We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Trojan:Win32/Qhost.HB
Aliases: Dropper/Win32.OnlineGameHack (AhnLab) Win32/PSW.OnLineGames.QDE trojan (ESET) Trojan.Win32.Qhost (Ikarus) Trojan-PSW.Win32.MoonBlk.ac (Kaspersky) TROJ_SPNR.0CJ112 (Trend Micro)
Summary
Trojan:Win32/Qhost.HB is a trojan that changes your Hosts file to redirect your Internet traffic to a predefined IP address.
To detect and remove this threat and other malicious software that may be installed on your computer, run a full-system scan with an appropriate, up-to-date, security solution. The following Microsoft products detect and remove this threat:
- Microsoft Security Essentials or, for Windows 8, Windows Defender
- Microsoft Safety Scanner
Additional remediation instructions for Trojan:Win32/Qhost.HB
This threat may make lasting changes to a computer's configuration that are NOT restored by detecting and removing this threat. For more information on returning an infected computer to its pre-infected state, please see the following articles: