werdiagcontroller.dll
Description: WER Diagnostic Controller
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.3996
Architecture: 32-bit
Operating System: Windows NT
SHA256: 6f0846a09b5dbbc9ce6bb47a2cda0d53
File Size: 38.0 KB
Uploaded At: Dec. 1, 2025, 8:06 a.m.
Views: 20
Exported Functions
- QueryOriginalBucket (Ordinal: 1, Address: 0x4c40)
- StartAppRecorder (Ordinal: 2, Address: 0x4e90)
- StartFDR (Ordinal: 3, Address: 0x5850)
Imported DLLs & Functions
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x1000a004)
- SetUnhandledExceptionFilter (Address: 0x1000a000)
- UnhandledExceptionFilter (Address: 0x1000a008)
api-ms-win-core-file-l1-1-0.dll
- CreateFileW (Address: 0x1000a018)
- DeleteFileW (Address: 0x1000a014)
- GetTempFileNameW (Address: 0x1000a010)
api-ms-win-core-file-l1-2-0.dll
- GetTempPathW (Address: 0x1000a020)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x1000a028)
api-ms-win-core-heap-l2-1-0.dll
- LocalAlloc (Address: 0x1000a030)
api-ms-win-core-libraryloader-l1-2-0.dll
- GetModuleFileNameA (Address: 0x1000a038)
- GetModuleFileNameW (Address: 0x1000a03c)
api-ms-win-core-memory-l1-1-0.dll
- ReadProcessMemory (Address: 0x1000a044)
api-ms-win-core-processthreads-l1-1-0.dll
- CreateProcessW (Address: 0x1000a050)
- GetCurrentProcess (Address: 0x1000a054)
- GetCurrentProcessId (Address: 0x1000a060)
- GetCurrentThreadId (Address: 0x1000a058)
- GetProcessId (Address: 0x1000a05c)
- TerminateProcess (Address: 0x1000a04c)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x1000a068)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x1000a078)
- CreateEventW (Address: 0x1000a084)
- OpenEventW (Address: 0x1000a070)
- ReleaseSRWLockExclusive (Address: 0x1000a074)
- SetEvent (Address: 0x1000a07c)
- WaitForSingleObject (Address: 0x1000a080)
api-ms-win-core-synch-l1-2-0.dll
- Sleep (Address: 0x1000a08c)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemDirectoryW (Address: 0x1000a09c)
- GetSystemTimeAsFileTime (Address: 0x1000a094)
- GetTickCount (Address: 0x1000a098)
api-ms-win-core-windowserrorreporting-l1-1-0.dll
- WerRegisterFile (Address: 0x1000a0a4)
api-ms-win-eventing-classicprovider-l1-1-0.dll
- GetTraceEnableFlags (Address: 0x1000a0b8)
- GetTraceEnableLevel (Address: 0x1000a0ac)
- GetTraceLoggerHandle (Address: 0x1000a0bc)
- RegisterTraceGuidsW (Address: 0x1000a0b4)
- TraceEvent (Address: 0x1000a0b0)
api-ms-win-eventing-controller-l1-1-0.dll
- StartTraceW (Address: 0x1000a0c4)
api-ms-win-eventing-legacy-l1-1-0.dll
- EnableTrace (Address: 0x1000a0cc)
api-ms-win-eventing-provider-l1-1-0.dll
- EventProviderEnabled (Address: 0x1000a0d4)
- EventRegister (Address: 0x1000a0dc)
- EventSetInformation (Address: 0x1000a0d8)
- EventUnregister (Address: 0x1000a0e4)
- EventWriteTransfer (Address: 0x1000a0e0)
msvcrt.dll
- _amsg_exit (Address: 0x1000a118)
- _except_handler4_common (Address: 0x1000a104)
- _initterm (Address: 0x1000a0f0)
- _vsnwprintf (Address: 0x1000a0ec)
- _wcsicmp (Address: 0x1000a10c)
- _wcsnicmp (Address: 0x1000a0f4)
- _wtoi (Address: 0x1000a110)
- _XcptFilter (Address: 0x1000a100)
- free (Address: 0x1000a0fc)
- isspace (Address: 0x1000a11c)
- malloc (Address: 0x1000a0f8)
- memcpy (Address: 0x1000a114)
- memmove (Address: 0x1000a120)
- memset (Address: 0x1000a128)
- toupper (Address: 0x1000a124)
- wcschr (Address: 0x1000a108)
ntdll.dll
- DbgPrintEx (Address: 0x1000a1a4)
- EtwEventWriteNoRegistration (Address: 0x1000a18c)
- LdrDisableThreadCalloutsForDll (Address: 0x1000a1a8)
- LdrGetDllHandle (Address: 0x1000a148)
- LdrGetProcedureAddress (Address: 0x1000a150)
- NtAlpcConnectPort (Address: 0x1000a164)
- NtAlpcSendWaitReceivePort (Address: 0x1000a130)
- NtClose (Address: 0x1000a19c)
- NtDelayExecution (Address: 0x1000a144)
- NtDeleteFile (Address: 0x1000a1a0)
- NtDeleteKey (Address: 0x1000a140)
- NtDeleteValueKey (Address: 0x1000a154)
- NtOpenEvent (Address: 0x1000a178)
- NtOpenKey (Address: 0x1000a168)
- NtQueryInformationProcess (Address: 0x1000a174)
- NtQuerySystemInformation (Address: 0x1000a180)
- NtQueryValueKey (Address: 0x1000a16c)
- NtSetValueKey (Address: 0x1000a170)
- NtWaitForSingleObject (Address: 0x1000a17c)
- RtlAllocateAndInitializeSid (Address: 0x1000a1ac)
- RtlAllocateHeap (Address: 0x1000a158)
- RtlCreateUserThread (Address: 0x1000a13c)
- RtlDosPathNameToNtPathName_U (Address: 0x1000a160)
- RtlFormatCurrentUserKeyPath (Address: 0x1000a198)
- RtlFreeHeap (Address: 0x1000a134)
- RtlFreeSid (Address: 0x1000a138)
- RtlFreeUnicodeString (Address: 0x1000a194)
- RtlGUIDFromString (Address: 0x1000a15c)
- RtlInitAnsiString (Address: 0x1000a14c)
- RtlInitUnicodeString (Address: 0x1000a190)
- ZwQueryWnfStateNameInformation (Address: 0x1000a184)
- ZwUpdateWnfStateData (Address: 0x1000a188)