|
Question: What processes did you (the investigator) use to successfully examine the entire contents of each file?
Answer: simmy jungle.doc - deleted/Recovered
The "J" in Jimmy jungle.doc was replaced with hexadecimal value 5h "sigma". -Replaced the "s" with the letter "J"
In regards to the Long File Name, the File ID "LFN" was replaced with "Del LFN". -Did not change - no reason to do so.
In Regards to the DOS legal name (8+3 ), the File ID "File" was replaced with "Erased". -Replaced the "sigma" with the "J", "Erased" was replaced with automatically replaced with "File".
The pointers in FAT for each cluster starting at cluster 2 up to and including cluster 41 were zeroed (0) out. -Clusters 2 up to and including cluster 41 were re-chained in FAT
The data area was left untouched. -No modifications were performed in the data area of the
|
|