vmsavedstatedumpprovider.dll
Description: VM Saved State Dump Provider
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.26100.4654
Architecture: Unknown (0xaa64)
Operating System: Windows NT
SHA256: c1c5dc93908d5040ad6446b8c9adc5cc
File Size: 915.8 KB
Uploaded At: Dec. 3, 2025, 2:38 a.m.
Views: 6
Exported Functions
- ApplyGuestMemoryFix (Ordinal: 1, Address: 0x34680)
- ApplyPendingSavedStateFileReplayLog (Ordinal: 2, Address: 0x34780)
- CallStackUnwind (Ordinal: 3, Address: 0x347c0)
- FindSavedStateSymbolFieldInType (Ordinal: 4, Address: 0x348c0)
- ForceActiveVirtualTrustLevel (Ordinal: 5, Address: 0x349d0)
- ForceArchitecture (Ordinal: 6, Address: 0x34ac0)
- ForceNestedHostMode (Ordinal: 7, Address: 0x34bb0)
- ForcePagingMode (Ordinal: 8, Address: 0x34cc0)
- GetActiveVirtualTrustLevel (Ordinal: 9, Address: 0x34db0)
- GetArchitecture (Ordinal: 10, Address: 0x34ea0)
- GetCrashDumpHeader (Ordinal: 11, Address: 0x34f90)
- GetEnabledVirtualTrustLevels (Ordinal: 12, Address: 0x350b0)
- GetGuestEnabledVirtualTrustLevels (Ordinal: 13, Address: 0x35170)
- GetGuestOsInfo (Ordinal: 14, Address: 0x35250)
- GetGuestPhysicalMemoryChunks (Ordinal: 15, Address: 0x35340)
- GetGuestRawSavedMemorySize (Ordinal: 16, Address: 0x35510)
- GetMemoryBlockCacheLimit (Ordinal: 17, Address: 0x355f0)
- GetNestedVirtualizationMode (Ordinal: 18, Address: 0x356d0)
- GetPagingMode (Ordinal: 19, Address: 0x357c0)
- GetRegisterValue (Ordinal: 20, Address: 0x358b0)
- GetSavedStateSymbolFieldInfo (Ordinal: 21, Address: 0x359b0)
- GetSavedStateSymbolProviderHandle (Ordinal: 22, Address: 0x35c50)
- GetSavedStateSymbolTypeSize (Ordinal: 23, Address: 0x35d10)
- GetVpCount (Ordinal: 24, Address: 0x35e00)
- GuestPhysicalAddressToRawSavedMemoryOffset (Ordinal: 25, Address: 0x35ee0)
- GuestVirtualAddressToPhysicalAddress (Ordinal: 26, Address: 0x35fd0)
- InKernelSpace (Ordinal: 27, Address: 0x360f0)
- IsActiveVirtualTrustLevelEnabled (Ordinal: 28, Address: 0x361e0)
- IsNestedVirtualizationEnabled (Ordinal: 29, Address: 0x362d0)
- LoadKernelImage (Ordinal: 30, Address: 0x363b0)
- LoadSavedStateFile (Ordinal: 31, Address: 0x364d0)
- LoadSavedStateFiles (Ordinal: 32, Address: 0x36670)
- LoadSavedStateModuleSymbols (Ordinal: 33, Address: 0x36820)
- LoadSavedStateModuleSymbolsEx (Ordinal: 34, Address: 0x36920)
- LoadSavedStateSymbolProvider (Ordinal: 35, Address: 0x36a30)
- LocateKernelImage (Ordinal: 36, Address: 0x36b20)
- LocateSavedStateFiles (Ordinal: 37, Address: 0x36c40)
- ReadGuestPhysicalAddress (Ordinal: 38, Address: 0x36ef0)
- ReadGuestRawSavedMemory (Ordinal: 39, Address: 0x36ff0)
- ReadSavedStateGlobalVariable (Ordinal: 40, Address: 0x370f0)
- ReleaseSavedStateFiles (Ordinal: 41, Address: 0x371f0)
- ReleaseSavedStateSymbolProvider (Ordinal: 42, Address: 0x372d0)
- ResolveSavedStateGlobalVariableAddress (Ordinal: 43, Address: 0x373b0)
- ScanMemoryForDosImages (Ordinal: 44, Address: 0x374b0)
- SetMemoryBlockCacheLimit (Ordinal: 45, Address: 0x375f0)
- SetSavedStateSymbolProviderDebugInfoCallback (Ordinal: 46, Address: 0x376d0)
- WriteCrashDumpFile (Ordinal: 47, Address: 0x37c80)
Imported DLLs & Functions
ADVAPI32.dll
- EventActivityIdControl (Address: 0x18009e050)
- EventEnabled (Address: 0x18009e030)
- EventRegister (Address: 0x18009e018)
- EventSetInformation (Address: 0x18009e040)
- EventUnregister (Address: 0x18009e020)
- EventWrite (Address: 0x18009e028)
- EventWriteTransfer (Address: 0x18009e038)
- RegCloseKey (Address: 0x18009e010)
- RegGetValueW (Address: 0x18009e000)
- RegOpenKeyExW (Address: 0x18009e008)
- RegQueryValueExW (Address: 0x18009e048)
api-ms-win-core-featurestaging-l1-1-0.dll
- RecordFeatureUsage (Address: 0x18009e4f0)
- SubscribeFeatureStateChangeNotification (Address: 0x18009e4f8)
- UnsubscribeFeatureStateChangeNotification (Address: 0x18009e500)
dbghelp.dll
- StackWalk64 (Address: 0x18009e550)
- SymCleanup (Address: 0x18009e530)
- SymFindFileInPath (Address: 0x18009e538)
- SymFromAddr (Address: 0x18009e518)
- SymFromName (Address: 0x18009e548)
- SymFunctionTableAccess64 (Address: 0x18009e580)
- SymGetLineFromAddr64 (Address: 0x18009e510)
- SymGetModuleBase64 (Address: 0x18009e588)
- SymGetModuleInfo64 (Address: 0x18009e520)
- SymGetOptions (Address: 0x18009e578)
- SymGetTypeFromName (Address: 0x18009e558)
- SymGetTypeInfo (Address: 0x18009e560)
- SymInitializeW (Address: 0x18009e568)
- SymLoadModuleEx (Address: 0x18009e540)
- SymRegisterCallback64 (Address: 0x18009e528)
- SymSetOptions (Address: 0x18009e570)
KERNEL32.dll
- AcquireSRWLockExclusive (Address: 0x18009e128)
- AcquireSRWLockShared (Address: 0x18009e138)
- CancelIoEx (Address: 0x18009e388)
- CloseHandle (Address: 0x18009e0c0)
- CloseThreadpoolWork (Address: 0x18009e448)
- CompareFileTime (Address: 0x18009e340)
- CreateEventExW (Address: 0x18009e378)
- CreateEventW (Address: 0x18009e3a0)
- CreateFileA (Address: 0x18009e418)
- CreateFileW (Address: 0x18009e2f0)
- CreateMutexExW (Address: 0x18009e0d8)
- CreateSemaphoreExW (Address: 0x18009e350)
- CreateThreadpoolWork (Address: 0x18009e460)
- DebugBreak (Address: 0x18009e100)
- DecodePointer (Address: 0x18009e468)
- DeleteCriticalSection (Address: 0x18009e1c8)
- DeviceIoControl (Address: 0x18009e390)
- EncodePointer (Address: 0x18009e330)
- EnterCriticalSection (Address: 0x18009e1b8)
- EnumSystemLocalesW (Address: 0x18009e250)
- ExitProcess (Address: 0x18009e258)
- FindClose (Address: 0x18009e3f8)
- FindFirstFileExW (Address: 0x18009e3d0)
- FindFirstFileW (Address: 0x18009e3e8)
- FindNextFileW (Address: 0x18009e3f0)
- FlsAlloc (Address: 0x18009e1e8)
- FlsFree (Address: 0x18009e200)
- FlsGetValue (Address: 0x18009e1f0)
- FlsSetValue (Address: 0x18009e1f8)
- FlushFileBuffers (Address: 0x18009e2b0)
- FormatMessageW (Address: 0x18009e098)
- FreeEnvironmentStringsW (Address: 0x18009e3b0)
- FreeLibrary (Address: 0x18009e218)
- FreeLibraryWhenCallbackReturns (Address: 0x18009e458)
- GetACP (Address: 0x18009e270)
- GetActiveProcessorCount (Address: 0x18009e438)
- GetCommandLineA (Address: 0x18009e3c8)
- GetCommandLineW (Address: 0x18009e3c0)
- GetConsoleMode (Address: 0x18009e2c8)
- GetConsoleOutputCP (Address: 0x18009e2c0)
- GetCPInfo (Address: 0x18009e280)
- GetCurrentProcess (Address: 0x18009e168)
- GetCurrentProcessId (Address: 0x18009e0e0)
- GetCurrentThreadId (Address: 0x18009e088)
- GetDiskFreeSpaceW (Address: 0x18009e348)
- GetEnvironmentStringsW (Address: 0x18009e3b8)
- GetFileSizeEx (Address: 0x18009e298)
- GetFileTime (Address: 0x18009e358)
- GetFileType (Address: 0x18009e1d8)
- GetFullPathNameW (Address: 0x18009e338)
- GetLastError (Address: 0x18009e0a0)
- GetLocaleInfoW (Address: 0x18009e238)
- GetModuleFileNameA (Address: 0x18009e228)
- GetModuleFileNameW (Address: 0x18009e158)
- GetModuleHandleExW (Address: 0x18009e078)
- GetModuleHandleW (Address: 0x18009e0f0)
- GetOEMCP (Address: 0x18009e278)
- GetOverlappedResult (Address: 0x18009e428)
- GetOverlappedResultEx (Address: 0x18009e480)
- GetProcAddress (Address: 0x18009e0d0)
- GetProcessHeap (Address: 0x18009e0e8)
- GetStartupInfoW (Address: 0x18009e1e0)
- GetStdHandle (Address: 0x18009e1d0)
- GetStringTypeW (Address: 0x18009e288)
- GetSystemInfo (Address: 0x18009e198)
- GetSystemTimeAsFileTime (Address: 0x18009e210)
- GetSystemTimePreciseAsFileTime (Address: 0x18009e3e0)
- GetTickCount (Address: 0x18009e170)
- GetUserDefaultLCID (Address: 0x18009e248)
- HeapAlloc (Address: 0x18009e0c8)
- HeapFree (Address: 0x18009e060)
- HeapQueryInformation (Address: 0x18009e398)
- HeapReAlloc (Address: 0x18009e2e0)
- HeapSize (Address: 0x18009e2d8)
- InitializeCriticalSectionAndSpinCount (Address: 0x18009e3a8)
- InitializeCriticalSectionEx (Address: 0x18009e208)
- InitializeSListHead (Address: 0x18009e308)
- InitializeSRWLock (Address: 0x18009e178)
- InitOnceBeginInitialize (Address: 0x18009e150)
- InitOnceComplete (Address: 0x18009e148)
- InterlockedFlushSList (Address: 0x18009e328)
- InterlockedPopEntrySList (Address: 0x18009e380)
- InterlockedPushEntrySList (Address: 0x18009e320)
- IsDebuggerPresent (Address: 0x18009e108)
- IsValidCodePage (Address: 0x18009e268)
- IsValidLocale (Address: 0x18009e240)
- K32GetModuleInformation (Address: 0x18009e188)
- LCMapStringEx (Address: 0x18009e470)
- LCMapStringW (Address: 0x18009e230)
- LeaveCriticalSection (Address: 0x18009e1c0)
- LoadLibraryExW (Address: 0x18009e220)
- LocalAlloc (Address: 0x18009e118)
- LocalFree (Address: 0x18009e110)
- LockFileEx (Address: 0x18009e360)
- MultiByteToWideChar (Address: 0x18009e290)
- OpenSemaphoreW (Address: 0x18009e0b8)
- OutputDebugStringA (Address: 0x18009e420)
- OutputDebugStringW (Address: 0x18009e0a8)
- QueryPerformanceCounter (Address: 0x18009e300)
- QueryPerformanceFrequency (Address: 0x18009e478)
- RaiseException (Address: 0x18009e2e8)
- RaiseFailFastException (Address: 0x18009e160)
- ReadFile (Address: 0x18009e2d0)
- ReleaseMutex (Address: 0x18009e090)
- ReleaseSemaphore (Address: 0x18009e070)
- ReleaseSRWLockExclusive (Address: 0x18009e120)
- ReleaseSRWLockShared (Address: 0x18009e140)
- ResetEvent (Address: 0x18009e408)
- RtlCaptureStackBackTrace (Address: 0x18009e130)
- RtlLookupFunctionEntry (Address: 0x18009e310)
- RtlPcToFileHeader (Address: 0x18009e190)
- RtlUnwindEx (Address: 0x18009e318)
- SetEndOfFile (Address: 0x18009e430)
- SetEvent (Address: 0x18009e400)
- SetFilePointerEx (Address: 0x18009e2a0)
- SetFileTime (Address: 0x18009e370)
- SetLastError (Address: 0x18009e068)
- SetStdHandle (Address: 0x18009e2a8)
- Sleep (Address: 0x18009e3d8)
- SleepConditionVariableSRW (Address: 0x18009e180)
- SubmitThreadpoolWork (Address: 0x18009e450)
- TerminateProcess (Address: 0x18009e260)
- UnlockFileEx (Address: 0x18009e368)
- VirtualAlloc (Address: 0x18009e1a0)
- VirtualProtect (Address: 0x18009e1a8)
- VirtualQuery (Address: 0x18009e1b0)
- WaitForSingleObject (Address: 0x18009e080)
- WaitForSingleObjectEx (Address: 0x18009e0b0)
- WakeAllConditionVariable (Address: 0x18009e410)
- WakeConditionVariable (Address: 0x18009e440)
- WideCharToMultiByte (Address: 0x18009e0f8)
- WriteConsoleW (Address: 0x18009e2f8)
- WriteFile (Address: 0x18009e2b8)
ntdll.dll
- NtCreateFile (Address: 0x18009e598)
- NtFsControlFile (Address: 0x18009e5a8)
- NtQueryInformationFile (Address: 0x18009e5b8)
- RtlDecompressBufferEx (Address: 0x18009e5c0)
- RtlGetCompressionWorkSpaceSize (Address: 0x18009e5b0)
- RtlNtStatusToDosError (Address: 0x18009e5a0)
ole32.dll
- CoCreateInstance (Address: 0x18009e5e8)
- CoGetObjectContext (Address: 0x18009e5e0)
- CoInitializeEx (Address: 0x18009e5d8)
- CoInitializeSecurity (Address: 0x18009e5d0)
- CoUninitialize (Address: 0x18009e5f0)
OLEAUT32.dll
- SysStringLen (Address: 0x18009e4a8)
- VariantChangeTypeEx (Address: 0x18009e490)
- VariantClear (Address: 0x18009e498)
- VariantInit (Address: 0x18009e4a0)
RPCRT4.dll
- UuidCreate (Address: 0x18009e4b8)
SHLWAPI.dll
- PathAppendW (Address: 0x18009e4d0)
- PathRemoveFileSpecW (Address: 0x18009e4c8)
XmlLite.dll
- CreateXmlReader (Address: 0x18009e4e0)