How antivirus software and System Restore work together

With System Restore in Windows XP, you can restore your computer to a previous state, and you do not lose private data files (such as Word documents, graphic files, and e-mail). System Restore actively monitors computer file changes and some program file changes to record or store earlier versions before the changes occurred. You do not have to take computer snapshots because System Restore automatically creates identifiable restore points that you can use to revert to a previous time. Restore points are created when significant computer events occur (such as the installation of a program or a driver) and periodically (each day).

To help protect critical computer and program files, System Restore monitors, records, and in some cases copies these files before they are modified. For example, when a process or a program (such as an upgrade, an inadvertent user change, a driver installation, or a virus) modifies a critical computer file or program file, System Restore records and saves a copy of the file before the change occurs. If a problem occurs, a restore operation can replace files with previously saved versions of those files. Antivirus support programs use auto-detection or scanning mechanism to monitor critical and personal files on the computer for signs of infectivity. The antivirus program then takes action to clean, remove, or quarantine (isolate) files that known viruses have infected. System Restore also tracks an antivirus program when it modifies (cleans), moves, or deletes a monitored, critical, computer or program file.

During a restoration, an active antivirus program scans for infected files. If the antivirus program detects any infected files, the antivirus program tries to modify, move, or delete the infected files. If the antivirus program successfully cleans the infected files, System Restore restores the cleaned files. However, if the antivirus software cannot clean a file, the antivirus software deletes or quarantines the file. As a result, the restoration does not work because these actions to the file cause an inconsistent restoration state. As a result, System Restore reverts to the state immediately before the restoration.

Signature files for antivirus programs are updated as viruses become known. As a result, a restoration that did not work several days ago might succeed after the antivirus program is updated. However, if you undo and retry a restoration to a point that succeeded before, the restoration may not work if a new signature or definition detects a virus that the antivirus program cannot clean on a backed-up file.

How to download AVG Removal Utility

This post provide further information about AVG antivirus support. AVG Remover utility removes all parts of AVG installation on your computer, including registry items, installation and user files on your disk, etc. AVG Remover is the least option to be used in case the AVG uninstallation / repair installation process has failed repeatedly.

Warning: All AVG user settings will be removed after the uninstallation, as well as the Virus Vault content and other item related to AVG installation and use. During the removal procedure you will be asked to restart your computer. Therefore please make sure to finish your work and to save all important data prior to AVG Remover launch.

AVG Remover(32bit) (avgremover.exe) for 32 Bit System
AVG Remover(64bit) (avgremoverx64.exe) for 64 Bit System

How to manually remove Power Antivirus 2009

This post provide antivirus support for remove Power antivirus from computer. PowerAntivirus2009, is a fake anti-spyware. Like other fake antispyware, Power Antivirus 2009 might launch false system alerts. This Power Antivirus 2009 popup is supposed to scare you into buying Power Antivirus 2009.

Step 1:- Stop unwanted process running in background.

Click Start then Run and type taskmgr.exe.
Click on Process tab in Task Manager and locate the following Image name(s).
Power Antivirus 2009
Highlight the Image name and Click End Process to stop.
Close the Task Manager.

Step 2:- Delete the suspicious file(s) or folder(s) from the computer

Click on Start and Run, type c:\progra~1, press Enter.
Locate the following file(s) and Delete.
Power-Antivirus-2009
Click on Start and Run, type %UserProfile%\Application Data , press Enter.
Locate the following file(s) and Delete
Power-Antivirus-2009
Click on Start and Run, type c:\Documents and Settings\All Users\Start Menu\Programs , press Enter.
Locate the following file(s) and Delete
Power-Antivirus-2009
Close the Window.
Step 3:- Uninstall the Suspicious program from the computer.

Click on Start and Run, type appwiz.cpl, press Enter.
Locate Power-Antivirus-2009 in Add and Remove Program.
Click on Remove (Uninstall) button.
Close Add or Remove program.
Restart the computer.
Step 4:- Manual Removal of suspicious entries from Registry.

CAUTION: Changing the Registry incorrectly could cause your comuter to stop working. Please make sure to create backup of registry or create system point before proceeding.

Click Start, Click run and type regedit.
Create a registry backup.
Locate the following registry keys, right click and Delete.
HKEY_CURRENT_USER\Software\Power-Antivirus-2009
Restart the computer.

Easy Steps to Protect Your Computer From Conficker Warm

The “Conficker” worm / virus also known as “Downadup” infection, is actually a virus code programmed in such a way that it can infect your computer and spread itself to other computers across a network automatically, without human interaction.This post provide antivirus support for remove conficker warm from your computer in 5 easy steps.

Step1
If you have a Mac or a Linux machine, breath a sigh of relief; you don't have the right code to be infected. If you're running Windows as your platform of choice, listen up, because this is critical; time is of the essence. You may experience any number of symptoms which are common like loss of Internet connection and loss of local network connection and which are less common like Automatic updates and Microsoft services being disabled.

Step2
Update your anti-virus software. Disconnect your computer from the Internet and scan your system, if you believe you are already infected. To stop the spread of the worm, see step 3. If possible, back up your data ASAP.

Step3
Disable Auto-play in Windows. For Vista: Start > Control Panel > click Play CD's or other media automatically > uncheck Use Autoplay for all media and devices. > click OK. For XP: Start > Run Enter GPEDIT.MSC >
The Group Policy dialogue box will appear. On left panel, double-click Computer Configuration > Administrative Templates > System > Double-click the Turn autoplay off option. The reason behind disabling autoplay is that Conficker can be spread through USB flash drives infected with code that starts on auto-play when the infected drive is inserted into the computer. Disabling auto-play is a good way to ensure against any malicious code automatically gaining access to your computer.

Step4
If you have the Conficker worm, DO NOT DO A SYSTEM RESTORE. Like most malware, Conficker hangs in the restore points and reactivates when you do a system restore. Utilize a decent anti-virus solution such as AVG, Avast!, or Malwarebyte's Anti-Malware. Again, disconnecting your computer from the Internet is critical to prevent the spread of the worm or the continued use of your computer by the worm for devious purposes. Windows Malicious Software Removal Tool can be used to detect and remove the Conficker worm as an option as well.

Step5
Regardless if you are on a network or a standalone computer, download the Microsoft update patch KB958644 (MS08-067) This will fix a security vulnerability that is exploited by the Conficker worm. For more information on how to exactly deploy this update across a network as well as additional information on Conficker, please visit the link in the Resources section.

 
©2009 Antivirus Support | by TNB