Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | July 2005 (3.95) |
| Protection available since | 5 June 2005 15:01:17 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
Windows NT/2000/XP/2003
In Windows NT/2000/XP/2003 you will also need to edit the following registry entry. The removal of this entry is optional in Windows 95/98/Me. Please read the warning about editing the registry.
At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.
Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.
Locate the HKEY_LOCAL_MACHINE entry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
combo.exe
"combo.exe"
and delete it if it exists.
Close the registry editor.
More Information
Troj/Chimo-D is a Trojan for the Windows platform.
When run, Troj/Chimo-D copies itself to the Windows system folder as combo.exe and creates the following registry entry in order to run each time a user logs on:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
combo.exe
"combo.exe"
The Trojan connects to a remote site to download configuration details. The Trojan then serves as an Email proxy, allowing remote attackers the ability to route arbitrary email anonymously through the infected computer.
Email sent by Troj/Chimo-D has the sender's name spoofed. The sender's name is randomly chosen by combining two of the following:
Abrahams
Adorno
Albert
Alexander
Alpert
Ellison
Emmanuel
Farber
Feidelberg
Feinberg
Feldman
Finkbein
Finkel
Finkelstein
Fishbein
Fleischer
Fleisher
Frankel
Friedman
Geffen
Gelbman
Gershwin
Glazer
Glickman
Glucksman
Goldberg
Goldenson
Goldwyn
Gottlieb
Gralnick
Greenberg
Grinberg
Grossman
Gruber
Gunzberg
Halperin
Halpern
Handler
Heller
Hellman
Herman
Hersch
Herzberg
Herzog
Hillel
Himmelfarb
Hirsch
Hohenemser
Hollaender
Horowitz
The Trojan randomly chooses several ports to listen for incoming email requests.
