|
|
|
|
|
|
|
Exit Function
BadLoad:
LoadInfo = - 1
Exit Function
BadBuild:
LoadInfo = - 1
Close #FileHandle
End Function |
|
|
|
|
|
|
|
|
The function first loads the IMAGE_DOS_HEADER structure into the variable DosHeader. The e_lfanew field of the structure contains the offset to the start of the PE Header, which is defined by the IMAGE_NT_HEADERS structure. The PEHeader variable is loaded with this information using the following Get statement: |
|
|
|
|
|
|
|
|
Get #FileHandle, PEHeaderOffset + 1, PEHeader |
|
|
|
|
|
|
|
|
Why do you have to add 1 to the offset? Because the offset is based on the assumption that the first byte in the file is at location 0, whereas the Get statement assumes that the first byte in the file is at location 1. |
|
|
|
|
|
|
|
|
The section table appears immediately after the PE header. The NumberOfSections field in the IMAGE_FILE_HEADER structure allows you to determine the number of sections in the file. Each section is defined using the IMAGE_SECTION_HEADER structure, which is defined as follows: |
|
|
|
|
|
|
|
|
#define IMAGE_SIZEOF_SHORT_NAME 8
typedef struct _IMAGE_SECTION_HEADER {
BYTE Name[IMAGE_SIZEOF_SHORT_NAME];
union {
DWORD PhysicalAddress;
DWORD VirtualSize;
} Misc;
DWORD VirtualAddress;
DWORD SizeOfRawData;
DWORD PointerToRawData;
DWORD PointerToRelocations;
DWORD PointerToLinenumbers;
WORD NumberOfRelocations;
WORD NumberOfLinenumbers;
DWORD Characteristics;
} IMAGE_SECTION_HEADER, *PIMAGE_SECTION_HEADER; |
|
|
|
|
|