Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | November 2005 (3.99) |
| Protection available since | 4 October 2005 00:39:29 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Lineage-MO is a password stealing Trojan for the Windows platform.
When Troj/Lineage-MO is installed it creates the file <System>\winme32.dll.
The file winme32.dll is registered as a COM object and ShellExecute hook, creating registry entries under:
HKCR\CLSID\(32A43994-9CDC-4633-A2F4-3152097D404D)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
(32A43994-9CDC-4633-A2F4-3152097D404D)
