[pchelpers] Re: antitrojan help

  • From: Scott McNay <Wizard@xxxxxxxx>
  • To: Billyus Eximius <pchelpers@xxxxxxxxxxxxx>
  • Date: Wed, 9 Jun 2004 22:32:35 -0500

Hi Billyus,

Wednesday, June 9, 2004, 12:30:59 PM, you wrote:

BE> The annoying thig is though, I've managed to get rid of this
BE> trojan, but I don't know what I did to get rid of it. Also, I
BE> couldn't get AVG to run in safe mode both times I tried it????

BE> Anyway, it's gone now but I wish I knew what I did.

There are two ways to get access to files in "\System Volume
Information". The first way is to turn off System Restore, as has been
mentioned. The other way is to add your UserId to the Security tab of
the Properties sheet for the folder. Normally, only the System account
has access to the folder, but anyone with Administrator privileges can
add other users. The second method has the advantage that you don't
lose your Restore Points (i.e., your backups).

I don't know why the AV manufacturers don't add the extra code needed
to remove viruses, etc., from "\System Volume Information". If they're
paranoid that a false alarm might result in the unintended deletion of
good backup files, all they have to do is make sure that the user
manually types something to approve the deletion.

BTW, I'm not certain about Win2K, but in WinXP, the folder seems to be
always present.

--Scott.


-------list-services-below-----------
Regards, John Durham (list moderator) <http://modecideas.com/contact.html?sig>
Freelists login at //www.freelists.org/cgi-bin/lsg2.cgi
List archives at //www.freelists.org/archives/pchelpers
PC-HELPERS list subscribe/unsub at http://modecideas.com/discuss.htm?sig
Latest news live feeds at http://modecideas.com/indexhomenews.htm?sig
Good advice is like good paint- it only works if applied.

Other related posts: