clkflt.dll is a file-system filter driver for Windows CE and Windows Phone 7.
It comes from the FullUnlock v4.0 project (© Maxim Menshikov (ultrashot), 2012). The driver hooks
the file-system API set of FSDMGR and redirects file lookups. When the OS
opens a stock system module, the driver can serve a patched copy from disk
instead.
This is legacy research and homebrew code for a platform that reached end of life long ago.
The driver installs as an FSDMGR filter. FSDMGR calls FILTER_HookVolume (in
main.cpp) one time per volume. This function wires the exported entry points to
the underlying FILTERHOOK. Every file-system call then passes through this DLL.
- Path redirection.
CreateFileWandGetFileAttributesWsend the requested name toCloaking_GetNewPath(Cloaking.cpp). The function matches the name against a replacement list. The driver loads this list one time from the registry. On a match, the driver reissues the call against the replacement name. - In-memory cache.
CFastCache(CFastCache.cpp) caches file contents. It uses a string hash (HashString) as the key. This speeds up repeated reads. The driver removes an entry when a file is opened for write. It adds the entry again on close. - Diagnostics. Every hook emits a
RETAILMSGtrace.DEBUGLOGindebug.hcontrols these traces.
The driver reads the redirection list from this key:
HKEY_LOCAL_MACHINE\Software\OEM\Cloaking
Each value under this key defines one redirect. The value name is the original
file name. The value data (REG_SZ) is the replacement name. The driver loads the
list on first use (LoadCloakList).
clkflt/
├── clkflt.vcproj Visual Studio 2008 project (WM6 Pro / WP7 ARMv4I)
├── .clang-format Formatting rules for src/
├── src/ Project sources
│ ├── main.cpp DllMain, FILTER_HookVolume / FILTER_UnhookVolume
│ ├── File.cpp Handle-based I/O hooks (read/write/seek/ioctl/…)
│ ├── Find.cpp FindFirstFile / FindNextFile / FindClose hooks
│ ├── Path.cpp Path-based hooks (attributes, move, delete, …)
│ ├── Cloaking.cpp/.h Registry-driven path redirection
│ ├── CFastCache.cpp/.h File-content cache
│ ├── CList.hpp Singly-linked list template used by the cache
│ ├── HashString.cpp/.h djb2-style string hash
│ ├── clkflt.h VolumeState / HandleState definitions
│ ├── debug.h Diagnostics macros
│ ├── stdafx.h/.cpp Precompiled-header stub
│ ├── resource.h, clkflt.rc Version resource
│ └── clkflt.def Exported filter entry points
└── sdk/ Vendored WinCE FSD SDK headers + import library
├── fsdmgr.h, fsioctl.h, extfile.h, lockmgr*.h
└── coredll7.lib
You need Visual Studio 2008 with the target device SDKs installed:
- Windows Mobile 6 Professional SDK (ARMV4I). This is the primary release target.
- WP7SDK (ARMv4I).
To build the driver:
- Open
clkflt.vcproj. - Select a configuration.
- Build the project.
The output is clkflt.dll. The include and library paths point at src/ and
sdk/. The project is self-contained and does not need an enclosing solution.