What System Restore actually snapshots — and what it never touches
A restore point is a snapshot of the Windows registry, system files and drivers — a few hundred megabytes managed by Volume Shadow Copy, taken before updates, driver installs and some application setups. It deliberately excludes your documents, downloads, browser profiles and essentially everything under your user profile folder. Modern malware overwhelmingly lives exactly there: launchers in AppData, scripts in Temp, malicious shortcuts in the Startup folder, hijacked browser extensions. Roll the system back, and every one of those payloads wakes up the moment the desktop appears.
The mechanism cuts the other way too. Restore points can contain infected system files from before you noticed anything, so a rollback can resurrect a Trojan you already cleaned. And a whole range of families — commodity stealers and ransomware in particular — disable System Restore or wipe existing shadow copies as one of their first moves, so on a genuinely infected machine the tool you were counting on may already be gone.
The security rollback trap nobody warns you about
Even when a rollback does reach an infection — old-school bootkits and driver droppers really did live inside snapshot scope — it reopens the hole the malware came through. Roll back past a cumulative update and you are running code Microsoft patched weeks ago, on a machine the attacker already knows intimately. Meanwhile the password stealer that shipped alongside it keeps every credential it exfiltrated while you were experimenting. Treating System Restore as antivirus does not just fail to clean; it hands the attacker both persistence and time.
What actually removes an infection
The working order is boring: boot into Microsoft Defender Offline or another rescue scanner so the malware is not running while you scan it, then remove persistence — Startup folder, Task Scheduler entries, Run keys — with a real tool, then install every pending update before you trust the machine again. System Restore belongs to a different job entirely: unwinding a bad driver or an update that broke boot, where rollback is fast and appropriate. For anything that exfiltrated data — stealers, keyloggers, ransomware — the only honest cleanup is a clean install plus password rotation from another device, because no cleaner on earth can un-leak a password.
- Run an offline scan from Windows Security: Microsoft Defender Offline reboots into a clean environment where nothing can hide in memory
- Afterwards check the classic persistence spots — Startup folder, Task Scheduler, Run keys in the registry
- Reset browser shortcuts and profiles: hijackers and stealers live there and survive any system rollback
- Install all pending updates immediately after cleanup, so the original hole is actually closed
- For stealers or ransomware, accept the loss: back up files, clean install, rotate every password from a different device
- Keep restore points for their real job — undoing bad drivers and updates — not for disinfection
Questions and Answers
Does System Restore remove viruses and malware?
No. It only rolls back the registry, system files and drivers; malware hiding in user folders, startup items and browser profiles survives the rollback completely untouched.
Should I use System Restore after a virus infection?
Only as a boot fix if the system is broken — never as the cleaning step. Offline scan, persistence removal and updates come first; for data-stealing malware, plan a clean install instead.
Know what is included before you buy.
The one-time 30-minute trial covers core tools. PRO-labelled features stay locked until a paid license is activated.
Read next
Write to us: [email protected]