Tuts 4 You

import address resolution through loadlibrary

abhijit mohanta

abhijit mohanta


I am quite new to malware analysis.I want to know do we need to fix imports that that are resolved dynamically using loadLibary() and getProcAddress() as we do case of import Resolved by IAT

If so how to do it?

For the "how to do it" you need to do some reading about other protectors/malware. Not something that can really be covered easily in a post.

Be aware though that sometimes GetProcAddress is emulated i.e. the same functionality is achieved without calling the API itself. Just makes things a little trickier.

abhijit mohanta


I know how to fix imports in case of API redirection .

I have idea on how address are resolved dynamically and I think we can know the dynamic calls though API spy which employ hooking mechanism.But can u please give me some more guidance or any references which can help me to proceed furthur.

