tdh.dll
Description: Event Trace Helper Library
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.5915
Architecture: 64-bit
Operating System: Windows NT
SHA256: ff70ee258e974fb7b775c14d6f7b1be7
File Size: 1.1 MB
Uploaded At: Dec. 1, 2025, 7:40 a.m.
Views: 8
Exported Functions
- DllCanUnloadNow (Ordinal: 1, Address: 0x12470)
- DllGetClassObject (Ordinal: 2, Address: 0x12490)
- TdhAggregatePayloadFilters (Ordinal: 3, Address: 0x12640)
- TdhApplyPayloadFilter (Ordinal: 4, Address: 0x1a7d0)
- TdhCleanupPayloadEventFilterDescriptor (Ordinal: 5, Address: 0x12690)
- TdhCloseDecodingHandle (Ordinal: 6, Address: 0x1ff50)
- TdhCreatePayloadFilter (Ordinal: 7, Address: 0x12700)
- TdhDeletePayloadFilter (Ordinal: 8, Address: 0x12740)
- TdhEnumerateManifestProviderEvents (Ordinal: 9, Address: 0x13070)
- TdhEnumerateProviderFieldInformation (Ordinal: 10, Address: 0x130a0)
- TdhEnumerateProviderFilters (Ordinal: 11, Address: 0x127b0)
- TdhEnumerateProviders (Ordinal: 12, Address: 0xb190)
- TdhEnumerateRemoteWBEMProviderFieldInformation (Ordinal: 13, Address: 0x1ef60)
- TdhEnumerateRemoteWBEMProviders (Ordinal: 14, Address: 0x1f060)
- TdhFormatProperty (Ordinal: 15, Address: 0x131a0)
- TdhGetAllEventsInformation (Ordinal: 16, Address: 0x12810)
- TdhGetDecodingParameter (Ordinal: 17, Address: 0x1ff70)
- TdhGetEventInformation (Ordinal: 18, Address: 0x4ad0)
- TdhGetEventMapInformation (Ordinal: 19, Address: 0x133a0)
- TdhGetManifestEventInformation (Ordinal: 20, Address: 0x13430)
- TdhGetProperty (Ordinal: 21, Address: 0x44c0)
- TdhGetPropertyOffsetAndSize (Ordinal: 22, Address: 0x128a0)
- TdhGetPropertySize (Ordinal: 23, Address: 0x3ed0)
- TdhGetWppMessage (Ordinal: 24, Address: 0x1ffe0)
- TdhGetWppProperty (Ordinal: 25, Address: 0x20010)
- TdhLoadManifest (Ordinal: 26, Address: 0x13490)
- TdhLoadManifestFromBinary (Ordinal: 27, Address: 0x12950)
- TdhLoadManifestFromMemory (Ordinal: 28, Address: 0x134e0)
- TdhOpenDecodingHandle (Ordinal: 29, Address: 0x200d0)
- TdhQueryProviderFieldInformation (Ordinal: 30, Address: 0xb0e0)
- TdhQueryRemoteWBEMProviderFieldInformation (Ordinal: 31, Address: 0x1f1f0)
- TdhSetDecodingParameter (Ordinal: 32, Address: 0x20180)
- TdhUnloadManifest (Ordinal: 33, Address: 0x13500)
- TdhUnloadManifestFromMemory (Ordinal: 34, Address: 0x13550)
- TdhValidatePayloadFilter (Ordinal: 35, Address: 0x1b0b0)
Imported DLLs & Functions
api-ms-win-core-datetime-l1-1-0.dll
- GetDateFormatW (Address: 0x180055da0)
- GetTimeFormatW (Address: 0x180055da8)
api-ms-win-core-debug-l1-1-0.dll
- IsDebuggerPresent (Address: 0x180055db8)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x180055dc8)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x180055dd8)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x180055e00)
- RaiseException (Address: 0x180055df8)
- SetLastError (Address: 0x180055e08)
- SetUnhandledExceptionFilter (Address: 0x180055de8)
- UnhandledExceptionFilter (Address: 0x180055df0)
api-ms-win-core-file-l1-1-0.dll
- CreateFileW (Address: 0x180055e20)
- FileTimeToLocalFileTime (Address: 0x180055e50)
- FindFirstVolumeW (Address: 0x180055e18)
- FindNextVolumeW (Address: 0x180055e30)
- FindVolumeClose (Address: 0x180055e28)
- GetFileSize (Address: 0x180055e40)
- GetFileTime (Address: 0x180055e38)
- QueryDosDeviceW (Address: 0x180055e48)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x180055e60)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x180055e78)
- HeapAlloc (Address: 0x180055e80)
- HeapFree (Address: 0x180055e70)
api-ms-win-core-heap-l2-1-0.dll
- LocalAlloc (Address: 0x180055e98)
- LocalFree (Address: 0x180055e90)
api-ms-win-core-interlocked-l1-1-0.dll
- InitializeSListHead (Address: 0x180055ec0)
- InterlockedFlushSList (Address: 0x180055eb0)
- InterlockedPopEntrySList (Address: 0x180055ea8)
- InterlockedPushEntrySList (Address: 0x180055eb8)
api-ms-win-core-libraryloader-l1-2-0.dll
- FindResourceExW (Address: 0x180055f18)
- FreeLibrary (Address: 0x180055ed0)
- FreeResource (Address: 0x180055f10)
- GetModuleFileNameW (Address: 0x180055f08)
- GetModuleHandleW (Address: 0x180055ed8)
- GetProcAddress (Address: 0x180055ef0)
- LoadLibraryExW (Address: 0x180055f20)
- LoadResource (Address: 0x180055ef8)
- LoadStringW (Address: 0x180055ee8)
- LockResource (Address: 0x180055f00)
- SizeofResource (Address: 0x180055ee0)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x180055f30)
api-ms-win-core-memory-l1-1-0.dll
- CreateFileMappingW (Address: 0x180055f50)
- MapViewOfFile (Address: 0x180055f48)
- UnmapViewOfFile (Address: 0x180055f40)
api-ms-win-core-processenvironment-l1-1-0.dll
- ExpandEnvironmentStringsW (Address: 0x180055f60)
- GetCurrentDirectoryW (Address: 0x180055f78)
- GetEnvironmentVariableA (Address: 0x180055f68)
- GetEnvironmentVariableW (Address: 0x180055f80)
- SearchPathW (Address: 0x180055f70)
api-ms-win-core-processthreads-l1-1-0.dll
- GetCurrentProcess (Address: 0x180055fa0)
- GetCurrentProcessId (Address: 0x180055f90)
- GetCurrentThreadId (Address: 0x180055f98)
- TerminateProcess (Address: 0x180055fa8)
api-ms-win-core-processthreads-l1-1-1.dll
- IsProcessorFeaturePresent (Address: 0x180055fb8)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x180055fc8)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x180055ff8)
- RegEnumKeyExW (Address: 0x180055fe8)
- RegOpenKeyExW (Address: 0x180055fe0)
- RegQueryInfoKeyW (Address: 0x180055ff0)
- RegQueryValueExW (Address: 0x180055fd8)
api-ms-win-core-string-l1-1-0.dll
- CompareStringOrdinal (Address: 0x180056008)
- MultiByteToWideChar (Address: 0x180056018)
- WideCharToMultiByte (Address: 0x180056010)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x180056090)
- AcquireSRWLockShared (Address: 0x180056080)
- CreateEventW (Address: 0x180056038)
- DeleteCriticalSection (Address: 0x180056078)
- EnterCriticalSection (Address: 0x180056040)
- InitializeCriticalSection (Address: 0x180056028)
- InitializeCriticalSectionAndSpinCount (Address: 0x180056060)
- InitializeCriticalSectionEx (Address: 0x180056068)
- LeaveCriticalSection (Address: 0x180056030)
- ReleaseSRWLockExclusive (Address: 0x180056070)
- ReleaseSRWLockShared (Address: 0x180056088)
- ResetEvent (Address: 0x180056050)
- SetEvent (Address: 0x180056058)
- WaitForSingleObjectEx (Address: 0x180056048)
api-ms-win-core-synch-l1-2-0.dll
- InitOnceExecuteOnce (Address: 0x1800560a0)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemTimeAsFileTime (Address: 0x1800560b0)
api-ms-win-core-timezone-l1-1-0.dll
- FileTimeToSystemTime (Address: 0x1800560c0)
api-ms-win-crt-math-l1-1-0.dll
- ceilf (Address: 0x1800560d0)
api-ms-win-crt-private-l1-1-0.dll
- __C_specific_handler (Address: 0x1800562b8)
- __CxxFrameHandler3 (Address: 0x180056278)
- __CxxFrameHandler4 (Address: 0x1800562c8)
- __std_terminate (Address: 0x1800562c0)
- _CxxThrowException (Address: 0x180056218)
- _o___acrt_iob_func (Address: 0x1800562a0)
- _o___std_exception_copy (Address: 0x180056268)
- _o___std_exception_destroy (Address: 0x180056260)
- _o___std_type_info_destroy_list (Address: 0x180056258)
- _o___stdio_common_vfprintf (Address: 0x180056250)
- _o___stdio_common_vsnwprintf_s (Address: 0x180056248)
- _o___stdio_common_vsprintf (Address: 0x180056240)
- _o___stdio_common_vsprintf_s (Address: 0x180056238)
- _o___stdio_common_vswprintf (Address: 0x180056230)
- _o___stdio_common_vswscanf (Address: 0x180056228)
- _o__callnewh (Address: 0x180056270)
- _o__cexit (Address: 0x180056220)
- _o__configure_narrow_argv (Address: 0x1800560e0)
- _o__crt_atexit (Address: 0x1800560e8)
- _o__errno (Address: 0x1800560f0)
- _o__execute_onexit_table (Address: 0x1800560f8)
- _o__initialize_narrow_environment (Address: 0x180056100)
- _o__initialize_onexit_table (Address: 0x180056108)
- _o__invalid_parameter_noinfo_noreturn (Address: 0x180056110)
- _o__purecall (Address: 0x180056118)
- _o__register_onexit_function (Address: 0x180056120)
- _o__resetstkoflw (Address: 0x180056128)
- _o__seh_filter_dll (Address: 0x180056130)
- _o__splitpath_s (Address: 0x180056138)
- _o__wcsicmp (Address: 0x180056148)
- _o__wcsnicmp (Address: 0x180056150)
- _o__wcstoi64 (Address: 0x180056158)
- _o__wcstoui64 (Address: 0x180056160)
- _o__wfopen (Address: 0x180056168)
- _o__wsplitpath_s (Address: 0x180056170)
- _o__wtoi (Address: 0x180056178)
- _o_fclose (Address: 0x180056180)
- _o_fgets (Address: 0x180056188)
- _o_fgetws (Address: 0x180056190)
- _o_fopen (Address: 0x180056198)
- _o_fputs (Address: 0x1800561a0)
- _o_free (Address: 0x1800561a8)
- _o_isdigit (Address: 0x1800561b0)
- _o_iswspace (Address: 0x1800561b8)
- _o_iswxdigit (Address: 0x1800561c0)
- _o_malloc (Address: 0x1800561c8)
- _o_memcpy_s (Address: 0x1800561d0)
- _o_strcpy_s (Address: 0x1800561d8)
- _o_strncpy_s (Address: 0x1800561e0)
- _o_terminate (Address: 0x1800561e8)
- _o_towlower (Address: 0x1800561f0)
- _o_wcscpy_s (Address: 0x1800561f8)
- _o_wcstok_s (Address: 0x180056200)
- _o_wcstol (Address: 0x180056208)
- _o_wcstoul (Address: 0x180056210)
- memcmp (Address: 0x1800562d0)
- memcpy (Address: 0x1800562d8)
- memmove (Address: 0x180056140)
- strchr (Address: 0x180056290)
- strrchr (Address: 0x180056298)
- strstr (Address: 0x180056288)
- wcschr (Address: 0x1800562b0)
- wcsrchr (Address: 0x180056280)
- wcsstr (Address: 0x1800562a8)
api-ms-win-crt-runtime-l1-1-0.dll
- _initterm (Address: 0x1800562e8)
- _initterm_e (Address: 0x1800562f0)
api-ms-win-crt-string-l1-1-0.dll
- memset (Address: 0x180056308)
- strcmp (Address: 0x180056318)
- strncmp (Address: 0x180056338)
- strnlen (Address: 0x180056300)
- wcscspn (Address: 0x180056330)
- wcsncmp (Address: 0x180056320)
- wcsnlen (Address: 0x180056310)
- wcsspn (Address: 0x180056328)
api-ms-win-eventing-classicprovider-l1-1-0.dll
- GetTraceEnableFlags (Address: 0x180056360)
- GetTraceEnableLevel (Address: 0x180056368)
- GetTraceLoggerHandle (Address: 0x180056358)
- RegisterTraceGuidsW (Address: 0x180056370)
- TraceEvent (Address: 0x180056348)
- TraceMessage (Address: 0x180056350)
- UnregisterTraceGuids (Address: 0x180056378)
api-ms-win-eventing-consumer-l1-1-0.dll
- CloseTrace (Address: 0x180056398)
- OpenTraceW (Address: 0x180056390)
- ProcessTrace (Address: 0x180056388)
api-ms-win-eventing-controller-l1-1-0.dll
- StartTraceW (Address: 0x1800563a8)
- StopTraceW (Address: 0x1800563b0)
api-ms-win-security-base-l1-1-0.dll
- GetLengthSid (Address: 0x1800563c0)
api-ms-win-security-lsalookup-l1-1-0.dll
- LookupAccountSidLocalW (Address: 0x1800563d0)
msvcp_win.dll
- ?_Xlength_error@std@@YAXPEBD@Z (Address: 0x1800563e0)
- ?_Xout_of_range@std@@YAXPEBD@Z (Address: 0x1800563e8)
ntdll.dll
- RtlAcquireSRWLockExclusive (Address: 0x180056408)
- RtlAcquireSRWLockShared (Address: 0x180056410)
- RtlCaptureContext (Address: 0x180056460)
- RtlEthernetAddressToStringW (Address: 0x180056450)
- RtlGUIDFromString (Address: 0x180056420)
- RtlInitializeSRWLock (Address: 0x1800563f8)
- RtlIpv4AddressToStringExW (Address: 0x180056448)
- RtlIpv6AddressToStringExW (Address: 0x180056468)
- RtlIpv6AddressToStringW (Address: 0x180056458)
- RtlLengthRequiredSid (Address: 0x180056430)
- RtlLookupFunctionEntry (Address: 0x180056438)
- RtlReleaseSRWLockExclusive (Address: 0x180056400)
- RtlReleaseSRWLockShared (Address: 0x180056418)
- RtlSubAuthorityCountSid (Address: 0x180056428)
- RtlVirtualUnwind (Address: 0x180056440)
SECHOST.dll
- EtwQueryRealtimeConsumer (Address: 0x180055d90)