
  ApiHooks.exe calls ApiHooks functions with 60 sec. limit. If this
interval expires, "Time out!" message box is displayed.
  ApiHooks.exe returns error codes (see HDK\DOC\E-Errors.txt) which
can be checked via GetProcessExitCode or in NT batch file via
ERRORLEVEL variable.

  Command line:

ApiHooks -<n|o|l|m|u>[q|r] [PathTo\]<Module> <[SessId/][PathTo\]TargetName|TargetPID|ALL> [Target's command line] [Redirections]

   Environment variables in [PathTo\]<Module> and  [PathTo\]<TargetName>
   allowed.

   Target can be specified by:
   a) Name (notepad.exe, \??\d:\winnt\system32\winlogon.exe, calc)
    For -n, -l switches can be specifed without extension.
    For -o, -m, -u switches MUST BE specifed WITH EXTENSION, can be specified with
      SessId - session id - decimal number or * for all sessions.
   b) PID - process identifier (must have 0d/0x prefix: 0d708, 0x98,
            0D4294870253, 0Xfffd3e47,..)
   c) ALL - all processes are Targets

   Redirections: >, < (in NT also |)

   The following applies to -o -m and -u switches:
   *) The youngest Target is found
      - more Targets with the same (base)name may exist.

   The following applies to -n and -l switches:
   *) NT: If debug privilege is granted, ApiHooks.exe enables it and creates
      Target -> Target will have debug privilege enabled.


  -n .. create new Target, load Module into it (1x) and establish
   API hooks. If Module is specified without PathTo, current directory
   will be added to Module.

  -o .. open existing Target, load Module into it (1x) and establish
   API hooks. If Module is specified without PathTo, current directory
   will be added to Module.

  -l .. create new Target and load module into it (1x)
   Module must be in ApiHooks search path.

  -m .. open existing Target and load module into it (1x)
   Module must be in Target's search path if it is not, you
   have to specify it WITH PathTo.

  -u .. open existing process and unload Module from it (1x).

   q .. display message box only if there was an error.

   r .. no message box at all.

 
   When ALL was specified as Target, ApiHooks.exe displays status for the LAST
   process. Because ApiHooks.exe is a console application, the last process in
   Win9x is _16bit_ WINOA386.MOD. Therefore, ApiHooks with ALL displays
   "Can't open process!" message box almost always.


  Examples:

  apihooks.exe -m  module.dll 00/%systemroot%\explorer.exe
  (loads module.dll into lsat existing %systemroot%\explorer.exe process in session 0;
   module.dll must be in 00/%systemroot%\explorer.exe's search path;
   msgbox is displayed)

  apihooks.exe -lq  cmdext cmd /C cmd /C cmd /C app
  (creates process "cmd /C cmd /C cmd /C app" and loads cmdext into it;
   module.dll must be in the current directory or in search path;
   msgbox is displayed only if there was an error)

  apihooks.exe -ur  "addon. 4" 0XaC
  (unloads "addon. 4" from process represented by identifier 172;
   msgbox is never displayed)

  apihooks.exe -m e:\temp\mod.dll ALL
  (loads e:\temp\mod.dll into all processes;
   msgbox is displayed)

  apihooks.exe -l e:\temp\mod.dll th32list >list
  (creates th32list.exe process, loads e:\temp\mod.dll into it; and
   redirects its output to list
   msgbox is displayed)