securebootai.dll
Description: CSI Secure Boot Servicing Plugin
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.4467
Architecture: 32-bit
Operating System: Windows NT
SHA256: e7e04428892c7c4cc607a93dda82c6fe
File Size: 286.4 KB
Uploaded At: Dec. 1, 2025, 8:40 a.m.
Views: 29
Exported Functions
- DllCanUnloadNow (Ordinal: 1, Address: 0x1e890)
- DllCsiGetHandler (Ordinal: 2, Address: 0x1e8b0)
Imported DLLs & Functions
api-ms-win-core-com-l1-1-0.dll
- CoCreateInstance (Address: 0x10041078)
- CoInitializeEx (Address: 0x10041080)
- CoInitializeSecurity (Address: 0x10041084)
- CoSetProxyBlanket (Address: 0x10041074)
- CoUninitialize (Address: 0x1004107c)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x1004108c)
- IsDebuggerPresent (Address: 0x10041090)
- OutputDebugStringW (Address: 0x10041094)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x100410a8)
- SetLastError (Address: 0x100410a0)
- SetUnhandledExceptionFilter (Address: 0x1004109c)
- UnhandledExceptionFilter (Address: 0x100410a4)
api-ms-win-core-file-l1-1-0.dll
- CreateDirectoryW (Address: 0x100410ec)
- CreateFileW (Address: 0x100410f4)
- DeleteFileW (Address: 0x100410e0)
- FindClose (Address: 0x100410e8)
- FindFirstFileW (Address: 0x100410cc)
- FindNextFileW (Address: 0x100410d4)
- FlushFileBuffers (Address: 0x100410f0)
- GetFileAttributesW (Address: 0x100410c4)
- GetFileInformationByHandle (Address: 0x100410d8)
- GetFileSizeEx (Address: 0x100410d0)
- GetFullPathNameW (Address: 0x100410e4)
- GetVolumeInformationW (Address: 0x100410bc)
- GetVolumePathNameW (Address: 0x100410b8)
- QueryDosDeviceW (Address: 0x100410b0)
- ReadFile (Address: 0x100410c0)
- SetFileAttributesW (Address: 0x100410c8)
- SetFileInformationByHandle (Address: 0x100410dc)
- WriteFile (Address: 0x100410b4)
api-ms-win-core-file-l1-2-0.dll
- GetVolumeNameForVolumeMountPointW (Address: 0x100410fc)
api-ms-win-core-file-l2-1-0.dll
- CopyFileExW (Address: 0x1004110c)
- GetFileInformationByHandleEx (Address: 0x10041104)
- MoveFileExW (Address: 0x10041108)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x10041114)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x1004111c)
- HeapAlloc (Address: 0x10041124)
- HeapDestroy (Address: 0x10041120)
- HeapFree (Address: 0x10041128)
api-ms-win-core-heap-obsolete-l1-1-0.dll
- LocalAlloc (Address: 0x10041130)
- LocalFree (Address: 0x10041134)
api-ms-win-core-io-l1-1-0.dll
- DeviceIoControl (Address: 0x1004113c)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
- CopyFileW (Address: 0x10041144)
- LoadLibraryW (Address: 0x10041148)
api-ms-win-core-libraryloader-l1-1-0.dll
- DisableThreadLibraryCalls (Address: 0x10041154)
- FindResourceExW (Address: 0x10041150)
- FreeLibrary (Address: 0x10041158)
- GetModuleFileNameA (Address: 0x1004116c)
- GetModuleHandleExW (Address: 0x1004115c)
- GetModuleHandleW (Address: 0x10041168)
- GetProcAddress (Address: 0x10041160)
- LoadLibraryExW (Address: 0x10041164)
- LoadResource (Address: 0x10041170)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x1004117c)
- GetLocaleInfoW (Address: 0x10041178)
api-ms-win-core-localization-obsolete-l1-2-0.dll
- GetSystemDefaultUILanguage (Address: 0x10041188)
- GetUserDefaultUILanguage (Address: 0x10041184)
api-ms-win-core-memory-l1-1-0.dll
- CreateFileMappingW (Address: 0x10041190)
- MapViewOfFile (Address: 0x10041194)
- UnmapViewOfFile (Address: 0x10041198)
api-ms-win-core-privateprofile-l1-1-0.dll
- GetPrivateProfileSectionW (Address: 0x100411a0)
api-ms-win-core-processenvironment-l1-1-0.dll
- SearchPathW (Address: 0x100411a8)
api-ms-win-core-processthreads-l1-1-0.dll
- GetCurrentProcess (Address: 0x100411c4)
- GetCurrentProcessId (Address: 0x100411c8)
- GetCurrentThread (Address: 0x100411cc)
- GetCurrentThreadId (Address: 0x100411b4)
- OpenProcessToken (Address: 0x100411b0)
- OpenThreadToken (Address: 0x100411b8)
- SetThreadToken (Address: 0x100411bc)
- TerminateProcess (Address: 0x100411c0)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x100411d4)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x100411e0)
- RegCreateKeyExW (Address: 0x100411f0)
- RegDeleteKeyExW (Address: 0x100411e4)
- RegGetValueW (Address: 0x100411e8)
- RegOpenKeyExW (Address: 0x100411ec)
- RegQueryValueExW (Address: 0x100411dc)
- RegSetValueExW (Address: 0x100411f4)
api-ms-win-core-shlwapi-legacy-l1-1-0.dll
- PathRemoveBackslashW (Address: 0x100411fc)
api-ms-win-core-shlwapi-obsolete-l1-1-0.dll
- StrCmpIW (Address: 0x10041204)
- StrStrIW (Address: 0x10041208)
api-ms-win-core-string-l1-1-0.dll
- MultiByteToWideChar (Address: 0x10041210)
api-ms-win-core-string-obsolete-l1-1-0.dll
- lstrlenA (Address: 0x10041218)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x10041250)
- AcquireSRWLockShared (Address: 0x10041244)
- CreateMutexExW (Address: 0x10041240)
- CreateSemaphoreExW (Address: 0x1004122c)
- DeleteCriticalSection (Address: 0x10041230)
- EnterCriticalSection (Address: 0x10041258)
- InitializeCriticalSection (Address: 0x10041224)
- InitializeCriticalSectionEx (Address: 0x10041234)
- LeaveCriticalSection (Address: 0x1004125c)
- OpenSemaphoreW (Address: 0x10041254)
- ReleaseMutex (Address: 0x10041220)
- ReleaseSemaphore (Address: 0x10041228)
- ReleaseSRWLockExclusive (Address: 0x10041248)
- ReleaseSRWLockShared (Address: 0x1004123c)
- WaitForSingleObject (Address: 0x10041238)
- WaitForSingleObjectEx (Address: 0x1004124c)
api-ms-win-core-synch-l1-2-0.dll
- InitOnceBeginInitialize (Address: 0x1004126c)
- InitOnceComplete (Address: 0x10041268)
- Sleep (Address: 0x10041264)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemDirectoryW (Address: 0x10041274)
- GetSystemInfo (Address: 0x10041288)
- GetSystemTimeAsFileTime (Address: 0x1004127c)
- GetTickCount (Address: 0x10041278)
- GetVersionExW (Address: 0x10041280)
- GetWindowsDirectoryW (Address: 0x10041284)
api-ms-win-core-threadpool-l1-2-0.dll
- CloseThreadpoolTimer (Address: 0x10041298)
- CreateThreadpoolTimer (Address: 0x10041290)
- SetThreadpoolTimer (Address: 0x1004129c)
- WaitForThreadpoolTimerCallbacks (Address: 0x10041294)
api-ms-win-eventing-provider-l1-1-0.dll
- EventRegister (Address: 0x100412a8)
- EventUnregister (Address: 0x100412a4)
- EventWriteTransfer (Address: 0x100412ac)
api-ms-win-security-base-l1-1-0.dll
- AdjustTokenPrivileges (Address: 0x100412c8)
- DuplicateTokenEx (Address: 0x100412d0)
- GetSecurityDescriptorControl (Address: 0x100412b8)
- GetSecurityDescriptorDacl (Address: 0x100412b4)
- GetSecurityDescriptorGroup (Address: 0x100412c0)
- GetSecurityDescriptorOwner (Address: 0x100412bc)
- GetSecurityDescriptorSacl (Address: 0x100412c4)
- GetTokenInformation (Address: 0x100412cc)
api-ms-win-security-lsalookup-l2-1-0.dll
- LookupPrivilegeValueW (Address: 0x100412d8)
api-ms-win-security-provider-l1-1-0.dll
- SetNamedSecurityInfoW (Address: 0x100412e0)
api-ms-win-security-sddl-l1-1-0.dll
- ConvertSidToStringSidW (Address: 0x100412ec)
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x100412e8)
bcrypt.dll
- BCryptCloseAlgorithmProvider (Address: 0x10041300)
- BCryptCreateHash (Address: 0x10041304)
- BCryptDestroyHash (Address: 0x1004130c)
- BCryptFinishHash (Address: 0x100412fc)
- BCryptHash (Address: 0x100412f4)
- BCryptHashData (Address: 0x10041308)
- BCryptOpenAlgorithmProvider (Address: 0x100412f8)
CRYPT32.dll
- CertCloseStore (Address: 0x10041010)
- CertCreateCertificateContext (Address: 0x10041014)
- CertFindCertificateInStore (Address: 0x10041008)
- CertFreeCertificateContext (Address: 0x10041000)
- CertGetCertificateContextProperty (Address: 0x10041004)
- CertGetNameStringW (Address: 0x1004101c)
- CryptMsgClose (Address: 0x10041018)
- CryptMsgGetParam (Address: 0x1004100c)
- CryptQueryObject (Address: 0x10041020)
imagehlp.dll
- CheckSumMappedFile (Address: 0x10041314)
msvcrt.dll
- __CxxFrameHandler3 (Address: 0x10041320)
- __dllonexit (Address: 0x10041360)
- __iob_func (Address: 0x100413e4)
- _amsg_exit (Address: 0x1004132c)
- _callnewh (Address: 0x100413a0)
- _CxxThrowException (Address: 0x100413c4)
- _except_handler4_common (Address: 0x10041368)
- _initterm (Address: 0x10041348)
- _lock (Address: 0x1004134c)
- _onexit (Address: 0x10041364)
- _purecall (Address: 0x100413ac)
- _snwscanf_s (Address: 0x100413d4)
- _ultow_s (Address: 0x100413dc)
- _unlock (Address: 0x10041350)
- _vsnprintf_s (Address: 0x10041378)
- _vsnwprintf (Address: 0x10041384)
- _vsnwprintf_s (Address: 0x10041374)
- _wcsicmp (Address: 0x100413b8)
- _wcslwr (Address: 0x100413d0)
- _wcsnicmp (Address: 0x10041358)
- _wcsupr (Address: 0x1004131c)
- _wfopen_s (Address: 0x10041394)
- _XcptFilter (Address: 0x10041354)
- ??0exception@@QAE@ABV0@@Z (Address: 0x1004136c)
- ??0exception@@QAE@XZ (Address: 0x1004135c)
- ??1exception@@UAE@XZ (Address: 0x10041344)
- ??1type_info@@UAE@XZ (Address: 0x1004133c)
- ?terminate@@YAXXZ (Address: 0x1004139c)
- bsearch (Address: 0x10041334)
- fclose (Address: 0x10041388)
- fflush (Address: 0x10041330)
- free (Address: 0x100413a8)
- fwprintf (Address: 0x10041338)
- malloc (Address: 0x100413a4)
- memcmp (Address: 0x100413c0)
- memcpy (Address: 0x100413bc)
- memcpy_s (Address: 0x100413b4)
- memmove (Address: 0x10041370)
- memmove_s (Address: 0x100413b0)
- memset (Address: 0x100413e8)
- strcpy_s (Address: 0x100413d8)
- strncmp (Address: 0x100413c8)
- swprintf_s (Address: 0x10041390)
- wcscat_s (Address: 0x10041328)
- wcschr (Address: 0x10041324)
- wcscpy_s (Address: 0x10041398)
- wcsncmp (Address: 0x10041340)
- wcsncpy_s (Address: 0x1004138c)
- wcsnlen (Address: 0x100413cc)
- wcsrchr (Address: 0x10041380)
- wcsstr (Address: 0x1004137c)
- wcstoul (Address: 0x100413e0)
ntdll.dll
- LdrAccessResource (Address: 0x10041428)
- LdrFindResource_U (Address: 0x10041424)
- LdrGetDllHandle (Address: 0x100414b4)
- LdrGetProcedureAddress (Address: 0x100414b0)
- NtAdjustPrivilegesToken (Address: 0x100414e4)
- NtClose (Address: 0x10041524)
- NtCreateEvent (Address: 0x100413fc)
- NtDeviceIoControlFile (Address: 0x100413f4)
- NtEnumerateBootEntries (Address: 0x10041518)
- NtOpenDirectoryObject (Address: 0x10041510)
- NtOpenFile (Address: 0x1004140c)
- NtOpenKey (Address: 0x100414f8)
- NtOpenProcess (Address: 0x10041540)
- NtOpenProcessTokenEx (Address: 0x100414e8)
- NtOpenSymbolicLinkObject (Address: 0x100414f4)
- NtOpenThreadTokenEx (Address: 0x100414ec)
- NtQueryBootEntryOrder (Address: 0x10041504)
- NtQueryBootOptions (Address: 0x10041508)
- NtQueryDirectoryObject (Address: 0x10041514)
- NtQueryInformationFile (Address: 0x10041400)
- NtQueryInformationProcess (Address: 0x10041520)
- NtQueryInformationThread (Address: 0x10041404)
- NtQuerySymbolicLinkObject (Address: 0x100414fc)
- NtQuerySystemEnvironmentValueEx (Address: 0x10041530)
- NtQuerySystemInformation (Address: 0x1004153c)
- NtQueryValueKey (Address: 0x10041500)
- NtReadFile (Address: 0x1004148c)
- NtSetInformationFile (Address: 0x10041414)
- NtSetInformationThread (Address: 0x100413f0)
- NtSetSystemEnvironmentValueEx (Address: 0x10041534)
- NtTranslateFilePath (Address: 0x1004150c)
- NtWaitForSingleObject (Address: 0x10041408)
- NtWriteFile (Address: 0x10041528)
- RtlAddAccessAllowedAceEx (Address: 0x10041470)
- RtlAllocateAndInitializeSid (Address: 0x10041474)
- RtlAllocateHeap (Address: 0x1004142c)
- RtlAppendUnicodeToString (Address: 0x10041450)
- RtlCompareMemory (Address: 0x10041420)
- RtlCreateAcl (Address: 0x10041498)
- RtlCreateSecurityDescriptor (Address: 0x100414a4)
- RtlFreeHeap (Address: 0x1004141c)
- RtlFreeSid (Address: 0x10041488)
- RtlFreeUnicodeString (Address: 0x10041410)
- RtlGetVersion (Address: 0x100414d8)
- RtlGUIDFromString (Address: 0x1004144c)
- RtlImageNtHeader (Address: 0x100413f8)
- RtlImpersonateSelf (Address: 0x100414f0)
- RtlInitAnsiString (Address: 0x100414bc)
- RtlInitUnicodeString (Address: 0x10041538)
- RtlLengthSecurityDescriptor (Address: 0x10041458)
- RtlLengthSid (Address: 0x10041478)
- RtlNtStatusToDosError (Address: 0x1004152c)
- RtlSetDaclSecurityDescriptor (Address: 0x10041460)
- RtlSetOwnerSecurityDescriptor (Address: 0x1004145c)
- RtlStringFromGUID (Address: 0x10041418)
- ZwAllocateUuids (Address: 0x100414e0)
- ZwClose (Address: 0x10041444)
- ZwCreateFile (Address: 0x10041464)
- ZwCreateKey (Address: 0x10041468)
- ZwDeleteKey (Address: 0x1004151c)
- ZwDeleteValueKey (Address: 0x10041480)
- ZwDeviceIoControlFile (Address: 0x100414cc)
- ZwEnumerateKey (Address: 0x10041490)
- ZwFlushKey (Address: 0x1004147c)
- ZwLoadKey (Address: 0x1004146c)
- ZwOpenDirectoryObject (Address: 0x100414dc)
- ZwOpenFile (Address: 0x1004143c)
- ZwOpenKey (Address: 0x100414ac)
- ZwOpenMutant (Address: 0x10041440)
- ZwOpenProcess (Address: 0x100414c4)
- ZwOpenSymbolicLinkObject (Address: 0x100414d4)
- ZwQueryAttributesFile (Address: 0x10041454)
- ZwQueryDirectoryObject (Address: 0x100414d0)
- ZwQueryInformationFile (Address: 0x100414c0)
- ZwQueryInformationProcess (Address: 0x100414b8)
- ZwQueryKey (Address: 0x10041434)
- ZwQuerySymbolicLinkObject (Address: 0x100414c8)
- ZwQuerySystemInformation (Address: 0x10041448)
- ZwQueryValueKey (Address: 0x10041494)
- ZwReleaseMutant (Address: 0x10041438)
- ZwSaveKey (Address: 0x10041484)
- ZwSetSecurityObject (Address: 0x1004149c)
- ZwSetValueKey (Address: 0x100414a8)
- ZwUnloadKey (Address: 0x100414a0)
- ZwWaitForSingleObject (Address: 0x10041430)
OLEAUT32.dll
- SysAllocString (Address: 0x1004102c)
- SysFreeString (Address: 0x10041034)
- VariantClear (Address: 0x10041030)
- VariantInit (Address: 0x10041028)
RPCRT4.dll
- UuidCreate (Address: 0x1004103c)
WCP.dll
- ?RtlGetFacilityTracingFlags@Rtl@WCP@Windows@@YIKPAU_RTL_TRACING_FACILITY@123@@Z (Address: 0x1004105c)
- ?RtlTraceFormat_PCHRESULT@Rtl@WCP@Windows@@YIXPAUIRtlFormattedOutputStream@13@PBX@Z (Address: 0x10041048)
- ?RtlTraceFormat_PCWSTR@Rtl@WCP@Windows@@YIXPAUIRtlFormattedOutputStream@13@PBX@Z (Address: 0x10041044)
- ?RtlTraceVa@Rtl@WCP@Windows@@YIXKKPAU_RTL_TRACING_FACILITY@123@QBDKPAD@Z (Address: 0x10041054)
- ConvertNtStatusToHResult (Address: 0x1004104c)
- RtlFreeLBlob (Address: 0x10041058)
- RtlReportErrorOrigination (Address: 0x10041050)
WINTRUST.dll
- WinVerifyTrust (Address: 0x1004106c)
- WTHelperGetProvSignerFromChain (Address: 0x10041064)
- WTHelperProvDataFromStateData (Address: 0x10041068)