If ransomware hit and you had a disconnected hard drive with an image of windows, could you use macrium to boot into a clean image of windows and remove the intrusion?
With the pc off >insert the macrium boot media>boot up and select windows. Would this delete the intrusion on the hard drive and install windows?
I was just confirming that I would not be a victim of ransomware because I have the Macrium boot media and the image to override ransomware.
I wasnt sure.
If your machine gets infected with ransomware, and you have a disk image, or clone, that has not been connected to your machine whilst you have been infected, then you can recover your machine by doing the following …..
Reset Windows to factory condition to remove infection.
Restore from your backup disk image / clone to restore your machine to its pre-infection condition.
Do not under any circumstances attach your backup to the infected machine before you have reset it and removed the infection, or the infection may well spread to your backup.
If your machine gets infected with ransomware, and you have a disk image, or clone, that has not been connected to your machine whilst you have been infected, then you can recover your machine by doing the following …..
Reset Windows to factory condition to remove infection.
Restore from your backup disk image / clone to restore your machine to its pre-infection condition.
Do not under any circumstances attach your backup to the infected machine before you have reset it and removed the infection, or the infection may well spread to your backup.
I Googled several sources and one should not reset the pc before using a back up rescue media or catastrophic results will occur.
Can you link me to some of those sources, because I can see no reason why you should not reset your machine, nor what catastrophic occurrences could occur if you do.
Only circumstance I could think of, is if you have upgraded your machine since you purchased it, in which case your backup media may be to an OS that was not originally present on your machine.
But really a backup should be "self-contained" because it is only going to be any good to you, if it's not dependant on your machine, since that may be corrupted, so should be able to function a restore, no matter what.
With anything else but ransomware, I would say resetting was optional, and I'm probably just being overcautious by advising one, but ransomware is insidious and capable of spreading to anything that's plugged into a machine that's infected with it, and since most people only have one backup, then I tend to err on the side of caution, and like to see it fully removed before attempting a restore from backup.
Theoretically, if you're booting from a recovery media that is not your OS, then you should be OK, however it would be a shame if that were not to prove true, and new ransomware variants seem to have ever expanding capabilities.
Oddly enough I have images on a portable SSD and also an HDD I put on a kit. Both have images but I tend to agree with you after all that is why I come to forums to learn not teach. Reset first it is.
✨ Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI