Q: After suspicion of a virus I erased the content of the drive and installed OS X Again. How can I restore a back-up from my time capsule without contaminating the drive again? Isn't the back up contaminated?
Hi guys,
I'm new here so I'm not sure if I'm at the right spot to ask this question (if I'm not let me know! ) but my situation is as following:
Two months ago I started noticing that my saved passwords (safari and preferences) and surf history would disappear from time to time. First I thought it's was a bug so I slightly payed attention to it and just planned to do a total clean up soon. Besides I secured all the important files on my computer and use different passwords for important websites. Even so I stopped saving the passwords right away.
A month ago I received an email from google that an android device (mobile phone) had logged in to my gmail account and had synchronized with it. Since I don't have an android device I was shocked. I tried tracking where the hack came from but my IP had been duplicated. I think the security of the router at my girlfriends house wasn't locked foolproof. Luckily I hardly use my gmail account (work) and have it linked to a hotmail account which is in turn linked to another work server email account so I was able to regain acces and change the password again to something new. I directly sharpen up my security, disk control, firewall, ad block plus, stealth-mode, upgrade to el capitan, installing two step authentication from an external device for important websites and changing all the passwords. Nothing happened ever since.
I just did a complete wipe out after backing up my drive with Time Machine and reinstalled El Capitan but I'm wondering:
- If the back up is contaminated?
- If I can restore the back-up without contaminating the drive again?
- If I can restore the back up partly, by selection?
There are some important files in the latest back up that I would really like to retain. Too bad I forgot to think about this possibility before.
If you have any advice on this matter, I would love to hear it! Please help! Thank you in advance!
Jean-Jacques
MacBook Pro with Retina display, OS X El Capitan (10.11.6), 2.4 Ghz, 8Gb, Late 2013
Posted on Aug 22, 2016 5:58 AM
edits are possible for a few minutes, then the of the post is committed and no longer editable.
At the time of this writing there are no virus for the mac in the wild that have been reported by any reputable securities lab, but having an email hacked requires no special or undermining software, only circumventing the security of the account from a computer, any computer anywhere in the world connected to the internet.
of you restored your entire drive and there was a corruption it's possible the corruption will still exist. If you have the data a more secure update from a "peace of mind" standpoint would be
backup, remove the backup drive
format the internal drive
reinstall the OS from the original disks or Internet Recovery if your mac supports it (yours does)
About OS X Recovery - Apple Support
reinstall any 3rd party software from the developers website or the original media
restore documents, photos, music and saved data from your backup, but exclude the applications from the backup for now.
this does not suggest your computer is contaminated, it's simply one method to contain contamination if there was one in the event you restore the drive.
[edit] no single method is ever fail-safe or fool proof.
Posted on Aug 22, 2016 8:43 AM