Skip to content

setupapi.dev.log: When a USB Device Was First Connected

How to read setupapi.dev.log device install sections, convert their local times to UTC, and compare them with the registry's first install date.

Published on 2 min read

TL;DR. C:\Windows\INF\setupapi.dev.log records a section every time Windows installs a device. The first section for a USB device is its first connection to that computer. Its timestamps are local time: convert them with the SYSTEM hive's time zone before comparing them with anything else.

What a section looks like

>>>  [Device Install (Hardware initiated) - USBSTOR\Disk&Ven_Contoso&Prod_SecureFlash&Rev_1.00\CS1234567890&0]
>>>  Section start 2026/09/14 12:30:14.212
     ump: Creating Install Process: DrvInst.exe 12:30:14.215
     ...
<<<  Section end 2026/09/14 12:30:16.034
<<<  [Exit status: SUCCESS]

A single stick usually produces several sections within seconds: the USB device (USB\VID_…&PID_…\serial), the disk (USBSTOR\…), and the portable-device view of the volume (SWD\WPDBUSENUM\…). They all carry the serial, so they group under one device.

Converting to UTC

The timestamps have no zone marker. The SYSTEM hive stores the zone in ControlSet00x\Control\TimeZoneInformation: Bias, StandardBias, DaylightBias and two rules, StandardStart and DaylightStart ("last Sunday of March at 02:00"). Apply the rule for the date of the entry, not the offset in force when the hive was collected: a September entry on a Paris machine is UTC+2 even if you image the disk in January.

In the example above, 12:30:14 Romance Standard Time in September is 10:30:14 UTC. USB Forensics does this conversion from the hive and says so in a note; without the SYSTEM hive it shows the times as if they were UTC and warns you.

Year-specific rules (Time Zones\<zone>\Dynamic DST in SOFTWARE) are rare for European and North American zones but can matter elsewhere.

Comparing with the registry

The registry's 0065 FirstInstallDate should be seconds away from the first setupapi section. When it is not:

  • setupapi earlier: the device was uninstalled (Device Manager, cleanup tools) and reinstalled; the registry was rebuilt, setupapi remembers the original installation.
  • An exact hour off: a time-zone conversion problem — check the zone and the DST rule.
  • No setupapi section at all: the log was rotated or deleted; look for setupapi.dev.*.log archives and Volume Shadow Copies.

Report both values. A tool that silently picks one hides the only clue you had about a reinstall.

Other install sources

The System log's UserPnp 20001/20003 events (driver installation for a device) and Kernel-PnP/Configuration 400 give independent install times in UTC. They are useful cross-checks when setupapi's conversion is in doubt. See the complete USB artifact map and the USBSTOR article for the registry side.

Related articles

A fictional intrusion walked through with USB Forensics: find the stick, confirm when it was connected, attribute the account and list the files copied.
Tie shortcuts, Jump Lists, ShellBags and 4663 events to a physical USB device with volume serial numbers, drive letters and time, and name the user.
Event 1006 in Microsoft-Windows-Partition/Diagnostic logs each USB disk with model, serial and boot records. How to read it and extract the volume serial number.