Files "Locked" and Cannot Backup or Delete After Malware Incident

Page 1 of 2 12 LastLast

  1. Posts : 239
    10
       #1

    Files "Locked" and Cannot Backup or Delete After Malware Incident


    Hi, I recently had a malware incident that forced me to restore a system image - however, I failed to realize that restoring the system image would not restore data stored in C:\Users\myname

    Once the system image was restored and I realized that I should probably include this Users folder in my daily mirror backup (using FreeFileSync), I ran the backup but 77 files generated a "Cannot Read File" error when trying to back them up. It also says "The file is locked by another process: System."

    I may be wrong to think this, but I suspect that the malware that was launched somehow created these unecessary files or locked them down. I would like to delete them if they are not required.

    Some of the files are .dat, dat.LOG1, .dat.LOG2, .log, .bin, .edb, .toc, .jfm, .jtx
    most are either locked by "System" and/or "Registry". Others are locked by various WindowsApps, System32, or Google Chrome processes.

    I'm attaching a few screenshots here... but like I said, there are 77 files so I won't put them all here.
    I'm assuming it is recommended to backup the entire C:\Users\myname folder and that this is not normal.
    Please advise...

    Files "Locked" and Cannot Backup or Delete After Malware Incident-2019-08-14_19-46-44.jpg

    Files "Locked" and Cannot Backup or Delete After Malware Incident-2019-08-14_20-25-27.jpg

    Files "Locked" and Cannot Backup or Delete After Malware Incident-2019-08-14_21-41-12.jpg

    Files "Locked" and Cannot Backup or Delete After Malware Incident-2019-08-14_20-28-23.jpg

    Files "Locked" and Cannot Backup or Delete After Malware Incident-2019-08-14_21-38-55.jpg
      My Computer


  2. Posts : 8,057
    windows 10
       #2

    Thats files your trying to backup yes? All will be locked as they are in use nothing to do with malware
      My Computer


  3. Posts : 239
    10
    Thread Starter
       #3

    Samuria said:
    Thats files your trying to backup yes? All will be locked as they are in use nothing to do with malware
    Really? So ... no way to backup the data in my Users folder without hitting this prompt 77 times? Certainly people must be backing up their User folder?
      My Computer


  4. Posts : 8,057
    windows 10
       #4

    Using a backup programe you can do it as that runs different and locks files while it backus up. Or you can back it up from another account as then it wont be in use
      My Computer


  5. Posts : 239
    10
    Thread Starter
       #5

    What do you mean by :
    Samuria said:
    Using a backup programe you can do it
    I am using the backup program called Free File Sync...
      My Computer


  6. Posts : 14,046
    Windows 11 Pro X64 22H2 22621.1848
       #6

    Use Macrium Reflect Free (or Premium) and start making image backups of the entire drive to an external hard drive. I schedule a full backup of the drive then do incrementals for the next couple months. This is done once a week. That reduces the size of the backups considerably. Then I swap out the drive and start over, keeping the previous until it's time to swap again. This gives me several months worth of backups which is sufficient for me.

    That way you lose nothing and if the hard drive ever dies or gets corrupted you replace it, restore the latest image and in 20-30 minutes you're up and running again at the exact point you were at when the image was created.

    Programs like Free File Sync are great for backing up volatile files that change a lot between your image backups. I use Mirror Folder for the same purpose. That way you can restore the image, then copy the additional saved files over the restored backup and you should be right where you were before any problem occurred.
      My Computers


  7. Posts : 239
    10
    Thread Starter
       #7

    Ztruker said:
    Use Macrium Reflect Free (or Premium) and start making image backups of the entire drive to an external hard drive.
    I do this as well. My point is that when I restored the image on C drive (Macrium), it seemed like it did not restore the Users folder to pre-malware infection. But that was likely because I assumed that the 77 errors that were generated after I decided to include the Users folder in my data backup (FreeFileSync) were locked as a result of malicious software having been deployed on my system before I cleaned it up. But it sounds like those files should be there and not be deleted, and that it it normal for them to appear "locked" when I try to include them as part of my daily mirror strategy on FreeFileSync.

    So it sounds like I should leave those 77 files alone - and not try to delete them. It also sounds like the entire Users folder should be part of the system image I backup using Macrium every month or so.

    So maybe what I can do instead of including the entire Users folder in my FreeFileSync daily mirror is just the "Downloads" and "Documents" subfolders, as nothing will be locked down there by the system, and the data in these changes often.

    I have not dabbled with "incremental backups" yet in Macrium... they scare me. I just do a full new image, and then delete the previous one (or second last one).
      My Computer


  8. Posts : 14,046
    Windows 11 Pro X64 22H2 22621.1848
       #8

    You can browse Macrium backup images. In File Explorer, just navigate to where they are stored, pick the one you want, right click and select Explore Image. You will be able to see what is in the image, including the files and folders you are interested in.
      My Computers


  9. Posts : 4,752
    Windows 11 Pro 64 Bit 22H2
       #9

    When you choose to do an Image file, you should choose to do an Image of the whole HDD, including any other partitions like the hidden System Files partition, which includes the Boot files. Even if you only choose to make an image of the C: drive, it will include your User files as they are in the root of the C: drive. If your image is several months old, you will only get the User files from that date the image was taken.
      My Computer


  10. Posts : 239
    10
    Thread Starter
       #10

    Ztruker said:
    You can browse Macrium backup images. In File Explorer, just navigate to where they are stored, pick the one you want, right click and select Explore Image. You will be able to see what is in the image, including the files and folders you are interested in.
    So technically, I COULD restore only the Users folder part if the system image if there was a problem there? I always thought I had to restore the entire disk image...
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 03:19.
Find Us




Windows 10 Forums