D**n those f***ing China! *joke*
This is new varian for Microsoft.vbs virus which I write formula how to clean it around a month ago when it hit my cybercafe until totally broken he he… Now most people know this virus as ARP virus. Why? Because after learning it more deeply this virus categorized as HIGH RISK and should removed as soon as possible before it infected total your network.
First.. To know this virus is active on your computer is you will get most error pages message when browsing, or error when using messenger, PLUS you will find this file Microsoft.vbs Microsoft.bat Microsoft.pif on your hard drive where you install your OS PLUS *again* your computer gonna be slow PLUS *oh not again* Your internet connectivity will going slow than usually PLUS *OMG* It will flooding your network until some billing(via TCP/IP) will stop responding.
It’s hard to know when your computer infected because it’s only showing a little error when you browsing and sometimes it’s not active (like clean computer) until you idle for some minutes/hour.

When you browsing you don’t feel something goes wrong… but when you look on the page source the evil is waiting on there

Clean page source from google.com not injected with any code.. but wait when virus active you will look something like this..

Holy s**t what is that!!!
So the answer is virus going active when you’re using internet by browsing or chat on messenger. Basically all internet explorer activity can bring this virus active! Enough let’s remove this virus permanently and stop it from coming back.
You can use Colasoft MAC Scanner (shareware) to scan your network, If you found there is mac address same with your gateway then you have to unplug that computer from network and clean it before you put it back on network. Why? In condition when you clean infected one virus will going to spread on other computer in your network once you clean it, it will calling back file from other infected one in your network so don’t waste your time for this stupid thing UNPLUG IT to stop it spreading in network!

Now.. Get Security Task Manager and delete/remove strange process on your computer background (usually with IE icon and dll files) delete/remove Desktopwin.dll/Jview.dll and ThunderAdvise.dll delete/remove AppInit_DLLs.
Done.. Now get hijackthis and restore your hosts file by Open the Misc Tools section, on System tools choose Open hosts file manager and deleted all line after 127.0.0.1 localhost or you can done this using notepad hosts file is on %systemroot%/system32/drivers/etc
Now get ATF Cleaner and deleted all cookies, history and java cache.
Repair your registry to back in normal by using this code:
[Version]
Signature=”$Chicago$”
Provider=Nobody
[DefaultInstall]
AddReg=UnhookRegKey
DelReg=del
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows, AppInit_DLLs,0, “”
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Object
[del]
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, ThunderAdvise
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, DesktopWin
Or download repair.inf
To stop virus coming back from other computer disable default share by using this code:
[Version]
Signature=”$Chicago$”
Provider=Nobody
[DefaultInstall]
AddReg=UnhookRegKey
DelReg=del
[UnhookRegKey]
HKLM, SYSTEM\CurrentControlSet\Services\lanmanserver\parameters, AutoShareWks,0×00010001,0
HKLM, SYSTEM\CurrentControlSet\Services\lanmanserver\parameters, AutoShareServer,0×00010001,0
Or download disable-default-share.inf and activate it restart-net-service.bat
Disable autorun to stop virus coming back from USB flashdisk/removable mediaby using this code:
[Version]
Signature=”$Chicago$”
Provider=Nobody
[DefaultInstall]
AddReg=UnhookRegKey
DelReg=del
[UnhookRegKey]
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoDriveTypeAutoRun,0×000000ff,255
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer, NoDriveTypeAutoRun,0×000000ff,255
Or download disable-autoplay.inf
To stop virus from coming back by replacing old files let’s make dummy files download dummy.bat!
Last scan with your BEST antivirus/antimalware to make sure your system clean! Another trick to stop virus from infected back your computer you can add static entry on ARP by write in command prompt “arp –s *gatewayipaddress* *gatewaymacaddress*” or another trick say we can blocked those d**n virus site by change it in hosts file here is some website list detected as virus update:
972.aksjd11.com
w3og.cn
qazc.fourtw.cn
www.aujoy.cn
www.hao601.cn
www.psp476.cn
222.1212l112.net
444.1212l112.net
555.1212l112.net
111.1212l112.net
root.51113.com
hk.www404.cn
err.www404.cn
(Still there a lot out there.. BLOCKING ALL .cn domain might resolve this problem ha ha ha :P)
Anyway this method is not really can stop virus updated as long the creator change website again we have to update block it manually.
Done (finally)… now using your computer like usually for 1-2 hours and see if the virus coming back..
If you're new here, you may want to subscribe to my RSS feed. You may copy or publish this article to your blog or other site as long you give credit link back to this site article. Thanks for visiting my blog!






July 30th, 2008 at 1:17 pm
virus apan lagi nih ?
August 2nd, 2008 at 9:55 pm
halo mas istanto virus ini nyerang warnet saya sudah coba saya bersihkan mengikuti petunjuk tapi kok setiap ada yang make internet muncul lagi ya? gimana nih saya pusing warnet saya kacau gara2 virus ini…
August 6th, 2008 at 11:08 am
@bowo: namanya dulu virus microsoft sekarang ganti nama jadi virus arp
@cencen: kalau warnet/kantor sudah terinfeksi memang susah sekali bersihkan jaringannya cara terbaik mungkin cencen bisa putuskan semua koneksi dalam jaringan lalu bersihkan satu persatu jangan di sambung kalau belum yakin bersih 100% soalnya ini virus ada kemampuan memanggil backup dia di computer dalam 1 network yang masih menyimpan file yang dia butuhkan. misalnya computer a sudah bersih lalu komputer b masih ada sisa virus sedikit nantinya computer b akan terus request file ke komputer a kalau tidak ditemukan dia akan request ke website (yang dibuat nyebarin virus) sampai dia complete dan aktif lagi di dalam jaringan lalu menyebarkan dirinya. jadi cara terbaik adalah cabut semua dan yakinkan bersih 100% baru di masukkan kembali ke network. kalau bersihkan tanggung2 yakinlah virus ini bisa bikin panas kepala dan hati
August 10th, 2008 at 9:21 am
i need networking
August 14th, 2008 at 11:09 pm
Your blog is interesting!
Keep up the good work!
October 23rd, 2008 at 10:50 pm
Mas, dikantor saya beberapa hari ini sering lambat. Ketika konek ke suatu site sering ditemukan network timeout atau network interupted. bahkan untuk masuk router wirelessnya aja kadang harus direstart tuh sih router. Saya scan pake Colasoft MAC Scanner, tapi tidak ada tanda2 duplikasi MAC Address. Apakah ini bisa jadi diakibatkan virus arp?
Terimakasih atas jawabannya (kalau boleh via email ya).
October 24th, 2008 at 6:09 am
DH Ricky, belum tentu itu akibat ulah virus ARP coba diperhatikan lebih teliti dulu apa penyebabnya, untuk MAC scanner coba digunakan setelah 2-3 jam setelah komputer aktif.. cara paling mudah untuk mengetahui terinfeksi virus ARP cukup dilihat di %systemroot%\WINDOWS\AppPatch\ ada gak file Desktopwin.dll, Jview.dll, arau ThunderAdvise.dll kalau ada salah satu dari file diatas dipastikan jaringan bapak terkena virus ARP.
October 26th, 2008 at 10:28 am
mas pas yang langkah make HijackThis nya gag bisa di delete line(s) yang setelah 127.0.0.1 nya. dah di delete eh muncul lagi alias gag bisa di delete. dah saya coba manual juga gag bisa tulisannya make sure the path or filename are correct trus malah kebuka jendela save as … bingung saya mas soalnya net udah tutup 2 hari ini… mohon pencerahannya… thx
October 26th, 2008 at 10:46 am
Ow.. itu sudah sangat positif kena virus ARP. Pastikan semua proses virus yang aktif di background sudah mati, kalau masih belum bisa coba di skip dulu, nanti kalau semua step sudah selesai baru files hosts di benerin.
Tolong di perhatikan SEMUA komputer yang ada di jaringan warnet tolong di cabut dulu kabel LAN untuk sementara, PASTIKAN PEMBERSIHAN KOMPUTER DALAM KONDISI TIDAK TERHUBUNG APAPUN, TIDAK ADA FILE MASUK/KELUAR, TIDAK ADA VIRUS LAIN (SEMISAL ALMAN/SALITY) YANG AKTIF. Kalau bersihkan setengah2 virus ini susah di basmi yang pasti malah bikin pusing karena dia bisa backup dirinya dari komputer lain yang terlihat seperti tidak terinfeksi dalam satu jaringan atau melalui media internet.
Saya sangat sarankan install ulang semua PC di warnet dan di beri proteksi seperti deepfreeze agar virus ini tidak menggangu bisnis anda.
Good luck
October 26th, 2008 at 11:17 am
sepertinya mesti install ulang mas, soalnya udah seperti yang mas istanto jabarin udah saya lakuin semua nya pak ttp gag beres ini.
oh iya mas saya punya 3 partisi, yang butuh di format apakah semua nya atau hanya C:/ nya saja? mohon bantuannya
October 27th, 2008 at 1:24 am
Gak beres itu karena dia masih ada dan aktif di komputer lain dalam 1 jaringan.. yah kalau nggak tau dimana letak virusnya memang lebih baik install ulang saja apalagi kondisi anda jaringan warnet yang rentan. sebaiknya scan pakai norman mallware cleaner dulu kalau sudah simpan file yang penting saja lalu di format semua partisi. ingat pakai proteksi seperti deepfreeze kalau nggak nanti terinfeksi lagi bisa stres anda install ulang terus.
November 3rd, 2008 at 8:16 am
mas istanto mau nanya nih penyebab virus arp ini aktip apaan sih apa gara” microsoft.bat,.pifdan .vbs ini?? soalnya saya dah bersihin kok tetep aja ya ada yang aktip mohon pencerahannya ya mas terimakasih sebelumnya….
November 4th, 2008 at 12:41 pm
he..he..he.. aktifnya ya selama backup virusnya masih ada pasti dia recover dijaringan
kk shirro pusing ya sama virus ARP? kalau untuk warnet saran saya sih yang terbaik install ulang aja semua PC trus diproteksi daripada ntar bolak balik bisa stres kk 
November 13th, 2008 at 12:20 am
mas setelah saya cobain,,, rpnya setelah “disable-default-share.inf and activate it restart-net-service.bat” ini bkin LAN jd gag kebaca jd gag bs sharing data antar pc… gmna cara enable nya lagi??? mohon bantuannya.. thx