Sophos

Troj/Chimo-C

Aliases
  • Email-Worm.Win32.Bagz.j
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from July 2005 (3.95)
Protection available since 2 June 2005 22:15:56 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Chimo-C is a Trojan for the Windows platform.

When run, Troj/Chimo-C copies itself to the Windows system folder as combo.exe and creates the following registry entry in order to run each time a user logs on:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
combo.exe
combo.exe

The Trojan connects to a remote site to download configuration details. The Trojan then serves as an Email proxy, allowing remote attackers the ability to route arbitrary email anonymously through the infected computer.

Email sent by Troj/Chimo-C has the sender's name spoofed. The sender's name is randomly chosen by combining two of the following:

Abrahams
Adorno
Albert
Alexander
Alpert
Ellison
Emmanuel
Farber
Feidelberg
Feinberg
Feldman
Finkbein
Finkel
Finkelstein
Fishbein
Fleischer
Fleisher
Frankel
Friedman
Geffen
Gelbman
Gershwin
Glazer
Glickman
Glucksman
Goldberg
Goldenson
Goldwyn
Gottlieb
Gralnick
Greenberg
Grinberg
Grossman
Gruber
Gunzberg
Halperin
Halpern
Handler
Heller
Hellman
Herman
Hersch
Herzberg
Herzog
Hillel
Himmelfarb
Hirsch
Hohenemser
Hollaender
Horowitz

The Trojan randomly chooses several ports to listen for incoming email requests.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer