Taking instructions now — the first conversation is freeExhibits posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
FDRForensic Data Recovery 0800 6890668 Price my job
FDR / What the evidence can show / Program execution and wiping tools

Prefetch · program execution · run count · wiping tools · CCleaner · secure overwrite

Program execution and wiping tools. Windows records what was run and when; that record includes the moment someone reached for a wiping tool.

Windows keeps several records of which programs have been run, chiefly Prefetch, a feature meant to speed up launching, which records each program's first and last run times and a run count, along with other execution artefacts. For most purposes this shows what software was used and when. In a dispute it does something more pointed: it records the installation and running of a cleaning or wiping tool, a program whose purpose is to delete files and overwrite the space so they cannot be recovered. The report shows when such a tool was downloaded, installed and run, how many times, and often, from its settings file, that its secure-overwrite option was enabled. That a wiping tool was run shortly after a demand letter or a resignation is frequently as significant as the deletions themselves. The evidence shows that the tool was run, under a user account, at particular times; it does not, on its own, show who ran it, and where the overwrite succeeded, the overwritten files are genuinely gone.

Owner-only, authority requiredFree first conversationStandard report £800 + VATWe say what it cannot prove

Rather talk it through? An engineer answers the bench line
0800 6890668

Before anything else: stop using the device, and do not let anyone have a look at it. Every time a computer is switched on and used, the very artefacts an examination relies on, the timeline, the recently-opened lists, the deleted-file space, are overwritten a little more. Do not reinstall, do not run recovery software, do not let IT open it to check, and keep it powered off. Preserve it as it is, record who has held it, and send it with the authority documents we ask for. If proceedings are contemplated, the duty to preserve evidence has already begun.

What the execution record shows, and the wiping-tool case.

Prefetch files are created by Windows to make programs start faster, and each records the program's name, the number of times it has been run, and the first and last times it ran. Other artefacts, the Amcache, UserAssist and BAM records, corroborate execution. Together they let an examiner say what was run on the machine and when, which matters wherever the question is whether a particular program, an unauthorised application, a data-transfer utility, was used.

The pointed case is a wiping tool. Programs whose job is to delete files and overwrite the freed space, so the files cannot be recovered, leave the same execution traces as any other program, so the examination can show that such a tool was downloaded (often still in Downloads, with a browser-history time), installed (in the installed-programs list and the Application log), and run, with run times and a count. Its settings file frequently records that a secure-overwrite option, a multi-pass wipe, was enabled.

The significance is often in the timing: a wiping tool run the morning after a demand letter is a fact the report can state plainly. The limits are equally plain. The execution record shows the tool was run under a user account at a time, not who ran it; and where the overwrite succeeded, the overwritten files are genuinely unrecoverable, so the examination may show that wiping occurred without being able to recover what was wiped.

What it records, and what it means.

Describe your situation →
What is recorded Where it comes from What it shows, and does not
Programs run, with times and countsPrefetch, Amcache, UserAssist, BAMWhat was run and when; not who ran it
A wiping tool installedInstalled programs, Application log, DownloadsThat the tool was installed and when; not its target
A wiping tool runPrefetch run times and countThat it ran and when; not who ran it
Its secure-overwrite settingThe tool's configuration fileThat overwriting was enabled; overwritten files are gone

From the exhibit arriving to the report.

Work we have closed →
01

The first conversation, and the authority check Free

Tell us the situation, who owns the device, and what you need to know. We tell you whether it is a job we can take on, what authority we will need, and whether the standard report answers your questions or an expert report is called for. That conversation is free, and some enquiries end there, because we will not take work we cannot lawfully or honestly do.

FreeOwner-only; authority established firstThe honest answer about what is possible
02

Imaging behind a write blocker, and the hashes

When the exhibit arrives, your authority is checked, the device is logged and photographed, and the drive is connected through a hardware write blocker and imaged bit for bit. MD5 and SHA-256 hashes of the source and the image are computed and verified, so the copy is provably identical. Nothing is examined on the original; every later step is done on the verified image.

Bit-for-bit, behind a write blockerMD5 and SHA-256, verifiedThe original never altered
03

The examination, on the image

The image is examined for the artefacts your questions turn on: USB device history, files opened from removable media, cloud and webmail activity, deleted files and the Recycle Bin, the USN journal, program execution, email, document metadata, shadow copies, and a timeline. Findings that matter are confirmed in a second tool. The work is scoped to what you asked; material outside the scope is not reproduced.

Scoped to your questionsConfirmed in a second toolPrivate material filtered out
04

The report

The standard forensic report sets out the exhibit and its condition, the integrity record, the tools and method, and the findings by category, with a timeline, the limitations, and factual conclusions, as a self-contained report with its chain-of-custody and case-log reports. It is written in plain terms, keeps fact separate from any comment, and is suitable for internal decisions, HR processes, negotiations and solicitors. Where you need opinion evidence for court, an expert report is quoted.

Factual, tool-generated, self-containedChain-of-custody and case-log reports5–10 working days

From the bench

  • Preserve the machine; execution artefacts are strong but can be affected by continued use and, deliberately, by the wiping tool itself.
  • Give us the key dates; a wiping tool run against a demand letter or a resignation is what the timing shows.
  • Accept the limit on overwritten files; the report can show wiping occurred even where it cannot recover what was wiped.

A wiping tool run the morning after a demand letter is a fact the report can state plainly, and the timing is often as significant as the deletions.

What helps, and what harms.

Do this much first

  • Stop using the device and keep it powered off
  • Preserve it as it is; record who has held it
  • Gather your proof of ownership or authority
  • Tell us the questions you need answered

What sets us back

  • Letting IT or anyone open it to have a look
  • Reinstalling, wiping or running recovery software
  • Carrying on using the device
  • Assuming artefacts prove who was at the keyboard
We examine devices only for the people and organisations with lawful authority over them. Before any work begins we ask for proof that the device is yours, or documented authority to have it examined: proof of ownership, a director's or HR letter for a company device with the lawful basis, a solicitor's instruction, a court order, or an executor's grant. It is a condition of the work, not a formality, and it is what keeps the examination on the right side of the Computer Misuse Act 1990. We will not access another adult's device or accounts without their consent or a court order, we will not install monitoring software or bypass anyone's security, and we do not undertake covert surveillance. A device with no proof of authority is returned unexamined.

Questions answered before you instruct.

Can you tell if someone used a wiping tool?

Yes. A wiping tool leaves the same execution traces as any program, so the examination can show it was downloaded, installed and run, with the times and run count, and often that its secure-overwrite option was enabled. That it was run, and when, is frequently as significant as the deletions, particularly against a key date.

If they wiped the files, can you still recover them?

Where a secure overwrite succeeded, the overwritten files are genuinely unrecoverable, by us or anyone. But the examination can still show that wiping occurred and when, recover whatever was not actually overwritten, and present that alongside the deletion and execution evidence. Showing that wiping happened is itself significant.

Does this prove who ran the tool?

No. The execution record shows the tool was run under a user account at particular times, not who was at the keyboard. As with every artefact, we state that limit, and the timing and the surrounding evidence are what give it weight.

What programs can you show were run?

Any that left execution traces, which is most. The report can show what software was run and when, which matters where the question is whether a particular application, a data-transfer utility, an unauthorised program, a wiping tool, was used on the machine.

What does it cost?

Execution evidence is part of the standard forensic report, £800 + VAT for a one-disk system. The first conversation is free.

The record is on the device; preserve it first.

The first conversation is free. Tell us the situation and who owns the device, and we will tell you what the evidence can show, what it cannot, and whether we can take it on. Until then, stop using the device and preserve it as it is.

0800 6890668