Thursday, April 22, 2010

System Volume Information folder it taking up too much space

If you System Volume Information folder grows too large and is taking up too much space, you can get these files safely cleaned out.

In Windows XP:

Right-click on My computer and click on Properties.  In System Properties click on the System Restore tab.  Here you an adjust the disk space used for System Restore.  If you need the space and do not need the saved restore points just check the box to turn off System Restore, click OK.  You will get a warning that all existing Restore Points will be deleted.  Click Yes if you do not need them.  The System Volume Information folder should be cleared out and disk space recovered.

In Server 2003:

I encountered this problem in a Windows Server 2003 box when the Backup Exec jobs were not completing successfully.  The System Volume Information folder grew to over 90GB. All I had to do was stop and start the Volume Shadow Copy service. All of the temp files were gone after the service started up again.

If this did not work for you then you could manually delete these files when the Volume Shadow Copy server is stopped.

http://seer.support.veritas.com/docs/269989.htm

In Windows 7:

Right-click on My computer and click on Properties. Click on Advanced System Settings from the left side.  In System Properties click System Protection.  Then click Configure.  Here you can adjust the disk space used for system protection.  You can also Delete all restore points.

Wednesday, March 10, 2010

Manual removal of malwares [sftav, sysguard, aabxam, and avscan

Disable LAN

  1. If possible, kill the following processes in Task Manager:

a. [RANDOM CHARACTERS]sysguard.exe, for example ghrtsysguard.exe

b. [RANDOM CHARACTERS]sftav.exe

  1. Remove These Registry entries:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[random characters]"

HKCU\Software\Microsoft\Windows\CurrentVersion\Run "[random charaters]"

HKCU \Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = "1"

HKCU \Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:5555"

HKCU \Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = ".exe"

HKCU\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1"

HKCU \Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = ""

HKCU \Software\AvScan

  1. Search and Remove These Files

%UserProfile%\Local Settings\Application Data\[random characters]\

%UserProfile%\Local Settings\Application Data\[random characters]\[random characters]sysguard.exe

%UserProfile%\Local Settings\Application Data\[random characters]\[random characters]sftav.exe

  1. Search registry for the following keywords (Note: You must use wildcards)
    1. *sftav*
    2. *sysguard*
    3. *aabxam*
    4. *avscan*
  2. Search computer for the following keywords
    1. *sftav*
    2. *sysguard*
    3. *aabxam*
    4. *avscan*
  3. Go to Internet Options à Connections tab à LAN Settings à Uncheck “Use proxy settings for your LAN…”

Thanks for the info RP!