To turn of File System Redirection call the Wow64DisableWow64FsRedirection and remember to turn it back on with Wow64RevertWow64FsRedirection.
For example:
Code: Select all
//turn off File System Redirection
LibFunc>kernel32,Wow64DisableWow64FsRedirection,result,0
Let>RP_ADMIN=1
let>RP_WAIT=1
DeleteFile>%TEMP_DIR%\vss.txt
Run>"cmd.exe" /c vssadmin list shadowstorage >> "%TEMP_DIR%\vss.txt"
ReadFile>%TEMP_DIR%\vss.txt,vss
MessageModal>vss
//revert File System Redirection
LibFunc>kernel32,Wow64RevertWow64FsRedirection,result,0