Question:
What processes did you (the investigator) use to successfully examine the entire contents of each file?
Answer: Scheduled visits.exe - misrepresented and password protected/Restored
Original file extension "zip" was replaced by "exe" for both the Long File Name and DOS legal name (8+3). -Examined starting cluster for signature and found "PK", which is the signature for a zip file. Location = Cluster 73, Sector, Offsets 0 and 1 -In the root directory, "exe" was replaced with "zip" for both the Long File Name and DOS legal name (8+3)
File size was changed from "2420" bytes to "1000" bytes. -Identified total number of required clusters for this file to be 5. Multiplied 5 * 512 to come up with the file size of 2560 -Changed file size "1000" to "2560" in the root directory
Zipped Excel spreadsheet was password protected.
-Opened zipped password protected file by entering the password "goodtimes" found earlier in the slack space of cover page.jpg
|