为何DUMPBIN /imports无法显示DeleteFileW?如何用DUMPBIN查看?
DeleteFileW via DUMPBIN When It's Not in Your EXE's Imports Great question! The reason you don't see DeleteFileW in your EXE's import table when running DUMPBIN /imports is because the remove function from the C Standard Library doesn't directly expose DeleteFileW as an import of your executable. Instead, the call chain goes through the C Runtime (CRT) library your program links against—here's how to verify it with DUMPBIN:
1. Check the CRT Library's Import Table
Your EXE only imports the CRT's remove function (from a DLL like msvcrt.dll, ucrtbase.dll, or a version-specific CRT DLL). To see DeleteFileW, you need to inspect the CRT DLL's imports:
- First, run
DUMPBIN /imports your_program.exeto identify which CRT DLL your program depends on (look for entries likemsvcrt.dllin the import list). - Then, run
DUMPBIN /imports path\to\crt_dll.dll(e.g.,DUMPBIN /imports C:\Windows\System32\msvcrt.dll). You'll findDeleteFileWlisted under thekernel32.dllimports section of the CRT DLL.
2. Check for Delay-Loaded Imports
If your program uses delay loading for the CRT or kernel32.dll functions, DeleteFileW won't show up in the standard import table. Instead, use this command to check delay-loaded imports:
DUMPBIN /delayload your_program.exe
This will reveal any functions marked for delayed loading, including DeleteFileW if it's loaded this way by the CRT or your code.
3. Inspect Disassembly to Trace the Call Chain
If the CRT uses dynamic loading (via LoadLibraryW and GetProcAddress) to fetch DeleteFileW at runtime (common in some CRT configurations), it won't appear in any import table. To confirm this, run:
DUMPBIN /disasm your_program.exe
Locate the call to remove, then trace through the disassembly to the CRT's implementation of remove—you'll see code that dynamically loads kernel32.dll and retrieves the DeleteFileW function pointer.
内容的提问来源于stack exchange,提问作者user7274385

