also have a look at this http://www.antiarp.com/Eng
Main Topics
Browse All TopicsOur web application server recently got hit by an ARP poison attack.
Which in turn prepended the following iframe to web pages.
<iframe src=hxxp://dsajk2.cn/z51.h
The server was hosted at a data center.
Anyway now all the Windows Computers in the office have gone strange.
Thunder bird won't start, Extra drive shares are showing up by them selves.
I have done a full scan with Escan our antivirus program but it didn't show up any results.
I know this question is really broad, but what software would you recommend I scan these computers with.
There are only 7 Windows Computers so I was thinking of taking the hard drives out ans scanning them in a computer which I know is clean.
Any suggestions ?
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
also have a look at this http://www.antiarp.com/Eng
Hello there,
Another thing I would suggest is that you download Hijackthis and run it on the computers or server.
You can download it from here...http://majorgeeks.c
Do a full system scan with a log first then go to www.hijackthis.de and copy/paste your log into the space provided and press analyze.
This will detect every process/apps that are running on your computers/servers
I would also try a spybot scan also
The latest version can be found here...http://www.safer-ne
Hope this helps
You probably have the Trojan horse PSW Generic 4 HOS
You can try the steps explained here http://www.geekstogo.com/f
But in the first place try spybot S&D it may be enough, and don't keep your pc too much in the network
Have done a full scan & full disk backup of my laptop.
Before I'm going to plug it into the network at work.
Then I'll copy S&D, Trend Micro & AVG into an external hard disk.
Switch off the Ethernet switch at work.
Then run a S&D an AVG scan on each computer.
Part the challenge for me is 3 of the computers are running the Chinese version of WindowsXP
And I can't read Chinese.
Will keep you posted, when I go into work later today.
But want to make sure my laptop is all up to date / backed up before I do anything!
from the hijack log nothing really suspicious all it says is
A newer version of service pack is available. Service packs increase the safety of your system. Visit Microsoft's windowsupdate site to download the newest version of the service pack.
It seems that you don't use an anti-virus scanner or your scanner is not active. Only an anti-virus scanner can protect you against new viruses. You can look here http://www.hijackthis-foru
We didn't detect any active process of a firewall on your system. Reasons maybe:
(1.) You are using the windows firewall or a hardware firewall.
(2.) You are using a firewall of an unknown vendor.
(3.) You are using a firewall, but for unknown reasons it is disabled
(4.) You don't use any firewall at all.
We recommend you to use a firewall. Download and install one or activate windows xp´s own one. In case you got questions or you want us to add the firewall you use to our database, contact us at our forum.
you will really have run a proper full system virus and spyware scan on every pc
yes you can do that if it's easier for you, but make sure you disable autorun so it doesn't launch anything from the drive by mistake
although I'm not sure if it will pick up the registry entries and won't scan the running processes
try and see what it finds but you may still want to install one of the scanners on the actual pc
Also try these on the infected pcs.
1. Download and run this tool for flashdrive infections and follow the prompts:
http://www.techsupportforu
Flash_Disinfector also creates a bogus folder "autorun.inf"(harmless autorun.inf) in the root of every partition to prevent loading point from getting created when an infected USB is inserted which should stop the spread.
2. download ComboFix by sUBs:
http://download.bleepingco
You must download it to and run it from your Desktop
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply.
Re-enable all the programs that were disabled during the running of ComboFix..
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
This link tells you How to use Combofix as well as installing RC if you haven't yet.
http://www.bleepingcompute
No I didn't run combo fix.
The computers I was working on are in Shanghai, I'm now in Bangkok.
So I don't want to attempt anything that I can't do remotely.
I can SSH onto the router and I have Radmin installed on the English computers.
Which brings me to a new point and one I may have to open a new thread on.
I'm about to start working for a new group of companies in Bangkok.
4 Seperate small companies all working in 4 countries. (China,Thailand,Singapore & Vietnam)
Any suggestions on best AntiVirus / AntiTrogan software ?
Also should we run some form of software firewall on the desktop machines to protect them from each other ?
We also have around 10 roving laptop users.
Let me know if this should be a separate post, or if the question is to vague / broad.
Business Accounts
Answer for Membership
by: cybrexusPosted on 2008-06-06 at 02:12:36ID: 21727355
try trendmicro http://us.trendmicro.com/u s/download s/home-and -homeoffic e/
it usually knows about arp trojans, try the trial on one pc and see if it finds anything