How to remove an infected file in the folder SYSTEM VOLUME INFORMATION on T43?

Respected Sir/Madam,

Recently, I have bee affected by a series of blue screen errors. Norton AntiVirus and other well-known software just crash. Update of virus definitions files are reported as being corrupted. Fortunately, I used this SPYWARE DOCTOR which founf a file infected by HACKIT name. ROOTKIT in the SYSTEM VOLUME INFORMATION folder, which is hidden from the usual interface of WINXP.

Please suggest some methods on how to DELETE the infected on this hidden folder?


pleas suggest alternative methods to get rid of this infection.

Thank you!

SYSTEM VOLUME INFORMATION is your Restore.As system an alternative to do a factory restore, try flushing the system restore, then you can start fresh. This procedure will not delete your saved data and apps like restoration to the State of the plant would be.

In order to remove the XP System Restore Points:
(On XP, you must be logged in as an administrator to do.)
Go to start > run and type msconfig and press ENTER.
When opens in msconfig, click Launch System Restore.
On the next page, click System Restore settings on the left.
Check the box enable the system restore.

Reset. Reassemble and turn on system restore. A new Restore Point is created.

So, if you still have problems, it would mean that you have active running malware, or you have run at the same time a scanner that was falsely reported as this file, please come back. Often our malware removal tools are captured by General scanners as "Hacktools.

Tags: Lenovo Products

Similar Questions

  • How can I transfer a file from the operating system to a backup of the production running VM virtual machine?

    Problem:  After I do a backup one using ghettoVCB on a local VMFS volume, I have a virtual machine that I can start something happened to that running.  However, sometimes I just need a file from the OS level, which means that I would need to start to get them, but then I have an IP address conflict.  I can't imagine a way to have the NICs turned off and still be able to move the file.  If I change the IP addresses, the software that I need to create the file that I need to transfer no longer works because, although there no need of constant connectivity to the seller, it is locked to the public IP address.

    Material:  I have two 4 ESXi hosts to work, each with local VMFS volumes.  They share a private vlan common and a vlan common public.  They each ssh, ftp, wput, wget, and rsync available.  I have a Windows 2003 Server VM which also hosts a NFS and the VI client and other VMWare tools.  It also has private and public interfaces as do virtual machines that would be to make and receive the OS files.

    Question:  How can I transfer a file from the operating system to a backup of the production running VM virtual machine?

    Thank you!

    Yes Mr President, make sure you set the network on this virtual machine to be connected to the 'Internal' vswitch, you set up before turning the power on to the virtual machine.


  • When I boot computer I get this message... Remove the c:/System Volume Information directory. EFaDATA\SYMEFA. DB-log is corrupted and unreadable

    Original title: damaged and unreadable

    When I boot computer I get this message... Remove the c:/System Volume Information directory. EFaDATA\SYMEFA. DB-Journal is damaged and unreadable... How to fix this?

    Thank you very much for your help.
    I discovered the new external hard drive was the problem. Formatted as NTFS seems to be a problem so I reformatted to FAT and the problem disappeared.
    The error message was: the journal of System Volume Information EfaData SYMFA DB file or directory is corrupted and unreadable.

    Thanks again.

  • I have windows Vista Home Basic, but my system was infected by viruses as recyclebin, System Volume Information. Wat to do how to get rid of this...

    Dear friends,

    (1) I have the windows Vista Home Basic, but my system was infected by viruses as recyclebin, System Volume Information. Wat to do how to get rid of it.

    (2) I want to format my laptop, but the problem is that I'm not having Windows Vista Home Basic Formate how about this disk, please help me in this respect... How can I procedures...

    (3) if I install the new Vista there will be no problem for my laptop... it

    $Recycle.bin and System Volume Information are important Windows that are normally hidden system files. Why do you think they are viruses?

  • Formatting the USB in Windows XP disk, create a folder "system volume information" How can I overcome this problem

    Hello team, I tried to format my 2 GB to Format NTFS USB in WINDOWS XP. When I format the drive, it has been formatted sucssfully, but in the formatted disk, a folder is created named as 'System Volume Information '. I tried to remove my USB drive safley but it show and error as "the generic Volume is used in another program... '. ».  Why this happens, the 'System Volume Information' folder is a virus? How can I fix this problem... reply me as soon as possible... Thank you all...


    It does seem like a virus. Since you're a NTFS format, it should be a system folder. System folder is present on NTFS volumes and is used for system restore points.

    If you want to remove, you may need to format the drive to FAT32.

    See also:

    Access to the System Volume Information folder;en-us;309531

  • Cannot delete the folder to the windows system volume information 7.

    I can not delete system volume information folder in D: / E: / Windows 7

    I took possession as administrator on the folder, but I can't remove it completely!

    I start a command prompt and deleted some of the files it contains, but can't delete the folder!

    In vista, I could eat to remove after that ownership on the folder by pressing Delete the folder will disappear!

    any ideas?

    don't ask me why I'm trying to delete the folder pls... I just need to

    Thank you

    Old post I know but I had this problem on several of my removable HDs, and finally I managed to remove the 'System Volume Information' folder:


    Right click on desktop, and then click [New-> shortcut]
    Write: cmd.exe

    Click [next] and then click [finish]

    Right click on cmd.exe icon, and then click 'run as administrator'
    Now select the external hard drive (f: in my case)


    Yes now the following (you can copy paste):
    F:\>attrib s h/s/d
    F:\>attrib - r/s/d
    F:\>Rd "System Volume Information" / s
    Are System Volume Information, you sure (Y/N)? There

    And you're DONE ;-)

  • How to put pictures of file to the folder in windows 7

    Images, I want to move image files in a folder.  How do I in a way much less time creating a folder, then drag each picture in it?  400 photos take forever!  I'm a novice at this business of the computer.

    After using a keys ctrl + together if you want to deselect multiple files to the list of list or a folder that also got selected with select all methods,.

    Hold down the CTRL key again and left click, the files or folders or point your Cruiser files (depending on how your mouse is put in place to select the files), you don't want to move or copy to the new folder.

    Make a right click dragging you offers four choices, move to / copy / create a shortcut for / and cancel.

  • How to save a pdf file in the folder my documents when you are printing from Explorer?

    I often need to print Web pages to PDF and save them in the folder my documents.  Until a few weeks ago, it was no problem.  About three weeks ago I started getting the following error message every time I print a Web page in Internet Explorer when the selected printer is Adobe PDF and when I try to save to the folder my documents: when printing to PDF on a Web page in Internet Explorer, I can not save to my documents folder.  I have an error message "you don't have permission to save in this location. Contact the administrator for approval. "Now, I must save the new pdf to my desktop and then transfer it to the documents folder, which is a waste of time and that clutters my office.  How can I fix it?

    This problem does not occur when printing to pdf from other browsers, but I have to use some Web sites that work best with Explorer.  Even if in the Solution Explorer, I can print to the Microsoft XPS Document Writer, and save the document to the my documents folder without this error message.

    OS is Windows 7

    11 the Explorer

    Adobe Acrobat Pro X

    Try disabling Internet Explorer protected mode and let us know if that suits him.

    To disable the protected mode:

    1. open Internet Explorer

    2 - go to the top gear icon on the right

    3 - click on Internet Options

    4. under the security"" tab.

    5. uncheck the box that says "Enable Protected mode"

    6. click on apply and OK

    Thank you!

  • How to remove "Ghost Audio Files" on the iPhone 6 s, iOS iTunes 12.3.3 9.3.1

    I have a Windows PC with iTunes 12.3.3 (latest version) and iOS iPhone 6s 9.3.1

    Struggled recently with iTunes think I have music on my iPhone when I don't really have the music on my phone, where the name "ghost files". I tried several other sites have suggested to do such as:

    • Download iFunbox and deleting files ghost
    • Delete all the music on the iPhone via settings > general > use > music and remove all the
    • Reset iPhone, worked, but only temporarily
    • Using another cable from Apple lightning
    • Download and run iExplorer

    Also posted a topic before, that brought me to the awareness that the audio files are on my iPhone but not appearing is not in the music app. Please read through this topic, I gave a lot of General information here that's not going to be written on this topic.

    So I just spent the last 2 hours synchronize music on my iPhone and just got "erased".

    I checked iTunes my iPhone Summary tab at the bottom, and it shows all the data for the files of music, which is very weird. I have since tried the music I want on my phone via iTunes, but it is not just sync to sync. iTunes behaves as if the files are already on my iPhone.

    A final problem that can have an impact on the music that is on iTunes next not all but some of the songs that I used on my iPhone have a! on the inside of a circle to the left of the song.


  • How to remove .wlmp (project) files in the list of Movie Maker?

    I want to remove previously saved projects (.wlmp files) that are in my project list.

    In search of regedit.exe for part of the name of one of the project files you're looking for. Here is what I get in less than a minute when I search my registry for 'southhaven', a project I did last night.

  • How can I move my files and the operating system on a new hard disk on Inspiron 580 s.

    My hard drive failed Diagnostics recently and needs to be replaced.  I have since installed a new hard drive in Bay 2. I need to move everything from the old drive to the new drive and delete the old which is completed. So what is the best way to go about this?


    The simplest method, I prefer to install a replacement hard drive, is to clone the existing hard drive to the new, that will also transfer all applications and programs.

    You need an imaging utility, similar to True Image Home 2015.

    Acronis resize partitions transferred to match the size of the new hard drive.

    Hard drive manufacturers, also have their own free cloning software available, but it can be used only with their hard drives.

    First, install the new drive as the secondary and the image of the main hard drive in it.

    Immediately after the cloning, shut down the system, switch the data cable [SATA port 0] to the new disk, making the new master hard drive and see if the system boots properly.

    Start the system with only the new hard drive connected.

    Be sure to leave the original drive disconnected, until the new hard drive is working to your satisfaction.

    Before cloning a hard drive, make sure that the existing drive has no corruption or virus on it, because they will be transferred to the new hard drive.

    It will take a second SATA data cable, there should be a spare connector to SATA power inside the housing.


  • Windows - message of corrupted file the file or directory c:\System Volume Information\_restore{106cf321-99A3-4E3A-9103-1BD02760-6A99}\rp687 is damaged and unreadable.

    the Information\_restore{106cf321-99A3-4E3A-9103-1BD02760-6A99}\rp687 Volume of c:\System file or directory is corrupted and unreadable. Run the chkdsk utility. I tried to run chkdsk but it does not work. I can't start the defragmentation either. I tried to run chkdsk on a restart and it does not start in safe mode it is running in read-only and shows errors but does not fix the

    You must run chkdsk with the "/ r", and/or switches 'f' for the errors to fix.

  • Windows 7: what are the individual "file system type" files in the system volume information folder?

    Original title: Windows 7: what are the individual "file system type" files in the folder system volume information accumulating [not the files system restore I already know and don't use yet]


    I stopped using the system restore, I found a better solution, for me, that's what I have to do.
    Then I noticed that several 'file system' 'type' was being created, 12 times yesterday, 3 up to today in the early hours of the morning and stored in they System Volume Information folder, anywhere from 30 MB to 2 GB.
    three of these file names 'file system' 'type' are:
    {debb21da-eafc-11e2-ba92-00241dc5d84e} {3808876b-c176-4e48-b7ae-04046e6cc752}
    {3debe675-eaa7-11e2-a462-00241dc5d84e} {3808876b-c176-4e48-b7ae-04046e6cc752}
    {3debe5e8-eaa7-11e2-a462-00241dc5d84e} {3808876b-c176-4e48-b7ae-04046e6cc752}
    Anyone know what it could be?
    Can I follow up to what program/process they are related?
    Are they safe to delete?
    Ideas?  Suggestions?
    Thank you.

    Hi John,.

    Yes, you can delete the system volume information data if not to use the system restore.

    You will need to give permission to the folder until you delete it.

    How to open a file if I get an access denied message?

    Please post with the State of the question.

  • delete personal saved files in the system volume information.

    recently, I saved a few personal secret files in the information system volume with the intention to hide other users. now when I try to delete this file, I can't delete. Please help me with detailed instructions to delete this file without affecting other files in the SVI. Thank you

    Hi Lokhojohn,

    Right click on the folder "System Volume Information"
    1 Select 'Properties' and then click on the 'Security' tab in the next dialog box
    2. click on 'Edit' and then on the button 'Add '.
    3. put in your user name in the following box and click on 'OK '.
    4. This will grant access to the folder "System Volume Information" username
    Then click on the "Start" button and then in the "Run" box (the box with the magnifying glass"at the bottom of entry the following entry and press on)
    Once the Windows CMD appears, type in the following commands:
    CD "C:\System Volume Information.
    del "I want to file delete.txt".
    Who's going to get rid of one of the files to delete
    Continue the above command for all the files you want to delete.
    A good tip is that you can actually drag the files you want to delete in the CMD window to save typing you the full name. Enter del in the CMD followed by a space, and then drag the file that you want to remove in the CMD window and it will automatically add the name of the file for you.
    Follow steps 1 through 4, once more when you're finished - but this time remove your username
    Hope this helps
  • System Volume Information folder 23 GB even when system restore is turned OFF. All backups shadow removed

    Dear users,

    I am facing a very strange problem and I tried to solve this problem for more than a month, but no use. I called the Support technique Microsoft in India and they send me the details to email customer support to get this addressed redirected.

    QUESTION to the folder System Volume Information in Windows 7 is 23 GB of my SSD. My SSD capacity is 120 GB. If this space takes more than 20% of my total space of SSD.

    I turned off the system restore feature and it is noted below.

    The system restore is turned off as shown below

    Space Ghost maximum allocated memory is about 500 MB. There is no current backup shadow


    I'll have a 120 GB SSD and more than 20% of the space is getting lost here

    I am running Windows 7 Professional 64 bit on a Dell E6220 laptop

    No virus / Trojan horses and system completely clean. Looking for Solutions...

    Run the Disk Cleanup Wizard (be sure to include system files)

Maybe you are looking for