Lab 16
Lab 16
Registry:
Prepare:
- Viturial Machine : Windows 2008
- 3 files including: Sample , plugins , rrv2.8. Download link is below:
https://code.google.com/archive/p/regripp er/downloads
RegRipper:
You need to unzip all 3 files above
Note*: if you want to start RegRipper software, you must first import the
plugins file.
There will be 2 ways to import:
- Method 1: You copy and paste directly into the file rrv2.8
- Method 2: In the file rrv2.8 there is a program named "pb" and there it
will display the interface window so that you can import the plugin's files.
And here we will conduct the analysis:
Analyst file Software:
First I will analyze the software file in Win 8
Note: when you analyze any file, you must choose its correct profile. For
example, if I am analyzing the file "software", I will choose the profile
"software"
First file: it is a log file that stores the analysis actions on the software file.
Second file: it's the result after an analysis process.
File log
In the second file, we can easily recognize the .exe files and its location in
Win 8