PDA

View Full Version : Detect unexpected alternate data streams (ADS)


PepiMK
2008-04-25, 11:50
Situation: RootAlyzer looks for indicators for rootkits.

Experienced: while ADS is used by legit applications as well, it can be used by malware to hide stuff, even executable code.

Expected: show these. Similar to ADSLocator.