EncryptedRegView is a free tool which finds, decrypts and displays Registry data

Costea Lestoc By: Costea Lestoc
2 minute read

Home » News » EncryptedRegView is a free tool which finds, decrypts and displays Registry data

Not long ago NirSoft released a free tool named EncryptedRegView, which helps you find, decrypt and display the data in the Registry which is protected by the DPAPI encryption system by Windows. This scheme is not that often used, not even by the products owned by Microsoft, but this program is still able to find details from Microsoft Edge, passwords in Outlook and other interesting things on a PC.

It is really easy to use and to understand. It is recommended that you run it as an administrator. Click OK when the opening dialog box appears and see how  the program will scan your Registry. It will show you every item protected by DPAPI that can be found on the machine, having columns for hash and encryption values, Registry path, decrypted and original values and many others. However, if you’re just a regular user, it won’t mean much to you. You will just see a path there similar to HKEY_CURRENT_USER\SOFTWARE\Microsoft\IdentityCRL\Immersive\production\Token\{60782261-81D18-4323-9C64-10DE93176363}, for instance, and nothing else.

Even so, there are other things that might seem interesting to you, such as the fact that a test system can have various value names “POP3 Password”. This is in fact an actual email address shown as “Decrypted Value”. Each has a path in Registry and it includes Microsoft\Office\16.0\Outlook\Profiles, which shows for sure that what you’re seeing is an Outlook password.

Of course, this is useful, but the program doesn’t tell you exactly which password belongs to what Outlook account, so you have to further investigate the profile path found in Registry if you want to find out that.

Thankfully, there are lots of other things you can do and explore the program. You can save the items you want as a html report, text or csv if you want to analyze them later on. There is also the option of running an advanced search, which lets you scan external HDD.



Next up

How to fix HP HIDClass error 0x800703e3 on Windows 10

Madeleine Dean By: Madeleine Dean
2 minute read

If you’re trying to install the latest HP updates on your Windows 10 computer but error code 0x800703e3 keeps on popping up, you’ve come to the […]

Continue Reading

6 WordPress hosting services for businesses to boost your profit

Vladimir Popescu avatar. By: Vladimir Popescu
Less than a 1 minute read

All the websites on the Internet are operated from a server. WordPress was launched in 2003 as a spin-off of a blogging application known as B2. […]

Continue Reading

Windows 10 v1809 is now available as automatic download

Rabia Noureen avatar. By: Rabia Noureen
2 minute read

Microsoft started the New Year with important updates for all the Windows 10 versions and devices currently supported by the company. Starting mid-January, the Windows […]

Continue Reading