Event ID - 22456

Port No22456
Service NameTrojanDropper
RFC Doc0
ProtocolTCP
DescriptionThis TrojanDropper drops backdoor programs. It also modifies the registry to enable its automatic execution on every Windows startup.
Reference LinkTrojanDropper
AttackSolution:
On Windows 9x/NT

Click Start>Find>Files and Folders.
In the Named input box, type:
winforce.exe
In the Look In drop-down list, select the drive which contains Windows then press Enter.
Delete the file once located. Perform the same procedures for these files:
eb.exe
WinntBB.exe
nono.exe
srv_portscan.dll
srv_pwinfo.dll
Shell32.exe
KERNEL32.DLL
On Windows 2000/ME/XP

Click Start>Search>For Files and Folders.
In the Search for files and folders named input box, type:
winforce.exe In the Look In drop-down list, select the drive which contains Windows then press Enter.
Delete the file once located. Perform the same procedures for these files:
eb.exe
WinntBB.exe
nono.exe
srv_portscan.dll
srv_pwinfo.dll
Shell32.exe
KERNEL32.DLL

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.