Files
2026-06-30 17:02:46 +08:00

47 lines
999 B
C++

#include "load_Image_callback.h"
namespace load_image_notify_routine
{
typedef NTSTATUS(__fastcall* fnMmUnloadSystemImage)(PVOID ImageBase);
fnMmUnloadSystemImage _MmUnloadSystemImage = (fnMmUnloadSystemImage)0xfffff800042748a0;
VOID load_image_notify_routine(
PUNICODE_STRING FullImageName,
HANDLE ProcessId,
PIMAGE_INFO ImageInfo
)
{
UNREFERENCED_PARAMETER(ProcessId);
UNREFERENCED_PARAMETER(ImageInfo);
if (FullImageName->Buffer)
{
if (wcsstr(FullImageName->Buffer, L"MyDriver1"))
{
//DbgBreakPoint();
//DbgPrintEx(77, 0, "[+] %ws | pid:%d\n", FullImageName->Buffer, ProcessId);
//auto status = _MmUnloadSystemImage(ImageInfo->ImageBase);
//DbgPrintEx(77, 0, "%x\n", status);
}
}
}
auto create_image_load_notify_routine() -> NTSTATUS
{
return PsSetLoadImageNotifyRoutine(load_image_notify_routine);
}
auto remove_image_load_notify_routine() -> NTSTATUS
{
return PsRemoveLoadImageNotifyRoutine(load_image_notify_routine);
}
}