FlyerTalk Forums - View Single Post - I got a virus. How do I 'restore' my computer to the day before
Old Jul 10, 2007, 12:20 pm
  #15  
mbreuer
 
Join Date: Jul 2004
Programs: CO Gold; SPG Gold***; AvisFirst;
Posts: 3,970
Originally Posted by Emma65
Star by TURNING OFF RESTORE! If you go back the virus is till present. You won't remove it that way.

So TURN OFF RESTORE!

Then download a trial of an antivirus software that you plan to eventually purchase. Burn that on a disk as well so you have a back up.

Close browser and mail and anything you can think of.

Install antivirus. Run the updated and run a complete check of your system. Go away and have lunch/coffee and come back to see the results. If anything is moved to quarantine - delete.

Then go to symantec.com and download (for free) every concievable virus removal tool you can find. Burn them on a disk.

Get your computer OFF LINE so it is not connected to the internet anymore.

Run ALL of the removal tools (even if you have a tool for a virus that didn't get flagged) one after another.

Run your antivirus software and see if it finds anything. If it does - see if you have the tool for it and run it again. If not - go online and find the removal tool.

If you go about it as above you will not have to do a complete install. However - Once your system is cleaned I'd recommend you back up your files, format the hard drive and reinstall everything including the antivirus.

Also make sure your firewall is activated and get anti spyware while your at it. Including pop-up blockers.

This is what I used to do when I was working for a small ISP and servicing client computers.

Just note that for removal tools to efficiently work RESTORE MUST BE TURNED OFF!!

Then leave it off. Restore is evil. It is much better to get a good back up software/workflow and stick with that than using restore.

Remember - Restore is EVIL!

:-)
Actually, you should never count on the integrity of any part of the system you're trying to recover. Do NOT download and make disks of the anti virus software on the infected machine. You'll likely end up with infected cd's. Also, you really want to boot from something clean. You could even install a minimal Window's partition onto a USB drive (if you can't boot from an external USB drive, you can install a new boot loader (grub, for example, or a multitude of commercial offerings) which redirect booting to the usb device.

You really want to do the scan from a clean system. That will, btw, usually detect infections in the RESTORE area. Doesn't make restore useful, but prevents re-infection.
mbreuer is offline