Sophos

Troj/Lineag-AIN

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from February 2007 (4.14)
Protection available since 9 January 2007 05:23:05 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Lineag-AIN is a Trojan downloader for the Windows platform.

Troj/Lineag-AIN includes functionality to download and execute code via HTTP.

Troj/Lineag-AIN also includes functionality to scan ports and SMB shares.

Troj/Lineag-AIN copies iteself to <Windows>\svch0st.exe and drops the following files:

<System>\expiorer.exe
<Temp>\ztconfig.ini
<Temp>\LgSyz.dll
<Temp>\MgSyz.dll

Troj/Lineag-AIN creates the following registry entries:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
ravtask
<Windows>\svch0st.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
SyztMy
<System>\expiorer.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer