Sophos

Troj/Lineage-F

Aliases
  • Trojan-PSW.Win32.Lineage.dq
  • Trojan.Spy.Lineage-8
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from May 2005 (3.93)
Protection available since 7 April 2005 12:53:00 (GMT)
Detected by All Sophos products

Action

Please follow the instructions for removing Trojans.

Change any data that may have become compromised.

Replace the Hosts file from a backup or edit it in Notepad to remove the changes that the Trojan has made.

Windows NT/2000/XP/2003

In Windows NT/2000/XP/2003 you will also need to edit the following registry entry. The removal of this entry is optional in Windows 95/98/Me. Please read the warning about editing the registry.

At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.

Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.

Locate the HKEY_LOCAL_MACHINE entry:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
qwe
C:\WINDOWS\qwe.exe

and delete it if it exists.

Close the registry editor.

More Information

Troj/Lineage-F is a password stealing Trojan for the Windows platform that attempts to steal passwords associated with the game called "Lineage".

Troj/Lineage-F copies itself to the Windows folder as qwe.exe and creates a DLL keylogging component qwe.dll.

Troj/Lineage-F searches for the "Lineage","Lineage Windows Client" functional window in attempt to initiate a keylogging routine.

In order to be able to run automatically when Windows starts up Troj/Lineage-F sets the registry entry:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
qwe
C:\WINDOWS\qwe.exe

The Trojan also modifies the HOSTS file (located in '<System>\drivers\etc\') in order to deny access to certain computer security websites. It adds entries for the following websites, redirecting them to 127.0.0.1:

avp.com
ca.com
customer.symantec.com
dispatch.mcafee.com
download.mcafee.com
f-secure.com
kaspersky.com
www.kasperksy-labs.com
liveupdate.symantec.com
liveupdate.symantecliveupdate.com
mast.mcafee.com
mcafee.com
my-etrust.com
nai.com
networkassociates.com
rads.mcafee.com
secure.nai.com
securityresponse.symantec.com
sophos.com
symantec.com
trendmicro.com
update.symantec.com
updates.symantec.com
us.mcafee.com
viruslist.com
www.avp.com
www.ca.com
www.f-secure.com
www.kaspersky.com
www.mcafee.com
www.my-etrust.com
www.symantec.com
www.viruslist.com
kaspersky-labs.com
downloads-eu1.kaspersky-labs.com
downloads-us1.kaspersky-labs.com
downloads1.kaspersky-labs.com
downloads2.kaspersky-labs.com
downloads3.kaspersky-labs.com
downloads4.kaspersky-labs.com
windowsupdate.microsoft.com
downloads5.kaspersky-labs.com
ftp.avp.ru
updates3.kaspersky-labs.com
updates2.kaspersky-labs.com
updates1.kaspersky-labs.com
ftp.kaspersky.com
downloads-us22.kaspersky-labs.com
downloads-us1.kaspersky-labs.com
downloads-us2l.kaspersky-labs.com
downloads-eu2l.kaspersky-labs.com
v4.windowsupdate.microsoft.com
v5.windowsupdate.microsoft.com
windowsupdate.microsoft.com

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer