stdafx.cpp 4.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212
  1. // stdafx.cpp : 只包括标准包含文件的源文件
  2. // WeChats.pch 将作为预编译头
  3. // stdafx.obj 将包含预编译类型信息
  4. #include "stdafx.h"
  5. HANDLE DuplicateHandleEx(DWORD pid, HANDLE h, DWORD flags)
  6. {
  7. HANDLE hHandle = NULL;
  8. HANDLE hProc = OpenProcess(PROCESS_ALL_ACCESS, FALSE, pid);
  9. if(hProc)
  10. {
  11. if(!DuplicateHandle(hProc,(HANDLE)h, GetCurrentProcess(),&hHandle, 0, FALSE, flags))
  12. {
  13. hHandle = NULL;
  14. }
  15. }
  16. CloseHandle(hProc);
  17. return hHandle;
  18. }
  19. // 获取指定名称的进程ID数组;
  20. int GetProcIds(LPTSTR Name, DWORD* Pids)
  21. {
  22. PROCESSENTRY32 pe32 = {sizeof(pe32)};
  23. int num = 0;
  24. HANDLE hSnap = CreateToolhelp32Snapshot(TH32CS_SNAPPROCESS, 0);
  25. if(hSnap)
  26. {
  27. if(Process32First(hSnap, &pe32))
  28. {
  29. do {
  30. if(!_tcsicmp(Name, pe32.szExeFile))
  31. {
  32. if(Pids)
  33. {
  34. Pids[num++] = pe32.th32ProcessID;
  35. }
  36. }
  37. } while(Process32Next(hSnap, &pe32));
  38. }
  39. CloseHandle(hSnap);
  40. }
  41. return num;
  42. }
  43. BOOL IsTargetPid(DWORD Pid, DWORD* Pids, int num)
  44. {
  45. for(int i=0; i<num; i++)
  46. {
  47. if(Pid == Pids[i])
  48. {
  49. return TRUE;
  50. }
  51. }
  52. return FALSE;
  53. }
  54. int PatchWeChat()
  55. {
  56. DWORD dwSize = 0;
  57. POBJECT_NAME_INFORMATION pNameInfo;
  58. POBJECT_NAME_INFORMATION pNameType;
  59. PVOID pbuffer = NULL;
  60. NTSTATUS Status;
  61. int nIndex = 0;
  62. DWORD dwFlags = 0;
  63. char szType[128] = {0};
  64. char szName[512] = {0};
  65. DWORD Pids[100] = {0};
  66. DWORD Num = GetProcIds(_T("WeChat.exe"), Pids);
  67. if(Num == 0)
  68. {
  69. return 0;
  70. }
  71. if(!ZwQuerySystemInformation)
  72. {
  73. goto Exit0;
  74. }
  75. pbuffer = VirtualAlloc(NULL, 0x1000, MEM_COMMIT, PAGE_READWRITE);
  76. if(!pbuffer)
  77. {
  78. goto Exit0;
  79. }
  80. Status = ZwQuerySystemInformation(SystemHandleInformation, pbuffer, 0x1000, &dwSize);
  81. if(!NT_SUCCESS(Status))
  82. {
  83. if (STATUS_INFO_LENGTH_MISMATCH != Status)
  84. {
  85. goto Exit0;
  86. }
  87. else
  88. {
  89. // 这里大家可以保证程序的正确性使用循环分配稍好
  90. if (NULL != pbuffer)
  91. {
  92. VirtualFree(pbuffer, 0, MEM_RELEASE);
  93. }
  94. if (dwSize*2 > 0x4000000) // MAXSIZE
  95. {
  96. goto Exit0;
  97. }
  98. pbuffer = VirtualAlloc(NULL, dwSize*2, MEM_COMMIT, PAGE_READWRITE);
  99. if(!pbuffer)
  100. {
  101. goto Exit0;
  102. }
  103. Status = ZwQuerySystemInformation(SystemHandleInformation, pbuffer, dwSize*2, NULL);
  104. if(!NT_SUCCESS(Status))
  105. {
  106. goto Exit0;
  107. }
  108. }
  109. }
  110. PSYSTEM_HANDLE_INFORMATION1 pHandleInfo = (PSYSTEM_HANDLE_INFORMATION1)pbuffer;
  111. for(nIndex = 0; nIndex < pHandleInfo->NumberOfHandles; nIndex++)
  112. {
  113. if(IsTargetPid(pHandleInfo->Handles[nIndex].UniqueProcessId, Pids, Num))
  114. {
  115. // 从微信进程中,复句柄到本进程中;
  116. HANDLE hHandle = DuplicateHandleEx(pHandleInfo->Handles[nIndex].UniqueProcessId,
  117. (HANDLE)pHandleInfo->Handles[nIndex].HandleValue,
  118. DUPLICATE_SAME_ACCESS
  119. );
  120. if(hHandle == NULL) continue;
  121. Status = NtQueryObject(hHandle, ObjectNameInformation, szName, 512, &dwFlags);
  122. if (!NT_SUCCESS(Status))
  123. {
  124. CloseHandle(hHandle);
  125. continue;
  126. }
  127. Status = NtQueryObject(hHandle, ObjectTypeInformation, szType, 128, &dwFlags);
  128. if (!NT_SUCCESS(Status))
  129. {
  130. CloseHandle(hHandle);
  131. continue;
  132. }
  133. pNameInfo = (POBJECT_NAME_INFORMATION)szName;
  134. pNameType = (POBJECT_NAME_INFORMATION)szType;
  135. WCHAR TypName[1024] = {0};
  136. WCHAR Name[1024] = {0};
  137. wcsncpy(TypName, (WCHAR*)pNameType->Name.Buffer, pNameType->Name.Length/2);
  138. wcsncpy(Name, (WCHAR*)pNameInfo->Name.Buffer, pNameInfo->Name.Length/2);
  139. // 匹配是否为需要关闭的句柄名称
  140. if (0 == wcscmp(TypName, L"Mutant"))
  141. {
  142. //WeChat_aj5r8jpxt_Instance_Identity_Mutex_Name
  143. //if (wcsstr(Name, L"_WeChat_App_Instance_Identity_Mutex_Name"))
  144. if (wcsstr(Name, L"_WeChat_") &&
  145. wcsstr(Name, L"_Instance_Identity_Mutex_Name"))
  146. {
  147. CloseHandle(hHandle);
  148. hHandle = DuplicateHandleEx(pHandleInfo->Handles[nIndex].UniqueProcessId,
  149. (HANDLE)pHandleInfo->Handles[nIndex].HandleValue,
  150. DUPLICATE_CLOSE_SOURCE
  151. );
  152. if(hHandle)
  153. {
  154. printf("+ Patch wechat success!\n");
  155. CloseHandle(hHandle);
  156. }
  157. else
  158. {
  159. printf("- Patch error: %d\n", GetLastError());
  160. }
  161. goto Exit0;
  162. }
  163. }
  164. CloseHandle(hHandle);
  165. }
  166. }
  167. Exit0:
  168. if (NULL != pbuffer)
  169. {
  170. VirtualFree(pbuffer, 0, MEM_RELEASE);
  171. }
  172. return 0;
  173. }