USBSTOR last writte...
 
Notifications
Clear all

USBSTOR last written times

6 Posts
3 Users
0 Reactions
1,616 Views
(@chrism)
Trusted Member
Joined: 16 years ago
Posts: 97
Topic starter  

Hi all,

I've got a situation where the last written times for all the keys in the USBSTOR directory are exactly the same.

I've done some research on this, and it seems to be the case for any Windows 7 computer I look at.

I'm trying to find a probable cause for this, could a system restart or another change affect the last written times of the keys? Windows update/backup? Is this a case for Windows 7 only?

This would mean that any real time/date recorded for when a USB device was plugged into a computer is wiped (, I've looked into the setupapi.dev.log (for another data source regarding USB devices) - does this log only record when a USB device is installed? So, for example, would it only record one entry for installation, and no further for any additional use?

Cheers all.


   
Quote
(@chrism)
Trusted Member
Joined: 16 years ago
Posts: 97
Topic starter  

Typical, as soon as a post a question I find some more information!

More information I have found under

SYSTEM\CurrentControlSet\Control\Devic
eClasses\{53f56307-b6bf-11d0-94f2-
00a0c91efb8b}

Under this key is a similar list of devices, but their respective last written times have not been overwritten. Still a mystery why SYSTEM\CurrentControlSet\Enum\USBSTOR\ has had all its last written times replaced.


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

ChrisM,

Many times, the reason for the LastWrite times for the USBStor keys all being the same is often an update…I'm sure if you put together a timeline, this is what you'll see.


   
ReplyQuote
jaclaz
(@jaclaz)
Illustrious Member
Joined: 18 years ago
Posts: 5133
 

More information I have found under

Yep.
Just for the record
http//www.forensicswiki.org/wiki/USB_History_Viewing

jaclaz


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

Hey, that's some good stuff…I wonder who wrote that???


   
ReplyQuote
jaclaz
(@jaclaz)
Illustrious Member
Joined: 18 years ago
Posts: 5133
 

Hey, that's some good stuff…I wonder who wrote that???

Probably roll
http//www.forensicswiki.org/wiki/Forensics_WikiAbout
http//www.forensicswiki.org/wiki/Simson_Garfinkel
Maybe someone added some good stuff to it between 2007 and 2008?
http//www.forensicswiki.org/w/index.php?title=USB_History_Viewing&action=history
http//www.forensicswiki.org/wiki/Harlan_Carvey

jaclaz


   
ReplyQuote
Share: