ChsEM.dll
Description: Microsoft IME
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.6456
Architecture: 64-bit
Operating System: Windows NT
SHA256: 691c33b5999085c359e335673687c289
File Size: 1.1 MB
Uploaded At: Dec. 1, 2025, 7:50 a.m.
Views: 6
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- DestroyMtf (Ordinal: 1, Address: 0x114f0)
- DllCanUnloadNow (Ordinal: 2, Address: 0xe180)
- DllGetClassObject (Ordinal: 3, Address: 0xe0a0)
- DllRegisterServer (Ordinal: 4, Address: 0xe4b0)
- DllUnregisterServer (Ordinal: 5, Address: 0xe4c0)
- SetupMtf (Ordinal: 6, Address: 0x114b0)
Imported DLLs & Functions
api-ms-win-core-apiquery-l1-1-0.dll
- ApiSetQueryApiSetPresence (Address: 0x150648b28)
api-ms-win-core-com-l1-1-0.dll
- CoCreateFreeThreadedMarshaler (Address: 0x150648b38)
- CoCreateInstance (Address: 0x150648b78)
- CoGetApartmentType (Address: 0x150648b50)
- CoGetMalloc (Address: 0x150648b88)
- CoInitializeEx (Address: 0x150648b48)
- CoTaskMemAlloc (Address: 0x150648b68)
- CoTaskMemFree (Address: 0x150648b60)
- CoTaskMemRealloc (Address: 0x150648b70)
- CoUninitialize (Address: 0x150648b80)
- CoWaitForMultipleHandles (Address: 0x150648b40)
- StringFromGUID2 (Address: 0x150648b58)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x150648b98)
- IsDebuggerPresent (Address: 0x150648ba8)
- OutputDebugStringW (Address: 0x150648ba0)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x150648bb8)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x150648bc8)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x150648bf0)
- RaiseException (Address: 0x150648be8)
- SetLastError (Address: 0x150648be0)
- SetUnhandledExceptionFilter (Address: 0x150648bd8)
- UnhandledExceptionFilter (Address: 0x150648bf8)
api-ms-win-core-errorhandling-l1-1-2.dll
- RaiseFailFastException (Address: 0x150648c08)
api-ms-win-core-file-l1-1-0.dll
- CreateDirectoryW (Address: 0x150648c18)
- CreateFileW (Address: 0x150648c30)
- DeleteFileW (Address: 0x150648c20)
- FindClose (Address: 0x150648c40)
- FindFirstFileW (Address: 0x150648c28)
- FindNextFileW (Address: 0x150648c38)
- GetFileAttributesW (Address: 0x150648c58)
- GetFullPathNameW (Address: 0x150648c50)
- WriteFile (Address: 0x150648c48)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x150648c68)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x150648c88)
- HeapAlloc (Address: 0x150648ca0)
- HeapDestroy (Address: 0x150648c80)
- HeapFree (Address: 0x150648c98)
- HeapReAlloc (Address: 0x150648c90)
- HeapSize (Address: 0x150648c78)
api-ms-win-core-heap-l2-1-0.dll
- GlobalAlloc (Address: 0x150648cc0)
- LocalAlloc (Address: 0x150648cb0)
- LocalFree (Address: 0x150648cb8)
api-ms-win-core-heap-obsolete-l1-1-0.dll
- GlobalLock (Address: 0x150648cd8)
- GlobalUnlock (Address: 0x150648cd0)
api-ms-win-core-kernel32-legacy-l1-1-1.dll
- VerifyVersionInfoW (Address: 0x150648ce8)
api-ms-win-core-libraryloader-l1-2-0.dll
- GetModuleFileNameA (Address: 0x150648d18)
- GetModuleFileNameW (Address: 0x150648d00)
- GetModuleHandleExW (Address: 0x150648d20)
- GetModuleHandleW (Address: 0x150648d10)
- GetProcAddress (Address: 0x150648cf8)
- LoadStringW (Address: 0x150648d08)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x150648d30)
api-ms-win-core-privateprofile-l1-1-0.dll
- GetPrivateProfileStringA (Address: 0x150648d40)
- GetPrivateProfileStringW (Address: 0x150648d48)
api-ms-win-core-processthreads-l1-1-0.dll
- CreateThread (Address: 0x150648d88)
- GetCurrentProcess (Address: 0x150648d60)
- GetCurrentProcessId (Address: 0x150648d80)
- GetCurrentThreadId (Address: 0x150648d70)
- OpenProcessToken (Address: 0x150648d58)
- ResumeThread (Address: 0x150648d78)
- TerminateProcess (Address: 0x150648d68)
api-ms-win-core-processthreads-l1-1-1.dll
- OpenProcess (Address: 0x150648d98)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x150648da8)
api-ms-win-core-psapi-l1-1-0.dll
- K32GetModuleBaseNameW (Address: 0x150648db8)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x150648dd0)
- RegCreateKeyExW (Address: 0x150648e00)
- RegDeleteTreeW (Address: 0x150648e10)
- RegDeleteValueW (Address: 0x150648de0)
- RegEnumValueW (Address: 0x150648df0)
- RegGetValueW (Address: 0x150648de8)
- RegOpenCurrentUser (Address: 0x150648dc8)
- RegOpenKeyExW (Address: 0x150648df8)
- RegQueryValueExW (Address: 0x150648e08)
- RegSetValueExW (Address: 0x150648dd8)
api-ms-win-core-registry-l1-1-1.dll
- RegSetKeyValueW (Address: 0x150648e20)
api-ms-win-core-rtlsupport-l1-1-0.dll
- RtlCaptureContext (Address: 0x150648e30)
- RtlLookupFunctionEntry (Address: 0x150648e38)
- RtlVirtualUnwind (Address: 0x150648e40)
api-ms-win-core-shlwapi-legacy-l1-1-0.dll
- PathFileExistsW (Address: 0x150648e58)
- PathFindExtensionW (Address: 0x150648e50)
api-ms-win-core-sidebyside-l1-1-0.dll
- ActivateActCtx (Address: 0x150648e68)
- CreateActCtxW (Address: 0x150648e70)
- DeactivateActCtx (Address: 0x150648e78)
api-ms-win-core-string-l1-1-0.dll
- CompareStringOrdinal (Address: 0x150648ea0)
- GetStringTypeW (Address: 0x150648e98)
- MultiByteToWideChar (Address: 0x150648e88)
- WideCharToMultiByte (Address: 0x150648e90)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x150648f38)
- AcquireSRWLockShared (Address: 0x150648f28)
- CreateEventExW (Address: 0x150648ef8)
- CreateEventW (Address: 0x150648ee0)
- CreateMutexExW (Address: 0x150648f08)
- CreateSemaphoreExW (Address: 0x150648f00)
- DeleteCriticalSection (Address: 0x150648f20)
- EnterCriticalSection (Address: 0x150648f40)
- InitializeCriticalSection (Address: 0x150648f10)
- InitializeCriticalSectionEx (Address: 0x150648f50)
- InitializeSRWLock (Address: 0x150648f18)
- LeaveCriticalSection (Address: 0x150648f48)
- OpenSemaphoreW (Address: 0x150648eb0)
- ReleaseMutex (Address: 0x150648ed8)
- ReleaseSemaphore (Address: 0x150648ef0)
- ReleaseSRWLockExclusive (Address: 0x150648f58)
- ReleaseSRWLockShared (Address: 0x150648f30)
- ResetEvent (Address: 0x150648ed0)
- SetEvent (Address: 0x150648ec8)
- WaitForMultipleObjectsEx (Address: 0x150648ec0)
- WaitForSingleObject (Address: 0x150648ee8)
- WaitForSingleObjectEx (Address: 0x150648eb8)
api-ms-win-core-synch-l1-2-0.dll
- InitOnceBeginInitialize (Address: 0x150648f80)
- InitOnceComplete (Address: 0x150648f90)
- InitOnceExecuteOnce (Address: 0x150648f88)
- Sleep (Address: 0x150648f78)
- SleepConditionVariableSRW (Address: 0x150648f70)
- WakeAllConditionVariable (Address: 0x150648f68)
api-ms-win-core-synch-l1-2-1.dll
- WaitForMultipleObjects (Address: 0x150648fa0)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemTime (Address: 0x150648fc0)
