Notifications
Clear all
08/09/2010 6:55 pm
That's always the way isn't it?
10/09/2010 12:06 am
When a file based TrueCrypt volume is mounted, it will create the entry that you listed.
gmarshall139 gave a good suggestion.
It is possible that the encrypted volumes are on external device(s), therefore looking at USB devices attached and correlating it with the listed registry entries can imply some relations.
Furthermore, as s/he pointed out detecting truecrypt file volumes is not always straight forward.
Igor_Michailov gave excellent guideline how to detect such volumes programatically.
Honestly, I just eye-ball the files in hex once I culled known headered ones. That gives me a general idea if they are data files, or encrypted files. (yes, I am aware that there are wrappers.)
Page 2 / 2
Prev