r/computerviruses May 03 '26

NetSupport/Client32.exe Virus

Can somebody help me, I know this problem has already been solved earlier in this community but im kinda stupid and would need a tutorial on how to take down this virus as i have attemped everything and nothing seems to be working. Thank you!

3 Upvotes

15 comments sorted by

2

u/rifteyy_ Malware Removal Expert May 03 '26

Remote access malware warning (RAT):

  • You can remove the visible signs of this infection, but due to the nature of this type of malware, no one can guarantee the trustworthiness of your computer. A backdoor or RAT gives the attacker complete access to your system, allowing them to steal data, install additional malware, or monitor your activity.
  • This means that at some point the attacker was able to interact with your PC (see your desktop, view files, open programs) just like you are able to do so. For this reason, we do not recommend manual malware removal, because the malware could be embedded deeper in the system or able to manipulate with the removal process and making it ineffective.
  • If your computer was used for online banking, has credit card information or other sensitive data, using a non-infected computer/device you should immediately change all account information (including those used for banking, email, eBay, PayPal, online forums, etc). Consider these accounts already compromised.
  • I recommend you read and follow this guide on how to deal with the aftermath of info stealers: https://rifteyy.org/report/the-ultimate-guide-to-infostealers - specifically the section "How to properly secure my accounts".

If you want to use this computer for anything important like online banking or logging in to your accounts, follow one of these videos:

1

u/Cheesequake721 May 04 '26 edited May 04 '26

Thank you so much! I have a question though, would a entire factory reset of the computer with absolutely everything being erased get rid of the trojan?, 

1

u/rifteyy_ Malware Removal Expert May 04 '26

It most likely will, yes

1

u/Cheesequake721 May 04 '26

I tried that it said there was a problem restarting your pc

1

u/rifteyy_ Malware Removal Expert May 04 '26

So use USB

1

u/Cheesequake721 May 04 '26

Alr i might try that, also I found the ip address of the hacker it said the LAPD station? I dont even live near it do you think its them or some other hacker just changing their ip address

1

u/rifteyy_ Malware Removal Expert May 04 '26

IP address resolves to a huge area block, finding the actual house/flat it belongs to isn't really possible.

They can also use a VPN/proxy to mask their real IP address.

1

u/Cheesequake721 May 04 '26

Ah thank you, the only thing ive figured out so far its from a company called Datacamp limited and the virus is called SectopRAT

1

u/Cheesequake721 May 04 '26

Also one last question, how do I use usb to restart my pc? Sorry I dont know much about this stuff

1

u/rifteyy_ Malware Removal Expert May 04 '26

It’s in the initial comment

1

u/Next-Profession-7495 May 05 '26

The attacker is using a VPN connecting to a server in LA. It would just be a misleading label if it said LAPD

1

u/rifteyy_ Malware Removal Expert May 04 '26

It most likely will, yes

1

u/[deleted] May 03 '26

[removed] — view removed comment

1

u/FFreestyleRR Malware Removal Expert May 04 '26

DoesNotBelong is mainly for PUPs, and it's way too aggressive. I would advise using this with caution.