Sophos

Sophos blogs

Troj/Daemoni-I

Aliases
  • TrojanProxy.Win32.Daemonize.aa
  • BKDR_DAEMOZ.AA
  • TrojanDownloader.Win32.Small.ub
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 14 October 2004 07:52:16 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Daemoni-I drops sdchost.exe, sdchosts.exe and sdchostc.exe. It may also set a registry entry in:

HKLM\SOFTWARE\Microsoft\dadsdasdn.

The sdchost.exe component waits for an active internet connection and then launches both sdchosts and sdchostc which will listen to a random port which will carry out simple port mapping or HTML proxying. sdchost.exe may also attempt to notify a remote host of the existing server.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer