MemoryDiagnostic.dll

Description: Microsoft Windows Memory Diagnostic Task Handler

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.4123

Architecture: 64-bit

Operating System: Windows NT

SHA256: 2bcdcd7b55cea95661d6ad19ac7caffc

File Size: 33.0 KB

Uploaded At: Dec. 1, 2025, 7:32 a.m.

Views: 5

Exported Functions

  • DllCanUnloadNow (Ordinal: 1, Address: 0x1810)
  • DllGetClassObject (Ordinal: 2, Address: 0x1830)
  • DllRegisterServer (Ordinal: 3, Address: 0x1170)
  • DllUnregisterServer (Ordinal: 4, Address: 0x1170)

Imported DLLs & Functions

ADVAPI32.dll
  • AdjustTokenPrivileges (Address: 0x180007228)
  • EventRegister (Address: 0x1800071c8)
  • EventUnregister (Address: 0x180007218)
  • EventWrite (Address: 0x1800071b8)
  • GetTraceEnableFlags (Address: 0x1800071e0)
  • GetTraceEnableLevel (Address: 0x1800071f0)
  • GetTraceLoggerHandle (Address: 0x1800071d8)
  • LookupPrivilegeValueW (Address: 0x180007230)
  • OpenProcessToken (Address: 0x1800071f8)
  • RegCloseKey (Address: 0x1800071c0)
  • RegisterTraceGuidsW (Address: 0x180007200)
  • RegOpenKeyExW (Address: 0x180007210)
  • RegQueryValueExW (Address: 0x180007220)
  • RegSetValueExW (Address: 0x1800071e8)
  • TraceMessage (Address: 0x1800071d0)
  • UnregisterTraceGuids (Address: 0x180007208)
bcd.dll
  • BcdCloseObject (Address: 0x180007348)
  • BcdCloseStore (Address: 0x180007338)
  • BcdGetElementData (Address: 0x180007350)
  • BcdOpenObject (Address: 0x180007328)
  • BcdOpenSystemStore (Address: 0x180007340)
  • BcdSetElementData (Address: 0x180007330)
KERNEL32.dll
  • CloseHandle (Address: 0x1800072c8)
  • CreateEventW (Address: 0x1800072a0)
  • CreateThread (Address: 0x1800072d8)
  • DisableThreadLibraryCalls (Address: 0x1800072c0)
  • FreeLibrary (Address: 0x1800072e0)
  • FreeLibraryAndExitThread (Address: 0x180007290)
  • GetCurrentProcess (Address: 0x180007278)
  • GetCurrentProcessId (Address: 0x180007250)
  • GetCurrentThreadId (Address: 0x180007248)
  • GetLastError (Address: 0x1800072b0)
  • GetModuleHandleExW (Address: 0x180007280)
  • GetSystemInfo (Address: 0x1800072d0)
  • GetSystemTimeAsFileTime (Address: 0x1800072e8)
  • GetTickCount (Address: 0x180007240)
  • GetTickCount64 (Address: 0x1800072a8)
  • QueryPerformanceCounter (Address: 0x180007258)
  • ResumeThread (Address: 0x180007298)
  • SetEvent (Address: 0x1800072b8)
  • SetUnhandledExceptionFilter (Address: 0x180007268)
  • Sleep (Address: 0x180007260)
  • TerminateProcess (Address: 0x180007270)
  • UnhandledExceptionFilter (Address: 0x1800072f0)
  • WaitForSingleObject (Address: 0x180007288)
msvcrt.dll
  • __C_specific_handler (Address: 0x180007378)
  • _amsg_exit (Address: 0x180007388)
  • _callnewh (Address: 0x180007398)
  • _initterm (Address: 0x180007380)
  • _wcsdup (Address: 0x180007360)
  • _XcptFilter (Address: 0x180007390)
  • bsearch (Address: 0x1800073b0)
  • free (Address: 0x1800073a8)
  • malloc (Address: 0x1800073a0)
  • memcpy (Address: 0x180007370)
  • memset (Address: 0x180007368)
  • qsort (Address: 0x1800073b8)
  • wcscmp (Address: 0x1800073c0)
ntdll.dll
  • NtQuerySystemInformation (Address: 0x1800073d0)
  • NtSetSystemInformation (Address: 0x1800073e0)
  • RtlCaptureContext (Address: 0x1800073f8)
  • RtlLookupFunctionEntry (Address: 0x180007400)
  • RtlVirtualUnwind (Address: 0x180007408)
  • WinSqmIncrementDWORD (Address: 0x1800073f0)
  • WinSqmSetDWORD (Address: 0x1800073e8)
  • WinSqmSetIfMaxDWORD (Address: 0x1800073d8)
ole32.dll
  • CoCreateInstance (Address: 0x180007418)
OLEAUT32.dll
  • SysAllocString (Address: 0x180007308)
  • SysFreeString (Address: 0x180007300)
  • VariantClear (Address: 0x180007310)
  • VariantInit (Address: 0x180007318)
wevtapi.dll
  • EvtClose (Address: 0x180007428)
  • EvtCreateRenderContext (Address: 0x180007430)
  • EvtNext (Address: 0x180007440)
  • EvtQuery (Address: 0x180007448)
  • EvtRender (Address: 0x180007438)