5039(-): A registry key was virtualized.

This event should be generated when registry key was virtualized using LUAFV.

This event occurs rarely during standard LUAFV registry key virtualization.

There's no example of this event in this document.

Subcategory: Audit Registry

Event Schema:

A registry key was virtualized.

Subject:

Security ID:%1%

Account Name:%2

Account Domain:%3

Logon ID:%4

Object:

Key Name:%5

Virtual Key Name:%6

Process Information:

Process ID:%7

Process Name%8

Required Server Roles: None.

Minimum OS Version: Windows Server 2008, Windows Vista.

Event Versions: 0.

Security Monitoring Recommendations

  • There's no recommendation for this event in this document.