-
Notifications
You must be signed in to change notification settings - Fork 56
/
Copy pathHhUtil.cpp
89 lines (72 loc) · 2.65 KB
/
HhUtil.cpp
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
#include "HookHunter.hpp"
DWORD HhSearchForProcess(std::string_view process_name) noexcept
{
PROCESSENTRY32 pe32{};
pe32.dwSize = sizeof pe32;
hh::nt::ScopedHandle hSnapshot = CreateToolhelp32Snapshot(TH32CS_SNAPPROCESS, 0);
if (static_cast<HANDLE>(hSnapshot) == INVALID_HANDLE_VALUE)
return -1;
if (Process32First(hSnapshot, &pe32))
{
do
{
std::string_view this_proc = pe32.szExeFile;
if (this_proc.find(process_name) != this_proc.npos && pe32.th32ProcessID != GetCurrentProcessId())
return pe32.th32ProcessID;
} while (Process32Next(hSnapshot, &pe32));
}
return static_cast<DWORD>(-1);
}
bool HhFindModulesInProcess(HANDLE proc, std::vector<ModuleInformation_t>& modules)
{
HMODULE hMods[1024];
DWORD cbNeeded;
unsigned int i;
if (EnumProcessModules(proc, hMods, sizeof(hMods), &cbNeeded))
{
for (i = 0; i < (cbNeeded / sizeof(HMODULE)); i++)
{
TCHAR szModName[MAX_PATH];
// Get the full path to the module's file.
if (GetModuleFileNameEx(proc, hMods[i], szModName,
sizeof(szModName) / sizeof(TCHAR)))
{
MODULEINFO info{};
GetModuleInformation(proc, hMods[i], &info, sizeof info);
modules.emplace_back(szModName, (std::uint64_t)hMods[i], info.SizeOfImage);
}
}
}
return modules.size() > 0;
}
bool HhFindNamedModulesInProcess(HANDLE proc, const std::vector<std::string>& names, std::vector<ModuleInformation_t>& modules)
{
HMODULE hMods[1024];
DWORD cbNeeded;
unsigned int i;
if (EnumProcessModules(proc, hMods, sizeof(hMods), &cbNeeded))
{
for (i = 0; i < (cbNeeded / sizeof(HMODULE)); i++)
{
TCHAR szModName[MAX_PATH];
// Get the full path to the module's file.
if (GetModuleFileNameEx(proc, hMods[i], szModName,
sizeof(szModName) / sizeof(TCHAR)))
{
std::string sMod = szModName;
std::transform(sMod.begin(), sMod.end(), sMod.begin(), ::tolower);
for (auto const& wanted_name : names)
{
if (sMod.find(wanted_name) != sMod.npos)
{
MODULEINFO info{};
GetModuleInformation(proc, hMods[i], &info, sizeof info);
modules.emplace_back(szModName, (std::uint64_t)hMods[i], info.SizeOfImage);
break;
}
}
}
}
}
return modules.size() > 0;
}