Sophos

Troj/Lineage-BN

Aliases
  • Trojan-PSW.Win32.Lineage.lp
  • TSPY_LINEAGE.LC
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from February 2006 (4.02)
Protection available since 30 November 2005 06:39:18 (GMT)
Last updated 23 December 2005 21:22:50 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Lineage-BN is a password stealing Trojan for the Windows platform that
attempts to steal passwords associated with the game called "Lineage".

Troj/Lineage-BN includes functionality to access the internet and communicate
with a remote server via HTTP.

When Troj/Lineage-BN is installed it creates the file <System>\winunits.dll.

The file winunits.dll is registered as a COM object and ShellExecute hook,
creating registry entries under:

HKCR\CLSID\(7B484C2F-AEE6-4e29-B894-EDEAA5DAF000)

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
\ShellExecuteHooks\(7B484C2F-AEE6-4e29-B894-EDEAA5DAF000)

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer