We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Backdoor:Win32/Ryknos.A
Detected by Microsoft Defender Antivirus
Aliases: No associated aliases
Summary
Backdoor:Win32/Ryknos.A is a backdoor Trojan that targets computers running certain versions of Microsoft Windows. The Trojan opens a backdoor on the infected computer to receive commands from attackers. If the rootkit VirTool:WinNT/F4IRootkit is already installed on the target computer, the Trojan uses the rootkit to hide.
It is best to use up-to-date antivirus software to remove Backdoor:Win32/Ryknos.A as well as rootkit VirTool:WinNT/F4IRootkit from your computer. To recover from these threats using antivirus software, follow these steps:
-
Run up-to-date antivirus software.
-
Take steps to prevent re-infection.
Run up-to-date antivirus software
You can use the online antivirus scanner at the Microsoft Safety Scanner Web site to detect and remove Backdoor:Win32/Ryknos.A, VirTool:WinNT/F4IRootkit, and other malicious software from your computer.
Take steps to prevent re-infection
Do not reconnect your computer to the Internet until the computer is protected from re-infection. See the "Preventing Infection" section for more information.”