الفريق العربي للبرمجةأرشيف المنتديات · 2000 – 2023
نسخة أرشيفية للقراءة فقط — التسجيل والمشاركة مغلقان، والمحتوى محفوظ كما كان.

Hide My Exe From Task Manager

بدأه YAR في 4 يناير 2009 · 15 رد · 1,508 مشاهدة · في Microsoft Visual C#.NET
مشاركة: واتساب X فيسبوك تيليجرام
#1 صاحب الموضوع

how are you

how can i hide my exe from task manager while it running

#2

well, gess it's not possible with managed code

try to find some solution in unmanaged code

العمل كثير و الوقت قليل أعاننا الله

seo zen SEO Enlightment amazon danbo

#3

thank you

but what do you mean by manged and unmanaged code

#4

السلام عليكــم ورحمـة الله وبركاتــه

this.Text=String.Empty;

#5
بن العيد كتب:
السلام عليكــم ورحمـة الله وبركاتــه

this.Text=String.Empty;

أظن ان هذا يخفيه من قائمة ال Applications لكن يبقى البرنامج موجود في ال Processes .

ربما كما قال اخي fkugd2003 ،

لا اعلم اذا كانت C# توفر هذه الامكانية ،،

لكن بكل تأكد ممكن مع unmanaged code.

اقتباس
but what do you mean by manged and unmanaged code

من كتاب Programming Microsoft Visual C# 2005: The Language

Chapter 15: Unsafe Code
Overview
Unsafe code can access unmanaged memory, which is outside the realm of the Common Language Runtime (CLR). Conversely, safe code is limited to accessing the managed heap. The managed heap is controlled by the CLR under the auspices of the garbage collector (GC). Code that addresses the managed heap is intrinsically safer. The CLR automatically releases unused objects, performs type verification, and conducts other checks on managed memory. Developers can focus on core application development instead of administrative tasks such as memory management. For this reason, safe code improves user productivity and satisfaction.

Pointers to unmanaged memory are available in unsafe code. Like unmanaged memory, pointers are also outside the realm of the CLR. Pointers point to a fixed location in unmanaged memory, whereas reference types point to a moveable location in managed memory. The CLR manages reference types, which includes controlling the lifetime of objects and calling cleanup code. Developers do not delete memory allocated for reference types and are not overly involved in the intricacies of memory management. In C and C++ application development, developers were preoccupied with memory management. Despite this, improper management of pointers is a primary contributor to unsafe code in the unmanaged environment, including memory leaks, access of invalid memory, deletion of pointers, and fence post errors. Abstracting the nuances of pointer management and manipulation with reference types has made managed code considerably safer. However, when needed, you can exempt yourself from secure code and access pointers directly.

When is unsafe code appropriate? Not often. Unsafe code is provided within C# as the exception, not the rule. There are specific circumstances in which unsafe code is recommended:

Unmanaged code often relies heavily on pointers. When porting this sort of code to C#, unsafe code is a possible solution. Most nontrivial C and C++ programmers heavily leverage pointers.

Implementing a software algorithm, in which pointers are integral to the design, might necessitate unsafe code.

Calling an unmanaged function might require function pointers.

Pointers might be required when working with binary memory resident data structures.

Unmanaged pointers might improve performance and efficiencies in certain circumstances.

/index.php/topic/264448-%D8%A7%D9%84%D8%A8%D8%AF%D8%A7%D9%8A%D8%A9-%D9%85%D8%B9-%D8%A7%D9%84%D8%A7%D9%86%D8%AF%D8%B1%D9%88%D9%8A%D8%AF/

 

اني وان كنت الاخير زمانه ---- لأتِ بما لم تستطعه الاوائلُ

#6

حسبما اعرف ان الامر يتطلب القيام بعمليات على مستوى النواة -_-

عن طريق درايفر (حسب ما تكلم عنه Ms-Rem ).. حاليا انا اراجع بعض المقالات و ارجو ان اتمكن

من تحويل الكود الى سي شارب على الرغم اني ارجو ان يكون فعالا :lol:

الفكرة بسيطة نوعا ما ادا قمنا بحقن مكتبة ربط ديناميكي و القيام بعملية هوكينق hooking

لكل الدوال مثل NtQuerySystemInformation بدلك لن نضطر الى كتابة درايفر ;)

لي رجعة ان شاء الله الى الموضوع

ربما GM يمكن ان يفيدنا بشيئ حتى لو كان بسي :lol:

العمل كثير و الوقت قليل أعاننا الله

seo zen SEO Enlightment amazon danbo

#7

السلام عليكم ورحمة الله وبركاته

يمكنك الاستعاضة عن إخفاء البرنامج من Proccess بجعله غير قابل للإنهاء وذلك بتسمية الEXE باسم Service من خدمات ويندوز جرب LSASS.EXE عندها يصبح البرنامج غير قابل للإنهاء

هذا والله أعلم.

أعوذ بالله من الشيطان الرجيم

قل إنّ صلاتي و نسكي و محيّاي و مماتي لله رب العالمين

صدق الله العظيم

#8

الامر ممكن مع الكرنل بكتابة درايفر على دوال ال *Zw ،، ثم تقوم فقط بتحميل الدرايفر من ال user mode .

لكن ايضا الامر ممكن بدون الدخول الى الكرنل ،، عن طريق دوال * Nt ،،

/index.php/topic/264448-%D8%A7%D9%84%D8%A8%D8%AF%D8%A7%D9%8A%D8%A9-%D9%85%D8%B9-%D8%A7%D9%84%D8%A7%D9%86%D8%AF%D8%B1%D9%88%D9%8A%D8%AF/

 

اني وان كنت الاخير زمانه ---- لأتِ بما لم تستطعه الاوائلُ

#9

نفس الشيئ الدي تكلمت عنه

ربما ان شاء الله نقترح القيام بشيئ مماثل في المنتدى من اجل العلم و التسلية ;)

المهم لا تعملوها و تقترحوه قبل فبراير لاني غارق في الاعمال :lol:

العمل كثير و الوقت قليل أعاننا الله

seo zen SEO Enlightment amazon danbo

#10

طبعا ال hide process من مميزات ال Rootkit و تطبيقها موجود في كتاب ال Rootkit ،،

انا سبق وان نفذته .. مع ال ddk و السي و ليس C# :D

/index.php/topic/264448-%D8%A7%D9%84%D8%A8%D8%AF%D8%A7%D9%8A%D8%A9-%D9%85%D8%B9-%D8%A7%D9%84%D8%A7%D9%86%D8%AF%D8%B1%D9%88%D9%8A%D8%AF/

 

اني وان كنت الاخير زمانه ---- لأتِ بما لم تستطعه الاوائلُ

#11
اقتباس
انا سبق وان نفذته .. مع ال ddk و السي و ليس C#

انا اريد ان اعرفها قبل الاخرين :D

اظن ان تغليف دوال ntdll موجود في C#

الباقي القليل فقط من التعب

العمل كثير و الوقت قليل أعاننا الله

seo zen SEO Enlightment amazon danbo

#12
اقتباس
اظن ان تغليف دوال ntdll موجود في C#

لا اعتقد ،، <_<

لكن ربما ،، اذا وجدت شيئا اخبرنا به :D

/index.php/topic/264448-%D8%A7%D9%84%D8%A8%D8%AF%D8%A7%D9%8A%D8%A9-%D9%85%D8%B9-%D8%A7%D9%84%D8%A7%D9%86%D8%AF%D8%B1%D9%88%D9%8A%D8%AF/

 

اني وان كنت الاخير زمانه ---- لأتِ بما لم تستطعه الاوائلُ

#13
[DllImport("ntdll.dll", ExactSpelling = true, SetLastError = true)]
public static extern int NtCreateFile(
	out SafeFileHandle handle, 
	FileAccess access, 
	OBJECT_ATTRIBUTES* objectAttributes, 
	IO_STATUS_BLOCK* ioStatus, 
	ref long allocSize, 
	uint fileAttributes, 
	FileShare share, 
	uint createDisposition, 
	uint createOptions, 
	IntPtr eaBuffer, 
	uint eaLength);

[DllImport("ntdll.dll")]
public static extern int NtOpenDirectoryObject(
   out SafeFileHandle DirectoryHandle,
   uint DesiredAccess,
   ref OBJECT_ATTRIBUTES ObjectAttributes);

ممم وجدت بعضها :lol:

www.pInvoke.net

تم تعديل هذه المشاركة بواسطة fkugd2003 في 7 يناير 2009 في 19:39

العمل كثير و الوقت قليل أعاننا الله

seo zen SEO Enlightment amazon danbo

#15

ادن نغلفه نحن

نضع كل الاستدعائات داخل كلاس و نريح انفسنا :lol:

سوف اخربش فيها قليلا و اضع النتيجة هنا

العمل كثير و الوقت قليل أعاننا الله

seo zen SEO Enlightment amazon danbo

#16
اقتباس
ادن نغلفه نحن

نضع كل الاستدعائات داخل كلاس و نريح انفسنا

سوف اخربش فيها قليلا و اضع النتيجة هنا

يا سلام .. جميل ،، بالتوفيق

صراحة لا املك الكثير من الوقت لأخربش معك :lol:

/index.php/topic/264448-%D8%A7%D9%84%D8%A8%D8%AF%D8%A7%D9%8A%D8%A9-%D9%85%D8%B9-%D8%A7%D9%84%D8%A7%D9%86%D8%AF%D8%B1%D9%88%D9%8A%D8%AF/

 

اني وان كنت الاخير زمانه ---- لأتِ بما لم تستطعه الاوائلُ

مواضيع مشابهة