亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频

? 歡迎來到蟲蟲下載站! | ?? 資源下載 ?? 資源專輯 ?? 關于我們
? 蟲蟲下載站

?? procpath.asm

?? KmdKit 匯編下開發驅動的工具 由俄羅斯某強男開發
?? ASM
?? 第 1 頁 / 共 2 頁
字號:
	; DesiredAccess is also doesn't matter, by the way !!! It can be any value :)
	;
	; To make it really check the object type we must specify UserMode.
	;
	; The above note is applicable to all ObReferenceObjectByPointer calls in this source code.
	;
	; Also bear in mind that existence of AccessMode parameter for ObReferenceObjectByPointer
	; is odd (in my humble opinion). It's OK for ObReferenceObjectByHandle because we may deal
	; with handle passed from user mode, but if we already have a pointer to object it means we
	; have managed to get it somehow from kernel. So no need to check access type.
	; I've tested this driver on 2000, XP & 2003 and it seems to be workable.
	; But I'm afraid that behaviour of ObReferenceObjectByPointer may change in the future.
	; 

	; Although DesiredAccess doesn't matter we will always pass valid access mask.

	PROCESS_QUERY_INFORMATION equ 400h	; winnt.inc

	mov ecx, PsProcessType
	mov ecx, [ecx]
	mov ecx, [ecx]						; PTR OBJECT_TYPE

	invoke ObReferenceObjectByPointer, peProcess, PROCESS_QUERY_INFORMATION, ecx, UserMode
	.if eax == STATUS_SUCCESS

		.if g_dwWinVer == WINVER_UNINITIALIZED
		
			; We are first time here
			; What Windows we are running on?

			invoke IoIsWdmVersionAvailable, 1, 20h
			.if al
				; If WDM 1.20 is supported, this is Windows XP or better
				mov g_dwWinVer, WINVER_XP_OR_HIGHER
			.else
				; If not, this is Windows 2000
				mov g_dwWinVer, WINVER_2K
			.endif

		.endif

		.if g_dwWinVer == WINVER_XP_OR_HIGHER

			;
			; This is Windows XP or better
			; So we should find EPROCESS.SectionObject
			; XP:   EPROCESS.SectionObject at 0138h
			; 2003: EPROCESS.SectionObject at 0114h
			; We could hardcode offset but better try to find it
			;
			; I hope to find section object pointer
			; in the range 80h - 200h from beginning of EPROCESS
			;

			mov esi, peProcess
			mov ebx, 80h			; Start at offset 80h
			.while ebx < 204h

				; Filter unreasonable candidates

				mov edi, [esi][ebx]
				invoke IsLikeObjectPointer, edi
				.if eax == TRUE

					; Additional check. At the moment of process creation/destruction
					; base section object PointerCount equal to 3/2 and
					; HandleCount equal to 1/0. This is true under XP+.
					; Assume that PointerCount may grow up to 4.
					; This check let us filter the rest.

					mov eax, edi
					sub eax, sizeof OBJECT_HEADER

					.if ([OBJECT_HEADER PTR [eax]].PointerCount <= 4) && ([OBJECT_HEADER PTR [eax]].HandleCount <= 1)

						; Very high chances that edi holds base section object pointer.

						mov ecx, MmSectionObjectType
						mov ecx, [ecx]
						mov ecx, [ecx]	; PTR OBJECT_TYPE

						invoke ObReferenceObjectByPointer, edi, SECTION_QUERY, ecx, UserMode
						.if eax == STATUS_SUCCESS

							; edi seems really to be a pointer to base section object

							mov status, eax
							mov pSection, edi

							;invoke DbgPrint, \
							;	$CTA0("ProcessMon: Section object pointer found at offset %X\n"), \
							;	ebx

							.break
						.endif
					.endif
				.endif

				add ebx, 4			; Pointer must be DWORD aligned
									; So lets try next DWORD
			.endw

		.else

			;
			; We are under Windows 2000. On this system the section handle that
			; process image file mapped into is stored in EPROCESS.SectionHandle
			; and is always (with one exception) equal to 4 because it's very
			; first object created in the process.  Handle tables are implemented
			; as a three-level arrays, similar to the way that the x86 memory
			; management unit implements virtual to physical address translation.
			; The object manager treats the low 24 bits of an object handle's value
			; as three 8-bit fields that index into each of the three levels
			; in the handle table.  The arrays at each level consist of 256 entries.
			; Each entry is 4 bytes long because it contains pointer to the object.
			; The last entry in the subhandle table is initialized with a value of -1.
			;
			; So when a process is created, the object manager starts to fill subhandle
			; tables from the beginning of the subhandle table. (The 0 handle index
			; is reserved, first handle index is 4, the second 8, and so on).
			; So we can just reference handle 4 to get section object pointer.
			;
			; On w2k+sp4 if the process is started from command line (cmd.exe)
			; or bat file the section handle is not value of 4!  Don't know why
			; but in this particular case the object manager fills subhandle tables
			; in reverse order (from top to bottom).  So the first index it uses
			; is not 4 but 254 (255 initialized with a value of -1.)
			; 254*sizeof(pointer) = 03F8h
			;
			; I can't be shure it's so on any sp4 box, but it appears to be so
			; at least on 5-6 test machines.  So my first workaround
			; is to try reference handle 3F8h.
			;

			; If it still fails our last try just to reference whatever value
			; in EPROCESS.SectionHandle.

			xor ebx, ebx		; counter of tries
			mov edi, 4			; First try to reference handle 4 (most common).
			.while ebx < 3

				invoke IoGetCurrentProcess
				.if eax == peProcess
					
					; The same process context
					
					mov ecx, MmSectionObjectType
					mov ecx, [ecx]
					mov ecx, [ecx]	; PTR OBJECT_TYPE
				
					invoke ObReferenceObjectByHandle, edi, SECTION_QUERY, ecx, KernelMode, addr pSection, NULL
					mov status, eax

				.else

					; Different process. Since handles are process specific switch to target.

					invoke KeAttachProcess, peProcess

					mov ecx, MmSectionObjectType
					mov ecx, [ecx]
					mov ecx, [ecx]	; PTR OBJECT_TYPE

					invoke ObReferenceObjectByHandle, edi, SECTION_QUERY, ecx, KernelMode, addr pSection, NULL
					mov status, eax

					invoke KeDetachProcess

				.endif

				; If section referenced successefuly break.

				.break .if status == STATUS_SUCCESS

				; It seams we are under SP4 and process started from command line.
				; Handle invalid or object we probably tried to reference is not a section object
				; (it can be while process destruction because process still has many handles)
				; or access denied. Whatever value it can be try to workaround anyway.
					
				.if ebx == 0

					mov edi, 03F8h	; Try 03F8h handle.
						
				.elseif ebx == 1
					
					; Last chance.
			
					mov eax, peProcess
					add eax, 01ACh			; + SectionHandle field offset
					mov eax, [eax]			; [EPROCESS.SectionHandle]
					mov edi, eax

					; The handle value is multiple of 4.  And the section handle
					; must have some reasonable value. If not, better go away.

					and eax, (4 - 1)
					.break .if ( eax != 0 ) || ( edi >= 800h )
						
				.endif
				
				inc ebx						; Next workaround.
			.endw

			;invoke DbgPrint, $CTA0("ProcessMon: Reference section. status: %08X\n"), status

		.endif

		; If status != STATUS_SUCCESS we failed to get section object pointer
		; Very bad. No section no image file name :(

		.if status == STATUS_SUCCESS

			; OK. We have section pointer in pSection and it is referenced

			mov status, STATUS_UNSUCCESSFUL

			mov ebx, pSection
			mov ebx, (SECTION PTR [ebx])._Segment				; -> _SEGMENT

			invoke IsAddressInPoolRanges, ebx
			push eax
			invoke MmIsAddressValid, ebx
			pop ecx
			.if al && ( ecx == TRUE )

				mov esi, ebx									; save PTR _SEGMENT

				mov ebx, (_SEGMENT PTR [ebx]).ControlArea		; -> CONTROL_AREA

				invoke IsAddressInPoolRanges, ebx
				push eax
				invoke MmIsAddressValid, ebx
				pop ecx
				.if al && ( ecx == TRUE ) && ([CONTROL_AREA PTR [ebx]]._Segment == esi )	; check for shure

					mov ebx, (CONTROL_AREA PTR [ebx]).FilePointer	; -> FILE_OBJECT

					invoke IsLikeObjectPointer, ebx
					.if eax == TRUE

						; Check object type and reference it for sure

						mov ecx, IoFileObjectType
						mov ecx, [ecx]
						mov ecx, [ecx]			; PTR OBJECT_TYPE

						invoke ObReferenceObjectByPointer, ebx, FILE_READ_ATTRIBUTES, ecx, UserMode
						.if eax == STATUS_SUCCESS

							; Allocate memory for full image file path

							invoke ExAllocatePool, PagedPool, (IMAGE_FILE_PATH_LEN+1) * sizeof WCHAR
							.if eax != NULL

								mov edi, pusImageFilePath
								assume edi:ptr UNICODE_STRING

								mov [edi].Buffer, eax

								invoke memset, eax, 0, (IMAGE_FILE_PATH_LEN+1) * sizeof WCHAR	; Zero out

								; MaximumLength is one char less than allocated/zeroed
								; because I want to have zero char for shure

								mov [edi].MaximumLength,	IMAGE_FILE_PATH_LEN * sizeof WCHAR
								and [edi]._Length,			0

								; Get dos name for volume. DDK stands that drivers written for
								; Windows XP and later must use IoVolumeDeviceToDosName instead of
								; RtlVolumeDeviceToDosName. But on XP and later both functions
								; have the same entry point. So it's OK to call RtlVolumeDeviceToDosName
								; under any.

								invoke RtlVolumeDeviceToDosName, \
										(FILE_OBJECT PTR [ebx]).DeviceObject, addr usDosName
								.if eax == STATUS_SUCCESS

									; Copy drive letter

									invoke RtlCopyUnicodeString, edi, addr usDosName

									; Free memory allocated by DeviceToDosName

									invoke ExFreePool, usDosName.Buffer

								.else
									; If we fail to get drive letter we could query device name instead.
									; So instead of
									; "\WINNT\system32\notepad.exe"
									; we would get
									; "\Device\HarddiskVolume1\system32\notepad.exe"
									; But I do nothing to simplify the things
								.endif

								; Append relative file path

								; We could use ObQueryNameString to obtain file name.
								; I just get it directly from file object. It's much more faster.

								invoke RtlAppendUnicodeStringToString, edi, \
												addr (FILE_OBJECT PTR [ebx]).FileName

								;invoke DbgPrint, $CTA0("ProcessMon: %ws\n"), [edi].Buffer

								assume edi:nothing

								mov status, STATUS_SUCCESS

							.endif

							invoke ObDereferenceObject, ebx		; FILE_OBJECT
						.endif
					.endif
				.endif
			.endif

			invoke ObDereferenceObject, pSection
		.endif

		invoke ObDereferenceObject, peProcess
	.endif

	mov eax, status
	ret

GetImageFilePath endp

?? 快捷鍵說明

復制代碼 Ctrl + C
搜索代碼 Ctrl + F
全屏模式 F11
切換主題 Ctrl + Shift + D
顯示快捷鍵 ?
增大字號 Ctrl + =
減小字號 Ctrl + -
亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频
午夜亚洲国产au精品一区二区| 久久久综合九色合综国产精品| 欧美年轻男男videosbes| 在线观看免费亚洲| 欧美日韩一级大片网址| 日韩欧美一区二区视频| 亚洲一二三区在线观看| 欧美久久久影院| 日本一区二区三区高清不卡| 视频一区欧美日韩| 亚洲成av人片www| 亚洲成人精品在线观看| 日韩高清在线观看| 久久超碰97中文字幕| 美国毛片一区二区| 精品午夜久久福利影院| 国产在线精品免费av| 国产中文一区二区三区| 国产成人免费xxxxxxxx| 成人动漫中文字幕| 欧美一级电影网站| 一区二区三区日韩精品视频| 香蕉加勒比综合久久| 波多野结衣中文字幕一区 | 中文字幕一区不卡| 亚洲福利视频导航| 成人亚洲精品久久久久软件| 精品动漫一区二区三区在线观看| 久久99久久久欧美国产| 国内成人精品2018免费看| 欧美精品一区男女天堂| 国产成人精品综合在线观看| 欧美国产成人精品| 一本到一区二区三区| 丝袜亚洲另类欧美| 欧美三级电影一区| 日韩精品一级二级| 日韩一区二区在线观看视频播放| 图片区小说区区亚洲影院| 精品视频一区二区不卡| 亚洲成人一区二区在线观看| 在线区一区二视频| 日日骚欧美日韩| 欧美精品一区二区三区视频| 国模娜娜一区二区三区| 国产精品毛片久久久久久| 91.麻豆视频| 国产亚洲欧美一区在线观看| 国产99久久久国产精品潘金网站| 国产精品水嫩水嫩| 欧美亚日韩国产aⅴ精品中极品| 图片区日韩欧美亚洲| 久久婷婷色综合| 欧美一级片在线看| 91一区二区在线| 美腿丝袜亚洲一区| 一区二区在线观看视频| 欧美电视剧免费全集观看| 91啦中文在线观看| 国产高清视频一区| 日韩国产欧美在线观看| 亚洲欧美日韩国产综合在线| 日韩免费电影网站| 欧美日韩一区中文字幕| av亚洲精华国产精华精| 久88久久88久久久| 天堂久久一区二区三区| 亚洲精品国产视频| 中文字幕免费一区| 久久久久99精品一区| 制服.丝袜.亚洲.另类.中文| 国产精品妹子av| 欧美色窝79yyyycom| 国产剧情一区二区| 天天综合色天天| 亚洲国产日韩一区二区| 亚洲激情图片qvod| 亚洲一区二区高清| 亚洲一卡二卡三卡四卡无卡久久 | 中文字幕欧美一| 久久久久久日产精品| 日韩无一区二区| 精品人在线二区三区| wwwwww.欧美系列| 久久精品亚洲乱码伦伦中文| 中文字幕+乱码+中文字幕一区| 久久久一区二区| 中文字幕一区二区三区色视频| 国产精品激情偷乱一区二区∴| 亚洲日本丝袜连裤袜办公室| 亚洲在线观看免费| 久久激情综合网| 高清shemale亚洲人妖| 精品美女在线播放| 中文字幕乱码日本亚洲一区二区 | 亚洲男女一区二区三区| 久久综合九色综合97婷婷女人 | 欧美一级免费大片| 亚洲精品中文字幕在线观看| 丰满少妇久久久久久久| 欧美日韩mp4| 国产精品视频一二三| 精品伊人久久久久7777人| 色综合一区二区| 欧美一级片在线看| 午夜精品久久久久久久| 国产精品白丝av| 欧美精品自拍偷拍| 亚洲婷婷在线视频| 国产综合一区二区| 欧美伦理视频网站| 亚洲欧洲中文日韩久久av乱码| 精品系列免费在线观看| 久久久综合九色合综国产精品| 国产精品久久久久久久蜜臀 | 91国内精品野花午夜精品| 久久久久久久久97黄色工厂| 日日摸夜夜添夜夜添精品视频| 91一区二区三区在线播放| 久久午夜羞羞影院免费观看| 青青青伊人色综合久久| 在线免费观看日韩欧美| 中文字幕一区视频| 国产高清不卡一区| 中文字幕二三区不卡| av不卡在线播放| 中文字幕在线观看不卡| 99re这里只有精品6| 亚洲成a人v欧美综合天堂 | 在线中文字幕不卡| 日韩不卡一区二区三区| 欧美国产精品v| 在线观看欧美精品| 韩日精品视频一区| 欧美三级三级三级爽爽爽| 亚洲成人在线网站| 精品国产麻豆免费人成网站| 国产精品自在欧美一区| 日韩一区有码在线| 欧美日韩三级一区二区| 精品一区二区日韩| 亚洲人成电影网站色mp4| 欧美另类久久久品| 成人午夜激情影院| 午夜精品久久一牛影视| 欧美精品一区男女天堂| 99视频一区二区三区| 日韩av在线播放中文字幕| 国产色91在线| 欧美精品高清视频| 成人激情免费视频| 六月婷婷色综合| 亚洲午夜一二三区视频| 2020日本不卡一区二区视频| 91蜜桃传媒精品久久久一区二区| 久久99热99| 五月婷婷激情综合网| 亚洲人成在线播放网站岛国| 国产午夜亚洲精品羞羞网站| 337p亚洲精品色噜噜噜| 91麻豆国产精品久久| 国产白丝网站精品污在线入口| 午夜精品久久久久影视| 亚洲天堂成人网| 中文字幕第一区二区| 精品1区2区在线观看| 欧美不卡一区二区| 精品播放一区二区| 久久影音资源网| 久久精品人人做人人爽人人| 精品久久久久久久久久久久久久久 | 国产成人在线看| 成人激情av网| 91婷婷韩国欧美一区二区| eeuss鲁片一区二区三区在线观看| 国产精品香蕉一区二区三区| 国产精品一区在线观看你懂的| 国产精品影视天天线| 国产91在线观看丝袜| 色综合久久中文综合久久97| 欧美亚洲一区二区在线| 欧美精品丝袜久久久中文字幕| 欧美精选一区二区| 久久―日本道色综合久久| 精品久久久久久久久久久久包黑料 | 久久久久97国产精华液好用吗| 欧美成人精品1314www| 91.com在线观看| 国产网站一区二区| 国产精品欧美综合在线| 亚洲天堂精品在线观看| 亚洲va欧美va国产va天堂影院| 免费看欧美女人艹b| av一区二区不卡| 欧美xingq一区二区| 中文字幕在线不卡一区二区三区| 一区二区三区精密机械公司| 国产一区在线看| 欧美一级在线免费| 亚洲一二三区视频在线观看|