-
Notifications
You must be signed in to change notification settings - Fork 1
/
Copy pathDriver.h
61 lines (49 loc) · 1.12 KB
/
Driver.h
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
#pragma once
#include <ntddk.h>
#include <intrin.h>
#include "Consts.h"
#pragma pack(push,1)
#define INTR_MAX 256
// Single interrupt descriptor
typedef struct {
UINT16 offs_lo; // offset bits 0..15
UINT16 selector; // a code segment selector in GDT or LDT
UINT8 zero; // unused, set to 0
UINT8 type_attr; // type and attributes
UINT16 offs_hi; // offset bits 16..31
} IDTDescriptor;
// Interrupt Descriptor Table
typedef IDTDescriptor IDT[INTR_MAX], *PIDT;
// Content of 48-bit IDTR register
typedef struct
{
UINT16 limit;
PIDT desc_table;
} IDTR;
// Interrupt Service Routine type
typedef int(__stdcall *ISR)();
typedef struct
{
UINT32 edi;
UINT32 esi;
UINT32 ebp;
UINT32 esp;
UINT32 ebx;
UINT32 edx;
UINT32 ecx;
UINT32 eax;
UINT32 pseudoflags;
UINT32 eip;
UINT32 cs;
UINT32 flags;
} CALLER_CONTEXT;
extern unsigned int getRegValue(
unsigned char src,
CALLER_CONTEXT* context);
extern void setRegValue(
unsigned char dst,
unsigned int value,
CALLER_CONTEXT* context);
/*** Handlers.c ***/
extern int __stdcall HandleUndefInstruction(unsigned char** instruction, CALLER_CONTEXT* context);
#pragma pack(pop)