X-Ways WinHex v15.8Program Type:
hexadecimal editorRelease Date:
Windows 2000/XP/2003/Vista/7File Size:
- универсальный HEX-редактор - позволяет работать с жесткими дисками, дискетами, CD-ROM, DVD, ZIP, Smart Media, Compact Flash memory cards и прочими носителями, при этом поддерживается FAT12, FAT16, FAT32, NTFS, CDFS.
Кроме этого, WinHex обеспечивает доступ к виртуальной памяти (этакий RAM-редактор) и позволяет производить множество других операций, включая, например, клонирование дисков или надежное удаление конфиденциальной информации - без возможности последующего восстановления.
is a universal hexadecimal editor, particularly helpful in the realm of computer forensics, data recovery, low-level data processing, and IT security. An advanced tool for everyday and emergency use: inspect and edit all kinds of files, recover deleted files or lost data from hard drives with corrupt file systems or from digital camera cards.Features include:
- Disk editor for hard disks, floppy disks, CD-ROM & DVD, ZIP, Smart Media, Compact Flash, ...
- Powerful directory browser for FAT, NTFS, Ext2/3, ReiserFS, CDFS, UDF
- RAM editor, providing access to other processes' virtual memory
- Data interpreter, knowing 20 data types
- Editing data structures using templates (e.g. to repair partition table/boot sector)
- Concatenating and splitting files, unifying and dividing odd and even bytes/words
- Analyzing and comparing files
- Particularly flexible search and replace functions
- Disk cloning, with a specialist license also under DOS
- Drive images & backups (optionally compressed or split into 650 MB archives)
- Programming interface (API) and scripting (professional & specialist licenses only)
- 128-bit encryption, checksums, CRC32, hashes (MD5, SHA-1, ...)
- Erase (wipe) confidential files securely, hard drive cleansing to protect your privacy
- Import all clipboard formats, incl. ASCII hex values
- Convert between binary, hex ASCII, Intel Hex, and Motorola S
- Character sets: ANSI ASCII, IBM ASCII, EBCDIC, (Unicode)
- Instant window switching. Printing. Random-number generator.
- Supports files >4 GB. Very fast. Easy to use.New in v15.8
- Ability to internally reconstruct JBOD, i.e. virtually concatenate spanned physical disks (or images of physical disks), via the menu command Specialist | Reconstruct RAID System. Requires a specialist license or higher.
- Recover/Copy: Ability to group existing and deleted files even when not recreating the original path. Forensic license only.
- Recover/Copy: Ability to group files by other parameters such as file type, category, description, sender, owner, hash set, hash category, report table association. Forensic license only.
- Recover/Copy: The single-character suffix that is used to name output folders for child objects of files (distinguish them from the name of the parent files, avoid name conflicts) is now user-definable. It can also be disabled to return to the behavior of v15.5 and earlier, where the words " child objects" were appended. Forensic license only.
- Recover/Copy no longer recreates the original Windows attributes when copying files because hidden and system attributes often make it unnecessarily complicated to see the output files.
- For e-mail extracted by v15.8, you can now see in the Attribute column if an e-mail message is marked as unread. Forensic license only.
- Revised ability to filter for e-mail messages via the Attr. column. Note that the additional e-mail properties by which you can filter are combined with a logical AND, not OR, as otherwise common within the Attr. filter. Forensic license only.
- The number of files that are contained in a directory or in evidence objects (recursively) is now optionally displayed in the directory tree and in the directory browser directly following the directory name, in parentheses. This allows you to easily find directories or evidence objects/partitions that contain most files. A file count is also provided for files that have child objects. File counts are also presented in a new directory browser column, which is sortable. Forensic license only.
- Numeric columns in the directory browser such as 1st sector, skin color percentage, internal ID etc. are now right-aligned.
- If recursive selection statistics are enabled, in the directory browser X-Ways Forensics now shows as the size of a directory the total size of all the files directly or indirectly contained in that directory, not the size of the data structures of the directory any more. Comments about this new feature are welcome. The recursive selection statistics now exclude the size of the data structures of the directories themselves.
- The recursive selection statistics are now considerably faster to compute for directories on large volume snapshots.
- It is now possible to monitor lengthy operations in X-Ways Forensics from other computers in the same network, i.e. see whether they are still ongoing or completed. In General Options you can enable progress notifications via text files (that can be created in a directory on a network drive) and via e-mail in user-defined intervals. Forensic license only.
- Detection of eCryptfs-encrypted files (files stored by the Enterprise Cryptographic FileSystem for Linux). Based on material provided by Ted Smith and implementations for Ubuntu 8.10, 9.04, 9.10 and 10.04. Such files will by marked with E in the Attributes column, just like EFS-encrypted files in NTFS, but only after the encryption test has been run. Forensic license only.
- New default directory for cases under Windows Vista and 7 if X-Ways Forensics has been installed with the setup program.
- Several minor improvements.Please note that volume snapshots created or imported by v15.8 cannot be used by earlier versions any more.