csrsrv.dll
Description: Client Server Runtime Process
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.1
Architecture: 64-bit
Operating System: Windows NT
SHA256: 31c66dd46da26c32d1457471e444e17a
File Size: 64.5 KB
Uploaded At: Dec. 1, 2025, 7:25 a.m.
Views: 13
Exported Functions
- CsrAddStaticServerThread (Ordinal: 1, Address: 0x6d10)
- CsrCallServerFromServer (Ordinal: 2, Address: 0x2b10)
- CsrConnectToUser (Ordinal: 3, Address: 0x6c80)
- CsrCreateProcess (Ordinal: 4, Address: 0x1af0)
- CsrCreateRemoteThread (Ordinal: 5, Address: 0x9260)
- CsrCreateThread (Ordinal: 6, Address: 0x1800)
- CsrDeferredCreateProcess (Ordinal: 7, Address: 0x9430)
- CsrDereferenceProcess (Ordinal: 8, Address: 0x12c0)
- CsrDereferenceThread (Ordinal: 9, Address: 0x3420)
- CsrDestroyProcess (Ordinal: 10, Address: 0x9460)
- CsrDestroyThread (Ordinal: 11, Address: 0x94f0)
- CsrExecServerThread (Ordinal: 12, Address: 0x5ec0)
- CsrGetProcessLuid (Ordinal: 13, Address: 0x34d0)
- CsrImpersonateClient (Ordinal: 14, Address: 0x29a0)
- CsrIsClientSandboxed (Ordinal: 15, Address: 0x9580)
- CsrLockProcessByClientId (Ordinal: 16, Address: 0x1a60)
- CsrLockThreadByClientId (Ordinal: 17, Address: 0x1010)
- CsrLockedReferenceProcess (Ordinal: 18, Address: 0x95c0)
- CsrQueryApiPort (Ordinal: 19, Address: 0x7270)
- CsrReferenceThread (Ordinal: 20, Address: 0x34c0)
- CsrRegisterClientThreadSetup (Ordinal: 21, Address: 0x7250)
- CsrReplyToMessage (Ordinal: 22, Address: 0x8e00)
- CsrRevertToSelf (Ordinal: 23, Address: 0x2870)
- CsrServerInitialization (Ordinal: 24, Address: 0x3800)
- CsrSetBackgroundPriority (Ordinal: 25, Address: 0x5dd0)
- CsrSetForegroundPriority (Ordinal: 26, Address: 0x9bb0)
- CsrShutdownProcesses (Ordinal: 27, Address: 0x2c90)
- CsrUnhandledExceptionFilter (Ordinal: 28, Address: 0x8c40)
- CsrUnlockProcess (Ordinal: 29, Address: 0x2ad0)
- CsrUnlockThread (Ordinal: 30, Address: 0x2c00)
- CsrValidateMessageBuffer (Ordinal: 31, Address: 0x2730)
- CsrValidateMessageString (Ordinal: 32, Address: 0x8e50)
Imported DLLs & Functions
ntdll.dll
- __C_specific_handler (Address: 0x18000a180)
- _snprintf_s (Address: 0x18000a228)
- _stricmp (Address: 0x18000a258)
- _vsnwprintf (Address: 0x18000a428)
- AlpcGetMessageAttribute (Address: 0x18000a408)
- AlpcInitializeMessageAttribute (Address: 0x18000a400)
- DbgPrint (Address: 0x18000a2a0)
- EtwEventEnabled (Address: 0x18000a440)
- EtwEventRegister (Address: 0x18000a290)
- EtwEventWrite (Address: 0x18000a4a0)
- LdrDisableThreadCalloutsForDll (Address: 0x18000a4b8)
- LdrGetProcedureAddress (Address: 0x18000a2c8)
- LdrLoadDll (Address: 0x18000a300)
- LdrUnloadDll (Address: 0x18000a2f0)
- memcpy (Address: 0x18000a4d8)
- memset (Address: 0x18000a4f0)
- NtAcceptConnectPort (Address: 0x18000a378)
- NtAdjustPrivilegesToken (Address: 0x18000a188)
- NtAlpcAcceptConnectPort (Address: 0x18000a3f8)
- NtAlpcCreatePort (Address: 0x18000a3d0)
- NtAlpcDeleteSectionView (Address: 0x18000a3f0)
- NtAlpcDisconnectPort (Address: 0x18000a4b0)
- NtAlpcOpenSenderProcess (Address: 0x18000a3e0)
- NtAlpcOpenSenderThread (Address: 0x18000a410)
- NtAlpcSendWaitReceivePort (Address: 0x18000a418)
- NtClose (Address: 0x18000a230)
- NtCompleteConnectPort (Address: 0x18000a368)
- NtCreateDirectoryObject (Address: 0x18000a1a8)
- NtCreateEvent (Address: 0x18000a248)
- NtCreatePort (Address: 0x18000a358)
- NtCreateSection (Address: 0x18000a2d8)
- NtCreateSymbolicLinkObject (Address: 0x18000a260)
- NtDelayExecution (Address: 0x18000a310)
- NtDuplicateObject (Address: 0x18000a478)
- NtImpersonateThread (Address: 0x18000a448)
- NtMapViewOfSection (Address: 0x18000a348)
- NtOpenDirectoryObject (Address: 0x18000a470)
- NtOpenEvent (Address: 0x18000a1d8)
- NtOpenKey (Address: 0x18000a1d0)
- NtOpenProcessToken (Address: 0x18000a198)
- NtOpenThread (Address: 0x18000a430)
- NtOpenThreadToken (Address: 0x18000a490)
- NtQueryInformationProcess (Address: 0x18000a3d8)
- NtQueryInformationThread (Address: 0x18000a390)
- NtQueryInformationToken (Address: 0x18000a208)
- NtQuerySystemInformation (Address: 0x18000a1c0)
- NtQueryValueKey (Address: 0x18000a2c0)
- NtRaiseHardError (Address: 0x18000a318)
- NtReadVirtualMemory (Address: 0x18000a468)
- NtRegisterThreadTerminatePort (Address: 0x18000a498)
- NtReplyWaitReceivePort (Address: 0x18000a370)
- NtResumeThread (Address: 0x18000a2b8)
- NtSetDefaultHardErrorPort (Address: 0x18000a3c8)
- NtSetEvent (Address: 0x18000a250)
- NtSetInformationObject (Address: 0x18000a1f0)
- NtSetInformationProcess (Address: 0x18000a388)
- NtSetInformationThread (Address: 0x18000a450)
- NtSetSecurityObject (Address: 0x18000a210)
- NtTerminateProcess (Address: 0x18000a350)
- NtTerminateThread (Address: 0x18000a360)
- NtWaitForSingleObject (Address: 0x18000a2a8)
- qsort (Address: 0x18000a460)
- RtlAddAccessAllowedAce (Address: 0x18000a220)
- RtlAddProcessTrustLabelAce (Address: 0x18000a3a8)
- RtlAdjustPrivilege (Address: 0x18000a320)
- RtlAllocateAndInitializeSid (Address: 0x18000a200)
- RtlAllocateHeap (Address: 0x18000a1b8)
- RtlAnsiStringToUnicodeString (Address: 0x18000a190)
- RtlAppendUnicodeStringToString (Address: 0x18000a2d0)
- RtlAppendUnicodeToString (Address: 0x18000a2e0)
- RtlCaptureContext (Address: 0x18000a4c0)
- RtlCharToInteger (Address: 0x18000a280)
- RtlCheckSandboxedToken (Address: 0x18000a480)
- RtlConnectToSm (Address: 0x18000a4e0)
- RtlCreateAcl (Address: 0x18000a278)
- RtlCreateHeap (Address: 0x18000a340)
- RtlCreateProcessParametersEx (Address: 0x18000a438)
- RtlCreateSecurityDescriptor (Address: 0x18000a298)
- RtlCreateTagHeap (Address: 0x18000a288)
- RtlCreateUserProcess (Address: 0x18000a4a8)
- RtlCreateUserThread (Address: 0x18000a330)
- RtlDestroyProcessParameters (Address: 0x18000a458)
- RtlEnterCriticalSection (Address: 0x18000a380)
- RtlFreeHeap (Address: 0x18000a268)
- RtlFreeSid (Address: 0x18000a240)
- RtlFreeUnicodeString (Address: 0x18000a1e8)
- RtlGetAce (Address: 0x18000a1e0)
- RtlGetCurrentServiceSessionId (Address: 0x18000a1a0)
- RtlGetDaclSecurityDescriptor (Address: 0x18000a2b0)
- RtlGetSuiteMask (Address: 0x18000a488)
- RtlInitAnsiString (Address: 0x18000a328)
- RtlInitializeCriticalSection (Address: 0x18000a420)
- RtlInitializeSid (Address: 0x18000a3b0)
- RtlInitString (Address: 0x18000a270)
- RtlInitUnicodeString (Address: 0x18000a1f8)
- RtlLeaveCriticalSection (Address: 0x18000a398)
- RtlLengthRequiredSid (Address: 0x18000a3c0)
- RtlLengthSid (Address: 0x18000a218)
- RtlLookupFunctionEntry (Address: 0x18000a4c8)
- RtlReportException (Address: 0x18000a308)
- RtlSendMsgToSm (Address: 0x18000a4e8)
- RtlSetDaclSecurityDescriptor (Address: 0x18000a1c8)
- RtlSetSaclSecurityDescriptor (Address: 0x18000a3a0)
- RtlSetUnhandledExceptionFilter (Address: 0x18000a2f8)
- RtlSubAuthoritySid (Address: 0x18000a3b8)
- RtlUnhandledExceptionFilter (Address: 0x18000a338)
- RtlVirtualUnwind (Address: 0x18000a4d0)
- RtlWaitOnAddress (Address: 0x18000a3e8)
- RtlWakeAddressAll (Address: 0x18000a1b0)
- strncpy_s (Address: 0x18000a2e8)
- swprintf_s (Address: 0x18000a238)