KeyboardFilterCore.dll

Description: Keyboard Filter Hooks

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.3636

Architecture: 32-bit

Operating System: Windows NT

SHA256: 58c49918d61d1fd3a3caffc7ff0f8d13

File Size: 35.0 KB

Uploaded At: Dec. 1, 2025, 7:59 a.m.

Views: 11

Exported Functions

  • HookMain (Ordinal: 1, Address: 0x3260)

Imported DLLs & Functions

ADVAPI32.dll
  • GetTraceEnableFlags (Address: 0x10007024)
  • GetTraceEnableLevel (Address: 0x10007028)
  • GetTraceLoggerHandle (Address: 0x1000702c)
  • RegCloseKey (Address: 0x10007010)
  • RegCreateKeyExW (Address: 0x10007018)
  • RegDeleteValueW (Address: 0x10007004)
  • RegEnumValueW (Address: 0x10007008)
  • RegGetValueW (Address: 0x10007030)
  • RegisterTraceGuidsW (Address: 0x10007020)
  • RegNotifyChangeKeyValue (Address: 0x10007000)
  • RegOpenKeyExW (Address: 0x1000700c)
  • RegSetValueExW (Address: 0x10007014)
  • TraceMessage (Address: 0x10007034)
  • UnregisterTraceGuids (Address: 0x1000701c)
KERNEL32.dll
  • CloseHandle (Address: 0x1000709c)
  • CreateEventW (Address: 0x10007044)
  • CreateThread (Address: 0x10007098)
  • GetCurrentProcess (Address: 0x10007078)
  • GetCurrentProcessId (Address: 0x1000708c)
  • GetCurrentThreadId (Address: 0x1000705c)
  • GetLastError (Address: 0x1000707c)
  • GetNativeSystemInfo (Address: 0x1000704c)
  • GetSystemTimeAsFileTime (Address: 0x10007060)
  • GetTickCount (Address: 0x10007064)
  • InitOnceExecuteOnce (Address: 0x10007048)
  • IsWow64Process (Address: 0x10007050)
  • MultiByteToWideChar (Address: 0x10007084)
  • OpenEventW (Address: 0x10007090)
  • ProcessIdToSessionId (Address: 0x10007088)
  • QueryPerformanceCounter (Address: 0x10007058)
  • RaiseException (Address: 0x10007040)
  • ResetEvent (Address: 0x10007074)
  • SetEvent (Address: 0x10007094)
  • SetProcessShutdownParameters (Address: 0x10007080)
  • SetUnhandledExceptionFilter (Address: 0x1000706c)
  • Sleep (Address: 0x10007054)
  • TerminateProcess (Address: 0x10007070)
  • UnhandledExceptionFilter (Address: 0x10007068)
  • WaitForMultipleObjects (Address: 0x1000703c)
msvcrt.dll
  • _amsg_exit (Address: 0x10007154)
  • _callnewh (Address: 0x1000714c)
  • _except_handler4_common (Address: 0x10007160)
  • _initterm (Address: 0x1000715c)
  • _purecall (Address: 0x10007140)
  • _vsnwprintf (Address: 0x10007134)
  • _wcsicmp (Address: 0x10007138)
  • _XcptFilter (Address: 0x10007150)
  • free (Address: 0x10007144)
  • iswalpha (Address: 0x10007148)
  • malloc (Address: 0x10007164)
  • memcpy_s (Address: 0x1000713c)
  • memset (Address: 0x10007168)
  • wcstoul (Address: 0x10007158)
RPCRT4.dll
  • NdrClientCall4 (Address: 0x100070c8)
  • NdrServerCall2 (Address: 0x100070c4)
  • RpcBindingFree (Address: 0x100070a4)
  • RpcBindingFromStringBindingW (Address: 0x100070ac)
  • RpcServerListen (Address: 0x100070b8)
  • RpcServerRegisterIfEx (Address: 0x100070c0)
  • RpcServerUnregisterIf (Address: 0x100070b4)
  • RpcServerUseProtseqEpW (Address: 0x100070bc)
  • RpcStringBindingComposeW (Address: 0x100070b0)
  • RpcStringFreeW (Address: 0x100070a8)
USER32.dll
  • CallNextHookEx (Address: 0x1000712c)
  • CloseDesktop (Address: 0x100070fc)
  • CreateWindowExW (Address: 0x10007110)
  • DefWindowProcW (Address: 0x10007128)
  • DestroyWindow (Address: 0x10007120)
  • DispatchMessageW (Address: 0x1000711c)
  • GetClassNameW (Address: 0x100070dc)
  • GetGUIThreadInfo (Address: 0x100070e4)
  • GetKeyboardLayout (Address: 0x10007104)
  • GetMessageW (Address: 0x10007114)
  • GetUserObjectInformationW (Address: 0x100070f8)
  • GetWindowThreadProcessId (Address: 0x100070e0)
  • MapVirtualKeyExW (Address: 0x100070d8)
  • OpenInputDesktop (Address: 0x100070f4)
  • PostMessageW (Address: 0x10007108)
  • PostQuitMessage (Address: 0x100070d0)
  • RegisterClassW (Address: 0x1000710c)
  • SetWindowsHookExW (Address: 0x10007124)
  • SetWinEventHook (Address: 0x100070ec)
  • SystemParametersInfoW (Address: 0x100070e8)
  • TranslateMessage (Address: 0x10007118)
  • UnhookWindowsHookEx (Address: 0x10007100)
  • UnhookWinEvent (Address: 0x100070f0)
  • VkKeyScanExW (Address: 0x100070d4)