Hi,
I had some general questions about backing up my data among others.
First, here’s some background info. on how my computer got infected (Sorry for the length.):
Back in April, my desktop got heavily infected. It was running on Windows XP Home Edition SP3. After doing a scan with McAfee (which came with my ISP) at the time, it moved several files including many important files from the WINDOWS folder. After I rebooted my computer at the time, I was subsequently locked out as I found out that I had a “login loop error” if I recall correctly. I was able to log back in after following a helpful guide on the Internet and running some bootable software.
The guide then suggested to run various software in Safe Mode such as Avast!, Spybot, and other various programs. I burned these programs onto a CD using my spare labtop. I was able to install some of the programs successfully while with others I ran into several roadblocks. I ran a boot-time scan with Avast!, and afterwards it found several infected files but none due to Vitro at the time. Then I ran a full thorough scan of my computer in Safe Mode, and it again found several infected files but none due to Vitro.
There were also other problems in Safe Mode. I found that a lot of .exe’s were missing and all my Microsoft Office Applications wouldn’t work along with notepad. Also, anytime I tried to right click on a file, my screen would flash and close any windows that I had open. Then, it would ask if I wanted to continue in Safe Mode indicating that System Restore wouldn’t be available if I did continue in Safe Mode, and I would always press OK to continue in Safe Mode again.
After discussing the problems I had with the creator of the guide, he said the computer seemed to be heavily infected and suggested to reinstall Windows from scratch. But he suggested doing a repair installation as a long shot though before reinstalling Windows from scratch. I used a Dell OS Reinstallation XP Home Edition SP1 CD to run the repair installation, and I ran into several errors because it couldn’t find certain files. But somehow I was able to complete a repair installation. Entering into safe mode after the repair installation, I could now open my Microsoft Office Applications, but I couldn’t right click on files without my screen flashing and then proceeding to close all open windows. I then proceeded to open Avast!, and after finding something wrong with my Operating Memory, it scheduled a boot-time scan. It was during the boot-time scan, that the Vitro virus was then detected. It said C:\WINDOWS\SYSTEM32\sdbinst.exe was infected by Win:32Vitro, and I had no other option but to delete it.
At this point, I’ve come to a realization that the best option is to do a fresh installation of Windows, but I want to back-up all my Microsoft Office files such as .doc, .xls, .ppt and media such as pictures, mp3s, and video files including .wmv, .mpeg, and .flv. I don’t particularly need any of the .exe files. In terms of importance, I need the Microsoft Office files above everything else. All of these files could fit onto a CD, but I can’t access my burning software because it’s missing. I don’t have a flash drive or external hard drive, but I was planning on buying an external hard drive to try to backup all of my files.
The questions I had concerning my situation after reading previous posts on this thread were the following: (Sorry if I’m repeating the same questions, but I wanted to make sure I got the correct answers in accordance to my situation. And sorry if these questions sound dumb, I’m not too advanced when it comes to computers.)
If I transferred applications such as Avast!, Spybot, and other software over to my infected computer using a CD, would this infect the CD? Would it infect the transferred software?
Is it safe to continue to operate in Safe Mode?
If I’ve continuously rebooted over and over in Safe Mode for a period of 2 weeks within the last 2 months but never in Normal Mode, will it make my computer any worse than what it is now? I’ve disconnected the infected computer from my home network, never went in Normal Mode, or connected to the Internet since this problem has occurred.
Is it safe to run applications and open files in Safe Mode? Will the Vitro virus infect any additional applications and files in Safe Mode?
I read in previous posts how the virus infects .htm/.html files, will it be safe to even attempt to open these in Safe Mode? The reason I ask is if possible, I would like to retain some of the information in these files such as certain logs by copying the text into a word file.
I read how the virus goes after certain media files such as .mp3 and .wmv, will it be safe to backup these files? Also, does the virus go after .flv files?
Can I backup files to an external hard drive in Safe Mode? I read how flash drives can become infected, can the virus spread to the external hard drive?
If backing up files to an external hard drive in Safe Mode is possible, will Vitro appear when copying these files?
Also, why wasn't Vitro detected when I first ran the scans with Avast! before the repair installation? It wasn't detected until after the repair installation during the boot-time scan.