Rocksolid Light

Welcome to Rocksolid Light

mail  files  register  newsreader  groups  login

Message-ID:  

Gary Hart: living proof that you *can* screw your brains out.


computers / alt.comp.os.windows-10 / Re: remote control software ?

SubjectAuthor
* remote control software ?T
`* remote control software ?Paul
 `- remote control software ?T

1
remote control software ?

<ulavdk$3s3e6$1@dont-email.me>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=76534&group=alt.comp.os.windows-10#76534

  copy link   Newsgroups: alt.comp.os.windows-10
Path: i2pn2.org!i2pn.org!paganini.bofh.team!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: T@invalid.invalid (T)
Newsgroups: alt.comp.os.windows-10
Subject: remote control software ?
Date: Tue, 12 Dec 2023 16:55:16 -0800
Organization: A noiseless patient Spider
Lines: 11
Message-ID: <ulavdk$3s3e6$1@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Wed, 13 Dec 2023 00:55:16 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="194f3480da2f46a87f5f4e0b7f76393a";
logging-data="4066758"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18DeJxJvJX3r1nSdclR9T/Y5xKHAy1Zi2I="
User-Agent: Mozilla Thunderbird
Cancel-Lock: sha1:O0peMhh6pxXPenMp8K2s2HcwXTQ=
Content-Language: en-US
 by: T - Wed, 13 Dec 2023 00:55 UTC

Hi All,

Anyone know of a scanner/utility that will hunt
down and identify all forms of remote assistance/control
software installed on Windows? Things like Secure Connect,
Any Desk, Go to Assist, etc..

Anti Virus products seem to ignore this threat.

Many thanks,
-T

Re: remote control software ?

<ulba3h$19gl$1@dont-email.me>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=76536&group=alt.comp.os.windows-10#76536

  copy link   Newsgroups: alt.comp.os.windows-10
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: nospam@needed.invalid (Paul)
Newsgroups: alt.comp.os.windows-10
Subject: Re: remote control software ?
Date: Tue, 12 Dec 2023 22:57:36 -0500
Organization: A noiseless patient Spider
Lines: 60
Message-ID: <ulba3h$19gl$1@dont-email.me>
References: <ulavdk$3s3e6$1@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 8bit
Injection-Date: Wed, 13 Dec 2023 03:57:37 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="aa7d14016488b5c5bec1def84bbc2aeb";
logging-data="42517"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19Sb+Vody3keBT9F/UeE9cZjA8lpvuRjzg="
User-Agent: Ratcatcher/2.0.0.25 (Windows/20130802)
Cancel-Lock: sha1:lxyPmqUmzPfozylThdxNoZTOeZE=
Content-Language: en-US
In-Reply-To: <ulavdk$3s3e6$1@dont-email.me>
 by: Paul - Wed, 13 Dec 2023 03:57 UTC

On 12/12/2023 7:55 PM, T wrote:
> Hi All,
>
> Anyone know of a scanner/utility that will hunt
> down and identify all forms of remote assistance/control
> software installed  on Windows?  Things like Secure Connect,
> Any Desk, Go to Assist, etc..
>
> Anti Virus products seem to ignore this threat.
>
> Many thanks,
> -T

They use the word "RAT" for that kind of software.

This page will put up some hard-to-read license terms, before you
can copy the text. Not the best-coded website I've ever seen,
but we cannot let that stop us.

https://www.ninjaone.com/blog/detect-remote-access-software-using-powershell/

This is a slightly-edited list of the RATs it looks for. I tried
to shorten the lines a bit, so it won't scroll off the end of the
screen quite as bad. The lines need to be left as is, in the
actual script.

