1. “Inside Windows NT”, Helen Custer, Microsoft Press, 1993.
2. “Playing Hide and Seek with Stored Keys”, Nicko van Someren and Adi Shamir, 22 September 1998, presented at Financial Cryptography 1999.
3. “Monitoring System Events by Subclassing the Shell”, Eric Heimburg, Windows Developers Journal, Vol.9,No. 2 (February 1998), p.35.
4. “Windows NT System-Call Hooking”, Mark Russinovich and Bryce Cogswell, Dr.Dobbs Journal, January 1997, p.42.
5. “Win NT 4.0 UserId and Password available in memory”, Russ Osterlund, posting to the ntbugtraq mailing list, message-ID C12566CD.00485E7F.00@ZurichNotes. com, 1 December 1998.