Skip to content

Latest commit

 

History

History
78 lines (45 loc) · 5.12 KB

5-Windows-Tools.md

File metadata and controls

78 lines (45 loc) · 5.12 KB

MoSucker

MoSucker is a visual basic Trojan. MoSucker's edit server program. It has a client with the same layout as sub Seven's client.

MoSucker is a powerful backdoor-hacker's remote access tool. The backdoor renames NETSTAT.EXE to NETSTAT.OLD when it is first activated and renames the file back when it is uninstalled. The backdoor also can install itself in a system with modification of startup keys in the Registry or INI files.

https://anonfile.com/90ZeF1Ifn7/MoSucker_zip

mosucker

ProRat

ProRat is a Remote Administration Tool written in C, and capable of working with all Windows OS.

ProRat was designed to allow users to control their own computers remotely from other computers. However, attackers have co-opted it for their own nefarious purposes. Some hackers take control of remote computer systems to conduct a denial of service (DoS) attack, which renders the target system unavailable for normal personal or business uses.

https://anonfile.com/V4x6GfI8nb/ProRat_zip

prorat

Theef

Theef is a Windows-based application for both client and server. The Theef server is a virus that you install on a target computer, and the Theef client is what you then use to control the virus.

Theef is a Remote Access Trojan written in Delphi, which gives remote attackers system access via port 9871.

https://anonfile.com/faf0H8I7na/Theef_zip

theef

JPS Virus Maker Tool

JPS Virus Maker is a tool to create viruses. It also has a feature for converting a virus into a worm.

https://anonfile.com/b4A1x0J6ne/JPS_Virus_Maker_zip

jps

Internet Worm Maker Thing

Internet Worm Maker Thing is an automated scripting tool used to generate malicious code. It enables you to specify criteria down to the most basic element, including the action you want it to perform, it display language, and its launch date.

https://anonfile.com/x9Y9x8J6nf/IWMT_zip

iwmt

Regshot

The purpose of this software is to compare your registry at two separate points by creating a snapshot of the registry before any system changes or when programs are added, removed, or modified and then taking a second snapshot after the modifications then comparing them.

Regshot is a great utility that you can use to compare the amount of registry entries that have been changed during an installation or a change in your system settings. It is a great tool for troubleshooting and monitoring your registry.

https://sourceforge.net/projects/regshot/

regshot

WinPatrol

WinPatrol is a computer monitoring utility used to protect files and folders from any unwanted changes.

http://www.winpatrol.com/download.html

winpatrol

TCPView

TCPView is a Windows program that will show you detailed listings of all TCP and UDP endpoints on your system, including the local and remote addresses and state of TCP connections. On Windows Server 2008, Vista, and XP, TCPView also reports the name of the process that owns the endpoint. TCPView provides a more informative and conveniently presented subset of the Netstat program that ships with Windows. The TCPView download includes Tcpvcon, a command-line version with the same functionality.

https://docs.microsoft.com/en-us/sysinternals/downloads/tcpview

tcpview

Autoruns

This utility, which has the most comprehensive knowledge of auto-starting locations of any startup monitor, shows you what programs are configured to run during system bootup or login, and when you start various built-in Windows applications like Internet Explorer, Explorer and media players. These programs and drivers include ones in your startup folder, Run, RunOnce, and other Registry keys. Autoruns reports Explorer shell extensions, toolbars, browser helper objects, Winlogon notifications, auto-start services, and much more. Autoruns goes way beyond other autostart utilities.

https://docs.microsoft.com/en-us/sysinternals/downloads/autoruns

autoruns

ClamWin

ClamWin is a Free Antivirus program for Microsoft Windows 10 / 8 / 7 / Vista / XP / Me / 2000 / 98 and Windows Server 2012, 2008 and 2003. ClamWin Free Antivirus is used by more than 600,000 users worldwide on a daily basis. It comes with an easy installer and open source code. You may download and use it absolutely free of charge.

http://www.clamwin.com/

clamwin