Global.cpp 31 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200
  1. #include "StdAfx.h"
  2. #include "Global.h"
  3. // 获取文件版本号函数头文件;
  4. #include <WinVer.h>
  5. #pragma comment(lib,"version.lib")
  6. using namespace std;
  7. #include <psapi.h>
  8. #pragma comment(lib,"Psapi.lib")
  9. #include <locale.h>
  10. #include <io.h>//_access头文件;
  11. TCHAR g_szModulePath[MAX_PATH] = _T(""); // 软件目录;
  12. TCHAR g_szModuleFileName[MAX_PATH] = _T(""); // 软件名称;
  13. TCHAR g_szIniFile[MAX_PATH] = _T("");
  14. // 配置文件信息;
  15. TCHAR g_szServAddress[MAX_PATH] = _T("");
  16. DWORD g_dwServPort = 0;
  17. TCHAR g_szAccount[MAX_PATH] = _T("");
  18. TCHAR g_szPassword[MAX_PATH] = _T("");
  19. TCHAR g_szWeChatPath[MAX_PATH] = _T("");
  20. TCHAR g_szCacheDir[MAX_PATH] = _T("");
  21. TCHAR g_szDynamicLibraryPath[MAX_PATH] = _T("");
  22. // 控制台输出;
  23. BOOL g_bStdOut = FALSE;
  24. #define TRACE4(sz, p1, p2, p3, p4) TRACE(_T(sz), p1, p2, p3, p4)
  25. /************************************************************************/
  26. /* 函数:[1/6/2019 Home];
  27. /* 描述:;
  28. /* 参数:;
  29. /* [IN] :;
  30. /* [OUT] :;
  31. /* [IN/OUT] :;
  32. /* 返回:void;
  33. /* 注意:;
  34. /* 示例:;
  35. /*
  36. /* 修改:;
  37. /* 日期:;
  38. /* 内容:;
  39. /************************************************************************/
  40. int GetIniInfo(LPCTSTR lpIniDir /* = NULL */, LPCTSTR lpIniName /* = NULL */)
  41. {
  42. TCHAR szDrive[_MAX_DRIVE] = { 0 };
  43. TCHAR szDir[_MAX_DIR] = { 0 };
  44. TCHAR szFna[_MAX_DIR] = { 0 };
  45. TCHAR szExt[_MAX_DIR] = { 0 };
  46. ::GetModuleFileName(NULL, g_szModulePath, sizeof(g_szModulePath) / sizeof(TCHAR));
  47. _stprintf_s(g_szModuleFileName, _T("%s"), g_szModulePath);
  48. _tsplitpath_s(g_szModulePath, szDrive, szDir, szFna, szExt);
  49. _tcscpy_s(g_szModulePath, szDrive);
  50. _tcscat_s(g_szModulePath, szDir);
  51. // 动态库路径;
  52. _stprintf_s(g_szDynamicLibraryPath, _T("%shook.dll"), g_szModulePath);
  53. #ifdef _DEBUG
  54. //_stprintf_s(g_szDynamicLibraryPath, _T("%shook.dll"), _T("E:\\bin\\WeChats2017\\"));
  55. WriteTextLog(_T("DLL路径=%s"),g_szDynamicLibraryPath);
  56. #endif
  57. if (lpIniDir != NULL && lpIniName != NULL)
  58. _stprintf_s(g_szIniFile, _T("%s%s"), lpIniDir, lpIniName);
  59. else
  60. _stprintf_s(g_szIniFile, _T("%sconfig.ini"), g_szModulePath);
  61. HANDLE hFile = CreateFile(g_szIniFile, 0/*GENERIC_READ*/, 0, NULL, OPEN_EXISTING, 0, NULL);
  62. if (ERROR_FILE_NOT_FOUND == GetLastError())
  63. {
  64. return -1;
  65. }
  66. CloseHandle(hFile);
  67. hFile = NULL;
  68. // 获取服务器端信息;
  69. GetPrivateProfileString(_T("ServerInfo"), _T("IP"), _T(""), g_szServAddress, MAX_PATH, g_szIniFile);
  70. g_dwServPort = GetPrivateProfileInt(_T("ServerInfo"), _T("Port"), 0, g_szIniFile);
  71. GetPrivateProfileString(_T("CustomerInfo"), _T("Account"), _T(""), g_szAccount, MAX_PATH, g_szIniFile);
  72. GetPrivateProfileString(_T("CustomerInfo"), _T("Password"), _T(""), g_szPassword, MAX_PATH, g_szIniFile);
  73. GetPrivateProfileString(_T("CustomerInfo"), _T("WeChat"), _T(""), g_szWeChatPath, MAX_PATH, g_szIniFile);
  74. GetPrivateProfileString(_T("CustomerInfo"), _T("Cache"), _T(""), g_szCacheDir, MAX_PATH, g_szIniFile);
  75. g_bStdOut = GetPrivateProfileInt(_T("CustomerInfo"), _T("StdOut"), 0, g_szIniFile);
  76. if ( g_bStdOut )
  77. {
  78. AllocConsole(); // 开辟控制台;
  79. SetConsoleTitle(_T("调试输出")); // 设置控制台窗口标题;
  80. freopen("CONOUT$", "w+t", stdout); // 重定向输出;
  81. freopen("CONIN$", "r+t", stdin); // 重定向输入;
  82. HWND hWnd = NULL;
  83. again:
  84. hWnd = ::FindWindow(NULL, _T("调试输出"));
  85. if( hWnd )
  86. {
  87. if (!::SetWindowPos(hWnd, HWND_TOPMOST, 0,0,0,0, SWP_NOMOVE | SWP_NOSIZE))
  88. {
  89. _tprintf_s(_T("前置设置失败\n"));
  90. }
  91. else
  92. {
  93. _tprintf_s(_T("前置设置成功\n"));
  94. }
  95. }
  96. else
  97. {
  98. goto again;
  99. }
  100. }
  101. return 0;
  102. }
  103. /************************************************************************/
  104. /* 函数:[1/6/2019 Home];
  105. /* 描述:;
  106. /* 参数:;
  107. /* [IN] :;
  108. /* [OUT] :;
  109. /* [IN/OUT] :;
  110. /* 返回:void;
  111. /* 注意:;
  112. /* 示例:;
  113. /*
  114. /* 修改:;
  115. /* 日期:;
  116. /* 内容:;
  117. /************************************************************************/
  118. DWORD FindProcess(LPCTSTR lpProName)
  119. {
  120. ASSERT(lpProName!=NULL);
  121. DWORD dwPID = 0;
  122. PROCESSENTRY32 pe32 = { 0 };
  123. HANDLE hSnapshot = CreateToolhelp32Snapshot(TH32CS_SNAPPROCESS, 0);
  124. if (hSnapshot == NULL)
  125. {
  126. return 0;
  127. }
  128. pe32.dwSize = sizeof(PROCESSENTRY32);
  129. if (Process32First(hSnapshot, &pe32))
  130. {
  131. do {
  132. if (_tcsicmp(lpProName, pe32.szExeFile) == 0)
  133. {
  134. dwPID = pe32.th32ProcessID;
  135. break;
  136. }
  137. } while (Process32Next(hSnapshot, &pe32));
  138. }
  139. CloseHandle(hSnapshot);
  140. return dwPID;
  141. }
  142. vector<DWORD> FindAllProcess(LPCTSTR lpProName)
  143. {
  144. ASSERT(lpProName!=NULL);
  145. vector<DWORD> vtPID;
  146. PROCESSENTRY32 pe32 = { 0 };
  147. HANDLE hSnapshot = CreateToolhelp32Snapshot(TH32CS_SNAPPROCESS, 0);
  148. if (hSnapshot == NULL)
  149. return vector<DWORD>();
  150. pe32.dwSize = sizeof(PROCESSENTRY32);
  151. if (Process32First(hSnapshot, &pe32))
  152. {
  153. do {
  154. if (_tcsicmp(lpProName, pe32.szExeFile) == 0)
  155. {
  156. vtPID.push_back(pe32.th32ProcessID);
  157. }
  158. } while (Process32Next(hSnapshot, &pe32));
  159. }
  160. CloseHandle(hSnapshot);
  161. return vtPID;
  162. }
  163. void FindAllProcess(std::vector<ProInfo> &vtProInfo)
  164. {
  165. PROCESSENTRY32 pe32 = { 0 };
  166. HANDLE hSnapshot = CreateToolhelp32Snapshot(TH32CS_SNAPPROCESS, 0);
  167. if (hSnapshot == NULL)
  168. return;
  169. pe32.dwSize = sizeof(PROCESSENTRY32);
  170. if (!Process32First(hSnapshot, &pe32))
  171. goto end;
  172. do
  173. {
  174. ProInfo proinfo;
  175. proinfo.dwProId = pe32.th32ProcessID;
  176. proinfo.strProName = pe32.szExeFile;
  177. vtProInfo.push_back(proinfo);
  178. } while (Process32Next(hSnapshot, &pe32));
  179. end:
  180. CloseHandle(hSnapshot);
  181. }
  182. HANDLE FindModule(LPCTSTR lpModuleName, DWORD dwPID)
  183. {
  184. ASSERT(lpModuleName!=NULL);
  185. DWORD dwMID = 0;
  186. MODULEENTRY32 me32 = { 0 };
  187. HANDLE hSnapshot = CreateToolhelp32Snapshot(TH32CS_SNAPALL, dwPID);
  188. if (hSnapshot == NULL)
  189. return NULL;
  190. me32.dwSize = sizeof(PROCESSENTRY32);
  191. if (Module32First(hSnapshot, &me32))
  192. {
  193. do {
  194. if (_tcsicmp(lpModuleName, me32.szModule) == 0)
  195. {
  196. break;
  197. }
  198. } while (Module32Next(hSnapshot, &me32));
  199. }
  200. CloseHandle(hSnapshot);
  201. return me32.hModule;
  202. }
  203. HANDLE FindModuleEx(LPCTSTR lpModuleName, DWORD dwPid)
  204. {
  205. HMODULE hMods[1024] = {0};
  206. DWORD cbNeeded = 0;
  207. TCHAR szModName[MAX_PATH];
  208. BOOL Wow64Process;
  209. HANDLE hProcess = ::OpenProcess(PROCESS_QUERY_INFORMATION|PROCESS_VM_READ|PROCESS_QUERY_LIMITED_INFORMATION, FALSE, dwPid);
  210. IsWow64Process(hProcess, &Wow64Process); //判断是32位还是64位进程
  211. if ( EnumProcessModulesEx(hProcess, hMods, sizeof(hMods), &cbNeeded, Wow64Process?LIST_MODULES_32BIT:LIST_MODULES_64BIT) )
  212. {
  213. for (UINT i = 0; i < (cbNeeded / sizeof(HMODULE)); i++ )
  214. {
  215. GetModuleFileNameEx(hProcess, hMods[i], szModName, _countof(szModName));
  216. #ifdef _DEBUG
  217. WriteTextLog(_T("目标=%s, 原始=%s, 地址=%p"), szModName, lpModuleName, hMods[i]);
  218. #endif
  219. if (_tcsicmp(lpModuleName, szModName) == 0)
  220. {
  221. CloseHandle(hProcess);
  222. WriteTextLog(_T("【目标=%s, 原始=%s, 地址=%p】"), szModName, lpModuleName, hMods[i]);
  223. return hMods[i];
  224. }
  225. }
  226. }
  227. CloseHandle(hProcess);
  228. return NULL;
  229. }
  230. // WINDOWS NT 以上的内核需要提权,才能对系统进行高级管理;
  231. /************************************************************************/
  232. /* 函数:[1/6/2019 Home];
  233. /* 描述:;
  234. /* 参数:;
  235. /* [IN] :;
  236. /* [OUT] :;
  237. /* [IN/OUT] :;
  238. /* 返回:void;
  239. /* 注意:;
  240. /* 示例:;
  241. /*
  242. /* 修改:;
  243. /* 日期:;
  244. /* 内容:;
  245. /************************************************************************/
  246. BOOL GetDebugPriv()
  247. {
  248. // 返回的访问令牌指针;
  249. HANDLE hToken;
  250. // 接收所返回的制定特权名称的信息;
  251. LUID sedebugnameValue;
  252. // 新特权信息的指针(结构体);
  253. TOKEN_PRIVILEGES tkp;
  254. //DWORD dwCurProcId = GetCurrentProcessId();
  255. // 要修改访问权限的进程句柄;
  256. HANDLE hCurProc = ::GetCurrentProcess();
  257. //hCurProc = ::OpenProcess(PROCESS_ALL_ACCESS, FALSE, dwCurProcId);
  258. if (!::OpenProcessToken(hCurProc, TOKEN_ADJUST_PRIVILEGES | TOKEN_QUERY, &hToken))
  259. {
  260. return FALSE;
  261. }
  262. if (!::LookupPrivilegeValue(NULL, SE_DEBUG_NAME, &sedebugnameValue))
  263. {
  264. CloseHandle(hToken);
  265. return FALSE;
  266. }
  267. tkp.PrivilegeCount = 1;
  268. tkp.Privileges[0].Luid = sedebugnameValue;
  269. tkp.Privileges[0].Attributes = SE_PRIVILEGE_ENABLED;
  270. if (!::AdjustTokenPrivileges(hToken, FALSE, &tkp, sizeof tkp, NULL, NULL))
  271. {
  272. CloseHandle(hToken);
  273. return FALSE;
  274. }
  275. CloseHandle(hCurProc);
  276. CloseHandle(hToken);
  277. return TRUE;
  278. }
  279. /************************************************************************/
  280. /*
  281. 函数:GetFileVersion
  282. 描述:获取可执行文件的文件版号;
  283. 参数:
  284. hModule[IN] 可执行文件模块句柄;
  285. dwArray[OUT] 返回的文件版本号;
  286. 返回:
  287. 成功返回TRUE,失败返回FALSE;
  288. 注意:
  289. 当hModule为空时,表示要获取的可执行文件为本程序的文件版本号;
  290. */
  291. /************************************************************************/
  292. BOOL GetFileVersion( IN HMODULE hModule, OUT DWORD (&dwArray)[4])
  293. {
  294. TCHAR fname[MAX_PATH];
  295. VS_FIXEDFILEINFO *pVi;
  296. DWORD dwHandle;
  297. if ( GetModuleFileName(hModule, fname, MAX_PATH))
  298. {
  299. INT nSize = GetFileVersionInfoSize(fname, &dwHandle);
  300. if (nSize > 0)
  301. {
  302. BYTE *pBuffer = new BYTE[nSize];
  303. memset(pBuffer, 0, nSize);
  304. if (GetFileVersionInfo(fname, dwHandle, nSize, pBuffer))
  305. {
  306. if (VerQueryValue(pBuffer, _T("\\"), (LPVOID *)&pVi, (PUINT)&nSize))
  307. {
  308. dwArray[0] = HIWORD(pVi->dwFileVersionMS);
  309. dwArray[1] = LOWORD(pVi->dwFileVersionMS);
  310. dwArray[2] = HIWORD(pVi->dwFileVersionLS);
  311. dwArray[3] = LOWORD(pVi->dwFileVersionLS);
  312. delete[]pBuffer;
  313. return TRUE;
  314. }
  315. }
  316. if ( pBuffer )
  317. delete[]pBuffer;
  318. }
  319. }
  320. return FALSE;
  321. }
  322. /************************************************************************/
  323. /*
  324. 函数:GetFileVersion
  325. 描述:获取可执行文件的文件版号;
  326. 参数:
  327. lpFileName[IN] 可执行文件名全路径;
  328. dwArray[OUT] 返回的文件版本号;
  329. 返回:
  330. 成功返回TRUE,失败返回FALSE;
  331. 注意:
  332. */
  333. /************************************************************************/
  334. BOOL GetFileVersionEx( IN LPCTSTR lpFileName, IN DWORD (&dwArray)[4] )
  335. {
  336. if ( lpFileName == NULL || !PathFileExists(lpFileName) )
  337. {
  338. OutputDebugString(_T("文件名错误或文件不存在\n"));
  339. return FALSE;
  340. }
  341. DWORD dwHandle = 0;
  342. VS_FIXEDFILEINFO *pVi = NULL;
  343. INT nSize = GetFileVersionInfoSize(lpFileName, &dwHandle);
  344. if ( nSize > 0 )
  345. {
  346. BYTE *pBuffer = new BYTE[nSize];
  347. memset(pBuffer, 0, nSize);
  348. if ( GetFileVersionInfo(lpFileName, dwHandle, nSize, pBuffer) )
  349. {
  350. if (VerQueryValue(pBuffer, _T("\\"), (LPVOID *)&pVi, (PUINT)&nSize))
  351. {
  352. dwArray[0] = HIWORD(pVi->dwFileVersionMS);
  353. dwArray[1] = LOWORD(pVi->dwFileVersionMS);
  354. dwArray[2] = HIWORD(pVi->dwFileVersionLS);
  355. dwArray[3] = LOWORD(pVi->dwFileVersionLS);
  356. if (pBuffer)
  357. delete[]pBuffer;
  358. return TRUE;
  359. }
  360. }
  361. if (pBuffer)
  362. delete[]pBuffer;
  363. }
  364. return FALSE;
  365. }
  366. /************************************************************************/
  367. /*
  368. 函数:GetProductVersion
  369. 描述:获取可执行文件的产品版号;
  370. 参数:
  371. hModule[IN] 可执行文件模块句柄;
  372. dwArray[OUT] 返回的产品版本号;
  373. 返回:
  374. 成功返回TRUE,失败返回FALSE;
  375. 注意:
  376. 当hModule为空时,表示要获取的可执行文件为本程序的产品版本号;
  377. */
  378. /************************************************************************/
  379. BOOL GetProductVersion(IN HMODULE hModule, IN DWORD (&dwArray)[4] )
  380. {
  381. TCHAR fname[MAX_PATH];
  382. VS_FIXEDFILEINFO *pVi;
  383. DWORD dwHandle;
  384. if (::GetModuleFileName(hModule, fname, MAX_PATH))
  385. {
  386. INT nSize = GetFileVersionInfoSize(fname, &dwHandle);
  387. if (nSize > 0)
  388. {
  389. BYTE *pBuffer = new BYTE[nSize];
  390. memset(pBuffer, 0, nSize);
  391. if (GetFileVersionInfo(fname, dwHandle, nSize, pBuffer))
  392. {
  393. if (VerQueryValue(pBuffer, _T("\\"), (LPVOID *)&pVi, (PUINT)&nSize))
  394. {
  395. dwArray[0] = HIWORD(pVi->dwProductVersionMS);
  396. dwArray[1] = LOWORD(pVi->dwProductVersionMS);
  397. dwArray[2] = HIWORD(pVi->dwProductVersionLS);
  398. dwArray[3] = LOWORD(pVi->dwProductVersionLS);
  399. if(pBuffer)
  400. delete[]pBuffer;
  401. return TRUE;
  402. }
  403. }
  404. if(pBuffer)
  405. delete[]pBuffer;
  406. }
  407. }
  408. return FALSE;
  409. }
  410. /************************************************************************/
  411. /*
  412. 函数:GetProductVersion
  413. 描述:获取可执行文件的产品版号;
  414. 参数:
  415. lpFileName[IN] 可执行文件名全路径;
  416. dwArray[OUT] 返回的产品版本号;
  417. 返回:
  418. 成功返回TRUE,失败返回FALSE;
  419. 注意:
  420. */
  421. /************************************************************************/
  422. BOOL GetProductVersionEx( IN LPCTSTR lpFileName, IN DWORD (&dwArray)[4] )
  423. {
  424. if ( lpFileName == NULL || !PathFileExists(lpFileName) )
  425. {
  426. OutputDebugString(_T("文件名错误或文件不存在\n"));
  427. return FALSE;
  428. }
  429. DWORD dwHandle = 0;
  430. VS_FIXEDFILEINFO *pVi = NULL;
  431. INT nSize = GetFileVersionInfoSize(lpFileName, &dwHandle);
  432. if ( nSize > 0 )
  433. {
  434. BYTE *pBuffer = new BYTE[nSize];
  435. memset(pBuffer, 0, nSize);
  436. if ( GetFileVersionInfo(lpFileName, dwHandle, nSize, pBuffer) )
  437. {
  438. if (VerQueryValue(pBuffer, _T("\\"), (LPVOID *)&pVi, (PUINT)&nSize))
  439. {
  440. dwArray[0] = HIWORD(pVi->dwProductVersionMS);
  441. dwArray[1] = LOWORD(pVi->dwProductVersionMS);
  442. dwArray[2] = HIWORD(pVi->dwProductVersionLS);
  443. dwArray[3] = LOWORD(pVi->dwProductVersionLS);
  444. if (pBuffer)
  445. delete[]pBuffer;
  446. return TRUE;
  447. }
  448. }
  449. if (pBuffer)
  450. delete[]pBuffer;
  451. }
  452. return FALSE;
  453. }
  454. /************************************************************************/
  455. /* 函数:WriteTextLog[7/28/2016 IT];
  456. /* 描述:写文本日志;
  457. /* 参数:;
  458. /* [IN] :;
  459. /* 返回:void;
  460. /* 注意:;
  461. /* 示例:;
  462. /*
  463. /* 修改:;
  464. /* 日期:;
  465. /* 内容:;
  466. /************************************************************************/
  467. void WriteTextLog(const TCHAR *format, ...)
  468. {
  469. #if 0
  470. try
  471. {
  472. //static ThreadSection _critSection;
  473. //AutoThreadSection aSection(&_critSection);
  474. // 解析出日志路径;
  475. TCHAR szlogpath[MAX_PATH] = {0};
  476. static TCHAR szModulePath[MAX_PATH] = {0};
  477. static TCHAR szFna[_MAX_DIR] = { 0 };
  478. if ( szModulePath[0] == _T('\0') )
  479. {
  480. TCHAR szDrive[_MAX_DRIVE] = { 0 };
  481. TCHAR szDir[_MAX_DIR] = { 0 };
  482. TCHAR szExt[_MAX_DIR] = { 0 };
  483. ::GetModuleFileName(NULL, szModulePath, sizeof(szModulePath) / sizeof(TCHAR));
  484. _tsplitpath_s(szModulePath, szDrive, szDir, szFna, szExt);
  485. _tcscpy_s(szModulePath, szDrive);
  486. _tcscat_s(szModulePath, szDir);
  487. }
  488. _stprintf_s(szlogpath, _T("%s日志\\%s%s.txt"), szModulePath, szFna, CTime::GetCurrentTime().Format("[%Y-%m-%d]"));
  489. // 打开或创建文件;
  490. CStdioFile fp;
  491. if (PathFileExists(szlogpath))
  492. {
  493. if (fp.Open(szlogpath, CFile::modeWrite) == FALSE)
  494. {
  495. return;
  496. }
  497. fp.SeekToEnd();
  498. }
  499. else
  500. {
  501. fp.Open(szlogpath, CFile::modeCreate | CFile::modeWrite);
  502. }
  503. // 格式化前设置语言区域;
  504. TCHAR* old_locale = _tcsdup(_tsetlocale(LC_CTYPE, NULL));
  505. _tsetlocale(LC_CTYPE, _T("chs"));//设定中文;
  506. // 格式化日志内容;
  507. va_list args = NULL;
  508. int len = 0;
  509. TCHAR *buffer = NULL;
  510. va_start( args, format );
  511. // _vscprintf doesn't count. terminating '\0'
  512. len = _vsctprintf( format, args ) + 1;
  513. buffer = (TCHAR*)malloc( len * sizeof(TCHAR) );
  514. _vstprintf_s( buffer, len, format, args ); // C4996
  515. // Note: vsprintf is deprecated; consider using vsprintf_s instead
  516. // 将日志内容输入到文件中;
  517. fp.WriteString( CTime::GetCurrentTime().Format(_T("%Y-%m-%d %H:%M:%S ")) );
  518. fp.WriteString(buffer);
  519. fp.WriteString(_T("\n"));
  520. // 关闭文件,释放资源并设置回原语言区域;
  521. free( buffer );
  522. _tsetlocale(LC_CTYPE, old_locale);
  523. free(old_locale);//还原区域设定;
  524. fp.Close();
  525. }
  526. catch (CException *e)
  527. {
  528. e->ReportError();
  529. e->Delete();
  530. }
  531. #else
  532. // 解析出日志路径;
  533. TCHAR szlogpath[MAX_PATH] = { 0 };
  534. static TCHAR szModulePath[MAX_PATH] = { 0 };
  535. static TCHAR szFna[MAX_PATH] = { 0 };
  536. if (szModulePath[0] == _T('\0'))
  537. {
  538. TCHAR szDrive[MAX_PATH] = { 0 };
  539. TCHAR szDir[MAX_PATH] = { 0 };
  540. TCHAR szExt[MAX_PATH] = { 0 };
  541. ::GetModuleFileName(NULL, szModulePath, sizeof(szModulePath) / sizeof(TCHAR));
  542. _tsplitpath_s(szModulePath, szDrive, szDir, szFna, szExt);
  543. _tcscpy_s(szModulePath, szDrive);
  544. _tcscat_s(szModulePath, szDir);
  545. }
  546. _stprintf_s(szlogpath, _T("%s%s.txt"), szModulePath, szFna);
  547. // 打开或创建文件;
  548. FILE *fp = NULL;
  549. //if (_taccess(szlogpath, 0) != -1)
  550. #ifndef UNICODE
  551. if (_access(szlogpath, 0) != -1)
  552. #else
  553. if (_taccess(szlogpath, 0) != -1)
  554. #endif
  555. {// 存在;
  556. fp = _tfopen(szlogpath, _T("a+"));
  557. // 移动到末尾;
  558. fseek(fp, 0, SEEK_END);
  559. }
  560. else
  561. {// 不存在;
  562. fp = _tfopen(szlogpath, _T("w+"));
  563. }
  564. if (fp == NULL)
  565. return;
  566. // 格式化前设置语言区域;
  567. TCHAR* old_locale = _tcsdup(_tsetlocale(LC_CTYPE, NULL));
  568. _tsetlocale(LC_CTYPE, _T("chs"));//设定中文;
  569. // 格式化日志内容;
  570. va_list args = NULL;
  571. int len = 0;
  572. TCHAR *buffer = NULL;
  573. va_start(args, format);
  574. // _vscprintf doesn't count. terminating '\0'
  575. len = _vsctprintf(format, args) + 1;
  576. buffer = (TCHAR*)malloc(len * sizeof(TCHAR));
  577. _vstprintf_s(buffer, len, format, args);
  578. // 将日志内容输入到文件中;
  579. // 获取今年年份;
  580. __time64_t gmt = time(NULL);// 获取当前日历时间(1900-01-01开始的Unix时间戳);
  581. struct tm gmtm = { 0 };
  582. localtime_s(&gmtm, &gmt); // 时间戳转成本地时间;
  583. _ftprintf(fp, _T("%04d-%02d-%02d %02d:%02d:%02d %s\n"), gmtm.tm_year + 1990, gmtm.tm_mon + 1, gmtm.tm_mday, gmtm.tm_hour, gmtm.tm_min, gmtm.tm_sec, buffer);
  584. // 关闭文件,释放资源并设置回原语言区域;
  585. free(buffer);
  586. fclose(fp);
  587. _tsetlocale(LC_CTYPE, old_locale);
  588. free(old_locale);//还原区域设定;
  589. #endif
  590. }
  591. //---------------------------------------------------------------------
  592. // add by Jeff 2014.10.27
  593. // 函数:全局函数IsDirectoryLegitimate,多字节版本,非UNICODE
  594. // 描述:判断一个目录路径字符串,是否属于合法的、可创建的目录路径。
  595. // 参数:strDirectory 被验证的路径字符串;
  596. //
  597. // 返回:合法路径返回TRUE;
  598. //---------------------------------------------------------------------
  599. BOOL IsDirectoryLegitimate(const CString &strDirectory)
  600. {
  601. if (strDirectory.Find('/') != -1 ||
  602. strDirectory.Find('\\') != -1 ||
  603. strDirectory.Find(':') != -1 ||
  604. strDirectory.Find('*') != -1 ||
  605. strDirectory.Find('?') != -1 ||
  606. strDirectory.Find('\"') != -1 ||
  607. strDirectory.Find('>') != -1 ||
  608. strDirectory.Find('<') != -1 ||
  609. strDirectory.Find('|') != -1
  610. )
  611. return FALSE;
  612. return TRUE;
  613. }
  614. //--------------------------------------------------------------------------------
  615. // Jeff add 2014.06.23;
  616. // 函数:ErrorExit
  617. // 描述:
  618. // 参数:
  619. // lpszFunction:函数名;
  620. // dwError:错误码;
  621. //
  622. //--------------------------------------------------------------------------------
  623. void ShowSystemErrorInfo(CString strDescription, const DWORD &dwError)
  624. {
  625. #if 1
  626. LPVOID lpMsgBuf;
  627. BOOL fOk = FormatMessage(
  628. FORMAT_MESSAGE_ALLOCATE_BUFFER |
  629. FORMAT_MESSAGE_FROM_SYSTEM |
  630. FORMAT_MESSAGE_IGNORE_INSERTS,
  631. NULL,
  632. dwError,
  633. MAKELANGID(LANG_NEUTRAL, SUBLANG_DEFAULT),
  634. (LPTSTR)&lpMsgBuf,
  635. 0, NULL);
  636. if (!fOk)
  637. {
  638. // Is it a network-related error?
  639. HMODULE hDll = LoadLibraryEx(TEXT("netmsg.dll"), NULL, DONT_RESOLVE_DLL_REFERENCES);
  640. if (hDll != NULL)
  641. {
  642. FormatMessage(
  643. FORMAT_MESSAGE_FROM_HMODULE |
  644. FORMAT_MESSAGE_FROM_SYSTEM |
  645. FORMAT_MESSAGE_IGNORE_INSERTS,
  646. hDll,
  647. dwError,
  648. MAKELANGID(LANG_ENGLISH, SUBLANG_ENGLISH_US),
  649. (LPTSTR)&lpMsgBuf,
  650. 0,
  651. NULL);
  652. FreeLibrary(hDll);
  653. }
  654. }
  655. if (lpMsgBuf != NULL)
  656. {
  657. CString strDisplay;
  658. strDisplay.Format(_T("%s.错误码=%d,Windows描述:%s"), strDescription, dwError, (PCTSTR)LocalLock(lpMsgBuf));
  659. //WriteLog(strDisplay);
  660. LocalFree(lpMsgBuf);
  661. }
  662. else
  663. {
  664. //WriteLog(strDescription);
  665. }
  666. #else
  667. HLOCAL hlocal = NULL; // Buffer that gets the error message string
  668. // Get the error code's textual description
  669. BOOL fOk = FormatMessage(
  670. FORMAT_MESSAGE_FROM_SYSTEM |
  671. FORMAT_MESSAGE_ALLOCATE_BUFFER |
  672. FORMAT_MESSAGE_IGNORE_INSERTS,
  673. NULL,
  674. dwError,
  675. MAKELANGID(LANG_ENGLISH, SUBLANG_ENGLISH_US),
  676. (PTSTR)&hlocal,
  677. 0,
  678. NULL);
  679. if (!fOk)
  680. {
  681. // Is it a network-related error?
  682. HMODULE hDll = LoadLibraryEx(TEXT("netmsg.dll"), NULL, DONT_RESOLVE_DLL_REFERENCES);
  683. if (hDll != NULL)
  684. {
  685. FormatMessage(
  686. FORMAT_MESSAGE_FROM_HMODULE |
  687. FORMAT_MESSAGE_FROM_SYSTEM |
  688. FORMAT_MESSAGE_IGNORE_INSERTS,
  689. hDll,
  690. dwError,
  691. MAKELANGID(LANG_ENGLISH, SUBLANG_ENGLISH_US),
  692. (PTSTR)&hlocal,
  693. 0,
  694. NULL);
  695. FreeLibrary(hDll);
  696. }
  697. }
  698. if (hlocal != NULL)
  699. {
  700. CString strDisplay;
  701. strDisplay.Format("%s 失败错误码=%d,Windows系统描述:%s", strDescription, dwError, (PCTSTR)LocalLock(hlocal));
  702. //WriteLog(strDisplay);
  703. LocalFree(hlocal);
  704. }
  705. else
  706. {
  707. //WriteLog("Error number not found.");
  708. }
  709. #endif
  710. }
  711. // The system displays a dialog box with a custom message and a message to the user to close applications within the specified time-out interval (30 seconds).
  712. // After the time-out interval elapses, the system is restarted.
  713. //The application must enable the SE_SHUTDOWN_NAME privilege before calling InitiateSystemShutdown
  714. BOOL MySystemShutdown(LPTSTR lpMsg)
  715. {
  716. HANDLE hToken; // handle to process token
  717. TOKEN_PRIVILEGES tkp; // pointer to token structure
  718. BOOL fResult; // system shutdown flag
  719. // Get the current process token handle so we can get shutdown
  720. // privilege.
  721. if (!OpenProcessToken(GetCurrentProcess(),
  722. TOKEN_ADJUST_PRIVILEGES | TOKEN_QUERY, &hToken))
  723. return FALSE;
  724. // Get the LUID for shutdown privilege.
  725. LookupPrivilegeValue(NULL, SE_SHUTDOWN_NAME,
  726. &tkp.Privileges[0].Luid);
  727. tkp.PrivilegeCount = 1; // one privilege to set
  728. tkp.Privileges[0].Attributes = SE_PRIVILEGE_ENABLED;
  729. // Get shutdown privilege for this process.
  730. AdjustTokenPrivileges(hToken, FALSE, &tkp, 0,
  731. (PTOKEN_PRIVILEGES)NULL, 0);
  732. // Cannot test the return value of AdjustTokenPrivileges.
  733. if (GetLastError() != ERROR_SUCCESS)
  734. return FALSE;
  735. // Display the shutdown dialog box and start the countdown.
  736. fResult = InitiateSystemShutdown(
  737. NULL, // shut down local computer
  738. lpMsg, // message for user
  739. 30, // time-out period, in seconds
  740. FALSE, // ask user to close apps
  741. TRUE); // reboot after shutdown
  742. if (!fResult)
  743. return FALSE;
  744. // Disable shutdown privilege.
  745. tkp.Privileges[0].Attributes = 0;
  746. AdjustTokenPrivileges(hToken, FALSE, &tkp, 0,
  747. (PTOKEN_PRIVILEGES)NULL, 0);
  748. return TRUE;
  749. }
  750. // If the AbortSystemShutdown function is executed in the time-out period specified by InitiateSystemShutdown,
  751. // the system does not shut down. For example, if PreventSystemShutdown is called after MySystemShutdown,
  752. // the system closes the dialog box and does not restart the system.
  753. BOOL PreventSystemShutdown()
  754. {
  755. HANDLE hToken; // handle to process token
  756. TOKEN_PRIVILEGES tkp; // pointer to token structure
  757. // Get the current process token handle so we can get shutdown
  758. // privilege.
  759. if (!OpenProcessToken(GetCurrentProcess(),
  760. TOKEN_ADJUST_PRIVILEGES | TOKEN_QUERY, &hToken))
  761. return FALSE;
  762. // Get the LUID for shutdown privilege.
  763. LookupPrivilegeValue(NULL, SE_SHUTDOWN_NAME,
  764. &tkp.Privileges[0].Luid);
  765. tkp.PrivilegeCount = 1; // one privilege to set
  766. tkp.Privileges[0].Attributes = SE_PRIVILEGE_ENABLED;
  767. // Get shutdown privilege for this process.
  768. AdjustTokenPrivileges(hToken, FALSE, &tkp, 0,
  769. (PTOKEN_PRIVILEGES)NULL, 0);
  770. if (GetLastError() != ERROR_SUCCESS)
  771. return FALSE;
  772. // Prevent the system from shutting down.
  773. if (!AbortSystemShutdown(NULL))
  774. return FALSE;
  775. // Disable shutdown privilege.
  776. tkp.Privileges[0].Attributes = 0;
  777. AdjustTokenPrivileges(hToken, FALSE, &tkp, 0,
  778. (PTOKEN_PRIVILEGES)NULL, 0);
  779. return TRUE;
  780. }
  781. // Shutting down flushes file buffers to disk and brings the system to a condition in which it is safe to turn off the computer
  782. // The application must first enable the SE_SHUTDOWN_NAME privilege.
  783. // The final parameter in the call to ExitWindowsEx indicates that the system was shut down for a planning update of the operating system.
  784. BOOL MySystemShutdown()
  785. {
  786. HANDLE hToken;
  787. TOKEN_PRIVILEGES tkp;
  788. // Get a token for this process.
  789. if (!OpenProcessToken(GetCurrentProcess(),
  790. TOKEN_ADJUST_PRIVILEGES | TOKEN_QUERY, &hToken))
  791. return(FALSE);
  792. // Get the LUID for the shutdown privilege.
  793. LookupPrivilegeValue(NULL, SE_SHUTDOWN_NAME,
  794. &tkp.Privileges[0].Luid);
  795. tkp.PrivilegeCount = 1; // one privilege to set
  796. tkp.Privileges[0].Attributes = SE_PRIVILEGE_ENABLED;
  797. // Get the shutdown privilege for this process.
  798. AdjustTokenPrivileges(hToken, FALSE, &tkp, 0,
  799. (PTOKEN_PRIVILEGES)NULL, 0);
  800. if (GetLastError() != ERROR_SUCCESS)
  801. return FALSE;
  802. // Shut down the system and force all applications to close.
  803. if (!ExitWindowsEx(EWX_SHUTDOWN | EWX_FORCE,
  804. SHTDN_REASON_MAJOR_OPERATINGSYSTEM |
  805. SHTDN_REASON_MINOR_UPGRADE |
  806. SHTDN_REASON_FLAG_PLANNED))
  807. return FALSE;
  808. return TRUE;
  809. }
  810. HWND GetProcessMainWnd(const DWORD& dwTagetProcessId, LPCTSTR lpTagetWndName)
  811. {
  812. DWORD dwCurPorcessId = 0;
  813. HWND hTagetProcessWnd = NULL;
  814. TCHAR szWndName[MAX_PATH] = { 0 };
  815. TCHAR szClassName[MAX_PATH] = { 0 };
  816. // 取得第一个窗口句柄;
  817. for (HWND hCurWnd = ::GetTopWindow(NULL); hCurWnd != NULL; hCurWnd = ::GetNextWindow(hCurWnd, GW_HWNDNEXT)) {
  818. // 重置为0;
  819. dwCurPorcessId = 0;
  820. // 通过窗口句柄反查进程pid;
  821. DWORD dwThreadId = ::GetWindowThreadProcessId(hCurWnd, &dwCurPorcessId);
  822. if (dwThreadId != 0) {
  823. // 判断当前进程id是否和目标进程id相同;
  824. if (dwCurPorcessId == dwTagetProcessId) {
  825. if (lpTagetWndName == NULL) {
  826. hTagetProcessWnd = hCurWnd;
  827. break;
  828. }
  829. else {
  830. // 获取窗口名称;
  831. ::GetWindowText(hCurWnd, szWndName, sizeof(szWndName) / sizeof(TCHAR));
  832. // 获取窗口类名;
  833. ::GetClassName(hCurWnd, szClassName, sizeof(szClassName) / sizeof(TCHAR));
  834. #ifdef _DEBUG
  835. TCHAR szLogMsg[MAX_PATH] = { 0 };
  836. _stprintf_s(szLogMsg, _T("类名:%s, 窗口名:%s,窗口地址:%p \n"), szClassName, szWndName, hCurWnd);
  837. OutputDebugString(szLogMsg);
  838. #endif
  839. if (_tcsstr(szWndName, lpTagetWndName) != NULL) {
  840. hTagetProcessWnd = hCurWnd;
  841. break;
  842. }
  843. }
  844. }
  845. }
  846. }
  847. // 当前窗口有可能不是进程父窗口;
  848. HWND hParentWnd = hTagetProcessWnd;
  849. while (hParentWnd) {
  850. hParentWnd = ::GetParent(hTagetProcessWnd);
  851. if (hParentWnd == NULL)
  852. break;
  853. hTagetProcessWnd = hParentWnd;
  854. }
  855. return hTagetProcessWnd;
  856. }
  857. BOOL CALLBACK EnumChildWindowCallBack(HWND hWnd, LPARAM lParam)
  858. {
  859. DWORD dwPid = 0;
  860. LPWNDDATA lpWndData = (LPWNDDATA)lParam;
  861. GetWindowThreadProcessId(hWnd, &dwPid); // 获得找到窗口所属的进程
  862. if(dwPid == lpWndData->dwPid) // 判断是否是目标进程的窗口
  863. {
  864. WNDINFO wndInfo;
  865. wndInfo.hWnd=hWnd;
  866. SendMessage(hWnd, WM_GETTEXT, MAX_PATH, (LPARAM)wndInfo.szWndTitle);
  867. GetClassName(hWnd, wndInfo.szClassName, MAX_PATH);
  868. wndInfo.dwCtrlId = ::GetDlgCtrlID(hWnd);
  869. lpWndData->AddWnd(wndInfo);
  870. // 输出窗口信息
  871. TRACE4("A-0x%08X, %ld, %s, %s\n", hWnd, wndInfo.dwCtrlId, wndInfo.szClassName, wndInfo.szWndTitle);
  872. // 此处如果再递归,会导致重复查找2次子窗口;
  873. //EnumChildWindows(hWnd, EnumChildWindowCallBack, lParam); // 递归查找子窗口
  874. return TRUE;
  875. }
  876. return FALSE;
  877. }
  878. BOOL CALLBACK EnumWindowCallBack(HWND hWnd, LPARAM lParam)
  879. {
  880. DWORD dwPid = 0;
  881. LPWNDDATA lpWndData = (LPWNDDATA)lParam;
  882. GetWindowThreadProcessId(hWnd, &dwPid); // 获得找到窗口所属的进程
  883. if(dwPid == lpWndData->dwPid) // 判断是否是目标进程的窗口
  884. {
  885. WNDINFO wndInfo;
  886. wndInfo.hWnd=hWnd;
  887. SendMessage(hWnd, WM_GETTEXT, MAX_PATH, (LPARAM)wndInfo.szWndTitle);
  888. GetClassName(hWnd, wndInfo.szClassName, MAX_PATH);
  889. wndInfo.dwCtrlId = ::GetDlgCtrlID(hWnd);
  890. lpWndData->AddWnd(wndInfo);
  891. // 输出窗口信息
  892. TRACE4("A-0x%08X, %ld, %s, %s\n", hWnd, wndInfo.dwCtrlId, wndInfo.szClassName, wndInfo.szWndTitle);
  893. EnumChildWindows(hWnd, EnumChildWindowCallBack, lParam); // 继续查找子窗口
  894. }
  895. return TRUE;
  896. }
  897. BOOL EnumProcessAllWnd(LPWNDDATA lpWndData)
  898. {
  899. return EnumWindows(EnumWindowCallBack, (LPARAM)lpWndData);
  900. }
  901. BOOL GetWeChatPath()
  902. {
  903. // 通过注册表获取微信安装目录;
  904. HKEY hKey = NULL;
  905. if(ERROR_SUCCESS != RegOpenKey(HKEY_CURRENT_USER, _T("Software\\Tencent\\WeChat"), &hKey))
  906. {
  907. return FALSE;
  908. }
  909. DWORD Type = REG_SZ;
  910. DWORD cbData = MAX_PATH*sizeof(WCHAR);
  911. if(ERROR_SUCCESS != RegQueryValueEx(hKey, _T("InstallPath"), 0, &Type, (LPBYTE)g_szWeChatPath, &cbData))
  912. {
  913. RegCloseKey(hKey);
  914. return FALSE;
  915. }
  916. PathAppend(g_szWeChatPath, _T("WeChat.exe"));
  917. return TRUE;
  918. }
  919. BOOL OpenWeChat()
  920. {
  921. STARTUPINFO si;
  922. PROCESS_INFORMATION pi;
  923. ZeroMemory(&si, sizeof(si));
  924. si.cb = sizeof(si);
  925. ZeroMemory(&pi, sizeof(pi));
  926. si.dwFlags = STARTF_USESHOWWINDOW; // 指定wShowWindow成员有效
  927. si.wShowWindow = SW_HIDE; // 设置创建进程时,窗口不显示,
  928. // 为FALSE的话则不显示
  929. BOOL bRet = ::CreateProcess (
  930. g_szWeChatPath, // 不在此指定可执行文件的文件名
  931. NULL, // 命令行参数
  932. NULL, // 默认进程安全性
  933. NULL, // 默认线程安全性
  934. FALSE, // 指定当前进程内的句柄不可以被子进程继承
  935. NULL,
  936. NULL, // 使用本进程的环境变量
  937. NULL, // 使用本进程的驱动器和目录
  938. &si,
  939. &pi);
  940. if(bRet)
  941. {
  942. // 进程挂起后,仍能成功注入dll;
  943. // TCHAR szDllPath[MAX_PATH];
  944. // ZeroMemory(szDllPath,MAX_PATH);
  945. // _stprintf_s(szDllPath, _T("%shook.dll"), g_szModulePath);
  946. // for (int i = 0; i < 10; i++)
  947. // {
  948. // CInjection inject(pi.dwProcessId,szDllPath);
  949. // inject.InjectDynamicLibrary();
  950. // inject.EjectDynamicLibrary();
  951. // }
  952. // 既然我们不使用两个句柄,最好是立刻将它们关闭
  953. ::CloseHandle (pi.hThread);
  954. ::CloseHandle (pi.hProcess);
  955. // 当进程挂起时,是无法修改关闭微信句柄;
  956. //PatchWeChat();
  957. }
  958. return TRUE;
  959. }
  960. BOOL OpenWeChat2()
  961. {
  962. SHELLEXECUTEINFO sei;
  963. memset(&sei, 0, sizeof(SHELLEXECUTEINFO));
  964. sei.cbSize = sizeof(SHELLEXECUTEINFO);
  965. sei.hwnd = NULL;
  966. sei.lpVerb = _T("open");
  967. //sei.lpVerb = _T("runas");
  968. //sei.fMask = SEE_MASK_NOCLOSEPROCESS;
  969. sei.lpFile = g_szWeChatPath;
  970. sei.lpParameters = NULL;
  971. sei.lpDirectory = NULL;
  972. sei.nShow = SW_NORMAL;
  973. sei.hInstApp = NULL;
  974. if (!ShellExecuteEx(&sei))
  975. {
  976. DWORD dw = GetLastError();
  977. return FALSE;
  978. }
  979. //PatchWeChat();
  980. return TRUE;
  981. }
  982. BOOL OpenWeChatAndSuspended()
  983. {
  984. STARTUPINFO si;
  985. PROCESS_INFORMATION pi;
  986. ZeroMemory(&si, sizeof(si));
  987. si.cb = sizeof(si);
  988. ZeroMemory(&pi, sizeof(pi));
  989. si.dwFlags = STARTF_USESHOWWINDOW; // 指定wShowWindow成员有效
  990. si.wShowWindow = TRUE; // 此成员设为TRUE的话则显示新建进程的主窗口,
  991. // 为FALSE的话则不显示
  992. BOOL bRet = ::CreateProcess(
  993. g_szWeChatPath, // 不在此指定可执行文件的文件名
  994. NULL, // 命令行参数
  995. NULL, // 默认进程安全性
  996. NULL, // 默认线程安全性
  997. FALSE, // 指定当前进程内的句柄不可以被子进程继承
  998. CREATE_SUSPENDED, // 挂起进程;CREATE_SUSPENDED
  999. NULL, // 使用本进程的环境变量
  1000. NULL, // 使用本进程的驱动器和目录
  1001. &si,
  1002. &pi);
  1003. if (bRet)
  1004. {
  1005. // 进程挂起后,仍能成功注入dll;
  1006. // TCHAR szDllPath[MAX_PATH];
  1007. // ZeroMemory(szDllPath,MAX_PATH);
  1008. // _stprintf_s(szDllPath, _T("%shook.dll"), g_szModulePath);
  1009. // for (int i = 0; i < 10; i++)
  1010. // {
  1011. // CInjection inject(pi.dwProcessId,szDllPath);
  1012. // inject.InjectDynamicLibrary();
  1013. // inject.EjectDynamicLibrary();
  1014. // }
  1015. //不sleep就会出现读取不到的297错误
  1016. //Sleep(5000);
  1017. //获取线程上下文
  1018. CONTEXT ct = { 0 };
  1019. ct.ContextFlags = CONTEXT_CONTROL;
  1020. GetThreadContext(pi.hThread, &ct);
  1021. ::ResumeThread(pi.hThread);
  1022. // 既然我们不使用两个句柄,最好是立刻将它们关闭
  1023. ::CloseHandle(pi.hThread);
  1024. ::CloseHandle(pi.hProcess);
  1025. // 当进程挂起时,是无法修改关闭微信句柄;
  1026. //PatchWeChat();
  1027. }
  1028. return TRUE;
  1029. }