|
What can I do to remove un-cleanable infected files in the System Restore data archive and be able to restore to uncompromised restore points? Be sure signature/definitions are current. Ensure your AV utility is configured to exclude the SVI directory.
If you suspect previous restore points contain copies of infected monitored files which your anti-virus utility was unable to clean, you can remove these, and all related restore points from the System Restore archive by disabling than re-enabling System Restore. Caution: Disabling System Restore will remove all restore points; Enabling System Restore again will resume the creation of new restore points as schedule and events require. To disable System Restore: Start=>Control Panel=>Performance & Maintenance=>System Applet=>
- On the System Applet, Click the System Restore tab,
- Check the Turn off System Restore box,
- Click OK, then click Yes. This will initiate the restore point purging process.
- To re-enable System Restore, clear the Turn-Off System Restore check box from the same location
By disabling your AV utility, it is possible to successfully restore your system to a previously infected point, and once the restore is complete, re-enable the AV utility to detect and take action on the restored state. * Warning* turning off Anti-Virus protection is not recommended and should be done only temporarily to restore the system.* PSS to validate warning and steps* It is recommended before disabling an AV utility on any system it is first removed from any network to prevent the risk of infection. Steps:
- Disconnect any system network connectivity
- Disable-Turn off AV protection
- Use System Restore to restore to desired point
- On reboot, Restore Success screen, validate optimal state achieved—problem resolved
- Re-enable or turn on the AV protection
- Immediately run a manual scan of all drives monitored by System Restore to ensure all files modified by the restore are inspected by the AV utility.
|