← Back to context

Comment by jpalomaki

7 years ago

”The Volume Shadow Copy Service (VSS) keeps historical versions of files and folders on NTFS volumes by copying old, newly overwritten data to shadow copy via copy-on-write technique. The user may later request an earlier version to be recovered.”

https://en.m.wikipedia.org/wiki/NTFS#Volume_Shadow_Copy

> Volume Shadow Copy Service

Sure, and the first thing every WIN virus does is deletes the shadow copies.

  • I don't see what you're getting at, an equivalent virus on Linux would delete snapshots as well.