Teach you how to detect ARP virus in your computer

  

ARP virus is a common virus in the LAN. He will attack your computer to slow down your network or not access the Internet. This virus is the most annoying. Internet access means nothing can be done. When we encounter such a virus, we need to clean it up in time.

Symptoms of the virus: the computer network connection is normal, the machine in the PING network can not PING通 gateway, can not open the webpage; or because the ARP spoofed Trojan (virus) attacks a large number of packets, resulting in The network is unstable, frequent network disconnection, frequent errors in IE browsers, and some common software failures.

Network interruption reason: When a host in the LAN is infected with ARP virus, it will send ARP spoofing attacks to all hosts in the local area network (referring to a certain network segment, such as: 172.16.24.0). The traffic originally flowing to the network center is redirected to the virus host and accessed through the virus host agent. Because the client has anti-proxy function, the victim can't access the Internet through the virus host.

Because a large number of packets will be congested when a virus attacks, everyone will feel that the Internet is getting slower and slower. The same is true for poisoned people, who are limited by their own processing power and may feel that they are slow to restart or other measures may be taken. At this point, the virus stops working for a short time, and everyone will feel that the network is back to normal. Repeatedly, the network is intermittent.

Troubleshooting: If the user finds the above suspected situation, you can diagnose it by clicking "Start"Button->Select"Run"->Enter"arp -d" ->Click the "OK" button and try again. If it returns to normal, the drop may be caused by ARP spoofing. The ("arp -d" command is used to clear and rebuild the local arp table and cannot defend against ARP spoofing. After execution, it may still suffer ARP attacks again.

This network detection tool: Download and run the AntiArp program. After entering the gateway IP address of this network segment, click "Get Gateway MAC Address", check the gateway IP address and MAC address is correct, click "Automatic Protection". If you do not know the gateway IP address, you can get the following operation : Click "Start"Button->Select"Run"->Enter"cmd"Click"OK"->Enter"ipconfig"Press Enter,"Default Gateway" The IP address is the gateway address. AntiArp software will display the MAC address of the virus host in the prompt box.

Native killing tool: Download and run TSC

Check if there is any computer inside This kind of virus is not difficult at all. Of course, nowadays technology is developed, and corresponding anti-virus software is randomly born. However, in addition to anti-virus software, the above methods can also come in handy. I hope everyone can use it.

Copyright © Windows knowledge All Rights Reserved