CWxObject.cpp 9.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361
  1. #include "stdafx.h"
  2. #include "CWxObject.h"
  3. #include <math.h>
  4. #define WX_MAIN_WND_NAME _T("微信")
  5. #define WX_MAIN_WND_CLASS_NAME _T("WeChatMainWndForPC")
  6. #define WX_LOGIN_WND_NAME _T("登录")
  7. #define WX_LOGIN_WND_CLASS_NAME _T("WeChatLoginWndForPC")
  8. BOOL ASCII2UNICODE(IN LPCCH lpASCIIStr, OUT PWCH pUNICODEStr, IN CONST INT& nUNICODEStrLen)
  9. {
  10. if (lpASCIIStr == NULL)
  11. return FALSE;
  12. // 获取宽字符字节数;
  13. int cchWideChar = MultiByteToWideChar(CP_ACP, 0, lpASCIIStr, -1, NULL, 0);
  14. if (cchWideChar == 0 || cchWideChar >= nUNICODEStrLen)
  15. return FALSE;
  16. // 转换成宽字符串;
  17. memset(pUNICODEStr, 0, sizeof(WCHAR)*nUNICODEStrLen);
  18. int nWriteNum = MultiByteToWideChar(CP_ACP, 0, lpASCIIStr, -1, pUNICODEStr, cchWideChar);
  19. if (nWriteNum != cchWideChar)
  20. return FALSE;
  21. return TRUE;
  22. }
  23. CWxObject::CWxObject()
  24. :m_dwWxProcId(0)
  25. , m_hWxProcess(NULL)
  26. , m_hWxMainWnd(NULL)
  27. , m_hWxLoginWnd(NULL)
  28. , m_lpInjectData(NULL)
  29. , m_lpEjectData(NULL)
  30. , m_hInjectThread(NULL)
  31. , m_hEjectThread(NULL)
  32. , m_dwPathLen(0)
  33. , m_bAttached(FALSE)
  34. , m_hook(NULL)
  35. {
  36. }
  37. CWxObject::CWxObject(DWORD dwProcId, LPCTSTR lpDynamicLibraryPath)
  38. :m_dwWxProcId(dwProcId)
  39. , m_hWxProcess(NULL)
  40. , m_hWxMainWnd(NULL)
  41. , m_hWxLoginWnd(NULL)
  42. , m_lpInjectData(NULL)
  43. , m_lpEjectData(NULL)
  44. , m_hInjectThread(NULL)
  45. , m_hEjectThread(NULL)
  46. , m_dwPathLen(0)
  47. , m_bAttached(FALSE)
  48. , m_hook(NULL)
  49. {
  50. setInjectionObj(dwProcId, lpDynamicLibraryPath);
  51. }
  52. CWxObject::~CWxObject()
  53. {
  54. // 卸载dll;
  55. EjectDynamicLibrary();
  56. // 释放所有资源;
  57. if (m_hInjectThread)
  58. CloseHandle(m_hInjectThread);
  59. m_hInjectThread = NULL;
  60. if (m_hEjectThread)
  61. CloseHandle(m_hEjectThread);
  62. m_hEjectThread = NULL;
  63. if (m_lpInjectData)
  64. VirtualFreeEx(m_hWxProcess, m_lpInjectData, m_dwPathLen, MEM_RELEASE);
  65. m_lpInjectData = NULL;
  66. if (m_lpEjectData)
  67. VirtualFreeEx(m_hWxProcess, m_lpEjectData, m_dwPathLen, MEM_RELEASE);
  68. m_lpEjectData = NULL;
  69. if (m_hWxProcess)
  70. CloseHandle(m_hWxProcess);
  71. m_hWxProcess = NULL;
  72. // 退出主窗口;
  73. // 注:必须在主窗口销毁前分离;
  74. if (!m_bAttached)
  75. DetachWxWnd();
  76. if (m_hook)
  77. UnhookWindowsHookEx(m_hook);
  78. }
  79. void CWxObject::setInjectionObj(DWORD dwProcId, LPCTSTR lpDynamicLibraryPath)
  80. {
  81. ASSERT(dwProcId != 0);
  82. ASSERT(lpDynamicLibraryPath != NULL);
  83. m_dwWxProcId = dwProcId;
  84. memset(m_szDllPath, 0, sizeof(m_szDllPath));
  85. memset(m_wszDllPath, 0, sizeof(m_wszDllPath));
  86. #ifdef UNICODE
  87. _tcscpy_s(m_szDllPath, lpDynamicLibraryPath);
  88. #else
  89. _tcscpy_s(m_szDllPath, lpDynamicLibraryPath);
  90. ASCII2UNICODE(lpDynamicLibraryPath, m_wszDllPath, MAX_PATH);
  91. #endif
  92. //m_hWxProcess = OpenProcess(PROCESS_ALL_ACCESS, FALSE, m_dwWxProcId);
  93. m_hWxProcess = OpenProcess(PROCESS_CREATE_THREAD | PROCESS_VM_OPERATION | PROCESS_VM_WRITE, FALSE, m_dwWxProcId);
  94. if (m_hWxProcess == NULL)
  95. {
  96. WriteTextLog(_T("打开WeChat.exe进程失败"));
  97. }
  98. }
  99. BOOL CWxObject::InjectDynamicLibrary()
  100. {
  101. ASSERT(m_hWxProcess != NULL);
  102. m_dwPathLen = wcslen(m_wszDllPath) * sizeof(WCHAR) + 1;
  103. m_lpInjectData = VirtualAllocEx(m_hWxProcess, NULL, m_dwPathLen, MEM_COMMIT, PAGE_READWRITE);
  104. if (NULL == m_lpInjectData)
  105. {
  106. WriteTextLog(_T("创建WeChat.exe进程虚拟内存失败"));
  107. return FALSE;
  108. }
  109. if (WriteProcessMemory(m_hWxProcess, m_lpInjectData, m_wszDllPath, m_dwPathLen, NULL) == 0)
  110. {
  111. // 注意:MEM_RELEASE释放时第三参数一定要为0,请查看MSDN;
  112. VirtualFreeEx(m_hWxProcess, m_lpInjectData, 0, MEM_RELEASE);
  113. return FALSE;
  114. }
  115. HMODULE hk32 = GetModuleHandle(_T("kernel32.dll"));
  116. // 注意:微信使用的是W版本;
  117. LPVOID lpAddr = GetProcAddress(hk32, "LoadLibraryW");
  118. m_hInjectThread = CreateRemoteThread(m_hWxProcess, NULL, 0, (LPTHREAD_START_ROUTINE)lpAddr, m_lpInjectData, 0, NULL);
  119. if (NULL == m_hInjectThread)
  120. {
  121. // 注意:MEM_RELEASE释放时第三参数一定要为0,请查看MSDN;
  122. VirtualFreeEx(m_hWxProcess, m_lpInjectData, 0, MEM_RELEASE);
  123. return FALSE;
  124. }
  125. WaitForSingleObject(m_hInjectThread, INFINITE);
  126. if (m_hInjectThread)
  127. CloseHandle(m_hInjectThread);
  128. m_hInjectThread = NULL;
  129. /* 注入成功后,不能释放内存否则微信会挂;
  130. if (m_lpInjectData != NULL)
  131. VirtualFreeEx(m_hWxProcess, m_lpInjectData, 0, MEM_RELEASE);
  132. */
  133. return TRUE;
  134. }
  135. BOOL CWxObject::EjectDynamicLibrary()
  136. {
  137. if (m_hWxProcess == NULL)
  138. return TRUE;
  139. // 获取模块句柄;
  140. HANDLE hModule = FindModuleEx(m_szDllPath, m_dwWxProcId);
  141. if (hModule == NULL)
  142. {
  143. WriteTextLog(_T("获取WeChat.exe进程模块hook.dll失败"));
  144. return FALSE;
  145. }
  146. LPVOID lpAddr = GetProcAddress(GetModuleHandle(_T("kernel32.dll")), "FreeLibraryAndExitThread");//FreeLibraryAndExitThread//FreeLibrary
  147. if (lpAddr == NULL)
  148. {
  149. WriteTextLog(_T("获取kernel32.dll中的FreeLibraryAndExitThread失败"));
  150. return FALSE;
  151. }
  152. m_hEjectThread = CreateRemoteThread(m_hWxProcess, NULL, 0, (LPTHREAD_START_ROUTINE)lpAddr, hModule, 0, NULL);
  153. if (m_hEjectThread == NULL)
  154. {
  155. WriteTextLog(_T("创建WeChat.exe远程线程(FreeLibraryAndExitThread)失败"));
  156. return FALSE;
  157. }
  158. WaitForSingleObject(m_hEjectThread, INFINITE);
  159. if (m_hEjectThread)
  160. CloseHandle(m_hEjectThread);
  161. m_hEjectThread = NULL;
  162. return TRUE;
  163. }
  164. BOOL CWxObject::FindWxMainWnd()
  165. {
  166. WNDINFO wnd;
  167. wnd.hWxWnd = NULL;
  168. wnd.dwWxProcId = m_dwWxProcId;
  169. _stprintf_s(wnd.szWndName, WX_MAIN_WND_NAME);
  170. _stprintf_s(wnd.szClassName, WX_MAIN_WND_CLASS_NAME);
  171. if (::EnumWindows(&EnumWindowsProc, (LPARAM)&wnd) == FALSE)
  172. {
  173. m_hWxMainWnd = wnd.hWxWnd;
  174. m_rcWxWnd = wnd.rcWnd;
  175. return TRUE;
  176. }
  177. return FALSE;
  178. }
  179. BOOL CWxObject::FindWxLoginWnd()
  180. {
  181. WNDINFO wnd;
  182. wnd.hWxWnd = NULL;
  183. wnd.dwWxProcId = m_dwWxProcId;
  184. _stprintf_s(wnd.szWndName, WX_LOGIN_WND_NAME);
  185. _stprintf_s(wnd.szClassName, WX_LOGIN_WND_CLASS_NAME);
  186. if (::EnumWindows(&EnumWindowsProc, (LPARAM)&wnd) == FALSE)
  187. {
  188. m_hWxLoginWnd = wnd.hWxWnd;
  189. m_rcWxWnd = wnd.rcWnd;
  190. return TRUE;
  191. }
  192. return FALSE;
  193. }
  194. BOOL CWxObject::Attach2MainWnd(CWnd *pMainWnd, BOOL bLoginWnd )
  195. {
  196. HWND hWxWnd = bLoginWnd ? m_hWxLoginWnd : m_hWxMainWnd;
  197. if (hWxWnd != NULL)
  198. {
  199. // 获取微信窗口的样式;
  200. DWORD dwStyle = ::GetWindowLong(hWxWnd, GWL_STYLE);
  201. // WS_CLIPSIBLINGS告诉父窗口不要绘制子窗口出现的区域;
  202. //dwStyle |= WS_CLIPSIBLINGS;
  203. // 如果窗口隐藏的,显示出来;
  204. dwStyle |= WS_VISIBLE;
  205. // 重新设置窗口样式 ;
  206. ::SetWindowLong(hWxWnd, GWL_STYLE, dwStyle);
  207. CRect rect;
  208. pMainWnd->GetWindowRect(&rect);
  209. // 设置父窗口;
  210. ::SetParent(hWxWnd, pMainWnd->m_hWnd);//set parent of ms paint to our dialog.
  211. // 擦除背景;
  212. //SetWindowLong(hWxWnd, GWL_STYLE, WS_VISIBLE);//eraze title of ms paint window.
  213. //Positioning ms paint.
  214. // 将屏幕坐标转在窗口坐标;
  215. pMainWnd->ScreenToClient(&rect);
  216. // 居中显示;
  217. CRect rcDisplay = rect;
  218. if (0)
  219. {// 居中显示;
  220. if (m_rcWxWnd.Width() >= rect.Width())
  221. {
  222. rcDisplay.left = 0;
  223. rcDisplay.right = rect.right;
  224. }
  225. else
  226. {
  227. rcDisplay.left = (rect.Width() - m_rcWxWnd.Width()) / 2;
  228. rcDisplay.right = rcDisplay.left + m_rcWxWnd.Width();
  229. }
  230. if (m_rcWxWnd.Height() >= rect.Height())
  231. {
  232. rcDisplay.top = 0;
  233. rcDisplay.bottom = rect.bottom;
  234. }
  235. else
  236. {
  237. rcDisplay.top = (rect.Height() - m_rcWxWnd.Height()) / 2;
  238. rcDisplay.bottom = rcDisplay.top + m_rcWxWnd.Height();
  239. }
  240. // 注意:MoveWindow/SetWindowPos使用的是父窗口的坐标,如果父窗口为NULL,则使用的是屏幕坐标;
  241. ::MoveWindow(hWxWnd, rcDisplay.left, rcDisplay.top, rcDisplay.Width(), rcDisplay.Height(), true);
  242. //::SetWindowPos(hWxWnd, NULL, rcDisplay.left, rcDisplay.top, rcDisplay.Width(), rcDisplay.Height(), WM_WINDOWPOSCHANGING|SWP_SHOWWINDOW | SWP_HIDEWINDOW);
  243. if (!bLoginWnd)
  244. ::PostMessage(hWxWnd, WM_SYSCOMMAND, SC_MAXIMIZE, NULL);
  245. }
  246. else
  247. {//最大化显示并固定;
  248. // 注意:MoveWindow/SetWindowPos使用的是父窗口的坐标,如果父窗口为NULL,则使用的是屏幕坐标;
  249. ::MoveWindow(hWxWnd, rcDisplay.left, rcDisplay.top, rcDisplay.Width(), rcDisplay.Height(), true);
  250. if (!bLoginWnd)
  251. ::PostMessage(hWxWnd, WM_SYSCOMMAND, SC_MAXIMIZE, NULL);
  252. //::SetWindowPos(hWxWnd, NULL, rcDisplay.left, rcDisplay.top, rcDisplay.Width(), rcDisplay.Height(), WM_MOVE| WM_SIZE| WM_WINDOWPOSCHANGING| WM_NCCALCSIZE | SWP_SHOWWINDOW);
  253. }
  254. //窗口重绘,(因创建exe时,设置为SW_HIDE,导致exe窗口会被父窗口覆盖一部分)
  255. pMainWnd->Invalidate();
  256. ::UpdateWindow(hWxWnd);
  257. ::ShowWindow(hWxWnd, SW_SHOW);
  258. m_bAttached = TRUE;
  259. }
  260. return 0;
  261. }
  262. BOOL CWxObject::DetachWxWnd()
  263. {
  264. if (m_bAttached)
  265. {
  266. //if (m_hWxMainWnd && GetParent(m_hWxMainWnd))
  267. if (m_hWxMainWnd ) // 使用GetParent可能返回NULL
  268. ::SetParent(m_hWxMainWnd, NULL);
  269. if (m_hWxLoginWnd )
  270. ::SetParent(m_hWxLoginWnd, NULL);
  271. m_bAttached = FALSE;
  272. #ifdef _DEBUG
  273. WriteTextLog(_T("DetachWxWnd"));
  274. #endif
  275. }
  276. return 0;
  277. }
  278. BOOL CWxObject::SetHook()
  279. {
  280. if (m_hook == NULL)
  281. m_hook = SetWindowsHookEx(WH_CBT, HookProc, NULL, ::GetCurrentThreadId());
  282. return 0;
  283. }
  284. BOOL CWxObject::EnumWindowsProc(HWND hwnd, LPARAM lParam)
  285. {
  286. DWORD dwProcId = 0, dwThreadId;
  287. TCHAR szWndName[MAX_PATH] = { 0 };
  288. TCHAR szClassName[MAX_PATH] = { 0 };
  289. WNDINFO* pWndInfo = (WNDINFO*)lParam;
  290. dwThreadId = GetWindowThreadProcessId(hwnd, &dwProcId);
  291. if(dwProcId == pWndInfo->dwWxProcId)
  292. {
  293. pWndInfo->hWxWnd = hwnd;
  294. pWndInfo->dwThreadId = dwThreadId;
  295. ::GetWindowText(hwnd, szWndName, MAX_PATH);
  296. ::GetClassName(hwnd, szClassName, MAX_PATH);
  297. #ifdef _DEBUG
  298. WriteTextLog(_T("窗口名称:%s, 窗口类名:%s, 线程ID:%d,句柄:%p"), szWndName, szClassName, dwThreadId, hwnd);
  299. #endif
  300. if (_tcscmp(szWndName, pWndInfo->szWndName) == 0 && _tcscmp(szClassName, pWndInfo->szClassName) == 0)
  301. {
  302. ::GetWindowRect(hwnd, &pWndInfo->rcWnd);
  303. return FALSE;
  304. }
  305. }
  306. return TRUE;
  307. }
  308. LRESULT CWxObject::HookProc(int nCode, WPARAM wParam, LPARAM lParam)
  309. {
  310. return LRESULT();
  311. }