Windows 디렉토리/파일 검색

Windows 아티팩트 검색

MD5SHA1경로(파일명)
1045bfd216ae1ae480dd0ef626f5ff39 377e869bc123602e9b568816b76be600ed03dbd0 [NTFS]\[root]\Windows\SoftwareDistribution\DataStore\Logs\edbres00002.jrs
1045bfd216ae1ae480dd0ef626f5ff39 377e869bc123602e9b568816b76be600ed03dbd0 [NTFS]\[root]\Windows\SoftwareDistribution\DataStore\Logs\edbres00001.jrs
1045bfd216ae1ae480dd0ef626f5ff39 377e869bc123602e9b568816b76be600ed03dbd0 [NTFS]\[root]\Windows\SoftwareDistribution\DataStore\Logs\edbtmp.log
3a1ee9494a55f88ec55f38588ad165bd d5bae5c6d66d6790138e52502ad081424c458987 [NTFS]\[root]\Windows\SoftwareDistribution\DataStore\Logs\edb.log
3f2c37c325ced33fd1f81d0cc6a7c4d2 7a494f70de4bf8d169dce0f47753ce4e8c43b713 [NTFS]\[root]\Windows\CSC\v2.0.6\$I30
f1d3ff8443297732862df21dc4e57262 9069ca78e7450a285173431b3e52c5c25299e473 [NTFS]\[root]\Windows\CSC\v2.0.6\sm
b18276cf4e7d3fbd3cd398778469210e a95759a8bd784f545f96698b229ba6841123dcc3 [NTFS]\[root]\Windows\CSC\v2.0.6\pq
d41d8cd98f00b204e9800998ecf8427e da39a3ee5e6b4b0d3255bfef95601890afd80709 [NTFS]\[root]\Windows\CSC\v2.0.6\temp\ea-{db44b044-10fc-11f0-b90b-08002786d04f}
e810cb1968a9c00132687fedc1b000bc ba32ffd128c00a26ee7566602593a03b3ece11ec [NTFS]\[root]\Windows\bootstat.dat
88b20a3b0e50dd0dea609754538121fd cdf8878d9529e560024e0dad899eab934cc91e9e [NTFS]\[root]\Windows\ServiceProfiles\LocalService\$I30
59071590099d21dd439896592338bf95 6a521e1d2a632c26e53b83d2cc4b0edecfc1e68c [NTFS]\[root]\Windows\ServiceProfiles\LocalService\NTUSER.DAT{53b39e88-18c4-11ea-a811-000d3aa4692b}.TMContainer00000000000000000002.regtrans-ms
87ccce37e027ff9dedd1285a6a90b545 9e7bcfc4b9f45e7b77710f7704bcb2f1acc897af [NTFS]\[root]\Windows\ServiceProfiles\LocalService\NTUSER.DAT{53b39e88-18c4-11ea-a811-000d3aa4692b}.TMContainer00000000000000000001.regtrans-ms
b16be0da68bfff4f6b8237e748e80e30 c7ba467266342b4430d1f4200eb75622a226cc86 [NTFS]\[root]\Windows\ServiceProfiles\LocalService\NTUSER.DAT{53b39e88-18c4-11ea-a811-000d3aa4692b}.TM.blf
7a5d61030f460f1bf46add42bd6d184f 9c758375a0f609f290f96b95ec0b9af7bc9b0a22 [NTFS]\[root]\Windows\ServiceProfiles\LocalService\NTUSER.DAT.LOG2
3f28bd4f93fc5a5966255efda84c00dd 17d5a448b0f31b88f52e02bafc7d3d7011054f09 [NTFS]\[root]\Windows\ServiceProfiles\LocalService\NTUSER.DAT.LOG1
8275a08783966e8d04a48159da5194fe 35b407717fc428511071b345a2cfad9f7606192d [NTFS]\[root]\Windows\ServiceProfiles\LocalService\NTUSER.DAT
f98f8310f1636ce06610231f8a262f8c a8a91bc7287094aee3399bad3f304cc0b71a47e6 [NTFS]\[root]\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Crypto\Keys\de7cf8a7901d2ad13e5c67c29e5d1662_c0849ae1-3e4e-4e45-b764-eea6b231d369
72e5cddeed630f9446c3249f859c51e0 8d7604d6f9466701b8ed531abeb383941b5c975a [NTFS]\[root]\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\$I30
feb01db6621ace0f900557a10ddd5f3c b495975055fea7082b3baf675d2104d6fb45f74e [NTFS]\[root]\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\$I30
2977b2f2121bf73e7a6fc814b57d9ed3 6c79add07870f491b342808315e3c7d74e873259 [NTFS]\[root]\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk