System Restore and malware.

System Restore and malware.

Secure Home | Search | About
 Anti-Virus Software    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
System Restore and malware. Dan 01-04-2006
Posted by Dan on January 4, 2006, 11:20 am
If you were  Registered and logged in, you could reply and use other advanced thread options
An acquaintance let it drop, in passing, that all she does if she
thinks she has malware is to do a System Restore. I did not comment at
the time. I myself can only describe my set-up as belt and braces as
well as a spare belt. I keep up to date with definitions, do a
thorough clean every week etc.
Anyone any opinion/ideas on her approach?
Just how safe is her approach?
I ask because we work from time to time on each others PC and exchange
work on CDs and DVDs.

This is not a disinterested enquiry for the askings sake.

Dan.

Posted by David H. Lipman on January 4, 2006, 11:27 am
If you were  Registered and logged in, you could reply and use other advanced thread options

| An acquaintance let it drop, in passing, that all she does if she
| thinks she has malware is to do a System Restore. I did not comment at
| the time. I myself can only describe my set-up as belt and braces as
| well as a spare belt. I keep up to date with definitions, do a
| thorough clean every week etc.
| Anyone any opinion/ideas on her approach?
| Just how safe is her approach?
| I ask because we work from time to time on each others PC and exchange
| work on CDs and DVDs.
|
| This is not a disinterested enquiry for the askings sake.
|
| Dan.


It may or may not work. Yes it will delte EXE files and revert back yto an olde
Registry
but some malware may be using other file taype that is not saved in the system
restore cache
and will still be present.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by Dave Cohen on January 4, 2006, 11:54 am
If you were  Registered and logged in, you could reply and use other advanced thread options

>
> | An acquaintance let it drop, in passing, that all she does if she
> | thinks she has malware is to do a System Restore. I did not comment at
> | the time. I myself can only describe my set-up as belt and braces as
> | well as a spare belt. I keep up to date with definitions, do a
> | thorough clean every week etc.
> | Anyone any opinion/ideas on her approach?
> | Just how safe is her approach?
> | I ask because we work from time to time on each others PC and exchange
> | work on CDs and DVDs.
> |
> | This is not a disinterested enquiry for the askings sake.
> |
> | Dan.
>
>
> It may or may not work. Yes it will delte EXE files and revert back yto
> an olde Registry
> but some malware may be using other file taype that is not saved in the
> system restore cache
> and will still be present.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>
By far the safest scheme is to partition the drive and keep the os and
program files in the main (c) partition and use one or more (usually
extended) partitions for data and everything else.
I use bootitng to manage this, and backup the c partition to one of the
volumes as well as to dvd but not necessarily as frequently. I recently got
image for windows which permits making the image without shutting down the
system.
Taking all the other normal precautions should still be done, but the
ultimate protection against any mishap is a good backup scheme.
Dave Cohen



Posted by David H. Lipman on January 4, 2006, 12:42 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


| By far the safest scheme is to partition the drive and keep the os and
| program files in the main (c) partition and use one or more (usually
| extended) partitions for data and everything else.
| I use bootitng to manage this, and backup the c partition to one of the
| volumes as well as to dvd but not necessarily as frequently. I recently got
| image for windows which permits making the image without shutting down the
| system.
| Taking all the other normal precautions should still be done, but the
| ultimate protection against any mishap is a good backup scheme.
| Dave Cohen
|

When it comes to the System Restore cache that is a moot point. The System
estore cache
caches data on all hard disks.

To take your idea a step futher, use a sepate physical hard diak for OS and
Data. If they
are IDE, each drive should be on its own IDE channel.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by (PeteCresswell) on January 4, 2006, 12:31 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Per Dan:
>Anyone any opinion/ideas on her approach?
>Just how safe is her approach?
>I ask because we work from time to time on each others PC and exchange
>work on CDs and DVDs.

I may be in the same boat as she is.

My approach:
----------------------------------------------------------
1) Partition the drive so there's about 40 gigs for C:\System

2) Install only the OS and applications on C:\

3) Dedicate an external USB2 drive as D:\Data

4) Take some time to make sure that all data (including "Favorites") winds up on
D:. This takes a few registry changes.

5) Dedicate another external USB2 drive to system images.

6) I take a system image (in 640k chunks) as soon as I have a working system
installed.

7) Then, as I install/change things I keep longhand notes on paper of exactly
what I did over the days/weeks.

8) Once I've got a "Final" system, I restore that first system - remaining
offline - and re-apply those changes, still offline.

9) Now I burn another system image in 640k chunks.

10) Generally, I'll burn that image to DVDs or CDs.

11) From then on, I do the longhand notes thing for successive changes. These
changes are generally minimal, but every so often, I'll restore the last good
image and update it with the changes as in #8.
------------------------------------------------------------


I've got a 13-year-old on this PC several hours a day, so I've had *plenty* of
opportunities to test out my scheme (as in a couple per month...) and it's been
working a-ok for me over the last 3 years or so.

In addition, I do regular incremental backups of D: to three separate USB2
drives. I keep one online for convenience, and shuttle the other two between
home and work for offsite backup.



As I read back over this, it sounds complicated and time-consuming.

In fact, it is minimally so.

The main investments are:
------------------------------------------------------
1) Buying and learning how to use an image backup utility

2) Buying and learning how to use the data backup utility

3) Buying the external USB2 drives

4) Keeping the longhand log of system changes

5) Making the occasional updated version of my "good" image
------------------------------------------------------

#s 4 and 5 are the only redcurrant efforts - and they're minimal time-wise.
--
PeteCresswell

Similar ThreadsPosted
missing system restore tab October 16, 2005, 10:45 pm
SYSTEM RESTORE BAGLE WORM November 12, 2005, 8:11 pm
Attack by Unknowns and Defunct Norton AV and System Restore November 8, 2007, 9:36 am
How does this malware target the system? June 22, 2008, 11:32 am
System tray virus/malware December 5, 2008, 2:27 pm
Virus in restore file September 30, 2007, 8:29 am
Re: Has David Lipman been providing malware to known malware criminals? March 24, 2007, 7:10 pm
Re: Has David Lipman been providing malware to known malware criminals? March 24, 2007, 7:15 pm
Re: Has David Lipman been providing malware to known malware criminals? March 26, 2007, 8:28 am
least system hog recommendation? January 26, 2006, 8:50 am

The site map in XML format XML site map

Contact Us | Privacy Policy