筆記型電腦維修必備,各型號筆電折解說明書大全

近來我有兩台筆記型電腦接連罷工,本來想找人維修,但維修費用大都要3000以上,在網上查到的一些資料,送原廠維修費用更高,都幾乎夠在網拍買一 台不錯的中古機,甚至是新電腦了。於是想動手自己diy折解看看,死馬當活馬醫,雖然最後都失敗,救不回來。但卻意外發現一個很棒的網站--Tim's laptop service manuals
,是一個想自己維修,或是拆解筆電不可缺少的好站。

網址如下:http://www.tim.id.au/blog/tims-laptop-service-manuals/


第 一台故障的電腦是acer travelmate 4002lci,它的螢幕先是出現一些小條紋,繼而出現雪花,然後隨著時間,情況愈來愈嚴重。最後就不能開機了,我判斷是顯示晶片的問題,於是找到上述的 網站,居然能找到同型號的筆電,依樣畫葫蘆,很順利的就拆解開了。雖然東敲敲西打打,火攻加熱法,也無法起死回生,不過倒是順便清理了鍵盤,風扇,主機板 等灰塵。也學會了如何拆解這一台acer travelmate的筆電,雖然自己動手維修失敗,但後來我在網拍,花了一千元買到一台同型號的筆記型電腦的良品主機板。很容易也很順利的安裝上去,開 機後一切正常,於是這台acer老筆電,目前還正常服役中。

不過現在良品的主機板相當難買到,我也是等了好久才遇到,一般筆電故障最大 的現象,就是不能開機,而無法開機的原因,很大的部分是主機板故障。 現在很多標榜獨立顯示晶片的筆電,都是把顯示晶片直接焊在主機板上的。一旦顯示晶片故障,也等於主機板故障,偏偏顯示晶片是最容易故障的部分。因為它很容 易發出高熱,如果筆電散熱不良,或是長時間使用,內部的散熱裝置故障,如風扇。很快這台筆電也就等著報銷了。

第二台故障的筆記型電腦, 是acer travelmate 220,這一台年代更是久遠,有時候無法開機,好像是電源方面的問題,時好時壞,我也在上述網站,找到拆解的方法,一樣順利拆開,但一樣維修失敗。目前這 台還是故障中,因為太古老了,所以就放著,我另外花了二千多元買了一台更好的中古機hp presario x1000來代替。不過這台hp的筆電,剛買來的時候風扇居然不轉,我一樣到Tim's laptop service manuals找到同型號的拆解手冊,將它拆開來看,原來是風扇的接線掉落了。小問題,將它接回去,就正常運轉了。


Tim's laptop service manuals這個網站蒐集到大量的各式各樣筆記型電腦的手冊,拆解說明,教學文章等,可以說應有盡有。這些內容所有權,都是各筆電廠商所有,不過我們如果到原廠網站去找恐怕也找不到,因為有些內容並不對外公開。

至 2011.12.1止共有以下的電腦型號,如果您的電腦在下列的名單內,請到該網站去下載拆機手冊:

Acer
Aspire One, NAV50
Aspire 1200, 1300, 1310, 1350, 1360, 1400, 1410, 1420PT, 1450, 1500, 1520, 1600, 1606, 1610, 1620, 1640Z, 1650, 1650Z, 1660, 1670, 1680, 1690, 1700, 1710, 1800, 1810t, 1820PT, 2000, 2010, 2020, 2420, 2920, 2920Z, 2930, 3000, 3010, 3020, 3050, 3100, 3300S, 3500, 3510, 3600, 3610, 3620, 3630, 3640, 3650, 3680, 3690, 3810T, 3810TG, 3810TZ, 3810TZG, 4220, 4220G, 4230, 4310, 4310G, 4315, 4320, 4330, 4332, 4520, 4520G, 4530, 4710, 4710G, 4715Z, 4720, 4720G, 4720Z, 4730Z, 4730ZG, 4732Z, 4740, 4740G, 4820T, 4920, 4920G, 4930, 4930G, 4935, 4935G, 5000, 5010, 5020, 5050, 5100, 5110, 5220, 5230, 5235, 5236, 5241, 5242, 5310, 5310G, 5330, 5332, 5335, 5338, 5340, 5500, 5500Z, 5510, 5515, 5517, 5520, 5530, 5530G, 5534, 5535, 5536, 5536G, 5538, 5540, 5541, 5542G, 5560, 5570, 5580, 5600, 5610, 5620, 5630, 5650, 5670, 5680, 5710, 5710G, 5720, 5720G, 5730Z, 5732Z, 5735, 5735Z, 5737Z, 5738, 5738G, 5738DG, 5738ZG, 5738DZG, 5738Z, 5738Z, 5738ZG, 5739, 5739G, 5740, 5740D, 5841, 5741G, 5910, 5920G, 5930, 5930Z, 5935, 5940G, 5942, 5942G, 6530, 6920, 6930, 6930G, 6935G, 7000, 7100, 7110, 7120, 7220, 7220G, 7230, 7315, 7336, 7420, 7520, 7520G, 7530, 7530G, 7540, 7715Z, 7720, 7720G, 7730, 7730G, 7736, 7736Z, 7740, 7740G, 7745, 7745G, 8530, 8730, 8730Z, 8920, 8920G, 8930, 8930Q, 8935G, 8940, 8942, 8942G, 9100, 9110, 9120, 9300, 9400, 9410, 9420, 9500, 9510, 9520, 9800, 9920, ASX1200, ASX3200
Extensa 365, 390, 450, 500, 510, 570, 600, 610, 650, 660, 670, 700, 710, 900, 2000, 2500, 2700, 3100, 5210, 5220, 5230, 5610, 5620, 5630, 5630Z, 6600
Ferrari One
Ferrari 1000, 1100, 1200, 3000, 3200, 3400, 4000, 5000
Travelmate 200, 210, 220, 230, 240, 250, 260, 270, 280, 290, 310, 330, 340, 350, 380, 420, 430, 505, 510, 520, 530, 550, 610, 620, 630, 650, 660, 720, 730, 740, 800, 2000, 2100, 2200, 2300, 2350, 2400, 2410, 2420, 2430, 2440, 2450, 2470, 2480, 2490, 2500, 2600, 2700, 3000, 3010, 3030, 3040, 3210, 3210Z, 3220, 3230, 3240, 3250, 3280, 3300, 4000, 4010, 4020, 4050, 4060, 4070, 4080, 4100, 4150, 4200, 4210, 4220, 4230, 4260, 4270, 4280, 4320, 4330, 4330G, 4400, 4500, 4520, 4530, 4600, 4650, 4670, 4720, 4730, 4730G, 5000, 5100, 5110, 5220, 5220G, 5230, 5310, 5320, 5330, 5520, 5520G, 5530, 5600, 5610, 5620, 5710, 5720, 5730, 6000, 6231, 6291, 6292, 6293, 6410, 6460, 6492, 6493, 6500, 6592, 6592G, 6593, 7100, 7220, 7230, 7300, 7320, 7510, 7520, 7520G, 7530, 7720, 7730, 7730A, 8000, 8100, 8200, 8210, 8331, 8371, 8431, 8471, 8531, 8571, C100, C110, C210, C300
eMachines E430, E627, E628, E630, EM250, G430, G627, G630


Apple

eMac - 2004 original, 2005 ATI/USB2
iMac 2000, 2001, Summer 2001, DV, DV Special Edition, Flat Panel, Flat Panel USB2.0, 17″ Flat Panel, 17″ Flat Panel 1GHz
iMac 17″ mid 2006, late 2006, late 2006 CD
iMac 20″ early 2006, late 2006, mid 2007, early 2008, early 2009, mid 2009
iMac 21″ late 2009, mid 2010
iMac 24″ 2006, mid 2007, early 2008, early 2009
iMac 27″ late 2009, mid 2010
iMac G5 17″ original, iSight, Ambient Light Sensor
iMac G5 20″ original, iSight, Ambient Light Sensor
iPad Wifi+3G
MacBook Air original, late 2008, mid 2009
MacBook 13″ original, late 2006, mid 2007, early 2009, mid 2009, late 2009, mid 2010, Aluminium late 2008
MacBook Pro 15″ original, Core 2 Duo, 2.2/2.4GHz 2007, early 2008, mid 2009, 2.53GHZ mid 2009, mid 2010
MacBook Pro 17″ original, Core 2 Duo, 2.4GHz 2007 and 2008, early 2009, mid 2010
Mac Mini 2006, Mini 2006/7, Mini 2009, Mini 2010
Mac Pro, 8x, 2008, 2009, 2010
PowerBook 100, 140, 145, 145B, 150, 160, 165, 165c, 170, 180, 180c, 190 and 190 REA, 200 series, 500 series, 550c, 1400 series, 2300c, 2400c, 3400c, 5300 series and 5300 series REA, Firewire
PowerBook G3 original series, Bronze series
PowerBook G4 original, DVI, Gigabit Ethernet, 1GHz/867MHz
PowerBook G4 12″, 12″ DVI, 12″ 1.33GHz, 12″ 1.5GHz
PowerBook G4 15″ 1.67/1.5GHz, 15″ Double-Layer SD, Firewire 800, 1.5/1.33GHz
PowerBook G4 17″ original, 17″ Double-Layer SD, 17″ 1.67/1.5/1.33GHz
Power Mac G3 All-In-One, Blue-White, Desktop, Server Minitower
Power Mac G4/Macintosh Server G4, Power Mac G4 Mirrored Drive Doors/Firewire 800, G4 Cube
Power Mac G5, 2004, 2005
Xserve 2003, 2005 G5, 2006, 2009, Xserve RAID
Macintosh Classic, Classic II, Color Classic, Color Classic II, 128k, 512k, II, IIcx, IIci, IIx, IIfx, IIsi, IIvx, IIvi, Plus, Portable, SE, SE/30, TV
Macintosh LC, LC II, LC III, LC 475, 520, 550, 575, 580
Macintosh/Powermac/Performa 200, 275, 400 series, 500 series, 580CD, 600, 630, 4400, 5200, 5260, 5280, 5300, 5400, 5500, 6100, 6200, 6300, 6400, 6500, 7100 series, 7200 series, 7300, 7500, 7600, 8100, 8200, 8500, 8600, 9500, 9600, WS6150, WS7250, WS7350, WS8150, WS8550, WS9150, WS9650
Macintosh Quadra/Centris 605, 610, LC630, Performa 640, 650, 660AV, 700, 800, 840AV, 900, 950, WS60, WS80, AWS95
Macintosh Network Server 500, 700
The Twentieth Anniversary Mac (user guide only - no official take-apart guide exists for these)
Apple Displays - including Monochrome, RGB, AppleColor, AppleVision, Multiple Scan, Cinema and Studio displays.
Miscellaneous manuals - including external drives, printers, ADB devices including keyboards and mice, eMate/Newton MessagePads, and various upgrade cards.


ASUS

Eee PC 4G (701)
A6JC, A6JM, A7T, A7V, A3000N, G1S, G73, KN1, L8400, M2400NE, M6000, S37E, S62, S62F, S96J, S97V, SW1, V1S, W5F, W3000A, X50RL, Z93E, Z500A, Z9200K, Z97V

BenQ

Joybook A33, R23, S52, S72

Clevo

Clevo 888E, 2200C, 2700C, D400E, D400S, D410E, D410S, D470V, D480V, D500E, D510E, D520E, D530E, D610S, D620S, D630S, D800P, D900C, D900F, D900K, D900T, L295N, L295T, L297N, L390T, LV19C, LV19N, LV22C, LV22N, M570A, M570TU, M575A, M590KE, M660SE, M665SE, M720T, M728T, M729T, M730T, M740T, M740TU, M760T, M760TU, M860TU, M980NU, TN120R
Compal CL50, CL51, CL56, CY23, CY25, HEL81
Eurocom M350C and M360C
FIC/Medion A360, A440, A985, M295, M296, M785, MB02, MB05W, MD02
Mitac 7521, 8011, 8050, 8050D, 8050QMA, 8066MP, 8081, 8170, 8224, 8355, 8399, 8575A, 8599, 8965, W130
Sager NP2280, NP4060, NP4780, NP5270, NP5690, NP61x0, NP8886, NP8890, NP9260, NP9261, NP9750
Uniwill 340S2 and 340S8

Compaq/HP
• Compaq 100, 510, 511, 515, 516, 610, 615, 800, nx4820, nx9010, nx9008, nx9005, nx9000
• Compaq Armada 100, 100s, 110, 1100, 1500, 4100, 4200, E500, E500S, E700, M300, M700, V300
• Compaq Business nx7000, nx9100, nx9500
• Compaq Evo N110, N150, N160, N180, N400c, N410c, N600c, N610C, N610v, N620c, N800c, N800v, N800w, N1010v, N1050v
• Compaq Mini 110, 311, 700
• Compaq Presario 1100, 2100, 2500, 2800, 3000, CQ50, CQ60, C300, F500, C700, M2000, M2300, R3000, R4000, V2000, V2400, V4000, Widescreen x1000
• Compaq Tablet PC TC1000
• HP 500, 510, 520, 530, 540, 541, 550
• HP 2533t, 4410t mobile thin client
• HP Compaq nc6110, nx6110, nc6120, nx6120, 6720t mobile thin client, 8710p notebook, 8710w mobile workstation, NC4400, TC1100 Tablet, TC4200 Tablet
• HP Elitebook 2530p, 2730p, 6930p, 8530p, 8530w, 8730w
• HP Envy 13, Envy 15
• HP G50, G60, G3000, G6000, G7000
• HP HDX 16, HDX 18, Pavilion HDX
• HP Media Center zd7000
• HP Mini 110, 311, 1000, 1101, 5101, Mini-note 2133, Mini-note 2140
• HP Omnibook xt1000, xt1500
• HP Pavilion dm1, dm3, dv2, dv3, dv4, dv5, dv6, dv7, dv8, dv1400, dv2000, dv4000, dv6500, dv6600, dv6700, dv8000, dv8200, dv9000, dv9200, dx6500, tx1000, tx2000, tx2500, xz100, xz300, zd7000, zd8000, ze2000, ze2300, ze4100, ze4200, ze4300, ze4400, ze4500, ze4600, ze4700, ze5200, ze5300, ze5400, ze5500, ze5600, zv6000, zx5000, zv5000, zt1000, zt1100, Widescreen zt3000
• HP Probook 4310s, 4311s, 4410s, 4411s, 4510s, 4710s, 5310m
• HP Special Edition L2000
• HP TouchSmart tx2
Dell/Alienware
• Inspiron 300M, 1501, 7000, 9100
• Inspiron XPS 9100
• Latitude CP, CPi, CS, LM, XPi CD
• Latitude C500, C600, C800, L400, X200, X300
• Alienware M17x
Gateway
• Gateway 400, 450RGH, 450ROG, 600, 6000, 6100, 6500, 6600, EC14, EC14D, EC14T, EC18, EC18T, EC34, EC38, EC54, EC58, LT21, LT31, NV42, NV53, NV59, NV59C, M275, M305, M350, M360, M675, MX6100, MX6200, MX6400, MX6500, MX6600, MX6900, NX500, P-78, P-79, Solo 1450
• Gateway Profile 4, Profile 5
• Gateway Convertible Notebook CX200, CX2000, M280, M285, S-7200, TA1, TA6, TA7
IBM/Lenovo
• IdeaPad S9e, S10, S10e
• ThinkPad 240, 240X, 380, 380XD, 380Z, 385, 385XD, 390, 390E, 390X, 560, 560E, 560X, 560Z, 570, 570E, 600, 600E, 600X, 760C, 760CD, 760E, 760ED, 760L, 760LD, 760EL, 760ELD, 760XL, 760XD, 765D, 765L, 770
• ThinkPad A20m, A20p, A21e, A21m, A21p, A22e, A22m, A22m wireless, A22p, A30, A30p, A31, A31p
• ThinkPad Edge 13″, E30, E31, Edge 14″, E40, Edge 15″, E50
• ThinkPad G40, G41
• ThinkPad L410, L412, L510, L512
• ThinkPad R30, R31, R32, R40, R50, R50e, R50p, R51, R51e, R52, R60, R60e, R61, R61e, R61i, R61i widescreen, R500
• ThinkPad S30, S31, SL300, SL400, SL400c, SL410, SL500, SL500c, SL510
• ThinkPad T20, T21, T22, T23, T30, T40, T40p, T41, T41p, T42, T42p, T43, T43p, T60, T60 widescreen, T60p, T60p widescreen, T61, T61 widescreen, T61p, T61p widescreen, T400, T400s, T410, T410i, T410s, T410si, T500, T510, T510i
• ThinkPad R400
• ThinkPad W500, W510, W700, W700ds, W701, W701ds
• ThinkPad X20, X21, X22, X23, X24, X30, X31, X32, X40, X41, X41 Tablet, X60, X60 Tablet, X60s, X61, X61 Tablet, X61s, X100e, X200, X200 tablet, X200s, X200si, X201, X201 Tablet, X201i, X201s, X300, X301
• ThinkPad Z60m, Z60t, Z61e, Z61m, Z61p, Z61t
• ThinkPad TransNote
• ThinkPad Dock, Dock II, Mini Dock, Port Replicator, Port Replicator II, Selectadock II
• WorkPad Z50
• iSeries 1200, 1300, 1400, 1500, 1700, 1800
JVC
• MP-XP5220KR, MP-XP5230GB, MP-XP7220KR, MP-XP7230GB, MP-XP741DE
• MP-XV841DE, MP-XV841GB, MP-XV841GBEX, MP-XV841US, MP-XV941DE
LG
• LE50, LM40, LM50, LS40, LS50, LS70, LW20, LW60, LW70, S1, P1, T1, TX
NEC and Packard Bell
• Dot a, m, mr, mr/u, s
• Dragon A, SN
• Easy Lite
• EasyNote A7, B3, BG, BU, C3, DT85, E, L, LJ61, LJ65, LJ75, LJ77, M3, M5, M7, MB, ME, MV, MX, MZ, R, R7, S, SB, SJ, SW, T5, TJ75, TJ76, TJ77, TJ78, TM85, TM86, TM89, V, W, W3, W7, XS, Butterfly Touch, Butterfly xs
• iPower GX
• Versa Lite, M340 and E2000, M400, M540, P520, S940, VX
Panasonic
• CF-08TX1A1M
• CF-1000
• CF-18JHU70TW, CF-18JHU80TW, CF-18KHH65Lx, CF-18NHHZXBM
• CF-19CDBAXVM, CF-19CHBAXBM, CF-19FHGAXxM, CF-19KDRAXCM
• CF-29N3LGZBM, CF-29NTQGZBM
• CF-30CTQAZBM, CF-30CTQAZxx, CF-30FTSAZAM, CF-30KTPAXxM
• CF-52AJYZDZM, CF-52EKMxDxM
• CF-73E3KVXxM
• CF-74CCBAXBM, CF-74ECBAXBM, CF-74ECBGDBM, CF-74GCDADBM, CF-74JCJBDxM
• CF-T4GWCTZBM, CF-T4HWETZBM
• CF-T5LWETZBM
• CF-W4GWCZZBM, CF-W4HWEZZBM
• CF-W5LWEZZBM
• CF-Y5LWVYZBM
Samsung
• Samsung NC10, P560, Q1U, Q40, Q45, R50, R510, R520, X460
Sony
• PCGA-DSD5, PCGA-DSM5
• PCG-C1VP, PCG-C1VPK
• PCG-FX210, PCG-FX220, PCG-FX220K, PCG-FX240, PCG-FX240K, PCG-FX250, PCG-FX250K, PCG-FX270, PCG-FX270K, PCG-FX290, PCG-FX290K, PCG-FX777, PCG-FX877
• PCG-FXA32, PCG-FXA33, PCG-FXA35, PCG-FXA35D, PCG-FXA36
• PCG-GR150, PCG-GR150K, PCG-GR170, PCG-GR170K
• PCG-R505AFE, PCG-R505JE, PCG-R505JEK, PCG-R505JEP, PCG-R505JL, PCG-R505JLK, PCG-R505JLP, PCG-R505JS, PCG-R505JSK, PCG-R505JSP
• PCG-SR27, PCG-SR27K
• VGN-A, VGN-AR, VGN-AX, VGN-B, VGN-BX, VGN-C, VGN-FE, VGN-FJ, VGN-FS, VGN-N, VGN-S, VGN-SZ, VGN-T, VGN-TX, VGN-U, VGN-UX
Toshiba
• 100CS and 110CS
• Dynabook V1, V2, VX4
• Equium A60, A210, A300, L300, L300D, L350, L350D, M40, M45
• Libretto 100CT, L100, L105, U100
• Mini Notebook NB100, NB200, NB250, NB255, NB300
• Portege 610CT, 620CT, 2000, 3010CT, 3020CT, 3110CT, 3400, 4000, 7010CT, 7020CT, 7200CT
• Portege A100, A200, A600, M100, M200, M300, M400, M500, M700, M750, M780, M800, M900D, P2000, R100, R200, R300, R400, R500, R600, R700, S100, T110, T110D, T130, T130D, T210
• Qosmio E10, F10, F20, F30, F40, F45, F50, F60, G10, G20, G30, G40, G50, X300, X500
• Satego A210, A300, L300, L300D, L350, L350D
• Satellite 220, 300, 310, 320, 330, 440, 460, 470, 480, 1400, 1405, 1700, 1710CDS, 1800, 1900, 2060CDS, 2100, 2230, 2250, 2400, 2405, 2500CDS, 2510CDS, 2520CDS, 2540XCDT, 2590CDT, 2610, 2750, 2800, 3000, 4000, 4010, 4020, 4030, 4060, 4070, 4080, 4090, 4100, 4200, 4300, 5000, 5100, 5200, TE2000
• Satellite A10, A20, A30, A40, A50, A50S, A60, A70, A80, A85, A100, A105, A200, A210, A215, A300, A350, A350D, A500D, A660, C650, C650D, C655D, E100, E105, E200, E205, L10, L20, L300, L300D, L305, L305D, L350, L350D, L450, L450D, L500, L500D, L510, L550, L600, L600D, L630, L635, L640, L640D, L645, L645D, L650, L655, L670, L670D, L675, L675D, M20, M30-35, M30X, M40, M40X, M50, M60, M70, M100, M200, M205, M300, M500, M505, M507, P10, P20-25, P30, P100, P200, P205, P250D, P300, P500, R10, R20, R70, T110, T110D, T130, T130D, T210, T215, T230, T230D, U200, U300, U400, U500, X200, X205
• Satellite Pro 220, 440, 460, 470, 480, 4600, 6000, 6100, A10, A60, A65, A120, A210, A300, A500D, A660, L300, L300D, L350, L350D, L450, L450D, L500, L550, L600, L600D, L630, L635, L640, L640D, L645, L650D, L650, L655, L670, L670D, L675, M10, M70, M200, M300, P500, S200, S300, S500, S500M, T110, T110D, T130, T130D, T210, T215, T230, T230D, U300, U400
• Tecra 520CDT, 530CDT, 550CDT, 750, 780CDM, 780DVD, 8000, 8100, 8200, 9000
• Tecra A1, A2, A3, A3X, A4, A5, A6, A7, A8, A9, A10, A11, M1, M2, M2V, M3, M4, M5, M7, M9, M10, M11, P5, P10, P11, R10, S1, S2, S3, S4, S5, S10, S11
Twinhead
• Durabook 14K
• efio! 121A, 121i

轉自 http://save-coco.blogspot.com/2011/11/3000diy-tims-laptop-service-manuals.html

Random Cookie Filenames

As forensic examiners will be aware, Microsoft Internet Explorer stores cached data within randomly assigned folders. This behaviour was designed to prevent Internet data being stored in predictable locations on the local system in order to foil a number of attack types. Prior to the release of Internet Explorer v9.0.2, cookies were an exception to this behaviour and their location was insufficiently random in many cases.




Cookie Files


Generally, for Vista and Windows 7, cookie files are stored in the location shown below:


Microsoft Windows Internet Explorer Cookie Location
\AppData\Roaming\Microsoft\Windows\Cookies\



Table 1



The cookie filename format was the user’s login name, the @ symbol and then a partial hostname for the domain of the cookie.


Digital Detective NetAnalysis Windows Cookies

Figure 1



With sufficient information about a user’s environment, an attacker might have been able to establish the location of any given cookie and use this information in an attack.


To mitigate the threat, Internet Explorer 9.0.2 now names the cookie files using a randomly-generated alphanumeric string. Older cookies are not renamed during the upgrade, but are instead renamed as soon as any update to the cookie data occurs. Figure 2 shows an updated cookie folder containing the new files.


Digital Detective NetAnalysis New Cookies Window

Figure 2


This change will have no impact on dealing with the examination of cookie data. It will obviously no longer be possible to identify which domain a cookie belongs to from just the file name.

轉自 http://wordpress.bladeforensics.com/?p=366

Evtx Parser Version 1.1.0

Evtx Parser and the Parse::EVTX Perl library is now available for download (ZIP).

轉自 http://computer.forensikblog.de/en/2011/11/evtx_parser_1_1_0.html#more

DocumentsRescue Pro

Office DocumentsRescue Professional recover lost data from Hard Drives, CompactFlash cards (type I/II), IBM Microdrives, SmartMedia cards, MultiMedia cards (MMCs), Secure Digital (SD) cards, Memory Sticks, CD/DVD disks, and any other storage device with the addition of wide range file format support: DOC, XLS, PPT, RTF, LIT, etc.

DocumentsRescue Pro is an effective document recovery tool for Microsoft Word, Excel, PowerPoint, Project, Publisher, Visio and many other popular document formats. DocumentsRescue Pro can recover documents lost due to computer crashes, accidental deletion - even if the Recycle Bin has been emptied, formatting of a disk drive, and when a document has never been saved! Easy to use for novice users, as well as a feature rich advanced mode for the skilled technician users. DocumentsRescue Pro is not just 'undelete' tool it can easily, quickly and absolutely reliably reconstruct the lost document files that undelete programs can never recover.

Program features

- Recovers deleted and corrupted files
- Recovers data from formatted media
- Recovers data from corrupted media
- Supports all popular formats of document files *
- Supports all formats of media used by digital devices
- Works with all digital devices and card readers
- Easy to use, intuitive wizard-driven interface
- Supports Windows® NT/2000/XP/2003/Vista
- and many more!

轉自 http://www.essentialdatatools.com/products/documentsrescuepro/

Blackberry 黑莓手機密碼破解

轉自 計算機取證技術

現在,恢復黑莓手機的密碼已經成為可能。Elcomsoft公司推出的手機密碼恢復工具現在能夠破解黑莓手機的密碼。但是,需要有個前提,就是用戶設置 「設備密碼」時,選擇了同時加密存儲卡中的數據。通過分析加密存儲卡中的數據,解密軟件可以通過在幾個小時之內,破解7位密碼,解密速度可達每秒幾百萬 次。對於黑莓手機加密的成功破解,打破了黑莓手機不可破解的神話。感興趣的朋友可試用一下。Sprite。

SQLite Forensic Reporter v1.2 Released

A new version of SQLite Forensic Reporter, Universal SQLite database examination tool is now available, Version 1.2 includes more features to analyse, extract and report on information from any SQLite database (not corrupted or encrypted). Useful for Computer & Phone Forensic Analysts and Data Recovery Technicians. Searches, identifies and decodes all SQLite database files in a case. Available for $125 per license with discounts for Government and Law Enforcement Agencies...

What's new:

  • More templates added!!!
  • Added Polish Language
  • Password and Username Identification, scans all identified SQLite database files for possible user credentials (saved as a separate listing).
  • Collates date and time activity from all identified SQLite database files in a case and saved as a seperate listing for timeline analysis
  • Added Unattended Mode, Identification and Processing of all SQLite database files is performed with a single mouse click
SQLite Forensic Reporter is the only universal SQLite database examination tool available to date, more information :
SQLite Forensic Reporter (Universal SQLite database examination tool)


In addition to the above new additions SQLite Forensic Reporter also includes the following features:
  • File Header Analysis for reliable file identification
  • Advanced identification using automated Table Analysis, Column Analysis and Field Data Analysis
  • Easy to manage template interface, create new templates for newly encountered database formats
  • User optional extraction of 'undecoded' data during processing for raw data comparison
  • Built-in MD5 hashing
  • Date / Time display user customisable
  • Once installed, can be setup and running in as little as 3 mouse clicks
  • Unattended mode, process an entire case overnite, come back to the results in the morning
  • Optional single folder or recurse folder
  • Handles unlimited number of templates
  • Templates are portable, develop and share with colleagues, can be stored locally or on a network location (ie mapped drive)
  • Supports numerous datatypes including all known date/time formats presently used in SQLite databases
  • User can select and decode columns using built in data types
  • User can selectively extract rows and columns matching any criteria using SQL scripting
  • Decodes Windows FILETIME Date/Time stamps (Big Endian, Little Endian, hexadecimal or numerical)
  • Decodes DOS 32-bit Date/Time stamps (hexadecimal or numerical)
  • Decodes Unix Date/Time stamps (Big Endian, Little Endian, Seconds, Millisecond and Precision based formats, hexadecimal or numerical
  • Decodes MAC Absolute Date/Time stamps
  • Decodes OLE Date/Time stamps
  • Decodes Base64 Encoded Text
  • Decodes PRTIME Date/Time stamps
  • Decodes WEBKIT Date/Time stamps
  • Decodes Julian Date/Time stamps
  • Decodes Display Boolean values (user customisable, Yes/No, True/False)
  • Decodes Uppercase Text
  • Decodes Lowercase Text
  • Decodes Text to Hexadecimal
  • Decodes Integer to Hexadecimal
  • Decodes Display number formatted as filesize (examples: 3 bytes,3GB,3TB)
  • Decodes seconds to hours/minutes/seconds
  • Inexpensive, affordable to both individuals and multiple users, additional discount is available to Law Enforcement & Government
  • Identifies fields containing possible usernames and passwords
  • Advanced Identification not available anywhere else
  • Identify files that have there file extensions renamed, a technique used by developers for basic data protection. also may be used for malicious purposes
  • Unicode enabled, reports will export text correctly (arabic etc)
  • SQLite automatically creates reports in HTML and CSV formats decoded as the user specifies
  • Utilitises both Default (simple SQL processing) and/or Advanced User Defined SQL querying, link and reference tables for automatic decoding and reporting
  • SQLite is available in English, German, Spanish, French and Indonesian Languages

SQLite Forensic Reporter costs $125 per license includes free customer support and updates.
www.filesig.co.uk. Discounts are available for Government and Law Enforcement Agencies...

More useful software:
www.simplecarver.com

轉自 http://www.forensicfocus.com/index.php?name=News&file=article&sid=1749

iLook之iximager鏡像效果評測


IXimagerILook分析軟件配套的一款光盤啟動數據獲取工具,獲取工具可以製作成軟盤版、光盤版和U盤版三種啟動設備,可以進行鏡像和克隆兩種方式的數據獲取。

為了檢驗IXimager的取證效果,Sprite和BlueSky利用蘋果筆記本計算機,分別通過USB 2.0FireWire 800eSATAUSB 3.0四種接口進行實測。此例中,我們使用了一款2008年上市的Macbook Pro,配置為:CPU:2.5Ghz Core 2 Duo,內存:2G,硬盤:250G SATA 5400轉。目標磁盤選擇西部數據的WD20EARS2Tb,外部傳輸速率為3Gb/s,轉速為5400/分,緩存為64MB

另外,為了獲得拷貝硬盤過程中的平均速度,拷貝硬盤的過程中分別在獲取開始後5分鐘和10分鐘左右時對拷貝速度進行截圖。10分鐘之後的數據獲取速度基本穩定。
蘋果計算機不具備eSATA和usb 3.0接口,通過轉接卡測試。實測證明,iximager可以直接識別各種pcmcia轉接設備,利用已有高速接口設備進行數據獲取。

測試1:利用usb 2.0接口進行數據獲取

五分鐘後速度:
14分鐘後速度
平均約1.2gb/分鐘

測試2:利用火線800接口進行數據獲取
五分鐘之後速度:
十分鐘之後速度:
平均速度約為3.5gb/分鐘。(註:在最新型號macbook Pro上通過火線800速度可達4-5GB)

測試3:利用eSATA接口進行數據獲取
蘋果機沒有esata接口,本例子中使用了如下轉接卡。
10分鐘後速度保持在3GB/分鐘以上的速度。
測試4:利用usb 3.0接口進行數據獲取
蘋果機沒有usb3.0接口,本例中使用了usb 3.0轉接卡。
10分鐘後,速度保持在3.5gb分鐘。

以 上僅僅對蘋果機進行了測試。通過本測試可以看到,IxImager在火線800和usb 3.0、eSata下表現均很出色。由於蘋果機接口非常規範,因此本測試可以適用於早期、最新上市的各種型號的MacbookPro系列筆記本計算機。由 於目前尚在對iximager的測試期間,故本測試結果不代表已達到iximager的最佳速度。目標磁盤速度和各種轉接口性能也會對數據獲取的速度造成 影響。

為了證明iximager對台式機計算機的性能,Sprite又和bluesky測試了雷神工作站:
        測試機型:雷神4數據分析/密碼破解工作站。CPU:XeonR X5680 3.3GHz (雙CPU,內存:24G DDR3,3*Nvidia GF590 GPU顯卡,硬盤:西部數據企業版1T SATA 64MB緩存 7200

測試結果:
Usb 2.0  1.9gb/分鐘
eSata    125mb/秒=7.5 GB/分鐘
圖片沒拍照,後附。

Sprite測試之後,感覺3點:
1、原來多來以來一直沒有好的鏡像工具。iximager的效果令人震驚。
2、usb 2.0 造成了速度下降,esata和usb 3.0、火線800的優勢一直未被挖掘
3、光盤啟動達到如此速度之後,硬盤複製機的優勢不是很大了。

Sprite還將繼續測試,將不同效果圖展示出來,大家評判。但總體來看,目前Sprite已經找不到能夠超越iximager目前水平的工具了。

Messenger Password Decryptor

Messenger Password Decryptor (formerly IMPasswordDecryptor)是一個免費且集多個密碼恢復功能為一身的解+密軟件。Messenger Password Decryptor支持的即時消息應用包括: GTalk, MSN, AOL, Trillian, Pidgin, Digsby等等。目前,Messenger Password Decryptor 發佈了4.5版,支持解密的應用包括:

    * Google Talk
    * Windows Live Messenger
    * MSN Messenger
    * AOL Messenger (AIM)
    * Digsby IM
    * PaltalkScene
    * Trillian
    * Trillian Astra
    * Pidgin (Formerly Gaim)
    * MySpaceIM
    * Miranda
    * Beyluxe IM
    * Meebo Notifier
    * Nimbuzz Messenger
    * IMVU
    * XFire Game Messenger

工具下載:http://nagareshwar.securityxploded.com/2011/10/22/released-messenger-password-decryptor-v4-5/ 

3 Free Tools to Fake DNS Responses for Malware Analysis

When analyzing malware using behavioral techniques, it’s often useful to intercept network connections in your lab. Since malicious software commonly uses hostnames when communicating with network resources, you can redirect such connections by defining the desired hostname to IP address mapping. Here are 3 free tools that can make it easy to accomplish this.

Rather than providing the malicious program the IP address of the actual host it’s trying to access, you can provide the IP address of an internal laboratory system. It’s possible to define this mapping in the “hosts” file on the infected laboratory computer. Alternatively, you can use a DNS server provide falsified DNS responses to queries. If you don’t want to configure a full-blown DNS server, you can use specialized tools such as ApateDNS, FakeDNS and fakeDNS.py.


ApateDNS in Action on Windows
Mandiant recently released a Windows tool called ApateDNS, written by Steve Davis. ApateDNS’s DNS responses will specify the desired IP address of your choosing, regardless of which hostname is being resolved. The tool logs all DNS queries it processes.


To use ApateDNS, you’ll need to point your infected laboratory system to the host where ApateDNS is running. In most scenarios, though, you’ll probably run ApateDNS directly on the infected host. While the tool attempts to automatically configure your local system to use localhost as the DNS server while ApateDNS is running, this doesn’t always work; be prepared to manually modify your DNS settings for this purpose.

FakeDNS in Action on Windows
FakeDNS is a free Windows tool from Verisign’s iDefense group, which is part of the larger Malcode Analysis Pack distribution. Though the original Malcode Analysis Pack web page is no longer accessible, you can still download the executable’s installer file from the iDefense website.

Like ApateDNS, FakeDNS responds to all DNS queries with the specified IP address, logging the details of the received requests and transmitted responses.


fakedns.py in Action on Linux
Another option for falsifying DNS responses in a malware analysis lab is the fakedns.py script by Francisco Santos. It’s written in Python, and will run on most platforms as long as Python is installed on the system. A version of this script is included in the REMnux Linux distribution.

The fakedns.py script is a command-line tool. By default, it will respond to DNS queries with the IP address of the host where the script is running, but this behavior can be modified using a command-line option.


To see how fake DNS servers can be used for malware analysis, take a look at my recorded Introduction to Malware Analysis webcast.
Hand-picked related posts:


轉自 http://blog.zeltser.com/post/11869187517/fake-dns-tools-for-malware-analysis

Research Tool Release: ApateDNS

Written by Steve Davis
Here at Mandiant we deal with our fair share of malicious code. Being able to quickly identify specific information about a piece of malware is imperative. More specifically, knowing which domains a piece of malware uses for command and control (C2) communication is important to on-site incident responders.
 
To aid analysts in DNS identification, I have written ApateDNS. It is a simple tool that acts as a phony DNS server that can log or manipulate DNS requests being made to it. Malware analysts typically use this to redirect beacon traffic from a guest virtual machine to the host system (or another virtual machine) to  monitor beacon and/or communication channels using Netcat or a custom written C2 script. Forensic analysts typically use this tool to quickly extract DNS names from malware samples.
 
ApateDNS automatically sets up your Windows network configurations by attempting to determine the default route or current DNS settings. This is most useful when in a guest virtual machine since the default route is typically the host machine. As shown in the figure below, ApateDNS has found the default route in my virtual machine (192.168.239.1) and uses this IP address for any DNS request on my virtual host. The user may override this by specifying an IP address for DNS Reply IP.
 
Malware often uses multiple C2 domains. To catch this, ApateDNS allows a user to specify a number of non-existent DNS (NXDOMAIN) replies for any possible DNS lookup. As seen in the figure below, the malware returns a single, non-existent domain for each DNS request (since a “1” is entered for “# of NXDOMAIN’s”). The example malware beacons and detects if a valid IP address has been resolved from a DNS request, if not, it will continue to walk down its C2 domain list. By using the NXDOMAIN functionality, we see three different DNS requests made by the malware: evil1.example.com, evil2.example.com and evil3.example.com.
 

ApateDNS gives malware analysts an easy way to control DNS on their machine and forensic analysts a way to monitor DNS requests made by malware. Of course, not all malware utilizes DNS and some may not beacon without a specific set of conditions being satisfied. ApateDNS’s use cases are not limited just to malware. It can be used for any purpose where a user may want to monitor outbound DNS requests or traffic.
 
Feel free to check out ApateDNS here.


轉自 https://blog.mandiant.com/archives/1961?utm_source=rss&utm_medium=rss&utm_campaign=research-tool-release-apatedns

SQLite Database Browser

SQLite Database Browser is a freeware, public domain, open source visual tool used to create, design and edit database files compatible with SQLite. It is meant to be used for users and developers that want to create databases, edit and search data using a familiar spreadsheet-like interface, without the need to learn complicated SQL commands. Controls and wizards are available for users to:
  • Create and compact database files
  • Create, define, modify and delete tables
  • Create, define and delete indexes
  • Browse, edit, add and delete records
  • Search records
  • Import and export records as text
  • Import and export tables from/to CSV files
  • Import and export databases from/to SQL dump files
  • Issue SQL queries and inspect the results
  • Examine a log of all SQL commands issued by the application

轉自 http://sqlitebrowser.sourceforge.net/index.html

Volatility Memory Forensics | Federal Trojan aka R2D2

Last weekend, the German based Chaos Computer Club (CCC) published details on a backdoor trojan they claimed was being used by German authorities, in violation of German law.

Fore more info on German State Backdoor go to:
Possible Governmental Backdoor Found

More Info on German State Backdoor

Several German states admit to use of controversial spy software


Download:
Here’s a memory image running the malware (Thx to jwcsr): 0zapftis.rar
PW: infected


1.) Image Identification

$ python vol.py -f /home/evild3ad/memory-samples/other/R2D2/0zapftis.vmem imageinfo

imageinfo

2.) Processes

$ python vol.py -f /home/evild3ad/memory-samples/other/R2D2/0zapftis.vmem pslist

pslist

3.) Networking

$ python vol.py -f /home/evild3ad/memory-samples/other/R2D2/0zapftis.vmem connscan

connscan

One active connection to the IP address 172.16.98.1 on port 6666 is listed. According to the process list, the process ID 1956 don’t belong to a browser process, such as Iexplore.exe or Firefox.exe, but rather to Explorer.exe. What is this system process doing on the internet?

Note:
The Chaos Computer Club modified the binary. The original IP address of the proxy is 207.158.22.134 on port 443.


4.) Researching IP Addresses

$ whois 207.158.22.134

whois

$ whois 83.236.140.90

whois

5.) Malware Detection
Now, it’s time for the Volatility plug-in malware.py, which was originally developed for the Malware Analyst’s Cookbook. The function ‘apihooks’ looks at the Explorer process with the PID 1956 and finds nothing. No inline hooks!

$ python vol.py -f /home/evild3ad/memory-samples/other/R2D2/0zapftis.vmem -p 1956 apihooks

apihooks

6.) Let’s try the function ‘malfind’ and the open source YARA project.

$ python vol.py -f /home/evild3ad/memory-samples/other/R2D2/0zapftis.vmem -p 1956 -Y /home/evild3ad/yara-rules/malware.yara -D /home/evild3ad/Volatility/dump-files malfind

YARA

7.) VirusTotal
The plugin ‘malfind’ dropped the suspicious PE file it discovered to my output directory as .dmp file. I submitted it to VirusTotal, and bingo, it is malicious and identified as ‘R2D2′ and ‘Bundestrojaner’. ;-)

VirusTotal

8.) Registry
The registry is spread across numerous files called ‘hives’. The current user’s registry branch, HKEY Current User (HKCU), is located in the hidden file NTUSER.DAT of the home directory under \Documents and Settings\. There are two more important branches: HKEY Local Machine (HKLM) and the sub-branch for software in \Windows\system32\config. But first, we need to have ‘hivelist’ display where Windows put the files into memory.

$ python vol.py -f /home/evild3ad/memory-samples/other/R2D2/0zapftis.vmem hivelist

hivelist

Volatility finds HKCU at the virtual address 0xe1bb2b60 and HKLM/Software at the virtual address 0xe1544b60. With this information, we can now use ‘printkey’ to display individual keys and work through the autorun list. After a few dead ends, I notice something suspicious about ‘HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows’.

$ python vol.py printkey -f /home/evild3ad/memory-samples/other/R2D2/0zapftis.vmem -o 0xe1544b60 -K ‘Microsoft\Windows NT\CurrentVersion\Windows’

Registry

All the DLLs that are specified in this value are loaded by each Microsoft Windows-based application that is running in the current log on session.
09.) Kernel Objects

$ python vol.py --profile=WinXPSP3x86 -f /home/evild3ad/memory-samples/other/R2D2/0zapftis.vmem filescan > filescan.txt

filescan

10.) Kernel Drivers

$ python vol.py --profile=WinXPSP3x86 -f /home/evild3ad/memory-samples/other/R2D2/0zapftis.vmem modules

Windows-Kernel-Modul


Links:
Chaos Computer Club analysiert Staatstrojaner

Addendum Staatstrojaner

Piratenpartei Deutschland: Schreiben des bayrischen Justizministeriums als PDF 



轉自 http://www.evild3ad.com/?p=1136 

Nmap / Zenmap

Author Name
Frank McClain

Artifact Name
Nmap/Zenmap

Artifact/Program Version
4.6, 5.1

Description
Artifacts remaining on system after a scan using Nmap/Zenmap (especially Zenmap).  This is not from the standpoint of showing that the application was run, or by whom (so no prefetch, user assist, etc), nor proving that the application was installed at some point. This is from the standpoint of showing the use (ie, how) an application was put to, and the timeframe (ie, when) involved.

In c:\program files\nmap\zenmap\ a file was created when a scan was saved.  This had the same user-selected name as the saved scan, with the extension USR.  So if the scan saved was “test” then the subsequent file would be “test.usr.”  If you find one of these, you can bet the user saved a scan; this file should be identical to that.  It is an XML file that has all the information about the scan.

In %User%\.zenmap (hidden folder) there are primarily three files of interest:  recent_scans.txt, target_list.txt and zenmap.db. Recent_scans.txt is a list of saved scans (or perhaps the .USR instance, it’s inconclusive at this point); all it has is a list of files with their paths.  Target_list.txt is a list of all target IP addresses, separated by semicolons; it has no other information, not even an associated date.  Zenmap.db is the fun one; it’s a SQLite database that contains a history of what scans were run – type of scan, target IP, XML output (ie, basic scan detail) and time.

%User%\%Local%\Temp has another potential treasure trove of evidence.  You may find temporary files (with no extension) located at this level.  Some contain no data, some contain only a small amount, and others provide a detailed breakdown of the scan, really the veritable motherlode, as it shows the time of the scan, each target port, protocol, scan times, and so on.  Very good stuff, when present.  The temporary files that had only a little content basically mirrored the type of content in the USR files, so if you don’t have one, you might have the other and still have some insight into the scan.

And a slightly tangential question posed on twitter was how to identify a scan with packets.  Fairly simple, right – just start Wireshark, run an Nmap scan, and review the results.  Turns out across multiple types of scans run, that there are 60-byte packets, and all have the following content:  00 0d 60 da b4 e7 00 11  25 d1 04 e0 08 00 45 00.  That’s obviously not the entire contents of each packet, but that was consistent across all packets I saw.

File Locations
c:\program files\nmap\zenmap\*.usr (where * is the user-provided filename)
%User%\.zenmap\recent_scans.txt
%User%\.zenmap\target_list.txt
%User%\.zenmap\zenmap.db (SQLite db)
%User%\%Local%\Temp\tmpf5nhgm (these all start with “tmp” and appear to have 6 more characters following)


Forensic Programs of Use
Nmap for Windows (cli) - http://nmap.org/download.html
Zenmap GUI for Nmap for Windows - http://nmap.org/download.html
SQLite Database Browser - http://sqlitebrowser.sourceforge.net/
Wireshark - http://www.wireshark.org/download.html

轉自 http://forensicartifacts.com/2011/10/nmap-zenmap/