Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | November 2007 (4.23) |
| Protection available since | 14 September 2007 19:42:19 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Lineag-BT is a backdoor Trojan for the Windows platform.
When first run Troj/Lineag-BT copies itself to <Program Files>\Windows NT\services.exe and creates the following files:
<Temp>\9j2u.sys
<Temp>\ac5ig.dll
The file 9j2u.sys is detected as Mal/RootKit-A. The file ac5ig.dll is also detected as Troj/Lineag-BT.
The following registry entry is changed to run Troj/Lineag-BT on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit
<System>\userinit.exe,<Program Files>\Windows NT\SERVICES.EXE,
