bdeui.dll

Description: Windows BitLocker Drive Encryption User Interface

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.6328

Architecture: 64-bit

Operating System: Windows NT

SHA256: 579869c4b2b53c909b8986cfd12c2aff

File Size: 35.0 KB

Uploaded At: Dec. 1, 2025, 7:23 a.m.

Views: 15

Exported Functions

  • ??0BuiVolume@@QEAA@XZ (Ordinal: 1, Address: 0x1940)
  • ??0BuiVolume@@QEAA@_N@Z (Ordinal: 2, Address: 0x19a0)
  • ??0VolumeFveStatus@@IEAA@XZ (Ordinal: 3, Address: 0x12e0)
  • ??0VolumeFveStatus@@QEAA@K_KJW4_FVE_WIPING_STATE@@@Z (Ordinal: 4, Address: 0x1010)
  • ??1BuiVolume@@QEAA@XZ (Ordinal: 5, Address: 0x1a70)
  • ??4BuiVolume@@QEAAAEAV0@AEBV0@@Z (Ordinal: 6, Address: 0x1340)
  • ??4VolumeFveStatus@@QEAAAEAV0@$$QEAV0@@Z (Ordinal: 7, Address: 0x1310)
  • ??4VolumeFveStatus@@QEAAAEAV0@AEBV0@@Z (Ordinal: 8, Address: 0x12f0)
  • ?AddSmartCard@BuiVolume@@QEAAJPEAUHWND__@@@Z (Ordinal: 9, Address: 0x2a10)
  • ?AllowForegroundWindowDisplay@BuiVolume@@AEAAJXZ (Ordinal: 10, Address: 0x2480)
  • ?AttemptAutoUnlock@BuiVolume@@QEAAJXZ (Ordinal: 11, Address: 0x2760)
  • ?BasicDispatch@BuiVolume@@AEAAJJPEAUHWND__@@PEBGPEAJ@Z (Ordinal: 12, Address: 0x32e0)
  • ?BasicDispatch@BuiVolume@@AEAAJJPEBG0PEAHPEAJ@Z (Ordinal: 13, Address: 0x2f00)
  • ?BasicDispatch@BuiVolume@@AEAAJJPEBG0PEAJ@Z (Ordinal: 14, Address: 0x2dd0)
  • ?BasicDispatch@BuiVolume@@AEAAJJPEBG0PEAK@Z (Ordinal: 15, Address: 0x33b0)
  • ?BasicDispatch@BuiVolume@@AEAAJJPEBGPEAHPEAJ@Z (Ordinal: 16, Address: 0x2cd0)
  • ?BasicDispatch@BuiVolume@@AEAAJJPEBGPEAJ@Z (Ordinal: 17, Address: 0x2c20)
  • ?BasicDispatch@BuiVolume@@AEAAJJPEBGPEAPEAG@Z (Ordinal: 18, Address: 0x3080)
  • ?BasicDispatch@BuiVolume@@AEAAJJPEBGPEAUtagVARIANT@@@Z (Ordinal: 19, Address: 0x3220)
  • ?CanBeResumed@BuiVolume@@QEBA_NXZ (Ordinal: 20, Address: 0x43d0)
  • ?CanRefreshStatus@BuiVolume@@AEBA_NXZ (Ordinal: 21, Address: 0x1f20)
  • ?ClearProxyObject@BuiVolume@@QEAAXXZ (Ordinal: 22, Address: 0x2530)
  • ?Decrypt@BuiVolume@@QEAAJPEAUHWND__@@@Z (Ordinal: 23, Address: 0x2950)
  • ?DeleteVolumeList@BuiVolume@@SAXPEAPEAU_BuiVolumeNode@@@Z (Ordinal: 24, Address: 0x4190)
  • ?Disable@BuiVolume@@QEAAJPEAUHWND__@@@Z (Ordinal: 25, Address: 0x2960)
  • ?DisableAutoUnlock@BuiVolume@@QEAAJXZ (Ordinal: 26, Address: 0x2730)
  • ?Dispatch@BuiVolume@@AEAAJJPEAUtagDISPPARAMS@@PEAJ@Z (Ordinal: 27, Address: 0x2ba0)
  • ?Dispatch@BuiVolume@@AEAAJJPEAUtagDISPPARAMS@@PEAUtagVARIANT@@@Z (Ordinal: 28, Address: 0x2b30)
  • ?EnableAutoUnlock@BuiVolume@@QEAAJXZ (Ordinal: 29, Address: 0x2700)
  • ?FailedDryRun@VolumeFveStatus@@QEBA_NXZ (Ordinal: 30, Address: 0x1230)
  • ?FindMountPoint@BuiVolume@@AEAAJXZ (Ordinal: 31, Address: 0x2210)
  • ?FormatNameAndMountPoint@BuiVolume@@AEAAJXZ (Ordinal: 32, Address: 0x2070)
  • ?GetAllVolumes@BuiVolume@@SAJPEAPEAU_BuiVolumeNode@@@Z (Ordinal: 33, Address: 0x3e70)
  • ?GetConvertedPercent@BuiVolume@@QEBANXZ (Ordinal: 34, Address: 0x4460)
  • ?GetDescription@BuiVolume@@QEAAJPEAPEAG@Z (Ordinal: 35, Address: 0x28e0)
  • ?GetExtendedFlags@VolumeFveStatus@@QEBA_KXZ (Ordinal: 36, Address: 0x12c0)
  • ?GetLastConvertStatus@VolumeFveStatus@@QEBAJXZ (Ordinal: 37, Address: 0x12d0)
  • ?GetOsVolume@BuiVolume@@SAJPEAPEAV1@@Z (Ordinal: 38, Address: 0x4200)
  • ?GetPasswordBackupTypes@BuiVolume@@QEAAJPEBGPEAK@Z (Ordinal: 39, Address: 0x2920)
  • ?GetPasswordId@BuiVolume@@QEAAJPEAPEAG@Z (Ordinal: 40, Address: 0x2900)
  • ?GetStatusFlags@VolumeFveStatus@@QEBAKXZ (Ordinal: 41, Address: 0x12b0)
  • ?GetWipeCount@BuiVolume@@QEBAKXZ (Ordinal: 42, Address: 0x4480)
  • ?GetWipedPercent@BuiVolume@@QEBANXZ (Ordinal: 43, Address: 0x4470)
  • ?HasAutoUnlockVolumesBound@BuiVolume@@QEAA_NXZ (Ordinal: 44, Address: 0x2640)
  • ?HasExternalKey@VolumeFveStatus@@QEBA_NXZ (Ordinal: 45, Address: 0x1080)
  • ?HasPBKDF2RecoveryPassword@VolumeFveStatus@@QEBA_NXZ (Ordinal: 46, Address: 0x1070)
  • ?HasPassphraseProtector@VolumeFveStatus@@QEBA_NXZ (Ordinal: 47, Address: 0x10a0)
  • ?HasPinProtector@VolumeFveStatus@@QEBA_NXZ (Ordinal: 48, Address: 0x1050)
  • ?HasRecoveryData@VolumeFveStatus@@QEBA_NXZ (Ordinal: 49, Address: 0x1210)
  • ?HasRecoveryPassword@VolumeFveStatus@@QEBA_NXZ (Ordinal: 50, Address: 0x1060)
  • ?HasSmartCardProtector@VolumeFveStatus@@QEBA_NXZ (Ordinal: 51, Address: 0x10b0)
  • ?HasStartupKeyProtector@VolumeFveStatus@@QEBA_NXZ (Ordinal: 52, Address: 0x1090)
  • ?HasTpmProtector@VolumeFveStatus@@QEBA_NXZ (Ordinal: 53, Address: 0x1040)
  • ?ImplicitPauseConversion@BuiVolume@@QEAAJXZ (Ordinal: 54, Address: 0x26a0)
  • ?Init@BuiVolume@@QEAAJPEAG@Z (Ordinal: 55, Address: 0x1ab0)
  • ?InitMembers@BuiVolume@@AEAAXXZ (Ordinal: 56, Address: 0x1a10)
  • ?IsAutoUnlockEnabled@BuiVolume@@QEAA_NXZ (Ordinal: 57, Address: 0x2570)
  • ?IsConverting@VolumeFveStatus@@QEBA_NXZ (Ordinal: 58, Address: 0x1130)
  • ?IsCsvMetadataVolume@VolumeFveStatus@@QEBA_NXZ (Ordinal: 59, Address: 0x1270)
  • ?IsCurrentPINEnhanced@BuiVolume@@QEAAJPEAH@Z (Ordinal: 60, Address: 0x1f40)
  • ?IsDEAutoProvisioned@VolumeFveStatus@@QEBA_NXZ (Ordinal: 61, Address: 0x12a0)
  • ?IsDecrypted@VolumeFveStatus@@QEBA_NXZ (Ordinal: 62, Address: 0x1190)
  • ?IsDecrypting@VolumeFveStatus@@QEBA_NXZ (Ordinal: 63, Address: 0x1180)
  • ?IsDisabled@VolumeFveStatus@@QEBA_NXZ (Ordinal: 64, Address: 0x11e0)
  • ?IsEDriveVolume@VolumeFveStatus@@QEBA_NXZ (Ordinal: 65, Address: 0x1260)
  • ?IsEncrypted@VolumeFveStatus@@QEBA_NXZ (Ordinal: 66, Address: 0x1170)
  • ?IsEncrypting@VolumeFveStatus@@QEBA_NXZ (Ordinal: 67, Address: 0x1160)
  • ?IsFveNotifyNecessary@BuiVolume@@QEBA_NXZ (Ordinal: 68, Address: 0x4340)
  • ?IsLocked@VolumeFveStatus@@QEBA_NXZ (Ordinal: 69, Address: 0x1200)
  • ?IsOn@VolumeFveStatus@@QEBA_NXZ (Ordinal: 70, Address: 0x1100)
  • ?IsOsCriticalVolume@VolumeFveStatus@@QEBA_NXZ (Ordinal: 71, Address: 0x10d0)
  • ?IsOsVolume@VolumeFveStatus@@QEBA_NXZ (Ordinal: 72, Address: 0x10c0)
  • ?IsPartiallyConverted@VolumeFveStatus@@QEBA_NXZ (Ordinal: 73, Address: 0x1150)
  • ?IsPaused@VolumeFveStatus@@QEBA_NXZ (Ordinal: 74, Address: 0x1110)
  • ?IsPreProvisioned@VolumeFveStatus@@QEBA_NXZ (Ordinal: 75, Address: 0x1220)
  • ?IsRoamingDevice@VolumeFveStatus@@QEBA_NXZ (Ordinal: 76, Address: 0x10f0)
  • ?IsSecure@VolumeFveStatus@@QEBA_NXZ (Ordinal: 77, Address: 0x11c0)
  • ?IsUnknownFveVersion@VolumeFveStatus@@QEBA_NXZ (Ordinal: 78, Address: 0x1280)
  • ?IsWiping@VolumeFveStatus@@QEBA_NXZ (Ordinal: 79, Address: 0x11a0)
  • ?LaunchUpdate@BuiVolume@@QEAAJXZ (Ordinal: 80, Address: 0x29a0)
  • ?LaunchWizard@BuiVolume@@QEAAJG@Z (Ordinal: 81, Address: 0x2990)
  • ?ManagementRequiresElevation@BuiVolume@@QEBA_NXZ (Ordinal: 82, Address: 0x4400)
  • ?NO_DRIVE_LETTER@BuiVolume@@2IB (Ordinal: 83, Address: 0x66c0)
  • ?NeedsDiscoveryVolumeUpdate@BuiVolume@@QEAAJPEAH@Z (Ordinal: 84, Address: 0x29c0)
  • ?NeedsRestart@VolumeFveStatus@@QEBA_NXZ (Ordinal: 85, Address: 0x11d0)
  • ?PauseConversion@BuiVolume@@QEAAJXZ (Ordinal: 86, Address: 0x2670)
  • ?ProxyAddSmartCard@BuiVolume@@AEAAJPEAUHWND__@@@Z (Ordinal: 87, Address: 0x3ba0)
  • ?ProxyAreVolumesBound@BuiVolume@@AEAAJXZ (Ordinal: 88, Address: 0x3930)
  • ?ProxyAttemptAutoUnlock@BuiVolume@@AEAAJXZ (Ordinal: 89, Address: 0x38b0)
  • ?ProxyDecrypt@BuiVolume@@AEAAJPEAUHWND__@@@Z (Ordinal: 90, Address: 0x3970)
  • ?ProxyDisable@BuiVolume@@AEAAJPEAUHWND__@@@Z (Ordinal: 91, Address: 0x39b0)
  • ?ProxyDisableAutoUnlock@BuiVolume@@AEAAJXZ (Ordinal: 92, Address: 0x3870)
  • ?ProxyEnableAutoUnlock@BuiVolume@@AEAAJXZ (Ordinal: 93, Address: 0x3830)
  • ?ProxyGetDescription@BuiVolume@@AEAAJPEAPEAG@Z (Ordinal: 94, Address: 0x28e0)
  • ?ProxyGetPasswordBackupTypes@BuiVolume@@AEAAJPEBGPEAK@Z (Ordinal: 95, Address: 0x2920)
  • ?ProxyGetPasswordId@BuiVolume@@AEAAJPEAPEAG@Z (Ordinal: 96, Address: 0x2900)
  • ?ProxyGetProcessId@BuiVolume@@AEAAJPEAK@Z (Ordinal: 97, Address: 0x3500)
  • ?ProxyImplicitPauseConversion@BuiVolume@@AEAAJXZ (Ordinal: 98, Address: 0x35d0)
  • ?ProxyIsAutoUnlockEnabled@BuiVolume@@AEAAJXZ (Ordinal: 99, Address: 0x38f0)
  • ?ProxyLaunchUpdate@BuiVolume@@AEAAJXZ (Ordinal: 100, Address: 0x3aa0)
  • ?ProxyLaunchWizard@BuiVolume@@AEAAJG@Z (Ordinal: 101, Address: 0x39f0)
  • ?ProxyNeedsDiscoveryVolumeUpdate@BuiVolume@@AEAAJPEAH@Z (Ordinal: 102, Address: 0x3b20)
  • ?ProxyPauseConversion@BuiVolume@@AEAAJXZ (Ordinal: 103, Address: 0x3590)
  • ?ProxyRemovePassphrase@BuiVolume@@AEAAJXZ (Ordinal: 104, Address: 0x3b60)
  • ?ProxyRemoveSmartCard@BuiVolume@@AEAAJ_N@Z (Ordinal: 105, Address: 0x3c70)
  • ?ProxyResumeConversion@BuiVolume@@AEAAJXZ (Ordinal: 106, Address: 0x3610)
  • ?ProxyServiceDiscoveryVolume@BuiVolume@@AEAAJXZ (Ordinal: 107, Address: 0x3ae0)
  • ?ProxyUnlockVolumeWithKey@BuiVolume@@AEAAJPEBGPEAH@Z (Ordinal: 108, Address: 0x36a0)
  • ?ProxyUnlockVolumeWithPassphrase@BuiVolume@@AEAAJPEBGPEAH@Z (Ordinal: 109, Address: 0x36f0)
  • ?ProxyUnlockVolumeWithPassword@BuiVolume@@AEAAJPEBGPEAH@Z (Ordinal: 110, Address: 0x3650)
  • ?ProxyUnlockVolumeWithSmartCard@BuiVolume@@AEAAJPEAUHWND__@@PEAH@Z (Ordinal: 111, Address: 0x3740)
  • ?ProxyUpgradeVolume@BuiVolume@@AEAAJXZ (Ordinal: 112, Address: 0x3d50)
  • ?RefreshStatus@BuiVolume@@QEAAJ_N@Z (Ordinal: 113, Address: 0x1c80)
  • ?RemovePassphrase@BuiVolume@@QEAAJXZ (Ordinal: 114, Address: 0x29d0)
  • ?RemoveSmartCard@BuiVolume@@QEAAJ_N@Z (Ordinal: 115, Address: 0x2a50)
  • ?ResumeConversion@BuiVolume@@QEAAJXZ (Ordinal: 116, Address: 0x26d0)
  • ?ResumeStatusRefreshing@BuiVolume@@QEAAXXZ (Ordinal: 117, Address: 0x1f10)
  • ?ServiceDiscoveryVolume@BuiVolume@@QEAAJXZ (Ordinal: 118, Address: 0x29b0)
  • ?SetProxyObject@BuiVolume@@QEAAXPEAUIDispatch@@@Z (Ordinal: 119, Address: 0x24e0)
  • ?SuspendStatusRefreshing@BuiVolume@@QEAAXXZ (Ordinal: 120, Address: 0x1ed0)
  • ?UnlockRequiresElevation@BuiVolume@@QEBA_NXZ (Ordinal: 121, Address: 0x4430)
  • ?UnlockWithKey@BuiVolume@@QEAAJPEBGPEAH@Z (Ordinal: 122, Address: 0x27f0)
  • ?UnlockWithPassphrase@BuiVolume@@QEAAJPEBGPEAH@Z (Ordinal: 123, Address: 0x2840)
  • ?UnlockWithPassword@BuiVolume@@QEAAJPEBGPEAH@Z (Ordinal: 124, Address: 0x27a0)
  • ?UnlockWithSmartCard@BuiVolume@@QEAAJPEAUHWND__@@PEAH@Z (Ordinal: 125, Address: 0x2890)
  • ?UpgradeVolume@BuiVolume@@QEAAJXZ (Ordinal: 126, Address: 0x2a90)
  • BuisCreateElevatedProxyObject (Ordinal: 127, Address: 0x1370)
  • BuisCreateProxyObject (Ordinal: 128, Address: 0x1490)
  • BuisDetectExistingWizard (Ordinal: 129, Address: 0x1590)
  • BuisIsFipsEnabled (Ordinal: 130, Address: 0x14e0)
  • BuisIsHardwareReadyForConversion (Ordinal: 131, Address: 0x1510)

Imported DLLs & Functions

api-ms-win-core-com-l1-1-0.dll
  • CoCreateInstance (Address: 0x1800061e8)
  • StringFromGUID2 (Address: 0x1800061e0)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x1800061f8)
  • SetUnhandledExceptionFilter (Address: 0x180006200)
  • UnhandledExceptionFilter (Address: 0x180006208)
api-ms-win-core-file-l1-1-0.dll
  • GetVolumeInformationW (Address: 0x180006218)
api-ms-win-core-file-l1-2-0.dll
  • GetVolumeNameForVolumeMountPointW (Address: 0x180006228)
  • GetVolumePathNamesForVolumeNameW (Address: 0x180006230)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x180006240)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x180006268)
  • GetCurrentProcessId (Address: 0x180006260)
  • GetCurrentThreadId (Address: 0x180006250)
  • TerminateProcess (Address: 0x180006258)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x180006278)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x180006290)
  • RtlLookupFunctionEntry (Address: 0x180006298)
  • RtlVirtualUnwind (Address: 0x180006288)
api-ms-win-core-synch-l1-1-0.dll
  • CreateMutexW (Address: 0x1800062a8)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x1800062b8)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTimeAsFileTime (Address: 0x1800062d0)
  • GetTickCount (Address: 0x1800062c8)
api-ms-win-core-sysinfo-l1-2-0.dll
  • VerSetConditionMask (Address: 0x1800062e0)
bcrypt.dll
  • BCryptGetFipsAlgorithmMode (Address: 0x1800062f0)
FVEAPI.dll
  • FveCloseHandle (Address: 0x180006178)
  • FveCloseVolume (Address: 0x180006180)
  • FveFindFirstVolume (Address: 0x180006150)
  • FveFindNextVolume (Address: 0x180006128)
  • FveGetAuthMethodInformation (Address: 0x180006140)
  • FveGetStatus (Address: 0x180006138)
  • FveGetVolumeNameW (Address: 0x180006160)
  • FveIsBoundDataVolume (Address: 0x180006148)
  • FveIsHardwareReadyForConversion (Address: 0x180006158)
  • FveIsVolumeEncryptable (Address: 0x180006170)
  • FveOpenVolumeByHandle (Address: 0x180006168)
  • FveOpenVolumeW (Address: 0x180006130)
msvcrt.dll
  • __C_specific_handler (Address: 0x180006340)
  • _amsg_exit (Address: 0x180006330)
  • _callnewh (Address: 0x180006318)
  • _initterm (Address: 0x180006338)
  • _vsnwprintf (Address: 0x180006308)
  • _wcsicmp (Address: 0x180006350)
  • _XcptFilter (Address: 0x180006328)
  • free (Address: 0x180006320)
  • malloc (Address: 0x180006310)
  • memcpy (Address: 0x180006300)
  • memset (Address: 0x180006358)
  • towupper (Address: 0x180006348)
ntdll.dll
  • RtlVerifyVersionInfo (Address: 0x180006368)
ole32.dll
  • CoGetObject (Address: 0x180006378)
OLEAUT32.dll
  • SysAllocString (Address: 0x180006190)
  • VariantClear (Address: 0x180006198)
  • VariantInit (Address: 0x1800061a0)
USER32.dll
  • AllowSetForegroundWindow (Address: 0x1800061b0)
  • EnumChildWindows (Address: 0x1800061b8)
  • FindWindowW (Address: 0x1800061c0)
  • GetWindowThreadProcessId (Address: 0x1800061d0)
  • SendMessageTimeoutW (Address: 0x1800061c8)