Solved

Get import table of a running process

Posted on 2003-11-11
16
1,035 Views
Last Modified: 2012-06-27
Hello,

I know the handle of an running process (  hProcess := OpenProcess(AccessRights, FALSE, PID); ) and I want to know which DLL files it have loaded. I do not want to know which DLL is in the process space of this running process (injected DLLs can be also in the process space, but injected DLLs are not loaded from a process, because injected DLLs are injected to the process.)
That means I can not use EnumProcessModules or Module32First, because these functions also enumerate the injected DLLs.
A solution could be to get the import table of this running process and look for the DLLs which the process is using. How can I do this? The .exe file of the running process is compressed, so I have to get the import table from the process in memory - not from the .exe file.
The solution should work on Windows NT (Win9x would be fine).

Thanky you for your answer for this difficult question
Ben

BTW: I think, here you can found something similar: Look for "function GetProcAddress32" at http://www.delphipages.com/news/detaildocs.cfm?ID=17
or look for "FindCallerModuleHandle" on http://groups.google.com

0
Comment
Question by:bengore
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 8
  • 4
  • 2
16 Comments
 
LVL 6

Accepted Solution

by:
GloomyFriar earned 250 total points
ID: 9721872
In a "running process" there is no differences between "loaded" and "injected" DLLs.
0
 
LVL 6

Expert Comment

by:GloomyFriar
ID: 9721884
"import table" may contain not all DLLs. How about DLLs loaded by LoadLibrary?
0
 
LVL 6

Expert Comment

by:GloomyFriar
ID: 9721901
Could you tell more detailed what do you want to make?
0
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:bengore
ID: 9721915
GloomyFriar, thank you for your comments.
How about DLLs linked static (not loaded by LoadLibrary). Is there a way to get this DLLs via "import table"?
0
 

Author Comment

by:bengore
ID: 9721974
More details? I have a DLL file. I want to know if a processes (somethimes with comressed .exe files) needs this DLL file (static linked).
0
 
LVL 6

Assisted Solution

by:DaFox
DaFox earned 250 total points
ID: 9722777
In Jeffrey Richter's book there is a DLL called ImgWalk.dll (lists all DLLs used by a process).

Markus
0
 

Author Comment

by:bengore
ID: 9723271
DaFox, I think ImgWalk.dll use EnumProcessModules or Module32First and enumerate also injected DLLs.
0
 
LVL 6

Expert Comment

by:DaFox
ID: 9723316
>> I think ImgWalk.dll use EnumProcessModules or Module32First

nope, it uses VirtualQuery that fills the MEMORY_BASIC_INFORMATION structure.

>> injected DLLs

that's right, and therefore it also gets dynamically loaded dlls.

Markus
0
 
LVL 6

Expert Comment

by:GloomyFriar
ID: 9724609
>How about DLLs linked static (not loaded by LoadLibrary). Is there a way to get this DLLs via "import table"?
Yes of course.
You just need to open the exe file and read its PE header.
0
 
LVL 6

Expert Comment

by:GloomyFriar
ID: 9724711
Something like that (it work with running exe, but you can do the same with a file):

function FindUsablePage(hProcess: THANDLE; PProcessBase: pointer): pointer;
var peHdrOffset: DWORD;
    cBytesMoved: DWORD;
    ntHdr: IMAGE_NT_HEADERS;
    pSection: ^IMAGE_SECTION_HEADER;
    i: ULONG;
    tmpPtr: PBYTE;
    section: IMAGE_SECTION_HEADER;
    SecName: string;
begin
   Result := nil;

   // Read in the offset of the PE header within the debuggee
   tmpPtr := PBYTE(PProcessBase);
   inc(tmpPtr, $3C);
   if ReadProcessMemory(ProcessInformation.hProcess,
                        tmpPtr,
                        @peHdrOffset,
                        sizeof(peHdrOffset),
                        cBytesMoved) = False then Exit;

   // Read in the IMAGE_NT_HEADERS.OptionalHeader.BaseOfCode field
   tmpPtr := PBYTE(PProcessBase);
   inc(tmpPtr, peHdrOffset);
   if ReadProcessMemory(ProcessInformation.hProcess,
                        tmpPtr, @ntHdr, sizeof(ntHdr),
                        cBytesMoved) = False then Exit;

   tmpPtr := PBYTE(PProcessBase);
   inc(tmpPtr, peHdrOffset + 4 + sizeof(ntHdr.FileHeader) +
       ntHdr.FileHeader.SizeOfOptionalHeader);
   pSection := pointer(tmpPtr);//(PIMAGE_SECTION_HEADER)

  for i:=0 to Pred(ntHdr.FileHeader.NumberOfSections) do begin
     //{IMAGE_SECTION_HEADER section;
     if ReadProcessMemory(ProcessInformation.hProcess,
                          pSection, @section, sizeof(section),
                          cBytesMoved) = False then Exit;
     // OutputDebugString( "trying section:
     // OutputDebugString( section.Name )'
     // OutputDebugString( "\r\n" )'

     SecName := StrPas(@section.Name[0]);
     // If it's writeable, and not the .idata section, we'll go with it
     if(((section.Characteristics and IMAGE_SCN_MEM_WRITE) <> 0) and
        (StrLComp(@section.Name[0], '.idata', 6) <> 0)) then begin
         OutputDebugString(PChar('using section.' + StrPas(@section.Name[0]) + #10 + #13));
        Result := pointer(DWORD(PProcessBase) + section.VirtualAddress);
        //Exit;
     end;
     Inc(pSection); // Not this section. Advance to next section.
  end;
end;
0
 
LVL 6

Expert Comment

by:GloomyFriar
ID: 9724775
0
 
LVL 6

Expert Comment

by:GloomyFriar
ID: 9724991
Here is the code that read exports, but it's rather easy to make it read imports.
If any problems I'll can help tomorrow.

http://www.experts-exchange.com/Programming/Programming_Languages/Delphi/Q_20079575.html
0
 

Author Comment

by:bengore
ID: 9729404
Hi GloomyFriar, thank you for your FindUsablePage source and the other links. I will check it.

> You just need to open the exe file and read its PE header.
This is not usefull, if the .exe file is compressed.
0
 
LVL 6

Expert Comment

by:GloomyFriar
ID: 9733230
>This is not usefull, if the .exe file is compressed.
Which compressor is used?
Are you sure that import sections is changed by the compressor?
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article explains how to create forms/units independent of other forms/units object names in a delphi project. Have you ever created a form for user input in a Delphi project and then had the need to have that same form in a other Delphi proj…
Introduction Raise your hands if you were as upset with FireMonkey as I was when I discovered that there was no TListview.  I use TListView in almost all of my applications I've written, and I was not going to compromise by resorting to TStringGrid…
In this video, viewers will be given step by step instructions on adjusting mouse, pointer and cursor visibility in Microsoft Windows 10. The video seeks to educate those who are struggling with the new Windows 10 Graphical User Interface. Change Cu…
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…
Suggested Courses
Course of the Month11 days, 4 hours left to enroll

628 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question