On a Vista box I am looking at there is a helpfully named folder entitled Local Search History at the path
C\Users\{account name}
Within this folder are five files on the box I am looking at
- google%2Emaps.w
- google%2Eweb.w
- google%2Egroups.w
- google%2Eimages.w
- google%2Enews.w
Notably testing using IE7 with a separate Google Toolbar installed running in Vista revealed that searches made using
- Instant search box (set to Google)
- Google Toolbar
- Google webpage
I have found traces of these files in unallocated clusters also.
The google toolbar has a Clear History option and as far as I can tell this modifies the MFT for the file resulting in Encase reporting an Empty File. In testing I carried out searches that caused google%2Eweb.w to extend over three clusters as follows
I cleared search history and via disk view in Encase viewed each cluster. In cluster 1447520 I found remnants of google%2Eweb.w but after a few minutes this cluster was zeroed out (during this test I had pointed Encase at my local drive). So at this point I am not sure why I have found traces in unallocated.
2 comments:
Thanks! You just provided me with a ton of good information!
regards,
mitch
Thank you very much.You just have jailed one pedophile.
Best regards from Banja Luka.
Bojan
Post a Comment