User avatar
LindaAthena
Topic Author
Posts: 71
OS: win7-64bit + SuSE Linux(x64)

MalwareBytes can't be touched by PH

Mon May 22, 2017 2:25 am

I downloaded the current ver of Malware Bytes to do a scan. During a scan its service, MBAMservice.exe, was using too much cpu, so I wanted to limit it to 1 core. It has a self-protection module, MBAMChameleon, that, when running disables PH altering any of the normal values (affinity, priority, etc). I can likely turn off the Chameleon service, but was wondering if there was a way to have PH be able to
modify various resource vals.

It's cool that it protects itself, but at the same time, I still want PH to be able to modify it's resource demands.

Thanks,
Astara
 
User avatar
dmex
Posts: 1204
Location: Australia

Re: MalwareBytes can't be touched by PH

Sat May 27, 2017 2:42 am

MalwareBytes is blocking THREAD_SET_INFORMATION access which prevents applications from changing priority and affinity and yet doesn't block PROCESS_VM_READ which allows memory access.

THREAD_SET_INFORMATION should never be blocked and there's no reason to block it while PROCESS_VM_READ/PROCESS_VM_WRITE should definitely be blocked which it isn't and there's a bunch of other problems with their driver...

I could add a workaround for Process Hacker but it would be easier if you just created a support ticket and asked them to fix their code?
 
User avatar
LindaAthena
Topic Author
Posts: 71
OS: win7-64bit + SuSE Linux(x64)

Re: MalwareBytes can't be touched by PH

Sat May 27, 2017 3:44 am

Probably a good idea... though I file too many bug reports that I get grief for, so I sorta lose interest if you know what I mean... ;-) Maybe I will if I get motivated...
 
User avatar
TETYYS
Posts: 465
OS: Win 7 x64

Re: MalwareBytes can't be touched by PH

Sun Jun 18, 2017 1:26 pm

I could add a workaround for Process Hacker but it would be easier if you just created a support ticket and asked them to fix their code?
doubt that they will care

Who is online

Users browsing this forum: No registered users and 4 guests