NtlmShared.dll

Description: NTLM Shared Functionality

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.6328

Architecture: 64-bit

Operating System: Windows NT

SHA256: ee52e3a4cedfc8b839e4d63f22bb9e47

File Size: 80.3 KB

Uploaded At: Dec. 1, 2025, 7:35 a.m.

Views: 7

Exported Functions

  • MsvpCachePasswordsToCredential (Ordinal: 1, Address: 0x90a0)
  • MsvpCalculateNtlm2Challenge (Ordinal: 2, Address: 0x72c0)
  • MsvpCalculateNtlm2ChallengeNew (Ordinal: 3, Address: 0x73d0)
  • MsvpCalculateNtlm2SessionKeys (Ordinal: 4, Address: 0x7580)
  • MsvpCalculateNtlm2SessionKeysNew (Ordinal: 5, Address: 0x7680)
  • MsvpCalculateNtlm3Owf (Ordinal: 6, Address: 0x7830)
  • MsvpCompareCredentials (Ordinal: 7, Address: 0x8f30)
  • MsvpComputeSaltedHashedPassword (Ordinal: 8, Address: 0x8960)
  • MsvpCredentialToCachePasswords (Ordinal: 9, Address: 0x9060)
  • MsvpDecryptDpapiMasterKey (Ordinal: 10, Address: 0x9100)
  • MsvpDeriveSecureCredKey (Ordinal: 11, Address: 0x8cd0)
  • MsvpGMSACred (Ordinal: 12, Address: 0xa6b0)
  • MsvpLm20GetNtlm3ChallengeResponse (Ordinal: 13, Address: 0x86b0)
  • MsvpLm3Response (Ordinal: 14, Address: 0x7b50)
  • MsvpLm3ResponseNew (Ordinal: 15, Address: 0x7d80)
  • MsvpLm3ValidateResponse (Ordinal: 16, Address: 0xaf30)
  • MsvpLm3ValidateResponseNew (Ordinal: 17, Address: 0xb000)
  • MsvpMakeSecretPasswordNT5 (Ordinal: 18, Address: 0x8af0)
  • MsvpNtlm3Response (Ordinal: 19, Address: 0x8100)
  • MsvpNtlm3ResponseNew (Ordinal: 20, Address: 0x8330)
  • MsvpNtlm3ValidateResponse (Ordinal: 21, Address: 0xb130)
  • MsvpNtlm3ValidateResponseNew (Ordinal: 22, Address: 0xb360)
  • MsvpPasswordValidate (Ordinal: 23, Address: 0xb6d0)
  • MsvpPutClearOwfsInPrimaryCredential (Ordinal: 24, Address: 0x8b90)
  • MsvpUpdateSharedConfiguration (Ordinal: 25, Address: 0xaa80)
  • MsvpValidateSupplementalCreds (Ordinal: 26, Address: 0xbe70)
  • MsvpValidateSupplementalCredsBuffer (Ordinal: 27, Address: 0xbe90)
  • NtLmAlterRtlEqualUnicodeString (Ordinal: 28, Address: 0xaaf0)
  • NtlmSharedAllocate (Ordinal: 29, Address: 0xaa00)
  • NtlmSharedAllocatePrivateHeap (Ordinal: 30, Address: 0xaa40)
  • NtlmSharedCleanup (Ordinal: 31, Address: 0xa980)
  • NtlmSharedFree (Ordinal: 32, Address: 0xaa20)
  • NtlmSharedFreePrivateHeap (Ordinal: 33, Address: 0xaa60)
  • NtlmSharedInit (Ordinal: 34, Address: 0xa6c0)

Imported DLLs & Functions

api-ms-win-core-crt-l1-1-0.dll
  • __C_specific_handler (Address: 0x18000e1a0)
  • _vsnwprintf_s (Address: 0x18000e180)
  • memcmp (Address: 0x18000e198)
  • memcpy (Address: 0x18000e190)
  • memcpy_s (Address: 0x18000e178)
  • memmove_s (Address: 0x18000e188)
  • memset (Address: 0x18000e1a8)
api-ms-win-core-crt-l2-1-0.dll
  • __dllonexit3 (Address: 0x18000e1b8)
  • _initterm (Address: 0x18000e1d8)
  • _initterm_e (Address: 0x18000e1d0)
  • _onexit (Address: 0x18000e1c0)
  • _purecall (Address: 0x18000e1c8)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x18000e1f0)
  • IsDebuggerPresent (Address: 0x18000e1e8)
  • OutputDebugStringW (Address: 0x18000e1f8)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x18000e208)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x18000e218)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x18000e238)
  • SetLastError (Address: 0x18000e228)
  • SetUnhandledExceptionFilter (Address: 0x18000e240)
  • UnhandledExceptionFilter (Address: 0x18000e230)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x18000e250)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x18000e268)
  • HeapAlloc (Address: 0x18000e260)
  • HeapFree (Address: 0x18000e270)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x18000e280)
  • LocalFree (Address: 0x18000e288)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x18000e2c0)
  • GetModuleFileNameA (Address: 0x18000e2b8)
  • GetModuleFileNameW (Address: 0x18000e2a8)
  • GetModuleHandleExW (Address: 0x18000e2a0)
  • GetModuleHandleW (Address: 0x18000e2b0)
  • GetProcAddress (Address: 0x18000e298)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x18000e2d0)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x18000e2f8)
  • GetCurrentProcessId (Address: 0x18000e2f0)
  • GetCurrentThreadId (Address: 0x18000e2e8)
  • TerminateProcess (Address: 0x18000e2e0)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x18000e308)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x18000e350)
  • AcquireSRWLockShared (Address: 0x18000e378)
  • CreateMutexExW (Address: 0x18000e370)
  • CreateSemaphoreExW (Address: 0x18000e368)
  • DeleteCriticalSection (Address: 0x18000e380)
  • EnterCriticalSection (Address: 0x18000e358)
  • InitializeCriticalSection (Address: 0x18000e338)
  • InitializeCriticalSectionEx (Address: 0x18000e388)
  • LeaveCriticalSection (Address: 0x18000e328)
  • OpenSemaphoreW (Address: 0x18000e320)
  • ReleaseMutex (Address: 0x18000e330)
  • ReleaseSemaphore (Address: 0x18000e348)
  • ReleaseSRWLockExclusive (Address: 0x18000e360)
  • ReleaseSRWLockShared (Address: 0x18000e340)
  • WaitForSingleObject (Address: 0x18000e390)
  • WaitForSingleObjectEx (Address: 0x18000e318)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTimeAsFileTime (Address: 0x18000e3a0)
  • GetTickCount (Address: 0x18000e3a8)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x18000e3c8)
  • CreateThreadpoolTimer (Address: 0x18000e3b8)
  • SetThreadpoolTimer (Address: 0x18000e3c0)
  • WaitForThreadpoolTimerCallbacks (Address: 0x18000e3d0)
api-ms-win-core-util-l1-1-0.dll
  • DecodePointer (Address: 0x18000e3e0)
  • EncodePointer (Address: 0x18000e3e8)
bcrypt.dll
  • BCryptCloseAlgorithmProvider (Address: 0x18000e430)
  • BCryptCreateHash (Address: 0x18000e400)
  • BCryptDecrypt (Address: 0x18000e448)
  • BCryptDeriveKeyPBKDF2 (Address: 0x18000e450)
  • BCryptDestroyHash (Address: 0x18000e440)
  • BCryptDestroyKey (Address: 0x18000e418)
  • BCryptFinishHash (Address: 0x18000e428)
  • BCryptGenerateSymmetricKey (Address: 0x18000e3f8)
  • BCryptGetProperty (Address: 0x18000e438)
  • BCryptHash (Address: 0x18000e420)
  • BCryptHashData (Address: 0x18000e408)
  • BCryptOpenAlgorithmProvider (Address: 0x18000e410)
cryptdll.dll
  • PBKDF2 (Address: 0x18000e460)
ntdll.dll
  • EtwEventRegister (Address: 0x18000e490)
  • EtwEventSetInformation (Address: 0x18000e4b0)
  • EtwEventUnregister (Address: 0x18000e488)
  • EtwGetTraceEnableFlags (Address: 0x18000e4b8)
  • EtwGetTraceEnableLevel (Address: 0x18000e4e0)
  • EtwGetTraceLoggerHandle (Address: 0x18000e4d0)
  • EtwRegisterTraceGuidsW (Address: 0x18000e4e8)
  • EtwTraceMessage (Address: 0x18000e470)
  • EtwUnregisterTraceGuids (Address: 0x18000e480)
  • NtQuerySystemTime (Address: 0x18000e510)
  • RtlCaptureContext (Address: 0x18000e4a8)
  • RtlCompareMemory (Address: 0x18000e4c0)
  • RtlConvertSidToUnicodeString (Address: 0x18000e508)
  • RtlDowncaseUnicodeString (Address: 0x18000e4f0)
  • RtlEqualUnicodeString (Address: 0x18000e478)
  • RtlFreeUnicodeString (Address: 0x18000e4f8)
  • RtlInitUnicodeString (Address: 0x18000e4c8)
  • RtlLookupFunctionEntry (Address: 0x18000e4a0)
  • RtlNtStatusToDosError (Address: 0x18000e4d8)
  • RtlUpcaseUnicodeString (Address: 0x18000e500)
  • RtlUpperChar (Address: 0x18000e518)
  • RtlVirtualUnwind (Address: 0x18000e498)