Sophos

Troj/Dorf-M

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Included in our products from September 2007 (4.21)
Protection available since 24 July 2007 22:48:20 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Dorf-M is a Trojan for the Windows platform with rootkit functionality.

Troj/Dorf-M attempts to turn off anti-virus applications and terminate kernel drivers associated with anti-virus software.

Troj/Dorf-M patches the legitimate Windows driver tcpip.sys in order to load its own driver code on startup. The patched version of tcpip.sys is also detected as Troj/Dorf-M.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer