What W7 Processes Create Shadow Copy?

Foreman

New member
Local time
12:55 PM
Messages
2
What processes or services does Windows 7 Home Premium use to create a HarddiskVolumeShadowCopy? I know that W7 backup does this but are there other automated W7 processes that do this? Is there any way to disable these or make them manual?

I have a problem with NIS 2011 alerting to a possible Boot.Bootlock.B infection with an identified file of HarddiskVolumeShadowCopy#.

This initially blocked the W7 backup early in the process and manually running W7 backup reproducibly produced the NIS 2011 block and alert.

I was able to complete the W7 backup successfully by shutting off NIS 2011 and turned off backup. However, I still get the same alert about once after booting. I suspect this is some other W7 restore or backup function that is running automatically but would like to confirm this and, if possible, either turn it off or make it a manual process rather than automatic.

I think this is a false positive alert because I have run several AV scans (NIS 2011, MalwareBytes, TDSSKiller, esagelab Bootkit Remover) that don't find anything. The NIS 2011 claims to have removed the file but doesn't put anything in quarantine.

Using Windows 7 Home Premium SP1 fully updated

Appreciate any help on this.

Thanks.

Foreman
 

My Computer

OS
Windows 7 Home Premium 32bit

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Jacee,

Thanks. I've already posted in the Norton forum. My question here is what W7 processes could automatically create a W7 HarddiskShadowCopy other than Backup. I think the answer may be system restore. I can get the detect by manually creating a restore point. I just would like to confirm that W7 can run this automatically and how to disable this.

Thanks.

Foreman
 

My Computer

OS
Windows 7 Home Premium 32bit

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Hello Foreman, and welcome to Seven Forums.

Shadow copies (previous versions) is a part of System Protection in Windows. System Protection is also responsible for restore points. If system protection is turned on for your Windows 7 drive, then Windows will automatically create previous versions and restore points on a scheduled task, and when you manually create a restore point and backup.

Here are some tutorials that can help explain shadow copies, restore points, and system protection in more detail if you like.

Hope this helps some,
Shawn
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self built custom
OS
64-bit Windows 11 Pro for Workstations
CPU
Intel i7-8700K OC'd to 5 GHz
Motherboard
ASUS ROG Maximus XI Formula Z390
Memory
64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz
Graphics Card(s)
ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Sound Card
Integrated
Monitor(s) Displays
2 x Samsung Odyssey G7 27"
Screen Resolution
2560x1440
Hard Drives
1TB Samsung 990 PRO M.2,
4TB Samsung 990 PRO PRO M.2,
TerraMaster F8 SSD Plus NAS
PSU
Seasonic Prime Titanium 850W
Case
Thermaltake Core P3
Cooling
Corsair Hydro H115i
Keyboard
Logitech wireless K800
Mouse
Logitech MX Master 4
Internet Speed
2 Gb/s Download and 100 Mb/s Upload
Antivirus
Malwarebyte Anti-Malware Premium
Browser
Google Chrome
Other Info
Logitech Z625 speaker system,
Logitech BRIO 4K Pro webcam,
HP Color LaserJet Pro MFP M477fdn,
APC SMART-UPS RT 1000 XL - SURT1000XLI,
Galaxy S23 Plus phone
Back
Top