Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Included in our products from | September 2007 (4.21) |
| Protection available since | 24 July 2007 22:48:20 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for disinfecting PE executables.
More Information
Troj/Dorf-M is a Trojan for the Windows platform with rootkit functionality.
Troj/Dorf-M attempts to turn off anti-virus applications and terminate kernel drivers associated with anti-virus software.
Troj/Dorf-M patches the legitimate Windows driver tcpip.sys in order to load its own driver code on startup. The patched version of tcpip.sys is also detected as Troj/Dorf-M.
