Professional Documents
Culture Documents
DIGITAL FORENSIC
By:
FACULTY OF COMPUTING
It shows information specific to the user account include various settings and properties
associated with the user account, but the specifics depend on the version of Windows and any
customizations made to the system.
SOFTWARE
A. C:\Users\yusuf\OneDrive\Desktop\Week 5 DigFor\SOFTWARE:
Microsoft\Windows NT\CurrentVersion
It shows the list of wifi or network names that the device has been connected to.
C. C:\Users\yusuf\OneDrive\Desktop\Week 5 DigFor\SOFTWARE:
Microsoft\Windows\CurrentVersion\Authentication\LogonUI
Shows information about user account on this device.
E. C:\Users\yusuf\OneDrive\Desktop\Week 5 DigFor\SOFTWARE:
Microsoft\Windows Portable Devices\Devices
It shows the list of device names that the laptop has been connected to.
F. C:\Users\yusuf\OneDrive\Desktop\Week 5 DigFor\SOFTWARE:
Microsoft\Windows\CurrentVersion\Uninstall
It shows the list of application names that have been uninstalled/deleted by the device.
G. C:\Users\yusuf\OneDrive\Desktop\Week 5 DigFor\SOFTWARE:
Microsoft\Windows\CurrentVersion\Run
It show the system that always runs in the background system on this device.
SYSTEM
H. C:\Users\yusuf\OneDrive\Desktop\Week 5 DigFor\SYSTEM:
ControlSet001\Control\ComputerName\ComputerName
J. C:\Users\yusuf\OneDrive\Desktop\Week 5 DigFor\SYSTEM:
ControlSet001\Control\Windows
It shows various configuration settings related to the behavior and appearance of the
Windows operating system.
K. C:\Users\yusuf\OneDrive\Desktop\Week 5 DigFor\SYSTEM:
ControlSet001\Control\CrashControl
It shows information about how many times the system crash/error appear.
L. C:\Users\yusuf\OneDrive\Desktop\Week 5 DigFor\SYSTEM:
ControlSet001\Control\Session Manager\Memory Management
M. C:\Users\yusuf\OneDrive\Desktop\Week 5 DigFor\SYSTEM:
ControlSet001\Services
It shows information about configuration settings for various services installed on the
system.
NTUSER.DAT
A. C:\Users\yusuf\OneDrive\Desktop\Week 5 DigFor\NTUSER.DAT:
Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
Shows a list of apps started when the device is turned on in this device.
C. C:\Users\yusuf\OneDrive\Desktop\Week 5 DigFor\NTUSER.DAT:
Software\Microsoft\Windows\CurrentVersion\Explorer\WordWheelQuery