We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Backdoor:Win32/Samsteal.A.dll
Detected by Microsoft Defender Antivirus
Aliases: No associated aliases
Summary
Backdoor:Win32/Samsteal.A.dll is a component of Backdoor:Win32/Samsteal.A. The .dll file is dropped by Backdoor:Win32/Samsteal.A.dr. It is used to log keystrokes and collect data from the Windows registry. This information is uploaded to certain Web sites or sent in e-mail attachments by Backdoor:Win32/Samsteal.A.
To recover manually from Backdoor:Win32/Samsteal.A.dll, follow these steps:
- Disconnect from the Internet.
- Perform the manual recovery steps for Backdoor:Win32/Samsteal.A.
- Delete the .dll file.
- Restart your computer.
- Take steps to prevent re-infection.
Disconnect from the Internet
To help ensure that your computer is not actively infecting other computers, disconnect it from the Internet before proceeding. Print this Web page or save a copy on your computer; then unplug your network cable and disable your wireless connection. You can reconnect to the Internet after completing these steps.
Perform the manual recovery steps for Backdoor:Win32/Samsteal.A
Follow the manual recovery instructions for the parent variant Backdoor:Win32/Samsteal.A.
Delete the .dll file
To delete the .dll file
- Click Start, and click Run.
- In the Open field, type %windir%\VirtualMGR, for example, C:\Windows\VirtualMGR
- Click OK.
- Click Name to sort files by name.
- If the files winsock.dll and winfw32.dat are in the list, delete them.
- On the Desktop, right-click the Recycle Bin and click Empty Recycle Bin.
- Click Yes to confirm the deletion.
Restart your computer
To restart your computer
- On the Start menu, click Shut Down.
- Select Restart from the drop-down list and click OK.
Take steps to prevent re-infection
Do not reconnect your computer to the Internet until the computer is protected from re-infection. See the "Preventing Infection" section for more information.