Generated by JEB on 2019/08/01
PE: C:\Windows\System32\capisp.dll Base=0x180000000 SHA-256=1C575011EF9983F27E85E97E31D046C5C0B3A940FB55DB3310C223584F5D9C2A
PDB: capisp.pdb GUID={17CF2366-DE88-0069-2CCBC2F79414D94E} Age=1
259 located named symbols:
0x18000349C: "__cdecl _raise_securityfailure" __raise_securityfailure
0x180004240: api-ms-win-core-file-l1-1-0_NULL_THUNK_DATA
0x1800048E0: "capisp.dll::SamOpenUser failed: " ??_C@_0CD@PHMHLDBP@capisp?4dll?3?3SamOpenUser?5failed?3?5@
0x1800032B0: "__cdecl FindPESection" _FindPESection
0x180005270: "capisp.dll::CryptoSysPrep_Specia" ??_C@_0FJ@BMKIFIGD@capisp?4dll?3?3CryptoSysPrep_Specia@
0x1800048C8: "capisp.dll::DomainSid=?" ??_C@_0BI@KGGJJPKC@capisp?4dll?3?3DomainSid?$DN?$DP?$AA@
0x180004298: "__cdecl _imp_GetCurrentDirectoryW" __imp_GetCurrentDirectoryW
0x180005BD4: "__cdecl _IMPORT_DESCRIPTOR_ntdll" __IMPORT_DESCRIPTOR_ntdll
0x180007010: "__cdecl _security_cookie_complement" __security_cookie_complement
0x180004258: "__cdecl _imp_DeviceIoControl" __imp_DeviceIoControl
0x180002D8C: "__cdecl CRT_INIT" _CRT_INIT
0x1800051A0: "capisp.dll::CryptoSysPrep_Specia" ??_C@_0GA@OKGPOCEP@capisp?4dll?3?3CryptoSysPrep_Specia@
0x1800042C8: "__cdecl _imp_GetCurrentThreadId" __imp_GetCurrentThreadId
0x1800043F0: "__cdecl _imp_RtlInitUnicodeString" __imp_RtlInitUnicodeString
0x180003710: "__cdecl guard_dispatch_icall_nop" _guard_dispatch_icall_nop
0x1800041E0: "__cdecl _imp_CurrentIP" __imp_CurrentIP
0x1800046F0: "DllRegisterServer" ??_C@_0BC@NPBLIDJ@DllRegisterServer?$AA@
0x180004220: "__cdecl _imp_RemoveDirectoryW" __imp_RemoveDirectoryW
0x180004838: "capisp.dll::SamConnect failed: %" ??_C@_0CC@KFOFLEJK@capisp?4dll?3?3SamConnect?5failed?3?5?$CF@
0x180004198: "__cdecl _imp_SamOpenUser" __imp_SamOpenUser
0x180005030: "capisp.dll::CryptoSysPrep_Specia" ??_C@_0FC@BCFAHKE@capisp?4dll?3?3CryptoSysPrep_Specia@
0x180001008: ConstructPartialMsgW
0x180005A30: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-file-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-file-l1-1-0
0x180004250: api-ms-win-core-heap-l2-1-0_NULL_THUNK_DATA
0x180005430: "System\Setup" ??_C@_1BK@DBNBIMPE@?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AA?2?$AAS?$AAe?$AAt?$AAu?$AAp?$AA?$AA@
0x180004418: "__cdecl _guard_dispatch_icall_fptr" __guard_dispatch_icall_fptr
0x180004484: "." ??_C@_13JOFGPIOO@?$AA?4?$AA?$AA@
0x180004860: "capisp.dll::SamOpenDomain failed" ??_C@_0CF@MDEGFMJI@capisp?4dll?3?3SamOpenDomain?5failed@
0x180001598: RegisterDll
0x180003294: "__cdecl XcptFilter" _XcptFilter
0x180004420: "__cdecl _xc_a" __xc_a
0x180004238: "__cdecl _imp_FindClose" __imp_FindClose
0x180004180: "__cdecl _imp_SamOpenDomain" __imp_SamOpenDomain
0x1800042A0: "__cdecl _imp_SetCurrentDirectoryW" __imp_SetCurrentDirectoryW
0x180004218: "__cdecl _imp_DeleteFileW" __imp_DeleteFileW
0x1800042A8: api-ms-win-core-processenvironment-l1-1-0_NULL_THUNK_DATA
0x180004C58: "capisp.dll::CAPISysPrep_Generali" ??_C@_0DP@FDLBNKAK@capisp?4dll?3?3CAPISysPrep_Generali@
0x1800024C0: CryptoSysPrep_Specialize_Offline
0x1800043E0: "__cdecl _imp_memset" __imp_memset
0x1800012E4: NukeTempCryptoFiles
0x1800049C0: "Software\Microsoft\Cryptography\" ??_C@_1HI@GKPNHNIL@?$AAS?$AAo?$AAf?$AAt?$AAw?$AAa?$AAr?$AAe?$AA?2?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAC?$AAr?$AAy?$AAp?$AAt?$AAo?$AAg?$AAr?$AAa?$AAp?$AAh?$AAy?$AA?2@
0x180004660: "AppData\Roaming\Microsoft\Protec" ??_C@_1EE@DHIJCOLJ@?$AAA?$AAp?$AAp?$AAD?$AAa?$AAt?$AAa?$AA?2?$AAR?$AAo?$AAa?$AAm?$AAi?$AAn?$AAg?$AA?2?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAP?$AAr?$AAo?$AAt?$AAe?$AAc@
0x18000346F: "__cdecl initterm" _initterm
0x180004C00: "dssenh.dll" ??_C@_1BG@CLNALJLF@?$AAd?$AAs?$AAs?$AAe?$AAn?$AAh?$AA?4?$AAd?$AAl?$AAl?$AA?$AA@
0x180005ABC: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-sysinfo-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-sysinfo-l1-1-0
0x1800075C0: "__cdecl _dyn_tls_init_callback" __dyn_tls_init_callback
0x180004360: "__cdecl _imp_Sleep" __imp_Sleep
0x180004440: "__cdecl _xi_z" __xi_z
0x1800048A8: "capisp.dll::DomainSid=%ws" ??_C@_0BK@JGIJBFMM@capisp?4dll?3?3DomainSid?$DN?$CFws?$AA@
0x180004200: "__cdecl _imp_UnhandledExceptionFilter" __imp_UnhandledExceptionFilter
0x180005200: "%08lx-%04x-%04x-%02x%02x-%02x%02" ??_C@_1GE@JPJFILLD@?$AA?$CF?$AA0?$AA8?$AAl?$AAx?$AA?9?$AA?$CF?$AA0?$AA4?$AAx?$AA?9?$AA?$CF?$AA0?$AA4?$AAx?$AA?9?$AA?$CF?$AA0?$AA2?$AAx?$AA?$CF?$AA0?$AA2?$AAx?$AA?9?$AA?$CF?$AA0?$AA2?$AAx?$AA?$CF?$AA0?$AA2@
0x1800041C8: USERENV_NULL_THUNK_DATA
0x18000347B: "__cdecl _C_specific_handler" __C_specific_handler
0x180004520: "AppData\Roaming\Microsoft\Creden" ??_C@_1EM@KCLDLLGP@?$AAA?$AAp?$AAp?$AAD?$AAa?$AAt?$AAa?$AA?2?$AAR?$AAo?$AAa?$AAm?$AAi?$AAn?$AAg?$AA?2?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAC?$AAr?$AAe?$AAd?$AAe?$AAn@
0x180001030: RemoveDir
0x180004480: "*" ??_C@_13BBDEGPLJ@?$AA?$CK?$AA?$AA@
0x180004908: "capisp.dll::SamQueryInformationU" ??_C@_0CP@IHILLKOB@capisp?4dll?3?3SamQueryInformationU@
0x1800042E8: "__cdecl _imp_RegCloseKey" __imp_RegCloseKey
0x18000368C: "__cdecl _GSHandlerCheckCommon" __GSHandlerCheckCommon
0x1800044D8: "AppData\Local\Microsoft\Vault" ??_C@_1DM@DOHGDCJ@?$AAA?$AAp?$AAp?$AAD?$AAa?$AAt?$AAa?$AA?2?$AAL?$AAo?$AAc?$AAa?$AAl?$AA?2?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAV?$AAa?$AAu?$AAl?$AAt?$AA?$AA@
0x1800041A8: SAMLIB_NULL_THUNK_DATA
0x1800050B0: "capisp.dll::CryptoSysPrep_Specia" ??_C@_0FG@OGMNHIBM@capisp?4dll?3?3CryptoSysPrep_Specia@
0x1800042F8: "__cdecl _imp_RegSetValueExW" __imp_RegSetValueExW
0x1800032A0: "__cdecl amsg_exit" _amsg_exit
0x1800041B0: "__cdecl _imp_WaitForSamService" __imp_WaitForSamService
0x180004BC0: "capisp.dll::CAPISysPrep_Generali" ??_C@_0DP@ONMBLFKJ@capisp?4dll?3?3CAPISysPrep_Generali@
0x180002B20: CryptoSysPrep_Clean
0x1800041D8: "__cdecl _imp_ConstructPartialMsgVW" __imp_ConstructPartialMsgVW
0x1800047D8: "capisp.dll::LsaOpenPolicy failed" ??_C@_0CF@IABGOJHP@capisp?4dll?3?3LsaOpenPolicy?5failed@
0x180004800: "capisp.dll::LsaQueryInformationP" ??_C@_0DB@LHKKFDNO@capisp?4dll?3?3LsaQueryInformationP@
0x180002C38: GetEntropyFromKsecdd
0x180004320: api-ms-win-core-registry-l1-1-0_NULL_THUNK_DATA
0x180004490: "AppData\Local\Microsoft\Credenti" ??_C@_1EI@EPAHNNBB@?$AAA?$AAp?$AAp?$AAD?$AAa?$AAt?$AAa?$AA?2?$AAL?$AAo?$AAc?$AAa?$AAl?$AA?2?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAC?$AAr?$AAe?$AAd?$AAe?$AAn?$AAt?$AAi@
0x180004208: api-ms-win-core-errorhandling-l1-1-0_NULL_THUNK_DATA
0x1800042C0: "__cdecl _imp_GetCurrentProcess" __imp_GetCurrentProcess
0x1800075B0: "__cdecl _native_startup_lock" __native_startup_lock
0x180002D30: DllMain
0x180004160: "__cdecl _imp_UuidFromStringW" __imp_UuidFromStringW
0x1800043A0: "__cdecl _imp__wcsicmp" __imp__wcsicmp
0x180005A94: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-string-l2-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-string-l2-1-0
0x1800043A8: "__cdecl _imp___C_specific_handler" __imp___C_specific_handler
0x180004330: "__cdecl _imp_RtlCaptureContext" __imp_RtlCaptureContext
0x180004280: api-ms-win-core-libraryloader-l1-2-0_NULL_THUNK_DATA
0x180004290: api-ms-win-core-libraryloader-l1-2-1_NULL_THUNK_DATA
0x180004AD8: "capisp.dll::CheckIFCryptoSysPrep" ??_C@_0DK@FIIOBIKA@capisp?4dll?3?3CheckIFCryptoSysPrep@
0x180004158: KERNEL32_NULL_THUNK_DATA
0x180004FE0: "KryptonModeEnabled" ??_C@_1CG@JIELMHIO@?$AAK?$AAr?$AAy?$AAp?$AAt?$AAo?$AAn?$AAM?$AAo?$AAd?$AAe?$AAE?$AAn?$AAa?$AAb?$AAl?$AAe?$AAd?$AA?$AA@
0x1800041F8: "__cdecl _imp_GetLastError" __imp_GetLastError
0x180004390: "__cdecl _imp_ConvertSidToStringSidW" __imp_ConvertSidToStringSidW
0x180004148: DPAPI_NULL_THUNK_DATA
0x180007000: "__cdecl _native_dllmain_reason" __native_dllmain_reason
0x180003668: "__cdecl _GSHandlerCheck" __GSHandlerCheck
0x180004760: "ds\security\cryptoapi\capisp\cap" ??_C@_1EM@IMHOPGFF@?$AAd?$AAs?$AA?2?$AAs?$AAe?$AAc?$AAu?$AAr?$AAi?$AAt?$AAy?$AA?2?$AAc?$AAr?$AAy?$AAp?$AAt?$AAo?$AAa?$AAp?$AAi?$AA?2?$AAc?$AAa?$AAp?$AAi?$AAs?$AAp?$AA?2?$AAc?$AAa?$AAp@
0x180004B78: "rsaenh.dll" ??_C@_1BG@NLKBJOOP@?$AAr?$AAs?$AAa?$AAe?$AAn?$AAh?$AA?4?$AAd?$AAl?$AAl?$AA?$AA@
0x180005BAC: "__cdecl _IMPORT_DESCRIPTOR_ADVAPI32" __IMPORT_DESCRIPTOR_ADVAPI32
0x180005BE8: "__cdecl _IMPORT_DESCRIPTOR_SAMLIB" __IMPORT_DESCRIPTOR_SAMLIB
0x1800042B0: "__cdecl _imp_GetCurrentProcessId" __imp_GetCurrentProcessId
0x180005368: "CryptoSysPrep_Clean" ??_C@_1CI@LJGIGJEJ@?$AAC?$AAr?$AAy?$AAp?$AAt?$AAo?$AAS?$AAy?$AAs?$AAP?$AAr?$AAe?$AAp?$AA_?$AAC?$AAl?$AAe?$AAa?$AAn?$AA?$AA@
0x1800043D8: "__cdecl _imp_swprintf_s" __imp_swprintf_s
0x180004310: "__cdecl _imp_RegDeleteValueW" __imp_RegDeleteValueW
0x180003360: "__cdecl ValidateImageBase" _ValidateImageBase
0x180004128: "__cdecl _imp_LsaQueryInformationPolicy" __imp_LsaQueryInformationPolicy
0x180004A40: "CheckIFCryptoSysPrepSpecialized" ??_C@_1EA@LFMPOJOC@?$AAC?$AAh?$AAe?$AAc?$AAk?$AAI?$AAF?$AAC?$AAr?$AAy?$AAp?$AAt?$AAo?$AAS?$AAy?$AAs?$AAP?$AAr?$AAe?$AAp?$AAS?$AAp?$AAe?$AAc?$AAi?$AAa?$AAl?$AAi?$AAz?$AAe?$AAd?$AA?$AA@
0x180004190: "__cdecl _imp_SamConnect" __imp_SamConnect
0x180005AE4: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-libraryloader-l1-2-0" __IMPORT_DESCRIPTOR_api-ms-win-core-libraryloader-l1-2-0
0x1800024A0: CryptoSysPrep_Specialize
0x180005AA8: "__cdecl _IMPORT_DESCRIPTOR_USERENV" __IMPORT_DESCRIPTOR_USERENV
0x180004278: "__cdecl _imp_FreeLibrary" __imp_FreeLibrary
0x180005008: "CreateMachineGuid" ??_C@_1CE@JAKAKDDA@?$AAC?$AAr?$AAe?$AAa?$AAt?$AAe?$AAM?$AAa?$AAc?$AAh?$AAi?$AAn?$AAe?$AAG?$AAu?$AAi?$AAd?$AA?$AA@
0x180004358: api-ms-win-core-string-l2-1-0_NULL_THUNK_DATA
0x180002FD0: "__cdecl DllMainCRTStartup" _DllMainCRTStartup
0x1800043B0: "__cdecl _imp__initterm" __imp__initterm
0x180004B20: "Software\Microsoft\Cryptography" ??_C@_1EA@FECOHKPP@?$AAS?$AAo?$AAf?$AAt?$AAw?$AAa?$AAr?$AAe?$AA?2?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAC?$AAr?$AAy?$AAp?$AAt?$AAo?$AAg?$AAr?$AAa?$AAp?$AAh?$AAy?$AA?$AA@
0x180004938: "capisp.dll::SamSetInformationUse" ??_C@_0CN@CNAPDDH@capisp?4dll?3?3SamSetInformationUse@
0x180004378: "__cdecl _imp_GetVersionExW" __imp_GetVersionExW
0x180005A44: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-registry-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-registry-l1-1-0
0x1800024B0: CryptoSysPrep_Specialize_Clone
0x1800075A0: "__cdecl _onexitend" __onexitend
0x180005AF8: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-libraryloader-l1-2-1" __IMPORT_DESCRIPTOR_api-ms-win-core-libraryloader-l1-2-1
0x180004410: "__cdecl _guard_check_icall_fptr" __guard_check_icall_fptr
0x180004210: "__cdecl _imp_FindFirstFileW" __imp_FindFirstFileW
0x1800042B8: "__cdecl _imp_TerminateProcess" __imp_TerminateProcess
0x180004388: api-ms-win-core-sysinfo-l1-1-0_NULL_THUNK_DATA
0x180004CD0: "SysprepMode" ??_C@_1BI@DIDJKAPA@?$AAS?$AAy?$AAs?$AAp?$AAr?$AAe?$AAp?$AAM?$AAo?$AAd?$AAe?$AA?$AA@
0x180004430: "__cdecl _xi_a" __xi_a
0x180004380: "__cdecl _imp_GetTickCount" __imp_GetTickCount
0x180001E60: CAPISysPrep_Generalize
0x1800047AC: "D" ??_C@_13MKMNOPIJ@?$AAD?$AA?$AA@
0x180004178: "__cdecl _imp_SamFreeMemory" __imp_SamFreeMemory
0x180005B98: "__cdecl _IMPORT_DESCRIPTOR_DPAPI" __IMPORT_DESCRIPTOR_DPAPI
0x180005B5C: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-processthreads-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-processthreads-l1-1-0
0x1800075C8: "__cdecl pRawDllMain" _pRawDllMain
0x180004488: ".." ??_C@_15DDHGOCBH@?$AA?4?$AA?4?$AA?$AA@
0x180004C18: "capisp.dll::CAPISysPrep_Generali" ??_C@_0DP@MHJNECAI@capisp?4dll?3?3CAPISysPrep_Generali@
0x180004570: "AppData\Roaming\Microsoft\Crypto" ??_C@_1EK@IKKMPAGC@?$AAA?$AAp?$AAp?$AAD?$AAa?$AAt?$AAa?$AA?2?$AAR?$AAo?$AAa?$AAm?$AAi?$AAn?$AAg?$AA?2?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAC?$AAr?$AAy?$AAp?$AAt?$AAo@
0x180004C98: "capisp.dll::CAPISysPrep_Generali" ??_C@_0DB@CEEBJJFA@capisp?4dll?3?3CAPISysPrep_Generali@
0x180004118: "__cdecl _imp_LsaFreeMemory" __imp_LsaFreeMemory
0x180003270: "__cdecl _security_check_cookie" __security_check_cookie
0x180004428: "__cdecl _xc_z" __xc_z
0x1800020B8: CryptoSysPrep_Specialize_Internal
0x180005B20: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-heap-l2-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-heap-l2-1-0
0x1800042D0: api-ms-win-core-processthreads-l1-1-0_NULL_THUNK_DATA
0x180004268: "__cdecl _imp_GetProcAddress" __imp_GetProcAddress
0x180004970: "capisp.dll::DisableAdministrator" ??_C@_0EJ@HKFLNJMP@capisp?4dll?3?3DisableAdministrator@
0x180004260: api-ms-win-core-io-l1-1-0_NULL_THUNK_DATA
0x180004370: "__cdecl _imp_GetSystemTimeAsFileTime" __imp_GetSystemTimeAsFileTime
0x18000256C: CreateMachineGuid
0x180005390: "capisp.dll::CryptoSysPrep_Clean:" ??_C@_0EJ@ECOBMCFB@capisp?4dll?3?3CryptoSysPrep_Clean?3@
0x180004230: "__cdecl _imp_FindNextFileW" __imp_FindNextFileW
0x1800041B8: SYSSETUP_NULL_THUNK_DATA
0x180004340: api-ms-win-core-rtlsupport-l1-1-0_NULL_THUNK_DATA
0x180005B70: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-rtlsupport-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-rtlsupport-l1-1-0
0x1800042E0: api-ms-win-core-profile-l1-1-0_NULL_THUNK_DATA
0x180004130: "__cdecl _imp_LsaClose" __imp_LsaClose
0x180004448: "__cdecl _guard_fids_table" __guard_fids_table
0x180004150: "__cdecl _imp_lstrcmpW" __imp_lstrcmpW
0x180005410: "\Device\KsecDD" ??_C@_1BO@BAEMGIAB@?$AA?2?$AAD?$AAe?$AAv?$AAi?$AAc?$AAe?$AA?2?$AAK?$AAs?$AAe?$AAc?$AAD?$AAD?$AA?$AA@
0x180004348: "__cdecl _imp_CharNextW" __imp_CharNextW
0x1800043E8: msvcrt_NULL_THUNK_DATA
0x180004010: "__cdecl load_config_used" _load_config_used
0x180004D60: "CryptoSysPrep_Specialize_Interna" ??_C@_1EE@KACPLMHK@?$AAC?$AAr?$AAy?$AAp?$AAt?$AAo?$AAS?$AAy?$AAs?$AAP?$AAr?$AAe?$AAp?$AA_?$AAS?$AAp?$AAe?$AAc?$AAi?$AAa?$AAl?$AAi?$AAz?$AAe?$AA_?$AAI?$AAn?$AAt?$AAe?$AAr?$AAn?$AAa@
0x180005450: "Upgrade" ??_C@_1BA@GGIBCIOH@?$AAU?$AAp?$AAg?$AAr?$AAa?$AAd?$AAe?$AA?$AA@
0x180005A80: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-security-sddl-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-security-sddl-l1-1-0
0x180004610: "AppData\Roaming\Microsoft\Crypto" ??_C@_1EM@ODMMALPP@?$AAA?$AAp?$AAp?$AAD?$AAa?$AAt?$AAa?$AA?2?$AAR?$AAo?$AAa?$AAm?$AAi?$AAn?$AAg?$AA?2?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAC?$AAr?$AAy?$AAp?$AAt?$AAo@
0x1800041A0: "__cdecl _imp_SamSetInformationUser" __imp_SamSetInformationUser
0x180005A6C: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-io-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-io-l1-1-0
0x180005B0C: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-processenvironment-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-processenvironment-l1-1-0
0x180004B60: "MachineGuid" ??_C@_1BI@HFOGPJOA@?$AAM?$AAa?$AAc?$AAh?$AAi?$AAn?$AAe?$AAG?$AAu?$AAi?$AAd?$AA?$AA@
0x1800015E0: DisableAdministratorIfApplicable
0x1800043C8: "__cdecl _imp__amsg_exit" __imp__amsg_exit
0x180005320: "capisp.dll::CryptoSysPrep_Specia" ??_C@_0EG@CKEALBIH@capisp?4dll?3?3CryptoSysPrep_Specia@
0x180004270: "__cdecl _imp_DisableThreadLibraryCalls" __imp_DisableThreadLibraryCalls
0x1800043F8: "__cdecl _imp_NtClose" __imp_NtClose
0x180004170: "__cdecl _imp_SamCloseHandle" __imp_SamCloseHandle
0x1800011A4: OPKAddPathN
0x180004328: "__cdecl _imp_RtlLookupFunctionEntry" __imp_RtlLookupFunctionEntry
0x1800042D8: "__cdecl _imp_QueryPerformanceCounter" __imp_QueryPerformanceCounter
0x180004188: "__cdecl _imp_SamQueryInformationUser" __imp_SamQueryInformationUser
0x1800046B0: "AppData\Roaming\Microsoft\Vault" ??_C@_1EA@OHCKBEMM@?$AAA?$AAp?$AAp?$AAD?$AAa?$AAt?$AAa?$AA?2?$AAR?$AAo?$AAa?$AAm?$AAi?$AAn?$AAg?$AA?2?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAV?$AAa?$AAu?$AAl?$AAt?$AA?$AA@
0x180004338: "__cdecl _imp_RtlVirtualUnwind" __imp_RtlVirtualUnwind
0x180004E00: "capisp.dll::CryptoSysPrep_Specia" ??_C@_0EC@LNMHEBOD@capisp?4dll?3?3CryptoSysPrep_Specia@
0x180003490: "__cdecl guard_check_icall_nop" _guard_check_icall_nop
0x180004B90: "CAPISysPrep_Generalize" ??_C@_1CO@HBGIBJOC@?$AAC?$AAA?$AAP?$AAI?$AAS?$AAy?$AAs?$AAP?$AAr?$AAe?$AAp?$AA_?$AAG?$AAe?$AAn?$AAe?$AAr?$AAa?$AAl?$AAi?$AAz?$AAe?$AA?$AA@
0x180004CF0: "Microsoft\Windows\CurrentVersion" ??_C@_1FO@DIEGPEHH@?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAW?$AAi?$AAn?$AAd?$AAo?$AAw?$AAs?$AA?2?$AAC?$AAu?$AAr?$AAr?$AAe?$AAn?$AAt?$AAV?$AAe?$AAr?$AAs?$AAi?$AAo?$AAn@
0x180005110: "capisp.dll::CryptoSysPrep_Specia" ??_C@_0IM@PBALOPIG@capisp?4dll?3?3CryptoSysPrep_Specia@
0x180004120: "__cdecl _imp_LsaOpenPolicy" __imp_LsaOpenPolicy
0x180004710: "DisableAdministratorIfApplicable" ??_C@_1EC@HBDPLNMB@?$AAD?$AAi?$AAs?$AAa?$AAb?$AAl?$AAe?$AAA?$AAd?$AAm?$AAi?$AAn?$AAi?$AAs?$AAt?$AAr?$AAa?$AAt?$AAo?$AAr?$AAI?$AAf?$AAA?$AAp?$AAp?$AAl?$AAi?$AAc?$AAa?$AAb?$AAl?$AAe@
0x180004350: "__cdecl _imp_CharPrevW" __imp_CharPrevW
0x1800043D0: "__cdecl _imp__XcptFilter" __imp__XcptFilter
0x180004408: ntdll_NULL_THUNK_DATA
0x180004F40: "capisp.dll::CryptoSysPrep_Specia" ??_C@_0DD@EBFEJAI@capisp?4dll?3?3CryptoSysPrep_Specia@
0x180001CEC: CheckIFCryptoSysPrepSpecialized
0x180007008: "__cdecl _security_cookie" __security_cookie
0x180004318: "__cdecl _imp_RegQueryValueExW" __imp_RegQueryValueExW
0x180004248: "__cdecl _imp_LocalFree" __imp_LocalFree
0x180005AD0: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-errorhandling-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-errorhandling-l1-1-0
0x180004288: "__cdecl _imp_LoadLibraryW" __imp_LoadLibraryW
0x1800042F0: "__cdecl _imp_RegCreateKeyExW" __imp_RegCreateKeyExW
0x1800075A8: "__cdecl _onexitbegin" __onexitbegin
0x180004F80: "SOFTWARE\Microsoft\Windows\Curre" ??_C@_1FO@ICCKHOGD@?$AAS?$AAO?$AAF?$AAT?$AAW?$AAA?$AAR?$AAE?$AA?2?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAW?$AAi?$AAn?$AAd?$AAo?$AAw?$AAs?$AA?2?$AAC?$AAu?$AAr?$AAr?$AAe@
0x1800041C0: "__cdecl _imp_GetProfilesDirectoryW" __imp_GetProfilesDirectoryW
0x1800041F0: "__cdecl _imp_SetUnhandledExceptionFilter" __imp_SetUnhandledExceptionFilter
0x180005BC0: "__cdecl _IMPORT_DESCRIPTOR_KERNEL32" __IMPORT_DESCRIPTOR_KERNEL32
0x180004EF0: "capisp.dll::CryptoSysPrep_Specia" ??_C@_0EO@FIPHNOPH@capisp?4dll?3?3CryptoSysPrep_Specia@
0x180004300: "__cdecl _imp_RegOpenKeyExW" __imp_RegOpenKeyExW
0x180003394: "__cdecl _security_init_cookie" __security_init_cookie
0x180004D50: "upgrade" ??_C@_1BA@HBLOFDJK@?$AAu?$AAp?$AAg?$AAr?$AAa?$AAd?$AAe?$AA?$AA@
0x180004888: "capisp.dll::DomainName=%wZ" ??_C@_0BL@BPKCHADM@capisp?4dll?3?3DomainName?$DN?$CFwZ?$AA@
0x1800041D0: "__cdecl _imp_WdsSetupLogMessageW" __imp_WdsSetupLogMessageW
0x180004308: "__cdecl _imp_RegGetValueW" __imp_RegGetValueW
0x1800047B0: "capisp.dll::GetVersionEx failed:" ??_C@_0CE@IHBEPENN@capisp?4dll?3?3GetVersionEx?5failed?3@
0x180005A1C: "__cdecl _IMPORT_DESCRIPTOR_msvcrt" __IMPORT_DESCRIPTOR_msvcrt
0x180004398: api-ms-win-security-sddl-l1-1-0_NULL_THUNK_DATA
0x180004A80: "capisp.dll::CheckIFCryptoSysPrep" ??_C@_0FD@DNIODELC@capisp?4dll?3?3CheckIFCryptoSysPrep@
0x180004140: "__cdecl _imp_CryptResetMachineCredentials" __imp_CryptResetMachineCredentials
0x1800043B8: "__cdecl _imp_malloc" __imp_malloc
0x180004138: ADVAPI32_NULL_THUNK_DATA
0x180005BFC: "__cdecl _IMPORT_DESCRIPTOR_SYSSETUP" __IMPORT_DESCRIPTOR_SYSSETUP
0x1800045C0: "AppData\Roaming\Microsoft\Crypto" ??_C@_1EK@MKGIFHNK@?$AAA?$AAp?$AAp?$AAD?$AAa?$AAt?$AAa?$AA?2?$AAR?$AAo?$AAa?$AAm?$AAi?$AAn?$AAg?$AA?2?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAC?$AAr?$AAy?$AAp?$AAt?$AAo@
0x180005A58: "__cdecl _IMPORT_DESCRIPTOR_RPCRT4" __IMPORT_DESCRIPTOR_RPCRT4
0x180004EA0: "capisp.dll::CryptoSysPrep_Specia" ??_C@_0EB@MDMOGLGB@capisp?4dll?3?3CryptoSysPrep_Specia@
0x180004168: RPCRT4_NULL_THUNK_DATA
0x1800034E0: "__cdecl _report_gsfailure" __report_gsfailure
0x180004400: "__cdecl _imp_NtOpenFile" __imp_NtOpenFile
0x1800052D0: "capisp.dll::CryptoSysPrep_Specia" ??_C@_0EO@FPNJFIFG@capisp?4dll?3?3CryptoSysPrep_Specia@
0x1800075B8: "__cdecl _native_startup_state" __native_startup_state
0x1800041E8: WDSCORE_NULL_THUNK_DATA
0x180004E50: "capisp.dll::CryptoSysPrep_Specia" ??_C@_0EB@OJJCJMMA@capisp?4dll?3?3CryptoSysPrep_Specia@
0x180005B48: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-profile-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-profile-l1-1-0
0x1800043C0: "__cdecl _imp_free" __imp_free
0x180003300: "__cdecl IsNonwritableInCurrentImage" _IsNonwritableInCurrentImage
0x180004368: api-ms-win-core-synch-l1-2-0_NULL_THUNK_DATA
0x180004DB0: "capisp.dll::CryptoSysPrep_Specia" ??_C@_0FA@BLMKBDBE@capisp?4dll?3?3CryptoSysPrep_Specia@
0x180005B84: "__cdecl _IMPORT_DESCRIPTOR_WDSCORE" __IMPORT_DESCRIPTOR_WDSCORE
0x180004228: "__cdecl _imp_SetFileAttributesW" __imp_SetFileAttributesW
0x180005B34: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-synch-l1-2-0" __IMPORT_DESCRIPTOR_api-ms-win-core-synch-l1-2-0
0x1800053E0: "capisp.dll::CryptoSysPrep_Clean:" ??_C@_0CO@OCCMODGK@capisp?4dll?3?3CryptoSysPrep_Clean?3@
0x1800036ED: memset
0x180005C10: "__cdecl _NULL_IMPORT_DESCRIPTOR" __NULL_IMPORT_DESCRIPTOR
0x180005088: "KryptonMachineGuid" ??_C@_1CG@EPEPGDFD@?$AAK?$AAr?$AAy?$AAp?$AAt?$AAo?$AAn?$AAM?$AAa?$AAc?$AAh?$AAi?$AAn?$AAe?$AAG?$AAu?$AAi?$AAd?$AA?$AA@
[JEB Decompiler by PNF Software]