Q: The server has the following system log
Windows has detected that an application is listening for incoming traffic.
Name:-
Path: C:\WINDOWS\system32\svchost.exe
Process identifier: 752
User account: Network SERVICE
User domain: NT authority
Service: Yes
RPC Server: No
IP version: IPv4
IP protocol: UDP
Port number: 57214
Allowed: No
Notify user of: No
For more information, see Help and support in http://go.microsoft.com/fwlink/events.asp
Excuse me, my server has this log, is not in the Trojan? Thank you!
For:
Based on the information you provide, we recommend that you check the log information on the server by doing the following:
1. On the server where the log information appears, click "Start"-"Run", enter CMD, and enter the command prompt.
2. Enter "Tasklist/svc", see Svchost.exe (728) The corresponding service is a normal system of services, such as: Dhcp,dnscache.
3. If it is a normal network service, you can safely ignore this information.
I hope my answer is helpful to you.