Originally Posted By: wfaulk
Leave Process Monitor running in the background somewhere, filtering to the relevant registry keys, and when they change, go inspect the log to see what did it.


Seconded! You can even set it up to start logging from boot. You will also want to drop filtered events to keep the log from getting overly large.
_________________________
Glenn