Generated by JEB on 2019/08/01

PE: C:\Windows\System32\WofTasks.dll Base=0x180000000 SHA-256=760EAD0E3812D0068DBADFE4B436750F2FA8E3FFE967250C99CA4DE8025AA384
PDB: WofTasks.pdb GUID={1654FDB3-15B0-6AD8-5C2B37F032736482} Age=1

285 located named symbols:
0x180006998: CLSID_TaskScheduler
0x180004ABC: "__cdecl _raise_securityfailure" __raise_securityfailure
0x180006320: api-ms-win-core-file-l1-1-0_NULL_THUNK_DATA
0x1800039D4: "long __cdecl ReportDataSourceIdDeletion(union _LARGE_INTEGER)" ?ReportDataSourceIdDeletion@@YAJT_LARGE_INTEGER@@@Z
0x1800063A8: "__cdecl _imp_EventRegister" __imp_EventRegister
0x180006658: WofTaskCompleteHashFileEventId
0x1800048D0: "__cdecl FindPESection" _FindPESection
0x180006010: "const CWinTaskClassFactoryT<class CWofTasksHandler,1>::`vftable'" ??_7?$CWinTaskClassFactoryT@VCWofTasksHandler@@$00@@6B@
0x180006790: "WIMH." ??_C@_1M@LPBICBEJ@?$AAW?$AAI?$AAM?$AAH?$AA?4?$AA?$AA@
0x180007170: "__cdecl _IMPORT_DESCRIPTOR_ntdll" __IMPORT_DESCRIPTOR_ntdll
0x1800071AC: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-com-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-com-l1-1-0
0x1800037E4: "void __cdecl LogFileOffset(struct _EVENT_DESCRIPTOR const * __ptr64,unsigned short const * __ptr64,unsigned __int64)" ?LogFileOffset@@YAXPEBU_EVENT_DESCRIPTOR@@PEBG_K@Z
0x180002D84: "long __cdecl TaskChangeFileHashes(enum _WOF_TASK_ACTION)" ?TaskChangeFileHashes@@YAJW4_WOF_TASK_ACTION@@@Z
0x180008010: "__cdecl _security_cookie_complement" __security_cookie_complement
0x180006258: "__cdecl _imp_DeviceIoControl" __imp_DeviceIoControl
0x18000438C: "__cdecl CRT_INIT" _CRT_INIT
0x1800061F8: "__cdecl _imp_GetCurrentThreadId" __imp_GetCurrentThreadId
0x180004D50: "__cdecl guard_dispatch_icall_nop" _guard_dispatch_icall_nop
0x180006268: "__cdecl _imp_CreateFileW" __imp_CreateFileW
0x180006390: "__cdecl _imp_GetSystemWindowsDirectoryW" __imp_GetSystemWindowsDirectoryW
0x180006340: "__cdecl _imp_CancelIoEx" __imp_CancelIoEx
0x180002650: DllGetClassObject
0x180002F74: "long __cdecl DisableValidationTask(void)" ?DisableValidationTask@@YAJXZ
0x180003D28: WofStartIntegrity
0x180007210: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-file-l1-2-0" __IMPORT_DESCRIPTOR_api-ms-win-core-file-l1-2-0
0x1800071E8: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-file-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-file-l1-1-0
0x180006410: bcrypt_NULL_THUNK_DATA
0x180006430: "__cdecl _imp_wcschr" __imp_wcschr
0x180006648: WofTaskFileReadErrorEventId
0x180006368: "__cdecl _imp_RegFlushKey" __imp_RegFlushKey
0x1800019F4: "public: long __cdecl WIMHashFile::Initialize(unsigned short const * __ptr64,unsigned short const * __ptr64,union _LARGE_INTEGER,int * __ptr64) __ptr64" ?Initialize@WIMHashFile@@QEAAJPEBG0T_LARGE_INTEGER@@PEAH@Z
0x1800064D0: "__cdecl _guard_dispatch_icall_fptr" __guard_dispatch_icall_fptr
0x180006488: "__cdecl _imp__wcsdup" __imp__wcsdup
0x180006290: "__cdecl _imp_GetModuleHandleExW" __imp_GetModuleHandleExW
0x18000215C: "public: __cdecl File::~File(void) __ptr64" ??1File@@QEAA@XZ
0x1800048B8: "__cdecl XcptFilter" _XcptFilter
0x1800064D8: "__cdecl _xc_a" __xc_a
0x180003888: "void __cdecl LogFileError(struct _EVENT_DESCRIPTOR const * __ptr64,unsigned short const * __ptr64,unsigned short const * __ptr64,int)" ?LogFileError@@YAXPEBU_EVENT_DESCRIPTOR@@PEBG1H@Z
0x180006408: "__cdecl _imp_BCryptCreateHash" __imp_BCryptCreateHash
0x1800069B0: "\\?\GlobalRoot" ??_C@_1BO@FLMEL@?$AA?2?$AA?2?$AA?$DP?$AA?2?$AAG?$AAl?$AAo?$AAb?$AAa?$AAl?$AAR?$AAo?$AAo?$AAt?$AA?$AA@
0x180006608: WofTaskActionErrorEventId
0x1800048AC: "__cdecl callnewh" _callnewh
0x1800062D0: "__cdecl _imp_DeleteFileW" __imp_DeleteFileW
0x180003714: "void __cdecl LogFile(struct _EVENT_DESCRIPTOR const * __ptr64,unsigned short const * __ptr64,unsigned short const * __ptr64)" ?LogFile@@YAXPEBU_EVENT_DESCRIPTOR@@PEBG1@Z
0x180004D19: memcpy
0x180006428: "__cdecl _imp_memset" __imp_memset
0x1800062B8: "__cdecl _imp_CreateEventW" __imp_CreateEventW
0x180006338: api-ms-win-core-file-l1-2-0_NULL_THUNK_DATA
0x180004A8F: "__cdecl initterm" _initterm
0x180001F2C: "public: long __cdecl File::Write(void * __ptr64,unsigned long) __ptr64" ?Write@File@@QEAAJPEAXK@Z
0x180007224: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-sysinfo-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-sysinfo-l1-1-0
0x18040F040: "__cdecl _dyn_tls_init_callback" __dyn_tls_init_callback
0x1800062E0: "__cdecl _imp_GetOverlappedResult" __imp_GetOverlappedResult
0x180006210: "__cdecl _imp_Sleep" __imp_Sleep
0x1800014D4: "private: long __cdecl WIMHashFile::HashWimBlock(unsigned char * __ptr64,unsigned long) __ptr64" ?HashWimBlock@WIMHashFile@@AEAAJPEAEK@Z
0x1800064F8: "__cdecl _xi_z" __xi_z
0x1800061C8: "__cdecl _imp_UnhandledExceptionFilter" __imp_UnhandledExceptionFilter
0x180006418: "__cdecl _imp_wcscmp" __imp_wcscmp
0x180004A9B: "__cdecl _C_specific_handler" __C_specific_handler
0x1800061B0: FVEAPI_NULL_THUNK_DATA
0x1800022D0: "protected: virtual long __cdecl CWinTaskHandler::StartWorker(struct IUnknown * __ptr64,unsigned short * __ptr64) __ptr64" ?StartWorker@CWinTaskHandler@@MEAAJPEAUIUnknown@@PEAG@Z
0x180006218: "__cdecl _imp_HeapFree" __imp_HeapFree
0x18040B018: "__cdecl _@@_PchSym_@00@KxulyqvxgPillgKxulmvxlivUyzhvUmthxyUxlnnlmUfnUlyquivUznwGEUkivxlnkOlyq@ngscb_common_um" __@@_PchSym_@00@KxulyqvxgPillgKxulmvxlivUyzhvUmthxyUxlnnlmUfnUlyquivUznwGEUkivxlnkOlyq@ngscb_common_um
0x1800048A0: malloc
0x180003530: "public: virtual long __cdecl CWinTaskClassFactoryT<class CWofTasksHandler,1>::CreateInstance(struct IUnknown * __ptr64,struct _GUID const & __ptr64,void * __ptr64 * __ptr64) __ptr64" ?CreateInstance@?$CWinTaskClassFactoryT@VCWofTasksHandler@@$00@@UEAAJPEAUIUnknown@@AEBU_GUID@@PEAPEAX@Z
0x180006358: "__cdecl _imp_RegCloseKey" __imp_RegCloseKey
0x180004CAC: "__cdecl _GSHandlerCheckCommon" __GSHandlerCheckCommon
0x180002630: DllCanUnloadNow
0x180006350: "__cdecl _imp_RegSetValueExW" __imp_RegSetValueExW
0x1800048C4: "__cdecl amsg_exit" _amsg_exit
0x180006460: "__cdecl _imp__callnewh" __imp__callnewh
0x180006590: IID_IClassFactory
0x180004224: WofpOpenSystemVolumeWithFlagsAndAttributes
0x1800065F8: WofTaskCreateHashFileEventId
0x1800067A0: "\System Volume Information" ??_C@_1DG@DJBEOOIC@?$AA?2?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AA?5?$AAV?$AAo?$AAl?$AAu?$AAm?$AAe?$AA?5?$AAI?$AAn?$AAf?$AAo?$AAr?$AAm?$AAa?$AAt?$AAi?$AAo?$AAn?$AA?$AA@
0x180001430: "public: long __cdecl WIMHashFile::Hash(unsigned char * __ptr64,unsigned long,unsigned char * __ptr64) __ptr64" ?Hash@WIMHashFile@@QEAAJPEAEK0@Z
0x180007184: "__cdecl _IMPORT_DESCRIPTOR_bcrypt" __IMPORT_DESCRIPTOR_bcrypt
0x1800063D8: "__cdecl _imp_BCryptProcessMultiOperations" __imp_BCryptProcessMultiOperations
0x1800068B8: "__cdecl GUID_eaec7a8f_27a0_4ddc_8675_14726a01a38a" _GUID_eaec7a8f_27a0_4ddc_8675_14726a01a38a
0x180006668: WofTaskActionGenerateHashesEventId
0x180006260: "__cdecl _imp_SetEndOfFile" __imp_SetEndOfFile
0x180001008: "private: long __cdecl WIMHashFile::InitializeHeader(void) __ptr64" ?InitializeHeader@WIMHashFile@@AEAAJXZ
0x180006388: api-ms-win-core-registry-l1-1-0_NULL_THUNK_DATA
0x1800066A8: WofTaskDeleteHashFileErrorEventId
0x180006220: "__cdecl _imp_GetSystemInfo" __imp_GetSystemInfo
0x1800062F8: "__cdecl _imp_GetCurrentProcess" __imp_GetCurrentProcess
0x1800022C0: "private: virtual long __cdecl CWinTaskHandler::Pause(void) __ptr64" ?Pause@CWinTaskHandler@@EEAAJXZ
0x180002580: "public: virtual void * __ptr64 __cdecl CWofTasksHandler::`vector deleting destructor'(unsigned int) __ptr64" ??_ECWofTasksHandler@@UEAAPEAXI@Z
0x18040F030: "__cdecl _native_startup_lock" __native_startup_lock
0x1800063E8: "__cdecl _imp_BCryptHashData" __imp_BCryptHashData
0x180002608: DllMain
0x180003650: "public: virtual unsigned long __cdecl CWinTaskClassFactoryT<class CWofTasksHandler,1>::AddRef(void) __ptr64" ?AddRef@?$CWinTaskClassFactoryT@VCWofTasksHandler@@$00@@UEAAKXZ
0x180006438: "__cdecl _imp___C_specific_handler" __imp___C_specific_handler
0x1800062B0: "__cdecl _imp_ResumeThread" __imp_ResumeThread
0x18040B008: "struct _WNF_USER_SUBSCRIPTION * __ptr64 __ptr64 WnfUserSubcription" ?WnfUserSubcription@@3PEAU_WNF_USER_SUBSCRIPTION@@EA
0x1800061E0: "__cdecl _imp_RtlCaptureContext" __imp_RtlCaptureContext
0x1800071D4: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-eventing-provider-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-eventing-provider-l1-1-0
0x180006300: KERNEL32_NULL_THUNK_DATA
0x1800062E8: "__cdecl _imp_GetWindowsDirectoryW" __imp_GetWindowsDirectoryW
0x180006270: "__cdecl _imp_GetLastError" __imp_GetLastError
0x1800042FC: "void * __ptr64 __cdecl operator new(unsigned __int64)" ??2@YAPEAX_K@Z
0x1800063C0: api-ms-win-eventing-provider-l1-1-0_NULL_THUNK_DATA
0x180008000: "__cdecl _native_dllmain_reason" __native_dllmain_reason
0x180004C88: "__cdecl _GSHandlerCheck" __GSHandlerCheck
0x180006480: "__cdecl _imp_memcmp" __imp_memcmp
0x1800063F8: "__cdecl _imp_BCryptCloseAlgorithmProvider" __imp_BCryptCloseAlgorithmProvider
0x180007198: "__cdecl _IMPORT_DESCRIPTOR_FVEAPI" __IMPORT_DESCRIPTOR_FVEAPI
0x1800066E8: "WofTaskAction" ??_C@_1BM@HFMOPDN@?$AAW?$AAo?$AAf?$AAT?$AAa?$AAs?$AAk?$AAA?$AAc?$AAt?$AAi?$AAo?$AAn?$AA?$AA@
0x1800068C8: "NULL" ??_C@_19CIJIHAKK@?$AAN?$AAU?$AAL?$AAL?$AA?$AA@
0x180006200: "__cdecl _imp_GetCurrentProcessId" __imp_GetCurrentProcessId
0x180006688: WofTaskActionDeleteHashesEventId
0x1800062A0: "__cdecl _imp_WaitForSingleObject" __imp_WaitForSingleObject
0x180006478: "__cdecl _imp_swprintf_s" __imp_swprintf_s
0x180006360: "__cdecl _imp_RegDeleteValueW" __imp_RegDeleteValueW
0x18040B000: "private: static long volatile CWinTaskHandler::s_cInstances" ?s_cInstances@CWinTaskHandler@@0JC
0x180004980: "__cdecl ValidateImageBase" _ValidateImageBase
0x180006858: "WimHashManagement" ??_C@_1CE@HKCOFOAI@?$AAW?$AAi?$AAm?$AAH?$AAa?$AAs?$AAh?$AAM?$AAa?$AAn?$AAa?$AAg?$AAe?$AAm?$AAe?$AAn?$AAt?$AA?$AA@
0x180006580: IID_IUnknown
0x180006710: "Software\Microsoft\Windows\Curre" ??_C@_1HM@EEKLNJND@?$AAS?$AAo?$AAf?$AAt?$AAw?$AAa?$AAr?$AAe?$AA?2?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAW?$AAi?$AAn?$AAd?$AAo?$AAw?$AAs?$AA?2?$AAC?$AAu?$AAr?$AAr?$AAe@
0x180006288: "__cdecl _imp_FlushFileBuffers" __imp_FlushFileBuffers
0x1800065A0: "\" ??_C@_13FPGAJAPJ@?$AA?2?$AA?$AA@
0x180006328: "__cdecl _imp_GetVolumeNameForVolumeMountPointW" __imp_GetVolumeNameForVolumeMountPointW
0x1800011C4: "private: long __cdecl WIMHashFile::FinalizeHeader(void) __ptr64" ?FinalizeHeader@WIMHashFile@@AEAAJXZ
0x180006228: "__cdecl _imp_HeapAlloc" __imp_HeapAlloc
0x1800062F0: "__cdecl _imp_FreeLibrary" __imp_FreeLibrary
0x1800045D0: "__cdecl DllMainCRTStartup" _DllMainCRTStartup
0x1800021D0: "protected: virtual unsigned long __cdecl CWinTaskHandler::Release(void) __ptr64" ?Release@CWinTaskHandler@@MEAAKXZ
0x180006440: "__cdecl _imp__initterm" __imp__initterm
0x180006618: WofTaskGenerateHashFileErrorEventId
0x180002580: "public: virtual void * __ptr64 __cdecl CWofTasksHandler::`scalar deleting destructor'(unsigned int) __ptr64" ??_GCWofTasksHandler@@UEAAPEAXI@Z
0x180006040: "const CWofTasksHandler::`vftable'" ??_7CWofTasksHandler@@6B@
0x18000A000: "unsigned long ExitFlag" ?ExitFlag@@3KA
0x1800071C0: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-registry-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-registry-l1-1-0
0x18040F020: "__cdecl _onexitend" __onexitend
0x180003510: "public: virtual long __cdecl CWinTaskClassFactoryT<class CWofTasksHandler,1>::LockServer(int) __ptr64" ?LockServer@?$CWinTaskClassFactoryT@VCWofTasksHandler@@$00@@UEAAJH@Z
0x1800062D8: "__cdecl _imp_CreateThread" __imp_CreateThread
0x1800064C8: "__cdecl _guard_check_icall_fptr" __guard_check_icall_fptr
0x1800063E0: "__cdecl _imp_BCryptGetProperty" __imp_BCryptGetProperty
0x1800061B8: "__cdecl _imp_TerminateProcess" __imp_TerminateProcess
0x1800063C8: "__cdecl _imp_BCryptDestroyHash" __imp_BCryptDestroyHash
0x180006398: api-ms-win-core-sysinfo-l1-1-0_NULL_THUNK_DATA
0x1800064E8: "__cdecl _xi_a" __xi_a
0x180003180: "public: virtual long __cdecl CWofTasksHandler::Worker(void) __ptr64" ?Worker@CWofTasksHandler@@UEAAJXZ
0x180006400: "__cdecl _imp_BCryptCreateMultiHash" __imp_BCryptCreateMultiHash
0x1800061E8: "__cdecl _imp_GetTickCount" __imp_GetTickCount
0x180001694: "private: long __cdecl WIMHashFile::ResumeHashWrites(void) __ptr64" ?ResumeHashWrites@WIMHashFile@@AEAAJXZ
0x1800064A0: "__cdecl _imp_RtlQueryWnfStateData" __imp_RtlQueryWnfStateData
0x1800064B0: "__cdecl _imp_RtlSubscribeWnfStateChangeNotification" __imp_RtlSubscribeWnfStateChangeNotification
0x180006988: IID_ITaskService
0x180006698: WofTaskPauseHashFileEventId
0x180002940: "long __cdecl FveWnfNoopCallback(struct _WNF_STATE_NAME,unsigned long,struct _WNF_TYPE_ID * __ptr64,void * __ptr64,void const * __ptr64,unsigned long)" ?FveWnfNoopCallback@@YAJU_WNF_STATE_NAME@@KPEAU_WNF_TYPE_ID@@PEAXPEBXK@Z
0x1800066E0: WNF_FVE_WIM_HASH_GENERATION_COMPLETION
0x180002210: "protected: virtual long __cdecl CWinTaskHandler::QueryInterface(struct _GUID const & __ptr64,void * __ptr64 * __ptr64) __ptr64" ?QueryInterface@CWinTaskHandler@@MEAAJAEBU_GUID@@PEAPEAX@Z
0x18040F048: "__cdecl pRawDllMain" _pRawDllMain
0x1800022A0: "protected: virtual long __cdecl CWinTaskHandler::Stop(long * __ptr64) __ptr64" ?Stop@CWinTaskHandler@@MEAAJPEAJ@Z
0x180006638: WofTaskResumeHashFileEventId
0x1800022C0: DllUnregisterServer
0x1800036E0: "public: virtual void * __ptr64 __cdecl CWinTaskClassFactoryT<class CWofTasksHandler,1>::`vector deleting destructor'(unsigned int) __ptr64" ??_E?$CWinTaskClassFactoryT@VCWofTasksHandler@@$00@@UEAAPEAXI@Z
0x1800066C0: WofEventProviderId
0x18000433C: "void __cdecl operator delete(void * __ptr64)" ??3@YAXPEAX@Z
0x180004870: "__cdecl _security_check_cookie" __security_check_cookie
0x1800064E0: "__cdecl _xc_z" __xc_z
0x1800021B0: "protected: virtual unsigned long __cdecl CWinTaskHandler::AddRef(void) __ptr64" ?AddRef@CWinTaskHandler@@MEAAKXZ
0x1800024F0: "private: static unsigned long __cdecl CWinTaskHandler::WorkerThreadProc(void * __ptr64)" ?WorkerThreadProc@CWinTaskHandler@@CAKPEAX@Z
0x180006348: api-ms-win-core-io-l1-1-0_NULL_THUNK_DATA
