how are you
how can i hide my exe from task manager while it running
how are you
how can i hide my exe from task manager while it running
well, gess it's not possible with managed code
try to find some solution in unmanaged code
العمل كثير و الوقت قليل أعاننا الله
thank you
but what do you mean by manged and unmanaged code
بن العيد كتب:السلام عليكــم ورحمـة الله وبركاتــهthis.Text=String.Empty;
أظن ان هذا يخفيه من قائمة ال Applications لكن يبقى البرنامج موجود في ال Processes .
ربما كما قال اخي fkugd2003 ،
لا اعلم اذا كانت C# توفر هذه الامكانية ،،
لكن بكل تأكد ممكن مع unmanaged code.
اقتباسbut what do you mean by manged and unmanaged code
من كتاب Programming Microsoft Visual C# 2005: The Language
Chapter 15: Unsafe Code Overview Unsafe code can access unmanaged memory, which is outside the realm of the Common Language Runtime (CLR). Conversely, safe code is limited to accessing the managed heap. The managed heap is controlled by the CLR under the auspices of the garbage collector (GC). Code that addresses the managed heap is intrinsically safer. The CLR automatically releases unused objects, performs type verification, and conducts other checks on managed memory. Developers can focus on core application development instead of administrative tasks such as memory management. For this reason, safe code improves user productivity and satisfaction. Pointers to unmanaged memory are available in unsafe code. Like unmanaged memory, pointers are also outside the realm of the CLR. Pointers point to a fixed location in unmanaged memory, whereas reference types point to a moveable location in managed memory. The CLR manages reference types, which includes controlling the lifetime of objects and calling cleanup code. Developers do not delete memory allocated for reference types and are not overly involved in the intricacies of memory management. In C and C++ application development, developers were preoccupied with memory management. Despite this, improper management of pointers is a primary contributor to unsafe code in the unmanaged environment, including memory leaks, access of invalid memory, deletion of pointers, and fence post errors. Abstracting the nuances of pointer management and manipulation with reference types has made managed code considerably safer. However, when needed, you can exempt yourself from secure code and access pointers directly. When is unsafe code appropriate? Not often. Unsafe code is provided within C# as the exception, not the rule. There are specific circumstances in which unsafe code is recommended: Unmanaged code often relies heavily on pointers. When porting this sort of code to C#, unsafe code is a possible solution. Most nontrivial C and C++ programmers heavily leverage pointers. Implementing a software algorithm, in which pointers are integral to the design, might necessitate unsafe code. Calling an unmanaged function might require function pointers. Pointers might be required when working with binary memory resident data structures. Unmanaged pointers might improve performance and efficiencies in certain circumstances.
اني وان كنت الاخير زمانه ---- لأتِ بما لم تستطعه الاوائلُ
حسبما اعرف ان الامر يتطلب القيام بعمليات على مستوى النواة -_-
عن طريق درايفر (حسب ما تكلم عنه Ms-Rem ).. حاليا انا اراجع بعض المقالات و ارجو ان اتمكن
من تحويل الكود الى سي شارب على الرغم اني ارجو ان يكون فعالا :lol:
الفكرة بسيطة نوعا ما ادا قمنا بحقن مكتبة ربط ديناميكي و القيام بعملية هوكينق hooking
لكل الدوال مثل NtQuerySystemInformation بدلك لن نضطر الى كتابة درايفر ;)
لي رجعة ان شاء الله الى الموضوع
ربما GM يمكن ان يفيدنا بشيئ حتى لو كان بسي :lol:
العمل كثير و الوقت قليل أعاننا الله
السلام عليكم ورحمة الله وبركاته
يمكنك الاستعاضة عن إخفاء البرنامج من Proccess بجعله غير قابل للإنهاء وذلك بتسمية الEXE باسم Service من خدمات ويندوز جرب LSASS.EXE عندها يصبح البرنامج غير قابل للإنهاء
هذا والله أعلم.
أعوذ بالله من الشيطان الرجيم
قل إنّ صلاتي و نسكي و محيّاي و مماتي لله رب العالمين
صدق الله العظيم
الامر ممكن مع الكرنل بكتابة درايفر على دوال ال *Zw ،، ثم تقوم فقط بتحميل الدرايفر من ال user mode .
لكن ايضا الامر ممكن بدون الدخول الى الكرنل ،، عن طريق دوال * Nt ،،
اني وان كنت الاخير زمانه ---- لأتِ بما لم تستطعه الاوائلُ
نفس الشيئ الدي تكلمت عنه
ربما ان شاء الله نقترح القيام بشيئ مماثل في المنتدى من اجل العلم و التسلية ;)
المهم لا تعملوها و تقترحوه قبل فبراير لاني غارق في الاعمال :lol:
العمل كثير و الوقت قليل أعاننا الله
طبعا ال hide process من مميزات ال Rootkit و تطبيقها موجود في كتاب ال Rootkit ،،
انا سبق وان نفذته .. مع ال ddk و السي و ليس C# :D
اني وان كنت الاخير زمانه ---- لأتِ بما لم تستطعه الاوائلُ
اقتباسانا سبق وان نفذته .. مع ال ddk و السي و ليس C#
انا اريد ان اعرفها قبل الاخرين :D
اظن ان تغليف دوال ntdll موجود في C#
الباقي القليل فقط من التعب
العمل كثير و الوقت قليل أعاننا الله
اقتباساظن ان تغليف دوال ntdll موجود في C#
لا اعتقد ،، <_<
لكن ربما ،، اذا وجدت شيئا اخبرنا به :D
اني وان كنت الاخير زمانه ---- لأتِ بما لم تستطعه الاوائلُ
[DllImport("ntdll.dll", ExactSpelling = true, SetLastError = true)]
public static extern int NtCreateFile(
out SafeFileHandle handle,
FileAccess access,
OBJECT_ATTRIBUTES* objectAttributes,
IO_STATUS_BLOCK* ioStatus,
ref long allocSize,
uint fileAttributes,
FileShare share,
uint createDisposition,
uint createOptions,
IntPtr eaBuffer,
uint eaLength);
[DllImport("ntdll.dll")]
public static extern int NtOpenDirectoryObject(
out SafeFileHandle DirectoryHandle,
uint DesiredAccess,
ref OBJECT_ATTRIBUTES ObjectAttributes);ممم وجدت بعضها :lol:
www.pInvoke.net
تم تعديل هذه المشاركة بواسطة fkugd2003 في 7 يناير 2009 في 19:39
العمل كثير و الوقت قليل أعاننا الله
و لكن هذا ليس تغليف ،، يعني استدعاء يدويا
اني وان كنت الاخير زمانه ---- لأتِ بما لم تستطعه الاوائلُ
ادن نغلفه نحن
نضع كل الاستدعائات داخل كلاس و نريح انفسنا :lol:
سوف اخربش فيها قليلا و اضع النتيجة هنا
العمل كثير و الوقت قليل أعاننا الله
اقتباسادن نغلفه نحننضع كل الاستدعائات داخل كلاس و نريح انفسنا
سوف اخربش فيها قليلا و اضع النتيجة هنا
يا سلام .. جميل ،، بالتوفيق
صراحة لا املك الكثير من الوقت لأخربش معك :lol:
اني وان كنت الاخير زمانه ---- لأتِ بما لم تستطعه الاوائلُ