Notifications
Clear all

Vista USBSTOR

4 Posts
4 Users
0 Reactions
456 Views
(@hash1980)
New Member
Joined: 18 years ago
Posts: 4
Topic starter  

I am working on a case where the operating system is Vista.
I'm trying to establish what USB devices were associated/plugged into the machine.

Once in the registry-system hive I have come across 1-19 control sets, hash anyone else come across this??

Below are details about the OS.

Product Name Windows Vista (TM) Business
Current Version 6.0
System Root C\Windows
Current Build Number 6001
Path Name C\Windows
Last Service Pack Service Pack 1
Install Date 13/08/09 122426
Last Shutdown Time 24/11/09 105544


   
Quote
(@funkygeek)
Active Member
Joined: 16 years ago
Posts: 6
 

hi, check out this website and it will tell you where to find out the usb drives that have been installed.
http//www.irongeek.com/i.php?page=security/windows-forensics-registry-and-file-system-spots#List%20of%20installed%20USB%20storage%20devices


   
ReplyQuote
binarybod
(@binarybod)
Reputable Member
Joined: 17 years ago
Posts: 272
 

Just the other day I came across a system with, wait for it… 52 Control Sets! Number 001 was the Current and the LastKnownGood was 052. All the intervening control sets were present.

I didn't have time to research why this situation should come about as it wasn't significant in this case but an interesting situation nonetheless.

Paul


   
ReplyQuote
(@douglasbrush)
Prominent Member
Joined: 16 years ago
Posts: 812
 

I have seen many as well - can't remember what the gold medal winning number has been.

Basic reference from MS on it for NT 3.x

http//support.microsoft.com/kb/100010


   
ReplyQuote
Share: