|
|
|
|
|
|
|
DWORD NumberOfFunctions;
DWORD NumberOfNames;
PDWORD *AddressOfFunctions;
PDWORD *AddressOfNames;
PWORD *AddressOfNameOrdinals;
} IMAGE_EXPORT_DIRECTORY, *PIMAGE_EXPORT_DIRECTORY; |
|
|
|
|
|
|
|
|
The structure looks a bit trickyhow do you handle data types defined as a PDWORD *? In fact, creating the VB declaration is straightforward. Pointers, and even pointers to pointers, are always 32 bits and thus declared As Long. |
|
|
|
|
|
|
|
|
Public Type IMAGE_EXPORT_DIRECTORY
Characteristics As Long
TimeDateStamp As Long
MajorVersion As Integer
MinorVersion As Integer
Name As Long
Base As Long
NumberOfFunctions As Long ' May not be used
NumberOfNames As Long
AddressOfFunctions As Long
AddressOfNames As Long
AddressOfNameOrdinals As Long
End Type |
|
|
|
|
|
|
|
|
The IMAGE_EXPORT_DIRECTORY structure is loaded into the ExportDirectory variable in the LoadInfo function using the ExportBase offset calculated earlier with this line of code: |
|
|
|
|
|
|
|
|
Get #FileHandle, ExportBase + 1, ExportDirectory
LoadExportInfo |
|
|
|
|
|
|
|
|
The LoadExportInfo function does the real work, as shown here: |
|
|
|
|
|
|
|
|
Private Sub LoadExportInfo()
Dim idx&
Dim startaddresses() As Long
Dim ExportsBuffer() As Byte
Dim tempstr As String
Dim stringlen As Long
Dim sourceloc As Long
NameCount = ExportDirectory.NumberOfNames |
|
|
|
|
|