[1166] | 1 | #ifndef _NTIMAGE_
|
---|
| 2 | #define _NTIMAGE_
|
---|
| 3 |
|
---|
| 4 | //
|
---|
| 5 | // Image Formats
|
---|
| 6 | //
|
---|
| 7 | #define IMAGE_DOS_SIGNATURE 0x5A4D
|
---|
| 8 | #define IMAGE_OS2_SIGNATURE 0x454E
|
---|
| 9 | #define IMAGE_OS2_SIGNATURE_LE 0x454C
|
---|
| 10 | #define IMAGE_VXD_SIGNATURE 0x454C
|
---|
| 11 | #define IMAGE_NT_SIGNATURE 0x00004550
|
---|
| 12 |
|
---|
| 13 | //
|
---|
| 14 | // Image architectures
|
---|
| 15 | //
|
---|
| 16 | #define IMAGE_FILE_MACHINE_AM33 0x1d3
|
---|
| 17 | #define IMAGE_FILE_MACHINE_AMD64 0x8664
|
---|
| 18 | #define IMAGE_FILE_MACHINE_ARM 0x1c0
|
---|
| 19 | #define IMAGE_FILE_MACHINE_ARMV7 0x1c4
|
---|
| 20 | #define IMAGE_FILE_MACHINE_EBC 0xebc
|
---|
| 21 | #define IMAGE_FILE_MACHINE_I386 0x14c
|
---|
| 22 | #define IMAGE_FILE_MACHINE_IA64 0x200
|
---|
| 23 | #define IMAGE_FILE_MACHINE_M32R 0x9041
|
---|
| 24 | #define IMAGE_FILE_MACHINE_MIPS16 0x266
|
---|
| 25 | #define IMAGE_FILE_MACHINE_MIPSFPU 0x366
|
---|
| 26 | #define IMAGE_FILE_MACHINE_MIPSFPU16 0x466
|
---|
| 27 | #define IMAGE_FILE_MACHINE_POWERPC 0x1f0
|
---|
| 28 | #define IMAGE_FILE_MACHINE_POWERPCFP 0x1f1
|
---|
| 29 | #define IMAGE_FILE_MACHINE_R4000 0x166
|
---|
| 30 | #define IMAGE_FILE_MACHINE_SH3 0x1a2
|
---|
| 31 | #define IMAGE_FILE_MACHINE_SH3E 0x01a4
|
---|
| 32 | #define IMAGE_FILE_MACHINE_SH3DSP 0x1a3
|
---|
| 33 | #define IMAGE_FILE_MACHINE_SH4 0x1a6
|
---|
| 34 | #define IMAGE_FILE_MACHINE_SH5 0x1a8
|
---|
| 35 | #define IMAGE_FILE_MACHINE_THUMB 0x1c2
|
---|
| 36 | #define IMAGE_FILE_MACHINE_WCEMIPSV2 0x169
|
---|
| 37 | #define IMAGE_FILE_MACHINE_R3000 0x162
|
---|
| 38 | #define IMAGE_FILE_MACHINE_R10000 0x168
|
---|
| 39 | #define IMAGE_FILE_MACHINE_ALPHA 0x184
|
---|
| 40 | #define IMAGE_FILE_MACHINE_ALPHA64 0x0284
|
---|
| 41 | #define IMAGE_FILE_MACHINE_AXP64 IMAGE_FILE_MACHINE_ALPHA64
|
---|
| 42 | #define IMAGE_FILE_MACHINE_CEE 0xC0EE
|
---|
| 43 | #define IMAGE_FILE_MACHINE_TRICORE 0x0520
|
---|
| 44 | #define IMAGE_FILE_MACHINE_CEF 0x0CEF
|
---|
| 45 |
|
---|
| 46 |
|
---|
| 47 | //
|
---|
| 48 | // DOS Image Header Format
|
---|
| 49 | //
|
---|
| 50 | #include <pshpack2.h>
|
---|
| 51 | typedef struct _IMAGE_DOS_HEADER {
|
---|
| 52 | USHORT e_magic;
|
---|
| 53 | USHORT e_cblp;
|
---|
| 54 | USHORT e_cp;
|
---|
| 55 | USHORT e_crlc;
|
---|
| 56 | USHORT e_cparhdr;
|
---|
| 57 | USHORT e_minalloc;
|
---|
| 58 | USHORT e_maxalloc;
|
---|
| 59 | USHORT e_ss;
|
---|
| 60 | USHORT e_sp;
|
---|
| 61 | USHORT e_csum;
|
---|
| 62 | USHORT e_ip;
|
---|
| 63 | USHORT e_cs;
|
---|
| 64 | USHORT e_lfarlc;
|
---|
| 65 | USHORT e_ovno;
|
---|
| 66 | USHORT e_res[4];
|
---|
| 67 | USHORT e_oemid;
|
---|
| 68 | USHORT e_oeminfo;
|
---|
| 69 | USHORT e_res2[10];
|
---|
| 70 | LONG e_lfanew;
|
---|
| 71 | } IMAGE_DOS_HEADER, *PIMAGE_DOS_HEADER;
|
---|
| 72 | #include <poppack.h>
|
---|
| 73 |
|
---|
| 74 |
|
---|
| 75 | //
|
---|
| 76 | // Export/Import Format
|
---|
| 77 | //
|
---|
| 78 | #include <pshpack4.h>
|
---|
| 79 | typedef struct _IMAGE_EXPORT_DIRECTORY {
|
---|
| 80 | ULONG Characteristics;
|
---|
| 81 | ULONG TimeDateStamp;
|
---|
| 82 | USHORT MajorVersion;
|
---|
| 83 | USHORT MinorVersion;
|
---|
| 84 | ULONG Name;
|
---|
| 85 | ULONG Base;
|
---|
| 86 | ULONG NumberOfFunctions;
|
---|
| 87 | ULONG NumberOfNames;
|
---|
| 88 | ULONG AddressOfFunctions;
|
---|
| 89 | ULONG AddressOfNames;
|
---|
| 90 | ULONG AddressOfNameOrdinals;
|
---|
| 91 | } IMAGE_EXPORT_DIRECTORY, *PIMAGE_EXPORT_DIRECTORY;
|
---|
| 92 |
|
---|
| 93 |
|
---|
| 94 | //
|
---|
| 95 | // Resource Data Entry Format
|
---|
| 96 | //
|
---|
| 97 | typedef struct _IMAGE_RESOURCE_DATA_ENTRY {
|
---|
| 98 | ULONG OffsetToData;
|
---|
| 99 | ULONG Size;
|
---|
| 100 | ULONG CodePage;
|
---|
| 101 | ULONG Reserved;
|
---|
| 102 | } IMAGE_RESOURCE_DATA_ENTRY, *PIMAGE_RESOURCE_DATA_ENTRY;
|
---|
| 103 |
|
---|
| 104 |
|
---|
| 105 | //
|
---|
| 106 | // Load Configuration Directory Entry Format
|
---|
| 107 | //
|
---|
| 108 | typedef struct {
|
---|
| 109 | ULONG Size;
|
---|
| 110 | ULONG TimeDateStamp;
|
---|
| 111 | USHORT MajorVersion;
|
---|
| 112 | USHORT MinorVersion;
|
---|
| 113 | ULONG GlobalFlagsClear;
|
---|
| 114 | ULONG GlobalFlagsSet;
|
---|
| 115 | ULONG CriticalSectionDefaultTimeout;
|
---|
| 116 | ULONG DeCommitFreeBlockThreshold;
|
---|
| 117 | ULONG DeCommitTotalFreeThreshold;
|
---|
| 118 | ULONG LockPrefixTable;
|
---|
| 119 | ULONG MaximumAllocationSize;
|
---|
| 120 | ULONG VirtualMemoryThreshold;
|
---|
| 121 | ULONG ProcessHeapFlags;
|
---|
| 122 | ULONG ProcessAffinityMask;
|
---|
| 123 | USHORT CSDVersion;
|
---|
| 124 | USHORT Reserved1;
|
---|
| 125 | ULONG EditList;
|
---|
| 126 | ULONG SecurityCookie;
|
---|
| 127 | ULONG SEHandlerTable;
|
---|
| 128 | ULONG SEHandlerCount;
|
---|
| 129 | } IMAGE_LOAD_CONFIG_DIRECTORY32, *PIMAGE_LOAD_CONFIG_DIRECTORY32;
|
---|
| 130 |
|
---|
| 131 | typedef struct {
|
---|
| 132 | ULONG Size;
|
---|
| 133 | ULONG TimeDateStamp;
|
---|
| 134 | USHORT MajorVersion;
|
---|
| 135 | USHORT MinorVersion;
|
---|
| 136 | ULONG GlobalFlagsClear;
|
---|
| 137 | ULONG GlobalFlagsSet;
|
---|
| 138 | ULONG CriticalSectionDefaultTimeout;
|
---|
| 139 | ULONGLONG DeCommitFreeBlockThreshold;
|
---|
| 140 | ULONGLONG DeCommitTotalFreeThreshold;
|
---|
| 141 | ULONGLONG LockPrefixTable;
|
---|
| 142 | ULONGLONG MaximumAllocationSize;
|
---|
| 143 | ULONGLONG VirtualMemoryThreshold;
|
---|
| 144 | ULONGLONG ProcessAffinityMask;
|
---|
| 145 | ULONG ProcessHeapFlags;
|
---|
| 146 | USHORT CSDVersion;
|
---|
| 147 | USHORT Reserved1;
|
---|
| 148 | ULONGLONG EditList;
|
---|
| 149 | ULONGLONG SecurityCookie;
|
---|
| 150 | ULONGLONG SEHandlerTable;
|
---|
| 151 | ULONGLONG SEHandlerCount;
|
---|
| 152 | } IMAGE_LOAD_CONFIG_DIRECTORY64, *PIMAGE_LOAD_CONFIG_DIRECTORY64;
|
---|
| 153 |
|
---|
| 154 | #ifdef _WIN64
|
---|
| 155 | typedef IMAGE_LOAD_CONFIG_DIRECTORY64 IMAGE_LOAD_CONFIG_DIRECTORY;
|
---|
| 156 | typedef PIMAGE_LOAD_CONFIG_DIRECTORY64 PIMAGE_LOAD_CONFIG_DIRECTORY;
|
---|
| 157 | #else
|
---|
| 158 | typedef IMAGE_LOAD_CONFIG_DIRECTORY32 IMAGE_LOAD_CONFIG_DIRECTORY;
|
---|
| 159 | typedef PIMAGE_LOAD_CONFIG_DIRECTORY32 PIMAGE_LOAD_CONFIG_DIRECTORY;
|
---|
| 160 | #endif
|
---|
| 161 |
|
---|
| 162 |
|
---|
| 163 | //
|
---|
| 164 | // Base Relocation Format
|
---|
| 165 | //
|
---|
| 166 | typedef struct _IMAGE_BASE_RELOCATION {
|
---|
| 167 | ULONG VirtualAddress;
|
---|
| 168 | ULONG SizeOfBlock;
|
---|
| 169 | } IMAGE_BASE_RELOCATION, *PIMAGE_BASE_RELOCATION;
|
---|
| 170 |
|
---|
| 171 |
|
---|
| 172 | //
|
---|
| 173 | // Resource Format
|
---|
| 174 | //
|
---|
| 175 | typedef struct _IMAGE_RESOURCE_DIRECTORY {
|
---|
| 176 | ULONG Characteristics;
|
---|
| 177 | ULONG TimeDateStamp;
|
---|
| 178 | USHORT MajorVersion;
|
---|
| 179 | USHORT MinorVersion;
|
---|
| 180 | USHORT NumberOfNamedEntries;
|
---|
| 181 | USHORT NumberOfIdEntries;
|
---|
| 182 | } IMAGE_RESOURCE_DIRECTORY, *PIMAGE_RESOURCE_DIRECTORY;
|
---|
| 183 |
|
---|
| 184 | typedef struct _IMAGE_RESOURCE_DIRECTORY_STRING {
|
---|
| 185 | USHORT Length;
|
---|
| 186 | CHAR NameString[ANYSIZE_ARRAY];
|
---|
| 187 | } IMAGE_RESOURCE_DIRECTORY_STRING, *PIMAGE_RESOURCE_DIRECTORY_STRING;
|
---|
| 188 |
|
---|
| 189 |
|
---|
| 190 | //
|
---|
| 191 | // Section Header Format
|
---|
| 192 | //
|
---|
| 193 | #define IMAGE_SIZEOF_SHORT_NAME 8
|
---|
| 194 | #define IMAGE_SIZEOF_SECTION_HEADER 40
|
---|
| 195 |
|
---|
| 196 | typedef struct _IMAGE_SECTION_HEADER {
|
---|
| 197 | UCHAR Name[IMAGE_SIZEOF_SHORT_NAME];
|
---|
| 198 | union
|
---|
| 199 | {
|
---|
| 200 | ULONG PhysicalAddress;
|
---|
| 201 | ULONG VirtualSize;
|
---|
| 202 | } Misc;
|
---|
| 203 | ULONG VirtualAddress;
|
---|
| 204 | ULONG SizeOfRawData;
|
---|
| 205 | ULONG PointerToRawData;
|
---|
| 206 | ULONG PointerToRelocations;
|
---|
| 207 | ULONG PointerToLinenumbers;
|
---|
| 208 | USHORT NumberOfRelocations;
|
---|
| 209 | USHORT NumberOfLinenumbers;
|
---|
| 210 | ULONG Characteristics;
|
---|
| 211 | } IMAGE_SECTION_HEADER, *PIMAGE_SECTION_HEADER;
|
---|
| 212 |
|
---|
| 213 | //
|
---|
| 214 | // Section Characteristics
|
---|
| 215 | //
|
---|
| 216 | #define IMAGE_SCN_CNT_CODE 0x00000020
|
---|
| 217 | #define IMAGE_SCN_CNT_INITIALIZED_DATA 0x00000040
|
---|
| 218 | #define IMAGE_SCN_CNT_UNINITIALIZED_DATA 0x00000080
|
---|
| 219 |
|
---|
| 220 | #define IMAGE_SCN_LNK_NRELOC_OVFL 0x01000000
|
---|
| 221 | #define IMAGE_SCN_MEM_DISCARDABLE 0x02000000
|
---|
| 222 | #define IMAGE_SCN_MEM_NOT_CACHED 0x04000000
|
---|
| 223 | #define IMAGE_SCN_MEM_NOT_PAGED 0x08000000
|
---|
| 224 | #define IMAGE_SCN_MEM_SHARED 0x10000000
|
---|
| 225 | #define IMAGE_SCN_MEM_EXECUTE 0x20000000
|
---|
| 226 | #define IMAGE_SCN_MEM_READ 0x40000000
|
---|
| 227 | #define IMAGE_SCN_MEM_WRITE 0x80000000
|
---|
| 228 |
|
---|
| 229 |
|
---|
| 230 | //
|
---|
| 231 | // File Header Format
|
---|
| 232 | //
|
---|
| 233 | #define IMAGE_SIZEOF_FILE_HEADER 20
|
---|
| 234 |
|
---|
| 235 | typedef struct _IMAGE_FILE_HEADER {
|
---|
| 236 | USHORT Machine;
|
---|
| 237 | USHORT NumberOfSections;
|
---|
| 238 | ULONG TimeDateStamp;
|
---|
| 239 | ULONG PointerToSymbolTable;
|
---|
| 240 | ULONG NumberOfSymbols;
|
---|
| 241 | USHORT SizeOfOptionalHeader;
|
---|
| 242 | USHORT Characteristics;
|
---|
| 243 | } IMAGE_FILE_HEADER, *PIMAGE_FILE_HEADER;
|
---|
| 244 |
|
---|
| 245 | //
|
---|
| 246 | // File Characteristics
|
---|
| 247 | //
|
---|
| 248 | #define IMAGE_FILE_RELOCS_STRIPPED 0x0001
|
---|
| 249 | #define IMAGE_FILE_EXECUTABLE_IMAGE 0x0002
|
---|
| 250 | #define IMAGE_FILE_LINE_NUMS_STRIPPED 0x0004
|
---|
| 251 | #define IMAGE_FILE_LOCAL_SYMS_STRIPPED 0x0008
|
---|
| 252 | #define IMAGE_FILE_AGGRESIVE_WS_TRIM 0x0010
|
---|
| 253 | #define IMAGE_FILE_LARGE_ADDRESS_AWARE 0x0020
|
---|
| 254 | #define IMAGE_FILE_BYTES_REVERSED_LO 0x0080
|
---|
| 255 | #define IMAGE_FILE_32BIT_MACHINE 0x0100
|
---|
| 256 | #define IMAGE_FILE_DEBUG_STRIPPED 0x0200
|
---|
| 257 | #define IMAGE_FILE_REMOVABLE_RUN_FROM_SWAP 0x0400
|
---|
| 258 | #define IMAGE_FILE_NET_RUN_FROM_SWAP 0x0800
|
---|
| 259 | #define IMAGE_FILE_SYSTEM 0x1000
|
---|
| 260 | #define IMAGE_FILE_DLL 0x2000
|
---|
| 261 | #define IMAGE_FILE_UP_SYSTEM_ONLY 0x4000
|
---|
| 262 | #define IMAGE_FILE_BYTES_REVERSED_HI 0x8000
|
---|
| 263 |
|
---|
| 264 |
|
---|
| 265 | //
|
---|
| 266 | // Directory format.
|
---|
| 267 | //
|
---|
| 268 | #define IMAGE_NUMBEROF_DIRECTORY_ENTRIES 16
|
---|
| 269 |
|
---|
| 270 | typedef struct _IMAGE_DATA_DIRECTORY {
|
---|
| 271 | ULONG VirtualAddress;
|
---|
| 272 | ULONG Size;
|
---|
| 273 | } IMAGE_DATA_DIRECTORY, *PIMAGE_DATA_DIRECTORY;
|
---|
| 274 |
|
---|
| 275 |
|
---|
| 276 | //
|
---|
| 277 | // Optional Header Formats
|
---|
| 278 | //
|
---|
| 279 | typedef struct _IMAGE_OPTIONAL_HEADER {
|
---|
| 280 | USHORT Magic;
|
---|
| 281 | UCHAR MajorLinkerVersion;
|
---|
| 282 | UCHAR MinorLinkerVersion;
|
---|
| 283 | ULONG SizeOfCode;
|
---|
| 284 | ULONG SizeOfInitializedData;
|
---|
| 285 | ULONG SizeOfUninitializedData;
|
---|
| 286 | ULONG AddressOfEntryPoint;
|
---|
| 287 | ULONG BaseOfCode;
|
---|
| 288 | ULONG BaseOfData;
|
---|
| 289 | ULONG ImageBase;
|
---|
| 290 | ULONG SectionAlignment;
|
---|
| 291 | ULONG FileAlignment;
|
---|
| 292 | USHORT MajorOperatingSystemVersion;
|
---|
| 293 | USHORT MinorOperatingSystemVersion;
|
---|
| 294 | USHORT MajorImageVersion;
|
---|
| 295 | USHORT MinorImageVersion;
|
---|
| 296 | USHORT MajorSubsystemVersion;
|
---|
| 297 | USHORT MinorSubsystemVersion;
|
---|
| 298 | ULONG Win32VersionValue;
|
---|
| 299 | ULONG SizeOfImage;
|
---|
| 300 | ULONG SizeOfHeaders;
|
---|
| 301 | ULONG CheckSum;
|
---|
| 302 | USHORT Subsystem;
|
---|
| 303 | USHORT DllCharacteristics;
|
---|
| 304 | ULONG SizeOfStackReserve;
|
---|
| 305 | ULONG SizeOfStackCommit;
|
---|
| 306 | ULONG SizeOfHeapReserve;
|
---|
| 307 | ULONG SizeOfHeapCommit;
|
---|
| 308 | ULONG LoaderFlags;
|
---|
| 309 | ULONG NumberOfRvaAndSizes;
|
---|
| 310 | IMAGE_DATA_DIRECTORY DataDirectory[IMAGE_NUMBEROF_DIRECTORY_ENTRIES];
|
---|
| 311 | } IMAGE_OPTIONAL_HEADER32, *PIMAGE_OPTIONAL_HEADER32;
|
---|
| 312 |
|
---|
| 313 | typedef struct _IMAGE_ROM_OPTIONAL_HEADER {
|
---|
| 314 | USHORT Magic;
|
---|
| 315 | UCHAR MajorLinkerVersion;
|
---|
| 316 | UCHAR MinorLinkerVersion;
|
---|
| 317 | ULONG SizeOfCode;
|
---|
| 318 | ULONG SizeOfInitializedData;
|
---|
| 319 | ULONG SizeOfUninitializedData;
|
---|
| 320 | ULONG AddressOfEntryPoint;
|
---|
| 321 | ULONG BaseOfCode;
|
---|
| 322 | ULONG BaseOfData;
|
---|
| 323 | ULONG BaseOfBss;
|
---|
| 324 | ULONG GprMask;
|
---|
| 325 | ULONG CprMask[4];
|
---|
| 326 | ULONG GpValue;
|
---|
| 327 | } IMAGE_ROM_OPTIONAL_HEADER, *PIMAGE_ROM_OPTIONAL_HEADER;
|
---|
| 328 |
|
---|
| 329 | typedef struct _IMAGE_OPTIONAL_HEADER64 {
|
---|
| 330 | USHORT Magic;
|
---|
| 331 | UCHAR MajorLinkerVersion;
|
---|
| 332 | UCHAR MinorLinkerVersion;
|
---|
| 333 | ULONG SizeOfCode;
|
---|
| 334 | ULONG SizeOfInitializedData;
|
---|
| 335 | ULONG SizeOfUninitializedData;
|
---|
| 336 | ULONG AddressOfEntryPoint;
|
---|
| 337 | ULONG BaseOfCode;
|
---|
| 338 | ULONGLONG ImageBase;
|
---|
| 339 | ULONG SectionAlignment;
|
---|
| 340 | ULONG FileAlignment;
|
---|
| 341 | USHORT MajorOperatingSystemVersion;
|
---|
| 342 | USHORT MinorOperatingSystemVersion;
|
---|
| 343 | USHORT MajorImageVersion;
|
---|
| 344 | USHORT MinorImageVersion;
|
---|
| 345 | USHORT MajorSubsystemVersion;
|
---|
| 346 | USHORT MinorSubsystemVersion;
|
---|
| 347 | ULONG Win32VersionValue;
|
---|
| 348 | ULONG SizeOfImage;
|
---|
| 349 | ULONG SizeOfHeaders;
|
---|
| 350 | ULONG CheckSum;
|
---|
| 351 | USHORT Subsystem;
|
---|
| 352 | USHORT DllCharacteristics;
|
---|
| 353 | ULONGLONG SizeOfStackReserve;
|
---|
| 354 | ULONGLONG SizeOfStackCommit;
|
---|
| 355 | ULONGLONG SizeOfHeapReserve;
|
---|
| 356 | ULONGLONG SizeOfHeapCommit;
|
---|
| 357 | ULONG LoaderFlags;
|
---|
| 358 | ULONG NumberOfRvaAndSizes;
|
---|
| 359 | IMAGE_DATA_DIRECTORY DataDirectory[IMAGE_NUMBEROF_DIRECTORY_ENTRIES];
|
---|
| 360 | } IMAGE_OPTIONAL_HEADER64, *PIMAGE_OPTIONAL_HEADER64;
|
---|
| 361 |
|
---|
| 362 | //
|
---|
| 363 | // Format Identifier Magics
|
---|
| 364 | //
|
---|
| 365 | #define IMAGE_NT_OPTIONAL_HDR32_MAGIC 0x10b
|
---|
| 366 | #define IMAGE_NT_OPTIONAL_HDR64_MAGIC 0x20b
|
---|
| 367 | #define IMAGE_ROM_OPTIONAL_HDR_MAGIC 0x107
|
---|
| 368 |
|
---|
| 369 |
|
---|
| 370 | #ifdef _WIN64
|
---|
| 371 | typedef IMAGE_OPTIONAL_HEADER64 IMAGE_OPTIONAL_HEADER;
|
---|
| 372 | typedef PIMAGE_OPTIONAL_HEADER64 PIMAGE_OPTIONAL_HEADER;
|
---|
| 373 | #define IMAGE_NT_OPTIONAL_HDR_MAGIC IMAGE_NT_OPTIONAL_HDR64_MAGIC
|
---|
| 374 | #else
|
---|
| 375 | typedef IMAGE_OPTIONAL_HEADER32 IMAGE_OPTIONAL_HEADER;
|
---|
| 376 | typedef PIMAGE_OPTIONAL_HEADER32 PIMAGE_OPTIONAL_HEADER;
|
---|
| 377 | #define IMAGE_NT_OPTIONAL_HDR_MAGIC IMAGE_NT_OPTIONAL_HDR32_MAGIC
|
---|
| 378 | #endif
|
---|
| 379 |
|
---|
| 380 |
|
---|
| 381 | //
|
---|
| 382 | // Nt Header Formats
|
---|
| 383 | //
|
---|
| 384 | typedef struct _IMAGE_NT_HEADERS64 {
|
---|
| 385 | ULONG Signature;
|
---|
| 386 | IMAGE_FILE_HEADER FileHeader;
|
---|
| 387 | IMAGE_OPTIONAL_HEADER64 OptionalHeader;
|
---|
| 388 | } IMAGE_NT_HEADERS64;
|
---|
| 389 |
|
---|
| 390 | typedef struct _IMAGE_NT_HEADERS {
|
---|
| 391 | ULONG Signature;
|
---|
| 392 | IMAGE_FILE_HEADER FileHeader;
|
---|
| 393 | IMAGE_OPTIONAL_HEADER32 OptionalHeader;
|
---|
| 394 | } IMAGE_NT_HEADERS32;
|
---|
| 395 |
|
---|
| 396 | #ifdef _WIN64
|
---|
| 397 | typedef IMAGE_NT_HEADERS64 IMAGE_NT_HEADERS;
|
---|
| 398 | #else
|
---|
| 399 | typedef IMAGE_NT_HEADERS32 IMAGE_NT_HEADERS;
|
---|
| 400 | #endif
|
---|
| 401 |
|
---|
| 402 | #ifndef _NTDDK_
|
---|
| 403 |
|
---|
| 404 | typedef struct _IMAGE_NT_HEADERS *PIMAGE_NT_HEADERS32;
|
---|
| 405 | typedef struct _IMAGE_NT_HEADERS64 *PIMAGE_NT_HEADERS64;
|
---|
| 406 |
|
---|
| 407 | #ifdef _WIN64
|
---|
| 408 | typedef PIMAGE_NT_HEADERS64 PIMAGE_NT_HEADERS;
|
---|
| 409 | #else
|
---|
| 410 | typedef PIMAGE_NT_HEADERS32 PIMAGE_NT_HEADERS;
|
---|
| 411 | #endif
|
---|
| 412 |
|
---|
| 413 | #endif /* _NTDDK_ */
|
---|
| 414 |
|
---|
| 415 | //
|
---|
| 416 | // Retreives the first image section header from the Nt Header
|
---|
| 417 | //
|
---|
| 418 | #define IMAGE_FIRST_SECTION( NtHeader ) ((PIMAGE_SECTION_HEADER) \
|
---|
| 419 | ((ULONG_PTR)(NtHeader) + \
|
---|
| 420 | FIELD_OFFSET( IMAGE_NT_HEADERS, OptionalHeader ) + \
|
---|
| 421 | ((NtHeader))->FileHeader.SizeOfOptionalHeader \
|
---|
| 422 | ))
|
---|
| 423 |
|
---|
| 424 | //
|
---|
| 425 | // Dll Characteristics
|
---|
| 426 | //
|
---|
| 427 | #define IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA 0x0020
|
---|
| 428 | #define IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE 0x0040
|
---|
| 429 | #define IMAGE_DLLCHARACTERISTICS_FORCE_INTEGRITY 0x0080
|
---|
| 430 | #define IMAGE_DLLCHARACTERISTICS_NX_COMPAT 0x0100
|
---|
| 431 | #define IMAGE_DLLCHARACTERISTICS_NO_ISOLATION 0x0200
|
---|
| 432 | #define IMAGE_DLLCHARACTERISTICS_NO_SEH 0x0400
|
---|
| 433 | #define IMAGE_DLLCHARACTERISTICS_NO_BIND 0x0800
|
---|
| 434 | #define IMAGE_DLLCHARACTERISTICS_APPCONTAINER 0x1000
|
---|
| 435 | #define IMAGE_DLLCHARACTERISTICS_WDM_DRIVER 0x2000
|
---|
| 436 | #define IMAGE_DLLCHARACTERISTICS_GUARD_CF 0x4000
|
---|
| 437 | #define IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE 0x8000
|
---|
| 438 |
|
---|
| 439 | //
|
---|
| 440 | // Loader Flags
|
---|
| 441 | //
|
---|
| 442 | #define IMAGE_LOADER_FLAGS_COMPLUS 0x00000001
|
---|
| 443 | #define IMAGE_LOADER_FLAGS_SYSTEM_GLOBAL 0x01000000
|
---|
| 444 |
|
---|
| 445 | //
|
---|
| 446 | // Directory Entry Specifiers
|
---|
| 447 | //
|
---|
| 448 | #define IMAGE_DIRECTORY_ENTRY_EXPORT 0
|
---|
| 449 | #define IMAGE_DIRECTORY_ENTRY_IMPORT 1
|
---|
| 450 | #define IMAGE_DIRECTORY_ENTRY_RESOURCE 2
|
---|
| 451 | #define IMAGE_DIRECTORY_ENTRY_EXCEPTION 3
|
---|
| 452 | #define IMAGE_DIRECTORY_ENTRY_SECURITY 4
|
---|
| 453 | #define IMAGE_DIRECTORY_ENTRY_BASERELOC 5
|
---|
| 454 | #define IMAGE_DIRECTORY_ENTRY_DEBUG 6
|
---|
| 455 | #define IMAGE_DIRECTORY_ENTRY_ARCHITECTURE 7
|
---|
| 456 | #define IMAGE_DIRECTORY_ENTRY_GLOBALPTR 8
|
---|
| 457 | #define IMAGE_DIRECTORY_ENTRY_TLS 9
|
---|
| 458 | #define IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG 10
|
---|
| 459 | #define IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT 11
|
---|
| 460 | #define IMAGE_DIRECTORY_ENTRY_IAT 12
|
---|
| 461 | #define IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT 13
|
---|
| 462 | #define IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR 14
|
---|
| 463 |
|
---|
| 464 |
|
---|
| 465 | //
|
---|
| 466 | // Import Formats
|
---|
| 467 | //
|
---|
| 468 | typedef struct _IMAGE_IMPORT_BY_NAME {
|
---|
| 469 | USHORT Hint;
|
---|
| 470 | UCHAR Name[1];
|
---|
| 471 | } IMAGE_IMPORT_BY_NAME, *PIMAGE_IMPORT_BY_NAME;
|
---|
| 472 |
|
---|
| 473 | #include <pshpack8.h>
|
---|
| 474 | typedef struct _IMAGE_THUNK_DATA64 {
|
---|
| 475 | union {
|
---|
| 476 | ULONGLONG ForwarderString;
|
---|
| 477 | ULONGLONG Function;
|
---|
| 478 | ULONGLONG Ordinal;
|
---|
| 479 | ULONGLONG AddressOfData;
|
---|
| 480 | } u1;
|
---|
| 481 | } IMAGE_THUNK_DATA64, *PIMAGE_THUNK_DATA64;
|
---|
| 482 | #include <poppack.h>
|
---|
| 483 |
|
---|
| 484 | typedef struct _IMAGE_THUNK_DATA32 {
|
---|
| 485 | union {
|
---|
| 486 | ULONG ForwarderString;
|
---|
| 487 | ULONG Function;
|
---|
| 488 | ULONG Ordinal;
|
---|
| 489 | ULONG AddressOfData;
|
---|
| 490 | } u1;
|
---|
| 491 | } IMAGE_THUNK_DATA32, *PIMAGE_THUNK_DATA32;
|
---|
| 492 |
|
---|
| 493 | #define IMAGE_ORDINAL_FLAG64 0x8000000000000000ULL
|
---|
| 494 | #define IMAGE_ORDINAL_FLAG32 0x80000000
|
---|
| 495 | #define IMAGE_ORDINAL64(Ordinal) (Ordinal & 0xffff)
|
---|
| 496 | #define IMAGE_ORDINAL32(Ordinal) (Ordinal & 0xffff)
|
---|
| 497 | #define IMAGE_SNAP_BY_ORDINAL64(Ordinal) ((Ordinal & IMAGE_ORDINAL_FLAG64) != 0)
|
---|
| 498 | #define IMAGE_SNAP_BY_ORDINAL32(Ordinal) ((Ordinal & IMAGE_ORDINAL_FLAG32) != 0)
|
---|
| 499 |
|
---|
| 500 |
|
---|
| 501 | //
|
---|
| 502 | // Thread Local Storage (TLS)
|
---|
| 503 | //
|
---|
| 504 | typedef
|
---|
| 505 | VOID
|
---|
| 506 | (NTAPI *PIMAGE_TLS_CALLBACK) (
|
---|
| 507 | PVOID DllHandle,
|
---|
| 508 | ULONG Reason,
|
---|
| 509 | PVOID Reserved
|
---|
| 510 | );
|
---|
| 511 |
|
---|
| 512 | typedef struct _IMAGE_TLS_DIRECTORY64 {
|
---|
| 513 | ULONGLONG StartAddressOfRawData;
|
---|
| 514 | ULONGLONG EndAddressOfRawData;
|
---|
| 515 | ULONGLONG AddressOfIndex;
|
---|
| 516 | ULONGLONG AddressOfCallBacks;
|
---|
| 517 | ULONG SizeOfZeroFill;
|
---|
| 518 | ULONG Characteristics;
|
---|
| 519 | } IMAGE_TLS_DIRECTORY64, *PIMAGE_TLS_DIRECTORY64;
|
---|
| 520 |
|
---|
| 521 | typedef struct _IMAGE_TLS_DIRECTORY32 {
|
---|
| 522 | ULONG StartAddressOfRawData;
|
---|
| 523 | ULONG EndAddressOfRawData;
|
---|
| 524 | ULONG AddressOfIndex;
|
---|
| 525 | ULONG AddressOfCallBacks;
|
---|
| 526 | ULONG SizeOfZeroFill;
|
---|
| 527 | ULONG Characteristics;
|
---|
| 528 | } IMAGE_TLS_DIRECTORY32, *PIMAGE_TLS_DIRECTORY32;
|
---|
| 529 |
|
---|
| 530 | #ifdef _WIN64
|
---|
| 531 | #define IMAGE_ORDINAL_FLAG IMAGE_ORDINAL_FLAG64
|
---|
| 532 | #define IMAGE_ORDINAL(Ordinal) IMAGE_ORDINAL64(Ordinal)
|
---|
| 533 | typedef IMAGE_THUNK_DATA64 IMAGE_THUNK_DATA;
|
---|
| 534 | typedef PIMAGE_THUNK_DATA64 PIMAGE_THUNK_DATA;
|
---|
| 535 | #define IMAGE_SNAP_BY_ORDINAL(Ordinal) IMAGE_SNAP_BY_ORDINAL64(Ordinal)
|
---|
| 536 | typedef IMAGE_TLS_DIRECTORY64 IMAGE_TLS_DIRECTORY;
|
---|
| 537 | typedef PIMAGE_TLS_DIRECTORY64 PIMAGE_TLS_DIRECTORY;
|
---|
| 538 | #else
|
---|
| 539 | #define IMAGE_ORDINAL_FLAG IMAGE_ORDINAL_FLAG32
|
---|
| 540 | #define IMAGE_ORDINAL(Ordinal) IMAGE_ORDINAL32(Ordinal)
|
---|
| 541 | typedef IMAGE_THUNK_DATA32 IMAGE_THUNK_DATA;
|
---|
| 542 | typedef PIMAGE_THUNK_DATA32 PIMAGE_THUNK_DATA;
|
---|
| 543 | #define IMAGE_SNAP_BY_ORDINAL(Ordinal) IMAGE_SNAP_BY_ORDINAL32(Ordinal)
|
---|
| 544 | typedef IMAGE_TLS_DIRECTORY32 IMAGE_TLS_DIRECTORY;
|
---|
| 545 | typedef PIMAGE_TLS_DIRECTORY32 PIMAGE_TLS_DIRECTORY;
|
---|
| 546 | #endif
|
---|
| 547 |
|
---|
| 548 | typedef struct _IMAGE_IMPORT_DESCRIPTOR {
|
---|
| 549 | _ANONYMOUS_UNION union {
|
---|
| 550 | ULONG Characteristics;
|
---|
| 551 | ULONG OriginalFirstThunk;
|
---|
| 552 | } DUMMYUNIONNAME;
|
---|
| 553 | ULONG TimeDateStamp;
|
---|
| 554 | ULONG ForwarderChain;
|
---|
| 555 | ULONG Name;
|
---|
| 556 | ULONG FirstThunk;
|
---|
| 557 | } IMAGE_IMPORT_DESCRIPTOR, *PIMAGE_IMPORT_DESCRIPTOR;
|
---|
| 558 |
|
---|
| 559 | #include <poppack.h>
|
---|
| 560 |
|
---|
| 561 |
|
---|
| 562 | #endif /* _NTIMAGE_ */
|
---|
| 563 |
|
---|