KeyboardFilterCore.dll
Description: Keyboard Filter Hooks
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.3636
Architecture: 64-bit
Operating System: Windows NT
SHA256: c8941e43af8c5acea1f40e87ff4bdaf2
File Size: 42.4 KB
Uploaded At: Dec. 1, 2025, 7:31 a.m.
Views: 5
Exported Functions
- HookMain (Ordinal: 1, Address: 0x1de0)
Imported DLLs & Functions
ADVAPI32.dll
- GetTraceEnableFlags (Address: 0x180005de0)
- GetTraceEnableLevel (Address: 0x180005de8)
- GetTraceLoggerHandle (Address: 0x180005df0)
- RegCloseKey (Address: 0x180005db8)
- RegCreateKeyExW (Address: 0x180005dc8)
- RegDeleteValueW (Address: 0x180005da0)
- RegEnumValueW (Address: 0x180005da8)
- RegGetValueW (Address: 0x180005df8)
- RegisterTraceGuidsW (Address: 0x180005dd8)
- RegNotifyChangeKeyValue (Address: 0x180005d98)
- RegOpenKeyExW (Address: 0x180005db0)
- RegSetValueExW (Address: 0x180005dc0)
- TraceMessage (Address: 0x180005e00)
- UnregisterTraceGuids (Address: 0x180005dd0)
KERNEL32.dll
- CloseHandle (Address: 0x180005ea0)
- CreateEventW (Address: 0x180005e20)
- CreateThread (Address: 0x180005e30)
- GetCurrentProcess (Address: 0x180005e58)
- GetCurrentProcessId (Address: 0x180005ed0)
- GetCurrentThreadId (Address: 0x180005e70)
- GetLastError (Address: 0x180005eb0)
- GetNativeSystemInfo (Address: 0x180005e50)
- GetSystemTimeAsFileTime (Address: 0x180005e78)
- GetTickCount (Address: 0x180005e80)
- InitOnceExecuteOnce (Address: 0x180005e48)
- IsWow64Process (Address: 0x180005ea8)
- MultiByteToWideChar (Address: 0x180005ec0)
- OpenEventW (Address: 0x180005e40)
- ProcessIdToSessionId (Address: 0x180005ec8)
- QueryPerformanceCounter (Address: 0x180005e68)
- RaiseException (Address: 0x180005e28)
- ResetEvent (Address: 0x180005e18)
- SetEvent (Address: 0x180005e38)
- SetProcessShutdownParameters (Address: 0x180005eb8)
- SetUnhandledExceptionFilter (Address: 0x180005e90)
- Sleep (Address: 0x180005e60)
- TerminateProcess (Address: 0x180005e98)
- UnhandledExceptionFilter (Address: 0x180005e88)
- WaitForMultipleObjects (Address: 0x180005e10)
msvcrt.dll
- __C_specific_handler (Address: 0x180006010)
- _amsg_exit (Address: 0x180006048)
- _callnewh (Address: 0x180006070)
- _initterm (Address: 0x180006058)
- _purecall (Address: 0x180006030)
- _vsnwprintf (Address: 0x180006018)
- _wcsicmp (Address: 0x180006020)
- _XcptFilter (Address: 0x180006008)
- free (Address: 0x180006040)
- iswalpha (Address: 0x180006068)
- malloc (Address: 0x180006038)
- memcpy_s (Address: 0x180006028)
- memset (Address: 0x180006060)
- wcscmp (Address: 0x180006078)
- wcstoul (Address: 0x180006050)
ntdll.dll
- RtlCaptureContext (Address: 0x180006088)
- RtlLookupFunctionEntry (Address: 0x180006090)
- RtlVirtualUnwind (Address: 0x180006098)
RPCRT4.dll
- NdrClientCall3 (Address: 0x180005f20)
- NdrServerCall2 (Address: 0x180005f18)
- NdrServerCallAll (Address: 0x180005f10)
- RpcBindingFree (Address: 0x180005ee0)
- RpcBindingFromStringBindingW (Address: 0x180005f28)
- RpcServerListen (Address: 0x180005ef8)
- RpcServerRegisterIfEx (Address: 0x180005f08)
- RpcServerUnregisterIf (Address: 0x180005ef0)
- RpcServerUseProtseqEpW (Address: 0x180005f00)
- RpcStringBindingComposeW (Address: 0x180005ee8)
- RpcStringFreeW (Address: 0x180005f30)
USER32.dll
- CallNextHookEx (Address: 0x180005f78)
- CloseDesktop (Address: 0x180005fe8)
- CreateWindowExW (Address: 0x180005fd8)
- DefWindowProcW (Address: 0x180005f80)
- DestroyWindow (Address: 0x180005ff8)
- DispatchMessageW (Address: 0x180005ff0)
- GetClassNameW (Address: 0x180005f58)
- GetGUIThreadInfo (Address: 0x180005f68)
- GetKeyboardLayout (Address: 0x180005fc0)
- GetMessageW (Address: 0x180005fe0)
- GetUserObjectInformationW (Address: 0x180005fa8)
- GetWindowThreadProcessId (Address: 0x180005f60)
- MapVirtualKeyExW (Address: 0x180005f50)
- OpenInputDesktop (Address: 0x180005fa0)
- PostMessageW (Address: 0x180005f70)
- PostQuitMessage (Address: 0x180005fb0)
- RegisterClassW (Address: 0x180005fd0)
- SetWindowsHookExW (Address: 0x180005fc8)
- SetWinEventHook (Address: 0x180005f90)
- SystemParametersInfoW (Address: 0x180005f88)
- TranslateMessage (Address: 0x180005f40)
- UnhookWindowsHookEx (Address: 0x180005fb8)
- UnhookWinEvent (Address: 0x180005f98)
- VkKeyScanExW (Address: 0x180005f48)