⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 ve-3f2.tmp

📁 驱动枚举进程,控制线程AFFINITY,通过修改EPROCESS,ETHREAD ,KTHREAD 等结构,修改AFFINITY
💻 TMP
字号:

#include "stdafx.h"
#include "Process_Functions.h"
#include "ProcessList.h"


extern PROCESSENTRY32 pe32;
extern HANDLE hProcessSnap;

int ListProcessThreads( DWORD dwOwnerPID, DWORD * dwThreadIdTable ) 
{
	int iThreadCount = 0; 
	HANDLE hThreadSnap = CreateToolhelp32Snapshot( TH32CS_SNAPTHREAD, 0UL );
	if( hThreadSnap == ( HANDLE ) -1 ) return 0;

	THREADENTRY32 te32;
	te32.dwSize = sizeof( THREADENTRY32 ); 

	if( ! Thread32First( hThreadSnap, &te32 ) )
	{
		CloseHandle( hThreadSnap );
		return 0;
	}

	do 
	{ 
		if( te32.th32OwnerProcessID == dwOwnerPID )
		{
			dwThreadIdTable[ iThreadCount++ ] = te32.th32ThreadID;
		}
	} while( Thread32Next( hThreadSnap, &te32 ) && iThreadCount < MAX_THREAD_CNT ); 

	CloseHandle( hThreadSnap );
	return iThreadCount;
}



BOOL GetProcessList( HWND hList)
{
	HANDLE hProcessSnap;

	// Take a snapshot of all processes in the system.
	hProcessSnap = CreateToolhelp32Snapshot( TH32CS_SNAPPROCESS, 0 );
	if( hProcessSnap == INVALID_HANDLE_VALUE )
	{
		printError( L"获取进程信息失败!CreateToolhelp32Snapshot" );
		return( FALSE );
	}

	// Set the size of the structure before using it.
	pe32.dwSize = sizeof( PROCESSENTRY32 );

	// Retrieve information about the first process,
	// and exit if unsuccessful
	if( !Process32First( hProcessSnap, &pe32 ) )
	{
		printError( L"Process32First" );  // Show cause of failure
		CloseHandle( hProcessSnap );     // Must clean up the snapshot object!
		return( FALSE );
	}

	// Now walk the snapshot of processes, and
	// display information about each process in turn
	int count=0;
	do
	{

		LVITEM LvItem;
		memset(&LvItem,0,sizeof(LvItem)); // Reset Item Struct
		Install_Process_To_Item( pe32, &LvItem, hList,count);


		// List the modules and threads associated with this process
		//ListProcessModules( pe32.th32ProcessID );
	//	ListProcessThreads( pe32.th32ProcessID );

		count++;
	} while( Process32Next( hProcessSnap, &pe32 ) );

	CloseHandle( hProcessSnap );
	return( TRUE );
}

//
//BOOL ListProcessModules( DWORD dwPID )
//{
//	HANDLE hModuleSnap = INVALID_HANDLE_VALUE;
//	MODULEENTRY32 me32;
//
//	// Take a snapshot of all modules in the specified process.
//	hModuleSnap = CreateToolhelp32Snapshot( TH32CS_SNAPMODULE, dwPID );
//	if( hModuleSnap == INVALID_HANDLE_VALUE )
//	{
//		printError( L"CreateToolhelp32Snapshot (of modules)" );
//		return( FALSE );
//	}
//
//	// Set the size of the structure before using it.
//	me32.dwSize = sizeof( MODULEENTRY32 );
//
//	// Retrieve information about the first module,
//	// and exit if unsuccessful
//	if( !Module32First( hModuleSnap, &me32 ) )
//	{
//		printError( L"Module32First" );  // Show cause of failure
//		CloseHandle( hModuleSnap );     // Must clean up the snapshot object!
//		return( FALSE );
//	}
//
//	// Now walk the module list of the process,
//	// and display information about each module
//	do
//	{
//		printf( "\n\n     MODULE NAME:     %s",             me32.szModule );
//		printf( "\n     executable     = %s",             me32.szExePath );
//		printf( "\n     process ID     = 0x%08X",         me32.th32ProcessID );
//		printf( "\n     ref count (g)  =     0x%04X",     me32.GlblcntUsage );
//		printf( "\n     ref count (p)  =     0x%04X",     me32.ProccntUsage );
//		printf( "\n     base address   = 0x%08X", (DWORD) me32.modBaseAddr );
//		printf( "\n     base size      = %d",             me32.modBaseSize );
//
//	} while( Module32Next( hModuleSnap, &me32 ) );
//
//	CloseHandle( hModuleSnap );
//	return( TRUE );
//}

BOOL ListProcessThreads( DWORD dwOwnerPID ) 
{ 
	HANDLE hThreadSnap = INVALID_HANDLE_VALUE; 
	THREADENTRY32 te32; 

	// Take a snapshot of all running threads  
	hThreadSnap = CreateToolhelp32Snapshot( TH32CS_SNAPTHREAD, 0 ); 
	if( hThreadSnap == INVALID_HANDLE_VALUE ) 
		return( FALSE ); 

	// Fill in the size of the structure before using it. 
	te32.dwSize = sizeof(THREADENTRY32 ); 

	// Retrieve information about the first thread,
	// and exit if unsuccessful
	if( !Thread32First( hThreadSnap, &te32 ) ) 
	{
		printError( L"Thread32First" );  // Show cause of failure
		CloseHandle( hThreadSnap );     // Must clean up the snapshot object!
		return( FALSE );
	}

	// Now walk the thread list of the system,
	// and display information about each thread
	// associated with the specified process

	ULONG result;
	do 
	{ 
	
		

			HANDLE hThread=OpenThread(THREAD_ALL_ACCESS,TRUE,te32.th32ThreadID);

			DWORD dwMask=0x0001;
			result=SetThreadAffinityMask(hThread,dwMask);
		

		

	} while( Thread32Next(hThreadSnap, &te32 ) ); 

	CloseHandle( hThreadSnap );
	return( TRUE );
}

void printError( TCHAR* msg )
{
	DWORD eNum;
	TCHAR sysMsg[256];
	TCHAR* p;

	eNum = GetLastError( );
	FormatMessage( FORMAT_MESSAGE_FROM_SYSTEM | FORMAT_MESSAGE_IGNORE_INSERTS,
		NULL, eNum,
		MAKELANGID(LANG_NEUTRAL, SUBLANG_DEFAULT), // Default language
		sysMsg, 256, NULL );

	// Trim the end of the line and terminate it with a null
	p = sysMsg;
	while( ( *p > 31 ) || ( *p == 9 ) )
		++p;
	do { *p-- = 0; } while( ( p >= sysMsg ) &&
		( ( *p == '.' ) || ( *p < 33 ) ) );

	// Display the message
	printf( "\n  WARNING: %s failed with error %d (%s)", msg, eNum, sysMsg );
}


#include "ioctls.h"
extern HANDLE hDevice;

BOOL GetProcess_From_Drv(HWND hList)
{



	BYTE *pProcessMemory=new BYTE(0x10000);
	DWORD BytesReturned;
	ULONG input,output;
	//BOOL result=DeviceIoControl(hDevice, IOCTL_GETPROCESS, &input, sizeof(ULONG), pProcessMemory, 0x10000,&BytesReturned, NULL);
	BOOL result=DeviceIoControl(hDevice, IOCTL_GETPROCESS, &input, sizeof(ULONG), &output,  sizeof(ULONG),&BytesReturned, NULL);


	DWORD dw = GetLastError(); 

	delete []pProcessMemory;


	return result;

}

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -