tcbloader.dll

Description: TCB Loader Library

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.6466

Architecture: 64-bit

Operating System: Windows NT

SHA256: d3b37f7e37d59c15384c6bc84404aed1

File Size: 219.9 KB

Uploaded At: Dec. 1, 2025, 7:40 a.m.

Views: 3

Exported Functions

  • OslGenRandomBytes (Ordinal: 1, Address: 0x177ec)
  • OslGetControlSubkeyCell (Ordinal: 2, Address: 0x15dd4)
  • OslGetExportRoutineInModule (Ordinal: 3, Address: 0x18868)
  • OslGetStringValue (Ordinal: 4, Address: 0x156b0)
  • OslGetValue (Ordinal: 5, Address: 0x15798)
  • OslIsRunningInSecureKernel (Ordinal: 6, Address: 0x184b8)
  • TcbLoadEntry (Ordinal: 7, Address: 0x184cc)
  • TcbResumeEntry (Ordinal: 8, Address: 0x18668)

Imported DLLs & Functions

winload.sys
  • __GSHandlerCheck (Address: 0x18002b198)
  • _stricmp (Address: 0x18002af50)
  • _strupr (Address: 0x18002aab8)
  • _wcsicmp (Address: 0x18002a8d8)
  • _wcsnicmp (Address: 0x18002ab88)
  • _wcstoui64 (Address: 0x18002acf8)
  • _wcsupr (Address: 0x18002ab10)
  • AhCreateLoadOptionsString (Address: 0x18002ac18)
  • ArchBuildKernelGdt (Address: 0x18002a7e8)
  • ArchGetGdtRegister (Address: 0x18002b150)
  • BlAllocateSlabPages (Address: 0x18002acb0)
  • BlAppendBootOptionString (Address: 0x18002aae8)
  • BlAppendUnicodeToString (Address: 0x18002a7a0)
  • BlArchCpuId (Address: 0x18002a7a8)
  • BlArchDetectSmt (Address: 0x18002aee0)
  • BlArchGetCpuVendor (Address: 0x18002aaa0)
  • BlArchGetPerformanceCounter (Address: 0x18002a830)
  • BlArchIsCpuIdFunctionSupported (Address: 0x18002aab0)
  • BlArchIsFiveLevelPagingActive (Address: 0x18002a7c8)
  • BlArchIsShadowStackSupported (Address: 0x18002ac70)
  • BlArchKernelSetup (Address: 0x18002a800)
  • BlArchQueryIoPortAccessSupported (Address: 0x18002abd0)
  • BlArchSetSecrets (Address: 0x18002b080)
  • BlBdDebuggerConnected (Address: 0x18002aa68)
  • BlBdDebugTransitionsEnabled (Address: 0x18002a828)
  • BlBdGetExtensionName (Address: 0x18002aea8)
  • BlBdInitializeDeviceDescriptor (Address: 0x18002aec0)
  • BlBdInitializeTransportExtension (Address: 0x18002aeb8)
  • BlBdLoadImageSymbols (Address: 0x18002aeb0)
  • BlBdPatchIdt (Address: 0x18002a7f0)
  • BlBdReleaseDebuggingDevice (Address: 0x18002aed0)
  • BlBdSetupDebuggingDevice (Address: 0x18002acb8)
  • BlBdStop (Address: 0x18002a790)
  • BlBootOptionExists (Address: 0x18002aac8)
  • BlBsdCloseLog (Address: 0x18002ab18)
  • BlBsdLogEntry (Address: 0x18002af80)
  • BlCopyBootOptions (Address: 0x18002ab58)
  • BlCopyStringToUnicodeString (Address: 0x18002ac30)
  • BlCopyUnicodeStringToUnicodeString (Address: 0x18002ac50)
  • BlCopyWcharStringToString (Address: 0x18002abe8)
  • BlCreateTpmSealedBlob (Address: 0x18002ae28)
  • BlDecryptSealedData (Address: 0x18002ae60)
  • BlDeviceClose (Address: 0x18002a8b0)
  • BlDeviceCompare (Address: 0x18002a9f0)
  • BlDeviceOpen (Address: 0x18002a990)
  • BlDisplayFreeOemBitmap (Address: 0x18002b0b8)
  • BlDisplayGetOemBitmap (Address: 0x18002b0c0)
  • BlDisplayInvalidateOemBitmap (Address: 0x18002b0c8)
  • BlEnNotifyEvent (Address: 0x18002aef0)
  • BlFileClose (Address: 0x18002a8d0)
  • BlFileExists (Address: 0x18002af78)
  • BlFileGetInformation (Address: 0x18002aa80)
  • BlFileLoad (Address: 0x18002ae18)
  • BlFileOpen (Address: 0x18002a920)
  • BlFileReadAtOffsetEx (Address: 0x18002a910)
  • BlFileReadEx (Address: 0x18002aca8)
  • BlFileSetInformation (Address: 0x18002b098)
  • BlFveCheckPermission (Address: 0x18002abe0)
  • BlFwGetAcpiMemoryMap (Address: 0x18002aca0)
  • BlFwGetSystemTable (Address: 0x18002acd8)
  • BlFwQueryEfiRuntimeVaRange (Address: 0x18002b038)
  • BlGetApplicationEntry (Address: 0x18002a8f0)
  • BlGetApplicationIdentifier (Address: 0x18002ab60)
  • BlGetBootDevice (Address: 0x18002a898)
  • BlGetBootOptionBoolean (Address: 0x18002a9f8)
  • BlGetBootOptionDevice (Address: 0x18002a9a0)
  • BlGetBootOptionInteger (Address: 0x18002aa58)
  • BlGetBootOptionString (Address: 0x18002aa20)
  • BlGetDevice (Address: 0x18002ac68)
  • BlGetDeviceIdentifier (Address: 0x18002ab90)
  • BlGetExecutionEnvironment (Address: 0x18002ab00)
  • BlImgFindSection (Address: 0x18002ab78)
  • BlImgGetPEImageSize (Address: 0x18002abb8)
  • BlImgGetSigningPolicy (Address: 0x18002a840)
  • BlImgGetWhqlEnforcementDateTime (Address: 0x18002a858)
  • BlImgIsBootUpgradedPlatform (Address: 0x18002aa38)
  • BlImgIsUpgradedPlatform (Address: 0x18002a848)
  • BlImgIsUpgradeInProgress (Address: 0x18002aa60)
  • BlImgIsWhqlDeveloperTestModeEnabled (Address: 0x18002aa08)
  • BlImgIsWhqlDisabledBySetting (Address: 0x18002aa78)
  • BlImgIsWhqlEnabledBySetting (Address: 0x18002a9e0)
  • BlImgIsWinPE (Address: 0x18002a850)
  • BlImgLoadImageWithProgress2 (Address: 0x18002ab30)
  • BlImgLoadPEImageEx (Address: 0x18002b0b0)
  • BlImgLoadPEImageWithPolicyValidatedHash (Address: 0x18002b0a8)
  • BlImgQueryCodeIntegrityBootOptions (Address: 0x18002a9d8)
  • BlImgRegisterCodeIntegrityCatalogDirectory (Address: 0x18002a8e8)
  • BlImgRegisterCodeIntegrityCatalogs (Address: 0x18002a8a8)
  • BlImgSetRestrictedSigning (Address: 0x18002a8f8)
  • BlImgSetSigningPolicy (Address: 0x18002a970)
  • BlImgSetSysDevWhqlPolicy (Address: 0x18002a8a0)
  • BlImgTrustCustomSignersForDrivers (Address: 0x18002a980)
  • BlImgUnLoadImage (Address: 0x18002aa10)
  • BlImgVerifyFontIntegrity (Address: 0x18002b088)
  • BlLdrBuildImagePath (Address: 0x18002a960)
  • BlLdrFreeDataTableEntry (Address: 0x18002a938)
  • BlLdrLoadDll (Address: 0x18002ae98)
  • BlLdrLoadImage (Address: 0x18002ac48)
  • BlLdrPreloadFile (Address: 0x18002a9b0)
  • BlLdrPreloadImage (Address: 0x18002ac38)
  • BlLdrUnloadImage (Address: 0x18002aec8)
  • BlLogDestroy (Address: 0x18002aac0)
  • BlLogDiagWrite (Address: 0x18002aaf0)
  • BlLogEtwRegister (Address: 0x18002b048)
  • BlLogEtwWrite (Address: 0x18002ada0)
  • BlLogEtwWriteTransfer (Address: 0x18002ab28)
  • BlLogInitialize (Address: 0x18002ab70)
  • BlMmAddEnclavePageRange (Address: 0x18002aaa8)
  • BlMmAllocateHeap (Address: 0x18002a900)
  • BlMmAllocatePages (Address: 0x18002a7f8)
  • BlMmAllocatePhysicalPages (Address: 0x18002a808)
  • BlMmAllocateVirtualPages (Address: 0x18002ab68)
  • BlMmDisableStaticDescriptors (Address: 0x18002ab40)
  • BlMmEnableStaticDescriptors (Address: 0x18002ac60)
  • BlMmEnumerateAllocations (Address: 0x18002abf0)
  • BlMmFlushTlb (Address: 0x18002b148)
  • BlMmFreeHeap (Address: 0x18002a9e8)
  • BlMmFreePages (Address: 0x18002a818)
  • BlMmFreePhysicalPages (Address: 0x18002a810)
  • BlMmFreeVirtualPages (Address: 0x18002b130)
  • BlMmGetMemoryMap (Address: 0x18002ab08)
  • BlMmInitMemoryMapHandle (Address: 0x18002ab98)
  • BlMmMapPhysicalAddress (Address: 0x18002a7e0)
  • BlMmMapPhysicalAddressEx (Address: 0x18002aad8)
  • BlMmQueryLargePageSize (Address: 0x18002aae0)
  • BlMmReleaseMemoryMap (Address: 0x18002ab38)
  • BlMmRemapVirtualAddress (Address: 0x18002b140)
  • BlMmTranslateEfiMemoryType (Address: 0x18002b058)
  • BlMmTranslateVirtualAddress (Address: 0x18002abf8)
  • BlMmUnmapVirtualAddress (Address: 0x18002a820)
  • BlMmUnmapVirtualAddressEx (Address: 0x18002b138)
  • BlNumaGetNumaMemoryRanges (Address: 0x18002abc8)
  • BlObtainUnusedSlabPages (Address: 0x18002ac98)
  • BlPdDestroyData (Address: 0x18002abb0)
  • BlPdFreeData (Address: 0x18002af70)
  • BlPdQueryDataAll (Address: 0x18002ac80)
  • BlPdSaveData (Address: 0x18002ad80)
  • BlpPdQueryData (Address: 0x18002a940)
  • BlpPdReleaseData (Address: 0x18002a918)
  • BlRemoveBootOption (Address: 0x18002ab20)
  • BlResourceFindDataFromImage (Address: 0x18002b0a0)
  • BlResourceFindMessage (Address: 0x18002af88)
  • BlResourceGetLanguageMapping (Address: 0x18002b090)
  • BlSealSecretToCurrentPcrValues (Address: 0x18002ad88)
  • BlSecureBootGetNonVolatilePrivateVariable (Address: 0x18002aa00)
  • BlSecureBootIgnoreSingleBootOption (Address: 0x18002ac20)
  • BlSecureBootSetVolatilePrivateVariable (Address: 0x18002b160)
  • BlSiDrtmEnvironmentUnsafe (Address: 0x18002ae10)
  • BlSiEnterInsecureStateEx (Address: 0x18002af28)
  • BlSiEnvironmentReady (Address: 0x18002aee8)
  • BlSiFlushCurrentMeasurements (Address: 0x18002add8)
  • BlSiHandleHypervisorLaunchEvent (Address: 0x18002aea0)
  • BlSiLeaveEnvironment (Address: 0x18002af30)
  • BlSiPaRecordConfigEvent (Address: 0x18002aef8)
  • BlSiPaRecordDrtmConfigEvent (Address: 0x18002ae08)
  • BlSIPolicyCheckPolicyOnDevice (Address: 0x18002a958)
