custom-trojan scanner ?

Permabanned
Joined
19 Oct 2007
Posts
6,322
Location
.
Hi, im running win 7 64 ultimate.

I think someone has a trojan running on my PC, and if there is i know who this person is.

The reason I think this is several things have been happening.

1. Ill be watching something on media player classic and it will come out of fullscreen even though i didnt use the mouse or keyboard. In the bottom of the window it will say

"focus lost to start menu" or "focus lost to firefox.exe" or even "focus lost to c:\my documents\important\" etc.

Also, i tried running firefox having had my pc monitor off just now and it told me it was already running even though it wasnt on my taskbar, i had to end the process in task manager to get it to run again.

Ive done scans with all sorts of spybot and trojan scanners and they have found nothing.

Any ideas what i can do other than a complete re-install ? Nothing dodgy that i know of shows up on process or services...
 
There's loads on google about it, seems it's an issue with running dual screens and mpc, seems if you have mpc full screen on one monitor and something else running on the other it can cause mpc to loose focus and drop to windowed mode.

As for scans, grab the latest malwarebytes and run that.
 
Last edited:
Grab a copy of wireshark and run a capture when you have nothign network related open.

See if there's any traffic going out of your pc to somewhere it shouldn't be.
 
Disconnect from the network completely, watch a movie, if it happens then its not a RAT, if it doesn't wireshark network traffic while testing watching a movie. If there's traffic you can identify that doesn't seem right, run Rootkit Unhooker and report back.
 
A quick look over your logs doesnt show anything immediatly wrong, although it would take lots of time for a full analysis.

Looks like streaming of HD video from AKAMAI (maybe?) or streaming of lots of something and some visits to network analysis sites like networktools.nl, there are no obvious malicious connections that stand out.

I would suspect your problem is elsewhere, but if you have a suspicion it's a custom targeted trojan you should just format anyway.
 
Last edited:
Back
Top Bottom