Hi folks
Sophos antivirus is picking up some viruses stuck away in shadowcopy4 on the SBS2003 server. Unfortunately it cannot remove them or move them to quarantine. I've checked under computer management and shadow copies seem to be disabled. I've also tried using wmic at command prompt and typed in shadowcopy, to which is replies No Instance(s).
Is there a way to manually see the shadowcopy folder and delete it? Some other way?
Thanks guys!
How to remove viruses from shadowcopy?
How to remove viruses from shadowcopy?
| Intel C2D E7300 | Asus Striker Extreme | CL X-Fi ME | Asus 8800GTS | Aopen 700W |
| 2*Seagate 1TB Raid | Samsung 2232GW 22" LCD | Team Extreem 2GB DDR2 800 |
Re: How to remove viruses from shadowcopy?
have you tried using another antivirus to scan and clean?
- rustypup
- Registered User
- Posts: 8872
- Joined: 13 Dec 2004, 02:00
- Location: nullus pixius demonica
- Contact:
Re: How to remove viruses from shadowcopy?
shadow copy is read only... nothing, aside from disabling, is supposed to delete them..3ddy wrote:have you tried using another antivirus to scan and clean?
@Belix: any chance the error message is pointing to a volume copy of your quarantine folder?
Most people would sooner die than think; in fact, they do so - Bertrand Russel
Re: How to remove viruses from shadowcopy?
does not seem to be, seems to point straight to the shadow copy.
Weird thing, like I say is that shadowcopy is disabled...
The location of the virus is given as \\.\GLOBALROOT\Device\HarddiskVolumeShadowCopy14\Shares\read\Programmes\....
Trying a full system scan to see if I can figure out anything, but can't imagine it would be able to delete the virus files any easier.
Also have notice that the number of the ShadowCopy number keeps changing...it was ShadowCopy4 earlier today.
Weird thing, like I say is that shadowcopy is disabled...
The location of the virus is given as \\.\GLOBALROOT\Device\HarddiskVolumeShadowCopy14\Shares\read\Programmes\....
Trying a full system scan to see if I can figure out anything, but can't imagine it would be able to delete the virus files any easier.
Also have notice that the number of the ShadowCopy number keeps changing...it was ShadowCopy4 earlier today.
| Intel C2D E7300 | Asus Striker Extreme | CL X-Fi ME | Asus 8800GTS | Aopen 700W |
| 2*Seagate 1TB Raid | Samsung 2232GW 22" LCD | Team Extreem 2GB DDR2 800 |
-
- Forum Administrator
- Posts: 22136
- Joined: 14 Jun 2004, 02:00
- Processor: Ryzen 1700K
- Motherboard: Asus X370
- Graphics card: Asus 1060 Strix
- Memory: 16GB RAM
- Location: Where Google says
Re: How to remove viruses from shadowcopy?
Ah I had this problem some time ago and we seemed to have solved it. However the link with the instructions is at work, I will only be at work at about 18:30...
JUSTICE, n A commodity which is a more or less adulterated condition the State sells to the citizen as a reward for his allegiance, taxes and personal service.
-
- Forum Administrator
- Posts: 22136
- Joined: 14 Jun 2004, 02:00
- Processor: Ryzen 1700K
- Motherboard: Asus X370
- Graphics card: Asus 1060 Strix
- Memory: 16GB RAM
- Location: Where Google says
Re: How to remove viruses from shadowcopy?
http://www.nerdparadise.com/blogs/omnipotententity/239/
Belix that solved my virus hidden in shadow copies. Good luck!
Belix that solved my virus hidden in shadow copies. Good luck!
JUSTICE, n A commodity which is a more or less adulterated condition the State sells to the citizen as a reward for his allegiance, taxes and personal service.
Re: How to remove viruses from shadowcopy?
Will try it tomorrow, thanks mate!
| Intel C2D E7300 | Asus Striker Extreme | CL X-Fi ME | Asus 8800GTS | Aopen 700W |
| 2*Seagate 1TB Raid | Samsung 2232GW 22" LCD | Team Extreem 2GB DDR2 800 |
-
- Forum Administrator
- Posts: 22136
- Joined: 14 Jun 2004, 02:00
- Processor: Ryzen 1700K
- Motherboard: Asus X370
- Graphics card: Asus 1060 Strix
- Memory: 16GB RAM
- Location: Where Google says
Re: How to remove viruses from shadowcopy?
Not a problem, hope it works for you .
JUSTICE, n A commodity which is a more or less adulterated condition the State sells to the citizen as a reward for his allegiance, taxes and personal service.
Re: How to remove viruses from shadowcopy?
weird, tried the command vssadmin as per the article, and it comes back "No items found that satisfy the query"...
| Intel C2D E7300 | Asus Striker Extreme | CL X-Fi ME | Asus 8800GTS | Aopen 700W |
| 2*Seagate 1TB Raid | Samsung 2232GW 22" LCD | Team Extreem 2GB DDR2 800 |