mirror of
https://github.com/BeneficialCode/WinArk
synced 2026-08-09 12:00:31 +00:00
Fix x86 compilation errors
This commit is contained in:
+3
-3
@@ -6,6 +6,9 @@ MinimumVisualStudioVersion = 10.0.40219.1
|
||||
Project("{8BC9CEB8-8B4A-11D0-8D11-00A0C91BC942}") = "Anti-Rootkit", "Anti-Rootkit\Anti-Rootkit.vcxproj", "{A29572BD-57C4-401D-80C0-29EA6AF7471E}"
|
||||
EndProject
|
||||
Project("{8BC9CEB8-8B4A-11D0-8D11-00A0C91BC942}") = "WinArk", "WinArk\WinArk.vcxproj", "{B8B52E8A-3A29-449D-B324-7A72994F83E2}"
|
||||
ProjectSection(ProjectDependencies) = postProject
|
||||
{A29572BD-57C4-401D-80C0-29EA6AF7471E} = {A29572BD-57C4-401D-80C0-29EA6AF7471E}
|
||||
EndProjectSection
|
||||
EndProject
|
||||
Project("{8BC9CEB8-8B4A-11D0-8D11-00A0C91BC942}") = "WinSysCore", "WinSysCore\WinSysCore.vcxproj", "{38942B29-A5A3-49C3-A922-0C1082DB33C0}"
|
||||
EndProject
|
||||
@@ -54,7 +57,6 @@ Global
|
||||
{A29572BD-57C4-401D-80C0-29EA6AF7471E}.Debug|x64.Deploy.0 = Debug|x64
|
||||
{A29572BD-57C4-401D-80C0-29EA6AF7471E}.Debug|x86.ActiveCfg = Debug|Win32
|
||||
{A29572BD-57C4-401D-80C0-29EA6AF7471E}.Debug|x86.Build.0 = Debug|Win32
|
||||
{A29572BD-57C4-401D-80C0-29EA6AF7471E}.Debug|x86.Deploy.0 = Debug|Win32
|
||||
{A29572BD-57C4-401D-80C0-29EA6AF7471E}.Release|ARM.ActiveCfg = Release|ARM
|
||||
{A29572BD-57C4-401D-80C0-29EA6AF7471E}.Release|ARM.Build.0 = Release|ARM
|
||||
{A29572BD-57C4-401D-80C0-29EA6AF7471E}.Release|ARM.Deploy.0 = Release|ARM
|
||||
@@ -117,7 +119,6 @@ Global
|
||||
{C8530718-A24C-4F86-BF28-CF5192F1751B}.Debug|x64.Deploy.0 = Debug|x64
|
||||
{C8530718-A24C-4F86-BF28-CF5192F1751B}.Debug|x86.ActiveCfg = Debug|Win32
|
||||
{C8530718-A24C-4F86-BF28-CF5192F1751B}.Debug|x86.Build.0 = Debug|Win32
|
||||
{C8530718-A24C-4F86-BF28-CF5192F1751B}.Debug|x86.Deploy.0 = Debug|Win32
|
||||
{C8530718-A24C-4F86-BF28-CF5192F1751B}.Release|ARM.ActiveCfg = Release|ARM
|
||||
{C8530718-A24C-4F86-BF28-CF5192F1751B}.Release|ARM.Build.0 = Release|ARM
|
||||
{C8530718-A24C-4F86-BF28-CF5192F1751B}.Release|ARM.Deploy.0 = Release|ARM
|
||||
@@ -225,7 +226,6 @@ Global
|
||||
{F967758B-AE4A-44F6-AC12-7F63A9CE23E3}.Debug|x64.Deploy.0 = Debug|x64
|
||||
{F967758B-AE4A-44F6-AC12-7F63A9CE23E3}.Debug|x86.ActiveCfg = Debug|Win32
|
||||
{F967758B-AE4A-44F6-AC12-7F63A9CE23E3}.Debug|x86.Build.0 = Debug|Win32
|
||||
{F967758B-AE4A-44F6-AC12-7F63A9CE23E3}.Debug|x86.Deploy.0 = Debug|Win32
|
||||
{F967758B-AE4A-44F6-AC12-7F63A9CE23E3}.Release|ARM.ActiveCfg = Release|ARM
|
||||
{F967758B-AE4A-44F6-AC12-7F63A9CE23E3}.Release|ARM.Build.0 = Release|ARM
|
||||
{F967758B-AE4A-44F6-AC12-7F63A9CE23E3}.Release|ARM.Deploy.0 = Release|ARM
|
||||
|
||||
@@ -962,6 +962,9 @@ NTSTATUS AntiRootkitDeviceControl(PDEVICE_OBJECT, PIRP Irp) {
|
||||
break;
|
||||
}
|
||||
auto info = (UnloadedDriversInfo*)Irp->AssociatedIrp.SystemBuffer;
|
||||
if (!info->pMmUnloadedDrivers) {
|
||||
break;
|
||||
}
|
||||
// MmUnloadedDrivers MmLastUnloadedDriver
|
||||
PUNLOADED_DRIVER pMmUnloadDrivers = nullptr;
|
||||
pMmUnloadDrivers = *(PUNLOADED_DRIVER*)info->pMmUnloadedDrivers;
|
||||
|
||||
@@ -275,4 +275,11 @@ typedef struct _LDR_DATA_TABLE_ENTRY32
|
||||
ULONG ReferenceCount;
|
||||
ULONG DependentLoadFlags;
|
||||
UCHAR SigningLevel; // since REDSTONE2
|
||||
} LDR_DATA_TABLE_ENTRY32, * PLDR_DATA_TABLE_ENTRY32;
|
||||
} LDR_DATA_TABLE_ENTRY32, * PLDR_DATA_TABLE_ENTRY32;
|
||||
|
||||
typedef struct _EWOW64PROCESS
|
||||
{
|
||||
VOID* Peb; //0x0
|
||||
USHORT Machine; //0x8
|
||||
enum _SYSTEM_DLL_TYPE NtdllType; //0xc
|
||||
}EWOW64PROCESS, * PEWOW64PROCESS;
|
||||
@@ -92,6 +92,8 @@ Return Value:
|
||||
DebugObject->Flags = 0;
|
||||
}
|
||||
|
||||
// _EWOW64PROCESS
|
||||
|
||||
// 调试对象插入句柄表
|
||||
status = ObInsertObject(
|
||||
DebugObject,
|
||||
@@ -105,6 +107,8 @@ Return Value:
|
||||
return status;
|
||||
}
|
||||
|
||||
|
||||
|
||||
__try {
|
||||
*DebugObjectHandle = handle;
|
||||
}
|
||||
@@ -1678,7 +1682,7 @@ Return Value:
|
||||
// No unread events there. Clear the event.
|
||||
KeClearEvent(&DebugObject->EventsPresent);
|
||||
}
|
||||
status = STATUS_SUCCESS;;
|
||||
status = STATUS_SUCCESS;
|
||||
|
||||
}
|
||||
else {
|
||||
|
||||
@@ -252,7 +252,7 @@ IMAGEHLP_MODULE SymbolHandler::GetModuleInfo(DWORD64 address) {
|
||||
ULONG_PTR SymbolHandler::GetSymbolAddressFromName(PCSTR name) {
|
||||
auto symbol = std::make_unique<ImagehlpSymbol>();
|
||||
auto info = symbol->GetSymbolInfo();
|
||||
BOOL success = ::SymGetSymFromName64(m_hProcess, name, info);
|
||||
BOOL success = ::SymGetSymFromName(m_hProcess, name, info);
|
||||
if (!success) {
|
||||
DWORD error = ::GetLastError();
|
||||
std::string value = to_string(error);
|
||||
|
||||
@@ -23,7 +23,7 @@
|
||||
<Keyword>Win32Proj</Keyword>
|
||||
<ProjectGuid>{495c31cf-8dd9-45ac-b53e-e70f3791c925}</ProjectGuid>
|
||||
<RootNamespace>ProcMon</RootNamespace>
|
||||
<WindowsTargetPlatformVersion>10.0</WindowsTargetPlatformVersion>
|
||||
<WindowsTargetPlatformVersion>10.0.19041.0</WindowsTargetPlatformVersion>
|
||||
</PropertyGroup>
|
||||
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.Default.props" />
|
||||
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Debug|Win32'" Label="Configuration">
|
||||
|
||||
@@ -4,6 +4,9 @@
|
||||
|
||||
* WinArk is an open source Anti-Rootkit(ARK) tool for Windows. It supports from Windows 7 to Windows 11. We also support both 32 bit and 64 bit. Compared with other Ark tools, WinArk can run on the latest Windows 11 without updating binary files since it will automatically downloads requisite symbol files.
|
||||
|
||||
* WinArk's official website:
|
||||
- [virtualcc.cn](https://virtualcc.cn)
|
||||
|
||||
## Compiling
|
||||
* [How to build WinArk](doc/build-winark.md)
|
||||
|
||||
|
||||
@@ -80,6 +80,7 @@ DriverEntry(PDRIVER_OBJECT DriverObject, PUNICODE_STRING RegistryPath) {
|
||||
|
||||
FZG* result = CONTAINING_RECORD(pBucket, FZG, bucket);
|
||||
KdPrint(("%d %d %s", result->age, result->height, result->name));
|
||||
UNREFERENCED_PARAMETER(result);
|
||||
}
|
||||
|
||||
|
||||
@@ -90,6 +91,7 @@ DriverEntry(PDRIVER_OBJECT DriverObject, PUNICODE_STRING RegistryPath) {
|
||||
{
|
||||
FZG* result = CONTAINING_RECORD(Iterator.HashEntry, FZG, bucket);
|
||||
KdPrint(("result %p", result));
|
||||
UNREFERENCED_PARAMETER(result);
|
||||
HashTableIterRemove(&Iterator);
|
||||
//KdPrint(("Iterator %d %d %s", result->age, result->height, result->name));
|
||||
//ExFreePoolWithTag(result, 'meti');
|
||||
|
||||
@@ -25,7 +25,7 @@ NtSuspendProcess(
|
||||
_In_ HANDLE ProcessHandle
|
||||
);
|
||||
|
||||
extern "C" NTSTATUS NtResumeProcess(_In_ HANDLE ProcessHandle);
|
||||
extern "C" NTSTATUS NTAPI NtResumeProcess(_In_ HANDLE ProcessHandle);
|
||||
|
||||
CProcessTable::CProcessTable(BarInfo& bars,TableInfo& table)
|
||||
:CTable(bars,table){
|
||||
@@ -180,7 +180,7 @@ LRESULT CProcessTable::OnSysKeyDown(UINT uMsg, WPARAM wParam, LPARAM lParam, BOO
|
||||
}
|
||||
|
||||
LRESULT CProcessTable::OnGetDlgCode(UINT /*uMsg*/, WPARAM /*wParam*/, LPARAM /*lParam*/, BOOL& /*bHandled*/) {
|
||||
return DLGC_WANTARROWS; // Direction keys.我想要处理方向键
|
||||
return DLGC_WANTARROWS; // Direction keys.����Ҫ���������
|
||||
}
|
||||
|
||||
void CProcessTable::Refresh() {
|
||||
@@ -284,7 +284,7 @@ LRESULT CProcessTable::OnProcessKill(WORD /*wNotifyCode*/, WORD /*wID*/, HWND /*
|
||||
auto& p = m_Table.data.info[selected];
|
||||
|
||||
CString text;
|
||||
text.Format(L"Kill Process:%u (%ws)?", p->Id, p->GetImageName().c_str());
|
||||
text.Format(L"Kill Process��%u (%ws)?", p->Id, p->GetImageName().c_str());
|
||||
if (AtlMessageBox(*this, (PCWSTR)text, IDS_TITLE, MB_ICONWARNING | MB_OKCANCEL | MB_DEFBUTTON2) == IDCANCEL)
|
||||
return 0;
|
||||
|
||||
|
||||
@@ -239,6 +239,13 @@ LONG WINAPI SelfUnhandledExceptionFilter(EXCEPTION_POINTERS* ExceptionInfo)
|
||||
}
|
||||
|
||||
int WINAPI _tWinMain(HINSTANCE hInstance, HINSTANCE /*hPrevInstance*/, LPTSTR lpstrCmdLine, int nCmdShow) {
|
||||
// Suppress the OS "There is no disk in the drive" critical-error dialog. It is
|
||||
// raised whenever the process touches an empty removable drive (e.g. D: on a VM):
|
||||
// DbgHelp below probes each module's build-time PDB path,
|
||||
// and various views enumerate drive letters. SEM_FAILCRITICALERRORS turns those
|
||||
// failures into silent error returns instead of a modal dialog.
|
||||
::SetErrorMode(SEM_FAILCRITICALERRORS | SEM_NOOPENFILEERRORBOX);
|
||||
|
||||
g_hSingleInstMutex = ::CreateMutex(nullptr, FALSE, L"WinArkSingleInstanceMutex");
|
||||
if (!g_hSingleInstMutex) {
|
||||
return 1;
|
||||
|
||||
@@ -149,7 +149,7 @@
|
||||
<Optimization>Disabled</Optimization>
|
||||
<PreprocessorDefinitions>WIN32;_WINDOWS;STRICT;_DEBUG;%(PreprocessorDefinitions)</PreprocessorDefinitions>
|
||||
<LanguageStandard>stdcpplatest</LanguageStandard>
|
||||
<AdditionalIncludeDirectories>..\PEParser;..\WinSysCore;..\PdbParser;..\Utils</AdditionalIncludeDirectories>
|
||||
<AdditionalIncludeDirectories>..\PEParser;..\WinSysCore;..\PdbParser;..\Utils;..\diStorm3\include</AdditionalIncludeDirectories>
|
||||
</ClCompile>
|
||||
<Link>
|
||||
<SubSystem>Windows</SubSystem>
|
||||
|
||||
Reference in New Issue
Block a user