All,
I've updated the code to the offline Registry parsing script that I posted.
The script is here
http//
The code is cleaner, more modular, and there's better documentation. I added in a small tweak to automagically translate the value names under the UserAssist key, as well.
My blog entry on it is here
http//
The archive contains a JPG image of a PPT slide…in order to get a better handle on things and how one parses through the Registry, I had to diagram it out…that's what the image is - my diagram. There's no explanation attached to it, so if you're interested, let me know and I'll add one…
H. Carvey
"Windows Forensics and Incident Recovery"
http//
http//windowsir.blogspot.com
Nice - thanks for the update Harlan. )
Guidoz,
Thanks. Should I take that to mean that you've tried it and it worked well for you?
H. Carvey
"Windows Forensics and Incident Recovery"
windowsir.blogspot.com
http//
www.windows-ir.com/regparse.zip
The link doesn't work any more. Is the tool no longer available?
I took it down b/c no one seemed interested.
I've posted the script in the Windows Forensic Analysis Yahoo Group.
Harlan
I write first time from Japan
I want to get "Offline Registry Parser".
What shoud I do ?
Let me know please.
Thanks. D