I am building a forensics PE cd mainly based on opnsource utility. Can someone post your experience. Actually I use WinHex, but it can only recover lost and deleted files...and for registry? for events? and for index.dat reading? and for syskey files? Thetheera I also want to cover the tracks,