Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Jan 24, 2008 | Updated Sep 15, 2017

Worm:Win32/Rootcip.E

Detected by Microsoft Defender Antivirus

Aliases: Backdoor.Win32.Rootcip.f (Kaspersky) Backdoor-CSS (McAfee) W32/Tdibd-C (Sophos)

Summary

Worm:Win32/Rootcip.E is installed by a dropper, and may be accompanied by a rootkit identified as VirTool:WinNT/Rootkitdrv.CN. Win32/Rootcip.E spreads by copying itself to the root of all logical disks, including removable drives. VirTool:WinNT/Rootkitdrv.CN hides all malicious processes created by the worm, and disables a security firewall service.
Manual removal is not recommended for this threat. To detect and remove this threat and other malicious software that may have been installed, run a full-system scan with an up-to-date antivirus product such as the Microsoft Safety Scanner (http://go.microsoft.com/fwlink/?LinkId=212742). For more information, see http://www.microsoft.com/protect/computer/viruses/vista.mspx.
Follow us