Forums: Process Hide (gui Version) By Q7x - Forums

Jump to content

  • (2 Pages)
  • +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

Process Hide (gui Version) By Q7x powerful tool to hide trojans

#1 User is offline   q7x 

  • Private
  • Icon
  • Group: Members
  • Posts: 10
  • Joined: 22-September 04

Post icon  Posted 27 August 2005 - 04:18 PM

Process Hider is a tool designed to hide your process in windows task manager and tasklist .
this is a powerful tool to hide trojans

<<< GUI Version And Only For Test >>>

Programer :Q7X ( Nima Salehi )
Special Tanx To My Best Friends Behrooz_ice And ActionSpider

Attached File(s)


Nima Salehi www.Ashiyane.ir
0

#2 User is offline   apoc_neo 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 113
  • Joined: 17-September 04

Posted 27 August 2005 - 04:48 PM

Interesting applications, why gui tho? Have you made a dos version? If so please post it :)
0

#3 User is offline   JaG 

  • Sergeant
  • Icon
  • Group: Specialist
  • Posts: 209
  • Joined: 10-August 03

Posted 27 August 2005 - 05:50 PM

I tested it in vmware, and it put a rootkit infected file into a driver folder...so beware.

system32/drivers/rundll32.exe

rootkit.win32.agent.x
0

#4 User is offline   q7x 

  • Private
  • Icon
  • Group: Members
  • Posts: 10
  • Joined: 22-September 04

Posted 27 August 2005 - 09:42 PM

hi
this GUI version is only for test
i will write binder for use this method and hide trojan ;)
Nima Salehi www.Ashiyane.ir
0

#5 User is offline   LittleHacker 

  • Master Sergeant
  • Icon
  • Group: Members
  • Posts: 453
  • Joined: 17-October 04

Posted 27 August 2005 - 10:27 PM

Hi Nima
nice 2 c u again.
If I were you I'd do it with CLI abilities (as foundstone sometimes does).
you may add some extra feactures too. such as converting a simple process to a service (look illwill's stuff)
anyway thanks for progi & keep good workin ...
0

#6 User is offline   GhostShell 

  • Sergeant First Class
  • Icon
  • Group: Members
  • Posts: 343
  • Joined: 07-May 05

Posted 27 August 2005 - 11:38 PM

Quote

Process Magic V1.0 By WinEggDrop

rundll32 -List          ----> List Processes And Show Hidden Processes
rundll32 -Hide PID      ----> Hide A Process

lol you could atleast give props to wineggdrop or give all credit to them...
look in "%windir%\system32\drivers\rundll32.exe"
this is just a GUI for pm.exe...kinda like that GUI of upx for skiddies
other than that nice job...
I just dont know why you didnt give any credit to wineggdrop
"As a young boy, I was taught in high school that hacking was cool." -Kevin Mitnick

"It's easy to point and click programs, but thats not real hacking." -illwill
0

#7 User is offline   LittleHacker 

  • Master Sergeant
  • Icon
  • Group: Members
  • Posts: 453
  • Joined: 17-October 04

Posted 28 August 2005 - 12:16 AM

@ Q7X
This is not a process hider! this is a task/window hider! if you hide a process it would not be shown in process list. something like rootkit's do. or you may do a process injection to hide a process (in another one)
this progi just make a visible window to invisible one ...

@ GhostShell
there are many process manager and pm is not the only one.
nothing undocumented here and there are many source codes too that do di in several ways (giving PID,giving ProcessImage, Clickin on the window , ...).
anyway rundll is located in %systemroot%\system32 and do not accept parameters you said... you may renamed pm to %windir%\system32\drivers\rundll32.exe
you don't need any extra progi on win xp & later. just run tasklist in console.
0

#8 User is offline   [R] 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 101
  • Joined: 14-March 04

Posted 28 August 2005 - 12:53 AM

what a shit...

got only a warning by the AV...
0

#9 User is offline   GhostShell 

  • Sergeant First Class
  • Icon
  • Group: Members
  • Posts: 343
  • Joined: 07-May 05

Posted 28 August 2005 - 01:07 AM

LittleHacker, on Aug 28 2005, 08:16 AM, said:

@  Q7X
This is not a process hider! this is a task/window hider! if you hide a process it would not be shown in process list. something like rootkit's do. or you may do a process injection to hide a process (in another one)
this progi just make a visible window to invisible one ...

@ GhostShell
there are many process manager and pm is not the only one.
nothing undocumented here and there are many source codes too that do di in several ways (giving PID,giving ProcessImage, Clickin on the window , ...).
anyway rundll is located in %systemroot%\system32 and do not accept parameters you said... you may renamed pm to %windir%\system32\drivers\rundll32.exe
you don't need any extra progi on win xp & later. just run tasklist in console.

whatcha talking about this uses almost only pm.exe take a look
"As a young boy, I was taught in high school that hacking was cool." -Kevin Mitnick

"It's easy to point and click programs, but thats not real hacking." -illwill
0

#10 User is offline   rasraven 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 64
  • Joined: 24-March 04

Posted 28 August 2005 - 01:08 AM

well. I think he binded that pm and piped to it & AVs are sensitive to binders
0

#11 User is offline   LittleHacker 

  • Master Sergeant
  • Icon
  • Group: Members
  • Posts: 453
  • Joined: 17-October 04

Posted 28 August 2005 - 01:13 AM

oh! you meant using exe/lib/ocx as a resource ?
I think I should have look ...

Nima you can develop your own prog with no extra stuff. that's nothing special.
0

#12 User is offline   roder 

  • Private
  • Icon
  • Group: Members
  • Posts: 6
  • Joined: 23-June 05

Posted 29 August 2005 - 04:11 PM

process hide whit this program, show with knlps10.exe

h**p://www.hxdef.org/download/knlps10.zip
0

#13 User is offline   emailpack 

  • Private
  • Icon
  • Group: Members
  • Posts: 4
  • Joined: 05-February 04

Post icon  Posted 29 August 2005 - 08:48 PM

roder, on Aug 30 2005, 12:11 AM, said:

process hide whit this program, show with knlps10.exe

h**p://www.hxdef.org/download/knlps10.zip






The process hider, works for time, when a kid gets out its, bed and realises theres
nothing more, then encrypted injected trojan horses, in his computer being tapped out, of his room and killed processes, that is computer is defenseless against, such threats because it couldnt programm, so why waste time on this, while knowing windows itself is more, a bigger threath then a hacker, ya know what Im talkin about, well just keep that in mind, let me know if u, got a better suggestion.

Holler at ya boy, emailpack.
0

#14 User is offline   st4n 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 48
  • Joined: 23-December 03

Posted 02 September 2005 - 03:37 AM

i like thos program, very useful!
As already said, parameter option would be really nice!
0

#15 User is offline   God 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 27
  • Joined: 10-October 05

Post icon  Posted 12 October 2005 - 09:40 AM

I think and truss up can be better, then avoid killing , it can be a bit better to do by inserting the process, for example insert rootkit which you need and a wanton systematic process.
0

  • (2 Pages)
  • +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting