Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | October 2005 (3.98) |
| Protection available since | 4 August 2005 15:15:54 (GMT) |
| Last updated | 1 September 2005 12:37:58 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Lineage-AH is a password stealing Trojan for the Windows platform that attempts to steal passwords associated with the game called "Lineage".
When Troj/Lineage-AH is installed it creates the file <System>\winhosts.dll.
The file winhosts.dll is registered as a COM object and ShellExecute hook, creating registry entries under:
HKCR\CLSID\(3B354F63-A696-424c-9E88-7F6BDFBA5CA5)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\(3B354F63-A696-424c-9E88-7F6BDFBA5CA5)
