Event ID - 10001

Port No10001
Service Namequeue
RFC Doc0
ProtocolTCP
Descriptionrscs1
Reference LinkMore Information
AttackName:Dtr

DTR is a backdoor program that enables intruder to remotely manage files, exchange and rename files, start programs, review running processes, scan a screen through a shell interface and deliver that system's information to the user of the Trojan, conduct keyboard spying and key stroke logging, and reboot and shutdown systems. This Trojan has a simple GUI.

How To Remove:
1. Open the registry editor (Click Start > Run, type regedit).
2. Navigate to the following key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run 3. In the right pane, delete the following entries:

nbsession
nbsystem.exe

4. Close registry editor.
5. Reboot the computer.
6. Search and delete the file Nbsystem.exe from the System foler ( by default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000/XP)) Search and delete the file DtrIVk.dll from Windows folder( (by default this is C:\Windows or C:\Winnt) ).

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.