메뉴 건너뛰기




Volumn , Issue , 2011, Pages

Windows Registry Forensics

Author keywords

[No Author keywords available]

Indexed keywords


EID: 85013686818     PISSN: None     EISSN: None     Source Type: Book    
DOI: 10.1016/C2009-0-63856-3     Document Type: Book
Times cited : (22)

References (113)
  • 1
    • 84882373390 scopus 로고    scopus 로고
    • Windows NT contains file system tunneling capabilities. Microsoft Support. N.p., n.d. (accessed 28.07.10).
    • Windows NT contains file system tunneling capabilities. Microsoft Support. N.p., n.d. (accessed 28.07.10). http://support.microsoft.com/kb/172190.
  • 2
    • 84882406551 scopus 로고    scopus 로고
    • How to disable the Prefetcher component in Windows XP. Microsoft Support. (accessed 29.03.07).
    • How to disable the Prefetcher component in Windows XP. Microsoft Support. (accessed 29.03.07). http://support.microsoft.com/kb/307498.
  • 3
    • 84882319310 scopus 로고    scopus 로고
    • Support for Windows Server 2003 SP1 on Windows Storage Server 2003-based server appliances. Microsoft Support. (accessed 31.03.07).
    • Support for Windows Server 2003 SP1 on Windows Storage Server 2003-based server appliances. Microsoft Support. (accessed 31.03.07). http://support.microsoft.com/kb/894372.
  • 4
    • 84882314646 scopus 로고    scopus 로고
    • Windows registry information for advanced users. Microsoft Support. (accessed 04.02.08).
    • Windows registry information for advanced users. Microsoft Support. (accessed 04.02.08). http://support.microsoft.com/kb/256986.
  • 5
    • 84882402319 scopus 로고    scopus 로고
    • Understanding and configuring registry size limit (RSL). Microsoft Support. (accessed 20.02.07).
    • Understanding and configuring registry size limit (RSL). Microsoft Support. (accessed 20.02.07). http://support.microsoft.com/kb/124594.
  • 6
    • 84882421140 scopus 로고    scopus 로고
    • Registry size limit functionality has been removed from Windows Server 2003 and from Windows XP. Microsoft Support. (accessed 28.12.07).
    • Registry size limit functionality has been removed from Windows Server 2003 and from Windows XP. Microsoft Support. (accessed 28.12.07). http://support.microsoft.com/kb/292726.
  • 7
    • 84882406623 scopus 로고    scopus 로고
    • Registry redirector. Microsoft Developer Network.
    • Registry redirector. Microsoft Developer Network. http://msdn.microsoft.com/en-us/library/aa384232(VA.85).aspx.
  • 8
    • 84882380991 scopus 로고    scopus 로고
    • Registry changes in x64-based versions of Windows Server 2003 and in Windows XP Professional x64 edition. Microsoft Support. (accessed 21.04.08).
    • Registry changes in x64-based versions of Windows Server 2003 and in Windows XP Professional x64 edition. Microsoft Support. (accessed 21.04.08). http://support.microsoft.com/kb/869459.
  • 9
    • 84882364146 scopus 로고    scopus 로고
    • Registry virtualization. Microsoft Developers Network.
    • Registry virtualization. Microsoft Developers Network. http://msdn.microsoft.com/en-us/library/aa965884(VS.85).aspx.
  • 10
    • 84882389869 scopus 로고    scopus 로고
    • What are ControlSets? What is CurrentControlSet?. Microsoft Support. (accessed 01.11.06).
    • What are ControlSets? What is CurrentControlSet?. Microsoft Support. (accessed 01.11.06). http://support.microsoft.com/kb/100010.
  • 11
    • 84882442904 scopus 로고    scopus 로고
    • File types. Microsoft Developers Network.
    • File types. Microsoft Developers Network. http://msdn.microsoft.com/en-us/library/cc144148(VS.85).aspx.
  • 12
    • 84882326369 scopus 로고    scopus 로고
    • Offline NT password & registry editor.
    • Offline NT password & registry editor. http://pogostick.net/~pnh/ntpasswd.
  • 13
    • 84882428652 scopus 로고    scopus 로고
    • Info: working with the FILETIME structure. Microsoft Support. (accessed 23.01.07).
    • Info: working with the FILETIME structure. Microsoft Support. (accessed 23.01.07). http://support.microsoft.com/kb/188768.
  • 14
    • 84882410416 scopus 로고    scopus 로고
    • SystemTime structure. Microsoft Developer Network.
    • SystemTime structure. Microsoft Developer Network. http://msdn.microsoft.com/en-us/library/ms724950%28VA.85%29.aspx.
  • 15
    • 84882337040 scopus 로고    scopus 로고
    • Registry value types. Microsoft Developer Network.
    • Registry value types. Microsoft Developer Network. http://msdn.microsoft.com/en-us/library/ms724884.aspx.
  • 16
    • 84882345332 scopus 로고    scopus 로고
    • AutoRuns for Windows v10.02. Microsoft SysInternals site. (accessed 22.07.10).
    • AutoRuns for Windows v10.02. Microsoft SysInternals site. (accessed 22.07.10). http://technet.microsoft.com/en-us/sysinternals/bb963902.aspx.
  • 17
    • 84882344028 scopus 로고    scopus 로고
    • Script Center Home Page. Microsoft.
    • Script Center Home Page. Microsoft. http://technet.microsoft.com/en-us/scriptcenter/default.aspx.
  • 18
    • 84882436314 scopus 로고    scopus 로고
    • Registry key security and access rights. Microsoft.
    • Registry key security and access rights. Microsoft. http://msdn.microsoft.com/en-us/library/ms724878(VS.85).aspx.
  • 20
    • 84882337583 scopus 로고    scopus 로고
    • Virus alert about the Win32/Conficker worm. Microsoft Support. (accessed 8.07.10).
    • Virus alert about the Win32/Conficker worm. Microsoft Support. (accessed 8.07.10). http://support.microsoft.com/kb/962007.
  • 21
    • 84882303859 scopus 로고    scopus 로고
    • Browse regshot Files on Sourceforge.net. SourceForge.net.
    • Browse regshot Files on Sourceforge.net. SourceForge.net. http://sourceforge.net/projects/regshot/files.
  • 22
    • 84882292160 scopus 로고    scopus 로고
    • Process Monitor v2.92. Microsoft SysInternals.
    • Process Monitor v2.92. Microsoft SysInternals. http://technet.microsoft.com/en-us/sysinternals/bb896645.aspx.
  • 23
    • 84882390388 scopus 로고    scopus 로고
    • How to debug Windows Services. Microsoft Support. (accessed 2.07.10).
    • How to debug Windows Services. Microsoft Support. (accessed 2.07.10). http://support.microsoft.com/kb/824344.
  • 24
    • 84882321918 scopus 로고    scopus 로고
    • How to turn off Windows Update feature in Windows XP. Microsoft Support. (accessed 25.01.10).
    • How to turn off Windows Update feature in Windows XP. Microsoft Support. (accessed 25.01.10). http://support.microsoft.com/kb/892894.
  • 25
    • 84882327308 scopus 로고    scopus 로고
    • AccessData Product Downloads.
    • AccessData Product Downloads. http://www.accessdata.com/downloads.html.
  • 26
    • 84882351793 scopus 로고    scopus 로고
    • Technology Pathways - Computer Forensics, Digital Discovery, Auditing, Incident Response.
    • Technology Pathways - Computer Forensics, Digital Discovery, Auditing, Incident Response. http://www.techpathways.com/DesktopDefault.aspx?tabindex=3%26tabid=12.
  • 27
    • 84882392142 scopus 로고    scopus 로고
    • Tools and utilities for Windows. ImDisk Virtual Disk Driver.
    • Tools and utilities for Windows. ImDisk Virtual Disk Driver. http://www.ltr-data.se/opencode.html#ImDisk.
  • 28
    • 84882378567 scopus 로고    scopus 로고
    • ASR Data - Smart Mount.
    • ASR Data - Smart Mount. http://www.asrdata.com/SmartMount.
  • 29
    • 84882417783 scopus 로고    scopus 로고
    • Binary Intelligence: Run RegRipper against a mounted drive. (accessed 14.05.10).
    • Binary Intelligence: Run RegRipper against a mounted drive. (accessed 14.05.10). http://www.binint.com/2010/05/run-regripper-against-mounted-drive.html.
  • 30
    • 84882433742 scopus 로고    scopus 로고
    • NSSA Documentation: RegRipper, RegView, and Bluetooth Registry Settings.Blog post, 7 Oct 2008, .
    • NSSA Documentation: RegRipper, RegView, and Bluetooth Registry Settings.Blog post, 7 Oct 2008, . http://nssadoc.blogspot.com/2008/10/regripper-regview-and-bluetooth.html.
  • 32
    • 84882377921 scopus 로고    scopus 로고
    • Open Perl IDE.
    • Open Perl IDE. http://open-perl-ide.sourceforge.net.
  • 33
    • 84882347824 scopus 로고    scopus 로고
    • EPIC - Eclipse Perl Integration. http://www.epic-ide.org.
  • 34
    • 84882375286 scopus 로고    scopus 로고
    • Security Identifier. Wikipedia, .
    • Security Identifier. Wikipedia, . http://en.wikipedia.org/wiki/Security_Identifier.
  • 35
    • 84882295937 scopus 로고    scopus 로고
    • How to determine audit policies from the Registry. Microsoft Support. (accessed 01.11.06).
    • How to determine audit policies from the Registry. Microsoft Support. (accessed 01.11.06). http://support.microsoft.com/kb/246120.
  • 36
    • 84882442826 scopus 로고    scopus 로고
    • Offline NT Password& Registry Editor.
    • Offline NT Password& Registry Editor. http://www.pogostick.net/~pnh/ntpasswd.
  • 37
    • 84882392039 scopus 로고    scopus 로고
    • How to use the UserAccountControl flags to manipulate user account properties. Microsoft Support. (accessed 03.12.07).
    • How to use the UserAccountControl flags to manipulate user account properties. Microsoft Support. (accessed 03.12.07). http://support.microsoft.com/kb/305144.
  • 38
    • 84882319451 scopus 로고    scopus 로고
    • Live View.
    • Live View. http://liveview.sourceforge.net.
  • 39
    • 84882418621 scopus 로고    scopus 로고
    • How to use the SysKey utility to secure the Windows Security Accounts Manager database. Microsoft Support. (accessed 30.10.06).
    • How to use the SysKey utility to secure the Windows Security Accounts Manager database. Microsoft Support. (accessed 30.10.06). http://support.microsoft.com/kb/310105.
  • 40
    • 84882408174 scopus 로고    scopus 로고
    • Tarasco Security: Password Dumper - PWDump 7 for Windows.
    • Tarasco Security: Password Dumper - PWDump 7 for Windows. http://www.tarasco.org/security/pwdump_7.
  • 41
    • 84882422538 scopus 로고    scopus 로고
    • oxid.it - Cain & Abel.
    • oxid.it - Cain & Abel. http://www.oxid.it/cain.html.
  • 42
    • 84882333125 scopus 로고    scopus 로고
    • LM Hash. Wikipedia, .
    • LM Hash. Wikipedia, . http://en.wikipedia.org/wiki/LM_hash.
  • 43
    • 84882414741 scopus 로고    scopus 로고
    • NTLM. Wikipedia, .
    • NTLM. Wikipedia, . http://en.wikipedia.org/wiki/NTLM.
  • 44
    • 84882293447 scopus 로고    scopus 로고
    • How to prevent Windows from storing a LAN manager hash of your password in Active Directory and local SAM databases. Microsoft Support. (accessed 03.12.07).
    • How to prevent Windows from storing a LAN manager hash of your password in Active Directory and local SAM databases. Microsoft Support. (accessed 03.12.07). http://support.microsoft.com/kb/299656.
  • 45
    • 84882416517 scopus 로고    scopus 로고
    • Hacking Case. NIST.
    • Hacking Case. NIST. http://www.cfreds.nist.gov/Hacking_Case.html.
  • 46
    • 84882405415 scopus 로고    scopus 로고
    • How to turn on automatic logon in Windows XP. Microsoft Support. (accessed 10.06.08).
    • How to turn on automatic logon in Windows XP. Microsoft Support. (accessed 10.06.08). http://support.microsoft.com/kb/315231.
  • 47
    • 84882306779 scopus 로고    scopus 로고
    • OphCrack. SourceForge.
    • OphCrack. SourceForge. http://ophcrack.sourceforge.net.
  • 48
    • 84882368976 scopus 로고    scopus 로고
    • SAMInside. InsidePro.com. (accessed 25.08.10).
    • SAMInside. InsidePro.com. (accessed 25.08.10). http://www.insidepro.com/eng/saminside.shtml.
  • 49
    • 84882368028 scopus 로고    scopus 로고
    • L0phtCrack6. L0phtCrack.com.
    • L0phtCrack6. L0phtCrack.com. http://www.l0phtcrack.com.
  • 50
    • 84882337188 scopus 로고    scopus 로고
    • What are ControlSets? What is CurrentControlSet? Microsoft Support. (accessed 1.11.06).
    • What are ControlSets? What is CurrentControlSet? Microsoft Support. (accessed 1.11.06). http://support.microsoft.com/kb/100010.
  • 51
    • 84882295782 scopus 로고    scopus 로고
    • CurrentControlSet\Services Subkey Entries. Microsoft Support. (accessed 11.12.06).
    • CurrentControlSet\Services Subkey Entries. Microsoft Support. (accessed 11.12.06). http://support.microsoft.com/kb/103000.
  • 52
    • 84882435783 scopus 로고    scopus 로고
    • A description of SvcHost.exe in Windows XP Professional Edition. Microsoft Support. (accessed 10.12.07).
    • A description of SvcHost.exe in Windows XP Professional Edition. Microsoft Support. (accessed 10.12.07). http://support.microsoft.com/kb/314056.
  • 53
    • 84882442912 scopus 로고    scopus 로고
    • SANS Computer Forensic Investigation and Incident Response.
    • SANS Computer Forensic Investigation and Incident Response. http://blogs.sans.org/computer-forensics.
  • 54
    • 84882308774 scopus 로고    scopus 로고
    • TrueCrypt.
    • TrueCrypt. http://www.truecrypt.org.
  • 55
    • 84882410424 scopus 로고    scopus 로고
    • Windows 7, Windows 2008 R2, and Windows Vista setup log file locations. Microsoft Support. (accessed 15.3.07).
    • Windows 7, Windows 2008 R2, and Windows Vista setup log file locations. Microsoft Support. (accessed 15.3.07). http://support.microsoft.com/kb/927521.
  • 56
    • 84882436018 scopus 로고    scopus 로고
    • Microsoft Word bites Tony Blair in the butt.
    • Microsoft Word bites Tony Blair in the butt. http://www.computerbytesman.com/privacy/blair.htm.
  • 57
    • 84882445103 scopus 로고    scopus 로고
    • Registry Entries for Printing. Microsoft Support. (accessed 26.11.07).
    • Registry Entries for Printing. Microsoft Support. (accessed 26.11.07). http://support.microsoft.com/kb/102966.
  • 58
    • 84882331148 scopus 로고    scopus 로고
    • Windows Firewall. Microsoft TechNet.
    • Windows Firewall. Microsoft TechNet. http://technet.microsoft.com/en-us/network/bb545423.aspx.
  • 59
    • 84882308631 scopus 로고    scopus 로고
    • FakeAlert-Winwebsecurity. McAfee.
    • FakeAlert-Winwebsecurity. McAfee. http://vil.nai.com/vil/content/v_153577.htm.
  • 60
    • 84882415292 scopus 로고    scopus 로고
    • Trojan-Proxy.Win32.Mitglieder.ee. SecureList.
    • Trojan-Proxy.Win32.Mitglieder.ee. SecureList. http://www.securelist.com/en/descriptions/old126765.
  • 61
    • 84882415781 scopus 로고    scopus 로고
    • Exploring the windows firewall. Microsoft TechNet.
    • Exploring the windows firewall. Microsoft TechNet. http://technet.microsoft.com/en-us/magazine/2007.06.vistafirewall.aspx.
  • 62
    • 84882412200 scopus 로고    scopus 로고
    • The "netsh firewall" command together with the "profile=all" parameter does not configure the public profile on a Windows Vista-based computer. Microsoft Support. (accessed 1.02.08).
    • The "netsh firewall" command together with the "profile=all" parameter does not configure the public profile on a Windows Vista-based computer. Microsoft Support. (accessed 1.02.08). http://support.microsoft.com/kb/947213.
  • 63
    • 84882434041 scopus 로고    scopus 로고
    • How to use the "netsh advfirewall firewall" context instead of the "netsh firewall" context to control Windows Firewall behavior in Windows Server 2008 and in Windows Vista. Microsoft Support. (accessed 5.12.08).
    • How to use the "netsh advfirewall firewall" context instead of the "netsh firewall" context to control Windows Firewall behavior in Windows Server 2008 and in Windows Vista. Microsoft Support. (accessed 5.12.08). http://support.microsoft.com/kb/947709.
  • 64
    • 84882291387 scopus 로고    scopus 로고
    • Microsoft TCP/IP Host name resolution order. Microsoft Support.
    • Microsoft TCP/IP Host name resolution order. Microsoft Support. http://support.microsoft.com/kb/172218.
  • 65
    • 84882343922 scopus 로고    scopus 로고
    • 'P' Switch for route command added to Windows, Microsoft Support. (accessed 20.02.07).
    • 'P' Switch for route command added to Windows, Microsoft Support. (accessed 20.02.07). http://support.microsoft.com/kb/141383.
  • 66
    • 84882400960 scopus 로고    scopus 로고
    • NtfsDisableLastAccessUpdate. Microsoft Technet.
    • NtfsDisableLastAccessUpdate. Microsoft Technet. http://technet.microsoft.com/en-us/library/cc758569%28WS.10%29.aspx.
  • 67
    • 84882309976 scopus 로고    scopus 로고
    • NtfsDisable8dot3NameCreation. Microsoft TechNet.
    • NtfsDisable8dot3NameCreation. Microsoft TechNet. http://technet.microsoft.com/en-us/library/cc959352.aspx.
  • 68
    • 84882396525 scopus 로고    scopus 로고
    • How to clear the Windows paging file at shutdown. Microsoft Support. (accessed 20.07.10).
    • How to clear the Windows paging file at shutdown. Microsoft Support. (accessed 20.07.10). http://support.microsoft.com/kb/314834.
  • 69
    • 84882420628 scopus 로고    scopus 로고
    • Internet Explorer file downloads over SSL do not work with the cache control headers. Microsoft Support. (accessed 15.11.07).
    • Internet Explorer file downloads over SSL do not work with the cache control headers. Microsoft Support. (accessed 15.11.07). http://support.microsoft.com/kb/323308.
  • 70
    • 84882325388 scopus 로고    scopus 로고
    • HTTP/1.1 Header Field Definitions. W3.org.
    • HTTP/1.1 Header Field Definitions. W3.org. http://www.w3.org/Protocols/rfc2616/rfc2616-sec14.html.
  • 71
    • 84882422944 scopus 로고    scopus 로고
    • Robert Hensing's Blog. Microsoft TechNet Blogs. 15 November 2006, .
    • Robert Hensing's Blog. Microsoft TechNet Blogs. 15 November 2006, . http://blogs.technet.com/b/robert_hensing.
  • 72
    • 84882330164 scopus 로고    scopus 로고
    • Definition of the RunOnce Keys in the Registry. Microsoft Support. (accessed 19.01.07).
    • Definition of the RunOnce Keys in the Registry. Microsoft Support. (accessed 19.01.07). http://support.microsoft.com/kb/137367.
  • 73
    • 84882425425 scopus 로고    scopus 로고
    • Registry changes in x64-based versions of Windows Server 2003 and in Windows XP Professional x64 Edition. Microsoft Support. (accessed 21.04.08).
    • Registry changes in x64-based versions of Windows Server 2003 and in Windows XP Professional x64 Edition. Microsoft Support. (accessed 21.04.08). http://support.microsoft.com/kb/896459.
  • 74
    • 84882329410 scopus 로고    scopus 로고
    • Registry keys affected by WOW64. Microsoft Developer Network.
    • Registry keys affected by WOW64. Microsoft Developer Network. http://msdn.microsoft.com/en-us/library/aa384253%28VS.85%29.aspx.
  • 75
    • 84882363462 scopus 로고    scopus 로고
    • INFO: Run, RunOnce, RunServices, RunServicesOnce and Startup. Microsoft Support. (accessed 21.11.06).
    • INFO: Run, RunOnce, RunServices, RunServicesOnce and Startup. Microsoft Support. (accessed 21.11.06). http://support.microsoft.com/kb/179365.
  • 76
    • 84882416754 scopus 로고    scopus 로고
    • Registry Entries. Microsoft Developer Network.
    • Registry Entries. Microsoft Developer Network. http://msdn.microsoft.com/en-us/library/aa379402%28VS.85%29.aspx.
  • 77
    • 84882403528 scopus 로고    scopus 로고
    • Generic Downloader.z!1516DDBD. McAfee.
    • Generic Downloader.z!1516DDBD. McAfee. http://vil.nai.com/vil/content/v_149604.htm.
  • 78
    • 84882445629 scopus 로고    scopus 로고
    • How to debug Windows Services. Microsoft Support.
    • How to debug Windows Services. Microsoft Support. http://support.microsoft.com/kb/824344.
  • 79
    • 84882338636 scopus 로고    scopus 로고
    • How to turn off the Windows Update feature in Windows XP. Microsoft Support. 28 January 2005, (accessed 28.01.05).
    • How to turn off the Windows Update feature in Windows XP. Microsoft Support. 28 January 2005, (accessed 28.01.05). http://support.microsoft.com/kb/892894.
  • 80
    • 84882371416 scopus 로고    scopus 로고
    • Using image file execution options as an attack vector on Windows. , 2005.
    • Using image file execution options as an attack vector on Windows. , 2005. http://silverstr.ufies.org/blog/archives/000809.html.
  • 81
    • 84882416897 scopus 로고    scopus 로고
    • A new CWDIllegalInDllSearch registry entry is available to control the DLL search path algorithm. Microsoft Support. (accessed 24.08.10).
    • A new CWDIllegalInDllSearch registry entry is available to control the DLL search path algorithm. Microsoft Support. (accessed 24.08.10). http://support.microsoft.com/kb/2264107.
  • 82
    • 84882401375 scopus 로고    scopus 로고
    • Dynamic-Link Library Search Order. Microsoft Developer Network.
    • Dynamic-Link Library Search Order. Microsoft Developer Network. http://msdn.microsoft.com/en-us/library/ms682586.
  • 83
    • 84882360125 scopus 로고    scopus 로고
    • Malware Persistence without the Windows Registry. blog, 15 July 2010, .
    • Malware Persistence without the Windows Registry. blog, 15 July 2010, . http://blog.mandiant.com/archives/1207.
  • 84
    • 84882324032 scopus 로고    scopus 로고
    • REG: CurrentControlSet Entries PART 2: SessionManager. Microsoft Support. (accessed 1.11.06).
    • REG: CurrentControlSet Entries PART 2: SessionManager. Microsoft Support. (accessed 1.11.06). http://support.microsoft.com/kb/102985.
  • 85
    • 84882393563 scopus 로고    scopus 로고
    • INFO: Windows NT/2000/XP Uses KnownDLLs registry entry to find DLLs. Microsoft Support. (accessed 21.11.06).
    • INFO: Windows NT/2000/XP Uses KnownDLLs registry entry to find DLLs. Microsoft Support. (accessed 21.11.06). http://support.microsoft.com/kb/164501.
  • 86
    • 84882376461 scopus 로고    scopus 로고
    • User Profile Structure. Microsoft TechNet.
    • User Profile Structure. Microsoft TechNet. http://technet.microsoft.com/en-us/library/cc775560%28WS.10%29.aspx.
  • 87
    • 84882384527 scopus 로고    scopus 로고
    • Well-known security identifiers in Windows operating systems. Microsoft Support. (accessed 12.01.10).
    • Well-known security identifiers in Windows operating systems. Microsoft Support. (accessed 12.01.10). http://support.microsoft.com/kb/243330.
  • 88
    • 84882363146 scopus 로고    scopus 로고
    • How to Associate a Username with a Security Identifier (SID). Microsoft Support. (accessed 27.02.07).
    • How to Associate a Username with a Security Identifier (SID). Microsoft Support. (accessed 27.02.07). http://support.microsoft.com/kb/154599.
  • 89
    • 84882433129 scopus 로고    scopus 로고
    • The "Set roaming profile path for all users logging onto this computer" Group Policy setting also applies to local user accounts in Windows Server 2008. Microsoft Support. (accessed 21.10.08).
    • The "Set roaming profile path for all users logging onto this computer" Group Policy setting also applies to local user accounts in Windows Server 2008. Microsoft Support. (accessed 21.10.08). http://support.microsoft.com/kb/958736.
  • 90
    • 84882314497 scopus 로고    scopus 로고
    • How to Prevent a User from Changing the User Profile Type. Microsoft Support. (accessed 21.02.07).
    • How to Prevent a User from Changing the User Profile Type. Microsoft Support. (accessed 21.02.07). http://support.microsoft.com/kb/150919.
  • 91
    • 84882302894 scopus 로고    scopus 로고
    • 2.2.11 User Account Control. Microsoft Developer Network.
    • 2.2.11 User Account Control. Microsoft Developer Network. http://msdn.microsoft.com/en-us/library/cc232771%28v=PROT.10%29.aspx.
  • 92
    • 84882369580 scopus 로고    scopus 로고
    • WCZ_WLAN_CONFIG. Microsoft Developer Network.
    • WCZ_WLAN_CONFIG. Microsoft Developer Network. http://msdn.microsoft.com/en-us/library/aa448338.aspx.
  • 93
    • 84882374668 scopus 로고    scopus 로고
    • SYSTEMTIME. Microsoft Developer Network.
    • SYSTEMTIME. Microsoft Developer Network. http://msdn.microsoft.com/en-us/library/aa908737.aspx.
  • 94
    • 84882410393 scopus 로고    scopus 로고
    • Unnamed, Perl script by Joshua D. Abraham, .
    • Unnamed, Perl script by Joshua D. Abraham, . http://spl0it.org/files/bssid-location.pl.
  • 95
    • 84882427607 scopus 로고    scopus 로고
    • The Microsoft Windows Malicious Software Removal Tool helps remove specific, prevalent malicious software from computers that are running Windows 7, Windows Vista, Windows Server 2003, Windows Server 2008, or Windows XP. Microsoft Support.
    • The Microsoft Windows Malicious Software Removal Tool helps remove specific, prevalent malicious software from computers that are running Windows 7, Windows Vista, Windows Server 2003, Windows Server 2008, or Windows XP. Microsoft Support. http://support.microsoft.com/?kbid=890830.
  • 96
    • 84882414854 scopus 로고    scopus 로고
    • Deployment of the Microsoft Windows Malicious Software Removal Tool in an enterprise environment. Microsoft Support.
    • Deployment of the Microsoft Windows Malicious Software Removal Tool in an enterprise environment. Microsoft Support. http://support.microsoft.com/kb/891716.
  • 97
    • 84882388574 scopus 로고    scopus 로고
    • SANS Computer Forensic Investigation and Incident Response. SANS Forensic Blog. 16 August 2010, .
    • SANS Computer Forensic Investigation and Incident Response. SANS Forensic Blog. 16 August 2010, . https://blogs.sans.org/computer-forensics.
  • 98
    • 84882445869 scopus 로고    scopus 로고
    • How to limit the maximum size of the Scheduled Tasks Log File. Microsoft Support. (accessed 3.12.07).
    • How to limit the maximum size of the Scheduled Tasks Log File. Microsoft Support. (accessed 3.12.07). http://support.microsoft.com/kb/169443.
  • 99
    • 84882357458 scopus 로고    scopus 로고
    • Changes to Shell Open Command. About.Com: AntiVirus Software.
    • Changes to Shell Open Command. About.Com: AntiVirus Software. http://antivirus.about.com/od/windowsbasics/a/shellopen.htm.
  • 100
    • 84882340583 scopus 로고    scopus 로고
    • You cannot start programs when your computer is infected with the SirCam virus. Microsoft Support. (accessed 29.03.07).
    • You cannot start programs when your computer is infected with the SirCam virus. Microsoft Support. (accessed 29.03.07). http://support.microsoft.com/kb/311446.
  • 101
    • 84882420498 scopus 로고    scopus 로고
    • Abusing Image File Execution Options. SANS Internet Storm Center blog. 28 February 2008, .
    • Abusing Image File Execution Options. SANS Internet Storm Center blog. 28 February 2008, . http://isc.sans.edu/diary.html?storyid=4039.
  • 102
    • 84882407642 scopus 로고    scopus 로고
    • A definition of the Run keys in the Windows XP registry. Microsoft Support. 1 December 2007, .
    • A definition of the Run keys in the Windows XP registry. Microsoft Support. 1 December 2007, . http://support.microsoft.com/kb/314866.
  • 103
    • 84882407190 scopus 로고    scopus 로고
    • My view settings or customizations for a folder are lost or incorrect. Microsoft Support. 15 July 2009, (accessed 15.07.09).
    • My view settings or customizations for a folder are lost or incorrect. Microsoft Support. 15 July 2009, (accessed 15.07.09). http://support.microsoft.com/kb/813711.
  • 104
    • 68649113319 scopus 로고    scopus 로고
    • Using shellbag information to reconstruct user activities
    • Y. Zhu, P. Gladyshev, J. James, Using shellbag information to reconstruct user activities, Digit. Invest. 6 (Supp. 1) (2009). http://cci.ucd.ie/content/using-shellbag-information-reconstruct-user-activities.
    • (2009) Digit. Invest. , vol.6 , Issue.SUPPL. 1
    • Zhu, Y.1    Gladyshev, P.2    James, J.3
  • 105
    • 84882348920 scopus 로고    scopus 로고
    • TraceHunter. The UCD Centre for Cybercrime Investigation.
    • TraceHunter. The UCD Centre for Cybercrime Investigation. http://cci.ucd.ie/tracehunter.
  • 106
    • 84882416532 scopus 로고    scopus 로고
    • Didier Stevens.
    • Didier Stevens. http://blog.didierstevens.com/programs/userassist/.
  • 107
    • 84882430830 scopus 로고    scopus 로고
    • INSECURE-Mag-10.pdf. [IN]SECURE Mag. (10) (2007). (issue 10, pp. 72-77, last accessed 3.11.2010).
    • INSECURE-Mag-10.pdf. [IN]SECURE Mag. (10) (2007). (issue 10, pp. 72-77, last accessed 3.11.2010). http://www.net-security.org/dl/insecure/INSECURE-Mag-10.pdf.
  • 108
    • 84882331960 scopus 로고    scopus 로고
    • ITEMIDLIST structure. Microsoft Developer Network. (accessed 19.10.2010).
    • ITEMIDLIST structure. Microsoft Developer Network. (accessed 19.10.2010). http://msdn.microsoft.com/en-us/library/bb773321%28VS.85%29.aspx.
  • 109
    • 84882297478 scopus 로고    scopus 로고
    • WD2000: general information about Word 2000 instrumented version. Microsoft Support. (accessed 23.10.02).
    • WD2000: general information about Word 2000 instrumented version. Microsoft Support. (accessed 23.10.02). http://support.microsoft.com/kb/239062.
  • 110
    • 84882403165 scopus 로고    scopus 로고
    • Policy settings for the Start menu in Windows XP. Microsoft Support. (accessed 02.07.10).
    • Policy settings for the Start menu in Windows XP. Microsoft Support. (accessed 02.07.10). http://support.microsoft.com/kb/292504.
  • 111
    • 84882379866 scopus 로고    scopus 로고
    • MojoPac. Wikipedia, .
    • MojoPac. Wikipedia, . http://en.wikipedia.org/wiki/MojoPac.
  • 112
    • 84882297610 scopus 로고    scopus 로고
    • MokaFive. Wikipedia, .
    • MokaFive. Wikipedia, . http://en.wikipedia.org/wiki/MokaFive.
  • 113
    • 84882412755 scopus 로고    scopus 로고
    • How to remove entries from the remote desktop connection computer box. Microsoft Support. (accessed 01.11.06).
    • How to remove entries from the remote desktop connection computer box. Microsoft Support. (accessed 01.11.06). http://support.microsoft.com/kb/312169.


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.