Hi,
While I scanned my client's network for trojans, I found that Windows ME
machines were shown having trojans at "PORT 5000 - Socket23". When I
checked for port 5000 for windows me, it shows as 'WindowsME ships with a
program called "SSDPSRV.EXE", or Simple Service Discover Protocol Server,
which is used for Universal Plug and Play. This process listens on TCP 5000
for XML exchange' in www.portsdb.org. But also there is a description for
this port as 'Sockets De Troie Trojan'. Should I ignore this as simply a
*indows problem, or take it serious as infected by trojans. FYI, They are
using Trend Micro's Office Scan to scan all the machines.
regards,
sheik