C# Hook About - WH_CALLWNDPROC

1using System;
  2using System.Collections.Generic;
  3using System.ComponentModel;
  4using System.Data;
  5using System.Drawing;
  6using System.Text;
  7using System.Windows.Forms;
  8using System.Runtime.InteropServices;
  9
 10 namespace HookTest
 11{
 12    public partial class Form1 : Form
 13    {
 14        #region 消息定义(WinUser.h中定义)
 15        private const int WM_PAINT = 0x000F;
 16        private const int WM_CLOSE = 0x0010;
 17        private const int WM_QUIT = 0x0012;
 18        private const int WM_DESTROY = 0x0002;
 19        #endregion
 20
 21        private MyHook callProcHook = new MyHook(HookType.WH_CALLWNDPROC);
 22        private MyHook keyHook = new MyHook(HookType.WH_KEYBOARD);
 23
 24        public Form1()
 25        {
 26            InitializeComponent();
 27        }
 28
 29        private void Form1_Load(object sender, EventArgs e)
 30        {
 31            keyHook.HookInvoked += new HookEventHandler(keyHook_HookInvoked);
 32            keyHook.Install();
 33
 34            callProcHook.HookInvoked += new HookEventHandler(callProcHook_HookInvoked);
 35            callProcHook.Install();
 36        }
 37
 38        private void keyHook_HookInvoked(object sender, HookEventArgs e)
 39        {
 40            if (e.key == Keys.F4 && e.bAltKey) //Alt + F4
 41            {
 42                this.WindowState = FormWindowState.Minimized;
 43            }
 44        }
 45
 46        private void callProcHook_HookInvoked(object sender, HookEventArgs e)
 47        {
 48            unsafe
 49            {
 50                CWPSTRUCT* message = (CWPSTRUCT*)e.lParam;
 51                if (message != null)
 52                {
 53                    if (message->message == WM_CLOSE)
 54                    {
 55                        (sender as MyHook).CallNextProc = false;
 56                        MessageBox.Show("程序即将关闭!");
 57                    }
 58                }
 59            }
 60        }
 61
 62    }
 63
 64    #region 消息结构体(参照WinUser.h中定义)
 65    public struct CWPSTRUCT
 66    {
 67        public IntPtr lparam;
 68        public IntPtr wparam;
 69        public int message;
 70        public IntPtr hwnd;
 71    }
 72    #endregion
 73
 74    #region 钩子类型的枚举
 75    public enum HookType : int
 76    {
 77        WH_JOURNALRECORD = 0,
 78        WH_JOURNALPLAYBACK = 1,
 79        WH_KEYBOARD = 2,
 80        WH_GETMESSAGE = 3,
 81        WH_CALLWNDPROC = 4,
 82        WH_CBT = 5,
 83        WH_SYSMSGFILTER = 6,
 84        WH_MOUSE = 7,
 85        WH_HARDWARE = 8,
 86        WH_DEBUG = 9,
 87        WH_SHELL = 10,
 88        WH_FOREGROUNDIDLE = 11,
 89        WH_CALLWNDPROCRET = 12,
 90        WH_KEYBOARD_LL = 13,
 91        WH_MOUSE_LL = 14
 92    }
 93    #endregion
 94
 95    #region 虚键值的定义(参照WinUser.h中定义)
 96    public enum VirtualKeys
 97    {
 98        VK_SHIFT = 0x10,
 99        VK_CONTROL = 0x11,
100        VK_MENU = 0x12,    //ALT
101        VK_PAUSE = 0x13,
102        VK_CAPITAL = 0x14
103    }
104    #endregion
105
106    #region 钩子委托
107    public delegate int HookProc(int code, IntPtr wParam, IntPtr lParam);
108    public delegate void HookEventHandler(object sender, HookEventArgs e);
109    #endregion
110
111    #region 钩子事件参数
112    public class HookEventArgs : EventArgs
113    {
114        public int HookCode;
115        public IntPtr wParam;
116        public IntPtr lParam;
117        public Keys key;
118        public bool bAltKey;
119        public bool bCtrlKey;
120    }
121    #endregion
122
123    #region 钩子类
124    public class MyHook
125    {
126        #region 调用Windows API
127        [DllImport("user32.dll")]
128        static extern IntPtr SetWindowsHookEx(HookType hook, HookProc callback, IntPtr hMod, uint dwThreadId);
129
130        [DllImport("user32.dll")]
131        static extern bool UnhookWindowsHookEx(IntPtr hhk);
132
133        [DllImport("user32.dll")]
134        static extern int CallNextHookEx(IntPtr hhk, int nCode, IntPtr wParam, IntPtr lParam);
135
136        [DllImport("user32.dll")]
137        static extern short GetKeyState(VirtualKeys nVirtKey);
138        #endregion
139
140        #region 局部变量
141        private IntPtr m_hook;
142        private HookType m_hooktype;
143        private HookProc m_hookproc;
144
145        private bool _bCallNext;
146
147        public bool CallNextProc
148        {
149            get { return _bCallNext; }
150            set { _bCallNext = value; }
151        }
152    
153        #endregion
154
155        public event HookEventHandler HookInvoked;
156
157        public void Install()
158        {
159            m_hook = SetWindowsHookEx(m_hooktype, m_hookproc, IntPtr.Zero, (uint)AppDomain.GetCurrentThreadId());
160        }
161
162        public void Uninstall()
163        {
164            if (m_hook != IntPtr.Zero)
165            {
166                UnhookWindowsHookEx(m_hook);
167            }
168        }
169
170        public MyHook(HookType HookType)
171        {
172            m_hooktype = HookType;
173            if (m_hooktype == HookType.WH_KEYBOARD)
174            {
175                m_hookproc = new HookProc(KeyHookProcedure);
176            }
177            else if (m_hooktype == HookType.WH_CALLWNDPROC)
178            {
179                m_hookproc = new HookProc(CallProcHookProcedure);
180            }
181        }
182
183        protected int KeyHookProcedure(int code, IntPtr wParam, IntPtr lParam)
184        {
185            if (code != 0)
186            {
187                return CallNextHookEx(m_hook, code, wParam, lParam);
188            }
189
190            if (HookInvoked != null)
191            {
192                Keys key = (Keys)wParam.ToInt32();
193                HookEventArgs eventArgs = new HookEventArgs();
194                eventArgs.key = key;
195                eventArgs.lParam = lParam;
196                eventArgs.wParam = wParam;
197                eventArgs.HookCode = code;
198                eventArgs.bAltKey = GetKeyState(VirtualKeys.VK_MENU) <= -127;
199                eventArgs.bCtrlKey = GetKeyState(VirtualKeys.VK_CONTROL) <= -127;
200                HookInvoked(this, eventArgs);
201            }
202
203            return CallNextHookEx(m_hook, code, wParam, lParam);
204        }
205
206        protected int CallProcHookProcedure(int code, IntPtr wParam, IntPtr lParam)
207        {
208            try
209            {
210                CallNextProc = true;
211                if (HookInvoked != null)
212                {
213                    HookEventArgs eventArgs = new HookEventArgs();
214                    eventArgs.lParam = lParam;
215                    eventArgs.wParam = wParam;
216                    eventArgs.HookCode = code;
217                    HookInvoked(this, eventArgs);
218                }
219
220                if (CallNextProc)
221                {
222                    return CallNextHookEx(m_hook, code, wParam, lParam);
223                }
224                else
225                {
226                    //return 1;
227                    return CallNextHookEx(IntPtr.Zero, code, wParam, lParam);
228                }
229            }
230            catch (Exception ex)
231            {
232                MessageBox.Show(ex.Message);
233                return 0;
234            }
235        }
236    }
237    #endregion
238}

//Gather code from internet as a memo.

时间: 2025-01-09 21:59:24

C# Hook About - WH_CALLWNDPROC的相关文章

vc++HOOK详细讲解

消息钩子函数入门 Windows 系统是建立在事件驱动的机制上的,说穿了就是整个系统都是通过消息的传递来实现的.而钩子是 Windows 系统中非常重要的系统接口,用它可以截获并处理送给其他应用程序的消息,来完成普通应用程序难以实现的功能.钩子可以监视系统或进程中的各种事件消息,截获发往目标窗口的消息并进行处理.这样,我们就可以在系统中安装自定义的钩子,监视系统中特定事件的发生,完成特定的功能,比如截获键盘.鼠标的输入,屏幕取词,日志监视等等.可见,利用钩子可以实现许多特殊而有用的功能.因此,对

VB6的HOOK技术

代码背景,自身程序的窗口上有一个TextBox,Hook住WH_CALLWNDPROC用来截获EN_CHNAGE即文本变更的消息. *这个其实用SetWindowLong和CallWindowProc也能做到,原理是一样的就是预处理窗口消息. Form1.frm Private Sub Command1_Click() hHook = SetWindowsHookEx(WH_CALLWNDPROC, AddressOf CallBackHookProc, App.hInstance, App.T

Using Hooks

The following code examples demonstrate how to perform the following tasks associated with hooks: Installing and Releasing Hook Procedures Monitoring System Events Installing and Releasing Hook Procedures You can install a hook procedure by calling t

钩子教程 - 原理(二)

原文地址:http://www.zdexe.com/program/201004/576.html 比较专业的对钩子的技术性理解 钩子(Hook),是Windows消息处理机制的一个平台,应用程序可以在上面设置子程以监视指定窗口的某种消息,而且所监视的窗口可以是其他进程所创 建的.当消息到达后,在目标窗口处理函数之前处理它.钩子机制允许应用程序截获处理window消息或特定事件. Windows系统是建立在事件驱动的机制上的,说穿了就是整个系统都是通过消息的传递来实现的.而钩子是Windows系

如何创建DLL,以及注入DLL

为了防止忘记,特记下 DLL的创建,在VS2017中选择dll的创建 // dllmain.cpp : Defines the entry point for the DLL application. #include "stdafx.h" #include <Windows.h> #include <stdio.h> HMODULE thisModule; HHOOK hook; LRESULT CALLBACK LaunchListener(int nCod

HOOK API (一)——HOOK基础+一个鼠标钩子实例

HOOK API (一)——HOOK基础+一个鼠标钩子实例 0x00 起因 最近在做毕业设计,有一个功能是需要实现对剪切板的监控和进程的防终止保护.原本想从内核层实现,但没有头绪.最后决定从调用层入手,即采用HOOK API的技术来挂钩相应的API,从而实现预期的功能.在这样的需求下,就开始学习了HOOK API. 0x01什么是HOOK API HOOK(钩子,挂钩)是一种实现Windows平台下类似于中断的机制[24].HOOK机制允许应用程序拦截并处理Windows消息或指定事件,当指定的

汇编Ring 3下实现 HOOK API

[文章标题]汇编ring3下实现HOOK API [文章作者]nohacks(非安全,hacker0058) [作者主页]hacker0058.ys168.com [文章出处]看雪论坛(bbs.pediy.com) ==================[ 汇编ring3下实现HOOK API ]===================== Author: nohacks                                                  Emil: [email pr

我的Hook学习笔记

关于Hook 一.基本概念: 钩子(Hook),是Windows消息处理机制的一个平台,应用程序能够在上面设置子程以监视指定窗体的某种消息,并且所监视的窗体能够是其它进程所创建的.当消息到达后,在目标窗体处理函数之前处理它.钩子机制同意应用程序截获处理window消息或特定事件. 钩子实际上是一个处理消息的程序段,通过系统调用,把它挂入系统.每当特定的消息发出,在没有到达目的窗体前,钩子程序就先捕获该消息,亦即钩子函数先得到控制权.这时钩子函数即能够加工处理(改变)该消息,也能够不作处理而继续传

unity3d进程通信利用WM_COPYDATE和HOOK

hello,近期用unity做了进程通信,应该是和c++的PC端实现通信,才開始一头雾水,后来实现了才知道好繁杂......先感谢对我提供帮助的百度,谷歌以及游戏圈的大大们. 在进程通信中非常多方法,可是wm_copydate绝对要比别的什么内存共享好了很多. unity大部分用c#语言,c#本身Forms这个dll里面也提供了对windows消息的接收可是在unity中无法非常好地使用System.Windows.Forms,所以在以下我的代码我用unity发送进程消息的是 user32.dl