Windows File Analyzer: A Tool for Forensic File Analysis!

by Black on January 27, 2010 · 0 comments

in Forensics, Windows

While performing Windows file Forensics, some folders/files are of importance. The best example being the thumbs.db file. The thumbs.db file is a thumbnail cache that is used to store thumbnail images for Windows Explorer’s thumbnail view. This speeds up the display of images as the smaller images do not need to be recalculated every time the user views the folder. You can use the Windows File Analyzer to analyze this file and check what kind of images was the computer used to view.

Windows File Analyzer decodes and analyzes some special files/folders used by Windows OS. These files/folders are:

  • Thumbs.db
  • Prefetch folder
  • Shortcuts (.lnk files)
  • Index.DAT
  • Recycle Bin folder

4bef61cc3b3476721534bb33f539df3f Windows File Analyzer: A Tool for Forensic File Analysis!

We have tried to list the important points as to why these files/folders are important in Windows Forensic Analysis.

  • Thumbs.db: The Thumbnail Analyser in Windows File Analyzer will extract the OLE embedded data from a Thumbs.db file and present the information in a visible format.
  • Prefetch folder: The Prefetch Analyser in Windows File Analyzer lists commonly used applications/files on that OS. This can help you determine what files were accessed user will access the application.
  • Shortcuts: The LNK Shortcut Analyzer in Windows File Analyzer will read all shortcut files in specified folder and displays data stored in them. The .LNK files inherit the “Creation Time” and “Last Accessed Date”
    of each relevant folder in the full path.
  • Index.DAT: The Index.DAT Analyzer read’s the Index.dat file and displays its content. Index.dat files usually store data of Internet Explorer cookies, temporary files or history.
  • Recycle Bin folder: The Recycle Bin Analyzer decodes and displays Info2 files that hold recycle bin content information.

Operating systems supported:
Windows 95
Windows 98
Windows ME
Windows NT 4.x
Windows 2000
Windows XP
Windows 2003
Windows Vista

Download Windows File Analyzer version 1.0.0 here.

Searches leading to this post:
index dat forensic, windows file analyzer, file forensics windows, forensic file analysis, forensic file explorer, dat file analyzer, index dat file analyser, file analyzer db, how to perform file analysis windows xp, open extract thumbs db 2009, chk file analysis, windows file search tools forensics, lnk analyzer, thumbnail analyzer, forensic website scrapping windows 7, reading thumbnailcache 32 db, prefetch files windows analyzer, reading pcap files windows, prefetch file analysis, perl read thumbs db

Related Posts

Previous post:

Next post: