From 1dfe28ca38d4b5d4d6580a2626e7dfe754646a71 Mon Sep 17 00:00:00 2001 From: maowenrui <3505719167@qq.com> Date: Tue, 16 Jun 2026 10:22:02 +0800 Subject: [PATCH] feat comm init win10-win11 --- Anti-Cheat_Driver/comm.cpp | 45 ++++++++++++++++ Anti-Cheat_Driver/comm.h | 10 ++++ Anti-Cheat_Driver/comm_dispatch.cpp | 29 +++++++++++ Anti-Cheat_Driver/comm_dispatch.h | 21 ++++++++ Anti-Cheat_Driver/comm_win10.cpp | 75 ++++++++++++++++++++++++++ Anti-Cheat_Driver/comm_win10.h | 9 ++++ Anti-Cheat_Driver/comm_win7.cpp | 81 +++++++++++++++++++++++++++++ Anti-Cheat_Driver/comm_win7.h | 12 +++++ 8 files changed, 282 insertions(+) create mode 100644 Anti-Cheat_Driver/comm.cpp create mode 100644 Anti-Cheat_Driver/comm.h create mode 100644 Anti-Cheat_Driver/comm_dispatch.cpp create mode 100644 Anti-Cheat_Driver/comm_dispatch.h create mode 100644 Anti-Cheat_Driver/comm_win10.cpp create mode 100644 Anti-Cheat_Driver/comm_win10.h create mode 100644 Anti-Cheat_Driver/comm_win7.cpp create mode 100644 Anti-Cheat_Driver/comm_win7.h diff --git a/Anti-Cheat_Driver/comm.cpp b/Anti-Cheat_Driver/comm.cpp new file mode 100644 index 0000000..601799b --- /dev/null +++ b/Anti-Cheat_Driver/comm.cpp @@ -0,0 +1,45 @@ +#include "comm.h" +#include "utils.h" +#include "comm_win10.h" +#include "comm_win7.h" + +namespace kernel_comm_create +{ + auto Init() -> BOOL + { + auto version = utils::GetVersion(); + if (version.dwBuildNumber == 7600 || version.dwBuildNumber == 7601) + { + //win7 + if (comm_win7::comm_init()) + { + return comm_win7::comm_install_hook(); + } + } + else + { + //win10 + if (comm_win10::comm_init()) + { + return comm_win10::comm_install_hook(); + } + } + + return FALSE; + } + + auto remove() -> BOOL + { + auto version = utils::GetVersion(); + if (version.dwBuildNumber == 7600 || version.dwBuildNumber == 7601) + { + //win7 + return comm_win7::comm_remov_hook(); + } + else + { + return comm_win10::comm_remov_hook(); + } + } + +} \ No newline at end of file diff --git a/Anti-Cheat_Driver/comm.h b/Anti-Cheat_Driver/comm.h new file mode 100644 index 0000000..5d244f9 --- /dev/null +++ b/Anti-Cheat_Driver/comm.h @@ -0,0 +1,10 @@ +#pragma once +#include "Base.h" + +namespace kernel_comm_create +{ + auto Init()->BOOL; + + auto remove()->BOOL; + +} \ No newline at end of file diff --git a/Anti-Cheat_Driver/comm_dispatch.cpp b/Anti-Cheat_Driver/comm_dispatch.cpp new file mode 100644 index 0000000..38f9674 --- /dev/null +++ b/Anti-Cheat_Driver/comm_dispatch.cpp @@ -0,0 +1,29 @@ +#include "comm_dispatch.h" +#include "protect_filter.h" + +namespace comm_dispatch +{ + auto dispatch(CMD_COMM* data) -> NTSTATUS + { + auto status = STATUS_UNSUCCESSFUL; + switch (data->CommID) + { + case CMD::DRIVER_COMM_TEST: + { + status = STATUS_SUCCESS; + break; + } + case CMD::DRIVER_PROTECT_PROCESS: + { + status = protect_filter::add_list((ULONG)data->Pid, NULL); + break; + } + default: + break; + } + + *(NTSTATUS*)data->status = status; + return status; + } +} + diff --git a/Anti-Cheat_Driver/comm_dispatch.h b/Anti-Cheat_Driver/comm_dispatch.h new file mode 100644 index 0000000..cfdb5f0 --- /dev/null +++ b/Anti-Cheat_Driver/comm_dispatch.h @@ -0,0 +1,21 @@ +#pragma once +#include "Base.h" + +struct CMD_COMM +{ + DWORD64 CommID; + DWORD64 Pid; + DWORD64 status; +}; + +enum CMD +{ + MSG_BASE = 0x10000, + DRIVER_COMM_TEST, + DRIVER_PROTECT_PROCESS +}; + +namespace comm_dispatch +{ + auto dispatch(CMD_COMM* data)->NTSTATUS; +} \ No newline at end of file diff --git a/Anti-Cheat_Driver/comm_win10.cpp b/Anti-Cheat_Driver/comm_win10.cpp new file mode 100644 index 0000000..550db97 --- /dev/null +++ b/Anti-Cheat_Driver/comm_win10.cpp @@ -0,0 +1,75 @@ +#include "comm_win10.h" +#include "comm_dispatch.h" +#include "utils.h" +#include "kernel_function.h" +#pragma warning(disable : 4309) +#pragma warning(disable : 4838) + +typedef NTSTATUS(__fastcall* fnHalpTimerConvertAuxiliaryCounterToPerformanceCounter)(PVOID, PVOID, PVOID); +fnHalpTimerConvertAuxiliaryCounterToPerformanceCounter _HalpTimerConvertAuxiliaryCounterToPerformanceCounter = 0; + +uintptr_t beep_trampoline_ptr; +uintptr_t func_call_address; + +namespace comm_win10 +{ + auto comm_callback(PVOID a1, PVOID a2, PVOID a3) -> NTSTATUS + { + comm_dispatch::dispatch((CMD_COMM*)a1); + return _HalpTimerConvertAuxiliaryCounterToPerformanceCounter(a1, a2, a3); + } + + auto comm_init() -> BOOL + { + beep_trampoline_ptr = utils::get_beep_trampoline_ptr(); + return !beep_trampoline_ptr ? FALSE : TRUE; + } + + auto comm_install_hook() -> BOOL + { + auto ntoskrnl = kernel_function::GetKernelModule("ntoskrnl.exe"); + if (!ntoskrnl) + return FALSE; + + // mov rax,comm_callback + // jmp rax + char jmprax[] = { 0x48, 0xB8, 0x13, 0x09, 0xFC, 0xD6, 0xFC, 0x7F, 0x00, 0x00, 0xFF, 0xE0 }; + *(uintptr_t*)&jmprax[2] = (uintptr_t)comm_callback; + + auto status = kernel_function::MmMDLPagesCopy((PVOID)beep_trampoline_ptr, &jmprax, sizeof(jmprax), 0x0000002, KernelMode); + if (!NT_SUCCESS(status)) + return FALSE; + + auto code_addr = utils::FindSectionsCode(ntoskrnl, "\x48\x8B\x05\x00\x00\x00\x00\x00\x00\x48\x8B\x05\x00\x00\x00\x00\xE8\x00\x00\x00\x00\x8B\xC8", + "xxx??????xxx????x????xx", "PAGE"); + + func_call_address = (*(long*)(code_addr + 3)) + (code_addr + 7); + _HalpTimerConvertAuxiliaryCounterToPerformanceCounter = + *(fnHalpTimerConvertAuxiliaryCounterToPerformanceCounter*)(func_call_address); + + *(uintptr_t*)func_call_address = beep_trampoline_ptr; + + return TRUE; + } + auto comm_remov_hook() -> BOOL + { + if (!func_call_address) + return FALSE; + + *(uintptr_t*)func_call_address = + (uintptr_t)_HalpTimerConvertAuxiliaryCounterToPerformanceCounter; + + if (!beep_trampoline_ptr) + return FALSE; + + + char nullcode[12]{ 0 }; + auto status = kernel_function::MmMDLPagesCopy((PVOID)beep_trampoline_ptr, &nullcode, sizeof(nullcode), 0x0000002, KernelMode); + if (!NT_SUCCESS(status)) + return FALSE; + + return TRUE; + } +} + + diff --git a/Anti-Cheat_Driver/comm_win10.h b/Anti-Cheat_Driver/comm_win10.h new file mode 100644 index 0000000..19f82b9 --- /dev/null +++ b/Anti-Cheat_Driver/comm_win10.h @@ -0,0 +1,9 @@ +#pragma once +#include "Base.h" + +namespace comm_win10 +{ + auto comm_init()->BOOL; + auto comm_install_hook()->BOOL; + auto comm_remov_hook()->BOOL; +} diff --git a/Anti-Cheat_Driver/comm_win7.cpp b/Anti-Cheat_Driver/comm_win7.cpp new file mode 100644 index 0000000..137be4f --- /dev/null +++ b/Anti-Cheat_Driver/comm_win7.cpp @@ -0,0 +1,81 @@ +#include "comm_win7.h" +#include "comm_dispatch.h" +#include "utils.h" +#include "kernel_function.h" + +#pragma warning(disable : 4309) +#pragma warning(disable : 4838) + +PFILE_OBJECT file_obj{ 0 }; +PDEVICE_OBJECT device_obj{ 0 }; + +LPVOID orign_maj_function = nullptr; + +namespace comm_win7 +{ + auto comm_init() -> BOOL + { + UNICODE_STRING unName{ 0 }; + RtlInitUnicodeString(&unName, L"\\Device\\Null"); + auto status = IoGetDeviceObjectPointer(&unName, FILE_ALL_ACCESS, &file_obj, &device_obj); + if (!NT_SUCCESS(status)) + return FALSE; + + ObDereferenceObject(file_obj); + return TRUE; + } + + auto dispatch_device_io(PDEVICE_OBJECT drvice_object, PIRP irp)->NTSTATUS + { + UNREFERENCED_PARAMETER(drvice_object); + + auto comm_buf_data = reinterpret_cast(irp->AssociatedIrp.SystemBuffer); + + auto status = comm_dispatch::dispatch(comm_buf_data); + + irp->IoStatus.Information = sizeof(CMD_COMM); + irp->IoStatus.Status = status; + IoCompleteRequest(irp, IO_NO_INCREMENT); + return status; + }; + + auto comm_install_hook() -> BOOL + { + auto drv_obj = device_obj->DriverObject; + if (!drv_obj) + return FALSE; + + orign_maj_function = drv_obj->MajorFunction[IRP_MJ_DEVICE_CONTROL]; + + auto beep_trampoline = utils::get_beep_trampoline_ptr(); + if (!beep_trampoline) + return FALSE; + + //mov rax,dispatch_device_io + //jmp rax + char jmprax[] = { 0x48, 0xB8, 0xA0, 0x9A, 0xD5, 0x3E, 0xFE, 0x7F, 0x00, 0x00, 0xFF, 0xE0 }; + + *(uintptr_t*)&jmprax[2] = (uintptr_t)dispatch_device_io; + kernel_function::MmMDLPagesCopy((PVOID)beep_trampoline, &jmprax, sizeof(jmprax), 0x0000002, KernelMode); + + drv_obj->MajorFunction[IRP_MJ_DEVICE_CONTROL] = (PDRIVER_DISPATCH)beep_trampoline/*直接就是你的函数*/; + + return TRUE; + } + + auto comm_remov_hook() -> BOOL + { + auto drv_obj = device_obj->DriverObject; + if (!drv_obj) + return FALSE; + + if (drv_obj->MajorFunction[IRP_MJ_DEVICE_CONTROL]) + { + drv_obj->MajorFunction[IRP_MJ_DEVICE_CONTROL] = + (PDRIVER_DISPATCH)orign_maj_function; + } + + return TRUE; + } + +} \ No newline at end of file diff --git a/Anti-Cheat_Driver/comm_win7.h b/Anti-Cheat_Driver/comm_win7.h new file mode 100644 index 0000000..bb9f832 --- /dev/null +++ b/Anti-Cheat_Driver/comm_win7.h @@ -0,0 +1,12 @@ +#pragma once +#include "Base.h" + +namespace comm_win7 +{ + auto comm_init()->BOOL; + + auto comm_install_hook()->BOOL; + + auto comm_remov_hook()->BOOL; + +} \ No newline at end of file