Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | January 2006 (4.01) |
| Protection available since | 11 November 2005 04:06:30 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/LegMir-BL is a password-stealing Trojan for the Windows platform.
Troj/LegMir-BL steals login details for the Legend of Mir online game and sends them to a preconfigured email address.
When first run Troj/LegMir-BL copies itself to <Windows>\PClK.exe.
The following registry entries are created to run PClK.exe on startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
PClK
<Windows>\PClK.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
PClK
<Windows>\PClK.exe
Troj/LegMir-BL terminates the following processes:
ravmon.exe
eghost.exe
mailmon.exe
netbargp.exe
Registry entries are created under:
HKCR\PCIK\
