vmsavedstatedumpprovider.dll

Description: VM Saved State Dump Provider

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.26100.4654

Architecture: 64-bit

Operating System: Windows NT

SHA256: 9d8a23098f52fe7d91cf00037e64ef61

File Size: 930.4 KB

Uploaded At: Dec. 3, 2025, 2:38 a.m.

Views: 6

Exported Functions

  • ApplyGuestMemoryFix (Ordinal: 1, Address: 0x34550)
  • ApplyPendingSavedStateFileReplayLog (Ordinal: 2, Address: 0x34620)
  • CallStackUnwind (Ordinal: 3, Address: 0x347c0)
  • FindSavedStateSymbolFieldInType (Ordinal: 4, Address: 0x348a0)
  • ForceActiveVirtualTrustLevel (Ordinal: 5, Address: 0x34980)
  • ForceArchitecture (Ordinal: 6, Address: 0x34a40)
  • ForceNestedHostMode (Ordinal: 7, Address: 0x34b00)
  • ForcePagingMode (Ordinal: 8, Address: 0x34be0)
  • GetActiveVirtualTrustLevel (Ordinal: 9, Address: 0x34ca0)
  • GetArchitecture (Ordinal: 10, Address: 0x34d60)
  • GetCrashDumpHeader (Ordinal: 11, Address: 0x34e20)
  • GetEnabledVirtualTrustLevels (Ordinal: 12, Address: 0x34f20)
  • GetGuestEnabledVirtualTrustLevels (Ordinal: 13, Address: 0x34fd0)
  • GetGuestOsInfo (Ordinal: 14, Address: 0x35080)
  • GetGuestPhysicalMemoryChunks (Ordinal: 15, Address: 0x35150)
  • GetGuestRawSavedMemorySize (Ordinal: 16, Address: 0x35340)
  • GetMemoryBlockCacheLimit (Ordinal: 17, Address: 0x35400)
  • GetNestedVirtualizationMode (Ordinal: 18, Address: 0x354c0)
  • GetPagingMode (Ordinal: 19, Address: 0x35580)
  • GetRegisterValue (Ordinal: 20, Address: 0x35640)
  • GetSavedStateSymbolFieldInfo (Ordinal: 21, Address: 0x35710)
  • GetSavedStateSymbolProviderHandle (Ordinal: 22, Address: 0x35890)
  • GetSavedStateSymbolTypeSize (Ordinal: 23, Address: 0x35940)
  • GetVpCount (Ordinal: 24, Address: 0x35a00)
  • GuestPhysicalAddressToRawSavedMemoryOffset (Ordinal: 25, Address: 0x35ab0)
  • GuestVirtualAddressToPhysicalAddress (Ordinal: 26, Address: 0x35b70)
  • InKernelSpace (Ordinal: 27, Address: 0x35c70)
  • IsActiveVirtualTrustLevelEnabled (Ordinal: 28, Address: 0x35d30)
  • IsNestedVirtualizationEnabled (Ordinal: 29, Address: 0x35df0)
  • LoadKernelImage (Ordinal: 30, Address: 0x35ea0)
  • LoadSavedStateFile (Ordinal: 31, Address: 0x35fb0)
  • LoadSavedStateFiles (Ordinal: 32, Address: 0x360a0)
  • LoadSavedStateModuleSymbols (Ordinal: 33, Address: 0x36190)
  • LoadSavedStateModuleSymbolsEx (Ordinal: 34, Address: 0x36260)
  • LoadSavedStateSymbolProvider (Ordinal: 35, Address: 0x36340)
  • LocateKernelImage (Ordinal: 36, Address: 0x36410)
  • LocateSavedStateFiles (Ordinal: 37, Address: 0x36510)
  • ReadGuestPhysicalAddress (Ordinal: 38, Address: 0x36710)
  • ReadGuestRawSavedMemory (Ordinal: 39, Address: 0x367f0)
  • ReadSavedStateGlobalVariable (Ordinal: 40, Address: 0x368d0)
  • ReleaseSavedStateFiles (Ordinal: 41, Address: 0x369a0)
  • ReleaseSavedStateSymbolProvider (Ordinal: 42, Address: 0x36ad0)
  • ResolveSavedStateGlobalVariableAddress (Ordinal: 43, Address: 0x36b90)
  • ScanMemoryForDosImages (Ordinal: 44, Address: 0x36c60)
  • SetMemoryBlockCacheLimit (Ordinal: 45, Address: 0x36d90)
  • SetSavedStateSymbolProviderDebugInfoCallback (Ordinal: 46, Address: 0x36e50)
  • WriteCrashDumpFile (Ordinal: 47, Address: 0x373d0)

Imported DLLs & Functions

ADVAPI32.dll
  • EventActivityIdControl (Address: 0x1800a0280)
  • EventEnabled (Address: 0x1800a0260)
  • EventRegister (Address: 0x1800a0248)
  • EventSetInformation (Address: 0x1800a0270)
  • EventUnregister (Address: 0x1800a0250)
  • EventWrite (Address: 0x1800a0258)
  • EventWriteTransfer (Address: 0x1800a0268)
  • RegCloseKey (Address: 0x1800a0240)
  • RegGetValueW (Address: 0x1800a0230)
  • RegOpenKeyExW (Address: 0x1800a0238)
  • RegQueryValueExW (Address: 0x1800a0278)
api-ms-win-core-featurestaging-l1-1-0.dll
  • RecordFeatureUsage (Address: 0x1800a0748)
  • SubscribeFeatureStateChangeNotification (Address: 0x1800a0750)
  • UnsubscribeFeatureStateChangeNotification (Address: 0x1800a0758)
dbghelp.dll
  • StackWalk64 (Address: 0x1800a07a8)
  • SymCleanup (Address: 0x1800a0788)
  • SymFindFileInPath (Address: 0x1800a0790)
  • SymFromAddr (Address: 0x1800a0770)
  • SymFromName (Address: 0x1800a07a0)
  • SymFunctionTableAccess64 (Address: 0x1800a07d8)
  • SymGetLineFromAddr64 (Address: 0x1800a0768)
  • SymGetModuleBase64 (Address: 0x1800a07e0)
  • SymGetModuleInfo64 (Address: 0x1800a0778)
  • SymGetOptions (Address: 0x1800a07d0)
  • SymGetTypeFromName (Address: 0x1800a07b0)
  • SymGetTypeInfo (Address: 0x1800a07b8)
  • SymInitializeW (Address: 0x1800a07c0)
  • SymLoadModuleEx (Address: 0x1800a0798)
  • SymRegisterCallback64 (Address: 0x1800a0780)
  • SymSetOptions (Address: 0x1800a07c8)
KERNEL32.dll
  • AcquireSRWLockExclusive (Address: 0x1800a0358)
  • AcquireSRWLockShared (Address: 0x1800a0368)
  • CancelIoEx (Address: 0x1800a05e0)
  • CloseHandle (Address: 0x1800a02f0)
  • CloseThreadpoolWork (Address: 0x1800a06a0)
  • CompareFileTime (Address: 0x1800a0598)
  • CreateEventExW (Address: 0x1800a05d0)
  • CreateEventW (Address: 0x1800a05f8)
  • CreateFileA (Address: 0x1800a0670)
  • CreateFileW (Address: 0x1800a0550)
  • CreateMutexExW (Address: 0x1800a0308)
  • CreateSemaphoreExW (Address: 0x1800a05a8)
  • CreateThreadpoolWork (Address: 0x1800a06b8)
  • DebugBreak (Address: 0x1800a0330)
  • DecodePointer (Address: 0x1800a06c0)
  • DeleteCriticalSection (Address: 0x1800a0430)
  • DeviceIoControl (Address: 0x1800a05e8)
  • EncodePointer (Address: 0x1800a0588)
  • EnterCriticalSection (Address: 0x1800a0420)
  • EnumSystemLocalesW (Address: 0x1800a04b8)
  • ExitProcess (Address: 0x1800a04c0)
  • FindClose (Address: 0x1800a0650)
  • FindFirstFileExW (Address: 0x1800a0628)
  • FindFirstFileW (Address: 0x1800a0640)
  • FindNextFileW (Address: 0x1800a0648)
  • FlsAlloc (Address: 0x1800a0450)
  • FlsFree (Address: 0x1800a0468)
  • FlsGetValue (Address: 0x1800a0458)
  • FlsSetValue (Address: 0x1800a0460)
  • FlushFileBuffers (Address: 0x1800a0510)
  • FormatMessageW (Address: 0x1800a02c8)
  • FreeEnvironmentStringsW (Address: 0x1800a0608)
  • FreeLibrary (Address: 0x1800a0488)
  • FreeLibraryWhenCallbackReturns (Address: 0x1800a06b0)
  • GetACP (Address: 0x1800a04d0)
  • GetActiveProcessorCount (Address: 0x1800a0690)
  • GetCommandLineA (Address: 0x1800a0620)
  • GetCommandLineW (Address: 0x1800a0618)
  • GetConsoleMode (Address: 0x1800a0528)
  • GetConsoleOutputCP (Address: 0x1800a0520)
  • GetCPInfo (Address: 0x1800a04e0)
  • GetCurrentProcess (Address: 0x1800a0398)
  • GetCurrentProcessId (Address: 0x1800a0310)
  • GetCurrentThreadId (Address: 0x1800a02b8)
  • GetDiskFreeSpaceW (Address: 0x1800a05a0)
  • GetEnvironmentStringsW (Address: 0x1800a0610)
  • GetFileSizeEx (Address: 0x1800a04f8)
  • GetFileTime (Address: 0x1800a05b0)
  • GetFileType (Address: 0x1800a0440)
  • GetFullPathNameW (Address: 0x1800a0590)
  • GetLastError (Address: 0x1800a02d0)
  • GetLocaleInfoW (Address: 0x1800a04a0)
  • GetModuleFileNameA (Address: 0x1800a0470)
  • GetModuleFileNameW (Address: 0x1800a0388)
  • GetModuleHandleExW (Address: 0x1800a02a8)
  • GetModuleHandleW (Address: 0x1800a0320)
  • GetOEMCP (Address: 0x1800a04d8)
  • GetOverlappedResult (Address: 0x1800a0680)
  • GetOverlappedResultEx (Address: 0x1800a06d8)
  • GetProcAddress (Address: 0x1800a0300)
  • GetProcessHeap (Address: 0x1800a0318)
  • GetStartupInfoW (Address: 0x1800a0448)
  • GetStdHandle (Address: 0x1800a0438)
  • GetStringTypeW (Address: 0x1800a04e8)
  • GetSystemInfo (Address: 0x1800a0400)
  • GetSystemTimeAsFileTime (Address: 0x1800a0480)
  • GetSystemTimePreciseAsFileTime (Address: 0x1800a0638)
  • GetTickCount (Address: 0x1800a03a0)
  • GetUserDefaultLCID (Address: 0x1800a04b0)
  • HeapAlloc (Address: 0x1800a02f8)
  • HeapFree (Address: 0x1800a0290)
  • HeapQueryInformation (Address: 0x1800a05f0)
  • HeapReAlloc (Address: 0x1800a0540)
  • HeapSize (Address: 0x1800a0538)
  • InitializeCriticalSectionAndSpinCount (Address: 0x1800a0600)
  • InitializeCriticalSectionEx (Address: 0x1800a0478)
  • InitializeSListHead (Address: 0x1800a0568)
  • InitializeSRWLock (Address: 0x1800a03a8)
  • InitOnceBeginInitialize (Address: 0x1800a0380)
  • InitOnceComplete (Address: 0x1800a0378)
  • InterlockedFlushSList (Address: 0x1800a0580)
  • InterlockedPopEntrySList (Address: 0x1800a05d8)
  • InterlockedPushEntrySList (Address: 0x1800a0578)
  • IsDebuggerPresent (Address: 0x1800a0338)
  • IsProcessorFeaturePresent (Address: 0x1800a03f8)
  • IsValidCodePage (Address: 0x1800a04c8)
  • IsValidLocale (Address: 0x1800a04a8)
  • K32GetModuleInformation (Address: 0x1800a03b8)
  • LCMapStringEx (Address: 0x1800a06c8)
  • LCMapStringW (Address: 0x1800a0498)
  • LeaveCriticalSection (Address: 0x1800a0428)
  • LoadLibraryExW (Address: 0x1800a0490)
  • LocalAlloc (Address: 0x1800a0348)
  • LocalFree (Address: 0x1800a0340)
  • LockFileEx (Address: 0x1800a05b8)
  • MultiByteToWideChar (Address: 0x1800a04f0)
  • OpenSemaphoreW (Address: 0x1800a02e8)
  • OutputDebugStringA (Address: 0x1800a0678)
  • OutputDebugStringW (Address: 0x1800a02d8)
  • QueryPerformanceCounter (Address: 0x1800a0560)
  • QueryPerformanceFrequency (Address: 0x1800a06d0)
  • RaiseException (Address: 0x1800a0548)
  • RaiseFailFastException (Address: 0x1800a0390)
  • ReadFile (Address: 0x1800a0530)
  • ReleaseMutex (Address: 0x1800a02c0)
  • ReleaseSemaphore (Address: 0x1800a02a0)
  • ReleaseSRWLockExclusive (Address: 0x1800a0350)
  • ReleaseSRWLockShared (Address: 0x1800a0370)
  • ResetEvent (Address: 0x1800a0660)
  • RtlCaptureContext (Address: 0x1800a03c8)
  • RtlCaptureStackBackTrace (Address: 0x1800a0360)
  • RtlLookupFunctionEntry (Address: 0x1800a03d0)
  • RtlPcToFileHeader (Address: 0x1800a03c0)
  • RtlUnwindEx (Address: 0x1800a0570)
  • RtlVirtualUnwind (Address: 0x1800a03d8)
  • SetEndOfFile (Address: 0x1800a0688)
  • SetEvent (Address: 0x1800a0658)
  • SetFilePointerEx (Address: 0x1800a0500)
  • SetFileTime (Address: 0x1800a05c8)
  • SetLastError (Address: 0x1800a0298)
  • SetStdHandle (Address: 0x1800a0508)
  • SetUnhandledExceptionFilter (Address: 0x1800a03e8)
  • Sleep (Address: 0x1800a0630)
  • SleepConditionVariableSRW (Address: 0x1800a03b0)
  • SubmitThreadpoolWork (Address: 0x1800a06a8)
  • TerminateProcess (Address: 0x1800a03f0)
  • UnhandledExceptionFilter (Address: 0x1800a03e0)
  • UnlockFileEx (Address: 0x1800a05c0)
  • VirtualAlloc (Address: 0x1800a0408)
  • VirtualProtect (Address: 0x1800a0410)
  • VirtualQuery (Address: 0x1800a0418)
  • WaitForSingleObject (Address: 0x1800a02b0)
  • WaitForSingleObjectEx (Address: 0x1800a02e0)
  • WakeAllConditionVariable (Address: 0x1800a0668)
  • WakeConditionVariable (Address: 0x1800a0698)
  • WideCharToMultiByte (Address: 0x1800a0328)
  • WriteConsoleW (Address: 0x1800a0558)
  • WriteFile (Address: 0x1800a0518)
ntdll.dll
  • NtCreateFile (Address: 0x1800a07f0)
  • NtFsControlFile (Address: 0x1800a0800)
  • NtQueryInformationFile (Address: 0x1800a0810)
  • RtlDecompressBufferEx (Address: 0x1800a0818)
  • RtlGetCompressionWorkSpaceSize (Address: 0x1800a0808)
  • RtlNtStatusToDosError (Address: 0x1800a07f8)
ole32.dll
  • CoCreateInstance (Address: 0x1800a0840)
  • CoGetObjectContext (Address: 0x1800a0838)
  • CoInitializeEx (Address: 0x1800a0830)
  • CoInitializeSecurity (Address: 0x1800a0828)
  • CoUninitialize (Address: 0x1800a0848)
OLEAUT32.dll
  • SysStringLen (Address: 0x1800a0700)
  • VariantChangeTypeEx (Address: 0x1800a06e8)
  • VariantClear (Address: 0x1800a06f0)
  • VariantInit (Address: 0x1800a06f8)
RPCRT4.dll
  • UuidCreate (Address: 0x1800a0710)
SHLWAPI.dll
  • PathAppendW (Address: 0x1800a0728)
  • PathRemoveFileSpecW (Address: 0x1800a0720)
XmlLite.dll
  • CreateXmlReader (Address: 0x1800a0738)