Dissect System Restore snapshots

Posted by Unsigned on Super User See other posts from Super User or by Unsigned
Published on 2011-11-09T16:18:11Z Indexed on 2011/11/19 17:57 UTC
Read the original article Hit count: 255

Filed under:

Is there any way to map the A000????.??? filenames in the System Volume Information to their original names, without restoring them?

The reason I ask is that several files in one user's System Volume Information RP1 were infected by a rootkit. Although they've been removed, I'd like to be able to figure out what they were originally. A0001253.sys and A0001211.sys are not very helpful names. :)

It happened on two systems, one XP SP2, the other XP SP3.

© Super User or respective owner

Related posts about system-restore