?? main.cpp
字號:
#include "main.h"
#include "DPCTest.h"
///////////////////////////////////////////////////////////////////////////////////////////////
UNICODE_STRING DeviceName;
UNICODE_STRING SymbolicLinkName;
PDEVICE_OBJECT deviceObject = NULL;
///////////////////////////////////////////////////////////////////////////////////////////////
NTSTATUS DriverEntry(IN PDRIVER_OBJECT DriverObject,
IN PUNICODE_STRING RegistryPath)
{
PDRIVER_DISPATCH *mj_func;
NTSTATUS st;
PCWSTR dDeviceName = L"\\Device\\TestDriver";
PCWSTR dSymbolicLinkName = L"\\DosDevices\\TestDriver";
libcpp_init();
DbgPrint("\t------START------\n");
RtlInitUnicodeString(&DeviceName, dDeviceName);
RtlInitUnicodeString(&SymbolicLinkName, dSymbolicLinkName);
st = IoCreateDevice(DriverObject, // pointer on DriverObject
0, // additional size of memory, for dev. extension
&DeviceName, // pointer to UNICODE_STRING
FILE_DEVICE_NULL,// Device type
0, // Device characteristic
FALSE, // "Exclusive" device
&deviceObject); // pointer do device object
if (st == STATUS_SUCCESS)
st = IoCreateSymbolicLink(&SymbolicLinkName,
&DeviceName);
mj_func = DriverObject->MajorFunction;
DriverObject->DriverUnload = DriverUnload;
mj_func[IRP_MJ_DEVICE_CONTROL] = DeviceControlRoutine;
mj_func[IRP_MJ_CREATE] = Create_File_IRPprocessing;
mj_func[IRP_MJ_CLOSE] = Close_HandleIRPprocessing;
return STATUS_SUCCESS;
}
VOID DriverUnload(IN PDRIVER_OBJECT DriverObject)
{
IoDeleteSymbolicLink(&SymbolicLinkName);
IoDeleteDevice(deviceObject);
// Cpp unload
libcpp_exit();
DbgPrint("\t------EXIT------\n");
return;
}
NTSTATUS CompleteIrp( PIRP Irp, NTSTATUS status, ULONG info)
{
Irp->IoStatus.Status = status;
Irp->IoStatus.Information = info;
IoCompleteRequest(Irp,IO_NO_INCREMENT);
return status;
}
NTSTATUS DeviceControlRoutine( IN PDEVICE_OBJECT fdo, IN PIRP pIrp )
{
ULONG BytesTxd =0; // Number of transmitted,received bytes
//UNICODE_STRING funcUnicodeStr_file;
//RtlInitUnicodeString(&funcUnicodeStr_file,L"NtQueryDirectoryFile");
//DPCTest dpcTest;
//dpcTest.Run();
//for(int i=0;i<1;i++)
//{
// gHookMng.ClearHooks();
// if(!gHookMng.AddHook(NewNtQueryDirectoryFile, // Pointer to new function
// (PVOID*)&TrueNtQueryDirectoryFile, // Pointer to true function
// &funcUnicodeStr_file)) // Unicode name of true function
// DbgPrint("Hook installing error3\n");
//}
//dpcTest.Stop();
return CompleteIrp(pIrp,STATUS_SUCCESS,BytesTxd);
}
// Create_File_IRPprocessing: process IRP_MJ_CREATE query.
NTSTATUS Create_File_IRPprocessing(IN PDEVICE_OBJECT fdo,IN PIRP Irp)
{
DbgPrint("-TestDriver- IRP_MJ_CREATE\n");
return CompleteIrp(Irp,STATUS_SUCCESS,0);
}
// Close_File_IRPprocessing: process IRP_MJ_CLOSE query.
NTSTATUS Close_HandleIRPprocessing(IN PDEVICE_OBJECT fdo,IN PIRP Irp)
{
DbgPrint("-TestDriver- IRP_MJ_CLOSE\n");
return CompleteIrp(Irp,STATUS_SUCCESS,0);
}
?? 快捷鍵說明
復制代碼
Ctrl + C
搜索代碼
Ctrl + F
全屏模式
F11
切換主題
Ctrl + Shift + D
顯示快捷鍵
?
增大字號
Ctrl + =
減小字號
Ctrl + -