|
Posted by Roger Abell [MVP] on June 13, 2005, 1:45 am
If you were Registered and logged in, you could reply and use other advanced thread options
The main way to uncover such things is the event log if there was
auditing configured before the event occurred. After it is done and
the change has happened there is little trace that remains, but one
can always examine the system for unknown/suspect software.
--
Roger Abell
Microsoft MVP (Windows Server: Security)
> wi there,
> Recently I have a problem that the key included the value in registry had
> been deleted / missing but I can not find why or by who? My question is
> perharps there is a way to zoom in why it could be happened and how to
> track
> the causing of missing key/value in registry. Is there any tools to help
> it
> out? Thanks for your help.....
|