Removal instructions for the trojan Dorifel

7-day Free Trial w/Credit card, no charge upfront or if you cancel up to 2 days before expiration; Subscription price varies per region w/ auto renewal unless you timely cancel; notification before you are billed; 30-day money-back guarantee; Read full terms and more information about free remover.

*Source of claim SH can remove it.

The digital world is filled with dangers, and one of the main threats out there is the Trojan Horse infection. Among its forms, Dorifel stands out as an impostor that seems to have been a global Lenovo problem, affecting several models. Once it sneaks in, it can wreak havoc by stealing information, introducing malware or even granting cybercriminals remote access. 

Is Dorifel Really a Virus?

People on Reddit have posted that Dorifel is frequently referred to as a virus, and that’s true. According to our research, it has been around since 2012 and falls under the Trojan Horse category.

The trojan Dorifel detected by Windows Defender
The trojan Dorifel detected by Windows Defender

In several user cases, a scan with Windows Defender on infected systems, discovered the installation of an unknown app called POKKI, without the victim’s knowledge. The scan also indicated the presence of a file inside “hostappservice” that seems to be connected to an engineering tool called Ansys, and two files linked to the “Lenovo App Explorer” on Lenovo laptops. If you also find these detections, it is possible that your system has vulnerabilities, and you should investigate it immediately.

How does the Trojan Dorifel spread?

Unlike viruses that replicate independently, this malware doesn’t spread on its own. Instead, it relies on manipulating users through social engineering tricks to gain access. When we researched further, we came across user complaints that suggest an infection with Win32/Dorifel through clicking on emails that pretend to be legitimate school emails.

This reliance on interaction makes Dorifel especially dangerous, since it exploits people’s trust, especially some unsecure habits of opening attachments immediately. Inside your system, this Trojan can be used for different activities from stealing data to creating entry points for future cyberattacks. 

Spotting Signs of the Dorifel Attack

Detecting an intruder like Dorifel can be quite tricky, however, there are signs that users should watch out for. These indicators include slow system performance, frequent crashes and unexpected pop up ads. 

Unauthorized modifications to your system settings, or the unexpected appearance of programs, such as the POKKI app that we mentioned above, could also be concerning. You also should be worried if you notice strange processes operating silently in the background. 

However, you should keep in mind that most Trojans can remain undetected for extended periods of time. So, it’s critical to run security scans should you notice anything unusual and always keep a close eye on your system.


Type Trojan
Detection Tool

*Source of claim SH can remove it.

Remove Dorifel Malware

To try and remove Dorifel quickly you can try this:

  1. Go to your browser’s settings and select More Tools (or Add-ons, depending on your browser).
  2. Then click on the Extensions tab.
  3. Look for the Dorifel extension (as well as any other unfamiliar ones).
  4. Remove Dorifel by clicking on the Trash Bin icon next to its name.
  5. Confirm and get rid of Dorifel and any other suspicious items.

If this does not work as described please follow our more detailed Dorifel removal guide below.

If you have a Windows virus, continue with the guide below.

If you have a Mac virus, please use our How to remove Ads on Mac guide.

If you have an Android virus, please use our Android Malware Removal guide.

If you have an iPhone virus, please use our iPhone Virus Removal guide.

Some of the steps may require you to exit the page. Bookmark it for later reference.
Next, Reboot in Safe Mode (use this guide if you don’t know how to do it).

Step1 Uninstall the Dorifel app and kill its processes

The first thing you must try to do is look for any sketchy installs on your computer and uninstall anything you think may come from Dorifel. After that, you’ll also need to get rid of any processes that may be related to the unwanted app by searching for them in the Task Manager.

Note that sometimes an app, especially a rogue one, may ask you to install something else or keep some of its data (such as settings files) on your PC – never agree to that when trying to delete a potentially rogue software. You need to make sure that everything is removed from your PC to get rid of the malware. Also, if you aren’t allowed to go through with the uninstallation, proceed with the guide, and try again after you’ve completed everything else.

  • Uninstalling the rogue app
  • Killing any rogue processes

Type Apps & Features in the Start Menu, open the first result, sort the list of apps by date, and look for suspicious recently installed entries.

Click on anything you think could be linked to Dorifel, then select uninstall, and follow the prompts to delete the app.

delete suspicious Dorifel apps

Press Ctrl + Shift + Esc, click More Details (if it’s not already clicked), and look for suspicious entries that may be linked to Dorifel.

If you come across a questionable process, right-click it, click Open File Location, scan the files with the free online malware scanner shown below, and then delete anything that gets flagged as a threat.

Each file will be scanned with up to 64 antivirus programs to ensure maximum accuracy
This scanner is free and will always remain free for our website's users.
This file is not matched with any known malware in the database. You can either do a full real-time scan of the file or skip it to upload a new file. Doing a full scan with 64 antivirus programs can take up to 3-4 minutes per file.
Drag and Drop File Here To Scan
Drag and Drop File Here To Scan
Analyzing 0 s
Each file will be scanned with up to 64 antivirus programs to ensure maximum accuracy
    This scanner is based on VirusTotal's API. By submitting data to it, you agree to their Terms of Service and Privacy Policy, and to the sharing of your sample submission with the security community. Please do not submit files with personal information if you do not want them to be shared.
    Delete Dorifel files and quit its processes.

    After that, if the rogue process is still visible in the Task Manager, right-click it again and select End Process.

    Step2 Undo Dorifel changes made to different system settings

    It’s possible that Dorifel has affected various parts of your system, making changes to their settings. This can enable the malware to stay on the computer or automatically reinstall itself after you’ve seemingly deleted it. Therefore, you need to check the following elements by going to the Start Menu, searching for them, and pressing Enter to open them and to see if anything has been changed there without your approval. Then you must undo any unwanted changes made to these settings in the way shown below:

    • DNS
    • Hosts
    • Startup
    • Task
    • Services
    • Registry

    Type in Start Menu: View network connections

    Right-click on your primary network, go to Properties, and do this:

    Undo DNS changes made by Dorifel

    Type in Start Menu: C:\Windows\System32\drivers\etc\hosts

    Delete Dorifel IPs from Hosts

    Type in the Start Menu: Startup apps

    Disable Dorifel startup apps

    Type in the Start Menu: Task Scheduler

    Delete Dorifel scheduled tasks

    Type in the Start Menu: Services

    Disable Dorifel services

    Type in the Start Menu: Registry Editor

    Press Ctrl + F to open the search window

    Clear the Registry from Dorifel items

    Preventing Trojan Win32/Dorifel Infections

    You can totally prevent an infection by Trojan Win32/Dorifel, but that requires a bit of preparation. We would recommend you to keep all software and operating systems up to date, because updates often contain fixes for security vulnerabilities, exploited by Trojans. You also need to use trusted antivirus and anti malware software as it can help you to identify and remove the malicious software before it has caused damage.

    Being cautious with emails by not opening attachments or clicking on links from sources can also lower the risk of encountering threats. Of course, we also have to emphasize on how crucial it is to practice browsing habits, such, as steering off suspicious websites and downloads.

    Significance of Firewalls

    Thanks to their ability to monitor and control network traffic flow, firewalls are an important defense layer against Trojans such as Win32/Dorifel. They stop them from interacting with servers and receiving commands from the hackers by acting as a barrier that prevents access to the system. That’s why, we always recommend to our readers to maintain firewall rules and settings updated.

    Dealing with the Win32/Dorifel Infection

    If your system has a Win32/Dorifel infection, you must take action to accurately identify and remove the threat. The first step is to disconnect the infected device from the network, in order to stop any potential data transfer, and contact with the malware developers. Next, you should perform a system scan with reliable antivirus software to identify and remove the Trojan. Following the removal of Win32/Dorifel, we also recommend that you change all passwords. This includes especially those linked to accounts that are accessed through the compromised computer.


    About the author


    Lidia Howler

    Lidia is a web content creator with years of experience in the cyber-security sector. She helps readers with articles on malware removal and online security. Her strive for simplicity and well-researched information provides users with easy-to-follow It-related tips and step-by-step tutorials.

    Leave a Comment

    We are here to help! Use SpyHunter to remove malware in under 15 minutes.

    Not Your OS? Download for Windows® and Mac®.

    * See Free Trial offer details and alternative Free offer here.

    ** SpyHunter Pro receives additional removal definitions and manual fixes through its HelpDesk in cases where they are needed.

    Spyware Helpdesk 1