<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Anti-Forensics &#187; upx</title>
	<atom:link href="http://www.anti-forensics.com/tag/upx/feed" rel="self" type="application/rss+xml" />
	<link>http://www.anti-forensics.com</link>
	<description>Rendering computer investigations irrelevant</description>
	<lastBuildDate>Thu, 15 Dec 2011 07:57:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Modify NTFS Timestamps and Cover Your Tracks With Timestomp.exe</title>
		<link>http://www.anti-forensics.com/modify-ntfs-timestamps-and-cover-your-tracks-with-timestomp</link>
		<comments>http://www.anti-forensics.com/modify-ntfs-timestamps-and-cover-your-tracks-with-timestomp#comments</comments>
		<pubDate>Thu, 05 Mar 2009 22:08:36 +0000</pubDate>
		<dc:creator>Max</dc:creator>
				<category><![CDATA[Anti-Forensics Software]]></category>
		<category><![CDATA[Hex Editing]]></category>
		<category><![CDATA[compression]]></category>
		<category><![CDATA[hex editor]]></category>
		<category><![CDATA[packing]]></category>
		<category><![CDATA[timestomp]]></category>
		<category><![CDATA[timestomp.exe]]></category>
		<category><![CDATA[upx]]></category>
		<category><![CDATA[windows xp]]></category>

		<guid isPermaLink="false">http://www.anti-forensics.com/?p=125</guid>
		<description><![CDATA[There have been a million articles written on using timestomp.exe. However, the goal of this article is to give some ideas on how to use timestomp and avoid leaving evidence behind that would point to its use.
Related posts:<ol>
<li><a href='http://www.anti-forensics.com/modify-truecrypt-encryption-boot-loader-strings' rel='bookmark' title='Modify TrueCrypt Encryption Boot Loader Strings'>Modify TrueCrypt Encryption Boot Loader Strings</a> <small>In a previous post I mentioned that TrueCrypt leaves behind...</small></li>
<li><a href='http://www.anti-forensics.com/beat-encase-file-signature-analysis-on-a-windows-system' rel='bookmark' title='Beat EnCase File Signature Analysis on a Windows System'>Beat EnCase File Signature Analysis on a Windows System</a> <small>Use a hex editor to modify the file signature of...</small></li>
</ol>]]></description>
		<wfw:commentRss>http://www.anti-forensics.com/modify-ntfs-timestamps-and-cover-your-tracks-with-timestomp/feed</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
	</channel>
</rss>

