Sophos

Troj/LegMir-ARE

Aliases
  • PWS-LegMir
  • trojan
  • Trojan-PSW.Win32.OnLineGames.acz
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from September 2007 (4.21)
Protection available since 27 July 2007 12:20:36 (GMT)
Detected by All Sophos products

Action

More Information

Troj/LegMir-ARE is a Trojan for the Windows platform.

When first run Troj/LegMir-ARE copies itself to <System>\kjgagklj11.exe and creates the file <System>\6lsd0.dll.

The following registry entry is created to run kjgagklj11.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
faslkakj11
<System>\kjgagklj11.exe

Sophos's anti-virus products include Behavioral Genotype® Protection, which can proactively guard against new threats without requiring an update. Sophos customers have been protected against Troj/LegMir-ARE (detected as Mal/Packer) since version 4.10.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer