ntdsbsrv.dll
Description: NT5DS
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.6033
Architecture: 64-bit
Operating System: Windows NT
SHA256: 16a93ed94a64b8b199951b0d43753241
File Size: 126.0 KB
Uploaded At: Dec. 1, 2025, 8:12 a.m.
Views: 13
Exported Functions
- ??0CVssJetWriterBase@@QEAA@XZ (Ordinal: 1, Address: 0x4de0)
- ??1CVssJetWriterBase@@UEAA@XZ (Ordinal: 2, Address: 0xcfd0)
- ?AreComponentsSelected@CVssJetWriterBase@@IEBA_NXZ (Ordinal: 3, Address: 0xcff0)
- ?GetBackupType@CVssJetWriterBase@@IEBA?AW4_VSS_BACKUP_TYPE@@XZ (Ordinal: 4, Address: 0xd030)
- ?GetContext@CVssJetWriterBase@@IEBAJXZ (Ordinal: 5, Address: 0xd070)
- ?GetCurrentLevel@CVssJetWriterBase@@IEBA?AW4_VSS_APPLICATION_LEVEL@@XZ (Ordinal: 6, Address: 0xd0b0)
- ?GetCurrentSnapshotSetId@CVssJetWriterBase@@IEBA?AU_GUID@@XZ (Ordinal: 7, Address: 0xd0e0)
- ?GetCurrentVolumeArray@CVssJetWriterBase@@IEBAPEAPEBGXZ (Ordinal: 8, Address: 0xd130)
- ?GetCurrentVolumeCount@CVssJetWriterBase@@IEBAIXZ (Ordinal: 9, Address: 0xd170)
- ?GetRestoreType@CVssJetWriterBase@@IEBA?AW4_VSS_RESTORE_TYPE@@XZ (Ordinal: 10, Address: 0xd1b0)
- ?GetSnapshotDeviceName@CVssJetWriterBase@@IEBAJPEBGPEAPEBG@Z (Ordinal: 11, Address: 0xd1f0)
- ?Initialize@CVssJetWriterBase@@QEAAJU_GUID@@PEBG_N211K@Z (Ordinal: 12, Address: 0xd220)
- ?IsBootableSystemStateBackedUp@CVssJetWriterBase@@IEBA_NXZ (Ordinal: 13, Address: 0xd4e0)
- ?IsPartialFileSupportEnabled@CVssJetWriterBase@@IEBA_NXZ (Ordinal: 14, Address: 0xd520)
- ?IsPathAffected@CVssJetWriterBase@@IEBA_NPEBG@Z (Ordinal: 15, Address: 0xd560)
- ?OnAbortBegin@CVssJetWriterBase@@UEAAXXZ (Ordinal: 16, Address: 0xc2a0)
- ?OnAbortEnd@CVssJetWriterBase@@UEAAXXZ (Ordinal: 17, Address: 0xc2a0)
- ?OnBackupCompleteBegin@CVssJetWriterBase@@UEAA_NPEAVIVssWriterComponents@@@Z (Ordinal: 18, Address: 0x8720)
- ?OnBackupCompleteEnd@CVssJetWriterBase@@UEAA_NPEAVIVssWriterComponents@@_N@Z (Ordinal: 19, Address: 0x8720)
- ?OnFreezeBegin@CVssJetWriterBase@@UEAA_NXZ (Ordinal: 20, Address: 0x8720)
- ?OnFreezeEnd@CVssJetWriterBase@@UEAA_N_N@Z (Ordinal: 21, Address: 0xd5a0)
- ?OnIdentify@CVssJetWriterBase@@UEAA_NPEAVIVssCreateWriterMetadata@@@Z (Ordinal: 22, Address: 0x8720)
- ?OnPostRestoreBegin@CVssJetWriterBase@@UEAA_NPEAVIVssWriterComponents@@@Z (Ordinal: 23, Address: 0x8720)
- ?OnPostRestoreEnd@CVssJetWriterBase@@UEAA_NPEAVIVssWriterComponents@@_N@Z (Ordinal: 24, Address: 0x8720)
- ?OnPostSnapshot@CVssJetWriterBase@@UEAA_NPEAVIVssWriterComponents@@@Z (Ordinal: 25, Address: 0x8720)
- ?OnPreRestoreBegin@CVssJetWriterBase@@UEAA_NPEAVIVssWriterComponents@@@Z (Ordinal: 26, Address: 0x8720)
- ?OnPreRestoreEnd@CVssJetWriterBase@@UEAA_NPEAVIVssWriterComponents@@_N@Z (Ordinal: 27, Address: 0x8720)
- ?OnPrepareBackupBegin@CVssJetWriterBase@@UEAA_NPEAVIVssWriterComponents@@@Z (Ordinal: 28, Address: 0x8720)
- ?OnPrepareBackupEnd@CVssJetWriterBase@@UEAA_NPEAVIVssWriterComponents@@_N@Z (Ordinal: 29, Address: 0xd5b0)
- ?OnPrepareSnapshotBegin@CVssJetWriterBase@@UEAA_NXZ (Ordinal: 30, Address: 0x8720)
- ?OnPrepareSnapshotEnd@CVssJetWriterBase@@UEAA_N_N@Z (Ordinal: 31, Address: 0xd5a0)
- ?OnThawBegin@CVssJetWriterBase@@UEAA_NXZ (Ordinal: 32, Address: 0x8720)
- ?OnThawEnd@CVssJetWriterBase@@UEAA_N_N@Z (Ordinal: 33, Address: 0xd5a0)
- ?SetWriterFailure@CVssJetWriterBase@@IEAAJJ@Z (Ordinal: 34, Address: 0xd5c0)
- ?Uninitialize@CVssJetWriterBase@@QEAAXXZ (Ordinal: 35, Address: 0xd760)
- InstallBackupServices (Ordinal: 36, Address: 0x2a30)
- NtdsbsrvDllInit (Ordinal: 37, Address: 0x1110)
- RegisterBackupServices (Ordinal: 38, Address: 0x3a20)
- UnInstallBackupServices (Ordinal: 39, Address: 0x117c0)
- UnRegisterBackupServices (Ordinal: 40, Address: 0x11890)
- UpdateBackupExclusionKey (Ordinal: 41, Address: 0x2fa0)
Imported DLLs & Functions
ADVAPI32.dll
- DeregisterEventSource (Address: 0x180018478)
- RegisterEventSourceW (Address: 0x180018470)
- ReportEventW (Address: 0x180018468)
api-ms-win-core-com-l1-1-0.dll
- CoInitializeEx (Address: 0x1800184d8)
- CoInitializeSecurity (Address: 0x1800184e0)
- CoUninitialize (Address: 0x1800184e8)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x180018500)
- IsDebuggerPresent (Address: 0x1800184f8)
- OutputDebugStringW (Address: 0x180018508)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x180018518)
- RaiseException (Address: 0x180018528)
- SetLastError (Address: 0x180018520)
- SetUnhandledExceptionFilter (Address: 0x180018538)
- UnhandledExceptionFilter (Address: 0x180018530)
api-ms-win-core-file-l1-1-0.dll
- CreateDirectoryA (Address: 0x180018548)
- GetFullPathNameW (Address: 0x180018550)
api-ms-win-core-file-l1-2-2.dll
- GetTempFileNameA (Address: 0x180018568)
- GetTempPathA (Address: 0x180018560)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x180018578)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x180018588)
- HeapAlloc (Address: 0x180018598)
- HeapFree (Address: 0x180018590)
api-ms-win-core-heap-l2-1-0.dll
- LocalAlloc (Address: 0x1800185b0)
- LocalFree (Address: 0x1800185a8)
api-ms-win-core-libraryloader-l1-2-0.dll
- DisableThreadLibraryCalls (Address: 0x1800185f0)
- FreeLibrary (Address: 0x1800185d0)
- GetModuleFileNameA (Address: 0x1800185c8)
- GetModuleHandleA (Address: 0x1800185d8)
- GetModuleHandleExW (Address: 0x1800185e8)
- GetModuleHandleW (Address: 0x1800185f8)
- GetProcAddress (Address: 0x1800185e0)
- LoadLibraryExA (Address: 0x1800185c0)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x180018608)
api-ms-win-core-processenvironment-l1-1-0.dll
- ExpandEnvironmentStringsA (Address: 0x180018618)
- ExpandEnvironmentStringsW (Address: 0x180018620)
api-ms-win-core-processthreads-l1-1-0.dll
- CreateThread (Address: 0x180018630)
- GetCurrentProcess (Address: 0x180018648)
- GetCurrentProcessId (Address: 0x180018658)
- GetCurrentThread (Address: 0x180018650)
- GetCurrentThreadId (Address: 0x180018660)
- GetExitCodeThread (Address: 0x180018670)
- OpenProcessToken (Address: 0x180018640)
- OpenThreadToken (Address: 0x180018638)
- TerminateProcess (Address: 0x180018668)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x180018680)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x1800186d0)
- RegCreateKeyExA (Address: 0x1800186a0)
- RegCreateKeyExW (Address: 0x1800186e0)
- RegDeleteKeyExA (Address: 0x1800186b0)
- RegDeleteValueW (Address: 0x1800186d8)
- RegNotifyChangeKeyValue (Address: 0x180018698)
- RegOpenKeyExA (Address: 0x1800186c8)
- RegOpenKeyExW (Address: 0x1800186c0)
- RegQueryValueExA (Address: 0x1800186b8)
- RegQueryValueExW (Address: 0x1800186e8)
- RegSetValueExA (Address: 0x180018690)
- RegSetValueExW (Address: 0x1800186a8)
api-ms-win-core-rtlsupport-l1-1-0.dll
- RtlCaptureContext (Address: 0x1800186f8)
- RtlLookupFunctionEntry (Address: 0x180018708)
- RtlVirtualUnwind (Address: 0x180018700)
api-ms-win-core-string-l1-1-0.dll
- MultiByteToWideChar (Address: 0x180018718)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x180018760)
- AcquireSRWLockShared (Address: 0x180018750)
- CreateEventA (Address: 0x1800187a8)
- CreateMutexExW (Address: 0x180018728)
- CreateSemaphoreExW (Address: 0x180018798)
- DeleteCriticalSection (Address: 0x180018730)
- EnterCriticalSection (Address: 0x1800187b0)
- InitializeCriticalSection (Address: 0x180018780)
- InitializeCriticalSectionEx (Address: 0x180018778)
- InitializeSRWLock (Address: 0x1800187a0)
- LeaveCriticalSection (Address: 0x1800187b8)
- OpenSemaphoreW (Address: 0x180018748)
- ReleaseMutex (Address: 0x180018770)
- ReleaseSemaphore (Address: 0x180018788)
- ReleaseSRWLockExclusive (Address: 0x180018768)
- ReleaseSRWLockShared (Address: 0x180018740)
- SetEvent (Address: 0x180018738)
- WaitForSingleObject (Address: 0x180018790)
- WaitForSingleObjectEx (Address: 0x180018758)
api-ms-win-core-synch-l1-2-0.dll
- Sleep (Address: 0x1800187c8)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemTime (Address: 0x1800187e8)
- GetSystemTimeAsFileTime (Address: 0x1800187d8)
- GetTickCount (Address: 0x1800187e0)
api-ms-win-core-threadpool-l1-2-0.dll
- CloseThreadpoolTimer (Address: 0x180018800)
- CreateThreadpoolTimer (Address: 0x180018810)
- SetThreadpoolTimer (Address: 0x1800187f8)
- WaitForThreadpoolTimerCallbacks (Address: 0x180018808)
api-ms-win-eventing-classicprovider-l1-1-0.dll
- GetTraceEnableFlags (Address: 0x180018838)
- GetTraceEnableLevel (Address: 0x180018830)
- GetTraceLoggerHandle (Address: 0x180018840)
- RegisterTraceGuidsW (Address: 0x180018848)
- TraceMessageVa (Address: 0x180018820)
- UnregisterTraceGuids (Address: 0x180018828)
api-ms-win-security-base-l1-1-0.dll
- CopySid (Address: 0x180018860)
- GetLengthSid (Address: 0x180018868)
- GetTokenInformation (Address: 0x180018858)
- MakeAbsoluteSD (Address: 0x180018870)
api-ms-win-security-sddl-l1-1-0.dll
- ConvertSidToStringSidW (Address: 0x180018888)
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x180018880)
api-ms-win-service-management-l1-1-0.dll
- CloseServiceHandle (Address: 0x180018898)
api-ms-win-service-winsvc-l1-1-0.dll
- ControlService (Address: 0x1800188c0)
- OpenSCManagerA (Address: 0x1800188c8)
- OpenServiceA (Address: 0x1800188b8)
- QueryServiceConfigA (Address: 0x1800188a8)
- QueryServiceStatus (Address: 0x1800188b0)
bcrypt.dll
- BCryptCloseAlgorithmProvider (Address: 0x1800188f0)
- BCryptCreateHash (Address: 0x1800188f8)
- BCryptDestroyHash (Address: 0x180018910)
- BCryptFinishHash (Address: 0x1800188e8)
- BCryptGenRandom (Address: 0x180018908)
- BCryptGetProperty (Address: 0x1800188e0)
- BCryptHashData (Address: 0x1800188d8)
- BCryptOpenAlgorithmProvider (Address: 0x180018900)
KERNEL32.dll
- GetComputerNameW (Address: 0x180018488)
msvcrt.dll
- __C_specific_handler (Address: 0x180018a50)
- __CxxFrameHandler3 (Address: 0x180018a68)
- __dllonexit (Address: 0x180018a80)
- _amsg_exit (Address: 0x180018a58)
- _beginthreadex (Address: 0x1800189f0)
- _callnewh (Address: 0x180018a38)
- _CxxThrowException (Address: 0x180018a40)
- _errno (Address: 0x1800189e0)
- _i64tow_s (Address: 0x1800189c0)
- _initterm (Address: 0x180018a60)
- _itow_s (Address: 0x180018978)
- _local_unwind (Address: 0x180018970)
- _lock (Address: 0x180018a70)
- _onexit (Address: 0x180018a90)
- _purecall (Address: 0x180018950)
- _stricmp (Address: 0x180018a18)
- _ultow_s (Address: 0x180018988)
- _unlock (Address: 0x180018a78)
- _vsnprintf (Address: 0x1800189e8)
- _vsnwprintf (Address: 0x180018a88)
- _wcsdup (Address: 0x180018958)
- _wcsicmp (Address: 0x180018960)
- _wcsnicmp (Address: 0x180018938)
- _XcptFilter (Address: 0x180018a48)
- ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x180018a10)
- ??0exception@@QEAA@AEBV0@@Z (Address: 0x180018a20)
- ??1exception@@UEAA@XZ (Address: 0x180018a28)
- ??1type_info@@UEAA@XZ (Address: 0x180018a98)
- ?what@exception@@UEBAPEBDXZ (Address: 0x180018a30)
- bsearch (Address: 0x1800189b0)
- free (Address: 0x1800189f8)
- isdigit (Address: 0x1800189b8)
- iswcntrl (Address: 0x180018990)
- isxdigit (Address: 0x1800189a8)
- malloc (Address: 0x1800189c8)
- memcmp (Address: 0x180018a00)
- memcpy (Address: 0x180018a08)
- memcpy_s (Address: 0x180018968)
- memmove_s (Address: 0x180018928)
- memset (Address: 0x180018aa0)
- qsort (Address: 0x1800189a0)
- strrchr (Address: 0x1800189d0)
- strtoul (Address: 0x180018998)
- towlower (Address: 0x180018aa8)
- towupper (Address: 0x180018930)
- wcschr (Address: 0x180018940)
- wcscmp (Address: 0x180018ab0)
- wcspbrk (Address: 0x180018948)
- wcsrchr (Address: 0x180018920)
- wcsstr (Address: 0x1800189d8)
- wprintf (Address: 0x180018980)
ntdll.dll
- EtwEventRegister (Address: 0x180018ac0)
- EtwEventUnregister (Address: 0x180018ac8)
- EvtIntReportEventAndSourceAsync (Address: 0x180018ad8)
- RtlConvertSidToUnicodeString (Address: 0x180018ad0)
- RtlLargeIntegerToChar (Address: 0x180018ae0)
NTDSA.dll
- DBDsReplBackupUpdate (Address: 0x1800184a8)
- DBUpdateBackupTimeStamps (Address: 0x180018498)
- DsRegisterServiceStateCallback (Address: 0x1800184a0)
- DsUnregisterServiceStateCallback (Address: 0x1800184b0)
- GetConfigurationInfo (Address: 0x1800184b8)
VSSAPI.DLL
- CreateWriter (Address: 0x1800184c8)