Shellbags volatilit...
 
Notifications
Clear all

Shellbags volatility

4 Posts
3 Users
0 Reactions
2,201 Views
(@wotsits)
Reputable Member
Joined: 10 years ago
Posts: 253
Topic starter  

How volatile are shell bags? Over time, or as people clear their history or use clean up tools like CCleaner how are the shell bags affected? Do they always stay there or do they get wiped?


   
Quote
Novunix
(@novunix)
Eminent Member
Joined: 16 years ago
Posts: 35
 

that depends, but without intervention they will remain.

You can manually delete them and there are also programs available to target shellbags and delete them, e.g. CCEnhancer or Shellbag Analyzer & Cleaner


   
ReplyQuote
(@wotsits)
Reputable Member
Joined: 10 years ago
Posts: 253
Topic starter  

Do shellbags remain until you manually remove them?

Are shellbags a part of the windows registry and is there a different analysis of the windows registry that can yield further results?

If you have an NTFS external drive (not a windows installation drive) is it possible you could find shellbags or a similar kind of registry on there or is it only found in windows installations?


   
ReplyQuote
jaclaz
(@jaclaz)
Illustrious Member
Joined: 18 years ago
Posts: 5133
 

Are shellbags a part of the windows registry and is there a different analysis of the windows registry that can yield further results?

If you have an NTFS external drive (not a windows installation drive) is it possible you could find shellbags or a similar kind of registry on there or is it only found in windows installations?

You seem like having no previous knowledge of what the Registry is, of where it is and of what it contains (which is BTW slightly different for different version of Windows). 😯

Make sure to go through these
https://support.microsoft.com/en-us/help/307545/how-to-recover-from-a-corrupted-registry-that-prevents-windows-xp-from
https://en.wikipedia.org/wiki/User_profiles_in_Microsoft_Windows
https://msdn.microsoft.com/en-us/library/windows/desktop/ms724877(v=vs.85).aspx
https://msdn.microsoft.com/en-us/library/windows/desktop/bb776892(v=vs.85).aspx
https://digital-forensics.sans.org/blog/2008/10/31/shellbags-registry-forensics
https://digital-forensics.sans.org/blog/2011/07/05/shellbags
https://www.sans.org/reading-room/whitepapers/forensics/windows-shellbag-forensics-in-depth-34545

I would guess that after having read them you won't ask those questions again.

jaclaz


   
ReplyQuote
Share: