Event ID - 29976

Port No29976
Service NameSpirit 2001a
RFC Doc0
ProtocolTCP
DescriptionTrojan Spirit 2001a beta and version 1.20 monitors Transmission Control Protocol (TCP) port 33911 for an incoming connection, while other versions may use a different port. The Trojan Spirit Server could allow remote attackers to perform malicious actions.
Reference LinkMore Information
AttackName:Spirit 2001a

Manual removal:
1. Remove the Internet key located in the registry at: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\. Which can be done with regedit or any other registry editing program. And the run=c:\windows\netip.exe located at under [windows] in the win.ini. Which can be done with any text editing program.
2. Reboot the computer or close netip.exe Delete the trojan file netip.exe in the windows directory

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.