Generated by JEB on 2019/08/01
PE: C:\Windows\System32\drivers\rootmdm.sys Base=0x1C0000000 SHA-256=E89EE2EB86E67487272AF630AD4D656187128B170D63EB0E1C3A3A62C1A41264
PDB: rootmdm.pdb GUID={788B433D-1F6A-724A-6CDD0B54C6383ECF} Age=1
83 located named symbols:
0x1C0003008: "__cdecl _security_cookie_complement" __security_cookie_complement
0x1C00050E8: "__cdecl _imp_ObfDereferenceObject" __imp_ObfDereferenceObject
0x1C0005018: "__cdecl _imp_RtlInitUnicodeString" __imp_RtlInitUnicodeString
0x1C00012F0: "__cdecl guard_dispatch_icall_nop" _guard_dispatch_icall_nop
0x1C0005038: "__cdecl _imp_IoCreateDevice" __imp_IoCreateDevice
0x1C0005030: "__cdecl _imp_IofCompleteRequest" __imp_IofCompleteRequest
0x1C0005118: "__cdecl _guard_dispatch_icall_fptr" __guard_dispatch_icall_fptr
0x1C0005048: "__cdecl _imp_IoAttachDeviceToDeviceStack" __imp_IoAttachDeviceToDeviceStack
0x1C0006370: FakeModemPnP
0x1C00050B0: "__cdecl _imp_PoStartNextPowerIrp" __imp_PoStartNextPowerIrp
0x1C0005010: "__cdecl _imp_MmGetSystemRoutineAddress" __imp_MmGetSystemRoutineAddress
0x1C0005050: "__cdecl _imp_KeInitializeSpinLock" __imp_KeInitializeSpinLock
0x1C0005088: "__cdecl _imp_KeWaitForSingleObject" __imp_KeWaitForSingleObject
0x1C0005080: "__cdecl _imp_RtlAppendUnicodeStringToString" __imp_RtlAppendUnicodeStringToString
0x1C0002108: "__cdecl _guard_iat_table" __guard_iat_table
0x1C0001300: memcpy
0x1C0005040: "__cdecl _imp_IoDeleteDevice" __imp_IoDeleteDevice
0x1C0005028: "__cdecl _imp_IofCallDriver" __imp_IofCallDriver
0x1C0001300: memmove
0x1C0006340: RootModemWmi
0x1C000127C: "__cdecl _GSHandlerCheckCommon" __GSHandlerCheckCommon
0x1C00050D0: "__cdecl _imp_IoGetDeviceObjectPointer" __imp_IoGetDeviceObjectPointer
0x1C00050E0: "__cdecl _imp_IoBuildDeviceIoControlRequest" __imp_IoBuildDeviceIoControlRequest
0x1C0005098: "__cdecl _imp_ExDeleteResourceLite" __imp_ExDeleteResourceLite
0x1C00050D8: "__cdecl _imp_ObfReferenceObject" __imp_ObfReferenceObject
0x1C00011CC: RemoveReference
0x1C0003010: "__cdecl _@@_PchSym_@00@KxulyqvxgPillgKxumvgUfmrnlwvnUhixUhbhUillgnwnUlyquivUznwGEUrmgvimzoOlyq@rootmdm" __@@_PchSym_@00@KxulyqvxgPillgKxumvgUfmrnlwvnUhixUhbhUillgnwnUlyquivUznwGEUrmgvimzoOlyq@rootmdm
0x1C0005000: "__cdecl _imp_ExAllocatePoolWithTag" __imp_ExAllocatePoolWithTag
0x1C0002168: "\DosDevices\" ??_C@_1BK@LABJKOM@?$AA?2?$AAD?$AAo?$AAs?$AAD?$AAe?$AAv?$AAi?$AAc?$AAe?$AAs?$AA?2?$AA?$AA@
0x1C0001070: RootModemPassThrough
0x1C0002188: "RtlQueryRegistryValuesEx" ??_C@_1DC@OAPHKEJN@?$AAR?$AAt?$AAl?$AAQ?$AAu?$AAe?$AAr?$AAy?$AAR?$AAe?$AAg?$AAi?$AAs?$AAt?$AAr?$AAy?$AAV?$AAa?$AAl?$AAu?$AAe?$AAs?$AAE?$AAx?$AA?$AA@
0x1C00050F8: "__cdecl _imp_KeLeaveCriticalRegion" __imp_KeLeaveCriticalRegion
0x1C0006010: FakeModemAddDevice
0x1C0001258: "__cdecl _GSHandlerCheck" __GSHandlerCheck
0x1C0001170: RemoveReferenceAndCompleteRequest
0x1C0001108: CheckStateAndAddReference
0x1C00065B0: FakeModemPower
0x1C0007220: GsDriverEntry
0x1C0005110: "__cdecl _guard_check_icall_fptr" __guard_check_icall_fptr
0x1C0005078: "__cdecl _imp_RtlAppendUnicodeToString" __imp_RtlAppendUnicodeToString
0x1C0006934: WaitForLowerDriverToCompleteIrp
0x1C0002160: "" ??_C@_11LOCGONAA@?$AA?$AA@
0x1C00010D0: DevicePowerCompleteRoutine
0x1C0002110: "BreakOnEntry" ??_C@_1BK@FOAFIPCB@?$AAB?$AAr?$AAe?$AAa?$AAk?$AAO?$AAn?$AAE?$AAn?$AAt?$AAr?$AAy?$AA?$AA@
0x1C00050A0: "__cdecl _imp_PoRequestPowerIrp" __imp_PoRequestPowerIrp
0x1C0001210: "__cdecl _security_check_cookie" __security_check_cookie
0x1C0005090: "__cdecl _imp_IoDetachDevice" __imp_IoDetachDevice
0x1C0005120: "__cdecl _IMPORT_DESCRIPTOR_ntoskrnl" __IMPORT_DESCRIPTOR_ntoskrnl
0x1C00010D0: FakeModemUnload
0x1C000614C: GetAttachedPort
0x1C0008000: "__cdecl _guard_fids_table" __guard_fids_table
0x1C00050C8: "__cdecl _imp_ExAcquireResourceExclusiveLite" __imp_ExAcquireResourceExclusiveLite
0x1C0002000: "__cdecl load_config_used" _load_config_used
0x1C0005070: "__cdecl _imp_ZwClose" __imp_ZwClose
0x1C0006880: FakeModemClose
0x1C0005058: "__cdecl _imp_KeInitializeEvent" __imp_KeInitializeEvent
0x1C0006670: FakeModemOpen
0x1C00010D0: "__cdecl guard_check_icall_nop" _guard_check_icall_nop
0x1C00010E0: IoCompletionSetEvent
0x1C00050F0: "__cdecl _imp_ExReleaseResourceLite" __imp_ExReleaseResourceLite
0x1C0002130: "DebugFlags" ??_C@_1BG@PDIFALE@?$AAD?$AAe?$AAb?$AAu?$AAg?$AAF?$AAl?$AAa?$AAg?$AAs?$AA?$AA@
0x1C0003000: "__cdecl _security_cookie" __security_cookie
0x1C0002148: "AttachedTo" ??_C@_1BG@BHKBJKOE@?$AAA?$AAt?$AAt?$AAa?$AAc?$AAh?$AAe?$AAd?$AAT?$AAo?$AA?$AA@
0x1C0005008: "__cdecl _imp_RtlQueryRegistryValues" __imp_RtlQueryRegistryValues
0x1C0007254: "__cdecl _security_init_cookie" __security_init_cookie
0x1C0005100: "__cdecl _imp_KeSetEvent" __imp_KeSetEvent
0x1C0005068: "__cdecl _imp_IoOpenDeviceRegistryKey" __imp_IoOpenDeviceRegistryKey
0x1C0001240: "__cdecl _report_gsfailure" __report_gsfailure
0x1C00050B8: "__cdecl _imp_PoCallDriver" __imp_PoCallDriver
0x1C0005060: "__cdecl _imp_ExInitializeResourceLite" __imp_ExInitializeResourceLite
0x1C0001010: RootModemCleanUp
0x1C0005108: ntoskrnl_NULL_THUNK_DATA
0x1C0005020: "__cdecl _imp_ExFreePoolWithTag" __imp_ExFreePoolWithTag
0x1C00050C0: "__cdecl _imp_KeEnterCriticalRegion" __imp_KeEnterCriticalRegion
0x1C00050A8: "__cdecl _imp_PoSetPowerState" __imp_PoSetPowerState
0x1C0007008: DriverEntry
0x1C0001640: memset
0x1C0005134: "__cdecl _NULL_IMPORT_DESCRIPTOR" __NULL_IMPORT_DESCRIPTOR
[JEB Decompiler by PNF Software]