Missing Timestamps ...
 
Notifications
Clear all

Missing Timestamps in LNK Files

j.puckett
(@j-puckett)
New Member

About 1,100 LNK files were found on a shared computer.  About 800 appear to be pornographic images, and some may be CP based on filename.  The images are deleted, overwritten and unreadable.  It is a Win7 machine.

What appears odd (to me) is that the LNK files are missing the three file timestamps.  The timestamps are present for the creation of the LNK file itself, and all three timestamps are the same.  Why are the file timestamps missing?  Because the file was deleted?

Also, I thought I found this on the Microsoft site but cannot repeat my find.  In Win7, does the LNK file get created when the file is downloaded/created, or when the file is first accessed?  The reason I ask this is there were a massive amount of pornographic images found (overwritten and unreadable) on a second drive, but there isn’t a single LNK found that suggests anyone ever accessed a single file.  I’m trying to figure out how they got there, as it appears no one ever knew they were there.

 

Thanks!!

Quote
Topic starter Posted : 30/06/2022 7:03 pm
Rich2005
(@rich2005)
Senior Member

This of any use? (sounds similar to what you might be looking at)

https://www.mandiant.com/resources/the-missing-lnk-correlating-user-search-lnk-files

ReplyQuote
Posted : 04/07/2022 11:01 am
Share:
Share to...