System Restore point


  1. Posts : 881
    Windows 7 Ultimate x64
       #1

    System Restore point


    Figured this would be the best place for this discussion. If incorrect please move.

    System restore point.... They're used a lot to fix viruses. Its one of the first thing I check when one is brought to me. I'm sure that a virus could find its way into your restore point data but how likely is that to happen?

    Has anyone ever experienced restoring a PC and it still be infected?
      My Computer


  2. Posts : 8,476
    Windows® 8 Pro (64-bit)
       #2

    Yes. It has happened with me. Because the virus was present in a different drive on the HDD. So it did not make a difference restoring system (C Drive).
      My Computer


  3. Posts : 881
    Windows 7 Ultimate x64
    Thread Starter
       #3

    I didnt even think of that. Was the PC's partitioned out user data or program files?
      My Computer


  4. Posts : 2,573
    Win7 Ultimate X64
       #4

    Some virus target system restore just for this purpose as AV often do not have access to "hidden" files, ensuring the virus can stay after removal
      My Computer


  5. Posts : 8,476
    Windows® 8 Pro (64-bit)
       #5

    There were 3 drives. The C drive contained the programs. The E drive contained all user media like music, video, etc. which also contained some infected files.

    After system restore, the PC looked fine but the viruses would enter in few hours again. Hence we determined that the viruses were hidden in another partition altogether.
      My Computer


  6. Posts : 7,781
    Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
       #6

    Most viruses can infect restore points nowadays, but it's usually the 1st restore point (although I'm sure some are quite capable of infecting all of them). I usually tell people when they are restoring due to a virus, to go the 2nd, or better yet, 3rd restore point.

    As Dinish pointed out, if you have a hidden partition somewhere on the system, usuall written by a rootkit, a system restore doesn't do any good.
      My Computer


  7. Posts : 881
    Windows 7 Ultimate x64
    Thread Starter
       #7

    Why do they target just one? And by first do you me the lasted one created or the first one ever created?
      My Computer


  8. Posts : 7,781
    Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
       #8

    It's usually the last one created, the one most people will roll back to in an attempt to purge the virus. Hence the reason it embeds itself into that point. I have seen systems though where the virus will either delete or disallow access to restore points altogether.
      My Computer


  9. Posts : 881
    Windows 7 Ultimate x64
    Thread Starter
       #9

    Borg 386 said:
    I have seen systems though where the virus will either delete or disallow access to restore points altogether.
    I actually think i have seen one of them before. Unless the user just turned them off. LOL
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 08:01.
Find Us