-
-
[原创]逆向小红伞杀毒软件--avkmgr
-
发表于:
2017-11-26 14:32
5358
-
NTSTATUS DriverEntry(_In_ PDRIVER_OBJECT DriverObject , _In_ PUNICODE_STRING RegistryPath) {
UNICODE_STRING DeviceName={ 0 };
PDEVICE_OBJECT DeviceObject={ 0 };
UNREFERENCED_PARAMETER(RegistryPath);
OSVERSIONINFOEXW os ={ 0 };
os.dwOSVersionInfoSize = sizeof(OSVERSIONINFOEXW);
RtlGetVersion((POSVERSIONINFOW)&os);
if (os.dwMajorVersion < 5 || os.dwMajorVersion == 5 && !os.dwMinorVersion) {
return 0x0C0000002;
}
g_dwMajorVersion = os.dwMajorVersion;
g_dwMinorVersion = os.dwMinorVersion;
sub_140001718();
avk_GetSystemRoutineAddress();
func9();
if (g_FunTable.sub_100) {
g_FunTable.sub_100(sub_140001390 , 0);
}
else {
g_FunTable.sub_F8(sub_14000130C , 0);
}
g_FunTable.sub_108(sub_140001414);
g_FunTable.sub_110(sub_140001608);
RtlInitUnicodeString(&DeviceName , avk_SystemRoutineName(0x3b));
IoCreateDevice(DriverObject , 0 , &DeviceName , 0x22u , 0x100u , 0 , &DeviceObject);
funcc.field_1C = 1;
avk_IoErrorLog(L"avkmgr.sys successfully loaded" , 0x40070011 , DriverObject);
return 0;
}
- 获取系统版本
- 获取系统函数地址
获取系统版本
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课