ChxEM.DLL

Description: Microsoft IME

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.5794

Architecture: 64-bit

Operating System: Windows NT

SHA256: 6dfb50883b4822554dacd167523e3b6c

File Size: 759.0 KB

Uploaded At: Dec. 1, 2025, 7:50 a.m.

Views: 6

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • DestroyMtf (Ordinal: 1, Address: 0x5e00)
  • DllCanUnloadNow (Ordinal: 2, Address: 0x2b70)
  • DllGetClassObject (Ordinal: 3, Address: 0x2a80)
  • DllRegisterServer (Ordinal: 4, Address: 0x2fa0)
  • DllUnregisterServer (Ordinal: 5, Address: 0x2fe0)
  • SetupMtf (Ordinal: 6, Address: 0x5dc0)

Imported DLLs & Functions

ADVAPI32.dll
  • ConvertSidToStringSidW (Address: 0x180091ef0)
  • ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x180091ee8)
  • EventActivityIdControl (Address: 0x180091f30)
  • EventRegister (Address: 0x180091f48)
  • EventSetInformation (Address: 0x180091f50)
  • EventUnregister (Address: 0x180091f58)
  • EventWriteTransfer (Address: 0x180091f40)
  • GetTokenInformation (Address: 0x180091ee0)
  • IsValidSid (Address: 0x180091ef8)
  • OpenProcessToken (Address: 0x180091f00)
  • RegCloseKey (Address: 0x180091f60)
  • RegCreateKeyExW (Address: 0x180091f68)
  • RegDeleteTreeW (Address: 0x180091f70)
  • RegEnumValueW (Address: 0x180091f38)
  • RegGetValueW (Address: 0x180091f28)
  • RegOpenCurrentUser (Address: 0x180091f18)
  • RegOpenKeyExW (Address: 0x180091f20)
  • RegQueryValueExW (Address: 0x180091f10)
  • RegSetKeyValueW (Address: 0x180091f08)
  • RegSetValueExW (Address: 0x180091f78)
api-ms-win-core-apiquery-l1-1-0.dll
  • ApiSetQueryApiSetPresence (Address: 0x180092358)
api-ms-win-core-com-l1-1-0.dll
  • CoCreateInstance (Address: 0x180092368)
  • CoGetMalloc (Address: 0x180092388)
  • CoInitializeEx (Address: 0x180092370)
  • CoTaskMemAlloc (Address: 0x1800923a8)
  • CoTaskMemFree (Address: 0x180092390)
  • CoTaskMemRealloc (Address: 0x1800923a0)
  • CoUninitialize (Address: 0x180092398)
  • CoWaitForMultipleHandles (Address: 0x180092380)
  • StringFromGUID2 (Address: 0x180092378)
api-ms-win-core-winrt-error-l1-1-0.dll
  • RoTransformError (Address: 0x1800923b8)
  • SetRestrictedErrorInfo (Address: 0x1800923c0)
api-ms-win-core-winrt-error-l1-1-1.dll
  • IsErrorPropagationEnabled (Address: 0x1800923d0)
  • RoGetMatchingRestrictedErrorInfo (Address: 0x1800923e0)
  • RoReportFailedDelegate (Address: 0x1800923d8)
api-ms-win-core-winrt-l1-1-0.dll
  • RoGetActivationFactory (Address: 0x1800923f0)
api-ms-win-core-winrt-string-l1-1-0.dll
  • WindowsCreateStringReference (Address: 0x180092400)
CoreMessaging.dll
  • CoreUICreate (Address: 0x180091f88)
KERNEL32.dll
  • AcquireSRWLockExclusive (Address: 0x180092128)
  • AcquireSRWLockShared (Address: 0x180092178)
  • ActivateActCtx (Address: 0x180091fe8)
  • Beep (Address: 0x180092160)
  • CloseHandle (Address: 0x180092070)
  • CloseThreadpoolTimer (Address: 0x1800921c0)
  • CreateActCtxW (Address: 0x180091fe0)
  • CreateEventExW (Address: 0x180092148)
  • CreateFileMappingW (Address: 0x180092248)
  • CreateFileW (Address: 0x180092208)
  • CreateMutexExW (Address: 0x180092088)
  • CreateSemaphoreExW (Address: 0x180091ff8)
  • CreateThreadpoolTimer (Address: 0x180092168)
  • DeactivateActCtx (Address: 0x180092040)
  • DebugBreak (Address: 0x1800920a8)
  • DecodePointer (Address: 0x180091fb0)
  • DelayLoadFailureHook (Address: 0x180091f98)
  • DeleteCriticalSection (Address: 0x180092198)
  • EncodePointer (Address: 0x180091fa8)
  • EnterCriticalSection (Address: 0x180092190)
  • FormatMessageW (Address: 0x180092048)
  • GetCurrentProcess (Address: 0x1800920f0)
  • GetCurrentProcessId (Address: 0x180092090)
  • GetCurrentThreadId (Address: 0x180092030)
  • GetFileSize (Address: 0x180092240)
  • GetFullPathNameW (Address: 0x180092010)
  • GetLastError (Address: 0x180091fd0)
  • GetModuleFileNameA (Address: 0x180091fd8)
  • GetModuleFileNameW (Address: 0x180091fc8)
  • GetModuleHandleExW (Address: 0x180092020)
  • GetModuleHandleW (Address: 0x1800920a0)
  • GetProcAddress (Address: 0x180092080)
  • GetProcessHeap (Address: 0x180092098)
  • GetStringTypeW (Address: 0x180091fa0)
  • GetSystemTime (Address: 0x180092130)
  • GetSystemTimeAsFileTime (Address: 0x180092100)
  • GetSystemWindowsDirectoryW (Address: 0x180092220)
  • GetTickCount (Address: 0x180092108)
  • GetTickCount64 (Address: 0x180092110)
  • GetWindowsDirectoryW (Address: 0x180092158)
  • HeapAlloc (Address: 0x180092078)
  • HeapFree (Address: 0x180092000)
  • HeapReAlloc (Address: 0x180092210)
  • InitializeCriticalSection (Address: 0x180092218)
  • InitializeCriticalSectionEx (Address: 0x1800921a0)
  • InitializeSRWLock (Address: 0x180092118)
  • InitOnceBeginInitialize (Address: 0x180091ff0)
  • InitOnceComplete (Address: 0x180092058)
  • IsDebuggerPresent (Address: 0x1800920b8)
  • K32GetModuleBaseNameW (Address: 0x1800921d0)
  • LeaveCriticalSection (Address: 0x180092188)
  • LocalAlloc (Address: 0x1800921d8)
  • LocalFree (Address: 0x1800921e0)
  • MapViewOfFile (Address: 0x180092250)
  • MulDiv (Address: 0x1800921f8)
  • MultiByteToWideChar (Address: 0x1800921e8)
  • OpenFileMappingW (Address: 0x180092230)
  • OpenProcess (Address: 0x1800921c8)
  • OpenSemaphoreW (Address: 0x180092068)
  • OutputDebugStringW (Address: 0x180092050)
  • PrefetchVirtualMemory (Address: 0x180092228)
  • QueryPerformanceCounter (Address: 0x1800920f8)
  • RaiseException (Address: 0x1800921a8)
  • ReleaseActCtx (Address: 0x1800920b0)
  • ReleaseMutex (Address: 0x180092038)
  • ReleaseSemaphore (Address: 0x180092018)
  • ReleaseSRWLockExclusive (Address: 0x180092120)
  • ReleaseSRWLockShared (Address: 0x180092180)
  • ResetEvent (Address: 0x180092150)
  • ResolveDelayLoadedAPI (Address: 0x180091fc0)
  • RtlCaptureContext (Address: 0x1800920c8)
  • RtlLookupFunctionEntry (Address: 0x1800920d0)
  • RtlVirtualUnwind (Address: 0x1800920d8)
  • SetEvent (Address: 0x180092140)
  • SetLastError (Address: 0x180092008)
  • SetThreadpoolTimer (Address: 0x180092170)
  • SetUnhandledExceptionFilter (Address: 0x1800920e8)
  • Sleep (Address: 0x1800920c0)
  • SleepConditionVariableSRW (Address: 0x180092200)
  • SystemTimeToFileTime (Address: 0x180092138)
  • TerminateProcess (Address: 0x180092258)
  • UnhandledExceptionFilter (Address: 0x1800920e0)
  • UnmapViewOfFile (Address: 0x180092238)
  • VerifyVersionInfoW (Address: 0x1800921b0)
  • VerSetConditionMask (Address: 0x180092260)
  • WaitForSingleObject (Address: 0x180092028)
  • WaitForSingleObjectEx (Address: 0x180092060)
  • WaitForThreadpoolTimerCallbacks (Address: 0x1800921b8)
  • WakeAllConditionVariable (Address: 0x180091fb8)
  • WideCharToMultiByte (Address: 0x1800921f0)
msvcrt.dll
  • ___lc_codepage_func (Address: 0x1800924b0)
  • ___lc_handle_func (Address: 0x1800924a8)
  • ___mb_cur_max_func (Address: 0x1800924a0)
  • __C_specific_handler (Address: 0x1800925b8)
  • __crtLCMapStringW (Address: 0x1800924e0)
  • __CxxFrameHandler3 (Address: 0x180092560)
  • __dllonexit (Address: 0x1800925f8)
  • __pctype_func (Address: 0x1800924c0)
  • __uncaught_exception (Address: 0x180092488)
  • _amsg_exit (Address: 0x180092598)
  • _callnewh (Address: 0x180092460)
  • _CxxThrowException (Address: 0x180092470)
  • _errno (Address: 0x180092498)
  • _initterm (Address: 0x1800925b0)
  • _ismbblead (Address: 0x1800924b8)
  • _lock (Address: 0x1800925d0)
  • _onexit (Address: 0x180092600)
  • _purecall (Address: 0x180092568)
  • _ultow_s (Address: 0x1800925e0)
  • _unlock (Address: 0x1800925d8)
  • _vsnprintf_s (Address: 0x180092588)
  • _vsnwprintf (Address: 0x180092550)
  • _wcsdup (Address: 0x1800924d8)
  • _wcsicmp (Address: 0x180092500)
  • _wsetlocale (Address: 0x1800924e8)
  • _wtoi (Address: 0x180092508)
  • _XcptFilter (Address: 0x180092590)
  • ??_V@YAXPEAX@Z (Address: 0x1800925f0)
  • ??0bad_cast@@QEAA@AEBV0@@Z (Address: 0x180092530)
  • ??0bad_cast@@QEAA@PEBD@Z (Address: 0x1800924f0)
  • ??0exception@@QEAA@AEBQEBD@Z (Address: 0x180092540)
  • ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x180092468)
  • ??0exception@@QEAA@AEBV0@@Z (Address: 0x180092580)
  • ??0exception@@QEAA@XZ (Address: 0x180092578)
  • ??1bad_cast@@UEAA@XZ (Address: 0x180092528)
  • ??1exception@@UEAA@XZ (Address: 0x180092570)
  • ??1type_info@@UEAA@XZ (Address: 0x180092610)
  • ??3@YAXPEAX@Z (Address: 0x1800925c0)
  • ?terminate@@YAXXZ (Address: 0x1800925c8)
  • ?what@exception@@UEBAPEBDXZ (Address: 0x180092548)
  • abort (Address: 0x1800924c8)
  • calloc (Address: 0x180092510)
  • floorf (Address: 0x180092620)
  • free (Address: 0x1800925a0)
  • iswalnum (Address: 0x180092430)
  • iswgraph (Address: 0x1800925e8)
  • iswprint (Address: 0x180092608)
  • localeconv (Address: 0x180092410)
  • malloc (Address: 0x1800925a8)
  • memcmp (Address: 0x1800924f8)
  • memcpy (Address: 0x180092478)
  • memcpy_s (Address: 0x180092558)
  • memmove (Address: 0x180092480)
  • memmove_s (Address: 0x180092518)
  • memset (Address: 0x1800924d0)
  • qsort (Address: 0x180092450)
  • qsort_s (Address: 0x180092458)
  • setlocale (Address: 0x180092490)
  • sprintf_s (Address: 0x180092538)
  • strcspn (Address: 0x180092418)
  • swscanf_s (Address: 0x180092440)
  • time (Address: 0x180092420)
  • toupper (Address: 0x180092428)
  • towupper (Address: 0x180092438)
  • wcschr (Address: 0x180092618)
  • wcscpy_s (Address: 0x180092520)
  • wcsncmp (Address: 0x180092448)
OLEAUT32.dll
  • SysAllocString (Address: 0x180092288)
  • SysAllocStringByteLen (Address: 0x180092298)
  • SysAllocStringLen (Address: 0x180092280)
  • SysFreeString (Address: 0x180092290)
  • SysStringByteLen (Address: 0x180092278)
  • SysStringLen (Address: 0x180092270)
SHELL32.dll
  • SHCreateDirectoryExW (Address: 0x1800922a8)
SHLWAPI.dll
  • StrChrW (Address: 0x1800922b8)
USER32.dll
  • CreateWindowExW (Address: 0x180092328)
  • DefWindowProcW (Address: 0x180092330)
  • DestroyWindow (Address: 0x180092300)
  • EnumChildWindows (Address: 0x1800922e8)
  • EnumThreadWindows (Address: 0x1800922d0)
  • GetForegroundWindow (Address: 0x1800922e0)
  • GetWindowLongPtrW (Address: 0x180092320)
  • GetWindowThreadProcessId (Address: 0x1800922f0)
  • IsWindow (Address: 0x1800922d8)
  • KillTimer (Address: 0x1800922f8)
  • RegisterClassExW (Address: 0x180092338)
  • SetTimer (Address: 0x180092310)
  • SetWindowLongPtrW (Address: 0x180092318)
  • SystemParametersInfoW (Address: 0x1800922c8)
  • UnregisterClassW (Address: 0x180092308)
WINMM.dll
  • PlaySoundW (Address: 0x180092348)