Max

15 responses to “Delete USB Device History from the Windows Registry (USBSTOR key) and the setupapi.log”

  1. Another tip I’d like to mention which many of you already probably know/do is to use software such as filemon and regmon or Process Monitor which contains both of the previouis apps I believe to test this stuff yourself. You can start up the application(s) and then plug in a USB device to see which logs and keys are updating.

    This is one of the best ways to find artifacts.

  2. Thanks for the post!

  3. once the registry keys are deleted will it be possible to recover again?

  4. Just use a live linux CD or DVD like puppy or slax.

    If your using windows you are leaving tracks no matter what you do to the drive to cover up reg keys or wiping sectors on a drive.l

    No drive—no evidence.

  5. Thanks or the nice tips.

  6. thanks for the nice tips

  7. Look for something in the registry is not really easy via Regedit. It is long and you need to press “F3″ to continue the whenever you search registry entry. Read more from the guide for “Monitor, clean and optimize the Windows registry” at: http://forums.techarena.in/guides-tutorials/1298086.htm

  8. I wonder why there is no setupapi.log in my %windir% …
    Can someone help me ?

  9. OddAnt: Windows root directory.
    C:\windows\setupapi.log

  10. @Soni : %windir% = C:\windows
    Still not having the setupapi.log file

  11. same for me… no file at C:\windows\setupapi.log

  12. ssame for me… no file at C:\windows\setupapi.log

  13. try search for setupapi.log in the from run

  14. Use a live LINUX CD/DVD Slax,puppy,Knoppix, ETC and you will not have to worry about an OS that records every little thing you do.

  15. What will happen if i delete the setupapi.log from my system and copy the setupapi.log from another system in the network ?

Leave a Reply

Archives