|
Evidence Evidence Erases your swap file
About Windows swap file.
The Windows Swap File is a
large hidden file located in
the root of your boot drive
used for keeping your virtual
memory. It is only a temporary
file, but Windows does not delete
it from your disk upon shut
down, therefore, anyone can
extract a lot of information
from it. Moreover, this file
contains traces of almost all
files and data you used during
the last working session.
The Windows SWAP file is a
hard disk file used by Windows
as extra memory in addition
to the physical RAM memory installed.
Correct cleaning of the Swap
file is essential for security.
It can store copies of any data
you have used, even though you
may not have "saved"
it.
The Windows swap file is potentially
a valuable source of evidence
and leads. The evaluation of
the swap file can be automated
with several of NTI's forensic
tools, e.g., NTA Stealth, Filter_N,
FNames, Filter_G, GExtract and
GetHTML. These intelligent filters
automatically identifies patterns
of English language text, phone
numbers, social security numbers,
credit card numbers, Internet
E-Mail addresses, Internet web
addresses and names of people.
The Evidence Eliminator Program will delete the Windows swap file.
When it is turned on, Evidence Eliminator will perform the wiping
execution.
It is strongly recommended that you clean the swap file regularly.
Of course this is just one of the many
pc security features of Evidence Eliminator.
|