<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-1746946614390371171.post8937912387744849517..comments</id><updated>2011-10-11T19:57:49.750-07:00</updated><category term='Cell Phones'/><category term='CRLF'/><category term='Wireless'/><category term='Vista'/><category term='Kindle'/><category term='CP'/><category term='File Signatures'/><category term='Hash'/><category term='SQL'/><category term='File System'/><category term='Email'/><category term='Patch'/><category term='Exclusion List'/><category term='dd'/><category term='SHA1'/><category term='MFT'/><category term='Photos'/><category term='Service Pack'/><category term='Keywords'/><category term='Import'/><category term='Encryption'/><category term='Firewall'/><category term='export'/><category term='EnScript Requests'/><category term='Install Date'/><category term='Timestamps'/><category term='Office Metadata'/><category term='NIST'/><category term='Password Bypass'/><category term='EnScript Tutorial'/><category term='MAC Address'/><category term='Domains'/><category term='GREP'/><category term='Thumbnails'/><category term='FTP'/><category term='USB History'/><category term='Virus'/><category term='Search Hits'/><category term='Bookmark'/><category term='MD5'/><category term='Winen'/><category term='LogFile'/><category term='EMLX'/><category term='Video'/><category term='Operating System'/><category term='Yahoo'/><category term='Duplicates'/><category term='Icons'/><category term='USNJRNL'/><category term='Restore Points'/><category term='Windows 7'/><category term='Base64'/><category term='Unallocated'/><category term='eBlaster'/><category term='Ghost'/><category term='XOR'/><category term='VSS'/><category term='Selected Text'/><category term='Network Information'/><category term='Forensic Practical'/><category term='Decode'/><category term='SANS'/><category term='Extensions'/><category term='Limewire'/><category term='Search'/><category term='Registry'/><category term='OSX'/><category term='IIS'/><category term='Unused Disk Space'/><category term='Event Logs'/><category term='Norton AV'/><category term='Foreign Language'/><category term='Lanman'/><category term='Redaction'/><category term='UserAssist'/><category term='ICAC'/><category term='LUHN'/><category term='Count'/><category term='Filename'/><category term='thumbcache'/><category term='ROT13'/><category term='HTML'/><category term='Incident Response'/><category term='Anti-Forensics'/><category term='Memory'/><category term='Internet History'/><category term='LEF'/><category term='File Types'/><category term='Triage'/><category term='SearchPak'/><category term='F-Response'/><category term='BitLocker'/><title type='text'>Comments on Computer Forensics, Malware Analysis &amp;amp; Digital Investigations: Forensic Practical Exercise #3</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.forensickb.com/feeds/8937912387744849517/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/8937912387744849517/comments/default'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3.html'/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>16</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-711686656724735008</id><published>2011-10-11T19:57:49.750-07:00</published><updated>2011-10-11T19:57:49.750-07:00</updated><title type='text'>I just downloaded.  Ill see if it works for me! i&amp;...</title><content type='html'>I just downloaded.  Ill see if it works for me! i&amp;#39;m excited to try it out!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/8937912387744849517/comments/default/711686656724735008'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/8937912387744849517/comments/default/711686656724735008'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3.html?showComment=1318388269750#c711686656724735008' title=''/><author><name>Chinese Kid</name><uri>http://www.chinawholesale.me</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-8937912387744849517' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/8937912387744849517' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1621904284'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-3180776072385046156</id><published>2011-07-12T08:29:00.759-07:00</published><updated>2011-07-12T08:29:00.759-07:00</updated><title type='text'>hi in have a macbook pro and in tried using spada ...</title><content type='html'>hi in have a macbook pro and in tried using spada for image but it gave an error 16, someone assist</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/8937912387744849517/comments/default/3180776072385046156'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/8937912387744849517/comments/default/3180776072385046156'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3.html?showComment=1310484540759#c3180776072385046156' title=''/><author><name>pekom</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-8937912387744849517' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/8937912387744849517' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-49534149'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-2502150648063835085</id><published>2011-01-18T05:55:52.776-08:00</published><updated>2011-01-18T05:55:52.776-08:00</updated><title type='text'>oh nice article i like it , i am a teacher of engl...</title><content type='html'>oh nice article i like it , i am a teacher of english as a second language and i do feel the content of your article so much.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/8937912387744849517/comments/default/2502150648063835085'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/8937912387744849517/comments/default/2502150648063835085'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3.html?showComment=1295358952776#c2502150648063835085' title=''/><author><name>satellitedirect review</name><uri>http://satellitedirectnetwork.com/</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-8937912387744849517' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/8937912387744849517' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1007518742'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-735536654614225827</id><published>2010-11-30T02:12:25.545-08:00</published><updated>2010-11-30T02:12:25.545-08:00</updated><title type='text'></title><content type='html'>This comment has been removed by a blog administrator.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/8937912387744849517/comments/default/735536654614225827'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/8937912387744849517/comments/default/735536654614225827'/><author><name>Silverdew</name><uri>http://www.blogger.com/profile/16752602650084239088</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-8937912387744849517' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/8937912387744849517' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.contentRemoved' value='true'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1080769187'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-8496539222761892910</id><published>2010-11-07T01:37:54.901-08:00</published><updated>2010-11-07T01:37:54.901-08:00</updated><title type='text'>I will provide an exact explanation of what was do...</title><content type='html'>I will provide an exact explanation of what was done to the device and file to those who submit answers so you can compare it with what you see.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/8937912387744849517/comments/default/8496539222761892910'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/8937912387744849517/comments/default/8496539222761892910'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3.html?showComment=1289122674901#c8496539222761892910' title=''/><author><name>rocket piano</name><uri>http://www.rocketpianoreviewscam.com</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-8937912387744849517' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/8937912387744849517' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-170392392'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-5506200357884213976</id><published>2010-01-29T11:57:08.093-08:00</published><updated>2010-01-29T11:57:08.093-08:00</updated><title type='text'></title><content type='html'>This comment has been removed by a blog administrator.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/8937912387744849517/comments/default/5506200357884213976'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/8937912387744849517/comments/default/5506200357884213976'/><author><name>electronics gadgets</name><uri>http://www.chinabuye.com/</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-8937912387744849517' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/8937912387744849517' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.contentRemoved' value='true'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-257838080'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-1161955739922243846</id><published>2010-01-07T17:41:12.537-08:00</published><updated>2010-01-07T17:41:12.537-08:00</updated><title type='text'>cdtdelta, 

The accountant had the flash drive for...</title><content type='html'>cdtdelta, &lt;br /&gt;&lt;br /&gt;The accountant had the flash drive for several minutes, and although I didn&amp;#39;t watch everything he did, he stated he could not read the drive and tried several things. I am not sure what he clicked but when he returned it to me he explained that he tried several times and could not read anything from the drive.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/8937912387744849517/comments/default/1161955739922243846'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/8937912387744849517/comments/default/1161955739922243846'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3.html?showComment=1262914872537#c1161955739922243846' title=''/><author><name>Mr. President</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-8937912387744849517' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/8937912387744849517' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-787613941'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-8471193919450538581</id><published>2010-01-07T15:59:48.701-08:00</published><updated>2010-01-07T15:59:48.701-08:00</updated><title type='text'>Okay so there&amp;#39;s that jpeg header.....er</title><content type='html'>Okay so there&amp;#39;s that jpeg header.....er</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/8937912387744849517/comments/default/8471193919450538581'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/8937912387744849517/comments/default/8471193919450538581'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3.html?showComment=1262908788701#c8471193919450538581' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-8937912387744849517' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/8937912387744849517' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-790705778'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-7525259528811826480</id><published>2010-01-07T14:50:58.704-08:00</published><updated>2010-01-07T14:50:58.704-08:00</updated><title type='text'>Mr President,
When the accountant received the mes...</title><content type='html'>Mr President,&lt;br /&gt;When the accountant received the message on his/her computer, did s/he recall clicking any buttons on the screen?  Or did s/he just remove the USB device and return it to you?&lt;br /&gt;&lt;br /&gt;Thank you.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/8937912387744849517/comments/default/7525259528811826480'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/8937912387744849517/comments/default/7525259528811826480'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3.html?showComment=1262904658704#c7525259528811826480' title=''/><author><name>cdtdelta</name><uri>http://cdtdelta.myopenid.com/</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/openid16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-8937912387744849517' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/8937912387744849517' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-872991623'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-3244407656331307439</id><published>2010-01-07T09:23:53.210-08:00</published><updated>2010-01-07T09:23:53.210-08:00</updated><title type='text'>One note: if you don&amp;#39;t have enCase, you can co...</title><content type='html'>One note: if you don&amp;#39;t have enCase, you can convert the image into a RAW image using the Sleuth Kit:&lt;br /&gt;&lt;br /&gt;img_cat -v -i ewf Forensic_Practical_3.E01 &amp;gt; dd.raw&lt;br /&gt;&lt;br /&gt;Just know that the resulting file will be ~4G, since it is the image of a 4G stick.&lt;br /&gt;&lt;br /&gt;Regards.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/8937912387744849517/comments/default/3244407656331307439'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/8937912387744849517/comments/default/3244407656331307439'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3.html?showComment=1262885033210#c3244407656331307439' title=''/><author><name>cdman83</name><uri>http://www.blogger.com/profile/05030326541176171725</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='30' src='http://4.bp.blogspot.com/_hrvCBhtWhJ4/SPBrNYhIpxI/AAAAAAAAAMc/ylcGT7ni7S4/S220/maci.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-8937912387744849517' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/8937912387744849517' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1728630828'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-7276793343966214237</id><published>2010-01-07T00:27:57.733-08:00</published><updated>2010-01-07T00:27:57.733-08:00</updated><title type='text'>In response to the questions directly above:

No, ...</title><content type='html'>In response to the questions directly above:&lt;br /&gt;&lt;br /&gt;No, there was no password set or any type of encryption used.&lt;br /&gt;&lt;br /&gt;I use a laptop and a desktop, both of which use Windows XP SP3&lt;br /&gt;&lt;br /&gt;The thumbdrive is fairly generic that I bought at bestbuy. It says &amp;quot;Transcend JF v30 / 4GB&amp;quot; on the outside. IT is primarily black with a green edge where the cap goes on.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/8937912387744849517/comments/default/7276793343966214237'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/8937912387744849517/comments/default/7276793343966214237'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3.html?showComment=1262852877733#c7276793343966214237' title=''/><author><name>Mr. President</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-8937912387744849517' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/8937912387744849517' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-787613941'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-20776314314393034</id><published>2010-01-06T14:38:21.307-08:00</published><updated>2010-01-06T14:38:21.307-08:00</updated><title type='text'>Mr President,

When you plugged this USB into your...</title><content type='html'>Mr President,&lt;br /&gt;&lt;br /&gt;When you plugged this USB into your computer, in order to access the file, did you first have to enter any password ?&lt;br /&gt;&lt;br /&gt;From what type of computer did you use to access this thumbdrive ? (Windows Vista, Windows 7, Windows XP ?) &lt;br /&gt;&lt;br /&gt;Do you recall the name of the manufacturer of the Thumbdrive ? The name is typically emblazoned on the thumbdrive itself...for example &amp;quot;SanDisk&amp;quot;?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/8937912387744849517/comments/default/20776314314393034'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/8937912387744849517/comments/default/20776314314393034'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3.html?showComment=1262817501307#c20776314314393034' title=''/><author><name>du212</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-8937912387744849517' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/8937912387744849517' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-264105675'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-4459614178877076613</id><published>2010-01-06T06:51:57.220-08:00</published><updated>2010-01-06T06:51:57.220-08:00</updated><title type='text'>Well, I don&amp;#39;t want to give away anything but I...</title><content type='html'>Well, I don&amp;#39;t want to give away anything but I just wanted to say thank you for posting this eventhough it is doing my head in! I&amp;#39;ve found some bits but am certainly no where near solving it.&lt;br /&gt;&lt;br /&gt;Thanks again - I&amp;#39;m looking forward to reading the answer!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/8937912387744849517/comments/default/4459614178877076613'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/8937912387744849517/comments/default/4459614178877076613'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3.html?showComment=1262789517220#c4459614178877076613' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-8937912387744849517' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/8937912387744849517' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1780720197'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-2556659826890445554</id><published>2010-01-05T01:21:28.769-08:00</published><updated>2010-01-05T01:21:28.769-08:00</updated><title type='text'>I received an email asking similar follow-up quest...</title><content type='html'>I received an email asking similar follow-up questions, which I have posted below, along with my answers.&lt;br /&gt;&lt;br /&gt;&amp;gt; How many partitions were on USB drive before it became unreadable? &lt;br /&gt;&lt;br /&gt;What do you mean by partitions? I dont know what that is ;) I would just plug it in and it would show up in &amp;quot;My Computer&amp;quot;&lt;br /&gt;&lt;br /&gt;&amp;gt; What type of file used to be on the USB drive before it was inaccessible?&lt;br /&gt;&amp;gt; (picture, document, etc)&lt;br /&gt;&lt;br /&gt;It was a picture file&lt;br /&gt;&lt;br /&gt;&amp;gt; When the accountant placed the USB drive in the Mac system did he get any&lt;br /&gt;&amp;gt; message on the screen such as “initialize, ignore or eject”?  Does the&lt;br /&gt;&amp;gt; president know if the accountant  pressed the initialize button?&lt;br /&gt;&lt;br /&gt;He did have problems with it and does remember a message popping up with an error, but cannot remember what it said, but it did have a red symbol on it.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/8937912387744849517/comments/default/2556659826890445554'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/8937912387744849517/comments/default/2556659826890445554'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3.html?showComment=1262683288769#c2556659826890445554' title=''/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-8937912387744849517' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/8937912387744849517' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1592171251'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-8926177290518876190</id><published>2010-01-04T11:29:07.414-08:00</published><updated>2010-01-04T11:29:07.414-08:00</updated><title type='text'>hmm good questions..

No back up, that&amp;#39;s why I...</title><content type='html'>hmm good questions..&lt;br /&gt;&lt;br /&gt;No back up, that&amp;#39;s why I am willing to pay you an absorbent amount of money to recover it ;)&lt;br /&gt;&lt;br /&gt;The name of the file was hd.jpg&lt;br /&gt;&lt;br /&gt;No other data other than a picture and the account number. No reference to a client name (it&amp;#39;s my offshore account in Belize).&lt;br /&gt;&lt;br /&gt;Yes he did state there was some type of error screen, but he could not access the drive and does not remember what it said, although he said it has some type of red warning symbol.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/8937912387744849517/comments/default/8926177290518876190'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/8937912387744849517/comments/default/8926177290518876190'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3.html?showComment=1262633347414#c8926177290518876190' title=''/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-8937912387744849517' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/8937912387744849517' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1592171251'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-4383114682204619740</id><published>2010-01-04T11:14:39.619-08:00</published><updated>2010-01-04T11:14:39.619-08:00</updated><title type='text'>El Presidente
Does the file reside on your primary...</title><content type='html'>El Presidente&lt;br /&gt;Does the file reside on your primary computer or another device that may have been backed up?&lt;br /&gt;&lt;br /&gt;Didn&amp;#39;t think so...&lt;br /&gt;&lt;br /&gt;What type of file contained the data?&lt;br /&gt;What was the name of the file?  If you&amp;#39;re not sure exactly, provide a guess as to what it may have been.&lt;br /&gt;What other data was in the file?  Did the account number reference a specific customer/entities name, etc.?&lt;br /&gt;Does the accountant recall receiving any errors or onscreen messages when plugging in the device?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/8937912387744849517/comments/default/4383114682204619740'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/8937912387744849517/comments/default/4383114682204619740'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3.html?showComment=1262632479619#c4383114682204619740' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-8937912387744849517' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/8937912387744849517' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-694455186'/></entry></feed>
