Login  |  Register
Bar Home         Features         Support         Purchase         Contact  
Link Exchange  - Article Details
ARTICLES
Windows Media Player Database CurrentDatabase_372.wmdb files
Brief introduction into the Windows Media Player program and analysis of currentdatabase_372.wmdb file and how to extract the content for review. This article may serve as an aid to forensic examiners or data recovery technicians.
Using FTK forensic software to detect SQLite Database Files
Using FTK forensic software to detect SQLite Database Files for processing in SQLite Forensic Reporter
Processing SQLite Databases using Templates (applicable to forensic analysis and data recovery)
Processing SQLite Databases using Templates (applicable to forensic analysis and data recovery). This article covers the processing of SQLite database files for forensic analysis, security auditing and data recovery purposes.
SQLite Forensic Reporter
SQLite Forensic Reporter is the most powerful tool available for analysing and reporting on the contents of SQLite database files on the market to date. With batch processing, advanced identification, decoding and reporting this is a perfect solution for computer & mobile phone examiners and data recovery technicians.
The use of Forensic Data Recovery Software in Different Sectors
These days, catching a criminal involves the use of highly sophisticated technologies which can generate vital evidence good enough to prove whether a person is really guilty or not. One of the known applications that can be taken under consideration in such cases is the forensic software or data recovery software.
STATISTICS
  • Active Links: 13
  • Pending Links: 1
  • Todays Links: 0
  • Total Articles: 26
  • Total Categories: 3
  • Sub Categories: 0

Vista Recycle Bin Records - How to extract information

Date Added: October 03, 2009 01:39:40 PM
Author: admin
Category: Documents

Microsoft Vista employs a different method of keeping track of individual files that have been recycled, for each file moved to the recycle bin by the operating system a record is created (as individual file)*.  These records are typically identified as being 544 bytes in size, the first character of the file record will be '$' and the file extension of the record will be the same the deleted file.

 

Example Vista Recycle bin records

Above example showing recycle bin records, each 544 bytes in size.

Vista Recycle Bin Reader, part of Simple Carver Suite is a forensic software utility designed to extract information relating to deleted files within the Recycle Bin from the Vista Operating System. It is capable of interpreting the recycle bin records from the Vista OS and show what has been deleted (original filename and path) and when (date/time information).

Vista Recycle Bin Usage:

  1. Copy out recycle bin record files to a new folder for processing.
  2. Start the Vista Recycle Bin Reader program.
  3. Click 'Select Folder' and choose folder containing the records.
  4. After processing the records will be decoded and displayed in a grid.
  5. Results can be saved as CSV and imported into Excel.

 

Click HERE for Vista Recycle Bin Reader

 

* for deleted folders a folder is created.

Ratings
You must be logged in to leave a rating.
Average rating: (0 votes)
Comments

No Comments Yet.


You must be logged in to leave a Comment.