Troj/Lineage-S is a password stealing Trojan for the Windows platform that attempts to steal passwords associated with the online game called "Lineage".
Troj/Lineage-S includes functionality to access the internet and communicate with a remote server via HTTP.
When first run the Trojan copies itself to <Windows folder>\grepclient1.exe.
The following registry entry is created to run grepclient1.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
55278
<Windows folder>\grepclient1.exe