Document ID:2000092513515106
Last Modified:08/30/2002
Cannot repair, quarantine, or delete a virus found in the
_RESTORE or System volume information folder
Situation:
Norton AntiVirus (NAV) has detected a virus in the _RESTORE or the
System volume information folder, but it cannot repair, quarantine, or
delete the infected file.
Solution:
One of the new features of Windows Me and Windows XP is System
Restore. This feature, which is enabled by default, is used by Windows to
restore files on your computer in case they become damaged. Windows
Me keeps the restore information in the _RESTORE folder. Windows XP
stores this information in the System volume information folder. These
folders are updated when the computer restarts.
If the computer is infected with a virus, then it is possible that the virus
could be backed up in the _RESTORE or System volume information
folder. By default, Windows prevents System Restore from being
modified by outside programs. Because of this, any repair attempts made
by Norton AntiVirus will fail. To work around this, you must disable
System Restore, and restart the computer. This will purge the contents of
the _RESTORE or System volume information folder. You must then run
a full system scan.
To disable System Restore:
Follow the steps that apply to your operating system:
Windows Me:
1. Close all open programs.
2. Right-click My Computer on the Windows desktop, and then click
Properties.
3. Click the Performance tab.
4. Click File System.
5. Click the Troubleshooting tab.
6. Check Disable System Restore, click OK, and then click Close.
7. Click Yes to restart. This disables the System Restore feature and
will purge the contents of the _RESTORE folder when the system is
restarted.
8. Run LiveUpdate and download the latest virus definitions.
9. Make sure that NAV is set to scan all files and all drives, and then
scan the computer.
10. After cleaning the infected files, repeat steps 1 through 7, except
in step 6, uncheck Disable System Restore.
(skip the nav part if you don't have nav, or substitute it with your av software)