Threat Search: 

ThreatExpert's Statistics for Trojan:Win32/Qhost.V [Microsoft]:

Trojan:Win32/Qhost.V [Microsoft] is also known as:
Threat AliasNumber of Incidents
W32/Autorun.worm.b [McAfee]136
Troj/Qhost-O [Sophos]104
Virus.Win32.Agent.GZY [Ikarus]31
New Malware.bx [McAfee]30
not-a-virus:AdWare.Win32.Agent.dyp [Kaspersky Lab]25
New Malware.dq [McAfee]18
Packer.Expressor.B [Ikarus]18
Adware.Agent!sd6 [PC Tools]15
not-a-virus:RiskTool.Win32.HideProc.c [Kaspersky Lab]15
not-a-virus:RiskTool.Win32.HideProc.c [Ikarus]13
W32.SillyFDC [Symantec]11
Virus.Win32.AutoRun.ain [Kaspersky Lab]8
Win-Trojan/Autorun.71168.B [AhnLab]7
Mal/Generic-A [Sophos]6
Trojan.Dropper [Symantec]5
Trojan.Win32.Agent.aebe [Kaspersky Lab]4
Trojan.Win32.Small.xup [Kaspersky Lab]4
Trojan-Downloader.Win32.VB.hqj [Kaspersky Lab]4
Trojan-Downloader.Win32.Agent.aiux [Kaspersky Lab]3
Generic Qhost [McAfee]2
Suspicious.MH690 [Symantec]2
Trojan-Downloader.Win32.VB.gja [Kaspersky Lab]2
Trojan-Spy.Win32.Agent.ccb [Ikarus]2
W32.Gammima [Symantec]2
W32/Autorun.worm.gen [McAfee]2
Worm.Win32.AutoRun.acua [Kaspersky Lab]2
Downloader [Symantec]1
Mal/Packer [Sophos]1
not-a-virus:Server-Proxy.Win32.CCProxy.63 [Kaspersky Lab]1
PWS-Lineage.dr [McAfee]1
TROJ_QHOST.MM [Trend Micro]1
Trojan.Win32.Agent.byje [Kaspersky Lab]1
Trojan.Win32.Agent2.gnq [Kaspersky Lab]1
Trojan.Win32.FlyStudio.bz [Kaspersky Lab]1
Trojan-Downloader.Agent!sd6 [PC Tools]1
Trojan-Downloader.Win32.VB.hfn [Kaspersky Lab]1
Trojan-Downloader.Win32.VB.hsx [Kaspersky Lab]1
Trojan-Dropper.Agent [Ikarus]1
Trojan-Dropper.Win32.Agent.yhq [Kaspersky Lab]1
Trojan-Spy.Win32.Agent.ccb [Kaspersky Lab]1
W32/AutoRun-AZ [Sophos]1
Worm.Win32.AutoRun.llx [Kaspersky Lab]1
Worm.Win32.AutoRun.min [Kaspersky Lab]1
Worm.Win32.Fujack [Ikarus]1

Trojan:Win32/Qhost.V [Microsoft] has the following possible country of origin:
OriginNumber of Incidents
China73

Trojan:Win32/Qhost.V [Microsoft] is known to be created as:
%FontsDir%\fonts.exe
%FontsDir%\lcsmssy.exe
%FontsDir%\smvs.exe
%FontsDir%\uows.exe
%FontsDir%\wyxp.exe
%FontsDir%\yuower.exe
%FontsDir%\yxowr.exe
%System%\svchosi.exe
%System%\war.exe
%System%\zhuruqi.exe
%Temp%\kafan virlist 2009.04.02\090402-a-38.exe
%Windir%\help\smccpi.exe
%Windir%\help\smcuu.exe
%Windir%\resources\themes\k.com
%Windir%\scw.exe
c:\setup.exe
c:\syssafe.exe
Notes:
  • %FontsDir% is a variable that refers to a virtual folder containing fonts. A typical path is C:\Windows\Fonts.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.