Solved

Trace Documents being moved from Pc to Flashdrive

Posted on 2014-12-11
6
149 Views
Last Modified: 2014-12-17
I have a new client that just terminated an employee. Right after that event, they checked the employee's Pc and found company documents missing from his stand alone peer to peer Pc. They never took any backups.

I installed Recuva and ran a full system scan for deleted files. The only files found were from a few months ago and there were only a few files per day deleted at that time. Nothing that would point to a mass deletion which is what I was looking for.
https://www.piriform.com/recuva
 
I suspect he moved all documents to a USB flash drive and took it with him.

Is there any way to track this down in Windows Logs?
0
Comment
Question by:Tony Giangreco
6 Comments
 
LVL 54

Accepted Solution

by:
McKnife earned 167 total points
ID: 40495073
No, there isn't. This would require settings for file auditing in place already before the copying.
0
 
LVL 25

Author Comment

by:Tony Giangreco
ID: 40495090
That's what I expected. No surprise. Just another instance if the customer not being proactive!
0
 
LVL 20

Assisted Solution

by:marsilies
marsilies earned 167 total points
ID: 40495152
"Moving" a file to a different drive is basically just a copy + delete function. First the OS copies the file to the destination, then deletes it from the source location. So undelete programs will recover "moved" files, assuming they haven't been overwritten.

You may want to try "Previous Versions" built into Windows 7 to recover the files. See instructions here:
http://www.howtogeek.com/56891/use-windows-7s-previous-versions-to-go-back-in-time-and-save-your-files/

Another possibility is that they were moved elsewhere on the same drive and/or hidden. They wouldn't show up as deleted then. You can use this tool to look for hidden files:
http://securityxploded.com/hidden-file-finder.php

For moved files, search the whole drive:
http://www.ehow.com/how_5880516_file-moved.html


Other possibilities are that the files were never saved on the PC's drive: the user may have created and kept everything on a USB drive in order to work on the files at home.  Or, if the user was malicious, used a file wiping program to "shred" or overwrite the files on the disk, making undelete impossible.
0
Guide to Performance: Optimization & Monitoring

Nowadays, monitoring is a mixture of tools, systems, and codes—making it a very complex process. And with this complexity, comes variables for failure. Get DZone’s new Guide to Performance to learn how to proactively find these variables and solve them before a disruption occurs.

 
LVL 80

Assisted Solution

by:David Johnson, CD, MVP
David Johnson, CD, MVP earned 166 total points
ID: 40495308
Good reasoning for using a domain.. during the termination interview the user account is disabled in AD
0
 
LVL 25

Author Comment

by:Tony Giangreco
ID: 40495313
I agree with the comments. I'll try those tools Saturday morning when I'm there.
0
 
LVL 25

Author Closing Comment

by:Tony Giangreco
ID: 40505924
Thanks for confirming my expectations on this one.
0

Featured Post

On Demand Webinar - Networking for the Cloud Era

This webinar discusses:
-Common barriers companies experience when moving to the cloud
-How SD-WAN changes the way we look at networks
-Best practices customers should employ moving forward with cloud migration
-What happens behind the scenes of SteelConnect’s one-click button

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

You may have a outside contractor who comes in once a week or seasonal to do some work in your office but you only want to give him access to the programs and files he needs and keep privet all other documents and programs, can you do this on a loca…
In this article we will learn how to backup a VMware farm using Nakivo Backup & Replication. In this tutorial we will install the software on a Windows 2012 R2 Server.
This tutorial will walk an individual through the process of installing the necessary services and then configuring a Windows Server 2012 system as an iSCSI target. To install the necessary roles, go to Server Manager, and select Add Roles and Featu…
This Micro Tutorial will give you a introduction in two parts how to utilize Windows Live Movie Maker to its maximum editing capability. This will be demonstrated using Windows Live Movie Maker on Windows 7 operating system.

679 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question