Sorry your browser is not supported!

You are using an outdated browser that does not support modern web technologies, in order to use this site please update to a new browser.

Browsers supported include Chrome, FireFox, Safari, Opera, Internet Explorer 10+ or Microsoft Edge.

Geek Culture / System Volume Information?

Author
Message
Hamish McHaggis
21
Years of Service
User Offline
Joined: 13th Dec 2002
Location: Modgnik Detinu
Posted: 4th Nov 2003 18:04
I recently acquired a ' nachi virus', which my virus scanner (suposedly) keeps popping up a window saying that it has detected it. However if I run the scan (AGV Anti-Virus (not pro)) it detects nothing. The message says that it is in a folder called 'system volume information' in the c:/ drive. However this folder does not exist, even as a hidden one, when using the windows file browser.

What makes me suspicious of this 'folder' is that I run a checklist for folders with dbpro, and this s.v.i. folder appears, however if I try to switch the directory to the folder, my program crashes and an error message appears saying "cannot find directory". However the command "path exist" returns a 1 when you plug in that directory. Very odd.

Thats why I am posting, I wonder if anyone else has had encounters with the nachi worm, or if they know anything about system volume information. Thanks.

Do you bite your thumb at me sir?

Athelon XP 1600 Plus - Nvidia Geforce MX400 - 256mb RAM
the_winch
21
Years of Service
User Offline
Joined: 1st Feb 2003
Location: Oxford, UK
Posted: 4th Nov 2003 18:24
if you are using winxp the folder is there, if you are using xp it hides it.
I guess the virus is expoiting the fact that winxp denys access to that folder so once it gets in there it is immune to your virus scanner.

If the filesystem is fat32 just use something that can read/write fat32 partions (win98 boot disk) and delete the System Volume Information folder and reboot.

If you are using ntfs perhaps search for something that will remove the virus or folder.

If it is still there bakup everything you want to keep and reformat, You don't want to do this too much as you can only do it 3 times in 6 months before having to phone up microsoft for permission to use the os you paid for.

Login to post a reply

Server time is: 2024-11-24 03:36:55
Your offset time is: 2024-11-24 03:36:55