[Unknown]

Talk about your favorite PC games, Steam and building awesome custom rigs!

Moderator:Moderators

Post Reply
User avatar
SonyPortableizer
Portablizer
Posts:1325
Joined:Sun Jun 01, 2008 6:49 pm
Contact:
[Unknown]

Post by SonyPortableizer » Mon Dec 14, 2009 2:06 pm

[Unknown]
Last edited by SonyPortableizer on Fri Nov 14, 2014 12:31 am, edited 1 time in total.
Image

User avatar
gamemasterAS
Senior Member
Posts:3309
Joined:Thu Nov 24, 2005 10:30 pm
Steam ID:lolz1337face
Location:Ohio
Contact:

Re: Usb Drive Question

Post by gamemasterAS » Mon Dec 14, 2009 2:14 pm

Is this hypothetical or has it already occurred?
.

User avatar
SonyPortableizer
Portablizer
Posts:1325
Joined:Sun Jun 01, 2008 6:49 pm
Contact:

Re: Usb Drive Question

Post by SonyPortableizer » Mon Dec 14, 2009 2:30 pm

occured, and hypothetical incase it happens again.
SO its still important
Image

Harshboy
Portablizer
Posts:3610
Joined:Tue Oct 11, 2005 3:44 pm

Re: Usb Drive Question

Post by Harshboy » Mon Dec 14, 2009 6:41 pm

SonyPortableizer wrote:I own a PC
Is there a way to tell if someone has put in or used a usb drive on my computer?
EX. I leave my computer alone, someone pops in their USB Drive, saves a word document on my computer

I dont want answers like, well pay attention, use a password, etc.
Well, check for recently added hardware to see if any drivers were installed. If it was a different device than one that you have ever used, it would have had a driver installed so the device could work.

User avatar
nitro2k01
Posts:651
Joined:Tue Dec 19, 2006 12:41 pm

Re: Usb Drive Question

Post by nitro2k01 » Mon Dec 14, 2009 7:40 pm

Huhum! Why isn't this thread in the computer tech forum?

Anyway, here's how to do it.
Information about all drives that have ever been connected to the computer is available in this registry key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\USBSTOR (Start run > regedit)
However, this tells you nothing when the device was connected. To do that you need to check one of several registry keys or log files. Let's for example that you think the USB drive has never been connected to your computer before. If so, open C:\windows\setupapi.log (xp) or C:\windows\setupapi.dev.log (Vista)
Open it in for example notepad. The log file is written top to bottom so go ahead and press ctrl+end to go to the end of the file. Then press ctrl+F to summon the search box. Enter USBSTOR and choose direction: up. Click Find next and you'll hopefully see something like this:
Image

Scroll up to the first line above the search result that doesn't begin with a #. That's the date when that device was first installed. The picture above shows when I installed a USB CD-ROM drive a month ago.

You're also supposed to be able to see the last time a certain device was connected, (as opposed to first) but I can't figure that out now. Hopefully this will get you started at least.

Or refer to this information sheet, if you're a bad enough dude: http://blogs.sans.org/computer-forensic ... -Guide.pdf" onclick="window.open(this.href);return false;
My blog
ASM Retro <- Gameboy Classic Backlight

Being the sadistic bastard I am, I have covered Frog's left eye with a Santa hat.

Last edited by nitro2k01 tomorrow, 1:48 pm; edited 1 time in total

User avatar
gamemasterAS
Senior Member
Posts:3309
Joined:Thu Nov 24, 2005 10:30 pm
Steam ID:lolz1337face
Location:Ohio
Contact:

Re: Usb Drive Question

Post by gamemasterAS » Mon Dec 14, 2009 7:44 pm

Do you think they ran any programs from the flash drive? Lots that I have seen still leave some files.
.

User avatar
SonyPortableizer
Portablizer
Posts:1325
Joined:Sun Jun 01, 2008 6:49 pm
Contact:

Re: Usb Drive Question

Post by SonyPortableizer » Mon Dec 14, 2009 8:10 pm

thanks
Image

User avatar
MasterPrime
Posts:88
Joined:Sun Feb 17, 2008 9:53 pm

Re: Usb Drive Question

Post by MasterPrime » Sun Dec 20, 2009 8:11 pm

there's nitro2k01's method. effective.

There's the event viewer:
right click my computer
select manage
click event viewer

if the document was opened before it was copied it should be in your recent documents folder.
you might try the temp folder as well. that's always fun.

If you know specifically which document, right click on the sorting bars in the folder, select More, and check the box next to Date Accessed.

that's all the easy stuff I know off the top of my head. If I come across something else that's cool I'll post it.
Image

Post Reply