PDA

View Full Version : System Restore And Malware Infections


ggf31416
March 15th, 2007, 02:49 PM
(Windows XP built-in) System Restore creates backup copies of some extensions and the registry.
If a computer were infected, supposing that:
a) There is a restore point for a date prior to the infection
b) System Restore doesn't fail for reasons not related to the infection
c) There isn't any other available backup

how effective would be system restore to clear the infection? Enough to justify trying it before disabling it?

Is there malware that adds itself to existing restore points or block the system restore feature?

TOMxEU
March 15th, 2007, 04:31 PM
There are not many infections (except rootkits), which could not be clean up with tools.
System restore is a good thing, but for software related problem only, not for cleaning PC.
-{ Quote: "Is there malware that adds itself to existing restore points" }-
It does not need to add itself, Windows back up infections too, I call it Mallware restore.
I met many people with infected PCs asking, how to remove malware from System Restore.

zcv
March 15th, 2007, 07:05 PM
-{ Quote: "I met many people with infected PCs asking, how to remove malware from System Restore." }-
You disable/re enable SR - that wipes all the RP's.

But you do that only after a system is clean because there is nothing to go back to just in caase the cure is worse than the disease.