Skip to content

Attempt at recreating a windows-based DKOM rootkit using c#

Notifications You must be signed in to change notification settings

29942016/DKOM-Rootkit

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

14 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

ckit

This application finds the handle to the task managers process chain in memory and attempts to modify it. The application is also packed with other functions to manipulation the task manager.

  • Disable redraw
  • Disable process status refresh
  • Delete process
  • Some other junk, check sTaskManager.cls for functions.

original dkom methodology: http://forums.codeguru.com/showthread.php?406555-How-to-hide-your-program-from-the-Task-Manager&p=1492556#post1492556

I've just translated the previously mentioned code snippet from VB/Windows XPx32 -> C#/Windows 10 x64 by updating the necessary required winapi calls to find the tasklist in the windows 10 environment.

tldr; Hides processes from the window's task manager.

About

Attempt at recreating a windows-based DKOM rootkit using c#

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages