{"id":1825,"date":"2019-02-09T21:57:25","date_gmt":"2019-02-09T21:57:25","guid":{"rendered":"https:\/\/stevenwhiting.com\/blog\/?p=1825"},"modified":"2019-02-11T14:26:54","modified_gmt":"2019-02-11T14:26:54","slug":"the-case-of-the-odd-outlook-pop-up","status":"publish","type":"post","link":"https:\/\/stevenwhiting.com\/blog\/?p=1825","title":{"rendered":"The Case Of The Odd Outlook Pop-up"},"content":{"rendered":"\n<p>Another old one from\nthe XP days and I believe this was Outlook 2010.<\/p>\n\n\n\n<p>Two users would kept\ngetting this Outlook popup every few minutes. Very helpful message &#8220;A\nprogram&#8221;. Would be good if it could report what program had invoked it.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"https:\/\/stevenwhiting.com\/blog\/wp-content\/uploads\/2019\/sysint\/thecaseoftheoddoutlookpopup\/0.png\" target=\"_blank\" rel=\"noreferrer noopener\"><img loading=\"lazy\" decoding=\"async\" width=\"338\" height=\"186\" src=\"https:\/\/stevenwhiting.com\/blog\/wp-content\/uploads\/2019\/sysint\/thecaseoftheoddoutlookpopup\/0.png\" alt=\"\" class=\"wp-image-1827\" srcset=\"https:\/\/stevenwhiting.com\/blog\/wp-content\/uploads\/2019\/sysint\/thecaseoftheoddoutlookpopup\/0.png 338w, https:\/\/stevenwhiting.com\/blog\/wp-content\/uploads\/2019\/sysint\/thecaseoftheoddoutlookpopup\/0-300x165.png 300w\" sizes=\"auto, (max-width: 338px) 100vw, 338px\" \/><\/a><figcaption>Outlook Message<\/figcaption><\/figure>\n\n\n\n<p>So I fire up Process\nMonitor and take a trace. Once I stop the capture I take a look. I assume it&#8217;s\na not registry issue so I filter all reg entries out.<\/p>\n\n\n\n<p>You can quickly do\nthis by just clicking the registry icon<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"https:\/\/stevenwhiting.com\/blog\/wp-content\/uploads\/2019\/sysint\/thecaseoftheoddoutlookpopup\/1.png\" target=\"_blank\" rel=\"noreferrer noopener\"><img loading=\"lazy\" decoding=\"async\" width=\"158\" height=\"55\" src=\"https:\/\/stevenwhiting.com\/blog\/wp-content\/uploads\/2019\/sysint\/thecaseoftheoddoutlookpopup\/1.png\" alt=\"\" class=\"wp-image-1828\"\/><\/a><figcaption>Filter buttons<\/figcaption><\/figure>\n\n\n\n<p>This now filters out\nall the reg entries in the trace.<\/p>\n\n\n\n<p>I then filter out\njust Outlook to see if there is anything obvious and see these entries.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"932\" height=\"392\" src=\"https:\/\/stevenwhiting.com\/blog\/wp-content\/uploads\/2019\/sysint\/thecaseoftheoddoutlookpopup\/2.png\" alt=\"\" class=\"wp-image-1830\" srcset=\"https:\/\/stevenwhiting.com\/blog\/wp-content\/uploads\/2019\/sysint\/thecaseoftheoddoutlookpopup\/2.png 932w, https:\/\/stevenwhiting.com\/blog\/wp-content\/uploads\/2019\/sysint\/thecaseoftheoddoutlookpopup\/2-300x126.png 300w, https:\/\/stevenwhiting.com\/blog\/wp-content\/uploads\/2019\/sysint\/thecaseoftheoddoutlookpopup\/2-768x323.png 768w\" sizes=\"auto, (max-width: 932px) 100vw, 932px\" \/><figcaption>Outlook filtered<\/figcaption><\/figure>\n\n\n\n<p>I pick the first TCP\nentry and press CTRL+B to bookmark it. I then go and turn the Outlook filter\noff so all other entries reappear. I do this to see what is going on around\nthat time other than Outlook and I bookmark it in case I lose my place.<\/p>\n\n\n\n<p>This reveals the app\nthat appears to be invoking this and causing the popup<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"https:\/\/stevenwhiting.com\/blog\/wp-content\/uploads\/2019\/sysint\/thecaseoftheoddoutlookpopup\/3.png\" target=\"_blank\" rel=\"noreferrer noopener\"><img loading=\"lazy\" decoding=\"async\" width=\"865\" height=\"391\" src=\"https:\/\/stevenwhiting.com\/blog\/wp-content\/uploads\/2019\/sysint\/thecaseoftheoddoutlookpopup\/3.png\" alt=\"\" class=\"wp-image-1829\" srcset=\"https:\/\/stevenwhiting.com\/blog\/wp-content\/uploads\/2019\/sysint\/thecaseoftheoddoutlookpopup\/3.png 865w, https:\/\/stevenwhiting.com\/blog\/wp-content\/uploads\/2019\/sysint\/thecaseoftheoddoutlookpopup\/3-300x136.png 300w, https:\/\/stevenwhiting.com\/blog\/wp-content\/uploads\/2019\/sysint\/thecaseoftheoddoutlookpopup\/3-768x347.png 768w\" sizes=\"auto, (max-width: 865px) 100vw, 865px\" \/><\/a><figcaption>More filters<\/figcaption><\/figure>\n\n\n\n<p>The piece of Crapita (sorry I mean Capita <a href=\"https:\/\/en.wikipedia.org\/wiki\/Capita\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\"https:\/\/en.wikipedia.org\/wiki\/Capita (opens in a new tab)\">https:\/\/en.wikipedia.org\/wiki\/Capita<\/a>) software appears to be reference the Outlook Object Library and then I see Outlook trying to connect to the exchange server. These all correspond with the pop-up. Speaking to the person who supported the Crapita app they discovered there was an issue on the server that was causing CapitaEVForms to do this. Once disabled the message stopped.<\/p>\n\n\n\n<p>It appears if an\nexternal app attempts to invoke Outlook without permission or as in this case,\naccess the address book without being &#8220;Trusted&#8221; then Outlook pops up\na warning in case the access was malicious.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Another old one from the XP days and I believe this was Outlook 2010. Two users would kept getting this Outlook popup every few minutes. Very helpful message &#8220;A program&#8221;. Would be good if it could report what program had &hellip; <a href=\"https:\/\/stevenwhiting.com\/blog\/?p=1825\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[197,200],"class_list":["post-1825","post","type-post","status-publish","format-standard","hentry","category-it-notes","tag-processmonitor","tag-sysinternals"],"_links":{"self":[{"href":"https:\/\/stevenwhiting.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/1825","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/stevenwhiting.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/stevenwhiting.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/stevenwhiting.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/stevenwhiting.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1825"}],"version-history":[{"count":2,"href":"https:\/\/stevenwhiting.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/1825\/revisions"}],"predecessor-version":[{"id":1847,"href":"https:\/\/stevenwhiting.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/1825\/revisions\/1847"}],"wp:attachment":[{"href":"https:\/\/stevenwhiting.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1825"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/stevenwhiting.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1825"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/stevenwhiting.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1825"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}