system restore

Posted on

Member Since: Jan 18, 2003

hey i think i might have picked up a trojan. mcaffe found it, but it's still alerting me to registry changes that are trying to happen. it finds nothing else yet it gives me notices like that.

anyway, i was wondering if i should use system restore. i never have before. but this happened yesterday when i installed something. could i just go back?

i'm also thinking about running spybot or something, though i've never used that.

[ Back to Top ]


Administrator
Since: Apr 03, 2002


Apr 08, 2007 05:52 pm

I hate system restore except in the most dire of circumstances. I would say find the offending trojan, delete it and usespybot and/or adaware and get rid of anything it finds as well.

Eat Spam before it eats YOU!!!
Member
Since: May 11, 2002


Apr 08, 2007 05:57 pm

often you have to find the name of the bugger and follow some instructions on removing it manually.


Member
Since: Jan 18, 2003


Apr 08, 2007 06:17 pm

db why do you hate system restore? what risks are associated with it? this is to sate my curiosity. i am not going to use it unless necessary...

i am using the spysweeper free scan right now. i remember that spybot was really hard to understand last time i had that thing. i was afraid of making any change because i understood none of it. anyone have anything negative to say about spysweeper?

like i said, mcafee tells me it removed the trojan. but it is really active lately, the mcaffee antivirus that is. after removal it still popped up with some stuff about registry changes trying to occur. and something trying to get access to the internet. the thing had the word 'email' in it. like it was trying to phone home.

Administrator
Since: Apr 03, 2002


Apr 08, 2007 06:37 pm

I see two red flags, for one, system resotre rolls back everything, and it sometimes screws up programs you installed since the last saved "safe point" and other registry entries and weird stuff like that. Bottom line is, while I have seen ti clean up a system from things like virus' and trojans, along with that it brings other problems.

Second, AV apps like Norton and MacAfee in my opinion are scare mongers, they find the littlest things and pop up big red windows with huge letters saying "the sky is falling", which pisses me off. I like apps like AVG that for one, are free, and for two, just pop up a little window and says "Oh, by the way, we found this, took care of it, no worries, just FYI."

Administrator
Since: Apr 03, 2002


Apr 08, 2007 06:37 pm

if you have the name of the trojan, go to spywareinfo.com and do a search on the forum of the name, often times you'll find great info to easily remove it yourself.

Member
Since: Jan 18, 2003


Apr 08, 2007 06:43 pm

i loved AVG. until i had that problem with it. it found a million .exe files infected on my computer. literally everything, it looked like. impulsively, i told it to quarantine infected files. then immediately said 'what are you doing' because it was putting all .exe files into quarantine, i soon realized. (because they were all infected.) basically, i wasn't thinking. but i told myself that i could unquarantine everything right away.

well, the quarantine folder contained two things. i thought, at the time, that maybe the folder was that small, and that each new item thrown in there was overwriting the old stuff.

anyway long story short, i had to reinstall windows. lost all my programs. my data survived. but i have no idea what happened back then. i am now afraid of avg. if nothing else, that quarantine folder was messed up.

i dont have the name of the trojan anymore. perhaps mcaffee saved the name in its history, but i doubt it. will check after spy sweeper runs. so far it is just finding cookies.

Administrator
Since: Apr 03, 2002


Apr 08, 2007 07:02 pm

yeah, I remember that now that you say it...a couple version have been released since then...

The Eternal Student
Member
Since: Oct 08, 2005


Apr 08, 2007 10:12 pm

i use avg as well, including spybot and ad-aware (all free). I had to do a system restore the other day though when a printer driver was magically "installed" on my computer which erased my outlook account. Then my security certificates on all websites which i'd been to before (school pages) suddenly weren't approved and junk.

Not cool. But the system restore worked well, didn't lose any of my documents, and it removed the printer driver and the web pages loaded fine again. Very odd... but system restore worked fine for me.

Administrator
Since: Apr 03, 2002


Apr 09, 2007 07:02 am

Any more I actually couldn't use system restore, cuz I shut it off...so it doesn't even save safe points or anything.

Prince CZAR-ming
Member
Since: Apr 08, 2004


Apr 09, 2007 08:45 am

forty, i've had a friend run into a few of those trojans.

I've had to open task manager, and see what files are running in memory, or, which files run for a minute, then disappear from memory.

Then I had to go online, searching for the name of the bugger, and follow their removal instructions.

Note: this was after adaware and spybot cleanings. Both didn't notice it, but the PC was still giving weird symptoms.

It's worked the few times I've done it, but it's usually a PITA. Find the offending file on the HD somewhere, and/or the directory to remove, then go into the registry and cut away the offending code. Reboot, and hopefully it doesn't return.

Member
Since: Jan 18, 2003


Apr 09, 2007 05:00 pm

i would have to take a class or something before manually messing with my registry.

i guess maybe i'll look up every process that's running in task manager later today

Related Forum Topics:



If you would like to participate in the forum discussions, feel free to register for your free membership.