Event ID - 31557

Port No31557
Service NameXanadu
RFC Doc0
ProtocolTCP
DescriptionXanadu 1.1 is a trojan from 1999. Xanadu comes is sent like a setup package (setup.ini, setup.ins, etc), however all the files except setup.exe (the trojan server) are 0 kilobytes
Reference LinkXanadu
AttackAutoloads: Registry: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices Key: Setup

Features:
Change pc name
Change resolution
Change various policies
Change volume
Crazy mouse on/off
File manager
Get cached passwords
Get info
Get screen saver password
Get/set clipboard
Hide/show cursor
Hide/show desktop
Hide/show task bar
Key logger
Open/close CD-Rom
Print text
Registry manager
Send keys
Send message
Send to URL
Show picture
Swap mouse buttons
iew/close processes

Fix:
Remove the SETUP key in the registry located at HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices Which can be done with regedit or any other registry editing program.
Reboot the computer or close SETUP.exe.
Delete the trojan file SETUP.exe in the windows directory

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.