Audit failures from explorer.exe

From: Jan Bares (jan.bares_at_nospam.nospam)
Date: 03/06/05


Date: Sun, 6 Mar 2005 11:10:56 +0100

Hi,

I audit failures on files from "Program Files" because I run as member of
"Users" group and I want to identify programs trying to write there, because
they are badly written. But my Event log is full of 560 Failure Events, that
are generated by explorer.exe as I browse through the folders.
Is there any way how can I remove explorer.exe from being audited? Otr any
other solution (besides using File Manager as mentioned in Q172509)

I know the reason why Explorer does this. When explorer checks for rights
for a folder, this results in a call to NtCreateFile. This call fails and
creates the audit log. There is a function that can return rights on folder,
but that function is slow, so Explorer uses this dirty way.

Thanks, Jan



Relevant Pages

  • Re: Hidden Directories, not empty, Virus created
    ... > explorer options but they still don't display. ... Downloaded Program Files is a special system folder, so Windows Explorer ...
    (microsoft.public.win2000.general)
  • Re: Errors during SBS 2003 SP1 Installation
    ... I think here's where you went wrong, the regedit of the 'Program Files' dir. ... reg hacking SBS is not to be taken lightly. ... ..Microsoft Office 97 Standard Edition ... is that I changed the program files folder to D: ...
    (microsoft.public.windows.server.sbs)
  • Re: removing folders from program files
    ... It's not a crime to remove sub-folders from the 'Program Files' ... The 'Common Files' folder within 'Program Files' ... It's a rarer occurrence that the program installed a windows 'service', ... I have this folder called "Emergent Music LLC" in my Program Files ...
    (microsoft.public.windowsxp.general)
  • Re: Vista Program Files Folder Problem - Issue 1
    ... It had been very convenient to simply copy the files to their final locations using a batch script; I just now need to make my batch script a little bit smarter to place the data file into the virtualized folder. ... Storing data in the Programs Files directory has never been a good practice and Vista actively prohibits it. ... I created a directory in Program Files and placed a front-end MS Access database in it and a back-end database into a subfolder; ...
    (microsoft.public.windows.vista.security)
  • Re: Sharing Program Files folder
    ... I know what you are saying but I think Simple File Sharing only ... Windows folder. ... error when trying to access shared Program Files folder. ...
    (microsoft.public.windowsxp.network_web)