vmsavedstatedumpprovider.dll
Description: VM Saved State Dump Provider
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.26100.4654
Architecture: 64-bit
Operating System: Windows NT
SHA256: 9d8a23098f52fe7d91cf00037e64ef61
File Size: 930.4 KB
Uploaded At: Dec. 3, 2025, 2:38 a.m.
Views: 6
Exported Functions
- ApplyGuestMemoryFix (Ordinal: 1, Address: 0x34550)
- ApplyPendingSavedStateFileReplayLog (Ordinal: 2, Address: 0x34620)
- CallStackUnwind (Ordinal: 3, Address: 0x347c0)
- FindSavedStateSymbolFieldInType (Ordinal: 4, Address: 0x348a0)
- ForceActiveVirtualTrustLevel (Ordinal: 5, Address: 0x34980)
- ForceArchitecture (Ordinal: 6, Address: 0x34a40)
- ForceNestedHostMode (Ordinal: 7, Address: 0x34b00)
- ForcePagingMode (Ordinal: 8, Address: 0x34be0)
- GetActiveVirtualTrustLevel (Ordinal: 9, Address: 0x34ca0)
- GetArchitecture (Ordinal: 10, Address: 0x34d60)
- GetCrashDumpHeader (Ordinal: 11, Address: 0x34e20)
- GetEnabledVirtualTrustLevels (Ordinal: 12, Address: 0x34f20)
- GetGuestEnabledVirtualTrustLevels (Ordinal: 13, Address: 0x34fd0)
- GetGuestOsInfo (Ordinal: 14, Address: 0x35080)
- GetGuestPhysicalMemoryChunks (Ordinal: 15, Address: 0x35150)
- GetGuestRawSavedMemorySize (Ordinal: 16, Address: 0x35340)
- GetMemoryBlockCacheLimit (Ordinal: 17, Address: 0x35400)
- GetNestedVirtualizationMode (Ordinal: 18, Address: 0x354c0)
- GetPagingMode (Ordinal: 19, Address: 0x35580)
- GetRegisterValue (Ordinal: 20, Address: 0x35640)
- GetSavedStateSymbolFieldInfo (Ordinal: 21, Address: 0x35710)
- GetSavedStateSymbolProviderHandle (Ordinal: 22, Address: 0x35890)
- GetSavedStateSymbolTypeSize (Ordinal: 23, Address: 0x35940)
- GetVpCount (Ordinal: 24, Address: 0x35a00)
- GuestPhysicalAddressToRawSavedMemoryOffset (Ordinal: 25, Address: 0x35ab0)
- GuestVirtualAddressToPhysicalAddress (Ordinal: 26, Address: 0x35b70)
- InKernelSpace (Ordinal: 27, Address: 0x35c70)
- IsActiveVirtualTrustLevelEnabled (Ordinal: 28, Address: 0x35d30)
- IsNestedVirtualizationEnabled (Ordinal: 29, Address: 0x35df0)
- LoadKernelImage (Ordinal: 30, Address: 0x35ea0)
- LoadSavedStateFile (Ordinal: 31, Address: 0x35fb0)
- LoadSavedStateFiles (Ordinal: 32, Address: 0x360a0)
- LoadSavedStateModuleSymbols (Ordinal: 33, Address: 0x36190)
- LoadSavedStateModuleSymbolsEx (Ordinal: 34, Address: 0x36260)
- LoadSavedStateSymbolProvider (Ordinal: 35, Address: 0x36340)
- LocateKernelImage (Ordinal: 36, Address: 0x36410)
- LocateSavedStateFiles (Ordinal: 37, Address: 0x36510)
- ReadGuestPhysicalAddress (Ordinal: 38, Address: 0x36710)
- ReadGuestRawSavedMemory (Ordinal: 39, Address: 0x367f0)
- ReadSavedStateGlobalVariable (Ordinal: 40, Address: 0x368d0)
- ReleaseSavedStateFiles (Ordinal: 41, Address: 0x369a0)
- ReleaseSavedStateSymbolProvider (Ordinal: 42, Address: 0x36ad0)
- ResolveSavedStateGlobalVariableAddress (Ordinal: 43, Address: 0x36b90)
- ScanMemoryForDosImages (Ordinal: 44, Address: 0x36c60)
- SetMemoryBlockCacheLimit (Ordinal: 45, Address: 0x36d90)
- SetSavedStateSymbolProviderDebugInfoCallback (Ordinal: 46, Address: 0x36e50)
- WriteCrashDumpFile (Ordinal: 47, Address: 0x373d0)
Imported DLLs & Functions
ADVAPI32.dll
- EventActivityIdControl (Address: 0x1800a0280)
- EventEnabled (Address: 0x1800a0260)
- EventRegister (Address: 0x1800a0248)
- EventSetInformation (Address: 0x1800a0270)
- EventUnregister (Address: 0x1800a0250)
- EventWrite (Address: 0x1800a0258)
- EventWriteTransfer (Address: 0x1800a0268)
- RegCloseKey (Address: 0x1800a0240)
- RegGetValueW (Address: 0x1800a0230)
- RegOpenKeyExW (Address: 0x1800a0238)
- RegQueryValueExW (Address: 0x1800a0278)
api-ms-win-core-featurestaging-l1-1-0.dll
- RecordFeatureUsage (Address: 0x1800a0748)
- SubscribeFeatureStateChangeNotification (Address: 0x1800a0750)
- UnsubscribeFeatureStateChangeNotification (Address: 0x1800a0758)
dbghelp.dll
- StackWalk64 (Address: 0x1800a07a8)
- SymCleanup (Address: 0x1800a0788)
- SymFindFileInPath (Address: 0x1800a0790)
- SymFromAddr (Address: 0x1800a0770)
- SymFromName (Address: 0x1800a07a0)
- SymFunctionTableAccess64 (Address: 0x1800a07d8)
- SymGetLineFromAddr64 (Address: 0x1800a0768)
- SymGetModuleBase64 (Address: 0x1800a07e0)
- SymGetModuleInfo64 (Address: 0x1800a0778)
- SymGetOptions (Address: 0x1800a07d0)
- SymGetTypeFromName (Address: 0x1800a07b0)
- SymGetTypeInfo (Address: 0x1800a07b8)
- SymInitializeW (Address: 0x1800a07c0)
- SymLoadModuleEx (Address: 0x1800a0798)
- SymRegisterCallback64 (Address: 0x1800a0780)
- SymSetOptions (Address: 0x1800a07c8)
KERNEL32.dll
- AcquireSRWLockExclusive (Address: 0x1800a0358)
- AcquireSRWLockShared (Address: 0x1800a0368)
- CancelIoEx (Address: 0x1800a05e0)
- CloseHandle (Address: 0x1800a02f0)
- CloseThreadpoolWork (Address: 0x1800a06a0)
- CompareFileTime (Address: 0x1800a0598)
- CreateEventExW (Address: 0x1800a05d0)
- CreateEventW (Address: 0x1800a05f8)
- CreateFileA (Address: 0x1800a0670)
- CreateFileW (Address: 0x1800a0550)
- CreateMutexExW (Address: 0x1800a0308)
- CreateSemaphoreExW (Address: 0x1800a05a8)
- CreateThreadpoolWork (Address: 0x1800a06b8)
- DebugBreak (Address: 0x1800a0330)
- DecodePointer (Address: 0x1800a06c0)
- DeleteCriticalSection (Address: 0x1800a0430)
- DeviceIoControl (Address: 0x1800a05e8)
- EncodePointer (Address: 0x1800a0588)
- EnterCriticalSection (Address: 0x1800a0420)
- EnumSystemLocalesW (Address: 0x1800a04b8)
- ExitProcess (Address: 0x1800a04c0)
- FindClose (Address: 0x1800a0650)
- FindFirstFileExW (Address: 0x1800a0628)
- FindFirstFileW (Address: 0x1800a0640)
- FindNextFileW (Address: 0x1800a0648)
- FlsAlloc (Address: 0x1800a0450)
- FlsFree (Address: 0x1800a0468)
- FlsGetValue (Address: 0x1800a0458)
- FlsSetValue (Address: 0x1800a0460)
- FlushFileBuffers (Address: 0x1800a0510)
- FormatMessageW (Address: 0x1800a02c8)
- FreeEnvironmentStringsW (Address: 0x1800a0608)
- FreeLibrary (Address: 0x1800a0488)
- FreeLibraryWhenCallbackReturns (Address: 0x1800a06b0)
- GetACP (Address: 0x1800a04d0)
- GetActiveProcessorCount (Address: 0x1800a0690)
- GetCommandLineA (Address: 0x1800a0620)
- GetCommandLineW (Address: 0x1800a0618)
- GetConsoleMode (Address: 0x1800a0528)
- GetConsoleOutputCP (Address: 0x1800a0520)
- GetCPInfo (Address: 0x1800a04e0)
- GetCurrentProcess (Address: 0x1800a0398)
- GetCurrentProcessId (Address: 0x1800a0310)
- GetCurrentThreadId (Address: 0x1800a02b8)
- GetDiskFreeSpaceW (Address: 0x1800a05a0)
- GetEnvironmentStringsW (Address: 0x1800a0610)
- GetFileSizeEx (Address: 0x1800a04f8)
- GetFileTime (Address: 0x1800a05b0)
- GetFileType (Address: 0x1800a0440)
- GetFullPathNameW (Address: 0x1800a0590)
- GetLastError (Address: 0x1800a02d0)
- GetLocaleInfoW (Address: 0x1800a04a0)
- GetModuleFileNameA (Address: 0x1800a0470)
- GetModuleFileNameW (Address: 0x1800a0388)
- GetModuleHandleExW (Address: 0x1800a02a8)
- GetModuleHandleW (Address: 0x1800a0320)
- GetOEMCP (Address: 0x1800a04d8)
- GetOverlappedResult (Address: 0x1800a0680)
- GetOverlappedResultEx (Address: 0x1800a06d8)
- GetProcAddress (Address: 0x1800a0300)
- GetProcessHeap (Address: 0x1800a0318)
- GetStartupInfoW (Address: 0x1800a0448)
- GetStdHandle (Address: 0x1800a0438)
- GetStringTypeW (Address: 0x1800a04e8)
- GetSystemInfo (Address: 0x1800a0400)
- GetSystemTimeAsFileTime (Address: 0x1800a0480)
- GetSystemTimePreciseAsFileTime (Address: 0x1800a0638)
- GetTickCount (Address: 0x1800a03a0)
- GetUserDefaultLCID (Address: 0x1800a04b0)
- HeapAlloc (Address: 0x1800a02f8)
- HeapFree (Address: 0x1800a0290)
- HeapQueryInformation (Address: 0x1800a05f0)
- HeapReAlloc (Address: 0x1800a0540)
- HeapSize (Address: 0x1800a0538)
- InitializeCriticalSectionAndSpinCount (Address: 0x1800a0600)
- InitializeCriticalSectionEx (Address: 0x1800a0478)
- InitializeSListHead (Address: 0x1800a0568)
- InitializeSRWLock (Address: 0x1800a03a8)
- InitOnceBeginInitialize (Address: 0x1800a0380)
- InitOnceComplete (Address: 0x1800a0378)
- InterlockedFlushSList (Address: 0x1800a0580)
- InterlockedPopEntrySList (Address: 0x1800a05d8)
- InterlockedPushEntrySList (Address: 0x1800a0578)
- IsDebuggerPresent (Address: 0x1800a0338)
- IsProcessorFeaturePresent (Address: 0x1800a03f8)
- IsValidCodePage (Address: 0x1800a04c8)
- IsValidLocale (Address: 0x1800a04a8)
- K32GetModuleInformation (Address: 0x1800a03b8)
- LCMapStringEx (Address: 0x1800a06c8)
- LCMapStringW (Address: 0x1800a0498)
- LeaveCriticalSection (Address: 0x1800a0428)
- LoadLibraryExW (Address: 0x1800a0490)
- LocalAlloc (Address: 0x1800a0348)
- LocalFree (Address: 0x1800a0340)
- LockFileEx (Address: 0x1800a05b8)
- MultiByteToWideChar (Address: 0x1800a04f0)
- OpenSemaphoreW (Address: 0x1800a02e8)
- OutputDebugStringA (Address: 0x1800a0678)
- OutputDebugStringW (Address: 0x1800a02d8)
- QueryPerformanceCounter (Address: 0x1800a0560)
- QueryPerformanceFrequency (Address: 0x1800a06d0)
- RaiseException (Address: 0x1800a0548)
- RaiseFailFastException (Address: 0x1800a0390)
- ReadFile (Address: 0x1800a0530)
- ReleaseMutex (Address: 0x1800a02c0)
- ReleaseSemaphore (Address: 0x1800a02a0)
- ReleaseSRWLockExclusive (Address: 0x1800a0350)
- ReleaseSRWLockShared (Address: 0x1800a0370)
- ResetEvent (Address: 0x1800a0660)
- RtlCaptureContext (Address: 0x1800a03c8)
- RtlCaptureStackBackTrace (Address: 0x1800a0360)
- RtlLookupFunctionEntry (Address: 0x1800a03d0)
- RtlPcToFileHeader (Address: 0x1800a03c0)
- RtlUnwindEx (Address: 0x1800a0570)
- RtlVirtualUnwind (Address: 0x1800a03d8)
- SetEndOfFile (Address: 0x1800a0688)
- SetEvent (Address: 0x1800a0658)
- SetFilePointerEx (Address: 0x1800a0500)
- SetFileTime (Address: 0x1800a05c8)
- SetLastError (Address: 0x1800a0298)
- SetStdHandle (Address: 0x1800a0508)
- SetUnhandledExceptionFilter (Address: 0x1800a03e8)
- Sleep (Address: 0x1800a0630)
- SleepConditionVariableSRW (Address: 0x1800a03b0)
- SubmitThreadpoolWork (Address: 0x1800a06a8)
- TerminateProcess (Address: 0x1800a03f0)
- UnhandledExceptionFilter (Address: 0x1800a03e0)
- UnlockFileEx (Address: 0x1800a05c0)
- VirtualAlloc (Address: 0x1800a0408)
- VirtualProtect (Address: 0x1800a0410)
- VirtualQuery (Address: 0x1800a0418)
- WaitForSingleObject (Address: 0x1800a02b0)
- WaitForSingleObjectEx (Address: 0x1800a02e0)
- WakeAllConditionVariable (Address: 0x1800a0668)
- WakeConditionVariable (Address: 0x1800a0698)
- WideCharToMultiByte (Address: 0x1800a0328)
- WriteConsoleW (Address: 0x1800a0558)
- WriteFile (Address: 0x1800a0518)
ntdll.dll
- NtCreateFile (Address: 0x1800a07f0)
- NtFsControlFile (Address: 0x1800a0800)
- NtQueryInformationFile (Address: 0x1800a0810)
- RtlDecompressBufferEx (Address: 0x1800a0818)
- RtlGetCompressionWorkSpaceSize (Address: 0x1800a0808)
- RtlNtStatusToDosError (Address: 0x1800a07f8)
ole32.dll
- CoCreateInstance (Address: 0x1800a0840)
- CoGetObjectContext (Address: 0x1800a0838)
- CoInitializeEx (Address: 0x1800a0830)
- CoInitializeSecurity (Address: 0x1800a0828)
- CoUninitialize (Address: 0x1800a0848)
OLEAUT32.dll
- SysStringLen (Address: 0x1800a0700)
- VariantChangeTypeEx (Address: 0x1800a06e8)
- VariantClear (Address: 0x1800a06f0)
- VariantInit (Address: 0x1800a06f8)
RPCRT4.dll
- UuidCreate (Address: 0x1800a0710)
SHLWAPI.dll
- PathAppendW (Address: 0x1800a0728)
- PathRemoveFileSpecW (Address: 0x1800a0720)
XmlLite.dll
- CreateXmlReader (Address: 0x1800a0738)