Link to home
Start Free TrialLog in
Avatar of ThievingSix
ThievingSixFlag for United States of America

asked on

Editing IAT/Import Table on the fly.

My question might be easier to understand if I give some background information.

I made a nice writeprocessmemory, and readprocessmemory hook in a dll and a program to log the function calls of a selected process. Works fine for some programs, but not for others. So I thought, why not take the program you want to log, run it suspended, and change the import table of the selected functions to point to your code.

Any hints/tips/code would be appreciated. =)
ASKER CERTIFIED SOLUTION
Avatar of Russell Libby
Russell Libby
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial