Solved

Identity of programs in the background (winxp)

Posted on 2008-06-22
5
274 Views
Last Modified: 2012-05-05
I noticed i can rename almost any programs' name & run it. When i view the processes in TaskManager  i can see the program name on the list of processes running.

I can rename notepad.exe to svchost.exe. if i am writing anti-hacking software in vb or delphi - how can i know which program is which -- is there any unique handle i can use?
0
Comment
Question by:eriklee
5 Comments
 
LVL 7

Expert Comment

by:YourReference
ID: 21841290
One way is to record the PID of the process running in a File or Registry.  If you rename norepad.exe to svchost.exe, when you launch it, record the PID of svchost.exe.

When you see PID 1111 (or whatever it ends up to be) you know it's your program
0
 

Author Comment

by:eriklee
ID: 21841771
the PID changes everytime you start the machine or the program.

notepad.exe can be 112 this time but can be 345 the next. there is not fixed unique PID associated with notepad.exe.
0
 
LVL 13

Expert Comment

by:ThievingSix
ID: 21842166
Every time you rename it, re-record the PID.
0
 
LVL 29

Accepted Solution

by:
nffvrxqgrcfqvvc earned 100 total points
ID: 21842256
This is done by the code in the application itself for example and application that would want to stop multiple instances of an application would create a mutex object with a unique mutex name then check if the unique mutex name is already active and act accordingly. Applications like notepad don't have these features.
0
 

Author Comment

by:eriklee
ID: 21842836
http://www.osix.net/modules/article/?id=6


found something abt mutex..
0

Featured Post

Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

Join & Write a Comment

Hello everybody This Article will show you how to validate number with TEdit control, What's the TEdit control? TEdit is a standard Windows edit control on a form, it allows to user to write, read and copy/paste single line of text. Usua…
When designing a form there are several BorderStyles to choose from, all of which can be classified as either 'Fixed' or 'Sizable' and I'd guess that 'Fixed Single' or one of the other fixed types is the most popular choice. I assume it's the most p…
Get people started with the process of using Access VBA to control Outlook using automation, Microsoft Access can control other applications. An example is the ability to programmatically talk to Microsoft Outlook. Using automation, an Access applic…
Get people started with the process of using Access VBA to control Excel using automation, Microsoft Access can control other applications. An example is the ability to programmatically talk to Excel. Using automation, an Access application can laun…

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now