Anti-Virus Tools an...
 
Notifications
Clear all

Anti-Virus Tools and File Accessed time stamps

7 Posts
7 Users
0 Reactions
1,051 Views
(@allikuzi)
New Member
Joined: 16 years ago
Posts: 4
Topic starter  

How does running Anti-Virus scan affect the file accessed time stamps on Windows XP NTFS partitions? ?


   
Quote
(@thall)
Trusted Member
Joined: 16 years ago
Posts: 53
 

set up a virtual machine check the time stamps run a scan re-check, doing your own experiments will always help you learn better than asking on the internet.


   
ReplyQuote
(@ba2llb)
Eminent Member
Joined: 16 years ago
Posts: 38
 

set up a virtual machine check the time stamps run a scan re-check, doing your own experiments will always help you learn better than asking on the internet.

Agreed experience is the best teacher and you tend to remember something better with hands-on experience. I recommend free version of Sun VirtualBox to run an instance of the operating system.


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

If someone doesn't have VMWare, or VMPlayer, and a usable VM, then try installing AV on your system, and selecting only a single directory to scan, say system32. Note the last access times beforehand, as well as afterward.


   
ReplyQuote
Beetle
(@beetle)
Reputable Member
Joined: 17 years ago
Posts: 318
 

Try Einstein's thought experiment technique if you can't conduct a physical experiment…

Think about this, when an AV tool is going to check for malware, what does it have to do to determine if a file is malicious?

(on reading that it almost looks like Zen)


   
ReplyQuote
(@keeper)
Estimable Member
Joined: 17 years ago
Posts: 106
 

NOD32 has an option that says "Preserve last access timestamp", so it depends which AV you have.


   
ReplyQuote
(@originl)
Active Member
Joined: 16 years ago
Posts: 9
 

Just thinking aloud…

1. Permissions on the file system/directory may also be something to consider. For instance, maybe the AV runs under a specific user that may/may not have read/write access, etc. and how that may affect timestamps.

2. If a user whitelists a specific file or folder for no scan, does the AV touch those listed before logically not scanning and does it affect the timestamps?

3. How does a scan differ from quarantining a file and its timestamps? Likewise for cleaning a file? How about for an unsuccessful cleaning?

Would be interesting to see how those play out.
Of course, each vendor and each revision of their software may differ in actions.


   
ReplyQuote
Share: