Register for your free account! | Forgot your password?

Go Back   elitepvpers > Coders Den > Coding Releases
You last visited: Today at 08:55

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



[AutoIt]Process-Hiding Tool

Discussion on [AutoIt]Process-Hiding Tool within the Coding Releases forum part of the Coders Den category.

Closed Thread
 
Old   #1

 
FichteFoll's Avatar
 
elite*gold: 237
Join Date: Sep 2008
Posts: 4,476
Received Thanks: 4,587
[AutoIt]Process-Hiding Tool

Nun, ich hatte Langeweile... Außerdem weiß ich nicht, wo ichs reinstellen soll, deswegen einfach mal hier.

Hier mal ein kleines Tool, das einfach nur einen Prozess versteckt. Dabei habe ich dann noch ein paar kleine Funktionen rein gebaut. Dabei handelt es sich um folgendes:
  • Im Kontextmenü lässt sich die Option "Run and Hide..." auswählen. Wenn man diese Option anklickt, wird dieser Prozess gestartet und automatisch danach sofort versteckt, sodass ihn kein Prozess Explorer oder der TaskManager sehen kann. Natürlich lassen sich dadurch auch manche Anti-Hack-Programme umgehen. Sieht im folgenden dann etwa so aus: (mein Menü ist etwas überfüllt...)
  • Außerdem bekommt man automatisch ein Programm, indem man einen bereits gestarteten Prozess verstecken kann. Dazu kann man entweder den Prozessnamen verwenden, die P-ID oder auch den Fensternamen. GUI sieht so aus:
Das ganze funktioniert mit einem Rootkit, wobei es sich um dieses handelt: . Davon werden die "fu.exe" und "msdirectx.sys" in das Windowsverzeichnis kopiert, sowie meine .exe.

Da ich leider keine Ahnung habe, was dieses Programm GENAU macht, musste ich es in meinen Installer mit einbauen, welcher dem entsprechend als Virus angezeigt wird (Rootkit/Trojaner). Ich beteuere hiermit, dass es sich bei den Funden in dieser Datei NICHT um einen Trojaner handelt. Ein Rootkit ist es natürlich trotzdem, aber das ist ja hier nicht negativ.

Dennoch gilt: Benutzung auf eigene Gefahr!

Dieses Rootkit funktioniert NICHT auf Windows Vista oder 7, weil der Treiber damit nicht kompatibel ist!



All rites Reveersed...
Attached Files
File Type: zip Hiding Extension by FichteFoll.zip (1.35 MB, 2636 views)
FichteFoll is offline  
Thanks
20 Users
Old 10/07/2009, 22:57   #2
 
muse-'s Avatar
 
elite*gold: 0
Join Date: Oct 2007
Posts: 520
Received Thanks: 61
funktioniert perfekt.
danke!
muse- is offline  
Old 10/08/2009, 01:00   #3

 
elite*gold: 150
Join Date: Apr 2007
Posts: 2,372
Received Thanks: 6,628
Würd ich nicht unbedingt nehmen, nix gegen dein tool aber ein treiber würde ich mir dafür nicht aufs system haun :>

Quote:
msdirectx.sys

This is an undesirable program.

This file has been identified as a program that is undesirable to have running on your computer. This consists of programs that are misleading, harmful, or undesirable.

If the description states that it is a piece of malware, you should immediately run an antivirus and antispyware program. If that does not help, feel free to ask us for assistance in the forums.
wurstbrot123 is offline  
Old 10/08/2009, 10:46   #4

 
Adroxxx's Avatar
 
elite*gold: 15
Join Date: Nov 2005
Posts: 13,021
Received Thanks: 5,323
Der Treiber gehört zum Rootkit. Ist eher eine Art GUI für das FU Rootkit.
Adroxxx is offline  
Old 10/08/2009, 15:28   #5

 
FichteFoll's Avatar
 
elite*gold: 237
Join Date: Sep 2008
Posts: 4,476
Received Thanks: 4,587
Ich sage dann hier mal, dass ich das gesammte rootkit von Adroxxx habe.

Wer mir also nicht glaubt, der tuts dann vielleicht ihm.
FichteFoll is offline  
Thanks
1 User
Old 10/08/2009, 17:40   #6


 
.Law.'s Avatar
 
elite*gold: 30
Join Date: Apr 2008
Posts: 2,947
Received Thanks: 1,768
I get BSOD each time I click hide process.
And no I'm not running on Vista,but FU Rootkit works just fine to me.
.Law. is offline  
Old 10/09/2009, 14:34   #7

 
FichteFoll's Avatar
 
elite*gold: 237
Join Date: Sep 2008
Posts: 4,476
Received Thanks: 4,587
Quote:
Originally Posted by PunkS7yle View Post
I get BSOD each time I click hide process.
And no I'm not running on Vista,but FU Rootkit works just fine to me.
Hm, sounds strange to me. Maybe vista is built on an other way than windows, so I can't write into the registry or maybe there is something different with the WindowsDir...
FichteFoll is offline  
Old 10/29/2009, 19:22   #8
 
acm-18's Avatar
 
elite*gold: 0
Join Date: Jul 2007
Posts: 31
Received Thanks: 22
Hello,
My problem is how to put the hide process windows 7 "breaks" and gets a blue screen that restarts the system, I tried to start it in administrator mode, I have also tried to change it the competibilitat (Win XP SP2 , SP3, Win Vista .)... And Hiding tool does not work because I click "run and hide" and not start anything, I also tested to open the program "HideProcess "and click on the process list (copy and paste it into the text box) but it does nothing ... I do not know what to do, I just want to work in UCE KIKI and trainer

THANKS ( sorry my english because I'm spanish)
acm-18 is offline  
Old 10/29/2009, 21:09   #9


 
MrSm!th's Avatar
 
elite*gold: 7110
Join Date: Jun 2009
Posts: 28,904
Received Thanks: 25,394
Quote:
Originally Posted by acm-18 View Post
Hello,
My problem is how to put the hide process windows 7 "breaks" and gets a blue screen that restarts the system, I tried to start it in administrator mode, I have also tried to change it the competibilitat (Win XP SP2 , SP3, Win Vista .)... And Hiding tool does not work because I click "run and hide" and not start anything, I also tested to open the program "HideProcess "and click on the process list (copy and paste it into the text box) but it does nothing ... I do not know what to do, I just want to work in UCE KIKI and trainer

THANKS ( sorry my english because I'm spanish)
^this with vista and 7
i dont know why
MrSm!th is offline  
Old 10/29/2009, 21:13   #10
 
acm-18's Avatar
 
elite*gold: 0
Join Date: Jul 2007
Posts: 31
Received Thanks: 22
But If you use XP, the bypass does not work, and S4 Trainer by FichteFoll V_1.0 * Patch 12 will not work ever!

What I do by hiding the process if I use it Win7?
acm-18 is offline  
Old 10/29/2009, 21:38   #11
 
elite*gold: 0
Join Date: Sep 2009
Posts: 22
Received Thanks: 2
hello, i am really thankful for all the work you have done but i am stumped.
i have tried the FU root kit and this and neither work. i am running windows vista 64x home premium and i am wondering why neither work. its like the root kits disabled every time i run it. is there any advice you could give me on this. it might be my anti virus because i am using avg full but i disabled it when trying fu root kit and it still didn't work.
i have also read that uac built into vista blocks root kits, could that be a possible reason for the problems i am having?
any help would be greatly appreciated. ^_^
Darth_Mullins is offline  
Old 11/03/2009, 15:19   #12

 
FichteFoll's Avatar
 
elite*gold: 237
Join Date: Sep 2008
Posts: 4,476
Received Thanks: 4,587
Yes it CAN be detected as virus. So just ignore this popup.

Did you start that as administrator? Maybe the programm doesn't have permissions to hide these processes. Btw this does not work for Vista...
FichteFoll is offline  
Old 11/03/2009, 17:33   #13
 
elite*gold: 0
Join Date: Dec 2007
Posts: 60
Received Thanks: 6
i wie will der bei mir nich funktionieren habs ma mit perx ausprobiert das zu verstecken und naja verschwindet nich ausm taskmanager ...


edit
hab vista
DarkDevilClaw is offline  
Old 11/04/2009, 01:52   #14
 
elite*gold: 0
Join Date: Sep 2009
Posts: 22
Received Thanks: 2
yeah i ran it as admin. but i think either vista or my antivirus blocks the fu.exe and the dll as they are executed. shrug
Edit:
i have tried disableing uac and my antivirus restarting and running this but it still doesn't work. its like as soon as i download or run this or anything with the rootkit fu.exe, my pc disables it for good. is there any other way to hide processes? i will keep looking into it because i am interested in using a ce but i can't get any to work.
Darth_Mullins is offline  
Old 12/26/2009, 15:49   #15
 
elite*gold: 0
Join Date: Dec 2008
Posts: 6
Received Thanks: 0
Exclamation Erm..

Hey FighteFoll,

I luv what you guys are doing and your forum has been very very usefull to me, but right now with the root kit thing, I don't know what to do. I got all the files from the FU, btu what am I suppose to do with them? Please help me, thank you!!!
2800 is offline  
Closed Thread


Similar Threads Similar Threads
Need a process/memory search tool
09/10/2008 - CO2 Programming - 1 Replies
Hi, I need a good program (full version ofcourse) for digging up the memory addresses to use in CO bots. Plz help. ty.
Window Hiding Tool
06/14/2008 - SRO Hacks, Bots, Cheats & Exploits - 17 Replies
Its called AceHide Free, heres the link. AceHide Free download and review - hide open windows from SnapFiles Basically you set up a key combination, mine is page down to hide, and page up to show, and when ever you press it the window hides. Its useful cuz it doesn't lag much and its better than any other window hiding tool i have used. :D now if anyone thinks im posting a keylogger, you can go fcuk yourself. scan it all u want.
Ace Hide Free Window Hiding tool
12/06/2007 - SRO Hacks, Bots, Cheats & Exploits - 7 Replies
Its called AceHide Free, heres the link. AceHide Free download and review - hide open windows from SnapFiles Basically you set up a key combination, mine is page down to hide, and page up to show, and when ever you press it the window hides. Its useful cuz it doesn't lag much and its better than any other window hiding tool i have used. now if anyone thinks im posting a keylogger, you can go fcuk yourself. scan it all u want. here is the link AceHide Free download and review - hide...



All times are GMT +2. The time now is 08:55.


Powered by vBulletin®
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2024 elitepvpers All Rights Reserved.