Login  |  Register
Bar Home         Features         Support         Purchase         Contact  
Link Exchange  - Article Details
ARTICLES
Windows Media Player Database CurrentDatabase_372.wmdb files
Brief introduction into the Windows Media Player program and analysis of currentdatabase_372.wmdb file and how to extract the content for review. This article may serve as an aid to forensic examiners or data recovery technicians.
Using FTK forensic software to detect SQLite Database Files
Using FTK forensic software to detect SQLite Database Files for processing in SQLite Forensic Reporter
Processing SQLite Databases using Templates (applicable to forensic analysis and data recovery)
Processing SQLite Databases using Templates (applicable to forensic analysis and data recovery). This article covers the processing of SQLite database files for forensic analysis, security auditing and data recovery purposes.
SQLite Forensic Reporter
SQLite Forensic Reporter is the most powerful tool available for analysing and reporting on the contents of SQLite database files on the market to date. With batch processing, advanced identification, decoding and reporting this is a perfect solution for computer & mobile phone examiners and data recovery technicians.
The use of Forensic Data Recovery Software in Different Sectors
These days, catching a criminal involves the use of highly sophisticated technologies which can generate vital evidence good enough to prove whether a person is really guilty or not. One of the known applications that can be taken under consideration in such cases is the forensic software or data recovery software.
STATISTICS
  • Active Links: 13
  • Pending Links: 1
  • Todays Links: 0
  • Total Articles: 26
  • Total Categories: 3
  • Sub Categories: 0

Windows Photo Gallery Primer

Date Added: July 14, 2009 02:58:45 PM
Author: admin
Category: Documents

This article covers the program Windows Photo Gallery and analysis

of data file typically titled pictures.pd4 file and how to extract the content

for review.

Windows Photo Gallery (WPG) is a multimedia management tool developed

by Microsoft and comes installed as part of the Microsoft Windows Vista

operating system.  It is accessible from the Start menu under 'Programs'.

WPG allows you to batch preview photo and video content as a series of

thumbnails serving as an electronic photo album.

A user can add additional information or 'tags' to each entry including

comments, ratings and other descriptive information.

 

Picture showing Windows Photo Gallery

 

The above picture shows WPG running and previewing both video and picture

files. New files are added from the menu option 'Add Folder to Gallery'. Files

can be previewed by tag, date or by rating, views can be filtered to show only

picture, video or both.

The information generated when a user has previewed files using WPG is written

to disk in a single file, this is typically titled 'pictures.pd4', one file exists for each

profile on the computer in the following location:

 

VOLUME\Users\PROFILE\AppData\Local\Microsoft\Windows Photo Gallery

 

Information is also written to disk in the Vista Operating system thumbcache file;

this is where the picture information is stored. When a user previews using WPG

the generated thumbnail pictures are stored in the thumbcache files relating to that

particular profile. Each user profile on the computer has its own thumbcache repository. 

It is important to note that the Vista operating system thumbcache is not only used

by WPG, it also stores thumbnail pictures in the cache when previewing using Windows

explorer.

 

VOLUME\Users\PROFILE\AppData\Local\Microsoft\Windows\Explorer

 

The WPG data file can be readily examined using the tool WPG Viewer a forensic software tool which is part

of the Simple Carver Suite and is capable of reading the 'pictures.pd4' file.

 

 

 

The WPG data (picture.pd4) file contains a wealth of information including but not limited to File

Path information, file properties, source label (hard disk drive label), source serial

(volume serial number), user rating information, tag information, comments and

descriptions and thumbnail moniker.

Ratings
You must be logged in to leave a rating.
Average rating: (0 votes)
Comments

No Comments Yet.


You must be logged in to leave a Comment.