Home » Virus Protection » How to - Disabling System Restore » 

What can I do to remove un-cleanable infected files in the System Restore data archive and be able to restore to uncompromised restore points? 
 
Be sure signature/definitions are current. Ensure your AV utility is configured to exclude the SVI directory.

If you suspect previous restore points contain copies of infected monitored files which your anti-virus utility was unable to clean, you can remove these, and all related restore points from the System Restore archive by disabling than re-enabling System Restore. Caution: Disabling System Restore will remove all restore points; Enabling System Restore again will resume the creation of new restore points as schedule and events require. To disable System Restore: Start=>Control Panel=>Performance & Maintenance=>System Applet=>

  1. On the System Applet, Click the System Restore tab,
  2. Check the Turn off System Restore box,
  3. Click OK, then click Yes. This will initiate the restore point purging process.
  4. To re-enable System Restore, clear the Turn-Off System Restore check box from the same location

By disabling your AV utility, it is possible to successfully restore your system to a previously infected point, and once the restore is complete, re-enable the AV utility to detect and take action on the restored state. * Warning* turning off Anti-Virus protection is not recommended and should be done only temporarily to restore the system.* PSS to validate warning and steps* It is recommended before disabling an AV utility on any system it is first removed from any network to prevent the risk of infection. Steps:

  1. Disconnect any system network connectivity
  2. Disable-Turn off AV protection
  3. Use System Restore to restore to desired point
  4. On reboot, Restore Success screen, validate optimal state achieved—problem resolved
  5. Re-enable or turn on the AV protection
  6. Immediately run a manual scan of all drives monitored by System Restore to ensure all files modified by the restore are inspected by the AV utility.


 
 


Mail this pageMail this page