Event ID - 21544

Port No21544
Service NameGirlFriend
RFC Doc0
ProtocolTCP
Description[trojan] GirlFriend
Reference LinkPort No:21544 Service Name: GirlFriend Protocol:TCP

ACTION
AttackStep 1. Click START | RUN
type REGEDIT and hit ENTER

Step 2. In the left window, click the "+" (plus sign) to the left of the following:
HKEY_LOCAL_MACHINE
Software
Microsoft
Windows
CurrentVersion
Run

Step 3. In the right window, look for a key that loads a file called "windll.exe".

Step 4. In the right window, highlight the key that loads the file and hit the DELETE key. Answer YES to delete the entry.

Step 5. Exit the Registry

Step 6. Reboot your computer

Step 7. After the computer has restarted, open Windows Explorer

Step 8. Go to the WINDOWS directory and look for the "windll.exe" file. Once you've found the file, DELETE it.

Step 9. Exit Windows Explorer and reboot your computer.

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.