Hello All,
Should I be concerned about the registry log information below obtained
using RegMon from http://www.sysinternals.com/Utilities/Regmon.html
filtering on a beta version of an email program that I use?
Notice I included the header of RegMon on the first line to provide what
the information pertains too.
"No","Time","Process","Request","Path","Result","Other"
2920,59.15,"Email_Program.exe:1844","CreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f1b6ec23-6d09-11da-9254-806d6172696f}\","SUCCESS","Access:
0x2000000"
2921,59.15,"Email_Program.exe:1844","SetValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f1b6ec23-6d09-11da-9254-806d6172696f}\BaseClass","SUCCESS","""Drive"""
2923,59.15,"Email_Program.exe:1844","CreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f1b6ec22-6d09-11da-9254-806d6172696f}\","SUCCESS","Access:
0x2000000"
2924,59.15,"Email_Program.exe:1844","SetValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f1b6ec22-6d09-11da-9254-806d6172696f}\BaseClass","SUCCESS","""Drive"""
2926,59.15,"Email_Program.exe:1844","CreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f1b6ec24-6d09-11da-9254-806d6172696f}\","SUCCESS","Access:
0x2000000"
2927,59.15,"Email_Program.exe:1844","SetValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f1b6ec24-6d09-11da-9254-806d6172696f}\BaseClass","SUCCESS","""Drive"""
2929,59.15,"Email_Program.exe:1844","CreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f1b6ec25-6d09-11da-9254-806d6172696f}\","SUCCESS","Access:
0x2000000"
2930,59.15,"Email_Program.exe:1844","SetValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f1b6ec25-6d09-11da-9254-806d6172696f}\BaseClass","SUCCESS","""Drive"""
3433,96.84,"Email_Program.exe:1844","CreateKey","HKLM\Software\Microsoft\Tracing","SUCCESS","Access:
0xF003F"
If MountPoints is anything like Linux I would think a device is being
mounted. Notice the log information is ends with
BaseClass","SUCCESS","""Drive"" and followed with a "Tracing" key.
Since I'm not very knowledgeable on the registry, I thought that I'd ask
where someone with more knowledge could provide insight.
TIA!
--
Regards,
Greg Strong