windows last shutdo...
 
Notifications
Clear all

windows last shutdown time

6 Posts
4 Users
1 Reactions
7,488 Views
(@noobster)
New Member
Joined: 18 years ago
Posts: 3
Topic starter  

Hello,

Using Regripper to extract System and SAM registry, and found out Shutdown time recorded few hours later than Last Login Date. following is the extracted registry

ControlSet001\Control\Windows key, ShutdownTime value
ControlSet001\Control\Windows
LastWrite Time Wed May 6 090419 2009 (UTC)
ShutdownTime = Wed May 6 090419 2009 (UTC)

Last Login Date Thu May 7 002546 2009 Z

My only conclusion is perhaps the system is power off hence the registry is not updated. Is there a way to correlate this. thanks in advance


   
Quote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

Sure, there are a number of ways to do so…check the user's UserAssist key entries for signs of activity, examine the Event Log, etc. The fact of the matter is that if you find signs of nothing, then it might just be that the system was simply powered off…unfortunately, the only definitive way to tell that is if you were standing there when it happened.


   
ReplyQuote
(@csericks)
Trusted Member
Joined: 18 years ago
Posts: 99
 

noobster,

Is the system on a network? If so and logging is active on the server, you might be able to find date/time-related network activity.


   
hipmatt reacted
ReplyQuote
(@noobster)
New Member
Joined: 18 years ago
Posts: 3
Topic starter  

hello,

thanks so much appreciate the feedback, i'll check out the UserAssist key entries once m back at work, btw i did checked the Event Log before i posted ths but it is not enable unfortunately. Also the computer is a stand alone system (


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

So you didn't see any events related to shutdown or reboot?


   
ReplyQuote
jhup
 jhup
(@jhup)
Noble Member
Joined: 16 years ago
Posts: 1442
 

If a laptop, battery charging log as reference?


   
ReplyQuote
Share: