Function name from offset?

If I have information such as:

AppName: myapp.exe   
AppVer: x.x.x.x  
ModName: kernel32.dll 
ModVer: 5.1.2600.3541    
Offset: 00012a6b

Is it possible for me to determine which function exists at offset 00012a6b in kernel32.dll?

+3
source share
2 answers

they are called dll viewers. this is just one example from a quick web search. but yes they exist

http://www.nirsoft.net/utils/dll_export_viewer.html

+3
source

Run windbg, download the application and run

ln address

in the debugger and it will print the closest character.

+5
source

Source: https://habr.com/ru/post/1714218/


All Articles