cancel
Showing results for 
Search instead for 
Did you mean: 

How to remove malware from shadow copies?

Jump to solution

Hi everybody.

ENS detected and removed malware for this path:

\Device\HarddiskVolumeShadowCopy111\%Folder%\%malware.exe%

And this malware all time appears again only for one server.

So, as I understand I need to remove this malware from shadow copies. And I have a few questions:

1) It's okay to remove shadow copies from infected machines or not? Because, ENS all time removing malware from shadow copies, but this file appears again. So, this file comes from another location, or not?

Command: vssadmin delete shadows /all

2) How to determine from where this file coming with this path that I wrote above?

1 Solution

Accepted Solutions
Highlighted
Reliable Contributor ninov_n
Reliable Contributor
Report Inappropriate Content
Message 2 of 2

Re: How to remove malware from shadow copies?

Jump to solution

Hello

1) It depends but usually these are being replicated or synchronized making them reappear again. Once you find the source it is fine to remove the file in question.

2) You can use diskpart to list local disks and volumes to find out exact location. Check this article: article

 

In case above information was useful or answered your question, please select "Accept as Solution" in my reply, or give a Kudo. Thanks!
Nino
1 Reply
Highlighted
Reliable Contributor ninov_n
Reliable Contributor
Report Inappropriate Content
Message 2 of 2

Re: How to remove malware from shadow copies?

Jump to solution

Hello

1) It depends but usually these are being replicated or synchronized making them reappear again. Once you find the source it is fine to remove the file in question.

2) You can use diskpart to list local disks and volumes to find out exact location. Check this article: article

 

In case above information was useful or answered your question, please select "Accept as Solution" in my reply, or give a Kudo. Thanks!
Nino