Sorry for not giving enough info. The trojan is called sockets de troie or socket23. it uses port 5000. I found an old post here and someone was talking about a trojan that affects plug and play on the same port. He advised to disable plug and play. So i did that and did a port scan. That did close the port, but do I have a trojan? Or is this microsoft I have norton anti virus, it detects nothing. Also this port 139 worries me. I've tried telnet with no success. I'm using windows me and i don't run a network so i don't know why that port should be open. I guess i'm allright i installed zonealarm. Anywayz thanks for your help.