|
You last visited: Today at 07:33
Advertisement
Hide AutoIT from TaskManager or other Options
Discussion on Hide AutoIT from TaskManager or other Options within the AutoIt forum part of the Coders Den category.
10/11/2009, 14:22
|
#1
|
elite*gold: 0
Join Date: Jul 2005
Posts: 116
Received Thanks: 28
|
Hide AutoIT from TaskManager or other Options
Hi,
does anyone have a code to hide autoit from task manager or any other options to make it not detectable ?
|
|
|
10/11/2009, 15:08
|
#2
|
elite*gold: 116
Join Date: Oct 2007
Posts: 677
Received Thanks: 248
|
What you're looking for is a rootkit. You either have to code one by yourself.. or you have to find one that's not detected by AV. I got one, but that's already detected ;-)
|
|
|
10/11/2009, 17:04
|
#3
|
elite*gold: 9
Join Date: Apr 2009
Posts: 10,163
Received Thanks: 3,811
|
Write
OPT("trayiconhide", 1)
Then the Icon on ur tast is gone.
You also can rename the script to svchos.exe to hide it.
But Non-Detectable is not possible i think.
|
|
|
10/11/2009, 22:31
|
#4
|
elite*gold: 0
Join Date: Dec 2008
Posts: 12,369
Received Thanks: 2,168
|
Rootkit.
|
|
|
10/11/2009, 23:43
|
#5
|
elite*gold: 0
Join Date: Jul 2005
Posts: 116
Received Thanks: 28
|
well what i want to is to hide the proccess from AION, from what i saw AION has a system to verify each running proccess i guess my best bet with autoit would be a program that rename's itself upon executation...
There is no problem with icons being show on the window being on top as long as it is not listed on the task manager or they cannot see it
SOLUTION has to be within AUTOIT and no 3rd party stuff :P
|
|
|
10/14/2009, 09:46
|
#6
|
elite*gold: 116
Join Date: Oct 2007
Posts: 677
Received Thanks: 248
|
Does AION detect AutoIT? Well if you don't wanna use 3rd party stuff^^ it's impossible... Kernel Stuff with AutoIT is impossible i think
|
|
|
10/16/2009, 19:35
|
#7
|
elite*gold: 0
Join Date: Jul 2005
Posts: 116
Received Thanks: 28
|
No it does not detect because at this very momment there is no GameGuard or nProtect or xTrap OR WHATEVER there is...
i see... well autoit can load dll and work with them... but still not sure what can be done with kernel.dll + autoit.
|
|
|
10/16/2009, 19:50
|
#8
|
elite*gold: 1826
Join Date: Mar 2009
Posts: 4,310
Received Thanks: 6,287
|
there's a dll, HideNtProcess.dll, maybe thats what you've been searching for.
Edit: Kernel stuff is not impossible..
Code:
$Handle1 = DllCallbackRegister("ThreadTest1", "int", "ptr")
$Handle2 = DllCallbackRegister("ThreadTest2", "int", "ptr")
Func CreateThread($Handle, $struct)
$return = DllCall("kernel32.dll", "hwnd", "CreateThread", "ptr", 0, "dword", 0, "long", DllCallbackGetPtr($Handle), "ptr", DllStructGetPtr($struct), "long", 0, "int*", 0)
Return $return[0]
EndFunc
$Struct1 = DllStructCreate("Char[200];int")
DllStructSetData($Struct1, 1, 10)
CreateThread($Handle1, $Struct1)
$Struct2 = DllStructCreate("Char[200];int")
DllStructSetData($Struct2, 1, 10)
CreateThread($Handle2, $Struct2)
MsgBox(0x40, "Thread 1", "Default Thread")
Func ThreadTest1($x)
$y = DllStructCreate("char[200];int", $x)
MsgBox(0x40, "Thread 2", "Added Thread #1")
EndFunc ;==>_ThreadStart
Func ThreadTest2($x)
$y = DllStructCreate("char[200];int", $x)
MsgBox(0x40, "Thread 3", "Added Thread #2")
EndFunc ;==>_ThreadStart
|
|
|
10/16/2009, 21:51
|
#9
|
elite*gold: 116
Join Date: Oct 2007
Posts: 677
Received Thanks: 248
|
Yeah i know Kernel stuff isn't impossible with AutoIT. But i wouldn't code a rootkit with AutoIT. It's just not that handy like for example C++
|
|
|
10/17/2009, 08:26
|
#10
|
elite*gold: 1826
Join Date: Mar 2009
Posts: 4,310
Received Thanks: 6,287
|
Well AutoIT isn't made for such complicated things. Remember for what it's done.
The only way you can use AutoIt sense is, calling Function's from DLL's
|
|
|
10/24/2009, 03:16
|
#11
|
elite*gold: 0
Join Date: Jul 2005
Posts: 116
Received Thanks: 28
|
Thanks for the share man i will dig on it
|
|
|
01/07/2014, 20:29
|
#12
|
elite*gold: 0
Join Date: Oct 2013
Posts: 9
Received Thanks: 1
|
sry for gravedig but if you are still interessted, here is a very quick and crappy solution by removing the process-item from taskmanager.
Tested on XP, Vista, 7 (32 and 64 Bit)
Code:
Global $dll = dllopen("user32.dll")
Func ProcessHide()
Opt("WinTitleMatchMode", 4)
$TaskManTitle = "[CLASS:#32770]"
Dim $ProcName1 = "calc.exe"
While 1
$FindIndex = ControlListView($TaskManTitle, "", 1009, "FindItem", $ProcName1)
If $FindIndex <> -1 Then
$hwnd = ControlGetHandle($TaskManTitle, "", 1009)
MsgBox(0,'',$hwnd)
DllCall($dll, "int", "SendMessage", "hwnd", $hwnd, "int", 0x1008, "int", $FindIndex, "int", 0)
EndIf
Sleep(10)
WEnd
EndFunc
ProcessHide()
|
|
|
01/08/2014, 14:14
|
#13
|
elite*gold: 2
Join Date: Jul 2009
Posts: 14,456
Received Thanks: 4,685
|
#closed
|
|
|
 |
Similar Threads
|
TaskManager aktivieren
11/14/2010 - Technical Support - 8 Replies
Also habe da ein Problem und jeder denkt sich jetzt bestimmt.
ach das ist doch einfach. da täuscht ihr euch leider,
habe natürlich schon in google überall nachgeschaut doch da kam am ende immer DisableTaskMrg raus das steht bei mir nix das ist das problem.!
werde niewieder eine taskmanager öffnen können!!!?!?!?!?!!
|
[Hilfe]Taskmanager
07/06/2010 - Technical Support - 2 Replies
Heyho,
ich hab seit 1 woche ein Problem und zwar folgendes:
in Meinem Taskmanager kann ich die Prozesse nichmehr einsehen..
das sieht nurnoch so aus...
*Bild im Anhang
|
taskmanager K anzeige
05/21/2010 - Technical Support - 10 Replies
irgendwie bin ich etwas confus, ich habe mein pc neu installiert und auf einmal wird mir der taskmanager seltsam angezeigt
so kannte ich ihn (mit speicher und "großen" zahlen)
http://www.trojaner-board.de/attachments/1333d115 7998516-taskmanager-beschaedigt-nachher.jpg
und so schaut er nun aus oO
http://xs.to/image-89E1_4BF43C2A.jpg
weiss einer woran es liegt das ich nur noch ein K mit nicht aussagekräftigen zahlen sehe?
|
[Taskmanager]
09/20/2009 - Technical Support - 5 Replies
Hi also immer wenn ich Strg+Alt+Entf drücke kam der Taskmanager aber jetzt seh ich den nimmer ?!? Wie kann ich den sonst noch öffnen ?
|
Taskmanager blocken...? (De+Eng)
09/03/2009 - General Coding - 10 Replies
Hey Leute,
wollte euch mal fragen, ob mir wer sagen kann wie man den Taskmanager blocken kann...
Also mit welchem Befehl in welcher Sprache^^
Weil ich würd gerne ein paar Kumpels ärgern und das is ja langweilig wenn die, die Programme einfach per Taskmanager abwürden können :/
Wäre echt froh über schnelle Antworten
Same in english:
Hey people,
|
All times are GMT +1. The time now is 07:33.
|
|