bfsvc.dll
Description: CMI boot file service plug-in
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.6088
Architecture: 32-bit
Operating System: Windows NT
SHA256: 6242f6fa25dd0a3d7d8f7d5bc4a8496d
File Size: 233.9 KB
Uploaded At: Dec. 1, 2025, 8:40 a.m.
Views: 14
Exported Functions
- DllCanUnloadNow (Ordinal: 1, Address: 0x18dd0)
- DllCsiGetHandler (Ordinal: 2, Address: 0x18df0)
Imported DLLs & Functions
ADVAPI32.dll
- AdjustTokenPrivileges (Address: 0x10035018)
- ConvertSidToStringSidW (Address: 0x10035028)
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x10035024)
- DuplicateTokenEx (Address: 0x1003500c)
- GetSecurityDescriptorControl (Address: 0x10035030)
- GetSecurityDescriptorDacl (Address: 0x10035038)
- GetSecurityDescriptorGroup (Address: 0x10035004)
- GetSecurityDescriptorOwner (Address: 0x1003502c)
- GetSecurityDescriptorSacl (Address: 0x10035000)
- GetTokenInformation (Address: 0x10035020)
- LookupPrivilegeValueW (Address: 0x1003501c)
- OpenProcessToken (Address: 0x10035014)
- OpenThreadToken (Address: 0x10035008)
- SetNamedSecurityInfoW (Address: 0x10035034)
- SetThreadToken (Address: 0x10035010)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x10035104)
- IsDebuggerPresent (Address: 0x10035108)
- OutputDebugStringW (Address: 0x1003510c)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x10035114)
- SetLastError (Address: 0x1003511c)
- SetUnhandledExceptionFilter (Address: 0x10035120)
- UnhandledExceptionFilter (Address: 0x10035118)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x10035128)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x10035134)
- HeapAlloc (Address: 0x10035130)
- HeapDestroy (Address: 0x1003513c)
- HeapFree (Address: 0x10035138)
api-ms-win-core-libraryloader-l1-1-0.dll
- DisableThreadLibraryCalls (Address: 0x10035148)
- FindResourceExW (Address: 0x10035150)
- FreeLibrary (Address: 0x10035154)
- GetModuleFileNameA (Address: 0x1003514c)
- GetModuleHandleExW (Address: 0x10035158)
- GetModuleHandleW (Address: 0x10035144)
- GetProcAddress (Address: 0x10035160)
- LoadResource (Address: 0x1003515c)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x10035168)
api-ms-win-core-localization-obsolete-l1-2-0.dll
- GetSystemDefaultUILanguage (Address: 0x10035174)
- GetUserDefaultUILanguage (Address: 0x10035170)
api-ms-win-core-processenvironment-l1-1-0.dll
- SearchPathW (Address: 0x1003517c)
api-ms-win-core-processthreads-l1-1-0.dll
- GetCurrentProcess (Address: 0x10035188)
- GetCurrentProcessId (Address: 0x10035190)
- GetCurrentThreadId (Address: 0x10035184)
- TerminateProcess (Address: 0x1003518c)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x10035198)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x100351b0)
- RegCreateKeyExW (Address: 0x100351a0)
- RegOpenKeyExW (Address: 0x100351ac)
- RegQueryValueExW (Address: 0x100351a4)
- RegSetValueExW (Address: 0x100351a8)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x100351d8)
