Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Apr 12, 2024 | Updated Sep 21, 2025

TrojanDownloader:JS/NetSupportRat!MTB

Detected by Microsoft Defender Antivirus

Aliases: No associated aliases

Summary

TrojanDownloader:JS/NetSupportRat!MTB is a JavaScript-based downloader that installs remote access malware version of NetSupport Manager's remote access tool while impersonating a remote access trojan (RAT). The delivery method of this threat is from hacked websites or fake web browser updates in which unsuspecting users have been enticed to launch the malicious JavaScript file. When the malicious JavaScript file is launched, the script installs the remote access tool, creating a means for unauthorized remote control, data theft, and lateral movement within the target networks.  

The "!MTB" suffix indicates a layer of detection completed on a machine learn model and takes advantage of a tree-based algorithm. MTB stands for "machine learning, tree-based," meaning that detection was generated using a tree-based algorithm, such as decision trees and random forests, that used some large dataset of malware properties. 

  • Disconnect from the network to prevent lateral movement or data exfiltration. 
  • Use Task Manager to end tasks related to wscript.exe, cscript.exe, or client32.exe. 
  • Delete registry keys under HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ 
  • Remove scheduled tasks created by Javascript. 
  • Erase all files in %AppData%\Roaming\ subdirectories, including client32.exe, DLLs, and configuration files. 
  • If critical files were modified, restore from clean backups after eradication. 

Microsoft Defender Antivirus automatically removes threats as they are detected. However, many infections can leave remnant files and system changes. Updating your antimalware definitions and running a full scan might help address these remnant artifacts. 

You can also visit our advanced troubleshooting page or search the Microsoft virus and malware community for more help. 

Follow us