As of late I have been trying to learn how to use pevFind for finding malware.
Instead of going to Billy for every question I have, and due to his preference so that others may learn too, I took his recommendation to create a thread here for discussions about pevFind.
Here is the URL you can d/l and read about the features of pevFind: https://bitbucket.org/BillyONeal/pevfind
_____________________________________________________________________________________________________________
There will undoubtedly be a lot of questions from me as I am eager to learn about this tool.
Here is my first one:
When I use the following code:
pev.exe -dc:G30 -r -sa:CDATE -sd:NAME --custom:##c . #m #t #f# AND "%windir%\*" OR "%windir%\system32\*" >>"%userprofile%\desktop\report.txt"
In the "report.txt" I get some of the following lines:
2011-12-28 19:22:51 . 2011-11-05 04:34:45 ----a-w- C:\Windows\system32\url.dll
2011-12-28 19:22:51 . 2011-11-05 02:48:51 ----a-w- C:\Windows\system32\mshtml.tlb
2011-12-28 19:22:46 . 2011-11-05 04:26:03 ----a-w- C:\Windows\system32\tzres.dll
2011-12-28 19:22:36 . 2011-10-15 05:38:59 ----a-w- C:\Windows\system32\EncDec.dll
1601-01-01 00:00:00 . 1601-01-01 00:00:00 ----a-w- C:\Windows\system32\AERTAC64.dll
1601-01-01 00:00:00 . 1601-01-01 00:00:00 ----a-w- C:\Windows\system32\AERTAR64.dll
1601-01-01 00:00:00 . 1601-01-01 00:00:00 ----a-w- C:\Windows\system32\FMAPO64.dll
The highlighted in red CDATE (Created date) and MDATE (Modified date) are obviously incorrect.
I am performing this command on a Windows 7 x64 system.
Also notice how not ALL system32 files are incorrect, just some of them.
What am I doing wrong here and how can I remedy this?


Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Back to top








