Generated by JEB on 2019/08/01

PE: C:\Windows\System32\cryptsp.dll Base=0x180000000 SHA-256=78D6A1CD068F5DE2A3DE7F83A975667FA332AA65EC59DD5991CEA1D021BD47C5
PDB: cryptsp.pdb GUID={455DDA60-8895-EA09-E790DEAC3609EDD4} Age=1

478 located named symbols:
0x180012818: ErrorSessionKey
0x18000A480: BenalohModExp64
0x18000C960: api-ms-win-core-file-l1-1-0_NULL_THUNK_DATA
0x18000DCE0: "unsigned char const * const rgbTestRoot1_PubKeyInfo" ?rgbTestRoot1_PubKeyInfo@@3QBEB
0x18000E3D0: "unsigned char const * const rgbTestRoot0_PubKeyInfo" ?rgbTestRoot0_PubKeyInfo@@3QBEB
0x18000CAA0: "__cdecl _imp_EtwUnregisterTraceGuids" __imp_EtwUnregisterTraceGuids
0x18000CAB8: "__cdecl _imp_atol" __imp_atol
0x18000CEC0: "CPDeriveKey" ??_C@_0M@LKMKHPPH@CPDeriveKey?$AA@
0x18000A320: BenalohMod64
0x180005398: CngRsa32Compat_MD5Final
0x180003B50: "__cdecl _delayLoadHelper2" __delayLoadHelper2
0x18000CB20: "__cdecl _imp_RtlFreeUnicodeString" __imp_RtlFreeUnicodeString
0x18000E8A8: "SHA384" ??_C@_1O@KOBLHLEG@?$AAS?$AAH?$AAA?$AA3?$AA8?$AA4?$AA?$AA@
0x18001063C: "__cdecl _IMPORT_DESCRIPTOR_ntdll" __IMPORT_DESCRIPTOR_ntdll
0x180014060: "__cdecl _imp_BCryptVerifySignature" __imp_BCryptVerifySignature
0x18000B3F0: "void __cdecl HashpAddExcludeRange(struct _EXCLUDE_RANGE * __ptr64 const,unsigned long * __ptr64,unsigned long,unsigned long)" ?HashpAddExcludeRange@@YAXQEAU_EXCLUDE_RANGE@@PEAKKK@Z
0x18000A2EC: BenalohGetPower64
0x180012018: "__cdecl _security_cookie_complement" __security_cookie_complement
0x18000CF98: "CPVerifySignature" ??_C@_0BC@NHEOEEDN@CPVerifySignature?$AA@
0x180009EC0: Compare
0x18000CFE0: "CPGetProvParam" ??_C@_0P@PLMLDLOG@CPGetProvParam?$AA@
0x180004CA0: CPReturnhWnd
0x18000CDC0: "__cdecl _sz_CRYPTBASE_dll" __sz_CRYPTBASE_dll
0x18000CAF8: "__cdecl _imp_RtlInitUnicodeString" __imp_RtlInitUnicodeString
0x180007D50: WppControlCallback
0x180007ABC: MD5HashData
0x1800045D0: "__cdecl guard_dispatch_icall_nop" _guard_dispatch_icall_nop
0x18000C948: "__cdecl _imp_CreateFileW" __imp_CreateFileW
0x18000CEB0: "CPGenKey" ??_C@_08KIKMCPCP@CPGenKey?$AA@
0x180004301: "__cdecl _imp_load_BCryptImportKeyPair" __imp_load_BCryptImportKeyPair
0x18000A248: Sub
0x180004E94: CheckSignature
0x180014038: "__cdecl _imp_BCryptDestroyKey" __imp_BCryptDestroyKey
0x18000C1E0: OptionalFunctionNames
0x18000CB48: "__cdecl _imp_EtwGetTraceLoggerHandle" __imp_EtwGetTraceLoggerHandle
0x180006870: CryptGetProvParam
0x18000E858: "__cdecl _pfnDliFailureHook2" __pfnDliFailureHook2
0x180004140: AccumulateSquares64
0x1800073E0: CryptSetProviderW
0x18000D010: "CPDuplicateKey" ??_C@_0P@JOHFOJAB@CPDuplicateKey?$AA@
0x18000CA70: "__cdecl _imp_RegDeleteKeyExA" __imp_RegDeleteKeyExA
0x180006D00: CryptSetProviderA
0x1800106C8: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-file-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-file-l1-1-0
0x18000CAC0: "__cdecl _imp_RtlUnicodeStringToAnsiString" __imp_RtlUnicodeStringToAnsiString
0x18000C9A8: api-ms-win-core-heap-l2-1-0_NULL_THUNK_DATA
0x18000E808: "System\Setup" ??_C@_1BK@DBNBIMPE@?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AA?2?$AAS?$AAe?$AAt?$AAu?$AAp?$AA?$AA@
0x18000CAF0: "__cdecl _imp_NtSetInformationThread" __imp_NtSetInformationThread
0x1800032C8: WppInitUm
0x18000B1D4: "long __cdecl I_HashComputeMemoryHash<struct BCRYPT_HASH_CTXT>(struct BCRYPT_HASH_CTXT * __ptr64,unsigned char * __ptr64,unsigned long,unsigned long,unsigned char * __ptr64,unsigned long * __ptr64)" ??$I_HashComputeMemoryHash@UBCRYPT_HASH_CTXT@@@@YAJPEAUBCRYPT_HASH_CTXT@@PEAEKK1PEAK@Z
0x18000AA3C: BenalohScramblePowerTable64
0x18000CEF0: "CPGetKeyParam" ??_C@_0O@MNFMAOJJ@CPGetKeyParam?$AA@
0x18000CBA8: "__cdecl _guard_dispatch_icall_fptr" __guard_dispatch_icall_fptr
0x18000CFF0: "CPSetHashParam" ??_C@_0P@DCLEILPF@CPSetHashParam?$AA@
0x18000CAD0: "__cdecl _imp_strcat_s" __imp_strcat_s
0x180012800: KerbGlobalStrToKeyProvider
0x18000AC4C: DigitLen64
0x18000CA48: "__cdecl _imp_RegSetValueExA" __imp_RegSetValueExA
0x180003F03: "__cdecl _imp_load_BCryptFinishHash" __imp_load_BCryptFinishHash
0x180002510: CryptAcquireContextA
0x180007490: CryptSignHashA
0x1800086B8: MinAsn1ExtractContent
0x180004BF0: BuildVHash
0x180014050: "__cdecl _imp_BCryptCreateHash" __imp_BCryptCreateHash
0x180007DD8: "int __cdecl I_IsNtPe32File(struct _CRYPTOAPI_BLOB * __ptr64)" ?I_IsNtPe32File@@YAHPEAU_CRYPTOAPI_BLOB@@@Z
0x18000909C: "int __cdecl I_FindCertificate(struct _LOADED_IMAGE * __ptr64,unsigned long,struct _WIN_CERTIFICATE * __ptr64 * __ptr64)" ?I_FindCertificate@@YAHPEAU_LOADED_IMAGE@@KPEAPEAU_WIN_CERTIFICATE@@@Z
0x180008758: MinAsn1ExtractValues
0x18000C990: api-ms-win-core-heap-l1-1-0_NULL_THUNK_DATA
0x180004020: Accumulate
0x18000CD1C: "Name" ??_C@_04FABLJDN@Name?$AA@
0x18000CF40: "CPCreateHash" ??_C@_0N@CLIAIOAI@CPCreateHash?$AA@
0x18000CCFC: "__cdecl _guard_iat_table" __guard_iat_table
0x180004337: "__cdecl _imp_load_BCryptCloseAlgorithmProvider" __imp_load_BCryptCloseAlgorithmProvider
0x18000CA30: api-ms-win-core-processenvironment-l1-1-0_NULL_THUNK_DATA
0x180004597: memcpy
0x18000C9D8: "__cdecl _imp_LoadLibraryExW" __imp_LoadLibraryExW
0x180001BA0: CryptDestroyHash
0x180003D8C: "__cdecl _security_init_cookie_ex" __security_init_cookie_ex
0x18000CB90: "__cdecl _imp_memset" __imp_memset
0x18000D090: "#666" ??_C@_19PMNODGGN@?$AA?$CD?$AA6?$AA6?$AA6?$AA?$AA@
0x18000CF78: "CPDestroyHash" ??_C@_0O@BHONDLHE@CPDestroyHash?$AA@
0x180004CCC: CheckAllSignatures
0x18000DF10: "unsigned char const * const rgbMicrosoftRoot4_PubKeyInfo" ?rgbMicrosoftRoot4_PubKeyInfo@@3QBEB
0x180012808: pbContextInfo
0x18000D060: "NTE_PROVIDER_DLL_FAIL" ??_C@_0BG@PIPGBEBA@NTE_PROVIDER_DLL_FAIL?$AA@
0x1800125F0: cbContextInfo
0x180003E5A: RtlUnhandledExceptionFilter
0x18000D190: szusertype
0x18000CB70: "__cdecl _imp_EtwRegisterTraceGuidsW" __imp_EtwRegisterTraceGuidsW
0x180003E1E: "__cdecl _C_specific_handler" __C_specific_handler
0x180003E36: RtlCaptureContext
0x180009294: imagehack_ImageGetCertificateData
0x1800045A3: memmove
0x18000C988: "__cdecl _imp_HeapFree" __imp_HeapFree
0x180005130: CheckSignatureInFile
0x1800125E8: WPP_REGISTRATION_GUIDS
0x180004313: "__cdecl _imp_load_BCryptGetProperty" __imp_load_BCryptGetProperty
0x18000CF20: "CPEncrypt" ??_C@_09KFLJGEIC@CPEncrypt?$AA@
0x18000D294: "MZ" ??_C@_02DIKIINKA@MZ?$AA@
0x18000D078: "dwErr" ??_C@_05HABMCAIK@dwErr?$AA@
0x18000CD24: "Type" ??_C@_04KOACHJEN@Type?$AA@
0x18000C970: api-ms-win-core-handle-l1-1-0_NULL_THUNK_DATA
0x180014000: "__cdecl _imp_SystemFunction001" __imp_SystemFunction001
0x180014008: "__cdecl _imp_SystemFunction003" __imp_SystemFunction003
0x180014010: "__cdecl _imp_SystemFunction002" __imp_SystemFunction002
0x18000CA98: "__cdecl _imp_NtQueryInformationThread" __imp_NtQueryInformationThread
0x18000CA80: "__cdecl _imp_RegCloseKey" __imp_RegCloseKey
0x18000E4C0: "unsigned char const * const rgbTestRoot0_Name" ?rgbTestRoot0_Name@@3QBEB
0x18000DC40: "unsigned char const * const rgbTestRoot1_Name" ?rgbTestRoot1_Name@@3QBEB
0x18000449C: "__cdecl _GSHandlerCheckCommon" __GSHandlerCheckCommon
0x1800053DC: CngRsa32Compat_MD5Init
0x180009D7C: BSafeEncPublicEx
0x18000CA40: "__cdecl _imp_RegEnumKeyExA" __imp_RegEnumKeyExA
0x18000E828: "SystemSetupInProgress" ??_C@_1CM@DHJDDPJO@?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AAS?$AAe?$AAt?$AAu?$AAp?$AAI?$AAn?$AAP?$AAr?$AAo?$AAg?$AAr?$AAe?$AAs?$AAs?$AA?$AA@
0x1800125B8: "__cdecl _hmod__CRYPTBASE_dll" __hmod__CRYPTBASE_dll
0x1800125C0: WPP_MAIN_CB
0x18000DA10: "unsigned char const * const rgbMicrosoftRoot3_PubKeyInfo" ?rgbMicrosoftRoot3_PubKeyInfo@@3QBEB
0x180008A54: I_MinCryptMapFile
0x18000ADD4: "long __cdecl HashpEmitExcludeRange<struct BCRYPT_HASH_CTXT>(struct BCRYPT_HASH_CTXT * __ptr64,unsigned long,struct _EXCLUDE_RANGE * __ptr64 const,unsigned long,struct _HASHLIB_LOADED_IMAGE * __ptr64,unsigned long,unsigned long)" ??$HashpEmitExcludeRange@UBCRYPT_HASH_CTXT@@@@YAJPEAUBCRYPT_HASH_CTXT@@KQEAU_EXCLUDE_RANGE@@KPEAU_HASHLIB_LOADED_IMAGE@@KK@Z
0x180002160: CryptAcquireContextW
0x180004190: Accumulate64
0x180007590: CryptSignHashW
0x18000E854: "__cdecl _DefaultResolveDelayLoadedAPIFlags" __DefaultResolveDelayLoadedAPIFlags
0x18000D260: szenumproviders
0x18000CEE0: "CPSetKeyParam" ??_C@_0O@MCECNIBK@CPSetKeyParam?$AA@
0x18000CB38: "__cdecl _imp_NtTerminateProcess" __imp_NtTerminateProcess
0x18000CAD8: "__cdecl _imp_RtlOpenCurrentUser" __imp_RtlOpenCurrentUser
0x180008C64: "long __cdecl I_MinCryptVerifySignerAuthenticatedAttributes(unsigned int,unsigned char * __ptr64 const,unsigned long * __ptr64,struct _CRYPTOAPI_BLOB * __ptr64)" ?I_MinCryptVerifySignerAuthenticatedAttributes@@YAJIQEAEPEAKPEAU_CRYPTOAPI_BLOB@@@Z
0x18000C9D0: "__cdecl _imp_LoadLibraryExA" __imp_LoadLibraryExA
0x180001F60: EnterKeyCritSec
0x180003FE8: "__cdecl _imp_load_SystemFunction001" __imp_load_SystemFunction001
0x18000120C: LocalVerifySignatureW
0x18000CA90: api-ms-win-core-registry-l1-1-0_NULL_THUNK_DATA
0x18000E140: "unsigned char const * const rgbMicrosoftRoot2_PubKeyInfo" ?rgbMicrosoftRoot2_PubKeyInfo@@3QBEB
0x18000C940: api-ms-win-core-errorhandling-l1-1-0_NULL_THUNK_DATA
0x180003420: CProvVerifyImage
0x180001880: CryptDestroyKey
0x1800042EF: "__cdecl _imp_load_BCryptVerifySignature" __imp_load_BCryptVerifySignature
0x180006BD0: CryptSetProvParam
0x1800054F0: CryptDecrypt
0x180014020: "__cdecl _imp_BCryptHashData" __imp_BCryptHashData
0x180004350: DllMain
0x180004500: "__cdecl _GSHandlerCheck_SEH" __GSHandlerCheck_SEH
0x18000CAE8: "__cdecl _imp___C_specific_handler" __imp___C_specific_handler
0x18000CB40: "__cdecl _imp_RtlCaptureContext" __imp_RtlCaptureContext
0x18000C9F8: api-ms-win-core-libraryloader-l1-2-0_NULL_THUNK_DATA
0x180008224: MinCryptDecodeHashAlgorithmIdentifier
0x180005C40: CryptEncrypt
0x18000FE98: CRYPTBASE_NULL_THUNK_DATA_DLB
0x18000C938: "__cdecl _imp_GetLastError" __imp_GetLastError
0x1800089D4: MinAsn1FindAttribute
0x180004478: "__cdecl _GSHandlerCheck" __GSHandlerCheck
0x180003FFA: "__cdecl _imp_load_SystemFunction002" __imp_load_SystemFunction002
0x18000CB18: "__cdecl _imp_EtwTraceMessage" __imp_EtwTraceMessage
0x180006690: CryptEnumProvidersW
0x18000CB80: "__cdecl _imp_memcmp" __imp_memcmp
0x180007E2C: MinCryptHashFile
0x180006370: CryptEnumProvidersA
0x18000D4A0: "unsigned char const * const rgbMicrosoftRoot1_PubKeyInfo" ?rgbMicrosoftRoot1_PubKeyInfo@@3QBEB
0x18000B058: "void __cdecl HashpPadHash<struct BCRYPT_HASH_CTXT * __ptr64>(struct BCRYPT_HASH_CTXT * __ptr64,unsigned long,unsigned long)" ??$HashpPadHash@PEAUBCRYPT_HASH_CTXT@@@@YAXPEAUBCRYPT_HASH_CTXT@@KK@Z
0x180009EF8: DigitLen
0x180014048: "__cdecl _imp_BCryptCloseAlgorithmProvider" __imp_BCryptCloseAlgorithmProvider
0x180001D80: CryptHashData
0x18000E888: "SHA1" ??_C@_19DILNDFJH@?$AAS?$AAH?$AAA?$AA1?$AA?$AA@
0x18000D038: "NULL" ??_C@_19CIJIHAKK@?$AAN?$AAU?$AAL?$AAL?$AA?$AA@
0x18000AAFC: BenalohSetup64
0x180010718: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-delayload-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-delayload-l1-1-0
0x18000CA60: "__cdecl _imp_RegDeleteValueA" __imp_RegDeleteValueA
0x18000E854: "__cdecl _ResolveDelayLoadedAPIFlags" __ResolveDelayLoadedAPIFlags
0x180005890: CryptDuplicateHash
0x18000C9E8: "__cdecl _imp_SizeofResource" __imp_SizeofResource
0x1800096E8: MinCryptVerifyCertificate
0x18000CF30: "CPDecrypt" ??_C@_09GLBEDAOG@CPDecrypt?$AA@
0x1800019A0: CryptCreateHash
0x18000E8B8: "SHA512" ??_C@_1O@GKBAHMNF@?$AAS?$AAH?$AAA?$AA5?$AA1?$AA2?$AA?$AA@
0x180010650: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-libraryloader-l1-2-0" __IMPORT_DESCRIPTOR_api-ms-win-core-libraryloader-l1-2-0
0x180014018: CRYPTBASE_NULL_THUNK_DATA_DLA
0x18000CD68: szmachinetype
0x180007B6C: WPP_SF_
0x18000CF50: "CPHashData" ??_C@_0L@CDBNAFIL@CPHashData?$AA@
0x18000C978: "__cdecl _imp_HeapAlloc" __imp_HeapAlloc
0x18000C9B8: "__cdecl _imp_FreeLibrary" __imp_FreeLibrary
0x180003F5D: "__cdecl _imp_load_SystemFunction003" __imp_load_SystemFunction003
0x18000FC54: "__cdecl _NULL_DELAY_IMPORT_DESCRIPTOR" __NULL_DELAY_IMPORT_DESCRIPTOR
0x180005470: CngRsa32Compat_rc4_key
0x18000CFB0: "CPGenRandom" ??_C@_0M@GCOGPPOB@CPGenRandom?$AA@
0x18000E540: "unsigned char const * const rgbMicrosoftRoot0_PubKeyInfo" ?rgbMicrosoftRoot0_PubKeyInfo@@3QBEB
0x180001630: CryptImportKey
0x180003E72: "__cdecl _tailMerge_bcrypt_dll" __tailMerge_bcrypt_dll
0x18000C930: "__cdecl _imp_SetLastError" __imp_SetLastError
0x180010704: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-delayload-l1-1-1" __IMPORT_DESCRIPTOR_api-ms-win-core-delayload-l1-1-1
0x18000C9C8: "__cdecl _imp_GetModuleFileNameW" __imp_GetModuleFileNameW
0x18000AEA8: "long __cdecl HashpHashMappedBytes<struct BCRYPT_HASH_CTXT>(struct BCRYPT_HASH_CTXT * __ptr64,unsigned long,struct _HASHLIB_LOADED_IMAGE * __ptr64,unsigned long,unsigned long)" ??$HashpHashMappedBytes@UBCRYPT_HASH_CTXT@@@@YAJPEAUBCRYPT_HASH_CTXT@@KPEAU_HASHLIB_LOADED_IMAGE@@KK@Z
0x180010664: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-registry-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-registry-l1-1-0
0x180009434: MinAsn1ParseCertificate
0x180009588: "unsigned long __cdecl I_MinCryptFindRootByKey(struct _CRYPTOAPI_BLOB * __ptr64,struct _CRYPTOAPI_BLOB * __ptr64 * __ptr64)" ?I_MinCryptFindRootByKey@@YAKPEAU_CRYPTOAPI_BLOB@@PEAPEAU1@@Z
0x180009344: MinAsn1ParseAttributes
0x18000A9F8: BenalohModSquare64
0x18000CBA0: "__cdecl _guard_check_icall_fptr" __guard_check_icall_fptr
0x180003E42: RtlLookupFunctionEntry
0x180014070: "__cdecl _imp_BCryptGetProperty" __imp_BCryptGetProperty
0x180008BB8: "struct _CRYPTOAPI_BLOB * __ptr64 __cdecl I_MinCryptFindSignerCertificateByIssuerAndSerialNumber(struct _CRYPTOAPI_BLOB * __ptr64,struct _CRYPTOAPI_BLOB * __ptr64,unsigned long,struct _CRYPTOAPI_BLOB (* __ptr64 const)[15])" ?I_MinCryptFindSignerCertificateByIssuerAndSerialNumber@@YAPEAU_CRYPTOAPI_BLOB@@PEAU1@0KQEAY0P@U1@@Z
0x18000D030: "NULL" ??_C@_04HIBGFPH@NULL?$AA@
0x180014040: "__cdecl _imp_BCryptEncrypt" __imp_BCryptEncrypt
0x18000C958: "__cdecl _imp_GetFileAttributesExW" __imp_GetFileAttributesExW
0x18000AC74: Multiply64
0x18000E670: "SOFTWARE\Microsoft\SystemCertifi" ??_C@_1MC@DGFKMOBH@?$AAS?$AAO?$AAF?$AAT?$AAW?$AAA?$AAR?$AAE?$AA?2?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AAC?$AAe?$AAr?$AAt?$AAi?$AAf?$AAi@
0x18000CF88: "CPSignHash" ??_C@_0L@IKNINJJP@CPSignHash?$AA@
0x1800125B0: "__cdecl _hmod__bcrypt_dll" __hmod__bcrypt_dll
0x180003E2A: NtTerminateProcess
0x18000CB00: "__cdecl _imp_RtlNtStatusToDosError" __imp_RtlNtStatusToDosError
0x180014058: "__cdecl _imp_BCryptDestroyHash" __imp_BCryptDestroyHash
0x1800036D0: UseOutsideStringToKey
0x180001FB0: CryptGetDefaultProviderW
0x18000B2F0: "long __cdecl HashpInitHash(struct BCRYPT_HASH_CTXT * __ptr64,unsigned long * __ptr64)" ?HashpInitHash@@YAJPEAUBCRYPT_HASH_CTXT@@PEAK@Z
0x18000C920: "__cdecl _imp_ResolveDelayLoadedAPI" __imp_ResolveDelayLoadedAPI
0x18000D750: "unsigned char const * const rgbMicrosoftFlightRoot1_PubKeyInfo" ?rgbMicrosoftFlightRoot1_PubKeyInfo@@3QBEB
0x18000759C: EncryptKey
0x180008150: "long __cdecl I_ConvertParsedRSAPubKeyToBCryptPubKey(struct _CRYPTOAPI_BLOB * __ptr64 const,struct BCRYPT_PUB_KEY_CONTENT * __ptr64)" ?I_ConvertParsedRSAPubKeyToBCryptPubKey@@YAJQEAU_CRYPTOAPI_BLOB@@PEAUBCRYPT_PUB_KEY_CONTENT@@@Z
0x180007B98: WPP_SF_Ds
0x180007C84: WPP_SF_ds
0x18000C120: FunctionNames
0x180012000: WPP_GLOBAL_Control
0x18000A9B0: BenalohModMultiply64
0x18000CA18: api-ms-win-core-memory-l1-1-0_NULL_THUNK_DATA
0x18000C9E0: "__cdecl _imp_FindResourceExW" __imp_FindResourceExW
0x18000CD10: "Image Path" ??_C@_0L@BHCFMCAG@Image?5Path?$AA@
0x18000E740: "SOFTWARE\Microsoft\SystemCertifi" ??_C@_1MC@MKOACEND@?$AAS?$AAO?$AAF?$AAT?$AAW?$AAA?$AAR?$AAE?$AA?2?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AAC?$AAe?$AAr?$AAt?$AAi?$AAf?$AAi@
0x180005DD0: CryptEnumProviderTypesA
0x180006180: CryptEnumProviderTypesW
0x180009638: "unsigned long __cdecl I_MinCryptFindRootByName(struct _CRYPTOAPI_BLOB * __ptr64,struct _CRYPTOAPI_BLOB * __ptr64 * __ptr64)" ?I_MinCryptFindRootByName@@YAKPEAU_CRYPTOAPI_BLOB@@PEAPEAU1@@Z
0x18000D400: "unsigned char const * const rgbMicrosoftFlightRoot1_Name" ?rgbMicrosoftFlightRoot1_Name@@3QBEB
0x180003F27: "__cdecl _imp_load_BCryptHashData" __imp_load_BCryptHashData
0x18001068C: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-heap-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-heap-l1-1-0
0x180008300: MinCryptHashMemory
0x180003BA0: "__cdecl _security_check_cookie" __security_check_cookie
0x1800106B4: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-heap-l2-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-heap-l2-1-0
0x180004120: BenalohEstimateQuotient64
0x18000C9C0: "__cdecl _imp_GetProcAddress" __imp_GetProcAddress
0x18000CF00: "CPExportKey" ??_C@_0M@OPGDHPIM@CPExportKey?$AA@
0x18000D2A8: "RSA" ??_C@_17CEGMJBCM@?$AAR?$AAS?$AAA?$AA?$AA@
0x18000CB58: "__cdecl _imp_RtlFreeAnsiString" __imp_RtlFreeAnsiString
0x180003348: WppCleanupUm
0x180003F39: "__cdecl _imp_load_BCryptCreateHash" __imp_load_BCryptCreateHash
0x18000CE98: "CPReleaseContext" ??_C@_0BB@JJJFNEII@CPReleaseContext?$AA@
0x180003860: CryptGenKey
0x180008D88: MinCryptVerifySignedDataWithPolicy
0x18000A290: "__cdecl Add" _Add
0x18000CF60: "CPHashSessionKey" ??_C@_0BB@MNEMFPOA@CPHashSessionKey?$AA@
0x18000B2BC: "void __cdecl HashpFinalizeHash(struct BCRYPT_HASH_CTXT * __ptr64,unsigned char * __ptr64,void * __ptr64 * __ptr64,unsigned char * __ptr64,unsigned long)" ?HashpFinalizeHash@@YAXPEAUBCRYPT_HASH_CTXT@@PEAEPEAPEAX1K@Z
0x18000D0A0: szprovidertypes
0x180007310: CryptSetProviderExW
0x18000C9A0: "__cdecl _imp_LocalAlloc" __imp_LocalAlloc
0x18000CB68: "__cdecl _imp_EtwGetTraceEnableLevel" __imp_EtwGetTraceEnableLevel
0x18000CF10: "CPImportKey" ??_C@_0M@BDAIJIDM@CPImportKey?$AA@
0x18000C910: "__cdecl _imp_DelayLoadFailureHook" __imp_DelayLoadFailureHook
0x180006E50: CryptSetProviderExA
0x18000C980: "__cdecl _imp_GetProcessHeap" __imp_GetProcessHeap
0x1800040A0: Reduce
0x1800014D0: CryptExportKey
0x18000FC90: CRYPTBASE_NULL_THUNK_DATA_DLN
0x18000CAA8: "__cdecl _imp_RtlInitAnsiString" __imp_RtlInitAnsiString
0x18000FC34: "__cdecl _DELAY_IMPORT_DESCRIPTOR_CRYPTBASE_dll" __DELAY_IMPORT_DESCRIPTOR_CRYPTBASE_dll
0x18000D048: "GetLastError()" ??_C@_0P@OLMLMBJL@GetLastError?$CI?$CJ?$AA@
0x18000CA10: "__cdecl _imp_UnmapViewOfFile" __imp_UnmapViewOfFile
0x180003990: CryptGetUserKey
0x180003EF1: "__cdecl _imp_load_BCryptDestroyKey" __imp_load_BCryptDestroyKey
0x180003F4B: "__cdecl _imp_load_BCryptGenerateSymmetricKey" __imp_load_BCryptGenerateSymmetricKey
0x180007624: GetCryptSigResourcePtr
0x180001200: CryptVerifySignatureW
0x180001010: CryptVerifySignatureA
0x18000CBB0: "__cdecl _guard_fids_table" __guard_fids_table
0x18000C010: "__cdecl load_config_used" _load_config_used
0x18000CDB0: "__cdecl _sz_bcrypt_dll" __sz_bcrypt_dll
0x18000FCF8: bcrypt_NULL_THUNK_DATA_DLN
0x180003E66: "__cdecl _imp_load_BCryptEncrypt" __imp_load_BCryptEncrypt
0x180014080: bcrypt_NULL_THUNK_DATA_DLA
0x18000FE58: bcrypt_NULL_THUNK_DATA_DLB
0x18000C928: api-ms-win-core-delayload-l1-1-1_NULL_THUNK_DATA
0x18000C918: api-ms-win-core-delayload-l1-1-0_NULL_THUNK_DATA
0x180005A70: CryptDuplicateKey
0x180012020: KerbGlobalAvailableStrToKeyProvider
0x18000CA88: "__cdecl _imp_RegQueryValueExA" __imp_RegQueryValueExA
0x180010678: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-processenvironment-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-processenvironment-l1-1-0
0x18000D980: "unsigned char const * const rgbMicrosoftRoot4_Name" ?rgbMicrosoftRoot4_Name@@3QBEB
0x180009F20: Mod
0x1800033A0: CryptContextAddRef
0x18000CE80: "CPAcquireContext" ??_C@_0BB@JOHKMLCL@CPAcquireContext?$AA@
0x18000798C: LocalSignHashW
0x180014078: "__cdecl _imp_BCryptOpenAlgorithmProvider" __imp_BCryptOpenAlgorithmProvider
0x18000C9F0: "__cdecl _imp_DisableThreadLibraryCalls" __imp_DisableThreadLibraryCalls
0x18000CAE0: "__cdecl _imp_NtClose" __imp_NtClose
0x180003F69: "__cdecl _tailMerge_cryptbase_dll" __tailMerge_cryptbase_dll
0x18000CB60: "__cdecl _imp_RtlLookupFunctionEntry" __imp_RtlLookupFunctionEntry
0x180014030: "__cdecl _imp_BCryptGenerateSymmetricKey" __imp_BCryptGenerateSymmetricKey
0x18000CB78: "__cdecl _imp_EtwGetTraceEnableFlags" __imp_EtwGetTraceEnableFlags
0x18000CB50: "__cdecl _imp_RtlAnsiStringToUnicodeString" __imp_RtlAnsiStringToUnicodeString
0x180006AB0: CryptSetKeyParam
0x18000CA08: "__cdecl _imp_CreateFileMappingW" __imp_CreateFileMappingW
0x18000CAC8: "__cdecl _imp_RtlVirtualUnwind" __imp_RtlVirtualUnwind
0x18000E858: "__cdecl _pfnDefaultDliFailureHook2" __pfnDefaultDliFailureHook2
0x18000B46C: "long __cdecl HashpParsePEHeader(void const * __ptr64,unsigned long,unsigned long,unsigned char,long (__cdecl*)(void * __ptr64,unsigned long,unsigned long * __ptr64,void * __ptr64 * __ptr64,unsigned long * __ptr64),void * __ptr64,struct HASHLIB_CERT_INFO * __ptr64,struct _HASHLIB_LOADED_IMAGE * __ptr64,struct _EXCLUDE_RANGE * __ptr64 const,unsigned long * __ptr64)" ?HashpParsePEHeader@@YAJPEBXKKEP6AJPEAXKPEAKPEAPEAX2@Z1PEAUHASHLIB_CERT_INFO@@PEAU_HASHLIB_LOADED_IMAGE@@QEAU_EXCLUDE_RANGE@@2@Z
0x180007F20: MinCryptVerifySignedFile
0x180004460: "__cdecl guard_check_icall_nop" _guard_check_icall_nop
0x18000B250: "long __cdecl HashComputeImageHash(void * __ptr64,void const * __ptr64,unsigned long,unsigned char * __ptr64,unsigned long * __ptr64,struct HASHLIB_CERT_INFO * __ptr64,unsigned char * __ptr64)" ?HashComputeImageHash@@YAJPEAXPEBXKPEAEPEAKPEAUHASHLIB_CERT_INFO@@2@Z
0x18000458B: memcmp
0x18000CA28: "__cdecl _imp_ExpandEnvironmentStringsA" __imp_ExpandEnvironmentStringsA
0x180001100: CryptSetHashParam
0x180009B4C: KeysFromIndex
0x180008FD4: "int __cdecl I_CalculateImagePtrs(struct _LOADED_IMAGE * __ptr64)" ?I_CalculateImagePtrs@@YAHPEAU_LOADED_IMAGE@@@Z
0x1800106F0: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-handle-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-handle-l1-1-0
0x1800098B8: I_CheckIsFlightRootAllowed
0x180003F15: "__cdecl _imp_load_BCryptDestroyHash" __imp_load_BCryptDestroyHash
0x180009900: I_CheckIsTestRootAllowed
0x180009D20: SystemFunction032
0x180009D20: SystemFunction033
0x180003830: SystemFunction030
0x180003830: SystemFunction031
0x18000CB10: "__cdecl _imp_RtlUnhandledExceptionFilter" __imp_RtlUnhandledExceptionFilter
0x18000CB98: ntdll_NULL_THUNK_DATA
0x18000CB88: "__cdecl _imp_memcpy" __imp_memcpy
0x18000E8C8: "MD5" ??_C@_17HLHJLHED@?$AAM?$AAD?$AA5?$AA?$AA@
0x180001EC0: EnterProviderCritSec
0x18000B3A0: "unsigned short const * __ptr64 __cdecl CapiAlgIdToCngAlgId(unsigned int)" ?CapiAlgIdToCngAlgId@@YAPEBGI@Z
0x18000A848: BenalohModExp64Wrapper
0x180012010: "__cdecl _security_cookie" __security_cookie
0x18000CA58: "__cdecl _imp_RegQueryValueExW" __imp_RegQueryValueExW
0x18000D6E0: "unsigned char const * const rgbMicrosoftRoot2_Name" ?rgbMicrosoftRoot2_Name@@3QBEB
0x18000CAB0: "__cdecl _imp_strcpy_s" __imp_strcpy_s
0x180001360: CryptGenRandom
0x18000AD10: Square64
0x18000840C: MinCryptVerifySignedHash
0x18000C968: "__cdecl _imp_CloseHandle" __imp_CloseHandle
0x18000CB08: "__cdecl _imp_RtlCompareMemory" __imp_RtlCompareMemory
0x18000C998: "__cdecl _imp_LocalFree" __imp_LocalFree
0x1800106A0: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-errorhandling-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-errorhandling-l1-1-0
0x180006960: CryptHashSessionKey
0x18000D058: "err" ??_C@_03JIDPIAJI@err?$AA@
0x1800094AC: MinAsn1ParseSignedDataCertificatesEx
0x18000CA68: "__cdecl _imp_RegCreateKeyExA" __imp_RegCreateKeyExA
0x18000D020: "CPDuplicateHash" ??_C@_0BA@BPOIMMIB@CPDuplicateHash?$AA@
0x180014068: "__cdecl _imp_BCryptImportKeyPair" __imp_BCryptImportKeyPair
0x180003430: SystemFunction026
0x180003790: SystemFunction027
0x180003430: SystemFunction024
0x180009CA0: SystemFunction025
0x180009C20: SystemFunction022
0x180009C30: SystemFunction023
0x180009C20: SystemFunction020
0x180009C30: SystemFunction021
0x180007CDC: WPP_SF_qS
0x18000AF94: "long __cdecl HashpImageGetDigestStream<struct BCRYPT_HASH_CTXT>(struct BCRYPT_HASH_CTXT * __ptr64,unsigned long,void const * __ptr64,unsigned long,unsigned long,long (__cdecl*)(void * __ptr64,unsigned long,unsigned long * __ptr64,void * __ptr64 * __ptr64,unsigned long * __ptr64),void * __ptr64,struct HASHLIB_CERT_INFO * __ptr64)" ??$HashpImageGetDigestStream@UBCRYPT_HASH_CTXT@@@@YAJPEAUBCRYPT_HASH_CTXT@@KPEBXKKP6AJPEAXKPEAKPEAPEAX3@Z2PEAUHASHLIB_CERT_INFO@@@Z
0x18000CA78: "__cdecl _imp_RegQueryInfoKeyA" __imp_RegQueryInfoKeyA
0x18000CA38: "__cdecl _imp_RegOpenKeyExA" __imp_RegOpenKeyExA
0x1800076B4: HashTheFile
0x18000CA50: "__cdecl _imp_RegOpenKeyExW" __imp_RegOpenKeyExW
0x180003D40: "__cdecl _security_init_cookie" __security_init_cookie
0x18000E860: "HashDigestLength" ??_C@_1CC@DMMMEHOM@?$AAH?$AAa?$AAs?$AAh?$AAD?$AAi?$AAg?$AAe?$AAs?$AAt?$AAL?$AAe?$AAn?$AAg?$AAt?$AAh?$AA?$AA@
0x18000863C: MinAsn1DecodeLength
0x180014028: "__cdecl _imp_BCryptFinishHash" __imp_BCryptFinishHash
0x18000D2B0: "RSAPUBLICBLOB" ??_C@_1BM@BJJGGDHH@?$AAR?$AAS?$AAA?$AAP?$AAU?$AAB?$AAL?$AAI?$AAC?$AAB?$AAL?$AAO?$AAB?$AA?$AA@
0x18000CB28: "__cdecl _imp_NtQuerySystemInformation" __imp_NtQuerySystemInformation
0x18000D000: "CPGetHashParam" ??_C@_0P@EGAKEHLJ@CPGetHashParam?$AA@
0x18000D650: "unsigned char const * const rgbMicrosoftRoot3_Name" ?rgbMicrosoftRoot3_Name@@3QBEB
0x18000B0E8: ??$I_HashComputeImageHashEx@UBCRYPT_HASH_CTXT@@$$T@@YAJPEAUBCRYPT_HASH_CTXT@@PEBXKKP6AJPEAXKPEAKPEAPEAX3@Z2PEAE3PEAUHASHLIB_CERT_INFO@@6$$T6K@Z
0x180003AA4: BuildVKey
0x18000CB30: "__cdecl _imp_memmove" __imp_memmove
0x180001F10: EnterHashCritSec
0x1800022C0: CryptGetDefaultProviderA
0x18000FC14: "__cdecl _DELAY_IMPORT_DESCRIPTOR_bcrypt_dll" __DELAY_IMPORT_DESCRIPTOR_bcrypt_dll
0x180003E4E: RtlVirtualUnwind
0x18000CDE0: "Microsoft Primitive Provider" ??_C@_1DK@HJHMGPGD@?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?5?$AAP?$AAr?$AAi?$AAm?$AAi?$AAt?$AAi?$AAv?$AAe?$AA?5?$AAP?$AAr?$AAo?$AAv?$AAi?$AAd?$AAe?$AAr?$AA?$AA@
0x180009C90: SystemFunction018
0x180009C40: SystemFunction016
0x180009C20: SystemFunction014
0x180009C30: SystemFunction015
0x180009B80: SystemFunction012
0x180009BD0: SystemFunction013
0x180009AE0: SystemFunction010
0x180009B40: SystemFunction011
0x18000C950: "__cdecl _imp_GetFileSize" __imp_GetFileSize
0x180004250: Add64
0x180003BF0: "__cdecl _report_gsfailure" __report_gsfailure
0x180004325: "__cdecl _imp_load_BCryptOpenAlgorithmProvider" __imp_load_BCryptOpenAlgorithmProvider
0x180012810: hWnd
0x18000D080: "TypeName" ??_C@_08NNKIOIN@TypeName?$AA@
0x18000CED0: "CPDestroyKey" ??_C@_0N@PGLPDBEM@CPDestroyKey?$AA@
0x18000CDD0: WPP_c36fa375a1fa3b473e5e510998607e3e_Traceguids
0x18000541C: CngRsa32Compat_rc4
0x18000CA20: "__cdecl _imp_SearchPathW" __imp_SearchPathW
0x18000E370: "unsigned char const * const rgbMicrosoftRoot0_Name" ?rgbMicrosoftRoot0_Name@@3QBEB
0x1800041E0: Reduce64
0x18000C9B0: "__cdecl _imp_LoadResource" __imp_LoadResource
0x180003180: CryptReleaseContext
0x18000E898: "SHA256" ??_C@_1O@HECGKAIN@?$AAS?$AAH?$AAA?$AA2?$AA5?$AA6?$AA?$AA@
0x18000CFC0: "CPGetUserKey" ??_C@_0N@EONMEBIP@CPGetUserKey?$AA@
0x1800106DC: "__cdecl _IMPORT_DESCRIPTOR_api-ms-win-core-memory-l1-1-0" __IMPORT_DESCRIPTOR_api-ms-win-core-memory-l1-1-0
0x1800042A0: Sub64
0x18000CA00: "__cdecl _imp_MapViewOfFile" __imp_MapViewOfFile
0x180005680: CryptDeriveKey
0x18000CD30: szprovider
0x180009A10: SystemFunction008
0x180009AD0: SystemFunction009
0x1800034D0: SystemFunction006
0x1800035D0: SystemFunction007
0x1800013D0: CryptGetKeyParam
0x18000A2E0: "__cdecl Sub" _Sub
0x18000D180: WPP_ThisDir_CTLGUID_CNGTraceControlGuid
0x18000CFD0: "CPSetProvParam" ??_C@_0P@IPHFPHKK@CPSetProvParam?$AA@
0x180003BC4: "__cdecl DllMainCRTStartupForGS2" _DllMainCRTStartupForGS2
0x180007C18: WPP_SF_S
0x1800045AF: memset
0x18001072C: "__cdecl _NULL_IMPORT_DESCRIPTOR" __NULL_IMPORT_DESCRIPTOR
0x180001C80: CryptGetHashParam
0x18000D5D0: "unsigned char const * const rgbMicrosoftRoot1_Name" ?rgbMicrosoftRoot1_Name@@3QBEB

[JEB Decompiler by PNF Software]