KeyboardFilterWmi.dll
Description: Keyboard Filter WMI Provider
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.4355
Architecture: 64-bit
Operating System: Windows NT
SHA256: ee2f6f89925670ccbeea9734dbfc309b
File Size: 74.0 KB
Uploaded At: Dec. 1, 2025, 8:12 a.m.
Views: 13
Exported Functions
- BlockAdminKeyboard (Ordinal: 1, Address: 0x37f0)
- BlockPredefinedKey (Ordinal: 2, Address: 0x2630)
- DllCanUnloadNow (Ordinal: 3, Address: 0x14c0)
- DllGetClassObject (Ordinal: 4, Address: 0x1500)
- DllMain (Ordinal: 5, Address: 0x11c0)
- DllRegisterServer (Ordinal: 6, Address: 0x1420)
- DllUnregisterServer (Ordinal: 7, Address: 0x1470)
- GetProviderClassID (Ordinal: 8, Address: 0x1220)
- IsAdminUnblocked (Ordinal: 9, Address: 0x3820)
- IsPredefinedKeyBlocked (Ordinal: 10, Address: 0x2650)
- KBF_DisableService (Ordinal: 11, Address: 0x5590)
- KBF_EnableService (Ordinal: 12, Address: 0x5490)
- KBF_QueryService (Ordinal: 13, Address: 0x5690)
- MI_Main (Ordinal: 14, Address: 0x15f0)
Imported DLLs & Functions
ADVAPI32.dll
- RegCloseKey (Address: 0x18000bcb8)
- RegCreateKeyExW (Address: 0x18000bc98)
- RegDeleteValueW (Address: 0x18000bcb0)
- RegEnumValueW (Address: 0x18000bc90)
- RegGetValueW (Address: 0x18000bca0)
- RegNotifyChangeKeyValue (Address: 0x18000bc88)
- RegOpenKeyExW (Address: 0x18000bcc0)
- RegQueryValueExW (Address: 0x18000bcc8)
- RegSetValueExW (Address: 0x18000bca8)
api-ms-win-core-winrt-l1-1-0.dll
- RoActivateInstance (Address: 0x18000be80)
api-ms-win-core-winrt-string-l1-1-0.dll
- WindowsCreateStringReference (Address: 0x18000be90)
KERNEL32.dll
- CloseHandle (Address: 0x18000be00)
- CreateMutexExW (Address: 0x18000be18)
- CreateSemaphoreExW (Address: 0x18000bda0)
- DebugBreak (Address: 0x18000be38)
- DeleteCriticalSection (Address: 0x18000bce0)
- DisableThreadLibraryCalls (Address: 0x18000bd78)
- EnterCriticalSection (Address: 0x18000bcd8)
- FindResourceExW (Address: 0x18000be60)
- FormatMessageW (Address: 0x18000bde0)
- FreeLibrary (Address: 0x18000bd88)
- GetCurrentProcess (Address: 0x18000bd30)
- GetCurrentProcessId (Address: 0x18000be20)
- GetCurrentThreadId (Address: 0x18000bdd0)
- GetLastError (Address: 0x18000bd70)
- GetModuleFileNameA (Address: 0x18000bd98)
- GetModuleHandleExW (Address: 0x18000bdc0)
- GetModuleHandleW (Address: 0x18000be30)
- GetProcAddress (Address: 0x18000bd80)
- GetProcessHeap (Address: 0x18000be28)
- GetSystemDirectoryW (Address: 0x18000bd68)
- GetSystemTimeAsFileTime (Address: 0x18000bd48)
- GetTickCount (Address: 0x18000bd50)
- HeapAlloc (Address: 0x18000be10)
- HeapDestroy (Address: 0x18000bcf0)
- HeapFree (Address: 0x18000bda8)
- HeapReAlloc (Address: 0x18000bcf8)
- HeapSize (Address: 0x18000bdd8)
- InitializeCriticalSection (Address: 0x18000bce8)
- IsDebuggerPresent (Address: 0x18000be40)
- LeaveCriticalSection (Address: 0x18000bd58)
- LoadLibraryExW (Address: 0x18000bd90)
- LoadResource (Address: 0x18000be58)
- LockResource (Address: 0x18000be50)
- OpenSemaphoreW (Address: 0x18000bdf8)
- OutputDebugStringW (Address: 0x18000bde8)
- QueryPerformanceCounter (Address: 0x18000bd40)
- RaiseException (Address: 0x18000be08)
- ReleaseMutex (Address: 0x18000bd60)
- ReleaseSemaphore (Address: 0x18000bdb8)
- RtlCaptureContext (Address: 0x18000bd08)
- RtlLookupFunctionEntry (Address: 0x18000bd10)
- RtlVirtualUnwind (Address: 0x18000bd18)
- SetLastError (Address: 0x18000bdb0)
- SetUnhandledExceptionFilter (Address: 0x18000bd28)
- SizeofResource (Address: 0x18000be48)
- Sleep (Address: 0x18000bd00)
- TerminateProcess (Address: 0x18000bd38)
- UnhandledExceptionFilter (Address: 0x18000bd20)
- WaitForSingleObject (Address: 0x18000bdc8)
- WaitForSingleObjectEx (Address: 0x18000bdf0)
msvcrt.dll
- __C_specific_handler (Address: 0x18000bee8)
- __dllonexit (Address: 0x18000bf30)
- _amsg_exit (Address: 0x18000bf10)
- _initterm (Address: 0x18000bf18)
- _lock (Address: 0x18000bf20)
- _ltow_s (Address: 0x18000bf40)
- _onexit (Address: 0x18000bf38)
- _purecall (Address: 0x18000bec0)
- _unlock (Address: 0x18000bf28)
- _vscwprintf (Address: 0x18000bea8)
- _vsnwprintf (Address: 0x18000bee0)
- _wcsicmp (Address: 0x18000bef8)
- _wcsnicmp (Address: 0x18000bec8)
- _wtoi (Address: 0x18000bef0)
- _XcptFilter (Address: 0x18000bf08)
- free (Address: 0x18000bf50)
- iswspace (Address: 0x18000bed0)
- malloc (Address: 0x18000bf00)
- memcpy_s (Address: 0x18000bed8)
- memmove_s (Address: 0x18000bf48)
- memset (Address: 0x18000bf60)
- swprintf_s (Address: 0x18000bf58)
- vswprintf_s (Address: 0x18000bea0)
- wcsrchr (Address: 0x18000beb8)
- wcstoul (Address: 0x18000beb0)
USER32.dll
- UnregisterClassA (Address: 0x18000be70)