Registry Explorer is another free Windows Registry forensic tool by another famous digital forensic examiner: Eric Zimmerman. One of the extremely useful features of this tool is its capability to recover deleted records. And it's easier than you might imagine.
Recovering deleted Registry artifacts with Registry Explorer
Getting ready
Go to Eric's GitHub and click on the Registry Explorer download link. In our case, it's called Registry Explorer/RECmd Version 0.8.1.0. As at the time of writing, the most recent version of the tool is 0.8.1.0. Once RegistryExplorer_RECmd.zip is downloaded, unpack it and you are ready to go.