Return to site

Windows 8.1 x64 u1 pe

broken image
broken image

HModule=ManualInject->fnLoadLibraryA((LPCSTR)ManualInject->ImageBase+pIID->Name) OrigFirstThunk=(PIMAGE_THUNK_DATA)((LPBYTE)ManualInject->ImageBase+pIID->OriginalFirstThunk) įirstThunk=(PIMAGE_THUNK_DATA)((LPBYTE)ManualInject->ImageBase+pIID->FirstThunk) PIBR=(PIMAGE_BASE_RELOCATION)((LPBYTE)pIBR+pIBR->SizeOfBlock) If(pIBR->SizeOfBlock>=sizeof(IMAGE_BASE_RELOCATION))Ĭount=(pIBR->SizeOfBlock-sizeof(IMAGE_BASE_RELOCATION))/sizeof(WORD) įor(i=0 iImageBase+(pIBR->VirtualAddress+(list & 0xFFF))) PIMAGE_THUNK_DATA FirstThunk,OrigFirstThunk ĭelta=(DWORD)((LPBYTE)ManualInject->ImageBase-ManualInject->NtHeaders->OptionalHeader.ImageBase) // Calculate the delta

broken image

PIMAGE_IMPORT_DESCRIPTOR ImportDirectory Typedef BOOL (WINAPI *PDLL_MAIN)(HMODULE,DWORD,PVOID) Typedef FARPROC (WINAPI *pGetProcAddress)(HMODULE,LPCSTR)

broken image

Typedef HMODULE (WINAPI *pLoadLibraryA)(LPCSTR)

broken image