47 lines
999 B
C++
47 lines
999 B
C++
#include "load_Image_callback.h"
|
|
|
|
namespace load_image_notify_routine
|
|
{
|
|
|
|
typedef NTSTATUS(__fastcall* fnMmUnloadSystemImage)(PVOID ImageBase);
|
|
fnMmUnloadSystemImage _MmUnloadSystemImage = (fnMmUnloadSystemImage)0xfffff800042748a0;
|
|
|
|
VOID load_image_notify_routine(
|
|
PUNICODE_STRING FullImageName,
|
|
HANDLE ProcessId,
|
|
PIMAGE_INFO ImageInfo
|
|
)
|
|
{
|
|
UNREFERENCED_PARAMETER(ProcessId);
|
|
UNREFERENCED_PARAMETER(ImageInfo);
|
|
|
|
if (FullImageName->Buffer)
|
|
{
|
|
|
|
if (wcsstr(FullImageName->Buffer, L"MyDriver1"))
|
|
{
|
|
//DbgBreakPoint();
|
|
|
|
//DbgPrintEx(77, 0, "[+] %ws | pid:%d\n", FullImageName->Buffer, ProcessId);
|
|
|
|
//auto status = _MmUnloadSystemImage(ImageInfo->ImageBase);
|
|
|
|
//DbgPrintEx(77, 0, "%x\n", status);
|
|
}
|
|
|
|
}
|
|
}
|
|
|
|
|
|
|
|
auto create_image_load_notify_routine() -> NTSTATUS
|
|
{
|
|
return PsSetLoadImageNotifyRoutine(load_image_notify_routine);
|
|
}
|
|
auto remove_image_load_notify_routine() -> NTSTATUS
|
|
{
|
|
return PsRemoveLoadImageNotifyRoutine(load_image_notify_routine);
|
|
}
|
|
}
|
|
|