The SetRegTime tool can modify the LastWriteTime timestamp in the registry on mounted hives; http//
code.google.com/p/mft2csv/wiki/SetRegTime
Very good ) , updated previous post.
From the given tool's page
My goal is to shed some light on the reality that registry timestamp manipulation is in fact very trivial. As a consequence it further reinforces the importance of proper (timeline) analysis, to get at the full picture and detect such attempts at timestamp modification.
jaclaz
Hi,
• After logging on to a system, a temporary profile gets loaded that shows when an account was created. I guess that can prove to be helpful.
• To make significant changes to the registry keys, export your changes to a .reg file and follow them -
1. Click Start –> Run
2. Type regedit in the pop up box
3. Click File –> Export
Regards
Hi,
• After logging on to a system, a temporary profile gets loaded that shows when an account was created. I guess that can prove to be helpful.
• To make significant changes to the registry keys, export your changes to a .reg file and follow them -
1. Click Start –> Run
2. Type regedit in the pop up box
3. Click File –> ExportRegards
Wow. 😯
Wouldn't these info be way too advanced to be posted on this thread? ?
jaclaz