Sophos

Troj/LegMir-DZ

Aliases
  • Trojan-PSW.Win32.QQShou.ci
  • PWS-JB
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 6 January 2006 08:55:31 (GMT)
Detected by All Sophos products
  • Endpoint Security and Control 9.0
  • Small business solutions 4.0

Action

More Information

Troj/LegMir-DZ is an information stealing Trojan for the Windows platform.

When first run Troj/LegMir-DZ copies itself to:

<Temp>\temp~3
<System>\ravspepts.exe

and creates the file <System>\winsyi1.dll. This file winsyi1.dll can be deleted.

Once installed, Troj/LegMir-DZ will harvest information and passwords from the
online game "Legends of Mir 2" and send the information to a remote location via
SMTP.

The following registry entry is created to run ravspepts.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Rapdeyer
<System>\ravspepts.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer