Generated by JEB on 2019/08/01
PE: C:\Windows\System32\drivers\bttflt.sys Base=0x1C0000000 SHA-256=2E8B80A5EBD8C3ED14DC2A6E7EEB710216DFF0D04251D8E452F68E6D35BFC6F7
PDB: bttflt.pdb GUID={F7BBAC9E-DABC-A34C-73B1746511518FA7} Age=1
196 located named symbols:
0x1C0001DE0: BttFltProcessScsi
0x1C0001490: WppClassicProviderCallback
0x1C0005568: "BTT: read_flog_pair: flog layout" ??_C@_0DO@CHCIHBDL@BTT?3?5read_flog_pair?3?5flog?5layout@
0x1C0002A60: ScmBttGetDataOffsetForBlock
0x1C0006018: "__cdecl _security_cookie_complement" __security_cookie_complement
0x1C0009150: WppTraceCallback
0x1C0006040: BttFltGlobalData
0x1C0001F70: BttFltPassThrough
0x1C0008120: "__cdecl _imp_MmGetPhysicalAddress" __imp_MmGetPhysicalAddress
0x1C0008050: "__cdecl _imp_RtlInitUnicodeString" __imp_RtlInitUnicodeString
0x1C0004330: "__cdecl guard_dispatch_icall_nop" _guard_dispatch_icall_nop
0x1C0003DB8: FillInPremappedVirtualAddresses
0x1C0005500: "BTT: read_flog_pair: invalid lan" ??_C@_0DE@CBNDMFCA@BTT?3?5read_flog_pair?3?5invalid?5lan@
0x1C0008048: "__cdecl _imp_ExpInterlockedPushEntrySList" __imp_ExpInterlockedPushEntrySList
0x1C00080B0: "__cdecl _imp_IoCreateDevice" __imp_IoCreateDevice
0x1C00055A8: "Reading %d arenas on lane %d" ??_C@_0BN@JBPCKAPI@Reading?5?$CFd?5arenas?5on?5lane?5?$CFd?$AA@
0x1C0008110: "__cdecl _imp_RtlWriteNonVolatileMemory" __imp_RtlWriteNonVolatileMemory
0x1C0005170: "WmiTraceMessage" ??_C@_1CA@OFIBBPKJ@?$AAW?$AAm?$AAi?$AAT?$AAr?$AAa?$AAc?$AAe?$AAM?$AAe?$AAs?$AAs?$AAa?$AAg?$AAe?$AA?$AA@
0x1C00080E8: "__cdecl _imp_IofCompleteRequest" __imp_IofCompleteRequest
0x1C0002B60: ScmBttOpenMappedPool
0x1C0001078: WPP_SF_IId
0x1C0001140: WPP_SF_Iqd
0x1C0005538: "BTT: read_flog_pair: invalid flo" ??_C@_0CN@LFLDPELI@BTT?3?5read_flog_pair?3?5invalid?5flo@
0x1C0001FBC: BttFltFreeSrbContext
0x1C0008038: "__cdecl _imp_MmBuildMdlForNonPagedPool" __imp_MmBuildMdlForNonPagedPool
0x1C0008150: "__cdecl _guard_dispatch_icall_fptr" __guard_dispatch_icall_fptr
0x1C0008080: "__cdecl _imp_IoAttachDeviceToDeviceStack" __imp_IoAttachDeviceToDeviceStack
0x1C0005230: WPP_f1d66ef65f5c378318982791487e82b4_Traceguids
0x1C000A700: BttFltNsZero
0x1C00080A0: "__cdecl _imp_MmGetSystemRoutineAddress" __imp_MmGetSystemRoutineAddress
0x1C0008058: "__cdecl _imp_KeInitializeSpinLock" __imp_KeInitializeSpinLock
0x1C0008070: "__cdecl _imp_IoForwardIrpSynchronously" __imp_IoForwardIrpSynchronously
0x1C0008108: "__cdecl _imp_RtlFlushNonVolatileMemory" __imp_RtlFlushNonVolatileMemory
0x1C0003FF4: AllocateAndFillInPremappedVirtualAddresses
0x1C00080F0: "__cdecl _imp_KeWaitForSingleObject" __imp_KeWaitForSingleObject
0x1C0001BC8: BttFltProcessReadWrite
0x1C0008088: "__cdecl _imp_KeReleaseSpinLock" __imp_KeReleaseSpinLock
0x1C0002570: nsunmap
0x1C0004340: memcpy
0x1C000A940: BttFltNsMap
0x1C0008060: "__cdecl _imp_IoDeleteDevice" __imp_IoDeleteDevice
0x1C0006030: pfnWppGetVersion
0x1C0005390: "BTT: nsmap: offset + count (%lld" ??_C@_0DO@PKDBNOBC@BTT?3?5nsmap?3?5offset?5?$CL?5count?5?$CI?$CFlld@
0x1C00080B8: "__cdecl _imp_IofCallDriver" __imp_IofCallDriver
0x1C0004340: memmove
0x1C0005410: "BTT: pmemblk_load_mapped_pool: m" ??_C@_0DN@BJKMOAHE@BTT?3?5pmemblk_load_mapped_pool?3?5m@
0x1C0005240: VHD_PMEM_ADDRESS_ABSTRACTION_BTT
0x1C00042AC: "__cdecl _GSHandlerCheckCommon" __GSHandlerCheckCommon
0x1C0001FB0: BttFltIsPhysicalMemoryRangeGood
0x1C0008078: "__cdecl _imp_IoBuildDeviceIoControlRequest" __imp_IoBuildDeviceIoControlRequest
0x1C0008130: "__cdecl _imp_KeQueryActiveProcessorCountEx" __imp_KeQueryActiveProcessorCountEx
0x1C0006160: WPP_MAIN_CB
0x1C00020A0: BttFltNsReadMapped
0x1C000152C: BttFltUnlinkDevice
0x1C0002104: ScmBttWriteTraceEvent
0x1C0001314: WPP_SF_qII
0x1C00020E0: BttFltNsUnmap
0x1C0005610: "BTT: write_layout: number of int" ??_C@_0EH@MJLLICNB@BTT?3?5write_layout?3?5number?5of?5int@
0x1C00012A0: WPP_SF_qDII
0x1C00080A8: "__cdecl _imp_ExAllocatePoolWithTag" __imp_ExAllocatePoolWithTag
0x1C0005450: "BTT: pmemblk_load_mapped_pool: m" ??_C@_0DN@OMIGDBHM@BTT?3?5pmemblk_load_mapped_pool?3?5m@
0x1C0008000: "__cdecl _imp_IoBuildPartialMdl" __imp_IoBuildPartialMdl
0x1C0006138: pfnWppQueryTraceInformation
0x1C0005750: "BTT: btt_init: rawsize smaller t" ??_C@_0DE@BNIAJLEF@BTT?3?5btt_init?3?5rawsize?5smaller?5t@
0x1C0002B7C: ScmBttInitializeLayout
0x1C00061A0: BttFltBttIoRoutines
0x1C00010E8: WPP_SF_Iq
0x1C00080E0: "__cdecl _imp_MmUnmapLockedPages" __imp_MmUnmapLockedPages
0x1C0004288: "__cdecl _GSHandlerCheck" __GSHandlerCheck
0x1C00099A4: BttFltStartDevice
0x1C0008040: "__cdecl _imp_IoAllocateMdl" __imp_IoAllocateMdl
0x1C0005150: "PsGetVersion" ??_C@_1BK@DHLDGJM@?$AAP?$AAs?$AAG?$AAe?$AAt?$AAV?$AAe?$AAr?$AAs?$AAi?$AAo?$AAn?$AA?$AA@
0x1C0008020: "__cdecl _imp_ExpInterlockedPopEntrySList" __imp_ExpInterlockedPopEntrySList
0x1C0009DC0: BttFltQueryDiskGeometry
0x1C0005490: "BTT: invalid_lba: lba out of ran" ??_C@_0CO@ICNMGMA@BTT?3?5invalid_lba?3?5lba?5out?5of?5ran@
0x1C0006020: pfnEtwRegisterClassicProvider
0x1C0005300: "BTT: nis_memory_range_good: offs" ??_C@_0EM@GGFIFMDA@BTT?3?5nis_memory_range_good?3?5offs@
0x1C0003B10: btt_init
0x1C0008010: "__cdecl _imp_ExDeleteLookasideListEx" __imp_ExDeleteLookasideListEx
0x1C0005260: VHD_PMEM_ADDRESS_ABSTRACTION_NONE
0x1C00056B8: "BTT: read_layout: nfree can't be" ??_C@_0CD@DJBNFDGM@BTT?3?5read_layout?3?5nfree?5can?8t?5be@
0x1C0001B20: BttFltContinueIoOperation
0x1C00017C4: BttFltStartNextIoOperation
0x1C00054C0: "BTT: invalid_arena_lba: arena lb" ??_C@_0DK@NHIDLFDL@BTT?3?5invalid_arena_lba?3?5arena?5lb@
0x1C0008100: "__cdecl _imp_KeGetCurrentProcessorNumberEx" __imp_KeGetCurrentProcessorNumberEx
0x1C0006140: pfnEtwUnregister
0x1C0002058: BttFltAlignOffsets
0x1C00021A0: nsio_callout
0x1C00052B0: "BTT: nsis_memory_range_good: off" ??_C@_0EP@DCGBEEJG@BTT?3?5nsis_memory_range_good?3?5off@
0x1C0006148: g_writeTraceEvent
0x1C000B1F0: GsDriverEntry
0x1C0008148: "__cdecl _guard_check_icall_fptr" __guard_check_icall_fptr
0x1C0005220: BTTFLT_BTT_SIGNATURE
0x1C0005350: "BTT: nswrite: offset + count (%l" ??_C@_0EA@KGHMDMBA@BTT?3?5nswrite?3?5offset?5?$CL?5count?5?$CI?$CFl@
0x1C0001754: BttFltCompleteIoOperation
0x1C0006000: WPP_GLOBAL_Control
0x1C0001210: WPP_SF_d
0x1C0004230: "__cdecl _security_check_cookie" __security_check_cookie
0x1C0008018: "__cdecl _imp_IoDetachDevice" __imp_IoDetachDevice
0x1C0002BC0: read_map_entry
0x1C0008158: "__cdecl _IMPORT_DESCRIPTOR_ntoskrnl" __IMPORT_DESCRIPTOR_ntoskrnl
0x1C00016D0: BttFltFreeWorkItem
0x1C0004311: "__cdecl _chkstk" __chkstk
0x1C0002A50: ScmBttGetUsableBlockCount
0x1C0002B60: ScmBttCreateMappedPool
0x1C0009434: WppCleanupKm
0x1C0009F60: BttFltContainsBttAddressAbstraction
0x1C000C000: "__cdecl _guard_fids_table" __guard_fids_table
0x1C0005040: "__cdecl load_config_used" _load_config_used
0x1C00056E0: "BTT: read_layout: external_nlba " ??_C@_0CL@PMOICIEE@BTT?3?5read_layout?3?5external_nlba?5@
0x1C0009810: BttFltIoctl
0x1C0005250: WPP_ThisDir_CTLGUID_BttFltTraceGuid
0x1C00014C4: BttFltLinkDevice
0x1C000A074: BttFltIsBttMetadataPresent
0x1C0008128: "__cdecl _imp_MmMapIoSpaceEx" __imp_MmMapIoSpaceEx
0x1C00080D8: "__cdecl _imp_KeInitializeEvent" __imp_KeInitializeEvent
0x1C0008028: "__cdecl _imp_IoSynchronousCallDriver" __imp_IoSynchronousCallDriver
0x1C0005190: "WmiQueryTraceInformation" ??_C@_1DC@DOCOAJH@?$AAW?$AAm?$AAi?$AAQ?$AAu?$AAe?$AAr?$AAy?$AAT?$AAr?$AAa?$AAc?$AAe?$AAI?$AAn?$AAf?$AAo?$AAr?$AAm?$AAa?$AAt?$AAi?$AAo?$AAn?$AA?$AA@
0x1C000A400: BttFltNsRead
0x1C0002BB4: ScmBttGetPoolIoCallbackContext
0x1C0005200: "EtwUnregister" ??_C@_1BM@CJMKDOJH@?$AAE?$AAt?$AAw?$AAU?$AAn?$AAr?$AAe?$AAg?$AAi?$AAs?$AAt?$AAe?$AAr?$AA?$AA@
0x1C000A2C0: BttFltSynchronousReadWrite
0x1C0008030: "__cdecl _imp_IoFreeIrp" __imp_IoFreeIrp
0x1C0004270: "__cdecl guard_check_icall_nop" _guard_check_icall_nop
0x1C0005270: "BTT: nsread: offset + count (%ll" ??_C@_0DP@JOHMLBNO@BTT?3?5nsread?3?5offset?5?$CL?5count?5?$CI?$CFll@
0x1C0009008: WppLoadTracingSupport
0x1C00080C8: "__cdecl _imp_IoWMIRegistrationControl" __imp_IoWMIRegistrationControl
0x1C0003C30: btt_fini
0x1C000410C: GetPremappedAreaAddress
0x1C0001008: WPP_SF_Dqd
0x1C0001428: WPP_SF_qqq
0x1C0008008: "__cdecl _imp_KeAcquireSpinLockRaiseToDpc" __imp_KeAcquireSpinLockRaiseToDpc
0x1C00098D0: BttFltPnp
0x1C0006010: "__cdecl _security_cookie" __security_cookie
0x1C00015CC: BttFltSetReadWriteOffsets
0x1C00094C0: BttFltAddDevice
0x1C000A570: BttFltNsWrite
0x1C00080F8: "__cdecl _imp_RtlCompareMemory" __imp_RtlCompareMemory
0x1C000A150: BttFltAllocateAndInitializeSrbContext
0x1C00051C8: "EtwRegisterClassicProvider" ??_C@_1DG@PFOPAIND@?$AAE?$AAt?$AAw?$AAR?$AAe?$AAg?$AAi?$AAs?$AAt?$AAe?$AAr?$AAC?$AAl?$AAa?$AAs?$AAs?$AAi?$AAc?$AAP?$AAr?$AAo?$AAv?$AAi?$AAd?$AAe?$AAr?$AA?$AA@
0x1C00020D0: BttFltNsWriteMapped
0x1C0008098: "__cdecl _imp_IoFreeMdl" __imp_IoFreeMdl
0x1C0001378: WPP_SF_qd
0x1C00013D0: WPP_SF_qq
0x1C0008118: "__cdecl _imp_MmUnmapIoSpace" __imp_MmUnmapIoSpace
0x1C000417C: FreePremappedVirtualAddresses
0x1C000B224: "__cdecl _security_init_cookie" __security_init_cookie
0x1C0001258: WPP_SF_q
0x1C0008138: "__cdecl _imp___chkstk" __imp___chkstk
0x1C00080D0: "__cdecl _imp_ExInitializeLookasideListEx" __imp_ExInitializeLookasideListEx
0x1C0006130: WPPTraceSuite
0x1C0003D3C: util_checksum
0x1C00053D0: "BTT: nszero: offset + count (%ll" ??_C@_0DP@KJCOBAJF@BTT?3?5nszero?3?5offset?5?$CL?5count?5?$CI?$CFll@
0x1C000168C: BttFltSetSrbOpCode
0x1C0004260: "__cdecl _report_gsfailure" __report_gsfailure
0x1C0001FA0: BttFltGetBadMemoryRangeCount
0x1C0005660: "BTT: read_layout: inconsistent l" ??_C@_0FH@LMGHFHEG@BTT?3?5read_layout?3?5inconsistent?5l@
0x1C0008068: "__cdecl _imp_ExQueryDepthSList" __imp_ExQueryDepthSList
0x1C0001590: BttFltUnload
0x1C0005710: "BTT: read_layout: next arena off" ??_C@_0DL@BEOJJOPA@BTT?3?5read_layout?3?5next?5arena?5off@
0x1C0008140: ntoskrnl_NULL_THUNK_DATA
0x1C00080C0: "__cdecl _imp_ExFreePoolWithTag" __imp_ExFreePoolWithTag
0x1C0008090: "__cdecl _imp_IoAllocateIrpEx" __imp_IoAllocateIrpEx
0x1C000B008: DriverEntry
0x1C00011B0: WPP_SF__guid_d
0x1C0006028: pfnWppTraceMessage
0x1C00029E8: ScmBttClose
0x1C00093A4: WppInitKm
0x1C00055C8: "BTT: write_layout: Invalid lba s" ??_C@_0DJ@FEONACJI@BTT?3?5write_layout?3?5Invalid?5lba?5s@
0x1C0001FB0: BttFltNsIsMemoryRangeGood
0x1C0009CD8: BttFltInvokeIoctl
0x1C0004680: memset
0x1C000816C: "__cdecl _NULL_IMPORT_DESCRIPTOR" __NULL_IMPORT_DESCRIPTOR
[JEB Decompiler by PNF Software]