Event ID - 1025

Port No1025
Service NameNetSpy
RFC Doc0
ProtocolTCP
DescriptionNetSpy 0.6.98 Build A is made to look like an installer for SysProtect 98. It is able to encrypt transfers between the client and server. This trojan is from 1998 and probably is not used anymore
Reference LinkNetSpy
AttackIt Autoloads: Registry: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Key: SysProtect

Features:

File manager
Hide/show start menu
Hide/show task bar
Shutdown computer
Sleep

Fix:
Remove the SysProtect key in the registry located at HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run Which can be done with regedit or any other registry editing program.
Reboot the computer or close system.exe.
Delete the trojan file system.exe in the windows system directory

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.