亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频

? 歡迎來到蟲蟲下載站! | ?? 資源下載 ?? 資源專輯 ?? 關于我們
? 蟲蟲下載站

?? mouspy.bat

?? KmdKit 匯編下開發驅動的工具 由俄羅斯某強男開發
?? BAT
?? 第 1 頁 / 共 3 頁
字號:
	.elseif [edi].Parameters.DeviceIoControl.IoControlCode == IOCTL_INVERT_MOVEMENT
		.if [edi].Parameters.DeviceIoControl.InputBufferLength == sizeof BOOL

			mov eax, [esi].AssociatedIrp.SystemBuffer
			mov eax, [eax]
			mov g_fInvertMovement, eax

			and [esi].IoStatus.Information, 0
			mov [esi].IoStatus.Status, STATUS_SUCCESS

		.else
			mov [esi].IoStatus.Status, STATUS_INFO_LENGTH_MISMATCH
		.endif


	.else
		mov [esi].IoStatus.Status, STATUS_INVALID_DEVICE_REQUEST
	.endif

	mov eax, [esi].IoStatus.Status
	mov status, eax

	assume esi:nothing
	assume edi:nothing

	fastcall IofCompleteRequest, esi, IO_NO_INCREMENT

	mov eax, status
	ret

CDO_DispatchDeviceControl endp

;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
;                                       DriverUnload                                                
;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

DriverUnload proc pDriverObject:PDRIVER_OBJECT

local MouseData:MOUSE_DATA

	invoke IoDeleteSymbolicLink, addr g_usSymbolicLinkName

	; Empty and destroy list

	.while TRUE

		invoke RemoveEntry, addr MouseData
		.break .if eax == 0

	.endw

	invoke ExDeleteNPagedLookasideList, g_pMouseDataLookaside
	invoke ExFreePool, g_pMouseDataLookaside

	mov eax, pDriverObject
	invoke IoDeleteDevice, (DRIVER_OBJECT PTR [eax]).DeviceObject

	ret

DriverUnload endp

;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
;                                      ReadComplete                                                 
;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

ReadComplete proc uses esi edi ebx pDeviceObject:PDEVICE_OBJECT, pIrp:PIRP, pContext:PVOID

local MouseData:MOUSE_DATA
local cEntriesLogged:DWORD

	; This routine is to be called when the IRP is completed.
	; It is running at IRQL <= DISPATCH_LEVEL and in an arbitrary thread context.

    mov esi, pIrp
    assume esi:ptr _IRP

	; Probably better to use NT_SUCCESS-like behaviour, but it works anyway

	.if [esi].IoStatus.Status == STATUS_SUCCESS
	
		; At least one MOUSE_INPUT_DATA structure was transferred.

		; The AssociatedIrp.SystemBuffer member points to the output buffer 
		; that is allocated by the Win32 subsystem to output the requested  
		; number of MOUSE_INPUT_DATA structures.
		
		mov edi, [esi].AssociatedIrp.SystemBuffer
		assume edi:ptr MOUSE_INPUT_DATA
		
        ; The Information member specifies the number of bytes       
        ; that are transferred to the Win32 subsystem output buffer. 
        
        mov ebx, [esi].IoStatus.Information

		and cEntriesLogged, 0
		.while sdword ptr ebx >= sizeof MOUSE_INPUT_DATA
			
			mov eax, [edi].LastX
			mov MouseData.LastX, eax

			mov eax, [edi].LastY
			mov MouseData.LastY, eax

			mov eax, [edi].Buttons
			mov MouseData.Buttons, eax

			invoke AddEntry, addr MouseData
				
			inc cEntriesLogged

			; Now lets have fun
			
			.if g_fInvertButtons

				.if [edi].ButtonFlags & MOUSE_LEFT_BUTTON_DOWN
					and [edi].ButtonFlags, not MOUSE_LEFT_BUTTON_DOWN
					or [edi].ButtonFlags, MOUSE_RIGHT_BUTTON_DOWN
				.elseif [edi].ButtonFlags & MOUSE_RIGHT_BUTTON_DOWN
					and [edi].ButtonFlags, not MOUSE_RIGHT_BUTTON_DOWN
					or [edi].ButtonFlags, MOUSE_LEFT_BUTTON_DOWN
				.endif

				.if [edi].ButtonFlags & MOUSE_LEFT_BUTTON_UP
					and [edi].ButtonFlags, not MOUSE_LEFT_BUTTON_UP
					or [edi].ButtonFlags, MOUSE_RIGHT_BUTTON_UP
				.elseif [edi].ButtonFlags & MOUSE_RIGHT_BUTTON_UP
					and [edi].ButtonFlags, not MOUSE_RIGHT_BUTTON_UP
					or [edi].ButtonFlags, MOUSE_LEFT_BUTTON_UP
				.endif
			
			.endif

			.if g_fInvertMovement

				movzx eax, [edi].Flags
				and eax, MOUSE_MOVE_RELATIVE
				.if eax == MOUSE_MOVE_RELATIVE

					; Only for relative movement

					.if [edi].LastX != 0
						xor eax, eax
						sub eax, [edi].LastX
						mov [edi].LastX, eax
					.endif

					.if [edi].LastY != 0
						xor eax, eax
						sub eax, [edi].LastY
						mov [edi].LastY, eax
					.endif

				.endif
			.endif

			add edi, sizeof MOUSE_INPUT_DATA
			sub ebx, sizeof MOUSE_INPUT_DATA
		.endw

		assume edi:nothing

		; Notify user-mode client.

		.if ( cEntriesLogged != 0 )

			LOCK_ACQUIRE g_EventSpinLock
			mov bl, al			; old IRQL

			.if ( g_pEventObject != NULL ) 	; EventObject may go away
				invoke KeSetEvent, g_pEventObject, 0, FALSE
			.endif
			
			LOCK_RELEASE g_EventSpinLock, bl
						
		.endif
	
	.endif

	; Any driver that returns STATUS_SUCCESS from IoCompletion routine should check the
	; IRP->PendingReturned flag in the IoCompletion routine.  If the flag is set,
	; the IoCompletion routine must call IoMarkIrpPending with the IRP.
	
	.if [esi].PendingReturned
		IoMarkIrpPending esi
	.endif

 	assume esi:nothing

	lock dec g_dwPendingRequests

	mov eax, STATUS_SUCCESS
	ret

ReadComplete endp

;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
;                                     FiDO_DispatchRead                                             
;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

FiDO_DispatchRead proc pDeviceObject:PDEVICE_OBJECT, pIrp:PIRP

	; The IRP_MJ_READ request transfers zero or more MOUSE_INPUT_DATA structures 
	; from Mouclass's internal data queue to the Win32 subsystem buffer.

	.if g_fSpy

		lock inc g_dwPendingRequests

		; We pass the same parameters to lower driver copying our stack location to the next-lower one.

		IoCopyCurrentIrpStackLocationToNext pIrp

		; To find out how the IRP will be completed we install completion routine.
		; It will be called when the next-lower-level driver has completed IRP.

		IoSetCompletionRoutine pIrp, ReadComplete, NULL, TRUE, TRUE, TRUE

	.else

		; No need to know what will happen with IRP. So just pass it down and forget.
		; Bacause we do not need to set completion routine use IoSkipCurrentIrpStackLocation
		; instead of IoCopyCurrentIrpStackLocationToNext. It's faster.

    	IoSkipCurrentIrpStackLocation pIrp

	.endif

	; It's time to send an IRP to next-lower-level driver.

	mov eax, pDeviceObject
	mov eax, (DEVICE_OBJECT ptr [eax]).DeviceExtension
	mov eax, (FiDO_DEVICE_EXTENSION ptr [eax]).pNextLowerDeviceObject

	invoke IoCallDriver, eax, pIrp

	; We must return exactly the same value IoCallDriver has returned.

	ret

FiDO_DispatchRead endp


;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
;                                     FiDO_DispatchPower                                            
;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

FiDO_DispatchPower proc pDeviceObject:PDEVICE_OBJECT, pIrp:PIRP

	invoke PoStartNextPowerIrp, pIrp

   	IoSkipCurrentIrpStackLocation pIrp
	
	mov eax, pDeviceObject
	mov eax, (DEVICE_OBJECT ptr [eax]).DeviceExtension
	mov eax, (FiDO_DEVICE_EXTENSION ptr [eax]).pNextLowerDeviceObject

	invoke PoCallDriver, eax, pIrp

	; We must return exactly the same value PoCallDriver has returned.

	ret

FiDO_DispatchPower endp

;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
;                                      DriverDispatch                                               
;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

DriverDispatch proc pDeviceObject:PDEVICE_OBJECT, pIrp:PIRP

local status:NTSTATUS
local dwMajorFunction:DWORD

	IoGetCurrentIrpStackLocation pIrp

	movzx eax, (IO_STACK_LOCATION PTR [eax]).MajorFunction
	mov dwMajorFunction, eax

	mov eax, pDeviceObject
	.if eax == g_pFilterDeviceObject

		mov eax, dwMajorFunction
		.if eax == IRP_MJ_READ
			invoke FiDO_DispatchRead, pDeviceObject, pIrp
			mov status, eax
		.elseif eax == IRP_MJ_POWER
			invoke FiDO_DispatchPower, pDeviceObject, pIrp
			mov status, eax
		.else
			invoke FiDO_DispatchPassThrough, pDeviceObject, pIrp
			mov status, eax
		.endif

	.elseif eax == g_pControlDeviceObject

		; Request is to our CDO. Let' see what our client want us do
	
		mov eax, dwMajorFunction
		.if eax == IRP_MJ_CREATE
			invoke CDO_DispatchCreate, pDeviceObject, pIrp
			mov status, eax
		.elseif eax == IRP_MJ_CLOSE
			invoke CDO_DispatchClose, pDeviceObject, pIrp
			mov status, eax
		.elseif eax == IRP_MJ_DEVICE_CONTROL
			invoke CDO_DispatchDeviceControl, pDeviceObject, pIrp
			mov status, eax
		.else

			mov ecx, pIrp
			mov (_IRP PTR [ecx]).IoStatus.Status, STATUS_INVALID_DEVICE_REQUEST
			and (_IRP PTR [ecx]).IoStatus.Information, 0

			fastcall IofCompleteRequest, ecx, IO_NO_INCREMENT

			mov status, STATUS_INVALID_DEVICE_REQUEST
	
		.endif
	
	.else

		; Strange, we have recieved IRP for the device we do not know about.
		; This should never happen. Just complete IRP as invalid.

		mov ecx, pIrp
		mov (_IRP PTR [ecx]).IoStatus.Status, STATUS_INVALID_DEVICE_REQUEST
		and (_IRP PTR [ecx]).IoStatus.Information, 0

		fastcall IofCompleteRequest, ecx, IO_NO_INCREMENT

		mov status, STATUS_INVALID_DEVICE_REQUEST

	.endif

	mov eax, status
	ret

DriverDispatch endp

;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
;                              D I S C A R D A B L E   C O D E                                      
;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

.code INIT

;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
;                                       DriverEntry                                                 
;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

DriverEntry proc pDriverObject:PDRIVER_OBJECT, pusRegistryPath:PUNICODE_STRING

local status:NTSTATUS

	mov status, STATUS_DEVICE_CONFIGURATION_ERROR

	; Create a Control Device Object (CDO). The purpose of the CDO is to allow
	; our user-mode client to communicate with us, even before the filter is attached
	; to its target
	;
	; We store the CDO pointer into g_pControlDeviceObject, a globally defined variable.
	; This way we can identify the control device object in dispatch routines by comparing
	; the passed in device pointer against our CDO pointer
	;
	; CDO is exclusive one. It ensures that only one process opens the device at a time.
	; DDK stands it is reserved for system use and drivers set this parameter to FALSE.
	; Anyway we set it to TRUE and to force single-client logic mantain global variable
	; g_fCDOOpened which we will set/reset in CDO_DispatchCreate/CDO_DispatchClose

	invoke IoCreateDevice, pDriverObject, 0, addr g_usControlDeviceName, \
							FILE_DEVICE_UNKNOWN, 0, TRUE, addr g_pControlDeviceObject
	.if eax == STATUS_SUCCESS

		;mov eax, g_pControlDeviceObject
		;mov eax, (DEVICE_OBJECT ptr [eax]).DeviceExtension
		;and (CDO_DEVICE_EXTENSION ptr [eax]).fOpened, 0

		invoke IoCreateSymbolicLink, addr g_usSymbolicLinkName, addr g_usControlDeviceName
		.if eax == STATUS_SUCCESS

			; Allocate memory for lookaside list

			invoke ExAllocatePool, NonPagedPool, sizeof NPAGED_LOOKASIDE_LIST
			.if eax != NULL

				mov g_pMouseDataLookaside, eax

				invoke ExInitializeNPagedLookasideList, g_pMouseDataLookaside, \
										NULL, NULL, 0, sizeof MOUSE_DATA_ENTRY, 'ypSM', 0

				; Use doubly linked list to track memory blocks
				; we will allocate/free from/to lookaside list

				InitializeListHead addr g_MouseDataListHead

				and g_cMouseDataEntries, 0

				; Init spin lock guarding common driver routines
				
				invoke KeInitializeSpinLock, addr g_MouseDataSpinLock

				; Init spin lock guarding event pointer
				
				invoke KeInitializeSpinLock, addr g_EventSpinLock

				; Init CDO state mutex
				
				MUTEX_INIT g_mtxCDO_State
			
				; I know they all are zero by default, but...

				and g_fCDO_Opened, FALSE
				and g_fFiDO_Attached, FALSE
				and g_pFilterDeviceObject, NULL
				and g_fSpy, FALSE
				and g_dwPendingRequests, 0
				and g_fInvertButtons, FALSE
				and g_fInvertMovement, FALSE

				mov eax, pDriverObject
				assume eax:ptr DRIVER_OBJECT

				mov ecx, IRP_MJ_MAXIMUM_FUNCTION + 1
				.while ecx
					dec ecx
					mov [eax].MajorFunction[ecx*(sizeof PVOID)], offset DriverDispatch
				.endw

				mov [eax].DriverUnload,	offset DriverUnload
				assume eax:nothing

				mov eax, pDriverObject
				mov g_pDriverObject, eax

				mov status, STATUS_SUCCESS

			.else	; ExAllocatePool failed
				invoke IoDeleteSymbolicLink, addr g_usSymbolicLinkName
				invoke IoDeleteDevice, g_pControlDeviceObject
			.endif

		.else		; IoCreateSymbolicLink failed
			invoke IoDeleteDevice, g_pControlDeviceObject
		.endif

	.endif

	mov eax, status
	ret

DriverEntry endp

;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
;                                                                                                   
;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

end DriverEntry

:make

set drv=MouSpy

if exist ..\%drv%.sys del ..\%drv%.sys

\masm32\bin\ml /nologo /c /coff %drv%.bat
\masm32\bin\link /nologo /driver /base:0x10000 /align:32 /out:%drv%.sys /subsystem:native /ignore:4078 %drv%.obj

del %drv%.obj
move %drv%.sys ..

echo.
pause

?? 快捷鍵說明

復制代碼 Ctrl + C
搜索代碼 Ctrl + F
全屏模式 F11
切換主題 Ctrl + Shift + D
顯示快捷鍵 ?
增大字號 Ctrl + =
減小字號 Ctrl + -
亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频
亚洲最新视频在线播放| 一区二区三区高清| 国产毛片一区二区| 欧美精品一区二区不卡| 国内精品伊人久久久久影院对白| 精品久久人人做人人爰| 国产麻豆精品theporn| 亚洲国产成人私人影院tom| 91老师片黄在线观看| 一区二区三区欧美日韩| 欧美日韩视频专区在线播放| 秋霞成人午夜伦在线观看| 久久久天堂av| 色香色香欲天天天影视综合网| 一个色妞综合视频在线观看| 欧美丰满嫩嫩电影| 国产成人aaa| 亚洲超丰满肉感bbw| 精品免费国产一区二区三区四区| 成人福利视频网站| 亚洲电影欧美电影有声小说| 久久免费精品国产久精品久久久久| 国产mv日韩mv欧美| 午夜免费欧美电影| 久久久国际精品| 欧美日韩国产乱码电影| 国产不卡高清在线观看视频| 亚洲国产精品一区二区尤物区| 精品国产污网站| 91久久一区二区| 国产乱人伦偷精品视频免下载| 亚洲宅男天堂在线观看无病毒| 日韩精品最新网址| 色狠狠综合天天综合综合| 国内久久精品视频| 首页国产丝袜综合| 国产精品免费网站在线观看| 欧美精品视频www在线观看| 99在线视频精品| 久久成人免费网| 亚洲一区二区视频在线观看| 久久九九99视频| 91麻豆精品国产91久久久| 99热精品国产| 国产一区二区三区四区五区入口| 首页国产丝袜综合| 亚洲卡通动漫在线| 日本一区二区三区四区 | 日本人妖一区二区| 中文字幕中文字幕在线一区| 久久久久国产免费免费| 欧美一区二区视频在线观看| 欧美性一区二区| a级高清视频欧美日韩| 国产一区二区电影| 毛片av一区二区| 日韩不卡手机在线v区| 亚洲综合一区二区三区| 亚洲人成精品久久久久| 欧美激情综合五月色丁香| 精品国产一区二区国模嫣然| 欧美一级在线观看| 777xxx欧美| 欧美乱妇15p| 56国语精品自产拍在线观看| 欧美亚洲国产怡红院影院| 99久久精品99国产精品| 成人丝袜高跟foot| 成人一区二区三区在线观看| 国产成人在线看| 高清成人免费视频| 国产激情一区二区三区| 精品无人区卡一卡二卡三乱码免费卡| 奇米一区二区三区| 裸体一区二区三区| 国产尤物一区二区| 国产剧情一区在线| 国产 欧美在线| 不卡视频在线观看| 91蜜桃视频在线| 91黄视频在线| 91精品婷婷国产综合久久| 欧美一区二区三区色| 日韩精品一区二区三区四区视频| 欧美变态tickle挠乳网站| 精品国产sm最大网站免费看| 久久久久久免费网| 国产精品久久久久永久免费观看| 亚洲男人都懂的| 亚洲va欧美va人人爽午夜| 蜜臀久久99精品久久久画质超高清| 美女免费视频一区| 国产成人在线色| 91九色02白丝porn| 3d动漫精品啪啪| 国产亚洲综合色| 亚洲欧美另类久久久精品2019| 亚洲一区二区影院| 久久国产精品露脸对白| 国产91丝袜在线播放九色| 99精品国产一区二区三区不卡| 欧美性大战久久久| 91精品国模一区二区三区| 日韩欧美二区三区| 国产日韩欧美电影| 亚洲成人免费影院| 另类小说综合欧美亚洲| 丁香桃色午夜亚洲一区二区三区| 色婷婷综合久久久久中文一区二区| 欧美色图一区二区三区| 欧美精品一区视频| 亚洲激情综合网| 国产在线精品一区二区不卡了| 91原创在线视频| 久久综合色鬼综合色| 亚洲欧美成aⅴ人在线观看| 日本欧洲一区二区| 99久久精品国产导航| 日韩视频一区二区三区在线播放| 国产精品久久毛片| 日韩av电影天堂| 色综合婷婷久久| 久久日韩粉嫩一区二区三区| 一区二区三区四区激情| 激情都市一区二区| 一本色道久久综合狠狠躁的推荐| 欧美mv日韩mv国产网站| 亚洲日本va午夜在线影院| 久久国产尿小便嘘嘘尿| 99re这里都是精品| 久久久99久久| 日本成人在线看| 91视频xxxx| 国产亚洲福利社区一区| 日韩福利电影在线观看| 色噜噜久久综合| 国产精品三级电影| 国产一区91精品张津瑜| 欧美一二三四区在线| 一区二区在线观看免费视频播放| 黄一区二区三区| 欧美一区二区成人| 亚洲午夜国产一区99re久久| 99精品热视频| 中文字幕欧美激情一区| 国产一区二区三区美女| 日韩欧美电影一二三| 亚洲国产另类av| 欧美亚洲一区三区| 自拍偷拍亚洲欧美日韩| 国产91露脸合集magnet| 久久久久97国产精华液好用吗| 免费成人结看片| 91麻豆精品国产91久久久资源速度 | 国产欧美精品日韩区二区麻豆天美| 人人精品人人爱| 666欧美在线视频| 午夜精品福利久久久| 欧美日韩中字一区| 亚洲va天堂va国产va久| 欧美另类变人与禽xxxxx| 丝袜脚交一区二区| 欧美一区二区在线播放| 免费看黄色91| 欧美精品一区二区三| 国产麻豆精品95视频| 国产欧美日韩三区| 成人小视频免费在线观看| 中文字幕一区二区5566日韩| 99国产精品久久久久久久久久| 中文字幕亚洲视频| 在线观看日韩国产| 亚洲图片欧美色图| 88在线观看91蜜桃国自产| 日本午夜精品一区二区三区电影| 欧美一区二区三区人| 久久精品国产精品青草| xnxx国产精品| 成人动漫视频在线| 一区二区三区日本| 日韩一区二区三区四区 | 国产精品看片你懂得| 午夜精品成人在线视频| 91精品国产91久久久久久一区二区| 26uuuu精品一区二区| 国产精品亚洲人在线观看| 中文乱码免费一区二区| 91猫先生在线| 欧美精品一区二| 亚洲天堂av老司机| 欧美精品高清视频| 成人av免费在线观看| 六月婷婷色综合| 一级做a爱片久久| 国产精品视频一二三区| 精品国产三级a在线观看| 欧美久久一二三四区| 97se亚洲国产综合自在线观| 国产综合色在线视频区| 日本伊人色综合网|