Event ID - 40071

Port No40071
Service NameDucktoy
RFC Doc0
ProtocolTCP
DescriptionBackdoor.Ducktoy.11 is related to Backdoor. Backdoor - parasite allowing hackers to pilot personal computer remotely without PC owner's agreement. Backdoor starts every time the computer is booted, stays in background and monitors your system. If you recognized Backdoor on your computer - remove it manually or use anti-spyware software to remove it.
Reference LinkMore Information
AttackName:Ducktoy

Manual Removal:
Follow these steps to remove DuckToy from your machine. Begin by backing up your registry and your system, and/or setting a Restore Point, to prevent trouble if you make a mistake.

1. Stop Running Processes:
ducktoy 1.1.1.exe
ducktoy 1.2.exe
ducktoy.exe
editor del server.exe
edit-server.exe
server.exe
systemroot+\explorer .exe
systemroot+\system36.exe


2. Remove Files:
ducktoy 1.1.1.exe
ducktoy 1.2.exe
ducktoy.exe
editor del server.exe
edit-server.exe
novedades.txt
server.exe
systemroot+\explorer .exe
systemroot+\system36.exe
upx leeme.txt

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.