Home Malware Programs Trojans Trojan-PSW.Lineage!rem

Trojan-PSW.Lineage!rem

Posted: March 16, 2011

Trojan-PSW.Lineage!rem is a keylogger and backdoor Trojan that conceals itself from the user while spying on personal information to send to criminals. Passwords and other information related to account logins are particularly likely to be stolen by Trojan-PSW.Lineage!rem. Some versions of Trojan-PSW.Lineage!rem may exhibit virus-like behavior and infect other files. You should delete Trojan-PSW.Lineage!rem with the help of an updated anti-malware application to reestablish your computer's privacy and overall security.

Don't Let Trojan-PSW.Lineage!rem's Sneaking Trojan Horse Inside

Like many other Trojans, Trojan-PSW.Lineage!rem changes the Windows Registry to better allow the infection to launch when Windows starts. You may not be able to see any obvious clues of Trojan-PSW.Lineage!rem's activities, but it's still in memory, using up your system resources and recording everything you do.

The Trojan Trojan-PSW.Lineage!rem has been reported to spread through gaming and pirated software-related applications, as an infection bundled with these programs and then circulated together with them along P2P networks and in free downloading websites. Avoid downloading or running any file from an insecure location unless you're certain that it's clean before you click!

Trojan-PSW.Lineage!rem is known to focus on keylogging, an activity which entails recording all keyboard input to a log. This log is then sent out to anonymous criminals, who look for account passwords and other sensitive information to steal. Many keyloggers like Trojan-PSW.Lineage!rem are also equipped with other illegal reconnaissance-related functions and can take screenshots or record mouse input, too.

Some variants of Trojan-PSW.Lineage!rem are also viruses. Viruses can infect other files with their code, even completely innocent ones. Removing one copy of Trojan-PSW.Lineage!rem isn't that helpful unless you delete all other copies simultaneously, so be particularly thorough in your cleanup efforts if your version of the Trojan-PSW.Lineage!rem infection can infect other files in this fashion.

Protect Your Passwords from Trojan-PSW.Lineage!rem

Removing Trojan-PSW.Lineage!rem can be accomplished by most good anti-malware programs. Manually deleting Trojan-PSW.Lineage!rem may not be wise, since Trojan-PSW.Lineage!rem may hide its files in critical system directories and register .dll files that could be difficult to find and remove properly.

Even better than getting rid of Trojan-PSW.Lineage!rem, though, is never getting infected by Trojan-PSW.Lineage!rem at all. Besides general safe web-browsing practices, you should also be careful about file sources from China. Most Trojan-PSW.Lineage!rem infections originate from that country, so having a little extra caution in such cases will help keep Trojan-PSW.Lineage!rem away from your PC. On the other hand, Trojan-PSW.Lineage!rem has also been spotted in a few other countries, albeit in much smaller numbers, so you shouldn't let your guard down online, regardless of where you are!

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\1.bat
    2 %Windir%\1.bat
    3 %Windir%\Debug\231346E28D27.dll
    4 %Windir%\Debug\231346E28D27.exe
    5 (Default) = "DIDI"
    6 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{47994C89-1857-4D33-B196-263ED6FA4CFF}]
    7 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{47994C89-1857-4D33-B196263ED6FA4CFF}\InPrOcSeRvEr32](Default) = "%Windir%\Debug\231346E28D27.dll"
    8 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    9 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{47994C89-1857-4D33-B196-263ED6FA4CFF}\InPrOcSeRvEr32
    10 ThrEaDiNgModEL = "aPaRTmEnT"
    11 {47994C89-1857-4D33-B196-263ED6FA4CFF} = ""
Loading...