What I don't understand is Juan Martinez is saying that the Defense Team powered up the TA computer IN FRONT OF Martinez and Flores. Says they even had to go and find a power cord for this. WTH? Why would anybody ever be powering up that computer?
The protocol for forensic examination as taught in certified courses is to physically remove the hard disk from the computer, insert it into the Encase (or other company) copying device. The Encase copying device then makes a mirror image of the hard disk, using a special encryption process. It is this encryption process that is at the heart of the Encase software program. It creates digital encrypted "signatures" all along the way as it is copying the files. If a file gets changed, the encrypted signature - which is an encoded numerical system - can NOT be duplicated. Thus, any change to a file would show up.
Was the Defense Team at the Evidence Room that day in order to make a "fresh" mirror copy from the hard disk? If so, they would have had to have their Encase copying device with them. Did they power up the TA computer PRIOR to removing the hard disk? If they did, they screwed up. And yes, an anti-virus program could have started up and run automatically when the laptop with hard disk in it was powered on.
BUT, to me, even with some viruses on board, that computer would not have had THOUSANDS of files erased. An anti-virus scan is just that. It looks for malware files and acts on them. Usually it "quarantines" the Trojans, viruses, and other crap and then asks you, the user, how you want to handle these quarantined files. You can look through them and delete files individually or you can delete them all at one. Then you must restart the computer.
Somewhere along the way in the not too distant future, each and every person who went near that computer will need to give a sworn statement as to what they actually did with it.
Also, there would be a pristine copy of the original mirror image in the evidence room along with the computer. Nobody works from the original mirror image. They work from copies of the original mirror image.
I see that the Encase company is now offering "cloud storage" for these original mirror images. As part of this service they will provide a mirror disk to whomever the Prosecutors direct them to. It says they will also perform a comparative scan of the original mirror image once per month to make sure nothing on it has changed.
Another service they are offering is to businesses. Encase enters into a contract with a company to have remote viewing capabilities for ALL of their computers. They set up the hardware so it works on the company network. No one who is using the company network would know this is on there. Encase can then go into any computer on the company network at any time, as per the directions of the company that hired them.
So unlike having to download a software program onto your actual computer for someone to have remote access, this is all contained within the company network itself. Oh, and Encase will send regular reports to the employer, based on whatever the employer wants to know. Internet usage? How much time on the Internet? Emails? Photos?
Oh I am so glad I am retired!
Interesting. Was Encase capable of all this in 2008? Any thoughts on how much things have changed since then?