Winhex Manual

Total Page:16

File Type:pdf, Size:1020Kb

Winhex Manual X-Ways Software Technology AG WinHex/ X-Ways Forensics Integrated Computer Forensics Environment. Data Recovery & IT Security Tool. Hexadecimal Editor for Files, Disks & RAM. Manual Copyright © 1995-2007 Stefan Fleischmann, X-Ways Software Technology AG. All rights reserved. Contents 1 Preface ..................................................................................................................................................1 1.1 About WinHex and X-Ways Forensics.........................................................................................1 1.2 Legalities.......................................................................................................................................2 1.3 License Types ...............................................................................................................................3 1.4 Differences between WinHex and X-Ways Forensics..................................................................4 1.5 Getting Started with X-Ways Forensics........................................................................................5 2 Technical Background ........................................................................................................................5 2.1 Using a Hex Editor........................................................................................................................5 2.2 Endian-ness...................................................................................................................................6 2.3 Integer Data Types........................................................................................................................6 2.4 Floating-Point Data Types ............................................................................................................6 2.5 Date Types ....................................................................................................................................7 2.6 ANSI ASCII/IBM ASCII..............................................................................................................8 2.7 Checksums ....................................................................................................................................9 2.8 Digests ..........................................................................................................................................9 2.9 Technical Hints ...........................................................................................................................10 3 Forensic Features...............................................................................................................................11 3.1 Case Management.......................................................................................................................11 3.2 Evidence Objects ........................................................................................................................12 3.3 Log & Report Feature .................................................................................................................13 3.4 Report Tables..............................................................................................................................14 3.5 Volume Snapshots ......................................................................................................................14 3.6 Directory Browser.......................................................................................................................18 3.7 Internal Viewer ...........................................................................................................................24 3.8 Registry Report ...........................................................................................................................25 3.9 Mode Buttons..............................................................................................................................25 3.10 Simultaneous Search...................................................................................................................27 3.11 Logical Search ............................................................................................................................28 3.12 Search Hit Lists...........................................................................................................................29 3.13 Search Term List.........................................................................................................................30 3.14 Indexing, Index Search ...............................................................................................................31 3.15 Hash Database.............................................................................................................................33 3.16 Time Zone Concept.....................................................................................................................34 3.17 Evidence File Containers ............................................................................................................34 4 Menu Reference .................................................................................................................................36 4.1 Directory Browser Context Menu...............................................................................................36 4.2 File Menu....................................................................................................................................40 4.3 Edit Menu ...................................................................................................................................41 4.4 Search Menu ...............................................................................................................................42 4.5 Position Menu .............................................................................................................................43 4.6 View Menu..................................................................................................................................44 4.7 Tools Menu .................................................................................................................................45 4.8 File Tools ....................................................................................................................................47 4.9 Specialist Menu...........................................................................................................................47 4.10 Options Menu .............................................................................................................................49 II 4.11 Window Menu ............................................................................................................................50 4.12 Help Menu ..................................................................................................................................50 4.13 Windows Context Menu .............................................................................................................51 5 Some Basic Concepts .........................................................................................................................51 5.1 Start Center .................................................................................................................................51 5.2 Entering Characters.....................................................................................................................52 5.3 Edit Modes..................................................................................................................................52 5.4 Status Bar....................................................................................................................................53 5.5 Scripts .........................................................................................................................................53 5.6 WinHex API................................................................................................................................54 5.7 Disk Editor..................................................................................................................................54 5.8 RAM Editor ................................................................................................................................56 5.9 Template Editing.........................................................................................................................56 6 Data Recovery....................................................................................................................................57 6.1 File Recovery with the Directory Browser .................................................................................57 6.2 File Recovery by Type................................................................................................................57 6.3 File Type Definitions ..................................................................................................................59 6.4 Manual Data Recovery ...............................................................................................................60 7 Options................................................................................................................................................61 7.1 General Options ..........................................................................................................................61
Recommended publications
  • Active@ UNDELETE Documentation
    Active @ UNDELETE Users Guide | Contents | 2 Contents Legal Statement.........................................................................................................5 Active@ UNDELETE Overview............................................................................. 6 Getting Started with Active@ UNDELETE.......................................................... 7 Active@ UNDELETE Views And Windows...................................................................................................... 7 Recovery Explorer View.......................................................................................................................... 8 Logical Drive Scan Result View..............................................................................................................9 Physical Device Scan View......................................................................................................................9 Search Results View...............................................................................................................................11 File Organizer view................................................................................................................................ 12 Application Log...................................................................................................................................... 13 Welcome View........................................................................................................................................14 Using
    [Show full text]
  • Administrator's Guide
    Trend Micro Incorporated reserves the right to make changes to this document and to the product described herein without notice. Before installing and using the product, review the readme files, release notes, and/or the latest version of the applicable documentation, which are available from the Trend Micro website at: http://docs.trendmicro.com/en-us/enterprise/scanmail-for-microsoft- exchange.aspx Trend Micro, the Trend Micro t-ball logo, Apex Central, eManager, and ScanMail are trademarks or registered trademarks of Trend Micro Incorporated. All other product or company names may be trademarks or registered trademarks of their owners. Copyright © 2020. Trend Micro Incorporated. All rights reserved. Document Part No.: SMEM149028/200709 Release Date: November 2020 Protected by U.S. Patent No.: 5,951,698 This documentation introduces the main features of the product and/or provides installation instructions for a production environment. Read through the documentation before installing or using the product. Detailed information about how to use specific features within the product may be available at the Trend Micro Online Help Center and/or the Trend Micro Knowledge Base. Trend Micro always seeks to improve its documentation. If you have questions, comments, or suggestions about this or any Trend Micro document, please contact us at [email protected]. Evaluate this documentation on the following site: https://www.trendmicro.com/download/documentation/rating.asp Privacy and Personal Data Collection Disclosure Certain features available in Trend Micro products collect and send feedback regarding product usage and detection information to Trend Micro. Some of this data is considered personal in certain jurisdictions and under certain regulations.
    [Show full text]
  • ACS – the Archival Cytometry Standard
    http://flowcyt.sf.net/acs/latest.pdf ACS – the Archival Cytometry Standard Archival Cytometry Standard ACS International Society for Advancement of Cytometry Candidate Recommendation DRAFT Document Status The Archival Cytometry Standard (ACS) has undergone several revisions since its initial development in June 2007. The current proposal is an ISAC Candidate Recommendation Draft. It is assumed, however not guaranteed, that significant features and design aspects will remain unchanged for the final version of the Recommendation. This specification has been formally tested to comply with the W3C XML schema version 1.0 specification but no position is taken with respect to whether a particular software implementing this specification performs according to medical or other valid regulations. The work may be used under the terms of the Creative Commons Attribution-ShareAlike 3.0 Unported license. You are free to share (copy, distribute and transmit), and adapt the work under the conditions specified at http://creativecommons.org/licenses/by-sa/3.0/legalcode. Disclaimer of Liability The International Society for Advancement of Cytometry (ISAC) disclaims liability for any injury, harm, or other damage of any nature whatsoever, to persons or property, whether direct, indirect, consequential or compensatory, directly or indirectly resulting from publication, use of, or reliance on this Specification, and users of this Specification, as a condition of use, forever release ISAC from such liability and waive all claims against ISAC that may in any manner arise out of such liability. ISAC further disclaims all warranties, whether express, implied or statutory, and makes no assurances as to the accuracy or completeness of any information published in the Specification.
    [Show full text]
  • Active @ UNDELETE Users Guide | TOC | 2
    Active @ UNDELETE Users Guide | TOC | 2 Contents Legal Statement..................................................................................................4 Active@ UNDELETE Overview............................................................................. 5 Getting Started with Active@ UNDELETE........................................................... 6 Active@ UNDELETE Views And Windows......................................................................................6 Recovery Explorer View.................................................................................................... 7 Logical Drive Scan Result View.......................................................................................... 7 Physical Device Scan View................................................................................................ 8 Search Results View........................................................................................................10 Application Log...............................................................................................................11 Welcome View................................................................................................................11 Using Active@ UNDELETE Overview................................................................. 13 Recover deleted Files and Folders.............................................................................................. 14 Scan a Volume (Logical Drive) for deleted files..................................................................15
    [Show full text]
  • X-Ways Forensics/ Winhex
    X-Ways Software Technology AG X-Ways Forensics/ WinHex Integrated Computer Forensics Environment. Data Recovery & IT Security Tool. Hexadecimal Editor for Files, Disks & RAM. Manual Copyright © 1995-2014 Stefan Fleischmann, X-Ways Software Technology AG. All rights reserved. Contents 1 Preface ..................................................................................................................................................1 1.1 About WinHex and X-Ways Forensics.........................................................................................1 1.2 Legalities.......................................................................................................................................2 1.3 License Types ...............................................................................................................................2 1.4 Differences between WinHex and X-Ways Forensics..................................................................3 1.5 Getting Started with X-Ways Forensics........................................................................................4 2 Technical Background ........................................................................................................................5 2.1 Using a Hex Editor........................................................................................................................5 2.2 Endian-ness...................................................................................................................................6 2.3
    [Show full text]
  • Guida-Comprimere-I-Documenti.Pdf
    Guida Comprimere i documenti alvare spazio e gestire me- Questione di spazio Guida glio i file. In sintesi, è questo Per capire bene il funzionamento ai programmi Sil principale vantaggio che di questi programmi e quale sia deriva dall’utilizzo dei program- ancora oggi la loro utilità, bisogna che permettono mi per creare archivi compressi, tenere conto di come si è evolu- ovvero quei software che ci con- ta nel tempo la gestione dei file: di creare archivi sentono di “impacchettare” i file vent’anni fa la memoria di massa compressi che abbiamo sui nostri computer e più economica e diffusa era il flop- ridurre così lo spazio occupato sui py disk (il cosiddetto “dischetto”) salvando spazio dispositivi di archiviazione (cioè, da 1.4 megabyte. Attualmente, la le cosiddette memorie di massa e dimensione dei dischi ottici, del- sul pc. simili). le chiavette usb e degli hard disk N° 39 SETTEMBRE 2013 13 Guida QUATTRO SOFTWARE A CONFRONTO WinAce v2.69 PUNTI FORTI Versione standard 29$ (circa 22 €) Indispensabile per aprire i file in formato Valido Navigando online non è raro imbattersi .ace. in archivi compressi distribuiti in formato anche PUNTI DEBOLI se meno .ace. WinAce non si discosta molto, come funzionalità, dagli altri programmi: legge e L’Interfaccia utente è un po’ più ostica ri- conosciuto crea anche file .zip e legge (ma non crea) spetto agli altri programmi. file in formato .rar. Winrar v4.20 PUNTI FORTI Singola licenza 36 € Interfaccia semplice e immediata; sup- Winrar è la versione per Windows del pro- porta un buon numero formati in lettura È un altro gramma, ma esistono anche versioni per e scrittura.
    [Show full text]
  • Filesystems HOWTO Filesystems HOWTO Table of Contents Filesystems HOWTO
    Filesystems HOWTO Filesystems HOWTO Table of Contents Filesystems HOWTO..........................................................................................................................................1 Martin Hinner < [email protected]>, http://martin.hinner.info............................................................1 1. Introduction..........................................................................................................................................1 2. Volumes...............................................................................................................................................1 3. DOS FAT 12/16/32, VFAT.................................................................................................................2 4. High Performance FileSystem (HPFS)................................................................................................2 5. New Technology FileSystem (NTFS).................................................................................................2 6. Extended filesystems (Ext, Ext2, Ext3)...............................................................................................2 7. Macintosh Hierarchical Filesystem − HFS..........................................................................................3 8. ISO 9660 − CD−ROM filesystem.......................................................................................................3 9. Other filesystems.................................................................................................................................3
    [Show full text]
  • Les Extensions Des Fichiers
    OUVRIR TOUS TYPES DE DOCUMENTS Quels logiciels pour quels fichiers? Fichiers_Audio Fichiers_Images Fichiers_Compressés Fichiers_De_Données Fichiers_Exécutables Fichiers_Encodés Fichiers_Exécutables Fichiers_Paramètres Fichiers_Polices Fichiers_Systèmes Fichiers_Texte Fichiers_Web Fichiers_Vidéos Famille de fichiers Fichiers_Audio Extension Programmes associés .aac iTunes/VLC Media Player .acm Ouvert directement par Windows .aif Windows media player/Quick Time/iTunes .asf Windows media player/VLC Media Player .au Windows media player/Quick Time/Real Player .cdr Windows media player/iTune .iff Quick Time .m3u iTunes/VLC Media Player/Real Player/WinAmp .mid ou .midi Quick Time .mp3 iTunes/VLC Media Player/Real Player/WinAmp Windows media player .mpa iTunes/Windows media player/Quick Time .ra Real Player .ram Real Player .Wav iTunes/Windows media player/VLC Media Player .wma Windows media player/navigateur internet/WinAmp Famille de fichiers Fichiers_Images Extension Programmes associés .3dmf Qick Time .ai Adobe Illustrator .bmp Ouverture par Windows .drw Paint shop pro/Picture it .eps GIMP/Irfanview .gif Paint/Irfanview/la plus part des logiciels multimédia .jpg/jpeg La plus part des logiciels multimédia .pdf Acrobat Reader .png Paint/Vista/Acdsee... .psd Adobe Photoshop/ logiciels de traitement image .psp Paint shop pro/divers traitement image .tiff Paint/Irfanview/divers traitement image .svg Flash player/navigateur internet Famille de fichiers Fichiers_Compressés Extension Programmes associés .ace Izarc/Winace/Winrar .arc Izarc/Winace/Winzip
    [Show full text]
  • Acronis® Disk Director® 12 User's Guide
    User Guide Copyright Statement Copyright © Acronis International GmbH, 2002-2015. All rights reserved. "Acronis", "Acronis Compute with Confidence", "Acronis Recovery Manager", "Acronis Secure Zone", Acronis True Image, Acronis Try&Decide, and the Acronis logo are trademarks of Acronis International GmbH. Linux is a registered trademark of Linus Torvalds. VMware and VMware Ready are trademarks and/or registered trademarks of VMware, Inc. in the United States and/or other jurisdictions. Windows and MS-DOS are registered trademarks of Microsoft Corporation. All other trademarks and copyrights referred to are the property of their respective owners. Distribution of substantively modified versions of this document is prohibited without the explicit permission of the copyright holder. Distribution of this work or derivative work in any standard (paper) book form for commercial purposes is prohibited unless prior permission is obtained from the copyright holder. DOCUMENTATION IS PROVIDED "AS IS" AND ALL EXPRESS OR IMPLIED CONDITIONS, REPRESENTATIONS AND WARRANTIES, INCLUDING ANY IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE OR NON-INFRINGEMENT, ARE DISCLAIMED, EXCEPT TO THE EXTENT THAT SUCH DISCLAIMERS ARE HELD TO BE LEGALLY INVALID. Third party code may be provided with the Software and/or Service. The license terms for such third-parties are detailed in the license.txt file located in the root installation directory. You can always find the latest up-to-date list of the third party code and the associated license terms used with the Software and/or Service at http://kb.acronis.com/content/7696 Acronis patented technologies Technologies, used in this product, are covered and protected by one or more U.S.
    [Show full text]
  • Disk Utilities
    STUDY MATERIALS ON HARDWARE INSTALLATION AND MAINTENANCE (As per the curriculum of fifth semester BSc Electronics of M. G. University) Compiled by Sam Kollannore U. Lecturer in Electronics M. E. S. College, Marampally DISK UTILITIES Disk Utilities are readymade softwares available in the market to help the computer user in managing the disk/drive and to help in the data recovery in case of some failure of the normal disk/drive operation. Example:- PCTOOLS and NORTON Utilities. These programs are useful to undelete accidentally deleted data, unformat accidentally formatted floppy and to recover from data corruption due to ill behavior of some software or some computer virus. New versions of Dos provide some of these facilities but these programs provide the same facilities with a lot more speed, accuracy and with additional options. PCTOOLS This package provide facility for:- 9 Data recovery – using the programs like DiskFix, FileFix, Unformat etc. 9 Unfragementing the disk – using programs like COMPRESS, DiskEdit etc. 9 Detecting and removing viruses – using the antivirus program CPAV (removes around 1400 viruses) 9 Searching, changing, adding, renaming, deleting and moving directories- using the Directory Maintenance program. 9 Searching files using FileFind 9 Providing information about your computer hardware, operating system and version, memory type and size and system speed – using the System Infomation (SI) program. DiskFix Command:- C:\PCTOOL\>DISKFIX Most useful program – can recover the data from very serious damages. DiskFix should be used regularly to detect and prevent potential problems. This program can do ¾ Repair most of the disk problem ¾ Thoroughly scan the disk surface for defects and damaged data, removing defective sectors and moving recoverable data to a safe location ¾ Recover lost cluster chains, including directories which CHKDSK cannot do ¾ Detect sectors going bad ¾ Low level format a disk that DOS cannot read or write properly without destroying any data.
    [Show full text]
  • Installation and Configuration
    6 Jun 2007 Drupal Handbook Table of Contents Installation and configuration . 1 System requirements . 2 Client System Requirements . 3 Javascript . 3 CSS . 4 RSS . 4 Browser Specifics . 4 Browser Popularity . 4 Known Problems . 4 Validation . 4 Caveats . 4 HOWTO: Server requirement recommendations for your consulting clients .. 5 Message to the Client . 5 Benchmark . 6 What Drupal.org runs on . 6 Requirements - older versions . 6 Installing Drupal, modules and themes . 8 Installing Drupal . 8 Formatted Drupal 5.x Installation instructions for better readability .. 13 Installation . 13 Changes . 14 Requirements . 14 Optional Requirements . 14 Installation . 14 Drupal Administration . 16 Customizing your theme(s) . 16 Multi-site configuration . 16 More Information . 17 Formatted Drupal 4.7.x Installation instructions for better readability .. 17 Installation . 17 REQUIREMENTS . 18 SERVER CONFIGURATION . 18 OPTIONAL COMPONENTS . 18 INSTALLATION . 19 1. DOWNLOAD DRUPAL . 19 2. CREATE THE DRUPAL DATABASE . 19 3. LOAD THE DRUPAL DATABASE SCHEME . 20 4. CONNECTING DRUPAL . 20 5. CONFIGURE DRUPAL . 21 6. CRON TASKS . 22 DRUPAL ADMINISTRATION . 22 CUSTOMIZING YOUR THEME(S) . 22 UPGRADING . 23 MORE INFORMATION . 23 i Drupal Handbook 6 Jun 2007 10 minute install using PuTTY SSH/Telnet client .. 23. How I installed Drupal: The Eightfold Way . 24. Installing virtual hosts for Drupal sites and subsites .. 25. Mac OS X-specific guidelines . 26. Important notes for MySQL install: . 27. HOWTO: Create a local server environment for drupal using MAMP .. 28. HOWTO: Installing PostgreSQL and MySQL on the same Mac OS X machine .. 29. Installing Drupal on Mac OS X 10.4 Tiger . 30. Installing and Configuring MySQL . 30. Sending mail . 32.
    [Show full text]
  • Active@ Livecd User Guide Copyright © 1999-2015, LSOFT TECHNOLOGIES INC
    Active@ LiveCD User Guide Copyright © 1999-2015, LSOFT TECHNOLOGIES INC. All rights reserved. No part of this documentation may be reproduced in any form or by any means or used to make any derivative work (such as translation, transformation, or adaptation) without written permission from LSOFT TECHNOLOGIES INC. LSOFT TECHNOLOGIES INC. reserves the right to revise this documentation and to make changes in content from time to time without obligation on the part of LSOFT TECHNOLOGIES INC. to provide notification of such revision or change. LSOFT TECHNOLOGIES INC. provides this documentation without warranty of any kind, either, implied or expressed, including, but not limited to, the implied warranties of merchantability and fitness for a particular purpose. LSOFT may make improvements or changes in the product(s) and/or the program(s) described in this documentation at any time. All technical data and computer software is commercial in nature and developed solely at private expense. As the User, or Installer/Administrator of this software, you agree not to remove or deface any portion of any legend provided on any licensed program or documentation contained in, or delivered to you in conjunction with, this User Guide. LSOFT.NET logo is a trademark of LSOFT TECHNOLOGIES INC. Other brand and product names may be registered trademarks or trademarks of their respective holders. 2 Active@ LiveCD User Guide Contents 1 Product Overview................................................................................................................ 4 1.1 About Active@ LiveCD .................................................................................................. 4 1.2 Requirements for Using Active@ Boot Disk .................................................................... 6 1.3 Downloading and Creating Active@ LiveCD.................................................................... 6 1.4 Booting from a CD, DVD or USB Media .........................................................................
    [Show full text]