-
Notifications
You must be signed in to change notification settings - Fork 5
Open
Labels
Description
This is part of usb_vaccine.cmd to-do list.
We can leverage NTFS permissions (or Access Control Lists) to:
(1) further protect the two dummy directories ("autorun.inf" and "Desktop.ini") from being removed, and also
(2) force move or delete some of the suspicious files that we are otherwise denied to move and delete.
This somewhat overlaps what Unlocker does, except that we will leave alone files that are actually in use.