Event ID - 30103

Port No30103
Service NameNSSX
RFC Doc0
ProtocolUDP
DescriptionIt will drop NSSX.EXE in c:\windows\system and NSSX.DLL in c:\windows, assumed you have a server on your computer.
Reference LinkNSSX
AttackDetails:

This is a remote control type Trojan. Similar to the wide spread BackOrifice program, it has the ability to do the following:
1. Know what application(s) you are running.
2. Send you a message / chat with you(this may come in as a warning, error, or other type of message box).
3. Modify or copy files in your system.
4. Internet connection, pop-up URL connection, redirect your out port.
5. Download Key log/send Keys to your system.
6. Access your modem.
7. Modify your mouse properties.
8. Capture screen, change its resolution, and turn ON/OFF the monitor.
9. Access email system.
10. Check and change password settings.
11. Shut down, logoff, or kill CPU.
12. Collect computer information, record sounds, edit registry.
13. Send mail as an anonymous mailer.

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.