NetSupport Manager file reports

NetSupport Manager

NetSupport Manager is a product name observed in ThreatInfo file telemetry. This page groups the latest 60 files that reference this product name, including their detection status and direct file reports.

Review the listed files before removing anything: legitimate software can share product names with unwanted or repacked installers, while malicious files often reuse familiar product metadata to appear trustworthy.

Scan files associated with NetSupport Manager:

client32.exe 8d9709ff7d9c83bd376e01912c734f0a Risk.NetSupport
nskbfltr.sys 1c2143adeab91d77eb5a9624bd28b283 Under review
pcisys.sys 84dee0f25fe97868071202065dab63bb Under review
.exe 1c98de71e922fc70a7065ceda74902de Trojan.Downloader
MPGPH1.exe 1f58166ffd2a774f254754a44699b743 Trojan.Downloader
DE5E.exe bf8e896716a528d67a5e80c7fbfb8f3e Spy.Gen
RetailerRise[1].exe 4d372e1be38eff759f9908f5f1739aed General Threat
TCCTL32.DLL 60aea67e2659e1961369e04185c61adf Under review
remcmdstub.exe ba2a1815e16b357eeff23b8394457aa5 Trojan.Downloader
PCICHEK.DLL a0b9388c5f18e27266a31f8c5765b263 Under review
HTCTL32.DLL 2d3b207c8a48148296156e5725426c7f Under review
PCICL32.DLL 00587238d16012152c2e951a087f2cc9 Under review
AudioCapture.dll 4182f37b9ba1fa315268c669b5335dde Under review
pcicapi.dll dcde2248d19c778a41aa165866dd52d0 Under review
PCICL32.DLL ad51946b1659ed61b76ff4e599e36683 Risk.RemoteAdmin
remcmdstub.exe 5be6fb8f28544d4f83c25a2b76ff7890 Trojan.Wacatac
HTCTL32.DLL 051cdb6ac8e168d178e35489b6da4c74 Under review
PCICHEK.DLL 3aabcd7c81425b3b9327a2bf643251c6 Under review
pcicapi.dll 67c53a770390e8c038060a1921c20da9 Under review
TCCTL32.DLL 1e6e804ca71eaf5bef0abef95c578cf0 Under review
AudioCapture.dll 7629af8099b76f85d37b3802041503ee Under review
client32.exe c4f1b50e3111d29774f7525039ff7086 Trojan.Wacatac
PCICL32.DLL e7b92529ea10176fe35ba73fa4edef74 Under review
nskbfltr.sys 2a92dbd1f05200f3d615637d3833c333 Risk.NetSupport
PCICL32.DLL d3d39180e85700f72aaae25e40c125ff Risk.RemoteAdmin
HTCTL32.DLL c94005d2dcd2a54e40510344e0bb9435 General Threat
TCCTL32.DLL 2c88d947a5794cf995d2f465f1cb9d10 General Threat
pcicapi.dll 34dfb87e4200d852d1fb45dc48f93cfc Risk.RemoteAdmin
PCICHEK.DLL 104b30fef04433a2d2fd1d5f99f179fe Risk.RemoteAdmin
TCCTL32.DLL eab603d12705752e3d268d86dff74ed4 Under review
client32.exe 89c9658f6400c13c74a9d59020af7fa1 Risk.NetSupport
keyshowhook.dll a4efc55ac7c2738fbee2b14cfdc6a8be Under review
AudioCapture.dll b80352b6383cb32d2e157d01a02b3e10 Under review
TCCTL32.DLL 16be802bf8272c578ab54ba47449ca2e Under review
PCICL32.DLL 878c3b8b0549fb86b254c22e7ad46b66 Under review
nsmexec.exe fe8e4505101cdb3d041553bbb4dc8b34 Risk.NetSupport
nsmres.dll d1789a79a7655c5d17368bd53d0e7726 Under review
keyshow.exe 510cff5a7ff87307f0f755b81368ff72 Risk.NetSupport
KeyShowHook64.dll 27109b6126ae154a2532ec8f366e4572 Under review
PCIHOOKS.DLL ed102071aaf904579a53df0601d5686e Under review
nskbfltr2.sys fe21de1984a1db19d520f01badae7087 Under review
pcivideovi.exe 19dee9286a3c13a8164ad47b0b7dcc93 Risk.NetSupport
remcmdstub.exe 961ceda609b7f5a1e31385386b20adc4 Risk.NetSupport
PciHooks64.dll 6d22d3208f7983ad4f5635fdc6e4e567 Under review
ismetro.exe 986bab6148eb6d6b0555d46c14ebb226 Risk.NetSupport
gdihook5.sys 9a348ed02f8b1efc9bfc5f53827f8a9c Under review
injlib.dll ecc50d8e4abe9af83d1b701b45bd0eaa Under review
PCIRES.dll fc44cfdd2ed93726e05c9931157e13e7 Under review
DBI.EXE 90c030b3f7dad73ffe4b2f5d700a3450 Risk.NetSupport
WINSTALL.EXE 8e1646bfdf53364f3e612d0ff7609143 Risk.NetSupport
gdihook5.dll 52b88eb20beb3b34a692a4cae0ff2196 Under review
DeskDup.dll d1f61d00b743782f3eefc29b47606d45 Under review
winst64.exe 29665b400bdf1c1a30178865a38fcb3c Risk.NetSupport
supporttool.exe 02738c3a0986fc5aecc197c6784e630e Risk.NetSupport
PCICTL.DLL 030e0ae12f30a29d9bb7238262462d16 Under review
pciinv.dll 7b462f2971ce809f4acdddaa2446442e Under review
PCICHEK.DLL 4e60882b59c95e74230400a546084550 Under review
clhook4.dll 38935db0dd061269b7d79a1d287e750c Under review
pcicfgui.exe a11a6cb44d01ad5f539c3b02381c9cf5 Risk.NetSupport
pcicapi.DLL 42bf403c096b00463ca2b4928f9a88df Under review