Forum Home
Press F1
 
Thread ID: 41787 2004-01-22 04:03:00 NetSpy Trojan somebody (208) Press F1
Post ID Timestamp Content User
209228 2004-01-22 04:03:00 I have a problem. Both my computers (running WinXP Home, with NAV 2003 and updated definitions) appear to be infected by the Netspy trojan. Norton Firewall's alert tracker tells me that it's blocking a trojan attack from port 3923, from localhost. I looked into the logs, and found that it was from the process "explorer.exe".

Therefore I **think** that both PCs are infected, as they were disconnected from the internet at the time, however on a home network. One is showing strange symptoms when using windows Explorer, My computer etc. is very slow response to right-clicking, and also very slow loading of pages.

I have decided that I will reformat the computer which is showing the slow symptoms, and leave this one (the other one which I think is infected, but showing no signs of problems at this stage) for a couple of days and see what happens. I have done a full system backup of important data, in case anything happens.

Is anybody able to offer me advice on this? I'm confused cos a manual scan of explorer.exe does not pick anything up.
somebody (208)
209229 2004-01-22 04:26:00 Hello Somebody.....

If you go to ...www.sysinfo.org/startuplist.....and enter it in tne search ,you will find 3or4 variations of this virus,and remedies for each.

Best of luck
DD.
dumdum (4965)
209230 2004-01-22 05:17:00 Here is a FIX (www.kephyr.com) for it, if you indeed do have it.
Also a trip to an online virus scanner (www.pandasoftware.com)
Pheonix (280)
209231 2004-01-22 19:52:00 Thanks guys. Based on your website link Phoenix, it appears that NetSpy is a program which has to be downloaded and installed - however, as I am the primary user of this PC, I would seriously doubt it, as no other users have the knowledge to install such software. I don't know whether this is a good thing or a bad thing, but I have not managed to find any trace of the trojan's suspect files on my PC. I am now wondering whether the IP was spoofed by the trojan, to make me think that my computer is infected?

At this stage I think reformatting would also be a good chance to get rid of all the annoying files clogging up the system which have been left by uninstalled trialware.
somebody (208)
209232 2004-01-22 21:08:00 I just use fix-it and reg cleaner to clear out all the debris left from uninstalled programs if things get too bad i just do a restore using a image backup created by drive image 2002 have all these on cd if needed kiwibeat (304)
209233 2004-01-22 22:58:00 Not sure if these will help with your Trojan, but they are great resources to add to your arsenal.

More features than the "windows task manager"
www.sysinternals.com

Identify processes running in the background without having to wade through pages of tech-kafubble.(unless you enjoy reading that stuff of course...lol)
www.liutilities.com
dchip (1426)
209234 2004-01-22 23:26:00 Thanks guys - i've formatted the computer, reinstalled windows, and all is working properly now. somebody (208)
1