Shellbags volatilit...
 
Notifications
Clear all

Shellbags volatility

4 Posts
3 Users
0 Likes
1,475 Views
(@wotsits)
Posts: 253
Reputable Member
Topic starter
 

How volatile are shell bags? Over time, or as people clear their history or use clean up tools like CCleaner how are the shell bags affected? Do they always stay there or do they get wiped?

 
Posted : 15/07/2017 7:43 am
Novunix
(@novunix)
Posts: 35
Eminent Member
 

that depends, but without intervention they will remain.

You can manually delete them and there are also programs available to target shellbags and delete them, e.g. CCEnhancer or Shellbag Analyzer & Cleaner

 
Posted : 16/07/2017 2:58 am
(@wotsits)
Posts: 253
Reputable Member
Topic starter
 

Do shellbags remain until you manually remove them?

Are shellbags a part of the windows registry and is there a different analysis of the windows registry that can yield further results?

If you have an NTFS external drive (not a windows installation drive) is it possible you could find shellbags or a similar kind of registry on there or is it only found in windows installations?

 
Posted : 24/07/2017 7:18 pm
jaclaz
(@jaclaz)
Posts: 5133
Illustrious Member
 

Are shellbags a part of the windows registry and is there a different analysis of the windows registry that can yield further results?

If you have an NTFS external drive (not a windows installation drive) is it possible you could find shellbags or a similar kind of registry on there or is it only found in windows installations?

You seem like having no previous knowledge of what the Registry is, of where it is and of what it contains (which is BTW slightly different for different version of Windows). 😯

Make sure to go through these
https://support.microsoft.com/en-us/help/307545/how-to-recover-from-a-corrupted-registry-that-prevents-windows-xp-from
https://en.wikipedia.org/wiki/User_profiles_in_Microsoft_Windows
https://msdn.microsoft.com/en-us/library/windows/desktop/ms724877(v=vs.85).aspx
https://msdn.microsoft.com/en-us/library/windows/desktop/bb776892(v=vs.85).aspx
https://digital-forensics.sans.org/blog/2008/10/31/shellbags-registry-forensics
https://digital-forensics.sans.org/blog/2011/07/05/shellbags
https://www.sans.org/reading-room/whitepapers/forensics/windows-shellbag-forensics-in-depth-34545

I would guess that after having read them you won't ask those questions again.

jaclaz

 
Posted : 24/07/2017 10:20 pm
Share: