AV finds trojan in C:\System Volume Information

Status
Not open for further replies.

b_man

Broken In
On two occasions, my AntiVirus has found some trojans in C:\System Volume Information...i allow it to delete the infected files since it can't repair them...my question is:

What is system volume information?? is it OK to let the AV delete these files?

The log is as under...

deleted: Trojan program Backdoor.Win32.Rbot.bwn File: C:\System Volume Information\_restore{592E117C-5274-4000-9367-749921843CE3}\RP271\A0129514.exe

deleted: Trojan program Backdoor.Win32.Rbot.bwn File: C:\System Volume Information\_restore{592E117C-5274-4000-9367-749921843CE3}\RP271\A0129515.exe

deleted: Trojan program Backdoor.Win32.Rbot.bwn File: C:\WINDOWS\system32\syms32.exe

deleted: Trojan program Trojan-Proxy.Win32.Agent.lu File: C:\System Volume Information\_restore{592E117C-5274-4000-9367-749921843CE3}\RP273\A0129550.exe

deleted: Trojan program Trojan-Downloader.Win32.Small.edb File: C:\System Volume Information\_restore{592E117C-5274-4000-9367-749921843CE3}\RP273\A0129551.exe//FSG

deleted: Trojan program Backdoor.Win32.Rbot.bwn File: C:\System Volume Information\_restore{592E117C-5274-4000-9367-749921843CE3}\RP273\A0129552.exe
 

Arsenal_Gunners

Human Spambot
System volume info=where xp stores system restore data,more here *www.theeldergeek.com/system_volume_information_folder1.htm

if it is a virus,go and delete it :D
 

Vishal Gupta

Microsoft MVP
Its the folder, which contains "System Restore" files. So I think u shouldnt worry about it. :)

I'll also suggest u to disable "System Restore" and then delete this folder and then enable it again, if u use "System Restore".

[Edit]
One minute late... :D
[/Edit]
 
Status
Not open for further replies.
Top Bottom