This script will decrypt the data from the .dat files used by the Ares and Lime Pro P2P file trading programs. The encryption is a simple stream cipher.
Files that are supported:
- ShareH.dat
- ShareL.dat
- PHashIdx.dat
The script can use the data from the afore-mentioned files in order to generate file-recovery records, which can be used by the Ares Deleted File Recovery EnScript.
The data-bookmark created by the script will only display the first 1499-bytes of any p-hash due to a limitation in EnCase. This does not affect the file created for the purposes of file-recovery.
Research by Matt McFadden and James Habben. Originally created by James Habben.
This script was developed for use in EnCase training. For more details, please click the following link: