vmsavedstatedumpprovider.dll
Description: VM Saved State Dump Provider
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.22621.5040
Architecture: 64-bit
Operating System: Windows NT
SHA256: 4b07a4dd37b1d7f6e3558fafcc1c0633
File Size: 949.6 KB
Uploaded At: Dec. 3, 2025, 2:37 a.m.
Views: 5
Exported Functions
- ApplyGuestMemoryFix (Ordinal: 1, Address: 0xe690)
- ApplyPendingSavedStateFileReplayLog (Ordinal: 2, Address: 0xd470)
- CallStackUnwind (Ordinal: 3, Address: 0xf270)
- FindSavedStateSymbolFieldInType (Ordinal: 4, Address: 0xef60)
- ForceActiveVirtualTrustLevel (Ordinal: 5, Address: 0xdb00)
- ForceArchitecture (Ordinal: 6, Address: 0xd940)
- ForceNestedHostMode (Ordinal: 7, Address: 0xdd70)
- ForcePagingMode (Ordinal: 8, Address: 0xdff0)
- GetActiveVirtualTrustLevel (Ordinal: 9, Address: 0xd9e0)
- GetArchitecture (Ordinal: 10, Address: 0xd8a0)
- GetCrashDumpHeader (Ordinal: 11, Address: 0xe830)
- GetEnabledVirtualTrustLevels (Ordinal: 12, Address: 0xda80)
- GetGuestEnabledVirtualTrustLevels (Ordinal: 13, Address: 0xd6e0)
- GetGuestOsInfo (Ordinal: 14, Address: 0xd770)
- GetGuestPhysicalMemoryChunks (Ordinal: 15, Address: 0xe210)
- GetGuestRawSavedMemorySize (Ordinal: 16, Address: 0xe4e0)
- GetMemoryBlockCacheLimit (Ordinal: 17, Address: 0xe600)
- GetNestedVirtualizationMode (Ordinal: 18, Address: 0xdcd0)
- GetPagingMode (Ordinal: 19, Address: 0xdf50)
- GetRegisterValue (Ordinal: 20, Address: 0xdeb0)
- GetSavedStateSymbolFieldInfo (Ordinal: 21, Address: 0xf020)
- GetSavedStateSymbolProviderHandle (Ordinal: 22, Address: 0xeae0)
- GetSavedStateSymbolTypeSize (Ordinal: 23, Address: 0xeec0)
- GetVpCount (Ordinal: 24, Address: 0xd810)
- GuestPhysicalAddressToRawSavedMemoryOffset (Ordinal: 25, Address: 0xe390)
- GuestVirtualAddressToPhysicalAddress (Ordinal: 26, Address: 0xe140)
- InKernelSpace (Ordinal: 27, Address: 0xde10)
- IsActiveVirtualTrustLevelEnabled (Ordinal: 28, Address: 0xdba0)
- IsNestedVirtualizationEnabled (Ordinal: 29, Address: 0xdc40)
- LoadKernelImage (Ordinal: 30, Address: 0xe740)
- LoadSavedStateFile (Ordinal: 31, Address: 0xd340)
- LoadSavedStateFiles (Ordinal: 32, Address: 0xd4a0)
- LoadSavedStateModuleSymbols (Ordinal: 33, Address: 0xebf0)
- LoadSavedStateModuleSymbolsEx (Ordinal: 34, Address: 0xeca0)
- LoadSavedStateSymbolProvider (Ordinal: 35, Address: 0xe9b0)
- LocateSavedStateFiles (Ordinal: 36, Address: 0xd140)
- ReadGuestPhysicalAddress (Ordinal: 37, Address: 0xe090)
- ReadGuestRawSavedMemory (Ordinal: 38, Address: 0xe430)
- ReadSavedStateGlobalVariable (Ordinal: 39, Address: 0xee10)
- ReleaseSavedStateFiles (Ordinal: 40, Address: 0xd5d0)
- ReleaseSavedStateSymbolProvider (Ordinal: 41, Address: 0xea50)
- ResolveSavedStateGlobalVariableAddress (Ordinal: 42, Address: 0xed60)
- ScanMemoryForDosImages (Ordinal: 43, Address: 0xf170)
- SetMemoryBlockCacheLimit (Ordinal: 44, Address: 0xe570)
- SetSavedStateSymbolProviderDebugInfoCallback (Ordinal: 45, Address: 0xeb60)
- WriteCrashDumpFile (Ordinal: 46, Address: 0xe900)
Imported DLLs & Functions
ADVAPI32.dll
- EventActivityIdControl (Address: 0x1800a2408)
- EventEnabled (Address: 0x1800a23e8)
- EventRegister (Address: 0x1800a23d0)
- EventSetInformation (Address: 0x1800a23f8)
- EventUnregister (Address: 0x1800a23d8)
- EventWrite (Address: 0x1800a23e0)
- EventWriteTransfer (Address: 0x1800a23f0)
- RegCloseKey (Address: 0x1800a23c8)
- RegGetValueW (Address: 0x1800a23b8)
- RegOpenKeyExW (Address: 0x1800a23c0)
- RegQueryValueExW (Address: 0x1800a2400)
api-ms-win-core-featurestaging-l1-1-0.dll
- RecordFeatureUsage (Address: 0x1800a28d8)
- SubscribeFeatureStateChangeNotification (Address: 0x1800a28e0)
- UnsubscribeFeatureStateChangeNotification (Address: 0x1800a28e8)
dbghelp.dll
- StackWalk64 (Address: 0x1800a2938)
- SymCleanup (Address: 0x1800a2918)
- SymFindFileInPath (Address: 0x1800a2920)
- SymFromAddr (Address: 0x1800a2900)
- SymFromName (Address: 0x1800a2930)
- SymFunctionTableAccess64 (Address: 0x1800a2968)
- SymGetLineFromAddr64 (Address: 0x1800a28f8)
- SymGetModuleBase64 (Address: 0x1800a2970)
- SymGetModuleInfo64 (Address: 0x1800a2908)
- SymGetOptions (Address: 0x1800a2960)
- SymGetTypeFromName (Address: 0x1800a2940)
- SymGetTypeInfo (Address: 0x1800a2948)
- SymInitializeW (Address: 0x1800a2950)
- SymLoadModuleEx (Address: 0x1800a2928)
- SymRegisterCallback64 (Address: 0x1800a2910)
- SymSetOptions (Address: 0x1800a2958)
KERNEL32.dll
- AcquireSRWLockExclusive (Address: 0x1800a24d8)
- AcquireSRWLockShared (Address: 0x1800a24e8)
- CancelIoEx (Address: 0x1800a2768)
- CloseHandle (Address: 0x1800a2478)
- CloseThreadpoolWork (Address: 0x1800a2830)
- CompareFileTime (Address: 0x1800a2720)
- CreateEventExW (Address: 0x1800a2758)
- CreateEventW (Address: 0x1800a2778)
- CreateFileA (Address: 0x1800a27f0)
- CreateFileW (Address: 0x1800a26d0)
- CreateMutexExW (Address: 0x1800a2490)
- CreateSemaphoreExW (Address: 0x1800a2730)
- CreateThreadpoolWork (Address: 0x1800a2848)
- DebugBreak (Address: 0x1800a24b0)
- DecodePointer (Address: 0x1800a2850)
- DeleteCriticalSection (Address: 0x1800a25b0)
- DeviceIoControl (Address: 0x1800a2770)
- EncodePointer (Address: 0x1800a2708)
- EnterCriticalSection (Address: 0x1800a25a0)
- EnumSystemLocalesW (Address: 0x1800a2630)
- ExitProcess (Address: 0x1800a2638)
- FindClose (Address: 0x1800a27d0)
- FindFirstFileExW (Address: 0x1800a27a0)
- FindFirstFileW (Address: 0x1800a27c0)
- FindNextFileW (Address: 0x1800a27c8)
- FlsAlloc (Address: 0x1800a25d0)
- FlsFree (Address: 0x1800a25e8)
- FlsGetValue (Address: 0x1800a25d8)
- FlsSetValue (Address: 0x1800a25e0)
- FlushFileBuffers (Address: 0x1800a2690)
- FormatMessageW (Address: 0x1800a2450)
- FreeEnvironmentStringsW (Address: 0x1800a2780)
- FreeLibrary (Address: 0x1800a2600)
- FreeLibraryWhenCallbackReturns (Address: 0x1800a2840)
- GetACP (Address: 0x1800a2648)
- GetActiveProcessorCount (Address: 0x1800a2800)
- GetCommandLineA (Address: 0x1800a2798)
- GetCommandLineW (Address: 0x1800a2790)
- GetConsoleMode (Address: 0x1800a26a8)
- GetConsoleOutputCP (Address: 0x1800a26a0)
- GetCPInfo (Address: 0x1800a2658)
- GetCurrentProcess (Address: 0x1800a2518)
- GetCurrentProcessId (Address: 0x1800a2498)
- GetCurrentThreadId (Address: 0x1800a2440)
- GetDiskFreeSpaceW (Address: 0x1800a2728)
- GetEnvironmentStringsW (Address: 0x1800a2788)
- GetFileSizeEx (Address: 0x1800a2678)
- GetFileTime (Address: 0x1800a2738)
- GetFileType (Address: 0x1800a25c0)
- GetFullPathNameW (Address: 0x1800a2718)
- GetLastError (Address: 0x1800a2458)
- GetLocaleInfoW (Address: 0x1800a2618)
- GetModuleFileNameA (Address: 0x1800a25f8)
- GetModuleFileNameW (Address: 0x1800a2508)
- GetModuleHandleExW (Address: 0x1800a2430)
- GetModuleHandleW (Address: 0x1800a24a8)
- GetOEMCP (Address: 0x1800a2650)
- GetOverlappedResult (Address: 0x1800a2808)
- GetOverlappedResultEx (Address: 0x1800a2868)
- GetProcAddress (Address: 0x1800a2488)
- GetProcessHeap (Address: 0x1800a24a0)
- GetStartupInfoW (Address: 0x1800a25c8)
- GetStdHandle (Address: 0x1800a25b8)
- GetStringTypeW (Address: 0x1800a2660)
- GetSystemInfo (Address: 0x1800a2580)
- GetSystemTimeAsFileTime (Address: 0x1800a27b8)
- GetSystemTimePreciseAsFileTime (Address: 0x1800a27b0)
- GetTickCount (Address: 0x1800a2520)
- GetUserDefaultLCID (Address: 0x1800a2628)
- HeapAlloc (Address: 0x1800a2480)
- HeapFree (Address: 0x1800a2418)
- HeapReAlloc (Address: 0x1800a26c0)
- HeapSize (Address: 0x1800a26b8)
- InitializeConditionVariable (Address: 0x1800a2828)
- InitializeCriticalSectionAndSpinCount (Address: 0x1800a25f0)
- InitializeCriticalSectionEx (Address: 0x1800a2710)
- InitializeSListHead (Address: 0x1800a26e8)
- InitializeSRWLock (Address: 0x1800a2528)
- InitOnceBeginInitialize (Address: 0x1800a2500)
- InitOnceComplete (Address: 0x1800a24f8)
- InterlockedFlushSList (Address: 0x1800a2700)
- InterlockedPopEntrySList (Address: 0x1800a2760)
- InterlockedPushEntrySList (Address: 0x1800a26f8)
- IsDebuggerPresent (Address: 0x1800a24b8)
- IsProcessorFeaturePresent (Address: 0x1800a2578)
- IsValidCodePage (Address: 0x1800a2640)
- IsValidLocale (Address: 0x1800a2620)
- K32GetModuleInformation (Address: 0x1800a2538)
- LCMapStringEx (Address: 0x1800a2858)
- LCMapStringW (Address: 0x1800a2610)
- LeaveCriticalSection (Address: 0x1800a25a8)
- LoadLibraryExW (Address: 0x1800a2608)
- LocalAlloc (Address: 0x1800a24c8)
- LocalFree (Address: 0x1800a24c0)
- LockFileEx (Address: 0x1800a2740)
- MultiByteToWideChar (Address: 0x1800a2668)
- OpenSemaphoreW (Address: 0x1800a2470)
- OutputDebugStringA (Address: 0x1800a27f8)
- OutputDebugStringW (Address: 0x1800a2460)
- QueryPerformanceCounter (Address: 0x1800a26e0)
- QueryPerformanceFrequency (Address: 0x1800a2860)
- RaiseException (Address: 0x1800a26c8)
- RaiseFailFastException (Address: 0x1800a2510)
- ReadFile (Address: 0x1800a26b0)
- ReleaseMutex (Address: 0x1800a2448)
- ReleaseSemaphore (Address: 0x1800a2428)
- ReleaseSRWLockExclusive (Address: 0x1800a24d0)
- ReleaseSRWLockShared (Address: 0x1800a24f0)
- ResetEvent (Address: 0x1800a27e0)
- RtlCaptureContext (Address: 0x1800a2548)
- RtlCaptureStackBackTrace (Address: 0x1800a24e0)
- RtlLookupFunctionEntry (Address: 0x1800a2550)
- RtlPcToFileHeader (Address: 0x1800a2540)
- RtlUnwindEx (Address: 0x1800a26f0)
- RtlVirtualUnwind (Address: 0x1800a2558)
- SetEndOfFile (Address: 0x1800a2810)
- SetEvent (Address: 0x1800a27d8)
- SetFilePointerEx (Address: 0x1800a2680)
- SetFileTime (Address: 0x1800a2750)
- SetLastError (Address: 0x1800a2420)
- SetStdHandle (Address: 0x1800a2688)
- SetUnhandledExceptionFilter (Address: 0x1800a2568)
- Sleep (Address: 0x1800a27a8)
- SleepConditionVariableSRW (Address: 0x1800a2530)
- SubmitThreadpoolWork (Address: 0x1800a2838)
- TerminateProcess (Address: 0x1800a2570)
- TryAcquireSRWLockExclusive (Address: 0x1800a2818)
- UnhandledExceptionFilter (Address: 0x1800a2560)
- UnlockFileEx (Address: 0x1800a2748)
- VirtualAlloc (Address: 0x1800a2588)
- VirtualProtect (Address: 0x1800a2590)
- VirtualQuery (Address: 0x1800a2598)
- WaitForSingleObject (Address: 0x1800a2438)
- WaitForSingleObjectEx (Address: 0x1800a2468)
- WakeAllConditionVariable (Address: 0x1800a27e8)
- WakeConditionVariable (Address: 0x1800a2820)
- WideCharToMultiByte (Address: 0x1800a2670)
- WriteConsoleW (Address: 0x1800a26d8)
- WriteFile (Address: 0x1800a2698)
ntdll.dll
- NtCreateFile (Address: 0x1800a2980)
- NtFsControlFile (Address: 0x1800a2990)
- NtQueryInformationFile (Address: 0x1800a29a0)
- RtlDecompressBufferEx (Address: 0x1800a29a8)
- RtlGetCompressionWorkSpaceSize (Address: 0x1800a2998)
- RtlNtStatusToDosError (Address: 0x1800a2988)
ole32.dll
- CoCreateInstance (Address: 0x1800a29d0)
- CoGetObjectContext (Address: 0x1800a29c8)
- CoInitializeEx (Address: 0x1800a29c0)
- CoInitializeSecurity (Address: 0x1800a29b8)
- CoUninitialize (Address: 0x1800a29d8)
OLEAUT32.dll
- SysStringLen (Address: 0x1800a2890)
- VariantChangeTypeEx (Address: 0x1800a2878)
- VariantClear (Address: 0x1800a2880)
- VariantInit (Address: 0x1800a2888)
RPCRT4.dll
- UuidCreate (Address: 0x1800a28a0)
SHLWAPI.dll
- PathAppendW (Address: 0x1800a28b8)
- PathRemoveFileSpecW (Address: 0x1800a28b0)
XmlLite.dll
- CreateXmlReader (Address: 0x1800a28c8)