@dietro…do you have something to reference that supports this? Like I mentioned, while I'm curious, it's never really come up as part of an examination. Can you point to something…testing, a white paper….that supports this?
@Cults14 - Regslack is an awesome tool for locating deleted keys/values in the unallocated space within a hive file.
@dietro…do you have something to reference that supports this? Like I mentioned, while I'm curious, it's never really come up as part of an examination. Can you point to something…testing, a white paper….that supports this?
Harlan, I've done "before and after" testing myself, and this very issue was a recent topic of conversation on the CCE mailing list. Several people relayed that in their testing as well, this behavior is a result of SP3 being installed on an existing XP installation.
However, Cults14 has already done the research on the image he's working on to give a VERY strong indication that this is precisely the cause.
From the original post
Using RegRipper , in System hive (USBStor ControlSet001\Enum\USBStor) 61 USB devices are listed. Of these, 57 have exactly the same Last Write Time of Mon Apr 19 143234 2010.
snippage
On Apr 19th there are a large number of Windows Updates reported by RegRipper in \Software\Microsoft\Windows\CurrentVersion\Uninstall, including XP3 update, various security updates for Windows XP, and various updates Windows XP. These commence at 153417 and finish at 155857.
I would suspect that the date/time that Cults14 found for the installation of SP3 is when the installation completed. Thus, the Last Write time for the 57 devices in the USBSTOR occurs at some point during the installation process.
Cults14, given that you have said your question was for informational purposes and would look elsewhere for definitive answers as to when the devices may have been connected, I would suggest Harlan's book(s), or you can download Rob Lee's cheat sheets for thumbdrives here
And for USB drive enclosures here
dietro - thanks. Yes I've already got those cheat sheets tucked safely away on my HD for reference.
As a matter of interest, what CCE mailing list are you talking about? I've requested training & certification but not been granted yet, might fork out for it myself if my employer doesn't but it's a fair old bite out of the personal cash-flow. Can non-CCEs join?
Regards