Dissect System Restore snapshots
- by Unsigned
Is there any way to map the A000????.??? filenames in the System Volume Information to their original names, without restoring them?
The reason I ask is that several files in one user's System Volume Information RP1 were infected by a rootkit. Although they've been removed, I'd like to be able to figure out what they were originally. A0001253.sys…