Rename running process (can't)

Rename running process (can't)

Secure Home | Search | About

Microsoft Applications Security - Microsoft's general security discussions and announcements 

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Rename running process (can't) Etienne Boucher 03-15-2006
Posted by =?Utf-8?B?RXRpZW5uZSBCb3VjaGVy on March 15, 2006, 4:39 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I posted this on the XP general newsgroup, but I'm not sure that was the
right place, this might not be either.

On all my computers, with Windows 2000 and up (apparently it should work
lower NT versions as well) I can rename an executable that is currently
running with either a MoveFile inside the program, or manually in the shell.
On one of my machines I can't, and I get a sharing mode (code 32) error. Does
anyone know what could influence this functionallity and make it impossible
to do this on that particular machine?

The machine is close to a fresh install, mostly there's just Windows OneCare
on it.

I only found one post about not being able to do this, back in 2003, with no
real anwser
http://groups.google.ca/group/microsoft.public.win2000.file_system/browse_thread/thread/d061625492aababe/5613724362886a6d?tvc=2&q=group%3Amicrosoft.*+rename+running+process

--
Etienne Boucher

Posted by Shenan Stanley on March 15, 2006, 4:53 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Etienne Boucher wrote:
> I posted this on the XP general newsgroup, but I'm not sure that
> was the right place, this might not be either.
>
> On all my computers, with Windows 2000 and up (apparently it should
> work lower NT versions as well) I can rename an executable that is
> currently running with either a MoveFile inside the program, or
> manually in the shell. On one of my machines I can't, and I get a
> sharing mode (code 32) error. Does anyone know what could influence
> this functionallity and make it impossible to do this on that
> particular machine?
>
> The machine is close to a fresh install, mostly there's just
> Windows OneCare on it.
>
> I only found one post about not being able to do this, back in
> 2003, with no real anwser.
>
http://groups.google.ca/group/microsoft.public.win2000.file_system/browse_thread/thread/d061625492aababe/5613724362886a6d?tvc=2&q=group%3Amicrosoft.*+rename+running+process

Tried doing it without the Beta Software running on it?

--
Shenan Stanley
MS-MVP
--
How To Ask Questions The Smart Way
http://www.catb.org/~esr/faqs/smart-questions.html



Posted by =?Utf-8?B?RXRpZW5uZSBCb3VjaGVy on March 16, 2006, 10:47 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I'll be damned. That's what it was. I have other machines with other security
products and OneCare is the only one to affect that functionality. I should I
tried without of course. Thanks for making me do it.

I'll have to see if I can report that as a bug for OneCare. I still don't
see why or how it affects renaming of running executables.

--
Etienne Boucher


"Shenan Stanley" wrote:

> Etienne Boucher wrote:
> > I posted this on the XP general newsgroup, but I'm not sure that
> > was the right place, this might not be either.
> >
> > On all my computers, with Windows 2000 and up (apparently it should
> > work lower NT versions as well) I can rename an executable that is
> > currently running with either a MoveFile inside the program, or
> > manually in the shell. On one of my machines I can't, and I get a
> > sharing mode (code 32) error. Does anyone know what could influence
> > this functionallity and make it impossible to do this on that
> > particular machine?
> >
> > The machine is close to a fresh install, mostly there's just
> > Windows OneCare on it.
> >
> > I only found one post about not being able to do this, back in
> > 2003, with no real anwser.
> >
http://groups.google.ca/group/microsoft.public.win2000.file_system/browse_thread/thread/d061625492aababe/5613724362886a6d?tvc=2&q=group%3Amicrosoft.*+rename+running+process
>
> Tried doing it without the Beta Software running on it?
>
> --
> Shenan Stanley
> MS-MVP
> --
> How To Ask Questions The Smart Way
> http://www.catb.org/~esr/faqs/smart-questions.html
>
>
>

Posted by Scherbina Vladimir on March 16, 2006, 7:55 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Probably some application have a handle to that executable. Most likely,
this is the result of CreateFile with share mode set to NULL.

--
Vladimir
http://spaces.msn.com/vladimir-scherbina/

>I posted this on the XP general newsgroup, but I'm not sure that was the
> right place, this might not be either.
>
> On all my computers, with Windows 2000 and up (apparently it should work
> lower NT versions as well) I can rename an executable that is currently
> running with either a MoveFile inside the program, or manually in the
> shell.
> On one of my machines I can't, and I get a sharing mode (code 32) error.
> Does
> anyone know what could influence this functionallity and make it
> impossible
> to do this on that particular machine?
>
> The machine is close to a fresh install, mostly there's just Windows
> OneCare
> on it.
>
> I only found one post about not being able to do this, back in 2003, with
> no
> real anwser.
>
http://groups.google.ca/group/microsoft.public.win2000.file_system/browse_thread/thread/d061625492aababe/5613724362886a6d?tvc=2&q=group%3Amicrosoft.*+rename+running+process
>
> --
> Etienne Boucher



Posted by =?Utf-8?B?RXRpZW5uZSBCb3VjaGVy on March 16, 2006, 10:47 am
If you were  Registered and logged in, you could reply and use other advanced thread options
> Probably some application have a handle to that executable. Most likely,
> this is the result of CreateFile with share mode set to NULL.

That's the first thing I checked for using ProcessExplorer by Sysinternals.
Turns out it's OneCare. See my other message.

Thanks anyway.

--
Etienne Boucher

Similar ThreadsPosted
list the privileges of a process running May 17, 2010, 2:48 pm
How to tell the running process--csrss.exe is malicious or not? April 25, 2005, 6:03 am
services.exe process is running eating away 50% of Processor time September 10, 2007, 1:12 am
rename Administrator account well after initial set-up January 4, 2006, 4:28 pm
Permissions to Rename a Computer within an AD domain February 16, 2006, 10:10 am
NTFS Rename vs Delete permissions February 28, 2006, 2:07 pm
should i have to rename administrator on domain server. April 24, 2006, 2:46 pm
Allow to read the file, but deny rename it ? June 11, 2006, 9:14 am
Rename the "Guest" account as "administrator"? May 3, 2005, 6:13 am
Wrong file security after domain rename November 20, 2007, 6:48 am

The site map in XML format XML site map

Contact Us | Privacy Policy