Event ID - 16969

Port No16969
Service NamePriority
RFC Doc0
ProtocolTCP
DescriptionPriority Beta is a simple visual basic trojan. Being in the beta form not all the features were finished, such as the ftp server. An earlier version of this was stolen and released as SK-Silencer by SmithKlan. Apparently they hex edited it and put their names in it. Other then that nothing interesting with this trojan
Reference Link Priority
AttackIt Autoloads: Registry: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\ Key: PServer

Features:

Beep
BlackOut
Client chat
Close server
Disconnect
Double click
Get number of connected clients
Hide task bar
ICQ PassJack
Lock mouse
Minimize applications
Moving button
Open web page
Open/Close Cd-Rom
Ping pong
Play sound
Run application
Screen saver
Send keys
Send message
Server chat
Show image
Shutdown
Swap mouse buttons
Task manager
Win PassJack

Fix:
Remove the PServer key in the registry located at HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices. Which can be done with regedit or any other registry editing program.
Reboot the computer or close PServer.exe.
Delete the trojan file PServer.exe in the windows system directory

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.