ntdsetup.dll

Description: NT5DS

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.4474

Architecture: 64-bit

Operating System: Windows NT

SHA256: aaa66dedf5ff198158ea76870427a764

File Size: 202.0 KB

Uploaded At: Dec. 1, 2025, 8:11 a.m.

Views: 19

Exported Functions

  • AdamFetchDemotionInfo (Ordinal: 1, Address: 0x184e0)
  • AdamGetCrossRefs (Ordinal: 2, Address: 0xed30)
  • FreeDemotionInfo (Ordinal: 3, Address: 0x18910)
  • NtdsAdamValidateInst (Ordinal: 4, Address: 0x10160)
  • NtdsAdamValidateServiceAccount (Ordinal: 5, Address: 0x105f0)
  • NtdsAdamVerifyBind (Ordinal: 6, Address: 0x10630)
  • NtdsCheckMachineAccountFlags (Ordinal: 7, Address: 0x192d0)
  • NtdsDemote (Ordinal: 8, Address: 0x192f0)
  • NtdsFreeDnsRRInfo (Ordinal: 9, Address: 0x12520)
  • NtdsGetDefaultDnsName (Ordinal: 10, Address: 0x194a0)
  • NtdsInstall (Ordinal: 11, Address: 0x4750)
  • NtdsInstallCancel (Ordinal: 12, Address: 0x194b0)
  • NtdsInstallReplicateFull (Ordinal: 13, Address: 0x19530)
  • NtdsInstallShutdown (Ordinal: 14, Address: 0x8980)
  • NtdsInstallUndo (Ordinal: 15, Address: 0x19740)
  • NtdsPrepareForDemotion (Ordinal: 16, Address: 0x19780)
  • NtdsPrepareForDemotionUndo (Ordinal: 17, Address: 0x198a0)
  • NtdsPrepareForDsUpgrade (Ordinal: 18, Address: 0x198c0)
  • NtdsSetReplicaMachineAccount (Ordinal: 19, Address: 0x19b30)
  • NtdspConfigRegistry (Ordinal: 20, Address: 0x2510)
  • NtdspDNStoRFC1779Name (Ordinal: 21, Address: 0x1b580)
  • NtdspFindSite (Ordinal: 22, Address: 0x1bd60)
  • NtdspValidateInstallParameters (Ordinal: 23, Address: 0x1190)
  • NtdspVerifyDsEnvironment (Ordinal: 24, Address: 0x8460)

Imported DLLs & Functions

ADVAPI32.dll
  • ClearEventLogW (Address: 0x180028198)
  • CloseEventLog (Address: 0x1800281a8)
  • ConvertStringSDToSDDomainW (Address: 0x180028168)
  • DeregisterEventSource (Address: 0x1800281d8)
  • GetNamedSecurityInfoW (Address: 0x1800281b8)
  • LogonUserW (Address: 0x1800281c0)
  • LsaClose (Address: 0x180028180)
  • LsaFreeMemory (Address: 0x180028160)
  • LsaLookupNames (Address: 0x180028158)
  • LsaLookupSids (Address: 0x180028150)
  • LsaNtStatusToWinError (Address: 0x1800281e0)
  • LsaOpenPolicy (Address: 0x180028178)
  • LsaQueryInformationPolicy (Address: 0x180028170)
  • LsaSetInformationPolicy (Address: 0x180028188)
  • OpenEventLogW (Address: 0x1800281c8)
  • RegCreateKeyA (Address: 0x180028190)
  • RegCreateKeyW (Address: 0x1800281d0)
  • RegDeleteKeyW (Address: 0x1800281a0)
  • RegisterEventSourceW (Address: 0x180028140)
  • RegOpenKeyW (Address: 0x1800281e8)
  • ReportEventW (Address: 0x180028148)
  • SetEntriesInAclW (Address: 0x180028138)
  • SetNamedSecurityInfoW (Address: 0x1800281b0)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x1800285d8)
  • SetUnhandledExceptionFilter (Address: 0x1800285c8)
  • UnhandledExceptionFilter (Address: 0x1800285d0)
api-ms-win-core-file-l1-1-0.dll
  • CreateDirectoryW (Address: 0x1800285f8)
  • DeleteFileW (Address: 0x180028618)
  • FindClose (Address: 0x180028600)
  • FindFirstFileW (Address: 0x1800285e8)
  • FindNextFileW (Address: 0x180028610)
  • GetFileAttributesW (Address: 0x180028608)
  • RemoveDirectoryW (Address: 0x1800285f0)
  • SetFileAttributesW (Address: 0x180028620)
api-ms-win-core-file-l2-1-2.dll
  • CopyFileW (Address: 0x180028630)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x180028640)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x180028658)
  • HeapAlloc (Address: 0x180028660)
  • HeapFree (Address: 0x180028650)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x180028680)
  • LocalFree (Address: 0x180028670)
  • LocalReAlloc (Address: 0x180028678)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x180028690)
  • FreeLibrary (Address: 0x1800286a8)
  • GetModuleHandleA (Address: 0x1800286a0)
  • GetProcAddress (Address: 0x180028698)
  • LoadLibraryExA (Address: 0x1800286b8)
  • LoadLibraryExW (Address: 0x1800286b0)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x1800286c8)
  • GetUserDefaultLangID (Address: 0x1800286d0)
api-ms-win-core-processenvironment-l1-1-0.dll
  • ExpandEnvironmentStringsA (Address: 0x1800286e0)
  • GetEnvironmentVariableW (Address: 0x1800286e8)
api-ms-win-core-processthreads-l1-1-0.dll
  • ExitProcess (Address: 0x1800286f8)
  • GetCurrentProcess (Address: 0x180028718)
  • GetCurrentProcessId (Address: 0x180028708)
  • GetCurrentThreadId (Address: 0x180028710)
  • TerminateProcess (Address: 0x180028700)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x180028728)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x180028770)
  • RegCreateKeyExA (Address: 0x180028758)
  • RegDeleteTreeW (Address: 0x180028768)
  • RegDeleteValueW (Address: 0x180028788)
  • RegNotifyChangeKeyValue (Address: 0x180028780)
  • RegOpenKeyExA (Address: 0x180028738)
  • RegOpenKeyExW (Address: 0x180028760)
  • RegQueryValueExA (Address: 0x180028740)
  • RegQueryValueExW (Address: 0x180028748)
  • RegSetValueExA (Address: 0x180028750)
  • RegSetValueExW (Address: 0x180028778)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x1800287a0)
  • RtlLookupFunctionEntry (Address: 0x1800287a8)
  • RtlVirtualUnwind (Address: 0x180028798)
api-ms-win-core-string-l1-1-0.dll
  • CompareStringEx (Address: 0x1800287b8)
  • CompareStringW (Address: 0x1800287c0)
  • MultiByteToWideChar (Address: 0x1800287c8)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x1800287f0)
  • AcquireSRWLockShared (Address: 0x180028808)
  • CreateEventA (Address: 0x180028810)
  • DeleteCriticalSection (Address: 0x180028818)
  • EnterCriticalSection (Address: 0x1800287e8)
  • InitializeCriticalSection (Address: 0x180028800)
  • InitializeSRWLock (Address: 0x1800287e0)
  • LeaveCriticalSection (Address: 0x1800287f8)
  • ReleaseSRWLockExclusive (Address: 0x1800287d8)
  • ReleaseSRWLockShared (Address: 0x180028820)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x180028830)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetComputerNameExW (Address: 0x180028858)
  • GetSystemDirectoryW (Address: 0x180028860)
  • GetSystemTime (Address: 0x180028848)
  • GetSystemTimeAsFileTime (Address: 0x180028850)
  • GetTickCount (Address: 0x180028868)
  • GetWindowsDirectoryW (Address: 0x180028840)
api-ms-win-eventing-classicprovider-l1-1-0.dll
  • GetTraceEnableFlags (Address: 0x180028878)
  • GetTraceEnableLevel (Address: 0x180028880)
  • GetTraceLoggerHandle (Address: 0x180028888)
  • RegisterTraceGuidsW (Address: 0x180028898)
  • TraceMessageVa (Address: 0x180028890)
api-ms-win-security-base-l1-1-0.dll
  • AddAccessAllowedAceEx (Address: 0x1800288e0)
  • AddAce (Address: 0x1800288e8)
  • AllocateAndInitializeSid (Address: 0x180028958)
  • DuplicateToken (Address: 0x1800288d8)
  • EqualSid (Address: 0x180028930)
  • FindFirstFreeAce (Address: 0x180028960)
  • FreeSid (Address: 0x180028980)
  • GetAce (Address: 0x180028950)
  • GetAclInformation (Address: 0x180028948)
  • GetLengthSid (Address: 0x1800288c0)
  • GetSecurityDescriptorControl (Address: 0x180028920)
  • GetSecurityDescriptorDacl (Address: 0x1800288a8)
  • GetSecurityDescriptorGroup (Address: 0x180028928)
  • GetSecurityDescriptorLength (Address: 0x180028900)
  • GetSecurityDescriptorOwner (Address: 0x180028918)
  • GetSecurityDescriptorSacl (Address: 0x180028970)
  • ImpersonateLoggedOnUser (Address: 0x180028968)
  • InitializeAcl (Address: 0x1800288f8)
  • InitializeSecurityDescriptor (Address: 0x1800288d0)
  • IsValidSid (Address: 0x180028940)
  • MakeAbsoluteSD (Address: 0x1800288b8)
  • MakeSelfRelativeSD (Address: 0x1800288c8)
  • RevertToSelf (Address: 0x180028978)
  • SetSecurityDescriptorControl (Address: 0x180028908)
  • SetSecurityDescriptorDacl (Address: 0x1800288b0)
  • SetSecurityDescriptorGroup (Address: 0x1800288f0)
  • SetSecurityDescriptorOwner (Address: 0x180028938)
  • SetSecurityDescriptorSacl (Address: 0x180028910)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertSidToStringSidW (Address: 0x180028990)
api-ms-win-service-management-l1-1-0.dll
  • CloseServiceHandle (Address: 0x1800289a0)
  • CreateServiceW (Address: 0x1800289b0)
  • DeleteService (Address: 0x1800289b8)
  • OpenSCManagerW (Address: 0x1800289a8)
  • OpenServiceW (Address: 0x1800289c0)
api-ms-win-service-management-l2-1-0.dll
  • ChangeServiceConfig2W (Address: 0x1800289d0)
api-ms-win-service-winsvc-l1-1-0.dll
  • ControlService (Address: 0x1800289e0)
  • QueryServiceStatus (Address: 0x1800289e8)
bcrypt.dll
  • BCryptCloseAlgorithmProvider (Address: 0x180028a30)
  • BCryptCreateHash (Address: 0x180028a08)
  • BCryptDestroyHash (Address: 0x180028a10)
  • BCryptFinishHash (Address: 0x180028a18)
  • BCryptGenRandom (Address: 0x180028a20)
  • BCryptGetProperty (Address: 0x180028a00)
  • BCryptHashData (Address: 0x1800289f8)
  • BCryptOpenAlgorithmProvider (Address: 0x180028a28)
certcli.dll
  • CACreateLocalAutoEnrollmentObject (Address: 0x180028a40)
  • CADeleteLocalAutoEnrollmentObject (Address: 0x180028a48)
CRYPT32.dll
  • CryptProtectData (Address: 0x180028200)
  • CryptProtectMemory (Address: 0x180028208)
  • CryptUnprotectData (Address: 0x1800281f8)
  • CryptUnprotectMemory (Address: 0x180028210)
cryptdll.dll
  • CDGenerateRandomBits (Address: 0x180028a58)
DNSAPI.dll
  • DnsValidateName_W (Address: 0x180028220)
DSPARSE.dll
  • DsMakeSpnW (Address: 0x180028230)
KERNEL32.dll
  • GetComputerNameW (Address: 0x180028248)
  • GetPrivateProfileStringW (Address: 0x180028250)
  • MoveFileW (Address: 0x180028240)
logoncli.dll
  • DsGetDcNameW (Address: 0x180028a68)
LSASRV.dll
  • LsaIFree_LSAPR_POLICY_INFORMATION (Address: 0x180028288)
  • LsaIOpenPolicyTrusted (Address: 0x180028278)
  • LsaIQueryInformationPolicyTrusted (Address: 0x180028260)
  • LsaISafeMode (Address: 0x180028268)
  • LsarClose (Address: 0x180028270)
  • LsarSetInformationPolicy (Address: 0x180028280)
msvcrt.dll
  • __C_specific_handler (Address: 0x180028ad0)
  • _amsg_exit (Address: 0x180028b00)
  • _i64tow_s (Address: 0x180028bc8)
  • _initterm (Address: 0x180028af8)
  • _itow (Address: 0x180028b70)
  • _itow_s (Address: 0x180028b90)
  • _local_unwind (Address: 0x180028ab8)
  • _ltow (Address: 0x180028b30)
  • _msize (Address: 0x180028b40)
  • _ultow_s (Address: 0x180028aa8)
  • _vsnprintf (Address: 0x180028ac0)
  • _vsnwprintf (Address: 0x180028bc0)
  • _wcsdup (Address: 0x180028b48)
  • _wcsicmp (Address: 0x180028bb8)
  • _wcsnicmp (Address: 0x180028b60)
  • _wtoi (Address: 0x180028b38)
  • _wtol (Address: 0x180028b28)
  • _XcptFilter (Address: 0x180028b08)
  • atoi (Address: 0x180028ba8)
  • bsearch (Address: 0x180028a88)
  • free (Address: 0x180028bb0)
  • isdigit (Address: 0x180028a98)
  • iswascii (Address: 0x180028b10)
  • iswcntrl (Address: 0x180028a90)
  • isxdigit (Address: 0x180028a80)
  • malloc (Address: 0x180028ba0)
  • memcmp (Address: 0x180028ad8)
  • memcpy (Address: 0x180028ae0)
  • memmove (Address: 0x180028ae8)
  • memset (Address: 0x180028af0)
  • qsort (Address: 0x180028b58)
  • strrchr (Address: 0x180028b50)
  • strtoul (Address: 0x180028a78)
  • swprintf_s (Address: 0x180028ac8)
  • tolower (Address: 0x180028b20)
  • wcschr (Address: 0x180028b78)
  • wcscmp (Address: 0x180028bd0)
  • wcscpy_s (Address: 0x180028b88)
  • wcsncmp (Address: 0x180028aa0)
  • wcsstr (Address: 0x180028b68)
  • wcstok (Address: 0x180028b18)
  • wcstol (Address: 0x180028b98)
  • wcstoul (Address: 0x180028b80)
  • wprintf (Address: 0x180028ab0)
netutils.dll
  • NetApiBufferFree (Address: 0x180028be0)
ntdll.dll
  • EtwEventRegister (Address: 0x180028cd8)
  • EtwEventUnregister (Address: 0x180028c60)
  • EvtIntReportEventAndSourceAsync (Address: 0x180028cd0)
  • NtClose (Address: 0x180028c18)
  • NtDeleteKey (Address: 0x180028c48)
  • NtEnumerateKey (Address: 0x180028c40)
  • NtOpenKey (Address: 0x180028c38)
  • NtOpenThreadToken (Address: 0x180028c10)
  • NtQueryKey (Address: 0x180028c58)
  • NtSetInformationThread (Address: 0x180028c30)
  • RtlAllocateAndInitializeSid (Address: 0x180028cb0)
  • RtlAllocateHeap (Address: 0x180028cc0)
  • RtlConvertSidToUnicodeString (Address: 0x180028bf0)
  • RtlCopySid (Address: 0x180028c70)
  • RtlEqualSid (Address: 0x180028c08)
  • RtlFreeHeap (Address: 0x180028ca8)
  • RtlGetNtProductType (Address: 0x180028c28)
  • RtlIdentifierAuthoritySid (Address: 0x180028bf8)
  • RtlInitializeSid (Address: 0x180028c90)
  • RtlInitUnicodeString (Address: 0x180028cb8)
  • RtlLargeIntegerToChar (Address: 0x180028c00)
  • RtlLengthRequiredSid (Address: 0x180028c78)
  • RtlLengthSecurityDescriptor (Address: 0x180028c50)
  • RtlLengthSid (Address: 0x180028cc8)
  • RtlNtStatusToDosError (Address: 0x180028ca0)
  • RtlReAllocateHeap (Address: 0x180028c20)
  • RtlSubAuthorityCountSid (Address: 0x180028c80)
  • RtlSubAuthoritySid (Address: 0x180028c88)
  • RtlValidSid (Address: 0x180028c98)
  • WinSqmAddToStream (Address: 0x180028c68)
  • WinSqmIsOptedIn (Address: 0x180028ce0)
NTDSA.dll
  • AppendRDN (Address: 0x180028298)
  • CountNameParts (Address: 0x180028370)
  • DirAddEntry (Address: 0x180028360)
  • DirErrorToWinError (Address: 0x180028310)
  • DirModifyEntry (Address: 0x180028340)
  • DirRead (Address: 0x180028358)
  • DirReplicaAdd (Address: 0x1800282f0)
  • DirReplicaDemote (Address: 0x180028330)
  • DirReplicaGetDemoteTarget (Address: 0x180028348)
  • DirReplicaSetCredentials (Address: 0x180028368)
  • DirReplicaSynchronize (Address: 0x180028318)
  • DirSearch (Address: 0x180028380)
  • DsaDisableUpdates (Address: 0x180028308)
  • DsaEnableUpdates (Address: 0x1800282f8)
  • DsaSetInstallCallback (Address: 0x180028328)
  • DsInitialize (Address: 0x180028390)
  • DSInstanceFromNameEx (Address: 0x180028320)
  • DSInstanceFromSetupEx (Address: 0x180028338)
  • DsIsDCReadOnly (Address: 0x1800283b0)
  • DsLoadDLL (Address: 0x1800282e0)
  • DsUninitialize (Address: 0x1800282e8)
  • DsUnloadDLL (Address: 0x1800282b8)
  • GetConfigurationName (Address: 0x1800283a0)
  • GetConfigurationNamesList (Address: 0x1800282b0)
  • GetRDNInfoExternal (Address: 0x1800282d8)
  • InitCommarg (Address: 0x180028350)
  • NameMatched (Address: 0x1800283a8)
  • NameMatchedStringNameOnly (Address: 0x180028398)
  • QuoteRDNValue (Address: 0x180028388)
  • SampSetDsa (Address: 0x1800282a0)
  • THAlloc (Address: 0x1800282c0)
  • THClearErrors (Address: 0x1800282c8)
  • THCreate (Address: 0x1800282a8)
  • THDestroy (Address: 0x180028300)
  • THFree (Address: 0x1800282d0)
  • THGetErrorString (Address: 0x180028378)
  • THQuery (Address: 0x1800283c0)
  • TrimDSNameBy (Address: 0x1800283b8)
NTDSAPI.dll
  • DsBindByInstanceW (Address: 0x1800283d0)
  • DsBindWithCredW (Address: 0x1800283e0)
  • DsBindWithSpnExW (Address: 0x1800283e8)
  • DsFinishDemotionW (Address: 0x180028400)
  • DsInitDemotionW (Address: 0x180028410)
  • DsRemoveDsDomainW (Address: 0x180028418)
  • DsRemoveDsServerW (Address: 0x1800283f8)
  • DsReplicaDemotionW (Address: 0x1800283d8)
  • DsReplicaSyncW (Address: 0x1800283f0)
  • DsUnBindW (Address: 0x180028408)
ntdsbsrv.dll
  • NtdsbsrvDllInit (Address: 0x180028cf0)
  • UnInstallBackupServices (Address: 0x180028cf8)
RPCRT4.dll
  • RpcStringFreeW (Address: 0x180028430)
  • UuidCreate (Address: 0x180028438)
  • UuidToStringW (Address: 0x180028428)
SAMSRV.dll
  • SamIDemote (Address: 0x180028460)
  • SamIDemoteUndo (Address: 0x180028458)
  • SamILoadDownlevelDatabase (Address: 0x180028480)
  • SamIPromote (Address: 0x180028448)
  • SamIPromoteUndo (Address: 0x180028468)
  • SamIReplaceDownlevelDatabase (Address: 0x180028470)
  • SamIUnLoadDownlevelDatabase (Address: 0x180028450)
  • SampUsingDsData (Address: 0x180028478)
SHLWAPI.dll
  • PathIsRootW (Address: 0x180028490)
WLDAP32.dll
  • (Address: 0x1800284a0)
  • (Address: 0x1800284a8)
  • (Address: 0x1800284b0)
  • (Address: 0x1800284b8)
  • (Address: 0x1800284c0)
  • (Address: 0x1800284c8)
  • (Address: 0x1800284d0)
  • (Address: 0x1800284d8)
  • (Address: 0x1800284e0)
  • (Address: 0x1800284e8)
  • (Address: 0x1800284f0)
  • (Address: 0x1800284f8)
  • (Address: 0x180028500)
  • (Address: 0x180028508)
  • (Address: 0x180028510)
  • (Address: 0x180028518)
  • (Address: 0x180028520)
  • (Address: 0x180028528)
  • (Address: 0x180028530)
  • (Address: 0x180028538)
  • (Address: 0x180028540)
  • (Address: 0x180028548)
  • (Address: 0x180028550)
  • (Address: 0x180028558)
  • (Address: 0x180028560)
  • (Address: 0x180028568)
  • (Address: 0x180028570)
  • (Address: 0x180028578)
  • (Address: 0x180028580)
  • (Address: 0x180028588)
  • (Address: 0x180028590)
  • (Address: 0x180028598)
  • (Address: 0x1800285a0)
  • (Address: 0x1800285a8)
WS2_32.dll
  • ntohl (Address: 0x1800285b8)