Hello again,
So, now that I am using the right profile, the plug ins seem to work.
My goal is recovering unsaved notepad files from hibernation. I have a hiberfil.sys from a
Win 7 SP1 64 bit system.
My next step seemed to be using pslist to get the PIDs, and putting those into one of the
built in plugins.
I've tried dumpfiles, vaddump, memdump, and some others.
It looks like I should be able to piece something together between the results of
dumpfiles with a PID switch, and of vaddump with a PID switch. I haven't figured that
out yet. I'm wondering if there is a more specific switch. They both seem to produce
a lot more files than I need.
Is there a better way to use volatility's built in tools to pull out files from
notepad?
Is there an add on that I can download which will pull out something more quickly and
cleanly?
Thanks,
andybellman(a)outlook.com