Event ID: 5039

A registry key was virtualized.

A registry key was virtualized.

    Security ID:        %1
    Account Name:       %2
    Account Domain:     %3
    Logon ID:       %4

    Key Name:       %5
    Virtual Key Name:       %6

Process Information:
    Process ID:     %7
    Process Name:       %8

This event should be generated when registry key was virtualized using LUAFV.

This event occurs very rarely during standard LUAFV registry key virtualization.

Microsoft Documentation

Event ID - 5039

Lookup Audit Policy Configuration Settings

C:\> AuditPol.exe /get /subcategory:Registry

LEFT/RIGHT arrow keys for navigation

Back to List