Event ID - 5512

Port No5512
Service NameIllusion Mailer
RFC Doc0
ProtocolTCP
DescriptionIllusion is a trojan that allows the person with the server to send email. That's all it can do. It is anonymous because the server's IP is sent with the email not the person who is really sending it.
Reference LinkIllusion Mailer Trojan
AttackIt autoloads the Registry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Key: Sysmem

It does the following :
Send anonymous email

Removal :
1. Remove the Sysmem key located in the registry at: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run. Which can be done with regedit or any other registry editing program.
2. Reboot the computer or close memory.exe.
3. Delete the trojan file memory.exe in the windows system directory.

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.