  • BlSIPolicyDoesActivePolicyGrantPermission (Address: 0x18002abc0)
  • BlSIPolicyLoadAndActivateTemporalPolicy (Address: 0x18002a9d0)
  • BlSiSetDrtmEnvironmentUnsafe (Address: 0x18002ae90)
  • BlSlGetSmmIsolationLevel (Address: 0x18002b060)
  • BlStatusError (Address: 0x18002af90)
  • BlStatusPrint (Address: 0x18002a888)
  • BlStatusRegisterErrorHandler (Address: 0x18002aba0)
  • BlSvnGetApplicationSvn (Address: 0x18002ad00)
  • BlSvnGetChainStatus (Address: 0x18002ad08)
  • BlSymCryptGetAesBlockCipher (Address: 0x18002ada8)
  • BlSymCryptGetHmacSha256Algorithm (Address: 0x18002b180)
  • BlTblSetEntry (Address: 0x18002af58)
  • BlTcgFwSetAndLockMemoryOverwriteRequestControl (Address: 0x18002ad10)
  • BlTimeQueryPerformanceCounter (Address: 0x18002ac10)
  • BlTpmGetRandom (Address: 0x18002afa0)
  • BlTpmShutdown (Address: 0x18002aaf8)
  • BlTpmStatus (Address: 0x18002a968)
  • BlUpdateBootOptions (Address: 0x18002abd8)
  • BlUtlCheckSum (Address: 0x18002af40)
  • BlUtlGetAcpiTable (Address: 0x18002a7b0)
  • BlUtlGetAcpiTableOverrides (Address: 0x18002ac00)
  • BlUtlPopulateAcpiTableCache (Address: 0x18002acd0)
  • BlUtlSetAcpiTableOverrides (Address: 0x18002af38)
  • BlUtlValidateMemoryRange (Address: 0x18002b128)
  • BlValidateAmeCertChain (Address: 0x18002acc0)
  • BlValidateAnsiStringMemory (Address: 0x18002b078)
  • BlValidateListMemory (Address: 0x18002b068)
  • BlValidateMemoryRange (Address: 0x18002ae30)
  • BlValidatePhysicalMemoryRange (Address: 0x18002b070)
  • BlValidateWideStringMemory (Address: 0x18002b050)
  • BlVsmCheckSystemPolicy (Address: 0x18002ac78)
  • BlVsmGetSystemPolicy (Address: 0x18002aa48)
  • BlVsmKeysAddNewKeyToArray (Address: 0x18002adf0)
  • BlVsmKeysCreateKeyPkg (Address: 0x18002ae48)
  • BlVsmKeysExplodePkg (Address: 0x18002ae68)
  • BlVsmKeysFindKeyMapByType (Address: 0x18002ae50)
  • BlVsmKeysGetCurrentLKeyRefFromArray (Address: 0x18002acf0)
  • BlVsmKeysGetCurrentLKeyRefFromPkg (Address: 0x18002b158)
  • BlVsmKeysReadAndUnsealLKeyPkg (Address: 0x18002b178)
  • BlVsmKeysSupportedByPlatform (Address: 0x18002b168)
  • BlVsmKeysValidateKeyPkgBuffer (Address: 0x18002ae40)
  • DbgLoadImageSymbols (Address: 0x18002acc8)
  • EfiGetMemoryAttributesTable (Address: 0x18002b040)
  • KdNetGetNetDataSize (Address: 0x18002ace8)
  • LdrInitSecurityCookie (Address: 0x18002ac58)
  • McGenEventWriteBoot (Address: 0x18002aad0)
  • memcmp (Address: 0x18002b1a0)
  • memcpy (Address: 0x18002b1a8)
  • memmove (Address: 0x18002b1b0)
  • memset (Address: 0x18002b190)
  • MinCrypL_HashMemory (Address: 0x18002a878)
  • MincryptSetWeakCryptoPolicy (Address: 0x18002a8e0)
  • OslGetDrtmSvn (Address: 0x18002ae70)
  • qsort (Address: 0x18002a948)
  • rsa_construction_fips186_3 (Address: 0x18002ad40)
  • rsa_decryption (Address: 0x18002ad70)
  • rsa_destruction (Address: 0x18002ade0)
  • rsa_encryption (Address: 0x18002ad28)
  • rsa_export (Address: 0x18002adc0)
  • rsa_export_sizes (Address: 0x18002ad60)
  • RtlAnsiStringToUnicodeString (Address: 0x18002a798)
  • RtlAppendUnicodeStringToString (Address: 0x18002b0d8)
  • RtlAppendUnicodeToString (Address: 0x18002ac90)
  • RtlClearAllBits (Address: 0x18002b118)
  • RtlClearBits (Address: 0x18002b120)
  • RtlCompareMemory (Address: 0x18002af60)
  • RtlCompareUnicodeString (Address: 0x18002b0d0)
  • RtlCompareUnicodeStrings (Address: 0x18002b188)
  • RtlEqualUnicodeString (Address: 0x18002a8b8)
  • RtlFindExportedRoutineByName (Address: 0x18002a880)
  • RtlFreeUnicodeString (Address: 0x18002a7b8)
  • RtlGUIDFromString (Address: 0x18002a890)
  • RtlImageDirectoryEntryToData (Address: 0x18002ac28)
  • RtlInitAnsiString (Address: 0x18002a7d0)
  • RtlInitializeBitMap (Address: 0x18002b0f0)
  • RtlInitializeBootFeatureConfigurations (Address: 0x18002b020)
  • RtlInitUnicodeString (Address: 0x18002a7c0)
  • RtlInitUnicodeStringEx (Address: 0x18002a998)
  • RtlPrefixUnicodeString (Address: 0x18002ac40)
  • RtlSetBits (Address: 0x18002b0f8)
  • RtlStringFromGUID (Address: 0x18002b0e0)
  • RtlUnicodeStringToAnsiString (Address: 0x18002af68)
  • RtlUpcaseUnicodeChar (Address: 0x18002b110)
  • RtlValidateDelayedFeatureUsageReportBuffer (Address: 0x18002b028)
  • RtlValidateFeatureConfigurationBuffer (Address: 0x18002b030)
  • RtlValidateFeatureUsageSubscriptionBuffer (Address: 0x18002b018)
  • SbArePolicyOptionsSet (Address: 0x18002a870)
  • SbDoesActivePolicyGrantPermission (Address: 0x18002ac08)
  • SbFreeFileData (Address: 0x18002a9a8)
  • SbGetKernelPolicyPackage (Address: 0x18002aa88)
  • SbGetSizeOfKernelPolicyPackage (Address: 0x18002a860)
  • SbIsDebugPolicyActive (Address: 0x18002aa90)
  • SbIsEnabled (Address: 0x18002a8c8)
  • SbIsEnabled2 (Address: 0x18002ace0)
  • SbIsPolicyActive (Address: 0x18002aba8)
  • SbIsTestRootTrusted (Address: 0x18002a9c8)
  • SbIsTestSigningBlocked (Address: 0x18002ac88)
  • SbLoadFile (Address: 0x18002a908)
  • SbValidateSkuUnlockToken (Address: 0x18002aa28)
  • SipaGetDataPointers (Address: 0x18002af00)
  • SipapAppendEntry (Address: 0x18002af08)
  • SipapCreateQueue (Address: 0x18002af20)
  • SipaQueueConfigEntry (Address: 0x18002ad20)
  • SipaQueueConfigEntryToQueue (Address: 0x18002af18)
  • SIPolicyClearAllActivePolicy (Address: 0x18002a988)
  • SIPolicyDeletePersistentVariable (Address: 0x18002aa70)
  • SIPolicyGetOptions (Address: 0x18002a9c0)
  • SIPolicyGetPolicyHandle (Address: 0x18002aa18)
  • SIPolicyGetPolicyInfoFromType (Address: 0x18002aa98)
  • SIPolicyGetSerializedPolicies (Address: 0x18002aa50)
  • SIPolicyGetSerializedPoliciesSize (Address: 0x18002a950)
  • SIPolicyHashActiveCodeExecutionPolicies (Address: 0x18002a978)
  • SIPolicyInvalidateEAsOnRebootEnabled (Address: 0x18002a8c0)
  • SIPolicyIsPolicyActive (Address: 0x18002a9b8)
  • SIPolicyIsSignedPolicyRequired (Address: 0x18002a868)
  • SIPolicySetTrialMode (Address: 0x18002aa30)
  • SIPolicyUmciEnabled (Address: 0x18002aa40)
  • sprintf_s (Address: 0x18002b0e8)
  • strcat_s (Address: 0x18002a7d8)
  • strcpy_s (Address: 0x18002af48)
  • strstr (Address: 0x18002ab80)
  • swprintf_s (Address: 0x18002ab48)
  • SymCryptGcmAuthPart (Address: 0x18002ad90)
  • SymCryptGcmDecryptFinal (Address: 0x18002ad38)
  • SymCryptGcmDecryptPart (Address: 0x18002adb8)
  • SymCryptGcmEncryptFinal (Address: 0x18002ad30)
  • SymCryptGcmEncryptPart (Address: 0x18002ad18)
  • SymCryptGcmExpandKey (Address: 0x18002ad68)
  • SymCryptGcmInit (Address: 0x18002ad58)
  • SymCryptHmacSha512Selftest (Address: 0x18002afe0)
  • SymCryptInit (Address: 0x18002b100)
  • SymCryptMarvin32ExpandSeed (Address: 0x18002b108)
  • SymCryptRdrandGet (Address: 0x18002afb8)
  • SymCryptRdrandStatus (Address: 0x18002afd0)
  • SymCryptRdseedGet (Address: 0x18002aff8)
  • SymCryptRdseedStatus (Address: 0x18002afa8)
  • SymCryptRngAesFips140_2Generate (Address: 0x18002afe8)
  • SymCryptRngAesFips140_2Instantiate (Address: 0x18002b010)
  • SymCryptRngAesFips140_2Uninstantiate (Address: 0x18002aff0)
  • SymCryptRngAesGenerateSelftest (Address: 0x18002b008)
  • SymCryptRngAesInstantiateSelftest (Address: 0x18002afb0)
  • SymCryptRngAesReseedSelftest (Address: 0x18002af98)
  • SymCryptSha1 (Address: 0x18002af10)
  • SymCryptSha256 (Address: 0x18002adc8)
  • SymCryptSha256Append (Address: 0x18002ad50)
  • SymCryptSha256Init (Address: 0x18002add0)
  • SymCryptSha256Result (Address: 0x18002adb0)
  • SymCryptSha512 (Address: 0x18002b000)
  • SymCryptSha512Append (Address: 0x18002afc8)
  • SymCryptSha512Init (Address: 0x18002afd8)
  • SymCryptSha512Result (Address: 0x18002afc0)
  • SymCryptSp800_108 (Address: 0x18002b170)
  • TpmApiCheckSecureNVIndex20 (Address: 0x18002ad48)
  • TpmApiCreateSecureNVIndex20 (Address: 0x18002ad98)
  • TpmApiCreateSrk20 (Address: 0x18002ae00)
  • TpmApiDrtmGetSigningKeys (Address: 0x18002ae20)
  • TpmApiGetKeyPublicProperty20 (Address: 0x18002ae80)
  • TpmApiGetTpmVersion (Address: 0x18002ade8)
  • TpmApiIsCurrentStatePolicyAuthorized20 (Address: 0x18002ae38)
  • TpmApiReadPublic20 (Address: 0x18002ae88)
  • TpmApiSealPolicyAuthorized20 (Address: 0x18002adf8)
  • TpmApiUnsealEx (Address: 0x18002ad78)
  • TpmApiUnsealPolicyAuthorized20 (Address: 0x18002ae58)
  • wcscat_s (Address: 0x18002a930)
  • wcscmp (Address: 0x18002b1b8)
  • wcscpy_s (Address: 0x18002a928)
  • wcsncmp (Address: 0x18002ae78)
  • wcsnlen (Address: 0x18002a838)
  • wcsrchr (Address: 0x18002aed8)
  • wcsstr (Address: 0x18002ab50)