aslgonzales

Can't suspend a process

Sat Apr 29, 2017 7:21 pm

I have a process that I want to suspend and when i try to suspend it it says "Unable to suspend GameMon64.des (PID 2680): Access is denied" when i do run the process hacker with administration rights, help?
 
User avatar
viksoftru
Posts: 419
OS: Win7 (Live! DVD), BSD

Re: Can't suspend a process

Sun Apr 30, 2017 6:30 pm

UAC enabled? If enabled then admin is have limited (virtual) rights.
 
User avatar
dmex
Posts: 1167
Location: Australia

Re: Can't suspend a process

Mon May 01, 2017 8:58 am

GameMon64.des is GameGuard anti-cheat... They inject DLLs into every process (including Task Manager, Process Explorer and Process Hacker) and hook multiple system APIs to make their anti-cheat 'invisible' by returning 'fake system data' and fake error codes such as STATUS_ACCESS_DENIED from those hooked functions (which is what you're experiencing).

It's incredibly dumb and the hooks they're using introduce system instability, performance issues and can be bypassed easily (especially on Win10).

GameGuard is not considered 'malicious' and doesn't appear to be doing anything illegal - I don't think its a good idea to discuss the internals of their anti-cheat and the various methods to bypass it without first informing them of these flaws.

Suffice to say if you're using Win10 you can add two function calls into winmain that block their anti-cheat:
https://github.com/processhacker2/processhacker2

Who is online

Users browsing this forum: Yahoo and 1 guest