spbcd.dll
Description: BCD Sysprep Plugin
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.3636
Architecture: 64-bit
Operating System: Windows NT
SHA256: 934b0ceed09f072d771ffadc3096f7ee
File Size: 108.5 KB
Uploaded At: Dec. 1, 2025, 7:39 a.m.
Views: 4
Exported Functions
- Sysprep_Generalize_Bcd (Ordinal: 1, Address: 0x10c0)
- Sysprep_Offline_Specialize_Bcd (Ordinal: 2, Address: 0x12f0)
- Sysprep_Online_Specialize_Bcd (Ordinal: 3, Address: 0x14c0)
Imported DLLs & Functions
ADVAPI32.dll
- RegGetValueW (Address: 0x180014138)
KERNEL32.dll
- CompareStringW (Address: 0x1800141c0)
- ExpandEnvironmentStringsW (Address: 0x1800141b0)
- GetCurrentProcess (Address: 0x180014178)
- GetCurrentProcessId (Address: 0x180014160)
- GetCurrentThreadId (Address: 0x180014148)
- GetLastError (Address: 0x1800141a8)
- GetProcessHeap (Address: 0x180014198)
- GetSystemTimeAsFileTime (Address: 0x180014158)
- GetTickCount (Address: 0x180014150)
- HeapAlloc (Address: 0x1800141a0)
- HeapFree (Address: 0x1800141b8)
- QueryDosDeviceW (Address: 0x1800141c8)
- QueryPerformanceCounter (Address: 0x180014168)
- SetUnhandledExceptionFilter (Address: 0x180014180)
- Sleep (Address: 0x180014190)
- TerminateProcess (Address: 0x180014170)
- UnhandledExceptionFilter (Address: 0x180014188)
msvcrt.dll
- __C_specific_handler (Address: 0x180014290)
- _amsg_exit (Address: 0x1800142b0)
- _initterm (Address: 0x180014298)
- _snwscanf_s (Address: 0x180014270)
- _ultow_s (Address: 0x1800141f8)
- _vsnwprintf (Address: 0x1800142d8)
- _vsnwprintf_s (Address: 0x180014208)
- _wcsicmp (Address: 0x1800142d0)
- _wcslwr (Address: 0x180014210)
- _wcsnicmp (Address: 0x180014238)
- _wcsupr (Address: 0x180014250)
- _XcptFilter (Address: 0x1800142b8)
- free (Address: 0x1800142a8)
- malloc (Address: 0x1800142a0)
- memcmp (Address: 0x180014278)
- memcpy (Address: 0x180014280)
- memmove (Address: 0x180014288)
- memset (Address: 0x180014268)
- strcpy_s (Address: 0x180014228)
- strncmp (Address: 0x180014258)
- swprintf_s (Address: 0x1800142c8)
- wcscat_s (Address: 0x180014240)
- wcschr (Address: 0x180014220)
- wcscpy_s (Address: 0x180014200)
- wcsncpy_s (Address: 0x1800142c0)
- wcsnlen (Address: 0x180014248)
- wcsrchr (Address: 0x180014230)
- wcsstr (Address: 0x180014260)
- wcstoul (Address: 0x180014218)
ntdll.dll
- LdrGetDllHandle (Address: 0x180014370)
- LdrGetProcedureAddress (Address: 0x180014378)
- NtAdjustPrivilegesToken (Address: 0x180014350)
- NtClose (Address: 0x1800144d8)
- NtCreateFile (Address: 0x1800144d0)
- NtDeviceIoControlFile (Address: 0x1800144c0)
- NtEnumerateBootEntries (Address: 0x1800142e8)
- NtOpenDirectoryObject (Address: 0x1800142f8)
- NtOpenFile (Address: 0x1800144b8)
- NtOpenKey (Address: 0x180014328)
- NtOpenProcessTokenEx (Address: 0x180014348)
- NtOpenSymbolicLinkObject (Address: 0x180014330)
- NtOpenThreadTokenEx (Address: 0x180014340)
- NtQueryBootEntryOrder (Address: 0x180014310)
- NtQueryBootOptions (Address: 0x180014308)
- NtQueryDirectoryObject (Address: 0x1800142f0)
- NtQuerySymbolicLinkObject (Address: 0x180014320)
- NtQuerySystemInformation (Address: 0x180014520)
- NtQueryValueKey (Address: 0x180014318)
- NtSetInformationThread (Address: 0x1800144c8)
- NtTranslateFilePath (Address: 0x180014300)
- NtWriteFile (Address: 0x1800144f0)
- RtlAddAccessAllowedAceEx (Address: 0x180014418)
- RtlAllocateAndInitializeSid (Address: 0x180014410)
- RtlAllocateHeap (Address: 0x180014488)
- RtlAppendUnicodeToString (Address: 0x180014480)
- RtlCaptureContext (Address: 0x180014510)
- RtlCompareMemory (Address: 0x1800144f8)
- RtlCreateAcl (Address: 0x1800143d8)
- RtlCreateSecurityDescriptor (Address: 0x1800143c0)
- RtlFreeHeap (Address: 0x180014490)
- RtlFreeSid (Address: 0x1800143f8)
- RtlFreeUnicodeString (Address: 0x1800144a0)
- RtlGetNtProductType (Address: 0x1800144e0)
- RtlGUIDFromString (Address: 0x1800144a8)
- RtlImpersonateSelf (Address: 0x180014338)
- RtlInitAnsiString (Address: 0x180014368)
- RtlInitUnicodeString (Address: 0x1800144e8)
- RtlLengthSecurityDescriptor (Address: 0x180014440)
- RtlLengthSid (Address: 0x180014408)
- RtlLookupFunctionEntry (Address: 0x180014508)
- RtlNtStatusToDosError (Address: 0x180014518)
- RtlSetDaclSecurityDescriptor (Address: 0x180014430)
- RtlSetOwnerSecurityDescriptor (Address: 0x180014438)
- RtlStringFromGUID (Address: 0x180014498)
- RtlVirtualUnwind (Address: 0x180014500)
- ZwAllocateUuids (Address: 0x1800143a8)
- ZwClose (Address: 0x180014448)
- ZwCreateKey (Address: 0x180014428)
- ZwDeleteKey (Address: 0x1800143f0)
- ZwDeleteValueKey (Address: 0x180014400)
- ZwDeviceIoControlFile (Address: 0x180014398)
- ZwEnumerateKey (Address: 0x1800143e8)
- ZwLoadKey (Address: 0x180014420)
- ZwOpenDirectoryObject (Address: 0x180014380)
- ZwOpenFile (Address: 0x180014458)
- ZwOpenKey (Address: 0x1800143b0)
- ZwOpenMutant (Address: 0x180014450)
- ZwOpenProcess (Address: 0x180014358)
- ZwOpenSymbolicLinkObject (Address: 0x180014388)
- ZwQueryAttributesFile (Address: 0x180014478)
- ZwQueryDirectoryObject (Address: 0x180014390)
- ZwQueryInformationFile (Address: 0x180014360)
- ZwQueryInformationProcess (Address: 0x180014528)
- ZwQueryKey (Address: 0x180014468)
- ZwQuerySymbolicLinkObject (Address: 0x1800143a0)
- ZwQuerySystemInformation (Address: 0x1800144b0)
- ZwQueryValueKey (Address: 0x1800143e0)
- ZwReleaseMutant (Address: 0x180014460)
- ZwSetSecurityObject (Address: 0x1800143d0)
- ZwSetValueKey (Address: 0x1800143b8)
- ZwUnloadKey (Address: 0x1800143c8)
- ZwWaitForSingleObject (Address: 0x180014470)
WDSCORE.dll
- ConstructPartialMsgVW (Address: 0x1800141d8)
- CurrentIP (Address: 0x1800141e0)
- WdsSetupLogMessageW (Address: 0x1800141e8)