|
-
November 16th, 2003, 07:41 PM
#9
Member
Hello,
I recently removed this virus from a load of MSN client computers. Apperently what happened was, QHost was created about 5/6 months ago; the trojans main purpose was to resolve Domain names to psuedo IP's and thus preventing you from getting to select websites. The machines I removed the virus from ran Win 98. There is a file that the trojan loads into the ~/system/ directory called 'hosts'. If you open this file in notepad, you'll see the fake DNS resolves. Delete the file for god sake.
The wierd this about this virus is that it resolves you to a website that actually explains to you how to remove this virus. Unfortunetly, the patch that microsoft put out didn't work on my PC's. After the virus was written, the IP's that were initially in the virus, were recently acquired by some company that has to deal with every single hit.
Neat.
scat
 If the scatman can do it so can you.
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|