Generated by JEB on 2019/08/01

PE: C:\Windows\System32\tbs.dll Base=0x180000000 SHA-256=455A99A197360E5C80D56921FE127127CEB870DB8CBF52E28B274B472B6CF58C
PDB: tbs.pdb GUID={926FA27E-24B2-B9EA-1499A8E85DBC52BB} Age=1

298 located named symbols:
0x180007268: "__cdecl _imp_EventSetInformation" __imp_EventSetInformation
0x18000271C: "__cdecl _raise_securityfailure" __raise_securityfailure
0x180007150: api-ms-win-core-file-l1-1-0_NULL_THUNK_DATA
0x180007278: "__cdecl _imp_EventRegister" __imp_EventRegister
0x180002520: "__cdecl FindPESection" _FindPESection
0x180008EC4: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-sysinfo-l1-2-0" __IMPORT_DESCRIPTOR_api-ms-win-core-sysinfo-l1-2-0
0x1800072D0: "__cdecl _imp_StackWalk64" __imp_StackWalk64
0x180006C38: GetModuleInfoFromAddress
0x180007E38: "SHA384" ??_C@_1O@KOBLHLEG@?$AAS?$AAH?$AAA?$AA3?$AA8?$AA4?$AA?$AA@
0x180008DAC: "__cdecl _IMPORT_DESCRIPTOR_ntdll" __IMPORT_DESCRIPTOR_ntdll
0x1800075C8: "WBCL" ??_C@_19HEALFAGP@?$AAW?$AAB?$AAC?$AAL?$AA?$AA@
0x18000A0A0: "__cdecl _security_cookie_complement" __security_cookie_complement
0x180001FDC: "__cdecl CRT_INIT" _CRT_INIT
0x180007198: "__cdecl _imp_GetCurrentThreadId" __imp_GetCurrentThreadId
0x180006538: WbclApiGetCurrentElement
0x1800073E0: "__cdecl _imp_RtlInitUnicodeString" __imp_RtlInitUnicodeString
0x1800029A0: "__cdecl guard_dispatch_icall_nop" _guard_dispatch_icall_nop
0x180007140: "__cdecl _imp_CreateFileW" __imp_CreateFileW
0x180007238: "__cdecl _imp_GetSystemWindowsDirectoryW" __imp_GetSystemWindowsDirectoryW
0x180007A68: "%s\%010u-%010u.log" ??_C@_1CG@OENHLJBE@?$AA?$CF?$AAs?$AA?2?$AA?$CF?$AA0?$AA1?$AA0?$AAu?$AA?9?$AA?$CF?$AA0?$AA1?$AA0?$AAu?$AA?4?$AAl?$AAo?$AAg?$AA?$AA@
0x180007760: "__cdecl TraceLoggingMetadata" _TraceLoggingMetadata
0x180007AD0: "System\CurrentControlSet\Service" ??_C@_1GA@NGBBHFHP@?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AA?2?$AAC?$AAu?$AAr?$AAr?$AAe?$AAn?$AAt?$AAC?$AAo?$AAn?$AAt?$AAr?$AAo?$AAl?$AAS?$AAe?$AAt?$AA?2?$AAS?$AAe?$AAr?$AAv?$AAi?$AAc?$AAe@
0x180007310: "__cdecl _imp_sprintf_s" __imp_sprintf_s
0x180008DE8: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-file-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-file-l1-1-0
0x1800072C8: bcrypt_NULL_THUNK_DATA
0x180007940: "System\CurrentControlSet\service" ??_C@_1EM@KDJICPAM@?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AA?2?$AAC?$AAu?$AAr?$AAr?$AAe?$AAn?$AAt?$AAC?$AAo?$AAn?$AAt?$AAr?$AAo?$AAl?$AAS?$AAe?$AAt?$AA?2?$AAs?$AAe?$AAr?$AAv?$AAi?$AAc?$AAe@
0x180007A10: "TpmDriverLogPath" ??_C@_1CC@EADICFAO@?$AAT?$AAp?$AAm?$AAD?$AAr?$AAi?$AAv?$AAe?$AAr?$AAL?$AAo?$AAg?$AAP?$AAa?$AAt?$AAh?$AA?$AA@
0x180001F20: Tbsip_Context_Close
0x1800072F8: "__cdecl _imp_SymGetModuleInfo64" __imp_SymGetModuleInfo64
0x180007200: "__cdecl _imp_SetEvent" __imp_SetEvent
0x180004EA0: "__cdecl TlgWrite" _TlgWrite
0x180007400: "__cdecl _guard_dispatch_icall_fptr" __guard_dispatch_icall_fptr
0x180006250: "unsigned char * __ptr64 __cdecl WbclGetCurrentElementDigest(struct _WBCL_Iterator * __ptr64)" ?WbclGetCurrentElementDigest@@YAPEAEPEAU_WBCL_Iterator@@@Z
0x180007CB8: "OwnerAuthFull" ??_C@_1BM@MAAJMDNP@?$AAO?$AAw?$AAn?$AAe?$AAr?$AAA?$AAu?$AAt?$AAh?$AAF?$AAu?$AAl?$AAl?$AA?$AA@
0x180007C30: "System\CurrentControlSet\Service" ??_C@_1FO@MJDBBJAB@?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AA?2?$AAC?$AAu?$AAr?$AAr?$AAe?$AAn?$AAt?$AAC?$AAo?$AAn?$AAt?$AAr?$AAo?$AAl?$AAS?$AAe?$AAt?$AA?2?$AAS?$AAe?$AAr?$AAv?$AAi?$AAc?$AAe@
0x180002508: "__cdecl XcptFilter" _XcptFilter
0x180004260: Tbsi_Get_OwnerAuth
0x180005CD0: Tbsi_FilterLog
0x180007408: "__cdecl _xc_a" __xc_a
0x180001460: Tbsi_Get_TCG_Log_Ex
0x180004E70: "__cdecl TlgKeywordOn" _TlgKeywordOn
0x1800072A0: "__cdecl _imp_BCryptCreateHash" __imp_BCryptCreateHash
0x180003BD8: "unsigned int __cdecl TbsGetCurrentLogIfResumed(int,unsigned char * __ptr64,unsigned int,unsigned int * __ptr64)" ?TbsGetCurrentLogIfResumed@@YAIHPEAEIPEAI@Z
0x1800019B0: "unsigned int __cdecl Tbsip_Submit_Command_Internal(void * __ptr64,unsigned int,unsigned int,unsigned char const * __ptr64,unsigned int,unsigned char * __ptr64,unsigned int * __ptr64,unsigned int)" ?Tbsip_Submit_Command_Internal@@YAIPEAXIIPEBEIPEAEPEAII@Z
0x180007180: api-ms-win-core-heap-l1-1-0_NULL_THUNK_DATA
0x180001290: GetDeviceIDWithTimeout
0x180007990: "TpmRegDriverTpm" ??_C@_1CA@FLCJILGM@?$AAT?$AAp?$AAm?$AAR?$AAe?$AAg?$AAD?$AAr?$AAi?$AAv?$AAe?$AAr?$AAT?$AAp?$AAm?$AA?$AA@
0x1800073C0: "__cdecl _imp_RtlGetPersistedStateLocation" __imp_RtlGetPersistedStateLocation
0x1800078F8: "TpmLockedOut" ??_C@_1BK@JBEIOA@?$AAT?$AAp?$AAm?$AAL?$AAo?$AAc?$AAk?$AAe?$AAd?$AAO?$AAu?$AAt?$AA?$AA@
0x1800024F0: "__cdecl callnewh" _callnewh
0x1800074BC: "__cdecl _guard_iat_table" __guard_iat_table
0x180002979: memcpy
0x180008EB0: "__cdecl _IMPORT_DESCRIPTOR_imagehlp" __IMPORT_DESCRIPTOR_imagehlp
0x1800067E0: WbclApiMoveToNextElement
0x180007270: "__cdecl _imp_EventWriteTransfer" __imp_EventWriteTransfer
0x180007308: "__cdecl _imp_memset" __imp_memset
0x180007208: "__cdecl _imp_CreateEventW" __imp_CreateEventW
0x1800026EC: "__cdecl initterm" _initterm
0x180007388: "__cdecl _imp_NtWaitForSingleObject" __imp_NtWaitForSingleObject
0x180008DD4: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-sysinfo-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-sysinfo-l1-1-0
0x18000A670: "__cdecl _dyn_tls_init_callback" __dyn_tls_init_callback
0x180007220: "__cdecl _imp_Sleep" __imp_Sleep
0x180007428: "__cdecl _xi_z" __xi_z
0x180007120: "__cdecl _imp_UnhandledExceptionFilter" __imp_UnhandledExceptionFilter
0x180006B2C: FetchStackInfo
0x1800026F8: "__cdecl _C_specific_handler" __C_specific_handler
0x1800078A8: "WBCLDrtm" ??_C@_1BC@GMFALMFC@?$AAW?$AAB?$AAC?$AAL?$AAD?$AAr?$AAt?$AAm?$AA?$AA@
0x180007178: "__cdecl _imp_HeapFree" __imp_HeapFree
0x180007C90: "\Registry\Machine\" ??_C@_1CG@ECHCOIBH@?$AA?2?$AAR?$AAe?$AAg?$AAi?$AAs?$AAt?$AAr?$AAy?$AA?2?$AAM?$AAa?$AAc?$AAh?$AAi?$AAn?$AAe?$AA?2?$AA?$AA@
0x180007F20: "Error Fetching Info: 0x%x" ??_C@_0BK@KJOLFFJ@Error?5Fetching?5Info?3?50x?$CFx?$AA@
0x1800024E4: malloc
0x180007160: api-ms-win-core-handle-l1-1-0_NULL_THUNK_DATA
0x180001730: Tbsi_Context_Create
0x18000290C: "__cdecl _GSHandlerCheckCommon" __GSHandlerCheckCommon
0x180007398: "__cdecl _imp_NtCreateEvent" __imp_NtCreateEvent
0x180001010: GetDeviceIDString
0x1800064A4: "long __cdecl WbclGetCurrentElementSize(struct _WBCL_Iterator * __ptr64,unsigned int * __ptr64)" ?WbclGetCurrentElementSize@@YAJPEAU_WBCL_Iterator@@PEAI@Z
0x180002514: "__cdecl amsg_exit" _amsg_exit
0x180007350: "__cdecl _imp__callnewh" __imp__callnewh
0x180006214: "unsigned int __cdecl WbclGetCurrentElementDataSize(struct _WBCL_Iterator * __ptr64)" ?WbclGetCurrentElementDataSize@@YAIPEAU_WBCL_Iterator@@@Z
0x180008E4C: "__cdecl _IMPORT_DESCRIPTOR_bcrypt" __IMPORT_DESCRIPTOR_bcrypt
0x1800079B0: "OsBootCount" ??_C@_1BI@LEEBACAP@?$AAO?$AAs?$AAB?$AAo?$AAo?$AAt?$AAC?$AAo?$AAu?$AAn?$AAt?$AA?$AA@
0x180007860: WIN32TPM_Provider
0x1800071D0: api-ms-win-core-registry-l1-1-0_NULL_THUNK_DATA
0x180007130: api-ms-win-core-errorhandling-l1-1-0_NULL_THUNK_DATA
0x180003CC8: "unsigned int __cdecl Tbsi_Get_TCG_Logs_Internal(int,unsigned int,unsigned int * __ptr64,unsigned char * __ptr64,unsigned int,unsigned int * __ptr64,unsigned int)" ?Tbsi_Get_TCG_Logs_Internal@@YAIHIPEAIPEAEI0I@Z
0x1800073E8: "__cdecl _imp_NtQueryInformationFile" __imp_NtQueryInformationFile
0x1800071A0: "__cdecl _imp_GetCurrentProcess" __imp_GetCurrentProcess
0x180001DB0: Tbsi_GetDeviceInfo
0x18000A660: "__cdecl _native_startup_lock" __native_startup_lock
0x180007298: "__cdecl _imp_BCryptHashData" __imp_BCryptHashData
0x1800026E0: DllMain
0x1800072E0: "__cdecl _imp_SymGetModuleBase64" __imp_SymGetModuleBase64
0x180007328: "__cdecl _imp___C_specific_handler" __imp___C_specific_handler
0x1800071E8: "__cdecl _imp_RtlCaptureContext" __imp_RtlCaptureContext
0x180008D98: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-eventing-provider-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-eventing-provider-l1-1-0
0x180006504: "unsigned int __cdecl WbclGetDigestSizeUnchecked(struct _WBCL_Iterator * __ptr64,unsigned short)" ?WbclGetDigestSizeUnchecked@@YAIPEAU_WBCL_Iterator@@G@Z
0x180007118: "__cdecl _imp_GetLastError" __imp_GetLastError
0x180001F50: "void * __ptr64 __cdecl operator new(unsigned __int64)" ??2@YAPEAX_K@Z
0x180007288: api-ms-win-eventing-provider-l1-1-0_NULL_THUNK_DATA
0x18000A090: "__cdecl _native_dllmain_reason" __native_dllmain_reason
0x1800028E8: "__cdecl _GSHandlerCheck" __GSHandlerCheck
0x180007318: "__cdecl _imp_memcmp" __imp_memcmp
0x18000382C: "long __cdecl RtlStringCchPrintfW(unsigned short * __ptr64,unsigned __int64,unsigned short const * __ptr64,...)" ?RtlStringCchPrintfW@@YAJPEAG_KPEBGZZ
0x180007390: "__cdecl _imp_NtDeviceIoControlFile" __imp_NtDeviceIoControlFile
0x1800014B0: "long __cdecl TbsGetLog(int,unsigned char * __ptr64,unsigned int,unsigned int * __ptr64)" ?TbsGetLog@@YAJHPEAEIPEAI@Z
0x1800072B8: "__cdecl _imp_BCryptCloseAlgorithmProvider" __imp_BCryptCloseAlgorithmProvider
0x180007E18: "SHA1" ??_C@_19DILNDFJH@?$AAS?$AAH?$AAA?$AA1?$AA?$AA@
0x180007190: "__cdecl _imp_GetCurrentProcessId" __imp_GetCurrentProcessId
0x180007210: "__cdecl _imp_WaitForSingleObject" __imp_WaitForSingleObject
0x1800025D0: "__cdecl ValidateImageBase" _ValidateImageBase
0x1800075A8: "WBCLTrustPoint" ??_C@_1BO@PAMBDDGE@?$AAW?$AAB?$AAC?$AAL?$AAT?$AAr?$AAu?$AAs?$AAt?$AAP?$AAo?$AAi?$AAn?$AAt?$AA?$AA@
0x180004B40: Tbsip_Submit_Command_NonBlocking
0x1800079E0: "%s\Logs\MeasuredBoot" ??_C@_1CK@HONEAOAO@?$AA?$CF?$AAs?$AA?2?$AAL?$AAo?$AAg?$AAs?$AA?2?$AAM?$AAe?$AAa?$AAs?$AAu?$AAr?$AAe?$AAd?$AAB?$AAo?$AAo?$AAt?$AA?$AA@
0x180007D28: "OwnerAuthUser" ??_C@_1BM@FNDGIBNH@?$AAO?$AAw?$AAn?$AAe?$AAr?$AAA?$AAu?$AAt?$AAh?$AAU?$AAs?$AAe?$AAr?$AA?$AA@
0x180007A38: "%s\%010u-%010u-DRTM.log" ??_C@_1DA@NMKBNFMK@?$AA?$CF?$AAs?$AA?2?$AA?$CF?$AA0?$AA1?$AA0?$AAu?$AA?9?$AA?$CF?$AA0?$AA1?$AA0?$AAu?$AA?9?$AAD?$AAR?$AAT?$AAM?$AA?4?$AAl?$AAo?$AAg?$AA?$AA@
0x180007168: "__cdecl _imp_HeapAlloc" __imp_HeapAlloc
0x180002220: "__cdecl DllMainCRTStartup" _DllMainCRTStartup
0x180007330: "__cdecl _imp__initterm" __imp__initterm
0x180004A30: Tbsi_Get_TCG_Log
0x18000634C: "long __cdecl WbclGetCurrentElementDigestSize(struct _WBCL_Iterator * __ptr64,unsigned int * __ptr64)" ?WbclGetCurrentElementDigestSize@@YAJPEAU_WBCL_Iterator@@PEAI@Z
0x180003768: "unsigned char __cdecl IsDrtmBoot(void)" ?IsDrtmBoot@@YAEXZ
0x180003B58: "unsigned int __cdecl TbsGetCurrentLog(int,unsigned char * __ptr64,unsigned int,unsigned int * __ptr64)" ?TbsGetCurrentLog@@YAIHPEAEIPEAI@Z
0x180008DC0: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-registry-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-registry-l1-1-0
0x18000A650: "__cdecl _onexitend" __onexitend
0x1800073A8: "__cdecl _imp_NtCreateFile" __imp_NtCreateFile
0x1800073F8: "__cdecl _guard_check_icall_fptr" __guard_check_icall_fptr
0x1800072A8: "__cdecl _imp_BCryptGetProperty" __imp_BCryptGetProperty
0x180007CF8: "OwnerAuthEndorsement" ??_C@_1CK@HMMGFOOB@?$AAO?$AAw?$AAn?$AAe?$AAr?$AAA?$AAu?$AAt?$AAh?$AAE?$AAn?$AAd?$AAo?$AAr?$AAs?$AAe?$AAm?$AAe?$AAn?$AAt?$AA?$AA@
0x1800071A8: "__cdecl _imp_TerminateProcess" __imp_TerminateProcess
0x1800073A0: "__cdecl _imp_RtlNtStatusToDosError" __imp_RtlNtStatusToDosError
0x1800072C0: "__cdecl _imp_BCryptDestroyHash" __imp_BCryptDestroyHash
0x180007888: WNF_TPM_DEVICEID_STATE
0x180007250: api-ms-win-core-sysinfo-l1-1-0_NULL_THUNK_DATA
0x180007418: "__cdecl _xi_a" __xi_a
0x180007260: api-ms-win-core-sysinfo-l1-2-0_NULL_THUNK_DATA
0x180007258: "__cdecl _imp_GetNativeSystemInfo" __imp_GetNativeSystemInfo
0x180007230: "__cdecl _imp_GetTickCount" __imp_GetTickCount
0x1800072D8: "__cdecl _imp_SymCleanup" __imp_SymCleanup
0x180004C40: Tbsip_TestMorBit
0x1800073B0: "__cdecl _imp_RtlQueryWnfStateData" __imp_RtlQueryWnfStateData
0x180007378: "__cdecl _imp_RtlSubscribeWnfStateChangeNotification" __imp_RtlSubscribeWnfStateChangeNotification
0x180005C2C: McGenEventWrite
0x180007E10: "" ??_C@_11LOCGONAA@?$AA?$AA@
0x180008E9C: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-processthreads-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-processthreads-l1-1-0
0x180004DF0: "__cdecl TlgEnableCallback" _TlgEnableCallback
0x18000A678: "__cdecl pRawDllMain" _pRawDllMain
0x180001F90: "void __cdecl operator delete(void * __ptr64)" ??3@YAXPEAX@Z
0x180004B80: Tbsip_TestInterruptInformation
0x1800041B0: Tbsi_Create_Windows_Key
0x1800037BC: "long __cdecl RtlStringCbCatW(unsigned short * __ptr64,unsigned __int64,unsigned short const * __ptr64)" ?RtlStringCbCatW@@YAJPEAG_KPEBG@Z
0x180004FD0: "long __cdecl Tbsi_ComputeSoftPCRs(unsigned char * __ptr64,unsigned int,unsigned short,unsigned char * __ptr64,unsigned int,unsigned int * __ptr64)" ?Tbsi_ComputeSoftPCRs@@YAJPEAEIG0IPEAI@Z
0x180008E24: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-heap-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-heap-l1-1-0
0x1800073D0: "__cdecl _imp_NtQueryValueKey" __imp_NtQueryValueKey
0x1800024C0: "__cdecl _security_check_cookie" __security_check_cookie
0x180007410: "__cdecl _xc_z" __xc_z
0x1800071B0: api-ms-win-core-processthreads-l1-1-0_NULL_THUNK_DATA
0x1800061D0: "unsigned char * __ptr64 __cdecl WbclGetCurrentElementData(struct _WBCL_Iterator * __ptr64)" ?WbclGetCurrentElementData@@YAPEAEPEAU_WBCL_Iterator@@@Z
0x1800074F0: "TpmRegDriverPersistedData" ??_C@_1DE@PNDCLOFA@?$AAT?$AAp?$AAm?$AAR?$AAe?$AAg?$AAD?$AAr?$AAi?$AAv?$AAe?$AAr?$AAP?$AAe?$AAr?$AAs?$AAi?$AAs?$AAt?$AAe?$AAd?$AAD?$AAa?$AAt?$AAa?$AA?$AA@
0x1800065C0: WbclApiInitIterator
0x180004D9C: "__cdecl TlgCreateWsz" _TlgCreateWsz
0x180007855: "__cdecl TraceLoggingMetadataEnd" _TraceLoggingMetadataEnd
0x1800068C4: CaptureStackTrace
0x180007248: "__cdecl _imp_GetSystemTimeAsFileTime" __imp_GetSystemTimeAsFileTime
0x180003C90: "unsigned int __cdecl Tbsi_Get_TCG_Logs(unsigned int,unsigned int * __ptr64,unsigned char * __ptr64,unsigned int,unsigned int * __ptr64,unsigned int)" ?Tbsi_Get_TCG_Logs@@YAIIPEAIPEAEI0I@Z
0x18000A040: WIN32TPM_Provider_Context
0x180007170: "__cdecl _imp_GetProcessHeap" __imp_GetProcessHeap
0x180004A70: Tbsi_Revoke_Attestation
0x180004D00: TraceLoggingRegisterEx
0x180007300: imagehlp_NULL_THUNK_DATA
0x1800071F8: api-ms-win-core-rtlsupport-l1-1-0_NULL_THUNK_DATA
0x1800074D0: "WindowsAIKHash" ??_C@_1BO@LKPJMIDA@?$AAW?$AAi?$AAn?$AAd?$AAo?$AAw?$AAs?$AAA?$AAI?$AAK?$AAH?$AAa?$AAs?$AAh?$AA?$AA@
0x18000A0B0: "char * TCG_EfiSpecIdEventStruct_Signature_03" ?TCG_EfiSpecIdEventStruct_Signature_03@@3PADA
0x180008E38: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-rtlsupport-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-rtlsupport-l1-1-0
0x180007F18: "%s+0x%x" ??_C@_07ENGKDEOH@?$CFs?$CL0x?$CFx?$AA@
0x1800071C0: api-ms-win-core-profile-l1-1-0_NULL_THUNK_DATA
0x180007430: "__cdecl _guard_fids_table" __guard_fids_table
0x180007368: msvcrt_NULL_THUNK_DATA
0x180007010: "__cdecl load_config_used" _load_config_used
0x1800079C8: "WBCLPath" ??_C@_1BC@IHPPFLDK@?$AAW?$AAB?$AAC?$AAL?$AAP?$AAa?$AAt?$AAh?$AA?$AA@
0x180005AA0: GetDeviceID
0x180005BFC: McGenEventUnregister
0x180007338: "__cdecl _imp__amsg_exit" __imp__amsg_exit
0x180007530: "System\CurrentControlSet\Service" ??_C@_1FE@EKJFIMAI@?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AA?2?$AAC?$AAu?$AAr?$AAr?$AAe?$AAn?$AAt?$AAC?$AAo?$AAn?$AAt?$AAr?$AAo?$AAl?$AAS?$AAe?$AAt?$AA?2?$AAS?$AAe?$AAr?$AAv?$AAi?$AAc?$AAe@
0x1800072B0: "__cdecl _imp_BCryptOpenAlgorithmProvider" __imp_BCryptOpenAlgorithmProvider
0x1800073C8: "__cdecl _imp_NtClose" __imp_NtClose
0x180007890: Microsoft_Windows_TPM_WMIKeywords
0x18000A0C0: "char * TCG_EfiSpecIdEventStruct_Signature_02" ?TCG_EfiSpecIdEventStruct_Signature_02@@3PADA
0x180004F68: "void __cdecl TpmFree(void * __ptr64)" ?TpmFree@@YAXPEAX@Z
0x1800071E0: "__cdecl _imp_RtlLookupFunctionEntry" __imp_RtlLookupFunctionEntry
0x1800071B8: "__cdecl _imp_QueryPerformanceCounter" __imp_QueryPerformanceCounter
0x180007BF0: "TpmRegDriverPersistedDataUser" ??_C@_1DM@DIJHNIPA@?$AAT?$AAp?$AAm?$AAR?$AAe?$AAg?$AAD?$AAr?$AAi?$AAv?$AAe?$AAr?$AAP?$AAe?$AAr?$AAs?$AAi?$AAs?$AAt?$AAe?$AAd?$AAD?$AAa?$AAt?$AAa?$AAU?$AAs?$AAe?$AAr?$AA?$AA@
0x180007B80: "System\CurrentControlSet\Service" ??_C@_1GM@HDEEAKNB@?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AA?2?$AAC?$AAu?$AAr?$AAr?$AAe?$AAn?$AAt?$AAC?$AAo?$AAn?$AAt?$AAr?$AAo?$AAl?$AAS?$AAe?$AAt?$AA?2?$AAS?$AAe?$AAr?$AAv?$AAi?$AAc?$AAe@
0x1800024FC: free
0x1800072F0: "__cdecl _imp_SymFunctionTableAccess64" __imp_SymFunctionTableAccess64
0x1800016B0: Tbsi_Physical_Presence_Command
0x1800071D8: "__cdecl _imp_RtlVirtualUnwind" __imp_RtlVirtualUnwind
0x180005A40: "long __cdecl WnfDeviceIDCallback(struct _WNF_STATE_NAME,unsigned long,struct _WNF_TYPE_ID * __ptr64,void * __ptr64,void const * __ptr64,unsigned long)" ?WnfDeviceIDCallback@@YAJU_WNF_STATE_NAME@@KPEAU_WNF_TYPE_ID@@PEAXPEBXK@Z
0x180007918: "TpmInFailureMode" ??_C@_1CC@INDJINOE@?$AAT?$AAp?$AAm?$AAI?$AAn?$AAF?$AAa?$AAi?$AAl?$AAu?$AAr?$AAe?$AAM?$AAo?$AAd?$AAe?$AA?$AA@
0x180002710: "__cdecl guard_check_icall_nop" _guard_check_icall_nop
0x18000296D: memcmp
0x180007D68: "StorageOwnerAuth" ??_C@_1CC@HLIHFHFL@?$AAS?$AAt?$AAo?$AAr?$AAa?$AAg?$AAe?$AAO?$AAw?$AAn?$AAe?$AAr?$AAA?$AAu?$AAt?$AAh?$AA?$AA@
0x180005370: "long __cdecl Tbsi_Create_Attestation_From_Log(unsigned char * __ptr64,unsigned int,unsigned short * __ptr64,unsigned short * __ptr64 * __ptr64,unsigned char * __ptr64,unsigned char * __ptr64,unsigned int,unsigned int * __ptr64,unsigned int)" ?Tbsi_Create_Attestation_From_Log@@YAJPEAEIPEAGPEAPEAG00IPEAII@Z
0x180008E10: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-handle-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-handle-l1-1-0
0x180007370: "__cdecl _imp_RtlUnsubscribeWnfStateChangeNotification" __imp_RtlUnsubscribeWnfStateChangeNotification
0x180004F40: "unsigned char * __ptr64 __cdecl TpmAlloc(unsigned long)" ?TpmAlloc@@YAPEAEK@Z
0x18000A680: "__cdecl _@@_PchSym_@00@KxulyqvxgPillgKxulmvxlivUyzhvUmthxyUgknUwooUfnUlyquivUznwGEUkxsOlyq@tbs" __@@_PchSym_@00@KxulyqvxgPillgKxulmvxlivUyzhvUmthxyUgknUwooUfnUlyquivUznwGEUkxsOlyq@tbs
0x180007380: "__cdecl _imp_RtlPublishWnfStateData" __imp_RtlPublishWnfStateData
0x180006A54: ExtractStackString
0x180007340: "__cdecl _imp__XcptFilter" __imp__XcptFilter
0x1800073F0: ntdll_NULL_THUNK_DATA
0x180007320: "__cdecl _imp_memcpy" __imp_memcpy
0x180007F10: "%s_eol_" ??_C@_07EFGKFAIH@?$CFs_eol_?$AA@
0x180007D48: "EndorsementAuth" ??_C@_1CA@KEAONADF@?$AAE?$AAn?$AAd?$AAo?$AAr?$AAs?$AAe?$AAm?$AAe?$AAn?$AAt?$AAA?$AAu?$AAt?$AAh?$AA?$AA@
0x180004F94: "void __cdecl TpmSecureFree(void * __ptr64,unsigned long)" ?TpmSecureFree@@YAXPEAXK@Z
0x180004DE0: "__cdecl TlgDefineProvider_annotation__Tlgg_hTpmTBSTraceLoggingProviderProv" _TlgDefineProvider_annotation__Tlgg_hTpmTBSTraceLoggingProviderProv
0x180008E60: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-synch-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-synch-l1-1-0
0x18000A098: "__cdecl _security_cookie" __security_cookie
0x180005FB0: Tbsi_ShaHash
0x180007158: "__cdecl _imp_CloseHandle" __imp_CloseHandle
0x1800071F0: "__cdecl _imp_RtlCompareMemory" __imp_RtlCompareMemory
0x180008DFC: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-errorhandling-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-errorhandling-l1-1-0
0x180005AC0: McGenControlCallbackV2
0x180007870: TPMCOREEVENT_TBS_PROVISION_DEVICEID
0x18000A658: "__cdecl _onexitbegin" __onexitbegin
0x180007360: "__cdecl _imp__vsnwprintf" __imp__vsnwprintf
0x1800072E8: "__cdecl _imp_SymInitialize" __imp_SymInitialize
0x180007128: "__cdecl _imp_SetUnhandledExceptionFilter" __imp_SetUnhandledExceptionFilter
0x180007188: "__cdecl _imp_GetCurrentThread" __imp_GetCurrentThread
0x180002604: "__cdecl _security_init_cookie" __security_init_cookie
0x180007E88: "HashDigestLength" ??_C@_1CC@DMMMEHOM@?$AAH?$AAa?$AAs?$AAh?$AAD?$AAi?$AAg?$AAe?$AAs?$AAt?$AAL?$AAe?$AAn?$AAg?$AAt?$AAh?$AA?$AA@
0x180007290: "__cdecl _imp_BCryptFinishHash" __imp_BCryptFinishHash
0x1800073B8: "__cdecl _imp_NtQuerySystemInformation" __imp_NtQuerySystemInformation
0x1800071C8: "__cdecl _imp_RegGetValueW" __imp_RegGetValueW
0x1800075D8: "\??\TPM" ??_C@_1BA@PAHEOFNM@?$AA?2?$AA?$DP?$AA?$DP?$AA?2?$AAT?$AAP?$AAM?$AA?$AA@
0x180001970: Tbsip_Submit_Command
0x180008D84: "__cdecl _IMPORT_DESCRIPTOR_msvcrt" __IMPORT_DESCRIPTOR_msvcrt
0x180007CD8: "OwnerAuthAdmin" ??_C@_1BO@PPKHJIJH@?$AAO?$AAw?$AAn?$AAe?$AAr?$AAA?$AAu?$AAt?$AAh?$AAA?$AAd?$AAm?$AAi?$AAn?$AA?$AA@
0x180007880: Microsoft_Windows_TPM_WMILevels
0x180005BC4: McGenEventRegister
0x1800073D8: "__cdecl _imp_NtOpenKey" __imp_NtOpenKey
0x180007358: "__cdecl _imp_malloc" __imp_malloc
0x180007E48: "Microsoft Primitive Provider" ??_C@_1DK@HJHMGPGD@?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?5?$AAP?$AAr?$AAi?$AAm?$AAi?$AAt?$AAi?$AAv?$AAe?$AA?5?$AAP?$AAr?$AAo?$AAv?$AAi?$AAd?$AAe?$AAr?$AA?$AA@
0x180007280: "__cdecl _imp_EventUnregister" __imp_EventUnregister
0x180007240: "__cdecl _imp_GetTickCount64" __imp_GetTickCount64
0x180007138: "__cdecl _imp_GetFileSize" __imp_GetFileSize
0x180007B30: "TpmRegDriverPersistedDataEndorse" ??_C@_1EK@JIKAHDGN@?$AAT?$AAp?$AAm?$AAR?$AAe?$AAg?$AAD?$AAr?$AAi?$AAv?$AAe?$AAr?$AAP?$AAe?$AAr?$AAs?$AAi?$AAs?$AAt?$AAe?$AAd?$AAD?$AAa?$AAt?$AAa?$AAE?$AAn?$AAd?$AAo?$AAr?$AAs?$AAe@
0x180002760: "__cdecl _report_gsfailure" __report_gsfailure
0x180003948: "long __cdecl TbsBase64Decode(unsigned short const * __ptr64,unsigned char * __ptr64,unsigned int * __ptr64)" ?TbsBase64Decode@@YAJPEBGPEAEPEAI@Z
0x1800078C0: "TpmLockoutCountIncreased" ??_C@_1DC@KJHLFGCN@?$AAT?$AAp?$AAm?$AAL?$AAo?$AAc?$AAk?$AAo?$AAu?$AAt?$AAC?$AAo?$AAu?$AAn?$AAt?$AAI?$AAn?$AAc?$AAr?$AAe?$AAa?$AAs?$AAe?$AAd?$AA?$AA@
0x18000A668: "__cdecl _native_startup_state" __native_startup_state
0x180007E28: "SHA256" ??_C@_1O@HECGKAIN@?$AAS?$AAH?$AAA?$AA2?$AA5?$AA6?$AA?$AA@
0x18000A6C0: Microsoft_Windows_TPM_WMIEnableBits
0x180008E88: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-profile-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-profile-l1-1-0
0x180007588: "WindowsAIKPub" ??_C@_1BM@FFGENHDP@?$AAW?$AAi?$AAn?$AAd?$AAo?$AAw?$AAs?$AAA?$AAI?$AAK?$AAP?$AAu?$AAb?$AA?$AA@
0x180007A90: "TpmRegDriverPersistedDataAdmin" ??_C@_1DO@DHNFKGAD@?$AAT?$AAp?$AAm?$AAR?$AAe?$AAg?$AAD?$AAr?$AAi?$AAv?$AAe?$AAr?$AAP?$AAe?$AAr?$AAs?$AAi?$AAs?$AAt?$AAe?$AAd?$AAD?$AAa?$AAt?$AAa?$AAA?$AAd?$AAm?$AAi?$AAn?$AA?$AA@
0x180007348: "__cdecl _imp_free" __imp_free
0x180005C90: McTemplateU0
0x180002570: "__cdecl IsNonwritableInCurrentImage" _IsNonwritableInCurrentImage
0x180007228: api-ms-win-core-synch-l1-2-0_NULL_THUNK_DATA
0x1800075F0: "\Registry\Machine\System\Current" ??_C@_1IK@GJOILNCH@?$AA?2?$AAR?$AAe?$AAg?$AAi?$AAs?$AAt?$AAr?$AAy?$AA?2?$AAM?$AAa?$AAc?$AAh?$AAi?$AAn?$AAe?$AA?2?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AA?2?$AAC?$AAu?$AAr?$AAr?$AAe?$AAn?$AAt@
0x180007218: api-ms-win-core-synch-l1-1-0_NULL_THUNK_DATA
0x180004B00: Tbsip_Cancel_Commands
0x180008E74: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-synch-l1-2-0" __IMPORT_DESCRIPTOR_api-ms-win-core-synch-l1-2-0
0x180002985: memset
0x180008ED8: "__cdecl _NULL_IMPORT_DESCRIPTOR" __NULL_IMPORT_DESCRIPTOR
0x180007148: "__cdecl _imp_ReadFile" __imp_ReadFile

[JEB Decompiler by PNF Software]