Sophos

Troj/Flood-EV

Aliases
  • IRC/Flood.b.dr
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 9 January 2006 14:02:45 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Flood-EV is a backdoor Trojan for the Windows platform.

Troj/Flood-EV allows unauthenticated access for remote intruders to the infected computer.

When Troj/Flood-EV is installed the following files are created:

<System>\temp\bat32.installed
<System>\temp\bootconfig.exe
<System>\temp\defragment.exe
<System>\temp\mirc.ini
<System>\temp\moo.dll
<System>\temp\registry.bat
<System>\temp\scripts\download.ini
<System>\temp\scripts\main.ini
<System>\temp\scripts\mescript.ini
<System>\temp\scripts\proxy.ini
<System>\temp\scripts\quakenet.ini
<System>\temp\scripts\regread.ini
<System>\temp\settings\aliases.ini
<System>\temp\settings\channels.txt
<System>\temp\settings\names.txt
<System>\temp\settings\pm.txt
<System>\temp\settings\remote.ini
<System>\temp\settings\servers.ini
<System>\temp\sleep.exe
<System>\temp\svchost.exe
<System>\temp\update.exe
<System>\temp\winsrv.exe

The files main.ini and mescript.ini are detected as Troj/Flood-EV. The file svchost.exe is a mIRC application which can be uninstalled from the Control Panel. The rest of the files can be deleted.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer