Event ID - 12631

Port No12631
Service NameWhack Job
RFC Doc0
ProtocolTCP
DescriptionWorks on Windows 95, 98 and NT. The password is "ecoli".
Reference LinkWhack Job Trojan
Attack It autoloads the Registry: HLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices

It does the following :
1. Remote Access.
2.Trojan dropper Disguised as a fake game and installs a NetBus Pro server.

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.