Event ID - 4000

Port No4000
Service NameW32.Witty.Worm
RFC Doc0
ProtocolUDP
DescriptionThis signature detects the propogation of W32.Witty.Worm
Reference LinkPort Number:4000 Service Name:W32.Witty.Worm Port:UDP
AttackAccording to Symantec

Resolution:
Because the worm resides in memory only and is not written to disk, virus definitions do not detect this threat. Symantec Security Response recommends that you follow the steps described below to deal with this threat.
1. Obtain the patch for the vulnerability from http://blackice.iss.net/update_center/index.php.
2. Disconnect the affected system from the network.
3. Reboot the system to remove the threat from memory.
4. Apply the patch.
5. Reconnect to the network

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.