 
 
 
 
 
 
 
| Information | comment | 
|---|---|
| drive/partition | *nix notation (/dev/hda or /dev/sda) | 
| file name | |
| size | Bytes | 
| contents of the stream | determined by the file command (stat + magic number test) | 
| last access date/time | atime | 
| last modification date/time | mtime | 
| feature\program | streams (sysinternals/msft) | lads | ntfs-ads | 
| list |  |  |  | 
| delete all streams |  |  |  | 
| delete individual streams |  |  |  | 
| copy/extract |  |  |  | 
| determine contents |  |  |  | 
| show atime |  |  |  | 
| show mtime |  |  |  | 
| cannot be cheated by windows rootkits? |  |  |  | 
| no change atime? |  |  |  | 
| show national characters correctly? (üöäøщξ) |  |  |  * | 
| open source? |  ** |  |  | 
echo X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H* > c:\test.txt:eicar.com

