Friday, November 8, 2013

How to delete a file in Windows with a too long filename?

Solution 1)
From a command prompt:

dir /X

This will list your files or folders in short name format. Then use the short name exactly as written to delete the file:

del LONGFI~1.txt

you are done!  :)
 
Solution 2)
Try this in a Command Prompt.
rd /s first_part_of_subdirectory_name

e.g. if the file is called "C:\temp\Files\verylongfilenames.ext"
rd /s C:\temp\Files
 

Monday, October 28, 2013

What is Encase "Lost Files" folder

This was posted by Jeffery Misner. I want to give credit for the source.

What is the Lost Files folder?


EnCase has a different method (compared to FAT) for recovering deleted files and folders with NTFS evidence files. When you add an NTFS Evidence file to EnCase, you will notice a folder added automatically to the evidence file in the case view called "Lost Files." In the MFT (Master File Table) in NTFS, all files and folders are marked as a folder or file, and are associated to a "parent."

Suppose you have a folder contain many files. Those files are its "children." For those files to become "lost," you delete them along with the folder itself. You then create a new folder. The entry in the MFT for the old folder is overwritten. So the original "parent" folder and its entry in the MFT are gone. But it's "children," while deleted, have not been overwritten, and their entries are still in the MFT. EnCase can then tell what those files are, but there is no longer any record of what folder those files were in. Because of this, all those files (without parent folders anymore) are lumped into the "Lost Files" folder that EnCase creates and places in the Entries view so that you can see those files.

That is different from the recover folders feature, btw. Also note that Lost Files only appear for NTFS volumes since FAT does not work the same way.

Note: There is no way you can see those deleted files without using specialized software like EnCase.

Original source link : http://www.forensicfocus.com/Forums/viewtopic/t=2718/

Thursday, September 26, 2013

How to get hard drive serial number from command line on Windows computer?

Get the Manufacturers serial number of the hard drive.

    C:\>wmic diskdrive get serialnumber

Get the volume serial number:

    C:\>vol C:

Get Drive Info:

    C:>wmic diskdrive list brief
   
Get service tag report:

    C:>wmic csproduct get name,vendor,identifyingNumber



Determine when Windows was installed on a computer

    C:\>wmic OS Get InstallDate
InstallDate
20091204171103.000000+480

You can easly read the above output adding the relevant markup: 2011-02-14 13:36:58

The install date is stored in the registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\InstallDate as UNIX time
 (32-bit value containing the number of seconds since 1/1/1970).
 

For more info get it at :
http://blogs.technet.com/b/askperf/archive/2012/02/17/useful-wmic-queries.aspx
http://theinterw3bs.com/wiki/index.php?title=WMIC_Commands
http://travisaltman.com/one-liner-commands-for-windows-cheat-sheet/

Monday, April 1, 2013

MS Outlook Data File (*.pst) Location in NTUSER.DAT

MS Outlook Data file (*.pst) location in NTUSER.DAT
HKEY_CURRENT_USER\Software\Microsoft\Office\[versionNumber]\Outlook\Catalog


Sample:
MS Outlook 2007
HKEY_CURRENT_USER\Software\Microsoft\Office\12.0\Outlook\Catalog

MS Outlook 2010
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Search
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Search\Catalog

Other Location:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\PST

Friday, March 22, 2013

EnCase Date Formats:

Encase reports these dates in the following manner as below:-

Windows "File Created" = EnCase  “File Created”
Windows "File Modified" = Encase “Last Written”
Windows "File Accessed" = EnCase  “Last Accessed”
Windows "MTF last written" = Encase “Entry Modified”
Windows "INFO2 file deleted date/time" = Encase "File Deleted"


Source URL:
http://whereismydata.wordpress.com/2009/04/10/forensics-what-does-entry-modified-mean-in-encase/

http://whereismydata.wordpress.com/2009/02/14/dates-ntfs-created-modified-accessed-written/

https://whereismydata.wordpress.com/tag/entry-modified/

Tuesday, September 11, 2012

Location of Browser Data

Extract from this URL :  http://kb.digital-detective.co.uk/display/NetAnalysis1/Location+of+Browser+Data

Microsoft Internet Explorer
Microsoft Windows XP
Cookies
C:\Documents and Settings\{user}\Cookies\index.dat

History
C:\Documents and Settings\{user}\Local Settings\History\History.IE5\index.dat
C:\Documents and Settings\{user}\Local Settings\History\History.IE5\MSHist01YYYYMMDDYYYYMMDD\index.dat

Cache
C:\Documents and Settings\{user}\Local Settings\Temporary Internet Files\Content.IE5\index.dat

Other
C:\Documents and Settings\{user}\IETldCache\index.dat
C:\Documents and Settings\{user}\PrivacIE\index.dat
C:\Documents and Settings\{user}\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat
C:\Documents and Settings\{user}\Local Settings\Application Data\Microsoft\Internet Explorer\DOMStore\index.dat

Microsoft Windows Vista / 7
AppData\Local\Microsoft
C:\Users\{user}\AppData\Local\Microsoft\Feeds Cache\index.dat
C:\Users\{user}\AppData\Local\Microsoft\Internet Explorer\DOMStore\index.dat

AppData\Local\Microsoft\Windows\History
C:\Users\{user}\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
C:\Users\{user}\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist01YYYYMMDDYYYYMMDD\index.dat
C:\Users\{user}\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.dat

AppData\Local\Microsoft\Windows\Temporary Internet Files
C:\Users\{user}\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
C:\Users\{user}\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat

AppData\Local\Temp\Low
C:\Users\{user}\AppData\Local\Temp\Low\Cookies\index.dat
C:\Users\{user}\AppData\Local\Temp\Low\History\History.IE5\index.dat
C:\Users\{user}\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5\index.dat

AppData\LocalLow
C:\Users\{user}\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\index.dat

AppData\Roaming
C:\Users\{user}\AppData\Roaming\Microsoft\Internet Explorer\UserData\index.dat
C:\Users\{user}\AppData\Roaming\Microsoft\Internet Explorer\UserData\Low\index.dat
C:\Users\{user}\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
C:\Users\{user}\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.dat
C:\Users\{user}\AppData\Roaming\Microsoft\Windows\IECompatCache\index.dat
C:\Users\{user}\AppData\Roaming\Microsoft\Windows\IECompatCache\Low\index.dat
C:\Users\{user}\AppData\Roaming\Microsoft\Windows\IEDownloadHistory\index.dat
C:\Users\{user}\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
C:\Users\{user}\AppData\Roaming\Microsoft\Windows\IETldCache\Low\index.dat
C:\Users\{user}\AppData\Roaming\Microsoft\Windows\PrivacIE\index.dat
C:\Users\{user}\AppData\Roaming\Microsoft\Windows\PrivacIE\Low\index.dat

Apple Safari

Microsoft Windows XP

History
C:\Documents and Settings\{user}\Application Data\Apple Computer\Safari\
Cache
C:\Documents and Settings\{user}\Local Settings\Application Data\Apple Computer\Safari\
Microsoft Windows Vista / 7

History
C:\Users\{user}\AppData\Roaming\Apple Computer\Safari\

Cache
C:\Users\{user}\AppData\Local\Apple Computer\Safari\

Apple Macintosh OS X 10.6

History
/Users/{user}/Library/Safari/
Cache
/Users/{user}/Library/Caches/com.apple.Safari/

Mozilla Firefox
Microsoft Windows XP

History and Downloads
C:\Documents and Settings\{user}\Application Data\Mozilla\Firefox\Profiles\{profile folder}\
Cache
C:\Documents and Settings\{user}\Local Settings\Application Data\Mozilla\Firefox\Profiles\{profile folder}\Cache\

Microsoft Windows Vista / 7

History and Downloads
C:\Users\{user}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile folder}\
Cache
C:\Users\{user}\AppData\Local\Mozilla\Firefox\Profiles\{profile folder}\Cache\

Apple Macintosh OS X 10.6

History and Downloads
/Users/{user}/Library/Application Support/Firefox/Profiles/{profile folder}/

Cache
/Users/{user}/Library/Caches/Firefox/Profiles/{profile folder}/Cache/

GNU / Linux
History and Downloads
/home/{user}/.mozilla/firefox/{profile folder}/
Cache
/home/{user}/.mozilla/firefox/{profile folder}/Cache/

Google Chrome
Microsoft Windows XP
History
C:\Documents and Settings\{user}\Local Settings\Application Data\Google\Chrome\User Data\Default\
Cache
C:\Documents and Settings\{user}\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache\

Microsoft Windows Vista / 7

History
C:\Users\{user}\AppData\Local\Google\Chrome\User Data\Default\
Cache
C:\Users\{user}\AppData\Local\Google\Chrome\User Data\Default\Cache\


Apple Macintosh OS X 10.6
History
/Users/{user}/Library/Application Support/Google/Chrome/Default/
Cache
/Users/{user}/Library/Caches/Google/Chrome/Default/Cache/


GNU / Linux
History
/home/{user}/.config/google-chrome/Default/
Cache
/home/{user}/.cache/google-chrome/Default/Cache/

Opera Browser
Microsoft Windows XP
History
C:\Documents and Settings\{user}\Application Data\Opera\Opera\
Cache
C:\Documents and Settings\{user}\Local Settings\Application Data\Opera\Opera\cache\

Microsoft Windows Vista / 7
History
C:\Users\{user}\AppData\Roaming\Opera\Opera\
Cache
C:\Users\{user}\AppData\Local\Opera\Opera\cache\

Apple Macintosh OS X 10.6
History
/Users/{user}/Library/Opera/
Cache
/Users/{user}/Library/Caches/Opera/cache/

GNU / Linux
History
/home/{user}/.opera/
Cache
/home/{user}/.opera/cache/

Wednesday, August 8, 2012

How to Export Events Log including "Event Description" from Windows Event Viewer

This is how you can get the details Event Log Description from Windows Event Viewer. The script is available on Windows OS.

cscript c:\windows\system32\eventquery.vbs /fi "Type eq Information" /fi "Source eq Print" /fi "ID eq 10" /v  /l System /fo csv > Event_Viewer_System.csv

The syntax I used was to filter (/fi) out
    Events equal the type “Information”
    filter out Source equal to “Print”
    filter out ID equal “10"    and have a verbose (/v) output
    from the System log (/l System)
    output as comma separated file (/fo)
    and redirect the result to a file > filename.csv
Sample File Output:
"Information","10","12.05.2009 13:24:48","Print","Servername","None","AD\username","Document 232, filename.pdf owned by username was printed on printername via port IP_192.168.0.254. Size in bytes: 279232; pages printed: 1"

This method also can be use to export from any Event Viewer data log like Application, Security, Internet Explorer or other logs you have on your system.

Source URL: http://technet.microsoft.com/en-us/library/bb490900.aspx

Source URL : http://pario.no/2009/05/13/exporting-events-including-event-properties-from-windows-event-viewer/

Source URL: http://pario.no/2009/05/15/simple-windows-print-accounting-using-event-viewer-data/