Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | July 2008 (4.31) |
| Protection available since | 9 May 2008 02:39:51 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Lineag-DN displays 2 pictures of a woman celebrating her birthday with cake.
When Troj/Lineag-DN is installed the following files are created:
<Temp>\RarSFX0\8.sfx.exe
<Temp>\RarSFX0\mm1\1.jpg
<Temp>\RarSFX0\mm1\2.jpg
<Current Folder>\2.bat
<Windows>\Debug\29124D4AA81F.dll
<Windows>\Debug\29124D4AA81F.exe
The file 29124D4AA81F.dll is detected as Mal/BHO-H, while 2.bat is not malicious and can be safely deleted.
The file 29124D4AA81F.dll is registered as a COM object and shell extension, creating registry entries under:
HKCR\CLSID\{083A5F21-BCB9-4B21-A121-2584BEEFBFEF}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{083A5F21-BCB9-4B21-A121-2584BEEFBFEF
