|
|
|
|
|
|
|
e_oemid As Integer
e_oeminfo As Integer
e_res2(9) As Integer
e_lfanew As Long
End Type |
|
|
|
|
|
|
|
|
The e_lfanew field specifies the offset in the file to the start of the PE Header structure. The PE Header structure is defined by an IMAGE_NT_HEADERS structure, which contains a signature that identifies the file as a PE format file and two additional structures: an IMAGE_FILE_HEADER structure and an IMAGE_OPTIONALHEADER structure. These structures are as follows: |
|
|
|
|
|
|
|
|
typedef struct _IMAGE_NT_HEADERS {
DWORD Signature;
IMAGE_FILE HEADER FileHeader;
IMAGE_OPTIONAL_HEADER OptionalHeader;
} IMAGE_NT_HEADERS, *PIMAGE_NT_HEADERS;
typedef struct _IMAGE_FILE_HEADER {
WORD Machine;
WORD NumberOfSections;
DWORD TimeDateStamp;
DWORD PointerToSymbolTable;
DWORD NumberOfSymbols;
WORD SizeOfOptionalHeader;
WORD Characteristics;
} IMAGE_FILE_HEADER, *PIMAGE_FILE_HEADER;
typedef struct _IMAGE_OPTIONAL_HEADER {
//
// Standard fields.
//
WORD Magic;
BYTE MajorLinkerVersion;
BYTE MinorLinkerVersion;
DWORD SizeOfCode;
DWORD SizeOfInitializedData;
DWORD SizeOfUninitializedData;
DWORD AddressOfEntryPoint;
DWORD BaseOfCode;
DWORD BaseOfData; |
|
|
|
|
|