Everything You Need to Know About Alternate Data Streams
Alternate Data Streams is used by recently discovered Rootkit to hide itself from the being discovered. By using Alternate Data Streams you can totally hide files from the user and from Anti-Virus applications
What is an alternate data stream (ADS)?
In NTFS, a file consists of different data streams. One stream holds the security information (access rights and such things), another one holds the “real data” you expect to be in a file. There may be another stream with link information instead of the real data stream, if the file actually is a link. And there may be alternate data streams, holding data the same way the standard data stream does.
heysoft.de published a page called: FAQ: Alternate Data Streams in NTFS which gives you all the information about Alternate Data Streams.







Feeds 
