Hi,
We have an issue whereby some files have been deleted by a local user account with (according to the watch logs) Source: 254.128.0.0 [254.128.0.0]
I expected to see an internal or external IP address if it was a real user
Have searched for the Ip and seen reference to
UDP 254.128.0.0:50046 : 2192 svchost.exe
Am I looking at a virus/trojan?
Thanks
Pete