另外,CE中的coredll.dll能不能单独取出来在windows系统中分析?
4 个解决方案
#1
顺便转贴一个coredll中所有API的列表:
http://blog.csdn.net/stoway/archive/2007/09/05/1772867.aspx
在Windows CE下,coredll.dll的作用相当于Win32的kernel32.dll
查看API方法,在在命令行下进入dumpbin.exe 所在文件夹,输入 dumpbin /EXPORTS coredll.dll > coredlldef.txt
以下仅作备份用
File Type: LIBRARY
Exports
ordinal name
1095 ??2@YAPAXI@Z (void * __cdecl operator new(unsigned int))
1646 ??2@YAPAXIABUnothrow_t@std@@@Z (void * __cdecl operator new(unsigned int,struct std::nothrow_t const &))
1094 ??3@YAXPAX@Z (void __cdecl operator delete(void *))
1662 ??3@YAXPAXABUnothrow_t@std@@@Z (void __cdecl operator delete(void *,struct std::nothrow_t const &))
1456 ??_U@YAPAXI@Z (void * __cdecl operator new[](unsigned int))
1661 ??_U@YAPAXIABUnothrow_t@std@@@Z (void * __cdecl operator new[](unsigned int,struct std::nothrow_t const &))
1457 ??_V@YAXPAX@Z (void __cdecl operator delete[](void *))
1663 ??_V@YAXPAXABUnothrow_t@std@@@Z (void __cdecl operator delete[](void *,struct std::nothrow_t const &))
1218 ?DefaultImcGet@@YAKXZ (unsigned long __cdecl DefaultImcGet(void))
1219 ?DefaultImeWndGet@@YAPAUHWND__@@XZ (struct HWND__ * __cdecl DefaultImeWndGet(void))
1223 ?ImmGetUIClassName@@YAPAGXZ (unsigned short * __cdecl ImmGetUIClassName(void))
1220 ?ImmProcessKey@@YAKPAUHWND__@@IJKI@Z (unsigned long __cdecl ImmProcessKey(struct HWND__ *,unsigned int,long,unsigned long,unsigned int))
806 ?ImmSetActiveContext@@YAHPAUHWND__@@KH@Z (int __cdecl ImmSetActiveContext(struct HWND__ *,unsigned long,int))
1221 ?ImmTranslateMessage@@YAHPAUHWND__@@IIJHIIPAH@Z (int __cdecl ImmTranslateMessage(struct HWND__ *,unsigned int,unsigned int,long,int,unsigned int,unsigned int,int *))
1660 ?_Nomemory@std@@YAXXZ (void __cdecl std::_Nomemory(void))
1658 ?_Xlen@std@@YAXXZ (void __cdecl std::_Xlen(void))
1659 ?_Xran@std@@YAXXZ (void __cdecl std::_Xran(void))
1555 ?__set_inconsistency@@YAP6AXXZP6AXXZ@Z (void (__cdecl*__cdecl __set_inconsistency(void (__cdecl*)(void)))(void))
1558 ?_inconsistency@@YAXXZ (void __cdecl _inconsistency(void))
1618 ?_query_new_handler@@YAP6AHI@ZXZ (int (__cdecl*__cdecl _query_new_handler(void))(unsigned int))
1649 ?_query_new_mode@@YAHXZ (int __cdecl _query_new_mode(void))
1650 ?_set_new_handler@@YAP6AHI@ZP6AHI@Z@Z (int (__cdecl*__cdecl _set_new_handler(int (__cdecl*)(unsigned int)))(unsigned int))
1648 ?_set_new_mode@@YAHH@Z (int __cdecl _set_new_mode(int))
1647 ?nothrow@std@@3Unothrow_t@1@B (struct std::nothrow_t const std::nothrow)
1619 ?set_new_handler@@YAP6AXXZP6AXXZ@Z (void (__cdecl*__cdecl set_new_handler(void (__cdecl*)(void)))(void))
1552 ?set_terminate@std@@YAP6AXXZP6AXXZ@Z (void (__cdecl*__cdecl std::set_terminate(void (__cdecl*)(void)))(void))
1553 ?set_unexpected@std@@YAP6AXXZP6AXXZ@Z (void (__cdecl*__cdecl std::set_unexpected(void (__cdecl*)(void)))(void))
1556 ?terminate@std@@YAXXZ (void __cdecl std::terminate(void))
1557 ?unexpected@std@@YAXXZ (void __cdecl std::unexpected(void))
655 AFS_CloseAllFileHandles
644 AFS_CreateDirectoryW
648 AFS_CreateFileW
649 AFS_DeleteFileW
1685 AFS_FindFirstChangeNotificationW
651 AFS_FindFirstFileW
656 AFS_GetDiskFreeSpace
646 AFS_GetFileAttributesW
650 AFS_MoveFileW
657 AFS_NotifyMountedFS
654 AFS_PrestoChangoFileName
652 AFS_RegisterFileSystemFunction
645 AFS_RemoveDirectoryW
647 AFS_SetFileAttributesW
643 AFS_Unmount
1791 A_SHAFinal
1789 A_SHAInit
1790 A_SHAUpdate
955 AbortDoc
1540 AccessibilitySoundSentryEvent
1179 ActivateDevice
1494 ActivateDeviceEx
1766 ActivateKeyboardLayout
1508 ActivateService
558 AddEventAccess
893 AddFontResourceW
578 AddTrackedItem
887 AdjustWindowRectEx
1687 AdvertiseInterface
1453 AllKeys
1486 AllocPhysMem
842 AppendMenuW
157 AttachDebugger
376 AudioUpdateFromRegistry
297 BatteryDrvrGetLevels
298 BatteryDrvrSupportsChangeNotification
713 BatteryGetLifeTimeInfo
714 BatteryNotifyOfTimeChange
1157 BeginDeferWindowPos
260 BeginPaint
593 BinaryCompress
594 BinaryDecompress
903 BitBlt
275 BringWindowToTop
1765 CacheRangeFlush
577 CacheSync
1204 CallNextHookEx
285 CallWindowProcW
340 CeChangeDatabaseLCID
328 CeClearReplChangeBitsEx
474 CeClearUserNotification
315 CeCreateDatabase
1190 CeCreateDatabaseEx
1468 CeCreateDatabaseEx2
318 CeDeleteDatabase
1193 CeDeleteDatabaseEx
320 CeDeleteRecord
1165 CeEnumDBVolumes
479 CeEventHasOccurred
313 CeFindFirstDatabase
1196 CeFindFirstDatabaseEx
314 CeFindNextDatabase
1189 CeFindNextDatabaseEx
1217 CeFlushDBVol
1226 CeFreeNotification
1601 CeGenRandom
1395 CeGetCallerTrust
1357 CeGetCurrentTrust
1473 CeGetDBInformationByHandle
1798 CeGetFileNotificationInfo
1443 CeGetRandomSeed
326 CeGetReplChangeBitsEx
324 CeGetReplChangeMask
329 CeGetReplOtherBitsEx
622 CeGetThreadPriority
1245 CeGetThreadQuantum
1354 CeGetUserNotification
1353 CeGetUserNotificationHandles
478 CeGetUserNotificationPreferences
477 CeHandleAppNotifications
1451 CeLogData
1681 CeLogGetZones
1467 CeLogReSync
1452 CeLogSetZones
1446 CeMapArgumentArray
53 CeModuleJit
1164 CeMountDBVol
312 CeOidGetInfo
1195 CeOidGetInfoEx
1472 CeOidGetInfoEx2
317 CeOpenDatabase
1192 CeOpenDatabaseEx
1469 CeOpenDatabaseEx2
321 CeReadRecordProps
1194 CeReadRecordPropsEx
331 CeRegisterFileSystemNotification
332 CeRegisterReplNotification
894 CeRemoveFontResource
1425 CeResyncFilesys
476 CeRunAppAtEvent
475 CeRunAppAtTime
319 CeSeekDatabase
1470 CeSeekDatabaseEx
http://blog.csdn.net/stoway/archive/2007/09/05/1772867.aspx
在Windows CE下,coredll.dll的作用相当于Win32的kernel32.dll
查看API方法,在在命令行下进入dumpbin.exe 所在文件夹,输入 dumpbin /EXPORTS coredll.dll > coredlldef.txt
以下仅作备份用
File Type: LIBRARY
Exports
ordinal name
1095 ??2@YAPAXI@Z (void * __cdecl operator new(unsigned int))
1646 ??2@YAPAXIABUnothrow_t@std@@@Z (void * __cdecl operator new(unsigned int,struct std::nothrow_t const &))
1094 ??3@YAXPAX@Z (void __cdecl operator delete(void *))
1662 ??3@YAXPAXABUnothrow_t@std@@@Z (void __cdecl operator delete(void *,struct std::nothrow_t const &))
1456 ??_U@YAPAXI@Z (void * __cdecl operator new[](unsigned int))
1661 ??_U@YAPAXIABUnothrow_t@std@@@Z (void * __cdecl operator new[](unsigned int,struct std::nothrow_t const &))
1457 ??_V@YAXPAX@Z (void __cdecl operator delete[](void *))
1663 ??_V@YAXPAXABUnothrow_t@std@@@Z (void __cdecl operator delete[](void *,struct std::nothrow_t const &))
1218 ?DefaultImcGet@@YAKXZ (unsigned long __cdecl DefaultImcGet(void))
1219 ?DefaultImeWndGet@@YAPAUHWND__@@XZ (struct HWND__ * __cdecl DefaultImeWndGet(void))
1223 ?ImmGetUIClassName@@YAPAGXZ (unsigned short * __cdecl ImmGetUIClassName(void))
1220 ?ImmProcessKey@@YAKPAUHWND__@@IJKI@Z (unsigned long __cdecl ImmProcessKey(struct HWND__ *,unsigned int,long,unsigned long,unsigned int))
806 ?ImmSetActiveContext@@YAHPAUHWND__@@KH@Z (int __cdecl ImmSetActiveContext(struct HWND__ *,unsigned long,int))
1221 ?ImmTranslateMessage@@YAHPAUHWND__@@IIJHIIPAH@Z (int __cdecl ImmTranslateMessage(struct HWND__ *,unsigned int,unsigned int,long,int,unsigned int,unsigned int,int *))
1660 ?_Nomemory@std@@YAXXZ (void __cdecl std::_Nomemory(void))
1658 ?_Xlen@std@@YAXXZ (void __cdecl std::_Xlen(void))
1659 ?_Xran@std@@YAXXZ (void __cdecl std::_Xran(void))
1555 ?__set_inconsistency@@YAP6AXXZP6AXXZ@Z (void (__cdecl*__cdecl __set_inconsistency(void (__cdecl*)(void)))(void))
1558 ?_inconsistency@@YAXXZ (void __cdecl _inconsistency(void))
1618 ?_query_new_handler@@YAP6AHI@ZXZ (int (__cdecl*__cdecl _query_new_handler(void))(unsigned int))
1649 ?_query_new_mode@@YAHXZ (int __cdecl _query_new_mode(void))
1650 ?_set_new_handler@@YAP6AHI@ZP6AHI@Z@Z (int (__cdecl*__cdecl _set_new_handler(int (__cdecl*)(unsigned int)))(unsigned int))
1648 ?_set_new_mode@@YAHH@Z (int __cdecl _set_new_mode(int))
1647 ?nothrow@std@@3Unothrow_t@1@B (struct std::nothrow_t const std::nothrow)
1619 ?set_new_handler@@YAP6AXXZP6AXXZ@Z (void (__cdecl*__cdecl set_new_handler(void (__cdecl*)(void)))(void))
1552 ?set_terminate@std@@YAP6AXXZP6AXXZ@Z (void (__cdecl*__cdecl std::set_terminate(void (__cdecl*)(void)))(void))
1553 ?set_unexpected@std@@YAP6AXXZP6AXXZ@Z (void (__cdecl*__cdecl std::set_unexpected(void (__cdecl*)(void)))(void))
1556 ?terminate@std@@YAXXZ (void __cdecl std::terminate(void))
1557 ?unexpected@std@@YAXXZ (void __cdecl std::unexpected(void))
655 AFS_CloseAllFileHandles
644 AFS_CreateDirectoryW
648 AFS_CreateFileW
649 AFS_DeleteFileW
1685 AFS_FindFirstChangeNotificationW
651 AFS_FindFirstFileW
656 AFS_GetDiskFreeSpace
646 AFS_GetFileAttributesW
650 AFS_MoveFileW
657 AFS_NotifyMountedFS
654 AFS_PrestoChangoFileName
652 AFS_RegisterFileSystemFunction
645 AFS_RemoveDirectoryW
647 AFS_SetFileAttributesW
643 AFS_Unmount
1791 A_SHAFinal
1789 A_SHAInit
1790 A_SHAUpdate
955 AbortDoc
1540 AccessibilitySoundSentryEvent
1179 ActivateDevice
1494 ActivateDeviceEx
1766 ActivateKeyboardLayout
1508 ActivateService
558 AddEventAccess
893 AddFontResourceW
578 AddTrackedItem
887 AdjustWindowRectEx
1687 AdvertiseInterface
1453 AllKeys
1486 AllocPhysMem
842 AppendMenuW
157 AttachDebugger
376 AudioUpdateFromRegistry
297 BatteryDrvrGetLevels
298 BatteryDrvrSupportsChangeNotification
713 BatteryGetLifeTimeInfo
714 BatteryNotifyOfTimeChange
1157 BeginDeferWindowPos
260 BeginPaint
593 BinaryCompress
594 BinaryDecompress
903 BitBlt
275 BringWindowToTop
1765 CacheRangeFlush
577 CacheSync
1204 CallNextHookEx
285 CallWindowProcW
340 CeChangeDatabaseLCID
328 CeClearReplChangeBitsEx
474 CeClearUserNotification
315 CeCreateDatabase
1190 CeCreateDatabaseEx
1468 CeCreateDatabaseEx2
318 CeDeleteDatabase
1193 CeDeleteDatabaseEx
320 CeDeleteRecord
1165 CeEnumDBVolumes
479 CeEventHasOccurred
313 CeFindFirstDatabase
1196 CeFindFirstDatabaseEx
314 CeFindNextDatabase
1189 CeFindNextDatabaseEx
1217 CeFlushDBVol
1226 CeFreeNotification
1601 CeGenRandom
1395 CeGetCallerTrust
1357 CeGetCurrentTrust
1473 CeGetDBInformationByHandle
1798 CeGetFileNotificationInfo
1443 CeGetRandomSeed
326 CeGetReplChangeBitsEx
324 CeGetReplChangeMask
329 CeGetReplOtherBitsEx
622 CeGetThreadPriority
1245 CeGetThreadQuantum
1354 CeGetUserNotification
1353 CeGetUserNotificationHandles
478 CeGetUserNotificationPreferences
477 CeHandleAppNotifications
1451 CeLogData
1681 CeLogGetZones
1467 CeLogReSync
1452 CeLogSetZones
1446 CeMapArgumentArray
53 CeModuleJit
1164 CeMountDBVol
312 CeOidGetInfo
1195 CeOidGetInfoEx
1472 CeOidGetInfoEx2
317 CeOpenDatabase
1192 CeOpenDatabaseEx
1469 CeOpenDatabaseEx2
321 CeReadRecordProps
1194 CeReadRecordPropsEx
331 CeRegisterFileSystemNotification
332 CeRegisterReplNotification
894 CeRemoveFontResource
1425 CeResyncFilesys
476 CeRunAppAtEvent
475 CeRunAppAtTime
319 CeSeekDatabase
1470 CeSeekDatabaseEx
#2
1533 CloseMsgQueue
589 CloseProcOE
1240 ComThreadBaseFunc
968 CombineRgn
54 CompactAllHeaps
18 CompareFileTime
198 CompareStringW
633 ConnectDebugger
504 ContinueDebugEvent
210 ConvertDefaultLocale
164 CopyFileW
96 CopyRect
674 CountClipboardFormats
636 CreateAPIHandle
559 CreateAPISet
92 CreateAcceleratorTableW
901 CreateBitmap
946 CreateBitmapFromPointer
658 CreateCaret
902 CreateCompatibleBitmap
910 CreateCompatibleDC
616 CreateCrit
909 CreateDCW
929 CreateDIBPatternBrushPt
90 CreateDIBSection
245 CreateDeviceHandle
688 CreateDialogIndirectParamW
160 CreateDirectoryW
957 CreateEnhMetaFileW
495 CreateEventW
552 CreateFileForMapping
1167 CreateFileForMappingW
548 CreateFileMappingW
168 CreateFileW
895 CreateFontIndirectW
723 CreateIconIndirect
1466 CreateLocaleView
851 CreateMenu
1529 CreateMsgQueue
555 CreateMutexW
947 CreatePalette
925 CreatePatternBrush
926 CreatePen
930 CreatePenIndirect
852 CreatePopupMenu
493 CreateProcessW
980 CreateRectRgn
969 CreateRectRgnIndirect
1238 CreateSemaphoreW
1512 CreateServiceHandle
931 CreateSolidBrush
1539 CreateStaticMapping
492 CreateThread
246 CreateWindowExW
126 CryptAcquireContextW
154 CryptContextAddRef
137 CryptCreateHash
136 CryptDecrypt
129 CryptDeriveKey
140 CryptDestroyHash
130 CryptDestroyKey
156 CryptDuplicateHash
155 CryptDuplicateKey
135 CryptEncrypt
152 CryptEnumProviderTypesW
153 CryptEnumProvidersW
133 CryptExportKey
128 CryptGenKey
143 CryptGenRandom
151 CryptGetDefaultProviderW
146 CryptGetHashParam
132 CryptGetKeyParam
148 CryptGetProvParam
144 CryptGetUserKey
139 CryptHashData
138 CryptHashSessionKey
134 CryptImportKey
1599 CryptProtectData
127 CryptReleaseContext
147 CryptSetHashParam
131 CryptSetKeyParam
149 CryptSetProvParam
150 CryptSetProviderExW
145 CryptSetProviderW
141 CryptSignHashW
1600 CryptUnprotectData
142 CryptVerifySignatureW
233 DBCanonicalize
1669 DDKReg_GetIsrInfo
1670 DDKReg_GetPciInfo
1668 DDKReg_GetWindowInfo
1180 DeactivateDevice
505 DebugActiveProcess
642 DebugNotify
1776 DecompressBinaryBlock
689 DefDlgProcW
264 DefWindowProcW
1158 DeferWindowPos
183 DeleteAndRenameFile
3 DeleteCriticalSection
911 DeleteDC
958 DeleteEnhMetaFile
165 DeleteFileW
850 DeleteMenu
912 DeleteObject
579 DeleteTrackedItem
335 DeregisterAFS
339 DeregisterAFSName
236 DeregisterDevice
1510 DeregisterService
93 DestroyAcceleratorTable
659 DestroyCaret
725 DestroyIcon
844 DestroyMenu
265 DestroyWindow
179 DeviceIoControl
1588 DevicePowerNotify
690 DialogBoxIndirectParamW
666 DisableCaretSystemWide
1232 DisableThreadLibraryCalls
859 DispatchMessageW
932 DrawEdge
933 DrawFocusRect
987 DrawFrameControl
726 DrawIconEx
856 DrawMenuBar
945 DrawTextW
341 DumpFileSystemHeap
510 DumpKCallProfile
1535 DuplicateHandle
934 Ellipse
677 EmptyClipboard
667 EnableCaretSystemWide
986 EnableEUDC
825 EnableHardwareKeyboard
847 EnableMenuItem
287 EnableWindow
1159 EndDeferWindowPos
691 EndDialog
959 EndDoc
960 EndPage
261 EndPaint
4 EnterCriticalSection
206 EnumCalendarInfoW
675 EnumClipboardFormats
208 EnumDateFormatsW
124 EnumDevices
1778 EnumDisplayDevices
1526 EnumDisplayMonitors
1777 EnumDisplaySettings
965 EnumFontFamiliesW
316 CeSetDatabaseInfo
1191 CeSetDatabaseInfoEx
1471 CeSetDatabaseInfoEx2
1455 CeSetExtendedPdata
1688 CeSetPowerOnEvent
1775 CeSetProcessVersion
327 CeSetReplChangeBitsEx
325 CeSetReplChangeMask
330 CeSetReplOtherBitsEx
621 CeSetThreadPriority
1244 CeSetThreadQuantum
473 CeSetUserNotification
1352 CeSetUserNotificationEx
1197 CeUnmountDBVol
322 CeWriteRecordProps
1781 CeZeroPointer
1611 ChangeDisplaySettingsEx
222 CharLowerBuffW
221 CharLowerW
226 CharNextW
225 CharPrevW
223 CharUpperBuffW
224 CharUpperW
848 CheckMenuItem
849 CheckMenuRadioItem
182 CheckPassword
684 CheckRadioButton
253 ChildWindowFromPoint
107 ClearCommBreak
108 ClearCommError
254 ClientToScreen
731 ClipCursor
244 CloseAllDeviceHandles
242 CloseAllFileHandles
1511 CloseAllServiceHandles
669 CloseClipboard
956 CloseEnhMetaFile
553 CloseHandle
966 EnumFontsW
123 EnumPnpIds
1500 EnumPropsEx
1517 EnumServices
220 EnumSystemCodePagesW
219 EnumSystemLocalesW
207 EnumTimeFormatsW
1320 EnumUILanguagesW
291 EnumWindows
97 EqualRect
91 EqualRgn
109 EscapeCommFunction
494 EventModify
970 ExcludeClipRect
6 ExitThread
1617 ExtCreateRegion
1182 ExtEscape
896 ExtTextOutW
727 ExtractIconExW
573 ExtractResource
241 FileSystemPowerFunction
21 FileTimeToLocalFileTime
20 FileTimeToSystemTime
935 FillRect
927 FillRgn
585 FilterTrackedItem
180 FindClose
1684 FindCloseChangeNotification
1682 FindFirstChangeNotificationW
1235 FindFirstFileExW
167 FindFirstFileW
1683 FindNextChangeNotification
181 FindNextFileW
531 FindResource
532 FindResourceW
286 FindWindowW
175 FlushFileBuffers
508 FlushInstructionCache
551 FlushViewOfFile
1215 FlushViewOfFileMaybe
218 FoldStringW
540 ForcePageout
234 FormatMessageW
1476 FreeIntChainHandler
529 FreeLibrary
1216 FreeLibraryAndExitThread
1487 FreePhysMem
186 GetACP
32 GetAPIAddress
706 GetActiveWindow
300 GetAssociatedMenu
826 GetAsyncKeyState
834 GetAsyncShiftFlags
913 GetBkColor
914 GetBkMode
188 GetCPInfo
1228 GetCRTFlags
1227 GetCRTStorageEx
1760 GetCallStackSnapshot
607 GetCallerProcess
641 GetCallerProcessIndex
707 GetCapture
665 GetCaretBlinkTime
663 GetCaretPos
1779 GetCharABCWidths
1664 GetCharWidth32
878 GetClassInfoW
881 GetClassLong
879 GetClassLongW
283 GetClassNameW
249 GetClientRect
971 GetClipBox
732 GetClipCursor
972 GetClipRgn
672 GetClipboardData
681 GetClipboardDataAlloc
676 GetClipboardFormatNameW
670 GetClipboardOwner
110 GetCommMask
111 GetCommModemStatus
112 GetCommProperties
113 GetCommState
114 GetCommTimeouts
1231 GetCommandLineW
205 GetCurrencyFormatW
29 GetCurrentFT
915 GetCurrentObject
612 GetCurrentPermissions
1653 GetCurrentPositionEx
733 GetCursor
734 GetCursorPos
262 GetDC
1185 GetDCEx
1665 GetDIBColorTable
203 GetDateFormatW
1397 GetDesktopWindow
1236 GetDeviceByIndex
916 GetDeviceCaps
125 GetDeviceKeys
1679 GetDevicePower
694 GetDialogBaseUnits
184 GetDiskFreeSpaceExW
693 GetDlgCtrlID
692 GetDlgItem
695 GetDlgItemInt
687 GetDlgItemTextW
888 GetDoubleClickTime
1527 GetEventData
519 GetExitCodeProcess
518 GetExitCodeThread
603 GetFSHeapInfo
1237 GetFileAttributesExW
166 GetFileAttributesW
174 GetFileInformationByHandle
172 GetFileSize
176 GetFileTime
1461 GetFileVersionInfoSizeW
1460 GetFileVersionInfoW
705 GetFocus
1224 GetForegroundInfo
1802 GetForegroundKeyboardLayoutHandle
1225 GetForegroundKeyboardTarget
701 GetForegroundWindow
52 GetHeapSnapshot
608 GetIdleTime
581 GetKPhys
860 GetKeyState
1229 GetKeyboardLayout
1767 GetKeyboardLayoutList
1160 GetKeyboardLayoutNameW
827 GetKeyboardStatus
711 GetKeyboardTarget
1771 GetKeyboardType
516 GetLastError
23 GetLocalTime
200 GetLocaleInfoW
854 GetMenuItemInfoW
862 GetMessagePos
1477 GetMessageQueueReadyTimeStamp
872 GetMessageSource
861 GetMessageW
863 GetMessageWNoWait
537 GetModuleFileNameW
1177 GetModuleHandleW
1721 GetModuleInformation
1525 GetMonitorInfo
820 GetMouseMovePoints
1532 GetMsgQueueInfo
952 GetNearestColor
948 GetNearestPaletteIndex
697 GetNextDlgGroupItem
696 GetNextDlgTabItem
204 GetNumberFormatW
187 GetOEMCP
917 GetObjectType
918 GetObjectW
680 GetOpenClipboardWindow
488 GetOpenFileNameW
606 GetOwnerProcess
949 GetPaletteEntries
269 GetParent
239 GetPasswordActive
1538 GetPasswordStatus
936 GetPixel
679 GetPriorityClipboardFormat
1400 GetPrivateCallbacks
#3
602 GetProcAddrBits
1230 GetProcAddressA
530 GetProcAddressW
600 GetProcFromPtr
624 GetProcName
50 GetProcessHeap
1727 GetProcessIDFromIndex
640 GetProcessIndexFromID
536 GetProcessVersion
1498 GetProp
1420 GetQueueStatus
570 GetRealTime
973 GetRegionData
974 GetRgnBox
576 GetRomFileBytes
575 GetRomFileInfo
489 GetSaveFileNameW
282 GetScrollInfo
1513 GetServiceByIndex
1518 GetServiceHandle
1149 GetStdioPathW
919 GetStockObject
323 GetStoreInformation
217 GetStringTypeExW
216 GetStringTypeW
855 GetSubMenu
889 GetSysColor
937 GetSysColorBrush
213 GetSystemDefaultLCID
211 GetSystemDefaultLangID
1317 GetSystemDefaultUILanguage
542 GetSystemInfo
336 GetSystemMemoryDivision
885 GetSystemMetrics
950 GetSystemPaletteEntries
1581 GetSystemPowerState
715 GetSystemPowerStatusEx
1358 GetSystemPowerStatusEx2
25 GetSystemTime
1234 GetTempFileNameW
162 GetTempPathW
1655 GetTextAlign
920 GetTextColor
897 GetTextExtentExPointW
967 GetTextFaceW
898 GetTextMetricsW
1148 GetThreadContext
515 GetThreadPriority
1186 GetThreadTimes
535 GetTickCount
202 GetTimeFormatW
27 GetTimeZoneInformation
274 GetUpdateRect
273 GetUpdateRgn
215 GetUserDefaultLCID
212 GetUserDefaultLangID
1318 GetUserDefaultUILanguage
1686 GetUserDirectory
1503 GetUserNameExW
17 GetVersionEx
717 GetVersionExW
251 GetWindow
270 GetWindowDC
259 GetWindowLongW
248 GetWindowRect
1399 GetWindowRgn
276 GetWindowTextLengthW
257 GetWindowTextW
1454 GetWindowTextWDirect
292 GetWindowThreadProcessId
582 GiveKPhys
1519 GlobalAddAtomW
1520 GlobalDeleteAtom
1521 GlobalFindAtomW
88 GlobalMemoryStatus
1763 GradientFill
1722 GwesPowerDown
296 GwesPowerOffSystem
1723 GwesPowerUp
46 HeapAlloc
HeapAllocTrace
44 HeapCreate
45 HeapDestroy
49 HeapFree
47 HeapReAlloc
48 HeapSize
51 HeapValidate
660 HideCaret
738 ImageList_Add
739 ImageList_AddMasked
740 ImageList_BeginDrag
767 ImageList_Copy
741 ImageList_CopyDitherImage
742 ImageList_Create
743 ImageList_Destroy
744 ImageList_DragEnter
745 ImageList_DragLeave
746 ImageList_DragMove
747 ImageList_DragShowNolock
748 ImageList_Draw
749 ImageList_DrawEx
750 ImageList_DrawIndirect
768 ImageList_Duplicate
751 ImageList_EndDrag
752 ImageList_GetBkColor
753 ImageList_GetDragImage
754 ImageList_GetIcon
755 ImageList_GetIconSize
756 ImageList_GetImageCount
757 ImageList_GetImageInfo
758 ImageList_LoadImage
759 ImageList_Merge
760 ImageList_Remove
761 ImageList_Replace
762 ImageList_ReplaceIcon
763 ImageList_SetBkColor
764 ImageList_SetDragCursorImage
765 ImageList_SetIconSize
769 ImageList_SetImageCount
766 ImageList_SetOverlayImage
770 ImmAssociateContext
1205 ImmAssociateContextEx
771 ImmConfigureIMEW
1198 ImmCreateContext
772 ImmCreateIMCC
1199 ImmDestroyContext
773 ImmDestroyIMCC
1206 ImmDisableIME
1541 ImmEnableIME
774 ImmEnumRegisterWordW
775 ImmEscapeW
776 ImmGenerateMessage
778 ImmGetCandidateListCountW
777 ImmGetCandidateListW
779 ImmGetCandidateWindow
780 ImmGetCompositionFontW
781 ImmGetCompositionStringW
782 ImmGetCompositionWindow
783 ImmGetContext
784 ImmGetConversionListW
785 ImmGetConversionStatus
786 ImmGetDefaultIMEWnd
787 ImmGetDescriptionW
788 ImmGetGuideLineW
813 ImmGetHotKey
789 ImmGetIMCCLockCount
790 ImmGetIMCCSize
791 ImmGetIMCLockCount
1207 ImmGetIMEFileNameW
1211 ImmGetImeMenuItemsW
1769 ImmGetKeyboardLayout
792 ImmGetOpenStatus
793 ImmGetProperty
794 ImmGetRegisterWordStyleW
1200 ImmGetStatusWindowPos
1210 ImmGetVirtualKey
1209 ImmIsIME
796 ImmIsUIMessageW
797 ImmLockIMC
798 ImmLockIMCC
800 ImmNotifyIME
801 ImmReSizeIMCC
802 ImmRegisterWordW
803 ImmReleaseContext
1242 ImmRequestMessageW
804 ImmSIPanelState
807 ImmSetCandidateWindow
808 ImmSetCompositionFontW
809 ImmSetCompositionStringW
810 ImmSetCompositionWindow
811 ImmSetConversionStatus
812 ImmSetHotKey
1222 ImmSetImeWndIMC
814 ImmSetOpenStatus
815 ImmSetStatusWindowPos
816 ImmSimulateHotKey
817 ImmUnlockIMC
818 ImmUnlockIMCC
819 ImmUnregisterWordW
1419 InSendMessage
98 InflateRect
8 InitLocale
2 InitializeCriticalSection
595 InputDebugCharW
841 InsertMenuW
1762 Int_CloseHandle
1761 Int_CreateEventW
Int_HeapAlloc
Int_HeapCreate
Int_HeapDestroy
Int_HeapFree
Int_HeapReAlloc
Int_HeapSize
1492 InterlockedCompareExchange
11 InterlockedDecrement
12 InterlockedExchange
1491 InterlockedExchangeAdd
10 InterlockedIncrement
9 InterlockedTestExchange
629 InterruptDisable
628 InterruptDone
627 InterruptInitialize
1797 InterruptMask
975 IntersectClipRect
99 IntersectRect
250 InvalidateRect
1615 InvalidateRgn
1770 InvertRect
30 IsAPIReady
521 IsBadCodePtr
601 IsBadPtr
522 IsBadReadPtr
523 IsBadWritePtr
277 IsChild
678 IsClipboardFormatAvailable
191 IsDBCSLeadByte
192 IsDBCSLeadByteEx
698 IsDialogMessageW
613 IsEncryptionPermitted
159 IsExiting
610 IsPrimaryThread
1213 IsProcessDying
1758 IsProcessorFeaturePresent
100 IsRectEmpty
1680 IsSystemFile
185 IsValidCodePage
209 IsValidLocale
271 IsWindow
288 IsWindowEnabled
886 IsWindowVisible
574 KernExtractIcons
557 KernelIoControl
1489 KernelLibIoControl
828 KeybdGetDeviceInfo
829 KeybdInitStates
830 KeybdVKeyToUnicode
605 KillAllOtherThreads
876 KillTimer
199 LCMapStringW
597 LeaveCritSec
5 LeaveCriticalSection
1652 LineTo
94 LoadAcceleratorsW
1493 LoadAnimatedCursor
873 LoadBitmapW
683 LoadCursorW
626 LoadDriver
237 LoadFSD
1421 LoadFSDEx
728 LoadIconW
730 LoadImageW
1475 LoadIntChainHandler
1671 LoadKernelLibrary
1768 LoadKeyboardLayoutW
1241 LoadLibraryExW
528 LoadLibraryW
846 LoadMenuW
533 LoadResource
874 LoadStringW
33 LocalAlloc
41 LocalAllocInProcess
LocalAllocTrace
22 LocalFileTimeToFileTime
36 LocalFree
42 LocalFreeInProcess
34 LocalReAlloc
35 LocalSize
43 LocalSizeInProcess
1161 LockPages
1794 MD5Final
1792 MD5Init
1793 MD5Update
14 MainThreadBaseFunc
1602 MapCallerPtr
699 MapDialogRect
1603 MapPtrToProcWithSize
598 MapPtrToProcess
599 MapPtrUnsecure
549 MapViewOfFile
831 MapVirtualKeyW
284 MapWindowPoints
904 MaskBlt
857 MessageBeep
858 MessageBoxW
1522 MonitorFromPoint
1523 MonitorFromRect
1524 MonitorFromWindow
163 MoveFileW
1651 MoveToEx
272 MoveWindow
871 MsgWaitForMultipleObjectsEx
196 MultiByteToWideChar
545 NKDbgPrintfW
623 NKTerminateThread
568 NKvDbgPrintfW
839 NLedGetDeviceInfo
840 NLedSetDevice
513 NotifyForceCleanboot
716 NotifyWinUserSystem
101 OffsetRect
976 OffsetRgn
668 OpenClipboard
1396 OpenDeviceKey
1496 OpenEventW
1536 OpenMsgQueue
509 OpenProcess
604 OtherThreadsRunning
541 OutputDebugStringW
638 PPSHRestart
7 PSLNotify
1780 PageOutModule
938 PatBlt
864 PeekMessageW
468 PegClearUserNotification
304 PegCreateDatabase
307 PegDeleteDatabase
309 PegDeleteRecord
302 PegFindFirstDatabase
303 PegFindNextDatabase
472 PegGetUserNotificationPreferences
471 PegHandleAppNotifications
301 PegOidGetInfo
306 PegOpenDatabase
310 PegReadRecordProps
899 PegRemoveFontResource
470 PegRunAppAtEvent
469 PegRunAppAtTime
308 PegSeekDatabase
305 PegSetDatabaseInfo
467 PegSetUserNotification
311 PegWriteRecordProps
1448 PerformCallBack4
961 PlayEnhMetaFile
378 PlaySoundW
939 Polygon
940 Polyline
832 PostKeybdMessage
865 PostMessageW
866 PostQuitMessage
290 PostThreadMessageW
617 PowerOffSystem
1764 PowerPolicyNotify
580 PrintTrackedItem
572 ProcessDetachAllDLLs
1800 ProfileCaptureStatus
82 ProfileStart
1801 ProfileStartEx
83 ProfileStop
569 ProfileSyscall
102 PtInRect
977 PtInRegion
115 PurgeComm
821 QASetWindowsJournalHook
#4
关注一下钩子的问题
可以用idapro5 分析coredll,
可以用idapro5 分析coredll,
#1
顺便转贴一个coredll中所有API的列表:
http://blog.csdn.net/stoway/archive/2007/09/05/1772867.aspx
在Windows CE下,coredll.dll的作用相当于Win32的kernel32.dll
查看API方法,在在命令行下进入dumpbin.exe 所在文件夹,输入 dumpbin /EXPORTS coredll.dll > coredlldef.txt
以下仅作备份用
File Type: LIBRARY
Exports
ordinal name
1095 ??2@YAPAXI@Z (void * __cdecl operator new(unsigned int))
1646 ??2@YAPAXIABUnothrow_t@std@@@Z (void * __cdecl operator new(unsigned int,struct std::nothrow_t const &))
1094 ??3@YAXPAX@Z (void __cdecl operator delete(void *))
1662 ??3@YAXPAXABUnothrow_t@std@@@Z (void __cdecl operator delete(void *,struct std::nothrow_t const &))
1456 ??_U@YAPAXI@Z (void * __cdecl operator new[](unsigned int))
1661 ??_U@YAPAXIABUnothrow_t@std@@@Z (void * __cdecl operator new[](unsigned int,struct std::nothrow_t const &))
1457 ??_V@YAXPAX@Z (void __cdecl operator delete[](void *))
1663 ??_V@YAXPAXABUnothrow_t@std@@@Z (void __cdecl operator delete[](void *,struct std::nothrow_t const &))
1218 ?DefaultImcGet@@YAKXZ (unsigned long __cdecl DefaultImcGet(void))
1219 ?DefaultImeWndGet@@YAPAUHWND__@@XZ (struct HWND__ * __cdecl DefaultImeWndGet(void))
1223 ?ImmGetUIClassName@@YAPAGXZ (unsigned short * __cdecl ImmGetUIClassName(void))
1220 ?ImmProcessKey@@YAKPAUHWND__@@IJKI@Z (unsigned long __cdecl ImmProcessKey(struct HWND__ *,unsigned int,long,unsigned long,unsigned int))
806 ?ImmSetActiveContext@@YAHPAUHWND__@@KH@Z (int __cdecl ImmSetActiveContext(struct HWND__ *,unsigned long,int))
1221 ?ImmTranslateMessage@@YAHPAUHWND__@@IIJHIIPAH@Z (int __cdecl ImmTranslateMessage(struct HWND__ *,unsigned int,unsigned int,long,int,unsigned int,unsigned int,int *))
1660 ?_Nomemory@std@@YAXXZ (void __cdecl std::_Nomemory(void))
1658 ?_Xlen@std@@YAXXZ (void __cdecl std::_Xlen(void))
1659 ?_Xran@std@@YAXXZ (void __cdecl std::_Xran(void))
1555 ?__set_inconsistency@@YAP6AXXZP6AXXZ@Z (void (__cdecl*__cdecl __set_inconsistency(void (__cdecl*)(void)))(void))
1558 ?_inconsistency@@YAXXZ (void __cdecl _inconsistency(void))
1618 ?_query_new_handler@@YAP6AHI@ZXZ (int (__cdecl*__cdecl _query_new_handler(void))(unsigned int))
1649 ?_query_new_mode@@YAHXZ (int __cdecl _query_new_mode(void))
1650 ?_set_new_handler@@YAP6AHI@ZP6AHI@Z@Z (int (__cdecl*__cdecl _set_new_handler(int (__cdecl*)(unsigned int)))(unsigned int))
1648 ?_set_new_mode@@YAHH@Z (int __cdecl _set_new_mode(int))
1647 ?nothrow@std@@3Unothrow_t@1@B (struct std::nothrow_t const std::nothrow)
1619 ?set_new_handler@@YAP6AXXZP6AXXZ@Z (void (__cdecl*__cdecl set_new_handler(void (__cdecl*)(void)))(void))
1552 ?set_terminate@std@@YAP6AXXZP6AXXZ@Z (void (__cdecl*__cdecl std::set_terminate(void (__cdecl*)(void)))(void))
1553 ?set_unexpected@std@@YAP6AXXZP6AXXZ@Z (void (__cdecl*__cdecl std::set_unexpected(void (__cdecl*)(void)))(void))
1556 ?terminate@std@@YAXXZ (void __cdecl std::terminate(void))
1557 ?unexpected@std@@YAXXZ (void __cdecl std::unexpected(void))
655 AFS_CloseAllFileHandles
644 AFS_CreateDirectoryW
648 AFS_CreateFileW
649 AFS_DeleteFileW
1685 AFS_FindFirstChangeNotificationW
651 AFS_FindFirstFileW
656 AFS_GetDiskFreeSpace
646 AFS_GetFileAttributesW
650 AFS_MoveFileW
657 AFS_NotifyMountedFS
654 AFS_PrestoChangoFileName
652 AFS_RegisterFileSystemFunction
645 AFS_RemoveDirectoryW
647 AFS_SetFileAttributesW
643 AFS_Unmount
1791 A_SHAFinal
1789 A_SHAInit
1790 A_SHAUpdate
955 AbortDoc
1540 AccessibilitySoundSentryEvent
1179 ActivateDevice
1494 ActivateDeviceEx
1766 ActivateKeyboardLayout
1508 ActivateService
558 AddEventAccess
893 AddFontResourceW
578 AddTrackedItem
887 AdjustWindowRectEx
1687 AdvertiseInterface
1453 AllKeys
1486 AllocPhysMem
842 AppendMenuW
157 AttachDebugger
376 AudioUpdateFromRegistry
297 BatteryDrvrGetLevels
298 BatteryDrvrSupportsChangeNotification
713 BatteryGetLifeTimeInfo
714 BatteryNotifyOfTimeChange
1157 BeginDeferWindowPos
260 BeginPaint
593 BinaryCompress
594 BinaryDecompress
903 BitBlt
275 BringWindowToTop
1765 CacheRangeFlush
577 CacheSync
1204 CallNextHookEx
285 CallWindowProcW
340 CeChangeDatabaseLCID
328 CeClearReplChangeBitsEx
474 CeClearUserNotification
315 CeCreateDatabase
1190 CeCreateDatabaseEx
1468 CeCreateDatabaseEx2
318 CeDeleteDatabase
1193 CeDeleteDatabaseEx
320 CeDeleteRecord
1165 CeEnumDBVolumes
479 CeEventHasOccurred
313 CeFindFirstDatabase
1196 CeFindFirstDatabaseEx
314 CeFindNextDatabase
1189 CeFindNextDatabaseEx
1217 CeFlushDBVol
1226 CeFreeNotification
1601 CeGenRandom
1395 CeGetCallerTrust
1357 CeGetCurrentTrust
1473 CeGetDBInformationByHandle
1798 CeGetFileNotificationInfo
1443 CeGetRandomSeed
326 CeGetReplChangeBitsEx
324 CeGetReplChangeMask
329 CeGetReplOtherBitsEx
622 CeGetThreadPriority
1245 CeGetThreadQuantum
1354 CeGetUserNotification
1353 CeGetUserNotificationHandles
478 CeGetUserNotificationPreferences
477 CeHandleAppNotifications
1451 CeLogData
1681 CeLogGetZones
1467 CeLogReSync
1452 CeLogSetZones
1446 CeMapArgumentArray
53 CeModuleJit
1164 CeMountDBVol
312 CeOidGetInfo
1195 CeOidGetInfoEx
1472 CeOidGetInfoEx2
317 CeOpenDatabase
1192 CeOpenDatabaseEx
1469 CeOpenDatabaseEx2
321 CeReadRecordProps
1194 CeReadRecordPropsEx
331 CeRegisterFileSystemNotification
332 CeRegisterReplNotification
894 CeRemoveFontResource
1425 CeResyncFilesys
476 CeRunAppAtEvent
475 CeRunAppAtTime
319 CeSeekDatabase
1470 CeSeekDatabaseEx
http://blog.csdn.net/stoway/archive/2007/09/05/1772867.aspx
在Windows CE下,coredll.dll的作用相当于Win32的kernel32.dll
查看API方法,在在命令行下进入dumpbin.exe 所在文件夹,输入 dumpbin /EXPORTS coredll.dll > coredlldef.txt
以下仅作备份用
File Type: LIBRARY
Exports
ordinal name
1095 ??2@YAPAXI@Z (void * __cdecl operator new(unsigned int))
1646 ??2@YAPAXIABUnothrow_t@std@@@Z (void * __cdecl operator new(unsigned int,struct std::nothrow_t const &))
1094 ??3@YAXPAX@Z (void __cdecl operator delete(void *))
1662 ??3@YAXPAXABUnothrow_t@std@@@Z (void __cdecl operator delete(void *,struct std::nothrow_t const &))
1456 ??_U@YAPAXI@Z (void * __cdecl operator new[](unsigned int))
1661 ??_U@YAPAXIABUnothrow_t@std@@@Z (void * __cdecl operator new[](unsigned int,struct std::nothrow_t const &))
1457 ??_V@YAXPAX@Z (void __cdecl operator delete[](void *))
1663 ??_V@YAXPAXABUnothrow_t@std@@@Z (void __cdecl operator delete[](void *,struct std::nothrow_t const &))
1218 ?DefaultImcGet@@YAKXZ (unsigned long __cdecl DefaultImcGet(void))
1219 ?DefaultImeWndGet@@YAPAUHWND__@@XZ (struct HWND__ * __cdecl DefaultImeWndGet(void))
1223 ?ImmGetUIClassName@@YAPAGXZ (unsigned short * __cdecl ImmGetUIClassName(void))
1220 ?ImmProcessKey@@YAKPAUHWND__@@IJKI@Z (unsigned long __cdecl ImmProcessKey(struct HWND__ *,unsigned int,long,unsigned long,unsigned int))
806 ?ImmSetActiveContext@@YAHPAUHWND__@@KH@Z (int __cdecl ImmSetActiveContext(struct HWND__ *,unsigned long,int))
1221 ?ImmTranslateMessage@@YAHPAUHWND__@@IIJHIIPAH@Z (int __cdecl ImmTranslateMessage(struct HWND__ *,unsigned int,unsigned int,long,int,unsigned int,unsigned int,int *))
1660 ?_Nomemory@std@@YAXXZ (void __cdecl std::_Nomemory(void))
1658 ?_Xlen@std@@YAXXZ (void __cdecl std::_Xlen(void))
1659 ?_Xran@std@@YAXXZ (void __cdecl std::_Xran(void))
1555 ?__set_inconsistency@@YAP6AXXZP6AXXZ@Z (void (__cdecl*__cdecl __set_inconsistency(void (__cdecl*)(void)))(void))
1558 ?_inconsistency@@YAXXZ (void __cdecl _inconsistency(void))
1618 ?_query_new_handler@@YAP6AHI@ZXZ (int (__cdecl*__cdecl _query_new_handler(void))(unsigned int))
1649 ?_query_new_mode@@YAHXZ (int __cdecl _query_new_mode(void))
1650 ?_set_new_handler@@YAP6AHI@ZP6AHI@Z@Z (int (__cdecl*__cdecl _set_new_handler(int (__cdecl*)(unsigned int)))(unsigned int))
1648 ?_set_new_mode@@YAHH@Z (int __cdecl _set_new_mode(int))
1647 ?nothrow@std@@3Unothrow_t@1@B (struct std::nothrow_t const std::nothrow)
1619 ?set_new_handler@@YAP6AXXZP6AXXZ@Z (void (__cdecl*__cdecl set_new_handler(void (__cdecl*)(void)))(void))
1552 ?set_terminate@std@@YAP6AXXZP6AXXZ@Z (void (__cdecl*__cdecl std::set_terminate(void (__cdecl*)(void)))(void))
1553 ?set_unexpected@std@@YAP6AXXZP6AXXZ@Z (void (__cdecl*__cdecl std::set_unexpected(void (__cdecl*)(void)))(void))
1556 ?terminate@std@@YAXXZ (void __cdecl std::terminate(void))
1557 ?unexpected@std@@YAXXZ (void __cdecl std::unexpected(void))
655 AFS_CloseAllFileHandles
644 AFS_CreateDirectoryW
648 AFS_CreateFileW
649 AFS_DeleteFileW
1685 AFS_FindFirstChangeNotificationW
651 AFS_FindFirstFileW
656 AFS_GetDiskFreeSpace
646 AFS_GetFileAttributesW
650 AFS_MoveFileW
657 AFS_NotifyMountedFS
654 AFS_PrestoChangoFileName
652 AFS_RegisterFileSystemFunction
645 AFS_RemoveDirectoryW
647 AFS_SetFileAttributesW
643 AFS_Unmount
1791 A_SHAFinal
1789 A_SHAInit
1790 A_SHAUpdate
955 AbortDoc
1540 AccessibilitySoundSentryEvent
1179 ActivateDevice
1494 ActivateDeviceEx
1766 ActivateKeyboardLayout
1508 ActivateService
558 AddEventAccess
893 AddFontResourceW
578 AddTrackedItem
887 AdjustWindowRectEx
1687 AdvertiseInterface
1453 AllKeys
1486 AllocPhysMem
842 AppendMenuW
157 AttachDebugger
376 AudioUpdateFromRegistry
297 BatteryDrvrGetLevels
298 BatteryDrvrSupportsChangeNotification
713 BatteryGetLifeTimeInfo
714 BatteryNotifyOfTimeChange
1157 BeginDeferWindowPos
260 BeginPaint
593 BinaryCompress
594 BinaryDecompress
903 BitBlt
275 BringWindowToTop
1765 CacheRangeFlush
577 CacheSync
1204 CallNextHookEx
285 CallWindowProcW
340 CeChangeDatabaseLCID
328 CeClearReplChangeBitsEx
474 CeClearUserNotification
315 CeCreateDatabase
1190 CeCreateDatabaseEx
1468 CeCreateDatabaseEx2
318 CeDeleteDatabase
1193 CeDeleteDatabaseEx
320 CeDeleteRecord
1165 CeEnumDBVolumes
479 CeEventHasOccurred
313 CeFindFirstDatabase
1196 CeFindFirstDatabaseEx
314 CeFindNextDatabase
1189 CeFindNextDatabaseEx
1217 CeFlushDBVol
1226 CeFreeNotification
1601 CeGenRandom
1395 CeGetCallerTrust
1357 CeGetCurrentTrust
1473 CeGetDBInformationByHandle
1798 CeGetFileNotificationInfo
1443 CeGetRandomSeed
326 CeGetReplChangeBitsEx
324 CeGetReplChangeMask
329 CeGetReplOtherBitsEx
622 CeGetThreadPriority
1245 CeGetThreadQuantum
1354 CeGetUserNotification
1353 CeGetUserNotificationHandles
478 CeGetUserNotificationPreferences
477 CeHandleAppNotifications
1451 CeLogData
1681 CeLogGetZones
1467 CeLogReSync
1452 CeLogSetZones
1446 CeMapArgumentArray
53 CeModuleJit
1164 CeMountDBVol
312 CeOidGetInfo
1195 CeOidGetInfoEx
1472 CeOidGetInfoEx2
317 CeOpenDatabase
1192 CeOpenDatabaseEx
1469 CeOpenDatabaseEx2
321 CeReadRecordProps
1194 CeReadRecordPropsEx
331 CeRegisterFileSystemNotification
332 CeRegisterReplNotification
894 CeRemoveFontResource
1425 CeResyncFilesys
476 CeRunAppAtEvent
475 CeRunAppAtTime
319 CeSeekDatabase
1470 CeSeekDatabaseEx
#2
1533 CloseMsgQueue
589 CloseProcOE
1240 ComThreadBaseFunc
968 CombineRgn
54 CompactAllHeaps
18 CompareFileTime
198 CompareStringW
633 ConnectDebugger
504 ContinueDebugEvent
210 ConvertDefaultLocale
164 CopyFileW
96 CopyRect
674 CountClipboardFormats
636 CreateAPIHandle
559 CreateAPISet
92 CreateAcceleratorTableW
901 CreateBitmap
946 CreateBitmapFromPointer
658 CreateCaret
902 CreateCompatibleBitmap
910 CreateCompatibleDC
616 CreateCrit
909 CreateDCW
929 CreateDIBPatternBrushPt
90 CreateDIBSection
245 CreateDeviceHandle
688 CreateDialogIndirectParamW
160 CreateDirectoryW
957 CreateEnhMetaFileW
495 CreateEventW
552 CreateFileForMapping
1167 CreateFileForMappingW
548 CreateFileMappingW
168 CreateFileW
895 CreateFontIndirectW
723 CreateIconIndirect
1466 CreateLocaleView
851 CreateMenu
1529 CreateMsgQueue
555 CreateMutexW
947 CreatePalette
925 CreatePatternBrush
926 CreatePen
930 CreatePenIndirect
852 CreatePopupMenu
493 CreateProcessW
980 CreateRectRgn
969 CreateRectRgnIndirect
1238 CreateSemaphoreW
1512 CreateServiceHandle
931 CreateSolidBrush
1539 CreateStaticMapping
492 CreateThread
246 CreateWindowExW
126 CryptAcquireContextW
154 CryptContextAddRef
137 CryptCreateHash
136 CryptDecrypt
129 CryptDeriveKey
140 CryptDestroyHash
130 CryptDestroyKey
156 CryptDuplicateHash
155 CryptDuplicateKey
135 CryptEncrypt
152 CryptEnumProviderTypesW
153 CryptEnumProvidersW
133 CryptExportKey
128 CryptGenKey
143 CryptGenRandom
151 CryptGetDefaultProviderW
146 CryptGetHashParam
132 CryptGetKeyParam
148 CryptGetProvParam
144 CryptGetUserKey
139 CryptHashData
138 CryptHashSessionKey
134 CryptImportKey
1599 CryptProtectData
127 CryptReleaseContext
147 CryptSetHashParam
131 CryptSetKeyParam
149 CryptSetProvParam
150 CryptSetProviderExW
145 CryptSetProviderW
141 CryptSignHashW
1600 CryptUnprotectData
142 CryptVerifySignatureW
233 DBCanonicalize
1669 DDKReg_GetIsrInfo
1670 DDKReg_GetPciInfo
1668 DDKReg_GetWindowInfo
1180 DeactivateDevice
505 DebugActiveProcess
642 DebugNotify
1776 DecompressBinaryBlock
689 DefDlgProcW
264 DefWindowProcW
1158 DeferWindowPos
183 DeleteAndRenameFile
3 DeleteCriticalSection
911 DeleteDC
958 DeleteEnhMetaFile
165 DeleteFileW
850 DeleteMenu
912 DeleteObject
579 DeleteTrackedItem
335 DeregisterAFS
339 DeregisterAFSName
236 DeregisterDevice
1510 DeregisterService
93 DestroyAcceleratorTable
659 DestroyCaret
725 DestroyIcon
844 DestroyMenu
265 DestroyWindow
179 DeviceIoControl
1588 DevicePowerNotify
690 DialogBoxIndirectParamW
666 DisableCaretSystemWide
1232 DisableThreadLibraryCalls
859 DispatchMessageW
932 DrawEdge
933 DrawFocusRect
987 DrawFrameControl
726 DrawIconEx
856 DrawMenuBar
945 DrawTextW
341 DumpFileSystemHeap
510 DumpKCallProfile
1535 DuplicateHandle
934 Ellipse
677 EmptyClipboard
667 EnableCaretSystemWide
986 EnableEUDC
825 EnableHardwareKeyboard
847 EnableMenuItem
287 EnableWindow
1159 EndDeferWindowPos
691 EndDialog
959 EndDoc
960 EndPage
261 EndPaint
4 EnterCriticalSection
206 EnumCalendarInfoW
675 EnumClipboardFormats
208 EnumDateFormatsW
124 EnumDevices
1778 EnumDisplayDevices
1526 EnumDisplayMonitors
1777 EnumDisplaySettings
965 EnumFontFamiliesW
316 CeSetDatabaseInfo
1191 CeSetDatabaseInfoEx
1471 CeSetDatabaseInfoEx2
1455 CeSetExtendedPdata
1688 CeSetPowerOnEvent
1775 CeSetProcessVersion
327 CeSetReplChangeBitsEx
325 CeSetReplChangeMask
330 CeSetReplOtherBitsEx
621 CeSetThreadPriority
1244 CeSetThreadQuantum
473 CeSetUserNotification
1352 CeSetUserNotificationEx
1197 CeUnmountDBVol
322 CeWriteRecordProps
1781 CeZeroPointer
1611 ChangeDisplaySettingsEx
222 CharLowerBuffW
221 CharLowerW
226 CharNextW
225 CharPrevW
223 CharUpperBuffW
224 CharUpperW
848 CheckMenuItem
849 CheckMenuRadioItem
182 CheckPassword
684 CheckRadioButton
253 ChildWindowFromPoint
107 ClearCommBreak
108 ClearCommError
254 ClientToScreen
731 ClipCursor
244 CloseAllDeviceHandles
242 CloseAllFileHandles
1511 CloseAllServiceHandles
669 CloseClipboard
956 CloseEnhMetaFile
553 CloseHandle
966 EnumFontsW
123 EnumPnpIds
1500 EnumPropsEx
1517 EnumServices
220 EnumSystemCodePagesW
219 EnumSystemLocalesW
207 EnumTimeFormatsW
1320 EnumUILanguagesW
291 EnumWindows
97 EqualRect
91 EqualRgn
109 EscapeCommFunction
494 EventModify
970 ExcludeClipRect
6 ExitThread
1617 ExtCreateRegion
1182 ExtEscape
896 ExtTextOutW
727 ExtractIconExW
573 ExtractResource
241 FileSystemPowerFunction
21 FileTimeToLocalFileTime
20 FileTimeToSystemTime
935 FillRect
927 FillRgn
585 FilterTrackedItem
180 FindClose
1684 FindCloseChangeNotification
1682 FindFirstChangeNotificationW
1235 FindFirstFileExW
167 FindFirstFileW
1683 FindNextChangeNotification
181 FindNextFileW
531 FindResource
532 FindResourceW
286 FindWindowW
175 FlushFileBuffers
508 FlushInstructionCache
551 FlushViewOfFile
1215 FlushViewOfFileMaybe
218 FoldStringW
540 ForcePageout
234 FormatMessageW
1476 FreeIntChainHandler
529 FreeLibrary
1216 FreeLibraryAndExitThread
1487 FreePhysMem
186 GetACP
32 GetAPIAddress
706 GetActiveWindow
300 GetAssociatedMenu
826 GetAsyncKeyState
834 GetAsyncShiftFlags
913 GetBkColor
914 GetBkMode
188 GetCPInfo
1228 GetCRTFlags
1227 GetCRTStorageEx
1760 GetCallStackSnapshot
607 GetCallerProcess
641 GetCallerProcessIndex
707 GetCapture
665 GetCaretBlinkTime
663 GetCaretPos
1779 GetCharABCWidths
1664 GetCharWidth32
878 GetClassInfoW
881 GetClassLong
879 GetClassLongW
283 GetClassNameW
249 GetClientRect
971 GetClipBox
732 GetClipCursor
972 GetClipRgn
672 GetClipboardData
681 GetClipboardDataAlloc
676 GetClipboardFormatNameW
670 GetClipboardOwner
110 GetCommMask
111 GetCommModemStatus
112 GetCommProperties
113 GetCommState
114 GetCommTimeouts
1231 GetCommandLineW
205 GetCurrencyFormatW
29 GetCurrentFT
915 GetCurrentObject
612 GetCurrentPermissions
1653 GetCurrentPositionEx
733 GetCursor
734 GetCursorPos
262 GetDC
1185 GetDCEx
1665 GetDIBColorTable
203 GetDateFormatW
1397 GetDesktopWindow
1236 GetDeviceByIndex
916 GetDeviceCaps
125 GetDeviceKeys
1679 GetDevicePower
694 GetDialogBaseUnits
184 GetDiskFreeSpaceExW
693 GetDlgCtrlID
692 GetDlgItem
695 GetDlgItemInt
687 GetDlgItemTextW
888 GetDoubleClickTime
1527 GetEventData
519 GetExitCodeProcess
518 GetExitCodeThread
603 GetFSHeapInfo
1237 GetFileAttributesExW
166 GetFileAttributesW
174 GetFileInformationByHandle
172 GetFileSize
176 GetFileTime
1461 GetFileVersionInfoSizeW
1460 GetFileVersionInfoW
705 GetFocus
1224 GetForegroundInfo
1802 GetForegroundKeyboardLayoutHandle
1225 GetForegroundKeyboardTarget
701 GetForegroundWindow
52 GetHeapSnapshot
608 GetIdleTime
581 GetKPhys
860 GetKeyState
1229 GetKeyboardLayout
1767 GetKeyboardLayoutList
1160 GetKeyboardLayoutNameW
827 GetKeyboardStatus
711 GetKeyboardTarget
1771 GetKeyboardType
516 GetLastError
23 GetLocalTime
200 GetLocaleInfoW
854 GetMenuItemInfoW
862 GetMessagePos
1477 GetMessageQueueReadyTimeStamp
872 GetMessageSource
861 GetMessageW
863 GetMessageWNoWait
537 GetModuleFileNameW
1177 GetModuleHandleW
1721 GetModuleInformation
1525 GetMonitorInfo
820 GetMouseMovePoints
1532 GetMsgQueueInfo
952 GetNearestColor
948 GetNearestPaletteIndex
697 GetNextDlgGroupItem
696 GetNextDlgTabItem
204 GetNumberFormatW
187 GetOEMCP
917 GetObjectType
918 GetObjectW
680 GetOpenClipboardWindow
488 GetOpenFileNameW
606 GetOwnerProcess
949 GetPaletteEntries
269 GetParent
239 GetPasswordActive
1538 GetPasswordStatus
936 GetPixel
679 GetPriorityClipboardFormat
1400 GetPrivateCallbacks
#3
602 GetProcAddrBits
1230 GetProcAddressA
530 GetProcAddressW
600 GetProcFromPtr
624 GetProcName
50 GetProcessHeap
1727 GetProcessIDFromIndex
640 GetProcessIndexFromID
536 GetProcessVersion
1498 GetProp
1420 GetQueueStatus
570 GetRealTime
973 GetRegionData
974 GetRgnBox
576 GetRomFileBytes
575 GetRomFileInfo
489 GetSaveFileNameW
282 GetScrollInfo
1513 GetServiceByIndex
1518 GetServiceHandle
1149 GetStdioPathW
919 GetStockObject
323 GetStoreInformation
217 GetStringTypeExW
216 GetStringTypeW
855 GetSubMenu
889 GetSysColor
937 GetSysColorBrush
213 GetSystemDefaultLCID
211 GetSystemDefaultLangID
1317 GetSystemDefaultUILanguage
542 GetSystemInfo
336 GetSystemMemoryDivision
885 GetSystemMetrics
950 GetSystemPaletteEntries
1581 GetSystemPowerState
715 GetSystemPowerStatusEx
1358 GetSystemPowerStatusEx2
25 GetSystemTime
1234 GetTempFileNameW
162 GetTempPathW
1655 GetTextAlign
920 GetTextColor
897 GetTextExtentExPointW
967 GetTextFaceW
898 GetTextMetricsW
1148 GetThreadContext
515 GetThreadPriority
1186 GetThreadTimes
535 GetTickCount
202 GetTimeFormatW
27 GetTimeZoneInformation
274 GetUpdateRect
273 GetUpdateRgn
215 GetUserDefaultLCID
212 GetUserDefaultLangID
1318 GetUserDefaultUILanguage
1686 GetUserDirectory
1503 GetUserNameExW
17 GetVersionEx
717 GetVersionExW
251 GetWindow
270 GetWindowDC
259 GetWindowLongW
248 GetWindowRect
1399 GetWindowRgn
276 GetWindowTextLengthW
257 GetWindowTextW
1454 GetWindowTextWDirect
292 GetWindowThreadProcessId
582 GiveKPhys
1519 GlobalAddAtomW
1520 GlobalDeleteAtom
1521 GlobalFindAtomW
88 GlobalMemoryStatus
1763 GradientFill
1722 GwesPowerDown
296 GwesPowerOffSystem
1723 GwesPowerUp
46 HeapAlloc
HeapAllocTrace
44 HeapCreate
45 HeapDestroy
49 HeapFree
47 HeapReAlloc
48 HeapSize
51 HeapValidate
660 HideCaret
738 ImageList_Add
739 ImageList_AddMasked
740 ImageList_BeginDrag
767 ImageList_Copy
741 ImageList_CopyDitherImage
742 ImageList_Create
743 ImageList_Destroy
744 ImageList_DragEnter
745 ImageList_DragLeave
746 ImageList_DragMove
747 ImageList_DragShowNolock
748 ImageList_Draw
749 ImageList_DrawEx
750 ImageList_DrawIndirect
768 ImageList_Duplicate
751 ImageList_EndDrag
752 ImageList_GetBkColor
753 ImageList_GetDragImage
754 ImageList_GetIcon
755 ImageList_GetIconSize
756 ImageList_GetImageCount
757 ImageList_GetImageInfo
758 ImageList_LoadImage
759 ImageList_Merge
760 ImageList_Remove
761 ImageList_Replace
762 ImageList_ReplaceIcon
763 ImageList_SetBkColor
764 ImageList_SetDragCursorImage
765 ImageList_SetIconSize
769 ImageList_SetImageCount
766 ImageList_SetOverlayImage
770 ImmAssociateContext
1205 ImmAssociateContextEx
771 ImmConfigureIMEW
1198 ImmCreateContext
772 ImmCreateIMCC
1199 ImmDestroyContext
773 ImmDestroyIMCC
1206 ImmDisableIME
1541 ImmEnableIME
774 ImmEnumRegisterWordW
775 ImmEscapeW
776 ImmGenerateMessage
778 ImmGetCandidateListCountW
777 ImmGetCandidateListW
779 ImmGetCandidateWindow
780 ImmGetCompositionFontW
781 ImmGetCompositionStringW
782 ImmGetCompositionWindow
783 ImmGetContext
784 ImmGetConversionListW
785 ImmGetConversionStatus
786 ImmGetDefaultIMEWnd
787 ImmGetDescriptionW
788 ImmGetGuideLineW
813 ImmGetHotKey
789 ImmGetIMCCLockCount
790 ImmGetIMCCSize
791 ImmGetIMCLockCount
1207 ImmGetIMEFileNameW
1211 ImmGetImeMenuItemsW
1769 ImmGetKeyboardLayout
792 ImmGetOpenStatus
793 ImmGetProperty
794 ImmGetRegisterWordStyleW
1200 ImmGetStatusWindowPos
1210 ImmGetVirtualKey
1209 ImmIsIME
796 ImmIsUIMessageW
797 ImmLockIMC
798 ImmLockIMCC
800 ImmNotifyIME
801 ImmReSizeIMCC
802 ImmRegisterWordW
803 ImmReleaseContext
1242 ImmRequestMessageW
804 ImmSIPanelState
807 ImmSetCandidateWindow
808 ImmSetCompositionFontW
809 ImmSetCompositionStringW
810 ImmSetCompositionWindow
811 ImmSetConversionStatus
812 ImmSetHotKey
1222 ImmSetImeWndIMC
814 ImmSetOpenStatus
815 ImmSetStatusWindowPos
816 ImmSimulateHotKey
817 ImmUnlockIMC
818 ImmUnlockIMCC
819 ImmUnregisterWordW
1419 InSendMessage
98 InflateRect
8 InitLocale
2 InitializeCriticalSection
595 InputDebugCharW
841 InsertMenuW
1762 Int_CloseHandle
1761 Int_CreateEventW
Int_HeapAlloc
Int_HeapCreate
Int_HeapDestroy
Int_HeapFree
Int_HeapReAlloc
Int_HeapSize
1492 InterlockedCompareExchange
11 InterlockedDecrement
12 InterlockedExchange
1491 InterlockedExchangeAdd
10 InterlockedIncrement
9 InterlockedTestExchange
629 InterruptDisable
628 InterruptDone
627 InterruptInitialize
1797 InterruptMask
975 IntersectClipRect
99 IntersectRect
250 InvalidateRect
1615 InvalidateRgn
1770 InvertRect
30 IsAPIReady
521 IsBadCodePtr
601 IsBadPtr
522 IsBadReadPtr
523 IsBadWritePtr
277 IsChild
678 IsClipboardFormatAvailable
191 IsDBCSLeadByte
192 IsDBCSLeadByteEx
698 IsDialogMessageW
613 IsEncryptionPermitted
159 IsExiting
610 IsPrimaryThread
1213 IsProcessDying
1758 IsProcessorFeaturePresent
100 IsRectEmpty
1680 IsSystemFile
185 IsValidCodePage
209 IsValidLocale
271 IsWindow
288 IsWindowEnabled
886 IsWindowVisible
574 KernExtractIcons
557 KernelIoControl
1489 KernelLibIoControl
828 KeybdGetDeviceInfo
829 KeybdInitStates
830 KeybdVKeyToUnicode
605 KillAllOtherThreads
876 KillTimer
199 LCMapStringW
597 LeaveCritSec
5 LeaveCriticalSection
1652 LineTo
94 LoadAcceleratorsW
1493 LoadAnimatedCursor
873 LoadBitmapW
683 LoadCursorW
626 LoadDriver
237 LoadFSD
1421 LoadFSDEx
728 LoadIconW
730 LoadImageW
1475 LoadIntChainHandler
1671 LoadKernelLibrary
1768 LoadKeyboardLayoutW
1241 LoadLibraryExW
528 LoadLibraryW
846 LoadMenuW
533 LoadResource
874 LoadStringW
33 LocalAlloc
41 LocalAllocInProcess
LocalAllocTrace
22 LocalFileTimeToFileTime
36 LocalFree
42 LocalFreeInProcess
34 LocalReAlloc
35 LocalSize
43 LocalSizeInProcess
1161 LockPages
1794 MD5Final
1792 MD5Init
1793 MD5Update
14 MainThreadBaseFunc
1602 MapCallerPtr
699 MapDialogRect
1603 MapPtrToProcWithSize
598 MapPtrToProcess
599 MapPtrUnsecure
549 MapViewOfFile
831 MapVirtualKeyW
284 MapWindowPoints
904 MaskBlt
857 MessageBeep
858 MessageBoxW
1522 MonitorFromPoint
1523 MonitorFromRect
1524 MonitorFromWindow
163 MoveFileW
1651 MoveToEx
272 MoveWindow
871 MsgWaitForMultipleObjectsEx
196 MultiByteToWideChar
545 NKDbgPrintfW
623 NKTerminateThread
568 NKvDbgPrintfW
839 NLedGetDeviceInfo
840 NLedSetDevice
513 NotifyForceCleanboot
716 NotifyWinUserSystem
101 OffsetRect
976 OffsetRgn
668 OpenClipboard
1396 OpenDeviceKey
1496 OpenEventW
1536 OpenMsgQueue
509 OpenProcess
604 OtherThreadsRunning
541 OutputDebugStringW
638 PPSHRestart
7 PSLNotify
1780 PageOutModule
938 PatBlt
864 PeekMessageW
468 PegClearUserNotification
304 PegCreateDatabase
307 PegDeleteDatabase
309 PegDeleteRecord
302 PegFindFirstDatabase
303 PegFindNextDatabase
472 PegGetUserNotificationPreferences
471 PegHandleAppNotifications
301 PegOidGetInfo
306 PegOpenDatabase
310 PegReadRecordProps
899 PegRemoveFontResource
470 PegRunAppAtEvent
469 PegRunAppAtTime
308 PegSeekDatabase
305 PegSetDatabaseInfo
467 PegSetUserNotification
311 PegWriteRecordProps
1448 PerformCallBack4
961 PlayEnhMetaFile
378 PlaySoundW
939 Polygon
940 Polyline
832 PostKeybdMessage
865 PostMessageW
866 PostQuitMessage
290 PostThreadMessageW
617 PowerOffSystem
1764 PowerPolicyNotify
580 PrintTrackedItem
572 ProcessDetachAllDLLs
1800 ProfileCaptureStatus
82 ProfileStart
1801 ProfileStartEx
83 ProfileStop
569 ProfileSyscall
102 PtInRect
977 PtInRegion
115 PurgeComm
821 QASetWindowsJournalHook
#4
关注一下钩子的问题
可以用idapro5 分析coredll,
可以用idapro5 分析coredll,