Where can I find a log of activity on my Windows 7 PC?


Recommended Posts

One particular important file has gone missing and I want to find out how it?s disappeared, so need to know all activity in the past 24hrs, if that?s possible?

Link to comment
Share on other sites

Forgive me for being a numbskull, but which ?Log Summary? do I need to choose? The file that's gone AWOL was a Word doc, located on the desktop.

 

Just to know when my PC was running would be helpful, because one concern is that I was hacked.

Link to comment
Share on other sites

Forgive me for being a numbskull, but which ?Log Summary? do I need to choose? The file that's gone AWOL was a Word doc, located on the desktop.

 

Just to know when my PC was running would be helpful, because one concern is that I was hacked.

Hi if you haven't shut your PC down since the file went missing... try opening 'windows explorer, click organise, then click undo'... windows will move the doc back to the desktop if it has been moved. If it has been deleted and isn't in the recycle bin you can try http://www.piriform.com/recuva to see if you can recover the doc.

 

And as to event viewer click 'Custom views, then Administrative events' this should show you about any warning pop-ups or remote access to your machine etc...

Link to comment
Share on other sites

Correct me if I'm wrong but the event viewer isn't going to tell you when a file has been deleted and by who.

 

If you cannot search for the file across your disk(s) nor is in the recycle been you SOL.  File recovery tools my find it if it hasn't been overwritten yet.

Link to comment
Share on other sites

Do you remember the name of the file? You should be able to find it using DIR from a command prompt:

dir /a /s \document*

will find all files starting with "document" on the drive, whether hidden or not.

 

It won't show you how it disappeared but it may find it if it's still there somewhere.

Link to comment
Share on other sites

Correct me if I'm wrong but the event viewer isn't going to tell you when a file has been deleted and by who.

 

If you cannot search for the file across your disk(s) nor is in the recycle been you SOL.  File recovery tools my find it if it hasn't been overwritten yet.

True but the sometimes the registry can in some cases...

Link to comment
Share on other sites

The Event Viewer/Security log will tell you when user logged in.

 

Filter on event ID = 4648

Link to comment
Share on other sites

In which cases? Because nothing like that is tracked via the registry.

Some files which are installed by software are tracked for uninstallation proposes. And sometimes files placed on the desktop leave identifiable data in registry. The registry and page file are two of the places police etc.. look for illegal content on a pc. So merely wiping a file can still leave traces on a computer.

Link to comment
Share on other sites

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.