Home Malware Programs Trojans TrojanSpy.Win32.Lineage

TrojanSpy.Win32.Lineage

Posted: March 28, 2006

Threat Metric

Threat Level: 8/10
Infected PCs: 133
First Seen: July 24, 2009
Last Seen: April 28, 2023
OS(es) Affected: Windows

This Chinese keylogger is designed for stealing information from users PC, by logging his keystrokes and delivering them to hacker's e-mail or FTP. Has it's own SMTP included. It may also stop or jam some processes related to antivirus security. Your machine can be infected by this virus through a web site, or you can get it as a component of a malware package. It runs on Windows 95, 98, ME, NT, 2000, and XP operating computers.

TrojanSpy.Win32.Lineage

Aliases

Trj/Lineage.AHR [Panda]PSW.Agent.BNK [AVG]Lineage!tr.pws [Fortinet]Trojan-PWS.Win32.Mefs [Ikarus]Trojan.Win32.Generic!BT [Sunbelt]Dropper/LineageHack.41537 [AhnLab-V3]Trojan/Win32.Agent [Antiy-AVL]Win32/Lineage.HD [eTrust-Vet]Mal/Packer [Sophos]Heuristic.BehavesLike.Win32.Packed.A [McAfee-GW-Edition]Mal_Lineage [TrendMicro]TR/PSW.Lineage.WO [AntiVir]Heur.Packed.Unknown [Comodo]Trojan.PWS.Lineage.KD [BitDefender]Worm.Mytob-73 [ClamAV]
More aliases (107)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



kavo.exe File name: kavo.exe
Size: 127.86 KB (127865 bytes)
MD5: 2894da8f370c7f2e850ccec23307ed4e
Detection count: 96
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
tavo0.dll File name: tavo0.dll
Size: 81.4 KB (81408 bytes)
MD5: dcd5be4f0c1ffe5d3803c7dd8f55f6aa
Detection count: 95
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
ztdll.dll File name: ztdll.dll
Size: 45.56 KB (45568 bytes)
MD5: d0df75b279b3c95cd976167623349262
Detection count: 95
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
kavo1.dll, kavo0.dll File name: kavo1.dll, kavo0.dll
Size: 165.88 KB (165888 bytes)
MD5: dba7d7a7315453e61dcb381c34612931
Detection count: 82
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
tavo0.dll File name: tavo0.dll
Size: 81.4 KB (81408 bytes)
MD5: 203885a80cf610e2896fe4293f2829b4
Detection count: 76
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
kavo.exe File name: kavo.exe
Size: 118.99 KB (118990 bytes)
MD5: 98e5f0a44aa0de7e1c1c9b602c76bff7
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 11, 2020
tavo.exe File name: tavo.exe
Size: 107.23 KB (107238 bytes)
MD5: edc7f5e1963dfc712864267f410ac3e8
Detection count: 65
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
kavo.exe File name: kavo.exe
Size: 114.99 KB (114996 bytes)
MD5: a44668c37d50b8ce98ad2e8901f54271
Detection count: 65
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
kavo0.dll, kavo1.dll File name: kavo0.dll, kavo1.dll
Size: 147.45 KB (147456 bytes)
MD5: 506e6de313748d3fa98b661f4180a855
Detection count: 64
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
tavo0.dll File name: tavo0.dll
Size: 81.4 KB (81408 bytes)
MD5: 73d482a7339a3a8ffe5ca1626d83b19f
Detection count: 61
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
tavo1.dll File name: tavo1.dll
Size: 81.4 KB (81408 bytes)
MD5: fbdaff19d8020342444a4bd2511e7aa5
Detection count: 60
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
cc[1].exe File name: cc[1].exe
Size: 120.32 KB (120320 bytes)
MD5: 34b066819d8d78e6744ae6f68accf7a9
Detection count: 56
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
tavo.exe File name: tavo.exe
Size: 107.22 KB (107226 bytes)
MD5: c89ce6286fe7559a4ee0e68b9cfeeab8
Detection count: 52
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
kavo.exe File name: kavo.exe
Size: 117.94 KB (117944 bytes)
MD5: 2bf5478c163b69736e47ff77a14807d4
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
tavo.exe File name: tavo.exe
Size: 106.75 KB (106753 bytes)
MD5: 551eb08b4f5898ba7ab554eb91b0a242
Detection count: 43
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
kavo.exe File name: kavo.exe
Size: 108.9 KB (108902 bytes)
MD5: 0777de449b4e5babae3a0d0835aa4597
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
cc[1].exe File name: cc[1].exe
Size: 123.9 KB (123904 bytes)
MD5: 91baf7aa8e72bde314231e3c3f10b24f
Detection count: 36
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
tavo.exe File name: tavo.exe
Size: 110.74 KB (110743 bytes)
MD5: 64e1a4abbefc7ba7e80f5be21acd0ce5
Detection count: 34
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
ff[1].exe File name: ff[1].exe
Size: 132.6 KB (132608 bytes)
MD5: 11f0a5bbb8f58e6f2e186af84032373c
Detection count: 32
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
kavo.exe File name: kavo.exe
Size: 119.45 KB (119450 bytes)
MD5: 903215a4f03612686224698c0d05d9b4
Detection count: 25
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
%WINDIR%\system32\explorer.exe File name: explorer.exe
Size: 41.53 KB (41537 bytes)
MD5: 4093f4a22f3862548770f75c0a426000
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: January 10, 2022
%WINDIR%\winlogin.exe File name: winlogin.exe
Size: 93.18 KB (93184 bytes)
MD5: d83e250ce2876d238e3808be0b61ec8f
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%
Group: Malware file
Last Updated: October 15, 2012
xydll.dll File name: xydll.dll
Size: 38.91 KB (38912 bytes)
MD5: 7bba97d1aae338bccffb88e09c0f7d4c
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009

More files

Registry Modifications

The following newly produced Registry Values are:

File name without path1[1].exeRun keysNewmanTray

Additional Information

The following URL's were detected:
orc10.com
Loading...