As this has been resolved, I won't add that much other than ntscan, ipcscan, and sqlscan have been the most popular tools I have seen in windows honeynet research. They all function as TH13 has noted; by grinding against a box with a list of passwords. Typically the password that got them in to your box will be at the top of the list if you find it on your box. An attacker typically will break in to a box and start trying to spread their sphere of influence in a matter of moments.
These are pretty much a part of the standard l337 h4x0r toolkit containing things like fport, psinfo and the like(usually a kit of 8 executables).




