Trojan

How to remove “Trojan:Win32/NetSupportRat.CCC!MTB”?

Malware Removal

The Trojan:Win32/NetSupportRat.CCC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/NetSupportRat.CCC!MTB virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/NetSupportRat.CCC!MTB?


File Info:

name: CAE30D83C66CCE4BBE07.mlw
path: /opt/CAPEv2/storage/binaries/99bb45530d3a0adfcfffd46ec1964d4df376c5cb577cae7d3ba9c9eac6a6b00f
crc32: C215D494
md5: cae30d83c66cce4bbe0779cf3bf6432d
sha1: 21dcc7fc82728ef69a34650a28d0e129af489482
sha256: 99bb45530d3a0adfcfffd46ec1964d4df376c5cb577cae7d3ba9c9eac6a6b00f
sha512: 6d7d506aa00649f84d001525dc37afa30558ca79ee12cb430bf56bdb38260321a8ed407fe6c04850add65d30c4fef2d5650427a945ba71021d1d7e56bdf4fe52
ssdeep: 196608:XqN5u06KN5hZnse0GziviT/4MQI8DOprMZjBvWMc7ZZb/sbvwZIKQmGS:aNHNbZnCvi74MQIEZjBv2ZbC+IKhp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DCC601217DE28577D72313318D1DF13972EDAAA01B3982CB57CC2F1D2E742A22A1567B
sha3_384: bc633bcd2b922ca32d5287b44c2a24977f3a335096bb53de9c4d4347a2401388080475545d711483e4627f605d4831db
ep_bytes: e8150c0000e94cfeffffcccccccccccc
timestamp: 2021-08-30 18:04:23

Version Info:

CompanyName: Hendrik Erz
FileDescription: A Markdown Editor for the 21st century.
FileVersion: 3.0.0
LegalCopyright: Zettlr is licensed under GNU GPL v3.
ProductName: Zettlr
ProductVersion: 3.0.0
Translation: 0x0409 0x04e4

Trojan:Win32/NetSupportRat.CCC!MTB also known as:

LionicTrojan.Win32.Agent.Y!c
MicroWorld-eScanTrojan.Generic.34192317
FireEyeTrojan.Generic.34192317
SkyhighArtemis!Trojan
ALYacTrojan.Generic.34192317
MalwarebytesGeneric.Malware/Suspicious
K7AntiVirusTrojan-Downloader ( 005abb6b1 )
AlibabaTrojanDownloader:Win32/NetSupportRat.6230917c
K7GWTrojan-Downloader ( 005abb6b1 )
ArcabitTrojan.Generic.D209BBBD
VirITTrojan.Win32.Genus.TIN
SymantecTrojan.Gen.MBT
tehtrisGeneric.Malware
ESET-NOD32Win32/TrojanDownloader.Rugmi.AAN
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderTrojan.Generic.34192317
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.13f0c6cd
EmsisoftTrojan.Generic.34192317 (B)
F-SecureTrojan.TR/Dldr.Rugmi.pudcs
DrWebTrojan.DownLoader46.21810
VIPRETrojan.Generic.34192317
TrendMicroTROJ_GEN.R002C0XJ523
SophosMal/Generic-S
GoogleDetected
AviraTR/Dldr.Rugmi.pudcs
Antiy-AVLTrojan/Win32.Sonbokli
MicrosoftTrojan:Win32/NetSupportRat.CCC!MTB
ZoneAlarmHEUR:Trojan.Win32.Agent.gen
GDataTrojan.Generic.34192317
VaristW32/ABRisk.CRSZ-4717
AhnLab-V3Malware/Win.Generic.C5496605
McAfeeArtemis!CAE30D83C66C
MAXmalware (ai score=88)
VBA32BScope.Trojan.Penguish
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002C0XJ523
IkarusTrojan-Downloader.Win32.Rugmi
MaxSecureTrojan.Malware.771626.susgen
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Trojan:Win32/NetSupportRat.CCC!MTB?

Trojan:Win32/NetSupportRat.CCC!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment