#include
#include
#include
#pragma prefast(disable:__WARNING_ENCODE_MEMBER_FUNCTION_POINTER, "Not valid for kernel mode drivers")
PFLT_FILTER gFilterHandle;
ULONG_PTR OperationStatusCtx = 1;
#define PTDBG_TRACE_ROUTINES 0x00000001
#define PTDBG_TRACE_OPERATION_STATUS 0x00000002
ULONG gTraceFlags = 0;
#define PT_DBG_PRINT( _dbgLevel, _string ) \
(FlagOn(gTraceFlags,(_dbgLevel)) ? \
DbgPrint _string : \
((int)0))
/*************************************************************************
Prototypes
*************************************************************************/
DRIVER_INITIALIZE DriverEntry;
UCHAR * PsGetProcessImageFileName(__in PEPROCESS Process);
NTSTATUS
DriverEntry (
_In_ PDRIVER_OBJECT DriverObject,
_In_ PUNICODE_STRING RegistryPath
);
NTSTATUS
FsFilter1InstanceSetup (
_In_ PCFLT_RELATED_OBJECTS FltObjects,
_In_ FLT_INSTANCE_SETUP_FLAGS Flags,
_In_ DEVICE_TYPE VolumeDeviceType,
_In_ FLT_FILESYSTEM_TYPE VolumeFilesystemType
);
VOID
FsFilter1InstanceTeardownStart (
_In_ PCFLT_RELATED_OBJECTS FltObjects,
_In_ FLT_INSTANCE_TEARDOWN_FLAGS Flags
);
VOID
FsFilter1InstanceTeardownComplete (
_In_ PCFLT_RELATED_OBJECTS FltObjects,
_In_ FLT_INSTANCE_TEARDOWN_FLAGS Flags
);
NTSTATUS
FsFilter1Unload (
_In_ FLT_FILTER_UNLOAD_FLAGS Flags
);
NTSTATUS
FsFilter1InstanceQueryTeardown (
_In_ PCFLT_RELATED_OBJECTS FltObjects,
_In_ FLT_INSTANCE_QUERY_TEARDOWN_FLAGS Flags
);
FLT_PREOP_CALLBACK_STATUS
FsFilter1PreOperation (
_Inout_ PFLT_CALLBACK_DATA Data,
_In_ PCFLT_RELATED_OBJECTS FltObjects,
_Flt_CompletionContext_Outptr_ PVOID *CompletionContext
);
VOID
FsFilter1OperationStatusCallback (
_In_ PCFLT_RELATED_OBJECTS FltObjects,
_In_ PFLT_IO_PARAMETER_BLOCK ParameterSnapshot,
_In_ NTSTATUS OperationStatus,
_In_ PVOID RequesterContext
);
FLT_POSTOP_CALLBACK_STATUS
FsFilter1PostOperation (
_Inout_ PFLT_CALLBACK_DATA Data,
_In_ PCFLT_RELATED_OBJECTS FltObjects,
_In_opt_ PVOID CompletionContext,
_In_ FLT_POST_OPERATION_FLAGS Flags
);
FLT_PREOP_CALLBACK_STATUS
FsFilter1PreOperationNoPostOperation (
_Inout_ PFLT_CALLBACK_DATA Data,
_In_ PCFLT_RELATED_OBJECTS FltObjects,
_Flt_CompletionContext_Outptr_ PVOID *CompletionContext
);
BOOLEAN
FsFilter1DoRequestOperationStatus(
_In_ PFLT_CALLBACK_DATA Data
);
//
// Assign text sections for each routine.
//
#ifdef ALLOC_PRAGMA
#pragma alloc_text(INIT, DriverEntry)
#pragma alloc_text(PAGE, FsFilter1Unload)
#pragma alloc_text(PAGE, FsFilter1InstanceQueryTeardown)
#pragma alloc_text(PAGE, FsFilter1InstanceSetup)
#pragma alloc_text(PAGE, FsFilter1InstanceTeardownStart)
#pragma alloc_text(PAGE, FsFilter1InstanceTeardownComplete)
#endif
BOOLEAN NPUnicodeStringToChar(PUNICODE_STRING UniName, char Name[])
{
ANSI_STRING AnsiName;
NTSTATUS ntstatus;
char* nameptr;
__try {
ntstatus = RtlUnicodeStringToAnsiString(&AnsiName, UniName, TRUE);
if (AnsiName.Length < 260) {
nameptr = (PCHAR)AnsiName.Buffer;
//strcpy(Name, _strupr(nameptr)); //将字符串转换成大写形式
strcpy(Name, _strlwr(nameptr));//讲字符串转换成小写形式
//DbgPrint("NPUnicodeStringToChar : %s\n", Name);
}
RtlFreeAnsiString(&AnsiName);
}
__except (EXCEPTION_EXECUTE_HANDLER) {
DbgPrint("NPUnicodeStringToChar EXCEPTION_EXECUTE_HANDLER\n");
return FALSE;
}
return TRUE;
}
//获取进程全路径
PUNICODE_STRING GetSeLocateProcessImageName(PEPROCESS Process, PUNICODE_STRING *pImageFileName)
{
POBJECT_NAME_INFORMATION pProcessImageName = NULL;
PUNICODE_STRING pTempUS = NULL;
ULONG NameLength = 0;
//Process->SeAuditProcessCreationInfo.ImageFileName->Name
//win7 x86 offset = 0x1ec
//if (NULL == Process->SeAuditProcessCreationInfo.ImageFileName)
pProcessImageName = (POBJECT_NAME_INFORMATION)(*(ULONG*)((ULONG)Process + 0x1ec));
if (pProcessImageName == NULL)
{
DbgPrint("Process->SeAuditProcessCreationInfo.ImageFileName == NULL \n");
return NULL;
}
else
{
NameLength = sizeof(UNICODE_STRING) + pProcessImageName->Name.MaximumLength;
pTempUS = ExAllocatePoolWithTag(NonPagedPool, NameLength, 'aPeS');
if (NULL != pTempUS) {
RtlCopyMemory(
pTempUS,
&pProcessImageName->Name,
NameLength
);
pTempUS->Buffer = (PWSTR)(((PUCHAR)pTempUS) + sizeof(UNICODE_STRING));
*pImageFileName = pTempUS;
return *pImageFileName;
}
return NULL;
}
}
//
// operation registration
//
FLT_PREOP_CALLBACK_STATUS NPPreCreate(
__inout PFLT_CALLBACK_DATA Data,
__in PCFLT_RELATED_OBJECTS FltObjects,
__deref_out_opt PVOID *CompletionContext)
{
char FileName[260] = "X:";//记录文件名
char FilePath[260] = "Y:";//记录相对路径(ParentDir)
char Ext[260] = "Z:";//记录扩展名
UCHAR *pProcName = NULL;
NTSTATUS status;
UNICODE_STRING uniString;
PEPROCESS pEprocess = 0;
PUNICODE_STRING uSProcessPath = NULL;
PFLT_FILE_NAME_INFORMATION nameInfo;
UNREFERENCED_PARAMETER(FltObjects);
UNREFERENCED_PARAMETER(CompletionContext);
PAGED_CODE();
__try {
status = FltGetFileNameInformation(Data, FLT_FILE_NAME_NORMALIZED | FLT_FILE_NAME_QUERY_DEFAULT, &nameInfo);
if (NT_SUCCESS(status)) {
//DbgPrint("进入了\r\n");
FltParseFileNameInformation(nameInfo);
if (NPUnicodeStringToChar(&nameInfo->Name, FileName)) {
if (NPUnicodeStringToChar(&nameInfo->ParentDir, FilePath)){
//输出文件名及相对路径
DbgPrint("文件名:%s\r\n", FileName);
DbgPrint("文件路径:%s\r\n", FilePath);
//输出扩展名
NPUnicodeStringToChar(&nameInfo->Extension, Ext);
DbgPrint("文件扩展名:%s\r\n", Ext);
pEprocess = Data->Thread ? IoThreadToProcess(Data->Thread) : PsGetCurrentProcess();
//uSProcessPath = PsGetProcessFullName(pEprocess);//这里需要释放UNICODESTRING 的内存
//GetSeLocateProcessImageName(pEprocess, &uSProcessPath);
pProcName = PsGetProcessImageFileName(pEprocess);
DbgPrint("ProcFullName : %s\n", pProcName);
//判断文件路径或名字是否符合要求,若是满足要求则拒绝访问
if (strstr(FileName, "txt") > 0) {
Data->IoStatus.Status = STATUS_ACCESS_DENIED;
Data->IoStatus.Information = 0;
FltReleaseFileNameInformation(nameInfo);
return STATUS_ACCESS_DENIED;
}
}
FltReleaseFileNameInformation(nameInfo);
}
}
}
__except (EXCEPTION_EXECUTE_HANDLER) {
DbgPrint("NPPreCreate EXCEPTION_EXECUTE_HANDLER\n");
}
return FLT_PREOP_SUCCESS_WITH_CALLBACK;
}
CONST FLT_OPERATION_REGISTRATION Callbacks[] = {
{ IRP_MJ_CREATE,
0,
NPPreCreate,
FsFilter1PostOperation },
#if 0 // TODO - List all of the requests to filter.
{ IRP_MJ_CREATE_NAMED_PIPE,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_CLOSE,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_READ,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_WRITE,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_QUERY_INFORMATION,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_SET_INFORMATION,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_QUERY_EA,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_SET_EA,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_FLUSH_BUFFERS,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_QUERY_VOLUME_INFORMATION,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_SET_VOLUME_INFORMATION,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_DIRECTORY_CONTROL,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_FILE_SYSTEM_CONTROL,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_DEVICE_CONTROL,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_INTERNAL_DEVICE_CONTROL,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_SHUTDOWN,
0,
FsFilter1PreOperationNoPostOperation,
NULL }, //post operations not supported
{ IRP_MJ_LOCK_CONTROL,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_CLEANUP,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_CREATE_MAILSLOT,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_QUERY_SECURITY,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_SET_SECURITY,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_QUERY_QUOTA,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_SET_QUOTA,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_PNP,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_ACQUIRE_FOR_SECTION_SYNCHRONIZATION,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_RELEASE_FOR_SECTION_SYNCHRONIZATION,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_ACQUIRE_FOR_MOD_WRITE,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_RELEASE_FOR_MOD_WRITE,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_ACQUIRE_FOR_CC_FLUSH,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_RELEASE_FOR_CC_FLUSH,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_FAST_IO_CHECK_IF_POSSIBLE,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_NETWORK_QUERY_OPEN,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_MDL_READ,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_MDL_READ_COMPLETE,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_PREPARE_MDL_WRITE,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_MDL_WRITE_COMPLETE,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_VOLUME_MOUNT,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
{ IRP_MJ_VOLUME_DISMOUNT,
0,
FsFilter1PreOperation,
FsFilter1PostOperation },
#endif // TODO
{ IRP_MJ_OPERATION_END }
};
//
// This defines what we want to filter with FltMgr
//
CONST FLT_REGISTRATION FilterRegistration = {
sizeof( FLT_REGISTRATION ), // Size
FLT_REGISTRATION_VERSION, // Version
0, // Flags
NULL, // Context
Callbacks, // Operation callbacks
FsFilter1Unload, // MiniFilterUnload
FsFilter1InstanceSetup, // InstanceSetup
FsFilter1InstanceQueryTeardown, // InstanceQueryTeardown
FsFilter1InstanceTeardownStart, // InstanceTeardownStart
FsFilter1InstanceTeardownComplete, // InstanceTeardownComplete
NULL, // GenerateFileName
NULL, // GenerateDestinationFileName
NULL // NormalizeNameComponent
};
NTSTATUS
FsFilter1InstanceSetup (
_In_ PCFLT_RELATED_OBJECTS FltObjects,
_In_ FLT_INSTANCE_SETUP_FLAGS Flags,
_In_ DEVICE_TYPE VolumeDeviceType,
_In_ FLT_FILESYSTEM_TYPE VolumeFilesystemType
)
/*++
Routine Description:
This routine is called whenever a new instance is created on a volume. This
gives us a chance to decide if we need to attach to this volume or not.
If this routine is not defined in the registration structure, automatic
instances are always created.
Arguments:
FltObjects - Pointer to the FLT_RELATED_OBJECTS data structure containing
opaque handles to this filter, instance and its associated volume.
Flags - Flags describing the reason for this attach request.
Return Value:
STATUS_SUCCESS - attach
STATUS_FLT_DO_NOT_ATTACH - do not attach
--*/
{
UNREFERENCED_PARAMETER( FltObjects );
UNREFERENCED_PARAMETER( Flags );
UNREFERENCED_PARAMETER( VolumeDeviceType );
UNREFERENCED_PARAMETER( VolumeFilesystemType );
PAGED_CODE();
PT_DBG_PRINT( PTDBG_TRACE_ROUTINES,
("FsFilter1!FsFilter1InstanceSetup: Entered\n") );
return STATUS_SUCCESS;
}
NTSTATUS
FsFilter1InstanceQueryTeardown (
_In_ PCFLT_RELATED_OBJECTS FltObjects,
_In_ FLT_INSTANCE_QUERY_TEARDOWN_FLAGS Flags
)
/*++
Routine Description:
This is called when an instance is being manually deleted by a
call to FltDetachVolume or FilterDetach thereby giving us a
chance to fail that detach request.
If this routine is not defined in the registration structure, explicit
detach requests via FltDetachVolume or FilterDetach will always be
failed.
Arguments:
FltObjects - Pointer to the FLT_RELATED_OBJECTS data structure containing
opaque handles to this filter, instance and its associated volume.
Flags - Indicating where this detach request came from.
Return Value:
Returns the status of this operation.
--*/
{
UNREFERENCED_PARAMETER( FltObjects );
UNREFERENCED_PARAMETER( Flags );
PAGED_CODE();
PT_DBG_PRINT( PTDBG_TRACE_ROUTINES,
("FsFilter1!FsFilter1InstanceQueryTeardown: Entered\n") );
return STATUS_SUCCESS;
}
VOID
FsFilter1InstanceTeardownStart (
_In_ PCFLT_RELATED_OBJECTS FltObjects,
_In_ FLT_INSTANCE_TEARDOWN_FLAGS Flags
)
/*++
Routine Description:
This routine is called at the start of instance teardown.
Arguments:
FltObjects - Pointer to the FLT_RELATED_OBJECTS data structure containing
opaque handles to this filter, instance and its associated volume.
Flags - Reason why this instance is being deleted.
Return Value:
None.
--*/
{
UNREFERENCED_PARAMETER( FltObjects );
UNREFERENCED_PARAMETER( Flags );
PAGED_CODE();
PT_DBG_PRINT( PTDBG_TRACE_ROUTINES,
("FsFilter1!FsFilter1InstanceTeardownStart: Entered\n") );
}
VOID
FsFilter1InstanceTeardownComplete (
_In_ PCFLT_RELATED_OBJECTS FltObjects,
_In_ FLT_INSTANCE_TEARDOWN_FLAGS Flags
)
/*++
Routine Description:
This routine is called at the end of instance teardown.
Arguments:
FltObjects - Pointer to the FLT_RELATED_OBJECTS data structure containing
opaque handles to this filter, instance and its associated volume.
Flags - Reason why this instance is being deleted.
Return Value:
None.
--*/
{
UNREFERENCED_PARAMETER( FltObjects );
UNREFERENCED_PARAMETER( Flags );
PAGED_CODE();
PT_DBG_PRINT( PTDBG_TRACE_ROUTINES,
("FsFilter1!FsFilter1InstanceTeardownComplete: Entered\n") );
}
/*************************************************************************
MiniFilter initialization and unload routines.
*************************************************************************/
NTSTATUS DriverEntry (_In_ PDRIVER_OBJECT DriverObject,_In_ PUNICODE_STRING RegistryPath)
{
NTSTATUS status;
UNREFERENCED_PARAMETER( RegistryPath );
PT_DBG_PRINT( PTDBG_TRACE_ROUTINES,
("FsFilter1!DriverEntry: Entered\n") );
//
// Register with FltMgr to tell it our callback routines
//
status = FltRegisterFilter( DriverObject,
&FilterRegistration,
&gFilterHandle );
FLT_ASSERT( NT_SUCCESS( status ) );
if (NT_SUCCESS( status )) {
status = FltStartFiltering( gFilterHandle );
if (!NT_SUCCESS( status )) {
FltUnregisterFilter( gFilterHandle );
}
}
return status;
}
NTSTATUS
FsFilter1Unload (_In_ FLT_FILTER_UNLOAD_FLAGS Flags)
{
UNREFERENCED_PARAMETER( Flags );
PAGED_CODE();
PT_DBG_PRINT( PTDBG_TRACE_ROUTINES,
("FsFilter1!FsFilter1Unload: Entered\n") );
FltUnregisterFilter( gFilterHandle );
return STATUS_SUCCESS;
}
/*************************************************************************
MiniFilter callback routines.
*************************************************************************/
FLT_PREOP_CALLBACK_STATUS
FsFilter1PreOperation (
_Inout_ PFLT_CALLBACK_DATA Data,
_In_ PCFLT_RELATED_OBJECTS FltObjects,
_Flt_CompletionContext_Outptr_ PVOID *CompletionContext
)
/*++
Routine Description:
This routine is a pre-operation dispatch routine for this miniFilter.
This is non-pageable because it could be called on the paging path
Arguments:
Data - Pointer to the filter callbackData that is passed to us.
FltObjects - Pointer to the FLT_RELATED_OBJECTS data structure containing
opaque handles to this filter, instance, its associated volume and
file object.
CompletionContext - The context for the completion routine for this
operation.
Return Value:
The return value is the status of the operation.
--*/
{
NTSTATUS status;
UNREFERENCED_PARAMETER( FltObjects );
UNREFERENCED_PARAMETER( CompletionContext );
PT_DBG_PRINT( PTDBG_TRACE_ROUTINES,
("FsFilter1!FsFilter1PreOperation: Entered\n") );
//
// See if this is an operation we would like the operation status
// for. If so request it.
//
// NOTE: most filters do NOT need to do this. You only need to make
// this call if, for example, you need to know if the oplock was
// actually granted.
//
if (FsFilter1DoRequestOperationStatus( Data )) {
status = FltRequestOperationStatusCallback( Data,
FsFilter1OperationStatusCallback,
(PVOID)(++OperationStatusCtx) );
if (!NT_SUCCESS(status)) {
PT_DBG_PRINT( PTDBG_TRACE_OPERATION_STATUS,
("FsFilter1!FsFilter1PreOperation: FltRequestOperationStatusCallback Failed, status=%08x\n",
status) );
}
}
// This template code does not do anything with the callbackData, but
// rather returns FLT_PREOP_SUCCESS_WITH_CALLBACK.
// This passes the request down to the next miniFilter in the chain.
return FLT_PREOP_SUCCESS_WITH_CALLBACK;
}
VOID
FsFilter1OperationStatusCallback (
_In_ PCFLT_RELATED_OBJECTS FltObjects,
_In_ PFLT_IO_PARAMETER_BLOCK ParameterSnapshot,
_In_ NTSTATUS OperationStatus,
_In_ PVOID RequesterContext
)
/*++
Routine Description:
This routine is called when the given operation returns from the call
to IoCallDriver. This is useful for operations where STATUS_PENDING
means the operation was successfully queued. This is useful for OpLocks
and directory change notification operations.
This callback is called in the context of the originating thread and will
never be called at DPC level. The file object has been correctly
referenced so that you can access it. It will be automatically
dereferenced upon return.
This is non-pageable because it could be called on the paging path
Arguments:
FltObjects - Pointer to the FLT_RELATED_OBJECTS data structure containing
opaque handles to this filter, instance, its associated volume and
file object.
RequesterContext - The context for the completion routine for this
operation.
OperationStatus -
Return Value:
The return value is the status of the operation.
--*/
{
UNREFERENCED_PARAMETER( FltObjects );
PT_DBG_PRINT( PTDBG_TRACE_ROUTINES,
("FsFilter1!FsFilter1OperationStatusCallback: Entered\n") );
PT_DBG_PRINT( PTDBG_TRACE_OPERATION_STATUS,
("FsFilter1!FsFilter1OperationStatusCallback: Status=%08x ctx=%p IrpMj=%02x.%02x \"%s\"\n",
OperationStatus,
RequesterContext,
ParameterSnapshot->MajorFunction,
ParameterSnapshot->MinorFunction,
FltGetIrpName(ParameterSnapshot->MajorFunction)) );
}
FLT_POSTOP_CALLBACK_STATUS
FsFilter1PostOperation (
_Inout_ PFLT_CALLBACK_DATA Data,
_In_ PCFLT_RELATED_OBJECTS FltObjects,
_In_opt_ PVOID CompletionContext,
_In_ FLT_POST_OPERATION_FLAGS Flags
)
/*++
Routine Description:
This routine is the post-operation completion routine for this
miniFilter.
This is non-pageable because it may be called at DPC level.
Arguments:
Data - Pointer to the filter callbackData that is passed to us.
FltObjects - Pointer to the FLT_RELATED_OBJECTS data structure containing
opaque handles to this filter, instance, its associated volume and
file object.
CompletionContext - The completion context set in the pre-operation routine.
Flags - Denotes whether the completion is successful or is being drained.
Return Value:
The return value is the status of the operation.
--*/
{
UNREFERENCED_PARAMETER( Data );
UNREFERENCED_PARAMETER( FltObjects );
UNREFERENCED_PARAMETER( CompletionContext );
UNREFERENCED_PARAMETER( Flags );
PT_DBG_PRINT( PTDBG_TRACE_ROUTINES,
("FsFilter1!FsFilter1PostOperation: Entered\n") );
return FLT_POSTOP_FINISHED_PROCESSING;
}
FLT_PREOP_CALLBACK_STATUS
FsFilter1PreOperationNoPostOperation (
_Inout_ PFLT_CALLBACK_DATA Data,
_In_ PCFLT_RELATED_OBJECTS FltObjects,
_Flt_CompletionContext_Outptr_ PVOID *CompletionContext
)
/*++
Routine Description:
This routine is a pre-operation dispatch routine for this miniFilter.
This is non-pageable because it could be called on the paging path
Arguments:
Data - Pointer to the filter callbackData that is passed to us.
FltObjects - Pointer to the FLT_RELATED_OBJECTS data structure containing
opaque handles to this filter, instance, its associated volume and
file object.
CompletionContext - The context for the completion routine for this
operation.
Return Value:
The return value is the status of the operation.
--*/
{
UNREFERENCED_PARAMETER( Data );
UNREFERENCED_PARAMETER( FltObjects );
UNREFERENCED_PARAMETER( CompletionContext );
PT_DBG_PRINT( PTDBG_TRACE_ROUTINES,
("FsFilter1!FsFilter1PreOperationNoPostOperation: Entered\n") );
// This template code does not do anything with the callbackData, but
// rather returns FLT_PREOP_SUCCESS_NO_CALLBACK.
// This passes the request down to the next miniFilter in the chain.
return FLT_PREOP_SUCCESS_NO_CALLBACK;
}
BOOLEAN
FsFilter1DoRequestOperationStatus(
_In_ PFLT_CALLBACK_DATA Data
)
/*++
Routine Description:
This identifies those operations we want the operation status for. These
are typically operations that return STATUS_PENDING as a normal completion
status.
Arguments:
Return Value:
TRUE - If we want the operation status
FALSE - If we don't
--*/
{
PFLT_IO_PARAMETER_BLOCK iopb = Data->Iopb;
//
// return boolean state based on which operations we are interested in
//
return (BOOLEAN)
//
// Check for oplock operations
//
(((iopb->MajorFunction == IRP_MJ_FILE_SYSTEM_CONTROL) &&
((iopb->Parameters.FileSystemControl.Common.FsControlCode == FSCTL_REQUEST_FILTER_OPLOCK) ||
(iopb->Parameters.FileSystemControl.Common.FsControlCode == FSCTL_REQUEST_BATCH_OPLOCK) ||
(iopb->Parameters.FileSystemControl.Common.FsControlCode == FSCTL_REQUEST_OPLOCK_LEVEL_1) ||
(iopb->Parameters.FileSystemControl.Common.FsControlCode == FSCTL_REQUEST_OPLOCK_LEVEL_2)))
||
//
// Check for directy change notification
//
((iopb->MajorFunction == IRP_MJ_DIRECTORY_CONTROL) &&
(iopb->MinorFunction == IRP_MN_NOTIFY_CHANGE_DIRECTORY))
);
}
将Instance1.Altitude = "370030"的注释去掉
安装:
右键FsFilter1.inf文件,点击安装xp下驱动不签名可以安装
win7以上用测试模式,或者伪造签名来安装驱动
启动驱动:管理员启动cmd, sc start FsFilter1(换成你自己驱动的名字)