X-Ways WinHex v17.2 » KinDzaDza
Home | Footage | Sound FX | Tutorials | Музыка | Фильмы | Контакт |
KinDzaDza - It's Other!  

Главная страница » Software » X-Ways WinHex v17.2
Забыли пароль?
Ещё не зарегистрированы?

X-Ways WinHex v17.2
Software | автор: SonyQ (16.07.13)
X-Ways WinHex v17.2

Program Name: WinHex v17.2
Program Type: Hexadecimal editor
Developer: X-Ways Software Technology AG
Homepage: www.winhex.com
Release Date: 11.07.2013
Interface Language: Multilingual (русский включительно)
Platform: Windows 2000/XP/2003/Vista/7
File Size: 3.61Mb

WinHex - это универсальный шестнадцатеричный редактор, особенно полезный в областях компьютерно-технической экспертизы, восстановления данных, низкоуровневой обработки данных и информационной безопасности. Усовершенствованный инструмент для повседневного использования или в случае аварии: изучение и редактирование всех видов файлов, восстановление удалённых файлов или утраченных данных с жёстких дисков с повреждённой файловой системой или с карт памяти цифровых камер.

Основные возможности:
- Редактор дисков для работы с жёсткими дисками, дискетами, CD/DVD, ZIP, SmartMedia, Compact Flash и прочими устройствами
- Поддержка файловых систем FAT12/16/32, exFAT, NTFS, Ext2/3/4, Next3, CDFS, UDF
- Встроенный интерпретатор для динамических дисков и RAID-систем
- Различные методы восстановления данных
- Редактор оперативной памяти, обеспечивающий доступ к физической памяти и виртуальной памяти других процессов
- Интерпретатор данных, знает 20 типов данных
- Редактирование структур данных, используя шаблоны (например, для восстановления таблицы разделов/загрузочного сектора)
- Соединение и разделение файлов, объединение и деление четных и нечетных байтов/слов
- Анализ и сравнение файлов
- Удобный гибкий поиск с функциями замены
- Клонирование дисков (под DOS с использованием X-Ways Replica)
- Создание снимка и резервной копии диска (при необходимости сжатие или разделение на архивы в 650 Мб)
- Программируемый интерфейс (API) и выполнение скриптов
- AES-шифрование с 256-битным ключом, контрольные суммы, CRC32, хэши (MD5, SHA 1...)
- Надёжное удаление (стирание) секретных файлов, очистка жёсткого диска
- Импорт всех форматов буфера обмена, включая шестнадцатеричные значения в кодировке ASCII
- Преобразование различных форматов: Двоичный, Hex ASCII, Intel Hex и Motorola S
- Наборы символов: ANSI ASCII, IBM ASCII, EBCDIC, (Unicode)
- Мгновенное переключение окна. Печать. Генератор случайных чисел
- Поддержка файлов размером более 4 Гб. Очень быстр. Прост в использовании. Подробная интерактивная справка


WinHex is a universal hexadecimal editor, particularly helpful in the realm of computer forensics, data recovery, low-level data processing, and IT security. An advanced tool for everyday and emergency use: inspect and edit all kinds of files, recover deleted files or lost data from hard drives with corrupt file systems or from digital camera cards.

- Disk editor for hard disks, floppy disks, CD-ROM & DVD, ZIP, Smart Media, Compact Flash, ...
- Native support for FAT12/16/32, exFAT, NTFS, Ext2/3/4, Next3, CDFS, UDF
- Built-in interpretation of RAID systems and dynamic disks
- Various data recovery techniques
- RAM editor, providing access to physical RAM and other processes virtual memory
- Data interpreter, knowing 20 data types
- Editing data structures using templates (e.g. to repair partition table/boot sector)
- Concatenating and splitting files, unifying and dividing odd and even bytes/words
- Analyzing and comparing files
- Particularly flexible search and replace functions
- Disk cloning (under DOS with X-Ways Replica)
- Drive images & backups (optionally compressed or split into 650 MB archives)
- Programming interface (API) and scripting
- 256-bit AES encryption, checksums, CRC32, hashes (MD5, SHA-1, ...)
- Erase (wipe) confidential files securely, hard drive cleansing to protect your privacy
- Import all clipboard formats, incl. ASCII hex values
- Convert between binary, hex ASCII, Intel Hex, and Motorola S
- Character sets: ANSI ASCII, IBM ASCII, EBCDIC, (Unicode)
- Instant window switching. Printing. Random-number generator
- Supports files >4 GB. Very fast. Easy to use. Extensive online help

What's new in v17.2:
- Yet another acquisition option for users who need to or want to exclude certain data from forensic images. You can now create ordinary images, in raw format or as an .e01 evidence file - with all the known options such as hashing, compression, encryption, splitting - and exclude the data in clusters associated with files that you hide before starting the acquisition process. The resulting image is called a cleansed image. The affected sectors are zeroed out in the image and optionally marked with an easily recognizable "watermark" of your choice. All other data is copied to the image normally.
Useful for anyone who needs to redact certain files in the file system, but otherwise wants to create an ordinary forensically sound sector-wise image, compatible with other tools. A must in countries whose legislation specially protects the most private personal data of individuals and certain data acquired from custodians of professional secrets (e.g. lawyers and physicians, whose profession swears them to secrecy/confidentiality). For a comparison of evidence file containers, skeleton images and cleansed images, which all serve similar purposes, please see Containers vs Skeleton images >>
Before you start the imaging process for a partitioned disk, open the partitions in which the files are located that you would like to exclude from the image. Wait till the volume snapshot has been taken if it was not taken before. Then hide the files. You do not need to open and take volume snapshots of partitions whose data you would like to include completely.
Note that alternatively you can retroactively cleanse (redact) already created complete raw images, in WinHex, by securely wiping files selected files via the directory browser context menu. The granularity of this operation is not limited to entire clusters. For example, that means it can also wipe files in NTFS file systems with so-called resident/inline storage and it does not erase file slack along.
- Totally revised indexing engine with many advantages: Created optionally at the same time when then volume snapshot is refined (synergy saves time), faster to create than before, no separate optimization step, just 1 index for multiple code pages/character sets, just 1 word list for multiple code pages/character sets (i.e. less duplicates), GREP searches in the index possible, multiple indexes with different names for different purposes may coexist for the same evidence object, indexing with regular expressions possible (details to be revealed later), more convenient search hit review (exactly like for ordinary search hits, search hits are stored permanently immediately, allowing for immediate logical AND and NEAR combinations), and more.
At the moment the old and the new indexing engines coexist within the program. To use the old indexing engine use the menu commands Search | Indexing (to create an index) and Search | Search in Index (to search in the index). To use the new indexing engine use the menu commands Specialist | Refine Volume Snapshot (to create an index) and Search | Simultaneous Search (to search in the index, select "Search in Index" in the drop-down box).
- Events recorded by Skype are now output to the event list (chats, calls, file transfers, account creation, ...). When sorting these events by their timestamps, you can read all chats messages in chronological order.
- Metadata extraction from PE .exe files with version resources.
- New directory browser column: Unique ID. Similar to the internal ID, but unique within the entire case, not just within the evidence object. A filter for this column will probably be added at a later time.
- The options "Group files and directory", "List dir.s when exploring recursively" and "Apply filters to directories, too" are now remembered separately by the normal directory browser, search hit lists and event lists.
- X-Tensions API: Ability to retrieve the result of the skin tone/gray scale analysis of pictures programmatically, via XWF_GetItemInformation.
- Several minor improvements.

Limitations under Windows Vista/2008 Server/7
Physical RAM cannot be opened. Install WinHlp32.exe (for Vista >>/for 7 >>) to be able to use the program help. Unable to write sectors on the partitions that contain Windows and WinHex.


For VIP-members only (BETA)
Если вы здесь ничего не видите, то значит здесь ничего нет, либо вы не входите в группу VIP-members
If You do not see here anything, it means there here is nothing, or you are not VIP-member.

Внимание! Всегда проверяйте антивирусом файлы, которые Вы загружаете! / Attention! Always check files you download with your antivirus software!

Другие новости по теме / See also:
  • X-Ways WinHex v16.6
  • X-Ways WinHex v17.5 SR-9
  • X-Ways WinHex v17.6 SR-1
  • X-Ways WinHex v16.0 SR-5
  • X-Ways WinHex v16.7 SR-4
    Уважаемый посетитель, Вы зашли на сайт как незарегистрированный пользователь. Мы рекомендуем Вам зарегистрироваться либо зайти на сайт под своим именем.

    Комментарии / Comments


    Посетители, находящиеся в группе guests, не могут оставлять комментарии в данной новости.
    KinDzaDza.net ©2016 :)
    Designed by Pazak
    Home | Software | Footage | Sound FX | Tutorials | E-Books | Музыка | Фильмы | Контакт
    Все публикуемые материалы предоставлены здесь только для ознакомления, все права на них принадлежат их владельцам!
    Published materials are given here only for acquaintance, all rights to them belong to their owners!