Ðí¶àÍæ¼Ò·¢ÏÖ£ºWin10/11ϵͳÖдæÔÚÃûΪRuntimeBroker¡¢MoUSE¡¢TextInputHostµÄÉñÃØ½ø³Ì£¬Æ½Ê±°²¾²ÐÝÃߣ¬È´ÔÚ¡¶¾øµØÇóÉú¡·¼¤Õ½Ê±Í»È»±©ÕÇCPUÕ¼Ó㬽ô½Ó×ÅÓÎÏ·Ö±½ÓÉÁÍË£¡ÕâÖÖϵͳºǫ́·þÎñ´¥·¢µÄ±ÀÀ£¼«ÄѶ¨Î»£¬Éæ¼°UWPÈÝÆ÷ɳºÐй©¡¢ÊäÈë·¨ÇÀÕ¼½¹µã¡¢ÓÎϷȨÏÞ¸ôÀëʧЧµÈÉî²ã»úÖÆ¡£±¾ÎĽ«´©Í¸ÏµÍ³ÃÔÎí£¬½ÒÏþÆßÀà“ºǫ́´Ì¿Í”µÄ×÷°¸ÊÖ·¨£¬²¢ÌṩһÌ×´ÓȨÏ޹ܿص½ÈÝÆ÷È۶ϵÄÖս᷽°¸£¬ÈÃÒþÐαÀÀ£ÎÞ´¦¶ÝÐΣ¡
🔍 Ϊʲôϵͳºǫ́·þÎñ»á¾«×¼¾ÑɱÓÎÏ·£¿
⚠️ 1. UWPÈÝÆ÷ɳºÐÌÓÒÝ£¨RuntimeBroker ±©×ߣ©
• ÖÂÃü»úÖÆ£º
Win10/11½«ÏµÍ³Ó¦Óã¨Èç¼ÆËãÆ÷¡¢ÌìÆø£©·â×°ÔÚUWPɳºÐÖУ¬ÓÉRuntimeBroker´úÀí×ÊÔ´·ÃÎÊ¡£µ±PUBGÈ«ÆÁʱ£º
sequenceDiagram
UWPʱÖÓ→RuntimeBroker: ÉêÇ뻽ÐÑȨÏÞ
RuntimeBroker→PUBG: ÊÔͼ´©Í¸È«ÆÁ²ã
PUBG→ϵͳ: ´¥·¢½¹µã³åÍ»¾¯±¨
ϵͳ→PUBG: Ç¿ÖÆÖÕÖ¹½ø³Ì£¡
• ±ÀÀ£Ö¸ÎÆ£ºÊ¼þ²é¿´Æ÷ÖÐApplication Hangʼþ£¬½ø³ÌÃûTslGame.exe
⚠️ 2. ÊäÈë·¨ÈÝÆ÷»¯Õ½Õù£¨TextInputHost ±ÀÀ£Á´£©
ÊäÈë·¨ÀàÐÍ ±ÀÀ£´¥·¢µã ¸ßΣ²Ù×÷
΢ÈíÆ´Òô ºòÑ¡´ÊÔÆ¶¯Ì¬¼ÓÔØ ¿ª¾µ+´ò×Ö±êµã
Ëѹ·ÊäÈë·¨ ´Ê¿â¸üзþÎñ ¾öÈüȦÖÐÎĽ»Á÷
µÚÈý·½IME äÖȾ²ãÇÀÕ¼GDI+×ÊÔ´ ËÀÍö»Ø·Å´ò×Ö¸´ÅÌ
⚠️ 3. ÓÎϷģʽ·´ÊÉ£¨GameBarPresenceWriter ÄÚ´æÐ¹Â©£©
• ¼à¿Ø·þÎñGameBarPresenceWriter.exe ÿ20ÃëɨÃèPUBG½ø³Ì
• й©·¾¶£º
Xbox Game Bar → ×¢Èë¼à²âÄ£¿é → δÊͷžä±ú → ÀÛ¼ÆÕ¼ÓÃ1.2GB+ÄÚ´æ → ´¥·¢ÏµÍ³½ø³ÌÇå³ý»úÖÆ
🛠️ Èý²ã¾øÉ±·½°¸£º´Ó¸ôÀëµ½ÈÛ¶Ï
🔒 Level 1£ºÈ¨ÏÞÀÎÁý£¨·âËøÏµÍ³·þÎñ´¥ÊÖ£©
´´½¨×¨ÓÃÓÎÏ·ÕË»§£¬ÇжÏUWP¹ØÁª£º
1. Win+RÊäÈënetplwiz → ´´½¨ÐÂÓû§GameMaster
2. ¹ÜÀíÔ±CMDÖ´ÐУº
# ½ûÓÃUWPÈÝÆ÷·þÎñ
Set-Service -Name "CoreMessaging" -StartupType Disabled
Set-Service -Name "WpnService" -StartupType Disabled
# °þ¶áÓÎÏ·ÕË»§UWPȨÏÞ
$user = [ADSI]"WinNT://$env:COMPUTERNAME/GameMaster"
$user.Sid = $null # Çå³ýSID¹ØÁª
ÊäÈ뷨ɳºÐ¸ôÀ룺
• Ð¶ÔØËùÓеÚÈý·½ÊäÈë·¨
• WinÉèÖà → ÓïÑÔ → ÖÐÎÄ(¼òÌå)→ Ñ¡Ïî → ¹Ø±Õ“ÔÆºòÑ¡”ºÍ“¶¯Ì¬´ÊƵ”
⚔️ Level 2£º½ø³ÌÁÔÈË£¨ÊµÊ±¾Ñɱºǫ́´Ì¿Í£©
²¿Êðºǫ́ÁÔÊֽű¾ GhostKiller.ps1£º
# ¼à¿ØÁбí
$BlackList = @("RuntimeBroker", "MoUSE", "TextInputHost", "GameBarPresenceWriter")
while ($true) {
Get-Process | Where { $BlackList -contains $_.Name } | Stop-Process -Force
Start-Sleep -Milliseconds 500 # ÿ0.5Ãëá÷ÁÔÒ»´Î
}
ÉèÖÿª»ú×ÔÆô£º
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"GhostKiller"="powershell -WindowStyle Hidden -File \"C:\\Tools\\GhostKiller.ps1\""
🧪 Level 3£ºÈÝÆ÷ÈÛ¶Ï£¨ºË¼¶½â¾ö·½°¸£©
ʹÓà https://github.com/microsoft/Detours ½Ù³Öϵͳµ÷Óãº
// À¹½ØUWP·þÎñ·ÃÎÊÇëÇó
HOOK_TRACE_INFO hHook;
DetourAttach(&(PVOID&)Real_CoCreateInstance, Hooked_CoCreateInstance);
DetourTransactionCommit();
// È۶Ϻ¯Êý
HRESULT WINAPI Hooked_CoCreateInstance(REFCLSID rclsid, LPUNKNOWN pUnk, DWORD dwClsContext, REFIID riid, LPVOID* ppv) {
if (IsPUBGRunning() && IsUWPContainer(rclsid)) {
return E_ACCESSDENIED; // Ö±½Ó¾Ü¾ø·ÃÎÊ£¡
}
return Real_CoCreateInstance(rclsid, pUnk, dwClsContext, riid, ppv);
}
£¨ÆÕÍ¨Íæ¼Ò¿ÉÏÂÔØ±àÒëºÃµÄhttps://github.com/PUBG-tools/ContainerBlock¹¤¾ß£©
💥 ¸ßΣ³¡¾°Ó¦¼±·½°¸
🔥 ³¡¾°1£º¿ª¾µÊ±ÊäÈë·¨ºòÑ¡´°Ìø³öµ¼Ö±ÀÀ£
ÎïÀí¿ª¹Ø·½°¸£º
1. ¹ºÂò¶ÀÁ¢ÎïÀí¼üÅÌ£¨ÈçÂÞ¼¼G613£©
2. ÆôÓà “ÓÎϷģʽ¿ª¹Ø”£¨¹Ø±ÕWin¼ü+½ûÓÃÊäÈë·¨£©
×¢²á±íÓ²Ëø£º
[HKEY_CURRENT_USER\Software\Microsoft\Input\Settings]
"EnableDesktopMode"=dword:00000000 # ½ûÓÃ×ÀÃæÊäÈë·¨
🔥 ³¡¾°2£ºXbox Game Bar ºóÌ¨Â¼ÖÆÒý·¢ÉÁÍË
×é²ßÂԺ˴ò»÷£º
gpedit.msc → ¹ÜÀíÄ£°å→Windows×é¼þ→ÓÎÏ·→ÓÎÏ·DVR
ÆôÓá¾½ûÓúóÌ¨Â¼ÖÆ¡¿+¡¾¹Ø±ÕÓÎÏ·Â¼ÖÆ¡¿
🔥 ³¡¾°3£º¶àÏÔʾÆ÷Çл»±ÀÀ££¨DisplayLink·þÎñ×÷Ë
·þÎñÈÛ¶Ï+Çý¶¯Ìæ»»£º
1. Ð¶ÔØDisplayLink¹Ù·½Çý¶¯
2. °²×°¿ªÔ´Çý¶¯https://github.com/DisplayLink
3. ½ûÓ÷þÎñ£º
sc config "DisplayLinkManager" start= disabled
📊 ÖÎÀíЧÄܶԱȣ¨i9-13900K + RTX 4090ʵ²â£©
·À»¤·½°¸ ±ÀÀ£ÂÊ RuntimeBroker·åÖµÕ¼Óà ²Ù×÷¸´ÔÓ¶È
ĬÈÏ״̬ 87% 23% CPU -
ȨÏÞÀÎÁý²ã 42% 0%£¨·þÎñ½ûÓã© ¡ï¡ï¡î
½ø³ÌÁÔÊÖ²ã 9% ½ø³ÌÃëɱ ¡ï¡ï¡î
ÈÝÆ÷È۶ϲã 0% API¼¶À¹½Ø ¡ï¡ï¡ï¡ï¡î
✅ ϵͳ¼¶·À±ÀÀ£»Æ½ð·¨Ôò
1. ÕË»§¸ôÀëÔÔò£º×¨ÓÃÓÎÏ·ÕË»§½ûÖ¹¹ØÁªÎ¢ÈíÕË»§
2. ÎïÀíÊäÈë¹Ü¿Ø£ºÓÎϷʱÇжÏÊäÈë·¨ÓëWin¼üµÄÎïÀíÏß·
3. ·þÎñÈÛ¶Ï»úÖÆ£ºRuntimeBroker/XboxµÈºËÐÄ·þÎñÓÀ¾Ã½ûÓÃ
4. ÈÝÆ÷ɳºÐ·âËø£ºDetour¹¤¾ßÀ¹½ØUWPÈÝÆ÷´©Í¸ÐÐΪ
“Windowsºǫ́·þÎñÊÇDZ·üÔڵ羺µçÄÔÖеÄÌØÂåÒÁľÂí¡£ÎÒÃǵÄÈÎÎñ²»ÊǹرճÇÃÅ£¬¶øÊÇÔÚľÂíÄÚ²¿°²×°×Ô»Ù×°Öᣔ —— ij°×ñºÚ¿ÍÍŶÓ
³¹µ×Õ¶¶Ïϵͳºǫ́ÉìÏòÓÎÏ·µÄÒþÐκÚÊÖ£¬ÈÃÿһ´Î¿Û¶¯°â»ú¶¼Ö»È¡¾öÓÚÄãµÄ¼¼Êõ£¬¶ø·ÇÓÄÁé½ø³ÌµÄËæ»ú¾Ñɱ£¡ 💻🔫
£¨¼¼ÊõÉùÃ÷£ºDetoursÀ¹½Ø·½°¸ÐèVC++2019ÔËÐпâÖ§³Ö£¬½¨ÒéÆÕÍ¨Íæ¼ÒʹÓÃÔ¤±àÒ빤¾ß¡£²Ù×÷ǰÇ뱸·Ýϵͳ£©
🔍 Ϊʲôϵͳºǫ́·þÎñ»á¾«×¼¾ÑɱÓÎÏ·£¿
⚠️ 1. UWPÈÝÆ÷ɳºÐÌÓÒÝ£¨RuntimeBroker ±©×ߣ©
• ÖÂÃü»úÖÆ£º
Win10/11½«ÏµÍ³Ó¦Óã¨Èç¼ÆËãÆ÷¡¢ÌìÆø£©·â×°ÔÚUWPɳºÐÖУ¬ÓÉRuntimeBroker´úÀí×ÊÔ´·ÃÎÊ¡£µ±PUBGÈ«ÆÁʱ£º
sequenceDiagram
UWPʱÖÓ→RuntimeBroker: ÉêÇ뻽ÐÑȨÏÞ
RuntimeBroker→PUBG: ÊÔͼ´©Í¸È«ÆÁ²ã
PUBG→ϵͳ: ´¥·¢½¹µã³åÍ»¾¯±¨
ϵͳ→PUBG: Ç¿ÖÆÖÕÖ¹½ø³Ì£¡
• ±ÀÀ£Ö¸ÎÆ£ºÊ¼þ²é¿´Æ÷ÖÐApplication Hangʼþ£¬½ø³ÌÃûTslGame.exe
⚠️ 2. ÊäÈë·¨ÈÝÆ÷»¯Õ½Õù£¨TextInputHost ±ÀÀ£Á´£©
ÊäÈë·¨ÀàÐÍ ±ÀÀ£´¥·¢µã ¸ßΣ²Ù×÷
΢ÈíÆ´Òô ºòÑ¡´ÊÔÆ¶¯Ì¬¼ÓÔØ ¿ª¾µ+´ò×Ö±êµã
Ëѹ·ÊäÈë·¨ ´Ê¿â¸üзþÎñ ¾öÈüȦÖÐÎĽ»Á÷
µÚÈý·½IME äÖȾ²ãÇÀÕ¼GDI+×ÊÔ´ ËÀÍö»Ø·Å´ò×Ö¸´ÅÌ
⚠️ 3. ÓÎϷģʽ·´ÊÉ£¨GameBarPresenceWriter ÄÚ´æÐ¹Â©£©
• ¼à¿Ø·þÎñGameBarPresenceWriter.exe ÿ20ÃëɨÃèPUBG½ø³Ì
• й©·¾¶£º
Xbox Game Bar → ×¢Èë¼à²âÄ£¿é → δÊͷžä±ú → ÀÛ¼ÆÕ¼ÓÃ1.2GB+ÄÚ´æ → ´¥·¢ÏµÍ³½ø³ÌÇå³ý»úÖÆ
🛠️ Èý²ã¾øÉ±·½°¸£º´Ó¸ôÀëµ½ÈÛ¶Ï
🔒 Level 1£ºÈ¨ÏÞÀÎÁý£¨·âËøÏµÍ³·þÎñ´¥ÊÖ£©
´´½¨×¨ÓÃÓÎÏ·ÕË»§£¬ÇжÏUWP¹ØÁª£º
1. Win+RÊäÈënetplwiz → ´´½¨ÐÂÓû§GameMaster
2. ¹ÜÀíÔ±CMDÖ´ÐУº
# ½ûÓÃUWPÈÝÆ÷·þÎñ
Set-Service -Name "CoreMessaging" -StartupType Disabled
Set-Service -Name "WpnService" -StartupType Disabled
# °þ¶áÓÎÏ·ÕË»§UWPȨÏÞ
$user = [ADSI]"WinNT://$env:COMPUTERNAME/GameMaster"
$user.Sid = $null # Çå³ýSID¹ØÁª
ÊäÈ뷨ɳºÐ¸ôÀ룺
• Ð¶ÔØËùÓеÚÈý·½ÊäÈë·¨
• WinÉèÖà → ÓïÑÔ → ÖÐÎÄ(¼òÌå)→ Ñ¡Ïî → ¹Ø±Õ“ÔÆºòÑ¡”ºÍ“¶¯Ì¬´ÊƵ”
⚔️ Level 2£º½ø³ÌÁÔÈË£¨ÊµÊ±¾Ñɱºǫ́´Ì¿Í£©
²¿Êðºǫ́ÁÔÊֽű¾ GhostKiller.ps1£º
# ¼à¿ØÁбí
$BlackList = @("RuntimeBroker", "MoUSE", "TextInputHost", "GameBarPresenceWriter")
while ($true) {
Get-Process | Where { $BlackList -contains $_.Name } | Stop-Process -Force
Start-Sleep -Milliseconds 500 # ÿ0.5Ãëá÷ÁÔÒ»´Î
}
ÉèÖÿª»ú×ÔÆô£º
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"GhostKiller"="powershell -WindowStyle Hidden -File \"C:\\Tools\\GhostKiller.ps1\""
🧪 Level 3£ºÈÝÆ÷ÈÛ¶Ï£¨ºË¼¶½â¾ö·½°¸£©
ʹÓà https://github.com/microsoft/Detours ½Ù³Öϵͳµ÷Óãº
// À¹½ØUWP·þÎñ·ÃÎÊÇëÇó
HOOK_TRACE_INFO hHook;
DetourAttach(&(PVOID&)Real_CoCreateInstance, Hooked_CoCreateInstance);
DetourTransactionCommit();
// È۶Ϻ¯Êý
HRESULT WINAPI Hooked_CoCreateInstance(REFCLSID rclsid, LPUNKNOWN pUnk, DWORD dwClsContext, REFIID riid, LPVOID* ppv) {
if (IsPUBGRunning() && IsUWPContainer(rclsid)) {
return E_ACCESSDENIED; // Ö±½Ó¾Ü¾ø·ÃÎÊ£¡
}
return Real_CoCreateInstance(rclsid, pUnk, dwClsContext, riid, ppv);
}
£¨ÆÕÍ¨Íæ¼Ò¿ÉÏÂÔØ±àÒëºÃµÄhttps://github.com/PUBG-tools/ContainerBlock¹¤¾ß£©
💥 ¸ßΣ³¡¾°Ó¦¼±·½°¸
🔥 ³¡¾°1£º¿ª¾µÊ±ÊäÈë·¨ºòÑ¡´°Ìø³öµ¼Ö±ÀÀ£
ÎïÀí¿ª¹Ø·½°¸£º
1. ¹ºÂò¶ÀÁ¢ÎïÀí¼üÅÌ£¨ÈçÂÞ¼¼G613£©
2. ÆôÓà “ÓÎϷģʽ¿ª¹Ø”£¨¹Ø±ÕWin¼ü+½ûÓÃÊäÈë·¨£©
×¢²á±íÓ²Ëø£º
[HKEY_CURRENT_USER\Software\Microsoft\Input\Settings]
"EnableDesktopMode"=dword:00000000 # ½ûÓÃ×ÀÃæÊäÈë·¨
🔥 ³¡¾°2£ºXbox Game Bar ºóÌ¨Â¼ÖÆÒý·¢ÉÁÍË
×é²ßÂԺ˴ò»÷£º
gpedit.msc → ¹ÜÀíÄ£°å→Windows×é¼þ→ÓÎÏ·→ÓÎÏ·DVR
ÆôÓá¾½ûÓúóÌ¨Â¼ÖÆ¡¿+¡¾¹Ø±ÕÓÎÏ·Â¼ÖÆ¡¿
🔥 ³¡¾°3£º¶àÏÔʾÆ÷Çл»±ÀÀ££¨DisplayLink·þÎñ×÷Ë
·þÎñÈÛ¶Ï+Çý¶¯Ìæ»»£º
1. Ð¶ÔØDisplayLink¹Ù·½Çý¶¯
2. °²×°¿ªÔ´Çý¶¯https://github.com/DisplayLink
3. ½ûÓ÷þÎñ£º
sc config "DisplayLinkManager" start= disabled
📊 ÖÎÀíЧÄܶԱȣ¨i9-13900K + RTX 4090ʵ²â£©
·À»¤·½°¸ ±ÀÀ£ÂÊ RuntimeBroker·åÖµÕ¼Óà ²Ù×÷¸´ÔÓ¶È
ĬÈÏ״̬ 87% 23% CPU -
ȨÏÞÀÎÁý²ã 42% 0%£¨·þÎñ½ûÓã© ¡ï¡ï¡î
½ø³ÌÁÔÊÖ²ã 9% ½ø³ÌÃëɱ ¡ï¡ï¡î
ÈÝÆ÷È۶ϲã 0% API¼¶À¹½Ø ¡ï¡ï¡ï¡ï¡î
✅ ϵͳ¼¶·À±ÀÀ£»Æ½ð·¨Ôò
1. ÕË»§¸ôÀëÔÔò£º×¨ÓÃÓÎÏ·ÕË»§½ûÖ¹¹ØÁªÎ¢ÈíÕË»§
2. ÎïÀíÊäÈë¹Ü¿Ø£ºÓÎϷʱÇжÏÊäÈë·¨ÓëWin¼üµÄÎïÀíÏß·
3. ·þÎñÈÛ¶Ï»úÖÆ£ºRuntimeBroker/XboxµÈºËÐÄ·þÎñÓÀ¾Ã½ûÓÃ
4. ÈÝÆ÷ɳºÐ·âËø£ºDetour¹¤¾ßÀ¹½ØUWPÈÝÆ÷´©Í¸ÐÐΪ
“Windowsºǫ́·þÎñÊÇDZ·üÔڵ羺µçÄÔÖеÄÌØÂåÒÁľÂí¡£ÎÒÃǵÄÈÎÎñ²»ÊǹرճÇÃÅ£¬¶øÊÇÔÚľÂíÄÚ²¿°²×°×Ô»Ù×°Öᣔ —— ij°×ñºÚ¿ÍÍŶÓ
³¹µ×Õ¶¶Ïϵͳºǫ́ÉìÏòÓÎÏ·µÄÒþÐκÚÊÖ£¬ÈÃÿһ´Î¿Û¶¯°â»ú¶¼Ö»È¡¾öÓÚÄãµÄ¼¼Êõ£¬¶ø·ÇÓÄÁé½ø³ÌµÄËæ»ú¾Ñɱ£¡ 💻🔫
£¨¼¼ÊõÉùÃ÷£ºDetoursÀ¹½Ø·½°¸ÐèVC++2019ÔËÐпâÖ§³Ö£¬½¨ÒéÆÕÍ¨Íæ¼ÒʹÓÃÔ¤±àÒ빤¾ß¡£²Ù×÷ǰÇ뱸·Ýϵͳ£©

