VS2017嵌套DLL断点设置:如何获取已加载DLL的起始地址?
Hey, let's tackle this problem step by step—since your nested DLL isn't showing up in VS2017's Modules window and you don't have PDBs, here are a few reliable ways to grab its base address once it's loaded into the process:
方法1:使用VS即时窗口调用Win32 API
First, make sure your program is paused at a point where the nested DLL has already been loaded (you can set a breakpoint right before the function call that triggers the DLL load). Then open the Immediate Window via Debug → Windows → Immediate and run this command:
(HMODULE)GetModuleHandle(L"your_target_dll.dll")
Replace your_target_dll.dll with the exact name of your nested DLL (include the .dll suffix). This will return the DLL's base address in hex format (like 0x00007FFABC120000). The GetModuleHandle API works regardless of whether the DLL shows up in VS's Modules window, as long as it's loaded into the process space.
方法2:用Process Explorer查看模块基地址
If you prefer a tool outside the debugger, use Process Explorer:
- Launch Process Explorer and locate your target process.
- Right-click the process → select Properties.
- Switch to the Modules tab, find your nested DLL in the list, and check the Base Address column—this is the DLL's starting address.
方法3:VS命令窗口执行模块列表命令
Open VS's Command Window via View → Other Windows → Command Window, type > to enter command mode, then run:
lm m *your_dll_name*
The * acts as a wildcard to filter the module list. You'll see your target DLL along with its base address. If you run just lm, it will list all loaded modules (it might be longer, but you can still scan for your DLL).
Once you have the base address, add the Relative Virtual Address (RVA) you got from dumpbin to get the absolute function address. For example:
- Base address:
0x12340000 - Dumpbin offset (RVA):
0x5678 - Absolute function address:
0x12340000 + 0x5678 = 0x12345678
Then go back to VS's Command Window and set the breakpoint with:
bp 0x12345678
Just make sure the address matches the bitness of your program (32-bit vs 64-bit) to avoid issues.
内容的提问来源于stack exchange,提问作者Steve London

