Generated by JEB on 2019/08/01

PE: C:\Windows\System32\svsvc.dll Base=0x180000000 SHA-256=C58DDE7BFEDCF6E8F37C531A01EC83B67791E1728CD8CB8557F35CCFECA29738
PDB: svsvc.pdb GUID={5719892B-0881-1EBA-9D283527AC12415B} Age=1

131 located named symbols:
0x180001FDC: "__cdecl _raise_securityfailure" __raise_securityfailure
0x180001DE0: "__cdecl FindPESection" _FindPESection
0x1800039A4: "__cdecl _IMPORT_DESCRIPTOR_ntdll" __IMPORT_DESCRIPTOR_ntdll
0x180004010: "__cdecl _security_cookie_complement" __security_cookie_complement
0x1800031D8: "__cdecl _imp_DeviceIoControl" __imp_DeviceIoControl
0x1800018BC: "__cdecl CRT_INIT" _CRT_INIT
0x180003180: "__cdecl _imp_GetCurrentThreadId" __imp_GetCurrentThreadId
0x180002250: "__cdecl guard_dispatch_icall_nop" _guard_dispatch_icall_nop
0x1800031E8: "__cdecl _imp_CreateFileW" __imp_CreateFileW
0x180003200: "__cdecl _imp_SetEvent" __imp_SetEvent
0x180003290: "__cdecl _guard_dispatch_icall_fptr" __guard_dispatch_icall_fptr
0x180001050: "unsigned short * __ptr64 __cdecl FindDriveName(unsigned short * __ptr64)" ?FindDriveName@@YAPEAGPEAG@Z
0x180003120: "__cdecl _imp_RegisterServiceCtrlHandlerExW" __imp_RegisterServiceCtrlHandlerExW
0x180001DC4: "__cdecl XcptFilter" _XcptFilter
0x180003298: "__cdecl _xc_a" __xc_a
0x180003438: " [SVC] CreateEvent error = %d, s" ??_C@_0CI@GPIEFNFC@?5?$FLSVC?$FN?5CreateEvent?5error?5?$DN?5?$CFd?0?5s@
0x180003268: "__cdecl _imp_memset" __imp_memset
0x1800031F0: "__cdecl _imp_CreateEventW" __imp_CreateEventW
0x180001FAC: "__cdecl initterm" _initterm
0x1800045D8: "__cdecl _dyn_tls_init_callback" __dyn_tls_init_callback
0x1800031C0: "__cdecl _imp_Sleep" __imp_Sleep
0x1800032B8: "__cdecl _xi_z" __xi_z
0x1800031B0: "__cdecl _imp_UnhandledExceptionFilter" __imp_UnhandledExceptionFilter
0x180001FB8: "__cdecl _C_specific_handler" __C_specific_handler
0x180003130: "__cdecl _imp_RegCloseKey" __imp_RegCloseKey
0x1800021CC: "__cdecl _GSHandlerCheckCommon" __GSHandlerCheckCommon
0x180003318: "EnableVolumeCompression" ??_C@_0BI@FEEAHPO@EnableVolumeCompression?$AA@
0x1800010A0: "unsigned char __cdecl IncrementRetryCount(unsigned short * __ptr64)" ?IncrementRetryCount@@YAEPEAG@Z
0x180003148: "__cdecl _imp_RegSetValueExW" __imp_RegSetValueExW
0x180001DD0: "__cdecl amsg_exit" _amsg_exit
0x180003370: "Software\Microsoft\Chkdsk\Verify" ??_C@_1EC@CAMKDKCK@?$AAS?$AAo?$AAf?$AAt?$AAw?$AAa?$AAr?$AAe?$AA?2?$AAM?$AAi?$AAc?$AAr?$AAo?$AAs?$AAo?$AAf?$AAt?$AA?2?$AAC?$AAh?$AAk?$AAd?$AAs?$AAk?$AA?2?$AAV?$AAe?$AAr?$AAi?$AAf?$AAy@
0x180003480: " [SVC] RegisterServiceCtrlHandle" ??_C@_0CN@HFPNPFDN@?5?$FLSVC?$FN?5RegisterServiceCtrlHandle@
0x1800031D0: "__cdecl _imp_GetCurrentProcess" __imp_GetCurrentProcess
0x1800045C8: "__cdecl _native_startup_lock" __native_startup_lock
0x180001FA0: DllMain
0x180003260: "__cdecl _imp_realloc" __imp_realloc
0x180003230: "__cdecl _imp___C_specific_handler" __imp___C_specific_handler
0x180003198: "__cdecl _imp_RtlCaptureContext" __imp_RtlCaptureContext
0x180003228: KERNEL32_NULL_THUNK_DATA
0x1800031F8: "__cdecl _imp_GetLastError" __imp_GetLastError
0x180003400: "NTFS" ??_C@_19ENNDBEJL@?$AAN?$AAT?$AAF?$AAS?$AA?$AA@
0x180004000: "__cdecl _native_dllmain_reason" __native_dllmain_reason
0x1800021A8: "__cdecl _GSHandlerCheck" __GSHandlerCheck
0x18000397C: "__cdecl _IMPORT_DESCRIPTOR_ADVAPI32" __IMPORT_DESCRIPTOR_ADVAPI32
0x180003178: "__cdecl _imp_GetCurrentProcessId" __imp_GetCurrentProcessId
0x1800031C8: "__cdecl _imp_WaitForSingleObject" __imp_WaitForSingleObject
0x1800045B0: "long volatile g_serviceControlFlags" ?g_serviceControlFlags@@3JC
0x180001E90: "__cdecl ValidateImageBase" _ValidateImageBase
0x1800034E0: " [SVC] SetServiceStatus on stopp" ??_C@_0DH@KFBBIEGE@?5?$FLSVC?$FN?5SetServiceStatus?5on?5stopp@
0x1800031E0: "__cdecl _imp_FreeLibrary" __imp_FreeLibrary
0x180001B00: "__cdecl DllMainCRTStartup" _DllMainCRTStartup
0x180003238: "__cdecl _imp__initterm" __imp__initterm
0x180003410: " [SVC] SetServiceStatus, opcode " ??_C@_0CE@LDPDCJDC@?5?$FLSVC?$FN?5SetServiceStatus?0?5opcode?5@
0x1800045B8: "__cdecl _onexitend" __onexitend
0x180003128: "__cdecl _imp_AdjustTokenPrivileges" __imp_AdjustTokenPrivileges
0x180003288: "__cdecl _guard_check_icall_fptr" __guard_check_icall_fptr
0x180003220: "__cdecl _imp_TerminateProcess" __imp_TerminateProcess
0x1800016D0: "void __cdecl ServiceMain(unsigned long,unsigned short * __ptr64 * __ptr64)" ?ServiceMain@@YAXKPEAPEAG@Z
0x1800032A8: "__cdecl _xi_a" __xi_a
0x180003190: "__cdecl _imp_GetTickCount" __imp_GetTickCount
0x1800045B4: "bool g_triggered" ?g_triggered@@3_NA
0x1800045E0: "__cdecl pRawDllMain" _pRawDllMain
0x1800034B0: " [SVC] SetServiceStatus error %l" ??_C@_0CM@NPFEPLNA@?5?$FLSVC?$FN?5SetServiceStatus?5error?5?$CFl@
0x180001DA0: "__cdecl _security_check_cookie" __security_check_cookie
0x1800032A0: "__cdecl _xc_z" __xc_z
0x180003218: "__cdecl _imp_GetProcAddress" __imp_GetProcAddress
0x180003188: "__cdecl _imp_GetSystemTimeAsFileTime" __imp_GetSystemTimeAsFileTime
0x180003138: "__cdecl _imp_SetServiceStatus" __imp_SetServiceStatus
0x180003460: " [SVC] Service %ws starting " ??_C@_0BN@OOJMHMJA@?5?$FLSVC?$FN?5Service?5?$CFws?5starting?6?$AA@
0x1800033B8: "\\.\Ntfs" ??_C@_1BC@EPIIAPPF@?$AA?2?$AA?2?$AA?4?$AA?2?$AAN?$AAt?$AAf?$AAs?$AA?$AA@
0x1800032C0: "__cdecl _guard_fids_table" __guard_fids_table
0x180003270: msvcrt_NULL_THUNK_DATA
0x180003010: "__cdecl load_config_used" _load_config_used
0x180004020: "unsigned long g_finishedResult" ?g_finishedResult@@3KA
0x180003308: "ChkdskEx" ??_C@_08CENBGMAG@ChkdskEx?$AA@
0x180003248: "__cdecl _imp__amsg_exit" __imp__amsg_exit
0x1800031A0: "__cdecl _imp_RtlLookupFunctionEntry" __imp_RtlLookupFunctionEntry
0x180003170: "__cdecl _imp_QueryPerformanceCounter" __imp_QueryPerformanceCounter
0x1800031A8: "__cdecl _imp_RtlVirtualUnwind" __imp_RtlVirtualUnwind
0x180001FD0: "__cdecl guard_check_icall_nop" _guard_check_icall_nop
0x180001620: "unsigned long __cdecl ServiceCtrlHandler(unsigned long,unsigned long,void * __ptr64,void * __ptr64)" ?ServiceCtrlHandler@@YAKKKPEAX0@Z
0x180003250: "__cdecl _imp__XcptFilter" __imp__XcptFilter
0x180003280: ntdll_NULL_THUNK_DATA
0x180004008: "__cdecl _security_cookie" __security_cookie
0x180001010: "unsigned char __cdecl _FmifsCallbackHandler(enum _FMIFS_PACKET_TYPE,unsigned long,void * __ptr64)" ?_FmifsCallbackHandler@@YAEW4_FMIFS_PACKET_TYPE@@KPEAX@Z
0x180003160: "__cdecl _imp_RegQueryValueExW" __imp_RegQueryValueExW
0x180003208: "__cdecl _imp_CloseHandle" __imp_CloseHandle
0x180003210: "__cdecl _imp_LoadLibraryW" __imp_LoadLibraryW
0x180003140: "__cdecl _imp_RegCreateKeyExW" __imp_RegCreateKeyExW
0x1800045C0: "__cdecl _onexitbegin" __onexitbegin
0x180003278: "__cdecl _imp_DbgPrint" __imp_DbgPrint
0x1800031B8: "__cdecl _imp_SetUnhandledExceptionFilter" __imp_SetUnhandledExceptionFilter
0x180003990: "__cdecl _IMPORT_DESCRIPTOR_KERNEL32" __IMPORT_DESCRIPTOR_KERNEL32
0x180003358: "QueryCorruptionState" ??_C@_0BF@PHDGHFJJ@QueryCorruptionState?$AA@
0x180003158: "__cdecl _imp_RegOpenKeyExW" __imp_RegOpenKeyExW
0x180001EC4: "__cdecl _security_init_cookie" __security_init_cookie
0x180003330: "FormatEx2" ??_C@_09NMLNEKLF@FormatEx2?$AA@
0x180003968: "__cdecl _IMPORT_DESCRIPTOR_msvcrt" __IMPORT_DESCRIPTOR_msvcrt
0x180003340: "GetDefaultFileSystem" ??_C@_0BF@HEECBCO@GetDefaultFileSystem?$AA@
0x180003240: "__cdecl _imp_malloc" __imp_malloc
0x180003168: ADVAPI32_NULL_THUNK_DATA
0x180003118: "__cdecl _imp_LookupPrivilegeValueW" __imp_LookupPrivilegeValueW
0x180002020: "__cdecl _report_gsfailure" __report_gsfailure
0x1800033D0: "SeManageVolumePrivilege" ??_C@_1DA@LIHDNJND@?$AAS?$AAe?$AAM?$AAa?$AAn?$AAa?$AAg?$AAe?$AAV?$AAo?$AAl?$AAu?$AAm?$AAe?$AAP?$AAr?$AAi?$AAv?$AAi?$AAl?$AAe?$AAg?$AAe?$AA?$AA@
0x1800045D0: "__cdecl _native_startup_state" __native_startup_state
0x1800011B4: "void __cdecl DoCheck(void * __ptr64)" ?DoCheck@@YAXPEAX@Z
0x1800032F0: "FMIFS.DLL" ??_C@_1BE@FMFHPIED@?$AAF?$AAM?$AAI?$AAF?$AAS?$AA?4?$AAD?$AAL?$AAL?$AA?$AA@
0x180003258: "__cdecl _imp_free" __imp_free
0x180001E30: "__cdecl IsNonwritableInCurrentImage" _IsNonwritableInCurrentImage
0x180003150: "__cdecl _imp_OpenProcessToken" __imp_OpenProcessToken
0x18000222D: memset
0x1800039B8: "__cdecl _NULL_IMPORT_DESCRIPTOR" __NULL_IMPORT_DESCRIPTOR

[JEB Decompiler by PNF Software]