KeyboardFilterShim.dll
Description: Keyboard Filter AppShim
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.4355
Architecture: 32-bit
Operating System: Windows NT
SHA256: a4441fba395eed4308a4fbafa3316055
File Size: 45.9 KB
Uploaded At: Dec. 1, 2025, 7:59 a.m.
Views: 12
Exported Functions
- GetHookAPIs (Ordinal: 1, Address: 0x5450)
- NotifyShims (Ordinal: 2, Address: 0x54c0)
Imported DLLs & Functions
ADVAPI32.dll
- GetTraceEnableFlags (Address: 0x1000a028)
- GetTraceEnableLevel (Address: 0x1000a02c)
- GetTraceLoggerHandle (Address: 0x1000a030)
- RegCloseKey (Address: 0x1000a010)
- RegCreateKeyExW (Address: 0x1000a018)
- RegDeleteValueW (Address: 0x1000a004)
- RegEnumValueW (Address: 0x1000a008)
- RegGetValueW (Address: 0x1000a01c)
- RegisterTraceGuidsW (Address: 0x1000a024)
- RegNotifyChangeKeyValue (Address: 0x1000a000)
- RegOpenKeyExW (Address: 0x1000a00c)
- RegSetValueExW (Address: 0x1000a014)
- TraceMessage (Address: 0x1000a034)
- UnregisterTraceGuids (Address: 0x1000a020)
apphelp.dll
- SE_GetShimId (Address: 0x1000a128)
- SE_ShimDPF (Address: 0x1000a12c)
KERNEL32.dll
- CloseHandle (Address: 0x1000a08c)
- CreateMutexExW (Address: 0x1000a0a4)
- CreateSemaphoreExW (Address: 0x1000a0dc)
- DebugBreak (Address: 0x1000a0b4)
- DeleteCriticalSection (Address: 0x1000a088)
- EnterCriticalSection (Address: 0x1000a084)
- FindResourceExW (Address: 0x1000a0e8)
- FormatMessageW (Address: 0x1000a04c)
- GetCurrentProcess (Address: 0x1000a070)
- GetCurrentProcessId (Address: 0x1000a0a8)
- GetCurrentThreadId (Address: 0x1000a0d4)
- GetLastError (Address: 0x1000a048)
- GetModuleFileNameA (Address: 0x1000a0d8)
- GetModuleHandleExW (Address: 0x1000a058)
- GetModuleHandleW (Address: 0x1000a0b0)
- GetProcAddress (Address: 0x1000a0a0)
- GetProcessHeap (Address: 0x1000a0ac)
- GetSystemTimeAsFileTime (Address: 0x1000a064)
- GetTickCount (Address: 0x1000a060)
- HeapAlloc (Address: 0x1000a09c)
- HeapDestroy (Address: 0x1000a090)
- HeapFree (Address: 0x1000a0e0)
- HeapReAlloc (Address: 0x1000a094)
- HeapSize (Address: 0x1000a098)
- InitializeCriticalSection (Address: 0x1000a0d0)
- InitOnceExecuteOnce (Address: 0x1000a0bc)
- IsDebuggerPresent (Address: 0x1000a0b8)
- LeaveCriticalSection (Address: 0x1000a080)
- LoadResource (Address: 0x1000a0cc)
- LockResource (Address: 0x1000a0c8)
- OpenSemaphoreW (Address: 0x1000a03c)
- OutputDebugStringW (Address: 0x1000a044)
- QueryPerformanceCounter (Address: 0x1000a068)
- RaiseException (Address: 0x1000a0c0)
- ReleaseMutex (Address: 0x1000a050)
- ReleaseSemaphore (Address: 0x1000a05c)
- SetLastError (Address: 0x1000a0e4)
- SetUnhandledExceptionFilter (Address: 0x1000a074)
- SizeofResource (Address: 0x1000a0c4)
- Sleep (Address: 0x1000a07c)
- TerminateProcess (Address: 0x1000a06c)
- UnhandledExceptionFilter (Address: 0x1000a078)
- WaitForSingleObject (Address: 0x1000a054)
- WaitForSingleObjectEx (Address: 0x1000a040)
msvcrt.dll
- __dllonexit (Address: 0x1000a170)
- _amsg_exit (Address: 0x1000a180)
- _except_handler4_common (Address: 0x1000a168)
- _initterm (Address: 0x1000a17c)
- _lock (Address: 0x1000a178)
- _onexit (Address: 0x1000a16c)
- _purecall (Address: 0x1000a14c)
- _unlock (Address: 0x1000a174)
- _vsnwprintf (Address: 0x1000a13c)
- _wcsicmp (Address: 0x1000a144)
- _wcsnicmp (Address: 0x1000a160)
- _XcptFilter (Address: 0x1000a184)
- free (Address: 0x1000a154)
- iswalpha (Address: 0x1000a164)
- iswspace (Address: 0x1000a158)
- malloc (Address: 0x1000a150)
- memcpy (Address: 0x1000a134)
- memcpy_s (Address: 0x1000a140)
- memmove (Address: 0x1000a138)
- memmove_s (Address: 0x1000a15c)
- memset (Address: 0x1000a188)
- toupper (Address: 0x1000a148)
ntdll.dll
- RtlAllocateHeap (Address: 0x1000a190)
- RtlFreeHeap (Address: 0x1000a194)
RPCRT4.dll
- NdrClientCall4 (Address: 0x1000a0f4)
- RpcBindingFree (Address: 0x1000a100)
- RpcBindingFromStringBindingW (Address: 0x1000a0f8)
- RpcStringBindingComposeW (Address: 0x1000a0f0)
- RpcStringFreeW (Address: 0x1000a0fc)
USER32.dll
- GetClassNameW (Address: 0x1000a118)
- GetGUIThreadInfo (Address: 0x1000a120)
- GetKeyboardLayout (Address: 0x1000a108)
- GetWindowThreadProcessId (Address: 0x1000a11c)
- MapVirtualKeyExW (Address: 0x1000a114)
- UnregisterClassA (Address: 0x1000a10c)
- VkKeyScanExW (Address: 0x1000a110)