Troj/Daemoni-J

Category: Viruses and Spyware
Type: Trojan
Prevalence: No Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/Daemoni-J is a backdoor Trojan for the Windows platform.

The Trojan runs HTTP proxy and TCP redirection servers and allows a remote attacker to control the infected computer and monitor user activity.

When run the Trojan creates the files sachost.exe and maro32.dll in the Windows folder and sachosts.exe and sachostc.exe in the Windows system folder.

Sachosts.exe and sachostc.exe are detected by Sophos's anti-virus products as Troj/Daemoni-I.

The Trojan randomly chooses a port between 1201 and 64999 and runs an HTTP proxy server (sachosts.exe) on that port. It then runs a TCP redirection server (sachostc.exe) on the next but one port (e.g. ports 4072 and 4074).

Troj/Daemoni-J monitors the user's keystrokes and logs them to a file named sysini.ini in the Windows folder.

The backdoor component of Troj/Daemoni-J is run on port 10002 and allows a remote attacker to transfer files to and from the infected computer, run programs and monitor and terminate processes.

Troj/Daemoni-J adds the following registry entry to ensure that it is run each time a user logs on:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Onlune Sarvice
<Windows folder>\sachost.exe

The Trojan also adds the following registry entry:

HKLM\Software\Mserv
IDwin

download Try Sophos products for free
Download now