We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
VirTool:WinNT/F4IRootkit.C
Detected by Microsoft Defender Antivirus
Aliases: No associated aliases
Summary
VirTool:WinNT/F4IRootkit.C is a kernel-mode rootkit used for copy protection on certain Sony BMG audio CDs. The rootkit hides certain Windows system resources, including files, processes, and registry settings. The rootkit can be used by attackers to hide malicious content on the computer.
It is best to use up-to-date antivirus software to remove VirTool:WinNT/F4IRootkit.C from your computer. You can scan your computer for VirTool:WinNT/F4IRootkit.C and other malicious software from the Microsoft Safety Scanner Web site.
To scan your computer for malicious software from the Microsoft Safety Scanner
-
Open an Internet Explorer browser window.
-
In the address bar, enter the following URL: http://go.microsoft.com/fwlink/?LinkId=212742site/en-US/default.htm
-
Click Full Service Scan.
-
Accept the Service Agreement if you are prompted to do so.
-
Click Install Now.
-
Select Quick Scan or Complete Scan.
Alternatively, after December 13, 2005, you can use the Microsoft Malicious Software Removal Tool to remove VirTool:WinNT/F4IRootkit.C from your computer. For more information about using the Malicious Software Removal Tool, visit http://www.microsoft.com/security/malwareremove/default.mspx.