$RemoteToolList = @(
["AeroAdmin"; ProcessName = "AeroAdmin" }
["Ammyy Admin"; ProcessName = "AA_v3" }
["AnyDesk"; DisplayName = "AnyDesk"; ProcessName = "AnyDesk"; ExecutablePath = "AnyDesk\AnyDesk.exe" }
["BeyondTrust"; DisplayName = "Remote Support Jump Client", "Jumpoint"; ProcessName = "bomgar-jpt" }
["Chrome Remote Desktop"; DisplayName = "Chrome Remote Desktop Host"; ProcessName = "remoting_host"; ExecutablePath = remoting_host.exe }
["Connectwise Control"; DisplayName = "ScreenConnect Client"; ProcessName = "ScreenConnect.ClientService" }
["DWService"; DisplayName = "DWAgent"; ProcessName = "dwagent","dwagsvc"; ExecutablePath = "DWAgent\runtime\dwagent.exe" }
["GoToMyPC"; DisplayName = "GoToMyPC"; ProcessName = "g2comm", "g2pre", "g2svc", "g2tray"; ExecutablePath = g2comm.exe, g2pre.exe, g2svc.exe, g2tray.exe }
["LiteManager"; DisplayName = "LiteManager Pro - Server"; ProcessName = "ROMServer", "ROMFUSClient"; ExecutablePath = ROMFUSClient.exe, ROMServer.exe }
["LogMeIn"; DisplayName = "LogMeIn"; ProcessName = "LogMeIn"; ExecutablePath = LogMeIn.exe, LogMeInSystray.exe }
["ManageEngine"; DisplayName = "ManageEngine Remote Access Plus - Server", "ManageEngine UEMS - Agent"; ProcessName = "dcagenttrayicon", "UEMS", "dcagentservice"; ExecutablePath = dcagenttrayicon.exe, UEMS.exe, dcagentservice.exe }
["NoMachine"; DisplayName = "NoMachine"; ProcessName = "nxd", "nxnode.bin", "nxserver.bin", "nxservice64"; ExecutablePath = nxd.exe, nxnode.bin, nxserver.bin, nxservice64.exe }
["Parsec"; DisplayName = "Parsec"; ProcessName = "parsecd", "pservice"; ExecutablePath = parsecd.exe, pservice.exe }
["Remote Utilities"; DisplayName = "Remote Utilities - Host"; ProcessName = "rutserv", "rfusclient"; ExecutablePath = rfusclient.exe }
["RemotePC"; DisplayName = "RemotePC"; ProcessName = "RemotePCHostUI","RPCPerformanceService"; ExecutablePath = RemotePCHostUI.exe, RPCPerformanceService.exe }
["Splashtop"; DisplayName = "Splashtop Streamer"; ProcessName = "SRAgent", "SRAppPB", "SRFeature", "SRManager", "SRService"; ExecutablePath = SRService.exe }
["Supremo"; ProcessName = "Supremo", "SupremoHelper", "SupremoService"; ExecutablePath = SupremoService.exe}
["TeamViewer"; DisplayName = "TeamViewer"; ProcessName = "TeamViewer", "TeamViewer_Service", "tv_w32", "tv_x64"; ExecutablePath = TeamViewer.exe, TeamViewer_Service.exe, tv_w32.exe, tv_x64.exe }
["TightVNC"; DisplayName = "TightVNC"; ProcessName = "tvnserver"; ExecutablePath = tvnserver.exe }
["UltraVNC"; DisplayName = "UltraVNC"; ProcessName = "winvnc"; ExecutablePath = WinVNC.exe }
["VNC Connect (RealVNC)"; DisplayName = "VNC Server"; ProcessName = "vncserver"; ExecutablePath = vncserver.exe }
["Zoho Assist"; DisplayName = "Zoho Assist Unattended Agent"; ProcessName = "ZohoURS", "ZohoURSService"; ExecutablePath = ZohoURS.exe, ZohoURSService.exe }
["Atera"; DisplayName = "AteraAgent"; ProcessName = "AteraAgent"; ExecutablePath = AteraAgent.exe }
["Automate"; DisplayName = "Connectwise Automate"; ProcessName = "LTService", "LabTechService"; SpecialExecutablePath = "C:\Windows\LTSvc\LTSvc.exe"}
["Datto RMM"; DisplayName = "Datto RMM"; ProcessName = "AEMAgent"; ExecutablePath = AEMAgent.exe, gui.exe }
["Kaseya"; DisplayName = "Kaseya Agent"; ProcessName = "AgentMon", "KaseyaRemoteControlHost", "Kasaya.AgentEndpoint"; ExecutablePath = AgentMon.exe }
["N-Able N-Central"; DisplayName = "Windows Agent"; ProcessName = "winagent"; ExecutablePath = winagent.exe }
["N-Able N-Sight"; DisplayName = "Advanced Monitoring Agent"; ProcessName = "winagent"; ExecutablePath = winagent.exe, winagent.exe }
["Syncro"; DisplayName = "Syncro","Kabuto"; ProcessName = "Syncro.App.Runner"... ; ExecutablePath = Syncro.Service.Runner.exe, Syncro.App.Runner.exe }
)
}

Paul

Re: remote control software ?

<ulbe38$1o0t$1@dont-email.me>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=76537&group=alt.comp.os.windows-10#76537

  copy link   Newsgroups: alt.comp.os.windows-10
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: T@invalid.invalid (T)
Newsgroups: alt.comp.os.windows-10
Subject: Re: remote control software ?
Date: Tue, 12 Dec 2023 21:05:44 -0800
Organization: A noiseless patient Spider
Lines: 39
Message-ID: <ulbe38$1o0t$1@dont-email.me>
References: <ulavdk$3s3e6$1@dont-email.me> <ulba3h$19gl$1@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
Injection-Date: Wed, 13 Dec 2023 05:05:45 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="194f3480da2f46a87f5f4e0b7f76393a";
logging-data="57373"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18jT3KrEiyD/SrgqFjdWm3YGqCO8ZCha6w="
User-Agent: Mozilla Thunderbird
Cancel-Lock: sha1:QSZZD+jW3qUrNk/ZL9FV/sbvB0M=
Content-Language: en-US
In-Reply-To: <ulba3h$19gl$1@dont-email.me>
 by: T - Wed, 13 Dec 2023 05:05 UTC

On 12/12/23 19:57, Paul wrote:
> On 12/12/2023 7:55 PM, T wrote:
>> Hi All,
>>
>> Anyone know of a scanner/utility that will hunt
>> down and identify all forms of remote assistance/control
>> software installed  on Windows?  Things like Secure Connect,
>> Any Desk, Go to Assist, etc..
>>
>> Anti Virus products seem to ignore this threat.
>>
>> Many thanks,
>> -T
>
> They use the word "RAT" for that kind of software.
>
> This page will put up some hard-to-read license terms, before you
> can copy the text. Not the best-coded website I've ever seen,
> but we cannot let that stop us.
>
> https://www.ninjaone.com/blog/detect-remote-access-software-using-powershell/
>
> This is a slightly-edited list of the RATs it looks for. I tried
> to shorten the lines a bit, so it won't scroll off the end of the
> screen quite as bad. The lines need to be left as is, in the
> actual script.
>

Paul! Dude! You are awesome!!! Thank you!

It caught my AnyDesk as soon as I ran it.

It does need
Set-ExecutionPolicy Unrestricted ("A" for all)
to run before it.

-T

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor