Professional Documents
Culture Documents
***Frostwire in identical to Limewire in everyway except for name and treats its file in the
exact same fashion***
After confirming the changes, the same above files were written to as well.
Downloads in Frostwire
When a download is initiated in Frostwire, for example and MP3 the following things occur
-Downloads.bak is created (if it’s the first ever download within frostwire) and written to.
-C:\....Frostwire\downloads.bak is written to/updated (this file is where Frostwire tracks its current
downloads in the exact same way Limewire does)
- C:\....Frostwire\xml\data\audio.sxml2 is created and is a database that provides Frostwire with the info
displayed when other P2P users search your shared files
- C:\...Frostwire\library.dat is written to
- C:\...Frostwire\Fileurns.cache is written to and contains an index of shared files and their paths. This
enables sharing of the files when user logs onto the network.
- C:\...Frostwire\Createtimes.cache is written to
Evidence Media Played in Built in Media Player
Using Frostwires’ built in media player wrote to the registry:
HKLM\System\CurrentControlSet\Hardware
Profiles\0001\System\CurrentControlSet\Enum\HDAUDIO\FUNC_01&VEN_10EC&DEV_0883&SUB
SYS_1043829E&REV_1000\4&B3DDC6A&0&0001\DirectSound\Speaker Configuration\Speaker
Configuration
PROPS Examination
FrostWire has been described as “LimeWire Pro for free”. It behaves like LimeWire and contains many
similarly named files. It is a peer-to-peer file sharing program that uses the Gnutella and BitTorrent
networks.
The user’s GUID is contained within CLIENT_ID=. As you can see, other important info such as the
directory where files are saved and the directory that is shared are contained.
To determine when the client was installed, the installation.props file was examined:
The date and time marked at the top of this file is one second later than the Created date within EnCase
for this file.
The default path for FrostWire’s storage is: C:\Documents and Settings\{user}\My Documents\FrostWire
and contains four folders:
• Incomplete – where the incomplete files are stored in a default installation. They are
prefixed with “T-{total number of bites for complete download}” unless they have been
previewed, in which case they are prefixed with “Preview-T-{total number of bites for
complete download}”
• Saved – where the complete downloaded files are stored in a default installation
• Shared – the default shared folder; by default all downloaded files are also shared
(checkbox in Tools->Options->Sharing)
• Store Purchased - where purchased content would be saved
While in LimeWire, the downloads.bak and downloads.dat files are stored in the Incomplete folder, these
files within FrostWire are stored by default at C:\Documents and Settings\{user}\Application
Data\FrostWire.
A search was conducted for the name “ridiculousness”. Returns were obtained with “ridiculousness”
listed as the album title for some mp3 files. One of these files was downloaded. The FrostWire folders
created during installation were then imported into EnCase for examination. A keyword search was
conducted for the term “ridiculousness” using the default text and Unicode. The only hits were contained
within the downloaded audio file and the audio.sxml2 file, where it showed that album=”Ridiculousness”.
It appeared that the search term was not stored in any other file.