bfsvc.dll
Description: CMI boot file service plug-in
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.1704
Architecture: 32-bit
Operating System: Windows NT
SHA256: c2bbcd237c7c00265ebab27ad4fba204
File Size: 222.4 KB
Uploaded At: Dec. 1, 2025, 8:39 a.m.
Views: 12
Exported Functions
- DllCanUnloadNow (Ordinal: 1, Address: 0x17970)
- DllCsiGetHandler (Ordinal: 2, Address: 0x17990)
Imported DLLs & Functions
ADVAPI32.dll
- AdjustTokenPrivileges (Address: 0x10033028)
- ConvertSidToStringSidW (Address: 0x1003300c)
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x10033008)
- GetSecurityDescriptorControl (Address: 0x10033018)
- GetSecurityDescriptorDacl (Address: 0x10033024)
- GetSecurityDescriptorGroup (Address: 0x10033020)
- GetSecurityDescriptorOwner (Address: 0x10033014)
- GetSecurityDescriptorSacl (Address: 0x1003302c)
- GetTokenInformation (Address: 0x10033000)
- LookupPrivilegeValueW (Address: 0x10033030)
- OpenProcessToken (Address: 0x10033010)
- OpenThreadToken (Address: 0x10033004)
- SetNamedSecurityInfoW (Address: 0x1003301c)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x100330e8)
- IsDebuggerPresent (Address: 0x100330e4)
- OutputDebugStringW (Address: 0x100330e0)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x100330f4)
- SetLastError (Address: 0x100330f0)
- SetUnhandledExceptionFilter (Address: 0x100330f8)
- UnhandledExceptionFilter (Address: 0x100330fc)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x10033104)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x10033114)
- HeapAlloc (Address: 0x1003310c)
- HeapDestroy (Address: 0x10033118)
- HeapFree (Address: 0x10033110)
api-ms-win-core-libraryloader-l1-1-0.dll
- DisableThreadLibraryCalls (Address: 0x10033134)
- FindResourceExW (Address: 0x1003313c)
- FreeLibrary (Address: 0x10033120)
- GetModuleFileNameA (Address: 0x10033128)
- GetModuleHandleExW (Address: 0x10033130)
- GetModuleHandleW (Address: 0x10033138)
- GetProcAddress (Address: 0x10033124)
- LoadResource (Address: 0x1003312c)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x10033144)
api-ms-win-core-localization-obsolete-l1-2-0.dll
- GetSystemDefaultUILanguage (Address: 0x1003314c)
- GetUserDefaultUILanguage (Address: 0x10033150)
api-ms-win-core-processenvironment-l1-1-0.dll
- SearchPathW (Address: 0x10033158)
api-ms-win-core-processthreads-l1-1-0.dll
- GetCurrentProcess (Address: 0x10033168)
- GetCurrentProcessId (Address: 0x10033160)
- GetCurrentThreadId (Address: 0x10033164)
- TerminateProcess (Address: 0x1003316c)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x10033174)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x10033180)
- RegCreateKeyExW (Address: 0x1003318c)
- RegOpenKeyExW (Address: 0x10033184)
- RegQueryValueExW (Address: 0x1003317c)
- RegSetValueExW (Address: 0x10033188)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x100331a0)
- AcquireSRWLockShared (Address: 0x10033198)
- CreateMutexExW (Address: 0x100331d0)
- CreateSemaphoreExW (Address: 0x100331b0)
- DeleteCriticalSection (Address: 0x100331c4)
- EnterCriticalSection (Address: 0x100331bc)
- InitializeCriticalSection (Address: 0x100331b4)
- InitializeCriticalSectionEx (Address: 0x100331c0)
- LeaveCriticalSection (Address: 0x100331ac)
- OpenSemaphoreW (Address: 0x100331cc)
- ReleaseMutex (Address: 0x100331a8)
- ReleaseSemaphore (Address: 0x100331a4)
- ReleaseSRWLockExclusive (Address: 0x1003319c)
- ReleaseSRWLockShared (Address: 0x10033194)
- WaitForSingleObject (Address: 0x100331c8)
- WaitForSingleObjectEx (Address: 0x100331b8)
api-ms-win-core-synch-l1-2-0.dll
- Sleep (Address: 0x100331d8)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemTimeAsFileTime (Address: 0x100331ec)
- GetSystemWindowsDirectoryW (Address: 0x100331e4)
- GetTickCount (Address: 0x100331e8)
- GetVersionExW (Address: 0x100331e0)
api-ms-win-core-threadpool-l1-2-0.dll
- CloseThreadpoolTimer (Address: 0x100331f8)
- CreateThreadpoolTimer (Address: 0x100331f4)
- SetThreadpoolTimer (Address: 0x10033200)
- WaitForThreadpoolTimerCallbacks (Address: 0x100331fc)
api-ms-win-eventing-provider-l1-1-0.dll
- EventRegister (Address: 0x1003320c)
- EventUnregister (Address: 0x10033210)
- EventWriteTransfer (Address: 0x10033208)
imagehlp.dll
- CheckSumMappedFile (Address: 0x10033218)
KERNEL32.dll
- CopyFileExW (Address: 0x1003306c)
- CreateDirectoryW (Address: 0x100330b0)
- CreateFileMappingW (Address: 0x1003308c)
- CreateFileW (Address: 0x1003309c)
- DeleteFileW (Address: 0x1003303c)
- DeviceIoControl (Address: 0x100330a4)
- FindClose (Address: 0x10033064)
- FindFirstFileW (Address: 0x10033078)
- FindNextFileW (Address: 0x10033074)
- FlushFileBuffers (Address: 0x10033084)
- GetCurrentThread (Address: 0x10033090)
- GetFileAttributesW (Address: 0x10033060)
- GetFileInformationByHandle (Address: 0x10033044)
- GetFileInformationByHandleEx (Address: 0x10033048)
- GetFileSizeEx (Address: 0x100330a8)
- GetFullPathNameW (Address: 0x10033038)
- GetLocaleInfoW (Address: 0x1003304c)
- GetPrivateProfileSectionW (Address: 0x10033068)
- GetVolumeInformationW (Address: 0x1003307c)
- GetVolumeNameForVolumeMountPointW (Address: 0x10033094)
- GetVolumePathNameW (Address: 0x100330a0)
- LoadLibraryExW (Address: 0x10033080)
- LoadLibraryW (Address: 0x10033054)
- LocalFree (Address: 0x10033050)
- MapViewOfFile (Address: 0x10033088)
- MoveFileExW (Address: 0x10033058)
- QueryDosDeviceW (Address: 0x100330ac)
- SetFileAttributesW (Address: 0x1003305c)
- SetFileInformationByHandle (Address: 0x10033040)
- UnmapViewOfFile (Address: 0x10033098)
- WriteFile (Address: 0x10033070)
msvcrt.dll
- __dllonexit (Address: 0x100332a4)
- __iob_func (Address: 0x100332c8)
- _amsg_exit (Address: 0x1003323c)
- _callnewh (Address: 0x100332b4)
- _except_handler4_common (Address: 0x100332b0)
- _initterm (Address: 0x10033240)
- _lock (Address: 0x10033258)
- _onexit (Address: 0x100332ac)
- _purecall (Address: 0x10033228)
- _snwscanf_s (Address: 0x10033280)
- _ultow_s (Address: 0x10033274)
- _unlock (Address: 0x100332a0)
- _vsnwprintf (Address: 0x100332a8)
- _vsnwprintf_s (Address: 0x10033250)
- _wcsicmp (Address: 0x1003325c)
- _wcslwr (Address: 0x10033284)
- _wcsnicmp (Address: 0x10033260)
- _wcsupr (Address: 0x10033270)
- _wfopen_s (Address: 0x10033248)
- _XcptFilter (Address: 0x10033234)
- bsearch (Address: 0x1003329c)
- fclose (Address: 0x1003324c)
- fflush (Address: 0x10033244)
- free (Address: 0x10033224)
- fwprintf (Address: 0x10033254)
- malloc (Address: 0x10033220)
- memcmp (Address: 0x100332bc)
- memcpy (Address: 0x100332c0)
- memcpy_s (Address: 0x10033238)
- memmove (Address: 0x100332b8)
- memmove_s (Address: 0x10033230)
- memset (Address: 0x100332cc)
- strcpy_s (Address: 0x10033290)
- strncmp (Address: 0x10033294)
- swprintf_s (Address: 0x10033268)
- wcscat_s (Address: 0x10033264)
- wcschr (Address: 0x1003326c)
- wcscpy_s (Address: 0x100332c4)
- wcsncmp (Address: 0x10033298)
- wcsncpy_s (Address: 0x1003327c)
- wcsnlen (Address: 0x1003328c)
- wcsrchr (Address: 0x1003322c)
- wcsstr (Address: 0x10033288)
- wcstoul (Address: 0x10033278)
ntdll.dll
- LdrAccessResource (Address: 0x10033308)
- LdrFindResource_U (Address: 0x10033304)
- LdrGetDllHandle (Address: 0x100333ec)
- LdrGetProcedureAddress (Address: 0x100333e8)
- NtAdjustPrivilegesToken (Address: 0x10033400)
- NtClose (Address: 0x10033418)
- NtCreateEvent (Address: 0x100332e8)
- NtDeviceIoControlFile (Address: 0x100332e0)
- NtEnumerateBootEntries (Address: 0x10033394)
- NtOpenDirectoryObject (Address: 0x1003338c)
- NtOpenFile (Address: 0x100332fc)
- NtOpenKey (Address: 0x1003335c)
- NtOpenProcess (Address: 0x10033374)
- NtOpenProcessTokenEx (Address: 0x10033404)
- NtOpenSymbolicLinkObject (Address: 0x10033354)
- NtOpenThreadTokenEx (Address: 0x10033408)
- NtQueryBootEntryOrder (Address: 0x10033380)
- NtQueryBootOptions (Address: 0x10033384)
- NtQueryDirectoryObject (Address: 0x10033390)
- NtQueryInformationFile (Address: 0x100332ec)
- NtQueryInformationProcess (Address: 0x1003341c)
- NtQueryInformationThread (Address: 0x100332f0)
- NtQuerySymbolicLinkObject (Address: 0x10033360)
- NtQuerySystemInformation (Address: 0x10033300)
- NtQueryValueKey (Address: 0x1003337c)
- NtReadFile (Address: 0x100332d8)
- NtSetInformationFile (Address: 0x10033310)
- NtSetInformationThread (Address: 0x100332dc)
- NtTranslateFilePath (Address: 0x10033388)
- NtWaitForSingleObject (Address: 0x100332f8)
- NtWriteFile (Address: 0x10033410)
- RtlAddAccessAllowedAceEx (Address: 0x10033364)
- RtlAllocateAndInitializeSid (Address: 0x10033368)
- RtlAllocateHeap (Address: 0x10033320)
- RtlAppendUnicodeToString (Address: 0x1003332c)
- RtlCompareMemory (Address: 0x1003331c)
- RtlCreateAcl (Address: 0x10033414)
- RtlCreateSecurityDescriptor (Address: 0x10033378)
- RtlFreeHeap (Address: 0x10033318)
- RtlFreeSid (Address: 0x10033370)
- RtlFreeUnicodeString (Address: 0x1003330c)
- RtlGetVersion (Address: 0x100333e0)
- RtlGUIDFromString (Address: 0x10033328)
- RtlImageNtHeader (Address: 0x100332e4)
- RtlImpersonateSelf (Address: 0x1003340c)
- RtlInitAnsiString (Address: 0x100333f4)
- RtlInitUnicodeString (Address: 0x100332d4)
- RtlLengthSecurityDescriptor (Address: 0x1003334c)
- RtlLengthSid (Address: 0x1003336c)
- RtlNtStatusToDosError (Address: 0x100332f4)
- RtlSetDaclSecurityDescriptor (Address: 0x10033358)
- RtlSetOwnerSecurityDescriptor (Address: 0x10033350)
- RtlStringFromGUID (Address: 0x10033314)
- ZwAllocateUuids (Address: 0x100333cc)
- ZwClose (Address: 0x10033348)
- ZwCreateFile (Address: 0x10033398)
- ZwCreateKey (Address: 0x1003339c)
- ZwDeleteKey (Address: 0x100333b0)
- ZwDeleteValueKey (Address: 0x100333a8)
- ZwDeviceIoControlFile (Address: 0x100333d4)
- ZwEnumerateKey (Address: 0x100333b4)
- ZwFlushKey (Address: 0x100333a4)
- ZwLoadKey (Address: 0x100333a0)
- ZwOpenDirectoryObject (Address: 0x100333e4)
- ZwOpenFile (Address: 0x10033340)
- ZwOpenKey (Address: 0x100333c8)
- ZwOpenMutant (Address: 0x10033344)
- ZwOpenProcess (Address: 0x100333fc)
- ZwOpenSymbolicLinkObject (Address: 0x100333dc)
- ZwQueryAttributesFile (Address: 0x10033330)
- ZwQueryDirectoryObject (Address: 0x100333d8)
- ZwQueryInformationFile (Address: 0x100333f8)
- ZwQueryInformationProcess (Address: 0x100333f0)
- ZwQueryKey (Address: 0x10033338)
- ZwQuerySymbolicLinkObject (Address: 0x100333d0)
- ZwQuerySystemInformation (Address: 0x10033324)
- ZwQueryValueKey (Address: 0x100333b8)
- ZwReleaseMutant (Address: 0x1003333c)
- ZwSaveKey (Address: 0x100333ac)
- ZwSetSecurityObject (Address: 0x100333bc)
- ZwSetValueKey (Address: 0x100333c4)
- ZwUnloadKey (Address: 0x100333c0)
- ZwWaitForSingleObject (Address: 0x10033334)
RPCRT4.dll
- UuidCreate (Address: 0x100330b8)
SHLWAPI.dll
- PathRemoveBackslashW (Address: 0x100330c0)
WCP.dll
- ?RtlGetFacilityTracingFlags@Rtl@WCP@Windows@@YIKPAU_RTL_TRACING_FACILITY@123@@Z (Address: 0x100330cc)
- ?RtlTraceFormat_PCWSTR@Rtl@WCP@Windows@@YIXPAUIRtlFormattedOutputStream@13@PBX@Z (Address: 0x100330d4)
- ?RtlTraceVa@Rtl@WCP@Windows@@YIXKKPAU_RTL_TRACING_FACILITY@123@QBDKPAD@Z (Address: 0x100330d8)
- RtlFreeLUnicodeString (Address: 0x100330d0)
- RtlReportErrorOrigination (Address: 0x100330c8)