Event ID - 7301

Port No7301
Service NameNetMonitor
RFC Doc0
ProtocolTCP
DescriptionNetMonitor
NetMonitor
swx.'the swiss exchange'
Reference LinkMore Information
AttackName:NetSpy (0.6.98 Build A)

Server Features
1. File manager
2. Hide/show start menu
3. Hide/show task bar
4. Shutdown computer
5. Sleep

Comments:
NetSpy 0.6.98 Build A is made to look like an installer for SysProtect 98. It is able to encrypt transfers between the client and server. This trojan is from 1998 and probably is not used anymore.

How To Remove:
1. Remove the SysProtect key in the registry located at HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run Which can be done with regedit or any other registry editing program.
2. Reboot the computer or close system.exe.
3. Delete the trojan file system.exe in the windows system directory

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.