Event ID - 47891

Port No47891
Service NameAntiLamer BackDoor
RFC Doc0
ProtocolTCP
DescriptionSevere risk threats are typically installed without user interaction through security exploits, and may allow an attacker to remotely control the infected machine. Such threats may allow the attacker to install additional malware and use the compromised machine to participate in denial of service attacks, spamming, and bot nets, or to transmit sensitive data to a remote server. The malware may be cloaked and not visible to the user. These threats severely compromise the system by lowering security settings, installing “backdoors,” infecting system files, or spreading to other networked machines.
Reference LinkMore INformation
AttackName:AntiLamer BackDoor

How To Remove:
1. End running tasks:
alb.exe
backdoor.antilam.20.a.exe
editor.exe
edtsrv.exe
new_alb.exe
server.exe

2. Unregister DLLs:
edit.dll

3. Remove files:
alb.exe
backdoor.antilam.20.a.exe
edit.dll
editor.exe
edtsrv.exe
new_alb.exe
readme.txt
server.exe

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.