Risk

RiskWare.NetSupport.RAT information

Malware Removal

The RiskWare.NetSupport.RAT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RiskWare.NetSupport.RAT virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Authenticode signature is invalid

How to determine RiskWare.NetSupport.RAT?


File Info:

name: 8D9709FF7D9C83BD376E.mlw
path: /opt/CAPEv2/storage/binaries/49a568f8ac11173e3a0d76cff6bc1d4b9bdf2c35c6d8570177422f142dcfdbe3
crc32: 2904524F
md5: 8d9709ff7d9c83bd376e01912c734f0a
sha1: e3c92713ce1d7eaa5e2b1fabeb06cdc0bb499294
sha256: 49a568f8ac11173e3a0d76cff6bc1d4b9bdf2c35c6d8570177422f142dcfdbe3
sha512: 042ad89ed2e15671f5df67766d11e1fa7ada8241d4513e7c8f0d77b983505d63ebfb39fefa590a2712b77d7024c04445390a8bf4999648f83dbab6b0f04eb2ee
ssdeep: 384:qTjV5+6j6Qa86Fkv2Wr120hZIqeTSGRp2TkFimMP:qHVZl6FhWr80/heT8TkFiH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10EA3854F428DE173EA52E93DC8859B040D50BDC8B5B058FB01AEF27E3E7278D6B6415A
sha3_384: 9afd9804e070876b90fa7236cdd22bcabf9eaade83de96f7435b9bdf2dd3539ce2037b91f797684b9a5075e31f4e0d9a
ep_bytes: 558bec83ec4456ff15002040008bf08a
timestamp: 2015-07-31 14:42:28

Version Info:

Comments:
CompanyName: NetSupport Ltd
FileDescription: NetSupport Client Application
FileVersion: V12.10
InternalName: client32
LegalCopyright: Copyright (c) 2015, NetSupport Ltd
LegalTrademarks:
OriginalFilename: client32.exe
PrivateBuild: V12.10
ProductName: NetSupport Manager
ProductVersion: V12.10
SpecialBuild:
Translation: 0x0809 0x04b0

RiskWare.NetSupport.RAT also known as:

LionicRiskware.Win32.NetSupport.1!c
MicroWorld-eScanApplication.RemoteAdmin.NetSupport.A
SkyhighPUP-RemoteAdmin.a
McAfeePUP-RemoteAdmin.a
MalwarebytesRiskWare.NetSupport.RAT
ZillyaTool.NetSup.Win32.9
AlibabaRiskWare:Win32/NetSup.f4fc8ee0
ArcabitApplication.RemoteAdmin.NetSupport.A
Paloaltogeneric.ml
Kasperskynot-a-virus:RemoteAdmin.Win32.NetSup.i
BitDefenderApplication.RemoteAdmin.NetSupport.A
EmsisoftApplication.RemoteAdmin.NetSupport.A (B)
DrWebProgram.RemoteAdmin.837
VIPREApplication.RemoteAdmin.NetSupport.A
FireEyeApplication.RemoteAdmin.NetSupport.A
JiangminRemoteAdmin.NetSup.s
GoogleDetected
VaristW32/Tool.EQYN-2153
Antiy-AVLGrayWare/Win32.Ta505
XcitiumApplicUnwnt@#3tkoudphjgdqt
ViRobotBackdoor.Win32.S.Agent.105848
ZoneAlarmnot-a-virus:RemoteAdmin.Win32.NetSup.i
GDataApplication.RemoteAdmin.NetSupport.A
ALYacMisc.Riskware.RemoteAdmin
MAXmalware (ai score=99)
Cylanceunsafe
YandexRiskware.RemoteAdmin!myez5VmqQPE
MaxSecureTrojan.Malware.115193137.susgen
FortinetRiskware/NetSup
DeepInstinctMALICIOUS

How to remove RiskWare.NetSupport.RAT?

RiskWare.NetSupport.RAT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment