Virus

Riskware/NetFilter

Analysis



Riskware/NetFilter is a highly generic detection for a set of Riskware samples. Most of these samples are unwanted application and may carry undesirable components during installation. Since this is a generic detection, malware that are detected as Riskware/NetFilter may have varying behaviour.

  • Below are some samples of illustration we observed during the tests of several samples:

    • Figure 1: Installer.


    • Figure 2: Installer.


    • Figure 3: Installer.


    • Figure 4: Application.


    • Figure 5: Installer.


    • Figure 6: Installer.




Recommended Action

  • Make sure that your FortiGate/FortiClient system is using the latest AV database.
  • Quarantine/delete files that are detected and replace infected files with clean backup copies.