Assumng that you don't have Applix on the machine,
I would recommend virus scanning as this may likely be the keylogging service of the DeepThroat trojan.
Check also :6667 for trace of SubSeven.
Well, I would hope that the latest engine and pattern (455) for my Trend Micro ServerProtect virus scanner that is running on this particular machine would catch this.
I am not running Applix on this Win2K server (at least I do not think so). What is Applix and how can I check? Chuck, MCSE
I would advise firing up regedt32 and seeing if any strange programs are in the startup list (possibly systempatch.exe): HKLM\Software\Microsoft\Windows\CurrentVersion\Run
No Applix? If not you might want to block the tcp/udp 999 service with tcp filter/firewall as I am hard pressed to find any useful service other than Applix.
Have you tried the online virus scan yet?
FYI, other known SubSevens that use port 999 - f0replay & WinSatan.
Check the Run/RunServices keys in the reg under HKCU hive. Also check your CONFIG.SYS, AUTOEXEC.BAT, WINSTART.BAT, WIN.INI, for any strange apps loading.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.