0 Members and 1 Guest are viewing this topic.
When first run Troj/LegMir-AQJ copies itself to <Windows>\cmdbcs.exe and creates the file <System>\cmdbcs.dll.Cmdbcs.dll is also detected as Troj/LegMir-AQJ.The following registry entry is created to run cmdbcs.exe on startup:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Runcmdbcs<Windows>\cmdbcs.exe