cfman wrote:
> I accidentally run into a adware program today.
>
> While it is running and trying to set up a lot sub adware programs, I
> immediately recognized it was a adware so I shutdown the Windows XP sp2
> immediately.
>
> Then I boot into safe-mode and did a system restore(the Windows Defender
> made a restore point right before I click to setup the adware).
>
> Then it rebooted and I boot into safe-mode again and did a Symentec
> Antivirus scanning and found two adwares in the "System Volume Information"
> folder.
>
> But Symentec could not delete it. The folder was not accessible. It is a
> system folder. I tried to look into it manually and failed getting into it
> too.
>
> What can I do to remove the two adwares found in this folder? (I believe it
> was because the Windows XP system restore actually made a backup before it
> made the restore, so the virus files got backuped into that folder, ...)
>
> Thanks a lot!
>
>
The System Volume Information is the hidden, protected operating
system folder in which WinXP's System Restore feature stores
information used to recover from errors. It's really not a good idea
for you, or an antivirus application, to directly access the contents
of that folder, unless you expect to have no future use for the
restore points, in which case it would be simpler just to turn off the
System Restore feature.
To clear viruses or other malware from the "System Volume
Information," simply turn off the System Restore feature (Start > All
Programs > Accessories > System Tools > System Restore, System Restore
Settings), reboot, then re-enable System Restore, and reboot one last
time. This will delete all of your Restore Points, including the
corrupted one(s), and allow you start with a clean slate.
--
Bruce Chambers
Help us help you:
http://dts-l.org/goodpost.htm
http://www.catb.org/~esr/faqs/smart-questions.html
They that can give up essential liberty to obtain a little temporary
safety deserve neither liberty nor safety. -Benjamin Franklin
Many people would rather die than think; in fact, most do. -Bertrum Russell