Sophos

Troj/Lineage-Z

Aliases
  • Trojan-PSW.Win32.Lineage.eb
  • PWS-Lineage.dll
  • trojan
  • TROJ_LINEAGE.CT
  • Trojan.Spy.Lineage-13
  • PWSteal.Lineage
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from August 2005 (3.96)
Protection available since 7 July 2005 01:08:40 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Lineage-Z is a password stealing Trojan for the Windows platform that
attempts to steal passwords associated with the game called "Lineage".

When first run Troj/Lineage-Z copies itself to <Windows>\_svchost_.exe and creates the file <Windows>\_msvc_.dll.

The following registry entries are created to run _svchost_.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
_System_Run
<Windows>\_svchost_.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe <Windows>\_svchost_.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer