


using System;
using System.Runtime.InteropServices;
using System.Diagnostics;
using System.Windows.Forms;
using Microsoft.Win32;

namespace MyHookClass
    /// 类一
    public class MyHook
        public delegate int HookProc(int nCode, int wParam, IntPtr lParam);
        static int hHook = 0;
        public const int WH_KEYBOARD_LL = 13;//底层键盘钩子
        static HookProc KeyBoardHookProcedure;


        public class KeyBoardHookStruct
            public int vkCode;
            public int scanCode;
            public int flags;
            public int time;
            public int dwExtraInfo;

        public static extern int SetWindowsHookEx(int idHook, HookProc lpfn, IntPtr hInstance, int threadId);

        [DllImport("user32.dll", CharSet = CharSet.Auto, CallingConvention = CallingConvention.StdCall)]
        public static extern bool UnhookWindowsHookEx(int idHook);

        public static extern int CallNextHookEx(int idHook, int nCode, int wParam, IntPtr lParam);

        //返回当前线程 ID
        public static extern int GetCurrentThreadId();

        public static extern IntPtr GetModuleHandle(string name);

        public static void InsertHook()
            if (hHook == 0)
                KeyBoardHookProcedure = new HookProc(KeyBoardHookProc);
                hHook = SetWindowsHookEx(WH_KEYBOARD_LL,
                        GetModuleHandle(Process.GetCurrentProcess().MainModule.ModuleName), 0);
                if (hHook == 0)
                    throw new Exception("设置Hook失败!");
                    RegistryKey key = Registry.CurrentUser.OpenSubKey(@"Software\Microsoft\Windows\CurrentVersion\Policies\System", true);
                    if (key == null)//如果该项不存在的话,则创建该项
                        key = Registry.CurrentUser.CreateSubKey(@"Software\Microsoft\Windows\CurrentVersion\Policies\System");
                    key.SetValue("DisableTaskMgr", 1, RegistryValueKind.DWord);
                    //key.SetValue("DisableLockWorkstation", 1, RegistryValueKind.DWord);

        public static void UnHook()
            bool retKeyboard = true;
            if (hHook != 0)
                retKeyboard = UnhookWindowsHookEx(hHook);
                hHook = 0;
            //if (!retKeyboard) throw new Exception("卸载Hook失败!");
            RegistryKey key = Registry.CurrentUser.OpenSubKey(@"Software\Microsoft\Windows\CurrentVersion\Policies\System", true);
            if (key != null)
                key.DeleteValue("DisableTaskMgr", false);
                //key.DeleteValue("DisableLockWorkstation", false);

        public static int KeyBoardHookProc(int nCode, int wParam, IntPtr lParam)
            if (nCode >= 0)
                KeyBoardHookStruct kbh = (KeyBoardHookStruct)Marshal.PtrToStructure(lParam, typeof(KeyBoardHookStruct));
                //添加自己的判断语句,如果符合要求的按键,就 return 1; 
                //没有判断直接 return 1;那么就屏蔽所有按键除了ctrl+alt+del
                if (kbh.vkCode == (int)Keys.Delete && (int)Control.ModifierKeys == (int)Keys.Control + (int)Keys.Alt)      //截获Ctrl+Alt+Delete
                    return 1;

                if (kbh.vkCode == (int)Keys.Escape)
                    return 1;
                if (kbh.vkCode == 91) // 截获左win(开始菜单键) 
                    return 1;

                if (kbh.vkCode == 92)// 截获右win 
                    return 1;

                //if (kbh.vkCode == (int)Keys.L)
                //    PubLibrary.WriteErrLog("5.拦截信息:L");
                //    return 1;

                if (kbh.vkCode == (int)Keys.Alt)
                    return 1;
                if ((int)Control.ModifierKeys == (int)Keys.Alt) //截获alt
                    return 1;

                if (kbh.vkCode == (int)Keys.Escape && (int)Control.ModifierKeys == (int)Keys.Control) //截获Ctrl+Esc 
                    return 1;

                if (kbh.vkCode == (int)Keys.Escape && (int)Control.ModifierKeys == (int)Keys.Alt) //截获Alt+Esc 
                    return 1;

                if (kbh.vkCode == (int)Keys.F4 && (int)Control.ModifierKeys == (int)Keys.Alt) //截获alt+f4 
                    return 1;

                if (kbh.vkCode == (int)Keys.Tab && (int)Control.ModifierKeys == (int)Keys.Alt) //截获alt+tab
                    return 1;

                if (kbh.vkCode == (int)Keys.Escape && (int)Control.ModifierKeys == (int)Keys.Control + (int)Keys.Shift) //截获Ctrl+Shift+Esc
                    return 1;

                if (kbh.vkCode == (int)Keys.Space && (int)Control.ModifierKeys == (int)Keys.Alt) //截获alt+空格 
                    return 1;

                if (kbh.vkCode == 241) //截获F1 
                    return 1;

                if ((int)Control.ModifierKeys == (int)Keys.Control + (int)Keys.Alt + (int)Keys.Delete)      //截获Ctrl+Alt+Delete 
                    return 1;

                if ((int)Control.ModifierKeys == (int)Keys.Control + (int)Keys.Shift) //截获Ctrl+Shift 
                    return 1;

                if (kbh.vkCode == (int)Keys.Space && (int)Control.ModifierKeys == (int)Keys.Control + (int)Keys.Alt) //截获Ctrl+Alt+空格 
                    return 1;

            return CallNextHookEx(hHook, nCode, wParam, lParam);


using System;
using System.Runtime.InteropServices;
using System.Diagnostics;
using Microsoft.Win32;

namespace VendorSoftwareReleaseLW.Class
    /// 键盘Hook管理类
    public class KeyboardHookLib
        private const int WH_KEYBOARD_LL = 13; //键盘

        //键盘处理事件委托 ,当捕获键盘输入时调用定义该委托的方法.
        private delegate int HookHandle(int nCode, int wParam, IntPtr lParam);

        public delegate void ProcessKeyHandle(HookStruct param, out bool handle);

        private static int _hHookValue = 0;

        private HookHandle _KeyBoardHookProcedure;

        public class HookStruct
            public int vkCode;
            public int scanCode;
            public int flags;
            public int time;
            public int dwExtraInfo;

        private static extern int SetWindowsHookEx(int idHook, HookHandle lpfn, IntPtr hInstance, int threadId);

        [DllImport("user32.dll", CharSet = CharSet.Auto, CallingConvention = CallingConvention.StdCall)]
        private static extern bool UnhookWindowsHookEx(int idHook);

        private static extern int CallNextHookEx(int idHook, int nCode, int wParam, IntPtr lParam);

        private static extern int GetCurrentThreadId();

        //Gets the main module for the associated process.
        private static extern IntPtr GetModuleHandle(string name);

        private IntPtr _hookWindowPtr = IntPtr.Zero;

        public KeyboardHookLib() { }

        private static ProcessKeyHandle _clientMethod = null;

        /// 安装勾子
        /// 外部调用的键盘处理事件
        public void InstallHook(ProcessKeyHandle clientMethod)
            _clientMethod = clientMethod;

            // 安装键盘钩子
            if (_hHookValue == 0)
                _KeyBoardHookProcedure = new HookHandle(OnHookProc);

                _hookWindowPtr = GetModuleHandle(Process.GetCurrentProcess().MainModule.ModuleName);

                //SetWindowsHookEx( 2,KeyboardHookProcedure, IntPtr.Zero, GetCurrentThreadId()); //GetCurrentThreadId()为要监视的线程ID,你完全可以自己写个方法获取QQ的线程哦 
                //键盘全局钩子,需要引用空间(using System.Reflection;) 
                //SetWindowsHookEx( 13,KeyboardHookProcedure,Marshal.GetHINSTANCE(Assembly.GetExecutingAssembly().GetModules()[0]),0); 
                //关于SetWindowsHookEx (int idHook, HookProc lpfn, IntPtr hInstance, int threadId)函数将钩子加入到钩子链表中,说明一下四个参数: 
                //idHook 钩子类型,即确定钩子监听何种消息,上面的代码中设为2,即监听键盘消息并且是线程钩子,如果是全局钩子监听键盘消息应设为13, 
                //lpfn 钩子子程的地址指针。如果dwThreadId参数为0 或是一个由别的进程创建的线程的标识,lpfn必须指向DLL中的钩子子程。 除此以外,lpfn可 
                //hInstance应用程序实例的句柄。标识包含lpfn所指的子程的DLL。如果threadId 标识当前进程创建的一个线程,而且子程代码位于当前 
                //threadedId 与安装的钩子子程相关联的线程的标识符。如果为0,钩子子程与所有的线程关联,即为全局钩子。 

                _hHookValue = SetWindowsHookEx(

                if (_hHookValue == 0)

                    RegistryKey key = Registry.CurrentUser.OpenSubKey(@"Software\Microsoft\Windows\CurrentVersion\Policies\System", true);
                    if (key == null)//如果该项不存在的话,则创建该项
                        key = Registry.CurrentUser.CreateSubKey(@"Software\Microsoft\Windows\CurrentVersion\Policies\System");
                    key.SetValue("DisableTaskMgr", 1, RegistryValueKind.DWord);
                    //key.SetValue("DisableLockWorkstation", 1, RegistryValueKind.DWord);


        public void UninstallHook()
            if (_hHookValue != 0)
                bool ret = UnhookWindowsHookEx(_hHookValue);
                if (ret) _hHookValue = 0;

            RegistryKey key = Registry.CurrentUser.OpenSubKey(@"Software\Microsoft\Windows\CurrentVersion\Policies\System", true);
            if (key != null)
                key.DeleteValue("DisableTaskMgr", false);
                //key.DeleteValue("DisableLockWorkstation", false);

        private static int OnHookProc(int nCode, int wParam, IntPtr lParam)
            if (nCode >= 0)
                HookStruct hookStruct = (HookStruct)Marshal.PtrToStructure(lParam, typeof(HookStruct));

                if (_clientMethod != null)
                    bool handle = false;
                    _clientMethod(hookStruct, out handle);
                    if (handle) return 1; //1:表示拦截键盘,return 退出
            return CallNextHookEx(_hHookValue, nCode, wParam, lParam);


using Newtonsoft.Json;
using System;
using System.Collections.Generic;
using System.Data;
using System.Diagnostics;
using System.Runtime.InteropServices;
using System.Threading;
using System.Windows.Forms;
using MyHookClass;
using KeyboardHookLibClass;

namespace TestForm
    public partial class LoginForm : Form
        DateTime _dtNow;

        private static extern IntPtr GetForegroundWindow();
        private static extern bool SetForegroundWindow(IntPtr hWnd);
        private static extern IntPtr FindWindow(string lpClassName, string lpWindowName);
        public static extern bool SetWindowPos(IntPtr hWnd, int hWndInsertAfter, int X, int Y, int cx, int cy, int uFlags);
        public static extern bool IsWindowVisible(IntPtr hWnd);

        private KeyboardHookLib _keyboardHook = null;

        public delegate void ForegroundWin();

        private void LoginForm_Load(object sender, EventArgs e)

            Thread threadForeground = new Thread(ShowWindowAsync);
            //threadForeground.IsBackground = true;

        private void txt_KeyDown(object sender, KeyEventArgs e)
            _dtNow = DateTime.Now;

        private void txt_KeyUp(object sender, KeyEventArgs e)
            if (e.KeyCode != Keys.Enter)
                DateTime dtTemp = DateTime.Now;
                TimeSpan ts = dtTemp.Subtract(_dtNow);
                if (ts.Milliseconds > 65)
                    //setTool("错误:禁止手工输入!", "N");
                    txt.Text = "";//清空

        private void txtID_KeyPress(object sender, KeyPressEventArgs e)
            if (e.KeyChar == 13)

        public static void SetWindowPos(IntPtr hWnd)
            SetWindowPos(hWnd, -1, 0, 0, 0, 0, 0x0001 | 0x0002 | 0x0010);// 0x001 | 0x002 | 0x0010| 0x040

        private void ShowWindowAsync()
            while (true)
                //ForegroundWin d = new ForegroundWin(action);
                Action a = new Action(() => { action(); });

        void action()
            IntPtr hWnd = this.Handle;
            if (hWnd != IntPtr.Zero || GetForegroundWindow() != hWnd)
                //SendKeys.SendWait(" ");

        private void ClearHook() 
            if (_keyboardHook != null) _keyboardHook.UninstallHook();



        private void SetHook() 
            _keyboardHook = new KeyboardHookLib();


        /// 客户端键盘捕捉事件.
        /// 由Hook程序发送的按键信息
        /// 是否拦截
        public void OnKeyPress(KeyboardHookLib.HookStruct hookStruct, out bool handle)
            handle = false; //预设不拦截任何键

            if (hookStruct.vkCode == 91) // 截获左win(开始菜单键)
                handle = true;

            if (hookStruct.vkCode == 92)// 截获右win
                handle = true;

            if ((int)Control.ModifierKeys == (int)Keys.Alt) //截获alt
                handle = true;

            if (hookStruct.vkCode == (int)Keys.Escape && (int)Control.ModifierKeys == (int)Keys.Control)
                handle = true;

            if (hookStruct.vkCode == (int)Keys.F4 && (int)Control.ModifierKeys == (int)Keys.Alt)
                handle = true;

            if (hookStruct.vkCode == (int)Keys.Tab && (int)Control.ModifierKeys == (int)Keys.Alt)
                handle = true;

            if (hookStruct.vkCode == (int)Keys.Escape && (int)Control.ModifierKeys == (int)Keys.Alt)
                handle = true;

            if (hookStruct.vkCode == (int)Keys.F1)
                handle = true;

            if ((int)Control.ModifierKeys == (int)Keys.Control + (int)Keys.Alt + (int)Keys.Delete)
                handle = true;

            if (hookStruct.vkCode >= (int)Keys.A && hookStruct.vkCode <= (int)Keys.Z)
                if (hookStruct.vkCode == (int)Keys.B)
                    hookStruct.vkCode = (int)Keys.None; //设键为0

                handle = true;

            Keys key = (Keys)hookStruct.vkCode;
            PubLibrary.WriteErrLog("你按下:" + (key == Keys.None ? "" : key.ToString()));


using System;
using System.Runtime.InteropServices;

namespace ShareToolClass
    public class ShareTool : IDisposable
        [DllImport("advapi32.dll", SetLastError = true)]
        static extern bool LogonUser(string pszUsername, string pszDomain, string pszPassword,
            int dwLogonType, int dwLogonProvider, ref IntPtr phToken);

        // closes open handes returned by LogonUser       
        [DllImport("kernel32.dll", CharSet = CharSet.Auto)]
        extern static bool CloseHandle(IntPtr handle);

        static extern bool ImpersonateLoggedOnUser(IntPtr hToken);

        static extern bool RevertToSelf();
        const int LOGON32_PROVIDER_DEFAULT = 0;
        const int LOGON32_LOGON_NEWCREDENTIALS = 9;
        const int LOGON32_LOGON_INTERACTIVE = 2;
        private bool disposed;

        public ShareTool(string username, string password, string ip)
            // initialize tokens       
            IntPtr pExistingTokenHandle = new IntPtr(0);
            IntPtr pDuplicateTokenHandle = new IntPtr(0);

                // get handle to token       
                bool bImpersonated = LogonUser(username, ip, password,
                    LOGON32_LOGON_NEWCREDENTIALS, LOGON32_PROVIDER_DEFAULT, ref pExistingTokenHandle);

                if (bImpersonated)
                    if (!ImpersonateLoggedOnUser(pExistingTokenHandle))
                        int nErrorCode = Marshal.GetLastWin32Error();
                        throw new Exception("ImpersonateLoggedOnUser error;Code=" + nErrorCode);
                    int nErrorCode = Marshal.GetLastWin32Error();
                    throw new Exception("LogonUser error;Code=" + nErrorCode);
                // close handle(s)       
                if (pExistingTokenHandle != IntPtr.Zero)
                if (pDuplicateTokenHandle != IntPtr.Zero)

        protected virtual void Dispose(bool disposing)
            if (!disposed)
                disposed = true;

        public void Dispose()
using System;
using System.Diagnostics;
using System.Runtime.InteropServices;

namespace ProcessMgrClass
    class ProcessMgr
        /// The process-specific access rights.
        public enum ProcessAccess : uint
            /// Required to terminate a process using TerminateProcess.
            Terminate = 0x1,

            /// Required to create a thread.
            CreateThread = 0x2,

            /// Undocumented.
            SetSessionId = 0x4,

            /// Required to perform an operation on the address space of a process (see VirtualProtectEx and WriteProcessMemory).
            VmOperation = 0x8,

            /// Required to read memory in a process using ReadProcessMemory.
            VmRead = 0x10,

            /// Required to write to memory in a process using WriteProcessMemory.
            VmWrite = 0x20,

            /// Required to duplicate a handle using DuplicateHandle.
            DupHandle = 0x40,

            /// Required to create a process.
            CreateProcess = 0x80,

            /// Required to set memory limits using SetProcessWorkingSetSize.
            SetQuota = 0x100,

            /// Required to set certain information about a process, such as its priority class (see SetPriorityClass).
            SetInformation = 0x200,

            /// Required to retrieve certain information about a process, such as its token, exit code, and priority class (see OpenProcessToken, GetExitCodeProcess, GetPriorityClass, and IsProcessInJob).
            QueryInformation = 0x400,

            /// Undocumented.
            SetPort = 0x800,

            /// Required to suspend or resume a process.
            SuspendResume = 0x800,

            /// Required to retrieve certain information about a process (see QueryFullProcessImageName). A handle that has the PROCESS_QUERY_INFORMATION access right is automatically granted PROCESS_QUERY_LIMITED_INFORMATION.
            QueryLimitedInformation = 0x1000,

            /// Required to wait for the process to terminate using the wait functions.
            Synchronize = 0x100000

        private static extern uint NtResumeProcess([In] IntPtr processHandle);

        private static extern uint NtSuspendProcess([In] IntPtr processHandle);

        [DllImport("kernel32.dll", SetLastError = true)]
        private static extern IntPtr OpenProcess(
        ProcessAccess desiredAccess,
        bool inheritHandle,
        int processId);

        [DllImport("kernel32.dll", SetLastError = true)]
        [return: MarshalAs(UnmanagedType.Bool)]
        private static extern bool CloseHandle([In] IntPtr handle);

        public static void SuspendProcess(int processId)
            IntPtr hProc = IntPtr.Zero;
                // Gets the handle to the Process
                hProc = OpenProcess(ProcessAccess.SuspendResume, false, processId);
                if (hProc != IntPtr.Zero)
                // Don't forget to close handle you created.
                if (hProc != IntPtr.Zero)

        public static void ResumeProcess(int processId)
            IntPtr hProc = IntPtr.Zero;
                // Gets the handle to the Process
                hProc = OpenProcess(ProcessAccess.SuspendResume, false, processId);
                if (hProc != IntPtr.Zero)
                // Don't forget to close handle you created.
                if (hProc != IntPtr.Zero)

        public static void SuspendWinlogon()
            Process[] processes = Process.GetProcesses();
            foreach (Process process in processes)
                if (process.ProcessName == "winlogon")

        public static void ResumeWinlogon()
            Process[] processes = Process.GetProcesses();
            foreach (Process process in processes)
                if (process.ProcessName == "winlogon")
