Belkasoft Forensic Carver Features
Retrieve deleted history fragments
You have a seized hard drive or a hard drive image. You would like to extract some information from it, like chats, emails or browser history. However, all the information has been deleted and your file recovery tools do not help you.
In this case, Belkasoft Forensic Carver can help you retrieve information which is still on drive. Even if the information has been deleted, some fragments are still there, and it is possible to recover them when file recovery tools are helpless.
Live memory investigation
The worst case is when a user has chosen not to store any history, which is possible in the most Instant Messengers, and their hard drive does not contain either whole history files or history fragments. What can be done?
The only way to retrieve information in this case is to analyze active computer memory (RAM). If a seized computer was switched on, its memory could contain some parts of conversations or browsing history made by a suspect just before. You can create a memory dump using the windd tool or FTK Imager and then analyze this dump using Belkasoft Forensic Carver.
Supported information types
The tool is able to search and extract the following information.
Deleted history extraction:
•Skype 3
•Skype 4, 5
•Digsby
•ICQ Lite
•ICQ 7
•Miranda IM
•Windows Live Messenger
•QIP Infium/2010
•SIM
•AIM
•Virtus
•Pidgin
•Trillian
•Mail.ru Agent 5
•Gajim
•Emesene
•Yahoo! Messenger
•Internet Explorer
•Firefox 3
Live memory extraction (Pro version only):
•AIM
•AIM Express
•ICQ 7
•Yahoo! Messenger
•Skype
•Gmail
•MSN
•Meebo
•Google Talk
•Facebook (personal messages)
•Vkontakte.ru (personal messages)
•Ya-Online
•eBuddy
•MySpace IM
Supported image types
The tools supports Encase images (E01), SMART (S01) images, DD images and windd RAM images.
Export history
After completing your investigation you need to export history of interest in a readable format. The product allows you to export history to plain text, HTML and XML.
Difference between Standard and Professional versions
The Standard version supports only hard drive and hard drive images analysis. The Professional version also supports Live RAM investigation.
The Professional version allows user to specify a set of custom signatures to look for (using header-footer method).
Release status
Please note that the current release status is "public Beta version". Although 1.01 Beta version is available to try and purchase, it may contain some bugs or inconveniences. We kindly ask you to let us know about all the problems you have with this software. This will help us to improve the product and to release a final bug-free version.