csrsrv.dll

Description: Client Server Runtime Process

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.1

Architecture: 64-bit

Operating System: Windows NT

SHA256: 31c66dd46da26c32d1457471e444e17a

File Size: 64.5 KB

Uploaded At: Dec. 1, 2025, 7:25 a.m.

Views: 13

Exported Functions

  • CsrAddStaticServerThread (Ordinal: 1, Address: 0x6d10)
  • CsrCallServerFromServer (Ordinal: 2, Address: 0x2b10)
  • CsrConnectToUser (Ordinal: 3, Address: 0x6c80)
  • CsrCreateProcess (Ordinal: 4, Address: 0x1af0)
  • CsrCreateRemoteThread (Ordinal: 5, Address: 0x9260)
  • CsrCreateThread (Ordinal: 6, Address: 0x1800)
  • CsrDeferredCreateProcess (Ordinal: 7, Address: 0x9430)
  • CsrDereferenceProcess (Ordinal: 8, Address: 0x12c0)
  • CsrDereferenceThread (Ordinal: 9, Address: 0x3420)
  • CsrDestroyProcess (Ordinal: 10, Address: 0x9460)
  • CsrDestroyThread (Ordinal: 11, Address: 0x94f0)
  • CsrExecServerThread (Ordinal: 12, Address: 0x5ec0)
  • CsrGetProcessLuid (Ordinal: 13, Address: 0x34d0)
  • CsrImpersonateClient (Ordinal: 14, Address: 0x29a0)
  • CsrIsClientSandboxed (Ordinal: 15, Address: 0x9580)
  • CsrLockProcessByClientId (Ordinal: 16, Address: 0x1a60)
  • CsrLockThreadByClientId (Ordinal: 17, Address: 0x1010)
  • CsrLockedReferenceProcess (Ordinal: 18, Address: 0x95c0)
  • CsrQueryApiPort (Ordinal: 19, Address: 0x7270)
  • CsrReferenceThread (Ordinal: 20, Address: 0x34c0)
  • CsrRegisterClientThreadSetup (Ordinal: 21, Address: 0x7250)
  • CsrReplyToMessage (Ordinal: 22, Address: 0x8e00)
  • CsrRevertToSelf (Ordinal: 23, Address: 0x2870)
  • CsrServerInitialization (Ordinal: 24, Address: 0x3800)
  • CsrSetBackgroundPriority (Ordinal: 25, Address: 0x5dd0)
  • CsrSetForegroundPriority (Ordinal: 26, Address: 0x9bb0)
  • CsrShutdownProcesses (Ordinal: 27, Address: 0x2c90)
  • CsrUnhandledExceptionFilter (Ordinal: 28, Address: 0x8c40)
  • CsrUnlockProcess (Ordinal: 29, Address: 0x2ad0)
  • CsrUnlockThread (Ordinal: 30, Address: 0x2c00)
  • CsrValidateMessageBuffer (Ordinal: 31, Address: 0x2730)
  • CsrValidateMessageString (Ordinal: 32, Address: 0x8e50)

