file deletion

Winsage
October 3, 2026
Windows 11 uses a thumbnail caching mechanism to store previews of images in specific databases located in %LocalAppData%MicrosoftWindowsExplorer, such as thumbcache32.db and thumbcache1024.db. When a user deletes an image, the corresponding thumbnail may remain in the cache, as deletion does not automatically remove it from the thumbnail database. The cache retains only reduced versions of images, not the original files, which is significant in digital forensics where thumbnails can provide insights even when original files are missing. Users can manage their thumbnail cache using the cleanmgr tool to clear saved thumbnails or disable thumbnail caching through the Local Group Policy Editor or File Explorer settings.
Winsage
September 28, 2026
Windows retains thumbnails in a cache file named thumbcache_256.db, but it does not save a thumbnail of every deleted photo. Other operating systems, including macOS and Linux, also use thumbnail caching. Users can access their thumbnail cache by navigating to %LOCALAPPDATA%MicrosoftWindowsExplorer, but this will not show deleted images. Thumbnails are created only when images are displayed in Explorer’s thumbnail view. Windows allows users to clear the thumbnail cache using the Disk Cleanup tool, and there is an option to disable thumbnail caching in Windows 11 Pro and higher. The cached thumbnails do not guarantee persistence and do not represent original files. Windows also keeps records of application launches in Prefetch, maintains entries for USB devices in the USBSTOR registry key, saves Wi-Fi networks and passwords, and can keep clipboard history and recent file shortcuts.
Winsage
September 15, 2026
A spear-phishing campaign linked to the Chinese threat actor UTA0560 targeted various NGOs on September 1, 2026, exploiting recently patched vulnerabilities in Google Chrome and Microsoft Windows. The campaign utilized a malicious JavaScript backdoor called GRIMWEDGE, which was deployed through a multi-stage exploit chain that involved three vulnerabilities: CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880. The attack began with spear-phishing emails that led recipients to a vulnerable U.S.-based university website, allowing attackers to redirect users to their infrastructure. The exploit chain enabled arbitrary code execution and facilitated the deployment of GRIMWEDGE, which is capable of host reconnaissance, file and process management, command execution, and payload delivery. The initial payload was an executable named "msgbox.exe," which extracted a legitimate Windows binary and a malicious DLL called "wsc.dll." This DLL initiated a sideloading chain and contacted a command-and-control server for further instructions. GRIMWEDGE allows for several commands, including system reconnaissance, directory listing, file deletion, and command execution in a hidden window. It lacks built-in persistence or lateral movement mechanisms but provides a foothold for further exploitation. Concurrently, another Chinese threat actor, JungleBamboo (APT31), used the same exploit chain to deploy a loader named SUPERSTOMP, which installs a credential-stealing Chrome extension called LONGTALE. The simultaneous use of the exploit chain by multiple actors suggests potential sharing or sale of the exploit, raising concerns about patch-gap vulnerabilities that pose risks for exploitation campaigns.
Winsage
July 26, 2026
Microsoft released Windows 11 Insider Experimental Preview Build 26300.8935 on July 20, which improves File Explorer's ability to delete large, fragmented files more quickly in certain scenarios. The update promises at least a 30% speed increase for bulk deletions and enhances the responsiveness of the Home tab in File Explorer. The Recommended section now supports touch scrolling. Future updates will include a modernization of the Properties dialog and improvements to search functionality. These enhancements aim to address the sluggishness of File Explorer, which has been attributed to fragmentation issues in NTFS and the hybrid architecture of the application.
Tech Optimizer
July 16, 2026
Panda Dome Complete is a comprehensive Windows security suite that offers protection against various digital threats, including ransomware, phishing scams, and data breaches. A one-year subscription is currently available for .99, reduced from its regular price of .99. Key features include real-time antivirus protection, anti-phishing tools, a dark web scanner, a built-in firewall, Wi-Fi protection, 150MB of daily VPN access, a password manager, PC cleanup tools, file encryption, secure file deletion, gaming and multimedia modes, and parental controls. The product is recognized by industry leaders and has over 23,000 reviews on Trustpilot.
Winsage
June 22, 2026
In the June 9, 2026 Patch Tuesday update for Windows 11, users experienced a bug where the Recycle Bin's confirmation dialog for permanent deletions displayed internal file names (e.g., $Rxxxxx.ext) instead of original filenames. Microsoft acknowledged this issue in its documentation for Windows 11 version 26H1. The Recycle Bin still correctly shows original filenames, and restoring items also uses the original names. This bug arose after installing the June security update (KB5095051), but file management remains functional. Microsoft plans to address this issue in a future update.
Winsage
June 19, 2026
Microsoft's recent Windows update has introduced a cosmetic glitch where the confirmation dialog for permanently deleting a file from the Recycle Bin displays the internal naming convention (e.g., $Rxxxxx.ext) instead of the original file name. This issue is limited to the deletion confirmation dialog; the original file name is preserved in the Recycle Bin and displayed correctly upon restoration. Microsoft has acknowledged the problem but has not provided a public workaround, advising organizations to contact Microsoft Support for assistance. A resolution is in progress and will be included in a future update. The glitch affects desktop versions of Windows from Windows 10 Enterprise LTSB 2016 to Windows 11 26H1, as well as Windows Server editions from 2012 to 2025.
Search