- GetSystemTimeAsFileTime (Address: 0x150648fd0)
- GetTickCount (Address: 0x150648fb8)
- GetTickCount64 (Address: 0x150648fc8)
- GetWindowsDirectoryW (Address: 0x150648fb0)
api-ms-win-core-sysinfo-l1-2-0.dll
- VerSetConditionMask (Address: 0x150648fe0)
api-ms-win-core-threadpool-l1-2-0.dll
- CloseThreadpoolTimer (Address: 0x150649008)
- CreateThreadpoolTimer (Address: 0x150648ff0)
- SetThreadpoolTimer (Address: 0x150648ff8)
- WaitForThreadpoolTimerCallbacks (Address: 0x150649000)
api-ms-win-core-timezone-l1-1-0.dll
- SystemTimeToFileTime (Address: 0x150649018)
api-ms-win-core-url-l1-1-0.dll
- PathIsURLW (Address: 0x150649028)
api-ms-win-core-util-l1-1-0.dll
- Beep (Address: 0x150649048)
- DecodePointer (Address: 0x150649038)
- EncodePointer (Address: 0x150649040)
api-ms-win-core-winrt-error-l1-1-0.dll
- GetRestrictedErrorInfo (Address: 0x150649068)
- RoOriginateError (Address: 0x150649058)
- RoOriginateErrorW (Address: 0x150649060)
- RoTransformError (Address: 0x150649070)
- SetRestrictedErrorInfo (Address: 0x150649078)
api-ms-win-core-winrt-error-l1-1-1.dll
- IsErrorPropagationEnabled (Address: 0x150649090)
- RoGetMatchingRestrictedErrorInfo (Address: 0x150649088)
- RoReportFailedDelegate (Address: 0x150649098)
api-ms-win-core-winrt-l1-1-0.dll
- RoGetActivationFactory (Address: 0x1506490a8)
api-ms-win-core-winrt-string-l1-1-0.dll
- WindowsCreateString (Address: 0x1506490b8)
- WindowsCreateStringReference (Address: 0x1506490c8)
- WindowsGetStringRawBuffer (Address: 0x1506490c0)
api-ms-win-eventing-provider-l1-1-0.dll
- EventActivityIdControl (Address: 0x1506490f0)
- EventRegister (Address: 0x1506490e0)
- EventSetInformation (Address: 0x1506490d8)
- EventUnregister (Address: 0x1506490f8)
- EventWriteTransfer (Address: 0x1506490e8)
api-ms-win-security-base-l1-1-0.dll
- CopySid (Address: 0x150649118)
- EqualSid (Address: 0x150649138)
- GetLengthSid (Address: 0x150649108)
- GetSidLengthRequired (Address: 0x150649130)
- GetSidSubAuthority (Address: 0x150649120)
- GetTokenInformation (Address: 0x150649128)
- InitializeSid (Address: 0x150649140)
- IsValidSid (Address: 0x150649110)
api-ms-win-security-cryptoapi-l1-1-0.dll
- CryptAcquireContextW (Address: 0x150649168)
- CryptCreateHash (Address: 0x150649170)
- CryptDecrypt (Address: 0x150649180)
- CryptDeriveKey (Address: 0x150649190)
- CryptDestroyHash (Address: 0x1506491a0)
- CryptDestroyKey (Address: 0x150649160)
- CryptEncrypt (Address: 0x150649188)
- CryptGetHashParam (Address: 0x150649150)
- CryptHashData (Address: 0x150649178)
- CryptReleaseContext (Address: 0x150649158)
- CryptSetKeyParam (Address: 0x150649198)
api-ms-win-security-sddl-l1-1-0.dll
- ConvertSidToStringSidW (Address: 0x1506491b0)
CoreMessaging.dll
- CoreUICreate (Address: 0x150648a70)
msvcrt.dll
- ___lc_codepage_func (Address: 0x150649330)
- ___lc_handle_func (Address: 0x150649328)
- ___mb_cur_max_func (Address: 0x150649308)
- __C_specific_handler (Address: 0x1506493b8)
- __crtLCMapStringW (Address: 0x150649310)
- __CxxFrameHandler3 (Address: 0x1506493e0)
- __dllonexit (Address: 0x150649358)
- __pctype_func (Address: 0x150649340)
- __uncaught_exception (Address: 0x1506492e8)
- _amsg_exit (Address: 0x1506493d8)
- _callnewh (Address: 0x1506492c0)
- _CxxThrowException (Address: 0x1506492d0)
- _errno (Address: 0x150649300)
