< previous page page_393 next page >

Page 393
7017a6ead0e3c4111b47a554df321e9f.gif
NameCount = ExportDirectory.NumberOfNames
ReDim startaddresses(NameCount - 1)
ReDim Ordinals(NameCount - 1)
ReDim Names(NameCount)
What is the AddressOfNameOrdinals field? The ordinal values appear in memory and in the file as a list of integer values. The AddressOfNameOrdinals field points to the location of the start of this list.
The location specified by the AddressOfNameOrdinals field is a virtual address, and we earlier calculated the ExportSectionOffset variable, which can be subtracted from any virtual address in a section to obtain a location in a file.
' Load an array with all the ordinals
   sourceloc = ExportDirectory.AddressOfNameOrdinals - _
   ExportSectionOffset + 1
   Get #FileHandle, sourceloc, Ordinals()
   For idx = 0 To NameCount-1
      Ordinals(idx) = Ordinals(idx) + ExportDirectory.Base
   Next idx
The ordinal array is loaded as a block. The PE file format specification indicates that the values have to be incremented by the ordinal base value, which can be found in the Base field of the export directory.
Retrieving the function names is a trickier process. Unlike numbers, variable length strings cannot be loaded in an array. Instead, the file contains an array of virtual addresses to each of the function names. Those addresses are loaded into the startaddresses array in the same way as the Ordinals array was loaded earlier.
' Make a copy of all the start addresses
   sourceloc = ExportDirectory.AddressOfNames - ExportSectionOffset + 1
   Get #FileHandle, sourceloc, startaddresses()
Rather than loading each string individually from the file, the entire section that contains the string data is preloaded into a byte array named ExportsBuffer using the following code:
7017a6ead0e3c4111b47a554df321e9f.gif
' Preload the entire section for speed
ReDim ExportsBuffer(Sections(ExportSection).SizeOfRawData)
Get #FileHandle, Sections(ExportSection).PointerToRawData _
+ 1, ExportsBuffer()
The location of each string in the file can be calculated using the following term:

 
< previous page page_393 next page >