Login  |  Register
Bar Home         Features         Support         Purchase         Contact  
Link Exchange  - Article Details
ARTICLES
Windows Media Player Database CurrentDatabase_372.wmdb files
Brief introduction into the Windows Media Player program and analysis of currentdatabase_372.wmdb file and how to extract the content for review. This article may serve as an aid to forensic examiners or data recovery technicians.
Using FTK forensic software to detect SQLite Database Files
Using FTK forensic software to detect SQLite Database Files for processing in SQLite Forensic Reporter
Processing SQLite Databases using Templates (applicable to forensic analysis and data recovery)
Processing SQLite Databases using Templates (applicable to forensic analysis and data recovery). This article covers the processing of SQLite database files for forensic analysis, security auditing and data recovery purposes.
SQLite Forensic Reporter
SQLite Forensic Reporter is the most powerful tool available for analysing and reporting on the contents of SQLite database files on the market to date. With batch processing, advanced identification, decoding and reporting this is a perfect solution for computer & mobile phone examiners and data recovery technicians.
The use of Forensic Data Recovery Software in Different Sectors
These days, catching a criminal involves the use of highly sophisticated technologies which can generate vital evidence good enough to prove whether a person is really guilty or not. One of the known applications that can be taken under consideration in such cases is the forensic software or data recovery software.
STATISTICS
  • Active Links: 13
  • Pending Links: 1
  • Todays Links: 0
  • Total Articles: 26
  • Total Categories: 3
  • Sub Categories: 0

WindowsMail.MSMessageStore Primer

Date Added: December 30, 2009 10:10:37 AM
Author: admin
Category: Documents

Windows Mail is client based software for email and newsgroup management and was introduced with Microsoft Windows Vista. It is accessible on a Vista platform from the Start Menu under ‘Programs’.


This short article covers the file WindowsMail.MSMessageStore, part of the Windows Mail repository for email storage and archiving.


When using Windows Mail on a regular basis the user will be prompted to compact the message store upon program closure.

prompt user to compress messagestore

The process takes several minutes depending on the quantity of messages.

messagestore compaction progress

The settings relating to the message store can be accessed and viewed from the main menu of Windows Mail under ‘Tools’ > ‘Options’, then click the ‘Advanced’ tab and ‘Maintenance’ button (see picture below).

messagestore settings

The maintenance window provides several pieces of information.

messagestore settings

The default setting for prompting a user to compress the message store is 100 runs (see picture above). If this setting is changed to 1 for example the user would be prompted to compress the message store each time Windows Mail is closed.

The clean up window shows the current size of the message store and allows a user to perform general cleaning tasks. The picture below shows the message store is 78 megabytes.

messagestore clean up

The message store folder window displays the current path setting for the message store, the default location is:

<VOLUME>\Users\<PROFILE>\AppData\Local\Microsoft\Windows Mail

messagestore location

messagestore file listing

Reviewing email and attachments from Windows Mail can be easily achieved by creating a virtual machine of the host system and using the Windows Mail application to view and export information.1


A utility called Windows Mail Store Extractor, part of Simple Carver Suite, will parse this data and provide a user with a summary of data contained within the WindowsMail.MSMessageStore.

messagestore program

 

1 Commercial forensic packages Encase, FTK etc support processing of .eml files and associated attachments (not covered in this article).

Ratings
You must be logged in to leave a rating.
Average rating: (0 votes)
Comments

No Comments Yet.


You must be logged in to leave a Comment.