ChxEM.DLL
Description: Microsoft IME
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.5794
Architecture: 64-bit
Operating System: Windows NT
SHA256: 6dfb50883b4822554dacd167523e3b6c
File Size: 759.0 KB
Uploaded At: Dec. 1, 2025, 7:50 a.m.
Views: 6
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- DestroyMtf (Ordinal: 1, Address: 0x5e00)
- DllCanUnloadNow (Ordinal: 2, Address: 0x2b70)
- DllGetClassObject (Ordinal: 3, Address: 0x2a80)
- DllRegisterServer (Ordinal: 4, Address: 0x2fa0)
- DllUnregisterServer (Ordinal: 5, Address: 0x2fe0)
- SetupMtf (Ordinal: 6, Address: 0x5dc0)
Imported DLLs & Functions
ADVAPI32.dll
- ConvertSidToStringSidW (Address: 0x180091ef0)
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x180091ee8)
- EventActivityIdControl (Address: 0x180091f30)
- EventRegister (Address: 0x180091f48)
- EventSetInformation (Address: 0x180091f50)
- EventUnregister (Address: 0x180091f58)
- EventWriteTransfer (Address: 0x180091f40)
- GetTokenInformation (Address: 0x180091ee0)
- IsValidSid (Address: 0x180091ef8)
- OpenProcessToken (Address: 0x180091f00)
- RegCloseKey (Address: 0x180091f60)
- RegCreateKeyExW (Address: 0x180091f68)
- RegDeleteTreeW (Address: 0x180091f70)
- RegEnumValueW (Address: 0x180091f38)
- RegGetValueW (Address: 0x180091f28)
- RegOpenCurrentUser (Address: 0x180091f18)
- RegOpenKeyExW (Address: 0x180091f20)
- RegQueryValueExW (Address: 0x180091f10)
- RegSetKeyValueW (Address: 0x180091f08)
- RegSetValueExW (Address: 0x180091f78)
api-ms-win-core-apiquery-l1-1-0.dll
- ApiSetQueryApiSetPresence (Address: 0x180092358)
api-ms-win-core-com-l1-1-0.dll
- CoCreateInstance (Address: 0x180092368)
- CoGetMalloc (Address: 0x180092388)
- CoInitializeEx (Address: 0x180092370)
- CoTaskMemAlloc (Address: 0x1800923a8)
- CoTaskMemFree (Address: 0x180092390)
- CoTaskMemRealloc (Address: 0x1800923a0)
- CoUninitialize (Address: 0x180092398)
- CoWaitForMultipleHandles (Address: 0x180092380)
- StringFromGUID2 (Address: 0x180092378)
api-ms-win-core-winrt-error-l1-1-0.dll
- RoTransformError (Address: 0x1800923b8)
- SetRestrictedErrorInfo (Address: 0x1800923c0)
api-ms-win-core-winrt-error-l1-1-1.dll
- IsErrorPropagationEnabled (Address: 0x1800923d0)
- RoGetMatchingRestrictedErrorInfo (Address: 0x1800923e0)
- RoReportFailedDelegate (Address: 0x1800923d8)
api-ms-win-core-winrt-l1-1-0.dll
- RoGetActivationFactory (Address: 0x1800923f0)
api-ms-win-core-winrt-string-l1-1-0.dll
- WindowsCreateStringReference (Address: 0x180092400)
CoreMessaging.dll
- CoreUICreate (Address: 0x180091f88)
KERNEL32.dll
- AcquireSRWLockExclusive (Address: 0x180092128)
- AcquireSRWLockShared (Address: 0x180092178)
- ActivateActCtx (Address: 0x180091fe8)
- Beep (Address: 0x180092160)
- CloseHandle (Address: 0x180092070)
- CloseThreadpoolTimer (Address: 0x1800921c0)
- CreateActCtxW (Address: 0x180091fe0)
- CreateEventExW (Address: 0x180092148)
- CreateFileMappingW (Address: 0x180092248)
- CreateFileW (Address: 0x180092208)
- CreateMutexExW (Address: 0x180092088)
- CreateSemaphoreExW (Address: 0x180091ff8)
- CreateThreadpoolTimer (Address: 0x180092168)
- DeactivateActCtx (Address: 0x180092040)
- DebugBreak (Address: 0x1800920a8)
- DecodePointer (Address: 0x180091fb0)
- DelayLoadFailureHook (Address: 0x180091f98)
- DeleteCriticalSection (Address: 0x180092198)
- EncodePointer (Address: 0x180091fa8)
- EnterCriticalSection (Address: 0x180092190)
- FormatMessageW (Address: 0x180092048)
- GetCurrentProcess (Address: 0x1800920f0)
- GetCurrentProcessId (Address: 0x180092090)
- GetCurrentThreadId (Address: 0x180092030)
- GetFileSize (Address: 0x180092240)
- GetFullPathNameW (Address: 0x180092010)
- GetLastError (Address: 0x180091fd0)
- GetModuleFileNameA (Address: 0x180091fd8)
- GetModuleFileNameW (Address: 0x180091fc8)
- GetModuleHandleExW (Address: 0x180092020)
- GetModuleHandleW (Address: 0x1800920a0)
- GetProcAddress (Address: 0x180092080)
- GetProcessHeap (Address: 0x180092098)
- GetStringTypeW (Address: 0x180091fa0)
- GetSystemTime (Address: 0x180092130)
- GetSystemTimeAsFileTime (Address: 0x180092100)
- GetSystemWindowsDirectoryW (Address: 0x180092220)
- GetTickCount (Address: 0x180092108)
- GetTickCount64 (Address: 0x180092110)
- GetWindowsDirectoryW (Address: 0x180092158)
- HeapAlloc (Address: 0x180092078)
- HeapFree (Address: 0x180092000)
- HeapReAlloc (Address: 0x180092210)
- InitializeCriticalSection (Address: 0x180092218)
- InitializeCriticalSectionEx (Address: 0x1800921a0)
- InitializeSRWLock (Address: 0x180092118)
- InitOnceBeginInitialize (Address: 0x180091ff0)
- InitOnceComplete (Address: 0x180092058)
- IsDebuggerPresent (Address: 0x1800920b8)
- K32GetModuleBaseNameW (Address: 0x1800921d0)
- LeaveCriticalSection (Address: 0x180092188)
- LocalAlloc (Address: 0x1800921d8)
- LocalFree (Address: 0x1800921e0)
- MapViewOfFile (Address: 0x180092250)
- MulDiv (Address: 0x1800921f8)
- MultiByteToWideChar (Address: 0x1800921e8)
- OpenFileMappingW (Address: 0x180092230)
- OpenProcess (Address: 0x1800921c8)
- OpenSemaphoreW (Address: 0x180092068)
- OutputDebugStringW (Address: 0x180092050)
- PrefetchVirtualMemory (Address: 0x180092228)
- QueryPerformanceCounter (Address: 0x1800920f8)
- RaiseException (Address: 0x1800921a8)
- ReleaseActCtx (Address: 0x1800920b0)
- ReleaseMutex (Address: 0x180092038)
- ReleaseSemaphore (Address: 0x180092018)
- ReleaseSRWLockExclusive (Address: 0x180092120)
- ReleaseSRWLockShared (Address: 0x180092180)
- ResetEvent (Address: 0x180092150)
- ResolveDelayLoadedAPI (Address: 0x180091fc0)
- RtlCaptureContext (Address: 0x1800920c8)
- RtlLookupFunctionEntry (Address: 0x1800920d0)
- RtlVirtualUnwind (Address: 0x1800920d8)
- SetEvent (Address: 0x180092140)
- SetLastError (Address: 0x180092008)
- SetThreadpoolTimer (Address: 0x180092170)
- SetUnhandledExceptionFilter (Address: 0x1800920e8)
- Sleep (Address: 0x1800920c0)
- SleepConditionVariableSRW (Address: 0x180092200)
- SystemTimeToFileTime (Address: 0x180092138)
- TerminateProcess (Address: 0x180092258)
- UnhandledExceptionFilter (Address: 0x1800920e0)
- UnmapViewOfFile (Address: 0x180092238)
- VerifyVersionInfoW (Address: 0x1800921b0)
- VerSetConditionMask (Address: 0x180092260)
- WaitForSingleObject (Address: 0x180092028)
- WaitForSingleObjectEx (Address: 0x180092060)
- WaitForThreadpoolTimerCallbacks (Address: 0x1800921b8)
- WakeAllConditionVariable (Address: 0x180091fb8)
- WideCharToMultiByte (Address: 0x1800921f0)
msvcrt.dll
- ___lc_codepage_func (Address: 0x1800924b0)
- ___lc_handle_func (Address: 0x1800924a8)
- ___mb_cur_max_func (Address: 0x1800924a0)
- __C_specific_handler (Address: 0x1800925b8)
- __crtLCMapStringW (Address: 0x1800924e0)
- __CxxFrameHandler3 (Address: 0x180092560)
- __dllonexit (Address: 0x1800925f8)
- __pctype_func (Address: 0x1800924c0)
- __uncaught_exception (Address: 0x180092488)
- _amsg_exit (Address: 0x180092598)
- _callnewh (Address: 0x180092460)
- _CxxThrowException (Address: 0x180092470)
- _errno (Address: 0x180092498)
- _initterm (Address: 0x1800925b0)
- _ismbblead (Address: 0x1800924b8)
- _lock (Address: 0x1800925d0)
- _onexit (Address: 0x180092600)
- _purecall (Address: 0x180092568)
- _ultow_s (Address: 0x1800925e0)
- _unlock (Address: 0x1800925d8)
- _vsnprintf_s (Address: 0x180092588)
- _vsnwprintf (Address: 0x180092550)
- _wcsdup (Address: 0x1800924d8)
- _wcsicmp (Address: 0x180092500)
- _wsetlocale (Address: 0x1800924e8)
- _wtoi (Address: 0x180092508)
- _XcptFilter (Address: 0x180092590)
- ??_V@YAXPEAX@Z (Address: 0x1800925f0)
- ??0bad_cast@@QEAA@AEBV0@@Z (Address: 0x180092530)
- ??0bad_cast@@QEAA@PEBD@Z (Address: 0x1800924f0)
- ??0exception@@QEAA@AEBQEBD@Z (Address: 0x180092540)
- ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x180092468)
- ??0exception@@QEAA@AEBV0@@Z (Address: 0x180092580)
- ??0exception@@QEAA@XZ (Address: 0x180092578)
- ??1bad_cast@@UEAA@XZ (Address: 0x180092528)
- ??1exception@@UEAA@XZ (Address: 0x180092570)
- ??1type_info@@UEAA@XZ (Address: 0x180092610)
- ??3@YAXPEAX@Z (Address: 0x1800925c0)
- ?terminate@@YAXXZ (Address: 0x1800925c8)
- ?what@exception@@UEBAPEBDXZ (Address: 0x180092548)
- abort (Address: 0x1800924c8)
- calloc (Address: 0x180092510)
- floorf (Address: 0x180092620)
- free (Address: 0x1800925a0)
- iswalnum (Address: 0x180092430)
- iswgraph (Address: 0x1800925e8)
- iswprint (Address: 0x180092608)
- localeconv (Address: 0x180092410)
- malloc (Address: 0x1800925a8)
- memcmp (Address: 0x1800924f8)
- memcpy (Address: 0x180092478)
- memcpy_s (Address: 0x180092558)
- memmove (Address: 0x180092480)
- memmove_s (Address: 0x180092518)
- memset (Address: 0x1800924d0)
- qsort (Address: 0x180092450)
- qsort_s (Address: 0x180092458)
- setlocale (Address: 0x180092490)
- sprintf_s (Address: 0x180092538)
- strcspn (Address: 0x180092418)
- swscanf_s (Address: 0x180092440)
- time (Address: 0x180092420)
- toupper (Address: 0x180092428)
- towupper (Address: 0x180092438)
- wcschr (Address: 0x180092618)
- wcscpy_s (Address: 0x180092520)
- wcsncmp (Address: 0x180092448)
OLEAUT32.dll
- SysAllocString (Address: 0x180092288)
- SysAllocStringByteLen (Address: 0x180092298)
- SysAllocStringLen (Address: 0x180092280)
- SysFreeString (Address: 0x180092290)
- SysStringByteLen (Address: 0x180092278)
- SysStringLen (Address: 0x180092270)
SHELL32.dll
- SHCreateDirectoryExW (Address: 0x1800922a8)
SHLWAPI.dll
- StrChrW (Address: 0x1800922b8)
USER32.dll
- CreateWindowExW (Address: 0x180092328)
- DefWindowProcW (Address: 0x180092330)
- DestroyWindow (Address: 0x180092300)
- EnumChildWindows (Address: 0x1800922e8)
- EnumThreadWindows (Address: 0x1800922d0)
- GetForegroundWindow (Address: 0x1800922e0)
- GetWindowLongPtrW (Address: 0x180092320)
- GetWindowThreadProcessId (Address: 0x1800922f0)
- IsWindow (Address: 0x1800922d8)
- KillTimer (Address: 0x1800922f8)
- RegisterClassExW (Address: 0x180092338)
- SetTimer (Address: 0x180092310)
- SetWindowLongPtrW (Address: 0x180092318)
- SystemParametersInfoW (Address: 0x1800922c8)
- UnregisterClassW (Address: 0x180092308)
WINMM.dll
- PlaySoundW (Address: 0x180092348)