PDA

View Full Version : RAT.Remoter


Terravita
December 29th, 2003, 02:54 AM
I keep getting this message in TDS-3.

Scan Control Dumped @ 13:25:10 28-12-03
RegVal Trace: RAT.Remoter: HKEY_LOCAL_MACHINE
File: SOFTWARE\Microsoft\Windows\CurrentVersion\Run [Taskman=C:\Program Files\Task Man 1.5\TASKMAN.EXE]

I have uninstalled Taskman, cleaned the registry and reinstalled Taskman. Why do I keep getting this message?

Gavin - DiamondCS
December 30th, 2003, 08:44 AM
Hi,

What is Task Man ?

This is a registry TRACE value, which was left over by a machine infected with "Remoter". If you have a legitimate application that uses that startup name, please send an email to gavin@diamondcs.com.au with the URL to the legitimate program. I'll remove the trace detection, you can ignore it for now :)

Terravita
January 1st, 2004, 11:30 PM
I downloaded Taskman 1.5 from the DiamondCS Freeware page:

TaskMan+
TaskMan+ is a free tiny utility that launches Windows Task Manager in a special way as to boost the security privileges of Task Manager, which in turn gives it a real unconditional license to terminate ANY process. Requires Administrator privileges

I downloaded a fresh copy and installed it. I still get the message in my original post.

Jooske
January 1st, 2004, 11:57 PM
Hello Terravita
Which operating system are you using?
Did you get the message immediately after the first install of Taskman+ or did it start after a while suddenly?

Terravita
January 2nd, 2004, 02:17 AM
Jooske

I am running XP Pro with all updates. I have been using TaskMan for several months. This error started suddenly, the same day or the day before posting my message.

Along with TDS-3, I am using WormGuard, RegProt, ProcessGuard, Port Explorer, Ad-aware, Ad-watch, Spybot, PC-cillin 2003, ZoneAlarmPro, and BOCLEAN. Except for PC-cillian, I am running the current release on all software.