Computer ForumsComputers  

Go Back   Computer Forums > PC Technology Zone > Windows Operating Systems and Software > Tips, Tricks & Tutorials

Reply
 
LinkBack Thread Tools Display Modes
Old 01-22-2007, 08:14 AM   #1 (permalink)
Security/Hacking Mod
 
Osiris's Avatar
 
Join Date: Jan 2005
Location: USA
Posts: 25,860
Default Windows stores information about the programs that you use

Windows XP displays a list of the most recent programs that you have accessed by default in the start menu. Did you know that those information are continuously updated even though the option to show them has been disabled ? A check on my personal account revealed that Windows stored information from 2005 until today.

The information are stored in the registry using a simple ROT-13 encryption. Windows XP saves the full path and name of the program, last access and the number of total executions. UserAssist is a nice little tool that decrypts the information and displays them it its main window. You can clear single entries by right-clicking and selecting clear. If you do have many entries in that list you might want to clear them all by clicking on commands, clear them all.

This does not disable the logging, it simply clears the current state. Windows XP will continue to log all activity unless you disable the whole process by clicking on commands, logging disabled. This will take effect once you restart, logoff and on again or kill the explorer.exe task in the task manager.

The manual way to disable logging would be to open your registry and navigate to the key

HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\UserAssist\Settings\NoLog

and set the value of that key to 1.

Windows stores the encrypted information in the key

HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\UserAssist

Please note that you should not disable or clear the feature if you want to work with the recent items in your start menu.


http://didierstevens.wordpress.com/programs/userassist/
__________________

www.MasterB365.com
www.Tech-Dump.com


"On 10-3-08 Obama Supporters Vandalized-Tresspassed and STOLE My Palin-McCain Sign Violating My First Amendment Right To Free Speech. Do It Again And You Will Find Out What The 2nd Amendment Is All ABOUT!"
Osiris is offline   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 12:16 AM.


Powered by vBulletin® Version 3.7.1
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0