Mastering Windows Network Forensics and Investigation, 2nd Edition
by Steven Anson, Steve Bunting, Ryan Johnson, Scott Pearson
Windows XP Restore Point Content
Now that we’ve covered all the details of restore point creation, let’s get to the good stuff, which is the content of restore points. In essence, an XP restore point makes copies of important system and program files that were added since the last restore point. These files, except for registry hive files, are stored in the root of the RP## folder; however, they are not easily recognized because their names have been changed. These files are renamed according to the following naming convention: A#######.ext, where the pound signs are random numbers and the file extension is the same as that of the original file.
Logic tells us that Windows must have a means of mapping these new filenames to the original filenames ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access