Skip to main content
Skip to main content
Published Nov 17, 2005 | Updated Sep 15, 2017

VirTool:WinNT/F4IRootkit.D

Detected by Microsoft Defender Antivirus

Aliases: No associated aliases

Summary

VirTool:WinNT/F4IRootkit.D is a kernel-mode rootkit used for copy protection on certain Sony BMG audio CDs. The rootkit hides certain Windows system resources, including files, processes, and registry settings. The rootkit can be used by attackers to hide malicious content on the computer.
It is best to use up-to-date antivirus software to remove VirTool:WinNT/F4IRootkit.D from your computer. You can scan your computer for VirTool:WinNT/F4IRootkit.D and other malicious software from the Microsoft Safety Scanner Web site. 
To scan your computer for malicious software from the Microsoft Safety Scanner
  1. Open an Internet Explorer browser window.
  2. In the address bar, enter the following URL: http://go.microsoft.com/fwlink/?LinkId=212742site/en-US/default.htm
  3. Click Full Service Scan.
  4. Accept the Service Agreement if you are prompted to do so.
  5. Click Install Now.
  6. Select Quick Scan or Complete Scan.
 
Alternatively, after December 13, 2005, you can use the Microsoft Malicious Software Removal Tool to remove VirTool:WinNT/F4IRootkit.D from your computer. For more information about using the Malicious Software Removal Tool, visit http://www.microsoft.com/security/malwareremove/default.mspx.
Follow us