Solved

Detecting if someone used a disk wipe / secure erase program

Posted on 2008-09-30
4
429 Views
Last Modified: 2012-06-27
I was recently on a tech call to try and recover some missing files from a small office that had a laptop returned to them from an employee that recently left, but apparently deleted all of their work files. I was unable to find any ms office documents and was wondering if there were any programs that can detect if a disk wiper was used? As this is a small office, they won't be sending the drive away for any expensive file recovery services (they'll live without the files), but they were curious to see if the employee had used a disk wipe program.

Any ideas?
0
Comment
Question by:mrbayne
  • 2
4 Comments
 
LVL 95

Expert Comment

by:Lee W, MVP
ID: 22610024
I can not imagine a situation where you would know unless you could find the actual disk wipe program installed.  
0
 
LVL 95

Expert Comment

by:Lee W, MVP
ID: 22610028
I suppose you can "guess" based on the configuration of the laptop when it was returned... but there are plenty of programs that can do a "file wipe"
0
 
LVL 38

Accepted Solution

by:
Rich Rumble earned 125 total points
ID: 22627597
No, most wipe utilities do a combination of things, all 1's all 0's alternating 1's and 0's and random... so you couldn't tell one from the other. Windows also has it's own wipe utility, cipher.exe which will over-write once with random data. You can run it as much as you like to get multiple wipes. Doesn't matter if they did really, you could never actually tell, maybe they just hit the delete button, and then defrag'd the HD, that would likely over-write the empty places those files used to be, especially if the HD was very fragmented. You can run recovery software, but you should never boot or install programs to the drive you want to recover data from, things will get overwritten that way. Take the HD out, use something like: http://www.newegg.com/Product/Product.aspx?Item=N82E16812119152 that adapter to read the HD. use a program like: http://tokiwa.qee.jp/EN/dr.html to scan the HD to see if you can recover the data.
Again, unless as stated above, you find the utility they used using software like I linked to, you will never know if they used a utility or if they simply hit shift+delete (by passes recycle bin) and then defragged the HD.
-rich
0
 
LVL 1

Expert Comment

by:Brese
ID: 22663427
Although you could use a tool like FTK, it appears you are looking for a quick fix. I would suggest removing the drive, loading it onto another machine as an external drive, then run a tool like PC Inspector File Recovery. That app in particular can recover "lost files" and you can see deleted applications.

IF they used a wipe program that they installed, like cCleaner for example, they had to uninstall it and therefore couldn't wipe it, which would leave it potentially available for recovery.

You could perform this inside an hour and get an answer to your client.
0

Featured Post

Why You Should Analyze Threat Actor TTPs

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

Join & Write a Comment

Solid State (Hard) Drives aka SSD began to evolve in the computer industry recently. As the name suggests, there are no moving parts in the drives. The drive uses microchip memory store the data, as opposed to the spinning disks of a traditional HDD…
The foremost challenge encountered by an investigator at the very beginning of a forensics investigation is, accessing a file/data to read/view its contents. Owing to the fact, a platform is necessary for both; opening as well as examining any file.…
This video Micro Tutorial explains how to clone a hard drive using a commercial software product for Windows systems called Casper from Future Systems Solutions (FSS). Cloning makes an exact, complete copy of one hard disk drive (HDD) onto another d…
You have products, that come in variants and want to set different prices for them? Watch this micro tutorial that describes how to configure prices for Magento super attributes. Assigning simple products to configurable: We assigned simple products…

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now