We’re Still Here to Help (Even Over the Holidays!) - find out more here.
Forum Discussion
harryisthename
3 years agoHelpful | Level 5
File accessed time changed
Sorry if this is a repeat. I went back in and could not find the original using Search. Label is 'Security' When I do a dir /s /a: /o:d /TA c:\*.* I am observing the file access date and time is...
harryisthename
3 years agoHelpful | Level 5
Hi Samantha, thank you very much! I need some time to investigate further. Thank you for the useful whitepaper. Perhaps you can comment on this:
Using SysInternals procmon, I am seeing that one or two times a day, Dropbox mysteriously chooses perhaps three or four files to do procmon operations of QueryEAFile on the file (say C:\Users\Admin\Dropbox\PITCH.51:COM.DROPBOX.ATTRS) (which BTW returns an INVALID PARAMETER code) and causes Windows Defender (Msmpeng.exe) to open and read the first 26 bytes of the original file (C:\Users\Admin\Dropbox\PITCH.51) and close the file. This may be what causes the file access time to change. I have no idea what provoked Dropbox todo the QueryEAFile (see https://learn.microsoft.com/en-us/windows-hardware/drivers/ddi/ntifs/nf-ntifs-ntqueryinformationfile ) and I am aware many people have complained for years about such files being created and remaining around (not the case here - they do not remain around). See https://help.dropbox.com/sync/extended-attributes .
Dropbox always states it's likely a shared folder or syncing to a device that is using a different file system and this is needed to propagate extended attributes from one file system to another. Fair enough. But there are no other devices connected to the account (a Free account), everything has been revoked, the password was changed, 2FA was set up, sfc /scannow, chkdsk C: were done, no other anti-virus is running, I went through autoruns with a fine tooth comb and the issue persists and apparently had been going on for months. I intend to study this, with hopefully your help -- otherwise I am overwhelmed trying to attempt this on another clean install of Windows 10.
Just a few files per day. It gets more interesting: I will add that at one point I saw on the portal Security settings an Android device which was connected to an ASN router belonging to my ISP and a few miles from my home. That was strange and smacks of (SWAG) MITM. It's very challenging to research this and get Spectrum or Dropbox to help. The natural inclination is: we do a great job and it has to be something on your end. Understood. But your help is appreciated and it's in your best interest to take this seriously, which I believe you do. I deleted that connection and the issue persists. I have never installed Dropbox on my Android phone. If I am contacted privately, I will be happy to provide screenshots and more procmon logs. Either I am being spied on (I have nothing to hide), my Dropbox is compromised/rogue, or my Windows Defender is compromised/rogue. I will be studying this further.
I am including a snippet of a procmon log for a file PITCH.51
This is important because Digital Forensics depends on the file access time for monitoring of file integrity and suspicious behaviors. It is challenging enough to get that last access time correct and interpret it, Dropbox (or Windows defender) just confuse the matter if they are responsible for these (possibly) unnecessary file access updates.
I will continue to update as I learn more.
Blessings!
Harry
Procmon for pitch.51
Sam DBX
Community Manager
3 years agoHi Harry,
Thanks for the detailed information.
We'll look into it and get back to you to share some insights if available.
Thanks for your patience so far!
- Sam DBX3 years ago
Community Manager
Hey Harry,Thanks for holding on. Here are some points we can provide a bit more info:First one (as you've mentioned) Dropbox does occasional sanity check true file comparisons and in between. Basically, we monitor the designated path of the syncing Dropbox folder and wait for filesystem events like add/edit/delete from the OS, which triggers a response from the Dropbox desktop application to then index/sync any changes that were made.Regarding other devices connected to your account, we are happy to look into this further for you, and get a better understanding of what you're seeing at your end.I’m sure you’re aware of these steps, but not harm in reinstating - if you suspect that an Android device has accessed your account without your authorization:- Change your password
- Review your connected devices: http://www.dropbox.com/account/security
- Disconnect any devices you don't recognise
Again, we can surely look into this further for you (via our support ticket).Best!- harryisthename3 years agoHelpful | Level 5
Hi Samantha, thank you again for your thoughtful reply. I believe you can see my email address from this message. If so, can I trouble you to *PLEASE* privately email me as there are some rather very important things I would like to discuss with you privately. I do intend, for transparency sake and as a professional courtesy to those who are following this post, to ask you at some point to summarize what we conclude privately, which may take a bit of time. Or perhaps I can summarize down the road.
In the meantime, my only comment about the sanity check scan -- it's good to know you do that from time to time BUT it does not apply here as the procmon tool did not reveal any Readfiles for the file compares -- just the Create, close and read (by Windows Defender) of the 26-byte com.dropbox.atttrs file. If this were a sanity check, the dropbox service would have to read and return the data to the cloud for cloud-compare (or the cloud would have to download the cloud version of the file to the local machine data for the local machine to compare to it's local copy).
I look forward (hopefully) to your email.
Blessings,
Harry
- Sam DBX3 years ago
Community Manager
Hi Harry,
Not a problem, always happy to help.
Our team has been advised to contact you directly (via email).
Ps: if you haven't done so, please verify your email address, so we can fully assist you there: https://help.dropbox.com/account-access/verify-email
Thank you!
About Security and Permissions
Start a discussion in the Dropbox Community forum to get help with your account security and permissions. Find support from Community members.
The Dropbox Community team is active from Monday to Friday. We try to respond to you as soon as we can, usually within 2 hours.
If you need more help you can view your support options (expected response time for an email or ticket is 24 hours), or contact us on X, Facebook or Instagram.
For more info on available support options for your Dropbox plan, see this article.
If you found the answer to your question in this Community thread, please 'like' the post to say thanks and to let us know it was useful!