Mar 27

How to become a computer detective

In the detective series, the researcher sitting in front of the suspect’s computer, press four keys and get all the information sought . In real life is not so simple, but with the right tools it is possible to scan a computer in a few hours.

Looking for what? For images, text, deleted files, chat logs, web history, passwords and all files that can track a person’s activity on a computer . Of course, many of these utilities can also be used to rescue your own information.

Recover deleted files and emails

Unless someone perform periodic cleaning of empty space (for example, Disk Wipe ) or working in temporary environments (eg Live-CD or virtual machines), recovering deleted files is not only possible but simple.

DiskDigger

Some of the most effective tools for this task are DiskDigger , Recuva , Pandora Recovery and TestDisk , which rescues even lost partitions and boot sectors.

If the data is unreadable CDs and DVDs, worth trying a low-level reading ISOBuster . For deleted emails in Outlook Express, Format Recovery is a good free option.

Rescue Passwords

The password protection is a system used by many websites, messengers and office tools. Collect existing keys can save much valuable information.

* BrowserPasswordDecryptor recovers all passwords stored in web browsers

* MessenPass does the same to users and passwords Messenger, ICQ, Yahoo …

* Mail PassView rescues key local mail accounts (Outlook, Eudora, Thunderbird, etc.).

* BulletsPassView , showin and AsteriskKey reveal passwords hidden behind asterisks

* WirelessKeyDump get the passwords for WiFi networks

* FireMaster attempts to recover the master password for Firefox

Mail Passview

Nirsoft and SecurityXploded have many tools designed exclusively for password recovery, almost all executables from USB sticks. It should be remembered that only get passwords stored without protection and that to break the encryption is necessary to use cryptographic attacks (for example, Cain & Abel ).

Digging in caches and histories

When we are using computers, spend much of our time surfing and chatting. This creates products in the form of text and images: the "trash" (cache) and activity logs (records) that are automatically stored (unless cleaned regularly or use private modes ).

* Sniper Chat collects records, pictures and contacts from Messenger, AIM and Yahoo Messenger

* IECacheView, MozillaCacheView, OperaCacheView y ChromeCacheView exploran la caché

* VideoCacheView is dedicated to Flash videos that are stored in the cache

* MyLastSearch collects recent searches performed on Google, Yahoo and Bing

* SkypeLogView used to see which were the last calls made ​​on Skype

* LiveContactsView lists the contact details of Windows Live Messenger

* FlashCookieView analiza las cookies Flash

skypelogview

There are also utilities for specific scenarios. WinPrefetchView , for example, discusses the Prefetch folder for data related to the programs that run more frequently, while Rifiuti delves into the Recycle Bin.

Search documents and email attachments

Search documents is a logical step in any investigation. FI Tools is able to find more than 4,000 types of files and browse its contents. On the other hand, with the help of DocFetcher and Metadata Extractor can search for text and metadata of the documents on the hard disk. To find text, Look Drive is particularly effective.

Drive Look

To rummage in Outlook attachments, OutlookAttachView is incredibly useful. For a quick backup of emails and attachments from Mozilla Thunderbird MozBackup is the first choice. And if you want a quick viewer, low Viewer Mail .

Search, sort and retrieve images

A portable version of Picasa is the best partner to find and organize photos quickly, even Adobis Photo Sorter and Media Event Organizer also serve to classify the images into groups.

Media Event Organizer

To recover deleted photos (Sean honest node ), we recommend Adroit Photo Recovery and Forensic Photo Adroit , the tools of computer forensics specialist in the recovery of images produced.

Explore your hard disk and memory

When considering a computer, you need an overview of folders and files; SpaceSniffer , scanner or Portable WinDirStat offer quick summaries of sharing space on hard drives. To create a database folder, use getFolder and FileList .

SpaceSniffer

Finally, it may happen that the computer you’ve accessed is still on and with open programs. Check out what files are in use with OpenedFilesView and analyzes the memory with the help of a hex editor (eg WinHex or HxD ).

Más avanzados son MoonSols Windows Memory Toolkit y Volatility Framework, que analizan volcados de memoria y ficheros de hibernación de Windows, trozos de memoria "congelados" que pueden contener información valiosa.

Suites: OSForensics y Windows File Analyzer

OSForensics is a suite of computer forensics with a series of unique utilities: text search, contents of the disc, recent activity analyzer, search for deleted files or discordant display of memory and disk.

OSForensics

The particularity of OSForensics, it concentrates several tools in one window, it is your case manager, useful for organizing data from different investigations.

The simplest is Windows File Analyzer , which explores in miniature databases (Thumbs.db files) files, preload (Prefetch), Recent Documents, Internet Explorer history and trash from the Trash.

Windows File Analyzer

An important warning …

These tools are distributed freely, but the legitimacy of their use depends on you. Unless you are authorized to access a computer and extract information, they should not use them.

More Resources:

* Forensics Wiki

* Computer Forensics en Wikipedia

* E-Evidence Tools

* Digital Investigation Journal

Other Electronics News:

 

Mar 16

Sandboxie: enters programs and websites in a cage

Imagine if every program you boot or website you open an animal loose in your computer: your code is rampant in the memory, leaving all traces of the hard disk, some difficult to eradicate. The virus does not act, because its mission is to prevent dangerous situations, not merely inconvenient.

The only way to run a program without affecting the operating system is isolated from the rest of the system. How? Through Sandbox ie literally, litter box – a program that intercepts any attempt to modify the system and locks it in the act, in short, a secure cage in which to open suspicious software. Let’s see how it works.

Installation and Getting Started

Sandboxie installation is very simple: just choose which language-in our case, Spanish-and follow the steps. The most sensitive is the Sandboxie driver installation, a low level component that is essential for blocking the programs in their attempts to access system resources.

Instalación de Sandboxie

Once installed and opened for the first time, Sandboxie automatically detects the installed applications that require special settings to run alone. Check the list to remove items and click OK. Do not disable this check, it is useful to increase the compatibility of Sandboxie with the software.

Sandboxie detecta aplicaciones instaladas

If the installer does not already done so, we recommend you enable integration with Windows Explorer. Click Configure and then click Integration with Windows Shell , once in the dialog box, mark the last two boxes and click OK.

Activar integracion con el Shell de Windows

Run a program with Sandboxie

Take a few seconds to study the window of Sandboxie. The first thing that jumps out is the program table sandboxed , ie isolated from other system resources. The menu is essential Sandbox: create multiple containers ( sandbox) and manage content and processes in memory.

Ejecutando Sandboxie con AllPlayer

When you right-click on a shortcut or executable, you’ll see a new option: Run Isolated in a Sandbox . Another click and you can assign the execution of the program in question to one of the sandbox exist. A typical configuration is to have a sandbox for surfing and another for opening files of dubious origin.

Lanzar un programa con Sandboxie

Título de programa ejecutado por Sandboxie

Caged programs are recognized by the presence of a pad between brackets in the title bar. Each was assigned an identifier itself (visible from the main window).

Sandboxie will display all open threads for the program, so do not panic if you see more than one process with the same name.

Manage programs caged

The program executed via Sandboxie can not save anything on your computer unless you so wish. For example, if you open a website in a sandbox (using the Run Web Browser menu Sandbox ) and downloads a file, Sandboxie detect the action and ask you what to do with it.

Restaurar archivo con Sandboxie

Remove files from the protected space Sandboxie is an action called "restoration." If you are unsure, do not worry, and then click Close: The files remain in the sandbox . You can view the contents of it by right clicking and selecting Explore Contents.

Contenido de una sandbox

Indeed, the sandbox is a system in miniature, with its own Windows Registry ( RegHive ) installed files and documents. Be very careful when exploring the contents of the sandbox, you will not be protected by the barrier. That is why Sandboxie recommended to manipulate time with a single browser.

Cleaning time

Have you finished working with the sandbox ? Then it’s time to collect belongings and cleaning. Command Quick Restore , accessible from the main window and from the notification icon, it lists the records kept by the individual programs within the chosen space, ready to be stored on your computer.

Restauracion rapida

Now it delete the files in the sandbox : Open the menu with a right click and select Clear Contents. In a show of wisdom, the program offers a last chance to save the files stored, waiting below a summary of the space occupied and the button deletion. Click to say goodbye to all that crap.

Borrado de una sandbox

For more secure deletion, we recommend that you install SDelete or Eraser and configure in paragraph Delete> Delete Order of settings sandbox . Its use ensures the complete disappearance of all traces left by programs temporary.

Have you ever used Sandboxie? Do you know any other alternatives?

Other Electronics News:

 

Mar 02

Reduce noise in your PC (and III): Portable

In our journey in search of a silent PC, we have seen what home solutions can take place and what components should be taken into account in choosing or renew your computer.

However, more and more users have a laptop, netbook or SFF (the Mac Mini) as host, and these teams are governed by different rules than those of desktops.

What are the tips to follow and which brands are the least noisy of the market?

Finding the culprits

First of all, we will explain why the additional problems of laptops about noise:

For maintaining its small size laptops, hardware designers must miniaturize the components and use all the space possible. In addition, the small size of the fans causes more noise, since they have to spin faster for chilled like normal.

These complications are structural and, of course, for designers is more important than a laptop remains cool and functioning properly to be quiet and do not last more than a few hours. That’s why there are few solutions in this field , very few if we consider also that many of these teams can not even open.

Homespun measures

Let’s start with the most obvious advice. One is that you be careful with where you place the laptop . If the surface is too padded, such as sofas, carpets and beds, or placed on the legs, there will be no space between the base of the laptop and the surface to dissipate heat. This will cause the fans are triggered earlier and faster.

If you look with the courage, performs a cleaning of the fans . To do this, remove the bottom first, as is usually the area from which you can access the innards of the computer. After removing the battery and open this part of the case, you’ll see more fans, among which is the CPU. This is the one you keep more clean, and always on a thin but consistent layer of thermal paste . On the materials used in cleaning, compressed air cans or simple hygienic ear buds can serve.

Taking account of the fans is not necessary nor a definitive solution but, due to their mobility, proportionally just attracting more dust and dirt than their counterparts, the desktop.

Controls and measures the speed

Generally, the workload is a portable medium is significantly lower than that of a desktop PC. Seen this way, why not turn off the fans in periods of low processing?

With programs such as SpeedFan (which we discussed in the previous chapter) and smcFanControl (for Mac), you not only control the speed in revolutions-fan, but the temperature data, to determine at what times you disable safe.

Zalman NC-1000: a silent base with auxiliary ports

If you impose too much respect to have your laptop without active cooling, you can replace it in specific places for a quieter fan base . Brands that have specialized in this type of media are silent Zalman and Silverstone .

Time for change

If these solutions do not satisfy you, the only alternative is a renewal of hardware , and hardware must be understood, in this case, the entire team. So, while you save to get your new notebook, ask yourself: What should I look to buy a laptop noise?

The Dell Inspiron Mini 9 netbook was the first that had no fans

And to give the team that makes less noise is not an easy task, mainly because the shops are not the best place to check this property and because there is usually very little information in the reviews on the decibels they generate. But do not worry, we will give you some tricks and makes you interested:

* Passive cooling: looking for a quiet laptop has to begin here. Increasingly, portable computers without fans, which are moving parts that tend to make more noise. An example are the latest models in the series Dell Inspiron Mini or Nokia 3G Booklet .

* SSD Memory: little by little, solid-state drives will gradually replace traditional hard drives for many reasons. They are faster, safer for moving equipment and what interests us make no noise. If you want to come on to the future, invest a little more dough and get a laptop with this type of storage, such as the Sony Vaio X or XPS Adamo , which come as standard.

* Buying Guides: since you can not consider more components, what from the other laptops are considered the quietest? The only answer I can give the empirical results , and very few specialists who collect them. A comprehensive website with information on emissions (noise and heat), is Notebookcheck , which devotes a special section in their reviews to analyze the noise generated by the equipment.

Conclusions: what is a silent computer?

Following the advice compiled in these three articles, you may have clues to what you can do to make your computer significantly lower noise levels. However, neither can make your PC or laptop sounds as if you were always off, or is this the key to make it silent.

All computers generate minimal noise. The key is to reduce it to acceptable limits and ensure that these are always regular and without contrasts, especially for our brains do not notice them.

Q " know hat similar solutions to mute the laptops? What brands consideráis the best in this regard?

Other supplies

* First part: household tips

* Part Two: Buying Guide

* Part Three: laptops and netbooks

Other Electronics News:

 

Nov 26

Is there life after Partition Magic?

A key task, too often delayed into oblivion, is to partition the hard disk. The structuring of space in units promotes defense against malware attacks, while helping to control more easily readable, write and execute.

The first partition should be allocated to different units placed in the Windows system files and private papers. Thus, if for some reason we had to delete the operating system, our documents, pictures and videos would be safe in another drive.

The Windows installation disc want to create as many partitions after formatting, which can mean a great inconvenience. Added are several solutions to overcome the setback of the formatting. When Partition Magic trial version available had no doubts about the tool to use. Today we have to make do with programs that are loaded before Windows in a three and a half drive or CD.

Partition Logic

After downloading the ISO image and burn to a CD, we start the computer with the disk inside the unit to read CD or DVD. Previously we verify that the system BIOS is enabled to boot from the CD rather than from the hard disk.

Not find a program with a Windows-like interface, really comfortable to choose the size of the partitions and format type.

SwissKnife Compuapps

Create partitions on external drives, no hard disk, so the program works from Windows.

Ranish Partition Manager

This program has been the traditional alternative to Partition Magic. For anyone familiar with the BIOS menus seem very easy to handle. The interface looks the same.

As partition logic, it needs to load the program from an external drive before you start the operating system.

Another option is really convenient to use a liveCD with some version of Linux and run a partitioning program such QParted.

Other Electronics News:

⇒⇒⇒ dell inspiron 1501 battery

⇒⇒⇒ dell inspiron e1505 battery

⇒⇒⇒ canon eos 350d battery grip

⇒⇒⇒ lenovo thinkpad x41 battery

⇒⇒⇒ laptop batteries