[SOLVED] Question about shadow copies

Szeska837

Commendable
Apr 20, 2021
27
0
1,530
Hi,

my older laptop still runs win 7 (I know I should switch, but not sure if it can handle it) and I have a question about shadow copies. I decided to run the "vssadmin list shadows" command and apparently I have 2 "ApplicationRollback" shadow copies from 2015. Every other shadow copy is from 2022 and they are listed as "ClientAccesibleWriters". The originating machine, service machine and provider are all the same (originating and service machine is my laptop and provider is Microsoft Software Shadow Copy Provider 1.0).
My question is, the copies from 2022 have the C: drive listed as their original volume, but the ones from 2015 don't have any drive letters associated to them.
The ones from 2022 show: <C:>\\?\Volume{......}\
The ones from 2015 show: <\\?\Volume{......}\>\\?\Volume{......}\ (I think they are listed together)
The dots are the volume ID's, didn't want to list the full thing.

Any idea why the one from 2015 have no drive associated with the original volume? Also, I can restore the ones from 2022, but the ones from 2015 are not listed.
 
Last edited:

Szeska837

Commendable
Apr 20, 2021
27
0
1,530
Because this particular volume has no drive letter assigned. Not every volume needs a drive letter.
Check Disk Management.
Will do later, hope it will help. So you think the copies are stored on that drive?

I also heard, that "ApplicationRollback" copies are generated by 3rd party applications, but I don't remember ever using one and the provider is the same as the new ones.
Also the System Volume Information folder takes up a lot of space, around 65 GB (checked it in TreeSize). I think it's most likely the shadow copies on the drive.
 
System Volume Information folder holds System Restore points.
You can configure amount of disk space allowed for Restore points.

 
Last edited:
  • Like
Reactions: Szeska837
Solution

Szeska837

Commendable
Apr 20, 2021
27
0
1,530
Thought so, thanks.

I'm mostly worried about the 2015 copy saved to some web server, not sure why it was created. The Shadow Copy Volume is the same as the others: \\?GlobalRoot\Device\...