APIHookCheck Results

for TESTSYSTEM

Checks started on 02 April 2004 14:42.16


Checking imports from KERNEL32.DLL for discrepancies

Base Address of KERNEL32.DLL at77E80000
End Address of KERNEL32.DLL at77F35FFF

API AddressAPI NameAPI Hooked ByRemarks
10001420FindNextFileWC:\WINNT\System32\apihookdll.dllAPI exists outside KERNEL32.DLL's memory space
100014B0FindFirstFileWC:\WINNT\System32\apihookdll.dllAPI exists outside KERNEL32.DLL's memory space
10001890CreateProcessWC:\WINNT\System32\apihookdll.dllAPI exists outside KERNEL32.DLL's memory space
10001810CreateProcessAC:\WINNT\System32\apihookdll.dllAPI exists outside KERNEL32.DLL's memory space
10001380LoadLibraryAC:\WINNT\System32\apihookdll.dllAPI exists outside KERNEL32.DLL's memory space
100013C0LoadLibraryWC:\WINNT\System32\apihookdll.dllAPI exists outside KERNEL32.DLL's memory space
10001970WriteConsoleAC:\WINNT\System32\apihookdll.dllAPI exists outside KERNEL32.DLL's memory space
100019D0WriteFileC:\WINNT\System32\apihookdll.dllAPI exists outside KERNEL32.DLL's memory space
10001910WriteConsoleWC:\WINNT\System32\apihookdll.dllAPI exists outside KERNEL32.DLL's memory space

Total number of imported APIs checked : 717


Checking exports of KERNEL32.DLL for discrepancies

Base Address of KERNEL32.DLL at77E80000
End Address of KERNEL32.DLL at77F35FFF

API AddressAPI NameAPI Hooked ByRemarks
10001810CreateProcessAC:\WINNT\System32\apihookdll.dllAPI exists outside KERNEL32.DLL's memory space
10001890CreateProcessWC:\WINNT\System32\apihookdll.dllAPI exists outside KERNEL32.DLL's memory space
100014B0FindFirstFileWC:\WINNT\System32\apihookdll.dllAPI exists outside KERNEL32.DLL's memory space
10001420FindNextFileWC:\WINNT\System32\apihookdll.dllAPI exists outside KERNEL32.DLL's memory space
10001380LoadLibraryAC:\WINNT\System32\apihookdll.dllAPI exists outside KERNEL32.DLL's memory space
100013C0LoadLibraryWC:\WINNT\System32\apihookdll.dllAPI exists outside KERNEL32.DLL's memory space
77E87E7CReadFile(unknown)API contains instruction that jumps to 7FFA3A74, this is outside KERNEL32.DLL's memory space
10001970WriteConsoleAC:\WINNT\System32\apihookdll.dllAPI exists outside KERNEL32.DLL's memory space
10001910WriteConsoleWC:\WINNT\System32\apihookdll.dllAPI exists outside KERNEL32.DLL's memory space
100019D0WriteFileC:\WINNT\System32\apihookdll.dllAPI exists outside KERNEL32.DLL's memory space

Total number of exported APIs checked : 826


Checking imports from ADVAPI32.DLL for discrepancies

Base Address of ADVAPI32.DLL at77DB0000
End Address of ADVAPI32.DLL at77E0CFFF

API AddressAPI NameAPI Hooked ByRemarks
10001B90CreateProcessAsUserAC:\WINNT\System32\apihookdll.dllAPI exists outside ADVAPI32.DLL's memory space
10001A50CreateProcessWithLogonWC:\WINNT\System32\apihookdll.dllAPI exists outside ADVAPI32.DLL's memory space
10001AF0CreateProcessAsUserWC:\WINNT\System32\apihookdll.dllAPI exists outside ADVAPI32.DLL's memory space

Total number of imported APIs checked : 401


Checking exports of ADVAPI32.DLL for discrepancies

Base Address of ADVAPI32.DLL at77DB0000
End Address of ADVAPI32.DLL at77E0CFFF

API AddressAPI NameAPI Hooked ByRemarks
10001B90CreateProcessAsUserAC:\WINNT\System32\apihookdll.dllAPI exists outside ADVAPI32.DLL's memory space
10001AF0CreateProcessAsUserWC:\WINNT\System32\apihookdll.dllAPI exists outside ADVAPI32.DLL's memory space
10001A50CreateProcessWithLogonWC:\WINNT\System32\apihookdll.dllAPI exists outside ADVAPI32.DLL's memory space
77DB1CF0EnumServiceGroupW(unknown)API contains instruction that jumps to 7FFA435E, this is outside ADVAPI32.DLL's memory space
77DC34DCEnumServicesStatusA(unknown)API contains instruction that jumps to 7FFA43C1, this is outside ADVAPI32.DLL's memory space
77DC7EA0EnumServicesStatusExA(unknown)API contains instruction that jumps to 7FFA4487, this is outside ADVAPI32.DLL's memory space
77DE54FCEnumServicesStatusExW(unknown)API contains instruction that jumps to 7FFA4421, this is outside ADVAPI32.DLL's memory space

Total number of exported APIs checked : 564


Checking imports from PSAPI.DLL for discrepancies

Base Address of PSAPI.DLL at690A0000
End Address of PSAPI.DLL at690AAFFF

No Discrepancies

Total number of imported APIs checked : 19


Checking exports of PSAPI.DLL for discrepancies

Base Address of PSAPI.DLL at690A0000
End Address of PSAPI.DLL at690AAFFF

No Discrepancies

Total number of exported APIs checked : 19


Checking imports from IPHLPAPI.DLL for discrepancies

Base Address of IPHLPAPI.DLL at77340000
End Address of IPHLPAPI.DLL at77352FFF

No Discrepancies

Total number of imported APIs checked : 46


Checking exports of IPHLPAPI.DLL for discrepancies

Base Address of IPHLPAPI.DLL at77340000
End Address of IPHLPAPI.DLL at77352FFF

No Discrepancies

Total number of exported APIs checked : 117


Checking imports from SNMPAPI.DLL for discrepancies

Base Address of SNMPAPI.DLL at754C0000
End Address of SNMPAPI.DLL at754C7FFF

No Discrepancies

Total number of imported APIs checked : 26


Checking exports of SNMPAPI.DLL for discrepancies

Base Address of SNMPAPI.DLL at754C0000
End Address of SNMPAPI.DLL at754C7FFF

No Discrepancies

Total number of exported APIs checked : 38


Checking imports from NETAPI32.DLL for discrepancies

Base Address of NETAPI32.DLL at75170000
End Address of NETAPI32.DLL at751BEFFF

No Discrepancies

Total number of imported APIs checked : 151


Checking exports of NETAPI32.DLL for discrepancies

Base Address of NETAPI32.DLL at75170000
End Address of NETAPI32.DLL at751BEFFF

No Discrepancies

Total number of exported APIs checked : 317


Checking kernel32.dll's imports from NTDLL.DLL for discrepancies

Base Address of NTDLL.DLL at77F80000
End Address of NTDLL.DLL at77FFAFFF

No Discrepancies

Total number of imported APIs checked : 330


Checking exports of NTDLL.DLL for discrepancies

Base Address of NTDLL.DLL at77F80000
End Address of NTDLL.DLL at77FFAFFF

API AddressAPI NameAPI Hooked ByRemarks
77F87F0CLdrLoadDll(unknown)API contains instruction that jumps to 7FFA41E9, this is outside NTDLL.DLL's memory space
77F83DA8NtCreateFile(unknown)API contains instruction that jumps to 7FFA488D, this is outside NTDLL.DLL's memory space
77F83C5FNtDeviceIoControlFile(unknown)API contains instruction that jumps to 7FFA45F7, this is outside NTDLL.DLL's memory space
77F86E21NtEnumerateKey(unknown)API contains instruction that jumps to 7FFA3E1C, this is outside NTDLL.DLL's memory space
77F85D3ANtEnumerateValueKey(unknown)API contains instruction that jumps to 7FFA3F11, this is outside NTDLL.DLL's memory space
77F86AF1NtOpenProcess(unknown)API contains instruction that jumps to 7FFA4828, this is outside NTDLL.DLL's memory space
77F8593CNtQueryDirectoryFile(unknown)API contains instruction that jumps to 7FFA3CF0, this is outside NTDLL.DLL's memory space
77F83B3FNtQuerySystemInformation(unknown)API contains instruction that jumps to 7FFA3B5E, this is outside NTDLL.DLL's memory space
77F839D2NtQueryVolumeInformationFile(unknown)API contains instruction that jumps to 7FFA4527, this is outside NTDLL.DLL's memory space
77F8ECBFNtReadVirtualMemory(unknown)API contains instruction that jumps to 7FFA3FE9, this is outside NTDLL.DLL's memory space
77F8669ANtResumeThread(unknown)API contains instruction that jumps to 7FFA3DC1, this is outside NTDLL.DLL's memory space
77F96D62NtVdmControl(unknown)API contains instruction that jumps to 7FFA3D52, this is outside NTDLL.DLL's memory space
77F83DA8ZwCreateFile(unknown)API contains instruction that jumps to 7FFA488D, this is outside NTDLL.DLL's memory space
77F83C5FZwDeviceIoControlFile(unknown)API contains instruction that jumps to 7FFA45F7, this is outside NTDLL.DLL's memory space
77F86E21ZwEnumerateKey(unknown)API contains instruction that jumps to 7FFA3E1C, this is outside NTDLL.DLL's memory space
77F85D3AZwEnumerateValueKey(unknown)API contains instruction that jumps to 7FFA3F11, this is outside NTDLL.DLL's memory space
77F86AF1ZwOpenProcess(unknown)API contains instruction that jumps to 7FFA4828, this is outside NTDLL.DLL's memory space
77F8593CZwQueryDirectoryFile(unknown)API contains instruction that jumps to 7FFA3CF0, this is outside NTDLL.DLL's memory space
77F83B3FZwQuerySystemInformation(unknown)API contains instruction that jumps to 7FFA3B5E, this is outside NTDLL.DLL's memory space
77F839D2ZwQueryVolumeInformationFile(unknown)API contains instruction that jumps to 7FFA4527, this is outside NTDLL.DLL's memory space
77F8ECBFZwReadVirtualMemory(unknown)API contains instruction that jumps to 7FFA3FE9, this is outside NTDLL.DLL's memory space
77F8669AZwResumeThread(unknown)API contains instruction that jumps to 7FFA3DC1, this is outside NTDLL.DLL's memory space
77F96D62ZwVdmControl(unknown)API contains instruction that jumps to 7FFA3D52, this is outside NTDLL.DLL's memory space

Total number of exported APIs checked : 1187


Checks completed on 02 April 2004 14:42.16
ApiHookCheck Version 1.0 Copyright (c) 2004 Chew Keong TAN.