esevss.dll

Description: Microsoft(R) ESENT shadow utilities

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.1

Architecture: 64-bit

Operating System: Windows NT

SHA256: a90c0f62e325efabc4c6cb5df54686c1

File Size: 37.5 KB

Uploaded At: Dec. 1, 2025, 7:27 a.m.

Views: 10

Exported Functions

  • EseShadowCreateShadow (Ordinal: 1, Address: 0x2a50)
  • EseShadowCreateSimpleShadow (Ordinal: 2, Address: 0x2fa0)
  • EseShadowInit (Ordinal: 3, Address: 0x11b0)
  • EseShadowMountShadow (Ordinal: 4, Address: 0x1b70)
  • EseShadowMountSimpleShadow (Ordinal: 5, Address: 0x1d20)
  • EseShadowPurgeShadow (Ordinal: 6, Address: 0x3360)
  • EseShadowTerm (Ordinal: 7, Address: 0x1440)
  • VssIdToString (Ordinal: 8, Address: 0x1570)

Imported DLLs & Functions

api-ms-win-core-com-l1-1-0.dll
  • CoInitializeEx (Address: 0x180006288)
  • CoUninitialize (Address: 0x180006290)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x1800062a8)
  • SetUnhandledExceptionFilter (Address: 0x1800062a0)
  • UnhandledExceptionFilter (Address: 0x1800062b0)
api-ms-win-core-file-l1-1-0.dll
  • CreateFileW (Address: 0x1800062d8)
  • FindClose (Address: 0x1800062c8)
  • FindFirstFileW (Address: 0x1800062e8)
  • GetFinalPathNameByHandleW (Address: 0x1800062e0)
  • GetTempFileNameW (Address: 0x1800062c0)
  • GetVolumePathNameW (Address: 0x1800062d0)
api-ms-win-core-file-l1-2-0.dll
  • GetTempPathW (Address: 0x1800062f8)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x180006308)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x180006318)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x180006330)
  • GetCurrentProcessId (Address: 0x180006328)
  • GetCurrentThreadId (Address: 0x180006340)
  • TerminateProcess (Address: 0x180006338)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x180006350)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x180006370)
  • RtlLookupFunctionEntry (Address: 0x180006368)
  • RtlVirtualUnwind (Address: 0x180006360)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x180006380)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTimeAsFileTime (Address: 0x180006398)
  • GetTickCount (Address: 0x180006390)
ESENT.dll
  • JetGetDatabaseFileInfoW (Address: 0x180006238)
  • JetInit3W (Address: 0x180006240)
  • JetSetSystemParameterW (Address: 0x180006228)
  • JetTerm2 (Address: 0x180006230)
msvcrt.dll
  • __C_specific_handler (Address: 0x1800063a8)
  • _amsg_exit (Address: 0x1800063b8)
  • _callnewh (Address: 0x1800063d0)
  • _initterm (Address: 0x1800063b0)
  • _purecall (Address: 0x1800063e0)
  • _vsnwprintf (Address: 0x180006408)
  • _wcsicmp (Address: 0x180006400)
  • _XcptFilter (Address: 0x180006410)
  • free (Address: 0x1800063f0)
  • malloc (Address: 0x1800063d8)
  • memcpy (Address: 0x1800063c0)
  • memset (Address: 0x180006418)
  • wcscpy_s (Address: 0x1800063f8)
  • wcsrchr (Address: 0x1800063e8)
  • wprintf (Address: 0x1800063c8)
RPCRT4.dll
  • RpcStringFreeW (Address: 0x180006258)
  • UuidToStringW (Address: 0x180006250)
VSSAPI.DLL
  • CreateVssBackupComponentsInternal (Address: 0x180006270)
  • CreateWriter (Address: 0x180006268)
  • VssFreeSnapshotPropertiesInternal (Address: 0x180006278)