Difference between revisions of "Windows SuperFetch Format"

From ForensicsWiki
Jump to: navigation, search
(File header)
Line 19: Line 19:
 
| 0
 
| 0
 
| 4
 
| 4
| 0x304D454D ("MEM0") or 0x4F4D454D ("MEMO")
+
| 0x4F4D454D ("MEMO") or 0x304D454D ("MEM0")
 
| Signature
 
| Signature
 
|-
 
|-
Line 28: Line 28:
 
|-
 
|-
 
|}
 
|}
 +
 +
Where:
 +
* 0x4F4D454D ("MEMO") is used on Windows Vista
 +
* 0x304D454D ("MEM0") is used on Windows 7
  
 
=== Compressed blocks ===
 
=== Compressed blocks ===

Revision as of 00:53, 15 April 2014

Information icon.png

Please help to improve this article by expanding it.
Further information might be found on the discussion page.

MEMO file

Some of the Ag*.db files are MEMO files.

The MEMO file consists of:

  • file header
  • compressed blocks

File header

The file header is 84 bytes of size and consists of:

Offset Size Value Description
0 4 0x4F4D454D ("MEMO") or 0x304D454D ("MEM0") Signature
4 4 Uncompressed (total) data size

Where:

  • 0x4F4D454D ("MEMO") is used on Windows Vista
  • 0x304D454D ("MEM0") is used on Windows 7

Compressed blocks

The file header is followed by compressed blocks:

Offset Size Value Description
0 4 Compressed data size
4 ... Compressed data

Uncompressed data

TODO

TRX file

The Ag*.db.trx files are TRX files.

Note that the following format specification is incomplete.

File header

The file header is variable of size and consists of:

Offset Size Value Description
0 4 1 Unknown (Version?)
4 4 Unknown
8 4 File size
12 4 Maximum number of records (of the record offsets array)
16 4 Number of records
20 ... Record offsets array, where the record offset is a 32-bit integer. Unused record offset are set to 0.

Record

TODO describe

See Also

External Links