|
System Volume Information file suspect
Hi
I have had a file on my computer for awhile now that has been causing problems. It was first identified by my av, saying it was a backdoor program, but gave me no option to remove it. When it is operating, my internet activity is contsant, even when I have no internet programs active. It seems to be related to my system restore, as when I disable system restore, it is no longer present, and the constant activity stops. When I enable system restore again, the file comes back (I have a process explorer program, where I can see it come and go), and the constant activity begins again. My other problem with system restore is, when I enable it, it never sets a restore point, the restore point is always today.
At the moment, I am also having trouble enabling system restore, I have tried through the control panel, and also the accessories, and they tell me system restore cannot protect my computer at the moment, please reboot and try again, and when I do, I just get the same message.
My question is, is there a way for me to get into the System Volume information folder and delete the problem file (I always get access denied, even though I have changed the file view to show hidden folders etc), and also, do you have any other ideas for me to enable system restore again?
The suspect file is :
C:\SystemVolumeInformation\-restore{4BAE78A9.A03E.4C8A.A330.6A3CC753B032}\RP25 3\change.log
There was also a similar file flagged by my av with a .exe at one stage, although I didn't get to write it down.
Thanks for your help
DM
|