Skip Over Navigation Links
Center for Information TechnologyAntivirus
Antivirus Home Page
Contact Us
Questions or Comments
Disclaimers

Software
Current client downloads:
 VScan Engine/Dat (SuperDat) -5400/1158.5812
 VirusScan Enterprise 8.5i (with Patch 7) - Windows NT/2000/XP/2003
 Virex (OS X) Engine/Def - 7.2(v1.1)/081029
 Virex (OS 9.x) Engine/Def - 6.2/071001
 Linux & Solaris Engine/Dat - 5.2.00/4.0.5196
 Symantec Endpoint Protection 11.0 MR4
 Symantec Antivirus - 10.2
 Clean Boot 1.0
 Stinger v3.8.0 virus removal tool (Updated 09/10/07)
Current server downloads:
 VirusScan Enterprise 8.7i
 VirusScan Enterprise 8.5i
 NetShield NetWare - 4.6.2
 NetShield NetWare - 4.6.3
 NetShield NetWare Engine Update - 4.4.00
 ePO agent for NetWare
 ScanMail eManager - 3.0

Information
 Virex 7.x Installation Instructions
 VirusScan FAQs
 VirusScan Instructions
 Additional Resources

Archives
 List of Viruses

Virus Archives

QHosts Trojan Last Updated 10/02/03 3:09PM

QHosts is a trojan that makes use of a new vulnerability in Microsoft's Internet Explorer to change DNS settings on Windows machines. There currently is no patch from Microsoft for this vulnerability. The trojan is spread by visiting webpages that host the malicious code.

One known file dropped by this trojan is AOLFix.exe. This file is dropped in the Windows System directory and the Windows temp directory.

Once the Trojan is run it will create a batch file to change the DNS server for the machine. The DNS address is known to be changed to one of the Following:

  • 69.57.146.14
  • 69.57.147.175

The trojan may also change the %Windows%host file and may make changes to the registry.

The trojan is detected and removed by the current DAT/SuperDAT 4296 released by NAI. Symantec release an IntelligentUpdate package to detect and remove this trojan. This file is available here

For more information see:

http://vil.nai.com/vil/content/v_100719.htm from NAI.
http://securityresponse.symantec.com/avcenter/venc/data/trojan.qhosts.html from Symantec.

This archive is not intended to be comprehensive. For a more complete virus library, please visit NAI's Virus Information Library at http://vil.nai.com.

Contact NIH Help Desk for assistance:
866-319-4357 (toll free), 301-496-4357 (6-HELP) (local), 301-496-8294 (TDD)
http://ithelpdesk.nih.gov/support
Register for iForgotMyPassWord

National Institutes of HealthCenter for Information Technology
National Institutes of Health
Bethesda, Maryland 20892

Questions or Comments | Disclaimers | Privacy Policy

Department of Health and Human ServicesHealth and Human Services
Washington, D.C. 20201
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -