Forensic Focus - Computer Forensics, Computer Forensic Training, Digital Forensics
LoginRegisterForumsColumnistsPapersEducationGraduatesReviewsInterviewsNewsletterJobsEventsBlogAdvertise
Search Forensic Focus
Custom Search

Find us on Facebook
Follow Forensic Focus on Twitter
Columnists
"I erred." "I was mistaken."
Craig Ball
Single Sign On
Simon Biles
Copyright and games console modification
Dan Gaskell
To GUI or not to GUI?
Chris Hargreaves
'Web 2.0' as evidence
Sean McLinden
Sometimes it’s all about timing
Sam Raincock
Avoiding common job application errors
David Sullivan
Scalability: A Big Headache
Dominik Weber
Graduate Recruitment

computer forensics graduate jobs

Main Menu
MY ACCOUNT
COMMUNITY
EMPLOYMENT
EDUCATION
RESOURCES
MISC
Follow Forensic Focus

Join newsletter

Join LinkedIn group

Follow on Twitter

Subscribe to news

Subscribe to forums

Subscribe to blog

Subscribe to tweets

Members' blogs

External feeds

Bookmark & share: Bookmark and Share

Computer Forensics Newsletter
Newsletter

You must be a
registered user
to receive our newsletter

Register Now!

HDD last write time - Files created, modified after?
Go to page 1, 2  Next
Post new topic   Reply to topic   Printer Friendly Page     Forum Index -> General Discussion
View previous topic :: View next topic  
Author Message
pronie2121
Senior Member


Joined: Mar 11, 2008
Posts: 117
Location: NY

PostPosted: Thu Dec 18, 2008 10:00 am    Post subject: HDD last write time - Files created, modified after? Reply with quote

Looking at a Windows XP box checking out the registry it gives a shutdown time and last write time at a specific date in 2007. When looking at files on the drive there are numerous amounts of files that are created, modified, and accessed over a year later in 2008. My question is if the registry is showing that the last write and shutdown time was in 2007 if the computer was turned on to use in 2008, would the registry last write time reflect this? This is looking in the Software\Microsoft\Windows NT\CurrentVersion, and also the shutdown time in System\ControlSet001\Control\windows. Thank you
Back to top
View user's profile
keydet89
Senior Member


Joined: Oct 19, 2004
Posts: 2380
Location: NoVA

PostPosted: Thu Dec 18, 2008 10:08 am    Post subject: Re: HDD last write time - Files created, modified after? Reply with quote

Pronie,

When performing analysis such as this, you have to keep in mind what the various values truly reflect. For example, a Registry key LastWrite time reflects that last time that key was modified; ie, when a value or subkey was created or modified (with deleted being the extreme case of modified).

As to the ShutdownTime value, that reflects the date/time that the system was last cleanly shutdown. My daughter never shuts off her computer, but lets it go into sleep() mode. Depending upon the type of system you're looking at, this may make perfect sense.

One way to correlate this is to check the System Event Logs for 6005 and 6009 events, which indicate a system shutdown/restart.
Back to top
View user's profile Visit poster's website AIM Address
pronie2121
Senior Member


Joined: Mar 11, 2008
Posts: 117
Location: NY

PostPosted: Thu Dec 18, 2008 10:22 am    Post subject: Re: HDD last write time - Files created, modified after? Reply with quote

Ok so if a year later the computer was turned on files were created, modified, etc.. and then the computer was just turned off or plug pulled, etc anything but being cleanly shut down then the registry key for shutdown time would not reflect this? thanks keydet
Back to top
View user's profile
stezer2000
Senior Member


Joined: Jun 09, 2008
Posts: 132
Location: Wales

PostPosted: Thu Dec 18, 2008 10:57 am    Post subject: Re: HDD last write time - Files created, modified after? Reply with quote

Have you considered that the user may have taken the drive out of the computer and plugged it into another externally

Maybe there was more than one drive that in the computer before that acted as O/S and accessed the other drive as they were both attached to the same mother board

I've had this in cases before where the defendant claims the files were planted, but then when you look at the drive, they have a slide out caddy which contains a separate O/S and link files to the files they allege were planted.
Back to top
View user's profile
pronie2121
Senior Member


Joined: Mar 11, 2008
Posts: 117
Location: NY

PostPosted: Thu Dec 18, 2008 11:15 am    Post subject: Re: HDD last write time - Files created, modified after? Reply with quote

I have thought of that this drive came from a laptop, something else I came across that I thought was odd was the OS install date is in 2006, but I have files that are created on that drive dating back to 1999 and all the years before 06???thanks stezer
Back to top
View user's profile
stezer2000
Senior Member


Joined: Jun 09, 2008
Posts: 132
Location: Wales

PostPosted: Thu Dec 18, 2008 11:17 am    Post subject: Re: HDD last write time - Files created, modified after? Reply with quote

Have you looked into the sys event files

Security Event, ID 520 - Indictes that the system clock is changed

Export the .evt files and view them in your sys event viewer in windows
Back to top
View user's profile
pronie2121
Senior Member


Joined: Mar 11, 2008
Posts: 117
Location: NY

PostPosted: Thu Dec 18, 2008 11:46 am    Post subject: Re: HDD last write time - Files created, modified after? Reply with quote

Only one entry in the security event log ID 517 (the audit log was cleared) by user name system on the date that the registry shows as the OS install date
Back to top
View user's profile
pronie2121
Senior Member


Joined: Mar 11, 2008
Posts: 117
Location: NY

PostPosted: Thu Dec 18, 2008 4:44 pm    Post subject: Re: HDD last write time - Files created, modified after? Reply with quote

Why would the OS install date say 2006 when there are files on the drive dating back to 1999 and everything in between?
Back to top
View user's profile
keydet89
Senior Member


Joined: Oct 19, 2004
Posts: 2380
Location: NoVA

PostPosted: Thu Dec 18, 2008 4:55 pm    Post subject: Re: HDD last write time - Files created, modified after? Reply with quote

Again, context. Specifically, which files are you referring to? Are they system files? Part of the default installation?

Asking "why are some files on the drive dated thus and such?" doesn't really do a lot to help us help you.
Back to top
View user's profile Visit poster's website AIM Address
pronie2121
Senior Member


Joined: Mar 11, 2008
Posts: 117
Location: NY

PostPosted: Thu Dec 18, 2008 5:09 pm    Post subject: Re: HDD last write time - Files created, modified after? Reply with quote

I appologize it is a lot of microsoft office files, word, excel, etc. as well as application files. I just dont see that if the computer OS was installed in 06 how could these files be on there from 6 years prior to the operating system being installed. I will get specifics on the system files but from a glance it was a lot of office files. Thanks
Back to top
View user's profile
Display posts from previous:   
Post new topic   Reply to topic   Printer Friendly Page     Forum Index -> General Discussion All times are GMT - 6 Hours
Go to page 1, 2  Next
Page 1 of 2


Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Use of this website signifies your agreement to the Terms of Use/Privacy Policy available here.

All logos and trademarks in this site are property of their respective owner. The comments are property of their posters, all the rest © 2010 Forensic Focus


Interactive software released under GNU GPL, Code Credits, Privacy Policy
.: fisubsilver shadow phpbb2 style by Daz :: CPG-Nuke port by norseman :: ported to CPG-Dragonfly by jamin :.