Imported DLLs & Functions

ntdll.dll
  • __C_specific_handler (Address: 0x18000a180)
  • _snprintf_s (Address: 0x18000a228)
  • _stricmp (Address: 0x18000a258)
  • _vsnwprintf (Address: 0x18000a428)
  • AlpcGetMessageAttribute (Address: 0x18000a408)
  • AlpcInitializeMessageAttribute (Address: 0x18000a400)
  • DbgPrint (Address: 0x18000a2a0)
  • EtwEventEnabled (Address: 0x18000a440)
  • EtwEventRegister (Address: 0x18000a290)
  • EtwEventWrite (Address: 0x18000a4a0)
  • LdrDisableThreadCalloutsForDll (Address: 0x18000a4b8)
  • LdrGetProcedureAddress (Address: 0x18000a2c8)
  • LdrLoadDll (Address: 0x18000a300)
  • LdrUnloadDll (Address: 0x18000a2f0)
  • memcpy (Address: 0x18000a4d8)
  • memset (Address: 0x18000a4f0)
  • NtAcceptConnectPort (Address: 0x18000a378)
  • NtAdjustPrivilegesToken (Address: 0x18000a188)
  • NtAlpcAcceptConnectPort (Address: 0x18000a3f8)
  • NtAlpcCreatePort (Address: 0x18000a3d0)
  • NtAlpcDeleteSectionView (Address: 0x18000a3f0)
  • NtAlpcDisconnectPort (Address: 0x18000a4b0)
  • NtAlpcOpenSenderProcess (Address: 0x18000a3e0)
  • NtAlpcOpenSenderThread (Address: 0x18000a410)
  • NtAlpcSendWaitReceivePort (Address: 0x18000a418)
  • NtClose (Address: 0x18000a230)
  • NtCompleteConnectPort (Address: 0x18000a368)
  • NtCreateDirectoryObject (Address: 0x18000a1a8)
  • NtCreateEvent (Address: 0x18000a248)
  • NtCreatePort (Address: 0x18000a358)
  • NtCreateSection (Address: 0x18000a2d8)
  • NtCreateSymbolicLinkObject (Address: 0x18000a260)
  • NtDelayExecution (Address: 0x18000a310)
  • NtDuplicateObject (Address: 0x18000a478)
  • NtImpersonateThread (Address: 0x18000a448)
  • NtMapViewOfSection (Address: 0x18000a348)
  • NtOpenDirectoryObject (Address: 0x18000a470)
  • NtOpenEvent (Address: 0x18000a1d8)
  • NtOpenKey (Address: 0x18000a1d0)
  • NtOpenProcessToken (Address: 0x18000a198)
  • NtOpenThread (Address: 0x18000a430)
  • NtOpenThreadToken (Address: 0x18000a490)
  • NtQueryInformationProcess (Address: 0x18000a3d8)
  • NtQueryInformationThread (Address: 0x18000a390)
  • NtQueryInformationToken (Address: 0x18000a208)
  • NtQuerySystemInformation (Address: 0x18000a1c0)
  • NtQueryValueKey (Address: 0x18000a2c0)
  • NtRaiseHardError (Address: 0x18000a318)
  • NtReadVirtualMemory (Address: 0x18000a468)
  • NtRegisterThreadTerminatePort (Address: 0x18000a498)
  • NtReplyWaitReceivePort (Address: 0x18000a370)
  • NtResumeThread (Address: 0x18000a2b8)
  • NtSetDefaultHardErrorPort (Address: 0x18000a3c8)
  • NtSetEvent (Address: 0x18000a250)
  • NtSetInformationObject (Address: 0x18000a1f0)
  • NtSetInformationProcess (Address: 0x18000a388)
  • NtSetInformationThread (Address: 0x18000a450)
  • NtSetSecurityObject (Address: 0x18000a210)
  • NtTerminateProcess (Address: 0x18000a350)
  • NtTerminateThread (Address: 0x18000a360)
  • NtWaitForSingleObject (Address: 0x18000a2a8)
  • qsort (Address: 0x18000a460)
  • RtlAddAccessAllowedAce (Address: 0x18000a220)
  • RtlAddProcessTrustLabelAce (Address: 0x18000a3a8)
  • RtlAdjustPrivilege (Address: 0x18000a320)
  • RtlAllocateAndInitializeSid (Address: 0x18000a200)
  • RtlAllocateHeap (Address: 0x18000a1b8)
  • RtlAnsiStringToUnicodeString (Address: 0x18000a190)
  • RtlAppendUnicodeStringToString (Address: 0x18000a2d0)
  • RtlAppendUnicodeToString (Address: 0x18000a2e0)
  • RtlCaptureContext (Address: 0x18000a4c0)
  • RtlCharToInteger (Address: 0x18000a280)
  • RtlCheckSandboxedToken (Address: 0x18000a480)
  • RtlConnectToSm (Address: 0x18000a4e0)
  • RtlCreateAcl (Address: 0x18000a278)
  • RtlCreateHeap (Address: 0x18000a340)
  • RtlCreateProcessParametersEx (Address: 0x18000a438)
  • RtlCreateSecurityDescriptor (Address: 0x18000a298)
  • RtlCreateTagHeap (Address: 0x18000a288)
  • RtlCreateUserProcess (Address: 0x18000a4a8)
  • RtlCreateUserThread (Address: 0x18000a330)
  • RtlDestroyProcessParameters (Address: 0x18000a458)
  • RtlEnterCriticalSection (Address: 0x18000a380)
  • RtlFreeHeap (Address: 0x18000a268)
  • RtlFreeSid (Address: 0x18000a240)
  • RtlFreeUnicodeString (Address: 0x18000a1e8)
  • RtlGetAce (Address: 0x18000a1e0)
  • RtlGetCurrentServiceSessionId (Address: 0x18000a1a0)
  • RtlGetDaclSecurityDescriptor (Address: 0x18000a2b0)
  • RtlGetSuiteMask (Address: 0x18000a488)
  • RtlInitAnsiString (Address: 0x18000a328)
  • RtlInitializeCriticalSection (Address: 0x18000a420)
  • RtlInitializeSid (Address: 0x18000a3b0)
  • RtlInitString (Address: 0x18000a270)
  • RtlInitUnicodeString (Address: 0x18000a1f8)
  • RtlLeaveCriticalSection (Address: 0x18000a398)
  • RtlLengthRequiredSid (Address: 0x18000a3c0)
  • RtlLengthSid (Address: 0x18000a218)
  • RtlLookupFunctionEntry (Address: 0x18000a4c8)
  • RtlReportException (Address: 0x18000a308)
  • RtlSendMsgToSm (Address: 0x18000a4e8)
  • RtlSetDaclSecurityDescriptor (Address: 0x18000a1c8)
  • RtlSetSaclSecurityDescriptor (Address: 0x18000a3a0)
  • RtlSetUnhandledExceptionFilter (Address: 0x18000a2f8)
  • RtlSubAuthoritySid (Address: 0x18000a3b8)
  • RtlUnhandledExceptionFilter (Address: 0x18000a338)
  • RtlVirtualUnwind (Address: 0x18000a4d0)
  • RtlWaitOnAddress (Address: 0x18000a3e8)
  • RtlWakeAddressAll (Address: 0x18000a1b0)
  • strncpy_s (Address: 0x18000a2e8)
  • swprintf_s (Address: 0x18000a238)