Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | May 2005 (3.93) |
| Protection available since | 7 April 2005 12:53:00 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
Change any data that may have become compromised.
Replace the Hosts file from a backup or edit it in Notepad to remove the changes that the Trojan has made.
Windows NT/2000/XP/2003
In Windows NT/2000/XP/2003 you will also need to edit the following registry entry. The removal of this entry is optional in Windows 95/98/Me. Please read the warning about editing the registry.
At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.
Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.
Locate the HKEY_LOCAL_MACHINE entry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
qwe
C:\WINDOWS\qwe.exe
and delete it if it exists.
Close the registry editor.
More Information
Troj/Lineage-F is a password stealing Trojan for the Windows platform that attempts to steal passwords associated with the game called "Lineage".
Troj/Lineage-F copies itself to the Windows folder as qwe.exe and creates a DLL keylogging component qwe.dll.
Troj/Lineage-F searches for the "Lineage","Lineage Windows Client" functional window in attempt to initiate a keylogging routine.
In order to be able to run automatically when Windows starts up Troj/Lineage-F sets the registry entry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
qwe
C:\WINDOWS\qwe.exe
The Trojan also modifies the HOSTS file (located in '<System>\drivers\etc\') in order to deny access to certain computer security websites. It adds entries for the following websites, redirecting them to 127.0.0.1:
avp.com
ca.com
customer.symantec.com
dispatch.mcafee.com
download.mcafee.com
f-secure.com
kaspersky.com
www.kasperksy-labs.com
liveupdate.symantec.com
liveupdate.symantecliveupdate.com
mast.mcafee.com
mcafee.com
my-etrust.com
nai.com
networkassociates.com
rads.mcafee.com
secure.nai.com
securityresponse.symantec.com
sophos.com
symantec.com
trendmicro.com
update.symantec.com
updates.symantec.com
us.mcafee.com
viruslist.com
www.avp.com
www.ca.com
www.f-secure.com
www.kaspersky.com
www.mcafee.com
www.my-etrust.com
www.symantec.com
www.viruslist.com
kaspersky-labs.com
downloads-eu1.kaspersky-labs.com
downloads-us1.kaspersky-labs.com
downloads1.kaspersky-labs.com
downloads2.kaspersky-labs.com
downloads3.kaspersky-labs.com
downloads4.kaspersky-labs.com
windowsupdate.microsoft.com
downloads5.kaspersky-labs.com
ftp.avp.ru
updates3.kaspersky-labs.com
updates2.kaspersky-labs.com
updates1.kaspersky-labs.com
ftp.kaspersky.com
downloads-us22.kaspersky-labs.com
downloads-us1.kaspersky-labs.com
downloads-us2l.kaspersky-labs.com
downloads-eu2l.kaspersky-labs.com
v4.windowsupdate.microsoft.com
v5.windowsupdate.microsoft.com
windowsupdate.microsoft.com
