This research aims (1) to examine anti-forensic techniques affecting data recovery software and (2) to compare each anti-forensic technique with impacts on efficiency of forensic data recovery software. The researcher conducted an experiment by utilizing simple and common digital anti-forensic techniques including delete, format and overwrite. After that, three forensic data recovery programs: EnCase Imager, FTK Imager and ProDiscover, were exercised to recover digital evidence and to compare the effectiveness in recovering data of the forensic software from each anti-forensic technique on data storage devices containing NTFS file system on Windows 7 operating system. The research findings revealed that the three forensic programs had similar effectiveness of forensic data recovery as follows.  (1) The anti-forensic technique with commands “Delete” and “Format” without switching modes could recover digital evidence with 100% perfect condition because it was a technique that corrected or destroyed data in MFT Entry without getting involved with raw data in the file. (2) The anti-forensic technique with command “Format” and switching modes as Format Drive: /P: Passes and overwrite could partially recover digital evidence for undestroyed raw data in the file or it was irrecoverable once the raw data in the file was demolished because the raw data in the file was damaged with overwriting. The success of data recovery was accounted for 35%, 50% and 75% from the original file. Therefore, to conclude, success of digital evidence recovery depended on the original raw data in the file.


