Troj/Lineage-F is a password stealing Trojan for the Windows platform that attempts to steal passwords associated with the game called "Lineage".
Troj/Lineage-F copies itself to the Windows folder as qwe.exe and creates a DLL keylogging component qwe.dll.
Troj/Lineage-F searches for the "Lineage","Lineage Windows Client" functional window in attempt to initiate a keylogging routine.
In order to be able to run automatically when Windows starts up Troj/Lineage-F sets the registry entry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
qwe
C:\WINDOWS\qwe.exe
The Trojan also modifies the HOSTS file (located in '<System>\drivers\etc\') in order to deny access to certain computer security websites. It adds entries for the following websites, redirecting them to 127.0.0.1:
avp.com
ca.com
customer.symantec.com
dispatch.mcafee.com
download.mcafee.com
f-secure.com
kaspersky.com
www.kasperksy-labs.com
liveupdate.symantec.com
liveupdate.symantecliveupdate.com
mast.mcafee.com
mcafee.com
my-etrust.com
nai.com
networkassociates.com
rads.mcafee.com
secure.nai.com
securityresponse.symantec.com
sophos.com
symantec.com
trendmicro.com
update.symantec.com
updates.symantec.com
us.mcafee.com
viruslist.com
www.avp.com
www.ca.com
www.f-secure.com
www.kaspersky.com
www.mcafee.com
www.my-etrust.com
www.symantec.com
www.viruslist.com
kaspersky-labs.com
downloads-eu1.kaspersky-labs.com
downloads-us1.kaspersky-labs.com
downloads1.kaspersky-labs.com
downloads2.kaspersky-labs.com
downloads3.kaspersky-labs.com
downloads4.kaspersky-labs.com
windowsupdate.microsoft.com
downloads5.kaspersky-labs.com
ftp.avp.ru
updates3.kaspersky-labs.com
updates2.kaspersky-labs.com
updates1.kaspersky-labs.com
ftp.kaspersky.com
downloads-us22.kaspersky-labs.com
downloads-us1.kaspersky-labs.com
downloads-us2l.kaspersky-labs.com
downloads-eu2l.kaspersky-labs.com
v4.windowsupdate.microsoft.com
v5.windowsupdate.microsoft.com
windowsupdate.microsoft.com