Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | October 2007 (4.22) |
| Protection available since | 6 September 2007 05:16:29 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Lineag-BE is a Trojan for the Windows platform.
When first run Troj/Lineag-BE copies itself to <Program Files>\Windows NT\services.exe and creates the following files:
<Temp>\f5lcmh0.sys - detected as Mal/RootKit-A
<Temp>\vnzn.dll - detected as Mal/EncPk-AH.
<System>\ACE.dll - detected as Troj/Lineag-Gen.
The following registry entry is changed to run Troj/Lineag-BE on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit
<System>\userinit.exe,<Program Files>\Windows NT\SERVICES.EXE,
