Page 1 of 1

ADS (Alternate Data Streams)

Posted: 12 Feb 2011, 04:05
by MrNiitriiX
Crash Overron made a video explaining Alternate Data Streams (ADS). ADS were introduced with NTFS and was essentially create to provide compatibility with Macintosh’s Hierarchical File System (HFS). ADS allows data to be forked into existing files without affecting their functionality, size, or display in a file browser. Consequently, ADS enables malicious hackers to easily hide viruses and rootkits in existing files or directories.
[youtube]http://www.youtube.com/watch?v=9Wk21tD_1VE[/youtube]
this is why you need a good antivirus :P

also such programs like HijackThis will find files hidden like this ! ;)