Sophos

Troj/LegMir-W

Aliases
  • Trojan-PSW.Win32.Lmir.ys
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 16 January 2005 16:24:33 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/LegMir-W is a Windows keylogging Trojan.

Troj/LegMir-W will copy itself to the Windows folder with the filename snet.exe and to the Windows system folder with the filename msapi.exe. A DLL file will also be created in the Windows system folder with the filename msapi.dll. The DLL file is the component of this Trojan that contains the password stealing functionality.

The following registry entry will be created so that the Trojan is run when a user logs on to Windows:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinLogon
Shell = explorer.exe <system>\msapi.exe

The DLL file will be loaded into the address space of the explorer process.

Troj/LegMir-W will terminate the following process:
iparmor.exe
mailmon.exe
kavpfw.exe

Troj/LegMir-W may close Windows associated with the applications ZoneAlarm and
Symantec AntiVirus.

Information gathered on the victim's computer will be sent to an attacker by email.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer