How to remove viruses from shadowcopy?

Discussion and support for the Windows family of operating systems.
Post Reply
Belix
Registered User
Posts: 3719
Joined: 26 Jul 2003, 02:00
Location: Randburg

How to remove viruses from shadowcopy?

Post by Belix »

Hi folks
Sophos antivirus is picking up some viruses stuck away in shadowcopy4 on the SBS2003 server. Unfortunately it cannot remove them or move them to quarantine. I've checked under computer management and shadow copies seem to be disabled. I've also tried using wmic at command prompt and typed in shadowcopy, to which is replies No Instance(s).
Is there a way to manually see the shadowcopy folder and delete it? Some other way?
Thanks guys!
    
| Intel C2D E7300 | Asus Striker Extreme | CL X-Fi ME | Asus 8800GTS | Aopen 700W |
| 2*Seagate 1TB Raid | Samsung 2232GW 22" LCD | Team Extreem 2GB DDR2 800 |
3ddy
Registered User
Posts: 31
Joined: 07 Jul 2010, 16:16

Re: How to remove viruses from shadowcopy?

Post by 3ddy »

have you tried using another antivirus to scan and clean?
User avatar
rustypup
Registered User
Posts: 8872
Joined: 13 Dec 2004, 02:00
Location: nullus pixius demonica
Contact:

Re: How to remove viruses from shadowcopy?

Post by rustypup »

3ddy wrote:have you tried using another antivirus to scan and clean?
shadow copy is read only... nothing, aside from disabling, is supposed to delete them..

@Belix: any chance the error message is pointing to a volume copy of your quarantine folder?
Most people would sooner die than think; in fact, they do so - Bertrand Russel
Belix
Registered User
Posts: 3719
Joined: 26 Jul 2003, 02:00
Location: Randburg

Re: How to remove viruses from shadowcopy?

Post by Belix »

does not seem to be, seems to point straight to the shadow copy.
Weird thing, like I say is that shadowcopy is disabled...
The location of the virus is given as \\.\GLOBALROOT\Device\HarddiskVolumeShadowCopy14\Shares\read\Programmes\....
Trying a full system scan to see if I can figure out anything, but can't imagine it would be able to delete the virus files any easier.

Also have notice that the number of the ShadowCopy number keeps changing...it was ShadowCopy4 earlier today.
    
| Intel C2D E7300 | Asus Striker Extreme | CL X-Fi ME | Asus 8800GTS | Aopen 700W |
| 2*Seagate 1TB Raid | Samsung 2232GW 22" LCD | Team Extreem 2GB DDR2 800 |
Anakha56
Forum Administrator
Posts: 22136
Joined: 14 Jun 2004, 02:00
Processor: Ryzen 1700K
Motherboard: Asus X370
Graphics card: Asus 1060 Strix
Memory: 16GB RAM
Location: Where Google says

Re: How to remove viruses from shadowcopy?

Post by Anakha56 »

Ah I had this problem some time ago and we seemed to have solved it. However the link with the instructions is at work, I will only be at work at about 18:30...
JUSTICE, n A commodity which is a more or less adulterated condition the State sells to the citizen as a reward for his allegiance, taxes and personal service.
Anakha56
Forum Administrator
Posts: 22136
Joined: 14 Jun 2004, 02:00
Processor: Ryzen 1700K
Motherboard: Asus X370
Graphics card: Asus 1060 Strix
Memory: 16GB RAM
Location: Where Google says

Re: How to remove viruses from shadowcopy?

Post by Anakha56 »

http://www.nerdparadise.com/blogs/omnipotententity/239/

Belix that solved my virus hidden in shadow copies. Good luck! :)
JUSTICE, n A commodity which is a more or less adulterated condition the State sells to the citizen as a reward for his allegiance, taxes and personal service.
Belix
Registered User
Posts: 3719
Joined: 26 Jul 2003, 02:00
Location: Randburg

Re: How to remove viruses from shadowcopy?

Post by Belix »

Will try it tomorrow, thanks mate!
    
| Intel C2D E7300 | Asus Striker Extreme | CL X-Fi ME | Asus 8800GTS | Aopen 700W |
| 2*Seagate 1TB Raid | Samsung 2232GW 22" LCD | Team Extreem 2GB DDR2 800 |
Anakha56
Forum Administrator
Posts: 22136
Joined: 14 Jun 2004, 02:00
Processor: Ryzen 1700K
Motherboard: Asus X370
Graphics card: Asus 1060 Strix
Memory: 16GB RAM
Location: Where Google says

Re: How to remove viruses from shadowcopy?

Post by Anakha56 »

Not a problem, hope it works for you :).
JUSTICE, n A commodity which is a more or less adulterated condition the State sells to the citizen as a reward for his allegiance, taxes and personal service.
Belix
Registered User
Posts: 3719
Joined: 26 Jul 2003, 02:00
Location: Randburg

Re: How to remove viruses from shadowcopy?

Post by Belix »

weird, tried the command vssadmin as per the article, and it comes back "No items found that satisfy the query"...
    
| Intel C2D E7300 | Asus Striker Extreme | CL X-Fi ME | Asus 8800GTS | Aopen 700W |
| 2*Seagate 1TB Raid | Samsung 2232GW 22" LCD | Team Extreem 2GB DDR2 800 |
Post Reply