Expunge a file so it cannot be retrieved under any circumstances. Is this possible?????

I have a work computer that is being taken away very unexpectedly.  I have one day to retrieve some files, but I'm afraid they've  already copied them and will use them against me to fire me.
a) The last time I got past my password and did anything with any files was a week ago.  I'm agraid they've copied all of my files.  There are some VERY sensitive personal correspondances on the computer that I never intended to be read.  How can I know, other than that the computer was turn on and they found they couldn't get past my password, that they didn't do anything else yesterday (like an administrator came in yesterday and copied them).
b) I know that it's real easy to get a file back once it's been deleted.  In fact, someone told me that even if you run a disc format, a file can be retrieved (which I find hard to believe!)  My problem is that I cannot reformat the entire drive.  But I do need to completely erase all traces of any files so that one of those file retrieving programs could never get them.  What can I do?  I'm almost thinking that if I put all of the files in a folder, then somehow corrupted them with a virus or something that would not spread to the rest of the computer, they'd be impossible to retrieve in their full capacity.   What are your suggestions?
ralphwalkerdjAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

aissimCommented:
There are programs on the Internet that help permanently delete data from disks.

I would start by gathering & deleting all the personal data from your computer. At this point the files are deleted and the disk space is marked as 'free' to the system; but the data is still recoverable until the system actually needs that space and overwrites the old data.

This is where a program like KillDisk (for example) comes in handy:
http://www.killdisk.com/

It will wipe out all that unused space on a disk that is marked as free, leaving all other files/folders intact, and your original/personal data will be purged forever.
0
war1Commented:
Hello ralphwalkerdj,

Here is how to permanently delete files on hard drive
http://www.wikihow.com/Permanently-Remove-Files-from-Your-Hard-Drive

Sure Delete is free
http://www.pcworld.com/downloads/file/fid,22393/description.html?tk=nl_lg

Secure File Delete is free
http://www.snapfiles.com/Freeware/security/fwerase.html



Hope this helps!
war1
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
ralphwalkerdjAuthor Commented:
Thank you both, but you did not address this question:  how do I know if the computer has been "entered" within the past 24 hours?
0
The Ultimate Tool Kit for Technolgy Solution Provi

Broken down into practical pointers and step-by-step instructions, the IT Service Excellence Tool Kit delivers expert advice for technology solution providers. Get your free copy for valuable how-to assets including sample agreements, checklists, flowcharts, and more!

aissimCommented:
To the best of my knowledge you won't unless you already had some sort of monitoring/auditing in place.
You could use event viewer to sift through recent Security Logs....a tedious task that might indicate whether an Administrator was on your machine or not (either locally or via a share), but you won't know what (if any) files were copied.
0
war1Commented:
You need to look at the Event logs to see the activity on your computer.
support.microsoft.com/kb/308427
0
ralphwalkerdjAuthor Commented:
I don't care about that.  I know the computer was turned on, because they called me and asked me for my pass word.  What I want to know is if they got one of their geeks who was able to somehow bypass it and get into Windows.  Wouldn't there be  some log that shows that?
0
aissimCommented:
You'll probably want to check the Security log for Event 528 (successfull logon) - it would also show that your username was used.
0
ralphwalkerdjAuthor Commented:
Thank you very much.  There's no way they'd be able get to my password unless it was hacked.  That aside, can you please walk me thru checking how to do Security Log for Event 528?  This will partially answer my question.
0
aissimCommented:
Go to Control Panel | Administrative Tools | Event Viewer - once the viewer opens switch to the Security log along the left-hand side. In the resultant pane to the right you'll see all the security events.

Click the column header named 'Events' and it will sort everything by event number (so all the 528's will be grouped together); then you can find recent Logons that have been logged.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Outlook

From novice to tech pro — start learning today.