bdesvc.dll

Description: BDE Service

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.5915

Architecture: 64-bit

Operating System: Windows NT

SHA256: e51904068fd0a59d3be98ac9c07fe1e1

File Size: 545.0 KB

Uploaded At: Dec. 1, 2025, 7:23 a.m.

Views: 22

Exported Functions

  • ServiceMain (Ordinal: 1, Address: 0x9f90)
  • SvchostPushServiceGlobals (Ordinal: 2, Address: 0xf480)

Imported DLLs & Functions

api-ms-win-core-com-l1-1-0.dll
  • CLSIDFromString (Address: 0x18006ccf8)
  • CoCreateGuid (Address: 0x18006ccf0)
  • CoCreateInstance (Address: 0x18006cce8)
  • CoInitializeEx (Address: 0x18006cd00)
  • CoTaskMemAlloc (Address: 0x18006ccd8)
  • CoTaskMemFree (Address: 0x18006ccd0)
  • CoUninitialize (Address: 0x18006ccc8)
  • CoWaitForMultipleHandles (Address: 0x18006cce0)
  • StringFromGUID2 (Address: 0x18006ccc0)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x18006cd20)
  • IsDebuggerPresent (Address: 0x18006cd10)
  • OutputDebugStringW (Address: 0x18006cd18)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x18006cd30)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x18006cd40)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x18006cd50)
  • RaiseException (Address: 0x18006cd60)
  • SetLastError (Address: 0x18006cd70)
  • SetUnhandledExceptionFilter (Address: 0x18006cd58)
  • UnhandledExceptionFilter (Address: 0x18006cd68)
api-ms-win-core-file-l1-1-0.dll
  • CreateDirectoryW (Address: 0x18006cda0)
  • CreateFileW (Address: 0x18006cdc0)
  • DeleteFileW (Address: 0x18006cdb0)
  • FindClose (Address: 0x18006cd90)
  • FindFirstFileW (Address: 0x18006cd80)
  • FindNextFileW (Address: 0x18006cd88)
  • FlushFileBuffers (Address: 0x18006cdd0)
  • GetFileAttributesW (Address: 0x18006cd98)
  • GetVolumeInformationW (Address: 0x18006cdb8)
  • GetVolumePathNameW (Address: 0x18006cde0)
  • ReadFile (Address: 0x18006cdd8)
  • RemoveDirectoryW (Address: 0x18006cda8)
  • WriteFile (Address: 0x18006cdc8)
api-ms-win-core-file-l1-2-0.dll
  • GetVolumePathNamesForVolumeNameW (Address: 0x18006cdf0)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x18006ce00)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x18006ce20)
  • HeapAlloc (Address: 0x18006ce30)
  • HeapFree (Address: 0x18006ce18)
  • HeapReAlloc (Address: 0x18006ce28)
  • HeapSize (Address: 0x18006ce10)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x18006ce40)
  • LocalFree (Address: 0x18006ce48)
api-ms-win-core-io-l1-1-0.dll
  • DeviceIoControl (Address: 0x18006ce58)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x18006ce68)
  • FreeLibrary (Address: 0x18006ce70)
  • GetModuleFileNameA (Address: 0x18006ce78)
  • GetModuleFileNameW (Address: 0x18006ce80)
  • GetModuleHandleExW (Address: 0x18006cea0)
  • GetModuleHandleW (Address: 0x18006ce88)
  • GetProcAddress (Address: 0x18006ce98)
  • LoadLibraryExW (Address: 0x18006ce90)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x18006ceb0)
api-ms-win-core-processthreads-l1-1-0.dll
  • CreateProcessAsUserW (Address: 0x18006cef8)
  • GetCurrentProcess (Address: 0x18006ced0)
  • GetCurrentProcessId (Address: 0x18006cef0)
  • GetCurrentThread (Address: 0x18006cf08)
  • GetCurrentThreadId (Address: 0x18006cf10)
  • GetExitCodeProcess (Address: 0x18006cee0)
  • OpenProcessToken (Address: 0x18006cec0)
  • OpenThreadToken (Address: 0x18006cf00)
  • ResumeThread (Address: 0x18006ced8)
  • SetThreadPriority (Address: 0x18006cee8)
  • SetThreadToken (Address: 0x18006cf18)
  • TerminateProcess (Address: 0x18006cec8)
api-ms-win-core-processthreads-l1-1-1.dll
  • GetProcessMitigationPolicy (Address: 0x18006cf28)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x18006cf38)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x18006cf68)
  • RegCreateKeyExW (Address: 0x18006cf58)
  • RegDeleteKeyExW (Address: 0x18006cf80)
  • RegDeleteTreeW (Address: 0x18006cf48)
  • RegEnumKeyExW (Address: 0x18006cf98)
  • RegEnumValueW (Address: 0x18006cfb0)
  • RegGetValueA (Address: 0x18006cf88)
  • RegGetValueW (Address: 0x18006cf70)
  • RegLoadKeyW (Address: 0x18006cf78)
  • RegOpenCurrentUser (Address: 0x18006cfa8)
  • RegOpenKeyExW (Address: 0x18006cfa0)
  • RegQueryInfoKeyW (Address: 0x18006cf50)
  • RegSetValueExW (Address: 0x18006cf90)
  • RegUnLoadKeyW (Address: 0x18006cf60)
api-ms-win-core-registry-l1-1-1.dll
  • RegDeleteKeyValueW (Address: 0x18006cfc0)
  • RegSetKeyValueW (Address: 0x18006cfc8)
api-ms-win-core-string-l1-1-0.dll
  • CompareStringOrdinal (Address: 0x18006cfd8)
  • MultiByteToWideChar (Address: 0x18006cfe0)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x18006d010)
  • AcquireSRWLockShared (Address: 0x18006d060)
  • CreateEventW (Address: 0x18006d020)
  • CreateMutexExW (Address: 0x18006d050)
  • CreateSemaphoreExW (Address: 0x18006d068)
  • DeleteCriticalSection (Address: 0x18006d070)
  • EnterCriticalSection (Address: 0x18006d080)
  • InitializeCriticalSection (Address: 0x18006d000)
  • InitializeCriticalSectionEx (Address: 0x18006d038)
  • InitializeSRWLock (Address: 0x18006d090)
  • LeaveCriticalSection (Address: 0x18006d078)
  • OpenSemaphoreW (Address: 0x18006cff0)
  • ReleaseMutex (Address: 0x18006d018)
  • ReleaseSemaphore (Address: 0x18006d088)
  • ReleaseSRWLockExclusive (Address: 0x18006cff8)
  • ReleaseSRWLockShared (Address: 0x18006d030)
  • ResetEvent (Address: 0x18006d048)
  • SetEvent (Address: 0x18006d040)
  • WaitForMultipleObjectsEx (Address: 0x18006d058)
  • WaitForSingleObject (Address: 0x18006d028)
  • WaitForSingleObjectEx (Address: 0x18006d008)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceExecuteOnce (Address: 0x18006d0a8)
  • Sleep (Address: 0x18006d0a0)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTime (Address: 0x18006d0d0)
  • GetSystemTimeAsFileTime (Address: 0x18006d0c0)
  • GetSystemWindowsDirectoryW (Address: 0x18006d0b8)
  • GetTickCount (Address: 0x18006d0c8)
  • GetTickCount64 (Address: 0x18006d0d8)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolCleanupGroup (Address: 0x18006d120)
  • CloseThreadpoolCleanupGroupMembers (Address: 0x18006d100)
  • CloseThreadpoolTimer (Address: 0x18006d118)
  • CreateThreadpoolCleanupGroup (Address: 0x18006d110)
  • CreateThreadpoolTimer (Address: 0x18006d108)
  • SetEventWhenCallbackReturns (Address: 0x18006d0e8)
  • SetThreadpoolTimer (Address: 0x18006d0f8)
  • TrySubmitThreadpoolCallback (Address: 0x18006d128)
  • WaitForThreadpoolTimerCallbacks (Address: 0x18006d0f0)
api-ms-win-core-threadpool-legacy-l1-1-0.dll
  • CreateTimerQueueTimer (Address: 0x18006d148)
  • DeleteTimerQueueTimer (Address: 0x18006d138)
  • UnregisterWaitEx (Address: 0x18006d140)
api-ms-win-core-timezone-l1-1-0.dll
  • FileTimeToSystemTime (Address: 0x18006d158)
  • GetTimeZoneInformation (Address: 0x18006d160)
  • SystemTimeToFileTime (Address: 0x18006d168)
  • SystemTimeToTzSpecificLocalTime (Address: 0x18006d170)
api-ms-win-core-winrt-l1-1-0.dll
  • RoGetActivationFactory (Address: 0x18006d180)
api-ms-win-core-winrt-string-l1-1-0.dll
  • WindowsCreateStringReference (Address: 0x18006d190)
api-ms-win-devices-config-l1-1-1.dll
  • CM_Register_Notification (Address: 0x18006d1a8)
  • CM_Unregister_Notification (Address: 0x18006d1a0)
api-ms-win-eventing-classicprovider-l1-1-0.dll
  • GetTraceEnableFlags (Address: 0x18006d1c0)
  • GetTraceEnableLevel (Address: 0x18006d1e0)
  • GetTraceLoggerHandle (Address: 0x18006d1d8)
  • RegisterTraceGuidsW (Address: 0x18006d1b8)
  • TraceMessage (Address: 0x18006d1d0)
  • UnregisterTraceGuids (Address: 0x18006d1c8)
api-ms-win-eventing-consumer-l1-1-0.dll
  • CloseTrace (Address: 0x18006d1f0)
  • OpenTraceW (Address: 0x18006d1f8)
  • ProcessTrace (Address: 0x18006d200)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventActivityIdControl (Address: 0x18006d228)
  • EventProviderEnabled (Address: 0x18006d210)
  • EventRegister (Address: 0x18006d238)
  • EventSetInformation (Address: 0x18006d218)
  • EventUnregister (Address: 0x18006d240)
  • EventWrite (Address: 0x18006d220)
  • EventWriteTransfer (Address: 0x18006d230)
api-ms-win-security-base-l1-1-0.dll
  • AdjustTokenPrivileges (Address: 0x18006d278)
  • AllocateAndInitializeSid (Address: 0x18006d288)
  • CheckTokenMembership (Address: 0x18006d280)
  • CreateRestrictedToken (Address: 0x18006d290)
  • CreateWellKnownSid (Address: 0x18006d2a0)
  • DuplicateTokenEx (Address: 0x18006d268)
  • FreeSid (Address: 0x18006d2a8)
  • GetSidSubAuthority (Address: 0x18006d258)
  • GetSidSubAuthorityCount (Address: 0x18006d250)
  • GetTokenInformation (Address: 0x18006d298)
  • ImpersonateLoggedOnUser (Address: 0x18006d270)
