HKTL_NETVIEW
Windows 2000, Windows XP, Windows Server 2003
Threat Type: Hacking Tool
Destructiveness: No
Encrypted: No
In the wild: Yes
OVERVIEW
This hacking tool is a command-line program that may perform certain routines.
This hacking tool may be manually installed by a user.
TECHNICAL DETAILS
51,712 bytes
EXE
No
03 Aug 2011
Lists shares on a remote computer or in a domain
Arrival Details
This hacking tool may be manually installed by a user.
Installation
This hacking tool drops the following non-malicious file:
- %Current%\result.txt
NOTES:
It is a command-line program that may perform the following:
- List the shares on a remote computer or in a domain
It has the following syntax:
- {malware file name}.exe "command | ips"
The data may then be stored to the created file.
SOLUTION
8.900
1.204.03
03 Aug 2011
Step 1
For Windows ME and XP users, before doing any scans, please make sure you disable System Restore to allow full scanning of your computer.
Step 2
Search and delete these files
- %Current%\result.txt
Step 3
Scan your computer with your Trend Micro product to delete files detected as HKTL_NETVIEW If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check this Knowledge Base page for more information.
Did this description help? Tell us how we did.