Event ID - 12346

Port No12346
Service NameNetBus
RFC Doc0
ProtocolTCP
DescriptionNetBus can be placed on your system in the same way as Back Orifice, and the same rules about programs and installers applies here as well. 99% of the time NetBus is gotten when you download a program from the internet, be it a freeware game on your friends webpage, to a members only warez ftp site... It can be an exe installer of itself, OR can be hidden inside a REAL setup.exe, usually planted in it and totally separate from whomever released the actual program.
Reference LinkMore Information
AttackName:NetBus

BO can be removed by deleting the server and removing its registry entry. If possible, you should back up all user data, format your hard drive, and reinstall all operating systems and software on the infected machine. However, if someone has installed BO on your machine, then it is most likely part of a larger security breach. You should act according to your site security policy.

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.