a simple question  
Author Message
Edmire





PostPosted: Tue Mar 20 21:22:28 CDT 2007 Top

Windows XP >> a simple question Hi, I have a simple question for whch I have found differing arguments even
on MVP sites. As I have got quite good advice here before, I'm trying here.
'Should one turn off system restore before scanning, or IF malware is found,
after scanning. I know a clean restore point should be made if malware has
been successfully cleaned. But why does some advice say to turn off before
scanning? Thx a lot.

Windows XP999  
 
 
Curt





PostPosted: Tue Mar 20 21:22:28 CDT 2007 Top

Windows XP >> a simple question Hi Mani,

Turning off System Restore deletes the Restore Points you may have had.
They (the restore points) may or may not be infected, but by turning off
Sys. Restore, you have *no* restore points left. I have been taught (as have
many others) that it is better to have a "buggy" restore point, than none at
all.

Also bear in mind, even if you were to have an infected restore point, it is
of no threat unless you use it to actually "restore" your system, and
actually begin using it.

Scan for malware with your RP's intact, clean up the system, and finally
turn off SR to delete any possible infected RP's. (And don't forget to turn
SR back on).

--
HTH,
Curt

Windows Support Center
http://aumha.org/

"Mani" <EMail@HideDomain.com> wrote in message
news:EMail@HideDomain.com...
> Hi, I have a simple question for whch I have found differing arguments
> even
> on MVP sites. As I have got quite good advice here before, I'm trying
> here.
> 'Should one turn off system restore before scanning, or IF malware is
> found,
> after scanning. I know a clean restore point should be made if malware has
> been successfully cleaned. But why does some advice say to turn off before
> scanning? Thx a lot.


 
 
Curt





PostPosted: Tue Mar 20 21:26:51 CDT 2007 Top

Windows XP >> a simple question Oh, forgot to answer the other query of yours. The reason so many say to
turn off SR before scanning is because so many believe that an infected SR
is dangerous. As I said in my first post, it is only dangerous if you
*invoke* that Restore Point.

--
HTH,
Curt

Windows Support Center
http://aumha.org/

"Mani" <EMail@HideDomain.com> wrote in message
news:EMail@HideDomain.com...
> Hi, I have a simple question for whch I have found differing arguments
> even
> on MVP sites. As I have got quite good advice here before, I'm trying
> here.
> 'Should one turn off system restore before scanning, or IF malware is
> found,
> after scanning. I know a clean restore point should be made if malware has
> been successfully cleaned. But why does some advice say to turn off before
> scanning? Thx a lot.


 
 
Rock





PostPosted: Tue Mar 20 21:39:36 CDT 2007 Top

Windows XP >> a simple question "Mani" <EMail@HideDomain.com> wrote
> Hi, I have a simple question for whch I have found differing arguments
> even
> on MVP sites. As I have got quite good advice here before, I'm trying
> here.
> 'Should one turn off system restore before scanning, or IF malware is
> found,
> after scanning. I know a clean restore point should be made if malware has
> been successfully cleaned. But why does some advice say to turn off before
> scanning? Thx a lot.

Do all malware removal with SR turned on, just in case something goes wrong
and you might need SR to get you going again. Once the system is cleaned,
the turn off SR to delete all restore points, turn it back on and create a
restore point.

Malware in a restore point can't hurt the system unless you restore to that
point, so there is no need to turn off SR before scanning.

--
Rock [MS-MVP User/Shell]

 
 
Mani





PostPosted: Wed Mar 21 05:00:38 CDT 2007 Top

Windows XP >> a simple question

Thanks guys for very helpful replies.:)
 
 
mikeyhsd





PostPosted: Wed Mar 21 09:11:20 CDT 2007 Top

Windows XP >> a simple question This is a multi-part message in MIME format.

------=_NextPart_000_0485_01C76B98.E3D5F740
Content-Type: text/plain;
charset="Utf-8"
Content-Transfer-Encoding: quoted-printable

you can always use Desk Cleanup to remove all but the latest restore =
point.
and even use system restore to force creating a new restore point.



EMail@HideDomain.com



"Mani" <EMail@HideDomain.com> wrote in message =
news:EMail@HideDomain.com...
Hi, I have a simple question for whch I have found differing arguments =
even=20
on MVP sites. As I have got quite good advice here before, I'm trying =
here.=20
'Should one turn off system restore before scanning, or IF malware is =
found,=20
after scanning. I know a clean restore point should be made if malware =
has=20
been successfully cleaned. But why does some advice say to turn off =
before=20
scanning? Thx a lot.
------=_NextPart_000_0485_01C76B98.E3D5F740
Content-Type: text/html;
charset="Utf-8"
Content-Transfer-Encoding: quoted-printable

=EF=BB=BF<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; charset=3Dutf-8">
<META content=3D"MSHTML 6.00.6000.16397" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=3D#ffffff>
<DIV><FONT face=3DArial size=3D2>you can always use Desk Cleanup to =
remove all but=20
the latest restore point.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>and even use system restore to force =
creating a new=20
restore point.</FONT></DIV>
<DIV>&nbsp;</DIV>
<DIV>
<P>&nbsp;</P>
<P><FONT color=3D#ff0000>
<MARQUEE scrollAmount=3D2 scrollDelay=3D9 behavior=3Dalternate =
width=3D"35%"=20
bgColor=3D#ffff00 height=3D22><A=20
href=3D"mailto:EMail@HideDomain.com">EMail@HideDomain.com</A></MARQUEE></=
FONT></P>
<P>&nbsp;</P></DIV>
<BLOCKQUOTE=20
style=3D"PADDING-RIGHT: 0px; PADDING-LEFT: 5px; MARGIN-LEFT: 5px; =
BORDER-LEFT: #000000 2px solid; MARGIN-RIGHT: 0px">
<DIV>"Mani" &lt;<A=20
=
href=3D"mailto:EMail@HideDomain.com">EMail@HideDomain.com=
.com</A>&gt;=20
wrote in message <A=20
=
href=3D"news:EMail@HideDomain.com">news:E73=
EMail@HideDomain.com</A>...</DIV>Hi,=20
I have a simple question for whch I have found differing arguments =
even <BR>on=20
MVP sites. As I have got quite good advice here before, I'm trying =
here.=20
<BR>'Should one turn off system restore before scanning, or IF malware =
is=20
found, <BR>after scanning. I know a clean restore point should be made =
if=20
malware has <BR>been successfully cleaned. But why does some advice =
say to=20
turn off before <BR>scanning? Thx a lot.</BLOCKQUOTE></BODY></HTML>

------=_NextPart_000_0485_01C76B98.E3D5F740--

 
 
Ken





PostPosted: Wed Mar 21 16:19:11 CDT 2007 Top

Windows XP >> a simple question Mani wrote:

> Hi, I have a simple question for whch I have found differing
> arguments even on MVP sites. As I have got quite good advice here
> before, I'm trying here. 'Should one turn off system restore before
> scanning, or IF malware is found, after scanning. I know a clean
> restore point should be made if malware has been successfully
> cleaned. But why does some advice say to turn off before scanning?



I see that others have answered you, and with good information, but I wanted
to add one more point:

It makes *no* sense to turn off System Restore before scanning for malware.
If you don't find any malware, you end up having lost all your Restore
Points for nothing.

The only question should be whether to turn off System Restore before or
after *removing* malware. And to that question, I strongly agree with Rock's
answer.

--
Ken Blake - Microsoft MVP Windows: Shell/User
Please reply to the newsgroup


 
 
Rock





PostPosted: Wed Mar 21 19:35:21 CDT 2007 Top

Windows XP >> a simple question "Mani" <EMail@HideDomain.com> wrote
> Thanks guys for very helpful replies.:)

You're welcome.

--
Rock [MS-MVP User/Shell]