vmsavedstatedumpprovider.dll
Description: VM Saved State Dump Provider
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.22621.5040
Architecture: Unknown (0xaa64)
Operating System: Windows NT
SHA256: b0dd8a55f7d9163521967851925013ed
File Size: 904.6 KB
Uploaded At: Dec. 3, 2025, 2:36 a.m.
Views: 6
Exported Functions
- ApplyGuestMemoryFix (Ordinal: 1, Address: 0xe220)
- ApplyPendingSavedStateFileReplayLog (Ordinal: 2, Address: 0xcee0)
- CallStackUnwind (Ordinal: 3, Address: 0xf010)
- FindSavedStateSymbolFieldInType (Ordinal: 4, Address: 0xebe0)
- ForceActiveVirtualTrustLevel (Ordinal: 5, Address: 0xd590)
- ForceArchitecture (Ordinal: 6, Address: 0xd3a0)
- ForceNestedHostMode (Ordinal: 7, Address: 0xd840)
- ForcePagingMode (Ordinal: 8, Address: 0xdb20)
- GetActiveVirtualTrustLevel (Ordinal: 9, Address: 0xd450)
- GetArchitecture (Ordinal: 10, Address: 0xd2f0)
- GetCrashDumpHeader (Ordinal: 11, Address: 0xe3e0)
- GetEnabledVirtualTrustLevels (Ordinal: 12, Address: 0xd500)
- GetGuestEnabledVirtualTrustLevels (Ordinal: 13, Address: 0xd100)
- GetGuestOsInfo (Ordinal: 14, Address: 0xd1a0)
- GetGuestPhysicalMemoryChunks (Ordinal: 15, Address: 0xdd80)
- GetGuestRawSavedMemorySize (Ordinal: 16, Address: 0xe040)
- GetMemoryBlockCacheLimit (Ordinal: 17, Address: 0xe180)
- GetNestedVirtualizationMode (Ordinal: 18, Address: 0xd790)
- GetPagingMode (Ordinal: 19, Address: 0xda70)
- GetRegisterValue (Ordinal: 20, Address: 0xd9b0)
- GetSavedStateSymbolFieldInfo (Ordinal: 21, Address: 0xecb0)
- GetSavedStateSymbolProviderHandle (Ordinal: 22, Address: 0xe6e0)
- GetSavedStateSymbolTypeSize (Ordinal: 23, Address: 0xeb30)
- GetVpCount (Ordinal: 24, Address: 0xd250)
- GuestPhysicalAddressToRawSavedMemoryOffset (Ordinal: 25, Address: 0xdec0)
- GuestVirtualAddressToPhysicalAddress (Ordinal: 26, Address: 0xdca0)
- InKernelSpace (Ordinal: 27, Address: 0xd900)
- IsActiveVirtualTrustLevelEnabled (Ordinal: 28, Address: 0xd640)
- IsNestedVirtualizationEnabled (Ordinal: 29, Address: 0xd6f0)
- LoadKernelImage (Ordinal: 30, Address: 0xe2f0)
- LoadSavedStateFile (Ordinal: 31, Address: 0xcdc0)
- LoadSavedStateFiles (Ordinal: 32, Address: 0xcf20)
- LoadSavedStateModuleSymbols (Ordinal: 33, Address: 0xe800)
- LoadSavedStateModuleSymbolsEx (Ordinal: 34, Address: 0xe8d0)
- LoadSavedStateSymbolProvider (Ordinal: 35, Address: 0xe590)
- LocateSavedStateFiles (Ordinal: 36, Address: 0xcb20)
- ReadGuestPhysicalAddress (Ordinal: 37, Address: 0xdbd0)
- ReadGuestRawSavedMemory (Ordinal: 38, Address: 0xdf70)
- ReadSavedStateGlobalVariable (Ordinal: 39, Address: 0xea60)
- ReleaseSavedStateFiles (Ordinal: 40, Address: 0xd050)
- ReleaseSavedStateSymbolProvider (Ordinal: 41, Address: 0xe640)
- ResolveSavedStateGlobalVariableAddress (Ordinal: 42, Address: 0xe9a0)
- ScanMemoryForDosImages (Ordinal: 43, Address: 0xef10)
- SetMemoryBlockCacheLimit (Ordinal: 44, Address: 0xe0e0)
- SetSavedStateSymbolProviderDebugInfoCallback (Ordinal: 45, Address: 0xe760)
- WriteCrashDumpFile (Ordinal: 46, Address: 0xe4c0)
Imported DLLs & Functions
ADVAPI32.dll
- EventActivityIdControl (Address: 0x18009a050)
- EventEnabled (Address: 0x18009a030)
- EventRegister (Address: 0x18009a018)
- EventSetInformation (Address: 0x18009a040)
- EventUnregister (Address: 0x18009a020)
- EventWrite (Address: 0x18009a028)
- EventWriteTransfer (Address: 0x18009a038)
- RegCloseKey (Address: 0x18009a010)
- RegGetValueW (Address: 0x18009a000)
- RegOpenKeyExW (Address: 0x18009a008)
- RegQueryValueExW (Address: 0x18009a048)
api-ms-win-core-featurestaging-l1-1-0.dll
- RecordFeatureUsage (Address: 0x18009a4f8)
- SubscribeFeatureStateChangeNotification (Address: 0x18009a500)
- UnsubscribeFeatureStateChangeNotification (Address: 0x18009a508)
dbghelp.dll
- StackWalk64 (Address: 0x18009a558)
- SymCleanup (Address: 0x18009a538)
- SymFindFileInPath (Address: 0x18009a540)
- SymFromAddr (Address: 0x18009a520)
- SymFromName (Address: 0x18009a550)
- SymFunctionTableAccess64 (Address: 0x18009a588)
- SymGetLineFromAddr64 (Address: 0x18009a518)
- SymGetModuleBase64 (Address: 0x18009a590)
- SymGetModuleInfo64 (Address: 0x18009a528)
- SymGetOptions (Address: 0x18009a580)
- SymGetTypeFromName (Address: 0x18009a560)
- SymGetTypeInfo (Address: 0x18009a568)
- SymInitializeW (Address: 0x18009a570)
- SymLoadModuleEx (Address: 0x18009a548)
- SymRegisterCallback64 (Address: 0x18009a530)
- SymSetOptions (Address: 0x18009a578)
KERNEL32.dll
- AcquireSRWLockExclusive (Address: 0x18009a120)
- AcquireSRWLockShared (Address: 0x18009a130)
- CancelIoEx (Address: 0x18009a390)
- CloseHandle (Address: 0x18009a0c0)
- CloseThreadpoolWork (Address: 0x18009a450)
- CompareFileTime (Address: 0x18009a348)
- CreateEventExW (Address: 0x18009a380)
- CreateEventW (Address: 0x18009a3a0)
- CreateFileA (Address: 0x18009a410)
- CreateFileW (Address: 0x18009a2f0)
- CreateMutexExW (Address: 0x18009a0d8)
- CreateSemaphoreExW (Address: 0x18009a358)
- CreateThreadpoolWork (Address: 0x18009a468)
- DebugBreak (Address: 0x18009a0f8)
- DecodePointer (Address: 0x18009a470)
- DeleteCriticalSection (Address: 0x18009a1c0)
- DeviceIoControl (Address: 0x18009a398)
- EncodePointer (Address: 0x18009a330)
- EnterCriticalSection (Address: 0x18009a1b0)
- EnumSystemLocalesW (Address: 0x18009a248)
- ExitProcess (Address: 0x18009a250)
- FindClose (Address: 0x18009a3f0)
- FindFirstFileExW (Address: 0x18009a3c8)
- FindFirstFileW (Address: 0x18009a3e0)
- FindNextFileW (Address: 0x18009a3e8)
- FlsAlloc (Address: 0x18009a1e0)
- FlsFree (Address: 0x18009a1f8)
- FlsGetValue (Address: 0x18009a1e8)
- FlsSetValue (Address: 0x18009a1f0)
- FlushFileBuffers (Address: 0x18009a2b0)
- FormatMessageW (Address: 0x18009a098)
- FreeEnvironmentStringsW (Address: 0x18009a3a8)
- FreeLibrary (Address: 0x18009a210)
- FreeLibraryWhenCallbackReturns (Address: 0x18009a460)
- GetACP (Address: 0x18009a268)
- GetActiveProcessorCount (Address: 0x18009a420)
- GetCommandLineA (Address: 0x18009a3c0)
- GetCommandLineW (Address: 0x18009a3b8)
- GetConsoleMode (Address: 0x18009a2c8)
- GetConsoleOutputCP (Address: 0x18009a2c0)
- GetCPInfo (Address: 0x18009a278)
- GetCurrentProcess (Address: 0x18009a160)
- GetCurrentProcessId (Address: 0x18009a0e0)
- GetCurrentThreadId (Address: 0x18009a088)
- GetDiskFreeSpaceW (Address: 0x18009a350)
- GetEnvironmentStringsW (Address: 0x18009a3b0)
- GetFileSizeEx (Address: 0x18009a298)
- GetFileTime (Address: 0x18009a360)
- GetFileType (Address: 0x18009a1d0)
- GetFullPathNameW (Address: 0x18009a340)
- GetLastError (Address: 0x18009a0a0)
- GetLocaleInfoW (Address: 0x18009a230)
- GetModuleFileNameA (Address: 0x18009a220)
- GetModuleFileNameW (Address: 0x18009a150)
- GetModuleHandleExW (Address: 0x18009a078)
- GetModuleHandleW (Address: 0x18009a0f0)
- GetOEMCP (Address: 0x18009a270)
- GetOverlappedResult (Address: 0x18009a428)
- GetOverlappedResultEx (Address: 0x18009a488)
- GetProcAddress (Address: 0x18009a0d0)
- GetProcessHeap (Address: 0x18009a0e8)
- GetStartupInfoW (Address: 0x18009a1d8)
- GetStdHandle (Address: 0x18009a1c8)
- GetStringTypeW (Address: 0x18009a280)
- GetSystemInfo (Address: 0x18009a190)
- GetSystemTimeAsFileTime (Address: 0x18009a208)
- GetSystemTimePreciseAsFileTime (Address: 0x18009a3d8)
- GetTickCount (Address: 0x18009a168)
- GetUserDefaultLCID (Address: 0x18009a240)
- HeapAlloc (Address: 0x18009a0c8)
- HeapFree (Address: 0x18009a060)
- HeapReAlloc (Address: 0x18009a2e0)
- HeapSize (Address: 0x18009a2d8)
- InitializeConditionVariable (Address: 0x18009a448)
- InitializeCriticalSectionAndSpinCount (Address: 0x18009a200)
- InitializeCriticalSectionEx (Address: 0x18009a338)
- InitializeSListHead (Address: 0x18009a308)
- InitializeSRWLock (Address: 0x18009a170)
- InitOnceBeginInitialize (Address: 0x18009a148)
- InitOnceComplete (Address: 0x18009a140)
- InterlockedFlushSList (Address: 0x18009a328)
- InterlockedPopEntrySList (Address: 0x18009a388)
- InterlockedPushEntrySList (Address: 0x18009a320)
- IsDebuggerPresent (Address: 0x18009a100)
- IsValidCodePage (Address: 0x18009a260)
- IsValidLocale (Address: 0x18009a238)
- K32GetModuleInformation (Address: 0x18009a180)
- LCMapStringEx (Address: 0x18009a478)
- LCMapStringW (Address: 0x18009a228)
- LeaveCriticalSection (Address: 0x18009a1b8)
- LoadLibraryExW (Address: 0x18009a218)
- LocalAlloc (Address: 0x18009a110)
- LocalFree (Address: 0x18009a108)
- LockFileEx (Address: 0x18009a368)
- MultiByteToWideChar (Address: 0x18009a288)
- OpenSemaphoreW (Address: 0x18009a0b8)
- OutputDebugStringA (Address: 0x18009a418)
- OutputDebugStringW (Address: 0x18009a0a8)
- QueryPerformanceCounter (Address: 0x18009a300)
- QueryPerformanceFrequency (Address: 0x18009a480)
- RaiseException (Address: 0x18009a2e8)
- RaiseFailFastException (Address: 0x18009a158)
- ReadFile (Address: 0x18009a2d0)
- ReleaseMutex (Address: 0x18009a090)
- ReleaseSemaphore (Address: 0x18009a070)
- ReleaseSRWLockExclusive (Address: 0x18009a118)
- ReleaseSRWLockShared (Address: 0x18009a138)
- ResetEvent (Address: 0x18009a400)
- RtlCaptureStackBackTrace (Address: 0x18009a128)
- RtlLookupFunctionEntry (Address: 0x18009a310)
- RtlPcToFileHeader (Address: 0x18009a188)
- RtlUnwindEx (Address: 0x18009a318)
- SetEndOfFile (Address: 0x18009a430)
- SetEvent (Address: 0x18009a3f8)
- SetFilePointerEx (Address: 0x18009a2a0)
- SetFileTime (Address: 0x18009a378)
- SetLastError (Address: 0x18009a068)
- SetStdHandle (Address: 0x18009a2a8)
- Sleep (Address: 0x18009a3d0)
- SleepConditionVariableSRW (Address: 0x18009a178)
- SubmitThreadpoolWork (Address: 0x18009a458)
- TerminateProcess (Address: 0x18009a258)
- TryAcquireSRWLockExclusive (Address: 0x18009a438)
- UnlockFileEx (Address: 0x18009a370)
- VirtualAlloc (Address: 0x18009a198)
- VirtualProtect (Address: 0x18009a1a0)
- VirtualQuery (Address: 0x18009a1a8)
- WaitForSingleObject (Address: 0x18009a080)
- WaitForSingleObjectEx (Address: 0x18009a0b0)
- WakeAllConditionVariable (Address: 0x18009a408)
- WakeConditionVariable (Address: 0x18009a440)
- WideCharToMultiByte (Address: 0x18009a290)
- WriteConsoleW (Address: 0x18009a2f8)
- WriteFile (Address: 0x18009a2b8)
ntdll.dll
- NtCreateFile (Address: 0x18009a5a0)
- NtFsControlFile (Address: 0x18009a5b0)
- NtQueryInformationFile (Address: 0x18009a5c0)
- RtlDecompressBufferEx (Address: 0x18009a5c8)
- RtlGetCompressionWorkSpaceSize (Address: 0x18009a5b8)
- RtlNtStatusToDosError (Address: 0x18009a5a8)
ole32.dll
- CoCreateInstance (Address: 0x18009a5f0)
- CoGetObjectContext (Address: 0x18009a5e8)
- CoInitializeEx (Address: 0x18009a5e0)
- CoInitializeSecurity (Address: 0x18009a5d8)
- CoUninitialize (Address: 0x18009a5f8)
OLEAUT32.dll
- SysStringLen (Address: 0x18009a4b0)
- VariantChangeTypeEx (Address: 0x18009a498)
- VariantClear (Address: 0x18009a4a0)
- VariantInit (Address: 0x18009a4a8)
RPCRT4.dll
- UuidCreate (Address: 0x18009a4c0)
SHLWAPI.dll
- PathAppendW (Address: 0x18009a4d8)
- PathRemoveFileSpecW (Address: 0x18009a4d0)
XmlLite.dll
- CreateXmlReader (Address: 0x18009a4e8)