Searching with Google gives the description of this trojan TROJ_LEGMIR.BI
It modifies the following registry entry to ensure its automatic execution at every Windows logon:
Everybody has the right to be stupid -- but some people abuse the privilege. (a quote from Stalin - and I am one of the abusers, sometimes...)
----------------------------------------
Experienced in the IT-chaos since 1984...
1. Go to Safe Mode
2. Start regedit, and navigate to:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
Edit the value "Shell" so that it says only:
"Explorer.exe"
3. Delete three files:
\Winnt\bak.exe – this is a copy of the original Trojan.
\Winnt\System32\whboy.exe – this is a copy of the original Trojan.
\Winnt\System32\whboy.txt – this is a .DLL component of the Trojan that is used to run its malicious routines.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.