$AAO?$AAS?$AA?0?$AA?5?$AAI?$AAn?$AAi?$AAt?$AAi?$AAa@
0x14005C0B0: api-ms-win-service-private-l1-1-0_NULL_THUNK_DATA_DLA
0x1400459A0: "__cdecl _imp__set_app_type" __imp__set_app_type
0x140045780: "__cdecl _imp_CreateRemoteThread" __imp_CreateRemoteThread
0x140045630: "__cdecl _imp_GetProcessHeap" __imp_GetProcessHeap
0x140005B80: "__cdecl _chkstk" __chkstk
0x1400480F0: "ErrorControl" ??_C@_1BK@PIFCGMJC@?$AAE?$AAr?$AAr?$AAo?$AAr?$AAC?$AAo?$AAn?$AAt?$AAr?$AAo?$AAl?$AA?$AA@
0x140050580: GUID_WINDOWS_BOOTMGR
0x14004D008: "Failed to load driver, %#08lx" ??_C@_1DM@JNLLIJKE@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAl?$AAo?$AAa?$AAd?$AA?5?$AAd?$AAr?$AAi?$AAv?$AAe?$AAr?$AA?0?$AA?5?$AA?$CF?$AA?$CD?$AA0?$AA8?$AAl?$AAx?$AA?$AA@
0x140004CF1: "__cdecl _imp_load_DwmpTerminateSessionProcess" __imp_load_DwmpTerminateSessionProcess
0x14005C0F8: ext-ms-win-composition-init-l1-1-0_NULL_THUNK_DATA_DLA
0x140054830: ext-ms-win-composition-init-l1-1-0_NULL_THUNK_DATA_DLB
0x140002410: WmsgpConnect
0x14005944C: "__cdecl _@@_PchSym_@00@KxulyqvxgPillgKxulmvxlivUwhUhvxfirgbUfnhgzigfkUfnhsokiUlyquivUznwGEUkivxlnkOlyq@UmsHlpr" __@@_PchSym_@00@KxulyqvxgPillgKxulmvxlivUwhUhvxfirgbUfnhgzigfkUfnhsokiUlyquivUznwGEUkivxlnkOlyq@UmsHlpr
0x140045F60: "__cdecl _imp_RtlInitAnsiString" __imp_RtlInitAnsiString
0x140045BE0: "__cdecl _imp_NtPrivilegeObjectAuditAlarm" __imp_NtPrivilegeObjectAuditAlarm
0x14005C050: "__cdecl _imp_LookupAccountSidLocalW" __imp_LookupAccountSidLocalW
0x140059340: "struct _RTL_CRITICAL_SECTION g_csNamedEscape" ?g_csNamedEscape@@3U_RTL_CRITICAL_SECTION@@A
0x1400542E8: ext-ms-win-composition-init-l1-1-0_NULL_THUNK_DATA_DLN
0x140058DB8: "__cdecl _hmod__ext_ms_win_coreui_navshutdown_l1_1_0_dll" __hmod__ext_ms_win_coreui_navshutdown_l1_1_0_dll
0x1400464B0: "__cdecl _sz_ext_ms_win_ntuser_keyboard_l1_1_0_dll" __sz_ext_ms_win_ntuser_keyboard_l1_1_0_dll
0x14000526E: "__cdecl _imp_load_CloseServiceHandle" __imp_load_CloseServiceHandle
0x14004A458: WLEvt_DwmpNotifyUserLogon_Start
0x140048110: "Failed to set 'ErrorControl' val" ??_C@_1FG@LDIBBCJK@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAs?$AAe?$AAt?$AA?5?$AA?8?$AAE?$AAr?$AAr?$AAo?$AAr?$AAC?$AAo?$AAn?$AAt?$AAr?$AAo?$AAl?$AA?8?$AA?5?$AAv?$AAa?$AAl@
0x140045510: api-ms-win-core-datetime-l1-1-1_NULL_THUNK_DATA
0x1400512B0: "BCDOBJECT=" ??_C@_1BG@IHEHAJI@?$AAB?$AAC?$AAD?$AAO?$AAB?$AAJ?$AAE?$AAC?$AAT?$AA?$DN?$AA?$AA@
0x14002788C: TraceLoggingRegisterEx
0x1400084D0: "void __cdecl AutoCheckLogsCallback(void * __ptr64,unsigned char)" ?AutoCheckLogsCallback@@YAXPEAXE@Z
0x14004AA28: "\PIPE\" ??_C@_1O@PGAGHCON@?$AA?2?$AAP?$AAI?$AAP?$AAE?$AA?2?$AA?$AA@
0x140045D28: "__cdecl _imp_EtwEventEnabled" __imp_EtwEventEnabled
0x14004B218: "Wininit" ??_C@_1BA@OGDJLPKO@?$AAW?$AAi?$AAn?$AAi?$AAn?$AAi?$AAt?$AA?$AA@
0x140051670: "multi(%d)disk(%d)rdisk(%d)" ??_C@_1DG@NPLCAPOH@?$AAm?$AAu?$AAl?$AAt?$AAi?$AA?$CI?$AA?$CF?$AAd?$AA?$CJ?$AAd?$AAi?$AAs?$AAk?$AA?$CI?$AA?$CF?$AAd?$AA?$CJ?$AAr?$AAd?$AAi?$AAs?$AAk?$AA?$CI?$AA?$CF?$AAd?$AA?$CJ?$AA?$AA@
0x140059370: "unsigned short * gwszUmfdAccountName" ?gwszUmfdAccountName@@3PAGA
0x14004C2C0: "Failed to open the target object" ??_C@_1FC@MFOKNOFA@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAo?$AAp?$AAe?$AAn?$AA?5?$AAt?$AAh?$AAe?$AA?5?$AAt?$AAa?$AAr?$AAg?$AAe?$AAt?$AA?5?$AAo?$AAb?$AAj?$AAe?$AAc?$AAt@
0x14002C13C: "int __cdecl TransferAutochkLogToEventLogIfAvailable(unsigned short const * __ptr64)" ?TransferAutochkLogToEventLogIfAvailable@@YAHPEBG@Z
0x1400453E0: "__cdecl _imp_RpcStringBindingParseW" __imp_RpcStringBindingParseW
0x1400494B0: "Kernel_Lsa_Ppl_Config" ??_C@_1CM@IGDPDBMK@?$AAK?$AAe?$AAr?$AAn?$AAe?$AAl?$AA_?$AAL?$AAs?$AAa?$AA_?$AAP?$AAp?$AAl?$AA_?$AAC?$AAo?$AAn?$AAf?$AAi?$AAg?$AA?$AA@
0x140047630: "%SystemRoot%\system32\lsass.exe" ??_C@_1EA@IJALJINO@?$AA?$CF?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AAR?$AAo?$AAo?$AAt?$AA?$CF?$AA?2?$AAs?$AAy?$AAs?$AAt?$AAe?$AAm?$AA3?$AA2?$AA?2?$AAl?$AAs?$AAa?$AAs?$AAs?$AA?4?$AAe?$AAx?$AAe?$AA?$AA@
0x1400513D0: "Failed to delete boot entry 0x%x" ??_C@_1FK@DFNGLIPH@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAd?$AAe?$AAl?$AAe?$AAt?$AAe?$AA?5?$AAb?$AAo?$AAo?$AAt?$AA?5?$AAe?$AAn?$AAt?$AAr?$AAy?$AA?5?$AA0?$AAx?$AA?$CF?$AAx@
0x140059400: "struct _WNF_USER_SUBSCRIPTION * __ptr64 __ptr64 _wnfSubscription" ?_wnfSubscription@@3PEAU_WNF_USER_SUBSCRIPTION@@EA
0x14004A3B8: WIEvt_AppInit_DLLs_Enabled
0x140045730: "__cdecl _imp_DeleteProcThreadAttributeList" __imp_DeleteProcThreadAttributeList
0x140047C10: "BcdOpenStore failed, %#08lx" ??_C@_1DI@NCPKDOMN@?$AAB?$AAc?$AAd?$AAO?$AAp?$AAe?$AAn?$AAS?$AAt?$AAo?$AAr?$AAe?$AA?5?$AAf?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?0?$AA?5?$AA?$CF?$AA?$CD?$AA0?$AA8?$AAl?$AAx?$AA?$AA@
0x14004D180: "\winload.sys" ??_C@_1BK@FNOKFGGL@?$AA?2?$AAw?$AAi?$AAn?$AAl?$AAo?$AAa?$AAd?$AA?4?$AAs?$AAy?$AAs?$AA?$AA@
0x140050400: "The system store is not already " ??_C@_1EO@GNKAIEIC@?$AAT?$AAh?$AAe?$AA?5?$AAs?$AAy?$AAs?$AAt?$AAe?$AAm?$AA?5?$AAs?$AAt?$AAo?$AAr?$AAe?$AA?5?$AAi?$AAs?$AA?5?$AAn?$AAo?$AAt?$AA?5?$AAa?$AAl?$AAr?$AAe?$AAa?$AAd?$AAy?$AA?5@
0x140050450: "Specified flags prevent opening " ??_C@_1GM@ODHJAIDK@?$AAS?$AAp?$AAe?$AAc?$AAi?$AAf?$AAi?$AAe?$AAd?$AA?5?$AAf?$AAl?$AAa?$AAg?$AAs?$AA?5?$AAp?$AAr?$AAe?$AAv?$AAe?$AAn?$AAt?$AA?5?$AAo?$AAp?$AAe?$AAn?$AAi?$AAn?$AAg?$AA?5@
0x14003FA7C: BiExportEfiBootManager
0x14005C170: "__cdecl _imp_WinStationSystemShutdownStartedWorker" __imp_WinStationSystemShutdownStartedWorker
0x140045960: "__cdecl _imp_GetFileVersionInfoSizeExW" __imp_GetFileVersionInfoSizeExW
0x1400455C0: "__cdecl _imp_CreateDirectoryW" __imp_CreateDirectoryW
0x140031834: ResilientSwitchDesktopWithFade
0x140031E98: "int __cdecl IsSetupCleanInstall(void)" ?IsSetupCleanInstall@@YAHXZ
0x140045850: api-ms-win-core-rtlsupport-l1-1-0_NULL_THUNK_DATA
0x14004B840: ""%s" /flags:0x%lx /state0:0x%lx " ??_C@_1FM@EFHHGHGL@?$AA?$CC?$AA?$CF?$AAs?$AA?$CC?$AA?5?$AA?1?$AAf?$AAl?$AAa?$AAg?$AAs?$AA?3?$AA0?$AAx?$AA?$CF?$AAl?$AAx?$AA?5?$AA?1?$AAs?$AAt?$AAa?$AAt?$AAe?$AA0?$AA?3?$AA0?$AAx?$AA?$CF?$AAl?$AAx?$AA?5@
0x140045F08: "__cdecl _imp_ZwLoadKey" __imp_ZwLoadKey
0x140045D30: "__cdecl _imp_EtwEventActivityIdControl" __imp_EtwEventActivityIdControl
0x14004CBB0: "DEVICE: RamDisk: '%ws'" ??_C@_1CO@LGEGMFOA@?$AAD?$AAE?$AAV?$AAI?$AAC?$AAE?$AA?3?$AA?5?$AAR?$AAa?$AAm?$AAD?$AAi?$AAs?$AAk?$AA?3?$AA?5?$AA?8?$AA?$CF?$AAw?$AAs?$AA?8?$AA?$AA@
0x140004C00: IsDwmpCreateSessionProcessPresent
0x1400460A8: "__cdecl _xp_z" __xp_z
0x140045940: "__cdecl _imp_SystemTimeToFileTime" __imp_SystemTimeToFileTime
0x1400504C0: "Synchronizing store with firmwar" ??_C@_1EE@IPBKMGFA@?$AAS?$AAy?$AAn?$AAc?$AAh?$AAr?$AAo?$AAn?$AAi?$AAz?$AAi?$AAn?$AAg?$AA?5?$AAs?$AAt?$AAo?$AAr?$AAe?$AA?5?$AAw?$AAi?$AAt?$AAh?$AA?5?$AAf?$AAi?$AAr?$AAm?$AAw?$AAa?$AAr@
0x140049E40: "winload.sys" ??_C@_1BI@EAPCKFEA@?$AAw?$AAi?$AAn?$AAl?$AAo?$AAa?$AAd?$AA?4?$AAs?$AAy?$AAs?$AA?$AA@
0x140046960: "__cdecl _sz_ext_ms_win_session_wtsapi32_l1_1_0_dll" __sz_ext_ms_win_session_wtsapi32_l1_1_0_dll
0x140053F70: "__cdecl _DELAY_IMPORT_DESCRIPTOR_api_ms_win_security_capability_l1_1_0_dll" __DELAY_IMPORT_DESCRIPTOR_api_ms_win_security_capability_l1_1_0_dll
0x1400459A0: "__cdecl _imp__o__set_app_type" __imp__o__set_app_type
0x1400459A8: "__cdecl _imp__o__set_fmode" __imp__o__set_fmode
0x1400511B8: "BiBindEfiEntries failed %x" ??_C@_1DG@JDHODPKM@?$AAB?$AAi?$AAB?$AAi?$AAn?$AAd?$AAE?$AAf?$AAi?$AAE?$AAn?$AAt?$AAr?$AAi?$AAe?$AAs?$AA?5?$AAf?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AA?$CF?$AAx?$AA?$AA@
0x140047A18: "Global\UMSServicesStarted" ??_C@_1DE@NEJIKEAE@?$AAG?$AAl?$AAo?$AAb?$AAa?$AAl?$AA?2?$AAU?$AAM?$AAS?$AAS?$AAe?$AAr?$AAv?$AAi?$AAc?$AAe?$AAs?$AAS?$AAt?$AAa?$AAr?$AAt?$AAe?$AAd?$AA?$AA@
0x14002AD80: s_BaseAbortShutdown
0x140050FC0: "BiBindEfiNamespaceObjects failed" ??_C@_1EI@CKKEMGAG@?$AAB?$AAi?$AAB?$AAi?$AAn?$AAd?$AAE?$AAf?$AAi?$AAN?$AAa?$AAm?$AAe?$AAs?$AAp?$AAa?$AAc?$AAe?$AAO?$AAb?$AAj?$AAe?$AAc?$AAt?$AAs?$AA?5?$AAf?$AAa?$AAi?$AAl?$AAe?$AAd@
0x140054C24: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-rtlsupport-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-rtlsupport-l1-1-0
0x1400477C0: "LastBootPerfCounterFrequency" ??_C@_1DK@HHNMLAIB@?$AAL?$AAa?$AAs?$AAt?$AAB?$AAo?$AAo?$AAt?$AAP?$AAe?$AAr?$AAf?$AAC?$AAo?$AAu?$AAn?$AAt?$AAe?$AAr?$AAF?$AAr?$AAe?$AAq?$AAu?$AAe?$AAn?$AAc?$AAy?$AA?$AA@
0x140054BAC: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-apiquery-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-apiquery-l1-1-0
0x1400457D0: api-ms-win-core-profile-l1-1-0_NULL_THUNK_DATA
0x140051C00: "__cdecl _rtc_tzz" __rtc_tzz
0x1400460C0: "__cdecl _guard_fids_table" __guard_fids_table
0x140045A08: "__cdecl _imp_wcscpy_s" __imp_wcscpy_s
0x140046750: "ext-ms-win-ntuser-private-l1-3-2" ??_C@_1EC@JFPGGCMG@?$AAe?$AAx?$AAt?$AA?9?$AAm?$AAs?$AA?9?$AAw?$AAi?$AAn?$AA?9?$AAn?$AAt?$AAu?$AAs?$AAe?$AAr?$AA?9?$AAp?$AAr?$AAi?$AAv?$AAa?$AAt?$AAe?$AA?9?$AAl?$AA1?$AA?9?$AA3?$AA?9?$AA2@
0x1400332DC: KsrpLogMessage
0x140045F30: "__cdecl _imp_ZwSetSecurityObject" __imp_ZwSetSecurityObject
0x140050F38: "Process Name [%d]: %ws" ??_C@_1CO@NHPCNFEE@?$AAP?$AAr?$AAo?$AAc?$AAe?$AAs?$AAs?$AA?5?$AAN?$AAa?$AAm?$AAe?$AA?5?$AA?$FL?$AA?$CF?$AAd?$AA?$FN?$AA?3?$AA?5?$AA?$CF?$AAw?$AAs?$AA?$AA@
0x140045BB0: "__cdecl _imp_CreateWellKnownSid" __imp_CreateWellKnownSid
0x140045C28: "__cdecl _imp_NtShutdownSystem" __imp_NtShutdownSystem
0x140058E18: "__cdecl _@@_PchSym_@00@KxulyqvxgPillgKxulmvxlivUwhUhvxfirgbUfnhgzigfkUoltlmfrUzkrUlyquivUznwGEUkivxlnkrovwOlyq@wluiapi" __@@_PchSym_@00@KxulyqvxgPillgKxulmvxlivUwhUhvxfirgbUfnhgzigfkUoltlmfrUzkrUlyquivUznwGEUkivxlnkrovwOlyq@wluiapi
0x140050AC0: "\Registry\Machine\System\Current" ??_C@_1HE@EPADLGDB@?$AA?2?$AAR?$AAe?$AAg?$AAi?$AAs?$AAt?$AAr?$AAy?$AA?2?$AAM?$AAa?$AAc?$AAh?$AAi?$AAn?$AAe?$AA?2?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AA?2?$AAC?$AAu?$AAr?$AAr?$AAe?$AAn?$AAt@
0x140054190: "__cdecl _DELAY_IMPORT_DESCRIPTOR_api_ms_win_service_management_l2_1_0_dll" __DELAY_IMPORT_DESCRIPTOR_api_ms_win_service_management_l2_1_0_dll
0x140043240: "__cdecl load_config_used" _load_config_used
0x140058D70: "__cdecl _hmod__ext_ms_win_session_wininit_l1_1_0_dll" __hmod__ext_ms_win_session_wininit_l1_1_0_dll
0x14003F954: BiExportBcdObjects
0x1400540D0: "__cdecl _DELAY_IMPORT_DESCRIPTOR_ext_ms_onecore_shellchromeapi_l1_1_1_dll" __DELAY_IMPORT_DESCRIPTOR_ext_ms_onecore_shellchromeapi_l1_1_1_dll
0x140048DB0: "BiUpdateEfiEntry failed %x" ??_C@_1DG@KDLKCBFG@?$AAB?$AAi?$AAU?$AAp?$AAd?$AAa?$AAt?$AAe?$AAE?$AAf?$AAi?$AAE?$AAn?$AAt?$AAr?$AAy?$AA?5?$AAf?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AA?$CF?$AAx?$AA?$AA@
0x1400046CC: IsExitWindowsExPresent
0x14004BF60: WPP_93b9e03668c83b5ad5bb53997a4e2f2c_Traceguids
0x140045F58: "__cdecl _imp_ZwQueryInformationProcess" __imp_ZwQueryInformationProcess
0x14002C27C: "unsigned long __cdecl UIDisplayStatusMessage(unsigned int,enum _WLUI_STATE,unsigned long)" ?UIDisplayStatusMessage@@YAKIW4_WLUI_STATE@@K@Z
0x140053F30: "__cdecl _DELAY_IMPORT_DESCRIPTOR_api_ms_win_security_sddl_l1_1_0_dll" __DELAY_IMPORT_DESCRIPTOR_api_ms_win_security_sddl_l1_1_0_dll
0x140045BA0: "__cdecl _imp_SetTokenInformation" __imp_SetTokenInformation
0x14000408A: "__cdecl set_new_mode" _set_new_mode
0x14004C740: "BcdQueryObject() failed, %#08lx" ??_C@_1EA@OJMDBOBA@?$AAB?$AAc?$AAd?$AAQ?$AAu?$AAe?$AAr?$AAy?$AAO?$AAb?$AAj?$AAe?$AAc?$AAt?$AA?$CI?$AA?$CJ?$AA?5?$AAf?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?0?$AA?5?$AA?$CF?$AA?$CD?$AA0?$AA8?$AAl?$AAx?$AA?$AA@
0x14004D098: "WIMGAPI.DLL" ??_C@_0M@BBAFBFGF@WIMGAPI?4DLL?$AA@
0x140045540: api-ms-win-core-delayload-l1-1-1_NULL_THUNK_DATA
0x140045530: api-ms-win-core-delayload-l1-1-0_NULL_THUNK_DATA
0x140053F90: "__cdecl _DELAY_IMPORT_DESCRIPTOR_api_ms_win_eventlog_legacy_l1_1_0_dll" __DELAY_IMPORT_DESCRIPTOR_api_ms_win_eventlog_legacy_l1_1_0_dll
0x1400041E8: swprintf_s
0x140047A68: "RPCSS" ??_C@_1M@BJMOGEFA@?$AAR?$AAP?$AAC?$AAS?$AAS?$AA?$AA@
0x140048B00: "\Device\Harddisk%lu\Partition%lu" ??_C@_1EC@CDJBOKNM@?$AA?2?$AAD?$AAe?$AAv?$AAi?$AAc?$AAe?$AA?2?$AAH?$AAa?$AAr?$AAd?$AAd?$AAi?$AAs?$AAk?$AA?$CF?$AAl?$AAu?$AA?2?$AAP?$AAa?$AAr?$AAt?$AAi?$AAt?$AAi?$AAo?$AAn?$AA?$CF?$AAl?$AAu@
0x14000402A: "__cdecl o__exit" _o__exit
0x140054170: "__cdecl _DELAY_IMPORT_DESCRIPTOR_api_ms_win_service_winsvc_l1_1_0_dll" __DELAY_IMPORT_DESCRIPTOR_api_ms_win_service_winsvc_l1_1_0_dll
0x140045D88: "__cdecl _imp_ZwClose" __imp_ZwClose
0x140050A98: "ZwUnloadKey2" ??_C@_0N@MNPIGGIJ@ZwUnloadKey2?$AA@
0x14003C70C: BiLoadHive
0x140054740: api-ms-win-service-private-l1-1-0_NULL_THUNK_DATA_DLB
0x14004B410: WPP_11adf6ceffd9339ae5756d352ab468bd_Traceguids
0x140046090: "__cdecl _scrt_stdio_legacy_msvcrt_compatibility" __scrt_stdio_legacy_msvcrt_compatibility
0x14002DD58: "long __cdecl StringCchLengthW(unsigned short const * __ptr64,unsigned __int64,unsigned __int64 * __ptr64)" ?StringCchLengthW@@YAJPEBG_KPEA_K@Z
0x1400459F8: "__cdecl _imp_toupper" __imp_toupper
0x14002B8BC: "unsigned long __cdecl GetDWORDPolicyValue(struct HKEY__ * __ptr64,unsigned short const * __ptr64,unsigned short const * __ptr64,unsigned long)" ?GetDWORDPolicyValue@@YAKPEAUHKEY__@@PEBG1K@Z
0x14004B518: WPP_b4e2f713360b3d010799b1753967ed40_Traceguids
0x140039A94: BiConvertNtFilePathToBootEnvironment
0x140045DE8: "__cdecl _imp_NtSetInformationProcess" __imp_NtSetInformationProcess
0x140058D80: "__cdecl _hmod__ext_ms_win_onecore_shutdown_l1_1_0_dll" __hmod__ext_ms_win_onecore_shutdown_l1_1_0_dll
0x14004A910: "SYSTEM\CurrentControlSet\Control" ??_C@_1GC@JHOBCLGJ@?$AAS?$AAY?$AAS?$AAT?$AAE?$AAM?$AA?2?$AAC?$AAu?$AAr?$AAr?$AAe?$AAn?$AAt?$AAC?$AAo?$AAn?$AAt?$AAr?$AAo?$AAl?$AAS?$AAe?$AAt?$AA?2?$AAC?$AAo?$AAn?$AAt?$AAr?$AAo?$AAl@
0x140058D08: "__cdecl _hmod__ext_ms_win_core_stateseparationext_l1_1_0_dll" __hmod__ext_ms_win_core_stateseparationext_l1_1_0_dll
0x140045A38: "__cdecl _imp__configthreadlocale" __imp__configthreadlocale
0x140045808: "__cdecl _imp_RegQueryValueExA" __imp_RegQueryValueExA
0x1400549F4: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-processenvironment-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-processenvironment-l1-1-0
0x140045430: "__cdecl _imp_Ndr64AsyncClientCall" __imp_Ndr64AsyncClientCall
0x140045AC8: "__cdecl _imp_wcsnlen" __imp_wcsnlen
0x140024D5C: "long __cdecl ResetShutdownStopTimePerfCounter(void)" ?ResetShutdownStopTimePerfCounter@@YAJXZ
0x1400467F0: "__cdecl _sz_ext_ms_win_ntuser_private_l1_1_0_dll" __sz_ext_ms_win_ntuser_private_l1_1_0_dll
0x1400453F8: "__cdecl _imp_RpcServerInqCallAttributesW" __imp_RpcServerInqCallAttributesW
0x1400453C0: "__cdecl _imp_RpcBindingToStringBindingW" __imp_RpcBindingToStringBindingW
0x14004FA60: "Closing store. Flags: 0x%x" ??_C@_1DG@JAFNKMKP@?$AAC?$AAl?$AAo?$AAs?$AAi?$AAn?$AAg?$AA?5?$AAs?$AAt?$AAo?$AAr?$AAe?$AA?4?$AA?5?$AAF?$AAl?$AAa?$AAg?$AAs?$AA?3?$AA?5?$AA0?$AAx?$AA?$CF?$AAx?$AA?$AA@
0x140045B58: "__cdecl _imp_SetKernelObjectSecurity" __imp_SetKernelObjectSecurity
0x140045A48: "__cdecl _imp__o___stdio_common_vswscanf" __imp__o___stdio_common_vswscanf
0x1400382B4: BiReleaseBcdSyncMutant
0x1400453D8: "__cdecl _imp_RpcBindingFromStringBindingW" __imp_RpcBindingFromStringBindingW
0x140003A90: "__cdecl _scrt_get_dyn_tls_init_callback" __scrt_get_dyn_tls_init_callback
0x14002F880: StartWMsgServer
0x140047D30: "Failed to calculate the drivers " ??_C@_1HO@JHLDNMFI@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAc?$AAa?$AAl?$AAc?$AAu?$AAl?$AAa?$AAt?$AAe?$AA?5?$AAt?$AAh?$AAe?$AA?5?$AAd?$AAr?$AAi?$AAv?$AAe?$AAr?$AAs?$AA?5@
0x140029B9C: "long __cdecl InitiatePanicSystemShutdown(struct _UNICODE_STRING * __ptr64,struct _UNICODE_STRING * __ptr64,unsigned long,unsigned long)" ?InitiatePanicSystemShutdown@@YAJPEAU_UNICODE_STRING@@0KK@Z
0x140045F80: "__cdecl _imp_NtOpenProcessTokenEx" __imp_NtOpenProcessTokenEx
0x140045C50: "__cdecl _imp_RtlDestroyEnvironment" __imp_RtlDestroyEnvironment
0x140045C48: "__cdecl _imp_NtQueryInformationProcess" __imp_NtQueryInformationProcess
0x14005C0E8: "__cdecl _imp_DwmpTerminateSessionProcess" __imp_DwmpTerminateSessionProcess
0x140045C80: "__cdecl _imp_NtClose" __imp_NtClose
0x1400505C0: "Failed to get object identifier." ??_C@_1FI@PDDFMHFP@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAg?$AAe?$AAt?$AA?5?$AAo?$AAb?$AAj?$AAe?$AAc?$AAt?$AA?5?$AAi?$AAd?$AAe?$AAn?$AAt?$AAi?$AAf?$AAi?$AAe?$AAr?$AA?4@
0x140058E88: "unsigned long cSystemProcesses" ?cSystemProcesses@@3KA
0x14004B338: "System" ??_C@_1O@GINMMDNN@?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AA?$AA@
0x140025C24: "long __cdecl StringCchPrintfW(unsigned short * __ptr64,unsigned __int64,unsigned short const * __ptr64,...)" ?StringCchPrintfW@@YAJPEAG_KPEBGZZ
0x140053FF0: "__cdecl _DELAY_IMPORT_DESCRIPTOR_ext_ms_win_ntuser_keyboard_l1_1_0_dll" __DELAY_IMPORT_DESCRIPTOR_ext_ms_win_ntuser_keyboard_l1_1_0_dll
0x140045948: "__cdecl _imp_FileTimeToSystemTime" __imp_FileTimeToSystemTime
0x14004CEC0: "\Device\winload" ??_C@_1CA@HPGNMNOJ@?$AA?2?$AAD?$AAe?$AAv?$AAi?$AAc?$AAe?$AA?2?$AAw?$AAi?$AAn?$AAl?$AAo?$AAa?$AAd?$AA?$AA@
0x140045978: "__cdecl _imp__o__get_narrow_winmain_command_line" __imp__o__get_narrow_winmain_command_line
0x14004CDF0: "NtDeleteKey(ServiceKey) failed, " ??_C@_1EO@NFAFKAFI@?$AAN?$AAt?$AAD?$AAe?$AAl?$AAe?$AAt?$AAe?$AAK?$AAe?$AAy?$AA?$CI?$AAS?$AAe?$AAr?$AAv?$AAi?$AAc?$AAe?$AAK?$AAe?$AAy?$AA?$CJ?$AA?5?$AAf?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?0?$AA?5@
0x140054130: "__cdecl _DELAY_IMPORT_DESCRIPTOR_api_ms_win_base_bootconfig_l1_1_0_dll" __DELAY_IMPORT_DESCRIPTOR_api_ms_win_base_bootconfig_l1_1_0_dll
0x14002F620: ServerWMsg_midl_user_free
0x14004A3A8: WIEvt_ShutdownWindows_Stop
0x14002AA08: "void __cdecl WsdpStopShutdownServerInterfaces(void)" ?WsdpStopShutdownServerInterfaces@@YAXXZ
0x140045FA0: "__cdecl _imp_RtlLookupFunctionEntry" __imp_RtlLookupFunctionEntry
0x1400457C8: "__cdecl _imp_QueryPerformanceCounter" __imp_QueryPerformanceCounter
0x140054890: api-ms-win-base-bootconfig-l1-1-0_NULL_THUNK_DATA_DLB
0x14005C030: "__cdecl _imp_RegisterLogonProcess" __imp_RegisterLogonProcess
0x1400548F0: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-crt-string-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-crt-string-l1-1-0
0x140041D6C: SiTranslateSymbolicLink
0x14005C108: ext-ms-win-core-stateseparationext-l1-1-0_NULL_THUNK_DATA_DLA
0x1400049F8: IsUIStartupWorkerPresent
0x1400494E0: "RunasPPL" ??_C@_1BC@MNIEMBKH@?$AAR?$AAu?$AAn?$AAa?$AAs?$AAP?$AAP?$AAL?$AA?$AA@
0x140048278: "ImagePath" ??_C@_1BE@CMLCLKJK@?$AAI?$AAm?$AAa?$AAg?$AAe?$AAP?$AAa?$AAt?$AAh?$AA?$AA@
0x14004EF20: "BcdGetElementDataWithFlags: Fail" ??_C@_1JE@HJEEOFJC@?$AAB?$AAc?$AAd?$AAG?$AAe?$AAt?$AAE?$AAl?$AAe?$AAm?$AAe?$AAn?$AAt?$AAD?$AAa?$AAt?$AAa?$AAW?$AAi?$AAt?$AAh?$AAF?$AAl?$AAa?$AAg?$AAs?$AA?3?$AA?5?$AAF?$AAa?$AAi?$AAl@
0x140003FBE: "__cdecl _p__commode" __p__commode
0x14003B1F4: BiTranslateSymbolicLink
0x140050B90: "MININT" ??_C@_1O@LCFBJBMP@?$AAM?$AAI?$AAN?$AAI?$AAN?$AAT?$AA?$AA@
0x140045CA0: "__cdecl _imp_RtlDosPathNameToNtPathName_U_WithStatus" __imp_RtlDosPathNameToNtPathName_U_WithStatus
0x140045E68: "__cdecl _imp_EtwGetTraceEnableFlags" __imp_EtwGetTraceEnableFlags
0x1400454D8: "__cdecl _imp_RpcMgmtIsServerListening" __imp_RpcMgmtIsServerListening
0x14002F1A8: WmsgpSendMessage
0x14004A6B0: "PrimaryDnsSuffix" ??_C@_1CC@IDHPGFBN@?$AAP?$AAr?$AAi?$AAm?$AAa?$AAr?$AAy?$AAD?$AAn?$AAs?$AAS?$AAu?$AAf?$AAf?$AAi?$AAx?$AA?$AA@
0x14004F3E0: "Deleting element %08x blocked by" ??_C@_1GK@FOHCBMEA@?$AAD?$AAe?$AAl?$AAe?$AAt?$AAi?$AAn?$AAg?$AA?5?$AAe?$AAl?$AAe?$AAm?$AAe?$AAn?$AAt?$AA?5?$AA?$CF?$AA0?$AA8?$AAx?$AA?5?$AAb?$AAl?$AAo?$AAc?$AAk?$AAe?$AAd?$AA?5?$AAb?$AAy@
0x14004BEB8: "PUBLIC" ??_C@_1O@OIBMMMPB@?$AAP?$AAU?$AAB?$AAL?$AAI?$AAC?$AA?$AA@
0x1400590F0: "struct MicrosoftTelemetryAssertTriggeredNode * __ptr64 __ptr64 g_MicrosoftTelemetryAssertsTriggeredList" ?g_MicrosoftTelemetryAssertsTriggeredList@@3PEAUMicrosoftTelemetryAssertTriggeredNode@@EA
0x14004CF20: "Faild to open the driver, %#08lx" ??_C@_1EC@DAHOKJCJ@?$AAF?$AAa?$AAi?$AAl?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAo?$AAp?$AAe?$AAn?$AA?5?$AAt?$AAh?$AAe?$AA?5?$AAd?$AAr?$AAi?$AAv?$AAe?$AAr?$AA?0?$AA?5?$AA?$CF?$AA?$CD?$AA0?$AA8?$AAl?$AAx@
0x14003DC2C: BiAcquirePrivilege
0x1400459B0: "__cdecl _imp__o__set_new_mode" __imp__o__set_new_mode
0x140045B68: "__cdecl _imp_GetSecurityDescriptorSacl" __imp_GetSecurityDescriptorSacl
0x140004F30: ApiSetQueryApiSetPresence
0x140045E08: "__cdecl _imp_RtlLeaveCriticalSection" __imp_RtlLeaveCriticalSection
0x140033C34: KsrpControlDriver
0x14004C700: "BcdOpenObject() failed, %#08lx" ??_C@_1DO@FHPCOJKK@?$AAB?$AAc?$AAd?$AAO?$AAp?$AAe?$AAn?$AAO?$AAb?$AAj?$AAe?$AAc?$AAt?$AA?$CI?$AA?$CJ?$AA?5?$AAf?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?0?$AA?5?$AA?$CF?$AA?$CD?$AA0?$AA8?$AAl?$AAx?$AA?$AA@
0x140027BF8: WPP_SF_ddS
0x14002ACF0: WPP_SF_sDD
0x140025074: "unsigned long __cdecl StartSystemProcess(unsigned short * __ptr64,unsigned short * __ptr64,enum SYSTEM_PROCESS_TYPE,unsigned long,unsigned long,unsigned long,void * __ptr64,unsigned long,void * __ptr64 * __ptr64)" ?StartSystemProcess@@YAKPEAG0W4SYSTEM_PROCESS_TYPE@@KKKPEAXKPEAPEAX@Z
0x14005C010: "__cdecl _imp_DeregisterEventSource" __imp_DeregisterEventSource
0x140004AFB: "__cdecl _imp_load_GetLoggedOnUserCount" __imp_load_GetLoggedOnUserCount
0x140045980: "__cdecl _imp__initialize_narrow_environment" __imp__initialize_narrow_environment
0x14004AFE0: "CommonW6432Dir" ??_C@_1BO@EBJJHLMH@?$AAC?$AAo?$AAm?$AAm?$AAo?$AAn?$AAW?$AA6?$AA4?$AA3?$AA2?$AAD?$AAi?$AAr?$AA?$AA@
0x140051510: "SymbolicLink" ??_C@_1BK@KDPOKCA@?$AAS?$AAy?$AAm?$AAb?$AAo?$AAl?$AAi?$AAc?$AAL?$AAi?$AAn?$AAk?$AA?$AA@
0x140027AB0: WPP_SF_SSD
0x140045D40: "__cdecl _imp_NtOpenEvent" __imp_NtOpenEvent
0x1400581F8: KsrpServicePath
0x140045678: "__cdecl _imp_InitializeSListHead" __imp_InitializeSListHead
0x14004AA18: WPP_ThisDir_CTLGUID_WinInit
0x140045400: "__cdecl _imp_RpcStringFreeW" __imp_RpcStringFreeW
0x14002B75C: "void __cdecl DealWithAutochkLogs(void)" ?DealWithAutochkLogs@@YAXXZ
0x140046008: "__cdecl _imp_RtlVirtualUnwind" __imp_RtlVirtualUnwind
0x14004A540: "LoadAppInit_DLLs" ??_C@_1CC@CEEDBKEJ@?$AAL?$AAo?$AAa?$AAd?$AAA?$AAp?$AAp?$AAI?$AAn?$AAi?$AAt?$AA_?$AAD?$AAL?$AAL?$AAs?$AA?$AA@
0x1400457F0: "__cdecl _imp_RegQueryInfoKeyW" __imp_RegQueryInfoKeyW
0x14004BFB0: "SetupType" ??_C@_1BE@MMGHIOAH@?$AAS?$AAe?$AAt?$AAu?$AAp?$AAT?$AAy?$AAp?$AAe?$AA?$AA@
0x14004EEF0: "__cdecl _pfnDefaultDliFailureHook2" __pfnDefaultDliFailureHook2
0x14004B2A0: "userinit" ??_C@_1BC@KAOCMILD@?$AAu?$AAs?$AAe?$AAr?$AAi?$AAn?$AAi?$AAt?$AA?$AA@
0x140045A58: "__cdecl _imp___stdio_common_vswprintf" __imp___stdio_common_vswprintf
0x140045D18: "__cdecl _imp_EtwEventWriteStartScenario" __imp_EtwEventWriteStartScenario
0x1400042A0: "__cdecl _tailMerge_api_ms_win_security_sddl_l1_1_0_dll" __tailMerge_api_ms_win_security_sddl_l1_1_0_dll
0x1400453F0: "__cdecl _imp_NdrAsyncServerCall" __imp_NdrAsyncServerCall
0x14000405A: "__cdecl o__register_onexit_function" _o__register_onexit_function
0x140049280: "\ArcName\" ??_C@_1BE@HOPMDIJK@?$AA?2?$AAA?$AAr?$AAc?$AAN?$AAa?$AAm?$AAe?$AA?2?$AA?$AA@
0x14004A610: "NV Hostname" ??_C@_1BI@NDKOFFBO@?$AAN?$AAV?$AA?5?$AAH?$AAo?$AAs?$AAt?$AAn?$AAa?$AAm?$AAe?$AA?$AA@
0x140004C00: IsDwmpTerminateSessionProcessPresent
0x14004C4E0: "Failed to surface the '%wZ', %#0" ??_C@_1EI@GCFCKIIA@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAs?$AAu?$AAr?$AAf?$AAa?$AAc?$AAe?$AA?5?$AAt?$AAh?$AAe?$AA?5?$AA?8?$AA?$CF?$AAw?$AAZ?$AA?8?$AA?0?$AA?5?$AA?$CF?$AA?$CD?$AA0@
0x1400586F0: "unsigned __int64 `__local_stdio_printf_options'::`2'::_OptionsStorage" ?_OptionsStorage@?1??__local_stdio_printf_options@@9@4_KA
0x140046AE0: "__cdecl _sz_ext_ms_win_composition_init_l1_1_0_dll" __sz_ext_ms_win_composition_init_l1_1_0_dll
0x140045BC8: api-ms-win-stateseparation-helpers-l1-1-0_NULL_THUNK_DATA
0x140002BF0: MIDL_user_allocate
0x140003A60: "__cdecl guard_check_icall_nop" _guard_check_icall_nop
0x140045700: "__cdecl _imp_ExpandEnvironmentStringsW" __imp_ExpandEnvironmentStringsW
0x140005BD7: memcmp
0x140045658: "__cdecl _imp_LocalReAlloc" __imp_LocalReAlloc
0x1400400E8: BiGetFilePathFromEfiPath
0x140038424: BcdCreateObject
0x14002C968: "int __cdecl IsMiniNTMode(void)" ?IsMiniNTMode@@YAHXZ
0x140045A80: "__cdecl _imp_wcsrchr" __imp_wcsrchr
0x1400240D4: "unsigned long __cdecl LaunchProcessInSession(unsigned short * __ptr64,unsigned long,unsigned long,struct _STARTUPINFOW * __ptr64,struct _PROCESS_INFORMATION * __ptr64)" ?LaunchProcessInSession@@YAKPEAGKKPEAU_STARTUPINFOW@@PEAU_PROCESS_INFORMATION@@@Z
0x140004940: "__cdecl _tailMerge_ext_ms_win_session_wtsapi32_l1_1_0_dll" __tailMerge_ext_ms_win_session_wtsapi32_l1_1_0_dll
0x1400355AC: BcdGetElementData
0x140054338: ext-ms-win-ntuser-private-l1-1-0_NULL_THUNK_DATA_DLN
0x14004A638: "NV Domain" ??_C@_1BE@JPMOBOFH@?$AAN?$AAV?$AA?5?$AAD?$AAo?$AAm?$AAa?$AAi?$AAn?$AA?$AA@
0x140003A48: "__cdecl _scrt_stub_for_acrt_uninitialize" __scrt_stub_for_acrt_uninitialize
0x1400492A8: "\Device\%s\Partition%lu" ??_C@_1DA@FBMBGMIJ@?$AA?2?$AAD?$AAe?$AAv?$AAi?$AAc?$AAe?$AA?2?$AA?$CF?$AAs?$AA?2?$AAP?$AAa?$AAr?$AAt?$AAi?$AAt?$AAi?$AAo?$AAn?$AA?$CF?$AAl?$AAu?$AA?$AA@
0x1400050B5: "__cdecl _tailMerge_api_ms_win_service_management_l1_1_0_dll" __tailMerge_api_ms_win_service_management_l1_1_0_dll
0x14004BEA0: "USERPROFILE" ??_C@_1BI@FAOJLPH@?$AAU?$AAS?$AAE?$AAR?$AAP?$AAR?$AAO?$AAF?$AAI?$AAL?$AAE?$AA?$AA@
0x14003AF1C: BiIssueGetDriveLayoutIoctl
0x140045758: "__cdecl _imp_SetPriorityClass" __imp_SetPriorityClass
0x14005C148: ext-ms-win-ntuser-private-l1-1-0_NULL_THUNK_DATA_DLA
0x140051120: "BiBindEfiBootManager failed %x" ??_C@_1DO@EJCDHKOL@?$AAB?$AAi?$AAB?$AAi?$AAn?$AAd?$AAE?$AAf?$AAi?$AAB?$AAo?$AAo?$AAt?$AAM?$AAa?$AAn?$AAa?$AAg?$AAe?$AAr?$AA?5?$AAf?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AA?$CF?$AAx?$AA?$AA@
0x1400547B8: ext-ms-win-ntuser-private-l1-1-0_NULL_THUNK_DATA_DLB
0x14004C598: "\DosDevices\GLOBAL\VDRVROOT" ??_C@_1DI@NHGGIPKM@?$AA?2?$AAD?$AAo?$AAs?$AAD?$AAe?$AAv?$AAi?$AAc?$AAe?$AAs?$AA?2?$AAG?$AAL?$AAO?$AAB?$AAA?$AAL?$AA?2?$AAV?$AAD?$AAR?$AAV?$AAR?$AAO?$AAO?$AAT?$AA?$AA@
0x140045EB0: "__cdecl _imp_RtlGUIDFromString" __imp_RtlGUIDFromString
0x140026DE4: "unsigned long __cdecl WinInitNotifyShutdown(unsigned long)" ?WinInitNotifyShutdown@@YAKK@Z
0x1400345CC: KsrpExtractFileFromWim
0x14004B380: "-d" ??_C@_15EBELCIOA@?$AA?9?$AAd?$AA?$AA@
0x140054090: "__cdecl _DELAY_IMPORT_DESCRIPTOR_ext_ms_win_onecore_shutdown_l1_1_0_dll" __DELAY_IMPORT_DESCRIPTOR_ext_ms_win_onecore_shutdown_l1_1_0_dll
0x140038998: BiGetDefaultBootEntryIdentifier
0x140003FE2: "__cdecl _stdio_common_vswprintf_s" __stdio_common_vswprintf_s
0x14002D02C: "unsigned long __cdecl WMsgClntInitialize(struct WI_GLOBAL_CONTEXT * __ptr64,int)" ?WMsgClntInitialize@@YAKPEAUWI_GLOBAL_CONTEXT@@H@Z
0x140045898: "__cdecl _imp_SleepEx" __imp_SleepEx
0x140047000: "S:(AU;SAFA;0x0010;;;WD)" ??_C@_1DA@HJMEKILO@?$AAS?$AA?3?$AA?$CI?$AAA?$AAU?$AA?$DL?$AAS?$AAA?$AAF?$AAA?$AA?$DL?$AA0?$AAx?$AA0?$AA0?$AA1?$AA0?$AA?$DL?$AA?$DL?$AA?$DL?$AAW?$AAD?$AA?$CJ?$AA?$AA@
0x140045EE8: "__cdecl _imp_ZwQuerySymbolicLinkObject" __imp_ZwQuerySymbolicLinkObject
0x14004C290: "Attaching root device" ??_C@_1CM@OFFDEEDI@?$AAA?$AAt?$AAt?$AAa?$AAc?$AAh?$AAi?$AAn?$AAg?$AA?5?$AAr?$AAo?$AAo?$AAt?$AA?5?$AAd?$AAe?$AAv?$AAi?$AAc?$AAe?$AA?$AA@
0x1400501B0: "\Registry\Machine" ??_C@_1CE@NMBJJGCH@?$AA?2?$AAR?$AAe?$AAg?$AAi?$AAs?$AAt?$AAr?$AAy?$AA?2?$AAM?$AAa?$AAc?$AAh?$AAi?$AAn?$AAe?$AA?$AA@
0x14005C060: "__cdecl _imp_ConvertStringSecurityDescriptorToSecurityDescriptorW" __imp_ConvertStringSecurityDescriptorToSecurityDescriptorW
0x140054B20: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-interlocked-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-interlocked-l1-1-0
0x14004C920: "Unsupported ramdisk parent devic" ??_C@_1IG@BKMJDCAL@?$AAU?$AAn?$AAs?$AAu?$AAp?$AAp?$AAo?$AAr?$AAt?$AAe?$AAd?$AA?5?$AAr?$AAa?$AAm?$AAd?$AAi?$AAs?$AAk?$AA?5?$AAp?$AAa?$AAr?$AAe?$AAn?$AAt?$AA?5?$AAd?$AAe?$AAv?$AAi?$AAc@
0x140048230: "Failed to allocate the path buff" ??_C@_1EG@KIIOELFD@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAa?$AAl?$AAl?$AAo?$AAc?$AAa?$AAt?$AAe?$AA?5?$AAt?$AAh?$AAe?$AA?5?$AAp?$AAa?$AAt?$AAh?$AA?5?$AAb?$AAu?$AAf?$AAf@
0x140054990: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-handle-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-handle-l1-1-0
0x140042C48: SiGetBiosSystemPartition
0x140046E30: WIEvt_Wininit_Lsa_Iso_SK_Not_Present
0x140059270: g_pSidPowerUser
0x1400456B0: "__cdecl _imp_GetModuleHandleW" __imp_GetModuleHandleW
0x140054AA8: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-version-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-version-l1-1-0
0x14004A568: "AppInit_DLLs" ??_C@_1BK@LNFEFIJC@?$AAA?$AAp?$AAp?$AAI?$AAn?$AAi?$AAt?$AA_?$AAD?$AAL?$AAL?$AAs?$AA?$AA@
0x1400453B8: "__cdecl _imp_RpcServerListen" __imp_RpcServerListen
0x140051650: "%s\Partition%lu" ??_C@_1CA@KOFIMBAB@?$AA?$CF?$AAs?$AA?2?$AAP?$AAa?$AAr?$AAt?$AAi?$AAt?$AAi?$AAo?$AAn?$AA?$CF?$AAl?$AAu?$AA?$AA@
0x140050260: "Failed to mark system store. Fil" ??_C@_1GE@BKEKDECN@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAm?$AAa?$AAr?$AAk?$AA?5?$AAs?$AAy?$AAs?$AAt?$AAe?$AAm?$AA?5?$AAs?$AAt?$AAo?$AAr?$AAe?$AA?4?$AA?5?$AAF?$AAi?$AAl@
0x140040E6C: BiUpdateBcdObject
0x1400355C8: BcdGetElementDataWithFlags
0x140050020: "A valid store must have a descri" ??_C@_1FG@CJJHKDMI@?$AAA?$AA?5?$AAv?$AAa?$AAl?$AAi?$AAd?$AA?5?$AAs?$AAt?$AAo?$AAr?$AAe?$AA?5?$AAm?$AAu?$AAs?$AAt?$AA?5?$AAh?$AAa?$AAv?$AAe?$AA?5?$AAa?$AA?5?$AAd?$AAe?$AAs?$AAc?$AAr?$AAi@
0x140034D9C: "public: unsigned long * __ptr64 __cdecl SP<unsigned long,class SP_MEM<unsigned long> >::GetPtrAs<unsigned long>(void)const __ptr64" ??$GetPtrAs@K@?$SP@KV?$SP_MEM@K@@@@QEBAPEAKXZ
0x140045B08: "__cdecl _imp_ControlTraceW" __imp_ControlTraceW
0x140045490: "__cdecl _imp_RpcBindingBind" __imp_RpcBindingBind
0x140045930: "__cdecl _imp_CreateTimerQueueTimer" __imp_CreateTimerQueueTimer
0x1400474D8: " -k -c " ??_C@_1BA@CEFJKJMP@?$AA?5?$AA?9?$AAk?$AA?5?$AA?9?$AAc?$AA?5?$AA?$AA@
0x140008538: "long __cdecl CheckWhetherSecureKernelIsRunning(unsigned char * __ptr64)" ?CheckWhetherSecureKernelIsRunning@@YAJPEAE@Z
0x140045A00: "__cdecl _imp__o_wcscat_s" __imp__o_wcscat_s
0x140003F82: "__cdecl initterm_e" _initterm_e
0x140045468: "__cdecl _imp_RpcBindingVectorFree" __imp_RpcBindingVectorFree
0x140047A10: "," ??_C@_13DEFPDAGF@?$AA?0?$AA?$AA@
0x14003A328: BiGetDriveLayoutInformation
0x140045AF8: api-ms-win-eventing-classicprovider-l1-1-0_NULL_THUNK_DATA
0x140048CC0: "GuidCache" ??_C@_1BE@LHKMDDCD@?$AAG?$AAu?$AAi?$AAd?$AAC?$AAa?$AAc?$AAh?$AAe?$AA?$AA@
0x140003890: "__cdecl _scrt_release_startup_lock" __scrt_release_startup_lock
0x140050878: "Object GUID: %s" ??_C@_1CA@CKEBPLDC@?$AAO?$AAb?$AAj?$AAe?$AAc?$AAt?$AA?5?$AAG?$AAU?$AAI?$AAD?$AA?3?$AA?5?$AA?$CF?$AAs?$AA?$AA@
0x140045D58: "__cdecl _imp_ZwQuerySystemInformation" __imp_ZwQuerySystemInformation
0x140004102: wcstoul
0x140038370: BiWasFirmwareModified
0x140004072: "__cdecl o__set_app_type" _o__set_app_type
0x140045D48: "__cdecl _imp_RtlPublishWnfStateData" __imp_RtlPublishWnfStateData
0x14004B348: "lsass.exe" ??_C@_1BE@FPBDCMAD@?$AAl?$AAs?$AAa?$AAs?$AAs?$AA?4?$AAe?$AAx?$AAe?$AA?$AA@
0x140046230: "Software\Microsoft\Shell\CShellU" ??_C@_1FI@LJFMNNPC@?$AAS?$AAo?$AAf?$AAt?$AAw?$AAa?$AAr?$AAe?$AA?2?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAS?$AAh?$AAe?$AAl?$AAl?$AA?2?$AAC?$AAS?$AAh?$AAe?$AAl?$AAl?$AAU@
0x140047788: "ShutdownStopTimePerfCounter" ??_C@_1DI@KMNHGFKK@?$AAS?$AAh?$AAu?$AAt?$AAd?$AAo?$AAw?$AAn?$AAS?$AAt?$AAo?$AAp?$AAT?$AAi?$AAm?$AAe?$AAP?$AAe?$AAr?$AAf?$AAC?$AAo?$AAu?$AAn?$AAt?$AAe?$AAr?$AA?$AA@
0x140041698: SiGetDriveLayoutInformation
0x14003CB98: BiOpenKeyNonBcd
0x14005C178: "__cdecl _imp_GetLoggedOnUserCount" __imp_GetLoggedOnUserCount
0x14004C530: "The surfaced device does not con" ??_C@_1GI@BLFJCBEE@?$AAT?$AAh?$AAe?$AA?5?$AAs?$AAu?$AAr?$AAf?$AAa?$AAc?$AAe?$AAd?$AA?5?$AAd?$AAe?$AAv?$AAi?$AAc?$AAe?$AA?5?$AAd?$AAo?$AAe?$AAs?$AA?5?$AAn?$AAo?$AAt?$AA?5?$AAc?$AAo?$AAn@
0x140035000: MicrosoftTelemetryAssertTriggeredWorker
0x1400480A0: "Failed to create a service key, " ??_C@_1EO@CHEIEHIH@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAc?$AAr?$AAe?$AAa?$AAt?$AAe?$AA?5?$AAa?$AA?5?$AAs?$AAe?$AAr?$AAv?$AAi?$AAc?$AAe?$AA?5?$AAk?$AAe?$AAy?$AA?0?$AA?5@
0x14004BE70: "NoDebugThread" ??_C@_1BM@JLMGJFLL@?$AAN?$AAo?$AAD?$AAe?$AAb?$AAu?$AAg?$AAT?$AAh?$AAr?$AAe?$AAa?$AAd?$AA?$AA@
0x14004B258: WPP_bc279b98c32d3a6902793c8640f1685b_Traceguids
0x14004A978: "Global\BootShellComplete" ??_C@_1DC@DCPMIOHJ@?$AAG?$AAl?$AAo?$AAb?$AAa?$AAl?$AA?2?$AAB?$AAo?$AAo?$AAt?$AAS?$AAh?$AAe?$AAl?$AAl?$AAC?$AAo?$AAm?$AAp?$AAl?$AAe?$AAt?$AAe?$AA?$AA@
0x140046820: "ext-ms-win-ntuser-windowstation-" ??_C@_1EO@FIHMJCLF@?$AAe?$AAx?$AAt?$AA?9?$AAm?$AAs?$AA?9?$AAw?$AAi?$AAn?$AA?9?$AAn?$AAt?$AAu?$AAs?$AAe?$AAr?$AA?9?$AAw?$AAi?$AAn?$AAd?$AAo?$AAw?$AAs?$AAt?$AAa?$AAt?$AAi?$AAo?$AAn?$AA?9@
0x14005C0A8: "__cdecl _imp_I_ScSendTSMessage" __imp_I_ScSendTSMessage
0x14005C1A0: "__cdecl _imp_WTSDisconnectSession" __imp_WTSDisconnectSession
0x140058668: "struct _GUID s_WppUmsHlprGuid" ?s_WppUmsHlprGuid@@3U_GUID@@A
0x140045C90: "__cdecl _imp_RtlUnhandledExceptionFilter" __imp_RtlUnhandledExceptionFilter
0x14004B228: "DisableLockWorkstation" ??_C@_1CO@IPPKJECH@?$AAD?$AAi?$AAs?$AAa?$AAb?$AAl?$AAe?$AAL?$AAo?$AAc?$AAk?$AAW?$AAo?$AAr?$AAk?$AAs?$AAt?$AAa?$AAt?$AAi?$AAo?$AAn?$AA?$AA@
0x140046020: ntdll_NULL_THUNK_DATA
0x140045A90: "__cdecl _imp_memcpy" __imp_memcpy
0x14004C058: "Cmdline" ??_C@_1BA@DOPIGINC@?$AAC?$AAm?$AAd?$AAl?$AAi?$AAn?$AAe?$AA?$AA@
0x14004BE90: WPP_f9d6e7366a593f8ceaa9f2f65b1296e6_Traceguids
0x140045BA8: "__cdecl _imp_GetSecurityDescriptorDacl" __imp_GetSecurityDescriptorDacl
0x14003E3C0: BiBindEfiEntries
0x140004F68: "__cdecl _tailMerge_api_ms_win_security_lsalookup_l1_1_0_dll" __tailMerge_api_ms_win_security_lsalookup_l1_1_0_dll
0x140050F80: "Binding EFI namespace objects" ??_C@_1DM@JCLOENPL@?$AAB?$AAi?$AAn?$AAd?$AAi?$AAn?$AAg?$AA?5?$AAE?$AAF?$AAI?$AA?5?$AAn?$AAa?$AAm?$AAe?$AAs?$AAp?$AAa?$AAc?$AAe?$AA?5?$AAo?$AAb?$AAj?$AAe?$AAc?$AAt?$AAs?$AA?$AA@
0x140045B80: "__cdecl _imp_SetFileSecurityW" __imp_SetFileSecurityW
0x14002D218: WPP_SF_ddd
0x14002D1B8: WPP_SF_dDd
0x140054070: "__cdecl _DELAY_IMPORT_DESCRIPTOR_ext_ms_win_session_wininit_l1_1_0_dll" __DELAY_IMPORT_DESCRIPTOR_ext_ms_win_session_wininit_l1_1_0_dll
0x1400029A0: s_WsdrCheckForHiberboot
0x140035D4C: BiConvertElementFormatToValueType
0x140027C9C: WPP_SF_sss
0x140041F1C: SiValidateSystemPartition
0x14004AC8C: "failed" ??_C@_06ODACHPEO@failed?$AA@
0x140045E48: "__cdecl _imp_EtwEventUnregister" __imp_EtwEventUnregister
0x140045FF0: "__cdecl _imp_NtOpenDirectoryObject" __imp_NtOpenDirectoryObject
0x140004066: "__cdecl seh_filter_exe" _seh_filter_exe
0x140034E7C: "public: void __cdecl SP<unsigned char,class SP_MEM<unsigned char> >::Reset(void) __ptr64" ?Reset@?$SP@EV?$SP_MEM@E@@@@QEAAXXZ
0x140045A38: "__cdecl _imp__o__configthreadlocale" __imp__o__configthreadlocale
0x14004D110: "WIMCloseHandle" ??_C@_0P@DLENGCKG@WIMCloseHandle?$AA@
0x14000527A: "__cdecl _tailMerge_ext_ms_win_ntuser_windowstation_l1_1_0_dll" __tailMerge_ext_ms_win_ntuser_windowstation_l1_1_0_dll
0x1400479C0: WPP_2eee37593a2f327ee590e9f45b9fb92e_Traceguids
0x140045A08: "__cdecl _imp__o_wcscpy_s" __imp__o_wcscpy_s
0x140026A70: "void __cdecl WLEventWrite(struct _EVENT_DESCRIPTOR const & __ptr64,unsigned long,unsigned long)" ?WLEventWrite@@YAXAEBU_EVENT_DESCRIPTOR@@KK@Z
0x140045DD0: "__cdecl _imp_ZwDeleteKey" __imp_ZwDeleteKey
0x140045F38: "__cdecl _imp_ZwUnloadKey" __imp_ZwUnloadKey
0x140045E00: "__cdecl _imp_EtwEventWriteTransfer" __imp_EtwEventWriteTransfer
0x140023BAC: "int __cdecl IsUpgradeShutdown(void)" ?IsUpgradeShutdown@@YAHXZ
0x1400459B0: "__cdecl _imp__set_new_mode" __imp__set_new_mode
0x140054954: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-synch-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-synch-l1-1-0
0x140046558: "ext-ms-win-ntuser-misc-l1-5-0" ??_C@_1DM@BJBMLEFI@?$AAe?$AAx?$AAt?$AA?9?$AAm?$AAs?$AA?9?$AAw?$AAi?$AAn?$AA?9?$AAn?$AAt?$AAu?$AAs?$AAe?$AAr?$AA?9?$AAm?$AAi?$AAs?$AAc?$AA?9?$AAl?$AA1?$AA?9?$AA5?$AA?9?$AA0?$AA?$AA@
0x14004A8A8: "Global\LogonUIExitEvent" ??_C@_1DA@EGKKANKM@?$AAG?$AAl?$AAo?$AAb?$AAa?$AAl?$AA?2?$AAL?$AAo?$AAg?$AAo?$AAn?$AAU?$AAI?$AAE?$AAx?$AAi?$AAt?$AAE?$AAv?$AAe?$AAn?$AAt?$AA?$AA@
0x1400040D2: "__cdecl o_exit" _o_exit
0x14003B87C: BiCreateKey
0x1400593D8: "unsigned __int64 s_WppLogger" ?s_WppLogger@@3_KA
0x140033434: KsrpDumpBcdeDevice
0x14004AFA0: "ProgramW6432Dir" ??_C@_1CA@CFPJEBPB@?$AAP?$AAr?$AAo?$AAg?$AAr?$AAa?$AAm?$AAW?$AA6?$AA4?$AA3?$AA2?$AAD?$AAi?$AAr?$AA?$AA@
0x1400454F0: "__cdecl _imp_ApiSetQueryApiSetPresence" __imp_ApiSetQueryApiSetPresence
0x140058400: "__cdecl _security_cookie" __security_cookie
0x140045818: "__cdecl _imp_RegQueryValueExW" __imp_RegQueryValueExW
0x140047690: "SYSTEM\CurrentControlSet\Control" ??_C@_1FC@BADDNJG@?$AAS?$AAY?$AAS?$AAT?$AAE?$AAM?$AA?2?$AAC?$AAu?$AAr?$AAr?$AAe?$AAn?$AAt?$AAC?$AAo?$AAn?$AAt?$AAr?$AAo?$AAl?$AAS?$AAe?$AAt?$AA?2?$AAC?$AAo?$AAn?$AAt?$AAr?$AAo?$AAl@
0x1400507A0: "Failed to open object's key. Sta" ??_C@_1FA@MKEEABKA@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAo?$AAp?$AAe?$AAn?$AA?5?$AAo?$AAb?$AAj?$AAe?$AAc?$AAt?$AA?8?$AAs?$AA?5?$AAk?$AAe?$AAy?$AA?4?$AA?5?$AAS?$AAt?$AAa@
0x140047150: "%SystemRoot%\system32\services.e" ??_C@_1EG@NMBEPCDO@?$AA?$CF?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AAR?$AAo?$AAo?$AAt?$AA?$CF?$AA?2?$AAs?$AAy?$AAs?$AAt?$AAe?$AAm?$AA3?$AA2?$AA?2?$AAs?$AAe?$AAr?$AAv?$AAi?$AAc?$AAe?$AAs?$AA?4?$AAe@
0x140005B80: "__cdecl alloca_probe" _alloca_probe
0x140046290: "b08669ee-8cb5-43a5-a017-84fe%08X" ??_C@_1EC@KCBNLCCM@?$AAb?$AA0?$AA8?$AA6?$AA6?$AA9?$AAe?$AAe?$AA?9?$AA8?$AAc?$AAb?$AA5?$AA?9?$AA4?$AA3?$AAa?$AA5?$AA?9?$AAa?$AA0?$AA1?$AA7?$AA?9?$AA8?$AA4?$AAf?$AAe?$AA?$CF?$AA0?$AA8?$AAX@
0x14004C7E0: "Failed to allocate buffer memory" ??_C@_1EC@MJFDEING@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAa?$AAl?$AAl?$AAo?$AAc?$AAa?$AAt?$AAe?$AA?5?$AAb?$AAu?$AAf?$AAf?$AAe?$AAr?$AA?5?$AAm?$AAe?$AAm?$AAo?$AAr?$AAy@
0x140045748: "__cdecl _imp_GetExitCodeProcess" __imp_GetExitCodeProcess
0x14005C120: "__cdecl _imp_GetAsyncKeyState" __imp_GetAsyncKeyState
0x140003AC0: "__cdecl _scrt_fastfail" __scrt_fastfail
0x140036F94: BiEnumerateSubObjectElements
0x14000408A: "__cdecl o__set_new_mode" _o__set_new_mode
0x140045A50: "__cdecl _imp__o___stdio_common_vswprintf_s" __imp__o___stdio_common_vswprintf_s
0x140045B98: "__cdecl _imp_CheckTokenMembership" __imp_CheckTokenMembership
0x14004AE80: "ProgramFiles" ??_C@_1BK@CECDDAML@?$AAP?$AAr?$AAo?$AAg?$AAr?$AAa?$AAm?$AAF?$AAi?$AAl?$AAe?$AAs?$AA?$AA@
0x140046E70: WLEvt_CreatePrimaryTerminal_Start
0x14003DF20: BiAddBootEntryToEfiBootManagerDisplayOrder
0x140054868: ext-ms-win-coreui-navshutdown-l1-1-0_NULL_THUNK_DATA_DLB
0x140034E1C: "public: static bool __cdecl SP<unsigned char,class SP_MEM<unsigned char> >::IsNull(unsigned char * __ptr64)" ?IsNull@?$SP@EV?$SP_MEM@E@@@@SA_NPEAE@Z
0x14005C118: ext-ms-win-coreui-navshutdown-l1-1-0_NULL_THUNK_DATA_DLA
0x1400458A8: "__cdecl _imp_ResetEvent" __imp_ResetEvent
0x1400049F8: IsStartLoadingFontsWorkerPresent
0x140054760: api-ms-win-eventlog-legacy-l1-1-0_NULL_THUNK_DATA_DLB
0x140054904: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-crt-runtime-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-crt-runtime-l1-1-0
0x14004A810: "A critical system process has te" ??_C@_1GO@GALFCPIB@?$AAA?$AA?5?$AAc?$AAr?$AAi?$AAt?$AAi?$AAc?$AAa?$AAl?$AA?5?$AAs?$AAy?$AAs?$AAt?$AAe?$AAm?$AA?5?$AAp?$AAr?$AAo?$AAc?$AAe?$AAs?$AAs?$AA?5?$AAh?$AAa?$AAs?$AA?5?$AAt?$AAe@
0x140004102: "__cdecl o_wcstoul" _o_wcstoul
0x140045600: "__cdecl _imp_CloseHandle" __imp_CloseHandle
0x140054308: ext-ms-win-coreui-navshutdown-l1-1-0_NULL_THUNK_DATA_DLN
0x140045B10: "__cdecl _imp_EnableTraceEx2" __imp_EnableTraceEx2
0x14005C1B0: "__cdecl _imp_WTSFreeMemory" __imp_WTSFreeMemory
0x140045848: "__cdecl _imp_RtlCompareMemory" __imp_RtlCompareMemory
0x14003A1D4: BiGetDriveLayoutBlock
0x140054AD0: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-eventing-controller-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-eventing-controller-l1-1-0
0x140054798: ext-ms-win-ntuser-keyboard-l1-1-0_NULL_THUNK_DATA_DLB
0x140045648: "__cdecl _imp_LocalFree" __imp_LocalFree
0x140041470: SiGetDeviceNumberInformation
0x140039D70: BiCreatePartitionDevice
0x14004BD80: "%SystemDrive%\Debuggers\ntsd.exe" ??_C@_1EC@JHJEDHOA@?$AA?$CF?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AAD?$AAr?$AAi?$AAv?$AAe?$AA?$CF?$AA?2?$AAD?$AAe?$AAb?$AAu?$AAg?$AAg?$AAe?$AAr?$AAs?$AA?2?$AAn?$AAt?$AAs?$AAd?$AA?4?$AAe?$AAx?$AAe@
0x140048180: "Failed to set 'Start' value, %#0" ??_C@_1EI@BHKOKEPE@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAs?$AAe?$AAt?$AA?5?$AA?8?$AAS?$AAt?$AAa?$AAr?$AAt?$AA?8?$AA?5?$AAv?$AAa?$AAl?$AAu?$AAe?$AA?0?$AA?5?$AA?$CF?$AA?$CD?$AA0@
0x14005C110: "__cdecl _imp_NAVShutdown" __imp_NAVShutdown
0x140004AD7: "__cdecl _imp_load_StartLoadingFontsWorker" __imp_load_StartLoadingFontsWorker
0x140054388: ext-ms-win-session-wininit-l1-1-0_NULL_THUNK_DATA_DLN
0x140005134: "__cdecl _imp_load_OpenServiceW" __imp_load_OpenServiceW
0x140054968: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-errorhandling-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-errorhandling-l1-1-0
0x140045680: api-ms-win-core-interlocked-l1-1-0_NULL_THUNK_DATA
0x140045C98: "__cdecl _imp_RtlCreateProcessParametersEx" __imp_RtlCreateProcessParametersEx
0x140034EA4: RtlUIntAdd
0x140047A78: "EventLog" ??_C@_1BC@FNLKCFOP@?$AAE?$AAv?$AAe?$AAn?$AAt?$AAL?$AAo?$AAg?$AA?$AA@
0x140038944: BiGetCurrentBootEntryIdentifier
0x14005C190: "__cdecl _imp_PrimaryTerminalAndHookWorker" __imp_PrimaryTerminalAndHookWorker
0x140045A98: api-ms-win-crt-private-l1-1-0_NULL_THUNK_DATA
0x140058CF0: "__cdecl _hmod__api_ms_win_eventlog_legacy_l1_1_0_dll" __hmod__api_ms_win_eventlog_legacy_l1_1_0_dll
0x14004A9C8: " /startpage:1" ??_C@_1BM@JBKBCFPH@?$AA?5?$AA?1?$AAs?$AAt?$AAa?$AAr?$AAt?$AAp?$AAa?$AAg?$AAe?$AA?3?$AA1?$AA?$AA@
0x1400455A0: "__cdecl _imp_GetFileAttributesW" __imp_GetFileAttributesW
0x14004FD28: "Loaded hive at BCD%08d" ??_C@_1CO@NBIMBNIG@?$AAL?$AAo?$AAa?$AAd?$AAe?$AAd?$AA?5?$AAh?$AAi?$AAv?$AAe?$AA?5?$AAa?$AAt?$AA?5?$AAB?$AAC?$AAD?$AA?$CF?$AA0?$AA8?$AAd?$AA?$AA@
0x140054B70: "__cdecl _IMPORT_DESCRIPTOR_profapi" __IMPORT_DESCRIPTOR_profapi
0x1400479D0: "ID_CAP_BUILTIN_SHUTDOWN" ??_C@_1DA@FHLNEPGM@?$AAI?$AAD?$AA_?$AAC?$AAA?$AAP?$AA_?$AAB?$AAU?$AAI?$AAL?$AAT?$AAI?$AAN?$AA_?$AAS?$AAH?$AAU?$AAT?$AAD?$AAO?$AAW?$AAN?$AA?$AA@
0x140059300: "__cdecl _@@_PchSym_@00@KxulyqvxgPillgKxulmvxlivUwhUhvxfirgbUfnhgzigfkUdrmrmrgUlyquivUznwGEUkivxlnkOlyq@wininit" __@@_PchSym_@00@KxulyqvxgPillgKxulmvxlivUwhUhvxfirgbUfnhgzigfkUdrmrmrgUlyquivUznwGEUkivxlnkOlyq@wininit
0x140046F10: WIEvt_WaitForWinstationShutdown_Start
0x140034E1C: "public: static bool __cdecl SP<unsigned char,class SP_HLOCAL<unsigned char> >::IsNull(unsigned char * __ptr64)" ?IsNull@?$SP@EV?$SP_HLOCAL@E@@@@SA_NPEAE@Z
0x140045838: "__cdecl _imp_RegCreateKeyExW" __imp_RegCreateKeyExW
0x140045EC0: "__cdecl _imp_ZwQueryAttributesFile" __imp_ZwQueryAttributesFile
0x140045968: "__cdecl _imp_GetFileVersionInfoExW" __imp_GetFileVersionInfoExW
0x1400415A0: SiGetDiskPartitionInformation
0x1400508C8: "\??\PhysicalDrive%lu" ??_C@_1CK@HJDFLMHG@?$AA?2?$AA?$DP?$AA?$DP?$AA?2?$AAP?$AAh?$AAy?$AAs?$AAi?$AAc?$AAa?$AAl?$AAD?$AAr?$AAi?$AAv?$AAe?$AA?$CF?$AAl?$AAu?$AA?$AA@
0x140045418: "__cdecl _imp_I_RpcBindingIsClientLocal" __imp_I_RpcBindingIsClientLocal
0x140049E30: "384700" ??_C@_1O@PBJHCAIH@?$AA3?$AA8?$AA4?$AA7?$AA0?$AA0?$AA?$AA@
0x140045B20: "__cdecl _imp_EventProviderEnabled" __imp_EventProviderEnabled
0x140045FB8: "__cdecl _imp_NtQuerySymbolicLinkObject" __imp_NtQuerySymbolicLinkObject
0x140046E40: WIEvt_PreShutdownNotification_Stop
0x140047AA8: "WinSta0" ??_C@_1BA@IMLGMNLL@?$AAW?$AAi?$AAn?$AAS?$AAt?$AAa?$AA0?$AA?$AA@
0x140058410: "__cdecl _isa_available" __isa_available
0x140045CE0: "__cdecl _imp_RtlAllocateAndInitializeSid" __imp_RtlAllocateAndInitializeSid
0x140004DF8: IsNAVShutdownPresent
0x140045F98: "__cdecl _imp_RtlImpersonateSelf" __imp_RtlImpersonateSelf
0x140045EB8: "__cdecl _imp_RtlStringFromGUID" __imp_RtlStringFromGUID
0x14002BE24: "int __cdecl SetUserEnvironmentVariable(void * __ptr64 * __ptr64,unsigned short const * __ptr64,unsigned short const * __ptr64,int)" ?SetUserEnvironmentVariable@@YAHPEAPEAXPEBG1H@Z
0x140036608: BiDeleteElement
0x140058E10: KsrpLogMessageCallback
0x14004BD30: "ntsd" ??_C@_19MCLDCDBL@?$AAn?$AAt?$AAs?$AAd?$AA?$AA@
0x14004F100: "Element" ??_C@_1BA@DLALOCKE@?$AAE?$AAl?$AAe?$AAm?$AAe?$AAn?$AAt?$AA?$AA@
0x140047FE0: "Failed to update soft reboot fla" ??_C@_1FG@DJHBKFLJ@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAu?$AAp?$AAd?$AAa?$AAt?$AAe?$AA?5?$AAs?$AAo?$AAf?$AAt?$AA?5?$AAr?$AAe?$AAb?$AAo?$AAo?$AAt?$AA?5?$AAf?$AAl?$AAa@
0x140003C14: "__cdecl _scrt_get_show_window_mode" __scrt_get_show_window_mode
0x140045390: "__cdecl _imp_RpcRevertToSelf" __imp_RpcRevertToSelf
0x140050940: "Failed to acquire permissions to" ??_C@_1GO@MDEDFILO@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAa?$AAc?$AAq?$AAu?$AAi?$AAr?$AAe?$AA?5?$AAp?$AAe?$AAr?$AAm?$AAi?$AAs?$AAs?$AAi?$AAo?$AAn?$AAs?$AA?5?$AAt?$AAo@
0x140045550: "__cdecl _imp_SetUnhandledExceptionFilter" __imp_SetUnhandledExceptionFilter
0x140003470: WinMainCRTStartup
0x140045798: "__cdecl _imp_GetCurrentThread" __imp_GetCurrentThread
0x140046D90: "__cdecl _sz_api_ms_win_service_winsvc_l1_1_0_dll" __sz_api_ms_win_service_winsvc_l1_1_0_dll
0x140054258: api-ms-win-security-sddl-l1-1-0_NULL_THUNK_DATA_DLN
0x140031AA0: "long __cdecl CreateLsaStallEvent(void)" ?CreateLsaStallEvent@@YAJXZ
0x1400031B4: "__cdecl _local_stdio_scanf_options" __local_stdio_scanf_options
0x14004A8D8: "COMPUTERNAME" ??_C@_1BK@ENEDBDPA@?$AAC?$AAO?$AAM?$AAP?$AAU?$AAT?$AAE?$AAR?$AAN?$AAA?$AAM?$AAE?$AA?$AA@
0x14004AE60: "ProgramFilesDir" ??_C@_1CA@BENHECIP@?$AAP?$AAr?$AAo?$AAg?$AAr?$AAa?$AAm?$AAF?$AAi?$AAl?$AAe?$AAs?$AAD?$AAi?$AAr?$AA?$AA@
0x140045830: "__cdecl _imp_RegDeleteTreeW" __imp_RegDeleteTreeW
0x140046F78: "Global\WinlogonLogoff" ??_C@_1CM@BIIJIOAJ@?$AAG?$AAl?$AAo?$AAb?$AAa?$AAl?$AA?2?$AAW?$AAi?$AAn?$AAl?$AAo?$AAg?$AAo?$AAn?$AAL?$AAo?$AAg?$AAo?$AAf?$AAf?$AA?$AA@
0x14005C188: "__cdecl _imp_StartLoadingFontsWorker" __imp_StartLoadingFontsWorker
0x14002AF10: s_WsdrAbortShutdown
0x140053FD0: "__cdecl _DELAY_IMPORT_DESCRIPTOR_ext_ms_win_core_stateseparationext_l1_1_0_dll" __DELAY_IMPORT_DESCRIPTOR_ext_ms_win_core_stateseparationext_l1_1_0_dll
0x140058D48: "__cdecl _hmod__ext_ms_win_ntuser_private_l1_1_0_dll" __hmod__ext_ms_win_ntuser_private_l1_1_0_dll
0x1400511F0: "BiExportBcdObjects failed %x" ??_C@_1DK@EFCNLFKL@?$AAB?$AAi?$AAE?$AAx?$AAp?$AAo?$AAr?$AAt?$AAB?$AAc?$AAd?$AAO?$AAb?$AAj?$AAe?$AAc?$AAt?$AAs?$AA?5?$AAf?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AA?$CF?$AAx?$AA?$AA@
0x140029954: "int __cdecl HasShutdownBegun(unsigned long * __ptr64)" ?HasShutdownBegun@@YAHPEAK@Z
0x140045828: "__cdecl _imp_RegOpenKeyExW" __imp_RegOpenKeyExW
0x140005478: BcdGetSystemStorePath
0x140045988: "__cdecl _imp__o__initialize_onexit_table" __imp__o__initialize_onexit_table
0x14003ECD8: BiCreateBootEntry
0x140058CD4: "__cdecl _favor" __favor
0x140036288: BiConvertRegistryDataToElement
0x140046C80: "__cdecl _sz_ext_ms_win_coreui_navshutdown_l1_1_0_dll" __sz_ext_ms_win_coreui_navshutdown_l1_1_0_dll
0x140045A68: "__cdecl _imp___p__commode" __imp___p__commode
0x140045A48: "__cdecl _imp___stdio_common_vswscanf" __imp___stdio_common_vswscanf
0x14004AD50: "SOFTWARE\Microsoft\Windows NT\Cu" ??_C@_1GM@GIBHDOLK@?$AAS?$AAO?$AAF?$AAT?$AAW?$AAA?$AAR?$AAE?$AA?2?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAW?$AAi?$AAn?$AAd?$AAo?$AAw?$AAs?$AA?5?$AAN?$AAT?$AA?2?$AAC?$AAu@
0x140004CDF: "__cdecl _imp_load_DwmpCreateSessionProcess" __imp_load_DwmpCreateSessionProcess
0x14004BA60: WPP_f9be4a30e7d533fe2713472534fe0b5c_Traceguids
0x140003968: "__cdecl _security_init_cookie" __security_init_cookie
0x140047CA0: "Failed to read option list, %#08" ??_C@_1EG@DKGKEGGM@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAr?$AAe?$AAa?$AAd?$AA?5?$AAo?$AAp?$AAt?$AAi?$AAo?$AAn?$AA?5?$AAl?$AAi?$AAs?$AAt?$AA?0?$AA?5?$AA?$CF?$AA?$CD?$AA0?$AA8@
0x14002D39C: WPP_SF_q
0x14004BC88: WPP_b2d9be87fed7360ec7124feb4b91f0e5_Traceguids
0x140045A40: "__cdecl _imp__cexit" __imp__cexit
0x140053FB0: "__cdecl _DELAY_IMPORT_DESCRIPTOR_api_ms_win_rtcore_ntuser_private_l1_1_2_dll" __DELAY_IMPORT_DESCRIPTOR_api_ms_win_rtcore_ntuser_private_l1_1_2_dll
0x140045DE0: "__cdecl _imp_NtQuerySystemInformation" __imp_NtQuerySystemInformation
0x140039480: BiConvertBootEnvironmentDeviceToUnknown
0x140051638: "\Partition0" ??_C@_1BI@LDJIHBPK@?$AA?2?$AAP?$AAa?$AAr?$AAt?$AAi?$AAt?$AAi?$AAo?$AAn?$AA0?$AA?$AA@
0x140036DF8: BiEnumerateSubElements
0x140003FCA: "__cdecl _stdio_common_vsnwprintf_s" __stdio_common_vsnwprintf_s
0x140045990: "__cdecl _imp__o__register_onexit_function" __imp__o__register_onexit_function
0x140058DD0: "__cdecl _hmod__api_ms_win_base_bootconfig_l1_1_0_dll" __hmod__api_ms_win_base_bootconfig_l1_1_0_dll
0x140045820: "__cdecl _imp_RegGetValueW" __imp_RegGetValueW
0x140049548: "LsaCfgFlags" ??_C@_1BI@OOKAPKAG@?$AAL?$AAs?$AAa?$AAC?$AAf?$AAg?$AAF?$AAl?$AAa?$AAg?$AAs?$AA?$AA@
0x140004560: IsInitializeStateSeparationPresent
0x14004A418: WLEvt_WluiServerShutdown_Stop
0x14003FF2C: BiGetDeviceFromEfiPath
0x140051460: "\Registry\Machine\SYSTEM\Current" ??_C@_1HG@BDMNOANN@?$AA?2?$AAR?$AAe?$AAg?$AAi?$AAs?$AAt?$AAr?$AAy?$AA?2?$AAM?$AAa?$AAc?$AAh?$AAi?$AAn?$AAe?$AA?2?$AAS?$AAY?$AAS?$AAT?$AAE?$AAM?$AA?2?$AAC?$AAu?$AAr?$AAr?$AAe?$AAn?$AAt@
0x1400459C0: "__cdecl _imp__o__wcsicmp" __imp__o__wcsicmp
0x140046FB0: "SYSTEM\CurrentControlSet\Control" ??_C@_1EK@PENFFGPM@?$AAS?$AAY?$AAS?$AAT?$AAE?$AAM?$AA?2?$AAC?$AAu?$AAr?$AAr?$AAe?$AAn?$AAt?$AAC?$AAo?$AAn?$AAt?$AAr?$AAo?$AAl?$AAS?$AAe?$AAt?$AA?2?$AAC?$AAo?$AAn?$AAt?$AAr?$AAo?$AAl@
0x140045FA8: "__cdecl _imp_NtOpenSymbolicLinkObject" __imp_NtOpenSymbolicLinkObject
0x14004C378: "Device already mounted" ??_C@_1CO@IHKCGHLO@?$AAD?$AAe?$AAv?$AAi?$AAc?$AAe?$AA?5?$AAa?$AAl?$AAr?$AAe?$AAa?$AAd?$AAy?$AA?5?$AAm?$AAo?$AAu?$AAn?$AAt?$AAe?$AAd?$AA?$AA@
0x14004A9B0: "bootim.exe" ??_C@_1BG@MEEPCNKP@?$AAb?$AAo?$AAo?$AAt?$AAi?$AAm?$AA?4?$AAe?$AAx?$AAe?$AA?$AA@
0x14004F9E0: "BcdCloseStore: Failed to acquire" ??_C@_1HK@OHPJHCML@?$AAB?$AAc?$AAd?$AAC?$AAl?$AAo?$AAs?$AAe?$AAS?$AAt?$AAo?$AAr?$AAe?$AA?3?$AA?5?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAa?$AAc?$AAq?$AAu?$AAi?$AAr?$AAe@
0x14005C028: api-ms-win-eventlog-legacy-l1-1-0_NULL_THUNK_DATA_DLA
0x1400459E0: "__cdecl _imp_memmove" __imp_memmove
0x14004C640: "Failed to query symlink for the " ??_C@_1FM@DMKIJBOO@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAq?$AAu?$AAe?$AAr?$AAy?$AA?5?$AAs?$AAy?$AAm?$AAl?$AAi?$AAn?$AAk?$AA?5?$AAf?$AAo?$AAr?$AA?5?$AAt?$AAh?$AAe?$AA?5@
0x140045EA0: "__cdecl _imp_NtSystemDebugControl" __imp_NtSystemDebugControl
0x14004A4D0: "Software\Microsoft\Windows NT\Cu" ??_C@_1GK@NIBGBKLB@?$AAS?$AAo?$AAf?$AAt?$AAw?$AAa?$AAr?$AAe?$AA?2?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAW?$AAi?$AAn?$AAd?$AAo?$AAw?$AAs?$AA?5?$AAN?$AAT?$AA?2?$AAC?$AAu@
0x1400335B4: KsrpGetBootOptionListSize
0x140025CF0: "void __cdecl SystemProcessDeath(void * __ptr64,unsigned char)" ?SystemProcessDeath@@YAXPEAXE@Z
0x14005C128: ext-ms-win-ntuser-keyboard-l1-1-0_NULL_THUNK_DATA_DLA
0x140040400: BiGetSavedBootEntry
0x14003F62C: BiDeleteBootEntry
0x140032638: KsrAttachRootDevice
0x1400044D2: "__cdecl _imp_load_RegisterLogonProcess" __imp_load_RegisterLogonProcess
0x14004B360: "AutoAdminLogon" ??_C@_1BO@IKBCMOPJ@?$AAA?$AAu?$AAt?$AAo?$AAA?$AAd?$AAm?$AAi?$AAn?$AAL?$AAo?$AAg?$AAo?$AAn?$AA?$AA@
0x140047DB0: "Registering and loading winload." ??_C@_1EI@EHLELMFA@?$AAR?$AAe?$AAg?$AAi?$AAs?$AAt?$AAe?$AAr?$AAi?$AAn?$AAg?$AA?5?$AAa?$AAn?$AAd?$AA?5?$AAl?$AAo?$AAa?$AAd?$AAi?$AAn?$AAg?$AA?5?$AAw?$AAi?$AAn?$AAl?$AAo?$AAa?$AAd?$AA?4@
0x14000407E: "__cdecl set_fmode" _set_fmode
0x140054228: api-ms-win-rtcore-ntuser-private-l1-1-2_NULL_THUNK_DATA_DLN
0x140046C00: "__cdecl _sz_ext_ms_onecore_shellchromeapi_l1_1_1_dll" __sz_ext_ms_onecore_shellchromeapi_l1_1_1_dll
0x140050D00: "No processes are using this file" ??_C@_1EE@DHCKIGJ@?$AAN?$AAo?$AA?5?$AAp?$AAr?$AAo?$AAc?$AAe?$AAs?$AAs?$AAe?$AAs?$AA?5?$AAa?$AAr?$AAe?$AA?5?$AAu?$AAs?$AAi?$AAn?$AAg?$AA?5?$AAt?$AAh?$AAi?$AAs?$AA?5?$AAf?$AAi?$AAl?$AAe@
0x1400460B8: "__cdecl _xt_z" __xt_z
0x140058688: "unsigned short * s_WppBackupFileName" ?s_WppBackupFileName@@3PAGA
0x140059330: "int WinlogonDebugSetup" ?WinlogonDebugSetup@@3HA
0x140045FB0: "__cdecl _imp_NtOpenKey" __imp_NtOpenKey
0x140050A20: "Failed open newly loaded key %ws" ??_C@_1HC@IHHDHBPH@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAo?$AAp?$AAe?$AAn?$AA?5?$AAn?$AAe?$AAw?$AAl?$AAy?$AA?5?$AAl?$AAo?$AAa?$AAd?$AAe?$AAd?$AA?5?$AAk?$AAe?$AAy?$AA?5?$AA?$CF?$AAw?$AAs@
0x140049230: "multi(%d)disk(%d)rdisk(%d)partit" ??_C@_1FA@CDDKIFEO@?$AAm?$AAu?$AAl?$AAt?$AAi?$AA?$CI?$AA?$CF?$AAd?$AA?$CJ?$AAd?$AAi?$AAs?$AAk?$AA?$CI?$AA?$CF?$AAd?$AA?$CJ?$AAr?$AAd?$AAi?$AAs?$AAk?$AA?$CI?$AA?$CF?$AAd?$AA?$CJ?$AAp?$AAa?$AAr?$AAt?$AAi?$AAt@
0x140003140: DefaultWMsgReconnectionUpdateHandler
0x1400469E0: "__cdecl _sz_ext_ms_win_session_wininit_l1_1_0_dll" __sz_ext_ms_win_session_wininit_l1_1_0_dll
0x140046028: "__cdecl _imp_CreateEnvBlock" __imp_CreateEnvBlock
0x140050760: "Object alias resolves to %s" ??_C@_1DI@ELOMOFKK@?$AAO?$AAb?$AAj?$AAe?$AAc?$AAt?$AA?5?$AAa?$AAl?$AAi?$AAa?$AAs?$AA?5?$AAr?$AAe?$AAs?$AAo?$AAl?$AAv?$AAe?$AAs?$AA?5?$AAt?$AAo?$AA?5?$AA?$CF?$AAs?$AA?$AA@
0x14000500C: "__cdecl _imp_load_ReportEventW" __imp_load_ReportEventW
0x140004F5C: "__cdecl _imp_load_LookupAccountSidLocalW" __imp_load_LookupAccountSidLocalW
0x14004F2D0: "Failed to convert data for eleme" ??_C@_1GE@MOGGGLMO@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAc?$AAo?$AAn?$AAv?$AAe?$AAr?$AAt?$AA?5?$AAd?$AAa?$AAt?$AAa?$AA?5?$AAf?$AAo?$AAr?$AA?5?$AAe?$AAl?$AAe?$AAm?$AAe@
0x14002F04C: WmsgPostMessage
0x140045B30: "__cdecl _imp_EventUnregister" __imp_EventUnregister
0x140027844: "void * __ptr64 __cdecl WininitHeapAlloc(unsigned __int64)" ?WininitHeapAlloc@@YAPEAX_K@Z
0x14004C138: "Getting default boot entry" ??_C@_1DG@KDHKBOOJ@?$AAG?$AAe?$AAt?$AAt?$AAi?$AAn?$AAg?$AA?5?$AAd?$AAe?$AAf?$AAa?$AAu?$AAl?$AAt?$AA?5?$AAb?$AAo?$AAo?$AAt?$AA?5?$AAe?$AAn?$AAt?$AAr?$AAy?$AA?$AA@
0x140045F10: "__cdecl _imp_RtlAddAccessAllowedAceEx" __imp_RtlAddAccessAllowedAceEx
0x140046ED0: WLEvt_CreatePrimaryTerminal_Stop
0x140050590: GUID_FIRMWARE_BOOTMGR
0x140054A1C: "__cdecl _IMPORT_DESCRIPTOR_RPCRT4" __IMPORT_DESCRIPTOR_RPCRT4
0x140051230: "Timeout" ??_C@_1BA@BKONPLFM@?$AAT?$AAi?$AAm?$AAe?$AAo?$AAu?$AAt?$AA?$AA@
0x140058370: "struct _REG_CHANGE * WinlogonSetupChanges" ?WinlogonSetupChanges@@3PAU_REG_CHANGE@@A
0x140045E38: "__cdecl _imp_RtlLengthSid" __imp_RtlLengthSid
0x140034D9C: "public: unsigned char * __ptr64 __cdecl SP<unsigned char,class SP_HLOCAL<unsigned char> >::GetPtrAs<unsigned char>(void)const __ptr64" ??$GetPtrAs@E@?$SP@EV?$SP_HLOCAL@E@@@@QEBAPEAEXZ
0x140059150: "unsigned long g_WIHiberboot" ?g_WIHiberboot@@3KA
0x140045990: "__cdecl _imp__register_onexit_function" __imp__register_onexit_function
0x140049D90: "\Registry\Machine\System\Current" ??_C@_1HI@IMNCHMIG@?$AA?2?$AAR?$AAe?$AAg?$AAi?$AAs?$AAt?$AAr?$AAy?$AA?2?$AAM?$AAa?$AAc?$AAh?$AAi?$AAn?$AAe?$AA?2?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AA?2?$AAC?$AAu?$AAr?$AAr?$AAe?$AAn?$AAt@
0x14004C128: WPP_c6db3ee58e84378e9d1008d6e475c92c_Traceguids
0x14003BFB4: BiEnumerateSubKeys
0x140046E20: WLEvt_DwmpCreateSessionProcess_Start
0x140004C60: "__cdecl _tailMerge_ext_ms_win_composition_init_l1_1_0_dll" __tailMerge_ext_ms_win_composition_init_l1_1_0_dll
0x1400454E8: RPCRT4_NULL_THUNK_DATA
0x14004A650: "Software\Policies\Microsoft\Syst" ??_C@_1FK@EMGPHCF@?$AAS?$AAo?$AAf?$AAt?$AAw?$AAa?$AAr?$AAe?$AA?2?$AAP?$AAo?$AAl?$AAi?$AAc?$AAi?$AAe?$AAs?$AA?2?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAS?$AAy?$AAs?$AAt@
0x140003530: "__cdecl _report_gsfailure" __report_gsfailure
0x140045370: BcdSyncMutantName
0x140054110: "__cdecl _DELAY_IMPORT_DESCRIPTOR_api_ms_win_security_lsalookup_l1_1_0_dll" __DELAY_IMPORT_DESCRIPTOR_api_ms_win_security_lsalookup_l1_1_0_dll
0x140051430: "ZwTranslateFilePath" ??_C@_0BE@KMEIDNLK@ZwTranslateFilePath?$AA@
0x1400454F8: api-ms-win-core-apiquery-l1-1-0_NULL_THUNK_DATA
0x140045728: "__cdecl _imp_UpdateProcThreadAttribute" __imp_UpdateProcThreadAttribute
0x140046018: "__cdecl _imp_EtwEventWrite" __imp_EtwEventWrite
0x14003791C: BiCleanupLoadedStores
0x140034E7C: "public: void __cdecl SP<unsigned short,class SP_MEM<unsigned short> >::Reset(void) __ptr64" ?Reset@?$SP@GV?$SP_MEM@G@@@@QEAAXXZ
0x140045950: api-ms-win-core-timezone-l1-1-0_NULL_THUNK_DATA
0x14000401E: "__cdecl crt_atexit" _crt_atexit
0x1400031A4: "__cdecl _local_stdio_printf_options" __local_stdio_printf_options
0x140047578: " -CredGuard" ??_C@_1BI@OCENLGAK@?$AA?5?$AA?9?$AAC?$AAr?$AAe?$AAd?$AAG?$AAu?$AAa?$AAr?$AAd?$AA?$AA@
0x14005C100: "__cdecl _imp_InitializeStateSeparation" __imp_InitializeStateSeparation
0x140005370: "__cdecl TlgDefineProvider_annotation__Tlgmtaum_hTelemetryAssertDiagTrackProv" _TlgDefineProvider_annotation__Tlgmtaum_hTelemetryAssertDiagTrackProv
0x140045FC8: "__cdecl _imp_NtOpenFile" __imp_NtOpenFile
0x14004F4C0: "Failed to open key for all objec" ??_C@_1HC@IKFAJEGO@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAo?$AAp?$AAe?$AAn?$AA?5?$AAk?$AAe?$AAy?$AA?5?$AAf?$AAo?$AAr?$AA?5?$AAa?$AAl?$AAl?$AA?5?$AAo?$AAb?$AAj?$AAe?$AAc@
0x14004BDF8: "%SystemRoot%\System32\ntsd.exe" ??_C@_1DO@JNDLDMLD@?$AA?$CF?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AAR?$AAo?$AAo?$AAt?$AA?$CF?$AA?2?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AA3?$AA2?$AA?2?$AAn?$AAt?$AAs?$AAd?$AA?4?$AAe?$AAx?$AAe?$AA?$AA@
0x1400458A0: "__cdecl _imp_LeaveCriticalSection" __imp_LeaveCriticalSection
0x1400038F0: "__cdecl onexit" _onexit
0x1400454B0: "__cdecl _imp_RpcAsyncInitializeHandle" __imp_RpcAsyncInitializeHandle
0x1400515A0: "\ArcName\multi(0)disk(0)rdisk(1)" ??_C@_1EC@DDFPLGMM@?$AA?2?$AAA?$AAr?$AAc?$AAN?$AAa?$AAm?$AAe?$AA?2?$AAm?$AAu?$AAl?$AAt?$AAi?$AA?$CI?$AA0?$AA?$CJ?$AAd?$AAi?$AAs?$AAk?$AA?$CI?$AA0?$AA?$CJ?$AAr?$AAd?$AAi?$AAs?$AAk?$AA?$CI?$AA1?$AA?$CJ@
0x140045500: "__cdecl _imp_GetTimeFormatEx" __imp_GetTimeFormatEx
0x140039540: BiConvertNtDeviceToBootEnvironment
0x14004B2F0: "%SystemRoot%\system32\userinit.e" ??_C@_1EG@PJHIKHEB@?$AA?$CF?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AAR?$AAo?$AAo?$AAt?$AA?$CF?$AA?2?$AAs?$AAy?$AAs?$AAt?$AAe?$AAm?$AA3?$AA2?$AA?2?$AAu?$AAs?$AAe?$AAr?$AAi?$AAn?$AAi?$AAt?$AA?4?$AAe@
0x140034D9C: "public: unsigned short * __ptr64 * __ptr64 __cdecl SP<unsigned short * __ptr64,class SP_MEM<unsigned short * __ptr64> >::GetPtrAs<unsigned short * __ptr64>(void)const __ptr64" ??$GetPtrAs@PEAG@?$SP@PEAGV?$SP_MEM@PEAG@@@@QEBAPEAPEAGXZ
0x140042110: SiDisambiguateSystemDevice
0x14004BE38: "%s -d -p %d" ??_C@_1BI@GGBEDBNJ@?$AA?$CF?$AAs?$AA?5?$AA?9?$AAd?$AA?5?$AA?9?$AAp?$AA?5?$AA?$CF?$AAd?$AA?$AA@
0x140045B00: "__cdecl _imp_StartTraceW" __imp_StartTraceW
0x140046910: "ext-ms-win-session-wtsapi32-l1-1" ??_C@_1EG@MFPCCJEE@?$AAe?$AAx?$AAt?$AA?9?$AAm?$AAs?$AA?9?$AAw?$AAi?$AAn?$AA?9?$AAs?$AAe?$AAs?$AAs?$AAi?$AAo?$AAn?$AA?9?$AAw?$AAt?$AAs?$AAa?$AAp?$AAi?$AA3?$AA2?$AA?9?$AAl?$AA1?$AA?9?$AA1@
0x140004E4C: "__cdecl _imp_load_NAVShutdown" __imp_load_NAVShutdown
0x140046F00: WLEvt_DwmpCreateSessionProcess_Stop
0x140058DF8: "__cdecl _dyn_tls_dtor_callback" __dyn_tls_dtor_callback
0x140045D78: "__cdecl _imp_ZwSetSystemInformation" __imp_ZwSetSystemInformation
0x140047A50: "ntdll.dll" ??_C@_1BE@GJOFHIHD@?$AAn?$AAt?$AAd?$AAl?$AAl?$AA?4?$AAd?$AAl?$AAl?$AA?$AA@
0x140046EA0: WIEvt_WaitForWinstationShutdown_Stop
0x14004B530: "SYSTEM\CurrentControlSet\Control" ??_C@_1FC@EOFODOEG@?$AAS?$AAY?$AAS?$AAT?$AAE?$AAM?$AA?2?$AAC?$AAu?$AAr?$AAr?$AAe?$AAn?$AAt?$AAC?$AAo?$AAn?$AAt?$AAr?$AAo?$AAl?$AAS?$AAe?$AAt?$AA?2?$AAC?$AAo?$AAn?$AAt?$AAr?$AAo?$AAl@
0x140045E18: "__cdecl _imp_RtlQueryEnvironmentVariable_U" __imp_RtlQueryEnvironmentVariable_U
0x1400269AC: "void __cdecl WLEventWrite(struct _EVENT_DESCRIPTOR const & __ptr64)" ?WLEventWrite@@YAXAEBU_EVENT_DESCRIPTOR@@@Z
0x14004CB88: "DEVICE: File: '%ws'" ??_C@_1CI@MDPGCFLA@?$AAD?$AAE?$AAV?$AAI?$AAC?$AAE?$AA?3?$AA?5?$AAF?$AAi?$AAl?$AAe?$AA?3?$AA?5?$AA?8?$AA?$CF?$AAw?$AAs?$AA?8?$AA?$AA@
0x140024B50: "unsigned long __cdecl RecordShutdownFlags(unsigned long)" ?RecordShutdownFlags@@YAKK@Z
0x140058D28: "__cdecl _hmod__ext_ms_win_ntuser_misc_l1_1_0_dll" __hmod__ext_ms_win_ntuser_misc_l1_1_0_dll
0x140045DC8: "__cdecl _imp_ZwCreateKey" __imp_ZwCreateKey
0x1400459F0: "__cdecl _imp__o_terminate" __imp__o_terminate
0x14004FF70: "Failed to initialize description" ??_C@_1KG@KMOOPLGK@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAi?$AAn?$AAi?$AAt?$AAi?$AAa?$AAl?$AAi?$AAz?$AAe?$AA?5?$AAd?$AAe?$AAs?$AAc?$AAr?$AAi?$AAp?$AAt?$AAi?$AAo?$AAn@
0x14004CD28: "Enum" ??_C@_19DDCEFKEI@?$AAE?$AAn?$AAu?$AAm?$AA?$AA@
0x140058CC0: "struct __type_info_node __type_info_root_node" ?__type_info_root_node@@3U__type_info_node@@A
0x14004ACD8: "winlogon.exe" ??_C@_1BK@HLMOGDAH@?$AAw?$AAi?$AAn?$AAl?$AAo?$AAg?$AAo?$AAn?$AA?4?$AAe?$AAx?$AAe?$AA?$AA@
0x14003BD28: BiDeleteKey
0x14004A628: "Domain" ??_C@_1O@OAMNPMOM@?$AAD?$AAo?$AAm?$AAa?$AAi?$AAn?$AA?$AA@
0x140041BEC: SiIssueSynchronousIoctl
0x14004A438: WIEvt_WaitForSystemProcesses_Stop
0x140046B60: "ext-ms-onecore-shellchromeapi-l1" ??_C@_1EK@NFKKGPPI@?$AAe?$AAx?$AAt?$AA?9?$AAm?$AAs?$AA?9?$AAo?$AAn?$AAe?$AAc?$AAo?$AAr?$AAe?$AA?9?$AAs?$AAh?$AAe?$AAl?$AAl?$AAc?$AAh?$AAr?$AAo?$AAm?$AAe?$AAa?$AAp?$AAi?$AA?9?$AAl?$AA1@
0x1400456A8: "__cdecl _imp_LoadResource" __imp_LoadResource
0x140003120: DefaultWMsgNotifyHandler
0x14004BEE0: "ALLUSERSPROFILE" ??_C@_1CA@KKKDHABE@?$AAA?$AAL?$AAL?$AAU?$AAS?$AAE?$AAR?$AAS?$AAP?$AAR?$AAO?$AAF?$AAI?$AAL?$AAE?$AA?$AA@
0x14003754C: BcdOpenStore
0x140045A20: "__cdecl _imp__o__exit" __imp__o__exit
0x14004AB70: "Software\Microsoft\Windows\Curre" ??_C@_1HE@KMAPOOMM@?$AAS?$AAo?$AAf?$AAt?$AAw?$AAa?$AAr?$AAe?$AA?2?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAW?$AAi?$AAn?$AAd?$AAo?$AAw?$AAs?$AA?2?$AAC?$AAu?$AAr?$AAr?$AAe@
0x140048380: "Failed to set 'Altitude' value, " ??_C@_1EO@OFEJIHIP@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAs?$AAe?$AAt?$AA?5?$AA?8?$AAA?$AAl?$AAt?$AAi?$AAt?$AAu?$AAd?$AAe?$AA?8?$AA?5?$AAv?$AAa?$AAl?$AAu?$AAe?$AA?0?$AA?5@
0x1400479A8: "BuildLab" ??_C@_1BC@HJOIIEGB@?$AAB?$AAu?$AAi?$AAl?$AAd?$AAL?$AAa?$AAb?$AA?$AA@
0x140048040: "Unknown soft reboot scenario run" ??_C@_1FK@LAFIADLG@?$AAU?$AAn?$AAk?$AAn?$AAo?$AAw?$AAn?$AA?5?$AAs?$AAo?$AAf?$AAt?$AA?5?$AAr?$AAe?$AAb?$AAo?$AAo?$AAt?$AA?5?$AAs?$AAc?$AAe?$AAn?$AAa?$AAr?$AAi?$AAo?$AA?5?$AAr?$AAu?$AAn@
0x14005C080: "__cdecl _imp_OpenSCManagerW" __imp_OpenSCManagerW
0x140045BC0: "__cdecl _imp_GetPersistedRegistryLocationW" __imp_GetPersistedRegistryLocationW
0x14003BE70: BiDoesHiveExist
0x140045770: "__cdecl _imp_SetThreadPriority" __imp_SetThreadPriority
0x14002EAD4: WluiDisplayStatus
0x140045578: "__cdecl _imp_FindVolumeClose" __imp_FindVolumeClose
0x1400459D8: "__cdecl _imp__o__wcsupr" __imp__o__wcsupr
0x1400548E0: ext-ms-win-ntuser-windowstation-l1-1-0_NULL_THUNK_DATA_DLB
0x14005C158: ext-ms-win-ntuser-windowstation-l1-1-0_NULL_THUNK_DATA_DLA
0x14002D11C: "unsigned long __cdecl WMsgClntTerminate(void)" ?WMsgClntTerminate@@YAKXZ
0x140024908: "long __cdecl ReadShutdownStopTimePerfCounter(union _LARGE_INTEGER * __ptr64,union _LARGE_INTEGER * __ptr64)" ?ReadShutdownStopTimePerfCounter@@YAJPEAT_LARGE_INTEGER@@0@Z
0x140054A44: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-datetime-l1-1-1" __IMPORT_DESCRIPTOR_api-ms-win-core-datetime-l1-1-1
0x140054348: ext-ms-win-ntuser-windowstation-l1-1-0_NULL_THUNK_DATA_DLN
0x14004CA40: "Failed to get the element size, " ??_C@_1EO@JBCPINIB@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAg?$AAe?$AAt?$AA?5?$AAt?$AAh?$AAe?$AA?5?$AAe?$AAl?$AAe?$AAm?$AAe?$AAn?$AAt?$AA?5?$AAs?$AAi?$AAz?$AAe?$AA?0?$AA?5@
0x140046330: "__cdecl _sz_api_ms_win_security_sddl_l1_1_0_dll" __sz_api_ms_win_security_sddl_l1_1_0_dll
0x140034338: KsrpUnregisterDriver
0x140003FD6: "__cdecl _stdio_common_vswprintf" __stdio_common_vswprintf
0x14002F684: StartWMsgKServer
0x14003ABBC: BiGetPhysicalDriveName
0x140059110: "struct HDESK__ * __ptr64 __ptr64 s_hdeskWinlogon" ?s_hdeskWinlogon@@3PEAUHDESK__@@EA
0x1400050A9: "__cdecl _imp_load_OpenSCManagerW" __imp_load_OpenSCManagerW
0x140045DA0: "__cdecl _imp_ZwOpenFile" __imp_ZwOpenFile
0x1400454C8: "__cdecl _imp_NdrClientCall3" __imp_NdrClientCall3
0x140050618: "Opening object %s" ??_C@_1CE@OBECFFDG@?$AAO?$AAp?$AAe?$AAn?$AAi?$AAn?$AAg?$AA?5?$AAo?$AAb?$AAj?$AAe?$AAc?$AAt?$AA?5?$AA?$CF?$AAs?$AA?$AA@
0x14002631C: "void __cdecl UnregisterPanicShutdownCallbacks(void)" ?UnregisterPanicShutdownCallbacks@@YAXXZ
0x14004CEE0: "NtOpenFile(%wZ) failed, %#08lx" ??_C@_1DO@MKNFDLBJ@?$AAN?$AAt?$AAO?$AAp?$AAe?$AAn?$AAF?$AAi?$AAl?$AAe?$AA?$CI?$AA?$CF?$AAw?$AAZ?$AA?$CJ?$AA?5?$AAf?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?0?$AA?5?$AA?$CF?$AA?$CD?$AA0?$AA8?$AAl?$AAx?$AA?$AA@
0x1400040AE: "__cdecl wcslwr" _wcslwr
0x1400590C0: "unsigned short g_usState" ?g_usState@@3GA
0x140045C70: "__cdecl _imp_NtCreateKey" __imp_NtCreateKey
0x1400514D8: "SystemPartition" ??_C@_1CA@BCILKFEE@?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AAP?$AAa?$AAr?$AAt?$AAi?$AAt?$AAi?$AAo?$AAn?$AA?$AA@
0x14004ABE8: "Win32 SystemShutdown module" ??_C@_1DI@CDDGHOGL@?$AAW?$AAi?$AAn?$AA3?$AA2?$AA?5?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AAS?$AAh?$AAu?$AAt?$AAd?$AAo?$AAw?$AAn?$AA?5?$AAm?$AAo?$AAd?$AAu?$AAl?$AAe?$AA?$AA@
0x14000463F: "__cdecl _imp_load_GetAsyncKeyState" __imp_load_GetAsyncKeyState
0x140045A30: "__cdecl _imp__configure_narrow_argv" __imp__configure_narrow_argv
0x1400375DC: BiAcquireBcdSyncMutant
0x140045CD8: "__cdecl _imp_RtlSetDaclSecurityDescriptor" __imp_RtlSetDaclSecurityDescriptor
0x140004C54: "__cdecl _imp_load_DwmpIsInitialSessionInteractive" __imp_load_DwmpIsInitialSessionInteractive
0x140045EF0: "__cdecl _imp_ZwOpenSymbolicLinkObject" __imp_ZwOpenSymbolicLinkObject
0x1400512D0: "Translated a DontSync entry with" ??_C@_1FC@IKHACEFF@?$AAT?$AAr?$AAa?$AAn?$AAs?$AAl?$AAa?$AAt?$AAe?$AAd?$AA?5?$AAa?$AA?5?$AAD?$AAo?$AAn?$AAt?$AAS?$AAy?$AAn?$AAc?$AA?5?$AAe?$AAn?$AAt?$AAr?$AAy?$AA?5?$AAw?$AAi?$AAt?$AAh@
0x140059250: g_pSidLocalService
0x140030D40: InitDebugHelpers
0x140058CE8: "__cdecl _hmod__api_ms_win_security_capability_l1_1_0_dll" __hmod__api_ms_win_security_capability_l1_1_0_dll
0x1400507F0: "Creating object. Version: %d. Ty" ??_C@_1FG@FFBPIKFN@?$AAC?$AAr?$AAe?$AAa?$AAt?$AAi?$AAn?$AAg?$AA?5?$AAo?$AAb?$AAj?$AAe?$AAc?$AAt?$AA?4?$AA?5?$AAV?$AAe?$AAr?$AAs?$AAi?$AAo?$AAn?$AA?3?$AA?5?$AA?$CF?$AAd?$AA?4?$AA?5?$AAT?$AAy@
0x1400040F6: wcscpy_s
0x140045AA0: "__cdecl _imp__c_exit" __imp__c_exit
0x140045D38: "__cdecl _imp_NtPowerInformation" __imp_NtPowerInformation
0x140002FC0: "int __cdecl WMsgNotifyHandler(unsigned long,unsigned long,unsigned short const * __ptr64,struct _RPC_ASYNC_STATE * __ptr64,long * __ptr64)" ?WMsgNotifyHandler@@YAHKKPEBGPEAU_RPC_ASYNC_STATE@@PEAJ@Z
0x140034EE0: StringCchLengthW
0x14003D040: BiGetFirmwareType
0x1400457B8: "__cdecl _imp_GetProcessMitigationPolicy" __imp_GetProcessMitigationPolicy
0x14002ACA0: WPP_SF__guid_d
0x140054B0C: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-profile-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-profile-l1-1-0
0x140050D50: "Found %d processes using this fi" ??_C@_1EI@JACBKJGA@?$AAF?$AAo?$AAu?$AAn?$AAd?$AA?5?$AA?$CF?$AAd?$AA?5?$AAp?$AAr?$AAo?$AAc?$AAe?$AAs?$AAs?$AAe?$AAs?$AA?5?$AAu?$AAs?$AAi?$AAn?$AAg?$AA?5?$AAt?$AAh?$AAi?$AAs?$AA?5?$AAf?$AAi@
0x140038B0C: BiGetObjectIdentifier
0x140034E7C: "public: void __cdecl SP<unsigned short * __ptr64,class SP_MEM<unsigned short * __ptr64> >::Reset(void) __ptr64" ?Reset@?$SP@PEAGV?$SP_MEM@PEAG@@@@QEAAXXZ
0x1400453D0: "__cdecl _imp_NdrServerCall2" __imp_NdrServerCall2
0x140046598: "ext-ms-win-ntuser-misc-l1-5-1" ??_C@_1DM@KBKANDDN@?$AAe?$AAx?$AAt?$AA?9?$AAm?$AAs?$AA?9?$AAw?$AAi?$AAn?$AA?9?$AAn?$AAt?$AAu?$AAs?$AAe?$AAr?$AA?9?$AAm?$AAi?$AAs?$AAc?$AA?9?$AAl?$AA1?$AA?9?$AA5?$AA?9?$AA1?$AA?$AA@
0x14004CD40: "NtOpenKey(ServiceKey) failed, %#" ??_C@_1EK@FLODLMCE@?$AAN?$AAt?$AAO?$AAp?$AAe?$AAn?$AAK?$AAe?$AAy?$AA?$CI?$AAS?$AAe?$AAr?$AAv?$AAi?$AAc?$AAe?$AAK?$AAe?$AAy?$AA?$CJ?$AA?5?$AAf?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?0?$AA?5?$AA?$CF?$AA?$CD@
0x140045A40: "__cdecl _imp__o__cexit" __imp__o__cexit
0x140003FD6: "__cdecl o___stdio_common_vswprintf" _o___stdio_common_vswprintf
0x140030EA8: WPP_SF_SL
0x140031270: WPP_SF_Sl
0x140048D40: "Created new boot entry 0x%x" ??_C@_1DI@CDFHKDHD@?$AAC?$AAr?$AAe?$AAa?$AAt?$AAe?$AAd?$AA?5?$AAn?$AAe?$AAw?$AA?5?$AAb?$AAo?$AAo?$AAt?$AA?5?$AAe?$AAn?$AAt?$AAr?$AAy?$AA?5?$AA0?$AAx?$AA?$CF?$AAx?$AA?$AA@
0x14002A7F0: "unsigned long __cdecl WsdpStartShutdownServer(void)" ?WsdpStartShutdownServer@@YAKXZ
0x14004B120: "O:BAG:BAD:PAI(A;;FA;;;SY)(A;IOCI" ??_C@_1OA@CKHLCHJB@?$AAO?$AA?3?$AAB?$AAA?$AAG?$AA?3?$AAB?$AAA?$AAD?$AA?3?$AAP?$AAA?$AAI?$AA?$CI?$AAA?$AA?$DL?$AA?$DL?$AAF?$AAA?$AA?$DL?$AA?$DL?$AA?$DL?$AAS?$AAY?$AA?$CJ?$AA?$CI?$AAA?$AA?$DL?$AAI?$AAO?$AAC?$AAI@
0x140027A38: WPP_SF_Sd
0x140027A38: WPP_SF_SD
0x14004AF70: "CommonProgramFiles(x86)" ??_C@_1DA@NDENMJEC@?$AAC?$AAo?$AAm?$AAm?$AAo?$AAn?$AAP?$AAr?$AAo?$AAg?$AAr?$AAa?$AAm?$AAF?$AAi?$AAl?$AAe?$AAs?$AA?$CI?$AAx?$AA8?$AA6?$AA?$CJ?$AA?$AA@
0x14003D928: BiAllocateCachedGuid
0x140045920: "__cdecl _imp_DeleteTimerQueueTimer" __imp_DeleteTimerQueueTimer
0x1400458E0: api-ms-win-core-synch-l1-2-0_NULL_THUNK_DATA
0x140045D50: "__cdecl _imp_NtSetEvent" __imp_NtSetEvent
0x140050848: "Generating object GUID." ??_C@_1DA@COAMFJPD@?$AAG?$AAe?$AAn?$AAe?$AAr?$AAa?$AAt?$AAi?$AAn?$AAg?$AA?5?$AAo?$AAb?$AAj?$AAe?$AAc?$AAt?$AA?5?$AAG?$AAU?$AAI?$AAD?$AA?4?$AA?$AA@
0x140059100: "unsigned __int64 g_TraceRegHandle" ?g_TraceRegHandle@@3_KA
0x14002ABF4: WPP_SF_SS
0x14002DCB0: WPP_SF_Ss
0x140050C60: "Failed to allocate process ID bu" ??_C@_1EM@MMKFALCH@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAa?$AAl?$AAl?$AAo?$AAc?$AAa?$AAt?$AAe?$AA?5?$AAp?$AAr?$AAo?$AAc?$AAe?$AAs?$AAs?$AA?5?$AAI?$AAD?$AA?5?$AAb?$AAu@
0x1400454E0: "__cdecl _imp_RpcBindingSetAuthInfoExW" __imp_RpcBindingSetAuthInfoExW
0x140045E20: "__cdecl _imp_EtwEventSetInformation" __imp_EtwEventSetInformation
0x140058E50: "struct _SYSTEM_PROCESS_DEATH * __ptr64 * rgpPanicShutdownCallbacks" ?rgpPanicShutdownCallbacks@@3PAPEAU_SYSTEM_PROCESS_DEATH@@A
0x140045740: "__cdecl _imp_OpenProcessToken" __imp_OpenProcessToken
0x1400506A0: "Failed to get aliased identifier" ??_C@_1FK@NOBMLHNI@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAg?$AAe?$AAt?$AA?5?$AAa?$AAl?$AAi?$AAa?$AAs?$AAe?$AAd?$AA?5?$AAi?$AAd?$AAe?$AAn?$AAt?$AAi?$AAf?$AAi?$AAe?$AAr@
0x14002BC38: "int __cdecl SetProcessSecurityDescriptor(unsigned long,unsigned short const * __ptr64)" ?SetProcessSecurityDescriptor@@YAHKPEBG@Z
0x140046F30: WIEvt_PreShutdownNotification_Start
0x14000407E: "__cdecl o__set_fmode" _o__set_fmode
0x140045DD8: "__cdecl _imp_ZwOpenKey" __imp_ZwOpenKey
0x1400457D8: "__cdecl _imp_K32GetModuleFileNameExW" __imp_K32GetModuleFileNameExW
0x140058D10: "__cdecl _hmod__ext_ms_win_ntuser_keyboard_l1_1_0_dll" __hmod__ext_ms_win_ntuser_keyboard_l1_1_0_dll
0x140003160: "__cdecl _scrt_initialize_winrt" __scrt_initialize_winrt
0x140004072: "__cdecl set_app_type" _set_app_type
0x140045998: "__cdecl _imp__o__seh_filter_exe" __imp__o__seh_filter_exe
0x1400044DE: "__cdecl _tailMerge_api_ms_win_rtcore_ntuser_private_l1_1_2_dll" __tailMerge_api_ms_win_rtcore_ntuser_private_l1_1_2_dll
0x1400468C0: "ext-ms-win-ntuser-windowstation-" ??_C@_1EO@PCHFFKDO@?$AAe?$AAx?$AAt?$AA?9?$AAm?$AAs?$AA?9?$AAw?$AAi?$AAn?$AA?9?$AAn?$AAt?$AAu?$AAs?$AAe?$AAr?$AA?9?$AAw?$AAi?$AAn?$AAd?$AAo?$AAw?$AAs?$AAt?$AAa?$AAt?$AAi?$AAo?$AAn?$AA?9@
0x1400458D0: api-ms-win-core-synch-l1-1-0_NULL_THUNK_DATA
0x14004FED0: "Failed to initialize objects key" ??_C@_1JO@GOAKEPKG@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAi?$AAn?$AAi?$AAt?$AAi?$AAa?$AAl?$AAi?$AAz?$AAe?$AA?5?$AAo?$AAb?$AAj?$AAe?$AAc?$AAt?$AAs?$AA?5?$AAk?$AAe?$AAy@
0x14005497C: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-synch-l1-2-0" __IMPORT_DESCRIPTOR_api-ms-win-core-synch-l1-2-0
0x14004FE40: "Failed to find a key to load sto" ??_C@_1HO@GNIINMFH@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAf?$AAi?$AAn?$AAd?$AA?5?$AAa?$AA?5?$AAk?$AAe?$AAy?$AA?5?$AAt?$AAo?$AA?5?$AAl?$AAo?$AAa?$AAd?$AA?5?$AAs?$AAt?$AAo@
0x1400279D8: WPP_SF_S
0x14002FC54: WPP_SF_s
0x14003046C: UmsReportApplicationEvent
0x140003FA6: memset
0x140054C38: "__cdecl _NULL_IMPORT_DESCRIPTOR" __NULL_IMPORT_DESCRIPTOR
0x14004FDD0: "Too many unexplained failures. F" ??_C@_1HA@GDPFBNC@?$AAT?$AAo?$AAo?$AA?5?$AAm?$AAa?$AAn?$AAy?$AA?5?$AAu?$AAn?$AAe?$AAx?$AAp?$AAl?$AAa?$AAi?$AAn?$AAe?$AAd?$AA?5?$AAf?$AAa?$AAi?$AAl?$AAu?$AAr?$AAe?$AAs?$AA?4?$AA?5?$AAF@
0x14004A888: "%08x" ??_C@_19HGGOABND@?$AA?$CF?$AA0?$AA8?$AAx?$AA?$AA@
0x14004AEA0: "CommonFilesDir" ??_C@_1BO@HALHHILJ@?$AAC?$AAo?$AAm?$AAm?$AAo?$AAn?$AAF?$AAi?$AAl?$AAe?$AAs?$AAD?$AAi?$AAr?$AA?$AA@
0x14002DDC0: "void __cdecl WlpPeriodicBreak(void * __ptr64,unsigned char)" ?WlpPeriodicBreak@@YAXPEAXE@Z
0x140047E00: "Failed to load and register the " ??_C@_1HE@IGDDAAGE@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAl?$AAo?$AAa?$AAd?$AA?5?$AAa?$AAn?$AAd?$AA?5?$AAr?$AAe?$AAg?$AAi?$AAs?$AAt?$AAe?$AAr?$AA?5?$AAt?$AAh?$AAe?$AA?5@
0x140059260: g_pSidWorld
0x1400455B0: "__cdecl _imp_ReadFile" __imp_ReadFile
0x14003749C: BcdForciblyUnloadStore
0x1400586F8: "unsigned __int64 `__local_stdio_scanf_options'::`2'::_OptionsStorage" ?_OptionsStorage@?1??__local_stdio_scanf_options@@9@4_KA
0x140059338: "void * __ptr64 __ptr64 ServerReadyEvent" ?ServerReadyEvent@@3PEAXEA
0x14003DE38: BiReleasePrivilege
0x14004BF00: "ReportBootOk" ??_C@_1BK@IEGAHKGL@?$AAR?$AAe?$AAp?$AAo?$AAr?$AAt?$AAB?$AAo?$AAo?$AAt?$AAO?$AAk?$AA?$AA@

[JEB Decompiler by PNF Software]