I am trying to locate evidence of what documents a user printed (Windows XP, SP2) and was looking in the print spooler directory at
c\windows\system32\spool\printers
for .shd or .spl files. I understand Windows deletes these files after a successful print but I've checked 4 hard drives now and have not found a single file (I'm searching allocated and unallocated/deleted files, of course). If the printer is networked, I'm pretty sure the file is spooled on the file/print server however I thought at least 1 of the drives printed locally.
Am I looking in the wrong place? Do I have the directories/process incorrect? Or perhaps everyone is just using network printers these days. Thanks for any direction.
"I understand Windows deletes these files after a successful print but I've checked 4 hard drives now and have not found a single file…"
Sounds like you're on the right track…
But on an 80GB+ hard drive, I can't imagine Windows would overwrite the deleted print files. Shouldn't there be a bunch of "deleted but recoverable" files? Do people come across many in their investigations? Thanks.
Are you looking for them in unallocated space in or in the spool\printers directory? If it's in unallocated, then you could try a search for EMF. If you have EnCase, then I have a grep search from my CF 2 book you could try too (or use the EnScript program if you have it).
Tom
try to check registry, maybe default spool directory place was changed
But on an 80GB+ hard drive, I can't imagine Windows would overwrite the deleted print files. Shouldn't there be a bunch of "deleted but recoverable" files? Do people come across many in their investigations? Thanks.
Windows systems, and XP in particular, have their own anti-forensics techniques built into the operating system…something I've blogged about and mentioned in my books.
I have examinations where finding indications of files being printed was important, and I found nothing with respect to the print spools, and instead relied on metadata from MS Word and Excel docs…
Oh no, you mentioned your book! Didn't you know that's not allowed on here? 😉