Sophos

Troj/IMFlood-A

Aliases
  • Trojan.Win32.Aditer.a
  • YIM-Flood
  • trojan
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from June 2006 (4.06)
Protection available since 19 April 2006 13:10:40 (GMT)
Detected by All Sophos products

Action

More Information

Troj/IMFlood-A is a Trojan for the Windows platform.

Troj/IMFlood-A includes functionality to send spam-like instant messages to contacts in Yahoo Instant Messenger.

When first run Troj/IMFlood-A copies itself to <System>\smlbsbv4.exe.

The following registry entry is created to run smlbsbv4.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
systtray
<System>\SMLBSBV4.exe

Registry entries are created under:

HKCR\MSWinsock.Winsock\
HKCR\MSWinsock.Winsock.1\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer