Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | December 2005 (4.00) |
| Protection available since | 11 October 2005 13:35:06 (GMT) |
| Last updated | 19 October 2005 12:00:12 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Lineage-BA is a password stealing Trojan for the Windows platform that attempts to steal passwords associated with the game called "Lineage".
When first run Troj/Lineage-BA copies itself to <System>\Kerne14.exe and creates the file <System>\microsoftie4.dll.
The following registry entry is created to run Kerne14.exe on startup:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows
load
<System>\Kerne14.exe
