• SONAR
  • AAAAHHH! VIRUS! Tech help needed (Screenshot) (p.3)
2012/12/18 16:05:20
Jonbouy
Image before you get infected.
 
Restore that image afterward.
 
2 simple steps, job done.
 
5 minutes per week to image your OS drive, 5 minutes to have it back up and running clean and without lingering doubt after an infection.
 
Turn off system restore into the bargain.  It's merely a waste of resources, space as well as a target drop off point for nasties.
 
Don't install your imaging program on the OS either, run it from an bootable optical disk that your imaging software will create for you.
 
You'll have to get cleaned up now before you do any of this, best of luck with that.  Next time though...
 
I gave up fiddling with malware cleaners, spyware removal stuff, manually searching and destroying files and registry entries years ago.  No need to spend a couple of days on a 10 minute job.
 
 
It also works with dodgy updates, failed installs and all manner of occasions where a perfect roll-back is required.
2012/12/18 16:55:03
vintagevibe
Jonbouy


Image before you get infected.
 
Restore that image afterward.
       
This has saved me several times over the years.  Keep your images up to date and it's painless.
2012/12/18 17:48:35
whack
This is why I love this forum, Ive got more suggestions and help quicker and better than I would a call centre.

Ok so far Im good (touch wood).


Booted in Safe Mode with Networking.

Downloaded MSessentials (but wouldnt let me install without normal mode)

I proceeded to download malwarebites in safe mode and ran scan => 18 files were detected and deleted (a lot of HKEY files)

After this I rebooted in normal mode and installed MSessential and done a quick test (nothing found I dont think).

AVG popped up once with the virus warning and I got a horrific, not white, but black screen in X2 (had to use power button!

Rebooted again and at the moment all seems to be ok (running for over an hour fine)......

Might just leave it do an indepth check over night with AVG.

Imaging..no idea how its done, but by damn am I gonna goodle it right now!

For the time being, thanks everybody big time.

Cian
2012/12/18 17:59:12
fireberd
I use Acronis True Image software to backup my entire hard drive(s) to a separate hard drive.  If there is a problem I can completely rebuild the hard drive in about an hour (plus or minus depending on how large the drive is). 

Acronis is not free but works much better than the built in Microsoft backup program in Windows 7.   Acronis is what I recommend to my clients and what most of the techies I know use.  I know one of the forum member DAW builders also uses Acronis.  There are other backup programs such as Macrium and Paragon. 

http://www.acronis.com/
2012/12/18 19:44:19
jm24
I have never had a virus move from a connected drive to the computer. The file is being accessed/scanned by the AV program.  Not being executed.  I have done this dozens of times for AV fixes, and for data recovery.

Also the pagefile, and the hibernate file, are deleted much easier. Viri put themselves in the files when the computer is powered-off. This means, one of the first steps is to disable the page and the hibernate functions.

DO NOT use more than one AV program at once.  I have "fixed" 6 computers in 6 months because Adobe "included" norton, and mcafee, when installing flash, shockwave, reader. And users do not read, and uncheck the "FREE" crap.

W7 includes an imager, w8 does not.  

I do not agree to disable system restore for the OS drive.   However, when the compute is running fine, I create a new restore point and then use DiskClean to delete all but the most recent restore points.

And then I image.

Need to use a 2nd disk, internal, or external.

I have macrium on the audio computer.

And have just installed Paragon free on a w8 machine for testing.
(http://www.paragon-software.com/home/br-free/)

And: I suggest using SuperAntispyware, and spybot, and kaspersky, and other, scanners to get any stuff AVG and MS have not caught.

I have Spybot teatimer starting on all computers to monitor changes to the startup areas of the registry.

And: update Malwarebytes again, and run full scan, again. Sometimes the virus is new, and all the AV program updates may not be as timely as we want.

And: change your email passwords to something NOT easy. 3 people I know were recently stranded in Spain because their passwords were way easy.
2012/12/18 19:50:35
Cactus Music
And why one needs a second computer for surfing.. DAW machines should have a WI Fi and LAN lobotomy. 
+1 to Microsoft Security essentials - have it on all my computers, even my DAW ( just incase.) It works and stays out of your way. It never asks you for money or to re new. 

Try this start DPCALT meter and toggled a few anti viruses on and off, MS essentials was the only one that didn't even move the level for me.  


2012/12/18 21:20:11
joakes
+ 1 for turning off System Restore, if you use it, BEFORE curing the PC.

I would run Ccleaner after the a/v and Malwarebytes to clean out any registry strings.

Prevention is the word alongside Acronis.

Cheers,
Jerry
2012/12/18 23:36:54
guitardood
Boot to safe-mode with networking and go to http://www.eset.com/online-scanner-popup

It has saved my butt multiple times and is free.

2012/12/19 08:52:35
Jonbouy
Here ya go Whack.
 
This is the tool I use, it strikes me as far simpler, cheaper, yet just as effective as any other solution.
 
http://www.disk-image.net/
 
The standard version works for me because the encryption and scheduled options are not needed here.
I don't even have it on my system the first thing I did was create a bootable optical disk and I boot it up with that. (nasties can't make their way on to a read only optical disk ) I've been using it now for a number of years.
 
Also I keep my OS partitions as lean as possible by storing all the large amounts of data required on my Samples or Projects drives where possible.
 
My OS partition (W7 64 Pro) weighs in at around 30Gb which makes the OS backups and restores quick.  For the data drives I have a different policy as the point here is to keep things quick and efficient as far as storing images goes, and getting back up and running without a long wait.
 
Unfortunately I can't help you with the cleaning process post infection as I haven't had to do it for so long I'd have no idea what works and what doesn't anymore.
2012/12/19 10:02:59
miguelito
MSessential and done a quick test (nothing found I dont think).

 
whack: Make sure you do a detailed scan with MS Essentials. On my system this takes about six hours but it will, on occasion, find infected files that the other scan misses. I always do a detailed scan if I have any reason to even suspect I may have picked up something.
 
Regards
© 2026 APG vNext Commercial Version 5.1

Use My Existing Forum Account

Use My Social Media Account