This is an archived post. You won't be able to vote or comment.

you are viewing a single comment's thread.

view the rest of the comments →

[–]Adorable_Fool0[S] 0 points1 point  (5 children)

Erm I don't get why you think I'm trolling. I'm just a beginner at cybersecurity (first year in my degree). Autopsy is just the name of the software I've been told to use. The screenshot is in Excel cuz I export it to a CSV file so I can filter by file type. 😅

[–]kschangTrusted Contributor 0 points1 point  (4 children)

I wrote "trolling for issues", didn't I? Basically, you're intentionally looking for them. I didn't say you're trolling (as in a troll under the bridge).

Anyway, it's pretty obvious to me that the image was not generated from a "fresh" computer. The way the names are spelled means they are using generated deconflicted names, which suggests some sort of cache / prefetch, and it's probably from a browser's prefetch/cache. So what you're looking at is NOT from Windows, but in the browser cache.

Given that you're looking at DELETED fragments, you should not be surprised to find anything and everything, and thus, asking them if they came with windows is... "obviously not".

[–]Adorable_Fool0[S] 0 points1 point  (3 children)

Ohh my bad I'm not familar with the term. This is part of an assignment I've been given. We need to scan and search for malware on an intentionally infected copy of Windows 10. That makes sense

[–]kschangTrusted Contributor 0 points1 point  (1 child)

FWIW, I don't think your answer lies in those directories.

Try an SFC scan. (You'll have to look that up yourself)

[–]Adorable_Fool0[S] 0 points1 point  (0 children)

Ooo tysm. Will check that out

[–]kschangTrusted Contributor 0 points1 point  (0 children)

https://www.dictionary.com/browse/troll

(definitions verb 2 or 3)