<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Forensic Artifacts</title>
	<atom:link href="http://forensicartifacts.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://forensicartifacts.com</link>
	<description>The Definitive Database</description>
	<lastBuildDate>Thu, 05 Jan 2012 23:53:51 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>IOCs and RMOs</title>
		<link>http://forensicartifacts.com/2012/01/iocs-and-rmos/</link>
		<comments>http://forensicartifacts.com/2012/01/iocs-and-rmos/#comments</comments>
		<pubDate>Thu, 05 Jan 2012 16:15:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[ioc]]></category>
		<category><![CDATA[mandiant]]></category>
		<category><![CDATA[rmo]]></category>
		<category><![CDATA[sans]]></category>

		<guid isPermaLink="false">http://forensicartifacts.com/?p=140</guid>
		<description><![CDATA[Happy New Year to the digital forensics community from everyone here at Forensic Artifacts! We have been busy with some site changes and additions that will hopefully benefit everyone in the upcoming year. First, we added a new subdomain, http://ioc.forensicartifacts.com, to assist in sharing information based on Mandiant&#8216;s OpenIOC initiative. The framework and tools released at OpenIOC.org for [...]]]></description>
			<content:encoded><![CDATA[<p>Happy New Year to the digital forensics community from everyone here at Forensic Artifacts! We have been busy with some site changes and additions that will hopefully benefit everyone in the upcoming year.</p>
<p>First, we added a new subdomain, <a href="http://ioc.forensicartifacts.com" target="_blank">http://ioc.forensicartifacts.com</a>, to assist in sharing information based on <a href="http://mandiant.com" target="_blank">Mandiant</a>&#8216;s OpenIOC initiative. The framework and tools released at <a href="http://openioc.org" target="_blank">OpenIOC.org</a> for standardizing and sharing Indicators of Compromise (IOC) allow analysts to quickly identify artifacts of network intrusions. The XML .ioc file produced can easily be shared allowing other analysts to look for the same artifact on different networks.</p>
<p>We created <a href="http://ioc.forensicartifacts.com/" target="_blank">http://ioc.forensicartifacts.com</a> as a place to categorize and share .ioc files. All that is needed is for an examiner to submit the .ioc file allowing us to populate the post and offer the .ioc for download, while other users can comment on the post to help make the .ioc stronger. Other than the <a href="https://forums.mandiant.com/tags/openioc" target="_blank">Mandiant Forum</a>, this is the only other repository we know of where users can share the IOCs they have created. By adding IOCs to the Forensic Artifacts website, our goal is to aid forensic examiners by having different types of information all under one roof. This should enhance the usefulness of the site and allow examiners to find the information they need much more efficiently.</p>
<p>Second, <a href="http://www.linkedin.com/in/leerob" target="_blank">Rob Lee</a> and <a href="http://computer-forensics.sans.org/" target="_blank">SANS</a> have graciously offered up a <a href="http://computer-forensics.sans.org/community/lethal-forensicator" target="_blank">SANS Lethal Forensicator Coin</a> for anyone submitting six or more artifacts or IOCs in any given year. There is a <a href="http://computer-forensics.sans.org/community/lethal-forensicator/coin-holders" target="_blank">proud group of forensic analysts</a> who currently possess one of these Round Metal Objects (RMO) and we are lucky enough to provide another avenue of earning the coin. The history of the coin and the term forensicator can be found on the link above. The rules for earning a coin through Forensic Artifacts are the same as the <a href="http://computer-forensics.sans.org/blog" target="_blank">SANS Forensic Blog</a>, simply <a href="http://forensicartifacts.com/submit/" target="_blank">submit six artifacts</a> or <a href="http://ioc.forensicartifacts.com/submit/" target="_blank">IOCs</a> in the span of a year and you&#8217;ll be eligible to earn the coin.</p>
<p>We&#8217;re looking forward to serving the community and watching the site grow. Please let us know if you have any suggestions or changes that will strengthen the site and enhance our ability to serve the digital forensics community.</p>
]]></content:encoded>
			<wfw:commentRss>http://forensicartifacts.com/2012/01/iocs-and-rmos/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SSH Server Connections</title>
		<link>http://forensicartifacts.com/2011/12/131/</link>
		<comments>http://forensicartifacts.com/2011/12/131/#comments</comments>
		<pubDate>Wed, 21 Dec 2011 23:36:26 +0000</pubDate>
		<dc:creator>Frank M.</dc:creator>
				<category><![CDATA[Registry]]></category>
		<category><![CDATA[SSH]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[registry]]></category>
		<category><![CDATA[User Activity]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://forensicartifacts.com/?p=131</guid>
		<description><![CDATA[Author Name Matonis Artifact Name Determine SSH Servers Users Connected To Artifact/Program Version PuTTY Categories User Activity, Active Machines Description SSH is a popular and practical management protocol for system administrators and nefarious users alike. In windows systems, the multifaceted terminal client, PuTTY, does not log by default but conditionally stores ssh host keys within the [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Author Name</strong><br />
Matonis</p>
<p><strong>Artifact Name</strong><br />
Determine SSH Servers Users Connected To</p>
<p><strong>Artifact/Program Version</strong><br />
PuTTY</p>
<p><strong>Categories</strong><br />
User Activity, Active Machines</p>
<p><strong>Description</strong><br />
SSH is a popular and practical management protocol for system administrators and nefarious users alike. In windows systems, the multifaceted terminal client, PuTTY, does not log by default but conditionally stores ssh host keys within the registry. This information can be beneficial to an analyst during a relevant incident/investigation to ascertain historical attributes about user activity and server authenticity.</p>
<p>Contained within the user&#8217;s NTUSER.DAT hive, the subkeys (outlined below) have the following syntax which are indicative of a successful SSH connection but not a successful SSH login:</p>
<p>rsa2@[port]:[hostname/IP]</p>
<p>The Last Write Time value of the NTUSER.DAT/Software/SimonTatham/SshHostKeys corresponds to the time the last ssh server was first connected to, as opposed to the last time the user had ssh&#8217;d to the server. If a user has connected to a server multiple times, these keys are not updated, in this event network logs are a more suitable quantitative source.</p>
<p>If a user chooses to save their PuTTY profile (connection preferences, servers, logs, etc), it will be stored under the NTUSER.DAT/Software/SimonTatham/Sessions.</p>
<p><strong>Registry Keys</strong><br />
To determine servers connected to via SSH:<br />
NTUSER.DAT/Software/SimonTatham/SshHostKeys -&gt; Subkeys correspond to successful SSH connections but not SSH logins.</p>
<p>To determine PuTTY configurations based on saved profiles:<br />
NTUSER.DAT/Software/SimonTatham/Sessions -&gt; Subkeys will correspond to profiles user created.</p>
<p>&nbsp;</p>
<p><strong>Related Posts:</strong></p>
<p><strong>
<ul>
<li><a title="Dropbox Config Files (Windows)" href="http://forensicartifacts.com/2011/07/dropbox-config-files-windows/">Dropbox Config Files (Windows)</a></li>
<li><a title="UserInfo (Windows)" href="http://forensicartifacts.com/2011/06/userinfo-windows/">UserInfo (Windows)</a></li>
<li><a title="MiTeC&#8217;s Windows Registry Analyzer and Windows Vista 64bit Edition" href="http://forensicartifacts.com/2010/08/mitecs-windows-registry-analyzer-and-windows-vista-64bit-edition/">MiTeC&#8217;s Windows Registry Analyzer and Windows Vista 64bit Edition</a></li>
<li><a title="Computer Name" href="http://forensicartifacts.com/2010/08/computer-name/">Computer Name</a></li>
<li><a title="Registry: Common MRUs" href="http://forensicartifacts.com/2010/08/registry-common-mrus/">Registry: Common MRUs</a></li>
</ul>
<p></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://forensicartifacts.com/2011/12/131/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OS X Lion Artifacts</title>
		<link>http://forensicartifacts.com/2011/11/os-x-lion-artifacts/</link>
		<comments>http://forensicartifacts.com/2011/11/os-x-lion-artifacts/#comments</comments>
		<pubDate>Sat, 26 Nov 2011 19:31:53 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Applications]]></category>
		<category><![CDATA[Browsers]]></category>
		<category><![CDATA[OSX]]></category>
		<category><![CDATA[Programs]]></category>
		<category><![CDATA[System]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Lion]]></category>
		<category><![CDATA[mac]]></category>

		<guid isPermaLink="false">http://forensicartifacts.com/?p=127</guid>
		<description><![CDATA[Author Name Sean Cavanaugh &#8211; AppleExaminer Artifact Name OS X Lion Artifacts Description Sean Cavanaugh of AppleExaminer.com maintains a Google Spreadsheet at the link listed below. Since this list is community driven and may change, it is not republished here, however, here is a spreadsheet containing the artifacts as of 11-26-11. This list contains artifacts [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Author Name</strong><br />
Sean Cavanaugh &#8211; AppleExaminer</p>
<p><strong>Artifact Name</strong><br />
OS X Lion Artifacts</p>
<p><strong></strong><strong>Description</strong><br />
Sean Cavanaugh of <a href="http://appleexaminer.com" target="_blank">AppleExaminer.com</a> maintains a Google Spreadsheet at the link listed below. Since this list is community driven and may change, it is not republished here, however, <a href="http://forensicartifacts.com/wp-content/uploads/2011/11/OS-X-Lion-Artifacts-v1.0.xls" target="_blank">here is a spreadsheet</a> containing the artifacts as of 11-26-11. This list contains artifacts of User Directories, Safari, Mail, iChat, iPhoto, iTunes, Photo Booth, Address Book, Spotlight, RSS, Saved Application State, Preferences, Autorun Locations, Recent Items, browsers, and specific applications.</p>
<p>&nbsp;</p>
<p><strong>Research Links</strong><br />
<a href="https://docs.google.com/spreadsheet/ccc?key=0AkBdGlxJhW-ydDlxVUxWUVU0dXVzMzUxRzh2b2ZzaFE&amp;hl=en_US#gid=0">https://docs.google.com/spreadsheet/ccc?key=0AkBdGlxJhW-ydDlxVUxWUVU0dXVzMzUxRzh2b2ZzaFE&amp;hl=en_US#gid=0</a></p>
<p>&nbsp;</p>
<p><strong>Related Posts:</strong></p>
<p><strong>
<ul>
<li><a title="System Version (Mac)" href="http://forensicartifacts.com/2011/06/system-version-mac/">System Version (Mac)</a></li>
<li><a title="Google Chrome Browser Profile (Mac OS X)" href="http://forensicartifacts.com/2011/03/google-chrome-browser-profile-mac-os-x/">Google Chrome Browser Profile (Mac OS X)</a></li>
<li><a title="Stickies (Mac)" href="http://forensicartifacts.com/2010/10/stickies-mac/">Stickies (Mac)</a></li>
<li><a title="Installed Printers (Mac)" href="http://forensicartifacts.com/2010/09/installed-printers-mac/">Installed Printers (Mac)</a></li>
<li><a title="Safari Browsing History (Mac)" href="http://forensicartifacts.com/2010/08/safari-browsing-history-mac/">Safari Browsing History (Mac)</a></li>
</ul>
<p></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://forensicartifacts.com/2011/11/os-x-lion-artifacts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Nmap / Zenmap</title>
		<link>http://forensicartifacts.com/2011/10/nmap-zenmap/</link>
		<comments>http://forensicartifacts.com/2011/10/nmap-zenmap/#comments</comments>
		<pubDate>Fri, 14 Oct 2011 01:30:46 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Programs]]></category>
		<category><![CDATA[System]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[logs]]></category>
		<category><![CDATA[packets]]></category>
		<category><![CDATA[SQLite]]></category>
		<category><![CDATA[temp files]]></category>

		<guid isPermaLink="false">http://forensicartifacts.com/?p=124</guid>
		<description><![CDATA[Author Name Frank McClain Artifact Name Nmap/Zenmap Artifact/Program Version 4.6, 5.1 Description Artifacts remaining on system after a scan using Nmap/Zenmap (especially Zenmap).  This is not from the standpoint of showing that the application was run, or by whom (so no prefetch, user assist, etc), nor proving that the application was installed at some point. This is from the [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Author Name</strong><br />
Frank McClain</p>
<p><strong>Artifact Name</strong><br />
Nmap/Zenmap</p>
<p><strong>Artifact/Program Version</strong><br />
4.6, 5.1</p>
<p><span style="text-decoration: underline;"><strong>Description</strong></span><br />
Artifacts remaining on system after a scan using Nmap/Zenmap (especially Zenmap).  This is not from the standpoint of showing that the application was run, or by whom (so no prefetch, user assist, etc), nor proving that the application was installed at some point. This is from the standpoint of showing the use (ie, how) an application was put to, and the timeframe (ie, when) involved.</p>
<p>In c:\program files\nmap\zenmap\ a file was created when a scan was saved.  This had the same user-selected name as the saved scan, with the extension USR.  So if the scan saved was “test” then the subsequent file would be “test.usr.”  If you find one of these, you can bet the user saved a scan; this file should be identical to that.  It is an XML file that has all the information about the scan.</p>
<p>In %User%\.zenmap (hidden folder) there are primarily three files of interest:  recent_scans.txt, target_list.txt and zenmap.db. Recent_scans.txt is a list of saved scans (or perhaps the .USR instance, it’s inconclusive at this point); all it has is a list of files with their paths.  Target_list.txt is a list of all target IP addresses, separated by semicolons; it has no other information, not even an associated date.  Zenmap.db is the fun one; it’s a SQLite database that contains a history of what scans were run – type of scan, target IP, XML output (ie, basic scan detail) and time.</p>
<p>%User%\%Local%\Temp has another potential treasure trove of evidence.  You may find temporary files (with no extension) located at this level.  Some contain no data, some contain only a small amount, and others provide a detailed breakdown of the scan, really the veritable motherlode, as it shows the time of the scan, each target port, protocol, scan times, and so on.  Very good stuff, when present.  The temporary files that had only a little content basically mirrored the type of content in the USR files, so if you don’t have one, you might have the other and still have some insight into the scan.</p>
<p>And a slightly tangential question posed on twitter was how to identify a scan with packets.  Fairly simple, right – just start Wireshark, run an Nmap scan, and review the results.  Turns out across multiple types of scans run, that there are 60-byte packets, and all have the following content:  00 0d 60 da b4 e7 00 11  25 d1 04 e0 08 00 45 00.  That’s obviously not the entire contents of each packet, but that was consistent across all packets I saw.</p>
<p><span style="text-decoration: underline;"><strong>File Locations</strong></span><br />
c:\program files\nmap\zenmap\*.usr (where * is the user-provided filename)<br />
%User%\.zenmap\recent_scans.txt<br />
%User%\.zenmap\target_list.txt<br />
%User%\.zenmap\zenmap.db (SQLite db)<br />
%User%\%Local%\Temp\tmpf5nhgm (these all start with “tmp” and appear to have 6 more characters following)</p>
<p><span style="text-decoration: underline;"><strong>Research Links</strong></span><br />
<a href="http://forensicaliente.blogspot.com/2011/10/artifacts-created-by-nmapzenmap.html" target="_blank">http://forensicaliente.<wbr>blogspot.com/2011/10/<wbr>artifacts-created-by-<wbr>nmapzenmap.html</wbr></wbr></wbr></a></p>
<p><span style="text-decoration: underline;"><strong>Forensic Programs of Use</strong></span><br />
Nmap for Windows (cli) - <a href="http://nmap.org/download.html" target="_blank">http://nmap.org/<wbr>download.html</wbr></a><br />
Zenmap GUI for Nmap for Windows - <a href="http://nmap.org/download.html" target="_blank">http://nmap.org/<wbr>download.html</wbr></a><br />
SQLite Database Browser - <a href="http://sqlitebrowser.sourceforge.net/" target="_blank">http://sqlitebrowser.<wbr>sourceforge.net/</wbr></a><br />
Wireshark - <a href="http://www.wireshark.org/download.html" target="_blank">http://www.wireshark.<wbr>org/download.html</wbr></a></p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://forensicartifacts.com/2011/10/nmap-zenmap/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Jump List AppIDs (Windows 7) &#8211; File Sharing/P2P, FTP, IRC, IM/Communications, Usenet Newsreaders, System Cleaners</title>
		<link>http://forensicartifacts.com/2011/09/jump-list-appids-windows-7-file-sharingp2p-ftp-irc-imcommunications-usenet-newsreaders-system-cleaners/</link>
		<comments>http://forensicartifacts.com/2011/09/jump-list-appids-windows-7-file-sharingp2p-ftp-irc-imcommunications-usenet-newsreaders-system-cleaners/#comments</comments>
		<pubDate>Fri, 23 Sep 2011 19:41:50 +0000</pubDate>
		<dc:creator>Joe G</dc:creator>
				<category><![CDATA[Registry]]></category>
		<category><![CDATA[System]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[AppId]]></category>
		<category><![CDATA[FTP]]></category>
		<category><![CDATA[IM]]></category>
		<category><![CDATA[IRC]]></category>
		<category><![CDATA[Jump Lists]]></category>
		<category><![CDATA[P2P]]></category>
		<category><![CDATA[windows 7]]></category>

		<guid isPermaLink="false">http://forensicartifacts.com/?p=123</guid>
		<description><![CDATA[Author Name Dan P (@4n6k) Artifact Name Jump List AppIDs (Windows 7) &#8211; File Sharing/P2P, FTP, IRC, IM/Communications, Usenet Newsreaders, System Cleaners Category Windows 7, Jump Lists Description The Jump List is essentially a new feature of the Windows 7 taskbar that allows quick access to recently viewed/opened/played or most frequently viewed/opened/played files. It also [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Author Name</strong><br />
Dan P (@4n6k)</p>
<p><strong>Artifact Name</strong><br />
Jump List AppIDs (Windows 7) &#8211; File Sharing/P2P, FTP, IRC, IM/Communications, Usenet Newsreaders, System Cleaners</p>
<p><strong>Category</strong><br />
Windows 7, Jump Lists</p>
<p><strong> </strong><strong>Description</strong><br />
The Jump List is essentially a new feature of the Windows 7 taskbar that allows quick access to recently viewed/opened/played or most frequently viewed/opened/played files. It also allows quick access to common tasks within each application. Each application has a little square of its own in the taskbar.</p>
<p>When the application performs certain actions (opening a file, right-clicking the application taskbar square, etc.), two types of files are created:</p>
<p>- *.automaticDestinations-ms files (in<br />
%appdata%\Microsoft\Windows\Recent\automaticDestinations)</p>
<p>- *.customDestinations-ms files (in<br />
%appdata%\Microsoft\Windows\Recent\customDestinations)</p>
<p>***Note: these directories are hidden***</p>
<p>You have to type in the full path in the address bar to see their contents). The ‘*’ in the above examples is where the Application (AppID) is represented. For the most part, the Windows operating system calculates the AppID of an application. Knowing an application’s AppID can help identify any given application when user activity is of great importance in an investigation.</p>
<p><strong>AppIds</strong><br />
FileSharing/P2P<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
e0f7a40340179171        imule 1.4.5 (rev. 749) installs to .exe loc AirDC++ 2.10<br />
76f6f1bd18c19698	aMule 2.2.6<br />
cb5250eaef7e3213	ApexDC++ 1.4.3.957<br />
bfc1d76f16fa778f	Ares (Galaxy) 1.8.4 / 1.9.8 / 2.1.0 / 2.1.7.3041<br />
depends on location     Azureus 0.9.0 (portable)<br />
accca100973ef8dc	Azureus 2.0.8.4<br />
ccb36ff8a8c03b4b	Azureus 2.5.0.4 / Vuze 3.0.5.0<br />
558c5bd9f906860a	BearShare Lite 5.2.5.1<br />
e1d47cb031dafb9f	BearShare 6.0.0.22717 / 8.1.0.70928 / 10.0.0.112380<br />
depends on location	BitComet 0.39 (portable)<br />
a31ec95fdd5f350f	BitComet 0.49 / 0.59 / 0.69 / 0.79 / 0.89 / 0.99 / 1.07 / 1.28<br />
bcd7ba75303acbcf	BitLord 1.1<br />
1434d6d62d64857d	BitLord 1.2.0-66<br />
e73d9f534ed5618a	BitSpirit 1.2.0.228 / 2.0 / 2.6.3.168 / 2.7.2.239 / 2.8.0.072 / 3.1.0.077 / 3.6.0.550<br />
c9374251edb4c1a8	BitTornado T-0.3.17<br />
2d61cccb4338dfc8	BitTorrent 5.0.0 / 6.0.0 / 7.2.1 (Build 25548)<br />
ba3a45f7fd2583e1	Blubster 3.1.1<br />
4a7e4f6a181d3d08	broolzShare<br />
f001ea668c0aa916	Cabos 0.8.2<br />
depends on location	CzDC 0.699 (portable)<br />
depends on location	Datawire 1.3 (portable)<br />
depends on location	DC++ 0.181 (portable)<br />
560d789a6a42ad5a	DC++ 0.261 / 0.698 / 0.782 (r2402.1)<br />
4aa2a5710da3efe0	DCSharpHub 2.0.0<br />
2db8e25112ab4453	Deluge 1.3.3<br />
5b186fc4a0b40504	Dtella 1.2.5 (Purdue network only)<br />
2437d4d14b056114	EiskaltDC++ 2.2.3<br />
b3016b8da2077262	eMule 0.50a<br />
cbbe886eca4bfc2d	ExoSee 1.0.0<br />
9ad1ec169bf2da7f	FlylinkDC++ r405 (Build 7358)<br />
4dd48f858b1a6ba7	Free Download Manager 3.0 (Build 852)<br />
depends on location	Freenet (default install dir is C:\Users\$user\&#8230;)<br />
depends on location	Frost 2011-03-05 (portable)<br />
f214ca2dd40c59c1	FrostWire 4.20.9<br />
73ce3745a843c0a4	FrostWire 5.1.4<br />
98b0ef1c84088		fulDC 6.78<br />
e6ea77a1d4553872	Gnucleus 1.8.6.0<br />
ed49e1e6ccdba2f5	GNUnet 0.8.1a<br />
cc4b36fbfb69a757	gtk-gnutella 0.97<br />
a746f9625f7695e8	HeXHub 5.07<br />
223bf0f360c6fea5	I2P 0.8.8 (restartable)<br />
2ff9dc8fb7e11f39	I2P 0.8.8 (no window)<br />
????????????????	[i2p] i2phex 3.2.0.103.0<br />
f1a4c04eebef2906	[i2p] Robert 0.0.29 Preferences<br />
????????????????	[i2p] Rufus 0.0.4<br />
c8e4c10e5460b00c	iMesh 6.5.0.16898<br />
f61b65550a84027e	iMesh 11.0.0.112351<br />
d460280b17628695	Java Binary<br />
depends on location	Jucy DC 0.85.0.201008281346 (portable)<br />
784182360de0c5b6	Kazaa Lite 1.7.1<br />
a75b276f6e72cf2a	Kazaa Lite Tools K++ 2.7.0<br />
ba132e702c0147ef	KCeasy 0.19-rc1<br />
a8df13a46d66f6b5	Kommute (Calypso) 0.24<br />
depends on location	LamaHub 0.0.5.5 (portable)<br />
c5ef839d8d1c76f4	LimeWire 5.2.13<br />
977a5d147aa093f4	Lphant 3.51<br />
96252daff039437a	Lphant 7.0.0.112351<br />
e76a4ef13fbf2bb1	Manolito 3.1.1<br />
99c15cf3e6d52b61	mldonkey 3.1.0<br />
ff224628f0e8103c	Morpheus 3.0.3.6<br />
depends on location	MUTE File Sharing 0.5.1 (portable)<br />
See Java Binary	ID	Nodezilla Agent 0.5.15 &#8211; built in Java<br />
depends on location	Perfect Dark 0.883 / 0.940 / 1.06 / 1.07 (all<br />
portable)<br />
See Java Binary	ID	Phex 3.4.2 (Build 116) &#8211; built in Java<br />
792699a1373f1386	Piolet 3.1.1<br />
ca1eb46544793057	RetroShare 0.5.2a (Build 4550)<br />
3cf13d83b0bd3867	RevConnect 0.674p (based on DC++)<br />
depends on location	PtokaX DC Hub 0.4.1.2 (portable)<br />
depends on location	RSX++ 1.21 (portable)<br />
5e01ecaf82f7d8e	        Scour Exchange 0.0.0.228<br />
depends on location	StrongDC++ 2.42	(portable)<br />
depends on location	TkDC++ 1.3 (portable)<br />
5d7b4175afdcc260	Shareaza 2.0.0.0<br />
b48ce76eda60b97	        Shareaza 8.0.0.112300<br />
23f08dab0f6aaf30	SoMud 1.3.3<br />
135df2a440abe9bb	SoulSeek 156c<br />
ecd21b58c2f65a2f	StealthNet 0.8.7.9<br />
5ea2a50c7979fbdc	TrustyFiles 3.1.0.22<br />
depends on location	uTorrent 1.1.1-dev (Build 110) / 1.3.0 / 1.5.0 (all portable)<br />
cd8cafb0fb6afdab	uTorrent 1.7.7 (Build 8179) / 1.8.5 / 2.0 / 2.21 (Build 25113) / 3.0 (Build 25583)<br />
a75b276f6e72cf2a	WinMX 3.53<br />
490c000889535727	WinMX 4.9.3.0<br />
depends on location	Winny 2.0b7.1 &#8211; all languages (portable)<br />
depends on location	xHub 0.2.6.7 (portable)<br />
depends on location	YnHub 1.036.152 (portable)<br />
ac3a63b839ac9d3a	Vuze 4.6.0.4</p>
<p>FTP<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
d28ee773b2cea9b2	3D-FTP 9.0 build 7<br />
cd2acd4089508507	AbsoluteTelnet 9.18 Lite<br />
e6ef42224b845020	ALFTP 5.20.0.4<br />
9e0b3f677a26bbc4	BitKinex 3.2.3<br />
4cdf7858c6673f4b	Bullet Proof FTP 1.26<br />
714b179e552596df	Bullet Proof FTP 2.4.0 (Build 31)<br />
20ef367747c22564	Bullet Proof FTP 2010.75.0.75<br />
44a50e6c87bc012	        Classic FTP Plus 2.15<br />
4fceec8e021ac978	CoffeeCup Free FTP 3.5.0.0<br />
8deb27dfa31c5c2a	CoffeeCup Free FTP 4.4 (Build 1904)<br />
49b5edbd92d8cd58	FTP Commander 8.02<br />
6a316aa67a46820b	Core FTP LE 1.3c (Build 1437) / 2.2 (Build 1689)<br />
be4875bb3e0c158f	CrossFTP 1.75a<br />
c04f69101c131440	CuteFTP 5.0 (Build 50.6.10.2)<br />
a79a7ce3c45d781	        CuteFTP 7.1 (Build 06.06.2005.1)<br />
59e86071b87ac1c3	CuteFTP 8.3 (Build 8.3.4.0007)<br />
d8081f151f4bd8a5	CuteFTP 8.3 Lite (Build 8.3.4.0007)<br />
3198e37206f28dc7	CuteFTP 8.3 Professional (Build 8.3.4.0007)<br />
f82607a219af2999	Cyberduck 4.1.2 (Build 8999)<br />
fa7144034d7d083d	Directory Opus 10.0.2.0.4269 (JL tasks supported)<br />
f91fd0c57c4fe449	ExpanDrive 2.1.0<br />
8f852307189803b8	Far Manager 2.0.1807<br />
226400522157fe8b	FileZilla Server 0.9.39 beta<br />
a1d19afe5a80f80	        FileZilla 2.2.32<br />
e107946bb682ce47	FileZilla 3.5.1<br />
b7cb1d1c1991accf	FlashFXP 4.0.0 (Build 1548)<br />
8628e76fd9020e81	Fling File Transfer Plus 2.24<br />
27da120d7e75cf1f	pbFTPClient 6.1<br />
f64de962764b9b0f	FTPRush 1.1.3 / 2.15<br />
10f5a20c21466e85	FTP Voyager 15.2.0.17<br />
7937df3c65790919	FTP Explorer 10.5.19 (Build 001)<br />
9560577fd87cf573	LeechFTP 1.3 (Build 207)<br />
fc999f29bc5c3560	Robo-FTP 3.7.9<br />
c99ddde925d26df3	Robo-FTP 3.7.9 CronMaker<br />
4b632cf2ceceac35	Robo-FTP Server 3.2.5<br />
3a5148bf2288a434	Secure FTP 2.6.1 (Build 20101209.1254)<br />
435a2f986b404eb7	SmartFTP 4.0.1214.0 explorer integrated Swish<br />
e42a8e0f4d9b8dcf	Sysax FTP Automation 5.15<br />
b8c13a5dd8c455a2	Titan FTP Server 8.40 (Build 1338)<br />
7904145af324576e	Total Commander 7.56a (Build 16.12.2010)<br />
79370f660ab51725	UploadFTP 2.0.1.0<br />
6a8b377d0f5cb666	WinSCP 2.3.0 (Build 146)<br />
9a3bdae86d5576ee	WinSCP 3.2.1 (Build 174) / 3.8.0 (Build 312)<br />
6bb54d82fa42128d	WinSCP 4.3.4 (Build 1428)<br />
b6267f3fcb700b60	WiseFTP 4.1.0<br />
a581b8002a6eb671	WiseFTP 5.5.9<br />
2544ff74641b639d	WiseFTP 6.1.5<br />
c54b96f328bdc28d	WiseFTP 7.3.0 Web-based WS_FTP</p>
<p>IM<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
b3965c840bf28ef4	AIM 4.8.2616<br />
1b29f0dc90366bb	        AIM 5.9.3857<br />
27ececd8d89b6767	AIM 6.2.14.2 / 6.5.3.12 / 6.9.17.2<br />
6f647f9488d7a		AIM 7.5.11.9 (custom AppID + JL support)<br />
ca942805559495e9	aMSN 0.98.4<br />
c6f7b5bf1b9675e4	BitWise IM 1.7.3a<br />
fb1f39d1f230480a	Bopup Messenger 5.6.2.9178 (all languages: en,du,fr,ger,rus,es)<br />
dc64de6c91c18300	Brosix Communicator 3.1.3 (Build 110719 nid 1)<br />
f09b920bfb781142	Camfrog 4.0.47 / 5.5.0 / 6.1 (build 146) (JL support)<br />
ebd8c95d87f25154	Carrier 2.5.5<br />
depends on location     Coccinella Messenger 0.96.20 (portable)<br />
30d23723bdd5d908	Digsby (Build 30140) (JL support)<br />
728008617bc3e34b	eM Client 3.0.10206.0<br />
689319b6547cda85	emesene 2.11.7<br />
454ef7dca3bb16b2	Exodus 0.10.0.0<br />
cca6383a507bac64	Gadu-Gadu 10.5.2.13164<br />
4278d3dc044fc88a	Gaim 1.5.0<br />
777483d3cdac1727	Gajim 0.14.4<br />
6aa18a60024620ae	GCN 2.9.1<br />
3f2cd46691bbee90	GOIM 1.1.0<br />
73c6a317412687c2	Google Talk 1.0.0.104<br />
b0236d03c0627ac4	ICQ 5.1 / ICQLite Build 1068<br />
a5db18f617e28a51	ICQ 6.5 (Build 2024)<br />
2417caa1f2a881d4	ICQ 7.6 (Build 5617)<br />
recognized VM		inSpeak 7.2.0.540<br />
989d7545c2b2e7b2	IMVU 465.8.0.0<br />
a3e0d98f5653b539	Instantbird 1.0 (20110623121653) (JL support)<br />
bcc705f705d8132b	Instan-t 5.2 (Build 2824)<br />
6059df4b02360af	        Kadu 0.10.0 / 0.6.5.5<br />
c312e260e424ae76	Mail.Ru Agent 5.8 (JL support)<br />
22cefa022402327d	Meca Messenger 5.3.0.52<br />
depends on location	Mercury Messenger (portable)<br />
86b804f7a28a3c17	Miranda IM 0.6.8 / 0.7.6 / 0.8.27 / 0.9.9 / 0.9.29 (ANSI + Unicode)<br />
b868d9201b866d96	Microsoft Lync 4.0.7577.0<br />
8c816c711d66a6b5	MSN Messenger 6.2.0137 / 7.0.0820<br />
depends on location     MSNPSharp (portable)<br />
2d1658d5dc3cbe2d	MySpaceIM 1.0.823.0 Beta<br />
bf9ae1f46bd9c491	Nimbuzz 2.0.0 (rev 6266)<br />
fb7ca8059b8f2123	ooVoo 3.0.7.21<br />
efb08d4e11e21ece	Paltalk Messenger 10.0 (Build 409)<br />
4f24a7b84a7de5a6	Palringo 2.6.3 (r45983)<br />
e93dbdcede8623f2	Pandion 2.6.106<br />
aedd2de3901a77f4	Pidgin 2.0.0 / 2.10.0 / 2.7.3<br />
c5236fd5824c9545	PLAYXPERT 1.0.140.2822<br />
dee18f19c7e3a2ec	PopNote 5.21<br />
1a60b1067913516a	Psi 0.14<br />
e0532b20aa26a0c9	QQ International 1.1 (2042)<br />
3c0022d9de573095	QuteCom 2.2<br />
93b18adf1d948fa3	qutIM 0.2<br />
e0246018261a9ccc	qutIM 0.2.80.0<br />
2aa756186e21b320	RealTimeQuery 3.2<br />
521a29e5d22c13b4	Skype 1.4.0.84 / 2.5.0.154 / 3.8.0.139 / 4.2.0.187 / Skype 5.3.0.120 / 5.5.0.115 / 5.5.32.117<br />
70b52cf73249257	        Sococo 1.5.0.2274<br />
d41746b133d17456	Tkabber 0.11.1<br />
c8aa3eaee3d4343d	Trillian 0.74 / 3.1 / 4.2.0.25 / 5.0.0.35 (JL support)<br />
d7d647c92cd5d1e6	uTalk 2.6.4 r47692<br />
36c36598b08891bf	Vovox 2.5.3.4250<br />
884fd37e05659f3a	VZOchat 6.3.5<br />
3461e4d1eb393c9c	WTW 0.8.18.2852 / 0.8.19.2940<br />
f2cb1c38ab948f58	X-Chat 1.8.10 / 2.6.9 / 2.8.9<br />
4e0ac37db19cba15	Xfire 1.138 (Build 44507)<br />
da7e8de5b8273a0f	Yahoo Messenger 5.0.0.1226 / 6.0.0.1922<br />
62dba7fb39bb0adc	Yahoo Messenger 7.5.0.647 / 8.1.0.421 / 9.0.0.2162 / 10.0.0.1270<br />
fb230a9fe81e71a8	Yahoo Messenger 11.0.0.2014-us<br />
b06a975b62567622	Windows Live Messenger 8.5.1235.0517 BETA<br />
bd249197a6faeff2	Windows Live Messenger 2011</p>
<p>IRC<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
b223c3ffbc0a7a42	Bersirc 2.2.14<br />
c01d68e40226892b	ClicksAndWhistles 2.7.146<br />
ac8920ed05001800	DMDirc 0.6.5 (Profile store: C:\Users\$user\AppData\Roaming\DMDirc\)<br />
d3530c5294441522	HydraIRC 0.3.165<br />
8904a5fd2d98b546	IceChat 7.70 20101031<br />
6b3a5ce7ad4af9e4	IceChat 9 RC2<br />
fa496fe13dd62edf	KVIrc 3.4.2.1 / 4.0.4<br />
65f7dd884b016ab2	LimeChat 2.39<br />
19ccee0274976da8	mIRC 4.72 / 5.61<br />
ae069d21df1c57df	mIRC 6.35 / 7.19<br />
e30bbea3e1642660	Neebly 1.0.4<br />
54c803dfc87b52ba	Nettalk 6.7.12<br />
dd658a07478b46c2	PIRCH98 1.0.1.1190<br />
depends on location     Quassel IRC 0.7.1 (portable)<br />
6fee01bd55a634fe	Smuxi 0.8.0.0<br />
2a5a615382a84729	X-Chat 2 2.8.6-2</p>
<p>Usenet<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
ace8715529916d31	40tude Dialog 2.0.15.1 (Beta 38)<br />
cc76755e0f925ce6	AllPicturez 1.2<br />
36f6bc3efe1d99e0	Alt.Binz 0.25.0 (Build 27.09.2007)<br />
d53b52fb65bde78c	Android Newsgroup Downloader 6.2<br />
c845f3a6022d647c	Another File 2.03 (Build 2/7/2004)<br />
780732558f827a42	AutoPix 5.3.3<br />
baea31eacd87186b	BinaryBoy 1.97 (Build 55)<br />
eab25958dbddbaa4	Binary News Reaper 2 (Beta 0.14.7.448)<br />
bf483b423ebbd327	Binary Vortex 5.0<br />
36801066f71b73c5	Binbot 2.0<br />
13eb0e5d9a49eaef	Binjet 3.0.2<br />
8172865a9d5185cb	Binreader 1.0 (Beta 1)<br />
6224453d9701a612	BinTube 3.7.1.0 (requires VLC 10.5!)<br />
cf6379a9a987366e	Digibin 1.31<br />
43886ba3395acdcc	Easy Post 3.0<br />
cfab0ec14b6f953		Express NewsPictures 2.41 (Build 08.05.07.0)<br />
7526de4a8b5914d9	Forte Agent 6.00 (Build 32.1186)<br />
c02baf50d02056fc	FotoVac 1.0<br />
3ed70ef3495535f7	Gravity 3.0.4<br />
86781fe8437db23e	Messenger Pro 2.66.6.3353<br />
f920768fe275f7f4	Grabit 1.5.3 Beta (Build 909) / 1.6.2 (Build 940) / 1.7.2 Beta 4 (Build 997)<br />
9f03ae476ad461fa	GroupsAloud 1.0<br />
d0261ed6e16b200b	News File Grabber 4.6.0.4<br />
8211531a7918b389	Newsbin Pro 6.00 (Build 1019) (JL support)<br />
d1fc019238236806	Newsgroup Commander Pro 9.05<br />
186b5ccada1d986b	NewsGrabber 3.0.36<br />
4d72cfa1d0a67418	Newsgroup Image Collector<br />
92f1d5db021cd876	NewsLeecher 4.0 / 5.0 Beta 6<br />
d7666c416cba240c	NewsMan Pro 3.0.5.2<br />
7b2b4f995b54387d	News Reactor 20100224.16<br />
cb984e3bc7faf234	NewsRover 17.0 (Rev.0)<br />
c98ab5ccf25dda79	NewsShark 2.0<br />
dba909a61476ccec	NewsWolf 1.41<br />
2b164f512891ae37	NewsWolf NSListGen<br />
cb1d97aca3fb7e6b	Newz Crawler 1.9.0 (Build 4100)<br />
3be7b307dfccb58f	NiouzeFire 0.8.7.0<br />
de76415e0060ce13	Noworyta News Reader 2.9<br />
cd40ead0b1eb15ab	NNTPGrab 0.6.2<br />
d5c02fc7afbb3fd4	NNTPGrab 0.6.2 Server<br />
a4def57ee99d77e9	Nomad News 1.43<br />
3f97341a65bac63a	Ozum 6.07 (Build 6070)<br />
bfe841f4d35c92b1	QuadSucker/News 5.0 web-based sabnzbd 0.6.8<br />
d3c5cf21e86b28af	SeaMonkey 2.3.3<br />
7a7c60efd66817a2	Spotnet 1.7.4<br />
eb3300e672136bc7	Stream Reactor 1.0 Beta 9 (uses VLC!)<br />
3168cc975b354a01	Slypheed 3.1.2 (Build 1120)<br />
776beb1fcfc6dfa5	Thunderbird 1.0.6 (20050716) / 3.0.2<br />
3d877ec11607fe4	        Thunderbird 6.0.2<br />
7192f2de78fd9e96	TIFNY 5.0.3<br />
9dacebaa9ac8ca4e	TLNews Newsreader 2.2.0 (Build 2430)<br />
7fd04185af357bd5	UltraLeeacher 1.7.0.2969 / 1.8 Beta (Build 3490)<br />
aa11f575087b3bdc	Unzbin 2.6.8 pay only Usenet Explorer 3.3 (pay)<br />
d7db75db9cdd7c5d	Xnews 5.04.25</p>
<p>System Cleaners<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
ed7a5cc3cca8d52a	CCleaner 1.32.345 / 1.41.544 / 2.36.1233 / 3.10.1525<br />
eb7e629258d326a1	WindowWasher 6.6.1.18</p>
<p><strong>File Locations</strong><br />
- *.automaticDestinations-ms files (in %appdata%\Microsoft\Windows\Recent\automaticDestinations)<br />
- *.customDestinations-ms files (in %appdata%\Microsoft\Windows\Recent\customDestinations)</p>
<p><strong>Research Links</strong><br />
<a href="http://4n6k.blogspot.com/2011/09/jump-list-forensics-appids-part-2.html" target="_blank"></a><br />
<a href="http://www.slideshare.net/ctin/windows-7-forensics-jump-listsrv3public" target="_blank"></a><br />
<a href="http://blogs.msdn.com/b/yochay/archive/2009/01/06/windows-7-taskbar-part-1-the-basics.aspx" target="_blank"></a><br />
<a href="http://www.alexbarnett.com/jumplistforensics.pdf" target="_blank"></a><br />
<a href="http://msdn.microsoft.com/en-us/library/dd378459(v=vs.85).aspx" target="_blank"></a><br />
<a href="http://windowsteamblog.com/windows/b/developers/archive/2009/06/18/developing-for-the-windows-7-taskbar-application-id.aspx" target="_blank"></a><br />
<a href="http://windowsteamblog.com/windows/b/developers/archive/2009/06/25/developing-for-the-windows-7-taskbar-jump-into-jump-lists-part-2.aspx" target="_blank"></a><br />
<a href="http://www.forensicswiki.org/wiki/List_of_Jump_List_IDs" target="_blank"></a><br />
<a href="http://imfreedom.org/wiki/Main_Page" target="_blank"></a></p>
<p><strong>Other Info</strong><br />
This is the second batch of AppIDs. Please check out the original blog<br />
post for which this information was gathered. It provides additional<br />
information and a nice layout for the AppIDs.</p>
<p><strong>
<ul>
<li><a title="Jump List AppIDs" href="http://forensicartifacts.com/2011/09/jump-list-appids/">Jump List AppIDs</a></li>
<li><a title="NetworkList (Vista/Windows 7)" href="http://forensicartifacts.com/2011/06/networklist-vistawindows-7/">NetworkList (Vista/Windows 7)</a></li>
<li><a title="Evernote note storage" href="http://forensicartifacts.com/2011/06/evernote-note-storage/">Evernote note storage</a></li>
<li><a title="Volume Shadow Copies" href="http://forensicartifacts.com/2011/05/volume-shadow-copies/">Volume Shadow Copies</a></li>
<li><a title="Google Chrome Browser Profile (Windows Vista/Windows 7)" href="http://forensicartifacts.com/2011/02/google-chrome-browser-profile-windows-vistawindows-7/">Google Chrome Browser Profile (Windows Vista/Windows 7)</a></li>
</ul>
<p></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://forensicartifacts.com/2011/09/jump-list-appids-windows-7-file-sharingp2p-ftp-irc-imcommunications-usenet-newsreaders-system-cleaners/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Jump List AppIDs</title>
		<link>http://forensicartifacts.com/2011/09/jump-list-appids/</link>
		<comments>http://forensicartifacts.com/2011/09/jump-list-appids/#comments</comments>
		<pubDate>Fri, 09 Sep 2011 15:00:34 +0000</pubDate>
		<dc:creator>Joe G</dc:creator>
				<category><![CDATA[Windows]]></category>
		<category><![CDATA[Jump Lists]]></category>
		<category><![CDATA[windows 7]]></category>

		<guid isPermaLink="false">http://forensicartifacts.com/?p=119</guid>
		<description><![CDATA[Author Name Dan P (@4n6k) Artifact Name Jump List AppIDs (Windows 7) &#8211; browsers, utilities, image viewers, and media players Categories Windows 7, Jump Lists Description The Jump List is essentially a new feature of the Windows 7 taskbar that allows quick access to recently viewed/opened/played or most frequently viewed/opened/played files. It also allows quick [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Author Name</strong><br />
Dan P (@4n6k)</p>
<p><strong>Artifact Name</strong><br />
Jump List AppIDs (Windows 7) &#8211; browsers, utilities, image viewers, and<br />
media players</p>
<p><strong>Categories</strong><br />
Windows 7, Jump Lists</p>
<p><strong> </strong><strong>Description</strong><br />
The Jump List is essentially a new feature of the Windows 7 taskbar that allows quick access to recently viewed/opened/played or most frequently viewed/opened/played files. It also allows quick access to common tasks within each application. Each application has a little square of its own in the taskbar.</p>
<p>When the application performs certain actions (opening a file, right-clicking the application taskbar square, etc.), two types of files are created:</p>
<p>- *.automaticDestinations-ms files (in %appdata%\Microsoft\Windows\Recent\automaticDestinations)</p>
<p>- *.customDestinations-ms files (in %appdata%\Microsoft\Windows\Recent\customDestinations).</p>
<p>***Note: these directories are hidden***</p>
<p>You have to type in the full path in the address bar to see their contents). The ‘*’ in the above examples is where the Application (AppID) is represented. For the most part, the Windows operating system calculates the AppID of an application. Knowing an application’s AppID can help identify any given application when user activity is of great importance in an investigation.</p>
<p><strong>AppIDs</strong></p>
<p>Internet Browsers<br />
——————————————<br />
5d696d521de238c3 Chrome 9.0.597.84 / 12.0.742.100 / 13.0.785.215<br />
cfb56c56fa0f0a54 Mozilla 0.9.9<br />
5c450709f7ae4396 Firefox 1.0 / 2.0 / 3.0<br />
5df4765359170e26 Firefox 4.0.1<br />
1eb796d87c32eff9 Firefox 5.0<br />
1461132e553e2e6c Firefox 6.0<br />
28c8b86deab549a1 Internet Explorer 8 / 9<br />
16ec093b8f51508f Opera 8.54 build 7730 / 9.64 build 10487 / 11.50 build 1074<br />
8a1c1c7c389a5320 Safari 3.2.3 (525.29)<br />
1da3c90a72bf5527 Safari 4.0.5 (531.22.7) / 5.1 (7534.50)</p>
<p>Utilities<br />
——————————————<br />
3dc02b55e44d6697 7-Zip 3.13 / 4.20<br />
4975d6798a8bdf66 7-Zip 4.65 / 9.20<br />
4b6925efc53a3c08 BCWipe 5.02.2 Task Manager 3.02.3<br />
337ed59af273c758 Sticky Notes<br />
290532160612e071 WinRAR 2.90 / 3.60 / 4.01<br />
c9950c443027c765 WinZip 9.0 SR-1 (6224) / 10.0 (6667)<br />
b74736c2bd8cc8a5 WinZip 15.5 (9468)<br />
bc0c37e84e063727 Windows Command Processor – cmd.exe (32-bit)</p>
<p>Image/Document Viewers<br />
——————————————<br />
f0468ce1ae57883d Adobe Reader 7.1.0<br />
c2d349a0e756411b Adobe Reader 8.1.2<br />
23646679aaccfae0 Adobe Acrobat 9.4.0<br />
ee462c3b81abb6f6 Adobe Reader X 10.1.0<br />
386a2f6aa7967f36 EyeBrowse 2.7<br />
e31a6a8a7506f733 Image AXS Pro 4.1<br />
b39c5f226977725d ACDSee Pro 8.1.99<br />
59f56184c796cfd4 ACDSee Photo Manager 10 (Build 219)<br />
8bd5c6433ca967e9 ACDSee Photo Manager 2009 (v11.0 Build 113)<br />
d838aac097abece7 ACDSee Photo Manager 12 (Build 344)<br />
b3f13480c2785ae Paint 6.1 (build 7601: SP1)<br />
7cb0735d45243070 CDisplay 1.8.1.0<br />
3594aab44bca414b Windows Photo Viewer<br />
3edf100b207e2199 digiKam 1.7.0 (KDE 4.4.4)<br />
169b3be0bc43d592 FastPictureViewer Professional 1.6 (Build 211)<br />
e9a39dfba105ea23 FastStone Image Viewer 4.6<br />
edc786643819316c HoneyView3 #5834<br />
76689ff502a1fd9e Imagine Image and Animation Viewer 1.0.7<br />
2519133d6d830f7e IMatch 3.6.0.113<br />
1110d9896dceddb3 imgSeek 0.8.5<br />
c634153e7f5fce9c IrfanView 3.10 / 4.30<br />
ea83017cdd24374d IrfanView Thumbnails<br />
3917dd550d7df9a8 Konvertor 4.06 (Build 10)<br />
2fa14c7753239e4c Paint.NET 2.72 / 3.5.8.4081.24580<br />
d33ecf70f0b74a77 Picasa 2.2.0 (Build 28.08, 0)<br />
b17d3d0c9ca7e29 Picasa 3.8.0 (Build 117.43, 0) Embedded in IE Prizm Viewer depends on Location Scientific and Technical Document Viewer 1.6.2 Portable (STDU)<br />
c5c24a503b1727df XnView 1.98.2 Small / 1.98.2 Standard<br />
497b42680f564128 Zoner PhotoStudio 13 (Build 7)</p>
<p>Media Players<br />
——————————————<br />
d22ad6d9d20e6857 ALLPlayer 4.7<br />
7494a606a9eef18e Crystal Player 1.98<br />
1cffbe973a437c74 DSPlayer 0.889 Lite<br />
817bb211c92fd254 GOM Player 2.0.12.3375 / 2.1.28.5039<br />
6bc3383cb68a3e37 iTunes 7.6.0.29 / 8.0.0.35<br />
83b03b46dcd30a0e iTunes 9.0.0.70 / 9.2.1.5 / 10.4.1.10 (begin custom ‘Tasks’ JL capability)<br />
fe5e840511621941 JetAudio 5.1.9.3018 Basic / 6.2.5.8220 Basic / 7.0.0 Basic / 8.0.16.2000 Basic<br />
a777ad264b54abab JetVideo 8.0.2.200 Basic<br />
3c93a049a30e25e6 J. River Media Center 16.0.149<br />
4a49906d074a3ad3 Media Go 1.8 (Build 121)<br />
1cf97c38a5881255 MediaPortal 1.1.3<br />
Depends on location Media Player Classic 6.4.8.9 (is portable)<br />
Depends on location Media Player Classic – Home Cinema 1.5.2.3456 (default install is \Users\user\ dir, so dynamic)<br />
62bff50b969c2575 Quintessential Media Player 5.0 (Build 121) – also usage stats (times used, tracks played, total time used)<br />
b50ee40805bd280f QuickTime Alternative 1.9.5 (Media Player Classic 6.4.9.1)<br />
ae3f2acd395b622e QuickTime Player 6.5.1 / 7.0.3 / 7.5.5 (Build 249.13)<br />
7593af37134fd767 RealPlayer 6.0.6.99 / 7 / 8 / 10.5<br />
37392221756de927 RealPlayer SP 12<br />
f92e607f9de02413 RealPlayer 14.0.6.666<br />
6e9d40a4c63bb562 Real Player Alternative 1.25 (Media Player Classic 6.4.8.2 / 6.4.9.0)<br />
c91d08dcfc39a506 SM Player 0.6.9 r3447<br />
e40cb5a291ad1a5b Songbird 1.9.3 (Build 1959)<br />
4d8bdacf5265a04f The KMPlayer 2.9.4.1434<br />
4acae695c73a28c7 VLC 0.3.0 / 0.4.6<br />
9fda41b86ddcf1db VLC 0.5.3 / 0.8.6i / 0.9.7 / 1.1.11<br />
e6ee34ac9913c0a9 VLC 0.6.2<br />
cbeb786f0132005d VLC 0.7.2<br />
f674c3a77cfe39d0 Winamp 2.95 / 5.1 / 5.621<br />
90e5e8b21d7e7924 Winamp 3.0d (Build 488)<br />
74d7f43c1561fc1e Windows Media Player 12.0.7601.17514</p>
<p>FileSharing/P2P<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<wbr>&#8212;&#8212;&#8212;&#8212;<br />
e0f7a40340179171    imule 1.4.5 (rev. 749)<br />
installs to .exe loc    AirDC++ 2.10<br />
76f6f1bd18c19698        aMule 2.2.6<br />
cb5250eaef7e3213        ApexDC++ 1.4.3.957<br />
bfc1d76f16fa778f                Ares (Galaxy) 1.8.4 / 1.9.8 / 2.1.0 / 2.1.7.3041<br />
depends on location     Azureus 0.9.0 (portable)<br />
accca100973ef8dc        Azureus 2.0.8.4<br />
ccb36ff8a8c03b4b        Azureus 2.5.0.4 / Vuze 3.0.5.0<br />
558c5bd9f906860a        BearShare Lite 5.2.5.1<br />
e1d47cb031dafb9f        BearShare 6.0.0.22717 / 8.1.0.70928 / 10.0.0.112380<br />
depends on location     BitComet 0.39 (portable)<br />
a31ec95fdd5f350f        BitComet 0.49 / 0.59 / 0.69 / 0.79 / 0.89 / 0.99 /<br />
1.07 / 1.28<br />
bcd7ba75303acbcf        BitLord 1.1<br />
1434d6d62d64857d        BitLord 1.2.0-66<br />
e73d9f534ed5618a        BitSpirit 1.2.0.228 / 2.0 / 2.6.3.168 / 2.7.2.239 /<br />
2.8.0.072 / 3.1.0.077 / 3.6.0.550<br />
c9374251edb4c1a8        BitTornado T-0.3.17<br />
2d61cccb4338dfc8        BitTorrent 5.0.0 / 6.0.0 / 7.2.1 (Build 25548)<br />
ba3a45f7fd2583e1        Blubster 3.1.1<br />
4a7e4f6a181d3d08        broolzShare<br />
f001ea668c0aa916        Cabos 0.8.2<br />
depends on location     CzDC 0.699 (portable)<br />
depends on location     Datawire 1.3 (portable)<br />
depends on location     DC++ 0.181 (portable)<br />
560d789a6a42ad5a        DC++ 0.261 / 0.698 / 0.782 (r2402.1)<br />
4aa2a5710da3efe0        DCSharpHub 2.0.0<br />
2db8e25112ab4453        Deluge 1.3.3<br />
5b186fc4a0b40504        Dtella 1.2.5 (Purdue network only)<br />
2437d4d14b056114        EiskaltDC++ 2.2.3<br />
b3016b8da2077262        eMule 0.50a<br />
cbbe886eca4bfc2d        ExoSee 1.0.0<br />
9ad1ec169bf2da7f        FlylinkDC++ r405 (Build 7358)<br />
4dd48f858b1a6ba7        Free Download Manager 3.0 (Build 852)<br />
depends on location     Freenet (default install dir is<br />
C:\Users\$user\&#8230;)<br />
depends on location     Frost 2011-03-05 (portable)<br />
f214ca2dd40c59c1        FrostWire 4.20.9<br />
73ce3745a843c0a4        FrostWire 5.1.4<br />
98b0ef1c84088           fulDC 6.78<br />
e6ea77a1d4553872        Gnucleus 1.8.6.0<br />
ed49e1e6ccdba2f5        GNUnet 0.8.1a<br />
cc4b36fbfb69a757        gtk-gnutella 0.97<br />
a746f9625f7695e8        HeXHub 5.07<br />
223bf0f360c6fea5        I2P 0.8.8 (restartable)<br />
2ff9dc8fb7e11f39        I2P 0.8.8 (no window)<br />
????????????????        [i2p] i2phex 3.2.0.103.0<br />
f1a4c04eebef2906        [i2p] Robert 0.0.29 Preferences<br />
????????????????        [i2p] Rufus 0.0.4<br />
c8e4c10e5460b00c        iMesh 6.5.0.16898<br />
f61b65550a84027e        iMesh 11.0.0.112351<br />
d460280b17628695        Java Binary<br />
depends on location     Jucy DC 0.85.0.201008281346 (portable)<br />
784182360de0c5b6        Kazaa Lite 1.7.1<br />
a75b276f6e72cf2a        Kazaa Lite Tools K++ 2.7.0<br />
ba132e702c0147ef        KCeasy 0.19-rc1<br />
a8df13a46d66f6b5        Kommute (Calypso) 0.24<br />
depends on location     LamaHub 0.0.5.5 (portable)<br />
c5ef839d8d1c76f4        LimeWire 5.2.13<br />
977a5d147aa093f4        Lphant 3.51<br />
96252daff039437a        Lphant 7.0.0.112351<br />
e76a4ef13fbf2bb1        Manolito 3.1.1<br />
99c15cf3e6d52b61        mldonkey 3.1.0<br />
ff224628f0e8103c        Morpheus 3.0.3.6<br />
depends on location     MUTE File Sharing 0.5.1 (portable)<br />
See Java Binary ID      Nodezilla Agent 0.5.15 &#8211; built in Java<br />
depends on location     Perfect Dark 0.883 / 0.940 / 1.06 / 1.07 (all<br />
portable)<br />
See Java Binary ID      Phex 3.4.2 (Build 116) &#8211; built in Java<br />
792699a1373f1386        Piolet 3.1.1<br />
ca1eb46544793057        RetroShare 0.5.2a (Build 4550)<br />
3cf13d83b0bd3867        RevConnect 0.674p (based on DC++)<br />
depends on location     PtokaX DC Hub 0.4.1.2 (portable)<br />
depends on location     RSX++ 1.21 (portable)<br />
5e01ecaf82f7d8e Scour Exchange 0.0.0.228<br />
depends on location     StrongDC++ 2.42 (portable)<br />
depends on location     TkDC++ 1.3 (portable)<br />
5d7b4175afdcc260        Shareaza 2.0.0.0<br />
b48ce76eda60b97 Shareaza 8.0.0.112300<br />
23f08dab0f6aaf30        SoMud 1.3.3<br />
135df2a440abe9bb        SoulSeek 156c<br />
ecd21b58c2f65a2f        StealthNet 0.8.7.9<br />
5ea2a50c7979fbdc        TrustyFiles 3.1.0.22<br />
depends on location     uTorrent 1.1.1-dev (Build 110) / 1.3.0 / 1.5.0<br />
(all portable)<br />
cd8cafb0fb6afdab        uTorrent 1.7.7 (Build 8179) / 1.8.5 / 2.0 / 2.21<br />
(Build 25113) / 3.0 (Build 25583)<br />
a75b276f6e72cf2a        WinMX 3.53<br />
490c000889535727        WinMX 4.9.3.0<br />
depends on location     Winny 2.0b7.1 &#8211; all languages (portable)<br />
depends on location     xHub 0.2.6.7 (portable)<br />
depends on location     YnHub 1.036.152 (portable)<br />
ac3a63b839ac9d3a        Vuze 4.6.0.4</wbr></p>
<p>FTP<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<wbr>&#8212;&#8212;&#8212;&#8212;<br />
d28ee773b2cea9b2        3D-FTP 9.0 build 7<br />
cd2acd4089508507        AbsoluteTelnet 9.18 Lite<br />
e6ef42224b845020        ALFTP 5.20.0.4<br />
9e0b3f677a26bbc4        BitKinex 3.2.3<br />
4cdf7858c6673f4b        Bullet Proof FTP 1.26<br />
714b179e552596df        Bullet Proof FTP 2.4.0 (Build 31)<br />
20ef367747c22564        Bullet Proof FTP 2010.75.0.75<br />
44a50e6c87bc012 Classic FTP Plus 2.15<br />
4fceec8e021ac978        CoffeeCup Free FTP 3.5.0.0<br />
8deb27dfa31c5c2a        CoffeeCup Free FTP 4.4 (Build 1904)<br />
49b5edbd92d8cd58        FTP Commander 8.02<br />
6a316aa67a46820b        Core FTP LE 1.3c (Build 1437) / 2.2 (Build 1689)<br />
be4875bb3e0c158f        CrossFTP 1.75a<br />
c04f69101c131440        CuteFTP 5.0 (Build 50.6.10.2)<br />
a79a7ce3c45d781 CuteFTP 7.1 (Build 06.06.2005.1)<br />
59e86071b87ac1c3        CuteFTP 8.3 (Build 8.3.4.0007)<br />
d8081f151f4bd8a5        CuteFTP 8.3 Lite (Build 8.3.4.0007)<br />
3198e37206f28dc7        CuteFTP 8.3 Professional (Build 8.3.4.0007)<br />
f82607a219af2999        Cyberduck 4.1.2 (Build 8999)<br />
fa7144034d7d083d        Directory Opus 10.0.2.0.4269 (JL tasks supported)<br />
f91fd0c57c4fe449        ExpanDrive 2.1.0<br />
8f852307189803b8        Far Manager 2.0.1807<br />
226400522157fe8b        FileZilla Server 0.9.39 beta<br />
a1d19afe5a80f80 FileZilla 2.2.32<br />
e107946bb682ce47        FileZilla 3.5.1<br />
b7cb1d1c1991accf        FlashFXP 4.0.0 (Build 1548)<br />
8628e76fd9020e81        Fling File Transfer Plus 2.24<br />
27da120d7e75cf1f        pbFTPClient 6.1<br />
f64de962764b9b0f        FTPRush 1.1.3 / 2.15<br />
10f5a20c21466e85        FTP Voyager 15.2.0.17<br />
7937df3c65790919        FTP Explorer 10.5.19 (Build 001)<br />
9560577fd87cf573        LeechFTP 1.3 (Build 207)<br />
fc999f29bc5c3560        Robo-FTP 3.7.9<br />
c99ddde925d26df3        Robo-FTP 3.7.9 CronMaker<br />
4b632cf2ceceac35        Robo-FTP Server 3.2.5<br />
3a5148bf2288a434        Secure FTP 2.6.1 (Build 20101209.1254)<br />
435a2f986b404eb7        SmartFTP 4.0.1214.0<br />
explorer integrated     Swish<br />
e42a8e0f4d9b8dcf        Sysax FTP Automation 5.15<br />
b8c13a5dd8c455a2        Titan FTP Server 8.40 (Build 1338)<br />
7904145af324576e        Total Commander 7.56a (Build 16.12.2010)<br />
79370f660ab51725        UploadFTP 2.0.1.0<br />
6a8b377d0f5cb666        WinSCP 2.3.0 (Build 146)<br />
9a3bdae86d5576ee        WinSCP 3.2.1 (Build 174) / 3.8.0 (Build 312)<br />
6bb54d82fa42128d        WinSCP 4.3.4 (Build 1428)<br />
b6267f3fcb700b60        WiseFTP 4.1.0<br />
a581b8002a6eb671        WiseFTP 5.5.9<br />
2544ff74641b639d        WiseFTP 6.1.5<br />
c54b96f328bdc28d        WiseFTP 7.3.0<br />
Web-based                       WS_FTP</wbr></p>
<p>IM<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<wbr>&#8212;&#8212;&#8212;&#8212;<br />
b3965c840bf28ef4        AIM 4.8.2616<br />
1b29f0dc90366bb AIM 5.9.3857<br />
27ececd8d89b6767        AIM 6.2.14.2 / 6.5.3.12 / 6.9.17.2<br />
6f647f9488d7a           AIM 7.5.11.9 (custom AppID + JL support)<br />
ca942805559495e9        aMSN 0.98.4<br />
c6f7b5bf1b9675e4        BitWise IM 1.7.3a<br />
fb1f39d1f230480a        Bopup Messenger 5.6.2.9178 (all languages:<br />
en,du,fr,ger,rus,es)<br />
dc64de6c91c18300        Brosix Communicator 3.1.3 (Build 110719 nid 1)<br />
f09b920bfb781142        Camfrog 4.0.47 / 5.5.0 / 6.1 (build 146) (JL<br />
support)<br />
ebd8c95d87f25154        Carrier 2.5.5<br />
depends on location     Coccinella Messenger 0.96.20 (portable)<br />
30d23723bdd5d908        Digsby (Build 30140) (JL support)<br />
728008617bc3e34b        eM Client 3.0.10206.0<br />
689319b6547cda85        emesene 2.11.7<br />
454ef7dca3bb16b2        Exodus 0.10.0.0<br />
cca6383a507bac64        Gadu-Gadu 10.5.2.13164<br />
4278d3dc044fc88a        Gaim 1.5.0<br />
777483d3cdac1727        Gajim 0.14.4<br />
6aa18a60024620ae        GCN 2.9.1<br />
3f2cd46691bbee90        GOIM 1.1.0<br />
73c6a317412687c2        Google Talk 1.0.0.104<br />
b0236d03c0627ac4        ICQ 5.1 / ICQLite Build 1068<br />
a5db18f617e28a51        ICQ 6.5 (Build 2024)<br />
2417caa1f2a881d4        ICQ 7.6 (Build 5617)<br />
recognized VM           inSpeak 7.2.0.540<br />
989d7545c2b2e7b2        IMVU 465.8.0.0<br />
a3e0d98f5653b539        Instantbird 1.0 (20110623121653) (JL support)<br />
bcc705f705d8132b        Instan-t 5.2 (Build 2824)<br />
6059df4b02360af Kadu 0.10.0 / 0.6.5.5<br />
c312e260e424ae76        Mail.Ru Agent 5.8 (JL support)<br />
22cefa022402327d        Meca Messenger 5.3.0.52<br />
depends on location     Mercury Messenger (portable)<br />
86b804f7a28a3c17        Miranda IM 0.6.8 / 0.7.6 / 0.8.27 / 0.9.9 / 0.9.29<br />
(ANSI + Unicode)<br />
b868d9201b866d96        Microsoft Lync 4.0.7577.0<br />
8c816c711d66a6b5        MSN Messenger 6.2.0137 / 7.0.0820<br />
depends on location     MSNPSharp (portable)<br />
2d1658d5dc3cbe2d        MySpaceIM 1.0.823.0 Beta<br />
bf9ae1f46bd9c491        Nimbuzz 2.0.0 (rev 6266)<br />
fb7ca8059b8f2123        ooVoo 3.0.7.21<br />
efb08d4e11e21ece        Paltalk Messenger 10.0 (Build 409)<br />
4f24a7b84a7de5a6        Palringo 2.6.3 (r45983)<br />
e93dbdcede8623f2        Pandion 2.6.106<br />
aedd2de3901a77f4        Pidgin 2.0.0 / 2.10.0 / 2.7.3<br />
c5236fd5824c9545        PLAYXPERT 1.0.140.2822<br />
dee18f19c7e3a2ec        PopNote 5.21<br />
1a60b1067913516a        Psi 0.14<br />
e0532b20aa26a0c9        QQ International 1.1 (2042)<br />
3c0022d9de573095        QuteCom 2.2<br />
93b18adf1d948fa3        qutIM 0.2<br />
e0246018261a9ccc        qutIM 0.2.80.0<br />
2aa756186e21b320        RealTimeQuery 3.2<br />
521a29e5d22c13b4        Skype 1.4.0.84 / 2.5.0.154 / 3.8.0.139 / 4.2.0.187 /<br />
Skype 5.3.0.120 / 5.5.0.115 / 5.5.32.117<br />
70b52cf73249257 Sococo 1.5.0.2274<br />
d41746b133d17456        Tkabber 0.11.1<br />
c8aa3eaee3d4343d        Trillian 0.74 / 3.1 / 4.2.0.25 / 5.0.0.35 (JL<br />
support)<br />
d7d647c92cd5d1e6        uTalk 2.6.4 r47692<br />
36c36598b08891bf        Vovox 2.5.3.4250<br />
884fd37e05659f3a        VZOchat 6.3.5<br />
3461e4d1eb393c9c        WTW 0.8.18.2852 / 0.8.19.2940<br />
f2cb1c38ab948f58        X-Chat 1.8.10 / 2.6.9 / 2.8.9<br />
4e0ac37db19cba15        Xfire 1.138 (Build 44507)<br />
da7e8de5b8273a0f        Yahoo Messenger 5.0.0.1226 / 6.0.0.1922<br />
62dba7fb39bb0adc        Yahoo Messenger 7.5.0.647 / 8.1.0.421 / 9.0.0.2162 /<br />
10.0.0.1270<br />
fb230a9fe81e71a8        Yahoo Messenger 11.0.0.2014-us<br />
b06a975b62567622        Windows Live Messenger 8.5.1235.0517 BETA<br />
bd249197a6faeff2        Windows Live Messenger 2011</wbr></p>
<p>IRC<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<wbr>&#8212;&#8212;&#8212;&#8212;<br />
b223c3ffbc0a7a42        Bersirc 2.2.14<br />
c01d68e40226892b        ClicksAndWhistles 2.7.146<br />
ac8920ed05001800        DMDirc 0.6.5 (Profile store:<br />
C:\Users\$user\AppData\<wbr>Roaming\DMDirc\)<br />
d3530c5294441522        HydraIRC 0.3.165<br />
8904a5fd2d98b546        IceChat 7.70 20101031<br />
6b3a5ce7ad4af9e4        IceChat 9 RC2<br />
fa496fe13dd62edf        KVIrc 3.4.2.1 / 4.0.4<br />
65f7dd884b016ab2        LimeChat 2.39<br />
19ccee0274976da8        mIRC 4.72 / 5.61<br />
ae069d21df1c57df        mIRC 6.35 / 7.19<br />
e30bbea3e1642660        Neebly 1.0.4<br />
54c803dfc87b52ba        Nettalk 6.7.12<br />
dd658a07478b46c2        PIRCH98 1.0.1.1190<br />
depends on location     Quassel IRC 0.7.1 (portable)<br />
6fee01bd55a634fe        Smuxi 0.8.0.0<br />
2a5a615382a84729        X-Chat 2 2.8.6-2</wbr></wbr></p>
<p>Usenet<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<wbr>&#8212;&#8212;&#8212;&#8212;<br />
ace8715529916d31        40tude Dialog 2.0.15.1 (Beta 38)<br />
cc76755e0f925ce6        AllPicturez 1.2<br />
36f6bc3efe1d99e0        Alt.Binz 0.25.0 (Build 27.09.2007)<br />
d53b52fb65bde78c        Android Newsgroup Downloader 6.2<br />
c845f3a6022d647c        Another File 2.03 (Build 2/7/2004)<br />
780732558f827a42        AutoPix 5.3.3<br />
baea31eacd87186b        BinaryBoy 1.97 (Build 55)<br />
eab25958dbddbaa4        Binary News Reaper 2 (Beta 0.14.7.448)<br />
bf483b423ebbd327        Binary Vortex 5.0<br />
36801066f71b73c5        Binbot 2.0<br />
13eb0e5d9a49eaef        Binjet 3.0.2<br />
8172865a9d5185cb        Binreader 1.0 (Beta 1)<br />
6224453d9701a612        BinTube 3.7.1.0 (requires VLC 10.5!)<br />
cf6379a9a987366e        Digibin 1.31<br />
43886ba3395acdcc        Easy Post 3.0<br />
cfab0ec14b6f953         Express NewsPictures 2.41 (Build 08.05.07.0)<br />
7526de4a8b5914d9        Forte Agent 6.00 (Build 32.1186)<br />
c02baf50d02056fc        FotoVac 1.0<br />
3ed70ef3495535f7        Gravity 3.0.4<br />
86781fe8437db23e        Messenger Pro 2.66.6.3353<br />
f920768fe275f7f4        Grabit 1.5.3 Beta (Build 909) / 1.6.2 (Build 940) /<br />
1.7.2 Beta 4 (Build 997)<br />
9f03ae476ad461fa        GroupsAloud 1.0<br />
d0261ed6e16b200b        News File Grabber 4.6.0.4<br />
8211531a7918b389        Newsbin Pro 6.00 (Build 1019) (JL support)<br />
d1fc019238236806        Newsgroup Commander Pro 9.05<br />
186b5ccada1d986b        NewsGrabber 3.0.36<br />
4d72cfa1d0a67418        Newsgroup Image Collector<br />
92f1d5db021cd876        NewsLeecher 4.0 / 5.0 Beta 6<br />
d7666c416cba240c        NewsMan Pro 3.0.5.2<br />
7b2b4f995b54387d        News Reactor 20100224.16<br />
cb984e3bc7faf234        NewsRover 17.0 (Rev.0)<br />
c98ab5ccf25dda79        NewsShark 2.0<br />
dba909a61476ccec        NewsWolf 1.41<br />
2b164f512891ae37        NewsWolf NSListGen<br />
cb1d97aca3fb7e6b        Newz Crawler 1.9.0 (Build 4100)<br />
3be7b307dfccb58f        NiouzeFire 0.8.7.0<br />
de76415e0060ce13        Noworyta News Reader 2.9<br />
cd40ead0b1eb15ab        NNTPGrab 0.6.2<br />
d5c02fc7afbb3fd4        NNTPGrab 0.6.2 Server<br />
a4def57ee99d77e9        Nomad News 1.43<br />
3f97341a65bac63a        Ozum 6.07 (Build 6070)<br />
bfe841f4d35c92b1        QuadSucker/News 5.0<br />
web-based                       sabnzbd 0.6.8<br />
d3c5cf21e86b28af        SeaMonkey 2.3.3<br />
7a7c60efd66817a2        Spotnet 1.7.4<br />
eb3300e672136bc7        Stream Reactor 1.0 Beta 9 (uses VLC!)<br />
3168cc975b354a01        Slypheed 3.1.2 (Build 1120)<br />
776beb1fcfc6dfa5        Thunderbird 1.0.6 (20050716) / 3.0.2<br />
3d877ec11607fe4 Thunderbird 6.0.2<br />
7192f2de78fd9e96        TIFNY 5.0.3<br />
9dacebaa9ac8ca4e        TLNews Newsreader 2.2.0 (Build 2430)<br />
7fd04185af357bd5        UltraLeeacher 1.7.0.2969 / 1.8 Beta (Build 3490)<br />
aa11f575087b3bdc        Unzbin 2.6.8<br />
pay only                                Usenet Explorer 3.3 (pay)<br />
d7db75db9cdd7c5d        Xnews 5.04.25</wbr></p>
<p>System Cleaners<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<wbr>&#8212;&#8212;&#8212;&#8212;<br />
ed7a5cc3cca8d52a        CCleaner 1.32.345 / 1.41.544 / 2.36.1233 / 3.10.1525<br />
eb7e629258d326a1        WindowWasher 6.6.1.18<br />
</wbr></p>
<p><strong>File Locations</strong><br />
- *.automaticDestinations-ms files (in %appdata%\Microsoft\Windows\Recent\automaticDestinations)<br />
- *.customDestinations-ms files (in %appdata%\Microsoft\Windows\Recent\customDestinations)</p>
<p><strong>Research Links</strong></p>
<p style="text-align: justify;"><strong></strong>Please check out the original blog post for which this information was gathered. It provides additional information and a nice layout for the AppIDs.<br />
<a href="http://4n6k.blogspot.com/2011/09/jump-list-forensics-appids-part-1.html">http://4n6k.blogspot.com/2011/09/jump-list-forensics-appids-part-1.html</a><br />
<a href="http://4n6k.blogspot.com/2011/09/jump-list-forensics-appids-part-2.html" target="_blank">http://4n6k.blogspot.com/2011/09/jump-list-forensics-appids-part-2.html</a></p>
<p style="text-align: justify;">References</p>
<ol>
<li>Forensic Examination of Windows 7 Jump Lists Powerpoint (by Troy Larson) – <a href="http://www.slideshare.net/ctin/windows-7-forensics-jump-listsrv3public" target="_blank">http://www.slideshare.net/ctin/windows-7-forensics-jump-listsrv3public</a></li>
<li>Windows 7 Taskbar Part 1 (by Yochay Kiriaty) – <a href="http://blogs.msdn.com/b/yochay/archive/2009/01/06/windows-7-taskbar-part-1-the-basics.aspx" target="_blank">http://blogs.msdn.com/b/yochay/archive/2009/01/06/windows-7-taskbar-part-1-the-basics.aspx</a></li>
<li>The Forensic Value of Windows 7 Jump Lists (by Alex Barnett) – <a href="http://www.alexbarnett.com/jumplistforensics.pdf" target="_blank">http://www.alexbarnett.com/jumplistforensics.pdf</a></li>
<li>Application User Model IDs (AppUserModelIDs) (by MSDN) – <a href="http://msdn.microsoft.com/en-us/library/dd378459(v=vs.85).aspx" target="_blank">http://msdn.microsoft.com/en-us/library/dd378459(v=vs.85).aspx</a></li>
<li>Developing for the Windows 7 Taskbar – Application ID (by Yochay Kiriaty) – <a href="http://windowsteamblog.com/windows/b/developers/archive/2009/06/18/developing-for-the-windows-7-taskbar-application-id.aspx" target="_blank">http://windowsteamblog.com/windows/b/developers/archive/2009/06/18/developing-for-the-windows-7-taskbar-application-id.aspx</a></li>
<li>Developing for the Windows 7 Taskbar – Jump into Jump Lists – Part 2 (by Yochay Kiriaty) – <a href="http://windowsteamblog.com/windows/b/developers/archive/2009/06/25/developing-for-the-windows-7-taskbar-jump-into-jump-lists-part-2.aspx" target="_blank">http://windowsteamblog.com/windows/b/developers/archive/2009/06/25/developing-for-the-windows-7-taskbar-jump-into-jump-lists-part-2.aspx</a></li>
<li>ForensicsWiki List of Jump List IDs – <a href="http://www.forensicswiki.org/wiki/List_of_Jump_List_IDs" target="_blank">http://www.forensicswiki.org/wiki/List_of_Jump_List_ID</a></li>
</ol>
<p>&nbsp;</p>
<p><strong>
<ul>
<li><a title="Jump List AppIDs (Windows 7) &#8211; File Sharing/P2P, FTP, IRC, IM/Communications, Usenet Newsreaders, System Cleaners" href="http://forensicartifacts.com/2011/09/jump-list-appids-windows-7-file-sharingp2p-ftp-irc-imcommunications-usenet-newsreaders-system-cleaners/">Jump List AppIDs (Windows 7) &#8211; File Sharing/P2P, FTP, IRC, IM/Communications, Usenet Newsreaders, System Cleaners</a></li>
<li><a title="NetworkList (Vista/Windows 7)" href="http://forensicartifacts.com/2011/06/networklist-vistawindows-7/">NetworkList (Vista/Windows 7)</a></li>
<li><a title="Evernote note storage" href="http://forensicartifacts.com/2011/06/evernote-note-storage/">Evernote note storage</a></li>
<li><a title="Volume Shadow Copies" href="http://forensicartifacts.com/2011/05/volume-shadow-copies/">Volume Shadow Copies</a></li>
<li><a title="Google Chrome Browser Profile (Windows Vista/Windows 7)" href="http://forensicartifacts.com/2011/02/google-chrome-browser-profile-windows-vistawindows-7/">Google Chrome Browser Profile (Windows Vista/Windows 7)</a></li>
</ul>
<p></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://forensicartifacts.com/2011/09/jump-list-appids/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Dropbox Config Files (Windows)</title>
		<link>http://forensicartifacts.com/2011/07/dropbox-config-files-windows/</link>
		<comments>http://forensicartifacts.com/2011/07/dropbox-config-files-windows/#comments</comments>
		<pubDate>Fri, 01 Jul 2011 17:58:23 +0000</pubDate>
		<dc:creator>Joe G</dc:creator>
				<category><![CDATA[Cloud Based]]></category>
		<category><![CDATA[Programs]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[dropbox]]></category>
		<category><![CDATA[registry]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://forensicartifacts.com/?p=115</guid>
		<description><![CDATA[Author Name Frank McClain Artifact Name Dropbox Config Files (Windows) Artifact/Program Version Dropbox 1.1.35 (Windows) Description Dropbox is a file-synchronization, backup, and (even) sharing service. It has applications that run on Windows ®, Mac, Linux, iPhone, Android and Blackberry. Once downloaded and installed, their application will run when the OS starts. It adds a systray [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Author Name</strong><br />
Frank McClain</p>
<p><strong>Artifact Name</strong><br />
Dropbox Config Files (Windows)</p>
<p><strong>Artifact/Program Version</strong><br />
Dropbox 1.1.35 (Windows)</p>
<p><strong> </strong><strong>Description</strong><br />
Dropbox is a file-synchronization, backup, and (even) sharing service.<br />
It has applications that run on Windows ®, Mac, Linux, iPhone,<br />
Android and Blackberry.  Once downloaded and installed, their<br />
application will run when the OS starts.  It adds a systray item that<br />
allows you to access the settings (&#8216;Preferences&#8217;), and your files.<br />
The application creates a ‘My Dropbox’ folder inside the user’s<br />
‘My Documents’ folder, for local cached/offline copies of the<br />
files (this default location can be changed).  These will then synch<br />
with the web storage and across all other computers connected to the<br />
account that are online.  Multiple computers can be connected to one<br />
account; if these are on the same network, a feature called ‘LAN<br />
synch’ allows them to communicate with one another directly when<br />
synching files, in order to reduce bandwidth consumption (as a note,<br />
the synch only transfers the data that is changed, not the entire<br />
file).</p>
<p><strong>Registry Keys</strong><br />
With a clean installation, there were 173 registry keys created and 58<br />
values set (captured via Sysinternals ProcMon).  During<br />
uninstallation, there were 153 changes to the registry (logged with<br />
regshot), including 49 deletions:<br />
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt1\:<br />
&#8220;{FB314ED9-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}&#8221;<br />
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt2\:<br />
&#8220;{FB314EDA-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}&#8221;<br />
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt3\:<br />
&#8220;{FB314EDB-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}&#8221;<br />
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt4\:<br />
&#8220;{FB314EDC-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx\Software\Dropbox\InstallPath:<br />
&#8220;C:\Documents and Settings\username\Application Data\Dropbox\bin&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx\Software\Microsoft\Windows\CurrentVersion\Shell<br />
Extensions\Approved\{FB314ED9-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}:<br />
&#8220;DropboxExt&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx\Software\Microsoft\Windows\CurrentVersion\Shell<br />
Extensions\Approved\{FB314EDA-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}:<br />
&#8220;DropboxExt&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx\Software\Microsoft\Windows\CurrentVersion\Shell<br />
Extensions\Approved\{FB314EDB-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}:<br />
&#8220;DropboxExt&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx\Software\Microsoft\Windows\CurrentVersion\Shell<br />
Extensions\Approved\{FB314EDC-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}:<br />
&#8220;DropboxExt&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx\Software\Microsoft\Windows\CurrentVersion\Uninstall\Dropbox\UninstallString:<br />
&#8220;&#8221;C:\Documents and Settings\username\Application<br />
Data\Dropbox\bin\Uninstall.exe&#8221;"<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx\Software\Microsoft\Windows\CurrentVersion\Uninstall\Dropbox\InstallLocation:<br />
&#8220;C:\Documents and Settings\username\Application Data\Dropbox\bin&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx\Software\Microsoft\Windows\CurrentVersion\Uninstall\Dropbox\DisplayName:<br />
&#8220;Dropbox&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx\Software\Microsoft\Windows\CurrentVersion\Uninstall\Dropbox\DisplayIcon:<br />
&#8220;C:\Documents and Settings\username\Application<br />
Data\Dropbox\bin\Dropbox.exe,0&#8243;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx\Software\Microsoft\Windows\CurrentVersion\Uninstall\Dropbox\DisplayVersion:<br />
&#8220;1.1.35&#8243;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx\Software\Microsoft\Windows\CurrentVersion\Uninstall\Dropbox\URLInfoAbout:<br />
&#8220;http://www.dropbox.com&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx\Software\Microsoft\Windows\CurrentVersion\Uninstall\Dropbox\HelpLink:<br />
&#8220;http://www.dropbox.com&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx\Software\Microsoft\Windows\CurrentVersion\Uninstall\Dropbox\NoModify:<br />
0&#215;00000001<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx\Software\Microsoft\Windows\CurrentVersion\Uninstall\Dropbox\NoRepair:<br />
0&#215;00000001<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx\Software\Microsoft\Windows\CurrentVersion\Uninstall\Dropbox\Publisher:<br />
&#8220;Dropbox, Inc.&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx\Software\Classes\*\shellex\ContextMenuHandlers\DropboxExt\:<br />
&#8220;{FB314ED9-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx\Software\Classes\CLSID\{FB314ED9-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}\InProcServer32\:<br />
&#8220;C:\Documents and Settings\username\Application<br />
Data\Dropbox\bin\DropboxExt.14.dll&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx\Software\Classes\CLSID\{FB314ED9-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}\InProcServer32\ThreadingModel:<br />
&#8220;Apartment&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx\Software\Classes\CLSID\{FB314ED9-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}\:<br />
&#8220;DropboxExt&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx\Software\Classes\CLSID\{FB314EDA-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}\InProcServer32\:<br />
&#8220;C:\Documents and Settings\username\Application<br />
Data\Dropbox\bin\DropboxExt.14.dll&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx\Software\Classes\CLSID\{FB314EDA-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}\InProcServer32\ThreadingModel:<br />
&#8220;Apartment&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx\Software\Classes\CLSID\{FB314EDA-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}\:<br />
&#8220;DropboxExt&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx\Software\Classes\CLSID\{FB314EDB-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}\InProcServer32\:<br />
&#8220;C:\Documents and Settings\username\Application<br />
Data\Dropbox\bin\DropboxExt.14.dll&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx\Software\Classes\CLSID\{FB314EDB-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}\InProcServer32\ThreadingModel:<br />
&#8220;Apartment&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx\Software\Classes\CLSID\{FB314EDB-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}\:<br />
&#8220;DropboxExt&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx\Software\Classes\CLSID\{FB314EDC-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}\InProcServer32\:<br />
&#8220;C:\Documents and Settings\username\Application<br />
Data\Dropbox\bin\DropboxExt.14.dll&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx\Software\Classes\CLSID\{FB314EDC-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}\InProcServer32\ThreadingModel:<br />
&#8220;Apartment&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx\Software\Classes\CLSID\{FB314EDC-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}\:<br />
&#8220;DropboxExt&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx\Software\Classes\Directory\Background\shellex\ContextMenuHandlers\DropboxExt\:<br />
&#8220;{FB314ED9-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx\Software\Classes\Directory\shellex\ContextMenuHandlers\DropboxExt\:<br />
&#8220;{FB314ED9-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx_Classes\*\shellex\ContextMenuHandlers\DropboxExt\:<br />
&#8220;{FB314ED9-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx_Classes\CLSID\{FB314ED9-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}\InProcServer32\:<br />
&#8220;C:\Documents and Settings\username\Application<br />
Data\Dropbox\bin\DropboxExt.14.dll&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx_Classes\CLSID\{FB314ED9-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}\InProcServer32\ThreadingModel:<br />
&#8220;Apartment&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx_Classes\CLSID\{FB314ED9-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}\:<br />
&#8220;DropboxExt&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx_Classes\CLSID\{FB314EDA-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}\InProcServer32\:<br />
&#8220;C:\Documents and Settings\username\Application<br />
Data\Dropbox\bin\DropboxExt.14.dll&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx_Classes\CLSID\{FB314EDA-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}\InProcServer32\ThreadingModel:<br />
&#8220;Apartment&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx_Classes\CLSID\{FB314EDA-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}\:<br />
&#8220;DropboxExt&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx_Classes\CLSID\{FB314EDB-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}\InProcServer32\:<br />
&#8220;C:\Documents and Settings\username\Application<br />
Data\Dropbox\bin\DropboxExt.14.dll&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx_Classes\CLSID\{FB314EDB-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}\InProcServer32\ThreadingModel:<br />
&#8220;Apartment&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx_Classes\CLSID\{FB314EDB-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}\:<br />
&#8220;DropboxExt&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx_Classes\CLSID\{FB314EDC-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}\InProcServer32\:<br />
&#8220;C:\Documents and Settings\username\Application<br />
Data\Dropbox\bin\DropboxExt.14.dll&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx_Classes\CLSID\{FB314EDC-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}\InProcServer32\ThreadingModel:<br />
&#8220;Apartment&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx_Classes\CLSID\{FB314EDC-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}\:<br />
&#8220;DropboxExt&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx_Classes\Directory\Background\shellex\ContextMenuHandlers\DropboxExt\:<br />
&#8220;{FB314ED9-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}&#8221;<br />
HKU\S-1-5-21-xxxxxxxxx-xxxxxxxxx-xxxxxxxxx-xxxx_Classes\Directory\shellex\ContextMenuHandlers\DropboxExt\:<br />
&#8220;{FB314ED9-xxxx-xxxx-xxxx-xxxxxxxxxxxxx}&#8221;</p>
<p><strong>File Locations</strong><br />
The majority of Dropbox&#8217;s configuration and user info are stored in<br />
SQLite database files in %appdata% under the Dropbox directory.<br />
config.db<br />
filecache.db<br />
sigstore.db<br />
host.db<br />
unlink.db<br />
Two are not actually SQLite files:  host.db (plain text) and unlink.db<br />
(not sure?).</p>
<p>Config.db contains some info about the local Dropbox installation and<br />
account.  It shows what it calls the “host_id” which appears to be<br />
an md5 hash value.  It also lists the email address associated with<br />
the account (could be useful during an investigation).  Also shown is<br />
the current version/build for the local application.</p>
<p>Filecache.db has several tables, but the one I think is of the most<br />
interest is &#8216;file_journal;&#8217; it contains a listing of all directories<br />
and files inside &#8216;My Dropbox.&#8217;  It appears these are only the live<br />
files, not deleted ones.  </p>
<p>Sigstore.db records SHA-256 hash and size information about each file,<br />
but no names etc.  </p>
<p>These can be viewed with a SQLite viewer, or parsed with other<br />
programs (see research links).</p>
<p>Inside the user&#8217;s Dropbox folder is a hidden directory,<br />
.dropbox.cache.  This contains a record of files created/modified (and<br />
saved) on another linked system.  There are copies of the files<br />
themselves, for each revision/save, and an entries.log file that<br />
appears to contain encoded information about each of those files.</p>
<p><strong>Research Links</strong><br />
<a href="http://sba-research.org/"></a><br />
<a href="http://www.cybermarshal.com/index.php/cyber-marshal-utilities/dropbox-reader"></a><br />
<a href="http://en.wikipedia.org/wiki/Dropship_%28software%29"></a><br />
<a href="http://dereknewton.com/2011/04/dropbox-authentication-static-host-ids/"></a><br />
<a href="http://dereknewton.com/tag/dropbox/"></a><br />
<a href="http://forensicaliente.blogspot.com/"></a> (some more research to be posted<br />
soon)<br />
<a href="http://www.forensicfocus.com/dropbox-forensics"></a><br />
<a href="http://computer-forensics.sans.org/blog/2011/06/17/digital-forensics-rain-drop-keeps-falling-on-my-box"></a></p>
<p><strong>Forensic Programs of Use</strong><br />
<a href="http://sqlitebrowser.sourceforge.net/"></a> (not forensic, but good for<br />
viewing the SQLite db files)<br />
<a href="http://www.ccl-forensics.com/Software/epilog-from-ccl-forensics.html"></a> (haven&#8217;t tried it yet, may be able to parse deleted records from the<br />
SQLite db files)</p>
<p><strong>Other Info</strong><br />
The Dropbox Reader python scripts are handy to parse through the<br />
SQLite db files quickly and get output that way, rather than trying to<br />
load up individually in a viewer.  They&#8217;re designed specifically to<br />
work with Dropbox&#8217;s implementation, and present the information in a<br />
more meaningful way.  </p>
<p>I had some issues getting them to work properly and they were very<br />
responsive and helpful.  Apparently one of my files is a bit of an<br />
oddball (missing some information) so it won&#8217;t parse correctly;<br />
they&#8217;re working on a fix for that.</p>
]]></content:encoded>
			<wfw:commentRss>http://forensicartifacts.com/2011/07/dropbox-config-files-windows/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>UserInfo (Windows)</title>
		<link>http://forensicartifacts.com/2011/06/userinfo-windows/</link>
		<comments>http://forensicartifacts.com/2011/06/userinfo-windows/#comments</comments>
		<pubDate>Thu, 09 Jun 2011 18:40:57 +0000</pubDate>
		<dc:creator>Joe G</dc:creator>
				<category><![CDATA[Registry]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[registry]]></category>
		<category><![CDATA[UserInfo]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://forensicartifacts.com/?p=113</guid>
		<description><![CDATA[Author Name Corey Harrell Artifact Name UserInfo Artifact/Program Version Windows Registry Description Microsoft Office documents contain metadata that show when a file was created, modified, and user names. The user names in Microsoft Office documents’ metadata is pulled from the UserInfo registry key of the user account’s registry hive performing the actions. The values responsible [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Author Name</strong><br />
Corey Harrell</p>
<p><strong>Artifact Name</strong><br />
UserInfo</p>
<p><strong>Artifact/Program Version</strong><br />
Windows Registry</p>
<p><strong> </strong><strong>Description</strong><br />
Microsoft Office documents contain metadata that show when a file was<br />
created, modified, and user names. The user names in Microsoft Office<br />
documents’ metadata is pulled from the UserInfo registry key of the<br />
user account’s registry hive performing the actions. The values<br />
responsible in the UserInfo registry are the UserName and Company<br />
values.</p>
<p>The population of the data in the UserName and Company registry values<br />
varies. The values are populated in the user account that installed<br />
Microsoft Office with the user name and company entered during<br />
installation. For the user accounts that are using Microsoft Office<br />
but didn’t install it, the values are populated a little different.<br />
The first time the user launches an Office application a dialog box<br />
appears asking for the user name and initials. The information entered<br />
in the dialog box is what results in the UserName value in the user&#8217;s<br />
UserInfo registry key. The location of the UserInfo registry key<br />
varies depending on the version of Microsoft Office installed on the<br />
system.</p>
<p><strong>Registry Keys</strong><br />
Microsoft Office 2007: HCU\Software\Microsoft\Office\Common\UserInfo<br />
Microsoft Office 2003:<br />
HCU\Software\Microsoft\Office\11.0\Common\UserInfo</p>
<p><strong>Research Links</strong><br />
<a href="http://support.microsoft.com/kb/821550"></a><a href="http://support.microsoft.com/kb/821550" target="_blank">http://support.microsoft.com/kb/821550</a><br />
<a href="http://journeyintoir.blogspot.com/2011/06/why-is-it-what-it-is.html" target="_blank">http://journeyintoir.blogspot.com/2011/06/why-is-it-what-it-is.html</a><br />
<a href="http://journeyintoir.blogspot.com/2011/06/why-is-it-what-it-is.html"></a></p>
<p><strong>Forensic Programs of Use</strong><br />
Registry viewer such as the free MiTeC Windows Registry Recovery</p>
]]></content:encoded>
			<wfw:commentRss>http://forensicartifacts.com/2011/06/userinfo-windows/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>NetworkList (Vista/Windows 7)</title>
		<link>http://forensicartifacts.com/2011/06/networklist-vistawindows-7/</link>
		<comments>http://forensicartifacts.com/2011/06/networklist-vistawindows-7/#comments</comments>
		<pubDate>Fri, 03 Jun 2011 02:33:29 +0000</pubDate>
		<dc:creator>Joe G</dc:creator>
				<category><![CDATA[Registry]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[networklist]]></category>
		<category><![CDATA[registry]]></category>
		<category><![CDATA[regripper]]></category>
		<category><![CDATA[vista]]></category>
		<category><![CDATA[windows 7]]></category>

		<guid isPermaLink="false">http://forensicartifacts.com/?p=110</guid>
		<description><![CDATA[Author Name H. Carvey Artifact Name NetworkList Artifact/Program Version RegRipper w/ networklist.pl plugin v.20090812 Description Vista and Windows 7 maintain a Registry key named “NetworkList”: HKLM\Microsoft\Windows NT\CurrentVersion\NetworkList This key appears to contain profiles regarding managed and unmanaged networks, including wireless networks that the system has connected to, including SSID, the date the profile was created, [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Author Name</strong><br />
H. Carvey</p>
<p><strong>Artifact Name</strong><br />
NetworkList</p>
<p><strong>Artifact/Program Version</strong><br />
RegRipper w/ networklist.pl plugin v.20090812</p>
<p><strong> </strong><strong>Description</strong><br />
Vista and Windows 7 maintain a Registry key named<br />
“NetworkList”:<br />
HKLM\Microsoft\Windows NT\CurrentVersion\NetworkList</p>
<p>This key appears to contain profiles regarding managed and<br />
unmanaged networks, including wireless networks that the system has<br />
connected to, including SSID, the date the profile was created, the<br />
date last connected, the MAC address of the WAP, etc.  This MAC can be<br />
looked up in the SkyHook database, and possibly converted to a Google<br />
Map.</p>
<p><strong>Registry Keys</strong><br />
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList (Updated 6/3- Thanks to Troy)</p>
<p><strong>File Locations</strong><br />
Software Hive</p>
<p><strong>Forensic Programs of Use</strong><br />
RegRipper w/ networklist.pl plugin</p>
]]></content:encoded>
			<wfw:commentRss>http://forensicartifacts.com/2011/06/networklist-vistawindows-7/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Evernote note storage</title>
		<link>http://forensicartifacts.com/2011/06/evernote-note-storage/</link>
		<comments>http://forensicartifacts.com/2011/06/evernote-note-storage/#comments</comments>
		<pubDate>Thu, 02 Jun 2011 04:53:36 +0000</pubDate>
		<dc:creator>Joe G</dc:creator>
				<category><![CDATA[Programs]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Evernote]]></category>
		<category><![CDATA[windows 7]]></category>

		<guid isPermaLink="false">http://forensicartifacts.com/?p=106</guid>
		<description><![CDATA[Author Name Joseph W Shaw II Artifact Name Evernote note storage Program Version Evernote 4.3.1.4479 Description Evernote is a tool used to capture, store, and share ideas and information in the form of multimedia notes mixing text, images, pdfs, and other document types into searchable &#8220;notes.&#8221; These notes are stored in an SQLite database format. [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Author Name</strong><br />
Joseph W Shaw II</p>
<p><strong>Artifact Name</strong><br />
Evernote note storage</p>
<p><strong>Program Version</strong><br />
Evernote 4.3.1.4479</p>
<p><strong> </strong><strong>Description</strong><br />
Evernote is a tool used to capture, store, and share ideas and<br />
information in the form of multimedia notes mixing text, images, pdfs,<br />
and other document types into searchable &#8220;notes.&#8221;  These notes are<br />
stored in an SQLite database format.  Records are appended to the end<br />
of the database.  As records are deleted, they are overwritten by new<br />
records.  However, data records can be retained inside of the database<br />
when the SQLIite database is viewed in Text or Hex view.</p>
<p><strong>File Locations</strong><br />
On Windows 7: C:\Users\<ProfileID>\AppData\Local\Evernote\Evernote\Database\<EvernoteAccountName>.exb</p>
<p><strong>Forensic Programs of Use</strong><br />
SQLite Database Browser<br />
EnCase 6.18.1.3 64bit</p>
<div id="attachment_108" class="wp-caption alignleft" style="width: 310px"><a href="http://forensicartifacts.com/wp-content/uploads/2011/06/005-Old-Record-Search-Hit1.jpg"><img src="http://forensicartifacts.com/wp-content/uploads/2011/06/005-Old-Record-Search-Hit1-300x161.jpg" alt="" title="Old Record Search Hit" width="300" height="161" class="size-medium wp-image-108" /></a>
<p class="wp-caption-text">Old Record Search Hit</p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://forensicartifacts.com/2011/06/evernote-note-storage/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic page generated in 1.695 seconds. -->
<!-- Cached page generated by WP-Super-Cache on 2012-02-06 15:04:00 -->

