chfi-tools Flashcards

1
Q

Recovers deleted files emptied from recycle bin or lost due to formating or corruption of hard drive from virus, trojan or system shutdown or failure. Can recover even if windows has been reinstalled. For windows systems.

A

Recover my Files (windows)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Can be used to recover any file type, can also be used to recover data from rewritable memory like memory cards and external storage. Offers deep scan capability and can delete files securely enough to meet military standards.

A

Recuva

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

a hard drive data recovery software to recover data lost from PCs, laptops, or other storage media because of deleting, formatting, partition loss, OS crash, virus attack, etc…Supports large hard disk, can specify recovery file types for precise search results, allows you to preview files before recovering.

A

EaseUS Data Recovery

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

scans the entire system for deleted files and folders and provides
an opportunity to recover them. Hard drives, partitions, external devices, CDs, DVDs can be scanned for recoverable files with Advanced Disk Recovery. Offers two types of scans– Quick Scan uses the Master File Table to find all files with the same file name. Deep Scan uses file signatures to search for deleted files and folders. After either type of scan, you are able to preview deleted files and folders, and restore any or all of them to the location of your choice.
With a few clicks, you can locate and restore the majority of the files.

A

Advanced Disk Recovery

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

recovers documents, photos, email, video, music. Recovers files emptied from the recycle bin, after accidental formatting, recovers even if Windows reinstalled. Recovers from storage devices.

A

Undelete Plus

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

contains CD/DVD ISO image that allows you to burn a bootable CD or
DVD with a lightweight version of Windows 7. Can recover from a system that is not bootable.

A

Active@ File Recovery :

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

allows you to locate and recover files deleted from FAT and NTFS-formatted volumes. Scans and builds an index of existing and deleted files and directories.

A

Pandora Recovery

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

raw file can be used for heavily damaged or unknown file systems, recovers data on disks even if partitions are formatted, damaged, or deleted.

A

R-Studio (Mac, Windows, Linux)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

recovers files from crashed or
virus-corrupted hard drive, non-mounting hard drive, reinstalled OS, or accidently reformatted hard drive, or damaged, missing, or previously deleted files. Recovers all file types from any
HFS/HFS+ formatted drive.

A

Data Rescue 4 for Mac (also Windows version)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

recovers deleted files with their original file name. Supports RAW recovery on lost volumes.

A

Stellar Phoenix (Mac or Windows)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

recovers lost files, iTunes libraries, iPhoto collections, lost data. Recovers from Mac OS hard drive, USB, PC disk, Linux disk, FAT32 disk, FLASH card, scratched CD,
digital camera, iPod, and any other file system recognized by Mac OS.

A

File Salvage (Mac)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

undeletes and recovers lost files from hard drives, memory cards, USB drives. Recovers documents or photos accidently deleted or from a reformatted camera memory card, or can be used to check files on an old USB drive. Shows recoverable files as a thumbnail preview

A

DiskDigger (Windows 10, 8, 7, Vista, XP) :

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

recovers lost data from hard drives, RAID , photos, deleted files, iPods, FireWire,
and USB.

A

Total Recall

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

recovers files that have been lost, deleted, corrupted, or deteriorated. Searches, scans, and recovers files that are encrypted and password protected and restores them. Repairs and recovers disk bad sectors , recovers virus-prone files, hidden and password protected files.

A

Quick Recovery

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

restores deleted emails and email attachments . Deeply scans hard
drives, external drives, iPod Shuffle, iPod NANO, and iPod Classic to recover a wide variety of files.

A

Data Recovery Pro

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

helps you monitor the installation of

executables, shows information like process ID, the new file path, open ports, process DLLs, loaded drivers, and tasks.

A

SysAnalyzer (for dynamic malware analysis)

17
Q

Open Source network forensic analysis tool (NFAT) that extracts applications data
contained from an internet traffic capture. Example— from a pcap file it would extract all email, HTTP contents, VOIP calls, FTP, etc…

A

xplico

18
Q

dynamic malware analysis tool that helps investigators detect hidden and background installations which the malware performs.

A

Comodo Programs Manager

19
Q

this is used to analysis registry changes in malware analysis. Registry Cleaner is a part of this set of tools that detects errors that can have a measurable impact against system performance.

A

Jv16 (jv16 Power Tools)

20
Q

dynamic malware analysis tool that helps investigators detect hidden and background installations which the malware performs.

A

Install Watch