±Forensic Focus Partners

Become an advertising partner

±Your Account


Username
Password

Forgotten password/username?

Site Members:

New Today: 0 Overall: 35251
New Yesterday: 4 Visitors: 103

±Follow Forensic Focus

Forensic Focus Facebook PageForensic Focus on TwitterForensic Focus LinkedIn GroupForensic Focus YouTube Channel

RSS feeds: News Forums Articles

±Latest Articles

±Latest Webinars

Xways and Jumplists

Forensic software discussion (commercial and open source/freeware). Strictly no advertising.
Reply to topicReply to topic Printer Friendly Page
Forum FAQSearchView unanswered posts
Page 1, 2  Next 
  

pajkow
Senior Member
 

Xways and Jumplists

Post Posted: Jun 16, 16 10:10

Hi All,

Does anyone know whether X-Wys 18.8 when parsing jumplists from Win 10 decodes application type by default and if yes, where can I find it? Or do I have to go on-line to decode it?

Also i have tried to use Jumplister v 1.1.0 but this does not seem to parse properly jumpists from Win 10.

So if both above are NO

Do you have any good program/methodology that I can apply to parse Jumplists from Windows 10?

If NOT, have anyone had this App ID? = fc866c38e3681848 Automatic Desitnations - it looks like a player to me but not sure which one.

So far I have checked IEF, Jumplister and on-line - nothing matching this ID. Is there any calc that can parse it?  
 
  

jaclaz
Senior Member
 

Re: Xways and Jumplists

Post Posted: Jun 16, 16 10:53

- pajkow


If NOT, have anyone had this App ID? = fc866c38e3681848 Automatic Desitnations - it looks like a player to me but not sure which one.

So far I have checked IEF, Jumplister and on-line - nothing matching this ID. Is there any calc that can parse it?

Do you have the actual file/stream?
Can you have a look at it in a hex viewer/editor (or maybe in a .lnk fileparser)?
Like:
www.nirsoft.net/utils/..._view.html

The format is documented, see;
windowsir.blogspot.it/...lysis.html
and:
forensicswiki.org/wiki/Jump_Lists
(via google web cache):
webcache.googleusercon...mp;ct=clnk

Unless of course the stupid Windows 10 has changed format. Confused

Check also this:
www.hexacorn.com/blog/...alculator/

(useful for verification)

jaclaz
_________________
- In theory there is no difference between theory and practice, but in practice there is. - 
 
  

ssenyl
Member
 

Re: Xways and Jumplists

Post Posted: Jun 16, 16 11:17

I discussed briefly here www.forensicfocus.com/...c/t=12527/ that the structure of the JumpLists in Windows 10 had changed slightly.

Although I haven't followed up in earnest, I have seen Windows 10 machines with JumpLists using both the old and new structure.  
 
  

pajkow
Senior Member
 

Re: Xways and Jumplists

Post Posted: Jun 16, 16 12:19

Jaclaz

Thanks for your suggestions, I have the entire Jumplist intact but by browsing through .lnk orphans could you not find any signs of any .exe - is this what you asked for?

I have tried JumpListView v1.04 but again it did not pull out what is the app name.

I have checked Hexacorn already, no such application yet - and as far as I understand the calc utility- this is to ascertain wether this is the one but from The APP to APP ID- NOT other way round.


So I think that the plan now is to run machine in VM, see it what movie app it is. Hopefully it is still there and it is still associated with video files I am after and then use this calc.  
 
  

woany
Member
 

Re: Xways and Jumplists

Post Posted: Jun 16, 16 12:28

Use Eric Zimmermans jump list tool, as it can handle Win10, then you can work out the associated app:

ericzimmerman.github.i...JLECmd.zip

I haven't updated Jumplister since 2013, and as Eric has written newer tools that cover the same areas, I would use his in the first instance. Especially as he tends to review the current assumptions/research when writing new tools.

Also can you look at any prefetch files to see what applications have been run, then use the application paths from those with the AppID Calculator?

I did some googling and looked at various lists of AppID's:

github.com/4n6k/Jump_L...er_List.md
github.com/randomacces.../AppID.txt
www.forensicswiki.org/...p_List_IDs

And none had that particular ID. I did find one reference to the ID:

www.cjoint.com/14nv/DK..._sftgc.txt

But the reference did not give any clues as to the originating app.  
 
  

pajkow
Senior Member
 

Re: Xways and Jumplists

Post Posted: Jun 16, 16 13:03

Woanny

Thanks - but again I have run this with ld & fd and App ID= Unknown

But the output is much better that from JumpListView v 1.04. File path, dates/times and locations are nicely displayed - so, much appreciated Woanny

I guess chaps from Microsoft may know.

If anyone knows email address to someone form M , please PM me.

Thx  

Last edited by pajkow on Jun 16, 16 13:11; edited 1 time in total
 
  

woany
Member
 

Re: Xways and Jumplists

Post Posted: Jun 16, 16 13:04

Are there are prefetch files available?  
 

Page 1 of 2
Page 1, 2  Next