|
|
 |
|
|
|
|
NameCount = ExportDirectory.NumberOfNames
ReDim startaddresses(NameCount - 1)
ReDim Ordinals(NameCount - 1)
ReDim Names(NameCount) |
|
|
|
|
|
|
|
|
What is the AddressOfNameOrdinals field? The ordinal values appear in memory and in the file as a list of integer values. The AddressOfNameOrdinals field points to the location of the start of this list. |
|
|
|
|
|
|
|
|
The location specified by the AddressOfNameOrdinals field is a virtual address, and we earlier calculated the ExportSectionOffset variable, which can be subtracted from any virtual address in a section to obtain a location in a file. |
|
|
|
|
|
|
|
|
' Load an array with all the ordinals
sourceloc = ExportDirectory.AddressOfNameOrdinals - _
ExportSectionOffset + 1
Get #FileHandle, sourceloc, Ordinals()
For idx = 0 To NameCount-1
Ordinals(idx) = Ordinals(idx) + ExportDirectory.Base
Next idx |
|
|
|
|
|
|
|
|
The ordinal array is loaded as a block. The PE file format specification indicates that the values have to be incremented by the ordinal base value, which can be found in the Base field of the export directory. |
|
|
|
|
|
|
|
|
Retrieving the function names is a trickier process. Unlike numbers, variable length strings cannot be loaded in an array. Instead, the file contains an array of virtual addresses to each of the function names. Those addresses are loaded into the startaddresses array in the same way as the Ordinals array was loaded earlier. |
|
|
|
|
|
|
|
|
' Make a copy of all the start addresses
sourceloc = ExportDirectory.AddressOfNames - ExportSectionOffset + 1
Get #FileHandle, sourceloc, startaddresses() |
|
|
|
|
|
|
|
|
Rather than loading each string individually from the file, the entire section that contains the string data is preloaded into a byte array named ExportsBuffer using the following code: |
|
|
|
 |
|
|
|
|
' Preload the entire section for speed
ReDim ExportsBuffer(Sections(ExportSection).SizeOfRawData)
Get #FileHandle, Sections(ExportSection).PointerToRawData _
+ 1, ExportsBuffer() |
|
|
|
|
|
|
|
|
The location of each string in the file can be calculated using the following term: |
|
|
|
|
|