Did It Execute? MUI Cache (Shellbag)

What is the MUI Cache.... What are Shellbags

Have you noticed when you open an application GUI using Windows, Windows seems to remember where the windows were, well it stores a bit more than that for this purpose, all of which is useful in an investigation.

Location of Data: 


Shellbags may be found in a few locations, depending on operating system version and user profile. On a Windows XP system, shellbags may be found under:


  • HKEY\_USERS\{USERID}\Software\Microsoft\Windows\Shell\
  • HKEY\_USERS\{USERID}\Software\Microsoft\Windows\ShellNoRoam\
  • The NTUser.dat hive file persists the Registry key HKEY\_USERS\{USERID}\.


On a Windows 7 system, shellbags may be found under:


  • HEKY\_USERS\{USERID}\Local Settings\Software\Microsoft\Windows\Shell\
  • The UsrClass.dat hive file persists the registry key HKEY\_USERS\{USERID}\.


Reference:


http://www.williballenthin.com/forensics/shellbags/

Comments

Popular posts from this blog

Did It Execute? AppCompatCache

PowerShell FILETIME conversion

Did It Execute? amcahce.hve