Event ID - 48512

Port No48512
Service NameArctic
RFC Doc0
ProtocolTCP
DescriptionThis malicious parasite is a backdoor trojan, which usually acts by infecting the system as an attachment from various e-mail messages and giving the anonymous hacker a remote control over infected machine. This technique is really dangerous for everyone, because the hacker is able to steal user's passwords, messages and other confidential information.
Reference LinkMore Information
AttackName:Arctic

Properties

Allows remote user connection
. Sends out logs by FTP or email
. Logs keystrokes
. Connects itself to the internet
. Hides from the user
. Stays resident in background

How To Remove:
1. Kill processes:
rundll16.exe, arctic.exe, server.exe

2. Delete files:
rundll16.exe, arctic.exe, server.exe

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.