Threat Database Trojans Trojan-PSW.Lineage!rem

Trojan-PSW.Lineage!rem

By Domesticus in Trojans

Trojan-PSW.Lineage!rem is a computer trojan infection that can open up a backdoor to enable a remote attacker to secretly access the affected PC system. Trojan-PSW.Lineage!rem may load a number of pop-up alerts that pretend a computer scan, parasite reports, system tray alerts, privacy warning and similar messages. Trojan-PSW.Lineage!rem tries to propagate through network exploits. Trojan-PSW.Lineage!rem infiltrates into the PC through its vulnerabilities and makes a perfect background for malware to invade a system.

File System Details

Trojan-PSW.Lineage!rem may create the following file(s):
# File Name Detections
1. %Windir%\Debug\231346E28D27.exe
2. %Windir%\Debug\231346E28D27.dll
3. %System%\1.bat
4. %Windir%\1.bat
5. [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{47994C89-1857-4D33-B196-263ED6FA4CFF}]
6. ThrEaDiNgModEL = "aPaRTmEnT"
7. {47994C89-1857-4D33-B196-263ED6FA4CFF} = ""
8. [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{47994C89-1857-4D33-B196263ED6FA4CFF}\InPrOcSeRvEr32](Default) = "%Windir%\Debug\231346E28D27.dll"
9. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
10. (Default) = "DIDI"
11. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{47994C89-1857-4D33-B196-263ED6FA4CFF}\InPrOcSeRvEr32

Trending

Most Viewed

Loading...