?
Solved

What happens to a file after it is moved?

Posted on 2009-07-11
5
Medium Priority
?
662 Views
Last Modified: 2012-05-07
I have a customer who MOVED her primary Quickbooks data file (x.QBW) file from her HDD to a Flash Drive. She thought she had just copied it, but instead she moved it. Then she took her flash drive home and attempted to transfer the .QBW over the Internet. She did not know what she was doing and that did not work for her. She then accidentally deleted the .QBW file from her flash drive, thinking that the original was still on her HDD. But Nooooo!

I am using EnCASE in an effort to recover the .QBW file. While I am not yet certified, I have passed the written EnCE certification and I am now waiting for the practical to arrive via UPS. My questions are:

1. What does Windows do when it moves a file? Does it change the file marker to hex e5, just like a deleted file? Or, does it simply remove the allocation marker all together and make the area available for over write? Or, what?

2. What would be the best way to attack this with EnCASE? I have her HDD and her flash drive in my lab so access is not a problem.

3. I THINK the old .QBW file will be found in the Unallocated Clusters on the HDD, but I am not sure. Is it better to attack the HDD first, or the flash drive?

Thank you very much.
0
Comment
Question by:SMPC
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
5 Comments
 
LVL 26

Accepted Solution

by:
akahan earned 2000 total points
ID: 24831613
Moving will have the same effect as deleting.  

You're trying to kill a mouse with a shotgun.  EnCASE is not the appropriate tool for this job.  You could use a simple file recovery program like Recuva to do what you're doing.  There's no harm in using Recuva first (and then graduating to EnCASE if Recuva doesn't do the job), because using Recuva won't change anything on the disk or the flash drive if it's unsuccessful.  I think you're better off going after the flash drive first, just because it's smaller and it'll be quicker.

Obviously, you don't want to install your file recovery software onto the hard drive (or the flash drive); you would install it on some other drive, and then, from there, try to recover the lost data on the hard drive and/or flash drive.

0
 
LVL 1

Author Comment

by:SMPC
ID: 24832040
Of course I know that, but you could not know that I knew that. I was actually practicing for my EnCase practical exam to see what questions came up and this one did. Yes, we have Recuva at the office. It works well and I was going to use it tonight. Thank you.
0
 
LVL 23

Expert Comment

by:Danny Child
ID: 24832175
A move is 2 processes.  A Copy, followed by a Delete.  
0
 
LVL 1

Author Comment

by:SMPC
ID: 24832646
Very good DanCh99! Thnak you for the insight.
0
 
LVL 1

Author Closing Comment

by:SMPC
ID: 31602455
Got tired of messing about with EnCase and used Recuva to get the file in about 5 minutes. Now that I know how it works it does not seem like magic anymore, but, it is one hell of a time saver! Especially since it is Freeware. Still, anyone who uses it like I do should give a donation so I gave another one tonight. Worth it to me and WELL worth it to the customer.
0

Featured Post

Ransomware-A Revenue Bonanza for Service Providers

Ransomware – malware that gets on your customers’ computers, encrypts their data, and extorts a hefty ransom for the decryption keys – is a surging new threat.  The purpose of this eBook is to educate the reader about ransomware attacks.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If your system is showing symptoms of browser hijacks or 'google search redirects' check out my other article (http://rdsrc.us/u3GP7A) first and run the tool TDSSKiller (http://rdsrc.us/GDBBs4) to get rid of the infection. Once done, and if the …
The foremost challenge encountered by an investigator at the very beginning of a forensics investigation is, accessing a file/data to read/view its contents. Owing to the fact, a platform is necessary for both; opening as well as examining any file.…
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…
In this video, Percona Solutions Engineer Barrett Chambers discusses some of the basic syntax differences between MySQL and MongoDB. To learn more check out our webinar on MongoDB administration for MySQL DBA: https://www.percona.com/resources/we…
Suggested Courses

800 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question