We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Using System Restore to Remove Spyware?

macman
macman Posts: 53,129 Forumite
Part of the Furniture 10,000 Posts Name Dropper
I am trying to help someone remove an infection of 'System Security' and/or 'Malware Defender' by telephone assistance (he's not nearby). Usual problem of uncontrollable pop-ups, hijacked web browser etc. But he's completely panicked by the whole thing, so impossible to talk him through calmly running MBAM, Superantispyware etc.
He's got Spyware Doctor and McAfee installed and these cannot detect it or remove it. I got him as far as checking Sys Restore and that is still working-he can access and create Restore Points. He is fairly sure of the date of infection too.
Under these circumstances is it wise to get him to do a System Restore to a pre-infection date? If the later (infected) Restore Points are then deleted, will this clear it, or does the spyware remain in files unaffected by Sys Restore?
No free lunch, and no free laptop ;)
«1

Comments

  • thomas01155
    thomas01155 Posts: 2,382 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    It might remove the infection but i would try to get him to do a quick scan with Malwarebytes shouldn't take to long.
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Restoring could possibly make it worse. All depends on the infection
    :idea:
  • macman
    macman Posts: 53,129 Forumite
    Part of the Furniture 10,000 Posts Name Dropper
    Please could you expand on that a bit aliEnRIK? I'm unclear if doing a sys restore simply 'masks' the spyware or what exactly?
    Otherwise I need to physically get to his PC to try to sort it.
    No free lunch, and no free laptop ;)
  • Browntoa
    Browntoa Posts: 49,612 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    go with the restore point , then talk them throught Malwarebytes. You may find that Restore is disabled by the infection though

    you could both download crossloop and you could do it remotely

    http://download.cnet.com/CrossLoop/3000-2654_4-10602416.html


    they click on Share and give you the code, you click on access and enter it
    Ex forum ambassador

    Long term forum member
  • macman
    macman Posts: 53,129 Forumite
    Part of the Furniture 10,000 Posts Name Dropper
    Thanks, Sorry I should have said, he did do a successful Sys Restore but the infection remained. However we then established that this restore point was later than the suspected infection date.
    But because it 'didn't work' he just got cold feet at that point and shut down.
    I'll try to get him to do an earlier restore point and then try MBAM.
    No free lunch, and no free laptop ;)
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    macman wrote: »
    Please could you expand on that a bit aliEnRIK? I'm unclear if doing a sys restore simply 'masks' the spyware or what exactly?
    Otherwise I need to physically get to his PC to try to sort it.

    I mean that some trojans 'hide' in restore points and so by restoring to an earlier point it actually executes the trojan (meaning you gain nothing)

    Im sure restoring will sometimes remove 'some' spyware. All depends on how bad it is

    I think Browntoas idea is a fantastic one though. Im kinda intrigued to see if you manage it with that
    :idea:
  • macman
    macman Posts: 53,129 Forumite
    Part of the Furniture 10,000 Posts Name Dropper
    And do some trojans effectively have a time delay built into them? The reason I ask is that I know his daughter has Limewire installed on it (I know, I know...). I pointed to that as a likely source of infection, but he insisted she hadn't been on it for days prior to the day the infection became 'live'.
    Wil take a look at the Crossloop idea too.
    No free lunch, and no free laptop ;)
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Well I know that a couple of years ago I had some nasty trojan which 'appeared' to 'lay in wait'. Once id run a particular program so many times it then executed (At least thats how it seemed). And suddenly I was full of them.

    They certainly do exist anyways, but I dont think theres many of them about
    :idea:
  • They may not have a built in time delay but they may require internet access or a certain file to be accessed before delivering its payload.
  • Patrick20
    Patrick20 Posts: 754 Forumite
    Delete Limwire immediately. I'm not saying because of copyright infringement or anything, thats none of my buisness, but the possibilities of pc crippling viruses are higher than the benifits of using it. I would suggest utorrent for downloads. And although malware Bytes was good when i tried it SuperAntiSpyware worked better for me and got rid of All of my problems. And in my opinion McAfee is aweful. I deleted it and installed Avast Home edition(FREE) and have had no infection in a year or more.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.3K Banking & Borrowing
  • 253.6K Reduce Debt & Boost Income
  • 454.3K Spending & Discounts
  • 245.3K Work, Benefits & Business
  • 601.1K Mortgages, Homes & Bills
  • 177.5K Life & Family
  • 259.2K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.