Intro:
  #1 in code injection (even running 9x console process).
  #1 in hooking (both code and PE.IAT patching).


In all files means
 9X, W9X, Win9X       : MS Windows 95, 98, Me
 NT4                  : Windows NT 4.0
 2K, W2K, Win2K       : Windows 2000
 XP                   : Windows XP
 NT                   : NT4, 2K, XP
 ApiHookChain         : array of API_HOOK structures
 Hooks_DLL            : module which exports ApiHookChain
 AH                   : ApiHooks                          


Installation:
  Copy ApiHooks.exe into PATH and ApiHooks.dll into search path of all
processes (PATH in 9X; %SystemRoot%\SYSTEM32 in NT). Copy files from
HDK\INC into your INCLUDE directory. Copy files from HDK\LIB into your
LIB directory.

  You don't have to distribute ApiHooks.dll/exe in your release if you
don't want to. Link your module statically with ApiHooks libraries
and you're done.


About:
  ApiHooks allows to execute user code in the context/s of
specified/all local 32bit process(es) in Microsoft Windows (x86, 32bit)
95, 98, Me, NT4, 2K and XP. ApiHooks wasn't tested on checked builds
of NT and debug versions of Me.
  ApiHooks doesn't use kernel drivers (no ring-0 code) and can operate
under NT guest account.
  ApiHooks doesn't change files or system registry.
  ApiHooks contains built-in code for (un)loading modules - "ModWorks"
and for hooking APIs - "ApiWorks".

  ApiHooks' core allows to:
a) Execute user code in given process.

  ModWorks allows to:
a) Detect presence of given module in given process.
b) Unload given module from given process.
c) Load given module into given process (and call given function).

  ApiWorks allows interception of:
a) Specific calls to API (ModuleImport -> ModuleExport).
b) "Any" extramodule call to API (ALL_MODULES -> ModuleExport).
c) Any (even intramodule) call to API (HOOK_OVERWRITE).
d) Any call to chosen location (HOOK_RAW) (symbols can be employed).
  You can change hooked function parameter/s before call to the
original function as well as you can change returned value/s
and buffers contents.
  Loading Hooks_DLL into given process is also ensured by ApiWorks.

  In addition, ApiHooks contains code for unhooking.

  ApiHooks exports several useful APIs in libraries, developer can call
from his programs.
  Writing ApiHooks related programs is very easy - ApiHooks supports
many compilers: Visual C++, Borland C++, LCC-Win32, Delphi, MASM, NASM,
TASM32 and maybe Visual Basic.
  ApiHooks is shipped with many examples - use them as templates.


Contact:
  WWW: http://www.anticracking.sk/EliCZ (updates without notification)
  EML: ApiHooks@EliCZ.cjb.net (no source)


Scheme:
---------------------------------Process-------------------------------

	      module0					   module1
		 |					      |
	CALL module1!API001 --------------------------------->| API001
		 |<-------------------------------------------|
		 |					      |
	  API215 |<----------------------------------CALL module0!API215
		 |------------------------------------------->|
		 |					      |
		 *					      *
-----------------------------------------------------------------------

---------------------------Process with API hooks----------------------

	      module0		   Hooooks.dll		   module1
		 |		       |		      |
	CALL module1!API001 -------->API001>----------------->| API001
		 |<-----------------<HOOOOK<------------------|
		 |		       |		      |
	  API215 |<-----------------<API215<---------CALL module0!API215
		 |------------------>HOOOOK>----------------->|
		 |		       |		      |
		 *		       *		      *
-----------------------------------------------------------------------