Hi, I'm a long time reader, first time poster. I'm also a stickler about creating a restore point before I install any new software or make any changes to my computer. Unfortunately, I often had to call up any one of a dozen or more restore points that I had saved. However, recently my System Restore has only been saving the last restore point or two (either manual or auto)
I rechecked to make sure I hadn't inadvertantly changed amount of space I had alotted to the storage settings and that's not it. I'm dumbfounded. How can I get the Sys Restore to save multiple points again. Dell Inspiron 6400 model E1505, Intel Core 2, 160GB HD, 2GB RAM (~47% used) Windows Vista OS (w/all upgrades). Thanks, you guys are my heros!
Please follow the steps below:
On a friend or family member's computer, download the Malwarebytes installer and update files from the links below, copy them to a CD or flash drive, then transfer the files to the problem machine and use them. If you can't start the computer into "normal" windows, try installing, updating, and running the scans AFTER the computer is started into Safe Mode.. I use the sites below to download the installer file and the manual updater:
Once downloaded and before transferring them to the problem machine, rename the program installer "mbam-setup.exe" file to something else like "Gogetum.exe", then copy the installer file and the update file to a CD or flash drive.. Transfer the file to the problem machine, then install the "Gogetum.exe" file, then run the update to get the program current.. After that, run a full system scan and delete anything it finds.
Malwarebytes Installer Download Link (Clicking on the links below will immediately start the download dialogue window.)
http://www.besttechie.net/tools/mbam-setup.exe
Malwarebytes Manual Updater link
http://www.malwarebytes.org/mbam/database/mbam-rules.exe
Next, download the SuperAntispyware program and the manual updater from the links below. After running the Malwarebytes tool above, if you still can't download and install it directly from the problem machine, download it on a friend or family member's computer as well.:
SuperAntispyware
http://www.superantispyware.com/
SuperAntispyware Manual Updater
http://www.superantispyware.com/definitions.html
____________
In a few situations, in order for the program to run, it was also necessary to rename the main "mbam.exe" file also after installing it.. It resides in the C:\Programs Files\Malwarebytes Antimalware folder.
____________________
Hope this helps and let us know more.
Grif
Is there anything I can do if I don't have access to another computer? I temporarily lent my desktop to my daughter 3 states away while she waits for her new laptop. Can I take any steps under these circumstances. Why do you suspect Malware? I have McAfee Security Suite & it updates at least once a day, scans weekly for viruses, malware, spyware, etc. I also run another spyware program from Comcast toolbar (which recently malfunctioned). Are there other apparent "symptoms" with malware? What if it's not malware, is there another fix I might be able to do without a 2nd computer? I'm really worried now. But thanks very much for your input.
And just a note... When it comes to detecting spyware, McAfee isn't one of the best. It's not bad at traditional viruses but tests indicate they have problems with trojans and spyware. Try other tools such as those I've mentioned.
Hope this helps.
Grif
It sounds like the above represents a more "advanced" way to get rid of malware, but also involves more effort.
Is this better than using Adaware, Spybot, and/or CCleaner?
You mentioned Ad-Aware, Spybot, and CCleaner.. First, CCleaner is NOT an antispyware malware removal tool.. It won't do the job at all for this type of malware.. Second, although Ad-Aware and Spybot were once the premium spyware removal tools, at this point in time, they simply are not as good as the two tools mentioned earlier. They "might" work but for the specific malware mentioned, the tools recommended will do a better job.
As to the specific instructions for downloading and installing Malwarebytes and SuperAntispyware, it's now becoming necessary to rename various tools before installing them because of the complexity of the viruses and malware that infect machines.. Basically, if you simply try to download and install removal tools such as Ad-Aware, Spybot, SuperAntispyware, or Malwarebytes, the malware will prevent it from being done.. The malware stops the tool from being downloaded, or installed, or run.. Are the steps a little bit more advanced, maybe, but if you don't take a few extra precautions to correctly install the program, you won't be able to clean out the malware.
Hope this helps.
Grif
A couple more things I was wondering...do the 2 tools you mentioned do more or less the same thing (meaning you recommended using both just to be on the safe side) or different things?
Also, would you recommend running these periodically just as a safety check, or only when something goes wrong? If the former, how often?
They all seem to find something different. There have been times, just for experimentation, where I've run full system scans with all four, one right after the other, deleting the various items that each scanner found, and they all found something extra that the others had not. Obviously, each tools is called a malware scanner but they all look for a slightly different set of malware definitions..
As to when it's necessary to run such scans, that depends on whether you have the "paid for" version which contain "real time" scanning ability, (scanning for such malware constantly in the background), or whether you're using the "free" versions which only work as stand-alone scanners without real-time protection.. It also matters how expert you are at seeing the signs of an infection.. An expert user might only run the scanner when they suspect something is wrong.. A "newbie" user should probably run weekly scans "just to be sure".. But all of this is based on the user having a real-time antivirus running constantly, a firewall enabled, and all other security features running at all times.
Hope this helps.
Grif
hi grif,
i did what you recommeded but malwarebytes won't open. does this mean i have malware virus?
thanks
steve
If Malwarebytes doesn't open, it's a good sign that malware is present.. As I mentioned in my post....
Once downloaded and before transferring them to the problem machine, rename the program installer "mbam-setup.exe" file to something else like "Gogetum.exe", then copy the installer file and the update file to a CD or flash drive.. Transfer the file to the problem machine, then install the "Gogetum.exe" file, then run the update to get the program current.
In a few situations, in order for the program to run, it was also necessary to rename the main "mbam.exe" file also after installing it.. It resides in the C:\Programs Files\Malwarebytes Antimalware folder. Once you've renamed the program executable, double click directly on the newly named file to open it..
In addition, there is a new online scanner for SuperAntispyware at the link below. Use it if you can't get Malwarebytes going.
SuperAntispyware Online Scanner
Hope this helps.
Grif
thank you for your help.. it worked!!!!
i did the online scanner for superantispyaware. after doing that... i was able to run malwarebyes.com. after a day, i realized my advanced protection was in the FIX mode and i don't have an X mark on the norton icon.
by the way, do you know a good software that will optimize my computer xp?
thank you again,
steve
Sorry it took so long to get back to this. 1st, I could not open the mbam.exe. I got an error message saying it was a corrupted file. 2nd I did run the other anti-spy ware programs you suggested and they eliminated 127 problems. That did not correct my problem. The reason I am trying to restore to a previous time is because after downloading and playing a game for many months I now get an error message that says "Access violation at 0x00e3e16c (tried to read from 0x806F4coe), program terminated" every time I open the game. I uninstalled the game and reinstalled it but get the same result.I was trying to see if going back to a previous point would get me into my game.
Most importantly, if you still can't run Malwarebytes, I'll guess your computer is still infected.. So, please perform the steps in my link above to download the Malwarebytes program on another CLEAN computer, rename the file, copy it to a CD or flash drive, then transfer the file to the problem machine.. Install and update the program, then run a full system scan..
In fact, make sure to update the other scanning programs and run some more scans until they all come up clean.
Using a set of restore points that are infected are a good way to reinfect the machine.. After such cleanups, I usually eliminate all previous restore points by temporarily disabling System Restore.. Afterward, I restart the computer, then re-enable System Restore again.
How To Disable System Restore
That said, it would be nice to know the operating system on the computer in question.. Which game are you having problems with? Are there any patches for the game at the game manufacturer's website?
Hope this helps and let us know more.
Grif
Did all you suggested, found 50 Malware/Adware and 1 Trojan. cleaned all but still cannot restore to previous date.
open a command prompt as administrator and run the following command:
vssadmin list shadowstorage /for=c:
divide the "Used Shadow Copy Storage space" by the number of restore points you have available to estimate the size of a point. subtract "Used Shadow Copy Storage" from "Maximum Shadow Copy Storage" to determine how much shadow space you have left. (on my laptop, i have 6.5gb used by 2 restore points so each one is roughly 3.25gb. since i only allocate 9gb, only 2.5gb is available so the next restore point will replace the oldest point.)
lastly, keep in mind that system restore tracks more than just installed apps and OS stuff. the list of monitored file extensions is shown below. if you have files named xxx.data or download software installs (.exe, .msi, .cab) or use some other 'gotcha' extensions, they'll be scooped up in a restore point also.
http://msdn.microsoft.com/en-us/library/aa378870.aspx
| Forum legend: | |
| Locked thread | |
| Moderator | |
![]() |
CNET staff |
![]() |
Samsung staff |
| Norton Authorized Support team | |
| AVG staff | |
| Windows Outreach team | |
![]() |
Dell staff |
| Intel staff | |