There are two different ways to manipulate the files of the registry keys. To access these files, you can use FTK Imager to locate and export these files.
The following screenshot shows a sample of this export process:
Alternatively, you can use the FTK to export the same files, as shown in the following screenshot. You can do this by right-clicking on the registry file and then clicking on Open in Registry Viewer.
The correct setting of the time zone is critical for proper analysis and generation of the results of the investigation process; incorrect settings may result in erroneous claims about those facts. When you select the correct Time Zone, all MAC time information is adjusted automatically as follows:
If you do not know the time zone of the seized computer, Registry Viewer can help you.
You can add the registry key, System, and locate the information at System\ControlSet001\Control\TimeZoneInformation
, as shown in the following screenshot...