We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
VirTool:WinNT/Rootkitdrv.HU
Detected by Microsoft Defender Antivirus
Aliases: Rkit/Agent.bixk (Avira) Rootkit.40546 (BitDefender) Rootkit.Win32.Agent.bixk (Kaspersky) Hacktool.Rootkit (Symantec) TROJ_AGENT.AULP (Trend Micro)
Summary
VirTool:WinNT/Rootkitdrv.HU is a kernel-mode rootkit that attempts to capture keystrokes entered by a user on the affected computer.
To detect and remove this threat and other malicious software that may be installed on your computer, run a full-system scan with an appropriate, up-to-date, security solution. The following Microsoft products will detect and remove this threat:
For more information on antivirus software, see http://www.microsoft.com/windows/antivirus-partners/.