Finding USB thumb drives on remote (LAN) comupters

Status
Not open for further replies.

Souka

Diamond Member
Sep 25, 2000
4,728
1
76
Hello,

I'm trying to figure out how to find USB thumbdrives on machines within my corporate network.

My comptuer: WinXP or Win7 x64 Enterprise
Remote computers: Win7 Embeded on network, but not joined to domain

I already have report tools in SCCM to handle the XP/Win7 systems that are on the domain. But the Win7 embeded systems are a problem for me as they do not have SCCM or are joined to the domain.

I have about 750 of these non-domain, networked systems to scan.
All these devices hostnames start with the same 2-letters so I can querry them fine.
All these devices use the same local admin userID/password, and I know it.

Any suggestions?

Thanks in advance!

--Souka
 
Last edited:

Souka

Diamond Member
Sep 25, 2000
4,728
1
76
Two reasons.

1. They're not allowed.

2. Because of the nature of these computers (Wyse ThinClients), we brought in a small crew of contractors to re-image these.... and in the process they lost quite a few thumb drives. We've occasionally come across one in the pack of one of these comptuers and I'm curios how many others are out there.

I have full authority to perform any query I wish, and since I'm not making any software/hardware changes across the board I don't have to go through change management.

I'd like help with somehow writing script that:
a. references a device list txt file.
b. runs a check for a USB Storage device, or a drive D: would also work.
c. exports a list of devices that are true
 
Last edited:

velis

Senior member
Jul 28, 2005
600
14
81
wmic logicaldisk get description,name

That said, this is SO NOT highly technical.
 

Souka

Diamond Member
Sep 25, 2000
4,728
1
76
wmic logicaldisk get description,name
That said, this is SO NOT highly technical.

Thank you for your response.

So taking your WMIC query, how would I gather that information from a list of about 750 devices?

And as I've said, each device is not a member of the domain, so unique userID will also be needed to query the wmi info. eg, COMPUTER1\administrator + password COMPUTER2\administrator + password
 

Squeetard

Senior member
Nov 13, 2004
815
7
76
First, I hope you have blocked their use in the domain using group policy.
Then, all you have to do is block local resource drives and the clipboard in RDP using group policy.
Now they are useless.
 

Souka

Diamond Member
Sep 25, 2000
4,728
1
76
First, I hope you have blocked their use in the domain using group policy.
Then, all you have to do is block local resource drives and the clipboard in RDP using group policy.
Now they are useless.

They are not on the domain. I am trying to find devices with USB drives, blocking them will not do that. Many of these computers are actually in locked cabinets/carts...but I've found that our techs have left USB thumbdrives in them when re-imaging via USB.

We do have a mangement server, and I can push images I've built moving forward, but I'm tyring to locate these USB drives.
 

velis

Senior member
Jul 28, 2005
600
14
81
Thank you for your response.

So taking your WMIC query, how would I gather that information from a list of about 750 devices?

And as I've said, each device is not a member of the domain, so unique userID will also be needed to query the wmi info. eg, COMPUTER1\administrator + password COMPUTER2\administrator + password

This stackoverflow question seems to hold the answer to that: http://stackoverflow.com/questions/9332090/powershell-remotely-run-windows-commands
 

Souka

Diamond Member
Sep 25, 2000
4,728
1
76
Thank you Velis and debian0001, I'll take a look.

I'm pretty sad in my programing skills... hopefully I can make it work.

I have list of hostnames I need to scan, I know the local admin/password info (same for all), hopefully I can get this to work!
 

sm625

Diamond Member
May 6, 2011
8,172
137
106
Code:
devcon status *USBSTOR*

When I run that from a command line on my machine I get:
Code:
USBSTOR\DISK&VEN_KINGSTON&PROD_DATATRAVELER_2.0&REV_PMAP\5B840A001CBB&0
    Name: Kingston DataTraveler 2.0 USB Device
    Driver is running.
1 matching device(s) found.
 
Last edited:

alkemyst

No Lifer
Feb 13, 2001
83,967
19
81
Look into PowerShell and Foreach loops on texts files with hostnames listed.

This would be my solution, exclude the drive letters assigned already and do a For Each with the range of hostnames.

For a this size network, shouldn't take long to get the report.

The easier method would be just to block them with a policy.

These USB drives are probably worth less than the time to hunt them down.
 

Souka

Diamond Member
Sep 25, 2000
4,728
1
76
Thank you all.

I'll poke around with your suggests when I get some time.
 
Status
Not open for further replies.
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |