Solved

Using process monitor to track registry changes

Posted on 2012-04-02
2
1,372 Views
Last Modified: 2012-04-02
I'd like to learn how to effectively use Process Monitor to track changes to the registry as they're happening. Specifically, I need to find the registry values that change when the "Override Automatic Cookie Handling" and "Always Allow Session Cookies" settings are changed. Thanks to an expert on this site I now know which values are changed, but I'd like to know how he arrived at this.

I poked around in Process Monitor a little today and was able to get so far but I need a little further explanation. I configured two filters to filter by process name and the other to filter by operation. The process name I'm filtering is iexplore.exe and the operation is RegSetValue. With these two filters, I'm able to narrow down the results down to a manageable level, but there still seems to be some extra output.

The required registry values are all under "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3" and are the following:

1A10
"{AEBA21FA-782A-4A90-978D-B72164C80120}"
"{A8A88C49-5EB2-4990-A1A2-0876022C854F}"

However, if you view the attached file you'll see the extra registry values (some are even listed twice, which I don't understand). My question is how to eliminate the extraneous results and narrow it down to what's needed?
ProcMon.JPG
0
Comment
Question by:mcpp661
2 Comments
 
LVL 6

Expert Comment

by:Raquero
Comment Utility
Try filtering on just the path value for the desired registry key. You may see multiple entries if the same key is queried or written to more than once during the monitoring window.
0
 
LVL 65

Accepted Solution

by:
RobSampson earned 500 total points
Comment Utility
Hi, here are the steps I took to figure this out.

1.  Looking at this article:
http://support.microsoft.com/?kbid=182569
you can see that the per session cookies settings are applied under the following key:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones

2. Fire up Process Monitor, and apply the following filters:
 ProcMon Filter
3. Open Internet Explorer, and click Tools --> Internet Options, and click the Privacy tab.  Then click the Advanced button.  If your settings are *not* shown as below, set them as shown, and click OK, then OK again, to apply the changes:
Cookie settings unchecked
If you needed to change the settings, follow the above steps to click back into the Advanced screen.

4. In Process Monitor, if it not currently capturing events, click the Capture button:
ProcMon Capture Button
If it is currently capturing events, click the Clear Display button:
ProcMon Clear Display Button
5. Now in the IE Advanced Privacy Settings box, select the options as below, and click OK, then OK again.
Privacy Settings Checked
6. Switch back to Process Monitor, and you see the following:
ProcMon Output
So now you can see which values are being modified, and set up a .reg file accordingly to import those settings automatically.

Regards,

Rob.
0

Featured Post

6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

Join & Write a Comment

Disclosure: Use this tutorial only when no other options helps to get Windows XP running without any problems and you don't want to format the drive. The back up of the data is the responsible of the user, however there is a description of how t…
There are 2 things you must have in order to connect to the internet behind a router, The "Gateway IP" of the router, which is usually something like 192.168.xxx.1, I've seen routers with default values of: 192.168.0.1, 192.168.1.1, 192.168.11.1, …
This tutorial will introduce the viewer to VisualVM for the Java platform application. This video explains an example program and covers the Overview, Monitor, and Heap Dump tabs.
This tutorial explains how to use the VisualVM tool for the Java platform application. This video goes into detail on the Threads, Sampler, and Profiler tabs.

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now