Solved

How do I detect calls made to the USER32.dll by other applications but my own

Posted on 2003-10-30
4
196 Views
Last Modified: 2010-04-05
If I wanted to detect calls made to the User32.dll by another application, how would I do this?

Lets say I am waiting for a specific call to the dll but do not know from where it would come.
If this API call is directed at this dll I want to be able to listen for calls like the CallNextHookEx or the FindWindow call.

If this call is made I want to be able to catch it before the dll reacts to it. If I catch it I want to be able to kill this call and not allow it to go through.

I know that I have to create a hook but I there is anyone out there that can use an example of how this is to be done I would be ever so happy!!

Thank you.
Horatio
0
Comment
Question by:HoratioH
4 Comments
 
LVL 6

Accepted Solution

by:
GloomyFriar earned 125 total points
ID: 9658590
Here is one link for you.
http://www.codeproject.com/system/hooksys.asp

I've developed similar programm. But the programm hooks API from kernel.dll and only for one application.
But i think it can be registered as global hook.
0
 
LVL 20

Assisted Solution

by:Madshi
Madshi earned 125 total points
ID: 9797653
Hi Horatio,

you might want to check this one out:

http://help.madshi.net/madCodeHook.htm

This package is free for non-commercial purpose (only). It can do system wide API hooking on all win32 OSs. Several demos are also included. The demos are available for download here:

http://madshi.net/MCHDemos.zip
0

Featured Post

Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

Join & Write a Comment

Introduction The parallel port is a very commonly known port, it was widely used to connect a printer to the PC, if you look at the back of your computer, for those who don't have newer computers, there will be a port with 25 pins and a small print…
Introduction I have seen many questions in this Delphi topic area where queries in threads are needed or suggested. I know bumped into a similar need. This article will address some of the concepts when dealing with a multithreaded delphi database…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now