20 {
NULL,
L"%systemroot%\\system32\\advapi32.dll",
NULL},
21 {
NULL,
L"%systemroot%\\system32\\comctl32.dll",
NULL},
22 {
NULL,
L"%systemroot%\\system32\\comdlg32.dll",
NULL},
23 {
NULL,
L"%systemroot%\\system32\\kernel32.dll",
NULL},
24 {
NULL,
L"%systemroot%\\system32\\ntdll.dll",
NULL},
25 {
NULL,
L"%systemroot%\\system32\\ntoskrnl.exe",
NULL}
#define DLL_PROCESS_ATTACH
#define DLL_PROCESS_DETACH
BOOL WINAPI DisableThreadLibraryCalls(IN HMODULE hLibModule)
static IN DWORD IN LPVOID lpvReserved
static PROTECT_FILE_ENTRY ProtectedFiles[]
NTSTATUS WINAPI SfcGetFiles(_Out_ PPROTECT_FILE_ENTRY *ProtFileData, _Out_ PULONG FileCount)
BOOL WINAPI DllMain(_In_ HINSTANCE hInstDLL, _In_ DWORD fdwReason, _In_ LPVOID lpvReserved)