I think I may have a trojan on my computer because twice in the past couple of months, my connection status window has told me that I had recieved 4-5,000 packets of information, but I’ve sent out 2 million packets of info one time and 4.2 million packets of info today. I have cable and can only think that my computer has been hijacked to send spam under my nose. Normally, I send out approximately the same number of packets I recieve in a regular session.
The Earthlink (www.earthlink.net) website has a very small program which does a 10 second scan and tells me I have a trojan, but I can’t believe that a 10 second scan from their website will show that.
On the other hand, I have installed and used Spybot, The Cleaner, and Trojan Cleaner. Scanning with all these usually takes about 10 minutes, and they’ve all come up clean.
Is there something in my registry that I can manually check to see if I’m harboring Trojans? I figure that if that Earthlink program is working, all it’s doing is checking registry changes.
Use ctrl+alt+del to check the active tasks. If you don’t know what they are, google the names. If anything on the list doesn’t look innocent, google on instructions for removing it.
Now, if it is a clever trojan or not running when you check the tasks, install a personal firewall. You want one that checks incoming and outgoing packets. Norton makes one.
Firewalls generally come preconfigured with rules that won’t get in your way for incoming traffic. It’s the outgoing filter that is going to help you. The firewall will prompt you whenever anything tries to send through any port. It will identify the program name, service and port and ask what it should do: allow, allow once, deny, deny once, etc…
It may be annoying the first few sessions you are surfing the web, but very shortly you end up with a set of rules that lets you do everything you need to do.
I have a hardware firewall. It doesn’t seem to let me configure it in anyway. And I had to completely uninstall my configurable software firewall before I could install my hardware firewall.
Regarding active tasks, what are the differences between tasks that are used by:
SYSTEM
LOCAL SERVICE
NETWORK SERVICE ?
I have multiple SVCHOST.EXE processes that are used by the above 3 users. Could that be the problem?
Read the brand name on the package? (Sorry, I coudln’t resist :))
All kidding aside, I don’t know if you have a trojan or not, but this site offers a free 30 day trial of trojan hunter, which works wonderfully well. http://www.misec.net/trojanhunter/