W64/Necurs.F!tr.rkit

description-logoAnalysis

W64/Necurs.F!tr.rkit is classified as a rootkit trojan.
A rootkit trojan is a type of malware that has privileged access on the computer. It is usually a device driver program that is designed to hide the existence of other malware on the infected system.
The Fortinet Antivirus Analyst Team is constantly updating our descriptions. Please check the FortiGuard Encyclopedia regularly for updates.

recommended-action-logoRecommended Action

  • Make sure that your FortiGate/FortiClient system is using the latest AV database.
  • Quarantine/delete files that are detected and replace infected files with clean backup copies.

Telemetry logoTelemetry

Detection Availability

FortiGate
Extreme
FortiClient
Extended
FortiMail
Extended
FortiSandbox
Extended
FortiWeb
Extended
Web Application Firewall
Extended
FortiIsolator
Extended
FortiDeceptor
Extended
FortiEDR

Version Updates

Date Version Detail
2021-06-15 86.00934
2021-03-31 85.00106
2019-09-10 71.50800 Sig Updated
2019-08-10 70.62600 Sig Added
2018-10-23 63.14400 Sig Updated
2018-10-02 62.64000 Sig Added