I scanned this thing and here are the results..
File MapGen19a.rar received on 05.26.2008 04:59:25 (CET)
Current status: finished
Result: 4/32 (12.50%)
Compact Print results
Antivirus Version Last Update Result
AhnLab-V3 2008.5.22.1 2008.05.23 -
AntiVir 7.8.0.19 2008.05.25 -
Authentium 5.1.0.4 2008.05.26 W32/SecRisk-ProcessPatcher-based!Maximus
Avast 4.8.1195.0 2008.05.26 -
AVG 7.5.0.516 2008.05.25 -
BitDefender 7.2 2008.05.26 -
CAT-QuickHeal 9.50 2008.05.24 -
ClamAV 0.92.1 2008.05.25 -
DrWeb 4.44.0.09170 2008.05.25 -
eSafe 7.0.15.0 2008.05.25 -
eTrust-Vet 31.4.5817 2008.05.23 -
Ewido 4.0 2008.05.25 -
F-Prot 4.4.4.56 2008.05.23 W32/SecRisk-ProcessPatcher-based!Maximus
F-Secure 6.70.13260.0 2008.05.26 -
Fortinet 3.14.0.0 2008.05.25 -
GData 2.0.7306.1023 2008.05.23 -
Ikarus T3.1.1.26.0 2008.05.26
Trojan.Win32.Qhost.it Kaspersky 7.0.0.125 2008.05.26 -
McAfee 5302 2008.05.23 -
Microsoft 1.3520 2008.05.26 -
NOD32v2 3129 2008.05.26 -
Norman 5.80.02 2008.05.23 -
Panda 9.0.0.4 2008.05.25 -
Prevx1 V2 2008.05.26 -
Rising 20.45.42.00 2008.05.23 -
Sophos 4.29.0 2008.05.26 -
Sunbelt 3.0.1123.1 2008.05.17 -
Symantec 10 2008.05.25 Hacktool
TheHacker 6.2.92.318 2008.05.23 -
VBA32 3.12.6.6 2008.05.25 -
VirusBuster 4.3.26:9 2008.05.25 -
Webwasher-Gateway 6.6.2 2008.05.25 -
Additional information
File size: 190673 bytes
MD5...: 52205034f63d7d71b3003d3baa9ee150
SHA1..: ad211319d54f605781ac6316f1a13a6e3212d3c3
SHA256: 679b4a3ba99849bd275d92a2bc9ca76840501fa84807daa96b 3b8d1cfb2f11a3
SHA512: fc798f3098aa01408f7a5003d89bfc2ef17619df24f8582f73 9f165ebefbcf9d
53da9e401023cfb54ef57f7941f0a49bf0f0ecab6fc0b84313 3aff55efc321d1
PEiD..: -
PEInfo: -
P.S.
This Trojan is a modified Windows %System%\drivers\etc\hosts file, which is used to translate domain names (DNS) to IP addresses. The modified file is 964 bytes in size. The file is modified in such a way as to prevent the user from viewing the sites listed below.
The following strings are added to the hosts file.
127.0.0.1 avp.com
127.0.0.1 ca.com
127.0.0.1 customer.symantec.com
127.0.0.1 dispatch.mcafee.com
127.0.0.1 download.mcafee.com
127.0.0.1 downloads1.kaspersky-labs.com
127.0.0.1 downloads2.kaspersky-labs.com
127.0.0.1 downloads3.kaspersky-labs.com
127.0.0.1 downloads4.kaspersky-labs.com
127.0.0.1 liveupdate.symantec.com
127.0.0.1 liveupdate.symantecliveupdate.com
127.0.0.1 mast.mcafee.com
127.0.0.1 networkassociates.com
127.0.0.1 rads.mcafee.com
127.0.0.1 secure.nai.com
127.0.0.1 securityresponse.symantec.com
127.0.0.1 sophos.com
127.0.0.1 updates.symantec.com
127.0.0.1 us.mcafee.com
127.0.0.1 viruslist.com
127.0.0.1
www.avp.com 127.0.0.1
www.ca.com 127.0.0.1
www.f-secure.com 127.0.0.1
www.kaspersky.com 127.0.0.1
www.mcafee.com 127.0.0.1
www.my-etrust.com 127.0.0.1
www.nai.com 127.0.0.1
www.networkassociates.com 127.0.0.1
www.sophos.com 127.0.0.1
www.symantec.com 127.0.0.1
www.trendmicro.com 127.0.0.1
www.viruslist.com Removal instructions
Modify the %System%\drivers\etc\hosts file using any standard application (e.g. Notepad). Delete the strings added by the Trojan. The original hosts file has the following contents:
# Copyright (c) 1993-1999 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
127.0.0.1 localhost
Update your antivirus databases and perform a full scan of the computer (download a trial version of Kaspersky Anti-Virus).