USB/CD Files copied...
 
Notifications
Clear all

USB/CD Files copied logs

10 Posts
6 Users
0 Reactions
1,795 Views
jimmy
(@jimmy)
Eminent Member
Joined: 17 years ago
Posts: 47
Topic starter  

Need some opinion on if there are any methods of finding out what files have been copied to a USB or CD.

I short any logs maintained for files copied to a usb drive or cd rom


   
Quote
(@jonathan)
Prominent Member
Joined: 20 years ago
Posts: 878
 

On a Windows system? XP?

A default install of XP does not store an historical log of files which a user has copied. lnk files may tell you if files have been accessed on a USB or CD drive though.


   
ReplyQuote
(@seanmcl)
Honorable Member
Joined: 19 years ago
Posts: 700
 

As noted, above, the default for drag and drop copy to CD using Microsoft Windows XP embedded cd burning does not not leave a log file, however, there may be evidence of the last burn recoverable from the CD Burning folder located in the user's profile (or in the Recycle Bin).

In addition, programs like Nero and Roxio do create log files. If there is evidence that one of these was used, I'd look more carefully.


   
ReplyQuote
FFD9
 FFD9
(@ffd9)
Active Member
Joined: 17 years ago
Posts: 8
 

As already noted .lnk files can tie in movements to USBs and CDs as they will give you a drive letter plus file name. Worth checking the Recent folder. Examining the appropriate Registry keys will also help verify your findings. Also usefully gives you the make and MAC addresses of any USB devices used (in most cases), plus dates, times etc.


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

Like seanmcl says, check out the CD Burning folder on XP
http//support.microsoft.com/kb/279157

Also, do what seanmcl says…check to see if there's any other CD/DVD burning software on the system, such as Sonic or Nero, and see what kind of logs or Registry keys may be accessible.

> Also usefully gives you the make and MAC addresses of any USB devices
> used (in most cases), plus dates, times etc.

USB devices don't have "MAC addresses".


   
ReplyQuote
(@ci2019)
Trusted Member
Joined: 19 years ago
Posts: 53
 

Like seanmcl says, check out the CD Burning folder on XP
http//support.microsoft.com/kb/279157

Also, do what seanmcl says…check to see if there's any other CD/DVD burning software on the system, such as Sonic or Nero, and see what kind of logs or Registry keys may be accessible.

> Also usefully gives you the make and MAC addresses of any USB devices
> used (in most cases), plus dates, times etc.

USB devices don't have "MAC addresses".

Unless it's a USB Network Card D .


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

Unless it's a USB Network Card D .

You're correct, but that doesn't fit the context of the conversation…


   
ReplyQuote
(@ci2019)
Trusted Member
Joined: 19 years ago
Posts: 53
 

Unless it's a USB Network Card D .

You're correct, but that doesn't fit the context of the conversation…

I know, was just razzin ya.


   
ReplyQuote
FFD9
 FFD9
(@ffd9)
Active Member
Joined: 17 years ago
Posts: 8
 

OK. Bad use of term.

I was, as I'm sure most people realised, referring to a USB device's particular identification number (eg. thumb drive) located under Disk&Ven key.

Still, so long as you guys are having fun…


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

I was, as I'm sure most people realised, referring to a USB device's particular identification number (eg. thumb drive) located under Disk&Ven key.

Ah, okay…the author of "Windows Forensic Analysis" refers to that value as the devices "unique identifier", and in many cases (such as when the second character is NOT a '&'), it is also the device's serial number, which can be found in the device's device descriptor (part of the firmware, not the memory area, of the device itself).

Referring to it as the "MAC address" can be confusing…

HTH,

h


   
ReplyQuote
Share: