Registry Hives

..................................................................................................................................................

The following registry keys are extracted and reported on by OnScene LHF. Many of these registry keys are a source of  valuable evidence during computer forensic investigations.

OnScene LHF will allow you to add your own registry keys. This can be useful for software licensing audits.

Registry Location:

HKCU

Key Location:

\Software\Microsoft\Terminal Server Client\Default

Description:

MRU list containing entries corresponding to terminal servers connected to by user

..................................................................................................................................................

Registry Location:

HKCU

Key Location:

\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU

Description:

MRU list containing entries that detail last visited locations in Windows Explorer

..................................................................................................................................................

Registry Location:

HKLM

Key Location:

\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\

Description:

Lists programs to be run when system starts.

..................................................................................................................................................

Registry Location:

HKLM

Key Location:

\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\any�subkey\

Description:

Lists programs to be run when system starts.

..................................................................................................................................................

Registry Location:

HKCU

Key Location:

\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\

Description:

..................................................................................................................................................

Registry Location:

HKLM

Key Location:

\Software\Microsoft\Windows\CurrentVersion\Run\

Description:

Lists programs to be run when system starts. On 2K and XP, these entries are ignored when booted to Safe Mode; however, entries preceded by "*" will be processed even when booted to Safe Mode. On XP, these 'Run' keys are referred to as the 'legacy Run list', as they are provided for backwards compatibility with previous versions of Windows.

..................................................................................................................................................

Registry Location:

HKLM

Key Location:

\Software\Microsoft\Windows\CurrentVersion\Run\any subkey\

Description:

Andy Aronoff, owner of SilentRunners.org, says that the contents of any subkey will be launched. At this point, I haven't tested it.

..................................................................................................................................................

Registry Location:

HKCU

Key Location:

\Software\Microsoft\Windows\CurrentVersion\Run\

Description:

..................................................................................................................................................

Registry Location:

HKLM

Key Location:

\Software\Microsoft\Windows\CurrentVersion\RunOnce\

Description:

Lists programs to be run once when the system starts, and deleted. The commands listed here are deleted before the actual commands are run. If the command is preceded by "!", the command is deleted after the command is run.

..................................................................................................................................................

Registry Location:

HKLM

Key Location:

\Software\Microsoft\Windows\CurrentVersion\RunOnce\Setup\

Description:

..................................................................................................................................................

Triage LHF module reports on this key

194 Registry Hives: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20    [ view all ]

Computer Forensics Experts

Creating an Image with OSI

Previewing PST Files

On Scene Computer Forensics

Copy with MD5 report

Windows Recycle Bin

Computer Forensics For Apple Mac

Viewing the Internet Cache

Registry Hives



Using OnScene Investigator

Using Registry LHF

Down Data Sheet

Uses for OnScene Investigator

Project Roadmap



Find a Reseller

Become a Reseller




Training Certification


 
 
 
Home I Site Map I About Us I Help I Terms & Conditions
Copyright 2007 www.forensicsmatter.com All Rights Reserved.