Disk access to Virtual Store folder for no reason?

Carbonyl

New member
Power User
Local time
8:20 PM
Messages
76
Hi everyone. I've just got a quick question that's been bothering me for a while. Recently I've noticed some bizarre activity in Win 7 Professional. I run ESET NOD32 v4, and it shows a 'current activity' readout that displays whatever file is being scanned, and thus currently being accessed by the OS or a program. I was watching it while my system was idle, and suddenly it started to scan through the Virtual Store directory. Specifically, it starting to scan through all of my old IM logs from a legacy IM client (Trillian). Now, I haven't even opened that IM client in a week, and the logs it was scanning were over three months old and haven't been altered since.

I ran a scan with NOD 32 v4, Windows Defender, and MalwareBytes antimalware. All of these came back clean with no infections/intrusions detected... But I can't think of any reason why three-month old files from a program that hasn't been run in a week would be accessed at all, other than a rootkit virus or something hidden poking through my personal correspondence.

Is there some reason that Win 7 might be accessing these file for some other purpose? I don't have automatic backups set up, and it looked pretty specific that the disk activity leafed through that specific folder and then stopped dead without looking at anything else.

Any advice would be appreciated. Thanks.
 

My Computer My Computer

Computer Manufacturer/Model Number
Custom
OS
Windows 7 RTM
CPU
i7 920
Motherboard
eVGA x58 SLi
Memory
6 GB Patriot
Graphics Card(s)
eVGA GeForce 275 GTX
Sound Card
Soundblaster X-Fi Gamer
Monitor(s) Displays
Acer 225Tw
Hard Drives
WD 1 TB
PSU
Corsair 750 W
Case
Antec Twelve Hundred
Cooling
Stock
What application was scanning the logs?
 

My Computer My Computer

Computer Manufacturer/Model Number
Dell XPS 15 L502x
OS
Windows 7 Ultimate x64 SP1
CPU
Core i7-2670QM
Memory
8GB DDR3 PC3-10600
Graphics Card(s)
Intel HD Graphics 3000 + GeForce GT 540M
Screen Resolution
1920x1080
Hard Drives
1TB 5400RPM Seagate
I wasn't able to tell. My attention was on NOD at the time, and NOD doesn't list the program doing the accessing, unfortunately. I had process explorer open at the same time, so if I'm going to judge by CPU usage, the only other program that was using any cycles at that time was an instance of svchost.exe. I think. I'm not positive about that.

Periodically when my system is idle, I'll hear the disk scanning or seeking (just the normal chugging sound you hear when disk access is going on), but process explorer will show every program completely idle - so I'm not sure if something 'hidden' is accessing the disk.
 

My Computer My Computer

Computer Manufacturer/Model Number
Custom
OS
Windows 7 RTM
CPU
i7 920
Motherboard
eVGA x58 SLi
Memory
6 GB Patriot
Graphics Card(s)
eVGA GeForce 275 GTX
Sound Card
Soundblaster X-Fi Gamer
Monitor(s) Displays
Acer 225Tw
Hard Drives
WD 1 TB
PSU
Corsair 750 W
Case
Antec Twelve Hundred
Cooling
Stock
How old is your Windows 7 installation?
 

My Computer My Computer

Computer Manufacturer/Model Number
Dell XPS 15 L502x
OS
Windows 7 Ultimate x64 SP1
CPU
Core i7-2670QM
Memory
8GB DDR3 PC3-10600
Graphics Card(s)
Intel HD Graphics 3000 + GeForce GT 540M
Screen Resolution
1920x1080
Hard Drives
1TB 5400RPM Seagate
It could have been the disk defragmentation moving the files away from the inner edge.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Alienware Aurora ALX R4
OS
Windows 10 Pro (x64)
CPU
Intel Core i7-3930K (3.2GHz - 4.5GHz)
Motherboard
Alienware Aurora-R4 x79
Memory
4x Samsung 4GB PC3-12800 DDR3 (16GB 1600MHz)
Graphics Card(s)
Nvidia Geforce GTX 690
Sound Card
SteelSeries Siberia Elite
Monitor(s) Displays
Dell UltraSharp U3011
Screen Resolution
2560x1600
Hard Drives
Samsung 850 Pro 256 GB, Seagate 1TB Desktop Hybrid HDD, 2x Western Digital 4TB Green HDD
PSU
875W Some Dell PSU <.<
Case
Alienware Aurora ALX
Cooling
Custom Liquid Cooling (EK CPU & GPU blocks) dual EK 480RAD
Keyboard
Logitech G710+ Mechanical
Mouse
Logitech G700s
Internet Speed
Verizon Fios (50 mbps average)
Other Info
Server: Intel NUC D54250WYK: i5-4250U, 16GB, 256 GB mSATA, Windows Server 2012 R2
Could by the search engine indexing the text files so when you search for them you will find them quicker...
 

My Computer My Computer

OS
Windows 7
CPU
Intel P4 3.0 GHz @ 3.4 GHz
Memory
1GB
Graphics Card(s)
ATI RADEON X850XT PE
Monitor(s) Displays
17 BENQ LCD
Hard Drives
300 GB IDE (For Main OS)
500 GB SATA (For Extra Space)
PSU
400 Watt
Cooling
Stock
The Win 7 Pro installation is roughly two months old at this point.

Also, I'm inclined to think that it's not the search indexer - usually when the indexer is running and indexing actively it has two daughter processes going. This time, not only were there no daughter processes for the Search Indexer task, but it also wasn't using any CPU. Defragmentation might be a possibility, but the defrag program certainly didn't pop up - I've seen that happen before when idling, and this certainly didn't happen, unless svchost was running defrag directly without launching a daughter process.
 

My Computer My Computer

Computer Manufacturer/Model Number
Custom
OS
Windows 7 RTM
CPU
i7 920
Motherboard
eVGA x58 SLi
Memory
6 GB Patriot
Graphics Card(s)
eVGA GeForce 275 GTX
Sound Card
Soundblaster X-Fi Gamer
Monitor(s) Displays
Acer 225Tw
Hard Drives
WD 1 TB
PSU
Corsair 750 W
Case
Antec Twelve Hundred
Cooling
Stock
Back
Top