securebootai.dll
Description: CSI Secure Boot Servicing Plugin
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.5547
Architecture: 32-bit
Operating System: Windows NT
SHA256: 731526cf9d0eaf1825a733b244cfb7f6
File Size: 292.4 KB
Uploaded At: Dec. 1, 2025, 8:40 a.m.
Views: 31
Exported Functions
- DllCanUnloadNow (Ordinal: 1, Address: 0x1e6a0)
- DllCsiGetHandler (Ordinal: 2, Address: 0x1e6c0)
Imported DLLs & Functions
api-ms-win-core-com-l1-1-0.dll
- CoCreateInstance (Address: 0x10043078)
- CoInitializeEx (Address: 0x10043074)
- CoInitializeSecurity (Address: 0x10043080)
- CoSetProxyBlanket (Address: 0x10043070)
- CoUninitialize (Address: 0x1004307c)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x1004308c)
- IsDebuggerPresent (Address: 0x10043090)
- OutputDebugStringW (Address: 0x10043088)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x10043098)
- SetLastError (Address: 0x100430a4)
- SetUnhandledExceptionFilter (Address: 0x100430a0)
- UnhandledExceptionFilter (Address: 0x1004309c)
api-ms-win-core-file-l1-1-0.dll
- CreateDirectoryW (Address: 0x100430d4)
- CreateFileW (Address: 0x100430f0)
- DeleteFileW (Address: 0x100430dc)
- FindClose (Address: 0x100430e4)
- FindFirstFileW (Address: 0x100430d0)
- FindNextFileW (Address: 0x100430e0)
- FlushFileBuffers (Address: 0x100430b4)
- GetFileAttributesW (Address: 0x100430b0)
- GetFileInformationByHandle (Address: 0x100430c4)
- GetFileSizeEx (Address: 0x100430d8)
- GetFullPathNameW (Address: 0x100430e8)
- GetVolumeInformationW (Address: 0x100430b8)
- GetVolumePathNameW (Address: 0x100430ec)
- QueryDosDeviceW (Address: 0x100430ac)
- ReadFile (Address: 0x100430cc)
- SetFileAttributesW (Address: 0x100430bc)
- SetFileInformationByHandle (Address: 0x100430c8)
- WriteFile (Address: 0x100430c0)
api-ms-win-core-file-l1-2-0.dll
- GetVolumeNameForVolumeMountPointW (Address: 0x100430f8)
api-ms-win-core-file-l2-1-0.dll
- CopyFileExW (Address: 0x10043104)
- GetFileInformationByHandleEx (Address: 0x10043100)
- MoveFileExW (Address: 0x10043108)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x10043110)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x1004311c)
- HeapAlloc (Address: 0x10043118)
- HeapDestroy (Address: 0x10043124)
- HeapFree (Address: 0x10043120)
api-ms-win-core-heap-obsolete-l1-1-0.dll
- LocalAlloc (Address: 0x10043130)
- LocalFree (Address: 0x1004312c)
api-ms-win-core-interlocked-l1-1-0.dll
- InitializeSListHead (Address: 0x10043138)
api-ms-win-core-io-l1-1-0.dll
- DeviceIoControl (Address: 0x10043140)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
- FindResourceW (Address: 0x10043148)
- LoadLibraryW (Address: 0x1004314c)
api-ms-win-core-libraryloader-l1-1-0.dll
- DisableThreadLibraryCalls (Address: 0x10043164)
- FindResourceExW (Address: 0x1004315c)
- FreeLibrary (Address: 0x10043174)
- GetModuleFileNameA (Address: 0x10043158)
- GetModuleHandleExW (Address: 0x1004316c)
- GetModuleHandleW (Address: 0x10043160)
- GetProcAddress (Address: 0x10043168)
- LoadLibraryExW (Address: 0x10043154)
- LoadResource (Address: 0x10043170)
- SizeofResource (Address: 0x10043178)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x10043180)
- GetLocaleInfoW (Address: 0x10043184)
api-ms-win-core-localization-obsolete-l1-2-0.dll
- GetSystemDefaultUILanguage (Address: 0x1004318c)
- GetUserDefaultUILanguage (Address: 0x10043190)
api-ms-win-core-memory-l1-1-0.dll
- CreateFileMappingW (Address: 0x100431a0)
- MapViewOfFile (Address: 0x1004319c)
- UnmapViewOfFile (Address: 0x10043198)
api-ms-win-core-privateprofile-l1-1-0.dll
- GetPrivateProfileSectionW (Address: 0x100431a8)
api-ms-win-core-processenvironment-l1-1-0.dll
- SearchPathW (Address: 0x100431b0)
api-ms-win-core-processthreads-l1-1-0.dll
- GetCurrentProcess (Address: 0x100431c0)
- GetCurrentProcessId (Address: 0x100431cc)
- GetCurrentThread (Address: 0x100431c8)
- GetCurrentThreadId (Address: 0x100431d4)
- OpenProcessToken (Address: 0x100431b8)
- OpenThreadToken (Address: 0x100431c4)
- SetThreadToken (Address: 0x100431d0)
- TerminateProcess (Address: 0x100431bc)
api-ms-win-core-processthreads-l1-1-1.dll
- IsProcessorFeaturePresent (Address: 0x100431dc)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x100431e4)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x100431ec)
- RegCreateKeyExW (Address: 0x100431f8)
- RegDeleteKeyExW (Address: 0x100431f0)
- RegGetValueW (Address: 0x100431f4)
- RegOpenKeyExW (Address: 0x10043200)
- RegQueryValueExW (Address: 0x10043204)
- RegSetValueExW (Address: 0x100431fc)
api-ms-win-core-shlwapi-legacy-l1-1-0.dll
- PathRemoveBackslashW (Address: 0x1004320c)
api-ms-win-core-shlwapi-obsolete-l1-1-0.dll
- StrCmpIW (Address: 0x10043214)
- StrStrIW (Address: 0x10043218)
api-ms-win-core-string-l1-1-0.dll
- MultiByteToWideChar (Address: 0x10043220)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x10043264)
- AcquireSRWLockShared (Address: 0x1004325c)
- CreateMutexExW (Address: 0x10043234)
- CreateSemaphoreExW (Address: 0x1004322c)
- DeleteCriticalSection (Address: 0x10043240)
- EnterCriticalSection (Address: 0x10043248)
- InitializeCriticalSection (Address: 0x10043228)
- InitializeCriticalSectionEx (Address: 0x10043244)
- LeaveCriticalSection (Address: 0x10043230)
- OpenSemaphoreW (Address: 0x10043238)
- ReleaseMutex (Address: 0x10043250)
- ReleaseSemaphore (Address: 0x10043254)
- ReleaseSRWLockExclusive (Address: 0x10043260)
- ReleaseSRWLockShared (Address: 0x10043258)
- WaitForSingleObject (Address: 0x1004323c)
- WaitForSingleObjectEx (Address: 0x1004324c)
api-ms-win-core-synch-l1-2-0.dll
- InitOnceBeginInitialize (Address: 0x1004326c)
- InitOnceComplete (Address: 0x10043274)
- Sleep (Address: 0x10043270)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemDirectoryW (Address: 0x10043280)
- GetSystemInfo (Address: 0x1004327c)
- GetSystemTimeAsFileTime (Address: 0x10043288)
- GetVersionExW (Address: 0x1004328c)
- GetWindowsDirectoryW (Address: 0x10043284)
api-ms-win-core-threadpool-l1-2-0.dll
- CloseThreadpoolTimer (Address: 0x10043294)
- CreateThreadpoolTimer (Address: 0x100432a0)
- SetThreadpoolTimer (Address: 0x1004329c)
- WaitForThreadpoolTimerCallbacks (Address: 0x10043298)
api-ms-win-crt-private-l1-1-0.dll
- __CxxFrameHandler3 (Address: 0x10043320)
- _CxxThrowException (Address: 0x1004335c)
- _except_handler4_common (Address: 0x10043308)
- _o___acrt_iob_func (Address: 0x10043354)
- _o___std_exception_copy (Address: 0x1004334c)
- _o___std_exception_destroy (Address: 0x10043348)
- _o___std_type_info_destroy_list (Address: 0x10043344)
- _o___stdio_common_vfwprintf (Address: 0x10043340)
- _o___stdio_common_vsnprintf_s (Address: 0x1004333c)
- _o___stdio_common_vsnwprintf_s (Address: 0x10043338)
- _o___stdio_common_vswprintf (Address: 0x10043334)
- _o___stdio_common_vswprintf_s (Address: 0x10043330)
- _o___stdio_common_vswscanf (Address: 0x1004332c)
- _o__callnewh (Address: 0x1004331c)
- _o__cexit (Address: 0x10043318)
- _o__configure_narrow_argv (Address: 0x10043314)
- _o__crt_atexit (Address: 0x10043310)
- _o__errno (Address: 0x10043358)
- _o__execute_onexit_table (Address: 0x10043350)
- _o__initialize_narrow_environment (Address: 0x100432a8)
- _o__initialize_onexit_table (Address: 0x100432ac)
- _o__invalid_parameter_noinfo (Address: 0x100432b0)
- _o__purecall (Address: 0x100432b4)
- _o__register_onexit_function (Address: 0x100432b8)
- _o__seh_filter_dll (Address: 0x100432bc)
- _o__ultow_s (Address: 0x100432c0)
- _o__wcsicmp (Address: 0x100432c4)
- _o__wcslwr (Address: 0x100432c8)
- _o__wcsnicmp (Address: 0x100432cc)
- _o__wcsupr (Address: 0x100432d4)
- _o__wfopen_s (Address: 0x100432d8)
- _o_bsearch (Address: 0x100432dc)
- _o_fclose (Address: 0x100432e0)
- _o_fflush (Address: 0x100432e4)
- _o_free (Address: 0x100432e8)
- _o_malloc (Address: 0x100432ec)
- _o_strcpy_s (Address: 0x100432f0)
- _o_terminate (Address: 0x100432f4)
- _o_wcscat_s (Address: 0x100432f8)
- _o_wcscpy_s (Address: 0x100432fc)
- _o_wcsncpy_s (Address: 0x10043300)
- _o_wcstoul (Address: 0x10043304)
- memcmp (Address: 0x10043360)
- memcpy (Address: 0x10043364)
- memmove (Address: 0x100432d0)
- wcschr (Address: 0x10043328)
- wcsrchr (Address: 0x10043324)
- wcsstr (Address: 0x1004330c)
api-ms-win-crt-runtime-l1-1-0.dll
- _initterm (Address: 0x10043370)
- _initterm_e (Address: 0x1004336c)
api-ms-win-crt-string-l1-1-0.dll
- memset (Address: 0x10043378)
- strncmp (Address: 0x1004337c)
- wcsncmp (Address: 0x10043384)
- wcsnlen (Address: 0x10043380)
api-ms-win-eventing-provider-l1-1-0.dll
- EventRegister (Address: 0x10043394)
- EventUnregister (Address: 0x1004338c)
- EventWriteTransfer (Address: 0x10043390)
api-ms-win-security-base-l1-1-0.dll
- AdjustTokenPrivileges (Address: 0x100433a4)
- DuplicateTokenEx (Address: 0x100433b0)
- GetSecurityDescriptorControl (Address: 0x100433a0)
- GetSecurityDescriptorDacl (Address: 0x100433b8)
- GetSecurityDescriptorGroup (Address: 0x100433b4)
- GetSecurityDescriptorOwner (Address: 0x100433a8)
- GetSecurityDescriptorSacl (Address: 0x1004339c)
- GetTokenInformation (Address: 0x100433ac)
api-ms-win-security-lsalookup-l2-1-0.dll
- LookupPrivilegeValueW (Address: 0x100433c0)
api-ms-win-security-provider-l1-1-0.dll
- SetNamedSecurityInfoW (Address: 0x100433c8)
api-ms-win-security-sddl-l1-1-0.dll
- ConvertSidToStringSidW (Address: 0x100433d0)
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x100433d4)
bcrypt.dll
- BCryptCloseAlgorithmProvider (Address: 0x100433e8)
- BCryptCreateHash (Address: 0x100433e4)
- BCryptDestroyHash (Address: 0x100433f4)
- BCryptFinishHash (Address: 0x100433e0)
- BCryptHash (Address: 0x100433ec)
- BCryptHashData (Address: 0x100433f0)
- BCryptOpenAlgorithmProvider (Address: 0x100433dc)
CRYPT32.dll
- CertCloseStore (Address: 0x1004301c)
- CertCreateCertificateContext (Address: 0x10043018)
- CertFindCertificateInStore (Address: 0x10043004)
- CertFreeCertificateContext (Address: 0x10043010)
- CertGetCertificateContextProperty (Address: 0x10043008)
- CertGetNameStringW (Address: 0x10043020)
- CryptMsgClose (Address: 0x1004300c)
- CryptMsgGetParam (Address: 0x10043000)
- CryptQueryObject (Address: 0x10043014)
imagehlp.dll
- CheckSumMappedFile (Address: 0x100433fc)
ntdll.dll
- LdrAccessResource (Address: 0x10043458)
- LdrFindResource_U (Address: 0x10043454)
- LdrGetDllHandle (Address: 0x10043504)
- LdrGetProcedureAddress (Address: 0x10043500)
- NtAdjustPrivilegesToken (Address: 0x10043534)
- NtClose (Address: 0x10043428)
- NtCreateEvent (Address: 0x1004342c)
- NtDeviceIoControlFile (Address: 0x10043420)
- NtEnumerateBootEntries (Address: 0x10043408)
- NtOpenDirectoryObject (Address: 0x100434c4)
- NtOpenFile (Address: 0x1004343c)
- NtOpenKey (Address: 0x10043498)
- NtOpenProcess (Address: 0x10043414)
- NtOpenProcessTokenEx (Address: 0x10043538)
- NtOpenSymbolicLinkObject (Address: 0x10043490)
- NtOpenThreadTokenEx (Address: 0x1004353c)
- NtQueryBootEntryOrder (Address: 0x100434bc)
- NtQueryBootOptions (Address: 0x100434c0)
- NtQueryDirectoryObject (Address: 0x100434c8)
- NtQueryInformationFile (Address: 0x10043430)
- NtQueryInformationProcess (Address: 0x10043410)
- NtQueryInformationThread (Address: 0x10043434)
- NtQuerySymbolicLinkObject (Address: 0x10043558)
- NtQuerySystemEnvironmentValueEx (Address: 0x10043548)
- NtQuerySystemInformation (Address: 0x10043554)
- NtQueryValueKey (Address: 0x100434b8)
- NtReadFile (Address: 0x10043418)
- NtSetInformationFile (Address: 0x10043444)
- NtSetInformationThread (Address: 0x1004341c)
- NtSetSystemEnvironmentValueEx (Address: 0x1004354c)
- NtTranslateFilePath (Address: 0x1004345c)
- NtWaitForSingleObject (Address: 0x10043438)
- NtWriteFile (Address: 0x1004340c)
- RtlAddAccessAllowedAceEx (Address: 0x100434a0)
- RtlAdjustPrivilege (Address: 0x10043544)
- RtlAllocateAndInitializeSid (Address: 0x100434a4)
- RtlAllocateHeap (Address: 0x1004355c)
- RtlAppendUnicodeToString (Address: 0x10043480)
- RtlCompareMemory (Address: 0x10043450)
- RtlCreateAcl (Address: 0x100434b0)
- RtlCreateSecurityDescriptor (Address: 0x100434b4)
- RtlFreeHeap (Address: 0x1004344c)
- RtlFreeSid (Address: 0x100434ac)
- RtlFreeUnicodeString (Address: 0x10043440)
- RtlGetVersion (Address: 0x10043528)
- RtlGUIDFromString (Address: 0x1004347c)
- RtlImageNtHeader (Address: 0x10043424)
- RtlImageNtHeaderEx (Address: 0x10043404)
- RtlImpersonateSelf (Address: 0x10043540)
- RtlInitAnsiString (Address: 0x1004350c)
- RtlInitUnicodeString (Address: 0x10043550)
- RtlLengthSecurityDescriptor (Address: 0x10043488)
- RtlLengthSid (Address: 0x100434a8)
- RtlNtStatusToDosError (Address: 0x1004349c)
- RtlSetDaclSecurityDescriptor (Address: 0x10043494)
- RtlSetOwnerSecurityDescriptor (Address: 0x1004348c)
- RtlStringFromGUID (Address: 0x10043448)
- ZwAllocateUuids (Address: 0x10043530)
- ZwClose (Address: 0x10043474)
- ZwCreateFile (Address: 0x100434cc)
- ZwCreateKey (Address: 0x100434d0)
- ZwDeleteKey (Address: 0x100434e4)
- ZwDeleteValueKey (Address: 0x100434dc)
- ZwDeviceIoControlFile (Address: 0x1004351c)
- ZwEnumerateKey (Address: 0x100434e8)
- ZwFlushKey (Address: 0x100434d8)
- ZwLoadKey (Address: 0x100434d4)
- ZwOpenDirectoryObject (Address: 0x1004352c)
- ZwOpenFile (Address: 0x1004346c)
- ZwOpenKey (Address: 0x100434fc)
- ZwOpenMutant (Address: 0x10043470)
- ZwOpenProcess (Address: 0x10043514)
- ZwOpenSymbolicLinkObject (Address: 0x10043524)
- ZwQueryAttributesFile (Address: 0x10043484)
- ZwQueryDirectoryObject (Address: 0x10043520)
- ZwQueryInformationFile (Address: 0x10043510)
- ZwQueryInformationProcess (Address: 0x10043508)
- ZwQueryKey (Address: 0x10043464)
- ZwQuerySymbolicLinkObject (Address: 0x10043518)
- ZwQuerySystemInformation (Address: 0x10043478)
- ZwQueryValueKey (Address: 0x100434ec)
- ZwReleaseMutant (Address: 0x10043468)
- ZwSaveKey (Address: 0x100434e0)
- ZwSetSecurityObject (Address: 0x100434f0)
- ZwSetValueKey (Address: 0x100434f8)
- ZwUnloadKey (Address: 0x100434f4)
- ZwWaitForSingleObject (Address: 0x10043460)
OLEAUT32.dll
- SysAllocString (Address: 0x1004302c)
- SysFreeString (Address: 0x10043034)
- VariantClear (Address: 0x10043030)
- VariantInit (Address: 0x10043028)
RPCRT4.dll
- UuidCreate (Address: 0x1004303c)
WCP.dll
- ?RtlGetFacilityTracingFlags@Rtl@WCP@Windows@@YIKPAU_RTL_TRACING_FACILITY@123@@Z (Address: 0x10043044)
- ?RtlTraceFormat_PCWSTR@Rtl@WCP@Windows@@YIXPAUIRtlFormattedOutputStream@13@PBX@Z (Address: 0x10043058)
- ?RtlTraceVa@Rtl@WCP@Windows@@YIXKKPAU_RTL_TRACING_FACILITY@123@QBDKPAD@Z (Address: 0x1004304c)
- ConvertNtStatusToHResult (Address: 0x10043054)
- RtlFreeLBlob (Address: 0x10043048)
- RtlReportErrorOrigination (Address: 0x10043050)
WINTRUST.dll
- WinVerifyTrust (Address: 0x10043068)
- WTHelperGetProvSignerFromChain (Address: 0x10043064)
- WTHelperProvDataFromStateData (Address: 0x10043060)