We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
VirTool:WinNT/Macpro.A
Detected by Microsoft Defender Antivirus
Aliases: BackDoor-CST (McAfee)
Summary
VirTool:WinNT/Macpro.A is a kernel-mode rootkit that targets Windows NT, Windows 2000, and Windows XP. It can hide processes, files, folders, and registry values on the infected computer. It is dropped by Backdoor:Win32/Samsteal.A.dr.
To recover manually from VirTool:WinNT/Macpro.A:
- Disconnect from the Internet.
- Remove the Trojan service.
- Delete the Trojan file.
- Take steps to prevent re-infection.
Disconnect from the Internet
To help ensure that your computer is not actively infecting other computers, disconnect it from the Internet before proceeding. Print this Web page or save a copy on your computer; then unplug your network cable and disable your wireless connection. You can reconnect to the Internet after completing these steps.
Remove the Trojan service
To remove the Trojan service
- On the Start menu, click Settings, then click Control Panel.
- Double-click Administrative Tools.
- Double-click Services.
- If a service called mac128 is in the list, right-click it.
- If the service is running, click Stop.
- Right-click the service again and click Properties.
- Under Startup Type, change the type to Disabled.
Delete the Trojan file
To delete the Trojan file
- Click Start, and click Run.
- In the Open field, type %windir%\VirtualMGR, for example, C:\Windows\VirtualMGR
- Click OK.
- Click Name to sort files by name.
- If the file mac128.sys is in the list, delete it.
- On the Desktop, right-click the Recycle Bin and click Empty Recycle Bin.
- Click Yes to confirm the deletion.
Restart your computer
To restart your computer
- On the Start menu, click Shut Down.
- Select Restart from the drop-down list and click OK.
Take steps to prevent re-infection
Do not reconnect your computer to the Internet until the computer is protected from re-infection. See the "Preventing Infection" section for more information.