|
|
|
|
|
|
|
Figure T9-1:
Export list for advapi32.dll |
|
|
|
|
|
|
|
|
in Figure T9-1, which shows the export list for the advapi32.dll dynamic link library. |
|
|
|
|
|
|
|
|
The Find command button brings up the form shown in Figure T9-2. Enter the name of the function that you want to search for in the text box. The three checkboxes offer the following options: |
|
|
|
|
|
|
|
|
Ignore Case. Check this box to ignore case during the search. |
|
|
|
|
|
|
|
|
Check A&W Suffixes. This option searches for the function name you specify and for variations that result in adding either an A or a W suffix to the name. This allows you to detect ANSI and Unicode entry points if they exist for a given function name. |
|
|
|
|
|
|
|
|
Search All DLLs. When checked, the DumpInfo program will search all of the DLLs in your system directory, even after the functions are found in a particular DLL. Otherwise the program will stop searching once it has found the functions. This option is useful if you think a particular function might be exported by more than one DLL. |
|
|
|
|
|
|
|
|
A search operation can be aborted while it's in progress by clicking on the Stop button (which appears only during a search). After a search operation has finished, you will see a list of the functions that match your search criteria, such as that shown for the GetWindowText function in Figure T9-3. |
|
|
|
|
|
|
|
|
Before you read farther, I must stress that this is an expert-level tutorial. To gain full benefit of this tutorial, you should first obtain a copy of the Microsoft Portable Executable File specification (available on MSDN and the Visual Studio |
|
|
|
|
|