Skip to content

Wrong import observed in dumped dlls #36

@greenozon

Description

@greenozon

while using pd with pid NNN
I've observed some strange behaviour in produced dlls..

here is an example:

original kernel32.dll module:

Image

and this is what being produced by pd64 -pid 3464 (one of the chrome.exe child process)

Image

the appended (fake?) entries list is huge (as you see it has 1361 imported dlls!)
majority of added records are duplicates (eg kernel32.dll LZDone
eg here is the end:

Image

so the question is:
is it possible to determine the real effective and of table and not append some fake records?

seen it almost on all dumped dlls....

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions