Event ID - 27184

Port No27184
Service NameAlvgusTrojan2000
RFC Doc0
ProtocolTCP
DescriptionThis application is a Remote Administration Tool (RAT), a Trojan that provides an intruder with the ability to remotely control a computer via a client on the intruder's machine and a “server" on the victim's machine. Often the intruder simply e-mails the RAT to the user along with a message that convinces the user to run the application. Alvgus Trojan 2000 is an updated version of Alvgus and requires the installation of the same files on both a user's computer and an intruder's computer. The intruder can then influence and control the user's computer via a simple GUI (Graphical User Interface).
Reference LinkMore INformation
AttackName:AlvgusTrojan2000

How To Remove:
1. Kill the following processes
atclient.exe,
atserver.exe,
atserverfinder.exe,
sysbckup.exe,
systrayc.exe

2. Remove the following files
!_readme.txt,
atclient.exe,
atserver.exe,
atserverfinder.exe.
sysbckup.exe,
systrayc.exe in
Windows\system

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.