  • RevertToSelf (Address: 0x18006d260)
api-ms-win-security-grouppolicy-l1-1-0.dll
  • RegisterGPNotificationInternal (Address: 0x18006d2c0)
  • UnregisterGPNotificationInternal (Address: 0x18006d2b8)
api-ms-win-security-lsalookup-l1-1-1.dll
  • EnumerateIdentityProviders (Address: 0x18006d2e0)
  • GetDefaultIdentityProvider (Address: 0x18006d2d0)
  • GetIdentityProviderInfoByGUID (Address: 0x18006d2e8)
  • ReleaseIdentityProviderEnumContext (Address: 0x18006d2d8)
api-ms-win-security-lsapolicy-l1-1-0.dll
  • LsaClose (Address: 0x18006d2f8)
  • LsaFreeMemory (Address: 0x18006d308)
  • LsaOpenPolicy (Address: 0x18006d310)
  • LsaQueryInformationPolicy (Address: 0x18006d300)
api-ms-win-service-core-l1-1-0.dll
  • RegisterServiceCtrlHandlerExW (Address: 0x18006d320)
  • SetServiceStatus (Address: 0x18006d328)
bcd.dll
  • BcdCloseObject (Address: 0x18006d348)
  • BcdCloseStore (Address: 0x18006d350)
  • BcdDeleteElement (Address: 0x18006d370)
  • BcdEnumerateAndUnpackElements (Address: 0x18006d338)
  • BcdEnumerateObjects (Address: 0x18006d360)
  • BcdGetElementData (Address: 0x18006d358)
  • BcdOpenObject (Address: 0x18006d340)
  • BcdOpenSystemStore (Address: 0x18006d368)
  • BcdSetElementData (Address: 0x18006d378)
bcrypt.dll
  • BCryptCloseAlgorithmProvider (Address: 0x18006d390)
  • BCryptCreateHash (Address: 0x18006d398)
  • BCryptDestroyHash (Address: 0x18006d3b0)
  • BCryptFinishHash (Address: 0x18006d3a8)
  • BCryptHashData (Address: 0x18006d3a0)
  • BCryptOpenAlgorithmProvider (Address: 0x18006d388)
FVEAPI.dll
  • FveAddAuthMethodInformation (Address: 0x18006cb90)
  • FveApplyGroupPolicy (Address: 0x18006cc10)
  • FveApplyNkpCertChanges (Address: 0x18006cc08)
  • FveAttemptAutoUnlock (Address: 0x18006cbe0)
  • FveAuthElementFromPassPhraseW (Address: 0x18006cbd0)
  • FveBackupRecoveryInformationToADEx (Address: 0x18006cb48)
  • FveBindDataVolume (Address: 0x18006cb38)
  • FveCheckADRecoveryInfoBackupPolicyEx (Address: 0x18006cbc0)
  • FveCheckTpmCapability (Address: 0x18006cb30)
  • FveCloseHandle (Address: 0x18006cb28)
  • FveCloseVolume (Address: 0x18006ca60)
  • FveCommitChanges (Address: 0x18006ca70)
  • FveCommitChangesEx (Address: 0x18006cbc8)
  • FveConversionEncryptEx (Address: 0x18006cc00)
  • FveConversionEncryptPendingRebootEx (Address: 0x18006cbf8)
  • FveDecrementClearKeyCounter (Address: 0x18006ca78)
  • FveDeleteAuthMethod (Address: 0x18006cb98)
  • FveFindFirstVolume (Address: 0x18006ca88)
  • FveFindNextVolume (Address: 0x18006ca90)
  • FveGenerateNkpSessionKeys (Address: 0x18006cad8)
  • FveGetAuthMethodGuids (Address: 0x18006cb50)
  • FveGetAuthMethodInformation (Address: 0x18006cbd8)
  • FveGetAuthMethodSid (Address: 0x18006cb08)
  • FveGetAuthMethodSidInformation (Address: 0x18006cbe8)
  • FveGetClearKeyCounter (Address: 0x18006ca80)
  • FveGetDataSet (Address: 0x18006cbb8)
  • FveGetFveMethod (Address: 0x18006cab0)
  • FveGetIdentity (Address: 0x18006ca58)
  • FveGetSecureBootBindingState (Address: 0x18006cbb0)
  • FveGetStatus (Address: 0x18006caa8)
  • FveGetStatusW (Address: 0x18006caf8)
  • FveGetVolumeNameW (Address: 0x18006cc18)
  • FveInitializeDeviceEncryption2 (Address: 0x18006caf0)
  • FveInitVolumeEx (Address: 0x18006cb40)
  • FveIsAnyDataVolumeBoundToOSVolume (Address: 0x18006cb18)
  • FveIsBoundDataVolume (Address: 0x18006cb58)
  • FveIsBoundDataVolumeToOSVolume (Address: 0x18006cb10)
  • FveIsDeviceLockedOut (Address: 0x18006cba8)
  • FveIsHardwareReadyForConversion (Address: 0x18006cb60)
  • FveIsHybridVolumeW (Address: 0x18006ca68)
  • FveIsSchemaExtInstalled (Address: 0x18006cb70)
  • FveIsVolumeEncryptable (Address: 0x18006cad0)
  • FveKeyManagement (Address: 0x18006cb20)
  • FveOpenVolumeByHandle (Address: 0x18006caa0)
  • FveOpenVolumeW (Address: 0x18006cb00)
  • FveRegenerateNbpSessionKey (Address: 0x18006cae0)
  • FveRevertVolume (Address: 0x18006cb68)
  • FveSelectBestRecoveryPasswordByBackupInformation (Address: 0x18006cba0)
  • FveSetAllowKeyExport (Address: 0x18006cbf0)
  • FveSysClearUserFlags (Address: 0x18006cac0)
  • FveSysCloseVolume (Address: 0x18006ca98)
  • FveSysGetUserFlags (Address: 0x18006cab8)
  • FveSysSetUserFlags (Address: 0x18006cac8)
  • FveUnlockVolumeAuthMethodSid (Address: 0x18006ca50)
  • FveUpdateBandIdBcd (Address: 0x18006cae8)
  • FveUpdatePinW (Address: 0x18006cb80)
  • FveValidateExistingPassphraseW (Address: 0x18006cb78)
  • FveValidateExistingPinW (Address: 0x18006cb88)
FVECERTS.dll
  • FveCertIsValidCertInfo (Address: 0x18006cc28)
msvcrt.dll
  • __C_specific_handler (Address: 0x18006d4b0)
  • __CxxFrameHandler3 (Address: 0x18006d500)
  • __dllonexit (Address: 0x18006d4c8)
  • __RTDynamicCast (Address: 0x18006d4f8)
  • _amsg_exit (Address: 0x18006d498)
  • _beginthreadex (Address: 0x18006d3f0)
  • _callnewh (Address: 0x18006d458)
  • _CxxThrowException (Address: 0x18006d478)
  • _initterm (Address: 0x18006d4a0)
  • _lock (Address: 0x18006d4b8)
  • _onexit (Address: 0x18006d4d0)
  • _purecall (Address: 0x18006d440)
  • _stricmp (Address: 0x18006d460)
  • _unlock (Address: 0x18006d4c0)
  • _vsnprintf_s (Address: 0x18006d420)
  • _vsnwprintf (Address: 0x18006d4a8)
  • _wcsicmp (Address: 0x18006d400)
  • _XcptFilter (Address: 0x18006d490)
  • ??_V@YAXPEAX@Z (Address: 0x18006d3f8)
  • ??0exception@@QEAA@AEBQEBD@Z (Address: 0x18006d410)
  • ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x18006d3d8)
  • ??0exception@@QEAA@AEBV0@@Z (Address: 0x18006d428)
  • ??0exception@@QEAA@XZ (Address: 0x18006d430)
  • ??1exception@@UEAA@XZ (Address: 0x18006d438)
  • ??1type_info@@UEAA@XZ (Address: 0x18006d4e0)
  • ??3@YAXPEAX@Z (Address: 0x18006d448)
  • ?terminate@@YAXXZ (Address: 0x18006d4d8)
  • ?what@exception@@UEBAPEBDXZ (Address: 0x18006d508)
  • free (Address: 0x18006d3d0)
  • iswascii (Address: 0x18006d468)
  • malloc (Address: 0x18006d3e8)
  • memcmp (Address: 0x18006d4f0)
  • memcpy (Address: 0x18006d480)
  • memcpy_s (Address: 0x18006d450)
  • memmove (Address: 0x18006d488)
  • memmove_s (Address: 0x18006d408)
  • memset (Address: 0x18006d4e8)
  • swprintf_s (Address: 0x18006d3c8)
  • toupper (Address: 0x18006d470)
  • wcschr (Address: 0x18006d418)
  • wcscmp (Address: 0x18006d510)
  • wcstok (Address: 0x18006d3c0)
  • wcstoul (Address: 0x18006d3e0)
ntdll.dll
  • NtClose (Address: 0x18006d580)
  • NtOpenFile (Address: 0x18006d560)
  • NtPowerInformation (Address: 0x18006d520)
  • NtQueryInformationFile (Address: 0x18006d588)
  • NtQuerySystemInformation (Address: 0x18006d5d8)
  • NtQueryWnfStateData (Address: 0x18006d598)
  • NtSetInformationThread (Address: 0x18006d5b8)
  • RtlCaptureContext (Address: 0x18006d5d0)
  • RtlCheckPortableOperatingSystem (Address: 0x18006d538)
  • RtlCompareMemory (Address: 0x18006d570)
  • RtlCreateSystemVolumeInformationFolder (Address: 0x18006d548)
  • RtlDosPathNameToNtPathName_U_WithStatus (Address: 0x18006d568)
  • RtlFreeUnicodeString (Address: 0x18006d540)
  • RtlInitUnicodeString (Address: 0x18006d578)
  • RtlLookupFunctionEntry (Address: 0x18006d5c8)
  • RtlNtStatusToDosError (Address: 0x18006d5b0)
  • RtlPublishWnfStateData (Address: 0x18006d550)
  • RtlQueryWnfStateData (Address: 0x18006d5f8)
  • RtlSetThreadErrorMode (Address: 0x18006d5e0)
  • RtlStringFromGUID (Address: 0x18006d558)
  • RtlSubscribeWnfStateChangeNotification (Address: 0x18006d5f0)
  • RtlUnsubscribeWnfNotificationWaitForCompletion (Address: 0x18006d5e8)
  • RtlVerifyVersionInfo (Address: 0x18006d528)
  • RtlVirtualUnwind (Address: 0x18006d5c0)
  • VerSetConditionMask (Address: 0x18006d530)
  • WinSqmAddToStreamEx (Address: 0x18006d590)
  • WinSqmIsOptedIn (Address: 0x18006d5a0)
  • WinSqmSetDWORD (Address: 0x18006d5a8)
RPCRT4.dll
  • NdrServerCall2 (Address: 0x18006cc58)
  • NdrServerCallAll (Address: 0x18006cc40)
  • RpcBindingVectorFree (Address: 0x18006cc68)
  • RpcEpRegisterW (Address: 0x18006cc98)
  • RpcEpUnregister (Address: 0x18006cc70)
  • RpcImpersonateClient (Address: 0x18006cc48)
  • RpcRevertToSelf (Address: 0x18006cc50)
  • RpcServerInqBindings (Address: 0x18006cca0)
  • RpcServerListen (Address: 0x18006cc60)
  • RpcServerRegisterAuthInfoW (Address: 0x18006cca8)
  • RpcServerRegisterIfEx (Address: 0x18006cc78)
  • RpcServerUnregisterIfEx (Address: 0x18006cc80)
  • RpcServerUseProtseqW (Address: 0x18006ccb0)
  • RpcStringFreeW (Address: 0x18006cc90)
  • UuidFromStringW (Address: 0x18006cc38)
  • UuidToStringW (Address: 0x18006cc88)
wevtapi.dll
  • EvtClose (Address: 0x18006d628)
  • EvtCreateRenderContext (Address: 0x18006d608)
  • EvtNext (Address: 0x18006d618)
  • EvtQuery (Address: 0x18006d620)
  • EvtRender (Address: 0x18006d610)