Missing Prefetch Fi...
 
Notifications
Clear all

Missing Prefetch Files

2 Posts
2 Users
0 Reactions
944 Views
(@mandjw)
Active Member
Joined: 17 years ago
Posts: 7
Topic starter   [#3523]

Hello,

Would it be uncharacteristic for there only to be one prefetch file on a system (win2003 server) that was build in mid 2008? The existing PF file is NTOSBOOT… I thought that they might have been deleted, but I looked in unallocated space. Also not sure how the command to delete the *.pf files wouldn't that application be listed in the prefetch? The only thing I can think of is that this system was remotely administered, the HTTP server, DNS etc were set to run of a scheduler…

Thoughts…

Thanks



   
Quote
keydet89
(@keydet89)
Famed Member
Joined: 22 years ago
Posts: 3568
 

As is stated and referenced in "Windows Forensic Analysis", Windows 2003 by default does NOT do application prefetching…therefore, you should NOT expect to see application prefetch files.

What you're seeing is normal for a Windows 2003 system.



   
ReplyQuote
Share: