securebootai.dll
Description: CSI Secure Boot Servicing Plugin
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.5363
Architecture: 32-bit
Operating System: Windows NT
SHA256: 9cedb5d60275595e4420198da7b1d9cd
File Size: 299.0 KB
Uploaded At: Dec. 1, 2025, 8:40 a.m.
Views: 35
Exported Functions
- DllCanUnloadNow (Ordinal: 1, Address: 0x20020)
- DllCsiGetHandler (Ordinal: 2, Address: 0x20040)
Imported DLLs & Functions
api-ms-win-core-com-l1-1-0.dll
- CoCreateInstance (Address: 0x10044078)
- CoInitializeEx (Address: 0x10044080)
- CoInitializeSecurity (Address: 0x10044084)
- CoSetProxyBlanket (Address: 0x10044074)
- CoUninitialize (Address: 0x1004407c)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x1004408c)
- IsDebuggerPresent (Address: 0x10044090)
- OutputDebugStringW (Address: 0x10044094)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x100440a8)
- SetLastError (Address: 0x100440a0)
- SetUnhandledExceptionFilter (Address: 0x1004409c)
- UnhandledExceptionFilter (Address: 0x100440a4)
api-ms-win-core-file-l1-1-0.dll
- CreateDirectoryW (Address: 0x100440f0)
- CreateFileW (Address: 0x100440f4)
- DeleteFileW (Address: 0x100440e0)
- FindClose (Address: 0x100440e8)
- FindFirstFileW (Address: 0x100440cc)
- FindNextFileW (Address: 0x100440d4)
- FlushFileBuffers (Address: 0x100440b8)
- GetFileAttributesW (Address: 0x100440b4)
- GetFileInformationByHandle (Address: 0x100440d8)
- GetFileSizeEx (Address: 0x100440d0)
- GetFullPathNameW (Address: 0x100440e4)
- GetVolumeInformationW (Address: 0x100440c4)
- GetVolumePathNameW (Address: 0x100440b0)
- QueryDosDeviceW (Address: 0x100440bc)
- ReadFile (Address: 0x100440c0)
- SetFileAttributesW (Address: 0x100440ec)
- SetFileInformationByHandle (Address: 0x100440dc)
- WriteFile (Address: 0x100440c8)
api-ms-win-core-file-l1-2-0.dll
- GetVolumeNameForVolumeMountPointW (Address: 0x100440fc)
api-ms-win-core-file-l2-1-0.dll
- CopyFileExW (Address: 0x1004410c)
- GetFileInformationByHandleEx (Address: 0x10044104)
- MoveFileExW (Address: 0x10044108)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x10044114)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x10044124)
- HeapAlloc (Address: 0x10044128)
- HeapDestroy (Address: 0x10044120)
- HeapFree (Address: 0x1004411c)
api-ms-win-core-heap-obsolete-l1-1-0.dll
- LocalAlloc (Address: 0x10044130)
- LocalFree (Address: 0x10044134)
api-ms-win-core-io-l1-1-0.dll
- DeviceIoControl (Address: 0x1004413c)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
- FindResourceW (Address: 0x10044144)
- LoadLibraryW (Address: 0x10044148)
api-ms-win-core-libraryloader-l1-1-0.dll
- DisableThreadLibraryCalls (Address: 0x10044150)
- FindResourceExW (Address: 0x1004415c)
- FreeLibrary (Address: 0x10044158)
- GetModuleFileNameA (Address: 0x10044170)
- GetModuleHandleExW (Address: 0x10044154)
- GetModuleHandleW (Address: 0x10044174)
- GetProcAddress (Address: 0x1004416c)
- LoadLibraryExW (Address: 0x10044160)
- LoadResource (Address: 0x10044168)
- SizeofResource (Address: 0x10044164)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x1004417c)
- GetLocaleInfoW (Address: 0x10044180)
api-ms-win-core-localization-obsolete-l1-2-0.dll
- GetSystemDefaultUILanguage (Address: 0x1004418c)
- GetUserDefaultUILanguage (Address: 0x10044188)
api-ms-win-core-memory-l1-1-0.dll
- CreateFileMappingW (Address: 0x10044198)
- MapViewOfFile (Address: 0x1004419c)
- UnmapViewOfFile (Address: 0x10044194)
api-ms-win-core-privateprofile-l1-1-0.dll
- GetPrivateProfileSectionW (Address: 0x100441a4)
api-ms-win-core-processenvironment-l1-1-0.dll
- SearchPathW (Address: 0x100441ac)
api-ms-win-core-processthreads-l1-1-0.dll
- GetCurrentProcess (Address: 0x100441c8)
- GetCurrentProcessId (Address: 0x100441bc)
- GetCurrentThread (Address: 0x100441cc)
- GetCurrentThreadId (Address: 0x100441d0)
- OpenProcessToken (Address: 0x100441c0)
- OpenThreadToken (Address: 0x100441c4)
- SetThreadToken (Address: 0x100441b4)
- TerminateProcess (Address: 0x100441b8)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x100441d8)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x100441e8)
- RegCreateKeyExW (Address: 0x100441f8)
- RegDeleteKeyExW (Address: 0x100441ec)
- RegGetValueW (Address: 0x100441e4)
- RegOpenKeyExW (Address: 0x100441f0)
- RegQueryValueExW (Address: 0x100441e0)
- RegSetValueExW (Address: 0x100441f4)
api-ms-win-core-shlwapi-legacy-l1-1-0.dll
- PathRemoveBackslashW (Address: 0x10044200)
api-ms-win-core-shlwapi-obsolete-l1-1-0.dll
- StrCmpIW (Address: 0x10044208)
- StrStrIW (Address: 0x1004420c)
api-ms-win-core-string-l1-1-0.dll
- MultiByteToWideChar (Address: 0x10044214)
api-ms-win-core-string-obsolete-l1-1-0.dll
- lstrlenA (Address: 0x1004421c)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x10044258)
- AcquireSRWLockShared (Address: 0x10044250)
- CreateMutexExW (Address: 0x10044224)
- CreateSemaphoreExW (Address: 0x10044234)
- DeleteCriticalSection (Address: 0x10044240)
- EnterCriticalSection (Address: 0x1004423c)
- InitializeCriticalSection (Address: 0x10044238)
- InitializeCriticalSectionEx (Address: 0x1004422c)
- LeaveCriticalSection (Address: 0x10044230)
- OpenSemaphoreW (Address: 0x10044244)
- ReleaseMutex (Address: 0x10044228)
- ReleaseSemaphore (Address: 0x1004424c)
- ReleaseSRWLockExclusive (Address: 0x10044254)
- ReleaseSRWLockShared (Address: 0x10044248)
- WaitForSingleObject (Address: 0x1004425c)
- WaitForSingleObjectEx (Address: 0x10044260)
api-ms-win-core-synch-l1-2-0.dll
- InitOnceBeginInitialize (Address: 0x1004426c)
- InitOnceComplete (Address: 0x10044268)
- Sleep (Address: 0x10044270)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemDirectoryW (Address: 0x1004428c)
- GetSystemInfo (Address: 0x10044288)
- GetSystemTimeAsFileTime (Address: 0x10044284)
- GetTickCount (Address: 0x1004427c)
- GetVersionExW (Address: 0x10044280)
- GetWindowsDirectoryW (Address: 0x10044278)
api-ms-win-core-threadpool-l1-2-0.dll
- CloseThreadpoolTimer (Address: 0x10044294)
- CreateThreadpoolTimer (Address: 0x10044298)
- SetThreadpoolTimer (Address: 0x100442a0)
- WaitForThreadpoolTimerCallbacks (Address: 0x1004429c)
api-ms-win-eventing-provider-l1-1-0.dll
- EventRegister (Address: 0x100442a8)
- EventUnregister (Address: 0x100442ac)
- EventWriteTransfer (Address: 0x100442b0)
api-ms-win-security-base-l1-1-0.dll
- AdjustTokenPrivileges (Address: 0x100442b8)
- DuplicateTokenEx (Address: 0x100442d0)
- GetSecurityDescriptorControl (Address: 0x100442d4)
- GetSecurityDescriptorDacl (Address: 0x100442c8)
- GetSecurityDescriptorGroup (Address: 0x100442cc)
- GetSecurityDescriptorOwner (Address: 0x100442c0)
- GetSecurityDescriptorSacl (Address: 0x100442c4)
- GetTokenInformation (Address: 0x100442bc)
api-ms-win-security-lsalookup-l2-1-0.dll
- LookupPrivilegeValueW (Address: 0x100442dc)
api-ms-win-security-provider-l1-1-0.dll
- SetNamedSecurityInfoW (Address: 0x100442e4)
api-ms-win-security-sddl-l1-1-0.dll
- ConvertSidToStringSidW (Address: 0x100442f0)
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x100442ec)
bcrypt.dll
- BCryptCloseAlgorithmProvider (Address: 0x100442f8)
- BCryptCreateHash (Address: 0x1004430c)
- BCryptDestroyHash (Address: 0x10044304)
- BCryptFinishHash (Address: 0x10044300)
- BCryptHash (Address: 0x10044310)
- BCryptHashData (Address: 0x10044308)
- BCryptOpenAlgorithmProvider (Address: 0x100442fc)
CRYPT32.dll
- CertCloseStore (Address: 0x10044010)
- CertCreateCertificateContext (Address: 0x10044014)
- CertFindCertificateInStore (Address: 0x10044008)
- CertFreeCertificateContext (Address: 0x10044000)
- CertGetCertificateContextProperty (Address: 0x10044004)
- CertGetNameStringW (Address: 0x1004401c)
- CryptMsgClose (Address: 0x10044018)
- CryptMsgGetParam (Address: 0x1004400c)
- CryptQueryObject (Address: 0x10044020)
imagehlp.dll
- CheckSumMappedFile (Address: 0x10044318)
msvcrt.dll
- __CxxFrameHandler3 (Address: 0x10044320)
- __dllonexit (Address: 0x1004436c)
- __iob_func (Address: 0x100443e8)
- _amsg_exit (Address: 0x10044328)
- _callnewh (Address: 0x100443a0)
- _CxxThrowException (Address: 0x100443c4)
- _except_handler4_common (Address: 0x10044378)
- _initterm (Address: 0x10044348)
- _lock (Address: 0x10044354)
- _onexit (Address: 0x10044370)
- _purecall (Address: 0x100443ac)
- _snwscanf_s (Address: 0x100443dc)
- _ultow_s (Address: 0x100443e0)
- _unlock (Address: 0x10044358)
- _vsnprintf_s (Address: 0x10044350)
- _vsnwprintf (Address: 0x1004439c)
- _vsnwprintf_s (Address: 0x10044344)
- _wcsicmp (Address: 0x10044324)
- _wcslwr (Address: 0x100443d8)
- _wcsnicmp (Address: 0x10044334)
- _wcsupr (Address: 0x10044390)
- _wfopen_s (Address: 0x1004438c)
- _XcptFilter (Address: 0x10044360)
- ??0exception@@QAE@ABV0@@Z (Address: 0x10044330)
- ??0exception@@QAE@XZ (Address: 0x10044368)
- ??1exception@@UAE@XZ (Address: 0x1004433c)
- ??1type_info@@UAE@XZ (Address: 0x10044398)
- ?terminate@@YAXXZ (Address: 0x10044384)
- bsearch (Address: 0x10044380)
- fclose (Address: 0x10044394)
- fflush (Address: 0x10044388)
- free (Address: 0x100443a8)
- fwprintf (Address: 0x1004435c)
- malloc (Address: 0x100443a4)
- memcmp (Address: 0x100443c0)
- memcpy (Address: 0x100443bc)
- memcpy_s (Address: 0x100443b4)
- memmove (Address: 0x1004437c)
- memmove_s (Address: 0x100443b0)
- memset (Address: 0x100443ec)
- strcpy_s (Address: 0x100443cc)
- strncmp (Address: 0x100443c8)
- swprintf_s (Address: 0x1004432c)
- wcscat_s (Address: 0x10044338)
- wcschr (Address: 0x10044340)
- wcscpy_s (Address: 0x1004434c)
- wcsncmp (Address: 0x10044374)
- wcsncpy_s (Address: 0x10044364)
- wcsnlen (Address: 0x100443d0)
- wcsrchr (Address: 0x100443b8)
- wcsstr (Address: 0x100443d4)
- wcstoul (Address: 0x100443e4)
ntdll.dll
- LdrAccessResource (Address: 0x1004442c)
- LdrFindResource_U (Address: 0x10044428)
- LdrGetDllHandle (Address: 0x100444d8)
- LdrGetProcedureAddress (Address: 0x100444d4)
- NtAdjustPrivilegesToken (Address: 0x10044508)
- NtClose (Address: 0x100443fc)
- NtCreateEvent (Address: 0x10044400)
- NtDeviceIoControlFile (Address: 0x100443f4)
- NtEnumerateBootEntries (Address: 0x10044528)
- NtOpenDirectoryObject (Address: 0x10044498)
- NtOpenFile (Address: 0x10044410)
- NtOpenKey (Address: 0x1004446c)
- NtOpenProcess (Address: 0x1004451c)
- NtOpenProcessTokenEx (Address: 0x1004450c)
- NtOpenSymbolicLinkObject (Address: 0x10044464)
- NtOpenThreadTokenEx (Address: 0x10044510)
- NtQueryBootEntryOrder (Address: 0x10044490)
- NtQueryBootOptions (Address: 0x10044494)
- NtQueryDirectoryObject (Address: 0x1004449c)
- NtQueryInformationFile (Address: 0x10044404)
- NtQueryInformationProcess (Address: 0x10044520)
- NtQueryInformationThread (Address: 0x10044408)
- NtQuerySymbolicLinkObject (Address: 0x10044470)
- NtQuerySystemEnvironmentValueEx (Address: 0x1004453c)
- NtQuerySystemInformation (Address: 0x10044548)
- NtQueryValueKey (Address: 0x1004448c)
- NtReadFile (Address: 0x1004454c)
- NtSetInformationFile (Address: 0x10044418)
- NtSetInformationThread (Address: 0x10044484)
- NtSetSystemEnvironmentValueEx (Address: 0x10044540)
- NtTranslateFilePath (Address: 0x10044534)
- NtWaitForSingleObject (Address: 0x1004440c)
- NtWriteFile (Address: 0x10044524)
- RtlAddAccessAllowedAceEx (Address: 0x10044474)
- RtlAdjustPrivilege (Address: 0x10044530)
- RtlAllocateAndInitializeSid (Address: 0x10044478)
- RtlAllocateHeap (Address: 0x10044430)
- RtlAppendUnicodeToString (Address: 0x10044454)
- RtlCompareMemory (Address: 0x10044424)
- RtlCreateAcl (Address: 0x10044518)
- RtlCreateSecurityDescriptor (Address: 0x10044488)
- RtlFreeHeap (Address: 0x10044420)
- RtlFreeSid (Address: 0x10044480)
- RtlFreeUnicodeString (Address: 0x10044414)
- RtlGetVersion (Address: 0x100444fc)
- RtlGUIDFromString (Address: 0x10044450)
- RtlImageNtHeader (Address: 0x100443f8)
- RtlImageNtHeaderEx (Address: 0x1004452c)
- RtlImpersonateSelf (Address: 0x10044514)
- RtlInitAnsiString (Address: 0x100444e0)
- RtlInitUnicodeString (Address: 0x10044544)
- RtlLengthSecurityDescriptor (Address: 0x1004445c)
- RtlLengthSid (Address: 0x1004447c)
- RtlNtStatusToDosError (Address: 0x10044538)
- RtlSetDaclSecurityDescriptor (Address: 0x10044468)
- RtlSetOwnerSecurityDescriptor (Address: 0x10044460)
- RtlStringFromGUID (Address: 0x1004441c)
- ZwAllocateUuids (Address: 0x10044504)
- ZwClose (Address: 0x10044448)
- ZwCreateFile (Address: 0x100444a0)
- ZwCreateKey (Address: 0x100444a4)
- ZwDeleteKey (Address: 0x100444b8)
- ZwDeleteValueKey (Address: 0x100444b0)
- ZwDeviceIoControlFile (Address: 0x100444f0)
- ZwEnumerateKey (Address: 0x100444bc)
- ZwFlushKey (Address: 0x100444ac)
- ZwLoadKey (Address: 0x100444a8)
- ZwOpenDirectoryObject (Address: 0x10044500)
- ZwOpenFile (Address: 0x10044440)
- ZwOpenKey (Address: 0x100444d0)
- ZwOpenMutant (Address: 0x10044444)
- ZwOpenProcess (Address: 0x100444e8)
- ZwOpenSymbolicLinkObject (Address: 0x100444f8)
- ZwQueryAttributesFile (Address: 0x10044458)
- ZwQueryDirectoryObject (Address: 0x100444f4)
- ZwQueryInformationFile (Address: 0x100444e4)
- ZwQueryInformationProcess (Address: 0x100444dc)
- ZwQueryKey (Address: 0x10044438)
- ZwQuerySymbolicLinkObject (Address: 0x100444ec)
- ZwQuerySystemInformation (Address: 0x1004444c)
- ZwQueryValueKey (Address: 0x100444c0)
- ZwReleaseMutant (Address: 0x1004443c)
- ZwSaveKey (Address: 0x100444b4)
- ZwSetSecurityObject (Address: 0x100444c4)
- ZwSetValueKey (Address: 0x100444cc)
- ZwUnloadKey (Address: 0x100444c8)
- ZwWaitForSingleObject (Address: 0x10044434)
OLEAUT32.dll
- SysAllocString (Address: 0x1004402c)
- SysFreeString (Address: 0x10044034)
- VariantClear (Address: 0x10044030)
- VariantInit (Address: 0x10044028)
RPCRT4.dll
- UuidCreate (Address: 0x1004403c)
WCP.dll
- ?RtlGetFacilityTracingFlags@Rtl@WCP@Windows@@YIKPAU_RTL_TRACING_FACILITY@123@@Z (Address: 0x1004405c)
- ?RtlTraceFormat_PCHRESULT@Rtl@WCP@Windows@@YIXPAUIRtlFormattedOutputStream@13@PBX@Z (Address: 0x10044048)
- ?RtlTraceFormat_PCWSTR@Rtl@WCP@Windows@@YIXPAUIRtlFormattedOutputStream@13@PBX@Z (Address: 0x10044044)
- ?RtlTraceVa@Rtl@WCP@Windows@@YIXKKPAU_RTL_TRACING_FACILITY@123@QBDKPAD@Z (Address: 0x10044054)
- ConvertNtStatusToHResult (Address: 0x1004404c)
- RtlFreeLBlob (Address: 0x10044058)
- RtlReportErrorOrigination (Address: 0x10044050)
WINTRUST.dll
- WinVerifyTrust (Address: 0x1004406c)
- WTHelperGetProvSignerFromChain (Address: 0x10044064)
- WTHelperProvDataFromStateData (Address: 0x10044068)