New
#11
The results seems to be the same for both:
Normal mode:
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.
C:\windows\system32>SC QUERYEX SCHEDULE
SERVICE_NAME: SCHEDULE
TYPE : 20 WIN32_SHARE_PROCESS
STATE : 4 RUNNING
(STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
WIN32_EXIT_CODE : 0 (0x0)
SERVICE_EXIT_CODE : 0 (0x0)
CHECKPOINT : 0x0
WAIT_HINT : 0x0
PID : 1464
FLAGS :
C:\windows\system32> REN C:\Windows\System32\winevt\logs\Application.evtx App.ol
d
The process cannot access the file because it is being used by another process.
C:\windows\system32> REN C:\Windows\System32\winevt\logs\System.evtx Sys.old
The process cannot access the file because it is being used by another process.
C:\windows\system32>
C:\windows\system32>
Safe mode:
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.
C:\Users\user>SC QUERYEX SCHEDULE
SERVICE_NAME: SCHEDULE
TYPE : 20 WIN32_SHARE_PROCESS
STATE : 1 STOPPED
WIN32_EXIT_CODE : 1084 (0x43c)
SERVICE_EXIT_CODE : 0 (0x0)
CHECKPOINT : 0x0
WAIT_HINT : 0x0
PID : 0
FLAGS :
C:\Users\user> REN C:\Windows\System32\winevt\logs\Application.evtx App.old
The process cannot access the file because it is being used by another process.
C:\Users\user> REN C:\Windows\System32\winevt\logs\System.evtx Sys.old
The process cannot access the file because it is being used by another process.
C:\Users\user>