Name: Troj/Flood-O Type: Trojan Date: 8 July 2002 At the time of writing Sophos has received no reports from users affected by this Trojan. However, we have issued this advisory following enquiries to our support department from customers. Note: Sophos has been capable of protecting against Troj/Flood-O since the July 2002 (3.59) release of Sophos Anti-Virus, but has issued this new IDE to improve detection. Description Troj/Flood-O is an attempt to create an IRC backdoor and flooder Trojan. The Trojan is derived from a legitimate mIRC32 client which has been intentionally manipulated to change the characteristics of the original client. The original client has a standard mIRC32 program icon whereas the Trojan file has no icon at all. The title in the Trojan window title bar is "Taskmon" instead of "mIRC32" and the Trojan file does not have the orignal client's menu information. The Trojan may attempt to flood IRC channels once connected to an IRC server. More information about Troj/Flood-O can be found at http://www.sophos.com/virusinfo/analyses/trojfloodo.html