13.07.2013 Views

Taking Registry Analysis to the Next Level - SANS Computer ...

Taking Registry Analysis to the Next Level - SANS Computer ...

Taking Registry Analysis to the Next Level - SANS Computer ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Testing VM<br />

GRR <strong>Registry</strong>Decoder RegRipper<br />

Found 2 RunOnce<br />

keys: 1 in<br />

LocalService and 1 in<br />

NetworkService<br />

Found 1 Run keys: 1<br />

in Local Service, 1 in<br />

NetworkService, and<br />

2 in System<br />

RunOnce keys are<br />

listed under <strong>the</strong> Run<br />

key plugin<br />

Found 4 Run keys: 2<br />

in Default and 2 for<br />

System<br />

No plugin detects<br />

RunOnce keys<br />

Found 3 Run keys: 1<br />

in Default and 2 in<br />

System<br />

2 BHO 3 BHO, but 2 were<br />

repeated<br />

NSTR in Services NSTR in Services<br />

NSTR in WinLogon NSTR in WinLogon

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!