Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 12th, 2011, 08:51 PM
Jula9600 Jula9600 is offline
Infrequent Poster
 
Join Date: Aug 2010
Posts: 21
Default Windows 7 system files Modified Date before Created Date

I remember reading/hearing somewhere that in many cases, malware changes the modified/creation dates on files. Does anyone know if this is true? For example, in the "properties" window;

audiodg.exe

Application(exe) file
Windows Audio Device Graph Isolation

Location: C:\Windows\System32
Size: 123 kb
Size on Disk: 124 kb

Created: Wednesday, March 09, 2011 1:47:03 AM
Modified: Saturday, November 20, 2010 8:24:26 AM
Accessed: Wednesday, March 09, 2011 1:47:03 AM


Would audiodg.exe then be considered a suspicious file? Or is this a common occurance?
  #2  
Old August 12th, 2011, 08:56 PM
LoneWolf's Avatar
LoneWolf LoneWolf is online now
Massive Poster
 
Join Date: Jan 2006
Posts: 3,130
Default Re: Windows 7 sysytem files Modified Date before Created Date

Quote:
Originally Posted by Jula9600
Would audiodg.exe then be considered a suspicious file? Or is this a common occurance?

http://www.runscanner.net/file/audiodg.exe.html
__________________
May you fly straight to heaven - but if you go to Hades - may Lethe run with Guinness
  #3  
Old August 12th, 2011, 09:11 PM
Jula9600 Jula9600 is offline
Infrequent Poster
 
Join Date: Aug 2010
Posts: 21
Default Re: Windows 7 sysytem files Modified Date before Created Date

Thank you, LoneWolf, but I know already that it is a valid file. I am more concerned with hijacked system files at this point. That is why I asked about the created vs modified date, I only included audiodg as an example.

I don't want to bore anyone so I'll leave the long story out of it. But still, is it common to have Windows\System32 files with a creation date AFTER the last modified/accessed date?
  #4  
Old August 12th, 2011, 09:16 PM
LoneWolf's Avatar
LoneWolf LoneWolf is online now
Massive Poster
 
Join Date: Jan 2006
Posts: 3,130
Default Re: Windows 7 sysytem files Modified Date before Created Date

Quote:
Originally Posted by Jula9600
But still, is it common to have Windows\System32 files with a creation date AFTER the last modified/accessed date?

Sorry I have no idea. Hopefully someone will be by soon with an answer for you.
__________________
May you fly straight to heaven - but if you go to Hades - may Lethe run with Guinness
  #5  
Old August 13th, 2011, 04:48 AM
tomazyk's Avatar
tomazyk tomazyk is offline
Frequent Poster
 
Join Date: Dec 2006
Location: Slovenia
Posts: 601
Default Re: Windows 7 sysytem files Modified Date before Created Date

Here is a link explaining file time stamps:

http://www.techrepublic.com/article/...indows/5034280

As article explains, it is possible to end up with file that has date modified earlier then date created. It will happen when you copy file from one location to another. Date modified of new file will remain the same, but date created will be set to system date and time when copying was made.
  #6  
Old August 14th, 2011, 01:00 AM
Jula9600 Jula9600 is offline
Infrequent Poster
 
Join Date: Aug 2010
Posts: 21
Default Re: Windows 7 system files Modified Date before Created Date

Ahhh...thank you very much, tomazyk. So copying the file from one location to another would most likely be the cause of a creation date after modification date.

I looked up an item listed in my event log and found an old 2009 technet forum post in which someone had replied:

"It is malware that has infected your BIOS. Watch searchprotocolhost.exe and searchfilter.exe Also audiodg.exe is hijacked. The same group that wrote Waledac."

So I looked at the properties of those files in C:\Windows\System32 and saw that their last modified date is way before their created date.

searchfilter.exe and searchprotocolhost.exe show

Created: ‎Tuesday, ‎June ‎28, ‎2011, ‏‎11:24:07 PM
Modified: Wednesday, ‎May ‎04, ‎2011, ‏‎1:19:28 AM
Accessed: Tuesday, ‎June ‎28, ‎2011, ‏‎11:24:07 PM

and audiodg.exe shows

Created: Wednesday, March 09, 2011 1:47:03 AM
Modified: Saturday, November 20, 2010 8:24:26 AM
Accessed: Wednesday, March 09, 2011 1:47:03 AM

Now the strange thing is that 2010 date... I did a factory restore in 2/2011 after cleaning 3 trojans off my Windows 7 x64 laptop and it still didn't function quite right. I suspect some hidden malware somewhere on my pc so my question is, could this be a clue as to the source? If so, then I am really in trouble because theirs HUNDREDS of files (exe's and dll's) in system32 that occur within seconds/minutes of those 3 files.

Oh, one more thing. I copied and pasted the dates from the properties panel in Windows Explorer to a notepad file. Of course, when I saved the file, I declined saving in unicode format and chose to save in ASNI format. When I re-opened it today, I saw this...
--------------------
Created: ?Tuesday, ?June ?28, ?2011, ??11:24:09 PM
Modified: Wednesday, ?May ?04, ?2011, ??1:19:28 AM
Accessed: Tuesday, ?June ?28, ?2011, ??11:24:09 PM
---------------------
AND
---------------------
Wednesday, ?March ?09, ?2011, ??1:47:03 AM
?Saturday, ?November ?20, ?2010, ??8:24:26 AM
?Wednesday, ?March ?09, ?2011, ??1:47:03 AM
---------------------

Now, obviously, I didn't put the question marks there so does this indicate altered dates?
  #7  
Old August 14th, 2011, 05:18 AM
tomazyk's Avatar
tomazyk tomazyk is offline
Frequent Poster
 
Join Date: Dec 2006
Location: Slovenia
Posts: 601
Default Re: Windows 7 system files Modified Date before Created Date

Hi Jula9600

I don't think you have to worry about those dates. I checked my audiodg.exe and date modified is earlier then date created. I can't check search files because I have search removed from Windows.

I think that cause of all this mess with dates is factory restoring. I belive that those files got copied during restoration and getting new create date stamps.

If you are not sure about your system safety, I suggest you to scan computer with online scanners or with Hitmanpro - just to be safe.

Next time you try to save txt file, try using Unicode instead of ANSI. It is just a coding problem of notepad.

Regards.
__________________
ESET Nod32 AV • Sandboxie • EMET • Emsisoft EK • OpenDNS • Secunia PSI • Acronis TI
My security setup in detail
• Always remember you're unique, just like everyone else •

  #8  
Old August 15th, 2011, 08:20 PM
Searching_ _ _'s Avatar
Searching_ _ _ Searching_ _ _ is offline
Very Frequent Poster
 
Join Date: Jan 2008
Location: iAnywhere
Posts: 1,988
Default Re: Windows 7 system files Modified Date before Created Date

Quote:
Originally Posted by jula9600
I did a factory restore in 2/2011
Could you give details about the process of your factory restore?
Did you wipe first? If yes, what method did you use?
Did you restore from media like DVD's or a restore partition on the HDD?
If it was media, was it a Windows disk or a factory image disk?
Did you reuse any saved media from before the restoration, files, documents, programs?
__________________
Americans are the enemy? Mil. can arrest you?
What the heck is going on?
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 12:21 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums