securebootai.dll
Description: CSI Secure Boot Servicing Plugin
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.5071
Architecture: 32-bit
Operating System: Windows NT
SHA256: dc636bd89ebd51b07a96833f1c09f32b
File Size: 294.5 KB
Uploaded At: Dec. 1, 2025, 8:40 a.m.
Views: 33
Exported Functions
- DllCanUnloadNow (Ordinal: 1, Address: 0x1f430)
- DllCsiGetHandler (Ordinal: 2, Address: 0x1f450)
Imported DLLs & Functions
api-ms-win-core-com-l1-1-0.dll
- CoCreateInstance (Address: 0x10043078)
- CoInitializeEx (Address: 0x10043080)
- CoInitializeSecurity (Address: 0x10043084)
- CoSetProxyBlanket (Address: 0x10043074)
- CoUninitialize (Address: 0x1004307c)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x1004308c)
- IsDebuggerPresent (Address: 0x10043090)
- OutputDebugStringW (Address: 0x10043094)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x100430a8)
- SetLastError (Address: 0x100430a0)
- SetUnhandledExceptionFilter (Address: 0x1004309c)
- UnhandledExceptionFilter (Address: 0x100430a4)
api-ms-win-core-file-l1-1-0.dll
- CreateDirectoryW (Address: 0x100430f0)
- CreateFileW (Address: 0x100430f4)
- DeleteFileW (Address: 0x100430e0)
- FindClose (Address: 0x100430e8)
- FindFirstFileW (Address: 0x100430cc)
- FindNextFileW (Address: 0x100430d4)
- FlushFileBuffers (Address: 0x100430b8)
- GetFileAttributesW (Address: 0x100430b4)
- GetFileInformationByHandle (Address: 0x100430d8)
- GetFileSizeEx (Address: 0x100430d0)
- GetFullPathNameW (Address: 0x100430e4)
- GetVolumeInformationW (Address: 0x100430c4)
- GetVolumePathNameW (Address: 0x100430b0)
- QueryDosDeviceW (Address: 0x100430bc)
- ReadFile (Address: 0x100430c0)
- SetFileAttributesW (Address: 0x100430ec)
- SetFileInformationByHandle (Address: 0x100430dc)
- WriteFile (Address: 0x100430c8)
api-ms-win-core-file-l1-2-0.dll
- GetVolumeNameForVolumeMountPointW (Address: 0x100430fc)
api-ms-win-core-file-l2-1-0.dll
- CopyFileExW (Address: 0x1004310c)
- GetFileInformationByHandleEx (Address: 0x10043104)
- MoveFileExW (Address: 0x10043108)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x10043114)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x10043124)
- HeapAlloc (Address: 0x10043128)
- HeapDestroy (Address: 0x10043120)
- HeapFree (Address: 0x1004311c)
api-ms-win-core-heap-obsolete-l1-1-0.dll
- LocalAlloc (Address: 0x10043130)
- LocalFree (Address: 0x10043134)
api-ms-win-core-io-l1-1-0.dll
- DeviceIoControl (Address: 0x1004313c)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
- FindResourceW (Address: 0x10043144)
- LoadLibraryW (Address: 0x10043148)
api-ms-win-core-libraryloader-l1-1-0.dll
- DisableThreadLibraryCalls (Address: 0x10043150)
- FindResourceExW (Address: 0x1004315c)
- FreeLibrary (Address: 0x10043158)
- GetModuleFileNameA (Address: 0x10043170)
- GetModuleHandleExW (Address: 0x10043154)
- GetModuleHandleW (Address: 0x10043174)
- GetProcAddress (Address: 0x1004316c)
- LoadLibraryExW (Address: 0x10043160)
- LoadResource (Address: 0x10043168)
- SizeofResource (Address: 0x10043164)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x1004317c)
- GetLocaleInfoW (Address: 0x10043180)
api-ms-win-core-localization-obsolete-l1-2-0.dll
- GetSystemDefaultUILanguage (Address: 0x1004318c)
- GetUserDefaultUILanguage (Address: 0x10043188)
api-ms-win-core-memory-l1-1-0.dll
- CreateFileMappingW (Address: 0x10043198)
- MapViewOfFile (Address: 0x1004319c)
- UnmapViewOfFile (Address: 0x10043194)
api-ms-win-core-privateprofile-l1-1-0.dll
- GetPrivateProfileSectionW (Address: 0x100431a4)
api-ms-win-core-processenvironment-l1-1-0.dll
- SearchPathW (Address: 0x100431ac)
api-ms-win-core-processthreads-l1-1-0.dll
- GetCurrentProcess (Address: 0x100431c8)
- GetCurrentProcessId (Address: 0x100431bc)
- GetCurrentThread (Address: 0x100431cc)
- GetCurrentThreadId (Address: 0x100431d0)
- OpenProcessToken (Address: 0x100431c0)
- OpenThreadToken (Address: 0x100431c4)
- SetThreadToken (Address: 0x100431b4)
- TerminateProcess (Address: 0x100431b8)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x100431d8)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x100431e8)
- RegCreateKeyExW (Address: 0x100431f8)
- RegDeleteKeyExW (Address: 0x100431ec)
- RegGetValueW (Address: 0x100431e4)
- RegOpenKeyExW (Address: 0x100431f0)
- RegQueryValueExW (Address: 0x100431e0)
- RegSetValueExW (Address: 0x100431f4)
api-ms-win-core-shlwapi-legacy-l1-1-0.dll
- PathRemoveBackslashW (Address: 0x10043200)
api-ms-win-core-shlwapi-obsolete-l1-1-0.dll
- StrCmpIW (Address: 0x10043208)
- StrStrIW (Address: 0x1004320c)
api-ms-win-core-string-l1-1-0.dll
- MultiByteToWideChar (Address: 0x10043214)
api-ms-win-core-string-obsolete-l1-1-0.dll
- lstrlenA (Address: 0x1004321c)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x10043258)
- AcquireSRWLockShared (Address: 0x10043250)
- CreateMutexExW (Address: 0x10043224)
- CreateSemaphoreExW (Address: 0x10043234)
- DeleteCriticalSection (Address: 0x10043240)
- EnterCriticalSection (Address: 0x1004323c)
- InitializeCriticalSection (Address: 0x10043238)
- InitializeCriticalSectionEx (Address: 0x1004322c)
- LeaveCriticalSection (Address: 0x10043230)
- OpenSemaphoreW (Address: 0x10043244)
- ReleaseMutex (Address: 0x10043228)
- ReleaseSemaphore (Address: 0x1004324c)
- ReleaseSRWLockExclusive (Address: 0x10043254)
- ReleaseSRWLockShared (Address: 0x10043248)
- WaitForSingleObject (Address: 0x1004325c)
- WaitForSingleObjectEx (Address: 0x10043260)
api-ms-win-core-synch-l1-2-0.dll
- InitOnceBeginInitialize (Address: 0x1004326c)
- InitOnceComplete (Address: 0x10043268)
- Sleep (Address: 0x10043270)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemDirectoryW (Address: 0x1004328c)
- GetSystemInfo (Address: 0x10043288)
- GetSystemTimeAsFileTime (Address: 0x10043284)
- GetTickCount (Address: 0x1004327c)
- GetVersionExW (Address: 0x10043280)
- GetWindowsDirectoryW (Address: 0x10043278)
api-ms-win-core-threadpool-l1-2-0.dll
- CloseThreadpoolTimer (Address: 0x10043294)
- CreateThreadpoolTimer (Address: 0x10043298)
- SetThreadpoolTimer (Address: 0x100432a0)
- WaitForThreadpoolTimerCallbacks (Address: 0x1004329c)
api-ms-win-eventing-provider-l1-1-0.dll
- EventRegister (Address: 0x100432a8)
- EventUnregister (Address: 0x100432ac)
- EventWriteTransfer (Address: 0x100432b0)
api-ms-win-security-base-l1-1-0.dll
- AdjustTokenPrivileges (Address: 0x100432b8)
- DuplicateTokenEx (Address: 0x100432d0)
- GetSecurityDescriptorControl (Address: 0x100432d4)
- GetSecurityDescriptorDacl (Address: 0x100432c8)
- GetSecurityDescriptorGroup (Address: 0x100432cc)
- GetSecurityDescriptorOwner (Address: 0x100432c0)
- GetSecurityDescriptorSacl (Address: 0x100432c4)
- GetTokenInformation (Address: 0x100432bc)
api-ms-win-security-lsalookup-l2-1-0.dll
- LookupPrivilegeValueW (Address: 0x100432dc)
api-ms-win-security-provider-l1-1-0.dll
- SetNamedSecurityInfoW (Address: 0x100432e4)
api-ms-win-security-sddl-l1-1-0.dll
- ConvertSidToStringSidW (Address: 0x100432f0)
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x100432ec)
bcrypt.dll
- BCryptCloseAlgorithmProvider (Address: 0x100432f8)
- BCryptCreateHash (Address: 0x1004330c)
- BCryptDestroyHash (Address: 0x10043304)
- BCryptFinishHash (Address: 0x10043300)
- BCryptHash (Address: 0x10043310)
- BCryptHashData (Address: 0x10043308)
- BCryptOpenAlgorithmProvider (Address: 0x100432fc)
CRYPT32.dll
- CertCloseStore (Address: 0x10043010)
- CertCreateCertificateContext (Address: 0x10043014)
- CertFindCertificateInStore (Address: 0x10043008)
- CertFreeCertificateContext (Address: 0x10043000)
- CertGetCertificateContextProperty (Address: 0x10043004)
- CertGetNameStringW (Address: 0x1004301c)
- CryptMsgClose (Address: 0x10043018)
- CryptMsgGetParam (Address: 0x1004300c)
- CryptQueryObject (Address: 0x10043020)
imagehlp.dll
- CheckSumMappedFile (Address: 0x10043318)
msvcrt.dll
- __CxxFrameHandler3 (Address: 0x10043320)
- __dllonexit (Address: 0x1004336c)
- __iob_func (Address: 0x100433e8)
- _amsg_exit (Address: 0x10043328)
- _callnewh (Address: 0x100433a0)
- _CxxThrowException (Address: 0x100433c4)
- _except_handler4_common (Address: 0x10043378)
- _initterm (Address: 0x10043348)
- _lock (Address: 0x10043354)
- _onexit (Address: 0x10043370)
- _purecall (Address: 0x100433ac)
- _snwscanf_s (Address: 0x100433dc)
- _ultow_s (Address: 0x100433e0)
- _unlock (Address: 0x10043358)
- _vsnprintf_s (Address: 0x10043350)
- _vsnwprintf (Address: 0x1004339c)
- _vsnwprintf_s (Address: 0x10043344)
- _wcsicmp (Address: 0x10043324)
- _wcslwr (Address: 0x100433d8)
- _wcsnicmp (Address: 0x10043334)
- _wcsupr (Address: 0x10043390)
- _wfopen_s (Address: 0x1004338c)
- _XcptFilter (Address: 0x10043360)
- ??0exception@@QAE@ABV0@@Z (Address: 0x10043330)
- ??0exception@@QAE@XZ (Address: 0x10043368)
- ??1exception@@UAE@XZ (Address: 0x1004333c)
- ??1type_info@@UAE@XZ (Address: 0x10043398)
- ?terminate@@YAXXZ (Address: 0x10043384)
- bsearch (Address: 0x10043380)
- fclose (Address: 0x10043394)
- fflush (Address: 0x10043388)
- free (Address: 0x100433a8)
- fwprintf (Address: 0x1004335c)
- malloc (Address: 0x100433a4)
- memcmp (Address: 0x100433c0)
- memcpy (Address: 0x100433bc)
- memcpy_s (Address: 0x100433b4)
- memmove (Address: 0x1004337c)
- memmove_s (Address: 0x100433b0)
- memset (Address: 0x100433ec)
- strcpy_s (Address: 0x100433cc)
- strncmp (Address: 0x100433c8)
- swprintf_s (Address: 0x1004332c)
- wcscat_s (Address: 0x10043338)
- wcschr (Address: 0x10043340)
- wcscpy_s (Address: 0x1004334c)
- wcsncmp (Address: 0x10043374)
- wcsncpy_s (Address: 0x10043364)
- wcsnlen (Address: 0x100433d0)
- wcsrchr (Address: 0x100433b8)
- wcsstr (Address: 0x100433d4)
- wcstoul (Address: 0x100433e4)
ntdll.dll
- LdrAccessResource (Address: 0x1004342c)
- LdrFindResource_U (Address: 0x10043428)
- LdrGetDllHandle (Address: 0x100434d8)
- LdrGetProcedureAddress (Address: 0x100434d4)
- NtAdjustPrivilegesToken (Address: 0x10043508)
- NtClose (Address: 0x100433fc)
- NtCreateEvent (Address: 0x10043400)
- NtDeviceIoControlFile (Address: 0x100433f4)
- NtEnumerateBootEntries (Address: 0x10043528)
- NtOpenDirectoryObject (Address: 0x10043498)
- NtOpenFile (Address: 0x10043410)
- NtOpenKey (Address: 0x1004346c)
- NtOpenProcess (Address: 0x1004351c)
- NtOpenProcessTokenEx (Address: 0x1004350c)
- NtOpenSymbolicLinkObject (Address: 0x10043464)
- NtOpenThreadTokenEx (Address: 0x10043510)
- NtQueryBootEntryOrder (Address: 0x10043490)
- NtQueryBootOptions (Address: 0x10043494)
- NtQueryDirectoryObject (Address: 0x1004349c)
- NtQueryInformationFile (Address: 0x10043404)
- NtQueryInformationProcess (Address: 0x10043520)
- NtQueryInformationThread (Address: 0x10043408)
- NtQuerySymbolicLinkObject (Address: 0x10043470)
- NtQuerySystemEnvironmentValueEx (Address: 0x1004353c)
- NtQuerySystemInformation (Address: 0x10043548)
- NtQueryValueKey (Address: 0x1004348c)
- NtReadFile (Address: 0x1004354c)
- NtSetInformationFile (Address: 0x10043418)
- NtSetInformationThread (Address: 0x10043484)
- NtSetSystemEnvironmentValueEx (Address: 0x10043540)
- NtTranslateFilePath (Address: 0x10043534)
- NtWaitForSingleObject (Address: 0x1004340c)
- NtWriteFile (Address: 0x10043524)
- RtlAddAccessAllowedAceEx (Address: 0x10043474)
- RtlAdjustPrivilege (Address: 0x10043530)
- RtlAllocateAndInitializeSid (Address: 0x10043478)
- RtlAllocateHeap (Address: 0x10043430)
- RtlAppendUnicodeToString (Address: 0x10043454)
- RtlCompareMemory (Address: 0x10043424)
- RtlCreateAcl (Address: 0x10043518)
- RtlCreateSecurityDescriptor (Address: 0x10043488)
- RtlFreeHeap (Address: 0x10043420)
- RtlFreeSid (Address: 0x10043480)
- RtlFreeUnicodeString (Address: 0x10043414)
- RtlGetVersion (Address: 0x100434fc)
- RtlGUIDFromString (Address: 0x10043450)
- RtlImageNtHeader (Address: 0x100433f8)
- RtlImageNtHeaderEx (Address: 0x1004352c)
- RtlImpersonateSelf (Address: 0x10043514)
- RtlInitAnsiString (Address: 0x100434e0)
- RtlInitUnicodeString (Address: 0x10043544)
- RtlLengthSecurityDescriptor (Address: 0x1004345c)
- RtlLengthSid (Address: 0x1004347c)
- RtlNtStatusToDosError (Address: 0x10043538)
- RtlSetDaclSecurityDescriptor (Address: 0x10043468)
- RtlSetOwnerSecurityDescriptor (Address: 0x10043460)
- RtlStringFromGUID (Address: 0x1004341c)
- ZwAllocateUuids (Address: 0x10043504)
- ZwClose (Address: 0x10043448)
- ZwCreateFile (Address: 0x100434a0)
- ZwCreateKey (Address: 0x100434a4)
- ZwDeleteKey (Address: 0x100434b8)
- ZwDeleteValueKey (Address: 0x100434b0)
- ZwDeviceIoControlFile (Address: 0x100434f0)
- ZwEnumerateKey (Address: 0x100434bc)
- ZwFlushKey (Address: 0x100434ac)
- ZwLoadKey (Address: 0x100434a8)
- ZwOpenDirectoryObject (Address: 0x10043500)
- ZwOpenFile (Address: 0x10043440)
- ZwOpenKey (Address: 0x100434d0)
- ZwOpenMutant (Address: 0x10043444)
- ZwOpenProcess (Address: 0x100434e8)
- ZwOpenSymbolicLinkObject (Address: 0x100434f8)
- ZwQueryAttributesFile (Address: 0x10043458)
- ZwQueryDirectoryObject (Address: 0x100434f4)
- ZwQueryInformationFile (Address: 0x100434e4)
- ZwQueryInformationProcess (Address: 0x100434dc)
- ZwQueryKey (Address: 0x10043438)
- ZwQuerySymbolicLinkObject (Address: 0x100434ec)
- ZwQuerySystemInformation (Address: 0x1004344c)
- ZwQueryValueKey (Address: 0x100434c0)
- ZwReleaseMutant (Address: 0x1004343c)
- ZwSaveKey (Address: 0x100434b4)
- ZwSetSecurityObject (Address: 0x100434c4)
- ZwSetValueKey (Address: 0x100434cc)
- ZwUnloadKey (Address: 0x100434c8)
- ZwWaitForSingleObject (Address: 0x10043434)
OLEAUT32.dll
- SysAllocString (Address: 0x1004302c)
- SysFreeString (Address: 0x10043034)
- VariantClear (Address: 0x10043030)
- VariantInit (Address: 0x10043028)
RPCRT4.dll
- UuidCreate (Address: 0x1004303c)
WCP.dll
- ?RtlGetFacilityTracingFlags@Rtl@WCP@Windows@@YIKPAU_RTL_TRACING_FACILITY@123@@Z (Address: 0x1004305c)
- ?RtlTraceFormat_PCHRESULT@Rtl@WCP@Windows@@YIXPAUIRtlFormattedOutputStream@13@PBX@Z (Address: 0x10043048)
- ?RtlTraceFormat_PCWSTR@Rtl@WCP@Windows@@YIXPAUIRtlFormattedOutputStream@13@PBX@Z (Address: 0x10043044)
- ?RtlTraceVa@Rtl@WCP@Windows@@YIXKKPAU_RTL_TRACING_FACILITY@123@QBDKPAD@Z (Address: 0x10043054)
- ConvertNtStatusToHResult (Address: 0x1004304c)
- RtlFreeLBlob (Address: 0x10043058)
- RtlReportErrorOrigination (Address: 0x10043050)
WINTRUST.dll
- WinVerifyTrust (Address: 0x1004306c)
- WTHelperGetProvSignerFromChain (Address: 0x10043064)
- WTHelperProvDataFromStateData (Address: 0x10043068)