ntdsbsrv.dll

Description: NT5DS

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.6033

Architecture: 64-bit

Operating System: Windows NT

SHA256: 16a93ed94a64b8b199951b0d43753241

File Size: 126.0 KB

Uploaded At: Dec. 1, 2025, 8:12 a.m.

Views: 13

Exported Functions

  • ??0CVssJetWriterBase@@QEAA@XZ (Ordinal: 1, Address: 0x4de0)
  • ??1CVssJetWriterBase@@UEAA@XZ (Ordinal: 2, Address: 0xcfd0)
  • ?AreComponentsSelected@CVssJetWriterBase@@IEBA_NXZ (Ordinal: 3, Address: 0xcff0)
  • ?GetBackupType@CVssJetWriterBase@@IEBA?AW4_VSS_BACKUP_TYPE@@XZ (Ordinal: 4, Address: 0xd030)
  • ?GetContext@CVssJetWriterBase@@IEBAJXZ (Ordinal: 5, Address: 0xd070)
  • ?GetCurrentLevel@CVssJetWriterBase@@IEBA?AW4_VSS_APPLICATION_LEVEL@@XZ (Ordinal: 6, Address: 0xd0b0)
  • ?GetCurrentSnapshotSetId@CVssJetWriterBase@@IEBA?AU_GUID@@XZ (Ordinal: 7, Address: 0xd0e0)
  • ?GetCurrentVolumeArray@CVssJetWriterBase@@IEBAPEAPEBGXZ (Ordinal: 8, Address: 0xd130)
  • ?GetCurrentVolumeCount@CVssJetWriterBase@@IEBAIXZ (Ordinal: 9, Address: 0xd170)
  • ?GetRestoreType@CVssJetWriterBase@@IEBA?AW4_VSS_RESTORE_TYPE@@XZ (Ordinal: 10, Address: 0xd1b0)
  • ?GetSnapshotDeviceName@CVssJetWriterBase@@IEBAJPEBGPEAPEBG@Z (Ordinal: 11, Address: 0xd1f0)
  • ?Initialize@CVssJetWriterBase@@QEAAJU_GUID@@PEBG_N211K@Z (Ordinal: 12, Address: 0xd220)
  • ?IsBootableSystemStateBackedUp@CVssJetWriterBase@@IEBA_NXZ (Ordinal: 13, Address: 0xd4e0)
  • ?IsPartialFileSupportEnabled@CVssJetWriterBase@@IEBA_NXZ (Ordinal: 14, Address: 0xd520)
  • ?IsPathAffected@CVssJetWriterBase@@IEBA_NPEBG@Z (Ordinal: 15, Address: 0xd560)
  • ?OnAbortBegin@CVssJetWriterBase@@UEAAXXZ (Ordinal: 16, Address: 0xc2a0)
  • ?OnAbortEnd@CVssJetWriterBase@@UEAAXXZ (Ordinal: 17, Address: 0xc2a0)
  • ?OnBackupCompleteBegin@CVssJetWriterBase@@UEAA_NPEAVIVssWriterComponents@@@Z (Ordinal: 18, Address: 0x8720)
  • ?OnBackupCompleteEnd@CVssJetWriterBase@@UEAA_NPEAVIVssWriterComponents@@_N@Z (Ordinal: 19, Address: 0x8720)
  • ?OnFreezeBegin@CVssJetWriterBase@@UEAA_NXZ (Ordinal: 20, Address: 0x8720)
  • ?OnFreezeEnd@CVssJetWriterBase@@UEAA_N_N@Z (Ordinal: 21, Address: 0xd5a0)
  • ?OnIdentify@CVssJetWriterBase@@UEAA_NPEAVIVssCreateWriterMetadata@@@Z (Ordinal: 22, Address: 0x8720)
  • ?OnPostRestoreBegin@CVssJetWriterBase@@UEAA_NPEAVIVssWriterComponents@@@Z (Ordinal: 23, Address: 0x8720)
  • ?OnPostRestoreEnd@CVssJetWriterBase@@UEAA_NPEAVIVssWriterComponents@@_N@Z (Ordinal: 24, Address: 0x8720)
  • ?OnPostSnapshot@CVssJetWriterBase@@UEAA_NPEAVIVssWriterComponents@@@Z (Ordinal: 25, Address: 0x8720)
  • ?OnPreRestoreBegin@CVssJetWriterBase@@UEAA_NPEAVIVssWriterComponents@@@Z (Ordinal: 26, Address: 0x8720)
  • ?OnPreRestoreEnd@CVssJetWriterBase@@UEAA_NPEAVIVssWriterComponents@@_N@Z (Ordinal: 27, Address: 0x8720)
  • ?OnPrepareBackupBegin@CVssJetWriterBase@@UEAA_NPEAVIVssWriterComponents@@@Z (Ordinal: 28, Address: 0x8720)
  • ?OnPrepareBackupEnd@CVssJetWriterBase@@UEAA_NPEAVIVssWriterComponents@@_N@Z (Ordinal: 29, Address: 0xd5b0)
  • ?OnPrepareSnapshotBegin@CVssJetWriterBase@@UEAA_NXZ (Ordinal: 30, Address: 0x8720)
  • ?OnPrepareSnapshotEnd@CVssJetWriterBase@@UEAA_N_N@Z (Ordinal: 31, Address: 0xd5a0)
  • ?OnThawBegin@CVssJetWriterBase@@UEAA_NXZ (Ordinal: 32, Address: 0x8720)
  • ?OnThawEnd@CVssJetWriterBase@@UEAA_N_N@Z (Ordinal: 33, Address: 0xd5a0)
  • ?SetWriterFailure@CVssJetWriterBase@@IEAAJJ@Z (Ordinal: 34, Address: 0xd5c0)
  • ?Uninitialize@CVssJetWriterBase@@QEAAXXZ (Ordinal: 35, Address: 0xd760)
  • InstallBackupServices (Ordinal: 36, Address: 0x2a30)
  • NtdsbsrvDllInit (Ordinal: 37, Address: 0x1110)
  • RegisterBackupServices (Ordinal: 38, Address: 0x3a20)
  • UnInstallBackupServices (Ordinal: 39, Address: 0x117c0)
  • UnRegisterBackupServices (Ordinal: 40, Address: 0x11890)
  • UpdateBackupExclusionKey (Ordinal: 41, Address: 0x2fa0)

Imported DLLs & Functions

ADVAPI32.dll
  • DeregisterEventSource (Address: 0x180018478)
  • RegisterEventSourceW (Address: 0x180018470)
  • ReportEventW (Address: 0x180018468)
api-ms-win-core-com-l1-1-0.dll
  • CoInitializeEx (Address: 0x1800184d8)
  • CoInitializeSecurity (Address: 0x1800184e0)
  • CoUninitialize (Address: 0x1800184e8)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x180018500)
  • IsDebuggerPresent (Address: 0x1800184f8)
  • OutputDebugStringW (Address: 0x180018508)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x180018518)
  • RaiseException (Address: 0x180018528)
  • SetLastError (Address: 0x180018520)
  • SetUnhandledExceptionFilter (Address: 0x180018538)
  • UnhandledExceptionFilter (Address: 0x180018530)
api-ms-win-core-file-l1-1-0.dll
  • CreateDirectoryA (Address: 0x180018548)
  • GetFullPathNameW (Address: 0x180018550)
api-ms-win-core-file-l1-2-2.dll
  • GetTempFileNameA (Address: 0x180018568)
  • GetTempPathA (Address: 0x180018560)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x180018578)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x180018588)
  • HeapAlloc (Address: 0x180018598)
  • HeapFree (Address: 0x180018590)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x1800185b0)
  • LocalFree (Address: 0x1800185a8)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x1800185f0)
  • FreeLibrary (Address: 0x1800185d0)
  • GetModuleFileNameA (Address: 0x1800185c8)
  • GetModuleHandleA (Address: 0x1800185d8)
  • GetModuleHandleExW (Address: 0x1800185e8)
  • GetModuleHandleW (Address: 0x1800185f8)
  • GetProcAddress (Address: 0x1800185e0)
  • LoadLibraryExA (Address: 0x1800185c0)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x180018608)
api-ms-win-core-processenvironment-l1-1-0.dll
  • ExpandEnvironmentStringsA (Address: 0x180018618)
  • ExpandEnvironmentStringsW (Address: 0x180018620)
api-ms-win-core-processthreads-l1-1-0.dll
  • CreateThread (Address: 0x180018630)
  • GetCurrentProcess (Address: 0x180018648)
  • GetCurrentProcessId (Address: 0x180018658)
  • GetCurrentThread (Address: 0x180018650)
  • GetCurrentThreadId (Address: 0x180018660)
  • GetExitCodeThread (Address: 0x180018670)
  • OpenProcessToken (Address: 0x180018640)
  • OpenThreadToken (Address: 0x180018638)
  • TerminateProcess (Address: 0x180018668)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x180018680)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x1800186d0)
  • RegCreateKeyExA (Address: 0x1800186a0)
  • RegCreateKeyExW (Address: 0x1800186e0)
  • RegDeleteKeyExA (Address: 0x1800186b0)
  • RegDeleteValueW (Address: 0x1800186d8)
  • RegNotifyChangeKeyValue (Address: 0x180018698)
  • RegOpenKeyExA (Address: 0x1800186c8)
  • RegOpenKeyExW (Address: 0x1800186c0)
  • RegQueryValueExA (Address: 0x1800186b8)
  • RegQueryValueExW (Address: 0x1800186e8)
  • RegSetValueExA (Address: 0x180018690)
  • RegSetValueExW (Address: 0x1800186a8)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x1800186f8)
  • RtlLookupFunctionEntry (Address: 0x180018708)
  • RtlVirtualUnwind (Address: 0x180018700)
api-ms-win-core-string-l1-1-0.dll
  • MultiByteToWideChar (Address: 0x180018718)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x180018760)
  • AcquireSRWLockShared (Address: 0x180018750)
  • CreateEventA (Address: 0x1800187a8)
  • CreateMutexExW (Address: 0x180018728)
  • CreateSemaphoreExW (Address: 0x180018798)
  • DeleteCriticalSection (Address: 0x180018730)
  • EnterCriticalSection (Address: 0x1800187b0)
  • InitializeCriticalSection (Address: 0x180018780)
  • InitializeCriticalSectionEx (Address: 0x180018778)
  • InitializeSRWLock (Address: 0x1800187a0)
  • LeaveCriticalSection (Address: 0x1800187b8)
  • OpenSemaphoreW (Address: 0x180018748)
  • ReleaseMutex (Address: 0x180018770)
  • ReleaseSemaphore (Address: 0x180018788)
  • ReleaseSRWLockExclusive (Address: 0x180018768)
  • ReleaseSRWLockShared (Address: 0x180018740)
  • SetEvent (Address: 0x180018738)
  • WaitForSingleObject (Address: 0x180018790)
  • WaitForSingleObjectEx (Address: 0x180018758)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x1800187c8)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTime (Address: 0x1800187e8)
  • GetSystemTimeAsFileTime (Address: 0x1800187d8)
  • GetTickCount (Address: 0x1800187e0)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x180018800)
  • CreateThreadpoolTimer (Address: 0x180018810)
  • SetThreadpoolTimer (Address: 0x1800187f8)
  • WaitForThreadpoolTimerCallbacks (Address: 0x180018808)
api-ms-win-eventing-classicprovider-l1-1-0.dll
  • GetTraceEnableFlags (Address: 0x180018838)
  • GetTraceEnableLevel (Address: 0x180018830)
  • GetTraceLoggerHandle (Address: 0x180018840)
  • RegisterTraceGuidsW (Address: 0x180018848)
  • TraceMessageVa (Address: 0x180018820)
  • UnregisterTraceGuids (Address: 0x180018828)
api-ms-win-security-base-l1-1-0.dll
  • CopySid (Address: 0x180018860)
  • GetLengthSid (Address: 0x180018868)
  • GetTokenInformation (Address: 0x180018858)
  • MakeAbsoluteSD (Address: 0x180018870)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertSidToStringSidW (Address: 0x180018888)
  • ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x180018880)
api-ms-win-service-management-l1-1-0.dll
  • CloseServiceHandle (Address: 0x180018898)
api-ms-win-service-winsvc-l1-1-0.dll
  • ControlService (Address: 0x1800188c0)
  • OpenSCManagerA (Address: 0x1800188c8)
  • OpenServiceA (Address: 0x1800188b8)
  • QueryServiceConfigA (Address: 0x1800188a8)
  • QueryServiceStatus (Address: 0x1800188b0)
bcrypt.dll
  • BCryptCloseAlgorithmProvider (Address: 0x1800188f0)
  • BCryptCreateHash (Address: 0x1800188f8)
  • BCryptDestroyHash (Address: 0x180018910)
  • BCryptFinishHash (Address: 0x1800188e8)
  • BCryptGenRandom (Address: 0x180018908)
  • BCryptGetProperty (Address: 0x1800188e0)
  • BCryptHashData (Address: 0x1800188d8)
  • BCryptOpenAlgorithmProvider (Address: 0x180018900)
KERNEL32.dll
  • GetComputerNameW (Address: 0x180018488)
msvcrt.dll
  • __C_specific_handler (Address: 0x180018a50)
  • __CxxFrameHandler3 (Address: 0x180018a68)
  • __dllonexit (Address: 0x180018a80)
  • _amsg_exit (Address: 0x180018a58)
  • _beginthreadex (Address: 0x1800189f0)
  • _callnewh (Address: 0x180018a38)
  • _CxxThrowException (Address: 0x180018a40)
  • _errno (Address: 0x1800189e0)
  • _i64tow_s (Address: 0x1800189c0)
  • _initterm (Address: 0x180018a60)
  • _itow_s (Address: 0x180018978)
  • _local_unwind (Address: 0x180018970)
  • _lock (Address: 0x180018a70)
  • _onexit (Address: 0x180018a90)
  • _purecall (Address: 0x180018950)
  • _stricmp (Address: 0x180018a18)
  • _ultow_s (Address: 0x180018988)
  • _unlock (Address: 0x180018a78)
  • _vsnprintf (Address: 0x1800189e8)
  • _vsnwprintf (Address: 0x180018a88)
  • _wcsdup (Address: 0x180018958)
  • _wcsicmp (Address: 0x180018960)
  • _wcsnicmp (Address: 0x180018938)
  • _XcptFilter (Address: 0x180018a48)
  • ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x180018a10)
  • ??0exception@@QEAA@AEBV0@@Z (Address: 0x180018a20)
  • ??1exception@@UEAA@XZ (Address: 0x180018a28)
  • ??1type_info@@UEAA@XZ (Address: 0x180018a98)
  • ?what@exception@@UEBAPEBDXZ (Address: 0x180018a30)
  • bsearch (Address: 0x1800189b0)
  • free (Address: 0x1800189f8)
  • isdigit (Address: 0x1800189b8)
  • iswcntrl (Address: 0x180018990)
  • isxdigit (Address: 0x1800189a8)
  • malloc (Address: 0x1800189c8)
  • memcmp (Address: 0x180018a00)
  • memcpy (Address: 0x180018a08)
  • memcpy_s (Address: 0x180018968)
  • memmove_s (Address: 0x180018928)
  • memset (Address: 0x180018aa0)
  • qsort (Address: 0x1800189a0)
  • strrchr (Address: 0x1800189d0)
  • strtoul (Address: 0x180018998)
  • towlower (Address: 0x180018aa8)
  • towupper (Address: 0x180018930)
  • wcschr (Address: 0x180018940)
  • wcscmp (Address: 0x180018ab0)
  • wcspbrk (Address: 0x180018948)
  • wcsrchr (Address: 0x180018920)
  • wcsstr (Address: 0x1800189d8)
  • wprintf (Address: 0x180018980)
ntdll.dll
  • EtwEventRegister (Address: 0x180018ac0)
  • EtwEventUnregister (Address: 0x180018ac8)
  • EvtIntReportEventAndSourceAsync (Address: 0x180018ad8)
  • RtlConvertSidToUnicodeString (Address: 0x180018ad0)
  • RtlLargeIntegerToChar (Address: 0x180018ae0)
NTDSA.dll
  • DBDsReplBackupUpdate (Address: 0x1800184a8)
  • DBUpdateBackupTimeStamps (Address: 0x180018498)
  • DsRegisterServiceStateCallback (Address: 0x1800184a0)
  • DsUnregisterServiceStateCallback (Address: 0x1800184b0)
  • GetConfigurationInfo (Address: 0x1800184b8)
VSSAPI.DLL
  • CreateWriter (Address: 0x1800184c8)