When the process is found, the malware manipulates the token and acquires the SeDebugPrivilege token to perform further memory manipulation
dll is used by another
CreateToolhelp32Snapshot, ; th32ParentProcessID PROCESSENTRY32
I have narrowed it down to that exact call of CreateToolhelp32Snapshot, and once the snapshot is open there is no problem calling the other enumeration APIs (such as Process32First etc)
First time when application is loading and second time when application is closing (to close another associated process before exiting itself)
everything but the game specific code
orgmaresystemdogtown-nagios-plugins C 1938 lines 1407 code 303 blank 228 comment 289