by Runtime Software
Category: Forensic
http://www.runtime.org/drivelook.htm
Synopsis:
DriveLook is a powerful forensic disk investigation tool. Investigate a drive for suspicious content. See what others put on your computer. Find traces of user activity. Collect evidence for litigation purposes.
DriveLook is a powerful forensic disk investigation tool, which enables you to
index a hard drive for all text that was ever written to it
browse a list of all words stored on the drive
search for words or combinations of words
view the location of words or in a disk editor
switch between several views, such as hex and text views
use physical drives or logical drives as an input
use image files as an input
access remote drives over serial cable or TCP/IP
Since this program is currently distributed as freeware, we don't offer technical support for it. Please refer to the program's help file and documentation.
License: Freeware (with fake registration)
How to install... (Oh boys... this time I had to sweat...)
0) save the registration infos from the download page:
License name: Runtime Software
License key: BKZSBKFTUPYEK
1) Unzip the compressed installation program and the uniextract _SETUP.1
2) create a folder whose name must be \dlook (immediately under the root of your USB key)
3) copy dlook.exe dlook.chm and drv16.dll into the folder
4) create a subfolder whose name is \source\
5) copy the file dict.dat into \dlook\folder
6) run dlook.exe and register it
(only because I did not want to install and uninstall...)
Write Setting: it writes the registration data into the registry... I guess that, due to the nature of the program it can be accepted as portable
Space on disk: about 775 Kb