I’ve got Outpost firewall- my SVCHOST.exe service is properly configured, but I keep getting messages about it using port 1027 and accessing random addresses every time, both TCP & UDP protocols. The weird thing is, these addresses trace to some Chinese & other ISPs and sites. These pop-ups come up while I’m browsing the Internet- no P2P or any other net app open.
My DNS & DHCP is perfectly set-up in the firewall-but if I BLOCK access to port 1027, then my internet connection stops working. There are no trojan-like entries in msconfig or Startup, and no weird processes open in task manager. I’ve scanned with Avast (is it effective vs trojans, anyways?), nothing.
So basically, I’m wondering if this is a trojan because 1) the weird sites it traces to 2) if I block the traffic, my connection dies although everything is configured as Agnitum Outpost suggests, including my DHCP/DNS ip’s.
Help much appreciated. Thanks.