< previous page page_390 next page >

Page 390
tions to find the first section whose virtual address is greater than this ExportDirectoryOffset value. The section before this must contain the export table itself.
So now we have the virtual address of the export table, the virtual address of the section that contains the export table, and the location of that section in the image file.
The following expression can be used to calculate the location of the export table in the image file:
ExportBase = ExportDirectoryOffset -
Sections(ExportSection).VirtualAddress +
Sections(ExportSection).PointerToRawData
It takes the offset of the export table from the start of the section and adds it to the location of the start of the section. But this does not match the code in the FindExportBase function. Why is this?
The code in the FindExportBase function does perform the same calculation, but rearranges the terms to first calculate a variable called ExportSectionOffset. The ExportSectionOffset variable now contains a value that can be subtracted from any virtual address in the specified section to find the corresponding location in the file. We'll be using this variable later, as many of the entries in the export table use virtual addresses as well.
ExportSectionOffset = Sections(ExportSection).VirtualAddress - _
   Sections(ExportSection).PointerToRawData
ExportBase = ExportDirectoryOffset - ExportSectionOffset
The ExportBase variable now contains the file offset to the start of the export data.
Loading the Export Table
The export data begins with an export data directory that is defined by a structure of type IMAGE_EXPORT_DIRECTORY. This structure is defined in C as follows:
typedef struct _IMAGE_EXPORT_DIRECTORY {
    DWORD   Characteristics;
    DWORD   TimeDateStamp;
    WORD    MajorVersion;
    WORD    MinorVersion;
    DWORD   Name;
    DWORD   Base;

 
< previous page page_390 next page >