Re: Is this a trojan tryng to send a message out ?

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



On Fri, 26 May 2006 20:51:54 +0200, "Dave Neve"
<NoAddressForSpammers@xxxxxxxx> wrote:

Hi

I suspect that I have got a trojan in my computer after having downloaded a
freebie.

My anti virus warned me and I got rid of it with SmitfraudFix.

But when I start up, the suspected program still tries to send a message out
thru IE.

The details (according to Kerio firewall) are

Distant Localhost 127.0.0.1 Port 1038
Distant details TCP local port 1039 and 1040

What surprises me are the local host adresses but I don't really know much
about TCP protocol.

Is this really an outgoing call or just some sort of legitimate activity at
startup for this software.

The software has no real reason to access Internet as it is just a type of
keyboard shortcut software (but I wonder if it is actually logging keyboard
activity?)

Thanks in advance

Dave Neve

PS I did try the IE group but surprisingly had little help


Whatever it is you did not get rid of it, probably is a trojan but
even if it is innocent you still need to ensure your PC is not
compromised.

Try this link - courtesy of David J Lipman who is one of the best
security posters around.

http://claymania.com/removal-trojan-adware.html

and go and have a look at

microsoft.public.security.homeusers

There are many posts in there with great anti malware advice Tell them
exactly what the malware is reported as and you will get a more
specific answer.

IE group? nobody with any sense uses IE any more for general
browsing 8-) get Firefox and add the "noscript" enhancement.

Jonah
.



Relevant Pages

  • A problem with a process CRCAB.exe
    ... Can anyone shed light on the CRCAB.exe process - what is it and how do I get ... rid of it (I suspect its a trojan) ...
    (microsoft.public.security.virus)
  • Re: A problem with a process CRCAB.exe
    ... | Can anyone shed light on the CRCAB.exe process - what is it and how do I get ... | rid of it (I suspect its a trojan) ... Another way to submit is to send the suspect file to the following email address ...
    (microsoft.public.security.virus)
  • Re: Ilomo trojan-regscan- how do I zap this thing?
    ... 64bit drivers for the computer internal hardware. ... may try triple boot with XPpro, ... gotten rid of it or not. ... the Trojan gets installed again and opens the ...
    (microsoft.public.win2000.general)
  • Re: Ilomo trojan-regscan- how do I zap this thing?
    ... gotten rid of it or not. ... and rings you find here and there about getting rid of this Trojan and you ... are no renamed Windows files on that server that will open it up as soon ... message saying they are in use and new temp files immediately appear with ...
    (microsoft.public.win2000.general)
  • Re: Ilomo trojan-regscan- how do I zap this thing?
    ... gotten rid of it or not. ... rings you find here and there about getting rid of this Trojan and you think ... renamed Windows files on that server that will open it up as soon as you ... message saying they are in use and new temp files immediately appear with ...
    (microsoft.public.win2000.general)