Aller au contenu principal

Restore full backup to remove virus

Thread needs solution

Foolishly I opened an email that gave me a virus. I thought I would be able to restore my backup from last night, redo today's changes, and be back to normal. But I couldn't restore. Fortunately I found a system to cure the virus, "live security platinum," and worked out of it.
My question: What should I do with TIH 12 so that I can recover from a future virus attack by restoring the whole backup? I'm running Win 7 Pro SP1 and doing two backups every night - an image backup and a data backup.

0 Users found this helpful

If you are doing a full disk image backup nightly, you should be able to boot to your recovery disk and restore from a previous backup created before the virus entered your system. You then could restore any data created since that time from more current backups. After restoring any data files created and backed up after the virus entered your system, you would need to scan them with an anit-virus/anti-malware program before opening any of them to prevent re-infection. You would need to be sure and recover the MBR (Master Boot Record) when doing your system restore to be sure you don't have a virus that hides in the MBR.

Restoring an earlier, good image is a good way to "roll back" to a state before the infection. There's no reason that you can't do that. I've done it myself on friends' systems.

You haven't told us anything about your failure, other than "I couldn't restore".

After re-reading your first post, I think you may have bigger problems than you realize if you are using "Live Security Platinum". See the search results here for that program: http://www.bing.com/search?q=live+security+platinum.

Removal instructions: http://www.bleepingcomputer.com/virus-removal/remove-live-security-plat…

Additional Windows security info: http://www.microsoft.com/security/default.aspx

James -
"Live Security Platinum" was the virus, and the removal instructions you listed were what I used to remove it, fairly easily. Thanks for the confirmation.