|
|
|
|
|
|
|
SizeOfStackCommit As Long
SizeOfHeapReserve As Long
SizeOfHeapCommit As Long
LoaderFlags As Long
NumberOfRvaAndSizes As Long
DataDirectory(15) As IMAGE_DATA_DIRECTORY
End Type |
|
|
|
|
|
|
|
|
Detailed explanations of the IMAGE_NT_HEADERS, IMAGE_FILE_HEADER, IMAGE_DATA_DIRECTORY, and IMAGE_OPTIONAL_HEADER structures can be found in the PE file format specification. In this tutorial, I'll only define those fields that are actually used by the program. The main function used within the Exports class to load the file information is the LoadInfo function shown here: |
|
|
|
|
|
|
|
|
Private Function LoadInfo(FileName As String) As Integer
Dim x%
FileHandle = FreeFile()
On Error GoTo BadLoad
Open FileName For Binary Access Read As #FileHandle
On Error GoTo BadBuild
' Get the DOS header
Get #FileHandle, , DosHeader
' Calculate the offset to the NT header
PEHeaderOffset = DosHeader.e_lfanew
' Get the NT header
Get #FileHandle, PEHeaderOffset + 1, PEHeader
SectionCount = PEHeader.FileHeader.NumberOfSections
ReDim Sections(SectionCount - 1)
SectionsOffset = Seek(FileHandle)
For x = 0 To SectionCount - 1
Get #FileHandle, , Sections(x)
Next x
FindExportBase
Get #FileHandle, ExportBase + 1, ExportDirectory
LoadExportInfo
Close #FileHandle |
|
|
|
|
|