Event ID - 25

Port No25
Service NameWinPC
RFC Doc0
ProtocolTCP
DescriptionWe belive WinPC to be a Password emailing trojan. We are not sure who the passwords or even what passwords are emailed.
Reference LinkWinPC
AttackAutoloads: Registry: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Key: Microsoft Corporation

Features:
Possible emailing of passwords

Fix:
Remove the load=winpc.exe key in the win.ini under [windows]. Which can be done with any other text editing program.
Reboot the computer or close winpc.exe.
Delete the trojan file winpc.exe in the windows directory

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.