HKTL_SPYBUILD
Information Stealer
Windows
Threat Type: Hacking Tool
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This hacking tool arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
Arrival Details
This hacking tool arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Dropping Routine
This hacking tool drops the following files:
- serveur.exe - detected as TSPY_IDRASTEAL.SM
NOTES:
The binary is a compiler and builder of malicious files, which can have the following capabilities:
- Steal information/credentials:
- Chrome passwords
- Windows serial key
- Paltalk credentials
- No-IP credentials
- FTP Commander credentials
- Filezilla credentials
- Coreftp credentials
- Minecraft account
- CD keys
- Pidgin credentials
- IMVU account
- FlashFXP account
- Dyndns credentials
- Clipboard data
- Keystrokes
- Desktop screenshot
- Delete or Disable file/information:
- Firefox cookies
- Anti-keylogger tools
- Autostart of compiled/built malware
SOLUTION
Step 1
Scan your computer with your Trend Micro product to delete files detected as HKTL_SPYBUILD. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check this Knowledge Base page for more information.
Step 2
Search and delete this file
*Note: The file name input box title varies depending on the Windows version (e.g. Search for files or folders named or All or part of the file name.).
• For Windows Vista, Windows 7, Windows Server 2008, Windows 8, Windows 8.1, and Windows Server 2012:
- Open a Windows Explorer window.
- For Windows Vista, 7, and Server 2008 users, click Start>Computer.
- For Windows 8, 8.1, and Server 2012 users, right-click on the lower left corner of the screen, then click File Explorer.
- In the Search Computer/This PC input box, type:
DATA_GENERIC - Once located, select the file then press SHIFT+DELETE to delete it.
*Note: Read the following Microsoft page if these steps do not work on Windows 7.
Did this description help? Tell us how we did.