0x180006308: "__cdecl _imp_CoCreateInstance" __imp_CoCreateInstance
0x1800061F0: "__cdecl _imp_GetSystemTimeAsFileTime" __imp_GetSystemTimeAsFileTime
0x180006230: "__cdecl _imp_GetProcessHeap" __imp_GetProcessHeap
0x180006800: "Microsoft\Windows\WOF\WIM-Hash-V" ??_C@_1FE@CCMBHBNC@?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAW?$AAi?$AAn?$AAd?$AAo?$AAw?$AAs?$AA?2?$AAW?$AAO?$AAF?$AA?2?$AAW?$AAI?$AAM?$AA?9?$AAH?$AAa?$AAs?$AAh?$AA?9?$AAV@
0x180006318: "__cdecl _imp_GetVolumePathNameW" __imp_GetVolumePathNameW
0x1800066D0: WofTaskFileWriteErrorEventId
0x180006628: WofTaskEnumVolumeEventId
0x180006280: "__cdecl _imp_SetFilePointerEx" __imp_SetFilePointerEx
0x180002950: "long __cdecl FveWnfControlCallback(struct _WNF_STATE_NAME,unsigned long,struct _WNF_TYPE_ID * __ptr64,void * __ptr64,void const * __ptr64,unsigned long)" ?FveWnfControlCallback@@YAJU_WNF_STATE_NAME@@KPEAU_WNF_TYPE_ID@@PEAXPEBXK@Z
0x180006500: "__cdecl _guard_fids_table" __guard_fids_table
0x180002A7C: EnumWIMCallback
0x180006490: msvcrt_NULL_THUNK_DATA
0x1800060A0: "__cdecl load_config_used" _load_config_used
0x1800065A8: "MSWIM" ??_C@_07BHGOIGBH@MSWIM?$AA?$AA?$AA@
0x180006330: "__cdecl _imp_GetVolumePathNamesForVolumeNameW" __imp_GetVolumePathNamesForVolumeNameW
0x1800065E8: WofTaskDeleteHashFileEventId
0x1800067D8: "%s%s\%s%016I64X" ??_C@_1CA@MHGDNOGA@?$AA?$CF?$AAs?$AA?$CF?$AAs?$AA?2?$AA?$CF?$AAs?$AA?$CF?$AA0?$AA1?$AA6?$AAI?$AA6?$AA4?$AAX?$AA?$AA@
0x1800071FC: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-io-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-io-l1-1-0
0x1800036E0: "public: virtual void * __ptr64 __cdecl CWinTaskClassFactoryT<class CWofTasksHandler,1>::`scalar deleting destructor'(unsigned int) __ptr64" ??_G?$CWinTaskClassFactoryT@VCWofTasksHandler@@$00@@UEAAPEAXI@Z
0x180002328: "protected: virtual long __cdecl CWinTaskHandler::StopWorker(long * __ptr64) __ptr64" ?StopWorker@CWinTaskHandler@@MEAAJPEAJ@Z
0x180006448: "__cdecl _imp__amsg_exit" __imp__amsg_exit
0x1800063D0: "__cdecl _imp_BCryptOpenAlgorithmProvider" __imp_BCryptOpenAlgorithmProvider
0x1800062C0: "__cdecl _imp_DisableThreadLibraryCalls" __imp_DisableThreadLibraryCalls
0x180003AF4: WofEnumEntries
0x1800061D8: "__cdecl _imp_RtlLookupFunctionEntry" __imp_RtlLookupFunctionEntry
0x180006208: "__cdecl _imp_QueryPerformanceCounter" __imp_QueryPerformanceCounter
0x1800063B0: "__cdecl _imp_EventWrite" __imp_EventWrite
0x180001FB0: "public: long __cdecl File::Read(void * __ptr64,unsigned long,unsigned long * __ptr64) __ptr64" ?Read@File@@QEAAJPEAXKPEAK@Z
0x180004894: free
0x1800061D0: "__cdecl _imp_RtlVirtualUnwind" __imp_RtlVirtualUnwind
0x180006248: "__cdecl _imp_GetFileSizeEx" __imp_GetFileSizeEx
0x180002714: "long __cdecl IdentifyTaskAction(enum _WOF_TASK_ACTION * __ptr64)" ?IdentifyTaskAction@@YAJPEAW4_WOF_TASK_ACTION@@@Z
0x180001DB0: "public: __cdecl WIMHashFile::~WIMHashFile(void) __ptr64" ??1WIMHashFile@@QEAA@XZ
0x180003FD8: WofpNormalizeFilePath
0x180004AB0: "__cdecl guard_check_icall_nop" _guard_check_icall_nop
0x180004D0D: memcmp
0x180003F80: WofpDeviceIoControl
0x1800022C0: "private: virtual long __cdecl CWinTaskHandler::Resume(void) __ptr64" ?Resume@CWinTaskHandler@@EEAAJXZ
0x1800064B8: "__cdecl _imp_RtlUnsubscribeWnfStateChangeNotification" __imp_RtlUnsubscribeWnfStateChangeNotification
0x180003610: "public: virtual unsigned long __cdecl CWinTaskClassFactoryT<class CWofTasksHandler,1>::Release(void) __ptr64" ?Release@?$CWinTaskClassFactoryT@VCWofTasksHandler@@$00@@UEAAKXZ
0x1800064A8: "__cdecl _imp_RtlPublishWnfStateData" __imp_RtlPublishWnfStateData
0x180006458: "__cdecl _imp__XcptFilter" __imp__XcptFilter
0x1800064C0: ntdll_NULL_THUNK_DATA
0x180006420: "__cdecl _imp_memcpy" __imp_memcpy
0x180002280: "protected: virtual long __cdecl CWinTaskHandler::Start(struct IUnknown * __ptr64,unsigned short * __ptr64) __ptr64" ?Start@CWinTaskHandler@@MEAAJPEAUIUnknown@@PEAG@Z
0x1800068E0: "SYSTEM\CurrentControlSet\Service" ??_C@_1IG@BIGMBKGO@?$AAS?$AAY?$AAS?$AAT?$AAE?$AAM?$AA?2?$AAC?$AAu?$AAr?$AAr?$AAe?$AAn?$AAt?$AAC?$AAo?$AAn?$AAt?$AAr?$AAo?$AAl?$AAS?$AAe?$AAt?$AA?2?$AAS?$AAe?$AAr?$AAv?$AAi?$AAc?$AAe@
0x180008008: "__cdecl _security_cookie" __security_cookie
0x180006678: WofTaskReportHashGenerationToBitlockerErrorEventId
0x180003DD8: StringCbPrintfW
0x180006278: "__cdecl _imp_CloseHandle" __imp_CloseHandle
0x180006498: "__cdecl _imp_WinSqmSetDWORD" __imp_WinSqmSetDWORD
0x180006978: IID_ITaskHandler
0x180006238: "__cdecl _imp_RtlCompareMemory" __imp_RtlCompareMemory
0x1800069F0: "__cdecl _xmm@0000000000000000ffffffffffffffff" __xmm@0000000000000000ffffffffffffffff
0x180006880: "WimHashValidation" ??_C@_1CE@CCKOKOFC@?$AAW?$AAi?$AAm?$AAH?$AAa?$AAs?$AAh?$AAV?$AAa?$AAl?$AAi?$AAd?$AAa?$AAt?$AAi?$AAo?$AAn?$AA?$AA@
0x180006310: api-ms-win-core-com-l1-1-0_NULL_THUNK_DATA
0x1800029B8: "void __cdecl FileHashesCleanup(union _LARGE_INTEGER,unsigned short const * __ptr64)" ?FileHashesCleanup@@YAXT_LARGE_INTEGER@@PEBG@Z
0x180002084: "public: long __cdecl File::GetUSN(__int64 * __ptr64) __ptr64" ?GetUSN@File@@QEAAJPEA_J@Z
0x180006370: "__cdecl _imp_RegCreateKeyExW" __imp_RegCreateKeyExW
0x18040F028: "__cdecl _onexitbegin" __onexitbegin
0x1800023A0: "private: long __cdecl CWinTaskHandler::CreateWorkerThread(struct IUnknown * __ptr64) __ptr64" ?CreateWorkerThread@CWinTaskHandler@@AEAAJPEAUIUnknown@@@Z
0x180003670: "public: virtual long __cdecl CWinTaskClassFactoryT<class CWofTasksHandler,1>::QueryInterface(struct _GUID const & __ptr64,void * __ptr64 * __ptr64) __ptr64" ?QueryInterface@?$CWinTaskClassFactoryT@VCWofTasksHandler@@$00@@UEAAJAEBU_GUID@@PEAPEAX@Z
0x180006450: "__cdecl _imp__vsnwprintf" __imp__vsnwprintf
0x1800061C0: "__cdecl _imp_SetUnhandledExceptionFilter" __imp_SetUnhandledExceptionFilter
0x1800062C8: "__cdecl _imp_GetCurrentThread" __imp_GetCurrentThread
0x1800069E0: "\\.\" ??_C@_19BKJMDJK@?$AA?2?$AA?2?$AA?4?$AA?2?$AA?$AA@
0x1800062A8: "__cdecl _imp_FreeLibraryAndExitThread" __imp_FreeLibraryAndExitThread
0x18000715C: "__cdecl _IMPORT_DESCRIPTOR_KERNEL32" __IMPORT_DESCRIPTOR_KERNEL32
0x180006378: "__cdecl _imp_RegOpenKeyExW" __imp_RegOpenKeyExW
0x1800049B4: "__cdecl _security_init_cookie" __security_init_cookie
0x1800065C0: "HashDigestLength" ??_C@_1CC@DMMMEHOM@?$AAH?$AAa?$AAs?$AAh?$AAD?$AAi?$AAg?$AAe?$AAs?$AAt?$AAL?$AAe?$AAn?$AAg?$AAt?$AAh?$AA?$AA@
0x1800068A8: CLSID_WofTasks
0x1800063F0: "__cdecl _imp_BCryptFinishHash" __imp_BCryptFinishHash
0x180006380: "__cdecl _imp_RegGetValueW" __imp_RegGetValueW
0x1800063A0: "__cdecl _imp_EventEnabled" __imp_EventEnabled
0x180003E58: WofpOpenVolumeWithFlagsAndAttributes
0x180007148: "__cdecl _IMPORT_DESCRIPTOR_msvcrt" __IMPORT_DESCRIPTOR_msvcrt
0x180004D31: wcscmp
0x18000A004: ?g_taskModule@@3V?$CWinTaskModuleT@VCWofTasksHandler@@$1?CLSID_WofTasks@@3U_GUID@@B@@A
0x180008020: "struct _HASH_VALIDATION_EVENT HashValidationEvent" ?HashValidationEvent@@3U_HASH_VALIDATION_EVENT@@A
0x180006468: "__cdecl _imp_malloc" __imp_malloc
0x1800063B8: "__cdecl _imp_EventUnregister" __imp_EventUnregister
0x180006250: "__cdecl _imp_WriteFile" __imp_WriteFile
0x1800061A8: "__cdecl _imp_FveGetStatusW" __imp_FveGetStatusW
0x1800030E0: "public: virtual long __cdecl CWofTasksHandler::StopWorker(long * __ptr64) __ptr64" ?StopWorker@CWofTasksHandler@@UEAAJPEAJ@Z
0x180004B00: "__cdecl _report_gsfailure" __report_gsfailure
0x180006968: "%I64u" ??_C@_1M@OGLPPGPN@?$AA?$CF?$AAI?$AA6?$AA4?$AAu?$AA?$AA@
0x18040F038: "__cdecl _native_startup_state" __native_startup_state
0x180001E38: "public: long __cdecl File::Initialize(unsigned short const * __ptr64,unsigned long,unsigned long,unsigned long,int * __ptr64) __ptr64" ?Initialize@File@@QEAAJPEBGKKKPEAH@Z
0x180003970: "void __cdecl LogError(struct _EVENT_DESCRIPTOR const * __ptr64,int)" ?LogError@@YAXPEBU_EVENT_DESCRIPTOR@@H@Z
0x1800065B0: "SHA256" ??_C@_1O@HECGKAIN@?$AAS?$AAH?$AAA?$AA2?$AA5?$AA6?$AA?$AA@
0x180006298: "__cdecl _imp_SetThreadPriority" __imp_SetThreadPriority
0x1800022C0: DllRegisterServer
0x1800069D0: "%ws\%ws" ??_C@_1BA@NPEHGALP@?$AA?$CF?$AAw?$AAs?$AA?2?$AA?$CF?$AAw?$AAs?$AA?$AA@
0x180006470: "__cdecl _imp_free" __imp_free
0x180004920: "__cdecl IsNonwritableInCurrentImage" _IsNonwritableInCurrentImage
0x1800066B8: WNF_FVE_WIM_HASH_GENERATION_TRIGGER
0x18000204C: "public: long __cdecl File::Flush(void) __ptr64" ?Flush@File@@QEAAJXZ
0x180004D25: memset
0x180007238: "__cdecl _NULL_IMPORT_DESCRIPTOR" __NULL_IMPORT_DESCRIPTOR
0x180006240: "__cdecl _imp_ReadFile" __imp_ReadFile

[JEB Decompiler by PNF Software]