werdiagcontroller.dll

Description: WER Diagnostic Controller

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.3996

Architecture: 32-bit

Operating System: Windows NT

SHA256: 6f0846a09b5dbbc9ce6bb47a2cda0d53

File Size: 38.0 KB

Uploaded At: Dec. 1, 2025, 8:06 a.m.

Views: 20

Exported Functions

  • QueryOriginalBucket (Ordinal: 1, Address: 0x4c40)
  • StartAppRecorder (Ordinal: 2, Address: 0x4e90)
  • StartFDR (Ordinal: 3, Address: 0x5850)

Imported DLLs & Functions

api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x1000a004)
  • SetUnhandledExceptionFilter (Address: 0x1000a000)
  • UnhandledExceptionFilter (Address: 0x1000a008)
api-ms-win-core-file-l1-1-0.dll
  • CreateFileW (Address: 0x1000a018)
  • DeleteFileW (Address: 0x1000a014)
  • GetTempFileNameW (Address: 0x1000a010)
api-ms-win-core-file-l1-2-0.dll
  • GetTempPathW (Address: 0x1000a020)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x1000a028)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x1000a030)
api-ms-win-core-libraryloader-l1-2-0.dll
  • GetModuleFileNameA (Address: 0x1000a038)
  • GetModuleFileNameW (Address: 0x1000a03c)
api-ms-win-core-memory-l1-1-0.dll
  • ReadProcessMemory (Address: 0x1000a044)
api-ms-win-core-processthreads-l1-1-0.dll
  • CreateProcessW (Address: 0x1000a050)
  • GetCurrentProcess (Address: 0x1000a054)
  • GetCurrentProcessId (Address: 0x1000a060)
  • GetCurrentThreadId (Address: 0x1000a058)
  • GetProcessId (Address: 0x1000a05c)
  • TerminateProcess (Address: 0x1000a04c)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x1000a068)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x1000a078)
  • CreateEventW (Address: 0x1000a084)
  • OpenEventW (Address: 0x1000a070)
  • ReleaseSRWLockExclusive (Address: 0x1000a074)
  • SetEvent (Address: 0x1000a07c)
  • WaitForSingleObject (Address: 0x1000a080)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x1000a08c)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemDirectoryW (Address: 0x1000a09c)
  • GetSystemTimeAsFileTime (Address: 0x1000a094)
  • GetTickCount (Address: 0x1000a098)
api-ms-win-core-windowserrorreporting-l1-1-0.dll
  • WerRegisterFile (Address: 0x1000a0a4)
api-ms-win-eventing-classicprovider-l1-1-0.dll
  • GetTraceEnableFlags (Address: 0x1000a0b8)
  • GetTraceEnableLevel (Address: 0x1000a0ac)
  • GetTraceLoggerHandle (Address: 0x1000a0bc)
  • RegisterTraceGuidsW (Address: 0x1000a0b4)
  • TraceEvent (Address: 0x1000a0b0)
api-ms-win-eventing-controller-l1-1-0.dll
  • StartTraceW (Address: 0x1000a0c4)
api-ms-win-eventing-legacy-l1-1-0.dll
  • EnableTrace (Address: 0x1000a0cc)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventProviderEnabled (Address: 0x1000a0d4)
  • EventRegister (Address: 0x1000a0dc)
  • EventSetInformation (Address: 0x1000a0d8)
  • EventUnregister (Address: 0x1000a0e4)
  • EventWriteTransfer (Address: 0x1000a0e0)
msvcrt.dll
  • _amsg_exit (Address: 0x1000a118)
  • _except_handler4_common (Address: 0x1000a104)
  • _initterm (Address: 0x1000a0f0)
  • _vsnwprintf (Address: 0x1000a0ec)
  • _wcsicmp (Address: 0x1000a10c)
  • _wcsnicmp (Address: 0x1000a0f4)
  • _wtoi (Address: 0x1000a110)
  • _XcptFilter (Address: 0x1000a100)
  • free (Address: 0x1000a0fc)
  • isspace (Address: 0x1000a11c)
  • malloc (Address: 0x1000a0f8)
  • memcpy (Address: 0x1000a114)
  • memmove (Address: 0x1000a120)
  • memset (Address: 0x1000a128)
  • toupper (Address: 0x1000a124)
  • wcschr (Address: 0x1000a108)
ntdll.dll
  • DbgPrintEx (Address: 0x1000a1a4)
  • EtwEventWriteNoRegistration (Address: 0x1000a18c)
  • LdrDisableThreadCalloutsForDll (Address: 0x1000a1a8)
  • LdrGetDllHandle (Address: 0x1000a148)
  • LdrGetProcedureAddress (Address: 0x1000a150)
  • NtAlpcConnectPort (Address: 0x1000a164)
  • NtAlpcSendWaitReceivePort (Address: 0x1000a130)
  • NtClose (Address: 0x1000a19c)
  • NtDelayExecution (Address: 0x1000a144)
  • NtDeleteFile (Address: 0x1000a1a0)
  • NtDeleteKey (Address: 0x1000a140)
  • NtDeleteValueKey (Address: 0x1000a154)
  • NtOpenEvent (Address: 0x1000a178)
  • NtOpenKey (Address: 0x1000a168)
  • NtQueryInformationProcess (Address: 0x1000a174)
  • NtQuerySystemInformation (Address: 0x1000a180)
  • NtQueryValueKey (Address: 0x1000a16c)
  • NtSetValueKey (Address: 0x1000a170)
  • NtWaitForSingleObject (Address: 0x1000a17c)
  • RtlAllocateAndInitializeSid (Address: 0x1000a1ac)
  • RtlAllocateHeap (Address: 0x1000a158)
  • RtlCreateUserThread (Address: 0x1000a13c)
  • RtlDosPathNameToNtPathName_U (Address: 0x1000a160)
  • RtlFormatCurrentUserKeyPath (Address: 0x1000a198)
  • RtlFreeHeap (Address: 0x1000a134)
  • RtlFreeSid (Address: 0x1000a138)
  • RtlFreeUnicodeString (Address: 0x1000a194)
  • RtlGUIDFromString (Address: 0x1000a15c)
  • RtlInitAnsiString (Address: 0x1000a14c)
  • RtlInitUnicodeString (Address: 0x1000a190)
  • ZwQueryWnfStateNameInformation (Address: 0x1000a184)
  • ZwUpdateWnfStateData (Address: 0x1000a188)