Content

HTool-OpenTS

Type
Program
SubType
Tool
Discovery Date
02/11/2009
Minimum DAT
5524 (02/12/2009)
Updated DAT
5525 (02/13/2009)
Minimum Engine
5.2.00
Description Added
02/11/2009
Description Modified
02/11/2009 2:27 PM (PT)

Tab Navigation

Characteristics

This application can accept command line or scripted options for a terminal services port number and may open a port to listen. This is accomplished by creating a .reg file during execution and importing it into the registry.

The command line options may appear like the below:

 

These key/value pair modifications have been observed after execution:

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\Tds\tcp
    "PortNumber"=dword:[hex value]
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp
    "PortNumber"=dword:[hex value]
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server
    "fDenyTSConnections"=dword:0

Other variants of this application have been observed to make outbound FTP connections to remote sites such as 86.21.[edited].

Removal

Instructions on Enabling/Disabling Detection and Removal of Potentially Unwanted Programs

Use the ADD/REMOVE Programs Control Panel in Windows to remove this program.

Aliases

Aliases

    N/A