Tech or Treat! Write an article about your scariest tech disaster to win gadgets!Learn more

x
?
Solved

Virus

Posted on 2003-12-02
9
Medium Priority
?
349 Views
Last Modified: 2010-04-11
Hello everyone,
     I have had McAfee come up saying that there is a virus in my C:\System Volume Information\ folder, I cannot delete the file from McAfee and I don't know what to do. Any idea's.

-Neocytrix
0
Comment
Question by:neocytrix
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
9 Comments
 
LVL 49

Expert Comment

by:sunray_2003
ID: 9863695
Dear neocytrix,

Are you sure if never said about the virus name ? Did it not say whether it was able to delete the file or quarantine it

Use these online scanners to see if you can get the name of the virus

online virus scanner:
---------------------

http://housecall.trendmicro.com/ 

http://security.symantec.com/

http://www.pandasoftware.com/activescan/com/activescan_principal.htm

http://www.pcpitstop.com/antivirus/default.asp 

DOS based : http://www.f-prot.com/download/download_fpdos.html


Thanks,
Sunray
0
 
LVL 6

Accepted Solution

by:
Joseph_Moore earned 200 total points
ID: 9879421
This is on WinXP, right? The System Volume Information folder is where XP holds the System Restore files. I have seen viruses get into a SR folder also.
Read this Technet article on working in the System Volume Information folder. It is locked pretty tight, so you need to go through a few steps to get in it and delete the infected files:
http://support.microsoft.com/?kbid=309531
I would do as the Technet article says, then try and re-scan with Mcafee.

hope this helps
0
 
LVL 5

Expert Comment

by:Hypoviax
ID: 9946634
The first step i would take is to check the processes running in WINDOWS TASK MANAGER then terminate the suspect file.
Then i would attempt to delete the file specified by McAfee. If this does not work then try running the programs by sunray_2003.

Regards,

Hypoviax
0
Q2 2017 - Latest Malware & Internet Attacks

WatchGuard’s Threat Lab is a group of dedicated threat researchers committed to helping you stay ahead of the bad guys by providing in-depth analysis of the top security threats to your network.  Check out our latest Quarterly Internet Security Report!

 
LVL 1

Expert Comment

by:hgottfried
ID: 9981985
Hello, there is nothing for you to terminate in the Windows Task manager as this file is residing in your "System Restore" folder.  What happens here is you either had a virus before and got rid of it or had one and didn't know it, but no matter Windows in its process to help you backed up the virus just like it would any other file if you had needed to restore it.

1.      Click Start.
2.      Right-click My Computer, and then click Properties.
3.      Click the System Restore tab.
4.      Select "Turn off System Restore" or "Turn off System Restore on all drives" check box
5.      Click Apply.
6.      As noted in the message, this will delete all existing restore points. Click Yes to do this.
7.      Click OK.
8.      Proceed with what you need to do. For example, removing viruses. Restart the computer and follow the instructions in the next section to turn on System Restore.

 This MAY get rid of the virus for you, or place it in a temp folder as the restore points become deleted.

To turn it back on:

1.      Click Start.
2.      Right-click My Computer, and then click Properties.
3.      Click the System Restore tab.
4.      Clear the "Turn off System Restore" or "Turn off System Restore on all drives" check box.
5.      Click Apply, and then click OK.

0
 
LVL 4

Expert Comment

by:mrfixitpc
ID: 10008542
What  Virus and  what  is the  exact file that it  states  is  the  error
0
 
LVL 5

Expert Comment

by:Hypoviax
ID: 12994209
In my opinion a split of points between experts should occur as a suitable response to the authors problem has been made.

Hypoviax
0

Featured Post

Q2 2017 - Latest Malware & Internet Attacks

WatchGuard’s Threat Lab is a group of dedicated threat researchers committed to helping you stay ahead of the bad guys by providing in-depth analysis of the top security threats to your network.  Check out our latest Quarterly Internet Security Report!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The well known Cerber ransomware continues to spread this summer through spear phishing email campaigns targeting enterprises. Learn how it easily bypasses traditional defenses - and what you can do to protect your data.
How does someone stay on the right and legal side of the hacking world?
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

647 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question