要写这几个函数会频繁用到FOA转VA
//文件里的偏移转化为内存偏移
DWORD FOAToVA(DWORD FOA, PVOID pFileBuffer) {
PIMAGE_DOS_HEADER pDosHeader = pFileBuffer;
PIMAGE_NT_HEADERS pNTHeader = (DWORD)pDosHeader + pDosHeader->e_lfanew;
if (pNTHeader->Signature != IMAGE_NT_SIGNATURE) {
printf("File is not PE\n");
free(pFileBuffer);
return FALSE;
}
PIMAGE_FILE_HEADER pFileHeader = &pNTHeader->FileHeader;
PIMAGE_OPTIONAL_HEADER pOptHeader = (DWORD)pFileHeader + sizeof(IMAGE_FILE_HEADER);
PIMAGE_SECTION_HEADER pSecHeader = (DWORD)pOptHeader + pFileHeader->SizeOfOptionalHeader;
if (FOA < pSecHeader->PointerToRawData) {
return FOA + (DWORD)pFileBuffer;
}
for (size_t i = 0; i < pFileHeader->NumberOfSections; i++) {
if (FOA >= pSecHeader->PointerToRawData && FOA < (pSecHeader->PointerToRawData + pSecHeader->SizeOfRawData)) {
return pSecHeader->VirtualAddress + (FOA - pSecHeader->PointerToRawData);
}
pSecHeader++;
}
return 0;
}
//移动导出表
BOOL MoveExportTable(PVOID fileName,PVOID newFileName) {
if (!IncreaseSection(fileName)) {
printf("Increase section failed\n");
return FALSE;
}
PVOID pFileBuffer = FileToFileBuffer(newFileName);
//定位导出表
PIMAGE_DOS_HEADER pDosHeader = pFileBuffer;
PIMAGE_NT_HEADERS pNTHeader = (DWORD)pDosHeader + pDosHeader->e_lfanew;
if (pNTHeader->Signature != IMAGE_NT_SIGNATURE) {
printf("File is not PE\n");
free(pFileBuffer);
return FALSE;
}
PIMAGE_FILE_HEADER pFileHeader = &pNTHeader->FileHeader;
PIMAGE_OPTIONAL_HEADER pOptHeader = (DWORD)pFileHeader + sizeof(IMAGE_FILE_HEADER

最低0.47元/天 解锁文章
977





