|
Registry Location:
SOFTWARE
Key Location:
\Microsoft\Windows\CurrentVersion\Policies\System\LegalNoticeText
Description:
Banner / boot message
..................................................................................................................................................
Registry Location:
SOFTWARE
Key Location:
\Microsoft\WindowsNT\CurrentVersion\Winlogon
Description:
Last logged on user
..................................................................................................................................................
Registry Location:
SOFTWARE
Key Location:
\Microsoft\Windows\CurrentVersion\Policies\System\LegalNoticeCaption
Description:
Legal captions used
..................................................................................................................................................
Registry Location:
HKCU
Key Location:
\Software\Microsoft\CurrentVersion\Applets\Paint\Recent File List
Description:
Files accessed with Paint program
..................................................................................................................................................
Registry Location:
HKCU
Key Location:
\Software\Microsoft\CurrentVersion\Applets\WordPad\Recent File List
Description:
Files accessed with WordPad
..................................................................................................................................................
Registry Location:
HKCU
Key Location:
\Software\Microsoft\MediaPlayer\Player\RecentFileList
Description:
Most Recently Used Files accessed with Media Player
..................................................................................................................................................
Registry Location:
HKCU
Key Location:
\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU
Description:
Most Recently Used List of programs last accessed
..................................................................................................................................................
Registry Location:
HKCU
Key Location:
\Software\Nico Mak Computing\WinZip\filemenu
Description:
Most Recently Used Winzip archives
..................................................................................................................................................
Registry Location:
HKLM
Key Location:
\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
Description:
List of programs that run after designated event
..................................................................................................................................................
Registry Location:
NTUSER.DAT
Key Location:
\Software\Microsoft\MessengerService\ FtReceiveFolder
Description:
Location of Received Files
..................................................................................................................................................
Triage LHF module reports on this key
|