VSSadmin
Qute stuff to do when running ShadowCopy (VVS) :) Comments from notepad while watching a online capture from some haxxor show. Prolly abit mixed, but a kewl thing it is ;pLinux Common Directory Names:-space/dotspace/dotdotspace/namespace -mkdir ´.[space]` -mv malware /path/.\[space]/ -/path/.\[space]/malvaremkdir `temp[space]´Windows Alternate Data Streams (ADS) type malware.exe > harmless.txt:evil.exe start c:\path\to\harmless.txt:evil.exe dir /r will find it. (vista and later) sysinternals Streams list alternate data streams (LADS) fairly easy to eradicate ADS on Steroids echo anything > … Continue reading