Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Included in our products from | April 2008 (4.28) |
| Protection available since | 6 March 2008 01:22:10 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/CHMDrop-B is a Trojan for the Windows platform.
Top-level component of Troj/CHMDrop-B is a compiled HTML help file containing an article called "Photos of Tibet in the early 1940's".
When Troj/CHMDrop-B is run, it drops a file called music.exe - also detected as Troj/CHMDrop-B.
The file music.exe drops two further files and deletes itself:
- <WINDOWS>\system\conime.exe -detected as Troj/CHMDrop-B
- <WINDOWS>\system\zipfldr.dll - proactively detected as Mal/Emogen-AA
Troj/CHMDrop-B will attempt to download two files:
- photos-downloaded1.exe - detected as Troj/CHMDrop-B
- photos-downloaded2.exe - detected as Mal/Emogen-Y
