Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | May 2008 (4.29) |
| Protection available since | 28 March 2008 18:22:49 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Flood-IM is a set of EXEs and DLLs that comprise a backdoor Trojan designed to be used as a Distributed Denial of Service tool.
When first run Troj/Flood-IM creates the following files:
<Windows>\edih.dll - detected as Troj/Flood-I
<System>\winnxp.hlp - mIRC script used for DDoS attack, can be safely deleted
<System>\Systemx.dll - log file used by the Trojan, can be safely deleted
<Windows>\rebot.dll - clean mIRC customization DLL, can be safely deleted
<Windows>\Winamp.exe - mIRC client, can be safely deleted
