Skip to main content

Rootkit:W32/Necurs

Classification

Category:

Malware

Type:

Rootkit

Aliases:

  • Rootkit.Necurs

Summary

Rootkit:W32/Necurs is a standalone malware that was first seen in 2011, but gained more prominence once it started being used in the Gameover Zeus botnet.

Removal

Technical Details

Rootkit:W32/Necurs is a kernel-mode driver component that can be used by an attacker (or added as component to another malicious program) to perform unauthorized actions to take control of an operating system, without alerting the system's security mechanisms.

According to published research, the Necurs rootkit was incorporated in late 2014 into the Gameover Zeus botnet as a protective mechanism, preventing attempts by the user to remove the malware from an infected machine. The addition of the standalone Necurs rootkit to an existing threat operated by another party (and analysis of the rootkit's code, which appears to be suitable for such use) has lead to it being considered 'crimeware for hire'.

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.