CommView Remote Agent

CommView Remote Agent is a potentially dangerous tool that captures network traffic on any computer. It also monitors remote network traffic.

General information:

Malware Name: CommView Remote Agent
Malware Type: Potentially Dangerous Tool
Company Name: TamoSoft
Company URL: http://tamos.com/
Threat Level: Low Risk
Operating System: WIN XP
Installation Type: Installed through EXE
Operation: Time of After Installation

Company Description:

TamoSoft provides you the software CommView Remote Agent that is an application for remote network traffic monitoring. It allows CommView users to capture network traffic on any computer where Remote Agent is running, regardless of the computer s physical location. This technology broadens your horizons: you are no longer limited by your LAN segment or personal computer.

Spyware Description:

CommView Remote Agent is a potentially dangerous tool that captures network traffic on any computer. It also monitors remote network traffic.

Characteristics/Symptoms:

    -> It captures network traffic on any computer. -> It also monitors remote network traffic.

Additional information might be found here:

google Search at Google for CommView Remote Agent
bing Search at Bing for CommView Remote Agent
yahoo Search at Yahoo for CommView Remote Agent

Processes Running:

Console.exe

File information Created after Installation:

File Location Size (Bytes) Type
C:\Program Files\CommRA\amd64\ts_lb.sys 28704 System file
C:\Program Files\CommRA\amd64\tscomm.sys 50984 System file
C:\Program Files\CommRA\amd64\tsnotify.dll 57128 Application Extension

Folder information Created after Installation:

Folder Location
C:\Program Files\CommR
C:\Program Files\CommRA\amd6

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CommView Remote Agent UninstallString
HKEY_LOCAL_MACHINE \SYSTEM\ControlSet001\Services\CommViewAgent
HKEY_LOCAL_MACHINE \SYSTEM\ControlSet001\Services\CommViewAgent FailureActions