< previous page page_394 next page >

Page 394
startaddresses(idx) - ExportSectionOffset
Subtracting off the start of the section in the file gives you the offset of the string in the ExportsBuffer table. This offset is stored in the sourceloc variable.
The lstrlenFromPtr function is an alias of the lstrlen function, which obtains the length of a string given a pointer. The lstrcpyFromPtr function uses the lstrcpy function to copy the string into an initialized string buffer. Finally, the Names array is loaded with the string up to the NULL terminating character.
' Extract each start array
   For idx = 0 To NameCount - 1
      sourceloc = startaddresses(idx)-ExportSectionOffset _
      - Sections(ExportSection).PointerToRawData
      ' Preinitialize the string
      ' Calculate the length of the string
      If sourceloc > 0 Then
         stringlen = lstrlenFromPtr(VarPtr(ExportsBuffer(sourceloc)))
         tempstr = String$(stringlen + 1, 0)
         Call lstrcpyFromPtr(tempstr, VarPtr(ExportsBuffer(sourceloc)))
         Names(idx + 1) = Left$(tempstr, stringlen)
      End If
   Next idx
Conclusion
Interpreting file specifications is not easy, and this tutorial gave you only a taste of what it is like. To gain full advantage of this tutorial, you should obtain a copy of the Portable Executable file specification from either of the two sources given at the beginning of the tutorial and read it yourself. Then step through the DumpInfo program as it performs its work, referring to this tutorial to understand how the information in the specification and header files is translated into Visual Basic.

 
< previous page page_394 next page >