Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | January 2005 (3.89) |
| Protection available since | 23 November 2004 22:00:27 (GMT) |
| Last updated | 23 November 2004 23:49:01 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
Change any data that may have become compromised.
Windows NT/2000/XP/2003
In Windows NT/2000/XP/2003 you will also need to edit the following registry entry. The removal of this entry is optional in Windows 95/98/Me. Please read the warning about editing the registry.
At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.
Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.
Locate the HKEY_LOCAL_MACHINE entry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Onlune Sarvice
<Windows folder>\sachost.exe
and delete it if it exists.
Close the registry editor.
More Information
Troj/Daemoni-J is a backdoor Trojan for the Windows platform.
The Trojan runs HTTP proxy and TCP redirection servers and allows a remote attacker to control the infected computer and monitor user activity.
When run the Trojan creates the files sachost.exe and maro32.dll in the Windows folder and sachosts.exe and sachostc.exe in the Windows system folder.
Sachosts.exe and sachostc.exe are detected by Sophos's anti-virus products as Troj/Daemoni-I.
The Trojan randomly chooses a port between 1201 and 64999 and runs an HTTP proxy server (sachosts.exe) on that port. It then runs a TCP redirection server (sachostc.exe) on the next but one port (e.g. ports 4072 and 4074).
Troj/Daemoni-J monitors the user's keystrokes and logs them to a file named sysini.ini in the Windows folder.
The backdoor component of Troj/Daemoni-J is run on port 10002 and allows a remote attacker to transfer files to and from the infected computer, run programs and monitor and terminate processes.
Troj/Daemoni-J adds the following registry entry to ensure that it is run each time a user logs on:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Onlune Sarvice
<Windows folder>\sachost.exe
The Trojan also adds the following registry entry:
HKLM\Software\Mserv
IDwin
