Determine the process which changed a registry value by the means of WMI


hello,

from time time determine process must change distinct registry value.

so possible determine process responsible means of wmi? discoverd registryvaluechangeevent class far see can pull information of event not of root cause for creation.

as altenative think procmon appropriate filter used.

are there further ways come on issue?

reinhard

 

 


reinhard

you use regmon, http://technet.microsoft.com/en-us/sysinternals/bb896652

this show process initiates it, action took, registry key affected, value changes , result.

only down side sheer amount of data through, exporting , opening in excel can filter out manageable format.



Windows Server  >  Management



Comments

Popular posts from this blog

Edit Group Policy

Hyper-V VM not reaching OS 'Logon' screen

DNS question...