kd> u IofCallDriver
nt!IofCallDriver:
804ef120 ff2500d25480 jmp dword ptr [nt!pIofCallDriver (8054d200)]
804ef126 cc int 3
804ef127 cc int 3
804ef128 cc int 3
804ef129 cc int 3
804ef12a cc int 3
804ef12b cc int 3
然后hook之后
nt!IofCallDriver:
804ef120 ff2590b087f8 jmp dword ptr ds:[0F887B090h]
804ef126 cc int 3
804ef127 cc int 3
804ef128 cc int 3
804ef129 cc int 3
804ef12a cc int 3
804ef12b cc int 3
查看f887b090也是自己的函数代码区
之后下断点,调试,却发现jmp到 8b55ff8b
nt!IofCallDriver:
804ef120 ff25903085f8 jmp dword ptr [hook_iofcalldriver!MypIofCallDriver (f8853090)]
Net COM port baud is ignored
kd> p
8b55ff8b ?? ???