Computing.Net > Forums > Windows Me > Restore & backup after virus....

Restore & backup after virus....

Reply to Message Icon

Original Message
Name: Gary67
Date: June 26, 2004 at 16:33:12 Pacific
Subject: Restore & backup after virus....
OS: ME
CPU/Ram: 128MB
Comment:

Hello everyone,

My computer was hit by a virus, it even affected Norton. My machine still stops in the middle of program, won't reboot entirely etc.. I was told to perform a backup and recovery. Will the backup work better than present situation? What is the easiest way of doing a backup & recovery? I have a recovery CD but it doesn't work the way the instructions indicate. Thanks in advance!

Gary


Report Offensive Message For Removal


Response Number 1
Name: buddymcw
Date: June 26, 2004 at 17:56:21 Pacific
Subject: Restore & backup after virus....
Reply: (edit)

Have you tried running Norton in "safe mode"? That may or maynot work but no harm trying.



Report Offensive Follow Up For Removal

Response Number 2
Name: Thresher
Date: June 26, 2004 at 20:02:49 Pacific
Subject: Restore & backup after virus....
Reply: (edit)

Gary:

Did NAV give you a name for the virus, that would help. What did you do about it so far? Did you run 'search files and folders' from Safe Mode and try to delete it (them) from there?

Are you updated--Windows, Me, IE, Outlook (settings affect IE even if you do not use Outlook). When was the last time you did a good general clean up? Dumped TIF, cookies, %TEMP% files, recycle bin, Disk Clean-up, Scan Disk, Defrag. . .? All those things give you better security. Do you run a firewall? If not go here and get this:

Sygate firewall:

http://smb.sygate.com/products/spf_standard.htm

Are you running Spybot and Adaware? if not go here and get these--download and UPDATE immendiately and run them and your AV from Safe Mode also (update and run them every 3 days):

Spybot:

Download and Read the SpyBot tutorial here:

http://s89223352.onlinehome.us/mirror/spybot/index1.php

Download it, Unzip the program, and immediately check for updates, install the updates and then do the scan.

Let it fix everything marked in red. Reboot but not with restart, shut it down for two full minutes. You’ve got two measely minutes and it’s worth it, and let Spybot run if it indicates.

To add an item to your ‘Ignore List” click on the little ‘+’ sign next to the item and left click it to highlight it, then right click it and a menu appears, select the function you want.

When you are done reboot again same way. Two full minutes shut sown is best.

Tea Time discussed by designer here:

http://forums.net-integration.net/index.php?showtopic=13433

Also, go to the update page. Notice 3 icons across the top. Between "Search For Updates" and "Download Updates" there is an icon for the download mirror location. After you click on ‘search for updates,’ the one in the middle will change. If it doesn't say "Spybot.US by Rootboxen.net USA" click on the dropbox arrows and click on Rootboxen, and use only that one. If you got a "checksum error" trying to download --that's why.

Ad-Aware:

Download AdAware from http://www.lavasoft.de/

check for updates at "webupdate".

I use these settings (green check)

From main window click "Start" then make sure " Activate in-depth scan" has a green check next to it.

Put a black dot nest to "Use custom scanning options” and click Customize" next to it, then green check these options:
"Scan within archives" ,"Scan active processes", "Scan registry",
"Deep scan registry" ,"Scan my IE Favorites for banned URL"
"Scan my host-files"

At the top of the “STATUS” page notice the Tweak (gear) icon. Click on it.

The first setting is “Scanning Engine.” Click on the little plus sign next to it, and in the drop-down green check "Unload recognized processes during scanning", and “include basic Ad-Aware settings in log file”. Next click on the ‘+’ next to "Cleaning Engine" and in the drop-down green check "Let windows remove files in use at next reboot" and Delete quarantine objects after restoring”

Click "proceed", that will save those settings.

Click "Scan"

When the scan finishes, mark everything for removal and delete it. Right-click the window and choose "select all" from the drop down menu, press ‘next’ and then ‘yes’ to the prompt: “remove all these entries”.

However, if you have certain programs running that will give a false indicator of a browser hijack attempt, such as Script Sentry, which places a monitoring function in the registry and looks like a browser hijacker but is not, then you may want to add that to the ignore list because you want to keep it there to do it’s job. To add an item to the ignore list, put the a cursor on the file it reveals and left click it to highlight it, then right click it and a menu appears. Click on ‘ignore list.’

Shut down, I shut down for two minutes, and let Adaware run on reboot if it indicates.



Report Offensive Follow Up For Removal

Response Number 3
Name: Ed in Texas.
Date: June 27, 2004 at 03:00:28 Pacific
Subject: Restore & backup after virus....
Reply: (edit)

Gary, maybe you are fortunate, see if you can 'Restore' to a date pre-virus and get things set right. If not, then you can probably clean out the virus O.K., but you need to be aware that nasties can hide in Restore and get rewritten in the directory. Since that is a protected file, Windows won't let you alter it. The work-around is to disable Restore/scan-clean/re-enable restore (do only as a last resort as it will destroy restore points)
Thresher gave you lots of good advice , but it is primarily concered with spyware/adware and I'm not sure that is your problem. Know we are all keeping our fingers crossed for you.
HTH.
Ed in Texas.


Report Offensive Follow Up For Removal

Response Number 4
Name: Gary67
Date: June 27, 2004 at 05:23:02 Pacific
Subject: Restore & backup after virus....
Reply: (edit)

Buddy,

Norton doesn't work in safe mode. Something about colors? Norton has already fixed virus.

Thresher,

Have cleaned up and have Spybot.

Ed,

Recovery CD doesn't work. Can I go to the computer without software or do I need to buy new software for recovery?

Thanks to all for your time and efforts!

Gary


Report Offensive Follow Up For Removal

Response Number 5
Name: Gary67
Date: June 27, 2004 at 17:16:11 Pacific
Subject: Restore & backup after virus....
Reply: (edit)

Thanks for your help everyone. Bought a new system.

Gary


Report Offensive Follow Up For Removal


Response Number 6
Name: vipergg
Date: June 28, 2004 at 15:20:22 Pacific
Subject: Restore & backup after virus....
Reply: (edit)

Wow wish my wife would let me get a new computer everytime I got a virus. :-)


Report Offensive Follow Up For Removal






Use following form to reply to current message:

   Name: From My Computing.Net Settings
 E-Mail: From My Computing.Net Settings

Subject: Restore & backup after virus....

Comments:

 


  Homepage URL (*): 
Homepage Title (*): 
         Image URL: 
 
Data Recovery Software




How often do you use Computing.Net?

Every Day
Once a Week
Once a Month
This Is My First Time!


View Results

Poll Finishes In 4 Days.
Discuss in The Lounge