Event ID - 29891

Port No29891
Service NameThe unexplained
RFC Doc0
ProtocolTCP
DescriptionThe Unexplained trojan is a Visual Basic trojan. This trojan has very few features and is most likely not used
Reference LinkThe unexplained
AttackIt Autloads: Registry: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ Key: InetB00st

Features:

Delete file
Ping server
Reboot
Spawn program
Upload file

Fix:
Remove the InetB00st key in the registry located at HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run Which can be done with regedit or any other registry editing program.
Reboot the computer or close the file in the InetB00st key
Delete the trojan file in the InetB00st key in the windows directory

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.