參考資訊:
https://wasm.in/
http://four-f.narod.ru/
https://github.com/steward-fu/ddk
main.c
#include <ntddk.h>
#include <ntstrsafe.h>
PDEVICE_OBJECT pNextDevice = NULL;
void Handler(HANDLE ParentId, HANDLE ProcessId, BOOLEAN Create)
{
DbgPrint("PPID:0x%08x, PID:0x%08x, Creation:%d", ParentId, ProcessId, Create);
}
NTSTATUS AddDevice(PDRIVER_OBJECT pMyDriver, PDEVICE_OBJECT pPhyDevice)
{
PDEVICE_OBJECT pMyDevice = NULL;
UNICODE_STRING usDeviceName = { 0 };
RtlInitUnicodeString(&usDeviceName, L"\\Device\\MyDriver");
IoCreateDevice(pMyDriver, 0, &usDeviceName, FILE_DEVICE_UNKNOWN, 0, FALSE, &pMyDevice);
pNextDevice = IoAttachDeviceToDeviceStack(pMyDevice, pPhyDevice);
pMyDevice->Flags &= ~DO_DEVICE_INITIALIZING;
pMyDevice->Flags |= DO_BUFFERED_IO;
return STATUS_SUCCESS;
}
void Unload(PDRIVER_OBJECT pMyDriver)
{
}
NTSTATUS IrpDispatch(PDEVICE_OBJECT pMyDevice, PIRP pIrp)
{
PIO_STACK_LOCATION pStack = IoGetCurrentIrpStackLocation(pIrp);
if (pStack->MinorFunction == IRP_MN_REMOVE_DEVICE) {
PsSetCreateProcessNotifyRoutine(Handler, TRUE);
IoDetachDevice(pNextDevice);
IoDeleteDevice(pMyDevice);
IoCompleteRequest(pIrp, IO_NO_INCREMENT);
return STATUS_SUCCESS;
}
IoSkipCurrentIrpStackLocation(pIrp);
return IoCallDriver(pNextDevice, pIrp);
}
NTSTATUS DriverEntry(PDRIVER_OBJECT pMyDriver, PUNICODE_STRING pMyRegistry)
{
PsSetCreateProcessNotifyRoutine(Handler, FALSE);
pMyDriver->MajorFunction[IRP_MJ_PNP] = IrpDispatch;
pMyDriver->DriverExtension->AddDevice = AddDevice;
pMyDriver->DriverUnload = Unload;
return STATUS_SUCCESS;
}
完成