Import table
advapi32.dll
OpenProcessToken, OpenServiceW, GetKernelObjectSecurity, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, AllocateAndInitializeSid, EqualSid, FreeSid, GetLengthSid, LookupPrivilegeValueW, AdjustTokenPrivileges, OpenSCManagerW, CloseServiceHandle, RegOpenKeyExA, RegQueryValueExA, RegCloseKey, ConvertStringSecurityDescriptorToSecurityDescriptorA, CryptDestroyKey, GetTokenInformation, CryptEncrypt, CryptAcquireContextW, CryptGenKey, CryptReleaseContext, CryptImportKey, CryptExportKey, ConvertSidToStringSidA, ConvertStringSidToSidA, RegOpenKeyExW, RegQueryValueExW, LookupAccountSidW, CreateProcessAsUserA, SetTokenInformation, DuplicateTokenEx, ConvertStringSidToSidW, GetEffectiveRightsFromAclW, SetEntriesInAclW, GetSidSubAuthority, InitiateSystemShutdownW, GetNamedSecurityInfoW, SetNamedSecurityInfoW
crypt32.dll
CertCloseStore, CryptQueryObject, CryptMsgGetParam, CertFindCertificateInStore, CertGetNameStringW, CryptDecodeObject
gdi32.dll
EndDoc, CreateCompatibleBitmap, DeleteDC, CreateCompatibleDC, SelectObject, DeleteObject
kernel32.dll
DllMain
psapi.dll
GetModuleFileNameExA, GetModuleInformation, GetMappedFileNameA, EnumProcessModules, GetDeviceDriverBaseNameA, EnumDeviceDrivers, EnumProcesses, GetModuleBaseNameA, GetProcessMemoryInfo
shell32.dll
SHGetFolderPathW, SHGetFolderPathA, CommandLineToArgvW, ShellExecuteExA
shlwapi.dll
PathAppendA, StrStrIA
user32.dll
FindWindowExA, GetWindowThreadProcessId, GetClassNameW, CallNextHookEx, GetClassInfoExW, GetDesktopWindow, wsprintfW, CloseDesktop, GetUserObjectInformationA, GetThreadDesktop, OpenInputDesktop, PrintWindow, MessageBoxExA, GetWindowTextA, ShowWindow, SetForegroundWindow, GetSystemMenu, DeleteMenu, GetParent, GetClientRect, MonitorFromPoint, EnumDisplayMonitors, MonitorFromWindow, OpenClipboard, EmptyClipboard, SetClipboardData, EnumWindows, GetForegroundWindow, GetWindowRect, GetDC, GetWindowDC, CloseClipboard
version.dll
VerQueryValueA, GetFileVersionInfoW, GetFileVersionInfoSizeW, GetFileVersionInfoA, GetFileVersionInfoSizeA, VerQueryValueW
wintrust.dll
CryptCATEnumerateAttr, CryptCATClose, CryptCATGetMemberInfo, CryptCATAdminReleaseContext, WinVerifyTrust, CryptCATOpen, CryptCATCatalogInfoFromContext, CryptCATAdminEnumCatalogFromHash, CryptCATAdminAcquireContext, CryptCATAdminCalcHashFromFileHandle, CryptCATAdminReleaseCatalogContext
wtsapi32.dll
WTSCloseServer
Export table
do_no_call_this_for_link_only
dummy
rooks_callback_dispatcher
rooks_clear_all_sinks
rooks_ctl_process_threadproc
rooks_get_base_version
rooks_get_process_data
rooks_get_registered_processes
rooks_is_initialized
rooksbas_callwnd_hook
rooksbas_init
tso_sb_init