to where does a fla...
 
Notifications
Clear all

to where does a flash drive leave traces in windows 7?

4 Posts
3 Users
0 Reactions
596 Views
nesrin
(@nesrin)
Active Member
Joined: 15 years ago
Posts: 14
Topic starter  

Hello
I need some information about registry structure of windows 7. When i attach a usb flash drive to a pc installed windows 7, flash drive leaves some traces. could you tell me Which traces are they and their places?

Any info., book, article etc. will be very helpful.
Thanks.


   
Quote
(@joe_bowman)
Active Member
Joined: 16 years ago
Posts: 11
 

Windows Forensic Analysis by Harlan Carvey pp.155-159 has some good info - I presume this is followed up to at least some extent in his new book Windows Registry Analysis, that I have not had the pleasure of reading yet.

There is however plenty of info if you search for 'USBSTOR' (this is the name of one of the keys in the SYSTEM hive that record information about removable devices), I am sure there is plenty written on the subject.

The program USBDeview is good, as is RegRipper (again, written by Harlan) when you run the SOFTWARE plugin again the SOFTWARE hive file.

Hope that helps!

Regards,

Joe


   
ReplyQuote
(@patrick4n6)
Honorable Member
Joined: 16 years ago
Posts: 650
 

Rob Lee from Sans did a great writeup about this a year or 2 back. I was working up my own materials on this at the time, but after Rob put his up, I just started linking to him. LMGTFY

http//computer-forensics.sans.org/blog/2009/09/09/computer-forensic-guide-to-profiling-usb-thumbdrives-on-win7-vista-and-xp

http//blogs.sans.org/computer-forensics/files/2009/09/USB_Drive_Enclosure-Guide.pdf


   
ReplyQuote
nesrin
(@nesrin)
Active Member
Joined: 15 years ago
Posts: 14
Topic starter  

Thanks everybody

All info are very good. I will read all of them.


   
ReplyQuote
Share: