How to use System Restore to Remove Viruses

On Windows XP, Vista and Windows 7 machines, there is a feature called System Restore.
It’s normally enabled by default and takes snapshots of your system files and registry settings.

I have used it on several occasions to repair a machine that had a virus/malware infection.

It can be very difficult to repair a virus or malware because as soon as the computer starts up, the virus gets loaded into memory and depending on the virus, it can prevent your attempts at removing it.

Luckily the viruses that I saw were not too harmful. It’s only just annoying.

You can try the following steps.

First shutdown your computer. Turn on the computer again but start it up in Safe Mode. To get into safe mode, you need to press the F8 key so it can display a list of startup options. This can be tricky so I usually hit the F8 key as soon as the computer starts and just keep hitting it until the startup options come up.

Select Safe mode from the list.

Once you have started the computer in Safe mode, go into Start->All Programs->Accessories->System Tools->System Restore.

Choose a system restore point previous to the date that you were infected with the virus.

When your computer restarts, in theory you will not see the virus or malware loading up.

This is the time now to install or update your anti-virus program and signatures. Run a full scan of your hard disk. Install the anti-malware products like Spybot or Malaware Bytes, update the signatures and scan your whole disk.

That should be it.

However, if you find that you haven’t been able to get rid of the virus or malware with System Restore, then the next step is to find it’s name or symptom or message. You can then Google to find out how to remove that particular virus. If after this you still aren’t able to remove the virus, then you will most likely need a computer professional to do it.


