In modern society, rapid increase in using mass storage devices, and it makes forensic examiners find important evidence hardly in the focus of time-consuming. Examiners spend much time to search files related to the case in variety of storage devices. Recently, NIST(National Institute of Standards and Technology) has developed a new database, called NSRL(National Software Reference Library), which contains hash values of trusted operating systems and programs. As establishing this database service in public, NIST contribute to reduce time-consuming in searching file and detecting forgery on the devices. On the other hand, the hash value based detection technique cannot be distinguished the similarity from other files perfectly. In this paper, therefore, we present novel methods for detecting similar files considering the known fuzzy hashing and statistical analysis and developed out prototype tool, called SimFD.