Home­Calendar­FAQ­Search­Register­Memberlist­Usergroups­Log in
Share | 
 

 ARP for Virus Detection Virus

View previous topic View next topic Go down 
AuthorMessage
Administrator



Number of posts: 83
Age: 35
Localisation: USA
Registration date: 2007-05-28

PostSubject: ARP for Virus Detection Virus   Tue Jan 08, 2008 7:20 pm

Virus attack symptoms: computer network connecting normal, the building
can PING-PING-machine is not the gateway, not the web, or to deceive as
the Trojans ARP (virus) attack sent a large number of data packets,
resulting in the operation of the network instability, frequent
offline, IE browser frequent errors as well as some commonly used
software failure, and other issues.

Network outages
reasons: When a LAN ARP hosts infected with the virus, to the LAN
(referring to a particular network segment, such as: 172.16.24.0 this
section) all mainframe sent ARP spoofing attacks, the original traffic
flow Network Center diverted the flow of the virus host, and through
the Internet virus host agents. Because of a client-agent functions,
resulting in the victim could not host the virus through the Internet.

The virus attack sent large amounts of data packets will be network
congestion, we will feel more and more slow speed Internet access. Do
the same poisoned by its own deal with capacity constraints, I feel
very slow speed, which may be taken to restart or other measures. At
this point the virus stopped short, we feel the network returned to
normal. So repeatedly, it causes intermittent network.

Fault Diagnosis approach: If you found more suspected cases, the
operation can be carried out through the following diagnosis: Click on
the "Start" button -> Select "run" -> Input "arp-d" -> click
"OK" button, and then re-try the Internet If it will return to normal
this is illustrated by the relation may be deceived by the ARP. (
"Arp-d" command is used to remove and rebuild the machine table can not
resist arp ARP deception, and may still again after the implementation
of ARP attack.)

Ben Wang detection tools: download and
run AntiArp procedures. Ben Wang importation of gateway ip address and
click on the "Access Gateway MAC address" to check gateway IP address
and MAC address After that, click the "automatic protection." If that
gateway IP address can be obtained through the following actions: Click
on the "Start" button -> Select "run" -> type "cmd" click "OK"
-> type "ipconfig" press the Enter, "Default Gateway" The IP address
is the gateway address. AntiArp software will appear in the prompt box
virus host MAC address.

The killing machine tools:
download and run TSC.EXE procedures. Commissioner in the course of the
operation it had been running to shut down automatically, the final
report documents Show glance whether poisoning. If the poisoning is
proposed to re-install the operating system.







_________________
By M4st3r.w4n1
Back to top Go down
View user profile http://security.up-your.com
 

ARP for Virus Detection Virus

View previous topic View next topic Back to top 
Page 1 of 1

Permissions of this forum:You cannot reply to topics in this forum
 :: ::Hacking:: :: Tutorials-