Generated by JEB on 2019/08/01

PE: C:\Windows\System32\efssvc.dll Base=0x180000000 SHA-256=5F693517EAE2E5A65D13A25432CA6B477A9AE78E4A342238990128059350D2E5
PDB: efssvc.pdb GUID={9BFFFBC4-0BC4-8EA0-E29546DD3F930D25} Age=1

655 located named symbols:
0x18000A371: "__cdecl _imp_load_EfsDllGetUserInfo" __imp_load_EfsDllGetUserInfo
0x180003D00: EdpRpcCredentialCreate
0x1800135F8: "bool (__cdecl* __ptr64 wil::g_pfnIsDebuggerPresent)(void)" ?g_pfnIsDebuggerPresent@wil@@3P6A_NXZEA
0x1800016D4: "public: void __cdecl CEfsService::CleanupService(void) __ptr64" ?CleanupService@CEfsService@@QEAAXXZ
0x180009D98: "__cdecl _raise_securityfailure" __raise_securityfailure
0x18000A401: "__cdecl _imp_load_EdpDllCredentialDelete" __imp_load_EdpDllCredentialDelete
0x18000DE58: api-ms-win-core-file-l1-1-0_NULL_THUNK_DATA
0x18000A4B5: "__cdecl _imp_load_EdpDllQueryDplEnforcedPolicyOwnerIds" __imp_load_EdpDllQueryDplEnforcedPolicyOwnerIds
0x180007F3C: "void __cdecl wil::details::ReportFailure_Hr(void * __ptr64,unsigned int,char const * __ptr64,char const * __ptr64,char const * __ptr64,void * __ptr64,enum wil::FailureType,long)" ?ReportFailure_Hr@details@wil@@YAXPEAXIPEBD110W4FailureType@2@J@Z
0x180009B00: "__cdecl FindPESection" _FindPESection
0x18000FFB0: "h" ??_C@_13CACJPPAP@?$AAh?$AA?$AA@
0x180001620: "public: long __cdecl CEfsService::StopService(void) __ptr64" ?StopService@CEfsService@@QEAAJXZ
0x18000DDE8: "__cdecl _imp_OutputDebugStringW" __imp_OutputDebugStringW
0x180002CB0: EfsRpcQueryProtectors
0x18000A1C1: "__cdecl _imp_load_EfsDllQueryRecoveryAgentsSrv" __imp_load_EfsDllQueryRecoveryAgentsSrv
0x18000E908: "mscn_np" ??_C@_07FKMJGLLK@mscn_np?$AA@
0x18000FAF0: "feclient-EfsEnabledBasic" ??_C@_1DC@HJEENKPO@?$AAf?$AAe?$AAc?$AAl?$AAi?$AAe?$AAn?$AAt?$AA?9?$AAE?$AAf?$AAs?$AAE?$AAn?$AAa?$AAb?$AAl?$AAe?$AAd?$AAB?$AAa?$AAs?$AAi?$AAc?$AA?$AA@
0x180007D64: "long __cdecl StringCchCatW(unsigned short * __ptr64,unsigned __int64,unsigned short const * __ptr64)" ?StringCchCatW@@YAJPEAG_KPEBG@Z
0x1800062F0: "__cdecl _delayLoadHelper2" __delayLoadHelper2
0x180011C88: "__cdecl _IMPORT_DESCRIPTOR_ntdll" __IMPORT_DESCRIPTOR_ntdll
0x180015038: "__cdecl _imp_EfsInitialize" __imp_EfsInitialize
0x18000DEE8: "__cdecl _imp_VirtualProtect" __imp_VirtualProtect
0x180013718: "long volatile `int __cdecl wil::details::RecordException(long)'::`2'::s_hrErrorLast" ?s_hrErrorLast@?1??RecordException@details@wil@@YAHJ@Z@4JC
0x1800071D4: EfsDplAppKeyCachingFeatureEnabled
0x180013020: "__cdecl _security_cookie_complement" __security_cookie_complement
0x18000DE20: "__cdecl _imp_RaiseException" __imp_RaiseException
0x1800089F0: EfsKRpcEstablishRpcConnection
0x1800136D8: g_AdminSid
0x18000E5B0: "ncalrpc" ??_C@_1BA@EONDGCCM@?$AAn?$AAc?$AAa?$AAl?$AAr?$AAp?$AAc?$AA?$AA@
0x180015118: "__cdecl _imp_EfsDllFreeUserInfo" __imp_EfsDllFreeUserInfo
0x1800095BC: "__cdecl CRT_INIT" _CRT_INIT
0x1800091AC: EfspDecryptFek
0x18000DF20: "__cdecl _imp_GetCurrentThreadId" __imp_GetCurrentThreadId
0x18000DD98: "__cdecl _imp_NdrServerCallAll" __imp_NdrServerCallAll
0x180003A40: EfsRpcFlushEfsCache
0x180008808: "void __cdecl wil::details::in1diag3::_FailFast_GetLastError(void * __ptr64,unsigned int,char const * __ptr64)" ?_FailFast_GetLastError@in1diag3@details@wil@@YAXPEAXIPEBD@Z
0x1800137E4: DloadSectionOldProtection
0x180015208: "__cdecl _imp_EdpDllRmsContainerizeFile" __imp_EdpDllRmsContainerizeFile
0x18000E148: "__cdecl _imp_RtlInitUnicodeString" __imp_RtlInitUnicodeString
0x18000A305: "__cdecl _imp_load_EdpDllRmsDecontainerizeFile" __imp_load_EdpDllRmsDecontainerizeFile
0x18000A790: "__cdecl guard_dispatch_icall_nop" _guard_dispatch_icall_nop
0x18000DD88: "__cdecl _imp_RpcServerRegisterAuthInfoW" __imp_RpcServerRegisterAuthInfoW
0x180003DF0: EdpRpcCredentialQuery
0x180002B40: EfsRpcQueryRecoveryAgents
0x18000A33B: "__cdecl _imp_load_EdpDllQueryRevokedPolicyOwnerIds" __imp_load_EdpDllQueryRevokedPolicyOwnerIds
0x1800137E8: DloadSectionLockCount
0x18000A19D: "__cdecl _imp_load_EdpDllGetTfaCache" __imp_load_EdpDllGetTfaCache
0x180001DF0: EfsRpcOpenFileRaw
0x180013000: "class wil::details_abi::ProcessLocalStorage<struct wil::details_abi::ProcessLocalData> wil::details::g_processLocalData" ?g_processLocalData@details@wil@@3V?$ProcessLocalStorage@UProcessLocalData@details_abi@wil@@@details_abi@2@A
0x18000857C: "void __cdecl wil::details::WilRaiseFailFastException(struct _EXCEPTION_RECORD * __ptr64,struct _CONTEXT * __ptr64,unsigned long)" ?WilRaiseFailFastException@details@wil@@YAXPEAU_EXCEPTION_RECORD@@PEAU_CONTEXT@@K@Z
0x180015088: "__cdecl _imp_EfsDllWriteEncryptedFileWithHeader" __imp_EfsDllWriteEncryptedFileWithHeader
0x18000FF78: "" ??_C@_00CNPNBAHC@?$AA@
0x18000A2CF: "__cdecl _imp_load_EdpDllDplUserCredentialsSet" __imp_load_EdpDllDplUserCredentialsSet
0x18000DE48: api-ms-win-core-featurestaging-l1-1-0_NULL_THUNK_DATA
0x18000A4EB: "__cdecl _imp_load_EfsDllReprotectFile" __imp_load_EfsDllReprotectFile
0x18000FF80: "__cdecl _pfnDliFailureHook2" __pfnDliFailureHook2
0x18000DEB0: "__cdecl _imp_GetModuleFileNameA" __imp_GetModuleFileNameA
0x18000A425: "__cdecl _imp_load_EdpDllGetLockSessionWrappedKey" __imp_load_EdpDllGetLockSessionWrappedKey
0x180010058: "Local\SM0:%d:%d:%hs" ??_C@_1CI@EOLMILME@?$AAL?$AAo?$AAc?$AAa?$AAl?$AA?2?$AAS?$AAM?$AA0?$AA?3?$AA?$CF?$AAd?$AA?3?$AA?$CF?$AAd?$AA?3?$AA?$CF?$AAh?$AAs?$AA?$AA@
0x1800089C0: "void __cdecl EfsxLibFree(void * __ptr64)" ?EfsxLibFree@@YAXPEAX@Z
0x180013760: "class wil::details_abi::ThreadLocalStorage<class wil::details::ThreadFailureCallbackHolder * __ptr64> wil::details::g_threadFailureCallbacks" ?g_threadFailureCallbacks@details@wil@@3V?$ThreadLocalStorage@PEAVThreadFailureCallbackHolder@details@wil@@@details_abi@2@A
0x180011C74: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-file-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-file-l1-1-0
0x180002990: EfsRpcDecryptFileSrv
0x180015140: "__cdecl _imp_EfsDllQueryProtectorsSrv" __imp_EfsDllQueryProtectorsSrv
0x18000DE98: api-ms-win-core-heap-l2-1-0_NULL_THUNK_DATA
0x1800151A0: "__cdecl _imp_EdpDllGetCredServiceState" __imp_EdpDllGetCredServiceState
0x180015210: "__cdecl _imp_EdpDllRmsGetContainerIdentity" __imp_EdpDllRmsGetContainerIdentity
0x180015218: EFSCORE_NULL_THUNK_DATA_DLA
0x180015220: "__cdecl _imp_EfsClientFileEncryptionStatus" __imp_EfsClientFileEncryptionStatus
0x18000DFA0: "__cdecl _imp_SetEvent" __imp_SetEvent
0x1800151E8: "__cdecl _imp_EdpDllServiceFileEncryptionQueue" __imp_EdpDllServiceFileEncryptionQueue
0x18000E180: "__cdecl _guard_dispatch_icall_fptr" __guard_dispatch_icall_fptr
0x180013728: "long volatile `int __cdecl wil::details::RecordLog(long)'::`2'::s_hrErrorLast" ?s_hrErrorLast@?1??RecordLog@details@wil@@YAHJ@Z@4JC
0x180015150: "__cdecl _imp_EdpDllDplUserUnlockStart" __imp_EdpDllDplUserUnlockStart
0x180001810: "private: long __cdecl CEfsService::NotifyDriverServiceReady(void) __ptr64" ?NotifyDriverServiceReady@CEfsService@@AEAAJXZ
0x18000A040: NdrServerCall2
0x180010168: "Msg:[%ws] " ??_C@_1BG@MCLOHHAM@?$AAM?$AAs?$AAg?$AA?3?$AA?$FL?$AA?$CF?$AAw?$AAs?$AA?$FN?$AA?5?$AA?$AA@
0x180011A78: FeClient_NULL_THUNK_DATA_DLB
0x180015228: FeClient_NULL_THUNK_DATA_DLA
0x180011020: FeClient_NULL_THUNK_DATA_DLN
0x18000DED8: "__cdecl _imp_FormatMessageW" __imp_FormatMessageW
0x180006CDC: "public: __cdecl wil::details_abi::ThreadLocalData::~ThreadLocalData(void) __ptr64" ??1ThreadLocalData@details_abi@wil@@QEAA@XZ
0x1800036A0: EfsRpcFileKeyInfoEx
0x18000DEB8: "__cdecl _imp_GetModuleHandleExW" __imp_GetModuleHandleExW
0x1800136C0: g_hPublisher
0x180003FD0: EdpRpcCredentialDelete
0x1800015E0: "private: static long __cdecl CEfsService::ServiceStopCallback(void * __ptr64)" ?ServiceStopCallback@CEfsService@@CAJPEAX@Z
0x18000E050: "__cdecl _imp_RegisterServiceCtrlHandlerExW" __imp_RegisterServiceCtrlHandlerExW
0x180009AE8: "__cdecl XcptFilter" _XcptFilter
0x180005A90: EdpRpcWriteLogSiteLearningEvents
0x1800019BC: "long __cdecl EfsRpcRegisterServer(void * __ptr64)" ?EfsRpcRegisterServer@@YAJPEAX@Z
0x18000E188: "__cdecl _xc_a" __xc_a
0x18000A04C: "__cdecl _imp_load_BCryptFinishHash" __imp_load_BCryptFinishHash
0x180013740: "void (__cdecl* __ptr64 g_wil_details_apiSubscribeFeatureStateChangeNotification)(struct FEATURE_STATE_CHANGE_SUBSCRIPTION__ * __ptr64 * __ptr64,void (__cdecl*)(void * __ptr64),void * __ptr64)" ?g_wil_details_apiSubscribeFeatureStateChangeNotification@@3P6AXPEAPEAUFEATURE_STATE_CHANGE_SUBSCRIPTION__@@P6AXPEAX@Z1@ZEA
0x180013640: "void (__cdecl* __ptr64 wil::details::g_pfnOriginateCallback)(struct wil::FailureInfo const & __ptr64)" ?g_pfnOriginateCallback@details@wil@@3P6AXAEBUFailureInfo@2@@ZEA
0x180010098: "ReturnHr" ??_C@_08KFPKLAKH@ReturnHr?$AA@
0x180015078: "__cdecl _imp_EfsDllQueryRecoveryAgentsSrv" __imp_EfsDllQueryRecoveryAgentsSrv
0x1800071A0: "void __cdecl wil::details::RecordSRUMFeatureUsage(unsigned int,unsigned int,unsigned int)" ?RecordSRUMFeatureUsage@details@wil@@YAXIII@Z
0x18000E0F0: "__cdecl _imp_RtlValidRelativeSecurityDescriptor" __imp_RtlValidRelativeSecurityDescriptor
0x180006F54: "public: static bool __cdecl wil::details::ThreadFailureCallbackHolder::GetThreadContext(struct wil::FailureInfo * __ptr64,class wil::details::ThreadFailureCallbackHolder * __ptr64,char * __ptr64,unsigned __int64)" ?GetThreadContext@ThreadFailureCallbackHolder@details@wil@@SA_NPEAUFailureInfo@3@PEAV123@PEAD_K@Z
0x180015240: "__cdecl _imp_BCryptCreateHash" __imp_BCryptCreateHash
0x18000E3F8: "RaiseFailFastException" ??_C@_0BH@EEDPADAA@RaiseFailFastException?$AA@
0x180011CC4: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-featurestaging-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-featurestaging-l1-1-0
0x180007BEC: "unsigned char * __ptr64 __cdecl wil::details::WriteResultString<char const * __ptr64>(unsigned char * __ptr64,unsigned char * __ptr64,char const * __ptr64,char const * __ptr64 * __ptr64)" ??$WriteResultString@PEBD@details@wil@@YAPEAEPEAE0PEBDPEAPEBD@Z
0x18000E3C0: "__cdecl _sz_FeClient_dll" __sz_FeClient_dll
0x18000DE40: "__cdecl _imp_SubscribeFeatureStateChangeNotification" __imp_SubscribeFeatureStateChangeNotification
0x180015058: "__cdecl _imp_EfsDllReadFileRaw" __imp_EfsDllReadFileRaw
0x18000DE88: api-ms-win-core-heap-l1-1-0_NULL_THUNK_DATA
0x18000A45B: "__cdecl _imp_load_EdpDllGetCredServiceState" __imp_load_EdpDllGetCredServiceState
0x180009F57: "__cdecl lock" _lock
0x180013608: g_pfnResultLoggingCallback
0x1800150C8: "__cdecl _imp_EdpDllQueueFileForEncryption" __imp_EdpDllQueueFileForEncryption
0x180011880: EFSCORE_NULL_THUNK_DATA_DLB
0x1800100B0: "FailFast" ??_C@_08IAOKKAJK@FailFast?$AA@
0x18000A23F: "__cdecl _imp_load_EfsDllIsConsumerProtectionEnforced" __imp_load_EfsDllIsConsumerProtectionEnforced
0x1800136F8: DloadSrwLock
0x18000E460: EFS_SERVICE_START_FAILED
0x180009AD0: "__cdecl callnewh" _callnewh
0x18000E380: "__cdecl _guard_iat_table" __guard_iat_table
0x18000A011: "__cdecl _imp_load_BCryptCloseAlgorithmProvider" __imp_load_BCryptCloseAlgorithmProvider
0x180013611: "bool wil::details::g_resultMessageCallbackSet" ?g_resultMessageCallbackSet@details@wil@@3_NA
0x18000A766: memcpy
0x1800150B0: "__cdecl _imp_EfsDllIsConsumerProtectionEnforced" __imp_EfsDllIsConsumerProtectionEnforced
0x1800036A0: EfsRpcNotSupported
0x180004220: EdpResolveAppHashForAppKeyCaching
0x18000A131: "__cdecl _imp_load_EfsInitialize" __imp_load_EfsInitialize
0x180006D74: "public: void __cdecl wil::details_abi::ThreadLocalData::SetLastError(struct wil::FailureInfo const & __ptr64) __ptr64" ?SetLastError@ThreadLocalData@details_abi@wil@@QEAAXAEBUFailureInfo@3@@Z
0x18000E410: "kernelbase.dll" ??_C@_1BO@MFOKJHPK@?$AAk?$AAe?$AAr?$AAn?$AAe?$AAl?$AAb?$AAa?$AAs?$AAe?$AA?4?$AAd?$AAl?$AAl?$AA?$AA@
0x18000E060: "__cdecl _imp_memset" __imp_memset
0x18000DF98: "__cdecl _imp_WaitForSingleObjectEx" __imp_WaitForSingleObjectEx
0x18000DFB8: "__cdecl _imp_CreateEventW" __imp_CreateEventW
0x18000A449: "__cdecl _imp_load_EfsDllShareDecline" __imp_load_EfsDllShareDecline
0x1800137E0: DloadSectionCommitPermanent
0x180009CCC: "__cdecl initterm" _initterm
0x180011C4C: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-sysinfo-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-sysinfo-l1-1-0
0x1800137D0: "__cdecl _dyn_tls_init_callback" __dyn_tls_init_callback
0x180015080: "__cdecl _imp_EfsDllUnloadUserProfile" __imp_EfsDllUnloadUserProfile
0x1800073C8: ?create@?$semaphore_t@V?$unique_storage@U?$resource_policy@PEAXP6AXPEAX@Z$1?CloseHandle@details@wil@@YAX0@ZU?$integral_constant@_K$0A@@wistd@@PEAX$0A@$$T@details@wil@@@details@wil@@Uerr_returncode_policy@3@@wil@@QEAAJJJPEBGKPEAU_SECURITY_ATTRIBUTES@@@Z
0x18000DFD0: "__cdecl _imp_Sleep" __imp_Sleep
0x18000A1D3: "__cdecl _imp_load_EfsDllUnloadUserProfile" __imp_load_EfsDllUnloadUserProfile
0x18000E1D8: "__cdecl _xi_z" __xi_z
0x180013720: "long volatile `int __cdecl wil::details::RecordReturn(long)'::`2'::s_hrErrorLast" ?s_hrErrorLast@?1??RecordReturn@details@wil@@YAHJ@Z@4JC
0x18000A1F7: "__cdecl _imp_load_EdpWriteSiteLearningLog" __imp_load_EdpWriteSiteLearningLog
0x1800150D8: "__cdecl _imp_EdpDllAllowFileAccessForProcess" __imp_EdpDllAllowFileAccessForProcess
0x18000A4FD: "__cdecl _imp_load_EdpDllServiceFileEncryptionQueue" __imp_load_EdpDllServiceFileEncryptionQueue
0x18000DE10: "__cdecl _imp_UnhandledExceptionFilter" __imp_UnhandledExceptionFilter
0x180013638: g_pfnThrowPlatformException
0x180006AE8: "public: void __cdecl wil::details_abi::ThreadLocalFailureInfo::Set(struct wil::FailureInfo const & __ptr64,unsigned int) __ptr64" ?Set@ThreadLocalFailureInfo@details_abi@wil@@QEAAXAEBUFailureInfo@3@I@Z
0x180013730: "long volatile `void __cdecl wil::details::LogFailure(void * __ptr64,unsigned int,char const * __ptr64,char const * __ptr64,char const * __ptr64,void * __ptr64,enum wil::FailureType,long,unsigned short const * __ptr64,bool,unsigned short * __ptr64,unsigned __int64,char * __ptr64,unsigned __int64,struct wil::FailureInfo * __ptr64)'::`2'::s_failureId" ?s_failureId@?1??LogFailure@details@wil@@YAXPEAXIPEBD110W4FailureType@3@JPEBG_NPEAG_KPEAD6PEAUFailureInfo@3@@Z@4JC
0x180009CD8: "__cdecl _C_specific_handler" __C_specific_handler
0x18000A4A3: "__cdecl _imp_load_EfsDllFreeHeap" __imp_load_EfsDllFreeHeap
0x180001C90: MIDL_user_free
0x18000DF88: "__cdecl _imp_ReleaseSRWLockExclusive" __imp_ReleaseSRWLockExclusive
0x18000A317: "__cdecl _imp_load_EdpDllCredSvcControl" __imp_load_EdpDllCredSvcControl
0x18000A491: "__cdecl _imp_load_EdpDllCredentialQuery" __imp_load_EdpDllCredentialQuery
0x18000E910: "\pipe\efsrpc" ??_C@_0N@OMBKJEHN@?2pipe?2efsrpc?$AA@
0x1800101D0: " " ??_C@_13LBAGMAIH@?$AA?6?$AA?$AA@
0x1800150A8: "__cdecl _imp_EfsDllGetLocalFileName" __imp_EfsDllGetLocalFileName
0x18000DFA8: "__cdecl _imp_CreateSemaphoreExW" __imp_CreateSemaphoreExW
0x180013600: "bool wil::g_fIsDebuggerPresent" ?g_fIsDebuggerPresent@wil@@3_NA
0x180007F20: "int __cdecl wil::details::RecordReturn(long)" ?RecordReturn@details@wil@@YAHJ@Z
0x18000E088: "__cdecl _imp__onexit" __imp__onexit
0x18000DE70: "__cdecl _imp_HeapFree" __imp_HeapFree
0x180004540: EdpRpcGetLockSessionWrappedKey
0x180004AE0: EdpRpcDplUpgradeVerifyUser
0x180009AC4: malloc
0x18000DE68: api-ms-win-core-handle-l1-1-0_NULL_THUNK_DATA
0x1800057A0: EdpRpcUnprotectFile
0x18000E168: "__cdecl _imp_NtQueryInformationToken" __imp_NtQueryInformationToken
0x18000A700: "__cdecl _GSHandlerCheckCommon" __GSHandlerCheckCommon
0x18000E140: "__cdecl _imp_NtCreateEvent" __imp_NtCreateEvent
0x180001F70: EfsRpcCloseRaw
0x18000A094: "__cdecl _imp_load_EfsDllOnSessionChange" __imp_load_EfsDllOnSessionChange
0x180004BE0: EdpRpcDplUserCredentialsSet
0x180015098: "__cdecl _imp_EfsDllOefsCheckSupportByFilePath" __imp_EfsDllOefsCheckSupportByFilePath
0x180010080: "wil" ??_C@_03KGBNGMMC@wil?$AA@
0x180013650: "void (__cdecl* __ptr64 wil::details::g_pfnThrowResultException)(struct wil::FailureInfo const & __ptr64)" ?g_pfnThrowResultException@details@wil@@3P6AXAEBUFailureInfo@2@@ZEA
0x180015110: "__cdecl _imp_EdpDllCredSvcControl" __imp_EdpDllCredSvcControl
0x18000E0E8: "__cdecl _imp_RtlAllocateHeap" __imp_RtlAllocateHeap
0x180015090: "__cdecl _imp_EdpWriteSiteLearningLog" __imp_EdpWriteSiteLearningLog
0x18000DE38: "__cdecl _imp_RecordFeatureUsage" __imp_RecordFeatureUsage
0x180011BFC: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-security-base-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-security-base-l1-1-0
0x180009AF4: "__cdecl amsg_exit" _amsg_exit
0x18000E0D0: "__cdecl _imp__callnewh" __imp__callnewh
0x18000E010: "__cdecl _imp_IsWellKnownSid" __imp_IsWellKnownSid
0x180009020: EfsKRpcNotifyEnterpriseFileWrite
0x180003000: EfsRpcAddUsersToFileEx
0x18000E3B0: "__cdecl _sz_EFSCORE_dll" __sz_EFSCORE_dll
0x18000DDF0: "__cdecl _imp_DebugBreak" __imp_DebugBreak
0x180015180: "__cdecl _imp_EfsDllLoadUserProfile" __imp_EfsDllLoadUserProfile
0x18000767C: "public: void __cdecl wil::details_abi::ProcessLocalStorageData<struct wil::details_abi::ProcessLocalData>::Release(void) __ptr64" ?Release@?$ProcessLocalStorageData@UProcessLocalData@details_abi@wil@@@details_abi@wil@@QEAAXXZ
0x18000A46D: "__cdecl _imp_load_EfsDllCloseFileRaw" __imp_load_EfsDllCloseFileRaw
0x18000A263: "__cdecl _imp_load_EfsDllEncryptFileSrv" __imp_load_EfsDllEncryptFileSrv
0x180015010: "__cdecl _imp_EfsDllValidateEfsStream" __imp_EfsDllValidateEfsStream
0x180005D08: EfspCheckForNetSession
0x18000A600: "__cdecl _tailMerge_ext_ms_win_security_efs_l1_1_0_dll" __tailMerge_ext_ms_win_security_efs_l1_1_0_dll
0x18000DF80: "__cdecl _imp_ReleaseSemaphore" __imp_ReleaseSemaphore
0x1800012E0: "void __cdecl wil::details::DebugBreak(void)" ?DebugBreak@details@wil@@YAXXZ
0x18000A2BD: "__cdecl _imp_load_EfsDllUsePinForEncryptedFilesSrv" __imp_load_EfsDllUsePinForEncryptedFilesSrv
0x18000E0A0: "__cdecl _imp__lock" __imp__lock
0x180015188: "__cdecl _imp_EdpDllGetLockSessionWrappedKey" __imp_EdpDllGetLockSessionWrappedKey
0x180015120: "__cdecl _imp_EdpDllQueryRevokedPolicyOwnerIds" __imp_EdpDllQueryRevokedPolicyOwnerIds
0x1800136D0: EfsServerInitialized
0x180009D78: atexit
0x18000A5F4: "__cdecl _imp_load_EfsPlatform_GetCallerID" __imp_load_EfsPlatform_GetCallerID
0x18000A1E5: "__cdecl _imp_load_EfsDllWriteEncryptedFileWithHeader" __imp_load_EfsDllWriteEncryptedFileWithHeader
0x1800019B0: "void __cdecl EfsRpcIdleCallback(void * __ptr64,void * __ptr64,unsigned long)" ?EfsRpcIdleCallback@@YAXPEAX0K@Z
0x180013648: "bool wil::details::g_processShutdownInProgress" ?g_processShutdownInProgress@details@wil@@3_NA
0x18001371C: "long volatile `int __cdecl wil::details::RecordException(long)'::`2'::s_cErrorCount" ?s_cErrorCount@?1??RecordException@details@wil@@YAHJ@Z@4JC
0x18000A18B: "__cdecl _imp_load_EfsDllDecryptFileSrv" __imp_load_EfsDllDecryptFileSrv
0x18000DEA8: "__cdecl _imp_LoadLibraryExA" __imp_LoadLibraryExA
0x180007F8C: "int __cdecl wil::details::RecordLog(long)" ?RecordLog@details@wil@@YAHJ@Z
0x18000E058: api-ms-win-service-core-l1-1-0_NULL_THUNK_DATA
0x180008644: "void __cdecl wil::details::ReportFailure(void * __ptr64,unsigned int,char const * __ptr64,char const * __ptr64,char const * __ptr64,void * __ptr64,enum wil::FailureType,long,unsigned short const * __ptr64,enum wil::details::ReportFailureOptions)" ?ReportFailure@details@wil@@YAXPEAXIPEBD110W4FailureType@2@JPEBGW4ReportFailureOptions@12@@Z
0x180004720: EdpRpcGetLockSessionUnwrappedKey
0x180013710: "class wil::details_abi::ProcessLocalStorage<struct wil::details_abi::ProcessLocalData> * __ptr64 __ptr64 wil::details_abi::g_pProcessLocalData" ?g_pProcessLocalData@details_abi@wil@@3PEAV?$ProcessLocalStorage@UProcessLocalData@details_abi@wil@@@12@EA
0x18000DF48: api-ms-win-core-registry-l1-1-0_NULL_THUNK_DATA
0x180001980: "long __cdecl EfsServiceMain(unsigned long,unsigned short * __ptr64 * __ptr64,struct _LSAP_SERVICE_STOP_CALLBACK_CONTEXT * __ptr64)" ?EfsServiceMain@@YAJKPEAPEAGPEAU_LSAP_SERVICE_STOP_CALLBACK_CONTEXT@@@Z
0x180015178: "__cdecl _imp_EdpDllCredentialDelete" __imp_EdpDllCredentialDelete
0x18000DE28: api-ms-win-core-errorhandling-l1-1-0_NULL_THUNK_DATA
0x18000A35F: "__cdecl _imp_load_EdpDllGetLockSessionUnwrappedKey" __imp_load_EdpDllGetLockSessionUnwrappedKey
0x18000E490: EFS_SL_EFS_DISABLED
0x1800150F0: "__cdecl _imp_EdpDllDplUserCredentialsSet" __imp_EdpDllDplUserCredentialsSet
0x18000E430: EFS_SERVER_READY
0x18000E4B8: "\EFSInitEvent" ??_C@_1BM@POMANDGO@?$AA?2?$AAE?$AAF?$AAS?$AAI?$AAn?$AAi?$AAt?$AAE?$AAv?$AAe?$AAn?$AAt?$AA?$AA@
0x18000A1AF: "__cdecl _imp_load_EfsDllWriteFileRaw" __imp_load_EfsDllWriteFileRaw
0x1800150A0: "__cdecl _imp_EdpDllPurgeAppLearningEvents" __imp_EdpDllPurgeAppLearningEvents
0x18000DFE8: "__cdecl _imp_GetSystemInfo" __imp_GetSystemInfo
0x18000DF18: "__cdecl _imp_GetCurrentProcess" __imp_GetCurrentProcess
0x180009F6F: "__cdecl _dllonexit" __dllonexit
0x180007810: "public: void * __ptr64 __cdecl wil::details_abi::ProcessLocalStorageData<struct wil::details_abi::ProcessLocalData>::`scalar deleting destructor'(unsigned int) __ptr64" ??_G?$ProcessLocalStorageData@UProcessLocalData@details_abi@wil@@@details_abi@wil@@QEAAPEAXI@Z
0x18000A209: "__cdecl _imp_load_EfsDllOefsCheckSupportByFilePath" __imp_load_EfsDllOefsCheckSupportByFilePath
0x1800137C0: "__cdecl _native_startup_lock" __native_startup_lock
0x18000A413: "__cdecl _imp_load_EfsDllLoadUserProfile" __imp_load_EfsDllLoadUserProfile
0x180015248: "__cdecl _imp_BCryptHashData" __imp_BCryptHashData
0x180009CC0: DllMain
0x180009120: EfsKRpcNotifyEnterpriseFileCleanup
0x180013670: "bool (__cdecl* __ptr64 wil::g_pfnWilFailFast)(struct wil::FailureInfo const & __ptr64)" ?g_pfnWilFailFast@wil@@3P6A_NAEBUFailureInfo@1@@ZEA
0x18001372C: "long volatile `int __cdecl wil::details::RecordLog(long)'::`2'::s_cErrorCount" ?s_cErrorCount@?1??RecordLog@details@wil@@YAHJ@Z@4JC
0x18000E3D0: "__cdecl _sz_ext_ms_win_security_efs_l1_1_0_dll" __sz_ext_ms_win_security_efs_l1_1_0_dll
0x18001303C: "private: static long volatile wil::details::ThreadFailureCallbackHolder::s_telemetryId" ?s_telemetryId@ThreadFailureCallbackHolder@details@wil@@0JC
0x18000A545: "__cdecl _imp_load_EdpDllRmsContainerizeFile" __imp_load_EdpDllRmsContainerizeFile
0x18000E070: "__cdecl _imp__wcsicmp" __imp__wcsicmp
0x180013680: "char * `char const * __ptr64 __cdecl wil::details::GetCurrentModuleName(void)'::`2'::s_szModule" ?s_szModule@?1??GetCurrentModuleName@details@wil@@YAPEBDXZ@4PADA
0x18000E0A8: "__cdecl _imp___C_specific_handler" __imp___C_specific_handler
0x180015138: "__cdecl _imp_EfsDllGetUserInfo" __imp_EfsDllGetUserInfo
0x180004170: EdpRpcQueryDplEnforcedPolicyOwnerIds
0x18000DF60: "__cdecl _imp_RtlCaptureContext" __imp_RtlCaptureContext
0x18000A3B9: "__cdecl _imp_load_EfsDllOpenFileRaw" __imp_load_EfsDllOpenFileRaw
0x18000DED0: api-ms-win-core-libraryloader-l1-2-0_NULL_THUNK_DATA
0x18000A155: "__cdecl _imp_load_EfsDllAddUsersToFileSrv" __imp_load_EfsDllAddUsersToFileSrv
0x180011068: ext-ms-win-security-efs-l1-1-0_NULL_THUNK_DATA_DLN
0x1800136F0: "__cdecl _puiHead" __puiHead
0x180015270: ext-ms-win-security-efs-l1-1-0_NULL_THUNK_DATA_DLA
0x180011A88: ext-ms-win-security-efs-l1-1-0_NULL_THUNK_DATA_DLB
0x1800135F0: "__cdecl _@@_PchSym_@00@KxulyqvxgPillgKxulmvxlivfzkUwhUhvxfirgbUvuhUhvierxvUlyquivUznwGEUkivxlnkOlyq@efssvc" __@@_PchSym_@00@KxulyqvxgPillgKxulmvxlivfzkUwhUhvxfirgbUvuhUhvierxvUlyquivUznwGEUkivxlnkOlyq@efssvc
0x18000DE18: "__cdecl _imp_GetLastError" __imp_GetLastError
0x18000952C: "void * __ptr64 __cdecl operator new(unsigned __int64)" ??2@YAPEAX_K@Z
0x18000A557: "__cdecl _imp_load_EdpDllRmsGetContainerIdentity" __imp_load_EdpDllRmsGetContainerIdentity
0x1800150C0: "__cdecl _imp_EfsDllEncryptFileSrv" __imp_EfsDllEncryptFileSrv
0x180013010: "__cdecl _native_dllmain_reason" __native_dllmain_reason
0x18000A6DC: "__cdecl _GSHandlerCheck" __GSHandlerCheck
0x18000DFC0: "__cdecl _imp_OpenSemaphoreW" __imp_OpenSemaphoreW
0x18000E588: "EFSK RPC Interface" ??_C@_1CG@MHFLALFA@?$AAE?$AAF?$AAS?$AAK?$AA?5?$AAR?$AAP?$AAC?$AA?5?$AAI?$AAn?$AAt?$AAe?$AAr?$AAf?$AAa?$AAc?$AAe?$AA?$AA@
0x180015018: "__cdecl _imp_EfsDllErrorToNtStatus" __imp_EfsDllErrorToNtStatus
0x18000A0A0: "__cdecl _tailMerge_efscore_dll" __tailMerge_efscore_dll
0x180008CE0: EfsKRpcGenerateKey
0x180015238: "__cdecl _imp_BCryptCloseAlgorithmProvider" __imp_BCryptCloseAlgorithmProvider
0x18000E440: EFS_API_ERROR
0x180015160: "__cdecl _imp_EdpDllDplUpgradeVerifyUser" __imp_EdpDllDplUpgradeVerifyUser
0x18000DF00: "__cdecl _imp_GetCurrentProcessId" __imp_GetCurrentProcessId
0x18000DFB0: "__cdecl _imp_WaitForSingleObject" __imp_WaitForSingleObject
0x18000A67F: "__cdecl _imp_load_EfsDllDecryptFek" __imp_load_EfsDllDecryptFek
0x180009480: EfspValidateClientCall
0x180005B90: EdpRpcIsConsumerProtectionEnforced
0x18000A6C7: "__cdecl _imp_load_EdpWriteAppLearningLog" __imp_load_EdpWriteAppLearningLog
0x180009BB0: "__cdecl ValidateImageBase" _ValidateImageBase
0x180013700: "class wil::details_abi::ThreadLocalStorage<class wil::details::ThreadFailureCallbackHolder * __ptr64> * __ptr64 __ptr64 wil::details::g_pThreadFailureCallbacks" ?g_pThreadFailureCallbacks@details@wil@@3PEAV?$ThreadLocalStorage@PEAVThreadFailureCallbackHolder@details@wil@@@details_abi@2@EA
0x18000E158: "__cdecl _imp_NtClearEvent" __imp_NtClearEvent
0x1800012F0: "void __cdecl wil::details::WilDynamicLoadRaiseFailFastException(struct _EXCEPTION_RECORD * __ptr64,struct _CONTEXT * __ptr64,unsigned long)" ?WilDynamicLoadRaiseFailFastException@details@wil@@YAXPEAU_EXCEPTION_RECORD@@PEAU_CONTEXT@@K@Z
0x180008AD0: EfsKRpcDecryptFek
0x18000E100: "__cdecl _imp_RtlFreeHeap" __imp_RtlFreeHeap
0x18000A691: "__cdecl _imp_load_EfsDllErrorToNtStatus" __imp_load_EfsDllErrorToNtStatus
0x1800150B8: "__cdecl _imp_EdpDllCredentialCreate" __imp_EdpDllCredentialCreate
0x180013748: "void (__cdecl* __ptr64 g_wil_details_RecordSRUMFeatureUsage)(unsigned int,unsigned int,unsigned int)" ?g_wil_details_RecordSRUMFeatureUsage@@3P6AXIII@ZEA
0x1800151F8: "__cdecl _imp_EfsDllCheckFileAccess" __imp_EfsDllCheckFileAccess
0x180010100: "(caller: %p) " ??_C@_1BM@EAHLIJPA@?$AA?$CI?$AAc?$AAa?$AAl?$AAl?$AAe?$AAr?$AA?3?$AA?5?$AA?$CF?$AAp?$AA?$CJ?$AA?5?$AA?$AA@
0x180015068: "__cdecl _imp_EdpDllGetTfaCache" __imp_EdpDllGetTfaCache
0x180011B20: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-libraryloader-l1-2-0" __IMPORT_DESCRIPTOR_api-ms-win-core-libraryloader-l1-2-0
0x180001FA0: PEXIMPORT_CONTEXT_HANDLE_rundown
0x180005C54: EfspIsValidNetworkProtSeq
0x18000A47F: "__cdecl _imp_load_EdpDllCredentialExists" __imp_load_EdpDllCredentialExists
0x18000DE78: "__cdecl _imp_HeapAlloc" __imp_HeapAlloc
0x18000E510: "SYSTEM\CurrentControlSet\Service" ??_C@_1EM@KAGIFAG@?$AAS?$AAY?$AAS?$AAT?$AAE?$AAM?$AA?2?$AAC?$AAu?$AAr?$AAr?$AAe?$AAn?$AAt?$AAC?$AAo?$AAn?$AAt?$AAr?$AAo?$AAl?$AAS?$AAe?$AAt?$AA?2?$AAS?$AAe?$AAr?$AAv?$AAi?$AAc?$AAe@
0x18000DEC0: "__cdecl _imp_FreeLibrary" __imp_FreeLibrary
0x18000FFA8: "_p0" ??_C@_17ONNCDEJM@?$AA_?$AAp?$AA0?$AA?$AA@
0x18000DF90: "__cdecl _imp_AcquireSRWLockExclusive" __imp_AcquireSRWLockExclusive
0x180010DD4: "__cdecl _NULL_DELAY_IMPORT_DESCRIPTOR" __NULL_DELAY_IMPORT_DESCRIPTOR
0x180015190: "__cdecl _imp_EfsDllFileKeyInfoSrv" __imp_EfsDllFileKeyInfoSrv
0x180013724: "long volatile `int __cdecl wil::details::RecordReturn(long)'::`2'::s_cErrorCount" ?s_cErrorCount@?1??RecordReturn@details@wil@@YAHJ@Z@4JC
0x18000E018: "__cdecl _imp_GetSidSubAuthority" __imp_GetSidSubAuthority
0x180009800: "__cdecl DllMainCRTStartup" _DllMainCRTStartup
0x18000A030: NdrServerCallAll
0x18000E0B0: "__cdecl _imp__initterm" __imp__initterm
0x180011B34: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-debug-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-debug-l1-1-0
0x18000DF70: "__cdecl _imp_CreateMutexExW" __imp_CreateMutexExW
0x180015198: "__cdecl _imp_EfsDllShareDecline" __imp_EfsDllShareDecline
0x18000DDC8: "__cdecl _imp_RpcImpersonateClient" __imp_RpcImpersonateClient
0x1800036B0: EfsRpcFileKeyInfo
0x180015028: "__cdecl _imp_EfsDllOnSessionChange" __imp_EfsDllOnSessionChange
0x180009F92: "__cdecl _tailMerge_bcrypt_dll" __tailMerge_bcrypt_dll
0x18000DE00: "__cdecl _imp_SetLastError" __imp_SetLastError
0x18000A275: "__cdecl _imp_load_EdpDllQueueFileForEncryption" __imp_load_EdpDllQueueFileForEncryption
0x180011B98: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-registry-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-registry-l1-1-0
0x180015020: "__cdecl _imp_EfsDllDecryptFek" __imp_EfsDllDecryptFek
0x180005640: EdpRpcAllowFileAccessForProcess
0x1800135E0: "__cdecl _hmod__FeClient_dll" __hmod__FeClient_dll
0x1800137B0: "__cdecl _onexitend" __onexitend
0x180009F63: "__cdecl unlock" _unlock
0x18000E178: "__cdecl _guard_check_icall_fptr" __guard_check_icall_fptr
0x1800151A8: "__cdecl _imp_EfsDllCloseFileRaw" __imp_EfsDllCloseFileRaw
0x18000A34D: "__cdecl _imp_load_EfsDllGetVolumeRoot" __imp_load_EfsDllGetVolumeRoot
0x18000DF10: "__cdecl _imp_TerminateProcess" __imp_TerminateProcess
0x18000191C: "private: bool __cdecl CEfsService::AllowServiceStop(void) __ptr64" ?AllowServiceStop@CEfsService@@AEAA_NXZ
0x1800151B0: "__cdecl _imp_EdpDllCredentialExists" __imp_EdpDllCredentialExists
0x1800135D0: "__cdecl _hmod__bcrypt_dll" __hmod__bcrypt_dll
0x180015268: "__cdecl _imp_EfsPlatform_GetCallerID" __imp_EfsPlatform_GetCallerID
0x18000E000: "__cdecl _imp_GetTokenInformation" __imp_GetTokenInformation
0x18000E128: "__cdecl _imp_EtwEventRegister" __imp_EtwEventRegister
0x18000E150: "__cdecl _imp_RtlNtStatusToDosError" __imp_RtlNtStatusToDosError
0x180015250: "__cdecl _imp_BCryptDestroyHash" __imp_BCryptDestroyHash
0x18000DDA8: "__cdecl _imp_I_RpcOpenClientProcess" __imp_I_RpcOpenClientProcess
0x18000DDE0: "__cdecl _imp_IsDebuggerPresent" __imp_IsDebuggerPresent
0x18000DFF8: api-ms-win-core-sysinfo-l1-1-0_NULL_THUNK_DATA
0x18000E1C8: "__cdecl _xi_a" __xi_a
0x18000A11F: "__cdecl _imp_load_EfsDllOnSessionUserChange" __imp_load_EfsDllOnSessionUserChange
0x18000DFF0: "__cdecl _imp_GetTickCount" __imp_GetTickCount
0x18000DDF8: api-ms-win-core-debug-l1-1-0_NULL_THUNK_DATA
0x18001370C: "unsigned int volatile `void __cdecl wil::SetLastError(struct wil::FailureInfo const & __ptr64)'::`2'::lastThread" ?lastThread@?1??SetLastError@wil@@YAXAEBUFailureInfo@2@@Z@4IC
0x180013042: g_header_init_InitializeStagingHeaderApi
0x18000E098: "__cdecl _imp__unlock" __imp__unlock
0x18000E030: api-ms-win-security-base-l1-1-0_NULL_THUNK_DATA
0x18000E0F8: "__cdecl _imp_NtOpenThreadToken" __imp_NtOpenThreadToken
0x18000A575: "__cdecl _tailMerge_feclient_dll" __tailMerge_feclient_dll
0x1800136C8: g_hSha256Alg
0x180015000: "__cdecl _imp_EdpDllGetLockSessionUnwrappedKey" __imp_EdpDllGetLockSessionUnwrappedKey
0x180006138: DloadMakePermanentImageCommit
0x180011C38: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-processthreads-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-processthreads-l1-1-0
0x1800049E0: EdpRpcDplUpgradePinInfo
0x18000DEF8: api-ms-win-core-memory-l1-1-0_NULL_THUNK_DATA
0x1800137D8: "__cdecl pRawDllMain" _pRawDllMain
0x18000DDB0: "__cdecl _imp_RpcRaiseException" __imp_RpcRaiseException
0x18000E090: "__cdecl _imp___dllonexit" __imp___dllonexit
0x18000A6A3: "__cdecl _imp_load_EfsDllValidateEfsStream" __imp_load_EfsDllValidateEfsStream
0x180006794: "private: static long __cdecl wil::details_abi::SemaphoreValue::GetValueFromSemaphore(void * __ptr64,long * __ptr64)" ?GetValueFromSemaphore@SemaphoreValue@details_abi@wil@@CAJPEAXPEAJ@Z
0x180015048: "__cdecl _imp_EfsDllAddUsersToFileSrv" __imp_EfsDllAddUsersToFileSrv
0x18000956C: "void __cdecl operator delete(void * __ptr64)" ??3@YAXPEAX@Z
0x18000612C: "__cdecl TlgDefineProvider_annotation__Tlgmtaum_hTelemetryAssertProv" _TlgDefineProvider_annotation__Tlgmtaum_hTelemetryAssertProv
0x18000A070: "__cdecl _imp_load_BCryptHashData" __imp_load_BCryptHashData
0x1800135D8: "__cdecl _hmod__EFSCORE_dll" __hmod__EFSCORE_dll
0x180011BE8: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-heap-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-heap-l1-1-0
0x180009AA0: "__cdecl _security_check_cookie" __security_check_cookie
0x18000E1C0: "__cdecl _xc_z" __xc_z
0x180011BC0: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-heap-l2-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-heap-l2-1-0
0x180007C8C: "long __cdecl wil::details::ReportFailure_GetLastErrorHr(void * __ptr64,unsigned int,char const * __ptr64,char const * __ptr64,char const * __ptr64,void * __ptr64,enum wil::FailureType)" ?ReportFailure_GetLastErrorHr@details@wil@@YAJPEAXIPEBD110W4FailureType@2@@Z
0x18000DF28: api-ms-win-core-processthreads-l1-1-0_NULL_THUNK_DATA
0x18000DEA0: "__cdecl _imp_GetProcAddress" __imp_GetProcAddress
0x1800032B0: EfsRpcSetFileEncryptionKey
0x18000DDB8: "__cdecl _imp_RpcServerInterfaceGroupClose" __imp_RpcServerInterfaceGroupClose
0x18000E480: EFS_PUBLISHER
0x18000A50F: "__cdecl _imp_load_EfsDllIsNonEfsSKU" __imp_load_EfsDllIsNonEfsSKU
0x18000FAC8: "feclient-EfsEnabled" ??_C@_1CI@BFEHANCK@?$AAf?$AAe?$AAc?$AAl?$AAi?$AAe?$AAn?$AAt?$AA?9?$AAE?$AAf?$AAs?$AAE?$AAn?$AAa?$AAb?$AAl?$AAe?$AAd?$AA?$AA@
0x180015128: "__cdecl _imp_EfsDllGetVolumeRoot" __imp_EfsDllGetVolumeRoot
0x18000A082: "__cdecl _imp_load_BCryptCreateHash" __imp_load_BCryptCreateHash
0x18000A437: "__cdecl _imp_load_EfsDllFileKeyInfoSrv" __imp_load_EfsDllFileKeyInfoSrv
0x18000E5C0: "ncacn_np" ??_C@_1BC@CCHMBIKG@?$AAn?$AAc?$AAa?$AAc?$AAn?$AA_?$AAn?$AAp?$AA?$AA@
0x18000FF80: "__cdecl _pfnDefaultDliNotifyHook2" __pfnDefaultDliNotifyHook2
0x18000DFE0: "__cdecl _imp_GetSystemTimeAsFileTime" __imp_GetSystemTimeAsFileTime
0x1800151D0: "__cdecl _imp_EfsDllQueryUsersOnFileSrv" __imp_EfsDllQueryUsersOnFileSrv
0x180013610: "bool wil::g_fBreakOnFailure" ?g_fBreakOnFailure@wil@@3_NA
0x18000DE80: "__cdecl _imp_GetProcessHeap" __imp_GetProcessHeap
0x18000A7B0: "__cdecl _chkstk" __chkstk
0x180010D94: "__cdecl _DELAY_IMPORT_DESCRIPTOR_FeClient_dll" __DELAY_IMPORT_DESCRIPTOR_FeClient_dll
0x1800017CC: "private: long __cdecl CEfsService::UpdateServiceStatus(unsigned long,unsigned long) __ptr64" ?UpdateServiceStatus@CEfsService@@AEAAJKK@Z
0x1800036A0: EfsRpcGetEncryptedFileMetadata
0x18000E048: "__cdecl _imp_SetServiceStatus" __imp_SetServiceStatus
0x180005180: EdpRpcCredSvcControl
0x18000897C: "unsigned long __cdecl EfsxLibAllocZero(unsigned __int64,void * __ptr64 * __ptr64)" ?EfsxLibAllocZero@@YAK_KPEAPEAX@Z
0x18000803C: "long __cdecl wil::GetFailureLogString(unsigned short * __ptr64,unsigned __int64,struct wil::FailureInfo const & __ptr64)" ?GetFailureLogString@wil@@YAJPEAG_KAEBUFailureInfo@1@@Z
0x180005700: EdpRpcGetTfaCache
0x18000269C: EfsRpcDecryptFileSrvInternal
0x18000E118: "__cdecl _imp_EtwEventEnabled" __imp_EtwEventEnabled
0x1800092E8: EfspGenerateKey
0x180015200: "__cdecl _imp_EdpDllDplUserUnlockComplete" __imp_EdpDllDplUserUnlockComplete
0x18000DD90: "__cdecl _imp_RpcStringBindingParseW" __imp_RpcStringBindingParseW
0x180013738: "void (__cdecl* __ptr64 g_wil_details_apiUnsubscribeFeatureStateChangeNotification)(struct FEATURE_STATE_CHANGE_SUBSCRIPTION__ * __ptr64)" ?g_wil_details_apiUnsubscribeFeatureStateChangeNotification@@3P6AXPEAUFEATURE_STATE_CHANGE_SUBSCRIPTION__@@@ZEA
0x180007EC0: "void __cdecl wil::details::in1diag3::FailFast_Unexpected(void * __ptr64,unsigned int,char const * __ptr64)" ?FailFast_Unexpected@in1diag3@details@wil@@YAXPEAXIPEBD@Z
0x18000DF68: api-ms-win-core-rtlsupport-l1-1-0_NULL_THUNK_DATA
0x180013620: "void (__cdecl* __ptr64 wil::details::g_pfnLoggingCallback)(struct wil::FailureInfo const & __ptr64)" ?g_pfnLoggingCallback@details@wil@@3P6AXAEBUFailureInfo@2@@ZEA
0x1800150E8: "__cdecl _imp_EfsDllUsePinForEncryptedFilesSrv" __imp_EfsDllUsePinForEncryptedFilesSrv
0x180005AD0: EfsRpcReprotectFile
0x18000E4E8: "AllowServiceStop" ??_C@_1CC@MLDBKAA@?$AAA?$AAl?$AAl?$AAo?$AAw?$AAS?$AAe?$AAr?$AAv?$AAi?$AAc?$AAe?$AAS?$AAt?$AAo?$AAp?$AA?$AA@
0x180011C60: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-rtlsupport-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-rtlsupport-l1-1-0
0x18000E4B0: "EFS" ??_C@_17PLBJKFCC@?$AAE?$AAF?$AAS?$AA?$AA@
0x180005570: EdpRpcRmsDecontainerizeFile
0x18000DF38: api-ms-win-core-profile-l1-1-0_NULL_THUNK_DATA
0x18000E1E0: "__cdecl _guard_fids_table" __guard_fids_table
0x18000E028: "__cdecl _imp_CreateWellKnownSid" __imp_CreateWellKnownSid
0x180002200: EfsRpcEncryptFileSrv
0x18000E0E0: msvcrt_NULL_THUNK_DATA
0x180010000: "SYSTEM\CurrentControlSet\Control" ??_C@_1FC@MEDFODCK@?$AAS?$AAY?$AAS?$AAT?$AAE?$AAM?$AA?2?$AAC?$AAu?$AAr?$AAr?$AAe?$AAn?$AAt?$AAC?$AAo?$AAn?$AAt?$AAr?$AAo?$AAl?$AAS?$AAe?$AAt?$AA?2?$AAC?$AAo?$AAn?$AAt?$AAr?$AAo?$AAl@
0x18000B010: "__cdecl load_config_used" _load_config_used
0x18000E3A0: "__cdecl _sz_bcrypt_dll" __sz_bcrypt_dll
0x18000DF78: "__cdecl _imp_ReleaseMutex" __imp_ReleaseMutex
0x180011BAC: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-security-sddl-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-security-sddl-l1-1-0
0x1800061D8: DloadProtectSection
0x180011058: bcrypt_NULL_THUNK_DATA_DLN
0x180015260: bcrypt_NULL_THUNK_DATA_DLA
0x180011848: bcrypt_NULL_THUNK_DATA_DLB
0x1800059D0: OefsRpcCheckSupport
0x180007050: "void __cdecl wil::details::GetContextAndNotifyFailure(struct wil::FailureInfo * __ptr64,char * __ptr64,unsigned __int64)" ?GetContextAndNotifyFailure@details@wil@@YAXPEAUFailureInfo@2@PEAD_K@Z
0x1800059A0: EdpRpcPurgeAppLearningEvents
0x180007D44: "long __cdecl wil::details::in1diag3::Return_GetLastError(void * __ptr64,unsigned int,char const * __ptr64)" ?Return_GetLastError@in1diag3@details@wil@@YAJPEAXIPEBD@Z
0x180001FF0: EfsRpcWriteFileRaw
0x180013708: "long volatile `void __cdecl wil::SetLastError(struct wil::FailureInfo const & __ptr64)'::`5'::depth" ?depth@?4??SetLastError@wil@@YAXAEBUFailureInfo@2@@Z@4JC
0x18000A287: "__cdecl _imp_load_EdpDllDplUpgradePinInfo" __imp_load_EdpDllDplUpgradePinInfo
0x18000A3DD: "__cdecl _imp_load_EfsDllRemoveUsersFromFileSrv" __imp_load_EfsDllRemoveUsersFromFileSrv
0x18000DD70: "__cdecl _imp_RpcServerInqCallAttributesW" __imp_RpcServerInqCallAttributesW
0x18000DD68: "__cdecl _imp_RpcBindingToStringBindingW" __imp_RpcBindingToStringBindingW
0x18000E0B8: "__cdecl _imp__amsg_exit" __imp__amsg_exit
0x1800136E8: "__cdecl _@@_PchSym_@00@KxulyqvxgPillgKxulmvxlivfzkUwhUhvxfirgbUvuhUoryUlyquivUznwGEUkivxlnkOlyq@efslib" __@@_PchSym_@00@KxulyqvxgPillgKxulmvxlivfzkUwhUhvxfirgbUvuhUoryUlyquivUznwGEUkivxlnkOlyq@efslib
0x180015258: "__cdecl _imp_BCryptOpenAlgorithmProvider" __imp_BCryptOpenAlgorithmProvider
0x18000A395: "__cdecl _imp_load_EfsDllSetFileEncryptionKeySrv" __imp_load_EfsDllSetFileEncryptionKeySrv
0x18000A2E1: "__cdecl _imp_load_EfsDllDisabled" __imp_load_EfsDllDisabled
0x18000E160: "__cdecl _imp_NtClose" __imp_NtClose
0x180001290: "char const * __ptr64 __cdecl wil::details::GetCurrentModuleName(void)" ?GetCurrentModuleName@details@wil@@YAPEBDXZ
0x18000FF80: "__cdecl _pfnDliNotifyHook2" __pfnDliNotifyHook2
0x180007E04: "long __cdecl StringCchPrintfW(unsigned short * __ptr64,unsigned __int64,unsigned short const * __ptr64,...)" ?StringCchPrintfW@@YAJPEAG_KPEBGZZ
0x1800085A8: "void __cdecl wil::details::WilFailFast(struct wil::FailureInfo const & __ptr64)" ?WilFailFast@details@wil@@YAXAEBUFailureInfo@2@@Z
0x180015100: "__cdecl _imp_EdpDllRmsClearKeys" __imp_EdpDllRmsClearKeys
0x1800036A0: EfsRpcSetEncryptedFileMetadata
0x18000DF50: "__cdecl _imp_RtlLookupFunctionEntry" __imp_RtlLookupFunctionEntry
0x180005E74: EfspEncryptFileCommonPrologue
0x18000E108: "__cdecl _imp_RtlValidSid" __imp_RtlValidSid
0x18000DF30: "__cdecl _imp_QueryPerformanceCounter" __imp_QueryPerformanceCounter
0x180015050: "__cdecl _imp_EfsDllMarkFileForDelete" __imp_EfsDllMarkFileForDelete
0x18000FF88: "internal\sdk\inc\wil\resource.h" ??_C@_0CA@BIKDFFBC@internal?2sdk?2inc?2wil?2resource?4h?$AA@
0x180015130: "__cdecl _imp_EdpWriteAppLearningLog" __imp_EdpWriteAppLearningLog
0x180009ADC: free
0x18000E138: "__cdecl _imp_NtOpenEvent" __imp_NtOpenEvent
0x1800151C8: "__cdecl _imp_EdpDllQueryDplEnforcedPolicyOwnerIds" __imp_EdpDllQueryDplEnforcedPolicyOwnerIds
0x18000DEF0: "__cdecl _imp_VirtualQuery" __imp_VirtualQuery
0x18000DD60: "__cdecl _imp_RpcStringFreeW" __imp_RpcStringFreeW
0x180007B90: "long __cdecl wil::details::GetLastErrorFailHr(void)" ?GetLastErrorFailHr@details@wil@@YAJXZ
0x18000DF58: "__cdecl _imp_RtlVirtualUnwind" __imp_RtlVirtualUnwind
0x180008750: "unsigned long __cdecl wil::details::ReportFailure_GetLastError(void * __ptr64,unsigned int,char const * __ptr64,char const * __ptr64,char const * __ptr64,void * __ptr64,enum wil::FailureType)" ?ReportFailure_GetLastError@details@wil@@YAKPEAXIPEBD110W4FailureType@2@@Z
0x18000FF80: "__cdecl _pfnDefaultDliFailureHook2" __pfnDefaultDliFailureHook2
0x1800040B0: EdpRpcQueryRevokedPolicyOwnerIds
0x1800135E8: "__cdecl _hmod__ext_ms_win_security_efs_l1_1_0_dll" __hmod__ext_ms_win_security_efs_l1_1_0_dll
0x180001C60: MIDL_user_allocate
0x1800019B0: "__cdecl guard_check_icall_nop" _guard_check_icall_nop
0x18000DEE0: api-ms-win-core-localization-l1-2-0_NULL_THUNK_DATA
0x1800036A0: EfsRpcGenerateEfsStream
0x18000FFB8: "WilError_02" ??_C@_0M@NMJHHMC@WilError_02?$AA@
0x180007F04: "int __cdecl wil::details::RecordException(long)" ?RecordException@details@wil@@YAHJ@Z
0x1800100C0: "%hs(%d)\%hs!%p: " ??_C@_1CC@CMMBNPBE@?$AA?$CF?$AAh?$AAs?$AA?$CI?$AA?$CF?$AAd?$AA?$CJ?$AA?2?$AA?$CF?$AAh?$AAs?$AA?$CB?$AA?$CF?$AAp?$AA?3?$AA?5?$AA?$AA@
0x1800150E0: "__cdecl _imp_EfsDllSsoFlushUserCache" __imp_EfsDllSsoFlushUserCache
0x18000A143: "__cdecl _imp_load_EfsUnInitialize" __imp_load_EfsUnInitialize
0x180001154: "bool __cdecl wil::details::GetModuleInformation(void * __ptr64,unsigned int * __ptr64,char * __ptr64,unsigned __int64)" ?GetModuleInformation@details@wil@@YA_NPEAXPEAIPEAD_K@Z
0x180002080: EfsRpcWriteFileWithHeaderRaw
0x18000E038: "__cdecl _imp_ConvertStringSecurityDescriptorToSecurityDescriptorW" __imp_ConvertStringSecurityDescriptorToSecurityDescriptorW
0x180011B84: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-handle-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-handle-l1-1-0
0x180007FA8: "void __cdecl wil::details::in1diag3::_FailFastImmediate_Unexpected(void)" ?_FailFastImmediate_Unexpected@in1diag3@details@wil@@YAXXZ
0x180015170: "__cdecl _imp_EfsDllDuplicateEncryptionInfoFileSrv" __imp_EfsDllDuplicateEncryptionInfoFileSrv
0x180003280: EfsRpcAddUsersToFile
0x18000DEC8: "__cdecl _imp_GetModuleHandleW" __imp_GetModuleHandleW
0x180008828: "public: static unsigned long __cdecl CEfsTokenManager::CheckIsLowILToken(void * __ptr64,int * __ptr64)" ?CheckIsLowILToken@CEfsTokenManager@@SAKPEAXPEAH@Z
0x180010DB4: "__cdecl _DELAY_IMPORT_DESCRIPTOR_ext_ms_win_security_efs_l1_1_0_dll" __DELAY_IMPORT_DESCRIPTOR_ext_ms_win_security_efs_l1_1_0_dll
0x18000A521: "__cdecl _imp_load_EfsDllCheckFileAccess" __imp_load_EfsDllCheckFileAccess
0x18000A569: "__cdecl _imp_load_EfsClientFileEncryptionStatus" __imp_load_EfsClientFileEncryptionStatus
0x18000A05E: "__cdecl _imp_load_BCryptDestroyHash" __imp_load_BCryptDestroyHash
0x1800101A8: "[%hs(%hs)] " ??_C@_1BI@PKOCHLJN@?$AA?$FL?$AA?$CF?$AAh?$AAs?$AA?$CI?$AA?$CF?$AAh?$AAs?$AA?$CJ?$AA?$FN?$AA?6?$AA?$AA@
0x18000E0C0: "__cdecl _imp__XcptFilter" __imp__XcptFilter
0x18000A3A7: "__cdecl _imp_load_EdpDllDplUserUnlockStart" __imp_load_EdpDllDplUserUnlockStart
0x18000E5D8: "\pipe\efsrpc" ??_C@_1BK@LHNOHCBH@?$AA?2?$AAp?$AAi?$AAp?$AAe?$AA?2?$AAe?$AAf?$AAs?$AAr?$AAp?$AAc?$AA?$AA@
0x18000E170: ntdll_NULL_THUNK_DATA
0x18000E080: "__cdecl _imp_memcpy" __imp_memcpy
0x180010088: "Exception" ??_C@_09FBNMMHMJ@Exception?$AA@
0x1800029A0: EfsRpcQueryUsersOnFile
0x180010158: " " ??_C@_19NMAFMAH@?$AA?5?$AA?5?$AA?5?$AA?5?$AA?$AA@
0x1800033F0: EfsRpcDuplicateEncryptionInfoFile
0x18000E120: "__cdecl _imp_EtwEventUnregister" __imp_EtwEventUnregister
0x1800100E8: "%hs!%p: " ??_C@_1BC@HOGHCIFF@?$AA?$CF?$AAh?$AAs?$AA?$CB?$AA?$CF?$AAp?$AA?3?$AA?5?$AA?$AA@
0x18000A299: "__cdecl _imp_load_EdpDllAllowFileAccessForProcess" __imp_load_EdpDllAllowFileAccessForProcess
0x180013043: g_header_init_InitializeStagingSRUMFeatureReporting
0x1800053B0: EdpRpcRmsContainerizeFile
0x18000E020: "__cdecl _imp_GetSidSubAuthorityCount" __imp_GetSidSubAuthorityCount
0x180011B70: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-synch-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-synch-l1-1-0
0x180013018: "__cdecl _security_cookie" __security_cookie
0x180008EC0: EfsKRpcGenerateDirEfs
0x180015060: "__cdecl _imp_EfsDllDecryptFileSrv" __imp_EfsDllDecryptFileSrv
0x18000A7B0: "__cdecl alloca_probe" _alloca_probe
0x1800054B0: EdpRpcRmsGetContainerIdentity
0x1800082A4: "void __cdecl wil::details::LogFailure(void * __ptr64,unsigned int,char const * __ptr64,char const * __ptr64,char const * __ptr64,void * __ptr64,enum wil::FailureType,long,unsigned short const * __ptr64,bool,unsigned short * __ptr64,unsigned __int64,char * __ptr64,unsigned __int64,struct wil::FailureInfo * __ptr64)" ?LogFailure@details@wil@@YAXPEAXIPEBD110W4FailureType@2@JPEBG_NPEAG_KPEAD6PEAUFailureInfo@2@@Z
0x1800101C0: "[%hs] " ??_C@_1O@PJKHPDBK@?$AA?$FL?$AA?$CF?$AAh?$AAs?$AA?$FN?$AA?6?$AA?$AA@
0x18000E008: "__cdecl _imp_CheckTokenMembership" __imp_CheckTokenMembership
0x18000E4A0: EFS_SERVICE_INIT_NOTIFYNTFS_ERROR
0x180003880: EfsUsePinForEncryptedFiles
0x18000DE60: "__cdecl _imp_CloseHandle" __imp_CloseHandle
0x180015158: "__cdecl _imp_EfsDllOpenFileRaw" __imp_EfsDllOpenFileRaw
0x18000DE90: "__cdecl _imp_LocalFree" __imp_LocalFree
0x180015030: "__cdecl _imp_EfsDllOnSessionUserChange" __imp_EfsDllOnSessionUserChange
0x180011B5C: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-errorhandling-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-errorhandling-l1-1-0
0x1800150D0: "__cdecl _imp_EdpDllDplUpgradePinInfo" __imp_EdpDllDplUpgradePinInfo
0x18000DE50: "__cdecl _imp_GetFileAttributesW" __imp_GetFileAttributesW
0x180001680: "private: static unsigned long __cdecl CEfsService::SvcCtrlHandler(unsigned long,unsigned long,void * __ptr64,void * __ptr64)" ?SvcCtrlHandler@CEfsService@@CAKKKPEAX0@Z
0x1800137B8: "__cdecl _onexitbegin" __onexitbegin
0x18000DDD0: "__cdecl _imp_I_RpcBindingIsClientLocal" __imp_I_RpcBindingIsClientLocal
0x18000A3CB: "__cdecl _imp_load_EdpDllDplUpgradeVerifyUser" __imp_load_EdpDllDplUpgradeVerifyUser
0x180013668: "unsigned char (__cdecl* __ptr64 wil::details::g_pfnRtlDllShutdownInProgress)(void)" ?g_pfnRtlDllShutdownInProgress@details@wil@@3P6AEXZEA
0x18000A4D9: "__cdecl _imp_load_EfsDllGetLogFile" __imp_load_EfsDllGetLogFile
0x1800151C0: "__cdecl _imp_EfsDllFreeHeap" __imp_EfsDllFreeHeap
0x180008558: "void __cdecl wil::ThrowResultException(struct wil::FailureInfo const & __ptr64)" ?ThrowResultException@wil@@YAXAEBUFailureInfo@1@@Z
0x18000E068: "__cdecl _imp__vsnwprintf" __imp__vsnwprintf
0x18000DDC0: "__cdecl _imp_RpcRevertToSelf" __imp_RpcRevertToSelf
0x18000DE08: "__cdecl _imp_SetUnhandledExceptionFilter" __imp_SetUnhandledExceptionFilter
0x180008A30: EdpKRpcWriteNetworkAppLearningEvt
0x18000FFC8: "DplAppKeyCachingLowILOnly" ??_C@_1DE@LFMIKNNE@?$AAD?$AAp?$AAl?$AAA?$AAp?$AAp?$AAK?$AAe?$AAy?$AAC?$AAa?$AAc?$AAh?$AAi?$AAn?$AAg?$AAL?$AAo?$AAw?$AAI?$AAL?$AAO?$AAn?$AAl?$AAy?$AA?$AA@
0x1800150F8: "__cdecl _imp_EfsDllDisabled" __imp_EfsDllDisabled
0x180013040: g_header_init_WilInitialize_ResultMacros_DesktopOrSystem_SuppressPrivateApiUse
0x180013750: "void (__cdecl* __ptr64 g_wil_details_apiRecordFeatureUsage)(unsigned int,unsigned int,unsigned int,char const * __ptr64)" ?g_wil_details_apiRecordFeatureUsage@@3P6AXIIIPEBD@ZEA
0x180006E94: "struct wil::details_abi::ThreadLocalData * __ptr64 __cdecl wil::details_abi::GetThreadLocalDataCache(bool)" ?GetThreadLocalDataCache@details_abi@wil@@YAPEAUThreadLocalData@12@_N@Z
0x180009BE4: "__cdecl _security_init_cookie" __security_init_cookie
0x180013658: "void (__cdecl* __ptr64 wil::details::g_pfnRaiseFailFastException)(struct _EXCEPTION_RECORD * __ptr64,struct _CONTEXT * __ptr64,unsigned long)" ?g_pfnRaiseFailFastException@details@wil@@3P6AXPEAU_EXCEPTION_RECORD@@PEAU_CONTEXT@@K@ZEA
0x180015230: "__cdecl _imp_BCryptFinishHash" __imp_BCryptFinishHash
0x180015148: "__cdecl _imp_EfsDllSetFileEncryptionKeySrv" __imp_EfsDllSetFileEncryptionKeySrv
0x180011B48: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-service-core-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-service-core-l1-1-0
0x180001FB0: EfsRpcReadFileRaw
0x18000DF40: "__cdecl _imp_RegGetValueW" __imp_RegGetValueW
0x180011B0C: "__cdecl _IMPORT_DESCRIPTOR_msvcrt" __IMPORT_DESCRIPTOR_msvcrt
0x180010D74: "__cdecl _DELAY_IMPORT_DESCRIPTOR_EFSCORE_dll" __DELAY_IMPORT_DESCRIPTOR_EFSCORE_dll
0x180015070: "__cdecl _imp_EfsDllWriteFileRaw" __imp_EfsDllWriteFileRaw
0x18000E040: api-ms-win-security-sddl-l1-1-0_NULL_THUNK_DATA
0x180001D54: fnEfsLogTrace1
0x1800078FC: ?MakeAndInitialize@?$ProcessLocalStorageData@UProcessLocalData@details_abi@wil@@@details_abi@wil@@CAJPEBG$$QEAV?$unique_any_t@V?$mutex_t@V?$unique_storage@U?$resource_policy@PEAXP6AXPEAX@Z$1?CloseHandle@details@wil@@YAX0@ZU?$integral_constant@_K$0A@@wistd@@PEAX$0A@$$T@details@wil@@@details@wil@@Uerr_returncode_policy@3@@wil@@@3@PEAPEAV123@@Z
0x180007E84: "void __cdecl wil::details::in1diag3::Return_Hr(void * __ptr64,unsigned int,char const * __ptr64,long)" ?Return_Hr@in1diag3@details@wil@@YAXPEAXIPEBDJ@Z
0x180004E80: EdpRpcQueueFileForEncryption
0x18000DD80: "__cdecl _imp_RpcServerInterfaceGroupCreateW" __imp_RpcServerInterfaceGroupCreateW
0x180007464: "public: static long __cdecl wil::details_abi::ProcessLocalStorageData<struct wil::details_abi::ProcessLocalData>::Acquire(char const * __ptr64,class wil::details_abi::ProcessLocalStorageData<struct wil::details_abi::ProcessLocalData> * __ptr64 * __ptr64)" ?Acquire@?$ProcessLocalStorageData@UProcessLocalData@details_abi@wil@@@details_abi@wil@@SAJPEBDPEAPEAV123@@Z
0x18000A22D: "__cdecl _imp_load_EfsDllGetLocalFileName" __imp_load_EfsDllGetLocalFileName
0x18000A533: "__cdecl _imp_load_EdpDllDplUserUnlockComplete" __imp_load_EdpDllDplUserUnlockComplete
0x180010D54: "__cdecl _DELAY_IMPORT_DESCRIPTOR_bcrypt_dll" __DELAY_IMPORT_DESCRIPTOR_bcrypt_dll
0x18000E0D8: "__cdecl _imp_malloc" __imp_malloc
0x18000A329: "__cdecl _imp_load_EfsDllFreeUserInfo" __imp_load_EfsDllFreeUserInfo
0x18000A179: "__cdecl _imp_load_EfsDllReadFileRaw" __imp_load_EfsDllReadFileRaw
0x180002220: EfsRpcEncryptFileExSrv
0x18000A6B5: "__cdecl _imp_load_EfsDllConstructEFS" __imp_load_EfsDllConstructEFS
0x180011BD4: "__cdecl _IMPORT_DESCRIPTOR_RPCRT4" __IMPORT_DESCRIPTOR_RPCRT4
0x180010180: "CallContext:[%hs] " ??_C@_1CG@CGJKEFKG@?$AAC?$AAa?$AAl?$AAl?$AAC?$AAo?$AAn?$AAt?$AAe?$AAx?$AAt?$AA?3?$AA?$FL?$AA?$CF?$AAh?$AAs?$AA?$FN?$AA?5?$AA?$AA@
0x180013630: "void (__cdecl* __ptr64 wil::details::g_pfnDebugBreak)(void)" ?g_pfnDebugBreak@details@wil@@3P6AXXZEA
0x18000DDD8: RPCRT4_NULL_THUNK_DATA
0x180015040: "__cdecl _imp_EfsUnInitialize" __imp_EfsUnInitialize
0x18000DD78: "__cdecl _imp_RpcServerInterfaceGroupActivate" __imp_RpcServerInterfaceGroupActivate
0x18000A251: "__cdecl _imp_load_EdpDllCredentialCreate" __imp_load_EdpDllCredentialCreate
0x180009DE0: "__cdecl _report_gsfailure" __report_gsfailure
0x18000E110: "__cdecl _imp_EtwEventWrite" __imp_EtwEventWrite
0x180009F86: "__cdecl _imp_load_BCryptOpenAlgorithmProvider" __imp_load_BCryptOpenAlgorithmProvider
0x180011010: EFSCORE_NULL_THUNK_DATA_DLN
0x18000612C: "__cdecl TlgDefineProvider_annotation__Tlgmtaum_hTelemetryAssertDiagTrackProv" _TlgDefineProvider_annotation__Tlgmtaum_hTelemetryAssertDiagTrackProv
0x1800050D0: EdpRpcServiceFileEncryptionQueue
0x18000A4C7: "__cdecl _imp_load_EfsDllQueryUsersOnFileSrv" __imp_load_EfsDllQueryUsersOnFileSrv
0x1800151E0: "__cdecl _imp_EfsDllReprotectFile" __imp_EfsDllReprotectFile
0x180009CE4: "__cdecl onexit" _onexit
0x18000E560: "EFS RPC Interface" ??_C@_1CE@FBOEMIOG@?$AAE?$AAF?$AAS?$AA?5?$AAR?$AAP?$AAC?$AA?5?$AAI?$AAn?$AAt?$AAe?$AAr?$AAf?$AAa?$AAc?$AAe?$AA?$AA@
0x18000A167: "__cdecl _imp_load_EfsDllMarkFileForDelete" __imp_load_EfsDllMarkFileForDelete
0x180013618: "void (__cdecl* __ptr64 wil::details::g_pfnTelemetryCallback)(bool,struct wil::FailureInfo const & __ptr64)" ?g_pfnTelemetryCallback@details@wil@@3P6AX_NAEBUFailureInfo@2@@ZEA
0x1800137C8: "__cdecl _native_startup_state" __native_startup_state
0x180015108: "__cdecl _imp_EdpDllRmsDecontainerizeFile" __imp_EdpDllRmsDecontainerizeFile
0x1800052C0: EdpRpcRmsClearKeys
0x18001367C: "long volatile `int __cdecl wil::details::RecordFailFast(long)'::`2'::s_hrErrorLast" ?s_hrErrorLast@?1??RecordFailFast@details@wil@@YAHJ@Z@4JC
0x180004CC0: EdpRpcDplUserUnlockStart
0x1800151D8: "__cdecl _imp_EfsDllGetLogFile" __imp_EfsDllGetLogFile
0x18000A21B: "__cdecl _imp_load_EdpDllPurgeAppLearningEvents" __imp_load_EdpDllPurgeAppLearningEvents
0x180004860: EdpRpcGetCredServiceState
0x1800151B8: "__cdecl _imp_EdpDllCredentialQuery" __imp_EdpDllCredentialQuery
0x18000A2AB: "__cdecl _imp_load_EfsDllSsoFlushUserCache" __imp_load_EfsDllSsoFlushUserCache
0x180013758: "void (__cdecl* __ptr64 g_wil_details_internalRecordFeatureUsage)(unsigned int,unsigned int,unsigned int,char const * __ptr64)" ?g_wil_details_internalRecordFeatureUsage@@3P6AXIIIPEBD@ZEA
0x1800151F0: "__cdecl _imp_EfsDllIsNonEfsSKU" __imp_EfsDllIsNonEfsSKU
0x180001140: "int __cdecl wil::details::RecordFailFast(long)" ?RecordFailFast@details@wil@@YAHJ@Z
0x18000E4D8: "SHA256" ??_C@_1O@HECGKAIN@?$AAS?$AAH?$AAA?$AA2?$AA5?$AA6?$AA?$AA@
0x180001CBC: fnEfsLogTrace0
0x180010120: "%hs(%d) tid(%x) %08X %ws" ??_C@_1DC@MFHOKFOG@?$AA?$CF?$AAh?$AAs?$AA?$CI?$AA?$CF?$AAd?$AA?$CJ?$AA?5?$AAt?$AAi?$AAd?$AA?$CI?$AA?$CF?$AAx?$AA?$CJ?$AA?5?$AA?$CF?$AA0?$AA8?$AAX?$AA?5?$AA?$CF?$AAw?$AAs?$AA?$AA@
0x18000A2F3: "__cdecl _imp_load_EdpDllRmsClearKeys" __imp_load_EdpDllRmsClearKeys
0x18000A3EF: "__cdecl _imp_load_EfsDllDuplicateEncryptionInfoFileSrv" __imp_load_EfsDllDuplicateEncryptionInfoFileSrv
0x180015168: "__cdecl _imp_EfsDllRemoveUsersFromFileSrv" __imp_EfsDllRemoveUsersFromFileSrv
0x180011C9C: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-memory-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-memory-l1-1-0
0x180004DB0: EdpRpcDplUserUnlockComplete
0x180007FB8: "unsigned short * __ptr64 __cdecl wil::details::LogStringPrintf(unsigned short * __ptr64,unsigned short const * __ptr64,unsigned short const * __ptr64,...)" ?LogStringPrintf@details@wil@@YAPEAGPEAGPEBG1ZZ
0x18000E450: EFS_SL_NOT_YET_INITIALIZED
0x180013660: "char const * __ptr64 (__cdecl* __ptr64 wil::details::g_pfnGetModuleName)(void)" ?g_pfnGetModuleName@details@wil@@3P6APEBDXZEA
0x180002E00: EfsRpcRemoveUsersFromFile
0x180003EE0: EdpRpcCredentialExists
0x18000A383: "__cdecl _imp_load_EfsDllQueryProtectorsSrv" __imp_load_EfsDllQueryProtectorsSrv
0x180011C24: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-profile-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-profile-l1-1-0
0x18000DE30: "__cdecl _imp_UnsubscribeFeatureStateChangeNotification" __imp_UnsubscribeFeatureStateChangeNotification
0x18000DDA0: "__cdecl _imp_NdrServerCall2" __imp_NdrServerCall2
0x180015008: "__cdecl _imp_EfsDllConstructEFS" __imp_EfsDllConstructEFS
0x1800072A8: EfsResolveProcessInfo
0x180013678: "bool volatile `char const * __ptr64 __cdecl wil::details::GetCurrentModuleName(void)'::`2'::s_fModuleValid" ?s_fModuleValid@?1??GetCurrentModuleName@details@wil@@YAPEBDXZ@4_NC
0x18000E0C8: "__cdecl _imp_free" __imp_free
0x180009B50: "__cdecl IsNonwritableInCurrentImage" _IsNonwritableInCurrentImage
0x18000DFD8: api-ms-win-core-synch-l1-2-0_NULL_THUNK_DATA
0x18000E130: "__cdecl _imp_NtSetEvent" __imp_NtSetEvent
0x180001350: "public: static long __cdecl CEfsService::StartServiceW(struct _LSAP_SERVICE_STOP_CALLBACK_CONTEXT * __ptr64)" ?StartServiceW@CEfsService@@SAJPEAU_LSAP_SERVICE_STOP_CALLBACK_CONTEXT@@@Z
0x1800068D8: "private: static long __cdecl wil::details_abi::SemaphoreValue::TryGetValueInternal(unsigned short const * __ptr64,bool,unsigned __int64 * __ptr64,bool * __ptr64)" ?TryGetValueInternal@SemaphoreValue@details_abi@wil@@CAJPEBG_NPEA_KPEA_N@Z
0x18000E470: EFS_ERROR_MEMORY
0x18000E078: "__cdecl _imp_memcpy_s" __imp_memcpy_s
0x1800100A4: "LogHr" ??_C@_05OILEHMGB@LogHr?$AA@
0x18000DF08: "__cdecl _imp_OpenProcessToken" __imp_OpenProcessToken
0x180011CB0: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-localization-l1-2-0" __IMPORT_DESCRIPTOR_api-ms-win-core-localization-l1-2-0
0x18000DFC8: api-ms-win-core-synch-l1-1-0_NULL_THUNK_DATA
0x180011C10: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-synch-l1-2-0" __IMPORT_DESCRIPTOR_api-ms-win-core-synch-l1-2-0
0x180013628: "void (__cdecl* __ptr64 wil::details::g_pfnGetContextAndNotifyFailure)(struct wil::FailureInfo * __ptr64,char * __ptr64,unsigned __int64)" ?g_pfnGetContextAndNotifyFailure@details@wil@@3P6AXPEAUFailureInfo@2@PEAD_K@ZEA
0x18000A772: memset
0x180011CD8: "__cdecl _NULL_IMPORT_DESCRIPTOR" __NULL_IMPORT_DESCRIPTOR
0x180013041: g_header_init_InitializeResultHeader

[JEB Decompiler by PNF Software]