Skip to content

Thumbnail Cache Viewers

What the viewers do

Windows thumbnail-cache examination

Thumbs Viewer and Thumbcache Viewer recover cached image previews from two different Windows database families. Use Thumbs Viewer for folder-level Thumbs.db and related legacy databases. Use Thumbcache Viewer for per-user thumbcache_*.db and iconcache_*.db databases from Windows Vista through Windows 11.

The recovered preview is an investigative lead, not proof that an original file still exists or that a named user deliberately opened it. Preserve the database path, profile or folder context, hashes, exact field labels, and the method used to map any filename or path.

Choose the correct viewer

Folder-level and legacy

Thumbs Viewer

Extract and preview images from Thumbs.db, ehthumbs.db, ehthumbs_vista.db, Image.db, Video.db, TVThumb.db, and musicThumbs.db databases.

Start here when: the database travelled with, or was recovered from, a specific directory.

Per-user and modern

Thumbcache Viewer

Extract and preview images and icons from thumbcache_*.db and iconcache_*.db. It can verify cache-entry checksums and attempt to map entry hashes using files or Windows Search data.

Start here when: the cache came from a user's Explorer cache profile.

The filename chooses the viewer

Open Thumbs.db and the other listed legacy databases in Thumbs Viewer. Open thumbcache_*.db or iconcache_*.db in Thumbcache Viewer. A parse failure is often a source-selection problem, not evidence that the file is empty.

Choose your journey

Evidence workflow

1Case question2Verified copy3Correct viewer4Relevant entry5Controlled export6Corroborated finding

The source database, original path, user or folder context, viewer settings, selected entry metadata, and exported-file hashes form one evidence trail. Keep them together so another analyst can reproduce the observation without relying on the preview image alone.

Primary input

A verified working copy of the thumbnail database, not the live source.

Minimum record

Source path, user or folder context, database SHA-256, tool/version, entry identifier and export hash.

Safe conclusion

Windows retained a cached preview consistent with the image; corroboration is required for attribution and activity.

Locate the source in acquired evidence

Database family Typical context Collection note
Thumbs.db Inside the directory whose items were cached; the file may be hidden Preserve the database with its directory and volume context. Do not search by filename alone and discard its parent path.
thumbcache_*.db %LocalAppData%\Microsoft\Windows\Explorer for a Windows user profile Collect the related cache family and retain the profile SID or identity, original path, and host context.
iconcache_*.db The same per-user Explorer cache area on supported Windows versions Keep related icon and thumbnail databases together where scope and storage permit.
Other databases supported by Thumbs Viewer Application- or Windows-version-specific locations Record the exact acquired path and avoid generalising one format's fields to another.

Absence from an expected path is not proof that thumbnails were never created. The cache may have been disabled, cleaned, rotated, overwritten, excluded from collection, stored elsewhere, or associated with another profile.

What thumbnail evidence can support

Supported observation

A selected database contained a recoverable cached image record with the reported identifier, size, metadata, and content at examination time.

Not established alone

The original file still exists; a named user opened it; the cached image is the full original; or a displayed database or entry value is the time of viewing.

Cache context is not user intent

Thumbnail creation can result from Explorer display, application activity, indexing, or other system behaviour. Treat mapping results and recovered names as leads. Corroborate them with file-system metadata, LNK files, Jump Lists, ShellBags, Windows Search, application records, and case context.