The attached program is interesting.
It hides a process after you put in the PID. Task Master and some others can't see it.

It uses a driver. Wonder if there is a way to do it without one ?

Based upon my knowledge, there is no way to do this type of thing without a driver as User mode does not have access to the data structures needed to perform such a task.

This material is at the edge of what we allow here, if not actually crossing it. I'm considering locking the topic or perhaps just removing the attachment.

But first, humor me - mention one single non-malicious use of this?
Thread locked, pending deletion, attachment removed.
I don't think so, skywalker has been here for a very long time and I believe "Learning" is a good answer ;) "Learning" took all of us down a weird path at some point or another.

However, I do agree with f0dder - besides enabling malware authors, this thread wouldn't help anyone much at all.
