Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations IamaSherpa on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

nuuhxuie - a trojan?

Status
Not open for further replies.

rmeleiro

IS-IT--Management
May 24, 2005
4
PT
Hello all
For the last couple of days my company's network has experienced slowdowns in http traffic and even denial of service for users. Tracking down from router and firewall logs, we've found that a single computer running Windows XP SP2 in the network was resopnsible for this: it had a program running (albeit a trojan) running under the name nuuhxuie and issuing DCOM calls through port 135 to several hundred ip addresses in several countries. Checking msconfig, that program was setup to run on startup, although no entry was found anywhere in the registry. I have foun absolutely no reference to this anywhere (eventually the name is randomly generated). Does anyone have any ideas on what it could be?

TIA

Rui Meleiro
 
Thank you for the tip. The truth of the matter is that this program, besides placing itself in the \windows\prefetch area, registers itself as an exception to SP2 firewall and neither Symantec Enterprise, AVG, Avast, AdWare, Microsoft A/S detects them. The major payload is such that it "eats" out the available bandwidht.
 
The machine has been quarantined and we'll take some of our already scarce time to investigate deeper. Thank you for the tip to rootkit.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top