Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | August 2007 (4.20) |
| Protection available since | 26 June 2007 02:47:35 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Dorf-K is a Trojan for the Windows platform.
When Troj/Dorf-K is installed it creates the file <System>\windev-<4 random characters>-<4 random characters >.sys, detected as Mal/EncPk-K.
This dropped file is registered as a new system driver service with the same service and display name as the file, and a startup type of automatic so that it is started automatically during system startup. Registry entries are created under:
HKLM\SYSTEM\CurrentControlSet\Services\windev-<4 random characters>-<4 random characters>
Troj/Dorf-K may attempts to download and execute files from a remote location
