Troj/LegMir-AQK is a password stealing Trojan for the Windows platform.
When run Troj/LegMir-AQK copies itself to <Temp>\winlog0n.exe and creates the file <Temp>\LgSy<random number>.dll. The file LgSy<random number>.dll is also detected as Troj/LegMir-AQK.
The following registry entry is set to run Troj/LegMir-AQK on startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
9m
<Temp>\winlog0n.exe