Question: For each file, what processes were taken by the suspect to mask them from others?
Answer: simmy jungle.doc - deleted
The "J" in Jimmy jungle.doc was replaced with hexadecimal value 5h "s".
In regards to the Long File Name, the File ID "LFN" was replaced with "Del LFN".
In Regards to the DOS legal name (8+3), the File ID "File" was replaced with "Erased".
The pointers in FAT for each cluster starting at cluster 2 up to and including cluster 41 were zeroed (0) out.
|