Sophos

Troj/Flood-IM

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from May 2008 (4.29)
Protection available since 28 March 2008 18:22:49 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Flood-IM is a set of EXEs and DLLs that comprise a backdoor Trojan designed to be used as a Distributed Denial of Service tool.

When first run Troj/Flood-IM creates the following files:

<Windows>\edih.dll - detected as Troj/Flood-I
<System>\winnxp.hlp - mIRC script used for DDoS attack, can be safely deleted
<System>\Systemx.dll - log file used by the Trojan, can be safely deleted
<Windows>\rebot.dll - clean mIRC customization DLL, can be safely deleted
<Windows>\Winamp.exe - mIRC client, can be safely deleted

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer