Generated by JEB on 2019/08/01

PE: C:\Windows\System32\rsaenh.dll Base=0x168000000 SHA-256=4B925FCAF87C3D539292319AB9BAE6EABF2FEA5B7A7FDB364BC2648E1B5F6AE8
PDB: rsaenh.pdb GUID={D3D5BE4E-C613-0656-BA7F4EDA2805D0E4} Age=1

755 located named symbols:
0x168026860: "Failed to delete key container. " ??_C@_1FO@KILNKPNK@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAd?$AAe?$AAl?$AAe?$AAt?$AAe?$AA?5?$AAk?$AAe?$AAy?$AA?5?$AAc?$AAo?$AAn?$AAt?$AAa?$AAi?$AAn?$AAe?$AAr?$AA?4?$AA?5@
0x168002830: CPVerifySignature
0x168023DE0: "__cdecl _sz_SspiCli_dll" __sz_SspiCli_dll
0x1680267E0: "Failed to delete key container d" ??_C@_1HC@DIEJOLLG@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAd?$AAe?$AAl?$AAe?$AAt?$AAe?$AA?5?$AAk?$AAe?$AAy?$AA?5?$AAc?$AAo?$AAn?$AAt?$AAa?$AAi?$AAn?$AAe?$AAr?$AA?5?$AAd@
0x16801BB5C: InflateKey
0x1680234A8: api-ms-win-core-file-l1-1-0_NULL_THUNK_DATA
0x168023700: "__cdecl _imp_GetSecurityDescriptorOwner" __imp_GetSecurityDescriptorOwner
0x1680261B8: ETW_LOG_RSAENH_CONTMAN_DELETE_KEY_CONTAINER
0x1680236B0: "__cdecl _imp_EventRegister" __imp_EventRegister
0x168005E78: GetUserDirectory
0x16801129C: GetTextualSidW
0x1680238C0: "__cdecl _imp_EtwUnregisterTraceGuids" __imp_EtwUnregisterTraceGuids
0x168024C50: g_RsaEnhPolicy
0x168023780: "__cdecl _imp_AllocateAndInitializeSid" __imp_AllocateAndInitializeSid
0x168023880: "__cdecl _imp_RtlReleaseRelativeName" __imp_RtlReleaseRelativeName
0x168003C30: "__cdecl _delayLoadHelper2" __delayLoadHelper2
0x168023A88: "SHA384" ??_C@_1O@KOBLHLEG@?$AAS?$AAH?$AAA?$AA3?$AA8?$AA4?$AA?$AA@
0x168026460: "Failed to open file in storage a" ??_C@_1II@NECDDFBO@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAo?$AAp?$AAe?$AAn?$AA?5?$AAf?$AAi?$AAl?$AAe?$AA?5?$AAi?$AAn?$AA?5?$AAs?$AAt?$AAo?$AAr?$AAa?$AAg?$AAe?$AA?5?$AAa@
0x16802917C: "__cdecl _IMPORT_DESCRIPTOR_ntdll" __IMPORT_DESCRIPTOR_ntdll
0x1680237D8: "__cdecl _imp_BCryptVerifySignature" __imp_BCryptVerifySignature
0x168023F80: "MD2" ??_C@_17OGKOIPPK@?$AAM?$AAD?$AA2?$AA?$AA@
0x168023580: "__cdecl _imp_VirtualProtect" __imp_VirtualProtect
0x168023C78: "%08lx%08lx%08lx%08lx" ??_C@_1CK@FLNECPEL@?$AA?$CF?$AA0?$AA8?$AAl?$AAx?$AA?$CF?$AA0?$AA8?$AAl?$AAx?$AA?$CF?$AA0?$AA8?$AAl?$AAx?$AA?$CF?$AA0?$AA8?$AAl?$AAx?$AA?$AA@
0x16802B830: g_hInstance
0x16802B068: "__cdecl _security_cookie_complement" __security_cookie_complement
0x168026690: "Failed to delete file in storage" ??_C@_1KE@PPINCFL@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAd?$AAe?$AAl?$AAe?$AAt?$AAe?$AA?5?$AAf?$AAi?$AAl?$AAe?$AA?5?$AAi?$AAn?$AA?5?$AAs?$AAt?$AAo?$AAr?$AAa?$AAg?$AAe@
0x168023870: "__cdecl _imp_wcsncpy_s" __imp_wcsncpy_s
0x168002740: DesParityOnKey
0x168020A50: TLSDeriveExportableRCKey
0x16802D020: "__cdecl _imp_SystemFunction036" __imp_SystemFunction036
0x168023DB0: "__cdecl _sz_CRYPTBASE_dll" __sz_CRYPTBASE_dll
0x1680237E8: "__cdecl _imp_BCryptSignHash" __imp_BCryptSignHash
0x168023FD0: Microsoft_Windows_Crypto_RSAEnhKeywords
0x168015340: CPDecrypt
0x168026960: "Failed to delete key container." ??_C@_1EA@EIIEIOCD@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAd?$AAe?$AAl?$AAe?$AAt?$AAe?$AA?5?$AAk?$AAe?$AAy?$AA?5?$AAc?$AAo?$AAn?$AAt?$AAa?$AAi?$AAn?$AAe?$AAr?$AA?4?$AA?$AA@
0x1680152B0: WppControlCallback
0x168026540: "Deleted file in storage area suc" ??_C@_1FG@MONDMHDH@?$AAD?$AAe?$AAl?$AAe?$AAt?$AAe?$AAd?$AA?5?$AAf?$AAi?$AAl?$AAe?$AA?5?$AAi?$AAn?$AA?5?$AAs?$AAt?$AAo?$AAr?$AAa?$AAg?$AAe?$AA?5?$AAa?$AAr?$AAe?$AAa?$AA?5?$AAs?$AAu?$AAc@
0x168006CF0: "__cdecl guard_dispatch_icall_nop" _guard_dispatch_icall_nop
0x168003260: CPExportKey
0x168028C80: USERENV_NULL_THUNK_DATA_DLN
0x168023468: "__cdecl _imp_CreateFileW" __imp_CreateFileW
0x16802261C: NtStatusToSpecificDosError
0x168023558: "__cdecl _imp_CompareStringA" __imp_CompareStringA
0x168023E00: "__cdecl _sz_api_ms_win_security_provider_l1_1_0_dll" __sz_api_ms_win_security_provider_l1_1_0_dll
0x16801294C: ReadContainerNameFromFile
0x168025F78: "Export Flag" ??_C@_1BI@NMFPHONN@?$AAE?$AAx?$AAp?$AAo?$AAr?$AAt?$AA?5?$AAF?$AAl?$AAa?$AAg?$AA?$AA@
0x168023770: "__cdecl _imp_GetSidIdentifierAuthority" __imp_GetSidIdentifierAuthority
0x168023458: "__cdecl _imp_RemoveDirectoryW" __imp_RemoveDirectoryW
0x168017FEC: SetupKeyToBeHashed
0x1680188F0: CPDuplicateKey
0x168023AF8: "Software\Microsoft\Cryptography" ??_C@_0CA@DMNKBPBF@Software?2Microsoft?2Cryptography?$AA@
0x168003C9C: UnloadStrings
0x168001A20: LocalPopulateBCryptPublicKey
0x16802B820: g_ulAdditionalProbeSize
0x168023810: "__cdecl _imp_BCryptDestroyKey" __imp_BCryptDestroyKey
0x168020EC0: MaskGeneration
0x1680238B0: "__cdecl _imp_EtwGetTraceLoggerHandle" __imp_EtwGetTraceLoggerHandle
0x168023638: "__cdecl _imp_AcquireSRWLockShared" __imp_AcquireSRWLockShared
0x168027060: "__cdecl _pfnDliFailureHook2" __pfnDliFailureHook2
0x168014E0C: McTemplateU0zzstqz
0x16802B7E8: "__cdecl _hmod__USERENV_dll" __hmod__USERENV_dll
0x168023BF8: "PrivKeyCacheMaxItems" ??_C@_0BF@EBIAOOOI@PrivKeyCacheMaxItems?$AA@
0x168005134: CreateSystemDirectory
0x16802921C: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-file-l1-2-0" __IMPORT_DESCRIPTOR_api-ms-win-core-file-l1-2-0
0x1680291A4: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-file-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-file-l1-1-0
0x168023C40: "\Microsoft\Crypto\RSA\" ??_C@_1CO@EEIHOJLM@?$AA?2?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAC?$AAr?$AAy?$AAp?$AAt?$AAo?$AA?2?$AAR?$AAS?$AAA?$AA?2?$AA?$AA@
0x168023830: bcrypt_NULL_THUNK_DATA
0x168023F90: "3DES_112" ??_C@_1BC@OBELMIOB@?$AA3?$AAD?$AAE?$AAS?$AA_?$AA1?$AA1?$AA2?$AA?$AA@
0x168023518: api-ms-win-core-heap-l2-1-0_NULL_THUNK_DATA
0x168023AC0: "Software\Microsoft\Cryptography\" ??_C@_0CI@FHKKDMLA@Software?2Microsoft?2Cryptography?2@
0x168023740: "__cdecl _imp_GetAce" __imp_GetAce
0x16802BAC0: g_pPrivKeyCache