- _initterm (Address: 0x1506493c0)
- _ismbblead (Address: 0x150649338)
- _lock (Address: 0x150649398)
- _onexit (Address: 0x150649350)
- _purecall (Address: 0x150649410)
- _ultow_s (Address: 0x150649288)
- _unlock (Address: 0x150649360)
- _vsnprintf_s (Address: 0x1506493f0)
- _vsnwprintf (Address: 0x150649420)
- _wcsdup (Address: 0x1506493a8)
- _wcsicmp (Address: 0x1506492b8)
- _wcsnicmp (Address: 0x1506491c0)
- _wsetlocale (Address: 0x150649220)
- _wtoi (Address: 0x150649200)
- _XcptFilter (Address: 0x1506493e8)
- ??_V@YAXPEAX@Z (Address: 0x150649368)
- ??0bad_cast@@QEAA@AEBV0@@Z (Address: 0x150649238)
- ??0bad_cast@@QEAA@PEBD@Z (Address: 0x150649228)
- ??0exception@@QEAA@AEBQEBD@Z (Address: 0x150649250)
- ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x1506492c8)
- ??0exception@@QEAA@AEBV0@@Z (Address: 0x1506493f8)
- ??0exception@@QEAA@XZ (Address: 0x150649400)
- ??1bad_cast@@UEAA@XZ (Address: 0x150649230)
- ??1exception@@UEAA@XZ (Address: 0x150649408)
- ??1type_info@@UEAA@XZ (Address: 0x150649348)
- ??3@YAXPEAX@Z (Address: 0x150649428)
- ?terminate@@YAXXZ (Address: 0x1506493a0)
- ?what@exception@@UEBAPEBDXZ (Address: 0x150649278)
- abort (Address: 0x150649380)
- calloc (Address: 0x1506492a8)
- free (Address: 0x1506493d0)
- isalnum (Address: 0x150649320)
- isdigit (Address: 0x1506492f8)
- isspace (Address: 0x150649370)
- iswalnum (Address: 0x1506491f8)
- iswalpha (Address: 0x1506492a0)
- iswgraph (Address: 0x150649290)
- iswprint (Address: 0x150649208)
- iswpunct (Address: 0x150649430)
- iswspace (Address: 0x1506491f0)
- iswupper (Address: 0x1506491e8)
- ldexp (Address: 0x150649268)
- localeconv (Address: 0x150649218)
- malloc (Address: 0x1506493c8)
- memchr (Address: 0x150649378)
- memcmp (Address: 0x1506493b0)
- memcpy (Address: 0x1506492d8)
- memcpy_s (Address: 0x150649418)
- memmove (Address: 0x1506492e0)
- memmove_s (Address: 0x150649318)
- memset (Address: 0x150649390)
- qsort (Address: 0x150649248)
- qsort_s (Address: 0x150649260)
- setlocale (Address: 0x1506492f0)
- sprintf_s (Address: 0x150649240)
- strcspn (Address: 0x150649210)
- swprintf_s (Address: 0x150649298)
- swscanf_s (Address: 0x1506491d0)
- time (Address: 0x1506492b0)
- tolower (Address: 0x1506491e0)
- toupper (Address: 0x1506491c8)
- towlower (Address: 0x150649388)
- wcscat_s (Address: 0x150649258)
- wcscmp (Address: 0x150649438)
- wcscpy_s (Address: 0x1506491d8)
- wcstod (Address: 0x150649280)
- wcstok_s (Address: 0x150649270)
OLEAUT32.dll
- SysAllocString (Address: 0x150648a90)
- SysAllocStringLen (Address: 0x150648a80)
- SysFreeString (Address: 0x150648ab0)
- SysStringByteLen (Address: 0x150648a98)
- SysStringLen (Address: 0x150648aa8)
- VariantClear (Address: 0x150648a88)
- VariantInit (Address: 0x150648aa0)
USER32.dll
- CloseClipboard (Address: 0x150648ad0)
- EmptyClipboard (Address: 0x150648af8)
- EnumChildWindows (Address: 0x150648ad8)
- EnumThreadWindows (Address: 0x150648af0)
- GetForegroundWindow (Address: 0x150648ae0)
- GetWindowThreadProcessId (Address: 0x150648b10)
- IsWindow (Address: 0x150648ae8)
- OpenClipboard (Address: 0x150648ac8)
- RegisterClipboardFormatW (Address: 0x150648ac0)
- SendInput (Address: 0x150648b00)
- SetClipboardData (Address: 0x150648b08)
- SystemParametersInfoW (Address: 0x150648b18)