This wiki will be going offline permanently in the near future. An exact date will be announced soon. Thank you for being a part of this community.
If you wish to work on the new forensicswiki, please join the Google Group forensicswiki-reborn
Thumbnails are reduced-size versions of pictures, serving the same role for images as a normal text index does for words.
Thumbs.db no longer exists in Vista. This data has been moved to \Users\\AppData\Local\Microsoft\Windows\Explorer. This directory contains following files:
- thumbcache_32.db, thumbcache_96.db, thumbcache_256.db, and thumbcache_1024.db
Thumbnails are stored in thumbcache_NN.db files in different formats (e.g. BMP) and can be extracted using file carving. There are several tools that can work with Vista Thumbcache: dmThumbs, Thumbs.db Viewer. Unfortunately, there is no information in the thumbcache that can easily link thumbnails with original files in all cases. One of the ways to link thumbnails with original files is to use Windows Indexer (Windows.edb) database.
Thumbcache format is described here.
KDE & GNOME
Example thumbnail in GNOME:
$ hachoir-metadata .thumbnails/normal/0d97afdc637ac86d75d13e72172dc77c.png Metadata: - Image width: 128 pixels - Image height: 122 pixels - Bits/pixel: 24 - Pixel format: RGB - Compression rate: 1.6x - Compression: deflate - Producer: GNOME::ThumbnailFactory - Comment: Thumb::Image::Width=779 - Comment: Thumb::Image::Height=744 - Comment: Thumb::URI=file:///media/truecrypt1/123.jpg - Comment: Thumb::MTime=1216153400 - MIME type: image/png - Endian: Big endian
GNOME will save thumbnails for files on mounted encrypted filesystems.