Download WinHex Forensic Edition v12.05SR-11 crack by DEVOTiON

Added to site2005-06-04
Rating80/100
Votes3


winhexforensiceditionv12.05sr11crackdevotion.zip (658879 bytes)

namesizecompressed
DVT/ 0 0
DVT/File Type Categories.txt 1221 660
DVT/hi.dll 876544 367282
DVT/rar.dll 46592 25844
DVT/Reg Report Keys.txt 27310 4131
DVT/user.txt 145 111
DVT/zip.dll 396288 196005
dvt.nfo 15043 4023
file_id.diz 564 232
crack.exe 174080 59651

DVT/File Type Categories.txt

:1:E-Mail
cnm
cnr
dbx
fdb
ldb
ldif
mbs
mbx
msf
olk
ost
pmb
pmm
pmr
pst
snm
tbb
tbi
:2:Internet
asp
cgi
css
dtml 
fla
htm
html
js
php
php3
php4
phtml
shtml
swf
thtml
ttml
xml
:3:Office/Document
aba
abw
abx
adp
ai
apd
csv
cws
doc
dqy
eps
etd
faq
fm
geo
hdf
ics
latex
lit
mdb
mif
oab
opf
pab
pdf
pkg
pm
pm3
pm4
pm5
pps
ppt
pqa
ps
pub
pwd
pxl
qxd
rb
rtf
sdc
sdd
sdw
seb
stc
std
sti
stw
sxc
sxd
sxi
sxw
tex
tr
tsv
txt
vor
wir
wk1
wks
wp
wp5
wp6
wpp
wq1
xls
wab
:4:Image
bmp
gif
ico
jbg
jbig
jpeg
jpg
png
tif
vsd
wmf
emf
tga
pcx
:5:Multimedia
aif
aifc
aiff
asf
avi
divx
mov
mp3
mpeg
mpg
ogg
rm
rpm
sav
wav
:6:Application
awk
bat
bin
bsh
class
com
csh
dcu
dll
drv
el
elc
exe
gid
hlp
chm
inf
ksh
lib
obj
ocx
out
ovl
pif
prg
py
pyc
pyo
rc
scr
sh
so
sys
tcl
vbs
vxd
whs
:7:Compressed
7z
adf
arj
bz
bz2
cab
d64
deb
gz
jar
lha
lzh
mht
pdb
pdc
rar
rpm
t64
tar
tar.bz
tar.gz
tgz
whx
zip
:8:Source Code
~pas
asm
bas
c
c#=
cc
cpp
cxx
dfm
dpr
dsp
dsw
f66
f77
f90
h
hpp
hxx
java
m
M
mak
mm
pas
tem
template
vcproj


DVT/Reg Report Keys.txt

NT	HKLM\Software\Microsoft\Windows NT\CurrentVersion\CurrentVersion				Operating system: version number
NT	HKLM\Software\Microsoft\Windows NT\CurrentVersion\InstallDate					Operating system: installation date
NT	HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProductId					Operating system: product id
NT	HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProductName					Operating system: name
NT	HKLM\Software\Microsoft\Windows NT\CurrentVersion\RegisteredOwner				Operating system: name of registered person
NT	HKLM\Software\Microsoft\Windows NT\CurrentVersion\RegisteredOrganization			Operating system: name of registered organization
NT	HKLM\Software\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber				Operating system: build number
NT	HKLM\Software\Microsoft\Windows NT\CurrentVersion\CurrentType					Operating system: processor architecture
NT	HKLM\Software\Microsoft\Windows NT\CurrentVersion\CSDVersion					Operating system: service pack

NT	HKLM\System\Select\Current									Number of control set that is currently active

NT	HKLM\System\ControlSet*\Services\DMIO\Boot Info\Primary Disk Group\*				Last removable disk mounted into system

NT	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\Device				Default printer

NT	HKLM\ControlSet*\Control\TimeZoneInformation\StandardName					User-configured time zone
NT	HKLM\ControlSet*\Control\TimeZoneInformation\DaylightName					User-configured daylight savings time

NT	HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\LegalNoticeText			Legal notice text appearing before logon
NT	HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\LegalNoticeCaption		Legal notice caption appearing before logon

NT	HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\*				User-specific directories
NT	HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\*			User-specific directories

NT	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\DefaultUserName			Last logged on user
NT	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\DefaultDomainName			Domain that last user logged on to

NT	HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\*\ProfileLoadTimeHigh		Profile load time of user
NT	HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\*\ProfileLoadTimeLow		Profile load time low of user
NT	HKLM\System\ControlSet*\Control\Windows\ShutdownTime						Time of last system shutdown

NT	HKLM\System\ControlSet*\Services\LanManServer\Shares\SharedDocs					Shared folders in a network
NT	HKCU\Network\*\RemotePath									Path of mapped network drive
NT	HKCU\Network\*\ProviderName									Type of network
NT	HKLM\Software\Microsoft\Windows NT\CurrentVersion\NetworkCards\*\Description			Model description of installed network card
NT	HKLM\Software\Microsoft\Windows NT\CurrentVersion\NetworkCards\*\ServiceName			Unique identifier for installed network cards
NT	HKLM\System\ControlSet001\Services\{*}\Parameters\Tcpip\*					Parameters of network card like IP address
NT	HKLM\System\ControlSet002\Services\{*}\Parameters\Tcpip\*					Parameters of network card like IP address
NT	HKLM\System\ControlSet003\Services\{*}\Parameters\Tcpip\*					Parameters of network card like IP address

NT	HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Logon User Name				Name of registered user

NT	HKCU\Environment\*										System environment variables

NT	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\AccountName				User-defined account name
NT	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\HTTPMail User Name			Hotmail?
NT	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\HTTPMail Password2			Hotmail?
NT	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\POP3 User Name			Incoming mail: user name
NT	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\POP3 Server				Incoming mail: server name
NT	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\POP3 Email Address			Incoming mail: email address
NT	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\POP3 Reply To Email Address		Incoming mail: reply-to address
NT	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\SMTP Signature			Outgoing mail: signature
NT	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\SMTP Server				Outgoing mail: server name
NT	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\SMTP User Name			Outgoing mail: user name
NT	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\SMTP Display Name			Outgoing mail: display name
NT	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\SMTP Email Address			Outgoing mail: email address
NT	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\SMTP Reply To Email Address		Outgoing mail: reply-to address
NT	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\NNTP Signature			Newsgroup: signature
NT	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\NNTP User Name			Newsgroup: user name
NT	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\NNTP Display Name			Newsgroup: display name
NT	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\NNTP Server				Newsgroup: server name
NT	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\NNTP Email Address			Newsgroup: email address
NT	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\NNTP ReplyTo			Newsgroup: reply-to address
NT	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\LDAP Server				LDAP Server
NT	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\LDAP Url				LDAP URL

NT	HKCU\Software\Mirabilis\ICQ\NewOwners\*\Name							ICQ user name
NT	HKCU\Software\Mirabilis\ICQ\NewOwners\*\LastLoginDate						ICQ user's last login date

NT	HKCU\Software\Yahoo\Pager\Yahoo! User ID							Yahoo Messenger login name
NT	HKCU\Software\Yahoo\Pager\File Transfer\*							Yahoo Messenger file transfer history
NT	HKCU\Software\Yahoo\Pager\profiles\*\Chat\LastSelCategory					Yahoo Messenger last chat room visited


NT	HKCU\Software\Kazaa\UserDetails\*								Kazaa user information
NT	HKCU\Software\Kazaa\Search\*									Kazaa history of search expressions
NT	HKCU\Software\Kazaa\LocalContent\DownloadDir							Kazaa current download directory
NT	HKCU\Software\Kazaa\Transfer\DlDir0								Kazaa first used download directory
NT	HKCU\Software\Kazaa\Transfer\DlDir1								Kazaa second used download directory
NT	HKCU\Software\Kazaa\Transfer\DlDir2								Kazaa third used download directory
NT	HKCU\Software\Kazaa\Transfer\DlDir3								Kazaa fourth used download directory
NT	HKCU\Software\Kazaa\Transfer\DlDir4								Kazaa fifth used download directory
NT	HKCU\Software\Kazaa\Transfer\DlDir5								Kazaa sixth used download directory
NT	HKCU\Software\Kazaa\Transfer\DlDir6								Kazaa seventh used download directory
NT	HKCU\Software\Kazaa\Transfer\DlDir7								Kazaa eigth used download directory
NT	HKCU\Software\Kazaa\Transfer\DlDir8								Kazaa nineth used download directory
NT	HKCU\Software\Kazaa\Transfer\DlDir9								Kazaa tenth used download directory

NT	HKCU\Software\Microsoft\Windows\CurrentVersion\Themes\InstallTheme				Installed wallpaper/desktop theme
NT	HKCU\Software\Microsoft\Windows\CurrentVersion\Themes\LastTheme\Wallpaper			Last installed wallpaper/desktop theme
NT	HKCU\Control Panel\Desktop\ConvertedWallpaper							Converted desktop wallpaper
NT	HKCU\Control Panel\Desktop\Wallpaper								Bitmap desktop wallpaper
NT	HKCU\Control Panel\Desktop\OriginalWallpaper							Original Bitmap desktop wallpaper
NT	HKCU\Control Panel\Desktop\SCRNSAVE.EXE								Screensaver

NT	HKCU\Software\Microsoft\Windows NT\CurrentVersion\Network\Persistent Connections\*\*		Foreign host name and shared resources (only one-character names)

NT	HKLM\Software\Microsoft\Windows\CurrentVersion\Installer					
NT	HKCU\Software\Microsoft\Windows\CurrentVersion\Installer

NT	HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\*\DisplayName				Local machine: installed programs:  name
NT	HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\*\InstallLocation			Local machine: installed programs:  target 
NT	HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\*\InstallSource			Local machine: installed programs:  source
NT	HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\*\InstallDate				Local machine: installed programs:  installation date

NT	HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\*\DisplayName				User-specific: installed programs:  name
NT	HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\*\InstallLocation			User-specific: installed programs:  target 
NT	HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\*\InstallSource			User-specific: installed programs:  source
NT	HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\*\InstallDate				User-specific: installed programs:  installation date


NT	HKCU\Software\Microsoft\Windows\CurrentVersion\Run\*						User-specific auto-start programs
NT	HKLM\Software\Microsoft\Windows\CurrentVersion\Run\*						System-specific auto-start programs

NT	HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\*				Programs associated with file extensions
NT	HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\*						Cache for installed executables

NT	HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count\*	History of web pages visited with IE (ROT 13 encryption)
NT	HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\*	History of programs started (ROT 13 encryption)


NT	HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU\*		List of folders visited (MRUList: order of entries: entry with first char as name was opened last etc.)
NT	HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*			History of files that were opened or saved (MRUList: order of entries: entry with first char as name was opened last etc.)
NT	HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*\*		History of files that were opened or saved, listed by extensions (MRUList: order of entries: entry with first char as name was opened last etc.) 
NT	HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\*				History of documents opened
NT	HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\*\*				History of documents opened, listed by extension
NT	HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU\*				History of programs started from run dialog box (MRUList: order of entries: entry with first char as name was opened last etc.)
NT	HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Map Network Drive MRU\*			Network drives that were mapped	(MRUList: order of entries: entry with first char as name was opened last etc.)

NT	HKCU\Software\Microsoft\Search Assistant\ACMru\5001\*						Expressions that were searched for on the Internet
NT	HKCU\Software\Microsoft\Search Assistant\ACMru\5603\*						Expressions that were searched for in local files, folders or documents
NT	HKCU\Software\Microsoft\Search Assistant\ACMru\5604\*						Pictures, music or videos that were searched for
NT	HKCU\Software\Microsoft\Search Assistant\ACMru\5647\*						Printers, computers or people that were searched for

NT	HKCU\Software\Microsoft\MediaPlayer\Player\RecentURLList\*					Video files that were opened with Windows Media Player
NT	HKCU\Software\Microsoft\MediaPlayer\Preferences\LastPlaylist\*					MS Media Player: Last opened playlist
NT	HKCU\Software\Microsoft\MediaPlayer\Player\RecentFileList\*					MS Media Player: Recent file list
NT	HKCU\Software\Microsoft\MediaPlayer\Player\Settings\OpenDir					MS Media Player: Recent open directory

NT	HKCU\Software\Microsoft\Direct3D\MostRecentApplication\Name					User-specific: most recent application that used Direct3D
NT	HKLM\SOFTWARE\Microsoft\Direct3D\MostRecentApplication\Name					Local machine: most recent application that used Direct3D
NT	HKLM\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication\Name					Local machine: most recent application that used DirectDraw
NT	HKCU\Software\Microsoft\Windows Media\WMSDK\General\VolumeSerialNumber				Windows Media SDK: Volume serial number
NT	HKCU\Software\Microsoft\Windows Media\WMSDK\General\ComputerName				Windows Media SDK: Computer name


NT	HKCU\Software\Microsoft\Internet Explorer\TypedURLs\*					 	History of URLs typed in Internet Explorer
NT	HKCU\Software\Microsoft\Internet Explorer\Download Directory					Last used download location of Internet Explorer
NT	HKCU\Software\Microsoft\Internet Explorer\Main\Save Directory					Last used download location of Internet Explorer
NT	HKCU\Software\Microsoft\Internet Explorer\Main\Start Page					Start page in Internet Explorer
NT	HKCU\Software\Microsoft\Internet Explorer\IntelliForms\SPW\*					Auto remember passwords Internet Explorer
NT	HKCU\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\ComputerNameMRU\*		Windows Explorer: Computer search history
NT	HKCU\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\FilesNamedMRU\*			Windows Explorer: File search history
NT	HKCU\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\ContainingTextMRU\*		Windows Explorer: history of containing text qualifiers that were used in searches


NT	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ratings\Key				Internet Explorer Content Advisor 128-bit-encrypted password  (MD4-encrypted)
NT	HKCU\Software\Adobe\Acrobat Reader\4.0\AVGeneral\cRecentFiles\c*\*				Recent documents opened in Acrobat Reader 4.0
NT	HKCU\Software\Adobe\Acrobat Reader\5.0\AVGeneral\cRecentFiles\c*\*				Recent documents opened in Acrobat Reader 5.0
NT	HKCU\Software\Adobe\Acrobat Reader\6.0\AVGeneral\cRecentFiles\c*\*				Recent documents opened in Acrobat Reader 6.0
NT	HKCU\Software\Adobe\Acrobat Reader\7.0\AVGeneral\cRecentFiles\c*\*				Recent documents opened in Acrobat Reader 7.0

NT	HKCU\Software\Microsoft\FrontPage\Editor\FrontPage Editor\Recent File List\*			MS Frontpage: Recent file list
NT	HKCU\Software\Microsoft\FrontPage\Editor\FrontPage Editor\Recent Page List\*			MS Frontpage: Recent page list
NT	HKCU\Software\Microsoft\FrontPage\Editor\FrontPage Editor\Recent Web List\*			MS Frontpage: Recent web list
NT	HKCU\Software\Microsoft\FrontPage\Editor\Recently Used URLs\*					MS Frontpage: Recently used image URLs

NT	HKCU\Software\Microsoft\Office\*\Excel\Recent Files\*						MS Office (Excel): Recent file list
NT	HKCU\Software\Microsoft\Office\11.0\Word\Data\Settings						WORD
NT	HKCU\Software\Microsoft\Office\*\PowerPoint\Recent File List\*					MS Office (PowerPoint): Recent file list
NT	HKCU\Software\Microsoft\Office\*\Access\Settings\MRU*						MS Office (Access) recent file

NT	HKCU\Software\Microsoft\Office\*\Outlook\Security\OutlookSecureTempFolder			Last download location for attachments received in Outlook

NT	HKCU\Software\Microsoft\Office\*\Common\Internet\*						MS Office Internet history

NT	HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List\*			MS Paint: Recent file list
NT	HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad\Recent File List\*		MS Wordpad: Recent file list
NT	HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\RegEdit\Recent File List\*		MS RegEdit: Recent file list

9x	HKLM\Hardware\Description\System\CentralProcessor\0\Identifier					Processor Identifier
9x	HKLM\Hardware\Description\System\CentralProcessor\0\VendorIdentifier				Processor's vendor identifier

9x	HKLM\Enum\SCSI\*										SCSI devices
9x	HKLM\Enum\PCI\*											PCI devices
9x	HKLM\Enum\USB\*											USB devices
9x	HKLM\Enum\FLOP\*										Disk floppy devices
9x	HKLM\Enum\ESDI\*										IDE devices

9x	HKLM\Software\Microsoft\Windows\CurrentVersion\VersionNumber					Operating system: version number
9x	HKLM\Software\Microsoft\Windows\CurrentVersion\FirstInstallDateTime				Operating system: installation date
9x	HKLM\Software\Microsoft\Windows\CurrentVersion\ProductId					Operating system: product id
9x	HKLM\Software\Microsoft\Windows\CurrentVersion\ProductKey					Operating system: product key
9x	HKLM\Software\Microsoft\Windows\CurrentVersion\ProductName					Operating system: name
9x	HKLM\Software\Microsoft\Windows\CurrentVersion\RegisteredOwner					Operating system: registered to

9x	HKLM\Network\Logon\username									Last used user name for logon
9x	HKLM\Network\Logon\PrimaryProvider								Primary provider for network services

9x	HKCU\.DEFAULT\Network\Recent\*									Network folders that were connected to/searched for
9x	HKCU\.DEFAULT\Network\Persistent\*								Persistent network connections
9x	HKCU\Network\Recent\*										Network folders that were connected to/searched for
9x	HKCU\Network\Persistent\*									Persistent network connections
9x	HKLM\Software\Microsoft\Windows\CurrentVersion\Network\LanMan\*					Shared folders in a network


9x	HKCU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\*		User-defined directories
9x	HKCU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\*		System-defined directories
9x	HKCU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\*			Recently accessed documents
9x	HKCU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU\*			Recently executed programs
9x	HKCU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\FindComputerMRU\*		Computers names that were looked for
9x	HKCU\.DEFAULT\InstallLocationsMRU\*								Recent application installation activities
9x	HKCU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Doc Find Spec MRU\*		Recently used search expressions
9x	HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\*			User-defined directories
9x	HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\*				System-defined directories
9x	HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\*				Recently accessed documents
9x	HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU\*				Recently executed programs
9x	HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FindComputerMRU\*			Computers names that were looked for
9x	HKCU\InstallLocationsMRU\*									Recent application installation activities
9x	HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Doc Find Spec MRU\*			Recently used search expressions

9x	HKCU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count\*	History of web pages visited with IE (ROT 13 encryption)
9x	HKCU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\*	History of programs started (ROT 13 encryption)
9x	HKCU\.DEFAULT\Identities\*									Installed identities
9x	HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count\*		History of web pages visited with IE (ROT 13 encryption)
9x	HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\*		History of programs started (ROT 13 encryption)
9x	HKCU\Identities\*										Installed identities
9x	HKLM\Software\Microsoft\Windows\CurrentVersion\Setup\Wallpaper					Desktop wallpaper
9x	HKCU\.DEFAULT\Desktop\Wallpaper									User-specific desktop wallpaper
9x	HKCU\.DEFAULT\Software\Microsoft\Internet Explorer\TypedURLs\*					History of URLs typed in Internet Explorer
9x	HKCU\.DEFAULT\Software\Microsoft\Internet Explorer\Main\Start Page				Start page in Internet Explorer
9x	HKLM\Software\Microsoft\Internet Domains\*							Internet domains


9x	HKLM\Software\Microsoft\Internet Account Manager\Preconfigured\*\AccountName				User-defined account name
9x	HKLM\Software\Microsoft\Internet Account Manager\Preconfigured\*\HTTPMail User Name			Hotmail?
9x	HKLM\Software\Microsoft\Internet Account Manager\Preconfigured\*\HTTPMail Password2			Hotmail?
9x	HKLM\Software\Microsoft\Internet Account Manager\Preconfigured\*\POP3 User Name				Incoming mail: user name
9x	HKLM\Software\Microsoft\Internet Account Manager\Preconfigured\*\POP3 Server				Incoming mail: server name
9x	HKLM\Software\Microsoft\Internet Account Manager\Preconfigured\*\POP3 Email Address			Incoming mail: email address
9x	HKLM\Software\Microsoft\Internet Account Manager\Preconfigured\*\POP3 Reply To Email Address		Incoming mail: reply-to address
9x	HKLM\Software\Microsoft\Internet Account Manager\Preconfigured\*\SMTP Signature				Outgoing mail: signature
9x	HKLM\Software\Microsoft\Internet Account Manager\Preconfigured\*\SMTP Server				Outgoing mail: server name
9x	HKLM\Software\Microsoft\Internet Account Manager\Preconfigured\*\SMTP User Name				Outgoing mail: user name
9x	HKLM\Software\Microsoft\Internet Account Manager\Preconfigured\*\SMTP Display Name			Outgoing mail: display name
9x	HKLM\Software\Microsoft\Internet Account Manager\Preconfigured\*\SMTP Email Address			Outgoing mail: email address
9x	HKLM\Software\Microsoft\Internet Account Manager\Preconfigured\*\SMTP Reply To Email Address		Outgoing mail: reply-to address
9x	HKLM\Software\Microsoft\Internet Account Manager\Preconfigured\*\NNTP Signature				Newsgroup: signature
9x	HKLM\Software\Microsoft\Internet Account Manager\Preconfigured\*\NNTP User Name				Newsgroup: user name
9x	HKLM\Software\Microsoft\Internet Account Manager\Preconfigured\*\NNTP Display Name			Newsgroup: display name
9x	HKLM\Software\Microsoft\Internet Account Manager\Preconfigured\*\NNTP Server				Newsgroup: server name
9x	HKLM\Software\Microsoft\Internet Account Manager\Preconfigured\*\NNTP Email Address			Newsgroup: email address
9x	HKLM\Software\Microsoft\Internet Account Manager\Preconfigured\*\NNTP ReplyTo				Newsgroup: reply-to address
9x	HKLM\Software\Microsoft\Internet Account Manager\Preconfigured\*\LDAP Server				LDAP Server
9x	HKLM\Software\Microsoft\Internet Account Manager\Preconfigured\*\LDAP Url				LDAP URL
9x	HKCU\.DEFAULT\Software\Microsoft\Internet Account Manager\Accounts\*\AccountName			User-defined account name
9x	HKCU\.DEFAULT\Software\Microsoft\Internet Account Manager\Accounts\*\HTTPMail User Name			Hotmail?
9x	HKCU\.DEFAULT\Software\Microsoft\Internet Account Manager\Accounts\*\HTTPMail Password2			Hotmail?
9x	HKCU\.DEFAULT\Software\Microsoft\Internet Account Manager\Accounts\*\POP3 User Name			Incoming mail: user name
9x	HKCU\.DEFAULT\Software\Microsoft\Internet Account Manager\Accounts\*\POP3 Server			Incoming mail: server name
9x	HKCU\.DEFAULT\Software\Microsoft\Internet Account Manager\Accounts\*\POP3 Email Address			Incoming mail: email address
9x	HKCU\.DEFAULT\Software\Microsoft\Internet Account Manager\Accounts\*\POP3 Reply To Email Address	Incoming mail: reply-to address
9x	HKCU\.DEFAULT\Software\Microsoft\Internet Account Manager\Accounts\*\SMTP Signature			Outgoing mail: signature
9x	HKCU\.DEFAULT\Software\Microsoft\Internet Account Manager\Accounts\*\SMTP Server			Outgoing mail: server name
9x	HKCU\.DEFAULT\Software\Microsoft\Internet Account Manager\Accounts\*\SMTP User Name			Outgoing mail: user name
9x	HKCU\.DEFAULT\Software\Microsoft\Internet Account Manager\Accounts\*\SMTP Display Name			Outgoing mail: display name
9x	HKCU\.DEFAULT\Software\Microsoft\Internet Account Manager\Accounts\*\SMTP Email Address			Outgoing mail: email address
9x	HKCU\.DEFAULT\Software\Microsoft\Internet Account Manager\Accounts\*\SMTP Reply To Email Address	Outgoing mail: reply-to address
9x	HKCU\.DEFAULT\Software\Microsoft\Internet Account Manager\Accounts\*\NNTP Signature			Newsgroup: signature
9x	HKCU\.DEFAULT\Software\Microsoft\Internet Account Manager\Accounts\*\NNTP User Name			Newsgroup: user name
9x	HKCU\.DEFAULT\Software\Microsoft\Internet Account Manager\Accounts\*\NNTP Display Name			Newsgroup: display name
9x	HKCU\.DEFAULT\Software\Microsoft\Internet Account Manager\Accounts\*\NNTP Server			Newsgroup: server name
9x	HKCU\.DEFAULT\Software\Microsoft\Internet Account Manager\Accounts\*\NNTP Email Address			Newsgroup: email address
9x	HKCU\.DEFAULT\Software\Microsoft\Internet Account Manager\Accounts\*\NNTP ReplyTo			Newsgroup: reply-to address
9x	HKCU\.DEFAULT\Software\Microsoft\Internet Account Manager\Accounts\*\LDAP Server			LDAP Server
9x	HKCU\.DEFAULT\Software\Microsoft\Internet Account Manager\Accounts\*\LDAP Url				LDAP URL
9x	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\AccountName					User-defined account name
9x	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\HTTPMail User Name				Hotmail?
9x	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\HTTPMail Password2				Hotmail?
9x	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\POP3 User Name				Incoming mail: user name
9x	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\POP3 Server					Incoming mail: server name
9x	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\POP3 Email Address				Incoming mail: email address
9x	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\POP3 Reply To Email Address			Incoming mail: reply-to address
9x	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\SMTP Signature				Outgoing mail: signature
9x	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\SMTP Server					Outgoing mail: server name
9x	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\SMTP User Name				Outgoing mail: user name
9x	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\SMTP Display Name				Outgoing mail: display name
9x	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\SMTP Email Address				Outgoing mail: email address
9x	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\SMTP Reply To Email Address			Outgoing mail: reply-to address
9x	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\NNTP Signature				Newsgroup: signature
9x	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\NNTP User Name				Newsgroup: user name
9x	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\NNTP Display Name				Newsgroup: display name
9x	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\NNTP Server					Newsgroup: server name
9x	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\NNTP Email Address				Newsgroup: email address
9x	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\NNTP ReplyTo				Newsgroup: reply-to address
9x	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\LDAP Server					LDAP Server
9x	HKCU\Software\Microsoft\Internet Account Manager\Accounts\*\LDAP Url					LDAP URL

9x	HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\*\DisplayName				Local machine: installed programs:  name

9x	HKCU\.DEFAULT\Software\Microsoft\MediaPlayer\Player\RecentURLList				Video files that were opened with Windows Media Player








DVT/user.txt

Name: "TEAM DVT"
Addr1: "TEAM DVT"
Addr2: "TEAM DVT"
Key1: 26549C015AE971F45702D554D66A9350
Key2: 6B639CD87A2ADC3D5301B684F0120991
Chksm: 2C


dvt.nfo

      ▄▄▄▄▄                                  ▀               ■
     ██████▓▓▓▄                          ▄▀                      ▄
    ▐███▓▓▓▀▀▀▀▀▀▄▄▄                 ▄▄▓▓▌   ▄        ▄            ▄
▓▓▄▓▓█▓▓▀           ▀▀▀▓▓▄▄▄▄    ▄████████▓██▓███▄█▓▓▄▓▄▓▓▓▓▄███▓▓▓▓▓▒▒░░░ ░
 ░▒▒▒ █▌       ▄▄▄       ▀▀█▓██░▐█████▓▓▓▓▒▓▓▒▓▓▓█▓▓▓▒▓▓▓▓▓▓█▓▓█▓▒▒▓▒▒░ ░░░  ░
█▄ ░░░ ▓    ▄▓▓▓▓▓▓▓▓▄▄      ▀▀▓▐████▓▒░▒▒░▒▓░▓▒▒▓▓▒▒░▒▓▒▒▓▓▓▒▒▓▒░░▒░░░░░
███▄▄   ▓  ▓▓▓▒▒▒▒▒▀▀▀▓▓▓▄▄▄      ▀███▄░▒░░ ▒░▒░░▒▓░░░░▒░▄▄▄▄▄▄▀▒░ ░░  ░ ▄▄██▓
██████▄ ░▓  ▓▒░        ░░▒▓▓▓▓▄▄▄    ▀▀▓▓░  ░ ░  ░▒░ ░░░░ ██████▐░ ░ ▄▄██▓▓▓▓▌
▓█████▒▓▄▒▓ ▒ ▄▀▀▀▀▓▄▄     ░░▒▒▓▓▓▓▄▄     ▀▀▀▄▄▄▄▄░    ░ ▐██▓▀░▒▀▓▓▓█▀████▓▓▓
▓▓▓█████▄▀▒▓▓▓     ▒  ██▄▄     ░░▒▒▓▓▓▒░░     ▐█▓█████▓▓▓▒▒░░░▒▒▒▓▓█▓▒░███▓▓█
█▓▓▓▓██████▄▄▄     ░  ▐▓▓█▓▓▄▄    ░░▒▒▒▒▒░░░  ░█▀▓▓█████▒▒░░▒▒▒░██▀▀  ▐██▓▓▓▌
 ▀▀▀▓▓▓▀█████████▄▄▄   █▓▓███▓▌       ░░▒░░░░░▒█░      █▒░▒▒▓▓▀       ▄▄▄▄ █
░░░    ▀▀▀▓▄▓▓▀▓▀▀▀▀███▄▄▀▓███▌         ░░▒░░▒▓█      █░▒▓▓▓▓▀       ▐▓▓▓▓▐▌
░░▒░░  ▄▄▄░░░▀▓▒▓▓▓▓▄▄▄▀▀▀▄▓███░░░▒▓▓▄▄   ▓▒▒▓█▌ ░   █░▓█▓▓▓▀        ▓▓▓▓▀▓
 ░░░▄▓▓▓▓▄▓▓▄░ ░  ▀▀▒▒▒▒▒▒▄▄ ▀█▌ ░░░░▒▓▒ ▐▓▒▒▐▒ ░   █▒██▓▓▓▌        ▒▀▀▀▄▀
  ▄▓▒░ ▓███░▒▒▌     ▒▒ ▀▓▓▓▓▓▄ █░░  ░░▒░ █▓▓▒█▒░   █▒██▓▓▓▓         ▄▄ ▀
 ▐▓▒░   ▓███░▒▓░    ░░   ███▓▓▓▐▒     ░ ▐▓▓▒██▌░  ▐████▓▓▓▌  ▄    ▀
▄▄▓▓▒▀  ▓███░▓▓▒   ▄▄    █████▓▐▓       █▓▒▐██▌   █▓███▓▓▓
▓▓▒░▌  ▓███░▒▓▓▒▀ ▀▓▓▀  ██████▓▒▌   ░░ ▐▓▒▐███▓   ▐▓████▓▓
▓▓▌▐▌ ▓██▀░▒▓▓▒       ▄▓█▓▓███░▓█      █▒░██▌█▓▌░  █▓▓███▓▌
██▓▄▀▒▀▀░▒▒▓▓▀   ▄▄▄▓██▓▒▓██▌▒▓█▓     ▐▒░▐██░▓█▓▄   ▀▓▓███▓
 ▀▓▓▓▓▒▒▓▓▓▓▄▄▓▓▓▓███▀░▄██▀░▓▓███▌    ▓░▐██▌░▒▓██▓▄░░ ▀▓▓██▒             ▄█▓
  ▄▄█▓▀▀█▀▀█▀█▀▀▀▀▀  ▄▀▀     ▓▓███   ▐░▐██▓  ░░▒██▓▓▄ ░░░▀▀▒▓▄▄      ▄▄▄▀ ███
▄█▓▓▒░░░░░ ░▀▓▓▄▄▄▓▓▓▀░▀▀▄   ▐▓███▌  ░▐███ ▄█▄░▐▓█▀▀▓▓▓▄▄▄░░░▒▒▒▓▓█▓▀▀░░░▒███▌
██▓▓▓▓▄░░░    ▀▀▓▓▓▌░░░░░ ▀▓▄ ▓▓███ ▐████▌  ▀ ▄▓▀  ░░░ ▀▀▓▓▓▓▓▓▀▀▀  ░░▄▄▄▓▓██▌
████▓▀▀▓▓▓▄▄     ▀▓▓▄▄░▒░░░░ ▀■▓▓███████▌   ▄▀ ░░░░░▒  ▄▄▄▄▀▀    ▄▄▄▓▓▀▀▓███▀
 ▀▓██▒░  ░▀▀▓▓▄▄    ▀▀▓▓▄▄   ░░▒▓▓██████▄■▀▓▒░  ░░▄▄▓▓▀▀     ▄▄▓▀ ░  ░▒███▀ ░
░   ▀▓█▄▄▄▄▒░░ ▀▓▓▓▄     ▀▀▓▓▓▓▄▄▓█████▓▒░▄▄▄▄▓▓▓▀▀      ▄▓▓▓▀ ░░▒▄▄▄▄██▀ ░░▒
   ▄▀░░░   ▀▀▓▄▄  ▀▓▓█▄    ░  ▀▀▀▓▓▓▓▓▓▓▓▓▓▀▀▀  ░     ▄█▓▓▀  ▄▄▓▀▀   ░░░▀▄ ░░
  ▐▌ ▄██▓█▀▄▄    ▀  ░░▀▓▓▄▄    ░░  ▀▀▀▀▀▀   ░░    ▄▄▓▓▓░░  ▀    ▄▄▀█▓██▄ ▐▌
  ▄▓▓▓████▒▓▓▓▓▄ ░░░ ■▄▄ ▀▀▓▓▓▄▄   ░░   ░░   ▄▄▄▓▓▀▀▄▒░  ░░░ ▄▓▓▓▓▒████▓▓▓▄ ░
 █▓█▀▀     ▀▀▀███▓▄▒▒▒░░▀▀▄▄▄▓█▓▓▓▓▄▄▄▄▄▄▄▓▓████▄▄▒░░▒▒▒▒▒▄▓███▀▀▀     ▀▀█▓█
▐█▀░░▄▄▓▄░░░     ▀█▓▓▓▄▓▓▓▓▓▓▒▀▀▀▀▀▀▓▓▓▓▓▓▓▓▓▀▀▒▒▓▓▓▓▓▓▓▓▓█▀     ░░░▄▓▄▄░░▀█▌
█  ▀███████▄▄  ░░▒▄▓▓▓▀▀▀▀▀  ░        ▒░           ▀▀▀▀▓▓▓▄▒░░  ▄▄███████▀  █
▀ ▄▓██▀▀ ░░░▒▒░▒▓▀   ▀▀■▄ ,,T..E..A..M░...D..V..T.,,▄■▀▀   ▀▓▒░▒▒░░░ ▀▀██▓▄ ▀
 ▄███       ▀▓▓▓▓          ▀    ■            ■   ▀          ▓▓▓▓▀       ███▄ ▒
▐███    ░░▒░░ ▀▓▀▄      ....P  R  E  S  E  N  T  S....     ▄▀▓▀ ░░▒░░    ███▌░
▐▓██░░ ░▒▒░ ▄▄▒▓▌▒▀▄                                     ▄▀▒▐▓▒▄▄ ░▒▒░ ░░██▓▌
▐▓▓██▒░░░ ▄▀  ▀▓ ░                                         ░ ▓▀  ▀▄ ░░░▒██▓▓▌░
░▀▓▓▓█▒▒▒▓█         WinHex Forensic Edition v12.05 SR-11          █▓▒▒▒█▓▓▓▀░▒
▒░ ▀▄▒▀▓▓▓█▄                                                     ▄█▓▓▓▀▒▄▀ ░▒▓
▀▓▓▄▒▀▄▄▀▀▓▓▓▄                       ▄▄▄                       ▄▓▓▓▀▀▄▄▀▒▄▓▓▀▀
░░░▀█▓▄▄▓▓▄▄■   ▄▄▄▓▓▓▓▓▀▀■   ▄▄▄▄█▓▓▒▒▒▓▓█▄▄▄▄▄  ■▀▀▓▓▓▓▓▄▄▄   ■▄▄▓▓▄▄▓█▀░░░▄
▒ ░  █▓▀█▓▄▄▄▓██▀▀▒▒▒▓██▄▄▓▓▓▓▀▓▀    ░▒░    ▀▓▀▓██▄▄▄██▓▒▒▒▀▀██▓▄▄▄▓█▀▓█  ░ ▒▓
▓█▄▄▓▀   ▀▓▓▀▀░   ░░   ▀▀▓▓  ░▒▒▀■ ▄  ░  ▄ ■▀▒▒░  ▓▓▀▀   ░░   ░▀▀▓▓▀   ▀▓▄▄█▓▓
▀▓██▄ ░  ░▒░      ░        ▀ ■ ░░     ▀     ░░ ■ ▀        ░      ░▒░  ░ ▄██▓▀▒
 ▐███▌   ▒░                                                       ░▒   ▐███▌ ░
▄██▓▓▌  ▓▓                                                         ▓▓  ▐▓▓██▄▄
▓█▓▓▀  ▓▓▀    Rel Type .:                                          ▀▓▓  ▀▓▓█▓▀
▓▀▓   ▄▀░     Rel Date .: 03/11/05                                  ░▀▄   ▓▀▓▄
░ ▀▄ ▓▌  ░    OS .......: WinALL                                   ░  ▐▓ ▄▀ ░█
▓▄ ░▓▒▓▄  ░   Disks ....: 01                                      ░  ▄▓▒▓░ ▄▓█
██▓▓▓▀▒   ░                                                       ░   ▒▀▓▓▓██▀
▀███▄ ░  ░▒   Company ..: X-Ways                                  ▒░  ░ ▄███▀▒
 ▐███▌   ▒░   Url ......: http://www.x-ways.net/                  ░▒   ▐███▌ ░
▄██▓▓▌  ▓▓                                                         ▓▓  ▐▓▓██▄▄
▓█▓▓▀  ▓▓▀                        ▄▄▄▄ ▄                           ▀▓▓  ▀▓▓█▓▀
▓▀▓   ▄▀░          ░           ▄▓▓▓▒░░    ▀■▄           ░           ░▀▄   ▓▀▓▄
░ ▀▄ ▓▌  ░        ▒▒          ▐▓▓▒░░░   ░░ ░▓▌          ▒▒         ░  ▐▓ ▄▀ ░█
▓▄ ░▓▒▓▄  ░    ░ ▄▓▓▒▒▓▓▓▄▄▒   ▀▓░▄▄▄  ▄▄▄░▓▀   ▒▄▄▓▓▓▒▒▓▓▄ ░     ░  ▄▓▒▓░ ▄▓█
██▓▓▓▀▒   ░   ░▒█▓▓▀ ░▒▓░░▀█▓▓▄▄▄▒▄▀░▄▄░▀▄▒▄▄▄▓▓█▀░░▓▒░ ▀▓▓█▒░    ░   ▒▀▓▓▓██▀
▀███▄ ░  ░▒ ▄ ▒▓██▌   ░░▄█▓▀   ░▀▀        ▀▀░   ▀▓█▄░░   ▐██▓▒ ▄  ▒░  ░ ▄███▀▒
 ▐███▌   ▒░  ▓█ ▀▓█   ▒▐█▒  Release Information   ▓█▌▒   █▓▀ █▓   ░▒   ▐███▌ ░
▄██▓▓▌  ▓▓     ▀   ▀  ▄▄▓▓  ░░░░░░░░░░░░░░░░░░░   ▓▓▄▄  ▀   ▀      ▓▓  ▐▓▓██▄▄
▓█▓▓▀  ▓▓▀               ▀▀                      ▀▀                ▀▓▓  ▀▓▓█▓▀
▓▀▓   ▄▀░                                                           ░▀▄   ▓▀▓▄
░ ▀▄ ▓▌  ░   WinHex is a universal hexadecimal editor,             ░  ▐▓ ▄▀ ░█
▓▄ ░▓▒▓▄  ░  particularly helpful in the realm of computer        ░  ▄▓▒▓░ ▄▓█
██▓▓▓▀▒   ░  forensics, data recovery, low-level data             ░   ▒▀▓▓▓██▀
▀███▄ ░  ░▒  processing, and IT security. An advanced tool for    ▒░  ░ ▄███▀▒
 ▐███▌   ▒░  everyday and emergency use: inspect and edit all     ░▒   ▐███▌ ░
▄██▓▓▌  ▓▓   kinds of files, recover deleted files or lost data    ▓▓  ▐▓▓██▄▄
▓█▓▓▀  ▓▓▀   from hard drives with corrupt file systems or from    ▀▓▓  ▀▓▓█▓▀
▓▀▓   ▄▀░    digital camera cards. Features include:                ░▀▄   ▓▀▓▄
░ ▀▄ ▓▌  ░   Disk editor for hard disks, floppy disks, CD-ROM &    ░  ▐▓ ▄▀ ░█
▓▄ ░▓▒▓▄  ░  DVD, ZIP, Smart Media, Compact Flash, ...            ░  ▄▓▒▓░ ▄▓█
██▓▓▓▀▒   ░  Powerful directory browser for FAT, NTFS, Ext2/3,    ░   ▒▀▓▓▓██▀
▀███▄ ░  ░▒  ReiserFS, CDFS, UDF                                  ▒░  ░ ▄███▀▒
 ▐███▌   ▒░  RAM editor, providing access to other processes'     ░▒   ▐███▌ ░
▄██▓▓▌  ▓▓   virtual memory                                        ▓▓  ▐▓▓██▄▄
▓█▓▓▀  ▓▓▀   Data interpreter, knowing 20 data types               ▀▓▓  ▀▓▓█▓▀
▓▀▓   ▄▀░    Editing data structures using templates (e.g. to       ░▀▄   ▓▀▓▄
░ ▀▄ ▓▌  ░   repair partition table/boot sector)                   ░  ▐▓ ▄▀ ░█
▓▄ ░▓▒▓▄  ░  Concatenating and splitting files, unifying and      ░  ▄▓▒▓░ ▄▓█
██▓▓▓▀▒   ░  dividing odd and even bytes/words                    ░   ▒▀▓▓▓██▀
▀███▄ ░  ░▒  Analyzing and comparing files                        ▒░  ░ ▄███▀▒
 ▐███▌   ▒░  Particularly flexible search and replace functions   ░▒   ▐███▌ ░
▄██▓▓▌  ▓▓   Disk cloning, with a specialist license also under    ▓▓  ▐▓▓██▄▄
▓█▓▓▀  ▓▓▀   DOS                                                   ▀▓▓  ▀▓▓█▓▀
▓▀▓   ▄▀░    Drive images & backups (optionally compressed or       ░▀▄   ▓▀▓▄
░ ▀▄ ▓▌  ░   split into 650 MB archives)                           ░  ▐▓ ▄▀ ░█
▓▄ ░▓▒▓▄  ░  Programming interface (API) and scripting            ░  ▄▓▒▓░ ▄▓█
██▓▓▓▀▒   ░  (professional & specialist licenses only)            ░   ▒▀▓▓▓██▀
▀███▄ ░  ░▒  128-bit encryption, checksums, CRC32, hashes (MD5,   ▒░  ░ ▄███▀▒
 ▐███▌   ▒░  SHA-1, ...)                                          ░▒   ▐███▌ ░
▄██▓▓▌  ▓▓   Erase (wipe) confidential files securely, hard        ▓▓  ▐▓▓██▄▄
▓█▓▓▀  ▓▓▀   drive cleansing to protect your privacy               ▀▓▓  ▀▓▓█▓▀
▓▀▓   ▄▀░    Import all clipboard formats, incl. ASCII hex          ░▀▄   ▓▀▓▄
░ ▀▄ ▓▌  ░   values                                                ░  ▐▓ ▄▀ ░█
▓▄ ░▓▒▓▄  ░  Convert between binary, hex ASCII, Intel Hex, and    ░  ▄▓▒▓░ ▄▓█
██▓▓▓▀▒   ░  Motorola S                                           ░   ▒▀▓▓▓██▀
▀███▄ ░  ░▒  Character sets: ANSI ASCII, IBM ASCII, EBCDIC,       ▒░  ░ ▄███▀▒
 ▐███▌   ▒░  (Unicode)                                            ░▒   ▐███▌ ░
▄██▓▓▌  ▓▓   Instant window switching. Printing. Random-number     ▓▓  ▐▓▓██▄▄
▓█▓▓▀  ▓▓▀   generator.                                            ▀▓▓  ▀▓▓█▓▀
▓▀▓   ▄▀░    Supports files >4 GB. Very fast. Easy to use.          ░▀▄   ▓▀▓▄
░ ▀▄ ▓▌  ░   Extensive online help. (more)                         ░  ▐▓ ▄▀ ░█
▓▄ ░▓▒▓▄  ░                                                       ░  ▄▓▒▓░ ▄▓█
██▓▓▓▀▒   ░                                                       ░   ▒▀▓▓▓██▀
▀███▄ ░  ░▒                                                       ▒░  ░ ▄███▀▒
 ▐███▌   ▒░                                                       ░▒   ▐███▌ ░
▄██▓▓▌  ▓▓                                                         ▓▓  ▐▓▓██▄▄
▓█▓▓▀  ▓▓▀                        ▄▄▄▄ ▄                           ▀▓▓  ▀▓▓█▓▀
▓▀▓   ▄▀░          ░           ▄▓▓▓▒░░    ▀■▄           ░           ░▀▄   ▓▀▓▄
░ ▀▄ ▓▌  ░        ▒▒          ▐▓▓▒░░░   ░░ ░▓▌          ▒▒         ░  ▐▓ ▄▀ ░█
▓▄ ░▓▒▓▄  ░    ░ ▄▓▓▒▒▓▓▓▄▄▒   ▀▓░▄▄▄  ▄▄▄░▓▀   ▒▄▄▓▓▓▒▒▓▓▄ ░     ░  ▄▓▒▓░ ▄▓█
██▓▓▓▀▒   ░   ░▒█▓▓▀ ░▒▓░░▀█▓▓▄▄▄▒▄▀░▄▄░▀▄▒▄▄▄▓▓█▀░░▓▒░ ▀▓▓█▒░    ░   ▒▀▓▓▓██▀
▀███▄ ░  ░▒ ▄ ▒▓██▌   ░░▄█▓▀   ░▀▀        ▀▀░   ▀▓█▄░░   ▐██▓▒ ▄  ▒░  ░ ▄███▀▒
 ▐███▌   ▒░  ▓█ ▀▓█   ▒▐█▒     Install Notes      ▓█▌▒   █▓▀ █▓   ░▒   ▐███▌ ░
▄██▓▓▌  ▓▓     ▀   ▀  ▄▄▓▓  ░░░░░░░░░░░░░░░░░░░   ▓▓▄▄  ▀   ▀      ▓▓  ▐▓▓██▄▄
▓█▓▓▀  ▓▓▀               ▀▀                      ▀▀                ▀▓▓  ▀▓▓█▓▀
▓▀▓   ▄▀░                                                           ░▀▄   ▓▀▓▄
░ ▀▄ ▓▌  ░   1. Unpack and install                                 ░  ▐▓ ▄▀ ░█
▓▄ ░▓▒▓▄  ░  2. Copy files from DVT dir to WinHex dir.            ░  ▄▓▒▓░ ▄▓█
██▓▓▓▀▒   ░                                                       ░   ▒▀▓▓▓██▀
▀███▄ ░  ░▒  *thanks Mogul666 for this really GREAT leak*         ▒░  ░ ▄███▀▒
 ▐███▌   ▒░                                                       ░▒   ▐███▌ ░
▄██▓▓▌  ▓▓   *NOTE*                                                ▓▓  ▐▓▓██▄▄
▓█▓▓▀  ▓▓▀   X-Ways.WinHex.v12.05.SR-11.Incl.Keymaker-ZWT is       ▀▓▓  ▀▓▓█▓▀
▓▀▓   ▄▀░    working for sure,                                      ░▀▄   ▓▀▓▄
░ ▀▄ ▓▌  ░   but Forensic-Files are missing.                       ░  ▐▓ ▄▀ ░█
▓▄ ░▓▒▓▄  ░                                                       ░  ▄▓▒▓░ ▄▓█
██▓▓▓▀▒   ░                                                       ░   ▒▀▓▓▓██▀
▀███▄ ░  ░▒                                                       ▒░  ░ ▄███▀▒
 ▐███▌   ▒░                                                       ░▒   ▐███▌ ░
▄██▓▓▌  ▓▓                                                         ▓▓  ▐▓▓██▄▄
▓█▓▓▀  ▓▓▀                        ▄▄▄▄ ▄                           ▀▓▓  ▀▓▓█▓▀
▓▀▓   ▄▀░          ░           ▄▓▓▓▒░░    ▀■▄           ░           ░▀▄   ▓▀▓▄
░ ▀▄ ▓▌  ░        ▒▒          ▐▓▓▒░░░   ░░ ░▓▌          ▒▒         ░  ▐▓ ▄▀ ░█
▓▄ ░▓▒▓▄  ░    ░ ▄▓▓▒▒▓▓▓▄▄▒   ▀▓░▄▄▄  ▄▄▄░▓▀   ▒▄▄▓▓▓▒▒▓▓▄ ░     ░  ▄▓▒▓░ ▄▓█
██▓▓▓▀▒   ░   ░▒█▓▓▀ ░▒▓░░▀█▓▓▄▄▄▒▄▀░▄▄░▀▄▒▄▄▄▓▓█▀░░▓▒░ ▀▓▓█▒░    ░   ▒▀▓▓▓██▀
▀███▄ ░  ░▒ ▄ ▒▓██▌   ░░▄█▓▀   ░▀▀        ▀▀░   ▀▓█▄░░   ▐██▓▒ ▄  ▒░  ░ ▄███▀▒
 ▐███▌   ▒░  ▓█ ▀▓█   ▒▐█▒      Group Notes       ▓█▌▒   █▓▀ █▓   ░▒   ▐███▌ ░
▄██▓▓▌  ▓▓     ▀   ▀  ▄▄▓▓  ░░░░░░░░░░░░░░░░░░░   ▓▓▄▄  ▀   ▀      ▓▓  ▐▓▓██▄▄
▓█▓▓▀  ▓▓▀               ▀▀                      ▀▀                ▀▓▓  ▀▓▓█▓▀
▓▀▓   ▄▀░                                                           ░▀▄   ▓▀▓▄
░ ▀▄ ▓▌  ░    DVT is a closed group, if you want to get in         ░  ▐▓ ▄▀ ░█
▓▄ ░▓▒▓▄  ░   contact with us you better have a really good       ░  ▄▓▒▓░ ▄▓█
██▓▓▓▀▒   ░   reason (besides the password requests stated        ░   ▒▀▓▓▓██▀
▀███▄ ░  ░▒   above) and some luck to get our attention.          ▒░  ░ ▄███▀▒
 ▐███▌   ▒░                                                       ░▒   ▐███▌ ░
▄██▓▓▌  ▓▓    If you are a talented cracker, supplier, dump        ▓▓  ▐▓▓██▄▄
▓█▓▓▀  ▓▓▀    owner or got something other we might have a         ▀▓▓  ▀▓▓█▓▀
▓▀▓   ▄▀░     interst in, try to get in contact with us some-       ░▀▄   ▓▀▓▄
▓▀▓   ▄▀░     where. DO NOT EVEN THINK OF ASKING FOR FILES OR       ░▀▄   ▓▀▓▄
░ ▀▄ ▓▌  ░    THINGS LIKE THAT. WE DO NOT SUPPORT ANY PUBLIC       ░  ▐▓ ▄▀ ░█
▓▄ ░▓▒▓▄  ░   FILE SHARING AND THE LIKE AND WILL NEVER DO THAT.   ░  ▄▓▒▓░ ▄▓█
██▓▓▓▀▒   ░                                                .      ░   ▒▀▓▓▓██▀
▀███▄ ░  ░▒                                                       ▒░  ░ ▄███▀▒
 ▐███▌   ▒░  ----                                                 ░▒   ▐███▌ ░
▄██▓▓▌  ▓▓                                                         ▓▓  ▐▓▓██▄▄
▓█▓▓▀  ▓▓▀    We would like to greet our friends around the        ▀▓▓  ▀▓▓█▓▀
▓▀▓   ▄▀░     world, and especially all the hard working groups     ░▀▄   ▓▀▓▄
░ ▀▄ ▓▌  ░    that keep the scene alive. You know who you are.     ░  ▐▓ ▄▀ ░█
▓▄ ░▓▒▓▄  ░                                                       ░  ▄▓▒▓░ ▄▓█
██▓▓▓▀▒   ░   Keep up the great work guys!                        ░   ▒▀▓▓▓██▀
▀███▄ ░  ░▒                                                       ▒░  ░ ▄███▀▒
 ▐███▌   ▒░                                                       ░▒   ▐███▌ ░
▄██▓▓▌  ▓▓                          Signed,                        ▓▓  ▐▓▓██▄▄
▓█▓▓▀  ▓▓▀                                                         ▀▓▓  ▀▓▓█▓▀
▓▀▓   ▄▀░                                 TEAM DVT                  ░▀▄   ▓▀▓▄
░ ▀▄ ▓▌  ░ ░   ■                         02/15/2005          ■   ░ ░  ▐▓ ▄▀ ░█
▓▄ ░▓▒▓▄  ░▒▄▀                                                 ▀▄▒░  ▄▓▒▓░ ▄▓█
██▓▓▓▀▒  ░▒▓▌ ▄    ░                                     ░    ▄ ▐▓▒░  ▒▀▓▓▓██▀
▀███▄ ░░ ░▒▒▒▄ ▀■▄ ▒                                     ▒ ▄■▀ ▄▒▒▒░ ░░ ▄███▀▒
 ▐███▌ ░░▒▒░░▓▓▓▄ ▀▓▒                                   ▒▓▀ ▄▓▓▓░░▒▒░░ ▐███▌ ░
▄██▓▓▌ ░▒░▒░▒▒▄▓▓▓▀▐▓░▄ ▄▀ ░▒▒░       ░       ░▒▒░ ▀▄ ▄░▓▌▀▓▓▓▄▒▒░▒░▒░ ▐▓▓██▄▄
▓█▓▓▀░▒▓▒░░░▓▀░▒▒░░▓▓▓▒▓▓▄▒▒░░░░░    ░░░    ░░░░░▒▒▄▓▓▒▓▓▓░░▒▒░▀▓░░░▒▓▒░▀▓▓█▓▀
 ▀▓▓▓▓▓▒▒░ ░▓    ▄▒░▒▓ ░░▀▄▄▄▄  ░░  ░░▒░░  ░░  ▄▄▄▄▀░░ ▓▒░▒▄    ▓░ ░▒▒▓▓▓▓▓▀ ▄
▓▄███▓▓▓▒▄▄▄■░▄▓░ ░▓▓░  ▒▓▀   ▀■▄   ░▒▒▒░   ▄■▀   ▀▓▒  ░▓▓░ ░▓▄░■▄▄▄▒▓▓▓███▄▓▓
▒▀▀▓███▓▓▓▓▀░▓▓▒░ ▓██▓░ ▓▌░       ▀░▒▒▓▒▒░▀       ░▐▓ ░▓██▓ ░▒▓▓░▀▓▓▓▓███▓▀▀▒▒
▒  ▒  ▀▀▄  ░░▒█▓▒░ ▓██▓▒░▀▒▄▄▄▀░  ░░▒▓▒▓▒░░  ░▀▄▄▄▒▀░▒▓██▓ ░▒▓█▒░░  ▄▀▀  ▒  ▒░
▒  ░    ▐▓▒░ ░▐█▓▒░░▀▀███▓▒░░▄▓▓ ░▒▒▓▒░▒▓▒▒░ ▓▓▄░░▒▓███▀▀░░▒▓█▌░ ░▒▓▌    ░  ▒
░      ▄▓▀▀▒▒▄███▓▓▒░░  ▀▀▓▓▓▒▒▄▄▄▓█▒░ ░▓▓▓▄▄▄▒▒▓▓▓▀▀  ░░▒▓▓███▄▒▒▀▀▓▄      ░
░     ▒░     ▀▀▓██▄▓▓▒▒▒▒▒▒░░▒▄█▓██▒░   ░▒▓█▓█▄▒░░▒▒▒▒▒▒▓▓▄██▓▀▀     ░▒     ░
     ░░        ▒ ▀▀▓▓▓▄▄▄▄▄▄▓▓▒▓█▓▒░     ░▒▓█▓▒▓▓▄▄▄▄▄▄▓▓▓▀▀ ▒        ░░
      ░        ░     ▀▀▀▀▓▓▒▓▒▒▓▓▓▓▓▒░ ░▒▓▓▓▓▓▒▒▓▒▓▓▀▀▀▀     ░        ░
       ░                   ░▒▒▒▄▄▄▄▄▓▒░▒▓▄▄▄▄▄▒▒▒░                   ░
          ░                  ░░  ░░▒▒▒░▒▒▒░░  ░░                  ░
                              ░      ░░░      ░
                                      ░   (( nFO layout by ixlover / buddha ))



file_id.diz

                                 _____    .   +
         _____                   \   |    : ,`
 ________\    |___________________   |____l____ _
/    .        |       |      /___  \_|____/___
\___________\_|\     /`     /   /    |      /y!r
--------------``----\_____/   /\__________/ ------
____\           `~~~~----/    `----------`   /____
\_____/(WinHex Forensic Edition v12.05SR-11)\____/

                    (C) X-Ways                     
____\\                                       //___
\_/-__/( 03/11/05 :: WinALL :: Disk xx/01  )\_-\_/
 



# 0 1 2 3 4 5 6 7 8 9 A B C D E F G H I J K L M N O P Q R S T U V W X Y Z