Detect if a process is using a VEH.

This commit is contained in:
BeneficialCode
2025-11-04 12:44:57 +08:00
parent f895c9a950
commit 1a9eb48947
7 changed files with 50 additions and 5 deletions
+2 -1
View File
@@ -61,7 +61,8 @@ void CMainFrame::InitProcessTable() {
{19,"Process Name",0},
{19,"Process ID",0},
{9,"Session",0},
{20,"User Name",0},
{32,"User Name",0},
{9,"Has VEH",0},
{20,"EPROCESS",0},
{12,"Priority",0},
{9,"Threads",0},
+4
View File
@@ -201,4 +201,8 @@ int ProcessInfoEx::GetImageIndex(CImageList images) const {
_image = images.AddIcon(hIcon);
}
return _image;
}
bool ProcessInfoEx::HasVEH(HANDLE hProcess) const {
return _process->HasVEH(hProcess);
}
+1
View File
@@ -37,6 +37,7 @@ public:
const std::wstring& GetCompanyName() const;
const std::wstring& GetDescription() const;
const std::wstring& GetVersion() const;
bool HasVEH(HANDLE hProcess) const;
int GetBitness() const;
const WinSys::Process* GetProcess() const {
+11 -3
View File
@@ -83,6 +83,14 @@ int CProcessTable::ParseTableEntry(CString& s, char& mask, int& select, std::sha
break;
case ProcessColumn::Eprocess:
s.Format(L"0x%p", info->EProcess);
break;
case ProcessColumn::HasVEH:
{
auto hProcess = DriverHelper::OpenProcess(info->Id, PROCESS_VM_READ | PROCESS_QUERY_INFORMATION);
s.Format(L"%s", px.HasVEH(hProcess) ? L"Yes" : L"No");
::CloseHandle(hProcess);
}
break;
default:
break;
@@ -275,7 +283,7 @@ LRESULT CProcessTable::OnProcessKill(WORD /*wNotifyCode*/, WORD /*wID*/, HWND /*
auto& p = m_Table.data.info[selected];
CString text;
text.Format(L"杀死进程:%u (%ws)?", p->Id, p->GetImageName().c_str());
text.Format(L"Kill Process£º%u (%ws)?", p->Id, p->GetImageName().c_str());
if (AtlMessageBox(*this, (PCWSTR)text, IDS_TITLE, MB_ICONWARNING | MB_OKCANCEL | MB_DEFBUTTON2) == IDCANCEL)
return 0;
@@ -294,7 +302,7 @@ LRESULT CProcessTable::OnProcessResume(WORD /*wNotifyCode*/, WORD /*wID*/, HWND
auto& p = m_Table.data.info[selected];
CString text;
text.Format(L"恢复进程: %u (%ws)?", p->Id, p->GetImageName().c_str());
text.Format(L"Resume Process: %u (%ws)?", p->Id, p->GetImageName().c_str());
if (AtlMessageBox(*this, (PCWSTR)text, IDS_TITLE, MB_ICONWARNING | MB_OKCANCEL | MB_DEFBUTTON2) == IDCANCEL)
return 0;
@@ -323,7 +331,7 @@ LRESULT CProcessTable::OnProcessSuspend(WORD /*wNotifyCode*/, WORD /*wID*/, HWND
auto& p = m_Table.data.info[selected];
CString text;
text.Format(L"挂起进程: %u (%ws)?", p->Id, p->GetImageName().c_str());
text.Format(L"Suspend Process: %u (%ws)?", p->Id, p->GetImageName().c_str());
if (AtlMessageBox(*this, (PCWSTR)text, IDS_TITLE, MB_ICONWARNING | MB_OKCANCEL | MB_DEFBUTTON2) == IDCANCEL)
return 0;
+1 -1
View File
@@ -97,7 +97,7 @@ public:
private:
enum class ProcessColumn {
Name,Id,Session,UserName,Eprocess,Priority,Threads,Handles,Attributes,CreateTime,Description,CompanyName,Version,ExePath,CmdLine
Name,Id,Session,UserName,HasVEH,Eprocess,Priority,Threads,Handles,Attributes,CreateTime,Description,CompanyName,Version,ExePath,CmdLine
};
//std::vector<std::shared_ptr<WinSys::ProcessInfo>> m_Processes;
mutable std::unordered_map<WinSys::ProcessInfo*, ProcessInfoEx> m_ProcessesEx;
+30
View File
@@ -416,4 +416,34 @@ SIZE_T Process::GetImageSize(HANDLE hProcess, DWORD_PTR imageBase) {
return info.RegionSize;
}
return 0;
}
bool Process::HasVEH(HANDLE hProcess) const {
ULONG len = 0;
PROCESS_BASIC_INFORMATION info;
DWORD status = ::NtQueryInformationProcess(hProcess, ProcessBasicInformation, &info, sizeof(info), &len);
if (!NT_SUCCESS(status))
return false;
if (info.PebBaseAddress == nullptr)
return false;
DWORD flags = 0;
DWORD* pCrossProcessFlags = nullptr;
PROCESS_EXTENDED_BASIC_INFORMATION extInfo;
if (!GetExtendedInfo(hProcess, &extInfo))
return false;
if (extInfo.IsWow64Process) {
pCrossProcessFlags = reinterpret_cast<DWORD*>((BYTE*)info.PebBaseAddress + 0x1000 + 0x28);
}
else {
pCrossProcessFlags = reinterpret_cast<DWORD*>((BYTE*)info.PebBaseAddress + 0x50);
}
if (!::ReadProcessMemory(hProcess, pCrossProcessFlags, &flags, sizeof(flags), nullptr))
return false;
if (flags & 0x00000004)
return true;
return false;
}
+1
View File
@@ -120,6 +120,7 @@ namespace WinSys {
static std::vector<std::pair<std::wstring, std::wstring>> GetEnvironment(HANDLE hProcess);
static DWORD_PTR GetImageBaseAddress(HANDLE hProcess);
static SIZE_T GetImageSize(HANDLE hProcess, DWORD_PTR imageBase);
bool HasVEH(HANDLE hProcess) const;
bool SetPriorityClass(ProcessPriorityClass pc);
uint32_t GetGdiObjectCount() const;