<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: Win32/Protector.C</title> <atom:link href="http://www.precisesecurity.com/threats/virus/win32protectorc/feed" rel="self" type="application/rss+xml" /><link>http://www.precisesecurity.com/virus/win32protectorc</link> <description></description> <lastBuildDate>Thu, 09 Feb 2012 05:23:27 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.2.1</generator> <xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" /> <item><title>By: bukoswki</title><link>http://www.precisesecurity.com/virus/win32protectorc#comment-5153</link> <dc:creator>bukoswki</dc:creator> <pubDate>Mon, 22 Feb 2010 20:21:16 +0000</pubDate> <guid
isPermaLink="false">http://www.precisesecurity.com/?p=4353#comment-5153</guid> <description>I&#039;ve this virus in my eeepc ,and i&#039;m trying your way...so i&#039;ll tell you later what&#039;s happen...
Thanks for this post , whatever the end for me</description> <content:encoded><![CDATA[<p>I&#8217;ve this virus in my eeepc ,and i&#8217;m trying your way&#8230;so i&#8217;ll tell you later what&#8217;s happen&#8230;<br
/> Thanks for this post , whatever the end for me</p> ]]></content:encoded> </item> <item><title>By: bresgib</title><link>http://www.precisesecurity.com/virus/win32protectorc#comment-3849</link> <dc:creator>bresgib</dc:creator> <pubDate>Thu, 01 Oct 2009 23:39:32 +0000</pubDate> <guid
isPermaLink="false">http://www.precisesecurity.com/?p=4353#comment-3849</guid> <description>Our company was just attacked by Win32/Protector it has taking 8 days to get rid of this virus from 200 PCs
Here is some advice from our experience
If you think you are infected with this virus first thing to do is
•	Pull all servers off the network as this virus will spread through your company so fast you won’t believe it
•	Ban usb thumb sticks ,usb cameras or any thing that can carry data from one pc to anotherBefore I recommend programs we found to be the best  let me just say that the antivirus we found the worst of all the programs was ESET Nod 32
This program was useless  agents this virus it was so bad that we have removed it from all are PCs and replaced it with a free antivirus
•	I would recommend these  programs
Malware bytes  hxxp://download.cnet.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html?tag=mncolSupper anti spy hxxp://download.cnet.com/SuperAntiSpyware-Free-Edition/3000-8022_4-10523889.html?tag=mncolAD-Aware
hxxp://download.cnet.com/Ad-Aware-Anniversary-Edition/3000-8022_4-10045910.html?tag=mncolSpybot
hxxp://download.cnet.com/Spybot-Search-amp-Destroy/3000-8022_4-10122137.html?tag=mncol
Ccleaner
hxxp://download.cnet.com/ccleaner/?tag=mncol
And last but not lest AVG free hxxp://download.cnet.com/AVG-Anti-Virus-Free-Edition/3000-2239_4-10320142.html?tag=mncolAfter you have downloaded all of the above
Install all programs on all PCs
Update all programs on all PCsAfter this update windows to all the latest patches and services packsNow you’re  ready to fight this virus
•	Disconnect all PCs from the network
•	Turn off system restore
•	Delete browsing history in IE/Firefox and so on
•	 Run disk clean up
•	Run ccleaner (2 or 3 times till it stops cleaning files )
•	Run the reg tool in ccleaner (2 or 3 times till it stops cleaning files )
•	 Boot into safe mode
•	Scan with AVG
•	Reboot the system and boot into normal mode and wait 5 to 10 minutes and give it a chance to regenerate its self
•	Restart the Pc into safe mode
•	Scan with adaware
•	 Reboot the system and boot into normal mode and wait 5 to 10 minutes and give it a chance to regenerate its self
•	Restart the Pc into safe mode
•	Scan with spybot
•	Reboot the system and boot into normal mode and wait 5 to 10 minutes and give it a chance to regenerate its self
•	Restart the Pc into safe mode
•	Scan with supper anti spy
•	Reboot the system and boot into normal mode and wait 5 to 10 minutes and give it a chance to regenerate its self
•	Restart the Pc into safe mode
•	Scan with malware bytes
•	Repeat the above steeps until you get a clean scan with all programs
Remember only scan with one program at a timeAfter you get a clean scan with all program in safe mode
Reboot the PCs and leave for about an hour doing nothing this will allow the virus to regenerateRun through the scans in safe mode again till you get clean  scans againIf you are getting clean scans at this stage don’t let that fool you keep going till you get to scan with all programsThen start up in normal mode and scan with all 5 programs until you get clean scans from all programs
Reboot between scansAt this stage you should be well on the way to been cleanAt this stage you could connected back to the network (1 PC at a time )
Now update all 5 programs
Disconnect from network againScan with all programs again reboot between scansAt this stage you can connect to the network againI would strongly recommend running 2 scans with at least 2 programs per day for about 2 weeks after you have cleaned the virusAs I have found that this virus can regenerate itself after a full week of clean scansHOW THIS VIRUS AFFECTED OUR COMPANYAt first we had intermitting internet access problems
It also caused our Leased Line to go down intermittently
When we pinged our default gateway we lost pings intermittently
When we set up ping tests to our external address from an external address it caused pings to drop intermittently
Also the pings to the external address started to talk longer and longer to reply
It started to reply at over 100MS and after a while pings took over 1000ms to reply
Also tracrert  started losing too hops before it finally reached our router (this happened so much that we blamed our ISP.  sorry guys)I hope someone found this helpful
And I don’t envy anyone faced with the job of removing this from a big network
If you are faced with this challenge brace yourself for some long days and some longer nights
And best of luck</description> <content:encoded><![CDATA[<p>Our company was just attacked by Win32/Protector it has taking 8 days to get rid of this virus from 200 PCs<br
/> Here is some advice from our experience<br
/> If you think you are infected with this virus first thing to do is<br
/> •	Pull all servers off the network as this virus will spread through your company so fast you won’t believe it<br
/> •	Ban usb thumb sticks ,usb cameras or any thing that can carry data from one pc to another</p><p>Before I recommend programs we found to be the best  let me just say that the antivirus we found the worst of all the programs was ESET Nod 32<br
/> This program was useless  agents this virus it was so bad that we have removed it from all are PCs and replaced it with a free antivirus<br
/> •	I would recommend these  programs<br
/> Malware bytes  hxxp://download.cnet.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html?tag=mncol</p><p>Supper anti spy hxxp://download.cnet.com/SuperAntiSpyware-Free-Edition/3000-8022_4-10523889.html?tag=mncol</p><p>AD-Aware<br
/> hxxp://download.cnet.com/Ad-Aware-Anniversary-Edition/3000-8022_4-10045910.html?tag=mncol</p><p>Spybot<br
/> hxxp://download.cnet.com/Spybot-Search-amp-Destroy/3000-8022_4-10122137.html?tag=mncol</p><p>Ccleaner<br
/> hxxp://download.cnet.com/ccleaner/?tag=mncol</p><p>And last but not lest AVG free hxxp://download.cnet.com/AVG-Anti-Virus-Free-Edition/3000-2239_4-10320142.html?tag=mncol</p><p>After you have downloaded all of the above<br
/> Install all programs on all PCs<br
/> Update all programs on all PCs</p><p>After this update windows to all the latest patches and services packs</p><p>Now you’re  ready to fight this virus<br
/> •	Disconnect all PCs from the network<br
/> •	Turn off system restore<br
/> •	Delete browsing history in IE/Firefox and so on<br
/> •	 Run disk clean up<br
/> •	Run ccleaner (2 or 3 times till it stops cleaning files )<br
/> •	Run the reg tool in ccleaner (2 or 3 times till it stops cleaning files )<br
/> •	 Boot into safe mode<br
/> •	Scan with AVG<br
/> •	Reboot the system and boot into normal mode and wait 5 to 10 minutes and give it a chance to regenerate its self<br
/> •	Restart the Pc into safe mode<br
/> •	Scan with adaware<br
/> •	 Reboot the system and boot into normal mode and wait 5 to 10 minutes and give it a chance to regenerate its self<br
/> •	Restart the Pc into safe mode<br
/> •	Scan with spybot<br
/> •	Reboot the system and boot into normal mode and wait 5 to 10 minutes and give it a chance to regenerate its self<br
/> •	Restart the Pc into safe mode<br
/> •	Scan with supper anti spy<br
/> •	Reboot the system and boot into normal mode and wait 5 to 10 minutes and give it a chance to regenerate its self<br
/> •	Restart the Pc into safe mode<br
/> •	Scan with malware bytes<br
/> •	Repeat the above steeps until you get a clean scan with all programs<br
/> Remember only scan with one program at a time</p><p>After you get a clean scan with all program in safe mode<br
/> Reboot the PCs and leave for about an hour doing nothing this will allow the virus to regenerate</p><p>Run through the scans in safe mode again till you get clean  scans again</p><p>If you are getting clean scans at this stage don’t let that fool you keep going till you get to scan with all programs</p><p>Then start up in normal mode and scan with all 5 programs until you get clean scans from all programs<br
/> Reboot between scans</p><p>At this stage you should be well on the way to been clean</p><p>At this stage you could connected back to the network (1 PC at a time )<br
/> Now update all 5 programs</p><p>Disconnect from network again</p><p>Scan with all programs again reboot between scans</p><p>At this stage you can connect to the network again</p><p>I would strongly recommend running 2 scans with at least 2 programs per day for about 2 weeks after you have cleaned the virus</p><p>As I have found that this virus can regenerate itself after a full week of clean scans</p><p>HOW THIS VIRUS AFFECTED OUR COMPANY</p><p>At first we had intermitting internet access problems<br
/> It also caused our Leased Line to go down intermittently<br
/> When we pinged our default gateway we lost pings intermittently<br
/> When we set up ping tests to our external address from an external address it caused pings to drop intermittently<br
/> Also the pings to the external address started to talk longer and longer to reply<br
/> It started to reply at over 100MS and after a while pings took over 1000ms to reply<br
/> Also tracrert  started losing too hops before it finally reached our router (this happened so much that we blamed our ISP.  sorry guys)</p><p>I hope someone found this helpful<br
/> And I don’t envy anyone faced with the job of removing this from a big network<br
/> If you are faced with this challenge brace yourself for some long days and some longer nights<br
/> And best of luck</p> ]]></content:encoded> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced
Database Caching 5/5 queries in 0.002 seconds using disk: basic
Object Caching 297/297 objects using disk: basic

Served from: www.precisesecurity.com @ 2012-02-12 11:48:18 -->
