| Windows 7: Privacy.. I forgot name of "file" that does not get wiped. |
10 Dec 2011
|
#1 | | |
Privacy.. I forgot name of "file" that does not get wiped. Hi guys. A conversation came up last night among my friends regarding Windows 7 (and Vista) and cleaning for security and privacy. There was a general consensus among the group that CCleaner (with CCenchancer) cleans everything. During this conversation I was reminded about some kind of "file" that does not get wiped by normal means. I remember reading that one would have to run a command window in order to properly wipe or reset this file -- that cleaners did not clean it nor did rebooting the pc reset the contents of this file. The way I remember it (although I had a poor understanding of it) this "file" was inherent in Windows and "recorded" browsing activity, program activity, and other things. I remember that it is something that can't be disabled, and so the best you could do was to "reset" its contents via command prompt window. It seemed to me like a pagefile type of thing, but it wasn't the pagefile and it wasn't hiberfile because those could be disabled. It wasn't index.dat either because it was something that cleaners didn't clean. I remember reading about this file on a Windows security website many years ago. The article was about law enforcement techniques and that they use this file because most people are too comfortable with ordinary cleaners and most people aren't aware of this file either. I wish I could remember more about it. The command to wipe this file was a very short command too. I'm searching all morning for any information and its driving me crazy because I am coming up empty. Any help would be appreciated. | My System Specs |
| OS Windows 7 Ultimate x64 |
10 Dec 2011
|
#2 | | Microsoft Windows 7 Home Premium 64-bit 7600 cornwall UK |
its possible its an index.dat file, Delete index.dat files | My System Specs | | System Manufacturer/Model Number Hewlett packard/p6512uk OS Microsoft Windows 7 Home Premium 64-bit 7600 CPU IIx4 amd athelon 635 processor Motherboard FOXCONN 2AA9 Memory 2x2gb Graphics Card ati radeon HD 5450 Sound Card (1) Realtek High Definition Audio (2) AMD High Definition Monitor(s) Displays samsung lcd tv 32" Screen Resolution 1360x 768 Keyboard wireless hp Mouse wireless Hp,optical PSU ? Cooling air! Hard Drives (1) WDC WD10 01FAES-60Z2A0 SATA Disk Device (2) Maxtor OneTouch USB Device (3) ST310003 33AS USB Device (4) WD My Book 1111 USB Device Internet Speed 1.10mb/s Antivirus MSE Browser Firefox |
10 Dec 2011
|
#3 | | Windows 7 Professional SP1 32-bit Fantasyland |
It might be the USN journal. It can be deleted with fsutil usn deletejournal /n X: but if you do this on the Windows system partition, it will immediately be recreated. | My System Specs | | System Manufacturer/Model Number Custom-built OS Windows 7 Professional SP1 32-bit CPU Intel Core 2 Duo E6600 2.4GHz, overclocked to 2.7GHz Motherboard Asus PL5D2 Memory 4GB DDR2-667 (4x1GB in dual-channel config) Graphics Card nVidia GeForce 9800 GT Sound Card Creative X-Fi XtremeMusic Monitor(s) Displays Acer Screen Resolution 1920x1200 (DVI) Keyboard Standard Mouse Microsoft wireless optical mouse PSU Antec TruePower 2.0 Case Cooler Master Centurion Cooling various fans Hard Drives OCZ SSD Vertex Plus 60GB SATA (Firmware 3.55), 64MB cache
Hitachi HD321KJ SATA, 320GB, 7200rpm, 16MB cache Internet Speed DSL; ~330KB/sec down, ~110KB/sec up Other Info Have a laptop too :) (Compaq CQ60 also with Win7 Pro SP1 32-bit)
Drives in both systems:
C: - Windows 7 + apps. Pagefile is fixed size and located at the very end of the partition.
D: - various temp files/cache for Firefox and apps/games.
E: - videos, music, misc. storage, torrent downloads, etc. |
10 Dec 2011
|
#4 | | Vista, Windows7, Mint Mate, Zorin, Windows 8 Florida in winter, Black Forest/Germany |
Maybe you were thinking about the shadowstorage. The command to delete is vssadmin delete shadows | My System Specs | | System Manufacturer/Model Number HP, Dell, Gateway, Toshiba - 4 laptops and 2 desktops OS Vista, Windows7, Mint Mate, Zorin, Windows 8 CPU from 1.6GHz Duo to i7 Monitor(s) Displays 2x HP w2207 Keyboard with trackball - no mices Mouse Trackball mice Hard Drives 5x HDD, 7x SSD, 12x Externals Internet Speed DSL 6000 |
11 Dec 2011
|
#5 | | |
There is a lot of information in $Logfile but it certainly doesn't record everything and although I haven't searched it cannot be deleted as far as I know. The single index.dat file that seems to hold most items is zeroed by CCleaner. | My System Specs | | System Manufacturer/Model Number Compaq desktop OS Windows 7 x64 SP1 CPU Athlon II x2 215 Memory 4.0 GB Graphics Card Onboard Sound Card Creative SB X-Fi Titanium HD (nice) Monitor(s) Displays 24" Dell LCD Screen Resolution 1900 x 1200 Keyboard USB Mouse USB PSU 430w Hard Drives 320 GB, 500 GB and 750 GB 7200 rpm Internet Speed approx 10 Mbps |
11 Dec 2011
|
#6 | | Windows 7 Home Premium x64 SP1 Bay Area Peninsula |
You say "It wasn't index.dat either because it was something that cleaners didn't clean". But it sure does sound like index.dat you are describing. Which CCleaner will delete BTW. You can also delete them manually:
Boot to Safe Mode With Command Prompt in an administrator account. In the command prompt type:
CD\
Enter
Type
del index.dat/s
Enter
Type
shutdown -r
Enter
The PC will restart
A Guy | My System Specs | | OS Windows 7 Home Premium x64 SP1 CPU INTEL Core i5-750 Quad-Core 3.37GHz Motherboard ASUS P7P55D Memory KINGSTON 4GB (2 x 2GB) HyperX PC3-12800 DDR3 1600MHz CL8 Graphics Card MSI N240GT-MD1G/D5 GeForce GT 240 1GB 128-bit GDDR5 Monitor(s) Displays Samsung SyncMaster B2430H 24" Screen Resolution 1920 x 1080 PSU ANTEC TruePower New TP-550, 80 PLUS, 550W Case ANTEC Three Hundred Illusion Cooling COOLER MASTER Hyper 212 Plus, 4 x 120mm 1 x 140mm Noctua's Hard Drives Intel X25M Gen2 80GB, SEAGATE 500GB Barracudaź 7200.12, SATA 3 Gb/s, 7200 RPM, 16MB cache Internet Speed 20 + Mbps Antivirus Avast Browser Opera |
11 Dec 2011
|
#7 | | |

Quote: Originally Posted by A Guy You say "It wasn't index.dat either because it was something that cleaners didn't clean". But it sure does sound like index.dat you are describing. Which CCleaner will delete BTW. You can also delete them manually:
Boot to Safe Mode With Command Prompt in an administrator account. In the command prompt type:
CD\
Enter
Type
del index.dat/s
Enter
Type
shutdown -r
Enter
The PC will restart
A Guy As I said the single instance of index.dat that seems to contain all the sensitive information is overwritten by zero's by CCleaner and not deleted, mine is about 8 MB. All the other instances of index.dat don't seem to contain anything or are deleted/erased. | My System Specs | | System Manufacturer/Model Number Compaq desktop OS Windows 7 x64 SP1 CPU Athlon II x2 215 Memory 4.0 GB Graphics Card Onboard Sound Card Creative SB X-Fi Titanium HD (nice) Monitor(s) Displays 24" Dell LCD Screen Resolution 1900 x 1200 Keyboard USB Mouse USB PSU 430w Hard Drives 320 GB, 500 GB and 750 GB 7200 rpm Internet Speed approx 10 Mbps Privacy.. I forgot name of "file" that does not get wiped. problems? All times are GMT -5. The time now is 09:12 AM. | |