spbcd.dll

Description: BCD Sysprep Plugin

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.3636

Architecture: 64-bit

Operating System: Windows NT

SHA256: 934b0ceed09f072d771ffadc3096f7ee

File Size: 108.5 KB

Uploaded At: Dec. 1, 2025, 7:39 a.m.

Views: 4

Exported Functions

  • Sysprep_Generalize_Bcd (Ordinal: 1, Address: 0x10c0)
  • Sysprep_Offline_Specialize_Bcd (Ordinal: 2, Address: 0x12f0)
  • Sysprep_Online_Specialize_Bcd (Ordinal: 3, Address: 0x14c0)

Imported DLLs & Functions

ADVAPI32.dll
  • RegGetValueW (Address: 0x180014138)
KERNEL32.dll
  • CompareStringW (Address: 0x1800141c0)
  • ExpandEnvironmentStringsW (Address: 0x1800141b0)
  • GetCurrentProcess (Address: 0x180014178)
  • GetCurrentProcessId (Address: 0x180014160)
  • GetCurrentThreadId (Address: 0x180014148)
  • GetLastError (Address: 0x1800141a8)
  • GetProcessHeap (Address: 0x180014198)
  • GetSystemTimeAsFileTime (Address: 0x180014158)
  • GetTickCount (Address: 0x180014150)
  • HeapAlloc (Address: 0x1800141a0)
  • HeapFree (Address: 0x1800141b8)
  • QueryDosDeviceW (Address: 0x1800141c8)
  • QueryPerformanceCounter (Address: 0x180014168)
  • SetUnhandledExceptionFilter (Address: 0x180014180)
  • Sleep (Address: 0x180014190)
  • TerminateProcess (Address: 0x180014170)
  • UnhandledExceptionFilter (Address: 0x180014188)
msvcrt.dll
  • __C_specific_handler (Address: 0x180014290)
  • _amsg_exit (Address: 0x1800142b0)
  • _initterm (Address: 0x180014298)
  • _snwscanf_s (Address: 0x180014270)
  • _ultow_s (Address: 0x1800141f8)
  • _vsnwprintf (Address: 0x1800142d8)
  • _vsnwprintf_s (Address: 0x180014208)
  • _wcsicmp (Address: 0x1800142d0)
  • _wcslwr (Address: 0x180014210)
  • _wcsnicmp (Address: 0x180014238)
  • _wcsupr (Address: 0x180014250)
  • _XcptFilter (Address: 0x1800142b8)
  • free (Address: 0x1800142a8)
  • malloc (Address: 0x1800142a0)
  • memcmp (Address: 0x180014278)
  • memcpy (Address: 0x180014280)
  • memmove (Address: 0x180014288)
  • memset (Address: 0x180014268)
  • strcpy_s (Address: 0x180014228)
  • strncmp (Address: 0x180014258)
  • swprintf_s (Address: 0x1800142c8)
  • wcscat_s (Address: 0x180014240)
  • wcschr (Address: 0x180014220)
  • wcscpy_s (Address: 0x180014200)
  • wcsncpy_s (Address: 0x1800142c0)
  • wcsnlen (Address: 0x180014248)
  • wcsrchr (Address: 0x180014230)
  • wcsstr (Address: 0x180014260)
  • wcstoul (Address: 0x180014218)
ntdll.dll
  • LdrGetDllHandle (Address: 0x180014370)
  • LdrGetProcedureAddress (Address: 0x180014378)
  • NtAdjustPrivilegesToken (Address: 0x180014350)
  • NtClose (Address: 0x1800144d8)
  • NtCreateFile (Address: 0x1800144d0)
  • NtDeviceIoControlFile (Address: 0x1800144c0)
  • NtEnumerateBootEntries (Address: 0x1800142e8)
  • NtOpenDirectoryObject (Address: 0x1800142f8)
  • NtOpenFile (Address: 0x1800144b8)
  • NtOpenKey (Address: 0x180014328)
  • NtOpenProcessTokenEx (Address: 0x180014348)
  • NtOpenSymbolicLinkObject (Address: 0x180014330)
  • NtOpenThreadTokenEx (Address: 0x180014340)
  • NtQueryBootEntryOrder (Address: 0x180014310)
  • NtQueryBootOptions (Address: 0x180014308)
  • NtQueryDirectoryObject (Address: 0x1800142f0)
  • NtQuerySymbolicLinkObject (Address: 0x180014320)
  • NtQuerySystemInformation (Address: 0x180014520)
  • NtQueryValueKey (Address: 0x180014318)
  • NtSetInformationThread (Address: 0x1800144c8)
  • NtTranslateFilePath (Address: 0x180014300)
  • NtWriteFile (Address: 0x1800144f0)
  • RtlAddAccessAllowedAceEx (Address: 0x180014418)
  • RtlAllocateAndInitializeSid (Address: 0x180014410)
  • RtlAllocateHeap (Address: 0x180014488)
  • RtlAppendUnicodeToString (Address: 0x180014480)
  • RtlCaptureContext (Address: 0x180014510)
  • RtlCompareMemory (Address: 0x1800144f8)
  • RtlCreateAcl (Address: 0x1800143d8)
  • RtlCreateSecurityDescriptor (Address: 0x1800143c0)
  • RtlFreeHeap (Address: 0x180014490)
  • RtlFreeSid (Address: 0x1800143f8)
  • RtlFreeUnicodeString (Address: 0x1800144a0)
  • RtlGetNtProductType (Address: 0x1800144e0)
  • RtlGUIDFromString (Address: 0x1800144a8)
  • RtlImpersonateSelf (Address: 0x180014338)
  • RtlInitAnsiString (Address: 0x180014368)
  • RtlInitUnicodeString (Address: 0x1800144e8)
  • RtlLengthSecurityDescriptor (Address: 0x180014440)
  • RtlLengthSid (Address: 0x180014408)
  • RtlLookupFunctionEntry (Address: 0x180014508)
  • RtlNtStatusToDosError (Address: 0x180014518)
  • RtlSetDaclSecurityDescriptor (Address: 0x180014430)
  • RtlSetOwnerSecurityDescriptor (Address: 0x180014438)
  • RtlStringFromGUID (Address: 0x180014498)
  • RtlVirtualUnwind (Address: 0x180014500)
  • ZwAllocateUuids (Address: 0x1800143a8)
  • ZwClose (Address: 0x180014448)
  • ZwCreateKey (Address: 0x180014428)
  • ZwDeleteKey (Address: 0x1800143f0)
  • ZwDeleteValueKey (Address: 0x180014400)
  • ZwDeviceIoControlFile (Address: 0x180014398)
  • ZwEnumerateKey (Address: 0x1800143e8)
  • ZwLoadKey (Address: 0x180014420)
  • ZwOpenDirectoryObject (Address: 0x180014380)
  • ZwOpenFile (Address: 0x180014458)
  • ZwOpenKey (Address: 0x1800143b0)
  • ZwOpenMutant (Address: 0x180014450)
  • ZwOpenProcess (Address: 0x180014358)
  • ZwOpenSymbolicLinkObject (Address: 0x180014388)
  • ZwQueryAttributesFile (Address: 0x180014478)
  • ZwQueryDirectoryObject (Address: 0x180014390)
  • ZwQueryInformationFile (Address: 0x180014360)
  • ZwQueryInformationProcess (Address: 0x180014528)
  • ZwQueryKey (Address: 0x180014468)
  • ZwQuerySymbolicLinkObject (Address: 0x1800143a0)
  • ZwQuerySystemInformation (Address: 0x1800144b0)
  • ZwQueryValueKey (Address: 0x1800143e0)
  • ZwReleaseMutant (Address: 0x180014460)
  • ZwSetSecurityObject (Address: 0x1800143d0)
  • ZwSetValueKey (Address: 0x1800143b8)
  • ZwUnloadKey (Address: 0x1800143c8)
  • ZwWaitForSingleObject (Address: 0x180014470)
WDSCORE.dll
  • ConstructPartialMsgVW (Address: 0x1800141d8)
  • CurrentIP (Address: 0x1800141e0)
  • WdsSetupLogMessageW (Address: 0x1800141e8)