Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 16 January 2005 16:24:33 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/LegMir-W is a Windows keylogging Trojan.
Troj/LegMir-W will copy itself to the Windows folder with the filename snet.exe and to the Windows system folder with the filename msapi.exe. A DLL file will also be created in the Windows system folder with the filename msapi.dll. The DLL file is the component of this Trojan that contains the password stealing functionality.
The following registry entry will be created so that the Trojan is run when a user logs on to Windows:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinLogon
Shell = explorer.exe <system>\msapi.exe
The DLL file will be loaded into the address space of the explorer process.
Troj/LegMir-W will terminate the following process:
iparmor.exe
mailmon.exe
kavpfw.exe
Troj/LegMir-W may close Windows associated with the applications ZoneAlarm and
Symantec AntiVirus.
Information gathered on the victim's computer will be sent to an attacker by email.
