FindNTFS, version 1.29. Copyright Svend Olaf Mikkelsen, 2002. Lists the content of an NTFS partition, or copies files. FindNTFS <disk number> <cylinder> <head> <sector> [ <log file> files | dirs | summary ] [ copy [ <dir number> ... [ max <max file size> ] ] ] [ tz <hours relative to GMT> ] [ noboot [ <search offset MB> ] | backupboot [ <partition sectors> ] ] [ mirror | nomftrecord ] [ kb <cluster KB>] [ cp <code page> ] [ showsys ] [ showdel ] Disks are numbered from 1. Log file extension must be .txt. If 'copy' is selected, files are copied to current directory, and to subdirectories to current directory. To interrupt after current directory, press Esc. If directory numbers are entered, only these directories, and subdirectories to them, are copied. Up to 10 directory numbers can be entered. The directory numbers are in the search output in front of the directory name. Keep the original partition until the integrity of copied files is verified. If partitions are overlapping, file copying can damage data. If you are in doubt, then do only copy to another physical disk, which is known to be OK. Also it should be known that the target partition cannot contain old deleted copies of lost files. This version cannot copy files that are compressed in the NTFS file system. Long file names are not copied in pure DOS. Also files with long paths cannot be copied in DOS. If 'backupboot' is used without partition sectors, a search is done for the backup boot sector. The 'noboot' option ignores boot sectors. If the 'mirror' option is used with the 'noboot' option, the search offset should be somewhat below the expected half partition size. The 'mirror' option uses the MFT mirror record if available. The 'nomftrecord' option ignores the MFT and mirror file record. Can be used for a partition that was accidently formatted. The 'kb' option is usually not needed. The 'showsys' and 'showdel' options shows system and deleted files. The 'cp' option can be used if the correct DOS font code page is not loaded. During file copying the correct code page should be loaded.
LaFuriaPL