Author Name
Matt
Artifact Name
ACMru – Search Assistant
Description
This registry key stores search terms that have been typed into the Windows Search dialog box (Windows Start Button –> Search). There may be up to four subkeys:
- 5001: Contains list of terms used for the Internet Search Assistant
- 5603: Contains the list of terms used for the Windows XP files and folders search
- 5604: Contains list of terms used in the “word or phrase in a file” search
- 5647: Contains list of terms used in the “for computers or people” search
Registry Keys
HKEY_CURRENT_USER\Software\Microsoft\Search Assistant\ACMru
Forensic Programs of Use
RegRipper
Other Info
A good explanation can be read in Windows Forensic Analysis 2e by Harlan Carvey. I highly recommend this book.
