Malware and Reinstall With An Image

richc46

Moderator
VIP
SF Team
Local time
7:18 AM
Messages
17,783
Location
CT
Well, we all make mistakes and now I am included on that list. I recently received an email from a friend. I opened the email and clicked on the link that was included. I knew that I made a mistake when I saw the contents of the email. I found out from her that she did not send it, but was infected herself. The Malware froze her home page, to the point that she lost internet access. The same thing happened to me.
I was able to get back my internet, by using a Macrium Image, made before the email arrived.

My Question. Does an install using a Macrium Image remove all Virus/Malware?
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell XPS 420
OS
Windows 10, Home Clean Install
CPU
Intel Core2 processsor Q8200(2.33Ghz 1333FSB) Quad Core Tech
Motherboard
Dell
Memory
6 gb
Graphics Card(s)
ATI Radeon 256MB HD3650
Sound Card
Intergrated 7.1 Channel Audio
Monitor(s) Displays
Dell SP2009W 20"
Hard Drives
640 GB Serial ATA Hard drive
Cooling
Fan
Keyboard
Dell USB Keyboard
Mouse
Dell Premium Optical USB
Internet Speed
DSL 2.85
Hello Rich, I have never used an image, but, I would think you are clean now.. just my thoughts.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell optiplex 740
OS
Win 7 Home Premium SP1 32 bit
CPU
AMD Athlon 64 X2 5000B
Motherboard
Dell Inc. 0YP696 (Socket M2 )
Memory
4.00 GB Dual-Channel DDR2 @ 370MHz (6-6-6-18)
Graphics Card(s)
Acer E181H (1366x768@60Hz) 64MB GeForce 6150 LE (Dell)
Sound Card
SigmaTel High Definition Audio CODEC
Monitor(s) Displays
Acer E181H (1366x768@60Hz) 64MB GeForce 6150 LE (Dell)
Hard Drives
699GB Seagate ST375064 0NS SCSI Disk Device (ATA)
Case
Mini tower
Internet Speed
Ping 36 ms, Download 57.71 mbps , Upload 11.79mbps
Antivirus
Free Avast. Pro paid Mbam , Free Sas
Browser
Palemoon .
Thanks Bill,
That was my initial thought, too. After, Google, however, I think that possibly the only certain way is to format, first. I really do not know at this point.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell XPS 420
OS
Windows 10, Home Clean Install
CPU
Intel Core2 processsor Q8200(2.33Ghz 1333FSB) Quad Core Tech
Motherboard
Dell
Memory
6 gb
Graphics Card(s)
ATI Radeon 256MB HD3650
Sound Card
Intergrated 7.1 Channel Audio
Monitor(s) Displays
Dell SP2009W 20"
Hard Drives
640 GB Serial ATA Hard drive
Cooling
Fan
Keyboard
Dell USB Keyboard
Mouse
Dell Premium Optical USB
Internet Speed
DSL 2.85
I have run across lots of users over on Yahoo Answers. and we always tell them to change passwords , especially the email and to rum mbam .. can't remember ever having them use an image install as a restore tho.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell optiplex 740
OS
Win 7 Home Premium SP1 32 bit
CPU
AMD Athlon 64 X2 5000B
Motherboard
Dell Inc. 0YP696 (Socket M2 )
Memory
4.00 GB Dual-Channel DDR2 @ 370MHz (6-6-6-18)
Graphics Card(s)
Acer E181H (1366x768@60Hz) 64MB GeForce 6150 LE (Dell)
Sound Card
SigmaTel High Definition Audio CODEC
Monitor(s) Displays
Acer E181H (1366x768@60Hz) 64MB GeForce 6150 LE (Dell)
Hard Drives
699GB Seagate ST375064 0NS SCSI Disk Device (ATA)
Case
Mini tower
Internet Speed
Ping 36 ms, Download 57.71 mbps , Upload 11.79mbps
Antivirus
Free Avast. Pro paid Mbam , Free Sas
Browser
Palemoon .
Could, not even do that Bill. I lost the internet, and my home page was frozen. After the image, MBAM and MSE all clean.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell XPS 420
OS
Windows 10, Home Clean Install
CPU
Intel Core2 processsor Q8200(2.33Ghz 1333FSB) Quad Core Tech
Motherboard
Dell
Memory
6 gb
Graphics Card(s)
ATI Radeon 256MB HD3650
Sound Card
Intergrated 7.1 Channel Audio
Monitor(s) Displays
Dell SP2009W 20"
Hard Drives
640 GB Serial ATA Hard drive
Cooling
Fan
Keyboard
Dell USB Keyboard
Mouse
Dell Premium Optical USB
Internet Speed
DSL 2.85
I believe the main concern for most users who have this happen is that the contact list is stolen. Then the contact list is sent emails with the malware in it.. The passwords to email definitely would be an issue , I believe. I am not sure what else besides passwords would need any action.
One thing about this Forum that I have noticed is that there are some really smart people here. I have learned alot in the last few days..
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell optiplex 740
OS
Win 7 Home Premium SP1 32 bit
CPU
AMD Athlon 64 X2 5000B
Motherboard
Dell Inc. 0YP696 (Socket M2 )
Memory
4.00 GB Dual-Channel DDR2 @ 370MHz (6-6-6-18)
Graphics Card(s)
Acer E181H (1366x768@60Hz) 64MB GeForce 6150 LE (Dell)
Sound Card
SigmaTel High Definition Audio CODEC
Monitor(s) Displays
Acer E181H (1366x768@60Hz) 64MB GeForce 6150 LE (Dell)
Hard Drives
699GB Seagate ST375064 0NS SCSI Disk Device (ATA)
Case
Mini tower
Internet Speed
Ping 36 ms, Download 57.71 mbps , Upload 11.79mbps
Antivirus
Free Avast. Pro paid Mbam , Free Sas
Browser
Palemoon .
If it was a full image of all of your files, then it would be clean. the full disk image would replace the current disk image. If it is a partial backup, then it is possible that the image replaced the files that were infected with the previous version of the files, but could have not replaced all instances of the virus.

Sorry to hear about the issue. Hope it is all sorted ok.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS G60-RBBX05
OS
Win7 Home Premium 64x
CPU
Intel Core 2 Duo P7450 / 2.13 GHz (2.29 with Extreme Turbo)
Memory
4 GB PC-6400 Hyundai (2X2) at 800Mhz
Graphics Card(s)
NVIDIA GeForce GTX 260M 1GB DDR3 VRAM
Monitor(s) Displays
16" LED Backlit
Screen Resolution
1366 x 768 on laptop 1600x1050 max res on 22" external mon
Hard Drives
OCZ Agility 3 60GB SSD / 320 GB - Serial ATA-150 - 7200 rpm
PSU
6-cell Lithium ion { lasts 1.5 hours }
Case
ASUS G60 Laptop
Keyboard
Chicklet type back-lit (white light) keyboard
Mouse
Logitech G9 Laser Mouse 3200dpi and 1000 reports per minute
Internet Speed
Comcast 8.60mb/s up - 3.11mb/s down
Antivirus
MSE
Browser
Firefox
Other Info
General mid-budget gaming Comp. Low batterylife - High FrameRates - currently overheating problems :(

2nd Rig: Case: Rosewill BLACKHAWK Gaming ATX Mid Tower Computer Case

Mobo: GIGABYTE GA-990FXA-UD3
CPU: AMD FX-6200 Zambezi 3.8GHz (4.1GHz Turbo)
Heatsink: COOLER MASTER V8 CPU Cooler
RAM: Patriot Viper 3 8GB (2 x 4GB) 240-Pin DDR3 SDRAM 1866 (PC3 15000)
GPU: SAPPHIRE Radeon HD 6850 1GB 2
TY for your concern and comment, Thorsen. The bacukup was my entire C drive.
I am pretty sure that I am ok. But in today's world extra caution is necessary.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell XPS 420
OS
Windows 10, Home Clean Install
CPU
Intel Core2 processsor Q8200(2.33Ghz 1333FSB) Quad Core Tech
Motherboard
Dell
Memory
6 gb
Graphics Card(s)
ATI Radeon 256MB HD3650
Sound Card
Intergrated 7.1 Channel Audio
Monitor(s) Displays
Dell SP2009W 20"
Hard Drives
640 GB Serial ATA Hard drive
Cooling
Fan
Keyboard
Dell USB Keyboard
Mouse
Dell Premium Optical USB
Internet Speed
DSL 2.85
Hi Rich

You might want to scan the computer with malwarebytes

Here is the download


Download



Look at the image below

oatz76.jpg
 

My Computer My Computer

Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
CPU
Intel Core i7 CPU 950 @ 3.07GHz
Motherboard
ASUS P6T DELUXE V2
Memory
OCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 1600 OCZ3X1600R2
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
OnBoard
Hard Drives
WD6400AACS-00M3B0 (640GB SATA )
PSU
CORSAIR 850w
Case
NZXT LEXA
Cooling
Intel Stock Heatsink Fan
Keyboard
Microsoft Wireless Laser Keyboard 7000
Mouse
Microsoft Wireless Laser Mouse 7000
Already did Malwarebytes and Security Essentials and it all looks good. I just want to feel 100% certain as these infections can get personal information, etc. Thanks for your help.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell XPS 420
OS
Windows 10, Home Clean Install
CPU
Intel Core2 processsor Q8200(2.33Ghz 1333FSB) Quad Core Tech
Motherboard
Dell
Memory
6 gb
Graphics Card(s)
ATI Radeon 256MB HD3650
Sound Card
Intergrated 7.1 Channel Audio
Monitor(s) Displays
Dell SP2009W 20"
Hard Drives
640 GB Serial ATA Hard drive
Cooling
Fan
Keyboard
Dell USB Keyboard
Mouse
Dell Premium Optical USB
Internet Speed
DSL 2.85
If it was a full image of all of your files, then it would be clean. the full disk image would replace the current disk image. If it is a partial backup, then it is possible that the image replaced the files that were infected with the previous version of the files, but could have not replaced all instances of the virus.

Sorry to hear about the issue. Hope it is all sorted ok.

I tend to agree with Thorsen. If you're really worried though maybe a clean install is in order if for no other reason than your peace of mind.

This can happen to anyone though, so don't beat yourself down over it. I've gotten a couple of e-mails this past week "from" an old girlfriend of mine who's pretty computer savvy that I KNOW aren't from her. Assuming she's infected too, but ...... :o ...... am not going to let her know from me as I'm sure her other friends will inform her soon enough.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
MSI GE72VR Apache Pro-416
OS
Windows 10x64 Build 1709
CPU
Intel i7 7700HQ Kaby Lake
Motherboard
Micro-Star Intl. MS-179B (U3C1)
Memory
16 GB DDR4 @2400
Graphics Card(s)
Nvidia Geforce GTX 1060
Screen Resolution
1920x1080 120Hz
Hard Drives
256 GB Nvme M.2 SSD

1TB HDD@7200
Cooling
Cooler Blast 4
Keyboard
Steel Series
Antivirus
Bit Defender Free
Browser
Edge
Hi Rich,

Assuming you were clean at the point when the image was made, which is sounds like you were, then it's safe to say that you will be clean now as the image restores all data on a disk. Just keep an eye on external storage media! :)

Tom
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Build #1
OS
Windows 8.1 Pro x64
CPU
Intel i7 3770K @4.5GHz
Motherboard
ASUS P8Z77-V PRO
Memory
Corsair Vengeance 2x4GB DDR3 1600MHz Low Profile (White)
Graphics Card(s)
Gigabyte Radeon HD 7850 (2GB GDDR5)
Sound Card
Integrated on motherboard
Monitor(s) Displays
23" LG LCD/LED IPS
Screen Resolution
1920*1080
Hard Drives
Samsung EVO 128GB SSD
Seagate Barracuda 2GB 7200rpm
2x Seagate FreeAgent [500gb]
PSU
Corsair TX650W V2 (80+ Bronze)
Case
NZXT Phantom 410 White
Cooling
Corsair H100 Water Cooler
Keyboard
Microsoft Desktop 2000 Wireless Keyboard
Mouse
Microsoft Desktop 2000 Wireless Mouse
Internet Speed
95 Mb/s Download 70 Mb/s Upload
Antivirus
MSE + MBAM Pro
Browser
Firefox
TY very much for your reply, Tom. Rep for your time and effort.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell XPS 420
OS
Windows 10, Home Clean Install
CPU
Intel Core2 processsor Q8200(2.33Ghz 1333FSB) Quad Core Tech
Motherboard
Dell
Memory
6 gb
Graphics Card(s)
ATI Radeon 256MB HD3650
Sound Card
Intergrated 7.1 Channel Audio
Monitor(s) Displays
Dell SP2009W 20"
Hard Drives
640 GB Serial ATA Hard drive
Cooling
Fan
Keyboard
Dell USB Keyboard
Mouse
Dell Premium Optical USB
Internet Speed
DSL 2.85
If it was a full image of all of your files, then it would be clean. the full disk image would replace the current disk image. If it is a partial backup, then it is possible that the image replaced the files that were infected with the previous version of the files, but could have not replaced all instances of the virus.

Sorry to hear about the issue. Hope it is all sorted ok.

I tend to agree with Thorsen. If you're really worried though maybe a clean install is in order if for no other reason than your peace of mind.

This can happen to anyone though, so don't beat yourself down over it. I've gotten a couple of e-mails this past week "from" an old girlfriend of mine who's pretty computer savvy that I KNOW aren't from her. Assuming she's infected too, but ...... :o ...... am not going to let her know from me as I'm sure her other friends will inform her soon enough.

TY for your help. I cannot give you rep as I am slow in passing it around.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell XPS 420
OS
Windows 10, Home Clean Install
CPU
Intel Core2 processsor Q8200(2.33Ghz 1333FSB) Quad Core Tech
Motherboard
Dell
Memory
6 gb
Graphics Card(s)
ATI Radeon 256MB HD3650
Sound Card
Intergrated 7.1 Channel Audio
Monitor(s) Displays
Dell SP2009W 20"
Hard Drives
640 GB Serial ATA Hard drive
Cooling
Fan
Keyboard
Dell USB Keyboard
Mouse
Dell Premium Optical USB
Internet Speed
DSL 2.85

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Build #1
OS
Windows 8.1 Pro x64
CPU
Intel i7 3770K @4.5GHz
Motherboard
ASUS P8Z77-V PRO
Memory
Corsair Vengeance 2x4GB DDR3 1600MHz Low Profile (White)
Graphics Card(s)
Gigabyte Radeon HD 7850 (2GB GDDR5)
Sound Card
Integrated on motherboard
Monitor(s) Displays
23" LG LCD/LED IPS
Screen Resolution
1920*1080
Hard Drives
Samsung EVO 128GB SSD
Seagate Barracuda 2GB 7200rpm
2x Seagate FreeAgent [500gb]
PSU
Corsair TX650W V2 (80+ Bronze)
Case
NZXT Phantom 410 White
Cooling
Corsair H100 Water Cooler
Keyboard
Microsoft Desktop 2000 Wireless Keyboard
Mouse
Microsoft Desktop 2000 Wireless Mouse
Internet Speed
95 Mb/s Download 70 Mb/s Upload
Antivirus
MSE + MBAM Pro
Browser
Firefox
I have read reports of malware surviving a re-image, although I'm not convinced on how credible they are. I have never seen it happen personally, and would consider a re-image clean. Of course all of the usual suspects in regards to on-demand scanners would be great for piece of mind if really needed, but I wouldn't give it a 2nd thought.
 

My Computer My Computer

OS
Windows 7 Home Premium x64 SP1
When my hompage froze due to the virus. I immediately restored with an image. I was enjoying my computer when the thought came to mind that the virus might still be present. I Googled, and came up with the possiblility that a format was needed to erdicate the virus. I ran several anti virus and Malwarebytes, and they were all negative. In addition, prior to the image, the computer did not work, after the image everything is running just as it should. I think that I just have to assume that everything is good.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell XPS 420
OS
Windows 10, Home Clean Install
CPU
Intel Core2 processsor Q8200(2.33Ghz 1333FSB) Quad Core Tech
Motherboard
Dell
Memory
6 gb
Graphics Card(s)
ATI Radeon 256MB HD3650
Sound Card
Intergrated 7.1 Channel Audio
Monitor(s) Displays
Dell SP2009W 20"
Hard Drives
640 GB Serial ATA Hard drive
Cooling
Fan
Keyboard
Dell USB Keyboard
Mouse
Dell Premium Optical USB
Internet Speed
DSL 2.85
Yea, I concur. I would too :D This is just more proof that the best AV you can have, is a recent system image to fall back on. ;)
 

My Computer My Computer

OS
Windows 7 Home Premium x64 SP1
If you want to be really sure next time you run a complete restore just use your Windows disc to format C first then run the Macrium backup. I also have started using the Paragon Backup & Recovery.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
1 Dell XPS8300, 1 home build
OS
W7 Prem 64 on Dell, Home Build W7 Pro 64 1drv, XP Pro 1 drv
TY for your comments. I have found through research that a virus can infect the boot sector (there is a test for that, which I passed) or the BIOS. There is no way to remove the BIOS infection, without an update or a flash. I don't think that I have that problem, however, as it is rare.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell XPS 420
OS
Windows 10, Home Clean Install
CPU
Intel Core2 processsor Q8200(2.33Ghz 1333FSB) Quad Core Tech
Motherboard
Dell
Memory
6 gb
Graphics Card(s)
ATI Radeon 256MB HD3650
Sound Card
Intergrated 7.1 Channel Audio
Monitor(s) Displays
Dell SP2009W 20"
Hard Drives
640 GB Serial ATA Hard drive
Cooling
Fan
Keyboard
Dell USB Keyboard
Mouse
Dell Premium Optical USB
Internet Speed
DSL 2.85
Back
Top