We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
VirTool:Win95/Macpro.A
Detected by Microsoft Defender Antivirus
Aliases: No associated aliases
Summary
VirTool:Win95/Macpro.A is a virtual device driver that hides files and folders on computers running Windows 9x.
To recover manually from VirTool:Win95/Macpro.A, follow these steps:
- Disconnect from the Internet.
- Delete the Trojan file.
- Restart your computer.
- Take steps to prevent re-infection.
Disconnect from the Internet
To help ensure that your computer is not actively infecting other computers, disconnect it from the Internet before proceeding. Print this Web page or save a copy on your computer; then unplug your network cable and disable your wireless connection. You can reconnect to the Internet after completing these steps.
Delete the Trojan file
To delete the Trojan file
- Click Start, and click Run.
- In the Open field, type %windir%\VirtualMGR, for example, C:\Windows\VirtualMGR
- Click OK.
- Click Name to sort files by name.
- If the file mnc128.vxd is in the list, delete it.
- On the Desktop, right-click the Recycle Bin and click Empty Recycle Bin.
- Click Yes.
If deleting the file fails, follow these steps to verify that the Trojan is not present:
- Press CTRL+ALT+DEL once and click Task Manager.
- Click Processes and click Image Name to sort the running processes by name.
- Confirm that mnc128.vxd is not in the list.
Restart your computer
To restart your computer
- On the Start menu, click Shut Down.
- Select Restart from the drop-down list and click OK.
Take steps to prevent re-infection
Do not reconnect your computer to the Internet until the computer is protected from re-infection. See the "Preventing Infection" section for more information.