securebootai.dll
Description: CSI Secure Boot Servicing Plugin
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.3562
Architecture: 64-bit
Operating System: Windows NT
SHA256: a1d5eb3b5fa0053bb92fa1068cec6daa
File Size: 90.0 KB
Uploaded At: Dec. 1, 2025, 8:20 a.m.
Views: 17
Exported Functions
- DllCanUnloadNow (Ordinal: 1, Address: 0x8510)
- DllCsiGetHandler (Ordinal: 2, Address: 0x8530)
Imported DLLs & Functions
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x18000f388)
- IsDebuggerPresent (Address: 0x18000f390)
- OutputDebugStringW (Address: 0x18000f380)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x18000f3b8)
- SetLastError (Address: 0x18000f3a0)
- SetUnhandledExceptionFilter (Address: 0x18000f3a8)
- UnhandledExceptionFilter (Address: 0x18000f3b0)
api-ms-win-core-file-l1-1-0.dll
- CreateFileW (Address: 0x18000f3d8)
- FindClose (Address: 0x18000f3f0)
- FindFirstFileW (Address: 0x18000f3c8)
- FindNextFileW (Address: 0x18000f3e8)
- GetFileSizeEx (Address: 0x18000f3e0)
- ReadFile (Address: 0x18000f3d0)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x18000f400)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x18000f418)
- HeapAlloc (Address: 0x18000f420)
- HeapDestroy (Address: 0x18000f410)
- HeapFree (Address: 0x18000f428)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
- CopyFileW (Address: 0x18000f438)
api-ms-win-core-libraryloader-l1-1-0.dll
- DisableThreadLibraryCalls (Address: 0x18000f478)
- FreeLibrary (Address: 0x18000f470)
- GetModuleFileNameA (Address: 0x18000f450)
- GetModuleHandleExW (Address: 0x18000f448)
- GetModuleHandleW (Address: 0x18000f460)
- GetProcAddress (Address: 0x18000f458)
- LoadLibraryExW (Address: 0x18000f468)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x18000f488)
api-ms-win-core-processthreads-l1-1-0.dll
- GetCurrentProcess (Address: 0x18000f4c8)
- GetCurrentProcessId (Address: 0x18000f4b0)
- GetCurrentThread (Address: 0x18000f498)
- GetCurrentThreadId (Address: 0x18000f4a0)
- OpenProcessToken (Address: 0x18000f4b8)
- OpenThreadToken (Address: 0x18000f4a8)
- TerminateProcess (Address: 0x18000f4c0)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x18000f4d8)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x18000f4f8)
- RegCreateKeyExW (Address: 0x18000f508)
- RegDeleteKeyExW (Address: 0x18000f4e8)
- RegGetValueW (Address: 0x18000f500)
- RegOpenKeyExW (Address: 0x18000f4f0)
- RegQueryValueExW (Address: 0x18000f510)
- RegSetValueExW (Address: 0x18000f518)
api-ms-win-core-rtlsupport-l1-1-0.dll
- RtlCaptureContext (Address: 0x18000f538)
- RtlLookupFunctionEntry (Address: 0x18000f530)
- RtlVirtualUnwind (Address: 0x18000f528)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x18000f5a8)
- AcquireSRWLockShared (Address: 0x18000f598)
- CreateMutexExW (Address: 0x18000f560)
- CreateSemaphoreExW (Address: 0x18000f568)
- DeleteCriticalSection (Address: 0x18000f5c0)
- EnterCriticalSection (Address: 0x18000f548)
- InitializeCriticalSection (Address: 0x18000f5b8)
- InitializeCriticalSectionEx (Address: 0x18000f570)
- LeaveCriticalSection (Address: 0x18000f550)
- OpenSemaphoreW (Address: 0x18000f5b0)
- ReleaseMutex (Address: 0x18000f580)
- ReleaseSemaphore (Address: 0x18000f588)
- ReleaseSRWLockExclusive (Address: 0x18000f5a0)
- ReleaseSRWLockShared (Address: 0x18000f590)
- WaitForSingleObject (Address: 0x18000f578)
- WaitForSingleObjectEx (Address: 0x18000f558)
api-ms-win-core-synch-l1-2-0.dll
- InitOnceBeginInitialize (Address: 0x18000f5e0)
- InitOnceComplete (Address: 0x18000f5d8)
- Sleep (Address: 0x18000f5d0)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemDirectoryW (Address: 0x18000f5f8)
- GetSystemTimeAsFileTime (Address: 0x18000f600)
- GetSystemWindowsDirectoryW (Address: 0x18000f5f0)
- GetTickCount (Address: 0x18000f608)
api-ms-win-core-threadpool-l1-2-0.dll
- CloseThreadpoolTimer (Address: 0x18000f618)
- CreateThreadpoolTimer (Address: 0x18000f630)
- SetThreadpoolTimer (Address: 0x18000f620)
- WaitForThreadpoolTimerCallbacks (Address: 0x18000f628)
api-ms-win-eventing-provider-l1-1-0.dll
- EventRegister (Address: 0x18000f648)
- EventUnregister (Address: 0x18000f640)
- EventWriteTransfer (Address: 0x18000f650)
api-ms-win-security-base-l1-1-0.dll
- AdjustTokenPrivileges (Address: 0x18000f660)
api-ms-win-security-lsalookup-l2-1-0.dll
- LookupPrivilegeValueW (Address: 0x18000f670)
CRYPT32.dll
- CertCloseStore (Address: 0x18000f300)
- CertCreateCertificateContext (Address: 0x18000f310)
- CertFindCertificateInStore (Address: 0x18000f2f8)
- CertFreeCertificateContext (Address: 0x18000f320)
- CertGetCertificateContextProperty (Address: 0x18000f330)
- CryptMsgClose (Address: 0x18000f318)
- CryptMsgGetParam (Address: 0x18000f328)
- CryptQueryObject (Address: 0x18000f308)
msvcrt.dll
- __C_specific_handler (Address: 0x18000f698)
- __CxxFrameHandler3 (Address: 0x18000f738)
- __dllonexit (Address: 0x18000f700)
- _amsg_exit (Address: 0x18000f6e0)
- _callnewh (Address: 0x18000f710)
- _CxxThrowException (Address: 0x18000f748)
- _initterm (Address: 0x18000f6e8)
- _lock (Address: 0x18000f6f0)
- _onexit (Address: 0x18000f708)
- _purecall (Address: 0x18000f6c0)
- _unlock (Address: 0x18000f6f8)
- _vsnprintf_s (Address: 0x18000f690)
- _vsnwprintf (Address: 0x18000f730)
- _wcsicmp (Address: 0x18000f6b8)
- _XcptFilter (Address: 0x18000f6d8)
- ??0exception@@QEAA@AEBV0@@Z (Address: 0x18000f6a0)
- ??0exception@@QEAA@XZ (Address: 0x18000f6a8)
- ??1exception@@UEAA@XZ (Address: 0x18000f6b0)
- ??1type_info@@UEAA@XZ (Address: 0x18000f718)
- ?terminate@@YAXXZ (Address: 0x18000f728)
- free (Address: 0x18000f680)
- malloc (Address: 0x18000f6d0)
- memcmp (Address: 0x18000f740)
- memcpy_s (Address: 0x18000f720)
- memmove_s (Address: 0x18000f6c8)
- memset (Address: 0x18000f750)
- wcsstr (Address: 0x18000f688)
ntdll.dll
- NtQuerySystemInformation (Address: 0x18000f770)
- NtSetSystemEnvironmentValueEx (Address: 0x18000f778)
- RtlInitUnicodeString (Address: 0x18000f768)
- RtlNtStatusToDosError (Address: 0x18000f760)
WCP.dll
- ?RtlGetFacilityTracingFlags@Rtl@WCP@Windows@@YAKPEAU_RTL_TRACING_FACILITY@123@@Z (Address: 0x18000f350)
- ?RtlTraceFormat_PCHRESULT@Rtl@WCP@Windows@@YAXPEAUIRtlFormattedOutputStream@13@PEBX@Z (Address: 0x18000f340)
- ?RtlTraceFormat_PCWSTR@Rtl@WCP@Windows@@YAXPEAUIRtlFormattedOutputStream@13@PEBX@Z (Address: 0x18000f370)
- ?RtlTraceVa@Rtl@WCP@Windows@@YAXKKPEAU_RTL_TRACING_FACILITY@123@QEBD_KPEAD@Z (Address: 0x18000f358)
- ConvertNtStatusToHResult (Address: 0x18000f360)
- RtlFreeLBlob (Address: 0x18000f348)
- RtlReportErrorOrigination (Address: 0x18000f368)