KeyboardFilterShim.dll

Description: Keyboard Filter AppShim

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.4355

Architecture: 64-bit

Operating System: Windows NT

SHA256: d455c0a6dc8e8d24334b441fd49321d2

File Size: 59.9 KB

Uploaded At: Dec. 1, 2025, 7:31 a.m.

Views: 4

Exported Functions

  • GetHookAPIs (Ordinal: 1, Address: 0x40d0)
  • NotifyShims (Ordinal: 2, Address: 0x4180)

Imported DLLs & Functions

ADVAPI32.dll
  • GetTraceEnableFlags (Address: 0x180009238)
  • GetTraceEnableLevel (Address: 0x180009240)
  • GetTraceLoggerHandle (Address: 0x180009248)
  • RegCloseKey (Address: 0x180009208)
  • RegCreateKeyExW (Address: 0x180009218)
  • RegDeleteValueW (Address: 0x1800091f0)
  • RegEnumValueW (Address: 0x1800091f8)
  • RegGetValueW (Address: 0x180009220)
  • RegisterTraceGuidsW (Address: 0x180009230)
  • RegNotifyChangeKeyValue (Address: 0x1800091e8)
  • RegOpenKeyExW (Address: 0x180009200)
  • RegSetValueExW (Address: 0x180009210)
  • TraceMessage (Address: 0x180009250)
  • UnregisterTraceGuids (Address: 0x180009228)
apphelp.dll
  • SE_GetShimId (Address: 0x180009438)
  • SE_ShimDPF (Address: 0x180009440)
KERNEL32.dll
  • CloseHandle (Address: 0x180009348)
  • CreateMutexExW (Address: 0x180009360)
  • CreateSemaphoreExW (Address: 0x1800092a0)
  • DebugBreak (Address: 0x180009380)
  • DeleteCriticalSection (Address: 0x1800092f8)
  • EnterCriticalSection (Address: 0x1800092f0)
  • FindResourceExW (Address: 0x180009320)
  • FormatMessageW (Address: 0x180009268)
  • GetCurrentProcess (Address: 0x1800092c8)
  • GetCurrentProcessId (Address: 0x180009368)
  • GetCurrentThreadId (Address: 0x180009278)
  • GetLastError (Address: 0x180009260)
  • GetModuleFileNameA (Address: 0x1800093b0)
  • GetModuleHandleExW (Address: 0x180009280)
  • GetModuleHandleW (Address: 0x180009378)
  • GetProcAddress (Address: 0x180009358)
  • GetProcessHeap (Address: 0x180009370)
  • GetSystemTimeAsFileTime (Address: 0x1800092b0)
  • GetTickCount (Address: 0x1800092a8)
  • HeapAlloc (Address: 0x180009350)
  • HeapDestroy (Address: 0x180009308)
  • HeapFree (Address: 0x180009298)
  • HeapReAlloc (Address: 0x1800093a0)
  • HeapSize (Address: 0x180009318)
  • InitializeCriticalSection (Address: 0x180009300)
  • InitOnceExecuteOnce (Address: 0x180009390)
  • IsDebuggerPresent (Address: 0x180009388)
  • LeaveCriticalSection (Address: 0x1800092e8)
  • LoadResource (Address: 0x180009328)
  • LockResource (Address: 0x180009330)
  • OpenSemaphoreW (Address: 0x180009340)
  • OutputDebugStringW (Address: 0x180009310)
  • QueryPerformanceCounter (Address: 0x1800092b8)
  • RaiseException (Address: 0x180009398)
  • ReleaseMutex (Address: 0x180009270)
  • ReleaseSemaphore (Address: 0x180009288)
  • SetLastError (Address: 0x180009290)
  • SetUnhandledExceptionFilter (Address: 0x1800092d0)
  • SizeofResource (Address: 0x1800093b8)
  • Sleep (Address: 0x1800092e0)
  • TerminateProcess (Address: 0x1800092c0)
  • UnhandledExceptionFilter (Address: 0x1800092d8)
  • WaitForSingleObject (Address: 0x1800093a8)
  • WaitForSingleObjectEx (Address: 0x180009338)
msvcrt.dll
  • __C_specific_handler (Address: 0x180009480)
  • __dllonexit (Address: 0x1800094c8)
  • _amsg_exit (Address: 0x1800094e8)
  • _initterm (Address: 0x1800094e0)
  • _lock (Address: 0x1800094d8)
  • _onexit (Address: 0x1800094c0)
  • _purecall (Address: 0x180009488)
  • _unlock (Address: 0x1800094d0)
  • _vsnwprintf (Address: 0x180009460)
  • _wcsicmp (Address: 0x180009470)
  • _wcsnicmp (Address: 0x1800094b0)
  • _XcptFilter (Address: 0x1800094f0)
  • free (Address: 0x180009498)
  • iswalpha (Address: 0x1800094b8)
  • iswspace (Address: 0x1800094a0)
  • malloc (Address: 0x180009490)
  • memcpy (Address: 0x180009450)
  • memcpy_s (Address: 0x180009468)
  • memmove (Address: 0x180009458)
  • memmove_s (Address: 0x1800094a8)
  • memset (Address: 0x1800094f8)
  • toupper (Address: 0x180009478)
ntdll.dll
  • RtlAllocateHeap (Address: 0x180009508)
  • RtlCaptureContext (Address: 0x180009518)
  • RtlFreeHeap (Address: 0x180009510)
  • RtlLookupFunctionEntry (Address: 0x180009520)
  • RtlVirtualUnwind (Address: 0x180009528)
RPCRT4.dll
  • NdrClientCall3 (Address: 0x1800093d0)
  • RpcBindingFree (Address: 0x1800093e8)
  • RpcBindingFromStringBindingW (Address: 0x1800093d8)
  • RpcStringBindingComposeW (Address: 0x1800093c8)
  • RpcStringFreeW (Address: 0x1800093e0)
USER32.dll
  • GetClassNameW (Address: 0x180009418)
  • GetGUIThreadInfo (Address: 0x180009428)
  • GetKeyboardLayout (Address: 0x1800093f8)
  • GetWindowThreadProcessId (Address: 0x180009420)
  • MapVirtualKeyExW (Address: 0x180009410)
  • UnregisterClassA (Address: 0x180009400)
  • VkKeyScanExW (Address: 0x180009408)