System Volume Information...WTF

System Volume Information...WTF

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
System Volume Information...WTF Catamount 12-14-2005
Posted by Catamount on December 14, 2005, 8:57 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Ok, so I got this machine that HAD a virus. I am not sure which one as
I only found parts of a virus that seem to be parts of several virus'.
One of my users did something right and noticed something strange and
disconnected from the Internet right away. So anyway, I have this
re.exe that Symantec Corp Edition keeps finding as a
"Hacktool.HideWindow" in the system volume information folder and leaves
it alone. Why does it leave it alone? Who knows, its set to delete
such things. I do know that the folder is set so only the system can
access it, but I can change that. I am concerned however that this
might break something if I go into that folder and mess with it. Anyone
know if its safe for me to go in and just delete it?

Posted by David H. Lipman on December 14, 2005, 9:49 am
If you were  Registered and logged in, you could reply and use other advanced thread options

| Ok, so I got this machine that HAD a virus. I am not sure which one as
| I only found parts of a virus that seem to be parts of several virus'.
| One of my users did something right and noticed something strange and
| disconnected from the Internet right away. So anyway, I have this
| re.exe that Symantec Corp Edition keeps finding as a
| "Hacktool.HideWindow" in the system volume information folder and leaves
| it alone. Why does it leave it alone? Who knows, its set to delete
| such things. I do know that the folder is set so only the system can
| access it, but I can change that. I am concerned however that this
| might break something if I go into that folder and mess with it. Anyone
| know if its safe for me to go in and just delete it?

You are using WinXP -- Right ?

Hacktool.HideWindow --
http://securityresponse.symantec.com/avcenter/venc/data/hacktool.hidewindow.html

Under the folder System Volume Information is _restore
c:\System Volume Information\_restore

This is the WinXP System Restore cache. Malware can't be removed from this
location as it
is protected by the OS. If you don't want to get re-infected by restoring it,
you need to
flush the System Restore cache by disabling System Restore, rebooting the PC and
then
re-enabling the System Restore. It would be a good idea to create a new restore
point after
the System Restore cache has been re-enabled.

http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001111912274039?OpenDocument&src=sec_doc_nam

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by Catamount on December 14, 2005, 10:30 am
If you were  Registered and logged in, you could reply and use other advanced thread options
David H. Lipman wrote:
>
> | Ok, so I got this machine that HAD a virus. I am not sure which one as
> | I only found parts of a virus that seem to be parts of several virus'.
> | One of my users did something right and noticed something strange and
> | disconnected from the Internet right away. So anyway, I have this
> | re.exe that Symantec Corp Edition keeps finding as a
> | "Hacktool.HideWindow" in the system volume information folder and leaves
> | it alone. Why does it leave it alone? Who knows, its set to delete
> | such things. I do know that the folder is set so only the system can
> | access it, but I can change that. I am concerned however that this
> | might break something if I go into that folder and mess with it. Anyone
> | know if its safe for me to go in and just delete it?
>
> You are using WinXP -- Right ?
>
> Hacktool.HideWindow --
>
http://securityresponse.symantec.com/avcenter/venc/data/hacktool.hidewindow.html
>
> Under the folder System Volume Information is _restore
> c:\System Volume Information\_restore
>
> This is the WinXP System Restore cache. Malware can't be removed from this
location as it
> is protected by the OS. If you don't want to get re-infected by restoring it,
you need to
> flush the System Restore cache by disabling System Restore, rebooting the PC
and then
> re-enabling the System Restore. It would be a good idea to create a new
restore point after
> the System Restore cache has been re-enabled.
>
>
http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001111912274039?OpenDocument&src=sec_doc_nam
>

Thats what I thought and so I turned off system restore, but didn't
re-enable. I will re-enable it and see if that clears it up. I will
let you know. Thanks David!

Posted by Catamount on December 15, 2005, 8:11 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Catamount wrote:
> David H. Lipman wrote:
>>
>> | Ok, so I got this machine that HAD a virus. I am not sure which one as
>> | I only found parts of a virus that seem to be parts of several virus'.
>> | One of my users did something right and noticed something strange and
>> | disconnected from the Internet right away. So anyway, I have this
>> | re.exe that Symantec Corp Edition keeps finding as a
>> | "Hacktool.HideWindow" in the system volume information folder and
>> leaves
>> | it alone. Why does it leave it alone? Who knows, its set to delete
>> | such things. I do know that the folder is set so only the system can
>> | access it, but I can change that. I am concerned however that this
>> | might break something if I go into that folder and mess with it.
>> Anyone
>> | know if its safe for me to go in and just delete it?
>>
>> You are using WinXP -- Right ?
>>
>> Hacktool.HideWindow --
>>
http://securityresponse.symantec.com/avcenter/venc/data/hacktool.hidewindow.html
>>
>>
>> Under the folder System Volume Information is _restore
>> c:\System Volume Information\_restore
>>
>> This is the WinXP System Restore cache. Malware can't be removed from
>> this location as it
>> is protected by the OS. If you don't want to get re-infected by
>> restoring it, you need to
>> flush the System Restore cache by disabling System Restore, rebooting
>> the PC and then
>> re-enabling the System Restore. It would be a good idea to create a
>> new restore point after
>> the System Restore cache has been re-enabled.
>>
>>
http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001111912274039?OpenDocument&src=sec_doc_nam
>>
>>
>
> Thats what I thought and so I turned off system restore, but didn't
> re-enable. I will re-enable it and see if that clears it up. I will
> let you know. Thanks David!

Nope. Still there. Any other suggestions?

Posted by Max Wachtel on December 15, 2005, 8:24 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Nope@spam.no AKA Catamount on 12/15/2005 in
this jewel:

> Catamount wrote:
> > David H. Lipman wrote:
> > >
> > > > Ok, so I got this machine that HAD a virus. I am not sure
> > > > which one as I only found parts of a virus that seem to be
> > > > parts of several virus'. One of my users did something right
> > > > and noticed something strange and disconnected from the
> > > > Internet right away. So anyway, I have this re.exe that
> > > > Symantec Corp Edition keeps finding as a "Hacktool.HideWindow"
> > > > in the system volume information folder and leaves it alone.
> > > > Why does it leave it alone? Who knows, its set to delete such
> > > > things. I do know that the folder is set so only the system
> > > > can access it, but I can change that. I am concerned however
> > > > that this might break something if I go into that folder and
> > > > mess with it. Anyone know if its safe for me to go in and
> > > > just delete it?
> > >
> > > You are using WinXP -- Right ?
> > >
> > > Hacktool.HideWindow --
> > > http://securityresponse.symantec.com/avcenter/venc/data/hacktool.h
> > > idewindow.html
> > >
> > > Under the folder System Volume Information is _restore
> > > c:\System Volume Information\_restore
> > >
> > > This is the WinXP System Restore cache. Malware can't be removed
> > > from this location as it is protected by the OS. If you don't
> > > want to get re-infected by restoring it, you need to flush the
> > > System Restore cache by disabling System Restore, rebooting the
> > > PC and then re-enabling the System Restore. It would be a good
> > > idea to create a new restore point after the System Restore
> > > cache has been re-enabled.
> > >
> > > http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/200111191
> > > 2274039?OpenDocument&src=sec_doc_nam
> > >
> >
> > Thats what I thought and so I turned off system restore, but didn't
> > re-enable. I will re-enable it and see if that clears it up. I
> > will let you know. Thanks David!
>
> Nope. Still there. Any other suggestions?
******************Reply Separator*************************

when you turned off system restore did you reboot?

max
--
Virus Removal Instructions: http://home.neo.rr.com/manna4u/
Keeping Windows Clean: http://home.neo.rr.com/manna4u/keepingclean.html
Windows Help: http://home.neo.rr.com/manna4u/tools.html
Specific Fixes: http://home.neo.rr.com/manna4u/fixes.html
Forums for HiJackThis Logs:
http://home.neo.rr.com/manna4u/forums_for_hijackthis_logs.html
To reply by e-mail change nomail.afraid.org to gmail.com
nomail.afraid.org is setup specifically for use in USENET
feel free to use it yourself. Registered Linux User #393236

Similar ThreadsPosted
Virus Information December 7, 2005, 2:43 am
One Care 1.5 information. April 13, 2007, 4:10 pm
Detail information September 17, 2007, 3:01 am
Virus Information October 10, 2007, 2:02 pm
Remove FCS SSA information July 15, 2008, 7:19 am
Virus security information? January 7, 2008, 4:50 am
simulation virus spread, thesis information needed September 20, 2006, 1:16 am
System.ini January 23, 2006, 9:52 am
System shutting Down June 28, 2005, 1:21 pm
NT AUTHORITY SYSTEM September 13, 2005, 5:52 pm

The site map in XML format XML site map

Contact Us | Privacy Policy