<?xml version="1.0"?><?xml-stylesheet type="text/xsl" href="/rss.xsl"?><rss version="2.0"><channel><title>MIR-ROR</title><link>http://mirror.codeplex.com/project/feeds/rss</link><description>MIR-ROR&amp;#58; Motile Incident Response &amp;#8211; Respond Objectively, Remediate    MIR-ROR is a security incident response specialized, command-line script that calls specific Windows Sysinternals tools, as well as some other useful utilities, to provide live capture data for investigation.</description><item><title>Source code checked in, #70298</title><link>http://mirror.codeplex.com/SourceControl/changeset/changes/70298</link><description>Upgrade&amp;#58; New Version of LabDefaultTemplate.xaml. To upgrade your build definitions, please visit the following link&amp;#58; http&amp;#58;&amp;#47;&amp;#47;go.microsoft.com&amp;#47;fwlink&amp;#47;&amp;#63;LinkId&amp;#61;254563</description><author>Project Collection Service Accounts</author><pubDate>Mon, 01 Oct 2012 21:36:45 GMT</pubDate><guid isPermaLink="false">Source code checked in, #70298 20121001093645P</guid></item><item><title>Source code checked in, #70297</title><link>http://mirror.codeplex.com/SourceControl/changeset/changes/70297</link><description>Checked in by server upgrade</description><author>Project Collection Service Accounts</author><pubDate>Mon, 01 Oct 2012 21:31:58 GMT</pubDate><guid isPermaLink="false">Source code checked in, #70297 20121001093158P</guid></item><item><title>Created Issue: nfscopy v 0.69 issues [7104]</title><link>http://mirror.codeplex.com/workitem/7104</link><description>Execution in Windows XP SP3 &amp;#91;August-2012 updated&amp;#93;&lt;br /&gt;&lt;br /&gt;- The script exits after ntfscopy command, so script stops after first ntfscopy &amp;#40;line 104&amp;#41;&lt;br /&gt;- Line 104&amp;#58; add -dst to define destination directory, error if no -dst&lt;br /&gt;- Lots of copies failed&amp;#58;  &lt;br /&gt;  &amp;#40;example&amp;#58; &amp;#34;failed&amp;#58;  c&amp;#58;&amp;#92;windows&amp;#92;system32&amp;#92;config&amp;#92;systemprofile&amp;#92;Menu Inicio&amp;#34;&amp;#41;&lt;br /&gt;</description><author>cachmon</author><pubDate>Mon, 03 Sep 2012 07:13:02 GMT</pubDate><guid isPermaLink="false">Created Issue: nfscopy v 0.69 issues [7104] 20120903071302A</guid></item><item><title>Created Issue: seccheck.exe [7058]</title><link>http://mirror.codeplex.com/workitem/7058</link><description>Can I get seccheck.exe&amp;#63; I have tried to access the specified location described on &amp;#34;fetch.txt&amp;#34;, but it returns &amp;#34;404 Error File Not Found&amp;#34;&lt;br /&gt;&lt;br /&gt;Thanks,&lt;br /&gt;</description><author>4n6ist</author><pubDate>Fri, 03 Aug 2012 05:58:19 GMT</pubDate><guid isPermaLink="false">Created Issue: seccheck.exe [7058] 20120803055819A</guid></item><item><title>Created Issue: Updated Fetch File [6909]</title><link>http://mirror.codeplex.com/workitem/6909</link><description>I was testing out the new MIR-ROR version and noted that the fetch page is missing the references to a number of tools &amp;#40;if by design due to licensing, you can just shoot me&amp;#41;.  I updated the fetch.txt file &amp;#40;maybe save you time&amp;#41; with the links and files below. I also included a note to copy Cygwin.dll for rifiuti.&lt;br /&gt; &lt;br /&gt;NirSoft&amp;#58;&lt;br /&gt;http&amp;#58;&amp;#47;&amp;#47;www.nirsoft.net&amp;#47;utils&amp;#47;winprefetchview.zip&lt;br /&gt;http&amp;#58;&amp;#47;&amp;#47;www.nirsoft.net&amp;#47;utils&amp;#47;iehv.zip&lt;br /&gt;http&amp;#58;&amp;#47;&amp;#47;www.nirsoft.net&amp;#47;utils&amp;#47;mozillahistoryview.zip&lt;br /&gt;http&amp;#58;&amp;#47;&amp;#47;www.nirsoft.net&amp;#47;utils&amp;#47;chromecacheview.zip&lt;br /&gt; &lt;br /&gt;Foundstone&amp;#58;&lt;br /&gt; &lt;br /&gt;http&amp;#58;&amp;#47;&amp;#47;downloadcenter.mcafee.com&amp;#47;products&amp;#47;tools&amp;#47;foundstone&amp;#47;rifiuti.zip&lt;br /&gt; &lt;br /&gt;7-Zip&amp;#58;&lt;br /&gt; &lt;br /&gt;http&amp;#58;&amp;#47;&amp;#47;www.7-zip.org&amp;#47;download.html&lt;br /&gt;</description><author>jcolorossi</author><pubDate>Wed, 25 Apr 2012 01:21:08 GMT</pubDate><guid isPermaLink="false">Created Issue: Updated Fetch File [6909] 20120425012108A</guid></item><item><title>Updated Release: MIR-ROR 2.0 (Mar 31, 2012)</title><link>http://mirror.codeplex.com/releases/view/84652</link><description>&lt;div class="wikidoc"&gt;&lt;b&gt;MIR-ROR 2.0&lt;/b&gt;&lt;br /&gt;The v.2.0 release incorporates many updates provided by Jon Mark Allen (contributing developer).&lt;br /&gt;Highlights include feature additions such as browser history collection, registry exports, prefetch view, recycle bin analysis, and 7z package creation.&lt;br /&gt;See Changelog.txt included in MIR-RORv2.0.zip for all changes.&lt;br /&gt;Thanks to Claus Valca for cleaning up fetch.txt (as of 4/11/12).&lt;/div&gt;&lt;div class="ClearBoth"&gt;&lt;/div&gt;</description><author>RussMcRee</author><pubDate>Thu, 12 Apr 2012 02:26:52 GMT</pubDate><guid isPermaLink="false">Updated Release: MIR-ROR 2.0 (Mar 31, 2012) 20120412022652A</guid></item><item><title>Released: MIR-ROR 2.0 (Mar 31, 2012)</title><link>http://mirror.codeplex.com/releases/view/84652</link><description>
&lt;div class="wikidoc"&gt;&lt;b&gt;MIR-ROR 2.0&lt;/b&gt;&lt;br&gt;
The v.2.0 release incorporates many updates provided by Jon Mark Allen (contributing developer).&lt;br&gt;
Highlights include feature additions such as browser history collection, registry exports, prefetch view, recycle bin analysis, and 7z package creation.&lt;br&gt;
See Changelog.txt included in MIR-RORv2.0.zip for all changes.&lt;br&gt;
Thanks to Claus Valca for cleaning up fetch.txt (as of 4/11/12).&lt;/div&gt;
&lt;div&gt;&lt;/div&gt;
</description><author></author><pubDate>Thu, 12 Apr 2012 02:26:52 GMT</pubDate><guid isPermaLink="false">Released: MIR-ROR 2.0 (Mar 31, 2012) 20120412022652A</guid></item><item><title>Updated Release: MIR-ROR 2.0 (Mar 31, 2012)</title><link>http://mirror.codeplex.com/releases/view/84652</link><description>&lt;div class="wikidoc"&gt;&lt;b&gt;MIR-ROR 2.0&lt;/b&gt;&lt;br /&gt;The v.2.0 release incorporates many updates provided by Jon Mark Allen (contributing developer).&lt;br /&gt;Highlights include feature additions such as browser history collection, registry exports, prefetch view, recycle bin analysis, and 7z package creation.&lt;br /&gt;See Changelog.txt included in MIR-RORv2.0.zip for all changes.&lt;/div&gt;&lt;div class="ClearBoth"&gt;&lt;/div&gt;</description><author>RussMcRee</author><pubDate>Thu, 12 Apr 2012 02:25:18 GMT</pubDate><guid isPermaLink="false">Updated Release: MIR-ROR 2.0 (Mar 31, 2012) 20120412022518A</guid></item><item><title>Closed Issue: Remote script available in the patches section [2585]</title><link>http://mirror.codeplex.com/workitem/2585</link><description>Remote script&lt;br /&gt;You can launch the mir-ror script in a remote machines to analyze each machine from your local machine and copy the results in other server,in this case, in a linux server to play with bash and logs. But you can put the logs whre you want....modify the final path.&lt;br /&gt;&lt;br /&gt;Thanks&amp;#33;&lt;br /&gt;Comments: &lt;p&gt;&lt;/p&gt;</description><author>RussMcRee</author><pubDate>Thu, 12 Apr 2012 02:19:23 GMT</pubDate><guid isPermaLink="false">Closed Issue: Remote script available in the patches section [2585] 20120412021923A</guid></item><item><title>Closed Issue: Handle Windows Vista and above [3398]</title><link>http://mirror.codeplex.com/workitem/3398</link><description>I think this should work for some basic version handling.&lt;br /&gt;&lt;br /&gt;REM http&amp;#58;&amp;#47;&amp;#47;ss64.org&amp;#47;viewtopic.php&amp;#63;id&amp;#61;879&lt;br /&gt;Setlocal&lt;br /&gt;&amp;#58;&amp;#58; Get Windows version numbers&lt;br /&gt;For &amp;#47;f &amp;#34;tokens&amp;#61;2 delims&amp;#61;&amp;#91;&amp;#93;&amp;#34; &amp;#37;&amp;#37;G in &amp;#40;&amp;#39;ver&amp;#39;&amp;#41; Do &amp;#40;set _version&amp;#61;&amp;#37;&amp;#37;G&amp;#41; &lt;br /&gt;For &amp;#47;f &amp;#34;tokens&amp;#61;2,3,4 delims&amp;#61;. &amp;#34; &amp;#37;&amp;#37;G in &amp;#40;&amp;#39;echo &amp;#37;_version&amp;#37;&amp;#39;&amp;#41; Do &amp;#40;set _major&amp;#61;&amp;#37;&amp;#37;G&amp;#38; set _minor&amp;#61;&amp;#37;&amp;#37;H&amp;#38; set _build&amp;#61;&amp;#37;&amp;#37;I&amp;#41; &lt;br /&gt;&lt;br /&gt;REM Echo Major version&amp;#58; &amp;#37;_major&amp;#37;  Minor Version&amp;#58; &amp;#37;_minor&amp;#37;.&amp;#37;_build&amp;#37;&lt;br /&gt;&lt;br /&gt;...&lt;br /&gt;&lt;br /&gt;REM seccheck.exe not compatible with Vista or above&lt;br /&gt;if &amp;#34;&amp;#37;_major&amp;#37;&amp;#34;&amp;#62;&amp;#61;&amp;#34;6&amp;#34; goto compromised_stage&lt;br /&gt;&lt;br /&gt;ECHO&amp;#9;Running seccheck on &amp;#37;COMPUTERNAME&amp;#37;.&lt;br /&gt;now.exe &amp;#91;Running seccheck on &amp;#37;COMPUTERNAME&amp;#37;.&amp;#93; &amp;#62;&amp;#62; &amp;#37;2&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;MIR-ROR.log&lt;br /&gt;seccheck &amp;#62; &amp;#37;2&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;seccheck.log&lt;br /&gt;move SecCheckLog.txt &amp;#37;2&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;SecCheckLog.txt&lt;br /&gt;&lt;br /&gt;&amp;#58;compromised_stage&lt;br /&gt;ECHO.&lt;br /&gt;ECHO&amp;#9;The following stage assesses for compromised code or settings.&lt;br /&gt;ECHO.&lt;br /&gt;&lt;br /&gt;...&lt;br /&gt;Comments: &lt;p&gt;&lt;/p&gt;</description><author>RussMcRee</author><pubDate>Thu, 12 Apr 2012 02:19:08 GMT</pubDate><guid isPermaLink="false">Closed Issue: Handle Windows Vista and above [3398] 20120412021908A</guid></item><item><title>Closed Issue: Identify installed software [4249]</title><link>http://mirror.codeplex.com/workitem/4249</link><description>Add another block for this command&amp;#58;&lt;br /&gt;&lt;br /&gt;wmic path Win32_Product get Name, Version &amp;#62; ...&lt;br /&gt;&lt;br /&gt;Knowing that version 6.0 of Adobe Reader is installed can help you assess whether the machine was compromised &amp;#58;-&amp;#41;.&lt;br /&gt;Comments: &lt;p&gt;&lt;/p&gt;</description><author>RussMcRee</author><pubDate>Thu, 12 Apr 2012 02:18:33 GMT</pubDate><guid isPermaLink="false">Closed Issue: Identify installed software [4249] 20120412021833A</guid></item><item><title>Updated Release: MIR-ROR 2.0 (Mar 31, 2012)</title><link>http://mirror.codeplex.com/releases/view/84652</link><description>&lt;div class="wikidoc"&gt;&lt;b&gt;MIR-ROR 2.0&lt;/b&gt;&lt;br /&gt;The v.2.0 release incorporates many updates provided by Jon Mark Allen (contributing developer).&lt;br /&gt;Highlights include feature additions such as browser history collection, registry exports, prefetch view, recycle bin analysis, and 7z package creation.&lt;br /&gt;See Changelog.txt included in MIR-RORv2.0.zip for all changes.&lt;/div&gt;&lt;div class="ClearBoth"&gt;&lt;/div&gt;</description><author>RussMcRee</author><pubDate>Sat, 31 Mar 2012 23:53:04 GMT</pubDate><guid isPermaLink="false">Updated Release: MIR-ROR 2.0 (Mar 31, 2012) 20120331115304P</guid></item><item><title>Released: MIR-ROR 2.0 (Mar 31, 2012)</title><link>http://mirror.codeplex.com/releases/view/84652</link><description>
&lt;div class="wikidoc"&gt;&lt;b&gt;MIR-ROR 2.0&lt;/b&gt;&lt;br&gt;
The v.2.0 release incorporates many updates provided by Jon Mark Allen (contributing developer).&lt;br&gt;
Highlights include feature additions such as browser history collection, registry exports, prefetch view, recycle bin analysis, and 7z package creation.&lt;br&gt;
See Changelog.txt included in MIR-RORv2.0.zip for all changes.&lt;/div&gt;
&lt;div&gt;&lt;/div&gt;
</description><author></author><pubDate>Sat, 31 Mar 2012 23:53:04 GMT</pubDate><guid isPermaLink="false">Released: MIR-ROR 2.0 (Mar 31, 2012) 20120331115304P</guid></item><item><title>Updated Wiki: Home</title><link>http://mirror.codeplex.com/wikipage?version=6</link><description>&lt;div class="wikidoc"&gt;&lt;b&gt;STATUS&lt;/b&gt;&lt;br /&gt;While more attention is now being spent on Bryan&amp;#39;s &lt;a href="http://confessor.codeplex.com/" class="externalLink"&gt;Confessor&lt;span class="externalLinkIcon"&gt;&lt;/span&gt;&lt;/a&gt; development, we&amp;#39;ve benefited from Jon Mark Allen&amp;#39;s (ubahmapk) many contributions, giving MIR-ROR some much needed attention. Please feel free to submit via Issue Tracker and we&amp;#39;ll review potential updates for future releases. &lt;br /&gt;&lt;br /&gt;&lt;b&gt;Project Description&lt;/b&gt;&lt;br /&gt;MIR-ROR&amp;#58; Motile Incident Response &amp;#8211; Respond Objectively, Remediate &lt;br /&gt;MIR-ROR is a security incident response specialized, command-line script that calls specific Windows Sysinternals tools, as well as some other useful utilities, to provide live capture data for investigation.&lt;br /&gt;&lt;br /&gt;You can easily enhance MIR-ROR to your liking with whatever command line tools you find useful. &lt;br /&gt;For incident response resource, we’ve found it indispensable.&lt;br /&gt;Windows Systinternals licensing prevents us from bundling the tools in a distribution package; you’ll have to retrieve them. &lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/sysinternals/bb842062.aspx" class="externalLink"&gt;Download&lt;span class="externalLinkIcon"&gt;&lt;/span&gt;&lt;/a&gt; the complete Sysinternals Suite and unpack in a preferred directory on your system, then move the necessary tools listed in &lt;i&gt;fetch.txt&lt;/i&gt; to a directory you create: &lt;i&gt;C:\tools\MIR-ROR&lt;/i&gt;.&lt;br /&gt;&lt;br /&gt;You can read the complete ISSA Journal article, &lt;b&gt;MIR-ROR: Motile Incident Response – Respond Objectively, Remediate&lt;/b&gt;, &lt;a href="http://holisticinfosec.org/content/view/12/26/" class="externalLink"&gt;here&lt;span class="externalLinkIcon"&gt;&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Feel free to offer feedback; we hope this tool serves you well.&lt;br /&gt;&lt;br /&gt;Russ McRee&lt;br /&gt;Troy Larson&lt;br /&gt;Jon Mark Allen&lt;/div&gt;&lt;div class="ClearBoth"&gt;&lt;/div&gt;</description><author>RussMcRee</author><pubDate>Thu, 22 Mar 2012 06:24:29 GMT</pubDate><guid isPermaLink="false">Updated Wiki: Home 20120322062429A</guid></item><item><title>Closed Issue: Collect browser cookies [4593]</title><link>http://mirror.codeplex.com/workitem/4593</link><description>Copy IE and Firefox browser cookies from all user profiles.&lt;br /&gt;&lt;br /&gt;These cookies can then be inspected offline using Nirsoft&amp;#39;s IECookiesView or MozillaCookiesView&lt;br /&gt;&lt;br /&gt;http&amp;#58;&amp;#47;&amp;#47;www.nirsoft.net&amp;#47;utils&amp;#47;iecookies.html&lt;br /&gt;http&amp;#58;&amp;#47;&amp;#47;www.nirsoft.net&amp;#47;utils&amp;#47;mzcv.html&lt;br /&gt;&lt;br /&gt;&amp;#40;This modification currently depends on the alternate version detection code I listed in the version detection issue tracker thread, but can easily be modified if another method is used.&amp;#41;&lt;br /&gt;&lt;br /&gt;ECHO.&lt;br /&gt;ECHO &amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&lt;br /&gt;ECHO&amp;#9;Collecting Cookies.&lt;br /&gt;ECHO &amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&lt;br /&gt;ECHO.&lt;br /&gt;&lt;br /&gt;now.exe &amp;#91;Collecting Cookies.&amp;#93; &amp;#62;&amp;#62; &amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;MIR-ROR.log&lt;br /&gt;&lt;br /&gt;IF &amp;#37;OSNAME&amp;#37; &amp;#61;&amp;#61; XP GOTO XP_COOKIES&lt;br /&gt;IF &amp;#37;OSNAME&amp;#37; &amp;#61;&amp;#61; Vista GOTO VISTA_COOKIES&lt;br /&gt;GOTO SKIP_COOKIES&lt;br /&gt;&lt;br /&gt;&amp;#58;XP_COOKIES&lt;br /&gt;ECHO&amp;#9;Now collecting IE Cookies...&lt;br /&gt;for &amp;#47;F &amp;#37;&amp;#37;i in &amp;#40;&amp;#39;dir &amp;#47;b &amp;#34;c&amp;#58;&amp;#92;Documents and Settings&amp;#34;&amp;#39;&amp;#41; do &amp;#64;mkdir &amp;#34;&amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;&amp;#37;&amp;#37;i_cookies&amp;#34; &amp;#38; xcopy &amp;#47;e &amp;#47;c &amp;#47;q &amp;#47;i &amp;#47;g &amp;#47;h &amp;#47;y &amp;#34;c&amp;#58;&amp;#92;Documents and Settings&amp;#92;&amp;#37;&amp;#37;i&amp;#92;Cookies&amp;#34; &amp;#34;&amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;&amp;#37;&amp;#37;i_cookies&amp;#34; 2&amp;#62;&amp;#62; &amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;MIR-ROR.log&lt;br /&gt;&lt;br /&gt;IF NOT EXIST &amp;#34;C&amp;#58;&amp;#92;Program Files&amp;#92;Mozilla Firefox&amp;#34; GOTO FINISH_COOKIES&lt;br /&gt;ECHO    Now searching for Firefox profiles and gathering Firefox cookies.&lt;br /&gt;ECHO.&amp;#9;&lt;br /&gt;ECHO &amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&lt;br /&gt;ECHO  This may generate some &amp;#34;The system cannot find the &lt;br /&gt;ECHO  path specified&amp;#34; error messages if a user doesn&amp;#39;t  &lt;br /&gt;ECHO  have a Firefox profile.                          &lt;br /&gt;ECHO &amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&lt;br /&gt;ECHO.&lt;br /&gt;&lt;br /&gt;for &amp;#47;F &amp;#37;&amp;#37;u in &amp;#40;&amp;#39;dir &amp;#47;b &amp;#34;c&amp;#58;&amp;#92;Documents and Settings&amp;#34;&amp;#39;&amp;#41; do for &amp;#47;F &amp;#37;&amp;#37;p in &amp;#40;&amp;#39;dir &amp;#47;b &amp;#34;c&amp;#58;&amp;#92;Documents and Settings&amp;#92;&amp;#37;&amp;#37;u&amp;#92;Application Data&amp;#92;Mozilla&amp;#92;Firefox&amp;#92;Profiles&amp;#92;&amp;#34;&amp;#39;&amp;#41; do &amp;#64;copy &amp;#47;v &amp;#47;y &amp;#34;c&amp;#58;&amp;#92;Documents and Settings&amp;#92;&amp;#37;&amp;#37;u&amp;#92;Application Data&amp;#92;Mozilla&amp;#92;Firefox&amp;#92;Profiles&amp;#92;&amp;#37;&amp;#37;p&amp;#92;cookies.sqlite&amp;#34; &amp;#34;&amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;mzcv_&amp;#37;&amp;#37;u_&amp;#37;&amp;#37;p_cookies.sqlite&amp;#34; 2&amp;#62;&amp;#62; &amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;MIR-ROR.log  &lt;br /&gt;&lt;br /&gt;GOTO FINISH_COOKIES&lt;br /&gt;&lt;br /&gt;&amp;#58;VISTA_COOKIES&lt;br /&gt;ECHO&amp;#9;Now collecting IE Cookies...&lt;br /&gt;for &amp;#47;F &amp;#37;&amp;#37;i in &amp;#40;&amp;#39;dir &amp;#47;b c&amp;#58;&amp;#92;Users&amp;#39;&amp;#41; do &amp;#64;mkdir &amp;#34;&amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;&amp;#37;&amp;#37;i_cookies&amp;#34; &amp;#38; xcopy &amp;#47;e &amp;#47;c &amp;#47;q &amp;#47;i &amp;#47;g &amp;#47;h &amp;#47;y &amp;#34;c&amp;#58;&amp;#92;Users&amp;#92;&amp;#37;&amp;#37;i&amp;#92;AppData&amp;#92;Roaming&amp;#92;Microsoft&amp;#92;Windows&amp;#92;Cookies&amp;#34; &amp;#34;&amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;&amp;#37;&amp;#37;i_cookies&amp;#34; 2&amp;#62;&amp;#62; &amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;MIR-ROR.log&lt;br /&gt;&lt;br /&gt;IF NOT EXIST &amp;#34;C&amp;#58;&amp;#92;Program Files&amp;#92;Mozilla Firefox&amp;#34; GOTO FINISH_COOKIES&lt;br /&gt;ECHO    Now searching for Firefox profiles and gathering Firefox cookies.&lt;br /&gt;ECHO.&amp;#9;&lt;br /&gt;ECHO &amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&lt;br /&gt;ECHO  This may generate some &amp;#34;The system cannot find the &lt;br /&gt;ECHO  path specified&amp;#34; error messages if a user doesn&amp;#39;t  &lt;br /&gt;ECHO  have a Firefox profile.                          &lt;br /&gt;ECHO &amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&lt;br /&gt;ECHO.&lt;br /&gt;&lt;br /&gt;for &amp;#47;F &amp;#37;&amp;#37;u in &amp;#40;&amp;#39;dir &amp;#47;b c&amp;#58;&amp;#92;Users&amp;#39;&amp;#41; do for &amp;#47;F &amp;#37;&amp;#37;p in &amp;#40;&amp;#39;dir &amp;#47;b c&amp;#58;&amp;#92;Users&amp;#92;&amp;#37;&amp;#37;u&amp;#92;AppData&amp;#92;Roaming&amp;#92;Mozilla&amp;#92;Firefox&amp;#92;Profiles&amp;#92;&amp;#39;&amp;#41; do &amp;#64;copy &amp;#47;v &amp;#47;y &amp;#34;c&amp;#58;&amp;#92;Users&amp;#92;&amp;#37;&amp;#37;u&amp;#92;AppData&amp;#92;Roaming&amp;#92;Mozilla&amp;#92;Firefox&amp;#92;Profiles&amp;#92;&amp;#37;&amp;#37;p&amp;#92;cookies.sqlite&amp;#34; &amp;#34;&amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;mzcv_&amp;#37;&amp;#37;u_&amp;#37;&amp;#37;p_cookies.sqlite&amp;#34; 2&amp;#62;&amp;#62; &amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;MIR-ROR.log  &lt;br /&gt;&lt;br /&gt;GOTO FINISH_COOKIES&lt;br /&gt;&lt;br /&gt;&amp;#58;SKIP_COOKIES&lt;br /&gt;ECHO&amp;#9;Unable to locate Cookie directories.&lt;br /&gt;now.exe &amp;#91;Unable to locate Cookie directories.&amp;#93; &amp;#62;&amp;#62; &amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;MIR-ROR.log&lt;br /&gt;&lt;br /&gt;&amp;#58;FINISH_COOKIES&lt;br /&gt;Comments: &lt;p&gt;Update included in 2.0 stable release.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><author>RussMcRee</author><pubDate>Thu, 22 Mar 2012 06:22:12 GMT</pubDate><guid isPermaLink="false">Closed Issue: Collect browser cookies [4593] 20120322062212A</guid></item><item><title>Closed Issue: Ability to double-click mirror.cmd from Windows Explorer [4588]</title><link>http://mirror.codeplex.com/workitem/4588</link><description>Since many of our techs shy away from the DOS prompt and they are the ones running the script for my analysis, I added the ability to double-click the mirror.cmd file and prompt for the required drive letters.  This modification still supports passing the drive letters from the DOS prompt.&lt;br /&gt;&lt;br /&gt;Created a &amp;#37;VERSION&amp;#37; variable, as we&amp;#39;ve made a few internal modifications.  This helps us keep track of which version is running.&lt;br /&gt;Created a &amp;#37;TOOLSDIR&amp;#37; variable, so the path can easily be changed, if necessary.&lt;br /&gt;&lt;br /&gt;I also added &amp;#37;LOGS&amp;#37; and &amp;#37;TOOLS&amp;#37; variables, and made the required modifications when calling the various .exe&amp;#39;s and logging paths. &amp;#40;more as a readability thing, really&amp;#41;&lt;br /&gt;&lt;br /&gt;SET VERSION&amp;#61;1.2.3&lt;br /&gt;SET TOOLSDIR&amp;#61;&amp;#92;tools&amp;#92;MIRROR&lt;br /&gt;&lt;br /&gt;if &amp;#34;&amp;#37;1&amp;#34;&amp;#61;&amp;#61;&amp;#34;&amp;#34; goto GetTools&lt;br /&gt;SET TOOLS&amp;#61;&amp;#37;1&lt;br /&gt;&lt;br /&gt;if &amp;#34;&amp;#37;2&amp;#34;&amp;#61;&amp;#61;&amp;#34;&amp;#34; goto GetLogs&lt;br /&gt;SET LOGS&amp;#61;&amp;#37;2&lt;br /&gt;&lt;br /&gt;goto SkipPrompts&lt;br /&gt;&lt;br /&gt;&amp;#58;GetTools&lt;br /&gt;ECHO.&lt;br /&gt;ECHO &amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&lt;br /&gt;ECHO Please enter the drive letter where the tools are located&lt;br /&gt;SET &amp;#47;P TOOLS&amp;#61; &amp;#40;typically a USB stick&amp;#41;&amp;#58; &lt;br /&gt;&lt;br /&gt;&amp;#58;GetLogs&lt;br /&gt;ECHO.&lt;br /&gt;ECHO &amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&lt;br /&gt;ECHO Please enter the drive letter where the logs should be stored&lt;br /&gt;SET &amp;#47;P LOGS&amp;#61; &amp;#40;typically the same USB stick&amp;#41;&amp;#58; &lt;br /&gt;&lt;br /&gt;&amp;#58;SkipPrompts&lt;br /&gt;&lt;br /&gt;REM&amp;#9;Adds &amp;#37;TOOLS&amp;#37;&amp;#92;Tools directory to the path for the execution of&lt;br /&gt;REM&amp;#9;the programs in the script.&lt;br /&gt;SET PATH&amp;#61;&amp;#37;TOOLS&amp;#37;&amp;#58;&amp;#37;TOOLSDIR&amp;#37;&amp;#59;&amp;#37;PATH&amp;#37;&lt;br /&gt;&lt;br /&gt;REM&amp;#9;Creates evidence collection folders.&lt;br /&gt;mkdir &amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&lt;br /&gt;&lt;br /&gt;CLS&lt;br /&gt;&lt;br /&gt;ECHO.&lt;br /&gt;ECHO &amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&lt;br /&gt;ECHO MIR-ROR live data capture is ready to begin.&lt;br /&gt;ECHO.&lt;br /&gt;ECHO Version &amp;#37;VERSION&amp;#37;&lt;br /&gt;ECHO.&lt;br /&gt;ECHO There may be slight delay depending on system type.&lt;br /&gt;ECHO.&lt;br /&gt;ECHO.&lt;br /&gt;ECHO Tools path is&amp;#58; &amp;#37;TOOLS&amp;#37;&amp;#58;&amp;#37;TOOLSDIR&amp;#37;&lt;br /&gt;ECHO Log path is  &amp;#58; &amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&lt;br /&gt;ECHO.&lt;br /&gt;ECHO &amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&lt;br /&gt;ECHO.&lt;br /&gt;&lt;br /&gt;pause&lt;br /&gt;Comments: &lt;p&gt;Update included in 2.0 stable release.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><author>RussMcRee</author><pubDate>Thu, 22 Mar 2012 06:20:55 GMT</pubDate><guid isPermaLink="false">Closed Issue: Ability to double-click mirror.cmd from Windows Explorer [4588] 20120322062055A</guid></item><item><title>Closed Issue: Gather information on attached USB devices [4590]</title><link>http://mirror.codeplex.com/workitem/4590</link><description>Copy USB log files and related registry keys.&lt;br /&gt;&lt;br /&gt;Version is required for this modification as the file system paths for the setupapi.log file are different for XP vs Vista or Win7.&lt;br /&gt;&lt;br /&gt;&amp;#40;This modification currently depends on the alternate version detection code I listed in the version detection issue tracker thread, but can easily be modified if another method is used.&amp;#41;&lt;br /&gt;&lt;br /&gt;ECHO.&lt;br /&gt;ECHO &amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&lt;br /&gt;ECHO  Gathering information about USB devices&lt;br /&gt;ECHO &amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&lt;br /&gt;ECHO.&lt;br /&gt;now.exe &amp;#91;Gathering information about USB devices.&amp;#93; &amp;#62;&amp;#62; &amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;MIR-ROR.log&lt;br /&gt;&lt;br /&gt;ECHO&amp;#9;Copying setupapi Logs.&lt;br /&gt;now.exe &amp;#91;Copying setupapi logs.&amp;#93; &amp;#62;&amp;#62; &amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;MIR-ROR.log&lt;br /&gt;&lt;br /&gt;if &amp;#37;OSNAME&amp;#37; &amp;#61;&amp;#61; XP Goto XP_USB_Setup_API&lt;br /&gt;if &amp;#37;OSNAME&amp;#37; &amp;#61;&amp;#61; Vista Goto Vista_USB_Setup_API&lt;br /&gt;&lt;br /&gt;&amp;#58;XP_USB_Setup_API&lt;br /&gt;copy &amp;#47;v &amp;#47;d C&amp;#58;&amp;#92;Windows&amp;#92;setupapi.&amp;#42; &amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;&lt;br /&gt;Goto USB_Setup_API_Done&lt;br /&gt;&lt;br /&gt;&amp;#58;Vista_USB_Setup_API&lt;br /&gt;copy &amp;#47;v &amp;#47;d C&amp;#58;&amp;#92;Windows&amp;#92;inf&amp;#92;setupapi.&amp;#42; &amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;&lt;br /&gt;Goto USB_Setup_API_Done&lt;br /&gt;&lt;br /&gt;&amp;#58;USB_Setup_API_Done&lt;br /&gt;&lt;br /&gt;ECHO&amp;#9;Exporting USB Registry keys.&lt;br /&gt;now.exe &amp;#91;Exporting USB Registry keys.&amp;#93; &amp;#62;&amp;#62; &amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;MIR-ROR.log&lt;br /&gt;reg export hklm&amp;#92;system&amp;#92;currentcontrolset&amp;#92;enum&amp;#92;usbstor &amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;usbstor.reg&lt;br /&gt;reg export hklm&amp;#92;system&amp;#92;currentcontrolset&amp;#92;enum&amp;#92;usb &amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;usb.reg&lt;br /&gt;Comments: &lt;p&gt;Update included in 2.0 stable release.&lt;/p&gt;</description><author>RussMcRee</author><pubDate>Thu, 22 Mar 2012 06:14:55 GMT</pubDate><guid isPermaLink="false">Closed Issue: Gather information on attached USB devices [4590] 20120322061455A</guid></item><item><title>Closed Issue: NirSoft Prefetch View [4589]</title><link>http://mirror.codeplex.com/workitem/4589</link><description>Added Nirsoft&amp;#39;s WinPrefetch View utility.  This should be the first utility run, since subsequent  commands can muddy the water of recently run programs.  Notice that even the now.exe command runs &amp;#42;after&amp;#42; winprefetchview.exe is complete.&lt;br /&gt;&lt;br /&gt;Utility is available at&amp;#58; http&amp;#58;&amp;#47;&amp;#47;www.nirsoft.net&amp;#47;utils&amp;#47;win_prefetch_view.html.  This is also freely distributable per Nirsoft&amp;#39;s license, so long as there is no charge and all files are included.&lt;br /&gt;&lt;br /&gt;ECHO.&lt;br /&gt;ECHO Reviewing Prefetch information as early as possible,&lt;br /&gt;ECHO  so that subsequent commands don&amp;#39;t remove potentially valuable information&lt;br /&gt;ECHO.&lt;br /&gt;&lt;br /&gt;REM ECHO&amp;#9;Running WinPrefetchView on the Prefetch directory.&lt;br /&gt;winprefetchview.exe &amp;#47;shtml &amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;winpf_view.html &amp;#47;sort &amp;#34;&amp;#126;Modified Time&amp;#34;&lt;br /&gt;now.exe &amp;#91;Completed WinPrefetchView on the Prefetch directory.&amp;#93; &amp;#62; &amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;MIR-ROR.log&lt;br /&gt;Comments: &lt;p&gt;Update included in 2.0 stable release.&lt;/p&gt;</description><author>RussMcRee</author><pubDate>Thu, 22 Mar 2012 06:14:41 GMT</pubDate><guid isPermaLink="false">Closed Issue: NirSoft Prefetch View [4589] 20120322061441A</guid></item><item><title>Closed Issue: Collect browser history [4592]</title><link>http://mirror.codeplex.com/workitem/4592</link><description>Uses Nirsoft&amp;#39;s Internet Explorer History Viewer &amp;#40;iehv&amp;#41; and Mozilla History Viewer &amp;#40;ffhv&amp;#41; to pull the Internet browser history for all user profiles.&lt;br /&gt;&lt;br /&gt;Checks to see if Firefox is installed before running Mozilla History Viewer&lt;br /&gt;&lt;br /&gt;&amp;#40;This modification currently depends on the alternate version detection code I listed in the version detection issue tracker thread, but can easily be modified if another method is used.&amp;#41;&lt;br /&gt;&lt;br /&gt;Nirsoft&amp;#39;s IEHV is available at&amp;#58; http&amp;#58;&amp;#47;&amp;#47;www.nirsoft.net&amp;#47;utils&amp;#47;iehv.html&lt;br /&gt;Nirsoft&amp;#39;s FFHV is available at&amp;#58; http&amp;#58;&amp;#47;&amp;#47;www.nirsoft.net&amp;#47;utils&amp;#47;mozilla_history_view.html&lt;br /&gt;&lt;br /&gt;ECHO.&lt;br /&gt;ECHO &amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&lt;br /&gt;ECHO  This section will gather information from various browsers installed &lt;br /&gt;ECHO  on the system.&lt;br /&gt;ECHO &amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&amp;#42;&lt;br /&gt;ECHO.&lt;br /&gt;now.exe &amp;#91;Now gathering information from various browsers installed on the system.&amp;#93; &amp;#62;&amp;#62; &amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;MIR-ROR.log&lt;br /&gt;&lt;br /&gt;ECHO&amp;#9;Running iehv on &amp;#37;COMPUTERNAME&amp;#37;.&lt;br /&gt;now.exe&amp;#9;&amp;#91;Running iehv on &amp;#37;COMPUTERNAME&amp;#37;.&amp;#93; &amp;#62;&amp;#62; &amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;MIR-ROR.log&lt;br /&gt;&lt;br /&gt;IF &amp;#37;OSNAME&amp;#37; &amp;#61;&amp;#61; XP GOTO iehv_XP&lt;br /&gt;IF &amp;#37;OSNAME&amp;#37; &amp;#61;&amp;#61; Vista GOTO iehv_VISTA&lt;br /&gt;GOTO SKIP&lt;br /&gt;&lt;br /&gt;&amp;#58;iehv_XP&lt;br /&gt;for &amp;#47;F &amp;#37;&amp;#37;i in &amp;#40;&amp;#39;dir &amp;#47;b &amp;#34;c&amp;#58;&amp;#92;Documents and Settings&amp;#34;&amp;#39;&amp;#41; do iehv.exe &amp;#47;stab &amp;#34;&amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;iehv_&amp;#37;&amp;#37;i.csv&amp;#34; -user &amp;#34;&amp;#37;&amp;#37;i&amp;#34; 2&amp;#62;&amp;#62; &amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;MIR-ROR.log &lt;br /&gt;GOTO FINISH_IEHV&lt;br /&gt;&lt;br /&gt;&amp;#58;iehv_VISTA&lt;br /&gt;for &amp;#47;F &amp;#37;&amp;#37;i in &amp;#40;&amp;#39;dir &amp;#47;b c&amp;#58;&amp;#92;Users&amp;#39;&amp;#41; do iehv.exe &amp;#47;stab &amp;#34;&amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;iehv_&amp;#37;&amp;#37;i.csv&amp;#34; -user &amp;#34;&amp;#37;&amp;#37;i&amp;#34; 2&amp;#62;&amp;#62; &amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;MIR-ROR.log  &lt;br /&gt;GOTO FINISH_IEHV&lt;br /&gt;&lt;br /&gt;&amp;#58;SKIP&lt;br /&gt;ECHO    Unable to determine Windows version - Skipped iehv.&lt;br /&gt;now.exe &amp;#91;Unable to determine Windows version - Skipped iehv.&amp;#93; &amp;#62;&amp;#62; &amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;MIR-ROR.log&lt;br /&gt;&lt;br /&gt;&amp;#58;FINISH_IEHV&lt;br /&gt;&lt;br /&gt;ECHO    Test to see if Firefox is installed&lt;br /&gt;now.exe &amp;#91;Test to see if Firefox is installed.&amp;#93; &amp;#62;&amp;#62; &amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;MIR-ROR.log&lt;br /&gt;IF NOT EXIST &amp;#34;C&amp;#58;&amp;#92;Program Files&amp;#92;Mozilla Firefox&amp;#34; GOTO SKIP&lt;br /&gt;&lt;br /&gt;now.exe &amp;#91;Searching for Firefox profiles and running MozillaHistoryView on &amp;#37;COMPUTERNAME&amp;#37;.&amp;#93; &amp;#62;&amp;#62; &amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;MIR-ROR.log&lt;br /&gt;ECHO    Now searching for Firefox profiles and running MozillaHistoryView.&lt;br /&gt;ECHO.&amp;#9;&lt;br /&gt;ECHO &amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&lt;br /&gt;ECHO  This may generate some &amp;#34;The system cannot find the &lt;br /&gt;ECHO  path specified&amp;#34; error messages if a user doesn&amp;#39;t  &lt;br /&gt;ECHO  have a Firefox profile.                          &lt;br /&gt;ECHO &amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&amp;#33;&lt;br /&gt;ECHO.&lt;br /&gt;&lt;br /&gt;IF &amp;#37;OSNAME&amp;#37; &amp;#61;&amp;#61; XP GOTO ffhv_XP&lt;br /&gt;IF &amp;#37;OSNAME&amp;#37; &amp;#61;&amp;#61; Vista GOTO ffhv_VISTA&lt;br /&gt;GOTO SKIP&lt;br /&gt;&lt;br /&gt;&amp;#58;ffhv_XP&lt;br /&gt;REM     Here, &amp;#37;&amp;#37;u is the list of Users on the system&lt;br /&gt;REM     and &amp;#37;&amp;#37;p is the list of profile directories for each user&lt;br /&gt;REM     This may generate some &amp;#34;The system cannot find the path specified&amp;#34; error messages&lt;br /&gt;REM     if a user doesn&amp;#39;t have a Firefox profile&lt;br /&gt;&lt;br /&gt;for &amp;#47;F &amp;#37;&amp;#37;u in &amp;#40;&amp;#39;dir &amp;#47;b &amp;#34;c&amp;#58;&amp;#92;Documents and Settings&amp;#34;&amp;#39;&amp;#41; do for &amp;#47;F &amp;#37;&amp;#37;p in &amp;#40;&amp;#39;dir &amp;#47;b &amp;#34;c&amp;#58;&amp;#92;Documents and Settings&amp;#92;&amp;#37;&amp;#37;u&amp;#92;Application Data&amp;#92;Mozilla&amp;#92;Firefox&amp;#92;Profiles&amp;#92;&amp;#34;&amp;#39;&amp;#41; do &amp;#64;MozillaHistoryView.exe &amp;#47;stab &amp;#34;&amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;ffhv_&amp;#37;&amp;#37;u_&amp;#37;&amp;#37;p.csv&amp;#34; -file &amp;#34;c&amp;#58;&amp;#92;Documents and Settings&amp;#92;&amp;#37;&amp;#37;u&amp;#92;Application Data&amp;#92;Mozilla&amp;#92;Firefox&amp;#92;Profiles&amp;#92;&amp;#37;&amp;#37;p&amp;#92;places.sqlite&amp;#34; 2&amp;#62;&amp;#62; &amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;MIR-ROR.log  &lt;br /&gt;GOTO FINISH_FFHV&lt;br /&gt;&lt;br /&gt;&amp;#58;ffhv_VISTA&lt;br /&gt;for &amp;#47;F &amp;#37;&amp;#37;u in &amp;#40;&amp;#39;dir &amp;#47;b c&amp;#58;&amp;#92;Users&amp;#39;&amp;#41; do for &amp;#47;F &amp;#37;&amp;#37;p in &amp;#40;&amp;#39;dir &amp;#47;b c&amp;#58;&amp;#92;Users&amp;#92;&amp;#37;&amp;#37;u&amp;#92;AppData&amp;#92;Roaming&amp;#92;Mozilla&amp;#92;Firefox&amp;#92;Profiles&amp;#92;&amp;#39;&amp;#41; do &amp;#64;MozillaHistoryView.exe &amp;#47;stab &amp;#34;&amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;ffhv_&amp;#37;&amp;#37;u_&amp;#37;&amp;#37;p.csv&amp;#34; -file &amp;#34;c&amp;#58;&amp;#92;Users&amp;#92;&amp;#37;&amp;#37;u&amp;#92;AppData&amp;#92;Roaming&amp;#92;Mozilla&amp;#92;Firefox&amp;#92;Profiles&amp;#92;&amp;#37;&amp;#37;p&amp;#92;places.sqlite&amp;#34; 2&amp;#62;&amp;#62; &amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;MIR-ROR.log  &lt;br /&gt;GOTO FINISH_FFHV&lt;br /&gt;&lt;br /&gt;&amp;#58;SKIP&lt;br /&gt;ECHO    Firefox doesn&amp;#39;t seem to be installed.  MozillaHistoryView skipped.&lt;br /&gt;now.exe &amp;#91;Firefox doesn&amp;#39;t seem to be installed - MozillaHistoryView skipped.&amp;#93; &amp;#62;&amp;#62; &amp;#37;LOGS&amp;#37;&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;MIR-ROR.log&lt;br /&gt;&lt;br /&gt;&amp;#58;FINISH_FFHV&lt;br /&gt;Comments: &lt;p&gt;Update included in 2.0 stable release.&lt;/p&gt;</description><author>RussMcRee</author><pubDate>Thu, 22 Mar 2012 06:14:26 GMT</pubDate><guid isPermaLink="false">Closed Issue: Collect browser history [4592] 20120322061426A</guid></item><item><title>Closed Issue: serverinfo.log file overwritten [2779]</title><link>http://mirror.codeplex.com/workitem/2779</link><description>Line 150 overwrites the server.log file created in Line 146.&lt;br /&gt;&lt;br /&gt;Changing the &amp;#34;&amp;#62;&amp;#34; to a &amp;#34;&amp;#62;&amp;#62;&amp;#34; resolves this issue.&lt;br /&gt;&lt;br /&gt;--- tmp&amp;#47;MIR-ROR.txt&amp;#9;2009-10-12 10&amp;#58;25&amp;#58;09.000000000 -0500&lt;br /&gt;&amp;#43;&amp;#43;&amp;#43; Tools&amp;#47;MIR-ROR&amp;#47;MIR-ROR.txt&amp;#9;2009-10-12 10&amp;#58;25&amp;#58;25.000000000 -0500&lt;br /&gt;&amp;#64;&amp;#64; -147,7 &amp;#43;147,7 &amp;#64;&amp;#64;&lt;br /&gt; &lt;br /&gt; ECHO&amp;#9;Running srvinfo.exe on &amp;#37;COMPUTERNAME&amp;#37;.&lt;br /&gt; now.exe &amp;#91;Running srvinfo.exe -d on &amp;#37;COMPUTERNAME&amp;#37;.&amp;#93; &amp;#62;&amp;#62; &amp;#37;2&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;MIR-ROR.log&lt;br /&gt;-srvinfo.exe -d &amp;#62; &amp;#37;2&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;server.log&lt;br /&gt;&amp;#43;srvinfo.exe -d &amp;#62;&amp;#62; &amp;#37;2&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;server.log&lt;br /&gt; &lt;br /&gt; ECHO&amp;#9;Running Systeminfo on &amp;#37;COMPUTERNAME&amp;#37;.&lt;br /&gt; now.exe &amp;#91;Running Systeminfo on &amp;#37;COMPUTERNAME&amp;#37;.&amp;#93; &amp;#62;&amp;#62; &amp;#37;2&amp;#58;&amp;#92;Livecap_&amp;#37;COMPUTERNAME&amp;#37;&amp;#92;MIR-ROR.log&lt;br /&gt;Comments: &lt;p&gt;Update included in 2.0 stable release.&lt;/p&gt;</description><author>RussMcRee</author><pubDate>Thu, 22 Mar 2012 06:14:11 GMT</pubDate><guid isPermaLink="false">Closed Issue: serverinfo.log file overwritten [2779] 20120322061411A</guid></item></channel></rss>