亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频

? 歡迎來(lái)到蟲(chóng)蟲(chóng)下載站! | ?? 資源下載 ?? 資源專輯 ?? 關(guān)于我們
? 蟲(chóng)蟲(chóng)下載站

?? processmon.bat

?? KmdKit 匯編下開(kāi)發(fā)驅(qū)動(dòng)的工具 由俄羅斯某強(qiáng)男開(kāi)發(fā)
?? BAT
字號(hào):
;@echo off
;goto make

;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
;
;  Process Monitor control programm.
;
;  Written by Four-F (four-f@mail.ru)
;
;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

.386
.model flat, stdcall
option casemap:none

;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
;                                  I N C L U D E   F I L E S                                        
;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

include \masm32\include\windows.inc

include \masm32\include\kernel32.inc
include \masm32\include\user32.inc
include \masm32\include\advapi32.inc
include \masm32\include\comctl32.inc

includelib \masm32\lib\kernel32.lib
includelib \masm32\lib\user32.lib
includelib \masm32\lib\advapi32.lib
includelib \masm32\lib\comctl32.lib

include \masm32\include\winioctl.inc

include cocomac\cocomac.mac
include cocomac\ListView.mac
include \masm32\Macros\Strings.mac

include ..\common.inc

;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
;                                      E Q U A T E S                                                
;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

IDD_MAIN		equ	1000
IDC_LISTVIEW	equ 1001
IDI_ICON		equ 1002

;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
;                              U N I N I T I A L I Z E D  D A T A                                   
;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

.data?

g_hInstance		HINSTANCE	?
g_hwndDlg		HWND		?
g_hwndListView	HWND		?

g_hSCManager	HANDLE		?
g_hService		HANDLE		?
g_hEvent		HANDLE		?

g_hDevice		HANDLE		?

g_fbExitNow		BOOL		?

;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
;                                        C O D E                                                    
;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

.code

;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
;                             MyUnhandledExceptionFilter                                            
;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

MyUnhandledExceptionFilter proc lpExceptionInfo:PTR EXCEPTION_POINTERS

; Just cleanup every possible thing.

local dwBytesReturned:DWORD
local _ss:SERVICE_STATUS

	; If something went wrong let the driver know it should undo the things.

	invoke DeviceIoControl, g_hDevice, IOCTL_REMOVE_NOTIFY, \
					NULL, 0, NULL, 0, addr dwBytesReturned, NULL

	mov g_fbExitNow, TRUE		; If exception has occured not in loop thread it should exit now.
	invoke SetEvent, g_hEvent
					
	invoke Sleep, 100

	invoke CloseHandle, g_hEvent
	invoke CloseHandle, g_hDevice

	invoke ControlService, g_hService, SERVICE_CONTROL_STOP, addr _ss

	invoke DeleteService, g_hService

	invoke CloseServiceHandle, g_hService
	invoke CloseServiceHandle, g_hSCManager

	mov eax, EXCEPTION_EXECUTE_HANDLER
	ret

MyUnhandledExceptionFilter endp

;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
;                                     ListViewInsertColumn                                          
;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

ListViewInsertColumn proc

local lvc:LV_COLUMN

	mov lvc.imask, LVCF_TEXT + LVCF_WIDTH 
	mov lvc.pszText, $CTA0("Process")
	mov lvc.lx, 354
	ListView_InsertColumn g_hwndListView, 0, addr lvc

	mov lvc.pszText, $CTA0("PID")
	or lvc.imask, LVCF_FMT
	mov lvc.fmt, LVCFMT_RIGHT
	mov lvc.lx, 40
	ListView_InsertColumn g_hwndListView, 1, addr lvc

	mov lvc.fmt, LVCFMT_LEFT
	mov lvc.lx, 80
	mov lvc.pszText, $CTA0("State")
	ListView_InsertColumn g_hwndListView, 2, addr lvc

	ret

ListViewInsertColumn endp

;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
;                                        FillProcessInfo                                            
;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

FillProcessInfo proc uses esi pProcessData:PTR PROCESS_DATA

local lvi:LV_ITEM
local buffer[1024]:CHAR

	mov esi, pProcessData
	assume esi:ptr PROCESS_DATA

	mov lvi.imask, LVIF_TEXT

	ListView_GetItemCount g_hwndListView
	mov lvi.iItem, eax

	; The path can be it the short form. Convert it to long.
	; If no long path is found or path is in long form, GetLongPathName
	; simply returns the specified path.

	invoke GetLongPathName, addr [esi].szProcessName, addr buffer, sizeof buffer
	.if ( eax == 0 ) || ( eax >= sizeof buffer )

		; 1024 bytes was not enough. Just display whatever we've got from the driver.
		; I want to keep the things simple. But you'd better to allocate more memory
		; and call GetLongPathName again and again until the buffer size will
		; satisfy the need.
		
		lea ecx, [esi].szProcessName

	.else

		lea ecx, buffer

	.endif

	and lvi.iSubItem, 0
	mov lvi.pszText, ecx
	ListView_InsertItem g_hwndListView, addr lvi

	inc lvi.iSubItem
	invoke wsprintf, addr buffer, $CTA0("%X"), [esi].dwProcessId
	lea eax, buffer
	mov lvi.pszText, eax
	ListView_SetItem g_hwndListView, addr lvi

	inc lvi.iSubItem
	.if [esi].bCreate
		mov lvi.pszText, $CTA0("Created")
	.else
		mov lvi.pszText, $CTA0("Destroyed")
	.endif
	ListView_SetItem g_hwndListView, addr lvi

	assume esi:nothing

	; Scroll down if needed
	ListView_GetItemCount g_hwndListView
	dec eax				; Make index zero-based
	ListView_EnsureVisible g_hwndListView, eax, FALSE

	ret

FillProcessInfo endp

;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
;                                     WaitForProcessData                                            
;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

WaitForProcessData proc hEvent:HANDLE

local ProcessData:PROCESS_DATA
local dwBytesReturned:DWORD

	invoke GetCurrentThread
	invoke SetThreadPriority, eax, THREAD_PRIORITY_HIGHEST	

	.while TRUE
		invoke WaitForSingleObject, hEvent, INFINITE
		.if eax != WAIT_FAILED

			.break .if g_fbExitNow == TRUE

			invoke DeviceIoControl, g_hDevice, IOCTL_GET_PROCESS_DATA, NULL, 0, \
						addr ProcessData, sizeof ProcessData, addr dwBytesReturned, NULL

			.if eax != 0
				invoke FillProcessInfo, addr ProcessData
			.endif

		.else
			invoke MessageBox, g_hwndDlg, \
				$CTA0("Wait for event failed. Thread now exits. Restart application."), \
				NULL, MB_ICONERROR
			.break
		.endif
	.endw

	invoke ExitThread, 0
	ret							; Never executed.

WaitForProcessData endp
	
;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
;                               D I A L O G     P R O C E D U R E                                   
;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

DlgProc proc hDlg:HWND, uMsg:UINT, wParam:WPARAM, lParam:LPARAM

local rect:RECT

	mov eax, uMsg
	.if eax == WM_INITDIALOG

		push hDlg
		pop g_hwndDlg

		invoke LoadIcon, g_hInstance, IDI_ICON
		invoke SendMessage, hDlg, WM_SETICON, ICON_BIG, eax

		invoke GetDlgItem, hDlg, IDC_LISTVIEW
		mov g_hwndListView, eax
		invoke SetFocus, g_hwndListView

		invoke GetClientRect, hDlg, addr rect
		invoke MoveWindow, g_hwndListView, rect.left, rect.top, rect.right, rect.bottom, FALSE

		ListView_SetExtendedListViewStyle g_hwndListView, LVS_EX_GRIDLINES + LVS_EX_FULLROWSELECT

		invoke ListViewInsertColumn

	.elseif eax == WM_SIZE

		mov eax, lParam
		mov ecx, eax
		and eax, 0FFFFh
		shr ecx, 16
		invoke MoveWindow, g_hwndListView, 0, 0, eax, ecx, TRUE

	.elseif eax == WM_COMMAND

		mov eax, wParam
		and eax, 0FFFFh
		.if eax == IDCANCEL
			invoke MessageBox, hDlg, $CTA0("Sure want to exit?"), \
					$CTA0("Exit Confirmation"), MB_YESNO + MB_ICONQUESTION + MB_DEFBUTTON1
			.if eax == IDYES
				invoke EndDialog, hDlg, 0
			.endif
		.endif

	.elseif uMsg == WM_GETMINMAXINFO

		mov ecx, lParam
		mov (MINMAXINFO PTR [ecx]).ptMinTrackSize.x, 380
		mov (MINMAXINFO PTR [ecx]).ptMinTrackSize.y, 150

	.else

		xor eax, eax
		ret
	
	.endif

	xor eax, eax
	inc eax
	ret
    
DlgProc endp

;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
;                                         start                                                     
;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

start proc

local acModulePath[MAX_PATH]:CHAR
local _ss:SERVICE_STATUS
local dwBytesReturned:DWORD

	CTA  "This program was tested on Windows 2000+sp2/sp3/sp4,\n", szExecutionConfirmation
	CTA  "Windows XP no sp, Windows Server 2003 Std and\n"
	CTA  "seems to be workable. But it uses undocumented\n"
	CTA  "tricks in kernel mode and may crash your system\:\n"
	CTA  "\n"
	CTA0 "Are your shure you want to run it?\n"

	invoke MessageBox, NULL, addr szExecutionConfirmation, \
		$CTA0("Execution Confirmation"), MB_YESNO + MB_ICONQUESTION + MB_DEFBUTTON2
	.if eax == IDNO
		invoke ExitProcess, 0
	.endif

	; The very first thing we have to do is to install exception handler
	
	invoke SetUnhandledExceptionFilter, MyUnhandledExceptionFilter

	invoke OpenSCManager, NULL, NULL, SC_MANAGER_ALL_ACCESS
	.if eax != NULL
		mov g_hSCManager, eax

		push eax
		invoke GetFullPathName, $CTA0("ProcessMon.sys"), sizeof acModulePath, addr acModulePath, esp
    	pop eax

		invoke CreateService, g_hSCManager, $CTA0("ProcessMon"), \
			$CTA0("Process creation/destruction monitor"), \
			SERVICE_START + SERVICE_STOP + DELETE, SERVICE_KERNEL_DRIVER, SERVICE_DEMAND_START, \
			SERVICE_ERROR_IGNORE, addr acModulePath, NULL, NULL, NULL, NULL, NULL

		.if eax != NULL
			mov g_hService, eax

			invoke StartService, g_hService, 0, NULL
			.if eax != 0

				invoke CreateFile, $CTA0("\\\\.\\ProcessMon"), \
						GENERIC_READ + GENERIC_WRITE, 0, NULL, OPEN_EXISTING, 0, NULL

				.if eax != INVALID_HANDLE_VALUE
					mov g_hDevice, eax

					; No need it to be registered anymore

					invoke DeleteService, g_hService
			
					; Create unnamed auto-reset event to be signalled when there is data to read.

					invoke CreateEvent, NULL, FALSE, FALSE, NULL
					mov g_hEvent, eax

					and g_fbExitNow, FALSE

					; Create thread to wait event signalled.

					push eax								; place for dwThreadID
					invoke CreateThread, NULL, 0, offset WaitForProcessData, g_hEvent, 0, esp
					pop ecx									; throw dwThreadID away
					.if eax != NULL
					
						invoke CloseHandle, eax								

						;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

						invoke DeviceIoControl, g_hDevice, IOCTL_SET_NOTIFY, \
								addr g_hEvent, sizeof g_hEvent, NULL, 0, addr dwBytesReturned, NULL

						.if eax != 0

							invoke GetModuleHandle, NULL
							mov g_hInstance, eax
							invoke DialogBoxParam, g_hInstance, IDD_MAIN, NULL, addr DlgProc, 0

							invoke DeviceIoControl, g_hDevice, IOCTL_REMOVE_NOTIFY, \
										NULL, 0, NULL, 0, addr dwBytesReturned, NULL
						.else
							invoke MessageBox, NULL, \
									$CTA0("Can't set notify."), NULL, MB_ICONSTOP
						.endif

						;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

						mov g_fbExitNow, TRUE
						invoke SetEvent, g_hEvent		; Signal event to make loop thread exit.
					
						invoke Sleep, 100
					
					.else
						invoke MessageBox, NULL, $CTA0("Can't create thread."), NULL, MB_ICONSTOP						
					.endif

					invoke CloseHandle, g_hEvent
					invoke CloseHandle, g_hDevice
				.else
					invoke MessageBox, NULL, $CTA0("Can't open device."), NULL, MB_ICONSTOP
				.endif
				invoke ControlService, g_hService, SERVICE_CONTROL_STOP, addr _ss
			.else
				invoke MessageBox, NULL, $CTA0("Can't start driver."), NULL, MB_ICONSTOP
			.endif

			invoke DeleteService, g_hService
			invoke CloseServiceHandle, g_hService

		.else
			invoke MessageBox, NULL, $CTA0("Can't register driver."), NULL, MB_ICONSTOP
		.endif
		invoke CloseServiceHandle, g_hSCManager
	.else
		invoke MessageBox, NULL, \
			$CTA0("Can't connect to SCM."), NULL, MB_ICONSTOP
	.endif

	invoke ExitProcess, 0
	invoke InitCommonControls
	ret

start endp

;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
;                                                                                                   
;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

end start

:make

set exe=ProcessMon

:makerc
if exist rsrc.obj goto final
	\masm32\bin\rc /v rsrc.rc
	\masm32\bin\cvtres /machine:ix86 rsrc.res
	if errorlevel 0 goto final
		echo.
		pause
		exit

:final

if exist rsrc.res del rsrc.res
if exist ..\%exe%.exe del ..\%exe%.exe

\masm32\bin\ml /nologo /c /coff %exe%.bat
\masm32\bin\link /nologo /subsystem:windows %exe%.obj rsrc.obj

del %exe%.obj
move %exe%.exe ..
if exist %exe%.exe del %exe%.exe

echo.
pause

?? 快捷鍵說(shuō)明

復(fù)制代碼 Ctrl + C
搜索代碼 Ctrl + F
全屏模式 F11
切換主題 Ctrl + Shift + D
顯示快捷鍵 ?
增大字號(hào) Ctrl + =
減小字號(hào) Ctrl + -
亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频
亚洲视频综合在线| 成人av在线观| 91视频免费看| 久久久久久久久久久久电影| 午夜欧美大尺度福利影院在线看 | 精品国产污网站| 一区二区三区四区高清精品免费观看| 黄色资源网久久资源365| 欧美三级一区二区| 亚洲视频资源在线| 成人午夜激情视频| 久久一区二区三区国产精品| 日韩专区一卡二卡| 在线视频亚洲一区| 亚洲欧洲美洲综合色网| 国产精品自拍三区| 精品久久久久久久久久久久久久久久久 | 国内精品久久久久影院薰衣草| 欧美三级视频在线观看| 亚洲欧美激情小说另类| 粉嫩嫩av羞羞动漫久久久| 日韩亚洲欧美高清| 日本人妖一区二区| 欧美日韩亚洲综合一区 | 日韩三级在线观看| 亚洲欧洲av一区二区三区久久| 国产专区综合网| 亚洲精品综合在线| 91精品国产欧美一区二区| 亚洲精品自拍动漫在线| 99精品视频在线观看| 亚洲人成小说网站色在线 | 韩国精品久久久| 精品夜夜嗨av一区二区三区| 国产成人av电影在线观看| 国产精品国产三级国产有无不卡| 国产精品亚洲午夜一区二区三区 | 欧美日韩另类国产亚洲欧美一级| 日韩1区2区3区| 亚洲国产一区视频| 美女任你摸久久| 久久久国产精品麻豆| 91精品啪在线观看国产60岁| 色婷婷综合久久久中文一区二区 | 韩国女主播一区| 亚洲视频一区在线| 亚洲成在线观看| 日韩电影在线一区二区三区| 韩国女主播成人在线| 日本精品视频一区二区三区| 中文字幕精品在线不卡| 亚洲一区二区视频在线观看| 国产精品伊人色| 欧美三级日韩在线| 欧美日韩国产小视频在线观看| 精品美女一区二区| 五月婷婷欧美视频| 26uuu亚洲综合色| 91亚洲男人天堂| 奇米888四色在线精品| 国产精品视频观看| 欧美群妇大交群的观看方式| 久久精品国产澳门| 国产成人啪免费观看软件| 成人亚洲精品久久久久软件| 国产综合久久久久久久久久久久| 国产一区二区调教| 国产v综合v亚洲欧| 波波电影院一区二区三区| 国产经典欧美精品| 成人免费视频视频在线观看免费| 国产在线精品免费av| 国产精品18久久久久久久久| 色综合久久久久综合99| 久久久不卡影院| 欧美亚洲国产一卡| 国产自产v一区二区三区c| 一区二区成人在线| 久久精品亚洲乱码伦伦中文| 国产嫩草影院久久久久| 在线这里只有精品| 国产精品69毛片高清亚洲| 天堂久久一区二区三区| 中文字幕巨乱亚洲| 日韩三级高清在线| 日本韩国精品一区二区在线观看| 激情文学综合插| 亚洲一区二区成人在线观看| 亚洲国产成人一区二区三区| 欧美一二三区精品| 欧美在线你懂的| 成人激情动漫在线观看| 美美哒免费高清在线观看视频一区二区 | 亚洲在线中文字幕| 日本一区二区在线不卡| 欧美一级高清大全免费观看| 色婷婷国产精品| 国产成人亚洲综合a∨猫咪| 亚洲大片一区二区三区| 中文字幕日韩av资源站| 精品福利一二区| 7777精品伊人久久久大香线蕉完整版 | 亚洲欧美视频在线观看| 粉嫩av一区二区三区| 欧美男女性生活在线直播观看 | 91丝袜美女网| 精品久久99ma| 亚洲午夜精品一区二区三区他趣| 国产一区二区三区视频在线播放| 欧美日韩亚洲综合一区| 中文字幕在线一区免费| 国内精品在线播放| 欧美日韩国产首页在线观看| 国产精品电影一区二区| 欧美日精品一区视频| 天天色 色综合| 亚洲综合在线第一页| 亚洲欧美激情一区二区| 亚洲欧洲日韩av| 中文字幕永久在线不卡| 中文字幕av资源一区| 久久欧美一区二区| 日韩精品中文字幕在线不卡尤物| 欧美人牲a欧美精品| 欧美日韩视频专区在线播放| 欧美亚洲综合一区| 欧美亚洲国产bt| 欧美性大战xxxxx久久久| 在线观看视频一区二区| 在线免费观看日韩欧美| 在线免费观看不卡av| 在线观看成人小视频| 色又黄又爽网站www久久| 91啪在线观看| 91精品办公室少妇高潮对白| 日本丶国产丶欧美色综合| 91麻豆精品一区二区三区| 91麻豆国产自产在线观看| 91视频xxxx| 欧美亚洲日本一区| 欧美久久免费观看| 日韩欧美一卡二卡| 久久综合av免费| 亚洲国产成人一区二区三区| 亚洲欧洲国产日韩| 亚洲欧美另类久久久精品2019| 亚洲最色的网站| 五月婷婷另类国产| 99久久伊人精品| 91国偷自产一区二区使用方法| 欧美亚洲国产一区在线观看网站| 在线观看91av| 欧美变态tickle挠乳网站| 久久亚洲免费视频| 国产精品久久一卡二卡| 一区二区三区四区视频精品免费 | 免费精品99久久国产综合精品| 中文字幕一区二区三区四区不卡| 欧美日韩免费视频| 韩国女主播一区二区三区| 中文字幕一区二区三| 在线播放91灌醉迷j高跟美女| 国产高清亚洲一区| 午夜av区久久| 亚洲你懂的在线视频| 精品国产免费视频| 99精品在线免费| 91在线国产福利| 欧美三区在线观看| 色乱码一区二区三区88| 欧美色图天堂网| 欧美成人性福生活免费看| 久久久99精品免费观看| 一区二区三区在线视频观看58| 日韩在线一区二区| 国产成人免费xxxxxxxx| 色哟哟一区二区| 欧美一级片在线观看| 中日韩av电影| 日韩国产在线一| 国产精品99久久久久久久vr | 日韩精品欧美成人高清一区二区| 极品美女销魂一区二区三区| www.欧美日韩国产在线| 91精品欧美一区二区三区综合在| 久久久久久久综合狠狠综合| 亚洲精品免费在线播放| 麻豆精品在线观看| 91免费版在线| 欧美mv日韩mv| 亚洲精品写真福利| 激情亚洲综合在线| 日本精品视频一区二区| 26uuu亚洲综合色| 亚洲r级在线视频| 国产91精品免费| 91精品免费观看| 亚洲日本一区二区三区| 久国产精品韩国三级视频| 91黄色免费观看|