Virus access to System Restore??

G

Guest

I just spent the day scanning my drives to remove some viruses.
- Yes I was at fault in that I didn't have antivirus sw on my system.. now
rectified
- Yes I shouldn't have gone to that site and accepted a downloaded codec
install

The av sw found 4 viruses including, as I suspected a fake virus alert:
The taskbar show (bottom right of screen) that there was a virus and
occassionally popped up meassage saying my machine was infected and to click
there to install antimalware sw ... I wasn't fooled on that one
(It pointed to something like xxxxquake.com)

My question is this:
=============
The 4 viruses were in the System Volume Information folder as part of System
Restore. How come virus software can inject into that folder. Surely it
should be trebly protected? I can't vene browse into myself as administrator?

PS The viruses were 3xPuper and 1x Fake-Alert-B, all Trojan
Virus scan sw is MacAfee

The annoying thing is that I couldn't do a system restore after the virus
scan and removal.
 
R

Roger Abell [MVP]

If malware is able to install something by leveraging admin context
then it can get to run as system which does have full access to the
system restore point storage.
When this has happened and you are insisting on not formatting
and installing fresh then you should shut off system restores so that
all gets delete and then turn it back on as a part of your cleanup.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top