Hello,
I recently removed this virus from a load of MSN client computers. Apperently what happened was, QHost was created about 5/6 months ago; the trojans main purpose was to resolve Domain names to psuedo IP's and thus preventing you from getting to select websites. The machines I removed the virus from ran Win 98. There is a file that the trojan loads into the ~/system/ directory called 'hosts'. If you open this file in notepad, you'll see the fake DNS resolves. Delete the file for god sake.

The wierd this about this virus is that it resolves you to a website that actually explains to you how to remove this virus. Unfortunetly, the patch that microsoft put out didn't work on my PC's. After the virus was written, the IP's that were initially in the virus, were recently acquired by some company that has to deal with every single hit.

Neat.

scat