Ran across another forensics paper that may be of use at some point:

PDF: Windows ShellBag Forensics in Depth