Registry Hives

..................................................................................................................................................

The following registry keys are extracted and reported on by OnScene LHF. Many of these registry keys are a source of  valuable evidence during computer forensic investigations.

OnScene LHF will allow you to add your own registry keys. This can be useful for software licensing audits.

Registry Location:

HKCU

Key Location:

\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell

Description:

..................................................................................................................................................

Registry Location:

HKLM

Key Location:

\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\System

Description:

Indicates programs to be executed in System mode.

..................................................................................................................................................

Registry Location:

HKLM

Key Location:

\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\TaskMan

Description:

Specifies the Task Manager to be used by Windows. The default is TaskMan.exe, but the SysInternals.com tool, Process Explorer, can replace this value.

..................................................................................................................................................

Registry Location:

HKLM

Key Location:

\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit

Description:

Lists programs to be automatically run when the user logs in. Userinit.exe is responsible for shell execution. Nddeagnt.exe is responsible for NetDDE. Multiple programs may be listed.

..................................................................................................................................................

Registry Location:

HKLM

Key Location:

\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\

Description:

Specifies programs to be run when certain system events (ie, logon, logoff, startup, shutdown, startscreensaver, stopscreensaver) occur. The event is generated by Winlogon.exe, at which point the system will look for a DLL within this key to handle the event.

..................................................................................................................................................

Registry Location:

HKLM

Key Location:

\System\CurrentControlSet\Control\Session Manager\BootExecute

Description:

Specifies the applications, services, and commands executed during startup.

..................................................................................................................................................

Registry Location:

HKLM

Key Location:

\System\CurrentControlSet\Services

Description:

Subkeys list services to be executed, most of which are run as LocalSystem. The Hacker Defender rootkit installs as a service.

..................................................................................................................................................

Registry Location:

HKLM

Key Location:

\Software\Microsoft\Active Setup\Installed Components\

Description:

..................................................................................................................................................

Registry Location:

HKLM

Key Location:

\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Startup

Description:

Designates location of Startup folders; ie, Autostart directory

..................................................................................................................................................

Registry Location:

HKCU

Key Location:

\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Startup

Description:

..................................................................................................................................................

Triage LHF module reports on this key

194 Registry Hives: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20    [ view all ]

Computer Forensics Experts

Creating an Image with OSI

Previewing PST Files

On Scene Computer Forensics

Copy with MD5 report

Windows Recycle Bin

Computer Forensics For Apple Mac

Viewing the Internet Cache

Registry Hives



Using OnScene Investigator

Using Registry LHF

Down Data Sheet

Uses for OnScene Investigator

Project Roadmap



Find a Reseller

Become a Reseller




Training Certification


 
 
 
Home I Site Map I About Us I Help I Terms & Conditions
Copyright 2007 www.forensicsmatter.com All Rights Reserved.