Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 11/17/2017 11:31:08 PM
Event ID: 4657
Task Category: Registry
Level: Information
Keywords: Audit Success
User: N/A
Computer: carl-PC
Description:
A registry value was modified.
Subject:
Security ID: S-1-5-21-3047833663-3766033810-2322992743-1002
Account Name: carl
Account Domain: carl-PC
Logon ID: 0x1960F
Object:
Object Name: \REGISTRY\USER\S-1-5-21-3047833663-3766033810-2322992743-1002\Software\Microsoft\Windows\CurrentVersion\Applets\Regedit
Object Value Name: LastKey
Handle ID: 0xf8
Operation Type: Existing registry value modified
Process Information:
Process ID: 0xad4
Process Name: C:\Windows\regedit.exe
Change Information:
Old Value Type: REG_SZ
Old Value: Computer
New Value Type: REG_SZ
New Value: Computer\HKEY_CURRENT_USER\sysnative