Volume Shadow Recov...
 
Notifications
Clear all

Volume Shadow Recovery?? -Vista

4 Posts
3 Users
0 Reactions
466 Views
rjpear
(@rjpear)
Trusted Member
Joined: 19 years ago
Posts: 97
Topic starter  

Hi Folks.
I am working a Vista Home Premium (HP make) laptop..and I am interested is determining if there is Gold in the VSS Stores. I have attempted a VMWare boot of the image file (DD) with only a Blue Screen/reboot to show for it… and I have hooked up the orignal HD to a Writeblocker and plugged it into a Vista Ultimate box. but ShadowExplorer (www.shadowexplorer.com) doesn't see (or want to see) the External Drive.. I'm not sure if the VSS Service will work on external drives either…
So two questions… is there an easy way to determine in a Forensic tool (EnCase etc.) if there are VSS Copies present…or how much data is VSS'ed.. AND if there is ..how is it possible to examine them without booting original media.. and assume I don't have an extra 140 gig Toshiba Laptop drive laying around to duplicate the original… 😉

Thanks for your time!!

Rob


   
Quote
JonN
 JonN
(@jonn)
Trusted Member
Joined: 20 years ago
Posts: 73
 

I found some details about VSS here

http//www.forensickb.com/search?updated-max=2008-01-25T15%3A59%3A00-08%3A00&max-results=20

Not sure if that answers your question.

We have started finding loads of stuff, images etc, in System Volume Information, which from the small amount of work I have done on it, can be apportioned to VSS

Hope this helps


   
ReplyQuote
rjpear
(@rjpear)
Trusted Member
Joined: 19 years ago
Posts: 97
Topic starter  

Thanks… From what I have gathered..If you quickly looks at the "System Volume Information" folder you can tell if VSS is on and approx how much stuff has been copied/backed up. I started VMWARE stuff and all the tricks only to determine my drive did not have VSS turned on!! (heh!)


   
ReplyQuote
(@vulcan)
Active Member
Joined: 17 years ago
Posts: 6
 

There is a free tool called Shadow Copy Explorer that allows you to view the contents of the Shadow Copies.

You can find it here..

http//www.shadowexplorer.com/


   
ReplyQuote
Share: