TROJ_QHOST.DMS
Windows 2000, Windows XP, Windows Server 2003
Threat Type: Trojan
Destructiveness: No
Encrypted: No
In the wild: Yes
OVERVIEW
This Trojan executes the dropped file(s). As a result, malicious routines of the dropped files are exhibited on the affected system.
It modifies the affected system's HOSTS files. This prevents users from accessing certain websites.
It attempts to steal sensitive online banking information, such as user names and passwords. This routine risks the exposure of the user's account information, which may then lead to the unauthorized use of the stolen data. It attempts to steal information, such as user names and passwords, used when logging into certain banking or finance-related websites.
TECHNICAL DETAILS
23,040 bytes
EXE
No
30 Oct 2011
Modifies HOSTS file, Connects to URLs/IPs
Arrival Details
This Trojan may be downloaded from the following remote sites:
- http://w{BLOCKED}s.com.br/advogadosoab/telas/www.facebook.com
Installation
This Trojan creates the following folders:
- %User Temp%\5.tmp
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003.)
Dropping Routine
This Trojan drops the following files:
- %User Temp%\5.tmp\1.18.bat - detected as BAT_HOST.FK
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003.)
It executes the dropped file(s). As a result, malicious routines of the dropped files are exhibited on the affected system.
HOSTS File Modification
This Trojan modifies the affected system's HOSTS files to prevent a user from accessing the following websites:
- {BLOCKED}.{BLOCKED}.238.100 itauuniclass.com.br
- {BLOCKED}.{BLOCKED}.238.100 www.itauuniclass.com.br
- {BLOCKED}.{BLOCKED}.238.100 www4.itau.com.br
- {BLOCKED}.{BLOCKED}.238.100 itau.com.br
- {BLOCKED}.{BLOCKED}.238.100 www.itau.com.br
- {BLOCKED}.{BLOCKED}.238.100 www.bancoitau.com.br
- {BLOCKED}.{BLOCKED}.238.100 bancoitau.com.br
- {BLOCKED}.{BLOCKED}.238.100 www.itaupersonnalite.com.br
- {BLOCKED}.{BLOCKED}.238.100 itaupersonnalite.com.br
- {BLOCKED}.{BLOCKED}.0.1 localhost
- {BLOCKED}.{BLOCKED}.238.100 bradesco.com.br
- {BLOCKED}.{BLOCKED}.238.100 www.bradesco.com.br
- {BLOCKED}.{BLOCKED}.238.100 www4.bradesco.com.br
- {BLOCKED}.{BLOCKED}.238.100 www.prime.com.br
- {BLOCKED}.{BLOCKED}.238.100 prime.com.br
- {BLOCKED}.{BLOCKED}.238.100 www.bradescoprime.com.br
- {BLOCKED}.{BLOCKED}.238.100 bradescoprime.com.br
- {BLOCKED}.{BLOCKED}.0.1 localhost
- {BLOCKED}.{BLOCKED}.238.100 bb.com.br
- {BLOCKED}.{BLOCKED}.238.100 www.bb.com.br
- {BLOCKED}.{BLOCKED}.238.100 www.bancodobrasil.com.br
- {BLOCKED}.{BLOCKED}.238.100 bancodobrasil.com.br
- {BLOCKED}.{BLOCKED}.238.100 tam.com.br
- {BLOCKED}.{BLOCKED}.238.100 www.tam.com.br
- {BLOCKED}.{BLOCKED}.0.1 localhost
- {BLOCKED}.{BLOCKED}.238.100 multiplusfidelidade.com.br
- {BLOCKED}.{BLOCKED}.238.100 www.multiplusfidelidade.com.br
- {BLOCKED}.{BLOCKED}.0.1 localhost
- {BLOCKED}.{BLOCKED}.238.100 www.sicredi.com.br
- {BLOCKED}.{BLOCKED}.0.1 localhost
- {BLOCKED}.{BLOCKED}.238.100 sicredi.com.br
- {BLOCKED}.{BLOCKED}.0.1 localhost
- {BLOCKED}.{BLOCKED}.238.100 www.santander.com.br
- {BLOCKED}.{BLOCKED}.238.100 www4.santander.com.br
- {BLOCKED}.{BLOCKED}.238.100 santander.com.br
- {BLOCKED}.{BLOCKED}.238.100 www.santandernet.com.br
- {BLOCKED}.{BLOCKED}.238.100 santandernet.com.br
- {BLOCKED}.{BLOCKED}.238.100 www.banespa.com.br
- {BLOCKED}.{BLOCKED}.238.100 santanderempresarial.com.br
- {BLOCKED}.{BLOCKED}.238.100 www.santanderempresarial.com.br
- {BLOCKED}.{BLOCKED}.0.1 localhost
- {BLOCKED}.{BLOCKED}.238.100 https://www.santandernetibe.com.br
- {BLOCKED}.{BLOCKED}.238.100 www.santandernetibe.com.br
- {BLOCKED}.{BLOCKED}.238.100 santandernetibe.com.br
- {BLOCKED}.{BLOCKED}.238.100 http://www.bb.com.br/portalbb/home23,116,116,1,1,1,1.bb
Information Theft
This Trojan attempts to steal sensitive online banking information, such as user names and passwords. This routine risks the exposure of the user's account information, which may then lead to the unauthorized use of the stolen data.
It attempts to steal information from the following banks and/or other financial institutions:
- Banco Bradesco
- Banco Itau
- Banco Santander
- Banco do Brasil
- Bradesco Prime
- Multiplus
- Prime
- Sicredi
- TAM
NOTES:
It accesses the URL https://{BLOCKED}y.com/124pr4 using the default browser.
However, the said URL is inaccessible as of this writing.
SOLUTION
9.200
8.536.03
30 Oct 2011
Step 1
For Windows XP and Windows Server 2003 users, before doing any scans, please make sure you disable System Restore to allow full scanning of your computer.
Step 2
Remove malware files dropped/downloaded by TROJ_QHOST.DMS
· BAT_HOST.FK
Step 3
Remove these strings added by the malware/grayware/spyware in the HOSTS file
- {BLOCKED}.{BLOCKED}.238.100 itauuniclass.com.br
{BLOCKED}.{BLOCKED}.238.100 www.itauuniclass.com.br
{BLOCKED}.{BLOCKED}.238.100 www4.itau.com.br
{BLOCKED}.{BLOCKED}.238.100 itau.com.br
{BLOCKED}.{BLOCKED}.238.100 www.itau.com.br
{BLOCKED}.{BLOCKED}.238.100 www.bancoitau.com.br
{BLOCKED}.{BLOCKED}.238.100 bancoitau.com.br
{BLOCKED}.{BLOCKED}.238.100 www.itaupersonnalite.com.br
{BLOCKED}.{BLOCKED}.238.100 itaupersonnalite.com.br
{BLOCKED}.{BLOCKED}.0.1 localhost
{BLOCKED}.{BLOCKED}.238.100 bradesco.com.br
{BLOCKED}.{BLOCKED}.238.100 www.bradesco.com.br
{BLOCKED}.{BLOCKED}.238.100 www4.bradesco.com.br
{BLOCKED}.{BLOCKED}.238.100 www.prime.com.br
{BLOCKED}.{BLOCKED}.238.100 prime.com.br
{BLOCKED}.{BLOCKED}.238.100 www.bradescoprime.com.br
{BLOCKED}.{BLOCKED}.238.100 bradescoprime.com.br
{BLOCKED}.{BLOCKED}.0.1 localhost
{BLOCKED}.{BLOCKED}.238.100 bb.com.br
{BLOCKED}.{BLOCKED}.238.100 www.bb.com.br
{BLOCKED}.{BLOCKED}.238.100 www.bancodobrasil.com.br
{BLOCKED}.{BLOCKED}.238.100 bancodobrasil.com.br
{BLOCKED}.{BLOCKED}.238.100 tam.com.br
{BLOCKED}.{BLOCKED}.238.100 www.tam.com.br
{BLOCKED}.{BLOCKED}.0.1 localhost
{BLOCKED}.{BLOCKED}.238.100 multiplusfidelidade.com.br
{BLOCKED}.{BLOCKED}.238.100 www.multiplusfidelidade.com.br
{BLOCKED}.{BLOCKED}.0.1 localhost
{BLOCKED}.{BLOCKED}.238.100 www.sicredi.com.br
{BLOCKED}.{BLOCKED}.0.1 localhost
{BLOCKED}.{BLOCKED}.238.100 sicredi.com.br
{BLOCKED}.{BLOCKED}.0.1 localhost
{BLOCKED}.{BLOCKED}.238.100 www.santander.com.br
{BLOCKED}.{BLOCKED}.238.100 www4.santander.com.br
{BLOCKED}.{BLOCKED}.238.100 santander.com.br
{BLOCKED}.{BLOCKED}.238.100 www.santandernet.com.br
{BLOCKED}.{BLOCKED}.238.100 santandernet.com.br
{BLOCKED}.{BLOCKED}.238.100 www.banespa.com.br
{BLOCKED}.{BLOCKED}.238.100 santanderempresarial.com.br
{BLOCKED}.{BLOCKED}.238.100 www.santanderempresarial.com.br
{BLOCKED}.{BLOCKED}.0.1 localhost
{BLOCKED}.{BLOCKED}.238.100 https://www.santandernetibe.com.br
{BLOCKED}.{BLOCKED}.238.100 www.santandernetibe.com.br
{BLOCKED}.{BLOCKED}.238.100 santandernetibe.com.br
{BLOCKED}.{BLOCKED}.238.100 http://www.bb.com.br/portalbb/home23,116,116,1,1,1,1.bb
Step 4
Search and delete these folders
Step 5
Scan your computer with your Trend Micro product to delete files detected as TROJ_QHOST.DMS. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check this Knowledge Base page for more information.
Did this description help? Tell us how we did.