X-Ways WinHex v18.4
Software | автор: SonyQ (22.07.15)
X-Ways WinHex v18.4

Program Name: WinHex v18.4
Program Type: Hexadecimal editor
Developer: X-Ways Software Technology AG
Homepage: www.winhex.com/winhex/index-m.html
Release Date: 15.07.2015
Interface Language: Multilingual (русский включительно)
Platform: Windows 2000/XP/2003/Vista/7/8/8.1
File Size: 5.24Mb

WinHex - это универсальный шестнадцатеричный редактор, особенно полезный в областях компьютерно-технической экспертизы, восстановления данных, низкоуровневой обработки данных и информационной безопасности. Усовершенствованный инструмент для повседневного использования или в случае аварии: изучение и редактирование всех видов файлов, восстановление удалённых файлов или утраченных данных с жёстких дисков с повреждённой файловой системой или с карт памяти цифровых камер.

Основные возможности:
• Редактор дисков для работы с жёсткими дисками, дискетами, CD/DVD, ZIP, SmartMedia, Compact Flash и прочими устройствами
• Поддержка файловых систем FAT12/16/32, exFAT, NTFS, Ext2/3/4, Next3, CDFS, UDF
• Встроенный интерпретатор для динамических дисков и RAID-систем
• Различные методы восстановления данных
• Редактор оперативной памяти, обеспечивающий доступ к физической памяти и виртуальной памяти других процессов
• Интерпретатор данных, знает 20 типов данных
• Редактирование структур данных, используя шаблоны (например, для восстановления таблицы разделов/загрузочного сектора)
• Соединение и разделение файлов, объединение и деление четных и нечетных байтов/слов
• Анализ и сравнение файлов
• Удобный гибкий поиск с функциями замены
• Клонирование дисков (под DOS с использованием X-Ways Replica)
• Создание снимка и резервной копии диска (при необходимости сжатие или разделение на архивы в 650 Мб)
• Программируемый интерфейс (API) и выполнение скриптов
• AES-шифрование с 256-битным ключом, контрольные суммы, CRC32, хэши (MD5, SHA 1...)
• Надёжное удаление (стирание) секретных файлов, очистка жёсткого диска
• Импорт всех форматов буфера обмена, включая шестнадцатеричные значения в кодировке ASCII
• Преобразование различных форматов: Двоичный, Hex ASCII, Intel Hex и Motorola S
• Наборы символов: ANSI ASCII, IBM ASCII, EBCDIC, (Unicode)
• Мгновенное переключение окна. Печать. Генератор случайных чисел
• Поддержка файлов размером более 4 Гб. Очень быстр. Прост в использовании. Подробная интерактивная справка


WinHex is a universal hexadecimal editor, particularly helpful in the realm of computer forensics, data recovery, low-level data processing, and IT security. An advanced tool for everyday and emergency use: inspect and edit all kinds of files, recover deleted files or lost data from hard drives with corrupt file systems or from digital camera cards.

• Disk editor for hard disks, floppy disks, CD-ROM & DVD, ZIP, Smart Media, Compact Flash, ...
• Native support for FAT12/16/32, exFAT, NTFS, Ext2/3/4, Next3, CDFS, UDF
• Built-in interpretation of RAID systems and dynamic disks
• Various data recovery techniques
• RAM editor, providing access to physical RAM and other processes virtual memory
• Data interpreter, knowing 20 data types
• Editing data structures using templates (e.g. to repair partition table/boot sector)
• Concatenating and splitting files, unifying and dividing odd and even bytes/words
• Analyzing and comparing files
• Particularly flexible search and replace functions
• Disk cloning (under DOS with X-Ways Replica)
• Drive images & backups (optionally compressed or split into 650 MB archives)
• Programming interface (API) and scripting
• 256-bit AES encryption, checksums, CRC32, hashes (MD5, SHA-1, ...)
• Erase (wipe) confidential files securely, hard drive cleansing to protect your privacy
• Import all clipboard formats, incl. ASCII hex values
• Convert between binary, hex ASCII, Intel Hex, and Motorola S
• Character sets: ANSI ASCII, IBM ASCII, EBCDIC, (Unicode)
• Instant window switching. Printing. Random-number generator
• Supports files >4 GB. Very fast. Easy to use. Extensive online help

What's new in v18.4:
- A new technology was implemented that can help you to identify known documents (word processing documents, presentations, spreadsheets, e-mails, plain text files, ...) with a much more robust approach than conventional hash values. Even if a document was stored in a different file format (e.g. first PPT, then PPTX, then PDF), it can still be recognized. Internal metadata changes, e.g. after a "Save as" or or after printing (which may update a "last printed" timestamp), do not prevent identification either. Very often even if text was inserted/removed/reordered/revised, a document can still be recognized. This is achieved by using fuzzy hashes. The technology is called FuzZyDoc.
FuzZyDoc hash values are stored in yet another hash database in X-Ways Forensics. So there are now 5 hash databases available in total, and counting. Hash sets based on selected documents can be added to the FuzZyDoc database exactly like hash sets can be created in ordinary hash databases, and the FuzZyDoc hash database can also be managed in the same dialog window as the other hash databases, so existing users will have no trouble locating and using the new functionality. For each selected document you can create 1 separate hash set, or you can create 1 hash set for all selected documents. Up to 65,535 hash sets are supported in a FuzZyDoc hash database.
FuzZyDoc is available to all users of X-Ways Forensics and X-Ways Investigator (i.e. not only law enforcement). FuzZyDoc should work well with documents in practically all Western and Eastern European languages, many Asian languages (e.g. Chinese, Japanese, Korean, Indonesian, Malay, Tamil, Tagalog, ..., but not Thai, Divehi, Tibetan, Punjabi, ...), and Middle Eastern languages (e.g. Arabic, Hebrew, ..., but not Pashto, ...). Note that numbers in spreadsheet cells are not exploited by the algorithm, only text. Note that only files with a confirmed or newly identified type will be matched against the FuzZyDoc hash database. For that reason, file type verification is applied automatically when FuzZyDoc matching is requested.
Documents whose contents are largely identical (e.g. invoices created by the same company with the same letterhead) are considered similar by the algorithm even if important details change (billing address, price), depending on the amount of identical text. That means that if you have 1 copy of an invoice of a company, matching against unknown documents will easily identify other invoices of the same company. For every document that is matched against the database, up to 4 matching hash sets are returned, and the 4 best matching hash sets are picked for that if more than 4 match. For every matching hash set, X-Ways Forensics also presents a percentage that roughly indicates to what degree the contents of the document match the hash set. For example, 100% means that all the textual contents that X-Ways Forensics deemed relevant in the given document can also be found in the hash set, 50% means half of the contents. 100% does not rule out the possibility that the document(s) that the hash set is based on contain(s) much more (other) text. The matching percentage does not count characters one by one, and it works only on documents that actually make sense, not on small test files that only contain a few words.
Before matching files against the FuzZyDoc hash database (a new operation of Specialist | Refine Volume Snapshot), you can specify which types of files you would like to analyze, and you can unselect hash sets in the database that you are temporarily not interested in. Note that processing less files (e.g. by specifying less file types in the mask) of course will require less time, proportionally, but selecting less hash sets for matching as such does not save time. You may specify a certain minimum percentage that you require for matches (15% by default) to ignore insignificant minor similarities. That option is not meant to save time either.
In order to re-match all documents in the volume snapshot against the FuzZyDoc hash database, please remove the checkmark in the "Already done" box first. Otherwise the same files will not be matched again, for performance reasons. Re-matching the same files may become necessary not only if you add additional hash sets to your FuzZyDoc database, but also if you delete hash sets, as that invalidates some internal links (if that happens, it will be shown in the cells of the result column).
FuzZyDoc should prove very useful for many kinds of white collar crime cases, most obviously (but not limited to) those involving stolen intellectual property (e.g. software source code) or leakage of classified documents. The technology is still in a testing stage.
- Matches with the FuzZyDoc database are presented in the same column as PhotoDNA matches and skin color percentages. That combined column is now more generically named "Analysis". A filter for FuzZyDoc matches is available. Sorting by the Analysis column in descending order now lists files with FuzZyDoc matches first (those files with the most confident matches for any hash set near the top, with lower percentages following), followed by PhotoDNA matches, if any, followed by pictures with no PhotoDNA matches (in descending order of their skin tone percentage). After that, irrelevant pictures are listed (picture with very small dimensions), and then files that are not pictures, and near the bottom black & white and gray scale pictures. Text color coding in that column now makes it easier to distinguish between different kinds of categorizations.
- The web history extracted from Internet Explorer (Webcache- files) is now added to the event list.
- Fixed possible errors when parsing UDF file systems.
- Several minor improvements.
- User manual and program help were updated for v18.4.
- Search in the registry viewer: Improved display of hits in the data of values.
- A rare exception error was fixed that could occur when extracting metadata from corrupt DBX e-mail archives.
- A rare exception error was fixed that could occur when carving individual e-mail messages (.eml files).
- A rare exception error was fixed that could occur when carving .dxf files.
- Fixed sender and recipients filter for processed original .eml and other single-mail files. These filters did not work in v18.2 and v18.3.
- Some inconsistencies within the inclusion of previously existing files and directories into snapshots of Ext3/Ext4 volumes in v18.3 were fixed.

Limitations under Windows Vista/2008 Server/7
Physical RAM cannot be opened. Install WinHlp32.exe (for Vista >>/for 7 >>) to be able to use the program help. Unable to write sectors on the partitions that contain Windows and WinHex.


For VIP-members only (BETA)
Если вы здесь ничего не видите, то значит здесь ничего нет, либо вы не входите в группу VIP-members
If You do not see here anything, it means there here is nothing, or you are not VIP-member.

Внимание! Всегда проверяйте антивирусом файлы, которые Вы загружаете! / Attention! Always check files you download with your antivirus software!