- AcquireSRWLockShared (Address: 0x100351d0)
- CreateMutexExW (Address: 0x100351f4)
- CreateSemaphoreExW (Address: 0x100351c8)
- DeleteCriticalSection (Address: 0x100351e0)
- EnterCriticalSection (Address: 0x100351e8)
- InitializeCriticalSection (Address: 0x100351f0)
- InitializeCriticalSectionEx (Address: 0x100351ec)
- LeaveCriticalSection (Address: 0x100351c4)
- OpenSemaphoreW (Address: 0x100351b8)
- ReleaseMutex (Address: 0x100351bc)
- ReleaseSemaphore (Address: 0x100351c0)
- ReleaseSRWLockExclusive (Address: 0x100351d4)
- ReleaseSRWLockShared (Address: 0x100351cc)
- WaitForSingleObject (Address: 0x100351dc)
- WaitForSingleObjectEx (Address: 0x100351e4)
api-ms-win-core-synch-l1-2-0.dll
- Sleep (Address: 0x100351fc)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemTimeAsFileTime (Address: 0x1003520c)
- GetTickCount (Address: 0x10035208)
- GetVersionExW (Address: 0x10035204)
api-ms-win-core-threadpool-l1-2-0.dll
- CloseThreadpoolTimer (Address: 0x10035218)
- CreateThreadpoolTimer (Address: 0x10035214)
- SetThreadpoolTimer (Address: 0x10035220)
- WaitForThreadpoolTimerCallbacks (Address: 0x1003521c)
api-ms-win-eventing-provider-l1-1-0.dll
- EventRegister (Address: 0x1003522c)
- EventUnregister (Address: 0x10035230)
- EventWriteTransfer (Address: 0x10035228)
bcrypt.dll
- BCryptCloseAlgorithmProvider (Address: 0x1003523c)
- BCryptCreateHash (Address: 0x10035240)
- BCryptDestroyHash (Address: 0x10035244)
- BCryptFinishHash (Address: 0x10035248)
- BCryptHash (Address: 0x1003524c)
- BCryptHashData (Address: 0x10035238)
- BCryptOpenAlgorithmProvider (Address: 0x10035250)
CRYPT32.dll
- CertGetNameStringW (Address: 0x10035040)
imagehlp.dll
- CheckSumMappedFile (Address: 0x10035258)
KERNEL32.dll
- CopyFileExW (Address: 0x10035048)
- CreateDirectoryW (Address: 0x100350bc)
- CreateFileMappingW (Address: 0x10035068)
- CreateFileW (Address: 0x10035094)
- DeleteFileW (Address: 0x1003504c)
- DeviceIoControl (Address: 0x10035070)
- FindClose (Address: 0x1003509c)
- FindFirstFileW (Address: 0x100350ac)
- FindNextFileW (Address: 0x100350a8)
- FlushFileBuffers (Address: 0x10035060)
- GetCurrentThread (Address: 0x100350c0)
- GetFileAttributesW (Address: 0x10035090)
- GetFileInformationByHandle (Address: 0x10035054)
- GetFileInformationByHandleEx (Address: 0x10035058)
- GetFileSizeEx (Address: 0x10035074)
- GetFullPathNameW (Address: 0x100350c4)
- GetLocaleInfoW (Address: 0x1003505c)
- GetPrivateProfileSectionW (Address: 0x100350a0)
- GetVolumeInformationW (Address: 0x100350b0)
- GetVolumeNameForVolumeMountPointW (Address: 0x1003508c)
- GetVolumePathNameW (Address: 0x10035098)
- LoadLibraryExW (Address: 0x100350b8)
- LoadLibraryW (Address: 0x10035080)
- LocalAlloc (Address: 0x1003507c)
- LocalFree (Address: 0x10035078)
- MapViewOfFile (Address: 0x10035064)
- MoveFileExW (Address: 0x10035084)
- QueryDosDeviceW (Address: 0x100350b4)
- SetFileAttributesW (Address: 0x10035088)
- SetFileInformationByHandle (Address: 0x10035050)
- UnmapViewOfFile (Address: 0x1003506c)
- WriteFile (Address: 0x100350a4)
msvcrt.dll
- __dllonexit (Address: 0x100352e8)
- __iob_func (Address: 0x100352f8)
- _amsg_exit (Address: 0x1003527c)
- _callnewh (Address: 0x10035260)
- _except_handler4_common (Address: 0x100352f0)
- _initterm (Address: 0x10035280)
- _lock (Address: 0x10035284)
- _onexit (Address: 0x100352ec)
- _purecall (Address: 0x1003526c)
- _snwscanf_s (Address: 0x100352d0)
- _ultow_s (Address: 0x100352c0)
- _unlock (Address: 0x100352e4)
- _vsnwprintf (Address: 0x10035278)
- _vsnwprintf_s (Address: 0x10035294)
- _wcsicmp (Address: 0x1003529c)
- _wcslwr (Address: 0x100352d4)
- _wcsnicmp (Address: 0x100352a0)
- _wcsupr (Address: 0x100352bc)
- _wfopen_s (Address: 0x1003528c)
- _XcptFilter (Address: 0x10035264)
- bsearch (Address: 0x100352e0)
- fclose (Address: 0x10035290)
- fflush (Address: 0x10035288)
- free (Address: 0x10035268)
- fwprintf (Address: 0x10035298)
- malloc (Address: 0x10035300)
- memcmp (Address: 0x10035304)
- memcpy (Address: 0x10035308)
- memcpy_s (Address: 0x100352fc)
- memmove (Address: 0x100352f4)
- memmove_s (Address: 0x10035274)
- memset (Address: 0x1003530c)
- strcpy_s (Address: 0x100352c8)
- strncmp (Address: 0x100352dc)
- swprintf_s (Address: 0x100352b8)
- wcscat_s (Address: 0x100352ac)
- wcschr (Address: 0x100352b4)
- wcscpy_s (Address: 0x100352a8)
- wcsncmp (Address: 0x100352a4)
- wcsncpy_s (Address: 0x100352b0)
- wcsnlen (Address: 0x100352d8)
- wcsrchr (Address: 0x10035270)
- wcsstr (Address: 0x100352cc)
- wcstoul (Address: 0x100352c4)
ntdll.dll
- LdrAccessResource (Address: 0x1003534c)
- LdrFindResource_U (Address: 0x10035348)
- LdrGetDllHandle (Address: 0x10035408)
- LdrGetProcedureAddress (Address: 0x10035404)
- NtAdjustPrivilegesToken (Address: 0x1003541c)
- NtClose (Address: 0x1003545c)
- NtCreateEvent (Address: 0x10035334)
- NtDeviceIoControlFile (Address: 0x1003532c)
- NtEnumerateBootEntries (Address: 0x10035450)
- NtOpenDirectoryObject (Address: 0x10035448)
- NtOpenFile (Address: 0x10035344)
- NtOpenKey (Address: 0x10035430)
- NtOpenProcess (Address: 0x10035320)
- NtOpenProcessTokenEx (Address: 0x10035420)
- NtOpenSymbolicLinkObject (Address: 0x1003542c)
- NtOpenThreadTokenEx (Address: 0x10035424)
- NtQueryBootEntryOrder (Address: 0x1003543c)
- NtQueryBootOptions (Address: 0x10035440)
- NtQueryDirectoryObject (Address: 0x1003544c)
- NtQueryInformationFile (Address: 0x10035338)
- NtQueryInformationProcess (Address: 0x1003531c)
- NtQueryInformationThread (Address: 0x1003533c)
- NtQuerySymbolicLinkObject (Address: 0x10035434)
- NtQuerySystemEnvironmentValueEx (Address: 0x100353b4)
- NtQuerySystemInformation (Address: 0x10035458)
- NtQueryValueKey (Address: 0x10035438)
- NtReadFile (Address: 0x10035324)
- NtSetInformationFile (Address: 0x10035354)
- NtSetInformationThread (Address: 0x10035328)
- NtTranslateFilePath (Address: 0x10035444)
- NtWaitForSingleObject (Address: 0x10035340)
- NtWriteFile (Address: 0x10035314)
- RtlAddAccessAllowedAceEx (Address: 0x100353a8)
- RtlAllocateAndInitializeSid (Address: 0x100353ac)
- RtlAllocateHeap (Address: 0x10035364)
- RtlAppendUnicodeToString (Address: 0x10035370)
- RtlCompareMemory (Address: 0x10035360)
- RtlCreateAcl (Address: 0x100353d0)
- RtlCreateSecurityDescriptor (Address: 0x100353dc)
- RtlFreeHeap (Address: 0x1003535c)
- RtlFreeSid (Address: 0x100353c0)
- RtlFreeUnicodeString (Address: 0x10035350)
- RtlGetVersion (Address: 0x100353fc)
- RtlGUIDFromString (Address: 0x1003536c)
- RtlImageNtHeader (Address: 0x10035330)
- RtlImpersonateSelf (Address: 0x10035428)
- RtlInitAnsiString (Address: 0x10035410)
- RtlInitUnicodeString (Address: 0x10035460)
- RtlLengthSecurityDescriptor (Address: 0x10035390)
- RtlLengthSid (Address: 0x100353b0)
- RtlNtStatusToDosError (Address: 0x10035318)
- RtlSetDaclSecurityDescriptor (Address: 0x10035398)
- RtlSetOwnerSecurityDescriptor (Address: 0x10035394)
- RtlStringFromGUID (Address: 0x10035358)
- ZwAllocateUuids (Address: 0x100353e8)
- ZwClose (Address: 0x1003538c)
- ZwCreateFile (Address: 0x1003539c)
- ZwCreateKey (Address: 0x100353a0)
- ZwDeleteKey (Address: 0x100353c4)
- ZwDeleteValueKey (Address: 0x100353b8)
- ZwDeviceIoControlFile (Address: 0x100353f0)
- ZwEnumerateKey (Address: 0x100353c8)
- ZwFlushKey (Address: 0x10035454)
- ZwLoadKey (Address: 0x100353a4)
- ZwOpenDirectoryObject (Address: 0x10035400)
- ZwOpenFile (Address: 0x10035384)
- ZwOpenKey (Address: 0x100353e4)
- ZwOpenMutant (Address: 0x10035388)
- ZwOpenProcess (Address: 0x10035418)
- ZwOpenSymbolicLinkObject (Address: 0x100353f8)
- ZwQueryAttributesFile (Address: 0x10035374)
- ZwQueryDirectoryObject (Address: 0x100353f4)
- ZwQueryInformationFile (Address: 0x10035414)
- ZwQueryInformationProcess (Address: 0x1003540c)
- ZwQueryKey (Address: 0x1003537c)
- ZwQuerySymbolicLinkObject (Address: 0x100353ec)
- ZwQuerySystemInformation (Address: 0x10035368)
- ZwQueryValueKey (Address: 0x100353cc)
- ZwReleaseMutant (Address: 0x10035380)
- ZwSaveKey (Address: 0x100353bc)
- ZwSetSecurityObject (Address: 0x100353d4)
- ZwSetValueKey (Address: 0x100353e0)
- ZwUnloadKey (Address: 0x100353d8)
- ZwWaitForSingleObject (Address: 0x10035378)
RPCRT4.dll
- UuidCreate (Address: 0x100350cc)
SHLWAPI.dll
- PathRemoveBackslashW (Address: 0x100350d4)
WCP.dll
- ?RtlGetFacilityTracingFlags@Rtl@WCP@Windows@@YIKPAU_RTL_TRACING_FACILITY@123@@Z (Address: 0x100350e8)
- ?RtlTraceFormat_PCWSTR@Rtl@WCP@Windows@@YIXPAUIRtlFormattedOutputStream@13@PBX@Z (Address: 0x100350ec)
- ?RtlTraceVa@Rtl@WCP@Windows@@YIXKKPAU_RTL_TRACING_FACILITY@123@QBDKPAD@Z (Address: 0x100350dc)
- RtlFreeLUnicodeString (Address: 0x100350e4)
- RtlReportErrorOrigination (Address: 0x100350e0)
WINTRUST.dll
- WinVerifyTrust (Address: 0x100350f4)
- WTHelperGetProvSignerFromChain (Address: 0x100350fc)
- WTHelperProvDataFromStateData (Address: 0x100350f8)