spbcd.dll

Description: BCD Sysprep Plugin

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.4291

Architecture: 32-bit

Operating System: Windows NT

SHA256: 761fb5b6119d94338c3213159d561dc4

File Size: 85.0 KB

Uploaded At: Dec. 1, 2025, 8:04 a.m.

Views: 15

Exported Functions

  • Sysprep_Generalize_Bcd (Ordinal: 1, Address: 0x5a00)
  • Sysprep_Offline_Specialize_Bcd (Ordinal: 2, Address: 0x5b20)
  • Sysprep_Online_Specialize_Bcd (Ordinal: 3, Address: 0x5c60)

Imported DLLs & Functions

ADVAPI32.dll
  • RegGetValueW (Address: 0x10015000)
KERNEL32.dll
  • CompareStringW (Address: 0x10015044)
  • ExpandEnvironmentStringsW (Address: 0x1001503c)
  • GetCurrentProcess (Address: 0x10015020)
  • GetCurrentProcessId (Address: 0x10015014)
  • GetCurrentThreadId (Address: 0x10015010)
  • GetLastError (Address: 0x10015038)
  • GetProcessHeap (Address: 0x10015030)
  • GetSystemTimeAsFileTime (Address: 0x1001500c)
  • GetTickCount (Address: 0x10015008)
  • HeapAlloc (Address: 0x10015034)
  • HeapFree (Address: 0x10015040)
  • QueryDosDeviceW (Address: 0x10015048)
  • QueryPerformanceCounter (Address: 0x10015018)
  • SetUnhandledExceptionFilter (Address: 0x10015024)
  • Sleep (Address: 0x1001502c)
  • TerminateProcess (Address: 0x1001501c)
  • UnhandledExceptionFilter (Address: 0x10015028)
msvcrt.dll
  • _amsg_exit (Address: 0x100150bc)
  • _except_handler4_common (Address: 0x100150ac)
  • _initterm (Address: 0x100150b0)
  • _snwscanf_s (Address: 0x10015078)
  • _ultow_s (Address: 0x10015084)
  • _vsnwprintf (Address: 0x100150d0)
  • _vsnwprintf_s (Address: 0x10015074)
  • _wcsicmp (Address: 0x100150cc)
  • _wcslwr (Address: 0x1001507c)
  • _wcsnicmp (Address: 0x10015060)
  • _wcsupr (Address: 0x10015094)
  • _XcptFilter (Address: 0x100150c0)
  • free (Address: 0x100150b8)
  • malloc (Address: 0x100150b4)
  • memcmp (Address: 0x100150a0)
  • memcpy (Address: 0x100150a4)
  • memmove (Address: 0x100150a8)
  • memset (Address: 0x10015070)
  • strcpy_s (Address: 0x10015068)
  • strncmp (Address: 0x10015098)
  • swprintf_s (Address: 0x100150c8)
  • wcscat_s (Address: 0x10015088)
  • wcschr (Address: 0x10015064)
  • wcscpy_s (Address: 0x10015080)
  • wcsncpy_s (Address: 0x100150c4)
  • wcsnlen (Address: 0x10015090)
  • wcsrchr (Address: 0x1001506c)
  • wcsstr (Address: 0x1001509c)
  • wcstoul (Address: 0x1001508c)
ntdll.dll
  • LdrGetDllHandle (Address: 0x10015120)
  • LdrGetProcedureAddress (Address: 0x10015124)
  • NtAdjustPrivilegesToken (Address: 0x1001510c)
  • NtClose (Address: 0x100151d4)
  • NtCreateFile (Address: 0x100151d0)
  • NtDeviceIoControlFile (Address: 0x100151c8)
  • NtEnumerateBootEntries (Address: 0x100150d8)
  • NtOpenDirectoryObject (Address: 0x100150e0)
  • NtOpenFile (Address: 0x100151c4)
  • NtOpenKey (Address: 0x100150f8)
  • NtOpenProcessTokenEx (Address: 0x10015108)
  • NtOpenSymbolicLinkObject (Address: 0x100150fc)
  • NtOpenThreadTokenEx (Address: 0x10015104)
  • NtQueryBootEntryOrder (Address: 0x100150ec)
  • NtQueryBootOptions (Address: 0x100150e8)
  • NtQueryDirectoryObject (Address: 0x100150dc)
  • NtQuerySymbolicLinkObject (Address: 0x100150f4)
  • NtQuerySystemInformation (Address: 0x100151ec)
  • NtQueryValueKey (Address: 0x100150f0)
  • NtSetInformationThread (Address: 0x100151cc)
  • NtTranslateFilePath (Address: 0x100150e4)
  • NtWriteFile (Address: 0x100151e0)
  • RtlAddAccessAllowedAceEx (Address: 0x10015174)
  • RtlAllocateAndInitializeSid (Address: 0x10015170)
  • RtlAllocateHeap (Address: 0x100151ac)
  • RtlAppendUnicodeToString (Address: 0x100151a8)
  • RtlCompareMemory (Address: 0x100151e4)
  • RtlCreateAcl (Address: 0x10015154)
  • RtlCreateSecurityDescriptor (Address: 0x10015148)
  • RtlFreeHeap (Address: 0x100151b0)
  • RtlFreeSid (Address: 0x10015164)
  • RtlFreeUnicodeString (Address: 0x100151b8)
  • RtlGetNtProductType (Address: 0x100151d8)
  • RtlGetVersion (Address: 0x10015128)
  • RtlGUIDFromString (Address: 0x100151bc)
  • RtlImpersonateSelf (Address: 0x10015100)
  • RtlInitAnsiString (Address: 0x10015118)
  • RtlInitUnicodeString (Address: 0x100151dc)
  • RtlLengthSecurityDescriptor (Address: 0x10015188)
  • RtlLengthSid (Address: 0x1001516c)
  • RtlNtStatusToDosError (Address: 0x100151e8)
  • RtlSetDaclSecurityDescriptor (Address: 0x10015180)
  • RtlSetOwnerSecurityDescriptor (Address: 0x10015184)
  • RtlStringFromGUID (Address: 0x100151b4)
  • ZwAllocateUuids (Address: 0x1001513c)
  • ZwClose (Address: 0x1001518c)
  • ZwCreateKey (Address: 0x1001517c)
  • ZwDeleteKey (Address: 0x10015160)
  • ZwDeleteValueKey (Address: 0x10015168)
  • ZwDeviceIoControlFile (Address: 0x10015134)
  • ZwEnumerateKey (Address: 0x1001515c)
  • ZwLoadKey (Address: 0x10015178)
  • ZwOpenDirectoryObject (Address: 0x100151f0)
  • ZwOpenFile (Address: 0x10015194)
  • ZwOpenKey (Address: 0x10015140)
  • ZwOpenMutant (Address: 0x10015190)
  • ZwOpenProcess (Address: 0x10015110)
  • ZwOpenSymbolicLinkObject (Address: 0x1001512c)
  • ZwQueryAttributesFile (Address: 0x100151a4)
  • ZwQueryDirectoryObject (Address: 0x10015130)
  • ZwQueryInformationFile (Address: 0x10015114)
  • ZwQueryInformationProcess (Address: 0x1001511c)
  • ZwQueryKey (Address: 0x1001519c)
  • ZwQuerySymbolicLinkObject (Address: 0x10015138)
  • ZwQuerySystemInformation (Address: 0x100151c0)
  • ZwQueryValueKey (Address: 0x10015158)
  • ZwReleaseMutant (Address: 0x10015198)
  • ZwSetSecurityObject (Address: 0x10015150)
  • ZwSetValueKey (Address: 0x10015144)
  • ZwUnloadKey (Address: 0x1001514c)
  • ZwWaitForSingleObject (Address: 0x100151a0)
WDSCORE.dll
  • ConstructPartialMsgVW (Address: 0x10015050)
  • CurrentIP (Address: 0x10015054)
  • WdsSetupLogMessageW (Address: 0x10015058)