0x168028E20: api-ms-win-security-sddl-l1-1-0_NULL_THUNK_DATA_DLB
0x16801206C: MyCryptProtectData
0x1680175F4: InitialHMACCalc
0x168023EA8: WPP_11203d914b3430d83a90c03bfc1ba2f9_Traceguids
0x168003ABC: WppInitUm
0x1680144F4: McTemplateU0zqsttqz
0x1680236D8: "__cdecl _imp_PrivilegeCheck" __imp_PrivilegeCheck
0x168020B60: TLSDeriveKey
0x16801C33C: PopulateUserHandleFromCngKey
0x168023958: "__cdecl _guard_dispatch_icall_fptr" __guard_dispatch_icall_fptr
0x1680292BC: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-file-l2-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-file-l2-1-0
0x16801F208: SCHSetKeyParam
0x16801C044: LocalPopulateBCryptKeyPair
0x168023668: "__cdecl _imp_InitializeCriticalSection" __imp_InitializeCriticalSection
0x1680124F0: PrivKeyCacheIsKeyValid
0x1680292F8: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-string-obsolete-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-string-obsolete-l1-1-0
0x16802B7D0: "__cdecl _hmod__RPCRT4_dll" __hmod__RPCRT4_dll
0x1680260F8: ETW_LOG_RSAENH_CONTMAN_OPERATION_FAILED
0x168023748: "__cdecl _imp_GetSecurityDescriptorControl" __imp_GetSecurityDescriptorControl
0x1680221FC: LocalInflateBCryptKey
0x168023AE8: "MachineGuid" ??_C@_0M@NKGGMCID@MachineGuid?$AA@
0x1680269A0: "MyCreateFile failed due to shari" ??_C@_1FM@BHABAHJA@?$AAM?$AAy?$AAC?$AAr?$AAe?$AAa?$AAt?$AAe?$AAF?$AAi?$AAl?$AAe?$AA?5?$AAf?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAd?$AAu?$AAe?$AA?5?$AAt?$AAo?$AA?5?$AAs?$AAh?$AAa?$AAr?$AAi@
0x168023768: "__cdecl _imp_MakeSelfRelativeSD" __imp_MakeSelfRelativeSD
0x1680235E8: "__cdecl _imp_RegSetValueExA" __imp_RegSetValueExA
0x168020838: TLSDeriveExportableEncKey
0x168004F30: CreateNestedDirectories
0x16800F114: AllocFindState
0x16801B360: GetDefaultKeyLength
0x168006650: "__cdecl _imp_load_SystemFunction036" __imp_load_SystemFunction036
0x168002F90: CPDestroyKey
0x168023828: "__cdecl _imp_BCryptCreateHash" __imp_BCryptCreateHash
0x168011B78: I_PrivKeyCachePurgeOldestItem
0x168023460: "__cdecl _imp_FindClose" __imp_FindClose
0x168006090: IsUniqueKeyFileName
0x168023F40: "AES" ??_C@_17PJMHNJHG@?$AAA?$AAE?$AAS?$AA?$AA@
0x1680027C8: ValidKeyAlgid
0x168025FD8: "S-%lu-" ??_C@_1O@NEDHCEJJ@?$AAS?$AA?9?$AA?$CF?$AAl?$AAu?$AA?9?$AA?$AA@
0x168026FD8: "ChainingModeCBC" ??_C@_1CA@NDPDKCGP@?$AAC?$AAh?$AAa?$AAi?$AAn?$AAi?$AAn?$AAg?$AAM?$AAo?$AAd?$AAe?$AAC?$AAB?$AAC?$AA?$AA@
0x168023500: api-ms-win-core-heap-l1-1-0_NULL_THUNK_DATA
0x16802D0A0: api-ms-win-security-sddl-l1-1-0_NULL_THUNK_DATA_DLA
0x168026A50: "MyCreateFile failed to open file" ??_C@_1IC@BKFODJPC@?$AAM?$AAy?$AAC?$AAr?$AAe?$AAa?$AAt?$AAe?$AAF?$AAi?$AAl?$AAe?$AA?5?$AAf?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAo?$AAp?$AAe?$AAn?$AA?5?$AAf?$AAi?$AAl?$AAe@
0x1680261D8: ETW_LOG_RSAENH_CONTMAN_CREATE_FILE_W
0x168003A60: CPGenRandom
0x16802248C: LocalSetBCryptKeyParams
0x168011A24: I_PrivKeyCacheLookupItem
0x16802BB80: g_wsProcessFileName
0x1680234A0: "__cdecl _imp_DeleteFileW" __imp_DeleteFileW
0x16802102C: OAEPDecryptExponentOfOne
0x168023A10: "__cdecl _guard_iat_table" __guard_iat_table
0x168025F48: "\\?\" ??_C@_19MJCDBCKE@?$AA?2?$AA?2?$AA?$DP?$AA?2?$AA?$AA@
0x1680118AC: I_PrivKeyCacheGetCurrentLuid
0x168023BB0: "PrivateKeyLifetimeSeconds" ??_C@_0BK@PECIEKGK@PrivateKeyLifetimeSeconds?$AA@
0x168006CB3: memcpy
0x16802BAD0: g_Strings
0x168011878: I_PrivKeyCacheDeleteItem
0x168023800: "__cdecl _imp_BCryptDecrypt" __imp_BCryptDecrypt
0x16800643C: "__cdecl _security_init_cookie_ex" __security_init_cookie_ex
0x1680236C0: "__cdecl _imp_EventWriteTransfer" __imp_EventWriteTransfer
0x1680013EC: LocalCreateBCryptKey
0x168023478: "__cdecl _imp_GetTempFileNameW" __imp_GetTempFileNameW
0x168023920: "__cdecl _imp_memset" __imp_memset
0x1680234B8: api-ms-win-core-file-l1-2-0_NULL_THUNK_DATA
0x1680234C8: api-ms-win-core-file-l2-1-0_NULL_THUNK_DATA
0x168023790: "__cdecl _imp_BCryptDuplicateHash" __imp_BCryptDuplicateHash
0x168026740: "Failed to delete file in storage" ??_C@_1EO@EBCGKHAI@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAd?$AAe?$AAl?$AAe?$AAt?$AAe?$AA?5?$AAf?$AAi?$AAl?$AAe?$AA?5?$AAi?$AAn?$AA?5?$AAs?$AAt?$AAo?$AAr?$AAa?$AAg?$AAe@
0x168029230: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-sysinfo-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-sysinfo-l1-1-0
0x168026F20: "*Default*" ??_C@_09IOAHGME@?$CKDefault?$CK?$AA@
0x168023680: "__cdecl _imp_Sleep" __imp_Sleep
0x168022790: "__cdecl resetstkoflw_static" _resetstkoflw_static
0x168001190: CPGenKey
0x1680068C4: "__cdecl _imp_load_GetBasicProfileFolderPath" __imp_load_GetBasicProfileFolderPath
0x16801CA98: ProtectPrivateKeyAfterImport
0x168022650: PrepareBCryptBlockCipher
0x16800650A: RtlUnhandledExceptionFilter
0x168013E64: EtwLogContmanDeleteKeyContainer
0x16802930C: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-localization-obsolete-l1-2-0" __IMPORT_DESCRIPTOR_api-ms-win-core-localization-obsolete-l1-2-0
0x168023940: "__cdecl _imp_wcscmp" __imp_wcscmp
0x168026080: "ntstatus" ??_C@_08POFJECNE@ntstatus?$AA@
0x16802D008: "__cdecl _imp_CryptUnprotectData" __imp_CryptUnprotectData
0x168023898: "__cdecl _imp_EtwRegisterTraceGuidsW" __imp_EtwRegisterTraceGuidsW
0x1680064CE: "__cdecl _C_specific_handler" __C_specific_handler
0x168023620: "__cdecl _imp_lstrlenW" __imp_lstrlenW
0x168023660: "__cdecl _imp_ReleaseSRWLockExclusive" __imp_ReleaseSRWLockExclusive
0x168011024: GetSecurityOnContainer
0x1680064E6: RtlCaptureContext
0x1680133F8: WriteContainerInfo
0x168001D50: CPCreateHash
0x16802D058: "__cdecl _imp_GetUserNameExA" __imp_GetUserNameExA
0x168023758: "__cdecl _imp_AddAccessAllowedAce" __imp_AddAccessAllowedAce
0x168012CC4: SetSecurityOnContainer
0x168013E04: EtwLogContmanDeleteFileW
0x1680260C0: "*" ??_C@_13BBDEGPLJ@?$AA?$CK?$AA?$AA@
0x1680234E8: "__cdecl _imp_HeapFree" __imp_HeapFree
