run the makis.bat with Administrator privilledges in the same folder with the required tools. If you want to gather all information uncomment the following lines: 35 (Generating Filesystem timeline).
Also at line 551 (Memory Dump) User Interaction is required, answering 'Y' and hitting Enter on 'Success'
-
fciv.exe - File Checksum Integrity Verifier utility. Download: http://support.microsoft.com/kb/841290
-
RawCopy.exe - Application that copy files off NTFS volumes by using low level disk reading method. Download: https://code.google.com/p/mft2csv/wiki/RawCopy
-
DumpIt.exe - A physical memory dump utility. Download: http://www.moonsols.com/downloads/7
-
winprefetchview.exe - utility that reads the Prefetch files stored in your system. Download: http://www.nirsoft.net/utils/win_prefetch_view.html
-
ChromeCacheView.exe - utility that reads the cache folder of Google Chrome Web browser. Download: http://www.nirsoft.net/utils/chrome_cache_view.html
-
fls.exe - http://sourceforge.net/projects/sleuthkit/files/sleuthkit/4.1.3/sleuthkit-4.1.3-win32.zip/download
-
handle.exe - http://technet.microsoft.com/en-us/sysinternals/bb896655.aspx
-
iehv.exe - utility reads all information from the history file on your computer, and displays the list of all URLs that you have visited in the last few days. Download: http://www.nirsoft.net/utils/iehv.html
-
Listdlls.exe - utility that reports the DLLs loaded into processes. Download: http://technet.microsoft.com/en-us/sysinternals/bb896656.aspx
-
MozillaHistoryView.exe - a small utility that reads the history data file (history.dat) of Firefox/Mozilla/Netscape Web browsers. Download: http://www.nirsoft.net/utils/mozilla_history_view.html
-
pendmoves.exe - dumps the contents of the pending rename/delete value and also reports an error when the source file is not accessible. Download: http://technet.microsoft.com/en-us/sysinternals/bb897556.aspx
-
psfile.exe - shows you a list of the files that other computers have opened on the system upon which you execute the command. Download: http://technet.microsoft.com/en-us/sysinternals/bb897552.aspx
-
PsInfo.exe - gathers key information about the local or remote Windows NT/2000 system. Download: http://technet.microsoft.com/en-us/sysinternals/bb897550.aspx
-
pslist.exe - Download: http://technet.microsoft.com/en-us/sysinternals/bb896682.aspx
-
PsService.exe - a service viewer and controller for Windows. Download: http://technet.microsoft.com/en-us/sysinternals/bb897542.aspx
-
showacls.exe & now.exe - http://www.microsoft.com/en-us/download/details.aspx?id=17657
-
autorunsc.exe - http://technet.microsoft.com/en-us/sysinternals/bb963902.aspx
-
psloglist.exe - http://technet.microsoft.com/en-us/sysinternals/bb897544.aspx
-
sigcheck.exe - http://technet.microsoft.com/en-us/sysinternals/bb897441.aspx