rutserv.exe

Remote Manipulator System

Usoris Systems

The application rutserv.exe by Usoris Systems has been detected as a potentially unwanted program by 16 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “TektonIT - R-Server”.
Publisher:
TektonIT  (signed by Usoris Systems)

Product:
Remote Manipulator System

Description:
RMS

Version:
5.5.2.0

MD5:
14886f6d81641714968551754f2827bd

SHA-1:
006a4370d0672b19fc04f69394afe9fe586f4fb1

SHA-256:
adf483c823340e43dcea48bfc9f24da5014915fc3cb7a9aae10d60efab39b838

Scanner detections:
16 / 68

Status:
Potentially unwanted

Analysis date:
7/13/2025 12:14:27 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.12477334
269

Agnitum Outpost
Riskware.RemoteAdmin.DK
7.1.1

Arcabit
Trojan.Generic.DBE6396
1.0.0.425

Bitdefender
Trojan.Generic.12477334
1.0.20.660

Bkav FE
W32.HfsAdware
1.3.0.7133

Dr.Web
Program.RemoteAdmin.785
9.0.1.0132

Emsisoft Anti-Malware
Trojan.Generic.12477334
8.16.05.11.06

ESET NOD32
Win32/RemoteAdmin.RemoteUtilities.D potentially unsafe (variant)
10.12147

Fortinet FortiGate
Riskware/Agent
5/11/2016

F-Secure
Trojan.Generic.12477334
11.2016-11-05_4

G Data
Trojan.Generic.12477334
16.5.25

K7 AntiVirus
Unwanted-Program
13.2016995

Kaspersky
not-a-virus:RemoteAdmin.Win32.Agent
14.0.0.229

McAfee
Artemis!14886F6D8164
5600.6403

MicroWorld eScan
Trojan.Generic.12477334
17.0.0.396

nProtect
Trojan.Generic.12477334
15.08.25.01

File size:
5.7 MB (6,004,992 bytes)

Product version:
5.5.2.0

Copyright:
Copyright © 2013 TektonIT. All rights reserved.

Trademarks:
Remote Manipulator System, TektonIT

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\remote manipulator system - host\rutserv.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/11/2013 3:00:00 AM

Valid to:
2/12/2014 2:59:59 AM

Subject:
CN=Usoris Systems, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Usoris Systems, L=Victoria, S=Mahe, C=SC

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
67FD5AEC0D8F9F6F1CAA40589F568A0C

File PE Metadata
Compilation timestamp:
6/30/2013 7:32:53 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:W2EIikmqPOWnSocKhFQSSnzqqvIwYHklYggFLsCLOZBeO2RKbGryiQyTQTvvxlfV:W2EIidqP3beP8oZQO2RKaryiQVYUy4

Entry address:
0x4C1348

Entry point:
55, 8B, EC, 83, C4, F0, B8, D4, 9C, 8A, 00, E8, 00, E2, B4, FF, E8, 6F, 74, FE, FF, E8, 8A, 88, B4, FF, 8B, C0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
4.8 MB (4,981,248 bytes)

Service
Display name:
TektonIT - R-Server

Service name:
RManService

Description:
Allows Remote Manipulator System users to connect to this machine.

Type:
Win32OwnProcess


Remove rutserv.exe - Powered by Reason Core Security