Event ID - 20034

Port No20034
Service NameNetBus Pro
RFC Doc0
ProtocolTCP
DescriptionAdded a few new features. That's about all for this version
Reference Linknetbus pro
AttackIt Autloads: Registry: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Runservices\ Key: Netbus Server Pro

Features:

Admin controls (Remove, close server and set password)
Allow certain IPs only to connect
App Redirect
Broadcast vCapture screen
Capture camera video
Change mouse
Change open window info (Title bars, position, etc)
Change the wave, synth and CD sound balance
Chat with server
Click key
Control mouse
Disable keys
Exit windows
File manager
Get cached passwords
Get screen shot
Get the user account info
Listen for keystrokes
Open file
Open/Close Cd-Rom
Open/Close Cd-Rom in intervals
Patch server before sending
Play sound
Port Redirect
Print file
Record from server microphone
Registry editor
Remote control of the server
Run program
Run program
Scan for servers
Schedule commands
Send message
Send server to URL
Send text
Show image
Swap mouse buttons
View/close running windows

Fix:
Remove the Netbus Server Pro key in the registry located at HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Runservices Which can be done with regedit or any other registry editing program
Reboot the computer or close the program.
Delete the trojan file which is listed in the registry key.

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.