G
Graham Love
All,
The following is from Norton Personal firewall:-
Rule "Default Block Netspy Trojan horse" stealthed (localhost,1024)
Inbound TCP connection
Local address,service is (0.0.0.0,1024)
Remote address,service is (localhost,3012)
Process name is "C:\WINDOWS\Explorer.EXE"
but Norton AV does not detect anything int he file 'c:\windows\explorer.exe'
I have tried other anti-trojan software and several report that
'explorer.exe' is listening on port 1024.
My question
Is this a genuine infection or a false-positive?
What are the specific symptoms of the netspy trojan?
If it is genuine, how can I get rid of it?
What should the correct version number be for WinXP sp1?
thanks
Graham
The following is from Norton Personal firewall:-
Rule "Default Block Netspy Trojan horse" stealthed (localhost,1024)
Inbound TCP connection
Local address,service is (0.0.0.0,1024)
Remote address,service is (localhost,3012)
Process name is "C:\WINDOWS\Explorer.EXE"
but Norton AV does not detect anything int he file 'c:\windows\explorer.exe'
I have tried other anti-trojan software and several report that
'explorer.exe' is listening on port 1024.
My question
Is this a genuine infection or a false-positive?
What are the specific symptoms of the netspy trojan?
If it is genuine, how can I get rid of it?
What should the correct version number be for WinXP sp1?
thanks
Graham