b_man
Broken In
On two occasions, my AntiVirus has found some trojans in C:\System Volume Information...i allow it to delete the infected files since it can't repair them...my question is:
What is system volume information?? is it OK to let the AV delete these files?
The log is as under...
deleted: Trojan program Backdoor.Win32.Rbot.bwn File: C:\System Volume Information\_restore{592E117C-5274-4000-9367-749921843CE3}\RP271\A0129514.exe
deleted: Trojan program Backdoor.Win32.Rbot.bwn File: C:\System Volume Information\_restore{592E117C-5274-4000-9367-749921843CE3}\RP271\A0129515.exe
deleted: Trojan program Backdoor.Win32.Rbot.bwn File: C:\WINDOWS\system32\syms32.exe
deleted: Trojan program Trojan-Proxy.Win32.Agent.lu File: C:\System Volume Information\_restore{592E117C-5274-4000-9367-749921843CE3}\RP273\A0129550.exe
deleted: Trojan program Trojan-Downloader.Win32.Small.edb File: C:\System Volume Information\_restore{592E117C-5274-4000-9367-749921843CE3}\RP273\A0129551.exe//FSG
deleted: Trojan program Backdoor.Win32.Rbot.bwn File: C:\System Volume Information\_restore{592E117C-5274-4000-9367-749921843CE3}\RP273\A0129552.exe
What is system volume information?? is it OK to let the AV delete these files?
The log is as under...
deleted: Trojan program Backdoor.Win32.Rbot.bwn File: C:\System Volume Information\_restore{592E117C-5274-4000-9367-749921843CE3}\RP271\A0129514.exe
deleted: Trojan program Backdoor.Win32.Rbot.bwn File: C:\System Volume Information\_restore{592E117C-5274-4000-9367-749921843CE3}\RP271\A0129515.exe
deleted: Trojan program Backdoor.Win32.Rbot.bwn File: C:\WINDOWS\system32\syms32.exe
deleted: Trojan program Trojan-Proxy.Win32.Agent.lu File: C:\System Volume Information\_restore{592E117C-5274-4000-9367-749921843CE3}\RP273\A0129550.exe
deleted: Trojan program Trojan-Downloader.Win32.Small.edb File: C:\System Volume Information\_restore{592E117C-5274-4000-9367-749921843CE3}\RP273\A0129551.exe//FSG
deleted: Trojan program Backdoor.Win32.Rbot.bwn File: C:\System Volume Information\_restore{592E117C-5274-4000-9367-749921843CE3}\RP273\A0129552.exe