tdh.dll

Description: Event Trace Helper Library

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.5915

Architecture: 64-bit

Operating System: Windows NT

SHA256: ff70ee258e974fb7b775c14d6f7b1be7

File Size: 1.1 MB

Uploaded At: Dec. 1, 2025, 7:40 a.m.

Views: 8

Exported Functions

  • DllCanUnloadNow (Ordinal: 1, Address: 0x12470)
  • DllGetClassObject (Ordinal: 2, Address: 0x12490)
  • TdhAggregatePayloadFilters (Ordinal: 3, Address: 0x12640)
  • TdhApplyPayloadFilter (Ordinal: 4, Address: 0x1a7d0)
  • TdhCleanupPayloadEventFilterDescriptor (Ordinal: 5, Address: 0x12690)
  • TdhCloseDecodingHandle (Ordinal: 6, Address: 0x1ff50)
  • TdhCreatePayloadFilter (Ordinal: 7, Address: 0x12700)
  • TdhDeletePayloadFilter (Ordinal: 8, Address: 0x12740)
  • TdhEnumerateManifestProviderEvents (Ordinal: 9, Address: 0x13070)
  • TdhEnumerateProviderFieldInformation (Ordinal: 10, Address: 0x130a0)
  • TdhEnumerateProviderFilters (Ordinal: 11, Address: 0x127b0)
  • TdhEnumerateProviders (Ordinal: 12, Address: 0xb190)
  • TdhEnumerateRemoteWBEMProviderFieldInformation (Ordinal: 13, Address: 0x1ef60)
  • TdhEnumerateRemoteWBEMProviders (Ordinal: 14, Address: 0x1f060)
  • TdhFormatProperty (Ordinal: 15, Address: 0x131a0)
  • TdhGetAllEventsInformation (Ordinal: 16, Address: 0x12810)
  • TdhGetDecodingParameter (Ordinal: 17, Address: 0x1ff70)
  • TdhGetEventInformation (Ordinal: 18, Address: 0x4ad0)
  • TdhGetEventMapInformation (Ordinal: 19, Address: 0x133a0)
  • TdhGetManifestEventInformation (Ordinal: 20, Address: 0x13430)
  • TdhGetProperty (Ordinal: 21, Address: 0x44c0)
  • TdhGetPropertyOffsetAndSize (Ordinal: 22, Address: 0x128a0)
  • TdhGetPropertySize (Ordinal: 23, Address: 0x3ed0)
  • TdhGetWppMessage (Ordinal: 24, Address: 0x1ffe0)
  • TdhGetWppProperty (Ordinal: 25, Address: 0x20010)
  • TdhLoadManifest (Ordinal: 26, Address: 0x13490)
  • TdhLoadManifestFromBinary (Ordinal: 27, Address: 0x12950)
  • TdhLoadManifestFromMemory (Ordinal: 28, Address: 0x134e0)
  • TdhOpenDecodingHandle (Ordinal: 29, Address: 0x200d0)
  • TdhQueryProviderFieldInformation (Ordinal: 30, Address: 0xb0e0)
  • TdhQueryRemoteWBEMProviderFieldInformation (Ordinal: 31, Address: 0x1f1f0)
  • TdhSetDecodingParameter (Ordinal: 32, Address: 0x20180)
  • TdhUnloadManifest (Ordinal: 33, Address: 0x13500)
  • TdhUnloadManifestFromMemory (Ordinal: 34, Address: 0x13550)
  • TdhValidatePayloadFilter (Ordinal: 35, Address: 0x1b0b0)

Imported DLLs & Functions

api-ms-win-core-datetime-l1-1-0.dll
  • GetDateFormatW (Address: 0x180055da0)
  • GetTimeFormatW (Address: 0x180055da8)
api-ms-win-core-debug-l1-1-0.dll
  • IsDebuggerPresent (Address: 0x180055db8)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x180055dc8)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x180055dd8)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x180055e00)
  • RaiseException (Address: 0x180055df8)
  • SetLastError (Address: 0x180055e08)
  • SetUnhandledExceptionFilter (Address: 0x180055de8)
  • UnhandledExceptionFilter (Address: 0x180055df0)
api-ms-win-core-file-l1-1-0.dll
  • CreateFileW (Address: 0x180055e20)
  • FileTimeToLocalFileTime (Address: 0x180055e50)
  • FindFirstVolumeW (Address: 0x180055e18)
  • FindNextVolumeW (Address: 0x180055e30)
  • FindVolumeClose (Address: 0x180055e28)
  • GetFileSize (Address: 0x180055e40)
  • GetFileTime (Address: 0x180055e38)
  • QueryDosDeviceW (Address: 0x180055e48)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x180055e60)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x180055e78)
  • HeapAlloc (Address: 0x180055e80)
  • HeapFree (Address: 0x180055e70)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x180055e98)
  • LocalFree (Address: 0x180055e90)
api-ms-win-core-interlocked-l1-1-0.dll
  • InitializeSListHead (Address: 0x180055ec0)
  • InterlockedFlushSList (Address: 0x180055eb0)
  • InterlockedPopEntrySList (Address: 0x180055ea8)
  • InterlockedPushEntrySList (Address: 0x180055eb8)
api-ms-win-core-libraryloader-l1-2-0.dll
  • FindResourceExW (Address: 0x180055f18)
  • FreeLibrary (Address: 0x180055ed0)
  • FreeResource (Address: 0x180055f10)
  • GetModuleFileNameW (Address: 0x180055f08)
  • GetModuleHandleW (Address: 0x180055ed8)
  • GetProcAddress (Address: 0x180055ef0)
  • LoadLibraryExW (Address: 0x180055f20)
  • LoadResource (Address: 0x180055ef8)
  • LoadStringW (Address: 0x180055ee8)
  • LockResource (Address: 0x180055f00)
  • SizeofResource (Address: 0x180055ee0)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x180055f30)
api-ms-win-core-memory-l1-1-0.dll
  • CreateFileMappingW (Address: 0x180055f50)
  • MapViewOfFile (Address: 0x180055f48)
  • UnmapViewOfFile (Address: 0x180055f40)
api-ms-win-core-processenvironment-l1-1-0.dll
  • ExpandEnvironmentStringsW (Address: 0x180055f60)
  • GetCurrentDirectoryW (Address: 0x180055f78)
  • GetEnvironmentVariableA (Address: 0x180055f68)
  • GetEnvironmentVariableW (Address: 0x180055f80)
  • SearchPathW (Address: 0x180055f70)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x180055fa0)
  • GetCurrentProcessId (Address: 0x180055f90)
  • GetCurrentThreadId (Address: 0x180055f98)
  • TerminateProcess (Address: 0x180055fa8)
api-ms-win-core-processthreads-l1-1-1.dll
  • IsProcessorFeaturePresent (Address: 0x180055fb8)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x180055fc8)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x180055ff8)
  • RegEnumKeyExW (Address: 0x180055fe8)
  • RegOpenKeyExW (Address: 0x180055fe0)
  • RegQueryInfoKeyW (Address: 0x180055ff0)
  • RegQueryValueExW (Address: 0x180055fd8)
api-ms-win-core-string-l1-1-0.dll
  • CompareStringOrdinal (Address: 0x180056008)
  • MultiByteToWideChar (Address: 0x180056018)
  • WideCharToMultiByte (Address: 0x180056010)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x180056090)
  • AcquireSRWLockShared (Address: 0x180056080)
  • CreateEventW (Address: 0x180056038)
  • DeleteCriticalSection (Address: 0x180056078)
  • EnterCriticalSection (Address: 0x180056040)
  • InitializeCriticalSection (Address: 0x180056028)
  • InitializeCriticalSectionAndSpinCount (Address: 0x180056060)
  • InitializeCriticalSectionEx (Address: 0x180056068)
  • LeaveCriticalSection (Address: 0x180056030)
  • ReleaseSRWLockExclusive (Address: 0x180056070)
  • ReleaseSRWLockShared (Address: 0x180056088)
  • ResetEvent (Address: 0x180056050)
  • SetEvent (Address: 0x180056058)
  • WaitForSingleObjectEx (Address: 0x180056048)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceExecuteOnce (Address: 0x1800560a0)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTimeAsFileTime (Address: 0x1800560b0)
api-ms-win-core-timezone-l1-1-0.dll
  • FileTimeToSystemTime (Address: 0x1800560c0)
api-ms-win-crt-math-l1-1-0.dll
  • ceilf (Address: 0x1800560d0)
api-ms-win-crt-private-l1-1-0.dll
  • __C_specific_handler (Address: 0x1800562b8)
  • __CxxFrameHandler3 (Address: 0x180056278)
  • __CxxFrameHandler4 (Address: 0x1800562c8)
  • __std_terminate (Address: 0x1800562c0)
  • _CxxThrowException (Address: 0x180056218)
  • _o___acrt_iob_func (Address: 0x1800562a0)
  • _o___std_exception_copy (Address: 0x180056268)
  • _o___std_exception_destroy (Address: 0x180056260)
  • _o___std_type_info_destroy_list (Address: 0x180056258)
  • _o___stdio_common_vfprintf (Address: 0x180056250)
  • _o___stdio_common_vsnwprintf_s (Address: 0x180056248)
  • _o___stdio_common_vsprintf (Address: 0x180056240)
  • _o___stdio_common_vsprintf_s (Address: 0x180056238)
  • _o___stdio_common_vswprintf (Address: 0x180056230)
  • _o___stdio_common_vswscanf (Address: 0x180056228)
  • _o__callnewh (Address: 0x180056270)
  • _o__cexit (Address: 0x180056220)
  • _o__configure_narrow_argv (Address: 0x1800560e0)
  • _o__crt_atexit (Address: 0x1800560e8)
  • _o__errno (Address: 0x1800560f0)
  • _o__execute_onexit_table (Address: 0x1800560f8)
  • _o__initialize_narrow_environment (Address: 0x180056100)
  • _o__initialize_onexit_table (Address: 0x180056108)
  • _o__invalid_parameter_noinfo_noreturn (Address: 0x180056110)
  • _o__purecall (Address: 0x180056118)
  • _o__register_onexit_function (Address: 0x180056120)
  • _o__resetstkoflw (Address: 0x180056128)
  • _o__seh_filter_dll (Address: 0x180056130)
  • _o__splitpath_s (Address: 0x180056138)
  • _o__wcsicmp (Address: 0x180056148)
  • _o__wcsnicmp (Address: 0x180056150)
  • _o__wcstoi64 (Address: 0x180056158)
  • _o__wcstoui64 (Address: 0x180056160)
  • _o__wfopen (Address: 0x180056168)
  • _o__wsplitpath_s (Address: 0x180056170)
  • _o__wtoi (Address: 0x180056178)
  • _o_fclose (Address: 0x180056180)
  • _o_fgets (Address: 0x180056188)
  • _o_fgetws (Address: 0x180056190)
  • _o_fopen (Address: 0x180056198)
  • _o_fputs (Address: 0x1800561a0)
  • _o_free (Address: 0x1800561a8)
  • _o_isdigit (Address: 0x1800561b0)
  • _o_iswspace (Address: 0x1800561b8)
  • _o_iswxdigit (Address: 0x1800561c0)
  • _o_malloc (Address: 0x1800561c8)
  • _o_memcpy_s (Address: 0x1800561d0)
  • _o_strcpy_s (Address: 0x1800561d8)
  • _o_strncpy_s (Address: 0x1800561e0)
  • _o_terminate (Address: 0x1800561e8)
  • _o_towlower (Address: 0x1800561f0)
  • _o_wcscpy_s (Address: 0x1800561f8)
  • _o_wcstok_s (Address: 0x180056200)
  • _o_wcstol (Address: 0x180056208)
  • _o_wcstoul (Address: 0x180056210)
  • memcmp (Address: 0x1800562d0)
  • memcpy (Address: 0x1800562d8)
  • memmove (Address: 0x180056140)
  • strchr (Address: 0x180056290)
  • strrchr (Address: 0x180056298)
  • strstr (Address: 0x180056288)
  • wcschr (Address: 0x1800562b0)
  • wcsrchr (Address: 0x180056280)
  • wcsstr (Address: 0x1800562a8)
api-ms-win-crt-runtime-l1-1-0.dll
  • _initterm (Address: 0x1800562e8)
  • _initterm_e (Address: 0x1800562f0)
api-ms-win-crt-string-l1-1-0.dll
  • memset (Address: 0x180056308)
  • strcmp (Address: 0x180056318)
  • strncmp (Address: 0x180056338)
  • strnlen (Address: 0x180056300)
  • wcscspn (Address: 0x180056330)
  • wcsncmp (Address: 0x180056320)
  • wcsnlen (Address: 0x180056310)
  • wcsspn (Address: 0x180056328)
api-ms-win-eventing-classicprovider-l1-1-0.dll
  • GetTraceEnableFlags (Address: 0x180056360)
  • GetTraceEnableLevel (Address: 0x180056368)
  • GetTraceLoggerHandle (Address: 0x180056358)
  • RegisterTraceGuidsW (Address: 0x180056370)
  • TraceEvent (Address: 0x180056348)
  • TraceMessage (Address: 0x180056350)
  • UnregisterTraceGuids (Address: 0x180056378)
api-ms-win-eventing-consumer-l1-1-0.dll
  • CloseTrace (Address: 0x180056398)
  • OpenTraceW (Address: 0x180056390)
  • ProcessTrace (Address: 0x180056388)
api-ms-win-eventing-controller-l1-1-0.dll
  • StartTraceW (Address: 0x1800563a8)
  • StopTraceW (Address: 0x1800563b0)
api-ms-win-security-base-l1-1-0.dll
  • GetLengthSid (Address: 0x1800563c0)
api-ms-win-security-lsalookup-l1-1-0.dll
  • LookupAccountSidLocalW (Address: 0x1800563d0)
msvcp_win.dll
  • ?_Xlength_error@std@@YAXPEBD@Z (Address: 0x1800563e0)
  • ?_Xout_of_range@std@@YAXPEBD@Z (Address: 0x1800563e8)
ntdll.dll
  • RtlAcquireSRWLockExclusive (Address: 0x180056408)
  • RtlAcquireSRWLockShared (Address: 0x180056410)
  • RtlCaptureContext (Address: 0x180056460)
  • RtlEthernetAddressToStringW (Address: 0x180056450)
  • RtlGUIDFromString (Address: 0x180056420)
  • RtlInitializeSRWLock (Address: 0x1800563f8)
  • RtlIpv4AddressToStringExW (Address: 0x180056448)
  • RtlIpv6AddressToStringExW (Address: 0x180056468)
  • RtlIpv6AddressToStringW (Address: 0x180056458)
  • RtlLengthRequiredSid (Address: 0x180056430)
  • RtlLookupFunctionEntry (Address: 0x180056438)
  • RtlReleaseSRWLockExclusive (Address: 0x180056400)
  • RtlReleaseSRWLockShared (Address: 0x180056418)
  • RtlSubAuthorityCountSid (Address: 0x180056428)
  • RtlVirtualUnwind (Address: 0x180056440)
SECHOST.dll
  • EtwQueryRealtimeConsumer (Address: 0x180055d90)