Determine the process which changed a registry value by the means of WMI
hello,
from time time determine process must change distinct registry value.
so possible determine process responsible means of wmi? discoverd registryvaluechangeevent class far see can pull information of event not of root cause for creation.
as altenative think procmon appropriate filter used.
are there further ways come on issue?
reinhard
reinhard
you use regmon, http://technet.microsoft.com/en-us/sysinternals/bb896652
this show process initiates it, action took, registry key affected, value changes , result.
only down side sheer amount of data through, exporting , opening in excel can filter out manageable format.
Windows Server > Management
Comments
Post a Comment