Windows – suspicious USB entries in the USBSTOR registry

I have restricted the use of USB sticks in my Windows domain environment. Recently, we discovered the use of unauthorized pen drives on our domain PCs. It has been observed that the registry entry in USBSTOR is automatically generated at different times, even though usb was kept safe and is not used in the domain. Is it possible for Usb Pen Dive Usage entries to be automatically replicated to the USBSTOR registry in the Windows domain?

Under what circumstances will a USB entry be automatically generated in USBSTOR without the Pendrive actually being inserted on PCs?