InputSwitch.dll

Description: Microsoft Windows Input Switcher

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.5848

Architecture: 32-bit

Operating System: Windows NT

SHA256: a33a7663be2ddc14f0c96bf2eb89275a

File Size: 418.5 KB

Uploaded At: Dec. 1, 2025, 7:57 a.m.

Views: 6

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • DllCanUnloadNow (Ordinal: 1, Address: 0x176d0)
  • DllGetClassObject (Ordinal: 2, Address: 0x16f60)

Imported DLLs & Functions

api-ms-win-appmodel-runtime-l1-1-1.dll
  • FindPackagesByPackageFamily (Address: 0x1005217c)
api-ms-win-appmodel-runtime-l1-1-3.dll
  • GetStagedPackagePathByFullName2 (Address: 0x10052184)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x10052190)
  • IsDebuggerPresent (Address: 0x1005218c)
  • OutputDebugStringW (Address: 0x10052194)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x1005219c)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x100521a4)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x100521b8)
  • RaiseException (Address: 0x100521b0)
  • SetLastError (Address: 0x100521bc)
  • SetUnhandledExceptionFilter (Address: 0x100521ac)
  • UnhandledExceptionFilter (Address: 0x100521b4)
api-ms-win-core-file-l1-1-0.dll
  • GetFullPathNameW (Address: 0x100521c4)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x100521cc)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x100521e0)
  • HeapAlloc (Address: 0x100521d8)
  • HeapFree (Address: 0x100521d4)
  • HeapReAlloc (Address: 0x100521dc)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x100521e8)
  • LocalFree (Address: 0x100521ec)
  • LocalReAlloc (Address: 0x100521f0)
api-ms-win-core-kernel32-legacy-l1-1-1.dll
  • VerifyVersionInfoW (Address: 0x10052200)
api-ms-win-core-libraryloader-l1-2-0.dll
  • FindResourceExW (Address: 0x10052214)
  • FindStringOrdinal (Address: 0x10052218)
  • FreeLibrary (Address: 0x10052224)
  • GetModuleFileNameA (Address: 0x10052208)
  • GetModuleHandleExW (Address: 0x1005222c)
  • GetModuleHandleW (Address: 0x10052220)
  • GetProcAddress (Address: 0x1005220c)
  • LoadLibraryExW (Address: 0x10052210)
  • LoadResource (Address: 0x1005221c)
  • LoadStringW (Address: 0x10052230)
  • LockResource (Address: 0x10052228)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x10052240)
  • GetLocaleInfoEx (Address: 0x1005223c)
  • GetLocaleInfoW (Address: 0x10052248)
  • GetThreadUILanguage (Address: 0x1005224c)
  • GetUserDefaultLangID (Address: 0x10052238)
  • SetThreadUILanguage (Address: 0x10052244)
api-ms-win-core-localization-obsolete-l1-2-0.dll
  • GetUserDefaultUILanguage (Address: 0x10052254)
api-ms-win-core-path-l1-1-0.dll
  • PathAllocCombine (Address: 0x1005225c)
  • PathCchRemoveFileSpec (Address: 0x10052260)
api-ms-win-core-processenvironment-l1-1-0.dll
  • ExpandEnvironmentStringsW (Address: 0x10052268)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x10052284)
  • GetCurrentProcessId (Address: 0x1005227c)
  • GetCurrentThreadId (Address: 0x10052280)
  • OpenThread (Address: 0x10052278)
  • TerminateProcess (Address: 0x10052288)
  • TlsAlloc (Address: 0x10052290)
  • TlsFree (Address: 0x1005228c)
  • TlsGetValue (Address: 0x10052270)
  • TlsSetValue (Address: 0x10052274)
api-ms-win-core-processthreads-l1-1-1.dll
  • OpenProcess (Address: 0x10052298)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x100522a0)
api-ms-win-core-psapi-l1-1-0.dll
  • QueryFullProcessImageNameW (Address: 0x100522a8)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x100522c4)
  • RegCreateKeyExW (Address: 0x100522bc)
  • RegGetValueW (Address: 0x100522b8)
  • RegOpenCurrentUser (Address: 0x100522b0)
  • RegOpenKeyExW (Address: 0x100522c8)
  • RegQueryInfoKeyW (Address: 0x100522c0)
  • RegQueryValueExW (Address: 0x100522cc)
  • RegSetValueExW (Address: 0x100522b4)
api-ms-win-core-registry-l1-1-1.dll
  • RegSetKeyValueW (Address: 0x100522d4)
api-ms-win-core-shlwapi-legacy-l1-1-0.dll
  • PathAppendW (Address: 0x100522dc)
  • PathFileExistsW (Address: 0x100522e8)
  • PathFindExtensionW (Address: 0x100522f0)
  • PathFindFileNameW (Address: 0x100522ec)
  • PathIsFileSpecW (Address: 0x100522e0)
  • PathIsRelativeW (Address: 0x100522f4)
  • PathRemoveFileSpecW (Address: 0x100522e4)
api-ms-win-core-shlwapi-obsolete-l1-1-0.dll
  • QISearch (Address: 0x100522fc)
api-ms-win-core-string-l1-1-0.dll
  • CompareStringOrdinal (Address: 0x10052304)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x1005234c)
  • AcquireSRWLockShared (Address: 0x10052334)
  • CreateEventW (Address: 0x10052348)
  • CreateMutexExW (Address: 0x1005231c)
  • CreateSemaphoreExW (Address: 0x10052330)
  • DeleteCriticalSection (Address: 0x10052338)
  • EnterCriticalSection (Address: 0x10052354)
  • InitializeCriticalSectionEx (Address: 0x1005232c)
  • LeaveCriticalSection (Address: 0x1005233c)
  • OpenSemaphoreW (Address: 0x10052318)
  • ReleaseMutex (Address: 0x10052310)
  • ReleaseSemaphore (Address: 0x10052324)
  • ReleaseSRWLockExclusive (Address: 0x10052320)
  • ReleaseSRWLockShared (Address: 0x10052340)
  • SetEvent (Address: 0x10052350)
  • TryEnterCriticalSection (Address: 0x10052344)
  • WaitForMultipleObjectsEx (Address: 0x10052314)
  • WaitForSingleObject (Address: 0x1005230c)
  • WaitForSingleObjectEx (Address: 0x10052328)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceBeginInitialize (Address: 0x10052370)
  • InitOnceComplete (Address: 0x1005235c)
  • InitOnceExecuteOnce (Address: 0x10052360)
  • Sleep (Address: 0x10052368)
  • SleepConditionVariableSRW (Address: 0x1005236c)
  • WakeAllConditionVariable (Address: 0x10052364)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTime (Address: 0x10052380)
  • GetSystemTimeAsFileTime (Address: 0x1005237c)
  • GetTickCount (Address: 0x10052378)
  • GetVersionExW (Address: 0x10052384)
api-ms-win-core-sysinfo-l1-2-0.dll
  • GetSystemTimePreciseAsFileTime (Address: 0x1005238c)
  • VerSetConditionMask (Address: 0x10052390)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x100523a0)
  • CreateThreadpoolTimer (Address: 0x1005239c)
  • SetThreadpoolTimer (Address: 0x100523a4)
  • WaitForThreadpoolTimerCallbacks (Address: 0x10052398)
api-ms-win-core-timezone-l1-1-0.dll
  • SystemTimeToFileTime (Address: 0x100523ac)
api-ms-win-core-url-l1-1-0.dll
  • PathIsURLW (Address: 0x100523bc)
  • UrlCreateFromPathW (Address: 0x100523b4)
  • UrlUnescapeW (Address: 0x100523b8)
api-ms-win-core-util-l1-1-0.dll
  • DecodePointer (Address: 0x100523c4)
  • EncodePointer (Address: 0x100523c8)
api-ms-win-core-winrt-error-l1-1-0.dll
  • RoOriginateError (Address: 0x100523d4)
  • SetRestrictedErrorInfo (Address: 0x100523d0)
api-ms-win-core-winrt-error-l1-1-1.dll
  • RoGetMatchingRestrictedErrorInfo (Address: 0x100523dc)
api-ms-win-core-winrt-l1-1-0.dll
  • RoActivateInstance (Address: 0x100523e8)
  • RoGetActivationFactory (Address: 0x100523e4)
api-ms-win-core-winrt-string-l1-1-0.dll
  • WindowsCreateString (Address: 0x10052400)
  • WindowsCreateStringReference (Address: 0x10052404)
  • WindowsDeleteString (Address: 0x100523f0)
  • WindowsDuplicateString (Address: 0x100523fc)
  • WindowsGetStringRawBuffer (Address: 0x100523f8)
  • WindowsIsStringEmpty (Address: 0x100523f4)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventActivityIdControl (Address: 0x10052418)
  • EventRegister (Address: 0x1005241c)
  • EventSetInformation (Address: 0x10052414)
  • EventUnregister (Address: 0x1005240c)
  • EventWriteTransfer (Address: 0x10052410)
api-ms-win-ntuser-rectangle-l1-1-0.dll
  • CopyRect (Address: 0x10052430)
  • OffsetRect (Address: 0x10052428)
  • PtInRect (Address: 0x10052424)
  • SetRectEmpty (Address: 0x1005242c)
api-ms-win-ntuser-sysparams-l1-1-0.dll
  • GetMonitorInfoW (Address: 0x10052438)
  • GetSystemMetrics (Address: 0x1005243c)
  • SystemParametersInfoW (Address: 0x10052440)
api-ms-win-rtcore-ntuser-private-l1-1-0.dll
  • CreateWindowInBand (Address: 0x1005244c)
  • GetWindowBand (Address: 0x10052448)
api-ms-win-rtcore-ntuser-shell-l1-1-0.dll
  • DeregisterShellHookWindow (Address: 0x10052458)
  • RegisterShellHookWindow (Address: 0x10052454)
api-ms-win-rtcore-ntuser-synch-l1-1-0.dll
  • MsgWaitForMultipleObjectsEx (Address: 0x10052460)
api-ms-win-rtcore-ntuser-window-l1-1-0.dll
  • ClientToScreen (Address: 0x1005248c)
  • CreateWindowExW (Address: 0x10052470)
  • DefWindowProcW (Address: 0x10052480)
  • DestroyWindow (Address: 0x100524bc)
  • DispatchMessageW (Address: 0x100524b4)
  • FindWindowExW (Address: 0x10052498)
  • FindWindowW (Address: 0x100524e8)
  • GetClassNameW (Address: 0x100524e4)
  • GetClientRect (Address: 0x100524a4)
  • GetCursorPos (Address: 0x10052468)
  • GetDesktopWindow (Address: 0x100524f8)
  • GetMessageExtraInfo (Address: 0x100524c8)
  • GetMessageW (Address: 0x10052488)
  • GetParent (Address: 0x10052490)
  • GetPropW (Address: 0x100524d0)
  • GetWindowLongW (Address: 0x10052474)
  • GetWindowRect (Address: 0x100524c4)
  • GetWindowThreadProcessId (Address: 0x100524c0)
  • KillTimer (Address: 0x100524d4)
  • PeekMessageW (Address: 0x100524a8)
  • PostMessageW (Address: 0x100524b8)
  • PostQuitMessage (Address: 0x100524ac)
  • RegisterClassExW (Address: 0x1005246c)
  • RegisterClassW (Address: 0x100524f0)
  • RegisterWindowMessageW (Address: 0x1005249c)
  • RemovePropW (Address: 0x100524d8)
  • ScreenToClient (Address: 0x1005247c)
  • SendMessageW (Address: 0x10052494)
  • SetForegroundWindow (Address: 0x100524f4)
  • SetMessageExtraInfo (Address: 0x100524cc)
  • SetPropW (Address: 0x100524dc)
  • SetTimer (Address: 0x100524a0)
  • SetWindowLongW (Address: 0x10052478)
  • SetWindowPos (Address: 0x100524ec)
  • ShowWindow (Address: 0x10052484)
  • TranslateMessage (Address: 0x100524b0)
  • WindowFromPoint (Address: 0x100524e0)
api-ms-win-rtcore-ntuser-winevent-l1-1-0.dll
  • NotifyWinEvent (Address: 0x10052500)
api-ms-win-rtcore-ntuser-wmpointer-l1-1-0.dll
  • GetCurrentInputMessageSource (Address: 0x10052508)
api-ms-win-security-base-l1-1-0.dll
  • CheckTokenMembership (Address: 0x10052518)
  • CreateWellKnownSid (Address: 0x10052510)
  • GetTokenInformation (Address: 0x10052514)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertSidToStringSidW (Address: 0x10052520)
api-ms-win-shcore-comhelpers-l1-1-0.dll
  • IUnknown_QueryService (Address: 0x1005252c)
  • IUnknown_Set (Address: 0x10052528)
api-ms-win-shlwapi-winrt-storage-l1-1-1.dll
  • (Address: 0x10052538)
  • (Address: 0x1005253c)
  • IUnknown_GetWindow (Address: 0x10052534)
api-ms-win-stateseparation-helpers-l1-1-0.dll
  • GetPersistedRegistryLocationW (Address: 0x10052544)
Bcp47Langs.dll
  • Bcp47FromLcid (Address: 0x10052004)
  • Bcp47GetAbbreviation (Address: 0x10052008)
  • Bcp47GetLanguageName (Address: 0x10052000)
GDI32.dll
  • BitBlt (Address: 0x10052028)
  • CreateCompatibleDC (Address: 0x1005201c)
  • CreateDIBSection (Address: 0x10052020)
  • CreateFontIndirectW (Address: 0x1005206c)
  • CreateSolidBrush (Address: 0x1005202c)
  • DeleteDC (Address: 0x10052078)
  • DeleteObject (Address: 0x10052070)
  • ExcludeClipRect (Address: 0x10052064)
  • ExtTextOutW (Address: 0x1005204c)
  • GdiAlphaBlend (Address: 0x10052018)
  • GetClipBox (Address: 0x10052048)
  • GetCurrentObject (Address: 0x10052030)
  • GetDeviceCaps (Address: 0x10052010)
  • GetDIBits (Address: 0x10052060)
  • GetObjectW (Address: 0x10052044)
  • GetStockObject (Address: 0x1005205c)
  • GetTextExtentPoint32W (Address: 0x10052054)
  • GetTextMetricsW (Address: 0x10052038)
  • RemoveFontMemResourceEx (Address: 0x10052074)
  • SelectObject (Address: 0x10052024)
  • SetBkColor (Address: 0x10052058)
  • SetBkMode (Address: 0x10052040)
  • SetStretchBltMode (Address: 0x10052068)
  • SetTextAlign (Address: 0x10052050)
  • SetTextColor (Address: 0x1005203c)
  • StretchBlt (Address: 0x10052014)
  • StretchDIBits (Address: 0x10052034)
IMM32.dll
  • ImmDisableLegacyIME (Address: 0x10052080)
msvcrt.dll
  • __CxxFrameHandler3 (Address: 0x10052550)
  • __dllonexit (Address: 0x100525b0)
  • __isascii (Address: 0x1005257c)
  • _amsg_exit (Address: 0x100525e0)
  • _callnewh (Address: 0x10052554)
  • _CIpow (Address: 0x10052594)
  • _CxxThrowException (Address: 0x10052558)
  • _except_handler4_common (Address: 0x100525a8)
  • _ftol2_sse (Address: 0x1005254c)
  • _get_errno (Address: 0x10052564)
  • _initterm (Address: 0x100525bc)
  • _itow_s (Address: 0x100525c4)
  • _lock (Address: 0x100525b8)
  • _onexit (Address: 0x100525ac)
  • _purecall (Address: 0x1005258c)
  • _set_errno (Address: 0x10052568)
  • _unlock (Address: 0x100525b4)
  • _vsnprintf_s (Address: 0x100525d4)
  • _vsnwprintf (Address: 0x10052590)
  • _wcsicmp (Address: 0x10052560)
  • _wtoi (Address: 0x10052584)
  • _XcptFilter (Address: 0x100525e4)
  • ??0exception@@QAE@ABV0@@Z (Address: 0x100525d0)
  • ??0exception@@QAE@XZ (Address: 0x100525cc)
  • ??1exception@@UAE@XZ (Address: 0x100525c8)
  • ??1type_info@@UAE@XZ (Address: 0x100525dc)
  • ?terminate@@YAXXZ (Address: 0x100525d8)
  • floor (Address: 0x1005259c)
  • free (Address: 0x100525e8)
  • islower (Address: 0x10052578)
  • malloc (Address: 0x100525c0)
  • memcmp (Address: 0x100525a0)
  • memcpy (Address: 0x100525f0)
  • memcpy_s (Address: 0x100525ec)
  • memmove (Address: 0x100525a4)
  • memmove_s (Address: 0x10052588)
  • memset (Address: 0x100525f4)
  • toupper (Address: 0x10052574)
  • wcschr (Address: 0x10052570)
  • wcsncmp (Address: 0x10052580)
  • wcsrchr (Address: 0x10052598)
  • wcsstr (Address: 0x1005255c)
  • wcstoul (Address: 0x1005256c)
ntdll.dll
  • NtQueryWnfStateData (Address: 0x10052610)
  • RtlGetDeviceFamilyInfoEnum (Address: 0x10052608)
  • RtlPublishWnfStateData (Address: 0x10052614)
  • RtlSubscribeWnfStateChangeNotification (Address: 0x1005260c)
  • RtlUnsubscribeWnfNotificationWaitForCompletion (Address: 0x10052600)
  • WinSqmAddToStream (Address: 0x10052604)
  • WinSqmIncrementDWORD (Address: 0x100525fc)
ole32.dll
  • CreateBindCtx (Address: 0x1005261c)
PROPSYS.dll
  • PropVariantToUInt32 (Address: 0x1005208c)
  • PSCreateMemoryPropertyStore (Address: 0x10052090)
  • PSPropertyBag_WriteStr (Address: 0x10052088)
SHCORE.dll
  • (Address: 0x1005209c)
  • SHTaskPoolQueueTask (Address: 0x10052098)
USER32.dll
  • AreDpiAwarenessContextsEqual (Address: 0x10052134)
  • BeginPaint (Address: 0x100520cc)
  • CalculatePopupWindowPosition (Address: 0x10052114)
  • CallNextHookEx (Address: 0x100520f4)
  • CheckMenuItem (Address: 0x10052144)
  • CopyIcon (Address: 0x1005215c)
  • CopyImage (Address: 0x1005212c)
  • CreateIconIndirect (Address: 0x10052154)
  • DestroyIcon (Address: 0x10052128)
  • DestroyMenu (Address: 0x100520fc)
  • DrawIconEx (Address: 0x100520b8)
  • DrawTextExW (Address: 0x100520f8)
  • DrawTextW (Address: 0x100520b4)
  • EndPaint (Address: 0x100520c8)
  • GetAsyncKeyState (Address: 0x100520e0)
  • GetDC (Address: 0x100520b0)
  • GetDpiForSystem (Address: 0x100520a4)
  • GetDpiForWindow (Address: 0x100520dc)
  • GetKeyboardState (Address: 0x10052108)
  • GetKeyState (Address: 0x100520f0)
  • GetMenuInfo (Address: 0x100520ac)
  • GetMenuItemInfoW (Address: 0x10052150)
  • GetMenuState (Address: 0x10052148)
  • GetSubMenu (Address: 0x10052130)
  • GetSysColor (Address: 0x10052118)
  • GetThreadDesktop (Address: 0x10052100)
  • GetWindowDpiAwarenessContext (Address: 0x10052138)
  • InjectKeyboardInput (Address: 0x1005214c)
  • LoadCursorW (Address: 0x10052124)
  • LoadIconW (Address: 0x100520c4)
  • LoadImageW (Address: 0x10052158)
  • LoadMenuW (Address: 0x10052140)
  • MonitorFromPoint (Address: 0x1005216c)
  • MonitorFromRect (Address: 0x1005210c)
  • MonitorFromWindow (Address: 0x10052110)
  • ReleaseCapture (Address: 0x100520e8)
  • ReleaseDC (Address: 0x100520bc)
  • RemoveMenu (Address: 0x100520d4)
  • SendInput (Address: 0x1005213c)
  • SetCapture (Address: 0x10052160)
  • SetCursor (Address: 0x10052120)
  • SetKeyboardState (Address: 0x10052104)
  • SetLayeredWindowAttributes (Address: 0x100520c0)
  • SetMenuInfo (Address: 0x100520a8)
  • SetMenuItemInfoW (Address: 0x100520d8)
  • SetThreadDesktop (Address: 0x1005211c)
  • SetWindowCompositionAttribute (Address: 0x10052168)
  • SetWindowsHookExW (Address: 0x100520ec)
  • TrackMouseEvent (Address: 0x10052164)
  • TrackPopupMenuEx (Address: 0x100520d0)
  • UnhookWindowsHookEx (Address: 0x100520e4)
WININET.dll
  • InternetCrackUrlW (Address: 0x10052174)