Disable and Enable Restore in Windows Xp after virus/worm infection

From: Bun Mui (bunmuing_at_hotmail.com)
Date: 05/16/04


Date: 16 May 2004 09:45:43 -0700

When someone is infected with a worm or virus.

One should scan with anti-virus checker.
Remove all viruses or worms.

Afterwards it is recommended that you disable restore
re-start the computer and afterward Enable restore
and re-start the computer.

As I understand this will delete all previously
restore points which may contain the virus/worm.

So from my understanding if a person's computer
is infected with a worm or virus your restore points
will become useless even before the infection since
you must delete all the previous restore points
in order to disable and enable restore to get rid of the
worm/virus currently on the computer.
Is that correct?

I just wonder where (what directory) on the hard drive
are the restore points located?????

What about the registry? Should I fool around with it?
Or is it not necessary?
Since some websites tell you to delete the stuff on
the registry which was made by virus or worm.
But I don't like fooling around with it.
Since they say if you make a mistake your
system may not start back up again if you do something
wrong or don't back it up.
Which is a scary thought.

I got infected with agobot virus before.
Now it is removed by anti-virus software.
Just wondering if it is still necessary to touch
the registry?

Thanks.

Bun Mui



Relevant Pages

  • Re: Watch out for this
    ... The 'swen' worm and its effects, ... there is not much you can do to stop the flood. ... e-mail for virus infection. ... You can use a remote virus scan from one of the antivirus program ...
    (microsoft.public.security.virus)
  • Re: I ran the exe file !!!!
    ... point before the virus infection. ... For the moment you should simply stick with MS windows Updates. ... What You Should Know About the Swen Worm ... you have Windows ME or Windows XP, you could run the System Restore ...
    (microsoft.public.security.virus)
  • Re: Was NT AUTHORITY SYSTEM now, for the moment, Swen worm rembered on its second anniversary
    ... > some clues to its spread and where the final repositories of infection ... > Director of the Back Khoa Internetwork Security Centre Nguyen Tu ... > The Swen computer virus has infected at least 200,000 computers worldwide ... > Internet virus and worm attacks. ...
    (microsoft.public.security.virus)
  • RE: Increasing ICMP Echo Requests
    ... Virus Name Risk Assessment ... SubType: Internet Worm ... Method Of Infection ... - Precisely Define and Implement Network Security and Performance Policies ...
    (Incidents)
  • Re: Virus
    ... don't post in reply to the "Virus" thread. ... One way the 'swen' worm is gets e-mail addresses is by ... e-mail for virus infection. ... I must empty my mailbox every 5 minutes, ...
    (microsoft.public.security.virus)

Loading