Event ID - 33270

Port No33270
Service NameTrinity
RFC Doc0
ProtocolTCP
DescriptionThis worm spreads via network shares. It searches for and lists down shared folders, where it drops a copy of itself. It also generates IP addresses and drops copies of itself in specific shared folder. If the said shares are password-protected, it uses a list of user names and passwords hardcoded in its body to gain access.
Reference LinkTrinity trojan port
AttackSOLUTION :
Terminating the Malware Program
This procedure terminates the running malware process.
If the process you are looking for is not in the list displayed by Task Manager, proceed to the succeeding solution set.

1.Open Windows Task Manager.
• On Windows 98 and ME, pressCTRL+ALT+DELETE
• On Windows NT, 2000, XP, and Server 2003, pressCTRL+SHIFT+ESC, then click the Processes tab.
2.In the list of running programs*, locate the process: TASKMNEGR.EXE
3.Select the malware process, then press either the End Task or the End Process button, depending on the version of Windows on your system.
4.To check if the malware process has been terminated, close Task Manager, and then open it again.
5.Close Task Manager.

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.