R
Ron Kinner
I downloaded a new program the other day that logs
registry access. Regmon from:
http://www.sysinternals.com/ntw2k/source/regmon.shtml
When sitting there idle AntiSpy constantly accesses the
registry. Anybody know what it is up to? Is it just
checking to make sure its keys haven't been touched?
Aren't there better ways to do that that don't involve
constantly checking the registry?
Ron
454 1.24754429 gcasServ.exe:1284 OpenKey
HKCU\SOFTWARE\GIANTCompany\AntiSpyware SUCCESS
Access: 0x2000000
455 1.24759066 gcasServ.exe:1284 QueryValue
HKCU\SOFTWARE\GIANTCompany\AntiSpyware\ServState
SUCCESS "1"
456 1.24762118 gcasServ.exe:1284 QueryValue
HKCU\SOFTWARE\GIANTCompany\AntiSpyware\ServState
SUCCESS "1"
457 1.24766445 gcasServ.exe:1284 QueryValue
HKCU\SOFTWARE\GIANTCompany\AntiSpyware\ServState
SUCCESS "1"
458 1.24769318 gcasServ.exe:1284 QueryValue
HKCU\SOFTWARE\GIANTCompany\AntiSpyware\ServState
SUCCESS "1"
459 1.24776888 gcasServ.exe:1284 CloseKey
HKCU\SOFTWARE\GIANTCompany\AntiSpyware SUCCESS
460 1.24784601 gcasServ.exe:1284 OpenKey
HKCU\SOFTWARE\GIANTCompany\AntiSpyware SUCCESS
Access: 0x2000000
461 1.24788320 gcasServ.exe:1284 QueryValue
HKCU\SOFTWARE\GIANTCompany\AntiSpyware\ServState
SUCCESS "1"
462 1.24791169 gcasServ.exe:1284 QueryValue
HKCU\SOFTWARE\GIANTCompany\AntiSpyware\ServState
SUCCESS "1"
registry access. Regmon from:
http://www.sysinternals.com/ntw2k/source/regmon.shtml
When sitting there idle AntiSpy constantly accesses the
registry. Anybody know what it is up to? Is it just
checking to make sure its keys haven't been touched?
Aren't there better ways to do that that don't involve
constantly checking the registry?
Ron
454 1.24754429 gcasServ.exe:1284 OpenKey
HKCU\SOFTWARE\GIANTCompany\AntiSpyware SUCCESS
Access: 0x2000000
455 1.24759066 gcasServ.exe:1284 QueryValue
HKCU\SOFTWARE\GIANTCompany\AntiSpyware\ServState
SUCCESS "1"
456 1.24762118 gcasServ.exe:1284 QueryValue
HKCU\SOFTWARE\GIANTCompany\AntiSpyware\ServState
SUCCESS "1"
457 1.24766445 gcasServ.exe:1284 QueryValue
HKCU\SOFTWARE\GIANTCompany\AntiSpyware\ServState
SUCCESS "1"
458 1.24769318 gcasServ.exe:1284 QueryValue
HKCU\SOFTWARE\GIANTCompany\AntiSpyware\ServState
SUCCESS "1"
459 1.24776888 gcasServ.exe:1284 CloseKey
HKCU\SOFTWARE\GIANTCompany\AntiSpyware SUCCESS
460 1.24784601 gcasServ.exe:1284 OpenKey
HKCU\SOFTWARE\GIANTCompany\AntiSpyware SUCCESS
Access: 0x2000000
461 1.24788320 gcasServ.exe:1284 QueryValue
HKCU\SOFTWARE\GIANTCompany\AntiSpyware\ServState
SUCCESS "1"
462 1.24791169 gcasServ.exe:1284 QueryValue
HKCU\SOFTWARE\GIANTCompany\AntiSpyware\ServState
SUCCESS "1"