Event ID - 9872

Port No9872
Service NamePortalofDoom
RFC Doc0
ProtocolTCP
DescriptionPortal of Doom
Reference LinkMore Information
AttackName:Portal of Doom

Server Features:
1. Beep
2. File explorer
3. File manager
4. Hide task bar
5. Key logger
6. Kill/Show windows
7. Move mouse Open file
8. Open/Close Cd-Rom
9. Red box
10. Screen saver
11. Send text
12. Shutdown
13. Steal passwords
14. Sticky caps
15. Swap mouse buttons

Comments
Portal of Doom V.3 is a old trojan made by the old Hack City. This is a beta version of the trojan. Our version did not write to the registry, but it is suppose to.

How To Remove
1. Remove the String key in the registry located at HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices Which can be done with regedit or any other registry editing program.
2. Reboot the computer or close ljsgz.exe.
3. Delete the trojan file ljsgz.exe in the windows system directory

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.