Event ID - 1049

Port No1049
Service Nameinitd
RFC Doc0
ProtocolTCP
DescriptionUpon execution, this worm drops a copy of itself in the Windows system folder as INITD.EXE. It creates registry entries to ensure its execution every system startup.
Reference Linkinitd trojan port
AttackSOLUTION :
AUTOMATIC REMOVAL INSTRUCTIONS
To automatically remove this malware from your system, please use Trend Micro Damage Cleanup Template / Engine.

MANUAL REMOVAL INSTRUCTIONS
Identifying the Malware Program
To remove this malware, first identify the malware program.
1.Scan your system with your Trend Micro antivirus product.
2.NOTE all files detected as WORM_RBOT.PAB .
Trend Micro customers need to download the latest pattern file before scanning their system. Other users can use Housecall, Trend Micro's online virus scanner.

Terminating the Malware Program
This procedure terminates the running malware process.
1.Open Windows Task Manager.
• On Windows 95, 98, and ME, pressCTRL+ALT+DELETE
• On Windows NT, 2000, and XP, pressCTRL+SHIFT+ESC, then click the Processes tab.
2.In the list of running programs*, locate the process:Initd.exe
3.Select the malware process, then press either the End Task or the End Process button, depending on the version of Windows on your system.
4.To check if the malware process has been terminated, close Task Manager, and then open it again.
5.Close Task Manager.

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.