Recent folder - Evi...
 
Notifications
Clear all

Recent folder - Evidence wiping program

7 Posts
6 Users
0 Reactions
443 Views
pronie2121
(@pronie2121)
Estimable Member
Joined: 17 years ago
Posts: 117
Topic starter  

In your opinions I am looking at a Windows XP computer and in the users recent folder I have approx 22 files that all look like the following
ZZZZZZZZZZZZZZ ZZ ZZZZZZZZZZZZZZ

The last accessed times for these files begin at 124521 and go down sequentially for about 7 seconds. This is all after a program called Evidence Nuker was created in the program files folder 5 minutes prior to the last accessed times in the recent folder beginning. Would those ZZZZZZZZZZ indiciate a wipe by the evidence nuker program?


   
Quote
(@gmarshall139)
Reputable Member
Joined: 21 years ago
Posts: 378
 

That would be my guess. Set it up and see if it overwrites with "Z" by default.


   
ReplyQuote
(@rich2005)
Honorable Member
Joined: 19 years ago
Posts: 541
 

A very quick and dirty way to check this would be to power the image up in a virtual machine. Load a copy of your forensic software of choice into it, use the 'nuker' program on its current settings on any folder of your choice, and preview the the result in the forensic software, see if the artefacts mirror what you are seeing/expected.
So you can illustrate your point with the fact that "using this software in its current configuration, upon a folder or set of files, results in …….." and compare that with your recent items.
Rich


   
ReplyQuote
(@dksniper)
Eminent Member
Joined: 17 years ago
Posts: 25
 

Agree with Rich, works well.

A similar approach is a phantom device between the suspect drive and the original base unit and run the software accordingly. It is actually writing to the phantom device not the suspect drive but shows everything in a "live" environment.


   
ReplyQuote
pronie2121
(@pronie2121)
Estimable Member
Joined: 17 years ago
Posts: 117
Topic starter  

Thanks for the replies I am going to attempt this in a virtual environment.


   
ReplyQuote
iruiper
(@iruiper)
Estimable Member
Joined: 19 years ago
Posts: 145
 

You could also look for prefetch files for that application in the date/time you point out. That would be a strong argument.


   
ReplyQuote
RarelyVisits
(@rarelyvisits)
New Member
Joined: 16 years ago
Posts: 2
 

I have seen the ZZZZZZZZZZZZZZZZ pattern used by CCleaner when the secure delete option is selected.


   
ReplyQuote
Share: