Soldato
- Joined
- 7 Mar 2005
- Posts
- 19,562
- Location
- LU7
What does it feel like being a trailblazer?I've googled and googled but I've never seen my technique talked about or documented anywhere. Quite strange really considering it is such a simple and easy to use technique.
I believe the only malware/rootkit that at least partially prevents this technique is Conficker. But only because it sets the NTFS Security of its hidden rootkit files to deny the "Users" group all access to its files. But the "SYSTEM" account would still have access so it would just be a case of executing a script under that account to modify the NTFS Security. It would be much more involved but still possible.
