Event ID - 30947

Port No30947
Service NameIntruse
RFC Doc0
ProtocolTCP
DescriptionThis potentially destructive backdoor malware consists of a client and a server component. Once the server component is executed on a target system, it opens up several ports. This malware allows unauthorized remote users or hackers access to its infected computer via its opened ports and hence, compromises network security.
Through these ports, the hacker can manipulate and take advantage of the infected system using the client component. The client component has several features for use by remote users
Reference LinkINTRUSE
AttackSolution

Open Registry Editor by clicking Start>Run. At the Run prompts, type REGEDIT then hit the ENTER key.
In the left panel of the Registry Editor, double click to access the following:
HKEY_LOCAL_MACHINE>Software>Microsoft>Windows>
CurrentVersion>Run
In the right panel, look for and delete the registry entry "Wind" by right-clicking it and selecting Delete from the drop-down list.
Select YES when prompted.
Close Registry Editor.
Restart your computer.

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.