Event ID - 7307

Port No7307
Service Nameswx
RFC Doc0
ProtocolTCP
Descriptionswx.'the swiss exchange'
Remote Process Monitor
NetMonitor
NetMonitor
Reference LinkMore Information
AttackName:NetSpy (0.6.98 Build A), Remote Process Monitor

Server Features
1. File manager
2. Hide/show start menu
3. Hide/show task bar
4. Shutdown computer
5. Sleep

Comments:
NetSpy 0.6.98 Build A is made to look like an installer for SysProtect 98. It is able to encrypt transfers between the client and server. This trojan is from 1998 and probably is not used anymore.

How To Remove:
1. Remove the SysProtect key in the registry located at HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run Which can be done with regedit or any other registry editing program.
2. Reboot the computer or close system.exe.
3. Delete the trojan file system.exe in the windows system directory

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.