Difference between pages "Upcoming events" and "Windows 7"

From ForensicsWiki
(Difference between pages)
Jump to: navigation, search
(Conferences)
 
 
Line 1: Line 1:
<b>PLEASE READ BEFORE YOU EDIT THE LISTS BELOW</b><br>
 
When events begin the same day, events of a longer length should be listed first.  New postings of events with the same date(s) as other events should be added after events already in the list. Please use three-letter month abbreviations (i.e. Sep, NOT Sept. or September), use two digit dates (i.e. Jan 01 NOT Jan 1), and use date ranges rather than listing every date during an event(i.e. Jan 02-05, NOT Jan 02, 03, 04, 05).<br>
 
<i>Some events may be <u>limited</u> to <b>Law Enforcement Only</b> or to a specific audience.  Such restrictions should be noted when known.</i>
 
  
This is a BY DATE listing of upcoming events relevant to [[digital forensics]].  It is not an all inclusive list, but includes most well-known activities.  Some events may duplicate events on the generic [[conferences]] page, but entries in this list have specific dates and locations for the upcoming event.
 
  
This listing is divided into three sections (described as follows):<br>
+
== File Structure ==
<ol><li><b><u>[[Upcoming_events#Calls_For_Papers|Calls For Papers]]</u></b> - Calls for papers for either Journals or for Conferences, relevant to Digital Forensics (Name, Closing Date, URL)</li><br>
+
File systems are covered separately.
<li><b><u>[[Upcoming_events#Conferences|Conferences]]</u></b> - Conferences relevant for Digital Forensics (Name, Date, Location, URL)</li><br>
+
<li><b><u>[[Training Courses and Providers]]</u></b> - Training </li><br></ol>
+
  
== Calls For Papers ==
+
== SSD ==
Please help us keep this up-to-date with deadlines for upcoming conferences that would be appropriate for forensic research.
+
Per MS [http://support.microsoft.com/kb/2727880 KB2727880], when Windows 7 is installed on a system with an SSD drive, automatic defragmentation and SuperFetch/prefetching are disabled.
  
{| border="0" cellpadding="2" cellspacing="2" align="top"
+
Further, [http://technet.microsoft.com/en-us/magazine/ff356869.aspx this TechNet post] states:  
|- style="background:#bfbfbf; font-weight: bold"
+
<i>Since ReadyBoost will not provide a performance gain when the primary disk is an SSD, Windows 7 disables ReadyBoost when reading from an SSD drive.</i>
! width="30%|Title
+
! width="15%"|Due Date
+
! width="15%"|Notification Date
+
! width="40%"|Website
+
|-
+
|4th Annual Open Source Digital Forensics Conference
+
|May 01, 2013
+
|
+
|http://www.basistech.com/about-us/events/open-source-forensics-conference/
+
|-
+
|5th International Conference on Digital Forensics & Cyber Crime (ICDF2C 2013)
+
|May 17, 2013
+
|Jun 17, 2013
+
|http://d-forensics.org/2013/show/cf-papers
+
|-
+
|2nd Cyberpatterns: Unifying Design Patterns with Security, Attack and Forensic Patterns Workshop
+
|May 20, 2013
+
|Jun 10, 2013
+
|http://tech.brookes.ac.uk/CyberPatterns2013
+
|-
+
|29th Annual Computer Security Applications Conference
+
|Jun 01, 2013
+
|Aug 15, 2013
+
|http://www.acsac.org/2013/cfp/
+
|-
+
|Eighth International Workshop on Systematic Approaches to Digital Forensics Engineering
+
|June 24, 2013
+
|October 1, 2013
+
|http://conf.ncku.edu.tw/sadfe/sadfe13/
+
|-
+
|AAFS 66th Annual Scientific Meeting
+
|Aug 01, 2013
+
|Nov 2013
+
|http://www.aafs.org/aafs-66th-annual-scientific-meeting
+
|-
+
|}
+
  
See also [http://www.wikicfp.com/cfp/servlet/tool.search?q=forensics WikiCFP 'Forensics']
+
  
== Conferences ==
 
{| border="0" cellpadding="2" cellspacing="2" align="top"
 
|- style="background:#bfbfbf; font-weight: bold"
 
! width="40%"|Title
 
! width="20%"|Date/Location
 
! width="40%"|Website
 
|-
 
|8th Annual Workshop on Digital Forensics and Incident Analysis (WDFIA)
 
|May 08-10<br>Lisbon, Portugal
 
|http://www.wdfia.org/default.asp
 
|-
 
|European Information Security Multi-Conference (EISMC 2013)
 
|May 08-10<br>Lisbon, Portugal
 
|http://www.eismc.org/
 
|-
 
|IEEE Symposium on Security & Privacy
 
|May 19-23<br>San Francisco, CA
 
|http://www.ieee-security.org/TC/SP2013/index.html
 
|-
 
|International Workshop on Cyber Crime
 
|May 24<br>San Francisco, CA
 
|http://stegano.net/IWCC2013/
 
|-
 
|Techno Security and Forensics Investigation Conference
 
|Jun 02-05<br>Myrtle Beach, SC
 
|http://www.thetrainingco.com/html/Security%20Conference%202013.html
 
|-
 
|Mobile Forensics World
 
|Jun 02-05<br>Myrtle Beach, SC
 
|http://www.techsec.com/html/MFC-2013-Spring.html
 
|-
 
|ADFSL 2013 Conference on Digital Forensics, Security and Law
 
|Jun 10-12<br>Richmond, VA
 
|http://www.digitalforensics-conference.org/index.htm
 
|-
 
|FIRST Conference
 
|Jun 16-21<br>Bangkok, Thailand
 
|http://conference.first.org/2013/
 
|-
 
|The 1st ACM Workshop on Information Hiding and Multimedia Security
 
|Jun 17-19<br>Montpellier, France
 
|http://ihmmsec.org/
 
|-
 
|28th IFIP TC-11 SEC 2013 International Information Security and Privacy Conference
 
|Jul 08-10<br>Auckland, New Zealand
 
|http://www.sec2013.org/
 
|-
 
|The Second International Workshop on Cyber Patterns: Unifying Design Patterns with Security, Attack and Forensic Patterns
 
|Jul 08-09<br>Abingdon, Oxfordshire, United Kingdom
 
|http://tech.brookes.ac.uk/CyberPatterns2013
 
|-
 
|10th Conference on Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA)
 
|Jul 18-19<br>Berlin, Germany
 
|http://dimva.sec.t-labs.tu-berlin.de/
 
|-
 
|Symposium On Usable Privacy and Security (SOUPS)
 
|Jul 24-26<br>Newcastle, United Kingdom
 
|http://cups.cs.cmu.edu/soups/2013/
 
|-
 
|BlackHat USA
 
|Jul 27-Aug 01<br>Las Vegas, NV
 
|https://www.blackhat.com/us-13/
 
|-
 
|DFRWS 2013
 
|Aug 04-07<br>Monterey, CA
 
|http://dfrws.org/2013
 
|-
 
|Regional Computer Forensics Group GMU 2013
 
|Aug 05-09<br>Fairfax, VA
 
|http://www.rcfg.org
 
|-
 
|6th USENIX Workshop on Large-Scale Exploits and Emergent Threats (LEET '13)
 
|Aug 12<br>Washington, DC
 
|https://www.usenix.org/conferences?page=1
 
|-
 
|8th USENIX Workshop on Hot Topics in Security (HotSec '13)
 
|Aug 13<br>Washington, DC
 
|https://www.usenix.org/conferences?page=1
 
|-
 
|22nd USENIX Security Symposium - USENIX Security '13
 
|Aug 14-16<br>Washington, DC
 
|https://www.usenix.org/conference/usenixsecurity13
 
|-
 
|6th International Workshop on Digital Forensics (WSDF 2013)
 
|Sep 02-06<br>Regensburg, Germany
 
|http://www.ares-conference.eu/conf/index.php?option=com_content&view=article&id=49&Itemid=95
 
|-
 
|2013 HTCIA International Conference & Training Expo
 
|Sep 08-11<br>Summerlin, NV
 
|http://www.htciaconference.org/
 
|-
 
|New Security Paradigms Workshop (NSPW)
 
|Sep 09-12<br>The Banff Center, Canada
 
|http://www.nspw.org/current/
 
|-
 
|Black Hat-Regional Summit
 
|Sep 10-12<br>Istanbul, Turkey
 
|https://www.blackhat.com/is-13/
 
|-
 
|French-Speaking Days on Digital Investigations-Journées Francophones de l'Investigation Numérique (AFSIN)
 
|Sep 10-12<br>Neuchâtel, Switzerland
 
|https://www.afsin.org/
 
|-
 
|5th International Conference on Digital Forensics & Cyber Crime
 
|Sep 25-27<br>Moscow, Russia
 
|http://d-forensics.org/2013/show/home
 
|-
 
|VB2013 - the 23rd Virus Bulletin International Conference
 
|Oct 02-04<br>Berlin, Germany
 
|http://www.virusbtn.com/conference/vb2013/index
 
|-
 
|16th International Symposium on Research in Attacks, Intrusions and Defenses (RAID)
 
|Oct 23-25<br>St. Lucia
 
|http://www.raid2013.org/
 
|-
 
|4th Annual Open Source Digital Forensics Conference (OSDF)
 
|Nov 04-05<br>Chantilly, VA
 
|http://www.basistech.com/about-us/events/open-source-forensics-conference/
 
|-
 
|Paraben Forensic Innovations Conference
 
|Nov 13-15<br>Salt Lake City, UT
 
|http://www.pfic-conference.com/
 
|-
 
|8th International Workshop on Systematic Approaches to Digital Forensic Engineering (SADFE)
 
|Nov 21-22<br>Hong Kong, China
 
|http://conf.ncku.edu.tw/sadfe/sadfe13/
 
|-
 
|Black Hat-Regional Summit
 
|Nov 26-27<br>Sao Paulo, Brazil
 
|https://www.blackhat.com/sp-13
 
|-
 
|29th Annual Computer Security Applications Conference (ACSAC)
 
|Dec 09-13<br>New Orleans, LA
 
|http://www.acsac.org
 
|-
 
|AAFS 66th Annual Scientific Meeting
 
|Feb 17-22<br>Seattle, WA
 
|http://www.aafs.org/aafs-66th-annual-scientific-meeting
 
|-
 
|}
 
  
==See Also==
+
== Jump Lists ==
* [[Training Courses and Providers]]
+
[[Jump Lists]] are Task Bar artifacts first introduced on Windows 7 (and also available on Windows 8).
==References==
+
 
* [http://faculty.cs.tamu.edu/guofei/sec_conf_stat.htm Computer Security Conference Ranking and Statistic]
+
== Registry ==  
* [http://www.kdnuggets.com/meetings/ Meetings and Conferences in Data Mining and Discovery]
+
The [[Windows_Registry]] remains a central component of the Windows 7 operating system.
* http://www.conferencealerts.com/data.htm Data Mining Conferences World-Wide]
+
 
 +
== Known keys of forensic interest ==
 +
 
 +
'''SAM Registry'''
 +
 
 +
SAM\\SAM\\Domains\\Account\\Users
 +
 
 +
SAM\\SAM\\Domains\\Account\\UsersSAM\\Domains\\Builtin\\Aliases
 +
 
 +
 
 +
'''Security Registry'''
 +
 
 +
Security\\Policy\\PolAcDmSPolicy\\PolPrDmS
 +
 
 +
Security\\Policy\\PolAdtEv
 +
 
 +
Security\\Policy\\Secrets
 +
 
 +
'''NTUSER Registry'''
 +
NTUSER\\Control Panel\\Desktop
 +
NTUSER\\Control Panel\\don\
 +
NTUSER\\Environment
 +
NTUSER\\Network
 +
NTUSER\\Printers\\Settings\\Wizard\\ConnectMRU
 +
NTUSER\\Software
 +
NTUSER\\Software\\Adobe\\Acrobat Reader\\Software\\Adobe\\Acrobat Reader\\
 +
NTUSER\\Software\\Ahead
 +
NTUSER\\Software\\America Online\\AOL Instant Messenger (TM)\\CurrentVersion\\Users
 +
NTUSER\\Software\\Ares
 +
NTUSER\\Software\\bindshell.net\\Odysseus
 +
NTUSER\\Software\\Blizzard Entertainment\\Warcraft III\\String
 +
NTUSER\\Software\\Cain\\Settings
 +
NTUSER\\Software\\DECAFme
 +
NTUSER\\Software\\Google\\Google Toolbar\\4.0\\whitelist
 +
NTUSER\\Software\\Google\\NavClient\\1.1\\History
 +
NTUSER\\Software\\JavaSoft\\Java Update\\Policy\\JavaFX
 +
NTUSER\\Software\\JavaSoft\\Prefs\\haven
 +
NTUSER\\Software\\Microsoft
 +
NTUSER\\Software\\Microsoft\\Command Processor
 +
NTUSER\\Software\\Microsoft\\Dependency Walker\\Recent File List
 +
NTUSER\\Software\\Microsoft\\IntelliPoint\\AppSpecific
 +
NTUSER\\Software\\Microsoft\\Internet Explorer\\Main
 +
NTUSER\\Software\\Microsoft\\Internet Explorer\\MainSoftware\\Microsoft\\Windows\\CurrentVersion\\Explorer\\AutoCompleteSoftware\\Microsoft\\Internet Account Manager\\Accounts
 +
NTUSER\\Software\\Microsoft\\Internet Explorer\\Settings
 +
NTUSER\\Software\\Microsoft\\Internet Explorer\\TypedURLs
 +
NTUSER\\Software\\Microsoft\\Internet Explorer\\TypedURLsTime
 +
NTUSER\\Software\\Microsoft\\MediaPlayer\\Player\\RecentFileList
 +
NTUSER\\Software\\Microsoft\\Microsoft Management Console\\Recent File List
 +
NTUSER\\Software\\Microsoft\\Multimedia\\OtherSoftware\\Microsoft\\CTF\\LangBarAddIn
 +
NTUSER\\Software\\Microsoft\\Office\\14.0Software\\Microsoft\\Office\\14.0
 +
NTUSER\\Software\\Microsoft\\Office\\Software\\Microsoft\\Office\\
 +
NTUSER\\Software\\Microsoft\\OfficeSoftware\\Microsoft\\Office\\
 +
NTUSER\\Software\\Microsoft\\PIMSRV
 +
NTUSER\\Software\\Microsoft\\Search Assistant\\ACMru
 +
NTUSER\\Software\\Microsoft\\Snapshot Viewer\\Recent File List
 +
NTUSER\\Software\\Microsoft\\Terminal Server Client\\DefaultSoftware\\Microsoft\\Terminal Server Client\\Servers
 +
NTUSER\\Software\\Microsoft\\Terminal Server Client\\Servers
 +
NTUSER\\Software\\Microsoft\\User Location Service\\Client
 +
NTUSER\\Software\\Microsoft\\Windows Live Contacts\\Database
 +
NTUSER\\Software\\Microsoft\\Windows Live Mail
 +
NTUSER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\Compatibility Assistant\\Persisted
 +
NTUSER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\Layers
 +
NTUSER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\PrinterPorts
 +
NTUSER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows
 +
NTUSER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles
 +
NTUSER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook\\0a0d020000000000c000000000000046
 +
NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion
 +
NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\App Management\\ARPCache
 +
NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Applets
 +
NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer
 +
NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\BitBucket
 +
NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ComDlg32
 +
NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ComputerDescriptions
 +
NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ControlPanel
 +
NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts
 +
NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Map Network Drive MRU
 +
NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MenuOrder
 +
NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2
 +
NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\PublishingWizard\\AddNetworkPlace\\AddNetPlace\\LocationMRU
 +
NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\RecentDocs
 +
NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\RunMRU
 +
NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders
 +
NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage
 +
NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StreamMRU
 +
NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\TypedPaths
 +
NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist
 +
NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Wallpaper\\MRU
 +
NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\WordWheelQuery
 +
NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{8AD9C840-044E-11D1-B3E9-00805F499D93}
 +
NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\FileHistory
 +
NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings
 +
NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap
 +
NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet SettingsSoftware\\Microsoft\\Internet Explorer\\Main\\WindowsSearch
 +
NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer
 +
NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\UFH\\SHC
 +
NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\UnreadMail
 +
NTUSER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop
 +
NTUSER\\Software\\Nico Mak Computing\\WinZip
 +
NTUSER\\Software\\ORL\\VNCHooks\\Application_Prefs
 +
NTUSER\\Software\\ORL\\VNCviewer\\MRUSoftware\\RealVNC\\VNCViewer4\\MRU
 +
NTUSER\\Software\\Piriform\\CCleaner
 +
NTUSER\\Software\\Privoxy
 +
NTUSER\\Software\\RealNetworks\\RealPlayer\\6.0\\Preferences
 +
NTUSER\\Software\\RealVNC\\VNCViewer4\\MRU
 +
NTUSER\\Software\\SimonTatham\\PuTTY\\SshHostKeys
 +
NTUSER\\Software\\Skype
 +
NTUSER\\Software\\SmartLine Vision\\aports
 +
NTUSER\\Software\\SysInternals
 +
NTUSER\\Software\\Sysinternals\\RootkitRevealer
 +
NTUSER\\Software\\VMware
 +
NTUSER\\Software\\WinRAR\\ArcHistory

Revision as of 15:18, 12 September 2013


File Structure

File systems are covered separately.

SSD

Per MS KB2727880, when Windows 7 is installed on a system with an SSD drive, automatic defragmentation and SuperFetch/prefetching are disabled.

Further, this TechNet post states: Since ReadyBoost will not provide a performance gain when the primary disk is an SSD, Windows 7 disables ReadyBoost when reading from an SSD drive.



Jump Lists

Jump Lists are Task Bar artifacts first introduced on Windows 7 (and also available on Windows 8).

Registry

The Windows_Registry remains a central component of the Windows 7 operating system.

Known keys of forensic interest

SAM Registry

SAM\\SAM\\Domains\\Account\\Users

SAM\\SAM\\Domains\\Account\\UsersSAM\\Domains\\Builtin\\Aliases


Security Registry

Security\\Policy\\PolAcDmSPolicy\\PolPrDmS

Security\\Policy\\PolAdtEv

Security\\Policy\\Secrets

NTUSER Registry NTUSER\\Control Panel\\Desktop NTUSER\\Control Panel\\don\ NTUSER\\Environment NTUSER\\Network NTUSER\\Printers\\Settings\\Wizard\\ConnectMRU NTUSER\\Software NTUSER\\Software\\Adobe\\Acrobat Reader\\Software\\Adobe\\Acrobat Reader\\ NTUSER\\Software\\Ahead NTUSER\\Software\\America Online\\AOL Instant Messenger (TM)\\CurrentVersion\\Users NTUSER\\Software\\Ares NTUSER\\Software\\bindshell.net\\Odysseus NTUSER\\Software\\Blizzard Entertainment\\Warcraft III\\String NTUSER\\Software\\Cain\\Settings NTUSER\\Software\\DECAFme NTUSER\\Software\\Google\\Google Toolbar\\4.0\\whitelist NTUSER\\Software\\Google\\NavClient\\1.1\\History NTUSER\\Software\\JavaSoft\\Java Update\\Policy\\JavaFX NTUSER\\Software\\JavaSoft\\Prefs\\haven NTUSER\\Software\\Microsoft NTUSER\\Software\\Microsoft\\Command Processor NTUSER\\Software\\Microsoft\\Dependency Walker\\Recent File List NTUSER\\Software\\Microsoft\\IntelliPoint\\AppSpecific NTUSER\\Software\\Microsoft\\Internet Explorer\\Main NTUSER\\Software\\Microsoft\\Internet Explorer\\MainSoftware\\Microsoft\\Windows\\CurrentVersion\\Explorer\\AutoCompleteSoftware\\Microsoft\\Internet Account Manager\\Accounts NTUSER\\Software\\Microsoft\\Internet Explorer\\Settings NTUSER\\Software\\Microsoft\\Internet Explorer\\TypedURLs NTUSER\\Software\\Microsoft\\Internet Explorer\\TypedURLsTime NTUSER\\Software\\Microsoft\\MediaPlayer\\Player\\RecentFileList NTUSER\\Software\\Microsoft\\Microsoft Management Console\\Recent File List NTUSER\\Software\\Microsoft\\Multimedia\\OtherSoftware\\Microsoft\\CTF\\LangBarAddIn NTUSER\\Software\\Microsoft\\Office\\14.0Software\\Microsoft\\Office\\14.0 NTUSER\\Software\\Microsoft\\Office\\Software\\Microsoft\\Office\\ NTUSER\\Software\\Microsoft\\OfficeSoftware\\Microsoft\\Office\\ NTUSER\\Software\\Microsoft\\PIMSRV NTUSER\\Software\\Microsoft\\Search Assistant\\ACMru NTUSER\\Software\\Microsoft\\Snapshot Viewer\\Recent File List NTUSER\\Software\\Microsoft\\Terminal Server Client\\DefaultSoftware\\Microsoft\\Terminal Server Client\\Servers NTUSER\\Software\\Microsoft\\Terminal Server Client\\Servers NTUSER\\Software\\Microsoft\\User Location Service\\Client NTUSER\\Software\\Microsoft\\Windows Live Contacts\\Database NTUSER\\Software\\Microsoft\\Windows Live Mail NTUSER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\Compatibility Assistant\\Persisted NTUSER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\Layers NTUSER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\PrinterPorts NTUSER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows NTUSER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles NTUSER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook\\0a0d020000000000c000000000000046 NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\App Management\\ARPCache NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Applets NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\BitBucket NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ComDlg32 NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ComputerDescriptions NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ControlPanel NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Map Network Drive MRU NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MenuOrder NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2 NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\PublishingWizard\\AddNetworkPlace\\AddNetPlace\\LocationMRU NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\RecentDocs NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\RunMRU NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StreamMRU NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\TypedPaths NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Wallpaper\\MRU NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\WordWheelQuery NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{8AD9C840-044E-11D1-B3E9-00805F499D93} NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\FileHistory NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet SettingsSoftware\\Microsoft\\Internet Explorer\\Main\\WindowsSearch NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\UFH\\SHC NTUSER\\Software\\Microsoft\\Windows\\CurrentVersion\\UnreadMail NTUSER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop NTUSER\\Software\\Nico Mak Computing\\WinZip NTUSER\\Software\\ORL\\VNCHooks\\Application_Prefs NTUSER\\Software\\ORL\\VNCviewer\\MRUSoftware\\RealVNC\\VNCViewer4\\MRU NTUSER\\Software\\Piriform\\CCleaner NTUSER\\Software\\Privoxy NTUSER\\Software\\RealNetworks\\RealPlayer\\6.0\\Preferences NTUSER\\Software\\RealVNC\\VNCViewer4\\MRU NTUSER\\Software\\SimonTatham\\PuTTY\\SshHostKeys NTUSER\\Software\\Skype NTUSER\\Software\\SmartLine Vision\\aports NTUSER\\Software\\SysInternals NTUSER\\Software\\Sysinternals\\RootkitRevealer NTUSER\\Software\\VMware NTUSER\\Software\\WinRAR\\ArcHistory