Event ID - 1967

Port No1967
Service Namesns-quote
RFC Doc0
ProtocolTCP
DescriptionForYourEyesOnly
Reference LinkMore Information
AttackName:WM FTP Server

WM FTP Server is a Delphi FTP server. The trojan listens on port 1967 and allows anyone to connect with a FTP client

Manual removal:
1. Remove the Microsoft Corporation key in the registry located at HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run Which can be done with regedit or any other registry editing program.
2. Reboot the computer or close mssystem98.exe.
3. Delete the trojan file mssystem98.exe in the windows directory.

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.