Event ID - 121

Port No121
Service NameJammer Killah
RFC Doc0
ProtocolTCP
DescriptionJammer Killah 1.2 is a trojan that is suppose to kill the Jammer program. This program detects back orifice and netbus. Then it drops a Back Orifice 1.20 server. The server is configured on port 121 with password hack.
Reference LinkJammer Killah Trojan
AttackIt autoloads the Registry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices Key: MsWind32drv

It does the following :
Back Orifice 1.20 features

Removal :
1.Remove the MsWind32 key in the registry located at HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices Which can be done with regedit or any other registry editing program.
2. Reboot the computer or close MsWind32.drv.
3. Delete the trojan file MsWind32.drv in the windows directory

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.