Sophos

W32/LegMir-BM

Aliases
  • Trojan-PSW.Win32.Lmir.ju
  • W32/Legendmir.APK@pws
  • PWS-CangKu
  • TROJ_LMIR.JU
  • Trojan.Lmir-27
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Infected files
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from January 2006 (4.01)
Protection available since 11 November 2005 04:06:30 (GMT)
Detected by All Sophos products

Action

More Information

W32/LegMir-BM is a keyboard-logging virus for the Windows platform.

In order to run automatically at startup the virus copies itself to <Windows>\YZH.exe and creates the following registry entries:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
YZH
<Windows>\YZH.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
YZH
<Windows>\YZH.exe

W32/LegMir-BM monitors all keypresses for potential passwords and periodically
emails its findings to a preconfigured email address.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer