Event ID - 4321

Port No4321
Service NameBoBo
RFC Doc0
ProtocolTCP
DescriptionWorks on Windows 95 and 98. Looks very much as a copy of Back Orifice 1.20. BoBo 2.0 and later are viewed as shareware.
Reference Link BoBo Trojan
AttackIt autoloads the Registry:
HLM\Software\Microsoft\Windows\CurrentVersion\Run HKEY_USER\.Default\Software\Mirabilis\ICQ\Agent\Apps\ICQ Accel\

It does the following :
Remote Access

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.