0x16802B868: WPP_REGISTRATION_GUIDS
0x168005ED8: CleanupFindState
0x1680065A1: "__cdecl _imp_load_ConvertStringSecurityDescriptorToSecurityDescriptorW" __imp_load_ConvertStringSecurityDescriptorToSecurityDescriptorW
0x168023F78: "MD4" ??_C@_17MDMFNACG@?$AAM?$AAD?$AA4?$AA?$AA@
0x1680234D8: api-ms-win-core-handle-l1-1-0_NULL_THUNK_DATA
0x1680235D8: "__cdecl _imp_RegCloseKey" __imp_RegCloseKey
0x168023878: "__cdecl _imp_NtQueryInformationToken" __imp_NtQueryInformationToken
0x168026B10: "Successfully set security on con" ??_C@_1FA@GHCBFGNG@?$AAS?$AAu?$AAc?$AAc?$AAe?$AAs?$AAs?$AAf?$AAu?$AAl?$AAl?$AAy?$AA?5?$AAs?$AAe?$AAt?$AA?5?$AAs?$AAe?$AAc?$AAu?$AAr?$AAi?$AAt?$AAy?$AA?5?$AAo?$AAn?$AA?5?$AAc?$AAo?$AAn@
0x168006BAC: "__cdecl _GSHandlerCheckCommon" __GSHandlerCheckCommon
0x168028C98: api-ms-win-security-provider-l1-1-0_NULL_THUNK_DATA_DLN
0x16801F91C: SSL2DeriveKey
0x16801E228: ProtectPrivKey
0x16801E938: CalculatePRF
0x168026DD0: "CAPIPRIVATEBLOB" ??_C@_1CA@LHEFDM@?$AAC?$AAA?$AAP?$AAI?$AAP?$AAR?$AAI?$AAV?$AAA?$AAT?$AAE?$AAB?$AAL?$AAO?$AAB?$AA?$AA@
0x168023838: "__cdecl _imp__strlwr" __imp__strlwr
0x1680233F0: g_AlgTables
0x16801F438: SChGenMasterKey
0x168022770: SafeAllocaFreeToHeap
0x16802B7E0: "__cdecl _hmod__CRYPTBASE_dll" __hmod__CRYPTBASE_dll
0x168026F00: WPP_328a31eb477c34c2c37925d291599ca3_Traceguids
0x1680238C8: "__cdecl _imp_RtlAllocateHeap" __imp_RtlAllocateHeap
0x168028C20: CRYPT32_NULL_THUNK_DATA_DLN
0x168023610: api-ms-win-core-string-l1-1-0_NULL_THUNK_DATA
0x16802B840: WPP_MAIN_CB
0x168026F10: "DefaultKeys" ??_C@_0M@EFNBIPIE@DefaultKeys?$AA@
0x168026040: "-%lu" ??_C@_19DEJHOMFE@?$AA?9?$AA?$CF?$AAl?$AAu?$AA?$AA@
0x168029190: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-security-base-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-security-base-l1-1-0
0x16801E5F4: UnprotectPrivKey
0x16801BDB0: LocalGenerateBCryptKeyPair
0x1680225F8: NtStatusToDosError
0x168005274: OpenFileInStorageArea
0x168023AA8: "ForceKeyProtection" ??_C@_0BD@BFDEEMJE@ForceKeyProtection?$AA@
0x168027058: "__cdecl _DefaultResolveDelayLoadedAPIFlags" __DefaultResolveDelayLoadedAPIFlags
0x1680015D0: CPImportKey
0x16800FED8: DeleteKeyContainer
0x16802D0A8: "__cdecl _imp_GetBasicProfileFolderPath" __imp_GetBasicProfileFolderPath
0x168026DF0: "IV" ??_C@_15IIAMFFIG@?$AAI?$AAV?$AA?$AA@
0x168006815: "__cdecl _imp_load_SystemFunction040" __imp_load_SystemFunction040
0x168025FF0: "0x%02hx%02hx%02hx%02hx%02hx%02hx" ??_C@_1EC@MPDKEHCN@?$AA0?$AAx?$AA?$CF?$AA0?$AA2?$AAh?$AAx?$AA?$CF?$AA0?$AA2?$AAh?$AAx?$AA?$CF?$AA0?$AA2?$AAh?$AAx?$AA?$CF?$AA0?$AA2?$AAh?$AAx?$AA?$CF?$AA0?$AA2?$AAh?$AAx?$AA?$CF?$AA0?$AA2?$AAh?$AAx@
0x1680025C0: addEntryToCache
0x1680238D8: "__cdecl _imp_NtTerminateProcess" __imp_NtTerminateProcess
0x1680292E4: "__cdecl _IMPORT_DESCRIPTOR_bcrypt" __IMPORT_DESCRIPTOR_bcrypt
0x16802B7D8: "__cdecl _hmod__api_ms_win_security_sddl_l1_1_0_dll" __hmod__api_ms_win_security_sddl_l1_1_0_dll
0x16801664C: SymDecrypt
0x168012258: OpenCallerToken
0x1680223DC: LocalSetBCryptChainingMode
0x168026188: ETW_LOG_RSAENH_CONTMAN_GET_USER_STORAGE_AREA_FAILED
0x168002230: MakeNewKey
0x16802B7F0: "__cdecl _hmod__CRYPT32_dll" __hmod__CRYPT32_dll
0x168023600: "__cdecl _imp_WideCharToMultiByte" __imp_WideCharToMultiByte
0x168011BC0: IsThreadLocalSystem
0x168002540: VerifyStackAvailable
0x168028AEC: "__cdecl _DELAY_IMPORT_DESCRIPTOR_RPCRT4_dll" __DELAY_IMPORT_DESCRIPTOR_RPCRT4_dll
0x168016DC0: CPHashSessionKey
0x168023530: "__cdecl _imp_LoadLibraryExA" __imp_LoadLibraryExA
0x1680121BC: MyGetTokenInformation
0x168023640: "__cdecl _imp_EnterCriticalSection" __imp_EnterCriticalSection
0x168023648: "__cdecl _imp_ReleaseSRWLockShared" __imp_ReleaseSRWLockShared
0x168026F80: "IV block" ??_C@_08IBBAIJIN@IV?5block?$AA@
0x1680235F8: api-ms-win-core-registry-l1-1-0_NULL_THUNK_DATA
0x168023738: "__cdecl _imp_GetSecurityDescriptorLength" __imp_GetSecurityDescriptorLength
0x168010AA4: GetNextContainer
0x168003A00: initBCryptAlgorithmProviderCache
0x168023450: api-ms-win-core-errorhandling-l1-1-0_NULL_THUNK_DATA
0x168025F90: "D:P(A;OICI;FA;;;SY)(A;OICI;FA;;;" ??_C@_1EI@HLMMPNC@?$AAD?$AA?3?$AAP?$AA?$CI?$AAA?$AA?$DL?$AAO?$AAI?$AAC?$AAI?$AA?$DL?$AAF?$AAA?$AA?$DL?$AA?$DL?$AA?$DL?$AAS?$AAY?$AA?$CJ?$AA?$CI?$AAA?$AA?$DL?$AAO?$AAI?$AAC?$AAI?$AA?$DL?$AAF?$AAA?$AA?$DL?$AA?$DL?$AA?$DL@
0x168023F88: "DSA" ??_C@_17JOLIKJIA@?$AAD?$AAS?$AAA?$AA?$AA@
0x168023B18: "Software\Microsoft\Cryptography\" ??_C@_0DK@MAOEHFNN@Software?2Microsoft?2Cryptography?2@
0x168023698: "__cdecl _imp_GetSystemInfo" __imp_GetSystemInfo
0x1680235A0: "__cdecl _imp_GetCurrentProcess" __imp_GetCurrentProcess
0x168012704: ProtectExportabilityFlag
0x168023618: "__cdecl _imp_lstrlenA" __imp_lstrlenA
0x168010EC8: GetNextEnumedOldMachKeys
0x168028B4C: "__cdecl _DELAY_IMPORT_DESCRIPTOR_USERENV_dll" __DELAY_IMPORT_DESCRIPTOR_USERENV_dll
0x16802D050: RPCRT4_NULL_THUNK_DATA_DLA
0x168028E10: RPCRT4_NULL_THUNK_DATA_DLB
0x168023798: "__cdecl _imp_BCryptHashData" __imp_BCryptHashData
0x1680069F0: DllMain
0x168028C60: RPCRT4_NULL_THUNK_DATA_DLN
0x1680066DB: "__cdecl _imp_load_SystemFunction041" __imp_load_SystemFunction041
0x168014CF8: McTemplateU0zzqz
0x16802BAB0: g_pBCryptProvHandleCacheLock
0x168020284: SSL3HashPreMaster
0x168023D70: "__cdecl _sz_RPCRT4_dll" __sz_RPCRT4_dll
0x16802D060: SspiCli_NULL_THUNK_DATA_DLA
0x16800F4B8: ConvertContainerSecurityDescriptor
0x168027018: "ChainingModeECB" ??_C@_1CA@GGHMBPCI@?$AAC?$AAh?$AAa?$AAi?$AAn?$AAi?$AAn?$AAg?$AAM?$AAo?$AAd?$AAe?$AAE?$AAC?$AAB?$AA?$AA@
0x168014204: McTemplateU0qzd
0x16800663E: "__cdecl _imp_load_UuidToStringA" __imp_load_UuidToStringA
0x168026FB0: "EffectiveKeyLength" ??_C@_1CG@JKHJNPKD@?$AAE?$AAf?$AAf?$AAe?$AAc?$AAt?$AAi?$AAv?$AAe?$AAK?$AAe?$AAy?$AAL?$AAe?$AAn?$AAg?$AAt?$AAh?$AA?$AA@
0x168006C10: "__cdecl _GSHandlerCheck_SEH" __GSHandlerCheck_SEH
0x168029258: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-string-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-string-l1-1-0
0x168023890: "__cdecl _imp_wcscat_s" __imp_wcscat_s
0x168016A34: SymEncrypt
0x1680236E0: "__cdecl _imp_IsValidSid" __imp_IsValidSid
0x16801AB48: CheckIfExponentOfOneRsaKey
0x168023860: "__cdecl _imp___C_specific_handler" __imp___C_specific_handler
0x168023E98: WPP_ea5e442a73413341eba8f36e3661246c_Traceguids
0x168026BE8: "Failed to delete file." ??_C@_1CO@PLEJFKFL@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAd?$AAe?$AAl?$AAe?$AAt?$AAe?$AA?5?$AAf?$AAi?$AAl?$AAe?$AA?4?$AA?$AA@
0x1680238E0: "__cdecl _imp_RtlCaptureContext" __imp_RtlCaptureContext
0x1680260E8: "crypt32.dll" ??_C@_0M@DNEEGAAA@crypt32?4dll?$AA@
0x168023550: api-ms-win-core-libraryloader-l1-2-0_NULL_THUNK_DATA
0x16801067C: FindClosestFileInStorageArea
0x1680292D0: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-eventing-provider-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-eventing-provider-l1-1-0
0x168028E40: CRYPTBASE_NULL_THUNK_DATA_DLB
0x16801142C: GetUniqueContainerName
0x168023448: "__cdecl _imp_GetLastError" __imp_GetLastError
0x168026BB0: "Successfully deleted file." ??_C@_1DG@PBIKJFKN@?$AAS?$AAu?$AAc?$AAc?$AAe?$AAs?$AAs?$AAf?$AAu?$AAl?$AAl?$AAy?$AA?5?$AAd?$AAe?$AAl?$AAe?$AAt?$AAe?$AAd?$AA?5?$AAf?$AAi?$AAl?$AAe?$AA?4?$AA?$AA@
0x16802D090: "__cdecl _imp_ConvertSidToStringSidW" __imp_ConvertSidToStringSidW
0x1680236C8: api-ms-win-eventing-provider-l1-1-0_NULL_THUNK_DATA
0x168004E38: GetHashOfContainer
0x16801BF0C: LocalGetBCryptHashVal
0x168006B88: "__cdecl _GSHandlerCheck" __GSHandlerCheck
0x168026FA0: WPP_ec947eaa8d5a32dda1bf00315552a98f_Traceguids
0x16801B324: FreeNewKey
0x16801ED9C: PRF
0x168023908: "__cdecl _imp_EtwTraceMessage" __imp_EtwTraceMessage
0x168023930: "__cdecl _imp_memcmp" __imp_memcmp
0x1680235B0: "__cdecl _imp_SetThreadStackGuarantee" __imp_SetThreadStackGuarantee
0x168023888: "__cdecl _imp_strchr" __imp_strchr
0x168023818: "__cdecl _imp_BCryptCloseAlgorithmProvider" __imp_BCryptCloseAlgorithmProvider
0x1680236D0: "__cdecl _imp_EqualSid" __imp_EqualSid
0x168023A78: "SHA1" ??_C@_19DILNDFJH@?$AAS?$AAH?$AAA?$AA1?$AA?$AA@
0x168023A98: ETW_LOG_RSAENH_CONTMAN_PROVIDER
0x1680261E8: "NULL" ??_C@_19CIJIHAKK@?$AAN?$AAU?$AAL?$AAL?$AA?$AA@
0x168029334: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-delayload-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-delayload-l1-1-0
0x168023840: "__cdecl _imp_swprintf_s" __imp_swprintf_s
0x1680125C4: PrivKeyCacheLookupItem
0x168011628: GetUserSid
0x168027058: "__cdecl _ResolveDelayLoadedAPIFlags" __ResolveDelayLoadedAPIFlags
0x1680260C8: "ExpoOffload" ??_C@_0M@KMONLGFP@ExpoOffload?$AA@
0x168028E90: SspiCli_NULL_THUNK_DATA_DLB
0x168006845: "__cdecl _tailMerge_sspicli_dll" __tailMerge_sspicli_dll
0x1680238A0: "__cdecl _imp_RtlFreeHeap" __imp_RtlFreeHeap
0x168023E28: "dwReturn" ??_C@_08KOCHCJLB@dwReturn?$AA@
0x168004590: InitExpOffloadInfo
0x168023F60: "SHA512" ??_C@_1O@GKBAHMNF@?$AAS?$AAH?$AAA?$AA5?$AA1?$AA2?$AA?$AA@
0x1680291F4: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-libraryloader-l1-2-0" __IMPORT_DESCRIPTOR_api-ms-win-core-libraryloader-l1-2-0
0x16802D030: CRYPTBASE_NULL_THUNK_DATA_DLA
0x168025F60: "\" ??_C@_13FPGAJAPJ@?$AA?2?$AA?$AA@
0x1680234B0: "__cdecl _imp_GetTempPathW" __imp_GetTempPathW
0x168003500: FreeUserRec
0x1680234F8: "__cdecl _imp_HeapAlloc" __imp_HeapAlloc
0x168023528: "__cdecl _imp_FreeLibrary" __imp_FreeLibrary
0x168005478: GetMachineKeysetDirDACL
0x168028CC0: profapi_NULL_THUNK_DATA_DLN
0x168023658: "__cdecl _imp_AcquireSRWLockExclusive" __imp_AcquireSRWLockExclusive
0x168028BEC: "__cdecl _NULL_DELAY_IMPORT_DESCRIPTOR" __NULL_DELAY_IMPORT_DESCRIPTOR
0x16800280C: LocateAlgorithm
0x168023628: api-ms-win-core-string-obsolete-l1-1-0_NULL_THUNK_DATA
0x16801B3D8: GetHashLength
0x1680236E8: "__cdecl _imp_GetSidSubAuthority" __imp_GetSidSubAuthority
0x168026D88: "System\ControlSet001\Control\Min" ??_C@_0CE@ENJIIOIF@System?2ControlSet001?2Control?2Min@
0x16800F380: CheckAndChangeAccessMasks
0x1680265A0: "Failed to delete file in storage" ??_C@_1IA@OAOAIEIH@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAd?$AAe?$AAl?$AAe?$AAt?$AAe?$AA?5?$AAf?$AAi?$AAl?$AAe?$AA?5?$AAi?$AAn?$AA?5?$AAs?$AAt?$AAo?$AAr?$AAa?$AAg?$AAe@
0x1680175B4: GetHashObjectSize
0x1680068D0: "__cdecl _tailMerge_profapi_dll" __tailMerge_profapi_dll
0x168023440: "__cdecl _imp_SetLastError" __imp_SetLastError
0x168023FB8: "RC4" ??_C@_17HLFLMDBJ@?$AAR?$AAC?$AA4?$AA?$AA@
0x168029320: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-delayload-l1-1-1" __IMPORT_DESCRIPTOR_api-ms-win-core-delayload-l1-1-1
0x16802B808: "__cdecl _hmod__api_ms_win_security_provider_l1_1_0_dll" __hmod__api_ms_win_security_provider_l1_1_0_dll
0x16801196C: I_PrivKeyCacheIsKeyValid
0x168023540: "__cdecl _imp_GetModuleFileNameW" __imp_GetModuleFileNameW
0x168013F1C: EtwLogContmanGetUserStorageAreaFailed
0x1680207E4: SetPRFHashParam
0x168023BD0: "PrivKeyCachePurgeIntervalSeconds" ??_C@_0CB@HKFEIEFA@PrivKeyCachePurgeIntervalSeconds@
0x168004ACC: OpenUserKeyGroup
0x168002B1C: GetPKCS1PaddingInfo
0x168029208: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-registry-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-registry-l1-1-0
0x1680234C0: "__cdecl _imp_MoveFileExW" __imp_MoveFileExW
0x168006827: "__cdecl _imp_load_UuidCreate" __imp_load_UuidCreate
0x168005CD4: StringCchPrintfW
0x1680236F8: "__cdecl _imp_InitializeSecurityDescriptor" __imp_InitializeSecurityDescriptor
0x16802D018: "__cdecl _imp_SystemFunction041" __imp_SystemFunction041
0x168026D40: "Failed to delete container info." ??_C@_1EC@PGBLCHEH@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAd?$AAe?$AAl?$AAe?$AAt?$AAe?$AA?5?$AAc?$AAo?$AAn?$AAt?$AAa?$AAi?$AAn?$AAe?$AAr?$AA?5?$AAi?$AAn?$AAf?$AAo?$AA?4@
0x16802D028: "__cdecl _imp_SystemFunction040" __imp_SystemFunction040
0x168023858: "__cdecl _imp_NtCreateFile" __imp_NtCreateFile
0x168025180: g_RsaSchPolicy
0x1680237D0: "__cdecl _imp_BCryptSetProperty" __imp_BCryptSetProperty
0x168023950: "__cdecl _guard_check_icall_fptr" __guard_check_icall_fptr
0x1680064F2: RtlLookupFunctionEntry
0x1680237A0: "__cdecl _imp_BCryptGetProperty" __imp_BCryptGetProperty
0x168012460: PrivKeyCacheDeleteItem
0x168025F64: "NULL" ??_C@_04HIBGFPH@NULL?$AA@
0x168023808: "__cdecl _imp_BCryptEncrypt" __imp_BCryptEncrypt
0x16800695B: "__cdecl _tailMerge_api_ms_win_security_provider_l1_1_0_dll" __tailMerge_api_ms_win_security_provider_l1_1_0_dll
0x168026090: "\AppData\Roaming" ??_C@_1CC@LGPIBLKE@?$AA?2?$AAA?$AAp?$AAp?$AAD?$AAa?$AAt?$AAa?$AA?2?$AAR?$AAo?$AAa?$AAm?$AAi?$AAn?$AAg?$AA?$AA@
0x16802D0B0: profapi_NULL_THUNK_DATA_DLA
0x168016C00: CPDuplicateHash
0x168023778: "__cdecl _imp_GetTokenInformation" __imp_GetTokenInformation
0x168028E68: CRYPT32_NULL_THUNK_DATA_DLB
0x1680064DA: NtTerminateProcess
0x168026FF8: "ChainingMode" ??_C@_1BK@BCJKEJJO@?$AAC?$AAh?$AAa?$AAi?$AAn?$AAi?$AAn?$AAg?$AAM?$AAo?$AAd?$AAe?$AA?$AA@
0x168027038: "ChainingModeCFB" ??_C@_1CA@PANOIHBM@?$AAC?$AAh?$AAa?$AAi?$AAn?$AAi?$AAn?$AAg?$AAM?$AAo?$AAd?$AAe?$AAC?$AAF?$AAB?$AA?$AA@
0x16802B800: "__cdecl _hmod__profapi_dll" __hmod__profapi_dll
0x168023850: "__cdecl _imp_RtlNtStatusToDosError" __imp_RtlNtStatusToDosError
0x1680237E0: "__cdecl _imp_BCryptDestroyHash" __imp_BCryptDestroyHash
0x1680236A8: api-ms-win-core-sysinfo-l1-1-0_NULL_THUNK_DATA
0x168023E50: "Successfully read container info" ??_C@_1EE@MHOBAMNO@?$AAS?$AAu?$AAc?$AAc?$AAe?$AAs?$AAs?$AAf?$AAu?$AAl?$AAl?$AAy?$AA?5?$AAr?$AAe?$AAa?$AAd?$AA?5?$AAc?$AAo?$AAn?$AAt?$AAa?$AAi?$AAn?$AAe?$AAr?$AA?5?$AAi?$AAn?$AAf?$AAo@
0x1680236A0: "__cdecl _imp_GetTickCount" __imp_GetTickCount
0x168023430: "__cdecl _imp_ResolveDelayLoadedAPI" __imp_ResolveDelayLoadedAPI
0x16802D080: "__cdecl _imp_SetNamedSecurityInfoW" __imp_SetNamedSecurityInfoW
0x168026AD8: "Failed to create file." ??_C@_1CO@INHPMAKO@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAc?$AAr?$AAe?$AAa?$AAt?$AAe?$AA?5?$AAf?$AAi?$AAl?$AAe?$AA?4?$AA?$AA@
0x168023788: api-ms-win-security-base-l1-1-0_NULL_THUNK_DATA
0x168021758: PKCS2EncryptExponentOfOne
0x1680132FC: WPP_SF_Ds
0x168013378: WPP_SF_ds
0x16801B504: ImportOpaqueBlob
0x16801FDBC: SSL3DeriveWriteKey
0x1680141A8: McGenEventWrite
0x16802B000: WPP_GLOBAL_Control
0x1680291E0: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-processthreads-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-processthreads-l1-1-0
0x16801756C: FreeHash
0x168023598: api-ms-win-core-memory-l1-1-0_NULL_THUNK_DATA
0x168021C68: RSAEncryptExponentOfOne
0x168021560: PKCS2DecryptExponentOfOne
0x168004B48: GetUserStorageArea
0x168023F58: "DES" ??_C@_17LBCHNHBC@?$AAD?$AAE?$AAS?$AA?$AA@
0x168015230: DllUnregisterServer
0x1680150AC: GetCallerUserName
0x168004780: SetMachineGUID
0x168026320: "Failed to get user storage area." ??_C@_1EC@DNPLAGCG@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAg?$AAe?$AAt?$AA?5?$AAu?$AAs?$AAe?$AAr?$AA?5?$AAs?$AAt?$AAo?$AAr?$AAa?$AAg?$AAe?$AA?5?$AAa?$AAr?$AAe?$AAa?$AA?4@
0x16801DAC0: CPSignHash
0x168026370: "Failed to open file in storage a" ??_C@_1HM@GIONGMKK@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAo?$AAp?$AAe?$AAn?$AA?5?$AAf?$AAi?$AAl?$AAe?$AA?5?$AAi?$AAn?$AA?5?$AAs?$AAt?$AAo?$AAr?$AAa?$AAg?$AAe?$AA?5?$AAa@
0x168005F18: UnprotectExportabilityFlag
0x168004860: GetMachineGUID
0x168026A00: "MyCreateFile failed. Access deni" ??_C@_1EI@PMDHGHAI@?$AAM?$AAy?$AAC?$AAr?$AAe?$AAa?$AAt?$AAe?$AAF?$AAi?$AAl?$AAe?$AA?5?$AAf?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?4?$AA?5?$AAA?$AAc?$AAc?$AAe?$AAs?$AAs?$AA?5?$AAd?$AAe?$AAn?$AAi@
0x1680060D0: CPGetUserKey
0x168023728: "__cdecl _imp_GetSecurityDescriptorGroup" __imp_GetSecurityDescriptorGroup
0x1680291B8: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-heap-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-heap-l1-1-0
0x16800662C: "__cdecl _imp_load_ConvertSidToStringSidW" __imp_load_ConvertSidToStringSidW
0x168023650: "__cdecl _imp_DeleteCriticalSection" __imp_DeleteCriticalSection
0x16801A680: CPSetProvParam
0x168006250: "__cdecl _security_check_cookie" __security_check_cookie
0x1680237C0: "__cdecl _imp_BCryptExportKey" __imp_BCryptExportKey
0x168023FE0: g_RsaStrongPolicy
0x1680292A8: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-heap-l2-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-heap-l2-1-0
0x1680235C8: api-ms-win-core-processthreads-l1-1-0_NULL_THUNK_DATA
0x1680037F0: CPGetKeyParam
0x168023D18: "Successfully created file." ??_C@_1DG@IIJLIMDJ@?$AAS?$AAu?$AAc?$AAc?$AAe?$AAs?$AAs?$AAf?$AAu?$AAl?$AAl?$AAy?$AA?5?$AAc?$AAr?$AAe?$AAa?$AAt?$AAe?$AAd?$AA?5?$AAf?$AAi?$AAl?$AAe?$AA?4?$AA?$AA@
0x168026DC0: WPP_85099a1de925389737c460ad439781f9_Traceguids
0x168023CC0: "Opened file in storage area succ" ??_C@_1FE@BHNIHKOL@?$AAO?$AAp?$AAe?$AAn?$AAe?$AAd?$AA?5?$AAf?$AAi?$AAl?$AAe?$AA?5?$AAi?$AAn?$AA?5?$AAs?$AAt?$AAo?$AAr?$AAa?$AAg?$AAe?$AA?5?$AAa?$AAr?$AAe?$AAa?$AA?5?$AAs?$AAu?$AAc?$AAc@
0x168023548: "__cdecl _imp_GetProcAddress" __imp_GetProcAddress
0x168011D34: LoadRSAStrings
0x168005374: ContFree
0x16800694F: "__cdecl _imp_load_GetNamedSecurityInfoW" __imp_load_GetNamedSecurityInfoW
0x168023F50: "RSA" ??_C@_17CEGMJBCM@?$AAR?$AAS?$AAA?$AA?$AA@
0x168020594: SecureChannelDeriveKey
0x168003B98: WppCleanupUm
0x1680119E4: I_PrivKeyCacheLock
0x168025CE0: g_RsaSigPolicy
0x1680036F0: uninitBCryptAlgorithmProviderCache
0x1680234E0: "__cdecl _imp_HeapReAlloc" __imp_HeapReAlloc
0x168023508: "__cdecl _imp_LocalAlloc" __imp_LocalAlloc
0x1680238A8: "__cdecl _imp_EtwGetTraceEnableLevel" __imp_EtwGetTraceEnableLevel
0x16802B7F8: "__cdecl _hmod__SspiCli_dll" __hmod__SspiCli_dll
0x168023420: "__cdecl _imp_DelayLoadFailureHook" __imp_DelayLoadFailureHook
0x1680234F0: "__cdecl _imp_GetProcessHeap" __imp_GetProcessHeap
0x168006C9B: "__cdecl _chkstk" __chkstk
0x168020DB0: ApplyPadding
0x168028BCC: "__cdecl _DELAY_IMPORT_DESCRIPTOR_api_ms_win_security_provider_l1_1_0_dll" __DELAY_IMPORT_DESCRIPTOR_api_ms_win_security_provider_l1_1_0_dll
0x168028C40: CRYPTBASE_NULL_THUNK_DATA_DLN
0x168023488: "__cdecl _imp_FindNextFileW" __imp_FindNextFileW
0x168021950: RSADecryptExponentOfOne
0x1680212F4: OAEPEncryptExponentOfOne
0x16802B010: ETW_LOG_RSAENH_CONTMAN_PROVIDER_Context
0x168028B2C: "__cdecl _DELAY_IMPORT_DESCRIPTOR_CRYPTBASE_dll" __DELAY_IMPORT_DESCRIPTOR_CRYPTBASE_dll
0x168023560: api-ms-win-core-localization-obsolete-l1-2-0_NULL_THUNK_DATA
0x168026118: ETW_LOG_RSAENH_CONTMAN_WRITE_CONTAINER_INFO
0x168026138: ETW_LOG_RSAENH_CONTMAN_DELETE_FILE_IN_STORAGE_AREA
0x168023568: "__cdecl _imp_UnmapViewOfFile" __imp_UnmapViewOfFile
0x168010A84: GetKeySizeForEncryptMemory
0x16802B880: l_LoadStringCritSec
0x1680261C8: ETW_LOG_RSAENH_CONTMAN_MY_CREATE_FILE
0x168026F40: "key expansion" ??_C@_0O@EOHBJBLD@key?5expansion?$AA@
0x168010958: FreeContainerInfo
0x168023DC0: "__cdecl _sz_USERENV_dll" __sz_USERENV_dll
0x1680180D0: CPDeriveKey
0x168023608: "__cdecl _imp_MultiByteToWideChar" __imp_MultiByteToWideChar
0x1680260D8: "OffloadModExpo" ??_C@_0P@GJIHJPHL@OffloadModExpo?$AA@
0x168026050: "\Microsoft\Crypto\DSS\" ??_C@_1CO@CACJLLID@?$AA?2?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAC?$AAr?$AAy?$AAp?$AAt?$AAo?$AA?2?$AAD?$AAS?$AAS?$AA?2?$AA?$AA@
0x1680116F8: GetUserTextualSidW
0x1680143B8: McTemplateU0zqstqz
0x1680026C0: findEntryInCache
0x168023960: "__cdecl _guard_fids_table" __guard_fids_table
0x168023900: "__cdecl _imp_wcscpy_s" __imp_wcscpy_s
0x16800F688: DeleteContainerInfo
0x16801477C: McTemplateU0ztqzzqz
0x168026F30: "master secret" ??_C@_0O@FEJGMKDJ@master?5secret?$AA@
0x168023010: "__cdecl load_config_used" _load_config_used
0x168001140: NTLValidate
0x168028C70: SspiCli_NULL_THUNK_DATA_DLN
0x168026F50: "server write key" ??_C@_0BB@HLBNJBJK@server?5write?5key?$AA@
0x168028B0C: "__cdecl _DELAY_IMPORT_DESCRIPTOR_api_ms_win_security_sddl_l1_1_0_dll" __DELAY_IMPORT_DESCRIPTOR_api_ms_win_security_sddl_l1_1_0_dll
0x168015E58: LocalEncrypt
0x16801B440: GetRC4KeyForSymWrap
0x1680142B0: McTemplateU0zqqtqz
0x1680154A8: LocalDecrypt
0x168023438: api-ms-win-core-delayload-l1-1-1_NULL_THUNK_DATA
0x168023428: api-ms-win-core-delayload-l1-1-0_NULL_THUNK_DATA
0x168003C6C: McGenEventUnregister
0x1680220EC: LocalCreateBCryptHash
0x1680268C0: "Failed to delete key container b" ??_C@_1JG@KKBLFBAC@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAd?$AAe?$AAl?$AAe?$AAt?$AAe?$AA?5?$AAk?$AAe?$AAy?$AA?5?$AAc?$AAo?$AAn?$AAt?$AAa?$AAi?$AAn?$AAe?$AAr?$AA?5?$AAb@
0x16801E9AC: HelperHash
0x168021CFC: RemovePadding
0x16802D078: "__cdecl _imp_GetNamedSecurityInfoW" __imp_GetNamedSecurityInfoW
0x1680235F0: "__cdecl _imp_RegQueryValueExA" __imp_RegQueryValueExA
0x1680237A8: "__cdecl _imp_BCryptDuplicateKey" __imp_BCryptDuplicateKey
0x16802D068: "__cdecl _imp_GetProfileType" __imp_GetProfileType
0x16801C594: PreparePrivateKeyForExport
0x168028EA0: profapi_NULL_THUNK_DATA_DLB
0x168026C60: "Successfully wrote container inf" ??_C@_1EG@GDLGDCOO@?$AAS?$AAu?$AAc?$AAc?$AAe?$AAs?$AAs?$AAf?$AAu?$AAl?$AAl?$AAy?$AA?5?$AAw?$AAr?$AAo?$AAt?$AAe?$AA?5?$AAc?$AAo?$AAn?$AAt?$AAa?$AAi?$AAn?$AAe?$AAr?$AA?5?$AAi?$AAn?$AAf@
0x16802D010: CRYPT32_NULL_THUNK_DATA_DLA
0x168013134: TryDPAPI
0x168004A10: InitializeForceHighProtection
0x1680237F8: "__cdecl _imp_BCryptOpenAlgorithmProvider" __imp_BCryptOpenAlgorithmProvider
0x168006803: "__cdecl _imp_load_CryptProtectData" __imp_load_CryptProtectData
0x1680019B0: NTLMakeItem
0x16801CB64: UnWrapSymKey
0x16801B75C: ImportPrivateKeyOntoUserHandle
0x168023538: "__cdecl _imp_DisableThreadLibraryCalls" __imp_DisableThreadLibraryCalls
0x16801EF8C: P_Hash
0x168023868: "__cdecl _imp_NtClose" __imp_NtClose
0x168026198: ETW_LOG_RSAENH_CONTMAN_READ_CONTAINER_INFO
0x168023520: "__cdecl _imp_LoadStringW" __imp_LoadStringW
0x168026200: "Failed to get user storage area " ??_C@_1IE@OLAKAANK@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAg?$AAe?$AAt?$AA?5?$AAu?$AAs?$AAe?$AAr?$AA?5?$AAs?$AAt?$AAo?$AAr?$AAa?$AAg?$AAe?$AA?5?$AAa?$AAr?$AAe?$AAa?$AA?5@
0x16800665C: "__cdecl _tailMerge_cryptbase_dll" __tailMerge_cryptbase_dll
0x168010A3C: FreeEnumOldMachKeyEntries
0x1680238E8: "__cdecl _imp_RtlLookupFunctionEntry" __imp_RtlLookupFunctionEntry
0x168023820: "__cdecl _imp_BCryptGenerateSymmetricKey" __imp_BCryptGenerateSymmetricKey
0x16801724C: CopyHash
0x168026CF0: "Successfully deleted container i" ??_C@_1EK@IOMBJHOK@?$AAS?$AAu?$AAc?$AAc?$AAe?$AAs?$AAs?$AAf?$AAu?$AAl?$AAl?$AAy?$AA?5?$AAd?$AAe?$AAl?$AAe?$AAt?$AAe?$AAd?$AA?5?$AAc?$AAo?$AAn?$AAt?$AAa?$AAi?$AAn?$AAe?$AAr?$AA?5?$AAi@
0x1680238B8: "__cdecl _imp_EtwGetTraceEnableFlags" __imp_EtwGetTraceEnableFlags
0x1680148E0: McTemplateU0ztzqqqqqz
0x168023670: "__cdecl _imp_InitializeSRWLock" __imp_InitializeSRWLock
0x168023570: "__cdecl _imp_VirtualAlloc" __imp_VirtualAlloc
0x168002520: NTLCheckList
0x1680122D8: PrivKeyCacheAddItem
0x168003770: CPReleaseContext
0x168023730: "__cdecl _imp_GetSecurityDescriptorSacl" __imp_GetSecurityDescriptorSacl
0x168014640: McTemplateU0zqztqz
0x168006784: "__cdecl _tailMerge_crypt32_dll" __tailMerge_crypt32_dll
0x168023578: "__cdecl _imp_CreateFileMappingW" __imp_CreateFileMappingW
0x168003B3C: PrivKeyCacheCleanup
0x168002E30: CPDestroyHash
0x168023590: "__cdecl _imp_VirtualQuery" __imp_VirtualQuery
0x1680238F0: "__cdecl _imp_RtlVirtualUnwind" __imp_RtlVirtualUnwind
0x168027060: "__cdecl _pfnDefaultDliFailureHook2" __pfnDefaultDliFailureHook2
0x1680153F0: CPEncrypt
0x168023FC0: "RC2" ??_C@_17FODAJMMF@?$AAR?$AAC?$AA2?$AA?$AA@
0x168028B6C: "__cdecl _DELAY_IMPORT_DESCRIPTOR_CRYPT32_dll" __DELAY_IMPORT_DESCRIPTOR_CRYPT32_dll
0x168019BB0: CPSetKeyParam
0x1680065AD: "__cdecl _tailMerge_api_ms_win_security_sddl_l1_1_0_dll" __tailMerge_api_ms_win_security_sddl_l1_1_0_dll
0x168018B40: CPGetProvParam
0x168006B70: "__cdecl guard_check_icall_nop" _guard_check_icall_nop
0x168006CA7: memcmp
0x168023690: "__cdecl _imp_GetSystemDirectoryW" __imp_GetSystemDirectoryW
0x1680260B8: "csp" ??_C@_17CCDAFIDN@?$AAc?$AAs?$AAp?$AA?$AA@
0x168005CA8: ContAlloc
0x1680261A8: ETW_LOG_RSAENH_CONTMAN_SET_SECURITY_ON_CONTAINER
0x1680237B8: "__cdecl _imp_BCryptGenerateKeyPair" __imp_BCryptGenerateKeyPair
0x168004D2C: AddMachineGuidAndAppContainerSidHashToContainerName
0x16802B8A8: Microsoft_Windows_Crypto_RSAEnhEnableBits
0x16802D098: "__cdecl _imp_ConvertStringSecurityDescriptorToSecurityDescriptorW" __imp_ConvertStringSecurityDescriptorToSecurityDescriptorW
0x168026128: ETW_LOG_RSAENH_CONTMAN_DELETE_FILE_W
0x168005D4C: GetHashValue
0x16802B810: g_ulMaxStackAllocSize
0x168029294: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-handle-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-handle-l1-1-0
0x168026290: "Failed to get user storage area " ??_C@_1JA@FHMHCOMG@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAg?$AAe?$AAt?$AA?5?$AAu?$AAs?$AAe?$AAr?$AA?5?$AAs?$AAt?$AAo?$AAr?$AAa?$AAg?$AAe?$AA?5?$AAa?$AAr?$AAe?$AAa?$AA?5@
0x168025F6C: "dwSts" ??_C@_05BIPIGFDK@dwSts?$AA@
0x168013D60: EtwLogContmanDeleteFileInStorageArea
0x168021EB4: HashTwoValues
0x168028B8C: "__cdecl _DELAY_IMPORT_DESCRIPTOR_SspiCli_dll" __DELAY_IMPORT_DESCRIPTOR_SspiCli_dll
0x1680053A4: MyCreateFile
0x1680238D0: "__cdecl _imp_RtlImageNtHeader" __imp_RtlImageNtHeader
0x168023D50: "Hj1diQ6kpUx7VC4m" ??_C@_0BB@IBKHNDLF@Hj1diQ6kpUx7VC4m?$AA@
0x1680238F8: "__cdecl _imp_RtlUnhandledExceptionFilter" __imp_RtlUnhandledExceptionFilter
0x168006778: "__cdecl _imp_load_CryptUnprotectData" __imp_load_CryptUnprotectData
0x168023948: ntdll_NULL_THUNK_DATA
0x168023938: "__cdecl _imp_memcpy" __imp_memcpy
0x16802D000: "__cdecl _imp_CryptProtectData" __imp_CryptProtectData
0x168023708: "__cdecl _imp_GetSecurityDescriptorDacl" __imp_GetSecurityDescriptorDacl
0x1680056CC: ReadContainerInfo
0x168023F70: "MD5" ??_C@_17HLHJLHED@?$AAM?$AAD?$AA5?$AA?$AA@
0x16801AB24: CheckDataLenForRSAEncrypt
0x1680014C0: BCryptOpenAndCacheAlgorithmProvider
0x168003160: CPHashData
0x16801D340: WrapSymKey
0x168006839: "__cdecl _imp_load_GetUserNameExA" __imp_load_GetUserNameExA
0x1680236F0: "__cdecl _imp_FreeSid" __imp_FreeSid
0x168023C10: "Software\Policies\Microsoft\Cryp" ??_C@_0CJ@HELPIGDA@Software?2Policies?2Microsoft?2Cryp@
0x168023750: "__cdecl _imp_GetSidSubAuthorityCount" __imp_GetSidSubAuthorityCount
0x168026CB0: "Failed to write container info." ??_C@_1EA@OEJLDHEC@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAw?$AAr?$AAi?$AAt?$AAe?$AA?5?$AAc?$AAo?$AAn?$AAt?$AAa?$AAi?$AAn?$AAe?$AAr?$AA?5?$AAi?$AAn?$AAf?$AAo?$AA?4?$AA?$AA@
0x1680291CC: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-synch-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-synch-l1-1-0
0x16801DA38: ApplyX931SigningFormat
0x16802D088: api-ms-win-security-provider-l1-1-0_NULL_THUNK_DATA_DLA
0x1680138A4: ZeroizeFile
0x16802B060: "__cdecl _security_cookie" __security_cookie
0x16802B818: g_pfnAllocate
0x168028E58: USERENV_NULL_THUNK_DATA_DLB
0x168023848: "__cdecl _imp_strcpy_s" __imp_strcpy_s
0x168026620: "Failed to delete file in storage" ??_C@_1GM@GNKNPGNL@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAd?$AAe?$AAl?$AAe?$AAt?$AAe?$AA?5?$AAf?$AAi?$AAl?$AAe?$AA?5?$AAi?$AAn?$AA?5?$AAs?$AAt?$AAo?$AAr?$AAa?$AAg?$AAe@
0x168010124: EnumOldMachineKeys
0x168010538: FetchString
0x16801ACE0: CopyKey
0x1680234D0: "__cdecl _imp_CloseHandle" __imp_CloseHandle
0x168023510: "__cdecl _imp_LocalFree" __imp_LocalFree
0x168005604: GetFilePath
0x168023718: "__cdecl _imp_GetLengthSid" __imp_GetLengthSid
0x168027070: "__stdcall _xmm" __xmm@36363636363636363636363636363636
0x168027080: "__cdecl _xmm@5c5c5c5c5c5c5c5c5c5c5c5c5c5c5c5c" __xmm@5c5c5c5c5c5c5c5c5c5c5c5c5c5c5c5c
0x168029280: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-errorhandling-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-errorhandling-l1-1-0
0x1680140A0: McGenControlCallbackV2
0x16801B2E0: FIsLegalKey
0x1680264F0: "Failed to open file in storage a" ??_C@_1EK@EMMGFDNF@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAo?$AAp?$AAe?$AAn?$AA?5?$AAf?$AAi?$AAl?$AAe?$AA?5?$AAi?$AAn?$AA?5?$AAs?$AAt?$AAo?$AAr?$AAa?$AAg?$AAe?$AA?5?$AAa@
0x16802271C: ReverseMemCpy
0x168006522: "__cdecl _tailMerge_rpcrt4_dll" __tailMerge_rpcrt4_dll
0x168023470: "__cdecl _imp_FindFirstFileExW" __imp_FindFirstFileExW
0x1680235E0: "__cdecl _imp_RegCreateKeyExA" __imp_RegCreateKeyExA
0x1680237C8: "__cdecl _imp_BCryptImportKeyPair" __imp_BCryptImportKeyPair
0x1680069DA: "__cdecl _imp_load_SetNamedSecurityInfoW" __imp_load_SetNamedSecurityInfoW
0x16801B230: FIsLegalImportSymKey
0x168025860: g_RsaBasePolicy
0x168023ED0: WPP_afe1e5f5a2923515a5b5050d21a5feac_Traceguids
0x168023C70: "_" ??_C@_13ENNFDPBH@?$AA_?$AA?$AA@
0x168012C1C: SetContainerUserName
0x168006210: IsLegalLength
0x168023918: "__cdecl _imp__vsnwprintf" __imp__vsnwprintf
0x168023DF0: "__cdecl _sz_profapi_dll" __sz_profapi_dll
0x168023E38: WPP_45c25558380f30f3bd7b5aadaf132a5e_Traceguids
0x1680263F0: "Failed to open file in storage a" ??_C@_1GI@BBHCNNCD@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAo?$AAp?$AAe?$AAn?$AA?5?$AAf?$AAi?$AAl?$AAe?$AA?5?$AAi?$AAn?$AA?5?$AAs?$AAt?$AAo?$AAr?$AAa?$AAg?$AAe?$AA?5?$AAa@
0x16801B090: ExportOpaqueBlob
0x168002B90: CPGetHashParam
0x1680235C0: "__cdecl _imp_GetCurrentThread" __imp_GetCurrentThread
0x16802D048: "__cdecl _imp_RpcStringFreeA" __imp_RpcStringFreeA
0x168028CB0: api-ms-win-security-sddl-l1-1-0_NULL_THUNK_DATA_DLN
0x16801523C: WPP_SF_qS
0x16801B428: GetLengthOfPrivateKeyForExport
0x1680235D0: "__cdecl _imp_RegOpenKeyExA" __imp_RegOpenKeyExA
0x168026108: ETW_LOG_RSAENH_CONTMAN_OPEN_FILE_IN_STORAGE_AREA
0x1680237B0: "__cdecl _imp_BCryptFinalizeKeyPair" __imp_BCryptFinalizeKeyPair
0x16801EAEC: MyPrimitiveHMACParam
0x16801C28C: MakeKeyRSABaseCompatible
0x1680063F0: "__cdecl _security_init_cookie" __security_init_cookie
0x168023FC8: Microsoft_Windows_Crypto_RSAEnhLevels
0x168023A20: "HashDigestLength" ??_C@_1CC@DMMMEHOM@?$AAH?$AAa?$AAs?$AAh?$AAD?$AAi?$AAg?$AAe?$AAs?$AAt?$AAL?$AAe?$AAn?$AAg?$AAt?$AAh?$AA?$AA@
0x168003EF0: NTagLogonUser
0x16801BD78: IsValidBSafePublicKey
0x168023928: "__cdecl _imp___chkstk" __imp___chkstk
0x1680237F0: "__cdecl _imp_BCryptFinishHash" __imp_BCryptFinishHash
0x168023A48: "RSAPUBLICBLOB" ??_C@_1BM@BJJGGDHH@?$AAR?$AAS?$AAA?$AAP?$AAU?$AAB?$AAL?$AAI?$AAC?$AAB?$AAL?$AAO?$AAB?$AA?$AA@
0x168026B60: "Failed to set security on contai" ??_C@_1EK@BPFEACJJ@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAs?$AAe?$AAt?$AA?5?$AAs?$AAe?$AAc?$AAu?$AAr?$AAi?$AAt?$AAy?$AA?5?$AAo?$AAn?$AA?5?$AAc?$AAo?$AAn?$AAt?$AAa?$AAi@
0x168006516: "__cdecl _imp_load_RpcStringFreeA" __imp_load_RpcStringFreeA
0x16802B828: g_pfnFree
0x168023720: "__cdecl _imp_SetSecurityDescriptorDacl" __imp_SetSecurityDescriptorDacl
0x16801C84C: PreparePrivateKeyForImport
0x1680066ED: "__cdecl _imp_load_GetProfileType" __imp_load_GetProfileType
0x168006CCB: wcscmp
0x168024510: g_RsaAesPolicy
0x168010F5C: GetRSAStringResource
0x16802D038: "__cdecl _imp_UuidToStringA" __imp_UuidToStringA
0x168028BAC: "__cdecl _DELAY_IMPORT_DESCRIPTOR_profapi_dll" __DELAY_IMPORT_DESCRIPTOR_profapi_dll
0x168023FA8: "3DES" ??_C@_19LEELFJDG@?$AA3?$AAD?$AAE?$AAS?$AA?$AA@
0x168003BEC: McGenEventRegister
0x168005FE4: MyCryptUnprotectData
0x16801180C: I_PrivKeyCacheCleanupNode
0x168026F90: WPP_1ab965b399613d0e3ba0e9700c9bf2f2_Traceguids
0x1680064FE: RtlVirtualUnwind
0x1680236B8: "__cdecl _imp_EventUnregister" __imp_EventUnregister
0x168023480: "__cdecl _imp_WriteFile" __imp_WriteFile
0x168023F48: "DH" ??_C@_15IEFEGGPE@?$AAD?$AAH?$AA?$AA@
0x168004510: InitUser
0x16800137C: CheckKeyLength
0x168023490: "__cdecl _imp_GetFileSize" __imp_GetFileSize
0x168023DD0: "__cdecl _sz_CRYPT32_dll" __sz_CRYPT32_dll
0x168026F68: "client write key" ??_C@_0BB@DJIGDMHM@client?5write?5key?$AA@
0x16801E134: VerifyX931SigningFormat
0x168026C18: "Failed to read container info." ??_C@_1DO@JFJNDNKC@?$AAF?$AAa?$AAi?$AAl?$AAe?$AAd?$AA?5?$AAt?$AAo?$AA?5?$AAr?$AAe?$AAa?$AAd?$AA?5?$AAc?$AAo?$AAn?$AAt?$AAa?$AAi?$AAn?$AAe?$AAr?$AA?5?$AAi?$AAn?$AAf?$AAo?$AA?4?$AA?$AA@
0x1680062A0: "__cdecl _report_gsfailure" __report_gsfailure
0x168026DB0: WPP_984b219c2d5d32f129d21384e872424c_Traceguids
0x168023630: "__cdecl _imp_LeaveCriticalSection" __imp_LeaveCriticalSection
0x168017ADC: LocalMACData
0x1680066F9: "__cdecl _tailMerge_userenv_dll" __tailMerge_userenv_dll
0x168026038: "%lu" ??_C@_17IJMNDCL@?$AA?$CF?$AAl?$AAu?$AA?$AA@
0x1680038D0: SafeAllocaInitialize
0x168023CA8: "MachineKeys" ??_C@_1BI@NNHJEFPI@?$AAM?$AAa?$AAc?$AAh?$AAi?$AAn?$AAe?$AAK?$AAe?$AAy?$AAs?$AA?$AA@
0x1680203A0: SSL3SingleHash
0x168003990: PrivKeyCacheAllocate
0x168001010: CPSetHashParam
0x168023A68: "SHA256" ??_C@_1O@HECGKAIN@?$AAS?$AAH?$AAA?$AA2?$AA5?$AA6?$AA?$AA@
0x16800FC84: DeleteFileInStorageArea
0x168023D80: "__cdecl _sz_api_ms_win_security_sddl_l1_1_0_dll" __sz_api_ms_win_security_sddl_l1_1_0_dll
0x168023760: "__cdecl _imp_GetAclInformation" __imp_GetAclInformation
0x168002570: InternalVerifyStackAvailable
0x168029244: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-memory-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-memory-l1-1-0
0x168021E0C: GetSymmetricKeyChecksum
0x1680235A8: "__cdecl _imp_OpenThreadToken" __imp_OpenThreadToken
0x168026790: "Deleted key container successful" ??_C@_1EI@GPFEFMJP@?$AAD?$AAe?$AAl?$AAe?$AAt?$AAe?$AAd?$AA?5?$AAk?$AAe?$AAy?$AA?5?$AAc?$AAo?$AAn?$AAt?$AAa?$AAi?$AAn?$AAe?$AAr?$AA?5?$AAs?$AAu?$AAc?$AAc?$AAe?$AAs?$AAs?$AAf?$AAu?$AAl@
0x168015190: DllRegisterServer
0x168023588: "__cdecl _imp_MapViewOfFile" __imp_MapViewOfFile
0x168002470: FIsLegalKeySize
0x168013CC4: EtwLogContmanCreateFileW
0x16802D040: "__cdecl _imp_UuidCreate" __imp_UuidCreate
0x168023710: "__cdecl _imp_InitializeAcl" __imp_InitializeAcl
0x168023EB8: "(DWORD)NTE_BAD_ALGID" ??_C@_0BF@CKGAJJHJ@?$CIDWORD?$CJNTE_BAD_ALGID?$AA@
0x168022750: SafeAllocaAllocateFromHeap
0x168014F64: McTemplateU0zzzqz
0x168026148: WPP_ThisDir_CTLGUID_CNGTraceControlGuid
0x168023688: api-ms-win-core-synch-l1-2-0_NULL_THUNK_DATA
0x168014A50: McTemplateU0zzqqqqqz
0x168014BA4: McTemplateU0zzqtqtqz
0x168013FB4: EtwLogContmanOperationFailed
0x168023B58: "Microsoft Base Cryptographic Pro" ??_C@_0CL@FODAGGJJ@Microsoft?5Base?5Cryptographic?5Pro@
0x168026178: ETW_LOG_RSAENH_CONTMAN_DELETE_CONTAINER_INFO
0x1680235B8: "__cdecl _imp_OpenProcessToken" __imp_OpenProcessToken
0x168023910: "__cdecl _imp_RtlDosPathNameToRelativeNtPathName_U" __imp_RtlDosPathNameToRelativeNtPathName_U
0x168011AF0: I_PrivKeyCachePurgeOldItems
0x168023678: api-ms-win-core-synch-l1-1-0_NULL_THUNK_DATA
0x16802926C: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-synch-l1-2-0" __IMPORT_DESCRIPTOR_api-ms-win-core-synch-l1-2-0
0x168006274: "__cdecl DllMainCRTStartupForGS2" _DllMainCRTStartupForGS2
0x168028EB0: api-ms-win-security-provider-l1-1-0_NULL_THUNK_DATA_DLB
0x168006CBF: memset
0x168029348: "__cdecl _NULL_IMPORT_DESCRIPTOR" __NULL_IMPORT_DESCRIPTOR
0x168023B88: "Microsoft Strong Cryptographic P" ??_C@_0CI@PNHBNEBL@Microsoft?5Strong?5Cryptographic?5P@
0x168023498: "__cdecl _imp_ReadFile" __imp_ReadFile
0x168003CC0: CPAcquireContext
0x16802D070: USERENV_NULL_THUNK_DATA_DLA

[JEB Decompiler by PNF Software]