System Volume Information Folder

message from Rich on 10 Jun 2004
I installed Kazaa sometime ago and recently deleted it. A little while
after that I installed AVG 6.0 (an anti-virus program) and it detected a
trojan horse involving keenvalue. Keenvalue (i Think) was installed with
Kazaa and I thought it had deleted it along with everything else. So,
I thought it would be OK to let it delete the program. Well now I keep
getting a pop-up stating that there is a trojan horse file in my System
Volume Information Folder, and it won't remove it, and I can't get
access to this folder in any conventional way. I've already tried going
into admin, but that won't even let me view the folder. I've tried
changing it so it wouldn't be read only but "I don't have permission" to
do that. I also tried reinstalling Kazaa and uninstalling it with no
effect. Does anyone know how I can gain access to this folder to rid
myself of this offending pop-up?
TIA
PS this is on Win XP Home Edition
 
Bruce Chambers replied to Rich on 10 Jun 2004
Greetings --

The System Volume Information is the hidden, protected operating
system folder in which WinXP's System Restore feature stores
information used to recover from errors. It's really not a good idea
for you, or an antivirus application, to directly access the contents
of that folder, unless you expect to have no future use for the
restore points, in which case it would be simpler just to turn off the
System Restore feature.

To clear viruses from the "System Volume Information," simply turn
off the System Restore feature (Start > All Programs > Accessories >
System Tools > System Restore, System Restore Settings), reboot, then
re-enable System Restore, and reboot one last time. This will delete
all of your Restore Points, including the corrupted one(s), and allow
you start with a clean slate.

Bruce Chambers
 
Carey Frisch [MVP] replied to Rich on 10 Jun 2004
You'll need to turn-off System Restore, reboot, then turn it back on.
The virus has infected your System Restore folder (system volume information).

How to Turn On and Turn Off System Restore in Windows XP
http://support.microsoft.com/default.aspx?scid=kb;en-us;310405&Product=winxp
 

Archived message: System Volume Information Folder (Microsoft WinXP)