Import table
advapi32.dll
RegCreateKeyExW, RegSetValueExW, RegOpenKeyExW, EqualSid, CryptEncrypt, CryptAcquireContextW, CryptGenKey, CryptReleaseContext, CryptImportKey, CryptExportKey, CryptDestroyKey, RegOpenKeyExA, RegQueryValueExA, RegQueryValueExW, RegEnumKeyW, RegCloseKey, RegDeleteKeyW, DeleteService, CreateServiceW, ControlService, OpenSCManagerW, OpenServiceW, QueryServiceConfigW, QueryServiceStatus, ChangeServiceConfigW, StartServiceW, AdjustTokenPrivileges, LookupPrivilegeValueW, GetTokenInformation, OpenProcessToken, GetKernelObjectSecurity, FreeSid, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, AllocateAndInitializeSid, GetLengthSid, CloseServiceHandle, ConvertSidToStringSidA, ConvertStringSidToSidA
kernel32.dll
CompareFileTime, GetSystemTime, SetEvent, RaiseException, UnhandledExceptionFilter, IsDebuggerPresent, ResetEvent, GetSystemTimeAsFileTime, GetProcAddress, GetModuleHandleA, WideCharToMultiByte, lstrlenW, EnterCriticalSection, LeaveCriticalSection, InterlockedIncrement, InterlockedDecrement, GetLastError, PostQueuedCompletionStatus, CreateFileW, ConnectNamedPipe, DeleteCriticalSection, InitializeCriticalSection, CreateIoCompletionPort, GetQueuedCompletionStatus, CreateThread, ReadFile, WriteFile, CloseHandle, CancelIo, LoadLibraryW, GetCurrentProcessId, VirtualProtect, VirtualFree, GetModuleHandleW, UnmapViewOfFile, MapViewOfFileEx, CreateFileMappingW, GetCurrentProcess, SetUnhandledExceptionFilter, InterlockedExchange, InterlockedCompareExchange, SetLastError, Sleep, MultiByteToWideChar, TlsAlloc, TlsFree, TlsSetValue, TlsGetValue, VirtualQuery, MapViewOfFile, FlushInstructionCache, IsBadReadPtr, CreateFileMappingA, GetVersion, LocalFree, LocalAlloc, VirtualAllocEx, VirtualQueryEx, VirtualFreeEx, GetCurrentThreadId, DuplicateHandle, GetCurrentThread, OpenProcess, VirtualProtectEx, WriteProcessMemory, HeapAlloc, GetProcessHeap, HeapFree, CreateRemoteThread, ReadProcessMemory, IsBadWritePtr, GetExitCodeThread, WaitForSingleObject, VerifyVersionInfoW, VerSetConditionMask, GetTickCount, lstrcpyW, TerminateProcess, ResumeThread, CreateProcessW, CreateProcessA, GetVersionExW, GetSystemDirectoryW, GetCurrentDirectoryW, GetModuleFileNameW, GetFileAttributesW, GetModuleFileNameA, ReleaseMutex, CreateMutexW, lstrcatA, GetThreadContext, OpenThread, OpenMutexW, OpenFileMappingW, CreateEventW, OpenEventW, lstrcpyA, GetWindowsDirectoryW, DeviceIoControl, QueryPerformanceCounter, QueryPerformanceFrequency, OutputDebugStringA, LoadLibraryA, SearchPathW, ProcessIdToSessionId, FreeLibrary, RtlCaptureContext, GetSystemInfo, GetVersionExA, InterlockedExchangeAdd, DeleteFileW, MoveFileW, CreateDirectoryW, FindClose, FindNextFileW, FindFirstFileW, GetProcessId, InitializeCriticalSectionAndSpinCount, CreateSemaphoreW, ReleaseSemaphore
msvcp80.dll
DllMain
msvcr80.dll
DllMain
psapi.dll
GetDeviceDriverBaseNameA, EnumDeviceDrivers, GetModuleFileNameExA, GetModuleInformation, GetMappedFileNameA
shell32.dll
SHGetFolderPathW, SHGetFolderPathA, CommandLineToArgvW
shlwapi.dll
PathAppendA
user32.dll
OpenInputDesktop, GetUserObjectInformationA, GetThreadDesktop, SetWindowLongW, EnumChildWindows, RegisterWindowMessageW, GetClassInfoExW, GetWindowLongW, SendMessageTimeoutW, GetWindowThreadProcessId, SendMessageW, FindWindowExA, GetClassNameW, GetParent, GetClassNameA, GetDesktopWindow, GetClassLongW, CallWindowProcW, CloseDesktop
version.dll
GetFileVersionInfoA, GetFileVersionInfoSizeA, VerQueryValueA
Export table
begin_fnhook_chelper_hooking
end_fnhook_chelper_hooking
on_construct_sink
on_resolve_sink
rooks_ext_get_rooks_extension
rooksdol_fnhook_chelper_hook
rooksdol_fnhook_chelper_phook
rooksdol_fnhook_chelper_unhook