Excelsior IT 406 – Computer Forensics
Subject: General Questions / General General Questions
Question
M3A2: Lab Activity- Operating Systems
IT406: Computer Forensics
Submit your findings for each hands-on project in a Word document, 2–3 pages in length, double spaced, and in 12-point font
Just a reminder on the format of your papers, they must have an introduction, details about the topic, include screen shots with narrative of those screen shots (no narrative reduces your credit), a conclusion of what you learned from the assignment, and references (every paper should have references on what you researched on the topic).
Hands-on project 6-3
(Hex Workshop – Free Demo Download available at: http://www.hexworkshop.com/)
In this project, you use Hex Workshop to become familiar with different file types. Follow these steps on a Windows XP or Vista computer:
1. On your hard drive, locate or create Microsoft Excel (.xls), Microsoft
Word (.doc), .gif, .jpg, and .avi files.
2. Start Hex Workshop.
3. Open each file by clicking File, Open from the menu, and then print just the first page of each file.
4. On each printout, circle the item that identifies the file type. Do this for all five file types.
5. Exit Hex Workshop.
Hands-on project 6-4
(Access Data Registry Viewer – currently Free Demo Download available at: http://accessdata.com/product-download/digital-forensics/registry-viewer-1-8-0-5)
In this project, you generate a word list based on an in-chapter activity. If you didn’t do the activity in “Examining the Windows Registry,” go back and perform those steps now. This word list could be used later with a password recovery program. When you’re finished, follow these steps:
1. Start AccessData Registry Viewer and open the User.dat file you retrieved from GCFI-Win98.eve earlier in this chapter.
2. Click Report, Export Word List from the menu.
3. In the Generate Word List dialog box, navigate to your work folder, and then click Save.
4. After the word list has been generated, exit Registry Viewer and turn the report file in to your instructor.

