Max

10 responses to “Delete USB Device History from the Windows Registry (USBSTOR key) and the setupapi.log”

  1. Another tip I’d like to mention which many of you already probably know/do is to use software such as filemon and regmon or Process Monitor which contains both of the previouis apps I believe to test this stuff yourself. You can start up the application(s) and then plug in a USB device to see which logs and keys are updating.

    This is one of the best ways to find artifacts.

  2. Thanks for the post!

  3. once the registry keys are deleted will it be possible to recover again?

  4. Just use a live linux CD or DVD like puppy or slax.

    If your using windows you are leaving tracks no matter what you do to the drive to cover up reg keys or wiping sectors on a drive.l

    No drive—no evidence.

  5. Thanks or the nice tips.

  6. thanks for the nice tips

  7. Look for something in the registry is not really easy via Regedit. It is long and you need to press “F3″ to continue the whenever you search registry entry. Read more from the guide for “Monitor, clean and optimize the Windows registry” at: http://forums.techarena.in/guides-tutorials/1298086.htm

  8. I wonder why there is no setupapi.log in my %windir% …
    Can someone help me ?

  9. OddAnt: Windows root directory.
    C:\windows\setupapi.log

  10. @Soni : %windir% = C:\windows
    Still not having the setupapi.log file

Leave a Reply

Archives