Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 9 January 2006 14:02:45 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Flood-EV is a backdoor Trojan for the Windows platform.
Troj/Flood-EV allows unauthenticated access for remote intruders to the infected computer.
When Troj/Flood-EV is installed the following files are created:
<System>\temp\bat32.installed
<System>\temp\bootconfig.exe
<System>\temp\defragment.exe
<System>\temp\mirc.ini
<System>\temp\moo.dll
<System>\temp\registry.bat
<System>\temp\scripts\download.ini
<System>\temp\scripts\main.ini
<System>\temp\scripts\mescript.ini
<System>\temp\scripts\proxy.ini
<System>\temp\scripts\quakenet.ini
<System>\temp\scripts\regread.ini
<System>\temp\settings\aliases.ini
<System>\temp\settings\channels.txt
<System>\temp\settings\names.txt
<System>\temp\settings\pm.txt
<System>\temp\settings\remote.ini
<System>\temp\settings\servers.ini
<System>\temp\sleep.exe
<System>\temp\svchost.exe
<System>\temp\update.exe
<System>\temp\winsrv.exe
The files main.ini and mescript.ini are detected as Troj/Flood-EV. The file svchost.exe is a mIRC application which can be uninstalled from the Control Panel. The rest of the files can be deleted.
