Event ID - 7000

Port No7000
Service NameRemote Grab
RFC Doc0
ProtocolTCP
DescriptionRemote grab 1.0 has one feature. That feature is to capture the screen of the host computer. It appears to overwrite the existing Mprexe.exe in the windows system directory
Reference LinkRemote Grab
AttackFeatures:

Gets screen shot of server computer

Fix:
Replace the Mprexe.exe in the Windows System directory with the real windows Mprexe.

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.