< previous page page_378 next page >

Page 378
0378-01.gif
Figure T9-1:
Export list for advapi32.dll
in Figure T9-1, which shows the export list for the advapi32.dll dynamic link library.
The Find command button brings up the form shown in Figure T9-2. Enter the name of the function that you want to search for in the text box. The three checkboxes offer the following options:
Ignore Case. Check this box to ignore case during the search.
Check A&W Suffixes. This option searches for the function name you specify and for variations that result in adding either an A or a W suffix to the name. This allows you to detect ANSI and Unicode entry points if they exist for a given function name.
Search All DLLs. When checked, the DumpInfo program will search all of the DLLs in your system directory, even after the functions are found in a particular DLL. Otherwise the program will stop searching once it has found the functions. This option is useful if you think a particular function might be exported by more than one DLL.
A search operation can be aborted while it's in progress by clicking on the Stop button (which appears only during a search). After a search operation has finished, you will see a list of the functions that match your search criteria, such as that shown for the GetWindowText function in Figure T9-3.
Before you read farther, I must stress that this is an expert-level tutorial. To gain full benefit of this tutorial, you should first obtain a copy of the Microsoft Portable Executable File specification (available on MSDN and the Visual Studio

 
< previous page page_378 next page >