C:\_restore
Bosnian_Cowboy
Join Date: 2003-06-07 Member: 17088Members, Constellation
in Off-Topic
<div class="IPBDescription">What is this?</div> I ran an internet virus scan utility that said I have a virus in one of the files in the C:\_RESTORE\TEMP\ folder. It couldn't delete the virus because it "might be in use." I found only the internet browser, system tray, and explorer running in the backround. I checked this _Restore folder out, it's only got like 4 files in there: DISKCFG.dat, SRDISKID.dat, VxDMon.cfg, and VxDMon.dat. There is no temp, but there must be more there. I can't see it even with "see hidden folders" thing enabled. The size of the folder _RESTORE is 14 gigs, but the files I see in there couldn't amount to more than 1 mb. I'm unable to delete the folder.
Can anyone explain to me what the hell is going on?
Can anyone explain to me what the hell is going on?
Comments
<span style='font-size:8pt;line-height:100%'><span style='font-family:Courier'>Just kidding <!--emo&:p--><img src='http://www.unknownworlds.com/forums/html/emoticons/tounge.gif' border='0' style='vertical-align:middle' alt='tounge.gif'><!--endemo--></span></span>
Not really.
Cause your NOT. Virus scanners catches most viruses but not all. STOP RELYING ON THEM.
"OH NOS I RAN MY VIRUS SKANNER I R LEET WITH NO VIRZES"
Now.
Because you dont know how much the virus has spread the best recommendation for you would be: Format. Even if you 'clean' the virus out it still leaves traces no matter what your scanner tells you.
Could be that it infected your Restore files <!--emo&:(--><img src='http://www.unknownworlds.com/forums/html/emoticons/sad.gif' border='0' style='vertical-align:middle' alt='sad.gif'><!--endemo-->
Bummer if it did, cause you'll need to format if it did <!--emo&:(--><img src='http://www.unknownworlds.com/forums/html/emoticons/sad.gif' border='0' style='vertical-align:middle' alt='sad.gif'><!--endemo-->
[right click my computer-> properties ->system restore -> disable]
the restart your machine into safe mode
now run your virus scan, now it should have full access to the drive
After you are done, I dunno, you may want to turn system restore back on. But only after you are sure the virus is gone. Best of luck!
oky; system restore saves all sorts of system information, and quite often this includes a virus file. if youve had a virus for a couple weeks then it will be recorded in the system restore files. here it is DORMANT. if you cleaned the virus from elsewhere on the system it will keep showing up uncleanable in the system restore folder until you purge your system restore data by disabling it and then deleting the folder.
its not hurting you in system restore, but if you ever use it theres a good chance the virus will be restored with the previous windows settings <!--emo&:)--><img src='http://www.unknownworlds.com/forums/html/emoticons/smile.gif' border='0' style='vertical-align:middle' alt='smile.gif'><!--endemo--> although the virus is harmless in its current state it would be wise to disable sysrestore, delete the folder, and reenable it.
GGKTHXBai!
Jk, but honestly. If you can't find any other way to deal with it. Backup the stuff you really want get a new OS and reformat.
This should get rid of it. If not, and if you're running FAT32, you can always get a hold of a bootable distro of Linux known as "Knoppix". You can then mount your drive ("mount hda0" or "mount hda1") and delete the pesky folder from there.
Then I suggest you get yourself a software firewall. I use <a href='http://www.tinysoftware.com/home/tiny2?la=EN' target='_blank'>Tiny Personal Firewall</a>. It's pretty good.
--Scythe--
[EDIT] /me slaps self
That'll learn me to not read the entire thread.
[/EDIT]
To FIX:
(This is in XP, but I've done this in ME. It should match up)
Control Panel -> System -> System Restore tab.
Disable System Restore
Restart Computer
Delete Virus
Turn System Restore back on.
Can we have a rule that, for tech support threads, we don't fill it up with worthless crap? 19 replies and I've seen maybe 3 that actually addressed the problem.
You aren't clever by writing a stale one liner (lol virus pwnge!) <!--emo&:angry:--><img src='http://www.unknownworlds.com/forums/html/emoticons/mad.gif' border='0' style='vertical-align:middle' alt='mad.gif'><!--endemo-->