tcbloader.dll
Description: TCB Loader Library
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.6466
Architecture: 64-bit
Operating System: Windows NT
SHA256: d3b37f7e37d59c15384c6bc84404aed1
File Size: 219.9 KB
Uploaded At: Dec. 1, 2025, 7:40 a.m.
Views: 3
Exported Functions
- OslGenRandomBytes (Ordinal: 1, Address: 0x177ec)
- OslGetControlSubkeyCell (Ordinal: 2, Address: 0x15dd4)
- OslGetExportRoutineInModule (Ordinal: 3, Address: 0x18868)
- OslGetStringValue (Ordinal: 4, Address: 0x156b0)
- OslGetValue (Ordinal: 5, Address: 0x15798)
- OslIsRunningInSecureKernel (Ordinal: 6, Address: 0x184b8)
- TcbLoadEntry (Ordinal: 7, Address: 0x184cc)
- TcbResumeEntry (Ordinal: 8, Address: 0x18668)
Imported DLLs & Functions
winload.sys
- __GSHandlerCheck (Address: 0x18002b198)
- _stricmp (Address: 0x18002af50)
- _strupr (Address: 0x18002aab8)
- _wcsicmp (Address: 0x18002a8d8)
- _wcsnicmp (Address: 0x18002ab88)
- _wcstoui64 (Address: 0x18002acf8)
- _wcsupr (Address: 0x18002ab10)
- AhCreateLoadOptionsString (Address: 0x18002ac18)
- ArchBuildKernelGdt (Address: 0x18002a7e8)
- ArchGetGdtRegister (Address: 0x18002b150)
- BlAllocateSlabPages (Address: 0x18002acb0)
- BlAppendBootOptionString (Address: 0x18002aae8)
- BlAppendUnicodeToString (Address: 0x18002a7a0)
- BlArchCpuId (Address: 0x18002a7a8)
- BlArchDetectSmt (Address: 0x18002aee0)
- BlArchGetCpuVendor (Address: 0x18002aaa0)
- BlArchGetPerformanceCounter (Address: 0x18002a830)
- BlArchIsCpuIdFunctionSupported (Address: 0x18002aab0)
- BlArchIsFiveLevelPagingActive (Address: 0x18002a7c8)
- BlArchIsShadowStackSupported (Address: 0x18002ac70)
- BlArchKernelSetup (Address: 0x18002a800)
- BlArchQueryIoPortAccessSupported (Address: 0x18002abd0)
- BlArchSetSecrets (Address: 0x18002b080)
- BlBdDebuggerConnected (Address: 0x18002aa68)
- BlBdDebugTransitionsEnabled (Address: 0x18002a828)
- BlBdGetExtensionName (Address: 0x18002aea8)
- BlBdInitializeDeviceDescriptor (Address: 0x18002aec0)
- BlBdInitializeTransportExtension (Address: 0x18002aeb8)
- BlBdLoadImageSymbols (Address: 0x18002aeb0)
- BlBdPatchIdt (Address: 0x18002a7f0)
- BlBdReleaseDebuggingDevice (Address: 0x18002aed0)
- BlBdSetupDebuggingDevice (Address: 0x18002acb8)
- BlBdStop (Address: 0x18002a790)
- BlBootOptionExists (Address: 0x18002aac8)
- BlBsdCloseLog (Address: 0x18002ab18)
- BlBsdLogEntry (Address: 0x18002af80)
- BlCopyBootOptions (Address: 0x18002ab58)
- BlCopyStringToUnicodeString (Address: 0x18002ac30)
- BlCopyUnicodeStringToUnicodeString (Address: 0x18002ac50)
- BlCopyWcharStringToString (Address: 0x18002abe8)
- BlCreateTpmSealedBlob (Address: 0x18002ae28)
- BlDecryptSealedData (Address: 0x18002ae60)
- BlDeviceClose (Address: 0x18002a8b0)
- BlDeviceCompare (Address: 0x18002a9f0)
- BlDeviceOpen (Address: 0x18002a990)
- BlDisplayFreeOemBitmap (Address: 0x18002b0b8)
- BlDisplayGetOemBitmap (Address: 0x18002b0c0)
- BlDisplayInvalidateOemBitmap (Address: 0x18002b0c8)
- BlEnNotifyEvent (Address: 0x18002aef0)
- BlFileClose (Address: 0x18002a8d0)
- BlFileExists (Address: 0x18002af78)
- BlFileGetInformation (Address: 0x18002aa80)
- BlFileLoad (Address: 0x18002ae18)
- BlFileOpen (Address: 0x18002a920)
- BlFileReadAtOffsetEx (Address: 0x18002a910)
- BlFileReadEx (Address: 0x18002aca8)
- BlFileSetInformation (Address: 0x18002b098)
- BlFveCheckPermission (Address: 0x18002abe0)
- BlFwGetAcpiMemoryMap (Address: 0x18002aca0)
- BlFwGetSystemTable (Address: 0x18002acd8)
- BlFwQueryEfiRuntimeVaRange (Address: 0x18002b038)
- BlGetApplicationEntry (Address: 0x18002a8f0)
- BlGetApplicationIdentifier (Address: 0x18002ab60)
- BlGetBootDevice (Address: 0x18002a898)
- BlGetBootOptionBoolean (Address: 0x18002a9f8)
- BlGetBootOptionDevice (Address: 0x18002a9a0)
- BlGetBootOptionInteger (Address: 0x18002aa58)
- BlGetBootOptionString (Address: 0x18002aa20)
- BlGetDevice (Address: 0x18002ac68)
- BlGetDeviceIdentifier (Address: 0x18002ab90)
- BlGetExecutionEnvironment (Address: 0x18002ab00)
- BlImgFindSection (Address: 0x18002ab78)
- BlImgGetPEImageSize (Address: 0x18002abb8)
- BlImgGetSigningPolicy (Address: 0x18002a840)
- BlImgGetWhqlEnforcementDateTime (Address: 0x18002a858)
- BlImgIsBootUpgradedPlatform (Address: 0x18002aa38)
- BlImgIsUpgradedPlatform (Address: 0x18002a848)
- BlImgIsUpgradeInProgress (Address: 0x18002aa60)
- BlImgIsWhqlDeveloperTestModeEnabled (Address: 0x18002aa08)
- BlImgIsWhqlDisabledBySetting (Address: 0x18002aa78)
- BlImgIsWhqlEnabledBySetting (Address: 0x18002a9e0)
- BlImgIsWinPE (Address: 0x18002a850)
- BlImgLoadImageWithProgress2 (Address: 0x18002ab30)
- BlImgLoadPEImageEx (Address: 0x18002b0b0)
- BlImgLoadPEImageWithPolicyValidatedHash (Address: 0x18002b0a8)
- BlImgQueryCodeIntegrityBootOptions (Address: 0x18002a9d8)
- BlImgRegisterCodeIntegrityCatalogDirectory (Address: 0x18002a8e8)
- BlImgRegisterCodeIntegrityCatalogs (Address: 0x18002a8a8)
- BlImgSetRestrictedSigning (Address: 0x18002a8f8)
- BlImgSetSigningPolicy (Address: 0x18002a970)
- BlImgSetSysDevWhqlPolicy (Address: 0x18002a8a0)
- BlImgTrustCustomSignersForDrivers (Address: 0x18002a980)
- BlImgUnLoadImage (Address: 0x18002aa10)
- BlImgVerifyFontIntegrity (Address: 0x18002b088)
- BlLdrBuildImagePath (Address: 0x18002a960)
- BlLdrFreeDataTableEntry (Address: 0x18002a938)
- BlLdrLoadDll (Address: 0x18002ae98)
- BlLdrLoadImage (Address: 0x18002ac48)
- BlLdrPreloadFile (Address: 0x18002a9b0)
- BlLdrPreloadImage (Address: 0x18002ac38)
- BlLdrUnloadImage (Address: 0x18002aec8)
- BlLogDestroy (Address: 0x18002aac0)
- BlLogDiagWrite (Address: 0x18002aaf0)
- BlLogEtwRegister (Address: 0x18002b048)
- BlLogEtwWrite (Address: 0x18002ada0)
- BlLogEtwWriteTransfer (Address: 0x18002ab28)
- BlLogInitialize (Address: 0x18002ab70)
- BlMmAddEnclavePageRange (Address: 0x18002aaa8)
- BlMmAllocateHeap (Address: 0x18002a900)
- BlMmAllocatePages (Address: 0x18002a7f8)
- BlMmAllocatePhysicalPages (Address: 0x18002a808)
- BlMmAllocateVirtualPages (Address: 0x18002ab68)
- BlMmDisableStaticDescriptors (Address: 0x18002ab40)
- BlMmEnableStaticDescriptors (Address: 0x18002ac60)
- BlMmEnumerateAllocations (Address: 0x18002abf0)
- BlMmFlushTlb (Address: 0x18002b148)
- BlMmFreeHeap (Address: 0x18002a9e8)
- BlMmFreePages (Address: 0x18002a818)
- BlMmFreePhysicalPages (Address: 0x18002a810)
- BlMmFreeVirtualPages (Address: 0x18002b130)
- BlMmGetMemoryMap (Address: 0x18002ab08)
- BlMmInitMemoryMapHandle (Address: 0x18002ab98)
- BlMmMapPhysicalAddress (Address: 0x18002a7e0)
- BlMmMapPhysicalAddressEx (Address: 0x18002aad8)
- BlMmQueryLargePageSize (Address: 0x18002aae0)
- BlMmReleaseMemoryMap (Address: 0x18002ab38)
- BlMmRemapVirtualAddress (Address: 0x18002b140)
- BlMmTranslateEfiMemoryType (Address: 0x18002b058)
- BlMmTranslateVirtualAddress (Address: 0x18002abf8)
- BlMmUnmapVirtualAddress (Address: 0x18002a820)
- BlMmUnmapVirtualAddressEx (Address: 0x18002b138)
- BlNumaGetNumaMemoryRanges (Address: 0x18002abc8)
- BlObtainUnusedSlabPages (Address: 0x18002ac98)
- BlPdDestroyData (Address: 0x18002abb0)
- BlPdFreeData (Address: 0x18002af70)
- BlPdQueryDataAll (Address: 0x18002ac80)
- BlPdSaveData (Address: 0x18002ad80)
- BlpPdQueryData (Address: 0x18002a940)
- BlpPdReleaseData (Address: 0x18002a918)
- BlRemoveBootOption (Address: 0x18002ab20)
- BlResourceFindDataFromImage (Address: 0x18002b0a0)
- BlResourceFindMessage (Address: 0x18002af88)
- BlResourceGetLanguageMapping (Address: 0x18002b090)
- BlSealSecretToCurrentPcrValues (Address: 0x18002ad88)
- BlSecureBootGetNonVolatilePrivateVariable (Address: 0x18002aa00)
- BlSecureBootIgnoreSingleBootOption (Address: 0x18002ac20)
- BlSecureBootSetVolatilePrivateVariable (Address: 0x18002b160)
- BlSiDrtmEnvironmentUnsafe (Address: 0x18002ae10)
- BlSiEnterInsecureStateEx (Address: 0x18002af28)
- BlSiEnvironmentReady (Address: 0x18002aee8)
- BlSiFlushCurrentMeasurements (Address: 0x18002add8)
- BlSiHandleHypervisorLaunchEvent (Address: 0x18002aea0)
- BlSiLeaveEnvironment (Address: 0x18002af30)
- BlSiPaRecordConfigEvent (Address: 0x18002aef8)
- BlSiPaRecordDrtmConfigEvent (Address: 0x18002ae08)
- BlSIPolicyCheckPolicyOnDevice (Address: 0x18002a958)
- BlSIPolicyDoesActivePolicyGrantPermission (Address: 0x18002abc0)
- BlSIPolicyLoadAndActivateTemporalPolicy (Address: 0x18002a9d0)
- BlSiSetDrtmEnvironmentUnsafe (Address: 0x18002ae90)
- BlSlGetSmmIsolationLevel (Address: 0x18002b060)
- BlStatusError (Address: 0x18002af90)
- BlStatusPrint (Address: 0x18002a888)
- BlStatusRegisterErrorHandler (Address: 0x18002aba0)
- BlSvnGetApplicationSvn (Address: 0x18002ad00)
- BlSvnGetChainStatus (Address: 0x18002ad08)
- BlSymCryptGetAesBlockCipher (Address: 0x18002ada8)
- BlSymCryptGetHmacSha256Algorithm (Address: 0x18002b180)
- BlTblSetEntry (Address: 0x18002af58)
- BlTcgFwSetAndLockMemoryOverwriteRequestControl (Address: 0x18002ad10)
- BlTimeQueryPerformanceCounter (Address: 0x18002ac10)
- BlTpmGetRandom (Address: 0x18002afa0)
- BlTpmShutdown (Address: 0x18002aaf8)
- BlTpmStatus (Address: 0x18002a968)
- BlUpdateBootOptions (Address: 0x18002abd8)
- BlUtlCheckSum (Address: 0x18002af40)
- BlUtlGetAcpiTable (Address: 0x18002a7b0)
- BlUtlGetAcpiTableOverrides (Address: 0x18002ac00)
- BlUtlPopulateAcpiTableCache (Address: 0x18002acd0)
- BlUtlSetAcpiTableOverrides (Address: 0x18002af38)
- BlUtlValidateMemoryRange (Address: 0x18002b128)
- BlValidateAmeCertChain (Address: 0x18002acc0)
- BlValidateAnsiStringMemory (Address: 0x18002b078)
- BlValidateListMemory (Address: 0x18002b068)
- BlValidateMemoryRange (Address: 0x18002ae30)
- BlValidatePhysicalMemoryRange (Address: 0x18002b070)
- BlValidateWideStringMemory (Address: 0x18002b050)
- BlVsmCheckSystemPolicy (Address: 0x18002ac78)
- BlVsmGetSystemPolicy (Address: 0x18002aa48)
- BlVsmKeysAddNewKeyToArray (Address: 0x18002adf0)
- BlVsmKeysCreateKeyPkg (Address: 0x18002ae48)
- BlVsmKeysExplodePkg (Address: 0x18002ae68)
- BlVsmKeysFindKeyMapByType (Address: 0x18002ae50)
- BlVsmKeysGetCurrentLKeyRefFromArray (Address: 0x18002acf0)
- BlVsmKeysGetCurrentLKeyRefFromPkg (Address: 0x18002b158)
- BlVsmKeysReadAndUnsealLKeyPkg (Address: 0x18002b178)
- BlVsmKeysSupportedByPlatform (Address: 0x18002b168)
- BlVsmKeysValidateKeyPkgBuffer (Address: 0x18002ae40)
- DbgLoadImageSymbols (Address: 0x18002acc8)
- EfiGetMemoryAttributesTable (Address: 0x18002b040)
- KdNetGetNetDataSize (Address: 0x18002ace8)
- LdrInitSecurityCookie (Address: 0x18002ac58)
- McGenEventWriteBoot (Address: 0x18002aad0)
- memcmp (Address: 0x18002b1a0)
- memcpy (Address: 0x18002b1a8)
- memmove (Address: 0x18002b1b0)
- memset (Address: 0x18002b190)
- MinCrypL_HashMemory (Address: 0x18002a878)
- MincryptSetWeakCryptoPolicy (Address: 0x18002a8e0)
- OslGetDrtmSvn (Address: 0x18002ae70)
- qsort (Address: 0x18002a948)
- rsa_construction_fips186_3 (Address: 0x18002ad40)
- rsa_decryption (Address: 0x18002ad70)
- rsa_destruction (Address: 0x18002ade0)
- rsa_encryption (Address: 0x18002ad28)
- rsa_export (Address: 0x18002adc0)
- rsa_export_sizes (Address: 0x18002ad60)
- RtlAnsiStringToUnicodeString (Address: 0x18002a798)
- RtlAppendUnicodeStringToString (Address: 0x18002b0d8)
- RtlAppendUnicodeToString (Address: 0x18002ac90)
- RtlClearAllBits (Address: 0x18002b118)
- RtlClearBits (Address: 0x18002b120)
- RtlCompareMemory (Address: 0x18002af60)
- RtlCompareUnicodeString (Address: 0x18002b0d0)
- RtlCompareUnicodeStrings (Address: 0x18002b188)
- RtlEqualUnicodeString (Address: 0x18002a8b8)
- RtlFindExportedRoutineByName (Address: 0x18002a880)
- RtlFreeUnicodeString (Address: 0x18002a7b8)
- RtlGUIDFromString (Address: 0x18002a890)
- RtlImageDirectoryEntryToData (Address: 0x18002ac28)
- RtlInitAnsiString (Address: 0x18002a7d0)
- RtlInitializeBitMap (Address: 0x18002b0f0)
- RtlInitializeBootFeatureConfigurations (Address: 0x18002b020)
- RtlInitUnicodeString (Address: 0x18002a7c0)
- RtlInitUnicodeStringEx (Address: 0x18002a998)
- RtlPrefixUnicodeString (Address: 0x18002ac40)
- RtlSetBits (Address: 0x18002b0f8)
- RtlStringFromGUID (Address: 0x18002b0e0)
- RtlUnicodeStringToAnsiString (Address: 0x18002af68)
- RtlUpcaseUnicodeChar (Address: 0x18002b110)
- RtlValidateDelayedFeatureUsageReportBuffer (Address: 0x18002b028)
- RtlValidateFeatureConfigurationBuffer (Address: 0x18002b030)
- RtlValidateFeatureUsageSubscriptionBuffer (Address: 0x18002b018)
- SbArePolicyOptionsSet (Address: 0x18002a870)
- SbDoesActivePolicyGrantPermission (Address: 0x18002ac08)
- SbFreeFileData (Address: 0x18002a9a8)
- SbGetKernelPolicyPackage (Address: 0x18002aa88)
- SbGetSizeOfKernelPolicyPackage (Address: 0x18002a860)
- SbIsDebugPolicyActive (Address: 0x18002aa90)
- SbIsEnabled (Address: 0x18002a8c8)
- SbIsEnabled2 (Address: 0x18002ace0)
- SbIsPolicyActive (Address: 0x18002aba8)
- SbIsTestRootTrusted (Address: 0x18002a9c8)
- SbIsTestSigningBlocked (Address: 0x18002ac88)
- SbLoadFile (Address: 0x18002a908)
- SbValidateSkuUnlockToken (Address: 0x18002aa28)
- SipaGetDataPointers (Address: 0x18002af00)
- SipapAppendEntry (Address: 0x18002af08)
- SipapCreateQueue (Address: 0x18002af20)
- SipaQueueConfigEntry (Address: 0x18002ad20)
- SipaQueueConfigEntryToQueue (Address: 0x18002af18)
- SIPolicyClearAllActivePolicy (Address: 0x18002a988)
- SIPolicyDeletePersistentVariable (Address: 0x18002aa70)
- SIPolicyGetOptions (Address: 0x18002a9c0)
- SIPolicyGetPolicyHandle (Address: 0x18002aa18)
- SIPolicyGetPolicyInfoFromType (Address: 0x18002aa98)
- SIPolicyGetSerializedPolicies (Address: 0x18002aa50)
- SIPolicyGetSerializedPoliciesSize (Address: 0x18002a950)
