Solved

Search containing two wildcards across multiple PCs

Posted on 2012-03-14
4
277 Views
Last Modified: 2012-03-19
Hi,

I'd like to perform the following search query on every running PC in our windows domain and like to have the results aggregated in one file: c:\Users\*\AppData\Local\Temp\*.exe
How can I achieve this using standard tools?

Regards,
Andreas
0
Comment
Question by:braunmiller
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
4 Comments
 
LVL 16

Accepted Solution

by:
ThinkPaper earned 125 total points
ID: 37726603
if you plan on using "standard tools" without using outside products, the only way I can think of doing this is using a script. Note that either way, this will be very time intensive as it will do a search for ALL machines that you specify.

You can use something of a VBS or powershell script to do the job:

http://www.activexperts.com/activmonitor/windowsmanagement/scripts/storage/filesystems/#SFUWQ.htm
0
 
LVL 8

Expert Comment

by:Brent Challis
ID: 37731797
Can you provide an example of your search query to inicate what information you are after from the computers?
0
 
LVL 15

Assisted Solution

by:qz8dsw
qz8dsw earned 125 total points
ID: 37732007
braunmiller,
ThinkPaper was correct, you can do this via VBS or windows scripting and his link gives good information on checking files.
But you will also beforehand need to enumerate the domain computers, check if they are up and if they are then run the check for exe's.

Checking all machines on a domain makes it difficult, better to have a part of the login script call the script that itterates through looking for c:\Users\*\AppData\Local\Temp\*.exe
Login scripts for the domain should run with admin access and hence have access to all profiles.
Are you just after the script with this question?
0
 

Author Closing Comment

by:braunmiller
ID: 37736585
Thank you all for the answers. We came across a trojan (troj_ransom.vtg) that seems to be inactive but we would like to know where it has spread it's component files. We know some file names and locations in c:\Users\<username>\AppData\Local\ and would have liked to know what clients still contain these files.
We will try the combined solution of using a custom VBS script being executed upon a user's domain login so we can get at least the files in this particular user's c:\Users\... hierarchy.

Best Regards,
Andreas
0

Featured Post

Don't Cry: How Liquid Web is Ensuring Security

WannaCry is just the start. Read how Liquid Web is protecting itself and its customers against new threats.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article is a collection of issues that people face from time to time and possible solutions to those issues. I hope you enjoy reading it.
I was prompted to write this article after the recent World-Wide Ransomware outbreak. For years now, System Administrators around the world have used the excuse of "Waiting a Bit" before applying Security Patch Updates. This type of reasoning to me …
Finding and deleting duplicate (picture) files can be a time consuming task. My wife and I, our three kids and their families all share one dilemma: Managing our pictures. Between desktops, laptops, phones, tablets, and cameras; over the last decade…
If you’ve ever visited a web page and noticed a cool font that you really liked the look of, but couldn’t figure out which font it was so that you could use it for your own work, then this video is for you! In this Micro Tutorial, you'll learn yo…

717 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question