Event ID - 5031

Port No5031
Service NameNet Metropolitan
RFC Doc0
ProtocolTCP
DescriptionNet Metropolitan 1.00 does not actually appear to infect computers. So, once you reboot the server is no longer running
Reference LinkNetMetro
AttackFeatures:

Beep
Change resolution
Chat
Clip cursor
Close server
Control mouse
Disconnect from internet
Enable/Disable Al and Ctrl
File manager
Freeze screen with "The matrix has you"
Get how long windows has been running
Get ICQ passwords
Get keystrokes
Get screen shot
Get system info
Hide/show task bar
Open/Close Cdrom
Play Tic-tac-toe with server (and cheat!)
Read/set clipboard
Remove server
Send message box
Set cursor position
Set date and time
Shutdow/Restart/Suspend
Swap mouse buttons
View running applications

Fix:
Reboot the computer or close NMS.exe
Delete the trojan file NMS.exe in whatever directory you ran it in.

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.