您的位置:首页 > 其它

NTFS FSD HOOK

2016-04-18 11:39 281 查看

NTFS FSD HOOK

NTSTATUS FSDHookControl( IN BOOLEAN IsHook )
{
NTSTATUS status = STATUS_SUCCESS;
UNICODE_STRING uNTFS = {0};
PDRIVER_OBJECT NTFS = NULL;

RtlInitUnicodeString( &uNTFS, L"\\FileSystem\\Ntfs" );

status = ObReferenceObjectByName(   &uNTFS,
OBJ_CASE_INSENSITIVE | OBJ_KERNEL_HANDLE,
NULL,
0,
*IoDriverObjectType,
KernelMode,
NULL,
&NTFS);

if ( ! NT_SUCCESS( status ) )
return status;

if( IsHook )
NtfsCreateDispatch = InterlockedExchangePointer(
&NTFS->MajorFunction[ IRP_MJ_CREATE ],
NtfsCreateDispatchHook );

if( ! IsHook && MmIsAddressValid( NtfsCreateDispatch ) )
InterlockedExchangePointer( &NTFS->MajorFunction[ IRP_MJ_CREATE ],
NtfsCreateDispatch );

status = ObDereferenceObject( NTFS );

return status;
}
内容来自用户分享和网络整理,不保证内容的准确性,如有侵权内容,可联系管理员处理 点击这里给我发消息
标签: