Generated by JEB on 2019/08/01
PE: C:\Windows\System32\pstask.dll Base=0x180000000 SHA-256=3169020E636443E377DD776F963A6CD0D282E130A2D3ECEC31C1EEB99FF03984
PDB: pstask.pdb GUID={F1699922-7DBC-4B45-ECDDA433AAEBE9A1} Age=1
171 located named symbols:
0x18000264C: "__cdecl _raise_securityfailure" __raise_securityfailure
0x180002460: "__cdecl FindPESection" _FindPESection
0x180001A74: "private: unsigned char __cdecl CsvtaskHandler::_IncrementRetryCount(unsigned short * __ptr64) __ptr64" ?_IncrementRetryCount@CsvtaskHandler@@AEAAEPEAG@Z
0x180003A38: "__cdecl _IMPORT_DESCRIPTOR_ntdll" __IMPORT_DESCRIPTOR_ntdll
0x180004010: "__cdecl _security_cookie_complement" __security_cookie_complement
0x180001C90: "public: virtual long __cdecl CWinTaskClassFactoryT<class CsvtaskHandler,1>::LockServer(int) __ptr64" ?LockServer@?$CWinTaskClassFactoryT@VCsvtaskHandler@@$00@@UEAAJH@Z
0x180003298: "__cdecl _imp_DeviceIoControl" __imp_DeviceIoControl
0x180001F1C: "__cdecl CRT_INIT" _CRT_INIT
0x180003268: "__cdecl _imp_GetCurrentThreadId" __imp_GetCurrentThreadId
0x180003240: "__cdecl _imp_TlsGetValue" __imp_TlsGetValue
0x1800028C0: "__cdecl guard_dispatch_icall_nop" _guard_dispatch_icall_nop
0x1800032A8: "__cdecl _imp_CreateFileW" __imp_CreateFileW
0x180003208: "__cdecl _imp_TlsAlloc" __imp_TlsAlloc
0x180001600: DllGetClassObject
0x1800013F0: "public: virtual void * __ptr64 __cdecl CsvtaskHandler::`scalar deleting destructor'(unsigned int) __ptr64" ??_GCsvtaskHandler@@UEAAPEAXI@Z
0x1800045AC: "unsigned long g_iTLSChkDskThreadData" ?g_iTLSChkDskThreadData@@3KA
0x180001748: "private: void __cdecl CsvtaskHandler::FindAndScan(void) __ptr64" ?FindAndScan@CsvtaskHandler@@AEAAXXZ
0x180003360: "__cdecl _guard_dispatch_icall_fptr" __guard_dispatch_icall_fptr
0x180003320: "__cdecl _imp__wcsdup" __imp__wcsdup
0x180003278: "__cdecl _imp_GetModuleHandleExW" __imp_GetModuleHandleExW
0x180002448: "__cdecl XcptFilter" _XcptFilter
0x180003368: "__cdecl _xc_a" __xc_a
0x18000243C: "__cdecl callnewh" _callnewh
0x180003328: "__cdecl _imp_memset" __imp_memset
0x18000261F: "__cdecl initterm" _initterm
0x1800045D8: "__cdecl _dyn_tls_init_callback" __dyn_tls_init_callback
0x180003250: "__cdecl _imp_Sleep" __imp_Sleep
0x180003388: "__cdecl _xi_z" __xi_z
0x180003228: "__cdecl _imp_UnhandledExceptionFilter" __imp_UnhandledExceptionFilter
0x18000262B: "__cdecl _C_specific_handler" __C_specific_handler
0x1800032C8: "__cdecl _imp_ReleaseSRWLockExclusive" __imp_ReleaseSRWLockExclusive
0x1800013F0: "public: virtual void * __ptr64 __cdecl CsvtaskHandler::`vector deleting destructor'(unsigned int) __ptr64" ??_ECsvtaskHandler@@UEAAPEAXI@Z
0x180001130: "protected: virtual long __cdecl CWinTaskHandler::StartWorker(struct IUnknown * __ptr64,unsigned short * __ptr64) __ptr64" ?StartWorker@CWinTaskHandler@@MEAAJPEAUIUnknown@@PEAG@Z
0x180002430: malloc
0x1800031B0: "__cdecl _imp_RegCloseKey" __imp_RegCloseKey
0x18000283C: "__cdecl _GSHandlerCheckCommon" __GSHandlerCheckCommon
0x1800015E0: DllCanUnloadNow
0x180003458: "EnableVolumeCompression" ??_C@_0BI@FEEAHPO@EnableVolumeCompression?$AA@
0x180001E60: "public: virtual void * __ptr64 __cdecl CWinTaskClassFactoryT<class CsvtaskHandler,1>::`vector deleting destructor'(unsigned int) __ptr64" ??_E?$CWinTaskClassFactoryT@VCsvtaskHandler@@$00@@UEAAPEAXI@Z
0x1800045A0: "struct _RTL_SRWLOCK g_srwTLSChkDskThreadData" ?g_srwTLSChkDskThreadData@@3U_RTL_SRWLOCK@@A
0x1800031C0: "__cdecl _imp_RegSetValueExW" __imp_RegSetValueExW
0x180002454: "__cdecl amsg_exit" _amsg_exit
0x180003300: "__cdecl _imp__callnewh" __imp__callnewh
0x180003420: IID_IClassFactory
0x180003558: "__cdecl GUID_eaec7a8f_27a0_4ddc_8675_14726a01a38a" _GUID_eaec7a8f_27a0_4ddc_8675_14726a01a38a
0x180003280: "__cdecl _imp_TlsSetValue" __imp_TlsSetValue
0x180003288: "__cdecl _imp_GetCurrentProcess" __imp_GetCurrentProcess
0x180001120: "private: virtual long __cdecl CWinTaskHandler::Pause(void) __ptr64" ?Pause@CWinTaskHandler@@EEAAJXZ
0x1800045C8: "__cdecl _native_startup_lock" __native_startup_lock
0x1800015B4: DllMain
0x180003318: "__cdecl _imp_realloc" __imp_realloc
0x1800032E0: "__cdecl _imp___C_specific_handler" __imp___C_specific_handler
0x1800032B8: "__cdecl _imp_ResumeThread" __imp_ResumeThread
0x180003338: "__cdecl _imp_RtlCaptureContext" __imp_RtlCaptureContext
0x1800032D8: KERNEL32_NULL_THUNK_DATA
0x1800032C0: "__cdecl _imp_GetLastError" __imp_GetLastError
0x180001E94: "void * __ptr64 __cdecl operator new(unsigned __int64)" ??2@YAPEAX_K@Z
0x1800034F8: "NTFS" ??_C@_19ENNDBEJL@?$AAN?$AAT?$AAF?$AAS?$AA?$AA@
0x180003010: "const CWinTaskClassFactoryT<class CsvtaskHandler,1>::`vftable'" ??_7?$CWinTaskClassFactoryT@VCsvtaskHandler@@$00@@6B@
0x180004000: "__cdecl _native_dllmain_reason" __native_dllmain_reason
0x180002818: "__cdecl _GSHandlerCheck" __GSHandlerCheck
0x180001E60: "public: virtual void * __ptr64 __cdecl CWinTaskClassFactoryT<class CsvtaskHandler,1>::`scalar deleting destructor'(unsigned int) __ptr64" ??_G?$CWinTaskClassFactoryT@VCsvtaskHandler@@$00@@UEAAPEAXI@Z
0x180003A4C: "__cdecl _IMPORT_DESCRIPTOR_ADVAPI32" __IMPORT_DESCRIPTOR_ADVAPI32
0x180003260: "__cdecl _imp_GetCurrentProcessId" __imp_GetCurrentProcessId
0x1800032A0: "__cdecl _imp_WaitForSingleObject" __imp_WaitForSingleObject
0x1800045B4: "private: static long volatile CWinTaskHandler::s_cInstances" ?s_cInstances@CWinTaskHandler@@0JC
0x180002510: "__cdecl ValidateImageBase" _ValidateImageBase
0x180003410: IID_IUnknown
0x1800045B0: ?g_taskModule@@3V?$CWinTaskModuleT@VCsvtaskHandler@@$1?CLSID_pstask@@3U_GUID@@B@@A
0x180003238: "__cdecl _imp_FreeLibrary" __imp_FreeLibrary
0x180003270: "__cdecl _imp_AcquireSRWLockExclusive" __imp_AcquireSRWLockExclusive
0x180002160: "__cdecl DllMainCRTStartup" _DllMainCRTStartup
0x180001030: "protected: virtual unsigned long __cdecl CWinTaskHandler::Release(void) __ptr64" ?Release@CWinTaskHandler@@MEAAKXZ
0x1800032E8: "__cdecl _imp__initterm" __imp__initterm
0x1800045B8: "__cdecl _onexitend" __onexitend
0x1800031F0: "__cdecl _imp_CreateThread" __imp_CreateThread
0x1800031A8: "__cdecl _imp_AdjustTokenPrivileges" __imp_AdjustTokenPrivileges
0x180003358: "__cdecl _guard_check_icall_fptr" __guard_check_icall_fptr
0x180003218: "__cdecl _imp_TerminateProcess" __imp_TerminateProcess
0x180003378: "__cdecl _xi_a" __xi_a
0x180003230: "__cdecl _imp_GetTickCount" __imp_GetTickCount
0x180001DF0: "public: virtual long __cdecl CWinTaskClassFactoryT<class CsvtaskHandler,1>::QueryInterface(struct _GUID const & __ptr64,void * __ptr64 * __ptr64) __ptr64" ?QueryInterface@?$CWinTaskClassFactoryT@VCsvtaskHandler@@$00@@UEAAJAEBU_GUID@@PEAPEAX@Z
0x180001BC0: "private: void __cdecl CsvtaskHandler::_ClearRetryCount(unsigned short * __ptr64) __ptr64" ?_ClearRetryCount@CsvtaskHandler@@AEAAXPEAG@Z
0x180001070: "protected: virtual long __cdecl CWinTaskHandler::QueryInterface(struct _GUID const & __ptr64,void * __ptr64 * __ptr64) __ptr64" ?QueryInterface@CWinTaskHandler@@MEAAJAEBU_GUID@@PEAPEAX@Z
0x1800045E0: "__cdecl pRawDllMain" _pRawDllMain
0x180001100: "protected: virtual long __cdecl CWinTaskHandler::Stop(long * __ptr64) __ptr64" ?Stop@CWinTaskHandler@@MEAAJPEAJ@Z
0x180001120: DllUnregisterServer
0x180001ED4: "void __cdecl operator delete(void * __ptr64)" ??3@YAXPEAX@Z
0x180002400: "__cdecl _security_check_cookie" __security_check_cookie
0x180003370: "__cdecl _xc_z" __xc_z
0x180003210: "__cdecl _imp_GetProcAddress" __imp_GetProcAddress
0x180001010: "protected: virtual unsigned long __cdecl CWinTaskHandler::AddRef(void) __ptr64" ?AddRef@CWinTaskHandler@@MEAAKXZ
0x180001360: "private: static unsigned long __cdecl CWinTaskHandler::WorkerThreadProc(void * __ptr64)" ?WorkerThreadProc@CWinTaskHandler@@CAKPEAX@Z
0x1800032D0: "__cdecl _imp_GetSystemTimeAsFileTime" __imp_GetSystemTimeAsFileTime
0x1800034B0: "\\.\Ntfs" ??_C@_1BC@EPIIAPPF@?$AA?2?$AA?2?$AA?4?$AA?2?$AAN?$AAt?$AAf?$AAs?$AA?$AA@
0x180003390: "__cdecl _guard_fids_table" __guard_fids_table
0x180001478: "unsigned char __cdecl LoadFMIFS(struct FMIFSLib * __ptr64)" ?LoadFMIFS@@YAEPEAUFMIFSLib@@@Z
0x180003330: msvcrt_NULL_THUNK_DATA
0x1800030A0: "__cdecl load_config_used" _load_config_used
0x180003040: "const CsvtaskHandler::`vftable'" ??_7CsvtaskHandler@@6B@
0x180003448: "ChkdskEx" ??_C@_08CENBGMAG@ChkdskEx?$AA@
0x180001D90: "public: virtual unsigned long __cdecl CWinTaskClassFactoryT<class CsvtaskHandler,1>::Release(void) __ptr64" ?Release@?$CWinTaskClassFactoryT@VCsvtaskHandler@@$00@@UEAAKXZ
0x180001DD0: "public: virtual unsigned long __cdecl CWinTaskClassFactoryT<class CsvtaskHandler,1>::AddRef(void) __ptr64" ?AddRef@?$CWinTaskClassFactoryT@VCsvtaskHandler@@$00@@UEAAKXZ
0x180001190: "protected: virtual long __cdecl CWinTaskHandler::StopWorker(long * __ptr64) __ptr64" ?StopWorker@CWinTaskHandler@@MEAAJPEAJ@Z
0x1800032F0: "__cdecl _imp__amsg_exit" __imp__amsg_exit
0x180003290: "__cdecl _imp_DisableThreadLibraryCalls" __imp_DisableThreadLibraryCalls
0x1800016D0: "private: static unsigned char __cdecl CsvtaskHandler::_FmifsCallback(enum _FMIFS_PACKET_TYPE,unsigned long,void * __ptr64)" ?_FmifsCallback@CsvtaskHandler@@CAEW4_FMIFS_PACKET_TYPE@@KPEAX@Z
0x180003340: "__cdecl _imp_RtlLookupFunctionEntry" __imp_RtlLookupFunctionEntry
0x180003258: "__cdecl _imp_QueryPerformanceCounter" __imp_QueryPerformanceCounter
0x180002424: free
0x1800045A8: "long g_cTLSChkDskThreadData" ?g_cTLSChkDskThreadData@@3JA
0x180003348: "__cdecl _imp_RtlVirtualUnwind" __imp_RtlVirtualUnwind
0x180002640: "__cdecl guard_check_icall_nop" _guard_check_icall_nop
0x180001120: "private: virtual long __cdecl CWinTaskHandler::Resume(void) __ptr64" ?Resume@CWinTaskHandler@@EEAAJXZ
0x1800032F8: "__cdecl _imp__XcptFilter" __imp__XcptFilter
0x180003350: ntdll_NULL_THUNK_DATA
0x1800010E0: "protected: virtual long __cdecl CWinTaskHandler::Start(struct IUnknown * __ptr64,unsigned short * __ptr64) __ptr64" ?Start@CWinTaskHandler@@MEAAJPEAUIUnknown@@PEAG@Z
0x180001A50: "private: virtual long __cdecl CsvtaskHandler::Worker(void) __ptr64" ?Worker@CsvtaskHandler@@EEAAJXZ
0x180004008: "__cdecl _security_cookie" __security_cookie
0x1800031D8: "__cdecl _imp_RegQueryValueExW" __imp_RegQueryValueExW
0x180003548: CLSID_pstask
0x180003508: "Software\Microsoft\Chkdsk\Scan" ??_C@_1DO@GDOKIHEM@?$AAS?$AAo?$AAf?$AAt?$AAw?$AAa?$AAr?$AAe?$AA?2?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAC?$AAh?$AAk?$AAd?$AAs?$AAk?$AA?2?$AAS?$AAc?$AAa?$AAn?$AA?$AA@
0x180003200: "__cdecl _imp_CloseHandle" __imp_CloseHandle
0x180003568: IID_ITaskHandler
0x1800031F8: "__cdecl _imp_LoadLibraryW" __imp_LoadLibraryW
0x1800031B8: "__cdecl _imp_RegCreateKeyExW" __imp_RegCreateKeyExW
0x1800045C0: "__cdecl _onexitbegin" __onexitbegin
0x180001208: "private: long __cdecl CWinTaskHandler::CreateWorkerThread(struct IUnknown * __ptr64) __ptr64" ?CreateWorkerThread@CWinTaskHandler@@AEAAJPEAUIUnknown@@@Z
0x180003220: "__cdecl _imp_SetUnhandledExceptionFilter" __imp_SetUnhandledExceptionFilter
0x1800032B0: "__cdecl _imp_FreeLibraryAndExitThread" __imp_FreeLibraryAndExitThread
0x180003A60: "__cdecl _IMPORT_DESCRIPTOR_KERNEL32" __IMPORT_DESCRIPTOR_KERNEL32
0x180003498: "QueryCorruptionState" ??_C@_0BF@PHDGHFJJ@QueryCorruptionState?$AA@
0x1800031D0: "__cdecl _imp_RegOpenKeyExW" __imp_RegOpenKeyExW
0x180002544: "__cdecl _security_init_cookie" __security_init_cookie
0x180003470: "FormatEx2" ??_C@_09NMLNEKLF@FormatEx2?$AA@
0x180003A24: "__cdecl _IMPORT_DESCRIPTOR_msvcrt" __IMPORT_DESCRIPTOR_msvcrt
0x180003480: "GetDefaultFileSystem" ??_C@_0BF@HEECBCO@GetDefaultFileSystem?$AA@
0x180003308: "__cdecl _imp_malloc" __imp_malloc
0x1800031E8: ADVAPI32_NULL_THUNK_DATA
0x1800031E0: "__cdecl _imp_LookupPrivilegeValueW" __imp_LookupPrivilegeValueW
0x180002690: "__cdecl _report_gsfailure" __report_gsfailure
0x1800034C8: "SeManageVolumePrivilege" ??_C@_1DA@LIHDNJND@?$AAS?$AAe?$AAM?$AAa?$AAn?$AAa?$AAg?$AAe?$AAV?$AAo?$AAl?$AAu?$AAm?$AAe?$AAP?$AAr?$AAi?$AAv?$AAi?$AAl?$AAe?$AAg?$AAe?$AA?$AA@
0x1800045D0: "__cdecl _native_startup_state" __native_startup_state
0x180001CB0: "public: virtual long __cdecl CWinTaskClassFactoryT<class CsvtaskHandler,1>::CreateInstance(struct IUnknown * __ptr64,struct _GUID const & __ptr64,void * __ptr64 * __ptr64) __ptr64" ?CreateInstance@?$CWinTaskClassFactoryT@VCsvtaskHandler@@$00@@UEAAJPEAUIUnknown@@AEBU_GUID@@PEAPEAX@Z
0x180001120: DllRegisterServer
0x180003430: "FMIFS.DLL" ??_C@_1BE@FMFHPIED@?$AAF?$AAM?$AAI?$AAF?$AAS?$AA?4?$AAD?$AAL?$AAL?$AA?$AA@
0x180003310: "__cdecl _imp_free" __imp_free
0x1800024B0: "__cdecl IsNonwritableInCurrentImage" _IsNonwritableInCurrentImage
0x180003248: "__cdecl _imp_TlsFree" __imp_TlsFree
0x1800031C8: "__cdecl _imp_OpenProcessToken" __imp_OpenProcessToken
0x18000289D: memset
0x180003A74: "__cdecl _NULL_IMPORT_DESCRIPTOR" __NULL_IMPORT_DESCRIPTOR
[JEB Decompiler by PNF Software]