NtlmShared.dll
Description: NTLM Shared Functionality
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.6328
Architecture: 32-bit
Operating System: Windows NT
SHA256: eca4ea4f8aca4605edc1d1c2486f3c0e
File Size: 62.6 KB
Uploaded At: Dec. 1, 2025, 8:02 a.m.
Views: 8
Exported Functions
- MsvpCachePasswordsToCredential (Ordinal: 1, Address: 0x7bb0)
- MsvpCalculateNtlm2Challenge (Ordinal: 2, Address: 0x6680)
- MsvpCalculateNtlm2ChallengeNew (Ordinal: 3, Address: 0x6730)
- MsvpCalculateNtlm2SessionKeys (Ordinal: 4, Address: 0x6890)
- MsvpCalculateNtlm2SessionKeysNew (Ordinal: 5, Address: 0x6900)
- MsvpCalculateNtlm3Owf (Ordinal: 6, Address: 0x6a40)
- MsvpCompareCredentials (Ordinal: 7, Address: 0x7ab0)
- MsvpComputeSaltedHashedPassword (Ordinal: 8, Address: 0x7670)
- MsvpCredentialToCachePasswords (Ordinal: 9, Address: 0x7b60)
- MsvpDecryptDpapiMasterKey (Ordinal: 10, Address: 0x7c10)
- MsvpDeriveSecureCredKey (Ordinal: 11, Address: 0x7930)
- MsvpGMSACred (Ordinal: 12, Address: 0x8bd0)
- MsvpLm20GetNtlm3ChallengeResponse (Ordinal: 13, Address: 0x7490)
- MsvpLm3Response (Ordinal: 14, Address: 0x6c80)
- MsvpLm3ResponseNew (Ordinal: 15, Address: 0x6da0)
- MsvpLm3ValidateResponse (Ordinal: 16, Address: 0x9190)
- MsvpLm3ValidateResponseNew (Ordinal: 17, Address: 0x9230)
- MsvpMakeSecretPasswordNT5 (Ordinal: 18, Address: 0x77a0)
- MsvpNtlm3Response (Ordinal: 19, Address: 0x7090)
- MsvpNtlm3ResponseNew (Ordinal: 20, Address: 0x71b0)
- MsvpNtlm3ValidateResponse (Ordinal: 21, Address: 0x9330)
- MsvpNtlm3ValidateResponseNew (Ordinal: 22, Address: 0x9500)
- MsvpPasswordValidate (Ordinal: 23, Address: 0x97e0)
- MsvpPutClearOwfsInPrimaryCredential (Ordinal: 24, Address: 0x7830)
- MsvpUpdateSharedConfiguration (Ordinal: 25, Address: 0x8e40)
- MsvpValidateSupplementalCreds (Ordinal: 26, Address: 0x9eb0)
- MsvpValidateSupplementalCredsBuffer (Ordinal: 27, Address: 0x9ee0)
- NtLmAlterRtlEqualUnicodeString (Ordinal: 28, Address: 0x8ec0)
- NtlmSharedAllocate (Ordinal: 29, Address: 0x8d80)
- NtlmSharedAllocatePrivateHeap (Ordinal: 30, Address: 0x8de0)
- NtlmSharedCleanup (Ordinal: 31, Address: 0x8d10)
- NtlmSharedFree (Ordinal: 32, Address: 0x8db0)
- NtlmSharedFreePrivateHeap (Ordinal: 33, Address: 0x8e10)
- NtlmSharedInit (Ordinal: 34, Address: 0x8be0)
Imported DLLs & Functions
api-ms-win-core-crt-l1-1-0.dll
- _except_handler4_common (Address: 0x1000d014)
- _vsnwprintf_s (Address: 0x1000d004)
- memcmp (Address: 0x1000d010)
- memcpy (Address: 0x1000d00c)
- memcpy_s (Address: 0x1000d000)
- memmove_s (Address: 0x1000d008)
- memset (Address: 0x1000d018)
api-ms-win-core-crt-l2-1-0.dll
- __dllonexit3 (Address: 0x1000d020)
- _initterm (Address: 0x1000d030)
- _initterm_e (Address: 0x1000d02c)
- _onexit (Address: 0x1000d024)
- _purecall (Address: 0x1000d028)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x1000d040)
- IsDebuggerPresent (Address: 0x1000d038)
- OutputDebugStringW (Address: 0x1000d03c)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x1000d048)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x1000d050)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x1000d060)
- SetLastError (Address: 0x1000d05c)
- SetUnhandledExceptionFilter (Address: 0x1000d058)
- UnhandledExceptionFilter (Address: 0x1000d064)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x1000d06c)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x1000d074)
- HeapAlloc (Address: 0x1000d078)
- HeapFree (Address: 0x1000d07c)
api-ms-win-core-heap-l2-1-0.dll
- LocalAlloc (Address: 0x1000d084)
- LocalFree (Address: 0x1000d088)
api-ms-win-core-libraryloader-l1-2-0.dll
- DisableThreadLibraryCalls (Address: 0x1000d098)
- GetModuleFileNameA (Address: 0x1000d094)
- GetModuleFileNameW (Address: 0x1000d09c)
- GetModuleHandleExW (Address: 0x1000d0a4)
- GetModuleHandleW (Address: 0x1000d090)
- GetProcAddress (Address: 0x1000d0a0)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x1000d0ac)
api-ms-win-core-processthreads-l1-1-0.dll
- GetCurrentProcess (Address: 0x1000d0c0)
- GetCurrentProcessId (Address: 0x1000d0b4)
- GetCurrentThreadId (Address: 0x1000d0b8)
- TerminateProcess (Address: 0x1000d0bc)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x1000d0c8)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x1000d0e8)
- AcquireSRWLockShared (Address: 0x1000d10c)
- CreateMutexExW (Address: 0x1000d0f0)
- CreateSemaphoreExW (Address: 0x1000d100)
- DeleteCriticalSection (Address: 0x1000d0f8)
- EnterCriticalSection (Address: 0x1000d104)
- InitializeCriticalSection (Address: 0x1000d0dc)
- InitializeCriticalSectionEx (Address: 0x1000d0ec)
- LeaveCriticalSection (Address: 0x1000d0f4)
- OpenSemaphoreW (Address: 0x1000d0d4)
- ReleaseMutex (Address: 0x1000d0e0)
- ReleaseSemaphore (Address: 0x1000d0fc)
- ReleaseSRWLockExclusive (Address: 0x1000d0d0)
- ReleaseSRWLockShared (Address: 0x1000d0d8)
- WaitForSingleObject (Address: 0x1000d0e4)
- WaitForSingleObjectEx (Address: 0x1000d108)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemTimeAsFileTime (Address: 0x1000d118)
- GetTickCount (Address: 0x1000d114)
api-ms-win-core-threadpool-l1-2-0.dll
- CloseThreadpoolTimer (Address: 0x1000d124)
- CreateThreadpoolTimer (Address: 0x1000d120)
- SetThreadpoolTimer (Address: 0x1000d12c)
- WaitForThreadpoolTimerCallbacks (Address: 0x1000d128)
api-ms-win-core-util-l1-1-0.dll
- DecodePointer (Address: 0x1000d134)
- EncodePointer (Address: 0x1000d138)
bcrypt.dll
- BCryptCloseAlgorithmProvider (Address: 0x1000d158)
- BCryptCreateHash (Address: 0x1000d16c)
- BCryptDecrypt (Address: 0x1000d14c)
- BCryptDeriveKeyPBKDF2 (Address: 0x1000d144)
- BCryptDestroyHash (Address: 0x1000d160)
- BCryptDestroyKey (Address: 0x1000d150)
- BCryptFinishHash (Address: 0x1000d164)
- BCryptGenerateSymmetricKey (Address: 0x1000d148)
- BCryptGetProperty (Address: 0x1000d15c)
- BCryptHash (Address: 0x1000d154)
- BCryptHashData (Address: 0x1000d140)
- BCryptOpenAlgorithmProvider (Address: 0x1000d168)
cryptdll.dll
- PBKDF2 (Address: 0x1000d174)
ntdll.dll
- EtwEventRegister (Address: 0x1000d17c)
- EtwEventSetInformation (Address: 0x1000d19c)
- EtwEventUnregister (Address: 0x1000d180)
- EtwGetTraceEnableFlags (Address: 0x1000d198)
- EtwGetTraceEnableLevel (Address: 0x1000d1a8)
- EtwGetTraceLoggerHandle (Address: 0x1000d1a0)
- EtwRegisterTraceGuidsW (Address: 0x1000d1ac)
- EtwTraceMessage (Address: 0x1000d18c)
- EtwUnregisterTraceGuids (Address: 0x1000d184)
- NtQuerySystemTime (Address: 0x1000d1c0)
- RtlCompareMemory (Address: 0x1000d190)
- RtlConvertSidToUnicodeString (Address: 0x1000d1bc)
- RtlDowncaseUnicodeString (Address: 0x1000d1b0)
- RtlEqualUnicodeString (Address: 0x1000d1c4)
- RtlFreeUnicodeString (Address: 0x1000d1b4)
- RtlInitUnicodeString (Address: 0x1000d188)
- RtlNtStatusToDosError (Address: 0x1000d1a4)
- RtlUpcaseUnicodeString (Address: 0x1000d1b8)
- RtlUpperChar (Address: 0x1000d194)