Fix x86 compilation errors

This commit is contained in:
BeneficialCode
2026-07-25 10:48:46 +08:00
parent 51a57fb6ef
commit 32754a4555
11 changed files with 37 additions and 11 deletions
+3 -3
View File
@@ -6,6 +6,9 @@ MinimumVisualStudioVersion = 10.0.40219.1
Project("{8BC9CEB8-8B4A-11D0-8D11-00A0C91BC942}") = "Anti-Rootkit", "Anti-Rootkit\Anti-Rootkit.vcxproj", "{A29572BD-57C4-401D-80C0-29EA6AF7471E}"
EndProject
Project("{8BC9CEB8-8B4A-11D0-8D11-00A0C91BC942}") = "WinArk", "WinArk\WinArk.vcxproj", "{B8B52E8A-3A29-449D-B324-7A72994F83E2}"
ProjectSection(ProjectDependencies) = postProject
{A29572BD-57C4-401D-80C0-29EA6AF7471E} = {A29572BD-57C4-401D-80C0-29EA6AF7471E}
EndProjectSection
EndProject
Project("{8BC9CEB8-8B4A-11D0-8D11-00A0C91BC942}") = "WinSysCore", "WinSysCore\WinSysCore.vcxproj", "{38942B29-A5A3-49C3-A922-0C1082DB33C0}"
EndProject
@@ -54,7 +57,6 @@ Global
{A29572BD-57C4-401D-80C0-29EA6AF7471E}.Debug|x64.Deploy.0 = Debug|x64
{A29572BD-57C4-401D-80C0-29EA6AF7471E}.Debug|x86.ActiveCfg = Debug|Win32
{A29572BD-57C4-401D-80C0-29EA6AF7471E}.Debug|x86.Build.0 = Debug|Win32
{A29572BD-57C4-401D-80C0-29EA6AF7471E}.Debug|x86.Deploy.0 = Debug|Win32
{A29572BD-57C4-401D-80C0-29EA6AF7471E}.Release|ARM.ActiveCfg = Release|ARM
{A29572BD-57C4-401D-80C0-29EA6AF7471E}.Release|ARM.Build.0 = Release|ARM
{A29572BD-57C4-401D-80C0-29EA6AF7471E}.Release|ARM.Deploy.0 = Release|ARM
@@ -117,7 +119,6 @@ Global
{C8530718-A24C-4F86-BF28-CF5192F1751B}.Debug|x64.Deploy.0 = Debug|x64
{C8530718-A24C-4F86-BF28-CF5192F1751B}.Debug|x86.ActiveCfg = Debug|Win32
{C8530718-A24C-4F86-BF28-CF5192F1751B}.Debug|x86.Build.0 = Debug|Win32
{C8530718-A24C-4F86-BF28-CF5192F1751B}.Debug|x86.Deploy.0 = Debug|Win32
{C8530718-A24C-4F86-BF28-CF5192F1751B}.Release|ARM.ActiveCfg = Release|ARM
{C8530718-A24C-4F86-BF28-CF5192F1751B}.Release|ARM.Build.0 = Release|ARM
{C8530718-A24C-4F86-BF28-CF5192F1751B}.Release|ARM.Deploy.0 = Release|ARM
@@ -225,7 +226,6 @@ Global
{F967758B-AE4A-44F6-AC12-7F63A9CE23E3}.Debug|x64.Deploy.0 = Debug|x64
{F967758B-AE4A-44F6-AC12-7F63A9CE23E3}.Debug|x86.ActiveCfg = Debug|Win32
{F967758B-AE4A-44F6-AC12-7F63A9CE23E3}.Debug|x86.Build.0 = Debug|Win32
{F967758B-AE4A-44F6-AC12-7F63A9CE23E3}.Debug|x86.Deploy.0 = Debug|Win32
{F967758B-AE4A-44F6-AC12-7F63A9CE23E3}.Release|ARM.ActiveCfg = Release|ARM
{F967758B-AE4A-44F6-AC12-7F63A9CE23E3}.Release|ARM.Build.0 = Release|ARM
{F967758B-AE4A-44F6-AC12-7F63A9CE23E3}.Release|ARM.Deploy.0 = Release|ARM
+3
View File
@@ -962,6 +962,9 @@ NTSTATUS AntiRootkitDeviceControl(PDEVICE_OBJECT, PIRP Irp) {
break;
}
auto info = (UnloadedDriversInfo*)Irp->AssociatedIrp.SystemBuffer;
if (!info->pMmUnloadedDrivers) {
break;
}
// MmUnloadedDrivers MmLastUnloadedDriver
PUNLOADED_DRIVER pMmUnloadDrivers = nullptr;
pMmUnloadDrivers = *(PUNLOADED_DRIVER*)info->pMmUnloadedDrivers;
+8 -1
View File
@@ -275,4 +275,11 @@ typedef struct _LDR_DATA_TABLE_ENTRY32
ULONG ReferenceCount;
ULONG DependentLoadFlags;
UCHAR SigningLevel; // since REDSTONE2
} LDR_DATA_TABLE_ENTRY32, * PLDR_DATA_TABLE_ENTRY32;
} LDR_DATA_TABLE_ENTRY32, * PLDR_DATA_TABLE_ENTRY32;
typedef struct _EWOW64PROCESS
{
VOID* Peb; //0x0
USHORT Machine; //0x8
enum _SYSTEM_DLL_TYPE NtdllType; //0xc
}EWOW64PROCESS, * PEWOW64PROCESS;
+5 -1
View File
@@ -92,6 +92,8 @@ Return Value:
DebugObject->Flags = 0;
}
// _EWOW64PROCESS
// 调试对象插入句柄表
status = ObInsertObject(
DebugObject,
@@ -105,6 +107,8 @@ Return Value:
return status;
}
__try {
*DebugObjectHandle = handle;
}
@@ -1678,7 +1682,7 @@ Return Value:
// No unread events there. Clear the event.
KeClearEvent(&DebugObject->EventsPresent);
}
status = STATUS_SUCCESS;;
status = STATUS_SUCCESS;
}
else {
+1 -1
View File
@@ -252,7 +252,7 @@ IMAGEHLP_MODULE SymbolHandler::GetModuleInfo(DWORD64 address) {
ULONG_PTR SymbolHandler::GetSymbolAddressFromName(PCSTR name) {
auto symbol = std::make_unique<ImagehlpSymbol>();
auto info = symbol->GetSymbolInfo();
BOOL success = ::SymGetSymFromName64(m_hProcess, name, info);
BOOL success = ::SymGetSymFromName(m_hProcess, name, info);
if (!success) {
DWORD error = ::GetLastError();
std::string value = to_string(error);
+1 -1
View File
@@ -23,7 +23,7 @@
<Keyword>Win32Proj</Keyword>
<ProjectGuid>{495c31cf-8dd9-45ac-b53e-e70f3791c925}</ProjectGuid>
<RootNamespace>ProcMon</RootNamespace>
<WindowsTargetPlatformVersion>10.0</WindowsTargetPlatformVersion>
<WindowsTargetPlatformVersion>10.0.19041.0</WindowsTargetPlatformVersion>
</PropertyGroup>
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.Default.props" />
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Debug|Win32'" Label="Configuration">
+3
View File
@@ -4,6 +4,9 @@
* WinArk is an open source Anti-Rootkit(ARK) tool for Windows. It supports from Windows 7 to Windows 11. We also support both 32 bit and 64 bit. Compared with other Ark tools, WinArk can run on the latest Windows 11 without updating binary files since it will automatically downloads requisite symbol files.
* WinArk's official website:
- [virtualcc.cn](https://virtualcc.cn)
## Compiling
* [How to build WinArk](doc/build-winark.md)
+2
View File
@@ -80,6 +80,7 @@ DriverEntry(PDRIVER_OBJECT DriverObject, PUNICODE_STRING RegistryPath) {
FZG* result = CONTAINING_RECORD(pBucket, FZG, bucket);
KdPrint(("%d %d %s", result->age, result->height, result->name));
UNREFERENCED_PARAMETER(result);
}
@@ -90,6 +91,7 @@ DriverEntry(PDRIVER_OBJECT DriverObject, PUNICODE_STRING RegistryPath) {
{
FZG* result = CONTAINING_RECORD(Iterator.HashEntry, FZG, bucket);
KdPrint(("result %p", result));
UNREFERENCED_PARAMETER(result);
HashTableIterRemove(&Iterator);
//KdPrint(("Iterator %d %d %s", result->age, result->height, result->name));
//ExFreePoolWithTag(result, 'meti');
+3 -3
View File
@@ -25,7 +25,7 @@ NtSuspendProcess(
_In_ HANDLE ProcessHandle
);
extern "C" NTSTATUS NtResumeProcess(_In_ HANDLE ProcessHandle);
extern "C" NTSTATUS NTAPI NtResumeProcess(_In_ HANDLE ProcessHandle);
CProcessTable::CProcessTable(BarInfo& bars,TableInfo& table)
:CTable(bars,table){
@@ -180,7 +180,7 @@ LRESULT CProcessTable::OnSysKeyDown(UINT uMsg, WPARAM wParam, LPARAM lParam, BOO
}
LRESULT CProcessTable::OnGetDlgCode(UINT /*uMsg*/, WPARAM /*wParam*/, LPARAM /*lParam*/, BOOL& /*bHandled*/) {
return DLGC_WANTARROWS; // Direction keys.我想要处理方向键
return DLGC_WANTARROWS; // Direction keys.����Ҫ���������
}
void CProcessTable::Refresh() {
@@ -284,7 +284,7 @@ LRESULT CProcessTable::OnProcessKill(WORD /*wNotifyCode*/, WORD /*wID*/, HWND /*
auto& p = m_Table.data.info[selected];
CString text;
text.Format(L"Kill Process:%u (%ws)?", p->Id, p->GetImageName().c_str());
text.Format(L"Kill Process��%u (%ws)?", p->Id, p->GetImageName().c_str());
if (AtlMessageBox(*this, (PCWSTR)text, IDS_TITLE, MB_ICONWARNING | MB_OKCANCEL | MB_DEFBUTTON2) == IDCANCEL)
return 0;
+7
View File
@@ -239,6 +239,13 @@ LONG WINAPI SelfUnhandledExceptionFilter(EXCEPTION_POINTERS* ExceptionInfo)
}
int WINAPI _tWinMain(HINSTANCE hInstance, HINSTANCE /*hPrevInstance*/, LPTSTR lpstrCmdLine, int nCmdShow) {
// Suppress the OS "There is no disk in the drive" critical-error dialog. It is
// raised whenever the process touches an empty removable drive (e.g. D: on a VM):
// DbgHelp below probes each module's build-time PDB path,
// and various views enumerate drive letters. SEM_FAILCRITICALERRORS turns those
// failures into silent error returns instead of a modal dialog.
::SetErrorMode(SEM_FAILCRITICALERRORS | SEM_NOOPENFILEERRORBOX);
g_hSingleInstMutex = ::CreateMutex(nullptr, FALSE, L"WinArkSingleInstanceMutex");
if (!g_hSingleInstMutex) {
return 1;
+1 -1
View File
@@ -149,7 +149,7 @@
<Optimization>Disabled</Optimization>
<PreprocessorDefinitions>WIN32;_WINDOWS;STRICT;_DEBUG;%(PreprocessorDefinitions)</PreprocessorDefinitions>
<LanguageStandard>stdcpplatest</LanguageStandard>
<AdditionalIncludeDirectories>..\PEParser;..\WinSysCore;..\PdbParser;..\Utils</AdditionalIncludeDirectories>
<AdditionalIncludeDirectories>..\PEParser;..\WinSysCore;..\PdbParser;..\Utils;..\diStorm3\include</AdditionalIncludeDirectories>
</ClCompile>
<Link>
<SubSystem>Windows</SubSystem>