- SIPolicyHashActiveCodeExecutionPolicies (Address: 0x18002a978)
- SIPolicyInvalidateEAsOnRebootEnabled (Address: 0x18002a8c0)
- SIPolicyIsPolicyActive (Address: 0x18002a9b8)
- SIPolicyIsSignedPolicyRequired (Address: 0x18002a868)
- SIPolicySetTrialMode (Address: 0x18002aa30)
- SIPolicyUmciEnabled (Address: 0x18002aa40)
- sprintf_s (Address: 0x18002b0e8)
- strcat_s (Address: 0x18002a7d8)
- strcpy_s (Address: 0x18002af48)
- strstr (Address: 0x18002ab80)
- swprintf_s (Address: 0x18002ab48)
- SymCryptGcmAuthPart (Address: 0x18002ad90)
- SymCryptGcmDecryptFinal (Address: 0x18002ad38)
- SymCryptGcmDecryptPart (Address: 0x18002adb8)
- SymCryptGcmEncryptFinal (Address: 0x18002ad30)
- SymCryptGcmEncryptPart (Address: 0x18002ad18)
- SymCryptGcmExpandKey (Address: 0x18002ad68)
- SymCryptGcmInit (Address: 0x18002ad58)
- SymCryptHmacSha512Selftest (Address: 0x18002afe0)
- SymCryptInit (Address: 0x18002b100)
- SymCryptMarvin32ExpandSeed (Address: 0x18002b108)
- SymCryptRdrandGet (Address: 0x18002afb8)
- SymCryptRdrandStatus (Address: 0x18002afd0)
- SymCryptRdseedGet (Address: 0x18002aff8)
- SymCryptRdseedStatus (Address: 0x18002afa8)
- SymCryptRngAesFips140_2Generate (Address: 0x18002afe8)
- SymCryptRngAesFips140_2Instantiate (Address: 0x18002b010)
- SymCryptRngAesFips140_2Uninstantiate (Address: 0x18002aff0)
- SymCryptRngAesGenerateSelftest (Address: 0x18002b008)
- SymCryptRngAesInstantiateSelftest (Address: 0x18002afb0)
- SymCryptRngAesReseedSelftest (Address: 0x18002af98)
- SymCryptSha1 (Address: 0x18002af10)
- SymCryptSha256 (Address: 0x18002adc8)
- SymCryptSha256Append (Address: 0x18002ad50)
- SymCryptSha256Init (Address: 0x18002add0)
- SymCryptSha256Result (Address: 0x18002adb0)
- SymCryptSha512 (Address: 0x18002b000)
- SymCryptSha512Append (Address: 0x18002afc8)
- SymCryptSha512Init (Address: 0x18002afd8)
- SymCryptSha512Result (Address: 0x18002afc0)
- SymCryptSp800_108 (Address: 0x18002b170)
- TpmApiCheckSecureNVIndex20 (Address: 0x18002ad48)
- TpmApiCreateSecureNVIndex20 (Address: 0x18002ad98)
- TpmApiCreateSrk20 (Address: 0x18002ae00)
- TpmApiDrtmGetSigningKeys (Address: 0x18002ae20)
- TpmApiGetKeyPublicProperty20 (Address: 0x18002ae80)
- TpmApiGetTpmVersion (Address: 0x18002ade8)
- TpmApiIsCurrentStatePolicyAuthorized20 (Address: 0x18002ae38)
- TpmApiReadPublic20 (Address: 0x18002ae88)
- TpmApiSealPolicyAuthorized20 (Address: 0x18002adf8)
- TpmApiUnsealEx (Address: 0x18002ad78)
- TpmApiUnsealPolicyAuthorized20 (Address: 0x18002ae58)
- wcscat_s (Address: 0x18002a930)
- wcscmp (Address: 0x18002b1b8)
- wcscpy_s (Address: 0x18002a928)
- wcsncmp (Address: 0x18002ae78)
- wcsnlen (Address: 0x18002a838)
- wcsrchr (Address: 0x18002aed8)
- wcsstr (Address: 0x18002ab50)