You can do it with OSForensics as well. There is a function to make a USB install, then you can run it from the USB drive on the live machine and do a File Name Search across the whole drive. From there you can sort by Create date or view the Time Line as a graph.
↧