SI ProcMon shows nonstop RegQuery

Discussion in 'Prevx Releases' started by justenough, May 18, 2010.

Thread Status:
Not open for further replies.
  1. justenough

    justenough Registered Member

    Joined:
    May 13, 2010
    Posts:
    1,509
    I am new to Windows, so I don't know if this is a problem, but it wasn't happening with Avast. I just installed Prevx, and it is working nonstop with RegQueryValue such as these:

    1:27:44.0539426 PM prevx.exe 1040 RegQueryValue HKLM\SOFTWARE\PCSI\UninstallDone SUCCESS Type: REG_DWORD, Length: 4, Data: 1

    1:27:44.0539531 PM prevx.exe 1040 RegQueryValue HKLM\SOFTWARE\PCSI\KCSI NAME NOT FOUND Length: 144

    1:27:44.2250841 PM prevx.exe 1380 RegQueryValue HKLM\SOFTWARE\PCSI\KCSI NAME NOT FOUND Length: 144


    It is around 160 queries a second, and seems to be the same things over and over. Is this normal?
     
  2. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    Hello,
    It is normal for Prevx to be querying those values, but not at that frequency. Could you please send me a log fom ProcMon to report@prevxresearch.com and I will investigate further?

    Thank you!
     
  3. justenough

    justenough Registered Member

    Joined:
    May 13, 2010
    Posts:
    1,509
    Yes I will be happy to send you the log. Can you tell me how to make such a log? And is report@prevxresearch.com the email address to send it to?
     
  4. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    Can you please try clicking File > Save and selecting "Comma-Separated Values (CSV)" and save the file to disk and then send that to us directly? I suspect there isn't actually a problem here because of how ProcMon reports events but still worthwhile investigating :)
     
  5. justenough

    justenough Registered Member

    Joined:
    May 13, 2010
    Posts:
    1,509
    Log file sent.
     
Thread Status:
Not open for further replies.