-
-
[求助]这段数据的含义是什么?(PE文件结构)
-
发表于:
2014-12-31 13:28
3958
-
Offset 0 1 2 3 4 5 6 7 8 9 A B C D E F
00000640 8C 20 00 00 00 00 00 00 00 00 00 00 74 21 00 00 ? t!
00000650 10 20 00 00 7C 20 00 00 00 00 00 00 00 00 00 00 |
00000660 B4 21 00 00 00 20 00 00 00 00 00 00 00 00 00 00 ?
00000670 00 00 00 00 00 00 00 00 00 00 00 00
A0 21 00 00 ?
00000680
8E 21 00 00 80 21 00 00 00 00 00 00 10 21 00 00 ? €! !
00000690 1C 21 00 00 F4 20 00 00 E0 20 00 00 50 21 00 00 ! ? ? P!
000006A0 64 21 00 00 02 21 00 00 CE 20 00 00 BC 20 00 00 d! ! ? ?
000006B0 2E 21 00 00 42 21 00 00 00 00 00 00 58 00 43 72 .! B! X Cr
这是加密与解密中PE.EXE文件中的一段,红色字体前的代码是输入表IMAGE_IMPORT_DIRECTORY,红色字体后的是OriginalFirstThunk。
那么红色字体:"
A0 21 00 00 8E 21 00 00 80 21 00 00 00 00 00 00 "是什么?
几个数据换算的结果是能指向三个函数:780h--ExitProcess、78Eh--GetCommandLineA和7A0h--GetModuleHandleA,这 样指向是否正确,含义是什么?是怎样定义的?
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课