Virus:BAT/Qhost.A
Date discovered:04/07/2005
Type:Trojan
In the wild:No
Reported Infections:Low
Distribution Potential:Low
Damage Potential:Low to medium
Static file:Yes
File size:~2.700 Bytes
VDF version:6.31.00.142

 General Method of propagation:
   • No own spreading routine


Aliases:
   •  Kaspersky: Trojan.BAT.Zapchast
   •  F-Secure: Trojan.BAT.Zapchast


Platforms / OS:
   • Windows 98
   • Windows 98 SE
   • Windows NT
   • Windows ME
   • Windows 2000
   • Windows XP
   • Windows 2003


Side effects:
   • Blocks access to security websites

 Files It deletes the initially executed copy of itself.




It tries to executes the following file:

– Filename:
   • %SYSDIR%\ipconfig.exe
using the following command line arguments: /flushdns>NUL

 Hosts The host file is modified as explained:

– In this case already existing entries remain unmodified.

– Access to the following domains is effectively blocked:
   • www.symantec.com; securityresponse.symantec.com; symantec.com;
      pandasoftware.com; www.pandasoftware.com; www.sophos.com; sophos.com;
      www.mcafee.com; mcafee.com; downloads-us1.kaspersky-labs.com;
      updates1.kaspersky-labs.com; updates2.kaspersky-labs.com;
      updates3.kaspersky-labs.com; downloads1.kaspersky-labs.com;
      downloads2.kaspersky-labs.com; downloads3.kaspersky-labs.com;
      ftp.downloads1.kaspersky-labs.com; ftp.downloads2.kaspersky-labs.com;
      ftp.downloads3.kaspersky-labs.com; dnl-eu5.kaspersky-labs.com;
      liveupdate.symantecliveupdate.com; www.viruslist.com; viruslist.com;
      f-secure.com; www.f-secure.com; kaspersky.com; kaspersky-labs.com;
      www.avp.com; www.kaspersky.com; avp.com; www.networkassociates.com;
      networkassociates.com; www.ca.com; ca.com; mast.mcafee.com;
      my-etrust.com; www.my-etrust.com; download.mcafee.com;
      dispatch.mcafee.com; secure.nai.com; nai.com; www.nai.com;
      update.symantec.com; updates.symantec.com; us.mcafee.com;
      liveupdate.symantec.com; customer.symantec.com; rads.mcafee.com;
      trendmicro.com; www.trendmicro.com; www.grisoft.com; virustotal.com;
      www.virustotal.com; windowsupdate.microsoft.com; www.microsoft.com;
      microsoft.com; virusscan.jotti.org




The modified host file will look like this:


Description inserted by Teodor Onisor on Thursday, September 14, 2006
Description updated by Teodor Onisor on Thursday, September 14, 2006

Back . . . .