Answers to your tech questions
Computer forums for help with removing malicious software (malware) and improving computer security

Welcome Guest to What the Tech! ( Log In | Register ) We specialize in the removal of malicious software (malware), but here you'll find free help and support for all your tech questions. We invite you to ask questions, share experiences, and learn. Explore our message boards, or register now to post messages of your own. Please Start Here. Register today (registration removes advertising)

 
Closed TopicStart new topic
> [Resolved] question about a file.
medicman151
post Aug 29 2008, 07:14 PM
Post #1


Authentic Member
Group Icon

Group: Freshman Class
Posts: 180
Joined: 4-August 07
Member No.: 71,874
Operating System: windows 2000 server



My McAfee scan keeps detecting this file: C;\System Volume Informatio_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP5\A0001025.exe
When I try to delete it, It will not let me. Any ideas?
Thanks
Go to the top of the page
 
+Quote Post
Noviciate
post Aug 31 2008, 04:05 PM
Post #2


SuperMember
Group Icon

Group: Malware Team
Posts: 1,276
Joined: 30-July 06
Member No.: 59,198
Operating System: Windows XP



The location in question, System Volume Information, is where Windows stores Restore Point information. Although this detection is a potential risk if you were to use the infected Restore Point, it isn't if you don't.
Although there are some scanners that can access this folder, Windows prefers to keep everyone out because System Restore is a safety net and you don't want it broken.
In order to manually delete this you will need to either access the folder, which is a little tricky, or just delete the old Restore Points. In order to do that, which is easiest and safest:

http://www.bleepingcomputer.com/forums/tutorial56.html You'll need to disable System Restore, reboot the PC and then enable System Restore. Don't forget to create a new Restore Point to ensure that the safety net is back in place.
Bear in mind that flushing these points will prevent you using them in the future, so if your system isn't otherwise OK I suggest you don't do it. While restoring the PC to an infected time will reinfect the PC, this is better than having an expensive paperweight if you lose the safety net.
Go to the top of the page
 
+Quote Post
medicman151
post Aug 31 2008, 07:42 PM
Post #3


Authentic Member
Group Icon

Group: Freshman Class
Posts: 180
Joined: 4-August 07
Member No.: 71,874
Operating System: windows 2000 server



Thank for the reply. That took care of the problem. I thought that would do it, but I wanted to make sure. All is well again. You can close this thread. Once again, Thanks.
Go to the top of the page
 
+Quote Post
Noviciate
post Sep 1 2008, 12:22 PM
Post #4


SuperMember
Group Icon

Group: Malware Team
Posts: 1,276
Joined: 30-July 06
Member No.: 59,198
Operating System: Windows XP



Since this issue appears to be resolved ... this Topic has been closed. Glad we could be of assistance.

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.

Go to the top of the page
 
+Quote Post

Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 


RSS Time is now: 9th January 2009 - 10:34 PM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy