<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: A Windows 7 Launch Party Trick!</title>
	<atom:link href="http://blog.didierstevens.com/2009/10/21/a-windows-7-launch-party-trick/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com/2009/10/21/a-windows-7-launch-party-trick/</link>
	<description>(blog 'DidierStevens)</description>
	<lastBuildDate>Wed, 17 Mar 2010 18:58:11 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2009/10/21/a-windows-7-launch-party-trick/#comment-37692</link>
		<dc:creator>Didier Stevens</dc:creator>
		<pubDate>Sun, 14 Feb 2010 17:04:04 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1816#comment-37692</guid>
		<description>@Napo: it&#039;s slightly different. I&#039;ve written an article that explains this in detail: http://blog.didierstevens.com/2010/01/04/new-format-for-userassist-registry-keys/</description>
		<content:encoded><![CDATA[<p>@Napo: it&#8217;s slightly different. I&#8217;ve written an article that explains this in detail: <a href="http://blog.didierstevens.com/2010/01/04/new-format-for-userassist-registry-keys/" rel="nofollow">http://blog.didierstevens.com/2010/01/04/new-format-for-userassist-registry-keys/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Napo</title>
		<link>http://blog.didierstevens.com/2009/10/21/a-windows-7-launch-party-trick/#comment-37691</link>
		<dc:creator>Napo</dc:creator>
		<pubDate>Sun, 14 Feb 2010 16:55:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1816#comment-37691</guid>
		<description>Hy there! First off: thanks for your great work &amp; effort! Very nice and helpful forensic tool.
Have to point something out:

Perhaps you can give explanations for the different counters: that the &quot;Counter&quot; table lists the number of times the application was launched in this Windows session (= since the last reboot) and the &quot;Focus counter&quot; table lists the overall application startups (= since the first Windows boot after install).

Am I right with these assumption?
Thanks in advance.</description>
		<content:encoded><![CDATA[<p>Hy there! First off: thanks for your great work &amp; effort! Very nice and helpful forensic tool.<br />
Have to point something out:</p>
<p>Perhaps you can give explanations for the different counters: that the &#8220;Counter&#8221; table lists the number of times the application was launched in this Windows session (= since the last reboot) and the &#8220;Focus counter&#8221; table lists the overall application startups (= since the first Windows boot after install).</p>
<p>Am I right with these assumption?<br />
Thanks in advance.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: New Format for UserAssist Registry Keys &#171; Didier Stevens</title>
		<link>http://blog.didierstevens.com/2009/10/21/a-windows-7-launch-party-trick/#comment-37385</link>
		<dc:creator>New Format for UserAssist Registry Keys &#171; Didier Stevens</dc:creator>
		<pubDate>Mon, 04 Jan 2010 15:30:06 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1816#comment-37385</guid>
		<description>[...] forget to use the special version of my UserAssist tool on Windows 7 and Windows Server 2008 R2. Possibly related posts: (automatically generated)   Leave [...]</description>
		<content:encoded><![CDATA[<p>[...] forget to use the special version of my UserAssist tool on Windows 7 and Windows Server 2008 R2. Possibly related posts: (automatically generated)   Leave [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yaggi</title>
		<link>http://blog.didierstevens.com/2009/10/21/a-windows-7-launch-party-trick/#comment-36092</link>
		<dc:creator>Yaggi</dc:creator>
		<pubDate>Sat, 07 Nov 2009 02:36:26 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1816#comment-36092</guid>
		<description>Thanks Didier for the clarification. Is this idea an opportunity for this tool to evolved and can be used for forensic evidence (one way of identfyig it would be abnormal operation of a certain account that can be flag by this tool)?

I understand its a long way to go but Im excited that this tool would grow for the IT community forensic tool.</description>
		<content:encoded><![CDATA[<p>Thanks Didier for the clarification. Is this idea an opportunity for this tool to evolved and can be used for forensic evidence (one way of identfyig it would be abnormal operation of a certain account that can be flag by this tool)?</p>
<p>I understand its a long way to go but Im excited that this tool would grow for the IT community forensic tool.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2009/10/21/a-windows-7-launch-party-trick/#comment-36089</link>
		<dc:creator>Didier Stevens</dc:creator>
		<pubDate>Fri, 06 Nov 2009 14:28:04 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1816#comment-36089</guid>
		<description>If it&#039;s done with the same user account, no.</description>
		<content:encoded><![CDATA[<p>If it&#8217;s done with the same user account, no.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yaggi</title>
		<link>http://blog.didierstevens.com/2009/10/21/a-windows-7-launch-party-trick/#comment-36088</link>
		<dc:creator>Yaggi</dc:creator>
		<pubDate>Fri, 06 Nov 2009 03:48:45 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1816#comment-36088</guid>
		<description>Hello,

This is a nice tool upgrade. Anyway, if the user is being hack and the hacker is exploring the windows explorer of the target, can it be detected that another user is using it so when it comes to investigation at least we can somehow separate a legitimate action from the legitimate user?</description>
		<content:encoded><![CDATA[<p>Hello,</p>
<p>This is a nice tool upgrade. Anyway, if the user is being hack and the hacker is exploring the windows explorer of the target, can it be detected that another user is using it so when it comes to investigation at least we can somehow separate a legitimate action from the legitimate user?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
