LDB: using NK to look at different parts, what was it you were tasked to do initially?
a fishing expediton regarding ZFG and any info that would lead us to Caylee
LDB: what did you do to look for references of ZFG?
with an examination the first thing I do is look through user folders. I look at desk top, active files, start at desk top level what is stored. internet history where they visit, temp internet files to see where visit. any info re: who owns this computer and what person uses it. are they online a lot, business computer? Games, sometimes people only use for games.
LDB: able to locate references to ZFG
yes in temp internet files
LDB: determine date and time?
yes
LDB: how are you able to do that?
the temp files are a record. save on hard drive. it is about speed, every page you visit will save to hard drive. I can see what pages have been visited on there. If I go to www. nascar . com that URL will be stored on my hard drive and have a record that I visited that side and it will load from my hard drive. what I found on the 16th it records not only where I went but the date and time. That reference on the 16th is it being cashed to hard drive.
LDB: ?
several searches on internet: class reunion. searches for the name. on the morning of July 16th 2008. looking for a age range of 22 to 29 either in Orlando or Jacksonville.
LDB: any references to ZFG prior to the date of July 16th?
no
LDB: the process is trying to asses the general usage. any conclusions as to use this computer got?
on and running. not much office work. resumes of Mr. Anthony's. not a lot of business. no homework. a lot of internet history the temp files where four and a half years of internet history. they did not clear the history either.
LDB: how, browser?
click on it and clear
LDB: have to do it for each browser?
yes, if clear for Internet explorer will not clear fire fox
LDB: once you clear that cashe?
it gets saved on deleted space, but it resides on hard drive
LDB: how long can info stay in the allocated space/deleted space
depends, maybe for years.
LDB: if you have this free space on the computer and it is written over can you ever retrive the data that is underlying what writes over it?
no
LDB: what is a key word search?
NCase allows me to ask NCase: Nascar it will go through every bit of that hard drive looking for Nascar. I can ask for only one file or part if I like.
LDB: user accounts password protected?
one did
LDB: determine password?
rico23
LDB: able to determine when set?
yes(looking at report)(police sirens in back ground) sorry there is a lot of info in this report. (it is taking a while) set earlier in year in 2008 if I remember correctly. I am trying to verify that. Earlier in the year March of 2008, I believe.
LDB: the internet history on the HP. How evaluate that?
complicated question. internet files or history
LDB: two different things?
one is the page, difference. the history I would have copied those files out from Ncase using Net Analysis which puts cookies files, etc into spread sheet how I want to look at them: by date or however I wanted to look at them
LDB: is Net Analysis used in the computer forensic field?
yes
LDB: standard in the field
has been and yes
LDB: in files, cookies or internet history, can you tell which user is making the search?
yes, the internet history data base
JB: objection
HHJP: overruled
it records which user account is logged in and using account. not who is sitting there but which account is being used.
LDB: user account? internet history? cookies?
correct
LDB: once files are deleted, will the record associated with deleted files tell you who made search?
no, info no longer available
LDB: asked by YM to perform a key word search for chloroform?
yes
LDB: when?
late in Aug 2008
LDB: how was that performed?
the same as the ZFG key word was performed, put it into Ncase.
LDB: was there a location on the computer where you determined the key word hits occured.
in deleted space on hard drive
LDB: are you able to view the info associated with those hits?
yes
LDB: what can you see?
because it is in deleted space. hit or miss if get entire record. with chloroform we were able to recover the complete history. from the beginning to the end. complete history record.
LDB: you said that is sometimes difficult
sometimes when you delete there is a chance it gets covered but not in this case, we got entire record
LDB: how do you know?
I gave to sargent who is expert in that area, I am not
objection
sustained
LDB: you alerted another individual you reported a hit
chloroform: I was able to look at the language surrounding that and recogzied it as a data base internet file. I went to the beginning of the record because I did not know where it appeared, I found the search hit and turned it over to my sargent.
LDB: how does that happen?
he shoulder surfs, we are in a few feet of each other in the lab, he copied that out to another source and created report from there.
LDB: the HP was not only one through NCase?
yes
LDB: Ricardo Moralas?
yes, I did
LDB: what did you receive and from who?
I received a computer reportedly belonging to RM by John Allen
LDB: what did you do to preserve the data on RM computer?
the proceedure to document is the same as the other computers. removing hard drive and checking system clock. it was an apple, mac book, hard drive removed and copied using the Ncase software.
LDB: note date and time?
oct 28 2008 at 3:24 and system was oct 28 2008: London time or Grenwich mean time. difference of four hours.
LDB: if I may show the witness what was introduced as states 12. There is a monitor that looks like it has been turned. may I publish to jury since it has already been introduced?
HHJP: you may
LDB: can you see image?
I can
LDB: were you asked to deterime if that image was on his computer?
look for pictures of caylee with pink tee and info
LDB: able to locate states number 12?
yes
LDB: how?
searching the graphic files on the computer. I am sorry I don't know that I did, if I recognize that one. I do not have that report printed out, mine is on disk.