<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Update: UserAssist utility</title>
	<atom:link href="http://blog.didierstevens.com/2006/08/04/update-userassist-utility/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com/2006/08/04/update-userassist-utility/</link>
	<description>(blog 'DidierStevens)</description>
	<lastBuildDate>Tue, 09 Mar 2010 09:33:38 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2006/08/04/update-userassist-utility/#comment-35107</link>
		<dc:creator>Didier Stevens</dc:creator>
		<pubDate>Wed, 10 Jun 2009 08:35:09 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/08/04/update-userassist-utility/#comment-35107</guid>
		<description>Yes it will leave traces, the tool is not designed not to leave traces.</description>
		<content:encoded><![CDATA[<p>Yes it will leave traces, the tool is not designed not to leave traces.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ronin Vladiamhe</title>
		<link>http://blog.didierstevens.com/2006/08/04/update-userassist-utility/#comment-35097</link>
		<dc:creator>Ronin Vladiamhe</dc:creator>
		<pubDate>Tue, 09 Jun 2009 21:48:50 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/08/04/update-userassist-utility/#comment-35097</guid>
		<description>Actually, looks like your app no longer exists.</description>
		<content:encoded><![CDATA[<p>Actually, looks like your app no longer exists.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ronin Vladiamhe</title>
		<link>http://blog.didierstevens.com/2006/08/04/update-userassist-utility/#comment-35096</link>
		<dc:creator>Ronin Vladiamhe</dc:creator>
		<pubDate>Tue, 09 Jun 2009 21:46:04 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/08/04/update-userassist-utility/#comment-35096</guid>
		<description>Question answered, yes, though .NET Framwork 2.0 is required on the pc being UA&#039;d. Will it leave any &quot;traces&quot; when run as a portable app?</description>
		<content:encoded><![CDATA[<p>Question answered, yes, though .NET Framwork 2.0 is required on the pc being UA&#8217;d. Will it leave any &#8220;traces&#8221; when run as a portable app?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ronin Vladiamhe</title>
		<link>http://blog.didierstevens.com/2006/08/04/update-userassist-utility/#comment-35095</link>
		<dc:creator>Ronin Vladiamhe</dc:creator>
		<pubDate>Tue, 09 Jun 2009 21:41:43 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/08/04/update-userassist-utility/#comment-35095</guid>
		<description>I&#039;ve been using UserAssistView (v1.00, NirSoft) for a few months now, and recently came across your app. Can it be used, with its full set of features, from removable media (CD/DVD, USB)?</description>
		<content:encoded><![CDATA[<p>I&#8217;ve been using UserAssistView (v1.00, NirSoft) for a few months now, and recently came across your app. Can it be used, with its full set of features, from removable media (CD/DVD, USB)?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jon Meads</title>
		<link>http://blog.didierstevens.com/2006/08/04/update-userassist-utility/#comment-43</link>
		<dc:creator>Jon Meads</dc:creator>
		<pubDate>Sun, 20 Aug 2006 21:59:31 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/08/04/update-userassist-utility/#comment-43</guid>
		<description>I can&#039;t seem to run the UserAssist program. I installed the .Net Framework, restarted the computer and moved UserAssist to the C: directory (though I&#039;d prefer to have it ona different system. When I double click C:\UserAssist\bin\Release\UserAssist.exe, I see a pointer with an horglass and then nothing.

Cheers,
jon</description>
		<content:encoded><![CDATA[<p>I can&#8217;t seem to run the UserAssist program. I installed the .Net Framework, restarted the computer and moved UserAssist to the C: directory (though I&#8217;d prefer to have it ona different system. When I double click C:\UserAssist\bin\Release\UserAssist.exe, I see a pointer with an horglass and then nothing.</p>
<p>Cheers,<br />
jon</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2006/08/04/update-userassist-utility/#comment-32</link>
		<dc:creator>Didier Stevens</dc:creator>
		<pubDate>Wed, 09 Aug 2006 17:33:25 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/08/04/update-userassist-utility/#comment-32</guid>
		<description>I don&#039;t have yet a full understanding of the Session ID, but here&#039;s what I discovered:

- these obversations apply for the 2 count keys: {5E6AB780-7743-11CF-A12B-00AA004AE837} and {75048700-EF1F-11D0-9888-006097DEACF9}
- each count key has its own session ID and appears to work independently from the other
- each time an entry with 16 bytes of binary data is created or updated, the 4 first bytes are set equal to the 4 last bytes of the binary data of the UEME_CTLSESSION entry. Thats why I call those numbers session IDs.
- example: you launch notepad, the session ID of UEME_CTLSESSION is 123, then the session ID for the notepad entry will be 123
- the session ID in UEME_CTLSESSION appears to increase each day with 1 (each day you use your computer)
- after you&#039;ve delete all entries and restarted Windows Explorer, the UEME_CTLSESSION entries are created with session IDs equal to 0
- the 4 first bytes of the binary data of the UEME_CTLSESSION entry is also a timestamp, but of anoher format which I&#039;ve still to understand (it appears to count in units of 53.69 seconds).

Hope this makes sense</description>
		<content:encoded><![CDATA[<p>I don&#8217;t have yet a full understanding of the Session ID, but here&#8217;s what I discovered:</p>
<p>- these obversations apply for the 2 count keys: {5E6AB780-7743-11CF-A12B-00AA004AE837} and {75048700-EF1F-11D0-9888-006097DEACF9}<br />
- each count key has its own session ID and appears to work independently from the other<br />
- each time an entry with 16 bytes of binary data is created or updated, the 4 first bytes are set equal to the 4 last bytes of the binary data of the UEME_CTLSESSION entry. Thats why I call those numbers session IDs.<br />
- example: you launch notepad, the session ID of UEME_CTLSESSION is 123, then the session ID for the notepad entry will be 123<br />
- the session ID in UEME_CTLSESSION appears to increase each day with 1 (each day you use your computer)<br />
- after you&#8217;ve delete all entries and restarted Windows Explorer, the UEME_CTLSESSION entries are created with session IDs equal to 0<br />
- the 4 first bytes of the binary data of the UEME_CTLSESSION entry is also a timestamp, but of anoher format which I&#8217;ve still to understand (it appears to count in units of 53.69 seconds).</p>
<p>Hope this makes sense</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: keydet89</title>
		<link>http://blog.didierstevens.com/2006/08/04/update-userassist-utility/#comment-31</link>
		<dc:creator>keydet89</dc:creator>
		<pubDate>Wed, 09 Aug 2006 01:11:01 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/08/04/update-userassist-utility/#comment-31</guid>
		<description>Cool tool!  What&#039;s the offset to the session ID, and do you know what that maps to?  I wrote some scripts for ProDiscover that parse this info, and I&#039;d like to add this to them...

Thanks,

Harlan</description>
		<content:encoded><![CDATA[<p>Cool tool!  What&#8217;s the offset to the session ID, and do you know what that maps to?  I wrote some scripts for ProDiscover that parse this info, and I&#8217;d like to add this to them&#8230;</p>
<p>Thanks,</p>
<p>Harlan</p>
]]></content:encoded>
	</item>
</channel>
</rss>
