Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 3 April 2007 10:51:04 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/LegMir-AQK is a password stealing Trojan for the Windows platform.
When run Troj/LegMir-AQK copies itself to <Temp>\winlog0n.exe and creates the file <Temp>\LgSy<random number>.dll. The file LgSy<random number>.dll is also detected as Troj/LegMir-AQK.
The following registry entry is set to run Troj/LegMir-AQK on startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
9m
<Temp>\winlog0n.exe

