8
1
If I open the registry with the SYSTEM account in Windows by using the PSExec tool from SysInternals:
psexec -i -s regedit
and I change an entry, for example, here:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
... I presume that a corresponding NTUSER.DAT
file will be modified.
What is the path to this NTUSER.DAT
file?
I think it's c:\windows\system32\config\systemprofile. – LawrenceC – 2014-07-28T00:56:42.550
What version of Windows? – I say Reinstate Monica – 2014-07-28T01:56:50.537
Well, @ultrasawblade, in fact there is a
ntuser.dat
file there. I am trying to browse it from linux's toolchntpw
to check what it is, but the key\Software\Microsoft\
only contains a tree namedCTF
. There is nothing about the rest of theHKEY_CURRENT_USER
tree. – Sopalajo de Arrierez – 2014-07-28T01:56:57.9101@Twisty, I am testing this matter with Windows XP SP3 and Windows 7. I think most Windows versions behave the same way. – Sopalajo de Arrierez – 2014-07-28T01:59:35.703
Not true. I believe Windows 7 stores the LocalSystem and NetworkService registry hives at 'C:\Windows\ServiceProfiles\LocalService\ntuser.dat' and C:\Windows\ServiceProfiles\NetworkService\ntuser.dat' respectively. These folders don't exist on XP. – I say Reinstate Monica – 2014-07-28T02:17:39.623
Well, @Twisty, I have just made the change above (the
CurrentVerion\Run
key), and according to its modification date, none of these last twontuser.dat
files seem to be what we seek. – Sopalajo de Arrierez – 2014-07-28T02:34:38.843@Twisty: as it happent with the @ultrasawblade above suggestion, I have edited those
ntuser.dat
files, and they have only theCTF
tree inside. – Sopalajo de Arrierez – 2014-07-28T02:50:30.453@SopalajodeArrierez - The path would be
C:\Users\<username>
, becauseRun
key inHKEY_CURRENT_USER
implies that must be associated in that specific user profile. – Ĭsααc tիε βöss – 2014-07-28T11:10:08.497@Ĭsααctիεβöss, the
HKEY_CURRENT_USER
registry tree, when opened viapsexec -s
is a diferent one than if I open it via simpleregedit
, so I must suppose<username>
here should be something likeSYSTEM
, and there is noc:\Users\SYSTEM
folder in Windows computers. – Sopalajo de Arrierez – 2014-07-28T14:16:51.597